2021-01-28
Added
The document establishes general provisions for electronic payment fund institutions regarding information security, operational continuity, third-party service contracting, and independent evaluations. It mandates specific authentication requirements, business continuity plans, and incident notification procedures, including reporting operational contingencies lasting at least 30 minutes to the CNBV and Bank of Mexico. The rules also define the obligations for managing third-party providers and commissionaires, and require the engagement of independent third parties to evaluate compliance with security and continuity standards.
CNBV published 1 document in the last 30 days — get each new one by email the day it lands.
PROVISIONS APPLICABLE TO ELECTRONIC PAYMENT FUND INSTITUTIONS REFERENCED IN ARTICLES 48, SECOND PARAGRAPH; 54, FIRST PARAGRAPH, AND 56, FIRST AND SECOND PARAGRAPHS OF THE LAW FOR REGULATING FINANCIAL TECHNOLOGY INSTITUTIONS
Published in the Official Gazette of the Federation on January 28, 2021.
Whereas, in accordance with Article 78 of the General Law for Regulatory Improvement and with the aim of reducing the compliance cost of these provisions, the National Banking and Securities Commission, through a resolution published in the Official Gazette of the Federation on December 26, 2017, modified the General Provisions applicable to credit institutions, to flexibly extend the deadline to which multiple banking institutions were subject for establishing their capital requirements for operational risk;
Whereas on March 9, 2018, the "Decree by which the Law for Regulating Financial Technology Institutions is issued and various provisions of the Credit Institutions Law, the Securities Market Law, the General Law of Organizations and Auxiliary Credit Activities, the Law for Transparency and Ordering of Financial Services, the Law for Regulating Credit Information Societies, the Law for Protection and Defense of Users of Financial Services, the Law for Regulating Financial Groups, the Law of the National Banking and Securities Commission, and the Federal Law for the Prevention and Identification of Operations with Resources of Illicit Origin are reformed and added" was published in the Official Gazette of the Federation;
Whereas the Law for Regulating Financial Technology Institutions incorporates, within the framework of the national financial system, financial technology institutions, while empowering the Bank of Mexico and the National Banking and Securities Commission to jointly issue the general provisions that electronic payment fund institutions must observe, which shall be governed by the principles of financial inclusion and innovation, promotion of competition, consumer protection, preservation of financial stability, and technological neutrality;
Whereas, in order to have adequate regulation for electronic payment fund institutions and in attention to the principles stated in the preceding Consideration, these general provisions are issued as a unified, systematic, coherent, and clear regulatory framework that provides legal certainty to participants in the financial technology market, promotes the growth of electronic payment fund institutions, and safeguards the interests of the clients of these institutions and the financial system as a whole;
Whereas, to guarantee the security of operations conducted with clients, the requirements that the authentication of the client and the notification made to them at the time of agreeing or concluding such operations must meet are established, as well as the terms and conditions for the provision of services through instruction channels, while also establishing information security requirements regarding these instruction channels to guarantee confidentiality and avoid vulnerabilities, in accordance with best practices and international standards;
Whereas, to safeguard the sequence in the activities and operations carried out by electronic payment fund institutions, it is indispensable to establish the obligation to have a business continuity plan that must be implemented upon verification of any event that hinders, prevents, or limits them from carrying out their operations or processes with an impact on their clients in the eventuality of failures due to unforeseen situations or events, which is strengthened by the obligation to have mechanisms for the administration of operational contingencies that reduce the risks to which they are exposed, such as the designation of the person responsible for the administration of contingencies and the necessary certifications in this matter when the aforementioned financial institutions hire third-party services to support their operation;
Whereas, regarding those electronic payment fund institutions that have a higher volume of accounts or operations and carry out their main processes through cloud computing provided by a third party, it is necessary that these include in their respective plans special measures for prudential reasons, in order to protect the interests of their clients, as well as to maintain the operational and financial security and integrity of said institutions individually, and the operational security and integrity of the payment system as a whole, without prejudice to any other measures imposed by these and other applicable provisions;
Whereas, in protection of the interests of the clients of electronic payment fund institutions, it is necessary to establish the obligation for these institutions to notify their clients of the existence of information security incidents involving the loss, extraction, elimination, or alteration of personal or sensitive information of these clients, whether it is in the possession of the electronic payment fund institutions themselves or of third parties providing services to them, indicating in this regard the deadlines and terms of such notification, the measures that will be implemented to safeguard client information, and, if applicable, the replacement or substitution of the disposal means or authentication factors that the electronic payment fund institutions themselves consider necessary to carry out;
Whereas, with the purpose that clients have knowledge of the degree of operational efficiency that electronic payment fund institutions with which they conduct operations have, it is considered relevant to establish that these financial entities must inform the National Banking and Securities Commission and the Bank of Mexico of operational contingencies with a duration of at least 30 minutes, arising in any of the public attention channels or within the electronic payment fund institution itself, while also specifying the elements that such communication must meet and the deadline by which it must be made once the operational contingency in question occurs; in addition to the above and in protection of the interests of their clients or users of disposal means, the minimum elements of the notification that these financial entities must make when one or more instruction channels are affected as a result of these operational contingencies are established;
Whereas, in order to procure greater legal certainty and security for the operations of electronic payment fund institutions and thereby protect the interests of their clients, it is considered indispensable to indicate the terms and requirements that these financial technology institutions must observe to contract services with third parties and to celebrate commercial commissions, establishing the circumstances in which they will require the authorization of the National Banking and Securities Commission and the Bank of Mexico for the celebration of such contracts;
Whereas, in order to have transparency in the information generated by the relationships that electronic payment fund institutions have with third parties, the characteristics of the registry of all their service providers, including sub-contracted providers by these, as well as administrators of commissionaires and commissionaires, with which electronic payment fund institutions have contracted service provision or commercial commission agreements, are specified, also providing for the dissemination that these financial entities will give, through their Internet page or mobile application, of the list of modules or establishments of commissionaires, in which they will indicate the operations and operation amounts permitted;
Whereas, in order to have transparent, reliable, and comparable financial information, for the benefit of the electronic payment fund institutions themselves, their clients, and the supervision functions of the Bank of Mexico and the National Banking and Securities Commission, it is established that these financial entities must hire the services of an independent third party for the evaluation of compliance with the information security requirements, the use of instruction channels, and operational continuity that they must observe, indicating the characteristics that said independent third party must meet; therefore, they have resolved to issue the following:
PROVISIONS APPLICABLE TO ELECTRONIC PAYMENT FUND INSTITUTIONS REFERENCED IN ARTICLES 48, SECOND PARAGRAPH; 54, FIRST PARAGRAPH, AND 56, FIRST AND SECOND PARAGRAPHS OF THE LAW FOR REGULATING FINANCIAL TECHNOLOGY INSTITUTIONS
CHAPTER I
GENERAL PROVISIONS
CHAPTER II
ON INFORMATION SECURITY
First Section
On Technological Infrastructure vis-à-vis Clients Subsection A On the celebration of contracts through Instruction Channels and Operations through them Subsection B On Authentication in Instruction Channels Subsection C On information security requirements in Instruction Channels Second Section On Technological Infrastructure in internal processes Third Section General Provisions for Technological Infrastructure
CHAPTER III
ON OPERATIONAL CONTINUITY
CHAPTER IV
COMMON PROVISIONS ON INFORMATION SECURITY AND OPERATIONAL CONTINUITY
CHAPTER V
ON CONTRACTING SERVICES WITH THIRD PARTIES AND COMMISSIONAIRES
CHAPTER VI
ON EVALUATION THROUGH INDEPENDENT THIRD PARTIES
CHAPTER VII
COMPLEMENTARY PROVISIONS
ANNEX 1 Information security indicators.
ANNEX 2 Minimum requirements to develop the Business Continuity Plan.
ANNEX 3 Incidents in matters of information security.
ANNEX 4 Information Security Incident Report.
ANNEX 5 Report on Operational Contingencies.
ANNEX 6 Characteristics of Independent Third Parties.
ANNEX 7 Technical requirements to carry out Operations through commissionaires.
ANNEX 8 Specifications of the information system developed by a third party for the encryption of information shared with the National Banking and Securities Commission and the Bank of Mexico.
CHAPTER I
GENERAL PROVISIONS
Article 1.- For the purposes of these Provisions, the following terms, in singular or plural, in addition to those used in the Law for Regulating Financial Technology Institutions, shall be understood as:
Administrator of Commissionaires:
the person who, in terms of Article 46 of these Provisions, organizes a network of commissionaires and acts as an intermediary between them and the electronic payment fund institution, so that said commissionaires conclude Operations and services with Clients.
Authentication:
the verification of the identity of (i) a Client, in order to allow them to carry out the Operations they require, or (ii) a User of the Technological Infrastructure of the electronic payment fund institution in question, in order for that person to access, use, or operate any component of said Technological Infrastructure.
Instruction Channels:
the equipment, electronic, optical, or any other technology media, automated data processing systems, and telecommunications networks that are part of the Technological Infrastructure of the electronic payment fund institution in question and through which it allows the Client to carry out Operations.
Encryption:
the mechanism that electronic payment fund institutions must use to protect the confidentiality of information through cryptographic methods in which algorithms and encryption keys are used.
Cloud Computing:
the model of computing services provided by a third party, on demand and on shared, private, or hybrid infrastructure, regardless of the physical location of the third party's Technological Infrastructure, which may consist, among others, of one or more of the following digital service schemes: infrastructure as a service, platform as a service, or software as a service.
Operational Contingency:
any event that hinders, limits, or prevents an electronic payment fund institution from carrying out its Operations, or those processes that could have an impact on its Clients or on the electronic payment fund institution itself.
Account:
that accounting record in which the electronic payment fund institution makes, among others, the entries of (a) credits corresponding to (i) the amount of electronic payment funds that it issues in favor of the Client in whose name said record was opened, in accordance with Article 22, fraction I of the Law, against the receipt of an amount of money, in national currency, or subject to the authorization of the Bank of Mexico, in foreign currency, object of a Fund Transfer, Money Transmission, by receipt of cash, or operations with Card; (ii) the amount of electronic payment funds object of the Electronic Payment Fund Transfers that it receives in favor of said Client, as well as (b) charges corresponding to (i) the disposal of electronic payment funds due to their redemption, object of a Fund Transfer, payment operations with any type of disposal means that the electronic payment fund institution has allowed its client to carry out, direct debits, Money Transmission, or the delivery of cash; (ii) the amount of electronic payment funds object of the Electronic Payment Fund Transfers in question.
Information Security Event:
any event, internal or external, related, among others, to Clients, third parties contracted by the electronic payment fund institution, persons or operational processes, as well as to components of the Technological Infrastructure, devices, physical media, or other elements that store information, which constitutes some indication of possible affectation in the confidentiality, integrity, or availability of the information that said institution manages or has access to in its own Technological Infrastructure.
Authentication Factor:
the Authentication mechanism, based on the physical characteristics of the Client, on devices or information that only the Client possesses or knows, as provided in Article 5 of these Provisions.
Client Identifier:
the alphanumeric character string, or the information of a device, or any other information known by both the electronic payment fund institution and the Client who is the holder of the respective Account that this administers, which allows identifying them through the Instruction Channel of said electronic payment fund institution. Among others, the Client Identifier may be the mobile phone line number that the Client uses to access the Instruction Channels, the email address, the number of their Card, or another unique identifier associated with the use of the corresponding Instruction Channel.
Information Security Incident:
any event, internal or external, related, among others, to Clients, third parties contracted by the electronic payment fund institution, persons and operational processes, as well as to components of the Technological Infrastructure, devices, physical media, or other elements that store information, that:
a) Compromises the confidentiality, integrity, or availability of one or more components of the Technological Infrastructure with an adverse effect on the electronic payment fund institution, its Clients, third parties, providers, or counterparties, among others. b) Violates the Technological Infrastructure in such a way that it compromises the information it processes, stores, or transmits. c) Constitutes a violation of the information security policies and procedures. d) Constitutes the materialization of a detriment to the electronic payment fund institution, whether by extraction, alteration, or loss of information; by failures derived from the use of hardware, software, systems, applications, networks, and any other information transmission channel; by unauthorized accesses that result in the improper use of information or systems; by fraud or theft; by an interruption of the activities carried out by the institution itself caused by some action; or by attacks against interconnected infrastructures known as cyberattacks.
Personal Information:
the combination of the name, surname, and another element of information that allows identifying the Client or the recipient of Transfers, such as address, phone numbers, or email addresses, among others.
Sensitive Information:
the combination of the name, surname, or another element of information that allows identifying the Client or the recipient of Transfers, as well as the information of the Client Identifier, of the Accounts, of the respective Card numbers, of previous Operation information, as well as information that allows Authentication and other data of a financial nature.
Administration Body:
the sole administrator or the board of directors of an electronic payment fund institution, as the case may be.
Business Continuity Plan:
the document that integrates the set of strategies, procedures, and actions previously determined by the corresponding electronic payment fund institution, to allow, upon the occurrence of Operational Contingencies, the continuity in the Operations, activities, or in the performance of the critical processes of said electronic payment fund institution, or their timely restoration, as well as the mitigation of the impacts resulting from said Operational Contingencies.
Security Master Plan:
the document that integrates the set of projects determined by the corresponding electronic payment fund institution, which must be executed in the short, medium, and long term, to establish correct information security management and prevent Information Security Events from materializing into Information Security Incidents.
Strategic Policy on Business Continuity and Information Security:
the document that integrates the strategies of the electronic payment fund institution in matters of business continuity and information security related to its operation in accordance with these Provisions, without prejudice to any other element in matters of risk management subject to the general provisions that, to this effect, the CNBV issues in accordance with Article 48 of the Law for Regulating Financial Technology Institutions.
Session:
the period during which the Client, holder of an Account administered by the electronic payment fund institution, can carry out balance inquiries or inquiries about their carried out Operations or initiate others, once they have entered the Instruction Channel with their Client Identifier.
Card:
the disposal means of the electronic payment funds registered in the Account in question, constituted as the set of data that, when processed through determined systems, allows initiating a charge instruction to said Account, distinct from that other instruction made to execute a Transfer.
Independent Third Party:
the competent professional capable of carrying out evaluation work on the compliance with the requirements that electronic payment fund institutions must fulfill in accordance with these Provisions, who is external to the electronic payment fund institution and who meets, insofar as applicable, the characteristics and requirements provided in Article 58 of these Provisions.
Transfer:
Fund Transfers, Electronic Payment Fund Transfers, and Money Transmissions, interchangeably or jointly.
Fund Transfer:
that Operation referred to in Article 22, fraction III of the Law for Regulating Financial Technology Institutions carried out between the electronic payment fund institution in question and another electronic payment fund institution, Financial Entity, foreign financial entity, or foreign electronic payment fund institution, pursuant to which the first one makes (i) the credit in an Account for the equivalent amount of money to that indicated in the respective order it receives, derived from the charge that that other electronic payment fund institution or entity makes in the corresponding account, or (ii) the charge in an Account equivalent to that amount of money that the Client indicated in the order they issue so that, once the redemption of said funds is carried out, said amount is credited to the other electronic payment fund institution or entity to whom said order is sent for credit in the deposit account indicated in the order itself. For the purposes of this definition, foreign electronic payment fund institutions shall be understood as legal entities located outside national territory that, in accordance with the applicable legislation in the jurisdiction in question, carry out activities similar to those of issuing, administering, redeeming, and transmitting instruments equivalent to electronic payment funds.
Electronic Payment Fund Transfer:
that Operation referred to in Article 22, fraction II of the Law for Regulating Financial Technology Institutions, carried out by the same electronic payment fund institution in accordance with the contracts celebrated with its Clients for the opening of Accounts, according to which said institution credits a determined amount of electronic payment funds in one of said Accounts, derived from the charge for said amount in any other of those Accounts.
Money Transmission:
that Operation referred to in Article 25, fraction II of the Law for Regulating Financial Technology Institutions that the authorized electronic payment fund institution carries out.
UDI: the accounting units known as “Investment Units” established in the “Decree establishing the obligations that may be denominated in Investment Units and reforming and adding various provisions of the Federal Tax Code and the Income Tax Law”, published in the Official Gazette of the Federation on April 1, 1995, as it may be modified or added from time to time.
Technology Infrastructure User: the person or component of the Technology Infrastructure of the electronic payment fund institution, which holds the respective authorization to access, use, or operate any component of this. This definition does not include Clients of the electronic payment fund institution.
CHAPTER II
ON INFORMATION SECURITY
First Section
On Technology Infrastructure vis-à-vis Clients
Subsection A
On the execution of contracts through Instruction Channels and Operations through them
Article 2.- Electronic payment fund institutions, when agreeing to the execution of Operations and the provision of services through Instruction Channels, must require the express consent of their Clients for such purposes, which may be obtained through the Authentication process referred to in Article 7 of these Provisions. Additionally, electronic payment fund institutions must:
I. In the respective contracting, clearly and precisely establish the following:
a) The Operations and services that may be performed and provided through such Instruction Channels. b) The mechanisms and procedures for Client Authentication, as well as the responsibilities of the Client and the electronic payment fund institution regarding the execution of Operations and the provision of services through the respective Instruction Channel. c) The mechanisms and procedures for notifying the Client of the Operations performed and services provided by the electronic payment fund institutions through the Instruction Channels. d) The mechanisms and procedures for canceling service contracts, which must be similar to those of the contracting itself, considering Customer Service Channels, Client Identification Mechanisms, and Authentication procedures. e) The operational restrictions applicable according to the Instruction Channel in question, in accordance with what is provided in this Chapter.
II. Inform their Clients, prior to contracting, the terms and conditions for the use of the Instruction Channels, keeping such information available for consultation at all times.
III. Inform their Clients of the risks inherent in the use of the respective Instruction Channels, as well as make known suggestions to prevent the execution of unauthorized acts or any other irregular or illegal acts, through which Operations referred to the Accounts of which they are holders may be carried out.
Article 3.- Electronic payment fund institutions, regarding Instruction Channels, may:
I. Allow their Clients to contract additional Operations and services to those originally agreed upon.
II. Modify the terms and conditions for the provision of previously agreed services that may have a financial impact on their Clients, prior to their express consent, which may be obtained by such institutions through the Authentication process referred to in Article 7 of these Provisions, from the Instruction Channel in question.
III. Allow Clients to contract the use of another Instruction Channel, provided that the electronic payment fund institution requires, at least, one Authentication Factor.
Article 4.- Electronic payment fund institutions must notify their respective Clients, through the means agreed upon with them and within a period not exceeding five seconds, when through Instruction Channels, any of the following Operations are executed or any of the following services are requested from the electronic payment fund institutions:
I. Transfers and delivery of money amounts resulting from charges to the Client’s Account in question, starting from when the accumulated daily amount of Operations performed exceeds the equivalent in national currency to 60 UDI’s, or when each individually exceeds the equivalent in national currency to 25 UDI’s.
II. Registration or modification of the Client notification means, in which case the respective electronic payment fund institution must send the notification referred to in this article through the means previously agreed upon with the Client, as well as through the new means.
III. Contracting of another service provided through Instruction Channels.
IV. Deactivation, blocking, reactivation, and modification of Authentication Factors.
Electronic payment fund institutions must ensure that the notifications sent in accordance with this article do not contain Personal Information or Sensitive Information of the Client.
Nevertheless, electronic payment fund institutions must enable mechanisms so that their Clients can, at their choice, receive information about the Account balance resulting from services provided through the Instruction Channels.
For the purposes of the notification referred to in this article, electronic payment fund institutions that issue disposition instruments must carry out such notification, both to their Clients and to the holders of the issued disposition instruments.
Electronic payment fund institutions may disable notifications when any of the Operations or services provided in fractions I to IV of this article are executed, prior to express request by their Clients, which must be obtained by such institutions through the Authentication process referred to in Article 7 of these Provisions, and having previously informed their Clients of the risks associated with such disabling.
Subsection B
On Authentication in Instruction Channels
Article 5.- For the purposes of these Provisions, the Authentication Factors that electronic payment fund institutions must use may only include information belonging to any of the following categories:
I. Information that the electronic payment fund institution provides to the Client or allows said Client to generate, under the understanding that only such person knows it, so that they can enter the system authorized by the electronic payment fund institution, in order to initiate a Session and execute the Operation in question. The Authentication Factors referred to in this fraction must comply with any of the following schemes:
a) Passwords that meet, at least, the following:
1. It must be composed of at least six consecutive characters and include alphanumeric characters.
2. Under no circumstances may the following information be used as passwords:
i) The Client Identifier. i). The name or trade name of the electronic payment fund institution. ii). More than three identical characters consecutively. iv) More than three numerical or alphabetic characters sequentially. b) Questionnaires conducted through electronic messaging channels, call centers, or automated agents, provided they observe the following:
1. Data that the Client knows and that electronic payment fund institutions can validate are required, maintaining the confidentiality of such information.
2. A set of open questions in questionnaires of at least three questions is defined, and in the event that the answer to one of them is incorrect, an additional question may be formulated. This set of questions must be unique per medium through which the questionnaire is presented, allowing the repetition of only one question across all mediums. Furthermore, randomness mechanisms must be implemented in the presentation of questions to the Client.
Under no circumstances can the answers to these questions be data displayed on the Instruction Channel. Furthermore, the information or data of the answer to two or more questions cannot be sent by electronic payment fund institutions to their Clients through the same communication channel, whether by printed or electronic means.
3. The answers provided by their Clients are validated through computer tools, without the operator or automated system being able to consult or access Client Authentication data.
Electronic payment fund institutions must allow their Clients to change the Authentication Factors of this category, when the latter so request, under the terms provided in these Provisions.
Electronic payment fund institutions may use questionnaires to unlock Authentication Factors that have previously been blocked, provided they do so in combination with a second Authentication Factor different from the questionnaire.
II. Information contained, received, or generated by electronic means or devices that only the Client possesses, including that obtained by devices or applications generating dynamic passwords that the electronic payment fund institution provides to the Client, as well as that which allows associating electronic means or devices with a Client through secure exchange mechanisms for credentials or cryptographic keys. The foregoing is subject to the information being contained, received, or generated in such electronic devices that only the Client possesses and meeting the following characteristics:
a) Possess properties that prevent duplication or alteration. b) Be dynamic information that cannot be used more than once with a validity that cannot exceed two minutes, or be dynamic information generated for the execution of an operation, as well as subsequent operations without any modification, in which case it will be considered, for the purposes of this subsection, as an independent element to authenticate operations as authorized by the Client only for the first operation in which it is used. c) Not be known prior to its generation and use by officials, employees, representatives of the electronic payment fund institution, or third parties. Electronic payment fund institutions may provide Clients with means or devices that generate single-use dynamic passwords using Operation information, by capturing data, so that such Password can only be used for the requested Operation. In this case, the validity established in subsection b) of this fraction will not apply.
III. Information derived from the Client’s own characteristics, such as those of a biometric nature, fingerprints, hand or face geometry, iris or retina patterns, and voice recognition, among others. For the use of this information, electronic payment fund institutions must have prior authorization from the CNBV and the Bank of Mexico.
In all cases, two or more Authentication Factors will be considered independent if the compromise of one of the Authentication Factors does not compromise the reliability of the others.
Article 6.- Electronic payment fund institutions may request authorization from the CNBV and the Bank of Mexico to use Authentication Factors referred to in fractions I and II of Article 5 of these Provisions with characteristics different from those indicated in said article, as well as the use of the information indicated in fraction III of the mentioned article, provided they demonstrate that the technology used, in the judgment of both Financial Authorities, is reliable for authenticating their Clients.
The request to obtain the authorization indicated in the preceding paragraph must contain the following:
I. The detailed description of the process, which must be approved by the Administration Body, as well as the technology used in each part of it.
II. The description of the means necessary for the transmission and storage of information that guarantee its integrity, the correct reading of the data, the impossibility of manipulation, as well as its adequate conservation and availability.
For the case prescribed in fraction III of Article 5 of these Provisions, the electronic payment fund institution formulating the authorization request referred to in this article must additionally present evidence collected from controlled tests demonstrating that the technological solution and methods used are effective for authenticating their Clients. Such evidence may be obtained by the electronic payment fund institution itself or by a specialized company in Authentication Factor certification with the capacity to present reports.
Electronic payment fund institutions must have mechanisms and procedures to ensure that, in the use of the Authentication Factors referred to in fraction III of Article 5 of these Provisions, the information transmitted for the Authentication process is different each time it is generated, by incorporating additional information, such as timestamps, random numbers, and counters, among others, in the message encryption process, so that in no case can it be used again or duplicated.
Electronic payment fund institutions must submit the authorization requests and other information referred to in this article to the Bank of Mexico and the CNBV, in accordance with what is established in Article 59 of these Provisions.
Article 7.- Electronic payment fund institutions, in order to allow access to Instruction Channels, must carry out Client Authentication. To perform such Authentication, electronic payment fund institutions must collect and validate, at least, the following:
I. The Client Identifier and
II. An Authentication Factor.
The Client Identifier must be unique for each Client and must be associated with all Operations performed by the latter.
Furthermore, electronic payment fund institutions must keep evidence of the Authentication, in accordance with what is established in Article 29, fraction IV of these Provisions.
Article 8.- Electronic payment fund institutions must request, at least, two independent Authentication Factors on each occasion when the following is intended to be performed:
I. Registration, cancellation, or any other modification related to the beneficiaries of the Account referred to in the seventh paragraph of Article 29 of the Law for Regulating Financial Technology Institutions.
II. Changes regarding Authentication Factors.
III. Request for account statements.
IV. Registration and modification of the Client notification means.
Electronic payment fund institutions are subject to what is established in Circular 12/2018 issued by the Bank of Mexico, in the case where they receive claims for unrecognized charges from their Clients resulting from any of the operations described in fractions I, II, and IV of this article.
For the purposes of what is provided in this article, electronic payment fund institutions may take into account the Authentication Factor used for initiating a Session in the Instruction Channels in question.
Article 9.- Electronic payment fund institutions must have policies and procedures to ensure that, in the generation, delivery, storage, unlocking, and restoration of Authentication Factors, only the Client receives, activates, knows, unlocks, and restores them.
Regarding passwords defined or generated by electronic payment fund institutions during the restoration of Authentication Factors referred to in subsection a) of fraction I of Article 5 of these Provisions, the institutions themselves must provide mechanisms and procedures through which the Client must modify them immediately after initiating the corresponding Session, when so required according to the type of Instruction Channel and prior to performing any Operation, validating that the Authentication Factors referred to in this paragraph are different from the passwords defined by the electronic payment fund institutions themselves.
Subsection C
On information security requirements in Instruction Channels
Article 10.- Electronic payment fund institutions must establish mechanisms and procedures so that their Clients, when accessing Instruction Channels, can recognize the institutions themselves, for which they must adhere to the following:
I. Provide personalized and sufficient information so that Clients can verify, before performing the Authentication procedure, that it is indeed the electronic payment fund institution of which they are a Client. For this, electronic payment fund institutions may use the following information:
a) That which the respective Client knows or has provided to the electronic payment fund institution, or which they have agreed with the electronic payment fund institution for this purpose, such as name, alias, and images, among others. b) That which the respective Client can verify through a means agreed upon for this purpose with the electronic payment fund institution.
II. Once the Client accesses the Instruction Channel in question, the electronic payment fund institution must make available to them, at least, the following information:
a) Date and time of the last access to the Instruction Channel in question, and b) Client’s first and last name.
The foregoing will not apply when the Client uses Instruction Channels that do not require prior interaction for the instruction of Operations, such as point-of-sale terminals.
Article 11.- Electronic payment fund institutions must provide for what is necessary so that, once the Client is authenticated in the Instruction Channel, the Session cannot be used by a third party. For the purposes of the foregoing, electronic payment fund institutions will establish, at least, the following mechanisms:
I. Terminate the Session immediately and automatically and inform the Client of the reason in any of the following cases:
a) When there is inactivity for more than 5 minutes. b) When during a Session, the electronic payment fund institution identifies relevant changes in the communication parameters of said Session, such as identification of the Instruction Channel, range of addresses of communication protocols, and geographic location, among others, that allow the institution to infer that it might be a Session theft.
II. Prevent simultaneous access in the same Instruction Channel, by using the same Client Identifier and making it known to the Client. Furthermore, electronic payment fund institutions must detect attempts to access the Instruction Channel with incorrect Authentication Factors, and in case of exceeding three consecutive failed access attempts, access to the Instruction Channel in question must be temporarily restricted, blocking the Client’s Authentication Factor for a period of ten minutes, notifying the Client about said blocking through the means previously agreed upon with them.
After the ten minutes indicated in the preceding paragraph have elapsed, the Client may have one more attempt to access the Instruction Channel, and in case that an incorrect Authentication Factor is entered, said Authentication Factor will be blocked permanently until the Client performs the unlocking process referred to in Article 9 of these Provisions.
The electronic payment fund institution must notify the Client of this permanent blocking, through the means agreed upon between the parties.
III. In the event that electronic payment fund institutions offer third-party services through links, they must communicate to their Clients that, upon entering such
services, it will be redirected to another link whose security does not depend on nor is the responsibility of said institution.
In the event that an electronic payment fund institution intends to establish parameters different from those established in this article, it must obtain prior authorization from the Bank of Mexico and the CNBV. Requests for such authorizations must be submitted in accordance with Article 59 of these Provisions.
Article 12.- Electronic payment fund institutions, in the use of the Customer Identifier and Authentication Factors, must comply with the following requirements:
I. Have the necessary mechanisms to prevent the reading or display in the Instruction Channel of the information provided by the Customer and used in the Identification and Authentication Mechanisms.
II. Ensure that, when at least two Authentication Factors are used, they are independent.
III. Have procedures to restore Authentication Factors, in such a way that the Personal Information or Sensitive Information of the Customer is not compromised.
IV. Have procedures to invalidate Authentication Factors, in order to prevent their use in a service provided by the electronic payment fund institution, when a Customer or the electronic payment fund institution itself cancels the use of said service or when the respective Customer ceases to be a Customer of said institution.
Article 13.- Electronic payment fund institutions may only store information related to the Authentication Factors used by their Customers in the Instruction Channels, when such storage is carried out under cryptographically secure protocols and it is not possible that:
I. The original information of the Authentication Factors is obtained from the stored information.
II. Different sets of data generate the same stored information.
Article 14.- Electronic payment fund institutions must establish procedures and mechanisms so that their Customers, who carry out Operations or request the services of these through Instruction Channels, can at all times deactivate the carrying out of said Operations or the provision of those services temporarily, as well as establish procedures to reactivate the use when the Customers request it.
Electronic payment fund institutions must allow Customers to temporarily deactivate the carrying out of the Operations and the provision of the services mentioned in the previous paragraph, through the Instruction Channels agreed upon with them for this purpose, requesting, at least, one Authentication Factor.
For the reactivation of the carrying out of Operations and the provision of services that electronic payment fund institutions provide through Instruction Channels, said institutions must allow Customers to use the Instruction Channels agreed upon for this purpose, for which they must require, at least, one Authentication Factor. Electronic payment fund institutions must observe what is stated in Article 7 of these Provisions, in order to allow access to the Instruction Channel in question once the service has been reactivated.
Second Section
On Technological Infrastructure in Internal Processes
Article 15.- Electronic payment fund institutions, regarding components of communications and computing, must establish the following security aspects:
I. Logical, or logical and physical, segregation of different networks into different domains and subnets, depending on the function they perform or the type of data transmitted, including segregation of production environments from development and testing environments, as well as perimeter security and network components that ensure that only authorized traffic is permitted.
In particular, in those segments with links to the outside, such as the Internet, providers, authorities, other networks of the electronic payment fund institution or headquarters, and other third parties, all of this referring to those services defined as critical by the electronic payment fund institution itself, related, at least with payment systems, Encryption equipment, or Operation Authorizers, among others, they must consider safe zones, including those known as demilitarized zones (referred to as DMZ, from its English acronym).
II. Secure configuration according to the type of component considering, at least, ports and services, incoming and outgoing connections to other networks, including the Internet, permissions granted under the principle of least privilege, use of removable storage media, access lists, manufacturer updates, and reconfiguration of factory parameters. The principle of least privilege shall be understood as the enabling of access only to the information and resources necessary for the development of the functions specific to each User of the Technological Infrastructure.
III. Security mechanisms in applications that ensure that, during their execution, they are protected from attacks or intrusions, such as code injection, session manipulation, information leakage, and alteration of access privileges, among others. Such mechanisms must be implemented, both for applications provided by third parties, as well as for applications developed, implemented, and maintained by the electronic payment fund institution itself.
Article 16.- Electronic payment fund institutions must encrypt Personal Information and Sensitive Information received, generated, stored, or transmitted in their own or contracted third-party Technological Infrastructure, as well as images of identification documents issued by official authorities and biometric information of Customers, and any other that they determine in accordance with their policies. In the case of Sensitive Information, encryption is exempted for information related to Operations, provided that such information is stored in tables or repositories different from those used to store the rest of the Personal Information and Sensitive Information, and there are security mechanisms that allow its dissociation and prevent access to said information, if not authorized to do so.
The mechanisms and procedures to decrypt the information referred to in this article, as well as the cryptographic keys required for such purpose, must be under the exclusive control of the Chief Information Security Officer of the respective electronic payment fund institution.
Article 17.- Electronic payment fund institutions must have procedures and mechanisms that allow structuring the Personal Information and Sensitive Information stored in the Technological Infrastructure, in such a way that the personal data of Customers cannot be related to the information regarding their Operations, including, among others, the amounts, as well as the names or designations of the recipients or senders of payments made by Customers. This relationship can only be generated through procedures or computer applications for consultation, designed by the electronic payment fund institution, which must be executed on demand each time it is necessary to build this relationship, either through manual mechanisms or computer systems.
Article 18.- Electronic payment fund institutions, regarding information related to Authentication Factors, must comply with the following requirements:
I. Maintain information security procedures for the custody, distribution, and assignment of Authentication Factors of their Customers.
II. Establish procedures and mechanisms so that information related to Authentication Factors is not known by any of its officials, employees, or representatives, or by any third party.
III. Establish procedures and mechanisms that prevent requesting from their Customers, through their officials, employees, representatives, or third parties, partial or complete information related to Authentication Factors.
Article 19.- Electronic payment fund institutions must establish procedures and mechanisms that ensure that, when discarding or decommissioning storage components or physical devices, known as hardware, of the Technological Infrastructure, the Customer information contained in said components or devices is unrecoverable.
Article 20.- Electronic payment fund institutions are obliged to use tools that allow detecting computer viruses and malicious codes in the Technological Infrastructure, as well as procedures that allow their periodic update.
Article 21.- Electronic payment fund institutions must perform, prior to the start of their operation and at least every two months, vulnerability scanning tests of all components of their own Technological Infrastructure, or of third parties and commissioned agents contracted, in which they store, process, or transmit information of electronic payment fund institutions and their Customers. Additionally, in the event of modifications or updates to the Technological Infrastructure, electronic payment fund institutions must perform vulnerability scanning tests on the updated or modified components, before putting the mentioned modifications or updates into the production environment, and must take the necessary actions to remediate, at least, vulnerabilities classified as critical and high. The general manager or, in its case, the sole administrator, will be responsible for monitoring that these tests are carried out, either through the institution itself or a third party contracted for this purpose.
Electronic payment fund institutions must generate a documented remediation plan to address the vulnerabilities detected in the tests mentioned in the previous paragraph, in which their attention must be prioritized according to the criticality of said vulnerabilities, in accordance with the classification made by the institution itself.
The remediation plans referred to in the previous paragraph must be validated by the Chief Information Security Officer. Likewise, said plans must contain, at least, the indication of the personnel responsible for their implementation and execution, detail of the defined activities, start and end dates of these, as well as the technical, material, and human resources required. The aforementioned remediation plans must be prepared within ten business days following the identification of the vulnerabilities and be available to the CNBV and the Bank of Mexico, when said authorities request them.
Article 22.- Electronic payment fund institutions must have procedures and mechanisms to prevent the installation of any service, application, or software, except those that:
I. Are necessary for the operation of the electronic payment fund institution.
II. Are authorized by the Chief Information Security Officer of the electronic payment fund institution, in each of the elements of its Technological Infrastructure.
Article 23.- Electronic payment fund institutions that have their own infrastructure for their operation and the safeguarding of information, must establish procedures and mechanisms to restrict access, both to physical connection ports and peripheral devices, as well as to computing or telecommunications infrastructure.
Likewise, when electronic payment fund institutions contract a third party for the infrastructure necessary for their operation and the safeguarding of information, they must ensure that said third party has the procedures and mechanisms referred to in the previous paragraph.
Article 24.- Electronic payment fund institutions must have access control procedures and mechanisms for the Technological Infrastructure that are robust and secure, for which they must comply, at least, with the following requirements:
I. Logical access controls to computing and telecommunications infrastructure, as well as their Technological Infrastructure and software infrastructure such as databases, operating systems, and software containers.
II. Controls for the management of Technological Infrastructure Users and passwords.
III. Controls that ensure the tracking and monitoring of access to systems used for the storage of Customer information, including automatic audits that allow the review of individual-level access to Customer information, the actions taken after access to such information, invalid access attempts, changes in Customer Identification and Authentication for access to Customer data, as well as all changes made to the storage system.
In the event that the electronic payment fund institution intends to use any practice or standard different from those mentioned above, it must obtain prior authorization from the Bank of Mexico and the CNBV, for which it must present the respective request in accordance with what is established in Article 59 of these Provisions. The CNBV and the Bank of Mexico may publish on their Internet pages the standards that meet the aforementioned requirements.
Article 25.- Electronic payment fund institutions must establish information security policies that their personnel are obliged to observe, which include the correct use of resources used for the storage of Customer data, prior review of the profiles of personnel that the electronic payment fund institution intends to hire, as well as risk assessment processes carried out at least once a year.
Third Section
General Provisions for Technological Infrastructure
Article 26.- Electronic payment fund institutions must establish and document policies and mechanisms so that Instruction Channels only use those communication protocols that guarantee the confidentiality of information in point-to-point communication, based on the best practices and international standards of computer security in this matter that, prior agreement between the CNBV and the Bank of Mexico, are published, on their respective Internet sites. The encryption mechanisms implemented for said communication protocols must be valid, not have known vulnerabilities, and contemplate that the length of encryption keys is robust.
In the event that any electronic payment fund institution intends to use any practice or standard different from those mentioned above, it must obtain prior authorization from the Bank of Mexico and the CNBV. For these purposes, electronic payment fund institutions must present the requests referred to in this article, in accordance with what is established in Article 59 of these Provisions.
Article 27.- Electronic payment fund institutions must have validation measures to guarantee the authenticity of processes executed by the different components of the Technological Infrastructure, including Operations carried out by Customers, considering, at least, the following:
I. The verification of the truthfulness and integrity of the information regardless of whether it is static or in transit.
II. Authentication between components of the Technological Infrastructure, which ensure that only legitimate service requests are executed from their origin to their execution and registration.
III. Messaging, communication, and Encryption protocols, which must ensure the integrity and confidentiality of information.
IV. The identification of atypical processes, ensuring that there are monitoring tools or automatic alert measures for their attention, by the corresponding operational areas.
V. The update and maintenance of digital certificates and components provided by service providers that are integrated into the execution processes.
The measures referred to in this article must be established in accordance with the degree of risk that electronic payment fund institutions define for each type of process.
Article 28.- Electronic payment fund institutions, for the implementation and development of their computer systems, either by the institution itself or through a third party specialized in computer program development contracted by it, must comply with the following:
I. Document their processes, functionalities, and configurations, including their development or acquisition methodology, as well as the record of their changes, updates, and the detailed inventory of each component of the Technological Infrastructure.
The development process must implement information security aspects, at least, in the following stages:
a) Elaboration of requirements.
b) Design of the computer system.
c) Development or acquisition of the computer system according to the design referred to in the preceding subsection b).
d) Validation of functionalities, purpose, capacity, and quality of the computer system.
e) Vulnerability tests and code analysis prior to their release.
f) Release or installation of the computer system.
g) Control of changes in the computer system.
h) Secure destruction of information at the end of the useful life of components or systems.
i) In the event that the software is developed by an external specialized company, the electronic payment fund institution must request that the delivered software contain mechanisms to validate its integrity and authenticity at the time of installation in its Technological Infrastructure.
II. Computer systems must consider the following functionalities throughout their entire operation process:
a) Authentication mechanisms between the different components used for the operation of the electronic payment fund institution.
b) Use of electronic signatures to guarantee the integrity and non-repudiation of the operational information of the electronic payment fund institution, regardless of whether it is static or in transit information.
c) Management of Technological Infrastructure Users and their privileges.
d) Use of encrypted communications for the communication of different computer systems and their components.
III. Review statically, at least through automated tools, the security of the computer system every time an update of it is performed.
Article 29.- Electronic payment fund institutions must maintain the robustness of their Technological Infrastructure, for which they must have:
I. Controls that allow reviewing, at least once a year, that the components that provide security to their Technological Infrastructure are valid, and, if applicable, update the components that are no longer so.
II. Procedures and tools for the detection of alteration or falsification of the information contained in the Technological Infrastructure.
III. Records that allow monitoring, auditing, and tracking the accesses and activities carried out by the different Users of the Technological Infrastructure of the computer systems, regardless of the level of privileges established for their access and the medium or protocol of access. These records must include, at least, the following information:
a) Date, hour, minute, and second of the activities carried out by Technological Infrastructure Users.
b) Elements that allow identifying the Technological Infrastructure User who carries out said activities.
c) Identification data of the access point used by the Technological Infrastructure User to carry out the operation in question.
d) Internet protocol addresses or similar, according to the electronic medium used by the Technological Infrastructure User.
The generated information must be stored securely for a minimum period of one hundred eighty calendar days and contemplate mechanisms to prevent its alteration, as well as maintain internal control procedures for its access and availability.
IV. Records that allow monitoring, auditing, and tracking the accesses and activities carried out by the different Customers. These records must include, at least, the following information:
a) Date, hour, minute, and second of the activities carried out by Customers.
b) Account numbers involved in the Operation, including that Account belonging to the orderer of the Operation and, if applicable, that of the recipients, and other information that allows identifying the Operations carried out by Customers or those who have used the respective disposal medium.
c) Identification data of the Instruction Channel used by the Customer or by whoever has used the respective disposal medium to carry out the Operation in question, as well as the Authentication Factors used for its instruction.
d) Internet protocol addresses or similar, the telephone line number or other data, according to the Instruction Channel used by the Customer or user of the disposal medium.
The generated information must be stored securely for a minimum period of one hundred eighty calendar days from its generation, through mechanisms previously determined to prevent its alteration, as well as maintain internal control procedures for its access and availability.
This information must be provided to Clients or users of the disposal instrument who expressly request it from the electronic payment fund institution through its customer service channels, within a period not exceeding ten business days, provided that it concerns Operations carried out in the Clients' or users' own accounts during the one hundred eighty natural days prior to the information request.
V. Records that allow monitoring, auditing, and tracking of all operations performed by the information systems, as well as blocking transmissions that do not meet the established security criteria. These records must include the following:
a) Date, hour, minute, and second of the activities performed by the information systems. b) Identification data of the access point used by the information system to perform the relevant operation. c) Internet protocol addresses or similar, according to the electronic medium used by the information system.
The generated information, including that from other media, must be stored securely for a minimum period of one hundred eighty natural days and include mechanisms to prevent alteration, as well as internal control procedures for access and availability.
Article 30.- Electronic payment fund institutions must have a Business Continuity and Information Security Strategic Policy, which must be approved by its Governing Body.
Article 31.- Electronic payment fund institutions must have a Security Master Plan, which must be approved by the General Director or, in his absence, by the sole administrator. The Security Master Plan must be aligned with the electronic payment fund institution's business strategy and with what is established in the Business Continuity and Information Security Strategic Policy, as well as define and prioritize projects in the area of information security, with the objective of reducing exposure to technological risks and the realization of Information Security Incidents to acceptable levels as defined by the Governing Body, based on an analysis of the current situation.
For the approval of the Security Master Plan, the General Director or, where applicable, the sole administrator must verify that it contains initiatives aimed at improving existing work methods and contemplates the controls required in accordance with applicable provisions. Modifications to the Security Master Plan must be approved by the General Director or, where applicable, by the sole administrator.
In the case of electronic payment fund institutions that have a General Director and a Board of Directors, the former must inform the Board of the content and modifications to the Security Master Plan, and must have evidence of its approval and implementation.
Article 32.- Electronic payment fund institutions must implement procedures and mechanisms to be followed for the handling of Information Security Incidents in their Technological Infrastructure, which include the identification, containment, and adequate collection and safeguarding of evidence of such incidents.
Article 33.- Electronic payment fund institutions must evaluate or audit, at least once a year, the information security of the Technological Infrastructure. Additionally, as part of such evaluation or audit work, electronic payment fund institutions must submit to the Governing Body, within the specified timeframe, the following documents:
I. Report specifying the computer risk level for the Technological Infrastructure.
II. Remediation plan to address observations classified with high and very high criticality, found in the aforementioned evaluation or audit.
III. Evidence of the implementation of remediation measures in accordance with the plan indicated in fraction II of this article.
IV. Evidence of the mitigation of the referred observations in accordance with the plan mentioned in fraction II of this article.
Electronic payment fund institutions, prior to the start of operations, must perform the evaluation or audit referred to in the previous paragraph, on those elements or components of the Technological Infrastructure, whether own or contracted from third parties, used to carry out the issuance, administration, redemption, or transmission of electronic payment funds, including the services they provide to their Clients to carry out these activities, as well as the storage of Personal Information and Sensitive Information.
For the purposes of what is established in the first and second paragraphs of this article, electronic payment fund institutions that use Technological Infrastructure from third parties must have, from these third parties, the following documents:
I. Results of the evaluation or audit performed at least once a year and prior to the start of operations for such third parties.
II. Remediation plan to address observations classified with high and very high criticality, found in the evaluation or audit referred to in the previous fraction I.
III. Evidence of the implementation of the remediation plan and the mitigation of the observations indicated in fraction II preceding.
Electronic payment fund institutions must submit to the Governing Body what is referred to in the preceding fractions.
The documents referred to in this article must be available for consultation by the Bank of Mexico and the CNBV, when such Financial Authorities so request, and in this case, must be sent in accordance with what is established in Article 59 of these Provisions.
Article 34.- Electronic payment fund institutions must hire a legal entity, with personnel who have verifiable technical capacity through industry certifications in the matter, so that, at least, every two years, penetration tests are performed in the different systems and applications of the Technological Infrastructure, with the aim of detecting errors, vulnerabilities, unauthorized functionality, or any code that puts or may put at risk the information and assets of Clients and of the electronic payment fund institution itself.
The electronic payment fund institution must send to the Bank of Mexico and the CNBV, within twenty business days, counted from the date on which the corresponding tests have ended, a report with the conclusions of such tests, in accordance with what is established in Article 59 of these Provisions. The report must be digitally signed by the General Director or, where applicable, by the sole administrator, and must be encrypted in accordance with what is provided in Article 59 of these Provisions.
In the event that, from the penetration tests performed, observations of high or very high criticality arise, the electronic payment fund institution in question must present a documented remediation plan to rectify such observations to the Bank of Mexico and the CNBV, within a period not exceeding 20 business days from the end of the penetration tests. The remediation plan must be digitally signed by the General Director or, where applicable, by the sole administrator, and encrypted in accordance with what is provided in Article 59 of these Provisions. The CNBV and the Bank of Mexico may make observations on this remediation plan at any time.
Once the remediation activities for the observations of high or very high criticality referred to in the previous paragraph are concluded, the electronic payment fund institution must again, within a period not exceeding two months after the date of conclusion of such activities, perform penetration tests to verify that the respective vulnerabilities have been mitigated.
Electronic payment fund institutions must document in manuals the methodologies used to classify the criticality and risk of the findings of information security tests, including those of penetration and vulnerabilities.
Article 35.- Electronic payment fund institutions must have a person who, among their functions, serves as the Chief Information Security Officer, known as CISO by its acronym in English (Chief Information Security Officer). These functions may be performed by a third party, provided that it complies with what is stated in this article.
The Chief Information Security Officer must be appointed by the General Director or, where applicable, by the sole administrator, and must not have conflicts of interest with respect to the person responsible for the auditing and information technology functions of the electronic payment fund institution.
Likewise, they cannot perform functions related to the operation of the information security of the electronic payment fund institution itself.
The Chief Information Security Officer may support, in the exercise of their functions, representatives from the different business units.
Electronic payment fund institutions may appoint the General Director or, where applicable, the sole administrator as the Chief Information Security Officer, for a maximum period of twelve months counted from the date on which they obtain authorization to act as electronic payment fund institutions.
Article 36.- The Chief Information Security Officer of the electronic payment fund institution must, at least:
I. Participate in the definition and verify the implementation and continuous compliance of the information security policies and procedures indicated in these Provisions.
II. Prepare the Security Master Plan, which must contain, for each project defined, the project name, objective, scope, start and end dates, involved areas, and projected investment. The plan referred to in this fraction must be reviewed and updated at least annually.
III. Verify, at least annually, the definition of access profiles for the Technological Infrastructure of the electronic payment fund institution, whether own or provided by third parties, according to job profiles, known as functional segregation, including those with high privileges, such as administration of operating systems, databases, and applications.
IV. Ensure, at least annually or sooner in case of an Information Security Incident, the correct assignment of access profiles to Users of the Technological Infrastructure. The function referred to in this fraction may be performed through representative and random samples.
Likewise, the Chief Information Security Officer will be responsible for the temporary authorization of exceptional accesses, such as those of Users of the Technological Infrastructure of development environments with access to production environments, accesses due to contingency events, or any other privileged access that does not correspond to the policy determined by the electronic payment fund institution. Likewise, they must have a record containing the name of the User of the Technological Infrastructure, associated application, environment, reason for the exception, and start and end dates of the assignment.
V. Approve and verify compliance with the measures adopted to rectify deficiencies detected as a result of the functions referred to in fractions III and IV of this article, as well as the findings, both of internal and external audits related to the Technological Infrastructure and information security.
VI. Manage information security alerts communicated by the CNBV or other means, as well as Information Security Incidents, considering the stages of identification, protection, detection, response, and recovery.
VII. Preside over the team formed for the detection and response to Information Security Incidents in the electronic payment fund institution.
VIII. Inform the Governing Body, or the audit committee and risk committee if they exist, in the next session, as applicable, after the verification of the Information Security Incident, regarding the actions taken and the follow-up on measures to prevent or avoid the recurrence of the mentioned incidents.
IX. Verify that annual training programs directed at all personnel, as well as awareness programs in the matter of information security for Clients, including, where applicable, third parties providing services to them, are implemented, which contemplate, among other aspects, the roles and responsibilities that Users of Technological Infrastructure have regarding this matter.
X. Submit monthly to the General Director or, where applicable, to the sole administrator, the management report on information security. This report must be submitted to the audit committee and risk committee or, in the absence of these, to the Board of Directors of the electronic payment fund institution, in their next session.
XI. Consider, at least, the risk indicators in the matter of information security established in Annex 1 of these Provisions, and inform the Governing Body, and where applicable, the audit committee or risk committee, of the result of the evaluation of such indicators.
XII. Respond to the requirements formulated by the Bank of Mexico and the CNBV and internally within the electronic payment fund institution, in the matter of information security.
Electronic payment fund institutions must ensure that the Chief Information Security Officer has access to the records of persons who have access to information related to the operations in which the electronic payment fund institution itself intervenes, including those located abroad, as well as to Users of the Technological Infrastructure who have high privileges, such as administration of operating systems, databases, and applications, as well as to their service providers.
Electronic payment fund institutions that belong to a financial group subject to the supervision of the CNBV, or that are part of Consortia or Business Groups that have a financial entity subject to the supervision of the CNBV itself, may assign the functions of the Chief Information Security Officer to the person performing such activities in the financial entity supervised by the CNBV, provided that such person complies with what is established in Article 35 of these Provisions.
CHAPTER III
ON OPERATIONAL CONTINUITY
Article 37.- Electronic payment fund institutions must have a Business Continuity Plan that they are obligated to comply with and include the minimum requirements established in Annex 2 of these Provisions, which must be aligned with the Business Continuity and Information Security Strategic Policy.
The Business Continuity Plan must be approved by the General Director or, where applicable, by the sole administrator, verifying that it contains initiatives aimed at improving existing work methods, in accordance with these Provisions. Modifications to the Business Continuity Plan must be approved by the General Director or, where applicable, by the sole administrator, with the General Director being responsible for adhering to the principles established by the Board of Directors in the business continuity and information security manual.
In the case of electronic payment fund institutions that have a General Director and a Board of Directors, the former must inform the Board of the content of the Business Continuity Plan, or its modifications, and have evidence of its approval and implementation.
Article 38.- Each electronic payment fund institution must have the necessary mechanisms for operational continuity and the administration of Operational Contingencies of the institution itself, which include their identification, evaluation, monitoring, and mitigation.
Article 39.- Electronic payment fund institutions must have methodologies to estimate the quantitative and qualitative impacts of possible Operational Contingencies that, in terms of these Provisions, are determined by the person responsible for the administration of Operational Contingencies for use in the analysis referred to in Annex 2 of these Provisions. The Governing Body of each electronic payment fund institution must approve such methodologies, without prejudice to the powers of the General Director to make modifications to the Business Continuity Plan, in accordance with the principles established by the respective Governing Body in the Business Continuity and Information Security Strategic Policy.
Article 40.- The Governing Body of the electronic payment fund institution must appoint a person responsible for the administration of Operational Contingencies, who has knowledge in the matter and who may be the same person appointed as the integral risk administrator in accordance with the general provisions issued by the CNBV. The person responsible for the administration of Operational Contingencies may be assisted by other areas of the electronic payment fund institution itself or by third parties contracted for this purpose, who are specialists in the matter. This person must have, at a minimum, the following functions:
I. Prepare, review, and, where applicable, update the Business Continuity Plan.
II. Evaluate, at least once a year, the scope and effectiveness, as well as compliance with the minimum requirements established in Annex 2 of these Provisions, as well as the established Business Continuity Plan, and report the results of such evaluation to the Governing Body and to the areas responsible for critical operational processes, identifying, where applicable, the necessary adjustments for its update, strengthening, and compliance. In the event that the electronic payment fund institution has an audit committee, the functions provided for in this fraction will be performed by said committee.
III. Coordinate and verify the execution of tests on the functionality and sufficiency of the Business Continuity Plan and report to the Governing Body, at least once a year, on the results of such tests.
IV. Define and present to the Governing Body, the methodology for the administration of Operational Contingencies, in the terms established in the corresponding provisions on the administration of operational events. For these purposes, the person responsible for the administration of operational events may be assisted by other areas of the electronic payment fund institution itself or by third parties contracted for this purpose, who are specialists in the matter.
V. Define and present for approval by the Governing Body, the methodologies to estimate the quantitative and qualitative impacts of Operational Contingencies. For these purposes, the person responsible for the administration of Operational Contingencies may be assisted by other areas of the electronic payment fund institution itself or by third parties contracted for this purpose who are specialists in the matter.
VI. Verify the effectiveness of the methodology for estimating the quantitative and qualitative impacts of possible Operational Contingencies, at least once a year, and, if applicable, correct said methodology within the same timeframe. Likewise, compare their estimates against the Operational Contingencies actually observed and, if necessary, carry out the necessary corrections.
In the event that electronic payment fund institutions contract third parties for the services necessary to support their operations, in substitution of what is provided in fractions II and III of this article, and solely with respect to the services provided by said third parties, the institutions must have documentation that certifies that such third parties hold a valid certification issued in accordance with international standards regarding their capacity to maintain the continuity of their services. The foregoing must be observed without prejudice to compliance with what is provided in Chapter V of these Provisions.
CHAPTER IV
COMMON PROVISIONS ON INFORMATION SECURITY AND OPERATIONAL CONTINUITY
Article 41.- Electronic payment fund institutions must maintain a database record of Information Security Events classified as relevant, Information Security Incidents, Operational Contingencies, as well as failures or vulnerabilities detected in the Technological Infrastructure, which shall include, as applicable, information related to the detection of failures, operational errors, attempts at computer attacks and those actually carried out, as well as loss, extraction, alteration, misplacement, or misuse of information belonging to Users of the Technological Infrastructure or Clients, where the date of the event and a brief description thereof, its duration, the service or element of the Technological Infrastructure affected, affected Clients and amounts, as well as the corrective measures implemented are contemplated.
The information on Information Security Events classified as relevant and Information Security Incidents, as well as Operational Contingencies, must be backed up in the media determined by the electronic payment fund institutions and preserved for at least ten years.
Article 42.- In the event that an Information Security Incident occurs, or an Information Security Event occurs in the components of the Technological Infrastructure of the electronic payment fund institution; in the Instruction Channels, or in the technological infrastructure of any third party that affects the operation or the Technological Infrastructure of the electronic payment fund institution, the General Manager or, as applicable, the sole administrator must carry out the following:
I. Provide for the necessary measures to immediately inform the Bank of Mexico and the CNBV of Information Security Incidents via email sent to the accounts ifpe@banxico.org.mx and Ciberseguridad-CNBV@cnbv.gob.mx, or through other means indicated by the Bank of Mexico or the CNBV itself. In such notification, at least the date and time of start of the Information Security Incident in question, and if applicable, an indication of whether it is ongoing or has concluded and its duration; a description of said event or incident, as well as an initial assessment of the impact or severity must be indicated.
Additionally, electronic payment fund institutions must send to the accounts ifpe@banxico.org.mx and Ciberseguridad-CNBV@cnbv.gob.mx, or through other means indicated by the Bank of Mexico or the CNBV itself, within five business days following the identification of the Information Security Incident in question, the information determined in Annexes 3 and 4 of these Provisions.
In the case of Information Security Events, they must be reported through the means indicated in the first paragraph of this fraction only those that, according to the policies and procedures established by the electronic payment fund institution itself, are classified as relevant due to having potential impact on the electronic payment fund institution, its Clients, counterparties, suppliers, or other entities in the financial system, as well as those related to Personal Information or Sensitive Information, images of official identification documents, and information on the Authentication Factors referred to in fraction III of Article 5 of these Provisions. This report shall only contain the date and time of start, as well as the description of the event in question.
II. Carry out an immediate investigation into the causes that generated the Information Security Incident and establish a work plan that describes the actions to be implemented to eliminate or mitigate the vulnerabilities that facilitated the mentioned incident. Such plan must indicate, at least, the personnel responsible for its design, implementation, execution, and monitoring; deadlines for its execution, as well as the technical, material, and human resources; and must be sent to the Bank of Mexico and the CNBV within a period not exceeding fifteen business days after the Information Security Incident concluded.
III. When the Information Security Incident consists of Personal Information or Sensitive Information under the custody of the electronic payment fund institution or third parties providing services to it, being extracted, lost, deleted, altered, or if the electronic payment fund institutions suspect the commission of any act involving unauthorized access to such information, the General Manager or, as applicable, the sole administrator or the person designated by either of them, must notify the Clients of the possible loss, extraction, alteration, misplacement, or unauthorized access to their information, within twenty-four hours after the Information Security Incident occurred or after knowledge thereof was obtained, through the notification means indicated by the Client for such effect, in order to prevent them from the risks derived from the misuse of the information that has been extracted, lost, deleted, or altered. Likewise, the Client will be informed of the measures they must take and, if applicable, the replacement of the corresponding disposal means or the substitution of necessary Authentication Factors will be effected.
The notification referred to in this fraction must include, at least, the nature of the event, its date and time of start, duration, and, if existing, delimit and indicate the individual impacts on each Client. The evidence of this notification must be included in the result of the investigation referred to in fraction II of this article.
Article 43.- Electronic payment fund institutions must inform the Bank of Mexico and the CNBV of Operational Contingencies that occur in any of the public service channels or within the electronic payment fund institution itself, via email sent to the accounts ifpe@banxico.org.mx, contingencias@cnbv.gob.mx, and supervisionfintech@cnbv.gob.mx, or through other means made available by the Bank of Mexico or the CNBV itself, an electronic receipt of receipt must be generated. The foregoing, provided that these interruptions last at least thirty minutes.
The notification mentioned in the previous paragraph must be made within sixty minutes following the occurrence of the Operational Contingency in question, and must include the date and time of start of the Operational Contingency; an indication of whether it is ongoing or has concluded and its duration; the processes, systems, and channels affected; a description of the event that was recorded, and an initial assessment of the impact or severity.
Likewise, in the event that an Operational Contingency occurs, the electronic payment fund institution in question must carry out an immediate investigation into the causes that generated the event, and send the results of said investigation to the Bank of Mexico and the CNBV, within a period not exceeding five business days in accordance with the specifications of Annex 5 of these Provisions.
On its part, in the event that, as a result of an Operational Contingency, one or more Instruction Channels are affected, the electronic payment fund institution in question must inform its Clients or users regarding the disposal means being affected by this, within a period not exceeding five seconds counted from the occurrence of the Operational Contingency and in accordance with the information available at the time of this, regarding the intermittency or impossibility of using the Instruction Channels, through the notification means agreed upon with the Clients or users themselves, and must maintain evidence thereof.
In addition to what is provided in the previous paragraph, the electronic payment fund institution must make available to the general public, on the Internet site previously made known to its Clients, the information related to the Operational Contingency in question, including, at least, the nature of the event, its date and time of start and duration, as well as a general description of the impacts on its Clients, within a maximum period of sixty minutes counted from the materialization of the event and, if existing, must delimit and indicate the individual impacts on each Client or user of the disposal means, which must be made known to its Clients through the means previously agreed upon for this purpose, within a maximum period of twenty-four hours, counted from the materialization of the event.
If applicable, the General Manager or sole administrator will be responsible for carrying out what is provided in this article.
CHAPTER V
ON THE CONTRACTING OF SERVICES WITH THIRD PARTIES AND COMMISSION AGENTS
Article 44.- Electronic payment fund institutions require authorization from the Bank of Mexico and the CNBV to contract the provision of services with any third party that meets any of the following characteristics:
I. Provides services that imply the transmission, storage, processing, safeguarding, or custody of Personal Information or Sensitive Information, images of identification documents issued by official authorities, or biometric information of Clients, provided that the third party in question has access privileges to know such information or security configuration information, or to access control administration.
II. Carries out processes abroad related to accounting or treasury.
III. Acts as the primary provider of those services whose interruption, partial or permanent, would prevent the electronic payment fund institution from issuing, administering, redeeming, or transmitting electronic payment funds, in accordance with the acts referred to in fractions II, III, IV, and V of Article 22 of the Law to Regulate Financial Technology Institutions.
Electronic payment fund institutions may only contract the services referred to in the aforementioned fractions, as well as any other, when the persons providing the respective services are obligated to maintain due confidentiality of information regarding Operations conducted with their Clients, as well as regarding the Clients themselves, in case of having access to it, at least under the same terms and conditions in which the electronic payment fund institutions are obligated to maintain such confidentiality. In any case, the electronic payment fund institutions will be responsible for violations of the confidentiality of information under their safeguard or custody by the referred third parties.
The General Manager or, as applicable, the sole administrator of the electronic payment fund institution will be responsible for approving the contracting of service providers referred to in this Chapter.
Electronic payment fund institutions must maintain the data of those who provide them services, in the registry referred to in Article 52 of these Provisions.
The authorization referred to in this article will not be necessary when electronic payment fund institutions contract other financial entities subject to general provisions substantially similar to these Provisions.
Article 45.- Electronic payment fund institutions must present a notice to the Bank of Mexico and the CNBV twenty business days in advance of contracting third parties, when such third party:
I. Acts as a secondary or backup provider to complement the operation of a primary provider or guarantee business continuity in the event that the primary provider is unable to provide the service, as well as for those services whose interruption, partial or permanent, would prevent the electronic payment fund institution from issuing, administering, redeeming, or transmitting electronic payment funds, in accordance with the acts referred to in fractions II, III, IV, and V of Article 22 of the Law, in which case the referred notice must comply with the requirements referred to in Article 49 of these Provisions.
II. Corresponds to a legally authorized financial entity and subject to regulation substantially similar to what is provided in these Provisions, in the federal financial sphere.
The Bank of Mexico and the CNBV, during the aforementioned twenty-business-day period, may require the electronic payment fund institution in question that the provision of said service not be carried out through the third party indicated in the notice referred to in this article, when either of the two authorities considers that, due to the terms and conditions of service contracting, internal control policies and procedures, or due to the technological or communications infrastructure subject of the service used by said third party, this third party will not be able to comply with the provisions applicable to the electronic payment fund institution and, if applicable, the financial stability or operational continuity of the institution itself may be affected, in the judgment of the Bank of Mexico or the CNBV.
Article 46.- Electronic payment fund institutions may enter into commercial commission contracts with third parties who act in front of the general public in the name and on behalf of the respective electronic payment fund institutions, solely for the performance of the following Operations:
I. Cash withdrawals made by the respective Client who is the holder of the account.
II. Receipt of cash for credit to own accounts or third-party accounts.
III. Balance and account movement inquiries.
IV. Circulation of instruments for the disposal of electronic payment funds.
V. Opening of electronic payment fund accounts, observing at all times what is established in the general provisions referred to in Article 58 of the Law to Regulate Financial Technology Institutions, issued by the Secretariat, or those that replace them.
VI. Transfers charged to electronic payment fund accounts, including service payments.
For the purposes of this article, electronic payment fund institutions must request authorization from the CNBV, in accordance with what is established in Article 59 of these Provisions.
The operations provided in the aforementioned fractions must be carried out in national currency and in the name and on behalf of the electronic payment fund institution. In the event that the electronic payment fund institution intends to carry out operations other than those indicated through commission agents, it must request authorization from the CNBV prior to its realization, in accordance with what is established in Article 59 of these Provisions.
Regarding those electronic payment fund institutions that carry out the operations indicated in fractions I and II of this article, through a credit institution, they are exempt from presenting the authorization request referred to in the previous paragraph. Additionally, electronic payment fund institutions must observe, at all times, the limits established in Article 9 of the General Provisions applicable to Financial Technology Institutions issued by the CNBV or those that replace it, and establish in the compliance manual provided for in the General Provisions referred to in Article 58 of the Law to Regulate Financial Technology Institutions issued by the Secretariat, or those that replace it, monitoring mechanisms to comply with the aforementioned limits.
Electronic payment fund institutions, in the celebration of the contracts referred to in this article, must ensure at all times that the third parties providing them services maintain due confidentiality of information regarding Operations conducted with their Clients, as well as regarding the Clients themselves, in case of having access to it.
The General Manager or, as applicable, the sole administrator of the electronic payment fund institution will be responsible for approving the contracting of commission agents.
Article 47.- Electronic payment fund institutions intending to celebrate the commercial commission contracts referred to in the previous article must present in the authorization request the following:
I. General functioning plan containing the following:
a) Detailed description and flowchart of the processes of each of the operations to be contracted, considering, if applicable, the reconciliation and settlement process of each of them, the third parties involved, and the Technological Infrastructure to be used in the Operation in question.
b) Mechanisms that include the automated controls that the electronic payment fund institution will use to prevent commission agents or the Commission Agent Administrator from exceeding the operational limits established in Article 48 of these Provisions.
c) Performance monitoring mechanisms of the commission agent or the Commission Agent Administrator, which must consider, at least, the compliance with their contractual obligations.
For the purposes of the foregoing, the electronic payment fund institution must have plans to evaluate and report to the Administrative Body or, as applicable, to the audit committee, the performance of the contracted commission agents or the Commission Agent Administrator and the compliance with the applicable regulation related to such contracting.
d) Technical requirements to carry out operations through commission agents, adjusting to what is indicated in Annex 7 of these Provisions.
Electronic payment fund institutions, for the realization of operations additional to those manifested in the general functioning plan referred to in this fraction, must request authorization from the CNBV, within a period not exceeding twenty business days prior to the start of the realization of the mentioned operations. Likewise, when they carry out reforms to said plan that imply substantial changes in the terms in which they would carry out Operations with Clients or users of the disposal means, they must request authorization from the CNBV, at least twenty business days in advance of the date on which they intend to take effect.
II. Draft contract in which the probable date of its celebration and the rights and obligations of the electronic payment fund institution and the commission agent or the Commission Agent Administrator must be indicated. Likewise, within the contract, the following must be provided for:
a) Operations that the commission agent or the Commission Agent Administrator will carry out in the name and on behalf of the electronic payment fund institution.
Regarding Operations carried out through Commission Agent Administrators, electronic payment fund institutions must provide in the contract the Operations that the Commission Agent Administrator will contract in the name and on behalf of the institution of
electronic payment fund institutions with the Commissionaires that it will administer, as well as, where applicable, the Operations and services that the Commissionaire Administrator itself will perform. b) Limits that will apply to each of the Operations, in accordance with the applicable provisions. c) Rights and obligations of the electronic payment fund institution, as well as the commissionaire or the Commissionaire Administrator, including the respective legal consequences and sanctions applicable in case of non-compliance with the terms of the contract. d) The authority of the electronic payment fund institution to suspend the performance of operations or terminate the respective contract, both without liability, in the event that the commissionaire or the Commissionaire Administrator fails to comply with applicable regulations or the contract, or presents changes in their operations that affect the conditions of the contracted service. e) Corrective measures that the electronic payment fund institution would implement due to the commissionaire's or the Commissionaire Administrator's non-compliance with applicable provisions. f) Prohibition for the commissionaire or Commissionaire Administrator to:
Condition the performance of the operation on the acquisition of a product or service.
Advertise or promote themselves in any manner through stationery or on the front of the receipts provided to Customers in the name of the respective electronic payment fund institution.
Perform the Commissioned Operations on terms different from those agreed with the respective electronic payment fund institution.
Subcontract the commercial commission. The provisions of this subsection shall not apply to the Commissionaire Administrator when contracting on behalf and for the account of the electronic payment fund institution the commissionaires that it administers, except with respect to those operations and services that the Commissionaire Administrator itself will perform.
Charge commissions, on their own behalf, to Customers for the provision of the services subject to the commercial commission, or receive price or rate differentials with respect to the operations in which they intervene.
Carry out Operations with Customers in their own name.
Exclusively agree with the electronic payment fund institution on the performance of Operations and activities consisting of receiving payments for services charged to electronic payment fund accounts.
g) Record, within the contract, the express acceptance by the commissionaire or Commissionaire Administrator of the following obligations:
Adhere to what is provided in Article 54 of the Law for Regulating Financial Technology Institutions.
Deliver, during the course of the audit and at the request of the electronic payment fund institution, to the independent external auditor of the electronic payment fund institution and to the CNBV, the books, systems, records, manuals, and documents in general, related to the provision of the service in question, as well as allow the independent external auditor or CNBV personnel access to their offices and facilities in general, related to the provision of the service in question.
Inform the electronic payment fund institution regarding any modification to its corporate purpose or any other change that could affect the operations subject to the contract, at least thirty days in advance of such modification or change occurring.
Maintain confidentiality regarding information that has been received, transmitted, processed, or stored during the performance of the operations. Likewise, accept that such information may only be used and exploited for the purposes agreed upon in the contract.
Manifest acceptance of direct responsibility for the improper use of the electronic payment fund institution's information and, where applicable, pay damages and losses caused by any non-compliance with the aforementioned provision.
Comply with the terms, conditions, and processes to guarantee the electronic payment fund institution the transfer, return, and secure deletion of information subject to the contracted commission when the contract is terminated.
Prevent the improper use of authentication factors of Customers and employees operating the contracted service.
Observe the measures that the electronic payment fund institution must implement to comply with the general provisions referred to in Article 58 of the Law for Regulating Financial Technology Institutions, issued by the Secretariat, or those that replace them.
Train personnel regarding the process for performing Operations, the use of the commissionaire's technological infrastructure, and information security.
Electronic payment fund institutions must submit to the CNBV the authorization request referred to in this article, in accordance with Article 59 of these Provisions, at least twenty business days in advance of the date on which they intend to perform the contracting.
Electronic payment fund institutions may authorize third parties, through a mandate or commission, to contract on their behalf and for their own account with other persons the commissions or services referred to in this article, designating such representatives, for the purposes of these Provisions, as Commissionaire Administrators.
In this case, electronic payment fund institutions must establish that it will be the responsibility of the Commissionaire Administrators to ensure that the commissionaires they contract comply with what is established in this article and in Annex 7 of these Provisions.
The provisions of this article shall be observed without prejudice to the authorization that the electronic payment fund institution may obtain for its own Commissionaire Administrator to also be a commissionaire.
Article 48.- Electronic payment fund institutions, in the performance of Operations through commissionaires referred to in fractions I and II of Article 46 of these Provisions, must adhere to the following limits:
I. With respect to the Operations referred to in fraction I of Article 46, the limit per commissionaire may not exceed a daily amount equivalent in national currency to 1,500 UDIs, per Customer Account.
II. With respect to the Operations referred to in fraction II of Article 46, the limit per commissionaire may not exceed a daily amount equivalent in national currency to 4,000 UDIs, per Customer Account.
Article 49.- Electronic payment fund institutions must accompany the authorization request referred to in Article 44 or, where applicable, the notice referred to in fraction I of Article 50 of these Provisions, the following:
I. Detailed description and flowcharts of the service processes to be contracted, considering the activities to be performed by the electronic payment fund institution, as well as by the service provider; the areas of the electronic payment fund institution itself and the third party that participate in the service flow; name, description, and functionality of the systems that, where applicable, will be contracted for the provision of the service, or the electronic payment fund institution's systems that will be used by the respective provider.
II. Draft service provision contract, in which the contemplated date of its celebration, the rights and obligations of the electronic payment fund institution and the third party must be stated, including the determination regarding intellectual property rights regarding the designs, developments, or processes used for the provision of the service. Such draft contract must be presented in Spanish.
Likewise, the contract must record the express acceptance by the third party of the following obligations:
a) Adhere to what is provided in Article 54 of the Law for Regulating Financial Technology Institutions. b) Deliver during the course of the audit and at the request of the electronic payment fund institution, to the Independent Third Party of the electronic payment fund institution itself, as well as to the Bank of Mexico and the CNBV, the books, systems, records, manuals, and documents in general, related to the provision of the service in question. Likewise, allow the Independent Third Party or Bank of Mexico or CNBV personnel access to their offices and facilities in general, related to the provision of the service in question. c) Inform the electronic payment fund institution regarding any modification to its corporate purpose or any other change that could affect the provision of the service subject to the contract, at least thirty days in advance of such modification or change occurring. d) Maintain confidentiality regarding information that has been received, transmitted, processed, or stored during the provision of the services. Likewise, accept that such information may only be used for the purposes agreed upon in the provision of the service. e) In the event that the third party performs subcontracting for the partial or total provision of any of the services provided to electronic payment fund institutions, it must notify the institution regarding such subcontracting; likewise, it will establish mechanisms for the subcontractor to comply with the agreed obligations and provide information for the purposes of Article 52 of these Provisions. f) Comply with the terms, conditions, and processes for the third party to guarantee the electronic payment fund institution the transfer, return, and secure deletion of information subject to the contracted service when it ceases to provide it. g) Maintain complete audit records that include detailed information on accesses or access attempts and the operation or activity performed by Users of the Technological Infrastructure. Such records must be available to authorized personnel of the electronic payment fund institution. h) Have information access controls according to the access levels and profiles determined by the electronic payment fund institution. i) Allow the electronic payment fund institution to perform the security reviews indicated in Articles 21, 33, and 34 of these Provisions on the contracted services, or provide evidence of the performance of these reviews.
III. Documentation regarding the Technological Infrastructure indicated below:
a) Description of the communication links used by the electronic payment fund institution to connect with the service provider, including the provider's name, bandwidth, and type of service provided, among others. b) Telecommunications diagram showing the existing connection between each of the participants in the provision of the service, such as providers, data centers, and electronic payment fund institution, among others, including redundancy schemes. c) Full address of the location where each of the services will be performed, as well as the primary and secondary data centers where information will be stored and processed. In the event that the indicated location is within national territory, it must include at least street, exterior and interior number, neighborhood, borough or municipality, postal code, and federal entity. With respect to a site located abroad, similar data must be included that allows locating the indicated place with certainty. With respect to Cloud Computing services, only what is indicated in Article 50 of these Provisions must be provided. d) Where applicable, the interrelationship scheme of applications or systems subject to the contract, including the electronic payment fund institution's own systems. e) Mechanisms for continuity of the contracted service.
IV. Mechanisms that will allow the electronic payment fund institution to keep under its custody, either in its own or third-party Technological Infrastructure within national territory, detailed records of all Operations performed, as well as its accounting records, in such a way as to ensure operational continuity at all times. Such records must be maintained in a format that allows their consultation, operation, and use, regardless of whether the contracted service with the third party is unavailable.
V. Evidence of the controls that the third party will maintain to guarantee the confidentiality, integrity, and availability of this information, when it has access privileges to images of official identifications or biometric information of Customers.
VI. Description of the mechanisms to monitor the performance of the contracted third party and compliance with its contractual obligations, including, at least, those provided in these Provisions.
VII. Plans to evaluate and report to the Administrative Body or, where applicable, the audit committee of the electronic payment fund institution, depending on the importance of the contracted service, the performance of the third party, and compliance with applicable regulation related to said service.
VIII. Evidence allowing verification that third parties have and implement data protection and information confidentiality policies that allow the electronic payment fund institution to comply with the legal provisions governing it in this matter.
With respect to services that are processed, provided, or executed wholly or partially outside national territory, electronic payment fund institutions must accompany the documentation that certifies that the third parties reside in countries whose internal law provides protection for personal data, safeguarding its proper confidentiality, or that such countries have agreements with Mexico in this matter, or exchange of information between supervisory bodies, with respect to Financial Entities. Additionally, electronic payment fund institutions must:
a) Have the approval of the Administrative Body regarding that there will be no impact on the continuity of the operation of the electronic payment fund institution, due to geographical distance and, where applicable, the language that will be used in the provision of the service. b) Have technical support schemes that allow solving problems and incidents, regardless of any differences that may exist in time zones and business days. Likewise, in the event that any authority of the third party's country of origin referred to in this subsection requests information related to the services it provides to the electronic payment fund institution, the third party must, as soon as legally possible, inform the institution of this, as well as provide it with a copy of the information it has delivered to said authority. In this case, the electronic payment fund institution must inform the Bank of Mexico and the CNBV of such situation in accordance with what is established in Article 59 of these Provisions, immediately after becoming aware of it, as well as provide them with a copy of the referred information. The Bank of Mexico and the CNBV will have a period of twenty-five business days to resolve the authorization request referred to in this article; if this period elapses without any pronouncement, the resolution will be understood to be positive. Any request for additional information made by the Bank of Mexico or the CNBV will interrupt the period indicated in this paragraph.
Article 50.- Electronic payment fund institutions that fall under any of the circumstances provided for in subsections a) and b) of this article must observe the measures established below for prudential reasons.
Institutions that will be obligated to adopt the measures referred to in this article are those that contract a third party as the primary provider of services corresponding to Cloud Computing to carry out any of the acts of issuance, administration, redemption, or transmission of electronic payment funds as indicated in fractions II, III, IV, and V of Article 22 of the Law for Regulating Financial Technology Institutions, when the services provided by said third party, regardless of the nationality of the latter or of the persons exercising Control over it, are susceptible to being interrupted, temporarily or permanently, due to some provision, order, instruction, mandate, or equivalent act of a foreign authority that is directly aimed at preventing, limiting, prohibiting, or blocking the provision of Cloud Computing services by the primary provider, either because of the place where it or the persons exercising Control over it are located or have been constituted, or because it maintains assets or performs its operations, as well as by the relationship that said third party has with the respective electronic payment fund institution, and that it makes it impossible for said institution to carry out the aforementioned acts of issuance, administration, redemption, or transmission of electronic payment funds. Electronic payment fund institutions that fall under the circumstance referred to in the previous paragraph must include in their respective Business Continuity Plans one of the mechanisms indicated below, with the purpose of guaranteeing that they will maintain the computing and processing capacity necessary so that, from a period not greater than two hours, the referred mechanisms are implemented and the respective processes can be performed, at least, to carry out all the acts of issuance, administration, redemption, or transmission of electronic payment funds referred to above, during the period that the primary Cloud Computing interruption lasts:
I. A mechanism that, in addition to the primary Cloud Computing referred to in this article, allows electronic payment fund institutions to have the availability of Cloud Computing services provided by a secondary provider, provided that this other additional provider is not subject to the same risk as the primary Cloud Computing, as contemplated in the second paragraph of this article, by being subject to a different jurisdiction from that in which the risk causing the interruption of services provided by the primary provider may occur, as well as by being under the Control of a person different from the primary provider or any other person belonging to the same Business Group of said primary provider or a Group of Persons in which said primary provider or person of the same Business Group participates.
The foregoing should not be understood to mean that the corresponding Cloud Computing secondary services must be carried out simultaneously with the primary Cloud Computing referred to used by the institution in its normal operation, while the referred interruption does not occur.
II. A mechanism that, in addition to the primary Cloud Computing used by the institution in question and located in the circumstance described in the second paragraph of this article, allows the institution in question to have its own infrastructure allowing it to perform, in a territory different from that of the foreign jurisdiction in which the risk referred to in the second paragraph of this article may occur, the processes referred to in said paragraph, provided that the execution of said processes is not carried out by the primary Cloud Computing provider or depends on it or the persons exercising Control over it, or depends on any other person that both it and those exercising Control over it are subject to the same jurisdiction in which the indicated risk may occur.
The implementation of the mechanism indicated in this subsection will not imply the simultaneous operation with the Cloud Computing of the primary provider used by the institution in its normal operation, while the referred interruption does not occur.
III. Any other mechanism different from those contemplated in the previous subsections I and II that, at the request of the electronic payment fund institution, the Bank of Mexico and the CNBV authorize, independent of the other authorization, in accordance with fraction III of Article 44 of these Provisions, that said authorities grant for the contracting of the primary Cloud Computing provider referred to in the second paragraph of this article, provided that the electronic payment fund institution demonstrates that said mechanism can ensure continuity in the performance of the acts indicated in the second paragraph cited, in the event that the interruption predicted in said paragraph occurs for the causes indicated therein.
The authorization request referred to in this subsection must be presented in the terms established in Article 59 of these Provisions.
Electronic payment fund institutions that fall under the circumstances of this article will be obligated to comply with what is prescribed in this same article, without prejudice to their authority to enter into contracts, under the terms and conditions established in these and other applicable provisions, that allow them to obtain and conserve services related to Cloud Computing provided by third parties from the country or abroad, with computer installations located within or outside national territory, in order to carry out the corresponding processes to their Operations that they are authorized to perform. The provisions of this article will only be applicable to those electronic payment fund institutions that, as a result of the evaluation performed with information at the close of each quarter, fall under any of the following circumstances:
a) During a twelve-calendar-month period, it carries out any of the following activities:
Performs more than three million five hundred thousand Transfer Operations.
Send or receive Transfers for a total amount exceeding the equivalent in national currency to six billion UDI’s.
b) At any time have had more than one million Accounts that, during a period of twelve consecutive calendar months, have registered, at any time, a positive balance or with respect to which at least one Transfer has been sent during said period, or have had a total balance in the Accounts exceeding the equivalent in national currency to four hundred million UDI’s.
Electronic payment fund institutions to which this article applies shall have a period of one hundred eighty natural days, counted from the first day of the calendar month immediately following that in which the circumstance contemplated in sub-paragraphs a) or b) above applies, to comply with the provisions established in this article.
Article 51.- Electronic payment fund institutions, for the contracting of services with third parties that are subject to authorization under Article 44 of these Provisions, as well as those related to operational processes and the administration of databases and computer systems, shall comply with the following:
I. Regarding third parties that provide services related to operational processes and the administration of databases and computer systems, provide for what is stated in fraction II, subsection g), items 1 to 6 of Article 47 of these Provisions and retain the respective contract.
II. Conduct, at least annually, internal or external audits on the contracted service or have evidence that the contracted third party carries them out.
III. Maintain in the offices where the administration functions of the electronic payment fund institution are carried out, at least, the documentation and information related to the evaluations, audit results, and, if applicable, the work plans that correspond, as well as the performance reports of the contracted third parties, including documentation regarding compliance with what is stated in fraction I of this article.
IV. Update the respective description or documentation when there are modifications that are considered to have a relevant impact on the service provided or that are related to the systems, equipment, and applications subject to the contract or their technical characteristics.
V. Regarding Technological Infrastructure and information security, in addition to the information determined in Article 49, fraction III, subsections b) and d) of these Provisions, have the following documentation:
a) Description of the technical characteristics of the systems, equipment, and applications subject to the contract.
b) That which details the mechanisms to ensure the transmission and storage of Personal Information or Sensitive Information in Encrypted form, if applicable, including the version of the Encryption protocols and security components in the Technological Infrastructure.
In the case of Sensitive Information, Encryption is exempted for information related to Operations, provided that such information is stored in tables or repositories different from those used to store the rest of the Personal Information and Sensitive Information and that there are security mechanisms that prevent the integration of said separate repositories if not authorized to do so.
c) That which contains the detail of the type of information of the electronic payment fund institution and Clients, specifying, if applicable, the type of Personal Information or Sensitive Information that will be stored by the third party on its equipment or facilities, or to which it may have access.
d) The description of the control and surveillance mechanisms for access to computer systems and to Personal Information or Sensitive Information transmitted, stored, processed, safeguarded, or custodied in said systems, as well as the logs, databases, and security configurations established for this purpose.
e) The evidence of the controls and of the control mechanisms referred to in fraction V of Article 49 of these Provisions.
VI. Have the evidence referred to in fraction VIII of Article 49 of these Provisions.
Article 52.- Electronic payment fund institutions shall have a registry of all service providers, including those subcontracted by them, as well as of the Administrators of Commission Agents and contracted commission agents, which shall contain at least the following information:
I. Service Providers:
a) Name, denomination, or corporate name of the service provider.
b) Name of the legal representative of the service provider.
c) Description of the service contracted with the third party, including the data or information that, if applicable, are stored, processed, or transmitted by it.
d) If applicable, information on the systems that support the service contracted with the third party, including, at least, the name, version, and function or purpose.
e) If applicable, interfaces with other systems and the purpose of these, including the detail of the information exchanged.
f) Location where the service is performed and where the personnel responsible for carrying it out are located.
g) If applicable, location or jurisdiction of the main data center where the processing equipment of the contracted system is located.
h) If applicable, location or jurisdiction of the alternate data center where the processing equipment is located, in the case of recovery of the contracted service.
i) If applicable, number and date of the official letter with which the Bank of Mexico and the CNBV granted authorization to act as a service provider.
II. Administrator of Commission Agents or Commission Agents:
a) Name, denomination, or corporate name of the commission agent or the Administrator of Commission Agents.
b) Name of the legal representative of the commission agent or the Administrator of Commission Agents.
c) Trade name of the commission agent or the Administrator of Commission Agents, as well as detail of the commercial modality under which it operates, whether it is a commercial chain or franchise.
d) Number of establishments of the commission agent where commercial commissions are carried out, and of each of them its full address, including the geo-statistical area key according to the Unique Catalog of State, Municipal, and Local Geo-statistical Area Keys of the National Institute of Statistics and Geography, or the one that replaces it.
e) Type of Operation carried out by the commission agent on behalf and for the account of the electronic payment fund institution.
f) Limits of the Operations agreed upon with the commission agent or with the Administrator of Commission Agents.
g) Access devices used to offer services to Clients, such as mobile phones, electronic tablets, and point-of-sale terminals, among others.
h) If applicable, number of official letter and date on which authorization was granted for the contracting of the commission agent or Administrator of Commission Agents.
Electronic payment fund institutions shall disseminate through their Internet page or application, the list of modules or establishments that the commission agents or the Administrator of Commission Agents have enabled to carry out the Operations referred to in Article 47 of these Provisions, specifying the Operations that can be carried out in each of them and the maximum amounts authorized per Operation.
Electronic payment fund institutions shall keep the registry referred to in this article updated.
Article 53.- The electronic payment fund institution shall carry out, at least annually, by itself or through a third party, audits whose purpose is to verify the degree of compliance with these Provisions. In the event that the commission agent or Administrator of Commission Agents has audit results with the same object previously carried out, with a maximum validity of one year, they may present them to the electronic payment fund institution. Without prejudice to the foregoing, the CNBV may order the carrying out of audits when, in its judgment, there are risk conditions in terms of operation and information security.
Article 54.- Electronic payment fund institutions shall, at all times, fully identify the Operations they carry out through the commission agent or the Administrator of Commission Agents, independently of those they carry out through their platforms.
Likewise, electronic payment fund institutions shall verify that the commission agents or Administrator of Commission Agents inform Clients by any means of the electronic payment fund institutions themselves, which act on behalf and for the account of the respective electronic payment fund institution.
Article 55.- Electronic payment fund institutions shall be liable at all times, both for the service that their commission agents or Administrator of Commission Agents provide to Clients, even when the carrying out of the corresponding Operations is carried out under terms different from those agreed upon, as well as for the non-compliance with the provisions incurred by said commission agents.
In the event of non-compliance by the commission agents or Administrator of Commission Agents with the applicable provisions, electronic payment fund institutions shall implement the necessary corrective measures.
The provisions established in the two preceding paragraphs shall be without prejudice to the civil, administrative, or penal responsibilities in which the commission agents or Administrator of Commission Agents or their employees may incur for violations of the applicable legal provisions.
What is stated in the preceding paragraph shall be established in the contract entered into between the electronic payment fund institution and the commission agent or the Administrator of Commission Agents.
CHAPTER VI
ON EVALUATION THROUGH INDEPENDENT THIRD PARTIES
Article 56.- Electronic payment fund institutions shall contract the services of an Independent Third Party or of the legal entity through which said Independent Third Party provides its services, to carry out the evaluation of the level of compliance with the information security requirements, the use of Instruction Channels, and operational continuity that these institutions must observe in accordance with what is provided in Chapters II, III, IV, and V of these Provisions.
Article 57.- The evaluation of the level of compliance carried out by the Independent Third Party referred to in the previous article shall be carried out every two years.
The compliance evaluation report shall be delivered by the Independent Third Party to the Administrative Body of the electronic payment fund institution and presented to the audit committee of said institution, if it has one.
Electronic payment fund institutions may not contract the services of an Independent Third Party, nor of the legal entities through which they provide the respective services, to obtain the compliance evaluation referred to in this article for more than two consecutive evaluation periods. Without prejudice to the foregoing, the electronic payment fund institution may designate the same Independent Third Party or referred legal entity again, after a minimum interruption of five years counted from the last compliance evaluation that it had granted with respect to said institution.
In the event that the evaluation carried out results in observations that, in the judgment of the Independent Third Party, represent serious violations, the electronic payment fund institution in question shall present the compliance evaluation report to its Board of Directors within twenty business days following the day the evaluation by the Independent Third Party ended, or in five business days if it is a Sole Administrator.
The report indicated in the preceding paragraph shall be delivered to the Bank of Mexico and the CNBV, in accordance with what is established in Article 59 of these Provisions, within a period of five business days counted from the day following the presentation to its Administrative Body of said report. The report shall be digitally signed by the general director or, if applicable, the sole administrator, and encrypted in accordance with what is provided in the cited Article 59.
In addition, the electronic payment fund institution shall present, in accordance with what is established in Article 59 of these Provisions, and within a period of twenty business days following the day the evaluation by the Independent Third Party ended, a remediation plan to remedy said observations. The remediation plan shall be digitally signed by the general director or, if applicable, the sole administrator, and encrypted in accordance with what is provided in the aforementioned Article 59. The CNBV and the Bank of Mexico may make observations to said remediation plan at any time.
Article 58.- The Independent Third Parties that evaluate the level of compliance of electronic payment fund institutions with the norms contained in these Provisions, as well as the legal entities through which they provide the respective services, shall be independent on the date of celebration of the service provision contract, during the development of the compliance evaluation and until the issuance of the compliance evaluation report in question, and shall comply with what is stated in Annex 6 of these Provisions.
CHAPTER VII
COMPLEMENTARY PROVISIONS
Article 59.- Regarding documents containing requests, reports, and work or remediation plans that electronic payment fund institutions must present through the Internet site that the CNBV and the Bank of Mexico make available to the mentioned institutions at the moment they obtain authorization to organize themselves as such, for the purposes established in Articles 6, 11, 24, 26, 33, 34, 43, 44, 45, 46, and 57 of these Provisions, they shall be presented with the respective electronic signatures of the corresponding representatives and, in the cases indicated, encrypted as follows:
I. Use of cryptographic keys, known as public and private asymmetric keys, for each electronic signature, in order to guarantee confidentiality and non-repudiation, avoiding sharing the private key.
II. Use of a digital certificate validated by a recognized certification agency or by a certification service provider accredited before the Ministry of Economy.
III. Incorporation of electronic signature that allows guaranteeing the integrity of the information provided.
The information of the public cryptographic keys that must be used to perform the encryption of the data message that constitutes the respective document, will be published on the Internet site that the Financial Authorities referred to in the first paragraph of this article will make available to the electronic payment fund institutions. To perform the encryption, these institutions may use the Bank of Mexico's information system called “WebSec” or any other developed by a third party that complies with what is provided in Annex 8 of these Provisions.
In cases where the Internet site referred to in the first paragraph of this article is not available or that electronic payment fund institutions do not have the necessary elements to be able to use electronic signatures in the documents referred to in this article, the aforementioned institutions shall present said documents through the Electronic Attention Module, known as MAE, of the Bank of Mexico, in terms of the applicable provisions issued by the Bank of Mexico itself for said purposes, or in the absence of said module, by the means it makes available.
Resolutions issued regarding the documentation entered into the Internet site of the aforementioned Financial Authorities, in accordance with what is established in this article, will be delivered jointly by said authorities, through the aforementioned Internet site.
TRANSITORY PROVISIONS
FIRST.- These Provisions shall enter into force ninety natural days following their publication in the Official Gazette of the Federation.
SECOND.- Electronic payment fund institutions shall have a maximum period of six months, counted from the entry into force of these Provisions, to comply with what is established in Article 15 of this instrument.
THIRD.- Electronic payment fund institutions shall have a period of nine months, counted from the entry into force of these Provisions, to comply with what is established in Articles 16 and 17 of this instrument.
FOURTH.- The persons referred to in the EIGHTH Transitory Provision of the Law to Regulate Financial Technology Institutions published in the Official Gazette on March 9, 2018, shall have a period of six months counted from the obtaining of their authorization to act as an electronic payment fund institution, to comply with what is established in Articles 44, 45, 46, and 47 of these Provisions.
Note from RegAlert. AI assistants can read this document in full, and search 70,000+ more, through the RegAlert MCP connector (https://mcp.regalert.today/mcp). Free with an account. How to connect ChatGPT, Claude or Cursor.
Read the rest free
Source: Comision Nacional Bancaria y de Valores — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from CNBV
CNBV published 1 document in the last 30 days. We email you each new one the day it's published.