TITLE: Chile's Financial Markets Commission Updates Operational Security Standards for Non-Bank Payment Card Issuers and Operators
BODY:
Chile's Financial Markets Commission (Comisión para el Mercado Financiero) has updated Circular N° 2, which establishes common operational safeguards and security standards for the issuance and operation of payment cards by non-bank entities. The circular, originally issued on November 28, 2017, has been amended through multiple updates, with the most recent modifications adopted on July 6, 2020.
The updated circular applies to non-bank payment card issuers and payment card operators, establishing comprehensive requirements across six key areas. These include authorization and transaction registration systems, which must employ robust authentication mechanisms and fraud prevention tools compliant with international standards and best practices. For electronic fund transfers from provisioning accounts, entities must implement strong authentication methods using at least two distinct factors—one for system access and another for authorizing each transaction. In transfers between different issuers' accounts, at least one authorization factor must be dynamically generated or assigned.
The circular mandates fraud prevention systems capable of identifying, evaluating, monitoring, and detecting suspicious transaction patterns in real time, including analysis of access points and user behaviour. Entities must also establish service outsourcing protocols, ensuring they retain responsibility for third-party service providers' operational security and performance. Additionally, the circular requires operational continuity plans to address contingencies, incident reporting procedures through the Commission's extranet, and comprehensive information security and cybersecurity management frameworks aligned with the Central Bank of Chile's (Banco Central de Chile) Financial Norms Compendium.
Entities must comply with these standards considering their operational nature, volume, and complexity. The requirements align with guidelines established in the Updated Compilation of Norms for Banks, Chapters 20-7 through 20-10, which provide detailed frameworks for service externalization, business continuity, operational incident communication, and information security governance.