Los Laureles Nº 214 - Lima 27 - Peru Tel. : (511) 6309000 Lima, June 26, 2024 S.B.S. Resolution No. 2286-2024 The Superintendent of Banking, Insurance and Private Pension Fund Administrators WHEREAS:
That, by SBS Resolution No. 6523-2013, the Regulation on Credit and Debit Cards was approved, which establishes general provisions applicable to credit and debit cards, among these, those referring to the responsibilities of companies in carrying out operations and the necessary validations required to verify the identity of each cardholder; That, by SBS Resolution No. 504-2021, the Regulation for Information Security and Cybersecurity Management was approved, with the purpose of strengthening the cybersecurity capabilities and authentication processes of companies in the financial, insurance, and private pension system, considering the increasing interconnectivity and greater adoption of digital channels for the provision of services, as well as the virtualization of some products; That, by SBS Resolution No. 3274-2017, the Regulation on Market Conduct Management of the Financial System was approved, with the purpose that companies have adequate market conduct management reflected in the practices they adopt in their relationship with users, in the offer of financial products and services, information transparency, and claims management; That, it is considered necessary to modify the previously indicated regulatory framework, considering the current functioning of the products and/or services offered by financial system companies to users, as well as the impact of the use of new technologies, making it necessary to specify the responsibility of companies in user identity validation procedures and obtaining their consent when carrying out operations, in cases of unrecognized operations and those that were processed without requiring strong authentication; as well as the obligations of companies associated with compliance with imperative provisions; That, in line with the foregoing, it is necessary that the mechanisms for identity validation and obtaining user consent be implemented by companies from the moment of contracting products and/or services, as well as during their execution, in order to have precise information on new users that allows for adequate monitoring of operations; Los Laureles Nº 214 - Lima 27 - Peru Tel. : (511) 6309000 That, in order to gather user opinions regarding the proposed regulation, the draft resolution was pre-published on the Superintendency's electronic portal, under the provisions of Supreme Decree No. 001-2009-JUS; With the approval of the Assistant Superintendencies of Banking and Microfinance, Insurance, Private Pension Fund Administrators, Risks, Legal Advisory, and Market Conduct and Financial Inclusion; and, In use of the powers conferred in numerals 7 and 9 of Article 349 of the General Law of the Financial System and the Insurance System and Organic Law of the Superintendency of Banking and Insurance, Law No. 26702 and its modifying norms; RESOLVES:
Article First.- Modify the Regulation on Credit and Debit Cards, approved by SBS Resolution No. 6523-2013, as indicated below:
- Incorporate numerals 23, 24, and 25 in Article 2, numeral 7 in Article 16, a last paragraph in Article 18, and numeral 10 in the second paragraph of Article 23, according to the following texts:
“Article 2.- Definitions
For the purposes of this Regulation, the following definitions shall be considered:
(...)
- Card-present operations: Operations in which the payment instrument interacts with the information capture device.
- Card-not-present operations: Operations in which the payment instrument does not interact with the information capture device.
- Cybersecurity Regulation: Regulation for Information Security and Cybersecurity Management, approved by SBS Resolution No. 504-2021 and its modifying norms.
Article 16.- Security measures regarding users
Companies must adopt, at a minimum, the following security measures regarding users:
(...)
- The user authentication process to carry out card operations must be performed as established in Article 19 of the Cybersecurity Regulation, using factors categorized in sub-paragraph j) of Article 2 of said regulation, and following the technical recommendations of the EMV standards issued by EMVCo, according to the type of operation in question:
7.1 For card-present operations, two factors are required, where the first is the card chip or its digital representation. The second factor may be a secret key (PIN) or another established by the Superintendency.
Los Laureles Nº 214 - Lima 27 - Peru Tel. : (511) 6309000
7.2 For card-not-present operations, two factors are required, where the first are the data contained in the physical or digital representation of the card. The second factor may be a dynamic card verification code or another verifiable online factor required from the user within the framework of the EMV 3DS standard, except for the exemption cases provided in Article 20 of the Cybersecurity Regulation.
7.3 For operations with third-party mobile wallets based on card tokenization, the affiliation of the card for the use of this service in accordance with numeral 7.2 and subsequent operations carried out must be authenticated through card tokenization and a second factor of a different nature.
7.4 The control required in sub-paragraph b) of Article 19 of the Cybersecurity Regulation, against man-in-the-middle attacks, is satisfied through the adoption of EMV 3DS and EMV Tokenization standards for numerals 7.2 and 7.3 of this article, as applicable.
7.5 For operations in which the second factor is not validated due to limitations beyond their control, the company must establish acceptance or rejection rules, based on the level of fraud risk, according to the transaction monitoring system described in Article 17 of this regulation. Such limitations may be associated with the service terminal, merchant practices, or the technology used by the user.
Article 18.- Measures regarding information security
(...)
The company must make available to third-party platforms mechanisms to replace card data with a unique identifier generated using cryptographic techniques (tokenization).
Article 23.- Responsibility for unrecognized operations
(...)
The company is responsible for losses from operations carried out in the following cases:
(...)
- Operations carried out without the use of a second authentication factor, as referred to in paragraph 7.5 of numeral 7 of Article 16 of this regulation.”
- Modify numerals 9 and 14 of Article 2, numeral 1 of Article 5, the third paragraph of Article 8, numeral 1 of Article 15, and the First Final and Transitory Provision, according to the following texts:
“Article 2.- Definitions
For the purposes of this Regulation, the following definitions shall be considered:
(...)
- Authentication factor: as defined in sub-paragraph j) of Article 2 of the Regulation for Information Security and Cybersecurity Management.
Los Laureles Nº 214 - Lima 27 - Peru Tel. : (511) 6309000 (...)
- Market Conduct Management Regulation: Regulation on Market Conduct Management of the Financial System, approved by SBS Resolution No. 3274-2017 and its modifying norms.
(...)
Article 5.- Minimum content of the contract
The credit card contract must contain, at a minimum, the following information:
- The conditions applicable for the reduction or increase of the credit line and the applicable mechanisms to require the user's prior consent in case an increase in the line is sought as provided by the Market Conduct Management Regulation, when applicable.
(...)
Article 8.- Additional credit card
(...)
Only the credit line holder can choose the additional services associated with the additional credit card they request, in accordance with Article 7 of this Regulation. The additional services of the additional card, with the exception of overdraft, must be able to be enabled or disabled by the holder independently of the additional services of the main card.
Article 15.- Security measures incorporated in cards
Cards must have an integrated circuit or chip that allows storing and processing user information and operations, complying with international interoperability standards for the use and verification of cards, as well as for payment authentication; for which, at a minimum, the security requirements established in the EMV standard issued by EMVCo must be met. In this regard, companies must apply, among others, the following measures:
- Security rules defined in the chip of physical support cards, which must be used to verify the authenticity of the card and validate the user's identity in accordance with the minimum requirements indicated in Article 16 of this Regulation.
(...)
Final and Transitory Provisions
First.- Market Conduct Management Regulation
The provisions regulated in the Market Conduct Management Regulation are applicable.”
Los Laureles Nº 214 - Lima 27 - Peru Tel. : (511) 6309000
- Replace Articles 6, 9, 12, and 14, according to the following texts:
“Article 6.- Minimum information, conditions, and validity applicable to credit cards Credit cards with physical or digital support are issued as non-transferable and must include at least the following information:
- Company name of the credit card issuer.
- Commercial name assigned by the company to the product.
- Identification of the credit card system (brand) to which it belongs, if applicable.
The validity period of credit cards cannot exceed five (5) years, and shorter expiration periods may be agreed upon.
Article 9.- Charges associated with credit cards
Companies shall charge the amount of goods, services, and obligations that the credit card user acquires or pays, as well as the services described in Article 7 of the Regulation, in accordance with current legislation on the matter, the contract signed between the parties, and the authorization of the credit card user.
Article 12.- Minimum information, conditions, and validity applicable to debit cards
Debit cards with physical or digital support are issued as non-transferable and must include at least the following information:
- Company name of the debit card issuer.
- Commercial name assigned by the company to the product.
- Identification of the debit card system (brand) to which it belongs, if applicable.
The validity period of debit cards cannot exceed five (5) years, and shorter expiration periods may be agreed upon.
Article 14.- Charges associated with debit cards
Companies shall charge the user's deposit account for the amount of goods, services, and obligations that the user acquires or pays, as well as the services described in Article 13 of the Regulation, in accordance with current legislation on the matter, the contract signed between the parties, and the authorization of the debit card user.”
- Eliminate numerals 5 and 6 of Article 17.
Los Laureles Nº 214 - Lima 27 - Peru Tel. : (511) 6309000
Article Second.- Modify paragraph 20.3 of Article 20 of the Regulation for Information Security and Cybersecurity Management, approved by SBS Resolution No. 504-2021, as indicated below:
“Article 20. Exemptions from strong authentication for digital channel operations (...)
20.3 The company is responsible for losses, unless it proves user responsibility, for operations not recognized by customers that have been carried out through a digital channel without complying with the strong authentication requirement, or in application of the exemption indicated in paragraph 20.2 of this article, or that were carried out after the user reported the theft or loss of their credentials.
Article Third.- Modify the first paragraph of Article 49 of the Regulation on Market Conduct Management of the Financial System, approved by SBS Resolution No. 3274-2017, as indicated below:
“Article 49. Contracting of financial products
49.1 In the contracting of financial products and services, the following must be considered:
- The company must verify the client's identity and record the acceptance of the contract, which includes the summary sheet or information card and any other relevant information, as well as any operation carried out during its execution.
- For the conclusion of the contract and during its execution through digital channels, the company must apply what is established in current regulations on information security and cybersecurity.
(...)"
Article Fourth.- Modify paragraphs 14.1 and 14.2 of Article 14 of the Regulation on Complaints and Requirements, approved by SBS Resolution No. 4036-2022, as indicated below:
“Article 14.- Information to the User
14.1 Companies must keep available to users, through their digital channels, and in all their establishments open to the public, in a visible and easily accessible place, information, posters and/or brochures on the procedures for handling complaints and requirements, the requirements for their processing, response times, the channels made available to users for their submission, and channels for the reception or availability of the response.
14.2 Companies must keep available to the public, informative material provided by the Superintendency regarding the work it carries out, in order to inform about its competencies in handling complaints or requirements related to the products and/or
Los Laureles Nº 214 - Lima 27 - Peru Tel. : (511) 6309000 services provided by companies; which may be disseminated through any of its service channels.
(...)"
Article Fifth.- In relation to the provisions on additional services in the last paragraph of Article Twelfth of SBS Resolution No. 5570-2019, cards issued under new contracts signed after 01.01.2021 are issued with all additional services disabled, and are enabled at the user's request. Similarly, all first renewals due to expiration or replacements due to loss, theft, or other cause, corresponding to contracts signed before 01.01.2021, must be issued with all additional services disabled, and are enabled at the user's request. In both cases, subsequent issues may retain the user's last decision, for which there is support, on enabling or disabling additional services.
Article Sixth.- In relation to the adaptation period established in Article Seventh of SBS Resolution No. 3240-2023, for the implementation of the modifications to numeral 4 of paragraph 29.1 of Article 29 of the Regulation on Market Conduct Management of the Financial System, approved by SBS Resolution No. 3274-2017, the granted period is extended by one hundred eighty (180) additional days counted from the expiration of the initial period.
Article Seventh.- The modifications to the Regulation on Credit and Debit Cards approved by SBS Resolution No. 6523-2013, established in Article First of this Resolution, have an adaptation period until December 31, 2024, except as provided below:
a) Debit card present operation: from the day following the publication of this Resolution, the company must authenticate the user in accordance with numeral 7.1 of Article 16 of the Regulation. b) Credit card present operation:
b.1.) For cards issued from July 1, 2025, inclusive, the company must authenticate the user in accordance with numeral 7.1 of Article 16 of the Regulation. b.2.) For cards issued before July 1, 2025, and still valid after that date, the company must authenticate the user in accordance with numeral 7.1 of Article 16 of the Regulation at the latest from its renewal. 1 c) Credit or debit card not present operation: from July 1, 2025, the company must authenticate the user in accordance with numerals 7.2 and 7.4 of Article 16 of the Regulation, regardless of the card's issue date. d) Operation with third-party mobile wallets based on card tokenization: from July 1, 2025, the company must authenticate the user in accordance with numeral 7.3 of Article 16 of the Regulation, regardless of the card's issue date. e) Additional credit card operation in card-not-present mode: from December 1, 2025, the company must authenticate the user in accordance with what is indicated in numerals 7.2, 7.3, and 7.4 of Article 16 of the Regulation, regardless of the card's issue date. f) Responsibility for losses in unrecognized operations: from July 1, 2025, the company is responsible for losses in unrecognized operations, unless it proves user responsibility, in accordance with what is established in numerals 9 and 10 of Article 23 of the Regulation, with the exception of the operation provided in sub-paragraph a) of this article, in which case responsibility will be enforceable from the effective date of this Resolution. 23 g) Numeral 7.5 of Article 16 and the last paragraph of Article 18 of the Regulation have an adaptation period until July 1, 2025 4.
Article Eighth.- This Resolution enters into force the day following its publication in the Official Gazette El Peruano.
Register, communicate and publish.
MARIA DEL SOCORRO HEYSEN ZEGARRA
Superintendent of Banking, Insurance and AFPs
1 Term extended to April 1, 2026 by SBS Resolution No. 2220-2025, effective June 26, 2025.
2 Term extended to April 1, 2026 for sub-paragraph b.2) by SBS Resolution No. 2220-2025, effective June 26, 2025.
3 Term extended to June 1, 2026 for sub-paragraph b.2) by SBS Resolution No. 0771-2026.
4 Term extended to April 1, 2026 for the last paragraph of Article 18 by SBS Resolution No. 2220-2025, effective June 26, 2025.