The Superintendency of Banks (SB) issued a new provision that seeks to protect financial users when failures of the computer systems of financial intermediation entities (EIF) occur and that result in damage to customers.
Through Circular SB: CSB-RG-202500015, the SB establishes that entities may not apply charges, commissions, or late fees to users when they do not demonstrate that they offered alternative channels that functioned during the interruption. In those cases, they must exonerate the client from any cost generated by unexecuted or delayed operations, or, alternatively, make refunds automatically, without the client needing to request it.
The circular also clarifies that users must comply with the payment obligations contracted with their financial institution, even if the systems are disabled, provided that the institution has additional channels that allow it. To do so, it is important to stay informed through the media of their bank.
“When the entity, in the event of system failures, cannot demonstrate that the other channels enabled for users were available and fully operational, the affected users must be compensated by refunding charges, commissions, late payment interest, or other contractually agreed costs, generated or applied as a result of said failure,” according to the circular.
With this regulation, the SB reinforces the right of users to receive clear, precise, and timely information. Going forward, the EIFs must implement a communication protocol for users that is activated in case of interruptions that affect access to their contracted products and services. When these failures exceed two hours, the entities will be obliged to notify their clients of the situation, indicating which services are affected, the causes of the incident, and the estimated resolution time.
The new regulation also stipulates that, in the case of scheduled maintenance affecting the availability of services, users must be informed at least 24 hours in advance. This communication must include details about the channels or services that will be offline, the estimated downtime, the available options, and the contact methods enabled for assistance. The entity must also notify the supervisory body at least five days in advance.
When the service interruption is a consequence of a cyberattack, the affected entities must notify the Cybersecurity Incident Response Center of the Payments System (SPRICS), a body created by the Monetary Board through the Cybersecurity and Information Security Regulation, for the prevention, coordination, and management of incidents affecting the financial sector of the Dominican Republic.
ATM Failures
Specific situations such as the retention of debit cards in ATMs are also regulated. If the reason for the retention is a failure attributable to the issuing bank or an ATM within its network, no charge for the replacement of the card may be applied to the user. Only in cases where the ATM does not belong to the bank’s network will the collection of the replacement cost be permitted, without additional penalties.
IFEs have a period of six months from the publication of this circular to comply with these provisions and, in the event of any non-compliance, will be sanctioned in accordance with the Monetary and Financial Law and the current Sanctions Regulation.





