2025-01-02
Added · Updated
The Central Bank of Uruguay replaced Article 364 and added Article 364.1 to the Compilation of Regulations and Control Norms of the Financial System, imposing new obligations on issuers of electronic instruments and requiring strong customer authentication. Issuers must now provide written information on user obligations, ensure secure authentication methods including double-factor authentication for remote transactions, and maintain detailed logs of operations and access. Strong customer authentication requires combining at least two factors from distinct categories (knowledge, possession, inherence), with advanced electronic signatures accepted for remote loan requests. These rules apply to financial intermediation companies, credit administration companies, credit granting entities, financial services companies, exchange houses, fund transfer companies, and peer-to-peer lending platform administration companies, effective March 1, 2025.
Diagonal Fabini 777 - C.P. 11100 - Tel.: (598 2) 1967 - Montevideo, Uruguay - www.bcu.gub.uy 1 Montevideo, January 2, 2025 CIRCULAR N°2472 Ref: FINANCIAL INTERMEDIATION COMPANIES, CREDIT ADMINISTRATION COMPANIES, CREDIT GRANTING ENTITIES, FINANCIAL SERVICES COMPANIES, EXCHANGE HOUSES, FUND TRANSFER COMPANIES AND PEER-TO-PEER LENDING PLATFORM ADMINISTRATION COMPANIES – OBLIGATIONS AND STRONG CUSTOMER AUTHENTICATION – ARTICLES 364 AND 364.1 OF THE RNRCSF
It is brought to your attention that the Board of Directors of the Central Bank of Uruguay, on December 27, 2024, exercised the right of assumption (article 36 of Law No. 16.696 of March 30, 1995, as amended by article 9 of Law No. 18.401 of October 24, 2008, and resolution D/160/2012 of June 14, 2012) over Resolution RR-SSF-2024-586 of December 20, 2024, and adopted the following resolution:
ARTICLE 364 (OBLIGATIONS OF THE ISSUER). The issuer of the electronic instrument shall:
a. Inform in writing the user of the electronic instrument, prior to the conclusion of the contract, of their obligations and responsibilities in the use of the system, indicating at least those applicable among those listed in articles 366 and 367. Such communication must be made in a document distinct from the contract signed by the parties, without prejudice to also being included in it.
b. Reveal the personal identification number or other key only to the user.
c. Deliver only those electronic instruments expressly requested by the client, except when it concerns the renewal of an electronic instrument already possessed.
d. Provide the client with elements that allow them to verify the operations carried out, at least one of which must be free of charge for clients.
e. Provide the client with elements that allow them to clearly identify the reason for a rejected operation, except in cases where legal or regulatory confidentiality requirements must be respected.
Diagonal Fabini 777 - C.P. 11100 - Tel.: (598 2) 1967 - Montevideo, Uruguay - www.bcu.gub.uy 2 f. Inform the client about the main risks to which they are exposed when using the electronic instrument to carry out financial transactions, and provide recommendations on how they should adequately protect themselves to mitigate such risks.
g. Inform the procedure that the client must follow to report the theft, robbery, snatching, or loss of the electronic instrument or any of the circumstances foreseen in letter h) of article 366, guarantee the existence of adequate means to do so, and prove that such notification has been made. For these purposes, the issuer (or the institution indicated by it) will provide the user with a number identifying their report and will indicate the date and time of it. The means for making the notification must operate every day of the year, during the twenty-four hours.
h. Demonstrate, in the event of a user claim regarding any transaction carried out, and without prejudice to any contrary evidence that the user may produce, that the transaction: • was carried out in accordance with the procedures agreed with the client; • was correctly registered and accounted for; • was not affected by a technical failure or any other anomaly; and • was correctly authenticated in accordance with the methodology established for it, and must also make available to the user - regardless of whether the instrument was used in the country or abroad - the safeguarded information indicated in letter i) and any other element that allows demonstrating that such transaction was carried out by the client or by third parties with the client's knowledge.
In the event that it cannot be demonstrated, the issuer will be responsible for the claimed transaction, provided it is not attributable to breaches of the user's obligations. For the purposes of complying with this obligation, the conditions of the contracts that the issuer may have signed with third parties shall not be opposable.
i. Establish measures that reasonably guarantee the security of the system in which the instrument operates, which include authentication methodologies associated with the risks of the different types of transactions and access levels to ensure that the operations carried out in it are those performed by authorized persons. Without prejudice to this, transfers or payments to third parties made from a bank account and loan requests made remotely will require as a minimum a double factor of authentication. Likewise, monitoring and control measures must be established that allow detecting irregular events linked to the use of the instrument or the system in which it operates, including changes and attempts to change passwords, personal identification numbers, address, phone, and contact email, means established to receive communications, among others.
Such system must safeguard, at a minimum: • dates and times of operations; • contents of messages; • identification of operators, issuers, and recipients; • accounts and amounts involved; • user authentication mechanism used in the operation; • identification of the terminal from which the operation was performed; and • whether the operation was performed in person or remotely.
Diagonal Fabini 777 - C.P. 11100 - Tel.: (598 2) 1967 - Montevideo, Uruguay - www.bcu.gub.uy 3 j. Ensure the correct functioning of the system, and the continuous provision of the service, under normal circumstances.
k. Remove electronic instruments from the system on the day they lose validity (due to expiration or by decision of the parties in accordance with the terms of the contract).
l. Determine the means and forms by which the institution can communicate with the client. It must indicate, if applicable, that it will never ask them to reveal their personal identification keys under any circumstances or by any means.
The user shall declare – at a minimum – two contact addresses (address, phone, email, among others) for the purpose of receiving communications, notifications, or alerts related to the electronic instrument, and the issuer must establish measures that reasonably guarantee the veracity of the information provided. These measures must be established at the time of contract conclusion and whenever the modification of such data is requested. In the case of clients who have only one contact address, when its modification is requested, the institution must obtain another address in order to comply with what is provided in letter m).
m. Notify the user of the commission of any illicit act or irregular event linked to the electronic instrument under their ownership upon detecting or becoming aware of it. Likewise, it must notify them of any attempt or request to modify the data referred to in letter i), indicating the modification request received. When it concerns the client's contact information, the communication must be directed, at a minimum, to two of the previously valid contact addresses and must indicate the procedure to follow to validate or reject the requested change. Once the modification is made, this must be communicated to the user.
n. Offer the user the possibility of receiving notifications via electronic means (email, instant messaging, SMS, notification in their own application, among others) every time a transaction linked to the electronic instrument under their ownership is processed, which must indicate the available means to make inquiries or complaints related to the transaction. At least one of these electronic means must be free of charge.
The user may modify the parameters of these notifications or decide not to receive them. In the latter case, the issuer must keep a record of the client's informed decision not to receive such notifications by means that allow for verification, in accordance with article 496.
ARTICLE 364.1 (STRONG CUSTOMER AUTHENTICATION). For the application of the double factor of authentication referred to in letter i) of article 364, at least two factors of distinct categories (knowledge, possession, and inherence) must be combined.
Likewise, advanced electronic signature provided by providers within the framework of Law No. 18.600 of September 21, 2009, and its amendments and regulatory provisions, is admitted as a strong customer authentication mechanism for loan requests made remotely.
Advanced electronic signature based on certificates issued by providers accredited before the Electronic Certification Unit or recognized as equivalent when issued by entities not established in the national territory will be accepted.
JUAN PEDRO CANTERA Superintendent of Financial Services 2023-50-1-01824