2017-01-19 | DOF 5469349

Added

Guidelines for Preparing the Audit Report to Evaluate Compliance with General Provisions on Prevention of Illicit Resource Operations and Terrorist Financing

The Mexican Banking and Securities Commission establishes mandatory minimum procedures and requirements for obligated entities, including banks, exchange houses, and investment societies, to prepare and submit an annual audit report verifying compliance with anti-money laundering and counter-terrorist financing regulations. The guidelines define specific qualifications for auditors, require the use of a standardized electronic questionnaire, and mandate detailed evaluation of customer identification policies, risk profiling, transaction monitoring systems, and corrective action plans within the report.

Secretaria de Hacienda y Credito Publico logo

Mexico

Secretaria de Hacienda y Credito Publico

Click to view thumbnail

DOF: 19/01/2017

GUIDELINES for the preparation of the Audit Report to evaluate compliance with general provisions in matters of prevention of operations with resources of illicit origin and terrorist financing.

A seal with the National Coat of Arms appears at the margin, which says: United Mexican States.- Ministry of Finance and Public Credit.- National Banking and Securities Commission.

The National Banking and Securities Commission, based on what is provided by the 52nd of the General Provisions referred to in Article 115 of the Credit Institutions Law in relation with Article 87-D of the General Law of Organizations and Auxiliary Credit Activities and Article 95-Bis of this latter legislation, applicable to multiple-object financial societies; 60th of the General Provisions referred to in Article 115 of the Credit Institutions Law; 61st of the General Provisions referred to in Article 212 of the Securities Market Law; 51st of the General Provisions referred to in Article 95 of the General Law of Organizations and Auxiliary Credit Activities applicable to Exchange Houses; 55th of the General Provisions referred to in Article 91 of the Investment Funds Law; 62nd of the General Provisions referred to in Article 124 of the Popular Savings and Credit Law; 48th of the General Provisions referred to in Article 95 Bis of the General Law of Organizations and Auxiliary Credit Activities applicable to currency centers referred to in Article 81-A of the same legislation; 52nd of the General Provisions referred to in Article 95 Bis of the General Law of Organizations and Auxiliary Credit Activities, applicable to money transmitters referred to in Article 81-A Bis of the same legislation; 52nd of the General Provisions referred to in Article 129 of the Credit Unions Law; 64th of the General Provisions referred to in Articles 71 and 72 of the Law to Regulate the Activities of Savings and Loan Cooperative Societies; 48th of AGREEMENT 04/2015 by which the General Provisions referred to in Article 60 of the Organic Law of the National Financial Development Bank for Agriculture, Rural, Forestry and Fishing are issued, and 51st of the General Provisions referred to in Article 95 of the General Law of Organizations and Auxiliary Credit Activities applicable to General Deposit Warehouses, as well as Articles 4, fraction XXXVI, 16, fraction I, 19 of the Law of the National Banking and Securities Commission, and 43, fraction VI of the Internal Regulations of the National Banking and Securities Commission, and

CONSIDERING

That in accordance with what is provided in the various general provisions issued by the Ministry of Finance and Public Credit in matters of prevention and detection of acts, omissions or operations that could be located in the conduct foreseen in Articles 139 Quater or 400 Bis of the Federal Penal Code, general deposit warehouses, currency centers, the National Financial Development Bank for Agriculture, Rural, Forestry and Fishing, savings and loan cooperative societies with operation levels from I to IV, multiple-object financial societies, money transmitters, credit unions, credit institutions, brokerage houses, exchange houses, investment fund operating societies, investment fund share distributors, popular financial societies, community financial societies with operation levels I to IV, as well as rural financial integration bodies, must maintain control measures that include review, evaluation and opinion by the internal audit area or by an independent external auditor, regarding compliance with said provisions during the period comprised from January to December of each year, in accordance with the guidelines for such effects issued by the National Banking and Securities Commission, and

That it is necessary that all financial entities and other persons subject to the supervision of the National Banking and Securities Commission in matters of prevention of operations with resources of illicit origin and terrorist financing have the same standard for the preparation of the audit opinion, which will result in a complete, truthful and homogeneous audit report among said entities, facilitating its preparation and the evaluation of its compliance, has resolved to issue the following:

GUIDELINES FOR THE PREPARATION OF THE AUDIT REPORT TO EVALUATE COMPLIANCE WITH GENERAL PROVISIONS IN MATTERS OF PREVENTION OF OPERATIONS WITH RESOURCES OF ILICIT ORIGIN AND TERRORIST FINANCING

FIRST.- In addition to the definitions contained in the Provisions, for the purposes of these guidelines, singular or plural, the following shall be understood:

I. Auditor, the person responsible for preparing the report, through which the evaluation and opinion on compliance with the Provisions is carried out, as well as the evaluation of the operational effectiveness of the measures implemented by the Obligated Subject.

II. Certificate, the electronic document issued by the Commission based on the General Provisions for the certification of independent external auditors, compliance officers and other professionals in matters of prevention of operations with resources of illicit origin and terrorist financing, published in the Official Gazette of the Federation on October 2, 2014 and their respective modifications.

III. Provisions, the "General Provisions referred to in Article 115 of the Credit Institutions Law"; "General Provisions referred to in Article 212 of the Securities Market Law"; "General Provisions referred to in Article 95 of the General Law of Organizations and Auxiliary Credit Activities applicable to Exchange Houses"; "General Provisions referred to in Article 91 of the Investment Funds Law"; "General Provisions referred to in Article 124 of the Popular Savings and Credit Law"; "General Provisions referred to in Articles 115 of the Credit Institutions Law in relation with Article 87-D of the General Law of Organizations and Auxiliary Credit Activities and Article 95-Bis of this latter legislation, applicable to multiple-object financial societies"; "General Provisions referred to in Article 95 Bis of the General Law of Organizations and Auxiliary Credit Activities applicable to currency centers referred to in Article 81-A of the same legislation"; "General Provisions referred to in Article 95 Bis of the General Law of Organizations and Auxiliary Credit Activities, applicable to money transmitters referred to in Article 81-A Bis of the same legislation"; "General Provisions referred to in Article 129 of the Credit Unions Law"; "General Provisions referred to in Articles 71 and 72 of the Law to Regulate the Activities of Savings and Loan Cooperative Societies"; the "AGREEMENT 04/2015 by which the General Provisions referred to in Article 60 of the Organic Law of the National Financial Development Bank for Agriculture, Rural, Forestry and Fishing are issued", and the "General Provisions referred to in Article 95 of the General Law of Organizations and Auxiliary Credit Activities applicable to General Deposit Warehouses".

IV. Policy Document, the document prepared by the Obligated Subject in which it establishes policies for Customer or User identification and due diligence, as well as the criteria, measures and procedures that it must follow to comply with the Provisions.

V. Terrorist Financing, the conduct foreseen and sanctioned in Article 139 Quater of the Federal Penal Code.

VI. Audit Report, the document provided for in the 60th of the "General Provisions referred to in Article 115 of the Credit Institutions Law"; 61st of the "General Provisions referred to in Article 212 of the Securities Market Law"; 51st of the "General Provisions referred to in Article 95 of the General Law of Organizations and Auxiliary Credit Activities applicable to Exchange Houses"; 55th of the "General Provisions referred to in Article 91 of the Investment Funds Law"; 62nd of the "General Provisions referred to in Article 124 of the Popular Savings and Credit Law"; 52nd of the "General Provisions referred to in Articles 115 of the Credit Institutions Law in relation with Article 87-D of the General Law of Organizations and Auxiliary Credit Activities and Article 95-Bis of this latter legislation, applicable to multiple-object financial societies"; 48th of the "General Provisions referred to in Article 95 Bis of the General Law of Organizations and Auxiliary Credit Activities applicable to currency centers referred to in Article 81-A of the same legislation"; 52nd of the "General Provisions referred to in Article 95 Bis of the General Law of Organizations and Auxiliary Credit Activities, applicable to money transmitters referred to in Article 81-A Bis of the same legislation"; 52nd of the "General Provisions referred to in Article 129 of the Credit Unions Law"; 64th of the "General Provisions referred to in Articles 71 and 72 of the Law to Regulate the Activities of Savings and Loan Cooperative Societies"; 48th of the "AGREEMENT 04/2015 by which the General Provisions referred to in Article 60 of the Organic Law of the National Financial Development Bank for Agriculture, Rural, Forestry and Fishing are issued", and 51st of the "General Provisions referred to in Article 95 of the General Law of Organizations and Auxiliary Credit Activities applicable to General Deposit Warehouses".

VII. Operations with resources of illicit origin, the conduct foreseen and sanctioned in Article 400 Bis of the Federal Penal Code.

VIII. 24-hour Report, the report presented by the Obligated Subject when it has information based on indications or concrete facts from which it may be presumed or inferred that the resources of an operation could come from illicit activities or be intended to favor, provide help, assistance or cooperation of any kind for the commission of the crime foreseen in Article 139 Quater of the Federal Penal Code, or that could be located in the circumstances of Article 400 Bis of said legal instrument.

IX. SITI PLD/FT, The Interinstitutional System for Information Transfer in matters of Prevention of Operations with Resources of Illicit Origin and Terrorist Financing.

X. Obligated Subjects, general deposit warehouses, brokerage houses, exchange houses, currency centers, National Financial Development Bank for Agriculture, Rural, Forestry and Fishing, credit institutions, rural financial integration bodies, savings and loan cooperative societies with operation level from I to IV, investment fund share distributing societies, community financial societies with operation levels I to IV, multiple-object financial societies, popular financial societies, investment fund operating societies, money transmitters and credit unions.

SECOND.- These guidelines have the object of establishing the minimum procedures and requirements that Obligated Subjects must observe and comply with regarding the preparation and presentation before the Commission of the Audit Report.

The Audit Report has the object of providing Obligated Subjects with the necessary information to adopt measures that allow making their processes, mechanisms and tools more efficient to prevent operations with resources of illicit origin and terrorist financing, as well as to establish action plans to improve the areas of opportunity derived from the review subject of the report.

The circumstances provided for in these guidelines are illustrative and do not limit the Auditor in the preparation of the Audit Report.

THIRD.- The Auditor responsible for preparing the Audit Report must comply with the following requirements:

I. Have a valid Certificate at the time of preparing the Audit Report.

II. Not have been sentenced for property crimes.

III. Not be disqualified to exercise commerce or to hold an employment, position or commission in public service, or in the Mexican financial system, nor be in bankruptcy proceedings under the terms of the applicable law.

IV. Not be, nor have an offer to be, counselor or executive of the Obligated Subject, except when it concerns the internal auditor of the Obligated Subject itself.

V. Not have pending litigation with the Obligated Subject.

VI. Not have antecedents of suspension, cancellation or revocation of any registration to act as Auditor, or that some Certificate has not been previously revoked by the Commission.

FOURTH.- The general management and the Committee or, in its case, the Compliance Officer of the Obligated Subjects must know the content of the Audit Report, in order to evaluate the operational effectiveness of the implemented measures and follow up on corrective action programs.

The report referred to in the previous paragraph must be made known to the Commission through the SITI PLD/FT, through a writing signed by the legal representative, sole administrator or the Committee or, in its case, the Compliance Officer, in which the respective agreement, its date, as well as the review period and the full name without abbreviations of the Auditor designated for the preparation of the Audit Report are informed.

Obligated Subjects must also send to the Commission at the time of delivering the report, through the SITI PLD/FT, a letter signed by the Auditor in which it indicates the number and date of issuance of the Certificate and declares under oath, that it knows the content of these guidelines and complies with the requirements referred to in guideline THIRD.

In the event that the designated Auditor is a legal entity, the letter referred to in the previous paragraph must be signed by the responsible auditor(s) who prepare the Audit Report, indicating the number and date of issuance of the Certificates issued both in their favor and in favor of the legal entity in question, as well as the trade name or corporate name of the latter.

FIFTH.- Obligated Subjects must present the Audit Report to the Commission in accordance with the format and terms contained in these guidelines and according to the specifications for its sending contained in the "Notices" section of the SITI PLD/FT Internet portal, to which one can enter through the electronic address http://www.gob.mx/cnbv .

SIXTH.- The Auditor who prepares the Audit Report , must answer a questionnaire based on the information and documentation that was available for the preparation of the cited report, in addition to the data collected as a result of the review carried out. Said questionnaire must be downloaded through the "Notices" section cited in guideline FIFTH above.

SEVENTH.- The Audit Report must be drafted in Spanish, with a font size of at least 10 points, have an index and be divided into chapters, sections, subsections or any other format that facilitates its reading and comprehension, which must be highlighted in bold to differentiate the respective divisions and, if applicable, have annexed the documentation that served as the basis for its preparation.

EIGHTH.- The audit must be supported by a risk analysis considering, among other aspects, the type of Customers or Users of the Obligated Subject, the products or services it offers, as well as its internal areas and structures. Likewise, the audit must be based on the criteria, measures and procedures established to mitigate the risk that the Obligated Subject is used as a means of commission or instrument to carry out operations with resources of illicit origin and terrorist financing.

The Auditor responsible for the Audit Report must design a program that contains at least, the schedule of activities to be performed, the topics to be evaluated, including the performance of tests on automated systems, random reviews of Customer or User identification files, and the material, technological and human resources available to the Obligated Subject; as well as the way in which it will determine, evaluate and follow up on corrective actions implemented in accordance with the risks and areas of opportunity detected in matters of prevention of operations with resources of illicit origin and terrorist financing.

NINTH.- The Audit Report must have a section or annex containing the follow-up, development and execution of the work program indicated in guideline EIGHTH above, indicating the deadlines in which they were carried out, as well as another diverse one in which it indicates whether the Obligated Subject complies with what is stated in the Provisions regarding branches, agencies, subsidiaries, premises, establishments, related agents or third parties with which it operates.

Additionally, the Audit Report must include the result of the review of compliance with all obligations provided for in the Provisions, including the following:

I. Regarding Customer or User identification policies, it must contain at least, if the Obligated Subject:

a) Has a Policy Document with the internal criteria, measures and procedures for the proper identification of the Customer or User, based on the services, products or operations offered.

To comply with what is stated in this subsection, the Auditor must evaluate and state whether the content and application of the Policy Document is adequate for the services, products or operations offered by the Obligated Subject.

b) Identifies the Customer or User in accordance with the profile, characteristics and type of Customer or User in question, as well as with the requirements established in the Provisions and in its Policy Document.

To comply with this subsection, the Auditor must perform a review of the records of the Customer or User identification files in question, based on probabilistic sampling methods to obtain a representative sample of the population, in order to determine if the identification data are properly captured and integrated.

Without prejudice to the foregoing, the auditor must consider carrying out a verification, based on stratified sampling method, of the integration of files of Customers or Users classified as High Risk and include the result in the Audit Report.

In all cases, the Auditor must explain the selection criteria of the sample, indicate the number of file records that formed part of said sample and the percentage it represents of the total records or files available to the Obligated Subject, as well as the missing data and documents in each record or file reviewed.

c) If applicable, applies the Customer or User identification and due diligence policies that operate in the concentration accounts opened by said Obligated Subject.

d) Has the follow-up and aggregation mechanisms for operations indicated in the Provisions, as well as those relative to internal approval escalation. In this case, it must be indicated what these mechanisms consist of and determine the way in which they have been implemented by the Obligated Subject.

e) Has policies, criteria, measures and procedures to verify Customer or User identification files in accordance with their degree of Risk, as well as to reclassify them in the higher degree of Risk corresponding in case of detecting significant changes in their transactional behavior.

The Auditor must indicate whether the policies, criteria, measures and procedures referred to in the previous paragraph have been implemented in accordance with the Obligated Subject's Policy Document.

f) Has carried out visits to the Customer's domicile in accordance with the Provisions, the cases in which such visits have been carried out, the results obtained from these, as well as the programming of future visits.

II. Regarding Customer or User due diligence policies, it must contain at least, if the Obligated Subject:

a) Has the Policy Document containing the criteria, measures and procedures for the proper due diligence of the Customer or User in accordance with the Provisions.

b) Has criteria, measures and procedures to determine the profile and transactional behavior of the Customer or User. In this case, the Auditor must indicate what the referred criteria, measures and procedures consist of and determine the way in which these have been implemented by the Obligated Subject.

c) Has criteria, measures and procedures to classify the Customer or User based on their degree of Risk. The Auditor must state whether the criteria, measures and procedures allow the Obligated Subject to perform an adequate classification in accordance with what is established in the Provisions.

d) Has an alert system that allows it to follow up and timely detect changes in the transactional behavior of the Customer or User.

e) Has criteria, measures and procedures for the supervision of the transactional behavior of Customers or Users classified as High Risk. The Auditor must indicate what the referred criteria, measures and procedures consist of, and determine the way in which these have been implemented by the Obligated Subject.

f) Has criteria, measures and procedures related to Customers or Users considered Politically Exposed Persons. The Auditor must indicate whether the criteria,

mechanisms, measures and procedures referred to in this subsection have been implemented by the Obligated Subject in accordance with the Policy Document.

g)

It has carried out operations with Clients or Users considered Politically Exposed Persons and of high Risk, which have been approved in accordance with the Provisions. In this case, it must be indicated what the approval procedure for such operations consists of, how such procedure is carried out and whether it was applied adequately.

h)

It has carried out operations, which by their characteristics could generate a high Risk for the Obligated Subject itself, which have been approved in accordance with the Provisions. For these purposes, it must be indicated what the approval procedure for such operations consists of, the manner in which such procedure is carried out and whether it was applied adequately.

i)

It has policies and procedures to identify the Beneficial Owner of the resources, as well as the beneficiary thereof. Additionally, it must indicate the manner in which such policies and procedures have been implemented by the Obligated Subject.

j)

It has criteria, measures and procedures to identify the number, amount and frequency of operations it carries out with Obligated Subjects when these have the status of Client or User, indicating the manner in which such policies and procedures have been implemented by the Obligated Subject.

k)

It has policies and procedures to identify Clients or Users who are within the List of Blocked Persons issued by the Secretariat, any third party acting on behalf or for the account of such persons, as well as the operations they have carried out. Likewise, it must be indicated the manner in which the policies and procedures have been implemented by the Obligated Subject.

III.

Regarding the submission of Operation reports to the Secretariat through the Commission, which shall contain, at least, whether the Obligated Subject:

a)

Submitted on time and in the proper form, the reports of Relevant Operations, in accordance with the Provisions and in the official format issued for such purpose. In the Audit Report, it must be indicated whether the reports included all Relevant Operations carried out by the Obligated Subject in the reported period, as well as those carried out through concentrating accounts, if applicable.

b)

Submitted on time and in the proper form the reports for each Unusual Operation alerted by its system, model, process or employee, in accordance with the Provisions and in the official format issued for such purpose. Likewise, it must be indicated whether such operations were adjudicated by the Committee or, in its case, by the Compliance Officer.

Likewise, it must be noted whether the Committee or, in its case, the Compliance Officer carried out, in accordance with the Provisions and the Policy Document, the analysis of those operations presented for examination that were not adjudicated as Unusual Operations.

c)

Submitted on time and in the proper form the 24-hour Reports, in accordance with what is established in the Provisions and in the official format issued for such purpose.

d)

Submitted on time and in the proper form the report of each Concerning Internal Operation alerted by its system, model, process or employee, in accordance with what is established in the Provisions and in the official format issued for such purpose. In this case, it must be indicated whether such operations were adjudicated by the Committee or, in its case, by the Compliance Officer.

Likewise, it must be noted whether the Committee or, in its case, the Compliance Officer carried out, in accordance with the Provisions and the Policy Document, the analysis of those operations presented for examination that were not adjudicated as Concerning Internal Operations.

e)

Submitted on time and in the proper form the other reports that, if applicable, are provided for in the Provisions, such as reports of international fund transfers, cash operations in United States of America dollars, cashier's checks, information exchange, as well as the report of total amounts of foreign currency. In the respective report, the Auditor must state whether such reports were submitted complying with what is stated in the Provisions and if they were presented in the official format issued for such purpose.

The Auditor must indicate in the report the operations that the Obligated Subject omitted to report, those that were presented outside the deadline established in the Provisions and those that in its opinion could contravene them.

IV.

Regarding the integration of internal structures, which shall contain, at least, whether the Obligated Subject:

a)

Integrated the Committee in accordance with the Provisions.

b)

Communicated on time and in the proper form, to the Secretariat through the Commission, the initial integration of its Committee, in accordance with the Provisions.

In the event of not having such Committee, the Auditor must verify that the Obligated Subject complies with the exceptions established in the applicable Provisions to not constitute the aforementioned Committee, and that it has communicated this, on time and in the proper form, to the Secretariat through the Commission.

c)

Submitted on time and in the proper form, to the Secretariat through the Commission, the information that must be sent within the first fifteen business days of the month of January of each year, regarding the integration and changes of the Committee referred to in the Provisions.

d)

Carried out the designation of the Compliance Officer in accordance with the Provisions and attending to the requirements stated therein.

e)

Communicated on time and in the proper form, to the Secretariat through the Commission, the initial designation of its Compliance Officer, or its substitution.

f)

Communicated on time and in the proper form, to the Secretariat through the Commission, the initial information on the identity of the person or group of persons exercising Control, as well as any changes in such persons, in accordance with the Provisions.

g)

Has communicated on time and in the proper form, to the Secretariat through the Commission, regarding the transmission of shares or social parts for more than two percent of its paid-up share capital, in accordance with the Provisions.

Additionally, the Auditor must include in the report a report of the functions and obligations carried out by the Committee and the Compliance Officer in accordance with the Provisions, as well as with the mechanisms, processes, deadlines and procedures stated in its Policy Document, or in any other document or manual prepared by the Obligated Subject.

In the event that the Auditor detects that the Obligated Subject did not adhere to what is provided for in this subsection or the Provisions, it must include in its report the possible non-compliances and the reasons why it considers these to occur.

V.

Regarding training and dissemination, it shall contain, whether the Obligated Subject:

a)

Has an annual training program. It must be specified whether this is in accordance with the services, products or operations offered by the Obligated Subject.

b)

Provided training courses to the members of the Committee, to the Compliance Officer, executives, officials, employees, proxies and other persons working in customer service or resource administration areas, in terms of the Provisions and its Policy Document and in accordance with the report presented to the Commission.

c)

Disseminated to the personnel cited in the previous subsection, the Provisions and their modifications, as well as information on techniques, methods, procedures and trends to prevent, detect and report operations with resources of illicit origin and terrorist financing.

d)

Issued certificates accrediting the participation of its officials or employees in the training courses.

e)

Has measures for the case of those officials or employees who do not obtain a satisfactory grade in the knowledge evaluations referred to in the Provisions. For this purpose, it must indicate what these measures are and if, in the event that this situation has occurred, they were carried out in accordance with its Policy Document.

Additionally, the Auditor must state in its report whether the Obligated Subject presented or not to the Commission, the training report that must be sent within the first fifteen business days of the month of January of each year, in accordance with what is established in the Provisions and in the official format issued for such purpose.

VI.

Regarding the automated system, it must include whether the Obligated Subject has automated systems that carry out all the functions stated in the Provisions, as well as the manner in which it ensured that the system carries out its functions, such as classifying types of operations, products or services, grouping operations of the same Client or User, executing alert systems, among others.

VII.

Regarding employees working in customer service or resource administration areas, it must be informed whether the Obligated Subject:

a)

Has employee selection procedures that comply with what is stated in the Provisions. It must be indicated the manner in which said procedure has been implemented by the Obligated Subject.

b)

Has files for each of the employees, indicating whether such files are integrated in accordance with their selection procedures.

c)

Has certificates or any other document that accredits that its employees have received training in the prevention of operations with resources of illicit origin and terrorist financing, prior or simultaneous to their entry or the start of their activities in said areas.

VIII.

Regarding the conservation of information, which shall contain at least whether the Obligated Subject:

a)

Has mechanisms to conserve, for a period not less than ten years in accordance with what is established in the Provisions, copies of, among others, the reports of the Operations provided for in the Provisions, as well as the data and documents that make up the identification files of Clients or Users.

b)

Conserves for the period mentioned in the previous subsection, copies of the reports of the Operations provided for in the Provisions, as well as the data and documents that make up the identification files of Clients or Users, among others.

c)

Has mechanisms to conserve for a period not less than five years, in accordance with what is established in the Provisions, the Audit Reports.

d)

Conserves for the period mentioned in the previous subsection, the Audit Reports.

IX.

Regarding the lists, it shall contain at least, whether the Obligated Subject:

a)

Has the officially recognized lists issued by Mexican authorities, intergovernmental groupings or authorities of other countries, of persons linked to operations with resources of illicit origin or terrorist financing, or with other illegal activities.

The respective report must indicate whether the Obligated Subject has mechanisms, which allow identifying the persons who are within the aforementioned lists, and whether such mechanisms identify them.

b)

Has the list of Politically Exposed Persons that the Obligated Subjects must prepare in accordance with the Provisions. The respective report must indicate whether the Obligated Subject has mechanisms that allow it to identify the persons who are within the aforementioned lists, and whether such mechanisms identify them.

c)

Has the lists of countries or jurisdictions that Mexican legislation considers apply preferential fiscal regimes, indicating whether the Obligated Subject has mechanisms that allow it to identify the countries and jurisdictions that are within the aforementioned lists, and whether such mechanisms identify them.

d)

Has the lists of countries or jurisdictions that, in the judgment of Mexican authorities, international organizations or intergovernmental groupings in the matter of prevention of operations with resources of illicit origin or terrorist financing of which Mexico is a member, do not have measures to prevent, detect and combat said operations, or when the application of such measures is deficient.

The report must indicate whether the Obligated Subject has mechanisms that allow it to identify the countries and jurisdictions that are within the aforementioned lists, and whether such mechanisms identify them.

e)

Has the List of Blocked Persons. It must be indicated whether the Obligated Subject has mechanisms that allow it to identify the persons who are within the aforementioned lists, and whether such mechanisms identify them.

f)

Has implemented the measures established in the Provisions in the event of identifying a Client or User in said lists.

X.

Of other information:

a)

In the case of money transmitters, if the notice containing the list of related agents with which each money transmitter has a contractual relationship and the third parties with which the related agents operate was submitted on time and in the proper form.

b)

Any other information that has been required from the Obligated Subject by the Commission.

c)

The Auditor must inform whether the Obligated Subject remedied the observations, recommendations and corrective actions that the Commission notified it.

TENTH.- The statements and data contained in the Audit Report must be supported by sufficient evidence to prove their veracity, so the Auditor must justify each of them and specifically indicate and relate the evidence, as well as, if applicable, the documentation that was analyzed, endeavoring to cite the full text of the document to which reference is made and indicate the identification data thereof.

ELEVENTH.- When during the course of the audit, the Auditor knows or determines that the measures implemented are not in accordance with the type of services, products or operations offered by the Obligated Subject to its Clients or Users; when operationally it considers that there is no efficacy in the controls implemented to mitigate risks, or detects irregularities that based on its professional judgment could favor, provide help, aid or cooperation of any kind for the commission of the crimes foreseen in articles 139 Quater or 400 Bis of the Federal Penal Code, it must present a detailed report on the observed situation to the Compliance Officer or the Committee, with the object that this report to the competent authority the possible commission of some illicit conduct through the corresponding report.

TWELFTH.- The Audit Report must contain a section in which the findings and corrective actions that, in the Auditor's judgment, are required to fully comply with the Provisions are included.

Additionally, it must contain a section in which the follow-up carried out by the Obligated Subject regarding the findings and corrective actions related to the Audit Report presented in the immediate previous year is indicated.

THIRTEENTH.- The interpretation of these guidelines and the attention of consultations related to them, will correspond to the Vice Presidency of Supervision of Preventive Processes of the Commission, through the General Directorates of Prevention of Operations with Resources of Illicit Origin A and B.

TRANSITORY PROVISIONS

FIRST.- These guidelines will enter into force starting from 2018, for those reports that must be presented by the Obligated Subjects regarding the review of the 2017 exercise, except for what is established in the following transitory article.

At the date of entry into force of this instrument, the "Guidelines for the preparation of the audit report to evaluate compliance with general provisions in the matter of prevention of operations with resources of illicit origin and terrorist financing", published in the Official Gazette of the Federation on November 7, 2013, will be repealed.

SECOND.- The obligation to have the Certificate referred to in these guidelines, for purposes of the preparation of the Audit Report, will be enforceable in accordance with the dates established in the "Agreement by which the calendar to initiate the process of certification of independent external auditors, internal auditors, compliance officers, representatives and other professionals in the matter of prevention of operations with resources of illicit origin and terrorist financing" published in the Official Gazette of the Federation on March 13, 2015 and its respective modification.

Respectfully

Mexico City, January 6, 2017.- The President of the National Banking and Securities Commission, Jaime González Aguadé.- Signature.

In the document you are viewing, there may be text, characters or objects that are not displayed correctly due to conversion to HTML format, so we recommend always taking as reference the digitized image of the DOF or the PDF file of the edition. The content, form and scope of the published documents are the strict responsibility of their issuer.

INQUIRY

BY DATE

Do Mo Tu We Th Fr Sa

INDICATORS

Exchange Rate and Rates as of 08/31/2026

DOLLAR 17.0427 UDIS 8.810483 TIIE 28 DAYS 6.7659% TIIE 91 DAYS 6.8033% TIIE 182 DAYS 6.8577% TIIE DE FONDEO 6.51%

See more

SURVEYS

Did you like the new look of the Official Gazette of the Federation website?

No Yes

Official Gazette of the Federation

Río Amazonas No. 62, Col. Cuauhtémoc, C.P. 06500, Mexico City Tel. (55) 5093-3200, where you can access our menu of services

Electronic address: dof.gob.mx

113

LEGAL NOTICE | SOME RIGHTS RESERVED © 2026

More like this from SHCP

SHCP published 14 documents in the last 30 days. We email you each new one the day it's published.

Share