Law / Haiti

BRH Circulaire 126, Information Security Rules for Financial Institutions

Banque de la République d'Haïti, Circulaire 126, Sur les règles en matière de sécurité informatique, 13 janvier 2022, arts. 1-5

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 1 February 2022.

A sector security regimes rule binding private bodies.

As of 19 September 2026.

What it requires

  • This binds every institution financière (bank and other financial institution) that Banque de la République d'Haïti supervises under the 14 May 2012 law on banks and other financial institutions.
  • Have a written information-security policy, updated annually and approved by your board of directors.
  • Maintain an information-security committee (or, for a non-bank financial institution, have your board of directors perform this function) to validate and approve the security measures your policy adopts.
  • Designate an information-security officer independent of the IT department, reporting to risk management or directly to general management, with the data and access needed to do the job.
  • Keep your security committee systematically informed of incidents capable of compromising information security and of the measures taken to address them.
  • Develop, test and maintain a risk-based contingency plan, including an offsite recovery center kept separate from your main site, and a regularly checked backup system.
  • Have your information system's security audited at least once every three years, and attach a copy of the audit report to your annual internal-control report.
  • A failure to complete the three-year audit draws a penalty of HTG 200,000; a failure to remedy a violation BRH identifies draws HTG 100,000 per day of continuing infraction, plus HTG 2,500 per day for late payment of any fine.

If you get it wrong

Criminal exposureNo

Private right of actionNo

Criminal exposure note

Articles 4 and 5 set only monetary penalties administered by BRH (a fixed HTG 200,000 penalty for an audit-cycle failure, an HTG 100,000 per-day penalty for unremedied violations, and an HTG 2,500 per-day late-payment surcharge); no provision reviewed here creates a criminal offense for noncompliance.

Penalty structure

Article 4's HTG 100,000-per-day penalty applies to a financial institution's continuing failure to remedy a violation BRH has identified and notified, running from the date of that notice. A separate, one-time HTG 200,000 penalty applies where the institution has failed to complete its own required security audit within the three-year cycle Article 3(t) sets. A further HTG 2,500-per-day late-payment surcharge applies where an institution without a BRH account fails to pay a fine by cheque within five business days of the payment notice.

Rule
Per violation only
As of
19 September 2026
Currency
HTG
Per violation unit
Day
Per violation amount
100,000

Over one month of continuous breach, HTG 3,044,000.

Who enforces it

Enforcement body

Banque de la République d'Haïti (BRH), which may order and charge an institution for an audit after notice, require an institution to remediate identified violations, and deduct any fine directly from the institution's account at BRH.

Settledness

As of
19 September 2026
Open questions
Has BRH issued any further guidance or an updated circular refining the technical detail of the Article 3 security standards since Circulaire 126 took effect on 1 February 2022?

What it reaches

Obligation class

Security, Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Circulaire 126 sets the information-security rules that bind every institution financière the Banque de la République d'Haïti (BRH) supervises, pursuant to Articles 83 and 161 of the 14 May 2012 law on banks and other financial institutions. Every financial institution must have a written information-security policy, updated annually and approved by its board of directors.

Every bank must have an information-security committee that validates and approves the security measures adopted to implement that policy, a function the board of directors performs for other categories of financial institution. Every financial institution must designate an information-security officer independent of the IT department, reporting either to the risk-management function or directly to general management.

Every financial institution must ensure that its security committee is systematically informed of incidents capable of compromising information security, and of the measures taken to address them. Every financial institution must develop, test and maintain a contingency plan based on a risk analysis, to ensure the continuity of its activities in all circumstances.

Every financial institution must have its information system's security audited at least once every three years, with a copy of the audit report attached to its annual internal-control report. A financial institution that fails to have its system audited on that three-year cycle is liable to a penalty of two hundred thousand gourdes, and BRH may itself order and charge for an audit after notice.

A financial institution that fails to remedy a violation BRH identifies is liable to a further penalty of one hundred thousand gourdes per day of continuing infraction, plus an additional late-payment penalty of two thousand five hundred gourdes per day. The circular's provisions took effect 1 February 2022.

When LexLint raises it

  • provides_financial_services

Read the law

Official PDF of Banque de la République d'Haïti Circulaire 126
hosted on BRH's own site (brh.ht), independently re-OCR'd on the leased GPU (Surya, used_ocr true, no extraction errors) after the crawler's compliant tier returned zero extractable text from the scanned PDF

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app