2026-08-27 | A 8471

Added · Updated

Fraud Risk Management. Guidelines for Risk Management in Financial Entities. Guidelines for Corporate Governance in Financial Entities. Payment Service Providers. Adjustments

The Guidelines for Risk Management and Corporate Governance in Financial Entities are amended to incorporate fraud risk management frameworks, anti-fraud programs, and specific reporting requirements to the Board and Superintendency. Payment Service Providers offering payment accounts must implement these measures according to a phased schedule between September 2026 and September 2027, culminating in a final report certified by an external auditor. Other registered Payment Service Providers must assign fraud risk management functions and comply with technology and information security risk management provisions effective January 1, 2027.

Banco Central de la Republica Argentina logo

Argentina

Banco Central de la Republica Argentina

Click to view thumbnail

"2026 - YEAR OF THE GRANDEUR OF ARGENTINA" COMMUNICATION "A" 8471 27/08/2026 TO FINANCIAL ENTITIES, TO PAYMENT SERVICE PROVIDERS: Ref.: Circular LISOL 1-1152, RUNOR 1-1968, SINAP 1-252: Fraud Risk Management. Guidelines for Risk Management in Financial Entities. Guidelines for Corporate Governance in Financial Entities. Payment Service Providers. Adjustments.


We write to inform you that this Institution adopted the resolution which, in its pertinent part, establishes: "1 - Incorporate as point 6.5. of the consolidated text on Guidelines for Risk Management in Financial Entities the provisions on fraud risk management contained in the Annex, which forms part of this communication. 2 - Incorporate into the consolidated text on Guidelines for Risk Management in Financial Entities as the second paragraph of point 6.2.1.1. and as point 6.2.2.10., the following: 6.2.1.1. "This framework must contemplate regarding fraud risk: i) the strategy, policies and anti-fraud practices, as well as the methodology for its evaluation; and ii) the specific organizational structure that will develop the fraud risk management function provided for in point 6.5.2. –whether a unit or responsible person– or the assignment of that function to the operational risk unit or responsible person (point 6.2.4.)." "6.2.2.10. It will ensure that the anti-fraud program is implemented in accordance with the strategy, policies and anti-fraud practices approved by the Board, according to what is provided in point 6.5." 3 - Replace in the consolidated text on Guidelines for Risk Management in Financial Entities the last paragraph of point 6.1.2., the first paragraph of point 6.2.1.9., points 6.2.2.6. and 6.2.2.7., and the third paragraph of point 6.3.2., with the following: 6.1.2. Operational risk management.

2- "The framework for operational risk management comprises the policies, practices, procedures and structures that the financial entity has for its adequate management, and must also allow it to evaluate the sufficiency of capital. The framework must cover the appetite and tolerance to operational risk of the entity –which must be established in the policies of management of this risk–, including the degree and the manner in which this risk is transferred outside of the entity. Likewise, it must specifically contemplate the management of fraud risk (internal and external)." "6.2.1.9. Approve and periodically review the definition of appetite and tolerance to operational risk in line with the nature, types and levels of operational risk that the entity financial is willing to assume, and specifically contemplating fraud risk." "6.2.2.6. It will receive reports from the operational risk unit or responsible person, from the unit or person that develops the fraud risk management function –where applicable, according to what is defined according to subsection ii) of point 6.2.1.1.– and, where applicable, from the functional level with decision-making capacity in risk management matters on which those units or persons depend, related to the results of the execution of processes and procedures, the detection of possible deficiencies that occur in the policies, processes and procedures of operational risk management and –in particular– of fraud risk, and the pertinent proposals for their correction. The financial entity will establish the periodicity of the cited reports in accordance with its size, the nature and complexity of its products and processes and with the magnitude of its operations." "6.2.2.7. It will report to the Board, at least semiannually, on the main aspects related to operational risk management. The report to the Board must be at least quarterly in the case of fraud risk management and must include key indicators, relevant incidents, metrics, corrective measures adopted, new fraud methodologies detected and opportunities for improvement, among others." 6.3.2. Monitoring. "The unit in charge or person responsible for operational risk management and, where applicable, the unit or person that develops the fraud risk management function –according to what is defined according to subsection ii) of point 6.2.1.1.– must send to the General Manager –or authority equivalent– or, where applicable, to the functional level with decision-making capacity in matters of risk management on which it depends, with the periodicity that the financial entity establishes in accordance with its size, the nature and complexity of its products and processes and with the magnitude of its operations, reports linked to the results of the monitoring carried out and the pertinent correction proposals in the processes and procedures." 4 - Replace point 4.2.1. of the consolidated text on Guidelines for Corporate Governance in Financial Entities, with the following: "4.2.1. Risk management Committee, which will monitor the activities of Senior Management related to the management of credit, market, liquidity and/or assets and liabilities, operational (including fraud risk), compliance and reputation risks, among others. Likewise, it will advise the Board on the risks of the entity."

3- 5 - Provide that payment service providers that offer payment accounts (PSPCP) shall comply with what is provided in Section 6. of the consolidated text on Guidelines for Risk Management in Financial Entities in relation to the PSPCP function for which they have registered with the Central Bank of the Republic of Argentina. The implementation of such provisions must be carried out in a manner proportional to their size and to the complexity of their operations, adequate to their risk profile, and based on the criticality of the products and channels, exposure to mass fraud, characteristics of the customer base and the degree of digitalization, among other aspects. Consequently, its implementation must be adapted to the organization and business model of each PSPCP, in order to manage operational risk effectively and, in particular, fraud risk. This measure will enter into force according to the following implementation schedule: (a) From 01/09/26 to 31/12/26: establishment of the operational risk management framework (including fraud risk prevention) –definition of structure, strategies, policies and anti-fraud practices–, roles and responsibilities; designation of responsible person/s; definition of risk appetite and tolerance; preliminary identification of operational and fraud risks associated with products, services, processes and digital channels; identification of critical processes. (b) From 01/01/27 to 31/05/27: definition and documentation of processes and procedures for the identification, evaluation, monitoring, control and mitigation of operational and fraud risks in critical processes. (c) From 01/06/27 to 31/08/27: self-assessment of full compliance with what is required by Section 6. of the consolidated text on Guidelines for Risk Management in Financial Entities and submission of the final report. (d) From 01/09/27: full validity. PSPCPs must send to the Superintendency of Financial and Exchange Entities a report on compliance with the implementation schedule for each of the first two stages, which demonstrates compliance with the requirements of each one. At the end of the third stage, they must submit a final report signed by the highest authority of the PSPCP that includes a special report by an external auditor certifying full compliance with what is required by Section 6. of the consolidated text on Guidelines for Risk Management in Financial Entities. 6 - Provide, effective as of 01/01/27, that other payment service providers registered and/or authorized by the Central Bank of the Republic of Argentina –not contemplated in point 5 of this communication– must: a) assign the fraud risk management function to a unit or responsible person and comply with what is provided in point 6.5.2. of the consolidated text on Guidelines for Risk Management in Financial Entities; b) carry out a self-assessment of fraud risk taking into consideration what is indicated in subsection i) of point 6.3.1.2. of that ordering; c) develop a plan for fraud risk mitigation; and

4- d) comply with what is established in point 6.4. of that consolidated text relative to the management of technology and information security risks. 7 - Establish that points 1 to 4 of this communication will be effective as of 01/12/26." Likewise, we inform you that subsequently we will send you the sheets which, in replacement of those timely provided, will correspond to incorporate into the consolidated texts of the reference. We greet you attentively. CENTRAL BANK OF THE REPUBLIC OF ARGENTINA Darío C. Stefanelli Marina Ongaro Principal Manager of Issuance and Regulatory Applications Deputy General Manager of Financial Regulation ANNEX

-1- 6.5. Fraud risk management. Financial entities must have a comprehensive, effective and sustainable process of management of internal and external fraud risk within the operational risk management framework, which allows minimizing the probability and impact of fraud events, protecting customers and the organization. The operational risk management process provided for in point 6.3. must contemplate specifically the management of fraud risk (internal and external) throughout all stages described (identification and evaluation, monitoring, control and mitigation –which includes change management and outsourcing risk–). Its implementation must be proportional to the dimensions of the entity and to the complexity of its operations, adequate to its risk profile, and based on the criticality of the products and channels, exposure to mass fraud, characteristics of the customer base and the degree of digitalization, among other aspects. It must be considered that certain modalities of internal or external fraud can materialize through cyber incidents. 6.5.1. Anti-fraud Program. Entities must have a duly documented anti-fraud program, conceived as a dynamic process that integrates the instances of prevention, detection, response, resolution and organizational learning. It must contain the detail of the procedures necessary for its implementation and the assignment of human, technological and financial resources required. The anti-fraud program must include at minimum: 6.5.1.1. Coordination between whoever develops the fraud risk management function –point 6.5.2.– and the regulatory compliance, legal areas, those with competencies in cybersecurity, money laundering, financing of terrorism and the proliferation of weapons of mass destruction, and other areas with functions linked to the prevention, detection, response and reporting of activities associated with fraud events. 6.5.1.2. The definition and documentation of fraud detection procedures (monitoring), based on technological solutions, with a comprehensive view that uses the available information and allows strengthening the timely identification of warning signals and preventing the development of illicit activities in accordance with applicable regulations. 6.5.1.3. The determination of reporting channels and response mechanisms to fraud. 6.5.1.4. The definition of clear action protocols before fraud incidents, including investigation, documentation, resolution and internal and external communication. B.C.R.A. GUIDELINES FOR RISK MANAGEMENT IN FINANCIAL ENTITIES Annex to the Com. "A" 8471

-2- 6.5.1.5. Specific training for personnel, according to each level of exposure to fraud risk. 6.5.1.6. Its review and update, at least annually and whenever relevant changes are identified in the fraud risk profile, in applicable regulations or after the occurrence of significant incidents. Any definition or update of anti-fraud policies and procedures must have the intervention of the internal audit or equivalent instance, prior to its elevation for approval of the Board. 6.5.2. Fraud risk management function. The fraud risk management function will be fully developed by a specific organizational structure –whether a unit or responsible person–, or by the unit of operational risk or responsible person (point 6.2.4.), according to the criterion provided in the third paragraph of point 6.5. This function must contemplate the characteristics described in points 6.2.4.2. to 6.2.4.5. and 6.2.4.8. The unit or person in charge of this function must: 6.5.2.1. Elaborate and implement the anti-fraud program, within the framework of the strategy, policies and anti-fraud practices approved by the Board. 6.5.2.2. Implement effective management of fraud risk through its identification, evaluation, monitoring, control and mitigation, according to what is provided in point 6.3. and the documented methodology for fraud risk evaluation. This, in order to determine fraud risk and establish prevention, detection and response measures. 6.5.2.3. Implement and maintain a fraud response plan, which allows employees, customers and third parties to report facts or presumed irregularities related to frauds through multiple channels. 6.5.2.4. Adopt mechanisms that ensure communication, interaction and coordination effective with those responsible for other areas, promoting a vision integral and transversal of fraud risk throughout the organization. 6.5.2.5. Implement periodic internal trainings oriented to prevention, detection and response to fraud and to awareness raising about the obligation of personnel to communicate timely any suspicion of fraudulent activity internal or external. 6.5.2.6. Promote awareness about fraud among the entity's customers, providing adequate and timely educational information, with the objective of fostering a clear understanding of the associated risks. 6.5.2.7. Act as a liaison before external bodies, coordinating the interventions that must be processed in matters linked to the subject. 6.5.2.8. Communicate by note to SEFYC, according to the procedure that is determined, any new typology or modality of fraud that is identified in the development of its activities.

-3- 6.5.2.9. Implement and maintain a single, centralized and systematized database destined to the integral management of complaints and reports of facts or presumed irregularities related to fraud (external and internal) and the responses given, which allows its easy traceability and that functions as a repository for the conservation of relevant information (such as amounts recognized to the customer). When applicable, fraud incidents will be integrated into the records provided for in the Operational Risk Events Database and in the regulations of Protection of Users of Financial Services, in a segregated manner as fraud. 6.5.2.10. Implement the necessary mechanisms to report and consult the Fraud Prevention Center (CPF) provided for by specific regulations.

More like this from BCRA

BCRA published 10 documents in the last 30 days. We email you each new one the day it's published.

Share