2026-01-28
Added · Updated
Resolution SSF N° 2025-744 amends Articles 364 and 364.1 of the Financial System Regulatory and Control Compilation to impose new security obligations on issuers of electronic instruments, including mandatory electronic notifications for data modification attempts and the adoption of periodic monitoring system efficacy evaluations. It extends the requirement for reinforced client authentication (two-factor) to digital channel access, non-presential loan requests, and sensitive data updates, while explicitly permitting passkeys and allowing exemptions for trusted beneficiary lists, same-account transfers, public transport payments, and corporate clients with robust protocols. The resolution extends penalty provisions to exchange houses, financial services companies, credit administrators, credit granting entities, fund transfer companies, and P2P lending platform administrators, with the new rules entering into force on October 1, 2026, except for specific exemptions effective upon publication.