2025-06-23 | DOF 5760800Added · Updated
The National Banking and Securities Commission amends Articles 207, 287 Bis, and 287 Bis 1, as well as Annexes 12-E, 12-F, and 36 of the general provisions for credit institutions. The changes require two distinct authentication factors for non-presence electronic increases in user transaction limits, mandate additional authentication for internet banking operations exceeding those limits, and update reporting requirements for monetary claims under Series R27. These modifications also adjust fraud management plan guidelines and information disclosure obligations regarding alerts generated in the 30 days preceding an unrecognized operation. The resolution enters into force the day following its publication in the Official Gazette.
If the document appears incomplete on the right margin, it is because it contains tables that exceed the default width. If this is the case, click here to view it correctly.
DOF: 23/06/2025
AMENDING RESOLUTION of the "Resolution that modifies the General Provisions applicable to credit institutions, published on June 14, 2024"
A seal with the National Coat of Arms appears at the margin, which says: United Mexican States.- Treasury.- Ministry of Finance and Public Credit.- National Banking and Securities Commission.
The National Banking and Securities Commission, based on articles 52, eighth paragraph; 96 Bis, first paragraph; 98 Bis and 101 Bis of the Credit Institutions Law; as well as 4 fractions II, V, XXXVI and XXXVIII; 6; 16, fraction I and 19 of the National Banking and Securities Commission Law and,
CONSIDERING
That on June 14, 2024, the "Resolution that modifies the General Provisions applicable to credit institutions" was published in the Official Gazette of the Federation, with which the internal control of credit institutions in matters of fraud was strengthened and a legal framework was established to determine observable behaviors for fraud management, their scope and obligations, providing legal certainty to credit institutions and to the National Banking and Securities Commission itself, by having a regulatory framework that strengthens supervision in matters of prevention, detection and timely response to the presence of observable behaviors for fraud management;
That as a result of said Amending Resolution and various consultations made by institutions to this Commission, some technical aspects were identified that require adjustment in order to provide greater certainty in compliance with the new obligations;
That, it is necessary to adjust the regulatory report " A-2701 Monetary Claims " contained in Series R27 of Annex 36, Annex 12-E " Minimum Guidelines for the Fraud Prevention Management Plan " and Annex 12-F " On the information that institutions must make available to the User or the Commission derived from Monetary Claims " , in order for credit institutions to be able to comply with the aforementioned obligations, it has resolved to issue the following:
AMENDING RESOLUTION OF THE " RESOLUTION THAT MODIFIES THE GENERAL PROVISIONS APPLICABLE TO CREDIT INSTITUTIONS, PUBLISHED IN THE OFFICIAL GAZETTE OF THE FEDERATION ON JUNE 14, 2024 "
SOLE.- Article 207 is REFORMED, the reference to the " Series R27 Monetary Claims " and its report " A- 2701 Monetary Claims " ; in Annex 12-E, fraction II, subsection c), second paragraph; in Annex 12-F, fraction III, subsection f); article 287 Bis, third paragraph and article 287 Bis 1 and it is SUBSTITUTED from Annex 36, the " Series R27 Monetary Claims " of the Resolution that modifies the General Provisions applicable to credit institutions, published in the Official Gazette of the Federation on June 14, 2024, to read as follows:
AMENDING RESOLUTION OF THE " RESOLUTION THAT MODIFIES THE GENERAL PROVISIONS APPLICABLE TO CREDIT INSTITUTIONS, PUBLISHED IN THE OFFICIAL GAZETTE OF THE FEDERATION ON JUNE 14, 2024 "
" Article 207.-
...
Series R01 Minimum Catalog to Series R26 Information by commission agents ...
Series R27 Claims A-2701 Claims Series R28 Operational Risk Information to Series R36 Advance Payments and Deferred Charges ...
...
... "
" Article 287 Bis.-
...
...
Institutions must allow their Users to modify the User's Transaction Amount via Electronic Means in a non-presential manner or through signature at Bank Branches. When the modification is carried out via Electronic Means in a non-presential manner to increase the User's Transaction Amount, such modification will require at least two Authentication Factors referred to in article 310 of these provisions, which must be of different categories. Once the User's Transaction Amount is modified, it will take effect once the Institution sends an alert to the User of the modification indicated in this paragraph through instant messaging with encrypted communication protocols, telephone call or email with encrypted communication protocols, and the latter confirms the referred action. In the case that the modification to increase the User's Transaction Amount in a non-presential manner is carried out through services other than Mobile Banking, the Authentication Factors referred to in this paragraph may be substituted by a confirmation of modification through Mobile Banking services, prior to the new User's Transaction Amount taking effect.
...
... Article 287 Bis 1.- When the amount of a Monetary Operation carried out through Internet Banking, Voice-to-Voice Telephone Banking, Audio Response Telephone Banking and Mobile Banking services is greater than the User's Transaction Amount, Institutions must request an additional Authentication Factor to those established in these provisions for the Monetary Operation in question, referred to in Article 310 of these provisions, requested or provided through instant messaging with encrypted communication protocols, telephone call or email with encrypted communication protocols. In the case that the Monetary Operation is carried out through services other than Mobile Banking, the additional Authentication Factor referred to in this paragraph may be substituted by a confirmation of celebration of the Monetary Operation through Mobile Banking services, prior to execution. "
TRANSITORY
SOLE.- This Resolution will enter into force the day following its publication in the Official Gazette of the Federation.
Respectfully
Mexico City, June 12, 2025.- President of the National Banking and Securities Commission, Dr. Jesús de la Fuente Rodríguez .- Rubric.
" Annex 12-E
Minimum Guidelines for the Fraud Prevention Management Plan
...
...
I .
..
II .
...
a) and b) ...
c)
...
The information resulting from alerting systems will form part of the evidence referred to in subsection f), fraction III of Annex 12-F of these provisions. Likewise, institutions must implement processes with the objective of protecting Users' resources when the referred alerts are presented, such as recommending to the User the change of passwords, change of Authentication Factors, if applicable, among others, whose methodology must be documented in this plan.
d) to f) ...
III .
..
...
... "
" Annex 12-F
On the information that institutions must make available to the User or the Commission derived from Monetary Claims
...
I .
..
II .
..
III .
...
a) to e) ...
f)
A summary of the alerts generated in the last 30 days prior to the date on which the unrecognized operation was performed, by the Institution's systems, associated with the User's accounts, whether or not relative to the Monetary Operation associated with the Monetary Claim. In case there are no alerts in said period, it must be stated.
g) to i) ...
IV
...
V
...
... "
" ANNEX 36
Regulatory Reports
INDEX
...
SERIES R01 MINIMUM CATALOG to SERIES R26 INFORMATION BY COMMISSION AGENTS
...
SERIES R27 CLAIMS
This series is integrated by one (1) report, whose frequency of preparation and presentation must be monthly.
REPORT
A-2701
Claims
This report requests information on User Claims derived from active operations, passive or acquiring services, specifying the transactional channel of the operation. Likewise, the report considers information regarding the data on the management of User Claims. For purposes of this report, a claim shall be understood as all those monetary operations not recognized by the User and who have communicated so to the Institution through any channel or means placed at their disposal.
CAPTURE FORMAT
Institutions will carry out the sending of information related to the A-2701 Claims report described above, by using the following capture format:
REQUESTED INFORMATION
REPORT IDENTIFIER SECTION
PERIOD
INSTITUTION KEY
REPORT
CLAIM DATA SECTION
CLAIM FILE NUMBER
CLAIM DATE
ORIGIN OF THE CLAIM
DATE OF INCIDENT
FEDERAL ENTITY WHERE THE CLAIM ORIGINATED
MUNICIPALITY OR ALCADEIA WHERE THE CLAIM ORIGINATED
CLIENT RFC
CLIENT CURP
INDIVIDUAL OR LEGAL PERSON
ACCOUNT NUMBER/CREDIT CARD NUMBER/DEBIT CARD NUMBER/TPB NUMBER
PERSON IN SITUATION OF VULNERABILITY
USER TRANSACTION AMOUNT
USE OF AUTHENTICATION FACTOR AND CATEGORY
USE OF AUTHENTICATION FACTOR AND CATEGORY WHEN EXCEEDING THE USER TRANSACTION AMOUNT
PRODUCT
IDENTIFIER OF INSTITUTION, COMMISSION AGENT OR MERCHANT WHERE THE OPERATION IS PERFORMED
ACQUIRER NAME IN CASE OF POS OPERATIONS
CHANNEL IN WHICH THE TRANSACTION WAS MADE
REASON FOR THE CLAIM
TRANSACTION WITH CONTACTLESS PAYMENT TECHNOLOGY
CLAIM AMOUNT
STATUS OF THE CLAIM
RESOLUTION DATA SECTION
RESOLUTION
RESOLUTION DATE
CAUSE OF RESOLUTION
AMOUNT CREDITED TO CLIENT
DATE OF CREDIT TO CLIENT
AMOUNT RECOVERED
MEANS BY WHICH THE AMOUNT WAS RECOVERED
LOSS FOR THE INSTITUTION
FRAUD MANAGEMENT OBSERVABLE BEHAVIOR
Institutions will report the information indicated in this series, which must comply with the validations and quality standards indicated by the Commission, adjusting to the characteristics and specifications that, for purposes of filling out and sending information, are presented in the filling instructions, which are published and updated in SITI or in that, if applicable, made known by the Commission. Once the validations and quality standards are met, SITI will generate an electronic receipt.
The information must be sent only once and will be received assuming it meets all characteristics and specifications, by virtue of which it cannot be modified and must present consistency with the various reports in which the same information is included with a different level of integration, therefore, if it does not meet the required quality and characteristics or has been presented incompletely, the obligation to present it will be considered unfulfilled and, consequently, the corresponding sanctions will be imposed in accordance with the legal provisions that apply.
SERIES R28 OPERATIONAL RISK INFORMATION to SERIES R36 ADVANCE PAYMENTS AND DEFERRED CHARGES
... "
In the document you are viewing, there may be text, characters or objects that do not display correctly due to conversion to HTML format, so we recommend always taking the digitized image of the DOF or the PDF file of the edition as reference. The content, form and scope of published documents are the strict responsibility of their issuer.
CONSULT
BY DATE
Su Mo Tu We Th Fr Sa INDICATORS
Exchange Rate and Rates as of 23/08/2026
UDIS
8.805888
See more SURVEYS
Did you like the new look of the Official Gazette of the Federation website?
No Yes Official Gazette of the Federation
Río Amazonas No. 62, Col. Cuauhtémoc, C.P. 06500, Mexico City Tel. (55) 5093-3200, where you can access our service menu Electronic address: dof.gob.mx
111 LEGAL NOTICE | SOME RIGHTS RESERVED © 2026
More like this from SHCP
SHCP published 14 documents in the last 30 days. We email you each new one the day it's published.