2021-09-23 | DOF 5630657Added · Updated
The National Banking and Securities Commission amends the General Provisions applicable to credit institutions to introduce seven exceptions to the prior authorization requirements for outsourcing services under Article 317, thereby exempting institutions from filing procedures for specific services such as professional advice, auxiliary services from affiliated entities, and certain payment processing. The resolution expands the definition of acceptable authentication factors for electronic banking login to include Category 3 factors, reflecting advancements in mobile security technologies like asymmetric cryptography. It formally defines the role of the Commissionaire Administrator, clarifies regulations regarding banking correspondents and their operational standards, and strengthens information security requirements to prevent fraudulent transactions and service interruptions. Additionally, the document updates and substitutes Annexes 52, 57, 58, and 59 to align with these regulatory changes.
DOF: 23/09/2021
RESOLUTION modifying the General Provisions applicable to credit institutions
At the margin, a seal with the National Coat of Arms, which reads: United Mexican States.- TREASURY.- Ministry of Finance and Public Credit.- National Banking and Securities Commission.
The National Banking and Securities Commission, with the prior agreement of its Board of Directors, based on the provisions of Articles 46 Bis 1, 46 Bis 2, 52, eighth paragraph, and 98 Bis of the Credit Institutions Law, as well as Articles 4, fractions XXXVI and XXXVIII, 12, fraction XV, and 16, fractions I and VI of the National Banking and Securities Commission Law, and
CONSIDERING
That in accordance with Article 78 of the General Law for Regulatory Improvement and with the aim of reducing the compliance cost of the General Provisions applicable to credit institutions, the National Banking and Securities Commission, through this modifying resolution, adds seven exceptions to those contemplated in Article 317 of the Provisions, which establish the cases where Chapter XI of Title Fifth of the same shall not be applicable, so that no procedure will be required on the part of the credit institutions before the Commission itself when contracting such services;
That the General Provisions applicable to credit institutions establish that, for the start of session in the electronic banking service, credit institutions must request and validate the user identifier, as well as an authentication factor of category 2 or category 4, which provides reasonable certainty regarding the confidentiality of the information of users of said service. Nevertheless, given the evolution and availability of new technologies that have been developed to facilitate the use of these technologies on mobile devices, allowing the establishment of security specifications for authentication using various layers of security such as those based on asymmetric cryptography (public and private keys), it is necessary to expand the scope of the regulation so that the use of authentication factor category 3 for login or a combination of these is considered as an additional option;
That Article 46 Bis 1 of the Credit Institutions Law allows credit institutions to agree with third parties, including other credit institutions or financial entities, on the provision of services necessary for their operation, as well as commissions to carry out the operations provided for in Article 46 of said law, in accordance with the general provisions issued by the National Banking and Securities Commission;
That the National Banking and Securities Commission has the mission to foster the efficiency and inclusive development of the Mexican financial system for the benefit of society. To this end, it is necessary to bring the use of a range of financial products and services offered by various financial entities to a larger number of population sectors, under appropriate regulation that protects the interests of system users and fosters their financial capabilities;
That the figure of banking correspondence is promoted with the aim of incentivizing the increase in points of distribution of financial services, representing a flexible alternative, with high penetration and low cost for the service provider, for the benefit of the end user. Financial inclusion, through this figure, seeks to attract the population that does not participate in the formal financial system, by increasing opportunities to have access to financial services ranging from savings, credit, payments, and transfers to insurance;
That in this order of ideas, to continue with actions to foster financial inclusion, it is necessary to modify the current regulation regarding contracting with third parties for services and commissions, to facilitate the authorization processes that must be processed before the financial authority and establish the circumstances under which this is not required; providing greater clarity on the requirements that financial entities must present to the National Banking and Securities Commission for such purposes;
That given the importance that the participation of what has been called Commissionaire Administrator in banking correspondents is taking, since through them the operations carried out by the latter can be offered in a uniform manner within a high quality standard, it is necessary to clarify this figure and regulate its participation in the commercial commission contracts that credit institutions celebrate with third parties, and
That despite the flexibilities made to the regulation, it is also important to strengthen the aspects of information security in the processes and technological infrastructure of banking correspondents, to avoid information security incidents that lead to the execution of fictitious transactions from the technological infrastructures of the correspondents and the interruption of services to the public, has resolved to issue the following:
RESOLUTION MODIFYING THE GENERAL PROVISIONS APPLICABLE TO
CREDIT INSTITUTIONS
SOLE. Articles 1, fraction VI; 308, fraction II; 317; 317 Bis, first paragraph and fraction II of the second paragraph; 318; 319; 320; 321; 322; 323, fraction III and second paragraph; 324, fractions II, III, second paragraph, V to XIII and last paragraph; 325; 329, second paragraph; 331, second paragraph; 332 first paragraph and fraction II of the second paragraph; 333; 334, first paragraph and fraction VII; are REFORMED; Articles 308, fourth paragraph; 318 Bis; 318 Bis 1; 321 Bis; 321 Bis 1; 321 Bis 2; 321 Bis 3; and 334, fraction IX; are ADDED; Articles 330 and 335; are REPEALED,
and Annexes 52, 57, 58 and 59 of the "General Provisions applicable to credit institutions", published in the Official Gazette of the Federation on December 2, 2005 and last modified by resolution published in said dissemination medium on August 6, 2021, are SUBSTITUTED, to read as follows:
" Annex 1 to 51
...
Annex 52
Minimum operational and security guidelines for the contracting of technological support services
Annex 53 to 56
...
Annex 57
Criteria to evaluate the experience and technical capacity of commissionaires that
operate under the second section of Chapter XI of Title Fifth of the
provisions
Annex 58
Technical requirements for the operation of electronic media for the operations
contemplated in the Second Section of Chapter XI of Title Fifth of the
provisions
Annex 59.
Information that must be presented in the authorization request of the commissionaire
Annex 60 to 73
... "
" Article 1.-
...
I. to V.
...
VI.
Commissionaire Administrator: The legal person that forms a network of banking commissionaires, that operates under the provisions of Article 321 Bis 2 of these
provisions.
VII. to CXCVII.
... "
" Article 308.-
...
I.
...
II.
An Authentication Factor of Categories 2, 3 or 4 as referred to in Article 310 of the
present provisions.
...
...
...
Regarding Authentication Factor Category 3, Institutions may not consider the use of
external or physical electronic devices delivered to their Users that generate Dynamic
Passwords of single use, nor random tables of Passwords. "
" Article 317.- Institutions may contract with third parties, including other Institutions or
financial entities, the provision of services necessary for their operation, as well as celebrate commissions
to carry out the operations provided for in Article 46 of the Law, subject to what is stated in the present
Chapter XI of Title Fifth of these provisions.
The provisions of this Chapter XI shall not be applicable when Institutions contract the
services indicated below:
I.
Professional or advisory services, including mandates and commissions other than those
celebrated for the carrying out of the operations indicated in Article 46 of the Law.
II.
Auxiliary and complementary services that the Institution receives from the societies referred to in
Article 88 of the Law, from the companies referred to in fraction XII of Article 5 of the
Law to Regulate Financial Groupings, as well as those contracted with their financial
subsidiaries or other financial entities that are part of the financial group to which the
own Institution belongs.
III.
Services for receiving resources from those accredited for the payment of credits in favor of the
accrediting Institution, as well as the carrying out of operational processes and database administration that have as their object the management of their credit portfolio in any of its stages,
when the third party with whom they intend to contract is any development organism supervised by the
Commission or public trust that is part of the Mexican Banking System in terms of the
Article 125 of the Law, or a decentralized organism of the Federal Public Administration,
whose object is to help the priority activity of the State to promote the development of the
agricultural, forestry, fishing and other economic activities linked to the
rural environment, and which are additionally subject to the supervision of the Commission, must
observe what is stated in Article 317 Bis next.
IV.
Referenced payment services for credits charged to Credit or Debit Cards, or in cash,
that are carried out through Specialized Companies used in the network of disposal media
and that, additionally, are subject to the supervision of the Commission as Participants in the
Payment Network with Card, according to such terms as defined in the General Provisions
applicable to the networks of disposal media, issued jointly by the Commission and the
Bank of Mexico, or those that replace them. This is without prejudice to the power of the Commission to
formulate directly to credit institutions the information requirements that derive from
the supervision it carries out as a result of the operations that Institutions carry out through
such Specialized Companies.
V.
Manufacturing,
delivery or distribution services of:
a)
Inactive credit cards, considering those in which a Temporary
Personal Identification Number (PIN) is available, defined or generated by the Institutions themselves, which
must be modified immediately after the Client starts the corresponding Session in
Electronic Media and inactive debit cards.
b)
Check skeletons and passbooks for savings deposits.
VI.
Securities transfer services.
VII.
Services for administrative collection management, including delegated, according to the
terms originally agreed with the client and the recovery of the credit portfolio in administrative or judicial processes. This fraction does not include the receipt of payments referred to in fraction IV of Article 319 of these
provisions.
VIII.
Preventive and corrective maintenance services for equipment and computer systems on the network,
owned, leased, or co-located, provided that the contracted third party does not have
access permissions to know Sensitive Information, security configuration information of
equipment, nor to the administration of access control.
IX.
Telecommunications services for the transmission of information, provided that the
Institutions have:
a)
Redundancy schemes or alternate mechanisms in point-to-point
telecommunications that allow for communication links that minimize the risk of interruption in the
telecommunications service.
b)
Measures to ensure the transmission of User Sensitive Information in encrypted
point-to-point form and elements or security controls at each of the nodes involved in the
sending and receiving of data.
X.
Services related to the management of the Institution, such as cleaning, security,
messaging and correspondence, storage and physical safeguarding of information and documentation,
among others.
XI.
The right to use by software licensing that is installed and resides in the
Technological Infrastructure of the own Institution that is acquiring it.
XII.
The service of processing credit operations in their promotion and evaluation phase.
XIII.
Billing services for company statements that form part of the registry of certifying bodies authorized before the Tax Administration System.
XIV.
Settlement and clearing services for card-related operations related to entities
established as Clearing Houses, in accordance with the General Provisions
applicable to the networks of disposal media, issued jointly by the Commission and the
Bank of Mexico, or those that replace them.
XV.
Certifiers of electronic signature services accredited before the Tax Administration System, as well as the services of issuing certificates of conservation of data messages and
document digitization by service providers of certification authorized by the
Ministry of Economy.
XVI.
The service of administration of databases of biometric information or of consultation of this
information provided by Mexican financial, electoral or tax authorities, or
federal departments.
XVII. The service to develop or administer standardized application programming interfaces
that allow sharing open financial data and aggregated data as referred to in
fractions I and II of Article 76 of the Law to Regulate Financial Technology Institutions;
understanding that regarding the service for the development or administration of
standardized application programming interfaces that allow sharing
transactional data as referred to in fraction III of said Article 76, Institutions must
observe what is provided in Articles 326 or 328 of these provisions, as applicable.
The provisions of Chapter XI of Title Fifth of these provisions shall also not be applicable
when Institutions contract other entities subject to the supervision of the Commission that within their
corporate purpose is the power to receive mandates or commissions and that are allowed to carry out the
operations object of the mandate or commission in question and, additionally, have regulation in
matters of technological risk, use of electronic media and information security, in addition to having
a regulatory regime for contracting with third parties.
Institutions must agree on what is necessary so that the persons who provide them with the services
referred to in this article and those provided in this Chapter XI, keep the due confidentiality of the
information related to active, passive and service operations celebrated with their clients, as well as the
information related to said clients, in case such persons have access to it.
For the services referred to in the previous fraction II, Institutions must have policies and
procedures related to the carrying out of internal or external audits on the services provided,
at least once every two years, in order to evaluate the operational controls implemented, the
compliance with the agreed conditions, as well as the confidentiality and security measures of the
services contracted.
Likewise, said Institutions must maintain the data of the persons who provide them with the
services mentioned in the first and second paragraphs of this article, in the registry referred to in
Article 333 of these provisions.
Article 317 Bis.- Institutions must request the Commission to confirm the exceptions
provided for in fractions III and IV of Article 317 of these provisions, at least 20 business days in
advance of the provision of the service in question. In case the Institution does not receive a written
response from the Commission within a period of 20 business days following the receipt of the request,
the provision of the respective service may begin.
...
I.
...
II.
An explanation of the service to be contracted, specifying the way in which the third party will receive the resources
for the payment of the respective credits, stating whether in addition to such operation, the third party will provide
any other service that requires presenting the notice or obtaining the authorization referred to in the
Articles 326 or 328 of these provisions, respectively.
Article 318.- Institutions, with the exceptions provided for in fractions I to XVII of Article 317
of these provisions, to contract any of the services or to celebrate the
commercial commissions referred to in this Chapter XI, must comply with the following requirements:
I.
Regarding activities that imply acting in front of the general public, at all times, the
third parties that Institutions contract must act in the name and on behalf of the
principal Institution, so that the said relationship must be documented through commercial commission
contracts.
Likewise, in no case, such commissionaires may carry out approvals and openings of
accounts for active, passive and service operations, unless it is about operations of the
provided for in Article 319, fractions IX and X of these provisions.
II.
Have a report that specifies the operational processes or database administration and
computer systems of the Institution that are the object of the services to be contracted, as well as
the policies and criteria for selecting the third party, which will be oriented to evaluate the
experience, technical capacity and human resources of the third party with whom the service is contracted to provide the
service with adequate levels of performance, reliability and security, as well as the effects that
might occur in one or more operations carried out by the Institution.
The policies and criteria referred to in the previous paragraph must be elaborated by the general director
or another official designated by him and approved by the Board of Directors of the
Institution, at the proposal of the Risk Committee or the Audit Committee.
The Audit Committee will be responsible for verifying the implementation of said policies and criteria.
III.
Provide in the service provision or commission contract respectively, the unconditional acceptance
of the commissionaire or of the third party that provides the service, to:
a)
Expressly:
Receive home visits by the external auditor of the Institution, of the Commission or
of the third parties that the Commission itself designates in terms of what is provided in Article
46 Bis 1 and Article 117 of the Law, with the purpose of carrying out the corresponding supervision,
with the purpose of obtaining information to verify that the services or commissions
contracted by the Institution allow the latter to comply with the applicable
dispositions. For the referred visits to be carried out, Institutions may designate a
representative.
Accept the carrying out of audits by the Institution, in relation to the services or
commissions object of said contract, in order to verify the observance of the applicable
dispositions to the Institutions.
Deliver, at the request of the Institution, to the external auditor of the own
Institution and to the Commission or to the third party that said Commission designates, books, systems, records, manuals and
documents in general, related to the provision of the service or commission in
question. Likewise, allow access to the responsible personnel and to their offices and installations
in general, related to the provision of the service in question.
Inform the Institution with at least thirty natural days in advance, regarding
any reform to its corporate purpose or in its internal organization that affects the provision
of the service or commission object of the contracting.
Keep confidentiality regarding the information to which it has access by the
provision of the service or commission, and must, additionally, establish the necessary measures
to maintain the security of the operations and protect the information of the clients,
manifesting understanding and acceptance that, by virtue of what is stated in Article 46 Bis 1,
third paragraph of the Law, what is provided in Article 142 of said Law will also be
applicable to them, as well as to their representatives, executives and employees, even if they cease to
work or provide services to such service providers or commissionaires.
What is provided in sub-items 1. to 5. above shall also be applicable to third parties with
whom service providers referred to in this chapter subcontract directly,
totally or partially, the service provided to the Institution.
b)
In addition to the previous item, the service provision or commission contract respectively must
provide the following:
The restrictions or conditions regarding the possibility that the third party subcontracts, in turn,
the provision of the service.
The obligations that correspond to the Institution and to the third party service provider
or
commissionaire, as well as the procedures to monitor the compliance with said
obligations.
The mechanisms for the resolution of disputes related to the service provision contract
or commercial commission.
The obligations and responsibilities of the parties to protect the information of the
clients of the Institution, the latter having to consider the requirements established by the
legislation in matters of personal data protection for the treatment and transfer of this type
of data, as well as that related to the defense of users of financial
services and any other that has as its object to protect the data of the clients of the
Institution.
The express manifestation that the Institution responds, at all times, for the service
that third parties contracted by it, or its commissionaires, provide to the clients
banking, even if the carrying out of the corresponding operations is carried out
in terms different from those agreed; as well as for the non-compliance with the dispositions in
which said third parties or commissionaires incur, according to what is provided in Article 46 Bis 1,
first paragraph of the Law.
The terms, conditions and processes for the commissionaire or service provider
guarantee the Institution the secure transfer, return, and elimination of information subject to the contracted service when it ceases to provide it.
Establish corrective measures in case of non-compliance by third-party service providers or agents with these provisions.
For services provided by a financial institution from abroad that controls the Subsidiary Institutions operating in Mexico, only subsection a) of this section shall apply.
IV.
Establish guidelines and mechanisms aimed at preventing the adverse effect on and ensuring the adequate provision of the Institution's services to the public, its financial stability, or operational continuity after the contract with the service provider or agent has ended, considering those necessary to verify that the latter does not retain any information from the Institution or its clients.
V.
Comply with the minimum operational and security guidelines set forth in Annexes 52 and 58 of these provisions, as applicable, for the operation of electronic media with agents or if the services to be contracted refer to the use of technological or telecommunications infrastructure.
VI.
Verify that third parties, their shareholders, and, where applicable, subcontractors, as well as agents and their shareholders, where applicable, the Administrator of Agents and the shareholders of the latter, are not included in the official lists issued by Mexican authorities, international organizations, intergovernmental groupings, or authorities of other countries, of persons linked or likely linked to operations with resources of illicit origin, terrorism or its financing, or with other illegal activities. To prove the foregoing, it shall suffice for the Institution to state in writing that it ensured that the persons mentioned in this section were not related in said official lists at the time of their hiring. Additionally, the Institution must state that it knows the business to which the agent is dedicated.
VII.
Have the prior approval of the Board of Directors or the Risk Committee of the Institution of the impact assessment that the contracts referred to in this Chapter XI might have, qualitatively or quantitatively, on the operations carried out by the Institution, according to its purpose, taking into account the following:
a)
The Institution's capacity to, in case of contingency, maintain operational continuity and the carrying out of operations and services with its clients.
b)
The complexity and time required to find a third party that, where applicable, replaces the originally contracted one.
c)
The Institution's ability to maintain appropriate internal controls and timeliness in accounting records, as well as to comply with regulatory requirements in case of service suspension by the third party or agent.
d)
The impact that the service suspension would have on the Institution's finances, reputation, and operations.
e)
The vulnerability of information related to clients.
Institutions that have the status of subsidiaries may contract services with the foreign financial institution that controls them, or with its subsidiaries or affiliated companies, when such contracts aim to carry out the processes referred to in the Third Section of this Chapter XI of this Fifth Title of these provisions. In this case, the Subsidiary Institutions shall not be subject to the provisions of subsections II, III subsection b), IV to VII above, provided that the Subsidiary Institution in question states that it complies with the policies and guidelines established by the aforementioned foreign financial institution; ensures that such policies and guidelines foresee the aspects referred to in this article, and has access to the evaluations and results of the audits carried out by the said foreign financial institution. The same case shall apply for services provided by a third party both to the foreign financial institution and to the subsidiary.
The Commission may, at any time, request the results of the audits referred to in the previous paragraph, through the Subsidiary Institutions.
The Institution must establish policies for the adequate handling, control, and security of information generated, received, transmitted, processed, or stored in the execution of services or commissions related to the use of technological, telecommunications, or information processing infrastructure, carried out partially or totally outside the national territory. The establishment of such policies shall be the responsibility of the General Manager, who may delegate such functions to the areas in charge of the Institution's information security, while the Audit Committee and the Institution's internal auditor shall be responsible for monitoring compliance, according to their respective competencies.
Article 318 Bis.- The information requests and, where applicable, observations or corrective measures resulting from the supervision carried out by the Commission in accordance with these provisions, shall be made directly to the Institution. Likewise, the Commission may, at any time, order the carrying out of the visits and audits indicated in Article 318, subsection III, subsection a) above, specifying the aspects that these must cover, with the Institution being obliged to submit a report to the Commission regarding this matter.
Regarding the operations referred to in subsections IX, X, and XI of Article 319 of these provisions, the Commission, in accordance with the "General Provisions referred to in Article 115 of the Credit Institutions Law" issued by the Secretariat, or those that replace them, may at any time, make information requests, as well as verify with the Institution that the agents it hires have the necessary information to comply with what is provided in said regulation.
Additionally, in the case of operations carried out with multiple banking institutions as principals, the Commission, without prejudice to the powers it exercises in the matter of supervision and oversight over stockbrokers in accordance with the Securities Market Law, may, at the request of the IPAB, carry out inspection visits to stockbrokers acting as agents, in order to verify and evaluate that the latter classify in automated data processing and conservation systems, as well as in any other technical procedures, the information referred to in Annex 58, Section V, Item 3, Letter B), subsection i) of these provisions. In this last case, the Commission shall act in accordance with what is provided in Article 124 of the Law.
Article 318 Bis 1.- The Institution must carry out, at least once every two years, audits aimed at verifying the degree of compliance with this Chapter XI, as well as what is established in Annexes 52 and 58 of these provisions, as applicable, when it comes to commissions for the carrying out of the operations referred to in Article 319 of these provisions or the provision of services for the carrying out of operational processes, the administration of databases or computer systems, as well as the infrastructure, controls, and operation of the service provider's computer center. Without prejudice to the foregoing, the Commission may order the carrying out of said audits in advance of said period, when in its judgment there are risk conditions in the matter of operation and information security.
Article 319.- . . .
I. to III.
. . .
IV.
Payments of credits in favor of the Institution itself or another in cash, charged to credit or debit cards, including payment by means of checks issued for such purposes by the principal Institution or by any other Institution.
V.
Payment orders in the bank offices of the principal Institutions, or through the agents themselves, as well as transfers between accounts, even to accounts of other Institutions.
VI to IX.
. . .
X.
. . .
a) and b)
. . .
In any case, the Institution must have in real time the information related to the clients who open these accounts with the agent, without prejudice to compliance with the other obligations provided in the "General Provisions referred to in Article 115 of the Credit Institutions Law", issued by the Secretariat, or those that replace them.
XI.
Carry out on behalf of the Institutions themselves, the purchase and sale of United States of America dollars in cash exclusively with natural persons.
In the carrying out of the operations referred to in this subsection, the provisions of Annexes 58 and 59 of these provisions shall not apply, nor shall they be obliged to issue an operation receipt to their clients. Notwithstanding the foregoing, the Institutions must have the necessary mechanisms to register and follow up on the daily transactionality they operate through each of their agents. In any case, the control mechanism referred to in this paragraph must contain the necessary elements that allow the Institutions to carry out audits to verify compliance with what is stated in subsection III of Article 323 of these provisions.
In any case, the operations referred to in this subsection may only be carried out by agents whose establishments are located in municipalities or boroughs where it is economically justified that they are recipients of cash dollars, based on the high flow of foreign natural persons and the revenue spill from said persons being significant with respect to the economic activity of the municipality or borough in question, or in municipalities located within the twenty-kilometer strip parallel to the northern international border line of the country or in the States of Baja California or Baja California Sur. For these purposes, the Secretariat will make known to the Institutions the list referred to in 33rd Bis of the "General Provisions referred to in Article 115 of the Credit Institutions Law", issued by the Secretariat, or those that replace them.
Likewise, they may be carried out by agents that have the status of establishments authorized for the exhibition and sale of foreign and national merchandise in international airports, border and high-seas maritime ports, in accordance with subsection I of Article 121 of the Customs Law, regardless of their location.
The Institutions are obliged to supervise that the operations referred to in this subsection are carried out by the agents in accordance with what is established in these provisions, as well as to suspend said operations in the establishments of the agents that incur in any non-compliance with what is established in this subsection.
XII.
Receipt of payments of federal, state, municipal contributions and those corresponding to the Mexico City, in cash or charged to credit or debit cards, or with checks issued for such purposes by the principal Institution.
The operations referred to in subsection IX of this article may only be carried out by Institutions whose Capitalization Index is at least 12 percent, likewise the Institutions must comply with what is established in subsection V of Annex 58 of this regulation. Additionally, for these purposes, said Institutions are not obliged to observe what is provided in Annex 57 of these provisions.
Regarding the operations referred to in subsection VIII of this article that Institutions carry out through agents operating call centers, the principal Institutions may carry out said operations, observing what is provided in Sections First, Third, and Fourth of this Chapter XI, as well as by Article 320 of these provisions.
The operations referred to in subsections I, III, IV, X, and XII of this article may only be carried out in national currency.
Article 320.- Institutions that enter into commercial commissions aimed at carrying out the operations referred to in Article 319 of these provisions through agents, will require presenting for authorization by the Commission, only once, a strategic business plan that contemplates all the operations provided for in the aforementioned article that could be carried out, and must include the model of commercial commission contract that will serve as the basis for the contracts to be entered into with each of the agents with whom it is intended to agree. Regarding development banking institutions, the authorization of the strategic plan may be requested once the exception referred to in Article 47 of the Law has been obtained.
For the purposes of the previous paragraph, the model of commercial commission contract must include what is established in Articles 318, subsection III, and 324 of these provisions.
The strategic plan referred to in the first paragraph of this article must foresee compliance with the requirements indicated in Article 318, subsections I, III, V, and VII of these provisions, without it being necessary to establish the implementation dates of each of the operations indicated in it.
Likewise, the said plan must contain the following aspects:
I.
Description of the automated controls that the Institution will use to prevent agents from exceeding the operational limits established in Article 323 of these provisions.
II.
Qualitative and quantitative information regarding the operations that the Institution will contract with the agent.
III.
The measures that the Institution must implement in the matter of:
a)
Internal control.
b)
Comprehensive risk management.
c)
Prevention of operations with resources of illicit origin and terrorism financing referred to in Article 115 of the Law and the "General Provisions referred to in Article 115 of the Credit Institutions Law" issued by the Secretariat, or those that replace them.
IV.
The procedure that the Institution would employ in the validation for the payment of checks in case of carrying out operations referred to in Article 319, subsection VII of these provisions.
V.
The criteria oriented to evaluate the experience and technical capacity of the agent in accordance with what is provided in Annex 57 of these provisions.
Once authorized by the Commission the strategic plan referred to in the first paragraph of this article, Institutions must request authorization from the Commission regarding reforms to said plan that imply changes to the terms in which they would carry out operations with banking clients and the general public, or when it comes to substantial changes in the conditions of contracting and obligations of the parties established in the model contract, particularly with respect to any of the aspects referred to in Articles 318 subsection III and 324 of these provisions; or if it is intended to operate with new agents not foreseen in the plan authorized by the Commission, with at least thirty natural days in advance of the date on which it is intended that they take effect.
Article 321.- When Institutions intend to carry out a new operation indicated in the strategic plan authorized to them in accordance with Article 320 above, or when they intend to implement new technology to operate with previously authorized agents or Administrators of Agents, they must comply with the following:
I.
Regarding the operations referred to in subsections II, III, V, VI, VII, VIII, IX, X, and XI of Article 319 of these provisions, they must request authorization from the Commission to carry out said operation, accompanying their request letter with the following:
a)
The technical requirements indicated in Annex 59 of these provisions, unless it is about the operations provided for in subsection XI of Article 319 of this regulation, likewise, the description of the new technology and its implementation must be included where applicable.
b)
The draft commercial commission contract to operate with the agent, which contemplates the aspects referred to in Articles 318, subsection III, and 324 of these provisions, in accordance with the authorized strategic business plan.
II.
Regarding the operations referred to in subsections I, IV, and XII of Article 319 of these provisions, they must present a notice to the Commission, stating in the same that the operation will be carried out under the contract to be entered into between the Institution and the agent, in the terms authorized by the Commission, indicating where applicable, if the contract it intends to enter into with the agent presents any variation with respect to the model contract, in which case it must send said draft. The notice referred to in this subsection must be sent to the Commission, and operations referred to in this subsection may begin the day after the corresponding notice is presented, understanding that the Commission may at any time require that operations not be carried out through one or more particular agents when these fail to comply with these provisions. Likewise, Institutions may incorporate in a single notice all the operations indicated in this subsection, which will be carried out with the same agent.
In the celebration of the operations referred to in this subsection, Institutions must comply, at all times, with what is established in Articles 318, subsection III, 321 Bis, 322, 324, and Annexes 57 and 58 of these provisions, keeping evidence of said compliance and keeping it available to the Commission.
Additionally, for the operations referred to in subsections I and II above, Institutions must present together with the request for authorization or notice, as applicable, the Internal Certification Format for Agents (FCIC) with pre-operational test information, duly filled out based on the new operation they intend to carry out.
For this, they must download the updated format of said report available on the Commission's website.
Article 321 Bis.- Institutions, through agents, will provide sufficient information so that their clients know the procedure to present clarifications or complaints derived from operations carried out through said agents, so they must indicate the telephone number and email address of the specialized unit for user attention that the Institution must have in accordance with the Law for the Protection and Defense of Users of Financial Services and the corresponding telephone numbers of the "Call Center" of the National Commission for the Protection and Defense of Users of Financial Services.
Additionally, Institutions will keep fully identified at all times the operations they carry out through agents independently of those they carry out through their other distribution channels.
Institutions will consolidate in a database managed and controlled at all times by the Institution, the clarifications or complaints derived from operations carried out through agents.
Article 321 Bis 1.- Institutions must provide to their banking clients and the general public, through their Internet page, the list of modules and establishments that agents have enabled to carry out the operations referred to in Article 319 of these provisions, specifying the operations that can be carried out in each of them and the maximum amounts authorized per operation, and additionally must provide a telephone number or indicate within the Internet site itself in a prominent way through which means third parties contracted by the Institution as agents can know.
Institutions will verify that agents inform banking clients, through operation receipts, visible announcements in establishments, technological platforms, or by any other means, that they act in the name and on behalf of the Institution itself.
Article 321 Bis 2.- Institutions may authorize legal entities, through a mandate or commission, to contract or participate in the contracting of third parties acting as agents of the Institution to celebrate with clients and the general public, in the name and on behalf of the Institution itself, the operations referred to in Article 319 of these provisions; said persons will receive, for the purposes of these provisions, the name of Administrator of Agents.
The foregoing, understanding that Institutions will grant such powers, with the aim that the Administrator of Agents organizes networks of banking agents so that the services provided are made uniformly, in order to maintain a high quality standard in the carrying out of such operations.
The hiring of the Administrator of Agents will require the authorization of the Commission, for which it must deliver the draft contract of mandate or commercial commission to be entered into between the Institution and the Administrator of Agents, as well as the draft contract with the corresponding agent.
Likewise, the other obligations that the provisions impose on agents and that the Administrator of Agents might supply and prove, without the Administrator of Agents being able to carry out the operations referred to in Article 319 of these provisions.
Additionally, when the Administrator of Agents provides the technological infrastructure service, it must deliver the following:
I.
Description of the support and operational infrastructure services, equipment, automated data processing systems, and telecommunications networks that the Administrator of Agents will provide to agents for the correct carrying out of the operations.
II.
Redundancy schemes or alternate mechanisms in point-to-point telecommunications that allow for communication links that minimize the risk of interruption in the telecommunications service to be adopted by the Commissionaire Administrator or the Institution.
III.
Continuity strategy for the computer services provided to the commissionaire regarding the capacity to process and operate systems in the event of contingencies, failures, or interruptions in telecommunications or central computer equipment and others involved in the information processing service for operations or services.
IV.
Mechanisms to be adopted by the Commissionaire Administrator or the Institution to establish and monitor the quality of information services, as well as system and application response times.
V.
Description of the automated controls that the Commissionaire Administrator will use to prevent commissionaires from exceeding the operational limits established in Article 323 of these provisions, when such operations are carried out using the Commissionaire Administrator's technological infrastructure.
VI.
Description of automated mechanisms to detect and prevent information security events and incidents, as well as to prevent unauthorized incoming or outgoing data connections and flows and information leakage, considering among other things, removable storage media.
VII.
Detailed report of vulnerability scanning test results of the components of the Commissionaire Administrator's technological infrastructure that store, process, or transmit information related to banking operations.
Additionally, the tests referred to in the preceding paragraph must be carried out at least quarterly, and the result reports and evidence of mitigation actions implemented to address critical and high-severity vulnerabilities must be kept available to the Commission.
VIII.
Detailed report of the results of penetration tests carried out by an independent third party, whose personnel have verifiable technical capacity through specialized certifications in the subject matter; these tests must cover the technological infrastructure of the Commissionaire Administrator for commercial commissioning. Additionally, these tests must be carried out at least once a year, and the result reports and evidence of mitigation actions implemented to address critical and high-severity vulnerabilities must be kept available to the Commission.
IX.
Remediation plans regarding the findings of the reviews and tests referred to in fractions VII and VIII above, as well as evidence of the mitigation actions implemented to address critical and high-severity vulnerabilities.
Institutions shall establish in the contracts they enter into with Commissionaire Administrators or in the contracts they enter into with commissionaires where the Commissionaire Administrator participates, as appropriate according to the obligations of each party to the contract, the following:
i.
The obligation of the Commissionaire Administrator to verify and accredit to the Institution that the commissionaires it hires to carry out the operations provided for in Article 319 above comply with the aspects set out in Article 318, fractions II to VII of these provisions, as well as to carry out the audits referred to in Article 318 Bis 1 of this instrument.
ii.
To establish that the Commissionaire Administrator is prohibited from:
a)
Carrying out any of the operations provided for in Article 319 in the name and on behalf of the Institution, nor in its own name.
b)
Advertising or promoting itself in any way through stationery or on the front of the receipts provided to customers for the operations it carries out in the name of the Institution in question.
c)
Subcontracting services related to commercial commissioning.
iii.
The right of the Institution to suspend the contract in the event that the Commissionaire Administrator fails to comply with these provisions.
The Commissionaire Administrator must verify that the commissionaires forming its network comply with what is established in Annex 58 of these Provisions.
Article 321 Bis 3.- Institutions must prepare an annual report regarding the evolution of their business strategic plan, which shall contain qualitative and quantitative information regarding the results obtained during that period. It must also include a comparison with the estimates presented in the strategic plan submitted to the Commission for its authorization, regarding the operations the Institution carries out through commissionaires, as well as a detailed report on any contingencies that may have arisen regarding the provision of services by the commissionaires referred to in this Second Section of this Chapter XI. The aforementioned report must be delivered to the Vice Presidency of the Commission responsible for its supervision during the first quarter of each year.
Article 322.- In carrying out any of the operations referred to in Article 319 of these provisions, Institutions must enter into a deposit contract with the commissionaire as depositor, acting as depositary. To this end, the Institution may grant the commissionaire itself a credit line that allows providing funds to the aforementioned deposit account, when necessary and in accordance with the Institution's own policies.
In any case, the demand deposit account must be charged or credited, depending on the nature of the transaction the commissionaire concludes with the banking client and the general public, transferring funds online to or from the general public's account, or to the Institution's own accounts, as appropriate, for the requested purposes, except for the operations referred to in fraction XI of Article 319 of these provisions.
Institutions must ensure that each operation corresponds to the charges and credits made to the aforementioned accounts.
In the commercial commission contract in which the Commissionaire Administrator participates, Institutions may agree that the latter provides the necessary technological infrastructure and technical support required by the commissionaires with which it operates, solely for the purpose of facilitating and strengthening the support processes for the operations concluded by said commissionaires, without this being understood as the Commissionaire Administrator itself directly carrying out operations with the Institution's clients. Regarding processes related to the compensation and settlement of funds, commissionaires that are part of the Administrator's network may dispense with the deposit account contract; in such cases, the Commissionaire Administrator must have such a deposit account and will be jointly liable for the operations carried out by the commissionaires it administers.
Institutions are exempt from entering into the deposit contract referred to in this article, provided they obtain authorization from the Commission regarding the procedure they would use for the net settlement corresponding to the carrying out of operations with their commissionaires. Such procedure must allow for the online transfer of funds from or to banking clients' accounts, as appropriate.
The payment operations for credits referred to in fraction IV of Article 319 of these provisions may be carried out without the need to transfer funds online, provided that the Institution in question, through its commissionaire, indicates on the respective operation receipt the date or deadline by which the payment made will be credited.
Likewise, regarding the operations referred to in fraction V of Article 319 of these provisions, when carried out in cash to accounts of Institutions other than the principal Institution, the latter must transfer the corresponding funds in the same manner as such operations are carried out in its branches, provided that the Institution in question so agrees with its clients through its commissionaires and indicates on the respective operation receipt the date or deadline by which the respective operations will be credited.
Article 323.- . . .
I.
. . .
II.
. . .
III.
Regarding the cash purchase and sale operations of United States dollars referred to in fraction XI of Article 319 of these provisions, provided that such transactions are carried out for the acquisition of products or services marketed or offered by the commissionaire, the amount of the banking operation may not exceed the equivalent of 250 United States dollars.
Notwithstanding the foregoing, in the event that the commissionaire in question is an establishment authorized to exhibit and sell foreign and national merchandise in international airports, border ports, and high-seas maritime ports in terms of what is provided in fraction I of Article 121 of the Customs Law, or if it is a commissionaire that has the status of an establishment providing lodging services, the limit of operations shall be up to:
a)
An accumulated amount over the course of a calendar month of 1,500 United States dollars, for foreign national individuals.
b)
A daily aggregate amount of 300 United States dollars, restricted to an accumulated amount over the course of a calendar month of 1,500 United States dollars for Mexican national individuals.
The provisions of this fraction are understood to mean that in the event that the currency commissionaire must return Mexican pesos or United States dollars as a result of the commercial operation referred to in the first paragraph of this fraction, such return may not be equal to or greater than the equivalent of 100 United States dollars.
The limits established in this fraction shall apply without prejudice to the Institutions carrying out operations with users or clients.
Institutions must ensure through computer systems and automated controls that the commissionaires they hire do not exceed the limits referred to in this article. Institutions must establish the necessary mechanisms so that, once the limits referred to in this article are reached, the aforementioned commissionaires direct the clients of the Institutions and the general public to the banking offices of the Institutions to carry out these operations.
. . .
. . .
Article 324.- . . .
I.
. . .
II.
The individual and aggregate limits of the operations indicated in Article 323 of this regulation.
III.
. . .
Institutions must provide in the mandate or commercial commission contracts they enter into with the Commissionaire Administrator or in contracts with commissionaires in which it participates, the joint obligation of the Commissionaire Administrator regarding compliance by the banking commissionaires subject to its administration with what is provided in Article 322, fourth paragraph of these provisions.
IV.
. . .
V.
The conventional penalties for breaches of contract, including what is provided in Article 331 of these provisions.
VI.
The other obligations and rights that the parties will have for the execution of the commission.
VII.
To establish that the commissionaire is prohibited from:
a)
Conditioning the carrying out of the banking operation on the acquisition of a product or service, regarding the operations referred to in fractions I to X and XII of Article 319 of these provisions.
The restriction referred to in this subsection shall not apply to cash purchase operations of United States dollars, as referred to in fraction III, in its first and second paragraphs, subsection a), of Article 323 of these provisions.
b)
Advertising or promoting itself in any way through stationery or on the front of the receipts provided to customers for the operations it carries out in the name of the Institution in question.
c)
Carrying out the object of the commission operation under terms different from those agreed with the principal Institution.
d)
Subcontracting services related to commercial commissioning.
e)
Charging commissions, on its own behalf, to banking clients for the provision of services that are the object of commercial commission, or receiving price or rate differentials regarding operations in which it intervenes. This is without prejudice to the payment of commissions that may be agreed between the client and the Institution or between the latter and the commissionaire.
f)
Carrying out operations with banking clients in its own name.
g)
Exclusively agreeing with the principal Institution the carrying out of operations and activities consisting of the receipt of payment for non-banking services, as well as the payment of credit cards.
VIII.
The obligation of the commissionaire to be subject to periodic monitoring procedures by the Institution, relating to information and system security, such that they allow evaluating the robustness of the commissionaire's computer infrastructure for the conclusion of operations, as well as its vulnerability and response capacity against possible computer attacks. Likewise, the provision regarding the fact that non-compliance with what is established in section IV of Annex 58 of these provisions, and in case of refusal, delay, and obstruction by the commissionaire regarding the compliance with said section, shall constitute a cause for rescission of the commercial commission contract.
IX.
The right of the Institution to carry out the security reviews indicated in Article 168 Bis 12, fractions II, III, and IV of these provisions on the services contracted by the commissionaire, or to provide evidence to the Institution of the carrying out of these reviews.
X.
Regarding the operations referred to in fraction XI of Article 319 of these provisions, in order to comply with the "General Provisions referred to in Article 115 of the Credit Institutions Law" issued by the Secretariat, or those that replace them, the obligation of the commissionaire to collect and conserve from the client the following:
a)
For operations up to the equivalent of 250 United States dollars, carried out for the acquisition of products or services marketed or offered by the commissionaire, the following information and documentation must be presented:
Paternal surname, maternal surname, and first name(s) without abbreviations.
Nationality.
Date of birth.
For the purposes of the foregoing, the data regarding the client's name and date of birth must be obtained from an official identification document as indicated in the 4th of the "General Provisions referred to in Article 115 of the Credit Institutions Law" issued by the Secretariat, or those that replace them.
b)
Regarding establishments authorized to exhibit and sell foreign and national merchandise in international airports, border ports, and high-seas maritime ports in terms of what is provided in fraction I of Article 121 of the Customs Law:
The following information and documentation:
i)
Paternal surname, maternal surname, and first name(s) without abbreviations.
ii)
Nationality.
iii)
Date of birth.
iv)
Passport number or passport card.
Type of operation, amount, and date of conclusion.
c)
Establishments providing lodging services:
The following information and documentation:
i)
Paternal surname, maternal surname, and first name(s) without abbreviations.
ii)
Nationality.
iii)
Date of birth.
iv)
Copy of official identification, passport, passport card, or consular registration certificate.
Regarding foreign national individuals, they may be identified with:
i)
Copy of the passport or passport card that accredits their nationality, and
ii)
Copy of the official document issued by the National Institute of Migration, when they have the latter accrediting their entry or legal stay in the country.
d)
Type of operation, amount, and date of conclusion.
Commissionaires must send the Institution the information related to the aforementioned operations, so that the Institution itself complies with the aforementioned Article 115 of the Law and the "General Provisions referred to in Article 115 of the Credit Institutions Law" issued by the Secretariat, or those that replace them, based on the information received from the commissionaires.
XI.
The right of the Institution to suspend operations in the event that commissionaires present changes in their operation contrary to what is provided in the contract, or in any way put the Institution, information security, or the resources of its clients at risk.
XII.
Regarding the operations referred to in fractions IX and X of Article 319 of these provisions, the obligation of the commissionaire to collect the necessary information from the client and transmit it in a timely manner to the Institution, in order to comply with what is provided in Article 115 of the Law and the "General Provisions referred to in Article 115 of the Credit Institutions Law," issued by the Secretariat, or those that replace them.
XIII.
The obligation of the commissionaire to prepare remediation plans regarding the findings of the security reviews and tests carried out as referred to in fraction XII of this article and deliver them to the Institution.
Institutions, in carrying out the operations referred to in this Second Section of Chapter XI, may hire commissionaires to provide their services exclusively, except for what is stated in subsection g) of fraction VII of this article.
Article 325.- Institutions may not enter into commercial commission contracts referred to in this section with the following persons:
I.
Brokerage houses, except when it concerns the operations referred to in fraction IX of Article 319 of these provisions.
II.
Persons whose main business object is the carrying out of the activities referred to in Article 81-A of the General Law of Organizations and Auxiliary Credit Activities.
"Article 329.-
. . .
The general director of the Institution in question or the person designated by him/her, shall be responsible for presenting the notice indicated in Article 326 of these provisions.
. . .
. . .
Article 330.- Repealed.
Article 331.-
. . .
Regarding the services or commissions referred to in the Second Section of this Chapter XI, Institutions must inform the Commission regarding any reform to the social object or internal organization of the third party or commissionaire that could affect the provision of the service that is the object of the contract, within five business days following the receipt of the notification referred to in Article 318, fraction III, subsection a), numeral 4. of these provisions.
Article 332.- The Commission, prior to the right to be heard granted to the Institution, may order the partial or total, temporary or definitive, suspension of the provision of services or commissions through the third party in question, when in the judgment of the Commission itself, the financial stability, information security and of clients or the institution, the operational continuity of the latter, or the protection of public interests may be affected, or when Institutions fail to comply with the provisions contained in this Chapter XI and the others that are applicable. This is without prejudice to, when exercising the aforementioned right to be heard, the Institution presenting a regularization program to be authorized by the Commission, which shall have a term of thirty natural days, counted from the date the respective Institution presents the corresponding request, in order to resolve what is appropriate.
. . .
I.
. . .
II.
Specify the stages and deadlines for each of the actions to be implemented. The execution and compliance with the program shall not exceed six months, counted from its authorization. Regardless of the foregoing, exceptionally, the Commission may authorize only once an extension for up to the same period established in this fraction, when in its judgment, the said extension is duly justified and provided that the non-compliance to be corrected does not put the financial resources or information security of clients at risk; the financial or operational stability of the institution, or constitute a potential risk to the stability of the financial system.
III.
. . .
Article 333.- Institutions must have a registry of commissionaires for the carrying out of the operations referred to in Article 319 of these provisions, as well as a registry of service providers. These registries must include at least the following information:
I.
For the commissionaire registry:
a)
Name, trade name, or corporate name of the commissionaire.
b)
Names of the commissionaire's administrators or, in its case, the legal representative, designated by the commissionaire to attend to any matter related to the commission in question.
c)
Description of the commissionaire, specifying whether it is a commercial chain, franchise, or Commissionaire Administrator, business line, and trade name.
d)
Number of commissionaire establishments or Internet page where they offer their services.
e)
Type of operations the commissionaire carries out in the name and on behalf of the Institution.
f)
The individual and aggregate limits of operations, agreed with the commissionaire.
g)
Settlement means contracted, such as checks, cash, or debit or credit cards.
h)
Access devices used to offer services to Clients, such as Mobile Phone, electronic tablets, Point of Sale Terminals, or any other.
i)
Official document number and date on which authorization was granted for the hiring of the commissionaire
o Commission Agent Administrator.
j)
Official number, if applicable, and date of commencement of operations with the commission agent or
Commission Agent Administrator.
II.
For the registry of service providers:
a)
Name, corporate name, or trade name of the service provider and, if applicable, of the
subcontractors.
b)
Names of the persons designated by the service provider or subcontractor for the
handling of any matter related to the contract in question.
c)
Description of the service, operational process, or systems contracted with the service provider
and, if applicable, with the subcontractors, including the data or information that, if applicable, are
stored or processed by them.
d)
Name of the system that supports the operational process or the administration of databases or
computer systems, contracted with the service provider and, if applicable, with the
subcontractors.
e)
Date of the notice or request for authorization, submitted to the Commission by the Institution and number
of the official letter issued by the Commission.
The Institution shall update the registries referred to in fractions I and II of this article and
keep them available to the Commission.
The Institution shall submit to the Commission within
ninety natural days after the close of the
fiscal year, an annual report detailing the results of the reviews carried out by the Institution, in accordance
with the procedures that it has developed and that form part of the Institution's Internal Control System, to ensure that the service providers or commission agents guaranteed the continuity
of the service with adequate levels of performance, reliability, capacity, security, maintenance,
integrity and with quality standards consistent with the requirements of their needs.
Article 334.- Institutions, in their policies regarding the contracting of services or commissions,
shall consider at least the guidelines and criteria for the selection of these, as well as the
evaluation measures of the contracted services and commissions. Within the evaluation measures of
the
services or commissions referred to in this chapter, the following shall be considered:
I. to VI.
. . .
VII.
The capacity of the Institutions, in the Integrated Risk Management, to identify, measure,
monitor, limit, control, report and disclose the risks that may arise from the provision of the
services or commissions referred to in this Chapter XI.
VIII.
. . .
IX.
The results of the vulnerability scanning tests and penetration tests referred to in
Article 168 bis 12, fractions III and IV of these provisions.
. . .
. . .
. . .
Article 335.- Repealed.
TRANSITORY PROVISIONS
FIRST. This Resolution shall enter into force the day following its publication in the Official Journal
of the Federation.
SECOND. Institutions shall have a period of 180 days counted from the entry into force
of this legal instrument to comply with what is established in Annex 58, fraction IV of these
provisions.
Respectfully,
Mexico City, September 13, 2021. - President of the National Banking and Securities Commission, Juan Pablo Graf Noriega. - Signature.
ANNEX 52
MINIMUM OPERATIONAL AND SECURITY GUIDELINES FOR THE CONTRACTING OF
TECHNOLOGY SUPPORT SERVICES
Institutions shall consider the following aspects:
I.
Operational Aspects
a.
Redundancy schemes or alternate mechanisms in point-to-point telecommunications
that allow for communication links that minimize the risk of interruption in the
telecommunications service.
b.
Continuity strategy in the computer services provided to the Institution that provide the
capacity to process and operate systems in case of contingency, failures or interruptions in
the telecommunications or of the central computer equipment and others that are involved in
the
information processing service of operations or services.
c.
Mechanisms to establish and monitor the quality of information services, as well as the
response times of systems and applications.
d.
Technical support scheme, in order to solve problems and incidents, independently,
if applicable, of differences in time zones and business days.
e.
Mechanisms that will allow the Institution to keep under its custody, either in
Own Technological Infrastructure or of third parties, in both cases in national territory, the
detailed records of all Operations carried out, as well as their accounting records in such a way as to ensure operational continuity at all times. Such records
shall be kept in a format that allows their consultation, operation and use by the
Commission at all times.
II.
Security Aspects
a.
Measures to ensure the transmission of Sensitive User Information in encrypted form
point-to-point and elements or security controls in each of the nodes involved in the
sending and receiving of data.
b.
Establishment of functions of the Chief Information Security Officer in accordance with
what is established in Articles 168 Bis 13 and 168 Bis 14 of the provisions. For the purposes of the
present annex, the security officer must have at all times the records of all
personnel who have access to information related to the Institution's operations,
even that located outside national territory, in which case the personnel authorized to
access such information must be authorized by the person responsible for the functions of
internal audit of the Institution, in accordance with what is stated in Article 167 of these
provisions.
c.
Scheme by which the
access log to information by duly authorized personnel will be maintained in an office of the contracting credit institution.
III.
Audit and Supervision
a.
Policies and procedures regarding the carrying out of internal or external audits on the
infrastructure, controls and operation of the third party's computer center, related to the
production environment for the credit institution, at least once every two years in order
to evaluate compliance with what is mentioned in this annex.
b.
Mechanisms for access to the technological environment, including information, databases and
security configurations, from the Institution's facilities in national territory.
ANNEX 57
CRITERIA TO EVALUATE THE EXPERIENCE AND TECHNICAL CAPACITY OF COMMISSION AGENTS THAT
OPERATE UNDER THE SECOND SECTION OF CHAPTER XI OF TITLE FIFTH
OF THE
PROVISIONS
It shall be presumed that commission agents have sufficient technical capacity when they declare under
oath that they comply with the following:
Their personnel is trained to properly operate the Electronic Media that the
Institution makes available to them to authenticate banking clients.
Have the necessary infrastructure to carry out the processing of the operations subject
of the banking service.
Be legal entities or natural persons with business activity and have a permanent establishment, understood as any place of business in which activities are developed, partially or
totally, business activities or independent personal services are provided, such as
offices, branches, agencies, or other facilities
Have their own business line.
Have honorability and satisfactory credit and business history; to this effect, it will be considered
that they meet this requirement the commission agents that:
a)
Enjoy a good credit history according to Credit Information Reports and are
up to date in the fulfillment of their credit obligations.
b)
By themselves or through intermediaries, have not caused loss, damage or
patrimonial detriment, to the detriment of credit institutions or issuing companies
in the securities market.
c)
Have not been declared in civil or commercial bankruptcy.
d)
If applicable, have not been convicted by a final judgment for intentional crime that imposes a penalty of more than one year of imprisonment.
e)
If applicable, have not been convicted by a final judgment for patrimonial crimes
committed intentionally regardless of the penalty.
f)
If applicable, have not been subject to investigation or administrative investigation
proceedings before the Commission for serious violations of national or foreign financial laws, or before other Mexican supervisory and regulatory institutions of the
financial system or of other countries, which have had as a conclusion any type of
final and definitive resolution or agreement in which the interested party has not been expressly exempted.
With respect to Entities of the Federal, State or Municipal Public Administration, it shall be sufficient that
they comply with what is stipulated in items 1 and 2 of this Annex and are expressly authorized by
their law or regulation, to provide the services or commissions in question.
Institutions may exempt from compliance with the requirements stipulated in items 3, and 5,
subparagraph a) of this annex, with respect to commission agents managed by a Commission Agent Administrator, it being sufficient for the said Commission Agent Administrator to comply with all the
requirements provided for by this annex.
ANNEX 58
TECHNICAL REQUIREMENTS FOR THE OPERATION OF ELECTRONIC MEDIA FOR THE
OPERATIONS CONTEMPLATED IN THE SECOND SECTION OF CHAPTER XI OF TITLE
FIFTH
OF THE PROVISIONS
The Electronic Media that Institutions use to guarantee the correct execution of the
banking operations that are carried out through commission agents and of information security of the
banking clients and the general public, must comply with the requirements referred to in the
present annex.
The Institution must have evidence of the compliance verification carried out prior to the start of
operations and at least once a year, of the following aspects and keep it available to the Commission
when it so requires.
With respect to Commission Agent Administrators, they must verify that the commission agents that
form their network comply with what is established in this Annex.
For the purposes of this Annex, "Operator" shall be understood as the employee of the commission agent who has
access to the Electronic Media.
I.
Requirements of Electronic Media
Mechanisms necessary to carry out online transactions.
The Electronic Media must have the necessary mechanisms to carry out the
online transactions, that is, at the very moment the operation is carried out,
updating the client's balances online except for the operations referred to in
fractions I, IV and XII of Article 319 of these provisions, where they may
perform the
balance update in accordance with what is established by the operating rules of the respective
Institutions.
For these purposes, the operations of cash or debit card service payments, or
charged to Bank Accounts, cash deposit, cash credit payment and fund status;
shall be recorded as a charge to the deposit account that the commission agent has
with the Institution. On the other hand, cash withdrawal and check payment operations shall
be recorded as a credit to the same account.
In cases where the client's balance information is stored in devices such as
integrated circuit cards or equipment located at the commission agent's facilities, it
shall not be considered as an online affectation carried out on such devices, as long as
there are mechanisms for their periodic consolidation in the central systems of the
Institutions.
With respect to the operations referred to in fractions I and IV of Article 319 of these
provisions and in case the processing is carried out through the batch scheme,
they must maintain controls implemented for the secure sending of files, as well as for
the reconciliation and settlement of the operations carried out through this medium.
Validation of Commission Agent's Electronic Media.
Only the Electronic Media of the commission agents authorized by the Institution will have
access to the infrastructure provided by it (use of dedicated lines, identification of physical or logical addresses, VPNs, digital signatures, among others).
The Institution's computer systems must authenticate the Electronic Media that the
commission agents use to carry out banking operations.
Certification of Commission Agent's Electronic Media.
The Institution shall be responsible for certifying the installation and use of the Electronic Media
that the commission agent maintains for the carrying out of banking operations, as well as for
establishing annual evaluations of said Electronic Media. Such certification may be
carried out by the Institution, if applicable, through its specialized technical areas in information
security or internal system audit, or through independent third parties,
contracted by the Institution itself, who must prove to it that they have
adequate technical credentials in computer or system audit.
The aforementioned certification must consider at least that the Institution must
ensure at all times that the electronic media used by the commission agents
maintain control mechanisms that prevent the reading and extraction of client information by unauthorized third parties.
Policies and procedures for the administration of access and configuration of Electronic
Media.
It is the responsibility of the Institution to verify that the commission agent has policies and
procedures for:
a)
The configuration of the Technological Infrastructure that connects to the systems
computer systems of the Institution.
b)
The administration of cryptographic keys used between the commission agents and the
systems of the Institution.
Generation of electronic records of operations.
All operations carried out through the commission agents must generate electronic records
that cannot be modified or deleted and in which must be included at least
the date, hour and minute, the type and amount of the instruction, the client's account number
banking, physical location of the counter or medium through which the instruction was executed, as well
as sufficient information to allow the identification of the personnel who carried out the
instruction. The custody of such records shall be the responsibility of the Institution.
II.
Requirements for Operator Identification and Banking Client Authentication.
Mechanisms necessary for the full identification of the Operators who will connect through
the commission agents.
Generation and delivery of Operator Access Passwords or Keys.
Institutions must establish mechanisms for the generation and delivery process of
the Authentication Factors that ensure that only the commission agent, and if applicable, the
Operators can know.
Composition of Operator Access Passwords or Keys.
Criteria must be established for the characteristics of the length of the Operator Access Passwords or Keys.
Protection of Access Passwords or Keys and Personal Identification Numbers (PIN).
Institutions must provide what is necessary to prevent the reading of the characters that
compose the Access Passwords or Keys, as well as the Personal Identification
Numbers (PIN) entered by banking clients, respectively, in the Electronic Media
of access, both in their capture and in their display through the screen.
The Access Passwords or Keys and the Personal Identification Numbers (PIN) must
be validated and stored through encryption mechanisms, whose cryptographic keys must
be under the administration and control of the Institution in question. At no time, the
commission agents may have access to the data or algorithms related to said
Access Passwords or Keys and Personal Identification Numbers (PIN).
Commission agents must have certifications of security standards of the
card industry for the security requirements and PIN transactions (PTS) or their equivalents or
those that, in the opinion of the Commission, allow the proper protection of the information
stored, transmitted or processed related to the entry of the Personal Identification Numbers (PIN)
of banking clients and bank card data.
Authentication for banking clients.
For the carrying out through the commission agents of consultations and operations that represent a
charge to the banking clients' accounts, the latter must authenticate themselves through the Electronic Media with which the aforementioned operations are carried out using two
Different Authentication Factors.
For the purposes of the foregoing, Institutions may opt for the combination of at least two of
the following Authentication Factors and comply with what is stipulated in Chapter X of Title
Fifth of these Provisions:
a)
Debit or credit cards with security mechanisms such as cards with
magnetic stripe and/or integrated circuit or "chip".
b)
Personal Identification Number (PIN).
In the case that debit or credit cards are used, card readers must be used,
such as PIN PADS, for the Authentication of banking clients, which must have
a screen and a keyboard exclusively designed for the banking client to
enter the information of their respective card and their Personal Identification Number (PIN), as well as mechanisms that prevent their reading by third parties.
Commission agents must have certifications of security standards of the
card industry for the security requirements and PIN transactions (PTS) or their
equivalents or those that, in the opinion of the Commission, allow the proper protection of the
information stored, transmitted or processed related to the entry of the
Personal Identification Numbers (PIN) of banking clients and the data of the
bank cards.
In the case of using a cell phone, the Personal Identification Number (PIN) must be
entered directly on the keyboard of said phone. At no time may the information of the
PIN be stored on the cell phone without encryption mechanisms.
c)
Biometric Factor.
In case biometric readers are used for the Authentication of banking clients, said
readers must have mechanisms that ensure that it is the authorized client who carries out the
operation, as well as implement mechanisms or procedures so that the commission agent does not
store the information processed related to the biometric factors of clients.
All administration and control of biometric information must be the sole responsibility
of the Institution through the customer service channels that it has established.
d)
Cell phone.
In case cell phones are used for the Authentication of banking clients, the
Institutions must verify that the technology of said cell phones allows them to
function as an Authentication Factor and that it has security mechanisms that prevent
duplication or spoofing.
Institutions may not use the combination of the Authentication Factors referred to in
subparagraphs a) and d) to authenticate their clients.
Authentication for Operators.
For the receipt and operation of transactions requested by banking clients through the
Electronic Media of the commission agents, the Operators must start a session and
authenticate themselves through said Media.
The authentication processes must be validated by the Institution, through the
mechanisms and controls that it deems appropriate. It is the responsibility of the Institution
to ensure that the commission agents have said operator authentication mechanisms, for the carrying out of the operations.
Blocking of Operator Authentication Factors.
Blocking schemes for Operator Authentication Factors must be established when
an attempt is made to enter the Electronic Media incorrectly. At no time may the
failed access attempts exceed five consecutive occasions without generating automatic blocking.
Access to banking client data.
At no time may the Electronic Media used by the commission agents allow the
carrying out of operations or balance inquiries without prior Authentication in terms of
item 5 of section II "Requirements for Operator Identification and Authentication
banking clients" of this annex, of the corresponding client. Deposits and payments operations are excepted from this case.
Likewise, with respect to banking operations that require the commission agent to access the
balances of banking clients' accounts, said commission agent must, at all times,
keep confidentiality regarding said operation and carry out prior to the respective access
the Authentication referred to in item 1 of section III "Electronic Media Operations"
of this annex.
III.
Electronic Media Operations
Validation of destination account structure.
The Electronic Media of the commission agents must validate, based on the information
available to the Institution, the structure of the destination account number or contract, whether
it is for deposit accounts, service payments, Standardized Banking Key, credit cards or other payment means.
Generation of operation receipts.
The Electronic Media must automatically generate the operation receipts that
are issued by the Institutions for each operation, without any intervention by the
personnel of the commission agent. Such operation receipts will be different from those used by the commission agents to record the operations of their own business and must include what is stipulated by the General Provisions of CONDUSEF in matters of
transparency and sound practices applicable to credit institutions. In addition to the
referred provisions, Institutions must consider in the operation receipts the following:
a)
The data that allow the banking client to identify the account with respect to which the
operation was carried out. At no time must the full number of the account be displayed on the receipts.
b)
The information regarding balance inquiries, when the client has requested and authorized it, in which case it must be provided only to the client through the corresponding receipt. The commissionaire may not issue a duplicate of said receipt or keep a copy of it.
c)
The identification of the Institution and the commissionaire with whom the operation was carried out, specifying in the latter case, the address of the establishment through which the instruction was executed.
d)
The information that allows the identification of the commissionaire's personnel who performed the instruction.
When the limits referred to in Article 323 of these provisions are exceeded, as applicable, the requested operations cannot be carried out; therefore, the Electronic Means must generate receipts indicating to the banking client this situation. For these purposes, a receipt must be provided that includes the following legends:
a)
In the case of the limit referred to in Article 323, fraction II, subsection b) of these Provisions: "Transaction not performed due to exceeding its permitted limit. Go to a bank branch."
b)
In the case of the limits referred to in Article 323, fractions I and II, subsection a) of these Provisions, as applicable: "Transaction not performed". Under no circumstances should the client's address be shown on the operation receipt.
Institutions will make available to their clients on operation receipts the information regarding the telephone number and email address of the specialized unit for user assistance that the Institution must have in terms of the Law for the Protection and Defense of Users of Financial Services, as well as the Institution's attention center.
All operation receipts issued through commissionaires will have probative value for any clarification purposes and must be recognized as such by the Institutions issuing them.
Monitoring of operations.
The Institution must establish continuous mechanisms using computer tools that allow it to monitor the activities performed by Operators through the Electronic Means of the commissionaires in order to detect transactions that deviate from usual operational parameters.
Storage of Sensitive User Information in Electronic Means of commissionaires.
In cases where, for operational and technical reasons, it is necessary to store partially or totally Sensitive Information of the User of the Institution in the Electronic Means of the commissionaire, the institution must verify that encryption mechanisms exist.
Likewise, commissionaires may not issue a duplicate of balance inquiry receipts or keep copies of these.
IV.
Information Security
Logical or logical and physical segregation of different networks in distinct domains and subnets, depending on the function they perform or the type of data transmitted, including segregation of production environments from development and testing environments, as well as perimeter and network security components that ensure that only authorized traffic is permitted. In particular, in those segments with links to the outside, such as the Internet, providers, authorities, other networks of the Institution or headquarters, Administrators, commissionaires, and other third parties, consider safe zones, including those known as demilitarized zones (DMZ).
Secure configuration of components, considering at least, ports and services, permissions granted under the principle of least privilege, use of removable storage media, access lists, manufacturer updates, and reconfiguration of factory parameters.
Security measures for their protection, as well as for the access and use of information that is received, generated, transmitted, stored, and processed in the technological infrastructure, having at least the following:
a)
Identification and authentication mechanisms for each and every one of the users of the technological infrastructure, which allow them to be recognized unequivocally and ensure access only to persons expressly authorized for this purpose, under the principle of least privilege. For this purpose, relevant controls must be included for those users of the technological infrastructure with greater privileges, derived from their functions, such as database and operating system administration.
b)
Encryption of information according to the degree of sensitivity or classification that the Institution determines and establishes in its policies, when such information is transmitted, exchanged, and communicated between components, or stored in the technological infrastructure or accessed remotely.
c)
Access keys with composition characteristics that prevent unauthorized access, considering processes that ensure that only the user of the Technological Infrastructure knows them, as well as security measures, encryption in storage, and mechanisms to change access keys every 90 days or less.
d)
Controls to automatically terminate unattended sessions, as well as to prevent simultaneous unauthorized sessions with the same user identifier of the technological infrastructure.
e)
Security mechanisms, both physical access and environmental and electrical energy controls, that protect the technological infrastructure and allow operation in accordance with the specifications of the supplier, manufacturer, or developer.
f)
Validation measures to guarantee the authenticity of transactions executed by the different components of the technological infrastructure, considering, at least the following:
i.
The veracity and integrity of the information.
ii.
The authentication between components of the technological infrastructure, which ensure that only legitimate service requests are executed from their origin to their execution and registration.
iii.
Messaging, communication, and encryption protocols, which must ensure the integrity and confidentiality of the information.
iv.
The identification of atypical transactions, anticipating that applications have automatic alert measures for attention by the corresponding operational areas.
g)
The update and maintenance of digital certificates and components provided by service providers that are integrated into the transaction execution process.
Automated mechanisms to detect and prevent information security events and incidents, as well as to prevent unauthorized incoming or outgoing data connections and flows and information leakage, considering among others, removable storage media.
Policies and procedures for the administration of encryption keys used by the Institution and the commissionaire, as applicable.
Policies and procedures for secure deletion for the destruction of data when they are no longer necessary, or upon the conclusion of the commercial commission.
Policies and procedures for the management of information security incidents of commissionaires that ensure the detection, classification, attention, and containment, investigation, and, if applicable, digital forensic analysis, diagnosis, reporting to competent hierarchical levels, solution, follow-up, and immediate communication to the Institution and counterparties of such incidents.
Registration in databases of incidents, failures, or vulnerabilities detected in the Technological Infrastructure of the commissionaire, which includes at least the information related to the detection of failures, operational errors, attempts at computer attacks and those effectively carried out, as well as loss, extraction, alteration, misplacement, or improper use of information of the Users of the Technological Infrastructure of the commissionaire, where the date of the event and a brief description of it, its duration, affected service or channel, amounts, as well as the corrective measures implemented are contemplated.
Likewise, maintain complete audit records that include detailed information of accesses or access attempts and the operation or activity performed by the Users of the Technological Infrastructure. Such records must be available to authorized personnel of the Institution.
Performance of vulnerability scanning tests of the technological infrastructure components of commissionaires that store, process, or transmit information of banking operations. Such tests must be performed at least quarterly.
Performance of penetration tests by an independent third party, whose personnel have verifiable technical capacity through specialized certifications in the matter, such tests must contemplate the technological infrastructure of the commissionaire for commercial commission. The tests must consider, at least the following:
a)
Its scope and methodology.
b)
Be performed at least once a year.
c)
Additional tests must be performed when there are significant changes in systems and applications, or perform them on previously reviewed systems and applications when critical vulnerabilities exist.
Continuous follow-up to remediation plans regarding the findings of the reviews and tests referred to in the previous items 9 and 10. Such plans must be reviewed by the institution and follow up on the actions implemented for their mitigation.
Have access controls to information according to the access levels and profiles determined by the Institution.
V.
Requirements for the operation referred to in fraction IX of Article 319 of these provisions
That the systems of the Institution, as well as, if applicable, those of the brokerage houses with which they intend to enter into commercial commissions, have the necessary technical requirements that allow them to comply with what is stipulated in Article 124 of the Law, as well as to receive and transmit the information referred to in the "General Rules to which multiple banking institutions must be subject to classify information related to active and passive operations referred to in Article 124 of the Credit Institutions Law", and those issued by the IPAB, or those that replace them, including what is stated in the following item 3.
The procedures through which the Institution will authorize the brokerage houses to carry out such operations.
The obligation of the commissioning brokerage house to:
a)
Collect from the client the necessary information in order to comply with what is provided in Article 115 of the Law and the "General Provisions referred to in article 115 of the Credit Institutions Law" issued by the Secretariat, or those that replace them.
For this purpose, the brokerage houses must transmit in a timely manner to the Institution the information related to the mentioned operations, so that the Institution itself complies with the cited Article 115 of the Law and the "General Provisions referred to in article 115 of the Credit Institutions Law" issued by the Secretariat, or those that replace them.
b)
Regarding operations carried out with multiple banking institutions as principals:
i.
Collect and classify in automated processing and data conservation systems, as well as in any other technical procedure, all the information that allows the multiple banking institution to comply with the Third of the "General Rules to which multiple banking institutions must be subject to classify information related to active and passive operations referred to in Article 124 of the Credit Institutions Law" issued by the IPAB or those that replace them;
ii.
Transmit to the multiple banking institution principal, simultaneously at the moment of the celebration of each operation, through its systems, the information that, in accordance with the Rules referred to in the previous item, the latter must maintain. This is without prejudice to the fact that the contracts referred to in this article must contain the obligation on the part of the brokerage houses acting as commissionaires to transmit to the multiple banking institution principals all the information referred to in the Third of the Rules mentioned in the previous item i., when so requested by the Commission, directly or at the request of the IPAB, provided that the corresponding assumptions of the resolution of the multiple banking institution principal in terms of Article 122 Bis of the Law are met;
iii.
Obtain from the client at the time of celebrating the operations, a written manifestation or by any means agreed with the banking client, in the terms of the format contained as Annex 60 of these provisions, and
iv.
Deliver to the client, on the back of the document referred to in the previous item iii., or by any means agreed with the banking client, an informative text in the terms established in Annex 61 of these provisions.
c)
The terms under which the settlement of the operations must be carried out.
In the event that the settlement of the respective operations is carried out in the offices of the brokerage houses, deliver to the client the respective amount in the manner agreed at the time of contracting. In any case, if the client does not request the referred settlement at the office within a period of three business days counted from the maturity date of the operation, the brokerage house will be released from the obligation to make the corresponding payment in favor of the client, so the settlement must be carried out directly with the Institution.
The obligation on the part of the Institution to provide the necessary means in order to comply with the provisions referred to in the previous items 1 and 2 and, in general, to what is established by the provisions related to the banking savings protection system, as well as to ensure that the commissionaire effectively complies with the foregoing.
Annex 59
Information that must be presented in the commissionaire authorization request
The information to be presented in the commissionaire authorization request must contain at least the following:
Detailed description and flowchart of the processes of each of the operations to be carried out through the commissionaires considering the reconciliation and settlement process of each of them, the third parties involved, and the Technological Infrastructure to be used in the operation in question.
Architecture and telecommunications diagram showing the security and network components of the technological infrastructure used for the operation with commissionaires, which ensure that only authorized traffic is permitted. This diagram must include each of the participants, as well as all information processing sites including redundancy schemes, link types, backup routes, servers, and communication devices.
The complete and detailed locations of the main and backup data centers, both of the Institution, the commissionaire, or the provider of the commissionaire's technological infrastructure where the information of the transactions carried out through the commissionaire will be stored and/or processed (street, exterior and interior number, neighborhood, borough or municipality, state, and country).
Diagram of interrelation of commissionaire applications or systems, including the Institution's own systems. (Must include all participants involved in the operation (e.g.: commissionaire, switches, payment media processors, third parties, and the Institution itself).
Detail of the Sensitive Information that will be stored by the commissionaire in its equipment or facilities, or by the provider of the commissionaire's technological infrastructure, or to which they may have access. Regarding Sensitive Information, the commissionaire must implement encrypted storage mechanisms.
Include the characteristics of the operation receipts, attach the design of the receipt of each of the operations to be contracted.
Description of validation measures to guarantee the authenticity of transactions executed by the different components of the technological infrastructure, considering, at least the following:
a)
The veracity and integrity of the information.
b)
The authentication between components of the technological infrastructure, which ensure that only legitimate service requests are executed from their origin to their execution and registration.
c)
Messaging, communication, and encryption protocols, which must ensure the integrity and confidentiality of the information.
d)
The identification of atypical transactions, anticipating that applications have automatic alert measures for attention by the corresponding operational areas.
Description of automated mechanisms to detect and prevent information security events and incidents, as well as to prevent unauthorized incoming or outgoing data connections and flows and information leakage, considering among others, removable storage media.
Detailed report of vulnerability scanning test results of the technological infrastructure components of commissionaires that store, process, or transmit information of banking operations.
Detailed report of penetration test results performed by an independent third party, whose personnel have verifiable technical capacity through specialized certifications in the matter, such tests must contemplate the technological infrastructure of the commissionaire for commercial commission.
Remediation plans regarding the findings of the reviews and tests referred to in the previous items 9 and 10, as well as evidence of mitigation actions implemented to remedy critical and high severity vulnerabilities.
Documentation of the Internal Certification Formats of Commissionaires (FCIC) related to the pre-operational tests of operations to commissionaires.
In the document you are viewing, there may be text, characters, or objects that are not displayed correctly due to conversion to HTML format, so we recommend always taking the digitized image of the DOF or the PDF file of the edition as a reference. The content, form, and scope of the published documents are the strict responsibility of their issuer.
CONSULT
BY DATE
Su Mo Tu We Th Fr Sa
INDICATORS
Exchange Rate and Rates as of 08/28/2026
DOLLAR 16.9712 UDIS 8.808812 TIIE 28 DAYS 6.7559% TIIE 91 DAYS 6.7931% TIIE 182 DAYS 6.8474% TIIE OVERNIGHT 6.50%
See more
SURVEYS
Did you like the new image of the Official Gazette of the Federation website?
No Yes
Official Gazette of the Federation
Río Amazonas No. 62, Col. Cuauhtémoc, C.P. 06500, Mexico City Tel. (55) 5093-3200, where you can access our service menu
Electronic address: dof.gob.mx
113
LEGAL NOTICE | SOME RIGHTS RESERVED © 2026
More like this from SHCP
SHCP published 14 documents in the last 30 days. We email you each new one the day it's published.