2018-11-16 | DOF 5544145Added
The National Retirement Savings System Commission modifies and adds provisions to the General Provisions on Operations of the Retirement Savings Systems to allow the use of biometric authentication models and non-presential mechanisms, such as mobile applications, for worker services. Administrators are required to contact workers aged 60 or older regarding their individual accounts and retirement options, and must simplify registration and transfer processes by removing certain documentation requirements. The regulation also establishes rules for the administration of individual accounts for minors and mandates information security measures for administrators, operating companies, and service providers.
DOF: 16/11/2018
MODIFICATIONS AND ADDITIONS TO THE GENERAL PROVISIONS ON OPERATIONS OF THE RETIREMENT SAVINGS SYSTEMS
At the margin, a seal with the National Coat of Arms, which says: United Mexican States.- Ministry of Finance and Public Credit.- National Commission of the Retirement Savings System.
MODIFICATIONS AND ADDITIONS TO THE GENERAL PROVISIONS ON OPERATIONS OF THE RETIREMENT SAVINGS SYSTEMS
The President of the National Commission of the Retirement Savings System, based on what is provided in articles 1, 2, fractions I, II, III, IV, VI, VII, XIII bis and XVI, 12 fractions I, VI, VIII and XVI, 18, 18 bis, 19, 20, 21, 25, 26, 29, 30, 31, 36, 37, 37 A, 37 C, 39, 40, 41, 43, 47, 47 bis, 53, 57, 58, 59, 64, 64 bis, 64 ter, 65, 70, 74, 74 bis, 74 ter, 74 quáter, 74 quinquies, 76, 77, 78, 79, 80, 88, 89 90 fractions II, IV and XIII, 91, 99, 111 and 113 of the Law of the Retirement Savings Systems; 167, 175, 176, 177, 179, 181, 182, 187, 188, 191 fraction II, 192, 195, 198 and 200 of the Social Security Law; 2, 13, 21, 26, 64, 76, 77, 78, 83, 87, 91, 93, 97, 98, 100, 101, 102, 105 fraction VII, 106, 108 fraction II, paragraph c, 119 and 123 fraction II, as well as Fifth, Seventh, Tenth, Eleventh, Twenty-second, Twenty-fourth, Twenty-fifth, Twenty-sixth and Twenty-seventh Transitional of the Decree by which the Law of the Institute of Security and Social Services of State Workers is issued; 1, 5 last paragraph, 29 fraction II, 34, 38, 40, 43, 43 bis and Eighth Transitional of the Law of the National Housing Fund for Workers; 1, 14, 15, 16, 23, 25, 28, 29, 30, 31, 32, 33, 34, 35, 37, 38, 39, 40, 41, 42, 43, 44, 45, 46, 47, 48, 49, 50, 51, 52, 53, 54, 55, 59 61, 62, 63, 64, 65, 66, 67, 68, 69, 70, 71, 72, 73, 74, 75, 76, 77, 78, 79, 80, 81, 82, 83, 84, 85, 86, 87, 88, 89, 90, 91, 92, 93, 94, 95, 96, 97, 98, 106, 109, 110, 111, 112, 113, 114, 115, 116, 117, 118, 119, 120, 121, 122, 123, 139, 140 and 154 of the Regulations of the Law of the Retirement Savings Systems; 1, 2 fraction III and 8 first paragraph of the Internal Regulations of the National Commission of the Retirement Savings System, and
CONSIDERING
That the global trend of using technological tools known as "RegTech" for compliance with regulatory requirements makes it essential to allow Participants in the Retirement Savings Systems to develop and implement biometric authentication models and non-presential mechanisms to facilitate the completion of any procedure, with the aim of significantly reducing regulatory compliance costs and optimizing inherent processes;
That it is imperative that Administrators, in compliance with the objective of attending to the interest of Workers who are closest to retirement, implement a contact mechanism with this sector, to inform them about the rights related to their Individual Account, as well as the retirement options and the procedures they must carry out to exercise, if applicable, their pension rights in a timely and informed manner;
That in recent years, advances in the use of information and communications technologies in the Mexican Financial System have brought multiple advantages; however, at the same time, they have caused an increase in the number of cyberattacks, diminishing the reputation, credibility, and assets of some financial sectors, which makes it imperative for financial authorities and their regulated entities to take actions to detect and prevent these risks;
That on May 24, 2018, the Authorities of the Mexican Financial Sector, the Attorney General's Office and the Trade Associations of the various financial entities in the country, signed the Coordination Bases in matters of Information Security; as a result of the foregoing, this Commission, within the scope of its respective competence, considers it necessary to update the regulation in matters of information security, particularly the requirements and practices that Administrators, Operating Companies and Service Providers must observe to mitigate acts that put the confidentiality, integrity and availability of information in the Retirement Savings Systems at risk;
That with the aim of facilitating the effective exercise of the rights of Workers who may require the Certificate on the Implications of the Transfer, it is considered necessary that this process be carried out through the Mobile Application, which will allow reducing costs for both applicants and Participants in the Retirement Savings Systems, since it can be requested at any time and remotely;
That with the objective of implementing public policies for regulatory improvement for the perfection of regulations and the simplification of procedures in the Retirement Savings Systems, it is necessary to simplify the Registration and Transfer process, so that attention and response times are made more efficient, and therefore it is convenient to dispense with various elements related to the Certificate of Registration and Transfer;
That with the object of regulating and maintaining the good functioning of the Retirement Savings Systems, it is appropriate to issue the pertinent provisions that regulate the participation of third parties who assist Administrators in the implementation of technological models, initiatives that stimulate voluntary savings or other aspects of financial inclusion through innovations, pilots and studies;
That with the purpose of promoting financial inclusion in the Retirement Savings Systems, it is necessary to regulate and provide legal certainty to Administrators, regarding the administration of Individual Accounts of minors with normative precision regarding their characteristics and functioning, and
That the Ministry of Finance and Public Credit, through this Commission, complies with what is established in article 78 of the General Law of Regulatory Improvement, as well as in article Fifth of the "Agreement that establishes the guidelines that must be observed by the dependencies and decentralized bodies of the Federal Public Administration, regarding the issuance of general administrative acts to which article 69-H of the Federal Administrative Procedure Law applies", in accordance with what is detailed in these modifications and additions, which derogate forty-one obligations that generate benefits and savings greater than the implementation costs, has seen fit to issue the following:
MODIFICATIONS AND ADDITIONS TO THE GENERAL PROVISIONS ON OPERATIONS OF THE RETIREMENT SAVINGS SYSTEMS
FIRST.- The articles 1, fraction LII bis, 4, with fraction VII; 14, with a fourth paragraph; 23 ter; 62 bis; 62 ter; 90, with fractions V and VI and a second paragraph in fraction IV; 90 bis; 149 bis with a fourth paragraph; 160, fraction VII; 180, fraction III with a paragraph c and a fourth paragraph; 210 quáter; to Chapter III "On the administration of individual accounts", a section VII "On the Administration of Individual Accounts of Minors", with articles 243 bis and 243 ter; 248, with a fourth paragraph, moving the current fourth and fifth paragraphs to become fifth and sixth respectively, 274 bis; 274 ter; 274 quáter; 337 bis; 337 ter;
ARE MODIFIED articles 1, fractions IV, IX bis, XII, LXI bis, LXVI, LXXIII, CXXX bis and CXXXVI; 4, fractions V and VI; 5, sixth paragraph; 12, second paragraph; 14, third paragraph; 23 bis; 57 fraction II; 90, fraction III; 92, fraction II, paragraph b, paragraph c, of paragraph d, its numeral i, paragraph f and its numeral iv; 129 second paragraph; 139; 148, fractions III and V; 149 bis second paragraph; 149 bis A, paragraph b; 149 bis E, fractions I and II; 150, fraction III; 153, first paragraph; 155 first paragraph; 156 fraction I, paragraph a; 168, fractions III and VIII and last paragraph; 172, first and second paragraphs; 173, fraction III; 176 first paragraph; 179, second paragraph; 180, fraction I, paragraph e, fraction III, second and third paragraphs, and paragraph a; 182, first paragraph; 189, fractions II, to become II and II bis, VI and XI; 195 third paragraph; 210 bis, first, second and third paragraphs; 214, first paragraph; 217, first and third paragraphs, and fraction II; 219, fraction VI; 229, first, second and fourth paragraphs; 248, first and third paragraphs; 249; 250; 258, first paragraph; the denomination of Section I of Chapter VIII; 296, first and second paragraphs, and paragraph a of the fifth paragraph; 297; 298; 299; 300, third and fourth paragraphs; 301 first and second paragraphs; 302; 309, second paragraph; 329; 346 first paragraph; 387 bis, last paragraph; 406 ter, fraction II; 419, first paragraph; 437; Annex B, fractions III, V and last paragraph, and Annex M and ARE DEROGATED articles, 9 fractions III and VI; 136; 137; 138; 148, its last paragraph and paragraph a of fraction II, 158, fractions II and III, of the second paragraph its paragraphs b and c; 160, fraction IV; 168, paragraph a of fraction II; 183, paragraph a of fraction I; 185, fractions II and III and paragraphs b and c of the second paragraph; 210 bis, its last paragraph and fractions I and II of the first paragraph, and 424, the second paragraph of fraction I, to remain in the following terms:
GENERAL PROVISIONS ON OPERATIONS OF THE RETIREMENT SAVINGS SYSTEMS
TITLE FIRST GENERAL PROVISIONS
"Article 1.
... :
I. to III ...
IV.
Service Agent, the person hired or subcontracted by the Administrator, authorized to intervene in the formation, updating and validation of the Worker's Identification Files, as well as to receive and attend to service requests in accordance with the provisions on user service of the Retirement Savings System issued by the Commission, as well as other procedures that Workers request from Administrators in terms of these general provisions;
V. to IX. ...
IX bis.
Mobile Application, the remote operation software application composed of a set of computer modules that allows corroborating the data and information of Workers that provides for the Factor of category 3 authentication referred to in Annex B of these general provisions and that partially or totally allows, through said modules, to process information generated by Workers directly or through Support Companies, which is sent to Administrators or Operating Companies for processing;
X. to XI. ...
XII.
Long-Term Savings Contributions, the amounts paid by Workers to the subaccount provided for in fraction VII of article 35 of the Regulations, and to which the tax incentive referred to in article 185 of the Income Tax Law is applied;
XIII. to LII. ...
LII bis.
Support Company, the legal entities that Operating Companies or Administrators hire, directly or through Operating Companies, to provide counter services to Workers to facilitate Mobile Registration and other services authorized by the Commission, in accordance with these general provisions;
LIII. to LXI. ...
LXI bis.
Mobile File, the set of images and individual, ordered and detailed information stored in Electronic Media in accordance with article 149 bis D of these general provisions and which allow the identification of persons in the Retirement Savings Systems;
LXI ter. to LXV. ...
LXVI.
Biometric Signature, the signature made by a person through the impression of their biometric elements, captured and stored in Electronic Media, which attest to their will and allow corroborating their identity in the Retirement Savings Systems, through the recognition of unique biometric characteristics registered in the Biometric Enrollment, whether through fingerprint, or voice, facial or any other biometric element authorized by the Commission;
LXVII to LXXII. ...
LXXIII.
Complaint or Service Folio, the unique folio that Administrators must assign to each of the service requests or complaints presented by Workers or Beneficiaries, as applicable, whether through the Specialized Unit, offices, branches, the Administrator's telephone call center, the Website or any other attention means that Administrators have available to Workers and the general public;
LXXIV. to CXXX. ...
CXXX Bis.
Unique Biometric Seal, the data chain generated and assigned by Operating Companies or Administrators authorized by the Commission to each Biometric Signature by which the biometric identity of the Worker, officials and employees of the Administrators concerned is verified in accordance with the Biometric Enrollment registered in the National SAR Database;
CXXXI. to CXXXV. ...
CXXXVI.
Information Reception System, the system administered by Operating Companies through which Dependencies, Entities and Insurers must make the payment of Quotas and Contributions, Voluntary Savings, discounts and other payments, as applicable, to be made to the Individual Accounts of ISSSTE Workers;
CXXXVII. to CLXIV. ... "
"Article 4.
...
The Manual of Policies and Procedures must contain at least the following sections:
I. to IV. ...
V.
Resource Disposition,
VI.
Information Security, Operational Continuity and Operational Risk, and
VII.
That which is established in accordance with the other general provisions issued by the Commission. "
...
...
...
...
...
...
"Article 5. ...
...
...
...
...
...
The Transactional Procedures Manual will detail the operation of Electronic Media and the Information Reception System, the participation that Administrators, Social Security Institutes, Workers, Dependencies, Entities and Insurers must execute, as well as for the exchange of information for the payment and deposit of resources, the registration and updating of information and the other information necessary for the deposit of resources in the Individual Accounts of Workers.
... "
"Article 9 . ... :
I. to II. ...
III.
Is derogated.
IV. to V. ...
VI. Is derogated.
VII. to IX. ...
...
...
a) to f)
... "
"Article 12.
...
Service requests for account administration that Administrators receive in accordance with what is provided in this article, must be attended, followed up and resolved within the deadlines provided for each of the processes in these general provisions. Likewise, Administrators must assign a Complaint or Service Folio to each of the requests from Workers or Beneficiaries they receive in terms of this article.
... "
"Article 14.
...
...
At least once a year, Administrators must contact by telephone or certified mail with receipt acknowledgment Workers who are 60 years of age or older, who have not started their pension procedure, in order to inform them of the characteristics of their Individual Account, the retirement options they have and the procedures they must carry out to obtain the pension that corresponds to them, if applicable. Administrators must keep evidence of contact with the Worker. When the Worker is 65 years of age or older, the Administrator concerned must communicate to the Worker in the sending of each account statement that, if applicable, they have resources that they can dispose of in accordance with what is established in article 408 of these general provisions. While the Worker has not been contacted as established in this paragraph and while they have not started their pension procedure, such sending must be through certified mail, or through email if the Worker expressly requested it and Administrators must keep evidence of the sending of the email and the result of contact with the Worker.
Administrators may only suspend the attempt to contact and the sending of communications to the Worker established in the preceding paragraphs when, after the third contact attempt, they are sure that the provided address does not exist, or that the Worker or Unaffiliated Worker does not have their domicile at the indicated place, as well as when they do not have data that allows them to contact the Worker. "
"Article 23 bis. Operating Companies must generate and send to the Administrator concerned, a Unique Biometric Seal every time the Worker provides their Biometric Signature, for any of the presential services referred to in article 209 of these general provisions, in accordance with the criteria, guidelines and exceptions established in the Transactional Procedures Manual. "
"Article 23 ter . Administrators may implement the use of authentication models that use biometric validation elements to generate a folio to be used in substitution for the alternative authentication factor of the Unique Biometric Seal; for this purpose they must request from the Commission the authorization referred to in article 62 ter of these general provisions. "
"Article 57. ... :
I. ... ;
II. Register their shares in the National Securities Registry and in a stock exchange authorized to organize and operate in terms of the Securities Market Law, and
III. ... "
"Article 62 bis .- Administrators may develop biometric authentication models that substitute the Unique Biometric Seal and that allow identifying Workers when they request any service referred to in article 209 of these general provisions. These models must be designed in such a way that they are linked to the infrastructure developed by Operating Companies so that these can recognize the folios issued by the referred models.
For the purposes of this article, biometric authentication models are those Online and Real-Time authentication processes that confront the biometric data provided by the Worker against official identifications, identification files and official databases operated by authorities of the Federal Public Administration, Autonomous Constitutional Bodies and national entities authorized, supervised and regulated by financial authorities of the Federal Public Administration, which allow identifying Workers, when they go to request any of the services referred to in article 209 of these general provisions.
Administrators that implement the models referred to in this article, must celebrate confidentiality agreements with the third parties referred to in the previous paragraph so that Worker information is used only for the management of the procedure they request. Administrators are responsible at all times for compliance with the applicable personal data protection regulations.
"Article 62 ter. Administrators that require developing the biometric authentication models referred to in the previous article, must present to the Commission an authorization request which must contain at least the following:
I.
Object;
II.
Services that will be provided using the model;
III.
Description of the model;
IV.
Start of operations date;
V.
Technical and operational feasibility analysis of the biometric authentication model for its operation;
VI.
Description of mechanisms that guarantee the security, integrity and confidentiality of the biometric information provided by the Worker through the biometric authentication model;
VII.
Generation and availability of audit logs that allow verifying that information that serves as evidence for the determination of compliance with the biometric authentication model; said logs must be available to the Commission, and
VIII.
Any other element that the Administrator considers necessary to facilitate the analysis of the request by the Commission.
The Commission, in terms of what is provided by the Law, may require the requesting Administrator any additional information it considers necessary to, if applicable, pronounce itself regarding the authorization of the model.
The authorization that the Commission issues, if applicable, will have a validity of three years, which may be renewed for equal periods, provided that such request is presented by the interested Administrator at least thirty business days prior to the expiration date.
The confrontation and comparison that is carried out using the biometric authentication models referred to in the preceding paragraphs, may be carried out by Administrators through third parties that have been evaluated by the Administrators themselves, considering a risk and vulnerability analysis, and that according to said evaluation, the Administrator determines that the model meets the characteristics indicated in Annex B, Authentication Factors, of these general provisions.
Administrators must ensure that the functioning and operation of the biometric models authorized to them in terms of this article, are subject to the current regulations in the Retirement Savings Systems.
Operating Companies must accept the folios issued by the biometric authentication models authorized by the Commission.
In the event that the authorized biometric authentication models cease to meet the necessary requirements for their operation or do not guarantee the security of the transactions or of the Worker's biometric information, the Commission may order the suspension of the operations of said models or revoke their authorization. "
"Article 90.
...
I. to II. ...
III.
Control the use and access to information, that they obtain in the exercise of their functions or through Promoter Agents, Service Agents, officials, employees and other persons who provide their services; as well as verify that these do not store, accumulate, disseminate or concentrate personal data of Workers, for purposes other than those
..."
established for the Retirement Savings Systems.
...
IV.
The contingency plans referred to in this subsection must be updated at least once a year or sooner, in the event that the participant makes a modification to the infrastructure, suppliers, processes, or operational responsibilities; likewise, comprehensive tests of the contingency plans must be carried out covering all processes that support operations and that allow continuing to provide all services to users, as well as complying with all requirements established by current regulations with a frequency that does not exceed twelve calendar months counted from the last test performed.
V.
Have the necessary human and material resources to allow them to operate the information technologies they possess in accordance with technological and cybersecurity security standards aimed at protecting information related to the Retirement Savings Systems, the personal data of Workers and their resources.
VI.
Integrate a specific area or unit that constitutes part of the structure of the Administrator, the Operating Companies, and Service Providers, responsible for aspects related to the administration of Technological Risk, technological and cybersecurity, as well as the security of information that is processed, transmitted, and safeguarded through information technologies referred to in Article 92 of these general provisions.
The area or unit referred to in this subsection must have personnel certified in cybersecurity matters; such certifications must be endorsed by international standardization bodies.
Additionally, they may have risk transfer mechanisms contracted with insurance entities or other entities that provide them to cover or mitigate the following:
a.
Events that compromise technological security;
b.
Events that compromise cybersecurity;
c.
Events that compromise information security;
d.
Events that compromise the security of information technologies, and
e.
Events that update any other Technological Risk. "
" Article 90 bis. The Administrators, Operating Companies, and Service Providers, through their trade associations, may establish groups, channels, or communication media that allow them to identify, communicate, disseminate, or detect possible vulnerabilities, threats, technological risks, and/or operational process risks, so that they allow them to attend or react in a timely manner to threats or risks to the security, confidentiality, and availability of information in the Retirement Savings Systems. "
" Article 92.
... :
I. ...
a. to h. ...
...
...
II.
... :
a.
...
b.
Evaluate at least once a year, the sufficiency, integrity, consistency, and degree of integration of the technological systems they use in information processing, as well as for risk analysis and its content;
c.
Evaluate at least once a year, the vulnerability to which they may be exposed in hardware, software, systems, applications, security, information recovery, networks, and any other type of information technology they implement, due to processing or operational errors, failures in procedures, inadequate capabilities, and insufficiencies of installed controls, among others. Likewise, at least once a year, they must carry out an audit, through a qualified and certified company in information security by an international standardization body, on the vulnerabilities referred to in the preceding paragraph, reporting the results of the audit to the Commission by the last business day of the month immediately following the receipt of the corresponding report, including a work program to strengthen and minimize the detected vulnerabilities;
d.
...
i.
Maintain updated policies and procedures that ensure at all times the quality levels of services, as well as the security and integrity of information. This, with emphasis in cases where Administrators hire external providers for the processing and storage of such information;
ii.
...
iii.
...
e.
...
f.
In the case of Web Pages, mobile devices, call centers, Specialized Units, offices, branches, or other Electronic Media, that are available to Workers, consider the following:
i. to iii.
...
iv.
Design, implement, and keep contingency plans updated, in order to ensure the capacity and continuity of the systems implemented to provide various services and operations, through Electronic Media. These plans must also include the necessary measures to minimize, control, and repair the effects generated by eventualities that, if any, were to affect the continuous and permanent functioning of the services.
The contingency plans referred to in this section must be updated at least once a year or sooner, in case the participant makes a modification to the infrastructure, systems, suppliers, processes, or operational responsibilities. Likewise, they must perform tests on these contingency plans with a frequency that does not exceed twelve calendar months counted from the last test performed.
v.
...
1 and 2. ...
III. ...
a. to d. ... "
" Article 129.
...
For this purpose, the Operating Companies must determine the age of the Workers, taken based on the guidelines established for this purpose by the Commission, and integrate into homogeneous groups the Individual Accounts for assignment and reassignment, distinguishing in the latter case if they are Reassigned for the first time or for subsequent Reassignments, taking into consideration the age of the Workers, the base salary for contributions, the number of contributions registered in the individual accounts, and the geographic location of the IMSS sub-delegation, as provided in the Transactional Procedures Manual. "
" Article 136. Repealed. "
" Article 137. Repealed. "
" Article 138. Repealed. "
" Article 139. The Operating Companies must assign a folio to the Registration or Transfer Request that is unique and non-repetitive, which must adhere to the guidelines, criteria, and characteristics established for this purpose in the Transactional Procedures Manual. The folio must be printed on said request.
The Operating Companies must send Online and in Real Time to the Worker the folio of the Registration or Transfer Request. The Operating Companies must establish criteria that allow the folio to be associated with the information of the Worker's Individual Account and that contained in the Registration or Transfer request.
The folios of the Registration or Transfer Requests will have a validity of ten business days counted from their date of issuance. Within that period, the folios will be valid until the date of signature of the Registration or Transfer Requests. "
" Article 148.
... :
I. ...
II.
Ensure that the Worker signs their full name, Biometric Signature, and Digital Handwritten Signature, with which they manifest that they know the scope, its content, and that it is their will to carry out the procedure, in the following documents:
a.
Repealed.
b. to d. ...
...
III.
Obtain the Folio for the Registration Request referred to in the previous Article 139;
IV. ...
V.
Register and store a video containing the Worker's manifestation expressing their consent for Registration and confirming their personal and contact data, in accordance with the characteristics established in the Transactional Procedures Manual. The Administrators will be responsible for the safeguarding and conservation of the video, keeping it available to the Commission and implementing the necessary security measures to guarantee that it is not manipulable.
Repealed. "
" Article 149 bis. ... :
I. to II. ...
The Mobile Registration request will have a validity of 5 business days counted from the generation of the Mobile Registration request made by the Worker. A new Mobile Registration request cannot be made for the same Worker during the validity of the request or, if applicable, until such request is rejected by the Administrator. The Commission will establish the design of the Mobile Registration request.
...
When the Administrators directly or through Support Companies facilitate the Mobile Registration procedure through any of the modules of the Mobile Application on electronic devices that are not owned by the Worker, they must record at the time of carrying out the Mobile Registration procedure, a video containing the Worker's manifestation expressing their consent for Mobile Registration and confirming their personal and contact data, in accordance with the characteristics established in the Transactional Procedures Manual; said video must be stored by the Administrators.
Likewise, the Administrators must keep said videos available to the Commission and implement the necessary security measures to guarantee that the data and information generated are not manipulable. "
" Article 149 bis A. ... :
a. ... , and
b.
Mark the Mobile Registration request as pending certification in the National SAR Database, when it concerns Workers assigned or pending assignment, in accordance with what is provided in the Transactional Procedures Manual.
... "
" Article 149 bis E.
... :
I.
In the event that the Worker who requests Mobile Registration is Assigned, request the Operating Companies to certify the Mobile Registration to update the data in the National SAR Database, and
II.
In the event that the Worker who requests Mobile Registration is Not Affiliated, request the Operating Companies to exempt the process of cleaning the National SAR Database.
...
...
... "
" Article 150. ... :
I. to II. ...
a. to e. ...
III.
Folio of the Registration Request or the folio that replaces it and that is generated by the Operating Companies through the Mobile Application;
IV. to V. ...
VI. ...
a. to c. ...
VII and VIII. ...
...
... "
" Article 153. The Administrators must ensure that the Workers or Beneficiaries, if applicable, sign their Digital Handwritten Signature, in the case of Workers, additionally they must sign their Biometric Signature on the Registration Request, through the Electronic Media made available by the Administrators, once the Request has been properly integrated.
... "
" Article 155. The Administrators, through their operations area, must establish verification controls oriented to ensure the identity and guarantee the exercise of the will of the Workers, the application of these controls being the exclusive responsibility of the Administrators. The verification controls established by the Administrators must consider, at least, the review of a statistically representative sample with a confidence interval not less than ninety percent, of the Workers' manifestations stored in the videos obtained at the time of processing the Registration Request, against the information contained in the Registration Request.
...
...
...
...
...
... "
" Article 156. ... :
I.
The measurement of the risk of process management, through a risk system by scores that includes, at least:
a.
The results of the verification of the Workers' manifestations in the videos obtained at the time of the Registration procedure, and
b.
...
II. to IV. ...
... "
" Article 158. ... :
I.
...
II.
Repealed.
III.
Repealed.
... :
a.
...
b.
Repealed.
c.
Repealed.
...
...
.... "
" Article 160.
... :
I. to III. ...
IV.
Repealed.
V. to VI. ...
VII.
That the cell phone number registered by the Worker in the Registration Request, if applicable, associated with the Mobile Application, does not belong to the cell phone of another Worker registered in the National SAR Database for at least a period of four months;
... :
a) and b) ...
... "
" Article 168. ... :
I.
... ;
II.
... :
a.
Repealed.
b. to d. ...
...
III.
Obtain the Folio for the Transfer Request referred to in the previous Article 139 ;
IV.
... ;
V.
... :
a. to c. ...
VI. to VII. ...
VIII.
Register and store a video containing the Worker's manifestation expressing their consent for the Transfer and confirming their personal and contact data, in accordance with the characteristics established in the Transactional Procedures Manual. The Administrators will be responsible for the safeguarding and conservation of the video, keeping it available to the Commission and implementing the necessary security measures to guarantee that it is not manipulable.
The Administrators who opt for the use of the Mobile Application may substitute the Folio of the Account Statement and the digitized image thereof, referred to in subsection V of this article. "
" Article 172. The Receiving Administrators must use the personal information contained in the Worker's Identification Files to generate and pre-fill the Transfer Requests, fund administration contracts for retirement, and Net Performance Documents. The Receiving Administrators must use mechanisms that guarantee the integrity, security, and confidentiality of the information to automatically extract the information from the Worker's Identification Files and pre-fill the information in the documents referred to in this article.
The Administrators must ensure that under no circumstances the information contained in the Worker's Identification File is available or stored on any electronic device or medium or any other form, for a period greater than ten business days from the date of extraction of the information. The information extracted from the Worker's Identification File must exist only in the Transfer Request, the fund administration contract for retirement, and the Net Performance Document; which must remain safeguarded in the computer systems determined by the Receiving Administrator, under mechanisms that guarantee the integrity, security, and confidentiality of the information, as well as audit logs that allow verifying the correct management of the information in the consulted File.
...
... "
" Article 173. ... :
I. and II. ... :
a. to e.
... ;
III. Folio of the Transfer Request or the folio that replaces it and that is generated by the Operating Companies through the Mobile Application;
IV. to X. ...
...
...
... "
" Article 176. The Receiving Administrators must ensure that the fund administration contracts for retirement, the Net Performance Documents, and the Transfer Requests made available to the Workers comply with the requirements provided in Annexes "A", "C", and "E" of these general provisions, are valid, personalized, and that the fields for the Workers and Promoter Agents to enter their Biometric Signature and Digital Handwritten Signature are within the same document and in the Worker's view.
...
... "
" Article 179.
...
The folio numbers that the Administrators assign to the records on the implications of Transfer must be unique and non-repetitive.
...
... "
" Article 180 .
... :
I.
... :
a.
to d. ...
e.
Receive from the Workers the notices in which they manifest not having received the record on the implications of the Transfer in accordance with the assumptions described in subsection III of this article.
II.
... :
a.
to d. ...
III.
... :
a.
If the address provided by the Worker when requesting the record on the implications of the Transfer in the E-SAR does not correspond to a Metropolitan Area where the Administrator has offices, branches, or a Specialized Unit, the Transferring Administrator must deliver the record on the implications of the Transfer, either to the address or email provided by the Worker through the E-SAR, within a period not exceeding ten business days counted from when the Worker makes the request through the E-SAR. The Administrator will determine if the record will be sent to the address or the email.
b.
...
c.
If the Worker requested their record on the implications of the transfer through the Mobile Application, using the Authentication Factors category 3 referred to in Annex B of these general provisions, the Transferring Administrators must send said Record within a period between five and seven business days counted from the date of the request, to the email specified by the Worker in the Mobile Application, and must notify the Operating Company about said sending, in terms of the Transactional Procedures Manual.
The record on the implications of the transfer generated through the Mobile Application can only be used by Receiving Administrators that have the service enabled in the Mobile Application.
The Receiving Administrators must ensure that the Worker has the Mobile Application active at the time of requesting the Operating Companies the Certification of the Transfer.
For the case referred to in subsection "b" above, when the Transferring Administrator is unable to deliver the record on the implications of the Transfer within the first ten business days from the day the Worker makes the request through the E-SAR, due to day and schedule availability reasons, it must deliver the record, either to the address or email provided by the Worker, within a period not exceeding ten business days counted from when the Worker makes the request through the E-SAR. The Administrator will determine if the record will be sent to the address or the email.
For the cases referred to in subsection "a" of this subsection or, in case the assumption described in the previous paragraph occurs, the Transferring Administrators must keep the evidence that allows them to corroborate that they delivered the record on the implications of the Transfer to the address or email provided by the Worker in the E-SAR and must inform the Operating Company of the result of the delivery of said record in accordance with the guidelines established for this purpose in the Transactional Procedures Manual.
For the cases referred to in subsection "c" of this subsection, the Transferring Administrators must keep the evidence that allows them to corroborate that they delivered the record on the implications of the Transfer to the email provided by the Worker in the Mobile Application and must inform the Operating Company of the result of the delivery of said record in accordance with the guidelines established for this purpose in the Transactional Procedures Manual.
...
IV.
...
a. to c. ...
...
V.
... .
... :
a. to e. ...
VI.
... :
a. to b. ...
...
....
...
...
VII. to IX ...
...
...
...
...
...
... "
" Article 182. The Receiving Administrators, through their operations area, must establish verification controls oriented to ensure the identity and guarantee the exercise of the will of the Workers, the application of said controls being the exclusive responsibility of the Receiving Administrators. The verification controls established by the Administrators must consider, at least, the review of a statistically representative sample with a confidence interval not less than ninety percent, of the Workers' manifestations, stored in the videos obtained at the time of processing the Transfer Request, against the information contained in the Transfer Request.
...
...
...
...
...
... "
" Article 183.
... :
I.
... :
a.
Repealed.
b.
Transfer Requests in which the same risk is identified;
II. to IV. ...
... "
" Article 185. ... :
I. ... ;
II.
Repealed.
III.
Repealed.
... :
a.
... ;
b.
Repealed.
c.
Repealed.
...
...
... "
" Article 189.
... :
I. to II.
... ;
II bis. ... ;
III. to V. ... ;
VI.
That the Folio of the Transfer Request referred to in the previous Article 139 has been generated ;
VII. to X. ... ;
XI.
That the cell phone number registered by the Worker in the Transfer Request or, if applicable, associated with the Mobile Application, does not belong to the cell phone of another Worker registered in the National SAR Database in a period of four months;
XII. to XIV. ...
...
...
... :
a. and b. ...
... "
" Article 195. ....
...
Likewise, Workers who receive the Record of Transfer Liquidation or the notification of the Registration or Transfer of their Individual Account, without having signed a Registration or Transfer Request, or who receive their account statement from an Administrator they have not chosen, will have a period of one hundred eighty business days counted from the date they receive any of the aforementioned documents, to present their complaints to CONDUSEF or through the defense means they consider convenient to their interests.
...
... "
" Article 210 bis. For the purpose of carrying out any of the presencial services referred to in the previous Article 209, Workers may carry them out through an attorney-in-fact, tutor, or curator, if applicable .
I. Repealed.
II. Repealed.
When Workers carry out procedures through an attorney-in-fact, the powers must be made manifest, through a power granted before a notary public. Instruments granted abroad must be presented legalized or apostilled and translated, if applicable, by an expert.
For the attorney-in-fact, tutor, or curator, if applicable, to manage the services provided in the previous Article 209 on behalf of the Worker, the Administrators must verify that the attorney-in-fact, tutor, or curator integrates the Worker's Electronic File and signs their Digital Handwritten Signature, likewise, they must verify that these do not have an Active Promoter Agent status in the Information System of
Promoting Agents referred to in the General Provisions to which Retirement Fund Administrators must adhere regarding their promoting agents. The Promoting Agent with active status may only act as an attorney-in-fact, guardian, or curator when acting on behalf of their spouse or person with whom they have a concubinage relationship, as well as those with whom they have a civil or blood relationship within the second degree.
...
I. and II ....
...
Repealed. "
" Article 210 quater. Administrators must prioritize the personal handling of all procedures related to the Worker's Individual Account at all times, and in the case that they carry out the handling referred to in the previous Article 210 bis, they must implement the use of electronic models that allow them to authenticate the identity of the attorney-in-fact, guardian, curator, or beneficiary, provided that the latter is of legal age, who presents themselves to manage the services provided for in the previous Article 209, using an authentication factor category 3 or higher in accordance with what is provided in Annex B Authentication Factors of these General Provisions. For the foregoing, Administrators must submit for authorization by this Commission the request for authorization of the authentication model they will implement, which must consider at least the following:
i.
Detailed description of the authentication model;
ii.
Detailed description of the authentication factors used by the model;
iii.
Evidence allowing to verify that the model has an Authentication Factor category 3 or higher according to Annex B of these provisions;
iv.
Analysis of the technical and operational feasibility of the authentication model;
v.
Description of mechanisms to guarantee the security, integrity, and confidentiality of the information;
Policies for the generation and conservation of auditable logs that allow verifying, at least, the place, date, and time of the transaction, as well as that information that serves as evidence for the determination of compliance with the model, such logs must be kept available to the Commission at all times, for its supervision.
The Commission, within the terms provided by the Law, may require the requesting Administrator any additional information it considers necessary to, if applicable, rule on the authorization of the authentication model.
The Commission will have a maximum term of thirty business days, counted from the receipt of the authorization request with complete documentation, to resolve on the authorization requests for authentication models that Administrators present to it.
The authorization, if granted, will have a validity of 2 years, which may be renewed for equal periods at the request of the Administrator. Upon expiration of the authorization, the operation of the model must remain suspended until the Administrator has the renewal authorization, if any, issued by the Commission.
Administrators must ensure that the authentication models authorized to them, if any, function correctly, being responsible for any malfunction that could affect the interests of the Workers.
In the event that the authentication model ceases to meet the necessary requirements for its operation or does not guarantee the security of transactions or information, the Commission may order the suspension of the operations of the authentication model in question or, if applicable, revoke the authorization. "
" Article 214. Administrators, before the management of services begins, must send to the Operating Companies the data and elements of the Worker's Identification File, as well as the Biometric Enrollment, the Biometric and Digital Handwritten Signature of the persons who have carried out the activities described in Articles 212 and 213 of these general provisions, and ensure that they are enrolled in the National SAR Database, with the exception of the Registration and Transfer processes, in which case it must be sent prior to the certification of the information and elements contained in the Registration and Transfer Requests referred to in Articles 149, 150, and 189 of these general provisions.
...
...
... "
" Article 217. Administrators may carry out the Re-certification of Workers' Individual Accounts only when they have at least six months since signing the retirement fund administration contract.
... :
I ...
II.
Of the total Re-certifications carried out during a calendar year, at least one-fifth of these must be carried out in person. Re-certification through the Mobile Application may replace in-person Re-certification up to fifty percent of the total in-person Re-certification and the entire telephone Re-certification.
Re-certification through the Mobile Application and in-person Re-certification of Workers' Individual Accounts will have a validity of thirty-six months, counted from the date this attribute is registered in the National SAR Database. When the Re-certification of Individual Accounts is carried out via telephone, the validity of the Re-certification will be eighteen months counted from the date the attribute is registered in the National SAR Database. "
" Article 219. ...
... :
I.
... ;
II.
... :
a. and b. ...
...
...
III. to V. ...
VI.
Register and store a video containing the Worker's manifestation expressing their consent for the Re-certification, in accordance with the characteristics established in the Transactional Procedures Manual. Administrators will be responsible for the safekeeping and conservation of the video, keeping it available to the Commission and implementing the necessary security measures to guarantee that it is not manipulable. "
... "
" Article 229. Administrators must receive, attend to, guide, and resolve the inquiries, requests, and complaints of Workers or their Beneficiaries, related to the administration and operation of their Individual Accounts, through the means made available by the Administrator to the Worker.
Administrators, in accordance with the systems established for such purposes, under Article 6 previous, must keep a record and follow-up of the inquiries, requests, and complaints requested by Workers and Beneficiaries, and assign a Complaint or Service Folio, which must be provided to the Worker at the time of presenting their inquiry, request, or complaint. Administrators must use said Folio to follow up and inform Workers or Beneficiaries of the status of the procedure and its result, in accordance with the deadlines established in these general provisions to carry out the requested processes or procedures.
...
Likewise, Administrators must have mechanisms that allow, at least, identifying the service for which the complaint is presented, or if applicable, qualifies, as well as the assigned Complaint or Service Folio. "
" Section VII
Of the Administration of Individual Accounts of minors "
" Article 243 bis. The minor who has been registered with an Administrator through the person exercising parental authority or through their tutor, will be represented at all times by them as appropriate, so that in their representation, they may carry out any procedure related to their Individual Account, including choosing the Investment Society or Investment Societies in which they wish to invest the resources, according to the investment prospectuses of each Administrator. "
" Article 243 ter. Once minors have capacity to exercise or begin contributing in one of the Social Security Institutes, they will obtain total control over their Individual Account, so the intervention of those exercising parental authority or their tutor will no longer be necessary to carry out any of the procedures related to their Individual Account.
For the foregoing, Administrators must update the Worker's data, as well as their Identification File in accordance with these provisions. "
" Article 248.
Administrators must attend only through the E-SAR or the Mobile Application, the pre-requests for transfer or permanence of resources from their Individual Account from one Investment Society to another.
...
Administrators must attend all pre-requests for the transfer or permanence of resources they receive from Operating Companies and make telephone contact to obtain from the Worker the choice of the Investment Society in which they wish to invest the resources of their Individual Account.
The foregoing, from the next business day after the date the Administrator received the information of the pre-requests for transfer or permanence and no later than the third business day following the date the Administrator received from the Operating Company the information of the pre-requests for transfer or permanence.
If the Worker during the telephone call they receive from the Administrator manifests that they wish to transfer their resources to an Investment Society different from the one they had chosen through the E-SAR or the Mobile Application, the Administrator must take this change into account to carry out the transfer of resources.
...
... "
" Article 249. Administrators must execute and invest the Workers' resources in the Investment Societies chosen by them, in accordance with the choice of Investment Societies obtained from the contact made with the Worker through the Administrator's telephone call center, no later than the fourth business day following the date the Administrator obtained the Worker's will telephonically. "
" Article 250. Administrators, within a period not exceeding five business days counted from the day following the conclusion of the procedure, must inform the Worker clearly as follows, as applicable:
a.
When the Worker has chosen to keep their resources in the same Investment Society in which their resources are already invested, that their resources will remain in said Investment Societies until they choose another.
b.
When the Worker has made a choice of an Investment Society different from the one in which their resources are already invested: that their resources were transferred to the Investment Society or Societies they chose.
c.
When a rejection occurs: the reason for rejection.
The notifications referred to in subsections a, b, and c above will be carried out through the means determined and established for such purposes in the Policies and Procedures Manuals of each Administrator. "
" Article 258. To keep the National SAR Database clean and updated, it will be the responsibility of Operating Companies and Administrators to carry out, in coordination with Social Security Institutes, either through the celebration of collaboration agreements or any other mechanism provided for, the procedures necessary for the unification and separation of Individual Accounts, in accordance with the guidelines and validation criteria established by the Commission.
...
...
...
... "
" Article 274 bis. Operating Companies must provide Administrators with the service, through which, using the Mobile Application, they can notify the Worker about the receipt of the account statement, contributions, disbursements, and withdrawals made to the Worker's Individual Account, as well as the result of the services requested by the Worker to the Administrator; likewise, allow them to deliver messages about the importance of making Voluntary Savings, information about requirements, deadlines, and other related to the Retirement Savings Systems. Likewise, the service must allow incorporating interactive applications to promote Voluntary Savings. Such notifications and messages must be adapted to the formats notified to them for such purposes by the Commission. "
" Article 274 ter. Operating Companies must provide Administrators with the service, through which, using the Mobile Application, they can send invitations to the Worker to make Voluntary Savings, carry out the Registration of their Individual Account when it concerns Non-Affiliated Workers. They must also provide balance inquiry services for the Individual Account, update or modification of the Worker's personal data, and interactive applications designed by Administrators. "
" Article 274 quater. Operating Companies must adapt the services referred to in Articles 274 bis and 274 ter in accordance with the guidelines that Administrators and Operating Companies must follow for the use and operation of the Mobile Application, established in Annex B fraction III of these general provisions. "
" CHAPTER VIII
OF THE COLLECTION
Section I
Of the Information Reception System and Solidarity Savings "
" Article 296. Operating Companies must develop, modify, update, and administer the Information Reception System in accordance with the Commission's requirements for the correct operation of collection processes.
Operating Companies must implement and administer an Internet portal linked to the Information Reception System, through which, ISSSTE Workers can make the choice, cancellation, or modification of the percentage of the Solidarity Savings benefit.
... :
I. to III. ...
....
... :
a.
Receive through the Information Reception System, the information of the Workers
who have chosen the Solidarity Savings benefit, and
b.
...
... . "
" Article 297. It is the responsibility of Operating Companies to guarantee the security, integrity, and confidentiality of the information exchanged through the Information Reception System, as well as of the Internet portal through which Workers choose, cancel, or modify the percentage of Solidarity Savings, and must keep available to Administrators the information of the National SAR Database of the Workers whose Individual Account they operate.
Likewise, Operating Companies must allow access to the Information Reception System through Electronic Means. "
" Article 298. Operating Companies will inform FOVISSSTE, through the Information Reception System, the data of the Departments and Entities or, if applicable, of the Payment Centers of the Departments and Entities, obliged to make the deposit of Housing Contributions in favor of the ISSSTE Worker who has obtained a housing credit, in order for that housing fund to provide the necessary information for the Amortization of the corresponding credits in accordance with these general provisions. "
" Article 299. Operating Companies must provide Departments, Entities, and Insurers with the corresponding advice and training for the integration and sending of files that must be transmitted through the Information Reception System. The foregoing, without prejudice to the attention that ISSSTE and/or FOVISSSTE may give to information requests they receive from Departments, Entities, and Insurers. "
" Article 300. ...
...
Operating Companies must establish the guidelines and technical characteristics of information exchange so that Departments and Entities can update the ISSSTE Worker Catalog through the Information Reception System.
Operating Companies will communicate through the Information Reception System to Departments and Entities, no later than the next business day after receiving the update of the catalog referred to in the previous paragraph, the result of the structure and information validation of the file, including, if applicable, the inconsistencies identified. In case the file is successfully validated, the Operating Company must issue a certificate of the update of the ISSSTE Worker Catalog in the National SAR Database. "
" Article 301. It is the responsibility of Insurers, Departments, and Entities to make the bimonthly calculation of the global and individualized amount of the resources corresponding to Quotas and Contributions, Solidarity Savings, as well as late payments referred to in Article 22 of the ISSSTE Law and the interests that, if any, correspond to them, in accordance with what is provided in the ISSSTE Law. Likewise, Departments and Entities may make Voluntary Savings contributions through the Information Reception System.
For such effect, Insurers, Departments, and Entities must integrate the corresponding information through the Information Reception System, in accordance with the guidelines and formats made known by the Commission.
... "
" Article 302. Operating Companies, through the Information Reception System, will issue the Capture Lines corresponding to the deposit of Quotas and Contributions, Solidarity Savings, Voluntary Savings, contributions for housing amortizations, late payments, and the interests that, if any, correspond to Departments, Entities, and Insurers, with the latter being responsible for ensuring that the Capture Lines contain the correct amounts to be paid.
The lack of receipt of the Capture Lines or errors in them do not exempt Insurers, Departments, and Entities from fulfilling the obligations to determine and deposit the resources referred to in this section, nor do they free them from the legal consequences derived from the non-compliance with said obligations; in which case, Insurers, Departments, and Entities must use the options contained in the Information Reception System to update the registered information and request the Capture Line again. "
" Article 309. ...
Operating Companies must receive from ISSSTE the request and information referred to in this article through the Information Reception System, no later than seven business days before the deadline for the payment of resources established in the third paragraph of Article 21 of the ISSSTE Law.
... "
" Article 329. Administrators must acquire on the same day they receive the resources corresponding to Quotas and Contributions, the Shares of the Investment Society corresponding to the Worker at the price registered on that date in a stock exchange authorized to organize and operate in accordance with the Securities Market Law. "
" Article 337 bis. Administrators may present before the Commission for authorization, models, projects, or initiatives that, through innovation and the use of technology, stimulate Voluntary Savings, the registration of Individual Accounts, the expansion of service coverage, or any other mechanism that facilitates the exercise of Workers' rights related to their Individual Account, as well as access to the services that Administrators must provide them, in which they may have the participation of companies, Support Companies, Non-Governmental Organizations (NGOs), government entities, international organizations, or natural persons with business activity.
For the foregoing, Administrators must send to the Commission their request for authorization, which must contain the description of the model, project, or initiative and must consider at least, the objective of the same, and the expected results, an analysis of information and personal data security, as well as operational and technical feasibility, and, if applicable, the authentication factor to be used, accrediting that the requirements established in Annex B of these general provisions are met.
Administrators that implement the models referred to in this article, must celebrate with the third parties referred to in the first paragraph of this article, the confidentiality agreements necessary so that Worker information is used only for the management of the procedure they request. Administrators will be responsible at all times for compliance with the applicable personal data protection regulations.
The Commission, prior to analysis of operational, technical, and information and personal data security feasibility, may authorize models, projects, or initiatives, within a maximum term of fifteen business days, counted from the receipt of the authorization request with complete documentation.
The Commission, within the terms provided by the Law, may require the requesting Administrator any additional information it considers necessary to, if applicable, rule on the authorization of the model, project, or initiative, notifying if applicable the authorization of the same to Operating Companies so that within a maximum term of ten business days, said Operating Companies coordinate with the applicant to establish the agreements and/or contracts required for their formalization; the authorization will have a validity of one year, which may be renewed for equal periods, provided that the renewal request is presented by the interested party no later than thirty business days prior to the expiration date.
Once the agreements or contracts referred to in this article are signed and prior to authorization of the models, projects, or initiatives by the Commission, Operating Companies must define the mechanisms that allow information exchange, within a maximum term of fifteen business days counted from the next business day following the entry into force of the respective contract or agreement. Such mechanisms must be established in the Transactional Procedures Manual.
In the case that Administrators or Operating Companies decide to hire the services of Auxiliary Companies or Support Companies for the operation of models, projects, or initiatives as provided in this article, they must ensure that the Auxiliary Company or Support Company
must have:
a.
Training for personnel participating in the project, model, or Initiative, so that, where applicable, they provide correct information to Workers;
b.
Confidentiality agreements ensuring that Worker information obtained in the development of the project, model, or initiative is used solely for the management of the procedure;
c.
Security mechanisms that protect Worker information.
If the models, projects, or initiatives cease to meet the requirements necessary for their operation or do not guarantee the security of transactions or Worker information, the Commission may order the suspension of operations of such models or revoke their authorization. "
" Article 337 ter. Operating Companies must implement in the E-SAR Portal the payment reference generation service for the deposit of Voluntary Savings contributions, according to the following characteristics:
I.
The service must be available to the general public;
II.
The service must allow the receipt of the data required for the generation of payment references, through:
a.
Manual capture by CURP.
b.
Importation of information through a data file according to the characteristics established in the Transactional Procedures Manual.
III.
The service must validate the received information and, where applicable, generate the payment reference covering the deposit or deposits requested by the user;
IV.
Operating Companies must store the details of the payment references, to be able to perform the reconciliation and distribution of contributions when they are received, and
V.
Operating Companies must establish in the Transactional Procedures Manual the mechanisms necessary for the control, receipt, reconciliation, and distribution of contributions received through payment references.
In addition to the services mentioned in the preceding subsections, other services may be included as required by each Administrator, adhering to what is established in the previous Article 337 bis. "
" Article 346. Administrators or Auxiliary Companies that receive Voluntary Savings contributions, through any of the means provided for in the previous Article 337, must issue a receipt of acknowledgment according to the characteristics, guidelines, and technical criteria agreed upon with Operating Companies, as well as, where applicable, those established by the Commission for such effect. The receipts of acknowledgment must contain at least, the name and CURP of the Worker, as well as the amount and type of Voluntary Savings contribution being made, this last requirement may be excluded for the case of Voluntary Contributions received abroad through Auxiliary Companies contracted for such effect by the Administrators or the Operating Companies by mandate of the latter.
... "
" Article 387 bis.
... :
a) to c). ... ;
d)
:
i.
... ;
ii.
... ;
iii.
... .
e)
... ;
...
In any case, the Worker may go to any office, branch, or Specialized Unit of the respective Administrator to request the disposal of resources for marriage expense assistance, Partial Withdrawal for Unemployment, and the resource disposal referred to in Article 406 of these general provisions, for which the Administrators must support the Worker or their Beneficiaries in making the pre-application, in accordance with the guidelines established by the Operating Company in the Transactional Procedures Manual for such effect. "
" Article 406 ter.
... :
a) to e). ... ;
...
...
I.
... ;
II.
Contact Workers based on the identification documents held in their records or in the Identification File, when the deposit amount exceeds 10 measurement and update units, with the purpose of informing them about the deposit referred to in this article, subject to the following:
i.
to iv. ... .
...
...
...
... "
" Article 419. In the case of partial withdrawals, the Worker who goes to an Administrator must present the pre-application for resource disposal for marriage expense assistance or Partial Withdrawal for Unemployment that was made through the E-SAR, accompanied by the documentation that, where applicable, is established by the Administrators and the Social Security Institutes, in the form and terms established by said Institutes for such effect.
...
... "
" Article 424. ... :
I.
That the Worker has made the pre-application for Partial Withdrawal for Unemployment referred to in subsections VIII and IX of Article 9 of these general provisions.
It is repealed.
II. to V. ...
VI.
...
a.
...
b.
...
VII.
... "
" Article 437 . To process a request for the disposal of Voluntary Savings, Administrators must previously comply with the following requirements:
I.
That the Worker has an Identification File or Mobile File and that it corresponds to the same;
II.
Ensure that the Worker declares in the request for disposal of Voluntary Savings that they know its content and that it is their will to carry out the procedure, for which they must write their full name, Biometric Signature, and Digital Handwritten Signature;
III.
Perform a review of the request for disposal of Voluntary Savings, to verify the consent, will, and identification of the Worker carrying out the procedure, and
IV.
In the event that the withdrawal is made through the Mobile Application, or other non-presence mechanisms, Administrators may substitute with this, the requirement referred to in the previous subsection II, provided there is express consent from the Worker and the deposit in favor of the Worker is made into bank accounts held in their name and designated for such effect.
The non-presence mechanisms that Administrators implement, where applicable, to effect the withdrawal of resources from the Individual Account, must be previously authorized by the Commission in accordance with the following:
Administrators must submit the request to operate a non-presence procedure for the withdrawal of Voluntary Contributions, which must consider at least the following:
i.
Detailed description of the non-presence procedure;
ii.
Detailed description of the authentication factors used by the non-presence procedure;
iii.
Evidence allowing to verify that the non-presence procedure has a Category 3 or higher Authentication Factor according to Annex B of these provisions;
iv.
Technical and operational feasibility analysis of the non-presence procedure;
v.
Description of mechanisms to guarantee the security, integrity, and confidentiality of the
information;
Policies for the generation and conservation of auditable logs that allow verifying, at least, the place, date, and time of the transaction, as well as that information that serves as evidence for determining compliance with the non-presence procedure, such logs must be kept available to the Commission at all times, for its supervision.
The Commission, in terms of what is provided by the Law, may require the requesting Administrator any additional information it considers necessary to, where applicable, pronounce itself regarding the authorization of the non-presence mechanism to effect the withdrawal of resources from the Individual Account.
The Commission will have a maximum term of thirty business days, counted from the receipt of the authorization request with complete documentation, to resolve on the authorization requests for non-presence mechanisms that Administrators submit to it.
Administrators must ensure that the non-presence mechanisms authorized to them, where applicable, function correctly, being responsible before the Worker for any malfunction that could affect their interests.
In the event that the non-presence mechanism ceases to meet the requirements necessary for its operation or does not guarantee the security of transactions or Worker information, the Commission may order the suspension of the operations of the non-presence mechanism in question or, where applicable, revoke the authorization.
Administrators that implement the resource disposal referred to in this article, prior to making the requested resources available to the Worker, must ensure that they comply with the General Provisions referred to in Article 108 Bis of the Retirement Savings Systems Law that the Secretariat issues for such effect, in particular, with the obligations related to customer identification.
" ANNEX B "
AUTHENTICATION FACTORS
... :
I.
Category 1 Authentication Factor:
...
... :
a.
... ,
b.
...
II.
Category 2 Authentication Factor:
... :
a.
... :
i.
... ;
ii.
... ;
iii.
... ,
iv.
... ;
b.
... ,
c.
...
...
... ;
III.
Category 3 Authentication Factor: It is composed of information contained or generated by
Electronic Means, as well as information obtained through the Mobile Application that
Operating Companies or Administrators implement, with prior authorization from the
Commission, as well as through devices generating dynamic one-time passwords. Such means or devices must be provided by the Administrators or
Operating Companies to the Workers and the information contained or generated by them,
must meet the following characteristics:
a.
Have properties that prevent duplication or alteration;
b.
Be dynamic information that cannot be used more than once;
c.
Not be known prior to its generation and use by Promoting Agents,
as well as any direct or indirect employee of the Administrator, Operating
Companies or by third parties;
The Commission will establish the guidelines that Administrators and
Operating Companies must follow for the use and application of this Authentication Factor.
Operating Companies or Administrators must provide Workers with the
mobile software application that generates passwords issued by Operating Companies.
Such passwords require association with a cell phone and any other information
related to the type of operation or service in question, so that said password
can only be used for the requested operation
The Commission may establish additional guidelines that Administrators
and Operating Companies must follow for the use and application of this Authentication Factor.
Operating Companies must enable the option to generate passwords to authorize
and sign services independent of the Mobile Application, when Administrators
so require.
In all cases, Operating Companies and Administrators must obtain authorization
from the Commission to operate the means referred to in this subsection, in whose
request they must expose the controls that will allow Workers to perform
operations securely. The Commission
will have a term of 40 business days to
resolve on the authorization requests referred to in this section.
Administrators may implement models to offer services through the
use of authentication factors developed by Operating Companies or by
Administrators referred to in this subsection, for which they may request authorization from the
Commission.
The authorization that the Commission issues, where applicable, will have a validity of two years, which
may be renewed for equal periods, provided that the renewal request is
submitted by the interested Administrator within a term no less than thirty business days
prior to the expiration date.
The authorization request for services must contain at least the following:
I.
Object;
II.
Services that will be implemented using the model;
III.
Detailed description of the model and service;
IV.
Start date of operations;
V.
Technical and operational feasibility analysis for the operation intended to be carried out;
VI.
Description of mechanisms that guarantee the security, integrity, and
confidentiality of the information exchanged through them;
VII.
Generation and availability of logs that are auditable and allow
verification, at least, of the place, exact date, and time of the transaction, as well as
that information that serves as evidence for determining compliance
with the model; such logs must be available for Commission supervision, and
VIII.
Any other element that the Administrator considers necessary to
facilitate the analysis of the request by the Commission.
The Commission, in terms of what is provided by the Law, may require the requesting Administrator
any additional information it considers necessary to, where applicable, pronounce itself
regarding the authorization
of the model.
The development of the service models referred to in the preceding paragraphs may be
carried out by Administrators through third parties who have been evaluated by the
Administrators themselves, considering a risk and vulnerability analysis, and that according to said evaluation, the Administrator determines that the model meets the characteristics indicated in Annex B, Authentication
Factors .
Operating Companies must accept the requests for implementation of service models
authorized by the Commission to configure interfaces and, jointly with the
Administrator, enable a secure channel for their interaction, allowing the use of authentication
factors of Mobile Applications. For the purposes of the above, the respective Administrators
and Operating Companies must execute the legal acts that support the operation of this additional service.
In the event that the authorized service models referred to in this article cease
to meet the requirements necessary for their operation or do not guarantee the security of the
transactions or information, the Commission may order the suspension of operations
of such models or revoke
their authorization.
IV.
... ;
V.
Category 5 Authentication Factor: It is composed of the Biometric Signature and Digitalized Handwritten
Signature of the Worker or Beneficiary, where applicable, which must contemplate the following elements:
a)
That the Biometric Signature and/or Digitalized Handwritten Signature is collected in real time.
b)
The Biometric Signature may be collected through biometric elements, based on
international standards, according to the following characteristics:
i.
The biometric element must verify liveness;
ii.
It may be composed of various biometric factors to improve the level of
confidence in validation, and
iii.
May use geo-localization components to identify the place where the
Biometric Signature is performed.
Administrators must use authentication factors to provide Workers with services related to the
administration of their Individual Account, in accordance with what is provided in
these general provisions. "
" ANNEX M "
CHARACTERISTICS THAT OPERATING COMPANIES MUST OBSERVE TO PROVIDE
SERVICES RELATED TO TRANSFER IMPLICATION CERTIFICATES
Operating Companies must establish mechanisms so that call centers have the following:
I.
Worker identification according to the internal procedures of Operating
Companies;
II.
Registration of the phone number from which the call was made;
III.
The transfer implication certificate service must be the first option in the
menu of services offered to Workers;
IV.
Call center operators must
a.
Be trained according to the internal procedures of Operating Companies, and
b.
Provide the service according to the script determined by the Commission for such effect.
Call center operators must not be Promoting Agents;
V.
Preserve in Electronic Media the recordings of all telephone calls received
referred to in this subsection for a period of ten years from the date on which
it was made, and
VI.
Have quality standards and service levels that allow them to operate in a schedule no
less than Monday to Saturday from nine to twenty hours of the country center's time zone. Operating
Companies may temporarily suspend the service when they require maintenance
to their systems and technological platforms, with prior notice to the Commission. "
SECOND .- Article One Transitory, subsection III, paragraphs C and D and subsection IV of the
MODIFICATIONS AND ADDITIONS TO THE GENERAL PROVISIONS ON OPERATIONS OF THE RETIREMENT SAVINGS SYSTEMS, published in the Official Gazette of the Federation on July 4, 2017; are MODIFIED;
" FIRST .- These modifications and additions will enter into force on the next business day following their
publication in the Official Gazette of the Federation with the exception of the following:
I. to II. ... ;
III.
Article 180 of these modifications and additions will begin its validity according to
the following:
A.
The first, second, third, fourth, fifth, sixth, seventh, and eighth paragraphs, will enter into
force 60 business days after the publication in the Official Gazette of the Federation of these
modifications and additions;
B.
Subsections I, with the exception of subsections a, c, and e, II, III, and IV will enter into force 60
business days after the publication in the Official Gazette of the Federation of these
modifications and additions;
C.
Subsections I, subsection e, V, and VI, will enter into force on January 19, 2018, and
D.
Subsections I, subsection a, VII, VIII, and IX will enter into force on September 3, 2018.
...
IV.
Article 387 bis, regarding partial and total withdrawals of resources from the Individual Account,
contained in these modifications and additions, with the exception of those referred to in the following subsection V, will enter into force on November 30, 2018. Article 387 bis,
regarding total withdrawals of resources from the Individual Account, contained in these
modifications and additions, with the exception of those referred to in the following subsection V,
will enter into force on April 30, 2019.
V.-
... "
TRANSITORIES
FIRST .- These modifications and additions will enter into force on the next business day following their
publication in the Official Gazette of the Federation with the exception of the following:
I.
Article 180, subsection III, subsection c, will begin its validity 120 business days after
the publication in the Official Gazette of the Federation of these modifications and
additions;
II.
Article 337 ter will begin its validity 260 business days after the publication
in the Official Gazette of the Federation of these modifications and additions;
III.
Articles 9, subsections III and VI, 136, 137, 138, 139, last paragraph and its subsections I, II, and III,
148, subsection II, subsection a, last paragraph, 158 subsections II and III, subsection b and c, 160 subsection IV, 168,
subsection II, subsection a, will end their validity and be repealed 60 business days after
the publication in the Official Gazette of the Federation of these
modifications and additions;
IV.
Modifications to Articles 139 paragraphs first, second, and third, 148, subsection III,
150, 168, subsection III, 172, 173, subsection III, 176, and 189, subsections VI and XI, will begin their
validity 60 business days after the publication in the Official Gazette of the Federation of these
modifications and additions;
V.
Modifications and additions to Articles 148 subsection V, 149 bis, last paragraph, 155, 156,
168 subsection VIII, 182, and 219 subsection VI, will begin their validity 40 business days after
the publication in the Official Gazette of the Federation of these modifications and
additions;
VI.
Articles 243 bis and 243 ter will begin their validity 150 business days after
the publication in the Official Gazette of the Federation of these modifications and additions;
VII.
Modifications to Article 217 will begin their validity 20 business days after
the publication in the Official Gazette of the Federation of these modifications and
additions;
VIII.
Modifications to Article 14 will begin their validity 90 business days after
the publication in the Official Gazette of the Federation of these modifications and additions;
IX.
Modifications and additions to Articles 90, subsections IV, V, and VI, 90 bis, and 92 subsection II
subsection b, subsection c, subsection d, numeral i, and subsection f numeral IV, will begin their validity 260
business days after the publication in the Official Gazette of the Federation of these
modifications and additions, and
X.
Article 210 quater will begin its validity 110 business days after the
publication in the Official Gazette of the Federation of these modifications and additions.
SECOND .- With the entry into force of these modifications, all those provisions that contravene these are abrogated.
Mexico City, November 9, 2018 .- The President of the National Commission of the Retirement Savings System,
Carlos Ramírez Fuentes .- Rubric.
In the document you are viewing, there may be text, characters, or objects that do not display correctly due to conversion to HTML format, so we recommend always taking the digitized image of the DOF or the PDF file of the edition as a reference. The content, form, and scope of published documents are the sole responsibility of their issuer.
INQUIRY
BY DATE
Do Mo Tu We Th Fr Sa
INDICATORS
Exchange Rate and Rates as of 08/29/2026
UDIS
8.809369
See more
SURVEYS
Did you like the new look of the Official Gazette of the Federation website?
No
Yes
Official Gazette of the Federation
Río Amazonas No. 62, Col. Cuauhtémoc, C.P. 06500, Mexico City Tel. (55) 5093-3200, where you can access our service menu
Electronic address: dof.gob.mx
113
LEGAL NOTICE | SOME RIGHTS RESERVED © 2026