2021-09-23 | DOF 5630657

Added · Updated

Resolution modifying the General Provisions applicable to credit institutions

The National Banking and Securities Commission amends the General Provisions applicable to credit institutions to introduce seven exceptions to the prior authorization requirements for outsourcing services under Article 317, thereby exempting institutions from filing procedures for specific services such as professional advice, auxiliary services from affiliated entities, and certain payment processing. The resolution expands the definition of acceptable authentication factors for electronic banking login to include Category 3 factors, reflecting advancements in mobile security technologies like asymmetric cryptography. It formally defines the role of the Commissionaire Administrator, clarifies regulations regarding banking correspondents and their operational standards, and strengthens information security requirements to prevent fraudulent transactions and service interruptions. Additionally, the document updates and substitutes Annexes 52, 57, 58, and 59 to align with these regulatory changes.

Secretaria de Hacienda y Credito Publico logo

Mexico

Secretaria de Hacienda y Credito Publico

Click to view thumbnail

DOF: 23/09/2021

RESOLUTION modifying the General Provisions applicable to credit institutions

At the margin, a seal with the National Coat of Arms, which reads: United Mexican States.- TREASURY.- Ministry of Finance and Public Credit.- National Banking and Securities Commission.

The National Banking and Securities Commission, with the prior agreement of its Board of Directors, based on the provisions of Articles 46 Bis 1, 46 Bis 2, 52, eighth paragraph, and 98 Bis of the Credit Institutions Law, as well as Articles 4, fractions XXXVI and XXXVIII, 12, fraction XV, and 16, fractions I and VI of the National Banking and Securities Commission Law, and

CONSIDERING

That in accordance with Article 78 of the General Law for Regulatory Improvement and with the aim of reducing the compliance cost of the General Provisions applicable to credit institutions, the National Banking and Securities Commission, through this modifying resolution, adds seven exceptions to those contemplated in Article 317 of the Provisions, which establish the cases where Chapter XI of Title Fifth of the same shall not be applicable, so that no procedure will be required on the part of the credit institutions before the Commission itself when contracting such services;

That the General Provisions applicable to credit institutions establish that, for the start of session in the electronic banking service, credit institutions must request and validate the user identifier, as well as an authentication factor of category 2 or category 4, which provides reasonable certainty regarding the confidentiality of the information of users of said service. Nevertheless, given the evolution and availability of new technologies that have been developed to facilitate the use of these technologies on mobile devices, allowing the establishment of security specifications for authentication using various layers of security such as those based on asymmetric cryptography (public and private keys), it is necessary to expand the scope of the regulation so that the use of authentication factor category 3 for login or a combination of these is considered as an additional option;

That Article 46 Bis 1 of the Credit Institutions Law allows credit institutions to agree with third parties, including other credit institutions or financial entities, on the provision of services necessary for their operation, as well as commissions to carry out the operations provided for in Article 46 of said law, in accordance with the general provisions issued by the National Banking and Securities Commission;

That the National Banking and Securities Commission has the mission to foster the efficiency and inclusive development of the Mexican financial system for the benefit of society. To this end, it is necessary to bring the use of a range of financial products and services offered by various financial entities to a larger number of population sectors, under appropriate regulation that protects the interests of system users and fosters their financial capabilities;

That the figure of banking correspondence is promoted with the aim of incentivizing the increase in points of distribution of financial services, representing a flexible alternative, with high penetration and low cost for the service provider, for the benefit of the end user. Financial inclusion, through this figure, seeks to attract the population that does not participate in the formal financial system, by increasing opportunities to have access to financial services ranging from savings, credit, payments, and transfers to insurance;

That in this order of ideas, to continue with actions to foster financial inclusion, it is necessary to modify the current regulation regarding contracting with third parties for services and commissions, to facilitate the authorization processes that must be processed before the financial authority and establish the circumstances under which this is not required; providing greater clarity on the requirements that financial entities must present to the National Banking and Securities Commission for such purposes;

That given the importance that the participation of what has been called Commissionaire Administrator in banking correspondents is taking, since through them the operations carried out by the latter can be offered in a uniform manner within a high quality standard, it is necessary to clarify this figure and regulate its participation in the commercial commission contracts that credit institutions celebrate with third parties, and

That despite the flexibilities made to the regulation, it is also important to strengthen the aspects of information security in the processes and technological infrastructure of banking correspondents, to avoid information security incidents that lead to the execution of fictitious transactions from the technological infrastructures of the correspondents and the interruption of services to the public, has resolved to issue the following:

RESOLUTION MODIFYING THE GENERAL PROVISIONS APPLICABLE TO

CREDIT INSTITUTIONS

SOLE. Articles 1, fraction VI; 308, fraction II; 317; 317 Bis, first paragraph and fraction II of the second paragraph; 318; 319; 320; 321; 322; 323, fraction III and second paragraph; 324, fractions II, III, second paragraph, V to XIII and last paragraph; 325; 329, second paragraph; 331, second paragraph; 332 first paragraph and fraction II of the second paragraph; 333; 334, first paragraph and fraction VII; are REFORMED; Articles 308, fourth paragraph; 318 Bis; 318 Bis 1; 321 Bis; 321 Bis 1; 321 Bis 2; 321 Bis 3; and 334, fraction IX; are ADDED; Articles 330 and 335; are REPEALED,

and Annexes 52, 57, 58 and 59 of the "General Provisions applicable to credit institutions", published in the Official Gazette of the Federation on December 2, 2005 and last modified by resolution published in said dissemination medium on August 6, 2021, are SUBSTITUTED, to read as follows:

" Annex 1 to 51

...

Annex 52

Minimum operational and security guidelines for the contracting of technological support services

Annex 53 to 56

...

Annex 57

Criteria to evaluate the experience and technical capacity of commissionaires that

operate under the second section of Chapter XI of Title Fifth of the

provisions

Annex 58

Technical requirements for the operation of electronic media for the operations

contemplated in the Second Section of Chapter XI of Title Fifth of the

provisions

Annex 59.

Information that must be presented in the authorization request of the commissionaire

Annex 60 to 73

... "

" Article 1.-

...

I. to V.

...

VI.

Commissionaire Administrator: The legal person that forms a network of banking commissionaires, that operates under the provisions of Article 321 Bis 2 of these

provisions.

VII. to CXCVII.

... "

" Article 308.-

...

I.

...

II.

An Authentication Factor of Categories 2, 3 or 4 as referred to in Article 310 of the

present provisions.

...

...

...

Regarding Authentication Factor Category 3, Institutions may not consider the use of

external or physical electronic devices delivered to their Users that generate Dynamic

Passwords of single use, nor random tables of Passwords. "

" Article 317.- Institutions may contract with third parties, including other Institutions or

financial entities, the provision of services necessary for their operation, as well as celebrate commissions

to carry out the operations provided for in Article 46 of the Law, subject to what is stated in the present

Chapter XI of Title Fifth of these provisions.

The provisions of this Chapter XI shall not be applicable when Institutions contract the

services indicated below:

I.

Professional or advisory services, including mandates and commissions other than those

celebrated for the carrying out of the operations indicated in Article 46 of the Law.

II.

Auxiliary and complementary services that the Institution receives from the societies referred to in

Article 88 of the Law, from the companies referred to in fraction XII of Article 5 of the

Law to Regulate Financial Groupings, as well as those contracted with their financial

subsidiaries or other financial entities that are part of the financial group to which the

own Institution belongs.

III.

Services for receiving resources from those accredited for the payment of credits in favor of the

accrediting Institution, as well as the carrying out of operational processes and database administration that have as their object the management of their credit portfolio in any of its stages,

when the third party with whom they intend to contract is any development organism supervised by the

Commission or public trust that is part of the Mexican Banking System in terms of the

Article 125 of the Law, or a decentralized organism of the Federal Public Administration,

whose object is to help the priority activity of the State to promote the development of the

agricultural, forestry, fishing and other economic activities linked to the

rural environment, and which are additionally subject to the supervision of the Commission, must

observe what is stated in Article 317 Bis next.

IV.

Referenced payment services for credits charged to Credit or Debit Cards, or in cash,

that are carried out through Specialized Companies used in the network of disposal media

and that, additionally, are subject to the supervision of the Commission as Participants in the

Payment Network with Card, according to such terms as defined in the General Provisions

applicable to the networks of disposal media, issued jointly by the Commission and the

Bank of Mexico, or those that replace them. This is without prejudice to the power of the Commission to

formulate directly to credit institutions the information requirements that derive from

the supervision it carries out as a result of the operations that Institutions carry out through

such Specialized Companies.

V.

Manufacturing,

delivery or distribution services of:

a)

Inactive credit cards, considering those in which a Temporary

Personal Identification Number (PIN) is available, defined or generated by the Institutions themselves, which

must be modified immediately after the Client starts the corresponding Session in

Electronic Media and inactive debit cards.

b)

Check skeletons and passbooks for savings deposits.

VI.

Securities transfer services.

VII.

Services for administrative collection management, including delegated, according to the

terms originally agreed with the client and the recovery of the credit portfolio in administrative or judicial processes. This fraction does not include the receipt of payments referred to in fraction IV of Article 319 of these

provisions.

VIII.

Preventive and corrective maintenance services for equipment and computer systems on the network,

owned, leased, or co-located, provided that the contracted third party does not have

access permissions to know Sensitive Information, security configuration information of

equipment, nor to the administration of access control.

IX.

Telecommunications services for the transmission of information, provided that the

Institutions have:

a)

Redundancy schemes or alternate mechanisms in point-to-point

telecommunications that allow for communication links that minimize the risk of interruption in the

telecommunications service.

b)

Measures to ensure the transmission of User Sensitive Information in encrypted

point-to-point form and elements or security controls at each of the nodes involved in the

sending and receiving of data.

X.

Services related to the management of the Institution, such as cleaning, security,

messaging and correspondence, storage and physical safeguarding of information and documentation,

among others.

XI.

The right to use by software licensing that is installed and resides in the

Technological Infrastructure of the own Institution that is acquiring it.

XII.

The service of processing credit operations in their promotion and evaluation phase.

XIII.

Billing services for company statements that form part of the registry of certifying bodies authorized before the Tax Administration System.

XIV.

Settlement and clearing services for card-related operations related to entities

established as Clearing Houses, in accordance with the General Provisions

applicable to the networks of disposal media, issued jointly by the Commission and the

Bank of Mexico, or those that replace them.

XV.

Certifiers of electronic signature services accredited before the Tax Administration System, as well as the services of issuing certificates of conservation of data messages and

document digitization by service providers of certification authorized by the

Ministry of Economy.

XVI.

The service of administration of databases of biometric information or of consultation of this

information provided by Mexican financial, electoral or tax authorities, or

federal departments.

XVII. The service to develop or administer standardized application programming interfaces

that allow sharing open financial data and aggregated data as referred to in

fractions I and II of Article 76 of the Law to Regulate Financial Technology Institutions;

understanding that regarding the service for the development or administration of

standardized application programming interfaces that allow sharing

transactional data as referred to in fraction III of said Article 76, Institutions must

observe what is provided in Articles 326 or 328 of these provisions, as applicable.

The provisions of Chapter XI of Title Fifth of these provisions shall also not be applicable

when Institutions contract other entities subject to the supervision of the Commission that within their

corporate purpose is the power to receive mandates or commissions and that are allowed to carry out the

operations object of the mandate or commission in question and, additionally, have regulation in

matters of technological risk, use of electronic media and information security, in addition to having

a regulatory regime for contracting with third parties.

Institutions must agree on what is necessary so that the persons who provide them with the services

referred to in this article and those provided in this Chapter XI, keep the due confidentiality of the

information related to active, passive and service operations celebrated with their clients, as well as the

information related to said clients, in case such persons have access to it.

For the services referred to in the previous fraction II, Institutions must have policies and

procedures related to the carrying out of internal or external audits on the services provided,

at least once every two years, in order to evaluate the operational controls implemented, the

compliance with the agreed conditions, as well as the confidentiality and security measures of the

services contracted.

Likewise, said Institutions must maintain the data of the persons who provide them with the

services mentioned in the first and second paragraphs of this article, in the registry referred to in

Article 333 of these provisions.

Article 317 Bis.- Institutions must request the Commission to confirm the exceptions

provided for in fractions III and IV of Article 317 of these provisions, at least 20 business days in

advance of the provision of the service in question. In case the Institution does not receive a written

response from the Commission within a period of 20 business days following the receipt of the request,

the provision of the respective service may begin.

...

I.

...

II.

An explanation of the service to be contracted, specifying the way in which the third party will receive the resources

for the payment of the respective credits, stating whether in addition to such operation, the third party will provide

any other service that requires presenting the notice or obtaining the authorization referred to in the

Articles 326 or 328 of these provisions, respectively.

Article 318.- Institutions, with the exceptions provided for in fractions I to XVII of Article 317

of these provisions, to contract any of the services or to celebrate the

commercial commissions referred to in this Chapter XI, must comply with the following requirements:

I.

Regarding activities that imply acting in front of the general public, at all times, the

third parties that Institutions contract must act in the name and on behalf of the

principal Institution, so that the said relationship must be documented through commercial commission

contracts.

Likewise, in no case, such commissionaires may carry out approvals and openings of

accounts for active, passive and service operations, unless it is about operations of the

provided for in Article 319, fractions IX and X of these provisions.

II.

Have a report that specifies the operational processes or database administration and

computer systems of the Institution that are the object of the services to be contracted, as well as

the policies and criteria for selecting the third party, which will be oriented to evaluate the

experience, technical capacity and human resources of the third party with whom the service is contracted to provide the

service with adequate levels of performance, reliability and security, as well as the effects that

might occur in one or more operations carried out by the Institution.

The policies and criteria referred to in the previous paragraph must be elaborated by the general director

or another official designated by him and approved by the Board of Directors of the

Institution, at the proposal of the Risk Committee or the Audit Committee.

The Audit Committee will be responsible for verifying the implementation of said policies and criteria.

III.

Provide in the service provision or commission contract respectively, the unconditional acceptance

of the commissionaire or of the third party that provides the service, to:

a)

Expressly:

Receive home visits by the external auditor of the Institution, of the Commission or

of the third parties that the Commission itself designates in terms of what is provided in Article

46 Bis 1 and Article 117 of the Law, with the purpose of carrying out the corresponding supervision,

with the purpose of obtaining information to verify that the services or commissions

contracted by the Institution allow the latter to comply with the applicable

dispositions. For the referred visits to be carried out, Institutions may designate a

representative.

Accept the carrying out of audits by the Institution, in relation to the services or

commissions object of said contract, in order to verify the observance of the applicable

dispositions to the Institutions.

Deliver, at the request of the Institution, to the external auditor of the own

Institution and to the Commission or to the third party that said Commission designates, books, systems, records, manuals and

documents in general, related to the provision of the service or commission in

question. Likewise, allow access to the responsible personnel and to their offices and installations

in general, related to the provision of the service in question.

Inform the Institution with at least thirty natural days in advance, regarding

any reform to its corporate purpose or in its internal organization that affects the provision

of the service or commission object of the contracting.

Keep confidentiality regarding the information to which it has access by the

provision of the service or commission, and must, additionally, establish the necessary measures

to maintain the security of the operations and protect the information of the clients,

manifesting understanding and acceptance that, by virtue of what is stated in Article 46 Bis 1,

third paragraph of the Law, what is provided in Article 142 of said Law will also be

applicable to them, as well as to their representatives, executives and employees, even if they cease to

work or provide services to such service providers or commissionaires.

What is provided in sub-items 1. to 5. above shall also be applicable to third parties with

whom service providers referred to in this chapter subcontract directly,

totally or partially, the service provided to the Institution.

b)

In addition to the previous item, the service provision or commission contract respectively must

provide the following:

The restrictions or conditions regarding the possibility that the third party subcontracts, in turn,

the provision of the service.

The obligations that correspond to the Institution and to the third party service provider

or

commissionaire, as well as the procedures to monitor the compliance with said

obligations.

The mechanisms for the resolution of disputes related to the service provision contract

or commercial commission.

The obligations and responsibilities of the parties to protect the information of the

clients of the Institution, the latter having to consider the requirements established by the

legislation in matters of personal data protection for the treatment and transfer of this type

of data, as well as that related to the defense of users of financial

services and any other that has as its object to protect the data of the clients of the

Institution.

The express manifestation that the Institution responds, at all times, for the service

that third parties contracted by it, or its commissionaires, provide to the clients

banking, even if the carrying out of the corresponding operations is carried out

in terms different from those agreed; as well as for the non-compliance with the dispositions in

which said third parties or commissionaires incur, according to what is provided in Article 46 Bis 1,

first paragraph of the Law.

The terms, conditions and processes for the commissionaire or service provider

guarantee the Institution the secure transfer, return, and elimination of information subject to the contracted service when it ceases to provide it.

Establish corrective measures in case of non-compliance by third-party service providers or agents with these provisions.

For services provided by a financial institution from abroad that controls the Subsidiary Institutions operating in Mexico, only subsection a) of this section shall apply.

IV.

Establish guidelines and mechanisms aimed at preventing the adverse effect on and ensuring the adequate provision of the Institution's services to the public, its financial stability, or operational continuity after the contract with the service provider or agent has ended, considering those necessary to verify that the latter does not retain any information from the Institution or its clients.

V.

Comply with the minimum operational and security guidelines set forth in Annexes 52 and 58 of these provisions, as applicable, for the operation of electronic media with agents or if the services to be contracted refer to the use of technological or telecommunications infrastructure.

VI.

Verify that third parties, their shareholders, and, where applicable, subcontractors, as well as agents and their shareholders, where applicable, the Administrator of Agents and the shareholders of the latter, are not included in the official lists issued by Mexican authorities, international organizations, intergovernmental groupings, or authorities of other countries, of persons linked or likely linked to operations with resources of illicit origin, terrorism or its financing, or with other illegal activities. To prove the foregoing, it shall suffice for the Institution to state in writing that it ensured that the persons mentioned in this section were not related in said official lists at the time of their hiring. Additionally, the Institution must state that it knows the business to which the agent is dedicated.

VII.

Have the prior approval of the Board of Directors or the Risk Committee of the Institution of the impact assessment that the contracts referred to in this Chapter XI might have, qualitatively or quantitatively, on the operations carried out by the Institution, according to its purpose, taking into account the following:

a)

The Institution's capacity to, in case of contingency, maintain operational continuity and the carrying out of operations and services with its clients.

b)

The complexity and time required to find a third party that, where applicable, replaces the originally contracted one.

c)

The Institution's ability to maintain appropriate internal controls and timeliness in accounting records, as well as to comply with regulatory requirements in case of service suspension by the third party or agent.

d)

The impact that the service suspension would have on the Institution's finances, reputation, and operations.

e)

The vulnerability of information related to clients.

Institutions that have the status of subsidiaries may contract services with the foreign financial institution that controls them, or with its subsidiaries or affiliated companies, when such contracts aim to carry out the processes referred to in the Third Section of this Chapter XI of this Fifth Title of these provisions. In this case, the Subsidiary Institutions shall not be subject to the provisions of subsections II, III subsection b), IV to VII above, provided that the Subsidiary Institution in question states that it complies with the policies and guidelines established by the aforementioned foreign financial institution; ensures that such policies and guidelines foresee the aspects referred to in this article, and has access to the evaluations and results of the audits carried out by the said foreign financial institution. The same case shall apply for services provided by a third party both to the foreign financial institution and to the subsidiary.

The Commission may, at any time, request the results of the audits referred to in the previous paragraph, through the Subsidiary Institutions.

The Institution must establish policies for the adequate handling, control, and security of information generated, received, transmitted, processed, or stored in the execution of services or commissions related to the use of technological, telecommunications, or information processing infrastructure, carried out partially or totally outside the national territory. The establishment of such policies shall be the responsibility of the General Manager, who may delegate such functions to the areas in charge of the Institution's information security, while the Audit Committee and the Institution's internal auditor shall be responsible for monitoring compliance, according to their respective competencies.

Article 318 Bis.- The information requests and, where applicable, observations or corrective measures resulting from the supervision carried out by the Commission in accordance with these provisions, shall be made directly to the Institution. Likewise, the Commission may, at any time, order the carrying out of the visits and audits indicated in Article 318, subsection III, subsection a) above, specifying the aspects that these must cover, with the Institution being obliged to submit a report to the Commission regarding this matter.

Regarding the operations referred to in subsections IX, X, and XI of Article 319 of these provisions, the Commission, in accordance with the "General Provisions referred to in Article 115 of the Credit Institutions Law" issued by the Secretariat, or those that replace them, may at any time, make information requests, as well as verify with the Institution that the agents it hires have the necessary information to comply with what is provided in said regulation.

Additionally, in the case of operations carried out with multiple banking institutions as principals, the Commission, without prejudice to the powers it exercises in the matter of supervision and oversight over stockbrokers in accordance with the Securities Market Law, may, at the request of the IPAB, carry out inspection visits to stockbrokers acting as agents, in order to verify and evaluate that the latter classify in automated data processing and conservation systems, as well as in any other technical procedures, the information referred to in Annex 58, Section V, Item 3, Letter B), subsection i) of these provisions. In this last case, the Commission shall act in accordance with what is provided in Article 124 of the Law.

Article 318 Bis 1.- The Institution must carry out, at least once every two years, audits aimed at verifying the degree of compliance with this Chapter XI, as well as what is established in Annexes 52 and 58 of these provisions, as applicable, when it comes to commissions for the carrying out of the operations referred to in Article 319 of these provisions or the provision of services for the carrying out of operational processes, the administration of databases or computer systems, as well as the infrastructure, controls, and operation of the service provider's computer center. Without prejudice to the foregoing, the Commission may order the carrying out of said audits in advance of said period, when in its judgment there are risk conditions in the matter of operation and information security.

Article 319.- . . .

I. to III.

. . .

IV.

Payments of credits in favor of the Institution itself or another in cash, charged to credit or debit cards, including payment by means of checks issued for such purposes by the principal Institution or by any other Institution.

V.

Payment orders in the bank offices of the principal Institutions, or through the agents themselves, as well as transfers between accounts, even to accounts of other Institutions.

VI to IX.

. . .

X.

. . .

a) and b)

. . .

In any case, the Institution must have in real time the information related to the clients who open these accounts with the agent, without prejudice to compliance with the other obligations provided in the "General Provisions referred to in Article 115 of the Credit Institutions Law", issued by the Secretariat, or those that replace them.

XI.

Carry out on behalf of the Institutions themselves, the purchase and sale of United States of America dollars in cash exclusively with natural persons.

In the carrying out of the operations referred to in this subsection, the provisions of Annexes 58 and 59 of these provisions shall not apply, nor shall they be obliged to issue an operation receipt to their clients. Notwithstanding the foregoing, the Institutions must have the necessary mechanisms to register and follow up on the daily transactionality they operate through each of their agents. In any case, the control mechanism referred to in this paragraph must contain the necessary elements that allow the Institutions to carry out audits to verify compliance with what is stated in subsection III of Article 323 of these provisions.

In any case, the operations referred to in this subsection may only be carried out by agents whose establishments are located in municipalities or boroughs where it is economically justified that they are recipients of cash dollars, based on the high flow of foreign natural persons and the revenue spill from said persons being significant with respect to the economic activity of the municipality or borough in question, or in municipalities located within the twenty-kilometer strip parallel to the northern international border line of the country or in the States of Baja California or Baja California Sur. For these purposes, the Secretariat will make known to the Institutions the list referred to in 33rd Bis of the "General Provisions referred to in Article 115 of the Credit Institutions Law", issued by the Secretariat, or those that replace them.

Likewise, they may be carried out by agents that have the status of establishments authorized for the exhibition and sale of foreign and national merchandise in international airports, border and high-seas maritime ports, in accordance with subsection I of Article 121 of the Customs Law, regardless of their location.

The Institutions are obliged to supervise that the operations referred to in this subsection are carried out by the agents in accordance with what is established in these provisions, as well as to suspend said operations in the establishments of the agents that incur in any non-compliance with what is established in this subsection.

XII.

Receipt of payments of federal, state, municipal contributions and those corresponding to the Mexico City, in cash or charged to credit or debit cards, or with checks issued for such purposes by the principal Institution.

The operations referred to in subsection IX of this article may only be carried out by Institutions whose Capitalization Index is at least 12 percent, likewise the Institutions must comply with what is established in subsection V of Annex 58 of this regulation. Additionally, for these purposes, said Institutions are not obliged to observe what is provided in Annex 57 of these provisions.

Regarding the operations referred to in subsection VIII of this article that Institutions carry out through agents operating call centers, the principal Institutions may carry out said operations, observing what is provided in Sections First, Third, and Fourth of this Chapter XI, as well as by Article 320 of these provisions.

The operations referred to in subsections I, III, IV, X, and XII of this article may only be carried out in national currency.

Article 320.- Institutions that enter into commercial commissions aimed at carrying out the operations referred to in Article 319 of these provisions through agents, will require presenting for authorization by the Commission, only once, a strategic business plan that contemplates all the operations provided for in the aforementioned article that could be carried out, and must include the model of commercial commission contract that will serve as the basis for the contracts to be entered into with each of the agents with whom it is intended to agree. Regarding development banking institutions, the authorization of the strategic plan may be requested once the exception referred to in Article 47 of the Law has been obtained.

For the purposes of the previous paragraph, the model of commercial commission contract must include what is established in Articles 318, subsection III, and 324 of these provisions.

The strategic plan referred to in the first paragraph of this article must foresee compliance with the requirements indicated in Article 318, subsections I, III, V, and VII of these provisions, without it being necessary to establish the implementation dates of each of the operations indicated in it.

Likewise, the said plan must contain the following aspects:

I.

Description of the automated controls that the Institution will use to prevent agents from exceeding the operational limits established in Article 323 of these provisions.

II.

Qualitative and quantitative information regarding the operations that the Institution will contract with the agent.

III.

The measures that the Institution must implement in the matter of:

a)

Internal control.

b)

Comprehensive risk management.

c)

Prevention of operations with resources of illicit origin and terrorism financing referred to in Article 115 of the Law and the "General Provisions referred to in Article 115 of the Credit Institutions Law" issued by the Secretariat, or those that replace them.

IV.

The procedure that the Institution would employ in the validation for the payment of checks in case of carrying out operations referred to in Article 319, subsection VII of these provisions.

V.

The criteria oriented to evaluate the experience and technical capacity of the agent in accordance with what is provided in Annex 57 of these provisions.

Once authorized by the Commission the strategic plan referred to in the first paragraph of this article, Institutions must request authorization from the Commission regarding reforms to said plan that imply changes to the terms in which they would carry out operations with banking clients and the general public, or when it comes to substantial changes in the conditions of contracting and obligations of the parties established in the model contract, particularly with respect to any of the aspects referred to in Articles 318 subsection III and 324 of these provisions; or if it is intended to operate with new agents not foreseen in the plan authorized by the Commission, with at least thirty natural days in advance of the date on which it is intended that they take effect.

Article 321.- When Institutions intend to carry out a new operation indicated in the strategic plan authorized to them in accordance with Article 320 above, or when they intend to implement new technology to operate with previously authorized agents or Administrators of Agents, they must comply with the following:

I.

Regarding the operations referred to in subsections II, III, V, VI, VII, VIII, IX, X, and XI of Article 319 of these provisions, they must request authorization from the Commission to carry out said operation, accompanying their request letter with the following:

a)

The technical requirements indicated in Annex 59 of these provisions, unless it is about the operations provided for in subsection XI of Article 319 of this regulation, likewise, the description of the new technology and its implementation must be included where applicable.

b)

The draft commercial commission contract to operate with the agent, which contemplates the aspects referred to in Articles 318, subsection III, and 324 of these provisions, in accordance with the authorized strategic business plan.

II.

Regarding the operations referred to in subsections I, IV, and XII of Article 319 of these provisions, they must present a notice to the Commission, stating in the same that the operation will be carried out under the contract to be entered into between the Institution and the agent, in the terms authorized by the Commission, indicating where applicable, if the contract it intends to enter into with the agent presents any variation with respect to the model contract, in which case it must send said draft. The notice referred to in this subsection must be sent to the Commission, and operations referred to in this subsection may begin the day after the corresponding notice is presented, understanding that the Commission may at any time require that operations not be carried out through one or more particular agents when these fail to comply with these provisions. Likewise, Institutions may incorporate in a single notice all the operations indicated in this subsection, which will be carried out with the same agent.

In the celebration of the operations referred to in this subsection, Institutions must comply, at all times, with what is established in Articles 318, subsection III, 321 Bis, 322, 324, and Annexes 57 and 58 of these provisions, keeping evidence of said compliance and keeping it available to the Commission.

Additionally, for the operations referred to in subsections I and II above, Institutions must present together with the request for authorization or notice, as applicable, the Internal Certification Format for Agents (FCIC) with pre-operational test information, duly filled out based on the new operation they intend to carry out.

For this, they must download the updated format of said report available on the Commission's website.

Article 321 Bis.- Institutions, through agents, will provide sufficient information so that their clients know the procedure to present clarifications or complaints derived from operations carried out through said agents, so they must indicate the telephone number and email address of the specialized unit for user attention that the Institution must have in accordance with the Law for the Protection and Defense of Users of Financial Services and the corresponding telephone numbers of the "Call Center" of the National Commission for the Protection and Defense of Users of Financial Services.

Additionally, Institutions will keep fully identified at all times the operations they carry out through agents independently of those they carry out through their other distribution channels.

Institutions will consolidate in a database managed and controlled at all times by the Institution, the clarifications or complaints derived from operations carried out through agents.

Article 321 Bis 1.- Institutions must provide to their banking clients and the general public, through their Internet page, the list of modules and establishments that agents have enabled to carry out the operations referred to in Article 319 of these provisions, specifying the operations that can be carried out in each of them and the maximum amounts authorized per operation, and additionally must provide a telephone number or indicate within the Internet site itself in a prominent way through which means third parties contracted by the Institution as agents can know.

Institutions will verify that agents inform banking clients, through operation receipts, visible announcements in establishments, technological platforms, or by any other means, that they act in the name and on behalf of the Institution itself.

Article 321 Bis 2.- Institutions may authorize legal entities, through a mandate or commission, to contract or participate in the contracting of third parties acting as agents of the Institution to celebrate with clients and the general public, in the name and on behalf of the Institution itself, the operations referred to in Article 319 of these provisions; said persons will receive, for the purposes of these provisions, the name of Administrator of Agents.

The foregoing, understanding that Institutions will grant such powers, with the aim that the Administrator of Agents organizes networks of banking agents so that the services provided are made uniformly, in order to maintain a high quality standard in the carrying out of such operations.

The hiring of the Administrator of Agents will require the authorization of the Commission, for which it must deliver the draft contract of mandate or commercial commission to be entered into between the Institution and the Administrator of Agents, as well as the draft contract with the corresponding agent.

Likewise, the other obligations that the provisions impose on agents and that the Administrator of Agents might supply and prove, without the Administrator of Agents being able to carry out the operations referred to in Article 319 of these provisions.

Additionally, when the Administrator of Agents provides the technological infrastructure service, it must deliver the following:

I.

Description of the support and operational infrastructure services, equipment, automated data processing systems, and telecommunications networks that the Administrator of Agents will provide to agents for the correct carrying out of the operations.

II.

Redundancy schemes or alternate mechanisms in point-to-point telecommunications that allow for communication links that minimize the risk of interruption in the telecommunications service to be adopted by the Commissionaire Administrator or the Institution.

III.

Continuity strategy for the computer services provided to the commissionaire regarding the capacity to process and operate systems in the event of contingencies, failures, or interruptions in telecommunications or central computer equipment and others involved in the information processing service for operations or services.

IV.

Mechanisms to be adopted by the Commissionaire Administrator or the Institution to establish and monitor the quality of information services, as well as system and application response times.

V.

Description of the automated controls that the Commissionaire Administrator will use to prevent commissionaires from exceeding the operational limits established in Article 323 of these provisions, when such operations are carried out using the Commissionaire Administrator's technological infrastructure.

VI.

Description of automated mechanisms to detect and prevent information security events and incidents, as well as to prevent unauthorized incoming or outgoing data connections and flows and information leakage, considering among other things, removable storage media.

VII.

Detailed report of vulnerability scanning test results of the components of the Commissionaire Administrator's technological infrastructure that store, process, or transmit information related to banking operations.

Additionally, the tests referred to in the preceding paragraph must be carried out at least quarterly, and the result reports and evidence of mitigation actions implemented to address critical and high-severity vulnerabilities must be kept available to the Commission.

VIII.

Detailed report of the results of penetration tests carried out by an independent third party, whose personnel have verifiable technical capacity through specialized certifications in the subject matter; these tests must cover the technological infrastructure of the Commissionaire Administrator for commercial commissioning. Additionally, these tests must be carried out at least once a year, and the result reports and evidence of mitigation actions implemented to address critical and high-severity vulnerabilities must be kept available to the Commission.

IX.

Remediation plans regarding the findings of the reviews and tests referred to in fractions VII and VIII above, as well as evidence of the mitigation actions implemented to address critical and high-severity vulnerabilities.

Institutions shall establish in the contracts they enter into with Commissionaire Administrators or in the contracts they enter into with commissionaires where the Commissionaire Administrator participates, as appropriate according to the obligations of each party to the contract, the following:

i.

The obligation of the Commissionaire Administrator to verify and accredit to the Institution that the commissionaires it hires to carry out the operations provided for in Article 319 above comply with the aspects set out in Article 318, fractions II to VII of these provisions, as well as to carry out the audits referred to in Article 318 Bis 1 of this instrument.

ii.

To establish that the Commissionaire Administrator is prohibited from:

a)

Carrying out any of the operations provided for in Article 319 in the name and on behalf of the Institution, nor in its own name.

b)

Advertising or promoting itself in any way through stationery or on the front of the receipts provided to customers for the operations it carries out in the name of the Institution in question.

c)

Subcontracting services related to commercial commissioning.

iii.

The right of the Institution to suspend the contract in the event that the Commissionaire Administrator fails to comply with these provisions.

The Commissionaire Administrator must verify that the commissionaires forming its network comply with what is established in Annex 58 of these Provisions.

Article 321 Bis 3.- Institutions must prepare an annual report regarding the evolution of their business strategic plan, which shall contain qualitative and quantitative information regarding the results obtained during that period. It must also include a comparison with the estimates presented in the strategic plan submitted to the Commission for its authorization, regarding the operations the Institution carries out through commissionaires, as well as a detailed report on any contingencies that may have arisen regarding the provision of services by the commissionaires referred to in this Second Section of this Chapter XI. The aforementioned report must be delivered to the Vice Presidency of the Commission responsible for its supervision during the first quarter of each year.

Article 322.- In carrying out any of the operations referred to in Article 319 of these provisions, Institutions must enter into a deposit contract with the commissionaire as depositor, acting as depositary. To this end, the Institution may grant the commissionaire itself a credit line that allows providing funds to the aforementioned deposit account, when necessary and in accordance with the Institution's own policies.

In any case, the demand deposit account must be charged or credited, depending on the nature of the transaction the commissionaire concludes with the banking client and the general public, transferring funds online to or from the general public's account, or to the Institution's own accounts, as appropriate, for the requested purposes, except for the operations referred to in fraction XI of Article 319 of these provisions.

Institutions must ensure that each operation corresponds to the charges and credits made to the aforementioned accounts.

In the commercial commission contract in which the Commissionaire Administrator participates, Institutions may agree that the latter provides the necessary technological infrastructure and technical support required by the commissionaires with which it operates, solely for the purpose of facilitating and strengthening the support processes for the operations concluded by said commissionaires, without this being understood as the Commissionaire Administrator itself directly carrying out operations with the Institution's clients. Regarding processes related to the compensation and settlement of funds, commissionaires that are part of the Administrator's network may dispense with the deposit account contract; in such cases, the Commissionaire Administrator must have such a deposit account and will be jointly liable for the operations carried out by the commissionaires it administers.

Institutions are exempt from entering into the deposit contract referred to in this article, provided they obtain authorization from the Commission regarding the procedure they would use for the net settlement corresponding to the carrying out of operations with their commissionaires. Such procedure must allow for the online transfer of funds from or to banking clients' accounts, as appropriate.

The payment operations for credits referred to in fraction IV of Article 319 of these provisions may be carried out without the need to transfer funds online, provided that the Institution in question, through its commissionaire, indicates on the respective operation receipt the date or deadline by which the payment made will be credited.

Likewise, regarding the operations referred to in fraction V of Article 319 of these provisions, when carried out in cash to accounts of Institutions other than the principal Institution, the latter must transfer the corresponding funds in the same manner as such operations are carried out in its branches, provided that the Institution in question so agrees with its clients through its commissionaires and indicates on the respective operation receipt the date or deadline by which the respective operations will be credited.

Article 323.- . . .

I.

. . .

II.

. . .

III.

Regarding the cash purchase and sale operations of United States dollars referred to in fraction XI of Article 319 of these provisions, provided that such transactions are carried out for the acquisition of products or services marketed or offered by the commissionaire, the amount of the banking operation may not exceed the equivalent of 250 United States dollars.

Notwithstanding the foregoing, in the event that the commissionaire in question is an establishment authorized to exhibit and sell foreign and national merchandise in international airports, border ports, and high-seas maritime ports in terms of what is provided in fraction I of Article 121 of the Customs Law, or if it is a commissionaire that has the status of an establishment providing lodging services, the limit of operations shall be up to:

a)

An accumulated amount over the course of a calendar month of 1,500 United States dollars, for foreign national individuals.

b)

A daily aggregate amount of 300 United States dollars, restricted to an accumulated amount over the course of a calendar month of 1,500 United States dollars for Mexican national individuals.

The provisions of this fraction are understood to mean that in the event that the currency commissionaire must return Mexican pesos or United States dollars as a result of the commercial operation referred to in the first paragraph of this fraction, such return may not be equal to or greater than the equivalent of 100 United States dollars.

The limits established in this fraction shall apply without prejudice to the Institutions carrying out operations with users or clients.

Institutions must ensure through computer systems and automated controls that the commissionaires they hire do not exceed the limits referred to in this article. Institutions must establish the necessary mechanisms so that, once the limits referred to in this article are reached, the aforementioned commissionaires direct the clients of the Institutions and the general public to the banking offices of the Institutions to carry out these operations.

. . .

. . .

Article 324.- . . .

I.

. . .

II.

The individual and aggregate limits of the operations indicated in Article 323 of this regulation.

III.

. . .

Institutions must provide in the mandate or commercial commission contracts they enter into with the Commissionaire Administrator or in contracts with commissionaires in which it participates, the joint obligation of the Commissionaire Administrator regarding compliance by the banking commissionaires subject to its administration with what is provided in Article 322, fourth paragraph of these provisions.

IV.

. . .

V.

The conventional penalties for breaches of contract, including what is provided in Article 331 of these provisions.

VI.

The other obligations and rights that the parties will have for the execution of the commission.

VII.

To establish that the commissionaire is prohibited from:

a)

Conditioning the carrying out of the banking operation on the acquisition of a product or service, regarding the operations referred to in fractions I to X and XII of Article 319 of these provisions.

The restriction referred to in this subsection shall not apply to cash purchase operations of United States dollars, as referred to in fraction III, in its first and second paragraphs, subsection a), of Article 323 of these provisions.

b)

Advertising or promoting itself in any way through stationery or on the front of the receipts provided to customers for the operations it carries out in the name of the Institution in question.

c)

Carrying out the object of the commission operation under terms different from those agreed with the principal Institution.

d)

Subcontracting services related to commercial commissioning.

e)

Charging commissions, on its own behalf, to banking clients for the provision of services that are the object of commercial commission, or receiving price or rate differentials regarding operations in which it intervenes. This is without prejudice to the payment of commissions that may be agreed between the client and the Institution or between the latter and the commissionaire.

f)

Carrying out operations with banking clients in its own name.

g)

Exclusively agreeing with the principal Institution the carrying out of operations and activities consisting of the receipt of payment for non-banking services, as well as the payment of credit cards.

VIII.

The obligation of the commissionaire to be subject to periodic monitoring procedures by the Institution, relating to information and system security, such that they allow evaluating the robustness of the commissionaire's computer infrastructure for the conclusion of operations, as well as its vulnerability and response capacity against possible computer attacks. Likewise, the provision regarding the fact that non-compliance with what is established in section IV of Annex 58 of these provisions, and in case of refusal, delay, and obstruction by the commissionaire regarding the compliance with said section, shall constitute a cause for rescission of the commercial commission contract.

IX.

The right of the Institution to carry out the security reviews indicated in Article 168 Bis 12, fractions II, III, and IV of these provisions on the services contracted by the commissionaire, or to provide evidence to the Institution of the carrying out of these reviews.

X.

Regarding the operations referred to in fraction XI of Article 319 of these provisions, in order to comply with the "General Provisions referred to in Article 115 of the Credit Institutions Law" issued by the Secretariat, or those that replace them, the obligation of the commissionaire to collect and conserve from the client the following:

a)

For operations up to the equivalent of 250 United States dollars, carried out for the acquisition of products or services marketed or offered by the commissionaire, the following information and documentation must be presented:

Paternal surname, maternal surname, and first name(s) without abbreviations.

Nationality.

Date of birth.

For the purposes of the foregoing, the data regarding the client's name and date of birth must be obtained from an official identification document as indicated in the 4th of the "General Provisions referred to in Article 115 of the Credit Institutions Law" issued by the Secretariat, or those that replace them.

b)

Regarding establishments authorized to exhibit and sell foreign and national merchandise in international airports, border ports, and high-seas maritime ports in terms of what is provided in fraction I of Article 121 of the Customs Law:

The following information and documentation:

i)

Paternal surname, maternal surname, and first name(s) without abbreviations.

ii)

Nationality.

iii)

Date of birth.

iv)

Passport number or passport card.

Type of operation, amount, and date of conclusion.

c)

Establishments providing lodging services:

The following information and documentation:

i)

Paternal surname, maternal surname, and first name(s) without abbreviations.

ii)

Nationality.

iii)

Date of birth.

iv)

Copy of official identification, passport, passport card, or consular registration certificate.

Regarding foreign national individuals, they may be identified with:

i)

Copy of the passport or passport card that accredits their nationality, and

ii)

Copy of the official document issued by the National Institute of Migration, when they have the latter accrediting their entry or legal stay in the country.

d)

Type of operation, amount, and date of conclusion.

Commissionaires must send the Institution the information related to the aforementioned operations, so that the Institution itself complies with the aforementioned Article 115 of the Law and the "General Provisions referred to in Article 115 of the Credit Institutions Law" issued by the Secretariat, or those that replace them, based on the information received from the commissionaires.

XI.

The right of the Institution to suspend operations in the event that commissionaires present changes in their operation contrary to what is provided in the contract, or in any way put the Institution, information security, or the resources of its clients at risk.

XII.

Regarding the operations referred to in fractions IX and X of Article 319 of these provisions, the obligation of the commissionaire to collect the necessary information from the client and transmit it in a timely manner to the Institution, in order to comply with what is provided in Article 115 of the Law and the "General Provisions referred to in Article 115 of the Credit Institutions Law," issued by the Secretariat, or those that replace them.

XIII.

The obligation of the commissionaire to prepare remediation plans regarding the findings of the security reviews and tests carried out as referred to in fraction XII of this article and deliver them to the Institution.

Institutions, in carrying out the operations referred to in this Second Section of Chapter XI, may hire commissionaires to provide their services exclusively, except for what is stated in subsection g) of fraction VII of this article.

Article 325.- Institutions may not enter into commercial commission contracts referred to in this section with the following persons:

I.

Brokerage houses, except when it concerns the operations referred to in fraction IX of Article 319 of these provisions.

II.

Persons whose main business object is the carrying out of the activities referred to in Article 81-A of the General Law of Organizations and Auxiliary Credit Activities.

"Article 329.-

. . .

The general director of the Institution in question or the person designated by him/her, shall be responsible for presenting the notice indicated in Article 326 of these provisions.

. . .

. . .

Article 330.- Repealed.

Article 331.-

. . .

Regarding the services or commissions referred to in the Second Section of this Chapter XI, Institutions must inform the Commission regarding any reform to the social object or internal organization of the third party or commissionaire that could affect the provision of the service that is the object of the contract, within five business days following the receipt of the notification referred to in Article 318, fraction III, subsection a), numeral 4. of these provisions.

Article 332.- The Commission, prior to the right to be heard granted to the Institution, may order the partial or total, temporary or definitive, suspension of the provision of services or commissions through the third party in question, when in the judgment of the Commission itself, the financial stability, information security and of clients or the institution, the operational continuity of the latter, or the protection of public interests may be affected, or when Institutions fail to comply with the provisions contained in this Chapter XI and the others that are applicable. This is without prejudice to, when exercising the aforementioned right to be heard, the Institution presenting a regularization program to be authorized by the Commission, which shall have a term of thirty natural days, counted from the date the respective Institution presents the corresponding request, in order to resolve what is appropriate.

. . .

I.

. . .

II.

Specify the stages and deadlines for each of the actions to be implemented. The execution and compliance with the program shall not exceed six months, counted from its authorization. Regardless of the foregoing, exceptionally, the Commission may authorize only once an extension for up to the same period established in this fraction, when in its judgment, the said extension is duly justified and provided that the non-compliance to be corrected does not put the financial resources or information security of clients at risk; the financial or operational stability of the institution, or constitute a potential risk to the stability of the financial system.

III.

. . .

Article 333.- Institutions must have a registry of commissionaires for the carrying out of the operations referred to in Article 319 of these provisions, as well as a registry of service providers. These registries must include at least the following information:

I.

For the commissionaire registry:

a)

Name, trade name, or corporate name of the commissionaire.

b)

Names of the commissionaire's administrators or, in its case, the legal representative, designated by the commissionaire to attend to any matter related to the commission in question.

c)

Description of the commissionaire, specifying whether it is a commercial chain, franchise, or Commissionaire Administrator, business line, and trade name.

d)

Number of commissionaire establishments or Internet page where they offer their services.

e)

Type of operations the commissionaire carries out in the name and on behalf of the Institution.

f)

The individual and aggregate limits of operations, agreed with the commissionaire.

g)

Settlement means contracted, such as checks, cash, or debit or credit cards.

h)

Access devices used to offer services to Clients, such as Mobile Phone, electronic tablets, Point of Sale Terminals, or any other.

i)

Official document number and date on which authorization was granted for the hiring of the commissionaire

o Commission Agent Administrator.

j)

Official number, if applicable, and date of commencement of operations with the commission agent or

Commission Agent Administrator.

II.

For the registry of service providers:

a)

Name, corporate name, or trade name of the service provider and, if applicable, of the

subcontractors.

b)

Names of the persons designated by the service provider or subcontractor for the

handling of any matter related to the contract in question.

c)

Description of the service, operational process, or systems contracted with the service provider

and, if applicable, with the subcontractors, including the data or information that, if applicable, are

stored or processed by them.

d)

Name of the system that supports the operational process or the administration of databases or

computer systems, contracted with the service provider and, if applicable, with the

subcontractors.

e)

Date of the notice or request for authorization, submitted to the Commission by the Institution and number

of the official letter issued by the Commission.

The Institution shall update the registries referred to in fractions I and II of this article and

keep them available to the Commission.

The Institution shall submit to the Commission within

ninety natural days after the close of the

fiscal year, an annual report detailing the results of the reviews carried out by the Institution, in accordance

with the procedures that it has developed and that form part of the Institution's Internal Control System, to ensure that the service providers or commission agents guaranteed the continuity

of the service with adequate levels of performance, reliability, capacity, security, maintenance,

integrity and with quality standards consistent with the requirements of their needs.

Article 334.- Institutions, in their policies regarding the contracting of services or commissions,

shall consider at least the guidelines and criteria for the selection of these, as well as the

evaluation measures of the contracted services and commissions. Within the evaluation measures of

the

services or commissions referred to in this chapter, the following shall be considered:

I. to VI.

. . .

VII.

The capacity of the Institutions, in the Integrated Risk Management, to identify, measure,

monitor, limit, control, report and disclose the risks that may arise from the provision of the

services or commissions referred to in this Chapter XI.

VIII.

. . .

IX.

The results of the vulnerability scanning tests and penetration tests referred to in

Article 168 bis 12, fractions III and IV of these provisions.

. . .

. . .

. . .

Article 335.- Repealed.

TRANSITORY PROVISIONS

FIRST. This Resolution shall enter into force the day following its publication in the Official Journal

of the Federation.

SECOND. Institutions shall have a period of 180 days counted from the entry into force

of this legal instrument to comply with what is established in Annex 58, fraction IV of these

provisions.

Respectfully,

Mexico City, September 13, 2021. - President of the National Banking and Securities Commission, Juan Pablo Graf Noriega. - Signature.

ANNEX 52

MINIMUM OPERATIONAL AND SECURITY GUIDELINES FOR THE CONTRACTING OF

TECHNOLOGY SUPPORT SERVICES

Institutions shall consider the following aspects:

I.

Operational Aspects

a.

Redundancy schemes or alternate mechanisms in point-to-point telecommunications

that allow for communication links that minimize the risk of interruption in the

telecommunications service.

b.

Continuity strategy in the computer services provided to the Institution that provide the

capacity to process and operate systems in case of contingency, failures or interruptions in

the telecommunications or of the central computer equipment and others that are involved in

the

information processing service of operations or services.

c.

Mechanisms to establish and monitor the quality of information services, as well as the

response times of systems and applications.

d.

Technical support scheme, in order to solve problems and incidents, independently,

if applicable, of differences in time zones and business days.

e.

Mechanisms that will allow the Institution to keep under its custody, either in

Own Technological Infrastructure or of third parties, in both cases in national territory, the

detailed records of all Operations carried out, as well as their accounting records in such a way as to ensure operational continuity at all times. Such records

shall be kept in a format that allows their consultation, operation and use by the

Commission at all times.

II.

Security Aspects

a.

Measures to ensure the transmission of Sensitive User Information in encrypted form

point-to-point and elements or security controls in each of the nodes involved in the

sending and receiving of data.

b.

Establishment of functions of the Chief Information Security Officer in accordance with

what is established in Articles 168 Bis 13 and 168 Bis 14 of the provisions. For the purposes of the

present annex, the security officer must have at all times the records of all

personnel who have access to information related to the Institution's operations,

even that located outside national territory, in which case the personnel authorized to

access such information must be authorized by the person responsible for the functions of

internal audit of the Institution, in accordance with what is stated in Article 167 of these

provisions.

c.

Scheme by which the

access log to information by duly authorized personnel will be maintained in an office of the contracting credit institution.

III.

Audit and Supervision

a.

Policies and procedures regarding the carrying out of internal or external audits on the

infrastructure, controls and operation of the third party's computer center, related to the

production environment for the credit institution, at least once every two years in order

to evaluate compliance with what is mentioned in this annex.

b.

Mechanisms for access to the technological environment, including information, databases and

security configurations, from the Institution's facilities in national territory.

ANNEX 57

CRITERIA TO EVALUATE THE EXPERIENCE AND TECHNICAL CAPACITY OF COMMISSION AGENTS THAT

OPERATE UNDER THE SECOND SECTION OF CHAPTER XI OF TITLE FIFTH

OF THE

PROVISIONS

It shall be presumed that commission agents have sufficient technical capacity when they declare under

oath that they comply with the following:

Their personnel is trained to properly operate the Electronic Media that the

Institution makes available to them to authenticate banking clients.

Have the necessary infrastructure to carry out the processing of the operations subject

of the banking service.

Be legal entities or natural persons with business activity and have a permanent establishment, understood as any place of business in which activities are developed, partially or

totally, business activities or independent personal services are provided, such as

offices, branches, agencies, or other facilities

Have their own business line.

Have honorability and satisfactory credit and business history; to this effect, it will be considered

that they meet this requirement the commission agents that:

a)

Enjoy a good credit history according to Credit Information Reports and are

up to date in the fulfillment of their credit obligations.

b)

By themselves or through intermediaries, have not caused loss, damage or

patrimonial detriment, to the detriment of credit institutions or issuing companies

in the securities market.

c)

Have not been declared in civil or commercial bankruptcy.

d)

If applicable, have not been convicted by a final judgment for intentional crime that imposes a penalty of more than one year of imprisonment.

e)

If applicable, have not been convicted by a final judgment for patrimonial crimes

committed intentionally regardless of the penalty.

f)

If applicable, have not been subject to investigation or administrative investigation

proceedings before the Commission for serious violations of national or foreign financial laws, or before other Mexican supervisory and regulatory institutions of the

financial system or of other countries, which have had as a conclusion any type of

final and definitive resolution or agreement in which the interested party has not been expressly exempted.

With respect to Entities of the Federal, State or Municipal Public Administration, it shall be sufficient that

they comply with what is stipulated in items 1 and 2 of this Annex and are expressly authorized by

their law or regulation, to provide the services or commissions in question.

Institutions may exempt from compliance with the requirements stipulated in items 3, and 5,

subparagraph a) of this annex, with respect to commission agents managed by a Commission Agent Administrator, it being sufficient for the said Commission Agent Administrator to comply with all the

requirements provided for by this annex.

ANNEX 58

TECHNICAL REQUIREMENTS FOR THE OPERATION OF ELECTRONIC MEDIA FOR THE

OPERATIONS CONTEMPLATED IN THE SECOND SECTION OF CHAPTER XI OF TITLE

FIFTH

OF THE PROVISIONS

The Electronic Media that Institutions use to guarantee the correct execution of the

banking operations that are carried out through commission agents and of information security of the

banking clients and the general public, must comply with the requirements referred to in the

present annex.

The Institution must have evidence of the compliance verification carried out prior to the start of

operations and at least once a year, of the following aspects and keep it available to the Commission

when it so requires.

With respect to Commission Agent Administrators, they must verify that the commission agents that

form their network comply with what is established in this Annex.

For the purposes of this Annex, "Operator" shall be understood as the employee of the commission agent who has

access to the Electronic Media.

I.

Requirements of Electronic Media

Mechanisms necessary to carry out online transactions.

The Electronic Media must have the necessary mechanisms to carry out the

online transactions, that is, at the very moment the operation is carried out,

updating the client's balances online except for the operations referred to in

fractions I, IV and XII of Article 319 of these provisions, where they may

perform the

balance update in accordance with what is established by the operating rules of the respective

Institutions.

For these purposes, the operations of cash or debit card service payments, or

charged to Bank Accounts, cash deposit, cash credit payment and fund status;

shall be recorded as a charge to the deposit account that the commission agent has

with the Institution. On the other hand, cash withdrawal and check payment operations shall

be recorded as a credit to the same account.

In cases where the client's balance information is stored in devices such as

integrated circuit cards or equipment located at the commission agent's facilities, it

shall not be considered as an online affectation carried out on such devices, as long as

there are mechanisms for their periodic consolidation in the central systems of the

Institutions.

With respect to the operations referred to in fractions I and IV of Article 319 of these

provisions and in case the processing is carried out through the batch scheme,

they must maintain controls implemented for the secure sending of files, as well as for

the reconciliation and settlement of the operations carried out through this medium.

Validation of Commission Agent's Electronic Media.

Only the Electronic Media of the commission agents authorized by the Institution will have

access to the infrastructure provided by it (use of dedicated lines, identification of physical or logical addresses, VPNs, digital signatures, among others).

The Institution's computer systems must authenticate the Electronic Media that the

commission agents use to carry out banking operations.

Certification of Commission Agent's Electronic Media.

The Institution shall be responsible for certifying the installation and use of the Electronic Media

that the commission agent maintains for the carrying out of banking operations, as well as for

establishing annual evaluations of said Electronic Media. Such certification may be

carried out by the Institution, if applicable, through its specialized technical areas in information

security or internal system audit, or through independent third parties,

contracted by the Institution itself, who must prove to it that they have

adequate technical credentials in computer or system audit.

The aforementioned certification must consider at least that the Institution must

ensure at all times that the electronic media used by the commission agents

maintain control mechanisms that prevent the reading and extraction of client information by unauthorized third parties.

Policies and procedures for the administration of access and configuration of Electronic

Media.

It is the responsibility of the Institution to verify that the commission agent has policies and

procedures for:

a)

The configuration of the Technological Infrastructure that connects to the systems

computer systems of the Institution.

b)

The administration of cryptographic keys used between the commission agents and the

systems of the Institution.

Generation of electronic records of operations.

All operations carried out through the commission agents must generate electronic records

that cannot be modified or deleted and in which must be included at least

the date, hour and minute, the type and amount of the instruction, the client's account number

banking, physical location of the counter or medium through which the instruction was executed, as well

as sufficient information to allow the identification of the personnel who carried out the

instruction. The custody of such records shall be the responsibility of the Institution.

II.

Requirements for Operator Identification and Banking Client Authentication.

Mechanisms necessary for the full identification of the Operators who will connect through

the commission agents.

Generation and delivery of Operator Access Passwords or Keys.

Institutions must establish mechanisms for the generation and delivery process of

the Authentication Factors that ensure that only the commission agent, and if applicable, the

Operators can know.

Composition of Operator Access Passwords or Keys.

Criteria must be established for the characteristics of the length of the Operator Access Passwords or Keys.

Protection of Access Passwords or Keys and Personal Identification Numbers (PIN).

Institutions must provide what is necessary to prevent the reading of the characters that

compose the Access Passwords or Keys, as well as the Personal Identification

Numbers (PIN) entered by banking clients, respectively, in the Electronic Media

of access, both in their capture and in their display through the screen.

The Access Passwords or Keys and the Personal Identification Numbers (PIN) must

be validated and stored through encryption mechanisms, whose cryptographic keys must

be under the administration and control of the Institution in question. At no time, the

commission agents may have access to the data or algorithms related to said

Access Passwords or Keys and Personal Identification Numbers (PIN).

Commission agents must have certifications of security standards of the

card industry for the security requirements and PIN transactions (PTS) or their equivalents or

those that, in the opinion of the Commission, allow the proper protection of the information

stored, transmitted or processed related to the entry of the Personal Identification Numbers (PIN)

of banking clients and bank card data.

Authentication for banking clients.

For the carrying out through the commission agents of consultations and operations that represent a

charge to the banking clients' accounts, the latter must authenticate themselves through the Electronic Media with which the aforementioned operations are carried out using two

Different Authentication Factors.

For the purposes of the foregoing, Institutions may opt for the combination of at least two of

the following Authentication Factors and comply with what is stipulated in Chapter X of Title

Fifth of these Provisions:

a)

Debit or credit cards with security mechanisms such as cards with

magnetic stripe and/or integrated circuit or "chip".

b)

Personal Identification Number (PIN).

In the case that debit or credit cards are used, card readers must be used,

such as PIN PADS, for the Authentication of banking clients, which must have

a screen and a keyboard exclusively designed for the banking client to

enter the information of their respective card and their Personal Identification Number (PIN), as well as mechanisms that prevent their reading by third parties.

Commission agents must have certifications of security standards of the

card industry for the security requirements and PIN transactions (PTS) or their

equivalents or those that, in the opinion of the Commission, allow the proper protection of the

information stored, transmitted or processed related to the entry of the

Personal Identification Numbers (PIN) of banking clients and the data of the

bank cards.

In the case of using a cell phone, the Personal Identification Number (PIN) must be

entered directly on the keyboard of said phone. At no time may the information of the

PIN be stored on the cell phone without encryption mechanisms.

c)

Biometric Factor.

In case biometric readers are used for the Authentication of banking clients, said

readers must have mechanisms that ensure that it is the authorized client who carries out the

operation, as well as implement mechanisms or procedures so that the commission agent does not

store the information processed related to the biometric factors of clients.

All administration and control of biometric information must be the sole responsibility

of the Institution through the customer service channels that it has established.

d)

Cell phone.

In case cell phones are used for the Authentication of banking clients, the

Institutions must verify that the technology of said cell phones allows them to

function as an Authentication Factor and that it has security mechanisms that prevent

duplication or spoofing.

Institutions may not use the combination of the Authentication Factors referred to in

subparagraphs a) and d) to authenticate their clients.

Authentication for Operators.

For the receipt and operation of transactions requested by banking clients through the

Electronic Media of the commission agents, the Operators must start a session and

authenticate themselves through said Media.

The authentication processes must be validated by the Institution, through the

mechanisms and controls that it deems appropriate. It is the responsibility of the Institution

to ensure that the commission agents have said operator authentication mechanisms, for the carrying out of the operations.

Blocking of Operator Authentication Factors.

Blocking schemes for Operator Authentication Factors must be established when

an attempt is made to enter the Electronic Media incorrectly. At no time may the

failed access attempts exceed five consecutive occasions without generating automatic blocking.

Access to banking client data.

At no time may the Electronic Media used by the commission agents allow the

carrying out of operations or balance inquiries without prior Authentication in terms of

item 5 of section II "Requirements for Operator Identification and Authentication

banking clients" of this annex, of the corresponding client. Deposits and payments operations are excepted from this case.

Likewise, with respect to banking operations that require the commission agent to access the

balances of banking clients' accounts, said commission agent must, at all times,

keep confidentiality regarding said operation and carry out prior to the respective access

the Authentication referred to in item 1 of section III "Electronic Media Operations"

of this annex.

III.

Electronic Media Operations

Validation of destination account structure.

The Electronic Media of the commission agents must validate, based on the information

available to the Institution, the structure of the destination account number or contract, whether

it is for deposit accounts, service payments, Standardized Banking Key, credit cards or other payment means.

Generation of operation receipts.

The Electronic Media must automatically generate the operation receipts that

are issued by the Institutions for each operation, without any intervention by the

personnel of the commission agent. Such operation receipts will be different from those used by the commission agents to record the operations of their own business and must include what is stipulated by the General Provisions of CONDUSEF in matters of

transparency and sound practices applicable to credit institutions. In addition to the

referred provisions, Institutions must consider in the operation receipts the following:

a)

The data that allow the banking client to identify the account with respect to which the

operation was carried out. At no time must the full number of the account be displayed on the receipts.

b)

The information regarding balance inquiries, when the client has requested and authorized it, in which case it must be provided only to the client through the corresponding receipt. The commissionaire may not issue a duplicate of said receipt or keep a copy of it.

c)

The identification of the Institution and the commissionaire with whom the operation was carried out, specifying in the latter case, the address of the establishment through which the instruction was executed.

d)

The information that allows the identification of the commissionaire's personnel who performed the instruction.

When the limits referred to in Article 323 of these provisions are exceeded, as applicable, the requested operations cannot be carried out; therefore, the Electronic Means must generate receipts indicating to the banking client this situation. For these purposes, a receipt must be provided that includes the following legends:

a)

In the case of the limit referred to in Article 323, fraction II, subsection b) of these Provisions: "Transaction not performed due to exceeding its permitted limit. Go to a bank branch."

b)

In the case of the limits referred to in Article 323, fractions I and II, subsection a) of these Provisions, as applicable: "Transaction not performed". Under no circumstances should the client's address be shown on the operation receipt.

Institutions will make available to their clients on operation receipts the information regarding the telephone number and email address of the specialized unit for user assistance that the Institution must have in terms of the Law for the Protection and Defense of Users of Financial Services, as well as the Institution's attention center.

All operation receipts issued through commissionaires will have probative value for any clarification purposes and must be recognized as such by the Institutions issuing them.

Monitoring of operations.

The Institution must establish continuous mechanisms using computer tools that allow it to monitor the activities performed by Operators through the Electronic Means of the commissionaires in order to detect transactions that deviate from usual operational parameters.

Storage of Sensitive User Information in Electronic Means of commissionaires.

In cases where, for operational and technical reasons, it is necessary to store partially or totally Sensitive Information of the User of the Institution in the Electronic Means of the commissionaire, the institution must verify that encryption mechanisms exist.

Likewise, commissionaires may not issue a duplicate of balance inquiry receipts or keep copies of these.

IV.

Information Security

Logical or logical and physical segregation of different networks in distinct domains and subnets, depending on the function they perform or the type of data transmitted, including segregation of production environments from development and testing environments, as well as perimeter and network security components that ensure that only authorized traffic is permitted. In particular, in those segments with links to the outside, such as the Internet, providers, authorities, other networks of the Institution or headquarters, Administrators, commissionaires, and other third parties, consider safe zones, including those known as demilitarized zones (DMZ).

Secure configuration of components, considering at least, ports and services, permissions granted under the principle of least privilege, use of removable storage media, access lists, manufacturer updates, and reconfiguration of factory parameters.

Security measures for their protection, as well as for the access and use of information that is received, generated, transmitted, stored, and processed in the technological infrastructure, having at least the following:

a)

Identification and authentication mechanisms for each and every one of the users of the technological infrastructure, which allow them to be recognized unequivocally and ensure access only to persons expressly authorized for this purpose, under the principle of least privilege. For this purpose, relevant controls must be included for those users of the technological infrastructure with greater privileges, derived from their functions, such as database and operating system administration.

b)

Encryption of information according to the degree of sensitivity or classification that the Institution determines and establishes in its policies, when such information is transmitted, exchanged, and communicated between components, or stored in the technological infrastructure or accessed remotely.

c)

Access keys with composition characteristics that prevent unauthorized access, considering processes that ensure that only the user of the Technological Infrastructure knows them, as well as security measures, encryption in storage, and mechanisms to change access keys every 90 days or less.

d)

Controls to automatically terminate unattended sessions, as well as to prevent simultaneous unauthorized sessions with the same user identifier of the technological infrastructure.

e)

Security mechanisms, both physical access and environmental and electrical energy controls, that protect the technological infrastructure and allow operation in accordance with the specifications of the supplier, manufacturer, or developer.

f)

Validation measures to guarantee the authenticity of transactions executed by the different components of the technological infrastructure, considering, at least the following:

i.

The veracity and integrity of the information.

ii.

The authentication between components of the technological infrastructure, which ensure that only legitimate service requests are executed from their origin to their execution and registration.

iii.

Messaging, communication, and encryption protocols, which must ensure the integrity and confidentiality of the information.

iv.

The identification of atypical transactions, anticipating that applications have automatic alert measures for attention by the corresponding operational areas.

g)

The update and maintenance of digital certificates and components provided by service providers that are integrated into the transaction execution process.

Automated mechanisms to detect and prevent information security events and incidents, as well as to prevent unauthorized incoming or outgoing data connections and flows and information leakage, considering among others, removable storage media.

Policies and procedures for the administration of encryption keys used by the Institution and the commissionaire, as applicable.

Policies and procedures for secure deletion for the destruction of data when they are no longer necessary, or upon the conclusion of the commercial commission.

Policies and procedures for the management of information security incidents of commissionaires that ensure the detection, classification, attention, and containment, investigation, and, if applicable, digital forensic analysis, diagnosis, reporting to competent hierarchical levels, solution, follow-up, and immediate communication to the Institution and counterparties of such incidents.

Registration in databases of incidents, failures, or vulnerabilities detected in the Technological Infrastructure of the commissionaire, which includes at least the information related to the detection of failures, operational errors, attempts at computer attacks and those effectively carried out, as well as loss, extraction, alteration, misplacement, or improper use of information of the Users of the Technological Infrastructure of the commissionaire, where the date of the event and a brief description of it, its duration, affected service or channel, amounts, as well as the corrective measures implemented are contemplated.

Likewise, maintain complete audit records that include detailed information of accesses or access attempts and the operation or activity performed by the Users of the Technological Infrastructure. Such records must be available to authorized personnel of the Institution.

Performance of vulnerability scanning tests of the technological infrastructure components of commissionaires that store, process, or transmit information of banking operations. Such tests must be performed at least quarterly.

Performance of penetration tests by an independent third party, whose personnel have verifiable technical capacity through specialized certifications in the matter, such tests must contemplate the technological infrastructure of the commissionaire for commercial commission. The tests must consider, at least the following:

a)

Its scope and methodology.

b)

Be performed at least once a year.

c)

Additional tests must be performed when there are significant changes in systems and applications, or perform them on previously reviewed systems and applications when critical vulnerabilities exist.

Continuous follow-up to remediation plans regarding the findings of the reviews and tests referred to in the previous items 9 and 10. Such plans must be reviewed by the institution and follow up on the actions implemented for their mitigation.

Have access controls to information according to the access levels and profiles determined by the Institution.

V.

Requirements for the operation referred to in fraction IX of Article 319 of these provisions

That the systems of the Institution, as well as, if applicable, those of the brokerage houses with which they intend to enter into commercial commissions, have the necessary technical requirements that allow them to comply with what is stipulated in Article 124 of the Law, as well as to receive and transmit the information referred to in the "General Rules to which multiple banking institutions must be subject to classify information related to active and passive operations referred to in Article 124 of the Credit Institutions Law", and those issued by the IPAB, or those that replace them, including what is stated in the following item 3.

The procedures through which the Institution will authorize the brokerage houses to carry out such operations.

The obligation of the commissioning brokerage house to:

a)

Collect from the client the necessary information in order to comply with what is provided in Article 115 of the Law and the "General Provisions referred to in article 115 of the Credit Institutions Law" issued by the Secretariat, or those that replace them.

For this purpose, the brokerage houses must transmit in a timely manner to the Institution the information related to the mentioned operations, so that the Institution itself complies with the cited Article 115 of the Law and the "General Provisions referred to in article 115 of the Credit Institutions Law" issued by the Secretariat, or those that replace them.

b)

Regarding operations carried out with multiple banking institutions as principals:

i.

Collect and classify in automated processing and data conservation systems, as well as in any other technical procedure, all the information that allows the multiple banking institution to comply with the Third of the "General Rules to which multiple banking institutions must be subject to classify information related to active and passive operations referred to in Article 124 of the Credit Institutions Law" issued by the IPAB or those that replace them;

ii.

Transmit to the multiple banking institution principal, simultaneously at the moment of the celebration of each operation, through its systems, the information that, in accordance with the Rules referred to in the previous item, the latter must maintain. This is without prejudice to the fact that the contracts referred to in this article must contain the obligation on the part of the brokerage houses acting as commissionaires to transmit to the multiple banking institution principals all the information referred to in the Third of the Rules mentioned in the previous item i., when so requested by the Commission, directly or at the request of the IPAB, provided that the corresponding assumptions of the resolution of the multiple banking institution principal in terms of Article 122 Bis of the Law are met;

iii.

Obtain from the client at the time of celebrating the operations, a written manifestation or by any means agreed with the banking client, in the terms of the format contained as Annex 60 of these provisions, and

iv.

Deliver to the client, on the back of the document referred to in the previous item iii., or by any means agreed with the banking client, an informative text in the terms established in Annex 61 of these provisions.

c)

The terms under which the settlement of the operations must be carried out.

In the event that the settlement of the respective operations is carried out in the offices of the brokerage houses, deliver to the client the respective amount in the manner agreed at the time of contracting. In any case, if the client does not request the referred settlement at the office within a period of three business days counted from the maturity date of the operation, the brokerage house will be released from the obligation to make the corresponding payment in favor of the client, so the settlement must be carried out directly with the Institution.

The obligation on the part of the Institution to provide the necessary means in order to comply with the provisions referred to in the previous items 1 and 2 and, in general, to what is established by the provisions related to the banking savings protection system, as well as to ensure that the commissionaire effectively complies with the foregoing.

Annex 59

Information that must be presented in the commissionaire authorization request

The information to be presented in the commissionaire authorization request must contain at least the following:

Detailed description and flowchart of the processes of each of the operations to be carried out through the commissionaires considering the reconciliation and settlement process of each of them, the third parties involved, and the Technological Infrastructure to be used in the operation in question.

Architecture and telecommunications diagram showing the security and network components of the technological infrastructure used for the operation with commissionaires, which ensure that only authorized traffic is permitted. This diagram must include each of the participants, as well as all information processing sites including redundancy schemes, link types, backup routes, servers, and communication devices.

The complete and detailed locations of the main and backup data centers, both of the Institution, the commissionaire, or the provider of the commissionaire's technological infrastructure where the information of the transactions carried out through the commissionaire will be stored and/or processed (street, exterior and interior number, neighborhood, borough or municipality, state, and country).

Diagram of interrelation of commissionaire applications or systems, including the Institution's own systems. (Must include all participants involved in the operation (e.g.: commissionaire, switches, payment media processors, third parties, and the Institution itself).

Detail of the Sensitive Information that will be stored by the commissionaire in its equipment or facilities, or by the provider of the commissionaire's technological infrastructure, or to which they may have access. Regarding Sensitive Information, the commissionaire must implement encrypted storage mechanisms.

Include the characteristics of the operation receipts, attach the design of the receipt of each of the operations to be contracted.

Description of validation measures to guarantee the authenticity of transactions executed by the different components of the technological infrastructure, considering, at least the following:

a)

The veracity and integrity of the information.

b)

The authentication between components of the technological infrastructure, which ensure that only legitimate service requests are executed from their origin to their execution and registration.

c)

Messaging, communication, and encryption protocols, which must ensure the integrity and confidentiality of the information.

d)

The identification of atypical transactions, anticipating that applications have automatic alert measures for attention by the corresponding operational areas.

Description of automated mechanisms to detect and prevent information security events and incidents, as well as to prevent unauthorized incoming or outgoing data connections and flows and information leakage, considering among others, removable storage media.

Detailed report of vulnerability scanning test results of the technological infrastructure components of commissionaires that store, process, or transmit information of banking operations.

Detailed report of penetration test results performed by an independent third party, whose personnel have verifiable technical capacity through specialized certifications in the matter, such tests must contemplate the technological infrastructure of the commissionaire for commercial commission.

Remediation plans regarding the findings of the reviews and tests referred to in the previous items 9 and 10, as well as evidence of mitigation actions implemented to remedy critical and high severity vulnerabilities.

Documentation of the Internal Certification Formats of Commissionaires (FCIC) related to the pre-operational tests of operations to commissionaires.


In the document you are viewing, there may be text, characters, or objects that are not displayed correctly due to conversion to HTML format, so we recommend always taking the digitized image of the DOF or the PDF file of the edition as a reference. The content, form, and scope of the published documents are the strict responsibility of their issuer.

CONSULT

BY DATE

Su Mo Tu We Th Fr Sa

INDICATORS

Exchange Rate and Rates as of 08/28/2026

DOLLAR 16.9712 UDIS 8.808812 TIIE 28 DAYS 6.7559% TIIE 91 DAYS 6.7931% TIIE 182 DAYS 6.8474% TIIE OVERNIGHT 6.50%

See more

SURVEYS

Did you like the new image of the Official Gazette of the Federation website?

No Yes

Official Gazette of the Federation

Río Amazonas No. 62, Col. Cuauhtémoc, C.P. 06500, Mexico City Tel. (55) 5093-3200, where you can access our service menu

Electronic address: dof.gob.mx

113

LEGAL NOTICE | SOME RIGHTS RESERVED © 2026

More like this from SHCP

SHCP published 14 documents in the last 30 days. We email you each new one the day it's published.

Share