Argentine Open Finance Profile (PAFA)
Eber Bezzone 15 min read
PAFA is an UNOFFICIAL initiative aimed at providing a technical and conceptual framework for deploying the open finance system in Argentina.
1 · Summary
Decree 353/2025 created the Open Finance System (Sistema de Finanzas Abiertas, SFA) and, to date, it remains unregulated [1]. The Central Bank of the Argentine Republic (BCRA) is the body in charge of issuing that regulation so it can be implemented. Recently, press reports [20] have described a “minimum viable product” (MVP) that is reportedly being tested and could be live with a few use cases, including communication with ARCA and express consent through Clave Fiscal.
Whatever progress the BCRA may be close to rolling out, the institution has so far not published any official communication with dates or technical specifications.
After months of technical research, looking at how other jurisdictions implemented their systems, regulations and standards, this proposal seeks to extrapolate those examples to the Argentine reality, in order to publish a framework that responds to the needs and challenges the Argentine jurisdiction may face when implementing it.
A profile is neither a regulation nor a product: it is a set of technical decisions and a selection of standards that Argentina should look at with particular interest when it builds its own framework.
With the aim of contributing information and knowledge to the field, the decision was made to start developing and open to debate an Argentine Open Finance Profile (Perfil Argentino de Finanzas Abiertas, PAFA).
This proposal is based on decisions other jurisdictions have already implemented successfully and on the regulations the BCRA has already published. The goal is to accompany the upcoming regulation with a point of view, mainly technical, on how to implement it.
2 · Where things stand
In its 2024 global survey, the Cambridge Centre for Alternative Finance (CCAF) at the University of Cambridge classified Argentina under the market-led approach, in the “voluntary” subtype: the State lets the market decide, with no material government initiatives [16].
On 22 May 2025, Decree 353/2025 was issued, naming the BCRA as the body that must “define the parameters, standards and requirements” that SFA participants will have to meet [1]. However, defining the requirements and operating the infrastructure are two different functions, and the decree only assigns the first.
Now, although to date there is neither a regulation nor a published roadmap, the BCRA, true to its habit of issuing “Circulars” (regulatory instruments that communicate the institution’s rules, decisions and provisions), has recently published rules that, while not declared part of the open finance ecosystem, all point in that direction.
One example is the registry of participants: the BCRA publishes the Registry of Payment Service Providers by category, with a formal registration procedure and a certificate with an RPSP number [9] [10]. The obligation to identify the account holder exists: article 25 of UIF Resolution 14/2023 requires, for remote identification, rigorous biometrics that can be stored and audited, and it has applied since 2023 to every entity within the perimeter, regardless of open finance [2].
There is also a precedent of PKI (public key infrastructure for digital identity) operating at national scale: ARCA’s web services, where the X.509 certificate works as a “digital passport” that authenticates the entity, while authorisation for each service resides in a separate registry [13]. Those who have integrated electronic invoicing have already worked with this scheme.
The BCRA’s consolidated text on technology risk requires encryption and protection of authentication factors, but it is PKI-agnostic and mentions no technical registry [14]. For its part, the Transferencias 3.0 interoperability document identifies administrators by a two-letter prefix, without specifying mutual authentication [12]. This means much of the information needed to run the system is already available and public. But a registry a person reads is not necessarily a directory a bank can query. So while participants can be identified, there is currently no way for them to authenticate securely.
PAFA proposes an open finance profile split into five layers, each aimed at solving a specific challenge of the system being implemented. A complementary view starts from the actors: identifying the ecosystem’s participants unambiguously (see section 4).
3 · Ecosystem architecture
When analysing the architecture of an open finance system, five layers can be identified (figure 1), each interacting closely with the layers beneath it. Each layer should answer one of these questions: who are the participants and how do they prove it? How does the account holder authorise, and how does that authorisation become a technical permission? What data is exposed? How do we know whether the system works? Who decides all of the above?

Figure 1 · The layers of the ecosystem
It is worth stressing that the final decision on this rests with the regulator; in the Argentine case, the BCRA.
Even so, the Argentine State has the advantage that other jurisdictions have already implemented secure, proven open finance systems based on international standards, which is why this profile ventures a formal proposal.
Layer 1: Identity and trust between participants
This layer seeks to answer the question: who are the participants and how do they prove it?
It covers the participant directory, roles, certificates and certification authorities (CAs), client onboarding and the secure channel they use to communicate. In other words, how two entities that do not know each other prove who they are to the rest, and what permissions they have as entities to operate in the ecosystem.
Layer 2: Authentication, consent and authorisation
Unlike the previous one, this layer deals with strong authentication of the account holder, consent as a resource with a lifecycle (how long it lasts, how it is revoked, what it can see), the OIDC/OAuth flow that turns that consent into a technical permission, the tokens that must circulate, and the revocation of those consents. It also focuses on specifying what should be notified to the other participants. This layer defines how the account holder authorises, and how that authorisation becomes a technical permission.
Layer 3: Resources
Once entities and users have proven who they are and what permissions they hold, the entities need to start sharing data. This layer tries to spell out which data to share, the field names, and what the responses from the different entities should be. Unlike the others, this layer will be in constant change, and it depends strictly on the flows the regulator enables as part of the open finance ecosystem.
Layer 4: Observability
One of the least developed layers in some current ecosystems is “observability”. The 2026 report by the Cambridge Centre for Alternative Finance (CCAF), Financial Innovation for Impact (Fii) and the Bank for International Settlements (BIS) on open finance in emerging economies devotes an entire chapter to this dimension and its importance. The report recommends building the data infrastructure to measure from the very start, long before results can be observed [17]. The same chapter stresses the importance not only of monitoring technical metrics to assess the ecosystem’s “technical health”, but also of defining and assessing policy metrics, in order to evaluate whether the SFA’s policies achieve the impact they pursue.
Layer 5: Governance
Decree 353/2025 makes it clear that the body in charge of regulating the open finance system will be the BCRA. Hence, the answers to who gets in, who decides and who is accountable depend on a BCRA regulation. While the initial list of participants could be that of the PSPs (with all their subcategories), what each one may do and how it must operate still depends on the specification the BCRA has to issue.
A cross-cutting layer: audit
One layer runs across all the others. This section seeks to answer how what happens inside the ecosystem should be recorded: if a transaction the account holder does not recognise shows up, or data turns up where it should not be, how do you prove who did what. Governance assigns liability, but it assigns it on evidence the ecosystem should hold, which is why what has to be auditable must be specified.
The 2026 report mentioned above devotes another entire chapter to liability: the models that specify who is responsible for a failure depend heavily on the audit trails participants will keep, and without that attribution the responsible party cannot be identified [17].
Layer 1 attributes each key to an entity in the directory so it can be identified. Layer 2 decides which messages travel signed, a problem FAPI has already solved and standardised for the authorisation flow [15]. Layer 4, in turn, keeps the trail in a way that cannot be tampered with. And layer 5 says who should be accountable, and how, according to what that trail shows.
4 · The actors in the ecosystem
The names of the entities taking part in the ecosystem change from one jurisdiction to the next. To keep a consistent nomenclature across the documents, generic names are proposed for the work. In international texts, the party that hands over data is called the “data holder”, ASPSP or transmitter, and the one that receives it the “data recipient”, TPP or receiver [16].
Argentina is no exception: the BCRA publishes the Registry of Payment Service Providers by category (payment account provider, acquirer, QR administrator, initiator, aggregator, ATM network, electronic transfer network, non-bank collection) [9]. However, what role each of these categories will play within the SFA is part of what the BCRA has to regulate.
In this sense, a transmitting entity (entidad transmisora) is the one that holds the data and transmits it to the entity that requests it; for example, a bank or a digital wallet. The receiving entity (entidad receptora) is the one that requests that data and processes or uses it to show it to the account holder (titular), who previously consented to the transmitting entity sharing their information with the receiving entity (figure 2).

Figure 2 · The flow: account holder, receiving entity and transmitting entity
Three actors do not appear in that flow, but they hold it up (figure 3). The directory is the ecosystem’s technical registry: who is a participant, with which roles, in what status and with which keys; it is what a machine queries at the moment of sharing data, to check that the requesting organisation is valid. The certification authority (CA) issues the certificates participants use to prove they belong to the ecosystem. Finally, the cornerstone of the system: the regulator, which in Argentina is the BCRA, by decree.

Figure 3 · The trust infrastructure: BCRA, CA, directory and participating entities
It is worth noting that, in some jurisdictions, the role of directory and ecosystem orchestrator, as well as the CA, can be performed by a private company. What we call here the transmitting and receiving entity is instituição transmissora e receptora in Brazil, ASPSP and TPP in the United Kingdom, and data holder and data recipient in Australia. The directory and the CA also have their own names in each; in Australia, moreover, the CA is endorsed by the regulator itself: mTLS certificates are issued by the ACCC CA, operated by DigiCert [18].
5 · Learning from the past
Argentina seeks to formally regulate its open finance system today, almost ten years after the introduction of what was one of the first “Open Banking” regulations, in the United Kingdom. As the CCAF rightly points out in its 2024 report, although Argentina did not formally regulate its open banking system, it let the market drive those developments and accompanied them with specific regulations that allowed the open banking ecosystem to develop in the country.
One example from this year is the formalisation of “Banking as a Service” in Communication “A” 8432 [21], issued on 30 April 2026. That rule creates the “PSPCP as a Service” figure and grants a 90-calendar-day adjustment period.
However, since Decree 353/2025 it could be argued that Argentina is moving from a market-led approach to a regulation-led one.
In its 2024 global survey, the CCAF notes that the regulated approach offers three main advantages: it ensures standardised, uniform implementation; it is the most efficient way to get data holders to actually share data; and it strengthens customers’ control over their information [16].
In terms of outcomes, regulated frameworks cover a wider range of data types in production (average score of 2.69 versus 1.75) and can be implemented around 22% faster [16].
It should be noted, however, that the same report warns that this result currently favours advanced economies with better-resourced regulators, and that in emerging economies a mandatory regime requires real enforcement capacity.
This proposal looks closely at countries that have already implemented their open finance systems with a “regulated” approach, as well as at the reports published by the CCAF. Some takeaways from the countries analysed:
Brazil: An open finance system with its own directory and CA from day one, with authorisation coupled to the certificate. Operation of the infrastructure moved in January 2025 from the Central Bank to the Associação Open Finance without changing the standard [3]. It is a precedent that the operator is an axis independent of the profile, and of what it costs to put governance on the technical critical path.
United Kingdom: One of the first jurisdictions to implement open banking. This case predates PSD2 (the regulation of the European open finance system) and changed trust anchor twice (OBIE certificates, then eIDAS, and the OB-certs again after Brexit) without rebuilding its ecosystem [8]; its dynamic registration explicitly accepts any anchor [7]. It is the precedent that decoupling the certificate from the authorisation to operate pays off by avoiding lock-in to any particular provider.
Australia: A case in which the register is maintained by the regulator itself, the ACCC [4]. It regulates both forms of outsourcing, and in both the accredited party is accountable [5] [6]; and it handles propagation of the directory’s status by polling, at two frequencies [11]. It is one of the precedents that the participant is the entity, never the provider. It is also one of the few jurisdictions that implement a single, concrete model for propagating directory status.
Chile: In Chile’s case, the CMF’s General Rule 514 prescribes the factors used to authenticate the account holder: strong authentication requires two or more independent elements of knowledge, possession and inherence [19]. Argentina, by contrast, already has a regulation for that obligation and a body in charge of its operation (UIF Resolution 14/2023 [2]). Chile is thus a case in which a jurisdiction had to regulate this within its own open finance system. That is why PAFA deliberately leaves this point out of its specification, on the understanding that the UIF resolution already covers it.
Colombia: In April 2026, Decree 0368 made the open finance system —voluntary since 2022— mandatory, and left the definition of its technical standards to the Superintendencia Financiera (SFC) [22]. The SFC requires compliance with FAPI 2.0 and authorisation over OAuth 2.0, with mutual authentication through mTLS [23]. Chile reached the same place: the CMF’s General Rule 569, of June 2026, added the technical annex of its system and requires FAPI 2.0 certification from every participant, except those opting into simplified participation [24]. Two jurisdictions in the region, with recent rules, chose the same OpenID Foundation security profile. It is the most direct regional precedent for PAFA’s layer 2, and an argument for Argentina adopting FAPI 2.0 rather than a profile of its own.
6 · Conclusions and next steps
While requiring an advanced security profile such as FAPI 2.0 may pose an initial barrier to entry for less technologically mature entities, early adoption of a unified standard prevents future fragmentation of the ecosystem, mitigates security gaps and drastically reduces compliance and audit costs in the long run.
Facing the challenge of regulating its open finance system, Argentina has two main advantages:
-
It is not starting from scratch. Although Argentina was considered a jurisdiction where open banking was market-driven, the State, through the BCRA and other bodies such as the UIF, has accompanied the process over the years with regulation. A concrete case is UIF Resolution 14/2023, which already regulates remote identification of the account holder [2]. A counterexample is Chile, a country that, like Argentina, is taking its steps towards an open finance system and did not have that kind of regulation. That means its profile has to cover more details than Argentina needs to.
-
The CCAF, in its June 2026 report, notes that roughly 16 jurisdictions worldwide have already passed laws implementing Open Finance proper, and focuses on 9 emerging economies going through that process [17]. This puts us in an advantageous position to look outward and learn from other countries’ successes and mistakes, in order to adapt and implement a sound, efficient Argentine Open Finance Profile.
This report tries to give an introduction to what PAFA is, how it is being worked on and what empirical evidence is used to back its decisions. To the same end, the next steps include developing each of the ecosystem’s layers and a public repository where the decisions the profile raises can be laid out, shared and debated.