2017-04-04 | DOF 5478612Added
This Resolution amends, adds, and repeals general provisions under Article 124 of the Popular Savings and Credit Law to implement a Risk-Based Approach for popular financial societies, community financial societies (levels I-IV), and rural financial integration organisms. It mandates the identification of beneficial owners, updates valid identification documents, modifies thresholds for relevant and unusual operations, and clarifies reporting deadlines for suspicious transactions. The changes also establish interim compliance officer appointments and require the exchange of information within financial groups to combat illicit funds and terrorism financing.
DOF: 04/04/2017
RESOLUTION amending, adding, and repealing various general provisions under Article 124 of the Popular Savings and Credit Law
At the margin, a seal with the National Coat of Arms, which reads: United Mexican States.- Ministry of Finance and Public Credit.
RESOLUTION AMENDING, ADDING, AND REPEALING VARIOUS GENERAL PROVISIONS UNDER ARTICLE 124 OF THE POPULAR SAVINGS AND CREDIT LAW.
JOSÉ ANTONIO MEADE KURIBREÑA, Secretary of Finance and Public Credit, based on the provisions of Articles 31, fractions VII and XXXIV of the Organic Law of the Federal Public Administration, as well as 45 Bis, ninth paragraph, and 124 of the Popular Savings and Credit Law, in exercise of the powers conferred upon me by Article 6, fraction XXXIV of the Internal Regulations of the Ministry of Finance and Public Credit, and having received the prior opinion of the National Banking and Securities Commission issued via letter number VSPP/19/2017 dated February 13, 2017; and
CONSIDERING
That one of the most effective mechanisms within the regulatory framework for the prevention and combat of operations with resources of illicit origin and terrorism financing consists in the implementation of customer and user identification and due diligence policies by popular financial societies, community financial societies with operation levels I to IV, and rural financial integration organisms, as these constitute fundamental elements to mitigate the risk that such societies are used for the commission of such offenses;
That since the year 2000, Mexico has been a member of the Financial Action Task Force (FATF), an intergovernmental body that sets international standards in matters of prevention and combat of operations with resources of illicit origin, terrorism financing, and financing for the proliferation of weapons of mass destruction;
That in this sense, Mexico has committed to the aforementioned group and its members to implement its recommendations and, consequently, to carry out a mutual evaluation consisting of a review of the systems and mechanisms created in our country as a member of the FATF, as well as Mexico's response in the effective implementation of the 40 Recommendations. This, with the objective of instituting legal and operational systems for the prevention of operations with resources of illicit origin and terrorism financing, as well as any other threat that could compromise the integrity of the financial system, both internationally and nationally;
That in accordance with FATF Recommendation 1, financial institutions must identify, evaluate, and take actions to mitigate risks regarding operations with resources of illicit origin and terrorism financing through customer and user due diligence mechanisms that are appropriate to the risk they represent, which implies that popular financial societies, community financial societies with operation levels I to IV, and rural financial integration organisms must apply a Risk-Based Approach, so a Chapter is added establishing the use of a methodology so that popular financial societies, community financial societies with operation levels I to IV, and rural financial integration organisms can evaluate risks in this matter and apply mitigants to them in accordance with a Risk-Based Approach, in order to avoid being used for the commission of operations with resources of illicit origin and terrorism financing;
That in accordance with FATF Recommendation 10, modifications are made regarding the customer identification policy for legal persons, regardless of the risk classification made by the popular financial society, the community financial society with operation level I, II, III, or IV, or the rural financial integration organism, so that obligated subjects know their shareholding and corporate structures, as well as to specify the mechanisms to collect data on beneficial owners. This, with the objective that popular financial societies, community financial societies with operation levels I to IV, and rural financial integration organisms have more information allowing them to better evaluate the risks to which they are exposed due to their commercial relationships if used for the commission of offenses of operations with resources of illicit origin and terrorism financing, and to adopt pertinent actions for their mitigation;
That in order to increase the effectiveness of measures in matters of prevention of operations with resources of illicit origin and combat to terrorism financing, the thresholds regarding relevant and unusual operations, as well as that regarding the establishment of internal approval escalation mechanisms when popular financial societies, community financial societies with operation levels I to IV, and rural financial integration organisms receive cash in branches, for the performance of individual operations of purchase, receipt of deposits, receipt of credit or service payments, and transfers or fund placements with their individual customers or users, are modified, which will result in authorities having more information for the development of their powers in this matter;
That based on FATF Recommendation 20 and in order to strengthen the sending of reports of unusual operations and reports of concerning internal operations submitted by popular financial societies, community financial societies with operation levels I to IV, and rural financial integration organisms in terms of the General Provisions under Article 124 of the Popular Savings and Credit Law, it is necessary to clarify the deadlines for presenting such reports once they have been determined, with the objective that the authority has timely information for the exercise of its powers;
That so that popular financial societies, community financial societies with operation levels I to IV, and rural financial integration organisms are able to comply with what is provided in these General Provisions, by having an official who at all times acts as a liaison with the authorities in terms of the General Provisions under Article 124 of the Popular Savings and Credit Law, the possibility is established to appoint an interim compliance officer for a determined period in case the compliance officer in charge has their appointment revoked or is unable to carry out their functions;
That in order to recognize other official identifications, new valid personal identification documents for the celebration of operations are provided;
That with the objective of providing certainty on the period that the annual audit report of popular financial societies, community financial societies with operation levels I to IV, and rural financial integration organisms that begin operations after the beginning of the calendar year must cover, it is considered necessary to clarify the scope of this obligation in this case;
That in accordance with FATF Recommendation 18, it is proposed that those financial entities that are part of the same financial group in terms of the Law to Regulate Financial Groups exchange information in matters of prevention of operations with resources of illicit origin and terrorism financing at the group level, and
That once the opinion of the National Banking and Securities Commission has been heard, I have deemed it appropriate to issue the following:
RESOLUTION AMENDING, ADDING, AND REPEALING VARIOUS GENERAL PROVISIONS UNDER ARTICLE 124 OF THE POPULAR SAVINGS AND CREDIT LAW
SINGLE ARTICLE.- The fractions VI in its second paragraph, XX, XXI in its first paragraph, XXII in its first paragraph, XXIII, and XXVII, of the 2nd; the fractions I, subsection b), numerals i, second paragraph, and iii, III, subsection b), second paragraph, numeral i, IV in its last paragraph, VI, IX, subsection a), numeral vii, and last paragraph of said fraction, as well as third paragraph of the 4th; the fractions I, subsections a) and b), II, , and c), III, as well as the second paragraph of the 18th; the first, second, and third paragraphs, as well as fractions I, II, and III of the 19th, the seventh paragraph of the 20th; the first and third paragraphs of the 23rd; fraction I of the 25th; the first, fourth, fifth, sixth, and seventh paragraphs of the 27th; the 28th; the first, second, and third paragraphs of the 30th; the first paragraph of the 31st; fractions I, first paragraph, and II of the 34th; the last paragraph of the 37th; the first paragraph of the 40th; fraction IV of the 41st; the first paragraph of the 44th; the first paragraph of the 45th; fractions II, IV, VIII, and IX of the 46th; the first, fifth, sixth, and seventh paragraphs of the 47th; the second paragraph, and fractions I and II of the 49th; the first and second paragraphs of the 50th; the 51st; fraction I of the 52nd; fractions IV and IX of the 54th; the first paragraph of the 55th; the 62nd; the 63rd; the second and third paragraphs, as well as fraction IV of the second paragraph of the 64th; the first paragraph of the 67th; the 72nd, the 78th; are AMENDED; fractions XIII Bis, XVI Bis, and a second paragraph to XXIII of the 2nd; a second paragraph to numeral iii, of subsection b), of fraction I, a subsection c) to fraction II, as well as a second and third paragraphs to fraction VI, of the 4th, a second paragraph to fraction II, and a third paragraph to the 18th; a Chapter II Bis titled "RISK-BASED APPROACH" with provisions 23rd-1 to 23rd-5; fraction I Bis to the 25th; a fourth paragraph, shifting the subsequent one in order in the 30th; a second paragraph, shifting the subsequent one in order to the 45th; fractions I. Bis and X to the 46th; a second and third paragraphs, shifting the others in order, as well as a fraction I Bis to the 50th; the 50th Bis; fractions I, II, and III to the 51st; a second paragraph to fraction I, of the 52nd; fraction IX. Bis, to the 54th; a second paragraph, shifting the subsequent one in order to the 62nd; the 64th Bis; a third paragraph to the 65th; a second, third, and fourth paragraphs, shifting the others in order to the 67th; the 72nd-1; fractions I and II to the 78th; are ADDED; and the second paragraph of fraction I of the 18th; the second paragraph of fraction I, and the second paragraph of the 34th; the second paragraph of the 47th, all of them of the General Provisions under Article 124 of the Popular Savings and Credit Law, are REPEALED, to remain as follows:
2nd.- ...
I. to V. ...
VI. ...
Additionally, it will be understood that Control is exercised by that natural person who directly or indirectly acquires 25% or more of the share composition or social capital of a legal person;
VII. to XIII. ...
XIII. Bis. Risk Grade, to the classification of Clients carried out by the Entity based on the evaluation of its Risk;
XIV. to XVI. ...
XVI. Bis. Mitigants, to the policies and procedures implemented by Entities that contribute to administering and decreasing exposure to Risks identified in the methodology referred to in Chapter II Bis of these General Provisions;
XVII. to XIX. ...
XX. Concerning Internal Operation, to the Operation, activity, conduct, or behavior of any of the directors, officials, commissioners, agents, and employees of the Entity in question, regardless of the labor regime under which they provide their services, that, due to its characteristics, could contravene, compromise, or evade the application of what is provided by the Law or these General Provisions, or that, for any other cause, results doubtful for Entities by considering that it could favor or not alert about the updating of the assumptions provided in articles 139 Quáter or 400 Bis of the Federal Penal Code;
XXI. Relevant Operation, to the Operation carried out with banknotes and legal tender coins in the United Mexican States or in any other country, for an amount equal to or greater than the equivalent in national currency to seven thousand five hundred United States dollars.
...
XXII. Politically Exposed Person, to that individual who performs or has performed prominent public functions in a foreign country or national territory, considering among others, heads of state or government, political leaders, high-ranking governmental, judicial, or military officials, high executives of state-owned companies, or officials or important members of political parties and international organizations; understood as those entities established through official political agreements between states, which have the status of international treaties; whose existence is recognized by law in their respective member states and are not treated as resident institutional units of the countries in which they are located.
...
...
...
XXIII. Beneficial Owner, to that natural person who, through another or any act or mechanism, obtains the benefits derived from an account, contract, or Operation and is, ultimately, the true owner of the resources, by having rights of use, enjoyment, exploitation, dispersion, or disposal over them.
The term Beneficial Owner also includes that person or group of natural persons who exercise Control over a legal person, as well as, in their case, the persons who can instruct or determine, for their own economic benefit, the acts susceptible of being carried out through Trusts, mandates, or commissions;
XXIV. to XXVI. ...
XXVII. Obligated Subjects, to the Entities, as well as to the persons, institutions, entities, or societies subject to the obligations referred to in articles 115 of the Credit Institutions Law, 108 Bis of the Savings for Retirement Systems Law, 91 of the Investment Funds Law, 212 and 226 Bis of the Securities Market Law, 492 of the Insurance and Surety Institutions Law, 129 of the Credit Unions Law, 71 and 72 of the Law to Regulate the Activities of Savings and Loan Cooperative Societies, 60 of the Organic Law of the National Financial Development Institution for Agriculture, Rural, Forestry, and Fisheries, and 95 and 95 Bis of the General Law of Organizations and Auxiliary Credit Activities, excluding exchange centers, and
XXVIII.
...
4th.- ...
I.
...
a)
...
b)
...
i.
For the purposes of what is provided in this subsection, the following documents issued by Mexican authorities will be considered as valid personal identification documents:
the voter credential, the passport, the professional ID, the national military service card, the consular registration certificate, the unique military identity card, the affiliation card to the National Institute of Older Adults, the credentials and cards issued by the Mexican Institute of Social Security, by the Institute of Security and Social Services for State Workers, by the Social Security Institute for the Mexican Armed Forces, or by Popular Insurance, the driver's license, the credentials issued by federal, state, and municipal authorities, the identity certificates issued by municipal authorities, and the other national identifications that, in their case, are approved by the Commission. Likewise, regarding natural persons of foreign nationality referred to in this fraction, in addition to those previously referred to in this paragraph, the passport or the documentation issued by the National Institute of Migration that accredits their migratory status will be considered as valid personal identification documents;
ii.
...
iii.
Proof of address, which may be any receipt for payment for home services such as, among others, electricity supply, telephone, natural gas, property tax, or water supply rights or bank statements, all of them with an age not greater than three months from their date of issuance, a valid lease contract on the date of presentation by the Client, a residence certificate issued by municipal authority, the proof of registration before the Federal Taxpayer Registry, as well as the others that, in their case, are approved by the Commission;
Notwithstanding the above, when the address declared in the contract celebrated by the Client with the Entity coincides with that of the Client's voter credential issued by a Mexican authority, in case they have been identified with the same, this will function as the proof of address referred to in the previous paragraph;
iv. and v. ...
II. ...
a)
and b) ...
c) Additionally, information must be collected from the Client that allows the Entity to know
(i)
their shareholding structure or social parts, as applicable, and (ii) in case the same has a Risk Grade other than low, their internal corporate structure; that is, the Client's legal person organizational chart, considering at least the full name and position of those individuals who occupy positions between general manager and the immediate lower hierarchy, as well as the full name and corresponding position of the members of their board of directors or equivalent.
Likewise, Entities must identify the Beneficial Owners of their legal person Clients who exercise Control over them in terms of the second paragraph of fraction VI of the 2nd of these General Provisions, in accordance with what is established in fraction VI of this Provision.
When there is no natural person who owns or controls, directly or indirectly, a percentage equal to or greater than 25% of the capital or voting rights of the legal person in question, or who by other means exercises Control, direct or indirect, over the legal person, it will be understood that the administrator or administrators thereof exercise such Control, understanding that the natural person designated for such effect exercises administration.
When the designated administrator is a legal person or Trust, it will be understood that Control is exercised by the natural person appointed by the administrator of the legal person or Trust.
For such purposes, Entities must collect a declaration signed by the legal representative of the legal person Client in question, in which it is indicated who their Beneficial Owners are in terms of this subsection.
In case Entities have indications that make the truthfulness of the declared information questionable, Entities must take reasonable measures to determine and identify the Beneficial Owners of the corresponding legal person Client.
III. ...
a)
...
b)
...
...
i.
Document that credibly proves its legal existence, document in which the tax identification number and/or equivalent is stated, issued by competent authority, as well as obtaining the information and collecting the data referred to in subsection c) of fraction II of this Provision;
ii.
and iii. ...
IV.
...
...
...
Entities may apply the simplified measures referred to in this fraction, provided that the aforementioned societies, dependencies, and entities have been classified as Clients with a low Risk Grade in terms of the 27th of these General Provisions;
V. ...
VI.
Regarding Beneficial Owners and that Entities are obligated to identify them in accordance with these General Provisions, they must record and collect in the respective Client identification file the same data and documents as those established in fractions I or III of this Provision, as applicable, with the exception of the document referred to in numeral iii of subsection b), of fraction I, as well as numeral ii of the second paragraph of subsection b), of fraction III of the 4th of these General Provisions, respectively, in case the obligation to identify the Beneficial Owner derives from a Client that is classified with a low Risk Grade. This, in accordance with the measures that for such purposes are established in the document referred to in the 67th of these General Provisions, or in another document or manual elaborated by the Entities themselves.
In case of legal persons whose representative titles of their social capital or securities representing such shares trade on any stock exchange in the country or in foreign securities markets recognized as such in terms of the General Provisions applicable to stock exchanges published in the Official Journal of the Federation on May 30, 2014, and their respective modifications, as well as those subsidiaries in which they have a majority participation of fifty percent in their social capital, Entities will not be obligated to collect the aforementioned identification data, considering that they are subject to provisions in matters of stock exchange disclosure of information.
The Ministry will issue the guidelines that Entities may consider for compliance with what is provided in the first paragraph of this fraction, which will be made known through the electronic means established for such effect by the Commission;
VII. and VIII.
...
IX. ...
a) ...
i. to vi. ...
vii.
Regarding settlors, trustees, fiduciary delegates, and, in their case, members of the technical committee or equivalent governing body, legal representatives, and legal agents, identification data must be collected in the terms referred to in this Provision, as applicable. Without prejudice to the above, Entities may comply with the obligation to collect data relating to members of the Technical Committee or equivalent governing body, indicating only the first and last names, without abbreviations, as well as their date of birth.
b)
...
...
...
...
Entities that carry out Operations with Trusts regarding which they do not act as trustees, may comply with the obligation (a) to collect the document referred to the
numeral i of subsection b) of this fraction, and (b) to that referred to in fraction VI of this Provision, respectively, through a certificate signed by the trustee delegate and the Compliance Officer of the institution or society acting as trustee, which must contain the information indicated in subsection a) above, as well as the obligation to keep such documentation available to the Secretariat and the Commission, in order to remit it, upon request by the latter, within the timeframe established by the Commission itself.
...
Additionally to what is provided in the previous paragraph, Entities must contractually agree with commissionaires mechanisms so that they can verify that the files are integrated in accordance with what is stated in these Provisions. In any case, the Entities will be responsible for compliance with the obligations regarding Customer identification established by these Provisions, to which effect, they must establish in the document referred to in the 67th of the cited Provisions, the mechanisms they will adopt to comply with what is stated in the previous paragraph.
...
...
...
...
18th.- ...
I.
...
a)
The full trade name or corporate name of the Client or User who ordered the transfer in question, or their paternal surname, maternal surname, and name(s), without abbreviations, number or reference of the Trust, as applicable;
b)
The address of said Client or User, which should only be included when the systems through which data transmission takes place allow including that information in a specific field for that purpose;
c) and d) ...
Paragraph repealed.
II.
Regarding Users, in the case where Entities act as ordering parties of fund transfers, either within national territory or to abroad, or when said Users are Recipients of transfers coming directly from an entity located in national territory or abroad, or through a money transmitter, referred to in Article 95 Bis of the General Law of Credit Auxiliary Organizations and Activities, said Entities must collect their paternal surname, maternal surname, and name(s) without abbreviations, the full trade name or corporate name or number or reference of the Trust, as applicable. Likewise, the receiving Entity must collect the reference number assigned by the ordering Entity to the transfer to identify it individually and the account number or reference number of the Entity, money transmitter, or Obligated Subject from which the funds of the transfer originate.
Likewise, said Entities must adhere to the following:
a)
When the sending or receipt of funds is for an amount equal to or greater than the equivalent in national currency to one thousand dollars and less than three thousand United States dollars or its equivalent in the foreign currency in which it is made, Entities must collect and preserve from the ordering User or Recipient of the funds, the following data at the time of carrying out said Operation, which must be obtained, when applicable, from an official identification referred to in the 4th of these Provisions:
i)
In case the User is an individual:
Paternal surname, maternal surname, and name(s) without abbreviations;
Country of birth;
Date of birth;
Nationality;
Home address (composed of the elements established for these effects in the 4th of these Provisions, as applicable to persons of Mexican or foreign nationality), and
Number of their official identification, which can only be one of those indicated in fraction I, subsection b), numeral i, of the 4th of these Provisions.
ii)
In case the User is a legal entity:
Trade name or corporate name;
Federal Taxpayer Registry Key (with homoclave) and, if applicable, tax identification number and/or equivalent, the country or countries that assigned them, as well as serial number of the Advanced Electronic Signature;
Address (composed of the data referred to in subsection a) above);
Nationality, and
The data of the person who attends the Entity on their behalf, under the same terms as those indicated in subsection a) above.
b)
When the sending or receipt of funds is for an amount equal to or greater than the equivalent in national currency to three thousand dollars and less than five thousand United States dollars, the Entity, in addition to collecting and preserving, at the time of carrying out said Operation, the data referred to in subsection a) above, must collect a copy of the official identification of the User in question.
c)
When the sending or receipt of funds is for an amount equal to or greater than the equivalent in national currency to five thousand United States dollars, the Entity must, at the time of carrying out said Operation, collect and preserve from said User, the data and documents referred to in fractions I, II, III, IV, VI, or IX of the 4th of these Provisions, as applicable.
III.
In the case where the Entity acts as the recipient of the fund transfer, it must collect the paternal surname, maternal surname, and name(s) without abbreviations, the full trade name or corporate name or reference number of the Trust, as applicable, from the individual, legal entity, or Trust that ordered said transfer, as well as the same data of the beneficiary of said transfer.
For the purposes of this Provision, Entities, whether acting as ordering or receiving parties of fund transfers, must load into the systems referred to in the 54th of these Provisions, the information and data indicated, on each of said Operations, and incorporate it into the alert system referred to in the 27th of these Provisions.
Entities must keep the respective information available to the Secretariat and the Commission, in order to remit it, upon request by the latter, within the timeframe established by the Commission itself.
19th.- When a User carries out any individual Operation in cash in national currency or in the foreign currency in question for an amount equal to or greater than five hundred United States dollars, or its equivalent in national currency or in the foreign currency in question, Entities, at the time of carrying out said Operation, must collect and preserve in the systems referred to in the 54th of these Provisions, the corresponding data, which must be obtained, when applicable, from an official identification referred to in the 4th of these Provisions, as follows:
I.
In case it is an individual:
a) to f) ...
II.
In case it is a legal entity:
a)
to e) ...
III.
In case it is a Trust, the data indicated in the 5th of these Provisions will be collected, as well as the data of the person who attends the Entity on their behalf, under the same terms as those indicated in the previous fraction I.
Likewise, in the event that the Operation referred to in this Provision is for an amount equal to or greater than three thousand dollars and less than five thousand United States dollars, or its equivalent in national currency or in the foreign currency in question, the Entity, in addition to collecting and preserving the data mentioned above, must integrate a copy of the official identification of the aforementioned persons.
In the event that the Operation referred to in this Provision is for an amount equal to or greater than five thousand United States dollars, or its equivalent in national currency or in the foreign currency in question, the Entity must collect and preserve in the aforementioned systems, the data and documents referred to in fractions I, II, III, IV, or IX of the 4th of these Provisions, as applicable.
...
20th.- ...
...
...
...
...
...
Entities must establish internal escalation mechanisms for approval when they receive foreign currency in cash at branches for amounts greater than the equivalent to seven thousand five hundred United States dollars or in national currency, for amounts greater than three hundred thousand pesos, for the realization of individual operations of purchase, receipt of deposits, receipt of payment of credits or services, and transfers or fund situations with their Clients or Users who are individuals. Entities must establish the same mechanisms when they receive from their Clients or Users who are legal entities or through Trusts, foreign currency in cash for amounts greater than the equivalent to fifty thousand United States dollars or national currency, for amounts greater than five hundred thousand pesos, for the realization of the referred operations.
...
23rd.-
Entities will verify that the identification files of their legal entity Clients, regardless of their Risk level, contain all the data and documents provided for in the 4th of these Provisions, as well as that said data and documents are updated, understanding that Entities may opt not to carry out the update of the latter, in case it is a legal entity Client with a Low Risk Level. The foregoing, under the terms and conditions that Entities establish in the document referred to in the 67th of the Provisions. Likewise, they will verify, at least once a year, that the identification files of their Clients classified as High Risk Level, are updated with all the data and documents provided for in the 4th, 30th, and 34th of these Provisions.
...
Entities must establish in the document referred to in the 67th of these Provisions, the policies, criteria, measures, and procedures they will adopt to comply with what is stated in this Provision, including the circumstances in which a visit to the domicile of Clients classified as High Risk Level must be carried out, with the object of properly integrating the files and/or updating the corresponding data and documents, in which case the results of such visit must be recorded in the respective file.
CHAPTER II BIS
RISK-BASED APPROACH
23rd-1.- Entities, under the terms provided for this effect in their policy, criteria, measures, and procedures documents referred to in the 67th of these Provisions, or in any other document or manual prepared by them, must establish a methodology, designed and implemented, to carry out a Risk assessment of the risks to which they are exposed derived from their products, services, practices, or technologies with which they operate. Said methodology must establish the processes for the identification, measurement, and mitigation of Risks, for which they must take into account, the Risk factors identified for this effect, as well as the national risk assessment and its updates that the Secretariat makes known to them through the Commission.
Regarding Entities that are part of financial groups in terms of the Law to Regulate Financial Groups, they must take into account the results of the methodology that, if applicable, have been implemented by the other financial entities that make up the corresponding group.
Likewise, Entities will carry out the processes referred to in the first paragraph of this Provision, prior to the launch or use of new products, services, practices, or technologies.
23rd-2.- Entities for the design of the Risk assessment methodology must comply with the following:
I. Consider in their identification process the indicators that explain how and to what extent the Entity can be found exposed to Risk, considering at least, the following elements: Clients, Users, countries and geographic areas, products, services, transactions, and sending channels linked to the Entity's Operations, with its Clients, and with its Users, as well as the national risk assessment and its updates that the Secretariat makes known to them through the Commission.
II. Use a method for the measurement of Risks that establishes a relationship between the indicators referred to in the previous fraction I and assign a weight to each of them consistently based on their importance to describe said Risks.
III. Establish the Mitigants considered necessary based on the indicators indicated in the previous fraction I, identified by each Entity to keep them at an acceptable tolerance level in conformity with their internal policy, criteria, measures, and procedures documents referred to in the 67th of these Provisions.
In the elaboration of the Risk assessment methodology, Entities must ensure that there are no inconsistencies between the information they incorporate into it and that which is in their automated systems.
23rd-3.- When, derived from the implementation of the Risk assessment methodology, the existence of greater or new Risks for the Entities themselves is detected, they must modify the policies and measures corresponding to mitigate them, as well as their Risk assessment methodology.
The compliance and results of the obligations contained in this Chapter must be reviewed and updated by Entities every twelve months, be recorded in writing, and be available to the Secretariat and to the Commission, upon request by the latter, within the timeframe established by the Commission itself.
The Commission may review and, if applicable, order Entities to modify their Risk assessment methodology or their Mitigants, among other circumstances, when they do not consider a proper Risk administration in the procedure and criterion(s) for the determination of the opening, limitation, and/or termination of a commercial relationship with Clients or Users, which must be congruent with said methodology, as well as request an action plan so that they adopt reinforced measures to manage and mitigate their Risks.
Entities must conserve the information generated by virtue of this Chapter for a period of no less than five years and provide it to the Secretariat and to the Commission, upon request by the latter, within the timeframe established by the Commission itself.
23rd-4.- Entities must comply with all the obligations contained in these Provisions, in concordance with the results generated by their methodologies referred to in this Chapter.
23rd-5.- The Commission will elaborate guidelines, guides, and/or best practices that Entities will consider for the better compliance with what is provided in this Chapter, which will be made known through the electronic means established by the same.
25th.- ...
I.
The policies, procedures, and controls to mitigate Risks, which must be in accordance with the results of the implementation of the methodology referred to in Chapter II Bis;
I. Bis.
Procedures for the Entity to follow up on Operations carried out by its Users and Clients, as well as on their capital contributions;
II. to V.
...
27th.- The application of the Customer knowledge policy must be based on the Risk Level that a Client represents, such that, when the Risk Level is greater, the Entity must collect more information about their predominant activity, as well as carry out stricter supervision of their transactional behavior.
...
...
Likewise, Entities must classify their Clients by their Risk Level and establish, at minimum, (i) two classifications regarding their individual Clients: High and Low Risk Levels, and (ii) three classifications regarding their legal entity Clients and Trusts: High, Medium, and Low Risk Levels. Entities may establish additional intermediate Risk Levels to the classifications mentioned above.
With the purpose of determining the Risk Level in which Clients should be located at the beginning of the commercial relationship, Entities must consider the information provided by them at the time of account opening or celebration of the respective contract. Additionally, Entities must carry out, at least, two evaluations per calendar year, in order to determine if it is necessary or not to modify the initial transactional profile of their Clients, as well as to classify them in a Risk Level different from the initially considered. The evaluations will be carried out on those Clients whose account opening or contract celebration was carried out at least six months in advance to the corresponding evaluation.
Entities, under the terms provided for this effect in their internal policy, criteria, measures, and procedures documents referred to in the 67th of these Provisions, will apply to their Clients who have been cataloged as High Risk Level, as well as to new Clients who meet such character, identification questionnaires that allow obtaining more information about the origin and destination of resources and the activities and Operations they carry out or intend to carry out.
To determine the Risk Level in which Clients should be located, as well as whether they should be considered Politically Exposed Persons, each Entity will establish in the documents indicated in the previous paragraph the criteria conducive to that end, which take into account, among other aspects, the Client's background, their profession, activity, or business sector, the origin and destination of their resources, the place of their residence, the methodology referred to in Chapter II Bis of these Provisions, and the other circumstances determined by the Entity itself.
28th.- For cases where, prior to or subsequent to the start of the commercial relationship, an Entity detects that the person who intends to be a Client or who already is, as applicable, meets the requirements to be considered a Politically Exposed Person and, additionally, as a High Risk Level, said Entity must, according to what is established for this effect in its internal policy, criteria, measures, and procedures document referred to in the 67th of the same, obtain the approval of one of the persons referred to in the 29th of the same, to effectuate the Operation in question.
30th.- Entities must classify their Clients based on their Risk Level.
Foreign Politically Exposed Persons will be considered at least as High Risk Level Clients. Regarding the latter, Entities must collect the information that allows them to know and record the reasons why these have chosen to open an account in national territory.
In the Operations carried out by Clients who have been classified as High Risk Level, Entities will adopt measures to know the origin of resources and will seek to obtain the data indicated in Chapter II of these Provisions, under the terms provided for this effect in their internal policy, criteria, measures, and procedures documents referred to in the 67th of these Provisions, or in any other document or manual prepared by them, regarding the spouse and economic dependents of the Client, as well as the societies and associations with which they maintain patrimonial links for the case of individuals, and, regarding legal entities, their main shareholders or partners, as applicable, while in the case of Trusts, they will seek to collect the same data regarding the spouse and economic dependents of the settlors and beneficiaries who are individuals, as well as the societies and associations with which they maintain patrimonial links, and, regarding settlors and beneficiaries who are legal entities, their corporate structure and their main shareholders or partners, under the terms provided for this effect in their internal policy, criteria, measures, and procedures documents referred to in the 67th of these Provisions, or in any other document or manual prepared by them. Regarding Foreign Politically Exposed Persons, Entities must obtain, in addition to the reference data, the documentation indicated in Chapter II of these Provisions, regarding the aforementioned individuals and legal entities in this paragraph.
Without prejudice to the foregoing, regarding legal entity Clients whose share certificates representing their social capital or securities representing said shares trade on any stock exchange in the country or in foreign securities markets recognized as such in terms of the general provisions applicable to stock exchanges published in the Official Journal of the Federation on May 30, 2014, and their respective modifications, as well as those subsidiaries in which they have a majority participation of fifty percent in their social capital, Entities will not be obligated to collect the aforementioned identification data, considering that they are subject to provisions in matters of stock exchange on information disclosure.
...
31st.- Without prejudice to what other applicable provisions establish, for the provision of correspondent services to foreign counterparts related to their object, Entities must consider the Risks and approve, at the executive level, the relationship that allows initiating said provision, and for this, they will document the measures and procedures that their counterparts observe in matters of prevention of operations with proceeds of illicit origin and financing of terrorism, in accordance with the regulations applicable to them in their corresponding jurisdiction.
...
34th.- ...
I.
In the case of commercial legal entity Clients who are classified as High Risk Level, information relative to the name, nationality, address, corporate object, and social capital of the legal entities that make up the business group or, in its case, the business groups that make up the consortium of which the Client is part, must be requested.
Paragraph repealed.
...
II.
Regarding legal entities with the character of societies or civil associations that are classified as High Risk Level, identify the person or persons who have Control over such societies or associations, and
III.
...
Paragraph Repealed.
37th.- ...
...
...
...
With respect to any Operation referred to in this Provision, carried out for an amount equal to or greater than seven thousand five hundred United States dollars, the Entity in question shall not be obligated to present the report indicated in the 36th of these Provisions.
40th.- For each Unusual Operation detected by an Entity, it must send the corresponding report to the Secretariat, through the Commission, within three business days following the conclusion of the Committee session that rules it as such. For the purpose of carrying out said ruling, the Entity, through its Committee, shall have a period not exceeding sixty calendar days counted from when the alert is generated by its system, model, process, or by an employee of the Entity, whichever occurs first.
...
41st.- ...
I. to III. ...
IV.
Operations carried out in the same account, as well as those carried out by the same User with foreign currency, traveler's checks, cashier's checks, and minted coins in platinum, gold, and silver, for multiple or fractional amounts that, for each individual Operation, are equal to or exceed the equivalent of five hundred United States dollars, carried out in the same calendar month that sum to at least seven thousand five hundred United States dollars or its equivalent in the currency in question, provided that they do not correspond to the Client's transactional profile or, with respect to those carried out by Users, it can be inferred from their structuring a possible intention to fraction the Operations to avoid being detected by the Entities for the purposes of these Provisions;
V. to XIV.
...
...
...
...
44th.- In the event that an Entity has information based on indications or concrete facts that, when attempting to carry out an Operation, the resources could originate from illicit activities or could be destined to favor, provide help, assistance, or cooperation of any kind for the commission of the crime provided for in Article 139 Quater of the Federal Penal Code, or that they could fall under the circumstances of Article 400 Bis of the same legal code, that same Entity, in the event that it decides to accept said Operation, must send to the Secretariat, through the Commission, within 24 hours counted from when it becomes aware of said information, a report of Unusual Operation, in which, in the column of description of the Operation, the legend "24-hour Report" must be inserted. Likewise, in those cases where the respective Client or User does not carry out the Operation referred to in this paragraph, the Entity must present to the Secretariat, through the Commission, the report of Unusual Operation under the terms indicated in this Provision and, with respect to said Users, it will provide, if applicable, all information known about them.
...
...
...
45th.- For each Internal Suspicious Operation detected by an Entity, it must send the corresponding report to the Secretariat, through the Commission, within three business days following the conclusion of the Committee session that rules it as such. For the purpose of carrying out said ruling, the Entity, through its Committee, shall have a period not exceeding sixty calendar days counted from when said Entity detects that Operation, by means of its system, model, process, or by any employee thereof, whichever occurs first.
To this effect, Entities must send the reports referred to in this Provision, through electronic means and in the official format issued for such effect by the Secretariat, in accordance with the terms and specifications indicated by the latter.
...
46th.- ...
I. ...
I. Bis. Submit to the approval of the Board of Directors of the Entity, the methodology developed and implemented to carry out the Risk evaluation referred to in the previous Chapter II Bis, as well as the results of its implementation;
II.
Act as the competent instance to know the results obtained by the internal audit area of the Entity or, if applicable, by the independent external auditor referred to in the 62nd of these Provisions, regarding the valuation of the effectiveness of the policies, criteria, measures, and procedures contained in the documents indicated in fraction I of this Provision, in order to adopt the necessary actions aimed at correcting flaws, deficiencies, or omissions;
III. ...
IV.
Establish and disseminate the criteria for the classification of Clients, based on their Degree of Risk, in accordance with what is indicated in the 27th of these Provisions;
V. to VII. ...
VIII. Inform the competent area of the Entity, regarding conduct carried out by executives, officials, employees, or agents thereof, that cause it to incur a violation of what is provided in these Provisions, or in cases where said executives, officials, employees, or agents contravene what is provided in the policies, criteria, measures, and procedures indicated in fraction I of this Provision, in order to impose the corresponding disciplinary measures;
IX.
Resolve other matters submitted to its consideration, related to the application of these Provisions, and
X. Ensure that the Entity, for the compliance with these Provisions, has the internal structures referred to in this Chapter, regarding organization, number of people, material and technological resources, in accordance with the results of the implementation of the methodology referred to in the previous Chapter II Bis.
...
47th.- Each Entity will determine the way in which its Committee will operate, which, except for what is indicated in the last paragraph of this Provision, shall be integrated with at least three members who, in any case, must hold the positions of the areas designated for such effect by the Board of Directors of said Entity and, in any case, members of that Board, the General Director, employees, or officials who hold positions within the three immediate lower hierarchies below that of the General Director of the Entity in question must participate.
Paragraph repealed.
...
...
The permanent members of the Committee must attend its sessions and may designate their respective substitutes, who may only represent them in two non-consecutive sessions per semester.
The Committee shall have a president and a secretary, who shall be designated from among its members. Said Committee shall meet with a frequency of at least once every month of the year. For the sessions to be held validly, it will be required that the majority of the members of the Committee itself be present.
Entities that have fewer than twenty-five people at their service, whether they perform functions for the same directly or indirectly through complementary service companies, shall not be obligated to constitute and maintain the Committee referred to in this Provision. In the case provided for in this paragraph, the functions and obligations that should correspond to the Committee in accordance with what is indicated in these Provisions, shall be exercised by the Compliance Officer.
49th.- ...
Likewise, each Entity must communicate to the Secretariat, through the Commission, through the means referred to in the preceding paragraph, the appointment, addition, or substitution of the members of the Committee, within fifteen business days following the date on which it was carried out. For these purposes, the following information must be provided:
I.- The name of the areas whose holders have been designated in addition or substitution to those that are part of the Committee, as well as the first and last names without abbreviations of said holders and first and last names without abbreviations and position of their substitutes;
II.- The date of the corresponding modification, and
III.
...
50th.- The Board of Directors or the Committee of each Entity shall designate, from among the members of said Committee, an official who shall be called "Compliance Officer".
In the event that the Entity does not have a Committee because it falls under the circumstance referred to in the last paragraph of the 47th of the Provisions, the Compliance Officer shall be designated by its Board of Directors, who must meet the requirements to be a member of the Committee, in terms of the aforementioned Provision.
In any case, the Compliance Officer must be an official who holds a position within the three immediate lower hierarchies below that of the General Director of the Entity in question, and who will perform, at least, the functions and obligations established below:
I.
Develop and submit to the consideration of the Committee the document referred to in the 67th of these Provisions, which contains the policies for identification and knowledge of the Client and the User, and the criteria, measures, and procedures that must be adopted to comply with what is provided in these Provisions;
I. Bis.
Present to the Committee the methodology developed and implemented to carry out the Risk evaluation referred to in the previous Chapter II Bis, as well as the results of its implementation;
II.
Verify the correct execution of the measures adopted by the Committee, in exercise of the powers provided in the 46th of these Provisions;
III.
Inform the Committee regarding conduct, activities, or behaviors carried out by the executives, officials, employees, or agents of the Entity, that cause it to incur a violation of what is provided in the Law or these Provisions, as well as cases where said executives, officials, employees, or agents contravene what is provided in the document indicated in fraction I of this Provision, in order to impose the corresponding disciplinary measures;
IV.
Make known to the Committee the celebration of contracts or opening of accounts in the Entity in question, whose characteristics could generate a high Risk for the Entity itself;
V.
Coordinate both the follow-up activities of Operations, as well as the investigations that must be carried out at the institutional level, in order for the Committee to have the necessary elements to rule them, if applicable, as Unusual Operations or Internal Suspicious Operations.
For the effects indicated in the preceding paragraph, the area in charge of the Compliance Officer of each Entity or, if applicable, the personnel designated by him, will verify that the corresponding alerts have been analyzed and the respective investigations documented;
VI.
Send to the Secretariat, through the Commission, the reports of Operations referred to in the 44th of these Provisions, as well as those considered urgent, and inform thereof to the Committee, in its next session;
VII.
Act as a consultation instance within the Entity regarding the application of these Provisions, as well as of the document referred to in the 67th of the same;
VIII.
Define the characteristics, content, and scope of the training programs for the Entity's personnel, referred to in the 52nd of these Provisions;
IX.
Receive and verify that the Entity gives a response, in terms of the applicable legal provisions, to the requests for information and documentation, as well as to the orders for securing or unlocking of accounts that, through the Commission, are formulated by the competent authorities in matters of prevention, investigation, prosecution, and sanction of conduct that could update the circumstances provided for in Articles 139 Quater or 400 Bis of the Federal Penal Code, likewise, verify that the Entity has appropriate procedures to ensure that it complies with what is provided in the 75th of these Provisions;
X.
Act as a link between the Committee, the Secretariat, and the Commission, for matters regarding the application of these Provisions, and
XI.
Ensure that the area under its charge receives directly and follows up on notices issued by employees and officials of the Entity, regarding facts and acts that could be susceptible to being considered as Unusual Operations or Internal Suspicious Operations.
Likewise, the appointment of the Compliance Officer must fall upon an official who is independent of the Entity's units in charge of promoting or managing the financial products or services that it offers to its Clients or Users. In no case, the appointment of the Compliance Officer of an Entity may fall upon a person who has internal audit functions in the Entity.
...
...
50th Bis.- The Committee of each Entity or, its Board of Directors or General Director, shall appoint an official of the Entity who may temporarily substitute its Compliance Officer, in the fulfillment of its obligations in accordance with these Provisions, for up to ninety calendar days during a calendar year, counted from when the official designated as Compliance Officer leaves, is revoked, or is unable to perform the assignment in question.
The Entity official who performs the aforementioned interim position must not have internal audit functions in the same.
Entities may make effective the interim period referred to in this Provision, in accordance with the needs of each Entity.
The Compliance Officer who is designated as interim must comply with the functions and obligations indicated in these Provisions, until the moment when the revocation indicated in fraction II of the 51st of these Provisions is reported.
51st.- The Entity must inform the Secretariat, through the Commission, through electronic means and in the official format issued for such effect by said Secretariat, in accordance with the terms and specifications that the latter indicates, the following:
I. The first and last names without abbreviations of the official who has been designated as Compliance Officer, as well as the other information provided in the indicated format, within two business days following the date on which the corresponding appointment was made;
II. The revocation of the appointment of the Compliance Officer, on the next business day following the date on which it occurred, whether by determination of the Entity, rejection of the assignment, or termination of labor or impossibility, as well as the other information provided in the indicated format, and
III. The first and last names without abbreviations of the official who has been designated as Compliance Officer in terms of what is established in the 50th Bis of these Provisions, as well as the other information provided in the indicated format, on the next business day following the date on which it occurred.
52nd.- ...
I.
The provision of courses, at least once a year, which must be directed especially to the members of their respective Boards of Directors, executives, officials, and employees, including those who work in customer service or resource administration areas, and which contemplate, among other aspects, those related to the content of their policy documents, criteria, measures, and procedures referred to in the 67th of these Provisions, which the Entity has developed for the due compliance with them, as well as on the activities, products, and services offered by the Entity.
Without prejudice to what is indicated in the preceding paragraph, the topics of the training must be coherent with the results of the implementation of the methodology referred to in Chapter II Bis and must adapt to the responsibilities of the members of their respective Boards of Directors, executives, officials, and employees, and
II.
...
...
54th.- ...
I. to III.
...
IV.
Detect and monitor Operations carried out in the same account or by the same Client or User indicated in the 18th, 19th, 20th, 21st, and 22nd of these Provisions, as well as those provided for in fraction IV of the 41st of these Provisions;
V. to VIII. ...
IX.
Maintain information security schemes for processed information, which guarantee its integrity, availability, auditability, and confidentiality;
IX. Bis.
Provide the information that Entities will include in the methodology they must develop in accordance with what is established in the 23rd-1 of these Provisions, and
X.
...
55th.- Members of the Board of Directors, the Committee, the Compliance Officer, as well as executives, officials, employees, and agents of the Entities, must maintain absolute confidentiality regarding information related to the reports provided for in these Provisions, except when requested by the Secretariat, through the Commission, and other authorities expressly empowered to do so or in the cases provided for in Chapter XIV of these Provisions.
...
62nd.- Entities must maintain control measures that include review by the internal audit area, or by an independent external auditor, to evaluate and rule from January to December of each year, or with respect to the period resulting from the date on which the Commission authorizes the start of operations of the Entity in question to December of the respective year, the effectiveness of compliance with these Provisions, in accordance with the guidelines issued for such effects by the Commission. The results of said reviews must be presented to the General Management and the Committee of the Entity, as a report, in order to evaluate the operational effectiveness of the implemented measures and to follow up on corrective action programs that may be applicable. In the aforementioned valuation exercise, no member of the Entity's Committee may participate.
With respect to Entities that are part of financial groups in terms of the Law to Regulate Financial Aggregations, they must take into account the reviews referred to in the first paragraph of this Provision that, if applicable, have been carried out by the other financial entities that make up the corresponding group.
The information referred to in this Provision must be preserved by the Entity for a period of no less than five years, and sent to the Commission within sixty calendar days following the closing of the exercise to which the review corresponds, in the electronic means indicated by the latter.
63rd.- In order to carry out the exchange of information referred to in the ninth paragraph of Article 45 Bis of the Law and 113 of the Law to Regulate Financial Aggregations, Entities shall be subject to what is provided in this Chapter.
64th.- ...
The exchange of information shall be carried out in the terms and under the conditions indicated in Provision 64th Bis, or as the case may be, in accordance with the following:
I. to III. ...
IV.
The information provided in terms of what is indicated in this Provision may only be used by the Entity that requested it, unless it is established in the response writing that it is information that can in turn be shared with other Entities, and
V. ...
When an Entity shares with another or other Entities the information referred to in this Provision, the former must preserve all supporting documentation, which must be available to the Secretariat and the Commission, upon request of the latter, within the timeframe established by the Commission itself.
64th Bis.- Entities that are part of financial groups in terms of the Law to Regulate Financial Aggregations may exchange any type of information regarding the Operations they carry out with their Clients and Users, with other financial entities that are part of the same group that are authorized to do so in accordance with applicable provisions, in matters of prevention of operations with resources of illicit origin and financing of terrorism, provided that they celebrate an agreement among themselves in which they stipulate the following:
a) The confidential treatment that will be given to the exchanged information, and
b) The positions of the officials authorized to carry out the aforementioned exchange.
Prior to the exchange of information being carried out, Entities must inform the Commission about the signing of the agreement referred to in this Provision, in the official format issued for such effects by it and through the means it establishes.
When an Entity shares with another or other financial entities that are part of the same financial group the information referred to in this Provision, the former must preserve all supporting documentation, which must be available to the Secretariat and the Commission, upon request of the latter, within the timeframe established by the Commission itself.
65th.- ...
...
In the case where the Entity hires foreign commission agents, in addition to what is established in the preceding paragraph, it must take into account the available information on the Risk level of the country where said commission agent operates.
67th.- Each Entity must develop and send to the Commission, through the electronic means indicated by it, a document in which said Entity develops its respective policies for identification and knowledge of the Client and the User, as well as the internal criteria, measures, and procedures that it must adopt to comply with what is provided in these Provisions, and to manage the Risks to which it is exposed in accordance with the results of the implementation of the methodology referred to in Chapter II Bis of these Provisions.
If applicable, in said document, references to those criteria, measures, internal procedures, and other information that, by virtue of what is provided in these Provisions, may be reflected in a document different from the aforementioned one, must also be included.
In any of the documents provided for in the preceding paragraph, the methodology referred to in Chapter II Bis of these Provisions must be included. Likewise, the procedure and criterion(s) for the determination of the opening, limitation, and/or termination of a commercial relationship with Clients or Users, which must be congruent with said methodology, must be included.
Entities must send to the Commission the modifications they make to the document referred to in the
first paragraph of this Provision together with a complete copy thereof, within the twenty business days following the date on which their respective audit committee approves them, in accordance with the terms provided in fraction I of the 46th of these Provisions.
...
...
...
...
...
...
...
...
72nd.- The Secretariat may interpret, for administrative purposes, the content of these Provisions, as well as determine the scope of their application, whenever so requested by the Institutions, associations or societies in which they are affiliated, self-regulatory bodies referred to in the Law, and national authorities that require it for the fulfillment of their functions, for which it will hear the opinion of the Commission.
72nd-1.- In order to be able to comply with what is established in these Provisions, the Institutions will request from the Commission the key to be used to access the electronic system that the Commission establishes for such purposes, and must have it at the time of starting operations.
78th.- The Secretariat may authorize, without prejudice to what is established in this chapter, access to certain resources, rights or assets, as well as acts, Operations or services, in accordance with the following:
I.
To Clients or Users who are located within the List of Blocked Persons, in terms of the international treaties celebrated by the Mexican State, in terms of resolution 1452 (2002) of the Security Council of the United Nations Organization, and
II.
To the Institutions, with respect to the obligations they have with some Client or User contracted with some Institution, among others, in accordance with the guidelines, guidelines or best practices that the Secretariat makes known for such purposes.
TRANSITIONAL PROVISIONS
First.- This Resolution will enter into force the day after its publication in the Official Gazette of the Federation.
Second.- The guidelines, interpretations and criteria issued by the Secretariat or by the Commission, based on the provisions of the general provisions referred to in Article 124 of the Savings and Popular Credit Law, published in the Official Gazette of the Federation on December 31, 2014, will continue to be applicable insofar as they do not oppose what is established in this Resolution.
Third.- The Institutions to which authorization is granted to constitute and operate as such on a date subsequent to the entry into force of this Resolution, must comply with the obligations contained in these Provisions, in the terms and in accordance with the deadlines set forth below:
I. Ninety calendar days counted from the date of authorization, to present to the Commission the document referred to in the 67th of these Provisions.
II. Sixty business days counted from the date of commencement of their operations to carry out the appointments referred to in the 47th and the 50th of these Provisions, informing thereof to the Commission, within the aforementioned period.
Fourth.- The Institutions that are in operation at the time of the entry into force of this Resolution, will have a period that may not exceed forty-five calendar days counted from the entry into force of this Resolution, in order to prepare a work schedule in which they must establish activities, deadlines and responsibilities, so that at the latest within the three hundred sixty calendar days following the entry into force of this Resolution, (i) they have updated the automated systems referred to in the 54th of these Provisions; (ii) begin to collect the corresponding information in accordance with the obligations established in this Resolution, as well as introduce it into the aforementioned automated systems, as appropriate, with respect to those accounts that are opened or Operations that are celebrated from the time this period expires; (iii) present to the Commission the document referred to in the 67th of these Provisions with the respective modifications, and (iv) comply with the other obligations established in the Resolution in question.
Fifth.- The obligation referred to in the 23rd of these Provisions, will apply with respect to all Client corporate persons of the Institutions regardless of whether the commercial relationship with them had begun prior to the entry into force of this Resolution.
Sixth.- The Institutions will comply with the modifications provided for in the 4th of these Provisions, insofar as including in the Client identification file the proof of address, with respect to those accounts that are opened or Operations that are celebrated from July 1, 2017.
Seventh.- The Secretariat, prior to the opinion of the Financial Intelligence Unit, will make known to the Institutions through the electronic means established by the Commission, the guidelines referred to in fraction VI of the 4th of the Provisions, within the ninety calendar days following the entry into force of this Resolution.
Eighth.- The Secretariat will make known to the Institutions the guidelines, guidelines or best practices referred to in fraction II of the 78th of the Provisions, within the two hundred forty calendar days following the entry into force of this Resolution.
Ninth.- The Commission will make known to the Institutions through the electronic means it establishes, the guidelines, guidelines and/or best practices referred to in the 23rd-5 of the Provisions, within the ninety calendar days following the entry into force of this Resolution.
The Institutions must comply with the obligations derived from the implementation of Chapter II Bis of the Provisions, added by this Resolution, at the latest within the four hundred fifty calendar days counted from when this Resolution enters into force.
Tenth.- The obligation to communicate to the Secretariat, through the Commission, the modifications to the internal structures referred to in the 49th and 51st of these Provisions reformed by this Resolution, will enter into force from the time the Secretariat makes known the electronic means and the official format that for such effect issues said Secretariat.
Mexico City, March 13, 2017. - The Secretary of Finance and Public Credit, José Antonio Meade Kuribreña .- Rubric.
In the document you are viewing, there may be text, characters or objects that are not displayed correctly due to conversion to HTML format, so we recommend always taking as reference the digitized image of the DOF or the PDF file of the edition. The content, form and scope of the published documents are the strict responsibility of their issuer.
CONSULT
BY DATE
Do Lu Ma Mi Ju Vi Sá INDICATORS
Exchange Rate and Rates as of 31/08/2026
DOLLAR 17.0427 UDIS
8.810483 TIIE 28 DAYS
6.7659% TIIE 91 DAYS
6.8033% TIIE 182 DAYS
6.8577% TIIE DE FONDEO
6.51%
See more
SURVEYS
Did you like the new image of the Official Gazette of the Federation website?
No
Yes
Official Gazette of the Federation
Río Amazonas No. 62, Col. Cuauhtémoc, C.P. 06500, Mexico City Tel. (55) 5093-3200, where you can access our menu of services
Electronic address: dof.gob.mx
113
LEGAL NOTICE | SOME RIGHTS RESERVED © 2026