Alert
Banking and Finance Alert - May 2026
For more information, contact:
Themes
May 14, 2026
Draft Regulation for the provision of Services under the Banking as a Service (BaaS) Model
On May 11, 2026, the Superintendence of Banking, Insurance and Private Pension Funds (“SBS”) announced the publication for public consultation of Resolution No. 01371-2026, which contains the draft regulation for the provision of services under the Banking as a Service (BaaS) model (the “Draft”).
The Draft regulates a financial services model that is already widely used in the market but currently lacks an express regulatory framework. Under this model, a supervised entity —the BaaS provider— enables third parties, whether supervised by the SBS or not —referred to as recipients— to offer financial services through its regulated infrastructure, via remote, automated digital connections and integrations.
- Scope of application: According to the Draft, the regulation would apply to banks, financial institutions, municipal savings banks, rural savings banks, credit companies, savings and credit cooperatives authorized to take deposits from the public, and electronic money issuers, all of which may act as BaaS providers.
- Permitted financial services: The Draft defines a list of services that may be offered under the BaaS model: (i) opening, maintenance, and closing of demand deposit and savings accounts; (ii) electronic money accounts; (iii) lending activities; (iv) collections, payments, and transfers linked to such accounts; (v) issuance and management of credit and debit cards; and (vi) any other services the SBS may authorize. It also requires BaaS providers to establish maximum transaction frequency limits on a daily and monthly basis. BaaS providers may only offer services that fall within the scope of their respective licenses granted by the SBS.
- Full responsibility of the BaaS provider: The BaaS provider retains full responsibility before both clients and the SBS for the provision of financial services, regardless of its contractual arrangements with the recipient. The provider must implement policies, procedures, and controls for credit and operational risk management, anti-money laundering and counter-terrorist financing, market conduct, information security, and cybersecurity. Although operational functions may be contractually delegated to the recipient —who must comply with these standards— ultimate responsibility remains with the BaaS provider at all times.
- In line with the above, the Draft establishes the following ownership conditions:
- (i) deposit and electronic money accounts must be opened in the client’s name directly with the BaaS provider;
- (ii) collections, payments, and transfers must originate from or be credited to such accounts; and
- (iii) in the case of loans and credit cards, it must be expressly stated in the agreement and in all communications that the client is the debtor of the BaaS provider. In all cases, the direct contractual relationship with the client lies with the BaaS provider, which is the supervised entity.
- Approval of arrangements: The board of directors of the BaaS provider, or the body to which it delegates such authority, must expressly approve —and record in the corresponding minutes— each BaaS agreement and each new service entered into with a recipient.
- Notification and supervision: Once the agreement is executed and approved, the BaaS provider must notify the SBS and submit the documentation required under Circular G-165-2012. Any amendments must also be reported.In addition, the provider must maintain an updated list of recipients with active agreements, submit it to the SBS on a semiannual basis, and publish it on its website.
- Key restrictions: BaaS providers may not contract with: (i) a recipient that already has an active BaaS agreement with another provider for the same service; or (ii) a recipient whose name or communications may mislead the public into believing that it carries out activities requiring prior SBS authorization. Furthermore, recipients may not subcontract or provide BaaS services to third parties.
- Minimum contractual content: The Draft sets out mandatory minimum clauses that must be included in agreements between BaaS providers and recipients.
- Policies and procedures for onboarding and monitoring recipients: BaaS providers must implement risk-based policies and procedures, approved by the board (or its delegate), for the due diligence, onboarding, and ongoing monitoring of recipients throughout the contractual relationship.