CiberLATAMbywhalemate

Brazil Central Bank tightens PIX rules

New PIX rules take effect March 1, 2027, adding fraud controls, longer dispute windows and bans on links in payment receipts.

Whalemate Labs · AI-assisted researchPublished:3 min read

Brazil's Central Bank announced new PIX security rules that take effect on March 1, 2027. The package bans ads and links in receipts, extends the fraud response window to 80 days, and requires apps to accept documents in disputes.

Brazil's Central Bank announced new PIX security rules that will take effect on March 1, 2027. The package changes payment receipts, extends the time to respond to suspicious transactions, and adds new requirements for banking and financial apps, with the stated goal of strengthening fraud prevention.

What changes in PIX receipts?

The Central Bank banned ads, commercial offers, hyperlinks, and any content unrelated to the transaction from PIX payment receipts. According to the official note cited by Tribuna do Agreste, the measure is meant to keep receipts from becoming a vector for scams through malicious links.

The restriction also applies to any element that does not belong to the operation itself. The decision is part of a broader security package the regulator published on September 3, 2026, with an effective date set for March 1, 2027.

How does fraud disputes change in the MED?

The deadline to respond to suspicious transactions through the Special Refund Mechanism, known as the MED, has increased from 30 to 80 days, according to Tecmundo and IstoÉ Dinheiro. The Central Bank says the change is designed to improve case review and give merchants and service providers more time to submit evidence.

G1 reported that banking and financial apps will have to let customers attach documents and receipts when contesting a fraudulent transfer. In practice, that includes tax receipts and delivery records, which the coverage cited says can help show that a transaction was legitimate.

IstoÉ Dinheiro added that the move to 80 days amounts to a 166% increase in the time available to respond to improper claims. The same report said the Central Bank paired these measures with the future removal of the fixed R$500 limit for tap-to-pay PIX transactions and with a requirement to map funds split across different accounts, in an effort to tighten controls over the system's use in money laundering.

What other security changes are in the regulatory package?

Beyond PIX, the Central Bank and the National Monetary Council are also tightening rules in crypto and in security requirements for financial institutions. For virtual asset service providers, Central Bank Resolutions No. 519, 520, and 521/2025, in force since February 2, 2026, govern authorization and operations, along with foreign-exchange transactions involving cryptoassets tied to international markets.

Vidigal Neto Advogados said that framework brought prudential and governance requirements into the PSAV sector. Fincatch added that these companies must show they can implement the Travel Rule, ensure operational segregation and the security of customer assets, and organize supporting documentation for the authorization process.

TrustSwap said that under those same resolutions, providers are subject to minimum capital requirements ranging from about R$10.8 million to R$37.2 million, depending on the activity. It also said foreign platforms must operate through an authorized Brazilian entity, and that stablecoin flows used for international payments and remittances are now treated as foreign-exchange transactions, with per-transaction limits and reporting obligations starting May 4, 2026.

Portal do Bitcoin reported that Coinext's shutdown reflected the concrete impact of that stricter regulatory environment on the local market, noting that companies unable to meet the new authorization and control requirements would have to stop operating. TechCripto added that the Central Bank defined the PSAV regime as the new regulated category for virtual asset service providers, marking the formal start of prudential and cybersecurity oversight for these entities.

How does the security requirement expand for banks and fintechs?

The updated CMN Resolution No. 5,274/2025 strengthens controls over key and certificate protection, traceability, continuous monitoring, security testing, and vendor risk management, according to Prodist. That framework adds to the cyber security policy already required under CMN Resolution No. 4,893/2021.

The regulatory focus also extends to the technology supply chain for banks, cooperatives, and fintechs. Prodist describes broader oversight of third parties and critical tools, while Fincatch's material notes that cybersecurity has become evidence of governance in PSAV authorization processes.

Sources

View all