2019-03-25 | DOF 5555030

Added

Resolution modifying the General Provisions applicable to Financial Technology Institutions

The National Banking and Securities Commission (CNBV) amends the General Provisions applicable to Financial Technology Institutions to introduce new regulatory frameworks for information security, the use of electronic media, third-party service contracting, and information disclosure. The resolution updates definitions in Article 2, modifies Article 51 regarding solvency requirements for lending terms, and adds Chapters VI through IX and Title IV to establish controls for cybersecurity, authentication, and operational continuity. It also mandates specific regulatory reporting obligations and updates Annexes 8 through 20 to define formats for security incidents, investor classifications, and information disclosure guidelines for collective financing entities.

Secretaria de Hacienda y Credito Publico logo

Mexico

Secretaria de Hacienda y Credito Publico

Click to view thumbnail

If the document is presented incomplete on the right margin, it is because it contains tables that exceed the default width. If this is the case, click here to view it correctly.

DOF: 25/03/2019

RESOLUTION modifying the General Provisions applicable to Financial Technology Institutions

At the margin, a seal with the National Coat of Arms, which reads: United Mexican States.- SHCP.- Ministry of Finance and Public Credit.- National Banking and Securities Commission.

The National Banking and Securities Commission, based on the provisions of Articles 18, fraction IV; 19, fraction IV; 48, first paragraph; 54, first paragraph; 56, second paragraph, and 57 of the Law to Regulate Financial Technology Institutions, as well as 4, fractions XXXVI and XXXVIII; 16, fraction I, and 19 of the Law of the National Banking and Securities Commission, and

CONSIDERING

That the National Banking and Securities Commission issued the resolution published in the Official Journal of the Federation on July 24, 2017, through which the General Provisions applicable to brokerage houses were reformed, to extend the deadline for these entities to sell or reclassify their held-to-maturity securities from 28 to 90 days, thereby satisfying Article 78 of the General Law for Regulatory Improvement regarding the compliance cost of this resolution;

That on the other hand, in order to be able to face risks and attacks that could cause damage to collective financing institutions and the execution of operations with their clients, it is convenient to incorporate the regulatory framework on the security of their systems and technological infrastructure, determining the internal controls they must have, establishing also a regime that seeks to guarantee the security of the technological infrastructure on which their operations are supported and the confidentiality, integrity, and availability of information;

That one of the fundamental characteristics of collective financing institutions is that they precisely operate through remote electronic or digital communication means, that is, technological devices, computer applications, interfaces, Internet pages, and similar; therefore, it is indispensable in light of the Law to Regulate Financial Technology Institutions to regulate the operation and use of equipment, electronic, optical, or any other technology means, automated data processing systems, and telecommunications networks, including the norms pertaining to the forms of authenticating both the institutions themselves and their clients, complying with the principles of technological neutrality and consumer protection established in the Law;

That in terms of the Law to Regulate Financial Technology Institutions, collective financing institutions may agree with third parties the provision of services necessary for their operation, in accordance with the provisions issued for such effect by the National Banking and Securities Commission, so the corresponding norms for such contracting are established, as well as those services that will require the authorization of the Commission itself, taking into account the due protection of the sensitive information of the clients of these financial entities;

That in order for clients to have the necessary information to identify the risks they incur in the celebration of operations and investment decision-making, it is indispensable to incorporate the regime applicable to collective financing institutions for the disclosure of information about financing applicants, in accordance with the authority held by the National Banking and Securities Commission to issue norms in matters of transparency of the services of these financial entities;

That at the same time, in terms of the Law to Regulate Financial Technology Institutions, once any operation has been carried out in collective financing institutions, these must have available to investors information about the payment behavior of the applicant, their performance, or any other that is relevant in terms of the provisions issued for such effect by the National Banking and Securities Commission;

That in this vein, it is indispensable to establish the content of the information, the form, and periodicity of this, in order for investors to have at all times the information that allows them to continue the operation in which they have participated, in congruence with the principles established in the Law itself regarding consumer protection and financial inclusion, and

That in order for the National Banking and Securities Commission to have the corresponding information regarding the activities and operations of financial technology institutions, the obligation to present the corresponding reports is established, designating the person responsible for their submission and the quality of their content, as well as the deadlines and means for their presentation, it has resolved to issue the following:

RESOLUTION MODIFYING THE GENERAL PROVISIONS APPLICABLE TO FINANCIAL TECHNOLOGY INSTITUTIONS

ARTICLE FIRST.- Articles 2 and 51, second paragraph, are REFORMED; Chapter VI to be called "On Information Security" comprising Articles 63 to 68; Chapter VII to be called "On the Use of Electronic Media" comprising Articles 69 to 84; Chapter VIII to be called "On the Contracting of Services with Third Parties" comprising Articles 85 to 88; Chapter IX to be called "On Information Disclosure" comprising the First Section called "On Information Disclosure in the Publication of Applications and Projects" with Articles 89 to 93, Second to be called "On Information Disclosure of the Payment Behavior and Performance of the Applicant or Project" with Articles 94 to 96, and Third to be called "On Information Disclosure to the General Public" with Article 97; Title Four to be called "On Regulatory Reports" with Chapter I to be called "On Reports in General" with Articles 98 to 103 and Chapter II to be called "On Delivery Means" with Article 103; as well as Annexes 11, 12, 13, 14, 15, 16, 17, 18, 19, and 20 are ADDED; and Annexes 8 and 9 of the General Provisions applicable to financial technology institutions, published in the Federal Diary on September 10, 2018, are SUBSTITUTED, to read as follows:

" FIRST and SECOND TITLES

...

THIRD TITLE

...

Chapters

I to V

...

Chapter VI

On Information Security

Chapter VII

On the Use of Electronic Media

Chapter VIII

On the Contracting of Services with Third Parties

Chapter IX

On Information Disclosure

First Section

On Information Disclosure in the Publication of Applications and Projects

Second Section

On Information Disclosure of the Payment Behavior and Performance of the Applicant or Project

Third Section

On Information Disclosure to the General Public

FOURTH TITLE

On Regulatory Reports

Chapter I

On Reports in General

Chapter II

On Delivery Means

ANNEXES

1 to 7

...

ANNEX 8

Instructions for obtaining electronic certificates of knowledge of risks

ANNEX 9

Format of declarations regarding compliance with requirements to be considered an Experienced Investor

ANNEX 10

...

ANNEX 11

Incidents affecting information security

ANNEX 12

Information Security Incident Report

ANNEX 13

Information security indicators

ANNEX 14

Format for information on systems and applications

ANNEX 15

Guidelines for information disclosure of Collective Financing of Debt for Business-to-Person Loans and for Real Estate Development

ANNEX 16

Guidelines for information disclosure for Collective Financing of Capital

ANNEX 17

Aggregated information of collective financing institutions for disclosure to the general public

ANNEX 18

Regulatory reports that collective financing institutions must present

ANNEX 19

Regulatory reports that electronic payment fund institutions must present

ANNEX 20 "Designation of responsible persons for the submission and quality of information"

" Article 2.- In addition to the definitions contained in the Law, for the purposes of these provisions, the following shall be understood, in singular or plural:

I.

Authentication, the set of techniques and procedures used to verify the identity of a Client and their authority to carry out operations through the Electronic Medium in question or a User of Technological Infrastructure to access, use, or operate any component of the Technological Infrastructure.

II.

Blocking, the process by which the collective financing institution disables the use of an Authentication Factor or Client Identifier temporarily or permanently.

III.

Encryption, the mechanism that collective financing institutions must use to protect the confidentiality of information through cryptographic methods in which algorithms and encryption keys are used.

IV.

Investment Commitments, the contributions that Investors have committed to make in favor of Applicants during the Collective Financing Application Period, regardless of whether the corresponding contributions are delivered to the collective financing institutions during said period or to the Applicants after its conclusion.

V.

Cloud Computing, the model of external provision of on-demand computing services on shared infrastructure, regardless of the physical location of the third-party's technological infrastructure providing the service, which may be among others one or more of the following digital service schemes: infrastructure as a service, platform as a service, or software as a service.

VI.

Operational Contingency, any event that hinders, limits, or prevents a collective financing institution from providing its services or carrying out those processes that could have an impact on its Clients.

VII.

Password, the chain of alphanumeric and special characters that authenticates a Client in the Electronic Medium of the collective financing institution.

VIII.

Destination Accounts, the accounts receiving monetary resources that Clients of the collective financing institution register in the corresponding Electronic Medium to carry out Operations.

IX.

Unblocking, the process by which the collective financing institution enables the use of an Authentication Factor or Client Identifier that was blocked.

X.

Access Device, the equipment that allows a Client to access the corresponding Electronic Medium of the collective financing institution.

XI.

Information Security Event, any internal or external event related to Clients, third parties contracted by the collective financing institution itself, people, and operational processes, as well as with components of the Technological Infrastructure, devices, physical media, or other elements that store information, among others, that could imply an impact on the confidentiality, integrity, or availability of the information that such institution manages or knows, or in the Technological Infrastructure itself.

XII.

Authentication Factor, the Authentication mechanism based on the physical characteristics of the Client, devices, or information that only the Client possesses or knows.

XIII.

Collective Financing of Capital, the collective financing operation through which Applicants obtain resources from Investors in exchange for shares representing their social capital.

XIV.

Collective Financing of Co-ownership or Royalties, the collective financing operation through which Investors and Applicants enter into partnerships or any other type of agreement by which Investors acquire an aliquot part or participation in a present or future asset or in the income, profits, royalties, or losses obtained from the realization of one or more activities or from the projects of the Applicants.

XV.

Collective Financing of Debt for Business-to-Person Loans, the collective financing operation in which Applicants are legal entities or natural persons with business activity and Investors make contributions: a)

With the aim that Applicants receive a loan or credit to finance their activities, being obligated to pay the principal and, if applicable, accessories to each of the Investors in proportion to their contributions in the Operation. b)

With the object of carrying out a financial leasing operation, in which an asset is acquired in the name of the Investors, or by the collective financing institutions in their own name, but on their behalf, and is given in financial lease to the Applicant. For the purposes of the financial leasing operation, the provisions of the General Law of Titles and Credit Operations shall apply. c)

With the aim of carrying out a financial factoring operation, in which they acquire part of some credit right that the Applicant has in their favor, with the Applicant remaining jointly liable for its debtor, without said right deriving from loans, credits, or loans previously granted by the Applicant. For the purposes of the financial factoring operation, the provisions of the General Law of Titles and Credit Operations shall apply.

XVI.

Collective Financing of Debt for Personal Loans between Persons, the collective financing operation in which the Applicant is a natural person who obtains in loan the resources contributed by the Investors, being obligated to pay the principal and, if applicable, accessories, to each of the Investors in proportion to their contributions in the Operation.

XVII.

Collective Financing of Debt for Real Estate Development, the collective financing operation whose object is for Investors to grant a loan or credit to Applicants destined for the financing of real estate development activities, with Investors being obligated to pay the principal and, if applicable, accessories to each of the Investors in proportion to their contributions in the Operation.

XVIII.

Private Capital Fund, the investment vehicle, trust, mandate, commission, or similar figures constituted under Mexican or foreign laws, whose purpose is to invest in the capital of companies not listed on stock exchanges at the time of investment to promote their development and provide them with financing.

XIX.

Client Identifier, the chain of alphanumeric or special characters, device information, or any other information known by both the collective financing institution and the Client, which allows identifying the Client in the Electronic Medium of the collective financing institution.

XX.

Information Security Incident, the Information Security Event in the collective financing institution when it updates any of the following situations: a)

It has compromised the confidentiality, integrity, or availability of a component or the entirety of the Technological Infrastructure with an adverse effect on the collective financing institution, its Clients, third parties, providers, or counterparties, among others. b)

It violates the Technological Infrastructure compromising the information it processes, stores, or transmits. c)

It constitutes a violation of the information security policies and procedures. d)

It represents the materialization of a loss, whether by extraction, alteration, or loss of information; by failures derived from the use of hardware, software, systems, applications, networks, and any other channel of information transmission; by unauthorized accesses resulting in the improper use of information or systems; by fraud, theft, or interruption of services, attacks on interconnected infrastructures, known as cyberattacks, among others.

XXI.

Sensitive Information, the personal information of Clients containing names, addresses, phone numbers, email addresses, or any other data identifying the Client, together with account numbers, card numbers, and other data of a financial nature, as well as Client Identifiers or Authentication information.

XXII.

Investor, the natural or legal person who contributes resources or virtual assets to Applicants for the celebration of collective financing operations.

XXIII.

Experienced Investor, any of the following: a)

Financial entities referred to in Article 21, third paragraph of the Law, as well as other financial entities that according to their legal regime can act as Investors in the Operations in question. b)

Foreign financial entities, provided that the collective financing institution has obtained authorization from the CNBV to receive or make transfers in terms of Article 10 of these provisions. c)

Departments and entities of the Federal Public Administration. d)

Persons who declare themselves to be in the situation indicated in Annex 9 of these provisions.

XXIV.

Related Investor, that which declares before the collective financing institutions to have kinship with the Applicant by blood, affinity, or civil law up to the fourth degree or be their spouse, concubine, or concubinary.

XXV.

Law, the Law to Regulate Financial Technology Institutions.

XXVI.

Electronic Media, the equipment, optical media, or any other technology, automated data processing systems, and telecommunications networks, whether public or private, including the Platform, that collective financing institutions use to provide their services.

XXVII.

Personal Identification Number (PIN), the Password that authenticates a Client in the Electronic Medium of the collective financing institution through a chain of numeric characters.

XXVIII.

Administrative Body, the sole administrator or the board of directors of an FTI.

XXIX.

Business Continuity Plan, the set of strategies, procedures, and actions that allow, upon verification of Operational Contingencies, the continuity in Operations, activities, or in the realization of critical processes of collective financing institutions, or their timely restoration, as well as the mitigation of impacts resulting from said Operational Contingencies.

XXX.

Security Master Plan, the document that establishes the security strategy of a collective financing institution in the short, medium, and long term to ensure proper management of information security and prevent Information Security Events from materializing into Information Security Incidents.

XXXI.

Platform, the computer applications, interfaces, Internet pages, or any other electronic or digital communication medium that collective financing institutions use to operate with their Clients.

XXXII.

Collective Financing Application Period, the period during which a collective financing application can remain published on the Platform of a collective financing institution in order to offer Investors the celebration of an Operation with Applicants.

XXXIII.

Credit Information Report, any of the credit reports issued by credit information societies referred to in Article 36 Bis of the Law to Regulate Credit Information Societies, namely: a)

The one issued by a credit information society that includes the information contained in the databases of other credit information societies. b)

Those issued by each of the credit information societies.

XXXIV.

Session, the period during which Clients can carry out queries and Operations, once they have entered the Platform with their Client Identifier.

XXXV.

SITI: Inter-institutional Information Transfer System, which is part of the CNBV's official registry.

XXXVI.

Applicant, the natural or legal person who has requested resources or virtual assets from Investors, through collective financing institutions.

XXXVII.

UDI, the account units called "Investment Units" established in the "Decree by which obligations that may be denominated in Investment Units are established and various provisions of the Federal Tax Code and the Income Tax Law are reformed and added", published in the Official Journal of the Federation on April 1, 1995, as it may be modified or added from time to time.

XXXVIII.

User of the Technological Infrastructure, the person, Client, or physical or logical component that accesses, uses, or operates any component of the Technological Infrastructure of collective financing institutions. "

" Article 51.- ...

I. and II.

...

The CNBV will grant the corresponding authorization provided that the collective financing institution proves that the terms of the loans or credits it intends to celebrate will not put its solvency and financial stability at risk.

... "

" Chapter VI

On Information Security

Article 63.- The general director or, if applicable, the sole administrator of the collective financing institution, shall be responsible for the implementation of internal controls in matters of information security that ensure its confidentiality, integrity, and availability. The management framework referred to in this paragraph must ensure that the Technological Infrastructure of said institution, whether its own or provided by third parties, complies with the following requirements:

I.

That each of its components performs the functions for which it was designed, developed, or acquired.

II.

That its processes, functionalities, and configurations, including its development or acquisition methodology, as well as the record of its changes, updates, and the detailed inventory of each component of the Technological Infrastructure, are documented.

III."

That information security aspects have been considered in the definition of projects to acquire or develop each of its components, including them during the various stages of the lifecycle. This will comprise the elaboration of requirements, design, development or acquisition, implementation testing, acceptance testing by Users of the Technological Infrastructure, release processes including vulnerability testing and code analysis prior to production, periodic testing, change management, replacement and destruction of information.

Regarding components of communications and computing, security aspects shall include, at least, the following:

a) Logical segregation, or logical and physical segregation of different networks into distinct domains and subnets, depending on the function they perform or the type of data transmitted, including segregation of production environments from development and testing environments, as well as perimeter and network security components that ensure that only authorized traffic is permitted. In particular, in those segments with links to the exterior, such as the Internet, providers, authorities, other networks of the collective financing institution or parent company, and other third parties, all of which refers to those services defined as critical by the institution itself, whether payment systems, Encryption equipment, Operation authorizers, among others, they shall consider secure zones, including those known as demilitarized zones (DMZ).

b) Secure configuration according to the type of component, considering at least, ports and services, permissions granted under the principle of least privilege, use of removable storage media, access lists, manufacturer updates, and reconfiguration of factory parameters. The principle of least privilege shall be understood as the enabling of access only to the information and resources necessary for the performance of the functions specific to each User of the Technological Infrastructure.

c) Security mechanisms in applications that ensure that, during their execution, they are protected from attacks or intrusions, such as code injection, session manipulation, information leakage, alteration of access privileges, among others. Such mechanisms shall be implemented both for applications provided by third parties and for applications developed, implemented, and maintained by the collective financing institution itself.

IV.

That each of its components be tested before being implemented or modified, using quality control mechanisms that prevent the use of real data from the production environment during such tests, the disclosure of confidential or security information, or the introduction of any functionality not recognized for said component.

V.

That it has the licenses or use authorizations, where applicable.

VI.

That it has security measures for its protection, as well as for the access and use of the information that is received, generated, transmitted, stored, and processed in the Technological Infrastructure itself, having at least the following:

a) Identification and Authentication mechanisms for all and each of the Users of the Technological Infrastructure, which allow them to be recognized unequivocally and ensure access only to persons expressly authorized for this purpose, under the principle of least privilege.

For this purpose, relevant controls shall be included for those Users of the Technological Infrastructure with greater privileges, derived from their functions, such as database administration, operating systems, and applications.

Likewise, policies and procedures for exception access authorizations shall be provided for in manuals, such as users of development environments with access to production environments and access due to contingency events, among others. Such policies and procedures shall be approved by the Chief Information Security Officer.

b) Encryption of information according to the degree of sensitivity or classification of the information that the collective financing institution determines and establishes in its policies, when such information is transmitted, exchanged, and communicated between components or stored in the Technological Infrastructure or accessed remotely.

Collective financing institutions shall encrypt at least the information they have classified as critical in terms of these provisions.

c) Access keys with composition characteristics that prevent unauthorized access, considering processes that ensure that only the User of the Technological Infrastructure knows them, as well as security measures, Encryption in their storage, and mechanisms to request the change of access keys every ninety days or less. Regarding Clients, the referred period shall be that defined by the collective financing institutions themselves in the manuals referred to in the last paragraph of this article. In the case of Users of the Technological Infrastructure assigned to applications or components to authenticate with each other, the change referred to in this subsection shall be carried out at least once a year. In the event that any User of the Technological Infrastructure has knowledge of the access keys and ceases to provide their services to the collective financing institution, these shall be disabled immediately.

d) Controls to automatically terminate idle sessions, as well as to prevent unauthorized simultaneous sessions with the same User of the Technological Infrastructure identifier.

e) Security mechanisms, both physical access and environmental and electrical energy controls, that protect the Technological Infrastructure and allow operation in accordance with the specifications of the supplier, manufacturer, or developer.

f) Validation measures to guarantee the authenticity of transactions executed by the different components of the Technological Infrastructure considering, at least, the following:

  1. The truthfulness and integrity of the information.

  2. Authentication between components of the Technological Infrastructure, which ensure that only legitimate service requests are executed from their origin to their execution and registration.

  3. Messaging, communication, and Encryption protocols, which must ensure the integrity and confidentiality of the information.

  4. The identification of atypical transactions, anticipating that monitoring tools or automatic alert measures will be available for attention by the corresponding operational areas.

  5. The update and maintenance of digital certificates and components provided by service providers that are integrated into the transaction execution process.

The measures referred to in this subsection shall be established in accordance with the degree of risk that collective financing institutions define for each type of transaction.

Collective financing institutions, in the classification of information referred to in subsection b) of this section, shall consider at least one category regarding critical information. In this category, they shall include at minimum Sensitive Information and images of official identification and biometric information of Clients, as well as any other they determine in accordance with their policies.

VII.

That it has backup mechanisms and information recovery procedures that mitigate the risk of operational interruption, in accordance with what is stipulated in its Business Continuity Plan referred to in Chapter V of Title Three of these provisions.

VIII.

That it maintains complete audit records, including detailed information of accesses or access attempts and the operation or activity carried out by Users of the Technological Infrastructure, this regardless of the level of privileges they have for access, generation, or modification of the information they receive, generate, store, or transmit in each component of the Technological Infrastructure, including automated process activity, as well as procedures for the periodic review of such records.

Collective financing institutions shall retain the audit records referred to in this subsection for a period of three years when such records refer to activities carried out on components that process or store information considered critical in accordance with the classification determined by the collective financing institution. Otherwise, the retention period for records shall be a minimum of six months.

IX.

That for the handling of Information Security Events and Information Security Incidents, there are management processes that ensure detection, classification, handling, containment, investigation, and, where applicable, digital forensic analysis, diagnosis, reporting to competent areas, resolution, follow-up, and communication to authorities, Clients, and counterparties.

For the detection and response to Information Security Incidents referred to in the previous paragraph, the general director or, where applicable, the sole administrator shall designate a team that incorporates personnel from the different areas of the collective financing institution to participate in each activity of the aforementioned management process, which in all cases shall include the Chief Information Security Officer in accordance with article 66 of these provisions.

In the event that vulnerabilities and deficiencies are detected in the Technological Infrastructure, corrective actions or compensatory controls shall be taken according to the level of risk involved, preventing Users of the Technological Infrastructure or the collective financing institution from being affected.

X.

That it be subjected to annual planning and review exercises that allow measuring its capacity to support its operation, ensuring that the needs for capacity increase detected as a result of such exercises are addressed promptly.

Likewise, the collective financing institution shall evaluate the obsolescence of the components of the Technological Infrastructure, having a plan for their update.

XI.

That it has automated controls or, in the absence of these, that compensatory controls are carried out, such as double verification and reconciliation that, prior or subsequent to the operation in question, minimize the risk of elimination, exposure, alteration, or modification of information, derived from manual or semi-automated processes carried out by the personnel of the collective financing institution, with the objective of preventing errors, omissions, theft, or manipulation of information.

XII.

That it has controls that allow detecting the alteration or falsification of books, records, and digital documents related to Operations.

XIII.

That it has processes to measure and ensure availability levels and response times, which guarantee the execution of Operations carried out; this, including scenarios where collective financing institutions hire third parties to provide services for the processing and storage of information.

XIV.

That it has devices or automated mechanisms to detect and prevent Information Security Events and Information Security Incidents, as well as to prevent unauthorized incoming or outgoing data connections and flows and information leakage, considering, among others, removable storage media.

Collective financing institutions shall correlate the data obtained from the devices or automated mechanisms referred to in the previous paragraph with data from other sources, such as records of activity of Information Security Events or Information Security Incidents.

Additionally, collective financing institutions shall maintain controls that prevent the leakage of information corresponding to the configuration of the Technological Infrastructure, such as IP addresses, firewall rules, as well as hardware and software versions.

XV.

That for the provision of information technology services to Users of the Technological Infrastructure, in their strategy, design, transition, operation, and continuous improvement phases, the integrity of the Technological Infrastructure is protected, as well as the integrity, confidentiality, and availability of the information received, generated, processed, stored, and transmitted by it.

The general director or, where applicable, the sole administrator of the collective financing institution shall be responsible for documenting in manuals the policies and procedures provided for in this article.

Article 64.- The general director or, where applicable, the sole administrator of the collective financing institution, shall be responsible for compliance with the following obligations regarding the Technological Infrastructure:

I.

Approve the Security Master Plan, as well as its updates, which must be aligned with the business strategy of the collective financing institution, as well as define and prioritize projects in the matter of information security, with the objective of reducing exposure to technological risks and the materialization of Information Security Incidents up to acceptable levels in the terms defined, where applicable, by the board of directors or the sole administrator themselves, as appropriate, from an analysis of the current situation.

For the approval of the Security Master Plan, the general director or, where applicable, the sole administrator shall verify that it contains initiatives aimed at improving existing work methods and may contemplate the controls required in accordance with applicable provisions.

Regarding collective financing institutions that have a general director and a board of directors, the former shall inform said board of the content of the Security Master Plan and have evidence of its approval and implementation.

II.

Carry out security reviews focused on verifying the sufficiency of controls applicable to the Technological Infrastructure. These reviews shall comprise, at least, the following:

a) Authentication mechanisms of Users of the Technological Infrastructure.

b) Configuration and access controls to the Technological Infrastructure.

c) Updates required for operating systems and software in general, prior to their implementation and once implemented.

d) Identification of possible unauthorized modifications to the original software.

e) Devices, communication networks, systems, and processes associated with Electronic Media and customer service channels, in order to verify that there are no vulnerabilities or that there are tools or procedures that allow knowing the Authentication credentials of Users of the Technological Infrastructure, as well as any information that, directly or indirectly, could give access to the Technological Infrastructure in the name of the User of the Technological Infrastructure.

The reviews referred to in this subsection shall be carried out at least once a year or earlier if significant changes occur in the Technological Infrastructure. To determine if it is a significant change, the opinion of the Chief Information Security Officer shall be obtained for this purpose.

III.

Prepare an annual calendar for the performance of vulnerability scanning tests of the components of the Technological Infrastructure that store, process, or transmit information, prioritizing them according to the result of the information classification exercise determined by the collective financing institution. The calendar shall provide for the bi-monthly review of the components of the Technological Infrastructure so that, by the end of the year, all components that store, process, or transmit information cataloged by the collective financing institution as critical, as well as those it considers necessary, have been reviewed. The general director or, where applicable, the sole administrator, shall be responsible for monitoring that such tests are carried out, either through the collective financing institution itself or a third party hired for this purpose. Additionally, when new components of the Technological Infrastructure are incorporated, the general director or, where applicable, the sole administrator, shall be responsible for monitoring that the vulnerability scanning test is performed prior to its production deployment.

IV.

Hire an independent third party, with personnel who have verifiable technical capacity through industry certifications in the matter, to perform penetration tests in the different systems and applications of the collective financing institution with the purpose of detecting errors, vulnerabilities, unauthorized functionality, or any code that puts or may put at risk the information and assets of Clients and of the collective financing institution itself. Such review shall include the verification of the integrity of hardware and software components that allow detecting alterations thereof. Penetration tests shall consider, at least, the following:

a) Its scope and methodology, which must be validated by the Chief Information Security Officer.

b) Be carried out at least twice a year on different components, systems, or applications that have been determined by the collective financing institution as higher risk, or when ordered by the CNBV having detected vulnerabilities or factors that may affect the systems and applications or the information received, generated, processed, stored, or transmitted therein. In the latter case, the CNBV shall determine the scope of the tests, as well as the deadlines for carrying them out.

Additional tests may be carried out at the discretion of the general director or, where applicable, the sole administrator, with the opinion of the Chief Information Security Officer, when there are significant changes in systems and applications, or carry them out on systems and applications previously tested when there are critical vulnerabilities.

The general director or, where applicable, the sole administrator of the collective financing institution shall send to the CNBV within twenty business days of having finalized the tests, a report with the conclusions thereof. In the submission made, care shall be taken to use mechanisms that prevent unauthorized personnel from accessing the content of this report.

V.

Classify detected vulnerabilities according to the methodology approved by the person responsible for risk management administration of the collective financing institution.

VI.

Prepare remediation plans regarding the findings of the reviews and tests referred to in subsections II, III, and IV above, considering the classification of subsection V of this article, as well as implementing defense mechanisms that prevent unauthorized access and use of the Technological Infrastructure.

The remediation plans referred to in the previous paragraph shall be validated by the Chief Information Security Officer. Likewise, such plans shall contain, at least, the indication of the personnel responsible for their implementation and execution, as well as deadlines for this, detail of activities carried out and to be carried out, as well as the technical, material, and human resources employed. The aforementioned remediation plans must be prepared once the vulnerabilities are identified and sent to the CNBV within a period of ten business days.

In addition to what is stated in the previous paragraph, in the case of short, medium, or long-term projects in the remediation plans, they shall be incorporated into the Security Master Plan.

VII.

Implement follow-up processes for compliance with the aforementioned remediation plans, which shall be verified by the Chief Information Security Officer, who additionally shall corroborate that the aforementioned plans have managed to correct the vulnerabilities found.

VIII.

Implement annual training programs directed to all personnel, as well as awareness programs in the matter of information security towards Clients including, where applicable, third parties that provide them with services, in which, among other aspects, the roles and responsibilities that Users of Technological Infrastructure have in this regard are contemplated.

IX.

Proactively and interactively search for fraud alerts, as well as threats, such as phishing email campaigns, fake Internet sites, disclosure of databases with Client information, mobile applications, and, where applicable, alteration of devices used to carry out Operations, among others, that could affect the information security of Clients, as well as actions for their protection considering, at least, the following:

a) The continuous investigation, collection, processing, and analysis of information that comes from any source related to the products and services offered by the collective financing institution, which may constitute indications or evidence that security controls have been evaded, representing a threat to the information or resources of the Client.

The indications or evidence referred to in the previous paragraph shall be kept in a record, which shall be contained in the database referred to in the first paragraph of article 68 of these provisions.

b) The implementation of proactive processes to protect the information or resources of Clients when the indications or evidence indicated in subsection a) above occur, such as Blocking and replacement of disposal means, change of Authentication data and notifications, among others.

c) That it has communication procedures and security recommendations with affected Clients, to inform them about the remediation processes that the collective financing institution will carry out and, where applicable, the measures that the

own Client must adopt, such as changing passwords, verifying balances and transactions, installing antivirus, installing malicious program detection software, reviewing devices and reinstalling applications, among others.

The terms and conditions for carrying out the processes through which the activities referred to in this subsection are carried out, must be documented in the respective policies and procedures manuals, in which it must be provided that the collective financing institution will maintain evidence of the performance of said activities.

X.

Implement controls that allow the collective financing institution to ensure the confidentiality, integrity, and availability of the information of the Clients and of the collective financing institution itself or access to the Technological Infrastructure, by its employees or personnel who have access to it, which guarantee that such information and Technological Infrastructure are not altered or cause an impact on the collective financing institution or on the resources of its Clients. Such controls must be implemented from the respective hiring until its termination.

XI.

Establish policies and procedures to ensure that the Chief Information Security Officer obtains from the business units of the collective financing institution the information and documentation necessary for the fulfillment of the functions established in these provisions.

Article 65.- Collective financing institutions must have a person who, among their functions, serves as the Chief Information Security Officer, known as CISO by its English acronym (Chief Information Security Officer).

The Chief Information Security Officer must be designated by the General Manager or, if applicable, by the sole administrator, must report to them, and must not have conflicts of interest with respect to the person responsible for the audit and information technology functions that exist within the collective financing institution. Likewise, they cannot perform functions related to the operation of the information security of the collective financing institution itself.

The functions of the Chief Information Security Officer may be performed by a third party, provided that it complies with what is stated in this article.

The Chief Information Security Officer may be supported, in the exercise of their functions, by representatives of the different business units.

Collective financing institutions may designate the General Manager or, if applicable, the sole administrator as the Chief Information Security Officer for a maximum period of twelve months, counted from the date on which they obtain authorization to act as such.

Article 66.- The Chief Information Security Officer of the collective financing institution must, at least:

I.

Participate in the definition and verify the implementation and continuous compliance of the security policies and procedures referred to in Article 63 of these provisions.

II.

Prepare the Security Master Plan, which must contain, for each project defined, the name of the project, objective, scope, start and end dates, areas involved, and projected investment. This plan must be reviewed and updated, at least, annually.

III.

Verify, at least annually, the definition of access profiles to the Technological Infrastructure of the collective financing institution, whether its own or provided by third parties, according to job profiles (functional segregation), including those with high privileges, such as administration of operating systems, databases, and applications.

IV.

Ensure at least annually, or earlier in the event of an Information Security Incident, the correct assignment of access profiles to Users of the Technological Infrastructure. The function referred to in this subsection may be carried out through representative and random samples.

Likewise, it will be responsible for the temporary authorization of access by exception, such as those of users of development environments with access to production environments, access due to contingency events, or any other privileged access that does not correspond to the policy determined by the collective financing institution. Likewise, it must have a record containing the name of the Technological Infrastructure User, associated application, environment, reason for the exception, and start and end dates of the assignment.

V.

Approve and verify compliance with the measures that have been adopted to remedy deficiencies detected as a result of the functions referred to in subsections III and IV of this article, as well as the findings of audits carried out related to the Technological Infrastructure and information security.

VI.

Manage information security alerts communicated by the CNBV or other means, as well as Information Security Incidents, considering the stages of identification, protection, detection, response, and recovery.

VII.

Coordinate and preside over the team for the detection and response to Information Security Incidents within the collective financing institution.

VIII.

Inform the Administrative Body or, if it has an audit committee and a risk committee, at its next immediate session, as applicable, upon verification of the Information Security Incident, regarding the actions taken and the follow-up on measures to prevent or avoid the recurrence of said incidents.

IX.

Propose and coordinate training programs directed at all personnel, as well as awareness programs regarding information security towards Clients, and verify their effectiveness.

X.

Present monthly to the General Manager or, if applicable, to the sole administrator, the management report on information security. This report must be submitted to the audit committee and the risk committee or, in the absence of these, to the board of directors of the collective financing institution.

XI.

Consider, at least, the risk indicators in information security established in Annex 13 of these provisions, and report the result of the evaluation of said indicators to the Administrative Body, and if applicable, to the audit committee or risk committee.

XII.

Be responsible for the implementation of the regulation that, in matters of information security, is issued by other Financial Authorities.

XIII.

Respond to requirements formulated by the authorities and within the collective financing institution in matters of information security.

Collective financing institutions must ensure that the Chief Information Security Officer has access to the records of persons who have access to information related to the operations in which the collective financing institution itself intervenes, including those located abroad and of Users of the Technological Infrastructure who have high privileges, such as administration of operating systems, databases, and applications, as well as their service providers.

Collective financing institutions that belong to a financial group subject to the supervision of the CNBV, or that are part of Consortia or Business Groups that have a financial entity subject to the supervision of the CNBV itself, may assign the functions of the Chief Information Security Officer to the person performing such activities in the financial entity supervised by the CNBV, provided that such person complies with what is established in Article 65 of these provisions.

Article 67.- When an Information Security Event or Information Security Incident occurs in: (i) the components of the Technological Infrastructure of the collective financing institution; (ii) the channels for attention to Clients, such as Electronic Media, or (iii) the technological infrastructure of any third party that affects the operation or the Technological Infrastructure of the collective financing institution, the General Manager or, if applicable, the sole administrator must:

I.

Provide for what is necessary to make the CNBV aware, immediately, of Information Security Incidents, by email sent to the account Ciberseguridad-CNBV@cnbv.gob.mx or through other means indicated by the CNBV itself.

In said notification, at least the date and time of start of the Information Security Incident in question must be indicated, and if applicable, the indication of whether it continues or has concluded and its duration; a description of said event or incident, as well as an initial assessment of the impact or gravity.

Additionally, collective financing institutions must send via email to the CNBV, to the account Ciberseguridad-CNBV@cnbv.gob.mx or through other means indicated by the CNBV itself, within five business days following the identification of the Information Security Incident in question, the information contained in Annexes 11 and 12 of these provisions.

In the case of Information Security Events, they must be reported through the means indicated in the first paragraph of this subsection only those that, according to the policies and procedures established by the collective financing institution itself, are qualified as relevant due to having potential impact on the collective financing institution, its Clients, counterparties, suppliers, or other entities in the financial system, in addition to those related to Sensitive Information, images of official identification, and biometric information of Clients. This report must only contain the date and time of start, as well as the description of the event in question.

II.

Carry out an immediate investigation into the causes that generated the Information Security Incident and establish a work plan that describes the actions to be implemented to eliminate or mitigate the risks and vulnerabilities that gave rise to said incident. This plan must indicate, at least, the personnel responsible for its design, implementation, execution, and follow-up, deadlines for its execution, as well as the technical, material, and human resources, and send it to the CNBV within a period not exceeding fifteen business days after the Information Security Incident concluded.

When the Information Security Incident refers to the fact that Sensitive Information in the custody of the collective financing institution or third parties providing services to it, was extracted, lost, deleted, altered, or if collective financing institutions suspect the commission of any act involving unauthorized access to said information, the General Manager or, if applicable, the sole administrator or the person designated by any of these, must notify the Clients of the possible loss, extraction, alteration, loss, or unauthorized access to their information, within the following forty-eight hours after the Information Security Incident occurred or after it was known, through the notification means that the Client has indicated for such effect, in order to prevent them from the risks derived from the misuse of the information that has been extracted, lost, deleted, or altered, informing them of the measures they must take and, if applicable, effecting the replacement of the corresponding disposal means or the substitution of necessary Authentication Factors. The evidence of this notification must be included in the result of the investigation referred to in the previous paragraph.

Article 68.- Collective financing institutions must keep a record in databases of Information Security Events qualified as relevant, Information Security Incidents, failures or vulnerabilities detected in the Technological Infrastructure that includes, at least, information related to the detection of failures, operational errors, attempts at computer attacks and those effectively carried out, as well as loss, extraction, alteration, loss, or misuse of information of Users of the Technological Infrastructure, where the date of the event and a brief description of it, its duration, service or channel affected, Clients affected and amounts, as well as the corrective measures implemented are contemplated.

The information of the Information Security Events qualified as relevant and Information Security Incidents referred to in this article must be backed up in the means that collective financing institutions determine and be preserved for, at least, ten years.

Chapter VII

On the use of electronic media

Article 69.- Collective financing institutions, for the use of Electronic Media, will make known to their Clients, at least the following:

I.

The Operations and services that can be performed.

II.

The identification and Authentication mechanisms and procedures.

III.

The responsibilities of the Client and the collective financing institution regarding the use of the corresponding Electronic Medium.

IV.

The mechanisms and procedures for the notification of Operations carried out and services provided by collective financing institutions.

V.

The limits of the amounts of Operations, without exceeding those established in Articles 49 and 50 of these provisions.

VI.

The inherent risks, terms and conditions for the use of the Electronic Medium in question, as well as suggestions to avoid the misuse of Authentication data to prevent the performance of irregular or illegal operations that go to the detriment of the patrimony of Clients and collective financing institutions.

VII.

The mechanisms and procedures that the collective financing institution will make available to Clients to address clarifications related to Operations and services.

VIII.

The notification procedures and terms and conditions for the acceptance, by Clients, of modifications to the conditions indicated in the subsections above of this article.

Article 70.- Collective financing institutions, to allow the start of a Session, will request and validate at least the following:

I.

The Client Identifier, and

II.

An Authentication Factor referred to in Article 72 of these provisions.

The Client Identifier must be unique for each Client and will allow collective financing institutions to identify all Operations performed by the Client themselves.

Article 71.- Collective financing institutions, in the use of the Client Identifier and Authentication Factors, will comply, at least, with the following:

I.

Have the necessary mechanisms to prevent the reading on the screen of the Access Device of the identification and Authentication information provided by the Client.

II.

Have procedures that ensure that, in the generation, delivery, storage, unlocking, and restoration of Authentication Factors, only the Client receives, activates, knows, unlocks, and restores them.

III.

Ensure that when there is more than one Authentication Factor, they are independent, that is, that the compromise of one does not compromise the reliability of the others.

IV.

Have procedures to restore a blocked Password, in which the identity of the Client is identified without compromising their Sensitive Information.

V.

Have procedures to invalidate Authentication Factors and the Client Identifier to prevent their use in the corresponding Electronic Medium when a Client ceases to be one.

Article 72.- Collective financing institutions must use Authentication Factors to verify the identity of their Clients and their authority to perform Operations through the Electronic Medium in question. Said Authentication Factors must be any of the following:

I.

Information such as Passwords and Personal Identification Numbers (PINs), which collective financing institutions provide to the Client or allow this to generate and which only the latter knows to enter the Platform and start the Session in question and which must have the following characteristics:

a)

Its length must be at least six characters and include alphanumeric and special characters, when the Access Device allows it.

b)

Under no circumstances may the following information be used as such:

i.

The Client Identifier.

ii.

The name of the collective financing institution.

iii.

More than three identical characters in a consecutive manner.

iv.

More than three numerical and alphabetic characters in a sequential manner.

Collective financing institutions will allow the Client to change their Passwords, Personal Identification Numbers (PINs), and other static Authentication information, when the latter so requires, under the terms provided in these provisions.

Regarding Passwords defined or generated by collective financing institutions during their restoration, the institutions themselves must provide mechanisms and procedures by means of which the Client must modify them immediately after starting the corresponding Session and prior to the performance of any Operation, validating that the Passwords are different from those defined by the collective financing institutions themselves.

II.

Information contained, received, or generated by electronic means or devices that only the Client possesses, including that obtained or received by devices or applications generating one-time passwords (OTP, one time password by its English acronym), said means or devices must be provided, validated, and registered by collective financing institutions for their Clients and the information contained or generated by them may be provided, among other formats, in quick response codes (QR, quick response by its English acronym). In any case, the following characteristics must be met:

a)

Have properties that prevent their duplication or alteration.

b)

Be dynamic information that cannot be used more than once.

c)

Have a validity that cannot exceed two minutes.

d)

Not be known in advance by its generation and use by officials, employees, representatives of the collective financing institution, or third parties.

Collective financing institutions may provide their Clients with means or devices that generate one-time passwords, which use information from the Destination Account, by capturing data, so that said Password can only be used for the requested Operation. In this case, what is provided in subsection c) of this subsection will not apply.

III.

Information derived from physical characteristics, such as fingerprints, hand geometry, patterns in iris or retina, and facial recognition. For the use of this information, prior authorization from the CNBV must be obtained.

Collective financing institutions that use this information as an Authentication Factor must ensure that the biometric data of their employees, executives, or officials are not used in substitution of the Client's.

Article 73.- Collective financing institutions may request the CNBV to approve Authentication Factors with characteristics different from those indicated in Article 72, subsections I and II of these provisions or in the use of the information indicated in subsection III of said article, provided they prove that the technology used, in the judgment of the CNBV itself, is reliable to authenticate their Clients.

The request to obtain CNBV approval, as appropriate, must contain the following:

I.

The detailed description of the processes related to the use of the technology used.

II.

The description of its technical and functional specifications, and if applicable, the certifications it has.

III.

The evidence of the approval of the use of the technology by the Administrative Body.

Article 74.- Collective financing institutions must establish mechanisms and procedures so that their Clients can verify the authenticity of the collective financing institutions themselves at the start of a Session, subject to the following:

I.

Provide their Clients with personalized information so that they can verify, before entering all identification and Authentication elements, that it is effectively their Platform on which the Session will be started. For this, collective financing institutions must use at least one of the following:

a)

Information that the Client knows or has provided to the collective financing institution, or that they have indicated for this purpose, such as name, alias, images, among others.

b)

Information that the Client can verify through a device or Electronic Medium provided by the collective financing institution for this purpose.

II.

Once the Client verifies that it is the collective financing institution and starts the Session, it must provide in a prominent and visible manner to the Client, at least the following information:

a)

Date and time of entry to their last Session, and

b)

First and last name of the Client.

Article 75.- Collective financing institutions must provide for what is necessary so that, once the Client is authenticated in the corresponding Electronic Medium, the Session cannot be used by a third party. For the purposes of the above, collective financing institutions will establish, at least, the following mechanisms:

I.

Terminate the Session immediately and automatically and inform the Client of the reason in any of the following cases:

a)

When there is inactivity for more than five minutes.

b)

When, during a Session, the crowdfunding institution identifies relevant changes in communication parameters, such as identification of the Access Device, range of communication protocol addresses, geographic location, among others.

II.

Prevent simultaneous access on the same Electronic Medium, by using the same Client Identifier and inform the Client thereof.

III.

In the event that crowdfunding institutions offer third-party services via links, they must inform their Clients that, upon entering said services, they will be redirected to another link whose security does not depend on nor is the responsibility of said crowdfunding institution.

Article 76.- Crowdfunding institutions, for the execution of Operations, will request from their Clients a second Authentication Factor from those established in Article 72 of these provisions, additional and different from the one used to initiate the Session and on each occasion when any of the following operations are intended to be performed:

I.

Instructions to make investment commitments or withdraw their resources.

II.

Registration or modification of Destination Accounts for the service in question.

III.

Change and Unblocking of Passwords or Personal Identification Numbers (PIN).

IV.

Registration and modification of the notification medium referred to in Article 79 of these provisions.

V.

Inquiries into account statements of one or more periods that allow obtaining information related to the Client and their Operations. It will not be necessary to use the aforementioned second factor for the case of account statement inquiries, provided that the Client has initiated their Session with an Authentication Factor as referred to in fractions II and III of Article 72 of these provisions.

Crowdfunding institutions, when agreeing with their Clients that account statement inquiries be made via email, the information transmitted must be done in an Encrypted manner or with mechanisms that prevent unauthorized third parties from reading it, and for the Client to have access to said information, they will require an Authentication Factor from those established in fractions II and III referred to in Article 72 of these provisions.

Article 77.- Crowdfunding institutions that offer services to their Clients through telephone call centers, electronic messaging channels, or automated agents, may identify their Clients and verify their identity through questionnaires, in which case they must observe the following:

I.

They must request data that the Client knows and that crowdfunding institutions can validate, maintaining the due confidentiality of said information.

II.

Have procedures to conduct random questionnaires in an automated manner or remotely by operators, in the latter case, preventing them from being used at their discretion.

III.

Define a set of open-ended questions in questionnaires of at least three questions, and in the event that the answer to one of them is incorrect, an additional question may be formulated. In no case can the answers to these questions be data displayed on the Electronic Medium or found in printed or electronic communications sent by crowdfunding institutions to their Clients.

IV.

Validate the answers provided by their Clients through computer tools, without the operator being able to consult or access the Client's Authentication data.

Crowdfunding institutions may use questionnaires to unblock Authentication Factors that have previously been Blocked in the cases contemplated in Article 80 of these provisions.

In the event of asking Clients secret questions, the answers to which have been previously provided by the Client, these will be stored in Encrypted form. For the purposes of the present paragraph, a secret question shall be understood as the questioning defined by the Client or the crowdfunding institution, regarding which information is generated as a response.

Each secret question defined may only be used once.

Article 78.- Crowdfunding institutions must request that their Clients confirm the Operation and its characteristics, prior to its execution, making the information explicit to give certainty to the Client of the Operation being performed.

Regarding the automatic investments referred to in Article 54 of these provisions, the confirmation mentioned in the previous paragraph will only be required to contract said service.

Article 79.- Crowdfunding institutions will immediately notify their Clients, through the communication media made available to them, such as mobile phone number or email address, which they have chosen for this purpose, regarding the execution of Operations. For the change of notification medium, a notice must be sent to both the previous and the new medium.

Article 80.- Crowdfunding institutions will establish automatic processes and mechanisms to Block the Authentication Factors, at least for the following cases:

I.

When an attempt is made to enter the Electronic Medium in question using incorrect Authentication information. In no case can failed access attempts exceed three consecutive times; once the established number of attempts is reached, automatic Blocking must be generated.

II.

When the Client does not access the Electronic Medium in question, for a period determined by each crowdfunding institution in its operational policies. In no case, said period may be greater than one year.

Article 81.- Crowdfunding institutions, in the management of Authentication Factors, will be subject to the following:

I.

They must maintain procedures that provide security for the information contained in the Authentication devices in their custody, as well as in the distribution, assignment, and replacement of said Authentication Factors to their Clients.

II.

They are prohibited from having mechanisms, algorithms, or procedures that allow them to know, recover, or decrypt the values of any information related to Authentication.

III.

They are prohibited from requesting from their Clients, through their officials, employees, or representatives, partial or complete information of the Authentication Factors referred to in Article 72 of these provisions.

IV.

In the event of obtaining approval for the use of the Authentication Factors from fraction III of Article 72 of these provisions, they must incorporate into the Authentication information obtained by biometric devices, elements that ensure that said information is different each time it is generated in order to constitute One-Time Passwords, which in no case can be used again or duplicated with that of another Client.

Article 82.- Crowdfunding institutions will foresee procedures and mechanisms for their Clients to report the theft or loss of their identification and Authentication information, which allow the crowdfunding institutions themselves to prevent their improper use.

Likewise, they must establish policies that define the responsibilities of both the Client and the crowdfunding institution, regarding Operations that have been carried out prior to a report of theft or loss of their identification or Authentication information.

Each report of theft or loss will generate a file number that will be made known to the Client and that will allow them to follow up on said report.

Article 83.- Crowdfunding institutions that have remote channels such as telephone call centers or electronic messaging channels, must:

I.

Maintain physical or logical security controls or both, as appropriate, in the Technological Infrastructure of the remote channels, including the recording devices of communications and the storage and backup media thereof, which protect at all times the confidentiality and integrity of the information provided by their Clients.

II.

Delimit the functions of the operators, so that they are independent with respect to other operational functions.

III.

Prevent operators from having mechanisms that allow them to register information provided by their Clients on media other than those provided by the crowdfunding institution itself for Authentication purposes. To this end, crowdfunding institutions must ensure that persons who have access to remote channels do not use electronic equipment or other devices, external email services, instant messaging programs, computer programs, or through these have access to unauthorized Internet pages, or to any other mechanism that allows them to copy, send, or extract by any means or technology information related to Clients.

IV.

Register in logs, the accesses and activities that operators of telephone call centers or electronic messaging channels perform with Clients, as well as preserve the logs.

What is established in this article must be provided for in the information security manuals established by crowdfunding institutions referred to in Article 63, last paragraph of these provisions.

Article 84.- Crowdfunding institutions must have trained personnel or technical and operational support infrastructure, to attend to and follow up on service requests that their Clients have in the use of Electronic Media.

Chapter VIII

On the contracting of services with third parties

Article 85.- Crowdfunding institutions will only require authorization from the CNBV to contract with third parties the provision of services that have the following characteristics:

I.

Those that imply the transmission, storage, processing, safeguarding, or custody of Sensitive Information, images of official identifications, or biometric information of Clients, provided that the contracted third party has access privileges to know said information or security configuration information, or access control administration.

II.

Those that perform processes abroad related to accounting or treasury, as well as with the recording of transactional movements of Clients.

Crowdfunding institutions, both in the contracting of the services referred to in the aforementioned fractions and in any other, must ensure at all times that the third parties providing them services maintain the due confidentiality of information regarding Operations carried out with their Clients, as well as regarding the latter, in case of having access to it.

The general manager or, in their case, the sole administrator of the crowdfunding institution will be responsible for approving the contracting of third parties.

Crowdfunding institutions must maintain the data of the third parties providing them services, in the registry referred to in Article 88 of these provisions.

Article 86.- Crowdfunding institutions must accompany the authorization request referred to in the previous article, with the following:

I.

The detailed description and flowcharts of the processes of the services to be contracted, considering the activities to be performed by the crowdfunding institution, as well as by the service provider; the areas of the crowdfunding institution itself and the third party that participate in the service flow; name, description, and functionality of the systems that, in their case, will be contracted for the provision of the service, or the systems of the crowdfunding institution that will be used by the respective provider.

II.

The draft service provision contract, in which the probable date of its celebration, the rights and obligations of the crowdfunding institution and the third party must be indicated, including the determination regarding intellectual property rights regarding the designs, developments, or processes used for the provision of the service. Said draft contract must be presented in Spanish.

Likewise, it must be recorded within the contract, the express acceptance by the third party of the following obligations:

a)

Comply with what is provided in Article 54 of the Law.

b)

Deliver in the development of an audit and at the request of the crowdfunding institution, to the independent external auditor of the crowdfunding institution itself and to the CNBV, the books, systems, records, manuals, and documents in general, related to the provision of the service in question. Likewise, allow the independent external auditor or CNBV personnel access to their offices and facilities in general, related to the provision of the service in question.

c)

Inform the crowdfunding institution regarding any modification to its corporate purpose or any other change that could affect the provision of the service subject to contracting, with at least thirty days' advance notice before such modification or change occurs.

d)

Maintain confidentiality regarding information that has been received, transmitted, processed, or stored during the provision of the services. Likewise, accept that said information can only be used and exploited for the purposes agreed upon in the provision of the service.

e)

In the event that the third party subcontracts the partial or total provision of any of the services provided to crowdfunding institutions, the obligation to notify the institution itself regarding said subcontracting; likewise, that it will establish mechanisms so that the subcontractor complies with the obligations agreed upon and provides information for the purposes of Article 88 of these provisions.

f)

Comply with the terms, conditions, and processes so that the third party guarantees to the crowdfunding institution the transfer, return, and secure elimination of the information subject to the contracted service when it ceases to provide it.

g)

Maintain complete audit records that include detailed information of accesses or access attempts and the operation or activity performed by Users of the Technological Infrastructure. Said records must be available to authorized personnel of the crowdfunding institution.

h)

Have access controls to information according to the access levels and profiles determined by the crowdfunding institution.

i)

Allow the crowdfunding institution to perform the security reviews indicated in Article 64, fractions II, III, and IV of these provisions on the contracted services or provide evidence of the performance of these reviews.

III.

The following documentation regarding the Technological Infrastructure:

a)

The description of the communication links used by the crowdfunding institution to connect with the service provider, including the provider's name, bandwidth, and type of service provided, among others.

b)

A telecommunications diagram showing the existing connection between each of the participants in the provision of the service (providers, data centers, crowdfunding institution, among others), including redundancy schemes.

c)

The complete address of the place where each of the services will be performed, as well as the primary and secondary data centers where information will be stored and processed. In the event that the indicated place is located in national territory, it must include, at least, street, exterior and interior number, neighborhood, borough or municipality, postal code, and federative entity. Regarding a site located abroad, similar data must be included that allow locating the indicated place with certainty. Regarding Cloud Computing services, only what is indicated in subsection b) of fraction VI of this article must be provided.

d)

In their case, the interrelation scheme of applications or systems subject to contracting, including the systems of the crowdfunding institution itself.

e)

The mechanisms for continuity of the contracted service.

IV.

The mechanisms that will allow the crowdfunding institution to maintain in its facilities the detailed records of all Operations performed, as well as its accounting records at daily closing. Said records must be maintained in a format that allows their consultation and use, regardless of whether the service contracted with the third party is not available.

V.

When the third party has access privileges to images of official identifications or biometric information of Clients, present evidence of the controls it will maintain to guarantee the confidentiality, integrity, and availability of this information.

VI.

Regarding the contracting of Cloud Computing services, additionally describe the following:

a)

Type of cloud, whether public, private, or hybrid.

b)

Specific regions where information will be stored and processed.

c)

In public cloud or virtualization schemes in shared infrastructure with other clients, the description of the control mechanisms that will be used to guarantee the confidentiality, integrity, and availability of Sensitive Information.

VII.

Description of the mechanisms to monitor the performance of the contracted third party and the compliance of its contractual obligations, including at least, those provided in these provisions.

VIII.

Plans to evaluate and report to the Governing Body or, in its case, to the audit committee of the crowdfunding institution, according to the importance of the contracted service, the performance of the third party and the compliance with applicable regulation related to said service.

IX.

Evidence that allows verifying that third parties have and implement data protection and information confidentiality policies that allow the crowdfunding institution to comply with the legal provisions governing it in this matter.

Regarding services that are processed, provided, or executed totally or partially outside national territory, crowdfunding institutions must accompany the documentation that accredits that the third parties reside in countries whose internal law provides protection for personal data, safeguarding their due confidentiality, or that said countries maintain international agreements signed with Mexico in this matter or of information exchange between supervisory bodies, regarding Financial Entities.

The CNBV will have a period of twenty-five business days to resolve regarding the authorization request referred to in this article; once this period has elapsed without any pronouncement, the resolution will be understood as positive. Any request for additional information made by the CNBV will interrupt the period indicated in this paragraph.

Article 87.- Crowdfunding institutions for the contracting of services with third parties that are subject to authorization by the CNBV in terms of these provisions, as well as those related to operational processes and with administration of databases and computer systems, must comply with the following:

I.

Regarding third parties that provide services related to operational processes and with administration of databases and computer systems, agree on what is stated in fraction II of Article 86 and preserve the respective contract.

II.

Perform, at least annually, internal or external audits on the contracted service or have evidence that the contracted third party carries them out.

III.

Maintain in their main offices, at least, the documentation and information related to evaluations, audit results, and, in their case, remediation plans that correspond, as well as performance reports of contracted third parties, including documentation regarding compliance with what is stated in fraction I of this article.

IV.

Update the description or respective documentation when there are modifications that are considered to have a relevant impact on the service provided or that are related to the systems, equipment, and applications subject to contracting or their technical characteristics.

V.

Regarding Technological Infrastructure and information security, in addition to the information determined in Article 86, fraction III, subsections b) and d) of these provisions, have the following documentation:

a)

The description of the technical characteristics of the systems, equipment, and applications subject to contracting that contains at least what is indicated in Annex 14 of these provisions.

b)

That in which the mechanisms to ensure the transmission and storage of information in Encrypted form are detailed, in their case, including the version of Encryption protocols and security components in the Technological Infrastructure.

c)

That which contains the detail of the type of information of the crowdfunding institution and Clients specifying, in their case, the type of Sensitive Information that will be stored by the third party in its equipment or facilities, or to which it may have access, in their case.

d)

The description of the control and monitoring mechanisms for access to computer systems and Sensitive Information transmitted, stored, processed, safeguarded, or custodied in said systems, as well as of the logs, databases, and security configurations established for this purpose.

e)

The evidence of the controls and of the control mechanisms referred to in fractions V and VI, subsection c) of Article 86 of these provisions.

VI.

Have the evidence referred to in fraction IX of the previous Article 86.

The general manager or, as applicable, the sole administrator shall be responsible for the implementation of the evaluations and remediation plans referred to in fraction III of this article.

Article 88.- Collective financing institutions must maintain a registry of all service providers, including those subcontracted by them, which must include, at least, the following information:

I. Name, corporate name, or business name of the service provider. II. Name of the legal representative of the service provider. III. Description of the service contracted with the third party, including the data or information that, as applicable, are stored, processed, or transmitted by this party. IV. As applicable, information on the systems supporting the service contracted with the third party, which must include at least the name, version, and function or purpose. V. As applicable, interfaces with other systems and the purpose of these, including the detail of the information exchanged. VI. Location where the service is performed and where the personnel responsible for carrying it out are located. VII. As applicable, location of the main data center where the processing equipment of the contracted system is located. VIII. As applicable, location of the alternate data center where the processing equipment is located, in the event of recovery of the contracted service. IX. As applicable, number and date of the official letter with which the CNBV granted the authorization.

Collective financing institutions must keep the registry referred to in this article updated.

Chapter IX Of the disclosure of information

First Section Of the disclosure of information in the publication of applications and projects

Article 89.- Collective financing institutions will include in the publications regarding the financing offers they make on their Platforms, information regarding the general analysis performed and any other variable that proves useful for Investors to make an informed investment decision.

Article 90.- Collective financing institutions that carry out Collective Financing Operations of Personal Loan Debt between Persons must disclose, for each financing application, the following information:

I. Amount of financing requested. II. Term of the Collective Financing Application. III. Description of the destination of the financing. IV. Term of the collective financing. V. Payment schedule of principal and interest, as well as their amount. VI. Ordinary interest rates and, as applicable, default interest rates. VII. As applicable, guarantees. VIII. Risk rating determined in accordance with the risk evaluation methodology defined by the collective financing institution, accompanied by a simple explanation of how to interpret it. IX. Schemes to share with Investors the risks of the Collective financing Operations. X. Data regarding the Applicant that are important for the decision-making of potential Investors, such as their age, sex, occupation, residence, and sources of income.

Article 91.- Collective financing institutions that carry out Collective Financing Operations of Business Loan Debt between Persons and for Real Estate Development must disclose for each Application or financing project, in addition to fractions I to IX of Article 90 above, the information corresponding to the type of collective financing in question, as detailed in Annex 15 of these provisions.

Article 92.- Collective financing institutions that carry out Collective Financing Operations of Capital must disclose for each project they promote on their Platform, the following information, as detailed in Annex 16 of these provisions:

I. Amount of financing requested. II. Term of the Collective Financing Application. III. Description of the ultimate purpose of the resources. IV. Description of the titles representing social capital and the rights acquired by the Investor, as well as the manner in which they will be compensated for the contributions they make. V. Risk rating determined in accordance with the risk evaluation methodology defined by the collective financing institution, accompanied by a simple explanation of how to interpret it. VI. Name and business activity of the legal entity, legal nature, date of incorporation, address of main offices, and, as applicable, website. VII. Description of the main elements that make up the business model or plan of the legal entity. VIII. Description of the dividend policy, as well as the risk factors that may significantly affect the performance and profitability of the legal entity. IX. Name of the administrator or administrators and, as applicable, the general manager, as well as the persons who exercise Control of the legal entity. X. Description of the financial situation, at the time of the financing application, of the legal entity considering aspects such as profitability, leverage, liquidity, and operational efficiency. At least the amount of equity capital, the main items of assets and liabilities, as well as the result of the previous fiscal year must be included. In the case of newly created companies, such situation must be stated and, as applicable, information regarding the business history or technical knowledge of the administrators or executors of the project, as well as the financial projections, if any, must be included. XI. The price of the titles representing the social capital of the legal entity offered, including a description of the method of determination and any limitation that exists for their acquisition. XII. As applicable, schemes to share with Investors the risks of the Collective financing Operations.

Article 93.- Collective financing institutions that carry out Collective Financing Operations of Co-ownership or Royalties must disclose, for each project they promote on their Platform, the following information:

I. Amount of financing requested. II. Term of the Collective Financing Application. III. Description of the destination of the financing including, as applicable, a description of the current state or financial situation of the project to be financed, as well as a model or business or investment plan for the resources and the manner of achieving the stated objectives, as well as the indicators on which the progress of the project or the achievement of results will be measured. IV. Explanation of the participation that the Investor will have in the present or future assets, income, profits, royalties, or, as applicable, losses derived from the project to be financed. V. Risk rating determined in accordance with the risk evaluation methodology defined by the collective financing institution, accompanied by a simple explanation of how to interpret it. VI. Information regarding the Applicant: a) In the case of natural persons, the aspects indicated in fraction X of Article 90 of these provisions must be disclosed, as well as a description of their productive activities. b) In the case of legal entities, the aspects indicated in fractions VI, VII, IX, and X of the previous Article 92 must be disclosed, to the extent applicable. c) Information regarding the strategic participants that the Applicant or the person responsible for the execution of the project may have, indicating the relationship that those have with the latter, as well as a description of the scope of their participation or contributions to the project. VII. As applicable, schemes to share with Investors the risks of the Collective financing Operations.

Second Section Of the disclosure of information regarding the payment behavior and performance of the Applicant or project

Article 94.- Collective financing institutions on whose Platforms Business Loan Debt Operations between Persons, Personal Loan Operations between Persons, and Real Estate Development Operations are carried out, must disclose to the Investors who are part of said Operations, the following information:

I. Indicators of the annualized return obtained by participating in the financing, including a description of its method of calculation. II. Payment and default indicators, indicating at minimum, if the credit is current in its payments of principal and interest, or in its defect, how many payments it has historically defaulted on and the total amount owed at the time of reporting, broken down by principal and financial accessories. For the purposes of the foregoing, default shall be understood as the event that occurs when the payment made by the Applicant is not enough to cover the payment that was committed according to the payment schedule programmed and agreed upon when the Operation was agreed. III. As applicable, update of the indicators on which it was defined that the progress of the financed project or the achievement of results would be measured.

Collective financing institutions must update the information referred to in fractions I and II above in accordance with the payment frequency defined in each Operation agreed.

Article 95.- Collective financing institutions that carry out Collective Financing Operations of Capital must make available to the Investors who have participated in the Operation in question, at least for the two years following the completion of the Operation, the following data:

I. The annual information of the administrators of the financed legal entity referred to in Article 172 of the General Law of Commercial Societies or equivalent. II. The risks and challenges faced by the financed legal entity. III. Financial indicators at the close of the reported annual fiscal year compared to the previous period, including a brief description of the method of calculation and its interpretation according to the following: a) Profitability, which is the result of dividing annual net profits by average capital to determine return on equity (ROE) or, the result of dividing annual net profits by average assets to determine return on assets (ROA). b) Leverage, which is the result of dividing total liabilities by total assets. c) Liquidity, which is the result of dividing liquid assets by total assets. Liquid assets are the sum of cash and bank accounts. d) Operational efficiency, which is the result of dividing annual administrative expenses by total annual revenues.

The data referred to in the fractions above must be made available through their Platform no later than April 30 of each year. Once the disclosure period referred to in the previous paragraph concludes, the collective financing institution must inform investors of such circumstance.

In the case of collective financing institutions that are also Investors through the implementation of schemes to share risks referred to in Article 21, second paragraph of the Law, the provisions of this article shall be applicable for the entire time that the institution is an Investor.

Article 96.- Collective financing institutions that carry out Collective Financing Operations of Co-ownership or Royalties must make available to the Investors who have participated in the Operation in question, at least for the two years following the completion of the Operation, a report on the business progress or project advancement, as well as disclose, at least annually, the indicators referred to in Article 94, fraction III of these provisions.

Third Section Of the disclosure of information to the general public

Article 97.- Collective financing institutions must maintain in a site of easy access for public consultation, within the Platforms they use to operate with their Clients, the aggregated information by type of financing granted in accordance with what is indicated in Annex 17 of these provisions.

FOURTH TITLE Of regulatory reports

Chapter I Of reports in general

Article 98.- Collective financing institutions must provide to the CNBV, with the frequency established in Article 99 below, the information attached to these provisions as Annex 18, which is identified with the series and reports listed below:

Series R01 Minimum Catalog. A-0112 Minimum Catalog. Series R08 Bank loans and from other organizations. D-0842 Disaggregated loans obtained. Series R10 Reclassifications. A-10112 Reclassifications in the statement of financial position. A-10122 Reclassifications in the statement of comprehensive income. Series R13 Financial Statements. A-13112 Statement of changes in equity. A-13162 Statement of cash flows. B-13212 Statement of financial position. B-13222 Statement of comprehensive income. Series R27 Claims. A-2702 Claims.

Article 99.- Collective financing institutions will present the information referred to in the previous Article 98, with the frequency indicated below:

I. Monthly, the information related to series R01, R08, R10, and R13, exclusively with respect to reports B-13212 and B-13222, which must be provided within the month immediately following the close of the calendar month being reported. II. Quarterly, the Information related to series R13, exclusively with respect to reports A-13112 and A-13162, and R27, which must be provided within the month immediately following the close of the calendar quarter being reported.

Article 100.- Payment fund institutions must provide to the CNBV, with the frequency established in Article 101 below, the information attached to these provisions as Annex 19, which is identified with the series and reports listed below:

Series R01 Minimum Catalog. A-0111 Minimum Catalog. Series R08 Bank loans and from other organizations. D-0843 Disaggregated loans obtained. Series R10 Reclassifications. A-10111 Reclassifications in the statement of financial position. A-10121 Reclassifications in the statement of comprehensive income. Series R13 Financial Statements. A-13111 Statement of changes in equity. A-13161 Statement of cash flows. B-13211 Statement of financial position. B-13221 Statement of comprehensive income. Series R26 Commissioner information. A-2610 Registrations and cancellations of commissioner administrators. A-2611 Disaggregated registrations and cancellations of commissioners. B-2612 Disaggregated registrations and cancellations of commissioner modules or establishments. C-2613 Disaggregated tracking of commissioner operations. Series R27 Claims. A-2701 Claims.

Article 101.- Payment fund institutions will present the information referred to in the previous Article 100, with the frequency indicated below:

I. Monthly, the Information related to series R01, R08, R10, R13, exclusively with respect to reports B-13211 and B-13221 and R26, exclusively with respect to report C-2613, which must be provided within the month immediately following the close of the calendar month being reported. II. Quarterly, the Information related to series R13, exclusively with respect to reports A-13111 and A-13161, and R27, which must be provided within the calendar month immediately following the close of the quarter being reported. III. By event, the information related to series R26, exclusively with respect to reports A-2610, A-2611, and B-2612, provided during the day of occurrence of the event individually or by the close of the day of occurrence of the event the total of the records.

Article 102.- FTIs will require prior authorization from the CNBV for the opening of new concepts or levels that are not contemplated in the series corresponding exclusively for the sending of information of the new operations that are authorized to them for this purpose by the Secretariat, in terms of the relevant legislation, for which they will request said authorization through a free-form letter within fifteen business days following the authorization made by the Secretariat. Likewise, in the event that changes in applicable regulations require establishing additional concepts or levels to those provided for in these provisions, the CNBV will inform the FTIs of the opening of the respective new concepts or levels.

In the two cases provided for in the previous paragraph, the CNBV will notify through the SITI the mechanism for recording and sending the corresponding information.

Chapter II Of the delivery means

Article 103.- FTIs, unless otherwise expressly provided, must send to the CNBV the information mentioned in this title, by transmitting it electronically using the SITI. In the event that there is no information for any report, institutions must send an empty submission, a functionality that is available in said system.

The information must comply with the validations established in the SITI, as well as the quality standards indicated by the CNBV through said system, and there must be consistency between the information that Institutions include in one or more regulatory reports referred to in these provisions, even if they are at a different level of integration. Likewise, the information must be sent only once and will be received assuming it meets all required characteristics, for which it cannot be modified, with the SITI generating an electronic receipt.

Once the information is received, it will be reviewed and if it does not meet the required quality and characteristics or is presented incompletely, the obligation to present it will be considered unfulfilled, and consequently, the corresponding sanctions will be imposed.

FTIs must send electronically to the address "cesiti@cnbv.gob.mx" the name of the person responsible for the quality and sending of the information referred to in this title, in the manner indicated in Annex 20 of these provisions. The designation of the person responsible for the quality of the information must fall on executives who are within the two lower hierarchies than the general manager or the sole administrator of the FTI, who have responsibility for the handling of the information. Likewise, they may designate more than one person as responsible for sending the information, depending on the type of information in question.

FTIs may request new user keys or access to regulatory reports in the SITI, by sending an email to the address "cesiti@cnbv.gob.mx" in the same manner as indicated in Annex 20.

Once the email referred to in this article is sent, the CNBV will notify the FTI by the same means, within five business days following the receipt of the request, the confirmation of the registration of the corresponding responsible person, as well as, as applicable, the access of the users of the requested regulatory reports.

The notification or substitution of any of the persons responsible for the sending and quality of the information referred to in this article, must be notified to the CNBV in the terms mentioned above, within three business days following the date of its designation or substitution.

SECOND ARTICLE.- Article FIFTH Transitory is REFORMED and Article SEVENTH Transitory of the "General Provisions applicable to financial technology institutions" published in the Official Journal of the Federation on September 10, 2018, is REPEALED, to read as follows:

"FIFTH.- Collective financing institutions may consider their Clients as Experienced Investors in terms of Article 2, fraction XXIII, subsection d) of these provisions, if said Clients had carried out Operations through one or more of the persons referred to in the EIGHTH Transitory Provision of the Law to Regulate Financial Technology Institutions."

"SEVENTH.- Repealed."

TRANSITORY PROVISIONS

FIRST.- This Resolution will enter into force the day following its publication in the Official Journal of the Federation.

SECOND.- The Fourth Title added to the General Provisions applicable to financial technology institutions by this Resolution will enter into force on January 1, 2020, so that financial technology institutions will begin to deliver the information referred to in Articles 98 and 100, with the frequency and deadlines established in Articles 99 and 101, respectively, on the dates indicated below, and only for the purposes of the first submission, with the information detailed in each case:

I. Regarding collective financing institutions: a) The information related to the regulatory reports of series R01, R08, R10, and R13, exclusively with respect to reports B-13212 and B-13222, no later than January 31, 2020, with the information covering the period from December 1 to December 31, 2019. b) The information related to the regulatory reports of series R13, exclusively with respect to reports A-13112 and A-13162 and R27, no later than January 31, 2020, with the information covering the period from October 1, 2019, to December 31, 2019. II. Regarding payment fund institutions: a) The information related to the regulatory reports of series R01, R08, R10, and R13, exclusively with respect to reports B-13211 and B-13221, no later than January 31, 2020, with the information covering the period from December 1 to December 31, 2019. b) The information related to the regulatory reports of series R13, exclusively with respect to reports A-13111 and A-13161 and R27, no later than January 31, 2020, with the information covering the period from October 1, 2019, to December 31, 2019. c) The information related to the regulatory report of series R26, on January 2, 2020, with the information as of December 31, 2019.

THIRD.- The obligation provided for in Article 97, which is added to the General Provisions applicable to financial technology institutions by this Resolution, shall enter into force on September 1, 2020.

Respectfully,

Mexico City, March 14, 2019.- The President of the National Banking and Securities Commission, Adalberto Palma Gómez.- Signature.

ANNEX 8

INSTRUCTIONS FOR OBTAINING ELECTRONIC CERTIFICATES OF AWARENESS OF RISKS

A. WARNINGS THAT COLLECTIVE FINANCING INSTITUTIONS MUST DISCLOSE TO INVESTORS REGARDING THE RISKS OF THEIR INVESTMENT

Collective financing institutions must indicate on their Platforms the importance of their Investors reading all information disclosed by the institution itself, regarding each of the financing requests from Applicants or projects in which they are considering investing. Likewise, these institutions must warn on their Platforms that Investors may only invest in published financing requests once they fully understand the risks of their investment, the manner and terms of the Operations they may enter into through the Platform, and that such Operations are consistent with their financial needs.

Collective financing institutions must disclose to Investors, prior to the execution of the contract that allows them to carry out Operations on the Platform in question, warnings regarding the risks to which their investment will be subject, such as the following:

I. The impossibility of disposing of the invested resources at the moment the Investor so requires.

II. The possibility that conditions may not exist for the sale of the rights or titles that document the Operations to take place through the collective financing institution.

III. The possibility of losing all resources invested through the collective financing institution, in the event that the Applicant does not pay the financing or it cannot be recovered.

IV. The possibility of investing, through the collective financing institution, in companies or projects in the formation stage that do not have a proven operational history, potentially losing up to one hundred percent of the investment. Additionally, the possibility of not receiving dividends, income, profits, or royalties, and that, as a result of the participation of more Investors in the company or project in question, corporate rights may be diminished.

V. The possibility that the financial statements of the companies or projects in which investment is made are not audited by an independent external auditor, so the financial information may not reasonably reflect the financial situation of the company or project in question.

VI. The possibility of receiving initial and subsequent limited information compared to what is observed in the securities market, so that, eventually, the Investor may not have sufficient information to make investment decisions.

VII. The prohibition established for collective financing institutions in accordance with what is provided in Article 20 of the Law and the impossibility referred to in Article 11, third paragraph of said legislation.

Each collective financing institution must add warnings regarding any other investment risk it identifies that is not contemplated in the preceding clauses, as well as display each warning with the font size predominantly used on the Platform it employs.

B. FORM FOR OBTAINING THE ELECTRONIC CERTIFICATE OF RISK AWARENESS

Once Investors confirm that they have read the warnings contained in section A above, collective financing institutions must collect, in a form provided by the institution itself, responses regarding the awareness of the risks to which these Investors are exposed by their investment.

The following is an example of the form referred to in the previous paragraph, which must be displayed by collective financing institutions on their Platform.

  1. Risk Information

Yes No

Loss Risk.- Do you understand that these investments are risky and that you may lose all invested money?

Liquidity Risk.- Do you understand that it is possible that you will not be able to cash out your investment prematurely?

Information Risk.- Do you understand that the information the collective financing institution provides regarding the offer and subsequent performance of the Financing Applicants may be limited?

Return Risk.- Do you understand that it is possible that you will not obtain any income or return, such as dividends or interest, from these investments?

  1. Approval and Advice

Yes No

No Approval.- Do you understand that the published investment offers have not been reviewed or approved in any way by the National Banking and Securities Commission or any other authority?

No Advice.- Do you understand that you will not receive advice on whether the investments are suitable for you?

  1. Regarding the Investment

Yes No

Investment Risks.- Have you read this form and do you understand the risks of carrying out these investments?

Disclosed Information.- Before investing, you must carefully read the information disclosed by each of the Financing Applicants in which you consider making the investment. If you have not read or do not understand this information, you should not invest.

Do you understand that, in addition to the general risks of investment, you must read and understand the information disclosed by the Financing Applicants?

  1. Investor Information

Full Name:

Date of questionnaire application:

Electronic Signature: By clicking the confirmation button, I acknowledge that I am signing this form electronically, producing the same effects that laws grant to a handwritten signature.

Collective financing institutions must formulate the questions of the form they design for this purpose in such a way that they cannot be answered entirely in the negative or positive sense.

When it is evident from any of the responses that the risks are not known, the collective financing institutions must automatically interrupt the contracting process and re-direct the Investor to the screen where the warnings of the general risks of investing in the Applicants or projects that the collective financing institution in question publishes through its Platform are described.

By submitting the responses with their advanced electronic signature or any other form of authentication in accordance with what is provided in Article 56, first paragraph of the Law, Investors will electronically attest that they are aware of the risks associated with their investment in the Applicants or projects that the collective financing institution publishes through its Platform.

Collective financing institutions must retain the original receipt of the electronic risk certificate for a minimum period of ten years, properly archived, either in printed format, or through electronic, optical, or any other technology.

ANNEX 9

FORMAT FOR DECLARATION REGARDING COMPLIANCE WITH THE REQUIREMENTS TO BE CONSIDERED AN EXPERIENCED INVESTOR

I, [NAME OF INTERESTED PARTY], declare that it is my interest to be considered an Experienced Investor under Article 2, clause XXIII, subsection d) of the General Provisions applicable to financial technology institutions, and that I am aware that acting with that status, in addition to the risks inherent to being an investor in a collective financing institution, implies being able to make investment commitments that exceed the percentages established in said provisions and, therefore, I could be concentrating my investment, which increases the risk of losing it.

I understand investment commitment as stated in Article 2, clause IV of those same provisions.

Having recognized the foregoing, I declare that I have carried out operations, as defined in the Law for Regulating Financial Technology Institutions, in collective financing institutions as an investor, whose aggregate amount is greater than the equivalent in national currency to 550,000 UDI's, and that I have at least 12 months of experience carrying them out.

I understand that [NAME OF THE COLLECTIVE FINANCING INSTITUTION IN QUESTION] will require the necessary information and documentation to verify that I meet the preceding condition; and that, if I do not provide it, I will not be considered an Experienced Investor for the purposes of Article 50, clause V of the aforementioned provisions.


NAME OF INTERESTED PARTY

OR LEGAL REPRESENTATIVE

AND SIGNATURE

ANNEX 11

Incidents affecting information security

I. Information of the collective financing institution

a) Name of the collective financing institution.

b) Full name of the Chief Information Security Officer, as well as their phone number and email address.

II. Detailed Information of the Information Security Incident

Description of the Information Security Incident

a) Date and time it occurred

b) Date and time it was detected

c) Duration of the incident

d) Is the information involved in the incident managed by third parties? Yes ( ) No ( )

e) If the answer to subsection d) is affirmative, detail provider data (name, address and contact data, email, phone, among others)

Impact caused by the Security Incident

f) Can the incident cause a monetary loss for Clients or for the collective financing institution itself? Yes ( ) No ( )

g) Is it viable to recover the possible monetary loss directly (own efforts) or indirectly (through insurance)? Yes ( ) No ( )

h) Have other related incidents been identified with the one reported, whether by origin, mode of operation, or impact? Yes ( ) No ( )

i) Indicate, if applicable, the type of information compromised with the Information Security Incident, according to the following tables:

Compromised Client Personal Information

Names Yes ( ) No ( )

Addresses Yes ( ) No ( )

Phone numbers Yes ( ) No ( )

Email addresses Yes ( ) No ( )

Biometric data (fingerprints, iris or retina patterns or facial recognition, among others) Yes ( ) No ( )

Other(s)

Account or Balance Information

Card numbers, or others Yes ( ) No ( )

Account numbers Yes ( ) No ( )

Passwords or identification numbers Yes ( ) No ( )

User identifiers Yes ( ) No ( )

Limits Yes ( ) No ( )

Balances Yes ( ) No ( )

Other(s)

Collective Financing Institution Information

Access keys Yes ( ) No ( )

Security configurations Yes ( ) No ( )

Port or service identification Yes ( ) No ( )

IP addresses of components or services Yes ( ) No ( )

IP addresses of internal components Yes ( ) No ( )

Access to internal network segments Yes ( ) No ( )

Software versions, operating systems, or databases Yes ( ) No ( )

Vulnerability identification Yes ( ) No ( )

Other(s)

III. Classify the reported Information Security Incident based on the following definitions:

a) Unintentional or accidental damage, loss of information, or loss of assets

Improperly shared information Yes ( ) No ( )

Errors or omissions in systems or devices Yes ( ) No ( )

Errors in procedures or controls Yes ( ) No ( )

Unauthorized changes to data Yes ( ) No ( )

Loss of information or devices Yes ( ) No ( )

Other(s):

b) Incidents due to failures or malfunctions

Devices Yes ( ) No ( )

Systems Yes ( ) No ( )

Communications Yes ( ) No ( )

Services Yes ( ) No ( )

Third-party equipment Yes ( ) No ( )

Supply chain Yes ( ) No ( )

Other(s)

c) Incidents due to interruption or lack of inputs

Absence of personnel Yes ( ) No ( )

Strikes Yes ( ) No ( )

Energy Yes ( ) No ( )

Water Yes ( ) No ( )

Telecommunications Yes ( ) No ( )

Other(s)

d) Incidents due to data interception

Espionage Yes ( ) No ( )

Messages Yes ( ) No ( )

Wardriving Yes ( ) No ( )

Man-in-the-middle attacks Yes ( ) No ( )

Session hijacking Yes ( ) No ( )

Sniffers Yes ( ) No ( )

Messaging theft Yes ( ) No ( )

Other(s)

e) Incidents due to malicious activity with the intent to take control, destabilize, or damage a computer system

Identity theft Yes ( ) No ( )

Phishing Yes ( ) No ( )

Denial of service (DOS, DDOS) Yes ( ) No ( )

Malicious code (malware, trojans, worms, code injection, virus, ransomware) Yes ( ) No ( )

Social engineering Yes ( ) No ( )

Certificate violation (site spoofing, false certificates) Yes ( ) No ( )

Hardware manipulation (anonymous proxies, skimmers, sniffers) Yes ( ) No ( )

Information alteration (address spoofing and routing table manipulation, DNS poisoning, configuration alteration) Yes ( ) No ( )

Abuse of audit applications Yes ( ) No ( )

Brute force attacks Yes ( ) No ( )

Abuse of authorizations Yes ( ) No ( )

Organized crime Yes ( ) No ( )

Hacktivists Yes ( ) No ( )

Government or affiliated groups Yes ( ) No ( )

Terrorists Yes ( ) No ( )

Insiders Yes ( ) No ( )

Other(s)

f) Incidents originating from legal aspects

Violation of contractual clauses Yes ( ) No ( )

Violation of confidentiality agreements Yes ( ) No ( )

Adverse decisions (judicial resolutions in the same jurisdiction or others) Yes ( ) No ( )

Other(s)

g) Others (specify)

IV. Classification of the Information Security Incident.

Indicate in the following table the classification in which the incident falls using the concepts from the catalog listed below:

Type

Sub Type

Sub Class of Events

I. Internal Fraud

1.1 Unauthorized Activities.

1.1.1 Undisclosed operations (intentional).

1.1.2 Unauthorized operations (with financial losses).

1.1.3 Incorrect valuation of positions (intentional).

( )

( )

( )

1.2 Internal Theft and Fraud.

1.2.1 Fraud / valueless deposits.

1.2.2 Extortion / embezzlement / theft.

1.2.3 Misappropriation of assets.

1.2.4 Destructive destruction of assets.

1.2.5 Internal Forgery.

1.2.6 Smuggling.

1.2.7 Misappropriation of accounts, identity, among others.

1.2.8 Non-compliance / tax evasion (intentional).

1.2.9 Bribery.

1.2.10 Abuse of insider information (not to the company's benefit).

( )

( )

( )

( )

( )

( )

( )

( )

( )

( )

1.3. System Security.

1.3.1 Violation of security systems.

1.3.2 Damage from cyberattacks.

1.3.3 Theft of information (with financial losses).

1.3.4 Inadequate use of access keys and/or authorization levels.

( )

( )

( )

( )

( )

II. External Fraud

2.1 External Theft and Fraud.

2.1.1 Theft / fraud / extortion / bribery.

2.1.2 External Forgery / Impersonation.

2.1.3 Use and/or disclosure of privileged information.

2.1.4 Industrial espionage.

2.1.5 Smuggling.

( )

( )

( )

( )

( )

2.2 System Security.

2.2.1 Violation of security systems.

2.2.2 Damage from cyberattacks.

2.2.3 Theft of information (with financial losses).

2.2.4 Inadequate use of access keys and/or authorization levels.

( )

( )

( )

( )

III. Business Incidents and System Failures

3.1 Systems

3.1.1. Hardware.

3.1.2. Software.

3.1.3 Telecommunications.

3.1.4. Interruption / supply incidents.

( )

( )

( )

( )

Name and signature of the Chief Information Security Officer

ANNEX 12

Report on information security incidents

I. Information of the collective financing institution

a) Name of the collective financing institution.

b) Full name of the information security officer, as well as their phone number and email address.

II. Detailed Information of the Information Security Incident

Attach, in encrypted digital media, the following information:

Description of the Information Security Incident.

Affected account numbers.

Status of affected accounts (blocked, suspended, active).

Affected network zone (Internet, internal network, administration network, among others).

Type of affected system (file server, web server, email service, database, workstations, either desktop or mobile, among others).

Operating system (specify version).

Protocols or services of the impacted components.

Number of components of the collective financing institution's systems affected.

Applications involved (specify version).

Compromised device information, if applicable (brand, software version, firmware, among others).

Impact on service (considering any disruption) caused by the Information Security Incident.

Amount of loss in pesos, if applicable.

Amount recovered in pesos, if applicable.

Status of the Information Security Incident (Resolved or Unresolved).

Indicate if the Information Security Incident has been disclosed to any authority. If affirmative, indicate the authority and the date.

Public IP addresses, email addresses, or domains from which the attack originates.

The communication protocol used, if applicable.

The URL in case of websites involved.

The detected malware or signature.

Detail the actions taken to mitigate the Information Security Incident, mentioning the persons responsible for implementing said mitigation actions.

Description of the results of the mitigation actions.

Incident recovery times.

Actions to minimize damage in similar subsequent situations.

Other information deemed necessary for the CNBV's knowledge.

Communication actions with Clients to inform them of the incident.

Name and signature of the Chief Information Security Officer

ANNEX 13

Information security indicators

The Chief Information Security Officer of the collective financing institution, in relation to the risk indicators in information security referred to in clause XI of Article 66, of these provisions, must:

Evaluate these indicators, which must adhere to the thresholds contained in this annex for each indicator. In the event of defining different thresholds, the reason must be documented.

Define remediation plans for those risks where the evaluation results yield values that fall within the medium and high risk thresholds established in this annex or, if applicable, those defined by the collective financing institution, provided they are in a high threshold for at least two consecutive periods.

Provide continuous maintenance, whether to add, eliminate, or update key risk indicators and information security performance indicators already existing, which must always be aligned with the collective financing institution's strategy and the Information Security Master Plan of this.

Measure and evaluate their evolution with the periodicity indicated in the following tables, or earlier in the event of unusual events.

In the event that not all conditions apply, indicate that they are not applicable and explain the reason.

Type

Definition

Sub Type

Sub Class of Events

Examples

I. Internal Fraud

Losses derived from any type of action directed at defrauding, improperly appropriating goods, or bypassing regulations, laws, or corporate policies (excluding diversity / discrimination events) in which at least one internal party to the Financial Technology Institution is involved.

1.1 Unauthorized Activities.

1.1.1 Undisclosed operations (intentional).

1.1.2 Unauthorized operations (with financial losses).

1.1.3 Incorrect valuation of positions (intentional).

Operations not communicated; unauthorized operations (with financial losses); incorrect valuation of positions, and intentional omission of regulations.

1.2 Internal Theft and Fraud.

1.2.1 Fraud / valueless deposits.

1.2.2 Extortion / embezzlement / theft.

1.2.3 Misappropriation of assets.

1.2.4 Destructive destruction of assets.

1.2.5 Internal Forgery.

1.2.6 Smuggling

1.2.7 Misappropriation of accounts, identity, among others.

1.2.8 Non-compliance / tax evasion (intentional)

1.2.9 Bribery.

1.2.10 Abuse of insider information (not to the company's benefit).

Theft; embezzlement; misappropriation; asset destruction; forgeries; identity spoofing; and bribes; manipulation of accounts.

1.3. System Security.

1.3.1 Violation of security systems.

1.3.2 Damage from cyberattacks.

1.3.3 Theft of information (with financial losses).

1.3.4 Inadequate use of access keys and/or authorization levels.

Abuse and use of privileged or confidential information; alteration of computer applications; theft of passwords, and prohibited computer access.

II. External Fraud

Losses derived from any type of action directed at defrauding, improperly appropriating goods, or bypassing legislation, by a third party.

2.1 External Theft and Fraud.

2.1.1 Theft / fraud / extortion / bribery.

2.1.2 External Forgery / Impersonation.

2.1.3 Use and/or disclosure of privileged information.

2.1.4 Industrial espionage.

2.1.5 Smuggling.

Forged or manipulated documents (transfers, etc.); identity spoofing; improper dispositions; counterfeit coins; deteriorated banknotes or out of legal circulation; thefts in the IFC facilities, and improper use of stolen or forged cards.

2.2 System Security.

2.2.1 Violation of security systems.

2.2.2 Damage from cyberattacks.

2.2.3 Theft of information (with financial losses).

2.2.4 Inadequate use of access keys and/or authorization levels.

Unauthorized computer access; manipulation of computer applications; damage from cyberattacks, and theft of

information.

VI. Incidents in

Business and Failures in

the Systems

Losses derived from

business incidents and

system failures.

6.1 Systems

6.1.1

Hardware.

6.1.2

Software.

6.1.3

Telecommunications.

6.1.4

Interruption / business incidents.

Interruption / incidents in supplies

and communication lines; errors in

computer programs; hardware and

software failures;

sabotage; business interruptions;

computer failures and virus programming.

ID

Name

Description

Domain

Type

Sub Type

Sub Class of

Events

Type of

Indicator

Period

Unit of

Measurement

Calculation

Variable X

Variable Y

High

Risk

Medium

Risk

Low

Risk

KRI0001

Incidents

via direct

attacks

against

internal

systems

Number of incidents

that have been originated by

attacks against the internal systems of the

Financial Technology Institution, in the

established period.

Logical

attacks.

II. External

Fraud.

2.2 Security of

the Systems.

2.2.1 Breach of

security systems.

Reactive.

Quarterly.

Quantity.

Variable X

Number of cases

of identified

incidents.

More than 1.

Equal to 1.

Equal to 0.

KRI0002

Fraud cases

on the platform.

Percentage of cases

where fraud is identified,

that has been

originated by attacks

against the Platform.

.

Logical

attacks.

II. External

Fraud

2.2 Security of

the Systems.

2.2.1 Breach of

security systems.

Reactive.

Monthly.

Percentage.

(X/Y)*100

Number of fraud

cases on the

Platform.

Number of

Clients who

use the

Platform.

More than

.01 %.

Between

0.005 %

and 0.01

%.

KRI0003

Equipment of

the Technological

Infrastructure

from which

its security

configuration

is managed.

Percentage of equipment

of Technological Infrastructure within the

Platform and/or process of

review of secure configuration

standards, with

respect to the total

equipment of the IFC during the

established period.

Compliance.

II. External

Fraud.

2.2 Security of

the Systems.

2.2.1 Breach of

security systems.

Preventive.

Monthly.

Percentage.

(X/Y)*100

Number of equipment

within the

platform or

process of review

of secure configuration

standards.

Total number

of equipment.

Less than

85 %.

Between 85

% and 95

%.

More than

95 %.

KRI0004

Level of

compliance of

secure

configuration

of servers

from which

its configuration

is managed.

Average percentage of

compliance level of

servers contemplated

within the tool and/or process of review of

secure configuration

standards.

Compliance.

II. External

Fraud

2.2 Security of

the Systems.

2.2.1 Breach of

security systems.

Preventive.

Monthly.

Average

percentage.

Average(

X)

% of compliance

of the secure

configuration

standard of each

one of the

Servers.

Less than

90 %.

Between 90

% and 95

%.

More than

95 %.

KRI0005

Users with

inadequate

roles and profiles.

Percentage of users

with inadequate profiles

within the applications

of the IFC, with respect to

the total of users in all

applications

of the

Financial Technology Institution.

Compliance.

I. Internal

Fraud

1.3. Security of

the systems.

1.3.3

Theft of

information (with

financial losses).

1.3.4

Inadequate

use of access

keys and/or levels

of authorization.

Corrective.

Semi-annual

.

Percentage.

(X/Y)*100

Number of

users with

incorrect profiles,

considering all

applications.

Total number

of users

considering

all

applications.

More than 3

%.

Between 1%

and 3 %.

Less

than 1 %.

KRI0006

Applications

without roles

and profiles.

Percentage of

applications which do not

possess the capacity

nor the

profiling of

roles

and

permissions, or that said

profiles are not

implemented, this with

respect to the total of

applications.

Compliance.

I. Internal

Fraud.

1.3. Security of

the systems.

1.3.3 Theft of

information (with

financial losses).

1.3.4 Inadequate

use of access

keys and/or levels

of authorization

Corrective.

Quarterly.

Percentage.

(X/Y)*100.

Number of

applications without capacity

of

profiling, or

profiling not

implemented.

Total number

of

applications.

More than 5

%.

Between 2

% and 5 %.

Less

than 2 %.

KRI0007

Security incidents

of information

generally

Total number of

incidents reported

during the established

period referring to

information security.

Information.

Applies to:

I.

Internal

Fraud

II.

External

Fraud

VI.

Incidents

in Business

and Failures in

the Systems.

Apply to:

1.3. Security of

the systems

2.2 Security of

the Systems.

6.1 Systems.

Apply to:

1.3.1

Breach of

security systems

1.3.2

Damage from

computer attacks.

1.3.3

Theft of

information (with

financial losses).

1.3.4

Inadequate

use of access

keys and/or levels of

authorization.

Reactive.

Monthly.

Quantity.

Variable X.

Number of

security incidents.

of information

More than 5.

From 2 to 5.

Less

than 2.

2.2.1 Breach of

security systems.

2.2.2 Damage from

computer

attacks.

2.2.3 Theft of

information (with

financial losses).

2.2.4 Inadequate

use of access

keys and/or levels of

authorization.

6.1.1 Hardware.

6.1.2 Software.

6.1.3

Telecommunications.

6.1.4 Interruption /

incidents in the

Supply

KRI0008

Obsolete and/or

outdated technological

platforms

Percentage of technological

platforms that are on

obsolete versions and/or

without support from the

manufacturer

Infrastructure.

II. External

Fraud.

2.2 Security of

the Systems.

2.2.1 Breach of

security systems.

Corrective.

Semi-annual

Percentage.

(X/Y)*10.

Number of

technological

platforms

obsolete.

Total of

technological

platforms.

More than 5

%.

Between 2

% and 5 %.

Less

than 2 %

KRI0009

System outages

related to

the services

provided to

their

Clients

Number of system outages related

to the services

provided to their Clients

greater than 10 minutes.

Infrastructure.

VI.

Incidents

in Business

and failures in

the systems

6.1 Systems.

6.1.4 Interruption /

incidents in the

Supply.

Reactive.

Monthly.

Quantity.

Variable X.

Number of

outages

of

systems.

More than 1.

Equal to 1.

Equal to 0.

KRI0010

Security incidents

from system

vulnerabilities

provided by

providers

(third parties).

Percentage of security

incidents caused

by vulnerabilities in

systems and infrastructure

technology provided by

providers (third parties)

that do not belong to the

payroll of the IFC,

reported during the

established period, with

respect to the total of

security incidents.

Infrastructure.

II. External

Fraud.

2.2 Security of

the Systems.

2.2.1

Breach of

security systems.

2.2.2

Damage from

computer attacks.

2.2.3

Theft of

information (with

financial losses).

2.2.4 Inadequate

use of access

keys and/or levels of

authorization.

Reactive.

Monthly.

Percentage.

(X/Y)*100.

Number of

security incidents

attributed to

vulnerabilities in

systems provided

by providers

(third parties).

Total number

of security

incidents.

More than 5

%.

Between 0.1

% and 5 %.

Less than

0.1 %.

KRI0011

Critical

vulnerabilities

pending to

correct

detected in

ethical hacking

tests.

Number of

vulnerabilities in the

information systems

that, according to the

ethical hacking tests,

are classified as

critical, which have

more than one month of

age from their

date of detection.

Infrastructure.

II. External

Fraud.

2.2 Security of

the Systems.

2.2.1 Breach of

security systems.

Preventive.

Monthly.

Quantity.

Variable X.

Number of

critical vulnerabilities

pending to correct with

age of more

than one month.

More than 2.

Between 1 and

Equal to 0.

KRI0012

Unavailability

of the IT

systems.

Average percentage of

unavailability time of

the systems against the

total time of the established

period.

Infrastructure.

VI.

Incidents in

Business and

Failures in

the Systems.

6.1 Systems.

6.1.4 Interruption /

incidents in the

Supply.

Reactive.

Monthly.

Average

Percentage.

Average(

X).

Average of

unavailability time of

IT systems.

More than 0.5

%.

Between

0.25 %

and 0.5 %.

Less

than

0.25 %.

KRI0013

Critical and high

priority incidents

in production

environments.

Percentage of incidents

qualified as critical and

high priority in

production environments

with respect to the total of

incidents in

production.

Infrastructure.

II. External

Fraud.

2.2 Security of

the Systems.

2.2.1 Breach of

security systems.

Reactive.

Monthly.

Percentage.

(X/Y)*100.

Number of

incidents in

production

qualified as

critical.

Total number

of incidents

in production.

Greater than

or equal to 0.5

%.

Greater than

0% and

less

than 0.5 %.

Equal to 0

%.

KRI0014

Components of

the technological

infrastructure

exposed to

internet without

ethical hacking

tests and/or

vulnerability

analysis

.

Percentage of the

components of the

infrastructure

technology of the

organization exposed towards internet to which

ethical hacking or vulnerability

analysis has not been

performed, with

respect to the total of

equipment for more than 3

months.

Infrastructure.

II. External

Fraud.

2.2 Security of

the Systems.

2.2.1 Breach of

security systems.

Corrective.

Quarterly.

Percentage.

(X/Y)*100.

Number of assets

exposed to

internet that have

not performed

ethical hacking

tests or vulnerability

analysis.

Number of

assets

exposed to

internet.

More than 3

%.

Between

1 % and 3

%.

Less

than 1 %.

KRI0015

Critical

vulnerabilities

pending to

correct

detected in

vulnerability

analyses

.

Number of

vulnerabilities in the

information systems

that, according to the

vulnerability

analyses, are

classified as critical,

which have more than

one month of age from

their date of detection.

Infrastructure.

II. External

Fraud.

2.2 Security of

the Systems.

2.2.1 Breach of

security systems.

Corrective.

Monthly.

Quantity.

Variable X.

Total number of

critical vulnerabilities.

More than 2

Between 1 and

2

Equal to 0

KRI0016

Obsolete Technological

Infrastructure

and/or without

support.

Number of equipment and

Technological Infrastructure,

which are in obsolete

versions or without support,

in comparison with all

active IT infrastructure in the established

period.

Infrastructure.

II. External

Fraud.

2.2 Security of

the Systems.

2.2.1 Breach of

security systems.

Corrective.

Quarterly.

Percentage.

(X/Y)*100.

Number of equipment

and obsolete

infrastructure.

Total number

of active

equipment.

More than 5

%.

Between 2

% and 5 %.

Less

than 2 %.

KRI0017

Servers without

antimalware

solution.

Percentage of servers

without antimalware with respect to the total of servers.

Malware.

II. External

Fraud.

2.2 Security of

the Systems.

2.2.1 Breach of

security systems.

Corrective.

Monthly.

Percentage.

(X/Y)*100.

Number of

servers without

antimalware.

Total number

of servers.

More than 6

%.

Between 3%

and 6 %.

Less than

3 %.

KRI0018

Servers with

outdated

antimalware

signatures.

Percentage of servers

with outdated antimalware

signatures (malware signatures)

with respect to the total of servers with

antimalware in each

IFC

Malware.

II. External

Fraud.

2.2 Security of

the Systems.

2.2.1 Breach of

security systems.

Corrective.

Monthly.

Percentage.

(X/Y)*100.

Number of

servers with

outdated antimalware

signatures.

Total number

of servers

with

antimalware.

More than 6

%

Between 3%

and 6 %

Less than

3 %

KRI0019

Workstations without

antimalware

solution

Percentage of

workstations without

antimalware with respect to the total of equipment

Malware.

II. External

Fraud.

2.2 Security of

the Systems.

2.2.1 Breach of

security systems.

Corrective.

Monthly.

Percentage.

(X/Y)*100.

Number of

workstations without

antimalware.

Total number

of

workstations.

More than 8

%.

Between 4%

and 8 %.

Less than

4 %.

KRI0020

Workstations

with outdated

antimalware

signatures.

Percentage of the

workstations that have

outdated antimalware

signatures (malware

signatures) with

respect to the total of

computing equipment with

antimalware installed.

Malware.

II. External

Fraud.

2.2 Security of

the Systems.

2.2.1 Breach of

security systems.

Corrective.

Monthly.

Percentage.

(X/Y)*100.

Number of

workstations with

outdated antimalware

signatures.

Number of

workstations

with

antimalware.

More than 8

%.

Between 4%

and 8 %.

Less than

4 %.

KRI0021

Security incidents

attributed to

provider

personnel

(third parties).

Percentage of security

incidents

related to personnel

of providers (third parties)

that do not belong to the

payroll of the IFC,

reported during the

established period, with

respect to the total of

security incidents.

Incidents.

II. External

Fraud.

2.2 Security of

the Systems.

2.2.1 Breach of

security systems.

Reactive.

Monthly.

Percentage.

(X/Y)*100.

Number of

security incidents

related to

provider personnel

(third parties).

Number of

security incidents

total of personnel

of

providers

(third parties).

More than 5

%.

Greater than

0 % and

less than 5

%.

Equal to 0

%.

KRI0022

Servers with

obsolete

operating system

versions.

Total percentage of

servers with obsolete

operating system

versions compared

against total number of

servers.

Software.

II. External

Fraud.

2.2 Security of

the Systems.

2.2.1 Breach of

security systems.

Corrective.

Monthly.

Percentage.

(X/Y)*100.

Number of

servers with

obsolete operating system

versions.

Total number

of servers.

More than 10

%.

Between 5%

and 10 %.

Less than

5 %.

KRI0023

Applications in

production with

partial or

deficient

compliance of

security controls.

Percentage of the

applications in

production with

partial or

deficient compliance, with respect to the established security

policies, in matters of

security, with respect to

the total of

applications.

Software.

II. External

Fraud.

2.2 Security of

the Systems.

2.2.1 Breach of

security systems.

Corrective.

Quarterly.

Percentage.

(X/Y)*100.

Number of

security controls

deficient in

applications in

production.

Total number

of security

controls.

More than 5

%.

Between 2

% and 5 %.

Less

than 2 %.

KRI0024

Database

managers

(DBM) with

obsolete or

unsupported technology

versions.

Percentage of database managers (DBM), which

are obsolete technology

versions or

unsupported by the

manufacturer, in

comparison with the total

of database managers

(DBM) active in the

established period.

Software.

II. External

Fraud.

2.2 Security of

the Systems.

2.2.1 Breach of

security systems.

Corrective.

Quarterly.

Percentage.

(X/Y)*100.

Number of database

managers

(DBM) obsolete or

unsupported.

Total number

database

managers

(DBM).

More than 10

%.

Between 5

% and 10

%.

Less

than 5 %.

KRI0025

Obsolete or

unsupported

applications.

Percentage of

applications within the

IFC, which are

obsolete or

without support from the

manufacturer, in relation to

all active applications

during the

established period.

Software.

II. External

Fraud.

VI.

Incidents in

Business and

Failures in

the Systems.

2.2 Security of

the Systems.

6.1 Systems.

2.2.1 Breach of

security systems.

6.1.2 Software.

Corrective.

Quarterly.

Percentage.

(X/Y)*100.

Number of

applications

obsolete or unsupported.

Total of

active

applications.

More than 5

%.

Between 2

% and 5 %.

Less

than 2 %.

KRI0026

Servers without

security patch

coverage.

Percentage of servers

without the most recent

security patches,

with respect to the total of

active servers during the

established period.

Software.

II. External

Fraud.

2.2 Security of

the Systems.

2.2.1 Breach of

security systems.

Corrective.

Monthly.

Percentage.

(X/Y)*100.

Number of

servers without the

most recent

security patches

installed.

Total of

servers.

More than 5

%.

Between 2

% and 5 %.

Less

than 2 %.

KRI0027

Workstations without

security patch

coverage.

Percentage of

workstations without the most recent

security patches regardless

of the operating system

of which they are,

with respect to

the total of workstations of the

IFC

Software.

II. External

Fraud.

2.2 Security of

the Systems.

2.2.1 Breach of

security systems.

Corrective.

Monthly.

Percentage.

(X/Y))*100.

Number

of workstations without the

most recent

security patches

installed total.

Number of

workstations

total.

More than 3

%.

Between 1

% and 3 %.

Less

than 1 %.

KRI0028

Database

managers

(DBM) without

security patch

coverage.

Percentage of database

managers (DBM) without

coverage of the most recent

security patches, with respect to the

total of database

managers (DBM) during the

established period.

Software.

II. External

Fraud.

2.2 Security of

the Systems.

2.2.1 Breach of

security systems.

Preventive.

Quarterly.

Percentage.

(X/Y)*100.

Number of database

managers

(DBM) without

coverage of

security patches.

Total number

of database

managers

(DBM).

More than 5

%.

Between 2

% and 5 %.

Less

than 2 %.

ANNEX 14

Format for Application System Information (F-SA)

Instructions: The numerals 1 to 11 must be removed from each title of the columns of the table once the format is documented, as well as the instructions that appear in the footer of the table, and the examples contained within it.

Name of the

application or

system 1

Related business

process(es)

with the system 2

Name of the equipment where

it is processed 3

Language 4

Platform (brand and

model of the main computing equipment of the

application or system) 5

Operating system 6

Database 7

Cloud

Services 8

Application Provider /

Self-development 9

Processing Location (Main / Alternate Site) 10

Operation Location

(Main Site /

Alternate) 11

Physical

Virtual

Physical

Virtual

Self /

Third Parties (a)

Location (b)

National /

Foreign

Location

Example 1:

Name of

System

< Collection,

Placement,

Teller, etc. >

< SRVCORE1 >

< JAVA 1.1 >

< IBM i 7.2 >

<UNIX>

< NA >

< Provider4, S.A

de C.V. >

< Third Parties >

< Main computer center

Triara, S.A. de C.V.

Mexico City

Col. Del Valle, CP

03100 >

< Alternate computer center

Mexico City

Alfonso Nápoles

Gándara 50, Col.

Peña Blanca Santa

Fe, CP 01210 >

< National >

< Corporate >

< SOCPROD2 >

<Windows Server

2018>

< Oracle >

< Foreign >

< Main office

Bournemouth, United

Kingdom >

< Alternate office

Bournemouth, United

Kingdom >

< SOCPROD3 >

<Windows Server

2012>

Example 2:

Name of

System

< Collection,

Placement,

Teller, etc. >

< SOCPROD2 >

< RPG II >

< Fedora >

< DB2 >

< SaaS >

< Provider1, S.A

de C.V. >

< Third Parties >

< North Zone of

United States of

North America >

< National >

< Alternate computer center

Mexico City

Alfonso Nápoles Gándara

50, Ground Floor Col. Peña

Blanca Santa Fe, CP 01210

< SOCPROD3 >

<Windows

Server 2012>

< Corporate >

< ... >

< ... >

< ... >

< ... >

< ... >

< ... >

< ... >

< ... >

< ... >

< ... >

< ... >

< ... >

< ... >

< ... >

< ... >

Name of the application or system: capture the name by which the application or system is identified internally within the Entity

or commercially.

Related business process(es) with the system: describe the business process(es) supported by the system.

Name of the equipment where it is processed: capture the name by which the physical and virtual server is identified internally within the

Entity.

Language: indicate the programming language(s) of the system including its version.

Platform (brand and model of the main computing equipment of the application or system): capture the brand and model of the physical server

(main equipment) where the system is processed.

Operating system: capture the name and version of the operating system of the physical and virtual equipment where the system is processed and/or the virtual machine resides.

Database: database where the information processed by the application is stored.

Cloud Services: include, if applicable, the type of service contracted in the cloud scheme: N/A (Not Applicable), SaaS (Software as a Service), IaaS (Infrastructure as a Service).

Application Provider / Self-development: if it is an internal development indicate: "Self-development"; if it is an

external development, include the legal name of the system provider.

Processing Location (Main / Alternate Site):

(a)

Indicate "Self" if the computer center belongs to the Entity; otherwise, the legal name of the provider of the

Main Computer Center must be indicated.

(b)

Specify the name of the computer center as it is known internally within the Entity or commercially, and the

full address where the main and alternate computer centers are located (street, number,

colony, delegation or municipality, state, postal code) when national. For foreign addresses,

the equivalent information to that stated above must be specified.

Operation Location (Main / Alternate Site): indicate if they are located in national or foreign territory (National/Foreign column) and specify the full address where the personnel who have access and operate the system in question are located

(Location column).

ANNEX 15

Guidelines for the disclosure of information on Collective Financing of Debt for Business Loans between Individuals and for Real Estate Development

I.

General Aspects

These guidelines establish the general criteria for information disclosure and minimum

contents that collective financing institutions must follow in the disclosure of information

they make regarding Collective Financing of Debt for Business Loans between Individuals and

for Real Estate Development that they promote through their Platforms. Collective financing institutions

may present the information referred to in this annex in the order they determine, being required to present it in all financing offers consistently. To this

effect, collective financing institutions must:

a.

Ensure that the information that proves relevant for the

Investors can make informed decisions, based on the knowledge that the collective financing institutions themselves have of the financing project and on the risk analysis and evaluation they have performed.

b. Include the most recent information known at the time of its publication on the Platform.

c. Determine the depth and breadth with which the information indicated in this annex will be disclosed, including any additional or complementary information to that established in this. In the event that a section does not apply, they must specify such situation.

d. Indicate the source of the reports, statistics, analyses, opinions or other public information they use and when the information comes from a third party, a declaration must be included indicating that such information has been considered with the consent of said third party, if applicable.

e. Express monetary figures in Mexican pesos and in the case of figures whose original source is denominated in foreign currency or virtual assets, the exchange rate used to convert them to Mexican pesos must be specified, indicating the date to which it corresponds and the source that publishes it. It must also be clarified that such conversion was carried out solely to facilitate reading and understanding by Investors.

f. Use clear, concise and easy-to-understand language, as well as avoid the use of technical terms or complex legal formalisms that cannot be easily understood by a person who does not have specialized knowledge in the subject matter and avoid the use of superlative terms and value judgments.

II. Information that must be disclosed regarding Collective Debt Financing for Business Loans between Individuals

A. Regarding the collective financing referred to in Article 2, fraction XV, subsection a) of these provisions

With respect to the financing

i) Amount of the financing requested.

ii) Term of the Collective Financing Application.

iii) Description of the use of the financing.

iv) Term of the collective financing.

v) Main source of payment for the financing.

vi) Payment schedule for principal and interest, as well as their amount.

vii) Ordinary interest rates and, if applicable, default interest.

viii) Real or personal guarantees, if applicable.

ix) Risk rating determined according to the risk evaluation methodology defined by the collective financing institution, accompanied by a simple explanation of how to interpret it.

x) The participation that collective financing institutions assume when, if applicable, they are Investors through the implementation of risk-sharing schemes referred to in Article 21, second paragraph of the Law.

With respect to the Applicant

In the case of a natural person with business activity:

i) Information related to their age, sex, residence, academic background and professional or business experience.

ii) Description of their main activity.

iii) Information regarding the economic solvency of the Applicant, including a description of their income sources.

iv) Description of the main source of payment for the requested financing.

In the case of a legal entity:

i) Name and business line, legal nature, date of incorporation, address of main offices, geographic coverage or location of main branches and, if applicable, website.

ii) Description of their objectives or business model, as well as an explanatory note on their administration (if it is a family business, if there is a person or group of people who exercises control, among other aspects).

iii) Distribution and marketing channels, including an explanation of the sales method used (for example, sales through electronic means).

iv) In the event that the legal entity requests financing for a specific project, provide a description of this and the expected benefits; the relevance of said project for its objectives or business model, as well as, if applicable, the indicators through which the progress and results of the project will be measured, the time in which they are expected to be achieved and the form and frequency with which Investors participating in the collective financing will be informed about the progress and results of the project.

v) Business history or technical knowledge of the administrators or executors of the project; if the source of payment for the financing depends on it.

vi) Description of the financial situation of the legal entity at the time of the financing application, considering aspects such as profitability, leverage, liquidity and operational efficiency.

vii) Selected financial indicators that include, at least, the amount of equity capital, the main items of assets and liabilities, as well as the result of the previous fiscal year.

viii) In the case of newly created companies, this situation must be indicated, stating that this could increase the risk of the project, and if applicable, information regarding the business history or technical knowledge of the administrators or executors of the project must be included; as well as the financial projections, if any.

ix) If applicable, it must be indicated whether the company is part of or has participated in any business or commercial incubator programs, as well as the description of the resources and services received under said program.

With respect to risk factors

The risk factors that could affect the payment capacity of the Applicants must be explained, such as: business strategy risks, lack of liquidity for the recently created company, increase in debt, increase in certain interest rates, adverse market conditions, economic recession, technological changes or changes in consumer preferences, increases in production or distribution costs, dependence on key clients or suppliers, natural disasters, entry of new competitors into the industry, legal or regulatory changes, environmental risks related to assets, inputs, products or services, among others.

With respect to the implementation of guarantees

The circumstances, mechanisms and procedures to make them effective must be indicated; the rights they grant to Investors and the role that, if applicable, the collective financing institution plays in that process.

With respect to periodic disclosure

It must be indicated what type of information or indicators will be disclosed to participating Investors, regarding the progress of the financed project and the impact of the financing obtained on their business activities. It must also be explained how Investors can access this information.

B. Regarding the collective financing referred to in Article 2, fraction XV, subsection b) of these provisions (financial leasing)

With respect to collective financing

i) Amount of the financing requested.

ii) Term of the Collective Financing Application.

iii) Description of the use of the financing.

iv) The characteristics of the goods subject to the Operation.

v) The obligations borne by the Applicant and, if applicable, by Investors, in relation to said goods.

vi) Term of the collective financing.

vii) Main source of payment for the financing.

viii) If applicable, description of the conditions for the purchase of the goods subject to the Operation at the end of this, by the Applicant.

ix) Payment schedule for principal and interest, as well as their amount.

x) Ordinary interest rates and, if applicable, default interest.

xi) Risk rating determined according to the risk evaluation methodology defined by the collective financing institution, accompanied by a simple explanation of how to interpret it.

xii) The participation that collective financing institutions assume when, if applicable, they are Investors through the implementation of risk-sharing schemes referred to in Article 21, second paragraph of the Law.

With respect to the Applicant

In the case of a natural person with business activity

i) Information related to their age, sex, residence, academic background and professional or business experience.

ii) Description of their main activity.

iii) Information regarding the economic solvency of the Applicant; including a description of their income sources.

iv) Description of the main source of payment for the requested financing.

In the case of a legal entity

i) Name and business line, legal nature, date of incorporation, address of main offices, geographic coverage or location of main branches and, if applicable, website.

ii) Description of the financial situation of the company at the time of the financing application, considering aspects such as profitability, leverage, liquidity and operational efficiency.

iii) Selected financial indicators that include, at least, the amount of equity capital, the main items of assets and liabilities, as well as the result of the previous fiscal year.

iv) If applicable, it must be indicated whether the company is part of or has participated in any business or commercial incubator programs, as well as the description of the resources and services received under said program.

With respect to risk factors

The risk factors that could affect the payment capacity of the Applicants must be explained, such as: business strategy risks, lack of liquidity for the recently created company, increase in debt, increase in certain interest rates, adverse market conditions, economic recession, technological changes, or changes in consumer preferences, increases in production or distribution costs, dependence on key clients or suppliers, natural disasters, entry of new competitors into the industry, legal or regulatory changes, environmental risks related to assets, inputs, products or services, among others.

With respect to periodic disclosure

It must be indicated what type of information or indicators will be disclosed to participating Investors. It must also be explained how Investors can access this information.

C. Regarding the collective financing referred to in Article 2, fraction XV, subsection c) of these provisions (financial factoring)

With respect to collective financing

i) Amount of the financing requested.

ii) Term of the Collective Financing Application.

iii) Term of the collective financing.

iv) Payment schedule for principal and interest, as well as their amount.

v) Ordinary interest rates and, if applicable, default interest.

vi) Risk rating determined according to the risk evaluation methodology defined by the Collective Financing Institution, accompanied by a simple explanation of how to interpret it.

vii) The participation that collective financing institutions assume when, if applicable, they are Investors through the implementation of risk-sharing schemes referred to in Article 21, second paragraph of the Law.

With respect to the credit rights subject to the Operation

i) Information related to the credit rights, titles or accounts receivable that constitute the object of the financing Operation, indicating their main characteristics, among which are:

a. Type of credit rights.

b. Nature of the goods or services that financed them.

c. Financial conditions of the credit right or rights:

· Term of the account(s) receivable.

· Total amount owed.

· Payment schedule for capital and interest.

· Ordinary and default interest rates.

d. In the case of a portfolio of credit rights, indicate if they are similar credits (homogeneous portfolio) or of different categories (non-homogeneous portfolio). In the latter case, information must be disclosed for each type of portfolio or account receivable.

e. Percentage of the value of the invoice or account receivable that is considered for granting the financing.

ii) Information related to the credit quality of the debtor of the credit rights that Investors will acquire. In the event of not having information on the debtor of the credit rights, this situation will be disclosed to Investors.

iii) In the event that the rights to be transferred to Investors derive from an invoice, it must be indicated whether the collective financing institution was able to electronically verify the data of this before the Tax Administration Service, as well as its validity.

With respect to the Applicant

i) Description of the Applicant's main business activity and the reason for requesting financing (working capital, expansion of operations, process automation, investment in infrastructure or technology, among others).

ii) General data of the Applicant:

In the case of a natural person with business activity:

a. Information related to their age, sex, residence, academic background and professional or business experience.

b. Information regarding solvency; including a description of their income sources.

In the case of a legal entity:

a. Name and business line or sector to which it belongs, legal nature, date of incorporation, address of main offices, geographic coverage or location of main branches and, if applicable, website.

b. Description of the Applicant's financial situation at the time of making the application, including aspects such as:

· Income from the sale of products or provision of services, registered in the last year.

· Profitability, leverage, liquidity and operational efficiency.

· Debt capacity and cash flow generation.

· Selected financial indicators that include, at least, the amount of equity capital, the main items of assets and liabilities, as well as the result of the previous fiscal year.

c. If applicable, it must be indicated whether the company is part of or has participated in any business or commercial incubator programs, as well as the description of the resources and services received under said program.

With respect to risk factors

Any material information of which the Applicant has knowledge that could negatively impact the credit quality of the debtor or debtors of the credit rights that constitute the object of the Operation must be disclosed.

With respect to periodic disclosure

The form and means through which Investors participating in the collective financing will be informed about the payment behavior of the accounts receivable must be specified, indicating the frequency of disclosure of this information, which must refer, at least, to the following aspects:

i) Amount and percentage of the account receivable or portfolio of credit rights that has already been recovered from the total.

ii) Overdue or delayed balance, if applicable.

iii) Total amount of interest paid, broken down into ordinary and default, if applicable.

iv) Collection actions taken, if applicable.

III. Information that must be disclosed regarding Collective Debt Financing for Real Estate Development

With respect to collective financing

i) Amount of the financing requested.

ii) Term of the Collective Financing Application.

iii) Description of the use of the financing, highlighting the main characteristics of the real estate properties subject to financing.

iv) Main source of payment for the financing.

v) Term of the collective financing.

vi) Payment schedule for principal and interest, as well as their amount.

vii) Ordinary and default interest rates.

viii) Guarantees granted by the Applicants and their relationship with the amount of financing; if the progress of the project has been defined in stages and will occupy more than one round of collective financing, the rights and guarantees of Investors in each stage must be stipulated; without ambiguity.

ix) Risk rating determined according to the risk evaluation methodology defined by the Collective Financing Institution, accompanied by a simple explanation of how to interpret it.

x) The participation that collective financing institutions assume when, if applicable, they are Investors through the implementation of risk-sharing schemes referred to in Article 21, second paragraph of the Law.

With respect to real estate development

i) Description and main characteristics of the real estate project.

ii) Use that will be given to the property.

iii) Location of the property.

iv) Degree of progress of the work.

v) Total investment required to carry out the project and estimated time for recovery of said investment.

vi) Additional sources of resources available to carry it out (different from collective financing) and guarantees granted, if applicable.

vii) Technical, legal and environmental aspects related to the development of the project, if applicable (land use permits, urbanization and drainage, environmental impact, among others, if applicable).

viii) Market study.

With respect to the Applicant

i) Name of the Applicant, legal nature, date of incorporation, address of main offices, geographic coverage of its services and location of main branches, as well as website.

ii) Description of its objectives or business model, as well as an explanatory note on its administration (if it is a family business, if there is a person or group of people who exercises control, among other aspects).

iii) Experience in the real estate business of the company and its administrators.

iv) Financial situation of the Applicant at the time of making the application, considering aspects such as profitability, leverage, liquidity and operational efficiency.

v) Selected financial indicators of the Applicant, which include, at least, the amount of its equity capital, the main items of assets and liabilities, as well as the result of the previous fiscal year.

With respect to risk factors

The variables or risk factors that could affect must be explained:

i) The payment capacity of the Applicant

ii) The progress and completion of the real estate development project.

iii) The sales value of the property or its rental income, if applicable.

iv) The recovery period of the resources from the collective financing.

All relevant risks must be highlighted, including, in an illustrative but not exhaustive manner, those related to macroeconomic and regional aspects that could affect the demand for real estate goods, legal, regulatory, environmental and technical risks, among others.

With respect to the implementation of guarantees

The assets and rights, present and future, that guarantee the financing must be described, as well as the circumstances, mechanisms and procedures to execute the guarantees; likewise, the obligations of the Applicant must be clearly established, as well as the responsibilities of the collective financing institution in the event that they have to be executed.

With respect to periodic disclosure

It must be indicated what type of information or indicators will be disclosed to participating Investors, regarding the progress of the project and the recovery of resources from collective financing. It must also be explained how Investors can access this information.

ANNEX 16

Guidelines for the disclosure of information for Collective Capital Financing

I. General aspects

These guidelines establish the general criteria for information disclosure and minimum contents that collective financing institutions must follow in the disclosure of information they provide regarding Collective Capital Financing that they promote through their Platforms.

Collective financing institutions may present the information referred to in this annex in the order they determine, presenting it consistently in all financing offers. To this end, collective financing institutions must:

a. Ensure that information is disclosed that is relevant for Investors to make informed decisions, based on the knowledge that the collective financing institutions themselves have of the financing project and on the risk analysis and evaluation they have performed.

b. Include the most recent information known at the time of its publication on the Platform.

c. Determine the depth and breadth with which the information indicated in this annex will be disclosed, including any additional or complementary information to that established in this. In the event that a section does not apply, they must specify such situation.

d. Indicate the source of the reports, statistics, analyses, opinions or other public information they use and when the information comes from a third party, a declaration must be included indicating that such information has been considered with the consent of said third party, if applicable.

e. Express monetary figures in Mexican pesos and in the case of figures whose original source is denominated in foreign currency or virtual assets, the exchange rate used to convert them to Mexican pesos must be specified, indicating the date to which it corresponds and the source that publishes it. It must also be clarified that such conversion was carried out solely to facilitate reading and understanding by Investors.

f. Use clear, concise and easy-to-understand language, as well as avoid the use of technical terms or complex legal formalisms that cannot be easily understood by a person who does not have specialized knowledge in the subject matter and avoid the use of superlative terms and value judgments.

II. Information that must be disclosed regarding Collective Capital Financing

With respect to the financing

i) Amount of the financing requested.

ii) Term of the Collective Financing Application.

iii) Description of the ultimate use of the resources.

iv) Risk rating determined according to the risk evaluation methodology defined by the collective financing institution, accompanied by a simple explanation of how to interpret it.

risks defined by the crowdfunding institution, accompanied by a simple explanation of how to interpret it.

v)

The participation assumed by crowdfunding institutions when, in their case, they act as Investors through the implementation of risk-sharing schemes referred to in Article 21, second paragraph of the Law.

With respect to the Applicant

i)

Name and business activity of the legal entity, legal nature, date of incorporation, address of main offices, geographic coverage or location of main branches, and, if applicable, website.

ii)

Description of its objectives, business model or plan, as well as an explanatory note on its administration (if it is a family business, if there is a person or group of persons exercising control, among other aspects).

iii)

Distribution and marketing channels, including an explanation of the sales method used (for example, sales through electronic media).

iv)

In the event of requesting financing for a specific project, indicate the expected benefits and the time frame in which they are expected to be achieved.

v)

Business history or technical knowledge of the administrators.

vi)

Description of the financial situation of the legal entity at the time of the application, considering aspects such as profitability, leverage, liquidity, and operational efficiency.

vii)

Selected financial indicators that include, at a minimum, the amount of book capital, the main asset and liability items, as well as the result of the previous fiscal year.

viii)

In the case of newly created companies, this status must be indicated, noting that this could increase the risk of the project, and if applicable, information regarding the business history or technical knowledge of the administrators must be included; as well as the financial projections, if any.

ix)

If applicable, information regarding strategic participants or strategic alliances held and the benefits or synergies they generate.

x)

If applicable, information on patents, licenses, trademarks, franchises, industrial and commercial contracts, and other rights owned by the legal entity that are considered important, mentioning the duration of these and the reason why they are relevant for the development of the business.

xi)

If applicable, it must be indicated whether the company is part of or has participated in any business incubation programs, as well as a description of the resources and services received under said program.

With respect to the securities representing the share capital of the legal entity subject to financing and the rights they confer to Investors

i)

Characteristics of the securities and the information necessary for the determination of their price.

Total ($)

Total number of

securities to offer

Amount of resources requested

Price per security *

  • Note: The method of determination of the security price must be described.

ii)

Amount of fixed and variable share capital of the legal entity subject to financing, if applicable, before and after the offering, considering the amount of resources requested, and the percentage that the requested amount represents with respect to the share capital, specifying the date of the general shareholders' meeting at which the increase was decreed.

iii)

Description of the number and type of securities in circulation of the legal entity subject to financing, as well as any limitations that exist for their acquisition, if applicable.

iv)

Description of the type and characteristics of the securities that investors will acquire.

v)

It must be indicated which of the following rights are provided by the offered securities (indicate all that apply):

Voting rights.

Right to receive dividends (describe what it consists of).

Rights in dissolution (describe what they consist of).

Conversion rights (describe what each security is convertible into).

Others (describe what it consists of).

vi)

Dividend policy applicable to the offered securities.

With respect to risk factors

The risk factors that could affect the company must be explained, such as: business strategy risks, lack of liquidity for recently created companies, increase in debt, increase in certain interest rates, adverse market conditions, economic recession, technological changes or changes in consumer preferences, increases in production or distribution costs, dependence on key customers or suppliers, natural disasters, entry of new competitors into the industry, legal or regulatory changes, environmental risks related to assets, inputs, products or services, among others.

Annex 17

Aggregated information of crowdfunding institutions for disclosure to the general public

I.

For Debt Crowdfunding:

Indicate the category of Debt Crowdfunding being reported: Personal Loan Debt Crowdfunding, Business Loan Debt Crowdfunding, or Real Estate Development Debt. If more than one category of Debt Crowdfunding is held, present the aggregated data for each of them separately.

Name of the Debt Crowdfunding Institution

Quarterly indicators

Aggregated indicator by financing category

Accumulated information with figures as of the end of each

quarter

t

t-1

t-2

t-3

t-4

Accumulated amount of financing granted

since the start of operations

Accumulated number of financing

granted since the start of operations

Number of active Financing Applicants

Individuals

Legal entities

Number of active Investors

Individuals

Legal entities

Amount of outstanding financings

Number of

outstanding financings

Amount of financings in default

Number of financings in default

Percentage that the Amount of

financings in default represents with respect to

the total of financings

Amount of financings

in default

Amount of financings in default

for more than 90 days

Number of financings

in default

for more than 90 days

Amount of financings in collection

Number of financings in collection

Average annual yield of the

financings granted, accompanied by

a note explaining the calculation procedure

employed (1)

Name of the Debt Crowdfunding Institution

Quarterly indicators

Indicator by financing category

Information for the reported period with figures as of the end of each quarter

t

t-1

t-2

t-3

t-4

Amount of financings in default

for more than 30 days during the reported

period

Number of financings in default

for more than 30 days during the reported

period

If applicable, amount recovered from

financings in default for more than

90 days during the

reported period

If applicable, percentage that the amount

recovered during the reported period

represents, with respect to the Amount of financings in

default for more than 90 days

Amount of new financings granted

during the reported period

Number of new financings granted

during the reported period

Amount of financings liquidated

during the reported period

Number of financings liquidated during

the reported period

Where:

·

t = most recent quarter being reported, with figures as of March, June, September, and December.

t - 1 = quarter immediately preceding the one being reported.

·

Active Financing Applicants: number of Applicants who have a financing in the

reported period.

·

Active Investors: number of Investors who are creditors in the reported period.

·

Amount of outstanding financings: includes the total outstanding balance of financings that are

current on their payments, both principal and interest, according to the

scheduled and agreed payment calendar when the Operation was agreed.

·

Number of outstanding financings: includes the total number of financings that are

current on their payments, both principal and interest, according to the

scheduled and agreed payment calendar when the Operation was agreed.

·

Amount of financings in default: includes the total balance of those financings in

which the Applicant has not covered the total payment of principal and/or interest committed according to the

scheduled and agreed payment calendar when the Operation was agreed.

·

Number of financings in default: includes the total number of financings in

which the Applicant has not covered the total payment of principal and/or interest committed according to the

scheduled and agreed payment calendar when the Operation was agreed.

·

Total number of financings = Number of outstanding financings + Number of

financings in default.

II.

For Capital, Co-ownership, and Royalty Crowdfunding:

Name of the Capital / Co-ownership or Royalty Crowdfunding Institution

Aggregated semi-annual indicators

Aggregated indicator by financing category

Information with figures as of the end of each semester

s

s-1

s-2

s-3

Accumulated amount of financing granted

since the start of operations

Accumulated number of financing granted

since the start of operations

Number of Applicants

Individuals

Legal entities

Number of Investors

Individuals

Legal entities

Amount of new financings granted

during the reported period

Number of new financings granted

during the reported period

Where:

·

s = most recent semester being reported with figures as of June and December.

s - 1 = semester immediately preceding the one being reported.

ANNEX 18

REGULATORY REPORTS OF CROWDFUNDING INSTITUTIONS (CFI)

Frequency

Series R01

Minimum Catalog

A-0112

Minimum Catalog

Monthly

Series R08

Bank loans and loans from other entities

D-0842

Disaggregation of loans obtained

Monthly

Series R10

Reclassifications

A-10112

Reclassifications in the statement of financial position

Monthly

A-10122

Reclassifications in the statement of comprehensive income

Monthly

Series R13

Financial Statements

A-13112

Statement of changes in equity

Quarterly

A-13162

Statement of cash flows

Quarterly

B-13212

Statement of financial position

Monthly

B-13222

Statement of comprehensive income

Monthly

Series R27

Claims

A-2702

Claims

Quarterly

SERIES R01 MINIMUM CATALOG

This series consists of one (1) report, whose frequency of preparation and submission must be monthly.

REPORT

A-0112

Minimum Catalog

In this report, the balances as of the end of the period for all concepts that

form part of the statement of financial position (including off-balance sheet accounts) and the

statement of comprehensive income of the Crowdfunding Institution are requested. The report is

requested in two subtotals:

·

National currency

·

Foreign currency valued in pesos.

For the completion of report A-0112

Minimum Catalog, the following aspects must be taken into consideration:

In the report, the balances of the Crowdfunding Institution must be presented without consolidation.

The balances of all concepts presented in Series R01 Minimum Catalog must be consistent with

those reported in the regulatory reports that are applicable.

For the case of the minimum catalog concepts denominated in national currency, UMA and UDIS

valued in pesos, these concepts must coincide with the sum of the concepts provided in the

regulatory reports in national currency, UMA and UDIS valued in pesos; while the concepts

denominated in foreign currency valued in pesos must coincide with the concepts provided in

the other regulatory reports in foreign currency valued in pesos.

Data referring to balances must be presented in national currency, foreign currency, UMA and

UDIS valued in pesos and foreign currency valued in pesos using the exchange rate indicated in

the current accounting criteria. Such balances must be presented in pesos, with four decimals and without

commas. For example: $20,585.7000 would be 20585.7000

CAPTURE FORMAT

Crowdfunding Institutions will carry out the submission of the information related to the

report A-0112

Minimum Catalog described above, by using the following capture format:

REQUESTED INFORMATION

SECTION REPORT IDENTIFIER

PERIOD START

PERIOD END

INSTITUTION KEY

REPORT

SECTION FINANCIAL INFORMATION

CONCEPT

CURRENCY

DATA

Crowdfunding Institutions will report the information indicated in this series,

which must comply with the validations and quality standards indicated by the National Banking and Securities Commission (Commission), adjusting to the characteristics and specifications. Once the validations and quality standards are met, the SITI will generate an electronic receipt.

The information must be sent only once and will be received assuming it meets all the characteristics

and specifications, in virtue of which it cannot be modified and must present consistency with the

different reports in which the same information is included at a different level of aggregation, therefore, if it does not meet the required quality and characteristics or has been presented incompletely, it will be considered

as non-compliance with the obligation of its presentation and, consequently, the corresponding

sanctions will be imposed in accordance with the applicable legal provisions.

Crowdfunding Institutions

Series R01 Minimum Catalog

Report A-0112 Minimum Catalog

Includes figures in national currency, foreign currency, UMA and UDIS valued in pesos

Figures in pesos

Concept

National currency,

UMA and UDIS

valued

Foreign currency

valued

OFF-BALANCE SHEET ACCOUNTS

Operations on behalf of clients

Clients current accounts

Applicant deposits

Debt

Equity

Co-ownership or royalties

Investor deposits

Margin accounts

Other current accounts

Custody operations

Financial instruments of clients received in custody

Other accounts in custody

Administration operations

Client virtual assets

Financial instruments of clients received in administration

Debt

Equity

Co-ownership or royalties

Collaterals received as guarantee on behalf of applicants

Collaterals delivered as guarantee on behalf of clients

In derivative financial instruments

Government debt

Bank debt

Other debt securities

Equity financial instruments

Others

Other collaterals delivered as guarantee for other operations on behalf of clients

Operations for the purchase of financial instruments

Derivatives

Of futures and forward contracts of clients (notional amount)

Of options

Of swaps

Of packages of client derivative financial instruments

Others

Operations for the sale of financial instruments

Derivatives

Of futures and forward contracts of clients (notional amount)

Of options

Of swaps

Of packages of client derivative financial instruments

Others

Goods in mandate

Other administration operations

Operations on own account

Contingent assets and liabilities

Collaterals received by the entity

Cash managed in trust

Government debt

Bank debt

Other debt securities

Equity financial instruments

Others

Collaterals received and sold by the entity

Government debt

Bank debt

Other debt securities

Equity financial instruments

Others

Other registration accounts

ASSETS

Cash and cash equivalents

Cash

Banks

Immediate collection documents

Investments available on demand

Restricted or pledged cash and cash equivalents

Foreign exchange to be received

Foreign exchange to be delivered

Cash managed in trust

Others

Others

Margin accounts (derivative financial instruments)

Cash

Investments in financial instruments

Other assets

Investments in financial instruments

Negotiable financial instruments

Negotiable financial instruments without restriction

Government debt

In position

To be delivered

Bank debt

In position

To be delivered

Other debt securities

In position

To be delivered

Equity financial instruments

In position

To be delivered

Negotiable financial instruments restricted or pledged

Government debt

In position

To be received

Bank debt

In position

To be received

Other debt securities

In position

To be received

Equity financial instruments

In position

To be received

Financial instruments to collect or sell

Financial instruments to collect or sell without restriction

Government debt

In position

To be delivered

Bank debt

In position

To be delivered

Other debt securities

In position

To be delivered

Financial instruments to collect or sell restricted or pledged

Government debt

In position

To be received

Bank debt

In position

To be received

Other debt securities

In position

To be received

Financial instruments to collect principal and interest

Financial instruments to collect principal and interest without restriction

Government debt

In position

To be delivered

Bank debt

In position

To be delivered

Other debt securities

In position

To be delivered

Financial instruments to collect principal and interest restricted or pledged

Government debt

In position

To be received

Bank debt

In position

To be received

Other debt securities

In position

To be received

Estimation of expected credit losses for investments in financial instruments to collect principal and

interest

Financial instruments to collect principal and interest without restriction

Government debt

In position

To be delivered

Bank debt

In position

To be delivered

Other debt securities

In position

To be delivered

Financial instruments to collect principal and interest restricted or pledged

Government debt

In position

To be received

Bank debt

In position

To be received

Other debt securities

In position

To be received

Repo debtors (debtor balance)

Derivative financial instruments

For trading purposes

Futures to be received

Forwards to be received

Options

Swaps

Structured operations

Valuation

Impairment

Packages of derivative financial instruments

Valuation

Impairment

For hedging purposes

Futures to be received

Forwards to be received

Options

Swaps

Structured operations

Valuation

Impairment

Packages of derivative financial instruments

Valuation

Impairment

Virtual assets

Restricted virtual assets

Unrestricted virtual assets

Benefits to be received in securitization operations

Benefits on the remainder in securitization operations

Asset for administration of transferred financial assets

Accounts receivable

Debtors from settlement of operations

Foreign exchange sales and purchases

Investments in financial instruments

Repos

Derivative financial instruments

By issuance of securities

Virtual assets

Debtors from margin accounts

Debtors from collaterals granted in cash

Operations with financial instruments

Operations not carried out in recognized markets (OTC)

Others

Other debtors

Premiums, commissions, and rights to be received

Clients

Loans and other debts of personnel

Other debtors

Taxes to be recovered

Conditional accounts receivable

Other accounts receivable

Estimation of expected credit losses

Other debtors

Conditional accounts receivable

Other accounts receivable

Long-term assets available for sale

Subsidiaries

Belonging to the financial sector

Not belonging to the financial sector

Associates

Belonging to the financial sector

Not belonging to the financial sector

Joint ventures

Belonging to the financial sector

Not belonging to the financial sector

Other permanent investments

Belonging to the financial sector

Not belonging to the financial sector

Other long-term assets available for sale

Belonging to the financial sector

Not belonging to the financial sector

Assets related to discontinued operations

Prepayments and other assets

Deferred charges

Insurance to be amortized

Other deferred charges

Prepayments

Interest paid in advance

Commissions paid in advance

Advances or provisional payments of taxes

Rent paid in advance

Other prepayments

Guarantee deposits

Employee benefits assets

Plan assets to cover employee benefits

Direct long-term benefits

Post-employment benefits

Pensions

Seniority premium

Other post-employment benefits

Deferred employee participation in profits (in favor)

Estimation for non-recoverable deferred PTU

Other short and long-term assets

Properties, furniture, and equipment

Properties, furniture, and equipment

Land

Buildings

Buildings under construction

Transport equipment

Computer equipment

Furniture

Adaptations and improvements

Other properties, furniture, and equipment

Revaluation of properties, furniture, and equipment (1)

Land

Buildings

Buildings under construction

Transport equipment

Computer equipment

Furniture

Adaptations and improvements

Other revaluations of properties, furniture, and equipment

Accumulated depreciation of properties, furniture, and equipment

Accumulated depreciation of properties, furniture, and equipment

Buildings

Transport equipment

Computer equipment

Furniture

Adaptations and improvements

Other accumulated depreciations of properties, furniture, and equipment

Revaluation of accumulated depreciation of properties, furniture, and equipment (1)

Buildings

Transport equipment

Computer equipment

Furniture

Adaptations and improvements

Other revaluations of accumulated depreciation of properties, furniture, and equipment

Assets for right of use of properties, furniture, and equipment

Land

Buildings

Transport equipment

Computer equipment

Furniture

Other properties, furniture, and equipment

Depreciation of assets for right of use of properties, furniture, and equipment

Buildings

Transport equipment

Computer equipment

Furniture

Other properties, furniture, and equipment

Permanent investments

Subsidiaries

Belonging to the financial sector

Not belonging to the financial sector

Associates

Belonging to the financial sector

Not belonging to the financial sector

Joint ventures

Belonging to the financial sector

Not belonging to the financial sector

Other permanent investments

Belonging to the financial sector

Not belonging to the financial sector

Deferred income tax asset (net)

Deferred income taxes (in favor)

Temporary differences

Tax losses

Tax credits

Estimation for non-recoverable deferred income tax assets

Temporary differences

Tax losses

Tax credits

Intangible assets

Other intangible assets

Revaluation of other intangible assets (1)

Accumulated amortization of other intangible assets

Accumulated amortization of other intangible assets

Revaluation of accumulated amortization of other intangible assets (1)

Assets for right to use intangible assets

Amortization of assets for right to use intangible assets

Goodwill

Goodwill

From subsidiaries

From associates

From joint ventures

Revaluation of goodwill (1)

From subsidiaries

From associates

From joint ventures

LIABILITY

Securities liabilities

Securities certificates

Nominal value and interest

Transaction costs

Premium or discount on placement

Others

Nominal value and interest

Transaction costs

Premium or discount on placement

Bank loans and loans from other entities

Short-term

Loans from multiple banking institutions

Loans from foreign banks

Loans from development banking institutions

Loans from other entities

Long-term

Loans from multiple banking institutions

Loans from foreign banks

Loans from development banking institutions

Loans from other entities

Obligation to return client deposits invested in repurchase agreements

Collaterals sold

Repurchase agreements (creditor balance)

Obligation of the pledgor to return collateral to the pledgee

Collaterals sold

Government debt

Bank debt

Other debt securities

Derivative financial instruments

Collaterals sold

Government debt

Bank debt

Other debt securities

Equity financial instruments

Others

Other collaterals sold

Derivative financial instruments

For trading

Futures to deliver

Forward contracts to deliver

Options

Swaps

Structured operations

Packages of derivative financial instruments

For hedging

Futures to deliver

Forward contracts to deliver

Options

Swaps

Structured operations

Packages of derivative financial instruments

Obligations in securitization operations

Liabilities for administration of transferred financial assets

Lease liability

Other payables

Creditors from settlement of operations

Foreign exchange sales and purchases

Investments in financial instruments

Repurchase agreements

Derivative financial instruments

Virtual assets

Creditors from margin accounts

Creditors from cash collaterals received

Operations with financial instruments

Operations not carried out in recognized markets (OTC)

Others

Contributions payable

Value added tax

Other taxes and duties payable

Taxes and social security contributions withheld for payment

Various creditors and other payables

Commissions payable on outstanding operations

Creditors for acquisition of assets

Dividends payable

Creditors for maintenance services

Provisions for various obligations

Fees and rents

Promotion and advertising expenses

Technology expenses

Other provisions

Other various creditors

Liabilities related to assets held for sale

Liabilities related to discontinued operations

Other financial instruments qualifying as liabilities

Subordinated obligations in circulation

Mandatory conversion

Nominal value and interest

Transaction costs

Premium or discount on placement

Conversion at holder's option

Nominal value and interest

Transaction costs

Premium or discount on placement

Conversion at issuer's option

Nominal value and interest

Transaction costs

Premium or discount on placement

Non-convertible

Nominal value and interest

Transaction costs

Premium or discount on placement

Contributions for future capital increases pending formalization in shareholders' meeting

Others

Obligations associated with the retirement of components of property, plant and equipment

Income tax liability

Taxes incurred

Income taxes (provision)

Income taxes (adjustment for definitive tax)

Deferred taxes

Temporary differences

Employee benefits liabilities

Short-term direct benefits

Long-term direct benefits

Post-employment benefits

Pensions

Seniority premium

Other post-employment benefits

Termination benefits

Termination benefits for reasons other than restructuring

Termination benefits due to restructuring

Workers' participation in profits incurred

Deferred workers' participation in profits

Deferred credits and advance collections

Deferred credits

Other income to be applied

Other deferred credits

Advance collections

Interest collected in advance

Commissions collected in advance

Advance collections of goods promised for sale or with reservation of ownership

Other advance collections

EQUITY CAPITAL

Contributed capital

Social capital

Unpaid social capital

Increase due to updating of paid social capital (1)

Contributions for future capital increases formalized in shareholders' meeting

Increase due to updating of contributions for future capital increases formalized in shareholders' meeting (1)

Share premium

Increase due to updating of share premium (1)

Other financial instruments qualifying as equity

Increase due to updating of other financial instruments qualifying as equity (1)

Earned capital

Capital reserves

Legal reserve

Other reserves

Increase due to updating of capital reserves (1)

Accumulated results

Results from prior periods

Results to be applied

Results from accounting changes and error corrections

Increase due to updating of results from prior periods (1)

Other comprehensive income

Valuation of financial instruments to collect or sell

Valuation

Effect of deferred income tax and PTU

Estimation for non-recoverable deferred income tax and PTU

Increase due to updating of valuation of financial instruments to collect or sell (1)

Valuation of virtual assets

Valuation

Effect of deferred income tax and PTU

Estimation for non-recoverable deferred income tax and PTU

Increase due to updating of valuation of virtual assets (1)

Valuation of derivative financial instruments for cash flow hedging

Valuation

Effect of deferred income tax and PTU

Estimation for non-recoverable deferred income tax and PTU

Increase due to updating of valuation of derivative financial instruments for cash flow hedging (1)

Remeasurement of defined employee benefits

Actuarial results in obligations

Valuation

Effect of deferred income tax and PTU

Estimation for non-recoverable deferred income tax and PTU

Result in the return of plan assets

Valuation

Effect of deferred income tax and PTU

Estimation for non-recoverable deferred income tax and PTU

Increase due to updating of remeasurement of defined employee benefits (1)

Accumulated effect from translation

Valuation

Effect of deferred income tax and PTU

Estimation for non-recoverable deferred income tax and PTU

Increase due to updating of accumulated effect from translation (1)

Participation in OCI of other entities

Valuation

Effect of deferred income tax and PTU

Estimation for non-recoverable deferred income tax and PTU

Increase due to updating of participation in OCI of other entities (1)

STATEMENT OF COMPREHENSIVE INCOME

Commissions collected

Account opening commission

Borne by the applicant

Borne by the investor

Administration commission

Borne by the applicant

Borne by the investor

Custody commission

Borne by the applicant

Borne by the investor

Sales and purchases of financial instruments

Sales and purchases of virtual assets

Other commissions and fees collected

Increase due to updating of commissions collected (1)

Commissions paid

Loans received

Debt placement

Sales and purchases of virtual assets

Other commissions and fees paid

Increase due to updating of commissions paid (1)

Profit from sales and purchases

Negotiable financial instruments

Financial instruments to collect or sell

Financial instruments to collect principal and interest

Derivative financial instruments for trading

Derivative financial instruments for hedging

Sale of received collaterals

Virtual assets

Currencies

Increase due to updating of profit from sales and purchases (1)

Loss from sales and purchases

Negotiable financial instruments

Financial instruments to collect or sell

Financial instruments to collect principal and interest

Derivative financial instruments for trading

Derivative financial instruments for hedging

Sale of received collaterals

Virtual assets

Currencies

Transaction costs

For negotiable financial instruments

For financial instruments to collect or sell

For derivative financial instruments

For virtual assets

Increase due to updating of loss from sales and purchases (1)

Interest income

Interest on cash and cash equivalents

Banks

Own funds

Client funds

Restricted cash and cash equivalents

Interest and yields from margin accounts

Cash

Financial instruments

Other assets

Interest and yields from investments in financial instruments

For negotiable financial instruments

For financial instruments to collect or sell

For financial instruments to collect principal and interest

Interest and yields from repurchase operations

Income from operations with derivative financial instruments

Derivative financial instruments for trading

Derivative financial instruments for hedging

Premiums from debt placement

Securities liabilities

Other financial instruments qualifying as liabilities

Dividends from instruments qualifying as equity financial instruments

Gain from revaluation

Gain from revaluation changes

Revaluation of indexed instruments

Revaluation of items in UDIS

Revaluation of items in UMA

Increase due to updating of interest income (1)

Interest expenses

Interest on securities liabilities

Interest, transaction costs and discounts borne for issuance of other financial instruments qualifying as liabilities

Subordinated obligations

Mandatory conversion

Conversion at holder's option

Conversion at issuer's option

Non-convertible

Other issued securities

Interest on bank loans and loans from other entities

Premiums paid for early redemption of financial instruments qualifying as liabilities

Expenses from operations with derivative financial instruments

Derivative financial instruments for trading

Derivative financial instruments for hedging

Loss from revaluation

Loss from revaluation changes

Revaluation of indexed instruments

Revaluation of items in UDIS

Revaluation of items in UMA

Interest on lease liabilities

Increase due to updating of interest expenses (1)

Result from fair value measurement

Result from fair value measurement

Negotiable financial instruments

Derivative financial instruments for trading

Derivative financial instruments for hedging

Financial instruments to collect or sell

Collaterals sold

Estimation of expected credit losses for investments in financial instruments

Loss from impairment or effect from reversal of impairment of financial instruments and derivative financial instruments

Financial instruments to collect or sell

Financial instruments to collect principal and interest

Derivative financial instruments

Result from foreign exchange valuation

Increase due to updating of result from fair value measurement (1)

Net monetary position result (financial margin from intermediation) (1)

Net monetary position result from positions generating financial margin (debtor balance)

Net monetary position result from positions generating financial margin (creditor balance)

Increase due to updating of net monetary position result (financial margin) (1)

Other operating income (expenses)

Costs and expenses incurred in collection management

Commissions in collection management

Recoveries

Taxes

Excess in benefits to receive in securitization operations

Other recoveries

Impacts on the estimation of expected credit losses

Losses

Labor relations and job security

Frauds

Internal

External

Natural disasters and other events

Clients, products and business practices

Business incidents and system failures

Execution, delivery and process management

Other losses

Donations

Loss in custody and administration of goods

Loss from impairment or effect from reversal of impairment of other assets

Interest borne in financing for acquisition of assets

Result in sale of property, plant and equipment

Cancellation of other liability accounts

Interest from loans to officials and employees

Result from valuation of benefits to receive in securitization operations

Result from valuation of asset for administration of transferred financial assets

Result from valuation of liability for administration of transferred financial assets

Result in benefits to receive in securitization operations

Other items of operating income (expenses)

Net monetary position result originated by items not related to financial margin (1)

Result from revaluation of items not related to financial margin

Increase due to updating of other operating income (expenses) (1)

Administration and promotion expenses

Short-term direct benefits

Workers' participation in profits

Workers' participation in profits incurred

Deferred workers' participation in profits

Estimation for non-recoverable deferred PTU

Other short-term direct benefits

Net cost of the period derived from long-term employee benefits

Long-term direct benefits

Post-employment benefits

Pensions

Seniority premium

Other post-employment benefits

Termination benefits

Termination benefits for reasons other than restructuring

Termination benefits due to restructuring

Fees

Rents

Insurance and bonds

Promotion and advertising expenses

Other taxes and duties

Non-deductible expenses

Technology expenses

Depreciations

Of the period

Loss from impairment or effect from reversal of impairment

Amortizations

Of the period

Loss from impairment or effect from reversal of impairment

Maintenance expenses

CNBV inspection and surveillance fees

Other administration and promotion expenses

Increase due to updating of administration and promotion expenses (1)

Participation in the net result of other entities

Result of the period from unconsolidated subsidiaries, associates and joint ventures

In unconsolidated subsidiaries

Belonging to the financial sector

Not belonging to the financial sector

In associates

Belonging to the financial sector

Not belonging to the financial sector

In joint ventures

Belonging to the financial sector

Not belonging to the financial sector

Dividends from permanent investments

Valuation of permanent investments available for sale

Adjustments associated with other permanent investments

Impairment or effect from reversal of impairment of permanent investments

Increase due to updating of participation in the net result of other entities (1)

Income taxes

Incurred income taxes

Incurred income taxes

Increase due to updating of incurred income taxes (1)

Deferred income taxes

Temporary differences

Tax losses

Tax credits

Estimation for non-recoverable income taxes

Temporary differences

Tax losses

Tax credits

Increase due to updating of deferred income taxes (1)

Discontinued operations

Discontinued operations

Increase due to updating of discontinued operations (1)

Other comprehensive income

Valuation of financial instruments to collect or sell

Period effect

Valuation

Effect of deferred income tax and PTU

Estimation for non-recoverable deferred income tax

Increase due to updating of valuation of financial instruments to collect or sell (1)

Period recycling

Valuation of derivative financial instruments for cash flow hedging

Period effect

Valuation

Effect of deferred income tax and PTU

Estimation for non-recoverable deferred income tax

Increase due to updating of valuation of derivative financial instruments for cash flow hedging (1)

Period recycling

Valuation of virtual assets

Period effect

Valuation

Effect of deferred income tax and PTU

Estimation for non-recoverable deferred income tax

Increase due to updating of valuation of virtual assets (1)

Period recycling

Remeasurement of defined employee benefits

Period effect

Valuation

Effect of deferred income tax and PTU

Estimation for non-recoverable deferred income tax

Increase due to updating of remeasurement of defined employee benefits (1)

Period recycling

Accumulated effect from translation

Period effect

Valuation

Effect of deferred income tax and PTU

Estimation for non-recoverable deferred income tax

Increase due to updating of accumulated effect from translation (1)

Period recycling

Participation in OCI of other entities

Period effect

Valuation

Effect of deferred income tax and PTU

Estimation for non-recoverable deferred income tax

Increase due to updating of participation in OCI of other entities (1)

Period recycling

Collective Financing Institutions

(1) These concepts will be applicable under an inflationary economic environment based on what is established in Financial Information Standard B-10 "Effects of Inflation", issued by the Mexican Council for Financial Information Standards, A.C.

SERIES R08 BANK LOANS AND LOANS FROM OTHER ENTITIES

This series is integrated by one (1) report, whose frequency of preparation and presentation must be monthly.

REPORT

D-0842

Disaggregation of obtained loans

In this report, information is collected that allows knowing the details of the loans granted to Collective Financing Institutions, such as the credit contracting date, the maturity date, the amount of the operation, the agreed interest rate, the guarantees backing it, the identification of the lender, the commissions paid, among others, as well as the information on credit follow-up.

CAPTURE FORMAT

Collective Financing Institutions will carry out the sending of the information related to the report R08-D-0842 Disaggregation of obtained loans, described above, by using the following capture format:

INFORMATION REQUESTED

REPORT IDENTIFIER SECTION

PERIOD START

PERIOD END

INSTITUTION KEY

LOAN IDENTIFIER SECTION

LOAN IDENTIFIER

LOAN STATUS

STATUS UPDATE DATE

LENDER IDENTIFICATION DATA SECTION

LENDER TYPE

NAME(S)/BUSINESS NAME OR CORPORATE NAME

PATERNAL SURNAMES

MATERNAL SURNAMES

COUNTRY OF ORIGIN

ACCOUNT DATA SECTION

IDENTIFIER OF THE ACCOUNT WHERE THE LOAN IS RECEIVED

OPERATION DATA SECTION

ACCOUNTING CLASSIFICATION (LOAN TYPE)

CONTRACTING OR OPENING DATE

MATURITY DATE

PRINCIPAL PAYMENT FREQUENCY

INTEREST PAYMENT FREQUENCY

CURRENCY TYPE

INITIAL LOAN AMOUNT IN ORIGIN CURRENCY

INITIAL LOAN AMOUNT REVALUED IN NATIONAL CURRENCY

EXCHANGE RATE

INTEREST RATE TYPE

VALUE OF THE ORIGINALLY AGREED RATE

VALUE OF THE APPLICABLE INTEREST RATE IN THE PERIOD

REFERENCE INTEREST RATE

ADJUSTMENT IN THE REFERENCE RATE

FREQUENCY OF RATE REVIEW

AMOUNT OF THE AGREED COMMISSION

CREDIT DISPOSITION TYPE

DESTINATION OF THE RESOURCES

LOAN FOLLOW-UP DATA SECTION

OUTSTANDING BALANCE AT PERIOD START

DUE CAPITAL

DUE INTERESTS

PRINCIPAL PAYMENTS

INTERESTS PAID

OTHER COMMISSIONS PAID

UNPAID ACCRUED INTERESTS

OUTSTANDING BALANCE AT PERIOD END

PERCENTAGE OF CREDIT DISBURSED

DATE OF LAST PAYMENT MADE

DATE OF NEXT IMMEDIATE PAYMENT

TOTAL AMOUNT OF NEXT IMMEDIATE PAYMENT

LOAN GUARANTEE IDENTIFICATION DATA SECTION

GUARANTEE TYPE

INITIAL VALUE

UPDATED VALUE

VALUATION DATE

Collective Financing Institutions will report the information indicated in this series, which must comply with the validations and quality standards indicated by the National Banking and Securities Commission (Commission), adjusting to the characteristics and specifications. Once the validations and quality standards are met, the SITI will generate an electronic receipt of acknowledgment.

The information must be sent only once and will be received assuming it meets all characteristics and specifications, for which it cannot be modified and must present consistency with the various reports in which the same information is included at a different level of integration, therefore, if it does not meet the required quality and characteristics or has been presented incompletely, the obligation of its presentation will be considered unfulfilled and, consequently, the corresponding sanctions will be imposed in accordance with the applicable legal provisions.

SERIES R10 RECLASSIFICATIONS

This series is integrated by two (2) reports, whose frequency of preparation and presentation must be monthly.

REPORTS

A-10112

Reclassifications in the statement of financial position

In this report, balances at the end of the period are requested for the concepts of the regulatory report A-0112 Minimum Catalog, as well as the respective movements for presentation and compensations according to accounting criteria

carried out for the purpose of presenting the items of the financial statement of the Collective Financing Institution without consolidation.

A-10122

Reclassifications in the statement of comprehensive income

In this report, balances at the end of the period for the concepts of the regulatory report A-0112 Minimum Catalog are requested, as well as the respective movements for presentation and compensations according to accounting criteria carried out for the purpose of presenting the items of the statement of comprehensive income of the Collective Financing Institution without consolidation.

For the completion of reports A-10112 and A-10122, the following aspects must be taken into consideration:

Data referring to balances and amounts must be presented in national currency, foreign currency, UMA and UDIS valued in pesos and foreign currency valued in pesos using the exchange rate indicated in the current accounting criteria. These amounts and balances must be presented in pesos, with four decimal places, without commas. For example: $20,585.7000 would be 20585.7000.

CAPTURE FORMAT

Collective Financing Institutions will carry out the sending of information related to reports A-10112 Reclassifications in the statement of financial position and A-10122 Reclassifications in the statement of comprehensive income, described above, by using the following capture format:

REQUESTED INFORMATION

SECTION REPORT IDENTIFIER PERIOD START PERIOD END INSTITUTION KEY REPORT

SECTION FINANCIAL INFORMATION CONCEPT BALANCE TYPE MOVEMENT TYPE DATA

Collective Financing Institutions will report the information indicated in this series, which must comply with the validations and quality standards indicated by the National Banking and Securities Commission (Commission), adjusting to the characteristics and specifications. Once the validations and quality standards are met, the SITI will generate an electronic receipt of acknowledgment.

The information must be sent only once and will be received assuming it meets all characteristics and specifications, for which reason it cannot be modified and must present consistency with the various reports in which the same information is included with a different level of integration; therefore, if it does not meet the required quality and characteristics or has been presented incompletely, the obligation to present it will be considered unfulfilled, and consequently, the corresponding sanctions will be imposed in accordance with the applicable legal provisions.

Collective Financing Institutions

Series R10 Reclassifications

Report A-10112 Reclassifications in the statement of financial position

Includes figures in national currency, foreign currency, UMA and UDIS valued in pesos

Figures in pesos

Concept Minimum catalog balance Movements for presentation according to accounting criteria Compensations according to accounting criteria Statement of financial position without consolidation (1) (2) (A) Debit Credit Debit Credit National currency, UMA and UDIS Foreign currency Total (B)* = (A) + (1) + (2)

OFF-BALANCE SHEET ACCOUNTS Operations on behalf of clients Clients current accounts Applicant deposits Debt Capital Co-ownership or royalties Investor deposits Margin accounts Other current accounts Custody operations Financial instruments of clients received in custody Other accounts in custody Administration operations Client virtual assets Financial instruments of clients received in administration Debt Capital Co-ownership or royalties Collateral received as guarantee on behalf of applicants Collateral delivered as guarantee on behalf of clients In derivative financial instruments Government debt Bank debt Other debt securities Equity financial instruments Others Other collateral delivered as guarantee for other operations on behalf of clients Operations for the purchase of financial instruments Derivatives Client futures and forward contracts (notional amount) Options Swaps Client derivative financial instrument packages Others Operations for the sale of financial instruments Derivatives Client futures and forward contracts (notional amount) Options Swaps Client derivative financial instrument packages Others Assets in mandate Other administration operations Operations on own account Contingent assets and liabilities Collateral received by the entity Cash managed in trust Government debt Bank debt Other debt securities Equity financial instruments Others Collateral received and sold by the entity Government debt Bank debt Other debt securities Equity financial instruments Others Other registration accounts

ASSET Cash and cash equivalents Cash Banks Immediate collection documents Investments available on demand Restricted or pledged cash and cash equivalents Foreign currencies to be received Foreign currencies to be delivered Cash managed in trust Others Others Margin accounts (derivative financial instruments) Cash Investments in financial instruments Other assets Investments in financial instruments Negotiable financial instruments Unrestricted negotiable financial instruments Government debt In position To be delivered Bank debt In position To be delivered Other debt securities In position To be delivered Equity financial instruments In position To be delivered Restricted or pledged negotiable financial instruments Government debt In position To be received Bank debt In position To be received Other debt securities In position To be received Equity financial instruments In position To be received Financial instruments to collect or sell Unrestricted financial instruments to collect or sell Government debt In position To be delivered Bank debt In position To be delivered Other debt securities In position To be delivered Restricted or pledged financial instruments to collect or sell Government debt In position To be received Bank debt In position To be received Other debt securities In position To be received Financial instruments to collect principal and interest Unrestricted financial instruments to collect principal and interest Government debt In position To be delivered Bank debt In position To be delivered Other debt securities In position To be delivered Restricted or pledged financial instruments to collect principal and interest Government debt In position To be received Bank debt In position To be received Other debt securities In position To be received Expected credit loss estimate for investments in financial instruments to collect principal and interest Unrestricted financial instruments to collect principal and interest Government debt In position To be delivered Bank debt In position To be delivered Other debt securities In position To be delivered Restricted or pledged financial instruments to collect principal and interest Government debt In position To be received Bank debt In position To be received Other debt securities In position To be received Repo debtors (debit balance) Derivative financial instruments For trading purposes Futures to be received Forwards to be received Options Swaps Structured operations Valuation Impairment Derivative financial instrument packages Valuation Impairment For hedging purposes Futures to be received Forwards to be received Options Swaps Structured operations Valuation Impairment Derivative financial instrument packages Valuation Impairment Virtual assets Restricted virtual assets Unrestricted virtual assets Benefits to be received in securitization operations Benefits on the remainder in securitization operations Asset from administration of transferred financial assets Accounts receivable Debtors from settlement of operations Foreign exchange sales and purchases Investments in financial instruments Repos Derivative financial instruments From issuance of securities Virtual assets Debtors from margin accounts Debtors from collateral granted in cash Operations with financial instruments Operations not carried out in recognized markets (OTC) Others Other debtors Premiums, commissions and rights to be received Clients Loans and other debts of personnel Other debtors Taxes to be recovered Conditional accounts receivable Other accounts receivable Expected credit loss estimate Other debtors Conditional accounts receivable Other accounts receivable Accounts receivable (net) Long-term assets available for sale Subsidiaries Belonging to the financial sector Not belonging to the financial sector Associates Belonging to the financial sector Not belonging to the financial sector Joint ventures Belonging to the financial sector Not belonging to the financial sector Other permanent investments Belonging to the financial sector Not belonging to the financial sector Other long-term assets available for sale Belonging to the financial sector Not belonging to the financial sector Assets related to discontinued operations Prepayments and other assets Deferred charges Insurance to be amortized Other deferred charges Prepayments Interest paid in advance Commissions paid in advance Advance or provisional payments of taxes Rent paid in advance Other prepayments Guarantee deposits Employee benefits assets Plan assets to cover employee benefits Long-term direct benefits Post-employment benefits Pensions Seniority premium Other post-employment benefits Deferred employee participation in profits (in favor) Estimate for non-recoverable deferred PTU Other short and long-term assets Properties, furniture and equipment Properties, furniture and equipment Land Buildings Buildings under construction Transport equipment Computing equipment Furniture Adaptations and improvements Other properties, furniture and equipment Revaluation of properties, furniture and equipment (1) Land Buildings Buildings under construction Transport equipment Computing equipment Furniture Adaptations and improvements Other revaluations of properties, furniture and equipment Accumulated depreciation of properties, furniture and equipment Accumulated depreciation of properties, furniture and equipment Buildings Transport equipment Computing equipment Furniture Adaptations and improvements Other accumulated depreciations of properties, furniture and equipment Revaluation of accumulated depreciation of properties, furniture and equipment (1) Buildings Transport equipment Computing equipment Furniture Adaptations and improvements Other revaluations of accumulated depreciation of properties, furniture and equipment Properties, furniture and equipment (net) Right-of-use assets for properties, furniture and equipment Land Buildings Transport equipment Computing equipment Furniture Other properties, furniture and equipment Depreciation of right-of-use assets for properties, furniture and equipment Buildings Transport equipment Computing equipment Furniture Other properties, furniture and equipment Right-of-use assets for properties, furniture and equipment (net) Permanent investments Subsidiaries Belonging to the financial sector Not belonging to the financial sector Associates Belonging to the financial sector Not belonging to the financial sector Joint ventures Belonging to the financial sector Not belonging to the financial sector Other permanent investments Belonging to the financial sector Not belonging to the financial sector Deferred income tax asset (net) Deferred income taxes (in favor) Temporary differences Tax losses Tax credits Estimate for non-recoverable deferred income taxes Temporary differences Tax losses Tax credits Intangible assets (net) Intangible assets Other intangible assets Revaluation of other intangible assets (1) Accumulated amortization of other intangible assets Accumulated amortization of other intangible assets Revaluation of accumulated amortization of other intangible assets (1) Right-of-use assets for intangible assets (net) Right-of-use assets for intangible assets Amortization of right-of-use assets for intangible assets Goodwill Goodwill From subsidiaries From associates From joint ventures Revaluation of goodwill (1) From subsidiaries From associates From joint ventures

LIABILITY Market liabilities Market certificates Nominal value and interest Transaction costs Placement premium or discount Others Nominal value and interest Transaction costs Placement premium or discount Bank loans and loans from other entities Short-term Loans from multiple banking institutions Loans from foreign banks Loans from development banking institutions Loans from other entities Long-term Loans from multiple banking institutions Loans from foreign banks Loans from development banking institutions Loans from other entities Obligation to return client deposits invested in repo Collateral sold Repos (credit balance) Repo provider's obligation to return collateral to the repo taker Collateral sold Government debt Bank debt Other debt securities Derivative financial instruments Collateral sold Government debt Bank debt Other debt securities Equity financial instruments Others Other collateral sold Derivative financial instruments For trading purposes Futures to be delivered Forwards to be delivered Options Swaps Structured operations Derivative financial instrument packages For hedging purposes Futures to be delivered Forwards to be delivered Options Swaps Structured operations Derivative financial instrument packages Obligations in securitization operations Liabilities from administration of transferred financial assets Lease liability Other accounts payable Creditors from settlement of operations Foreign exchange sales and purchases Investments in financial instruments Repos Derivative financial instruments Virtual assets Creditors from margin accounts Creditors from collateral received in cash Operations with financial instruments Operations not carried out in recognized markets (OTC) Others Contributions to be paid Value added tax Other taxes and duties to be paid Taxes and social security contributions withheld for payment Other creditors and other accounts payable Commissions to be paid on ongoing operations Creditors for acquisition of assets Dividends to be paid Creditors for maintenance services Provisions for various obligations Fees and rents Promotion and advertising expenses Technology expenses Other provisions Other miscellaneous creditors Liabilities related to assets available for sale Liabilities related to discontinued operations Other financial instruments qualifying as liabilities Subordinated obligations in circulation Mandatory conversion Nominal value and interest Transaction costs Placement premium or discount Conversion at holder's decision Nominal value and interest Transaction costs Placement premium or discount Conversion at issuer's decision Nominal value and interest Transaction costs Placement premium or discount Non-convertible Nominal value and interest Transaction costs Placement premium or discount Contributions for future capital increases pending formalization in shareholders' meeting Others Obligations associated with the retirement of components of properties, furniture and equipment Income tax liability Taxes incurred Income taxes (provision) Income taxes (adjustment for definitive tax) Deferred taxes Temporary differences Employee benefits liabilities Short-term direct benefits Long-term direct benefits Post-employment benefits Pensions Seniority premium Other post-employment benefits Termination benefits Termination benefits for reasons other than restructuring Termination benefits due to restructuring Employee participation in profits incurred Deferred employee participation in profits Deferred credits and advance collections Deferred credits Other income to be applied Other deferred credits Advance collections Interest collected in advance Commissions collected in advance Advance collections of goods promised for sale or with retention of title Other advance collections

OWN CAPITAL Contributed capital Social capital Unpaid social capital Increase due to updating of paid social capital (1) Contributions for future capital increases formalized in shareholders' meeting Increase due to updating of contributions for future capital increases formalized in shareholders' meeting (1) Share premium Increase due to updating of share premium (1) Other financial instruments qualifying as capital Increase due to updating of other financial instruments qualifying as capital (1) Retained earnings Capital reserves Legal reserve Other reserves Increase due to updating of capital reserves (1) Accumulated results Result from prior periods Result to be applied Result from accounting changes and error corrections Increase due to updating of result from prior periods (1) Net result Other comprehensive income Valuation of financial instruments to collect or sell Valuation Effect of income taxes and deferred PTU Estimate for non-recoverable deferred income taxes and PTU Increase due to updating of valuation of financial instruments to collect or sell (1) Valuation of virtual assets Valuation Effect of income taxes and deferred PTU Estimate for non-recoverable deferred income taxes and PTU Increase due to updating of valuation of virtual assets (1) Valuation of derivative financial instruments for cash flow hedging Valuation Effect of income taxes and deferred PTU Estimate for non-recoverable deferred income taxes and PTU Increase due to updating of valuation of derivative financial instruments for cash flow hedging (1) Remeasurement of defined employee benefits Actuarial results in obligations Valuation Effect of income taxes and deferred PTU Estimate for non-recoverable deferred income taxes and PTU Result in the return of plan assets Valuation Effect of income taxes and deferred PTU Estimate for non-recoverable deferred income taxes and PTU Increase due to updating of remeasurement of defined employee benefits (1) Accumulated effect from translation Valuation Effect of income taxes and deferred PTU Estimate for non-recoverable deferred income taxes and PTU Increase due to updating of accumulated effect from translation (1) Participation in OCI of other entities Valuation Effect of income taxes and deferred PTU Estimate for non-recoverable deferred income taxes and PTU Increase due to updating of participation in OCI of other entities (1)

Collective Financing Institutions

(1) These concepts will be applicable under an inflationary economic environment based on what is established in Financial Information Standard B-10 "Effects of Inflation", issued by the Mexican Council of Financial Information Standards, A.C. (CINIF).

  • The sum of the movements and compensations must respect the nature of the account.

Collective Financing Institutions

Series R10 Reclassifications

Report A-10122 Reclassifications in the statement of comprehensive income

Includes figures in national currency, foreign currency, UMA and UDIS valued in pesos

Figures in pesos

Concept Minimum catalog balance Movements for presentation according to accounting criteria Compensations according to accounting criteria Statement of comprehensive income without consolidation (1) (2) (A) Debit Credit Debit Credit National currency, UMA and UDIS Foreign currency Total (B)* = (A) + (1) + (2)

Commissions collected Account opening commission On behalf of the applicant On behalf of the investor Administration commission On behalf of the applicant On behalf of the investor Custody commission On behalf of the applicant On behalf of the investor Sale and purchase of financial instruments Sale and purchase of virtual assets Other commissions and fees collected Increase due to updating of commissions collected (1) Commissions paid Loans received Debt placement Sale and purchase of virtual assets Other commissions and fees paid Increase due to updating of commissions paid (1)

RESULT FROM SERVICES Profit from sale and purchase Negotiable financial instruments Financial instruments to collect or sell Financial instruments to collect principal and interest Derivative financial instruments for trading purposes Derivative financial instruments for hedging purposes Sale of received collateral Virtual assets Foreign currencies Increase due to updating of profit from sale and purchase (1) Loss from sale and purchase Negotiable financial instruments Financial instruments to collect or sell Financial instruments to collect principal and interest Derivative financial instruments for trading purposes Derivative financial instruments for hedging purposes Sale of received collateral Virtual assets Foreign currencies Transaction costs For negotiable financial instruments For financial instruments to collect or sell For derivative financial instruments For virtual assets Increase due to updating of loss from sale and purchase (1) Interest income Interest on cash and cash equivalents Banks Own resources Client resources Restricted cash and cash equivalents Interest and yields in favor from margin accounts Cash Financial instruments Other assets Interest and yields in favor from investments in financial instruments For negotiable financial instruments

For financial instruments held to collect or sell

For financial instruments held to collect principal and interest

Interest and yields in favor in repo operations

Income from operations with financial derivative instruments

Financial derivative instruments for trading purposes

Financial derivative instruments for hedging purposes

Debt issuance premiums

Stock exchange liabilities

Other financial instruments that qualify as liabilities

Dividends from instruments that qualify as equity financial instruments

Gain on revaluation

Gain on revaluation changes

Revaluation of indexed instruments

Revaluation of UDIS items

Revaluation of UMA items

Increase by updating interest income (1)

Interest expenses

Interest on stock exchange liabilities

Interest, transaction costs, and discounts payable for the issuance of other financial instruments that qualify as liabilities

Subordinated obligations

Of mandatory conversion

Of conversion by holder decision

Of conversion by issuer entity decision

Non-convertible

Other issued securities

Interest on bank loans and from other organizations

Premiums paid for the early redemption of financial instruments that qualify as liabilities

Expenses from operations with financial derivative instruments

Financial derivative instruments for trading purposes

Financial derivative instruments for hedging purposes

Loss on revaluation

Loss on revaluation changes

Revaluation of indexed instruments

Revaluation of UDIS items

Revaluation of UMA items

Interest on lease liabilities

Increase by updating interest expenses (1)

Result from valuation at fair value

Result from valuation at fair value

Negotiable financial instruments

Financial derivative instruments for trading purposes

Financial derivative instruments for hedging purposes

Financial instruments held to collect or sell

Collaterals sold

Estimation of expected credit losses for investments in financial instruments

Loss on impairment or effect of reversal of impairment of financial instruments and financial derivative instruments

Financial instruments held to collect or sell

Financial instruments held to collect principal and interest

Financial derivative instruments

Result from foreign currency valuation

Increase by updating the result from valuation at fair value (1)

Result from net monetary position (financial margin from intermediation) (1)

Result from monetary position from positions generating financial margin (debit balance)

Result from monetary position from positions generating financial margin (credit balance)

Increase by updating the result from net monetary position (financial margin) (1)

FINANCIAL MARGIN FROM INTERMEDIATION

Other income (expenses) from operations

Costs and expenses incurred in collection management

Commissions in collection management

Recoveries

Taxes

Excess in benefits to receive in securitization operations

Other recoveries

Charges to the estimation of expected credit losses

Losses

Labor relations and job security

Frauds

Internal

External

Natural disasters and other events

Clients, products, and business practices

Business incidents and system failures

Execution, delivery, and process management

Other losses

Donations

Loss in custody and administration of assets

Loss on impairment or effect of reversal of impairment of other assets

Interest payable in financing for asset acquisition

Result in sale of properties, furniture, and equipment

Cancellation of other liability accounts

Interest in favor from loans to officials and employees

Result from valuation of benefits to receive in securitization operations

Result from valuation of assets for administration of transferred financial assets

Result from valuation of liabilities for administration of transferred financial assets

Result in benefits to receive in securitization operations

Other items of operations income (expenses)

Result from monetary position originated by items not related to financial margin (1)

Result from revaluation of items not related to financial margin

Increase by updating other income (expenses) from operations (1)

Administration and promotion expenses

Short-term direct benefits

Workers' participation in profits

Workers' participation in profits accrued

Deferred workers' participation in profits

Estimation for non-recoverable deferred PTU

Other short-term direct benefits

Net cost of the period derived from long-term employee benefits

Long-term direct benefits

Post-employment benefits

Pensions

Seniority premium

Other post-employment benefits

Termination benefits

Termination benefits for reasons other than restructuring

Termination benefits due to restructuring

Fees

Rents

Insurance and bonds

Promotion and advertising expenses

Taxes and various duties

Non-deductible expenses

Technology expenses

Depreciations

Of the period

Loss on impairment or effect of reversal of impairment

Amortizations

Of the period

Loss on impairment or effect of reversal of impairment

Maintenance expenses

CNBV inspection and surveillance fees

Other administration and promotion expenses

Increase by updating administration and promotion expenses (1)

OPERATING RESULT

Participation in the net result of other entities

Result of the exercise of non-consolidated subsidiaries, associates, and joint ventures

In non-consolidated subsidiaries

Belonging to the financial sector

Not belonging to the financial sector

In associates

Belonging to the financial sector

Not belonging to the financial sector

In joint ventures

Belonging to the financial sector

Not belonging to the financial sector

Dividends from permanent investments

Valuation of available-for-sale permanent investments

Adjustments associated with other permanent investments

Impairment or effect of reversal of impairment of permanent investments

Increase by updating participation in the net result of other entities (1)

RESULT BEFORE INCOME TAXES

Income taxes

Income taxes accrued

Income taxes accrued

Increase by updating accrued income taxes (1)

Deferred income taxes

Temporary differences

Tax losses

Tax credits

Estimation for non-recoverable income taxes

Temporary differences

Tax losses

Tax credits

Increase by updating deferred income taxes (1)

RESULT OF CONTINUING OPERATIONS

Discontinued operations

Discontinued operations

Increase by updating discontinued operations (1)

NET RESULT

Other comprehensive income

Valuation of financial instruments held to collect or sell

Period effect

Valuation

Effect of income taxes and deferred PTU

Estimation for non-recoverable deferred income taxes

Increase by updating the valuation of financial instruments held to collect or sell (1)

Period recycling

Valuation of cash flow hedging financial derivative instruments

Period effect

Valuation

Effect of income taxes and deferred PTU

Estimation for non-recoverable deferred income taxes

Increase by updating the valuation of cash flow hedging financial derivative instruments of cash flow (1)

Period recycling

Valuation of virtual assets

Period effect

Valuation

Effect of income taxes and deferred PTU

Estimation for non-recoverable deferred income taxes

Increase by updating the valuation of virtual assets (1)

Period recycling

Remeasurement of defined employee benefits

Period effect

Valuation

Effect of income taxes and deferred PTU

Estimation for non-recoverable deferred income taxes

Increase by updating the remeasurement of defined employee benefits (1)

Period recycling

Accumulated effect from conversion

Period effect

Valuation

Effect of income taxes and deferred PTU

Estimation for non-recoverable deferred income taxes

Increase by updating the accumulated effect from conversion (1)

Period recycling

Participation in OCI of other entities

Period effect

Valuation

Effect of income taxes and deferred PTU

Estimation for non-recoverable deferred income taxes

Increase by updating participation in OCI of other entities (1)

Period recycling

COMPREHENSIVE RESULT

BASIC EARNINGS PER ORDINARY SHARE (2)

Collective Financing Institutions

(1) These concepts will be applicable under an inflationary economic environment based on what is established in Financial Reporting Standard B-10 "Effects of Inflation", issued by the Mexican Council of Financial Reporting Standards, A.C. (CINIF).

(2) Determined in accordance with what is established in Bulletin B-14 "Earnings per share", issued by the Mexican Council of Financial Reporting Standards, A.C. (CINIF).

  • The sum of movements and compensations must respect the nature of the account.

SERIES R13 FINANCIAL STATEMENTS

This series is integrated by four (4) reports, whose frequency of preparation and presentation must be monthly for reports R13 B-13212 Statement of Financial Position and R13 B-13222 Statement of Comprehensive Income, and quarterly for reports R13 A-13112 Statement of Changes in Equity and R13 A-13162 Statement of Cash Flows.

REPORTS

A-13112

Statement of Changes in Equity

The statement of changes in equity aims to present information on changes in the investment of the owners of the Collective Financing Institution during the accounting period. It must show the reconciliation between initial and final balances of the period for each of the items that form part of equity.

In this report, balances of all equity concepts of the Collective Financing Institution are requested, showing the movements occurred in the period being reported. The movements refer to the increases or decreases of equity originated by owner movements, reserve movements, and comprehensive income.

A-13162

Statement of Cash Flows

The statement of cash flows has the main objective of providing information regarding changes in resources and financing sources during the accounting period. The changes refer to differences classified according to resources generated or used by operations, financing activities, and investment activities.

Likewise, the increase or decrease in cash and equivalents in the period must be reflected.

B-13212

Statement of Financial Position

The statement of financial position aims to present the value of assets and rights, of real, direct, or contingent obligations, as well as of equity capital of the Collective Financing Institution at a specific date.

The statement of financial position, therefore, must adequately show on consistent bases, the position of the Collective Financing Institution in terms of its assets, liabilities, equity capital, and off-balance sheet accounts, so that the economic resources available to the institution can be evaluated, as well as its financial structure.

Additionally, the statement of financial position must fulfill the objective of being a useful tool for analysis.

B-13222

Statement of Comprehensive Income

The statement of comprehensive income aims to show information relative to the result of its operations in equity capital and, therefore, of income and expenses and other comprehensive income (OCI) and comprehensive income.

In this report, relevant information on operations carried out by the Collective Financing Institution is requested and must fulfill the objective of being a useful tool for analysis.

For the completion of reports A-13112, A-13162, B-13212, and B-13222, the following aspects must be considered:

Data referring to balances must be presented in national currency, foreign currency, UMA, and UDIS valued in pesos and foreign currency valued in pesos using the exchange rate indicated in the current accounting criteria. These amounts and balances must be presented in pesos, with four decimal places, and without commas. For example: $20,585.7000 would be 20585.7000.

CAPTURE FORMAT

Collective Financing Institutions will carry out the submission of information related to reports A-13112 Statement of Changes in Equity and A-13162 Statement of Cash Flows, described above, by using the following capture format:

REQUESTED INFORMATION

Statement of Changes in Equity and Statement of Cash Flows

SECTION REPORT IDENTIFIER

PERIOD START

PERIOD END

INSTITUTION KEY

REPORT

SECTION FINANCIAL INFORMATION

CONCEPT

BALANCE TYPE

DATA

Collective Financing Institutions will carry out the submission of information related to reports B-13212 Statement of Financial Position and B 13222 Statement of Comprehensive Income, described above, by using the following capture format:

REQUESTED INFORMATION

Statement of Financial Position and Statement of Comprehensive Income

SECTION REPORT IDENTIFIER

PERIOD START

PERIOD END

INSTITUTION KEY

REPORT

SECTION FINANCIAL INFORMATION

CONCEPT

DATA

Collective Financing Institutions will report the information indicated in this series, adhering to the characteristics and specifications for filling out and submitting information provided by the National Banking and Securities Commission (Commission). The information must comply with the established validations, as well as the quality standards indicated by this Commission, in addition to presenting consistency between the information contained in the various regulatory reports applicable in which the same information is included at a different level of integration. Likewise, it must be sent only once and will be received assuming it meets all required characteristics, by virtue of which it cannot be modified.

Once the information is received, it will be reviewed by the Commission and if it does not meet the quality and characteristics required or has been presented incompletely, the obligation to present it will be considered unfulfilled.

Collective Financing Institutions

Series R13 Financial Statements

Report A-13112 Statement of Changes in Equity Capital

Includes figures in national currency, foreign currency, UMA, and UDIS valued in pesos

Figures in pesos

Concept

Contributed capital

Earned capital

Total controlling interest participation

Non-controlling interest participation

Total Equity Capital

Share capital

Contributions for future capital increases formalized in shareholder meetings

Premium on share sales

Other financial instruments that qualify as equity

Capital reserves

Accumulated results

Valuation of financial instruments held to collect or sell

Valuation of virtual assets

Valuation of cash flow hedging financial derivative instruments

Remeasurement of defined employee benefits

Accumulated effect from conversion

Participation in OCI of other entities

Balance as of ___ of _________ of ___

Retrospective adjustments for accounting changes

Retrospective adjustments for error corrections

Balance as of ___ of _______ of ___ adjusted

OWNER MOVEMENTS

Share subscription

Capital contributions

Capital refunds

Dividend decree

Capitalization of other equity capital concepts

Changes in controlling participation that do not imply loss of control

Total

RESERVE MOVEMENTS

Capital reserves (1)

COMPREHENSIVE INCOME:

Net result

Other comprehensive income

Valuation of financial instruments held to collect or sell

Valuation of virtual assets

Valuation of cash flow hedging financial derivative instruments

Remeasurement of defined employee benefits

Accumulated effect from conversion

Participation in OCI of other entities

Total

Balance as of ___ of __________ of ___

Collective Financing Institutions

(1) The entity must show in this line, the amounts that represent increases or decreases to capital reserves

Collective Financing Institutions

Series R13 Financial Statements

Report A-13162 Statement of Cash Flows

Includes figures in national currency, foreign currency, UMA, and UDIS valued in pesos

Figures in pesos

Concept

Amount

Operating Activities

Result before income taxes

Adjustments for items associated with investment activities:

Depreciation of properties, furniture, and equipment

Amortizations of intangible assets

Losses or reversal of losses on impairment of long-term assets

Discontinued operations

Result from sale of long-term assets

Participation in the net result of other entities

Other adjustments for items associated with investment activities

Adjustments for items associated with financing activities

Interest associated with bank loans and from other organizations

Interest associated with financial instruments that qualify as liabilities

Interest associated with other financial instruments that qualify as equity

Other interest

Changes in operating items

Change in margin accounts (financial derivative instruments)

Change in investments in negotiable financial instruments (net)

Change in repo debtors (net)

Change in financial derivative instruments (asset)

Change in benefits to receive in securitization operations

Change in virtual assets

Change in accounts receivable (net)

Change in other operating assets (net)

Change in stock exchange liabilities

Change in sold collaterals

Change in financial derivative instruments (liability)

Change in obligations in securitization operations

Change in other operating liabilities

Change in hedging financial derivative instruments (of covered items related to operating activities)

Change in assets/liabilities for employee benefits

Change in other accounts payable

Change in other provisions

Income tax refunds

Income tax payments

Net cash flows from operating activities

Investment Activities

Collections associated with financial instruments held to collect or sell

Payments associated with financial instruments held to collect or sell

Collections associated with financial instruments held to collect principal and interest

Payments associated with financial instruments held to collect principal and interest

Collections from disposal of virtual assets

Payments for acquisition of virtual assets

Payments for acquisition of properties, furniture, and equipment

Collections from disposal of properties, furniture, and equipment

Payments for acquisition of subsidiaries

Collections from disposal of subsidiaries

Payments for acquisition of associates, joint ventures, and other permanent investments

Collections from disposal of associates, joint ventures, and other permanent investments

Collections of cash dividends from permanent investments

Payments for acquisition of intangible assets

Collections from disposal of intangible assets

Collections associated with cash flow hedging financial derivative instruments (of covered items related to investment activities)

Payments associated with cash flow hedging financial derivative instruments (of covered items related to investment activities)

Other collections for investment activities

Other payments for investment activities

Net cash flows from investment activities

Financing Activities

Collections from obtaining bank loans and from other organizations

Payments of bank loans and from other organizations

Payment of lease liability

Collections from share issuance

Payments for share capital refunds

Collections from issuance of other financial instruments that qualify as equity

Payments associated with other financial instruments that qualify as equity

Cash dividend payments

Payments associated with repurchase of own shares

Collections from issuance of financial instruments that qualify as liabilities

Payments associated with financial instruments that qualify as liabilities

Payments for interest on lease liability

Other collections for financing activities

Other payments for financing activities

Net cash flows from financing activities

Net increase or decrease in cash and cash equivalents

Effects from changes in the value of cash and cash equivalents

Cash and cash equivalents at the beginning of the period

Cash and cash equivalents at the end of the period

Collective Financing Institutions

Note: In accordance with what accounting criteria establish, the concepts appearing in this statement are shown in an exhaustive but not exhaustive manner. The opening of a greater number of concepts in order to provide a more detailed presentation of the information must be requested to the National Banking and Securities Commission.

Collective Financing Institutions

Series R13 Financial Statements

Report B-1321 Statement of Financial Position

Includes figures in national currency, foreign currency, UMA, and UDIS valued in pesos

Figures in pesos

Concept

Amount

OFF-BALANCE SHEET ACCOUNTS

Operations on behalf of clients

Clients current accounts

Applicant deposits

Debt

Capital

Co-ownership or royalties

Investor deposits

Margin accounts

Other current accounts

Custody operations

Financial instruments of clients received in custody

Other accounts in custody

Administration operations

Client virtual assets

Financial instruments of clients received in administration

Collaterals received as guarantee on behalf of applicants

Collaterals delivered as guarantee on behalf of clients

Financial instrument purchase operations

Financial instrument sale operations

Assets in mandate

Other administration operations

Operations on own account

Contingent assets and liabilities

Collaterals received by the entity

Cash administered in trust

Government debt

Bank Debt

Other Debt Instruments

Equity Financial Instruments

Others

Collateral Received and Sold by the Entity

Government Debt

Bank Debt

Other Debt Instruments

Equity Financial Instruments

Others

Other Register Accounts

ASSET

Cash and cash equivalents

Margin accounts (financial derivative instruments)

Investments in financial instruments

Negotiable financial instruments

Financial instruments to collect or sell

Financial instruments to collect principal and interest

Estimate of expected credit losses for investments in financial instruments to collect principal and interest

Repo debtors (debit balance)

Financial derivative instruments

For trading purposes

For hedging purposes

Virtual assets

Benefits to be received in securitization operations

Accounts receivable (net)

Long-term assets available for sale

Assets related to discontinued operations

Prepayments and other assets

Properties, furniture and equipment (net)

Assets for right of use of properties, furniture and equipment (net)

Permanent investments

Deferred income tax asset (net)

Intangible assets (net)

Assets for right of use of intangible assets (net)

Goodwill

LIABILITY

Securities liabilities

Bank and other organism loans

Short-term

Long-term

Obligation to return deposits of clients invested in repo

Collateral sold

Repos (credit balance)

Financial derivative instruments

Other collateral sold

Financial derivative instruments

For trading purposes

For hedging purposes

Obligations in securitization operations

Liabilities for administration of transferred financial assets

Lease liability

Other accounts payable

Creditors for settlement of operations

Creditors for margin accounts

Creditors for cash collateral received

Contributions payable

Diverse creditors and other accounts payable

Liabilities related to assets available for sale

Liabilities related to discontinued operations

Other financial instruments that qualify as liability

Subordinated obligations in circulation

Contributions for future capital increases pending formalization in shareholders' meeting

Others

Obligations associated with the withdrawal of components of properties, furniture and equipment

Income tax liability

Employee benefits liabilities

Deferred credits and advance payments

OWNERS' EQUITY

Controlling interest

Contributed capital

Share capital

Unissued share capital

Increase due to update of paid share capital (1)

Contributions for future capital increases formalized in shareholders' meeting

Increase due to update of contributions for future capital increases formalized in shareholders' meeting

(1)

Share premium

Increase due to update of share premium (1)

Other financial instruments that qualify as capital

Increase due to update of other financial instruments that qualify as capital (1)

Earned capital

Capital reserves

Increase due to update of capital reserves (1)

Accumulated results

Results of prior periods

Increase due to update of results of prior periods (1)

Net result

Other comprehensive income

Valuation of financial instruments to collect or sell

Increase due to update of valuation of financial instruments to collect or sell (1)

Valuation of virtual assets

Increase due to update of valuation of virtual assets (1)

Valuation of cash flow hedging financial derivative instruments

Increase due to update of valuation of cash flow hedging financial derivative instruments (1)

Remeasurement of defined employee benefits

Increase due to update of remeasurement of defined employee benefits (1)

Accumulated effect by conversion

Increase due to update of accumulated effect by conversion (1)

Participation in OCI of other entities

Increase due to update of participation in OCI of other entities (1)

Non-controlling interest

Net result attributable to non-controlling interest

Other non-controlling interest

Other comprehensive income attributable to non-controlling interest

Collective Financing Institutions

(1) These concepts will be applicable under an inflationary economic environment based on what is established in Financial Information Standard B-10 "Effects of Inflation", issued by the Mexican Council of Financial Information Standards, A.C. (CINIF).

Collective Financing Institutions

Series R13 Financial Statements

Report B-13222 Statement of Comprehensive Income

Includes figures in national currency, foreign currency, UMA and UDIS valued in pesos

Figures in pesos

Concept

Amount

Charged commissions

Paid commissions

RESULT FROM SERVICES

Profit from sales

Loss from sales

Interest income

Interest expenses

Result from fair value valuation

Net monetary position result (financial margin from intermediation) (1)

FINANCIAL MARGIN FROM INTERMEDIATION

Other operating income (expenses)

Administration and promotion expenses

OPERATING RESULT

Participation in the net result of other entities

RESULT BEFORE INCOME TAXES

Income taxes

RESULT FROM CONTINUING OPERATIONS

Discontinued operations

NET RESULT

Other comprehensive income

Valuation of financial instruments to collect or sell

Valuation of cash flow hedging financial derivative instruments

Valuation of virtual assets

Remeasurement of defined employee benefits

Accumulated effect by conversion

Participation in OCI of other entities

COMPREHENSIVE RESULT

Net result attributable to:

Controlling interest

Non-controlling interest

Comprehensive result attributable to:

Controlling interest

Non-controlling interest

BASIC EARNINGS PER ORDINARY SHARE (2)

Collective Financing Institutions

(1) These concepts will be applicable under an inflationary economic environment based on what is established in Financial Information Standard B-10 "Effects of Inflation", issued by the Mexican Council of Financial Information Standards, A.C. (CINIF).

(2) Determined in accordance with what is stipulated by Bulletin B-14 "Earnings per share", issued by the Mexican Council of Financial Information Standards, A.C. (CINIF).

SERIES R27 COMPLAINTS

This series is integrated by one (1) report, whose frequency of preparation and presentation must be quarterly.

REPORT

A-2702

Complaints

In this report, information regarding complaints related to collective financing operations carried out by Clients of Collective Financing Institutions is collected. Additionally, this report considers information regarding the management data of said complaints.

CAPTURE FORMAT

Collective Financing Institutions will carry out the sending of information related to report R27 A-2702 Complaints, by using the following capture format:

REQUESTED INFORMATION

REPORT IDENTIFIER SECTION

PERIOD START

PERIOD END

INSTITUTION KEY

REPORT

COMPLAINT IDENTIFICATION SECTION

COMPLAINT FOLIO

COMPLAINT STATUS

STATUS UPDATE DATE

CLIENT IDENTIFICATION SECTION

CLIENT TYPE

CLIENT IDENTIFIER

FINANCING IDENTIFIER

COMPLAINT DETAIL SECTION

COMPLAINT DATE

COMPLAINT RECEPTION CHANNEL

COMPLAINT TYPE

COMPLAINT REASON

COMPLAINT DESCRIPTION

EVENT DETAIL SECTION

CAUSING THE COMPLAINT

EVENT DATE

EVENT OBJECT

CHANNEL IN WHICH THE UNRECOGNIZED OPERATION WAS CARRIED OUT

AMOUNT VALUED IN NATIONAL CURRENCY

RESOLUTION DETAIL SECTION

RESOLUTION DATE

DIRECTION OF THE RESOLUTION

AMOUNT CREDITED TO THE CLIENT'S ACCOUNT IN THE INSTITUTION

DATE OF CREDIT TO THE CLIENT'S ACCOUNT IN THE INSTITUTION

IDENTIFIER OF THE ACCOUNT OR TRUST OF THE INSTITUTION

AMOUNT RECOVERED

DATE OF RECOVERY OF RESOURCES

IDENTIFIER OF THE ACCOUNT OR TRUST OF THE INSTITUTION

WHERE THE RECOVERED AMOUNT IS RECEIVED

LOSS FOR THE INSTITUTION

Collective Financing Institutions will report the information indicated in this series, which must comply with the validations and quality standards indicated by the National Banking and Securities Commission (Commission), adjusting to the characteristics and specifications. Once the validations and quality standards are met, SITI will generate an electronic receipt.

The information must be sent only once and will be received assuming it meets all characteristics and specifications, in virtue of which it cannot be modified and must present consistency with the various reports in which the same information is included with a different level of integration, therefore, if it does not meet the required quality and characteristics or has been presented incompletely, it will be considered as not fulfilling the obligation of its presentation, and consequently, the corresponding sanctions will be imposed in accordance with the applicable legal provisions.

ANNEX 19

REGULATORY REPORTS OF ELECTRONIC PAYMENT FUND INSTITUTIONS (EPFI)

Frequency

Series R01

Minimum Catalog

A-0111

Minimum Catalog

Monthly

Series R08

Bank and other organism loans

D-0843

Disaggregated loans obtained

Monthly

Series R10

Reclassifications

A-10111

Reclassifications in the statement of financial position

Monthly

A-10121

Reclassifications in the statement of comprehensive income

Monthly

Series R13

Financial Statements

A-13111

Statement of changes in owners' equity

Quarterly

A-13161

Statement of cash flows

Quarterly

B-13211

Statement of financial position

Monthly

B-13221

Statement of comprehensive income

Monthly

Series R26

Commissioner information

A-2610

Highs and lows of commissioner administrators

Per event

A-2611

Disaggregated highs and lows of commissioners

Per event

B-2612

Disaggregated highs and lows of commissioner modules or establishments

Per event

C-2613

Disaggregated tracking of commissioner operations

Monthly

Series R27

Complaints

A-2701

Complaints

Quarterly

SERIES R01 MINIMUM CATALOG

This series is integrated by one (1) report, whose frequency of preparation and presentation must be monthly.

REPORT

A-0111

Minimum Catalog

In this report, the balances at the end of the period of all concepts that form part of the statement of financial position (including off-balance sheet accounts) and the statement of comprehensive income of the Electronic Payment Fund Institution are requested. The report is requested in two subtotals:

·

National currency

·

Foreign currency valued in pesos.

For the completion of report A-0111, the following aspects must be taken into consideration:

The report must present the balances of the Electronic Payment Fund Institution without consolidation.

The balances of all concepts presented in Series R01 Minimum Catalog must be consistent with those reported in the applicable regulatory reports.

For the case of minimum catalog concepts denominated in national currency, UMA and UDIS valued in pesos, these concepts must coincide with the sum of the concepts provided in the regulatory reports in national currency, UMA and UDIS valued in pesos; while the concepts denominated in foreign currency valued in pesos must coincide with the concepts provided in the other regulatory reports in foreign currency valued in pesos.

The data referring to balances must be presented in national currency, foreign currency, UMA and UDIS valued in pesos and foreign currency valued in pesos using the exchange rate indicated in the current accounting criteria. Such balances must be presented in pesos, with four decimals and without commas. For example: $20,585.7000 would be 20585.7000

CAPTURE FORMAT

Electronic Payment Fund Institutions will carry out the sending of information related to report A-0111 Minimum Catalog described above, by using the following capture format:

REQUESTED INFORMATION

REPORT IDENTIFIER SECTION

PERIOD START

PERIOD END

INSTITUTION KEY

REPORT

FINANCIAL INFORMATION SECTION

CONCEPT

CURRENCY

DATA

Electronic Payment Fund Institutions will report the information indicated in this series, which must comply with the validations and quality standards indicated by the National Banking and Securities Commission (Commission), adjusting to the characteristics and specifications. Once the validations and quality standards are met, SITI will generate an electronic receipt.

The information must be sent only once and will be received assuming it meets all characteristics and specifications, in virtue of which it cannot be modified and must present consistency with the various reports in which the same information is included with a different level of integration, therefore, if it does not meet the required quality and characteristics or has been presented incompletely, it will be considered as not fulfilling the obligation of its presentation, and consequently, the corresponding sanctions will be imposed in accordance with the applicable legal provisions.

Electronic Payment Fund Institutions

Series R01 Minimum Catalog

Report A-0111 Minimum Catalog

Includes figures in national currency, foreign currency, UMA and UDIS valued in pesos

Figures in pesos

Concept

National currency,

UMA and UDIS

valued

Foreign currency

valued

ASSET

Cash and cash equivalents

Cash

Banks

Immediate collection documents

Investments available on demand

Restricted or pledged cash and cash equivalents

Virtual assets

Foreign currencies to receive

Foreign currencies to deliver

Others

Others

Margin accounts (financial derivative instruments)

Cash

Investments in financial instruments

Other assets

Investments in financial instruments

Negotiable financial instruments

Negotiable financial instruments without restriction

Government Debt

In position

To deliver

Bank Debt

In position

To deliver

Other debt instruments

In position

To deliver

Equity financial instruments

In position

To deliver

Negotiable financial instruments restricted or pledged

Government Debt

In position

To receive

Bank Debt

In position

To receive

Other debt instruments

In position

To receive

Equity financial instruments

In position

To receive

Financial instruments to collect or sell

Financial instruments to collect or sell without restriction

Government Debt

In position

To deliver

Bank Debt

In position

To deliver

Other debt instruments

In position

To deliver

Financial instruments to collect or sell restricted or pledged

Government Debt

In position

To receive

Bank Debt

In position

To receive

Other debt instruments

In position

To receive

Financial instruments to collect principal and interest

Financial instruments to collect principal and interest without restriction

Government Debt

In position

To deliver

Bank Debt

In position

To deliver

Other debt instruments

In position

To deliver

Financial instruments to collect principal and interest restricted or pledged

Government Debt

In position

To receive

Bank Debt

In position

To receive

Other debt instruments

In position

To receive

Estimate of expected credit losses for investments in financial instruments to collect principal and interest

Financial instruments to collect principal and interest without restriction

Government Debt

In position

To deliver

Bank Debt

In position

To deliver

Other debt instruments

In position

To deliver

Financial instruments to collect principal and interest restricted or pledged

Government Debt

In position

To receive

Bank Debt

In position

To receive

Other debt instruments

In position

To receive

Repo debtors (debit balance)

Financial derivative instruments

For trading purposes

Futures to receive

Forward contracts to receive

Options

Swaps

Credit financial derivative instruments

Structured operations

Valuation

Impairment

Packages of financial derivative instruments

Valuation

Impairment

For hedging purposes

Futures to receive

Forward contracts to receive

Options

Swaps

Credit financial derivative instruments

Structured operations

Valuation

Impairment

Packages of financial derivative instruments

Valuation

Impairment

Virtual assets

Restricted virtual assets

Unrestricted virtual assets

Benefits to be received in securitization operations

Benefits on the remainder in securitization operations

Asset for administration of transferred financial assets

Accounts receivable

Debtors for settlement of operations

Foreign exchange sales

Investments in financial instruments

Repos

Financial derivative instruments

By issuance of securities

Virtual assets

Overdrafts in accounts derived from the transmission of electronic payment funds

Debtors for margin accounts

Debtors for cash collateral granted

Operations with financial instruments

Operations not carried out in recognized markets (OTC)

Others

Diverse debtors

Premiums, commissions and rights to be received

Loans and other debts of personnel

Overdue debts

Other debtors

Taxes to recover

Conditional accounts receivable

Other accounts receivable

Estimate of expected credit losses

Diverse debtors

Conditional accounts receivable

Other accounts receivable

Long-term assets available for sale

Assets related to discontinued operations

Prepayments and other assets

Deferred charges

Insurance to amortize

Other deferred charges

(Continues in the Third Section)

1

Which includes, at least, the calculation base and the total number of financings considered for the determination of the yield.

In its case, average yields can be calculated for different ranges of financed amounts within the same category

of financing.

In the document you are viewing, there may be text, characters or objects that are not displayed correctly due to the conversion to HTML format, so we recommend always taking as reference the digitized image of the DOF or the PDF file of the edition. The content, form and scope of the published documents are the strict responsibility of their issuer.

INQUIRY

BY DATE

Su

Mo

Tu

We

Th

Fr

Sa

INDICATORS

Exchange Rate and Rates as of 08/28/2026

DOLLAR

16.9712 UDIS

8.808812 TIIE 28 DAYS

6.7559% TIIE 91 DAYS

6.7931% TIIE 182 DAYS

6.8474% TIIE DE FONDEO

6.50%

See more

SURVEYS

Did you like the new image of the Official Federal Gazette website?

No

Yes

Official Federal Gazette

Río Amazonas No. 62, Col. Cuauhtémoc, C.P. 06500, Mexico City Tel. (55) 5093-3200, where you can access our services menu

Electronic address: dof.gob.mx

113

LEGAL NOTICE | SOME RIGHTS RESERVED © 2026

More like this from SHCP

SHCP published 14 documents in the last 30 days. We email you each new one the day it's published.

Share