Chile’s CMF Finalizes Binding Outsourcing Standard for Insurers, Reinsurers

Chile’s CMF Finalizes Binding Outsourcing Standard for Insurers, Reinsurers

Chile's financial regulator has closed a two-year rulemaking process with a binding standard on how insurers and reinsurers must manage outsourcing risk. The rule follows two rounds of public consultation and folds outsourcing oversight into the CMF's existing governance, risk-management and cybersecurity framework, with a transition period for existing contracts.

Chile’s insurance sector has a new, binding standard governing how companies manage the risk of outsourcing services to third parties. On 12 de agosto de 2026 — August 12 — the Comisión para el Mercado Financiero (CMF), Chile’s integrated financial regulator, publicó hoy la Norma de Carácter General N° 573, que imparte instrucciones sobre la externalización de servicios por parte de las compañías de seguros y reaseguros, or, in plain terms, published General Regulation No. 573, instructing insurance and reinsurance companies on how they must handle externalized services. The CMF simultaneously released an official English-language statement headlined CMF issues regulation on service outsourcing for insurance, reinsurance companies, a signal that the rule is meant to be read well beyond Santiago by international reinsurers, brokers and outsourcing vendors with exposure to the Chilean market.

What Norma General 573 Actually Requires

At its core, NCG 573 is a risk-management rule, not a licensing or procurement regime. La norma establece los principios y requisitos mínimos que deberán cumplir las compañías de seguros y reaseguros en la identificación, evaluación, monitoreo y control de los riesgos derivados de la externalización de servicios. In other words, it sets out the minimum principles insurers and reinsurers must follow to identify, assess, monitor and control the risks that come with handing services to outside providers — the kind of functions, from claims handling to IT hosting, that outsourcing rules elsewhere typically capture. The CMF frames the exercise as a strengthening measure rather than a restriction: Mediante la implementación de esta normativa se fortalece la gestión de este riesgo, estableciendo lineamientos para su adecuada identificación, evaluación, monitoreo y control. Implementing the standard, the regulator says, reinforces how outsourcing risk is identified, assessed, monitored and controlled across the industry.

Formally, the standard carries a longer bureaucratic title in the CMF’s regulatory registry, where it is listed as IMPARTE INSTRUCCIONES EN MATERIA DE EXTERNALIZACIÓN DE SERVICIOS EN EL CONTEXTO DE LA GESTIÓN DE RIESGO OPERACIONAL. — instructions on service outsourcing in the context of operational risk management. The same registry entry confirms the standard’s legal underpinning: EJECUTA ACUERDO DEL CONSEJO DE LA COMISIÓN PARA EL MERCADO FINANCIERO QUE APRUEBA LA PUBLICACIÓN DE LA NORMA QUE IMPARTE INSTRUCCIONES SOBRE LA EXTERNALIZACIÓN DE SERVICIOS DE LAS COMPAÑÍAS DE SEGUROS Y REASEGUROS. — meaning the filing formally executes the CMF Council’s agreement approving publication of the outsourcing standard for insurance and reinsurance companies.

Two Consultations, One Set of Adjustments

NCG 573 did not arrive overnight. Luego de realizados dos procesos de consulta pública -de julio a septiembre de 2025 y de enero a marzo de 2026- se tuvieron en consideración los comentarios recibidos por parte de la industria, además de las mejores prácticas en la materia, para la elaboración de la normativa definitiva. Translated, the CMF ran two public consultation rounds — the first spanning mid-2025, the second running into early 2026 — weighing industry comments and international best practice before finalizing the text. The result, according to the regulator, was a more calibrated rule: A partir de dichos procesos se introducen ajustes orientados a dar mayor precisión y proporcionalidad a las exigencias establecidas en la regulación. The two rounds, in other words, led to adjustments intended to make the regulation’s requirements more precise and proportionate, rather than a flat obligation applied uniformly regardless of an insurer’s size or risk profile.

The consultation process is not the only outsourcing-adjacent dossier open at the CMF this year. The regulator has also kept open a separate, reopened consultation on cross-border annuity reinsurance, a reminder of how exposed Chile’s institutional insurance market is to offshore counterparties and service arrangements alike.

How NCG 573 Fits Chile’s Prudential Framework

The CMF is explicit that the new standard does not stand alone. Esta norma se enmarca en los principios prudenciales establecidos por las normativas de gobierno corporativo (NCG N°309), sistemas de gestión de riesgo (NCG N°325) y gestión de riesgo operacional y ciberseguridad (NCG N°454). The outsourcing rule, that is, is framed within the prudential principles already set by the CMF’s standards on corporate governance, risk-management systems, and operational risk and cybersecurity management. That lineage matters for compliance teams: an insurer’s outsourcing arrangements will now be assessed against the same prudential logic that already governs board oversight, enterprise risk frameworks and cyber-resilience obligations, rather than as a bolt-on compliance exercise.

The CMF has also published supporting material alongside the rule itself. As the regulator noted in its Spanish-language release: La norma se encuentra disponible en la sección Normativa del sitio web institucional. — the full text sits in the Normativa section of the regulator’s website — and, separately, Adicionalmente, la CMF pone a disposición de los interesados el informe normativo que, entre otros elementos, evalúa el impacto de esta normativa., an accompanying regulatory report that assesses the rule’s expected impact. For insurers weighing how NCG 573 compares with cyber and operational-resilience expectations elsewhere, it sits alongside a parallel push by Switzerland’s FINMA on operational and cybersecurity governance — different jurisdiction, same underlying instinct to fold outsourcing and vendor risk into existing prudential supervision rather than treat it as a stand-alone silo.

A Transition Window for Existing Contracts

Compliance teams typically ask one question first when a new prudential rule lands: how much time do we have? The CMF built in an answer. Entre ellas, se establece una regla de transitoriedad en la entrada en vigencia, de modo de que las compañías puedan adecuar los contratos relativos a servicios externalizados. Among the adjustments made after consultation, in other words, the regulator set a transitional rule for the standard’s entry into force, giving companies time to bring their existing outsourced-service contracts into line with the new requirements, rather than requiring instant renegotiation of every vendor agreement.

There is a small wrinkle in the paper trail worth flagging for anyone tracking the filing date. The CMF’s public registry entry lists the measure under NCG | 573 | 11/08/2026, one day ahead of the press release announcing it — a routine gap between internal filing and public announcement, but one that matters for firms counting transition-period deadlines from the regulation’s formal date rather than its press date.

The broader signal is one of a Chilean regulator increasingly comfortable legislating around risk concentration and third-party dependency across the insurance value chain — a posture visible elsewhere in the Chilean market as well, where pension funds have been building a growing footprint in the region’s catastrophe bond market. For outsourcing vendors, brokers and reinsurers with Chilean counterparties, NCG 573 is now the reference point against which those relationships will be measured.

Frequently Asked Questions

What does Chile’s Norma General 573 require of insurers and reinsurers?
La norma establece los principios y requisitos mínimos que deberán cumplir las compañías de seguros y reaseguros en la identificación, evaluación, monitoreo y control de los riesgos derivados de la externalización de servicios. In practice, Chilean insurers and reinsurers must set minimum principles for identifying, assessing, monitoring and controlling the risks tied to any service they outsource to a third party.
How does NCG 573 relate to Chile’s existing prudential rules?
Esta norma se enmarca en los principios prudenciales establecidos por las normativas de gobierno corporativo (NCG N°309), sistemas de gestión de riesgo (NCG N°325) y gestión de riesgo operacional y ciberseguridad (NCG N°454). The outsourcing standard is explicitly built on top of the CMF’s existing corporate-governance, risk-management-systems, and operational-risk-and-cybersecurity rules, rather than replacing them.
Does the new rule give insurers time to adjust existing outsourcing contracts?
Entre ellas, se establece una regla de transitoriedad en la entrada en vigencia, de modo de que las compañías puedan adecuar los contratos relativos a servicios externalizados. Yes — the CMF built a transitional rule into the regulation’s entry into force specifically so companies can bring their current outsourcing contracts into compliance rather than renegotiate them overnight.
P

Patrice Dumont

InsuraBeat correspondent

Senior reporter at InsuraBeat leading coverage of insurance regulation, executive moves, and the insurtech landscape across EMEA and APAC. Fifteen years straddling regulation and trade journalism: began in the legal team of a French insurance industry body, advising members on Solvency II implementation and product approvals, then moved to specialised insurance media to cover EIOPA, NAIC and IAIS work and prudential reform. Graduate of the Pan-Asian School of Governance and Regulatory Affairs (Singapore), with an LL.M. in Insurance Prudential Law and Cross-Border Compliance from the Nihon-Siam Institute of Legal Studies (Bangkok). Writes from Brussels, on European afternoon markets.

All articles by Patrice Dumont →

Daily Beat newsletter

Never miss a beat in global insurance.

Get the day’s top deals, executive moves and regulatory shifts in your inbox every morning.

Free. No spam. Unsubscribe anytime.