Resources

Chile’s Open Finance System: Your Guide to Get Started

Milestone to reach goal or success target, strategy to progress achievement, leadership planning or advancement, improvement step to mission objective, businessman on mountain looking for next target.
Structure

An Ozone API & Finerio Connect Article

Most Open Finance debates in Latin America still centre on what the rules will say, but not Chile. The Sistema de Finanzas Abiertas (SFA) is defined in law, its technical annex is published, and every deadline that matters is already counting down. What’s left isn’t interpretation, it’s execution.

Ozone API and Finerio Connect have been tracking Chile’s framework alongside our live work in Colombia and Guatemala, and Chile stands out for a simple reason: it’s the most complete technical specification in the region today. That completeness changes the nature of the decision facing banks, insurers, and fintechs operating there. This isn’t a market to wait and see. It’s a market to plan and build, and the time starts now.

The Legal Stack

Three instruments built the SFA:

  • Law N°21.521 (the FinTech Law, 2023) created the SFA and, under Article 18, defined who must participate.
  • NCG N°514, published by the CMF on 3 July 2024, set the operating rules and started the regulatory clock.
  • NCG N°569 (2026) amended NCG 514: it added Technical Annex N°3, pushed the effective date from 24 to 36 months out, and introduced a pilot period with simplified participation and softened enforcement.

The effective date that came out of that amendment is 3 July 2027. Every subsequent deadline in the SFA counts from that day.

The Real First Milestone

Here’s the detail that changes planning horizons: the technology sandbox and Participants Directory are expected to go live around October 2026, roughly nine months before the SFA takes effect. That date is derived from the regulation’s timelines rather than stated outright by the CMF, so treat it as a working estimate, not a confirmed one. Either way, it means the practical starting gun fires well before mid-2027.

Two Groups, Two Timelines

The SFA splits obligated entities into two groups, covering 82 entities in total.

  • Group 1 (42 entities): banks established in Chile, foreign bank branches, and credit or prepaid card issuers. They must file their roster application within 60 days of the effective date, around September 2027, and meet API deadlines set 5 to 18 months after that date.
  • Group 2 (40 entities): payment card operators, savings and credit cooperatives, insurers, mortgage loan agents, mass credit placement companies, fund managers, stockbrokers, settlement houses, and registered financial service providers. Their roster window is 15 months, with API deadlines 20 to 30 months out. Entities certifying fewer than 100,000 unique customers can use a simplified participation track: a single API, no consent panel, and no requirement for FAPI 2.0 certificates or incident reporting.

The framework defines four roles: IPI (information provider institution), IPC (an account-provider subset of IPI), PSBI (information-based service provider), and PSIP (payment initiation service provider). Being an IPI is mandatory for every Article 18 entity. Acting as a recipient, PSBI or PSIP, is a business choice made through self-registration.

Estimated DateMilestoneGroup
~ October 2026Technology Sandbox and Participant Directory available for preliminary testing, nine months before the effective dateAll
July 3, 2027Enter into force of the SFA. Formal start of the regime and the computation of all subsequent deadlinesAll
~ September 2027Expires the 60-day deadline to submit the application for inclusion in the NominaGroup 1
December 3, 2027Terms and Conditions and Support Channels (5 months)Group 1
April 3, 2028Data of individuals: enrollment, historical positions, transactions, and current products (9 months)Group 1
July 3, 2028Data of legal entities (12 months) and initiation of payments by individuals, single payment (12 months)Group 1
September 3, 2028Payment Initiation of Natural Persons, Recurring (14 Months)Group 1
October 3 to November 3, 2028Payment Initiation of Legal Entities with Single Mandate, Single Payment, and Recurring (15 and 16 Months)Group 1
December 3, 2028 to January 3, 2029Payment Initiation of Legal Entities with Multiple Mandates, Single Payment, and Recurring (17 and 18 Months)Group 1
March 3, 2029Terms and Conditions and Support Channels (20 months)Group 2
July 3, 2029Data of individuals. In insurance, individual policies (24 months)Group 2
November 3, 2029Insurance companies: large-scale policies for individuals (28 months)Group 2
January 3, 2030Data of legal entities (30 months)Group 2

Top Technical Spec in LATAM

Technical Annex N°3 leaves little to guess at:

  • Security: FAPI 2.0 with Message Signing for non-repudiation, OAuth 2.0 and OpenID Connect, TLS 1.3 with mTLS (chosen over DPoP and private_key_jwt), and X.509 v3 Extended Validation certificates under a two-layer CA.
  • Data: seven mandated data sets, with 24 months of history for financial positions and transactions. Transaction data must land in the system within 5 minutes of appearing on the institution’s own channels, which rules out nightly batch loads entirely.
  • Service levels: information APIs need 95% daily and 99% monthly availability with processing under 4,000ms at the 95th percentile. Payment APIs are tighter: 95%/99.5% availability and under 800ms. Traffic caps sit at 10 TPS to the recipient set for information APIs and 10 TPS uncapped per minute for payments, recalculated after year one based on actual demand.
  • Consent: a 36-month maximum duration (90 days for single scheduled payments), a free consent-management dashboard with five years of visibility, and revocation that must reach the third party within 5 minutes over webhook. Pre-ticked boxes and manipulative consent design are explicitly banned.

Reporting to the CMF doesn’t end at go-live. Entities file monthly availability, activity, customer-count, and maintenance reports, report incidents within 30 minutes of detection, and run annual data-quality testing. The SFA is a permanent operating obligation, not a project with an end date.

The Certification Bottleneck

Group 1’s roster application, due roughly two months after the effective date, requires two independent third-party certifications already in hand: a functional test report and a security-profile implementation certificate. Certification takes time, and it can’t be shortcut by outsourcing the build. The regulation is explicit that the IPI or IPC remains solely responsible to the CMF even when a vendor does the development work.

There’s also a graduated path to full enforcement: a voluntary pilot, then a mandatory 60-day pilot with SLAs and traffic limits not yet enforced, then six months of mitigated exigibility (90%/95% availability, looser latency), and only then the final regime.

Payment initiation, via the PSIP role, is staggered further out, from July 2028 to January 2029, depending on the type of payer and payment.

Decisions in Q4 2026

Work backward from the certification requirement and the picture is clear: the roster deadline lands around September 2027, and the two certifications behind it have to be finished before that date. That means the certification path itself needs to start well before then, which puts the real decision point at the 2027 budget cycle, running September to November 2026.

For a Group 1 or Group 2 entity, that’s a matter of months away, not years. Chile has already answered the “what will the rules say” question. What’s left is choosing a platform and a partner, and starting the clock.

Ozone API and Finerio Connect are working with institutions across Latin America  on exactly this transition, from framework to functioning infrastructure.

How Ozone API and Finerio Connect Can Help

Ozone API and Finerio Connect split the work along the same line this market demands. Ozone API supplies the standards-compliant platform, built by the original architects of the UK Open Banking standard and already FAPI-certified, so the FAPI 2.0, mTLS, and sub-4,000ms latency requirements in Technical Annex N°3 are met by the platform itself rather than built from scratch. Finerio Connect brings the regional deployment experience, running live Open Finance ecosystems in Colombia, Chile, and Guatemala ahead of their own regulatory deadlines, and applies that experience to the specific bottleneck Chile presents: the two independent certifications a Group 1 entity needs in hand before its roster application. Together they get an entity from platform selection to certification-ready and operational inside the 2027 budget-cycle window, not after it closes.

Speak to the team today to get started.

Recommended articles

Business milestones or achievement to reach goal or success, progress development, vision to see target destination, step to success, businessman look on telescope to see success trophy milestone.
Resources

Colombia’s Open Finance Roadmap: Moving from Mandate to Operational

An Ozone API & Finerio Connect Article The shift in Colombia’s regulatory framework from an optional model to a mandatory requirement was paramount in setting clear, unified expectations across the entire financial ecosystem. With Open Finance officially backed by law since April 2026, the market’s focus has now turned to the critical transition from legal...

Ozone API and Finerio Connect
25, Aug 2026
Business crossroad, decision to choosing choice, success direction challenge, right or wrong opportunity, option, alternative selection businessman thinking make decision to choose business direction.
Resources

A Look at Peru: Two Open Finance Paths at Once

An Ozone API & Finerio Connect Article Peru is a market in the region where the final rulebook hasn’t been shared yet, and that’s precisely what makes it different. Ozone API and Finerio Connect track Chile, Colombia, and Peru as three distinct paths to the same destination, and Peru has only recently finished allowing market...

Ozone API and Finerio Connect
25, Aug 2026
Protection shield to protect from security threat, safety risk or hazard crisis chance, business resilience to win and survive, defense trust control, businessman run with protection shield strength.
Resources

What is FAPI? Financial-Grade API Explained

FAPI is the OpenID Foundation’s security profile for OAuth 2.0 and OpenID Connect, purpose-built for APIs that enable access to financial accounts to ensure the security model is “bank grade”, for example to access sensitive financial data, or to initiate transactions . In other words, it takes the two protocols and removes the insecure choices....

Ozone API
29, Jul 2026