El Salvador · BCR Rules Committee · SSF

NRP-23 and NRP-32: change control must be supported by systems

NRP-23 (information security) and NRP-32 (cybersecurity in digital channels) govern exactly the ground where AI already writes code: the digital channels of supervised entities.

NRP-23 · Article 21, e) and f)

Requires change control “duly supported by information systems” and secure development that remediates vulnerabilities across the life cycle.

The clock: NRP-32 reforms give 3-month windows to adapt digital channels (the latest in force since November 2025).

What the regulation demands of software development

  • NRP-32, Art. 5. Remediate or mitigate ALL security gaps, not only critical ones, duly documented.
  • NRP-23, Art. 20. Controls and testing over changes to information systems.
  • NRP-23, Annex 1. Outsourced development must remediate vulnerabilities verifiably.
  • NRP-23, Art. 30. Internal audit over these processes.

How LineBreak answers

  • Nothing reaches production with known vulnerabilities. Every change is scanned before merging; if the scanner cannot run, the change does not pass. Exceptions are human, scoped to one exact finding, with name and reason on the record.
  • The AI writes the code; an identified person signs. Approved criteria carry the name of who approved them. The AI writing code can read them, but cannot modify them.
  • Every approval is cryptographically signed. Your auditor verifies it independently, without relying on us or on the team's word, years later if needed.
  • The evidence lives in YOUR infrastructure. Not on our servers. The record of every change (who approved what, when, with what result) travels with the code itself.

What LineBreak is NOT

  • LineBreak does not certify or guarantee compliance with any regulation: it produces the evidence your accountable people answer with.
  • It does not replace the roles your regulation requires (security officers, internal audit, regulatory reporting).
  • Decisions and accountability remain human. That is the product's design principle.

An AI-generated change is blocked, a person approves it by name, and the audit report is generated in front of you. With your risk team or your auditor present.