Brazil Open Finance (Resolução Conjunta No. 1/2020)
Evidence request list. 31 controls, 31 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Brazil Open Finance Cap. I-II: Implementation, Definitions and Objectives
Implementation. Article 1 provides that the Resolution governs the implementation of Open Finance by financial institutions, payment institutions and other institutions authorised by the Banco Central do Brasil.
- Determination that the institution is in scope of Open Finance
- Open Finance implementation plan and governance
- Open Finance obligations not mapped
- Scope misjudged
Definitions. Article 2 defines the key terms (Open Finance, participating institution, data transmitter, data recipient, payment transaction initiator, client, consent and others).
- Mapping of statutory definitions to internal roles (transmitter/recipient/initiator)
- Roles misclassified
- Definitions not applied
Objectives. Article 3 sets the objectives of Open Finance, including promoting competition, financial citizenship, efficiency and innovation in the financial and payments system.
- Alignment of Open Finance participation with the stated objectives
- Objectives not reflected in implementation
Institutions' obligations. Article 4 sets out the general obligations of the institutions referred to in Article 1 for the purposes of fulfilling the Resolution.
- Documentation of how the institution meets its Open Finance obligations
- Obligations not operationalised
Brazil Open Finance Cap. III: Scope of Sharing and Participants
Scope of sharing. Article 5 defines the minimum scope of sharing under Open Finance: registration (cadastro) and transaction data, and payment transaction initiation services.
- Inventory of data and services shared under Open Finance
- Mapping of shared data categories to the Article 5 minimum scope
- Required data/services not shared
- Scope under-implemented
Participants. Article 6 defines the categories of Open Finance participants: data transmitters/account holders, data recipients and payment transaction initiators.
- Identification of the institution's participant role(s)
- Records of role registration
- Participant role not identified
- Role obligations not applied
Registration. Article 7 requires participating institutions to register their participation in Open Finance as prescribed.
- Evidence of registration of Open Finance participation
- Maintenance/update of registration
- Participation not registered
- Registration not updated
Brazil Open Finance Cap. IV: Data Sharing, Consent and Security
Recipient obligations. Article 10 sets obligations on the data recipient or payment transaction initiator regarding the use and protection of shared data.
- Controls limiting use of received data to the consented purpose
- Protection of received data
- Received data used beyond purpose
- No protection of received data
Use limitation. Article 12 requires the data recipient to ensure shared data are used only for the consented purposes and handled accurately.
- Purpose-binding controls for shared data
- Accuracy handling of shared data
- Purpose creep
- Inaccurate handling of shared data
Payment initiation. Article 13 sets the consent requirements for sharing of payment transaction initiation services.
- Consent mechanism specific to payment initiation
- Records of payment-initiation consents
- Payment initiation without specific consent
- Consent not recorded
Client information. Article 14 sets the minimum information that participating institutions must provide to the client in connection with sharing.
- Client information meeting the Article 14 minimum
- Delivery of information to clients
- Minimum client information not provided
Responsibilities. Article 15 allocates responsibilities among participating institutions involved in the data sharing.
- Documented allocation of responsibilities across participants
- Records identifying responsible parties per sharing
- Responsibilities undefined
- Roles not documented
Security. Article 16 requires the data transmitter or account holder to adopt security measures and authentication controls for the sharing.
- Security and authentication controls for sharing
- Protection of the sharing interface
- Inadequate security on sharing
- Weak authentication
Authentication. Article 17 requires customer authentication procedures and controls to be compatible with the risks of the sharing.
- Risk-based customer authentication procedures
- Strong authentication for sharing/payment initiation
- Authentication not risk-based
- No strong authentication
Confirmation. Article 20 requires the data transmitter/account holder (and the initiator) to request confirmation of the sharing from the client.
- Mechanism to confirm sharing with the client
- Records of sharing confirmations
- Sharing not confirmed with the client
- Confirmation not recorded
Dedicated interfaces. Article 23 requires participating institutions to make available dedicated interfaces (APIs) for the sharing of data and services.
- Dedicated API interfaces conforming to Open Finance standards
- Availability/performance monitoring of interfaces
- No dedicated interfaces
- Interfaces not standard-conformant
Information to participants. Article 24 requires institutions to provide other participants with the information necessary for the sharing.
- Provision of required information to other participants
- Process for participant information exchange
- Information not provided to participants
Consent. Article 8 requires that sharing of registration and transaction data be based on the client's free, informed and specific consent, granted to the data recipient.
- Consent capture mechanism (free, informed, specific)
- Consent records and scope
- Consent expiry/renewal handling
- Consent not free/informed/specific
- Consent not recorded
- Sharing beyond consent scope
Information to client. Article 9 requires participating institutions to ensure provision of information to the client about the data sharing.
- Client-facing information about data sharing
- Process to provide the information before/at sharing
- Client not informed about sharing
- Information incomplete
Brazil Open Finance Cap. V: Availability, Conduct and Governance
Availability. Article 25 addresses unavailability situations that generate a crisis at the institution and the related obligations.
- Availability monitoring of Open Finance interfaces
- Crisis/contingency procedures for unavailability
- No availability monitoring
- No crisis procedures
No obstacles. Article 28 prohibits participating institutions from creating obstacles to the sharing of data and services.
- Assessment that no undue obstacles to sharing are imposed
- Controls preventing obstruction practices
- Obstacles to sharing imposed
- No assessment of obstruction
Service channel. Article 30 requires participating institutions to provide a customer service channel for Open Finance matters.
- Customer service channel for Open Finance
- Records of client queries/complaints and handling
- No dedicated service channel
- Queries not handled
Reliability. Article 31 makes the participating institution responsible for the reliability, integrity, availability, security and secrecy of the sharing.
- Controls ensuring reliability, integrity, availability, security and secrecy
- Assurance over the sharing chain
- Reliability/security not assured
- Secrecy not maintained
Responsible director. Article 33 requires the designation of a director responsible for the sharing referred to in the Resolution.
- Appointment of the director responsible for Open Finance sharing
- Defined responsibilities and reporting
- No responsible director designated
- Responsibilities undefined
Personal data treatment. Article 34 makes the institutions responsible for treating personal data in accordance with the General Data Protection Law (LGPD).
- LGPD-compliant treatment of personal data shared under Open Finance
- Lawful basis and data-subject rights handling
- Data treatment not LGPD-compliant
- Lawful basis not documented
Brazil Open Finance Cap. VI-VIII: Convention, Oversight and Final Provisions
Convention. Article 44 requires participating institutions to enter into a convention establishing the rules, procedures and standards for the operation of Open Finance.
- Adherence to the Open Finance convention
- Implementation of convention rules, procedures and standards
- Not party to the convention
- Convention standards not implemented
Oversight. Article 46 sets out the role of the Banco Central do Brasil in overseeing Open Finance and the convention.
- Engagement with Banco Central oversight of Open Finance
- Responses to Banco Central requirements
- Banco Central requirements not met
- No engagement with oversight
Risk management. Article 48 requires institutions to ensure their risk management policies address the risks arising from Open Finance participation.
- Risk management policy covering Open Finance risks
- Risk assessment of sharing activities
- Open Finance risks not in the risk policy
- No risk assessment of sharing
Records. Article 49 requires institutions to keep records relating to Open Finance available to the Banco Central do Brasil.
- Retention of Open Finance records available to the Banco Central
- Record-keeping policy
- Records not retained/available
- No record-keeping policy
Veto power. Article 52 empowers the Banco Central do Brasil to veto or impose restrictions on participation in Open Finance.
- Awareness of the Banco Central's veto/restriction powers
- Responses to any restrictions imposed
- Restrictions not complied with
Entry into force. Article 53 sets the transitional arrangements and the schedule for institutions to comply with the Resolution.
- Implementation/transition plan against the Resolution's schedule
- Milestone tracking
- No transition plan
- Schedule not tracked
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.