2026-09-03 | A 8473

Added · Updated

Circular SINAP 1-254: Fraud Prevention

The Central Bank of Argentina (BCRA) mandates that administrators of immediate payment transfer schemes provide a fraud risk score to financial entities and payment service providers offering payment accounts (PSPCPs) based on BCRA-supplied data. These entities must integrate the score into new client onboarding, transactional monitoring, and periodic account reviews to detect fraud risks. Implementation deadlines are set at 120 days for scheme administrators, while financial entities and PSPCPs have 60 days for onboarding and monitoring processes and 90 days for periodic reviews, contingent upon receiving technical documentation from the scheme administrators.

Banco Central de la Republica Argentina logo

Argentina

Banco Central de la Republica Argentina

Click to view thumbnail

"2026 - YEAR OF ARGENTINE GREATNESS" COMMUNICATION “A” 8473 03/09/2026 TO FINANCIAL ENTITIES, TO ADMINISTRATORS OF ELECTRONIC FUND TRANSFER SCHEMES, TO PROVIDERS OF PAYMENT SERVICES THAT OFFER PAYMENT ACCOUNTS: Ref.: Circular SINAP 1-254: Fraud Prevention.


We address you to inform you that this Institution has adopted the resolution, in its pertinent part, which is transcribed below:

“1- Approve the provisions to mitigate fraud exposed in the Annex. 2- Establish that the subjects covered by these provisions will begin to comply with them according to the following schedule: – Administrators of immediate payment transfer schemes: within 120 (one hundred twenty) calendar days counted from the publication of this communication. – Financial entities and providers of payment services that offer payment accounts: Subsections 5.1. and 5.3. of the Annex of this communication: within 60 (sixty) calendar days counted from the date on which the administrators of the immediate payment transfer schemes in which they participate have supplied them with the technical documentation provided for in subsection 7.1.7. of the Annex of this communication. Subsection 5.2. of the Annex of this communication: within 90 (ninety) calendar days counted from the date on which the administrators of the immediate payment transfer schemes in which they participate have supplied them with the technical documentation provided for in subsection 7.1.7. of the Annex of this communication.”

We salute you respectfully. CENTRAL BANK OF THE ARGENTINE REPUBLIC Matías A. Gutierrez Girault Alejandra I. Sanguinetti Main Manager of Payment Systems and Current Accounts General Deputy Manager of Payment Means

ANNEX

  1. Objective The Central Bank of the Argentine Republic (BCRA) will supply information on natural persons to administrators of immediate payment transfer schemes so that, using it, they develop a fraud risk assessment tool intended to strengthen the customer knowledge and fraud prevention processes that financial entities and providers of payment services that offer payment accounts (PSPCPs) must have implemented, in order to facilitate the early detection of profiles with higher fraud risk or other relevant inconsistencies.

  2. Subjects Covered 2.1. Financial entities. 2.2. PSPCPs. 2.3. Administrators of immediate payment transfer schemes.

  3. Information Supply by the BCRA The information will be supplied by the BCRA monthly and free of charge, via a file and exclusively to administrators of immediate payment transfer schemes. This information will be public access, or obtained from public access information or, when linked to non-public access information, will be expressed in a minimal and/or aggregated form.

  4. Elaboration and Submission of the Risk Assessment Administrators of immediate payment transfer schemes must use the information supplied by the BCRA to develop, according to the methodology they mutually agree upon, a score, grouping, ranking, or analogous measure (hereinafter, score) of fraud risk in electronic payments for each CUIL/CUIT corresponding to a natural person. In developing this score, the aforementioned administrators must also use the information contained in the Fraud Prevention Central mentioned in Communication B 13117, and may use transactional information in whose processing they intervene and that –within the framework of that mutually agreed methodology– they agree to share. This score must be supplied by such administrators, free of charge, to financial entities and to PSPCPs that originate immediate transfers in any modality in their scheme –fund sending, fund deposit, payment with transfer, collection with transfer, and those regulated in the future– through all of the following mechanisms: a) An updated monthly file, containing all CUIT/CUILs of natural persons. b) An automated programming interface (API) so that, if applicable, the updated score can be consulted. B.C.R.A. Annex to Comm. “A” 8473 c) Others established by the BCRA.

  5. Mandatory Use by Financial Entities and PSPCPs Financial entities and PSPCPs must use the score provided for in point 4. in the following processes: 5.1. new client onboarding and account opening; 5.2. transactional monitoring of all modalities of transfers included in the consolidated text on the National Payment System – Transfers – Supplementary Rules, both regarding ordering clients and recipients; 5.3. periodic review of their account holder registry, in order to reevaluate and, if applicable, recategorize the risk level associated with each one.

  6. Implementation 6.1. Administrators of immediate payment transfer schemes, financial entities, and PSPCPs must have, for the implementation of what is provided for in this regulation, policies, procedures, methodologies, and controls duly formalized and approved by the highest administrative body or equivalent authority. The decisions they adopt within this framework must be based on objective, reasonable, and generally applicable criteria. 6.2. Financial entities and PSPCPs must incorporate the score into their risk management policies and procedures, without this exempting them from applying their own due diligence mechanisms, transactional monitoring, enhanced analysis, and adoption of mitigation measures, in accordance with current regulations and their risk appetite. 6.3. The decisions of financial entities and PSPCPs cannot be based exclusively on the score. Its use does not alter the responsibility assigned to them in matters of fraud prevention.

  7. Formalization, Traceability, and Review 7.1. Administrators of immediate payment transfer schemes must: 7.1.1. Preserve evidence of the information received from the BCRA. 7.1.2. Have completely and detailedly documented the methodology used for the development of the score, as well as the statistical measures that endorse its robustness, calibration, and discriminatory power. 7.1.3. Preserve evidence of the supply of the score to financial entities and/or PSPCPs. 7.1.4. Accredit before the Specialized Supervision Management and the Payment Systems Management that the score presents and maintains an appropriate predictive power to identify fraud risk in electronic payments, by presenting an independent review report with a periodicity of at least semi-annual.

7.1.5. Periodically update the model used in the generation of scores, based on new available information and to reflect changes in behavioral patterns in electronic payments and other structural changes. These updates must be documented. 7.1.6. Modify the estimated model, when in the judgment of the BCRA it does not present sufficient predictive power or presents other deficiencies requiring correction. 7.1.7. Supply to financial entities and PSPCPs documentation allowing them to understand and use the score. This documentation must explain the methodology used for estimation, the variables included and their importance or relative weight, the relationship between the score and the estimated risk, and include graphs and statistical measures allowing evaluation of its robustness, calibration, and discriminatory power. 7.2. Financial entities and PSPCPs must preserve evidence of the use of the score in the processes provided for in point 5. When the processes defined in point 5. are performed directly by administrators of immediate payment transfer schemes, these must preserve the corresponding evidence of the use of the score. All documentation and analyses required in this point must remain available to the Superintendence of Financial and Exchange Entities (SEFYC) and the Payment Systems Management upon their request.

  1. Internal Audit The internal audits of financial entities and the equivalent control bodies of PSPCPs must include in their planning, at least annually, procedures intended to review the effectiveness of the policies, procedures, controls, and methodologies implemented in compliance with this regulation. This periodicity must be increased when the complexity, characteristics, or level of exposure to risk so warrant.

  2. Confidentiality and Protection of Information Administrators of immediate payment transfer schemes, financial entities, and PSPCPs must adopt the security, confidentiality, integrity, availability, and protection measures that are necessary to ensure that the information supplied by the BCRA in one case, and the score developed from it in another, are used exclusively for the purposes provided for in this regulation, avoiding unauthorized access, treatment, reproduction, assignment, or disclosure. Likewise, they must establish control and traceability mechanisms that allow identifying accesses, uses, transfers, and eventual incidents linked to said information and to the score, and maintain the corresponding evidence available to the SEFYC upon its request.

  3. Non-Compliance The subjects covered and those found responsible may be subject to the application of the sanctions provided for in articles 41 and 42 of the Financial Entities Law and other concordant provisions, for the non-compliances that are established with respect to this regulation.

More like this from BCRA

BCRA published 11 documents in the last 30 days. We email you each new one the day it's published.

Share