2024-12-20 | Instrução Normativa BCB 575Added · Updated
Participating institutions must ensure data quality, adhere to API specifications, and report metrics to the Open Finance Governance Structure. They must send at least 95% of daily reports by 8:00 am the next day and 99% within seven days, with UNPAIRED reports capped at 5% and 1% respectively. Institutions must maintain a data quality index SLA of 95% and correct non-compliances promptly upon receiving tickets. Non-compliant institutions must submit a non-conformity report within five business days or an adequacy plan within ten business days. Failure to meet conversion rate thresholds below 60% triggers a specific evaluation. This instruction enters into force on the date of publication, replacing previous versions.
BCB published 19 documents in the last 30 days — get each new one by email the day it lands.
INSTRUCTION NORMATIVE BCB NO. 575, OF
DECEMBER 20, 2024
Regulatory document revoked by Instruction Normative BCB No. 706, of 1/29/2026.
Publishes version 2.0 of the Open Finance Monitoring Manual.
The Heads of the Department of Financial System Regulation (Denor), the Department of Supervision of Cooperatives and Non-Bank Institutions (Desuc), the Department of Banking Supervision (Desup) and the Department of Information Technology (Deinf), in the exercise of the powers conferred upon them by art. 23, item I, letter "a", of the Internal Regulations of the Central Bank of Brazil, annexed to Resolution BCB No. 340, of September 21, 2023, based on art. 3, item VI, of Resolution BCB No. 32, of October 29, 2020,
R E S O L V E :
Art. 1 This Instruction Normative publishes version 2.0 of the Open Finance Monitoring Manual, mandatory compliance by participating institutions, as per Annex.
Sole Paragraph. The manual referred to in the *caput*, in its most recent version, will be accessible on the *Open Finance* page on the internet website of the Central Bank of Brazil and on the *Open Finance* Portal in Brazil, maintained by the Open Finance Governance Structure referred to in art. 44, § 1, of Joint Resolution No. 1, of May 4, 2020.
Art. 2 Instruction Normative No. 441, of December 20, 2023, published in the Official Gazette of the Union on December 22 of 2023, is hereby revoked.
Art. 3 This Instruction Normative enters into force on date of its publication.
RENATO KIYOTAKA UEMA IVENS ARUA NEVES DE MIRANDA Head of Denor, substitute Head of Desuc, substitute
BELLINE SANTANA HAROLDO JAYME MARTINS FROES CRUZ Head of Desup Head of Deinf
ANNEX TO INSTRUCTION NORMATIVE BCB NO. 575, OF DECEMBER 20, 2024
Open Finance Monitoring Manual Version 2.0
Summary of changes
| Date | Version | Description of changes |
| .../12/2024 | 2.0 | Section 1: expansion of the Monitoring Manual to all participating institutions. |
| Subsection 2.1: inclusion of the quantity of errors with HTTP 529 status code as an additional item regarding API performance. | ||
| Subsection 2.2: aggregation of monitored sub-items into three items regarding the theme of the subsection and flexibility of some sub-items regarding non-compliance analysis. | ||
| Subsection 2.3: flexibility of the percentage of tickets attended within the maximum deadline for the purpose of non-compliance analysis of the item and adjustments to give greater clarity to the text. | ||
| Subsection 2.4: establishment of a service level agreement (SLA) for reporting information to the metrics collection platform. | ||
| Subsection 2.5: establishment of SLA for data quality of participating institutions. | ||
| Subsection 2.6.1: journey monitoring now applies to the priority brands of participating institutions, with the exception of those that do not have journeys related to a certain scope, and it is now admitted that institutions send their own evidence for the purpose of demonstrating correction of non-compliances. | ||
| Subsection 2.6.2: inclusion of conversion rate regarding account linking on devices, included in the journey without redirection. | ||
| Section 3: removal of the provision that the Open Finance Governance Structure applies "warning" and "fine" measures to participating institutions in non-compliance. |
Terms of Use
This manual defines the basic principles of Open Finance monitoring, complementing the current regulation on the subject.
The manual will be reviewed and updated periodically in order to preserve compatibility with the regulation, as well as incorporate improvements resulting from the evolution of Open Finance.
More detailed information and examples of the application of this manual can be found on the Open Finance Portal in Brazil (https://openfinancebrasil.org.br/), maintained by the Open Finance Governance Structure.
Suggestions, criticisms or requests for clearing up doubts regarding the content of this document can be sent to the Central Bank of Brazil through the institutional channels of this autarchy.
References
These specifications are based on, reference and complement, when applicable, the following documents:
| Reference | Origin |
| Joint Resolution No. 1, of 2020 | https://www.bcb.gov.br/estabilidadefinanceira/exibenormativo?tipo=Resolu%C3%A7%C3%A3o%20Conjunta&numero=1 |
| Resolution BCB No. 32, of 2020 | https://www.bcb.gov.br/estabilidadefinanceira/exibenormativo?tipo=Resolu%C3%A7%C3%A3o%20BCB&numero=32 |
| Law No. 13.709, of 2018, General Law for the Protection of Personal Data (LGPD) | http://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/L13709.htm |
Introduction
This manual was prepared with the objective of guaranteeing that the monitoring of Open Finance, to be carried out by the Open Finance Governance Structure, is capable of verifying if the participating institutions are in compliance with the obligations provided for in the regulation of the Central Bank of Brazil and in documents prepared by the Open Finance Governance Structure, as defined by the current regulation.
It is worth highlighting that the determinations regarding the monitoring of technology services established in this manual are complementary and not exclusive in relation to what is determined by the Manual of Services Provided by the Open Finance Governance Structure.
This monitoring manual is not limited to technology issues, since the adequate monitoring of the infrastructure of Open Finance involves different aspects, being a condition for the system to continue evolving in an agile, efficient and secure manner.
Among these aspects, the following items stand out:
I - performance of application programming interfaces (APIs) and non-functional requirements;
II - specifications, registrations, certification and publication of APIs;
III - deadline goals for ticket resolution;
IV - information reporting;
V - data quality; and
VI - customer experience.
It is important to highlight that the Open Finance Governance Structure must carry out the monitoring of the various items mentioned above through the evaluation of all occurrences, being permitted to monitor by sampling only in specific situations expressly authorized by the Central Bank of Brazil.
The Open Finance Governance Structure must store and give publicity to statistical data and indicators regarding the various monitored items. In addition, participating institutions must provide quality data with sufficient detail to allow the Open Finance Governance Structure to implement the monitoring process referred to in this manual.
Additionally, it is emphasized that the Open Finance monitoring process must be documented through a monitoring policy, which must comprise the items monitored by the system, the monitoring management flow, the roles and responsibilities of the members of this flow and the measures applicable in situations of non-compliance.
All documentation related to the process of monitoring is the responsibility of the Open Finance Governance Structure and must be kept available to the Central Bank of Brazil for five years.
Monitored items
This section describes the items that must be monitored by the Open Finance Governance Structure of Open Finance. Such items and the detail of each of them represent the minimum required, with the Open Finance Governance Structure of Open Finance, regardless of normative change, guaranteeing that the monitored items are expanded whenever necessary, with a view to the final objective of the monitoring process, which is the good functioning of Open Finance for all stakeholders: participating institutions, clients and society.
Additionally, considering that the tools and processes of Open Finance monitoring are in a constant process of development, this manual will be restricted to aspects in which it is already possible to obtain metrics for monitoring, with the other metrics and indicators being subsequently incorporated as they become available for tracking.
In this sense, the obtaining of monitored items must be carried out, prioritarily, through tools of the Open Finance Governance Structure of Open Finance. In the absence of these tools or in case of tools that can obtain only partially the monitored items, participating institutions must report the necessary information so that the Open Finance Governance Structure of Open Finance can fulfill all stages of monitoring described in this manual or in its documentation.
2.1 API
Performance and non-functional requirements
The
Open Finance Governance Structure of Open
Finance must monitor various issues related to API performance and non-functional requirements, among which, the following items must be prioritized, at a minimum, for the purposes of the monitoring process:
I
II
III
For the purposes of the monitoring process, it is admitted that tickets opened automatically by tools of the Open Finance Governance Structure of Open Finance or specific tickets are used, and that the application of the flow of monitoring occurs in a monthly manner, it being worth noting, however, that the participating institutions must correct non-compliances in a prompt manner, as soon as they receive the tickets.
The
Service Level Agreement (SLA) and calculation methods regarding the response time and availability of APIs of participating institutions, as well as the volume of requests with HTTP 529 status code, are contained in the Open Finance API Manual.
2.2
Specifications, registrations, certification and publication of APIs
This subsection will address the monitored items regarding API specifications; registrations in the Participants Directory, certification and publication of these APIs. It is highlighted that the items of this subsection must be fulfilled in their totality, so that any deviation from the established standard will result in the application of measures to the participating institution in non-compliance.
The occurrence of non-compliances regarding the items treated in this subsection will result in the opening of tickets to the participating institution in non-compliance, whose maximum response deadlines are contained in the Manual of Services Provided by the Open Finance Governance Structure of Open Finance.
The
Open Finance Governance Structure of Open
Finance must monitor, at a minimum, the following items regarding specifications, registrations, certification and publication of APIs of participating institutions:
I
a) monitor and require compliance with the intermediate milestones of the process of certification and publication in production of initial versions and new versions of APIs, whether they are defined in regulation or by the Open Finance Governance Structure of Open Finance itself; and
b) verify and require the proper publication of APIs of participating institutions in the Participants Directory and in a production environment;
II
a) verify and require that the APIs and associated artifacts of participating institutions in a production environment are adherent to the current functional and security specifications; and
b) verify and require that information regarding APIs, including the appropriate certifications, are correctly updated in the tools and systems associated with the services provided by the Open Finance Governance Structure of Open Finance;
III
IV
The
Open Finance Governance Structure of Open
Finance must manage the process of obtaining maturity of the functional and security certification engines, with a view to enabling participating institutions to fulfill the obligations of item I of this subsection.
It is highlighted that non-compliances regarding the items referred to in this subsection must be ascertained as soon as they are detected.
For the purposes of the monitoring process, it is admitted that tickets opened automatically by tools of the Open Finance Governance Structure of Open Finance or specific tickets are used, and that the application of the flow of monitoring occurs in a monthly manner, it being worth noting, however, that the participating institutions must correct non-compliances in a prompt manner, as soon as they receive the tickets.
Regarding the items of this subsection, with the exception of item I, letter "b", if participating institutions manage to correct the non-compliances within the maximum deadline allowed, according to the Manual of Services Provided by the Open Finance Governance Structure of Open Finance, such non-compliance situations must be registered in the information made available to participating institutions for the management of non-compliance situations, as per section 5 of this Manual, but must not be considered for the purpose of applying measures.
2.3
Deadline goals for ticket resolution
The
Open Finance Governance Structure of Open
Finance must monitor, at a minimum, the deadline for resolution of:
I
II
The
Open Finance Governance Structure of Open
Finance must monitor, track and demand resolution for each ticket, bilateral or opened by it, if it has not been resolved within the maximum deadline for its resolution, and generate statistics on the resolution deadline of each ticket, bilateral or opened by it, that has been closed or that has exceeded its deadline.
Participating institutions must respect the maximum response deadlines for tickets established in the Manual of Services Provided by the Open Finance Governance Structure of Open Finance. It is admitted, for the purpose of evaluating compliance with the monitored item referred to in this subsection, that participating institutions meet the maximum deadline for 80% of their tickets, provided they do not present tickets with a delay exceeding double the maximum deadline established in the aforementioned Manual.
For the purposes of the monitoring process, the assessment period regarding the item of which this subsection deals is monthly.
2.4
Information Reporting
Participating institutions must make available, within the deadlines defined by the Open Finance Governance Structure of Open Finance, data with adequate quality and with sufficient detail, in order to allow the Open Finance Governance Structure of Open Finance to implement the functionalities set forth in this manual.
The
Open Finance Governance Structure of Open
Finance must establish, for each case, the data that need to be sent by participating institutions, as well as their method of sending, periodicity, among other applicable items.
Regarding the Metrics Collection Platform (PCM), participating institutions must send at least 95% of reports of a given day by 8:00 am the next day and at least 99% of reports within seven days from the date and time of the transactions.
It is admitted that an institution does not meet the daily reporting goal in up to three days of a given month, provided that it has sent at least 99% of the reports of those days within seven days from the date and time of the transactions.
To meet the goal of sending at least 95% of reports by 8:00 am the next day from the date and time of the transactions, reports with status "UNPAIRED" cannot exceed 5% of the volume of calls of the institution for each API.
To meet the goal of sending at least 99% of reports within seven days from the date and time of the transactions, reports with status "UNPAIRED" or "PAIRED INCONSISTENT" cannot exceed 1% of the volume of calls of the institution for each API.
If the institution is unable to send the reports due to PCM failures, the goal of sending reports by 8:00 am the next day does not need to be met, but the institution remains obligated to send them within seven days from the date and time of the transactions.
For the purposes of the monitoring process, the assessment period regarding the items of which this subsection deals is monthly and there must be daily control of the sending of reports. If it is detected that a participating institution is not meeting any of the established goals, it must be notified and return to timely normality. It is highlighted that any failures in the notification generation process throughout the month should not impact the application of the monthly monitoring flow.
2.5
Data Quality
Participating institutions of
Open Finance must guarantee the quality of the data reported through their APIs, with observance, at a minimum, of the following items:
I
II
III
IV
V
VI
Aiming at the maintenance of Open Finance data quality, participating institutions that have adhered, mandatorily or voluntarily, to the sharing of data must implement the data quality engine, according to parameters defined by the Open Finance Governance Structure of Open Finance, and use it in their role as data transmitters.
The reporting of information regarding the use of the data quality engine must be carried out by each participating institution, with consolidated reporting by the conglomerate not being valid. It is admitted that credit cooperatives report their information in a consolidated manner through cooperative systems.
Based on the reports generated from the analysis of tickets related to data quality and statistics resulting from the use of the data quality engine by participating institutions, the Open Finance Governance Structure of Open Finance must maintain a data quality index that demonstrates the individual performance of each institution. This index must be in constant update according to the evolution of Open Finance.
Participating institutions of Open Finance must maintain an SLA on the data quality index equal to or greater than 95%. Participating institutions with performance below this value will be considered in non-compliance.
In the case of API versions where there is a pilot period in production, the calculation of the data quality index should not include them, with a view to allowing these APIs to achieve greater maturity, but they must be included in the calculation of the said index from the date of go-live.
During the pilot period in production, the tickets generated must respect the maximum deadlines established in the Manual of Services Provided by the Open Finance Governance Structure of Open Finance and, consequently, be monitored according to subsection 2.3 of this Manual, in order for data quality to also be improved in the pilot phase in production.
For the purposes of the monitoring process, the assessment period regarding the items of which this subsection deals is monthly.
2.6
Customer Experience
2.6.1
Customer Journey
The
Open Finance Governance Structure of Open
Finance must monitor customer journeys, according to the different modalities of:
I - existing flows, considering the different channels, devices and environments in which the Open Finance journey is made available, such as app-to-app, app-to-browser and vice-versa on the same device; app-to-browser and vice-versa between different devices; and browser-to-browser;
II
III
IV
The Open Finance Governance Structure must generate its own evidence of customer journeys or hire independent suppliers to do so, with the caveat that the generation of journey evidence by sending journeys directly from the participating institution itself will not be admitted. The generation of evidence by the participating institution itself is admitted for the purpose of proving the correction of non-conformities, to be evaluated by the Open Finance Governance Structure for the closure of tickets.
For the monitoring process, the period for calculating the monitoring of the customer journey will be defined by the Open Finance Governance Structure and will occur with the same frequency as the evaluation rounds to be carried out with the selected participating institutions.
The Open Finance Governance Structure will define the scopes of evaluation for each round and, with the exception of brands or institutions that do not operate within the scopes defined for a specific evaluation round, the brands considered priorities of the most relevant participating institutions, as defined by the Central Bank of Brazil, must be present in all rounds.
If the participating institution corrects the non-conformity within its maximum deadline for response, that non-conformity situation must be recorded in the information made available to participating institutions for the management of non-conformity situations, as per section 5 of this Manual, but it must not be considered for the application of measures.
For the purpose of analyzing the verification of the correction of the non-conformity, the participating institution must send evidence to the Open Finance Governance Structure as soon as the correction is made, and the Open Finance Governance Structure must evaluate such evidence in a timely manner. If the participating institution is unable to generate evidence regarding a specific scope or target audience, the generation of evidence for the analysis regarding the verification of the correction of the non-conformity must be carried out by the Open Finance Governance Structure, directly or through independent suppliers hired for this purpose. The non-conformity will only be considered corrected after the analysis of such evidence.
2.6.2
Conversion Rate
The Open Finance Governance Structure must monitor the conversion rate of data sharing journeys and payment initiation journeys.
The minimum conversion rates for data sharing journeys and payment initiation journeys are:
I - data sharing: 80% of the weighted average by requested consents of the three highest conversion rates of data transmitting institutions in the last three months, including the reference month;
II - payment transaction initiation: 80% of the weighted average by requested consents of the three highest conversion rates of account-holding institutions in the last three months, including the reference month; and
III - link: 80% of the weighted average by requested links of the three highest conversion rates of account-holding institutions in the last three months, including the reference month.
There is a tolerance limit of three percentage points for the minimum conversion rates referred to in this subsection.
The conversion rates referred to in this subsection must be calculated as follows:
I - data sharing: quantity of consents whose "access tokens" were successfully generated in relation to the quantity of "consentIds" generated for customers redirected to the data transmitting institution; and
II - payment transaction initiation: quantity of consents whose "access tokens" were successfully generated in relation to the quantity of "consentIds" generated for account-holding customers redirected to the account-holding institution; and
III - link: quantity of authorized links in relation to requests for link creation by account-holding customers redirected to the account-holding institution.
The "customer" in the above formulas is considered to be the CPF/CNPJ that has an authenticator credential to proceed in the monitored flow.
The period for calculating the conversion rates is monthly, and for each month, all weeks whose Fridays occurred in the month must be considered.
For the purpose of the monitoring process, the calculation period for the item referred to in this subsection is monthly.
Monitoring Process
The Open Finance monitoring process, carried out by the Open Finance Governance Structure, together with the participating institutions, must be guided by the principles of transparency, continuous improvement, efficiency, and accuracy, and have the objective of ensuring that participating institutions are in line with the obligations provided for in documents elaborated within the scope of the Open Finance Governance Structure and in the regulation of the Central Bank of Brazil.
The Open Finance Governance Structure must define and document the monitoring process through a specific policy (Monitoring Policy), which must comprise, at a minimum, the monitoring and application of measures flow, the roles and responsibilities of the members of this flow, and the measures applicable in case of non-compliance with the desired performance.
Other aspects regarding the monitoring process, such as the monitored items, must also be documented, but, considering the need for more frequent updates, they may appear in a document auxiliary to the Monitoring Policy or directly on the developer portal.
If it is detected that a participating institution is not in compliance with a monitored item, the case must be followed up by a Service Desk ticket, and a ticket that was already opened regarding the case may be used, or a new ticket may be opened, specific or consolidating several non-conformity situations.
3.1
Monitoring and Application of Measures Flow
The Monitoring Policy must describe the monitoring and application of measures flow, discriminated by each member of the flow, encompassing, at a minimum, the following stages of this process:
I - verification of SLAs, minimum conversion rates, and maximum deadlines for Service Desk ticket response;
II - identification of non-conformity situations;
III - follow-up of non-conformity situations through Service Desk tickets;
IV - evaluation of the response of non-compliant participating institutions regarding non-conformity situations;
V - sending the case for analysis and action by eventual higher instances, in case of continuity of the non-conformity situation or of the impact of the situation on the proper functioning of Open Finance; and
VI - application of measures to non-compliant participating institutions.
3.2
Applicable Measures
In case of non-conformity situations, the Monitoring Policy must provide for the application of the following measures:
I - delivery of a report on non-conformity situations;
II - presentation of an adequacy plan; and
III - presentation of a specific evaluation on the conversion rate.
This subsection contemplates minimum provisions on measures applicable to non-conformity situations regarding the items monitored that are in section 2 of this manual.
3.2.1
Report on Non-Conformity Situations
The report on non-conformity situations, mentioned in item I of subsection 3.2, must:
I - be presented by the non-compliant participating institution;
II - contain a description of what occurred and the solution adopted for correction;
III - be accompanied by the acknowledgment of the director responsible for data sharing and services within the scope of Open Finance, according to the internal flows of each participating institution of Open Finance;
IV - be presented through the official channels of the participating institution within five business days after the request by the Open Finance Governance Structure; and
V - be available to the Central Bank of Brazil.
In case of the absence of the responsible director, the acknowledgment of another statutory director is admitted.
Institutions that, when requested, do not present the report referred to in this subsection within the defined deadline must present the adequacy plan referred to in subsection 3.2.2.
3.2.2
Adequacy Plan
The adequacy plan, mentioned in item II of subsection 3.2, must:
I - be presented by the non-compliant participating institution;
II - contain a detailed schedule for the non-conformity situation to be solved and mitigating elements for the prevention of new occurrences;
III - be signed by the director responsible for data sharing and services within the scope of Open Finance;
IV - be presented through the official channels of the participating institution within ten business days after the request by the Open Finance Governance Structure; and
V - be evaluated and approved by the Open Finance Governance Structure.
In case of the absence of the responsible director, the signature of another statutory director is admitted.
Non-conformities identified in monitored items contained in an adequacy plan that is being implemented and being complied with as approved by the Open Finance Governance Structure and, when applicable, by the Central Bank of Brazil, must not be considered, as long as improvements consistent with the expected are being observed.
If the adequacy plan in execution by a non-compliant participating institution does not present results consistent with the expected, the Open Finance Governance Structure must communicate the case to the Central Bank of Brazil with the information referred to in subsection 3.4.1.
Adequacy plans that include monitored items contained in subsection 2.3 must contemplate any open tickets and adjustments in internal processes, so that the customer service teams of the participating institutions begin to meet the established response deadlines.
The Open Finance Governance Structure must notify the Central Bank of Brazil about the eventual non-presentation of an adequacy plan within the regulatory deadline.
Adequacy plans must be available to the Central Bank of Brazil, which may request adjustments to them.
3.2.3
Specific Evaluation on Conversion Rate
The specific evaluation on the conversion rate, mentioned in item III of subsection 3.2, must:
I - be presented by the non-compliant participating institution that presents a conversion rate below the threshold referred to in subsection 3.4.2.1;
II - contain a diagnosis of its conversion rate;
III - be presented within ten business days after the detection of the non-conformity; and
IV - have its results submitted to the Open Finance Governance Structure and to the Central Bank of Brazil.
After analysis by the Open Finance Governance Structure, in cases where most of the errors that caused the conversion rate below the referred threshold refer to implementation aspects, both regarding technical issues or related to the customer journey, the non-compliant participating institution must hire an independent specialized company to carry out a more complete diagnosis of the conversion rate of the non-compliant participating institution.
The referred diagnosis must be presented within ninety calendar days after the request by the Open Finance Governance Structure and is valid for twelve months.
3.3
Repeated Occurrences
The presentation of a non-conformity situation regarding the same monitored item by a participating institution may constitute a repeated occurrence.
Below, the rules, by monitored item, are presented for a certain case to be configured as a repeated occurrence:
I - API performance and non-functional requirements: presentation of a non-conformity situation during three calculation periods after the detection of the initial non-conformity. Each of the items of the corresponding subsection is considered separately. Even if the non-conformity situation occurred in a different endpoint from the initial non-conformity, it is considered a repeated occurrence. The calculation period for the purpose of detecting a repeated occurrence is monthly;
II - specifications, registrations, certification, and publication of APIs: presentation of a non-conformity situation during three calculation periods after the detection of the initial non-conformity. Each of the items of the corresponding subsection is considered separately. Even if the non-conformity situation occurred in a different API from the initial non-conformity, it is considered a repeated occurrence. The calculation period for the purpose of detecting a repeated occurrence is monthly;
III - maximum deadline goals for ticket response: presentation of a non-conformity situation during three calculation periods after the detection of the initial non-conformity. The calculation period for the purpose of detecting a repeated occurrence is monthly;
IV - reporting of information: presentation of a non-conformity situation during three calculation periods after the detection of the initial non-conformity. The calculation period for the purpose of detecting a repeated occurrence is monthly;
V - data quality: presentation of a non-conformity situation during three calculation periods after the detection of the initial non-conformity. The calculation period for the purpose of detecting a repeated occurrence is monthly;
VI - customer experience - customer journey: presentation of a non-conformity situation during four monitoring cycles after the detection of the initial non-conformity for the same role (account holder, payment transaction initiator, data transmitter, or data receiver), for the same target audience (natural person or legal entity), and for the same brand. The calculation period for the purpose of detecting a repeated occurrence will be at the beginning of the month following the end of the maximum deadline for resolution of the non-conformities identified by the monitoring of the customer journey; and
VII - customer experience - conversion rate: presentation of a non-conformity situation during three calculation periods after the detection of the initial non-conformity. Each of the items of the corresponding subsection is considered separately. The calculation period for the purpose of detecting a repeated occurrence is monthly.
3.4
Measure Application Rule
3.4.1
General Rule
In the event of detection of non-conformity situations regarding a monitored item, the non-compliant participating institution must present to the Open Finance Governance Structure the report referred to in subsection 3.2.1.
If the participating institution presents a non-conformity situation regarding the same monitored item repeatedly, as per subsection 3.3, it must present the adequacy plan referred to in subsection 3.2.2.
In case of a second repeated occurrence, the higher management body of the Open Finance Governance Structure, as per the regulation of the Central Bank of Brazil, must communicate the case to the Central Bank of Brazil with, at a minimum, the following information:
I - the device violated of a normative act of the National Monetary Council or of the Central Bank of Brazil or of the technical documentation of the Open Finance Governance Structure;
II - a descriptive report of the case;
III - history of all available information; and
IV - supporting documentation.
The Open Finance Governance Structure must inform the non-compliant participating institution about the communication to the Central Bank of Brazil.
After the communication to the Central Bank of Brazil, the Open Finance Governance Structure must continue to follow up with the non-compliant participating institution, which must present new adequacy plans until the non-conformity is ceased. As soon as the non-conformity is ceased, the Open Finance Governance Structure must notify the Central Bank of Brazil.
3.4.2
Specific Rules
The applicable measures referred to in this subsection are complementary to the measures set out in subsection 3.4.1.
3.4.2.1
Customer Experience - Conversion Rate
In the event that the conversion rate falls below 60% of the minimum conversion rates referred to in subsection 2.6.2, the non-compliant participating institution must present the evaluation referred to in subsection 3.2.3.
3.5 Communication of the Monitoring Process
The communication of the monitoring process is a fundamental aspect so that participating institutions have broad knowledge about the items being monitored, the desired performance, how the monitoring and application of measures flow works, the roles and responsibilities of each member of this flow, and what the applicable measures are.
3.5.1
Broad Communication to Participating Institutions
The Open Finance Governance Structure must communicate, broadly, to participating institutions how the monitoring process in Open Finance works, addressing, at a minimum, the monitored items, the SLAs, the minimum conversion rates, and the maximum deadlines for ticket response, the monitoring and application of measures flow, the roles and responsibilities, and the applicable measures.
The communication strategy must consider that some of these items may undergo frequent changes, and thus, timely updates are necessary, so that participating institutions are always well-informed regarding the monitoring process.
3.5.2
Specific Communication to Participating Institutions
The Open Finance Governance Structure must make available information about the performance of each participating institution regarding the monitored items, with a view to monitoring by these institutions regarding their performance, with greater emphasis on the items that are in a situation of non-conformity with the desired performance.
This information must be provided at a level of detail sufficient for the participating institution to verify the fidelity of the data analyzed in the monitoring and application of measures flow regarding its internal data.
Statistical Data and Indicators on the Performance of Participating Institutions in Open Finance
The Open Finance Governance Structure must provide the means for storage and compilation of statistical data regarding the performance of participating institutions in Open Finance and their performance regarding the monitored items, as well as produce and make available indicators based on this data.
To ensure the proper functioning of the system, the Open Finance Governance Structure may collect and store other relevant metrics not explicitly mentioned in this manual, noting that the collection and storage of customer data are prohibited, even if anonymized or pseudonymized.
4.1 Disclosure of Statistical Data and Indicators on the Performance of Participating Institutions
The statistical data regarding the performance of participating institutions must cover, at a minimum, information regarding:
I - the quantity of calls per API and per endpoint, including their history;
II - the availability of APIs per endpoint, including their history;
III - the percentage of success of calls, as well as their errors, per status code;
IV - the quantity of active consents in total and per unique customers, natural and legal persons, including views by transmitter or holder (as applicable) and by receiver or initiator (as applicable), including their history; and
V - the conversion rates of the consent with a breakdown of each stage of its generation, including views by transmitter or holder and by receiver or initiator.
The data reported by participating institutions are the responsibility of each institution, represented by the director responsible for data sharing and services within the scope of Open Finance, and must be reported with a minimum frequency that allows verifying the compliance with service level agreements:
I - of the APIs of the participating institutions; and
II - of the elements of the shared infrastructure.
The Open Finance Governance Structure, based on the service level indicators calculated for participating institutions, must build an Open Finance performance index, calculate it individually for each participating institution, and publish it monthly.
These statistical data must also be made available, in a public area of the Open Finance Portal in Brazil in the form of an indicator dashboard of easy visualization, individually and nominally regarding the participating institutions, which allows the general public to verify this performance in a quick and clear manner.
The indicator dashboard must provide data visualization in, at a minimum, two different levels:
I - consolidated view: with the averages of the most important indicators, providing highlights for the best and worst performances of the month; and
II - customized/comparative view: with the possibility of sorting by value (ascending and descending), search, and selection of multiple parameters by the user, such as the name of the participating institution, endpoint, period, among others.
In both views, the indicator dashboard must contain a visual resource, such as graphs, icons, or symbols, that allows assessing the performance of the indicator in relation to the required regulatory minimum. The views must allow the general public to identify nominally the performance of each of the participating institutions.
Given the broad scope of Open Finance participants, any graphs that list all participating institutions must have a search tool to assist the user in locating a specific institution in the graph, if desired.
The indicator dashboard must also contain resources for custom search, in order to enable the selection of fields, including individualized and non-aggregated data. The results must be downloadable in different formats, respecting the selection of fields or segregation of data performed.
The metrics, units of measurement, and definitions used must be clear to the user, as well as any limitations, exclusions, or changes regarding the calculation base.
4.2 Disclosure of Statistical Data and Indicators on the Monitored Items
The Open Finance Governance Structure must compile the statistical data on the monitored items, generate indicators and indices regarding them, and publish them, with a view to providing transparency regarding the monitoring process and creating incentives for participating institutions to seek continuous evolution of their performance.
This disclosure must include statistical data, indicators, and indices for each participating institution, individually and nominally, considering its history, as well as any non-compliance situations regarding each monitored item and other identified non-compliance situations that are not yet within the scope of the monitored items.
Statistical data, indicators, and indices must be documented for internal control purposes of the Open Finance Governance Structure and be available to the Central Bank of Brazil.
The Open Finance Governance Structure must make the following information available so that participating institutions can manage non-compliance situations:
I - a list of all open cases and the history of cases that are already closed;
II - the status of each open case depending on the phase it is in within the monitoring and measure application flow; and
III - the details of each case, with specific information about the non-compliance situation, the date the case entered the monitoring and measure application flow, and the remaining time for its resolution, in accordance with the regulation of the Central Bank of Brazil and the documentation of the Open Finance Governance Structure.
The monitoring information for non-compliance situations mentioned in this section must be accessible to the Central Bank of Brazil.
This manual applies:
I - to data-transmitting institutions belonging to conglomerates or cooperative systems that represented 99% of the total stock of active consents on December 20, 2023, considering the information reported by institutions to the Central Bank of Brazil;
II - to account-holding institutions belonging to conglomerates or cooperative systems in which 99% of the total quantity of payment transactions successfully carried out within the scope of Open Finance were initiated;
III - to participating institutions not covered by the criteria set forth in items I and II, regarding subsection 2.2 and its impacts on other sections and subsections;
IV - to participating institutions not covered by the criteria set forth in items I and II, from July 1, 2025, regarding subsection 2.3 and its impacts on other sections and subsections; and
V - to all participating institutions, from January 2, 2026, regarding the remaining sections and subsections.
The identification of the account-holding institutions mentioned in item II of this section must be carried out by ordering, by institution and in descending order, the total quantity of payment initiation transactions carried out within the scope of Open Finance, considering the information reported by institutions to the Central Bank of Brazil regarding the last 24 weeks, counted from December 20, 2023.
The changes made in the sections and subsections of this manual enter into force as follows:
I - subsections 2.1, 2.2, 2.4, 2.5, and 2.6.1: from July 1, 2025; and
II - remaining sections and subsections: from the entry into force of the Instruction Normative containing this manual.
Brasília, December 20, 2024.
NOTE 887/2024-BCB/DENOR, OF DECEMBER 19, 2024.
Justifies the proposal for the issuance of a normative instruction that establishes version 2.0 of the Open Finance Monitoring Manual.
Chiefs of Denor, Desuc, Desup, and Deinf,
This Note justifies the proposal for the issuance of a normative instruction by the Department of Regulation of the Financial System (Denor), the Department of Supervision of Cooperatives and Non-Bank Institutions (Desuc), the Department of Banking Supervision (Desup), and the Department of Information Technology (Deinf), in the exercise of the powers conferred upon them by art. 23, item I, letter "a", of the Internal Regulations of the Central Bank of Brazil, annexed to Resolution BCB No. 340, of September 21, 2023, based on art. 3º, item VI, of Resolution BCB No. 32, of October 29, 2020.
In this regard, the proposal deals with the issuance of a normative instruction that establishes version 2.0 of the Open Finance Monitoring Manual, revoking Instruction Normative BCB No. 441, of December 20, 2023, which published version 1.0 of the Customer Experience Manual in Open Finance.
The changes made in this new version refer to the expansion of items applicable to all participating institutions, such as compliance with the maximum deadline for ticket response, the flexibility of the ticket response percentage, the inclusion of an additional item for monitoring the performance of application programming interfaces (APIs) and service level agreement (SLA) for the reporting of information regarding the metric collection platform and for the data quality of participating institutions, the expansion of customer journey monitoring to all brands of participating institutions except those that do not have journeys within the monitored scope, the inclusion of monitoring of the conversion rate of the linking stage of the journey without redirection, the removal of the possibility for the Open Finance Governance Structure to apply warning and fine measures to participating institutions in non-compliance, the flexibility of situations that entail repeated occurrences, and other details or adjustments aimed at bringing greater clarity to the normative text.
It is worth highlighting that, by virtue of art. 5º of Law No. 13.874, of September 20, 2019, proposals for the issuance and alteration of normative acts of general interest to economic agents or users of the services provided, issued by an organ or entity of the federal public administration, including autarchies and public foundations, must be preceded by the realization of a regulatory impact analysis (RIA), which will contain information and data on the possible effects of the normative act to verify the reasonableness of its economic impact.
For its part, Decree No. 10.411, of June 30, 2020, which regulates this Law, in its art. 4º, item II, establishes that the RIA may be dispensed with in the case of a normative act that reduces requirements, obligations, restrictions, requests, or specifications with the objective of reducing regulatory costs, applicable to the exclusion of measures that may be applied by the Open Finance Governance Structure and other regulatory flexibilities carried out.
Regarding the expansion of items applicable to all participating institutions, the inclusion of an additional item for monitoring API performance, SLAs for reporting information and for data quality, the expansion of customer journey monitoring to all brands of participating institutions except those that do not have journeys within the monitored scope, and the monitoring of the conversion rate of the linking stage of the journey without redirection, it is highlighted that institutions already monitor such metrics, with some already having SLAs established by the Open Finance Governance Structure, so that such adjustments can be considered low impact and, thus, are exempt from RIA, according to art. 4º, item III, of said Decree No. 10.411, of 2020. It is important to highlight that, according to art. 9º-A, § 2º, the discussions regarding these changes took place within the scope of the Open Finance Governance Structure, an environment in which all participating institutions of Open Finance are represented, guaranteeing social participation.
Thus, considering the above, the normative instruction now proposed is exempt from RIA.
For your consideration.
JANAÍNA PIMENTA
ATTIE MATHEUS RAUBER CORADIN Chief of Subunit Senior Advisor
IVENS ARUA NEVES DE MIRANDA RICARDO SIVIERI ZENI Deputy Chief of Desuc Deputy Chief of Desup
VERUSKA ROCHA ARAGÃO Deputy Chief of Deinf
In agreement.
RENATO KIYOTAKA UEMA ADALBERTO FELINTO DA CRUZ JUNIOR Chief of Denor, substitute Chief of Desuc
BELLINE SANTANA HAROLDO JAYME MARTINS FROES CRUZ Chief of Desup Chief of Deinf
Read the rest free
Amended 1 time · last 2026-01-29
Source: Banco Central do Brasil — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from BCB
BCB published 19 documents in the last 30 days. We email you each new one the day it's published.