regulatoryJuly 21, 20269 min read···

BCRA Communication A 8432: PSP Compliance Guide for Argentina

BCRA Communication A 8432 expires August 3. Argentine PSPs have 90 days to meet new KYC, AML, and ownership disclosure requirements or face deregistration.

Gu1

Team Gu1

Gu1

Argentina's payment sector is moving toward a compliance model that looks much more like banking. Communication A 8432, published by the BCRA on May 6, 2026, is the clearest signal of that direction yet. It formalizes a new type of regulated entity, tightens ownership transparency requirements, restructures the PSP registration process, and gives the central bank new ex officio powers to remove inactive or non-compliant operators from the registry.

The BCRA Communication A 8432 adaptation deadline is August 3, 2026. Ninety calendar days from publication.

This guide covers what changed, what it means operationally, and what compliance teams and fintech operators need to complete before that date.

What BCRA Communication A 8432 Changes#

The Communication modifies the Texto Ordenado de Proveedores de Servicios de Pago across six areas:

  1. A new regulated entity type: the "PSPCP como Servicio" (PSPCP-as-a-Service)
  2. New exclusions and restrictions on shareholders, beneficial owners, and directors
  3. Additional registration requirements including mandatory UIF compliance officer disclosure
  4. Extended registration-to-operations window (from 6 to 12 months)
  5. New BCRA powers to deregister PSPs ex officio
  6. Explicit AML/CFT obligations for PSPs that are UIF-obligated entities

The underlying signal from the BCRA is consistent: the central bank wants to know who is behind each PSP, how they operate, and whether compliance controls travel with the service even when third parties are involved in delivery.

The PSPCP-as-a-Service Model#

The most structurally significant change in the Communication is the formal regulation of the "PSPCP como Servicio" model.

Before A 8432, a payment account provider (PSPCP) that offered its infrastructure to third parties to serve end users existed in a regulatory gray area. The relationship was governed by commercial contracts, without explicit BCRA rules about how regulatory responsibility was allocated between the PSPCP and the third party.

That gray area is now closed.

The BCRA defines a PSPCP-as-a-Service as a payment account provider that offers accounts, and potentially interoperable digital wallet services, to the customers of a third-party "service taker." The end users interact through the third party's interface, which is technologically integrated with the underlying PSPCP infrastructure.

This covers a range of fintech architectures that are common in Argentina: embedded wallets, Banking-as-a-Service (BaaS) integrations, white-label payment accounts, and platform models where the user experience belongs to a third party while the underlying payment account is provided by a regulated PSPCP.

The core regulatory principle: the BCRA considers the third party's customers to be customers of the PSPCP-as-a-Service. Routing service delivery through an intermediary interface does not transfer regulatory responsibility. The underlying PSPCP retains full compliance obligations across all dimensions of the service.

What the PSPCP-as-a-Service Must Do#

New requirements apply to any PSPCP operating under this model:

Before onboarding a service taker: The PSPCP cannot provide service to a third-party service taker until the BCRA has formally approved that service taker's registration. This requires a signed affidavit (DDJJ) from the PSPCP's legal representative committing to this restriction.

At registration: The PSPCP must provide the BCRA with a complete registry of all service takers, including corporate name, CUIT, legal domicile, legal representative, and governance information. Individuals holding at least 10% of capital or voting rights in the service taker, those exercising final control, and all board members must be individually identified.

Ongoing obligations: Contracts with service takers must remain available for BCRA inspection at all times. These contracts must include explicit clauses establishing the following requirements on the service taker:

  • Customer identification and due diligence processes aligned with BCRA standards
  • Digital onboarding that meets BCRA requirements
  • AML and CFT controls
  • Fraud prevention processes
  • Information security controls
  • Operational continuity protocols
  • Technological and operational risk management procedures

Third-party user interfaces must display the PSPCP's commercial name clearly and legibly, alongside all information required under the Financial Services User Protection framework.

Compliance audits: PSPCPs-as-a-Service are subject to compliance reports with professionals registered in the SEFYC auditor registry.

For PSPCPs that were already operating under this model before the Communication was published on May 6, there was a 10-business-day window (until May 20, 2026) to notify the BCRA of all existing service takers. That initial deadline has already passed.

Ownership Transparency and Director Eligibility#

The Communication's shareholder and director restrictions reflect a broader regulatory trend: the BCRA wants full visibility into who controls and runs each PSP, not just at registration but on an ongoing basis.

The exclusion criteria now cover individuals who appear on:

  • UIF resolutions related to terrorism financing
  • The RePET public registry (Registro Publico de Personas y Entidades vinculadas a actos de Terrorismo y su Financiamiento)
  • UN Security Council sanction lists

Beyond those lists, the BCRA will also consider prior convictions, fines, suspensions, revocations of authorizations, and disqualifications imposed by the UIF, BCRA, CNV, or SSN on any shareholder, partner, beneficial owner, director, or supervisory board member.

The practical implication: PSPs are now required to conduct KYC on their own ownership structure with the same rigor expected for customer onboarding. This is not a one-time registration exercise. If an investor enters the shareholder register, if a board member is added, or if the control structure changes, the PSP must verify eligibility under these criteria.

New Registration Requirements#

The Communication adds several mandatory items to the PSP registration process:

UIF compliance officer: PSPs must now designate and register both a primary and an alternate compliance officer (Oficial de Cumplimiento) with the UIF. This is a formal registration requirement, not just an internal appointment.

Sponsoring banks: PSPCPs must disclose which banks will act as their sponsors. This information is now part of the formal registration record.

Extended governance documentation: Shareholders, beneficial owners, and directors must submit affidavits covering declared incompatibilities, prior sanctions, PEP status, and criminal background. Criminal background certificates are required, and in some cases must carry digital signatures under Law 25.506.

Federal jurisdiction consent: All PSPs must consent to the jurisdiction of the Buenos Aires Federal Justice system for all legal matters arising from their relationship with the BCRA.

Extended operational window: The window for PSPs to begin operations after registration has been extended from 6 to 12 months, acknowledging the complexity of integrations with banks and technology providers before launch.

For UIF-obligated PSPs, the Communication explicitly incorporates them into the BCRA's Texto Ordenado on Prevention of Money Laundering, Terrorism Financing, and Other Illicit Activities. This does not create new substantive obligations beyond what the UIF framework already requires, but it formalizes BCRA supervisory authority over those obligations.

BCRA Ex Officio Deregistration Powers#

The Communication gives the BCRA new tools to remove PSPs from the registry without waiting for voluntary notification or going through a formal sanction process.

Grounds for ex officio deregistration include:

Inactivity: Failure to comply with mandatory reporting requirements for at least 180 consecutive calendar days, including failure to submit required operational reports, failure to report transactions, or absence of data in transfer reporting systems.

Structural changes: Fundamental changes in conditions required for registration, including changes to shareholders, directors, ownership structure, or operational model that were not disclosed to the BCRA.

Sanctions: Sanctions imposed by BCRA, UIF, CNV, SSN, or equivalent foreign regulators on the PSP, its shareholders, or its authorities.

Reporting inconsistencies: Relevant changes in shareholder, director, or operational information relative to what was registered, when not proactively reported.

The inactivity trigger deserves specific attention. A PSP that goes through an extended operational pause, a pivot, or a funding gap can be removed from the registry if its regulatory reporting lapses for 180 consecutive days, even without any intention to cease operations. This requires PSPs to actively manage reporting cadences independent of operational activity.

What to Complete Before August 3#

The 90-day period ends on August 3, 2026. For compliance teams and fintech operators, the workstreams that need to be completed include:

Ownership structure audit: Map all shareholders, beneficial owners, partners, and directors against UIF terrorism financing resolutions, the RePET registry, and UN Security Council sanction lists. Prepare affidavits. Document the process. Build a mechanism to repeat this whenever ownership or governance changes.

PSPCP-as-a-Service registration (if applicable): If operating under this model, ensure all service takers are registered with the BCRA. Audit existing contracts to verify that all applicable BCRA regulatory requirements are included as contractual obligations on the service taker. Validate that third-party interfaces meet BCRA identification, AML, fraud prevention, and information security standards.

UIF compliance officer: Designate and formally register a primary and alternate compliance officer with the UIF.

Reporting cadence review: Confirm that all mandatory regulatory reporting is current. Set up monitoring for the 180-day inactivity threshold. A lapse in reporting can now trigger deregistration without prior notice.

Documentation update: Update all shareholder, director, and governance documentation to meet the new format and content requirements. Ensure criminal background certificates and PEP declarations are in order for every required individual.

The August 4 Context: RMGCTI#

The day after the A 8432 deadline, August 4, the RMGCTI (Requisitos Minimos de Gestion, Control y Tecnologias de la Informacion) enters into force. Under RMGCTI, PSPs must include specific audit, cybersecurity, and operational continuity clauses in their contracts with technology providers.

Two major BCRA requirements go live within 48 hours. PSPs that arrive at August 3 with minimal documentation and no structural improvements will immediately face another set of requirements with no runway.

Compliance as Infrastructure#

There is a meaningful difference between adapting for August 3 and being positioned for what comes after.

Compliance built as a set of documents, policies, and manual review cycles functions until the regulatory environment changes. Every update triggers a cycle of revision, internal distribution, training, and verification that depends on the right people having time and attention. In a regulatory environment moving as fast as Argentina's payment sector, that cycle repeats constantly.

Compliance built as infrastructure codifies controls into systems. A regulatory change translates into a configuration update, a rule parameter change, or a new data source integration rather than a policy rewrite and a training session. The controls travel with the operation automatically.

The BCRA's direction is clear: the PSP regulatory framework continues to converge toward the standards applied to financial entities. Each Communication adds scope, precision, and enforcement capability.

Communication A 8432 does not require infrastructure. It requires adaptation. But the PSPs that arrive at August 3 with automated KYC verification, codified AML rules, integrated beneficial ownership monitoring, and real-time fraud detection are in a fundamentally different position than those that arrive with updated affidavits and revised policy documents.

The organizations that build compliance as an operational capability rather than a documentation function are the ones that scale without hitting regulatory ceilings.

Gu1 provides compliance and fraud prevention infrastructure for financial institutions across Argentina, Brazil, Mexico, Colombia, and Chile. The platform covers KYC, AML monitoring, fraud prevention, and regulatory reporting under BCRA and UIF requirements in Argentina, and under the frameworks of each country's regulators across the region.

Share this post

Get new posts in your inbox

One email when we publish. No spam. Unsubscribe whenever you want.