2026-01-28
Added · Updated
Resolution SSF N° 2025-744 amends Articles 364 and 364.1 of the Financial System Regulatory and Control Compilation to impose new security obligations on issuers of electronic instruments, including mandatory electronic notifications for data modification attempts and the adoption of periodic monitoring system efficacy evaluations. It extends the requirement for reinforced client authentication (two-factor) to digital channel access, non-presential loan requests, and sensitive data updates, while explicitly permitting passkeys and allowing exemptions for trusted beneficiary lists, same-account transfers, public transport payments, and corporate clients with robust protocols. The resolution extends penalty provisions to exchange houses, financial services companies, credit administrators, credit granting entities, fund transfer companies, and P2P lending platform administrators, with the new rules entering into force on October 1, 2026, except for specific exemptions effective upon publication.
BCU published 3 documents in the last 30 days — get each new one by email the day it lands.
1
Montevideo, January 28, 2026
Ref: FINANCIAL INTERMEDIATION COMPANIES, CREDIT ADMINISTRATOR COMPANIES, CREDIT GRANTING ENTITIES, FINANCIAL SERVICES COMPANIES, EXCHANGE HOUSES, FUND TRANSFER COMPANIES AND COMPANIES ADMINISTRATING PLATFORMS FOR PERSON-TO-PERSON LOANS - REVIEW OF THE REGULATIONS RELATING TO THE SECURITY OF ELECTRONIC INSTRUMENTS
The market is informed that the Superintendency of Financial Services adopted Resolution SSF N° 2025-744 on December 29, 2025.
2025-50-1-02303
Diagonal Fabini 777 - C.P. 11100 - Tel.: (598 2) 1967 - Montevideo, Uruguay - www.bcu.gub.uy JUAN PEDRO CANTERA Superintendent of Financial Services
CIRCULAR N°2497
SUPERINTENDENCY OF FINANCIAL SERVICES – RESOLUTION SUPERINTENDENCY OF FINANCIAL SERVICES
VIEWING:
Articles 364 and 364.1 of the Compilation of Regulations and Control Norms of the Financial System, referring to the obligations of issuers of electronic instruments and reinforced authentication of clients, respectively.
RESULTING:
I) That, with the objective of protecting users from potential frauds, the 2025 Regulatory Plan included an initiative that entails the review of the regulations relating to the security of electronic instruments, considering the risks associated with them.
II) That the project incorporates minimum requirements that monitoring and control systems must meet in order to detect irregularities linked to the use of the instrument or the environment in which it operates (identification of unusual transactions or those outside the client's usual behavioral patterns, verification of geolocation of said transactions, alerts regarding the use of unknown devices, and identification of suspicious patterns in rejected transactions).
III) That, regarding notifications to the user, it incorporates the obligation to notify via electronic means whenever data such as passwords, personal identification number, address, telephone, contact email, means and parameters established to receive communications and notifications, or any type of operational and/or security parameter, are attempted to be modified.
IV) That, in the matter of reinforced authentication of clients, the project extends the currently valid obligation of issuers to apply a double factor of authentication to transfers or payments to third parties made from a bank account and to loan requests made non-presentially for the following operations:
V) That the project specifies some cases in which institutions may opt not to apply a double factor of authentication:
VI) That the fine for non-compliance with the obligations of issuers of electronic instruments referred to in Article 364, established in Article 690 of the Compilation of Regulations and Control Norms of the System for financial intermediation institutions, is extended to Article 364.1 since both articles contain provisions on the matter.
VII) That the aforementioned normative proposal was put up for consultation with supervised institutions and the general public on August 18, 2025, with the deadline for receiving comments expiring on September 12, 2025.
VIII) That comments were received from: Sistarbank S.R.L, Cooperative of Officials of the Maldonado Municipal Intendancy (CACFIMM), Consortium of Uruguay S.A, Bank of the Oriental Republic of Uruguay (BROU), Visa International Payment Services Spain S.R.L.U, OCA S.A., National Association of Credit Administrator Companies (ANEAC), Consumer Defense Unit of the Ministry of Economy and Finance (UDECO), Paigo, Itaú Bank, and the Association of Private Banks of Uruguay (ABPU).
IX) That the main comments referred to aspects related to monitoring, notifications, reinforced authentication for debit and credit card purchases and for access to the institutions' digital channels, as well as to the proposed validity date of the regulation.
CONSIDERING:
I) That the comments received from the industry provided elements that allowed improving the original proposal, corroborating the value that the consultation process has for the regulator.
II) That, with respect to the monitoring system, the minimum requirements are redefined as orienting elements that must be considered, but are not demanded, and the obligation to evaluate, periodically, the efficacy of the system and to adopt corrective measures in a timely manner is incorporated.
III) That, considering the aforementioned comments, regarding the categories of authentication factors, it will be clarified that usual devices used by the client will be considered as a possession factor, provided they meet the enrollment requirements according to the instructions that will be issued.
IV) That, furthermore, it will be clarified that the use of passkeys will be admitted as a valid mechanism for reinforced authentication of clients, provided that its implementation meets the requirements established in the instructions that will be issued.
V) That the Superintendency of Financial Services will continue to analyze the requirement for reinforced authentication for credit and debit card purchases; therefore, in this instance, this requirement will not be demanded, an aspect that will be resumed in a next stage of the project.
VI) That it has been considered necessary to incorporate that the non-compliance with the obligations referred to in Article 364.1 by exchange houses, financial services companies, credit administrator companies, credit granting entities, fund transfer companies, and companies administering person-to-person lending platforms will be sanctioned according to what is established in Articles 707.3, 712.3, 717.2, and 720.3 of the Compilation of Regulations and Control Norms of the Financial System, respectively, in the same way as has been established for financial intermediation institutions.
VII) That it has been understood reasonable to extend the entry into force date of the proposed normative modifications to October 1, 2026, except for the exceptions established in numerals 1 to 4 of Article 364.1, which may apply from the date of publication of this Resolution in the Official Diary.
ATTENTIVE:
To what is established in literal A) of Article 38 of Law No. 16.696 of March 30, 1995, in the wording given by Article 2 of Law No. 20.345 of September 19, 2024, and in Memorandum MM/2025/00464 of December 18, 2025.
The MR. MANAGER OF THE FINANCIAL INFORMATION AND ANALYSIS UNIT IN EXERCISE OF DELEGATED AND COMMITTED ATTRIBUTES AS SUPERINTENDENT OF FINANCIAL SERVICES RESOLVES:
ARTICLE 364 (OBLIGATIONS OF THE ISSUER). The issuer of the electronic instrument shall:
a. Inform in writing to the user of the electronic instrument, prior to the celebration of the contract, of their obligations and responsibilities in the use of the system, indicating as a minimum those that are applicable among those enumerated in Articles 366 and 367. Such communication must be made in a document distinct from the contract signed by the parties, without prejudice to also being included in it. b. Reveal the personal identification number or another key only to the user.
c. Deliver only those electronic instruments expressly requested by the client, except when it concerns the renewal of an electronic instrument that the client already possessed.
d. Provide the client with elements that allow them to verify the operations carried out, of which at least one must be free of charge for the clients. e. Provide the client with elements that allow them to clearly identify the reason for a rejected operation, except in cases where confidentiality requirements established legally or regulationally must be respected. f. Inform the client about the main risks to which they are exposed when using the electronic instrument to carry out financial transactions, and provide recommendations on how they should adequately protect themselves to mitigate said risks. g. Inform the procedure that the client must follow to effect the notification of theft, robbery, snatching, or loss of the electronic instrument or of any of the circumstances foreseen in literal h) of Article 366, guarantee the existence of adequate means to do so, and prove that such notification has been effected. For these purposes, the issuer (or the institution indicated by him) will provide the user with a number that identifies their report and will indicate the date and time of it. The means to effect the notification must operate every day of the year, during the twenty-four hours. h. Demonstrate, in case of a user claim related to some transaction effected, and without prejudice to any contrary proof that the user may produce, that the transaction:
ARTICLE 364.1 (REINFORCED AUTHENTICATION OF CLIENTS).
The security measures referred to in literal i) of Article 364 must include the application of reinforced authentication mechanisms of clients, as a minimum, for the following operations:
a) Clients' access to the institution's digital channels. b) Transfers or payments made from bank accounts. c) Loan requests made by non-presential means. d) Access, modification, or update of sensitive data, including credentials, personal information, security parameters, or contact means. Reinforced authentication of clients requires the use of at least two authentication factors of different categories (knowledge, possession, and inherence). Devices of trust used by the client will be considered as a possession factor, provided they meet the enrollment requirements detailed in the instructions that will be issued. The use of passkeys will be admitted as a valid mechanism for reinforced authentication of clients, provided that its implementation meets the requirements established in the instructions that will be issued. Likewise, advanced electronic signature provided by providers within the framework of Law No. 18.600 of September 21, 2009, and its modifications and regulationally dispositions, will be admitted as a mechanism of reinforced authentication of clients for loan requests that are made non-presentially. Advanced electronic signature based on certificates issued by providers accredited before the Electronic Certification Unit or that are recognized as equivalent when they have been issued by entities not established in the national territory will be accepted. Institutions may opt not to apply a double factor of authentication in the following cases:
ARTICLE 690.5 (FINE FOR NON-COMPLIANCE WITH THE OBLIGATIONS OF THE ISSUERS OF ELECTRONIC INSTRUMENTS).
Financial intermediation institutions that do not comply with the obligations referred to in Articles 364 and 364.1 will be sanctioned with a fine not lower than 1/10,000 (one by ten thousand) nor higher than 2/1,000 (two by one thousand) of the basic patrimonial responsibility for banks.
ARTICLE 707.3 (FINE FOR NON-COMPLIANCE WITH THE OBLIGATIONS OF ISSUERS OF ELECTRONIC INSTRUMENTS).
Exchange houses and financial service companies that fail to comply with the obligations referred to in Articles 364 and 364.1 shall be sanctioned with a fine not less than 1/10,000 (one ten-thousandth) nor more than 2/1,000 (two thousandths) of the basic patrimonial responsibility for banks.
ARTICLE 712.3 (FINE FOR NON-COMPLIANCE WITH THE OBLIGATIONS OF ISSUERS OF ELECTRONIC INSTRUMENTS).
Credit administration companies and credit granting entities that fail to comply with the obligations referred to in Articles 364 and 364.1 shall be sanctioned with a fine not less than 1/10,000 (one ten-thousandth) nor more than 2/1,000 (two thousandths) of the basic patrimonial responsibility for banks.
ARTICLE 717.2 (FINE FOR NON-COMPLIANCE WITH THE OBLIGATIONS OF ISSUERS OF ELECTRONIC INSTRUMENTS).
Fund transfer companies that fail to comply with the obligations referred to in Articles 364 and 364.1 shall be sanctioned with a fine not less than 1/10,000 (one ten-thousandth) nor more than 2/1,000 (two thousandths) of the basic patrimonial responsibility for banks.
ARTICLE 720.3 (FINE FOR NON-COMPLIANCE WITH THE OBLIGATIONS OF ISSUERS OF ELECTRONIC INSTRUMENTS).
Companies administering peer-to-peer lending platforms that fail to comply with the obligations referred to in Articles 364 and 364.1 shall be sanctioned with a fine not less than 1/10,000 (one ten-thousandth) nor more than 2/1,000 (two thousandths) of the basic patrimonial responsibility for banks.
VALIDITY: The provisions set forth in the preceding items 1 to 6 shall govern from October 1, 2026, except for the exceptions set forth in items 1 to 4 of Article 364.1, which may apply from the date of publication of this Resolution in the Official Gazette.
COMMUNICATE the foregoing by Circular.
RR-SSF-2025-744 Date: 12/29/2025 16:35:11
CIRCULAR NO. 2497
RR-SSF-2025-744 Date: 12/29/2025 16:35:11
Exp. 2025-50-1-02303
Publishable: Yes - Signatory: FERNANDO GUSTAVO FUENTES SOSA CIRCULAR NO. 2497
Read the rest free
Source: Banco Central del Uruguay — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works