2025-09-19 | Resolución SBS 3289-2025The Peruvian Superintendence of Banking, Insurance and Private Pension Fund Administrators (SBS) issued Resolution No. 3289-2025 to modify Article 17 of the Credit and Debit Card Regulations, mandating financial institutions to implement distinct transaction monitoring systems that operate independently from user authentication processes. The amended article requires companies to adopt minimum security measures, including fraud pattern identification, alert management procedures, transaction amount limits across service channels, and enhanced authentication for high-risk operations. Furthermore, the resolution clarifies that monitoring measures constitute part of corporate risk management without independently determining transaction validity, thereby defining institutional liability for user transactions according to Article 23 of the Regulations.
Lima, September 17, 2025 SBS Resolution No. 3289-2025 The Superintendent of Banks, Insurance Companies and Private Pension Fund Administrators CONSIDERING: Whereas, by SBS Resolution No. 6523-2013 the Credit and Debit Card Regulations were approved, which establish general provisions applicable to credit and debit cards, including those regarding the implementation of transaction monitoring systems and corporate responsibilities when transactions are executed, as well as the necessary validations required to verify each cardholder's identity; Whereas, by SBS Resolution No. 2286-2024 the regulatory framework for card usage was modified, establishing that financial system companies must assume responsibility for users' identity validation procedures and obtaining their consent when executing transactions, in cases of unrecognized transactions and those processed without requiring enhanced authentication, as well as the companies' obligations associated with compliance with mandatory provisions; Whereas, it is necessary to define the scope of implementing monitoring systems as part of each company's risk management, with the purpose of clarifying that these systems are not part of and are distinct from the user authentication process for conducting card transactions; Whereas, likewise, financial system companies may incorporate additional measures into the monitoring system as part of their risk management, such as applying amount limits per transaction, additional authentication methods for high-risk transactions, obtaining insurance policies to cover potential losses, among others; Having obtained the approval of the Deputy Superintendencies for Banking and Microfinance, Regulation and Legal Affairs, as well as the Risk Management, Market Conduct and Financial Inclusion Departments; and, In the exercise of the powers conferred by paragraphs 7 and 9 of Article 349, and in accordance with the Thirty-Second Final and Complementary Provision of Law No. 26702, General Law of the Financial System and Insurance System and Organic Law of the Superintendence of Banking and Insurance, and its amendments;
RESOLVES: Article One.- Article 17 of the Credit and Debit Card Regulations, approved by SBS Resolution No. 6523-2013 and its amendments, is modified as indicated below: "Article 17th.- Security measures regarding transaction monitoring 17.1 Companies must adopt, at a minimum, the following security measures regarding the monitoring of card transactions executed by users: