Alert
Fintech Alert - December 2025
For more information, contact:
Themes
December 19, 2025
CENTRAL RESERVE BANK OF PERU APPROVES NEW GENERAL REGULATIONS FOR THE NATIONAL PAYMENTS SYSTEM
The Central Reserve Bank of Peru (“BCRP”) has published Circular No. 0022-2025-BCRP, approving the new General Regulation of the National Payments System (“Regulations”), which will enter into force on April 1, 2026.
The Regulations will replace the regulations in effect since 2010 (Circular No. 012-2010-BCRP) and fall within the powers granted by the Payments Law (Law No. 29440), as amended by Legislative Decree No. 1665, which expanded the BCRP’s authority to respond to technological innovation and the incorporation of new participants in the National Payments System.
Who does it apply to?
The Regulation applies to the (“Regulated Entities”) of the National Payments System, which include:
- Administrators and participants in payment infrastructures (payment systems and agreements).
- Payment Service Providers (“PSPs”), including Payment Service Entities (“ESPs”) that do not manage deposit accounts or electronic money.
- Technology Service Providers and Third-Party Entities that operate within the National Payments System.
SPECIFIC ASPECTS ACCORDING TO THE TYPE OF REGULATED ENTITY
- Payment Systems: Payment system administrators that process, settle, or clear payments between participants must register with the Central Reserve Bank of Peru (BCRP) and submit their internal and operating regulations. They must comply with requirements for access, good corporate governance, comprehensive risk management, information security, and ensure operational continuity. Direct participants, in turn, are obligated to comply with the required technical standards, report relevant incidents, maintain sufficient financial resources, and participate in the validation tests established by the system.
- Payment Agreements: The Regulation defines these as procedures for transferring funds between customer accounts of Payment Service Providers (PSPs), using one or more payment instruments. Administrators must register with the BCRP, submit corporate documentation and operating regulations, and comply with requirements for access, risk management, and security. Participants, in turn, must comply with security standards, report incidents, and guarantee operational continuity.
- Payment Service Providers (PSPs): PSPs may include multi-operation companies authorized by the SBS to issue electronic money, the Banco de la Nación, money transfer companies, ESPs that do not manage deposit accounts or electronic money, and other entities that the BCRP determines. PSPs must comply with the regulations, implement transaction controls, retain information for five years, promptly inform their clients, and communicate the completion of transfers. They must also report information periodically and comply with security, risk management, and personal data protection requirements.
- Payment Service Entities (ESPs): The regulations applicable to ESPs are defined, which include providers that do not manage deposit accounts or electronic money. Depending on their role, they must obtain prior authorization or registration with the BCRP and comply with minimum requirements for share capital and net worth, among others.
- Critical Technology Service Providers and Third-Party Entities: These are legal entities contracted by administrators or PSPs to delegate functions or processes in payment services. They must have risk management, information security, and cybersecurity policies in place, participate in business continuity tests, report incidents that affect service availability, and report relevant information to the administrator and the Central Reserve Bank of Peru (BCRP). Furthermore, they must retain confidential information for five years and provide advance notice of their cessation of operations.
KEY ASPECTS OF THE REGULATIONS
- Interoperability: Regulated Entities must comply with the requirements, standards, and principles established by the Central Reserve Bank of Peru (BCRP) to promote interoperability among Systems, Agreements, Services, and Payment Instruments. The BCRP defines the scope and timing of interoperability.
- Security and Cybersecurity: Regulated Entities must align with current financial system guidelines, including cybersecurity standards, risk management, and authentication. Administrators will be obligated to report incidents that affect operational continuity and communicate these events to participants.
- Transparency and Non-Discrimination in Charges, Commissions, and Fees: The Regulations incorporate rules designed to guarantee transparent and non-discriminatory charges. The fees, commissions, and other charges applied by Regulated Entities must reflect the actual costs of the services, avoiding practices that create barriers to interoperability. The BCRP may request supporting documentation and require changes to charge policies.
- Supervision and Sanctions: The Central Reserve Bank of Peru (BCRP) will have greater powers to supervise payment system participants, including the authority to request detailed information, conduct inspections, and issue mandatory instructions. Non-compliance may be sanctioned with fines of up to 20 Tax Units (UIT), and persistent violations could result in the suspension or revocation of the entity's access, authorization, or registration.
- Progressive Implementation: Although the regulation takes effect on April 1, 2026, the implementation process will be gradual, with different timelines depending on the volume of transactions of each entity.