Skip to content

Evidence request lists

Brazil Open Finance (Resolução Conjunta No. 1/2020)

Evidence request list. 31 controls, 31 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Brazil Open Finance Cap. I-II: Implementation, Definitions and Objectives

BR-OF-A1
Implementation and scope of Open Finance

Implementation. Article 1 provides that the Resolution governs the implementation of Open Finance by financial institutions, payment institutions and other institutions authorised by the Banco Central do Brasil.

Artefacts an auditor will ask for
  • Determination that the institution is in scope of Open Finance
  • Open Finance implementation plan and governance
Where this commonly fails
  • Open Finance obligations not mapped
  • Scope misjudged
BR-OF-A2
Definitions

Definitions. Article 2 defines the key terms (Open Finance, participating institution, data transmitter, data recipient, payment transaction initiator, client, consent and others).

Artefacts an auditor will ask for
  • Mapping of statutory definitions to internal roles (transmitter/recipient/initiator)
Where this commonly fails
  • Roles misclassified
  • Definitions not applied
BR-OF-A3
Objectives of Open Finance

Objectives. Article 3 sets the objectives of Open Finance, including promoting competition, financial citizenship, efficiency and innovation in the financial and payments system.

Artefacts an auditor will ask for
  • Alignment of Open Finance participation with the stated objectives
Where this commonly fails
  • Objectives not reflected in implementation
BR-OF-A4
Institutions' obligations

Institutions' obligations. Article 4 sets out the general obligations of the institutions referred to in Article 1 for the purposes of fulfilling the Resolution.

Artefacts an auditor will ask for
  • Documentation of how the institution meets its Open Finance obligations
Where this commonly fails
  • Obligations not operationalised

Brazil Open Finance Cap. III: Scope of Sharing and Participants

BR-OF-A5
Scope of data and services shared

Scope of sharing. Article 5 defines the minimum scope of sharing under Open Finance: registration (cadastro) and transaction data, and payment transaction initiation services.

Artefacts an auditor will ask for
  • Inventory of data and services shared under Open Finance
  • Mapping of shared data categories to the Article 5 minimum scope
Where this commonly fails
  • Required data/services not shared
  • Scope under-implemented
BR-OF-A6
Participants (transmitter, recipient, initiator)

Participants. Article 6 defines the categories of Open Finance participants: data transmitters/account holders, data recipients and payment transaction initiators.

Artefacts an auditor will ask for
  • Identification of the institution's participant role(s)
  • Records of role registration
Where this commonly fails
  • Participant role not identified
  • Role obligations not applied
BR-OF-A7
Registration of participation

Registration. Article 7 requires participating institutions to register their participation in Open Finance as prescribed.

Artefacts an auditor will ask for
  • Evidence of registration of Open Finance participation
  • Maintenance/update of registration
Where this commonly fails
  • Participation not registered
  • Registration not updated

Brazil Open Finance Cap. IV: Data Sharing, Consent and Security

BR-OF-A10
Data recipient and initiator obligations

Recipient obligations. Article 10 sets obligations on the data recipient or payment transaction initiator regarding the use and protection of shared data.

Artefacts an auditor will ask for
  • Controls limiting use of received data to the consented purpose
  • Protection of received data
Where this commonly fails
  • Received data used beyond purpose
  • No protection of received data
BR-OF-A12
Data use limitation and accuracy

Use limitation. Article 12 requires the data recipient to ensure shared data are used only for the consented purposes and handled accurately.

Artefacts an auditor will ask for
  • Purpose-binding controls for shared data
  • Accuracy handling of shared data
Where this commonly fails
  • Purpose creep
  • Inaccurate handling of shared data
BR-OF-A13
Payment initiation consent

Payment initiation. Article 13 sets the consent requirements for sharing of payment transaction initiation services.

Artefacts an auditor will ask for
  • Consent mechanism specific to payment initiation
  • Records of payment-initiation consents
Where this commonly fails
  • Payment initiation without specific consent
  • Consent not recorded
BR-OF-A14
Client information requirements

Client information. Article 14 sets the minimum information that participating institutions must provide to the client in connection with sharing.

Artefacts an auditor will ask for
  • Client information meeting the Article 14 minimum
  • Delivery of information to clients
Where this commonly fails
  • Minimum client information not provided
BR-OF-A15
Responsibilities in data sharing

Responsibilities. Article 15 allocates responsibilities among participating institutions involved in the data sharing.

Artefacts an auditor will ask for
  • Documented allocation of responsibilities across participants
  • Records identifying responsible parties per sharing
Where this commonly fails
  • Responsibilities undefined
  • Roles not documented
BR-OF-A16
Security measures by transmitter/account holder

Security. Article 16 requires the data transmitter or account holder to adopt security measures and authentication controls for the sharing.

Artefacts an auditor will ask for
  • Security and authentication controls for sharing
  • Protection of the sharing interface
Where this commonly fails
  • Inadequate security on sharing
  • Weak authentication
BR-OF-A17
Customer authentication procedures

Authentication. Article 17 requires customer authentication procedures and controls to be compatible with the risks of the sharing.

Artefacts an auditor will ask for
  • Risk-based customer authentication procedures
  • Strong authentication for sharing/payment initiation
Where this commonly fails
  • Authentication not risk-based
  • No strong authentication
BR-OF-A20
Confirmation of sharing

Confirmation. Article 20 requires the data transmitter/account holder (and the initiator) to request confirmation of the sharing from the client.

Artefacts an auditor will ask for
  • Mechanism to confirm sharing with the client
  • Records of sharing confirmations
Where this commonly fails
  • Sharing not confirmed with the client
  • Confirmation not recorded
BR-OF-A23
Dedicated interfaces (APIs)

Dedicated interfaces. Article 23 requires participating institutions to make available dedicated interfaces (APIs) for the sharing of data and services.

Artefacts an auditor will ask for
  • Dedicated API interfaces conforming to Open Finance standards
  • Availability/performance monitoring of interfaces
Where this commonly fails
  • No dedicated interfaces
  • Interfaces not standard-conformant
BR-OF-A24
Information to participants

Information to participants. Article 24 requires institutions to provide other participants with the information necessary for the sharing.

Artefacts an auditor will ask for
  • Provision of required information to other participants
  • Process for participant information exchange
Where this commonly fails
  • Information not provided to participants
BR-OF-A8
Consent for data and transaction sharing

Consent. Article 8 requires that sharing of registration and transaction data be based on the client's free, informed and specific consent, granted to the data recipient.

Artefacts an auditor will ask for
  • Consent capture mechanism (free, informed, specific)
  • Consent records and scope
  • Consent expiry/renewal handling
Where this commonly fails
  • Consent not free/informed/specific
  • Consent not recorded
  • Sharing beyond consent scope
BR-OF-A9
Information provision to client

Information to client. Article 9 requires participating institutions to ensure provision of information to the client about the data sharing.

Artefacts an auditor will ask for
  • Client-facing information about data sharing
  • Process to provide the information before/at sharing
Where this commonly fails
  • Client not informed about sharing
  • Information incomplete

Brazil Open Finance Cap. V: Availability, Conduct and Governance

BR-OF-A25
Availability and crisis management

Availability. Article 25 addresses unavailability situations that generate a crisis at the institution and the related obligations.

Artefacts an auditor will ask for
  • Availability monitoring of Open Finance interfaces
  • Crisis/contingency procedures for unavailability
Where this commonly fails
  • No availability monitoring
  • No crisis procedures
BR-OF-A28
Prohibition on obstacles to sharing

No obstacles. Article 28 prohibits participating institutions from creating obstacles to the sharing of data and services.

Artefacts an auditor will ask for
  • Assessment that no undue obstacles to sharing are imposed
  • Controls preventing obstruction practices
Where this commonly fails
  • Obstacles to sharing imposed
  • No assessment of obstruction
BR-OF-A30
Customer service channel

Service channel. Article 30 requires participating institutions to provide a customer service channel for Open Finance matters.

Artefacts an auditor will ask for
  • Customer service channel for Open Finance
  • Records of client queries/complaints and handling
Where this commonly fails
  • No dedicated service channel
  • Queries not handled
BR-OF-A31
Reliability and responsibility

Reliability. Article 31 makes the participating institution responsible for the reliability, integrity, availability, security and secrecy of the sharing.

Artefacts an auditor will ask for
  • Controls ensuring reliability, integrity, availability, security and secrecy
  • Assurance over the sharing chain
Where this commonly fails
  • Reliability/security not assured
  • Secrecy not maintained
BR-OF-A33
Responsible director

Responsible director. Article 33 requires the designation of a director responsible for the sharing referred to in the Resolution.

Artefacts an auditor will ask for
  • Appointment of the director responsible for Open Finance sharing
  • Defined responsibilities and reporting
Where this commonly fails
  • No responsible director designated
  • Responsibilities undefined
BR-OF-A34
Personal data treatment (LGPD)

Personal data treatment. Article 34 makes the institutions responsible for treating personal data in accordance with the General Data Protection Law (LGPD).

Artefacts an auditor will ask for
  • LGPD-compliant treatment of personal data shared under Open Finance
  • Lawful basis and data-subject rights handling
Where this commonly fails
  • Data treatment not LGPD-compliant
  • Lawful basis not documented

Brazil Open Finance Cap. VI-VIII: Convention, Oversight and Final Provisions

BR-OF-A44
Open Finance governance convention

Convention. Article 44 requires participating institutions to enter into a convention establishing the rules, procedures and standards for the operation of Open Finance.

Artefacts an auditor will ask for
  • Adherence to the Open Finance convention
  • Implementation of convention rules, procedures and standards
Where this commonly fails
  • Not party to the convention
  • Convention standards not implemented
BR-OF-A46
Banco Central oversight role

Oversight. Article 46 sets out the role of the Banco Central do Brasil in overseeing Open Finance and the convention.

Artefacts an auditor will ask for
  • Engagement with Banco Central oversight of Open Finance
  • Responses to Banco Central requirements
Where this commonly fails
  • Banco Central requirements not met
  • No engagement with oversight
BR-OF-A48
Risk management policies

Risk management. Article 48 requires institutions to ensure their risk management policies address the risks arising from Open Finance participation.

Artefacts an auditor will ask for
  • Risk management policy covering Open Finance risks
  • Risk assessment of sharing activities
Where this commonly fails
  • Open Finance risks not in the risk policy
  • No risk assessment of sharing
BR-OF-A49
Records available to the Banco Central

Records. Article 49 requires institutions to keep records relating to Open Finance available to the Banco Central do Brasil.

Artefacts an auditor will ask for
  • Retention of Open Finance records available to the Banco Central
  • Record-keeping policy
Where this commonly fails
  • Records not retained/available
  • No record-keeping policy
BR-OF-A52
Banco Central power to veto or restrict participation

Veto power. Article 52 empowers the Banco Central do Brasil to veto or impose restrictions on participation in Open Finance.

Artefacts an auditor will ask for
  • Awareness of the Banco Central's veto/restriction powers
  • Responses to any restrictions imposed
Where this commonly fails
  • Restrictions not complied with
BR-OF-A53
Entry into force and transition

Entry into force. Article 53 sets the transitional arrangements and the schedule for institutions to comply with the Resolution.

Artefacts an auditor will ask for
  • Implementation/transition plan against the Resolution's schedule
  • Milestone tracking
Where this commonly fails
  • No transition plan
  • Schedule not tracked
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.