2017-03-23 | DOF 5477324

Added

Resolution amending, adding, and repealing various general provisions under Article 91 of the Investment Funds Law

This resolution amends, adds, and repeals general provisions under Article 91 of the Investment Funds Law to implement a Risk-Based Approach for anti-money laundering and counter-terrorist financing compliance by investment fund operating companies and fund share distributors. It introduces new definitions for risk grade and mitigants, mandates the identification of beneficial owners and corporate structures for legal persons, and updates thresholds for relevant operations to seven thousand five hundred US dollars. The text also establishes a chapter on risk-based methodology, provisions for interim compliance officers, and rules for information exchange within financial groups.

Secretaria de Hacienda y Credito Publico logo

Mexico

Secretaria de Hacienda y Credito Publico

Click to view thumbnail

DOF: 23/03/2017

RESOLUTION amending, adding, and repealing various general provisions referred to in Article 91 of the Investment Funds Law

A seal bearing the National Coat of Arms, which reads: United Mexican States.- Ministry of Finance and Public Credit, is placed at the margin.

RESOLUTION AMENDING, ADDING, AND REPEALING VARIOUS GENERAL PROVISIONS REFERRED TO IN ARTICLE 91 OF THE INVESTMENT FUNDS LAW

JOSÉ ANTONIO MEADE KURIBREÑA, Secretary of Finance and Public Credit, based on the provisions of Articles 31, fractions VII and XXXIV of the Organic Law of the Federal Public Administration, as well as Article 91 of the Investment Funds Law, in exercise of the powers conferred upon me by Article 6, fraction XXXIV of the Internal Regulations of the Ministry of Finance and Public Credit, and with the prior opinion of the National Banking and Securities Commission issued via letter number VSPP/19/2017 dated February 13, 2017; and

CONSIDERING

That one of the most effective mechanisms within the regulatory framework for the prevention and combat of operations with resources of illicit origin and terrorist financing consists in the implementation of customer identification and knowledge policies by investment fund operating companies and fund share distributors, as they constitute fundamental elements to mitigate the risk that such companies are used for the commission of such illicit acts;

That since the year 2000, Mexico has been a member of the Financial Action Task Force (FATF), an intergovernmental body that sets international standards in matters of prevention and combat of operations with resources of illicit origin, terrorist financing, and financing for the proliferation of weapons of mass destruction;

That in this sense, Mexico has committed to the aforementioned group and its members to implement its recommendations and, consequently, to carry out a mutual evaluation consisting of a review of the systems and mechanisms created in our country as a member of the FATF, as well as Mexico's response in the effective implementation of the 40 Recommendations. This is with the objective of instituting legal and operational systems for the prevention of operations with resources of illicit origin and terrorist financing, as well as any other threat that could undermine the integrity of the financial system, both internationally and nationally;

That in accordance with FATF Recommendation 1, financial institutions must identify, evaluate, and take actions to mitigate risks regarding operations with resources of illicit origin and terrorist financing through customer and user knowledge mechanisms that are appropriate to the risk they represent, which implies that investment fund operating companies and fund share distributors carry out the application of a Risk-Based Approach, so a Chapter is added in which the use of a methodology is established so that investment fund operating companies and fund share distributors can evaluate risks in this matter and apply mitigants to them in accordance with a Risk-Based Approach, in order to avoid being used for the commission of operations with resources of illicit origin and terrorist financing;

That in accordance with FATF Recommendation 10, modifications are made regarding the customer identification policy for legal persons, regardless of the risk qualification made by investment fund operating companies and fund share distributors, so that obligated subjects know their shareholding and corporate structures, as well as to specify the mechanisms to collect data on beneficial owners. This is with the objective that investment fund operating companies and fund share distributors have more information allowing them to perform a better evaluation of the risks to which they are exposed due to their commercial relationships, of being used for the commission of crimes involving operations with resources of illicit origin and terrorist financing, and to adopt pertinent actions for their mitigation;

That with the aim of increasing the effectiveness of measures in matters of prevention of operations with resources of illicit origin and combat against terrorist financing, the thresholds regarding relevant and unusual operations are modified, which will result in authorities having more information for the development of their powers in this matter;

That based on FATF Recommendation 20 and with the aim of strengthening the submission of reports on unusual operations and reports on concerning internal operations that are submitted by entities in terms of the General Provisions referred to in Article 91 of the Investment Funds Law, it is necessary to clarify the deadlines for the submission of such reports once they have been determined, with the objective that the authority has the information in a timely manner for the exercise of its powers;

That for investment fund operating companies and fund share distributors to be able to comply with what is provided in these General Provisions by having an official who acts at all times as a liaison with the authorities in terms of the General Provisions referred to in Article 91 of the Investment Funds Law, the possibility is established to appoint an interim compliance officer for a determined period in case the compliance officer in charge has their appointment revoked or is unable to carry out their functions;

That with the object of recognizing other official identifications, new valid personal identification documents for the celebration of operations are provided;

That with the objective of providing certainty on the period that the annual audit report of investment fund operating companies and fund share distributors that begin operations after the beginning of the calendar year must cover, it is considered necessary to clarify the scope of this obligation in this scenario;

That in accordance with FATF Recommendation 18, it is proposed that those financial entities that form part of the same financial group in terms of the Law to Regulate Financial Groups, exchange information in matters of prevention of operations with resources of illicit origin and terrorist financing at the group level, and

That once the opinion of the National Banking and Securities Commission has been heard, I have deemed it appropriate to issue the following:

RESOLUTION AMENDING, ADDING, AND REPEALING VARIOUS GENERAL PROVISIONS REFERRED TO IN ARTICLE 91 OF THE INVESTMENT FUNDS LAW

SINGLE ARTICLE.- The fractions V in its second paragraph, XVII, XVIII in its first paragraph, XIX in its first paragraph, and XX in its first paragraph of the 2nd; fractions I, sub-paragraph b) numerals (i) in its second paragraph and (iii), III, sub-paragraph b), numeral (i), IV in its last paragraph, VI, IX, sub-paragraph a) and last paragraph of said fraction, as well as third paragraph of the 4th; the first and last paragraphs of the 17th; fraction I of the 19th; the first, fourth, fifth, sixth, and seventh paragraphs of the 21st; the 22nd; the first, second, and third paragraphs of the 24th; the first paragraph of the 25th; fractions I in its first paragraph and II of the 28th; the first paragraph of the 31st; fraction IV of the 32nd; the first paragraph of the 35th; the first paragraph of the 36th; fractions II, IV, VIII, and IX of the 37th; the first, fourth, fifth, and sixth paragraphs of the 38th; the second paragraph and fractions I and II of the 40th; the first and second paragraphs, the latter to become the fourth, of the 41st; the first paragraph and fraction V of the 42nd; the first paragraph of the 43rd; fraction I of the 44th; fraction IX of the 46th; the first paragraph of the 47th; the first and last paragraphs of the 55th; the first paragraph of the 57th; the 62nd and the 68th; are AMENDED; fractions X Bis, XIII Bis, and a second paragraph of fraction XX to the 2nd; a second paragraph to numeral (iii), sub-paragraph b) of fraction I, a sub-paragraph c) to fraction II, a second and third paragraphs to fraction VI of the 4th; a Chapter II Bis named "RISK-BASED APPROACH" with provisions 17-1 to 17-5; fraction I Bis to the 19th; a fourth paragraph, shifting the subsequent ones in order, in the 24th; a second paragraph, shifting the subsequent ones in order, in the 36th; fractions I Bis and X of the 37th; a second and third paragraphs, shifting the others in order, to the 41st; the 41st Bis; fractions II Bis and II Ter to the 42nd; fractions I to III to the first paragraph of the 43rd; a second paragraph to fraction I of the 44th; fraction IX Bis to the 46th; a second paragraph, shifting the subsequent ones in order, in the 55th; a Chapter XI Bis named "EXCHANGE OF INFORMATION" with provision 55-1st; a third paragraph, shifting the others in order, to the 56th; a second, third, and fourth paragraphs, shifting the others in order, of the 57th; the 62nd-1 and fractions I and II to the first paragraph of the 68th; are ADDED; and the second paragraph of fraction I and the last paragraph of the 28th and the second paragraph of the 38th, all of them of the General Provisions referred to in Article 91 of the Investment Funds Law, are REPEALED, to read as follows:

2nd.- ...

I.

a) to IV . ...

V . ...

Additionally, it will be understood that Control is exercised by that natural person who directly or indirectly, acquires 25% or more of the share composition or social capital of a legal person;

VI. to X ....

X. Bis. Risk Grade , the classification of Clients carried out by the Entity based on the evaluation of its Risk;

XI. to XIII ....

XIII. Bis. Mitigants , the policies and procedures implemented by the Entities that contribute to managing and reducing exposure to Risks identified in the methodology referenced in Chapter II Bis of these Provisions;

XIV. to XVI ....

XVII. Concerning Internal Operation , the Operation, activity, conduct, or behavior of any of the directors, officials, agents, and employees of the Entity in question, regardless of the labor regime under which they provide their services, that, due to its characteristics, could contravene, undermine, or evade the application of what is provided by the Law or these Provisions, or that, for any other cause, proves doubtful to the Brokerages for considering that it could favor or not alert on the updating of the scenarios provided in Articles 139 Quater or 400 Bis of the Federal Penal Code;

XVIII. Relevant Operation , the Operation carried out with legal tender banknotes and metallic coins in the United Mexican States or in any other country, as well as with traveler's checks and coins minted in platinum, gold, and silver, for an amount equal to or greater than the equivalent in national currency to seven thousand five hundred United States dollars;

...

XIX.

Politically Exposed Person , that individual who performs or has performed prominent public functions in a foreign country or in national territory, considering, among others, heads of State or government, political leaders, high-ranking governmental, judicial, or military officials, high executives of state-owned companies, or officials or important members of political parties and international organizations; understood as those entities established through official political agreements between states, which have the status of international treaties; whose existence is recognized by law in their respective member states and are not treated as resident institutional units of the countries in which they are located.

...

...

...

XX. Beneficial Owner , that natural person who, through another or through any act or mechanism, obtains the benefits derived from a contract or Operation and is, ultimately, the true owner of the resources, by having rights of use, enjoyment, benefit, disposal, or disposition over them.

The term Beneficial Owner also includes that person or group of natural persons who exercise Control over a legal person, as well as, where applicable, the persons who can instruct or determine, for their own economic benefit, the acts susceptible to be carried out through Trusts, mandates, or commissions;

XXI. to XXIV ....

4th.- ...

I. ...

a)...

b)...

(i) For the purposes of what is provided in this sub-paragraph, the following valid personal identification documents issued by Mexican authorities will be considered: the voter credential, the passport, the professional ID, the national military service card, the consular registration certificate, the unique military identity card, the affiliation card to the National Institute of Elderly Persons; the credentials and cards issued by the Mexican Social Security Institute, by the Social Security and Services Institute for State Workers, by the Social Security Institute for the Mexican Armed Forces, or by Popular Insurance, the driver's license, the credentials issued by federal, state, and municipal entities, and other national identifications that, where applicable, are approved by the Commission. Likewise, regarding natural persons of foreign nationality referred to in this fraction, in addition to those previously referred to in this paragraph, the passport or documentation issued by the National Institute of Migration that accredits their migratory status will be considered as valid personal identification documents;

(ii) ...

(iii) Proof of address, which may be any receipt for payment of domestic services such as, among others, electricity supply, telephone, natural gas, property tax, or water supply rights or bank statements, all of them with an age not greater than three months from their date of issuance or a valid lease contract on the date of presentation by the Client, the proof of registration before the Federal Taxpayer Registry, as well as others that, where applicable, are approved by the Commission;

Notwithstanding the foregoing, when the address stated in the contract celebrated by the Client with the Entity coincides with that of the Client's voter credential issued by a Mexican authority, in case they have been identified with the same, this will function as the proof of address referred to in the previous paragraph;

(iv) and (v) ...

II. ...

a) ...

b) ...

c) Additionally, information from the Client must be collected that allows the Entity to know (i) its shareholding or partnership structure, as applicable, and (ii) in case it has a Risk Grade other than low, its internal corporate structure; that is, the organizational chart of the legal person Client, considering at least the full name and position of those individuals who hold positions between general manager and the immediate lower hierarchy, as well as the full name and corresponding position of the members of its board of directors or equivalent.

Likewise, Entities must identify the Beneficial Owners of their legal person Clients who exercise Control over them in terms of the second paragraph of fraction V of the 2nd of these Provisions, in accordance with what is established in fraction VI of this provision.

When there is no natural person who owns or controls, directly or indirectly, a percentage equal to or greater than 25% of the capital or voting rights of the legal person in question, or who by other means exercises Control, direct or indirect, over the legal person, it will be understood that the administrator or administrators thereof exercise such Control, understanding that the natural person designated for such effect exercises administration.

When the designated administrator is a legal person or Trust, it will be understood that Control is exercised by the natural person appointed by the administrator of the legal person or Trust.

For such purposes, Entities must collect a declaration signed by the legal representative of the legal person Client in question, indicating who their Beneficial Owners are in terms of this sub-paragraph.

In case Entities have indications that make the truthfulness of the declared information questionable, Entities must take reasonable measures to determine and identify the Beneficial Owners of the corresponding legal person Client.

III....

a) ...

b) ...

...

(i) Document that credibly proves its legal existence, document in which the assignment of the tax identification number and/or equivalent issued by competent authority is stated, as well as obtaining the information and collecting the data referred to in sub-paragraph c) of fraction II of this provision;

(ii) and (iii) ...

...

IV....

...

...

Entities may apply the simplified measures referred to in this fraction, provided that the aforementioned societies, dependencies, and entities have been classified as Clients with a Low Risk Grade in terms of the 21st of these Provisions.

V....

VI. Regarding Beneficial Owners and that Entities are obligated to identify them in accordance with these Provisions, they must record and collect in the respective client identification file the same data and documents as those established in fractions I or III of this Provision, as applicable, with the exception of the document referred to in numeral (iii) of sub-paragraph b), of fraction I, as well as numeral (ii) of sub-paragraph b), of fraction III of the 4th of these Provisions, respectively, in case the obligation to identify the Beneficial Owner derives from a Client classified with a Low Risk Grade. This, in accordance with the measures established for such effects in the document referred to in the 57th of these Provisions, or in another document or manual elaborated by the Entities themselves.

In the case of legal persons whose representative titles of their social capital or securities representing such shares trade on any stock exchange in the country or in foreign securities markets recognized as such in terms of the General Provisions applicable to stock exchanges published in the Official Journal of the Federation on May 30, 2014, and their respective modifications, as well as those subsidiaries in which they have a majority participation of fifty percent in their social capital, Entities will not be obligated to collect the aforementioned identification data, considering that they are subject to stock market provisions on information disclosure.

The Ministry will issue guidelines that Entities may observe for compliance with what is provided in the first paragraph of this fraction, which will be made known through the electronic means established for such effect by the Commission;

VII....

VIII....

IX....

a) ...

â

...

â

...

â

...

â

...

â

...

â

...

â

...

â

regarding the settlors, beneficiaries, fiduciary delegates, and, where applicable, members of the technical committee or equivalent governing body, legal representative(s) and legal agent(s), identification data must be collected in the terms referred to in this Provision, as applicable. Without prejudice to the foregoing, the investment fund operating company that does not act as fiduciary may comply with the obligation to collect data regarding members of the technical committee or equivalent governing body, indicating only the first and last names, without abbreviations, of these as well as their date of birth.

b) ...

...

...

Entities that carry out Operations with Trusts regarding which they do not act as fiduciaries, may comply with the obligation (a) to collect the document referred to in numeral (i) of sub-paragraph b) of this fraction, and (b) that referred to in fraction VI of this provision, respectively, through a certificate signed by the fiduciary delegate and the Compliance Officer of the Entity acting as fiduciary, which must contain the information indicated in the previous sub-paragraph a), as well as the obligation to keep such documentation available to the Ministry and the Commission, in order to submit it, upon request of the latter, within the deadline established by the Commission itself.

...

Additionally to what is provided in the previous paragraph, Entities must contractually agree with such commissionaires or third parties, mechanisms so that the Entities themselves can verify that the files are integrated in accordance with what is stated in these Provisions. In all cases, Entities will be responsible for compliance with the obligations, in matters of Client identification, established by these Provisions, to which effect, they must establish in the document referred to in the 57th of the cited Provisions, the mechanisms they will adopt to comply with what is stated in the previous paragraph.

...

...

...

...

...

...

17th.- Entities will verify that the identification files of their legal person Clients, regardless of their Risk level, contain all the data and documents provided in the 4th of these Provisions, as well as that such data and documents are updated, understanding that Entities may opt not to carry out the update of the latter, in case it concerns a legal person Client with a Low Risk Grade. This, in the terms and conditions that Entities establish in the document referred to in the 57th of the Provisions. Likewise, they will verify, at least once a year, that the identification files of their Clients classified as High Risk Grade, contain in an updated manner all the data and documents provided in the 4th, 24th, and 28th of these Provisions.

Entities must establish in the document referred to in the 57th of these Provisions, the policies, criteria, measures, and procedures they will adopt to comply with what is stated in this Provision, including the circumstances in which a visit to the domicile of Clients classified as High Risk Grade must be carried out, in order to properly integrate the files and/or update the corresponding data and documents, in which case the results of such visit must be recorded in the respective file.

CHAPTER II BIS

RISK-BASED APPROACH

17th-1.- Entities, under the terms provided for this purpose in their internal policies, criteria, measures, and procedures documents referred to in the 57th of these Provisions, or in another document or manual prepared by them, must establish a methodology, designed and implemented, to carry out a Risk Assessment of the risks to which they are exposed derived from their products, services, practices, or technologies with which they operate. Said methodology must establish the processes for the identification, measurement, and mitigation of Risks, for which they must take into account the Risk factors identified for this purpose, as well as the national risk assessment and its updates, which the Secretariat will make known to them through the Commission.

With regard to Entities that are part of financial groups in terms of the Law to Regulate Financial Groups, they must take into account the results of the methodology that, if applicable, have been implemented by the other financial entities that make up the corresponding group.

Likewise, Entities will carry out the processes referred to in the first paragraph of this provision, prior to the launch or use of new products, services, practices, or technologies.

17th-2.- For the design of the Risk assessment methodology, Entities must comply with the following:

I. Consider in their identification process the indicators that explain how and to what extent the Entity may be exposed to Risk, considering at least the following elements: Clients, countries and geographic areas, products, services, transactions, and sending channels linked to the Entity's Operations, with its Clients, as well as the national risk assessment and its updates that the Secretariat will make known to them through the Commission.

II. Use a method for the measurement of Risks that establishes a relationship between the indicators referred to in the preceding fraction I and assign a weight to each of them consistently based on their importance to describe said Risks.

III. Establish the Mitigants considered necessary based on the indicators indicated in the preceding fraction I, identified by each Entity to keep them at an acceptable tolerance level in accordance with their internal policies, criteria, measures, and procedures documents referred to in the 57th of these Provisions.

In the preparation of the Risk assessment methodology, Entities must ensure that there are no inconsistencies between the information they incorporate into it and that which is in their automated systems.

17th-3.- When, as a result of the implementation of the Risk assessment methodology, the existence of greater or new Risks for the Entities themselves is detected, they must modify the corresponding policies and measures to mitigate them, as well as their Risk assessment methodology.

The compliance and results of the obligations contained in this Chapter must be reviewed and updated by Entities every twelve months, be recorded in writing, and be available to the Secretariat and to the Commission, at the latter's request, within the timeframe established by the Commission itself.

The Commission may review and, if applicable, order Entities to modify their Risk assessment methodology or their Mitigants, among other circumstances, when they do not consider adequate Risk administration in the procedure and criterion(s) for the determination of the opening, limitation, and/or termination of a commercial relationship with Clients, which must be congruent with said methodology, as well as request an action plan for them to adopt reinforced measures to manage and mitigate their Risks.

Entities must retain the information generated by virtue of this Chapter for a period of no less than five years and provide it to the Secretariat and to the Commission, at the latter's request, within the timeframe established by the Commission itself.

17th-4.- Entities must comply with all obligations contained in these Provisions, in accordance with the results generated by their methodologies referred to in this Chapter.

17th-5.- The Commission will prepare guidelines, guides, and/or best practices that Entities will consider for better compliance with what is provided in this Chapter, which will be made known through the electronic means established by the same.

19th.- ...

I. The policies, procedures, and controls to mitigate Risks, which must be consistent with the results of the implementation of the methodology referred to in Chapter II Bis;

I. Bis. Procedures for the Entity to follow up on Operations carried out by its Clients;

II. to V ....

21st.- The application of the Customer Knowledge policy must be based on the Risk Grade that a Client represents, such that when the Risk Grade is higher, the Entity must collect more information about their predominant activity, as well as carry out stricter supervision of their transactional behavior.

...

...

Likewise, Entities must classify Clients by their Risk Grade and establish, as a minimum (i) two classifications regarding their natural person Clients: High and Low Risk Grades, and (ii) three classifications regarding their legal person Clients and Trusts: High, Medium, and Low Risk Grades. Entities may establish additional Intermediate Risk Grades beyond the aforementioned classifications.

In order to determine the Risk Grade in which Clients should be located at the beginning of the contractual relationship, Entities must consider the information provided by them at the time of signing the respective contract. Additionally, Entities must carry out, at least, two evaluations per calendar year, in order to determine if it is necessary or not to modify the initial transactional profile of their Clients, as well as to classify them in a Risk Grade different from the initially considered one. The evaluations will be carried out on those Clients whose contract signing was carried out at least six months in advance of the corresponding evaluation.

Entities, under the terms provided for this purpose in their internal policies, criteria, measures, and procedures documents referred to in the 57th of these Provisions, will apply to their Clients who have been cataloged as High Risk Grade, as well as to new Clients who meet such character, identification questionnaires that allow obtaining more information about the origin and destination of resources and the activities and Operations they carry out or intend to carry out.

To determine the Risk Grade in which Clients should be located, as well as whether they should be considered Politically Exposed Persons, each Entity will establish in the documents indicated in the previous paragraph the criteria conducive to that end, which take into account, among other aspects, the Client's background, profession, activity, or business sector, the origin and destination of their resources, the place of their residence, the methodology referred to in Chapter II Bis of these Provisions, and the other circumstances determined by the Entity itself.

22nd.- For cases where, prior to or after the start of the contractual relationship, an Entity detects that the person who intends to be a Client or who already is, as applicable, meets the requirements to be considered a Politically Exposed Person and, additionally, of High Risk Grade, said Entity must, in accordance with what is established for this purpose in its internal policies, criteria, measures, and procedures document referred to in the 57th of these Provisions, obtain the approval of an official who holds a position within the three hierarchical levels below the General Director within the same, in order to initiate or, if applicable, continue the contractual relationship.

24th.- Entities must classify their Clients based on their Risk Grade.

Foreign Politically Exposed Persons will be considered at least as High Risk Grade Clients. With respect to the Clients referred to in this paragraph, Entities must collect the information that allows them to know and record the reasons why these have chosen to carry out Operations in national territory.

In the Operations carried out by Clients who have been classified as High Risk Grade, Entities will adopt measures to know the origin of the resources, and will seek to obtain the data and documents indicated in Chapter II of these Provisions, under the terms provided for this purpose in their internal policies, criteria, measures, and procedures documents referred to in the 57th of these Provisions, or in another document or manual prepared by them, regarding the spouse and economic dependents of the Client, as well as the companies and associations with which they maintain patrimonial links, in the case of natural persons, and with regard to legal persons, their main shareholders or partners, as applicable, while in the case of Trusts, they will seek to collect the same data regarding the spouse and economic dependents of the settlors and beneficiaries who are natural persons, as well as the companies and associations with which they maintain patrimonial links and, with regard to settlors and beneficiaries who are legal persons, their corporate structure and their main shareholders or partners, under the terms provided for this purpose in their internal policies, criteria, measures, and procedures documents referred to in the 57th of these Provisions, or in another document or manual prepared by them. With regard to Foreign Politically Exposed Persons, Entities must obtain, in addition to the reference data, the documentation indicated in Chapter II of these Provisions, regarding the natural and legal persons mentioned earlier in this paragraph.

Without prejudice to the foregoing, with regard to legal person Clients whose shares representing their share capital or securities representing said shares trade on any stock exchange in the country or in foreign securities markets recognized as such in terms of the general provisions applicable to stock exchanges published in the Official Gazette on May 30, 2014, and their respective modifications, as well as those subsidiaries in which they have a majority participation of fifty percent in their share capital, Entities will not be obligated to collect the aforementioned identification data, considering that they are subject to provisions on stock market disclosure of information.

...

25th.- Without prejudice to what other applicable provisions establish, for the provision of correspondent services to foreign counterparties, Entities must consider the Risks and approve, at the executive level, the relationship that allows initiating such provision and, for this purpose, they will document the measures and procedures their counterparties observe in matters of prevention of operations with proceeds of illicit origin and financing of terrorism, in accordance with the regulations applicable to them in their corresponding jurisdiction.

...

28th.- ...

I. In the case of commercial legal person Clients classified as High Risk Grade, information relative to the name, nationality, domicile, corporate purpose, and share capital of the legal persons that make up the business group or, if applicable, the business groups that make up the consortium of which the Client is part, must be requested.

Paragraph repealed

...

II. With regard to legal persons with the character of civil societies or associations that are classified as High Risk Grade, identify the person or persons who have Control over such societies or associations, and

III....

Paragraph Repealed.

31st.- For each Unusual Operation detected by an Entity, it must send to the Secretariat, through the Commission, the corresponding report, within three business days following the conclusion of the Committee session that adjudges it as such. For the purpose of carrying out said adjudication, the Entity through its Committee will have a period that will not exceed sixty calendar days counted from when the alert is generated through its system, model, process, or by the Entity's employee, whichever occurs first.

...

32nd.- ...

I. to III ....

IV. The Operations carried out under the same contract, as well as those carried out with traveler's checks and coins minted in platinum, gold, and silver, for multiple or fractional amounts that, for each individual Operation, are equal to or exceed the equivalent in national currency to five hundred United States dollars, carried out in the same calendar month that sum, at least, the equivalent in national currency to the amount of seven thousand five hundred United States dollars or its equivalent in the currency in question, provided that they do not correspond to the Client's transactional profile;

V. to XIII ....

...

...

...

35th.- In the event that an Entity has information based on indications or concrete facts that, in attempting to carry out an Operation, the resources could originate from illicit activities or could be destined to favor, provide help, aid, or cooperation of any kind for the commission of the crime provided for in Article 139 Quater of the Federal Penal Code, or that they could fall under the circumstances of Article 400 Bis of the same legal instrument, or in the event that an Entity exclusively carries out the activities referred to in fraction V, of Article 39 Bis and the last paragraph of Article 40 Bis of the Law, has information based on indications or concrete facts that, in attempting to carry out an Operation, it could be destined to favor, provide help, aid, or cooperation of any kind for the commission of the crime provided for in Article 139 Quater of the Federal Penal Code, or that they could fall under the circumstances of Article 400 Bis of the same legal instrument; said Entities, in the event that they decide to accept said Operation, must send to the Secretariat, through the Commission, within 24 hours counted from when they know said information, an Unusual Operation Report, in which, in the column of Operation description, the legend "24-hour Report" must be inserted. Likewise, in those cases where the respective Client does not carry out the Operation referred to in this paragraph, Entities must present to the Secretariat, through the Commission, the Unusual Operation Report under the terms indicated in this provision.

...

...

...

36th.- For each Internally Concerning Operation detected by an Entity, it must send to the Secretariat, through the Commission, the corresponding report, within three business days following the conclusion of the Committee session that adjudges it as such. For the purpose of carrying out said adjudication, the Entity through its Committee will have a period that will not exceed sixty calendar days counted from when said Entity detects that Operation, through its system, model, process, or by any employee thereof, whichever occurs first.

To this effect, Entities must send the reports referred to in this provision, through electronic means and in the official format issued for this purpose by the Secretariat, in accordance with the terms and specifications indicated by the latter.

...

37th.- ...

I. ...

...

I. Bis. Submit to the approval of the Entity's Board of Directors, as applicable, the methodology elaborated and implemented to carry out the Risk Assessment referred to in the previous Chapter II Bis, as well as the results of its implementation;

II. Act as the competent instance to know the results obtained by the Entity's internal audit area or, if applicable, by the independent external auditor referred to in the 55th of these Provisions, regarding the valuation of the effectiveness of the policies, criteria, measures, and procedures contained in the document indicated in the preceding fraction I, in order to adopt necessary actions aimed at correcting flaws, deficiencies, or omissions.

III ....

IV. Establish and disseminate the criteria for the classification of Clients, based on their Risk Grade, in accordance with what is indicated in the 21st of these Provisions;

V. to VII. ...

VIII. Inform the competent area of the Entity, regarding conduct carried out by executives, officials, employees, or agents thereof, that cause the Entity to incur in a violation of what is provided in these Provisions, or in cases where said executives, officials, employees, or agents contravene what is provided in the policies, criteria, measures, and procedures indicated in fraction I of this Provision, in order to impose the corresponding disciplinary measures;

IX. Resolve other matters submitted to its consideration, related to the application of these Provisions; and

X. Ensure that the Entity, for the compliance with these Provisions, has the internal structures referred to in this Chapter, regarding organization, number of people, material and technological resources, in accordance with the results of the implementation of the methodology referred to in the previous Chapter II Bis.

...

38th.- Each Entity will determine the way in which the Committee will operate, which, except for what is indicated in the last paragraph of this Provision, will be integrated with at least three members who, in any case, must hold the headships of the areas designated for this purpose by the Board of Directors of said Entity and, in any case, members of that Board, the General Director, employees, or officials who hold positions within the three immediate hierarchical levels below the General Director of the Entity in question must participate.

Paragraph repealed

...

The permanent members of the Committee must attend the sessions thereof and may designate their respective alternates, who may only represent them in two non-consecutive sessions per semester.

The Committee will have a president and a secretary, designated from among its members. Said Committee will meet with a frequency of at least once every month of the year. For the sessions to be held validly, it will be required that the majority of the members of the Committee itself be present.

Entities that have fewer than twenty-five people serving them, whether performing functions for them directly or indirectly, through complementary service companies, will not be obligated to constitute and maintain the Committee referred to in this Provision. In the circumstance provided for in this paragraph, the functions and obligations that should correspond to the Committee in accordance with what is indicated in these Provisions, will be exercised by the Compliance Officer.

40th.- ...

Likewise, each Entity must communicate to the Secretariat, through the Commission, through the means referred to in the preceding paragraph, the appointment, addition, or substitution of the members of the Committee, within fifteen business days following the date on which it was carried out. For these purposes, the following information must be provided:

I. The name of the areas whose heads have been appointed in addition or substitution to those that are part of the Committee, as well as the full name without abbreviations of said heads and full name without abbreviations and position of their alternates;

II. The date of the corresponding modification, and

III ....

41st.- The Board of Directors or the Committee of each Entity will designate, from among the members of said Committee, an official who will be called "Compliance Officer".

In the event that the Entity does not have a Committee due to being in the circumstance referred to in the last paragraph of the 38th of the Provisions, the Compliance Officer will be designated by its Board of Directors who must meet the requirements to be a member of the Committee, in terms of the aforementioned provision.

In any case, the Compliance Officer must be an official who holds a position within the three immediate hierarchical levels below the General Director of the Entity in question and who will perform, at least, the functions and obligations established below:

I. Prepare and submit to the consideration of the Committee the document referred to in the 57th of these Provisions, which contains the Customer identification and knowledge policies and the criteria, measures, and procedures they must adopt to comply with what is provided in these Provisions;

I. Bis. Present to the Committee the methodology elaborated and implemented to carry out the Risk Assessment referred to in the previous Chapter II Bis, as well as the results of its implementation;

II. Verify the correct execution of the measures adopted by the Committee, in exercise of the powers provided for in the 37th of these Provisions;

III. Inform the Committee regarding conduct, activities, or behaviors carried out by the executives, officials, employees, or agents of the Entity, that cause it to incur in a violation of what is provided in the Law and these Provisions, or in cases where said executives, officials, employees, or agents contravene what is provided in the document indicated in fraction I of this

Disposición, with the objective that the corresponding disciplinary measures be imposed;

IV. To make known to the Committee, the celebration of Operations by the Entity in question, whose characteristics could generate a high Risk for the Entity itself;

V. Coordinate both the follow-up activities of Operations, as well as the investigations that must be carried out at the institutional level, with the purpose that the Committee has the necessary elements to rule on them, if applicable, as Unusual Operations or Concerning Internal Operations;

For the effects indicated in the preceding paragraph, the area in charge of the Compliance Officer of each Entity or, where appropriate, the personnel designated by him/her, will verify that the corresponding alerts have been analyzed and the respective investigations documented;

VI. Send to the Secretariat, through the Commission, the reports of Operations referred to in the 35th of these Provisions, as well as those considered urgent, and inform the Committee thereof, at its next session;

VII. Act as a consultation instance within the Entity regarding the application of these Provisions, as well as of the document referred to in the 57th of the same;

VIII. Define the characteristics, content and scope of the training programs for the Entity's personnel, as referenced in the 44th of these Provisions;

IX. Receive and verify that the Entity responds, in accordance with the applicable legal provisions, to requests for information and documentation, as well as orders for securing or unlocking resources, which, through the Commission, are formulated by competent authorities in matters of prevention, investigation, prosecution and sanction of conduct that could update the circumstances foreseen in Articles 139 Quater or 400 Bis of the Federal Penal Code; likewise, verify that the Entity has appropriate procedures to ensure that it complies with what is provided in the 65th of these Provisions;

X. Act as a liaison between the Committee, the Secretariat and the Commission, for matters relating to the application of these Provisions, and

XI. Ensure that the area under its charge receives directly and follows up on notices issued by employees and officials of the Entity, regarding facts and acts that may be susceptible to being considered as Unusual Operations or Concerning Internal Operations.

Likewise, the designation of the Compliance Officer must fall upon an official who is independent of the Entity's units in charge of promoting or managing the financial products or services that it offers to its Clients. In no case shall the designation of the Compliance Officer of an Entity fall upon a person in charge of internal audit tasks in the Entity.

...

...

41st Bis.- The Committee of each Entity or, alternatively, its board of directors or general manager, shall appoint an Entity official who may temporarily substitute for its Compliance Officer, in the fulfillment of its obligations pursuant to these Provisions, for up to ninety (90) natural days during a calendar year, counted from the date the official designated as Compliance Officer leaves, is revoked or finds himself/herself unable to perform the assignment in question.

The Entity official performing the interim position shall not have internal audit functions in the same.

Entities may make effective the interim period referred to in this Provision, according to the needs of each Entity.

The Compliance Officer appointed as interim shall comply with the functions and obligations set forth in these Provisions, until the moment the revocation mentioned in fraction II of the 43rd of these Provisions is reported.

42nd.- Entities that exclusively carry out the activities referred to in fraction V, of article 39 Bis and the last paragraph of article 40 Bis of the Law, shall not be obliged to comply with what is provided in the 37th, 38th, 39th, 40th,

41st and 41st Bis of these Provisions, as well as those derived therefrom that, pursuant to these Provisions, oppose what is established in this Provision.

...

I. and II ....

II. Bis. Present the methodology for carrying out the Risk Evaluation referred to in Chapter II Bis above, as well as the results of its implementation;

II. Ter. Submit for approval by the Entity's board of directors, as appropriate, the methodology developed and implemented to carry out the Risk Evaluation referred to in Chapter II Bis above, as well as the results of its implementation;

III. and IV ....

V. Establish and disseminate criteria for the classification of Clients, based on their Degree of Risk, in accordance with what is stated in the 21st of these Provisions;

VI. to XVII.

...

...

...

43rd.- The Entity shall inform the Secretariat, through the Commission, via electronic means and in the official format issued for such effect by said Secretariat, in accordance with the terms and specifications indicated by the latter, the following:

I. The full name without abbreviations of the official designated as Compliance Officer or of the representative referred to in the 42nd of these Provisions, as applicable, as well as the other information provided for in the indicated format, within two (2) business days following the date on which the corresponding designation was made;

II. The revocation of the designation of the Compliance Officer or of the representative referred to in the 42nd of these Provisions, as applicable, on the business day following the date on which it occurred, whether by determination of the Entity, rejection of the assignment, termination of employment or inability, as well as the other information provided for in the indicated format, and

III. The full name without abbreviations of the official designated as Compliance Officer in terms of what is established in the 41st Bis of these Provisions, as well as the other information provided for in the indicated format, on the business day following the date on which it occurred.

44th .- ...

I. The provision of courses, at least once a year, which shall be directed especially to the members of their respective boards of directors, executives,

officials and employees, including

those who work in customer service or resource administration areas and which contemplate, among other aspects, those relating to the content of their policy documents, criteria, measures and procedures referred to in the 57th of these Provisions, which the Entity has developed for the due compliance thereof, as well as regarding the activities, products and services offered by the Entity.

Without prejudice to what is stated in the preceding paragraph, the topics of the training must be coherent with the results of the implementation of the methodology referred to in Chapter II Bis and adapt to the responsibilities of the members of their respective boards of directors, executives, officials and

employees.

II....

...

46th.- ...

I.

a VIII ....

IX. Maintain information security schemes for processed information, guaranteeing its integrity,

availability, auditability and confidentiality;

IX. Bis. Provide the information that Entities will include in the methodology they must develop pursuant to what is established in the 17th-1 of these Provisions, and

X....

...

47th.- Members of the board of directors, the Committee, the Compliance Officer, the representative

referred to in the 42nd of these Provisions, if applicable, as well as executives, officials,

employees and proxies of the Entities, must maintain absolute confidentiality regarding information

relating to the reports foreseen in these Provisions, except when requested by the Secretariat, through the Commission, and other authorities expressly empowered to do so or in the case foreseen in Chapter XI Bis

of these Provisions.

...

55th.- Entities must maintain control measures that include review by the internal audit area, or by an independent external auditor, to evaluate and rule from January to December of each year, or with respect to the period resulting from the date the Commission authorizes the start of operations of the Entity in question to December of the respective year, the effectiveness of compliance with these Provisions, in accordance with guidelines issued by the Commission for such effects. The results of such reviews must be presented to the general management, to the Entity's Committee or, where appropriate, to the representative referred to in the 42nd of these Provisions, as a report, in order to evaluate the operational efficacy of implemented measures and follow up on corrective action programs that may apply. In the aforementioned valuation exercise, no member of the Entity's Committee may participate.

Regarding Entities that form part of financial groups in terms of the Law to Regulate Financial Groupings, these must take into account the reviews referred to in the first paragraph of this provision that, if any, have been carried out by other financial entities integrating the corresponding group.

The information referred to in this provision must be preserved by the Entity for a period of no less than five years, and sent to the Commission within sixty (60) natural days following the close of the exercise to which the review corresponds, in the electronic media indicated by the latter.

CHAPTER XI BIS

EXCHANGE OF INFORMATION

55-1st.- In order to strengthen measures to prevent and detect acts, omissions or Operations that could favor, provide help, aid or cooperation of any kind for the commission of the crimes foreseen in Articles 139 Quater and 400 Bis of the Federal Penal Code, Entities that form part of financial groups in terms of the Law to Regulate Financial Groupings may exchange any type of information regarding the Operations they carry out with their Clients, with other financial entities that form part of the same group that are authorized to do so pursuant to applicable provisions, in matters of prevention of operations with proceeds of illicit origin and financing of terrorism, provided that they enter into an agreement among themselves stipulating the following:

a) The confidential treatment that will be given to the exchanged information, and

b)

The positions of the officials authorized to carry out the aforementioned exchange.

Prior to the exchange of information taking place, Entities must inform the Commission about the signing of the agreement referred to in this provision, in the official format issued for such effects by it and through the means it establishes.

When an Entity shares with another or other financial entities that form part of the same financial group the information referred to in this provision, the former must preserve all supporting documentation, which must be available to the Secretariat and the Commission, upon request by the latter, within the timeframe established by the Commission itself.

56th .- ...

...

In the case where the Entity hires foreign commissioners, in addition to what is established in the preceding paragraph, it must take into account the available information on the Risk level of the country where said commissioner operates.

...

...

...

57th.- Each Entity must prepare and send to the Commission, through the electronic means indicated by it, a document in which said Entity develops its respective Client identification and knowledge policies, as well as the criteria, measures and internal procedures it must adopt to comply with what is provided in these Provisions, and to manage the Risks to which it is exposed in accordance with the results of the implementation of the methodology referred to in Chapter II

Bis of these Provisions.

If applicable, in said document references to those criteria, measures,

internal procedures and other information that, by virtue of what is provided in these Provisions, may be reflected in a document different from the one mentioned above must also be included.

In any of the documents provided for in the preceding paragraph, the methodology referred to in Chapter II Bis of these Provisions must be included. Likewise, the procedure and criterion(s) for determining the opening, limitation and/or termination of a commercial relationship with Clients, which must be congruent with said methodology, must be included.

Entities must send to the Commission the modifications they make to the document referred to in the first paragraph of this Provision along with a complete copy of the same, within twenty (20) business days following the date that their respective audit committee approves them, in the terms provided for in fraction I of the 37th of these Provisions.

...

...

...

...

...

...

62nd.- The Secretariat may interpret, for administrative purposes, the content of these

Provisions, as well as determine the scope of their application, whenever so requested by the Entities,

associations or societies in which they are affiliated, self-regulatory bodies referred to in the Law,

and national authorities that require it for the fulfillment of their functions, for which it will listen to the opinion of the Commission.

62nd-1.- In order to be able to comply with what is established in these Provisions, Entities will request from the Commission, the key to be used to access the electronic system established for such effects by the Commission, having the same at the moment of starting operations.

68th.- The Secretariat may authorize, without prejudice to what is established in this chapter, access to certain resources, rights or assets, as well as acts, Operations or services, in accordance with the following:

I. To Clients who are located within the List of Blocked Persons, in terms of international treaties celebrated by the Mexican State, in terms of resolution 1452 (2002) of the Security Council of the United Nations Organization, and

II. To Entities, regarding obligations they have with some Client contracted with some

Entity, among others, in accordance with the guides, guidelines or best practices made public by the Secretariat for such effects.

TRANSITIONAL PROVISIONS

First.- This Resolution shall enter into force the day following its publication in the Diario Oficial de la Federación.

Second.- Guidelines, interpretations and criteria issued by the Secretariat or by the Commission, based on what is provided in the General Provisions referred to in Article 91 of the Investment Funds Law, published in the Diario Oficial de la Federación on December 31, 2014, will continue to be applicable insofar as they do not oppose what is established in this Resolution.

Third .- Entities to which authorization is granted to constitute and operate as such on a date

subsequent to the entry into force of this Resolution, must comply with the obligations contained in

these Provisions, in the terms and in accordance with the deadlines indicated below:

I. Ninety (90) natural days counted from the date of authorization, to present to the Commission the

document referred to in the 57th of these Provisions.

II. Sixty (60) business days counted from the date of commencement of their operations to carry out the

designations referred to in the 38th, 41st or 42nd, as applicable, of these Provisions, informing the

Commission thereof, within the mentioned deadline.

Fourth.- Entities that are in operation at the time of entry into force of this

Resolution, will have a period that cannot exceed forty-five (45) natural days counted from

the entry into force of this Resolution, in order to elaborate a work schedule in which they must

establish activities, deadlines and responsible parties, so that at the latest within two hundred seventy (270) natural days

following the entry into force of this Resolution, (i) have updated the automated systems referred to in the 46th of these Provisions; (ii) begin to collect the corresponding information pursuant to the obligations established in this Resolution, as well as introduce it into the same automated systems referred to above, as applicable, regarding those

Operations that are celebrated from the expiration of said deadline; (iii) present to the Commission the document

referred to in the 57th of these Provisions with the respective modifications, and (iv) comply with the other obligations established in the Resolution in question.

Fifth.- The obligation referred to in the 17th of these Provisions, will apply with respect to all

Clients corporate persons of the Entities regardless of whether the commercial relationship with them

had started prior to the entry into force of this Resolution.

Sixth.- Entities will comply with the modifications provided in the 4th of these

Provisions, insofar as including in the Client identification file the proof of address, regarding those Operations that are celebrated from July 1, 2017.

Seventh.- The Secretariat, prior to the opinion of the Financial Intelligence Unit, will make known to the Entities through the electronic means established by the Commission,

the guidelines referred to in fraction VI of the 4th of the Provisions, within ninety (90) natural days following the entry into force

of this Resolution.

Eighth.- The Secretariat will make known to the Entities the guides, guidelines or best practices referred to

in fraction II of the 68th of the Provisions, within two hundred forty (240) natural days

following the entry into force of this Resolution.

Ninth.- The Commission will make known to the Entities through the electronic means it establishes,

the guidelines, guides and/or best practices referred to in the 17th-5 of the Provisions, within

ninety (90) natural days following the entry into force of this Resolution.

Entities will comply with the obligations derived from the implementation of Chapter II Bis of

the Provisions, added by this Resolution, at the latest within three hundred sixty (360) natural days counted from the entry into force of this Resolution.

Tenth.- The obligation to communicate to the Secretariat, through the Commission, the modifications to

the internal structures referred to in the 40th and 43rd of these Provisions reformed by

this Resolution, will enter into force from the moment the Secretariat makes known the electronic media and the

official format issued for such effect by said Secretariat.

Mexico City, March 13, 2017. - The Secretary of Finance and Public Credit,

José Antonio

Meade Kuribreña. - Rubric.

In the document you are viewing, there may be text, characters or objects that do not display correctly due to conversion to HTML format, therefore we recommend always taking as reference the digitized image of the DOF or the PDF file of the edition. The content, form and scope of published documents are the sole responsibility of their issuer.

INQUIRY

BY DATE

Do Mo Tu We Th Fr Sa

INDICATORS

Exchange Rate and Rates as of 08/31/2026

DOLLAR

17.0427 UDIS

8.810483 TIIE 28 DAYS

6.7659% TIIE 91 DAYS

6.8033% TIIE 182 DAYS

6.8577% TIIE DE FONDEO

6.51%

See more

SURVEYS

Did you like the new look of the Official Gazette website?

No

Yes

Official Gazette of the Federation

Río Amazonas No. 62, Col. Cuauhtémoc, C.P. 06500, Mexico City Tel. (55) 5093-3200, where you can access our menu of services

Electronic address: dof.gob.mx

113

LEGAL NOTICE | SOME RIGHTS RESERVED © 2026

More like this from SHCP

SHCP published 14 documents in the last 30 days. We email you each new one the day it's published.

Topics
Share