2024-07-11 | DOF 5732991

Added

Resolution modifying the General Provisions applicable to credit institutions

The National Banking and Securities Commission establishes a new regulatory framework for 'technology-based agents' (comisionistas de base tecnológica), allowing credit institutions to contract with third parties to offer specific banking services via digital channels such as websites and applications. The resolution defines permitted operations, including level 2 account opening, credits up to 3,000 UDIs, bill payments, and balance inquiries, while imposing strict security requirements such as session timeouts of five minutes inactivity or twenty minutes total duration. It mandates that authentication processes remain under the exclusive responsibility of the credit institution and prohibits technology-based agents from accessing, processing, or storing client authentication factors.

Secretaria de Hacienda y Credito Publico logo

Mexico

Secretaria de Hacienda y Credito Publico

Click to view thumbnail

DOF: 11/07/2024

RESOLUTION modifying the General Provisions applicable to credit institutions

With a seal apart bearing the National Coat of Arms, which says: United Mexican States.- TREASURY.- Ministry of Finance and Public Credit.- National Banking and Securities Commission.

The National Banking and Securities Commission, prior agreement of its Board of Directors,

on the basis of what is provided by articles 46 Bis 1; 46 Bis 2; 52, eighth paragraph; 96 Bis, first paragraph and 98 Bis of the Credit Institutions Law, as well as 4, sections XXXVI and XXXVIII; 12, section XV and 16, sections I and VI of the Law of the National Banking and Securities Commission, and

CONSIDERING

That, in accordance with article 78 of the General Law for Regulatory Improvement and with the purpose of reducing the compliance cost of these provisions, the National Banking and Securities Commission, through the issuance of the "Resolution modifying the General Provisions applicable to general warehouses, exchange houses, credit unions and multiple-object financial companies regulated" published in the Official Journal of the Federation on April 26, 2018, adjudicated by the National Commission for Regulatory Improvement through letter COFEME/18/0413, contained in file 05/0006/ 020218 eliminated the obligation for credit unions to have an opinion on the receipt of loans from members and recognition of joint liability;

That, the General Provisions applicable to credit institutions establish the possibility that said institutions enter into commission contracts with third parties who act in their name to offer and carry out banking operations in the establishments of said latter parties, which they do through operators who interact in person with the user public;

That, the network of commissioners has allowed the geographic expansion coverage of the Mexican Financial System, being present in 75% of the municipalities in the country, which exceeds the coverage of both bank branches and automated teller machines;

That, since the coverage of telecommunications networks is greater than that of the physical establishments of the commissioners, it is convenient that credit institutions, especially those that do not possess physical infrastructure or Internet applications, integrate their services into the digital platforms of the commissioners and specialized companies, taking advantage of the infrastructure of these and even the consolidated customer base of the same. The foregoing, it is estimated that it mitigates some of the difficulties presented by the face-to-face channels such as the risk and cost associated with the use of cash, and the cost that represents for the user to travel to the establishments;

That, likewise, the Mexican financial authorities have issued diverse regulation that allows credit institutions (i) to offer their services and products outside their branches by taking advantage of the technology available in the markets, and (ii) to mitigate the risks to which they are exposed, with the purpose of maintaining and fostering the sound and balanced development of the Mexican Financial System as a whole, in protection of the interests of the public;

That, for all the above, the present "Resolution modifying the General Provisions applicable to credit institutions" regulates the figure of the technology-based commissioner and seeks to allow credit institutions to contract with commissioners, allowing them to offer and carry out, on behalf of said institutions, to the general public some banking services and products through digital access channels in order to expand access to them among the public. In addition to the above, said Resolution also seeks to establish, among others, the contractual obligations and responsibilities that credit institutions have with said commissioners, and

That, in order to mitigate identity theft, the exclusive responsibility of credit institutions is established in the process for authenticating client operations, as well as the establishment of a secure communication channel between them, to execute client instructions, has resolved to issue the following:

RESOLUTION MODIFYING THE GENERAL PROVISIONS APPLICABLE TO CREDIT INSTITUTIONS

UNIQUE.

  • REFORMED are articles 1, sections XXXI and LXXXIII; 318, first paragraph, sections I, second paragraph, II, first paragraph, III, first paragraph, subsection a), numeral 3, subsection b), first paragraph, numerals 1, 3 and 6, and VI; 320, paragraphs first and third; 321, paragraphs first, section II and second; 321 Bis 1, paragraphs first and third; 324 first paragraph, sections VII, subsections a) in its first paragraph and g), XII and XIII, and second; ADDED to article 1 is section XLIV Bis; to article 318, first paragraph, section III, first paragraph, subsection a) numerals 6 and 7; articles 319 Bis; 319 Bis 1; 319 Bis 2; 319 Bis 3; 319 Bis 4; 319 Bis 5; 321 section III; 321 Bis 1 a second paragraph that incorporates sections I, II, III, IV, V, VI, VII, and VIII and to article 324, first paragraph, a section IV Bis ; to Title Five, Chapter XI, Second Section, the title of Subsection A named "Of commissioners with physical establishments", which comprises article 319; a Subsection B named "Of technology-based commissioners", which comprises articles 319 Bis to 319 Bis 5, and the title of Subsection C named "Complementary provisions", which comprises articles 320 to 325 , and SUBSTITUTED are Annexes 57, 58 and 59 of the "General Provisions applicable to credit institutions", published in the Official Journal of the Federation on December 2, 2005 and modified through resolutions published in the aforementioned dissemination medium, to remain as follows:

RESOLUTION MODIFYING THE GENERAL PROVISIONS APPLICABLE TO CREDIT INSTITUTIONS

INDEX

TITLE FIRST to FOURTH . . .

TITLE FIFTH . . .

Chapter I to X . . .

Chapter XI . . .

First Section . . .

Second Section . . .

Subsection A Of commissioners with physical establishments

Subsection B Of technology-based commissioners

Subsection C Complementary provisions

Second Section Bis to Fourth . . .

Chapter XII to XV . . . "

" Article 1.- . . .

I. to XXX. . . .

XXXI. Encryption: to the mechanism that Institutions and technology-based commissioners referred to in Subsection B of the Second Section, Chapter XI of Title Five of these Provisions must use to protect the confidentiality of information through cryptographic methods in which algorithms and encryption keys are used.

XXXII. to XLIV. . . .

XLIV Bis. Asymmetric Mathematical Cryptography: to the Encryption methods that employ a pair of encryption keys known as public key and private key, which are mathematically related in such a way that information Encrypted with one of the keys can only be decrypted with the associated key.

XLV. to LXXXII. . . .

LXXXIII. Technological Infrastructure: to computing equipment, data processing and communications installations, equipment and communications networks, operating systems, databases, applications and systems used by Institutions to support their operation. Likewise, it also refers to the computing equipment, data processing and communications installations, equipment and communications networks, operating systems, databases, applications and systems used by technology-based commissioners referred to in Subsection B of the Second Section, Chapter XI of Title Five of these Provisions to support the operation agreed upon between said commissioners and the Institutions.

LXXXIV. to CXCVII. . . . "

" TITLE FIFTH . . .

Chapter XI . . .

First Section . . .

Articles 317 and 317 Bis. - . . .

Article 318.- . . .

I. . . .

Likewise, in no case, said commissioners may carry out approvals and openings of active, passive and service operation accounts, unless it concerns operations provided for by Article 319, sections IX and X and Article 319 Bis of these provisions.

II. Have a report and flowchart that specify the operational or database and computer system administration processes, the information exchanged in said processes, the physical location of the Institution's servers and the technology-based commissioner, as well as the name, address and the contract that technology-based commissioners agree with third parties for the provision of on-demand computing services and technological infrastructure through the Internet to support their operation that are subject to the services to be contracted. Likewise, they must have the policies and criteria to select the third party, which will be oriented to evaluate the experience, technical capacity and human resources of the third party with whom the service is contracted with adequate levels of performance, reliability and security, as well as the effects that could occur in one or more operations carried out by the Institution.

. . .

. . .

III. . . .

a) . . .

  1. and 2. . . .

  2. Deliver, at the request of the Institution, to the external auditor of the Institution itself and to the Commission or to the third party designated by said Commission, books, control figures, information structures, reports, operation tests, records, manuals and documents in general that prove and take evidence regarding compliance with these provisions, related to the provision of the service or commission in question, which may be delivered digitally and signed with Advanced Electronic Signature or Reliable. Likewise, permit access to responsible personnel and their offices and installations in general, related to the provision of the service in question.

  3. and 5. . . .

  4. In the case of employees or officials of the commissioners referred to in Article 319 Bis, who are in charge of executing the processes agreed upon in the commercial commission contract with the Institution in question in terms of this Article and Articles 319 Bis to 319 Bis 5 of these Provisions, they must be identified by the technology-based commissioner in terms of Annex 58 of these Provisions. Likewise, Institutions must agree with the commissioners referred to in the previous paragraph, the written delivery of a document containing the following information, prior to operating with the User Public in order to identify them:

i. Full name without abbreviations.

ii. Employee number.

iii. The processes of which the employee or commissioner official will be in charge in relation to Articles 319 Bis to 319 Bis 5.

iv. Institutional email of the employee or official.

This document must be signed by the employee or commissioner official, for which they may use their Advanced Electronic Signature. Likewise, in the event that there is a change of the employee or commissioner official referred to in the first paragraph of this numeral, the commissioner must notify the Institution of said change within two business days that the corresponding designation has been made in the terms indicated in this numeral.

  1. Exchange client information with the corresponding Institution through a secure channel observing as a minimum the requirements provided for in Article 319 Bis 1 for those commissioners who appear before the User Public through their Internet pages or computer applications.

. . .

b) . . .

  1. The restrictions and conditions regarding the possibility that the third party subcontracts, in turn, the provision of the service. In no case, the foregoing, implies that the subcontracted third party may carry out Operations and functions on its own behalf or different from those agreed upon in the service provision or commission contract respective for purposes of what is provided for in this Chapter. Likewise, the third parties with whom Institutions contract cannot subcontract the services or commissions referred to in Article 319 Bis of these Provisions, except for the contracting of services corresponding to on-demand computing and technological infrastructure through the Internet to support their operation.

  2. . . .

  3. The mechanisms for the resolution of disputes relative to the service provision or commercial commission contract. In the same manner, it must provide for the mechanisms for the resolution of disputes relative to the contract between the commissioner and a subcontracted third party.

  4. and 5. . . .

  5. The terms, conditions and processes for the commissioner or service provider to guarantee to the Institution the transfer, return and secure elimination of the information subject to the contracted service when it ceases to provide it. Regarding the commissioners referred to in Article 319 Bis, Institutions must require of these to observe the requirements for the secure handling of information in terms of Section Eighth Bis "Of information security", of Chapter VI "Internal Controls" of Title Second "Prudential Provisions" in order to protect the information of clients, potential clients and of the Institution.

  6. . . .

. . .

IV. and V . . . .

VI. Verify that third parties, shareholders of these and, if applicable, subcontractors, as well as commissioners and their shareholders, if applicable, the Administrator of Commissioners and shareholders of these latter, do not fall within the official lists issued by Mexican authorities, international organizations, intergovernmental groups or authorities of other countries, of persons linked or probably linked with operations with resources of illicit origin, terrorism or its financing, or with other illegal activities. To accredit the foregoing, it will suffice for the Institution to state in the written application it presents that it ensured that the persons mentioned in this section were not related in said official lists at the time of their hiring. Additionally, the Institution must state, in the same written application, that it knows the business to which the commissioner is dedicated.

VII. . . .

. . .

. . .

. . .

Article 318 Bis and 318 Bis 1. - . . .

Second Section . . .

Subsection A Of commissioners with physical establishments

Article 319.- . . .

Subsection B Of technology-based commissioners

Article 319 Bis. - Institutions may enter into commercial commission contracts with third parties who act at all times in name and on behalf of the former before clients or potential clients through the Internet pages or computer applications of said commissioners, with the exception of the Internet pages or computer applications that will perform Client Authentication, change or update of Authentication Factors and update of the client's contact medium in accordance with what is established in Articles 319 Bis 2, 319 Bis 3, 319 Bis 4 and 319 Bis 5, without prejudice to the other obligations applicable in terms of Article 318 of these Provisions, as well as of this Section, additionally observing the following requirements:

I. Institutions may only contract with the commissioners referred to in this article, the carrying out of the banking operations listed below and that will be executed in the client session referred to in Article 319 Bis 2 of these Provisions:

a) Opening of level 2 accounts and transfers of resources associated with said accounts.

b) Granting of credits for amounts not greater than three thousand UDIs.

c) Payment of goods and services.

d) Balance and movement queries of the products and operations that the client has contracted and celebrated with the Institution, respectively, through the technology-based commissioner.

All these operations must observe what is provided for in the current provisions of the Secretariat, Commission, Bank of Mexico and other applicable regulation.

II. Institutions must establish mechanisms and procedures to ensure that, through the Internet pages or computer applications of the commissioner in question, personalized, sufficient and clear information is provided to clients or potential clients of the Institutions regarding the following:

a) The responsibilities of the commissioner and of the Institution towards clients regarding the use of: (i) the information that the client provides them, and (ii) the Internet pages, computer applications and Technological Infrastructure of the commissioner.

b) The acknowledgment that the contracting service is with the Institutions themselves and that the commissioner is a channel or means to carry out the operations referred to in section I of this article, as appropriate.

c) The Authentication processes referred to in Articles 319 Bis 2 and 319 Bis 3 that will be followed in order to:

  1. Verify the identity of the client or potential client both in account opening and in the celebration of the operations referred to in section I of this article,
  2. Associate the corresponding Authentication Factors to the client or potential client.
  3. Identify the commissioner so that the client or potential client verifies that they are indeed before the commissioner of the corresponding Institution.

d) The right of the client to use the Category 2 Authentication Factor defined by this in the terms of Article 319 Bis 2, to Authenticate directly in the Mobile Banking or Internet Banking services of the corresponding Institution, in order to carry out operations or modify their Authentication information.

III. Institutions must stipulate in the contract they enter into with the commissioner that the latter may not know, process, transmit, store, modify or copy under any circumstance the information of the Authentication Factors associated with the clients of the Institution, therefore it must attend to what is provided for in Articles 319 Bis 2, 319 Bis 3, 319 Bis 4 and 319 Bis 5.

IV. Institutions must agree with the commissioner that the aggregated and disaggregated information that derives from the contractual relationship with the Institution may not be used, shared, sold or granted to any third party other than those provided for in Article 318, section III, subsection a) numeral 7 of these Provisions. Without prejudice to the foregoing, Institutions may agree upon the conditions under which the technology-based commissioner will use, process and transmit to this the aggregated information of clients for its treatment.

V. Institutions must contract with commissioners that the inactivity periods of the session mentioned in Article 319 Bis 2 may not last more than five minutes and the total duration of the session may not exceed twenty minutes, whether there is activity or not on the part of the client. In these cases, the session must be closed automatically, as well as any communication that exists between the Institution and the client, also revoking the permissions granted to the commissioner for access to client information.

VI. Institutions must contract with the commissioner that the Internet pages or computer applications of the commissioner provide to clients, through their email, a record of all operations and instructions carried out during the session referred to in Article 319 Bis 2, which must be sent in Encrypted form at the end of said session.

VII. Institutions must publish on their Internet page the list of certificates and public keys of their commissioners, previously

verified,

in accordance with

what is established in

the second fraction of

Article 319 Bis

  1. Additionally,

the Institutions must provide

to the Commission

the direct link

to said list,

in order for

the Commission to make it available

to the User Public

for consultation on its

Internet page.

For the purposes of the foregoing,

the Institutions must verify

periodically the validity

of the certificates and

public keys that are contained

in said list.

Likewise,

the Institutions must notify

the Commission of any

change or update that is made

to the link or to the content

of said list.

The provisions of

Article 318,

third fraction,

subsection b),

numeral 1,

as well as Article 321 Bis 2,

both of these Provisions,

shall not apply,

except for contracting with third parties

to provide

on-demand computing services

and technological infrastructure

through the Internet

to support their operation,

inasmuch as the operations

referred to in this Section

cannot be subcontracted.

Article 319 Bis 1.

  • The Institutions must stipulate

with the commission agents

referred to in Article 319 Bis

of these Provisions,

the identification and segregation

of the Technological Infrastructure,

Internet pages and

computer applications that are

property of the Institution

and those of the commission agent,

respectively,

in order to establish

a secure channel

for the exchange of

Authentication information

of the clients and their operations,

said channel must comply with,

at least, the following requirements:

I. The exchange of information

between the Technological Infrastructures

of the Institutions and

commission agents must be

Encrypted using, at least,

a method of

Asymmetric Mathematical Cryptography

complying with what is established

in Articles 93,

93 Bis, 97 and 107

of the Code of Commerce.

II. Prior to

the commission agents offering

the Institution's operations

to clients or

potential clients,

the commission agent and the

corresponding Institution must

reciprocally provide (i)

a list with the

keys and public certificates associated

with the Technological Infrastructure

that are their property or

under their control, respectively,

through which each party will process

the exchange of the permissions associated

with the Authentication of the client

and their operations, and (ii)

the information that allows

identifying the Technological Infrastructure

of both the Institution

and the commission agent,

in order for the Institution

and the commission agent

to mutually authenticate

to allow the exchange of the permissions associated

with the Authentication of the client

and their operations.

Likewise, the Institution must verify

the reliability of the

keys and public certificates of the

commission agent of technological basis

in order to identify those that

might be apocryphal.

III. The Technological Infrastructures

of the Institution and

of the commission agent must carry out

a mutual authentication protocol

to allow the exchange of the permissions associated

with the Authentication of the client

and their operations, this with the purpose

that only the commission agent and the Institution

have access to said information.

IV. Once the exchange of

Authentication information of the clients

and their operations is carried out,

the respective information exchanged

between the Technological Infrastructure

of the Institution and

that of the commission agent,

must be signed using the

private key of the sender

of the information and, subsequently,

Encrypted with the

public key of the receiver

of the information.

In this case, depending on

the direction of the flow of

the information, both the

Institution and the commission agent

will have the status of

sender or receiver.

Article 319 Bis 2.

  • The Institutions that agree

with the commission agents

referred to in Article 319 Bis

of these Provisions,

the opening of

level 2 accounts and

granting of credit for amounts

not greater than three thousand

Investment Units,

without prejudice to compliance with

the obligations provided for in

other provisions, must observe

the following for purposes of

Authentication of potential clients:

I. Through the

Internet page or computer application

of the commission agents,

the client or

potential client must be informed

that their Authentication will be carried out by the

corresponding Institution,

for which the latter will request

a Category 2 Authentication Factor

and a Category 3 Authentication Factor,

in accordance with what is provided by

Article 310 of these Provisions.

Likewise, the client must be informed

that in order for said Authentication to take place,

they will be redirected to the

Technological Infrastructure of the Institution,

in order for the client to be able to

define their Category 2 Authentication Factor

and enter their Category 3 Authentication Factor.

II. Once the client is

on the Technological Infrastructure

of the Institution,

the client must be requested to:

i. Define their Category 2 Authentication Factor.

ii. Provide their

electronic mail or a

instant messaging contact medium that uses

Encrypted communication protocols,

in order for the Technological Infrastructure

of the Institution to send

to said contact medium one of the

Category 3 Authentication Factors.

iii. Enter the Category 3 Authentication Factor

on the Technological Infrastructure

of the Institution in order for it to be

verified and the client to be associated

with the Category 2 Authentication Factor.

III. After having established the

Category 2 Authentication Factor and entered the

Category 3 Authentication Factor referred to in

the first fraction of this article,

the Institution will grant the

commission agent the necessary permissions

to be able to access

the client's information and the client

will be redirected to the

Internet page or computer application

of the commission agent so that said client can

carry out the opening of the

account referred to in Article 319 Bis,

first fraction of these Provisions.

In the case of the redirections

referred to in this article,

both the Technological Infrastructure

of the commission agents and

those of the Institutions,

as the case may be, must inform

in an explicit, clear and

visible message to the client,

the reasons why the

respective redirection is being carried out

and at what step of the

Authentication process the client is.

The permissions granted to the

commission agent for access to

the client's information referred to in

the third fraction of this article,

will be revoked once the

session on the

Internet page or computer application

of the commission agent is finalized to carry out

the operations referred to in Article 319 Bis

of these Provisions.

A session will be understood as the

interaction between clients and the

Internet pages or computer applications

of the technological basis commission agent,

initiated by the Authentication of the client

and finalized after the interval

referred to in Article 319 Bis

fraction V, during which

the operations referred to in

Article 319 Bis fraction I can be carried out.

The Institutions must allow

their clients to use the

Category 2 Authentication Factor defined by

them under the terms of this article,

to Authenticate in the

Mobile Banking or Internet Banking services

of the corresponding Institution.

Article 319 Bis 3.

  • The Institutions that agree

with the commission agents

referred to in Article 319 Bis

of these Provisions,

the celebration of the

operations referred to in said article,

must inform the clients,

prior to the execution of the

respective operation, that they will be requested

the Category 2 Authentication Factor that they defined

previously with the Institution and that they enter a

Category 3 Authentication Factor,

so that it can be

Authenticated by the Institution.

In this case, the Institutions must provide

the Technological Infrastructure so that the client

enters the Category 2 Authentication Factor and

the Category 3 Authentication Factor is generated and sent

that will be requested from the client

to Authenticate it.

Once the client is on the Technological Infrastructure

of the Institution,

the client must be requested to:

i. Enter their Category 2 Authentication Factor

so that it is verified with the information stored by

the Institution.

ii. Enter the Category 3 Authentication Factor

in the Electronic Means of the Institution that they receive

in the electronic mail or the

instant messaging contact medium that they provided to the Institution

previously.

After the Institution has carried out the

Authentication of the client,

the Institution will grant the

commission agent the necessary permissions

to be able to access

the client's information and the client

will be redirected to the

Internet page or computer application

of the commission agent so that this can

carry out the operations provided for in

the first fraction, of Article 319 Bis

of these Provisions.

In the case of the redirections

referred to in this article,

both the Technological Infrastructure

of the commission agents and

those of the Institutions,

as the case may be, must inform

in an explicit, clear and

visible message to the client,

the reasons why the

respective redirection is being carried out

and at what step of the

Authentication process the client is.

Once the Authentication of the client is carried out,

the Institution must allow the

commission agent access to

the client's information in order for the client to be able to

carry out the operations provided for in

Article 319 Bis through the

Technological Infrastructure of the commission agent,

exclusively for the session, understanding by

session what is established in

Article 319 Bis 2.

The permissions granted to the

commission agent for access to

the client's information referred to in the

fourth paragraph of this article,

will be revoked once the

session on the graphical interface defined by the

commission agent on their

Internet page or computer application is finalized to carry out

the operations referred to in Article 319 Bis

of these Provisions.

Article 319 Bis 4.-

The instructions of the clients for the

execution of operations that the Technological Infrastructure

of the commission agent receives referred to in

Article 319 Bis must be Encrypted.

For the foregoing, the

Internet page or computer application

of the commission agent must carry out the

Encryption with, at least, the

key or the public certificate of the

commission agent, which (i)

must be previously loaded on the

Internet pages or computer applications

of the commission agent or (ii)

must be updated by an

instruction from the Technological Infrastructure

of the commission agent.

Article 319 Bis 5.

  • The Institutions must allow

the clients to modify the

Category 2 Authentication Factor,

as well as their

electronic mail or instant messaging contact medium that uses

Encrypted communication protocols through which they receive

the Category 3 Authentication Factor,

which they defined under the terms of

Article 319 Bis 2,

for which the

Internet page or the computer application

of the commission agent must provide an

explicit, clear and visible option or link that carries out the

redirection towards the Technological Infrastructure

of the Institution,

in order to modify said

Authentication Factors, electronic mail or

instant messaging contact medium that uses

Encrypted communication protocols.

In order for the respective modification to take place,

what is provided in Article 319 Bis 2 must be complied with.

Section C

Complementary Provisions

Article 320.-

The Institutions that celebrate

commercial commission contracts that have as their object to carry out the operations

referred to in Articles 319 and 319 Bis

of these provisions through

commission agents, will require

presenting for authorization of the Commission,

prior to the signing of the

commercial commission contract and for

a single occasion, a

strategic business plan that contemplates the

totality of the operations provided for in the

referenced articles that they could carry out, and must include the

model of commercial commission contract that will serve as

the basis for the contracts that are

celebrated with each one of the

commission agents with which it is intended to contract.

In the case of development banking institutions,

the authorization of the strategic plan may be

requested once the exception referred to in

Article 47 of the Law is obtained.

. . .

The strategic plan referred to in the first paragraph

of this article must provide for compliance with the

requirements indicated in Article 318,

fractions I, III, V and VII

of these provisions,

establishing the implementation dates of each

of the operations indicated therein.

Likewise, the aforementioned plan must contain the

following aspects:

I.

to V.

. . .

. . .

Article 321.-

When the Institutions intend to carry out

operations other than those indicated in the

strategic plan that was authorized to them in accordance with

Article 320 above, or well, intend to operate with

new commission agents not provided for in the

authorized plan or implement a new technology to operate with

commission agents or Administrators of Commission Agents

previously authorized, must be subject to

the following:

I.

. . .

II. In the case of the

operations referred to in the

fractions I, IV and XII of Article 319

of these provisions,

they must present a notice to the Commission,

must manifest in the same that the

operation will be carried out under the

contract to be celebrated between the

Institution and the commission agent,

under the terms authorized by the Commission,

indicating in its case, if the

contract that intends to celebrate with the

commission agent presents any variation that falls on a

modifying agreement with respect to the model contract,

in which case it must remit said project.

The notice referred to in this fraction must be sent to the

Commission, being able to initiate the

operations referred to in this fraction on the

day following the presentation of the

corresponding notice, on the understanding that the Commission may at any

moment require that the operations not be

carried out through any or some commission agents in

particular when these fail to comply with these

provisions.

Likewise, the Institutions may incorporate in a

single notice all the operations of the

indicated in this fraction, that will be

effectuated with the same commission agent.

. . .

III. In the case of the

operations referred to in the first fraction of Article 319 Bis

of these Provisions,

they must request authorization from the Commission,

attaching to their request letter the following:

a) The technical requirements indicated in Annex 59 of these

provisions and, in its case, the description of the new

technology and its implementation.

b) The draft commercial commission contract for operating with

the commission agent, which contemplates the aspects

referred to in Articles 318, fraction III and 324, with

the exception of the second paragraph of fraction I,

of these provisions, in accordance with the strategic plan of

business authorized.

Additionally, for the operations referred to in

fractions I, II and III above, the Institutions must present

along with the request for authorization or notice,

as applicable, the Internal Certification Format of

Commission Agents (FCIC) with information on

pre-operational tests, duly filled out based on the

new operation they intend to carry out.

For this they must download the updated format of said

report available on the Internet site of the

Commission.

Article 321 Bis.-

. . .

Article 321 Bis 1.-

The Institutions must provide to the

User Public and to the general public,

through their Internet page or in their

branches, as applicable,

the information of the commission agents that they have

enabled to carry out the operations referred to in

Article 319 and Article 319 Bis

of these provisions,

specifying the operations that can be carried out in each

one of them and the maximum amounts authorized per

operation.

Likewise, the Institutions must inform regarding

the commission agents, whenever applicable,

the following:

I. The legal domiciles of the

commission agent, comprising at least, their

tax and commercial domicile;

II. The list of the

physical attention modules with their

physical address;

III. The Internet pages

through their Internet domain name,

such as those known as

URL ("Uniform Resource Locator");

IV. The names and logos of the

mobile applications, the name of the administrator and owner of the

mobile application and the digital stores

where they are available, in their case;

V. The list of all the

official telephone numbers that the commission agents themselves use

which must be enabled to receive

calls from the public, in addition to this, there must be the

option of offering telephone

attention through an employee of the

technological basis commission agent;

VI. The list of official

electronic contact mails;

VII. The social networks used for

promotion, and

VIII. Any other

communication channel that is used to interact with

the public and is not contemplated in the

previous fractions.

Likewise, the Institutions must verify that the

commission agents inform the clients,

through the receipts or proofs of the

operations they carry out, visible advertisements in

the establishments, technological platforms or by

any other means they use to promote with the

User Public their operations as

commission agent, that they act in the name and on behalf of the

corresponding Institution represented.

Articles 321 Bis 2 to 323.

  • . . .

Article 324.-

. . .

I.

to IV.

. . .

IV. Bis.

In the case of the commission agents that present themselves

to the clients or potential clients through their

Internet pages or computer applications,

what is provided in Articles 319 Bis, 319 Bis 1, 319 Bis 2, 319 Bis 3, 319 Bis 4 and 319 Bis 5 must be complied with.

V.

and VI.

. . .

VII.

. . .

a) Conditioning the

execution of the banking operation to the

acquisition of a product or service, in the case of the

operations referred to in fractions I to X and XII of Article 319 and the

first fraction of Article 319 Bis of these

provisions.

. . .

b)

to f)

. . .

g) Contracting exclusivity conditions with the

Institution in question, without prejudice to the duties of

confidentiality of the information by the commission agent towards each

Institution with which they agree on the

services referred to in this article.

VIII.

to XI.

. . .

XII. In the case of the

operations referred to in fractions IX and X of Article 319 and Article 319 Bis,

first fraction of these provisions, the obligation of the

commission agent to gather from the client the

necessary information and transmit it in time and form to the

Institution, in order to comply with what is provided in

Article 115 of the Law and the "General Provisions

referred to in Article 115 of the Law of Credit Institutions",

issued by the Secretariat, or those that replace them.

XIII. The obligation of the commission agent to elaborate

remediation plans regarding the findings of the

reviews and security tests carried out to those referred to in

the ninth fraction of this article and deliver them to the

Institution.

The Institutions, in the carrying out of the operations

referred to in this Second Section of Chapter XI,

cannot hire commission agents in such a way that they provide

their services exclusively to them.

Article 325.-

. . . "

TRANSITORY PROVISIONS

FIRST. -

This Resolution will enter into force on the

day following its publication in the Official Journal of the

Federation, except as provided in the following

transitory article.

SECOND. -

The Institutions will have eighteen months counted from

the entry into force of this Resolution,

to modify the contracts that they have

celebrated with the third parties referred to in Chapter XI of these

Disposiciones

and give simultaneously with the obligations derived from the modification of said contracts, so that with respect to the reforms applicable provided for in Articles 318, paragraphs II and III, subparagraph a), numeral 3 and subparagraph b), numeral 1, second paragraph and numeral 3; Article 321 Bis 1; Article 324, paragraph VII, subparagraph g); Annex 58, paragraph I, numeral 5, second paragraph, paragraph III, numeral 2, second paragraph, subparagraph b) and subparagraph d), third paragraph, subparagraph b) and Annex 59, numeral 2 and 6.

Respectfully

Mexico City, July 3, 2024. - President of the National Banking and Securities Commission, Dr. Jesús de la Fuente Rodríguez .- Rubric.

ANNEX 57

CRITERIA FOR EVALUATING THE EXPERIENCE AND TECHNICAL CAPACITY OF COMMISSION AGENTS THAT OPERATE UNDER THE SECOND SECTION OF CHAPTER XI OF TITLE FIVE OF THE PROVISIONS

It will be presumed that commission agents have sufficient technical capacity when they declare under oath that they comply with the following:

  1. Their personnel is trained to adequately operate the Electronic Media that the Institution makes available to them to authenticate banking clients.

  2. Have the necessary infrastructure to carry out the processing of the operations subject to the banking service.

  3. Be legal entities or natural persons with business activity and have (i) a permanent establishment, understood as any place of business where business activities are carried out, partially or totally, or independent personal services are provided, such as offices, branches, agencies, or other facilities on national territory, or (ii) make available to the User Public a web page or software application and Technological Infrastructure that allows carrying out the processes indicated in Chapter XI of these Provisions.

  4. Have their own line of business.

  5. Have honorability and a satisfactory credit and business history; to this effect, commission agents will be considered to meet this requirement if they:

a) Enjoy a good credit history according to Credit Information Reports and are up to date in the fulfillment of their credit obligations.

b) Have not caused, directly or through intermediaries, any loss, diminution, or detriment to the patrimony, to the detriment of credit institutions or issuing companies in the securities market.

c) Have not been declared in civil or commercial bankruptcy.

d) In their case, have not been convicted by a final judgment for an intentional crime that imposes a penalty of more than one year of imprisonment.

e) In their case, have not been convicted by a final judgment for intentional property crimes, regardless of the penalty.

f) In their case, have not been subject to inquiries or investigations of an administrative nature before the Commission for serious violations of national or foreign financial laws, or before other Mexican supervisory and regulatory institutions of the financial system or of other countries, which have resulted in any type of final and definitive resolution or agreement in which the interested party has not been expressly exonerated.

With respect to Entities of the Federal, State, or Municipal Public Administration, it will be sufficient that they comply with what is established in numerals 1 and 2 of this Annex and are expressly authorized by their law or regulations to provide the services or commissions in question.

Institutions may exempt from compliance with the requirements indicated in numerals 3, and 5, subparagraph a) of this annex, with respect to commission agents administered by a Commission Agent Administrator, provided that the said Commission Agent Administrator complies with all the requirements provided for by this annex.

ANNEX 58

TECHNICAL REQUIREMENTS FOR THE OPERATION OF ELECTRONIC MEDIA FOR THE OPERATIONS CONTEMPLATED IN THE SECOND SECTION OF CHAPTER XI OF TITLE FIVE OF THE PROVISIONS

The Electronic Media that Institutions use to guarantee the correct execution of banking operations carried out through commission agents and the security of the information of banking clients and the general public, must comply with the requirements referred to in this annex.

The Institution must have evidence of the verification of compliance carried out prior to the start of operations and at least once a year, of the following aspects and have it available to the Commission when it so requires.

With respect to Administrators of Commission Agents, these must verify that the commission agents that make up their network comply with what is established in this Annex.

For the purposes of this Annex, "Operator" will be understood as the employee of the commission agent who has access to the Electronic Media.

I. Requirements of Electronic Media

  1. Mechanisms necessary to carry out online transactions.

The Electronic Media must have the necessary mechanisms to carry out online transactions, that is, at the very same instant that the operation is carried out, updating the client's online balance except for the operations referred to in paragraphs I, IV, and XII of Article 319 of these provisions, where balance updates may be carried out in accordance with what is established by the operating rules of the respective Institutions.

For such purposes, service payment operations in cash or with debit card, or charged to Bank Accounts, cash deposit, credit payment in cash, and fund status; must be registered as a charge to the deposit account that the commission agent has with the Institution.

On the other hand, cash withdrawal and check payment operations must be registered as a credit to the same account.

In cases where the client's balance information is stored in devices such as integrated circuit cards or equipment located in the commission agent's facilities, online impact will not be considered the one carried out in such devices, provided that there are mechanisms for their periodic consolidation in the central systems of the Institutions.

With respect to the operations referred to in paragraphs I and IV of Article 319, as well as in paragraph I, subparagraph c) of Article 319 Bis, of these provisions and in case that processing is carried out through the batch scheme, controls must be maintained implemented for the secure sending of files, as well as for the reconciliation and settlement of the operations carried out through this medium.

  1. Validation of Electronic Media of the commission agent.

Only the Electronic Media of the commission agents authorized by the Institution will have access to the infrastructure set up by it (use of dedicated lines, identification of physical or logical addresses, VPNs, digital signatures, among others).

The Institution's computer systems must authenticate the Electronic Media that commission agents use to carry out banking operations.

  1. Certification of Electronic Media of the commission agent.

The Institution will be responsible for certifying the installation and use of the Electronic Media that the commission agent maintains for the carrying out of banking operations, as well as for establishing annual evaluations of said Electronic Media.

This certification may be carried out by the Institution, in its case, through its specialized technical areas in information security or internal systems audit, or well, through independent third parties, hired by the Institution itself, who must accredit to it that they have adequate technical credentials in the matter of computer or systems audit.

The aforementioned certification must consider at least that the Institution must ensure at all times that the electronic media used by commission agents maintain control mechanisms that prevent the reading and extraction of client information by unauthorized third parties.

  1. Policies and procedures for the administration of access and configuration of Electronic Media.

It is the responsibility of the Institution to verify that the commission agent has policies and procedures for:

a) The configuration of the Technological Infrastructure that connects to the Institution's computer systems.

b) The administration of cryptographic keys used between commission agents and the Institution's systems.

  1. Generation of electronic records of operations.

All operations carried out through commission agents must generate electronic records that cannot be modified or deleted and in which at least the date, hour, and minute, the type and amount of the instruction, the banking client's account number, physical location of the window or medium through which the instruction was executed, as well as sufficient information that allows the identification of the personnel who carried out the instruction, as well as audit information that considers at least, client, IP addresses of origin and destination, date, hour, name of the application programming interface (API by its initials in English), type of request, version, and response code to effect having traceability of events in the systems of the Institution and of the commission agent.

The custody of said records must be the responsibility of the Institution.

II. Requirements for Identification of Operators and Authentication of banking clients.

  1. Mechanisms necessary for the full identification of the Operators that will connect through commission agents.

With respect to the identification of the Operators of the technology-based commission agents referred to in numeral 6, of subparagraph a), of paragraph III, of Article 318 of these Provisions, what is mentioned in Section II Bis "Identification of Operators of technology-based commission agents" of this Annex must be observed.

  1. Generation and delivery of Passwords, Dynamic One-Time Passwords, or Access Keys of the Operators.

Institutions must establish mechanisms for the process of generating and delivering the Authentication Factors that ensure that only the commission agent, and in its case, the Operators can know.

  1. Composition of Passwords, Dynamic One-Time Passwords, or Access Keys of the Operators.

Criteria must be established for the characteristics of the length of the Passwords, Dynamic One-Time Passwords, or Access Keys of the Operators.

3 Bis. Validity of Passwords, Dynamic One-Time Passwords, or Access Keys of the Operators.

Institutions must establish criteria for the validity of the Passwords, Dynamic One-Time Passwords, or Access Keys, in order to strengthen the identification processes of the Operator of the technology-based commission agent.

In the case of Dynamic One-Time Passwords, their validity cannot exceed 1 minute and for Passwords or Access Keys that do not correspond to Category 4 Authentication Factors, this validity cannot exceed 90 business days.

  1. Protection of Passwords or Access Keys and Personal Identification Numbers (PIN).

Institutions must provide what is necessary to prevent the reading of the characters that make up the Passwords or Access Keys, as well as the Personal Identification Numbers (PIN) typed by banking clients, respectively, in the Electronic Media of access, both in their capture and in their display through the screen.

The Passwords or Access Keys and the Personal Identification Numbers (PIN) must be validated and stored through encryption mechanisms, whose cryptographic keys must be under the administration and control of the Institution in question.

At no time can commission agents have access to the data or algorithms related to said Passwords or Access Keys and Personal Identification Numbers (PIN).

Commission agents must have certifications of security standards of the card industry of the security and PIN transaction requirements (PTS) or their equivalents or those that, at the discretion of the Commission, allow the proper protection of the information stored, transmitted, or processed related to the entry of the Personal Identification Numbers (PIN) of banking clients and the data of bank cards.

  1. Authentication for banking clients.

For the carrying out through commission agents of consultations and operations that represent a charge to the banking clients' accounts, the latter must authenticate themselves through the Electronic Media with which the aforementioned operations are carried out using two different Authentication Factors.

The foregoing will not be applicable to the commission agents referred to in Article 319 Bis of these Provisions.

For the purposes of the foregoing, Institutions may opt for the combination of at least two of the following Authentication Factors and adhere to what is established in Chapter X of Title Five of these Provisions:

a) Debit or credit cards with security mechanisms such as cards with magnetic stripe and/or integrated circuit or "chip".

b) Personal Identification Number (PIN).

In the case that debit or credit cards are used, card readers must be used, such as PIN PADS, for the Authentication of banking clients, which must have a screen and a keyboard exclusively designed so that the banking client can enter the information of their respective card and their Personal Identification Number (PIN), as well as mechanisms that prevent their reading by third parties.

Commission agents must have certifications of security standards of the card industry of the security and PIN transaction requirements (PTS) or their equivalents or those that, at the discretion of the Commission, allow the proper protection of the information stored, transmitted, or processed related to the entry of the Personal Identification Numbers (PIN) of banking clients and the data of bank cards.

In the case of using a cell phone, the Personal Identification Number (PIN) must be entered directly on the keyboard of said phone.

Under no circumstances can the PIN information be stored on the cell phone without encryption mechanisms.

c) Biometric Factor.

In case of using biometric readers for the Authentication of banking clients, said readers must have mechanisms that ensure that it is the authorized client who carries out the operation, as well as implement mechanisms or procedures so that the commission agent does not store the processed information related to the biometric factors of the clients.

All administration and control of biometric information must be the sole responsibility of the Institution through the customer service channels they have established.

d) Cell phone.

In case of using cell phones for the Authentication of banking clients, Institutions must verify that the technology of said cell phones allows them to function as an Authentication Factor and that they have security mechanisms that prevent their duplication or spoofing.

Institutions cannot use the combination of the Authentication Factors referred to in subparagraphs a) and d) to authenticate their clients.

  1. Authentication for Operators.

For the reception and operation of transactions requested by banking clients through the Electronic Media of commission agents, Operators must start a session and authenticate themselves through said Media.

The authentication processes must be validated by the Institution, through the mechanisms and controls that it deems appropriate.

It is the responsibility of the Institution to ensure that commission agents have said operator authentication mechanisms, for the carrying out of operations.

  1. Blocking of the Authentication Factors of the Operators.

Blocking schemes for the Authentication Factors of the Operators must be established when an attempt is made to enter the Electronic Media incorrectly.

Under no circumstances can failed access attempts exceed five consecutive times without generating automatic blocking.

  1. Access to banking client data.

Under no circumstances can the Electronic Media used by commission agents allow the carrying out of operations or balance inquiries without the prior Authentication in terms of numeral 5 of section II "Requirements for Identification of Operators and Authentication of banking clients" of this annex, of the corresponding client.

Deposit and payment operations will be exempt from this case.

Likewise, with respect to banking operations that require the commission agent to access the balances of banking clients' accounts, said commission agent must, at all times, keep confidentiality regarding said operation and carry out prior to the respective access, the Authentication referred to in numeral 1 of section III "Electronic Media Operations" of this annex.

II. Bis Identification of Operators of technology-based commission agents

In addition to what is provided in paragraph II "Requirements for Identification of Operators and Authentication of banking clients" of this Annex, Institutions must request technology-based commission agents to carry out the identification of their Operators for the purposes of complying with what is established in numeral 6, subparagraph a), paragraph III of Article 318 of these Provisions.

For the foregoing, technology-based commission agents must request from their Operators, at least, a Category 2 Authentication Factor and a Category 3 Authentication Factor, observing the following:

  1. For the purposes of the Operator establishing a Category 2 Authentication Factor for their identification, the technology-based commission agent must observe the following:

a) The technology-based commission agent must generate and provide to the Operator a Category 3 Authentication Factor, which will be sent to the institutional email that the Operator provided in the document referred to in numeral 6, subparagraph a), paragraph III of Article 318 of these Provisions.

b) The technology-based commission agent must request from the Operator the Category 3 Authentication Factor that was provided to him as established in subparagraph a) of this numeral.

c) The Operator must enter in the Technological Infrastructure of the technology-based commission agent the Category 3 Authentication Factor referred to in subparagraph b) of this numeral, verifying the validity of said Factor.

d) Once the technology-based commission agent verifies the validity of the Category 3 Authentication Factor referred to in the previous subparagraph c), the technology-based commission agent must request from the Operator to define a Category 2 Authentication Factor, which can only be used by him in order to protect his identification information.

  1. For the technology-based commission agent to identify the Operator, it must request, at least, (i) the Category 2 Authentication Factor established by the Operator in accordance with what is mentioned in numeral 1 of this paragraph, and (ii) a Category 3 Authentication Factor, observing the following:

a) Prior to the technology-based commission agent carrying out the identification of the Operator, the technology-based commission agent must generate and provide to the Operator a Category 3 Authentication Factor.

This Category 3 Authentication Factor must be sent to the institutional email that the Operator provided in the document referred to in numeral 6, subparagraph a),


fraction

III

of

Article

318

of these

Provisions.

b)

The technological base commissionaire must

request from the Operator the

Category 2 Authentication Factor

established by

the Operator and the

Category 3 Authentication Factor

provided by the technological base commissionaire,

for the purpose of

performing the identification of the Operator.

The technological base commissionaire must

provide the Operator with the

necessary means to

modify the

Category 2 Authentication Factor

must observe what is provided in

numeral 1 of this

fraction.

In the event that an Operator ceases to perform the processes reported in the document delivered to the Institution as established in the second paragraph of numeral 6, subsection a), fraction III of Article 318 of these Provisions, the technological base commissionaire must revoke the access permissions of its Technological Infrastructure, in order to protect the integrity of the processes executed by the technological base commissionaire and the operability of the Institution.

III. Operation of Electronic Media

Validation of destination account structure.

The Electronic Media of the commissionaires must validate, based on the information available to the Institution, the structure of the destination account number or contract, whether they are deposit accounts, service payments, Standardized Banking Key, credit cards or other payment methods.

Generation of operation receipts.

The Electronic Media must automatically generate the operation receipts that the Institutions issue for each operation, without any intervention on the part of the commissionaire's personnel.

Such operation receipts will be different from those used by the commissionaires to record the operations of their commercial business and must include what is provided by the General Provisions of CONDUSEF in matters of transparency and sound practices applicable to credit institutions.

In addition to the aforementioned provisions, Institutions must consider the following in the operation receipts:

a)

The data that allow the banking client to identify the account with respect to which the operation was carried out.

At no time should the complete account number be displayed on the receipts.

b)

The information from balance inquiries, when the client has requested and authorized it, in which case it must be provided only to the client through the corresponding receipt, the commissionaire's Internet page or computer application.

The commissionaire may not safeguard or conserve information related or associated in physical or digital media.

c)

The identification of the Institution and of the commissionaire with which the operation was carried out, specifying in the latter case, the address of the establishment or the address of the Internet page or computer application through which the instruction was executed.

d)

The information that allows the identification of the commissionaire's personnel who carried out the instruction where, at least, the full name of the commissionaire's official or employee appears.

When the limits referred to in Article 323 of these provisions are exceeded, as applicable, the requested operations cannot be carried out, so the Electronic Media must generate receipts indicating to the banking client this situation.

For such purposes, a receipt must be provided that includes the following legends:

a)

In the case of the limit referred to in Article 323, fraction II, subsection b) of these Provisions:

" Transaction not performed for having exceeded your permitted limit. Go to a bank branch. "

b)

In the case of the limits referred to in Article 323, fractions I and II, subsection a) of these Provisions, as applicable:

" Transaction not performed " .

Under no circumstances should the client's address be shown on the operation receipt.

Likewise, the address should not be shown to any employee or official of the commissionaire during the generation of said receipt.

Institutions will make available to their clients in the operation receipts the information regarding the telephone number and electronic mail of the specialized unit for user attention that the Institution must have in terms of the Law on Protection and Defense of the User of Financial Services, as well as that of the Institution's attention center.

All operation receipts that are celebrated through commissionaires will have probative value for the purposes of any clarification and must be recognized in those terms by the Institutions that issue them.

Monitoring of operations.

The Institution must establish continuous mechanisms through computer tools that allow it to monitor the activities carried out by the Operators through the Electronic Media of the commissionaires in order to detect transactions that deviate from the usual operational parameters.

Storage of Sensitive User Information in Electronic Media of the commissionaires.

In cases where, for operational and technical reasons, it is necessary to store partially or totally Sensitive Information of the User of the Institution in the Electronic Media of the commissionaire, the institution must verify that encryption mechanisms exist.

Likewise, commissionaires may not issue a duplicate of the balance inquiry receipts or keep copies of these.

The Institution must contract with the technological base commissionaire that, when clients access the graphical Interfaces of the commissionaire's Internet page or computer applications, these must provide detailed and sufficient information that identifies the celebration of operations with the Institution for which it may use images, letters or visible colors related to the same.

The Institution is obliged to notify its clients, as soon as possible and through the communication means that it makes available to them and that they have chosen for that purpose, the operations referred to in subsections a), b) and c) of fraction I, of Article 319 Bis carried out through the technological base commissionaires.

IV. Information Security

Logical segregation, or logical and physical segregation of the different networks in different domains and subnets, depending on the function they develop or the type of data that is transmitted, including segregation of the productive environments from those of development and testing, as well as perimeter security components and networks that ensure that only authorized traffic is permitted.

In particular, in those segments with links to the outside, such as Internet, providers, authorities, other networks of the Institution or headquarters, Administrators, commissionaires and other third parties, consider safe zones, including those known as demilitarized zones (DMZ).

Secure configuration of components, considering at least, ports and services, permissions granted under the principle of least privilege, use of removable storage media, access lists, manufacturer updates and reconfiguration of factory parameters.

Security measures for their protection, as well as for the access and use of the information that is received, generated, transmitted, stored and processed in the technological infrastructure, having at least the following:

a)

Identification and authentication mechanisms of all and each of the users of the technological infrastructure, which allow them to be recognized unequivocally and ensure access only to persons expressly authorized for this purpose, under the principle of least privilege.

For the foregoing, pertinent controls must be included for those users of the technological infrastructure with greater privileges, derived from their functions, such as, that of database and operating system administration.

b)

Encryption of information according to the degree of sensitivity or classification that the Institution determines and establishes in its policies, when such information is transmitted, exchanged and communicated between components, or stored in the technological infrastructure or accessed remotely.

c)

Access keys with composition characteristics that prevent unauthorized access, considering processes that ensure that only the user of the Technological Infrastructure is the one who knows them, as well as security measures, encryption in their storage and mechanisms to change access keys every 90 days or less.

d)

Controls to automatically terminate unattended sessions, as well as to prevent simultaneous unauthorized sessions with the same user identifier of the technological infrastructure.

e)

Security mechanisms, both of physical access, as well as of environmental and electrical energy controls, that protect the technological infrastructure and allow operation in accordance with the specifications of the provider, manufacturer or developer.

f)

Validation measures to guarantee the authenticity of the transactions executed by the different components of the technological infrastructure, considering, at least the following:

i.

The veracity and integrity of the information.

ii.

The authentication between components of the technological infrastructure, which ensure that only legitimate service requests are executed from their origin to their execution and registration.

iii.

The messaging, communication and encryption protocols, which must ensure the integrity and confidentiality of the information.

iv.

The identification of atypical transactions, anticipating that the applications have automatic alert measures for their attention by the corresponding operational areas.

g)

The update and maintenance of digital certificates and components provided by service providers that are integrated into the transaction execution process.

Automated mechanisms to detect and prevent events and information security incidents, as well as to prevent unauthorized incoming and outgoing data connections and flows and information leakage, considering among others, removable storage media.

Policies and procedures for the administration of encryption keys used by the Institution and the commissionaire, as applicable.

Policies and procedures for secure deletion for the destruction of data when they are no longer necessary, or upon conclusion of the commercial commission.

Policies and procedures for the management of information security incidents of the commissionaires that ensure the detection, classification, attention and containment, investigation and, as applicable, digital forensic analysis, diagnosis, reporting to competent hierarchical levels, solution, follow-up and immediate communication to the Institution and counterparts of said incidents.

Registration in databases, of the incidents, failures or vulnerabilities detected in the Technological Infrastructure of the commissionaire, which includes at least the information related to the detection of failures, operational errors, attempts at computer attacks and those effectively carried out as well as loss, extraction, alteration, loss or improper use of information of the Users of the Technological Infrastructure of the commissionaire, where the date of the event and a description of it, its duration, service or channel affected, amounts, as well as the corrective measures implemented are contemplated.

Likewise, maintain complete audit records that include the detailed information of the accesses or access attempts and the operation or activity carried out by the Users of the Technological Infrastructure.

Such records must be available to the authorized personnel of the Institution.

Performance of vulnerability scanning tests on the components of the technological infrastructure of the commissionaires that store, process or transmit information of the banking operations.

Such tests must be performed at least quarterly.

Performance of penetration tests by an independent third party, whose personnel has verifiable technical capacity through specialized certifications in the matter, such tests must contemplate the technological infrastructure of the commissionaire for the commercial commission.

The tests must consider, at least the following:

a)

Its scope and methodology.

b)

Be performed at least once a year.

c)

Additional tests must be carried out when there are significant changes in systems and applications, or perform them on previously reviewed systems and applications when there are critical vulnerabilities.

Continuous follow-up to the remediation plans regarding the findings of the reviews and tests referred to in the previous numerals 9 and 10.

Such plans must be reviewed by the institution and follow up on the actions implemented for their mitigation.

Have access controls to information according to the access levels and profiles determined by the Institution.

V. Requirements for the operation referred to in fraction IX of Article 319 of these provisions

That the systems of the Institution, as well as, as applicable, those of the stock exchanges with which they intend to celebrate commercial commissions, have the necessary technical requirements that allow them to comply with what is provided in Article 124 of the Law, as well as to receive and transmit the information referred to in the " General Rules to which multiple banking institutions must be subject to classify information related to active and passive operations referred to in Article 124 of the Credit Institutions Law ", and those issued by the IPAB, or those that replace them, including what is stated in numeral 3 below.

The procedures through which the Institution will authorize the stock exchanges to carry out such operations.

The obligation of the commissionaire stock exchange to:

a)

Collect from the client the necessary information in order to comply with what is provided in Article 115 of the Law and the " General Provisions referred to in Article 115 of the Credit Institutions Law " issued by the Secretariat, or those that replace them.

For this purpose, stock exchanges must transmit in time and form to the Institution the information related to the mentioned operations, in order for the Institution itself to comply with the cited Article 115 of the Law and the " General Provisions referred to in Article 115 of the Credit Institutions Law " issued by the Secretariat, or those that replace them.

b)

Regarding operations celebrated with multiple banking institutions as principals:

i.

Collect and classify in automated processing and data conservation systems, as well as in any other technical procedure, all the information that allows the multiple banking institution to comply with the Third of the " General Rules to which multiple banking institutions must be subject to classify information related to active and passive operations referred to in Article 124 of the Credit Institutions Law " issued by the IPAB or those that replace them;

ii.

Transmit to the multiple banking institution principal, simultaneously at the moment of the celebration of each operation, through its systems, the information that according to the Rules referred to in the previous numeral, the latter must maintain.

The foregoing, without prejudice to the fact that the contracts referred to in this article must contain the obligation on the part of the stock exchanges acting as commissionaires, to transmit to the multiple banking institutions principals, all the information referred to in the Third of the Rules mentioned in numeral i. above, when so required by the Commission, directly or at the request of the IPAB, always that the corresponding assumptions are met for the resolution of the multiple banking institution principal in terms of Article 122 Bis of the Law;

iii.

Obtain from the client at the moment of celebrating the operations, a written manifestation or by any means agreed with the banking client, in the terms of the format contained as Annex 60 of these provisions, and

iv.

Deliver to the client, on the back of the document referred to in numeral iii. above, or by any means agreed with the banking client, an informative text in the terms established in Annex 61 of these provisions.

c)

The terms under which the settlement of the operations must be carried out.

In the event that the settlement of the respective operations is carried out in the offices of the stock exchanges, deliver to the client the respective amount in the form agreed at the time of contracting.

In any case, if the client does not request the office for the referred settlement within a period of three business days counted from the date of maturity of the operation, the stock exchange will be released from the obligation to make the corresponding payment in favor of the client, so the settlement must be carried out directly with the Institution.

The obligation on the part of the Institution to provide the necessary means in order to comply with the provisions referred to in the previous numerals 1 and 2 and, in general, to what is established by the provisions related to the banking savings protection system, as well as to ensure that the commissionaire effectively complies with the foregoing.

Annex 59

Information that must be presented in the commissionaire authorization request

The information to be presented in the commissionaire authorization request must contain at least the following:

Detailed description and flow diagram of the processes of each of the operations to be carried out through the commissionaires considering the reconciliation and settlement process of each of them, the third parties involved and the Technological Infrastructure to be used in the operation in question.

Architecture and telecommunications diagram in which the security components, networks and databases of the technological infrastructure used for the operation with commissionaires are shown, which ensure that only authorized traffic is permitted.

Such diagram must include each of the participants, as well as all information processing sites including redundancy schemes, link types and backup routes, servers and communication devices.

The complete and detailed locations of the main and backup data centers, both of the Institution, of the commissionaire or of the provider of the commissionaire's technological infrastructure where the information of the transactions carried out through the commissionaire will be stored and/or processed (street, exterior and interior number, neighborhood, borough or municipality, state and country).

Diagram of interrelation of applications or systems of the commissionaire, including the systems of the Institution itself.

(It must Include all participants involved in the operation (e.g.: commissionaire, switches, payment media processors, third parties and the Institution itself).

Detail of the Sensitive Information that will be stored by the commissionaire in its equipment or facilities, or of the provider of the commissionaire's technological infrastructure, or to which they may have access.

Regarding Sensitive Information, the commissionaire must implement encrypted storage mechanisms.

Structure of the commissionaire's personnel and of the provider of the commissionaire's infrastructure with access to the information of the transactions carried out through the commissionaire and the associated Sensitive Information, which includes as a minimum position, hierarchical level of the same and responsibilities and authorized activities

related

to

such

Information

for

such

position.

Include

the

characteristics

of

the

operation

receipts,

attach

the

design

of

receipt

of

each

one

of

the

operations

to

contract.

Description

of

the

validation

measures

to guarantee

the

authenticity

of

the

transactions

executed

by

the

different

components

of

the

technological

infrastructure,

considering,

at

least

the

following:

a)

The

veracity

and

integrity

of

the

information.

b)

The

authentication

between

components

of

the

technological

infrastructure,

which

ensure

that

only

legitimate

service

requests

are

executed

from

their

origin

until

their

execution

and

registration.

c)

The

messaging,

communication,

and

encryption

protocols,

which

must

ensure

the

integrity

and

confidentiality

of

the

information.

d)

The

identification

of

atypical

transactions,

anticipating

that

the

applications

have

automatic

alert

measures

for

their

attention

by

the

corresponding

operational

areas.

A

list

containing

all

the

keys

and

the

public

certificates

of

the

Internet

pages

or

computer

applications

of

the

commissionaire

for

those

commissionaires

to

which

Article

319

Bis

of

these

Provisions

refers.

Description

of

automated

mechanisms

to detect

and

prevent

security

events

and

information

incidents,

as

well

as

to

avoid

unauthorized

incoming

or

outgoing

data

connections

and

flows

and

information

leakage,

considering

among

others,

removable

storage

media.

Detailed

report

of

the

results

of

vulnerability

scanning

tests

of

the

components

of

the

technological

infrastructure

of

the

commissionaires

that

store,

process,

or

transmit

information

of

the

banking

operations.

Detailed

results

report

of

the

penetration

tests

performed

by

an

independent

third

party,

whose

personnel

possess

demonstrable

technical

capacity

through

specialized

certifications

in

the

field,

such

penetration

tests

must

encompass

the

technological

infrastructure

of

the

commissionaire

for

commercial

commission.

Remediation

plans

regarding

the

findings

of

the

reviews

and

tests

referred

to

in

numerals

9

and

10

above,

as

well

as

the

evidence

of

the

mitigation

actions

implemented

to

correct

the

critical

and

high-severity

vulnerabilities.

Documentation

of

the

Internal

Commissionaire

Certification

Formats

(FIC)

relative

to

the

pre-operational

tests

of

the

operations

with

the

commissionaires.


In the document you are viewing, there may be text, characters, or objects that do not display correctly due to conversion to HTML format, so we recommend always taking the digitized image of the DOF or the PDF file of the edition as a reference. The content, form, and scope of published documents are the strict responsibility of their issuer.

CONSULT

BY

DATE

Do

Lu

Ma

Mi

Ju

Vi

INDICATORS

Exchange Rate and Rates as of 25/08/2026

DOLAR

16.9647

UDIS

8.807141

CCP

6.12%

CCP-UDIS

4.72%

CPP

5.09%

TIIE

28

DIAS

6.7559%

TIIE

91

DIAS

6.7931%

TIIE

182

DIAS

6.8474%

TIIE

DE

FONDEO

6.50%

See more

SURVEYS

Did you like the new look of the Official Gazette of the Federation website?

No

Yes

Official Gazette of the Federation

Río Amazonas No. 62, Col. Cuauhtémoc, C.P. 06500, Mexico City Tel. (55) 5093-3200, where you can access our service menu

Electronic address: dof.gob.mx

111

LEGAL NOTICE | SOME RIGHTS RESERVED © 2026

More like this from SHCP

SHCP published 15 documents in the last 30 days. We email you each new one the day it's published.

Share