2026-01-28

Added · Updated

Financial Intermediation Companies, Credit Administrators, Credit Granting Entities, Financial Services Companies, Exchange Houses, Fund Transfer Companies, and P2P Lending Platform Administrators - Review of Regulations on Electronic Instrument Security

Resolution SSF N° 2025-744 amends Articles 364 and 364.1 of the Financial System Regulatory and Control Compilation to impose new security obligations on issuers of electronic instruments, including mandatory electronic notifications for data modification attempts and the adoption of periodic monitoring system efficacy evaluations. It extends the requirement for reinforced client authentication (two-factor) to digital channel access, non-presential loan requests, and sensitive data updates, while explicitly permitting passkeys and allowing exemptions for trusted beneficiary lists, same-account transfers, public transport payments, and corporate clients with robust protocols. The resolution extends penalty provisions to exchange houses, financial services companies, credit administrators, credit granting entities, fund transfer companies, and P2P lending platform administrators, with the new rules entering into force on October 1, 2026, except for specific exemptions effective upon publication.

Banco Central del Uruguay logo

Uruguay

Banco Central del Uruguay

Click to view thumbnail

1 Montevideo, January 28, 2026 Ref: FINANCIAL INTERMEDIATION COMPANIES, CREDIT ADMINISTRATOR COMPANIES, CREDIT GRANTING ENTITIES, FINANCIAL SERVICES COMPANIES, EXCHANGE HOUSES, FUND TRANSFER COMPANIES AND COMPANIES ADMINISTRATING PLATFORMS FOR PERSON-TO-PERSON LOANS - REVIEW OF THE REGULATIONS RELATING TO THE SECURITY OF ELECTRONIC INSTRUMENTS

The market is informed that the Superintendency of Financial Services adopted Resolution SSF N° 2025-744 on December 29, 2025.

2025-50-1-02303 Diagonal Fabini 777 - C.P. 11100 - Tel.: (598 2) 1967 - Montevideo, Uruguay - www.bcu.gub.uy JUAN PEDRO CANTERA Superintendent of Financial Services

CIRCULAR N°2497

SUPERINTENDENCY OF FINANCIAL SERVICES – RESOLUTION SUPERINTENDENCY OF FINANCIAL SERVICES

VIEWING: Articles 364 and 364.1 of the Compilation of Regulations and Control Norms of the Financial System, referring to the obligations of issuers of electronic instruments and reinforced authentication of clients, respectively.

RESULTING: I) That, with the objective of protecting users from potential frauds, the 2025 Regulatory Plan included an initiative that entails the review of the regulations relating to the security of electronic instruments, considering the risks associated with them.

II) That the project incorporates minimum requirements that monitoring and control systems must meet in order to detect irregularities linked to the use of the instrument or the environment in which it operates (identification of unusual transactions or those outside the client's usual behavioral patterns, verification of geolocation of said transactions, alerts regarding the use of unknown devices, and identification of suspicious patterns in rejected transactions).

III) That, regarding notifications to the user, it incorporates the obligation to notify via electronic means whenever data such as passwords, personal identification number, address, telephone, contact email, means and parameters established to receive communications and notifications, or any type of operational and/or security parameter, are attempted to be modified.

IV) That, in the matter of reinforced authentication of clients, the project extends the currently valid obligation of issuers to apply a double factor of authentication to transfers or payments to third parties made from a bank account and to loan requests made non-presentially for the following operations:

  • Clients' access to the institution's digital channels.
  • Credit and debit card purchases made non-presentially.
  • Access, modification, or update of sensitive data, including credentials, personal information, security parameters, or contact means.

V) That the project specifies some cases in which institutions may opt not to apply a double factor of authentication:

  • Transfers or payments to third parties assigned to a trusted beneficiary list.
  • Transfers in which the orderer and the beneficiary are the same person and both accounts are maintained at the same institution.
  • Toll and public transport payments.
  • Payments made by clients that are legal entities through the use of processes and/or protocols that guarantee robust mechanisms of authentication, authorization, and security, at the discretion of the Superintendency of Financial Services.

VI) That the fine for non-compliance with the obligations of issuers of electronic instruments referred to in Article 364, established in Article 690 of the Compilation of Regulations and Control Norms of the System for financial intermediation institutions, is extended to Article 364.1 since both articles contain provisions on the matter.

VII) That the aforementioned normative proposal was put up for consultation with supervised institutions and the general public on August 18, 2025, with the deadline for receiving comments expiring on September 12, 2025.

VIII) That comments were received from: Sistarbank S.R.L, Cooperative of Officials of the Maldonado Municipal Intendancy (CACFIMM), Consortium of Uruguay S.A, Bank of the Oriental Republic of Uruguay (BROU), Visa International Payment Services Spain S.R.L.U, OCA S.A., National Association of Credit Administrator Companies (ANEAC), Consumer Defense Unit of the Ministry of Economy and Finance (UDECO), Paigo, Itaú Bank, and the Association of Private Banks of Uruguay (ABPU).

IX) That the main comments referred to aspects related to monitoring, notifications, reinforced authentication for debit and credit card purchases and for access to the institutions' digital channels, as well as to the proposed validity date of the regulation.

CONSIDERING: I) That the comments received from the industry provided elements that allowed improving the original proposal, corroborating the value that the consultation process has for the regulator.

II) That, with respect to the monitoring system, the minimum requirements are redefined as orienting elements that must be considered, but are not demanded, and the obligation to evaluate, periodically, the efficacy of the system and to adopt corrective measures in a timely manner is incorporated.

III) That, considering the aforementioned comments, regarding the categories of authentication factors, it will be clarified that usual devices used by the client will be considered as a possession factor, provided they meet the enrollment requirements according to the instructions that will be issued.

IV) That, furthermore, it will be clarified that the use of passkeys will be admitted as a valid mechanism for reinforced authentication of clients, provided that its implementation meets the requirements established in the instructions that will be issued.

V) That the Superintendency of Financial Services will continue to analyze the requirement for reinforced authentication for credit and debit card purchases; therefore, in this instance, this requirement will not be demanded, an aspect that will be resumed in a next stage of the project.

VI) That it has been considered necessary to incorporate that the non-compliance with the obligations referred to in Article 364.1 by exchange houses, financial services companies, credit administrator companies, credit granting entities, fund transfer companies, and companies administering person-to-person lending platforms will be sanctioned according to what is established in Articles 707.3, 712.3, 717.2, and 720.3 of the Compilation of Regulations and Control Norms of the Financial System, respectively, in the same way as has been established for financial intermediation institutions.

VII) That it has been understood reasonable to extend the entry into force date of the proposed normative modifications to October 1, 2026, except for the exceptions established in numerals 1 to 4 of Article 364.1, which may apply from the date of publication of this Resolution in the Official Diary.

ATTENTIVE: To what is established in literal A) of Article 38 of Law No. 16.696 of March 30, 1995, in the wording given by Article 2 of Law No. 20.345 of September 19, 2024, and in Memorandum MM/2025/00464 of December 18, 2025.

The MR. MANAGER OF THE FINANCIAL INFORMATION AND ANALYSIS UNIT IN EXERCISE OF DELEGATED AND COMMITTED ATTRIBUTES AS SUPERINTENDENT OF FINANCIAL SERVICES RESOLVES:

  1. SUBSTITUTE in Title II – Electronic Instruments, of Book IV – Protection of the user of financial services of the Compilation of Regulations and Control Norms of the Financial System, Articles 364 and 364.1 with the following:

ARTICLE 364 (OBLIGATIONS OF THE ISSUER). The issuer of the electronic instrument shall: a. Inform in writing to the user of the electronic instrument, prior to the celebration of the contract, of their obligations and responsibilities in the use of the system, indicating as a minimum those that are applicable among those enumerated in Articles 366 and 367. Such communication must be made in a document distinct from the contract signed by the parties, without prejudice to also being included in it. b. Reveal the personal identification number or another key only to the user. c. Deliver only those electronic instruments expressly requested by the client, except when it concerns the renewal of an electronic instrument that the client already possessed. d. Provide the client with elements that allow them to verify the operations carried out, of which at least one must be free of charge for the clients. e. Provide the client with elements that allow them to clearly identify the reason for a rejected operation, except in cases where confidentiality requirements established legally or regulationally must be respected. f. Inform the client about the main risks to which they are exposed when using the electronic instrument to carry out financial transactions, and provide recommendations on how they should adequately protect themselves to mitigate said risks. g. Inform the procedure that the client must follow to effect the notification of theft, robbery, snatching, or loss of the electronic instrument or of any of the circumstances foreseen in literal h) of Article 366, guarantee the existence of adequate means to do so, and prove that such notification has been effected. For these purposes, the issuer (or the institution indicated by him) will provide the user with a number that identifies their report and will indicate the date and time of it. The means to effect the notification must operate every day of the year, during the twenty-four hours. h. Demonstrate, in case of a user claim related to some transaction effected, and without prejudice to any contrary proof that the user may produce, that the transaction: • has been effected according to the procedures agreed with the client; • has been registered and accounted for correctly; • has not been affected by a technical failure or by any other anomaly; and • has been correctly authenticated according to the methodology established for it, also making available to the user - regardless of whether the instrument was used in the country or abroad - the safeguarded information indicated in literal i) and any other element that allows demonstrating that said transaction was carried out by the client or by third parties with the client's knowledge. In case of not being able to demonstrate it, the issuer will be responsible for the claimed transaction, provided that it is not attributable to non-compliance with the user's obligations. For the purposes of complying with this obligation, the conditions of the contracts that the issuer may have signed with third parties will not be opposable. i. Establish measures that allow reasonably guaranteeing the security of the environment in which the instrument operates, which include authentication methodologies associated with the risks of the different types of transactions and access levels to ensure that operations are carried out by authorized persons, considering, when appropriate, what is established in Article 364.1. It must be safeguarded, as a minimum: • dates and times of the operations; • contents of the messages; • identification of operators, issuers, and receivers; • accounts and amounts involved; • user authentication mechanism used in the operation; • identification of the terminal from which the operation was performed; and • whether the operation was performed presentially or remotely. j. Establish a monitoring and control system that allows detecting irregularities linked to the use of the instrument or the environment in which it operates, including changes and attempts to change passwords, personal identification number, address, telephone, and contact email, as well as other means established to receive communications, among others. Said system must contemplate, among other aspects, elements that allow: • identifying unusual transactions or those outside the client's usual behavioral patterns (for example: amounts significantly higher than usual; quantity and frequency of transactions higher than the normal usage pattern). • verifying the geolocation from where the transactions are made (for example: absence of travel declaration; purchases made from different countries in a short period of time, among others, etc.). • alerting about the use of unknown devices and, in that case, reinforcing authentication. • identifying suspicious patterns in rejected transactions (amounts, origin, frequency/sequence, etc.). Issuers must define the expected efficacy criteria of the monitoring system, including the necessary parameters and methodologies to evaluate its capacity to detect irregular or potentially fraudulent operations. The efficacy of the system must be evaluated periodically, at least once a year, and in case deviations from the established objectives are verified, the institution must adopt in a timely manner the necessary corrective measures to ensure its adequate functioning. k. Ensure the correct functioning of the system, and the continuous provision of the service, under normal circumstances. l. Annul from the system the electronic instruments on the day they lose validity (by expiration or by decision of the parties according to the terms of the contract). m. Determine the means and forms by which the institution can communicate with the client. It must indicate, if applicable, that it will never ask them to reveal their personal identification keys under any circumstance or by any means. The user shall declare – as a minimum – two contact addresses (address, telephone, email, among others) for the purposes of receiving communications, notifications, or notices related to the electronic instrument, and the issuer must establish measures that reasonably guarantee the veracity of the information provided. These measures must be established at the time of the celebration of the contract and whenever the modification of said data is requested. In the case of clients who have only one contact address, when its modification is requested, the institution must obtain another address for the purposes of complying with what is established in literal m). n. Communicate to the user the commission of any illicit or irregular fact linked to the electronic instrument of their ownership upon detecting or taking knowledge of it. Likewise, it must communicate to them any attempt or request to modify the data referred to in literal i), indicating the received modification request. When it concerns the client's contact information, the communication must be directed, as a minimum, to two of the previously valid contact addresses and must indicate the procedure to follow to validate or reject the requested change. Once the modification is made, such fact must be communicated to the user. o. Offer the user the possibility of receiving notifications via electronic means (email, instant messaging, SMS, notification in their own application, among others) every time a transaction linked to the electronic instrument of their ownership is processed, which must indicate the available means to make inquiries or claims linked to the transaction. At least one of said electronic means must be free of charge. The user may modify the parameters of these notifications or decide not to receive them. In the latter case, the issuer must keep a record of the client's informed decision not to receive said notifications by means that allow their verification, according to what is established by Article 496. Likewise, institutions must notify the user via electronic means every time data such as passwords, personal identification number, address, telephone, contact email, means and parameters established to receive communications and notifications, or any type of operational and/or security parameter, are attempted to be modified.

ARTICLE 364.1 (REINFORCED AUTHENTICATION OF CLIENTS). The security measures referred to in literal i) of Article 364 must include the application of reinforced authentication mechanisms of clients, as a minimum, for the following operations: a) Clients' access to the institution's digital channels. b) Transfers or payments made from bank accounts. c) Loan requests made by non-presential means. d) Access, modification, or update of sensitive data, including credentials, personal information, security parameters, or contact means. Reinforced authentication of clients requires the use of at least two authentication factors of different categories (knowledge, possession, and inherence). Devices of trust used by the client will be considered as a possession factor, provided they meet the enrollment requirements detailed in the instructions that will be issued. The use of passkeys will be admitted as a valid mechanism for reinforced authentication of clients, provided that its implementation meets the requirements established in the instructions that will be issued. Likewise, advanced electronic signature provided by providers within the framework of Law No. 18.600 of September 21, 2009, and its modifications and regulationally dispositions, will be admitted as a mechanism of reinforced authentication of clients for loan requests that are made non-presentially. Advanced electronic signature based on certificates issued by providers accredited before the Electronic Certification Unit or that are recognized as equivalent when they have been issued by entities not established in the national territory will be accepted. Institutions may opt not to apply a double factor of authentication in the following cases:

  1. Transfers or payments to third parties assigned to a trusted beneficiary list. The creation and update of said list requires the application of the double factor of authentication.

  2. Transfers in which the orderer and the beneficiary are the same person and both accounts are maintained at the same institution.

  3. Toll and public transport payments.

  4. Payments made by clients that are legal entities through the use of processes and/or protocols that guarantee robust mechanisms of authentication, authorization, and security, at the discretion of the Superintendency of Financial Services. These mechanisms must consider at least the following aspects, as applicable to the operational modality implemented: • Centralized user management, in which each user accessing the platform used has been created and managed through, at least, two Security Administrators formally authorized to such effects by the client. • Reinforced authentication through multiple factors when accessing the platform. • Transaction approval flow according to risk levels and considering the principle of separation of duties. • Session control with automatic disconnection by inactivity and by multiple sessions. • Active monitoring of behavioral patterns and fraud prevention that provides notifications to the designated Security Administrators in case of unusual or suspicious behaviors. • In the case of the use of "host to host" connectivity systems, secure connectivity mechanisms must be established for the transmission of intact data between the institution and its corporate clients. Said mechanisms must include, as a minimum, end-to-end data encryption; robust mutual authentication methods; centralized activity logging; intrusion detection and network security systems designed to monitor, filter, and control incoming and outgoing network traffic based on predetermined security rules; validation of input and output data of requests between each host; adequate vulnerability management; and updated and versioned documentation of the interfaces involved in the connections.

  5. SUBSTITUTE in Title VI – Other Sanctions, of Part I – Sanctions for financial intermediation institutions, of Book VII – Sanctioning and Procedural Regime of the Compilation of Regulations and Control Norms of the Financial System, Article 690.5 with the following:

ARTICLE 690.5 (FINE FOR NON-COMPLIANCE WITH THE OBLIGATIONS OF THE ISSUERS OF ELECTRONIC INSTRUMENTS). Financial intermediation institutions that do not comply with the obligations referred to in Articles 364 and 364.1 will be sanctioned with a fine not lower than 1/10,000 (one by ten thousand) nor higher than 2/1,000 (two by one thousand) of the basic patrimonial responsibility for banks.

  1. SUBSTITUTE in Title V – Other Sanctions, of Part II – Sanctions for exchange houses and financial service companies, of Book VII – Sanctioning and Procedural Regime of the Compilation of Regulations and Control of the Financial System, Article 707.3 with the following:

ARTICLE 707.3 (FINE FOR NON-COMPLIANCE WITH THE OBLIGATIONS OF ISSUERS OF ELECTRONIC INSTRUMENTS).

Exchange houses and financial service companies that fail to comply with the obligations referred to in Articles 364 and 364.1 shall be sanctioned with a fine not less than 1/10,000 (one ten-thousandth) nor more than 2/1,000 (two thousandths) of the basic patrimonial responsibility for banks.

  1. SUBSTITUTE in Part III – Sanctions for credit administration companies and credit granting entities, of Book VII – Sanctioning and Procedural Regime of the Compilation of Regulations and Control of the Financial System, Article 712.3 with the following:

ARTICLE 712.3 (FINE FOR NON-COMPLIANCE WITH THE OBLIGATIONS OF ISSUERS OF ELECTRONIC INSTRUMENTS).

Credit administration companies and credit granting entities that fail to comply with the obligations referred to in Articles 364 and 364.1 shall be sanctioned with a fine not less than 1/10,000 (one ten-thousandth) nor more than 2/1,000 (two thousandths) of the basic patrimonial responsibility for banks.

  1. SUBSTITUTE in Part V – Sanctions for fund transfer companies, value transport companies, and companies providing leasing and safe deposit box custody services, of Book VII – Sanctioning and Procedural Regime of the Compilation of Regulations and Control of the Financial System, Article 717.2 with the following:

ARTICLE 717.2 (FINE FOR NON-COMPLIANCE WITH THE OBLIGATIONS OF ISSUERS OF ELECTRONIC INSTRUMENTS).

Fund transfer companies that fail to comply with the obligations referred to in Articles 364 and 364.1 shall be sanctioned with a fine not less than 1/10,000 (one ten-thousandth) nor more than 2/1,000 (two thousandths) of the basic patrimonial responsibility for banks.

  1. SUBSTITUTE in Part VI – Sanctions for providers of administration, accounting, or data processing services and companies administering peer-to-peer lending platforms, of Book VII – Sanctioning and Procedural Regime of the Compilation of Regulations and Control of the Financial System, Article 720.3 with the following:

ARTICLE 720.3 (FINE FOR NON-COMPLIANCE WITH THE OBLIGATIONS OF ISSUERS OF ELECTRONIC INSTRUMENTS).

Companies administering peer-to-peer lending platforms that fail to comply with the obligations referred to in Articles 364 and 364.1 shall be sanctioned with a fine not less than 1/10,000 (one ten-thousandth) nor more than 2/1,000 (two thousandths) of the basic patrimonial responsibility for banks.

  1. VALIDITY: The provisions set forth in the preceding items 1 to 6 shall govern from October 1, 2026, except for the exceptions set forth in items 1 to 4 of Article 364.1, which may apply from the date of publication of this Resolution in the Official Gazette.

  2. COMMUNICATE the foregoing by Circular.

RR-SSF-2025-744 Date: 12/29/2025 16:35:11 CIRCULAR NO. 2497

RR-SSF-2025-744 Date: 12/29/2025 16:35:11 Exp. 2025-50-1-02303 Publishable: Yes - Signatory: FERNANDO GUSTAVO FUENTES SOSA CIRCULAR NO. 2497

More like this from BCU

We email you every new BCU publication the day it's published.

Share