- Spotlight
- Aug 11, 2026
Scaling Payments Across Latin America: Fraud, Compliance, and Local Rails
In this interview, Victor de Aguiar, Head of Operations for Clara in Brazil, talks about the future of payments in LATAM, safe scaling in these markets, and the fraud risks companies may face.

Across Latin America, digital payments are scaling faster than in almost any other region in the world. However, the map looks different in every market. In Brazil, for example, the central bank's Pix rail processed 79.8 billion transactions worth R$35.36 trillion in 2025, up 33.6% year over year. It now accounts for 54.7% of all payment transactions in the country and reaches roughly 93% of the adult population. Mexico runs on SPEI: more than 5.4 billion operations in 2024, growing 39% annually, with newer overlays like CoDi and DiMo, even as cash still accounts for around 85% of purchases under 500 pesos. Colombia only switched on its interoperable instant-payments system, Bre-B, in October 2025. For a company operating across all three, that means three regulators, three rails, and three fraud realities at once.
Speed comes at a cost. In Brazil alone, Pix-related fraud losses reached an estimated R$6.5 billion in 2025, with only about 7% of disputed funds recovered. This pushed the central bank to make its upgraded refund mechanism, MED 2.0, mandatory in February 2026. Two of every three accounts now receiving fraudulent Pix transfers are business accounts—precisely where corporate spend platforms operate.
Today, we sit down with Victor de Aguiar, Head of Operations for Clara in Brazil, who is responsible for keeping payment operations fast and compliant as the company scales across markets that refuse to standardize. Clara is a leading corporate spend management platform in Latin America, serving tens of thousands of companies across Brazil, Mexico, and Colombia. We discuss where payments in LATAM are heading, how companies can scale safely across these markets, and the hidden challenges and fraud risks they need to navigate along the way.
THE SUMSUBER: You run payment operations across Brazil, Mexico, and Colombia—three markets with completely different rails: Pix, SPEI and its overlays, and now Bre-B. What makes it hard to run secure, compliant operations across all three at once, and what do people get wrong when they assume "Latin America" is a single market?
VICTOR DE AGUIAR: LATAM isn't one market. Let’s take Brazil, Mexico, and Colombia you mentioned. They have three regulators, three rails, three banking behaviors, different customer expectations, different levels of infrastructure maturity, and, therefore, three completely different risk profiles for each country. Even when we think about credit cards, which are orchestrated by the same network company worldwide, we have structural differences in the three countries where we run instant payment operations. Each one is built by its respective regulator, and the differences are even bigger.
Brazil is a very good example. Pix changed the baseline for speed and availability. Payments are instant, available 24/7, and deeply embedded in both consumer and business behavior. Cash is basically gone from the streets. That creates a very different operational reality from a market where bank transfers are still more fragmented or where instant payments are still gaining adoption.
So it would be a mistake to assume that Latin America can be managed as one single payment environment. From the outside, the region may look similar because many companies face the same broad challenges: digitization, fraud sophistication, issues with financial inclusion, and regulatory complexity. But operationally, each country requires its own playbook.
In my view, the regulatory structure and customer expectations are the baseline to work on: each market has its own reporting logic and supervisory priorities, so secure operations depend on understanding the regulator and meeting high expectations and quality standards as much as understanding the rail and customers.
THE SUMSUBER: I understand your point. Yet, there are operations that can be global across LATAM, right? For example, anti-fraud operations? Which fraud and compliance controls can you standardize across the entire region, and which ones have to be rebuilt market by market? Where's the line between "one global policy" and "local by necessity"?
VICTOR DE AGUIAR: What can genuinely be global are: sanctions list screening against US and UN lists, identification of the UBO (ultimate beneficial owner), identifying the legal representative of each company we onboard, validating that all documents presented are authentic, confirming that the person contacting us during onboarding really is who they claim to be, industry-based risk classification, and verifying that the person signing actually has the power to sign on behalf of the company.
But those are not rail-specific or market-specific, they are the baseline questions that any serious payments institution has to answer before doing business with someone, regardless of country. One of the things that has to be built locally is the product-level regulatory permissions: what a given product is allowed to do in one country and not in another.
In Mexico, we need a special license to operate our fleet product. In Brazil, there are regulatory limits on how much interest a payment institution can charge. These aren't differences in principle. They are differences in what each regulator has decided is permissible. So, even if it makes sense to launch the same product in the three countries, sometimes we need to do adjustments behind the scenes to be able to offer the same conditions.
THE SUMSUBER: In your opinion, where do payment controls most often break down: onboarding, supplier and vendor setup, approvals, or the transaction itself? What's the failure point people underestimate?
VICTOR DE AGUIAR: I'd say that is another step that wasn't mentioned: the maintenance layer. We know that it is easy to focus on the onboarding process. The client is engaged with the solution, and companies want to offer the best possible experience when starting a relationship. But the greater challenge comes when this first energy decreases, and we need to cope with the constant changes that a company naturally has: a legal representative that leaves the company, a shift in the business model of the company, a process handover to another manager, or a new policy that wasn't implemented correctly. Those changes, when not handled correctly, create gaps and failure points in payment controls and can lead to fraud and losses.
THE SUMSUBER: Let’s turn again to regional specifics. Pix is now used by around 93% of Brazilian adults, and business-to-business is its fastest-growing flow. For a corporate spend platform, what does Pix unlock that cards or traditional transfers couldn't? And how do you slot it into a multi-rail setup when Mexico and Colombia work so differently?
VICTOR DE AGUIAR: For a corporate spend platform, the main thing Pix unlocks is reach. It allows companies to pay suppliers that may not accept cards, smaller vendors that historically depended on cash, and situations where the receiver expects immediate settlement. It is also very relevant in cases where suppliers offer better commercial conditions for immediate payment, including discounts.
For finance teams, the question is not only “How do I pay?” but “Which payment method makes the most sense for this expense, this supplier, and this moment?” All those new variables add more possibilities to explore by companies, but also add more complexity and challenges to deal with. The rails are different, but the final objective and the offered experience aren’t. So, even though the final step is different, the platform needs to make the payment method feel integrated into the same spend management logic. The challenge is to make the behind-the-scenes work toward the same goal as the card platform we have in every country.
THE SUMSUBER: Pix is instant and irreversible. Fraud losses hit an estimated R$6.5 billion in 2025, and business accounts are increasingly the destination for stolen funds. With MED 2.0 and tighter cybersecurity rules now in force, how has Clara had to adapt its verification and fraud controls specifically for instant rails at onboarding and at the moment of payment?
VICTOR DE AGUIAR: With Pix, the control focus has to shift to before the money moves, because once the transaction is executed, the recovery window is more limited than card transactions.
We had to reinforce the payment confirmation page to increase awareness among payers the moment they're transferring money to another party. At the moment of payment, the focus is on combining speed with friction only where it is justified. The system needs to look at signals such as the beneficiary, payment amount, frequency, timing, user permissions, approval flow, and whether the transaction fits the company’s behavior. A first payment to a new beneficiary, an unusual amount, or a change in pattern should not be treated the same way as a recurring payment to a known supplier.
MED 2.0 also reinforces the need for traceability and fast response. If there is a dispute or suspected fraud, you need clear records of who initiated the payment, who approved it, and how the transaction moved through the system. Fraud control is not only about blocking bad transactions; it is also about being able to investigate and respond quickly when something goes wrong.
For Clara, as a payment institution regulated by the Central Bank of Brazil, this also means treating fraud prevention, cybersecurity, traceability, and incident response as part of the core operating model, not as isolated compliance requirements.
THE SUMSUBER: Beyond instant payments, you're juggling cards, bank transfers, and cash across markets—each with its own licenses, integrations, and risk profile. How do you build operations that handle all of that in one place without the controls fragmenting along with the rails?
VICTOR DE AGUIAR: We need deep knowledge of each rail to have everything working perfectly. Yet, we can’t base our operations on each one of them. So, what we do is we build a common operating layer above the rails that gives all the control and visibility that companies need. The same logic applies to regulated products.
In Mexico, for example, our SAT authorization as a Monedero Electrónico de Combustible creates specific fiscal and operational requirements for fleet payments, but those controls still need to connect back to the same Clara platform logic: permissions, limits, visibility, and reconciliation.
This operational layer is seen through our platform, where you can access all the information in one place regardless of the rail. You can localize the technical and regulatory execution, but keep a unified view of risk, customer behavior, approvals, and money movement.
THE SUMSUBER: Based on your experience, what's the single hardest part of scaling secure payment operations across Latin America without losing control, and what would you tell an operator who's about to try it?
VICTOR DE AGUIAR: The hardest part might be maintaining consistency locally and globally at the same time that you keep a standard on the offered customer experience. For that, you need to find the middle ground: do not go totally global or totally local. You should have one operating standard adapted locally to be flexible with customer needs. At Clara, that means having a clear regional framework for risk, compliance, approvals, monitoring, and reconciliation, while giving each market enough depth to respond to how payments actually work there and how to explore new opportunities.
My advice to an operator would be: do not scale payment operations only through processes. Scale through visibility and the customer experience you want to offer. You need to know who is moving money, why, through which rail, with which approval, and with what level of risk. If you do not have that visibility, adding more countries or payment methods will only multiply the blind spots.
Relevant articles
- spotlight
- 3 weeks ago

- spotlight
- May 27, 2026
Take a peek into what a real investigation into scam compounds looks like, with Erin West, investigator and founder of Operation Shamrock.

What is Sumsub anyway?
Not everyone loves compliance—but we do. Sumsub helps businesses verify users, prevent fraud, and meet regulatory requirements anywhere in the world, without compromises. From neobanks to mobility apps, we make sure honest users get in, and bad actors stay out.


