Argentine Open Finance Profile
PAFA is a proposed technical profile for the Argentine open finance system created by Decree 353/2025.
Argentina is in the process of defining its profile. Yet today, almost 10 years after the first open banking implementations in the UK, the documentation, the technical specifications and the number of jurisdictions that have implemented it have grown steadily. This unofficial proposal does not try to write a profile from scratch: it takes the lessons of recent years, analyses and adapts them, and proposes a profile that fits.
Argentina is in the process of defining its profile. This unofficial proposal takes almost 10 years of open banking lessons from around the world, analyses and adapts them, and proposes a profile that fits.
A profile does not invent protocols: it chooses them
Decree 353/2025 creates the Open Finance System so that people can share their financial information «through their express consent» (art. 5), and makes the BCRA, the central bank, responsible for defining «the parameters, standards and requirements» that participants must meet (art. 6).
Between the decree and that regulation there is a window in which the technical decisions are still being discussed. This profile tries to answer the questions every regulator needs to ask before implementing a system like this.
It takes standards that already exist and are widely adopted worldwide (OAuth 2.0, OpenID Connect, FAPI, mTLS) and fixes the baseline every country has to set: what the directory records, who the participants are, what a certificate proves, what happens when an entity leaves the register, among others.
Without those baseline decisions, two implementations could both be correct and still be unable to talk to each other.
Decree 353/2025, full text (in Spanish) →The 5 layers of an open finance systemThe 5 layers of the system
-
1
Identity and trust between participantsIdentity and trust
Who asks and who answers: the directory, the roles, the certificates, dynamic registration and what happens when an entity leaves.The directory, the roles, the certificates and the dynamic registration of participants.
-
2
Authentication, consent and authorizationAuthentication and consent
The person: how they authorize, with what scope, for how long, and how they revoke.
-
3
Resources
The data specification itself: what is exposed about an account and under which contract. It is the largest layer and the one that most depends on which resources end up inside the open finance system.What is exposed about an account and under which contract. The largest layer.
In progress -
4
Observability
How compliance is measured: availability, latency and the report that makes them comparable.Availability, latency and the report that makes participants comparable.
In progress -
5
Governance
Who operates the register and the directory, with what level of governance and with what funding it could be built and maintained.Who operates the register and the directory, with what funding and level of governance.
In progress
Ecosystem actors
Each jurisdiction picks different names for its ecosystem. Beyond the names, the basis of these participants is the same and can be classified into 5. To present this profile in a consistent way, generic names identify each participant, understanding that each one may be one kind of company, or several.
Beyond the names each jurisdiction adopts, the participants can be classified into 5 generic roles.
-
01
Data owner
The person whose data is shared. The one who consents, and who can revoke. The owner of the data being shared.
-
02
Transmitter
The entity that holds that data and hands it over when the owner authorizes it. For example, a bank or a digital wallet.
-
03
Receiver
The entity that requests that data to provide a service or show it to the user.
-
04
Directory
The register of participants, so that each one can check the status of the others in the ecosystem.
-
05
Technology provider
Operates a participant's infrastructure. It has no identity of its own in the register: the participant is the entity.
FAQs
Does this replace the BCRA regulation?
No. The decree puts the BCRA in charge of defining the parameters, standards and requirements. PAFA proposes what they could be, and the empirical evidence behind them.
Why write it before the rule?
Because after the rule the design is no longer discussed, only compliance is. A proposal is useful while the decisions are still open.
Why not copy the standard of a mature model like Brazil's?
Each profile has its own names and fields but, more importantly, its own regulation. Much of that regulation is inherited from earlier rules. Looking at and learning from other jurisdictions is essential. Yet every decision has a local meaning that needs to be properly analysed and adapted.
Is it ready to implement?
The profile, though further along than what is published, still needs a thorough review. As each layer gets the evidence behind its decisions, its open questions will be published.
It still needs a thorough review. Each layer is published as its evidence is ready.
What is PAFA's business?
PAFA currently has no commercial purpose. The profile proposal is publicly available in the public GitHub repository, under its licence.
How can I take part or contribute?
With an issue in the repository. If it brings a precedent or a technical reason it joins the debate, and if it ends up changing a decision, the one it superseded is recorded, properly versioned.
Not everything is settled. How to take part?How to take part?
Although the profile is not official, its repository is public for analysis and debate. The open questions that still need more research, or knowledge of Argentine companies and their challenges, are put up for debate in that same repository, in its «Projects» section, so that anyone can contribute their knowledge, experience or point of view.
With an issue in the public GitHub repository, in its «Projects» section.
Contact
The profile is discussed in public. The open questions are in the repository's discussions, and any contribution, correction or question comes in as an issue.