2024-06-14 | DOF 5730493Added · Updated
The National Banking and Securities Commission modifies general provisions for credit institutions to strengthen internal control regarding fraud prevention. The resolution defines 'Observable Conducts for Fraud Management' and mandates that institutions implement a Fraud Prevention Management Plan, including specific lineaments, risk assessment, and audit requirements. It introduces the concept of 'User Transaction Amount' to enhance security in electronic banking operations, requiring additional authentication factors for transactions exceeding this threshold or when modifications are made remotely. Furthermore, it establishes stricter reporting obligations for monetary complaints and requires institutions to assume risks and costs for unrecognized operations under specific contractual conditions.
If the document is presented incomplete on the right margin, it is because it contains tables that exceed the default width. If this is the case, click here to view it correctly.
DOF: 14/06/2024
RESOLUTION that modifies the General Provisions applicable to credit institutions
A seal with the National Emblem appears at the margin, which says: United Mexican States.- TREASURY.- Ministry of Finance and Public Credit.- National Banking and Securities Commission.
The National Banking and Securities Commission, based on articles 21, second and third paragraphs; 40, second paragraph; 52, antepenultimate paragraph; 96 Bis, first paragraph, 98 Bis and 101 Bis of the Credit Institutions Law; as well as 4 sections II, V XXXVI and XXXVIII; 6; 16, section I and 19 of the Law of the National Banking and Securities Commission and,
CONSIDERING
That, in accordance with article 78 of the General Law of Regulatory Improvement and with the purpose of reducing the compliance cost of these provisions, the National Banking and Securities Commission issued the Resolution that modifies the General Provisions applicable to credit institutions published in the Official Journal of the Federation on July 23, 2021, through which savings in reserves were generated, regarding personal loans on seven multiple banking institutions; as well as the Resolution that modifies the general provisions applicable to the activities of savings and loan cooperatives, published in the Official Journal of the Federation on April 26, 2018, through which article 220 was repealed generating a benefit by eliminating the opinion on the reasonableness of the classification and valuation of investments and transfers between categories;
That the National Banking and Securities Commission has the authority to issue prudential regulation within its competence to which credit institutions will be subject, including that related to internal control matters; as well as those related to the minimum functions that the audit committee of credit institutions must perform regarding the timeliness and sufficiency of the information that this collegiate body must consider;
That, in order to strengthen internal control in fraud matters, it is sought to establish a clear legal scheme that determines Observable Conducts for Fraud Management, their scope and specific obligations, which will provide legal certainty both to credit institutions and to the Commission itself, by having a valid regulatory framework that strengthens supervision in matters of prevention, detection and timely response to the presence of Observable Conducts for Fraud Management, in order to have the legal grounds that establish the obligation to follow up on said conducts, for the benefit of financial stability and users of financial services;
That the adequate implementation of an internal control system will provide credit institutions with greater security in the celebration of their operations and reduce the risks to which they are exposed, facilitating the timely recording of transactions and compliance with the regulations applicable to them,
and
That it is convenient to dictate minimum guidelines through a prudential regulation framework, with the purpose that credit institutions have objectives and guidelines in internal control matters that segregate functions, establish operational control mechanisms and foresee general internal and external audit programs, among other aspects, has resolved to issue the following:
RESOLUTION THAT MODIFIES THE GENERAL PROVISIONS APPLICABLE TO
CREDIT INSTITUTIONS
UNIQUE. - Articles 1, section CXXXVI; 51 Bis 1, fourth paragraph; 142, first paragraph and section III, second paragraph; 164, first paragraph, as well as third paragraph, section IV, subsection c); 168 Bis 11, first and second paragraphs; 168 Bis 12, section VIII; 207, the reference to the "Series R27 Monetary Complaints" and its report "A-2701 Monetary Complaints"; 208, first paragraph, section II, subsection f) and section III; 307, first paragraph, section I, subsection e), second paragraph; 309, first paragraph, section I, third paragraph; 310, first paragraph, section III, fourth and sixth paragraphs; 313, third and sixth paragraphs; 316 Bis 14, as well as Annex 36, in its series R27 "Monetary Complaints"; are REFORMED; and Articles 1, the sections XXXVII Bis, CXV Bis 1, moving the current CXV Bis 1 to CXV Bis 2, CXXXVI Bis, CXXXVI Bis 1 and CXLVIII Bis; 160, section XV; 164, third paragraph, section X; 164 Bis 1; 166, sections VII and VIII; 168 Bis 11, section XVI; 171 Bis 1; 287 Bis; 287 Bis 1; 339, first paragraph, section V and Annexes 12-E and 12-F of the "General Provisions applicable to credit institutions", published in the Official Journal of the Federation on December 2, 2005 and modified through various resolutions published in said official dissemination medium, are ADDED, to remain as follows:
RESOLUTION THAT MODIFIES THE GENERAL PROVISIONS APPLICABLE TO THE
CREDIT INSTITUTIONS
" TITLES FIRST to FIFTH
...
Annexes 1 to 12-D
...
Annex 12-E
Minimum Guidelines for the Fraud Prevention Management Plan.
Annex 12-F
Of the information that institutions must make available to the User or the Commission derived from Monetary Complaints.
Annexes 13 to 73.
... "
" Article 1.-
...
I. to XXXVII.
...
XXXVII Bis.
Observable Conducts for Fraud Management: In singular or plural, the Internal or External conducts that, for purposes of compliance with these provisions, are those behaviors or set of actions carried out by a person or group of people against the User Public with the intention of obtaining undue profit for oneself or for a third party; which include the actions indicated below:
i.
Impersonate or usurp the User's identity.
ii.
Steal personal data and financial information of the User.
iii.
Impersonate the institution itself.
iv.
Use privileged information of Users by employees of Institutions.
v.
Compromise the Electronic Means used by the User with the objective of installing malicious code capable of altering the execution of Monetary Operations.
vi.
Alter checks and issue fake checks.
For the purposes of these provisions and the management that Institutions must carry out in the probable presence of such conducts, Institutions will consider them to be:
a)
Internal: When the conducts are carried out by at least one employee, personnel holding any position, mandate or commission or any other designation that the Institutions themselves have granted for the execution of their Operations, against the User Public, when the conducts are contrary to the regulations of the institutions.
b)
External: When the conducts are carried out exclusively by one or more third parties, different from the persons mentioned in the previous subsection, against their Users.
XXXVIII. to CXV Bis.
...
CXV Bis 1.
User Transaction Amount: Reference amount of Monetary Operations carried out by Users who are natural persons through Internet Banking, Voice-to-Voice Telephone Banking, Audio Response Telephone Banking and Mobile Banking, defined by said User or, in default, estimated by the Institution, used for the specific purposes of these provisions.
CXV Bis 2.
NIF C-16: to the Financial Information Standard "Deterioration of Receivable Financial Instruments" published by the Mexican Council of Financial Information Standards, A.C., which converges with International Financial Reporting Standard 9 "Financial Instruments" issued by the International Accounting Standards Board.
CXVI. to CXXXV.
...
CXXXVI.
Persons in Vulnerable Situations: To the group of people who declare freely and voluntarily to Institutions, in accordance with these provisions, belonging in an enumerative, but not limiting manner, to elderly persons, persons with disabilities, persons belonging to some ethnicity, indigenous people or community.
CXXXVI Bis.
Fraud Prevention Management Plan: Is the document containing the set of guidelines, analysis methodologies and minimum actions that establish the strategy, operational processes and projects of Institutions to carry out the identification, measurement, monitoring, and attention to Observable Conducts for Fraud Management, as well as to the prevention, detection, timely response and monetary compensation of damage to the User Public derived from these.
CXXXVI Bis 1.
Security Master Plan: to the document that establishes the security strategy of an Institution to ensure correct management of information security and avoid the materialization of Information Security Incidents that could negatively affect the Institution.
CXXXVII. to CXLVIII.
...
CXLVIII Bis.
Monetary Complaint: In singular or plural, all those Monetary Operations not recognized by the user and that have been communicated to the Institution through any channel or means made available to the user.
CXLIX. to CXCVII.
... "
" Article 51 Bis 1.-
...
I. to III.
...
...
...
Institutions may not perform the verification actions described in this article, when they agree with their clients in the respective Level 4 Bank Account contracts, as well as in current account credit opening contracts, that they commit to assume the risks and, therefore, the costs of the operations that are not recognized by their clients, obligating themselves additionally that the amounts of the Monetary Complaints of said operations will be credited to them, no later than forty-eight hours after the Monetary Complaint made by the User. Institutions must notify the Commission when they decide to opt for what is provided in this paragraph no later than ten business days after such determination, indicating the operations to which it will be applicable. "
" Article 142.- The Board, once the objectives of the Internal Control System and the guidelines for its implementation are approved, must, within its competence:
I. and II.
...
III.
...
The code of conduct must contain norms consistent with current legislation and other applicable legal provisions, with sound practices and banking usages. Additionally, it must incorporate guidelines detailing the obligations related to the confidentiality of information of the Institution, other entities, or its users, as well as the Observable Conducts for Fraud Management internal and their corresponding sanctions applied by the Institution, specifying that the latter are independent of those imposed by the corresponding judicial authorities.
...
IV. to VII.
...
... "
" Article 160.-
...
I. to XIV.
...
XV.
Evaluate, at least once every two years, and alternately with the external audit in accordance with the last paragraph of Annex 12-E of these provisions, the effectiveness and weaknesses of the Fraud Prevention Management Plan, establishing recommendations for its continuous improvement, taking into account the identified facts that represented the commission of the crime of fraud, carrying out the follow-up of corrective actions implemented by the areas or functions responsible for attending to such recommendations. The findings of each audit will form part of the annex of the next submission of the Fraud Prevention Management Plan to the Commission.
...
... "
" Article 164.- The General Directorate, within the scope of its functions, shall be responsible for the proper implementation of the Internal Control System.
...
...
I. to III.
...
IV.
...
a) and b)
...
c)
Implement and make known to the Board the mechanisms so that the different activities in the Institution are carried out, only by personnel defined previously, and, if applicable, authorized in accordance with the organizational structure of each Institution referred to in subsection a) of this section, for which they must have technical quality, necessary experience and honorability for which they must carry out an evaluation, at least once every three years, which must be documented and available at all times for the Commission for at least five years.
d) to i)
...
V. to IX.
...
X
Approve the Fraud Prevention Management Plan. The head of the general direction must inform the Board of the content of said plan, and have evidence of its implementation since its preparation and elaboration.
...
... "
" Article 164 Bis 1.- The Fraud Prevention Management Plan must contain the guidelines, processes, policies and criteria for the prevention, detection and timely response of Observable Conducts for Fraud Management. Likewise, for each project defined within said plan, at least the following must be indicated: project name, objective and strategies defined to achieve it, scope, start and end dates, deadlines and periodicity for its execution, areas involved and a detailed specification of the responsibilities of each area involved in each defined project, projected investment, the detail of actions and activities performed and to be performed, the technical, material and human resources employed; verifying that in the elaboration of the plan referred to in this article compliance with the minimum guidelines described in Annex 12-E of these provisions is given.
The head of the general direction may designate in some official of the two hierarchical levels below this, and who do not belong to the business or audit area, or well to the area responsible for fraud prevention, the faculty to elaborate the Fraud Prevention Management Plan, documenting such designation. The Fraud Prevention Management Plan will be executed by a specific administrative structure.
The minutes or certification issued by the secretary or pro-secretary in which the presentation of the Fraud Prevention Management Plan to the Board for its knowledge is recorded, must be included as an annex of the document sent to the Commission. Once the Fraud Prevention Management Plan is made known to the Board, the Institution must send it to the vicepresidency of the Commission in charge of its supervision, no later than the last business day of January of each year. The Commission may request adjustments to the Fraud Prevention Management Plan derived from the review referred to in this paragraph. Without prejudice to the foregoing, Institutions must execute the plan from its approval by the head of the general direction.
Institutions must have documented evidence of the implementation of each project that forms part of the Fraud Prevention Management Plan, which must be preserved and available to the Commission for a period of at least five years. "
" Article 166.-
...
I. to VI.
...
VII.
Allow to verify and review that the basic aspects of determining Monetary Complaints, and alerting for possible events of Observable Conducts for Fraud Management, are carried out with a minimum level of quality, which will be determined in the manuals, policies and internal procedures of the Institution, by the responsible areas involved in each determination process, as well as to comply with what is established in this matter in Annexes 12-E and 12-F of these provisions.
VIII.
Allow to follow up and promote compliance with the projects contained in the Fraud Prevention Management Plan, having to have documented evidence which must be preserved and available to the Commission for a period of at least five years.
...
"
" Article 168 Bis 11.- The head of the General Directorate of the Institution shall be responsible for the implementation of the Internal Control System in matters of information security that ensures its confidentiality, integrity and availability. The management framework referred to in this article must ensure that the Technological Infrastructure, own or provided by third parties, complies with the following requirements:
I. to XV.
...
XVI.
Define in the respective policies and procedures manuals, the roles and responsibilities of the Technological Infrastructure personnel in matters of information security of the Institution.
The general director shall be responsible for documenting in policies and procedures what is provided for in this article.
Article 168 Bis 12.-
...
I. to VII.
...
VIII.
Implement and evaluate through internal audit, the annual training programs referred to in Article 69, section V of these provisions, as well as those on awareness in matters of information security, directed to all personnel and to the User including, if applicable, third parties who provide services related to the means through which Observable Conducts for Fraud Management can be committed, in which, among other aspects, the roles and responsibilities that Users of the Technological Infrastructure have in this regard are contemplated.
IX. and X.
... "
" Article 171 Bis 1.- Institutions must have processes that evaluate the effectiveness of the resolution of Monetary Complaints. Likewise, they must guarantee transparency in said processes for which they must adhere to what is stated in Annex 12-F of these provisions. "
" Article 207.-
...
Series R01 Minimum Catalog to Series R26 Information by commissioners ...
Series R27 Monetary Complaints A-2701 Monetary Complaints
Series R28 Operational Risk Information to Series R36 ...
...
... "
" Article 208.-
...
I.
...
II.
...
a) to e)
...
f)
The information relative to series R16, exclusively with respect to reports A- 1611 and A-1612, series R24, only reports B-2421, B-2422, C-2431, D-2441 and D- 2442, as well as that corresponding to series R26, R27 and R35 with respect to report A-3511, must be sent no later than the last day of the month immediately following that of its date.
g) and h)
...
III.
Quarterly, the information of series R14, R15, and R32 must be sent within the month immediately following that of its date.
...
...
IV.
...
... "
" Article 287 Bis.- The User Transaction Amount may be defined by the User in the celebration of the contract for the opening of any account, product or service in question or at any time through the Electronic Banking service subsequent to the contracting of account opening, product or service. The Institution must provide what is necessary for its Users to establish the User Transaction Amount, using any Authentication Factor determined by the Institution, if carried out in Electronic Means or by signature in Bank Offices, prior to client identification.
In the event that the User does not establish their User Transaction Amount for the services of the preceding paragraph, this must be estimated by the Institution in accordance with the User's Monetary Operations history or well, considering the transaction profiles of other Users with characteristics similar to those of said User, within a period not greater than six months from the celebration of the referenced contract. Once the User Transaction Amount is determined, it must be sent to the User for their knowledge through a means that allows proving its receipt, and it will take effect the day following its notification. The methodology and procedure for its determination must be documented in the Fraud Prevention Management Plan.
Institutions must allow their Users to modify the User Transaction Amount through Electronic Means remotely or by signature in Bank Offices. When the modification is carried out through Electronic Means remotely, such modification will require at least two Authentication Factors referred to in article 310 of these provisions, which must be of distinct category. Once the User Transaction Amount is modified, it will take effect once the Institution sends an alert to the User of the modification indicated in this paragraph through instant messaging with Encryption protocols, via telephone or email, and the latter confirms the action referred to.
Institutions may use the User Transaction Amount as input for the detection and prevention of events that deviate from the usual usage parameters of their Users through Electronic Means referred to in Article 316 Bis 13 of these provisions.
What is established in this article will not be applicable to Level 1 Bank Accounts, nor to their services, credits and debit or credit cards associated with said accounts.
Article 287 Bis 1.- When the amount of a Monetary Operation carried out through Internet Banking, Voice-to-Voice Telephone Banking, Audio Response Telephone Banking and Mobile Banking services is greater than the User Transaction Amount, Institutions must require an additional Authentication Factor to those established in these provisions for the Monetary Operation in question, referred to in Article 310 of these provisions, requested through instant messaging with Encryption protocols, via telephone or email with Encryption protocols. In the event that the Monetary Operation is carried out through services other than Mobile Banking, the additional Authentication Factor referred to in this paragraph may be requested through a confirmation of celebration of the Monetary Operation through Mobile Banking services, prior to its execution. "
" Article 307.- ...
I.
...
a) to d) ...
e)
...
Likewise, Institutions must agree at the time of contracting with their Users that they will assume the risks and therefore the costs of operations carried out through the services mentioned above that are not recognized by the Users themselves, and that the Monetary Complaints derived from these operations must be credited to the
Users or, in the case of granting credits, that the resources will be withdrawn from the User's account without charging any commission, at the latest forty-eight (48) hours after the claim, except when the User has confirmed said contracting in the terms described.
II. to VI.
. . . "
" Article 309.- . . .
I.
. . .
. . .
Likewise, Institutions that obtain the authorization referred to in the preceding paragraph, must provide, at the time of contracting with their Users, that the Institutions themselves will assume the risks and therefore the costs of operations carried out through Mobile Payment that do not comply with what is provided in the first paragraph of this section and that are not recognized by the Users. Monetary Claims arising from these operations must be paid to the Users at the latest forty-eight (48) hours after the Monetary Claim.
. . .
II.
. . . "
" Article 310.- . . .
I. and II.
. . .
III.
. . .
. . .
. . .
Institutions that approve the execution of operations through the use of bank cards without integrated circuits, in ATMs and Point of Sale Terminals, must agree with their Users that they will assume the risks and therefore the costs of operations that are not recognized by the Users in the use of said cards. Monetary Claims arising from these operations must be paid to the Users at the latest forty-eight (48) hours after the Monetary Claim.
. . .
. . .
Institutions that obtain the authorization referred to in the preceding paragraph, must agree with their Users that they will assume the risks and therefore the costs of unrecognized operations carried out through the Electronic Banking service in question. Monetary Claims arising from these operations must be paid to the Users at the latest forty-eight (48) hours after the Monetary Claim.
IV.
. . . "
" Article 313.-
. . .
. . .
In the case of Monetary Operations considered as Micro Payments, whose Access Device is a Mobile Phone or a Point of Sale Terminal, they may be carried out without the Institutions requesting Authentication Factors. Institutions must agree, at the time of contracting with their Users, that the Institutions themselves will assume the risks and therefore the costs of operations that are not recognized by the Users in said cases. Monetary Claims arising from these operations must be paid to the Users at the latest forty-eight (48) hours after the Monetary Claim.
. . .
. . .
Institutions that obtain the authorization referred to in the preceding paragraph, must agree with their Users, that the Institutions themselves will assume the risks and therefore the costs of unrecognized operations by the Users in said cases. Monetary Claims arising from these operations must be paid to the Users at the latest forty-eight (48) hours after the Monetary Claim. "
" Article 316 Bis 14.- Institutions must maintain for a period of at least 5 years, in their databases, all operations carried out through the Electronic Banking service that are not recognized by their Users and that, at least, include information related to these operations and the information regarding the procedure that, if applicable, the User has promoted, such as the information established in the regulatory report R27 A-2701 Monetary Claims. "
" Article 339.-
. . .
I. to IV.
. . .
V.
Those related to ensuring the privacy conditions of withdrawals and other transactions that the Public User carries out at counters, regarding those who are in the waiting room of Branches and Banking Modules. "
TRANSITORY PROVISIONS
FIRST.- This Resolution will enter into force the day following its publication in the Official Journal of the Federation, subject to the timeframes established in the following transitory provisions for compliance with the obligations contained herein.
SECOND.- Multiple banking institutions will have:
I.
180 natural days counted from the entry into force, to send to the Commission for a single occasion on a date different from that established in article 164 Bis 1, the first delivery of the Fraud Prevention Management Plan.
II.
Until the first day of the tenth month subsequent to the entry into force, to implement what is established in the Fraud Prevention Management Plan delivered to the Commission in accordance with the previous first transitory article, as well as to adjust to what is established in this Resolution.
III.
Until the first day of the sixteenth month subsequent to the entry into force, for the User Transaction Amount to be determined, either by the Institution or by the User themselves, when it has not been established for accounts, products, or services in force at the entry into force of this resolution.
THIRD.- Development banking institutions will have:
I.
Until September 30, 2025, to send to the Commission for a single occasion on a date different from that established in article 164 Bis 1, the first delivery of the Fraud Prevention Management Plan.
II.
Until January 2, 2026, to implement what is established in the Fraud Prevention Management Plan delivered to the Commission on September 30, 2025, as well as to adjust to what is established in this Resolution.
III.
Until July 2, 2026, for the User Transaction Amount to be determined, either by the Institution or by the User themselves, when it has not been established for accounts, products, or services in force on January 2, 2026.
FOURTH.- From January 2, 2026, Institutions will be obligated to include the evaluation referred to in article 160 section XV and in the last paragraph of Annex 12-E, as well as concluded and analyzed fraud crime events, and the indicators referred to in subsection d) and e) of section III, and subsection d), section II of Annex 12-E of this Modifying Resolution.
FIFTH.- Institutions must send the code of conduct resulting from the modifications provided in article 142 section III to the Commission, no later than October 1, 2025 for multiple banking institutions and July 1, 2026 for development banking institutions.
Respectfully,
Mexico City, June 10, 2024. - President of the National Banking and Securities Commission, Dr. Jesús de la Fuente Rodríguez. - Rubric.
" Annex 12-E
Minimum Guidelines for the Fraud Prevention Management Plan
The Fraud Management Plan must consider the following minimum elements: having mechanisms for identification, measurement, prevention, control, and response to possible events of Observable Behaviors for Fraud Management, reporting schemes that consider quantitative and qualitative aspects, as well as the execution of periodic reviews and audits to timely readjust, if applicable, the parameters of models, mechanisms, and surveillance processes, under the following principles.
Corporate Governance: A corporate governance structure must be established that shows the principles for the management of Observable Behaviors for Fraud Management and the expectations of the Board and General Management regarding their commitment to ethical values for the attention of Observable Behaviors for Fraud Management, which must be documented in the institutional policies of the fraud prevention area. Likewise, incentives must be established in accordance with what is established in Section Eighth, Chapter VI of Title Two of these Provisions, as well as the requirements for officials and employees to achieve goals and good performance in the attention of Observable Behaviors for Fraud Management, as well as to monitor and document compliance with said goals.
Measurement and monitoring of Observable Behaviors for Fraud Management: The General Management of the Institution must guarantee that evaluations are carried out to identify schemes of Observable Behaviors for Fraud Management, evaluating their probability and importance and the control activities of said existing behaviors. The results of these evaluations must be used to feed back and strengthen the design of the Institution's risk management system. The policies established must clearly define and communicate the commitment of the Board and General Management to the attention of Observable Behaviors for Fraud Management.
Collaboration, investigation, and information exchange: Institutions must have policies, communication processes, and internal investigations which must be documented in the Institution's policy and procedure manuals, as well as internal control systems that guarantee a coordinated approach to carry out appropriate investigations, timely responses, and the attention of reports of suspicion of Observable Behaviors for Fraud Management, as well as those confirmed. For the purposes of this paragraph, in the case of development banking institutions, their internal control body must be involved.
The processes of the Fraud Prevention Management Plan must contain a combination of preventive, detection, and response controls for Observable Behaviors for Fraud Management. All processes must be carried out and duly documented. The minimum projects to be considered in the Fraud Prevention Management Plan are:
I.
Prevention of Observable Behaviors for Fraud Management.
a)
Establish in the Institution a culture that promotes ethical behavior at all levels of staff, through campaigns, training, and the establishment of ethics manuals.
b)
Include in its code of conduct or ethics statement the measures and responsibilities that employees have regarding the treatment and prevention of Observable Behaviors for Fraud Management, as well as the corresponding sanctions in case of non-compliance.
c)
Train, at least once a year, employees on the attention of Observable Behaviors for Fraud Management according to their functions and responsibilities.
d)
Train, at least once a year, employees on the attention to Public Users who are victims of possible Observable Behaviors for Fraud Management.
e)
Provide Users with training on the risks of Observable Behaviors for Fraud Management and the preventive measures they can take to reduce the risk of becoming victims. In the case of operations through the Electronic Banking service, what is stated in this paragraph will be complementary to what is referred to in article 306, section III of these Provisions.
f)
Implement strategies for fraud prevention in the credit origination process, with the objective of preventing the acceptance of false information in credit applications.
g)
Establish measures to prevent the execution of Observable Behaviors for Fraud Management in Persons in a Vulnerable Situation, through staff training, promotion of new banking service attention models, financial education campaigns stating that Institutions never request confidential information from the User, advisory programs with staff at ATMs in branches, anti-fraud campaigns, remote advisory programs, and alternative solutions to problems regarding banking products and services, and implementation of actions that allow new attention models.
h)
Establish measures to combat behaviors aimed at obtaining confidential User data, through a fraudulent request by email, websites, phone calls, SMS Messages, among other means, in which the perpetrator poses as a legitimate company or a trusted person; establishing as a minimum, the following measures: permanent campaigns directed at the User, stating that Institutions never request confidential information from the User; advice on identifying fake emails, fraudulent calls or text messages; promotion of protected and encrypted communication channels to transmit sensitive information with the User; establishment of clear procedures for reporting this type of behavior; implementation of online solutions such as antivirus and antimalware software; and monitoring of fake websites.
i)
Provide informational campaigns to the Public User with the purpose of preventing Observable Behaviors for Fraud Management.
II.
Detection of Observable Behaviors for Fraud Management.
a)
Have systems and controls for the review and monitoring of operations, capable of detecting anomalies and operations that deviate from the User Transaction Amount or related to possible fraudulent activities. In the case of operations through Electronic Means, what is stated in this paragraph will be complementary to what is referred to in article 316 Bis 13, of these Provisions.
b)
Have models, monitoring systems, or reports designed to detect and alert fraudulent acts in all lines of business such as, by way of example but not limitation, exception reports, file maintenance reports, employee surveillance processes, account monitoring, system access control, patterns, and cancellations.
c)
Have automated alert systems for operations directed at Users, that deviate from the User Transaction Amount and parameters based on the consumption and location of Monetary Operations generated by the User, in such a way that the User can detect the start of operations and failed attempts to initiate them, as well as documented processes in manuals for alert management.
The information resulting from the alert systems will form part of the evidence referred to in subsection f), section IV of Annex 12-F of these provisions. Likewise, institutions must implement processes with the objective of protecting User resources when the aforementioned alerts occur, such as recommending the User change passwords, change Authentication Factors, if applicable, among others, whose methodology must be documented in this plan.
d)
Design operational indicators related to the detection of Observable Behaviors for Fraud Management. The indicators and their monitoring as of the date of approval of the Fraud Prevention Management Plan must form part of it as an annex.
e)
Analyze loss data derived from Observable Behaviors for Fraud Management, transactions, cancellations, Monetary Claims, errors, and data from complaints by the Public User, with the purpose of detecting possible fraud commission facts.
f)
Incorporate internal channels and reporting systems through which Institution employees can anonymously report Observable Behaviors for Fraud Management.
III.
Response to Observable Behaviors for Fraud Management.
a)
Investigate all cases of Observable Behaviors for Fraud Management, to determine facts and identify risks and control weaknesses.
b)
Establish documented procedures approved by General Management that govern the investigation of actual cases or suspicions of Observable Behaviors for Fraud Management. These procedures must designate the personnel responsible for supervising and carrying out the investigation, and establish rules regarding the investigation procedure, such as the rules governing the conduct of interviews, the treatment of proof or evidence, the treatment of involved persons, and the reporting of results.
c)
Inform the Board, through the head or person responsible for the area in charge of fraud prevention, all relevant events of Observable Behaviors for Fraud Management, defining their relevance in the Fraud Prevention Management Plan itself. Likewise, in said plan, the frequency with which the Board must be informed must be established.
d)
Register all facts determined as fraud crime commission by competent authorities and analyze them to improve the Fraud Prevention Management Plan. The concluded events and their analyses as of the date of approval of the Fraud Prevention Management Plan must form part of it as an annex, grouping by fraud crime casuistics and describing how they were carried out, what control measures, if any, failed, and the adjustments or new control measures implemented to prevent control measures from failing again, if applicable.
e)
Establish a series of indicators for the monitoring of Observable Behaviors for Fraud Management. The indicators and their monitoring as of the date of approval of the Fraud Prevention Management Plan must form part of it as an annex.
f)
Establish an interbank communication channel where information relative to the casuistics and possible natural persons employed by Institutions who committed internal Observable Behaviors for Fraud Management is shared, only in the case that the infringement regarding the Institution's code of conduct is documented.
g)
Establish an interbank communication channel, through which credit institutions will exchange information when they have alerts, including Monetary Claims from their clients for presumed fraudulent activities carried out by natural or legal persons, involving more than one institution, as well as the actions they will carry out to collaborate with each other to avoid the materialization of a crime, as well as to share the behaviors and trends of fraud crime detected within the Financial System, data, and necessary documentation for the resolution of Monetary Claims received by the Public User.
The head of the General Management is responsible for monitoring the review, at least once a year, to guarantee that the strategy can contribute to a response approach to Observable Behaviors for Fraud Management. Each of the business units must carry out tests and reviews based on controls that may have failed. Likewise, at least once every two years, alternately with the internal audit indicated in section XV of article 160 of these provisions, an independent external auditor must determine the effectiveness and weaknesses of the Fraud Prevention Management Plan, establishing recommendations for its continuous improvement, taking into account the identified facts that represented the commission of frauds, carrying out the follow-up of corrective actions implemented by the areas or functions responsible for attending to said recommendations. The report of each audit will form part of the Fraud Prevention Management Plan as an annex.
Annex 12-F
Of the information that institutions must make available to the User or the Commission
derived from Monetary Claims
Institutions must ensure that the processes and basic aspects of ruling on Monetary Claims are transparent, considering at least the following:
I.
Each Institution must have established a procedure for Monetary Claims documented in its procedure manuals and make it available to the User on its Internet page and in branch through a visible notice or using visible informative screens or any other similar means, which allows the User to obtain or download in writing the Monetary Claims procedure expeditiously.
These procedures must consider the applicable considerations when the Monetary Claim is made by a User who is a member of any group of Persons in a Vulnerable Situation.
II.
The Institution must make available to the User who filed the Monetary Claim, at least every 20 business days, an update regarding the progress of the investigation of the Monetary Claim until it is resolved or can no longer be processed within the Institution, through the channels that the Institution has established in its procedures for claim handling.
III.
In the case of Monetary Claims that resulted as not valid for the User, the Institution must have evidence and the detail of the following minimum elements, which must be available to the Commission or any other competent authority:
a)
User Transaction Amount, as well as the information determined by the institution regarding the amount, number, type, nature, frequency, and channels that the User who filed the Monetary Claim commonly carries out.
b)
Transactionality declared by the User at the opening of the account, which, among others, includes channels, periodicity, and amount of their Monetary Operations.
c)
Monetary Claims of the User that are known to the institution in the last 12 months, indicating the medium or channel by which it was communicated to the institution, and the date on which they were registered.
d)
Evidence of the registration of the Monetary Claim in the institution's systems or logs.
e)
Verification of the legitimacy and adherence to the institution's internal control system of the operations carried out by the institution on the account where the Monetary Operation was made, in the 90 natural days prior to the date of the Monetary Claim:
i)
That the mechanisms and authentication procedures stipulated and regulatorily permitted were used to carry out the transaction whenever the Institution had allowed the User to use the category of Authentication Factor provided in these provisions and, not so, an Authentication Factor of a category lower than the aforementioned one.
ii)
That it was carried out in accordance with the amount limits agreed with the User pursuant to article 315 of these provisions.
iii)
That, if the amount of the claimed Monetary Operation is greater than the User Transaction Amount, the procedures stipulated in article 287 Bis I of these provisions were verified.
iv.
That, in the case of Monetary Claims for Monetary Operations carried out through Electronic Banking, the registration of Destination Accounts was carried out in accordance with the applicable regulations, and that the Institution fulfilled the obligation to ensure that its clients registered the Destination Accounts in the Electronic Banking service in question prior to their use, whether to be used within the same service or in other Electronic Banking services.
v)
That the generation of receipts and notification of operations was carried out in accordance with Article 316 bis 1 of these provisions and was recorded in the Institution's accounting and serves as evidence in court in accordance with Article 100 of the Law, without the Institution being obligated to prove that the User consulted the aforementioned receipt or notification.
vi)
Registration or changes in contact data, confidential keys, Authentication Factors or beneficiaries, associated with the affected accounts.
f)
A summary of the alerts generated in the last 30 days by the Institution's systems, associated with the User's accounts, whether or not they relate to the Monetary Operation associated with the Monetary Claim. In the event that there are no alerts during this period, this must be indicated.
g)
Actions taken with other Institutions for the return of resources from the Monetary Operation associated with the Monetary Claim, where applicable.
h)
If the User self-identifies as part of a group of Persons in a Situation of Vulnerability. In such a case, in the design of data collection, Institutions must indicate to Users that the declaration is made freely and voluntarily.
i)
Opinions or operational, technical, telephone, or any other type of reports generated by the institution, arising from the Monetary Claim.
IV.
In the case of Monetary Claims that are not valid for the User, Institutions must include in the resolution dictation a legend specifying to the User that, in the event that they do not agree with the response provided by the Institution, they may initiate a claim or complaint with the Institution's Specialized Units, and that they may also formally initiate the procedure to which they are entitled before the National Commission for the Protection and Defense of Financial Services Users, detailing the channels and procedures to file the Monetary Claim with that body.
V.
Institutions must retain records of all Monetary Claim resolutions and documentation delivered to the Public User who presents the Monetary Claim for at least five years, so that they can be reviewed by the Commission or any other competent authority.
This annex shall not be mandatory for claims presented to the Specialized Units of the Institutions, nor to the National Commission for the Protection and Defense of Financial Services Users in accordance with the Law for the Protection and Defense of Financial Services Users Users.
" Annex 36
Regulatory Reports
Index
Series R01 to Series R26
.
.
.
Series R27 Monetary Claims
Frequency
A-2701
Monetary Claims
Monthly
Series R28 to Series R34
.
.
. "
" SERIES R01 MINIMUM CATALOG to SERIES R26 INFORMATION BY COMMISSIONERS
.
.
.
SERIES R27 MONETARY CLAIMS
This series consists of one (1) report, whose frequency of preparation and presentation must be monthly.
REPORT
A-2701
Monetary Claims
This report requests information on the User's Monetary Claims derived from active and passive operations, specifying the transactional channel of the operation.
Likewise, the report considers information regarding the management data of the User's claims. For the purposes of this report, a claim shall be understood as all those monetary operations not recognized by the User and which they have communicated to the Institution through any channel or means made available to them.
CAPTURE FORMAT
.
.
.
INFORMATION REQUESTED
REPORT IDENTIFIER SECTION
PERIOD
INSTITUTION KEY
CLAIM DATA SECTION
CLAIM DATE
CLAIM ORIGIN
INCIDENT DATE
STATE WHERE THE MONETARY CLAIM ORIGINATED
MUNICIPALITY WHERE THE MONETARY CLAIM ORIGINATED
CLIENT RFC
CLIENT CURP
INDIVIDUAL OR LEGAL ENTITY
ACCOUNT NUMBER/CREDIT CARD NUMBER/DEBIT CARD NUMBER/DEBIT CARD NUMBER
PERSON IN A SITUATION OF VULNERABILITY
USER TRANSACTION AMOUNT
USE OF AUTHENTICATION FACTOR AND CATEGORY
USE OF AUTHENTICATION FACTOR AND CATEGORY WHEN THE USER TRANSACTION AMOUNT IS EXCEEDED
PRODUCT
IDENTIFIER OF INSTITUTION, COMMISSIONER OR MERCHANT WHERE THE OPERATION IS CARRIED OUT
ACQUIRER NAME IN THE CASE OF POS OPERATIONS
CHANNEL IN WHICH THE TRANSACTION WAS CARRIED OUT
REASON FOR THE CLAIM
TRANSACTION WITH CONTACTLESS PAYMENT TECHNOLOGY
AMOUNT OF THE MONETARY CLAIM
STATUS OF THE CLAIM
RESOLUTION DATA SECTION
RESOLUTION
RESOLUTION DATE
REASON FOR RESOLUTION
AMOUNT CREDITED TO THE CLIENT
DATE OF CREDIT TO THE CLIENT
AMOUNT RECOVERED
MEANS BY WHICH THE AMOUNT WAS RECOVERED
LOSS FOR THE INSTITUTION
FRAUD DATA SECTION
OBSERVABLE BEHAVIOR OF FRAUD MANAGEMENT
Institutions will report the information indicated in this series, which must comply with the validations and quality standards indicated by the Commission, adjusting to the characteristics and specifications, for the purposes of filling out and sending information, presented in the filling instructions, which are published and updated on the SITI or in the case, made known by the Commission. Once the validations and quality standards are met, the SITI will generate an electronic receipt of receipt.
The information must be sent only once and will be received assuming it meets all characteristics and specifications, in virtue of which it cannot be modified and must present consistency with the various reports in which the same information is included with a different level of integration, so that, if it does not meet the required quality and characteristics or has been presented incompletely, the obligation of its presentation will be considered unfulfilled and, consequently, the corresponding sanctions will be imposed in accordance with the applicable legal provisions.
SERIES R28 OPERATIONAL RISK INFORMATION to SERIES R36 ADVANCED PAYMENTS
.
.
. "
In the document you are viewing, there may be text, characters or objects that do not display correctly due to conversion to HTML format, so we recommend always taking the digitized image of the DOF or the PDF file of the edition as a reference. The content, form and scope of published documents are the strict responsibility of their issuer.
CONSULT
BY DATE
Do
Lu
Ma
Mi
Ju
Vi
Sá
INDICATORS
Exchange Rate and Rates as of 25/08/2026
DOLLAR
16.9647 UDIS
8.807141 CCP
6.12% CCP-UDIS
4.72% CPP
5.09% TIIE 28 DAYS
6.7559% TIIE 91 DAYS
6.7931% TIIE 182 DAYS
6.8474% TIIE DE FONDEO
6.50%
See more
SURVEYS
Did you like the new image of the Federal Official Gazette website?
No
Yes
Federal Official Gazette
Río Amazonas No. 62, Col. Cuauhtémoc, C.P. 06500, Mexico City Tel. (55) 5093-3200, where you can access our service menu
Electronic address: dof.gob.mx
111
LEGAL NOTICE | SOME RIGHTS RESERVED © 2026
More like this from SHCP
SHCP published 14 documents in the last 30 days. We email you each new one the day it's published.