2024-07-11 | DOF 5732991Added
The National Banking and Securities Commission establishes a new regulatory framework for 'technology-based agents' (comisionistas de base tecnológica), allowing credit institutions to contract with third parties to offer specific banking services via digital channels such as websites and applications. The resolution defines permitted operations, including level 2 account opening, credits up to 3,000 UDIs, bill payments, and balance inquiries, while imposing strict security requirements such as session timeouts of five minutes inactivity or twenty minutes total duration. It mandates that authentication processes remain under the exclusive responsibility of the credit institution and prohibits technology-based agents from accessing, processing, or storing client authentication factors.
DOF: 11/07/2024
RESOLUTION modifying the General Provisions applicable to credit institutions
With a seal apart bearing the National Coat of Arms, which says: United Mexican States.- TREASURY.- Ministry of Finance and Public Credit.- National Banking and Securities Commission.
The National Banking and Securities Commission, prior agreement of its Board of Directors,
on the basis of what is provided by articles 46 Bis 1; 46 Bis 2; 52, eighth paragraph; 96 Bis, first paragraph and 98 Bis of the Credit Institutions Law, as well as 4, sections XXXVI and XXXVIII; 12, section XV and 16, sections I and VI of the Law of the National Banking and Securities Commission, and
CONSIDERING
That, in accordance with article 78 of the General Law for Regulatory Improvement and with the purpose of reducing the compliance cost of these provisions, the National Banking and Securities Commission, through the issuance of the "Resolution modifying the General Provisions applicable to general warehouses, exchange houses, credit unions and multiple-object financial companies regulated" published in the Official Journal of the Federation on April 26, 2018, adjudicated by the National Commission for Regulatory Improvement through letter COFEME/18/0413, contained in file 05/0006/ 020218 eliminated the obligation for credit unions to have an opinion on the receipt of loans from members and recognition of joint liability;
That, the General Provisions applicable to credit institutions establish the possibility that said institutions enter into commission contracts with third parties who act in their name to offer and carry out banking operations in the establishments of said latter parties, which they do through operators who interact in person with the user public;
That, the network of commissioners has allowed the geographic expansion coverage of the Mexican Financial System, being present in 75% of the municipalities in the country, which exceeds the coverage of both bank branches and automated teller machines;
That, since the coverage of telecommunications networks is greater than that of the physical establishments of the commissioners, it is convenient that credit institutions, especially those that do not possess physical infrastructure or Internet applications, integrate their services into the digital platforms of the commissioners and specialized companies, taking advantage of the infrastructure of these and even the consolidated customer base of the same. The foregoing, it is estimated that it mitigates some of the difficulties presented by the face-to-face channels such as the risk and cost associated with the use of cash, and the cost that represents for the user to travel to the establishments;
That, likewise, the Mexican financial authorities have issued diverse regulation that allows credit institutions (i) to offer their services and products outside their branches by taking advantage of the technology available in the markets, and (ii) to mitigate the risks to which they are exposed, with the purpose of maintaining and fostering the sound and balanced development of the Mexican Financial System as a whole, in protection of the interests of the public;
That, for all the above, the present "Resolution modifying the General Provisions applicable to credit institutions" regulates the figure of the technology-based commissioner and seeks to allow credit institutions to contract with commissioners, allowing them to offer and carry out, on behalf of said institutions, to the general public some banking services and products through digital access channels in order to expand access to them among the public. In addition to the above, said Resolution also seeks to establish, among others, the contractual obligations and responsibilities that credit institutions have with said commissioners, and
That, in order to mitigate identity theft, the exclusive responsibility of credit institutions is established in the process for authenticating client operations, as well as the establishment of a secure communication channel between them, to execute client instructions, has resolved to issue the following:
RESOLUTION MODIFYING THE GENERAL PROVISIONS APPLICABLE TO CREDIT INSTITUTIONS
UNIQUE.
RESOLUTION MODIFYING THE GENERAL PROVISIONS APPLICABLE TO CREDIT INSTITUTIONS
INDEX
TITLE FIRST to FOURTH . . .
TITLE FIFTH . . .
Chapter I to X . . .
Chapter XI . . .
First Section . . .
Second Section . . .
Subsection A Of commissioners with physical establishments
Subsection B Of technology-based commissioners
Subsection C Complementary provisions
Second Section Bis to Fourth . . .
Chapter XII to XV . . . "
" Article 1.- . . .
I. to XXX. . . .
XXXI. Encryption: to the mechanism that Institutions and technology-based commissioners referred to in Subsection B of the Second Section, Chapter XI of Title Five of these Provisions must use to protect the confidentiality of information through cryptographic methods in which algorithms and encryption keys are used.
XXXII. to XLIV. . . .
XLIV Bis. Asymmetric Mathematical Cryptography: to the Encryption methods that employ a pair of encryption keys known as public key and private key, which are mathematically related in such a way that information Encrypted with one of the keys can only be decrypted with the associated key.
XLV. to LXXXII. . . .
LXXXIII. Technological Infrastructure: to computing equipment, data processing and communications installations, equipment and communications networks, operating systems, databases, applications and systems used by Institutions to support their operation. Likewise, it also refers to the computing equipment, data processing and communications installations, equipment and communications networks, operating systems, databases, applications and systems used by technology-based commissioners referred to in Subsection B of the Second Section, Chapter XI of Title Five of these Provisions to support the operation agreed upon between said commissioners and the Institutions.
LXXXIV. to CXCVII. . . . "
" TITLE FIFTH . . .
Chapter XI . . .
First Section . . .
Articles 317 and 317 Bis. - . . .
Article 318.- . . .
I. . . .
Likewise, in no case, said commissioners may carry out approvals and openings of active, passive and service operation accounts, unless it concerns operations provided for by Article 319, sections IX and X and Article 319 Bis of these provisions.
II. Have a report and flowchart that specify the operational or database and computer system administration processes, the information exchanged in said processes, the physical location of the Institution's servers and the technology-based commissioner, as well as the name, address and the contract that technology-based commissioners agree with third parties for the provision of on-demand computing services and technological infrastructure through the Internet to support their operation that are subject to the services to be contracted. Likewise, they must have the policies and criteria to select the third party, which will be oriented to evaluate the experience, technical capacity and human resources of the third party with whom the service is contracted with adequate levels of performance, reliability and security, as well as the effects that could occur in one or more operations carried out by the Institution.
. . .
. . .
III. . . .
a) . . .
and 2. . . .
Deliver, at the request of the Institution, to the external auditor of the Institution itself and to the Commission or to the third party designated by said Commission, books, control figures, information structures, reports, operation tests, records, manuals and documents in general that prove and take evidence regarding compliance with these provisions, related to the provision of the service or commission in question, which may be delivered digitally and signed with Advanced Electronic Signature or Reliable. Likewise, permit access to responsible personnel and their offices and installations in general, related to the provision of the service in question.
and 5. . . .
In the case of employees or officials of the commissioners referred to in Article 319 Bis, who are in charge of executing the processes agreed upon in the commercial commission contract with the Institution in question in terms of this Article and Articles 319 Bis to 319 Bis 5 of these Provisions, they must be identified by the technology-based commissioner in terms of Annex 58 of these Provisions. Likewise, Institutions must agree with the commissioners referred to in the previous paragraph, the written delivery of a document containing the following information, prior to operating with the User Public in order to identify them:
i. Full name without abbreviations.
ii. Employee number.
iii. The processes of which the employee or commissioner official will be in charge in relation to Articles 319 Bis to 319 Bis 5.
iv. Institutional email of the employee or official.
This document must be signed by the employee or commissioner official, for which they may use their Advanced Electronic Signature. Likewise, in the event that there is a change of the employee or commissioner official referred to in the first paragraph of this numeral, the commissioner must notify the Institution of said change within two business days that the corresponding designation has been made in the terms indicated in this numeral.
. . .
b) . . .
The restrictions and conditions regarding the possibility that the third party subcontracts, in turn, the provision of the service. In no case, the foregoing, implies that the subcontracted third party may carry out Operations and functions on its own behalf or different from those agreed upon in the service provision or commission contract respective for purposes of what is provided for in this Chapter. Likewise, the third parties with whom Institutions contract cannot subcontract the services or commissions referred to in Article 319 Bis of these Provisions, except for the contracting of services corresponding to on-demand computing and technological infrastructure through the Internet to support their operation.
. . .
The mechanisms for the resolution of disputes relative to the service provision or commercial commission contract. In the same manner, it must provide for the mechanisms for the resolution of disputes relative to the contract between the commissioner and a subcontracted third party.
and 5. . . .
The terms, conditions and processes for the commissioner or service provider to guarantee to the Institution the transfer, return and secure elimination of the information subject to the contracted service when it ceases to provide it. Regarding the commissioners referred to in Article 319 Bis, Institutions must require of these to observe the requirements for the secure handling of information in terms of Section Eighth Bis "Of information security", of Chapter VI "Internal Controls" of Title Second "Prudential Provisions" in order to protect the information of clients, potential clients and of the Institution.
. . .
. . .
IV. and V . . . .
VI. Verify that third parties, shareholders of these and, if applicable, subcontractors, as well as commissioners and their shareholders, if applicable, the Administrator of Commissioners and shareholders of these latter, do not fall within the official lists issued by Mexican authorities, international organizations, intergovernmental groups or authorities of other countries, of persons linked or probably linked with operations with resources of illicit origin, terrorism or its financing, or with other illegal activities. To accredit the foregoing, it will suffice for the Institution to state in the written application it presents that it ensured that the persons mentioned in this section were not related in said official lists at the time of their hiring. Additionally, the Institution must state, in the same written application, that it knows the business to which the commissioner is dedicated.
VII. . . .
. . .
. . .
. . .
Article 318 Bis and 318 Bis 1. - . . .
Second Section . . .
Subsection A Of commissioners with physical establishments
Article 319.- . . .
Subsection B Of technology-based commissioners
Article 319 Bis. - Institutions may enter into commercial commission contracts with third parties who act at all times in name and on behalf of the former before clients or potential clients through the Internet pages or computer applications of said commissioners, with the exception of the Internet pages or computer applications that will perform Client Authentication, change or update of Authentication Factors and update of the client's contact medium in accordance with what is established in Articles 319 Bis 2, 319 Bis 3, 319 Bis 4 and 319 Bis 5, without prejudice to the other obligations applicable in terms of Article 318 of these Provisions, as well as of this Section, additionally observing the following requirements:
I. Institutions may only contract with the commissioners referred to in this article, the carrying out of the banking operations listed below and that will be executed in the client session referred to in Article 319 Bis 2 of these Provisions:
a) Opening of level 2 accounts and transfers of resources associated with said accounts.
b) Granting of credits for amounts not greater than three thousand UDIs.
c) Payment of goods and services.
d) Balance and movement queries of the products and operations that the client has contracted and celebrated with the Institution, respectively, through the technology-based commissioner.
All these operations must observe what is provided for in the current provisions of the Secretariat, Commission, Bank of Mexico and other applicable regulation.
II. Institutions must establish mechanisms and procedures to ensure that, through the Internet pages or computer applications of the commissioner in question, personalized, sufficient and clear information is provided to clients or potential clients of the Institutions regarding the following:
a) The responsibilities of the commissioner and of the Institution towards clients regarding the use of: (i) the information that the client provides them, and (ii) the Internet pages, computer applications and Technological Infrastructure of the commissioner.
b) The acknowledgment that the contracting service is with the Institutions themselves and that the commissioner is a channel or means to carry out the operations referred to in section I of this article, as appropriate.
c) The Authentication processes referred to in Articles 319 Bis 2 and 319 Bis 3 that will be followed in order to:
d) The right of the client to use the Category 2 Authentication Factor defined by this in the terms of Article 319 Bis 2, to Authenticate directly in the Mobile Banking or Internet Banking services of the corresponding Institution, in order to carry out operations or modify their Authentication information.
III. Institutions must stipulate in the contract they enter into with the commissioner that the latter may not know, process, transmit, store, modify or copy under any circumstance the information of the Authentication Factors associated with the clients of the Institution, therefore it must attend to what is provided for in Articles 319 Bis 2, 319 Bis 3, 319 Bis 4 and 319 Bis 5.
IV. Institutions must agree with the commissioner that the aggregated and disaggregated information that derives from the contractual relationship with the Institution may not be used, shared, sold or granted to any third party other than those provided for in Article 318, section III, subsection a) numeral 7 of these Provisions. Without prejudice to the foregoing, Institutions may agree upon the conditions under which the technology-based commissioner will use, process and transmit to this the aggregated information of clients for its treatment.
V. Institutions must contract with commissioners that the inactivity periods of the session mentioned in Article 319 Bis 2 may not last more than five minutes and the total duration of the session may not exceed twenty minutes, whether there is activity or not on the part of the client. In these cases, the session must be closed automatically, as well as any communication that exists between the Institution and the client, also revoking the permissions granted to the commissioner for access to client information.
VI. Institutions must contract with the commissioner that the Internet pages or computer applications of the commissioner provide to clients, through their email, a record of all operations and instructions carried out during the session referred to in Article 319 Bis 2, which must be sent in Encrypted form at the end of said session.
VII. Institutions must publish on their Internet page the list of certificates and public keys of their commissioners, previously
verified,
in accordance with
what is established in
the second fraction of
Article 319 Bis
the Institutions must provide
to the Commission
the direct link
to said list,
in order for
the Commission to make it available
to the User Public
for consultation on its
Internet page.
For the purposes of the foregoing,
the Institutions must verify
periodically the validity
of the certificates and
public keys that are contained
in said list.
Likewise,
the Institutions must notify
the Commission of any
change or update that is made
to the link or to the content
of said list.
The provisions of
Article 318,
third fraction,
subsection b),
numeral 1,
as well as Article 321 Bis 2,
both of these Provisions,
shall not apply,
except for contracting with third parties
to provide
on-demand computing services
and technological infrastructure
through the Internet
to support their operation,
inasmuch as the operations
referred to in this Section
cannot be subcontracted.
Article 319 Bis 1.
with the commission agents
referred to in Article 319 Bis
of these Provisions,
the identification and segregation
of the Technological Infrastructure,
Internet pages and
computer applications that are
property of the Institution
and those of the commission agent,
respectively,
in order to establish
a secure channel
for the exchange of
Authentication information
of the clients and their operations,
said channel must comply with,
at least, the following requirements:
I. The exchange of information
between the Technological Infrastructures
of the Institutions and
commission agents must be
Encrypted using, at least,
a method of
Asymmetric Mathematical Cryptography
complying with what is established
in Articles 93,
93 Bis, 97 and 107
of the Code of Commerce.
II. Prior to
the commission agents offering
the Institution's operations
to clients or
potential clients,
the commission agent and the
corresponding Institution must
reciprocally provide (i)
a list with the
keys and public certificates associated
with the Technological Infrastructure
that are their property or
under their control, respectively,
through which each party will process
the exchange of the permissions associated
with the Authentication of the client
and their operations, and (ii)
the information that allows
identifying the Technological Infrastructure
of both the Institution
and the commission agent,
in order for the Institution
and the commission agent
to mutually authenticate
to allow the exchange of the permissions associated
with the Authentication of the client
and their operations.
Likewise, the Institution must verify
the reliability of the
keys and public certificates of the
commission agent of technological basis
in order to identify those that
might be apocryphal.
III. The Technological Infrastructures
of the Institution and
of the commission agent must carry out
a mutual authentication protocol
to allow the exchange of the permissions associated
with the Authentication of the client
and their operations, this with the purpose
that only the commission agent and the Institution
have access to said information.
IV. Once the exchange of
Authentication information of the clients
and their operations is carried out,
the respective information exchanged
between the Technological Infrastructure
of the Institution and
that of the commission agent,
must be signed using the
private key of the sender
of the information and, subsequently,
Encrypted with the
public key of the receiver
of the information.
In this case, depending on
the direction of the flow of
the information, both the
Institution and the commission agent
will have the status of
sender or receiver.
Article 319 Bis 2.
with the commission agents
referred to in Article 319 Bis
of these Provisions,
the opening of
level 2 accounts and
granting of credit for amounts
not greater than three thousand
Investment Units,
without prejudice to compliance with
the obligations provided for in
other provisions, must observe
the following for purposes of
Authentication of potential clients:
I. Through the
Internet page or computer application
of the commission agents,
the client or
potential client must be informed
that their Authentication will be carried out by the
corresponding Institution,
for which the latter will request
a Category 2 Authentication Factor
and a Category 3 Authentication Factor,
in accordance with what is provided by
Article 310 of these Provisions.
Likewise, the client must be informed
that in order for said Authentication to take place,
they will be redirected to the
Technological Infrastructure of the Institution,
in order for the client to be able to
define their Category 2 Authentication Factor
and enter their Category 3 Authentication Factor.
II. Once the client is
on the Technological Infrastructure
of the Institution,
the client must be requested to:
i. Define their Category 2 Authentication Factor.
ii. Provide their
electronic mail or a
instant messaging contact medium that uses
Encrypted communication protocols,
in order for the Technological Infrastructure
of the Institution to send
to said contact medium one of the
Category 3 Authentication Factors.
iii. Enter the Category 3 Authentication Factor
on the Technological Infrastructure
of the Institution in order for it to be
verified and the client to be associated
with the Category 2 Authentication Factor.
III. After having established the
Category 2 Authentication Factor and entered the
Category 3 Authentication Factor referred to in
the first fraction of this article,
the Institution will grant the
commission agent the necessary permissions
to be able to access
the client's information and the client
will be redirected to the
Internet page or computer application
of the commission agent so that said client can
carry out the opening of the
account referred to in Article 319 Bis,
first fraction of these Provisions.
In the case of the redirections
referred to in this article,
both the Technological Infrastructure
of the commission agents and
those of the Institutions,
as the case may be, must inform
in an explicit, clear and
visible message to the client,
the reasons why the
respective redirection is being carried out
and at what step of the
Authentication process the client is.
The permissions granted to the
commission agent for access to
the client's information referred to in
the third fraction of this article,
will be revoked once the
session on the
Internet page or computer application
of the commission agent is finalized to carry out
the operations referred to in Article 319 Bis
of these Provisions.
A session will be understood as the
interaction between clients and the
Internet pages or computer applications
of the technological basis commission agent,
initiated by the Authentication of the client
and finalized after the interval
referred to in Article 319 Bis
fraction V, during which
the operations referred to in
Article 319 Bis fraction I can be carried out.
The Institutions must allow
their clients to use the
Category 2 Authentication Factor defined by
them under the terms of this article,
to Authenticate in the
Mobile Banking or Internet Banking services
of the corresponding Institution.
Article 319 Bis 3.
with the commission agents
referred to in Article 319 Bis
of these Provisions,
the celebration of the
operations referred to in said article,
must inform the clients,
prior to the execution of the
respective operation, that they will be requested
the Category 2 Authentication Factor that they defined
previously with the Institution and that they enter a
Category 3 Authentication Factor,
so that it can be
Authenticated by the Institution.
In this case, the Institutions must provide
the Technological Infrastructure so that the client
enters the Category 2 Authentication Factor and
the Category 3 Authentication Factor is generated and sent
that will be requested from the client
to Authenticate it.
Once the client is on the Technological Infrastructure
of the Institution,
the client must be requested to:
i. Enter their Category 2 Authentication Factor
so that it is verified with the information stored by
the Institution.
ii. Enter the Category 3 Authentication Factor
in the Electronic Means of the Institution that they receive
in the electronic mail or the
instant messaging contact medium that they provided to the Institution
previously.
After the Institution has carried out the
Authentication of the client,
the Institution will grant the
commission agent the necessary permissions
to be able to access
the client's information and the client
will be redirected to the
Internet page or computer application
of the commission agent so that this can
carry out the operations provided for in
the first fraction, of Article 319 Bis
of these Provisions.
In the case of the redirections
referred to in this article,
both the Technological Infrastructure
of the commission agents and
those of the Institutions,
as the case may be, must inform
in an explicit, clear and
visible message to the client,
the reasons why the
respective redirection is being carried out
and at what step of the
Authentication process the client is.
Once the Authentication of the client is carried out,
the Institution must allow the
commission agent access to
the client's information in order for the client to be able to
carry out the operations provided for in
Article 319 Bis through the
Technological Infrastructure of the commission agent,
exclusively for the session, understanding by
session what is established in
Article 319 Bis 2.
The permissions granted to the
commission agent for access to
the client's information referred to in the
fourth paragraph of this article,
will be revoked once the
session on the graphical interface defined by the
commission agent on their
Internet page or computer application is finalized to carry out
the operations referred to in Article 319 Bis
of these Provisions.
Article 319 Bis 4.-
The instructions of the clients for the
execution of operations that the Technological Infrastructure
of the commission agent receives referred to in
Article 319 Bis must be Encrypted.
For the foregoing, the
Internet page or computer application
of the commission agent must carry out the
Encryption with, at least, the
key or the public certificate of the
commission agent, which (i)
must be previously loaded on the
Internet pages or computer applications
of the commission agent or (ii)
must be updated by an
instruction from the Technological Infrastructure
of the commission agent.
Article 319 Bis 5.
the clients to modify the
Category 2 Authentication Factor,
as well as their
electronic mail or instant messaging contact medium that uses
Encrypted communication protocols through which they receive
the Category 3 Authentication Factor,
which they defined under the terms of
Article 319 Bis 2,
for which the
Internet page or the computer application
of the commission agent must provide an
explicit, clear and visible option or link that carries out the
redirection towards the Technological Infrastructure
of the Institution,
in order to modify said
Authentication Factors, electronic mail or
instant messaging contact medium that uses
Encrypted communication protocols.
In order for the respective modification to take place,
what is provided in Article 319 Bis 2 must be complied with.
Section C
Complementary Provisions
Article 320.-
The Institutions that celebrate
commercial commission contracts that have as their object to carry out the operations
referred to in Articles 319 and 319 Bis
of these provisions through
commission agents, will require
presenting for authorization of the Commission,
prior to the signing of the
commercial commission contract and for
a single occasion, a
strategic business plan that contemplates the
totality of the operations provided for in the
referenced articles that they could carry out, and must include the
model of commercial commission contract that will serve as
the basis for the contracts that are
celebrated with each one of the
commission agents with which it is intended to contract.
In the case of development banking institutions,
the authorization of the strategic plan may be
requested once the exception referred to in
Article 47 of the Law is obtained.
. . .
The strategic plan referred to in the first paragraph
of this article must provide for compliance with the
requirements indicated in Article 318,
fractions I, III, V and VII
of these provisions,
establishing the implementation dates of each
of the operations indicated therein.
Likewise, the aforementioned plan must contain the
following aspects:
I.
to V.
. . .
. . .
Article 321.-
When the Institutions intend to carry out
operations other than those indicated in the
strategic plan that was authorized to them in accordance with
Article 320 above, or well, intend to operate with
new commission agents not provided for in the
authorized plan or implement a new technology to operate with
commission agents or Administrators of Commission Agents
previously authorized, must be subject to
the following:
I.
. . .
II. In the case of the
operations referred to in the
fractions I, IV and XII of Article 319
of these provisions,
they must present a notice to the Commission,
must manifest in the same that the
operation will be carried out under the
contract to be celebrated between the
Institution and the commission agent,
under the terms authorized by the Commission,
indicating in its case, if the
contract that intends to celebrate with the
commission agent presents any variation that falls on a
modifying agreement with respect to the model contract,
in which case it must remit said project.
The notice referred to in this fraction must be sent to the
Commission, being able to initiate the
operations referred to in this fraction on the
day following the presentation of the
corresponding notice, on the understanding that the Commission may at any
moment require that the operations not be
carried out through any or some commission agents in
particular when these fail to comply with these
provisions.
Likewise, the Institutions may incorporate in a
single notice all the operations of the
indicated in this fraction, that will be
effectuated with the same commission agent.
. . .
III. In the case of the
operations referred to in the first fraction of Article 319 Bis
of these Provisions,
they must request authorization from the Commission,
attaching to their request letter the following:
a) The technical requirements indicated in Annex 59 of these
provisions and, in its case, the description of the new
technology and its implementation.
b) The draft commercial commission contract for operating with
the commission agent, which contemplates the aspects
referred to in Articles 318, fraction III and 324, with
the exception of the second paragraph of fraction I,
of these provisions, in accordance with the strategic plan of
business authorized.
Additionally, for the operations referred to in
fractions I, II and III above, the Institutions must present
along with the request for authorization or notice,
as applicable, the Internal Certification Format of
Commission Agents (FCIC) with information on
pre-operational tests, duly filled out based on the
new operation they intend to carry out.
For this they must download the updated format of said
report available on the Internet site of the
Commission.
Article 321 Bis.-
. . .
Article 321 Bis 1.-
The Institutions must provide to the
User Public and to the general public,
through their Internet page or in their
branches, as applicable,
the information of the commission agents that they have
enabled to carry out the operations referred to in
Article 319 and Article 319 Bis
of these provisions,
specifying the operations that can be carried out in each
one of them and the maximum amounts authorized per
operation.
Likewise, the Institutions must inform regarding
the commission agents, whenever applicable,
the following:
I. The legal domiciles of the
commission agent, comprising at least, their
tax and commercial domicile;
II. The list of the
physical attention modules with their
physical address;
III. The Internet pages
through their Internet domain name,
such as those known as
URL ("Uniform Resource Locator");
IV. The names and logos of the
mobile applications, the name of the administrator and owner of the
mobile application and the digital stores
where they are available, in their case;
V. The list of all the
official telephone numbers that the commission agents themselves use
which must be enabled to receive
calls from the public, in addition to this, there must be the
option of offering telephone
attention through an employee of the
technological basis commission agent;
VI. The list of official
electronic contact mails;
VII. The social networks used for
promotion, and
VIII. Any other
communication channel that is used to interact with
the public and is not contemplated in the
previous fractions.
Likewise, the Institutions must verify that the
commission agents inform the clients,
through the receipts or proofs of the
operations they carry out, visible advertisements in
the establishments, technological platforms or by
any other means they use to promote with the
User Public their operations as
commission agent, that they act in the name and on behalf of the
corresponding Institution represented.
Articles 321 Bis 2 to 323.
Article 324.-
. . .
I.
to IV.
. . .
IV. Bis.
In the case of the commission agents that present themselves
to the clients or potential clients through their
Internet pages or computer applications,
what is provided in Articles 319 Bis, 319 Bis 1, 319 Bis 2, 319 Bis 3, 319 Bis 4 and 319 Bis 5 must be complied with.
V.
and VI.
. . .
VII.
. . .
a) Conditioning the
execution of the banking operation to the
acquisition of a product or service, in the case of the
operations referred to in fractions I to X and XII of Article 319 and the
first fraction of Article 319 Bis of these
provisions.
. . .
b)
to f)
. . .
g) Contracting exclusivity conditions with the
Institution in question, without prejudice to the duties of
confidentiality of the information by the commission agent towards each
Institution with which they agree on the
services referred to in this article.
VIII.
to XI.
. . .
XII. In the case of the
operations referred to in fractions IX and X of Article 319 and Article 319 Bis,
first fraction of these provisions, the obligation of the
commission agent to gather from the client the
necessary information and transmit it in time and form to the
Institution, in order to comply with what is provided in
Article 115 of the Law and the "General Provisions
referred to in Article 115 of the Law of Credit Institutions",
issued by the Secretariat, or those that replace them.
XIII. The obligation of the commission agent to elaborate
remediation plans regarding the findings of the
reviews and security tests carried out to those referred to in
the ninth fraction of this article and deliver them to the
Institution.
The Institutions, in the carrying out of the operations
referred to in this Second Section of Chapter XI,
cannot hire commission agents in such a way that they provide
their services exclusively to them.
Article 325.-
. . . "
TRANSITORY PROVISIONS
FIRST. -
This Resolution will enter into force on the
day following its publication in the Official Journal of the
Federation, except as provided in the following
transitory article.
SECOND. -
The Institutions will have eighteen months counted from
the entry into force of this Resolution,
to modify the contracts that they have
celebrated with the third parties referred to in Chapter XI of these
Disposiciones
and give simultaneously with the obligations derived from the modification of said contracts, so that with respect to the reforms applicable provided for in Articles 318, paragraphs II and III, subparagraph a), numeral 3 and subparagraph b), numeral 1, second paragraph and numeral 3; Article 321 Bis 1; Article 324, paragraph VII, subparagraph g); Annex 58, paragraph I, numeral 5, second paragraph, paragraph III, numeral 2, second paragraph, subparagraph b) and subparagraph d), third paragraph, subparagraph b) and Annex 59, numeral 2 and 6.
Respectfully
Mexico City, July 3, 2024. - President of the National Banking and Securities Commission, Dr. Jesús de la Fuente Rodríguez .- Rubric.
ANNEX 57
CRITERIA FOR EVALUATING THE EXPERIENCE AND TECHNICAL CAPACITY OF COMMISSION AGENTS THAT OPERATE UNDER THE SECOND SECTION OF CHAPTER XI OF TITLE FIVE OF THE PROVISIONS
It will be presumed that commission agents have sufficient technical capacity when they declare under oath that they comply with the following:
Their personnel is trained to adequately operate the Electronic Media that the Institution makes available to them to authenticate banking clients.
Have the necessary infrastructure to carry out the processing of the operations subject to the banking service.
Be legal entities or natural persons with business activity and have (i) a permanent establishment, understood as any place of business where business activities are carried out, partially or totally, or independent personal services are provided, such as offices, branches, agencies, or other facilities on national territory, or (ii) make available to the User Public a web page or software application and Technological Infrastructure that allows carrying out the processes indicated in Chapter XI of these Provisions.
Have their own line of business.
Have honorability and a satisfactory credit and business history; to this effect, commission agents will be considered to meet this requirement if they:
a) Enjoy a good credit history according to Credit Information Reports and are up to date in the fulfillment of their credit obligations.
b) Have not caused, directly or through intermediaries, any loss, diminution, or detriment to the patrimony, to the detriment of credit institutions or issuing companies in the securities market.
c) Have not been declared in civil or commercial bankruptcy.
d) In their case, have not been convicted by a final judgment for an intentional crime that imposes a penalty of more than one year of imprisonment.
e) In their case, have not been convicted by a final judgment for intentional property crimes, regardless of the penalty.
f) In their case, have not been subject to inquiries or investigations of an administrative nature before the Commission for serious violations of national or foreign financial laws, or before other Mexican supervisory and regulatory institutions of the financial system or of other countries, which have resulted in any type of final and definitive resolution or agreement in which the interested party has not been expressly exonerated.
With respect to Entities of the Federal, State, or Municipal Public Administration, it will be sufficient that they comply with what is established in numerals 1 and 2 of this Annex and are expressly authorized by their law or regulations to provide the services or commissions in question.
Institutions may exempt from compliance with the requirements indicated in numerals 3, and 5, subparagraph a) of this annex, with respect to commission agents administered by a Commission Agent Administrator, provided that the said Commission Agent Administrator complies with all the requirements provided for by this annex.
ANNEX 58
TECHNICAL REQUIREMENTS FOR THE OPERATION OF ELECTRONIC MEDIA FOR THE OPERATIONS CONTEMPLATED IN THE SECOND SECTION OF CHAPTER XI OF TITLE FIVE OF THE PROVISIONS
The Electronic Media that Institutions use to guarantee the correct execution of banking operations carried out through commission agents and the security of the information of banking clients and the general public, must comply with the requirements referred to in this annex.
The Institution must have evidence of the verification of compliance carried out prior to the start of operations and at least once a year, of the following aspects and have it available to the Commission when it so requires.
With respect to Administrators of Commission Agents, these must verify that the commission agents that make up their network comply with what is established in this Annex.
For the purposes of this Annex, "Operator" will be understood as the employee of the commission agent who has access to the Electronic Media.
I. Requirements of Electronic Media
The Electronic Media must have the necessary mechanisms to carry out online transactions, that is, at the very same instant that the operation is carried out, updating the client's online balance except for the operations referred to in paragraphs I, IV, and XII of Article 319 of these provisions, where balance updates may be carried out in accordance with what is established by the operating rules of the respective Institutions.
For such purposes, service payment operations in cash or with debit card, or charged to Bank Accounts, cash deposit, credit payment in cash, and fund status; must be registered as a charge to the deposit account that the commission agent has with the Institution.
On the other hand, cash withdrawal and check payment operations must be registered as a credit to the same account.
In cases where the client's balance information is stored in devices such as integrated circuit cards or equipment located in the commission agent's facilities, online impact will not be considered the one carried out in such devices, provided that there are mechanisms for their periodic consolidation in the central systems of the Institutions.
With respect to the operations referred to in paragraphs I and IV of Article 319, as well as in paragraph I, subparagraph c) of Article 319 Bis, of these provisions and in case that processing is carried out through the batch scheme, controls must be maintained implemented for the secure sending of files, as well as for the reconciliation and settlement of the operations carried out through this medium.
Only the Electronic Media of the commission agents authorized by the Institution will have access to the infrastructure set up by it (use of dedicated lines, identification of physical or logical addresses, VPNs, digital signatures, among others).
The Institution's computer systems must authenticate the Electronic Media that commission agents use to carry out banking operations.
The Institution will be responsible for certifying the installation and use of the Electronic Media that the commission agent maintains for the carrying out of banking operations, as well as for establishing annual evaluations of said Electronic Media.
This certification may be carried out by the Institution, in its case, through its specialized technical areas in information security or internal systems audit, or well, through independent third parties, hired by the Institution itself, who must accredit to it that they have adequate technical credentials in the matter of computer or systems audit.
The aforementioned certification must consider at least that the Institution must ensure at all times that the electronic media used by commission agents maintain control mechanisms that prevent the reading and extraction of client information by unauthorized third parties.
It is the responsibility of the Institution to verify that the commission agent has policies and procedures for:
a) The configuration of the Technological Infrastructure that connects to the Institution's computer systems.
b) The administration of cryptographic keys used between commission agents and the Institution's systems.
All operations carried out through commission agents must generate electronic records that cannot be modified or deleted and in which at least the date, hour, and minute, the type and amount of the instruction, the banking client's account number, physical location of the window or medium through which the instruction was executed, as well as sufficient information that allows the identification of the personnel who carried out the instruction, as well as audit information that considers at least, client, IP addresses of origin and destination, date, hour, name of the application programming interface (API by its initials in English), type of request, version, and response code to effect having traceability of events in the systems of the Institution and of the commission agent.
The custody of said records must be the responsibility of the Institution.
II. Requirements for Identification of Operators and Authentication of banking clients.
With respect to the identification of the Operators of the technology-based commission agents referred to in numeral 6, of subparagraph a), of paragraph III, of Article 318 of these Provisions, what is mentioned in Section II Bis "Identification of Operators of technology-based commission agents" of this Annex must be observed.
Institutions must establish mechanisms for the process of generating and delivering the Authentication Factors that ensure that only the commission agent, and in its case, the Operators can know.
Criteria must be established for the characteristics of the length of the Passwords, Dynamic One-Time Passwords, or Access Keys of the Operators.
3 Bis. Validity of Passwords, Dynamic One-Time Passwords, or Access Keys of the Operators.
Institutions must establish criteria for the validity of the Passwords, Dynamic One-Time Passwords, or Access Keys, in order to strengthen the identification processes of the Operator of the technology-based commission agent.
In the case of Dynamic One-Time Passwords, their validity cannot exceed 1 minute and for Passwords or Access Keys that do not correspond to Category 4 Authentication Factors, this validity cannot exceed 90 business days.
Institutions must provide what is necessary to prevent the reading of the characters that make up the Passwords or Access Keys, as well as the Personal Identification Numbers (PIN) typed by banking clients, respectively, in the Electronic Media of access, both in their capture and in their display through the screen.
The Passwords or Access Keys and the Personal Identification Numbers (PIN) must be validated and stored through encryption mechanisms, whose cryptographic keys must be under the administration and control of the Institution in question.
At no time can commission agents have access to the data or algorithms related to said Passwords or Access Keys and Personal Identification Numbers (PIN).
Commission agents must have certifications of security standards of the card industry of the security and PIN transaction requirements (PTS) or their equivalents or those that, at the discretion of the Commission, allow the proper protection of the information stored, transmitted, or processed related to the entry of the Personal Identification Numbers (PIN) of banking clients and the data of bank cards.
For the carrying out through commission agents of consultations and operations that represent a charge to the banking clients' accounts, the latter must authenticate themselves through the Electronic Media with which the aforementioned operations are carried out using two different Authentication Factors.
The foregoing will not be applicable to the commission agents referred to in Article 319 Bis of these Provisions.
For the purposes of the foregoing, Institutions may opt for the combination of at least two of the following Authentication Factors and adhere to what is established in Chapter X of Title Five of these Provisions:
a) Debit or credit cards with security mechanisms such as cards with magnetic stripe and/or integrated circuit or "chip".
b) Personal Identification Number (PIN).
In the case that debit or credit cards are used, card readers must be used, such as PIN PADS, for the Authentication of banking clients, which must have a screen and a keyboard exclusively designed so that the banking client can enter the information of their respective card and their Personal Identification Number (PIN), as well as mechanisms that prevent their reading by third parties.
Commission agents must have certifications of security standards of the card industry of the security and PIN transaction requirements (PTS) or their equivalents or those that, at the discretion of the Commission, allow the proper protection of the information stored, transmitted, or processed related to the entry of the Personal Identification Numbers (PIN) of banking clients and the data of bank cards.
In the case of using a cell phone, the Personal Identification Number (PIN) must be entered directly on the keyboard of said phone.
Under no circumstances can the PIN information be stored on the cell phone without encryption mechanisms.
c) Biometric Factor.
In case of using biometric readers for the Authentication of banking clients, said readers must have mechanisms that ensure that it is the authorized client who carries out the operation, as well as implement mechanisms or procedures so that the commission agent does not store the processed information related to the biometric factors of the clients.
All administration and control of biometric information must be the sole responsibility of the Institution through the customer service channels they have established.
d) Cell phone.
In case of using cell phones for the Authentication of banking clients, Institutions must verify that the technology of said cell phones allows them to function as an Authentication Factor and that they have security mechanisms that prevent their duplication or spoofing.
Institutions cannot use the combination of the Authentication Factors referred to in subparagraphs a) and d) to authenticate their clients.
For the reception and operation of transactions requested by banking clients through the Electronic Media of commission agents, Operators must start a session and authenticate themselves through said Media.
The authentication processes must be validated by the Institution, through the mechanisms and controls that it deems appropriate.
It is the responsibility of the Institution to ensure that commission agents have said operator authentication mechanisms, for the carrying out of operations.
Blocking schemes for the Authentication Factors of the Operators must be established when an attempt is made to enter the Electronic Media incorrectly.
Under no circumstances can failed access attempts exceed five consecutive times without generating automatic blocking.
Under no circumstances can the Electronic Media used by commission agents allow the carrying out of operations or balance inquiries without the prior Authentication in terms of numeral 5 of section II "Requirements for Identification of Operators and Authentication of banking clients" of this annex, of the corresponding client.
Deposit and payment operations will be exempt from this case.
Likewise, with respect to banking operations that require the commission agent to access the balances of banking clients' accounts, said commission agent must, at all times, keep confidentiality regarding said operation and carry out prior to the respective access, the Authentication referred to in numeral 1 of section III "Electronic Media Operations" of this annex.
II. Bis Identification of Operators of technology-based commission agents
In addition to what is provided in paragraph II "Requirements for Identification of Operators and Authentication of banking clients" of this Annex, Institutions must request technology-based commission agents to carry out the identification of their Operators for the purposes of complying with what is established in numeral 6, subparagraph a), paragraph III of Article 318 of these Provisions.
For the foregoing, technology-based commission agents must request from their Operators, at least, a Category 2 Authentication Factor and a Category 3 Authentication Factor, observing the following:
a) The technology-based commission agent must generate and provide to the Operator a Category 3 Authentication Factor, which will be sent to the institutional email that the Operator provided in the document referred to in numeral 6, subparagraph a), paragraph III of Article 318 of these Provisions.
b) The technology-based commission agent must request from the Operator the Category 3 Authentication Factor that was provided to him as established in subparagraph a) of this numeral.
c) The Operator must enter in the Technological Infrastructure of the technology-based commission agent the Category 3 Authentication Factor referred to in subparagraph b) of this numeral, verifying the validity of said Factor.
d) Once the technology-based commission agent verifies the validity of the Category 3 Authentication Factor referred to in the previous subparagraph c), the technology-based commission agent must request from the Operator to define a Category 2 Authentication Factor, which can only be used by him in order to protect his identification information.
a) Prior to the technology-based commission agent carrying out the identification of the Operator, the technology-based commission agent must generate and provide to the Operator a Category 3 Authentication Factor.
This Category 3 Authentication Factor must be sent to the institutional email that the Operator provided in the document referred to in numeral 6, subparagraph a),
fraction
III
of
Article
318
of these
Provisions.
b)
The technological base commissionaire must
request from the Operator the
Category 2 Authentication Factor
established by
the Operator and the
Category 3 Authentication Factor
provided by the technological base commissionaire,
for the purpose of
performing the identification of the Operator.
The technological base commissionaire must
provide the Operator with the
necessary means to
modify the
Category 2 Authentication Factor
must observe what is provided in
numeral 1 of this
fraction.
In the event that an Operator ceases to perform the processes reported in the document delivered to the Institution as established in the second paragraph of numeral 6, subsection a), fraction III of Article 318 of these Provisions, the technological base commissionaire must revoke the access permissions of its Technological Infrastructure, in order to protect the integrity of the processes executed by the technological base commissionaire and the operability of the Institution.
III. Operation of Electronic Media
Validation of destination account structure.
The Electronic Media of the commissionaires must validate, based on the information available to the Institution, the structure of the destination account number or contract, whether they are deposit accounts, service payments, Standardized Banking Key, credit cards or other payment methods.
Generation of operation receipts.
The Electronic Media must automatically generate the operation receipts that the Institutions issue for each operation, without any intervention on the part of the commissionaire's personnel.
Such operation receipts will be different from those used by the commissionaires to record the operations of their commercial business and must include what is provided by the General Provisions of CONDUSEF in matters of transparency and sound practices applicable to credit institutions.
In addition to the aforementioned provisions, Institutions must consider the following in the operation receipts:
a)
The data that allow the banking client to identify the account with respect to which the operation was carried out.
At no time should the complete account number be displayed on the receipts.
b)
The information from balance inquiries, when the client has requested and authorized it, in which case it must be provided only to the client through the corresponding receipt, the commissionaire's Internet page or computer application.
The commissionaire may not safeguard or conserve information related or associated in physical or digital media.
c)
The identification of the Institution and of the commissionaire with which the operation was carried out, specifying in the latter case, the address of the establishment or the address of the Internet page or computer application through which the instruction was executed.
d)
The information that allows the identification of the commissionaire's personnel who carried out the instruction where, at least, the full name of the commissionaire's official or employee appears.
When the limits referred to in Article 323 of these provisions are exceeded, as applicable, the requested operations cannot be carried out, so the Electronic Media must generate receipts indicating to the banking client this situation.
For such purposes, a receipt must be provided that includes the following legends:
a)
In the case of the limit referred to in Article 323, fraction II, subsection b) of these Provisions:
" Transaction not performed for having exceeded your permitted limit. Go to a bank branch. "
b)
In the case of the limits referred to in Article 323, fractions I and II, subsection a) of these Provisions, as applicable:
" Transaction not performed " .
Under no circumstances should the client's address be shown on the operation receipt.
Likewise, the address should not be shown to any employee or official of the commissionaire during the generation of said receipt.
Institutions will make available to their clients in the operation receipts the information regarding the telephone number and electronic mail of the specialized unit for user attention that the Institution must have in terms of the Law on Protection and Defense of the User of Financial Services, as well as that of the Institution's attention center.
All operation receipts that are celebrated through commissionaires will have probative value for the purposes of any clarification and must be recognized in those terms by the Institutions that issue them.
Monitoring of operations.
The Institution must establish continuous mechanisms through computer tools that allow it to monitor the activities carried out by the Operators through the Electronic Media of the commissionaires in order to detect transactions that deviate from the usual operational parameters.
Storage of Sensitive User Information in Electronic Media of the commissionaires.
In cases where, for operational and technical reasons, it is necessary to store partially or totally Sensitive Information of the User of the Institution in the Electronic Media of the commissionaire, the institution must verify that encryption mechanisms exist.
Likewise, commissionaires may not issue a duplicate of the balance inquiry receipts or keep copies of these.
The Institution must contract with the technological base commissionaire that, when clients access the graphical Interfaces of the commissionaire's Internet page or computer applications, these must provide detailed and sufficient information that identifies the celebration of operations with the Institution for which it may use images, letters or visible colors related to the same.
The Institution is obliged to notify its clients, as soon as possible and through the communication means that it makes available to them and that they have chosen for that purpose, the operations referred to in subsections a), b) and c) of fraction I, of Article 319 Bis carried out through the technological base commissionaires.
IV. Information Security
Logical segregation, or logical and physical segregation of the different networks in different domains and subnets, depending on the function they develop or the type of data that is transmitted, including segregation of the productive environments from those of development and testing, as well as perimeter security components and networks that ensure that only authorized traffic is permitted.
In particular, in those segments with links to the outside, such as Internet, providers, authorities, other networks of the Institution or headquarters, Administrators, commissionaires and other third parties, consider safe zones, including those known as demilitarized zones (DMZ).
Secure configuration of components, considering at least, ports and services, permissions granted under the principle of least privilege, use of removable storage media, access lists, manufacturer updates and reconfiguration of factory parameters.
Security measures for their protection, as well as for the access and use of the information that is received, generated, transmitted, stored and processed in the technological infrastructure, having at least the following:
a)
Identification and authentication mechanisms of all and each of the users of the technological infrastructure, which allow them to be recognized unequivocally and ensure access only to persons expressly authorized for this purpose, under the principle of least privilege.
For the foregoing, pertinent controls must be included for those users of the technological infrastructure with greater privileges, derived from their functions, such as, that of database and operating system administration.
b)
Encryption of information according to the degree of sensitivity or classification that the Institution determines and establishes in its policies, when such information is transmitted, exchanged and communicated between components, or stored in the technological infrastructure or accessed remotely.
c)
Access keys with composition characteristics that prevent unauthorized access, considering processes that ensure that only the user of the Technological Infrastructure is the one who knows them, as well as security measures, encryption in their storage and mechanisms to change access keys every 90 days or less.
d)
Controls to automatically terminate unattended sessions, as well as to prevent simultaneous unauthorized sessions with the same user identifier of the technological infrastructure.
e)
Security mechanisms, both of physical access, as well as of environmental and electrical energy controls, that protect the technological infrastructure and allow operation in accordance with the specifications of the provider, manufacturer or developer.
f)
Validation measures to guarantee the authenticity of the transactions executed by the different components of the technological infrastructure, considering, at least the following:
i.
The veracity and integrity of the information.
ii.
The authentication between components of the technological infrastructure, which ensure that only legitimate service requests are executed from their origin to their execution and registration.
iii.
The messaging, communication and encryption protocols, which must ensure the integrity and confidentiality of the information.
iv.
The identification of atypical transactions, anticipating that the applications have automatic alert measures for their attention by the corresponding operational areas.
g)
The update and maintenance of digital certificates and components provided by service providers that are integrated into the transaction execution process.
Automated mechanisms to detect and prevent events and information security incidents, as well as to prevent unauthorized incoming and outgoing data connections and flows and information leakage, considering among others, removable storage media.
Policies and procedures for the administration of encryption keys used by the Institution and the commissionaire, as applicable.
Policies and procedures for secure deletion for the destruction of data when they are no longer necessary, or upon conclusion of the commercial commission.
Policies and procedures for the management of information security incidents of the commissionaires that ensure the detection, classification, attention and containment, investigation and, as applicable, digital forensic analysis, diagnosis, reporting to competent hierarchical levels, solution, follow-up and immediate communication to the Institution and counterparts of said incidents.
Registration in databases, of the incidents, failures or vulnerabilities detected in the Technological Infrastructure of the commissionaire, which includes at least the information related to the detection of failures, operational errors, attempts at computer attacks and those effectively carried out as well as loss, extraction, alteration, loss or improper use of information of the Users of the Technological Infrastructure of the commissionaire, where the date of the event and a description of it, its duration, service or channel affected, amounts, as well as the corrective measures implemented are contemplated.
Likewise, maintain complete audit records that include the detailed information of the accesses or access attempts and the operation or activity carried out by the Users of the Technological Infrastructure.
Such records must be available to the authorized personnel of the Institution.
Performance of vulnerability scanning tests on the components of the technological infrastructure of the commissionaires that store, process or transmit information of the banking operations.
Such tests must be performed at least quarterly.
Performance of penetration tests by an independent third party, whose personnel has verifiable technical capacity through specialized certifications in the matter, such tests must contemplate the technological infrastructure of the commissionaire for the commercial commission.
The tests must consider, at least the following:
a)
Its scope and methodology.
b)
Be performed at least once a year.
c)
Additional tests must be carried out when there are significant changes in systems and applications, or perform them on previously reviewed systems and applications when there are critical vulnerabilities.
Continuous follow-up to the remediation plans regarding the findings of the reviews and tests referred to in the previous numerals 9 and 10.
Such plans must be reviewed by the institution and follow up on the actions implemented for their mitigation.
Have access controls to information according to the access levels and profiles determined by the Institution.
V. Requirements for the operation referred to in fraction IX of Article 319 of these provisions
That the systems of the Institution, as well as, as applicable, those of the stock exchanges with which they intend to celebrate commercial commissions, have the necessary technical requirements that allow them to comply with what is provided in Article 124 of the Law, as well as to receive and transmit the information referred to in the " General Rules to which multiple banking institutions must be subject to classify information related to active and passive operations referred to in Article 124 of the Credit Institutions Law ", and those issued by the IPAB, or those that replace them, including what is stated in numeral 3 below.
The procedures through which the Institution will authorize the stock exchanges to carry out such operations.
The obligation of the commissionaire stock exchange to:
a)
Collect from the client the necessary information in order to comply with what is provided in Article 115 of the Law and the " General Provisions referred to in Article 115 of the Credit Institutions Law " issued by the Secretariat, or those that replace them.
For this purpose, stock exchanges must transmit in time and form to the Institution the information related to the mentioned operations, in order for the Institution itself to comply with the cited Article 115 of the Law and the " General Provisions referred to in Article 115 of the Credit Institutions Law " issued by the Secretariat, or those that replace them.
b)
Regarding operations celebrated with multiple banking institutions as principals:
i.
Collect and classify in automated processing and data conservation systems, as well as in any other technical procedure, all the information that allows the multiple banking institution to comply with the Third of the " General Rules to which multiple banking institutions must be subject to classify information related to active and passive operations referred to in Article 124 of the Credit Institutions Law " issued by the IPAB or those that replace them;
ii.
Transmit to the multiple banking institution principal, simultaneously at the moment of the celebration of each operation, through its systems, the information that according to the Rules referred to in the previous numeral, the latter must maintain.
The foregoing, without prejudice to the fact that the contracts referred to in this article must contain the obligation on the part of the stock exchanges acting as commissionaires, to transmit to the multiple banking institutions principals, all the information referred to in the Third of the Rules mentioned in numeral i. above, when so required by the Commission, directly or at the request of the IPAB, always that the corresponding assumptions are met for the resolution of the multiple banking institution principal in terms of Article 122 Bis of the Law;
iii.
Obtain from the client at the moment of celebrating the operations, a written manifestation or by any means agreed with the banking client, in the terms of the format contained as Annex 60 of these provisions, and
iv.
Deliver to the client, on the back of the document referred to in numeral iii. above, or by any means agreed with the banking client, an informative text in the terms established in Annex 61 of these provisions.
c)
The terms under which the settlement of the operations must be carried out.
In the event that the settlement of the respective operations is carried out in the offices of the stock exchanges, deliver to the client the respective amount in the form agreed at the time of contracting.
In any case, if the client does not request the office for the referred settlement within a period of three business days counted from the date of maturity of the operation, the stock exchange will be released from the obligation to make the corresponding payment in favor of the client, so the settlement must be carried out directly with the Institution.
The obligation on the part of the Institution to provide the necessary means in order to comply with the provisions referred to in the previous numerals 1 and 2 and, in general, to what is established by the provisions related to the banking savings protection system, as well as to ensure that the commissionaire effectively complies with the foregoing.
Annex 59
Information that must be presented in the commissionaire authorization request
The information to be presented in the commissionaire authorization request must contain at least the following:
Detailed description and flow diagram of the processes of each of the operations to be carried out through the commissionaires considering the reconciliation and settlement process of each of them, the third parties involved and the Technological Infrastructure to be used in the operation in question.
Architecture and telecommunications diagram in which the security components, networks and databases of the technological infrastructure used for the operation with commissionaires are shown, which ensure that only authorized traffic is permitted.
Such diagram must include each of the participants, as well as all information processing sites including redundancy schemes, link types and backup routes, servers and communication devices.
The complete and detailed locations of the main and backup data centers, both of the Institution, of the commissionaire or of the provider of the commissionaire's technological infrastructure where the information of the transactions carried out through the commissionaire will be stored and/or processed (street, exterior and interior number, neighborhood, borough or municipality, state and country).
Diagram of interrelation of applications or systems of the commissionaire, including the systems of the Institution itself.
(It must Include all participants involved in the operation (e.g.: commissionaire, switches, payment media processors, third parties and the Institution itself).
Detail of the Sensitive Information that will be stored by the commissionaire in its equipment or facilities, or of the provider of the commissionaire's technological infrastructure, or to which they may have access.
Regarding Sensitive Information, the commissionaire must implement encrypted storage mechanisms.
Structure of the commissionaire's personnel and of the provider of the commissionaire's infrastructure with access to the information of the transactions carried out through the commissionaire and the associated Sensitive Information, which includes as a minimum position, hierarchical level of the same and responsibilities and authorized activities
related
to
such
Information
for
such
position.
Include
the
characteristics
of
the
operation
receipts,
attach
the
design
of
receipt
of
each
one
of
the
operations
to
contract.
Description
of
the
validation
measures
to guarantee
the
authenticity
of
the
transactions
executed
by
the
different
components
of
the
technological
infrastructure,
considering,
at
least
the
following:
a)
The
veracity
and
integrity
of
the
information.
b)
The
authentication
between
components
of
the
technological
infrastructure,
which
ensure
that
only
legitimate
service
requests
are
executed
from
their
origin
until
their
execution
and
registration.
c)
The
messaging,
communication,
and
encryption
protocols,
which
must
ensure
the
integrity
and
confidentiality
of
the
information.
d)
The
identification
of
atypical
transactions,
anticipating
that
the
applications
have
automatic
alert
measures
for
their
attention
by
the
corresponding
operational
areas.
A
list
containing
all
the
keys
and
the
public
certificates
of
the
Internet
pages
or
computer
applications
of
the
commissionaire
for
those
commissionaires
to
which
Article
319
Bis
of
these
Provisions
refers.
Description
of
automated
mechanisms
to detect
and
prevent
security
events
and
information
incidents,
as
well
as
to
avoid
unauthorized
incoming
or
outgoing
data
connections
and
flows
and
information
leakage,
considering
among
others,
removable
storage
media.
Detailed
report
of
the
results
of
vulnerability
scanning
tests
of
the
components
of
the
technological
infrastructure
of
the
commissionaires
that
store,
process,
or
transmit
information
of
the
banking
operations.
Detailed
results
report
of
the
penetration
tests
performed
by
an
independent
third
party,
whose
personnel
possess
demonstrable
technical
capacity
through
specialized
certifications
in
the
field,
such
penetration
tests
must
encompass
the
technological
infrastructure
of
the
commissionaire
for
commercial
commission.
Remediation
plans
regarding
the
findings
of
the
reviews
and
tests
referred
to
in
numerals
9
and
10
above,
as
well
as
the
evidence
of
the
mitigation
actions
implemented
to
correct
the
critical
and
high-severity
vulnerabilities.
Documentation
of
the
Internal
Commissionaire
Certification
Formats
(FIC)
relative
to
the
pre-operational
tests
of
the
operations
with
the
commissionaires.
In the document you are viewing, there may be text, characters, or objects that do not display correctly due to conversion to HTML format, so we recommend always taking the digitized image of the DOF or the PDF file of the edition as a reference. The content, form, and scope of published documents are the strict responsibility of their issuer.
CONSULT
BY
DATE
Do
Lu
Ma
Mi
Ju
Vi
Sá
INDICATORS
Exchange Rate and Rates as of 25/08/2026
DOLAR
16.9647
UDIS
8.807141
CCP
6.12%
CCP-UDIS
4.72%
CPP
5.09%
TIIE
28
DIAS
6.7559%
TIIE
91
DIAS
6.7931%
TIIE
182
DIAS
6.8474%
TIIE
DE
FONDEO
6.50%
See more
SURVEYS
Did you like the new look of the Official Gazette of the Federation website?
No
Yes
Official Gazette of the Federation
Río Amazonas No. 62, Col. Cuauhtémoc, C.P. 06500, Mexico City Tel. (55) 5093-3200, where you can access our service menu
Electronic address: dof.gob.mx
111
LEGAL NOTICE | SOME RIGHTS RESERVED © 2026