2021-10-18
Added
The National Banking and Securities Commission establishes minimum requirements for supervised entities to hire auditors and prepare audit reports evaluating compliance with anti-money laundering and counter-terrorism financing regulations. The document defines eligible auditors, mandating specific educational levels, experience, and certification, while outlining the required structure, content, and submission procedures for the audit report. These guidelines apply to a wide range of financial institutions, including credit institutions, securities firms, exchange houses, and fintech entities.
CNBV published 1 document in the last 30 days — get each new one by email the day it lands.
Published in the Official Gazette of the Federation on October 18, 2021
The National Banking and Securities Commission, based on the provisions of articles 4, fractions VI and XXXVI, 16, fraction I, and 19 of the National Banking and Securities Commission Law, and 98 Bis of the Credit Institutions Law; in relation to the 52nd of the General Provisions referred to in article 115 of the Credit Institutions Law in relation to 87-D of the General Law of Credit Auxiliary Organizations and Activities and 95-Bis of this latter legislation, applicable to multiple-object financial societies; 60th of the General Provisions referred to in article 115 of the Credit Institutions Law; 61st of the General Provisions referred to in article 212 of the Securities Market Law; 51st of the General Provisions referred to in article 95 of the General Law of Credit Auxiliary Organizations and Activities applicable to Exchange Houses; 55th of the General Provisions referred to in article 91 of the Investment Funds Law; 62nd of the General Provisions referred to in article 124 of the Popular Savings and Credit Law; 48th of the General Provisions referred to in article 95 Bis of the General Law of Credit Auxiliary Organizations and Activities applicable to the exchange centers referred to in article 81-A of the same legislation; 52nd of the General Provisions referred to in article 95 Bis of the General Law of Credit Auxiliary Organizations and Activities, applicable to money transmitters referred to in article 81-A Bis of the same legislation; 52nd of the General Provisions referred to in article 129 of the Credit Unions Law; 64th of the General Provisions referred to in articles 71 and 72 of the Law to Regulate the Activities of Savings and Loan Cooperative Societies; 48th of AGREEMENT 04/2015 by which the General Provisions referred to in article 60 of the Organic Law of the National Financial Development Bank for Agriculture, Rural, Forestry and Fisheries are issued; 51st of the General Provisions referred to in article 95 of the General Law of Credit Auxiliary Organizations and Activities applicable to General Deposit Warehouses, and article 76 and 106 of the General Provisions referred to in article 58 of the Law to Regulate Financial Technology Institutions, and
CONSIDERING
That in accordance with article 78 of the General Law for Regulatory Improvement and with the aim of reducing the compliance cost of these Guidelines, the National Banking and Securities Commission, through the issuance of the "Resolution that modifies the General Provisions applicable to credit institutions" and the "Modifying Resolution of the 'Resolution that modifies the General Provisions applicable to the activities of savings and loan cooperative societies', published in the Official Gazette of the Federation on January 23, 2018", published in the Official Gazette of the Federation on April 26 and November 15, 2018 respectively, proceeded to eliminate the obligations for multiple banking institutions to present to the Commission the Opinion of the Independent Expert Auditor on deferred taxes and the participation of workers in profits and on employee benefits; and for Savings and Loan Cooperative Societies with operation levels I to IV, the deadline was extended for them to be in a position to observe what is provided by the Financial Information Standards issued by the Mexican Council of Financial Information Standards, A.C.;
That the National Banking and Securities Commission is a decentralized body of the Ministry of Finance and Public Credit whose object is to supervise and regulate the entities comprising the Mexican financial system, empowered to issue the regulations that allow it to effectively fulfill its attributes;
That among the powers of said Commission is the power to issue regulations related to the characteristics and requirements of the auditors used by the entities supervised by the Commission and the opinions they issue, such as the auditors or audit areas responsible for the evaluation and opinion on the effectiveness of compliance with the provisions that, in matters of prevention and detection of acts, omissions, or operations that could be located in the conduct foreseen in articles 139 Quater or 400 Bis of the Federal Penal Code, issued by the Ministry of Finance and Public Credit;
That the Ministry of Finance and Public Credit has issued provisions that regulate general deposit warehouses, brokerage houses, exchange houses, exchange centers, credit institutions, financial technology institutions, rural financial integration organisms, societies authorized to operate with novel models, savings and loan cooperative societies with operation levels I to IV, societies distributing shares of investment funds, community financial societies with operation levels I to IV, regulated and unregulated multiple-object financial societies, popular financial societies, investment fund operating societies, money transmitters, credit unions, and the National Financial Development Bank for Agriculture, Rural, Forestry and Fisheries, which must maintain control measures, including review, evaluation, and opinion by their internal audit area or by an external or independent third-party auditor, regarding the effectiveness of compliance with said provisions during the period established by them in accordance with the guidelines issued for such purposes by the National Banking and Securities Commission;
That in order to allow the National Banking and Securities Commission to effectively fulfill the powers mentioned above, on January 19, 2017, the Guidelines for the Preparation of the Audit Report to Evaluate Compliance with General Provisions on the Prevention of Operations with Illicit Proceeds and Terrorism Financing were published in the Official Gazette of the Federation, which did not contemplate, as a supervised subject, financial technology institutions as new financial entities provided for in the Law to Regulate Financial Technology Institutions, so it is necessary to incorporate them, and
That given the importance that the audit report on the evaluation of the effectiveness of compliance with the provisions issued by the Ministry of Finance and Public Credit in matters of prevention of money laundering and terrorism financing holds, in the internal control of entities, as well as for the supervision that the National Banking and Securities Commission performs on these, it is necessary to specify the characteristics that the auditor must have, the content of the audit report, and its submission to said Commission, so it is necessary to update the guidelines referred to in the immediate preceding consideration to give order, coherence, and clarity regarding the minimum procedures and requirements that supervised subjects must observe and comply with in these aspects, so it has resolved to issue the following:
SECTION A. PRELIMINARY GUIDELINES
FIRST. Object
SECOND. Definitions
THIRD. Interpretation and consultations
SECTION B. ON THE AUDITOR
FOURTH. Requirements that the Auditor must meet FIFTH. Requirements that the Legal Entity must meet
SECTION C. OF THE PREPARATION OF THE AUDIT REPORT SIXTH. Audit planning SEVENTH. Work program EIGHTH. Sections of the Audit Report A. Results of the Review B. Regulatory compliance
C. Key audit matters
D. Findings, corrective actions, and improvement recommendations
SECTION D. OF THE AUDIT REPORT
NINTH. Drafting and structure of the Audit Report TENTH. Tests and supporting documentation of the Audit Report ELEVENTH. Knowledge and submission of the Audit Report TWELFTH. Conservation
FIRST. Object
These guidelines have the following objectives:
The Audit Report aims to provide Supervised Subjects with the necessary information to adopt measures that allow them to make their processes, mechanisms, and tools for preventing Operations with Illicit Proceeds and Terrorism Financing more efficient, as well as to establish action plans derived from the review subject of the Audit Report.
The circumstances foreseen in these guidelines are illustrative and do not limit the Auditor in the preparation of the Audit Report.
SECOND. Definitions
In addition to the definitions contained in the Provisions that are applicable, for the purposes of these guidelines, the following terms shall be understood, in singular or plural, as:
I. Auditor, the natural person responsible for preparing and signing the Audit Report of the Supervised Subject, who may be part of a Legal Entity.
II. Certificate, the document issued electronically by the Commission, in which the certification referred to in article 4, fractions X and X Bis of the National Banking and Securities Commission Law is stated.
III. Provisions, the General Provisions referred to in article 115 of the Credit Institutions Law; General Provisions referred to in article 212 of the Securities Market Law; General Provisions referred to in article 95 of the General Law of Credit Auxiliary Organizations and Activities applicable to Exchange Houses; General Provisions referred to in article 91 of the Investment Funds Law; General Provisions referred to in article 124 of the Popular Savings and Credit Law; General Provisions referred to in articles 115 of the Credit Institutions Law in relation to 87-D of the General Law of Credit Auxiliary Organizations and Activities and 95-Bis of this latter legislation, applicable to multiple-object financial societies; General Provisions referred to in article 95 Bis of the General Law of Credit Auxiliary Organizations and Activities applicable to the exchange centers referred to in article 81-A of the same legislation; General Provisions referred to in article 95 Bis of the General Law of Credit Auxiliary Organizations and Activities, applicable to money transmitters referred to in article 81-A Bis of the same legislation; General Provisions referred to in article 129 of the Credit Unions Law; General Provisions referred to in articles 71 and 72 of the Law to Regulate the Activities of Savings and Loan Cooperative Societies; AGREEMENT 04/2015 by which the General Provisions referred to in article 60 of the Organic Law of the National Financial Development Bank for Agriculture, Rural, Forestry and Fisheries are issued; General Provisions referred to in article 95 of the General Law of Credit Auxiliary Organizations and Activities applicable to General Deposit Warehouses, and the General Provisions referred to in Article 58 of the Law to Regulate Financial Technology Institutions.
IV. Terrorism Financing, the conduct foreseen and sanctioned in article 139 Quater of the Federal Penal Code.
V. Audit Report, the document referred to in the 60th of the General Provisions referred to in article 115 of the Credit Institutions Law; 61st of the General Provisions referred to in article 212 of the Securities Market Law; 51st of the General Provisions referred to in article 95 of the General Law of Credit Auxiliary Organizations and Activities applicable to Exchange Houses; 55th of the General Provisions referred to in article 91 of the Investment Funds Law; 62nd of the General Provisions referred to in article 124 of the Popular Savings and Credit Law; 52nd of the General Provisions referred to in articles 115 of the Credit Institutions Law in relation to 87-D of the General Law of Credit Auxiliary Organizations and Activities and 95-Bis of this latter legislation, applicable to multiple-object financial societies; 48th of the General Provisions referred to in article 95 Bis of the General Law of Credit Auxiliary Organizations and Activities applicable to the exchange centers referred to in article 81-A of the same legislation; 52nd of the General Provisions referred to in article 95 Bis of the General Law of Credit Auxiliary Organizations and Activities, applicable to money transmitters referred to in article 81-A Bis of the same legislation; 52nd of the General Provisions referred to in article 129 of the Credit Unions Law; 64th of the General Provisions referred to in articles 71 and 72 of the Law to Regulate the Activities of Savings and Loan Cooperative Societies; 48th of AGREEMENT 04/2015 by which the General Provisions referred to in article 60 of the Organic Law of the National Financial Development Bank for Agriculture, Rural, Forestry and Fisheries are issued, 51st of the General Provisions referred to in article 95 of the General Law of Credit Auxiliary Organizations and Activities applicable to General Deposit Warehouses, and in article 76 of the General Provisions referred to in Article 58 of the Law to Regulate Financial Technology Institutions.
VI. Operations with Illicit Proceeds, the conduct foreseen and sanctioned in article 400 Bis of the Federal Penal Code.
VII. Legal Entity, the person hired by the Supervised Subject to provide them with the services of preparation of the Audit Report.
VIII. SITI AML/CFT, the Inter-institutional System for Information Transfer in matters of Prevention of Operations with Illicit Proceeds and Terrorism Financing.
IX. Supervised Subjects, general deposit warehouses, brokerage houses, exchange houses, exchange centers, National Financial Development Bank for Agriculture, Rural, Forestry and Fisheries, credit institutions, electronic payment fund institutions, collective financing institutions, rural financial integration organisms, societies authorized to operate with novel models, savings and loan cooperative societies with operation level I to IV, societies distributing shares of investment funds, community financial societies with operation levels I to IV, multiple-object financial societies (regulated and unregulated), popular financial societies, investment fund operating societies, money transmitters, and credit unions.
THIRD. Interpretation and consultations
The interpretation of these guidelines and the attention of consultations related to them will correspond to the Vice Presidency of Preventive Process Supervision of the Commission.
FOURTH. Requirements that the Auditor must meet The Auditor must meet the following requirements:
I. Have at least a level of studies equivalent to a bachelor's degree and have at least three years of experience in matters of prevention, detection, and reporting of Operations with Illicit Proceeds and Terrorism Financing.
In the event of not having the level of studies indicated in the previous paragraph, have at least five years of experience in matters of prevention, detection, and reporting of Operations with Illicit Proceeds and Terrorism Financing.
II. Have the Certificate valid at the time of preparing and signing the Audit Report.
III. Not have been sentenced for property crimes.
IV. Not be disqualified from exercising commerce or from holding a job, position, or commission in public service, or in the Mexican financial system, nor be in commercial bankruptcy under the terms of the applicable law.
V. Not be, nor have an offer to be, a councilor or executive of the Supervised Subject, except when it concerns the internal auditor of the Supervised Subject itself.
VI. Not be part of the shareholding structure or governing bodies, nor be a Compliance Officer, official, attorney, or employee in the Supervised Subject to which they provide their services, regardless of the labor regime under which they provide their services.
This requirement will not be applicable for the internal auditor of the Supervised Subject itself.
VII. Not have a pending lawsuit with the Supervised Subject.
VIII. Not have a valid suspension, cancellation, or revocation of any registration to act as an independent external auditor, or of any certification issued by any self-regulatory body recognized under the terms of applicable legal provisions.
IX. Not be found on the official lists issued by Mexican authorities, international organizations, intergovernmental groupings, or authorities of other countries, of persons linked or probably linked to Operations with Illicit Proceeds and Terrorism Financing, or with other illegal activities.
Likewise, it will be the responsibility of the Supervised Subject in question to collect the following documents:
a) In its case, a copy of the degree or professional license or equivalent document of the Auditor referred to in the previous fraction I.
b) Document accrediting the professional experience indicated in the previous fraction I.
c) Copy of the Certificate referred to in the previous fraction II.
d) Letter under oath stating that they meet the requirements indicated in the previous fractions III to VIII, and that the documentation provided in accordance with these guidelines is truthful.
FIFTH. Requirements that the Legal Entity must meet In the event that the Supervised Subject chooses to hire a Legal Entity to provide the services of preparation of the Audit Report, each Supervised Subject must observe the following:
I. The Legal Entity, the Auditor, and the individuals forming part of the audit team, who provide their services to the Supervised Entity, must be and remain independent from the latter, at the time of signing the service contract, during the development of the audit, and until the issuance of the Audit Report.
Independence shall be considered non-existent in any of the following cases:
a) The Auditor or any partner of the Legal Entity where they work, are or have been during the year immediately preceding the signing of the service contract:
i) Compliance Officer or internal auditor of the Supervised Entity in question, or, in their case, in any other Supervised Entity that forms part of the same financial group or business group. ii) General Manager, Legal Representative, or employee holding a position within the three immediate lower levels to this in the Supervised Entity, or, in their case, in any other Supervised Entity that forms part of the same financial group or business group. b) The income that the Legal Entity receives or will receive for the provision of services for the preparation of the Audit Report depends on the result of the report itself or the success of any activity carried out by the Supervised Entity, based on said report.
The Supervised Entity shall be responsible for compliance with the independence requirements referred to in this subsection.
II. The Legal Entity in question must have sufficient technical, human, financial, and administrative resources to provide the corresponding service.
III. The Legal Entity in question must not exercise Control over the Supervised Entity to which it provides services.
Additionally, the Supervised Entity must agree with the Legal Entity that the documentation and working papers belonging to the Legal Entity that support the Audit Report, as well as all information and other elements of judgment used to prepare said report, must be preserved and kept available for consultation by the Supervised Entity, and, if applicable, presented to the Commission at the moment the latter so requires from the Supervised Entity. The foregoing, for a minimum period of five years counted from the submission to the Commission of the corresponding Audit Report.
SECTION C
OF THE PREPARATION OF THE AUDIT REPORT
SIXTH. Audit Planning
The Audit Report that the Supervised Entities submit to the Commission must be prepared following a methodology that serves the Auditor to understand the Supervised Entity in question and define the scope of the work program referred to in the SEVENTH of these guidelines, according to the characteristics of the Supervised Entity. This methodology must include as a minimum the following criteria:
I. Initial questionnaire to understand the Supervised Entity in question: The Auditor must collect the information and documentation they consider pertinent for the performance of their work.
II. Risk Analysis: The Auditor must prepare a Risk Analysis based on the information and documentation provided by the Supervised Entity in question in their initial questionnaire, through which it is clearly established what are the Risks detected, which in their opinion must be evaluated to attest that the preventive regime implemented by the Supervised Entity is sufficient and effective in its design and application.
The Auditor must consider in their Risk Analysis, among others, the following variables:
a) Products and services offered by the Supervised Entity. b) Type of clients and users with whom the Supervised Entity operates. c) Countries and geographic areas in which the Supervised Entity operates. d) Transactions and channels of shipment or distribution linked to the operations of the Supervised Entity. e) Technological Infrastructure with which the Supervised Entity is equipped.
III. Review of all relevant information and documentation for the performance of the audit. This review must be recorded and, if applicable, presented to the Supervised Entity in question for objective evidence purposes.
Additionally, the Risk Analysis referred to in these guidelines must serve the Auditor to verify that the Risk evaluation methodology, which according to the Provisions the Supervised Entities are obligated to perform, is coherent with the characteristics of the Supervised Entity in question.
SEVENTH. Work Program
The Auditor responsible for the Audit Report must design a program that contains, at least, the schedule of activities to be performed, the topics to be evaluated, including, among others, the performance of tests on automated systems, random reviews of Client or User identification files, and the material, technological, and human resources available to the Supervised Entity; as well as the manner in which the Supervised Entity will follow up on corrective actions implemented according to the Risks and areas of opportunity detected in matters of prevention of Operations with Resources of Illicit Origin and Terrorism Financing. The foregoing may be carried out within or outside the facilities of the Supervised Entity, as determined by both parties.
EIGHTH. Sections of the Audit Report
The Audit Report must consist of at least the following sections:
A. Results of the review
The Audit Report must include the result of the review of compliance with all obligations provided in the Provisions applicable to the Supervised Entity in question, including the following:
I. Regarding Client or User identification policies, they must contain at least, if the Supervised Entity:
a) Has a Compliance Manual with the criteria, measures, and internal procedures for the proper identification of the Client or User, based on the services, products, or Operations offered.
To comply with what is stated in this subsection, the Auditor must evaluate and state whether the content and application of the Compliance Manual is adequate for the services, products, or Operations offered by the Supervised Entity.
b) Identifies the Client or User in accordance with the profile, characteristics, and type of Client or User in question, as well as with the requirements established in the Provisions and in their Compliance Manual.
To comply with this subsection, the Auditor must review the records of the identification files of the Client or User in question, based on sampling methods to obtain a representative sample, in order to determine if the identification data are properly captured in their automated systems and integrated into the respective identification file.
Without prejudice to the foregoing, the auditor must consider carrying out a verification, based on the sampling method, of the integration of files of Clients or Users classified as High Risk Grade and include the result in the Audit Report.
In all cases, the Auditor must explain the sample selection criteria, state the number of file records that were part of said sample, and the percentage it represents of the total records or files with which the Supervised Entity is equipped, as well as the missing data and documents in each record or file reviewed.
c) In their case, if they apply Client or User identification and knowledge policies for those carrying out Operations in the Concentration Accounts of which said Supervised Entity is the holder, opened in another Supervised Entity.
d) Has the monitoring and aggregation mechanisms for Operations indicated in the Provisions, and, if applicable, those regarding the escalation of internal approval. In this case, it must be indicated what these mechanisms consist of and determine how they have been implemented by the Supervised Entity.
e) Has policies, criteria, measures, and procedures to verify Client or User identification files in accordance with their Risk Grade, as well as to reclassify them into the higher Risk Grade corresponding in case of detecting significant changes in their transactional behavior.
The Auditor must indicate whether the policies, criteria, measures, and procedures referred to in the previous paragraph have been implemented in accordance with the Supervised Entity's Compliance Manual.
f) Has carried out visits to the Client or User's domicile in accordance with the applicable Provisions, the cases in which such visits have been carried out, the results obtained from these, as well as the scheduling of future visits.
II. Regarding the development of a risk-based methodology, it must contain at least, if the Supervised Entity:
a) Established in their Compliance Manual, or in another document or manual prepared by the Supervised Entity, all processes that will be carried out for the identification, measurement, and mitigation of Risks, taking into account the Risk factors identified for this purpose.
b) Designed and implemented a methodology to carry out a Risk evaluation for those to which they are exposed derived from their products, services, Clients, and/or Users, countries or geographic areas, transactions, and channels of shipment or distribution with which they operate.
c) Considered, within the process of identifying Risk indicators, the total products, services, types of Clients and/or Users, countries or geographic areas, transactions, and channels of shipment or distribution with which the Supervised Entity operates.
d) Used a method for the measurement of Risks that establishes a relationship between Risk indicators and the element to which they belong, as well as whether they assigned a weight to each of them consistently based on their importance to describe said Risks.
e) Identified the Mitigants they had implemented at the time of the design of the methodology, considering all the policies, criteria, measures, and procedures indicated in their Compliance Manual, as well as their effective application, in order to establish the effect these will have on Risk indicators and elements.
f) In their case, modified the policies, criteria, measures, and procedures corresponding, contained in the Compliance Manual, or in another document or manual prepared by the Supervised Entity, in order to establish the Mitigants they considered necessary based on the identified Risks, as well as to keep them at an acceptable tolerance level in accordance with what is established in the Compliance Manual, derived from the results of the implementation of the Risk evaluation methodology.
g) In the implementation stage, the supervised entity put the risk evaluation methodology into operation, ensuring that there are no inconsistencies between the information incorporated into it and that which is in their automated systems, and used, at least, the information corresponding to the total number of Clients, number of operations, and amount operated corresponding to a period that cannot be less than twelve months.
h) Performed the valuation of the Methodology, reviewing its efficiency and effectiveness.
III. Regarding Client or User knowledge policies, it must contain at least, if the Supervised Entity:
a) Has the Compliance Manual containing the criteria, measures, and procedures for the proper knowledge of the Client or User in accordance with the Provisions.
b) Has criteria, measures, and procedures to determine the profile and transactional behavior of the Client or User. In this case, the Auditor must indicate what the criteria, measures, and procedures referred to consist of and determine how these have been implemented by the Supervised Entity.
c) Has a Risk evaluation model to determine the Risk Grade in which Clients or Users should be located, or, in their case, the criteria, measures, and procedures to classify Clients or Users based on their Risk Grade. The Auditor must state whether the model or the criteria, measures, and procedures allow the Supervised Entity to perform an adequate classification in accordance with what is established in the Provisions.
d) Has an alert system that allows them to follow up and timely detect changes in the transactional behavior of the Client or User. The Auditor must state whether the alert system is appropriate for the products, services, types of Clients and/or Users, countries or geographic areas, transactions, and channels of shipment or distribution with which the Supervised Entity operates.
e) Has criteria, measures, and procedures for the supervision of the transactional behavior of Clients or Users classified as High Risk Grade. The Auditor must indicate what the criteria, measures, and procedures indicated consist of and determine how these have been implemented by the Supervised Entity.
f) Has criteria, measures, and procedures related to Clients or Users considered Politically Exposed Persons. The Auditor must indicate whether the criteria, mechanisms, measures, and procedures referred to in this subsection have been implemented by the Supervised Entity in accordance with the Compliance Manual.
g) Has carried out Operations with Clients or Users considered Politically Exposed Persons and also of High Risk Grade, which have been approved in accordance with the Provisions. In this case, it must be indicated what the approval procedure for such Operations consists of, how such procedure is carried out, and whether it was applied adequately.
h) Has carried out Operations, which by their characteristics could generate a High Risk for the Supervised Entity itself, which have been approved in accordance with the Provisions. For the purposes of the foregoing, it must be indicated what the approval procedure for such Operations consists of, the manner in which such procedure is carried out, and whether it was applied adequately.
i) Has policies and procedures to identify the Beneficial Owner of the resources, as well as the beneficiary thereof. Additionally, it must indicate the manner in which such policies and procedures have been implemented by the Supervised Entity.
j) In their case, has criteria, measures, and procedures to identify the number, amount, and frequency of Operations carried out with Supervised Entities when these have the status of Client or User, indicating the manner in which such policies and procedures have been implemented by the Supervised Entity.
k) Has policies and procedures to identify Clients or Users who are within the List of Blocked Persons issued by the Secretariat, to any third party acting on behalf or for the account of said persons, as well as the Operations they have carried out. Likewise, it must be indicated how the policies and procedures have been implemented by the Supervised Entity.
IV. Regarding the submission of Operation reports to the Secretariat through the Commission, which shall contain, at least, if the Supervised Entity:
a) Submitted in a timely and proper manner, the Relevant Operation reports, in accordance with the Provisions and in the official format issued for this purpose. The Audit Report must indicate whether the reports included all Relevant Operations carried out by the Supervised Entity in the reported period, as well as those, if any, carried out through their Concentration Accounts.
b) Submitted in a timely and proper manner the reports for each Unusual Operation alerted by their system, model, process, or employee, in accordance with the Provisions and in the official format issued for this purpose. Likewise, it must be indicated whether such Operations were adjudicated by the Committee or, if applicable, by the Compliance Officer.
Likewise, it must be stated whether the Committee or, if applicable, the Compliance Officer performed, in accordance with the Provisions and the Compliance Manual, the analysis of those Operations presented for valuation and which were not adjudicated as Unusual Operations.
c) Submitted in a timely and proper manner the 24-hour Reports, in accordance with what is established in the Provisions and in the official format issued for this purpose.
d) Submitted in a timely and proper manner the report of each Concerning Internal Operation alerted by their system, model, process, or employee, in accordance with what is established in the Provisions and in the official format issued for this purpose. In this case, it must be indicated whether such Operations were adjudicated by the Committee or, if applicable, by the Compliance Officer.
Likewise, it must be stated whether the Committee or, if applicable, the Compliance Officer performed, in accordance with the Provisions and the Compliance Manual, the analysis of those Operations presented for examination and which were not adjudicated as Concerning Internal Operations.
e) Submitted in a timely and proper manner the other reports, if any, provided for in the Provisions, such as reports on international fund transfers, operations in US dollars, cashier's checks, Virtual Assets, operations in foreign currency, as well as the report of total amounts of foreign exchange.
In the respective Audit Report, the Auditor must state whether such reports were presented complying with what is stated in the Provisions and if they were presented in the official format issued for this purpose.
The Auditor must state in the Audit Report the Operations that the Supervised Entity omitted to report, those that were presented outside the deadline established in the Provisions, and those that in their opinion might contravene them.
V. Regarding the integration of internal structures, which shall contain, at least, if the Supervised Entity:
a) Integrated the Committee in accordance with the Provisions.
b) Communicated in a timely and proper manner to the Secretariat, through the Commission, the initial integration of their Committee in accordance with the Provisions.
In case of not having such Committee, the Auditor must verify that the Supervised Entity complies with the exceptions established in the applicable Provisions not to constitute the aforementioned Committee and that they have communicated this, in a timely and proper manner, to the Secretariat through the Commission.
c) Submitted in a timely and proper manner, to the Secretariat through the Commission, the information corresponding to the integration and changes of the Committee referred to in the Provisions.
d) Performed the appointment or revocation of the Compliance Officer or the interim Compliance Officer in accordance with the Provisions and attending to the requirements indicated in these.
e) Communicated in a timely and proper manner, to the Secretariat through the Commission, the appointment or revocation of their Compliance Officer or interim Compliance Officer.
Additionally, the Auditor must include in the report a report of the functions and obligations performed by the Committee, the Compliance Officer, or interim Compliance Officer in accordance with the Provisions, as well as in accordance with the mechanisms, processes, deadlines, and procedures indicated in their Compliance Manual, or in another document or manual prepared by the Supervised Entity.
In case that the Auditor detects that the Supervised Entity did not adhere to what is provided in this subsection or the Provisions, they must include in their report the possible non-compliances and the reasons why they consider these occur.
VI. Regarding training and dissemination, it must contain, if the Supervised Entity:
a) Has an annual training program. It must be specified whether the training topics are coherent with the results of the implementation of the Risk evaluation methodology and if they are adequate to the responsibilities of the members of their respective boards of directors, executives, officials, employees, among others, depending on the Supervised Entity in question.
b) Provided training courses to the members of the Committee, the Compliance Officer, executives, officials, employees, proxies, and other persons, in terms of the applicable Provisions and their Compliance Manual.
c) Disseminated to the personnel cited in the previous subsection, the Provisions and their modifications, as well as information on techniques, methods, procedures, and trends to prevent, detect, and report Operations with Resources of Illicit Origin and Terrorism Financing.
d) Issued certificates accrediting the participation of their officials or employees in the training courses.
e) Has measures for the case of those officials or employees who do not obtain a satisfactory grade in the knowledge evaluations referred to in the Provisions. For this effect, it must indicate what these measures are and if, in case such a situation has occurred, they carried them out in accordance with their Compliance Manual.
VII. Regarding Technological Infrastructure, it must include whether the Supervised Entity has automated systems that perform all the functions indicated in the Provisions, as well as the manner in which it ensured that the system performs its functions.
VIII. Regarding employees who work in customer service or resource administration areas, it must be reported whether the Supervised Entity:
a) Has employee selection procedures that comply with what is stated in the Provisions. The manner in which said procedure has been implemented by the Supervised Entity must be indicated.
b) Has files for each of the employees, indicating whether said files are integrated in accordance with their selection procedures.
c) Has certificates or any other document that proves that its employees have received training in the subject, prior to or simultaneous with their entry or the start of their activities in said areas.
IX. Regarding the retention of information, it must contain at least whether the Supervised Entity:
a) Has mechanisms to conserve, for a period of no less than ten years in accordance with what is established in the Provisions, a physical copy or, where applicable, a digital version of, among others, the Transaction Reports provided for in the Provisions, as well as the data and documents that make up the identification files of Clients or Users.
b) Conserves for the period mentioned in the preceding subsection, a physical copy or, where applicable, a digital version of the Transaction Reports provided for in the Provisions, as well as the data and documents that make up the identification files of Clients or Users, among others.
c) Has mechanisms to conserve for a period of no less than five years, in accordance with what is established in the Provisions, the Audit Reports.
d) Conserves for the period mentioned in the preceding subsection, the Audit Reports.
X. Regarding lists, it must contain at least whether the Supervised Entity:
a) Has the officially recognized lists issued by Mexican authorities, intergovernmental groupings, or authorities of other countries, of persons linked to Operations with Proceeds of Illicit Origin or Terrorist Financing, or with other illegal activities.
The respective report must indicate whether the Supervised Entity has mechanisms that allow identifying the persons who are on the aforementioned lists, and whether said mechanisms are effective.
b) Has the list of Politically Exposed Persons that the Supervised Entities must prepare in accordance with the Provisions. The respective report must indicate whether the Supervised Entity has mechanisms that allow it to identify the persons who are on the aforementioned lists, and whether said mechanisms are effective.
c) Has the lists of countries or jurisdictions that Mexican legislation considers apply preferential tax regimes, indicating whether the Supervised Entity has mechanisms that allow it to identify the countries and jurisdictions that are on the aforementioned lists, and whether said mechanisms are effective.
d) Has the lists of countries or jurisdictions that, in the judgment of Mexican authorities, international bodies, or intergovernmental groupings in matters of prevention of Operations with Proceeds of Illicit Origin or Terrorist Financing of which Mexico is a member, do not have measures to prevent, detect, and combat said operations, or when the application of said measures is deficient.
The report must state whether the Supervised Entity has mechanisms that allow it to identify the countries and jurisdictions that are on the aforementioned lists, and whether said mechanisms are effective.
e) Has the List of Blocked Persons. It must be indicated whether the Supervised Entity has mechanisms that allow it to identify the persons who are on the aforementioned list, and whether said mechanisms are effective.
f) Has implemented the measures established in the Provisions in the event of identifying a Client or User on said lists.
XI. Regarding the exchange of information, it must contain at least whether the Supervised Entity:
a) Exchanged information in accordance with the form and terms established in the Provisions, as well as whether it communicated or presented to the Secretariat, through the Commission, or to the latter, as applicable, the information and documentation that so accredits it.
XII. Regarding Novel Models, it must contain at least whether the Supervised Entity:
a) Obtained the authorization of the Commission to operate with Novel Models.
b) Identified and evaluated the Risk to which it is exposed, prior to the launch of the product or service in question through Novel Models.
c) The evaluation referred to in the preceding subsection b) was carried out in accordance with the Risk-based approach of the Provisions applicable to it.
d) Presented to the Commission, together with its authorization request, the result of the evaluation referred to in the preceding subsections b) and c).
e) Complied with the Provisions applicable to it, according to the cases, forms, terms, deadlines, conditions, and exceptions indicated in its authorization by the Commission, prior to the opinion of the Secretariat.
f) Carries out the Operations indicated in the Provisions applicable to it, through the authorized Novel Model.
XIII. Of other information:
a) Where applicable, it communicated in due time and form, to the Secretariat through the Commission, the initial information on the identity of the person or group of persons who exercise Control, as well as any changes in said persons, in accordance with the Provisions.
b) Where applicable, it communicated in due time and form, to the Secretariat through the Commission, regarding the transmission of shares or social parts for more than two percent of its paid-up capital, in accordance with the Provisions.
c) Regarding money transmitters, if the notice containing the list of related agents and legal entities assisting with which each money transmitter has a contractual relationship and the third parties with whom the related agents and legal entities assisting operate were presented in due time and form.
d) Any other information that has been required from the Supervised Entity by the Commission.
e) Where applicable, the Auditor must report whether the Supervised Entity remedied the observations, recommendations, and corrective actions notified by the Commission.
f) If it has offices, branches, agencies, and subsidiaries, in national territory or abroad. Where applicable, the Auditor must verify whether the Supervised Entity complies with the obligations established in the Provisions in each of them.
XIV. Regarding the commission agents referred to in the Provisions. Stating whether the Supervised Entity carries out Operations through commission agents authorized to carry out Operations in the name and on behalf of the Supervised Entities themselves. In the affirmative case, it must contain, at least:
a) The results of the review of the obligations related to commission agents, established in the Provisions.
b) Whether the Supervised Entity allows the identification files to be integrated and conserved by its commission agents.
c) The results of the review that, where applicable, the Auditor has made on one or more of the commission agents through which the Supervised Entity carries out Operations, in order to know their regime for the prevention of Operations with Proceeds of Illicit Origin and Terrorist Financing. In the event that said review is not carried out, the respective justification must be incorporated instead, which exposes the reasons why the Auditor did not consider it necessary.
B. Regulatory Compliance
The evaluation of each of the obligations referred to in the previous section A must be in any of the following five senses:
The evaluation can only be in this sense when it is demonstrated that no improvements are required or recommended for the compliance with the obligation in question.
In this case, the Auditor must include at least one improvement recommendation and, where applicable, some findings, which must be identified in the evaluated obligation.
In this case, the Auditor must include at least one finding and, where applicable, one or more improvement recommendations, which must be identified in the evaluated obligation.
In this case, the Auditor must include at least one finding, which must be identified in the evaluated obligation.
C. Key Audit Matters
If required, the Auditor will develop a section in which it clearly describes the aspects, conditions, or concerning information that it considered when carrying out the audit of the Supervised Entity.
It is considered concerning when during the course of the audit, the Auditor knows or determines that the measures implemented are not appropriate to the type of services, products, or Operations offered and carried out by the Supervised Entity; when operationally it considers that there is no efficacy in the controls implemented to mitigate Risks; when there are findings that fall within some serious infringement in terms of the applicable Laws; or when it detects irregularities that based on its professional judgment could favor, provide help, assistance, or cooperation of any kind for the commission of the crimes provided for in articles 139 Quater or 400 Bis of the Federal Penal Code.
D. Findings, corrective actions, and improvement recommendations
The Audit Report must contain a section in which it includes the findings with their corresponding corrective action or actions, as well as the improvement recommendations that, in the Auditor's judgment, are required to fully comply with the Provisions, including the deadlines, the responsible persons for their implementation, as well as for the supervision of these.
Additionally, it must contain the follow-up that the Supervised Entity carried out regarding the findings and corrective actions related to the Audit Report presented in the immediately preceding year.
Where applicable, it must also contain a section in which it indicates the follow-up that the Supervised Entity carried out regarding the observations, recommendations, or corrective actions that have been formulated by the Commission in the immediately preceding year.
SECTION D
OF THE AUDIT REPORT
NINTH. Drafting and structure of the Audit Report
The Audit Report must be drafted in Spanish, with a font of at least 10 points, have an index, and be divided into sections, chapters, subsections, paragraphs, or any other format that facilitates its reading and comprehension, which must be highlighted in bold to differentiate the respective divisions and, where applicable, have annexed the documentation that served as the basis for its preparation.
TENTH. Evidence and documentation supporting the Audit Report
The statements and data contained in the Audit Report must be supported by evidence that allows accrediting their truthfulness, so the Auditor must justify each of them and specifically indicate and relate the evidence, as well as, where applicable, the documentation that was analyzed, endeavoring to cite the full text of the document to which reference is made and indicate the identification data of this.
ELEVENTH. Knowledge and submission of the Audit Report
The general management and the Committee or, where applicable, the Compliance Officer, of the Supervised Entities must know the content of the Audit Report, in order to evaluate the operational efficacy of the implemented measures and follow up on corrective action programs.
The Audit Report must be made known to the Commission through the SITI PLD/FT, through a written document signed by the legal representative, sole administrator, or Compliance Officer, in which it informs the date on which the general management and the Committee or, where applicable, the Compliance Officer knew the content of the Audit Report, the review period, the full name without abbreviations of the Auditor designated for its preparation, as well as the number and date of its Certificate, as well as, where applicable, the name of the Legal Person that has been hired for the preparation of the report.
The Supervised Entities must send to the Commission at the time of delivery of the Audit Report through the SITI PLD/FT, the letter referred to in guideline FOURTH, second paragraph, subsection d).
The Supervised Entities must present to the Commission the Audit Report in accordance with the form and terms contained in these guidelines, in Portable Document Format (PDF) document format, with accessibility configuration that allows text selection and data search in the document content, and in accordance with the specifications for its sending contained in the "Notices" section of the SITI PLD/FT portal on the Commission's website.
TWELFTH. Conservation
The Supervised Entities must conserve all information and documentation generated as a result of these guidelines for a period of no less than five years, counted from the time they send their Audit Report and keep it available to the Commission, at the request of the latter.
TRANSITORY PROVISIONS
FIRST. These Guidelines will enter into force the day following their publication in the Official Gazette of the Federation.
SECOND. The "Guidelines for the preparation of the audit report to evaluate compliance with the general provisions in matters of prevention of operations with proceeds of illicit origin and terrorist financing", published in the Official Gazette of the Federation on January 19, 2017, are repealed.
Read the rest free
Source: Comision Nacional Bancaria y de Valores — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from CNBV
CNBV published 1 document in the last 30 days. We email you each new one the day it's published.