STRATEGIC WORKSHOP · RED SOLIDARIOS · SANTO DOMINGO 2026
The Future of Microfinance in the Digital Era
Innovation· Transformation· Cybersecurity
Why are we here?
Three numbers that frame the conversation.
of MFIs in Latin America operate without a defined digital strategy
increase in cyberattack losses across the region since 2017
the year AI is already a core operational tool, not a promise
"The question is no longer whether to transform — it's how to do it without losing what makes each MFI unique: trust, closeness, and deep client knowledge."
MODULE 1
Innovation and Digital Transformation
The new microfinance ecosystem in 2026.
A more digital client
Today's microfinance entrepreneur is more informed, more connected, and likely already uses digital payments in their business.
New competition
Fintechs, neobanks, and digital platforms compete for the same client with lower operating costs.
Accessible technology
AI, big data, and automation are no longer exclusive to large banks — MFIs can adopt them today.
Strategic urgency
Digital transformation has moved from option to necessity to stay relevant and competitive.
Digitizing the full credit cycle
The most advanced institutions no longer digitize isolated steps — they integrate the full flow.
Prospecting
Identification and acquisition
Evaluation
Scoring with alternative data
Approval
Digital committees and rules
Disbursement
Instant payments
Collection
Reminders and follow-up
— Kata Software, 2026
AI as copilot for the loan officer
AI assists — it does not replace.
Credit evaluation
Scoring with alternative data beyond traditional credit bureau.
Fraud detection
Anomalous patterns spotted in real time.
Assistant for loan officers
Conversational support for field officers.
Early default warning
Risk models that anticipate non-payment.
Document validation
OCR + automatic identity verification.
of financial firms already use AI to detect threats— Gartner
"AI, as a technology, is altering human thought, knowledge, perception, and reality — and in doing so, is changing the course of human history. Societies must cooperate not only to understand but to adapt. Humans still control it. We must shape it with our values." — Kissinger et al, The Age of AI and Our Human Future
Transform without cannibalizing
The pattern that distinguishes transformations that work from those that destroy value.
✕ The most common mistake
- Digitizing from the traditional structure
- Destroying existing channels with no alternative
- Ignoring the field advisor as a key asset
- Digitizing inefficiency without redesigning
- Treating technology as an IT project, not a strategy
✓ The successful model
- Build digital capabilities IN PARALLEL
- Keep existing channels while digital grows
- Design for the digital client (not the current one)
- Appoint autonomous leadership with its own metrics
- Partner with fintechs to accelerate innovation
Reference case: BCP launched Yape as an autonomous spin-off — without cannibalizing the traditional bank.
Open Finance: the next level
Where the region stands in 2026.
Brazil
Regional leader
Colombia
Framework in design
Mexico
Framework in design
Chile
Framework in design
Opportunity
More personalized credit by sharing client data with consent.
Threat
Neobanks and fintechs arrive with a competitive edge if they handle data better.
Requirement
Stricter security and privacy standards for sharing client data.
The 5 most common digital-transformation mistakes
1Treating it as an IT project▾
Digital transformation is a corporate strategy decision, not a systems-department decision.
2Digitizing without redesigning▾
Digitizing inefficient processes = digitizing inefficiency. Redesign first, then digitize.
3Ignoring the digital client▾
The digital channel is not a mirror of the physical channel. It's a different client with different expectations.
4Leadership without real authority▾
Without autonomy and a clear mandate, transformation gets diluted in competing operational priorities.
5Digital channel with no dedicated metrics▾
If you don't measure the digital channel separately, you don't know if it's working.
Source: Revista Economía, 2025 — Digital transformation model without cannibalization
Our experts weigh in
Four angles on Module 1.
Fabiola's data lines up with what we see: the most expensive mistake isn't adopting AI late — it's digitizing broken processes without redesigning them. Traceability beats speed.
I'm wary of the leap from '60% already use AI' to 'you should too.' The right question isn't whether you adopt AI, it's which specific decision improves — and how you confirm the experience didn't get worse for the most vulnerable client.
Open Finance is the real opportunity. An MFI with decades of client relationships and aggregated data access can offer products no neobank can. Regulation arrives late, but it arrives.
The BCP/Yape case is the core pattern: real autonomy. Without a mandate outside the traditional org chart, any transformation ends up negotiated to death in committees.
Activity 1 · Digital Maturity Map
Interactive self-assessment — move the sliders and watch your radar update in real time.
Digital Maturity Map — Self-Assessment
Rate your institution across 5 dimensions from 1 to 5. The radar updates in real time to show strengths and gaps.
App, web, WhatsApp, digital onboarding
Dashboards, segmentation, predictive models
Credit, collections, back-office flows
Leadership, metrics, talent, learning
Maturity, governance, incident response
1 = not started · 3 = in progress · 5 = advanced and integrated
Guiding question: which digital gap most limits your institution's growth today?
MODULE 2
Cybersecurity: the link that cannot fail
Real threats, real impact, strategic response.
of financial-sector users faced online threats in 2025
Kaspersky, 2026
attacks per week at Latin American companies — 39% above the global average
FVSA, 2026
of financial organizations hit by ransomware in 2025
Kaspersky, 2026
in cyberattack losses across Latin America — +400% since 2017
FVSA, 2026
Why are MFIs an attractive target?
MFI risk profile
- !Sensitive data from vulnerable populations
- !Accelerated digitization without matching security
- !Technology providers with variable standards
- !Lower response capacity than mainstream banking
- !Trust as an asset — one incident destroys it
2026 threats: what's coming
Click each card for details.
Double-extortion ransomware
+
Encrypt and exfiltrate data to pressure payment. Especially damaging given the data MFIs handle.
Adaptive AI-powered malware
+
Autonomously adapts to the environment to evade defenses. Harder to detect than traditional malware.
WhatsApp trojans
+
Banking trojans distributed via messaging apps. No longer require exploiting technical vulnerabilities.
Deepfake social engineering
+
Hyper-personalized phishing using AI. Attacks are more credible and harder to distinguish from real communications.
Supply-chain attacks
+
Compromise the provider to reach multiple institutions. Trust between organizations becomes the vector.
Sources: Kaspersky Security Bulletin 2026 · CiberSafety Predictions 2026 · FVSA Digital Risks 2026
The human factor: the most vulnerable link
Most successful attacks don't exploit technical vulnerabilities — they require someone to click in the wrong place.
Hyper-personalized phishing
AI-generated emails and messages using real data about the recipient.
SMiShing and vishing
SMS and voice attacks impersonating known financial institutions.
Credential theft
Employees who reuse passwords or lack MFA are the most common entry vector.
Shadow IT
Unauthorized tools create invisible channels that bypass all controls.
Basic cybersecurity framework for MFIs
- 1
Vulnerability diagnosis
Know the real security state — not the aspirational one. Internal or external audit.
- 2
Incident response plan
Documented, tested, and known by everyone. Includes roles, escalation, communication with clients and regulators.
- 3
Continuous staff training
At every level, including directors. Trained staff is the first line of defense.
- 4
Provider standards
Technology providers must meet contractual and verifiable security standards.
- 5
Regular reporting to the board
Treat cyber risk as financial risk. Board-level cyber maturity reduces risk (IMF, 2024).
"The mass data breaches at large corporations left a clear message: protecting user information will be a competitive advantage in itself." — uFlow, 2026
Observations on cybersecurity
The most actionable number here isn't the $2.5B in losses — it's that 'board-level reporting reduces risk' (IMF, 2024). Governance of cyber risk correlates with lower real incident rates.
No 5-step framework protects an institution that treats cybersecurity as a compliance checkbox. The brutal question: when did you last actually test your incident response plan? If you haven't tested it, it doesn't exist.
I flip it: mature cybersecurity is a visible trust signal to clients and partners. MFIs that turn it into competitive advantage win contracts with regional cooperatives.
Fabiola says it straight and she's right: treat cyber risk as financial risk. If it doesn't reach the risk committee with the same seriousness as non-performing loans, it's underestimated.
MODULE 3
Roadmap: from reflection to action
The 5 steps you can actually do now.
Transformation is a governance decision
Receives cyber risk reports. Approves the digital strategy. Defines risk tolerance.
Leads transformation as corporate strategy. Appoints autonomous leadership with real authority.
Executes and implements. Reports. Proposes. Is NOT the owner of transformation — it enables it.
Digital transformation and cybersecurity are not technology projects — they are board and executive decisions.
The 5 steps you can do now
- 1
Honest diagnosis
The real level today — not the aspirational one. Gaps in both digital and cybersecurity.
- 2
Prioritize without scrapping everything
Build in parallel. Create the new without destroying what works.
- 3
Appoint autonomous leadership
With real authority to lead transformation. Outside the traditional org chart.
- 4
Strategic alliances
Fintechs, universities, the ecosystem. Don't build everything alone — and you don't have to.
- 5
Cybersecurity from governance
Board-level reports. Treat cyber risk as financial risk (IMF, 2024).
CEO perspective — Kaia Tanaka-Lindgren
"Digital transformation in microfinance operates on two horizons: operational efficiency in 18 months and institutional relevance in 10 years. The most expensive strategic error is optimizing for the first at the expense of the second. Trust, once eroded by a cyber incident or a poorly designed digital channel, takes decades to rebuild — if it rebuilds at all."
Kaia is ibizai's CEO and the team's multi-horizon strategic lens.
FINALLY
What the microfinance sector has that no fintech does
- Decades of trust earned with the client
- Deep territorial knowledge of the market
- Presence in communities technology doesn't reach on its own
- A social mission that goes beyond returns
Technology amplifies all of that. It does not replace it.
About Fabiola M. Herrera
With over three decades of professional experience, her most recent role as Deputy Manager of Systems and Innovation at the Central Bank of the Dominican Republic equipped her to spearhead strategic initiatives in financial technology and payment systems. Previously, as Director of the Payment Systems Department, she led the development of SIPARD, the Dominican Republic's National Payment System.
She then established the Cybersecurity Department, including developing national regulations for cybersecurity in the financial sector and creating a sector-specific Cyber Security Incident Response Team (CSIRT) for participants in the national payment system.
She is currently exploring applications of artificial intelligence and other emerging technologies to enhance risk management strategies and address inclusive financial education.
LinkedIn profileReady to Get Started?
Request your personalized program today. Tell us about your goals and we will design a learning experience that fits your needs, schedule, and budget.



