Snap Compliance
Contact us

Language

EN ES PT
Start free
Regulatory framework · Chile

Compliance in Chile, from Law 19.913 to Law 21.719, with the evidence ready for every authority

For banks, insurers, brokers, pension fund administrators, cooperatives, fintechs and every company: what Law 19.913 and the UAF require, the crime prevention model of Law 20.393 after Law 21.595, personal data Law 21.719 and cybersecurity Law 21.663, and how Snap Compliance turns them into a program that works.

At a glance

The framework in six pieces

Framework law

Ley 19.913

Creates the Financial Analysis Unit and criminalizes money laundering. Its article 3 lists who must report: from the financial system to notaries, real estate brokers, car dealers, jewelers and the firms registered under the Fintech Law.

Financial intelligence

UAF · Circular N° 62

The UAF receives reports through its Reporting Entities Portal. Its Circular No. 62, in force since June 1, 2025, brought its instructions for the private sector into a single rule and repealed Circular No. 49 and those that followed.

Financial supervision

CMF

Supervises banks, insurers, brokers, fund administrators and the cooperatives under its oversight. Its Circular No. 2368 of February 2026 aligned chapter 1-14 of the RAN with Circular No. 62.

Corporate criminal liability

Ley 20.393 · Ley 21.595

Since September 1, 2024, a legal entity is liable for economic crimes committed in the course of its activity when they were made easier by the lack of an effectively implemented prevention model.

Personal data

Ley 21.719 · Decreto 662

Replaces the Law 19.628 regime from December 1, 2026 and creates the Personal Data Protection Agency. Decree 662 regulates the infringement prevention model and its certification.

Cybersecurity

Ley 21.663 · ANCI

Applies to providers of essential services, including banking, financial services and means of payment, and requires them to report incidents to the National CSIRT with an early warning within three hours.

Who is obligated

Four laws, four sets of obligated parties

Each law reaches a different group: Law 19.913, the entities it lists; Law 20.393, every legal entity; Law 21.719, anyone who processes personal data; and Law 21.663, anyone who provides an essential service. The same entity is often in all four.

Ley 19.913 · art. 3

Anti-money laundering

Article 3 entities appoint a compliance officer, apply due diligence, identify the beneficial owner from a 10% stake or through effective control, treat PEPs as such until at least one year after leaving office, report suspicious transactions as soon as they detect them and keep for five years a record of cash transactions above USD 10,000.

Prevention rules
Circular UAF N° 62 · RAN 1-14
Supervisor
UAF · CMF

How Snap Compliance solves it

Ley 20.393 · arts. 3 y 4

Corporate criminal liability

It covers every private-law legal entity and State-owned companies and universities. An adequate, effectively implemented crime prevention model exempts it: identified risk activities, protocols with secure reporting channels and internal sanctions written into employment contracts, a person in charge with independence and resources, and periodic assessments by independent third parties.

Prevention rules
Ley 21.595
Supervisor
Ministerio Público

Ley 21.719 · Ley 19.628

Personal data protection

From December 1, 2026 it binds every data controller, with no size threshold: legal bases, responses to data subjects' requests within 30 calendar days, security measures, notice to the Agency of security breaches without undue delay, and impact assessments for high-risk processing. The infringement prevention model is voluntary and, once certified, mitigates liability.

Prevention rules
Decreto 662 de Hacienda
Supervisor
Agencia de Protección de Datos Personales

How Snap Compliance solves it

Ley 21.663 · arts. 4, 8 y 9

Cybersecurity

It requires institutions that provide essential services to prevent, report and resolve incidents. Operators of vital importance, designated by the ANCI by resolution, must also have an information security management system, certified continuity plans, regular exercises and a cybersecurity delegate.

Prevention rules
Decreto 295 · Decreto 285
Supervisor
ANCI · CSIRT Nacional

How Snap Compliance solves it

By sector

What each sector has to do

The four laws intersect differently in each industry. Start with yours: which law binds it, which rule develops it and who supervises it.

Ley 19.913 · Ley 21.663

Banks and card issuers

Banks, financial institutions and issuers and operators of credit and prepaid cards are obligated entities under Law 19.913, and banking is an essential service under Law 21.663.

  • They report suspicious transactions to the UAF as soon as they detect them and, every month within the first ten business days, cash transactions above USD 10,000; if there were none, they file a nil report.
  • Through its Circular No. 2368 of February 2026, the CMF aligned with Circular No. 62 chapter 1-14 of the RAN, which governs their anti-money laundering and counter-terrorist financing. The same circular updated Circular No. 1 for non-bank card issuers.
  • They report cybersecurity incidents to the National CSIRT: an early warning within three hours, an update within 72 hours —24 for operators of vital importance— and a final report within fifteen days. The first list of operators of vital importance, of December 2025, includes banking, financial services and payment institutions.
  • Since December 2020, chapter 20-10 of the RAN has governed their information security and cybersecurity management.
Prevention rules
RAN 1-14 · RAN 20-10 · Circular UAF N° 62
Supervisor
CMF · UAF

Solutions for this sector

Ley 19.913 · art. 3

Securities market and funds

Stock exchanges, stockbrokers, securities agents, general fund administrators and investment fund administrators are obligated entities under Law 19.913.

  • Besides UAF Circular No. 62, they apply Circular No. 1809 of the former Superintendency of Securities and Insurance, still in force with its amendments and enforced by the CMF.
  • They report cash transactions above USD 10,000 every quarter, by the 10th of January, April, July and October, and suspicious transactions as soon as they detect them.
  • General fund administrators are among the banking, financial services and payment institutions in the first list of operators of vital importance under Law 21.663.
Prevention rules
Circular SVS N° 1.809 · Circular UAF N° 62
Supervisor
CMF · UAF

Solutions for this sector

Ley 19.913 · art. 3

Insurance

Insurance companies are obligated entities under Law 19.913 and report their suspicious and cash transactions to the UAF.

  • Circular No. 1809 of the former SVS sets their anti-money laundering and counter-terrorist financing rules; since February 2024, CMF rule NCG 325 includes those risks in their risk management system.
  • They report cash transactions above USD 10,000 every quarter, like the rest of the non-bank financial sector.
  • The first list of operators of vital importance under Law 21.663 includes insurance companies.
Prevention rules
Circular SVS N° 1.809 · NCG 325
Supervisor
CMF · UAF

Solutions for this sector

Ley 19.913 · art. 3

Pension fund administrators

Pension fund administrators (AFPs) are obligated entities under Law 19.913 and report their suspicious and cash transactions to the UAF.

  • They apply UAF Circular No. 62; to identify the beneficial owner, UAF Circular No. 36 remains in force for their sector.
  • Law 21.663 lists the administration of social security benefits among essential services, and the second list of operators of vital importance, of July 2026, covers that sector.
Prevention rules
Circular UAF N° 62 · Circular UAF N° 36
Supervisor
UAF

Solutions for this sector

Ley 19.913 · art. 3

Savings and credit cooperatives

Savings and credit cooperatives are obligated entities under Law 19.913, with their own CMF rules.

  • CMF Circular No. 123 governs their anti-money laundering program; the CMF aligned it with UAF Circular No. 62 in February 2026.
  • The first list of operators of vital importance under Law 21.663 includes savings and credit cooperatives.
  • Like every private-law legal entity, they are criminally liable under Law 20.393 if an economic crime was made easier by the lack of an effective prevention model.
Prevention rules
Circular CMF N° 123 · Circular UAF N° 62
Supervisor
CMF · UAF

Solutions for this sector

Ley 19.913 · Ley 21.521

Fintechs and payment services

Firms registered with the CMF as financial service providers or payment initiation service providers are obligated entities since the Fintech Law, Law 21.521.

  • Circular No. 62 requires them to apply the travel rule —originator and beneficiary information in transfers— since July 1, 2025.
  • Issuers and operators of prepaid cards and similar payment systems are also obligated entities, and means of payment are an essential service under Law 21.663.
  • If they carry out automated profiling with significant legal effects or process data on a large scale, Law 21.719 requires an impact assessment.
Prevention rules
Circular UAF N° 62
Supervisor
CMF · UAF

Solutions for this sector

Ley 19.913 · art. 3

Real estate, notaries and registrars

Real estate brokers, property management companies, notaries and registrars are obligated entities under Law 19.913.

  • They report cash transactions above USD 10,000 every six months, by January 10 and July 10, and a nil report if there were none.
  • They appoint a compliance officer who deals with the UAF, identify their clients' beneficial owners and report suspicious transactions as soon as they detect them.
Prevention rules
Circular UAF N° 62
Supervisor
UAF

Ley 20.393 · Ley 21.719 · Ley 19.913

Companies in the real economy

No company is outside Law 20.393 or Law 21.719: the first reaches every private-law legal entity and the second, anyone who processes personal data.

  • Since Law 21.575 of 2023, car dealers, vehicle rental companies, dealers in precious metals, jewelry and precious stones, and arms manufacturers and sellers are obligated entities under Law 19.913.
  • Free-zone administrators and users, customs agents and auction houses also report to the UAF.
  • The crime prevention model of Law 20.393 is sized to the company's business, size, complexity and resources, and its protocols are written into employment and service contracts, including those of its top executives.
Prevention rules
Ley 21.595 · Decreto 662 · Ley 21.575

How we solve it

From the rules to the evidence the supervisor asks for

Reading the rules is the first step. What a supervisor reviews is a program that works and leaves evidence.

Fortaleza AML Program

We implement the prevention program with your team —technology, training and documentation— and organize the evidence for the supervisor. Institutions that complete the program receive the Fortaleza AML seal. It is a Snap Compliance seal, not a certification.

Law 21.719 Toolkit · Chile

38 editable deliverables in eight phases, from the processing inventory to the certification file for the infringement prevention model. While it is being released, its free self-assessment shows how far you have to go.

See the toolkit

Compliance OS

Screening of customers and beneficial owners against lists and news, risk matrices and AML monitoring on a single platform. Your team decides; the platform does the heavy lifting.

See the platform

Inside the platform

What you will find in Snap Compliance

This is how Snap Compliance tracks your portfolio's risk, closing by closing: from the full picture to the client who moved and the reason behind every change.

Risk Trajectory: clients escalating, recently deteriorating, oscillating and stable at the high level, and the portfolio by risk level over twelve closings View the full screen (opens in a new tab)

How your portfolio moved

Twelve risk-matrix closings in a single view: how many clients moved to high risk, how many keep escalating without stepping back, and from which closing a new methodology applies.

Client list with each client's twelve-closing trajectory, score, pattern and current risk level View the full screen (opens in a new tab)

Who to look at today

Every client with their twelve closings and a pattern that sets the priority: sustained escalation, recent deterioration, oscillating, or stable at the high level, a candidate for enhanced due diligence. The list exports to Excel in one click.

Client detail: the score at each closing with the methodology change marked, and every level change with the subfactor that drove it View the full screen (opens in a new tab)

What moved each client

The score at every closing, the subfactor that changed the level, and in which month. Each move opens its justification in Client Reclassification.

AML Monitoring

Snap Compliance screens with fictitious data.

Frequently asked questions

What we are asked most about compliance in Chile

Who are the obligated entities under Chile's Law 19.913?

Those listed in its article 3: banks and financial institutions, card issuers and operators, exchange houses, stockbrokers, fund administrators, insurers, pension fund administrators, savings and credit cooperatives, casinos, notaries, registrars, real estate brokers and property management companies, among others. The Fintech Law added the firms in the CMF's registers, and Law 21.575 of 2023 added car dealers, jewelers and precious metal dealers. With Due Diligence, every client is identified and has its risk calculated.

What did UAF Circular No. 62 change?

Since June 1, 2025 it brings the UAF's instructions for the private sector into a single rule, and it repealed Circular No. 49 and those that followed. It sets the beneficial owner as whoever holds 10% or more of the capital or voting rights, or exercises effective control; it widens the categories of politically exposed persons and extends that status until at least one year after leaving office. Scan Agent checks every client and beneficial owner against lists and news.

When are suspicious and cash transactions reported to the UAF?

Suspicious transactions, as soon as they are detected, through the Reporting Entities Portal and without telling the client: article 6 of Law 19.913 forbids it. Cash transactions above USD 10,000 are recorded and kept for at least five years. Banks report them monthly; the rest of the financial sector, quarterly; and the non-financial sector, every six months, with a nil report if there were none. AML Monitoring alerts you when a client moves outside its profile.

What fines does the UAF impose for breaching Law 19.913?

Article 20 sets a warning or fines of up to 800 UF for minor breaches, up to 3,000 UF for less serious ones —such as failing to keep the cash transaction record— and up to 5,000 UF for serious ones, including failing to report suspicious transactions. If a breach of the same kind is repeated within twelve months, the fine can triple, and it can also reach the directors or representatives involved. AML Monitoring keeps the evidence of every alert and how it was resolved.

What did Law 21.595 change in corporate criminal liability?

Since September 1, 2024, Law 20.393 makes a legal entity liable for all the crimes in articles 1 to 4 of the Economic Crimes Law, whether or not that law treats them as economic crimes, as well as terrorist financing and human trafficking. The crime no longer has to benefit the company: it is enough that it is committed in the course of its activity and made easier by the lack of an effectively implemented prevention model. Risk Management keeps the matrix of those risks.

What must a crime prevention model include under Law 20.393?

Article 4 requires four elements, to the extent the entity's business, size, complexity and resources call for: identifying activities with a risk of crime; protocols and procedures with secure reporting channels and internal sanctions, communicated to everyone and written into contracts; one or more people in charge with independence, powers and resources; and periodic assessments by independent third parties. The Anonymous Whistleblowing Channel provides the secure channel, and Risk Management, the identification of risk activities.

When does Law 21.719 take effect and what fines does it set?

Its amendments to Law 19.628 take effect on December 1, 2026; until then, the current text of Law 19.628 applies. The Personal Data Protection Agency can fine up to 5,000 UTM for minor breaches, 10,000 for serious ones and 20,000 for very serious ones. Repeat offenses allow up to triple, and a company that is not small and reoffends with a serious or very serious breach risks up to 2% or 4% of its annual revenue. The free Law 21.719 Assessment shows your gaps.

What is the Law 21.719 infringement prevention model and what does Decree 662 regulate?

It is the voluntary compliance program of article 49: a data protection officer with means and powers, a description of the data processed, risk activities, protocols, internal reporting and internal sanctions. Once certified by the Agency, it mitigates liability and the entity is listed in the National Register of Sanctions and Compliance. Decree 662 of the Ministry of Finance, published on September 9, 2026, regulates its implementation, its certification —valid for three years and renewable— and its supervision.

Who does cybersecurity Law 21.663 bind and how fast must incidents be reported?

Providers of essential services —including energy, telecommunications, health, and banking, financial services and means of payment— and, with extra duties, the operators of vital importance designated by the ANCI. All report to the National CSIRT: an early warning within three hours of learning of the incident, an update within 72 hours —24 for operators of vital importance— and a final report within fifteen days. Fines reach 20,000 UTM, and double that for those operators.

How does Snap Compliance help you comply with these laws at once?

With a single program and the evidence in one place. Due Diligence and Scan Agent identify clients and beneficial owners and check them against lists; AML Monitoring tracks their risk close by close; Risk Management keeps the risk matrix for crimes, data and cybersecurity; the Anonymous Whistleblowing Channel provides the secure channel Law 20.393 requires; and the Law 21.719 Assessment measures what is missing before December 1, 2026.

Would your program withstand a supervisor's review today?

We review with you where your institution stands against these rules and what it still needs to demonstrate compliance.

Talk to a specialist

Free self-assessment · Chile

How ready is your organization for Chile's Law No. 21.719?

Answer the questions that apply to your organization and see its blocking findings, its gaps by domain and its estimated exposure, with an action plan in Word. Available in Spanish.

16 domains · 45 to 90 minutes · save and resume 64 days until enforcement