STRATEGIC WORKSHOP · RED SOLIDARIOS · SANTO DOMINGO 2026

The Future of Microfinance in the Digital Era

Innovation· Transformation· Cybersecurity

Fabiola M. Herrera

Content and facilitation

Fabiola M. Herrera

Former Deputy Manager of Systems and Innovation — Central Bank of the Dominican Republic

Over three decades in payment systems, financial technology, and cybersecurity. Led the design of SIPARD (National Payment System) and the Dominican financial-sector CSIRT. Currently exploring AI applications for risk management and inclusive financial education.

LinkedIn

Why are we here?

Three numbers that frame the conversation.

2/3

of MFIs in Latin America operate without a defined digital strategy

+400%

increase in cyberattack losses across the region since 2017

2026

the year AI is already a core operational tool, not a promise

"The question is no longer whether to transform — it's how to do it without losing what makes each MFI unique: trust, closeness, and deep client knowledge."

MODULE 1

Innovation and Digital Transformation

The new microfinance ecosystem in 2026.

A more digital client

Today's microfinance entrepreneur is more informed, more connected, and likely already uses digital payments in their business.

New competition

Fintechs, neobanks, and digital platforms compete for the same client with lower operating costs.

Accessible technology

AI, big data, and automation are no longer exclusive to large banks — MFIs can adopt them today.

Strategic urgency

Digital transformation has moved from option to necessity to stay relevant and competitive.

Digitizing the full credit cycle

The most advanced institutions no longer digitize isolated steps — they integrate the full flow.

1

Prospecting

Identification and acquisition

2

Evaluation

Scoring with alternative data

3

Approval

Digital committees and rules

4

Disbursement

Instant payments

5

Collection

Reminders and follow-up

Reduces response timeEliminates reworkImproves traceabilityBoosts productivityCuts costs

— Kata Software, 2026

AI as copilot for the loan officer

AI assists — it does not replace.

Credit evaluation

Scoring with alternative data beyond traditional credit bureau.

Fraud detection

Anomalous patterns spotted in real time.

Assistant for loan officers

Conversational support for field officers.

Early default warning

Risk models that anticipate non-payment.

Document validation

OCR + automatic identity verification.

60%

of financial firms already use AI to detect threats— Gartner

"AI, as a technology, is altering human thought, knowledge, perception, and reality — and in doing so, is changing the course of human history. Societies must cooperate not only to understand but to adapt. Humans still control it. We must shape it with our values." — Kissinger et al, The Age of AI and Our Human Future

Transform without cannibalizing

The pattern that distinguishes transformations that work from those that destroy value.

The most common mistake

  • Digitizing from the traditional structure
  • Destroying existing channels with no alternative
  • Ignoring the field advisor as a key asset
  • Digitizing inefficiency without redesigning
  • Treating technology as an IT project, not a strategy

The successful model

  • Build digital capabilities IN PARALLEL
  • Keep existing channels while digital grows
  • Design for the digital client (not the current one)
  • Appoint autonomous leadership with its own metrics
  • Partner with fintechs to accelerate innovation

Reference case: BCP launched Yape as an autonomous spin-off — without cannibalizing the traditional bank.

Open Finance: the next level

Where the region stands in 2026.

Brazil

Regional leader

Colombia

Framework in design

Mexico

Framework in design

Chile

Framework in design

Opportunity

More personalized credit by sharing client data with consent.

Threat

Neobanks and fintechs arrive with a competitive edge if they handle data better.

Requirement

Stricter security and privacy standards for sharing client data.

The 5 most common digital-transformation mistakes

1Treating it as an IT project

Digital transformation is a corporate strategy decision, not a systems-department decision.

2Digitizing without redesigning

Digitizing inefficient processes = digitizing inefficiency. Redesign first, then digitize.

3Ignoring the digital client

The digital channel is not a mirror of the physical channel. It's a different client with different expectations.

4Leadership without real authority

Without autonomy and a clear mandate, transformation gets diluted in competing operational priorities.

5Digital channel with no dedicated metrics

If you don't measure the digital channel separately, you don't know if it's working.

Source: Revista Economía, 2025 — Digital transformation model without cannibalization

Our experts weigh in

Four angles on Module 1.

BillyThe Balanced Guide

Fabiola's data lines up with what we see: the most expensive mistake isn't adopting AI late — it's digitizing broken processes without redesigning them. Traceability beats speed.

NailaThe Critical Realist

I'm wary of the leap from '60% already use AI' to 'you should too.' The right question isn't whether you adopt AI, it's which specific decision improves — and how you confirm the experience didn't get worse for the most vulnerable client.

AinthonyThe Innovation Advocate

Open Finance is the real opportunity. An MFI with decades of client relationships and aggregated data access can offer products no neobank can. Regulation arrives late, but it arrives.

Carlos Miranda LevyThe Curator

The BCP/Yape case is the core pattern: real autonomy. Without a mandate outside the traditional org chart, any transformation ends up negotiated to death in committees.

Activity 1 · Digital Maturity Map

Interactive self-assessment — move the sliders and watch your radar update in real time.

Digital Maturity Map — Self-Assessment

Rate your institution across 5 dimensions from 1 to 5. The radar updates in real time to show strengths and gaps.

Digital channels 3/5

App, web, WhatsApp, digital onboarding

Data analytics 3/5

Dashboards, segmentation, predictive models

Automation 3/5

Credit, collections, back-office flows

Digital culture 3/5

Leadership, metrics, talent, learning

Cybersecurity 3/5

Maturity, governance, incident response

1 = not started · 3 = in progress · 5 = advanced and integrated

Digital channelsData analyticsAutomationDigital cultureCybersecurity
Developing
Average maturity 3.0/5
Strongest: Digital channels (3/5)
Biggest gap: Cybersecurity (3/5)

Guiding question: which digital gap most limits your institution's growth today?

MODULE 2

Cybersecurity: the link that cannot fail

Real threats, real impact, strategic response.

8.15%

of financial-sector users faced online threats in 2025

Kaspersky, 2026

2,716

attacks per week at Latin American companies — 39% above the global average

FVSA, 2026

12.8%

of financial organizations hit by ransomware in 2025

Kaspersky, 2026

$2.5B

in cyberattack losses across Latin America — +400% since 2017

FVSA, 2026

Why are MFIs an attractive target?

PROFILE HIGH

MFI risk profile

  • !Sensitive data from vulnerable populations
  • !Accelerated digitization without matching security
  • !Technology providers with variable standards
  • !Lower response capacity than mainstream banking
  • !Trust as an asset — one incident destroys it

2026 threats: what's coming

Click each card for details.

Double-extortion ransomware

+

Encrypt and exfiltrate data to pressure payment. Especially damaging given the data MFIs handle.

Adaptive AI-powered malware

+

Autonomously adapts to the environment to evade defenses. Harder to detect than traditional malware.

WhatsApp trojans

+

Banking trojans distributed via messaging apps. No longer require exploiting technical vulnerabilities.

Deepfake social engineering

+

Hyper-personalized phishing using AI. Attacks are more credible and harder to distinguish from real communications.

Supply-chain attacks

+

Compromise the provider to reach multiple institutions. Trust between organizations becomes the vector.

Sources: Kaspersky Security Bulletin 2026 · CiberSafety Predictions 2026 · FVSA Digital Risks 2026

The human factor: the most vulnerable link

Most successful attacks don't exploit technical vulnerabilities — they require someone to click in the wrong place.

Hyper-personalized phishing

AI-generated emails and messages using real data about the recipient.

SMiShing and vishing

SMS and voice attacks impersonating known financial institutions.

Credential theft

Employees who reuse passwords or lack MFA are the most common entry vector.

Shadow IT

Unauthorized tools create invisible channels that bypass all controls.

Basic cybersecurity framework for MFIs

  1. 1

    Vulnerability diagnosis

    Know the real security state — not the aspirational one. Internal or external audit.

  2. 2

    Incident response plan

    Documented, tested, and known by everyone. Includes roles, escalation, communication with clients and regulators.

  3. 3

    Continuous staff training

    At every level, including directors. Trained staff is the first line of defense.

  4. 4

    Provider standards

    Technology providers must meet contractual and verifiable security standards.

  5. 5

    Regular reporting to the board

    Treat cyber risk as financial risk. Board-level cyber maturity reduces risk (IMF, 2024).

"The mass data breaches at large corporations left a clear message: protecting user information will be a competitive advantage in itself." — uFlow, 2026

Observations on cybersecurity

BillyThe Balanced Guide

The most actionable number here isn't the $2.5B in losses — it's that 'board-level reporting reduces risk' (IMF, 2024). Governance of cyber risk correlates with lower real incident rates.

NailaThe Critical Realist

No 5-step framework protects an institution that treats cybersecurity as a compliance checkbox. The brutal question: when did you last actually test your incident response plan? If you haven't tested it, it doesn't exist.

AinthonyThe Innovation Advocate

I flip it: mature cybersecurity is a visible trust signal to clients and partners. MFIs that turn it into competitive advantage win contracts with regional cooperatives.

Carlos Miranda LevyThe Curator

Fabiola says it straight and she's right: treat cyber risk as financial risk. If it doesn't reach the risk committee with the same seriousness as non-performing loans, it's underestimated.

MODULE 3

Roadmap: from reflection to action

The 5 steps you can actually do now.

Transformation is a governance decision

Board of Directors

Receives cyber risk reports. Approves the digital strategy. Defines risk tolerance.

Executive Leadership

Leads transformation as corporate strategy. Appoints autonomous leadership with real authority.

Technology Area

Executes and implements. Reports. Proposes. Is NOT the owner of transformation — it enables it.

Digital transformation and cybersecurity are not technology projects — they are board and executive decisions.

The 5 steps you can do now

  1. 1

    Honest diagnosis

    The real level today — not the aspirational one. Gaps in both digital and cybersecurity.

  2. 2

    Prioritize without scrapping everything

    Build in parallel. Create the new without destroying what works.

  3. 3

    Appoint autonomous leadership

    With real authority to lead transformation. Outside the traditional org chart.

  4. 4

    Strategic alliances

    Fintechs, universities, the ecosystem. Don't build everything alone — and you don't have to.

  5. 5

    Cybersecurity from governance

    Board-level reports. Treat cyber risk as financial risk (IMF, 2024).

Kaia Tanaka-Lindgren

CEO perspective — Kaia Tanaka-Lindgren

"Digital transformation in microfinance operates on two horizons: operational efficiency in 18 months and institutional relevance in 10 years. The most expensive strategic error is optimizing for the first at the expense of the second. Trust, once eroded by a cyber incident or a poorly designed digital channel, takes decades to rebuild — if it rebuilds at all."

Kaia is ibizai's CEO and the team's multi-horizon strategic lens.

FINALLY

What the microfinance sector has that no fintech does

  • Decades of trust earned with the client
  • Deep territorial knowledge of the market
  • Presence in communities technology doesn't reach on its own
  • A social mission that goes beyond returns

Technology amplifies all of that. It does not replace it.

Fabiola Herrera

About Fabiola M. Herrera

With over three decades of professional experience, her most recent role as Deputy Manager of Systems and Innovation at the Central Bank of the Dominican Republic equipped her to spearhead strategic initiatives in financial technology and payment systems. Previously, as Director of the Payment Systems Department, she led the development of SIPARD, the Dominican Republic's National Payment System.

She then established the Cybersecurity Department, including developing national regulations for cybersecurity in the financial sector and creating a sector-specific Cyber Security Incident Response Team (CSIRT) for participants in the national payment system.

She is currently exploring applications of artificial intelligence and other emerging technologies to enhance risk management strategies and address inclusive financial education.

LinkedIn profile

Ready to Get Started?

Request your personalized program today. Tell us about your goals and we will design a learning experience that fits your needs, schedule, and budget.