2017-12-27 | DOF 5509090Added
These guidelines establish the procedures, formats, terms, and security measures for credit institutions to exchange information on national foreign currency and international fund transfers through the Bank of Mexico's technological platform. Institutions must obtain client consent, sign a confidentiality contract, and demonstrate compliance with strict IT security, operational risk management, and internal control requirements before accessing the Transfer Database. Authorized entities are required to maintain robust security infrastructure, conduct regular penetration testing, and restrict data access to personnel with a legitimate need for compliance and anti-money laundering purposes.
If the document is presented incomplete on the right margin, it is because it contains tables that exceed the default width. If this is the case, click here to view it correctly.
DOF: 27/12/2017
GENERAL GUIDELINES for the exchange of information between credit institutions through the technological platform operated by the Bank of Mexico regarding national fund transfers in foreign currency and international transfers in any currency, in accordance with the General Provisions referred to in Article 115 of the Credit Institutions Law.
A seal with the National Coat of Arms is placed at the margin, which reads: United Mexican States.- Ministry of Finance and Public Credit.- National Banking and Securities Commission.- Bank of Mexico.
The Bank of Mexico, based on the provisions of Articles 36 and 62, fraction I, of the Bank of Mexico Law, as well as 14 Bis, in relation to 17, fraction VI, and 15, in relation to 20, fractions IV and XI, of the Internal Regulations of the Bank of Mexico and 62nd Quater, fraction II, subsection a) of the "General Provisions referred to in Article 115 of the Credit Institutions Law", the Ministry of Finance and Public Credit, based on the provisions of Article 6, fraction XXXIV, of the Internal Regulations of the Ministry of Finance and Public Credit, as well as provision 62nd Quater, fraction II, subsection a), cited above, and the National Banking and Securities Commission, based on the provisions of Articles 4, fractions XXXVI and XXXVIII; 16, fraction I of the National Banking and Securities Commission Law, and provision 62nd Quater, fraction II, subsection a), cited above, and
CONSIDERING
That in accordance with Articles 52 and 115 Bis of the Credit Institutions Law, credit institutions may exchange information in terms of the General Provisions referred to in Article 115 of that legal framework, with the aim of strengthening measures to prevent and detect acts, omissions, or operations that could favor, provide help, assistance, or cooperation of any kind for the commission of the crimes of operations with resources of illicit origin and financing of terrorism;
That based on the above, 62nd Quater, fraction II, subsection a), of the General Provisions referred to in Article 115 of the Credit Institutions Law, provides for the authority of the Ministry of Finance and Public Credit, the National Banking and Securities Commission, and the Bank of Mexico to issue general guidelines that will be applicable to the technological platform operated by the Bank of Mexico, for the exchange of information regarding national fund transfers in foreign currency, as well as international fund transfers sent or received by credit institutions;
That the Bank of Mexico has the necessary technological infrastructure to operate the platform referred to in 62nd Quater, fraction II, subsection a), of the Provisions mentioned in the previous Consideration;
That it is necessary to establish the procedures, formats, terms and conditions of use, characteristics, infrastructure conditions, computer applications, and security measures applicable to the technological platform operated by the Bank of Mexico in accordance with 62nd Quater of the General Provisions referred to in Article 115 of the Credit Institutions Law, so that credit institutions are able to exchange information among themselves regarding their fund transfers that they send or receive on their own behalf or on behalf of their clients and users, with the object of preventing and identifying operations with resources of illicit origin;
That in order to provide the information referred to in 62nd Quater of the General Provisions referred to in Article 115 of the Credit Institutions Law to the technological platform operated by the Bank of Mexico, it is necessary to have the consent of the client or user with whom the credit institutions have a relationship;
That taking the above into account, they have seen fit to issue the following:
General Guidelines for the exchange of information between credit institutions through the technological platform operated by the Bank of Mexico regarding national fund transfers in foreign currency and international transfers in any currency, in accordance with the General Provisions referred to in Article 115 of the Credit Institutions Law
FIRST.- These General Guidelines aim to establish the procedures, formats, terms and conditions of use, as well as the characteristics, infrastructure conditions, computer applications, and security measures of the technological platform operated by the Bank of Mexico so that credit institutions provide information regarding national fund transfers in foreign currency and international transfers in any currency, that they send or receive on their own behalf or on behalf of their Clients or Users, as well as so that the institutions themselves can obtain information of this type of transfers that they send or receive on their own behalf or on behalf of their Clients or Users, in terms of 62nd Quater of the General Provisions referred to in Article 115 of the Credit Institutions Law.
The Bank of Mexico shall have the status of service provider of the platform operated in terms of the previous paragraph under the contracts it enters into for this purpose with credit institutions.
SECOND.- For the purposes of these Guidelines, the terms used herein shall have the same meanings as those included in the General Provisions referred to in Article 115 of the Credit Institutions Law. Additionally, they shall be understood in singular or plural, without this changing their meaning, as follows:
Authorities:
To the Bank of Mexico, the Commission, and the Ministry, jointly or interchangeably.
Transfer Database:
To the technological platform operated by the Bank of Mexico, for the purposes of 62nd Quater of the Provisions indicated in the first paragraph of this Guideline, regarding information on national fund transfers in foreign currency and international transfers in any currency that Entities send or receive.
Digital Certificate:
To the data message in digital format generated in terms of the Rules for operating as a Registrar Agency and/or Certification Agency in the Extended Security Infrastructure, issued by the Bank of Mexico through Circular-Telefax 6/2005, as they may be modified or substituted after their issuance.
Banking Business Day:
To the day on which Entities are not obliged to close their doors or suspend Operations, in terms of the general provisions issued for such effect by the Commission in accordance with Article 95 of the Law.
Provisions:
To the General Provisions referred to in Article 115 of the Credit Institutions Law, issued by the Ministry.
Accredited Entity:
To the Entity that, in accordance with the service provision contract it enters into with the Bank of Mexico, has access to the Transfer Database for the purposes of the Provisions.
Electronic Signature:
To that generated in accordance with the Rules for operating as a Registrar Agency and/or Certification Agency in the Extended Security Infrastructure, issued by the Bank of Mexico through Circular-Telefax 6/2005, as they may be modified or substituted after their issuance.
Transfer Form:
To the format with the fields of the data that make up the Information subject to the Transfer Database, as indicated in the Manual, which Accredited Entities must use for the delivery of the Information to said Transfer Database.
Authorized Official:
To the representative of the Accredited Entity in question that, for the purposes of 62nd Quater, fraction III of the Provisions, is registered with the Bank of Mexico to consult, on behalf of said Entity, the respective Information from the Transfer Database.
Information:
To that composed of data on national fund transfers in foreign currency and international transfers in any currency that Accredited Entities must report to the Transfer Database, as well as any other information derived from said data that the Entities themselves must consult, in accordance with the provisions of 16th, fraction IV; 25th Ter and 62nd Quater of the Provisions.
Technological Infrastructure:
To the computing, telecommunications, software, computer applications, and other tools infrastructure used by Accredited Entities to interconnect and operate the Transfer Database.
Guidelines:
To these General Guidelines.
Manual:
To the document that the Bank of Mexico issues and makes available to Accredited Entities, as well as to those Entities interested in having access to the Transfer Database, prior to celebrating the confidentiality contract referred to in the following SEVENTEENTH Guideline, which contains the technical and operational specifications for Accredited Entities to establish and maintain access to the Transfer Database, as well as the specifications for delivering and obtaining the respective Information.
THIRD.- The Entity interested in providing and consulting Information through the Transfer Database, in accordance with the Provisions, must submit a request to the Bank of Mexico via digital communication addressed to the Management of Payment Systems Operation and Business Continuity, as established in the SEVENTY-SEVENTH Guideline, which must contain the Electronic Signature of the General Director or of any official of the Entity holding a position two levels below that of the General Director, and who in any case has powers of administration or dominion.
The interested Entities, as well as those that acquire the status of Accredited Entities, must, on the one hand, keep strict confidentiality regarding all data, technical and operational specifications, and other information, including the Information subject to these Guidelines, whether expressed in oral, written, graphic, electronic, or any other form, that are provided to them by the Bank of Mexico in connection with their application for admission and, if applicable, their operation with the Transfer Database; and on the other hand, use all such data and information exclusively for the purposes provided in 62nd Quater of the Provisions. Likewise, Interested Entities and Accredited Entities shall only grant access to the information referred to those persons who necessarily need to know it to comply with 62nd Quater of the Provisions, as well as these Guidelines, and shall assume responsibility for the use made of said information by their personnel, representatives, administrators, directors, agents, employees, factors, dependents, or any person related to the Entity.
The Entities previously mentioned must maintain the confidentiality indicated, regardless of whether they acquire or lose the status of Accredited Entities.
For the purposes of the confidentiality that Entities must maintain in accordance with the above, prior to submitting the request referred to in the first paragraph of this Guideline, the interested Entity must enter into a unilateral confidentiality contract with the Bank of Mexico, signed by one of the representatives indicated in the first paragraph of this Guideline, in terms of the clauses that the Bank of Mexico, through the Management of Payment Systems Operation and Business Continuity, makes available to interested Entities.
The interested Entity must accompany the request it submits to the Bank of Mexico, in accordance with this Guideline, with a report signed by the head of its internal audit area stating that the Entity complies with the requirements provided in the FOURTH Guideline, according to the review that said head has carried out for this purpose, in terms of these Guidelines and the Manual.
FOURTH.- The Entity submitting the request referred to in the previous Guideline must demonstrate to the Bank of Mexico that it fully complies with the requirements in the matters indicated below, in terms of the specifications established in the Manual.
Regarding this, the Entity mentioned must consider and include in the policies and procedures it is obliged to follow to comply with the aforementioned requirements, the following:
A.
In matters of IT security:
That the area that the Entity maintains to perform information security functions verifies that the administration and operation of the Technological Infrastructure is carried out in accordance with the corresponding IT security policies and procedures.
That the Entity ensures and maintains the robustness of the Technological Infrastructure, for which it must establish and follow, at least, the following procedures:
a)
Those for evaluating the communication protocols used in the Technological Infrastructure and discarding those considered insecure in accordance with what is specified in the Manual.
b)
Those that contemplate the mandatory use of tools that allow detecting computer viruses and malicious code in the Technological Infrastructure, as well as those that allow periodic updating of said tools in accordance with what is specified in the Manual.
c)
Those that allow identifying and mitigating IT security vulnerabilities derived from changes, updates, or errors in the Technological Infrastructure, among other factors.
d)
Those that inhibit the installation of any service, application, or software that is not indispensable for the operation between the Transfer Database and the Technological Infrastructure.
e)
Those that allow detecting and managing IT security incidents in the Technological Infrastructure, which in turn allow identifying what type of incidents they are, as well as containing, collecting, and properly safeguarding IT security evidence for notification to the risk committee and the internal audit area of the Entity referred to in the General Provisions applicable to credit institutions, issued by the Commission.
f)
Those for evaluating, at least every two years, the IT security of the Technological Infrastructure, which include the performance of penetration tests by an independent third party specialized in this matter. To this effect, the Entity must prepare a report establishing the technological risk level to which it is subject, as well as the formulation of a documented work plan to address the risks that the Entity itself categorizes as vulnerabilities, understood as those risks that could affect the security and business continuity of its Technological Infrastructure, based on a technological and operational risk analysis.
That for the implementation of the Entity's computer systems used to consult Information, whether by the Entity itself or by an external specialized company in computer software development, they include, at least, the following procedures:
a)
Those that ensure that a formal and documented development process is followed for the implementation of its computer systems. Such development process must consider, at least, the following stages:
i.
Design and development of computer systems.
ii.
Validation of functionalities, purpose, capacity, and quality of computer systems.
iii.
Implementation of computer systems.
iv.
Formal follow-up to changes in computer systems.
b)
Those that ensure that IT security aspects are considered during the different stages of its development process.
c)
Those that ensure that the components providing security to its computer systems are valid in accordance with the terms and deadlines established in the Manual.
d)
Those that allow the security of computer systems to be reviewed statically through source code analysis, as well as dynamically through evaluation of the code in execution.
e)
Those that allow monitoring, auditing, and tracking accesses and activities carried out by different users of computer services regardless of the privilege level established for their access and the communication medium or protocol. These procedures must consider safeguarding the collected information for a period of at least 12 months.
f)
Those that allow monitoring, auditing, and tracking all activity carried out through the Technological Infrastructure to consult Information. These procedures must consider safeguarding the collected information for a period of at least 12 months.
That allow the Entity to securely handle Information stored electronically and that include, at least, the following procedures:
a)
Those that ensure that when discarding or decommissioning physical components or devices (hardware) of the Technological Infrastructure, all Information they contained becomes unrecoverable.
b)
Those that allow restricting access to physical connection ports and peripheral devices of the Technological Infrastructure.
c)
Those established for safeguarding Information of the Technological and operational infrastructure.
d)
Those that allow detecting the alteration or falsification of Information contained in the Technological Infrastructure.
e)
Those that allow encrypting sensitive Information in the Technological Infrastructure.
That the Entity implements access control mechanisms to the Technological Infrastructure, considering, at least, the procedures established for:
a)
The implementation of robust logical access mechanisms and controls to the Technological Infrastructure.
b)
Allowing user and password management.
c)
Allowing manual and automatic locking of the Technological Infrastructure to ensure that equipment can only be used by authorized personnel.
d)
Allowing the management of access privileges to the Technological Infrastructure.
e)
Auditing accesses and activities carried out by users of the Technological Infrastructure. These procedures must consider safeguarding the collected information for a period of at least 12 months.
That the Entity communicates with the Bank of Mexico securely and efficiently, considering the following:
a)
Allowing the management of a telecommunications network that favors said communication with the Bank of Mexico and restricts access to Information.
b)
Restricting Internet access from the Technological Infrastructure.
B.
In matters of operational risk management:
That the methodology for operational risk management developed by the Entity contemplates that, in the operation with the Transfer Database, the identification and evaluation of said risk is considered, as well as the implementation of controls to mitigate it.
That hiring and training requirements ensure that personnel related to the operation of the Transfer Database has the skills, competencies, and knowledge required for the position they hold.
That it has procedure manuals and operation manuals with the Transfer Database, describing, at least, the automatic and semi-automatic processes described in subsections a) to e) of this section, indicating the positions and functions of the personnel responsible for executing the activities of said processes, including those with access to the Information of the Transfer Database:
a)
For obtaining Information reported through the Transfer Form, including the process for informing cancellations.
b)
For consultation in the Transfer Database, including the frequency of consultation.
c)
For handling Information obtained from the Transfer Database.
d)
For monitoring and supporting the operation of the Accredited Entity with the Transfer Database.
e)
Those related to obtaining the consent of Clients or Users to carry out the consultation of their Information.
That it has a list of risks identified in the operation of the Transfer Database and their respective controls. In said list, the Entity must include, at least, human, technological, process, and external factors, including those associated with suppliers.
That it has guidelines for the management of physical access controls to operational sites where the operation of the Transfer Database is carried out and to data centers hosting the Technological Infrastructure.
C.
In matters of internal controls of information flows from areas dedicated to preventing operations with resources of illicit origin and financing of terrorism to business areas:
That the Entity ensures the proper use of Information obtained through consultations to the Transfer Database, considering, at least, the following:
a)
Establish an organizational structure that ensures that personnel having access to the Information of the Transfer Database is exclusively that which requires it for the use provided in 16th, fraction IV; 25th Ter and 62nd Quater of the Provisions; such personnel must always be that which is assigned in the areas of the Entity where the functions of audit, risk management, regulatory compliance, or those specialized areas in data analysis susceptible to be exchanged for the purposes of the Provisions, or those areas of information technology, or those areas in charge of the official referred to as Compliance Officer referred to in the Provisions, that, for the performance of their functions, are related to the prevention and detection of acts, omissions, or operations that could favor, provide help, assistance, or cooperation of any kind for the commission of the crimes provided for in Articles 139 Quater or 400 Bis of the Federal Penal Code or other crimes against the clientele or the Entity itself, and require having
access to such Information. In all cases, the Compliance Officer must approve the personnel who will have access to the Information.
b)
Have operational procedure manuals that explicitly include:
i.
The indication of personnel with access to the Information and the prohibition of granting access to the Information to personnel external to the Entity, with the exception of service providers referred to in GUIDELINE FIFTH, which will be subject to what is provided in fraction I, subsection d), of the aforementioned Guideline.
ii.
The obligation for the Entity's personnel to maintain strict confidentiality of the Information.
iii.
The prohibition of using the Information for purposes other than those provided in the 16th, fraction IV; 25th Ter and 62nd Quáter of the Provisions.
D.
In matters of certification of the Technological Infrastructure that Accredited Entities will use to consult the Transfer Database and the connection scheme with the Bank of Mexico's systems established for this purpose, the Entity must comply with the technical specifications included in the Manual, as well as with the following requirements:
Accredit that the computer applications that the Entity will use in relation to the connectivity schemes with the Bank of Mexico's systems, indicated in subsections a) and b) of this section, comply with the consultation protocol of the Transfer Database established for this purpose by the Bank of Mexico in accordance with the technical specifications indicated in the Manual, and that they relate to the following schemes:
a)
Web Service.
The Entity may connect to the web service that the Bank of Mexico makes available to it for the consultation of transactional statistical Information.
b)
Web Application.
The Entity may consult transactional statistical Information through the web application that the Bank of Mexico develops for this purpose.
Validate that it can operate with the Technological Infrastructure that, if applicable, the Bank of Mexico has implemented for the operation of the Transfer Database in contingency cases.
The Entity must implement the connection scheme indicated by the Bank of Mexico to connect with it and consult the Transfer Database, in accordance with what is established in the Appendix of the Manual titled "Connection Scheme with Bank of Mexico".
FIFTH.- The Entity interested in having access to the Transfer Database, as well as any Accredited Entity, may agree with third parties on the provision of computer services for the connection and operation that the respective Entity must establish with the Transfer Database, in accordance with what is provided in GUIDELINE FOURTH, section A, section 3, provided that the Bank of Mexico has previously expressly manifested its acceptance regarding the terms and conditions established by said Entity for the provision of these services, according to the request that, for this purpose, the Entity or the Accredited Entity must present to it, through the Business Continuity and Operations Management of the Payment Systems.
In the event that the Bank of Mexico has not notified its resolution regarding the aforementioned request within a period of 45 Banking Business Days after the one in which it was presented or, if applicable, after the one in which the Entity has delivered the information required by the Bank of Mexico in connection with said request, it will be understood as denied.
Together with the request referred to in the previous paragraph, the Entity or the Accredited Entity must provide, regarding the third party with which it intends to agree on the provision of the respective service, the documentation and information indicated below:
I.
Draft contract or legal instrument that it intends to celebrate with the third party, in which, on the one hand, this expressly manifests its will, regarding the services subject to contracting, to unconditionally subject itself to these Guidelines and the Manual applicable to it, as well as to all those obligations to which the Entity or the Accredited Entity is subject related to the contracted service, and, on the other hand, the applicable conventional penalties are included, as well as, in an enumerative and non-limiting manner, the following obligations on the part of the third party:
a)
Allow the Bank of Mexico's personnel to carry out visits to the offices and other installations, including reviews of that third party's equipment to verify compliance with the applicable requirements referred to in these Guidelines and the Manual.
b)
Provide the Bank of Mexico with the information it requests within the timeframes it indicates.
c)
Allow the Entity or the Accredited Entity that hired it, as well as an independent third party specialized hired by said Entity or Accredited Entity, to carry out the corresponding reviews and audits and that, for this purpose, have access to their facilities and equipment, and provide them with the books, system codes, records, manuals and documents and information in general related to the provision of the service.
d)
Keep confidentiality regarding the data, specifications and other information related to the technical aspects of the operation of the Transfer Database, including the Information subject to these Guidelines to which, due to the nature of its functions, it has access, as well as the information that, in accordance with applicable legislation, must be treated as confidential and that it obtains as part of the activities it carries out under the contract or legal instrument it celebrates with the Entity or the Accredited Entity.
e)
Have, if applicable, security standards that comply with what is established in the Manual.
f)
Refrain from subcontracting or delegating in any way to another third party the performance of the services it provides to the Entity or Accredited Entity.
II.
That which records the approval of the board of directors of the Entity or the Accredited Entity, in which it must be stated that:
a)
The contracting of the services offered by the third party does not put at risk the compliance with the applicable provisions to the Entity or to the Accredited Entity regarding its operation in the Transfer Database and the use of the Information in terms of the Provisions.
b)
The third party's business practices, according to the review carried out for this purpose, are consistent with the operation of the Entity or the Accredited Entity.
III.
Documents that accredit the third party's experience, technical capacity and sufficiency of human resources regarding the services subject to contracting.
IV.
The procedure that the third party offers to the Entity or to the Accredited Entity to identify, measure, monitor, limit, control, report and disclose the risks that may arise from the provision of its services.
V.
The mechanisms for the resolution of disputes, agreed upon between the Entity or the Accredited Entity and the third party, regarding the contract or legal instrument they have celebrated.
VI.
The procedure to evaluate the third party's performance in the provision of services and the compliance with its contractual obligations.
VII.
The document that describes the actions that the parties will carry out for the orderly termination of the service provision contract, in the event that it is suspended and it is not possible to immediately replace the third party to continue carrying out the corresponding services.
VIII.
Any other documentation, information and certifications that the Bank of Mexico requests from the Entity or the Accredited Entity in relation to the compliance with these Guidelines and the Manual.
SIXTH.- In the event that an Entity or the Accredited Entity intends to celebrate a contract with any third party contemplated in the previous Guideline and this is going to provide the respective service wholly or partially outside the national territory, in addition to the requirements established in said Guideline, the aforementioned Entities must:
I.
Accredit that the third party maintains its principal place of business and that it will provide the respective service in a country whose national legal system provides protection to personal data under principles substantially similar to those provided by Mexican legislation, or that it maintains in force international agreements celebrated with the Mexican State in matters of personal data protection, and that, in any case, the exchange of information with competent foreign authorities is allowed.
II.
Additionally provide, in the record of the board of directors' approval referred to in fraction II of GUIDELINE FIFTH, that there will be no impact on the operational continuity of the Entity or the Accredited Entity in its operation with the Transfer Database, due to the geographical distance and, if applicable, the language that will be used in the provision of the service.
III.
Have technical support schemes that allow solving problems and incidents, regardless of the differences that, if any, exist in time zones and business days.
Additionally, in the event that any authority of the third party's country of origin referred to in this Guideline requires information related to the services it provides to the Entity or to the Accredited Entity, it must, as soon as it is legally possible, inform said Entity or Accredited Entity thereof, as well as provide it with a copy of the information it has delivered to said authority.
In this case, the Entity or the Accredited Entity must inform the Business Continuity and Operations Management of the Payment Systems of the Bank of Mexico of such situation immediately after having knowledge of it, as well as provide it with a copy of the referred information, so that the Bank of Mexico itself informs, if applicable, the competent Mexican authority.
SEVENTH.- The documentation referred to in GUIDELINES FIFTH and SIXTH must remain, at all times, available to the Bank of Mexico, at the domicile of the Entity or of the Accredited Entity, without prejudice to the latter's faculty to require the Entities and the Accredited Entities to deliver that information and documentation necessary in relation to the operation in the Transfer Database in accordance with these Guidelines and the Manual.
The Bank of Mexico must previously manifest its acceptance to the Entity or to the Accredited Entity regarding any modification to the contract or legal instrument that it intends to celebrate with the third party, according to the request that, for this purpose, it presents to it through a communication prepared in accordance with GUIDELING TWENTY-SEVENTH and addressed to the Business Continuity and Operations Management of the Payment Systems of the Bank of Mexico.
In the event that the Bank of Mexico has not notified its resolution regarding the aforementioned request within a period of 45 Banking Business Days after the one in which it was presented or, if applicable, after the one in which the Entity has delivered the information required by the Bank of Mexico in connection with said request, it will be understood as denied.
Likewise, the Entity or the Accredited Entity must inform the Business Continuity and Operations Management of the Payment Systems of the Bank of Mexico regarding any reform to the third party's corporate purpose or modifications to its internal organization, which may affect the provision of the service, at least five Banking Business Days in advance before these take place, in accordance with what is established in GUIDELING TWENTY-SEVENTH.
In the event that the documentation referred to in GUIDELINES FIFTH and SIXTH is in a language other than Spanish, it must be presented to the Bank of Mexico together with its corresponding duly legalized translation, when so requested.
EIGHTH.- The Entity or the Accredited Entity will be responsible at all times for the services provided by third parties, even when these are carried out under terms different from those agreed. Likewise, the Entity or the Accredited Entity will be responsible for the actions of said third parties that result in non-compliance with these Guidelines, the Manual or any other applicable provision in the operation with the Transfer Database. The foregoing will proceed without prejudice to the civil, administrative or penal liabilities in which said third parties may incur for violations of applicable legal provisions.
What is stated in this Guideline must be expressly provided for in the contract or legal instrument celebrated by the Entity or Accredited Entity and the third party.
NINTH.- The Accredited Entity must suspend the service provided by the third party when it notices changes in its operation that may affect the compliance with these Guidelines, the Manual, or when it identifies or has knowledge of the non-compliance by the third party with the applicable regulations, as well as with the obligations referred to in FIFTH of these Guidelines.
Regardless of what is stated in the previous paragraph, the Accredited Entity must inform the Bank of Mexico, through a communication prepared in accordance with what is established in GUIDELING TWENTY-SEVENTH and addressed to the Business Continuity and Operations Management of the Payment Systems, about the suspension or termination of the service provision by the third party, the causes that motivated it, as well as the actions that are being carried out for the continuity of its operation, at least thirty natural days prior to the date of suspension or termination of the service provision.
TENTH.- The Entities must provide the Bank of Mexico with the documentation and carry out the execution of tests that it requires them, in addition to that documentation that they deliver as part of the report referred to in GUIDELINE THIRD, to accredit compliance with the information security, operational risk management and internal information flow control requirements related to their operation with the Transfer Database, provided for in these Guidelines and in the Manual.
ELEVENTH.- Once the Bank of Mexico has determined that the requesting Entity complies with the technical and operational requirements provided for in these Guidelines and in the Manual to have access to the Transfer Database, it will notify it thereof, in order for them to celebrate the service provision contract whose object is to carry out the operation of the respective Entity with the Transfer Database, in terms of the Provisions and these Guidelines, as well as to establish the applicable consideration.
For the celebration of the contract referred to in the previous paragraph, the Entity in question must communicate to the Operations Instrumentation Management of the Bank of Mexico the name of the legal representatives who will sign said instrument, as well as provide a simple copy of their respective official identifications and a certified copy of the public deed in which the powers granted to said persons, by the Entity in question, to exercise acts of administration or of domain are recorded.
TWELFTH.- The Accredited Entity must verify, in successive periods of two years, the compliance that said Entity gives to the requirements established in GUIDELINE FOURTH. Such verification must be carried out by the internal audit area of the Accredited Entity itself and by an independent specialized third party, through alternating reviews that one of them carries out in one of the referred periods and the other in the immediate next period. The Accredited Entity must present to the Bank of Mexico, through the Business Continuity and Operations Management of the Payment Systems, the result of the corresponding review through a report that must be prepared in terms of what is indicated for this purpose in the Appendix of the Manual titled "General Characteristics of the Report on the Evaluation of Compliance with the Requirements to Operate with the Transfer Database" and that, if applicable, indicates the actions that the Accredited Entity must follow to comply with the observed requirements.
The report referred to in the previous paragraph must be presented during the month of March and must cover the verification of the compliance of the Accredited Entity's obligations as of the last Banking Business Day of the month of January of the review period that corresponds. The Accredited Entity must present the first report contemplated in this Guideline at the end of the period of seven hundred twenty natural days from the signing of the contract referred to in GUIDELINE ELEVENTH. In the event that the day of the conclusion of this last period does not correspond to a Banking Business Day, the report must be presented on the immediate next Banking Business Day.
THIRTEENTH.- The Accredited Entity must register its Authorized Officials with the Bank of Mexico. To this effect, it must present to the Bank of Mexico, through a digital communication prepared in accordance with what is established in GUIDELING TWENTY-SEVENTH and addressed to the Business Continuity and Operations Management of the Payment Systems, a registration request in the terms established in the Manual which must be recorded in a digital communication, containing the Electronic Signature of the representative of the Accredited Entity in question who has powers of administration or of domain, that said Entities make known to the Bank of Mexico, through the Operations Instrumentation Management. In all cases, each Accredited Entity must verify and keep record that each of the persons it designates as Authorized Officials complies with the following:
I.
Be attached to the area of the Entity in charge of the official designated as Compliance Officer referred to in the Provisions, or that it be attached to any other area of the Entity where the functions of audit, or risk management, or regulatory compliance, or those specialized areas in data analysis susceptible to be exchanged for the purposes of the Provisions fall, and that the referred Compliance Officer has approved their designation as Authorized Official.
II.
Have a valid Digital Certificate, during the period in which it retains the status of Authorized Official, issued in its name.
III.
Have a certificate of non-existence of records of penal convictions in the federal realm, referred to as a criminal record certificate, issued by the Disaggregated Administrative Body for Prevention and Social Readaptation, of the Ministry of the Interior, with an issuance date not greater than one year prior to its designation as Authorized Official.
IV.
Not have been disqualified from holding a job, position or commission in the Mexican financial system, according to the information published by the Commission and other supervisory commissions of financial entities.
V.
Not have been previously designated as an Authorized Official and have its respective registration annulled for being in the situation mentioned in fraction II of GUIDELING FIFTEENTH.
The registration referred to in this Guideline will take effect from the date on which the Bank of Mexico notifies the respective Accredited Entity of the execution of said registration.
FOURTEENTH.- Each Accredited Entity must have at all times, at least, two Authorized Officials, each of whom will be responsible for signing, through an Electronic Signature supported by their respective Digital Certificate, the consultation requests for Information to the Transfer Database on behalf of the respective Accredited Entity.
In the event that, for any cause, the Accredited Entity has fewer than two Authorized Officials, it must designate who or who should assume that status, in a maximum period of five Banking Business Days following the one in which the corresponding vacancy was generated.
Without prejudice to what is stated above, in the months of February to March of each year, the Accredited Entity must confirm to the Bank of Mexico if the registered Authorized Officials continue with that status, as well as the update of their data in accordance with what is established in the Manual, through a digital communication prepared in accordance with what is established in GUIDELING TWENTY-SEVENTH and addressed and delivered to the Business Continuity and Operations Management of the Payment Systems of the Bank of Mexico. In the event that, at the end of the month of March, an Accredited Entity has not carried out the confirmation of its Authorized Officials in accordance with this paragraph, the Bank of Mexico, without prior notification to the Accredited Entity, will annul the respective registration, at the latest on the tenth Banking Business Day of the following month of April, without prejudice to the fact that the Accredited Entity in question may request the registration of the respective Authorized Official or Officials again, in accordance with GUIDELING THIRTEENTH.
FIFTEENTH.- The Accredited Entity must request the Bank of Mexico to annul the registration of the persons it has designated as Authorized Officials, by presenting to the Business Continuity and Operations Management of the Payment Systems a digital communication prepared in accordance with what is established in GUIDELING TWENTY-SEVENTH and in the terms established in the Manual.
In all cases, Accredited Entities are obliged to request the annulment of the registration of their Authorized Officials, within a period not greater than one Banking Business Day counted from the date on which:
I.
The Authorized Official terminates their labor relationship with the Accredited Entity or ceases to exercise the functions as such;
II.
The Accredited Entity detects that the Authorized Official has been involved in some incident by which sensitive information related to the operation of the Transfer Database could be compromised, or
III.
The Accredited Entity has knowledge that the person designated as Authorized Official ceases to comply with the requirements provided for in GUIDELING THIRTEENTH.
The Bank of Mexico will remove the Authorized Official referred to in this Guideline from its respective system, at the latest, on the second Banking Business Day following the one in which the request was presented in accordance with the terms established in the Manual.
Likewise, the Bank of Mexico may remove the Authorized Officials registered by the Accredited Entity to consult the Transfers Database if the Accredited Entity does not confirm to the Bank of Mexico the validity and update of the Authorized Officials, as established in the third paragraph of Guideline FOURTEENTH. This is without prejudice to the conventional penalties that correspond according to the respective contract.
SIXTEENTH.- Accredited Entities will report their respective Information to the Transfers Database in the schedule indicated in the Manual, on the same Banking Business Day as the sending or receipt of the fund transfers subject to such Information, following the specifications to generate the Transfers Form, available through the system managed by the Bank of Mexico specified in the Manual or any other electronic or computing means that the Bank of Mexico makes known for these effects.
Regarding the transfers that Accredited Entities send on behalf of a Client or User, they must identify them as the respective originator.
Accredited Entities will not be obligated to report to the Transfers Database the Information corresponding to fund transfers carried out through a payment system operated by the Bank of Mexico. In this case, the Bank of Mexico will carry out the loading of the Information referred to in this paragraph, on behalf of the respective Accredited Entities, according to the notification thereof made to them, in accordance with the 62nd Quater, fraction IV, of the Provisions.
In all cases, Accredited Entities must verify that the Information they report to the Transfers Database is authentic and complies with the specifications detailed in the Manual.
Regarding fund transfers that Accredited Entities have sent or received after the opening of the Information sending schedule through the system managed by the Bank of Mexico specified in the Manual or on a day other than a Banking Business Day, such Accredited Entities must send the report of the corresponding Information no later than the next Banking Business Day, to that on which they sent or received the fund transfers in question.
Accredited Entities that have omitted to report Information on the corresponding dates as indicated in this Guideline must do so as soon as possible, without prejudice to the penalties or sanctions that may apply to them.
SEVENTEENTH.- In the event that Accredited Entities need to correct erroneous, imprecise, or incomplete Information they have provided to the Transfers Database, they must request the Bank of Mexico, through the Payment Systems Attention Center, to rehabilitate the form corresponding to the day on which the fund transfer in question was carried out, in order for it to be sent again with the corrected Information.
The provisions of this Guideline will not exempt Accredited Entities from the conventional penalties or sanctions that may apply to them.
EIGHTEENTH.- In the event that any fund transfer reported to the Transfers Database has been cancelled, the Accredited Entities involved in such operation must inform the Business Continuity and Operations Management of the Payment Systems of the Bank of Mexico no later than the next Banking Business Day after the cancellation was carried out, as well as accompany the explanation of the causes that occasioned it. The respective Accredited Entities must prepare the referred report according to the cancellation format specified in the Manual so that the data on such fund transfer are eliminated from the Transfers Database.
Accredited Entities must preserve evidence of the fund transfers they have cancelled, as well as the causes thereof, for a period of at least five years.
NINETEENTH.- Accredited Entities must send Information reports to the Transfers Database in accordance with what is provided in Guidelines SIXTEENTH, SEVENTEENTH, and EIGHTEENTH, and with the specifications indicated in the Manual.
In the event that an Accredited Entity does not report the required Information in accordance with the terms established in these Guidelines, the Bank of Mexico may, in its case, in accordance with the clauses established for this effect in the contract referred to in these Guidelines, impose a program of corrective actions that the Accredited Entity must observe to remedy errors or inconsistencies, without prejudice to other corrective measures, as well as penalties or sanctions, that any of the Authorities may impose in the exercise of their respective powers.
TWENTIETH.- Accredited Entities will consult the statistical Information of the fund transfers reported to the Transfers Database, as well as other general data on such transfers corresponding to their Clients or Users in the circumstances and for the effects referred to in the Provisions, in accordance with the technical and operational specifications established for this effect in the Manual.
At the beginning of each Information consultation, Authorized Officials must authenticate themselves using Digital Certificates and the user identifier provided to them by the Bank of Mexico. The following will be observed in the consultations referred to in this Guideline:
I.
Consultation Scheme.
Accredited Entities may consult the statistical aggregates indicated in the Chapter of the Manual titled "Client or User Transactional Statistical Indicators," relating to the Information of their Clients or Users at the banking system level updated to the immediate previous Banking Business Day under the consultation schemes, whose specifications are detailed in the Manual.
II.
Information to Consult.
When Accredited Entities carry out Information consultations, they may obtain from the Transfers Database, for each of their Clients or Users who have sent or received at least one national foreign currency or international fund transfer in any currency, the statistical Information and other general data specified in the Chapter of the Manual titled "Client or User Transactional Statistical Indicators." This Information will consider the fund transfers that such person has carried out through all national credit institutions during the last 360 natural days prior to the day the consultation is carried out. The Information will be updated each Banking Business Day with the Information from the immediate previous Banking Business Day.
TWENTY-FIRST.- Accredited Entities must have the consent of their Clients or Users to be able to provide and consult their Information, under the terms established in the Provisions.
TWENTY-SECOND.- When an Accredited Entity identifies any discrepancy between the Information it must report and the Information stored in the Transfers Database, it must notify this fact to the Payment Systems Attention Center of the Bank of Mexico, immediately, by telephone, to the number indicated in the Manual, and subsequently, confirm the foregoing without delay through a digital communication prepared in accordance with what is established in Guideline TWENTY-SEVENTH and addressed to the Business Continuity and Operations Management of the Payment Systems of the Bank of Mexico.
TWENTY-THIRD.- In the event that any event occurs that affects the operations of the Transfers Database or puts its integrity and security at risk, the Bank of Mexico may:
I.
Suspend the connection to such Accredited Entities as it deems convenient to prevent such affectation.
II.
Restrict access to consultations to the Transfers Database of one or more Authorized Officials.
III.
Instruct any Accredited Entity to suspend consultations to the Transfers Database.
IV.
Determine schedules different from those indicated for consultation to the Transfers Database, which will be made known to Accredited Entities through the Payment Systems Attention Center of the Bank of Mexico or another means available to the Bank of Mexico at that time.
V.
Indicate some contingency procedure that the Accredited Entity must carry out.
TWENTY-FOURTH.- In the event that any event occurs that affects the operation of an Accredited Entity with the Transfers Database or this detects any irregularity in such operation, and the duration of said event or irregularity is greater than thirty consecutive minutes, or if it relates to any unauthorized intrusion in the information technology systems of the Accredited Entity or unauthorized theft of its information, the Accredited Entity must notify the Bank of Mexico by telephone to the Payment Systems Attention Center and confirm this fact, through a digital communication prepared in accordance with what is established in Guideline TWENTY-SEVENTH and addressed to the Business Continuity and Operations Management of the Payment Systems of the Bank of Mexico, according to the procedure that this establishes in the Manual for this effect.
The communication referred to in the previous paragraph must be sent within sixty minutes after the event arises or the referred irregularity is detected, in which the date and time of the start of the event or irregularity must be indicated, the indication of whether these continue or have concluded and their duration, the affected processes, as well as a description of the event or irregularity observed.
Additionally, in the event that the Accredited Entity identifies any imminent threat to the general operation of the Transfers Database, such as, among others, the presence of malicious codes, attacks or unauthorized instructions to the Technological Infrastructure related to its operation with the Transfers Database, the commission of acts linked to possible frauds or the unauthorized theft of its Information, when this could affect the operation that the Accredited Entity carries out in particular with the Transfers Database, it must carry out the notification of these facts to the Bank of Mexico immediately upon detection, by telephone to the Payment Systems Attention Center and, subsequently, through a communication in the terms established in the first paragraph of this Guideline.
TWENTY-FIFTH.- For Accredited Entities to maintain their access to the Transfers Database, they must comply with the requirements established in Guideline FOURTH and others applicable. For these effects, in accordance with the 62nd Quater, fraction II, last paragraph, of the Provisions, without prejudice to the supervisory powers of the Commission, the Bank of Mexico may carry out the verifications it deems appropriate, according to the contracts referred to in Guideline ELEVENTH, in order to determine that Accredited Entities comply with these Guidelines, for which the latter must allow the Bank of Mexico to practice such verifications.
For the purposes of what is stated in the previous paragraph, the Bank of Mexico may carry out the following acts as part of the verification of compliance with these Guidelines:
I.
Information Requirements. Require Accredited Entities information regarding their operation with the Transfers Database, including the equipment, systems, computer programs and other elements with which it has in relation to such operation.
II.
Requirement of certification by independent third party. Require Accredited Entities opinions, evaluations and other reports prepared by an independent third party, which must comply with the characteristics established in the Manual, regarding audits carried out with respect to such Accredited Entity in relation to compliance with these Guidelines.
III.
Inspection Visit. Carry out inspections in the facilities, offices, branches, equipment and information and communication technology systems of Accredited Entities and, during their development, conduct interviews with their employees or officials as it deems convenient or necessary.
TWENTY-SIXTH.- In the event that the Bank of Mexico proves any non-compliance with these Guidelines by an Accredited Entity, it may require it to present a program of corrective actions that it obligates itself to carry out to remedy the referred non-compliance.
Likewise, in the event that an Accredited Entity fails to comply with what is established in these Guidelines or in the respective contract, puts at risk the correct functioning of the Transfers Database or the integrity of the Information contained therein or, in its case, fails to follow a program of corrective actions, the Bank of Mexico, without prejudice to other conventional penalties or sanctions that may apply to it, may, after hearing the referred Accredited Entity:
I.
Suspend the operation of such Accredited Entity with the Transfers Database. For such effects the Bank of Mexico will suspend the operation when it determines that the non-compliance could put at risk the correct functioning of the Transfers Database or the security of the Information contained therein.
II.
Rescind the contract entered into with the Accredited Entity to operate with the Transfers Database in accordance with these Guidelines.
TWENTY-SEVENTH.- Entities and Accredited Entities must send the communications referred to in Guidelines THIRD, SEVENTH, NINTH, THIRTEENTH, FOURTEENTH, FIFTEENTH, TWENTY-SECOND and TWENTY-FOURTH by email addressed to the Payment Systems Attention Center of the Bank of Mexico in accordance with what is established in the Manual.
Each of the communications must, in all cases, contain the Electronic Signature of the person who must sign it in accordance with what is established for this effect by the respective Guideline. In all cases, the persons who sign the referred communications must be previously registered in the catalog of personnel authorized by the Accredited Entity to carry out the management of operations and various requests with the Bank of Mexico, according to the procedure that this establishes for this effect in the Manual. When the Guidelines cited in the previous paragraph do not indicate the persons who must electronically sign the respective communications, these must contain the Electronic Signature of the persons registered in the catalog of personnel that the Accredited Entity authorizes to carry out the management of operations and various requests to operate with the Bank of Mexico, according to the procedure that this establishes for this effect.
It is the responsibility of Accredited Entities to keep the catalog referred to in the previous paragraph updated at all times.
The persons who sign the communications in terms of this Guideline must:
I.
Have a valid Digital Certificate issued in their name.
II.
Sign the communications digitally using the tool that the Bank of Mexico determines for these purposes and makes known to Accredited Entities in accordance with what is provided in the Manual, as well as the Digital Certificate referred to in fraction I of this Guideline.
In cases where the Accredited Entity does not have access to the necessary elements to send digitally signed requests, it may deliver to the Business Continuity and Operations Management of the Payment Systems of the Bank of Mexico, the respective communications in original, in duplicate, and signed by persons whose signature has been previously registered before the aforementioned Management for the management of operations and various requests to operate with the Bank of Mexico, adding a communication in which it specifies the reason why it sees itself in the need to send communications by this alternative means.
TWENTY-EIGHTH.- The Accredited Entity may request the Bank of Mexico, through the Business Continuity and Operations Management of the Payment Systems, the early termination of the service provision contract that has as its object the use of the Transfers Database. The mentioned request must be presented in writing to the referred Management, at least, one Banking Business Day in advance of the date on which the Accredited Entity intends for the termination of the contract to take effect.
TWENTY-NINTH.- The Authorities, jointly, may interpret, for administrative purposes, what is established in these Guidelines.
TRANSITORY
FIRST.- These Guidelines will enter into force the day following their publication in the Official Gazette of the Federation.
SECOND.- In accordance with the transitory provision Seventh of the resolution that reforms, adds and repeals various of the Provisions, published in the Official Gazette of the Federation on February 24, 2017, Entities must begin to report the Information on international fund transfers they send in any currency starting from the tenth Banking Business Day following the publication of these Guidelines. Without prejudice to the foregoing, those Entities that comply with what is provided in the Provisions may begin to report the information referred to in this paragraph from the day of the publication of these Guidelines. Likewise, Entities must begin to consult the Information on their Clients and Users starting from sixty-five Banking Business Days following the publication of these Guidelines.
THIRD.- The obligation of Accredited Entities to report the Information of international fund transfers in any currency received will enter into force on November 30, 2018.
FOURTH.- The obligation of Accredited Entities to report operations carried out in their own name and on their own account in terms of these Guidelines will enter into force on November 30, 2018.
Mexico City, November 27, 2017. - For the Ministry of Finance and Public Credit: the Secretary, José Antonio González Anaya. - Signature. - National Banking and Securities Commission: the President, Jaime González Aguadé. - Signature. - Bank of Mexico: the Governor, Agustín Guillermo Carstens Carstens. - Signature.
In the document you are viewing, there may be text, characters or objects that are not displayed correctly due to conversion to HTML format, so we recommend always taking the digitized image of the DOF or the PDF file of the edition as a reference. The content, form and scope of published documents are the strict responsibility of their issuer.
INQUIRY
BY DATE
Su Mo Tu We Th Fr Sa
INDICATORS
Exchange Rate and Rates as of 08/29/2026
UDIS
8.809369
See more
SURVEYS
Did you like the new look of the Official Gazette of the Federation website?
No
Yes
Official Gazette of the Federation
Río Amazonas No. 62, Col. Cuauhtémoc, C.P. 06500, Mexico City Tel. (55) 5093-3200, where you can access our service menu
Electronic address: dof.gob.mx
113
LEGAL NOTICE | SOME RIGHTS RESERVED © 2026