Strengthening New Technologies in the Financial System
#### By: Dr. Luz Eneida Saldaña, attorney, Universidad del Rosario, specialist in Administrative Law and Financial Law.

Under a deadline set back in 2019, as of June 1 the instructions in External Circular Letter 029 of December 11, 2019 took effect for entities supervised by Colombia's Financial Superintendency, aimed at strengthening, facilitating, and promoting the use of new technologies that improve efficiency in delivering financial services.
This necessarily involves both regulation and oversight, since it also means strengthening the use of digital channels to deliver financial services securely and in line with international standards. Under the Circular Letter, supervised entities must:
- Meet minimum requirements for implementing and using biometrics as an electronic authentication factor, and promote its use — fingerprints or facial features, for example — as an authentication method, combined with a second authentication factor for remote transactions.
- Not require a second authentication factor for in-person transactions.
- Cross-check biometric data against the databases of the National Civil Registry, or against the supervised entity's own databases.
- Provide mechanisms letting users automatically recover any fees charged for failed ATM transactions, to be refunded within 2 business days (for transactions carried out within Colombia) or 5 business days (for transactions carried out abroad) of the transaction.
- Treat a transaction as "failed" whenever the financial consumer doesn't receive the service they requested for any reason — meaning the entity may never charge for that transaction or debit any related amount. This requirement, which includes notifying the consumer, has been mandatory since June 2021.
- Adopt the procedures needed to let their ATM network allow a single withdrawal of the maximum daily amount set by the entity based on its own risk assessment, or a lower amount set by the customer.
- Adopt security mechanisms for remote (card-not-present) transactions beyond validating the card number, expiration date, and a static verification code — such as app-based consumer authorization, dynamic CVV, tokens, and 3D Secure, among others.
- These rules also require financial entities to offer users greater protection through biometric security mechanisms at ATMs.
Do you have questions about how these new technologies apply to you? Contact us here.
Several financial institutions have been announcing this new measure — an increase in the maximum single-transaction ATM withdrawal limit — to customers on their channels, and some let customers set their own limits through the entity's online banking platform.
At Consejurídico, #WeWantToBeThere
Source: External Circular Letter No. 029 of December 11, 2019, Financial Superintendency of Colombia
El asistente jurídico digital de Jurídiconline analiza tu situación específica. La revisión inicial es gratuita.