BCRA launches anti-fraud score for transfers
Communication A 8473 sets risk scoring for electronic payments, with deadlines, traceability and data safeguards for banks.
Argentina’s central bank, the BCRA, issued Communication A 8473 and launched a fraud-risk evaluation system for instant transfers. The rule applies to financial institutions, PSPCPs and scheme administrators, using public data, implementation deadlines and evidence, security and traceability requirements.
Argentina’s central bank, the BCRA, issued Communication A 8473 and launched a fraud-risk scoring system for electronic payments based on information the bank itself will provide to instant transfer administrators. The measure applies to financial institutions, PSPCPs and scheme administrators, and it is tied to a public data framework meant to detect suspicious activity, accounts linked to fraud and illegal gambling.
What changes under Communication A 8473?
The rule requires a fraud-risk score for customer onboarding, transaction monitoring and periodic review of the customer roster, with evidence available to the Superintendency of Financial and Exchange Institutions. It also says the information and the score may be used only for the intended purposes, with traceability and data protection controls.
According to analysis by Bruchou & Funes de Rioja, the BCRA will provide scheme administrators with monthly, no-cost information on public or aggregated personal data. That data must be combined with records from the Fraud Prevention Central Registry and, eventually, with shared transactional information. The result will be a score for each CUIL or CUIT, available to banks and PSPCPs that originate instant transfers.
Who does it cover, and what must they keep?
Communication A 8473 applies to financial institutions, payment service providers that offer payment accounts, and instant transfer scheme administrators. It also requires them to retain evidence of how the score is used in key processes. They must adopt security, confidentiality, integrity and availability controls for the information, along with mechanisms to monitor access, use, transfers and incidents.
Bruchou & Funes de Rioja says that evidence must remain available for regulatory supervision. The same analysis adds that entities covered by the rule may face sanctions under Articles 41 and 42 of the Financial Institutions Law, including fines, disqualifications and other administrative measures for noncompliance.
What deadlines did the BCRA set?
The rule sets different deadlines. Financial institutions and other covered entities have 60 calendar days from the moment administrators provide the technical documentation on the score to implement customer onboarding and periodic roster review. They have 90 calendar days for transaction monitoring.
For instant transfer scheme administrators, Bruchou & Funes de Rioja cites a separate 120-day deadline from the publication of the rule to implement the framework. Reporting in Argentina also said rollout would be gradual, and that starting in September 2026 administrators would begin receiving public information to build risk profiles and distribute them at no cost to banks and PSPCPs.
How does this connect with other rules in the region?
In Argentina, Ciberseguridad Latam had already highlighted BCRA Communication A 7724 as an important tool in bank cybersecurity regulation and in the fight against cybercrime. At the same time, local general-interest media reported that Communication A 8471 brought internal and external fraud into the operational risk management framework and required antifraud strategies, policies and practices, along with a formal responsible structure.
In Mexico, the CNBV has also been adjusting authentication and security rules for operations through technology agents and digital channels. According to Ciberseguridad Latam, those changes affect balance inquiries and low-risk transactions, although stronger multi-factor requirements remain in place for higher-risk operations. ZeroTrust Consulting added that some rules allow SMS to be used as an authentication factor in certain lower-risk schemes.
SHCP’s Economic Policy Criteria 2027, meanwhile, say the agency will take part in coordination and communication efforts among financial authorities to address cybersecurity incidents and will continue pushing regulatory changes in anti-money laundering and counterterrorism financing prevention. An analysis by Truora also notes that the CNBV requires continuous identification and verification of customer identity before and throughout the entire relationship with the institution, not just at onboarding.
Sources
- El BCRA implementa un nuevo esquema para detectar fraudes y apuestas ilegales en el sistema de pagosyogonet.com· Yogonet Latinoamérica
- El nuevo estándar de KYC para el ecosistema fintech en LATAMblog.truora.com· Truora
- El BCRA endurecerá los controles sobre las transferencias en Argentinalmneuquen.com· LM Neuquén
- Nuevo score de riesgo de fraude del BCRA para transferencias inmediatas (Com. “A” 8473)bruchoufunes.com· Bruchou & Funes de Rioja
- Individual fraud risk profiles introduced for instant transfersstate-of.biz· State-of.biz
- El Banco Central compartirá datos para detectar cuentas vinculadas a fraudes y juego ilegallosprimeros.tv· Los Primeros TV
- ZTC Cyber Intelligence 003 | 7 de septiembre de 2026zerotrust.consulting· ZeroTrust Consulting
- Tag entidades financieras (incluye análisis sobre Comunicación A 7724 del BCRA)ciberseguridadlatam.com· Ciberseguridad Latam
- El fin del cumplimiento de papelexcelsior.com.mx· Excélsior
- Tag tecnología financiera (incluye análisis sobre medidas de seguridad y comisionistas tecnológicos en México)ciberseguridadlatam.com· Ciberseguridad Latam
- Criterios generales de política económica 2027 (SHCP-Criterios-politica_economica-2027.pdf)inep.org· Secretaría de Hacienda y Crédito Público (SHCP) de México



