Chile CMF adjusts fraud reporting rule
The CMF removed a semiannual fraud-reporting duty for cases already posted on websites. Law 21,663 adds new cybersecurity obligations.
Chile’s Financial Market Commission amended General Regulation No. 539 on Sept. 8, 2026, removing the semiannual duty to report fraud already published on websites. At the same time, Framework Cybersecurity Law No. 21,663 adds risk management and incident-reporting obligations for financial entities classified as essential services or vital operators.
Chile’s Financial Market Commission amended General Regulation No. 539 on Sept. 8, 2026, and removed the semiannual requirement to report fraud cases already published on websites. The change comes alongside the new Framework Cybersecurity Law No. 21,663, which sets risk management and incident-reporting obligations for certain Chilean financial entities.
What changed in the fraud reporting obligation?
The CMF formalized the change to the semiannual fraud reporting requirement through an amendment to NCG 539 issued on Sept. 8, 2026. Based on the available material, the update means that the semiannual report is no longer required when the information has already been published on websites.
The regulatory point matters because it marks a specific compliance adjustment within the framework that applies to supervised entities. The reference to NCG 539 and the date of the regulatory act places the change in formal terms, without extending it beyond what the source material states.
What does Law 21,663 require from financial entities?
Framework Cybersecurity Law No. 21,663 requires covered organizations to put internal processes in place to manage cybersecurity risk and report incidents with significant impact. For financial-sector actors, those obligations apply when they are classified as essential service providers or vital operators.
The source cited in the material, IAPP, says this creates new compliance obligations for Chilean financial entities that fall into those categories. The focus is not only on incident notification, but also on the internal organization needed to comply with the risk and reporting scheme established by the law.
Who does this new framework apply to?
It applies to certain essential service providers and vital operators, including financial-sector actors that are classified in those categories. In the material, the law is not presented as a general rule for all companies, but as a specific regime for entities defined by their role and importance within the system.
That distinction connects the CMF’s regulatory change with the new legal framework. While NCG 539 adjusts a fraud reporting obligation, Law 21,663 expands the compliance scope on risk and incidents for entities covered by the legal classification.



