Peru has no single Fintech Law — the sector is regulated by type of activity (electronic money, lending, payments, factoring, crowdfunding). However, 2026 marked a clear tightening: the SBS created an Open Finance Department, renamed its former Information Security Department to Cybersecurity Department, and approved the Banking as a Service (BaaS) regulation — all requiring information security standards as a requirement, not an option.
Why did the SBS give so much weight to cybersecurity this year?
Through Resolution SBS N° 03206-2025, the Superintendency of Banking, Insurance and AFP created the Open Finance Department as a structural modification that positions digital security as a fundamental requirement for the open-finance model in Peru. The former Information Security Department was renamed to Cybersecurity Department — a name change that reflects a real shift in regulatory priority, not merely a cosmetic one.
What is the BaaS regulation and why does it affect non-bank fintechs?
The Banking as a Service regulation, formalized through Resolution SBS N° 01747-2026 (after a public consultation launched in May 2026 with over 100 sector actors), allows banks and electronic-money issuers to put their technological infrastructure at the service of technology companies, both supervised and non-supervised. The regulation explicitly requires that all parties —including non-supervised fintechs participating as third parties— comply with information security, risk management, and anti-money-laundering standards.
What happens if my fintech operates today without a clear regulatory framework?
Before this regulatory wave, there was a real asymmetry: fintechs managed financial services for banks, but the SBS could only directly sanction the banks, not the allied fintechs. That gap is closing — Resolution SBS N° 01029-2026 already strengthened the sanctions regime, and the new BaaS framework extends security obligations to non-supervised actors participating in the chain.
What other Peruvian regulations should I have on my radar?
Peruvian regulations relevant to fintechs (2026)
| Regulation | What it governs |
|---|---|
| Legislative Decree 1700 (01/23/2026) | Amends the Cybercrime Law; adds illegal trafficking of personal data with up to 10 years in prison |
| New personal data protection regulation | Adds the Data Protection Officer as a mandatory role; inspection fines already exceed S/11 million |
| Circular N° 0022-2025-BCRP | New General Regulation of the National Payment System (in force since 04/01/2026); modernizes interoperability and technological security |
How many fintechs operate in Peru today, and how prepared are they?
It is estimated that around 300 fintech startups operate in the country. A significant portion of them still operates in regulatory gray zones that the SBS is actively closing during 2026 — which turns certification, or at least a formal security management system, into a real competitive differentiator when facing license evaluations or participation in the SBS regulatory sandbox.
How to start preparing?
An external audit or diagnosis of your cybersecurity infrastructure, data-protection protocols, and access management is the recommended first step — documenting the process today is what will differentiate you when the SBS begins formally evaluating non-bank actors.
Regulatory sources: Resolution SBS N° 03206-2025, Resolution SBS N° 01747-2026 (BaaS), Resolution SBS N° 01029-2026, Legislative Decree 1700 (01/23/2026), Circular N° 0022-2025-BCRP.
In this topic
View the full topicQuick answerDetail
What does the Peruvian SBS require from fintechs regarding information security in 2026?
With no single Fintech Law, the SBS regulates by activity type, and in 2026 it tightened the framework: it created the Open Finance Department (Res. SBS 03206-2025), renamed its area to Cybersecurity Department, and approved the Banking as a Service regulation (Res. SBS 01747-2026), which extends information-security obligations to non-supervised fintechs acting as third parties. On top of that come Legislative Decree 1700 (illegal data trafficking, up to 10 years), the new personal data regulation, and BCRP Circular 0022-2025. Security went from option to requirement, and a formal management system under ISO 27001 is the direct way to demonstrate it.
Written and reviewed by Rogelio Barajas González — certified Lead Auditor ISO 27001:2022 and ISO 9001:2015, with direct experience in SOC 1 Type 2 and SOC 2 Type 2. Founder of Barajas Advisory.
Verify his credentials on LinkedIn:linkedin.com/in/rogelio-barajas-gonzalezLast updated: August 2026
This is one of nine real cases
Cicatrices de Nube — do you want the rest of the stories?
All nine documented cases —FinOps, Release Management, Service Delivery, Compliance, and AI governance— with a self-assessment checklist per chapter and an overall scorecard.
Download the free playbook