2020-11-19 | DOF 5605311Added · Updated
This agreement establishes general provisions for insurance institutions and mutual insurance societies to prevent and detect money laundering and terrorist financing. It defines key terms such as clients, beneficial owners, and politically exposed persons, and mandates the implementation of client identification policies, risk assessments, and internal controls. The document outlines specific reporting obligations and record-keeping requirements to ensure compliance with anti-money laundering standards.
DOF: 19/11/2020
AGREEMENT issuing the general provisions referenced in Article 492 of the Insurance and Surety Institutions Law, applicable to insurance institutions and mutual insurance societies
Agreement 117/2020
ARTURO HERRERA GUTIÉRREZ, Secretary of Finance and Public Credit, based on the provisions of Article 31, fraction VIII of the Organic Law of the Federal Public Administration; in relation to Article 492 of the Insurance and Surety Institutions Law, and in exercise of the powers conferred upon me by Article 6, fraction XXXIV of the Internal Regulations of the Secretariat of Finance and Public Credit, having heard the prior opinion of the National Insurance and Surety Commission, and
CONSIDERING
I.
That the National Development Plan 2019-2024 foresees in Strategy 1 regarding Policy and Government, the fight against money laundering and terrorist financing.
II.
That by virtue of Resolutions 1267 (1999), 1373 (2001), 1456 (2003) and others related, issued by the United Nations Security Council, Mexico recognizes the close relationship that exists between international terrorism and organized crime, committing itself to elaborate mechanisms to prevent and repress acts of terrorism.
III.
That since the year 2000, Mexico has been a full member of the Financial Action Task Force on Money Laundering (FATF), an intergovernmental body that sets international standards in matters of prevention and combat against money laundering and terrorist financing.
IV.
That Mexico has actively participated in the design and implementation of the 40 recommendations of the FATF, through which the adoption of necessary measures is foreseen for the identification, detection, and seizure or confiscation of all funds used or assigned to commit the crimes of terrorism or its financing, as well as the proceeds obtained from such criminal conduct.
V.
That the FATF establishes in its Recommendation 4 that member countries must implement procedures to comply with measures similar to those established in the United Nations Convention against Illicit Traffic in Narcotic Drugs and Psychotropic Substances of 1988 (Vienna Convention), the United Nations Convention against Transnational Organized Crime and its three Supplementary Protocols (Palermo Convention) and the International Convention for the Suppression of the Financing of Terrorism of 1999; instruments signed and ratified by the Mexican State with the object of promoting the effective implementation of legal, regulatory and operational measures to combat money laundering, terrorist financing and other threats that undermine the security and stability of nations and the international financial system.
VI.
That on April 4, 2015, the General Law of Insurance and Mutual Insurance Societies and the Federal Law of Surety Institutions were repealed and the Insurance and Surety Institutions Law entered into force.
VII.
That to date, in matters of prevention and detection of acts, omissions and operations of money laundering and terrorist financing, the General Provisions referred to in Article 140 of the General Law of Insurance and Mutual Insurance Societies and the Provisions referred to in Article 112 of the Federal Law of Surety Institutions remain in force, until such time as the provisions referred to in Article 492 of the Insurance and Surety Institutions Law are issued, in accordance with the Third Transitory Provision of this latter regulation.
VIII.
That to address the recommendations made to Mexico by the FATF, in connection with the Mutual Evaluation of 2018, it is necessary to issue the provisions referred to in Article 492 of the Insurance and Surety Institutions Law and integrate into a single regulation the provisions applicable to insurance institutions and mutual insurance societies, as well as to surety institutions, and once the prior opinion of the National Insurance and Surety Commission has been heard, I have deemed it appropriate to issue the present:
AGREEMENT BY WHICH GENERAL PROVISIONS ARE ISSUED REFERENCED IN ARTICLE 492 OF THE INSURANCE AND SURETY INSTITUTIONS LAW, APPLICABLE TO INSURANCE INSTITUTIONS AND MUTUAL INSURANCE SOCIETIES
CHAPTER I
OF THE OBJECT AND DEFINITIONS
First. These Provisions have the object, in accordance with what is provided by Article 492 of the Insurance and Surety Institutions Law:
I. To establish the minimum measures and procedures that Insurance Institutions and Mutual Insurance Societies must observe to prevent and detect acts, omissions or operations that could favor, provide help, aid or cooperation of any kind for the commission of the crimes provided for in articles 139, 139 Quater, 148 Bis or 400 Bis of the Federal Penal Code;
II. To indicate the form, terms and modality, in accordance with which Insurance Institutions and Mutual Insurance Societies must present to the Secretariat, through the Commission, reports on:
a) The acts, operations and services they carry out with their Clients relating to fraction I of this Provision.
b) The acts, operations or services carried out by members of their board of directors, executives, officials, employees or agents, which could update the circumstances provided for in fraction I of this Provision, as well as contravene or fail to comply with the obligations established in these Provisions.
III. To set guidelines on the procedure and criteria that Institutions, Mutual Societies and Agents must observe to comply with what is provided in these Provisions.
In accordance with the general provisions issued by the Commission, Institutions will agree with the legal entities referred to in Article 102 of the Law, the form and terms in which they will contribute to the compliance with these Provisions.
Second. For the purposes of these Provisions, the following shall be understood, in singular or plural:
I. Agents, as natural and legal persons, who are not linked to Institutions by an employment relationship, who intervene in the contracting of insurance and sureties through the exchange of proposals and acceptances, as well as in advising to celebrate, maintain or modify them, according to the best convenience of the contracting parties and who have the authorization of the Commission for this purpose.
II. Archive or Registry, as the set of data and documents that are kept or stored in printed format or in electronic, optical or any other technology media, provided that, in these latter media, it is ensured that the information has remained intact and unaltered from the moment it was generated for the first time in its definitive form and is accessible for subsequent consultation, with the aim of integrating, conserving and evidencing the Operations of Institutions or Mutual Insurance Societies.
III. Beneficiary, as the person:
a) Designated by the insured or by Law, so that, when the eventuality provided for in the insurance contract occurs, the money is paid to them or the services that constitute the content of the obligation owed by the Institution or Mutual Insurance Society are provided.
b) Who has the status of creditor of the obligation guaranteed in a surety policy or a bond certificate.
c) Who has the status of trustee, in a trust contract.
d) In whose favor stipulations are made in a mandate, commission or any other contract.
IV. Client, as the natural or legal person or fiduciary, who has the status of:
a) Policyholder, the party obliged to pay a premium in a contract or insurance policy other than that of surety or bond, and who is obliged to pay so that when the eventuality provided for in said documents occurs, the Institution or Mutual Insurance Society compensates for the damage, pays a sum of money or provides the services that constitute the content of the obligation to its charge.
b) Insured, when not being the policyholder, pays the premium in whole or in part or allocates resources for investment in a contract or insurance policy, so that when the eventuality provided for in said documents occurs, the Insurance Institution, to him or his Beneficiary, compensates for the damage, pays a sum of money or provides the services that constitute the content of the obligation to its charge.
c) Policyholder, surety or jointly liable party in a contract or surety policy or surety insurance, obliged, as appropriate, to pay a premium so that the Institution fulfills its obligations to its charge, when they do not do so.
d) Settlor in a trust contract, in which the Institution is the trustee.
e) Principal in a commercial commission.
f) Mandator in the case of a mandate.
g) Obligated to pay a consideration for the services received from the Institution or Mutual Insurance Society, by virtue of a contract other than those of insurance or surety.
h) Buyer of the salvage, the natural or legal person who acquires goods, by paying them to the Insurance Institution, after the occurrence of a loss, to which the insurer determines an estimated recovery value.
Natural persons who are subject to the tax regime applicable to natural persons with business activity shall be considered as legal persons for the purposes of what is established in these Provisions, except with respect to the integration of their file, which must be carried out in terms of what is established in the Fourth Provision.
V. Commission, as the National Insurance and Surety Commission.
VI. Committee, as the Communication and Control Committee referred to in the Forty-Fourth Provision.
VII. Contract, as the insurance contract; surety contract; trust contract, to the commission, to the mandate, and any other that Institutions or Mutual Insurance Societies celebrate with their Clients to carry out any Operation.
VIII. Consortium, as the set of legal persons linked to each other by one or more natural persons that, integrating a group of persons, have Control of the former.
IX. Control, as the capacity of a person or group of persons, through the ownership of securities, by the celebration of a contract or by any other legal act, to:
a) Impose, directly or indirectly, decisions in the general assembly of shareholders or partners or in the equivalent governing body of a legal person.
b) Appoint or remove the majority of the counselors, administrators or equivalents of a legal person.
c) Maintain the ownership of rights that allow, directly or indirectly, to exercise the vote with respect to more than fifty percent of the share capital of a legal person.
d) Direct, directly or indirectly, the administration, the strategy or the main policies of a legal person.
Additionally, it shall be understood that the person who directly or indirectly acquires twenty-five percent or more of the share composition or share capital of a legal person exercises Control.
X. Concentrating Account, as the bank or deposit account that an Institution or Mutual Insurance Society opens in its favor in a credit institution, to receive through said account resources from Clients or debtors.
XI. Device, as the equipment that allows access to the worldwide network called Internet, which can be used to celebrate Operations.
XII. Foreign Financial Entity, as the entity or institution constituted outside the national territory that provides financial services and that is regulated and supervised in matters of prevention of operations with resources of illicit origin and terrorist financing by the authorities of the country in which it has been constituted.
XIII. Trust, it shall be understood as such both the Trusts celebrated or constituted in accordance with national legislation within the territory of the United Mexican States, as well as any legal instrument or entity analogous to this one, celebrated or constituted in accordance with foreign laws and outside the national territory.
XIV. Electronic Signature, as the traces or data in electronic form recorded in a Data Message, or attached or logically associated with it by any technology, which are used to identify the subscriber or originator of the instruction of some Operation or financial service and indicate that the signer approves the information contained in the Data Message, and that produces the same legal effects as the autograph signature.
XV. Advanced Electronic Signature, as the digital certificate with which natural and legal persons must comply, in accordance with what is provided by Article 17-D of the Federal Tax Code.
XVI. Geolocation, as the geographic coordinates of latitude and longitude in which the Device is located.
XVII. Degree of Risk, as the classification of Clients carried out by the Institution or Mutual Insurance Society based on the evaluation of its Risk.
XVIII. Business Group, as the set of legal persons organized under schemes of direct or indirect participation in the share capital, in which a company maintains Control of said legal persons. Likewise, financial groups constituted in accordance with the Law to Regulate Financial Groupings shall be considered as a Business Group.
XIX. Technological Infrastructure, as the computer equipment, data processing and communications facilities, equipment and communications networks, operating systems, databases, applications and systems that Institutions or Mutual Insurance Societies use to support their Operations.
XX. Insurance Institution, as the anonymous society authorized to organize and operate in accordance with the Law as an insurance institution, its object being the carrying out of the Operations, in terms of Article 25 of the Law.
XXI. Surety Institution, as the anonymous society authorized to organize and operate in accordance with the Law as a surety institution, its object being the granting of sureties for consideration, in terms of Article 36 of the Law.
XXII. Institution(s), as the Insurance Institution and the Surety Institution.
XXIII. Law, as the Insurance and Surety Institutions Law.
XXIV. Blocked Persons List, as the list provided by the Secretariat referred to in Chapter XV of these Provisions.
XXV. Compliance Manual, as the document referred to in the Seventy-Third Provision.
XXVI. Data Message, as the information generated, sent, received or archived by electronic, optical or any other technology means, in accordance with the Code of Commerce.
XXVII. Mitigants, as the policies and procedures implemented by Institutions and Mutual Insurance Societies that contribute to managing and reducing exposure to the Risks identified in the methodology referred to in Chapter III of these Provisions.
XXVIII. Novel model, as that which for the provision of financial services uses tools or technological means with modalities different from those existing in the market at the time the temporary authorization referred to in the Law to Regulate Financial Technology Institutions is granted.
XXIX. Compliance Officer, as the person referred to in the Forty-Eighth Provision.
XXX. Operations, as the operations referred to in the Law:
a) With respect to Insurance Institutions in Article 118, fractions I, II, IX, X, XI, XV, XVI, XXI, XXIII and XXIV, of the Law, and the analogous and connected ones to the foregoing that the Secretariat authorizes in accordance with fraction XXVI of the cited provision, as well as salvage operations, as they are defined in the general provisions issued by the Commission, when there is the possibility that they be settled in cash.
b) In the case of Mutual Insurance Societies in Article 341, fractions I, VI, VII, VIII, XII, of the Law and the analogous and connected ones to the foregoing that the Secretariat authorizes in accordance with fraction XIII.
c) For Surety Institutions, those established in Article 144, fractions I, II, IX, X, XI XIV, XVII and XVIII of the Law, and the others analogous and connected to the foregoing that the Secretariat authorizes.
XXXI. Internal Concerning Operation, as the Operation, activity, conduct or behavior of any of the shareholders, partners, executives, officials, employees, agents and of those who exercise Control of the Institutions or Mutual Insurance Societies, which by its characteristics, could contravene, violate or evade the application of what is provided by the Law or these Provisions, or that, for any other cause, results doubtful for the Institutions or Mutual Insurance Societies by considering that it could favor or not alert on acts, omissions or Operations that could favor, provide help, aid or cooperation of any kind for the commission of the crimes provided for in articles 139, 139 Quater, 148 Bis or 400 Bis of the Federal Penal Code.
XXXII. Unusual Operation, as the Operation, activity, conduct or behavior of a Client that does not match the background or known activity by the Institution or Mutual Insurance Society or declared to it, or with the initial or habitual transactional profile of said Client, in function to the origin or destination of the resources, as well as to the amount, frequency, type or nature of the Operation in question, without there being a reasonable justification for said operation, activity, conduct or behavior, or that Operation, activity, conduct or behavior that a Client carries out or intends to carry out with the Institution or Mutual Insurance Society in question in which, for any cause, it considers that the corresponding resources could be used to provide help, aid or cooperation of any kind for the commission of the crimes provided for in articles 139, 139 Quater, 148 Bis or 400 Bis of the Federal Penal Code.
XXXIII. Relevant Operation, as the Operation that is carried out with legal tender banknotes and metallic coins in the United Mexican States or in any other country, as well as with traveler's checks and coins minted in platinum, gold and silver, for an amount equal to or greater than the equivalent in national currency to seven thousand five hundred United States dollars.
For the purposes of calculating the amount of the Operations to its equivalent in national currency, the exchange rate to settle obligations denominated in foreign currency payable in the United Mexican States, published by the Bank of Mexico in the Official Journal of the Federation, on the next banking business day prior to the date on which the Operation is carried out, shall be considered.
XXXIV. Politically Exposed Person, as that individual who performs or has performed prominent public functions in a foreign country or in national territory, considering among others, heads of state or government, political leaders, high-ranking government, judicial or military officials, high executives of state-owned companies or officials or important members of political parties and international organizations; understood as those entities established through official political agreements between states, which have the status of international treaties; whose existence is recognized by law in their respective member states and are not treated as resident institutional units of the countries in which they are located.
The spouse, concubine, concubinary and persons with whom they maintain kinship by blood or affinity up to the second degree, as well as legal persons with which the Politically Exposed Person maintains patrimonial links, are assimilated to Politically Exposed Persons.
With respect to this, national Politically Exposed Persons shall continue to be considered those persons who had been cataloged with such character, during the year following that in which they left their office.
Without prejudice to the foregoing, in cases where a person ceases to meet the characteristics required to be considered as a national Politically Exposed Person, within the year immediately preceding that in which the new commercial relationship with any Institution or Mutual Insurance Society begins, the latter must catalog them as such, during the year following the start of the new relationship.
XXXV. Beneficial Owner, as the natural person who, not being the Client, or Beneficiary, through another or by any act or mechanism, obtains the benefits derived from a contract or Operation celebrated with the Institution or Mutual Insurance Society and is who, in the last instance, exercises the rights of use, enjoyment, benefit or disposal of the resources, that is, as the true owner of the resources.
The term Beneficial Owner also includes persons who exercise Control over a legal person, as well as, where applicable, persons who can instruct or determine, for their own economic benefit, the acts susceptible to be carried out through Trusts, mandates or commissions.
XXXVI. Resource Provider, as that person who, not being the Client in an Operation with a savings or investment component, contributes the resources without obtaining the economic benefits derived from that Operation.
XXXVII. Risk, as the probability that Institutions or Mutual Insurance Societies may be used by Clients to carry out acts or Operations through which they could favor, provide help, aid or cooperation of any kind for the commission of the crimes provided for in articles 139, 139 Quater, 148 Bis or 400 Bis of the Federal Penal Code.
XXXVIII. Secretariat, as the Secretariat of Finance and Public Credit.
XXXIX. Mutual Insurance Society, as the society authorized to organize and operate in accordance with the Law with such character.
CHAPTER II
CLIENT IDENTIFICATION POLICY
Third. Institutions and Mutual Insurance Societies must elaborate and observe a client identification policy, which will comprise, at least, the guidelines established for such effect in these Provisions, as well as the criteria, measures and procedures that are required for its due compliance, including those related to the verification and updating of the data provided by Clients.
In the elaboration of the client identification policy, guidelines must be included and observed
for the identification of Beneficiaries, Real Owners, and Resource Providers.
The aforementioned policy and guidelines shall form an integral part of the Compliance Manual of the Institution or Mutual Insurance Society.
Agents shall apply the Client identification policy of the Institutions with respect to which they act as intermediaries; for these purposes, the Institutions shall deliver or make available to them the Compliance Manual or any other document or manual prepared by the Institution or Mutual Insurance Society, as well as any modifications made thereto, leaving a record thereof.
Fourth. Institutions and Mutual Insurance Societies shall integrate and maintain an identification file for each of their Clients, prior to the execution of contracts to carry out Operations of any type.
To integrate the Client identification files, they must meet at least the following requirements:
I. Regarding Clients who are natural persons, declaring themselves to be of Mexican nationality, those indicated in Annex 1.
Regardless of the data and documents collected from the Client, the same data and, where applicable, documents from Annex 1 must be integrated into the file, regarding natural persons of Mexican nationality when they have the status of:
a) Real Owner.
b) Spouse or economic dependent, when the Client has been classified with a High Risk Grade.
c) Beneficiaries.
II. Regarding Clients who are natural persons, declaring themselves to be of foreign nationality under conditions of temporary or permanent resident stay, in terms of the Migration Law, or in the capacity of diplomatic and consular representations in terms of the Guidelines for the issuance of non-ordinary visas, those indicated in Annex 2.
Regardless of the data and documents collected from the Client, the same data and information from Annex 2 must be integrated into the file, regarding natural persons of foreign nationality, under conditions of temporary or permanent resident stay, in terms of the aforementioned Law, or in the capacity of diplomatic and consular representations in terms of the aforementioned Guidelines, that have the status of:
a) Real Owner.
b) Spouse or economic dependent, when the Client has been classified with a High Risk Grade.
c) Beneficiary.
III. Regarding Clients who are natural persons, of foreign nationality, who declare that they are not in the national territory under conditions of temporary or permanent resident stay in terms of the Migration Law, those indicated in Annex 3.
Regardless of the data and documents collected from the Client, the same data and information from Annex 3 must be integrated into the file, regarding natural persons of foreign nationality who declare not to be in the national territory under conditions of temporary or permanent resident stay, that have the status of:
a) Real Owner.
b) Spouse or economic dependent, when the Client has been classified with a High Risk Grade.
c) Beneficiary.
IV. Regarding Clients who are legal entities of Mexican nationality, those indicated in Annex 4.
The same data and information must be collected and integrated into the Client files, regarding legal entities of Mexican nationality that have the status of Beneficiaries.
V. Regarding Clients who are legal entities of foreign nationality, those indicated in Annex 5.
The same data and information must be collected and integrated into the Client files, regarding legal entities of Mexican nationality that have the status of Beneficiaries.
VI. Regarding the attorneys-in-fact of Clients, when they act through them, those indicated in Annex 6, even regarding Clients that are societies, departments, and entities referred to in Annex 7.
VII. Regarding clients that are societies, departments, and entities referred to in Annex 7, those indicated in Annex 8 as simplified measures for their identification.
The measures may only be applied if the societies, departments, and entities are classified as Clients with a Risk Grade other than High in terms of the Twenty-Eighth of these Provisions.
VIII. Regarding fiduciaries, the identification file must meet the requirements indicated in Annex 10.
The same data and information must be collected and integrated into the Client files, regarding Trusts that have the status of Beneficiaries.
IX. Resource Providers must integrate those indicated in Annex 11, when at the time of contracting an insurance with a savings/investment component, the Institution or Mutual Insurance Society identifies that the resources are not from the insured and/or are not contributed by virtue of a labor benefit.
Institutions and Mutual Insurance Societies must identify whether the Real Owner or the Resource Provider is a Politically Exposed Person in order, if applicable, to comply with what is indicated in Provision Thirty-First.
The types and characteristics of the data and documents that, according to each of the Annexes, must be integrated into the Client files are specified in Annex 9.
Institutions and Mutual Insurance Societies must verify the data and documents that their potential Clients provide to prove their identity in order to comply with the obligation provided in the first paragraph of this Provision. Verification may be carried out non-presentially in accordance with the provisions issued for this purpose by the Commission, to the extent applicable.
When the identification documents provided present strikethroughs or amendments, another means of identification must be collected or, in default thereof, two banking or commercial references and two personal references must be requested, which include the phone number, first and last names without abbreviations, address composed of the same data as indicated in Annex 9, and phone number of those who issue them.
The authenticity of the documents indicated in the previous paragraph must be verified with the persons who sign such references, before the Operation is executed.
The Client identification file may be used for all Operations that he/she has executed with the Institution or Mutual Insurance Society.
Simple copies of the documents that must be integrated into the Client identification files must be compared against the corresponding original documents that are physically present and must be legible.
The identification requirements provided in this Provision shall be applicable to all types of Operations that Institutions and Mutual Insurance Societies execute directly or through third parties on behalf of or for the account of the Institutions and Mutual Insurance Societies themselves, including numbered and coded ones. Regarding Operations executed through third parties, Institutions must identify the name of the country in which the domicile of said third parties is located.
Institutions and Mutual Insurance Societies may keep in Files or Records, separately, the data and documents that must form part of the identification files of their Clients, without the need to integrate them into a single physical file, provided that automated systems are available that allow combining said data and documents for timely consultation by the Institutions and Mutual Insurance Societies themselves, or by the Secretariat or the Commission, at the request of the latter in terms of the Provisions and the others that are applicable.
Institutions and Mutual Insurance Societies that execute Operations through Devices in a non-presential manner, in accordance with the general provisions issued for this purpose by the Commission, must request and obtain from their Clients, prior consent of these, the Geolocation of the Device from which they execute the Operation and also the data and identification documents established for these purposes in each of the aforementioned Annexes.
Institutions and Mutual Insurance Societies must not carry out the execution of the Operation through Devices in a non-presential manner with Clients, when they do not collect the data regarding Geolocation in accordance with the previous paragraph.
The consent that, in terms of this Provision, Institutions and Mutual Insurance Societies obtain from their Clients to identify the place where the Operation was performed, may be obtained through Electronic Signature, Advanced Electronic Signature, or in accordance with the general provisions issued for this purpose by the Commission. Such Client consent shall serve as proof to legally establish the execution of the Operation that he/she carries out with the Institution or Mutual Insurance Society through non-presential Devices.
Institutions and Mutual Insurance Societies may collect digital versions of the documentation referred to in this Provision in a non-presential manner and through optical means or any other technology.
The digital versions that Institutions and Mutual Insurance Societies collect for identification purposes must allow for verification. Likewise, said digital versions must be kept in their Files or Records in accordance with these Provisions.
Institutions and Mutual Insurance Societies must establish in their Compliance Manual, the criteria and mechanisms that they must adopt to comply with what is stated in this Provision.
Fifth. The Institution or Mutual Insurance Society, prior to establishing or initiating a commercial relationship with a Client, must hold a personal interview with said Client or their attorney-in-fact, in order to collect the respective identification data and documents. The results of the interview must be recorded in writing or electronically and appear in the Files or Records and be integrated into the Client's identification file.
Institutions and Mutual Insurance Societies may sign agreements with third parties for the conduct of the interview referred to in the previous paragraph.
Regarding Operations that are executed in a non-presential manner, the interview referred to in the previous paragraph may be carried out in a non-presential manner, for which purpose forms that interact with the Client may be used, both in terms of the general provisions issued for this purpose by the Commission.
Likewise, prior notice to the Commission, Institutions that are subsidiaries in accordance with Article 75 of the Law, may sign agreements to carry out the interview with financial institutions from abroad, their branches, and subsidiaries that have participation in them, provided that they do not operate in countries of high risk or non-cooperative as indicated by the Financial Action Task Force. Institutions that fall under the scenario provided in this paragraph shall be responsible for compliance with the obligations regarding identification and client knowledge established in these Provisions.
In all cases, Institutions and Mutual Insurance Societies shall be responsible for compliance with the obligations regarding identification and client knowledge established in these Provisions.
Sixth. In the event that the Institution is the holder of a Concentrating Account, it must:
I. Apply with respect to its Clients who carry out Operations in such account, the identification and knowledge policies and measures provided in these Provisions.
II. Follow up on all Operations carried out in said Concentrating Account.
III. Report to the Secretariat, in terms of these Provisions, the Relevant Operations, Unusual Operations, and Concerning Internal Operations that correspond in relation to its Clients, executives, officials, employees, or attorneys-in-fact who intervene in said Concentrating Account.
Seventh. As an exception to what is provided in Provisions Fourth and Fifth, Institutions and Mutual Insurance Societies, in the case of Operations that by their characteristics are of Low Risk Grade:
I. Prior to executing Contracts, they may integrate the identification file of each of their Clients with the data from the Annexes cited in Provision Fourth, as applicable, and complete the verification of identity against the presentation of the official identification exhibited by Clients for these purposes. At that same moment, Institutions and Mutual Insurance Societies will record in the Client's file, the type of identification and its number, as well as the issuer, with the indication that they validated them previously.
II. The measure indicated in the preceding subsection may be employed by Institutions and Mutual Insurance Societies, provided that the conditions indicated in Provision Ninth are met in the following scenarios:
a) Insurance operations with a savings/investment component with an annual premium less than two thousand five hundred United States dollars, and that the savings or investment amount is less than seven thousand five hundred United States dollars.
b) Accident and illness, damage, auto, and life insurance operations without a savings or investment component, with an annual premium between two thousand five hundred and seven thousand five hundred United States dollars.
III. The measure indicated in the preceding subsection I may be employed by Institutions in the following cases:
a) Sureties or cautions certificates intended to guarantee the provisional freedom of a Client due to a traffic accident.
b) Sureties or cautions certificates whose premium amount is equal to or less than three thousand seven hundred United States dollars.
IV. Prior to executing contracts, they may integrate the identification file of each of their Clients with their name, address, and date of birth with the characteristics indicated in Annex 9, for natural persons; and with their trade name or corporate name, address, and date of incorporation, for legal entities, with the characteristics indicated in Annexes 4 and 5. Before resources are delivered for any concept or at the latest when Clients present themselves to exercise their rights or when they present themselves to exercise their rights and at the latest before resources are delivered for any concept, Institutions and Mutual Insurance Societies will complete the verification of their identity against the presentation of the official identification exhibited by Clients for these purposes. At that same moment, they will record in the Client's file, the type of identification and its number, as well as the issuer, with the indication that they validated them previously.
V. The measure indicated in the preceding subsection may be employed by Institutions and Mutual Insurance Societies in the following cases and provided that the conditions indicated in Provision Ninth are met:
a) Insurance operations with an annual premium less than two thousand five hundred United States dollars.
b) Pension insurance derived from social security laws.
c) In sureties whose premium amount is equal to or less than one thousand five hundred United States dollars.
In the scenarios indicated in the preceding subsections, Institutions and Mutual Insurance Societies must integrate the file in accordance with what is provided in Provisions Fourth and Fifth or, if applicable, with what is prescribed in subsection I above, at the moment it is detected that the Client with the same operation or through several exceeds the thresholds indicated.
The simplified scheme established in this Provision does not apply to the Operations provided in Provision Fourth, subsection VIII of these Provisions.
Institutions and Mutual Insurance Societies must inform their Clients that resources will not be delivered nor rights exercised until the verification process referred to in this Provision is concluded.
Eighth. Regarding Beneficiaries, at the moment they are named, Institutions and Mutual Insurance Societies must integrate their data into the file of the Client who designates them.
In the case of natural persons, full name, address, and date of birth; and regarding legal entities, their trade name or corporate name, date of incorporation, and address with the characteristics indicated in Annexes 4, 5, or 9 as applicable.
When the Beneficiary of a Client is a politically exposed person, regardless of their nationality, the institution or Mutual Insurance Society must collect the aforementioned requirements and verify their identities.
The file must be completed in accordance with what is provided in Provisions Fourth, Fifth, and Seventh, respectively, before resources are delivered for any concept and at the latest when they present themselves to exercise their rights, or when they present themselves to exercise their rights and at the latest before resources are delivered for any concept, except that they intervene in the signing of the respective contract, in which case from that moment the data and respective documentation must be integrated into the file.
The Client identification file must be completed on the dates indicated or at the signing of the contract, in accordance with Provisions Fourth and Fifth.
Ninth. Institutions and Mutual Insurance Societies may implement the simplified or reduced schemes indicated in Provision Seventh, when:
I. They have criteria and procedures to determine Operations that by their characteristics are of low Risk;
II. The criteria and procedures consider measures that Institutions and Mutual Insurance Societies adopt regarding the number, types, and amount of Operations, as well as their monitoring to determine those that are carried out outside the expected transactional behavior, and
III. During the last quarter of each year, the Committee or the Compliance Officer in charge of the Committee determines whether, during the following fiscal year, they will apply the indicated schemes, considering, among other aspects, the observations pending to be resolved regarding the integration of files, that have been formulated by their internal audit area, independent external auditor, or the Commission.
Tenth. In the event of Operations executed by a means other than presential, such as electronic, optical, or any other technology or Technological Infrastructure, Institutions and Mutual Insurance Societies must have specific and adequate measures to mitigate the high Risk involved, such as:
a) Previously integrate the Client identification file in accordance with what is established in these Provisions.
b) Establish mechanisms to identify the Client in accordance with the general provisions issued for this purpose by the Commission.
c) Develop procedures to prevent the improper use of said means or technologies, which must be contained in their Compliance Manual.
Eleventh. When Institutions are part of financial groups, the Client identification file may be integrated and maintained by any of the other entities that form part of the same group, provided that:
I. The entity that integrates and maintains said file has the express authorization of the Client to provide the data and documents related to their identification or the digital version of the latter to any of the entities that make up the financial group with which they intend to establish a commercial relationship.
II. The entities that make up the financial group sign an agreement among themselves, in which they expressly stipulate that:
a) They may exchange data and documents, as well as digital versions related to Client identification, in order to establish a new commercial relationship with the same.
b) The entity that integrates the file undertakes, on the one hand, to do so under the same terms in which the other entities must integrate it in accordance with the provisions applicable to them in this matter, and on the other hand, to keep it available to the other entities for consultation and to provide it to the authority in charge of its inspection and oversight, when the latter so requires.
c) In the event that any of the entities obliged to integrate Client identification files under terms similar to those provided in these Provisions separates from the financial group, it must integrate the identification file of its Clients under those terms.
Twelfth. Commercial relationships may not be established with anonymous Clients or under fictitious names, so Contracts may only be executed until they have satisfactorily met the identification requirements of their Clients.
Institutions and Mutual Insurance Societies may not apply to their Clients the simplified measures provided in this Chapter, when they have a well-founded suspicion or indications that the resources, goods, or values that their Clients intend to use to carry out an Operation, could be related to the acts or conduct referred to in Articles 139, 139 Quater, 148 Bis, or 400 Bis of the Federal Penal Code.
The policies, criteria, measures, and procedures that Institutions or Mutual Insurance Societies develop to determine what is stated in the previous paragraph must be documented in their Compliance Manual.
Thirteenth. Institutions or Mutual Insurance Societies may suspend the identification process of their potential Client, when they reasonably estimate:
I. That they could be related to acts or conduct referred to in Articles 139, 139 Quater, 148 Bis, or 400 Bis of the Federal Penal Code.
II. That continuing with the identification process could prevent or alert the Client that the Institution or Mutual Insurance Society considers that the resources, goods, or values are related to acts or conduct referred to in Articles 139, 139 Quater, 148 Bis, or 400 Bis of the Federal Penal Code.
III. The existence of Risks in accordance with the criteria established in the Compliance Manual.
In the event that the suspension referred to in this Provision is carried out, the Institutions or Mutual Insurance Societies must generate the 24-hour Unusual Operation Report corresponding to the information they have regarding the possible Client in question.
The report referred to in the preceding paragraph must be sent to the Secretariat, through the Commission, within 24 hours from the time the Institution or Mutual Insurance Society becomes aware of the information indicated in this Provision, using the corresponding official format with the information they have regarding the possible Client in question, which may be prepared manually.
For the purposes of what is established in this Provision, Institutions or Mutual Insurance Societies must establish in their Compliance Manual, or in another document or manual prepared by the Institution or Mutual Insurance Society itself, the necessary policies, criteria, measures, and procedures.
Fourteenth. Regarding Operations that are contracted through third parties, in accordance with the Law, identification files may be compiled and preserved by them, under the following terms:
I. Insurance Institutions and Mutual Insurance Societies may apply this Provision, among others, in the following cases:
a) Trusts that are constituted to fulfill general labor or social security benefits, in which contributions are received from the dependencies and entities of the Federal Public Administration, from a federal entity or municipality, or from companies, their unions, or persons belonging to both. For example, trusts in which resources related to seniority premiums are affected; individual pension funds, life annuities, dividends, and insured sums in which reserves for pension or retirement funds for personnel are managed, complementary to those established by social security laws and seniority premiums, or those constituted to establish multiple benefits or pensions, for mortgage loans to employees, and savings funds and mutual aid benefits.
b) Collective, group, and fleet insurance.
c) Insurance that is offered and contracted with clients of credit institutions and other financial institutions, through them, directly in their offices or via electronic banking.
d) Operations that are celebrated through Agents in terms of Article 91 of the Law, or through legal entities, which without being Agents intervene exclusively in the intermediation of adhesion contracts in accordance with Articles 91 and 102 of the Law.
II. Surety Institutions may apply this Provision, among others, in the following cases:
a) Fidelity Sureties, and those known as maximum amount sureties.
b) Regarding Trusts, identification files of all parties appearing to subscribe the respective Contracts will invariably be compiled.
What is established in this Provision shall also apply to the identification of trustees of Trusts in which, upon constitution, the ownership of the trust assets is transferred and which serve as a payment instrument for unfulfilled obligations, in the case of sureties granted by the Surety Institutions themselves.
This Provision shall also apply in the case of Operations celebrated by the Institutions or Mutual Insurance Societies with fiduciary institutions when they agree and comply with the requirements provided in the following Provision.
Fifteenth. When Institutions or Mutual Insurance Societies decide to apply the previous Provision, they must agree with the third parties who, in their substitution, compile and preserve the Client identification files, at minimum, the following:
I. Compile and preserve, in terms of what is provided in these Provisions, the identification files of the Clients.
II. The obligation to keep the files available for consultation and to provide them promptly to the Institution or Mutual Insurance Society for itself, or to present them to the Commission, if so required, or for the Commission to deliver them to the Secretariat.
III. Establish mechanisms so that the Institutions or Mutual Insurance Societies themselves can:
a) Verify, randomly, that such files are compiled in accordance with what is indicated in these Provisions.
b) Preserve the identification file of those workers or personnel, once they cease to provide their services to third-party applicants or contractors, as well as when the relationship between the Institution or Mutual Insurance Society and the third parties who, in its substitution, compiled the file concludes.
Institutions or Mutual Insurance Societies will be responsible at all times for compliance with the obligations regarding Client identification established in these Provisions, for which effect, they must establish in the Compliance Manual the mechanisms they will adopt to comply with what is indicated in this paragraph.
Sixteenth. Regarding insurance and/or surety contracts that legal entity Clients contract for their workers, the identification file of each of those workers may be compiled and preserved by said applicant Client instead of the Institution or Mutual Insurance Society. In this case, the Institution or Mutual Insurance Society in question must contractually agree with the applicant Client the obligation to keep said file available for consultation and provide it to the Institution itself, so that it can present it to the Commission, at the moment the latter so requires, or for the Commission to deliver it to the Secretariat.
Seventeenth. In the case of Operations celebrated at the request of dependencies or entities of the Federal, State, or Municipal Public Administration on behalf of their workers, the identification files of each of those workers may be compiled only with the data and copies of their identifications, and preserved by the corresponding dependency or entity, during the validity of the labor relationship with the employee in question.
In this case, the Institutions and Mutual Insurance Societies must contractually agree with the requesting dependency or entity the obligation to keep said file available for consultation and provide it promptly to the Institution and Mutual Society for itself, or to present it to the Commission, if so required, or for the Commission to deliver it to the Secretariat.
CHAPTER III
RISK-BASED APPROACH
Eighteenth. Institutions and Mutual Insurance Societies must design and implement a methodology to carry out a Risk Assessment of the risks to which they are exposed derived from their products, services, Clients, countries or geographic areas, transactions, and sending or distribution channels with which they operate.
The design of the methodology referred to in the preceding paragraph must be established in their Compliance Manual, or in another document or manual prepared by the Institution or Mutual Insurance Society, and must establish and describe all processes that will be carried out for the identification, measurement, and mitigation of Risks, for which they must take into account, the Risk factors identified for such effect, as well as the information that results applicable given the context of each Institution or Mutual Insurance Society contained in the national risk assessment and its updates, which the Secretariat makes known to them through the Commission.
Regarding Institutions that are part of financial groups in terms of the Law to Regulate Financial Aggregations, they must establish in the design of the methodology how the results of the methodology that, if applicable, have been implemented by the other financial entities that make up the corresponding group will be taken into account.
Likewise, Institutions and Mutual Insurance Societies will carry out a Risk Assessment of the risks to which they are exposed in accordance with what is established in this Chapter, prior to the launch or use of new products, services, practices, or technologies.
Nineteenth. Institutions and Mutual Insurance Societies, for the design of the risk assessment methodology, must comply with the following:
I. Identify the elements and indicators associated with each of them that explain how and to what extent the Institution or Mutual Society may be exposed to Risk, considering at least the following elements:
a) Products and services.
b) Clients.
c) Countries and geographic areas.
d) Transactions and sending or distribution channels linked to the Operations of the Institution or Mutual Insurance Society and with its Clients.
Within the process of identifying Risk indicators, all products, services, types of Clients, countries or geographic areas, transactions, and sending or distribution channels, with which the Institution or Mutual Insurance Society operates, must be considered.
II. Use a method for the measurement of Risks that establishes a relationship between the indicators and the element to which those referred to in the previous fraction I belong, and assign a weight to each of them consistently based on their importance to describe said Risks. In turn, a weight must be assigned to each of the defined Risk elements consistently based on their importance to describe the Risks to which the Institution or Mutual Insurance Society is exposed.
III. Identify the Mitigants that the Institution or Mutual Insurance Society has implemented at the time of designing the methodology, considering all the internal policies, criteria, measures, and procedures referred to in the Seventy-Third of these Provisions, as well as their effective application, in order to establish the effect these will have on the indicators and Risk elements indicated in the previous fraction I, as well as on the Risk of the Institution or Mutual Insurance Society.
Twentieth. Institutions or Mutual Insurance Societies must implement the designed methodology and obtain the results thereof in order to know the Risks to which they are exposed. In the implementation of the risk assessment methodology, Institutions and Mutual Insurance Societies must ensure:
I. That there are no inconsistencies between the information they incorporate into this and that which is in their automated systems.
II. To use, at least, the information corresponding to the total number of Clients, number of Operations, and amount operated corresponding to a period that cannot be less than twelve months.
When, derived from the results of the implementation of the risk assessment methodology, the existence of greater or new Risks for the Institutions or Mutual Insurance Societies themselves is detected, these must modify the policies, criteria, measures, and procedures that correspond, contained in the Compliance Manual, or in another document or manual prepared by the Institution or Mutual Insurance Society, in order to establish the Mitigants they consider necessary based on the identified Risks, as well as to maintain them at an acceptable tolerance level in accordance with what is established in the Compliance Manual.
The modifications to the internal policies, criteria, measures, and procedures referred to in the preceding paragraph, derived from the results of the implementation of the risk assessment methodology, must be made within a period not exceeding twelve months from the time the Institution or Mutual Insurance Society has the results of its implementation and must be clearly identified and indicated, indicating at least the year and month in which the results of the implementation of the methodology that gave rise to said modifications were obtained.
Twenty-First. Compliance and results of the obligations contained in this Chapter must be reviewed and updated by the Institution or Mutual Insurance Society: when the existence of new Risks is detected, when the national risk assessment is updated, or within a period not exceeding 12 months from the time the Institution or Mutual Insurance Society has the results of its implementation. Such reviews and updates must be in writing and available to the Secretariat and the Commission, at the request of the latter, within the period established by the Commission itself.
The Commission may review and, if applicable, order Institutions and Mutual Insurance Societies to modify their risk assessment methodology or their Mitigants, among other cases, when they do not consider adequate Risk administration in the procedure and criteria for the determination of the celebration, limitation, or termination of a commercial relationship with their Clients, which must be congruent with said methodology, as well as to request an action plan so that they adopt reinforced measures to manage and mitigate their Risks.
Institutions and Mutual Insurance Societies must preserve the information generated with respect to this Chapter for a period of no less than five years and provide it to the Commission, at its request, within the period provided in the electronic means established by the Commission itself.
Twenty-Second. Institutions or Mutual Insurance Societies must comply with all obligations contained in these Provisions, in concordance with the results generated by their methodologies referred to in this Chapter.
Twenty-Third. The Commission, prior to the opinion of the Secretariat, will elaborate guidelines, guides, and/or best practices that Institutions and Mutual Insurance Societies will consider for the better compliance of what is provided in this present Chapter, which will be made known through the electronic means established by the same.
CHAPTER IV
CLIENT KNOWLEDGE POLICY
Twenty-Fourth. Institutions and Mutual Insurance Societies must elaborate and observe a Client knowledge policy, which will comprise the criteria, measures, and procedures required to duly comply with what is established in these Provisions.
Such policy must be an integral part of the Compliance Manual of each Institution or Mutual Insurance Society.
Agents must apply the Client knowledge policy of the Institution with respect to which they act as intermediaries. For these purposes, Institutions must deliver or make available to Agents the Compliance Manual or the sections or parts of this document that they determine as necessary for compliance with the obligation and leave a record of it.
Twenty-Fifth. The Client knowledge policy must include, at least:
I. The policies, procedures, and controls to mitigate Risks, which must be in accordance with the results of the implementation of the methodology referred to in Chapter III of these Provisions.
II. What is established in the Twenty-First of these Provisions in the sense of having procedures and criteria for the celebration, limitation, and/or termination of the commercial relationship.
Institutions and Mutual Insurance Societies will not be obliged to have procedures and criteria to limit or terminate the commercial relationship, regarding the Operations referred to in Article 118, fraction I, and Article 341, fraction I of the Law.
III. Procedures to follow up on Operations carried out by Clients, including all those carried out in the Concentrator Account of which the Institution or Mutual Insurance Society is the holder.
IV. Procedures for the due knowledge of the transactional profile of each of the Clients and for the grouping of the Operations referred to in this Provision.
V. The circumstances in which Operations deviate from the transactional profile of each of the Clients.
VI. Measures for the identification of possible Unusual Operations.
VII. Criteria to establish and, if applicable, modify the previously determined Risk Level for a Client.
VIII. The policies, criteria, measures, and procedures they will adopt to comply with Provision Twenty-Ninth, including the circumstances in which a visit to the domicile of Clients classified as high Risk must be made, in order to duly compile the files and update the corresponding data and documents.
The results of such a visit must be recorded in the respective file.
These policies, criteria, measures, and procedures must be incorporated into the Compliance Manual.
IX. Mechanisms to follow up and, if applicable, group the Operations that Clients carry out in cash individually:
a) In foreign currency or with traveler's checks, for amounts equal to or greater than five hundred United States dollars or its equivalent in the foreign currency in question.
b) In Mexican pesos, which Clients carry out individually for amounts exceeding three hundred thousand pesos, when they are natural persons, or for amounts exceeding five hundred thousand pesos, when they are legal entities or fiduciary institutions.
Institutions and Mutual Insurance Societies must follow up and group all Operations in United States dollars in cash that their Clients carry out, for each individual Operation, that are equal to or exceed the equivalent of five hundred United States dollars.
For the purposes of what is provided in this Provision, the systems referred to in the Fifty-Third of these Provisions must have the capacity to group the Operations referred to in the preceding paragraphs, in periods of one calendar month.
X. The establishment of a register of Clients who carry out the Operations indicated in the previous fraction, in order to identify them, know their transactionality, and have more elements to issue the reports that, if applicable, correspond in accordance with what is provided in these Provisions.
XI. The establishment of internal approval escalation mechanisms, regarding cash Operations carried out by clients:
a) Natural persons with any type of foreign currency, for amounts exceeding seven thousand five hundred United States dollars or its equivalent in the foreign currency in question.
b) Natural persons, in national currency, for amounts exceeding three hundred thousand pesos.
c) Legal entities, with foreign currencies, for amounts exceeding thirty-seven thousand five hundred United States dollars or in national currency, for amounts exceeding five hundred thousand pesos.
XII. The establishment of mechanisms for monitoring and grouping Operation amounts stricter than those indicated in fraction IX of this Provision, regarding those Clients who carry out cash Operations during a calendar month:
a) In national currency, for an accumulated amount equal to or greater than one million pesos.
b) In foreign currency, for an accumulated amount, during a calendar month, equal to or greater than the equivalent of seventy-five thousand United States dollars.
In addition to the above, Institutions and Mutual Insurance Societies must keep a register of the Clients referred to in this fraction, which will contain the information indicated in Annexes 1, 2, and 3, if they are natural persons, Annexes 4 and 5 in the case of legal entities.
The monitoring, follow-up, and grouping mechanisms of Operations, internal approval escalation, the registers referred to in this Provision, as well as the date, amount, and office, branch, or place where each of the indicated Operations were carried out, must be expressly documented.
Institutions and Mutual Insurance Societies must preserve the information contemplated in this Provision to provide it to the Secretariat and the Commission, at the request of the latter.
Twenty-Sixth. For the purposes of these Provisions, the transactional profile of each of the Clients will be based on:
I. The information provided by the Client, as well as by the knowledge that employees and officials of the Institution or Mutual Insurance Society have, based on their Client portfolio, or that which is in the files of the Institution or Mutual Insurance Society.
II. The amount, number, type, nature, and frequency of the Operations that the Client habitually or recurrently carries out.
III. The origin and destination of the resources subject to the Operation.
IV. The other elements and criteria that Institutions or Mutual Insurance Societies determine for such purposes.
Regarding those Operations carried out non-presence, in addition to the elements to determine the Client's transactional profile indicated above, the Geolocation of the Device from which said Operation is carried out must also be taken into account.
Twenty-Seventh. The application of the Client knowledge policy must be based on the transactional Risk Level that a Client represents, such that, when the Risk Level is higher, the Institution or Mutual Insurance Society must collect more information about its predominant activity, as well as carry out stricter supervision of the transactional behavior of the Client in question.
For the effect of what is indicated in the preceding paragraph, Institutions and Mutual Insurance Societies must have an alert system that allows them to follow up and, if applicable, promptly detect any change in the transactional behavior of their Clients, in order to adopt the necessary measures to prevent or detect acts, Operations, or omissions that could be located in the circumstances of Articles 139, 139 Quáter, 148 Bis, or 400 Bis of the Federal Penal Code.
To evaluate transactionality, the alert system of Insurance and Mutual Insurance Societies must include, for at least the first six months following the start of the commercial relationship, the information provided by each of its Clients at that time, regarding the Transactions that the Clients themselves estimate they will carry out, in order to determine their initial transactional profile, which must be integrated into the alert system referred to in the preceding paragraph, with the objective of detecting inconsistencies between the information provided by the Client and the Transactions carried out.
Additionally, Insurance and Mutual Insurance Societies must carry out an evaluation of their Clients' transactional profile, at least every six months, in order to determine if it is necessary to modify it.
Twenty-Eighth. With the aim of determining the Risk Level in which Clients should be placed, Insurance and Mutual Insurance Societies must have a risk evaluation methodology that must be coherent with what is established in Chapter III, regarding the Risk-Based Approach, of these Provisions, through which they will carry out the process of identification, measurement, and classification of the Risk Levels of their Clients. The design and details of the methodology and the processes for its use and validation must be contemplated in the Compliance Manual, and it must be approved by the Committee of the respective Insurance and Mutual Insurance Societies, which must inform the board of directors or general manager, as applicable, of the respective Insurance and Mutual Insurance Societies. Likewise, the respective Insurance and Mutual Insurance Societies must provide it to the Secretariat and the Commission, upon the latter's request.
Insurance and Mutual Insurance Societies must establish, between the low and high Risk Levels, as many intermediate Risk Levels as they deem necessary. The Risk Levels must be clearly distinguishable from each other, while within each Risk Level, they must contemplate Clients with homogeneous characteristics.
Insurance and Mutual Insurance Societies must consider, for at least the first six months following the start of the commercial relationship, the information provided by each of their Clients at that time, to determine their initial Risk Level.
In the case of Transactions carried out remotely, Insurance and Mutual Insurance Societies must consider Geolocation information, with the Client's prior consent, of the Device from which the Client carries out the Transaction.
Additionally, Insurance and Mutual Insurance Societies must carry out an evaluation of the Risk Level at least every six months, in order to determine if it is or is not necessary to classify their Clients into a different Risk Level. The frequency of the evaluation must be higher when the Risk Level classification is also higher.
Insurance and Mutual Insurance Societies, in the terms provided in their Compliance Manual, will apply identification questionnaires to their Clients who have been categorized as High Risk Level, as well as to new Clients who meet such characteristics, to obtain more information about the origin and destination of resources and the activities and Transactions they carry out or intend to carry out.
Twenty-Ninth. If during the course of the commercial relationship with the Client, the Insurance or Mutual Insurance Society detects significant changes in the Client's usual transactional behavior, without there being a justified cause for it, or if doubts arise regarding the truthfulness or accuracy of the data or documents provided by the Client itself, among other cases established by the Insurance or Mutual Insurance Society in its Compliance Manual, it will reclassify said Client into the corresponding higher Risk Level.
Insurance and Mutual Insurance Societies will verify that the identification files of their Corporate Clients, regardless of their Risk Level, contain all the data and documents provided in Annexes 4 and 5, as applicable, of these Provisions, as well as that said data and documents are up to date, understanding that Insurance and Mutual Insurance Societies may opt not to update documents if it concerns a Corporate Client with a Low Risk Level. This, in the terms and conditions established by Insurance and Mutual Insurance Societies in their Compliance Manual.
Insurance and Mutual Insurance Societies will verify, at least once a year, that the identification files of Clients classified as High Risk Level contain all data and documents, as well as that they are up to date. The data and documents referred to in this paragraph are those indicated in Provision Fourth.
Thirtieth. Prior to the celebration of Transactions with Clients who, due to their characteristics, could generate a High Risk Level for the Insurance or Mutual Insurance Society, at least one executive or equivalent who has specific powers to approve the opening or celebration of said accounts or contracts, as applicable, must grant, in writing, digitally or electronically, the respective approval.
Compliance Officers must be aware of those Transactions that may generate a High Risk for Insurance or Mutual Insurance Societies for the purposes referred to in Provision Forty-Eighth, sections V and VI. Insurance and Mutual Insurance Societies must provide in their Compliance Manual, the mechanisms for their Compliance Officers to be aware of those Clients who have been classified with a High Risk Level, as well as the procedures to process the aforementioned approval.
Thirty-First. Insurance and Mutual Insurance Societies must classify their Clients based on their Risk Level.
Foreign Politically Exposed Persons and Non-Resident Clients who operate insurance with foreign currency investment components will be considered High Risk Level Clients, regarding which Insurance and Mutual Insurance Societies must collect information that allows them to know and record the reasons why they have chosen to carry out Transactions in national territory.
In Transactions carried out by High Risk Level Clients, Insurance and Mutual Insurance Societies:
I. Will adopt reasonable measures to know the origin of the resources.
II. Must obtain the data indicated in Chapter II of these Provisions, in the terms provided in their Compliance Manual, or in another document or manual prepared by them:
a) Regarding the spouse, common-law partner, and economic dependents of the Client, as well as the companies and associations with which they maintain patrimonial links, in the case of natural persons.
b) Of the corporate structure and main shareholders or partners, as applicable, in the case of legal entities.
III. Must obtain the data and documents indicated in Chapter II of these Provisions, regarding the spouse and economic dependents, in the case of Foreign Politically Exposed Persons, as well as the companies and associations with which they maintain Patrimonial Links.
IV. In the case of Trusts, they will seek to collect the same data regarding the spouse, common-law partner, and economic dependents of the natural person Settlor and Trustee, as well as the companies and associations with which they maintain patrimonial links, and regarding corporate Settlor and Trustee legal entities, of their corporate structure and main shareholders or partners, in the terms provided in their Compliance Manual, or in another document or manual prepared by them.
High Risk Level Transactions are considered, among others, those carried out with Foreign Politically Exposed Persons, as well as those products available only to Clients with greater wealth than the majority of Clients, in which the Insurance or Mutual Insurance Society provides a preferential service characterized by personalized attention and advice and a high level of discretion. In these cases, Insurance and Mutual Insurance Societies will apply the measures provided, among others, in Provisions Twenty-Seventh to Thirtieth and Forty-Eighth sections V and VI.
In cases where, prior to or after the start of the commercial relationship, the Insurance or Mutual Insurance Society detects that the person who intends to be a Client or who already is, as applicable, meets the requirements to be considered a Politically Exposed Person and, additionally, of High Risk Level, said Insurance or Mutual Insurance Society must, in accordance with what is established in its Compliance Manual, obtain the approval of an executive or equivalent who has specific powers to approve the celebration of the Transaction or contract, as applicable, in order to initiate or, as applicable, continue the commercial relationship.
Thirty-Second. Without prejudice to what other applicable provisions establish, when Institutions act as reinsurers or surety providers for foreign institutions, Institutions must consider the Risks and approve, at the executive level, the relationship that allows them to act in such capacity, and for this purpose, they will document the measures and procedures that their counterparts observe in matters of prevention of Transactions with illicit proceeds and terrorist financing, in accordance with the regulations applicable to them in their jurisdiction.
For the purposes of the foregoing paragraph, Institutions must obtain from foreign institutions the following:
I. A certification by an independent auditor or, in its absence, a certification by the respective foreign institution, stating that said foreign institution complies with obligations similar to those established for Institutions in these Provisions, regarding Client identification and due diligence.
II. That information that, to the satisfaction of the Institutions themselves, allows them:
a) To know the business to which such counterparts are dedicated.
b) To evaluate the controls they have, in order to determine that they comply with international standards applicable in matters of prevention of Transactions with illicit proceeds and terrorist financing.
The criteria according to which Institutions will carry out the evaluation indicated in this section must be contemplated in the Compliance Manual, or in another document or manual prepared by the respective Institution.
c) To know if such foreign institutions are supervised by any competent authority in the matter referred to in the previous subsection b).
d) To identify if they have a good reputation, for which Institutions must consider, at least, the information that allows them to know if the counterparts have been subject to sanctions derived from non-compliance with the applicable regulations in the matter referred to in the previous subsection b).
Both Institutions and their foreign counterparts must document the obligations in matters of prevention of Transactions with illicit proceeds and terrorist financing to which each is subject in their countries. In order to comply with what is established in this paragraph, Institutions may request the prevention program of Transactions with illicit proceeds and terrorist financing from their foreign counterpart.
Likewise, the Institution, prior to celebrating Reinsurance or Surety Transactions with foreign institutions, must gather available information that allows it to have knowledge of the obligations in matters of prevention of Transactions with illicit proceeds and terrorist financing of the foreign institution, as well as to know from publicly available information, the reputation of said institution and the quality of supervision, including whether it has been the object or not of an investigation on Transactions with illicit proceeds and/or terrorist financing.
Thirty-Third. Institutions must strictly apply their Client knowledge policy, in cases where they act as reinsurers or surety providers for foreign institutions, domiciled outside national territory and constituted in countries or territories that the Secretariat makes known as those in which measures in matters of prevention of Transactions with illicit proceeds and terrorist financing do not exist or are applied insufficiently.
In accordance with the foregoing, the Secretariat will make available to Institutions, through its Internet page, the list of countries and territories previously indicated, in accordance with information provided by Mexican authorities, international organizations, and intergovernmental groupings in matters of prevention and combat of Transactions with illicit proceeds and terrorist financing.
Institutions must refrain from carrying out Reinsurance or Surety Transactions with institutions or financial intermediaries that do not have physical presence in any jurisdiction.
Thirty-Fourth. When an Insurance or Mutual Insurance Society has information based on indications or certain facts about the fact that one of the Clients acts on behalf of another person, without having declared it in accordance with what is indicated in Provision Fourth, it must request from the Client in question, information that allows it to identify the Beneficial Owner of the resources involved in the respective Transaction, without prejudice to confidentiality duties towards third parties that said Client has assumed by convention.
In the case provided for in the preceding paragraph, as well as in the case where doubts arise regarding the truthfulness or authenticity of the data or documents provided by the Client for identification purposes, or regarding their transactional behavior, the Insurance or Mutual Insurance Society must:
I. Carry out a specific and comprehensive follow-up of the Transactions that said Client carries out, in accordance with what is established in the Compliance Manual for this purpose.
II. As applicable, submit the Transactions to the consideration of the Committee, which must rule and, if appropriate, issue the corresponding Unusual Transaction Report.
Thirty-Fifth. Insurance and Mutual Insurance Societies must establish in the Compliance Manual, procedures to identify the Beneficial Owners of the resources used by Clients in their Transactions, which allow them:
I. To know the corporate structure and shareholders or partners who exercise Control over Commercial Legal Entity Clients that are classified as High Risk.
For this purpose, the Insurance or Mutual Insurance Society must request information relative to the name, nationality, domicile, corporate purpose, and share capital of the legal entities that make up the Business Group or, as applicable, the Business Groups that integrate the Consortium of which the Client is a part.
II. To identify those who have Control over civil societies or associations that are classified as High Risk, regardless of the percentage of social equity with which they participate in the society or association.
III. To collect, when they present themselves to exercise their rights, the same data and documents indicated in Provision Fourth, from the Settlor, Trustee, Mandator, Principal, or participants whose identity was indeterminate at the time of subscribing the trusts, mandates, commissions, or any similar instrument.
In the case of Corporate Clients whose share certificates or securities representing said shares trade on any stock exchange in the country or in recognized foreign stock markets as such in terms of the general provisions applicable to stock exchanges issued by the National Banking and Securities Commission, as well as those subsidiaries in which they have a majority participation of fifty percent of their share capital, Insurance or Mutual Insurance Societies will not be obliged to collect the aforementioned identification data, considering that they are subject to stock market regulations on information disclosure. This will only be permissible when the legal entities are not classified as High Risk Level Clients.
Thirty-Sixth. Insurance or Mutual Insurance Societies, that have as Clients any of the persons referred to in Article 95 Bis of the General Law of Auxiliary Credit Organizations and Activities, in addition to the obligations established in Provision Twenty-Fifth, sections IX and XII, must:
I. Identify the number, amount, and frequency of the Transactions that said Client carries out.
II. Obtain the registration certificate of unregulated multiple-object financial societies, money exchange centers and transmitters, before the National Banking and Securities Commission or the National Commission for the Protection and Defense of Users of Financial Services, as applicable, in terms of what is established by articles 81-B or 87-B of the General Law of Auxiliary Credit Organizations and Activities.
CHAPTER V
REPORTS OF RELEVANT TRANSACTIONS
Thirty-Seventh. Insurance and Mutual Insurance Societies must submit to the Secretariat, through the Commission, within the first ten business days of the months of January, April, July, and October of each year, through electronic means and in the official format issued for this purpose by the Secretariat, in accordance with the terms and specifications indicated by the latter, a report on all Relevant Transactions that their Clients have carried out in the three months prior to the month in which they must present it, including those carried out in the Concentration Accounts of which the Insurance or Mutual Insurance Society is the holder.
Insurance and Mutual Insurance Societies, whose Clients have not carried out Relevant Transactions during the corresponding quarter, must submit in the terms and under the format indicated in the preceding paragraph, a report in which they must only fill in the fields relative to the identification of the respective Insurance or Mutual Insurance Societies, the type of report, and the period thereof, leaving the rest of the fields contained in said format blank.
To facilitate the transmission process of the reports referred to in this Provision, the Commission, upon request of Insurance or Mutual Insurance Societies, may determine the sequence that they must follow, within the deadline indicated in this Provision.
Agents are obliged to deliver to Institutions the necessary information so that Relevant Transaction reports can be generated. For this purpose, both must agree on the terms in which said information will be transmitted.
CHAPTER VI
REPORTS OF UNUSUAL TRANSACTIONS
Thirty-Eighth. Insurance and Mutual Insurance Societies, for each Unusual Transaction they detect, including those carried out in the Concentration Accounts of which they are the holder, must submit to the Secretariat, through the Commission, the corresponding report, within three business days following the conclusion of the Committee session that rules on it. For the purpose of carrying out the ruling, the Insurance or Mutual Insurance Society, through its Committee, will have a period that will not exceed sixty calendar days counted from the generation of the alert through its system, model, process, or by the employee of the Insurance or Mutual Insurance Society.
To this effect, Insurance and Mutual Insurance Societies must submit the reports referred to in this Provision, through electronic means and in the official format issued for this purpose by the Secretariat, in accordance with the terms and specifications indicated by the latter.
In the event that the Insurance or Mutual Insurance Society detects a series of Transactions carried out by the same Client that are related to each other as Unusual Transactions, or that are related to one or more Unusual Transactions, or that complement any of them, the Insurance or Mutual Insurance Society will describe all of them in a single report.
Agents are obliged to deliver to Institutions the necessary information so that Unusual Transaction reports can be generated. For this purpose, both must agree on the terms in which said information will be transmitted.
Thirty-Ninth. For the purpose of determining which Transactions are Unusual, Insurance or Mutual Insurance Societies must consider, among others, the following circumstances, regardless of whether they occur individually or jointly:
I. The specific conditions of each of the Clients, such as, among others, their background, the Risk Level in which they have been classified, as well as their occupation, profession, activity, business line, or corresponding corporate purpose.
II. The types, amounts, frequency, and nature of the Transactions that their Clients usually carry out, the relationship they have with their background and known economic activity.
III. Unusually high amounts, the complexity, and the unusual modalities of the Transactions carried out by Clients.
IV. Transactions carried out by the same Client, provided that they do not correspond to their transactional profile or that it can be inferred that they are split to avoid detection by the Insurance or
Mutual Insurance Societies for the purposes of these Provisions.
V. The uses and practices of insurance, surety, fiduciary, and commercial matters in general or those prevailing in the market where they operate.
VI. When Clients refuse to provide the identification data or documents corresponding to the scenarios provided for this purpose in these Provisions, or when it is detected that they present information that could be fictitious or data that could be false.
VII. When Clients attempt to bribe, persuade, or intimidate the personnel of the Institutions or Mutual Insurance Societies, with the purpose of achieving their cooperation to carry out Unusual Operations or if these Provisions, other legal norms, or the policies, criteria, measures, and procedures of the Institution or Mutual Insurance Society in this matter are contravened.
VIII. When Clients intend to evade the parameters that the Institutions or Mutual Insurance Societies have to report the Operations referred to in these Provisions.
IX. When there are indications or extraordinary facts regarding which the Institution or Mutual Insurance Society does not have an explanation, giving rise to any type of suspicion regarding the origin, handling, or destination of the resources used in the respective Operations, or when there are suspicions that such indications or facts could be related to acts, omissions, or Operations that could favor, provide help, aid, or cooperation of any kind for the commission of the crimes provided for in Articles 139, 139 Quáter, 148 Bis, and 400 Bis of the Federal Penal Code.
X. When the Operations that Clients intend to carry out involve countries or jurisdictions:
a) That Mexican legislation considers to apply preferential fiscal regimes.
b) That, in the judgment of Mexican authorities, international organizations, or intergovernmental groupings in matters of prevention of operations with proceeds of illicit origin or financing of terrorism of which Mexico is a member, do not have measures to prevent, detect, and combat such operations, or when the application of such measures is deficient.
For the purposes of what is provided in the preceding paragraph, the Secretariat will make available to the Institutions and Mutual Insurance Societies, through consultation means on the worldwide network known as the Internet, the list of countries and jurisdictions that fall under the scenarios indicated in said paragraph.
XI. When it is presumed or there are doubts that a Client operates for the benefit, on behalf, or on account of a third party, without having declared it to the Institution or Mutual Insurance Society, in accordance with what is indicated in these Provisions; or if the Institution or Mutual Insurance Society is not convinced to the contrary, despite the information provided by the Client referred to in the first paragraph of the Thirty-Fourth Provision of these Provisions.
XII. The conditions under which other Clients operate who have stated they are dedicated to the same activity, profession, or commercial business, or having the same corporate purpose.
XIII. The type of risk that constitutes the basis of the Client's insurance contract, the realization of the risk, or the settlement of the claim covered by said contract.
XIV. The various Operations corresponding to excess premiums, additional contributions, amounts, or any other similar to insurance with savings or investment components, which when added are equal to or exceed the equivalent of seven thousand five hundred United States dollars, within a calendar month.
XV. The request for a policy by a person who wishes to have the status of Client, from a different market, where a similar policy can be obtained.
XVI. The early termination or cancellation of a contract or Operation, especially if it results in a loss and if the return of money is requested in cash or in the name of a third party.
XVII. The transfer of the benefit of a policy to an apparently unrelated third person.
XVIII. The attempt to use a check issued by a third party to acquire a policy.
XIX. When a person who wishes to have the status of Client shows little interest in the cost of the policy, but much more interest in the early termination of the Contract.
XX. When the Client refuses to provide the information and documentation required to celebrate an Operation, providing minimal, fictitious, or very difficult-to-verify information.
XXI. Clients unexpectedly change their business or economic activity, especially migrating to international trade or land cultivation activities.
XXII. The deposit of pledges received as counter-guarantees from an individual as surety, the policyholder, or their joint obligors, when issuing a surety bond or guarantee certificate, and it is requested that upon its cancellation, it be returned or delivered to a third party unrelated to the guaranteed operation.
XXIII. The giving in payment with real estate and automobiles.
XXIV. The establishment of guarantees for simulated Operations, which imply the transfer of resources from one company to another, which are delivered in administration to the Institution, but the Operations are never perfected nor are the surety bonds or guarantee certificates claimed.
XXV. Claims by individuals or legal entities that predominantly handle cash and that, when asked to reimburse the Institution for amounts paid on their behalf, deliver as payment in kind rural real estate, hotels, bars, or similar, constructed or acquired probably in cash, or certain movable goods such as automobiles.
XXVI. Claims in which, as a counter-guarantee or reimbursement, pledges in cash deposited at different times or by different people who were not located in the scenarios to be reported as Relevant Operations are received, and it was requested that they be returned to a third person, distinct from the depositor.
XXVII. Operations carried out by the same Client with foreign currency, traveler's checks, cashier's checks, and minted coins in platinum, gold, and silver, for multiple or fractional amounts that, for each individual Operation, are equal to or exceed the equivalent of five hundred United States dollars, carried out in the same calendar month that sum, at least, the amount of seven thousand five hundred United States dollars or its equivalent in the currency in question, provided that they do not correspond to the Client's transactional profile or that, with respect to those carried out by the same Client, it can be inferred from their structuring a possible intention to fractionate the Operations to avoid being detected by the Institutions or Mutual Insurance Societies for the purposes of these Provisions.
XXVIII. When Operations have been carried out or are intended to be carried out by Clients who are within the list issued for such purposes by the Secretariat under the heading "List of Blocked Persons".
Each Institution or Mutual Insurance Society must provide in the Compliance Manual, or in some other document, the mechanisms based on which the background and purposes of those Operations that must be presented to the Committee for the purpose of their determination as Unusual Operations, in accordance with these Provisions, must be examined.
The results of the above examination must be recorded in writing and be available to the Secretariat and the Commission, for at least ten years counted from the celebration of the Committee meeting in which such results were presented.
To facilitate the process of identifying Unusual Operations, the Secretariat must regularly advise the Institutions or Mutual Insurance Societies and provide guides, information, and typologies that allow detecting Operations that must be reported in accordance with these Provisions.
In the process of determining Unusual Operations, the Institutions or Mutual Insurance Societies must rely on their Compliance Manual, as well as any other document or manual prepared by the Institutions and Mutual Insurance Societies themselves, and in addition to this, consider the guides prepared by the Secretariat, as well as by international organizations and intergovernmental groupings in matters of prevention and combat of operations with proceeds of illicit origin and financing of terrorism, of which Mexico is a member, that the Secretariat provides.
Fortieth. In the event that a Relevant Operation is considered by the Institution or Mutual Insurance Society as an Unusual Operation, it must formulate, separately, a report for each of those types of Operations.
For the preparation of reports on Unusual Operations and Internal Concerning Operations, the Institutions and Mutual Insurance Societies will take into account the best practice proposals that, if any, the Secretariat makes known, likewise for the purposes of the above, they may observe what is provided in the Fifty-Seventh Provision.
With the aim of improving Operation reports, the Secretariat will send to the Institutions and Mutual Insurance Societies reports on the quality of the Unusual Operations and Internal Concerning Operations reports that they present to it, with a periodicity of at least every six months and in accordance with the guidelines contained in the best practice proposals referred to in the Fifty-Seventh Provision.
Forty-First. The Institutions or Mutual Insurance Societies must submit an Unusual Operation report when they accept the carrying out of an Operation of which they have information based on well-founded suspicions, indications, or concrete facts from which it can be inferred that the resources could come from illicit activities or be destined to favor, provide help, aid, or cooperation of any kind for the commission of the crimes provided for in Articles 139, 139 Quáter, 148 Bis, or 400 Bis of the Federal Penal Code.
The report must be submitted within 24 hours counted from the time the Institution or Mutual Insurance Society accepts the carrying out of the Operation, and in the Unusual Operation report format, in the Operation description column, the legend "24-hour Report" must be inserted.
Likewise, in those cases where the respective Client does not accept or rejects the Operation referred to in this Provision, the Institution or Mutual Insurance Society must present to the Secretariat, through the Commission, the Unusual Operation report under the terms previously indicated, with respect to said Clients and provide, if applicable, all the information known about them.
For the purposes of what is provided in this Provision, the Institutions or Mutual Insurance Societies must establish in their Compliance Manual, the policies, criteria, measures, and internal procedures in accordance with which their personnel, once they know the information, must make it known immediately to the Compliance Officer, so that he fulfills the obligation to send the report that, if applicable, corresponds.
What is provided in this Provision will be applicable without prejudice to the actions taken by the Institutions or Mutual Insurance Societies in accordance with what agreed with the Clients.
Agents are obligated to deliver to the Institutions the necessary information so that they can generate the aforementioned reports. For this purpose, they must agree on the terms in which such information will be transmitted.
CHAPTER VII
REPORT OF INTERNAL CONCERNING OPERATIONS
Forty-Second. For each Internal Concerning Operation, including those related to Concentrating Accounts, that an Institution or Mutual Insurance Society detects, it must submit to the Secretariat, through the Commission, the corresponding report, within three business days following counted from the conclusion of the Committee session that determines it as such. For the purposes of carrying out the aforementioned determination, the Institution or Mutual Insurance Society, through its Committee, will have a period that will not exceed sixty natural days counted from the time it detects that Operation, through its system, model, process, or by any employee of the same, whichever occurs first.
To this effect, the Institutions and Mutual Insurance Societies must submit the reports referred to in this Provision, through electronic means and in the official format issued for such purpose by the Secretariat, in accordance with the terms and specifications indicated by the latter.
Forty-Third. The Institutions and Mutual Insurance Societies, for the purposes of determining which Operations are Internally Concerning, must consider, among others, the following circumstances, regardless of whether they occur individually or jointly:
I. When it is detected that some director, official, employee, or agent of the Institution or Mutual Insurance Society maintains a standard of living notably higher than what would correspond to them, according to the income they receive from it.
II. When, without justified cause, some director, official, employee, or agent of the Institution or Mutual Insurance Society has repeatedly intervened in the carrying out of Operations that have been reported as Unusual Operations.
III. When there are suspicions that some director, official, employee, or agent of the Institution or Mutual Insurance Society may have committed acts, omissions, or Operations that could favor, provide help, aid, or cooperation of any kind for the commission of the crimes provided for in Articles 139, 139 Quáter, 148 Bis, or 400 Bis of the Federal Penal Code.
IV. When, without justified cause, there is a lack of correspondence between the functions entrusted to the director, official, employee, or agent of the Institution or Mutual Insurance Society and the activities that they actually carry out.
CHAPTER VIII
INTERNAL STRUCTURES
Forty-Fourth. Each Institution or Mutual Insurance Society must have a collegiate body that will be called "Communication and Control Committee" and that will have, at least, the following functions and obligations:
I. Submit to the approval of the audit committee of the Institution or Mutual Insurance Society, the Compliance Manual, as well as any modification to it.
II. Approve the Risk Evaluation Methodology referred to in Chapter III of these Provisions, informing the board of directors of the Institution or Mutual Insurance Society thereof.
III. Present to the board of directors of the Institution or Mutual Insurance Society, the results of the implementation of the methodology elaborated and implemented to carry out the Risk Evaluation referred to in the previous Chapter III.
IV. Be informed of the results obtained by the internal audit area of the Institution or Mutual Insurance Society or by an independent external auditor regarding the valuation of the effectiveness of the policies, criteria, measures, and procedures contained in the Compliance Manual, in order to adopt the necessary actions aimed at correcting flaws, deficiencies, or omissions. The referred external auditor is the one provided for in the Sixty-Second Provision.
V. Be informed of those Clients who, due to their characteristics, are classified with a High Risk Grade for the Institution or Mutual Insurance Society, according to the reports presented to it for this purpose by the Compliance Officer and, if applicable, formulate the recommendations deemed appropriate.
VI. Establish and disseminate the criteria for the classification of Clients, based on their Risk Grade, in accordance with what is indicated in the Twenty-Eighth Provision.
VII. Ensure that the automated systems of the Institution or Mutual Insurance Society contain the lists:
a) Of countries or jurisdictions that Mexican legislation considers to apply preferential fiscal regimes.
b) Of countries or jurisdictions, that in the judgment of Mexican authorities, international organizations, or intergovernmental groupings in matters of prevention of operations with proceeds of illicit origin or financing of terrorism of which Mexico is a member, do not have measures to prevent, detect, and combat such operations or when the application of such measures is deficient.
c) Under the heading "List of Blocked Persons", provided by the Secretariat.
d) Of Politically Exposed Persons that the Institutions and Mutual Insurance Societies must elaborate, in accordance with the Seventy-Seventh Provision.
VIII. Determine the Operations that must be reported to the Secretariat, through the Commission, as Unusual Operations or Internal Concerning Operations, under the terms established in these Provisions.
IX. Approve the training programs for the personnel of the Institution or Mutual Insurance Society, in matters of prevention, detection, and reporting of acts, omissions, or Operations that could update the scenarios provided for in Articles 139, 139 Quáter, 148 Bis, or 400 Bis of the Federal Penal Code.
X. Inform the competent area of the Institution or Mutual Insurance Society, regarding conduct carried out by its directors, officials, employees, or agents, that cause them to incur in a violation of what is provided in these Provisions, or in cases where the persons indicated contravene what is provided in the policies, criteria, measures, and procedures provided in the Compliance Manual, with the object that the corresponding disciplinary measures are imposed.
XI. Determine in the last quarter of each year, if during the following fiscal year the schemes indicated in the Seventh Provision will be applied.
XII. Resolve other matters that are submitted to its consideration, related to the application of these Provisions.
XIII. Ensure that the Institution or Mutual Insurance Society, for the compliance with these Provisions, has the internal structures referred to in this Chapter, regarding organization, number of people, material and technological resources, in accordance with the results of the implementation of the methodology referred to in Chapter III of these Provisions.
XIV. Ensure that the key referred to in the Eightieth Provision is requested and kept updated in the name of the Compliance Officer or Compliance Officer who is designated as interim, as applicable.
Each Institution and Mutual Insurance Society must establish in the Compliance Manual, or in some other document or manual that they prepare, the mechanisms, processes, deadlines, and moments, as the case may be, that must be observed in the performance of the functions indicated in this Provision.
Forty-Fifth. The Committee of the Institutions or Mutual Insurance Societies must be integrated as follows:
I. The number of members cannot be less than three.
II. The members must hold the positions of the areas designated by the board of directors of the Institution or Mutual Insurance Society.
III. The members must, at least, in the Institution or Mutual Insurance Society or in the entities indicated in the last paragraph of this Provision, hold the position of General Director, or positions within the three immediate lower hierarchies to that of the latter. Councilors of these entities may also be members.
IV. The internal auditor or persons assigned to the audit area will not be part of the Committee.
V. The principal members of the Committee must attend its sessions and may designate their respective substitutes, who may only represent them in two non-consecutive sessions per semester.
The substitutes must meet the same requirements as the principals.
VI. The Committee will have a president and a secretary, who will be designated from among its members.
The Institutions and Mutual Insurance Societies will not be obligated to constitute and maintain the Committee referred to in this Provision when they have fewer than twenty-five people at their service, whether these perform functions for them directly or through complementary service companies.
In the scenario provided for in the preceding paragraph, the functions and obligations that should correspond to the Committee will be exercised by the Compliance Officer, except for that provided for in fraction XIII of the Forty-Fourth Provision of these provisions, which will correspond to the General Director or equivalent of the Institution or Mutual Insurance Society.
They may also form and maintain the Committee with members from the communication and control committees of the financial entities that are part of the financial group to which the Institution or Mutual Insurance Society belongs; from the financial entity that has Control over it, or from some entity that has common shareholders that Control both entities. Invariably, the members must be designated by the board of directors of the Institution or Mutual Insurance Society and the Committee must be constituted in accordance with what is indicated in this Provision.
The Institutions and Mutual Insurance Societies must prove that the officials designated by the board of directors to integrate the Committee in question, are within the three immediate lower hierarchies to that of the General Director.
Forty-Sixth. Each Institution and Mutual Insurance Society will determine the way in which its Committee will operate, the rules of operation must consider the following:
I. The Committee must meet, at least, once every month of the year.
II. The internal auditor or the person from the audit area that he designates, must participate in the sessions of said Committee with voice, but without vote.
III. For the Committee sessions to be held validly, it will be required that the majority of the members of the Committee itself are present.
IV. The decisions of the Committee will be taken by virtue of the favorable vote of the majority of the members present in the session, in case of a tie, the president will have a casting vote.
V. From each session, a minutes will be drawn up, in which the resolutions adopted will be recorded. The
Minutes must be signed by the Chair and Secretary of the Committee or, if applicable, by their respective substitutes.
Insurance Institutions or Mutual Insurance Societies must properly safeguard the documents and information on which the justifications are recorded for determining whether to report or not report each of the Operations subject to being considered as Unusual Operations or Concerning Internal Operations that were analyzed in the corresponding session, as well as the other resolutions adopted.
Forty-Seventh. The Institution or Mutual Insurance Society must communicate to the Secretariat, through the Commission, the initial composition of the Committee, within fifteen business days following the date on which the Board of Directors has designated the areas whose heads will form part of the Committee. The communication will include the full first and last names without abbreviations of each of the principal and substitute members of said Committee, as well as their position and the hierarchical level they occupy within the Institution or Mutual Insurance Society.
The aforementioned communication will be made through electronic means and in the official format issued for such effect by the Secretariat, in accordance with the terms and specifications set by the latter.
Insurance Institutions and Mutual Insurance Societies that fall under the circumstance established in the Forty-Fifth Provision, second paragraph, must communicate this situation to the Secretariat under the terms indicated in the preceding paragraph.
Each Institution or Mutual Insurance Society must communicate to the Secretariat, through the Commission, via the aforementioned electronic means, the appointment, addition, or substitution of the Committee members, within fifteen business days following the date on which they occurred. For these purposes, the following information must be provided:
I. The name of the areas whose heads were appointed in addition to or in substitution of those who were part of the Committee; the full first and last names without abbreviations of said heads; whether they are principal or substitute members; their position, and the hierarchical level they occupy within the Mutual Insurance Society.
II. The date on which the addition or substitution took place.
III. The other information required in the official format provided for in this Provision.
Forty-Eighth. The Board of Directors or the Committee of the Institution or Mutual Insurance Society will designate from among its members an official who will be called the "Compliance Officer".
In the event that the Institution or Mutual Insurance Society does not have a Committee because it falls under the circumstance referred to in the Forty-Fifth Provision, second paragraph, the Compliance Officer will be designated by its Board of Directors, who must meet the requirements to be a member of the Committee, in terms of the aforementioned Provision.
In any case, the Compliance Officer must be an official who holds a position within the three hierarchical levels immediately below that of the General Director of the respective Institution or Mutual Insurance Society and will perform, at least, the following functions and obligations:
I. Draft and submit to the Committee for approval the Compliance Manual, for subsequent approval by the Audit Committee, which shall contain the policies for client identification and due diligence, and the criteria, measures, and procedures to be adopted to comply with what is provided in these Provisions.
II. Submit to the Committee for approval the methodology designed to carry out the Risk Assessment referred to in Chapter III of these Provisions, as well as the results of its implementation.
III. Verify the correct execution of the measures adopted by the Committee, in exercise of the powers provided for in the Forty-Fourth Provision.
IV. Inform the Committee regarding conduct, activities, or behaviors carried out by executives, officials, employees, or agents of the Institution or Mutual Insurance Society that cause it to incur violations of what is established in the Law or these Provisions, as well as cases in which the aforementioned persons contravene what is provided in the Compliance Manual, with the aim that the corresponding disciplinary measures are imposed.
V. Bring to the attention of the Committee the celebration of Operations whose characteristics could generate a high Risk, as well as information regarding those Clients who, due to their characteristics, are classified with a high Risk Grade for the Institution or Mutual Insurance Society.
VI. Coordinate both the follow-up activities of Operations and the investigations that must be carried out at the institutional level, with the aim that the Committee has the necessary elements to rule on them, if applicable, as Unusual Operations or Concerning Internal Operations.
For the purposes indicated in the preceding paragraph, the area in charge of the Compliance Officer or, if applicable, the personnel designated by him, will verify that the corresponding alerts have been analyzed and the respective investigations documented.
VII. Send to the Secretariat, through the Commission, the reports of Unusual Operations indicated in the Thirty-Eighth Provision, as well as those considered urgent, and inform the Committee thereof at its next session.
VIII. Act as a consultation body within the Institution or Mutual Insurance Society regarding the application of these Provisions, as well as the Compliance Manual.
IX. Define the characteristics, content, and scope of the training programs for the personnel of the Institution or Mutual Insurance Society, referred to in the Fifty-First Provision.
X. Receive and verify that the Institution or Mutual Insurance Society responds, in accordance with applicable legal provisions, to requests for information and documentation, as well as to preservation orders, through the Commission, formulated by competent authorities in matters of prevention, investigation, prosecution, and sanction of conduct that may update the circumstances provided for in Articles 139, 139 Quáter, 148 Bis, or 400 Bis of the Federal Penal Code; likewise, verify that the Institution or Mutual Insurance Society has appropriate procedures to ensure compliance with what is provided in the Seventy-Second of these Provisions.
XI. Act as a liaison between the Committee, the Secretariat, and the Commission, for matters regarding the application of these Provisions.
XII. Ensure that the area under its charge directly receives notices issued by employees and officials of the Institution or Mutual Insurance Society regarding facts and acts that may be considered as Unusual Operations or Concerning Internal Operations, and follow up on them.
The appointment of the Compliance Officer must fall upon an official who is independent of the units of the Institution or Mutual Insurance Society responsible for promoting or managing the financial products offered to Clients. In no case, the appointment of the Compliance Officer may fall upon a person who has internal audit functions in the Institution or Mutual Insurance Society.
The Compliance Officer of an Institution or Mutual Insurance Society may also be appointed as the Compliance Officer of the financial entities that are part of a financial group to which it belongs; of the financial entity that has Control over it; or of any entity that has common shareholders that Control both entities, provided that the Institution or Mutual Insurance Society in question complies with what is provided in this Provision.
Each Institution or Mutual Insurance Society must expressly establish in the Compliance Manual, or in some other document they draft, the procedures according to which the Compliance Officer will perform the functions and obligations established in this Provision and the manner in which they will document compliance with them, if applicable.
Forty-Ninth. The Institution or Mutual Insurance Society must inform the Secretariat, through the Commission, via electronic means and in the official format issued for such effect by said Secretariat, in accordance with the terms and specifications set by the latter, the following:
I. The full first and last names without abbreviations of the official designated as Compliance Officer, as well as the other information provided for in the indicated format, within two business days following the date on which the corresponding appointment was made.
II. The revocation of the appointment of the Compliance Officer, on the next business day following the date on which it occurred, whether by determination of the Institution or Mutual Insurance Society, rejection of the appointment, termination of employment, or impossibility, as well as the other information provided for in the indicated format.
III. The full first and last names without abbreviations of the official designated as Compliance Officer in terms of what is established in the following Provision, as well as the other information provided for in the indicated format, on the next business day following the date on which it occurred.
Fiftieth. The Committee of each Institution or Mutual Insurance Society, or its Board of Directors or General Director, will appoint an official of the Institution or Mutual Insurance Society who will temporarily substitute for its Compliance Officer in the fulfillment of its obligations in accordance with these Provisions, for up to ninety natural days during a calendar year, counted from the date the official designated as Compliance Officer leaves, is revoked, or is unable to perform the appointment in question.
The official of the Institution or Mutual Insurance Society who performs the aforementioned interim position must not have internal audit functions in the same.
Insurance Institutions or Mutual Insurance Societies may make effective the interim period referred to in this Provision, in accordance with the needs of each Institution or Mutual Insurance Society.
The Compliance Officer designated as interim must comply with the functions and obligations indicated in these Provisions, until the moment the revocation is reported.
CHAPTER IX
TRAINING AND DISSEMINATION
Fifty-First. Insurance Institutions and Mutual Insurance Societies will develop training and dissemination programs in which they must contemplate, at least, the following:
I. The delivery of courses, at least once a year, which must be directed especially to the members of their respective Boards of Directors, executives, officials, and employees, including those who work in customer service or resource administration areas, and which contemplate, among other aspects, those related to the content of the Compliance Manual that the Institution or Mutual Insurance Society has developed for the proper compliance with the Provisions, as well as regarding the activities, products, and services offered by the Institution or Mutual Insurance Society.
With respect to Insurance Institutions and Mutual Insurance Societies that only carry out Reinsurance and Surety Bond Reinsurance Operations, the courses must be directed to employees who carry out the placement of reinsurance or surety bond reinsurance, as well as to those who grant approval and analyze the information referred to in the Thirty-Second Provision.
II. The dissemination of these Provisions and their modifications, as well as information on techniques, methods, and trends to prevent, detect, and report Operations that could update the circumstances provided for in Articles 139, 139 Quáter, 148 Bis, and 400 Bis of the Federal Penal Code.
Without prejudice to what is stated in this Provision, the topics of the training must be coherent with the results of the implementation of the methodology referred to in Chapter III of these Provisions and must be adapted to the responsibilities of the members of their respective Boards of Directors, executives, officials, and employees.
Fifty-Second. Insurance Institutions and Mutual Insurance Societies must issue certificates accrediting the participation of their officials and employees in training courses, for whom evaluations on the knowledge acquired will be conducted, establishing the measures that will be adopted regarding those who do not obtain satisfactory results.
The officials and employees of Insurance Institutions and Mutual Insurance Societies who will work in customer service areas or, if applicable, resource administration areas, must receive training in the subject matter, prior to or simultaneous with their entry or start of activities in said areas.
CHAPTER X
AUTOMATED SYSTEMS
Fifty-Third. Each Institution or Mutual Insurance Society, as part of its Technological Infrastructure, must have automated systems that develop, among others, the following functions:
I. Preserve and update, as well as allow the consultation of data related to the records of the information contained in the respective identification file of each Client.
II. Generate and securely transmit to the Secretariat, through the Commission, information regarding reports of Relevant Operations, Unusual Operations, and Concerning Internal Operations, as well as the other information that must be communicated to the Secretariat or to the Commission, in the terms and according to the deadlines established in these Provisions.
III. Classify the types of Operations or financial products offered to Clients, based on the criteria established by the Institution or Mutual Insurance Society, in order to detect possible Unusual Operations.
IV. Detect and monitor Operations carried out in cash by the same Client from those indicated in the Forty-Ninth Provision, fraction XXVII, as well as group said Operations, in periods of one calendar month.
V. Execute the alert system contemplated in the Twenty-Seventh Provision.
VI. Contribute to the detection, follow-up, and analysis of possible Unusual Operations and Concerning Internal Operations, considering at least:
a) The information that has been provided by the Client at the start of the commercial relationship.
b) The historical records of Operations carried out by the Client.
c) The transactional behavior of the Client.
d) The average balances of the Client.
e) Any other parameter that may provide more elements for the analysis of this type of Operations.
VII. Group in a consolidated database the different Operations and Contracts of the same Client, in order to control and provide integral follow-up to their Operations.
VIII. Preserve historical records of possible Unusual Operations and Concerning Internal Operations.
IX. Serve as a means for personnel of Insurance Institutions or Mutual Insurance Societies to report to internal areas determined, possible Unusual Operations or Concerning Internal Operations, in a secure, confidential, and auditable manner.
X. Maintain information security schemes for processed information, guaranteeing its integrity, availability, auditability, and confidentiality.
XI. Provide the information that Insurance Institutions and Societies will include in the methodology they must draft in accordance with what is established in Chapter III of these Provisions.
XII. Execute an alert system regarding those Operations:
a) In which countries or jurisdictions are involved that Mexican legislation considers apply preferential fiscal regimes or that, in the judgment of Mexican authorities, international organizations, or intergovernmental groupings in matters of prevention of Operations with resources of illicit origin or terrorism financing of which Mexico is a member, do not have measures to prevent, detect, and combat said Operations or when the application of said measures is deficient.
b) That are intended to be carried out with Politically Exposed Persons or with those who are within the "Blocked Persons Lists" provided by the Secretariat.
XIII. Facilitate the verification of data and documents provided remotely by the Client.
CHAPTER XI
RESERVE AND CONFIDENTIALITY
Forty-Fourth. The members of the Board of Directors and the Committee, the Compliance Officer, as well as the executives, officials, employees, and agents of Insurance Institutions and Mutual Insurance Societies, must maintain absolute confidentiality regarding information related to the reports provided for in these Provisions, except when requested by the Secretariat, through the Commission, and other authorities expressly empowered to do so or in the cases provided for in Chapter XIV of these Provisions.
In addition to the above, persons subject to the confidentiality obligation mentioned above are strictly prohibited from alerting or notifying:
I. Clients, regarding any reference made about them in said reports.
II. Clients or any third party regarding any of the requests for information or documentation provided for in the Forty-Eighth Provision, fraction X.
III. Clients or any third party about the existence or presentation of preservation orders referred to in the Forty-Eighth Provision, fraction X, before they are executed.
IV. Clients or any third party about the content of the "Blocked Persons List".
Forty-Fifth. Compliance with the obligation incumbent upon Insurance Institutions or Mutual Insurance Societies, the members of their Board of Directors and Committees, Compliance Officers, as well as executives, officials, employees, and agents, to send to the Secretariat through the Commission the reports and information referred to in these Provisions, will not constitute a violation of restrictions on information disclosure imposed by contract or by any legal provision and will not imply any type of liability.
Reports and other information generated by Insurance Institutions or Mutual Insurance Societies to comply with these Provisions regarding them will not be considered as founded indications of the commission of a crime.
CHAPTER XII
OTHER OBLIGATIONS
Forty-Sixth. Insurance Institutions or Mutual Insurance Societies must provide to the Secretariat, through the Commission, all information and documentation requested of them, including that containing images, related to the reports provided for in these Provisions.
In the event that the Secretariat, through the Commission, requests an Institution or Mutual Insurance Society a copy of the identification file of any of the Clients, they must remit all data and a copy of all documentation that, in accordance with what is provided in these Provisions, should form part of the respective file. In the case where the Secretariat requires other related information, the Institution or Mutual Insurance Society must present all other information and a copy of all documentation regarding said Client in its possession.
The documentation required by the Secretariat as indicated in the preceding paragraph must be delivered in simple copy, unless it requests that it be certified by an official authorized for such purpose by the Institution or Mutual Insurance Society, as well as in electronic files capable of showing their content through the application of computing specified by the Secretariat, provided that the Institution or Mutual Insurance Society has the application that allows it to generate the respective type of file.
For the purposes stated in this Provision, the information and documentation required by the Commission must be presented directly in the administrative unit designated for such purpose, and must be contained in a closed envelope to prevent persons unrelated to said unit from accessing the referenced information and documentation.
Forty-Seventh. Insurance Institutions and Mutual Insurance Societies may establish, in accordance with the guidelines and proposals for best practices that the Secretariat may make known, homogeneous and uniform Risk methodologies consistent with the general characteristics of various types of Operations, to detect and report, in accordance with these Provisions, acts, omissions, or Operations that could favor the circumstances provided for in Articles 139, 139 Quáter, 148 Bis, or 400 Bis of the Federal Penal Code.
For the effect of the foregoing, the homogeneous and uniform Risk methodologies must reflect the self-regulation norms that, if applicable, are established by the Association to which the Insurance Institutions or Mutual Insurance Societies belong.
Forty-Eighth. Insurance Institutions or Mutual Insurance Societies, when they have doubts about the veracity of the Tax Identification Card and/or the serial number of the Advanced Electronic Signature of their Clients, will verify the authenticity of the data contained therein, in accordance with the procedures that, if applicable, the Secretariat establishes for such effect.
Forty-Ninth. Insurance Institutions or Mutual Insurance Societies must adopt selection procedures to ensure that their personnel have the necessary technical quality and experience, as well as honorability, to carry out the activities corresponding to them.
The aforementioned procedures must include the obtaining of a signed declaration by the official or employee, in which they will record information regarding any other Institution or Mutual Insurance Society in which they have previously worked, if applicable, as well as the fact of not having been sentenced for property crimes or disqualified from engaging in commerce as a result of non-compliance with legislation or to hold a job, position, or commission in public service, or in the Mexican financial system.
The selection procedures shall be contemplated in the document referred to in the Compliance Manual, or in some other document or manual, prepared by the Institution or Mutual Insurance Society itself.
Each Insurance Institution and Mutual Insurance Society shall establish mechanisms and systems that allow its employees and officials to send directly to the area in charge of the Compliance Officer, notices regarding facts or acts that may be considered as constituting Unusual Operations or Concerning Internal Operations, as well as so that the Agents with whom it has concluded intermediation agreements give the corresponding notices to the Compliance Officer of the Institution.
The mechanisms and systems indicated shall ensure that the hierarchical superior of the employee or official who issues the corresponding notice, as well as the other persons indicated in said notice, do not have knowledge of it.
Sixtieth. To the extent possible, Institutions and Mutual Societies will endeavor to ensure that what is provided in these Provisions is applied, where applicable, in their offices, branches, agencies, and subsidiaries located abroad, especially those situated in countries where measures to prevent, detect, and combat Operations with funds of illicit origin and terrorism financing do not exist or are applied insufficiently.
When it is impossible for Insurance Institutions and Mutual Insurance Societies to apply what is provided in these Provisions in their offices, branches, agencies, and subsidiaries located abroad, they shall inform in writing of such situation to the Secretariat, through the Commission, within a period not exceeding twenty business days following the conclusion of the procedures that, for this purpose, they have carried out.
In those cases where the legislation of the country where the offices, branches, agencies, and subsidiaries of an Insurance Institution or Mutual Insurance Society are located establishes greater requirements than those imposed by these Provisions, the Insurance Institutions and Mutual Insurance Societies shall ensure that such requirements are complied with and that they are informed thereof, in order to evaluate their relationship with these Provisions.
Sixty-first. The Institution and Mutual Insurance Society shall preserve, for a period no less than ten years, counted from the execution of the Operation carried out by its Clients, the following:
I. The documentation and information that certifies the Operation in question once it has been concluded.
II. The data and documents that make up the identification files of its Clients, which shall be preserved throughout the validity of the Contract and, once these conclude, for the period referred to in this Provision, from the conclusion of the contractual relationship.
The identification file that Insurance Institutions and Mutual Insurance Societies must preserve in terms of this Provision must allow the identification of the Client, as well as knowledge of the Operations carried out with the Institution or Mutual Insurance Society.
III. The historical records of the Operations carried out with its Clients.
IV. Copies of the reports of Unusual Operations, Concerning Internal Operations, and Relevant Operations that have been submitted in terms of these Provisions, as well as the original or copy or accounting or financial record of all supporting documentation, which shall be identified and preserved as such by the Institution or Mutual Insurance Society itself for the same period.
The records of the reports submitted in accordance with these Provisions, as well as the records of the Operations carried out, shall allow knowledge of the manner and terms in which they were carried out, in accordance with the applicable legal provisions.
The preservation provided for in this Provision may be carried out by electronic or digital means, which shall guarantee the security of the information and documentation collected from the Client.
For this purpose, the Institutions and Mutual Insurance Societies shall comply with the technical bases established by the Commission in accordance with the Law, in matters of microfilming, recording, preservation, and destruction of documents.
Sixty-second. The Institutions and Mutual Insurance Societies shall maintain control measures that include review by the internal audit area, or by an independent external auditor, to evaluate and report from January to December, or with respect to the period resulting from the date on which the Commission authorizes the start of Operations of the Institution or Mutual Insurance Society in question to December of the respective year, the effectiveness of compliance with these Provisions, in accordance with the guidelines issued by the Commission for such purposes.
The report on the results of the reviews shall be presented to the General Management and the Committee, in order to evaluate the operational effectiveness of the implemented measures and to follow up on corrective action programs that may be applicable. In the aforementioned valuation exercise, no member of the Committee of the Institution or Mutual Insurance Society may participate.
With respect to Institutions that are part of financial groups in terms of the Law to Regulate Financial Groups, they shall take into account the reviews referred to in the first paragraph of this Provision that, where applicable, have been carried out by the other financial entities that make up the corresponding group.
The report referred to in this Provision shall be preserved by the Institution or Mutual Insurance Society for a period no less than five years, and submitted to the Commission within sixty calendar days following the closing of the exercise to which the review corresponds, in the electronic means indicated by the latter.
Sixty-third. The Institutions shall verify that the Agents with whom they operate comply with what is provided in these Provisions, without prejudice to the supervisory powers that the Commission has with respect to them and that it exercises in accordance with its audit programs.
The Institutions and Mutual Insurance Societies shall agree with the Agents, the manner and terms in which they will coordinate for the application of these Provisions, among other aspects regarding the identification and customer knowledge policies that will be applied, the preservation of files, and the verification of the data and documents that make up said files during the commercial relationship.
CHAPTER XIII
NOVEL MODELS
Sixty-fourth. Institutions and Mutual Insurance Societies that intend to obtain authorization from the Commission so that, through Novel Models, they carry out any of the Operations referred to in fraction XXIX of Provision Second, shall:
I. Identify and evaluate the risk to which they are exposed, prior to the launch of the product or service in question through Novel Models. The evaluation referred to in this fraction shall be carried out in accordance with Chapter III of these Provisions.
II. Present the result of the evaluation referred to in the previous fraction to the Commission along with its request for authorization.
III. Comply with these Provisions, according to the cases, forms, terms, deadlines, conditions, and exceptions indicated in the respective authorization, prior to the opinion of the Secretariat.
CHAPTER XIV
EXCHANGE OF INFORMATION BETWEEN ENTITIES
Sixty-fifth. In order to carry out the exchange of information referred to in articles 199, 346, and 493 of the Law and 113 of the Law to Regulate Financial Groups, the Institutions and Mutual Insurance Societies shall be subject to what is provided in this Chapter.
Sixty-sixth. The Institutions and Mutual Insurance Societies may exchange information on Client Operations, for which they shall limit themselves solely and exclusively to cases where the purpose is to strengthen measures to prevent and detect acts, omissions, or Operations that could update the circumstances provided for in articles 139, 139 Quater, 148 Bis, or 400 Bis of the Federal Penal Code.
The exchange of information referred to in this Chapter shall be carried out in accordance with the following:
I. It may be carried out between Institutions and Mutual Insurance Societies.
II. It may be requested only by officials of the Institutions and Mutual Insurance Societies authorized for such purposes, in writing in which the reason and class of information required must be specified.
III. The information request may be sent electronically or digitally, ensuring the confidentiality of the information.
IV. The response to the information request shall be sent in writing signed by the officials authorized for such purposes, within a period that shall not exceed 30 calendar days counted from the date on which it was requested. The response to the request may also be sent electronically or digitally, ensuring the confidentiality of the information.
V. The information provided in terms of what is stated in this Chapter may only be used by the person who requested it, unless the written response establishes that it is information that can in turn be shared with other Institutions.
VI. The Institutions and Mutual Insurance Societies may, without needing to receive the request referred to in fraction II of this Provision, share with other Institutions and Mutual Insurance Societies, as appropriate, the information they consider relevant for the aforementioned purposes, through the mechanisms established for such purposes, provided that what is provided in this Chapter is complied with.
When an Institution or Mutual Insurance Society shares with another and other Institutions or Mutual Insurance Societies the information referred to in this provision, the former shall preserve all supporting documentation, which shall be available to the Secretariat and the Commission, at the request of the latter, within the period established by the Commission itself.
The Institution or Mutual Insurance Society may preserve the information and documentation indicated in this paragraph in the Files or Records that it keeps for this purpose to comply with these Provisions, guaranteeing the security and preservation of the information.
VII. Prior to or simultaneously with an Institution or Mutual Insurance Society sharing, with another or other Institutions or a Mutual Insurance Society sharing, the information referred to in this Provision, it shall give notice of such circumstance to the Secretariat, through the Commission, in the electronic means and in the official format issued by the Commission for such purpose, for which it shall provide the following:
a) Whether there is a request or if the information in question is shared spontaneously.
b) The Institution or Mutual Insurance Society to which the information will be delivered.
c) The information that will be shared.
d) The purposes pursued with the delivery of such information.
Sixty-seventh. The Institutions and Mutual Insurance Societies may exchange information about their Clients, as well as their Operations, with analogous Foreign Financial Entities, for the purposes referred to in the first paragraph of the Sixty-sixth of these Provisions, through the official format issued by the Secretariat and through the means indicated by it; subject to compliance with the following conditions:
I. The Institutions and Mutual Insurance Societies shall agree with the analogous Foreign Financial Entities on the confidential treatment of the exchanged information and the positions of the persons authorized by both parties to carry out such exchange.
Likewise, prior to the exchange of information, the Institutions and Mutual Insurance Societies shall inform the Commission, in the official format issued by the Commission for such purposes and through the means it establishes, about the signing of the agreement referred to in this fraction.
II. Prior to or simultaneously with the exchange of information, the Institution or Mutual Insurance Society shall send to the Secretariat, through the Commission, through the means designated by the Secretariat, a copy of the format referred to in the first paragraph of this Provision containing the exchanged information.
In all cases, the exchange of information must result from an Operation carried out between the Institutions or Mutual Insurance Societies and the analogous Foreign Financial Entities.
Sixty-eighth. In order to strengthen measures to prevent and detect acts, omissions, or Operations that could favor, provide help, assistance, or cooperation of any kind for the commission of the crimes provided for in articles 139, 139 Quater, 148 Bis, or 400 Bis of the Federal Penal Code, the Institutions and Mutual Insurance Societies may exchange the content of the List of Blocked Persons, with the following persons:
I. Representative offices referred to in article 108 of the Law, with which they maintain a commercial relationship.
II. Foreign Financial Institutions referred to in article 74 of the Law, when they are subsidiaries of the latter.
III. Foreign financial entities in which they hold direct or indirect investments in shares representing their share capital, as well as with those financial intermediaries that are their subsidiaries, in terms of what is established in article 265 of the Law.
IV. Foreign Financial Entities with which the Institutions carry out Operations as reinsurer or reinsurer.
V. Financial entities that are part of the same financial group, in terms of what is provided in the Law to Regulate Financial Groups.
For the purposes of the foregoing, the Institutions and Mutual Insurance Societies shall establish in their Compliance Manual, or in some other document or manual prepared by them, the measures that must be applied to guarantee the confidential treatment of the content of the List of Blocked Persons.
Sixty-ninth. The Institutions and Mutual Insurance Societies that are part of financial groups in terms of the Law to Regulate Financial Groups may exchange any type of information on the Operations they carry out with their Clients, with the other financial entities that are part of the same group that are authorized to do so in accordance with the applicable provisions, in matters of prevention of operations with funds of illicit origin and terrorism financing, provided that they conclude an agreement between them in which they stipulate the following:
I. The confidential treatment that will be given to the exchanged information.
II. The positions of the officials authorized to carry out the aforementioned exchange.
Prior to the exchange of information, the Institutions and Mutual Insurance Societies shall inform the Commission about the signing of the agreement referred to in this provision, in the official format issued by it for such purposes and through the means it establishes.
When an Institution and Mutual Insurance Society shares with another or other financial entities that are part of the same financial group the information referred to in this provision, the former shall preserve all supporting documentation, which shall be available to the Secretariat and the Commission, at the request of the latter, within the period established by the Commission itself.
CHAPTER XV
LIST OF BLOCKED PERSONS
Seventieth. The Secretariat shall make available to the Institutions and Mutual Insurance Societies, through the Commission, the List of Blocked Persons and its updates.
The Institutions and Mutual Insurance Societies shall adopt and implement mechanisms that allow them to identify Clients who are within the List of Blocked Persons, as well as any third party acting on behalf or for the account of the same. Such mechanisms shall be provided for in the Compliance Manual.
Seventy-first. The Secretariat may introduce persons into the List of Blocked Persons, under the following parameters:
I. Those that are within the lists derived from resolutions 1267 (1999) and successive, and 1373 (2001) and those that are issued by the United Nations Security Council or international organizations.
II. Those that are made known by foreign authorities, international organizations, or intergovernmental groupings and that are determined by the Secretariat in terms of the international instruments celebrated by the Mexican State with said authorities, organizations, or groupings, or in terms of the agreements celebrated by the Secretariat itself.
III. Those that are made known by the competent national authorities for having sufficient indications that they are related to the crimes of terrorism financing, operations with funds of illicit origin, or those related to the crimes indicated, provided for in the Federal Penal Code.
IV. Those that are serving sentences for the crimes of terrorism financing or operations with funds of illicit origin, provided for in the Federal Penal Code.
V. Those that the competent national authorities determine have carried out or are carrying out activities that form part of, assist, or are related to the crimes of terrorism financing or operations with funds of illicit origin, provided for in the Federal Penal Code.
VI. Those that omit providing information or data, conceal it, or prevent the origin, location, destination, or ownership of funds, rights, or assets coming from crimes of terrorism financing or operations with funds of illicit origin, provided for in the Federal Penal Code or those related to them, from being known.
Seventy-second. The Institution or Mutual Insurance Society, when identifying upon carrying out an Operation that the name of its Client is within the List of Blocked Persons, or that third parties carry them out in its favor, to its account, or in its name, shall send to the Secretariat, through the Commission, within twenty-four hours counted from when it knows of such information, a report of Unusual Operation, in terms of the Thirty-eighth of these Provisions, in which, in the column of description of the Operation, the legend "List of Blocked Persons" shall be inserted.
CHAPTER XVI
GENERAL PROVISIONS
Seventy-third. Each Institution or Mutual Insurance Society shall prepare a document in which it develops its policies for identification and customer knowledge, as well as the criteria, measures, and internal procedures that it must adopt to comply with what is provided in these Provisions and to manage the Risks to which it is exposed in accordance with the results of implementation of the methodology referred to in Chapter III, of these Provisions.
In the aforementioned document, references to those criteria, measures, internal procedures, and other information that, by virtue of what is provided in these Provisions, may be reflected in a document different from the one mentioned shall be included.
In any of the documents provided for in the previous paragraph, the methodology referred to in Chapter III of these Provisions shall be included. Likewise, the procedure and criteria for the determination of the celebration, limitation, and/or termination of a commercial relationship with Clients shall be included, which shall be congruent with said methodology.
The Institutions and Mutual Insurance Societies shall not be obliged to have procedures and criteria to limit or terminate the commercial relationship, with respect to the Operations referred to in article 118, fraction I, and 341, fraction I of the Law.
The Institutions and Mutual Insurance Societies shall submit to the Commission, through the electronic means determined by it, the documents indicated and any modifications to them, within twenty business days following the date on which their respective Audit Committee approves them.
The criteria, measures, procedures, and other information related to compliance with these Provisions, which are contained in documents other than those referred to in the first paragraph, shall be available to the Commission, for the purposes of what is established in Provision Seventy-fifth.
The Institutions and Mutual Insurance Societies may reserve the disclosure within themselves of the content of some or some of the sections of the document referred to in the first paragraph, as well as of any other document containing information related to what is established in these Provisions.
With respect to entities that are part of financial groups in terms of articles 5°, fraction I, and 102 of the Law to Regulate Financial Groups, they shall have a program that includes the requirements implemented by the financial group to which they belong in matters of Money Laundering Prevention and Combating Terrorism Financing, which shall form part of the document referred to in this Provision.
The Commission shall, at the request of the Secretariat, send it a copy of the documents referred to in this Provision.
Seventy-fourth. The Commission shall be empowered to require the Institutions and Mutual Insurance Societies to make modifications to the Compliance Manual, as well as to the other documents indicated in them, when in its judgment it is necessary for the correct application of them.
Seventy-fifth. The Commission, in exercise of the supervisory powers conferred by the Law and other legal instruments, will monitor that the Institutions and Mutual Insurance Societies, including in its case, their offices, branches, agencies, and subsidiaries, both in national territory and abroad, comply with the obligations established in these Provisions, in the Compliance Manual,
Compliance, as well as in any other document that establishes criteria, measures, and procedures related to compliance with these Provisions.
The Commission may request at any time the information or documentation necessary for the development of its powers and will impose the corresponding sanctions for failure to comply with the obligations indicated in the preceding paragraph.
Seventy-Sixth. For the purpose of imposing sanctions, non-compliance with the provisions of these Provisions shall be considered to include cases where Insurance Institutions and Mutual Insurance Societies submit incomplete, illegible, or erroneous information, or when the electronic medium does not meet the technical specifications indicated by the Secretariat or the Commission, as applicable.
Sanctions shall also be imposed on Agents when, due to their acts or omissions, they cause Institutions to fail to comply with their imposed obligations.
Seventy-Seventh. The Secretariat, after hearing the opinion of the Commission, shall make known to Insurance Institutions and Mutual Insurance Societies, by way of example, the list of public offices that will be considered as national Politically Exposed Persons and shall make it available to the respective Insurance Institutions and Mutual Insurance Societies through their portal on the worldwide web known as the Internet.
Insurance Institutions and Mutual Insurance Societies shall prepare their own lists of persons who could be considered Politically Exposed Persons, taking as a basis the list referred to in the preceding paragraph.
Likewise, the Secretariat shall make known to Insurance Institutions and Mutual Insurance Societies the officially recognized lists issued by international organizations or authorities of other countries, of persons blocked for being linked to terrorism or its financing, or with other illegal activities.
Seventy-Eighth. The Secretariat may interpret, for administrative purposes, the content of these Provisions, as well as determine the scope of their application, for which it will hear the opinion of the Commission.
Seventy-Ninth. When, legally or by policy, commercial strategy, or business strategy, Insurance Institutions and Mutual Insurance Societies do not carry out or participate in any of the Operations indicated in these Provisions, it will not be necessary to establish the policies, criteria, procedures, and systems provided for in those cases.
In the case indicated in the preceding paragraph, Insurance Institutions and Mutual Insurance Societies shall establish this situation in their Compliance Manual.
If the rule or commercial or business strategy is modified, the Institution or Mutual Insurance Society must develop the necessary policies, criteria, procedures, and systems before carrying out or participating in the Operations in question.
Eightieth. Insurance Institutions and Mutual Insurance Societies, in order to be able to comply with what is established in these Provisions, shall request from the Commission the key that will be used to access the electronic system that the Commission establishes for such purposes, and must have it at the time of initiating operations.
Likewise, Insurance Institutions and Mutual Insurance Societies must ensure that the key referred to in the preceding paragraph remains updated in the name of the Compliance Officer or Compliance Officer designated as interim, as applicable.
Eighty-First. From the moment a declaration of natural disaster, health contingency, or emergency is issued, and for the following eight months, regarding claims related to such situations, Insurance Institutions may abstain from completing the verification of identity in terms of the Fourth, Seventh, and Eighth of the Provisions, at the moment their Clients and Beneficiaries exercise their rights or resources are delivered to them, provided that the payment is made via:
I. Transfer to an account that the Client or Beneficiary holds at any credit institution, or
II. The delivery of a named check in the name of the Client or Beneficiary, for deposit into an account in their name at any credit institution.
TRANSITIONAL PROVISIONS
First.- This Resolution issuing the General Provisions referred to in Article 492 of the Law of Insurance and Surety Institutions shall enter into force on December 31, 2020.
Second.- From the date of entry into force of this Resolution, the Resolutions issuing the General Provisions referred to in Article 140 of the General Law of Insurance and Mutual Insurance Institutions, and the General Provisions referred to in Article 112 of the Federal Law of Surety Institutions, both published in the Official Journal of the Federation on July 19, 2012, are hereby repealed.
Any reference to the Repealed Resolutions shall be understood to refer to the General Provisions referred to in Article 492 of the Law of Insurance and Surety Institutions contained in this Resolution.
Third.- Guidelines, interpretations, and criteria issued by the Secretariat or by the Commission, based on what is provided in the Repealed Resolutions, shall remain applicable insofar as they do not conflict with what is established in this Resolution.
Fourth.- The Commission shall make known within sixty calendar days following the date of publication of this Resolution, the Lists of Blocked Persons and from that date, shall remit the corresponding updates.
The Commission may request from Insurance Institutions and Mutual Insurance Societies, prior to the entry into force of this Resolution, a report on the progress in the implementation and compliance with these Provisions.
The obligations, procedures, and requirements related to Geolocation shall be enforceable until the corresponding general provisions are issued.
Fifth.- Insurance Institutions and Mutual Insurance Societies must initiate the implementation and compliance processes of the Provisions from the publication of this Resolution.
Given in Mexico City, on the 10th day of the month of November of two thousand twenty.- The Secretary of Finance and Public Credit, Arturo Herrera Gutiérrez. - Rubric.
ANNEXES OF THE GENERAL PROVISIONS REFERRED TO IN ARTICLE 492 OF THE LAW OF INSURANCE AND SURETY INSTITUTIONS
ANNEX 1
DATA AND DOCUMENTS WITH WHICH THE CLIENT FILE MUST BE INTEGRATED MEXICAN NATURAL PERSONS
The client file must include the same data and documents of Mexican natural persons who have the status of:
Beneficial Owners, independent of the data and documents that must be collected from whoever presents themselves as the Client.
Spouse or economic dependent when the Client has been classified with High Risk Grade.
Beneficiaries.
I. DATA
a) Paternal surname, maternal surname, name(s).
b) Date of birth.
c) Country of birth.
d) Federal entity of birth.
e) Nationality.
f) Occupation, profession, activity, or business sector to which the Client is dedicated.
g) Private address at their place of residence.
h) Phone number where they can be reached.
i) Email address, if applicable.
j) Unique Population Registry Key and Federal Taxpayer Registry (with homoclave), when available.
k) Serial number of the digital certificate of the Advanced Electronic Signature, when available.
l) Regarding persons who have their place of residence abroad and, at the same time, have an address in national territory where they can receive correspondence addressed to them, the Institution or Mutual Insurance Society must record in the file the data related to said address, with the elements contemplated in this Annex.
II. DOCUMENTS
a) Personal identification.
b) Certificate of the Unique Population Registry Key (with homoclave). This certificate will not be necessary if the Key appears in another document or official identification.
c) Federal Taxpayer Registry Key (with homoclave) when available.
d) Tax Identification Card and/or equivalent (with homoclave); the Card will not be necessary if the tax identification number and/or equivalent appears in another document issued by a competent tax authority, when available.
e) Proof of registration for the Advanced Electronic Signature, when available.
f) Proof of address.
g) Signed Declaration of the natural person, which may be granted in writing, by optical means, or by any other technology, which may be included in the application documentation for the Operation or in the respective contract, in which it is stated that such person acts for these purposes in their own name and on their own account or on behalf of a third party, as applicable.
III. DEVICES (Non-presential) when dealing with operations other than those established in Provision Seventh.
a) Voter Key, if applicable.
b) Consent.
c) Email or cell phone.
d) If applicable, account number and Standardized Banking Key (CLABE) in the Entity, financial entity, or National or Foreign Financial Entity authorized to receive deposits, and which corresponds to the name indicated in the Client's data and documents.
e) The statement of the natural person indicating whether they act on their own account or on behalf of a third party; if they state that they act on behalf of a third party, the same data and documents of the third party will be collected. Such statement may be established in the Terms and Conditions established for this purpose by the Institution or Mutual Insurance Society.
f) The digital version of the valid official personal identification document from which the data referred to in this Annex originate, which must be preserved in accordance with the applicable Mexican official standard on digitization and preservation of Data Messages.
Regarding Beneficial Owners, the Data of the address where they can be located will suffice. If the Client is classified with a low risk grade, it will not be necessary to collect proof of address.
Any other authorized by the National Insurance and Sureties Commission.
ANNEX 2
DATA AND DOCUMENTS WITH WHICH THE CLIENT FILE MUST BE INTEGRATED FOREIGN NATURAL PERSONS, IN CONDITIONS OF TEMPORARY OR PERMANENT RESIDENT STAY, IN TERMS OF THE MIGRATION LAW
The client file must include the same data and documents of foreign natural persons, in conditions of temporary or permanent resident stay, in terms of the Migration Law, who have the status of:
Beneficial Owners, independent of the data and documents that must be collected from whoever presents themselves as the Client.
Spouse or economic dependent when the Client has been classified with High Risk Grade.
I. DATA
a) Paternal surname, maternal surname, name(s).
b) Date of birth.
c) Country of birth.
d) Federal entity of birth.
e) Nationality.
f) Occupation, profession, activity, or business sector to which the Client is dedicated.
g) Private address at their place of residence.
h) Phone number where they can be reached.
i) Email address, if applicable.
j) Unique Population Registry Key and Federal Taxpayer Registry (with homoclave), tax identification number and/or equivalent, as well as the country or countries that assigned them, when available.
k) Serial number of the digital certificate of the Advanced Electronic Signature, when available.
II. DOCUMENTS
a) Personal identification.
b) Certificate of the Unique Population Registry Key and/or Tax Identification Card, when available.
c) Proof of registration for the Advanced Electronic Signature, when available.
d) Proof of address.
e) Signed Declaration of the natural person, which may be granted in writing, by optical means, or by any other technology, which may be included in the application documentation for the Operation or in the respective contract, in which it is stated that such person acts for these purposes in their own name and on their own account or on behalf of a third party, as applicable.
f) Document accrediting their migratory status.
III. DEVICES (Non-presential) when dealing with operations other than those established in Provision Seventh.
a) Voter Key, if applicable.
b) Consent.
c) Email or cell phone.
d) If applicable, account number and Standardized Banking Key (CLABE) in the Entity, financial entity, or National or Foreign Financial Entity authorized to receive deposits, and which corresponds to the name indicated in the Client's data and documents.
e) The statement of the natural person indicating whether they act on their own account or on behalf of a third party; if they state that they act on behalf of a third party, the same requirements contemplated for titular Clients will be collected. Such statement may be established in the Terms and Conditions established for this purpose by the Institution or Mutual Insurance Society.
f) The digital version of the valid official personal identification document from which the data referred to in this Annex originate, which must be preserved in accordance with the applicable Mexican official standard on digitization and preservation of Data Messages.
Regarding Beneficial Owners, the Data of the address where they can be located will suffice. If the Client is classified with a low risk grade, it will not be necessary to collect proof of address.
Any other authorized by the National Insurance and Sureties Commission.
ANNEX 3
DATA AND DOCUMENTS WITH WHICH THE CLIENT FILE MUST BE INTEGRATED FOREIGN NATURAL PERSONS
The client file must include the same data and documents of foreign natural persons who have the status of:
Beneficial Owners, independent of the data and documents that must be collected from whoever presents themselves as the Client.
Spouse or economic dependent when the Client has been classified with High Risk Grade.
Beneficiaries.
I. DATA
a) Paternal surname, maternal surname, name(s).
b) Date of birth.
c) Country of birth.
d) Nationality.
e) Occupation, profession, activity, or business sector to which the Client is dedicated.
f) Private address at their place of residence.
g) Phone number where they can be reached.
h) Email address, if applicable.
i) Unique Population Registry Key and Federal Taxpayer Registry (with homoclave), tax identification number and/or equivalent, as well as the country or countries that assigned them, when available.
j) Serial number of the digital certificate of the Advanced Electronic Signature, when available.
k) Regarding persons who have their place of residence abroad and, at the same time, have an address in national territory where they can receive correspondence addressed to them, the Institution or Mutual Insurance Society must record in the file the data related to said address, with the elements contemplated in this Annex.
II. DOCUMENTS
a) Passport.
b) Official document issued by the National Institute of Migration, when available, accrediting their entry or legal stay in the country.
c) Document accrediting address at the permanent place of residence.
d) Signed Declaration of the natural person, which may be granted in writing, by optical means, or by any other technology, which may be included in the application documentation for the Operation or in the respective contract, in which it is stated that such person acts for these purposes in their own name and on their own account or on behalf of a third party, as applicable.
III. DEVICES (Non-presential) when dealing with operations other than those established in Provision Seventh.
a) Voter Key, if applicable.
b) Consent.
c) Email or cell phone.
d) If applicable, account number and Standardized Banking Key (CLABE) in the Entity, financial entity, or National or Foreign Financial Entity authorized to receive deposits, and which corresponds to the name indicated in the Client's data and documents.
e) The statement of the natural person indicating whether they act on their own account or on behalf of a third party; if they state that they act on behalf of a third party, the same requirements contemplated for titular Clients will be collected. Such statement may be established in the Terms and Conditions established for this purpose by the Institution or Mutual Insurance Society.
f) The digital version of the valid official personal identification document from which the data referred to in this Annex originate, which must be preserved in accordance with the applicable Mexican official standard on digitization and preservation of Data Messages.
Regarding Beneficial Owners, the Data of the address where they can be located will suffice. If the Client is classified with a low risk grade, it will not be necessary to collect proof of address.
Any other authorized by the National Insurance and Sureties Commission.
ANNEX 4
DATA AND DOCUMENTS WITH WHICH THE CLIENT FILE MUST BE INTEGRATED MEXICAN LEGAL ENTITIES
The client file must include the same data and documents of Mexican legal entities that have the status of Beneficiaries.
I. DATA
a) Trade name or corporate name.
b) Commercial sector, activity, or corporate purpose.
c) Nationality.
d) Federal Taxpayer Registry Key (with homoclave) and/or tax identification number and/or equivalent, the country or countries that assigned them.
e) The serial number of the digital certificate of the Advanced Electronic Signature, when available.
f) Address.
g) Phone number of said address.
h) Email, if applicable.
i) Date of Constitution.
j) Commercial Folio.
k) Name(s) and paternal and maternal surnames, without abbreviations, of the administrator or administrators, director, general manager, or attorney-in-fact who, with their signature, can
l) bind the legal entity for the purposes of the celebration of the Operation in question.
When the Mexican legal entity has been classified with High Risk Grade, data related to the following must also be included:
a) Corporate, shareholder, or partnership structure.
b) Of the Principal shareholders: i) name, ii) nationality; iii) percentage of capital representing their participation in the corresponding social capital.
II. DOCUMENTS
a) Notarial deed or certified copy accrediting their legal existence registered in the public registry corresponding to it, according to the nature of the legal entity, or any instrument in which the data of their constitution and their registration in said registry appear, or the document that, according to the regime applicable to the legal entity in question, credibly accredits its existence.
b) In the case that the legal entity is of recent constitution, and therefore not yet registered in the public registry corresponding to it according to its nature, the Institution in question must obtain a written statement signed by a person legally authorized, in which the obligation to carry out the respective registration and provide, in due course, the corresponding data to the Institution or Mutual Insurance Society is stated.
c) Tax Identification Card and, if applicable, the document in which the assignment of the tax identification number and/or equivalent issued by a competent authority and proof of the Advanced Electronic Signature appear.
d) Proof of address.
e) Notarial deed or certified copy of the instrument containing the powers of the representative or legal representatives, issued by a public notary, when not contained in the public instrument accrediting the legal existence of the legal entity in question, as well as the personal identification of each of said representatives.
f) In case it has a Risk Grade other than low, its internal corporate structure; that is, the organizational chart of the Client legal entity, considering at least the full name and position of those individuals occupying positions between general director and the immediate lower hierarchy, as well as the full name and corresponding position of the members of its board of directors or equivalent.
g) Document containing the identification of the Natural Person exercising Control; when there is no natural person who owns or controls, directly or indirectly, a percentage equal to or greater than 25% of the capital or voting rights of the legal entity in question, or who by other means exercises Control, direct or indirect, of the legal entity, it will be considered that Control is exercised by the administrator or administrators thereof, understanding that administration is exercised by the natural person designated for such effect by this.
h) When the designated administrator is a legal entity or fiduciary institution in a Trust, it will be understood that Control is exercised by the natural person appointed as administrator by said legal entity or Trust.
When the Mexican legal entity has been classified with High Risk Grade, the following documents must also be included:
a) The one identifying the respective shareholders or partners, in the case that they are classified as high risk.
b) Written declaration, by electronic, optical, or any other technology means of the legal representative of the Client legal entity in question, indicating who their Beneficial Owners are in terms of this Annex.
III. DEVICES (Non-presential) when dealing with operations other than those established in Provision Seventh.
a) Email.
b) If applicable, account number and Standardized Banking Key (CLABE) in the financial entity or Foreign Financial Entity authorized to receive deposits, and which corresponds to the name indicated in the Client's data and documents.
c) Electronic Signature or Advanced Electronic Signature of the legal representative.
d) The information referred to in items I and II of this Annex.
e.
The digital version of the identification documents referred to in items I and II of this Annex.
ANNEX 5
DATA AND DOCUMENTS WITH WHICH THE CLIENT FILE
MUST BE INTEGRATED
LEGAL ENTITIES OF FOREIGN NATIONALITY
The client file must include the same data and documents for foreign legal entities that have the status of:
Beneficiaries.
I. DATA
a)
Trade name or corporate name.
b)
Commercial activity, activity, or corporate purpose.
c)
Nationality.
d)
Federal Taxpayer Registry Key (with homoclave) and/or tax identification number and/or equivalent, the country or countries that assigned it, and, if applicable, the serial number of the Advanced Electronic Signature digital certificate.
e)
Address.
f)
Telephone number(s) for said address.
g)
Email, if applicable.
h)
Date of incorporation.
The following data may be obtained at all times, but will be mandatory when the foreign legal entity has been classified as High Risk:
a)
Corporate, shareholder, or partnership structure.
b)
Regarding Principal Shareholders: i) name, ii) nationality; iii) percentage of capital representing their participation in the corresponding social capital.
II. DOCUMENTS
a)
Document that reliably proves their legal existence, as well as information allowing knowledge of their shareholding structure.
b)
Document showing the assignment of the tax identification number and/or equivalent issued by the competent authority.
c)
Document allowing knowledge of their shareholding or partnership structure, as applicable.
d)
Proof of declared address.
e)
Document identifying the respective shareholders or partners, in the case that they are classified as high risk.
f)
Notarized copy or certified copy of the instrument containing the powers of the representative or legal representatives, issued by a public notary or equivalent, when not contained in the document that reliably proves the legal existence of the legal entity in question, as well as the personal identification of said representatives.
III. DEVICES (Non-presential) when dealing with operations other than those established in Seventh Provision.
a)
Email.
b)
If applicable, account number and Standardized Banking Key (CLABE) in the financial entity or Foreign Financial Entity authorized to receive deposits, and which corresponds to the name indicated in the client's data and documents.
c)
Electronic Signature or Advanced Electronic Signature, of the legal representative.
d)
The information referred to in items I and II of this Annex.
e)
The digital version of the identification documents referred to in items I and II of this Annex.
ANNEX 6
DOCUMENTS OF CLIENTS' ATTORNEYS-IN-FACT, WHICH MUST BE INTEGRATED INTO THEIR
FILE, EVEN WHEN DEALING WITH CLIENTS THAT ARE COMPANIES, DEPARTMENTS AND
ENTITIES REFERRED TO IN ANNEX 7
Personal identification.
The document accrediting the status of attorney-in-fact, in terms of the legislation applicable to the principal and the nature of the business: For example:
a)
Power of attorney signed before two witnesses.
b)
Certified copy of the notarized instrument or constitutive deed in which the powers conferred on the attorney-in-fact are stated, with or without registration data, as applicable.
c)
When dealing with credit institutions and brokerage houses, certificate of appointment in terms of Article 90 of the Credit Institutions Law and 129 of the Securities Market Law, respectively.
d)
When dealing with federal, state, and municipal public departments and entities, as well as other Mexican legal entities of public law, to prove the powers of their legal representatives and/or attorneys-in-fact, the laws, regulations, decrees, or organic statutes that create and regulate their constitution and operation shall apply, and if applicable, a copy of their appointment or by public instrument issued by a notary, as applicable.
e)
In cases where Clients carry out operations through legal representatives, attorneys-in-fact, fiduciary delegates, or signature holders, whose domicile is located outside the national territory, the Institution will be obligated to request such Clients for information regarding domiciles outside the national territory and collect the tax identification number and/or equivalent, as well as the country or countries that generated said numbers, if applicable.
f)
When dealing with federal, state, and municipal public departments and entities, as well as other Mexican legal entities of public law, to prove their legal existence, the laws, regulations, decrees, or organic statutes that create and regulate their constitution and operation shall apply.
g)
Email.
h)
If applicable, account number and Standardized Banking Key (CLABE) in the National or Foreign Financial Entity authorized to receive deposits.
ANNEX 7
COMPANIES, DEPARTMENTS AND ENTITIES REGARDING WHICH SIMPLIFIED MEASURES
MAY BE APPLIED FOR THEIR IDENTIFICATION
Controlling Companies of Financial Groups.
Investment Funds.
Investment Companies Specialized in Retirement Funds.
Investment Fund Operating Companies.
Investment Fund Share Distributing Companies.
Credit Institutions.
Brokerage Houses.
Exchange Houses.
Retirement Fund Administrators.
Insurance Institutions.
Mutual Insurance Societies.
Surety Institutions.
General Warehouses.
Savings and Loan Cooperative Societies.
Popular Financial Societies.
Multiple-Objective Financial Societies.
Credit Unions.
Securities Issuing Companies (1).
Foreign Financial Entities (2).
Federal, state, and municipal public departments and entities.
Stock Exchange.
Companies that administer mechanisms to facilitate transactions with securities.
Central Counterparties.
Price Providers.
Securities Rating Agencies.
ANNEX 8
DATA THAT MUST BE INTEGRATED INTO THE FILE OF THE COMPANIES,
DEPARTMENTS AND
ENTITIES OF ANNEX 7
·
Trade name or corporate name.
·
Activity or corporate purpose.
·
Federal Taxpayer Registry (with homoclave) and, if applicable, tax identification number and/or equivalent, as well as the country or countries that assigned them.
·
The serial number of the Advanced Electronic Signature, when they have it.
·
Address.
·
Telephone number(s) for said address.
·
Email, if applicable.
·
Full name without abbreviations of the administrator or administrators, director, general manager or attorney-in-fact, who with their signature can bind the company, department or entity for the purposes of celebrating the Operation in question.
When the Company or Entity has been classified as High Risk, the following data must also be included:
·
Corporate, shareholder, or partnership structure.
·
Name and nationality of the principal shareholders.
·
Regarding principal shareholders: i) name, ii) nationality; iii) percentage of capital representing their participation in the corresponding social capital.
ANNEX 9
TYPES AND CHARACTERISTICS OF THE DATA AND DOCUMENTS THAT ACCORDING TO EACH ONE
OF THE ANNEXES MUST BE INTEGRATED INTO THE CLIENT FILES
I. PERSONAL IDENTIFICATION
Voter Credential.
Passport.
Professional ID.
National Military Service Card.
Consular Enrollment Certificate.
Unified Military Identity Card.
Credentials and/or Affiliation Cards of the Mexican Institute of Social Security or the Institute of Security and Social Services for State Workers.
Affiliation Card of the National Institute of Older Adults.
Driver's License.
Credentials issued by federal, state, or municipal authorities.
Regarding foreign natural persons who do not have a passport, any official document issued by the competent authority of the country of origin, valid on the date of its presentation, containing the photograph, signature, and, if applicable, domicile of the person in question, will be considered as valid personal identification documents. For these purposes, the driver's license and credentials issued by the authorities of the country in question are considered valid personal identification documents. The verification of the authenticity of said documents will be the responsibility of the Institutions.
Any other authorized by the National Insurance and Sureties Commission.
II. PROOF OF ADDRESS
It will be required when the address stated in the contract celebrated by the Client with the Institution does not coincide with that of the identification or if the latter does not contain it.
Receipt accrediting the payment of any of the following home services (3)
a)
Electricity supply
b)
Residential and cellular telephony subject to a payment plan
c)
Natural gas, and
d)
Rights for the water supply service.
Property tax payment receipt
Bank statements
Lease agreement, valid on the date of presentation by the Client
Proof of registration with the Federal Taxpayer Registry
Notarized copy or certified copy accrediting that the Client is the legitimate owner of the property indicated as current and permanent domicile
Any other authorized by the National Insurance and Sureties Commission.
III. ADDRESS DATA
For the case of domicile within national territory, it must be composed of the following elements: name of the street, avenue, or road, duly specified; exterior number and, if applicable, interior; neighborhood or urbanization; delegation, municipality, or political demarcation that corresponds; city or town, federative entity, state, province, department, or similar political demarcation that corresponds, if applicable; postal code and country.
For the case of domicile abroad, the domicile must be composed of the following elements: name of the street, avenue, or road, duly specified; exterior number and, if applicable, interior; neighborhood or urbanization; delegation, municipality, or political demarcation that corresponds; city or town, federative entity, state, and postal code.
When dealing with natural persons who have their place of residence abroad and, at the same time, have a domicile within national territory where they can receive correspondence, the Institution must record in the file the data relating to said domicile.
IV. SIGNED DECLARATION
The Institution or Mutual Insurance Society must obtain from the natural person a signed declaration by them, in the format prepared for this effect, in which it is stated that such person acts in their own name and on their own behalf or on behalf of a third party, as the case may be, which the Institution must keep in the Client's file.
V. PUBLIC DOCUMENTS ISSUED ABROAD
For a public document issued abroad to have legal effects in the Mexican Republic, the Institution or Mutual Insurance Society in question must require that it be duly legalized or apostilled, in the case where the country where said document was issued is a party to the "Convention Abolishing the Requirement of Legalization for Foreign Public Documents" adopted in The Hague, The Hague, Netherlands, on October 5, 1961, by which the requirement of legalization of foreign public documents is abolished, it will suffice that said document bears the apostille referred to in said Convention.
In the event that the respective Client does not present the documentation duly legalized or apostilled, it will be the responsibility of the Institution or Mutual Insurance Society to ensure the authenticity of said documentation.
Institutions and Mutual Insurance Societies may keep, in their Files or Records, separately the data and documents that should form part of the identification files of their Clients, without the need to integrate both into a single physical file, provided they have automated systems that allow them to combine said data and documents for timely consultation by the Institutions and Mutual Insurance Societies themselves or by the Secretariat or the Commission, at the request of the latter, in terms of these Provisions and the others that are applicable.
ANNEX 10
TRUSTEES, DATA AND DOCUMENTS THAT HAVE
TO BE INTEGRATED INTO THE CLIENT FILES
The client file must include the same data and documents of trusts that have the status of Beneficiaries.
I. GENERAL DATA:
a)
Number or reference of the Trust
b)
If applicable, Federal Taxpayer Registry Key (with homoclave) or tax identification number and/or equivalent and the country or countries that assigned it.
c)
Serial number of the Advanced Electronic Signature,
d)
Purpose of the Trust and, if applicable, indicate the vulnerable activity(ies) carried out in terms of Article 17 of the Federal Law for the Prevention and Identification of Operations with Resources of Illicit Origin;
e)
Place and date of constitution or celebration of the Trust
f)
Trade name or corporate name of the trustee institution;
g)
Trusted assets (goods and rights);
h)
Contributions by the settlors, and
i)
Regarding the settlors, beneficiaries, fiduciary delegates, and, if applicable, members of the technical committee or equivalent governing body, legal representative(s) and legal attorney(s), identification data must be collected in the terms referred to in Annexes 1, 2, 3, 4 and 5, as applicable. Without prejudice to the foregoing, the Institution that does not act as trustee may comply with the obligation to collect data relating to members of the technical committee or equivalent governing body, indicating only the first and last names, without abbreviations, of these.
II. THE INSTITUTION MUST COLLECT AND INCLUDE IN THE RESPECTIVE IDENTIFICATION FILE A SIMPLE COPY OF AT LEAST THE FOLLOWING DOCUMENTS RELATIVE TO
THE
TRUST:
a)
Contract, notarized instrument, or certified copy of the public instrument accrediting the celebration or constitution of the Trust, registered, if applicable, in the public registry that corresponds, or else, the document that, according to the regime applicable to the Trust in question, reliably proves its existence.
b)
In the event that the Trust is of recent constitution and, in virtue thereof, is not yet registered in the public registry that corresponds according to its nature, the Institution in question must obtain a written document signed by a person legally authorized to accredit their personality in terms of the public instrument issued by a public notary, in which the obligation to carry out the respective registration and provide, in due course, the corresponding data to the Institution itself is stated;
c)
Proof of address,
d)
Notarized copy or certified copy of the instrument containing the powers of the legal representative(s), legal attorney(s) or fiduciary delegate(s), issued by a public notary, when not contained in the public instrument that proves the legal existence of the Trust in question, as well as the personal identification of each of said representatives, attorneys, or fiduciary delegates, and
e)
Tax Identification Card issued by the Secretariat and, if applicable, the document in which the assignment of the tax identification number and/or equivalent issued by the competent authority is stated, as well as certificate of the Advanced Electronic Signature.
Entities will not be obligated to integrate the identification file when it comes to Trusts in which the contributions destined for labor benefits or social security for workers come from the workers themselves or from the employers, and the settlor is always a public entity that allocates the funds in question for the aforementioned purposes.
The Trusts referred to in the previous paragraph may be, among others, the following: Trusts based on pension funds with seniority premium plans; to establish multiple benefits or benefits; for mortgage loans to employees; for savings and mutual aid funds and boxes.
When the designated administrator is a trustee institution, it will be understood that Control is exercised by the natural person appointed as administrator of the Trust.
Institutions and Mutual Insurance Societies that carry out Operations with Trusts regarding which they do not act as trustees may comply with the obligation to collect the document referred to in item a) of this section, through a certificate signed by the fiduciary delegate and the Compliance Officer of the trustee, which must contain the information indicated in the previous item a), as well as the obligation to keep such documentation available to the Secretariat and the Commission, in order to remit it, at the request of the latter, within the timeframe established by the Commission itself.
ANNEX 11
DATA OF THE RESOURCE PROVIDERS OF THE CLIENTS, WHICH HAVE
TO BE INTEGRATED
INTO THEIR FILE
I. IN THE CASE OF NATURAL PERSONS:
j)
Paternal surname, maternal surname, and first name(s) without abbreviations.
a)
Date of birth.
b)
Nationality.
c)
Home address (composed of the name of the street, avenue, or road in question, duly specified, exterior number and, if applicable, interior, neighborhood, city or town, delegation or municipality, federative entity, and postal code), and
d)
If applicable, Federal Taxpayer Registry Key (with homoclave) and/or Unique Registry of Population Key or the ID or tax identification number, in the latter case dealing with foreigners, as well as the serial number of the Advanced Electronic Signature, when they have it.
e)
Occupation, profession, activity, or business sector to which the Resource Provider is dedicated.
II. IN THE CASE OF LEGAL ENTITIES AND SETTLORS:
a)
Trade name or corporate name.
b)
Nationality.
c)
Federal Taxpayer Registry Key (with homoclave), if applicable, ID or tax identification number and/or equivalent, as well as the country or countries that assigned them.
d)
The serial number of the Advanced Electronic Signature digital certificate, when they have it, or tax identification number if they are foreigners, and
e)
Address (composed of the name of the street, avenue, or road in question, duly specified, exterior number and, if applicable, interior, neighborhood, city or town, delegation or municipality, federative entity, and postal code)
Institutions and Mutual Insurance Societies will not be obligated to collect the data referred to in this annex from the Concentrating Accounts of which the Institution or Mutual Insurance Society is the holder when:
a)
The Account in question is used for the payment of payrolls or other benefits resulting from an employment relationship, or for the payment of the supply of goods or services derived from a commercial relationship.
b)
The Resource Providers are departments or entities of the Federal Public Administration, of the City of Mexico, or of any federative entity or municipality, that contribute resources to the respective account under support programs for the benefit of certain sectors of the population.
1
Whose values are registered in the National Securities Registry.
2
That are constituted in countries or territories where measures are applied to prevent, detect, and combat operations with resources of illicit origin and terrorist financing and that are supervised regarding compliance with such measures.
3
With an age not greater than three months, counted from the date of its issuance
In the document you are viewing, there may be text, characters, or objects that do not display correctly due to conversion to HTML format, so we recommend always taking the digitized image of the DOF or the PDF file of the edition as a reference. The content, form, and scope of the published documents are the strict responsibility of their issuer.
CONSULT
BY DATE
Su Mo Tu We Th Fr Sa
INDICATORS
Exchange Rate and Rates as of 08/28/2026
DOLLAR
16.9712 UDIS
8.808812 TIIE 28 DAYS
6.7559% TIIE 91 DAYS
6.7931% TIIE 182 DAYS
6.8474% TIIE OVERNIGHT
6.50%
See more
SURVEYS
Did you like the new look of the Official Federal Gazette website?
No
Yes
Official Federal Gazette
Río Amazonas No. 62, Col. Cuauhtémoc, C.P. 06500, Mexico City Tel. (55) 5093-3200, where you can access our service menu
Electronic address: dof.gob.mx
113
LEGAL NOTICE | SOME RIGHTS RESERVED © 2026