2017-01-12 | DOF 5468963Added
The document establishes general provisions for securities depository institutions, mandating that financial statements be prepared under IFRS or Mexican financial reporting standards and audited by independent external auditors. It requires monthly submission of financial statements within twenty days and annual statements within sixty days of the fiscal year-end. The rules define eligible service recipients, prohibit exclusivity in contracts with foreign institutions, and impose strict requirements for outsourcing, including segregation of assets and legal convertibility of currencies. Additionally, institutions must implement technological controls, business continuity plans, and equitable conduct policies to prevent conflicts of interest and ensure operational resilience.
DOF: 12/01/2017
GENERAL PROVISIONS APPLICABLE TO SECURITIES DEPOSITORY INSTITUTIONS
A seal bearing the National Coat of Arms, which reads: United Mexican States.- Ministry of Finance and Public Credit.- National Banking and Securities Commission.
The National Banking and Securities Commission, based on articles 279 and 280, fractions I, subsection b) and II of the Securities Market Law; as well as 4, fractions III, XXXVI and XXXVIII, 16, fraction I and 19 of the National Banking and Securities Commission Law,
AND CONSIDERING
That the Securities Market Law establishes the authority of the National Banking and Securities Commission to issue provisions applicable to securities depository institutions regarding internal controls, risk management, prevention of conflicts of interest, corporate practices and auditing, transparency and equity regarding the services they offer, and that it is therefore necessary to strengthen the secondary regulatory framework applicable to these financial entities to ensure the best performance in the provision of their services for the benefit of the securities market as a whole;
That on the other hand, it is opportune to provide that securities depository institutions have the necessary measures to prevent possible conflicts of interest, as well as expressly establish the obligation for said institutions to provide equitable treatment in the conduct of their activities and in the provision of their services in order to grant unrestricted equality of treatment among participants in the securities market in order to promote transparency and foster a deeper securities market;
That additionally, it is deemed convenient to provide for the controls, policies and procedures that securities depository institutions must have so that their computer systems incorporate the necessary mechanisms to support their processes and carry out their operations and the provision of their services securely and efficiently;
That in this vein, it is essential to point out a series of measures that securities depository institutions must implement in order to ensure the continuity of their critical operations in contingency situations that hinder or disable the conduct of their operations and the provision of their services, as well as incorporating rules relating to both the identification of possible sources of risk of said contingencies, and the strategies to be established to respond to them, considering the lessons learned from emergency situations in Mexico and other countries, and
That it is opportune to issue a single legal instrument containing the provisions applicable to securities depository institutions, systematizing their integration and homogenizing the terminology used, in order to thereby provide legal certainty regarding the regulatory framework to which said institutions must adhere in the development of their operations, which will also facilitate consultation, compliance and observance of the provisions applicable to them, for which reason the norms pertaining to the services that securities depository institutions may contract with foreign credit institutions or foreign securities depository institutions are also included, as well as the rules relating to the disclosure and presentation of financial information, has resolved to issue the following:
GENERAL PROVISIONS APPLICABLE TO SECURITIES DEPOSITORY INSTITUTIONS
FIRST TITLE General Provisions
Sole Chapter Definitions
SECOND TITLE On Financial Information
Sole Chapter On Financial Information in General
THIRD TITLE On the Provision of Services
Chapter I On the characteristics of the entities, institutions and persons to whom securities depository institutions may provide their services
Chapter II On the services that securities depository institutions may contract with foreign credit institutions or foreign securities depository institutions
Chapter III On Business Conduct
FOURTH TITLE On Prudential Provisions
Chapter I On the Administration and Control of Technological Infrastructure
Chapter II On the Business Continuity Plan
Chapter III On the Management of Treasury Liquidity
Chapter IV Additional Regulation
Annex 1 Minimum Requirements of the Business Continuity Plan.
FIRST TITLE General Provisions
Sole Chapter Definitions
Article 1.- For the purposes of these provisions, the following shall be understood:
I. Commission: the National Banking and Securities Commission.
II. Operational Contingency: any event that hinders, disables or prevents a securities depository institution from providing the services or carrying out the activities referred to in article 280 of the Law.
III. Technological Infrastructure: the computing infrastructure, telecommunications networks, operating systems, databases, software and applications used by securities depository institutions to support their operations.
IV. Law: the Securities Market Law.
V. Business Continuity Plan: the set of strategies, procedures and actions referred to in article 26 of these provisions that allow for the continuity in the provision of services or in the realization of critical processes of securities depository institutions in the face of Operational Contingencies or their timely restoration, as well as the mitigation of the effects resulting from said contingencies.
VI. Registry: the National Securities Registry referred to in the Law.
SECOND TITLE On Financial Information
Sole Chapter On Financial Information in General
Article 2.- The financial statements of securities depository institutions shall be prepared in accordance with one of the following options:
I. International Financial Reporting Standards "International Financial Reporting Standards" issued by the International Accounting Standards Board "International Accounting Standards Board".
II. Financial Reporting Standards recognized and issued by the Mexican Council for Financial Reporting Standards, A.C.
Article 3.- The financial statements referred to in the preceding article shall be audited by an independent external auditor based on the International Standards on Auditing "International Standards on Auditing" issued by the International Auditing and Assurance Standards Board "International Auditing and Assurance Standards Board" of the International Federation of Accountants "International Federation of Accountants".
The Commission may establish additional requirements that external audits must satisfy, taking into account the particular problems presented by the securities depository institution.
Article 4.- Securities depository institutions shall submit to the Commission, within twenty natural days of each month, the financial statements corresponding to the immediately preceding month, signed by the general director and the head of the finance area or their equivalent.
Article 5.- Securities depository institutions shall submit to the Commission, no later than a period of sixty natural days following the closing of their fiscal year, the annual financial statements signed by the general director and the head of the finance area or their equivalent, accompanied by the opinion of the independent external auditor.
THIRD TITLE On the Provision of Services
Chapter I On the characteristics of the entities, institutions and persons to whom securities depository institutions may provide their services
Article 6.- Securities depository institutions may provide their services, in addition to the persons established in article 280, fractions I and II of the Law, to the following:
I. Those institutions of foreign nationality responsible for the deposit, custody, administration, clearing, settlement and transfer of securities, which have automated systems for the management of securities, both locally and internationally.
II. Foreign stock exchanges.
III. Other entities whose statutes expressly identify in their object the provision of any of the services of deposit, custody, administration, clearing, settlement or transfer of securities.
Article 7.- The persons referred to in the preceding article must be constituted and organized in accordance with the laws of the country in which they are domiciled, have authorization for the conduct of their activities and be subject to the inspection and supervision of an authority that performs functions similar to those of the Commission.
Article 8.- Securities depository institutions must verify that the persons referred to in article 6 of these provisions meet the characteristics set forth in the preceding article 7, prior to the signing of the contract in which the legal relationship between them is formalized. It shall be the responsibility of securities depository institutions that the corresponding contracts comply with the legal, regulatory and administrative provisions governing their operation.
Article 9.- Securities depository institutions, in addition to providing the services of deposit, custody, administration, clearing, settlement and transfer of securities registered in the Registry in favor of national or foreign financial entities, in accordance with the Law, may provide their services to:
I. Societies that manage electronic trading mechanisms for shares of investment funds authorized by the Commission in accordance with the provisions of article 40, fourth paragraph of the Investment Funds Law, provided that securities depository institutions only open accounts in favor of said societies on behalf of third parties.
II. Trusts that act as clearing houses for derivative contracts in terms of the "Rules to which participants in the derivative contracts market must adhere" issued by the Ministry of Finance and Public Credit, the Bank of Mexico and the Commission and published in the Official Gazette of the Federation on December 31, 1996 and their respective modifications.
Article 10.- When any security is cancelled from the international quotation system established by the stock exchanges referred to in the Law, securities depository institutions may continue to provide their services with respect to the securities in question, but in no case shall they admit new deposits of the same securities while these are not listed again in the said system.
As an exception to what is stated in the preceding paragraph, securities depository institutions may only accept new deposits when such increase derives from a payment of rights in kind decreed by the issuer or from a corporate event.
Article 11.- Securities depository institutions, on the day they become aware of it, must provide to the stock exchanges simultaneously and through electronic means that leave irrefutable proof, the information related to the exercise of property rights derived from foreign securities listed in the international quotation system established by the stock exchanges and with respect to which the securities depository institutions themselves are provided with the services of deposit, which must include the payment of dividends or distributions, increases or decreases in share capital or the number of securities, among others. For the purposes of complying with the foregoing, securities depository institutions may enter into contracts with information providers, foreign credit institutions or foreign securities depository institutions, in which said entities are obligated to deliver sufficient and timely information related to the exercise of property rights of the securities listed in said international quotation systems.
The information that securities depository institutions make public regarding the exercise of property rights of foreign securities listed in the international quotation system established by the stock exchanges will depend exclusively on the information provided by the aforementioned entities. This is without prejudice to the responsibility of securities depository institutions for any error, omission or delay in the delivery of information to the stock exchanges, for causes attributable to said institutions, including failures or interruptions in their information systems.
Without prejudice to the foregoing, when securities depository institutions have elements to consider that the information provided to them presents discrepancies, they will proceed in accordance with the terms established by said institutions in their internal regulations.
Article 12.- Securities depository institutions must publish on their Internet page the updated catalog of types of securities on which they provide their services of deposit, custody, administration, clearing, settlement and transfer and keep it updated, informing the Commission, stock exchanges, securities market intermediaries, price providers and clearing houses for derivative contracts, central counterparties for securities and other market participants simultaneously, at least thirty business days in advance.
Chapter II On the services that securities depository institutions may contract with foreign credit institutions or foreign securities depository institutions
Article 13.- Securities depository institutions may contract the services of deposit, custody, administration, clearing, settlement and transfer of securities that they have deposited, as well as the provision of other services inherent to the functions that are proper to them, including services related to the provision of information regarding the exercise of property rights of foreign securities listed in the international quotation system established by the stock exchanges, both with foreign credit institutions and with foreign securities depository institutions, that offer said services and that meet the characteristics established in these provisions.
In the contracts entered into by securities depository institutions with the institutions referred to in the preceding paragraph, exclusivity agreements may not be established.
Article 14.- Foreign credit institutions and foreign securities depository institutions that enter into contracts with securities depository institutions must be constituted and organized in accordance with the laws of the country in which they are domiciled, have authorization for the conduct of their activities and be subject to the inspection and supervision of a specialized authority.
Article 15.- Securities depository institutions may only contract the services of the institutions referred to in the preceding article 14, provided that the latter have automated systems for the centralized management of securities.
Article 16.- Securities depository institutions must review the audited financial statements of foreign credit institutions and foreign securities depository institutions corresponding to each fiscal year, during the period in which they maintain securities on deposit in said institutions, in order to corroborate their financial strength, as a condition for the signing and, if applicable, for the validity of the contract.
Article 17.- Securities depository institutions, for the celebration of a contract with a foreign credit institution or a foreign securities depository institution, must verify that the following requirements are met:
I. That the contracts to be entered into contemplate the following obligations:
a) The conduct of external audits, as well as the obligation to deliver to securities depository institutions the audited financial statements during the term of the contract.
b) The definition of procedures that allow for the delivery or replacement of securities to securities depository institutions, in the event that the foreign credit institution or the foreign securities depository institution in question enters into a commercial bankruptcy or liquidation, or equivalent, or if they are lost, stolen or destroyed.
c) The legal prohibition that the custodied securities can be taken by the foreign credit institution or the foreign securities depository institution in question or by their creditors to cover any type of right, debt, judicial claim or encumbrance and the existence of systems that prevent this from occurring.
II. The existence of a legal provision to the effect that the securities of clients custodied under the contract to be entered into remain adequately segregated with respect to the assets of the foreign credit institution or the foreign securities depository institution in question.
III. The existence of a legal provision relating to the existence of a regime for the free convertibility of currencies in the country in which the foreign credit institution or the foreign securities depository institution in question is domiciled.
IV. The accreditation of adequate performance of the foreign credit institution or the corresponding foreign securities depository institution, in accordance with the criteria established by securities depository institutions in their internal regulations for such purposes.
V. The security, transparency, efficiency and automation in the provision of services of the foreign credit institution or the foreign securities depository institution in question.
Article 18.- Securities depository institutions, in contracting the services referred to in article 13 of these provisions, must enter into a service provision contract with the foreign credit institution or the foreign securities depository institution in question, with the responsibility of the former that said contract complies with the legal, regulatory and administrative provisions governing their operation.
Article 19.- Securities depository institutions must submit to the Commission the contracts they intend to enter into under this Chapter, as well as their respective modifications, ten business days in advance of the date of their celebration, accrediting compliance with these provisions and specifying the reasons on which the choice of the institution in question was based. The Commission itself may object to the said contracts or their modifications, within the period referred to in this article, when they do not comply with or contravene what is established in this legal order and other applicable provisions.
Article 20.- Securities depository institutions must transfer the securities they have deposited in a foreign credit institution or a foreign securities depository institution to another institution that meets the requirements provided for in this Chapter, when in their judgment there is risk to the security of the deposited securities, of the securities depository institutions themselves or of their depositors.
Chapter III On Business Conduct
Article 21.- Securities depository institutions must establish, prior to the approval of their board of directors with the favorable vote of the majority of the independent directors, the necessary measures to prevent conflicts of interest that could arise in relation to their depositors and other market participants to whom they offer their services.
Article 22.- Securities depository institutions must establish the same conditions, as well as an unrestricted treatment of equality among and for the depositors and other participants in the securities market to whom they offer their services. Additionally, they must ensure efficient communication and connection with them, including the availability and equality of information that, if applicable, may be disseminated to the respective participants in the market.
Additionally, securities depository institutions must ensure that their computer systems allow for efficient communication and connection with the persons referred to in the preceding paragraph, adhering, in the event of Operational Contingencies, to what is established in the Business Continuity Plans established for such effect.
FOURTH TITLE On Prudential Provisions
Chapter I On the Administration and Control of Technological Infrastructure
Article 23.- Securities depository institutions must elaborate, document and implement the policies and procedures necessary so that the Technological Infrastructure they use to carry out their processes and provide their services, complies with the following:
I. Each element of the Technological Infrastructure performs at all times the functions for which it was designed, developed or acquired.
II. Include controls that allow equitable and timely access for all users in accordance with what each of them will perform in the computer systems to which they have access.
III. Have documented processes, functionalities and configurations, including their development or acquisition methodology, as well as records of their changes and the inventory of all elements of the Technological Infrastructure.
IV. Incorporate aspects of information security and a mechanism for project control of each element of the Technological Infrastructure during the various stages of the lifecycle,
considering the development of requirements, design, development or acquisition, implementation testing, release processes, periodic testing, change management, replacement and destruction of information. These security aspects shall include, at least:
a) Logical and physical segregation of the different networks into distinct domains depending on the function they perform or the type of data transmitted.
b) Secure configuration according to the type of element, considering at least, ports, services, permissions, access lists, manufacturer updates and factory configuration.
V. Each element of the Technological Infrastructure is tested before being implemented or when modified, using quality control mechanisms that prevent the use of real production environment data in such tests, the disclosure of sensitive or security information, or the introduction of any functionality not recognized for said element.
VI. Have the necessary licenses or use authorizations.
VII. Contain strict security measures for the access and use of information that is transmitted, stored and processed in the Technological Infrastructure that supports it, considering at least the following:
a) Identification and authentication mechanisms for all and each of the users of the Technological Infrastructure of the securities depository institutions that allow them to be recognized unequivocally and ensure access only to persons expressly authorized for that purpose. Both mechanisms must include specific controls for those users with greater privileges, derived from their functions, such as those for database and operating system administration.
b) Allow the segregation of functions through the establishment of user profiles that limit access only to the functionality of the Technological Infrastructure and information required, based on the responsibilities and powers of each user's position.
c) Information encryption mechanisms according to the degree of sensitivity determined by the securities depository institutions, when such information is transmitted or stored.
d) Robust composition of passwords and access keys.
e) Control of unattended sessions, as well as simultaneous sessions with the same user identifier.
f) Security mechanisms, both physical and environmental and electrical power, that protect and allow operation in accordance with the specifications of the supplier, manufacturer or developer of each element of the Technological Infrastructure of the securities depository institutions.
VIII. Minimize the risk of operational interruption based on backup mechanisms and information recovery procedures, as well as of the Technological Infrastructure and alternative means for information exchange, in accordance with Article 26 of these provisions.
IX. Maintain audit records, including detailed information of accesses and the operation or activity carried out by users, that prevent repudiation, regardless of the level of privileges they have for access, generation or modification of the information they receive, generate, store or transmit in each element of the Technological Infrastructure, as well as the procedures for periodic review of said records.
X. Contemplate the carrying out of tests aimed at detecting vulnerabilities and threats, as well as penetration in the different elements of their Technological Infrastructure, in order to implement defense mechanisms that prevent unauthorized access and use thereof. Such tests shall be carried out at least once a year or when they make substantive modifications to any element of the Technological Infrastructure.
XI. Reaction and security incident management processes that ensure the detection, classification, attention, investigation, diagnosis, reporting to competent hierarchical levels, solution, follow-up and communication of said incidents.
XII. Have planning exercises that allow measuring the capacity of the Technological Infrastructure that supports their operation, defined by the securities depository institutions themselves, as well as that adhere to the results of said exercises regarding the needs for capacity increase.
XIII. Contemplate automated controls that minimize the risk that user personnel commit errors or omissions in the manual or semi-automated processes they must perform in the applications of the Technological Infrastructure.
XIV. Allow the detection of alteration or falsification of records in the Technological Infrastructure.
XV. Implement mechanisms that measure and ensure levels of availability and response times, which guarantee the execution of operations and services performed.
Article 24.- Securities depository institutions shall establish and implement information classification and treatment policies and procedures, according to the degree of risk that such information implies and which will be determined by each of its operational areas. Such classification shall be used to evaluate and implement the necessary controls in the Technological Infrastructure and in the operational processes, in order to ensure the confidentiality, integrity and availability of the information of the securities depository institutions and of the participants.
Article 25.- Securities depository institutions shall designate a person to serve as information security officer, who must enjoy independence with respect to the operational, administrative, audit and systems areas, and shall be in charge of, at least, the functions mentioned below:
I. Authorize and monitor access to the institution's computer systems for the securities depository, including that used for the storage, processing and transmission of information, according to the profile corresponding to each type of user.
II. Participate in the definition of security policies and procedures, mentioned in Article 23 of these provisions.
III. Review at least quarterly, or earlier in case of security events or incidents, the activities carried out by users and by service providers in the different elements of the Technological Infrastructure of the securities depository institutions, including technical personnel who have high privileges, such as operating system and database administration.
IV. Verify the implementation and continuous compliance of information security policies and procedures in the Technological Infrastructure of the securities depository institutions, including, at least, those included in Article 23 of these provisions.
Securities depository institutions shall ensure that the information security officer has at their disposal the records of persons who have access to information related to the operations in which the securities depository institutions themselves are involved, including those of those located abroad and of users who have high privileges, such as operating system and database administration, as well as their service providers.
Chapter II
Of the Business Continuity Plan
Article 26.- Securities depository institutions shall prepare action and contingency plans to restore their operation in the event of an Operational Contingency, which shall be included in the Business Continuity Plan. Such plans shall be consistent with the criticality of the business processes and with the business impact analysis referred to in fraction I of Annex 1 of these provisions.
Article 27.- The general manager of the securities depository institutions shall prepare the Business Continuity Plan observing what is established in Annex 1 of these provisions. Said plan and its modifications shall be submitted for approval by the board of directors through the audit committee.
The general manager shall be responsible for:
I. The implementation, as well as the continuous updating and dissemination of the Business Continuity Plan within the securities depository institution. To this effect, they shall establish a program to train personnel on the actions they will take in the event of an Operational Contingency, as well as during the development of the plan itself.
II. Design and carry out a communication policy regarding the verification of Operational Contingencies, which shall be part of the Business Continuity Plan. Such policy shall provide for immediate communication with its clients, central securities counterparties and with the different administrative and business units within the securities depository institution itself, as well as with the Commission and other competent authorities in attention to the nature of the contingency in question.
III. Provide for what is necessary to make known to the Commission and the Bank of Mexico the Operational Contingencies that occur in any of its systems or channels of attention to its clients, authorities and central securities counterparties.
In the notice referred to in this fraction, at least the date and time of start of the Operational Contingency, the indication of whether it continues or has concluded and its duration, as well as a description of the event that has been registered, shall be indicated.
Likewise, the general manager shall send to the Commission and the Bank of Mexico within a period not greater than fifteen calendar days following the conclusion of the Operational Contingency, the description of said contingency, an analysis of the causes that motivated it, the impact caused in qualitative and quantitative terms, the processes, systems and channels affected, as well as a work plan indicating the detail of the actions that will be implemented to minimize the impact or damage in similar subsequent situations and the dates on which each of them will be fulfilled.
IV. Ensure that the Business Continuity Plan is subjected to effectiveness tests at least once a year, in which the participants in the securities market related to each of the processes to be evaluated are included, and made known to its personnel. Likewise, they shall ratify it in its terms or update it, at least once a year, according to what is determined for this purpose by the board of directors itself or as a result of the effectiveness tests.
In any case, for the performance of the responsibilities referred to in this article, the general manager may be assisted by the personnel they determine, in which case they shall make it known to the Commission within a period not greater than five business days from their designation, maintaining at all times an adequate segregation of functions that avoids conflicts of interest.
Article 28.- Securities depository institutions shall have a methodology to estimate the quantitative and qualitative impacts of Operational Contingencies, which shall be used in the impact analysis referred to in Annex 1, fraction I, subsection d) of these provisions, which shall have the prior approval of the board of directors.
The audit committee shall annually verify the effectiveness of the methodology by comparing its estimates against the observed Operational Contingencies and, if applicable, shall carry out the necessary corrections.
The audit committee shall inform the board of directors, the Commission and the Bank of Mexico of the results of the effectiveness tests and of the evaluation of the scope of the Business Continuity Plan, of its adequate dissemination among the pertinent areas and of the identification, if applicable, of the necessary adjustments for its updating and strengthening. Such report shall be made at least once a year or earlier if relevant results are detected.
Chapter III
Of the administration of treasury liquidity
Article 29.- Securities depository institutions may invest their treasury surpluses in the following securities:
I. Investments in securities issued or guaranteed by the United Mexican States, as well as those issued by the Bank of Mexico whose maturity term does not exceed one year.
II. Investments in bank deposits of demand money and debt securities issued by credit institutions that have a minimum rating of AA, on a national scale, granted by any securities rating agency and whose maturity term does not exceed one year.
III. Investments in shares representing the social capital of investment funds in debt instruments with daily liquidation.
Chapter IV
Additional Regulation
Article 30.- Securities depository institutions, without prejudice to what is provided in these provisions, shall be subject, insofar as applicable, to the general provisions issued by the Commission and, if applicable, to their modifications, which are listed below:
I. General rules for the integration of files containing the information that accredits the compliance with the requirements that persons performing jobs, positions or commissions in financial entities must satisfy, published in the Official Journal of the Federation on March 1, 2002.
II. General provisions applicable to the international quotation system, published in the Official Journal of the Federation on December 18, 2003.
III. General provisions applicable to the entities and persons referred to in Articles 3, fractions IV, V, VI, VII and VIII, and 4, fraction XXX, of the Law of the National Banking and Securities Commission as well as to the General Public, in the delivery and receipt of documents at the National Banking and Securities Commission, published in the Official Journal of the Federation on October 5, 2011, modified by Resolution published in the same Journal on December 22, 2015.
IV. General provisions that regulate self-correction programs, published in the Official Journal of the Federation on October 20, 2014.
V. General provisions applicable to securities operations carried out by councilors, executives and employees of financial entities and other obligated persons, published in the Official Journal of the Federation on November 4, 2014.
VI. General provisions applicable to investment funds and to the persons who provide them with services, published in the Official Journal of the Federation on November 24, 2014.
VII. General provisions that indicate the days of the year, in which the financial entities subject to the supervision of the Commission, shall close their doors and suspend operations, published in the Official Journal of the Federation for each fiscal year.
TRANSITORY PROVISIONS
FIRST.- These Provisions shall enter into force the day following their publication in the Official Journal of the Federation, except for what is provided in the following transitory articles.
SECOND.- Securities depository institutions shall have the same period referred to in the last paragraph of the Third Transitory Article of the "General Provisions applicable to the international quotation system" issued on December 13, 2016 to provide the stock exchanges with the information related to the exercise of rights referred to in Article 11, second paragraph of these provisions.
THIRD.- Securities depository institutions shall have the periods indicated in the following fractions, counted from the publication of this instrument in the Official Journal of the Federation to comply with the provisions indicated below:
I. Six months for compliance with Article 25 of Chapter I of Title IV of these Provisions.
II. Twelve months for compliance with Chapter II of Title IV of this instrument.
III. Eighteen months for compliance with Articles 23 and 24 of Chapter I of Title IV of this instrument.
FOURTH.- Upon the entry into force of these Provisions, the "General Provisions applicable to securities depository institutions", published in the Official Journal of the Federation on January 18, 2011, and reformed by resolutions published in the said Journal on March 16, 2011 and December 22, 2015, shall be repealed.
Respectfully,
Mexico City, January 6, 2017. - The President of the National Banking and Securities Commission, Jaime González Aguadé. - Rubric.
Annex 1
Minimum Requirements of the Business Continuity Plan
I. Securities depository institutions, prior to the development of the Business Continuity Plan, shall carry out a business impact analysis that:
a) Includes all services, processes and participants, identifying those critical ones that are considered indispensable for the continuity of operations, among which they shall include at least those necessary to carry out the activities foreseen in Article 280 fractions I to V,
VII and IX of the Law.
b) Determines the minimum resources (human, logistical, material, technological infrastructure and any other nature) necessary to maintain and restore the services and processes of the securities depository institutions in the event of an Operational Contingency, as well as at the end of it.
c) Elaborates relevant scenarios regarding possible Operational Contingencies, considering, at least, the following:
i. Natural and environmental disasters.
ii. Infectious diseases.
iii. Cyberattacks or computer activity attacks.
iv. Sabotage.
v. Terrorism.
vi. Interruptions in energy supply.
vii. Failures or unavailability in technological infrastructure (application functionality, telecommunications, information processing and networks).
viii. Unavailability of human, material or technical resources.
ix. Interruptions occurring in services provided by third parties.
d) Estimates the quantitative and qualitative impacts of Operational Contingencies, based on the scenarios defined for each process and through the methodology referred to in Article 28 of these provisions.
e) Defines the recovery priority for each of the processes.
f) Determines the recovery time objective (known as RTO, by its initials in English), for each of the services and processes. Regarding the services and processes related to the activities indicated in fractions I to V, VII and IX of Article 280 of the Law, it shall not be greater than sixty minutes counted from the time the securities depository institutions identify the Operational Contingency, being obliged to contemplate the provisions within their reach to comply with said recovery time objective.
g) Considers that the recovery point objective (known as RPO, by its initials in English) understood as the maximum tolerable data loss for each of the services and processes, considering that the information of those operations already concluded cannot be lost in any scenario, and that the state that each concluded operation had at the moment the Operational Contingency occurred must be known in a timely manner.
h) Identifies and evaluates risks related to operational processes and data processing and transmission services contracted with providers, as well as those related to custody and safeguarding of information of the securities depository institution or its clients.
i) Determines the risks derived from the geographic location of the main data processing centers and of the operation of the processes identified as critical according to subsection a) of this fraction, to avoid that the alternative data processing and operation centers are exposed to the same risks as the main ones.
j) Considers establishing alternative information processing sites, as well as of operation, which shall allow operating at the moment it is required, and must not be subject to the same risks as the primary site.
II. In the elaboration of the Business Continuity Plan, securities depository institutions shall incorporate the following strategies:
a) Prevention, which shall include at least the determination, based on the business impact analysis, of actions and procedures relative to:
i. Reducing the vulnerability of the processes and services of the securities depository institutions to Operational Contingencies.
ii. The availability of the human, financial, material, technical and technological infrastructure resources necessary to act in a timely manner in the face of an Operational Contingency.
iii. The establishment of a program of tests on the functioning and sufficiency of the Business Continuity Plan that contemplates annual updating, or earlier if there is a significant change in the Technological Infrastructure, processes, products and services, or internal organization of the securities depository institutions that evaluate all stages and components of the Business Continuity Plan.
iv. The training program referred to in fraction I of Article 27 of these provisions.
v. The communication policy referred to in fraction II of Article 27 of these provisions, which shall attend all moments of the Operational Contingencies, from its occurrence and containment to its resolution and evaluation, this in attention to the nature of said contingency and the different recipients of its communications.
vi. Procedures for registration, attention, follow-up and dissemination to relevant personnel of the findings, incidents or observations resulting from the tests carried out on the Business Continuity Plan or, well, of the execution of the plan itself in case an Operational Contingency has occurred.
b) Contingency, which shall comprise the definition of the authorized response actions and procedures for:
i. Identifying the nature of the Operational Contingencies that affect the processes of the securities depository institutions.
ii. Containing the effects of the Operational Contingencies on the processes and favoring the
restoration of operations to the required levels of functioning based on
what is established in subsections f) and g) of the preceding fraction I.
iii.
Ensure the continuity of operations, equal conditions for the conduct of
its activities and the services it provides, as well as availability and equality for
market participants to consult information regarding said activities and services.
c)
Of restoration, which shall include the definition of actions and procedures for the
services and processes of securities depository institutions to return to minimum levels
of service and eventually to normality, including mechanisms for updating and
reconciliation of information, observing in this regard the standards established in subsections
f) and g) of the preceding fraction I.
d)
Of evaluation, which shall include matters related to the collection and analysis of information
relevant to the development of the Operational Contingency and the actions and procedures
followed for its prevention, containment, and restoration in order to, if applicable, make the
necessary adjustments to the Business Continuity Plan.
Securities depository institutions, when defining the different actions and procedures referred to in this fraction, must at all times clearly determine the responsible personnel, as well as provide for their replacement or substitution in case the holders are unable to carry out what the Business Continuity Plan establishes.
The personnel referred to in the preceding paragraph must participate in the execution of the tests of effectiveness referred to in fraction IV of Article 27 of these provisions.
In the document you are viewing, there may be text, characters, or objects that do not display correctly due to conversion to HTML format, so we recommend always taking the digitized image of the DOF or the PDF file of the edition as a reference. The content, form, and scope of published documents are the strict responsibility of their issuer.
CONSULT
BY DATE
Do
Mo
Tu
We
Th
Fr
Sa
INDICATORS
Exchange Rate and Rates as of 08/31/2026
DOLLAR
17.0427 UDIS
8.810483 TIIE 28 DAYS
6.7659% TIIE 91 DAYS
6.8033% TIIE 182 DAYS
6.8577% TIIE OVERNIGHT
6.51%
See more
SURVEYS
Did you like the new look of the Official Gazette website?
No
Yes
Official Gazette of the Federation
Río Amazonas No. 62, Col. Cuauhtémoc, C.P. 06500, Mexico City Tel. (55) 5093-3200, where you can access our menu of services
Electronic address: dof.gob.mx
113
LEGAL NOTICE | SOME RIGHTS RESERVED © 2026
More like this from SHCP
SHCP published 14 documents in the last 30 days. We email you each new one the day it's published.