CHILE Law and Practice Contributed by: Claudio Magliona, Bárbara Reyes and Diego Lisoni, Magliona Abogados
3. Operational Resilience in the Financial Sector 3.1 Scope of Financial Sector Operational Resilience Regulation In banking and financial matters, Chapter 20-10 of the Updated Compilation of Standards (RAN) establishes the obligation for financial institutions (mainly banks) to define an organisational structure with specialised and dedicated personnel, with the necessary powers and competencies to manage IT security and cyber - security. In addition, the function of an information security and cybersecurity officer in charge of these matters must be part of this organisational structure. The Board of Directors of banking and financial institu - tions subject to Chapter 20-10 of the RAN shall estab - lish the above and other matters in relation to their information security and cybersecurity management systems, such as: • policies for the management of information security and cybersecurity risks; • promotion of risk-awareness in terms of informa - tion security and cybersecurity; • permanent monitoring of the infrastructure con - nected with external providers, and analysis and implementation of measures to detect and mitigate potential threats to the cybersecurity of the entity; and • internal behaviour policy. There is a large number of other specific operational risk and cybersecurity regulations applicable to other entities participating in the banking and financial sys - tem – eg, mutual fund administrators; entities provid - ing fintech services, including investment advisers or alternative transaction platforms; and even enti - ties that will participate in the Open Finance System, which is being implemented gradually until 2027. Thus, Chapter 20-10 is of general application to cer - tain financial entities (banks; payment card operators and issuers) but shares several provisions with the specific regulations mentioned above.
3.2 ICT Service Provider Contractual Requirements
The Chilean regulatory landscape for Information and Communication Technology (ICT) and third-party service providers in the financial sector is primarily governed by the CMF. The core requirements are established in the Updated Compilation of Standards (RAN), specifically Chapter 20-7 on the Outsourcing of Services and Chapter 20-10 on Information Secu - rity and Cybersecurity Management. Furthermore, the Fintech Law (Law No 21.521) and its supplementary regulations, such as General Rule No 514 for the Open Finance System (SFA), impose rigorous technical and oversight duties on new technological actors. Definition of ICT Service Providers Under Chapter 20-7 of the RAN, a service provider is broadly defined as any entity, whether related to the contracting institution or not, that provides services or supplies goods and facilities to the bank. This defini - tion applies to banking institutions and payment card operators. Within the Open Finance System estab - lished by the Fintech Law, the regulation specifically identifies Information-based Service Providers (PSBI) and Payment Initiation Service Providers (PSIP) as participants that interact with traditional financial insti - tutions through Interfaced Programming Applications (APIs). Criteria for Criticality and Strategic Activities Activities are classified as strategic or critical under Chapter 20-7 of the RAN when any failure in the ser - vice provision would significantly impact regulatory compliance, business continuity, information security, or the quality of the entity’s image. Strategic criticality is also automatically triggered for any activity involv - ing the processing of data subject to banking secrecy under Article 154 of the General Banking Law. Mandatory Contractual and Oversight Requirements Financial institutions must ensure that contracts with ICT providers clearly define the rights and obligations of both parties, including measurable Service Level Agreements (SLAs) and early termination clauses. Contracts must include provisions for business con - tinuity and the ownership and confidentiality of infor - mation. It is a mandatory requirement that providers
66 CHAMBERS.COM
Powered by FlippingBook