Banking Regulation Alert - July 2026
For more information, contact:
Themes
REGULATION ON THE PROVISION OF SERVICES UNDER THE BANKING AS A SERVICE (“BaaS”) MODEL
Through SBS Resolution No. 01747-2026, published on July 3, 2026, in the Official Gazette El Peruano, the Superintendency of Banking, Insurance and Private Pension Fund Administrators (“SBS”) approved the Regulation governing the provision of services under the Banking as a Service (“BaaS”) model (the “Regulation”).
The Regulation governs a financial services model that has already become a reality in the market but, until now, lacked an express regulatory framework: one in which a supervised entity—the BaaS provider—enables third parties, whether supervised by the SBS or not—the BaaS recipients—to offer certain financial services through its regulated infrastructure by means of remote access digital connections and integrations. The main aspects addressed by the Regulation are as follows:
- Scope of application: The following entities may act as BaaS providers: banks, finance companies, municipal savings and credit banks, rural savings and credit banks, credit companies, savings and credit cooperatives authorized to accept public deposits, and electronic money issuers.
- Permitted financial services: (i) demand deposit, savings, time deposit, and compensation for length of service (CTS) accounts; (ii) electronic money accounts; (iii) lending activities; (iv) the issuance and administration of credit and debit cards; (v) the marketing of bancassurance products and services; and (vi) any other services determined by the SBS. The provision of the services referred to in items (i) and (ii) enables the processing of collections, payments, and transfers through such accounts. The BaaS provider must establish maximum transaction frequency limits under a risk-based approach.
- General conditions: BaaS providers may only offer services within the scope of their respective authorizations granted by the SBS and are responsible for ensuring that financial services offered through BaaS recipients comply with applicable regulations, while maintaining a direct contractual relationship with end customers at all times.
Consistent with the foregoing, the following conditions are established:
- Deposit accounts and electronic money accounts must be opened in the customer’s name directly with the BaaS provider.
- In the case of loans and credit cards, the agreement and all communications must expressly state that the customer is the debtor under the credit transaction entered into with the BaaS provider.
- Approval and implementation: BaaS providers must have policies and procedures approved by their Board of Directors for the comprehensive management of risks throughout the entire lifecycle of their relationship with BaaS recipients.
Such policies and procedures must include, at a minimum: (i) the definition of the objectives, scope, and requirements of the BaaS services to be offered; (ii) the allocation of roles, responsibilities, and accountability mechanisms for those responsible for the evaluation, approval, contracting, and monitoring of the BaaS recipient; (iii) the performance of a comprehensive assessment process prior to entering into each agreement; (iv) the establishment of periodic monitoring mechanisms for the BaaS recipient; and (v) the procedure for the provision of BaaS services when the BaaS provider or the BaaS recipient is involved in circumstances that may affect service delivery.
Any implementation of, or modification to, BaaS services is subject to the framework applicable to new products and major changes, requiring risk assessments and the submission of the corresponding reports to the SBS.
- Liability: The BaaS provider remains responsible to customers and the SBS for the financial services provided, regardless of the contractual arrangements entered into with the BaaS recipient. The BaaS provider must manage the risks associated with the BaaS model, including credit and operational risk management, prevention of money laundering and terrorist financing, market conduct, information security, and cybersecurity.
The BaaS provider must be clearly and unequivocally identified by BaaS recipients and end customers and must maintain separate agreements with each BaaS recipient. In addition, it must ensure access to the information necessary for regulatory compliance, transaction traceability, and the proper allocation of responsibilities for supervisory purposes.
- Prohibitions: BaaS recipients may not: (i) use, in their corporate name or through any other means, terms that may lead the public to believe that their activities include operations requiring prior authorization from the SBS; (ii) subcontract the services received from the BaaS provider; or (iii) contract the same financial service with more than one BaaS provider.
- Minimum contractual requirements: The agreement between the BaaS provider and the BaaS recipient must include the minimum content established under the Regulation.
- Reporting and supervision: The BaaS provider must maintain an updated list of BaaS recipients with active agreements, submit such list to the SBS on a semiannual basis, and publish it on its website.