CiberLATAMbywhalemate

Chile redefines banking MFA and fraud controls

Chile’s CMF tightens banking security, keeping coordinate cards only for vulnerable users while moving critical transactions to MFA.

Whalemate Labs · AI-assisted researchJul 22, 20262 min read

Chile’s CMF update leaves coordinate cards reserved for vulnerable segments and pushes local banks toward multifactor verification for higher-risk operations. The change intersects with General Rule 502 and Laws 21.521 and 21.459, which expand security and compliance requirements for banks and payment instrument issuers.

Coordinate cards only in exceptional cases

According to El Mostrador, the CMF’s update allows coordinate cards to remain in use only for vulnerable segments. That category includes older adults, users with low digital literacy, people living in areas with limited connectivity, and other profiles that banks can substantiate to the regulator. As a result, institutions will need specific segmentation models and exception-handling processes.

MFA for higher-risk transactions

The same report says the new multifactor verification scheme will be mandatory for critical, high-risk operations, such as transfers to new recipients, high-value payments, and changes to security settings. The shift moves the focus away from a uniform control model and toward stronger authentication tied to transaction risk.

Under that model, banking MFA in Chile relies on combining knowledge factors, such as a password or PIN, possession factors, such as a trusted device with a soft token, and biometrics. The rule is designed so that at least two of those categories are used in each critical transaction, bringing local practice closer to international strong-authentication standards.

A stricter regulatory framework

The broader reading is that Chile’s banking sector is facing not only an operational change in transfer channels, but also a denser compliance layer. CMF General Rule No. 502, on information security and cybersecurity management, is joined by Law 21.521, on theft and fraud involving cards and financial instruments, and Law 21.459, on cybercrime.

Taken together, the framework pushes banks and payment instrument issuers to justify exceptions, document controls, and adjust authentication flows for sensitive operations. At the same time, the coexistence of mandatory MFA and coordinate cards limited to vulnerable segments forces institutions to define internal criteria, traceability, and regulator-facing proof, according to the CMF framework and El Mostrador’s coverage.

Sources

View all