2017-09-08 | DOF 5496686

Added

Amending Circular 9/17 of the Single Insurance and Surety Circular

The National Insurance and Sureties Commission amends provisions 4.10.1, 4.10.2, 4.10.3, and 4.10.8 of the Single Insurance and Surety Circular to establish security measures for electronic transactions. The amendments require institutions to provide clear terms of use, obtain express consent via advanced electronic signatures, and implement multi-factor authentication based on risk levels for various operations such as policy issuance, cancellations, and beneficiary changes. Additionally, provision 4.10.29 is added to mandate compliance with general provisions under Article 492 of the Insurance and Surety Institutions Law. These changes take effect on January 1, 2018.

Secretaria de Hacienda y Credito Publico logo

Mexico

Secretaria de Hacienda y Credito Publico

Click to view thumbnail

DOF: 08/09/2017

Amending Circular 9/17 of the Single Insurance and Surety Circular

At the margin, a seal with the National Coat of Arms, which says: United Mexican States.- Ministry of Finance and Public Credit.- National Insurance and Sureties Commission.

AMENDING CIRCULAR 9/17 OF THE SINGLE INSURANCE AND SURETY CIRCULAR

(Provisions 4.10.1., 4.10.2., 4.10.3., 4.10.8. and 4.10.29.)

The National Insurance and Sureties Commission, based on the provisions of Articles 366, fraction II, 372, fractions VI and XLII, 373 and 381 of the Law of Insurance and Surety Institutions, and

CONSIDERING

That on April 4, 2013, the "Decree by which the Law of Insurance and Surety Institutions is issued and various provisions of the Law on the Insurance Contract are reformed and added" was published in the Official Gazette of the Federation, through which, in terms of its First Article, the Law of Insurance and Surety Institutions is issued.

That on December 19, 2014, the Single Insurance and Surety Circular was published in the Official Gazette of the Federation, through which the general provisions emanating from the Law of Insurance and Surety Institutions are made known, systematizing their integration and homogenizing the terminology used, in order to thereby provide legal certainty regarding the regulatory framework to which insurance institutions and mutual insurance societies, surety institutions, and other persons and entities subject to the inspection and surveillance of the National Insurance and Sureties Commission must adhere in the development of their operations.

That the globalization that the world is currently experiencing, as well as the formation of economic groups, has generated various forms or mechanisms for the commercialization of financial products, including those related to insurance and sureties.

That Article 214 of the Law of Insurance and Surety Institutions, in conjunction with Article 348 of the same legal instrument, provides that the conclusion of operations and the provision of services by insurance institutions and mutual insurance societies, as well as by surety institutions, may be agreed upon through the use of equipment, electronic, optical, or any other technology means, automated data processing systems, and telecommunications networks, whether private or public.

That in view of the foregoing, insurance institutions and mutual insurance societies, as well as surety institutions, must foresee security measures or mechanisms for the transmission, storage, and processing of information generated through electronic means, in order to provide certainty to their insured and/or sureties regarding the security of the use of electronic means, both in the conclusion of their operations and in the provision of the services they offer, as well as to prevent information provided to them from being known by third parties unrelated to the contracting or services and to prevent misuse thereof.

That in light of the above, the National Insurance and Sureties Commission has deemed it necessary to make certain clarifications to Provisions 4.10.1., 4.10.2., 4.10.3., 4.10.8. and 4.10.29. of the current Single Insurance and Surety Circular, with the purpose of establishing a regulatory framework that helps safeguard the information of insured and/or sureties in the conduct of operations through electronic means, thereby facilitating the use of electronic tools that allow easier access to such financial products by the population and their development therein, taking into account the constant technological advances that imply adapting the applicable regulations in order to be at the forefront in the forms of contracting and commercialization of insurance and sureties, without prejudice to data security.

For the aforementioned reasons, the National Insurance and Sureties Commission has resolved to issue the following modification to the Single Insurance and Surety Circular in the following terms:

AMENDING CIRCULAR 9/17 OF THE SINGLE INSURANCE AND SURETY CIRCULAR

(Provisions 4.10.1., 4.10.2., 4.10.3., 4.10.8. and 4.10.29. )

FIRST.- Provisions 4.10.1., 4.10.2., 4.10.3., and 4.10.8. of the Single Insurance and Surety Circular are modified to read as follows:

4.10.1 ...

I.

In the terms of use of Electronic Means, the following shall be established clearly and precisely:

a) to e) ...

II.

Inform their clients in advance of the contracting of the use of Electronic Means of the terms and conditions for their use, keeping such information available for consultation on the worldwide electronic network known as the Internet, updated at all times.

The terms and conditions of use of Electronic Means referred to in this fraction shall be available on the website of the Institution or Mutual Society and shall be provided in the contractual documentation with a link to the site where such information can be consulted.

III.

Include in the contractual documentation of insurance or surety products, a clause that specifies, in general terms, the client's option to use Electronic Means, in those products that have such an option, and;

IV.

Communicate to Users the risks inherent in the conduct of Electronic Operations, as well as make known to them suggestions to prevent the conduct of irregular or illegal operations that would be detrimental to the assets of the Users and of the Institution or Mutual Society, which may be carried out, among others, through periodic campaigns to disseminate security recommendations for the conduct of Electronic Operations.

4.10.2.

...

I.

They shall obtain express consent through autograph signature of their clients, prior to their identification, or through advanced or reliable electronic signature of their clients, provided that these are subject to what is established in the Code of Commerce for these purposes. In any case, some other form of manifestation of consent could be used, in the case of Mobile Electronic Operations, Internet Electronic Operations, Audio Response Electronic Operations, and Voice-to-Voice Telephone Operations;

II.

For the contracting of services and operations additional to those originally agreed upon or to modify the conditions of the service or operation originally contracted, Institutions and Mutual Societies shall require a second Authentication Factor referred to in Provision 4.10.5, in addition to the one used, if applicable, to initiate the Session in terms of Provision 4.10.8. In these cases, Institutions and Mutual Societies shall send a notification in terms of what is provided by Provision 4.10.10, providing some means to make any clarification.

Institutions and Mutual Societies shall not allow their Users to contract Electronic Operations services through Point of Sale Terminals;

III.

Regarding the operations mentioned in the previous fraction I, the contracting may be carried out in accordance with the previous fractions I and II, or through the telephone service centers of the Institutions and Mutual Societies themselves, subject to what is stated in fraction I of Provision 4.10.5, and

IV.

They shall request from their Users at the time of contracting, data of some means of communication, such as their email address or mobile phone number for the receipt of SMS Text Messages, in order for Institutions and Mutual Societies to deliver to them the notifications referred to in Provision 4.10.10.

4.10.3.

...

I.

...

II.

An Authentication Factor of at least Category 2 referred to in Provision 4.10.5.

...

...

...

4.10.8.

Institutions and Mutual Societies shall request from their Users, for the conclusion or modification of operations or provision of services through Electronic Means subsequent to the contracting of the use of Electronic Means, an additional Authentication Factor to the one used to initiate the Session in which each of the following operations and services is to be performed, considering that, when it is intended to perform any of the operations and services that require an Authentication Factor of level 3 or 4, the authentication process shall be carried out on each occasion:

I.

Contracting of life or accidental death insurance, at least level 3;

II.

Contracting of damage, accident, and illness insurance, with the exception of coverage for accidental death or a surety, at least level 2;

III.

Cancellation of an insurance or surety, at least level 2, except for life or accidental death insurance which will require a level 3;

IV.

Request, acceptance, or issuance of endorsements to contracts, at least level 2;

V.

Transfers of monetary resources to third-party accounts or other Institutions or Mutual Societies, including the payment of premiums, as well as authorizations and instructions for direct debit of premiums, at least level 3.

When the destination accounts, understood as accounts receiving monetary resources in monetary operations, have been registered in banking offices or if the User has requested that such accounts be considered as recurring destination accounts, Institutions or Mutual Societies may allow Users to perform such operations using a single Authentication Factor of at least level 2;

VI.

Modification of beneficiary designation, at least level 3;

VII.

Registration and modification of the means of notification to the User, which shall be sent to both the previous and the new means of notification, at least level 2;

VIII.

Inquiries of account statements or other inquiries that allow knowing information related to the User or the contracts they have concluded with the Institution or Mutual Society, which may be used as Authentication information, at least level 3;

IX.

Contracting of another Electronic Operations service or modification of the conditions for the use of the previously contracted service, at least level 2;

X.

Unlocking of Passwords or Personal Identification Numbers (PIN), as well as for the reactivation of the use of services regarding other Electronic Operations that they have contracted, at least level 1;

XI.

Modification of Passwords or Personal Identification Numbers (PIN) by the User, at least level 2, and

XII.

Request for payment of surrender or application of guaranteed values, at least level 3.

...

SECOND.- Provision 4.10.29. is added to the Single Insurance and Surety Circular to read as follows:

4.10.29. In the conduct of the operations referred to in this Chapter, Institutions and Mutual Societies shall comply with these Provisions, the General Provisions referred to in Article 492 of the LISF, and other applicable legal, regulatory, and administrative provisions.

TRANSITORY

SINGLE.- This Amending Circular shall enter into force as of January 1, 2018.

The foregoing is made known to you, based on Articles 366, fraction II, 372, fractions VI and XLII, 373 and 381 of the Law of Insurance and Surety Institutions.

Respectfully,

Effective Suffrage. No Re-election.

Mexico City, August 25, 2017.- The President of the National Insurance and Sureties Commission, Norma Alicia Rosas Rodríguez.- Rubric.

In the document you are viewing, there may be text, characters, or objects that do not display correctly due to conversion to HTML format, so we recommend always taking the digitized image of the DOF or the PDF file of the edition as a reference. The content, form, and scope of the published documents are the strict responsibility of their issuer.

INQUIRY

BY DATE

Do Mo Tu We Th Fr Sa

INDICATORS

Exchange Rate and Rates as of 08/29/2026

UDIS

8.809369

See more

SURVEYS

Did you like the new image of the Official Gazette of the Federation website?

No

Yes

Official Gazette of the Federation

Río Amazonas No. 62, Col. Cuauhtémoc, C.P. 06500, Mexico City Tel. (55) 5093-3200, where you can access our menu of services

Electronic address: dof.gob.mx

113

LEGAL NOTICE | SOME RIGHTS RESERVED © 2026

More like this from SHCP

SHCP published 14 documents in the last 30 days. We email you each new one the day it's published.

Share