2019-03-25 | DOF 5555030Added
The National Banking and Securities Commission (CNBV) amends the General Provisions applicable to Financial Technology Institutions to introduce new regulatory frameworks for information security, the use of electronic media, third-party service contracting, and information disclosure. The resolution updates definitions in Article 2, modifies Article 51 regarding solvency requirements for lending terms, and adds Chapters VI through IX and Title IV to establish controls for cybersecurity, authentication, and operational continuity. It also mandates specific regulatory reporting obligations and updates Annexes 8 through 20 to define formats for security incidents, investor classifications, and information disclosure guidelines for collective financing entities.
If the document is presented incomplete on the right margin, it is because it contains tables that exceed the default width. If this is the case, click here to view it correctly.
DOF: 25/03/2019
RESOLUTION modifying the General Provisions applicable to Financial Technology Institutions
At the margin, a seal with the National Coat of Arms, which reads: United Mexican States.- SHCP.- Ministry of Finance and Public Credit.- National Banking and Securities Commission.
The National Banking and Securities Commission, based on the provisions of Articles 18, fraction IV; 19, fraction IV; 48, first paragraph; 54, first paragraph; 56, second paragraph, and 57 of the Law to Regulate Financial Technology Institutions, as well as 4, fractions XXXVI and XXXVIII; 16, fraction I, and 19 of the Law of the National Banking and Securities Commission, and
CONSIDERING
That the National Banking and Securities Commission issued the resolution published in the Official Journal of the Federation on July 24, 2017, through which the General Provisions applicable to brokerage houses were reformed, to extend the deadline for these entities to sell or reclassify their held-to-maturity securities from 28 to 90 days, thereby satisfying Article 78 of the General Law for Regulatory Improvement regarding the compliance cost of this resolution;
That on the other hand, in order to be able to face risks and attacks that could cause damage to collective financing institutions and the execution of operations with their clients, it is convenient to incorporate the regulatory framework on the security of their systems and technological infrastructure, determining the internal controls they must have, establishing also a regime that seeks to guarantee the security of the technological infrastructure on which their operations are supported and the confidentiality, integrity, and availability of information;
That one of the fundamental characteristics of collective financing institutions is that they precisely operate through remote electronic or digital communication means, that is, technological devices, computer applications, interfaces, Internet pages, and similar; therefore, it is indispensable in light of the Law to Regulate Financial Technology Institutions to regulate the operation and use of equipment, electronic, optical, or any other technology means, automated data processing systems, and telecommunications networks, including the norms pertaining to the forms of authenticating both the institutions themselves and their clients, complying with the principles of technological neutrality and consumer protection established in the Law;
That in terms of the Law to Regulate Financial Technology Institutions, collective financing institutions may agree with third parties the provision of services necessary for their operation, in accordance with the provisions issued for such effect by the National Banking and Securities Commission, so the corresponding norms for such contracting are established, as well as those services that will require the authorization of the Commission itself, taking into account the due protection of the sensitive information of the clients of these financial entities;
That in order for clients to have the necessary information to identify the risks they incur in the celebration of operations and investment decision-making, it is indispensable to incorporate the regime applicable to collective financing institutions for the disclosure of information about financing applicants, in accordance with the authority held by the National Banking and Securities Commission to issue norms in matters of transparency of the services of these financial entities;
That at the same time, in terms of the Law to Regulate Financial Technology Institutions, once any operation has been carried out in collective financing institutions, these must have available to investors information about the payment behavior of the applicant, their performance, or any other that is relevant in terms of the provisions issued for such effect by the National Banking and Securities Commission;
That in this vein, it is indispensable to establish the content of the information, the form, and periodicity of this, in order for investors to have at all times the information that allows them to continue the operation in which they have participated, in congruence with the principles established in the Law itself regarding consumer protection and financial inclusion, and
That in order for the National Banking and Securities Commission to have the corresponding information regarding the activities and operations of financial technology institutions, the obligation to present the corresponding reports is established, designating the person responsible for their submission and the quality of their content, as well as the deadlines and means for their presentation, it has resolved to issue the following:
RESOLUTION MODIFYING THE GENERAL PROVISIONS APPLICABLE TO FINANCIAL TECHNOLOGY INSTITUTIONS
ARTICLE FIRST.- Articles 2 and 51, second paragraph, are REFORMED; Chapter VI to be called "On Information Security" comprising Articles 63 to 68; Chapter VII to be called "On the Use of Electronic Media" comprising Articles 69 to 84; Chapter VIII to be called "On the Contracting of Services with Third Parties" comprising Articles 85 to 88; Chapter IX to be called "On Information Disclosure" comprising the First Section called "On Information Disclosure in the Publication of Applications and Projects" with Articles 89 to 93, Second to be called "On Information Disclosure of the Payment Behavior and Performance of the Applicant or Project" with Articles 94 to 96, and Third to be called "On Information Disclosure to the General Public" with Article 97; Title Four to be called "On Regulatory Reports" with Chapter I to be called "On Reports in General" with Articles 98 to 103 and Chapter II to be called "On Delivery Means" with Article 103; as well as Annexes 11, 12, 13, 14, 15, 16, 17, 18, 19, and 20 are ADDED; and Annexes 8 and 9 of the General Provisions applicable to financial technology institutions, published in the Federal Diary on September 10, 2018, are SUBSTITUTED, to read as follows:
" FIRST and SECOND TITLES
...
THIRD TITLE
...
Chapters
I to V
...
Chapter VI
On Information Security
Chapter VII
On the Use of Electronic Media
Chapter VIII
On the Contracting of Services with Third Parties
Chapter IX
On Information Disclosure
First Section
On Information Disclosure in the Publication of Applications and Projects
Second Section
On Information Disclosure of the Payment Behavior and Performance of the Applicant or Project
Third Section
On Information Disclosure to the General Public
FOURTH TITLE
On Regulatory Reports
Chapter I
On Reports in General
Chapter II
On Delivery Means
ANNEXES
1 to 7
...
ANNEX 8
Instructions for obtaining electronic certificates of knowledge of risks
ANNEX 9
Format of declarations regarding compliance with requirements to be considered an Experienced Investor
ANNEX 10
...
ANNEX 11
Incidents affecting information security
ANNEX 12
Information Security Incident Report
ANNEX 13
Information security indicators
ANNEX 14
Format for information on systems and applications
ANNEX 15
Guidelines for information disclosure of Collective Financing of Debt for Business-to-Person Loans and for Real Estate Development
ANNEX 16
Guidelines for information disclosure for Collective Financing of Capital
ANNEX 17
Aggregated information of collective financing institutions for disclosure to the general public
ANNEX 18
Regulatory reports that collective financing institutions must present
ANNEX 19
Regulatory reports that electronic payment fund institutions must present
ANNEX 20 "Designation of responsible persons for the submission and quality of information"
" Article 2.- In addition to the definitions contained in the Law, for the purposes of these provisions, the following shall be understood, in singular or plural:
I.
Authentication, the set of techniques and procedures used to verify the identity of a Client and their authority to carry out operations through the Electronic Medium in question or a User of Technological Infrastructure to access, use, or operate any component of the Technological Infrastructure.
II.
Blocking, the process by which the collective financing institution disables the use of an Authentication Factor or Client Identifier temporarily or permanently.
III.
Encryption, the mechanism that collective financing institutions must use to protect the confidentiality of information through cryptographic methods in which algorithms and encryption keys are used.
IV.
Investment Commitments, the contributions that Investors have committed to make in favor of Applicants during the Collective Financing Application Period, regardless of whether the corresponding contributions are delivered to the collective financing institutions during said period or to the Applicants after its conclusion.
V.
Cloud Computing, the model of external provision of on-demand computing services on shared infrastructure, regardless of the physical location of the third-party's technological infrastructure providing the service, which may be among others one or more of the following digital service schemes: infrastructure as a service, platform as a service, or software as a service.
VI.
Operational Contingency, any event that hinders, limits, or prevents a collective financing institution from providing its services or carrying out those processes that could have an impact on its Clients.
VII.
Password, the chain of alphanumeric and special characters that authenticates a Client in the Electronic Medium of the collective financing institution.
VIII.
Destination Accounts, the accounts receiving monetary resources that Clients of the collective financing institution register in the corresponding Electronic Medium to carry out Operations.
IX.
Unblocking, the process by which the collective financing institution enables the use of an Authentication Factor or Client Identifier that was blocked.
X.
Access Device, the equipment that allows a Client to access the corresponding Electronic Medium of the collective financing institution.
XI.
Information Security Event, any internal or external event related to Clients, third parties contracted by the collective financing institution itself, people, and operational processes, as well as with components of the Technological Infrastructure, devices, physical media, or other elements that store information, among others, that could imply an impact on the confidentiality, integrity, or availability of the information that such institution manages or knows, or in the Technological Infrastructure itself.
XII.
Authentication Factor, the Authentication mechanism based on the physical characteristics of the Client, devices, or information that only the Client possesses or knows.
XIII.
Collective Financing of Capital, the collective financing operation through which Applicants obtain resources from Investors in exchange for shares representing their social capital.
XIV.
Collective Financing of Co-ownership or Royalties, the collective financing operation through which Investors and Applicants enter into partnerships or any other type of agreement by which Investors acquire an aliquot part or participation in a present or future asset or in the income, profits, royalties, or losses obtained from the realization of one or more activities or from the projects of the Applicants.
XV.
Collective Financing of Debt for Business-to-Person Loans, the collective financing operation in which Applicants are legal entities or natural persons with business activity and Investors make contributions: a)
With the aim that Applicants receive a loan or credit to finance their activities, being obligated to pay the principal and, if applicable, accessories to each of the Investors in proportion to their contributions in the Operation. b)
With the object of carrying out a financial leasing operation, in which an asset is acquired in the name of the Investors, or by the collective financing institutions in their own name, but on their behalf, and is given in financial lease to the Applicant. For the purposes of the financial leasing operation, the provisions of the General Law of Titles and Credit Operations shall apply. c)
With the aim of carrying out a financial factoring operation, in which they acquire part of some credit right that the Applicant has in their favor, with the Applicant remaining jointly liable for its debtor, without said right deriving from loans, credits, or loans previously granted by the Applicant. For the purposes of the financial factoring operation, the provisions of the General Law of Titles and Credit Operations shall apply.
XVI.
Collective Financing of Debt for Personal Loans between Persons, the collective financing operation in which the Applicant is a natural person who obtains in loan the resources contributed by the Investors, being obligated to pay the principal and, if applicable, accessories, to each of the Investors in proportion to their contributions in the Operation.
XVII.
Collective Financing of Debt for Real Estate Development, the collective financing operation whose object is for Investors to grant a loan or credit to Applicants destined for the financing of real estate development activities, with Investors being obligated to pay the principal and, if applicable, accessories to each of the Investors in proportion to their contributions in the Operation.
XVIII.
Private Capital Fund, the investment vehicle, trust, mandate, commission, or similar figures constituted under Mexican or foreign laws, whose purpose is to invest in the capital of companies not listed on stock exchanges at the time of investment to promote their development and provide them with financing.
XIX.
Client Identifier, the chain of alphanumeric or special characters, device information, or any other information known by both the collective financing institution and the Client, which allows identifying the Client in the Electronic Medium of the collective financing institution.
XX.
Information Security Incident, the Information Security Event in the collective financing institution when it updates any of the following situations: a)
It has compromised the confidentiality, integrity, or availability of a component or the entirety of the Technological Infrastructure with an adverse effect on the collective financing institution, its Clients, third parties, providers, or counterparties, among others. b)
It violates the Technological Infrastructure compromising the information it processes, stores, or transmits. c)
It constitutes a violation of the information security policies and procedures. d)
It represents the materialization of a loss, whether by extraction, alteration, or loss of information; by failures derived from the use of hardware, software, systems, applications, networks, and any other channel of information transmission; by unauthorized accesses resulting in the improper use of information or systems; by fraud, theft, or interruption of services, attacks on interconnected infrastructures, known as cyberattacks, among others.
XXI.
Sensitive Information, the personal information of Clients containing names, addresses, phone numbers, email addresses, or any other data identifying the Client, together with account numbers, card numbers, and other data of a financial nature, as well as Client Identifiers or Authentication information.
XXII.
Investor, the natural or legal person who contributes resources or virtual assets to Applicants for the celebration of collective financing operations.
XXIII.
Experienced Investor, any of the following: a)
Financial entities referred to in Article 21, third paragraph of the Law, as well as other financial entities that according to their legal regime can act as Investors in the Operations in question. b)
Foreign financial entities, provided that the collective financing institution has obtained authorization from the CNBV to receive or make transfers in terms of Article 10 of these provisions. c)
Departments and entities of the Federal Public Administration. d)
Persons who declare themselves to be in the situation indicated in Annex 9 of these provisions.
XXIV.
Related Investor, that which declares before the collective financing institutions to have kinship with the Applicant by blood, affinity, or civil law up to the fourth degree or be their spouse, concubine, or concubinary.
XXV.
Law, the Law to Regulate Financial Technology Institutions.
XXVI.
Electronic Media, the equipment, optical media, or any other technology, automated data processing systems, and telecommunications networks, whether public or private, including the Platform, that collective financing institutions use to provide their services.
XXVII.
Personal Identification Number (PIN), the Password that authenticates a Client in the Electronic Medium of the collective financing institution through a chain of numeric characters.
XXVIII.
Administrative Body, the sole administrator or the board of directors of an FTI.
XXIX.
Business Continuity Plan, the set of strategies, procedures, and actions that allow, upon verification of Operational Contingencies, the continuity in Operations, activities, or in the realization of critical processes of collective financing institutions, or their timely restoration, as well as the mitigation of impacts resulting from said Operational Contingencies.
XXX.
Security Master Plan, the document that establishes the security strategy of a collective financing institution in the short, medium, and long term to ensure proper management of information security and prevent Information Security Events from materializing into Information Security Incidents.
XXXI.
Platform, the computer applications, interfaces, Internet pages, or any other electronic or digital communication medium that collective financing institutions use to operate with their Clients.
XXXII.
Collective Financing Application Period, the period during which a collective financing application can remain published on the Platform of a collective financing institution in order to offer Investors the celebration of an Operation with Applicants.
XXXIII.
Credit Information Report, any of the credit reports issued by credit information societies referred to in Article 36 Bis of the Law to Regulate Credit Information Societies, namely: a)
The one issued by a credit information society that includes the information contained in the databases of other credit information societies. b)
Those issued by each of the credit information societies.
XXXIV.
Session, the period during which Clients can carry out queries and Operations, once they have entered the Platform with their Client Identifier.
XXXV.
SITI: Inter-institutional Information Transfer System, which is part of the CNBV's official registry.
XXXVI.
Applicant, the natural or legal person who has requested resources or virtual assets from Investors, through collective financing institutions.
XXXVII.
UDI, the account units called "Investment Units" established in the "Decree by which obligations that may be denominated in Investment Units are established and various provisions of the Federal Tax Code and the Income Tax Law are reformed and added", published in the Official Journal of the Federation on April 1, 1995, as it may be modified or added from time to time.
XXXVIII.
User of the Technological Infrastructure, the person, Client, or physical or logical component that accesses, uses, or operates any component of the Technological Infrastructure of collective financing institutions. "
" Article 51.- ...
I. and II.
...
The CNBV will grant the corresponding authorization provided that the collective financing institution proves that the terms of the loans or credits it intends to celebrate will not put its solvency and financial stability at risk.
... "
" Chapter VI
On Information Security
Article 63.- The general director or, if applicable, the sole administrator of the collective financing institution, shall be responsible for the implementation of internal controls in matters of information security that ensure its confidentiality, integrity, and availability. The management framework referred to in this paragraph must ensure that the Technological Infrastructure of said institution, whether its own or provided by third parties, complies with the following requirements:
I.
That each of its components performs the functions for which it was designed, developed, or acquired.
II.
That its processes, functionalities, and configurations, including its development or acquisition methodology, as well as the record of its changes, updates, and the detailed inventory of each component of the Technological Infrastructure, are documented.
III."
That information security aspects have been considered in the definition of projects to acquire or develop each of its components, including them during the various stages of the lifecycle. This will comprise the elaboration of requirements, design, development or acquisition, implementation testing, acceptance testing by Users of the Technological Infrastructure, release processes including vulnerability testing and code analysis prior to production, periodic testing, change management, replacement and destruction of information.
Regarding components of communications and computing, security aspects shall include, at least, the following:
a) Logical segregation, or logical and physical segregation of different networks into distinct domains and subnets, depending on the function they perform or the type of data transmitted, including segregation of production environments from development and testing environments, as well as perimeter and network security components that ensure that only authorized traffic is permitted. In particular, in those segments with links to the exterior, such as the Internet, providers, authorities, other networks of the collective financing institution or parent company, and other third parties, all of which refers to those services defined as critical by the institution itself, whether payment systems, Encryption equipment, Operation authorizers, among others, they shall consider secure zones, including those known as demilitarized zones (DMZ).
b) Secure configuration according to the type of component, considering at least, ports and services, permissions granted under the principle of least privilege, use of removable storage media, access lists, manufacturer updates, and reconfiguration of factory parameters. The principle of least privilege shall be understood as the enabling of access only to the information and resources necessary for the performance of the functions specific to each User of the Technological Infrastructure.
c) Security mechanisms in applications that ensure that, during their execution, they are protected from attacks or intrusions, such as code injection, session manipulation, information leakage, alteration of access privileges, among others. Such mechanisms shall be implemented both for applications provided by third parties and for applications developed, implemented, and maintained by the collective financing institution itself.
IV.
That each of its components be tested before being implemented or modified, using quality control mechanisms that prevent the use of real data from the production environment during such tests, the disclosure of confidential or security information, or the introduction of any functionality not recognized for said component.
V.
That it has the licenses or use authorizations, where applicable.
VI.
That it has security measures for its protection, as well as for the access and use of the information that is received, generated, transmitted, stored, and processed in the Technological Infrastructure itself, having at least the following:
a) Identification and Authentication mechanisms for all and each of the Users of the Technological Infrastructure, which allow them to be recognized unequivocally and ensure access only to persons expressly authorized for this purpose, under the principle of least privilege.
For this purpose, relevant controls shall be included for those Users of the Technological Infrastructure with greater privileges, derived from their functions, such as database administration, operating systems, and applications.
Likewise, policies and procedures for exception access authorizations shall be provided for in manuals, such as users of development environments with access to production environments and access due to contingency events, among others. Such policies and procedures shall be approved by the Chief Information Security Officer.
b) Encryption of information according to the degree of sensitivity or classification of the information that the collective financing institution determines and establishes in its policies, when such information is transmitted, exchanged, and communicated between components or stored in the Technological Infrastructure or accessed remotely.
Collective financing institutions shall encrypt at least the information they have classified as critical in terms of these provisions.
c) Access keys with composition characteristics that prevent unauthorized access, considering processes that ensure that only the User of the Technological Infrastructure knows them, as well as security measures, Encryption in their storage, and mechanisms to request the change of access keys every ninety days or less. Regarding Clients, the referred period shall be that defined by the collective financing institutions themselves in the manuals referred to in the last paragraph of this article. In the case of Users of the Technological Infrastructure assigned to applications or components to authenticate with each other, the change referred to in this subsection shall be carried out at least once a year. In the event that any User of the Technological Infrastructure has knowledge of the access keys and ceases to provide their services to the collective financing institution, these shall be disabled immediately.
d) Controls to automatically terminate idle sessions, as well as to prevent unauthorized simultaneous sessions with the same User of the Technological Infrastructure identifier.
e) Security mechanisms, both physical access and environmental and electrical energy controls, that protect the Technological Infrastructure and allow operation in accordance with the specifications of the supplier, manufacturer, or developer.
f) Validation measures to guarantee the authenticity of transactions executed by the different components of the Technological Infrastructure considering, at least, the following:
The truthfulness and integrity of the information.
Authentication between components of the Technological Infrastructure, which ensure that only legitimate service requests are executed from their origin to their execution and registration.
Messaging, communication, and Encryption protocols, which must ensure the integrity and confidentiality of the information.
The identification of atypical transactions, anticipating that monitoring tools or automatic alert measures will be available for attention by the corresponding operational areas.
The update and maintenance of digital certificates and components provided by service providers that are integrated into the transaction execution process.
The measures referred to in this subsection shall be established in accordance with the degree of risk that collective financing institutions define for each type of transaction.
Collective financing institutions, in the classification of information referred to in subsection b) of this section, shall consider at least one category regarding critical information. In this category, they shall include at minimum Sensitive Information and images of official identification and biometric information of Clients, as well as any other they determine in accordance with their policies.
VII.
That it has backup mechanisms and information recovery procedures that mitigate the risk of operational interruption, in accordance with what is stipulated in its Business Continuity Plan referred to in Chapter V of Title Three of these provisions.
VIII.
That it maintains complete audit records, including detailed information of accesses or access attempts and the operation or activity carried out by Users of the Technological Infrastructure, this regardless of the level of privileges they have for access, generation, or modification of the information they receive, generate, store, or transmit in each component of the Technological Infrastructure, including automated process activity, as well as procedures for the periodic review of such records.
Collective financing institutions shall retain the audit records referred to in this subsection for a period of three years when such records refer to activities carried out on components that process or store information considered critical in accordance with the classification determined by the collective financing institution. Otherwise, the retention period for records shall be a minimum of six months.
IX.
That for the handling of Information Security Events and Information Security Incidents, there are management processes that ensure detection, classification, handling, containment, investigation, and, where applicable, digital forensic analysis, diagnosis, reporting to competent areas, resolution, follow-up, and communication to authorities, Clients, and counterparties.
For the detection and response to Information Security Incidents referred to in the previous paragraph, the general director or, where applicable, the sole administrator shall designate a team that incorporates personnel from the different areas of the collective financing institution to participate in each activity of the aforementioned management process, which in all cases shall include the Chief Information Security Officer in accordance with article 66 of these provisions.
In the event that vulnerabilities and deficiencies are detected in the Technological Infrastructure, corrective actions or compensatory controls shall be taken according to the level of risk involved, preventing Users of the Technological Infrastructure or the collective financing institution from being affected.
X.
That it be subjected to annual planning and review exercises that allow measuring its capacity to support its operation, ensuring that the needs for capacity increase detected as a result of such exercises are addressed promptly.
Likewise, the collective financing institution shall evaluate the obsolescence of the components of the Technological Infrastructure, having a plan for their update.
XI.
That it has automated controls or, in the absence of these, that compensatory controls are carried out, such as double verification and reconciliation that, prior or subsequent to the operation in question, minimize the risk of elimination, exposure, alteration, or modification of information, derived from manual or semi-automated processes carried out by the personnel of the collective financing institution, with the objective of preventing errors, omissions, theft, or manipulation of information.
XII.
That it has controls that allow detecting the alteration or falsification of books, records, and digital documents related to Operations.
XIII.
That it has processes to measure and ensure availability levels and response times, which guarantee the execution of Operations carried out; this, including scenarios where collective financing institutions hire third parties to provide services for the processing and storage of information.
XIV.
That it has devices or automated mechanisms to detect and prevent Information Security Events and Information Security Incidents, as well as to prevent unauthorized incoming or outgoing data connections and flows and information leakage, considering, among others, removable storage media.
Collective financing institutions shall correlate the data obtained from the devices or automated mechanisms referred to in the previous paragraph with data from other sources, such as records of activity of Information Security Events or Information Security Incidents.
Additionally, collective financing institutions shall maintain controls that prevent the leakage of information corresponding to the configuration of the Technological Infrastructure, such as IP addresses, firewall rules, as well as hardware and software versions.
XV.
That for the provision of information technology services to Users of the Technological Infrastructure, in their strategy, design, transition, operation, and continuous improvement phases, the integrity of the Technological Infrastructure is protected, as well as the integrity, confidentiality, and availability of the information received, generated, processed, stored, and transmitted by it.
The general director or, where applicable, the sole administrator of the collective financing institution shall be responsible for documenting in manuals the policies and procedures provided for in this article.
Article 64.- The general director or, where applicable, the sole administrator of the collective financing institution, shall be responsible for compliance with the following obligations regarding the Technological Infrastructure:
I.
Approve the Security Master Plan, as well as its updates, which must be aligned with the business strategy of the collective financing institution, as well as define and prioritize projects in the matter of information security, with the objective of reducing exposure to technological risks and the materialization of Information Security Incidents up to acceptable levels in the terms defined, where applicable, by the board of directors or the sole administrator themselves, as appropriate, from an analysis of the current situation.
For the approval of the Security Master Plan, the general director or, where applicable, the sole administrator shall verify that it contains initiatives aimed at improving existing work methods and may contemplate the controls required in accordance with applicable provisions.
Regarding collective financing institutions that have a general director and a board of directors, the former shall inform said board of the content of the Security Master Plan and have evidence of its approval and implementation.
II.
Carry out security reviews focused on verifying the sufficiency of controls applicable to the Technological Infrastructure. These reviews shall comprise, at least, the following:
a) Authentication mechanisms of Users of the Technological Infrastructure.
b) Configuration and access controls to the Technological Infrastructure.
c) Updates required for operating systems and software in general, prior to their implementation and once implemented.
d) Identification of possible unauthorized modifications to the original software.
e) Devices, communication networks, systems, and processes associated with Electronic Media and customer service channels, in order to verify that there are no vulnerabilities or that there are tools or procedures that allow knowing the Authentication credentials of Users of the Technological Infrastructure, as well as any information that, directly or indirectly, could give access to the Technological Infrastructure in the name of the User of the Technological Infrastructure.
The reviews referred to in this subsection shall be carried out at least once a year or earlier if significant changes occur in the Technological Infrastructure. To determine if it is a significant change, the opinion of the Chief Information Security Officer shall be obtained for this purpose.
III.
Prepare an annual calendar for the performance of vulnerability scanning tests of the components of the Technological Infrastructure that store, process, or transmit information, prioritizing them according to the result of the information classification exercise determined by the collective financing institution. The calendar shall provide for the bi-monthly review of the components of the Technological Infrastructure so that, by the end of the year, all components that store, process, or transmit information cataloged by the collective financing institution as critical, as well as those it considers necessary, have been reviewed. The general director or, where applicable, the sole administrator, shall be responsible for monitoring that such tests are carried out, either through the collective financing institution itself or a third party hired for this purpose. Additionally, when new components of the Technological Infrastructure are incorporated, the general director or, where applicable, the sole administrator, shall be responsible for monitoring that the vulnerability scanning test is performed prior to its production deployment.
IV.
Hire an independent third party, with personnel who have verifiable technical capacity through industry certifications in the matter, to perform penetration tests in the different systems and applications of the collective financing institution with the purpose of detecting errors, vulnerabilities, unauthorized functionality, or any code that puts or may put at risk the information and assets of Clients and of the collective financing institution itself. Such review shall include the verification of the integrity of hardware and software components that allow detecting alterations thereof. Penetration tests shall consider, at least, the following:
a) Its scope and methodology, which must be validated by the Chief Information Security Officer.
b) Be carried out at least twice a year on different components, systems, or applications that have been determined by the collective financing institution as higher risk, or when ordered by the CNBV having detected vulnerabilities or factors that may affect the systems and applications or the information received, generated, processed, stored, or transmitted therein. In the latter case, the CNBV shall determine the scope of the tests, as well as the deadlines for carrying them out.
Additional tests may be carried out at the discretion of the general director or, where applicable, the sole administrator, with the opinion of the Chief Information Security Officer, when there are significant changes in systems and applications, or carry them out on systems and applications previously tested when there are critical vulnerabilities.
The general director or, where applicable, the sole administrator of the collective financing institution shall send to the CNBV within twenty business days of having finalized the tests, a report with the conclusions thereof. In the submission made, care shall be taken to use mechanisms that prevent unauthorized personnel from accessing the content of this report.
V.
Classify detected vulnerabilities according to the methodology approved by the person responsible for risk management administration of the collective financing institution.
VI.
Prepare remediation plans regarding the findings of the reviews and tests referred to in subsections II, III, and IV above, considering the classification of subsection V of this article, as well as implementing defense mechanisms that prevent unauthorized access and use of the Technological Infrastructure.
The remediation plans referred to in the previous paragraph shall be validated by the Chief Information Security Officer. Likewise, such plans shall contain, at least, the indication of the personnel responsible for their implementation and execution, as well as deadlines for this, detail of activities carried out and to be carried out, as well as the technical, material, and human resources employed. The aforementioned remediation plans must be prepared once the vulnerabilities are identified and sent to the CNBV within a period of ten business days.
In addition to what is stated in the previous paragraph, in the case of short, medium, or long-term projects in the remediation plans, they shall be incorporated into the Security Master Plan.
VII.
Implement follow-up processes for compliance with the aforementioned remediation plans, which shall be verified by the Chief Information Security Officer, who additionally shall corroborate that the aforementioned plans have managed to correct the vulnerabilities found.
VIII.
Implement annual training programs directed to all personnel, as well as awareness programs in the matter of information security towards Clients including, where applicable, third parties that provide them with services, in which, among other aspects, the roles and responsibilities that Users of Technological Infrastructure have in this regard are contemplated.
IX.
Proactively and interactively search for fraud alerts, as well as threats, such as phishing email campaigns, fake Internet sites, disclosure of databases with Client information, mobile applications, and, where applicable, alteration of devices used to carry out Operations, among others, that could affect the information security of Clients, as well as actions for their protection considering, at least, the following:
a) The continuous investigation, collection, processing, and analysis of information that comes from any source related to the products and services offered by the collective financing institution, which may constitute indications or evidence that security controls have been evaded, representing a threat to the information or resources of the Client.
The indications or evidence referred to in the previous paragraph shall be kept in a record, which shall be contained in the database referred to in the first paragraph of article 68 of these provisions.
b) The implementation of proactive processes to protect the information or resources of Clients when the indications or evidence indicated in subsection a) above occur, such as Blocking and replacement of disposal means, change of Authentication data and notifications, among others.
c) That it has communication procedures and security recommendations with affected Clients, to inform them about the remediation processes that the collective financing institution will carry out and, where applicable, the measures that the
own Client must adopt, such as changing passwords, verifying balances and transactions, installing antivirus, installing malicious program detection software, reviewing devices and reinstalling applications, among others.
The terms and conditions for carrying out the processes through which the activities referred to in this subsection are carried out, must be documented in the respective policies and procedures manuals, in which it must be provided that the collective financing institution will maintain evidence of the performance of said activities.
X.
Implement controls that allow the collective financing institution to ensure the confidentiality, integrity, and availability of the information of the Clients and of the collective financing institution itself or access to the Technological Infrastructure, by its employees or personnel who have access to it, which guarantee that such information and Technological Infrastructure are not altered or cause an impact on the collective financing institution or on the resources of its Clients. Such controls must be implemented from the respective hiring until its termination.
XI.
Establish policies and procedures to ensure that the Chief Information Security Officer obtains from the business units of the collective financing institution the information and documentation necessary for the fulfillment of the functions established in these provisions.
Article 65.- Collective financing institutions must have a person who, among their functions, serves as the Chief Information Security Officer, known as CISO by its English acronym (Chief Information Security Officer).
The Chief Information Security Officer must be designated by the General Manager or, if applicable, by the sole administrator, must report to them, and must not have conflicts of interest with respect to the person responsible for the audit and information technology functions that exist within the collective financing institution. Likewise, they cannot perform functions related to the operation of the information security of the collective financing institution itself.
The functions of the Chief Information Security Officer may be performed by a third party, provided that it complies with what is stated in this article.
The Chief Information Security Officer may be supported, in the exercise of their functions, by representatives of the different business units.
Collective financing institutions may designate the General Manager or, if applicable, the sole administrator as the Chief Information Security Officer for a maximum period of twelve months, counted from the date on which they obtain authorization to act as such.
Article 66.- The Chief Information Security Officer of the collective financing institution must, at least:
I.
Participate in the definition and verify the implementation and continuous compliance of the security policies and procedures referred to in Article 63 of these provisions.
II.
Prepare the Security Master Plan, which must contain, for each project defined, the name of the project, objective, scope, start and end dates, areas involved, and projected investment. This plan must be reviewed and updated, at least, annually.
III.
Verify, at least annually, the definition of access profiles to the Technological Infrastructure of the collective financing institution, whether its own or provided by third parties, according to job profiles (functional segregation), including those with high privileges, such as administration of operating systems, databases, and applications.
IV.
Ensure at least annually, or earlier in the event of an Information Security Incident, the correct assignment of access profiles to Users of the Technological Infrastructure. The function referred to in this subsection may be carried out through representative and random samples.
Likewise, it will be responsible for the temporary authorization of access by exception, such as those of users of development environments with access to production environments, access due to contingency events, or any other privileged access that does not correspond to the policy determined by the collective financing institution. Likewise, it must have a record containing the name of the Technological Infrastructure User, associated application, environment, reason for the exception, and start and end dates of the assignment.
V.
Approve and verify compliance with the measures that have been adopted to remedy deficiencies detected as a result of the functions referred to in subsections III and IV of this article, as well as the findings of audits carried out related to the Technological Infrastructure and information security.
VI.
Manage information security alerts communicated by the CNBV or other means, as well as Information Security Incidents, considering the stages of identification, protection, detection, response, and recovery.
VII.
Coordinate and preside over the team for the detection and response to Information Security Incidents within the collective financing institution.
VIII.
Inform the Administrative Body or, if it has an audit committee and a risk committee, at its next immediate session, as applicable, upon verification of the Information Security Incident, regarding the actions taken and the follow-up on measures to prevent or avoid the recurrence of said incidents.
IX.
Propose and coordinate training programs directed at all personnel, as well as awareness programs regarding information security towards Clients, and verify their effectiveness.
X.
Present monthly to the General Manager or, if applicable, to the sole administrator, the management report on information security. This report must be submitted to the audit committee and the risk committee or, in the absence of these, to the board of directors of the collective financing institution.
XI.
Consider, at least, the risk indicators in information security established in Annex 13 of these provisions, and report the result of the evaluation of said indicators to the Administrative Body, and if applicable, to the audit committee or risk committee.
XII.
Be responsible for the implementation of the regulation that, in matters of information security, is issued by other Financial Authorities.
XIII.
Respond to requirements formulated by the authorities and within the collective financing institution in matters of information security.
Collective financing institutions must ensure that the Chief Information Security Officer has access to the records of persons who have access to information related to the operations in which the collective financing institution itself intervenes, including those located abroad and of Users of the Technological Infrastructure who have high privileges, such as administration of operating systems, databases, and applications, as well as their service providers.
Collective financing institutions that belong to a financial group subject to the supervision of the CNBV, or that are part of Consortia or Business Groups that have a financial entity subject to the supervision of the CNBV itself, may assign the functions of the Chief Information Security Officer to the person performing such activities in the financial entity supervised by the CNBV, provided that such person complies with what is established in Article 65 of these provisions.
Article 67.- When an Information Security Event or Information Security Incident occurs in: (i) the components of the Technological Infrastructure of the collective financing institution; (ii) the channels for attention to Clients, such as Electronic Media, or (iii) the technological infrastructure of any third party that affects the operation or the Technological Infrastructure of the collective financing institution, the General Manager or, if applicable, the sole administrator must:
I.
Provide for what is necessary to make the CNBV aware, immediately, of Information Security Incidents, by email sent to the account Ciberseguridad-CNBV@cnbv.gob.mx or through other means indicated by the CNBV itself.
In said notification, at least the date and time of start of the Information Security Incident in question must be indicated, and if applicable, the indication of whether it continues or has concluded and its duration; a description of said event or incident, as well as an initial assessment of the impact or gravity.
Additionally, collective financing institutions must send via email to the CNBV, to the account Ciberseguridad-CNBV@cnbv.gob.mx or through other means indicated by the CNBV itself, within five business days following the identification of the Information Security Incident in question, the information contained in Annexes 11 and 12 of these provisions.
In the case of Information Security Events, they must be reported through the means indicated in the first paragraph of this subsection only those that, according to the policies and procedures established by the collective financing institution itself, are qualified as relevant due to having potential impact on the collective financing institution, its Clients, counterparties, suppliers, or other entities in the financial system, in addition to those related to Sensitive Information, images of official identification, and biometric information of Clients. This report must only contain the date and time of start, as well as the description of the event in question.
II.
Carry out an immediate investigation into the causes that generated the Information Security Incident and establish a work plan that describes the actions to be implemented to eliminate or mitigate the risks and vulnerabilities that gave rise to said incident. This plan must indicate, at least, the personnel responsible for its design, implementation, execution, and follow-up, deadlines for its execution, as well as the technical, material, and human resources, and send it to the CNBV within a period not exceeding fifteen business days after the Information Security Incident concluded.
When the Information Security Incident refers to the fact that Sensitive Information in the custody of the collective financing institution or third parties providing services to it, was extracted, lost, deleted, altered, or if collective financing institutions suspect the commission of any act involving unauthorized access to said information, the General Manager or, if applicable, the sole administrator or the person designated by any of these, must notify the Clients of the possible loss, extraction, alteration, loss, or unauthorized access to their information, within the following forty-eight hours after the Information Security Incident occurred or after it was known, through the notification means that the Client has indicated for such effect, in order to prevent them from the risks derived from the misuse of the information that has been extracted, lost, deleted, or altered, informing them of the measures they must take and, if applicable, effecting the replacement of the corresponding disposal means or the substitution of necessary Authentication Factors. The evidence of this notification must be included in the result of the investigation referred to in the previous paragraph.
Article 68.- Collective financing institutions must keep a record in databases of Information Security Events qualified as relevant, Information Security Incidents, failures or vulnerabilities detected in the Technological Infrastructure that includes, at least, information related to the detection of failures, operational errors, attempts at computer attacks and those effectively carried out, as well as loss, extraction, alteration, loss, or misuse of information of Users of the Technological Infrastructure, where the date of the event and a brief description of it, its duration, service or channel affected, Clients affected and amounts, as well as the corrective measures implemented are contemplated.
The information of the Information Security Events qualified as relevant and Information Security Incidents referred to in this article must be backed up in the means that collective financing institutions determine and be preserved for, at least, ten years.
Chapter VII
On the use of electronic media
Article 69.- Collective financing institutions, for the use of Electronic Media, will make known to their Clients, at least the following:
I.
The Operations and services that can be performed.
II.
The identification and Authentication mechanisms and procedures.
III.
The responsibilities of the Client and the collective financing institution regarding the use of the corresponding Electronic Medium.
IV.
The mechanisms and procedures for the notification of Operations carried out and services provided by collective financing institutions.
V.
The limits of the amounts of Operations, without exceeding those established in Articles 49 and 50 of these provisions.
VI.
The inherent risks, terms and conditions for the use of the Electronic Medium in question, as well as suggestions to avoid the misuse of Authentication data to prevent the performance of irregular or illegal operations that go to the detriment of the patrimony of Clients and collective financing institutions.
VII.
The mechanisms and procedures that the collective financing institution will make available to Clients to address clarifications related to Operations and services.
VIII.
The notification procedures and terms and conditions for the acceptance, by Clients, of modifications to the conditions indicated in the subsections above of this article.
Article 70.- Collective financing institutions, to allow the start of a Session, will request and validate at least the following:
I.
The Client Identifier, and
II.
An Authentication Factor referred to in Article 72 of these provisions.
The Client Identifier must be unique for each Client and will allow collective financing institutions to identify all Operations performed by the Client themselves.
Article 71.- Collective financing institutions, in the use of the Client Identifier and Authentication Factors, will comply, at least, with the following:
I.
Have the necessary mechanisms to prevent the reading on the screen of the Access Device of the identification and Authentication information provided by the Client.
II.
Have procedures that ensure that, in the generation, delivery, storage, unlocking, and restoration of Authentication Factors, only the Client receives, activates, knows, unlocks, and restores them.
III.
Ensure that when there is more than one Authentication Factor, they are independent, that is, that the compromise of one does not compromise the reliability of the others.
IV.
Have procedures to restore a blocked Password, in which the identity of the Client is identified without compromising their Sensitive Information.
V.
Have procedures to invalidate Authentication Factors and the Client Identifier to prevent their use in the corresponding Electronic Medium when a Client ceases to be one.
Article 72.- Collective financing institutions must use Authentication Factors to verify the identity of their Clients and their authority to perform Operations through the Electronic Medium in question. Said Authentication Factors must be any of the following:
I.
Information such as Passwords and Personal Identification Numbers (PINs), which collective financing institutions provide to the Client or allow this to generate and which only the latter knows to enter the Platform and start the Session in question and which must have the following characteristics:
a)
Its length must be at least six characters and include alphanumeric and special characters, when the Access Device allows it.
b)
Under no circumstances may the following information be used as such:
i.
The Client Identifier.
ii.
The name of the collective financing institution.
iii.
More than three identical characters in a consecutive manner.
iv.
More than three numerical and alphabetic characters in a sequential manner.
Collective financing institutions will allow the Client to change their Passwords, Personal Identification Numbers (PINs), and other static Authentication information, when the latter so requires, under the terms provided in these provisions.
Regarding Passwords defined or generated by collective financing institutions during their restoration, the institutions themselves must provide mechanisms and procedures by means of which the Client must modify them immediately after starting the corresponding Session and prior to the performance of any Operation, validating that the Passwords are different from those defined by the collective financing institutions themselves.
II.
Information contained, received, or generated by electronic means or devices that only the Client possesses, including that obtained or received by devices or applications generating one-time passwords (OTP, one time password by its English acronym), said means or devices must be provided, validated, and registered by collective financing institutions for their Clients and the information contained or generated by them may be provided, among other formats, in quick response codes (QR, quick response by its English acronym). In any case, the following characteristics must be met:
a)
Have properties that prevent their duplication or alteration.
b)
Be dynamic information that cannot be used more than once.
c)
Have a validity that cannot exceed two minutes.
d)
Not be known in advance by its generation and use by officials, employees, representatives of the collective financing institution, or third parties.
Collective financing institutions may provide their Clients with means or devices that generate one-time passwords, which use information from the Destination Account, by capturing data, so that said Password can only be used for the requested Operation. In this case, what is provided in subsection c) of this subsection will not apply.
III.
Information derived from physical characteristics, such as fingerprints, hand geometry, patterns in iris or retina, and facial recognition. For the use of this information, prior authorization from the CNBV must be obtained.
Collective financing institutions that use this information as an Authentication Factor must ensure that the biometric data of their employees, executives, or officials are not used in substitution of the Client's.
Article 73.- Collective financing institutions may request the CNBV to approve Authentication Factors with characteristics different from those indicated in Article 72, subsections I and II of these provisions or in the use of the information indicated in subsection III of said article, provided they prove that the technology used, in the judgment of the CNBV itself, is reliable to authenticate their Clients.
The request to obtain CNBV approval, as appropriate, must contain the following:
I.
The detailed description of the processes related to the use of the technology used.
II.
The description of its technical and functional specifications, and if applicable, the certifications it has.
III.
The evidence of the approval of the use of the technology by the Administrative Body.
Article 74.- Collective financing institutions must establish mechanisms and procedures so that their Clients can verify the authenticity of the collective financing institutions themselves at the start of a Session, subject to the following:
I.
Provide their Clients with personalized information so that they can verify, before entering all identification and Authentication elements, that it is effectively their Platform on which the Session will be started. For this, collective financing institutions must use at least one of the following:
a)
Information that the Client knows or has provided to the collective financing institution, or that they have indicated for this purpose, such as name, alias, images, among others.
b)
Information that the Client can verify through a device or Electronic Medium provided by the collective financing institution for this purpose.
II.
Once the Client verifies that it is the collective financing institution and starts the Session, it must provide in a prominent and visible manner to the Client, at least the following information:
a)
Date and time of entry to their last Session, and
b)
First and last name of the Client.
Article 75.- Collective financing institutions must provide for what is necessary so that, once the Client is authenticated in the corresponding Electronic Medium, the Session cannot be used by a third party. For the purposes of the above, collective financing institutions will establish, at least, the following mechanisms:
I.
Terminate the Session immediately and automatically and inform the Client of the reason in any of the following cases:
a)
When there is inactivity for more than five minutes.
b)
When, during a Session, the crowdfunding institution identifies relevant changes in communication parameters, such as identification of the Access Device, range of communication protocol addresses, geographic location, among others.
II.
Prevent simultaneous access on the same Electronic Medium, by using the same Client Identifier and inform the Client thereof.
III.
In the event that crowdfunding institutions offer third-party services via links, they must inform their Clients that, upon entering said services, they will be redirected to another link whose security does not depend on nor is the responsibility of said crowdfunding institution.
Article 76.- Crowdfunding institutions, for the execution of Operations, will request from their Clients a second Authentication Factor from those established in Article 72 of these provisions, additional and different from the one used to initiate the Session and on each occasion when any of the following operations are intended to be performed:
I.
Instructions to make investment commitments or withdraw their resources.
II.
Registration or modification of Destination Accounts for the service in question.
III.
Change and Unblocking of Passwords or Personal Identification Numbers (PIN).
IV.
Registration and modification of the notification medium referred to in Article 79 of these provisions.
V.
Inquiries into account statements of one or more periods that allow obtaining information related to the Client and their Operations. It will not be necessary to use the aforementioned second factor for the case of account statement inquiries, provided that the Client has initiated their Session with an Authentication Factor as referred to in fractions II and III of Article 72 of these provisions.
Crowdfunding institutions, when agreeing with their Clients that account statement inquiries be made via email, the information transmitted must be done in an Encrypted manner or with mechanisms that prevent unauthorized third parties from reading it, and for the Client to have access to said information, they will require an Authentication Factor from those established in fractions II and III referred to in Article 72 of these provisions.
Article 77.- Crowdfunding institutions that offer services to their Clients through telephone call centers, electronic messaging channels, or automated agents, may identify their Clients and verify their identity through questionnaires, in which case they must observe the following:
I.
They must request data that the Client knows and that crowdfunding institutions can validate, maintaining the due confidentiality of said information.
II.
Have procedures to conduct random questionnaires in an automated manner or remotely by operators, in the latter case, preventing them from being used at their discretion.
III.
Define a set of open-ended questions in questionnaires of at least three questions, and in the event that the answer to one of them is incorrect, an additional question may be formulated. In no case can the answers to these questions be data displayed on the Electronic Medium or found in printed or electronic communications sent by crowdfunding institutions to their Clients.
IV.
Validate the answers provided by their Clients through computer tools, without the operator being able to consult or access the Client's Authentication data.
Crowdfunding institutions may use questionnaires to unblock Authentication Factors that have previously been Blocked in the cases contemplated in Article 80 of these provisions.
In the event of asking Clients secret questions, the answers to which have been previously provided by the Client, these will be stored in Encrypted form. For the purposes of the present paragraph, a secret question shall be understood as the questioning defined by the Client or the crowdfunding institution, regarding which information is generated as a response.
Each secret question defined may only be used once.
Article 78.- Crowdfunding institutions must request that their Clients confirm the Operation and its characteristics, prior to its execution, making the information explicit to give certainty to the Client of the Operation being performed.
Regarding the automatic investments referred to in Article 54 of these provisions, the confirmation mentioned in the previous paragraph will only be required to contract said service.
Article 79.- Crowdfunding institutions will immediately notify their Clients, through the communication media made available to them, such as mobile phone number or email address, which they have chosen for this purpose, regarding the execution of Operations. For the change of notification medium, a notice must be sent to both the previous and the new medium.
Article 80.- Crowdfunding institutions will establish automatic processes and mechanisms to Block the Authentication Factors, at least for the following cases:
I.
When an attempt is made to enter the Electronic Medium in question using incorrect Authentication information. In no case can failed access attempts exceed three consecutive times; once the established number of attempts is reached, automatic Blocking must be generated.
II.
When the Client does not access the Electronic Medium in question, for a period determined by each crowdfunding institution in its operational policies. In no case, said period may be greater than one year.
Article 81.- Crowdfunding institutions, in the management of Authentication Factors, will be subject to the following:
I.
They must maintain procedures that provide security for the information contained in the Authentication devices in their custody, as well as in the distribution, assignment, and replacement of said Authentication Factors to their Clients.
II.
They are prohibited from having mechanisms, algorithms, or procedures that allow them to know, recover, or decrypt the values of any information related to Authentication.
III.
They are prohibited from requesting from their Clients, through their officials, employees, or representatives, partial or complete information of the Authentication Factors referred to in Article 72 of these provisions.
IV.
In the event of obtaining approval for the use of the Authentication Factors from fraction III of Article 72 of these provisions, they must incorporate into the Authentication information obtained by biometric devices, elements that ensure that said information is different each time it is generated in order to constitute One-Time Passwords, which in no case can be used again or duplicated with that of another Client.
Article 82.- Crowdfunding institutions will foresee procedures and mechanisms for their Clients to report the theft or loss of their identification and Authentication information, which allow the crowdfunding institutions themselves to prevent their improper use.
Likewise, they must establish policies that define the responsibilities of both the Client and the crowdfunding institution, regarding Operations that have been carried out prior to a report of theft or loss of their identification or Authentication information.
Each report of theft or loss will generate a file number that will be made known to the Client and that will allow them to follow up on said report.
Article 83.- Crowdfunding institutions that have remote channels such as telephone call centers or electronic messaging channels, must:
I.
Maintain physical or logical security controls or both, as appropriate, in the Technological Infrastructure of the remote channels, including the recording devices of communications and the storage and backup media thereof, which protect at all times the confidentiality and integrity of the information provided by their Clients.
II.
Delimit the functions of the operators, so that they are independent with respect to other operational functions.
III.
Prevent operators from having mechanisms that allow them to register information provided by their Clients on media other than those provided by the crowdfunding institution itself for Authentication purposes. To this end, crowdfunding institutions must ensure that persons who have access to remote channels do not use electronic equipment or other devices, external email services, instant messaging programs, computer programs, or through these have access to unauthorized Internet pages, or to any other mechanism that allows them to copy, send, or extract by any means or technology information related to Clients.
IV.
Register in logs, the accesses and activities that operators of telephone call centers or electronic messaging channels perform with Clients, as well as preserve the logs.
What is established in this article must be provided for in the information security manuals established by crowdfunding institutions referred to in Article 63, last paragraph of these provisions.
Article 84.- Crowdfunding institutions must have trained personnel or technical and operational support infrastructure, to attend to and follow up on service requests that their Clients have in the use of Electronic Media.
Chapter VIII
On the contracting of services with third parties
Article 85.- Crowdfunding institutions will only require authorization from the CNBV to contract with third parties the provision of services that have the following characteristics:
I.
Those that imply the transmission, storage, processing, safeguarding, or custody of Sensitive Information, images of official identifications, or biometric information of Clients, provided that the contracted third party has access privileges to know said information or security configuration information, or access control administration.
II.
Those that perform processes abroad related to accounting or treasury, as well as with the recording of transactional movements of Clients.
Crowdfunding institutions, both in the contracting of the services referred to in the aforementioned fractions and in any other, must ensure at all times that the third parties providing them services maintain the due confidentiality of information regarding Operations carried out with their Clients, as well as regarding the latter, in case of having access to it.
The general manager or, in their case, the sole administrator of the crowdfunding institution will be responsible for approving the contracting of third parties.
Crowdfunding institutions must maintain the data of the third parties providing them services, in the registry referred to in Article 88 of these provisions.
Article 86.- Crowdfunding institutions must accompany the authorization request referred to in the previous article, with the following:
I.
The detailed description and flowcharts of the processes of the services to be contracted, considering the activities to be performed by the crowdfunding institution, as well as by the service provider; the areas of the crowdfunding institution itself and the third party that participate in the service flow; name, description, and functionality of the systems that, in their case, will be contracted for the provision of the service, or the systems of the crowdfunding institution that will be used by the respective provider.
II.
The draft service provision contract, in which the probable date of its celebration, the rights and obligations of the crowdfunding institution and the third party must be indicated, including the determination regarding intellectual property rights regarding the designs, developments, or processes used for the provision of the service. Said draft contract must be presented in Spanish.
Likewise, it must be recorded within the contract, the express acceptance by the third party of the following obligations:
a)
Comply with what is provided in Article 54 of the Law.
b)
Deliver in the development of an audit and at the request of the crowdfunding institution, to the independent external auditor of the crowdfunding institution itself and to the CNBV, the books, systems, records, manuals, and documents in general, related to the provision of the service in question. Likewise, allow the independent external auditor or CNBV personnel access to their offices and facilities in general, related to the provision of the service in question.
c)
Inform the crowdfunding institution regarding any modification to its corporate purpose or any other change that could affect the provision of the service subject to contracting, with at least thirty days' advance notice before such modification or change occurs.
d)
Maintain confidentiality regarding information that has been received, transmitted, processed, or stored during the provision of the services. Likewise, accept that said information can only be used and exploited for the purposes agreed upon in the provision of the service.
e)
In the event that the third party subcontracts the partial or total provision of any of the services provided to crowdfunding institutions, the obligation to notify the institution itself regarding said subcontracting; likewise, that it will establish mechanisms so that the subcontractor complies with the obligations agreed upon and provides information for the purposes of Article 88 of these provisions.
f)
Comply with the terms, conditions, and processes so that the third party guarantees to the crowdfunding institution the transfer, return, and secure elimination of the information subject to the contracted service when it ceases to provide it.
g)
Maintain complete audit records that include detailed information of accesses or access attempts and the operation or activity performed by Users of the Technological Infrastructure. Said records must be available to authorized personnel of the crowdfunding institution.
h)
Have access controls to information according to the access levels and profiles determined by the crowdfunding institution.
i)
Allow the crowdfunding institution to perform the security reviews indicated in Article 64, fractions II, III, and IV of these provisions on the contracted services or provide evidence of the performance of these reviews.
III.
The following documentation regarding the Technological Infrastructure:
a)
The description of the communication links used by the crowdfunding institution to connect with the service provider, including the provider's name, bandwidth, and type of service provided, among others.
b)
A telecommunications diagram showing the existing connection between each of the participants in the provision of the service (providers, data centers, crowdfunding institution, among others), including redundancy schemes.
c)
The complete address of the place where each of the services will be performed, as well as the primary and secondary data centers where information will be stored and processed. In the event that the indicated place is located in national territory, it must include, at least, street, exterior and interior number, neighborhood, borough or municipality, postal code, and federative entity. Regarding a site located abroad, similar data must be included that allow locating the indicated place with certainty. Regarding Cloud Computing services, only what is indicated in subsection b) of fraction VI of this article must be provided.
d)
In their case, the interrelation scheme of applications or systems subject to contracting, including the systems of the crowdfunding institution itself.
e)
The mechanisms for continuity of the contracted service.
IV.
The mechanisms that will allow the crowdfunding institution to maintain in its facilities the detailed records of all Operations performed, as well as its accounting records at daily closing. Said records must be maintained in a format that allows their consultation and use, regardless of whether the service contracted with the third party is not available.
V.
When the third party has access privileges to images of official identifications or biometric information of Clients, present evidence of the controls it will maintain to guarantee the confidentiality, integrity, and availability of this information.
VI.
Regarding the contracting of Cloud Computing services, additionally describe the following:
a)
Type of cloud, whether public, private, or hybrid.
b)
Specific regions where information will be stored and processed.
c)
In public cloud or virtualization schemes in shared infrastructure with other clients, the description of the control mechanisms that will be used to guarantee the confidentiality, integrity, and availability of Sensitive Information.
VII.
Description of the mechanisms to monitor the performance of the contracted third party and the compliance of its contractual obligations, including at least, those provided in these provisions.
VIII.
Plans to evaluate and report to the Governing Body or, in its case, to the audit committee of the crowdfunding institution, according to the importance of the contracted service, the performance of the third party and the compliance with applicable regulation related to said service.
IX.
Evidence that allows verifying that third parties have and implement data protection and information confidentiality policies that allow the crowdfunding institution to comply with the legal provisions governing it in this matter.
Regarding services that are processed, provided, or executed totally or partially outside national territory, crowdfunding institutions must accompany the documentation that accredits that the third parties reside in countries whose internal law provides protection for personal data, safeguarding their due confidentiality, or that said countries maintain international agreements signed with Mexico in this matter or of information exchange between supervisory bodies, regarding Financial Entities.
The CNBV will have a period of twenty-five business days to resolve regarding the authorization request referred to in this article; once this period has elapsed without any pronouncement, the resolution will be understood as positive. Any request for additional information made by the CNBV will interrupt the period indicated in this paragraph.
Article 87.- Crowdfunding institutions for the contracting of services with third parties that are subject to authorization by the CNBV in terms of these provisions, as well as those related to operational processes and with administration of databases and computer systems, must comply with the following:
I.
Regarding third parties that provide services related to operational processes and with administration of databases and computer systems, agree on what is stated in fraction II of Article 86 and preserve the respective contract.
II.
Perform, at least annually, internal or external audits on the contracted service or have evidence that the contracted third party carries them out.
III.
Maintain in their main offices, at least, the documentation and information related to evaluations, audit results, and, in their case, remediation plans that correspond, as well as performance reports of contracted third parties, including documentation regarding compliance with what is stated in fraction I of this article.
IV.
Update the description or respective documentation when there are modifications that are considered to have a relevant impact on the service provided or that are related to the systems, equipment, and applications subject to contracting or their technical characteristics.
V.
Regarding Technological Infrastructure and information security, in addition to the information determined in Article 86, fraction III, subsections b) and d) of these provisions, have the following documentation:
a)
The description of the technical characteristics of the systems, equipment, and applications subject to contracting that contains at least what is indicated in Annex 14 of these provisions.
b)
That in which the mechanisms to ensure the transmission and storage of information in Encrypted form are detailed, in their case, including the version of Encryption protocols and security components in the Technological Infrastructure.
c)
That which contains the detail of the type of information of the crowdfunding institution and Clients specifying, in their case, the type of Sensitive Information that will be stored by the third party in its equipment or facilities, or to which it may have access, in their case.
d)
The description of the control and monitoring mechanisms for access to computer systems and Sensitive Information transmitted, stored, processed, safeguarded, or custodied in said systems, as well as of the logs, databases, and security configurations established for this purpose.
e)
The evidence of the controls and of the control mechanisms referred to in fractions V and VI, subsection c) of Article 86 of these provisions.
VI.
Have the evidence referred to in fraction IX of the previous Article 86.
The general manager or, as applicable, the sole administrator shall be responsible for the implementation of the evaluations and remediation plans referred to in fraction III of this article.
Article 88.- Collective financing institutions must maintain a registry of all service providers, including those subcontracted by them, which must include, at least, the following information:
I. Name, corporate name, or business name of the service provider. II. Name of the legal representative of the service provider. III. Description of the service contracted with the third party, including the data or information that, as applicable, are stored, processed, or transmitted by this party. IV. As applicable, information on the systems supporting the service contracted with the third party, which must include at least the name, version, and function or purpose. V. As applicable, interfaces with other systems and the purpose of these, including the detail of the information exchanged. VI. Location where the service is performed and where the personnel responsible for carrying it out are located. VII. As applicable, location of the main data center where the processing equipment of the contracted system is located. VIII. As applicable, location of the alternate data center where the processing equipment is located, in the event of recovery of the contracted service. IX. As applicable, number and date of the official letter with which the CNBV granted the authorization.
Collective financing institutions must keep the registry referred to in this article updated.
Chapter IX Of the disclosure of information
First Section Of the disclosure of information in the publication of applications and projects
Article 89.- Collective financing institutions will include in the publications regarding the financing offers they make on their Platforms, information regarding the general analysis performed and any other variable that proves useful for Investors to make an informed investment decision.
Article 90.- Collective financing institutions that carry out Collective Financing Operations of Personal Loan Debt between Persons must disclose, for each financing application, the following information:
I. Amount of financing requested. II. Term of the Collective Financing Application. III. Description of the destination of the financing. IV. Term of the collective financing. V. Payment schedule of principal and interest, as well as their amount. VI. Ordinary interest rates and, as applicable, default interest rates. VII. As applicable, guarantees. VIII. Risk rating determined in accordance with the risk evaluation methodology defined by the collective financing institution, accompanied by a simple explanation of how to interpret it. IX. Schemes to share with Investors the risks of the Collective financing Operations. X. Data regarding the Applicant that are important for the decision-making of potential Investors, such as their age, sex, occupation, residence, and sources of income.
Article 91.- Collective financing institutions that carry out Collective Financing Operations of Business Loan Debt between Persons and for Real Estate Development must disclose for each Application or financing project, in addition to fractions I to IX of Article 90 above, the information corresponding to the type of collective financing in question, as detailed in Annex 15 of these provisions.
Article 92.- Collective financing institutions that carry out Collective Financing Operations of Capital must disclose for each project they promote on their Platform, the following information, as detailed in Annex 16 of these provisions:
I. Amount of financing requested. II. Term of the Collective Financing Application. III. Description of the ultimate purpose of the resources. IV. Description of the titles representing social capital and the rights acquired by the Investor, as well as the manner in which they will be compensated for the contributions they make. V. Risk rating determined in accordance with the risk evaluation methodology defined by the collective financing institution, accompanied by a simple explanation of how to interpret it. VI. Name and business activity of the legal entity, legal nature, date of incorporation, address of main offices, and, as applicable, website. VII. Description of the main elements that make up the business model or plan of the legal entity. VIII. Description of the dividend policy, as well as the risk factors that may significantly affect the performance and profitability of the legal entity. IX. Name of the administrator or administrators and, as applicable, the general manager, as well as the persons who exercise Control of the legal entity. X. Description of the financial situation, at the time of the financing application, of the legal entity considering aspects such as profitability, leverage, liquidity, and operational efficiency. At least the amount of equity capital, the main items of assets and liabilities, as well as the result of the previous fiscal year must be included. In the case of newly created companies, such situation must be stated and, as applicable, information regarding the business history or technical knowledge of the administrators or executors of the project, as well as the financial projections, if any, must be included. XI. The price of the titles representing the social capital of the legal entity offered, including a description of the method of determination and any limitation that exists for their acquisition. XII. As applicable, schemes to share with Investors the risks of the Collective financing Operations.
Article 93.- Collective financing institutions that carry out Collective Financing Operations of Co-ownership or Royalties must disclose, for each project they promote on their Platform, the following information:
I. Amount of financing requested. II. Term of the Collective Financing Application. III. Description of the destination of the financing including, as applicable, a description of the current state or financial situation of the project to be financed, as well as a model or business or investment plan for the resources and the manner of achieving the stated objectives, as well as the indicators on which the progress of the project or the achievement of results will be measured. IV. Explanation of the participation that the Investor will have in the present or future assets, income, profits, royalties, or, as applicable, losses derived from the project to be financed. V. Risk rating determined in accordance with the risk evaluation methodology defined by the collective financing institution, accompanied by a simple explanation of how to interpret it. VI. Information regarding the Applicant: a) In the case of natural persons, the aspects indicated in fraction X of Article 90 of these provisions must be disclosed, as well as a description of their productive activities. b) In the case of legal entities, the aspects indicated in fractions VI, VII, IX, and X of the previous Article 92 must be disclosed, to the extent applicable. c) Information regarding the strategic participants that the Applicant or the person responsible for the execution of the project may have, indicating the relationship that those have with the latter, as well as a description of the scope of their participation or contributions to the project. VII. As applicable, schemes to share with Investors the risks of the Collective financing Operations.
Second Section Of the disclosure of information regarding the payment behavior and performance of the Applicant or project
Article 94.- Collective financing institutions on whose Platforms Business Loan Debt Operations between Persons, Personal Loan Operations between Persons, and Real Estate Development Operations are carried out, must disclose to the Investors who are part of said Operations, the following information:
I. Indicators of the annualized return obtained by participating in the financing, including a description of its method of calculation. II. Payment and default indicators, indicating at minimum, if the credit is current in its payments of principal and interest, or in its defect, how many payments it has historically defaulted on and the total amount owed at the time of reporting, broken down by principal and financial accessories. For the purposes of the foregoing, default shall be understood as the event that occurs when the payment made by the Applicant is not enough to cover the payment that was committed according to the payment schedule programmed and agreed upon when the Operation was agreed. III. As applicable, update of the indicators on which it was defined that the progress of the financed project or the achievement of results would be measured.
Collective financing institutions must update the information referred to in fractions I and II above in accordance with the payment frequency defined in each Operation agreed.
Article 95.- Collective financing institutions that carry out Collective Financing Operations of Capital must make available to the Investors who have participated in the Operation in question, at least for the two years following the completion of the Operation, the following data:
I. The annual information of the administrators of the financed legal entity referred to in Article 172 of the General Law of Commercial Societies or equivalent. II. The risks and challenges faced by the financed legal entity. III. Financial indicators at the close of the reported annual fiscal year compared to the previous period, including a brief description of the method of calculation and its interpretation according to the following: a) Profitability, which is the result of dividing annual net profits by average capital to determine return on equity (ROE) or, the result of dividing annual net profits by average assets to determine return on assets (ROA). b) Leverage, which is the result of dividing total liabilities by total assets. c) Liquidity, which is the result of dividing liquid assets by total assets. Liquid assets are the sum of cash and bank accounts. d) Operational efficiency, which is the result of dividing annual administrative expenses by total annual revenues.
The data referred to in the fractions above must be made available through their Platform no later than April 30 of each year. Once the disclosure period referred to in the previous paragraph concludes, the collective financing institution must inform investors of such circumstance.
In the case of collective financing institutions that are also Investors through the implementation of schemes to share risks referred to in Article 21, second paragraph of the Law, the provisions of this article shall be applicable for the entire time that the institution is an Investor.
Article 96.- Collective financing institutions that carry out Collective Financing Operations of Co-ownership or Royalties must make available to the Investors who have participated in the Operation in question, at least for the two years following the completion of the Operation, a report on the business progress or project advancement, as well as disclose, at least annually, the indicators referred to in Article 94, fraction III of these provisions.
Third Section Of the disclosure of information to the general public
Article 97.- Collective financing institutions must maintain in a site of easy access for public consultation, within the Platforms they use to operate with their Clients, the aggregated information by type of financing granted in accordance with what is indicated in Annex 17 of these provisions.
FOURTH TITLE Of regulatory reports
Chapter I Of reports in general
Article 98.- Collective financing institutions must provide to the CNBV, with the frequency established in Article 99 below, the information attached to these provisions as Annex 18, which is identified with the series and reports listed below:
Series R01 Minimum Catalog. A-0112 Minimum Catalog. Series R08 Bank loans and from other organizations. D-0842 Disaggregated loans obtained. Series R10 Reclassifications. A-10112 Reclassifications in the statement of financial position. A-10122 Reclassifications in the statement of comprehensive income. Series R13 Financial Statements. A-13112 Statement of changes in equity. A-13162 Statement of cash flows. B-13212 Statement of financial position. B-13222 Statement of comprehensive income. Series R27 Claims. A-2702 Claims.
Article 99.- Collective financing institutions will present the information referred to in the previous Article 98, with the frequency indicated below:
I. Monthly, the information related to series R01, R08, R10, and R13, exclusively with respect to reports B-13212 and B-13222, which must be provided within the month immediately following the close of the calendar month being reported. II. Quarterly, the Information related to series R13, exclusively with respect to reports A-13112 and A-13162, and R27, which must be provided within the month immediately following the close of the calendar quarter being reported.
Article 100.- Payment fund institutions must provide to the CNBV, with the frequency established in Article 101 below, the information attached to these provisions as Annex 19, which is identified with the series and reports listed below:
Series R01 Minimum Catalog. A-0111 Minimum Catalog. Series R08 Bank loans and from other organizations. D-0843 Disaggregated loans obtained. Series R10 Reclassifications. A-10111 Reclassifications in the statement of financial position. A-10121 Reclassifications in the statement of comprehensive income. Series R13 Financial Statements. A-13111 Statement of changes in equity. A-13161 Statement of cash flows. B-13211 Statement of financial position. B-13221 Statement of comprehensive income. Series R26 Commissioner information. A-2610 Registrations and cancellations of commissioner administrators. A-2611 Disaggregated registrations and cancellations of commissioners. B-2612 Disaggregated registrations and cancellations of commissioner modules or establishments. C-2613 Disaggregated tracking of commissioner operations. Series R27 Claims. A-2701 Claims.
Article 101.- Payment fund institutions will present the information referred to in the previous Article 100, with the frequency indicated below:
I. Monthly, the Information related to series R01, R08, R10, R13, exclusively with respect to reports B-13211 and B-13221 and R26, exclusively with respect to report C-2613, which must be provided within the month immediately following the close of the calendar month being reported. II. Quarterly, the Information related to series R13, exclusively with respect to reports A-13111 and A-13161, and R27, which must be provided within the calendar month immediately following the close of the quarter being reported. III. By event, the information related to series R26, exclusively with respect to reports A-2610, A-2611, and B-2612, provided during the day of occurrence of the event individually or by the close of the day of occurrence of the event the total of the records.
Article 102.- FTIs will require prior authorization from the CNBV for the opening of new concepts or levels that are not contemplated in the series corresponding exclusively for the sending of information of the new operations that are authorized to them for this purpose by the Secretariat, in terms of the relevant legislation, for which they will request said authorization through a free-form letter within fifteen business days following the authorization made by the Secretariat. Likewise, in the event that changes in applicable regulations require establishing additional concepts or levels to those provided for in these provisions, the CNBV will inform the FTIs of the opening of the respective new concepts or levels.
In the two cases provided for in the previous paragraph, the CNBV will notify through the SITI the mechanism for recording and sending the corresponding information.
Chapter II Of the delivery means
Article 103.- FTIs, unless otherwise expressly provided, must send to the CNBV the information mentioned in this title, by transmitting it electronically using the SITI. In the event that there is no information for any report, institutions must send an empty submission, a functionality that is available in said system.
The information must comply with the validations established in the SITI, as well as the quality standards indicated by the CNBV through said system, and there must be consistency between the information that Institutions include in one or more regulatory reports referred to in these provisions, even if they are at a different level of integration. Likewise, the information must be sent only once and will be received assuming it meets all required characteristics, for which it cannot be modified, with the SITI generating an electronic receipt.
Once the information is received, it will be reviewed and if it does not meet the required quality and characteristics or is presented incompletely, the obligation to present it will be considered unfulfilled, and consequently, the corresponding sanctions will be imposed.
FTIs must send electronically to the address "cesiti@cnbv.gob.mx" the name of the person responsible for the quality and sending of the information referred to in this title, in the manner indicated in Annex 20 of these provisions. The designation of the person responsible for the quality of the information must fall on executives who are within the two lower hierarchies than the general manager or the sole administrator of the FTI, who have responsibility for the handling of the information. Likewise, they may designate more than one person as responsible for sending the information, depending on the type of information in question.
FTIs may request new user keys or access to regulatory reports in the SITI, by sending an email to the address "cesiti@cnbv.gob.mx" in the same manner as indicated in Annex 20.
Once the email referred to in this article is sent, the CNBV will notify the FTI by the same means, within five business days following the receipt of the request, the confirmation of the registration of the corresponding responsible person, as well as, as applicable, the access of the users of the requested regulatory reports.
The notification or substitution of any of the persons responsible for the sending and quality of the information referred to in this article, must be notified to the CNBV in the terms mentioned above, within three business days following the date of its designation or substitution.
SECOND ARTICLE.- Article FIFTH Transitory is REFORMED and Article SEVENTH Transitory of the "General Provisions applicable to financial technology institutions" published in the Official Journal of the Federation on September 10, 2018, is REPEALED, to read as follows:
"FIFTH.- Collective financing institutions may consider their Clients as Experienced Investors in terms of Article 2, fraction XXIII, subsection d) of these provisions, if said Clients had carried out Operations through one or more of the persons referred to in the EIGHTH Transitory Provision of the Law to Regulate Financial Technology Institutions."
"SEVENTH.- Repealed."
TRANSITORY PROVISIONS
FIRST.- This Resolution will enter into force the day following its publication in the Official Journal of the Federation.
SECOND.- The Fourth Title added to the General Provisions applicable to financial technology institutions by this Resolution will enter into force on January 1, 2020, so that financial technology institutions will begin to deliver the information referred to in Articles 98 and 100, with the frequency and deadlines established in Articles 99 and 101, respectively, on the dates indicated below, and only for the purposes of the first submission, with the information detailed in each case:
I. Regarding collective financing institutions: a) The information related to the regulatory reports of series R01, R08, R10, and R13, exclusively with respect to reports B-13212 and B-13222, no later than January 31, 2020, with the information covering the period from December 1 to December 31, 2019. b) The information related to the regulatory reports of series R13, exclusively with respect to reports A-13112 and A-13162 and R27, no later than January 31, 2020, with the information covering the period from October 1, 2019, to December 31, 2019. II. Regarding payment fund institutions: a) The information related to the regulatory reports of series R01, R08, R10, and R13, exclusively with respect to reports B-13211 and B-13221, no later than January 31, 2020, with the information covering the period from December 1 to December 31, 2019. b) The information related to the regulatory reports of series R13, exclusively with respect to reports A-13111 and A-13161 and R27, no later than January 31, 2020, with the information covering the period from October 1, 2019, to December 31, 2019. c) The information related to the regulatory report of series R26, on January 2, 2020, with the information as of December 31, 2019.
THIRD.- The obligation provided for in Article 97, which is added to the General Provisions applicable to financial technology institutions by this Resolution, shall enter into force on September 1, 2020.
Respectfully,
Mexico City, March 14, 2019.- The President of the National Banking and Securities Commission, Adalberto Palma Gómez.- Signature.
ANNEX 8
INSTRUCTIONS FOR OBTAINING ELECTRONIC CERTIFICATES OF AWARENESS OF RISKS
A. WARNINGS THAT COLLECTIVE FINANCING INSTITUTIONS MUST DISCLOSE TO INVESTORS REGARDING THE RISKS OF THEIR INVESTMENT
Collective financing institutions must indicate on their Platforms the importance of their Investors reading all information disclosed by the institution itself, regarding each of the financing requests from Applicants or projects in which they are considering investing. Likewise, these institutions must warn on their Platforms that Investors may only invest in published financing requests once they fully understand the risks of their investment, the manner and terms of the Operations they may enter into through the Platform, and that such Operations are consistent with their financial needs.
Collective financing institutions must disclose to Investors, prior to the execution of the contract that allows them to carry out Operations on the Platform in question, warnings regarding the risks to which their investment will be subject, such as the following:
I. The impossibility of disposing of the invested resources at the moment the Investor so requires.
II. The possibility that conditions may not exist for the sale of the rights or titles that document the Operations to take place through the collective financing institution.
III. The possibility of losing all resources invested through the collective financing institution, in the event that the Applicant does not pay the financing or it cannot be recovered.
IV. The possibility of investing, through the collective financing institution, in companies or projects in the formation stage that do not have a proven operational history, potentially losing up to one hundred percent of the investment. Additionally, the possibility of not receiving dividends, income, profits, or royalties, and that, as a result of the participation of more Investors in the company or project in question, corporate rights may be diminished.
V. The possibility that the financial statements of the companies or projects in which investment is made are not audited by an independent external auditor, so the financial information may not reasonably reflect the financial situation of the company or project in question.
VI. The possibility of receiving initial and subsequent limited information compared to what is observed in the securities market, so that, eventually, the Investor may not have sufficient information to make investment decisions.
VII. The prohibition established for collective financing institutions in accordance with what is provided in Article 20 of the Law and the impossibility referred to in Article 11, third paragraph of said legislation.
Each collective financing institution must add warnings regarding any other investment risk it identifies that is not contemplated in the preceding clauses, as well as display each warning with the font size predominantly used on the Platform it employs.
B. FORM FOR OBTAINING THE ELECTRONIC CERTIFICATE OF RISK AWARENESS
Once Investors confirm that they have read the warnings contained in section A above, collective financing institutions must collect, in a form provided by the institution itself, responses regarding the awareness of the risks to which these Investors are exposed by their investment.
The following is an example of the form referred to in the previous paragraph, which must be displayed by collective financing institutions on their Platform.
Yes No
Loss Risk.- Do you understand that these investments are risky and that you may lose all invested money?
Liquidity Risk.- Do you understand that it is possible that you will not be able to cash out your investment prematurely?
Information Risk.- Do you understand that the information the collective financing institution provides regarding the offer and subsequent performance of the Financing Applicants may be limited?
Return Risk.- Do you understand that it is possible that you will not obtain any income or return, such as dividends or interest, from these investments?
Yes No
No Approval.- Do you understand that the published investment offers have not been reviewed or approved in any way by the National Banking and Securities Commission or any other authority?
No Advice.- Do you understand that you will not receive advice on whether the investments are suitable for you?
Yes No
Investment Risks.- Have you read this form and do you understand the risks of carrying out these investments?
Disclosed Information.- Before investing, you must carefully read the information disclosed by each of the Financing Applicants in which you consider making the investment. If you have not read or do not understand this information, you should not invest.
Do you understand that, in addition to the general risks of investment, you must read and understand the information disclosed by the Financing Applicants?
Full Name:
Date of questionnaire application:
Electronic Signature: By clicking the confirmation button, I acknowledge that I am signing this form electronically, producing the same effects that laws grant to a handwritten signature.
Collective financing institutions must formulate the questions of the form they design for this purpose in such a way that they cannot be answered entirely in the negative or positive sense.
When it is evident from any of the responses that the risks are not known, the collective financing institutions must automatically interrupt the contracting process and re-direct the Investor to the screen where the warnings of the general risks of investing in the Applicants or projects that the collective financing institution in question publishes through its Platform are described.
By submitting the responses with their advanced electronic signature or any other form of authentication in accordance with what is provided in Article 56, first paragraph of the Law, Investors will electronically attest that they are aware of the risks associated with their investment in the Applicants or projects that the collective financing institution publishes through its Platform.
Collective financing institutions must retain the original receipt of the electronic risk certificate for a minimum period of ten years, properly archived, either in printed format, or through electronic, optical, or any other technology.
ANNEX 9
FORMAT FOR DECLARATION REGARDING COMPLIANCE WITH THE REQUIREMENTS TO BE CONSIDERED AN EXPERIENCED INVESTOR
I, [NAME OF INTERESTED PARTY], declare that it is my interest to be considered an Experienced Investor under Article 2, clause XXIII, subsection d) of the General Provisions applicable to financial technology institutions, and that I am aware that acting with that status, in addition to the risks inherent to being an investor in a collective financing institution, implies being able to make investment commitments that exceed the percentages established in said provisions and, therefore, I could be concentrating my investment, which increases the risk of losing it.
I understand investment commitment as stated in Article 2, clause IV of those same provisions.
Having recognized the foregoing, I declare that I have carried out operations, as defined in the Law for Regulating Financial Technology Institutions, in collective financing institutions as an investor, whose aggregate amount is greater than the equivalent in national currency to 550,000 UDI's, and that I have at least 12 months of experience carrying them out.
I understand that [NAME OF THE COLLECTIVE FINANCING INSTITUTION IN QUESTION] will require the necessary information and documentation to verify that I meet the preceding condition; and that, if I do not provide it, I will not be considered an Experienced Investor for the purposes of Article 50, clause V of the aforementioned provisions.
NAME OF INTERESTED PARTY
OR LEGAL REPRESENTATIVE
AND SIGNATURE
ANNEX 11
Incidents affecting information security
I. Information of the collective financing institution
a) Name of the collective financing institution.
b) Full name of the Chief Information Security Officer, as well as their phone number and email address.
II. Detailed Information of the Information Security Incident
Description of the Information Security Incident
a) Date and time it occurred
b) Date and time it was detected
c) Duration of the incident
d) Is the information involved in the incident managed by third parties? Yes ( ) No ( )
e) If the answer to subsection d) is affirmative, detail provider data (name, address and contact data, email, phone, among others)
Impact caused by the Security Incident
f) Can the incident cause a monetary loss for Clients or for the collective financing institution itself? Yes ( ) No ( )
g) Is it viable to recover the possible monetary loss directly (own efforts) or indirectly (through insurance)? Yes ( ) No ( )
h) Have other related incidents been identified with the one reported, whether by origin, mode of operation, or impact? Yes ( ) No ( )
i) Indicate, if applicable, the type of information compromised with the Information Security Incident, according to the following tables:
Compromised Client Personal Information
Names Yes ( ) No ( )
Addresses Yes ( ) No ( )
Phone numbers Yes ( ) No ( )
Email addresses Yes ( ) No ( )
Biometric data (fingerprints, iris or retina patterns or facial recognition, among others) Yes ( ) No ( )
Other(s)
Account or Balance Information
Card numbers, or others Yes ( ) No ( )
Account numbers Yes ( ) No ( )
Passwords or identification numbers Yes ( ) No ( )
User identifiers Yes ( ) No ( )
Limits Yes ( ) No ( )
Balances Yes ( ) No ( )
Other(s)
Collective Financing Institution Information
Access keys Yes ( ) No ( )
Security configurations Yes ( ) No ( )
Port or service identification Yes ( ) No ( )
IP addresses of components or services Yes ( ) No ( )
IP addresses of internal components Yes ( ) No ( )
Access to internal network segments Yes ( ) No ( )
Software versions, operating systems, or databases Yes ( ) No ( )
Vulnerability identification Yes ( ) No ( )
Other(s)
III. Classify the reported Information Security Incident based on the following definitions:
a) Unintentional or accidental damage, loss of information, or loss of assets
Improperly shared information Yes ( ) No ( )
Errors or omissions in systems or devices Yes ( ) No ( )
Errors in procedures or controls Yes ( ) No ( )
Unauthorized changes to data Yes ( ) No ( )
Loss of information or devices Yes ( ) No ( )
Other(s):
b) Incidents due to failures or malfunctions
Devices Yes ( ) No ( )
Systems Yes ( ) No ( )
Communications Yes ( ) No ( )
Services Yes ( ) No ( )
Third-party equipment Yes ( ) No ( )
Supply chain Yes ( ) No ( )
Other(s)
c) Incidents due to interruption or lack of inputs
Absence of personnel Yes ( ) No ( )
Strikes Yes ( ) No ( )
Energy Yes ( ) No ( )
Water Yes ( ) No ( )
Telecommunications Yes ( ) No ( )
Other(s)
d) Incidents due to data interception
Espionage Yes ( ) No ( )
Messages Yes ( ) No ( )
Wardriving Yes ( ) No ( )
Man-in-the-middle attacks Yes ( ) No ( )
Session hijacking Yes ( ) No ( )
Sniffers Yes ( ) No ( )
Messaging theft Yes ( ) No ( )
Other(s)
e) Incidents due to malicious activity with the intent to take control, destabilize, or damage a computer system
Identity theft Yes ( ) No ( )
Phishing Yes ( ) No ( )
Denial of service (DOS, DDOS) Yes ( ) No ( )
Malicious code (malware, trojans, worms, code injection, virus, ransomware) Yes ( ) No ( )
Social engineering Yes ( ) No ( )
Certificate violation (site spoofing, false certificates) Yes ( ) No ( )
Hardware manipulation (anonymous proxies, skimmers, sniffers) Yes ( ) No ( )
Information alteration (address spoofing and routing table manipulation, DNS poisoning, configuration alteration) Yes ( ) No ( )
Abuse of audit applications Yes ( ) No ( )
Brute force attacks Yes ( ) No ( )
Abuse of authorizations Yes ( ) No ( )
Organized crime Yes ( ) No ( )
Hacktivists Yes ( ) No ( )
Government or affiliated groups Yes ( ) No ( )
Terrorists Yes ( ) No ( )
Insiders Yes ( ) No ( )
Other(s)
f) Incidents originating from legal aspects
Violation of contractual clauses Yes ( ) No ( )
Violation of confidentiality agreements Yes ( ) No ( )
Adverse decisions (judicial resolutions in the same jurisdiction or others) Yes ( ) No ( )
Other(s)
g) Others (specify)
IV. Classification of the Information Security Incident.
Indicate in the following table the classification in which the incident falls using the concepts from the catalog listed below:
Type
Sub Type
Sub Class of Events
I. Internal Fraud
1.1 Unauthorized Activities.
1.1.1 Undisclosed operations (intentional).
1.1.2 Unauthorized operations (with financial losses).
1.1.3 Incorrect valuation of positions (intentional).
( )
( )
( )
1.2 Internal Theft and Fraud.
1.2.1 Fraud / valueless deposits.
1.2.2 Extortion / embezzlement / theft.
1.2.3 Misappropriation of assets.
1.2.4 Destructive destruction of assets.
1.2.5 Internal Forgery.
1.2.6 Smuggling.
1.2.7 Misappropriation of accounts, identity, among others.
1.2.8 Non-compliance / tax evasion (intentional).
1.2.9 Bribery.
1.2.10 Abuse of insider information (not to the company's benefit).
( )
( )
( )
( )
( )
( )
( )
( )
( )
( )
1.3. System Security.
1.3.1 Violation of security systems.
1.3.2 Damage from cyberattacks.
1.3.3 Theft of information (with financial losses).
1.3.4 Inadequate use of access keys and/or authorization levels.
( )
( )
( )
( )
( )
II. External Fraud
2.1 External Theft and Fraud.
2.1.1 Theft / fraud / extortion / bribery.
2.1.2 External Forgery / Impersonation.
2.1.3 Use and/or disclosure of privileged information.
2.1.4 Industrial espionage.
2.1.5 Smuggling.
( )
( )
( )
( )
( )
2.2 System Security.
2.2.1 Violation of security systems.
2.2.2 Damage from cyberattacks.
2.2.3 Theft of information (with financial losses).
2.2.4 Inadequate use of access keys and/or authorization levels.
( )
( )
( )
( )
III. Business Incidents and System Failures
3.1 Systems
3.1.1. Hardware.
3.1.2. Software.
3.1.3 Telecommunications.
3.1.4. Interruption / supply incidents.
( )
( )
( )
( )
Name and signature of the Chief Information Security Officer
ANNEX 12
Report on information security incidents
I. Information of the collective financing institution
a) Name of the collective financing institution.
b) Full name of the information security officer, as well as their phone number and email address.
II. Detailed Information of the Information Security Incident
Attach, in encrypted digital media, the following information:
Description of the Information Security Incident.
Affected account numbers.
Status of affected accounts (blocked, suspended, active).
Affected network zone (Internet, internal network, administration network, among others).
Type of affected system (file server, web server, email service, database, workstations, either desktop or mobile, among others).
Operating system (specify version).
Protocols or services of the impacted components.
Number of components of the collective financing institution's systems affected.
Applications involved (specify version).
Compromised device information, if applicable (brand, software version, firmware, among others).
Impact on service (considering any disruption) caused by the Information Security Incident.
Amount of loss in pesos, if applicable.
Amount recovered in pesos, if applicable.
Status of the Information Security Incident (Resolved or Unresolved).
Indicate if the Information Security Incident has been disclosed to any authority. If affirmative, indicate the authority and the date.
Public IP addresses, email addresses, or domains from which the attack originates.
The communication protocol used, if applicable.
The URL in case of websites involved.
The detected malware or signature.
Detail the actions taken to mitigate the Information Security Incident, mentioning the persons responsible for implementing said mitigation actions.
Description of the results of the mitigation actions.
Incident recovery times.
Actions to minimize damage in similar subsequent situations.
Other information deemed necessary for the CNBV's knowledge.
Communication actions with Clients to inform them of the incident.
Name and signature of the Chief Information Security Officer
ANNEX 13
Information security indicators
The Chief Information Security Officer of the collective financing institution, in relation to the risk indicators in information security referred to in clause XI of Article 66, of these provisions, must:
Evaluate these indicators, which must adhere to the thresholds contained in this annex for each indicator. In the event of defining different thresholds, the reason must be documented.
Define remediation plans for those risks where the evaluation results yield values that fall within the medium and high risk thresholds established in this annex or, if applicable, those defined by the collective financing institution, provided they are in a high threshold for at least two consecutive periods.
Provide continuous maintenance, whether to add, eliminate, or update key risk indicators and information security performance indicators already existing, which must always be aligned with the collective financing institution's strategy and the Information Security Master Plan of this.
Measure and evaluate their evolution with the periodicity indicated in the following tables, or earlier in the event of unusual events.
In the event that not all conditions apply, indicate that they are not applicable and explain the reason.
Type
Definition
Sub Type
Sub Class of Events
Examples
I. Internal Fraud
Losses derived from any type of action directed at defrauding, improperly appropriating goods, or bypassing regulations, laws, or corporate policies (excluding diversity / discrimination events) in which at least one internal party to the Financial Technology Institution is involved.
1.1 Unauthorized Activities.
1.1.1 Undisclosed operations (intentional).
1.1.2 Unauthorized operations (with financial losses).
1.1.3 Incorrect valuation of positions (intentional).
Operations not communicated; unauthorized operations (with financial losses); incorrect valuation of positions, and intentional omission of regulations.
1.2 Internal Theft and Fraud.
1.2.1 Fraud / valueless deposits.
1.2.2 Extortion / embezzlement / theft.
1.2.3 Misappropriation of assets.
1.2.4 Destructive destruction of assets.
1.2.5 Internal Forgery.
1.2.6 Smuggling
1.2.7 Misappropriation of accounts, identity, among others.
1.2.8 Non-compliance / tax evasion (intentional)
1.2.9 Bribery.
1.2.10 Abuse of insider information (not to the company's benefit).
Theft; embezzlement; misappropriation; asset destruction; forgeries; identity spoofing; and bribes; manipulation of accounts.
1.3. System Security.
1.3.1 Violation of security systems.
1.3.2 Damage from cyberattacks.
1.3.3 Theft of information (with financial losses).
1.3.4 Inadequate use of access keys and/or authorization levels.
Abuse and use of privileged or confidential information; alteration of computer applications; theft of passwords, and prohibited computer access.
II. External Fraud
Losses derived from any type of action directed at defrauding, improperly appropriating goods, or bypassing legislation, by a third party.
2.1 External Theft and Fraud.
2.1.1 Theft / fraud / extortion / bribery.
2.1.2 External Forgery / Impersonation.
2.1.3 Use and/or disclosure of privileged information.
2.1.4 Industrial espionage.
2.1.5 Smuggling.
Forged or manipulated documents (transfers, etc.); identity spoofing; improper dispositions; counterfeit coins; deteriorated banknotes or out of legal circulation; thefts in the IFC facilities, and improper use of stolen or forged cards.
2.2 System Security.
2.2.1 Violation of security systems.
2.2.2 Damage from cyberattacks.
2.2.3 Theft of information (with financial losses).
2.2.4 Inadequate use of access keys and/or authorization levels.
Unauthorized computer access; manipulation of computer applications; damage from cyberattacks, and theft of
information.
VI. Incidents in
Business and Failures in
the Systems
Losses derived from
business incidents and
system failures.
6.1 Systems
6.1.1
Hardware.
6.1.2
Software.
6.1.3
Telecommunications.
6.1.4
Interruption / business incidents.
Interruption / incidents in supplies
and communication lines; errors in
computer programs; hardware and
software failures;
sabotage; business interruptions;
computer failures and virus programming.
ID
Name
Description
Domain
Type
Sub Type
Sub Class of
Events
Type of
Indicator
Period
Unit of
Measurement
Calculation
Variable X
Variable Y
High
Risk
Medium
Risk
Low
Risk
KRI0001
Incidents
via direct
attacks
against
internal
systems
Number of incidents
that have been originated by
attacks against the internal systems of the
Financial Technology Institution, in the
established period.
Logical
attacks.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Reactive.
Quarterly.
Quantity.
Variable X
Number of cases
of identified
incidents.
More than 1.
Equal to 1.
Equal to 0.
KRI0002
Fraud cases
on the platform.
Percentage of cases
where fraud is identified,
that has been
originated by attacks
against the Platform.
.
Logical
attacks.
II. External
Fraud
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Reactive.
Monthly.
Percentage.
(X/Y)*100
Number of fraud
cases on the
Platform.
Number of
Clients who
use the
Platform.
More than
.01 %.
Between
0.005 %
and 0.01
%.
KRI0003
Equipment of
the Technological
Infrastructure
from which
its security
configuration
is managed.
Percentage of equipment
of Technological Infrastructure within the
Platform and/or process of
review of secure configuration
standards, with
respect to the total
equipment of the IFC during the
established period.
Compliance.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Preventive.
Monthly.
Percentage.
(X/Y)*100
Number of equipment
within the
platform or
process of review
of secure configuration
standards.
Total number
of equipment.
Less than
85 %.
Between 85
% and 95
%.
More than
95 %.
KRI0004
Level of
compliance of
secure
configuration
of servers
from which
its configuration
is managed.
Average percentage of
compliance level of
servers contemplated
within the tool and/or process of review of
secure configuration
standards.
Compliance.
II. External
Fraud
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Preventive.
Monthly.
Average
percentage.
Average(
X)
% of compliance
of the secure
configuration
standard of each
one of the
Servers.
Less than
90 %.
Between 90
% and 95
%.
More than
95 %.
KRI0005
Users with
inadequate
roles and profiles.
Percentage of users
with inadequate profiles
within the applications
of the IFC, with respect to
the total of users in all
applications
of the
Financial Technology Institution.
Compliance.
I. Internal
Fraud
1.3. Security of
the systems.
1.3.3
Theft of
information (with
financial losses).
1.3.4
Inadequate
use of access
keys and/or levels
of authorization.
Corrective.
Semi-annual
.
Percentage.
(X/Y)*100
Number of
users with
incorrect profiles,
considering all
applications.
Total number
of users
considering
all
applications.
More than 3
%.
Between 1%
and 3 %.
Less
than 1 %.
KRI0006
Applications
without roles
and profiles.
Percentage of
applications which do not
possess the capacity
nor the
profiling of
roles
and
permissions, or that said
profiles are not
implemented, this with
respect to the total of
applications.
Compliance.
I. Internal
Fraud.
1.3. Security of
the systems.
1.3.3 Theft of
information (with
financial losses).
1.3.4 Inadequate
use of access
keys and/or levels
of authorization
Corrective.
Quarterly.
Percentage.
(X/Y)*100.
Number of
applications without capacity
of
profiling, or
profiling not
implemented.
Total number
of
applications.
More than 5
%.
Between 2
% and 5 %.
Less
than 2 %.
KRI0007
Security incidents
of information
generally
Total number of
incidents reported
during the established
period referring to
information security.
Information.
Applies to:
I.
Internal
Fraud
II.
External
Fraud
VI.
Incidents
in Business
and Failures in
the Systems.
Apply to:
1.3. Security of
the systems
2.2 Security of
the Systems.
6.1 Systems.
Apply to:
1.3.1
Breach of
security systems
1.3.2
Damage from
computer attacks.
1.3.3
Theft of
information (with
financial losses).
1.3.4
Inadequate
use of access
keys and/or levels of
authorization.
Reactive.
Monthly.
Quantity.
Variable X.
Number of
security incidents.
of information
More than 5.
From 2 to 5.
Less
than 2.
2.2.1 Breach of
security systems.
2.2.2 Damage from
computer
attacks.
2.2.3 Theft of
information (with
financial losses).
2.2.4 Inadequate
use of access
keys and/or levels of
authorization.
6.1.1 Hardware.
6.1.2 Software.
6.1.3
Telecommunications.
6.1.4 Interruption /
incidents in the
Supply
KRI0008
Obsolete and/or
outdated technological
platforms
Percentage of technological
platforms that are on
obsolete versions and/or
without support from the
manufacturer
Infrastructure.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Semi-annual
Percentage.
(X/Y)*10.
Number of
technological
platforms
obsolete.
Total of
technological
platforms.
More than 5
%.
Between 2
% and 5 %.
Less
than 2 %
KRI0009
System outages
related to
the services
provided to
their
Clients
Number of system outages related
to the services
provided to their Clients
greater than 10 minutes.
Infrastructure.
VI.
Incidents
in Business
and failures in
the systems
6.1 Systems.
6.1.4 Interruption /
incidents in the
Supply.
Reactive.
Monthly.
Quantity.
Variable X.
Number of
outages
of
systems.
More than 1.
Equal to 1.
Equal to 0.
KRI0010
Security incidents
from system
vulnerabilities
provided by
providers
(third parties).
Percentage of security
incidents caused
by vulnerabilities in
systems and infrastructure
technology provided by
providers (third parties)
that do not belong to the
payroll of the IFC,
reported during the
established period, with
respect to the total of
security incidents.
Infrastructure.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1
Breach of
security systems.
2.2.2
Damage from
computer attacks.
2.2.3
Theft of
information (with
financial losses).
2.2.4 Inadequate
use of access
keys and/or levels of
authorization.
Reactive.
Monthly.
Percentage.
(X/Y)*100.
Number of
security incidents
attributed to
vulnerabilities in
systems provided
by providers
(third parties).
Total number
of security
incidents.
More than 5
%.
Between 0.1
% and 5 %.
Less than
0.1 %.
KRI0011
Critical
vulnerabilities
pending to
correct
detected in
ethical hacking
tests.
Number of
vulnerabilities in the
information systems
that, according to the
ethical hacking tests,
are classified as
critical, which have
more than one month of
age from their
date of detection.
Infrastructure.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Preventive.
Monthly.
Quantity.
Variable X.
Number of
critical vulnerabilities
pending to correct with
age of more
than one month.
More than 2.
Between 1 and
Equal to 0.
KRI0012
Unavailability
of the IT
systems.
Average percentage of
unavailability time of
the systems against the
total time of the established
period.
Infrastructure.
VI.
Incidents in
Business and
Failures in
the Systems.
6.1 Systems.
6.1.4 Interruption /
incidents in the
Supply.
Reactive.
Monthly.
Average
Percentage.
Average(
X).
Average of
unavailability time of
IT systems.
More than 0.5
%.
Between
0.25 %
and 0.5 %.
Less
than
0.25 %.
KRI0013
Critical and high
priority incidents
in production
environments.
Percentage of incidents
qualified as critical and
high priority in
production environments
with respect to the total of
incidents in
production.
Infrastructure.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Reactive.
Monthly.
Percentage.
(X/Y)*100.
Number of
incidents in
production
qualified as
critical.
Total number
of incidents
in production.
Greater than
or equal to 0.5
%.
Greater than
0% and
less
than 0.5 %.
Equal to 0
%.
KRI0014
Components of
the technological
infrastructure
exposed to
internet without
ethical hacking
tests and/or
vulnerability
analysis
.
Percentage of the
components of the
infrastructure
technology of the
organization exposed towards internet to which
ethical hacking or vulnerability
analysis has not been
performed, with
respect to the total of
equipment for more than 3
months.
Infrastructure.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Quarterly.
Percentage.
(X/Y)*100.
Number of assets
exposed to
internet that have
not performed
ethical hacking
tests or vulnerability
analysis.
Number of
assets
exposed to
internet.
More than 3
%.
Between
1 % and 3
%.
Less
than 1 %.
KRI0015
Critical
vulnerabilities
pending to
correct
detected in
vulnerability
analyses
.
Number of
vulnerabilities in the
information systems
that, according to the
vulnerability
analyses, are
classified as critical,
which have more than
one month of age from
their date of detection.
Infrastructure.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Monthly.
Quantity.
Variable X.
Total number of
critical vulnerabilities.
More than 2
Between 1 and
2
Equal to 0
KRI0016
Obsolete Technological
Infrastructure
and/or without
support.
Number of equipment and
Technological Infrastructure,
which are in obsolete
versions or without support,
in comparison with all
active IT infrastructure in the established
period.
Infrastructure.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Quarterly.
Percentage.
(X/Y)*100.
Number of equipment
and obsolete
infrastructure.
Total number
of active
equipment.
More than 5
%.
Between 2
% and 5 %.
Less
than 2 %.
KRI0017
Servers without
antimalware
solution.
Percentage of servers
without antimalware with respect to the total of servers.
Malware.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Monthly.
Percentage.
(X/Y)*100.
Number of
servers without
antimalware.
Total number
of servers.
More than 6
%.
Between 3%
and 6 %.
Less than
3 %.
KRI0018
Servers with
outdated
antimalware
signatures.
Percentage of servers
with outdated antimalware
signatures (malware signatures)
with respect to the total of servers with
antimalware in each
IFC
Malware.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Monthly.
Percentage.
(X/Y)*100.
Number of
servers with
outdated antimalware
signatures.
Total number
of servers
with
antimalware.
More than 6
%
Between 3%
and 6 %
Less than
3 %
KRI0019
Workstations without
antimalware
solution
Percentage of
workstations without
antimalware with respect to the total of equipment
Malware.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Monthly.
Percentage.
(X/Y)*100.
Number of
workstations without
antimalware.
Total number
of
workstations.
More than 8
%.
Between 4%
and 8 %.
Less than
4 %.
KRI0020
Workstations
with outdated
antimalware
signatures.
Percentage of the
workstations that have
outdated antimalware
signatures (malware
signatures) with
respect to the total of
computing equipment with
antimalware installed.
Malware.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Monthly.
Percentage.
(X/Y)*100.
Number of
workstations with
outdated antimalware
signatures.
Number of
workstations
with
antimalware.
More than 8
%.
Between 4%
and 8 %.
Less than
4 %.
KRI0021
Security incidents
attributed to
provider
personnel
(third parties).
Percentage of security
incidents
related to personnel
of providers (third parties)
that do not belong to the
payroll of the IFC,
reported during the
established period, with
respect to the total of
security incidents.
Incidents.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Reactive.
Monthly.
Percentage.
(X/Y)*100.
Number of
security incidents
related to
provider personnel
(third parties).
Number of
security incidents
total of personnel
of
providers
(third parties).
More than 5
%.
Greater than
0 % and
less than 5
%.
Equal to 0
%.
KRI0022
Servers with
obsolete
operating system
versions.
Total percentage of
servers with obsolete
operating system
versions compared
against total number of
servers.
Software.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Monthly.
Percentage.
(X/Y)*100.
Number of
servers with
obsolete operating system
versions.
Total number
of servers.
More than 10
%.
Between 5%
and 10 %.
Less than
5 %.
KRI0023
Applications in
production with
partial or
deficient
compliance of
security controls.
Percentage of the
applications in
production with
partial or
deficient compliance, with respect to the established security
policies, in matters of
security, with respect to
the total of
applications.
Software.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Quarterly.
Percentage.
(X/Y)*100.
Number of
security controls
deficient in
applications in
production.
Total number
of security
controls.
More than 5
%.
Between 2
% and 5 %.
Less
than 2 %.
KRI0024
Database
managers
(DBM) with
obsolete or
unsupported technology
versions.
Percentage of database managers (DBM), which
are obsolete technology
versions or
unsupported by the
manufacturer, in
comparison with the total
of database managers
(DBM) active in the
established period.
Software.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Quarterly.
Percentage.
(X/Y)*100.
Number of database
managers
(DBM) obsolete or
unsupported.
Total number
database
managers
(DBM).
More than 10
%.
Between 5
% and 10
%.
Less
than 5 %.
KRI0025
Obsolete or
unsupported
applications.
Percentage of
applications within the
IFC, which are
obsolete or
without support from the
manufacturer, in relation to
all active applications
during the
established period.
Software.
II. External
Fraud.
VI.
Incidents in
Business and
Failures in
the Systems.
2.2 Security of
the Systems.
6.1 Systems.
2.2.1 Breach of
security systems.
6.1.2 Software.
Corrective.
Quarterly.
Percentage.
(X/Y)*100.
Number of
applications
obsolete or unsupported.
Total of
active
applications.
More than 5
%.
Between 2
% and 5 %.
Less
than 2 %.
KRI0026
Servers without
security patch
coverage.
Percentage of servers
without the most recent
security patches,
with respect to the total of
active servers during the
established period.
Software.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Monthly.
Percentage.
(X/Y)*100.
Number of
servers without the
most recent
security patches
installed.
Total of
servers.
More than 5
%.
Between 2
% and 5 %.
Less
than 2 %.
KRI0027
Workstations without
security patch
coverage.
Percentage of
workstations without the most recent
security patches regardless
of the operating system
of which they are,
with respect to
the total of workstations of the
IFC
Software.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Corrective.
Monthly.
Percentage.
(X/Y))*100.
Number
of workstations without the
most recent
security patches
installed total.
Number of
workstations
total.
More than 3
%.
Between 1
% and 3 %.
Less
than 1 %.
KRI0028
Database
managers
(DBM) without
security patch
coverage.
Percentage of database
managers (DBM) without
coverage of the most recent
security patches, with respect to the
total of database
managers (DBM) during the
established period.
Software.
II. External
Fraud.
2.2 Security of
the Systems.
2.2.1 Breach of
security systems.
Preventive.
Quarterly.
Percentage.
(X/Y)*100.
Number of database
managers
(DBM) without
coverage of
security patches.
Total number
of database
managers
(DBM).
More than 5
%.
Between 2
% and 5 %.
Less
than 2 %.
ANNEX 14
Format for Application System Information (F-SA)
Instructions: The numerals 1 to 11 must be removed from each title of the columns of the table once the format is documented, as well as the instructions that appear in the footer of the table, and the examples contained within it.
Name of the
application or
system 1
Related business
process(es)
with the system 2
Name of the equipment where
it is processed 3
Language 4
Platform (brand and
model of the main computing equipment of the
application or system) 5
Operating system 6
Database 7
Cloud
Services 8
Application Provider /
Self-development 9
Processing Location (Main / Alternate Site) 10
Operation Location
(Main Site /
Alternate) 11
Physical
Virtual
Physical
Virtual
Self /
Third Parties (a)
Location (b)
National /
Foreign
Location
Example 1:
Name of
System
< Collection,
Placement,
Teller, etc. >
< SRVCORE1 >
< JAVA 1.1 >
< IBM i 7.2 >
<UNIX>< NA >
< Provider4, S.A
de C.V. >
< Third Parties >
< Main computer center
Triara, S.A. de C.V.
Mexico City
Col. Del Valle, CP
03100 >
< Alternate computer center
Mexico City
Alfonso Nápoles
Gándara 50, Col.
Peña Blanca Santa
Fe, CP 01210 >
< National >
< Corporate >
< SOCPROD2 >
<Windows Server
2018>
< Oracle >
< Foreign >
< Main office
Bournemouth, United
Kingdom >
< Alternate office
Bournemouth, United
Kingdom >
< SOCPROD3 >
<Windows Server
2012>
Example 2:
Name of
System
< Collection,
Placement,
Teller, etc. >
< SOCPROD2 >
< RPG II >
< Fedora >
< DB2 >
< SaaS >
< Provider1, S.A
de C.V. >
< Third Parties >
< North Zone of
United States of
North America >
< National >
< Alternate computer center
Mexico City
Alfonso Nápoles Gándara
50, Ground Floor Col. Peña
Blanca Santa Fe, CP 01210
< SOCPROD3 >
<Windows
Server 2012>
< Corporate >
< ... >
< ... >
< ... >
< ... >
< ... >
< ... >
< ... >
< ... >
< ... >
< ... >
< ... >
< ... >
< ... >
< ... >
< ... >
Name of the application or system: capture the name by which the application or system is identified internally within the Entity
or commercially.
Related business process(es) with the system: describe the business process(es) supported by the system.
Name of the equipment where it is processed: capture the name by which the physical and virtual server is identified internally within the
Entity.
Language: indicate the programming language(s) of the system including its version.
Platform (brand and model of the main computing equipment of the application or system): capture the brand and model of the physical server
(main equipment) where the system is processed.
Operating system: capture the name and version of the operating system of the physical and virtual equipment where the system is processed and/or the virtual machine resides.
Database: database where the information processed by the application is stored.
Cloud Services: include, if applicable, the type of service contracted in the cloud scheme: N/A (Not Applicable), SaaS (Software as a Service), IaaS (Infrastructure as a Service).
Application Provider / Self-development: if it is an internal development indicate: "Self-development"; if it is an
external development, include the legal name of the system provider.
Processing Location (Main / Alternate Site):
(a)
Indicate "Self" if the computer center belongs to the Entity; otherwise, the legal name of the provider of the
Main Computer Center must be indicated.
(b)
Specify the name of the computer center as it is known internally within the Entity or commercially, and the
full address where the main and alternate computer centers are located (street, number,
colony, delegation or municipality, state, postal code) when national. For foreign addresses,
the equivalent information to that stated above must be specified.
Operation Location (Main / Alternate Site): indicate if they are located in national or foreign territory (National/Foreign column) and specify the full address where the personnel who have access and operate the system in question are located
(Location column).
ANNEX 15
Guidelines for the disclosure of information on Collective Financing of Debt for Business Loans between Individuals and for Real Estate Development
I.
General Aspects
These guidelines establish the general criteria for information disclosure and minimum
contents that collective financing institutions must follow in the disclosure of information
they make regarding Collective Financing of Debt for Business Loans between Individuals and
for Real Estate Development that they promote through their Platforms. Collective financing institutions
may present the information referred to in this annex in the order they determine, being required to present it in all financing offers consistently. To this
effect, collective financing institutions must:
a.
Ensure that the information that proves relevant for the
Investors can make informed decisions, based on the knowledge that the collective financing institutions themselves have of the financing project and on the risk analysis and evaluation they have performed.
b. Include the most recent information known at the time of its publication on the Platform.
c. Determine the depth and breadth with which the information indicated in this annex will be disclosed, including any additional or complementary information to that established in this. In the event that a section does not apply, they must specify such situation.
d. Indicate the source of the reports, statistics, analyses, opinions or other public information they use and when the information comes from a third party, a declaration must be included indicating that such information has been considered with the consent of said third party, if applicable.
e. Express monetary figures in Mexican pesos and in the case of figures whose original source is denominated in foreign currency or virtual assets, the exchange rate used to convert them to Mexican pesos must be specified, indicating the date to which it corresponds and the source that publishes it. It must also be clarified that such conversion was carried out solely to facilitate reading and understanding by Investors.
f. Use clear, concise and easy-to-understand language, as well as avoid the use of technical terms or complex legal formalisms that cannot be easily understood by a person who does not have specialized knowledge in the subject matter and avoid the use of superlative terms and value judgments.
II. Information that must be disclosed regarding Collective Debt Financing for Business Loans between Individuals
A. Regarding the collective financing referred to in Article 2, fraction XV, subsection a) of these provisions
With respect to the financing
i) Amount of the financing requested.
ii) Term of the Collective Financing Application.
iii) Description of the use of the financing.
iv) Term of the collective financing.
v) Main source of payment for the financing.
vi) Payment schedule for principal and interest, as well as their amount.
vii) Ordinary interest rates and, if applicable, default interest.
viii) Real or personal guarantees, if applicable.
ix) Risk rating determined according to the risk evaluation methodology defined by the collective financing institution, accompanied by a simple explanation of how to interpret it.
x) The participation that collective financing institutions assume when, if applicable, they are Investors through the implementation of risk-sharing schemes referred to in Article 21, second paragraph of the Law.
With respect to the Applicant
In the case of a natural person with business activity:
i) Information related to their age, sex, residence, academic background and professional or business experience.
ii) Description of their main activity.
iii) Information regarding the economic solvency of the Applicant, including a description of their income sources.
iv) Description of the main source of payment for the requested financing.
In the case of a legal entity:
i) Name and business line, legal nature, date of incorporation, address of main offices, geographic coverage or location of main branches and, if applicable, website.
ii) Description of their objectives or business model, as well as an explanatory note on their administration (if it is a family business, if there is a person or group of people who exercises control, among other aspects).
iii) Distribution and marketing channels, including an explanation of the sales method used (for example, sales through electronic means).
iv) In the event that the legal entity requests financing for a specific project, provide a description of this and the expected benefits; the relevance of said project for its objectives or business model, as well as, if applicable, the indicators through which the progress and results of the project will be measured, the time in which they are expected to be achieved and the form and frequency with which Investors participating in the collective financing will be informed about the progress and results of the project.
v) Business history or technical knowledge of the administrators or executors of the project; if the source of payment for the financing depends on it.
vi) Description of the financial situation of the legal entity at the time of the financing application, considering aspects such as profitability, leverage, liquidity and operational efficiency.
vii) Selected financial indicators that include, at least, the amount of equity capital, the main items of assets and liabilities, as well as the result of the previous fiscal year.
viii) In the case of newly created companies, this situation must be indicated, stating that this could increase the risk of the project, and if applicable, information regarding the business history or technical knowledge of the administrators or executors of the project must be included; as well as the financial projections, if any.
ix) If applicable, it must be indicated whether the company is part of or has participated in any business or commercial incubator programs, as well as the description of the resources and services received under said program.
With respect to risk factors
The risk factors that could affect the payment capacity of the Applicants must be explained, such as: business strategy risks, lack of liquidity for the recently created company, increase in debt, increase in certain interest rates, adverse market conditions, economic recession, technological changes or changes in consumer preferences, increases in production or distribution costs, dependence on key clients or suppliers, natural disasters, entry of new competitors into the industry, legal or regulatory changes, environmental risks related to assets, inputs, products or services, among others.
With respect to the implementation of guarantees
The circumstances, mechanisms and procedures to make them effective must be indicated; the rights they grant to Investors and the role that, if applicable, the collective financing institution plays in that process.
With respect to periodic disclosure
It must be indicated what type of information or indicators will be disclosed to participating Investors, regarding the progress of the financed project and the impact of the financing obtained on their business activities. It must also be explained how Investors can access this information.
B. Regarding the collective financing referred to in Article 2, fraction XV, subsection b) of these provisions (financial leasing)
With respect to collective financing
i) Amount of the financing requested.
ii) Term of the Collective Financing Application.
iii) Description of the use of the financing.
iv) The characteristics of the goods subject to the Operation.
v) The obligations borne by the Applicant and, if applicable, by Investors, in relation to said goods.
vi) Term of the collective financing.
vii) Main source of payment for the financing.
viii) If applicable, description of the conditions for the purchase of the goods subject to the Operation at the end of this, by the Applicant.
ix) Payment schedule for principal and interest, as well as their amount.
x) Ordinary interest rates and, if applicable, default interest.
xi) Risk rating determined according to the risk evaluation methodology defined by the collective financing institution, accompanied by a simple explanation of how to interpret it.
xii) The participation that collective financing institutions assume when, if applicable, they are Investors through the implementation of risk-sharing schemes referred to in Article 21, second paragraph of the Law.
With respect to the Applicant
In the case of a natural person with business activity
i) Information related to their age, sex, residence, academic background and professional or business experience.
ii) Description of their main activity.
iii) Information regarding the economic solvency of the Applicant; including a description of their income sources.
iv) Description of the main source of payment for the requested financing.
In the case of a legal entity
i) Name and business line, legal nature, date of incorporation, address of main offices, geographic coverage or location of main branches and, if applicable, website.
ii) Description of the financial situation of the company at the time of the financing application, considering aspects such as profitability, leverage, liquidity and operational efficiency.
iii) Selected financial indicators that include, at least, the amount of equity capital, the main items of assets and liabilities, as well as the result of the previous fiscal year.
iv) If applicable, it must be indicated whether the company is part of or has participated in any business or commercial incubator programs, as well as the description of the resources and services received under said program.
With respect to risk factors
The risk factors that could affect the payment capacity of the Applicants must be explained, such as: business strategy risks, lack of liquidity for the recently created company, increase in debt, increase in certain interest rates, adverse market conditions, economic recession, technological changes, or changes in consumer preferences, increases in production or distribution costs, dependence on key clients or suppliers, natural disasters, entry of new competitors into the industry, legal or regulatory changes, environmental risks related to assets, inputs, products or services, among others.
With respect to periodic disclosure
It must be indicated what type of information or indicators will be disclosed to participating Investors. It must also be explained how Investors can access this information.
C. Regarding the collective financing referred to in Article 2, fraction XV, subsection c) of these provisions (financial factoring)
With respect to collective financing
i) Amount of the financing requested.
ii) Term of the Collective Financing Application.
iii) Term of the collective financing.
iv) Payment schedule for principal and interest, as well as their amount.
v) Ordinary interest rates and, if applicable, default interest.
vi) Risk rating determined according to the risk evaluation methodology defined by the Collective Financing Institution, accompanied by a simple explanation of how to interpret it.
vii) The participation that collective financing institutions assume when, if applicable, they are Investors through the implementation of risk-sharing schemes referred to in Article 21, second paragraph of the Law.
With respect to the credit rights subject to the Operation
i) Information related to the credit rights, titles or accounts receivable that constitute the object of the financing Operation, indicating their main characteristics, among which are:
a. Type of credit rights.
b. Nature of the goods or services that financed them.
c. Financial conditions of the credit right or rights:
· Term of the account(s) receivable.
· Total amount owed.
· Payment schedule for capital and interest.
· Ordinary and default interest rates.
d. In the case of a portfolio of credit rights, indicate if they are similar credits (homogeneous portfolio) or of different categories (non-homogeneous portfolio). In the latter case, information must be disclosed for each type of portfolio or account receivable.
e. Percentage of the value of the invoice or account receivable that is considered for granting the financing.
ii) Information related to the credit quality of the debtor of the credit rights that Investors will acquire. In the event of not having information on the debtor of the credit rights, this situation will be disclosed to Investors.
iii) In the event that the rights to be transferred to Investors derive from an invoice, it must be indicated whether the collective financing institution was able to electronically verify the data of this before the Tax Administration Service, as well as its validity.
With respect to the Applicant
i) Description of the Applicant's main business activity and the reason for requesting financing (working capital, expansion of operations, process automation, investment in infrastructure or technology, among others).
ii) General data of the Applicant:
In the case of a natural person with business activity:
a. Information related to their age, sex, residence, academic background and professional or business experience.
b. Information regarding solvency; including a description of their income sources.
In the case of a legal entity:
a. Name and business line or sector to which it belongs, legal nature, date of incorporation, address of main offices, geographic coverage or location of main branches and, if applicable, website.
b. Description of the Applicant's financial situation at the time of making the application, including aspects such as:
· Income from the sale of products or provision of services, registered in the last year.
· Profitability, leverage, liquidity and operational efficiency.
· Debt capacity and cash flow generation.
· Selected financial indicators that include, at least, the amount of equity capital, the main items of assets and liabilities, as well as the result of the previous fiscal year.
c. If applicable, it must be indicated whether the company is part of or has participated in any business or commercial incubator programs, as well as the description of the resources and services received under said program.
With respect to risk factors
Any material information of which the Applicant has knowledge that could negatively impact the credit quality of the debtor or debtors of the credit rights that constitute the object of the Operation must be disclosed.
With respect to periodic disclosure
The form and means through which Investors participating in the collective financing will be informed about the payment behavior of the accounts receivable must be specified, indicating the frequency of disclosure of this information, which must refer, at least, to the following aspects:
i) Amount and percentage of the account receivable or portfolio of credit rights that has already been recovered from the total.
ii) Overdue or delayed balance, if applicable.
iii) Total amount of interest paid, broken down into ordinary and default, if applicable.
iv) Collection actions taken, if applicable.
III. Information that must be disclosed regarding Collective Debt Financing for Real Estate Development
With respect to collective financing
i) Amount of the financing requested.
ii) Term of the Collective Financing Application.
iii) Description of the use of the financing, highlighting the main characteristics of the real estate properties subject to financing.
iv) Main source of payment for the financing.
v) Term of the collective financing.
vi) Payment schedule for principal and interest, as well as their amount.
vii) Ordinary and default interest rates.
viii) Guarantees granted by the Applicants and their relationship with the amount of financing; if the progress of the project has been defined in stages and will occupy more than one round of collective financing, the rights and guarantees of Investors in each stage must be stipulated; without ambiguity.
ix) Risk rating determined according to the risk evaluation methodology defined by the Collective Financing Institution, accompanied by a simple explanation of how to interpret it.
x) The participation that collective financing institutions assume when, if applicable, they are Investors through the implementation of risk-sharing schemes referred to in Article 21, second paragraph of the Law.
With respect to real estate development
i) Description and main characteristics of the real estate project.
ii) Use that will be given to the property.
iii) Location of the property.
iv) Degree of progress of the work.
v) Total investment required to carry out the project and estimated time for recovery of said investment.
vi) Additional sources of resources available to carry it out (different from collective financing) and guarantees granted, if applicable.
vii) Technical, legal and environmental aspects related to the development of the project, if applicable (land use permits, urbanization and drainage, environmental impact, among others, if applicable).
viii) Market study.
With respect to the Applicant
i) Name of the Applicant, legal nature, date of incorporation, address of main offices, geographic coverage of its services and location of main branches, as well as website.
ii) Description of its objectives or business model, as well as an explanatory note on its administration (if it is a family business, if there is a person or group of people who exercises control, among other aspects).
iii) Experience in the real estate business of the company and its administrators.
iv) Financial situation of the Applicant at the time of making the application, considering aspects such as profitability, leverage, liquidity and operational efficiency.
v) Selected financial indicators of the Applicant, which include, at least, the amount of its equity capital, the main items of assets and liabilities, as well as the result of the previous fiscal year.
With respect to risk factors
The variables or risk factors that could affect must be explained:
i) The payment capacity of the Applicant
ii) The progress and completion of the real estate development project.
iii) The sales value of the property or its rental income, if applicable.
iv) The recovery period of the resources from the collective financing.
All relevant risks must be highlighted, including, in an illustrative but not exhaustive manner, those related to macroeconomic and regional aspects that could affect the demand for real estate goods, legal, regulatory, environmental and technical risks, among others.
With respect to the implementation of guarantees
The assets and rights, present and future, that guarantee the financing must be described, as well as the circumstances, mechanisms and procedures to execute the guarantees; likewise, the obligations of the Applicant must be clearly established, as well as the responsibilities of the collective financing institution in the event that they have to be executed.
With respect to periodic disclosure
It must be indicated what type of information or indicators will be disclosed to participating Investors, regarding the progress of the project and the recovery of resources from collective financing. It must also be explained how Investors can access this information.
ANNEX 16
Guidelines for the disclosure of information for Collective Capital Financing
I. General aspects
These guidelines establish the general criteria for information disclosure and minimum contents that collective financing institutions must follow in the disclosure of information they provide regarding Collective Capital Financing that they promote through their Platforms.
Collective financing institutions may present the information referred to in this annex in the order they determine, presenting it consistently in all financing offers. To this end, collective financing institutions must:
a. Ensure that information is disclosed that is relevant for Investors to make informed decisions, based on the knowledge that the collective financing institutions themselves have of the financing project and on the risk analysis and evaluation they have performed.
b. Include the most recent information known at the time of its publication on the Platform.
c. Determine the depth and breadth with which the information indicated in this annex will be disclosed, including any additional or complementary information to that established in this. In the event that a section does not apply, they must specify such situation.
d. Indicate the source of the reports, statistics, analyses, opinions or other public information they use and when the information comes from a third party, a declaration must be included indicating that such information has been considered with the consent of said third party, if applicable.
e. Express monetary figures in Mexican pesos and in the case of figures whose original source is denominated in foreign currency or virtual assets, the exchange rate used to convert them to Mexican pesos must be specified, indicating the date to which it corresponds and the source that publishes it. It must also be clarified that such conversion was carried out solely to facilitate reading and understanding by Investors.
f. Use clear, concise and easy-to-understand language, as well as avoid the use of technical terms or complex legal formalisms that cannot be easily understood by a person who does not have specialized knowledge in the subject matter and avoid the use of superlative terms and value judgments.
II. Information that must be disclosed regarding Collective Capital Financing
With respect to the financing
i) Amount of the financing requested.
ii) Term of the Collective Financing Application.
iii) Description of the ultimate use of the resources.
iv) Risk rating determined according to the risk evaluation methodology defined by the collective financing institution, accompanied by a simple explanation of how to interpret it.
risks defined by the crowdfunding institution, accompanied by a simple explanation of how to interpret it.
v)
The participation assumed by crowdfunding institutions when, in their case, they act as Investors through the implementation of risk-sharing schemes referred to in Article 21, second paragraph of the Law.
With respect to the Applicant
i)
Name and business activity of the legal entity, legal nature, date of incorporation, address of main offices, geographic coverage or location of main branches, and, if applicable, website.
ii)
Description of its objectives, business model or plan, as well as an explanatory note on its administration (if it is a family business, if there is a person or group of persons exercising control, among other aspects).
iii)
Distribution and marketing channels, including an explanation of the sales method used (for example, sales through electronic media).
iv)
In the event of requesting financing for a specific project, indicate the expected benefits and the time frame in which they are expected to be achieved.
v)
Business history or technical knowledge of the administrators.
vi)
Description of the financial situation of the legal entity at the time of the application, considering aspects such as profitability, leverage, liquidity, and operational efficiency.
vii)
Selected financial indicators that include, at a minimum, the amount of book capital, the main asset and liability items, as well as the result of the previous fiscal year.
viii)
In the case of newly created companies, this status must be indicated, noting that this could increase the risk of the project, and if applicable, information regarding the business history or technical knowledge of the administrators must be included; as well as the financial projections, if any.
ix)
If applicable, information regarding strategic participants or strategic alliances held and the benefits or synergies they generate.
x)
If applicable, information on patents, licenses, trademarks, franchises, industrial and commercial contracts, and other rights owned by the legal entity that are considered important, mentioning the duration of these and the reason why they are relevant for the development of the business.
xi)
If applicable, it must be indicated whether the company is part of or has participated in any business incubation programs, as well as a description of the resources and services received under said program.
With respect to the securities representing the share capital of the legal entity subject to financing and the rights they confer to Investors
i)
Characteristics of the securities and the information necessary for the determination of their price.
Total ($)
Total number of
securities to offer
Amount of resources requested
Price per security *
ii)
Amount of fixed and variable share capital of the legal entity subject to financing, if applicable, before and after the offering, considering the amount of resources requested, and the percentage that the requested amount represents with respect to the share capital, specifying the date of the general shareholders' meeting at which the increase was decreed.
iii)
Description of the number and type of securities in circulation of the legal entity subject to financing, as well as any limitations that exist for their acquisition, if applicable.
iv)
Description of the type and characteristics of the securities that investors will acquire.
v)
It must be indicated which of the following rights are provided by the offered securities (indicate all that apply):
Voting rights.
Right to receive dividends (describe what it consists of).
Rights in dissolution (describe what they consist of).
Conversion rights (describe what each security is convertible into).
Others (describe what it consists of).
vi)
Dividend policy applicable to the offered securities.
With respect to risk factors
The risk factors that could affect the company must be explained, such as: business strategy risks, lack of liquidity for recently created companies, increase in debt, increase in certain interest rates, adverse market conditions, economic recession, technological changes or changes in consumer preferences, increases in production or distribution costs, dependence on key customers or suppliers, natural disasters, entry of new competitors into the industry, legal or regulatory changes, environmental risks related to assets, inputs, products or services, among others.
Annex 17
Aggregated information of crowdfunding institutions for disclosure to the general public
I.
For Debt Crowdfunding:
Indicate the category of Debt Crowdfunding being reported: Personal Loan Debt Crowdfunding, Business Loan Debt Crowdfunding, or Real Estate Development Debt. If more than one category of Debt Crowdfunding is held, present the aggregated data for each of them separately.
Name of the Debt Crowdfunding Institution
Quarterly indicators
Aggregated indicator by financing category
Accumulated information with figures as of the end of each
quarter
t
t-1
t-2
t-3
t-4
Accumulated amount of financing granted
since the start of operations
Accumulated number of financing
granted since the start of operations
Number of active Financing Applicants
Individuals
Legal entities
Number of active Investors
Individuals
Legal entities
Amount of outstanding financings
Number of
outstanding financings
Amount of financings in default
Number of financings in default
Percentage that the Amount of
financings in default represents with respect to
the total of financings
Amount of financings
in default
Amount of financings in default
for more than 90 days
Number of financings
in default
for more than 90 days
Amount of financings in collection
Number of financings in collection
Average annual yield of the
financings granted, accompanied by
a note explaining the calculation procedure
employed (1)
Name of the Debt Crowdfunding Institution
Quarterly indicators
Indicator by financing category
Information for the reported period with figures as of the end of each quarter
t
t-1
t-2
t-3
t-4
Amount of financings in default
for more than 30 days during the reported
period
Number of financings in default
for more than 30 days during the reported
period
If applicable, amount recovered from
financings in default for more than
90 days during the
reported period
If applicable, percentage that the amount
recovered during the reported period
represents, with respect to the Amount of financings in
default for more than 90 days
Amount of new financings granted
during the reported period
Number of new financings granted
during the reported period
Amount of financings liquidated
during the reported period
Number of financings liquidated during
the reported period
Where:
·
t = most recent quarter being reported, with figures as of March, June, September, and December.
t - 1 = quarter immediately preceding the one being reported.
·
Active Financing Applicants: number of Applicants who have a financing in the
reported period.
·
Active Investors: number of Investors who are creditors in the reported period.
·
Amount of outstanding financings: includes the total outstanding balance of financings that are
current on their payments, both principal and interest, according to the
scheduled and agreed payment calendar when the Operation was agreed.
·
Number of outstanding financings: includes the total number of financings that are
current on their payments, both principal and interest, according to the
scheduled and agreed payment calendar when the Operation was agreed.
·
Amount of financings in default: includes the total balance of those financings in
which the Applicant has not covered the total payment of principal and/or interest committed according to the
scheduled and agreed payment calendar when the Operation was agreed.
·
Number of financings in default: includes the total number of financings in
which the Applicant has not covered the total payment of principal and/or interest committed according to the
scheduled and agreed payment calendar when the Operation was agreed.
·
Total number of financings = Number of outstanding financings + Number of
financings in default.
II.
For Capital, Co-ownership, and Royalty Crowdfunding:
Name of the Capital / Co-ownership or Royalty Crowdfunding Institution
Aggregated semi-annual indicators
Aggregated indicator by financing category
Information with figures as of the end of each semester
s
s-1
s-2
s-3
Accumulated amount of financing granted
since the start of operations
Accumulated number of financing granted
since the start of operations
Number of Applicants
Individuals
Legal entities
Number of Investors
Individuals
Legal entities
Amount of new financings granted
during the reported period
Number of new financings granted
during the reported period
Where:
·
s = most recent semester being reported with figures as of June and December.
s - 1 = semester immediately preceding the one being reported.
ANNEX 18
REGULATORY REPORTS OF CROWDFUNDING INSTITUTIONS (CFI)
Frequency
Series R01
Minimum Catalog
A-0112
Minimum Catalog
Monthly
Series R08
Bank loans and loans from other entities
D-0842
Disaggregation of loans obtained
Monthly
Series R10
Reclassifications
A-10112
Reclassifications in the statement of financial position
Monthly
A-10122
Reclassifications in the statement of comprehensive income
Monthly
Series R13
Financial Statements
A-13112
Statement of changes in equity
Quarterly
A-13162
Statement of cash flows
Quarterly
B-13212
Statement of financial position
Monthly
B-13222
Statement of comprehensive income
Monthly
Series R27
Claims
A-2702
Claims
Quarterly
SERIES R01 MINIMUM CATALOG
This series consists of one (1) report, whose frequency of preparation and submission must be monthly.
REPORT
A-0112
Minimum Catalog
In this report, the balances as of the end of the period for all concepts that
form part of the statement of financial position (including off-balance sheet accounts) and the
statement of comprehensive income of the Crowdfunding Institution are requested. The report is
requested in two subtotals:
·
National currency
·
Foreign currency valued in pesos.
For the completion of report A-0112
Minimum Catalog, the following aspects must be taken into consideration:
In the report, the balances of the Crowdfunding Institution must be presented without consolidation.
The balances of all concepts presented in Series R01 Minimum Catalog must be consistent with
those reported in the regulatory reports that are applicable.
For the case of the minimum catalog concepts denominated in national currency, UMA and UDIS
valued in pesos, these concepts must coincide with the sum of the concepts provided in the
regulatory reports in national currency, UMA and UDIS valued in pesos; while the concepts
denominated in foreign currency valued in pesos must coincide with the concepts provided in
the other regulatory reports in foreign currency valued in pesos.
Data referring to balances must be presented in national currency, foreign currency, UMA and
UDIS valued in pesos and foreign currency valued in pesos using the exchange rate indicated in
the current accounting criteria. Such balances must be presented in pesos, with four decimals and without
commas. For example: $20,585.7000 would be 20585.7000
CAPTURE FORMAT
Crowdfunding Institutions will carry out the submission of the information related to the
report A-0112
Minimum Catalog described above, by using the following capture format:
REQUESTED INFORMATION
SECTION REPORT IDENTIFIER
PERIOD START
PERIOD END
INSTITUTION KEY
REPORT
SECTION FINANCIAL INFORMATION
CONCEPT
CURRENCY
DATA
Crowdfunding Institutions will report the information indicated in this series,
which must comply with the validations and quality standards indicated by the National Banking and Securities Commission (Commission), adjusting to the characteristics and specifications. Once the validations and quality standards are met, the SITI will generate an electronic receipt.
The information must be sent only once and will be received assuming it meets all the characteristics
and specifications, in virtue of which it cannot be modified and must present consistency with the
different reports in which the same information is included at a different level of aggregation, therefore, if it does not meet the required quality and characteristics or has been presented incompletely, it will be considered
as non-compliance with the obligation of its presentation and, consequently, the corresponding
sanctions will be imposed in accordance with the applicable legal provisions.
Crowdfunding Institutions
Series R01 Minimum Catalog
Report A-0112 Minimum Catalog
Includes figures in national currency, foreign currency, UMA and UDIS valued in pesos
Figures in pesos
Concept
National currency,
UMA and UDIS
valued
Foreign currency
valued
OFF-BALANCE SHEET ACCOUNTS
Operations on behalf of clients
Clients current accounts
Applicant deposits
Debt
Equity
Co-ownership or royalties
Investor deposits
Margin accounts
Other current accounts
Custody operations
Financial instruments of clients received in custody
Other accounts in custody
Administration operations
Client virtual assets
Financial instruments of clients received in administration
Debt
Equity
Co-ownership or royalties
Collaterals received as guarantee on behalf of applicants
Collaterals delivered as guarantee on behalf of clients
In derivative financial instruments
Government debt
Bank debt
Other debt securities
Equity financial instruments
Others
Other collaterals delivered as guarantee for other operations on behalf of clients
Operations for the purchase of financial instruments
Derivatives
Of futures and forward contracts of clients (notional amount)
Of options
Of swaps
Of packages of client derivative financial instruments
Others
Operations for the sale of financial instruments
Derivatives
Of futures and forward contracts of clients (notional amount)
Of options
Of swaps
Of packages of client derivative financial instruments
Others
Goods in mandate
Other administration operations
Operations on own account
Contingent assets and liabilities
Collaterals received by the entity
Cash managed in trust
Government debt
Bank debt
Other debt securities
Equity financial instruments
Others
Collaterals received and sold by the entity
Government debt
Bank debt
Other debt securities
Equity financial instruments
Others
Other registration accounts
ASSETS
Cash and cash equivalents
Cash
Banks
Immediate collection documents
Investments available on demand
Restricted or pledged cash and cash equivalents
Foreign exchange to be received
Foreign exchange to be delivered
Cash managed in trust
Others
Others
Margin accounts (derivative financial instruments)
Cash
Investments in financial instruments
Other assets
Investments in financial instruments
Negotiable financial instruments
Negotiable financial instruments without restriction
Government debt
In position
To be delivered
Bank debt
In position
To be delivered
Other debt securities
In position
To be delivered
Equity financial instruments
In position
To be delivered
Negotiable financial instruments restricted or pledged
Government debt
In position
To be received
Bank debt
In position
To be received
Other debt securities
In position
To be received
Equity financial instruments
In position
To be received
Financial instruments to collect or sell
Financial instruments to collect or sell without restriction
Government debt
In position
To be delivered
Bank debt
In position
To be delivered
Other debt securities
In position
To be delivered
Financial instruments to collect or sell restricted or pledged
Government debt
In position
To be received
Bank debt
In position
To be received
Other debt securities
In position
To be received
Financial instruments to collect principal and interest
Financial instruments to collect principal and interest without restriction
Government debt
In position
To be delivered
Bank debt
In position
To be delivered
Other debt securities
In position
To be delivered
Financial instruments to collect principal and interest restricted or pledged
Government debt
In position
To be received
Bank debt
In position
To be received
Other debt securities
In position
To be received
Estimation of expected credit losses for investments in financial instruments to collect principal and
interest
Financial instruments to collect principal and interest without restriction
Government debt
In position
To be delivered
Bank debt
In position
To be delivered
Other debt securities
In position
To be delivered
Financial instruments to collect principal and interest restricted or pledged
Government debt
In position
To be received
Bank debt
In position
To be received
Other debt securities
In position
To be received
Repo debtors (debtor balance)
Derivative financial instruments
For trading purposes
Futures to be received
Forwards to be received
Options
Swaps
Structured operations
Valuation
Impairment
Packages of derivative financial instruments
Valuation
Impairment
For hedging purposes
Futures to be received
Forwards to be received
Options
Swaps
Structured operations
Valuation
Impairment
Packages of derivative financial instruments
Valuation
Impairment
Virtual assets
Restricted virtual assets
Unrestricted virtual assets
Benefits to be received in securitization operations
Benefits on the remainder in securitization operations
Asset for administration of transferred financial assets
Accounts receivable
Debtors from settlement of operations
Foreign exchange sales and purchases
Investments in financial instruments
Repos
Derivative financial instruments
By issuance of securities
Virtual assets
Debtors from margin accounts
Debtors from collaterals granted in cash
Operations with financial instruments
Operations not carried out in recognized markets (OTC)
Others
Other debtors
Premiums, commissions, and rights to be received
Clients
Loans and other debts of personnel
Other debtors
Taxes to be recovered
Conditional accounts receivable
Other accounts receivable
Estimation of expected credit losses
Other debtors
Conditional accounts receivable
Other accounts receivable
Long-term assets available for sale
Subsidiaries
Belonging to the financial sector
Not belonging to the financial sector
Associates
Belonging to the financial sector
Not belonging to the financial sector
Joint ventures
Belonging to the financial sector
Not belonging to the financial sector
Other permanent investments
Belonging to the financial sector
Not belonging to the financial sector
Other long-term assets available for sale
Belonging to the financial sector
Not belonging to the financial sector
Assets related to discontinued operations
Prepayments and other assets
Deferred charges
Insurance to be amortized
Other deferred charges
Prepayments
Interest paid in advance
Commissions paid in advance
Advances or provisional payments of taxes
Rent paid in advance
Other prepayments
Guarantee deposits
Employee benefits assets
Plan assets to cover employee benefits
Direct long-term benefits
Post-employment benefits
Pensions
Seniority premium
Other post-employment benefits
Deferred employee participation in profits (in favor)
Estimation for non-recoverable deferred PTU
Other short and long-term assets
Properties, furniture, and equipment
Properties, furniture, and equipment
Land
Buildings
Buildings under construction
Transport equipment
Computer equipment
Furniture
Adaptations and improvements
Other properties, furniture, and equipment
Revaluation of properties, furniture, and equipment (1)
Land
Buildings
Buildings under construction
Transport equipment
Computer equipment
Furniture
Adaptations and improvements
Other revaluations of properties, furniture, and equipment
Accumulated depreciation of properties, furniture, and equipment
Accumulated depreciation of properties, furniture, and equipment
Buildings
Transport equipment
Computer equipment
Furniture
Adaptations and improvements
Other accumulated depreciations of properties, furniture, and equipment
Revaluation of accumulated depreciation of properties, furniture, and equipment (1)
Buildings
Transport equipment
Computer equipment
Furniture
Adaptations and improvements
Other revaluations of accumulated depreciation of properties, furniture, and equipment
Assets for right of use of properties, furniture, and equipment
Land
Buildings
Transport equipment
Computer equipment
Furniture
Other properties, furniture, and equipment
Depreciation of assets for right of use of properties, furniture, and equipment
Buildings
Transport equipment
Computer equipment
Furniture
Other properties, furniture, and equipment
Permanent investments
Subsidiaries
Belonging to the financial sector
Not belonging to the financial sector
Associates
Belonging to the financial sector
Not belonging to the financial sector
Joint ventures
Belonging to the financial sector
Not belonging to the financial sector
Other permanent investments
Belonging to the financial sector
Not belonging to the financial sector
Deferred income tax asset (net)
Deferred income taxes (in favor)
Temporary differences
Tax losses
Tax credits
Estimation for non-recoverable deferred income tax assets
Temporary differences
Tax losses
Tax credits
Intangible assets
Other intangible assets
Revaluation of other intangible assets (1)
Accumulated amortization of other intangible assets
Accumulated amortization of other intangible assets
Revaluation of accumulated amortization of other intangible assets (1)
Assets for right to use intangible assets
Amortization of assets for right to use intangible assets
Goodwill
Goodwill
From subsidiaries
From associates
From joint ventures
Revaluation of goodwill (1)
From subsidiaries
From associates
From joint ventures
LIABILITY
Securities liabilities
Securities certificates
Nominal value and interest
Transaction costs
Premium or discount on placement
Others
Nominal value and interest
Transaction costs
Premium or discount on placement
Bank loans and loans from other entities
Short-term
Loans from multiple banking institutions
Loans from foreign banks
Loans from development banking institutions
Loans from other entities
Long-term
Loans from multiple banking institutions
Loans from foreign banks
Loans from development banking institutions
Loans from other entities
Obligation to return client deposits invested in repurchase agreements
Collaterals sold
Repurchase agreements (creditor balance)
Obligation of the pledgor to return collateral to the pledgee
Collaterals sold
Government debt
Bank debt
Other debt securities
Derivative financial instruments
Collaterals sold
Government debt
Bank debt
Other debt securities
Equity financial instruments
Others
Other collaterals sold
Derivative financial instruments
For trading
Futures to deliver
Forward contracts to deliver
Options
Swaps
Structured operations
Packages of derivative financial instruments
For hedging
Futures to deliver
Forward contracts to deliver
Options
Swaps
Structured operations
Packages of derivative financial instruments
Obligations in securitization operations
Liabilities for administration of transferred financial assets
Lease liability
Other payables
Creditors from settlement of operations
Foreign exchange sales and purchases
Investments in financial instruments
Repurchase agreements
Derivative financial instruments
Virtual assets
Creditors from margin accounts
Creditors from cash collaterals received
Operations with financial instruments
Operations not carried out in recognized markets (OTC)
Others
Contributions payable
Value added tax
Other taxes and duties payable
Taxes and social security contributions withheld for payment
Various creditors and other payables
Commissions payable on outstanding operations
Creditors for acquisition of assets
Dividends payable
Creditors for maintenance services
Provisions for various obligations
Fees and rents
Promotion and advertising expenses
Technology expenses
Other provisions
Other various creditors
Liabilities related to assets held for sale
Liabilities related to discontinued operations
Other financial instruments qualifying as liabilities
Subordinated obligations in circulation
Mandatory conversion
Nominal value and interest
Transaction costs
Premium or discount on placement
Conversion at holder's option
Nominal value and interest
Transaction costs
Premium or discount on placement
Conversion at issuer's option
Nominal value and interest
Transaction costs
Premium or discount on placement
Non-convertible
Nominal value and interest
Transaction costs
Premium or discount on placement
Contributions for future capital increases pending formalization in shareholders' meeting
Others
Obligations associated with the retirement of components of property, plant and equipment
Income tax liability
Taxes incurred
Income taxes (provision)
Income taxes (adjustment for definitive tax)
Deferred taxes
Temporary differences
Employee benefits liabilities
Short-term direct benefits
Long-term direct benefits
Post-employment benefits
Pensions
Seniority premium
Other post-employment benefits
Termination benefits
Termination benefits for reasons other than restructuring
Termination benefits due to restructuring
Workers' participation in profits incurred
Deferred workers' participation in profits
Deferred credits and advance collections
Deferred credits
Other income to be applied
Other deferred credits
Advance collections
Interest collected in advance
Commissions collected in advance
Advance collections of goods promised for sale or with reservation of ownership
Other advance collections
EQUITY CAPITAL
Contributed capital
Social capital
Unpaid social capital
Increase due to updating of paid social capital (1)
Contributions for future capital increases formalized in shareholders' meeting
Increase due to updating of contributions for future capital increases formalized in shareholders' meeting (1)
Share premium
Increase due to updating of share premium (1)
Other financial instruments qualifying as equity
Increase due to updating of other financial instruments qualifying as equity (1)
Earned capital
Capital reserves
Legal reserve
Other reserves
Increase due to updating of capital reserves (1)
Accumulated results
Results from prior periods
Results to be applied
Results from accounting changes and error corrections
Increase due to updating of results from prior periods (1)
Other comprehensive income
Valuation of financial instruments to collect or sell
Valuation
Effect of deferred income tax and PTU
Estimation for non-recoverable deferred income tax and PTU
Increase due to updating of valuation of financial instruments to collect or sell (1)
Valuation of virtual assets
Valuation
Effect of deferred income tax and PTU
Estimation for non-recoverable deferred income tax and PTU
Increase due to updating of valuation of virtual assets (1)
Valuation of derivative financial instruments for cash flow hedging
Valuation
Effect of deferred income tax and PTU
Estimation for non-recoverable deferred income tax and PTU
Increase due to updating of valuation of derivative financial instruments for cash flow hedging (1)
Remeasurement of defined employee benefits
Actuarial results in obligations
Valuation
Effect of deferred income tax and PTU
Estimation for non-recoverable deferred income tax and PTU
Result in the return of plan assets
Valuation
Effect of deferred income tax and PTU
Estimation for non-recoverable deferred income tax and PTU
Increase due to updating of remeasurement of defined employee benefits (1)
Accumulated effect from translation
Valuation
Effect of deferred income tax and PTU
Estimation for non-recoverable deferred income tax and PTU
Increase due to updating of accumulated effect from translation (1)
Participation in OCI of other entities
Valuation
Effect of deferred income tax and PTU
Estimation for non-recoverable deferred income tax and PTU
Increase due to updating of participation in OCI of other entities (1)
STATEMENT OF COMPREHENSIVE INCOME
Commissions collected
Account opening commission
Borne by the applicant
Borne by the investor
Administration commission
Borne by the applicant
Borne by the investor
Custody commission
Borne by the applicant
Borne by the investor
Sales and purchases of financial instruments
Sales and purchases of virtual assets
Other commissions and fees collected
Increase due to updating of commissions collected (1)
Commissions paid
Loans received
Debt placement
Sales and purchases of virtual assets
Other commissions and fees paid
Increase due to updating of commissions paid (1)
Profit from sales and purchases
Negotiable financial instruments
Financial instruments to collect or sell
Financial instruments to collect principal and interest
Derivative financial instruments for trading
Derivative financial instruments for hedging
Sale of received collaterals
Virtual assets
Currencies
Increase due to updating of profit from sales and purchases (1)
Loss from sales and purchases
Negotiable financial instruments
Financial instruments to collect or sell
Financial instruments to collect principal and interest
Derivative financial instruments for trading
Derivative financial instruments for hedging
Sale of received collaterals
Virtual assets
Currencies
Transaction costs
For negotiable financial instruments
For financial instruments to collect or sell
For derivative financial instruments
For virtual assets
Increase due to updating of loss from sales and purchases (1)
Interest income
Interest on cash and cash equivalents
Banks
Own funds
Client funds
Restricted cash and cash equivalents
Interest and yields from margin accounts
Cash
Financial instruments
Other assets
Interest and yields from investments in financial instruments
For negotiable financial instruments
For financial instruments to collect or sell
For financial instruments to collect principal and interest
Interest and yields from repurchase operations
Income from operations with derivative financial instruments
Derivative financial instruments for trading
Derivative financial instruments for hedging
Premiums from debt placement
Securities liabilities
Other financial instruments qualifying as liabilities
Dividends from instruments qualifying as equity financial instruments
Gain from revaluation
Gain from revaluation changes
Revaluation of indexed instruments
Revaluation of items in UDIS
Revaluation of items in UMA
Increase due to updating of interest income (1)
Interest expenses
Interest on securities liabilities
Interest, transaction costs and discounts borne for issuance of other financial instruments qualifying as liabilities
Subordinated obligations
Mandatory conversion
Conversion at holder's option
Conversion at issuer's option
Non-convertible
Other issued securities
Interest on bank loans and loans from other entities
Premiums paid for early redemption of financial instruments qualifying as liabilities
Expenses from operations with derivative financial instruments
Derivative financial instruments for trading
Derivative financial instruments for hedging
Loss from revaluation
Loss from revaluation changes
Revaluation of indexed instruments
Revaluation of items in UDIS
Revaluation of items in UMA
Interest on lease liabilities
Increase due to updating of interest expenses (1)
Result from fair value measurement
Result from fair value measurement
Negotiable financial instruments
Derivative financial instruments for trading
Derivative financial instruments for hedging
Financial instruments to collect or sell
Collaterals sold
Estimation of expected credit losses for investments in financial instruments
Loss from impairment or effect from reversal of impairment of financial instruments and derivative financial instruments
Financial instruments to collect or sell
Financial instruments to collect principal and interest
Derivative financial instruments
Result from foreign exchange valuation
Increase due to updating of result from fair value measurement (1)
Net monetary position result (financial margin from intermediation) (1)
Net monetary position result from positions generating financial margin (debtor balance)
Net monetary position result from positions generating financial margin (creditor balance)
Increase due to updating of net monetary position result (financial margin) (1)
Other operating income (expenses)
Costs and expenses incurred in collection management
Commissions in collection management
Recoveries
Taxes
Excess in benefits to receive in securitization operations
Other recoveries
Impacts on the estimation of expected credit losses
Losses
Labor relations and job security
Frauds
Internal
External
Natural disasters and other events
Clients, products and business practices
Business incidents and system failures
Execution, delivery and process management
Other losses
Donations
Loss in custody and administration of goods
Loss from impairment or effect from reversal of impairment of other assets
Interest borne in financing for acquisition of assets
Result in sale of property, plant and equipment
Cancellation of other liability accounts
Interest from loans to officials and employees
Result from valuation of benefits to receive in securitization operations
Result from valuation of asset for administration of transferred financial assets
Result from valuation of liability for administration of transferred financial assets
Result in benefits to receive in securitization operations
Other items of operating income (expenses)
Net monetary position result originated by items not related to financial margin (1)
Result from revaluation of items not related to financial margin
Increase due to updating of other operating income (expenses) (1)
Administration and promotion expenses
Short-term direct benefits
Workers' participation in profits
Workers' participation in profits incurred
Deferred workers' participation in profits
Estimation for non-recoverable deferred PTU
Other short-term direct benefits
Net cost of the period derived from long-term employee benefits
Long-term direct benefits
Post-employment benefits
Pensions
Seniority premium
Other post-employment benefits
Termination benefits
Termination benefits for reasons other than restructuring
Termination benefits due to restructuring
Fees
Rents
Insurance and bonds
Promotion and advertising expenses
Other taxes and duties
Non-deductible expenses
Technology expenses
Depreciations
Of the period
Loss from impairment or effect from reversal of impairment
Amortizations
Of the period
Loss from impairment or effect from reversal of impairment
Maintenance expenses
CNBV inspection and surveillance fees
Other administration and promotion expenses
Increase due to updating of administration and promotion expenses (1)
Participation in the net result of other entities
Result of the period from unconsolidated subsidiaries, associates and joint ventures
In unconsolidated subsidiaries
Belonging to the financial sector
Not belonging to the financial sector
In associates
Belonging to the financial sector
Not belonging to the financial sector
In joint ventures
Belonging to the financial sector
Not belonging to the financial sector
Dividends from permanent investments
Valuation of permanent investments available for sale
Adjustments associated with other permanent investments
Impairment or effect from reversal of impairment of permanent investments
Increase due to updating of participation in the net result of other entities (1)
Income taxes
Incurred income taxes
Incurred income taxes
Increase due to updating of incurred income taxes (1)
Deferred income taxes
Temporary differences
Tax losses
Tax credits
Estimation for non-recoverable income taxes
Temporary differences
Tax losses
Tax credits
Increase due to updating of deferred income taxes (1)
Discontinued operations
Discontinued operations
Increase due to updating of discontinued operations (1)
Other comprehensive income
Valuation of financial instruments to collect or sell
Period effect
Valuation
Effect of deferred income tax and PTU
Estimation for non-recoverable deferred income tax
Increase due to updating of valuation of financial instruments to collect or sell (1)
Period recycling
Valuation of derivative financial instruments for cash flow hedging
Period effect
Valuation
Effect of deferred income tax and PTU
Estimation for non-recoverable deferred income tax
Increase due to updating of valuation of derivative financial instruments for cash flow hedging (1)
Period recycling
Valuation of virtual assets
Period effect
Valuation
Effect of deferred income tax and PTU
Estimation for non-recoverable deferred income tax
Increase due to updating of valuation of virtual assets (1)
Period recycling
Remeasurement of defined employee benefits
Period effect
Valuation
Effect of deferred income tax and PTU
Estimation for non-recoverable deferred income tax
Increase due to updating of remeasurement of defined employee benefits (1)
Period recycling
Accumulated effect from translation
Period effect
Valuation
Effect of deferred income tax and PTU
Estimation for non-recoverable deferred income tax
Increase due to updating of accumulated effect from translation (1)
Period recycling
Participation in OCI of other entities
Period effect
Valuation
Effect of deferred income tax and PTU
Estimation for non-recoverable deferred income tax
Increase due to updating of participation in OCI of other entities (1)
Period recycling
Collective Financing Institutions
(1) These concepts will be applicable under an inflationary economic environment based on what is established in Financial Information Standard B-10 "Effects of Inflation", issued by the Mexican Council for Financial Information Standards, A.C.
SERIES R08 BANK LOANS AND LOANS FROM OTHER ENTITIES
This series is integrated by one (1) report, whose frequency of preparation and presentation must be monthly.
REPORT
D-0842
Disaggregation of obtained loans
In this report, information is collected that allows knowing the details of the loans granted to Collective Financing Institutions, such as the credit contracting date, the maturity date, the amount of the operation, the agreed interest rate, the guarantees backing it, the identification of the lender, the commissions paid, among others, as well as the information on credit follow-up.
CAPTURE FORMAT
Collective Financing Institutions will carry out the sending of the information related to the report R08-D-0842 Disaggregation of obtained loans, described above, by using the following capture format:
INFORMATION REQUESTED
REPORT IDENTIFIER SECTION
PERIOD START
PERIOD END
INSTITUTION KEY
LOAN IDENTIFIER SECTION
LOAN IDENTIFIER
LOAN STATUS
STATUS UPDATE DATE
LENDER IDENTIFICATION DATA SECTION
LENDER TYPE
NAME(S)/BUSINESS NAME OR CORPORATE NAME
PATERNAL SURNAMES
MATERNAL SURNAMES
COUNTRY OF ORIGIN
ACCOUNT DATA SECTION
IDENTIFIER OF THE ACCOUNT WHERE THE LOAN IS RECEIVED
OPERATION DATA SECTION
ACCOUNTING CLASSIFICATION (LOAN TYPE)
CONTRACTING OR OPENING DATE
MATURITY DATE
PRINCIPAL PAYMENT FREQUENCY
INTEREST PAYMENT FREQUENCY
CURRENCY TYPE
INITIAL LOAN AMOUNT IN ORIGIN CURRENCY
INITIAL LOAN AMOUNT REVALUED IN NATIONAL CURRENCY
EXCHANGE RATE
INTEREST RATE TYPE
VALUE OF THE ORIGINALLY AGREED RATE
VALUE OF THE APPLICABLE INTEREST RATE IN THE PERIOD
REFERENCE INTEREST RATE
ADJUSTMENT IN THE REFERENCE RATE
FREQUENCY OF RATE REVIEW
AMOUNT OF THE AGREED COMMISSION
CREDIT DISPOSITION TYPE
DESTINATION OF THE RESOURCES
LOAN FOLLOW-UP DATA SECTION
OUTSTANDING BALANCE AT PERIOD START
DUE CAPITAL
DUE INTERESTS
PRINCIPAL PAYMENTS
INTERESTS PAID
OTHER COMMISSIONS PAID
UNPAID ACCRUED INTERESTS
OUTSTANDING BALANCE AT PERIOD END
PERCENTAGE OF CREDIT DISBURSED
DATE OF LAST PAYMENT MADE
DATE OF NEXT IMMEDIATE PAYMENT
TOTAL AMOUNT OF NEXT IMMEDIATE PAYMENT
LOAN GUARANTEE IDENTIFICATION DATA SECTION
GUARANTEE TYPE
INITIAL VALUE
UPDATED VALUE
VALUATION DATE
Collective Financing Institutions will report the information indicated in this series, which must comply with the validations and quality standards indicated by the National Banking and Securities Commission (Commission), adjusting to the characteristics and specifications. Once the validations and quality standards are met, the SITI will generate an electronic receipt of acknowledgment.
The information must be sent only once and will be received assuming it meets all characteristics and specifications, for which it cannot be modified and must present consistency with the various reports in which the same information is included at a different level of integration, therefore, if it does not meet the required quality and characteristics or has been presented incompletely, the obligation of its presentation will be considered unfulfilled and, consequently, the corresponding sanctions will be imposed in accordance with the applicable legal provisions.
SERIES R10 RECLASSIFICATIONS
This series is integrated by two (2) reports, whose frequency of preparation and presentation must be monthly.
REPORTS
A-10112
Reclassifications in the statement of financial position
In this report, balances at the end of the period are requested for the concepts of the regulatory report A-0112 Minimum Catalog, as well as the respective movements for presentation and compensations according to accounting criteria
carried out for the purpose of presenting the items of the financial statement of the Collective Financing Institution without consolidation.
A-10122
Reclassifications in the statement of comprehensive income
In this report, balances at the end of the period for the concepts of the regulatory report A-0112 Minimum Catalog are requested, as well as the respective movements for presentation and compensations according to accounting criteria carried out for the purpose of presenting the items of the statement of comprehensive income of the Collective Financing Institution without consolidation.
For the completion of reports A-10112 and A-10122, the following aspects must be taken into consideration:
Data referring to balances and amounts must be presented in national currency, foreign currency, UMA and UDIS valued in pesos and foreign currency valued in pesos using the exchange rate indicated in the current accounting criteria. These amounts and balances must be presented in pesos, with four decimal places, without commas. For example: $20,585.7000 would be 20585.7000.
CAPTURE FORMAT
Collective Financing Institutions will carry out the sending of information related to reports A-10112 Reclassifications in the statement of financial position and A-10122 Reclassifications in the statement of comprehensive income, described above, by using the following capture format:
REQUESTED INFORMATION
SECTION REPORT IDENTIFIER PERIOD START PERIOD END INSTITUTION KEY REPORT
SECTION FINANCIAL INFORMATION CONCEPT BALANCE TYPE MOVEMENT TYPE DATA
Collective Financing Institutions will report the information indicated in this series, which must comply with the validations and quality standards indicated by the National Banking and Securities Commission (Commission), adjusting to the characteristics and specifications. Once the validations and quality standards are met, the SITI will generate an electronic receipt of acknowledgment.
The information must be sent only once and will be received assuming it meets all characteristics and specifications, for which reason it cannot be modified and must present consistency with the various reports in which the same information is included with a different level of integration; therefore, if it does not meet the required quality and characteristics or has been presented incompletely, the obligation to present it will be considered unfulfilled, and consequently, the corresponding sanctions will be imposed in accordance with the applicable legal provisions.
Collective Financing Institutions
Series R10 Reclassifications
Report A-10112 Reclassifications in the statement of financial position
Includes figures in national currency, foreign currency, UMA and UDIS valued in pesos
Figures in pesos
Concept Minimum catalog balance Movements for presentation according to accounting criteria Compensations according to accounting criteria Statement of financial position without consolidation (1) (2) (A) Debit Credit Debit Credit National currency, UMA and UDIS Foreign currency Total (B)* = (A) + (1) + (2)
OFF-BALANCE SHEET ACCOUNTS Operations on behalf of clients Clients current accounts Applicant deposits Debt Capital Co-ownership or royalties Investor deposits Margin accounts Other current accounts Custody operations Financial instruments of clients received in custody Other accounts in custody Administration operations Client virtual assets Financial instruments of clients received in administration Debt Capital Co-ownership or royalties Collateral received as guarantee on behalf of applicants Collateral delivered as guarantee on behalf of clients In derivative financial instruments Government debt Bank debt Other debt securities Equity financial instruments Others Other collateral delivered as guarantee for other operations on behalf of clients Operations for the purchase of financial instruments Derivatives Client futures and forward contracts (notional amount) Options Swaps Client derivative financial instrument packages Others Operations for the sale of financial instruments Derivatives Client futures and forward contracts (notional amount) Options Swaps Client derivative financial instrument packages Others Assets in mandate Other administration operations Operations on own account Contingent assets and liabilities Collateral received by the entity Cash managed in trust Government debt Bank debt Other debt securities Equity financial instruments Others Collateral received and sold by the entity Government debt Bank debt Other debt securities Equity financial instruments Others Other registration accounts
ASSET Cash and cash equivalents Cash Banks Immediate collection documents Investments available on demand Restricted or pledged cash and cash equivalents Foreign currencies to be received Foreign currencies to be delivered Cash managed in trust Others Others Margin accounts (derivative financial instruments) Cash Investments in financial instruments Other assets Investments in financial instruments Negotiable financial instruments Unrestricted negotiable financial instruments Government debt In position To be delivered Bank debt In position To be delivered Other debt securities In position To be delivered Equity financial instruments In position To be delivered Restricted or pledged negotiable financial instruments Government debt In position To be received Bank debt In position To be received Other debt securities In position To be received Equity financial instruments In position To be received Financial instruments to collect or sell Unrestricted financial instruments to collect or sell Government debt In position To be delivered Bank debt In position To be delivered Other debt securities In position To be delivered Restricted or pledged financial instruments to collect or sell Government debt In position To be received Bank debt In position To be received Other debt securities In position To be received Financial instruments to collect principal and interest Unrestricted financial instruments to collect principal and interest Government debt In position To be delivered Bank debt In position To be delivered Other debt securities In position To be delivered Restricted or pledged financial instruments to collect principal and interest Government debt In position To be received Bank debt In position To be received Other debt securities In position To be received Expected credit loss estimate for investments in financial instruments to collect principal and interest Unrestricted financial instruments to collect principal and interest Government debt In position To be delivered Bank debt In position To be delivered Other debt securities In position To be delivered Restricted or pledged financial instruments to collect principal and interest Government debt In position To be received Bank debt In position To be received Other debt securities In position To be received Repo debtors (debit balance) Derivative financial instruments For trading purposes Futures to be received Forwards to be received Options Swaps Structured operations Valuation Impairment Derivative financial instrument packages Valuation Impairment For hedging purposes Futures to be received Forwards to be received Options Swaps Structured operations Valuation Impairment Derivative financial instrument packages Valuation Impairment Virtual assets Restricted virtual assets Unrestricted virtual assets Benefits to be received in securitization operations Benefits on the remainder in securitization operations Asset from administration of transferred financial assets Accounts receivable Debtors from settlement of operations Foreign exchange sales and purchases Investments in financial instruments Repos Derivative financial instruments From issuance of securities Virtual assets Debtors from margin accounts Debtors from collateral granted in cash Operations with financial instruments Operations not carried out in recognized markets (OTC) Others Other debtors Premiums, commissions and rights to be received Clients Loans and other debts of personnel Other debtors Taxes to be recovered Conditional accounts receivable Other accounts receivable Expected credit loss estimate Other debtors Conditional accounts receivable Other accounts receivable Accounts receivable (net) Long-term assets available for sale Subsidiaries Belonging to the financial sector Not belonging to the financial sector Associates Belonging to the financial sector Not belonging to the financial sector Joint ventures Belonging to the financial sector Not belonging to the financial sector Other permanent investments Belonging to the financial sector Not belonging to the financial sector Other long-term assets available for sale Belonging to the financial sector Not belonging to the financial sector Assets related to discontinued operations Prepayments and other assets Deferred charges Insurance to be amortized Other deferred charges Prepayments Interest paid in advance Commissions paid in advance Advance or provisional payments of taxes Rent paid in advance Other prepayments Guarantee deposits Employee benefits assets Plan assets to cover employee benefits Long-term direct benefits Post-employment benefits Pensions Seniority premium Other post-employment benefits Deferred employee participation in profits (in favor) Estimate for non-recoverable deferred PTU Other short and long-term assets Properties, furniture and equipment Properties, furniture and equipment Land Buildings Buildings under construction Transport equipment Computing equipment Furniture Adaptations and improvements Other properties, furniture and equipment Revaluation of properties, furniture and equipment (1) Land Buildings Buildings under construction Transport equipment Computing equipment Furniture Adaptations and improvements Other revaluations of properties, furniture and equipment Accumulated depreciation of properties, furniture and equipment Accumulated depreciation of properties, furniture and equipment Buildings Transport equipment Computing equipment Furniture Adaptations and improvements Other accumulated depreciations of properties, furniture and equipment Revaluation of accumulated depreciation of properties, furniture and equipment (1) Buildings Transport equipment Computing equipment Furniture Adaptations and improvements Other revaluations of accumulated depreciation of properties, furniture and equipment Properties, furniture and equipment (net) Right-of-use assets for properties, furniture and equipment Land Buildings Transport equipment Computing equipment Furniture Other properties, furniture and equipment Depreciation of right-of-use assets for properties, furniture and equipment Buildings Transport equipment Computing equipment Furniture Other properties, furniture and equipment Right-of-use assets for properties, furniture and equipment (net) Permanent investments Subsidiaries Belonging to the financial sector Not belonging to the financial sector Associates Belonging to the financial sector Not belonging to the financial sector Joint ventures Belonging to the financial sector Not belonging to the financial sector Other permanent investments Belonging to the financial sector Not belonging to the financial sector Deferred income tax asset (net) Deferred income taxes (in favor) Temporary differences Tax losses Tax credits Estimate for non-recoverable deferred income taxes Temporary differences Tax losses Tax credits Intangible assets (net) Intangible assets Other intangible assets Revaluation of other intangible assets (1) Accumulated amortization of other intangible assets Accumulated amortization of other intangible assets Revaluation of accumulated amortization of other intangible assets (1) Right-of-use assets for intangible assets (net) Right-of-use assets for intangible assets Amortization of right-of-use assets for intangible assets Goodwill Goodwill From subsidiaries From associates From joint ventures Revaluation of goodwill (1) From subsidiaries From associates From joint ventures
LIABILITY Market liabilities Market certificates Nominal value and interest Transaction costs Placement premium or discount Others Nominal value and interest Transaction costs Placement premium or discount Bank loans and loans from other entities Short-term Loans from multiple banking institutions Loans from foreign banks Loans from development banking institutions Loans from other entities Long-term Loans from multiple banking institutions Loans from foreign banks Loans from development banking institutions Loans from other entities Obligation to return client deposits invested in repo Collateral sold Repos (credit balance) Repo provider's obligation to return collateral to the repo taker Collateral sold Government debt Bank debt Other debt securities Derivative financial instruments Collateral sold Government debt Bank debt Other debt securities Equity financial instruments Others Other collateral sold Derivative financial instruments For trading purposes Futures to be delivered Forwards to be delivered Options Swaps Structured operations Derivative financial instrument packages For hedging purposes Futures to be delivered Forwards to be delivered Options Swaps Structured operations Derivative financial instrument packages Obligations in securitization operations Liabilities from administration of transferred financial assets Lease liability Other accounts payable Creditors from settlement of operations Foreign exchange sales and purchases Investments in financial instruments Repos Derivative financial instruments Virtual assets Creditors from margin accounts Creditors from collateral received in cash Operations with financial instruments Operations not carried out in recognized markets (OTC) Others Contributions to be paid Value added tax Other taxes and duties to be paid Taxes and social security contributions withheld for payment Other creditors and other accounts payable Commissions to be paid on ongoing operations Creditors for acquisition of assets Dividends to be paid Creditors for maintenance services Provisions for various obligations Fees and rents Promotion and advertising expenses Technology expenses Other provisions Other miscellaneous creditors Liabilities related to assets available for sale Liabilities related to discontinued operations Other financial instruments qualifying as liabilities Subordinated obligations in circulation Mandatory conversion Nominal value and interest Transaction costs Placement premium or discount Conversion at holder's decision Nominal value and interest Transaction costs Placement premium or discount Conversion at issuer's decision Nominal value and interest Transaction costs Placement premium or discount Non-convertible Nominal value and interest Transaction costs Placement premium or discount Contributions for future capital increases pending formalization in shareholders' meeting Others Obligations associated with the retirement of components of properties, furniture and equipment Income tax liability Taxes incurred Income taxes (provision) Income taxes (adjustment for definitive tax) Deferred taxes Temporary differences Employee benefits liabilities Short-term direct benefits Long-term direct benefits Post-employment benefits Pensions Seniority premium Other post-employment benefits Termination benefits Termination benefits for reasons other than restructuring Termination benefits due to restructuring Employee participation in profits incurred Deferred employee participation in profits Deferred credits and advance collections Deferred credits Other income to be applied Other deferred credits Advance collections Interest collected in advance Commissions collected in advance Advance collections of goods promised for sale or with retention of title Other advance collections
OWN CAPITAL Contributed capital Social capital Unpaid social capital Increase due to updating of paid social capital (1) Contributions for future capital increases formalized in shareholders' meeting Increase due to updating of contributions for future capital increases formalized in shareholders' meeting (1) Share premium Increase due to updating of share premium (1) Other financial instruments qualifying as capital Increase due to updating of other financial instruments qualifying as capital (1) Retained earnings Capital reserves Legal reserve Other reserves Increase due to updating of capital reserves (1) Accumulated results Result from prior periods Result to be applied Result from accounting changes and error corrections Increase due to updating of result from prior periods (1) Net result Other comprehensive income Valuation of financial instruments to collect or sell Valuation Effect of income taxes and deferred PTU Estimate for non-recoverable deferred income taxes and PTU Increase due to updating of valuation of financial instruments to collect or sell (1) Valuation of virtual assets Valuation Effect of income taxes and deferred PTU Estimate for non-recoverable deferred income taxes and PTU Increase due to updating of valuation of virtual assets (1) Valuation of derivative financial instruments for cash flow hedging Valuation Effect of income taxes and deferred PTU Estimate for non-recoverable deferred income taxes and PTU Increase due to updating of valuation of derivative financial instruments for cash flow hedging (1) Remeasurement of defined employee benefits Actuarial results in obligations Valuation Effect of income taxes and deferred PTU Estimate for non-recoverable deferred income taxes and PTU Result in the return of plan assets Valuation Effect of income taxes and deferred PTU Estimate for non-recoverable deferred income taxes and PTU Increase due to updating of remeasurement of defined employee benefits (1) Accumulated effect from translation Valuation Effect of income taxes and deferred PTU Estimate for non-recoverable deferred income taxes and PTU Increase due to updating of accumulated effect from translation (1) Participation in OCI of other entities Valuation Effect of income taxes and deferred PTU Estimate for non-recoverable deferred income taxes and PTU Increase due to updating of participation in OCI of other entities (1)
Collective Financing Institutions
(1) These concepts will be applicable under an inflationary economic environment based on what is established in Financial Information Standard B-10 "Effects of Inflation", issued by the Mexican Council of Financial Information Standards, A.C. (CINIF).
Collective Financing Institutions
Series R10 Reclassifications
Report A-10122 Reclassifications in the statement of comprehensive income
Includes figures in national currency, foreign currency, UMA and UDIS valued in pesos
Figures in pesos
Concept Minimum catalog balance Movements for presentation according to accounting criteria Compensations according to accounting criteria Statement of comprehensive income without consolidation (1) (2) (A) Debit Credit Debit Credit National currency, UMA and UDIS Foreign currency Total (B)* = (A) + (1) + (2)
Commissions collected Account opening commission On behalf of the applicant On behalf of the investor Administration commission On behalf of the applicant On behalf of the investor Custody commission On behalf of the applicant On behalf of the investor Sale and purchase of financial instruments Sale and purchase of virtual assets Other commissions and fees collected Increase due to updating of commissions collected (1) Commissions paid Loans received Debt placement Sale and purchase of virtual assets Other commissions and fees paid Increase due to updating of commissions paid (1)
RESULT FROM SERVICES Profit from sale and purchase Negotiable financial instruments Financial instruments to collect or sell Financial instruments to collect principal and interest Derivative financial instruments for trading purposes Derivative financial instruments for hedging purposes Sale of received collateral Virtual assets Foreign currencies Increase due to updating of profit from sale and purchase (1) Loss from sale and purchase Negotiable financial instruments Financial instruments to collect or sell Financial instruments to collect principal and interest Derivative financial instruments for trading purposes Derivative financial instruments for hedging purposes Sale of received collateral Virtual assets Foreign currencies Transaction costs For negotiable financial instruments For financial instruments to collect or sell For derivative financial instruments For virtual assets Increase due to updating of loss from sale and purchase (1) Interest income Interest on cash and cash equivalents Banks Own resources Client resources Restricted cash and cash equivalents Interest and yields in favor from margin accounts Cash Financial instruments Other assets Interest and yields in favor from investments in financial instruments For negotiable financial instruments
For financial instruments held to collect or sell
For financial instruments held to collect principal and interest
Interest and yields in favor in repo operations
Income from operations with financial derivative instruments
Financial derivative instruments for trading purposes
Financial derivative instruments for hedging purposes
Debt issuance premiums
Stock exchange liabilities
Other financial instruments that qualify as liabilities
Dividends from instruments that qualify as equity financial instruments
Gain on revaluation
Gain on revaluation changes
Revaluation of indexed instruments
Revaluation of UDIS items
Revaluation of UMA items
Increase by updating interest income (1)
Interest expenses
Interest on stock exchange liabilities
Interest, transaction costs, and discounts payable for the issuance of other financial instruments that qualify as liabilities
Subordinated obligations
Of mandatory conversion
Of conversion by holder decision
Of conversion by issuer entity decision
Non-convertible
Other issued securities
Interest on bank loans and from other organizations
Premiums paid for the early redemption of financial instruments that qualify as liabilities
Expenses from operations with financial derivative instruments
Financial derivative instruments for trading purposes
Financial derivative instruments for hedging purposes
Loss on revaluation
Loss on revaluation changes
Revaluation of indexed instruments
Revaluation of UDIS items
Revaluation of UMA items
Interest on lease liabilities
Increase by updating interest expenses (1)
Result from valuation at fair value
Result from valuation at fair value
Negotiable financial instruments
Financial derivative instruments for trading purposes
Financial derivative instruments for hedging purposes
Financial instruments held to collect or sell
Collaterals sold
Estimation of expected credit losses for investments in financial instruments
Loss on impairment or effect of reversal of impairment of financial instruments and financial derivative instruments
Financial instruments held to collect or sell
Financial instruments held to collect principal and interest
Financial derivative instruments
Result from foreign currency valuation
Increase by updating the result from valuation at fair value (1)
Result from net monetary position (financial margin from intermediation) (1)
Result from monetary position from positions generating financial margin (debit balance)
Result from monetary position from positions generating financial margin (credit balance)
Increase by updating the result from net monetary position (financial margin) (1)
FINANCIAL MARGIN FROM INTERMEDIATION
Other income (expenses) from operations
Costs and expenses incurred in collection management
Commissions in collection management
Recoveries
Taxes
Excess in benefits to receive in securitization operations
Other recoveries
Charges to the estimation of expected credit losses
Losses
Labor relations and job security
Frauds
Internal
External
Natural disasters and other events
Clients, products, and business practices
Business incidents and system failures
Execution, delivery, and process management
Other losses
Donations
Loss in custody and administration of assets
Loss on impairment or effect of reversal of impairment of other assets
Interest payable in financing for asset acquisition
Result in sale of properties, furniture, and equipment
Cancellation of other liability accounts
Interest in favor from loans to officials and employees
Result from valuation of benefits to receive in securitization operations
Result from valuation of assets for administration of transferred financial assets
Result from valuation of liabilities for administration of transferred financial assets
Result in benefits to receive in securitization operations
Other items of operations income (expenses)
Result from monetary position originated by items not related to financial margin (1)
Result from revaluation of items not related to financial margin
Increase by updating other income (expenses) from operations (1)
Administration and promotion expenses
Short-term direct benefits
Workers' participation in profits
Workers' participation in profits accrued
Deferred workers' participation in profits
Estimation for non-recoverable deferred PTU
Other short-term direct benefits
Net cost of the period derived from long-term employee benefits
Long-term direct benefits
Post-employment benefits
Pensions
Seniority premium
Other post-employment benefits
Termination benefits
Termination benefits for reasons other than restructuring
Termination benefits due to restructuring
Fees
Rents
Insurance and bonds
Promotion and advertising expenses
Taxes and various duties
Non-deductible expenses
Technology expenses
Depreciations
Of the period
Loss on impairment or effect of reversal of impairment
Amortizations
Of the period
Loss on impairment or effect of reversal of impairment
Maintenance expenses
CNBV inspection and surveillance fees
Other administration and promotion expenses
Increase by updating administration and promotion expenses (1)
OPERATING RESULT
Participation in the net result of other entities
Result of the exercise of non-consolidated subsidiaries, associates, and joint ventures
In non-consolidated subsidiaries
Belonging to the financial sector
Not belonging to the financial sector
In associates
Belonging to the financial sector
Not belonging to the financial sector
In joint ventures
Belonging to the financial sector
Not belonging to the financial sector
Dividends from permanent investments
Valuation of available-for-sale permanent investments
Adjustments associated with other permanent investments
Impairment or effect of reversal of impairment of permanent investments
Increase by updating participation in the net result of other entities (1)
RESULT BEFORE INCOME TAXES
Income taxes
Income taxes accrued
Income taxes accrued
Increase by updating accrued income taxes (1)
Deferred income taxes
Temporary differences
Tax losses
Tax credits
Estimation for non-recoverable income taxes
Temporary differences
Tax losses
Tax credits
Increase by updating deferred income taxes (1)
RESULT OF CONTINUING OPERATIONS
Discontinued operations
Discontinued operations
Increase by updating discontinued operations (1)
NET RESULT
Other comprehensive income
Valuation of financial instruments held to collect or sell
Period effect
Valuation
Effect of income taxes and deferred PTU
Estimation for non-recoverable deferred income taxes
Increase by updating the valuation of financial instruments held to collect or sell (1)
Period recycling
Valuation of cash flow hedging financial derivative instruments
Period effect
Valuation
Effect of income taxes and deferred PTU
Estimation for non-recoverable deferred income taxes
Increase by updating the valuation of cash flow hedging financial derivative instruments of cash flow (1)
Period recycling
Valuation of virtual assets
Period effect
Valuation
Effect of income taxes and deferred PTU
Estimation for non-recoverable deferred income taxes
Increase by updating the valuation of virtual assets (1)
Period recycling
Remeasurement of defined employee benefits
Period effect
Valuation
Effect of income taxes and deferred PTU
Estimation for non-recoverable deferred income taxes
Increase by updating the remeasurement of defined employee benefits (1)
Period recycling
Accumulated effect from conversion
Period effect
Valuation
Effect of income taxes and deferred PTU
Estimation for non-recoverable deferred income taxes
Increase by updating the accumulated effect from conversion (1)
Period recycling
Participation in OCI of other entities
Period effect
Valuation
Effect of income taxes and deferred PTU
Estimation for non-recoverable deferred income taxes
Increase by updating participation in OCI of other entities (1)
Period recycling
COMPREHENSIVE RESULT
BASIC EARNINGS PER ORDINARY SHARE (2)
Collective Financing Institutions
(1) These concepts will be applicable under an inflationary economic environment based on what is established in Financial Reporting Standard B-10 "Effects of Inflation", issued by the Mexican Council of Financial Reporting Standards, A.C. (CINIF).
(2) Determined in accordance with what is established in Bulletin B-14 "Earnings per share", issued by the Mexican Council of Financial Reporting Standards, A.C. (CINIF).
SERIES R13 FINANCIAL STATEMENTS
This series is integrated by four (4) reports, whose frequency of preparation and presentation must be monthly for reports R13 B-13212 Statement of Financial Position and R13 B-13222 Statement of Comprehensive Income, and quarterly for reports R13 A-13112 Statement of Changes in Equity and R13 A-13162 Statement of Cash Flows.
REPORTS
A-13112
Statement of Changes in Equity
The statement of changes in equity aims to present information on changes in the investment of the owners of the Collective Financing Institution during the accounting period. It must show the reconciliation between initial and final balances of the period for each of the items that form part of equity.
In this report, balances of all equity concepts of the Collective Financing Institution are requested, showing the movements occurred in the period being reported. The movements refer to the increases or decreases of equity originated by owner movements, reserve movements, and comprehensive income.
A-13162
Statement of Cash Flows
The statement of cash flows has the main objective of providing information regarding changes in resources and financing sources during the accounting period. The changes refer to differences classified according to resources generated or used by operations, financing activities, and investment activities.
Likewise, the increase or decrease in cash and equivalents in the period must be reflected.
B-13212
Statement of Financial Position
The statement of financial position aims to present the value of assets and rights, of real, direct, or contingent obligations, as well as of equity capital of the Collective Financing Institution at a specific date.
The statement of financial position, therefore, must adequately show on consistent bases, the position of the Collective Financing Institution in terms of its assets, liabilities, equity capital, and off-balance sheet accounts, so that the economic resources available to the institution can be evaluated, as well as its financial structure.
Additionally, the statement of financial position must fulfill the objective of being a useful tool for analysis.
B-13222
Statement of Comprehensive Income
The statement of comprehensive income aims to show information relative to the result of its operations in equity capital and, therefore, of income and expenses and other comprehensive income (OCI) and comprehensive income.
In this report, relevant information on operations carried out by the Collective Financing Institution is requested and must fulfill the objective of being a useful tool for analysis.
For the completion of reports A-13112, A-13162, B-13212, and B-13222, the following aspects must be considered:
Data referring to balances must be presented in national currency, foreign currency, UMA, and UDIS valued in pesos and foreign currency valued in pesos using the exchange rate indicated in the current accounting criteria. These amounts and balances must be presented in pesos, with four decimal places, and without commas. For example: $20,585.7000 would be 20585.7000.
CAPTURE FORMAT
Collective Financing Institutions will carry out the submission of information related to reports A-13112 Statement of Changes in Equity and A-13162 Statement of Cash Flows, described above, by using the following capture format:
REQUESTED INFORMATION
Statement of Changes in Equity and Statement of Cash Flows
SECTION REPORT IDENTIFIER
PERIOD START
PERIOD END
INSTITUTION KEY
REPORT
SECTION FINANCIAL INFORMATION
CONCEPT
BALANCE TYPE
DATA
Collective Financing Institutions will carry out the submission of information related to reports B-13212 Statement of Financial Position and B 13222 Statement of Comprehensive Income, described above, by using the following capture format:
REQUESTED INFORMATION
Statement of Financial Position and Statement of Comprehensive Income
SECTION REPORT IDENTIFIER
PERIOD START
PERIOD END
INSTITUTION KEY
REPORT
SECTION FINANCIAL INFORMATION
CONCEPT
DATA
Collective Financing Institutions will report the information indicated in this series, adhering to the characteristics and specifications for filling out and submitting information provided by the National Banking and Securities Commission (Commission). The information must comply with the established validations, as well as the quality standards indicated by this Commission, in addition to presenting consistency between the information contained in the various regulatory reports applicable in which the same information is included at a different level of integration. Likewise, it must be sent only once and will be received assuming it meets all required characteristics, by virtue of which it cannot be modified.
Once the information is received, it will be reviewed by the Commission and if it does not meet the quality and characteristics required or has been presented incompletely, the obligation to present it will be considered unfulfilled.
Collective Financing Institutions
Series R13 Financial Statements
Report A-13112 Statement of Changes in Equity Capital
Includes figures in national currency, foreign currency, UMA, and UDIS valued in pesos
Figures in pesos
Concept
Contributed capital
Earned capital
Total controlling interest participation
Non-controlling interest participation
Total Equity Capital
Share capital
Contributions for future capital increases formalized in shareholder meetings
Premium on share sales
Other financial instruments that qualify as equity
Capital reserves
Accumulated results
Valuation of financial instruments held to collect or sell
Valuation of virtual assets
Valuation of cash flow hedging financial derivative instruments
Remeasurement of defined employee benefits
Accumulated effect from conversion
Participation in OCI of other entities
Balance as of ___ of _________ of ___
Retrospective adjustments for accounting changes
Retrospective adjustments for error corrections
Balance as of ___ of _______ of ___ adjusted
OWNER MOVEMENTS
Share subscription
Capital contributions
Capital refunds
Dividend decree
Capitalization of other equity capital concepts
Changes in controlling participation that do not imply loss of control
Total
RESERVE MOVEMENTS
Capital reserves (1)
COMPREHENSIVE INCOME:
Net result
Other comprehensive income
Valuation of financial instruments held to collect or sell
Valuation of virtual assets
Valuation of cash flow hedging financial derivative instruments
Remeasurement of defined employee benefits
Accumulated effect from conversion
Participation in OCI of other entities
Total
Balance as of ___ of __________ of ___
Collective Financing Institutions
(1) The entity must show in this line, the amounts that represent increases or decreases to capital reserves
Collective Financing Institutions
Series R13 Financial Statements
Report A-13162 Statement of Cash Flows
Includes figures in national currency, foreign currency, UMA, and UDIS valued in pesos
Figures in pesos
Concept
Amount
Operating Activities
Result before income taxes
Adjustments for items associated with investment activities:
Depreciation of properties, furniture, and equipment
Amortizations of intangible assets
Losses or reversal of losses on impairment of long-term assets
Discontinued operations
Result from sale of long-term assets
Participation in the net result of other entities
Other adjustments for items associated with investment activities
Adjustments for items associated with financing activities
Interest associated with bank loans and from other organizations
Interest associated with financial instruments that qualify as liabilities
Interest associated with other financial instruments that qualify as equity
Other interest
Changes in operating items
Change in margin accounts (financial derivative instruments)
Change in investments in negotiable financial instruments (net)
Change in repo debtors (net)
Change in financial derivative instruments (asset)
Change in benefits to receive in securitization operations
Change in virtual assets
Change in accounts receivable (net)
Change in other operating assets (net)
Change in stock exchange liabilities
Change in sold collaterals
Change in financial derivative instruments (liability)
Change in obligations in securitization operations
Change in other operating liabilities
Change in hedging financial derivative instruments (of covered items related to operating activities)
Change in assets/liabilities for employee benefits
Change in other accounts payable
Change in other provisions
Income tax refunds
Income tax payments
Net cash flows from operating activities
Investment Activities
Collections associated with financial instruments held to collect or sell
Payments associated with financial instruments held to collect or sell
Collections associated with financial instruments held to collect principal and interest
Payments associated with financial instruments held to collect principal and interest
Collections from disposal of virtual assets
Payments for acquisition of virtual assets
Payments for acquisition of properties, furniture, and equipment
Collections from disposal of properties, furniture, and equipment
Payments for acquisition of subsidiaries
Collections from disposal of subsidiaries
Payments for acquisition of associates, joint ventures, and other permanent investments
Collections from disposal of associates, joint ventures, and other permanent investments
Collections of cash dividends from permanent investments
Payments for acquisition of intangible assets
Collections from disposal of intangible assets
Collections associated with cash flow hedging financial derivative instruments (of covered items related to investment activities)
Payments associated with cash flow hedging financial derivative instruments (of covered items related to investment activities)
Other collections for investment activities
Other payments for investment activities
Net cash flows from investment activities
Financing Activities
Collections from obtaining bank loans and from other organizations
Payments of bank loans and from other organizations
Payment of lease liability
Collections from share issuance
Payments for share capital refunds
Collections from issuance of other financial instruments that qualify as equity
Payments associated with other financial instruments that qualify as equity
Cash dividend payments
Payments associated with repurchase of own shares
Collections from issuance of financial instruments that qualify as liabilities
Payments associated with financial instruments that qualify as liabilities
Payments for interest on lease liability
Other collections for financing activities
Other payments for financing activities
Net cash flows from financing activities
Net increase or decrease in cash and cash equivalents
Effects from changes in the value of cash and cash equivalents
Cash and cash equivalents at the beginning of the period
Cash and cash equivalents at the end of the period
Collective Financing Institutions
Note: In accordance with what accounting criteria establish, the concepts appearing in this statement are shown in an exhaustive but not exhaustive manner. The opening of a greater number of concepts in order to provide a more detailed presentation of the information must be requested to the National Banking and Securities Commission.
Collective Financing Institutions
Series R13 Financial Statements
Report B-1321 Statement of Financial Position
Includes figures in national currency, foreign currency, UMA, and UDIS valued in pesos
Figures in pesos
Concept
Amount
OFF-BALANCE SHEET ACCOUNTS
Operations on behalf of clients
Clients current accounts
Applicant deposits
Debt
Capital
Co-ownership or royalties
Investor deposits
Margin accounts
Other current accounts
Custody operations
Financial instruments of clients received in custody
Other accounts in custody
Administration operations
Client virtual assets
Financial instruments of clients received in administration
Collaterals received as guarantee on behalf of applicants
Collaterals delivered as guarantee on behalf of clients
Financial instrument purchase operations
Financial instrument sale operations
Assets in mandate
Other administration operations
Operations on own account
Contingent assets and liabilities
Collaterals received by the entity
Cash administered in trust
Government debt
Bank Debt
Other Debt Instruments
Equity Financial Instruments
Others
Collateral Received and Sold by the Entity
Government Debt
Bank Debt
Other Debt Instruments
Equity Financial Instruments
Others
Other Register Accounts
ASSET
Cash and cash equivalents
Margin accounts (financial derivative instruments)
Investments in financial instruments
Negotiable financial instruments
Financial instruments to collect or sell
Financial instruments to collect principal and interest
Estimate of expected credit losses for investments in financial instruments to collect principal and interest
Repo debtors (debit balance)
Financial derivative instruments
For trading purposes
For hedging purposes
Virtual assets
Benefits to be received in securitization operations
Accounts receivable (net)
Long-term assets available for sale
Assets related to discontinued operations
Prepayments and other assets
Properties, furniture and equipment (net)
Assets for right of use of properties, furniture and equipment (net)
Permanent investments
Deferred income tax asset (net)
Intangible assets (net)
Assets for right of use of intangible assets (net)
Goodwill
LIABILITY
Securities liabilities
Bank and other organism loans
Short-term
Long-term
Obligation to return deposits of clients invested in repo
Collateral sold
Repos (credit balance)
Financial derivative instruments
Other collateral sold
Financial derivative instruments
For trading purposes
For hedging purposes
Obligations in securitization operations
Liabilities for administration of transferred financial assets
Lease liability
Other accounts payable
Creditors for settlement of operations
Creditors for margin accounts
Creditors for cash collateral received
Contributions payable
Diverse creditors and other accounts payable
Liabilities related to assets available for sale
Liabilities related to discontinued operations
Other financial instruments that qualify as liability
Subordinated obligations in circulation
Contributions for future capital increases pending formalization in shareholders' meeting
Others
Obligations associated with the withdrawal of components of properties, furniture and equipment
Income tax liability
Employee benefits liabilities
Deferred credits and advance payments
OWNERS' EQUITY
Controlling interest
Contributed capital
Share capital
Unissued share capital
Increase due to update of paid share capital (1)
Contributions for future capital increases formalized in shareholders' meeting
Increase due to update of contributions for future capital increases formalized in shareholders' meeting
(1)
Share premium
Increase due to update of share premium (1)
Other financial instruments that qualify as capital
Increase due to update of other financial instruments that qualify as capital (1)
Earned capital
Capital reserves
Increase due to update of capital reserves (1)
Accumulated results
Results of prior periods
Increase due to update of results of prior periods (1)
Net result
Other comprehensive income
Valuation of financial instruments to collect or sell
Increase due to update of valuation of financial instruments to collect or sell (1)
Valuation of virtual assets
Increase due to update of valuation of virtual assets (1)
Valuation of cash flow hedging financial derivative instruments
Increase due to update of valuation of cash flow hedging financial derivative instruments (1)
Remeasurement of defined employee benefits
Increase due to update of remeasurement of defined employee benefits (1)
Accumulated effect by conversion
Increase due to update of accumulated effect by conversion (1)
Participation in OCI of other entities
Increase due to update of participation in OCI of other entities (1)
Non-controlling interest
Net result attributable to non-controlling interest
Other non-controlling interest
Other comprehensive income attributable to non-controlling interest
Collective Financing Institutions
(1) These concepts will be applicable under an inflationary economic environment based on what is established in Financial Information Standard B-10 "Effects of Inflation", issued by the Mexican Council of Financial Information Standards, A.C. (CINIF).
Collective Financing Institutions
Series R13 Financial Statements
Report B-13222 Statement of Comprehensive Income
Includes figures in national currency, foreign currency, UMA and UDIS valued in pesos
Figures in pesos
Concept
Amount
Charged commissions
Paid commissions
RESULT FROM SERVICES
Profit from sales
Loss from sales
Interest income
Interest expenses
Result from fair value valuation
Net monetary position result (financial margin from intermediation) (1)
FINANCIAL MARGIN FROM INTERMEDIATION
Other operating income (expenses)
Administration and promotion expenses
OPERATING RESULT
Participation in the net result of other entities
RESULT BEFORE INCOME TAXES
Income taxes
RESULT FROM CONTINUING OPERATIONS
Discontinued operations
NET RESULT
Other comprehensive income
Valuation of financial instruments to collect or sell
Valuation of cash flow hedging financial derivative instruments
Valuation of virtual assets
Remeasurement of defined employee benefits
Accumulated effect by conversion
Participation in OCI of other entities
COMPREHENSIVE RESULT
Net result attributable to:
Controlling interest
Non-controlling interest
Comprehensive result attributable to:
Controlling interest
Non-controlling interest
BASIC EARNINGS PER ORDINARY SHARE (2)
Collective Financing Institutions
(1) These concepts will be applicable under an inflationary economic environment based on what is established in Financial Information Standard B-10 "Effects of Inflation", issued by the Mexican Council of Financial Information Standards, A.C. (CINIF).
(2) Determined in accordance with what is stipulated by Bulletin B-14 "Earnings per share", issued by the Mexican Council of Financial Information Standards, A.C. (CINIF).
SERIES R27 COMPLAINTS
This series is integrated by one (1) report, whose frequency of preparation and presentation must be quarterly.
REPORT
A-2702
Complaints
In this report, information regarding complaints related to collective financing operations carried out by Clients of Collective Financing Institutions is collected. Additionally, this report considers information regarding the management data of said complaints.
CAPTURE FORMAT
Collective Financing Institutions will carry out the sending of information related to report R27 A-2702 Complaints, by using the following capture format:
REQUESTED INFORMATION
REPORT IDENTIFIER SECTION
PERIOD START
PERIOD END
INSTITUTION KEY
REPORT
COMPLAINT IDENTIFICATION SECTION
COMPLAINT FOLIO
COMPLAINT STATUS
STATUS UPDATE DATE
CLIENT IDENTIFICATION SECTION
CLIENT TYPE
CLIENT IDENTIFIER
FINANCING IDENTIFIER
COMPLAINT DETAIL SECTION
COMPLAINT DATE
COMPLAINT RECEPTION CHANNEL
COMPLAINT TYPE
COMPLAINT REASON
COMPLAINT DESCRIPTION
EVENT DETAIL SECTION
CAUSING THE COMPLAINT
EVENT DATE
EVENT OBJECT
CHANNEL IN WHICH THE UNRECOGNIZED OPERATION WAS CARRIED OUT
AMOUNT VALUED IN NATIONAL CURRENCY
RESOLUTION DETAIL SECTION
RESOLUTION DATE
DIRECTION OF THE RESOLUTION
AMOUNT CREDITED TO THE CLIENT'S ACCOUNT IN THE INSTITUTION
DATE OF CREDIT TO THE CLIENT'S ACCOUNT IN THE INSTITUTION
IDENTIFIER OF THE ACCOUNT OR TRUST OF THE INSTITUTION
AMOUNT RECOVERED
DATE OF RECOVERY OF RESOURCES
IDENTIFIER OF THE ACCOUNT OR TRUST OF THE INSTITUTION
WHERE THE RECOVERED AMOUNT IS RECEIVED
LOSS FOR THE INSTITUTION
Collective Financing Institutions will report the information indicated in this series, which must comply with the validations and quality standards indicated by the National Banking and Securities Commission (Commission), adjusting to the characteristics and specifications. Once the validations and quality standards are met, SITI will generate an electronic receipt.
The information must be sent only once and will be received assuming it meets all characteristics and specifications, in virtue of which it cannot be modified and must present consistency with the various reports in which the same information is included with a different level of integration, therefore, if it does not meet the required quality and characteristics or has been presented incompletely, it will be considered as not fulfilling the obligation of its presentation, and consequently, the corresponding sanctions will be imposed in accordance with the applicable legal provisions.
ANNEX 19
REGULATORY REPORTS OF ELECTRONIC PAYMENT FUND INSTITUTIONS (EPFI)
Frequency
Series R01
Minimum Catalog
A-0111
Minimum Catalog
Monthly
Series R08
Bank and other organism loans
D-0843
Disaggregated loans obtained
Monthly
Series R10
Reclassifications
A-10111
Reclassifications in the statement of financial position
Monthly
A-10121
Reclassifications in the statement of comprehensive income
Monthly
Series R13
Financial Statements
A-13111
Statement of changes in owners' equity
Quarterly
A-13161
Statement of cash flows
Quarterly
B-13211
Statement of financial position
Monthly
B-13221
Statement of comprehensive income
Monthly
Series R26
Commissioner information
A-2610
Highs and lows of commissioner administrators
Per event
A-2611
Disaggregated highs and lows of commissioners
Per event
B-2612
Disaggregated highs and lows of commissioner modules or establishments
Per event
C-2613
Disaggregated tracking of commissioner operations
Monthly
Series R27
Complaints
A-2701
Complaints
Quarterly
SERIES R01 MINIMUM CATALOG
This series is integrated by one (1) report, whose frequency of preparation and presentation must be monthly.
REPORT
A-0111
Minimum Catalog
In this report, the balances at the end of the period of all concepts that form part of the statement of financial position (including off-balance sheet accounts) and the statement of comprehensive income of the Electronic Payment Fund Institution are requested. The report is requested in two subtotals:
·
National currency
·
Foreign currency valued in pesos.
For the completion of report A-0111, the following aspects must be taken into consideration:
The report must present the balances of the Electronic Payment Fund Institution without consolidation.
The balances of all concepts presented in Series R01 Minimum Catalog must be consistent with those reported in the applicable regulatory reports.
For the case of minimum catalog concepts denominated in national currency, UMA and UDIS valued in pesos, these concepts must coincide with the sum of the concepts provided in the regulatory reports in national currency, UMA and UDIS valued in pesos; while the concepts denominated in foreign currency valued in pesos must coincide with the concepts provided in the other regulatory reports in foreign currency valued in pesos.
The data referring to balances must be presented in national currency, foreign currency, UMA and UDIS valued in pesos and foreign currency valued in pesos using the exchange rate indicated in the current accounting criteria. Such balances must be presented in pesos, with four decimals and without commas. For example: $20,585.7000 would be 20585.7000
CAPTURE FORMAT
Electronic Payment Fund Institutions will carry out the sending of information related to report A-0111 Minimum Catalog described above, by using the following capture format:
REQUESTED INFORMATION
REPORT IDENTIFIER SECTION
PERIOD START
PERIOD END
INSTITUTION KEY
REPORT
FINANCIAL INFORMATION SECTION
CONCEPT
CURRENCY
DATA
Electronic Payment Fund Institutions will report the information indicated in this series, which must comply with the validations and quality standards indicated by the National Banking and Securities Commission (Commission), adjusting to the characteristics and specifications. Once the validations and quality standards are met, SITI will generate an electronic receipt.
The information must be sent only once and will be received assuming it meets all characteristics and specifications, in virtue of which it cannot be modified and must present consistency with the various reports in which the same information is included with a different level of integration, therefore, if it does not meet the required quality and characteristics or has been presented incompletely, it will be considered as not fulfilling the obligation of its presentation, and consequently, the corresponding sanctions will be imposed in accordance with the applicable legal provisions.
Electronic Payment Fund Institutions
Series R01 Minimum Catalog
Report A-0111 Minimum Catalog
Includes figures in national currency, foreign currency, UMA and UDIS valued in pesos
Figures in pesos
Concept
National currency,
UMA and UDIS
valued
Foreign currency
valued
ASSET
Cash and cash equivalents
Cash
Banks
Immediate collection documents
Investments available on demand
Restricted or pledged cash and cash equivalents
Virtual assets
Foreign currencies to receive
Foreign currencies to deliver
Others
Others
Margin accounts (financial derivative instruments)
Cash
Investments in financial instruments
Other assets
Investments in financial instruments
Negotiable financial instruments
Negotiable financial instruments without restriction
Government Debt
In position
To deliver
Bank Debt
In position
To deliver
Other debt instruments
In position
To deliver
Equity financial instruments
In position
To deliver
Negotiable financial instruments restricted or pledged
Government Debt
In position
To receive
Bank Debt
In position
To receive
Other debt instruments
In position
To receive
Equity financial instruments
In position
To receive
Financial instruments to collect or sell
Financial instruments to collect or sell without restriction
Government Debt
In position
To deliver
Bank Debt
In position
To deliver
Other debt instruments
In position
To deliver
Financial instruments to collect or sell restricted or pledged
Government Debt
In position
To receive
Bank Debt
In position
To receive
Other debt instruments
In position
To receive
Financial instruments to collect principal and interest
Financial instruments to collect principal and interest without restriction
Government Debt
In position
To deliver
Bank Debt
In position
To deliver
Other debt instruments
In position
To deliver
Financial instruments to collect principal and interest restricted or pledged
Government Debt
In position
To receive
Bank Debt
In position
To receive
Other debt instruments
In position
To receive
Estimate of expected credit losses for investments in financial instruments to collect principal and interest
Financial instruments to collect principal and interest without restriction
Government Debt
In position
To deliver
Bank Debt
In position
To deliver
Other debt instruments
In position
To deliver
Financial instruments to collect principal and interest restricted or pledged
Government Debt
In position
To receive
Bank Debt
In position
To receive
Other debt instruments
In position
To receive
Repo debtors (debit balance)
Financial derivative instruments
For trading purposes
Futures to receive
Forward contracts to receive
Options
Swaps
Credit financial derivative instruments
Structured operations
Valuation
Impairment
Packages of financial derivative instruments
Valuation
Impairment
For hedging purposes
Futures to receive
Forward contracts to receive
Options
Swaps
Credit financial derivative instruments
Structured operations
Valuation
Impairment
Packages of financial derivative instruments
Valuation
Impairment
Virtual assets
Restricted virtual assets
Unrestricted virtual assets
Benefits to be received in securitization operations
Benefits on the remainder in securitization operations
Asset for administration of transferred financial assets
Accounts receivable
Debtors for settlement of operations
Foreign exchange sales
Investments in financial instruments
Repos
Financial derivative instruments
By issuance of securities
Virtual assets
Overdrafts in accounts derived from the transmission of electronic payment funds
Debtors for margin accounts
Debtors for cash collateral granted
Operations with financial instruments
Operations not carried out in recognized markets (OTC)
Others
Diverse debtors
Premiums, commissions and rights to be received
Loans and other debts of personnel
Overdue debts
Other debtors
Taxes to recover
Conditional accounts receivable
Other accounts receivable
Estimate of expected credit losses
Diverse debtors
Conditional accounts receivable
Other accounts receivable
Long-term assets available for sale
Assets related to discontinued operations
Prepayments and other assets
Deferred charges
Insurance to amortize
Other deferred charges
(Continues in the Third Section)
1
Which includes, at least, the calculation base and the total number of financings considered for the determination of the yield.
In its case, average yields can be calculated for different ranges of financed amounts within the same category
of financing.
In the document you are viewing, there may be text, characters or objects that are not displayed correctly due to the conversion to HTML format, so we recommend always taking as reference the digitized image of the DOF or the PDF file of the edition. The content, form and scope of the published documents are the strict responsibility of their issuer.
INQUIRY
BY DATE
Su
Mo
Tu
We
Th
Fr
Sa
INDICATORS
Exchange Rate and Rates as of 08/28/2026
DOLLAR
16.9712 UDIS
8.808812 TIIE 28 DAYS
6.7559% TIIE 91 DAYS
6.7931% TIIE 182 DAYS
6.8474% TIIE DE FONDEO
6.50%
See more
SURVEYS
Did you like the new image of the Official Federal Gazette website?
No
Yes
Official Federal Gazette
Río Amazonas No. 62, Col. Cuauhtémoc, C.P. 06500, Mexico City Tel. (55) 5093-3200, where you can access our services menu
Electronic address: dof.gob.mx
113
LEGAL NOTICE | SOME RIGHTS RESERVED © 2026
More like this from SHCP
SHCP published 14 documents in the last 30 days. We email you each new one the day it's published.