2022-09-15 | Instrução Normativa BCB 305Added · Updated
Participating institutions must comply with the mandatory Open Finance Security Manual v4.0, effective October 1, 2022, replacing Instruction No. 134. Obligations include maintaining governance processes, segregating networks, enforcing TLS 1.2+ with PFS, and using ICP-Brasil certificates. Institutions must implement vulnerability analysis, patch management, and multi-factor authentication for remote access. Audit trails and incident response plans are required, with mandatory sharing of compromise details with the Structure Responsible for the Governance of Open Finance.
BCB published 19 documents in the last 30 days — get each new one by email the day it lands.
NORMATIVE INSTRUCTION BCB NO. 305, OF SEPTEMBER 15, 2022
Regulatory document revoked by Normative Instruction BCB No. 720, of 4/2/2026.
Publishes version 4.0 of the Open Finance Security Manual.
The Heads of the Financial System Regulation Department (Denor) and the Information Technology Department (Deinf), in the exercise of the powers conferred upon them by arts. 23, item I, letter "a", 62, item IV, and 116, item I, letter "b", of the Internal Regulations of the Central Bank of Brazil, annexed to Ordinance No. 84.287, of February 27, 2015, based on art. 3, item IV, of BCB Resolution No. 32, of October 29, 2020,
R E S O L V E:
Art. 1. This Normative Instruction publishes version 4.0 of the Open Finance Security Manual, which is mandatory for participating institutions, as per the Annex.
Sole Paragraph. The manual referred to in the caput, in its most recent version, will be accessible on the Open Finance page on the Central Bank of Brazil's internet website and on the Open Finance Portal of Brazil, maintained by the Structure Responsible for the Governance of Open Finance referred to in art. 44, § 1, of Joint Resolution No. 1, of May 4, 2020.
Art. 2. Normative Instruction BCB No. 134, of July 22, 2021, is hereby revoked.
Art. 3. This Normative Instruction enters into force on October 1, 2022.
João André Calvino Marques Pereira Haroldo Jayme Martins Froes Cruz Head of the Regulation Department Head of the Technology of the Financial System Department
ANNEX TO NORMATIVE INSTRUCTION BCB NO. 305, OF SEPTEMBER 15, 2022
Open Finance Security Manual Version 4.0
Revision History
| Date | Version | Description of changes |
| 15/09/2022 | 4.0 | Improvements in the wording of the text, without alteration of merit. |
| Change of nomenclature from Open Banking to Open Finance. | ||
| Update of references. | ||
| Change of item 3.9, with the restriction of the scope of its application. | ||
| Change of item 3.12, providing for the certificates required for partnership contracts. |
Terms of Use
This manual details the technical requirements for the implementation of the elements necessary for the operationalization of Open Finance, complementing the current regulation on the subject.
The manual will be reviewed and updated periodically in order to preserve compatibility with the regulation, as well as to incorporate improvements resulting from the evolution of Open Finance and technology.
More detailed information and examples of the application of this manual can be found in the guides and tutorials available on the Open Finance Portal in Brazil, in the Developer Area.
Suggestions, criticisms, or requests for clarification of doubts regarding the content of this document may be sent to the Central Bank of Brazil through the institutional channels of this autonomous entity.
References
These specifications are based on, reference, and complement, when applicable, the following documents:
1. Introduction
This manual details in operational terms the security guidelines established by Joint Resolution No. 1, of May 4, 2020, and by BCB Resolution No. 32, of October 29, 2020. It contains both the mandatory minimum security requirements for participating institutions and for the other elements that make up the Structure Responsible for the Governance of Open Finance.
To ensure the security of Open Finance in the Country, the current regulation establishes the obligation to comply with a series of measures, including those described in this manual.
Regarding the mandatory requirements for participating institutions, this manual presents the following sections: 2. governance, 3. protection, 4. detection, and 5. reaction. The mandatory requirements for the Structure Responsible for the Governance are contained in Section 6.
This manual prescribes the minimum security requirements necessary for:
I - the sharing of data on service channels and products and services referred to in art. 5, item I, letters "a" and "b", items 1 to 5, of Joint Resolution No. 1, of 2020;
II - the sharing of registration and transaction data referred to in art. 5, item I, letters "c" and "d", items 1 to 5, of Joint Resolution No. 1, of 2020; and
III - the sharing of the payment transaction initiation service related to the Pix arrangement, referred to in arts. 5, item II, letter "a", of Joint Resolution No. 1, of 2020, and 6, item IV, of Circular No. 4.015, of May 4, 2020.
As Open Finance covers the sharing of other data and services, new security requirements may be added to this manual, in addition to the applicable regulation.
Throughout this document, the use of acronyms to designate some common expressions of information security professionals will be constant. Some examples of the most frequently used, with the corresponding definitions, are as follows:
I - ACL: Access Control List;
II - API: Application Programming Interface;
III - ETIR: Incident Handling Team;
IV - HTTP: HyperText Transfer Protocol;
V - ICP-Brasil: Brazilian Public Key Infrastructure;
VI - IP: Internet Protocol;
VII - NTP: Network Time Protocol;
VIII - PFS: Perfect Forward Secrecy;
IX - PGP: Pretty Good Privacy;
X - TCP: Transmission Control Protocol;
XI - TLS: Transport Layer Security;
XII - URI: Uniform Resource Identifier; and
XIII - UTC: Universal Time Coordinated.
2. Governance
2.1 Participating institutions in Open Finance must adopt processes to monitor the publication and entry into force of normative acts with an impact on the subject, in order to remain permanently updated with regulatory determinations.
2.2 The list of normative acts whose observance is essential by participating institutions in Open Finance includes, non-exhaustively:
I - Joint CMN/BCB Resolution No. 1, of 2020;
II - Resolutions issued by the Monetary National Council (CMN) and norms issued by the Central Bank of Brazil applicable to participating institutions, including those that provide for the cybersecurity policy and requirements for contracting data processing and storage and cloud computing services; and
III - the General Law on the Protection of Personal Data (LGPD – Law No. 13.709, of 2018).
2.3 The incident response action plan of participating institutions must cover the procedures and controls to be used in the prevention and response to incidents affecting systems, APIs, and other resources related to the implementation and operation of Open Finance, in a manner compatible with the institution's cybersecurity policy and current regulation.
2.4 Participating institutions must define procedures and controls aimed at the prevention and handling of incidents to be adopted by third-party service providers that handle data or information required for the conduct of activities related to Open Finance, in compatibility with the policy referred to in item 2.3 and with current regulation.
2.5 The procedures and controls referred to in item 2.4 must be disclosed to service providers in clear, accessible language and at a level of detail compatible with the functions performed and the sensitivity of the information.
2.6 Participating institutions, prior to contracting services required for the conduct of activities related to Open Finance, must adopt procedures that include verifying the potential service provider's capacity to ensure compliance with current legislation and regulation.
2.7 Institutions must store and process the data specified during the consent stage according to the purpose for which they were shared and in a secure manner, observing current legislation and regulation.
2.8 Participating institutions must keep their registration information permanently updated in the Open Finance Participants Directory, observing current regulation.
3. Protection
3.1 Access to data and the payment transaction initiation service within the scope of Open Finance must be carried out exclusively through APIs.
3.2 Systems and APIs related to Open Finance must be maintained on an internal network logically segregated from networks ordinarily used by workstations or wireless networks.
3.3 Data-transmitting institutions and account-holding institutions must implement inbound and outbound traffic controls, in order to allow only what is necessary for communication with Open Finance APIs.
3.4 Institutions must implement encryption in communication with publicly exposed Open Finance APIs, using the TLS protocol version 1.2 or higher, using cipher suites that meet the perfect forward secrecy (PFS) requirement.
3.5 "TLS Session Resumption" and "TLS Renegotiation" functionalities must be disabled.
3.6 Institutions must apply security controls at the application layer that allow for the inspection of threats and the blocking of code injection attacks, among others, appropriate to the technologies used in the APIs.
3.7 Institutions must not expose the data repositories used in Open Finance directly to the internet.
3.8 Participating institutions must verify and ensure that the quantity, order, format, size, and content of the fields of access requests to the APIs, as well as their responses, are in accordance with the Open Finance definitions.
3.9 For signing messages and secure communication with APIs used for the sharing of customer registration and transaction data and the payment transaction initiation service related to the Pix arrangement, valid digital certificates issued by a certifying authority participating in ICP-Brasil must be used, in accordance with the digital certification standards established by the Structure Responsible for the Governance of Open Finance.
3.10 The digital certificates referred to in item 3.9 must include mechanisms for the protection of communication channels and for the signing or encryption of messages exchanged with APIs.
3.11 The use of digital certificates issued by the service of the Directory of the Structure Responsible for the Governance of Open Finance is admitted for use in the API testing environment referred to in art. 12, item IV of BCB Resolution No. 32, of 2020.
3.12 The certificates required for partnership contracts must observe current legislation and regulation and, where applicable, follow the digital certificate standards defined by the Structure Responsible for the Governance of Open Finance. The standards referred to in this item must include the certificate formatting, cryptographic algorithms, and attributes established.
3.13 For the establishment of TLS connections of calls to confidential endpoints, the following algorithms must be used:
I - ‘TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256’; and
II - ‘TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384’.
3.14 The certificates used for communication of Front-End systems, accessed directly by customers of participating institutions, especially to perform authentication, must be of the Extended Validation (EV) type and may be issued by a functioning certifying authority.
3.15 Procedures and controls related to encryption must include secure means of storage, transfer, use, and destruction of secrets or keys used within the scope of Open Finance, observing current regulation.
3.16 It is recommended to use the following cryptographic algorithms for the protection and storage of secrets within the scope of Open Finance:
I - ‘AES-256bits’ or higher;
II - ‘SHA-256bits’ or higher; and
III - ‘RSA-2048bits’ or higher.
3.17 It is advisable that secrets and keys used to authenticate, protect, and ensure the integrity of data are generated in a manner that respects double control and secret handling processes (split-knowledge), storing log records that include the date of generation, participants, and those responsible for custody, when applicable and in a manner compatible with current regulation.
3.18 Participating institutions must implement procedures and security controls for vulnerability analysis at the development and production usage stages of the APIs used in Open Finance, observing current regulation.
3.19 The vulnerabilities referred to in item 3.18 must be categorized and prioritized according to risk classification.
3.20 Participants must implement processes for periodic review of the configurations of systems and APIs used in Open Finance, to ensure that only authorized ports and services are enabled, observing current regulation.
3.21 Participating institutions must ensure that portals and applications related to the implementation and operation of Open Finance have adequate authentication means and authorization control in observance of current regulation.
3.22 The authentication process must always be carried out through a secure communication channel, using TLS 1.2 or higher encryption, in a manner compatible with current regulation.
3.23 Remote accesses for the administration of systems or infrastructure related to Open Finance must be carried out using multiple authentication factors, observing, where applicable, compatibility with current regulation.
3.24 Institutions must implement a formal patch application process that includes systems related to the implementation of Open Finance, in a manner compatible with the institution's cybersecurity policy, observing current regulation.
3.25 Systems and APIs related to Open Finance must have a clock synchronized with a reliable time source, for example, through the use of the NTP protocol.
3.26 APIs and systems related to Open Finance must be implemented using secure configuration standards (hardening), observing current regulation.
4. Detection
4.1 Participating institutions must maintain audit trails containing, at a minimum, the source IP address of the call, the source communication port of the call, date, time, system, user (when applicable), object, failure or success of the action of the configurations performed on systems and APIs related to Open Finance, observing current legislation and regulation.
4.2 Participating institutions must monitor records related to accesses to APIs related to Open Finance, especially records indicating internal errors (e.g., HTTP status 500) or invalid requests (e.g., HTTP status 400), observing current regulation.
4.3 Participating institutions must monitor the volume and pattern of requests to APIs related to Open Finance, to detect incidents related to items I to IV of item 5.5.
5. Reaction
5.1 It is optional for participating institutions transmitting data and account-holding institutions to implement blocking of accesses to their APIs, with the aim of addressing cyber risks or handling ongoing cyber incidents. The implementation of these blocks must be compatible with the institution's cybersecurity policy.
5.2 In the event of compromise of any credential related to Open Finance, the participating institution must revoke it promptly before the Participants Directory and share this information with other participating institutions, observing current regulation.
5.3 In the event of compromise of security certificates, the participating institution of Open Finance must promptly request the revocation of the compromised certificate to the certifying authority and share this information with the Structure Responsible for the Governance of Open Finance and with other participating institutions, observing current regulation.
5.4 Without prejudice to the duty of confidentiality and free competition, participating institutions must share with other participating institutions and with the Structure Responsible for the Governance of Open Finance information about cyber incidents that affect Open Finance services, observing current regulation.
5.5 Within the scope of Open Finance, observing current regulation, the incident response action plan must include, at a minimum, procedures to prevent and respond to incidents that may imply:
I - unauthorized access;
II - data leakage;
III - denial of service; and
IV - failure in data integrity.
6. Structure Responsible for the Governance of Open Finance
6.1 Each institution must register in the Participants Directory the contact data of its representatives for handling incidents, with at least e-mail, PGP cryptographic keys (if any), and a field for additional data. Such data must be made available by the Directory for access by other participants.
6.2 Each institution must make available the e-mail contacts of security teams according to RFC 2142 (abuse and security).
6.3 Access to restricted areas of the Participants Directory must be:
I - allowed only to users authorized by participating institutions or by the Structure Responsible for the Governance of Open Finance; and
II - conditioned by multi-factor authentication.
6.4 Accesses to the Directory must be recorded in audit trails, which must contain, at a minimum, the date and time of access in timezone UTC, the source IP address of the call, the source communication port of the call, the accessed URI, the HTTP method used, and the return status, observing current legislation and regulation.
6.5 The Structure Responsible for the Governance of Open Finance must implement and maintain a cybersecurity policy formulated based on principles and guidelines that seek to ensure the confidentiality, integrity, and availability of data and information systems used, with a view to covering the activities referred to in art. 12 of BCB Resolution No. 32, of 2020.
6.6 The policy referred to in item 6.5 must include:
I - procedures and controls to reduce vulnerability to incidents;
II - the execution, at least annually, of intrusion tests;
III - mechanisms for disseminating the culture of cybersecurity; and
IV - the diffusion of good cybersecurity practices to participants and other stakeholders in the implementation and operation of Open Finance in Brazil.
6.7 The Structure Responsible for the Governance of Open Finance must implement and maintain an incident response action plan aimed at implementing the cybersecurity policy referred to in item 6.5.
6.8 The action plan and response mentioned in item 6.7 must include the routines, procedures, controls, and technologies to be used in the prevention, monitoring, and response to incidents affecting the services defined in art. 12 of BCB Resolution No. 32, of 2020.
6.9 The monitoring of the services referred to in item 6.8 must be carried out permanently and be available 24 hours a day, 7 days a week.
6.10 The policy referred to in item 6.5 and the incident response action plan mentioned in item 6.7 must be approved by the Deliberative Council of the Structure Responsible for the Governance of Open Finance, after prior technical evaluation.
6.11 The intrusion tests mentioned in item II of item 6.6 must be carried out independently and impartially by a natural person or specialized company contracted for this purpose.
6.12 The vulnerabilities identified in the intrusion tests must be documented and promptly handled by the Structure Responsible for the Governance of Open Finance.
6.13 The Structure Responsible for the Governance of Open Finance must establish an Incident Handling Team responsible for:
I - preventing and handling cyber incidents affecting the activities referred to in art. 12 of BCB Resolution No. 32, of 2020;
II - monitoring the use of participant access credentials for the activities referenced in Item I; and
III - being responsible for any access violations if the credentials referred to in Item II are used.
6.14 It is the responsibility of the Incident Handling Team referred to in item 6.13, within the scope of its duties, to support the handling of incidents that may imply risk to the functioning of systems related to the implementation of Open Finance, especially to promote:
I - the diffusion and sharing of indicators of compromise and cybersecurity intelligence information; and
II - the monitoring and handling of incidents involving the activities referred to in Article 12 of BCB Resolution No. 32, of 2020.
6.15 The information regarding cyber incidents cited in Item I of item 6.13 must be:
I - shared with the incident handling representatives of the participating institutions; and
II - made available to the Central Bank of Brazil, in accordance with current regulations.
6.16 The Structure Responsible for Open Finance Governance must make available on the Open Finance Portal in Brazil:
I - the security standards and digital certificates for the purpose of data and service sharing within the scope of Open Finance, in accordance with current regulations; and
II - the instructions to support the issuance of digital certificates required for partnership contracts for sharing purposes as provided for in current regulations.
6.17 The Open Finance Participant Directory must make available mechanisms that allow certificate authorities to validate the attributes of the digital certificates referred to in item 3.9.
Brasília, September 15, 2022.
NOTE 1121/2022-BCB/DENOR, OF SEPTEMBER 9, 2022
Substantiates proposal for the issuance of a normative instruction that establishes version 4.0 of the Security Manual for Open Finance.
Gentlemen Heads of Denor and Deinf,
This Note substantiates a proposal for the issuance of a normative instruction by the Financial System Regulation Department (Denor) and the Information Technology Department (Deinf), using the attribution conferred upon them by Article 23, item I, letter "a", of the Internal Regulations of the Central Bank of Brazil, annexed to Ordinance No. 84,287, of February 27, 2015, and observing item IX of Article 51 of Joint Resolution No. 1, of May 4, 2020.
Regarding this, the proposal concerns the issuance of a normative instruction that establishes version 4.0 of the Open Finance Security Manual, revoking BCB Instruction Normative No. 134, of July 22, 2021, which publishes version 3.0 of the Open Banking Security Manual.
The changes refer to the updating of the expression "Open Banking" to "Open Finance", in accordance with changes made by Joint Resolution No. 4, of March 24, 2022, the updating of references, and clarifications regarding the use of digital certificates in cases of communication via Open Finance APIs and regarding the certificates required for partnership contracts. These changes seek to improve the understanding of the content of the aforementioned manual, after evaluation by the supervision and information technology teams of this Central Bank.
Finally, in compliance with the provisions of Article 5 of Law No. 13,874, of September 20, 2019, Decree No. 10,411, of June 30, 2020, determines that proposals for normative acts of general interest of economic agents formulated by bodies and entities of the direct, autarchic, and foundational federal public administration, as well as by collegiate bodies through the body or entity responsible for providing them administrative support, must be preceded by a Regulatory Impact Analysis (RIA).
However, it is worth highlighting that the proposed adjustments do not significantly impact the set of institutions participating in Open Finance, as they imply only specific updates, encompassing clarifications of specific items of the Security Manual. In this sense, according to Article 4, item III, of the aforementioned Decree, the normative act now proposed is exempt from the preparation of an RIA as it is considered to have low impact.
For your consideration.
Mardilson Fernandes Queiroz
Consultant of the Financial System Regulation Department
Aristides Andrade Cavalcante Neto
Deputy Head of the Information Technology Department
Agreed.
João André Calvino Marques Pereira
Head of the Financial System Regulation Department
Haroldo Jayme Martins Froes Cruz
Head of the Information Technology Department
Read the rest free
Amended 1 time · last 2026-04-02
Source: Banco Central do Brasil — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from BCB
BCB published 19 documents in the last 30 days. We email you each new one the day it's published.