2021-09-09 | DOF 5629270

Added · Updated

Resolution reforming, adding, and repealing General Provisions regarding Articles 115 of the Credit Institutions Law in relation to Articles 87-D and 95-Bis of the General Law of Credit Organizations and Auxiliary Activities, applicable to Multiple-Object Financial Companies

This Resolution amends the General Provisions applicable to Multiple-Object Financial Companies to expand non-presidential identification methods, allowing the use of digital identification mechanisms such as videoconferencing, biometric life proofs, and geolocation data verification. It updates definitions for devices and geolocation, mandates the collection of digital identification documents and electronic consent, and strengthens the Blocked Persons List by including taxpayers listed under Article 69-B of the Federal Tax Code to prevent illicit operations and terrorist financing. The changes aim to align with Financial Action Task Force (FATF) recommendations and accommodate operational needs during the COVID-19 pandemic while maintaining anti-money laundering standards.

Secretaria de Hacienda y Credito Publico logo

Mexico

Secretaria de Hacienda y Credito Publico

Click to view thumbnail

DOF: 09/09/2021

RESOLUTION that reforms, adds, and repeals various of the General Provisions referred to in Articles 115 of the Credit Institutions Law in relation to Article 87-D of the General Law of Credit Organizations and Auxiliary Activities and 95-Bis of this latter legislation, applicable to Multiple-Object Financial Companies.

A seal bearing the National Coat of Arms, which reads: United Mexican States.- TREASURY.- Ministry of

Treasury and Public Credit.

RESOLUTION THAT REFORMS, ADDS, AND REPEALS VARIOUS OF THE GENERAL PROVISIONS REFERRED TO IN ARTICLES 115 OF THE CREDIT INSTITUTIONS LAW IN RELATION TO ARTICLE 87-D OF THE GENERAL LAW OF CREDIT ORGANIZATIONS AND AUXILIARY ACTIVITIES AND 95-BIS OF THIS LATTER LEGISLATION, APPLICABLE TO MULTIPLE-OBJECT FINANCIAL COMPANIES

ROGELIO EDUARDO RAMÍREZ DE LA O, Secretary of Treasury and Public Credit, based on

the provisions of Articles 31, fractions VII and XXXII, of the Organic Law of the Federal Public Administration;

115 of the Credit Institutions Law in relation to 87-D and 95 Bis of the General Law of

Organizations and Auxiliary Credit Activities, in the exercise of the powers conferred upon me by

Article 6, fraction XXXIV, of the Internal Regulations of the Ministry of Treasury and Public Credit, and

having received the prior opinion of the National Banking and Securities Commission issued via letter number

VSPP-220/10030526/2021 dated July 29, 2021; and

CONSIDERING

That since the year 2000 Mexico has been a full member of the Financial Action Task Force (FATF),

an intergovernmental organization that sets international standards in matters of prevention and combat against

operations with proceeds of illicit origin and terrorist financing.

That on March 21, 2019, the Ministry of Treasury and Public Credit published in the Official Gazette of the

Feder various modifications to the General Provisions referred to in Articles 115

of the Credit Institutions Law in relation to Article 87-D of the General Law of

Organizations and Auxiliary Credit Activities and 95-Bis of this latter legislation, applicable to the societies

multiple-object financial with the objective of addressing the recommendations of the FATF and establishing a

non-presidential identification regime, thereby granting the possibility to multiple-object financial societies,

to carry out client identification through a real-time online videoconference in the case of unregulated multiple-object financial societies; which resulted in a

strengthening of the risk assessment methodology so that these entities evaluate their risks of

being used to carry out operations with proceeds of illicit origin and terrorist financing

prior to the use of new technologies.

That on March 6, 2020, the FATF published the Digital Identification Guide, resulting as

a watershed in the topic of financial technology, showing the benefits of digital identity in matters of

prevention and combat against operations with proceeds of illicit origin and terrorist financing,

presenting financial technology as a more reliable and secure method for financial entities

when carrying out client identification through the use of mechanisms such as

life proof, the use of biometric elements and authentication factors, among others, which allow the

mitigation of risks of operations with proceeds of illicit origin and terrorist financing.

That on March 11, 2020, the World Health Organization declared the disease caused by the virus

SARS-CoV2 (COVID-19) as a pandemic, calling on countries to: (i) adopt measures

urgent and aggressive to contain the spread of the virus, (ii) implement an approach based on the

participation of the entire government and all of society, around a comprehensive strategy aimed at preventing

infections, saving lives, and minimizing their effects, and (iii) find a delicate balance between the

protection of health, the minimization of social and economic disruptions, and respect for human

rights.

That on March 24, 2020, the Ministry of Health published in the Official Gazette of the Federation the

"Agreement establishing the preventive measures that must be implemented for the mitigation and

control of health risks implied by the disease caused by the SARS-CoV2 virus (COVID-19)", which

establishes in its Second Article, subsection c) "Temporarily suspend the activities of the sectors

public, social, and private that involve physical concentration, transit, or displacement of people starting from

the entry into force of this Agreement and until April 19, 2020".

That on March 31, 2020, the Ministry of Health published in the Official Gazette of the Federation the

"Agreement establishing extraordinary actions to address the health emergency generated

by the SARS-CoV2 virus", which, in its First Article, fraction I, orders the immediate suspension, from March 30

to April 30, 2020, of non-essential activities, with the aim of mitigating the dispersion and

transmission of the SARS-CoV2 virus in the community.

That through the "Agreement modifying the similar one establishing extraordinary actions to address the

health emergency generated by the SARS-CoV2 virus, published on March 31

of 2020", published on April 21, 2020 in the Official Gazette of the Federation, the Ministry of Health

deemed it necessary to maintain and extend the National Day of Healthy Distance until May 30, 2020,

as well as to ensure the adequate implementation and compliance with health security measures.

That on May 15, 2020, the Ministry of Health published in the Official Gazette of the Federation the "Agreement

modifying the one establishing a strategy for the reopening of social, educational, and economic activities,

as well as a regional traffic light system to evaluate weekly the epidemiological risk related to the reopening of activities in each federal entity, as well as establishing extraordinary actions, published on May 14, 2020" with the objective

of establishing a mechanism involving the public, social, and private sectors to resume

activities under health security protocols, guaranteeing both to their workers, as well as to the general public that standards are being met that reduce risks associated with SARS-CoV2.

That in this sense and particularly with respect to the financial system, there was a massive closure of

branches of various financial entities, in compliance with the sanitary measures declared by the

Federal Government for the period during which the contingency due to COVID-19 is in effect; which translated

into one of the main challenges to guarantee the continuity of the offering and provision of services

financial to the general public attending to the new normality, without neglecting or undermining the regime of

prevention of operations with proceeds of illicit origin and terrorist financing.

That on April 1, 2020, the FATF issued a statement regarding the health emergency generated

by COVID-19 and measures to combat illicit financing, calling for (i) countries to explore the appropriate use of simplified identification measures and digital identification to facilitate

financial operations while mitigating risks of operations with proceeds of

illicit origin and terrorist financing, and (ii) regulators, supervisors, and other authorities

involved in the matter, provide the necessary assistance to the private sector regarding how the

regulation in this matter will be applied during the current health crisis.

That, even though currently multiple-object financial societies have had since March

2019 a non-presidential identification regime, it was not sufficient to address the needs of the

general public to enter into contracts and, at the same time, mitigate risks in matters of prevention of

operations with proceeds of illicit origin and terrorist financing.

That in this sense and based on the FATF Digital Identification Guide, as well as in compliance with

Recommendations 10 and 15 of said group, it is necessary, just as with other participants

regulated in the matter, to recognize the legal possibility that multiple-object financial societies

can comply with their obligations in matters of prevention of operations with proceeds of illicit origin

and terrorist financing through the use of new technologies, of course with

the responsibility of complying with the applicable regulations to that effect so that they have the value that in

law corresponds.

That, additionally, in adherence to FATF Recommendation 4 and the content of the Mutual Evaluation Report,

issued by this intergovernmental organization, in January 2018, it is necessary to strengthen the

legal framework regarding the composition of the Blocked Persons List given that our country,

as a member of the FATF, has recognized the formation of ghost companies as a generalized technique

to carry out operations with proceeds of illicit origin, in this sense, the condition of

inclusion to the Blocked Persons List is added for those taxpayers referred to in the fourth paragraph of

Article 69-B of the Federal Tax Code, the above in order to prevent the commission of the crimes of

operations with proceeds of illicit origin and terrorist financing.

That in attention to Article 78 of the General Law of Regulatory Improvement and with the purpose of complying with the

requirement of regulatory simplification for the issuance of this Resolution, the savings generated in the "Resolution that reforms, adds, and repeals various of the General Provisions

general referred to in Articles 115 of the Credit Institutions Law in relation to Article 87-D of the

General Law of Organizations and Auxiliary Credit Activities and 95-Bis of this latter legislation,

applicable to multiple-object financial societies", dictated by the National Commission for Regulatory Improvement

in file CONAMER/21/3460, with an amount of $1,443,177,655.03 pesos.

RESOLUTION THAT REFORMS, ADDS, AND REPEALS VARIOUS OF THE GENERAL PROVISIONS REFERRED TO IN ARTICLES 115 OF THE CREDIT INSTITUTIONS LAW IN RELATION TO ARTICLE 87-D OF THE GENERAL LAW OF CREDIT ORGANIZATIONS AND AUXILIARY ACTIVITIES AND 95-BIS OF THIS LATTER LEGISLATION, APPLICABLE TO MULTIPLE-OBJECT FINANCIAL COMPANIES

SINGLE ARTICLE.- The 2nd, fractions VIII and XIV; 4th Ter first, second, fourth, and sixth

paragraphs; 5th; 7th, second, fourth, and last paragraphs; 8th; 13th Bis; 20th, second paragraph; 21st, sixth and last

paragraphs; 23rd; 29th first paragraph; 34th first paragraph; 35th, first paragraph, fraction I; 39th Bis, first and last

paragraphs; 40th first paragraph, fractions I to III; 61st, second paragraph; Annex 2 articles 1, 2, and 4; are

REFORMED; the 2nd fractions XIX Bis and XXIII Bis; 4th Ter third and sixth paragraphs, with the rest being renumbered in their

order; 20th third and last paragraphs; 21st seventh paragraph, with the rest being renumbered in their order; 62nd first

paragraph, fraction VII; 65th first paragraph, fraction V; Annex 2 Chapter I "Object", Chapter II "Thresholds for

non-presidential identification", Chapter III "Technological Identification Mechanisms", Chapter IV

"Requirements" and Chapter V "Other provisions", with the articles being renumbered in their order, and are REPEALED 4th Ter

third paragraph; Annex 2, article 3, all of them of the General Provisions referred to in

Articles 115 of the Credit Institutions Law in relation to Article 87-d of the General Law of

organizations and auxiliary credit activities and 95-bis of this latter legislation, applicable to the

multiple-object financial societies, to remain as follows:

2nd.-

...

I. to VII. ...

VIII. Device, the equipment that allows access to the worldwide network called Internet, used for

entering into contracts or carrying out Operations through internet pages or mobile applications, among other

technological developments, which the Entities themselves make available to their Clients to carry them

to.

Devices shall not be considered those that:

a) Are owned by the Entities.

b) Are under the control of the Entities.

c) Are granted under additional controls by the Entities to their Clients so that they can carry out

Operations, or

d) Are installed in the branches of the Entities themselves or in public sites, complying with

the respective regulation so that Clients can enter into contracts or carry out Operations;

IX. to XIII. ...

XIV.

Geolocation, the geographic location of the Device used to enter into contracts or carry out

Non-presidential Operations, which consists of obtaining the geographic coordinates of latitude and longitude

through the global positioning system (GPS) in which the Device is located.

In the event that Clients enter into contracts or carry out Non-presidential Operations from a

Device that, due to its characteristics, cannot provide the geographic coordinates of latitude and

longitude through GPS, the Entities must obtain the geographic coordinates of latitude and longitude

based on matching the Internet protocol address provided by the Client's Device with a

geographic location, for the approximate obtaining of said coordinates.

The geographic coordinates of latitude and longitude obtained through GPS or based on the

matching of the Internet protocol address must be obtained prior to the Client's consent in terms of the regulation that in matters of data protection is applicable;

XV. to XIX. ...

XIX. Bis. Technological Identification Mechanism, any

of the procedures referred to in

Annex 2, through which the Entities carry out the comparison of the valid identification document and

the application of life proofs;

XX. to XXIII.- ...

XXIII. Bis. Interim Compliance Officer, the person referred to in Article 39th Bis of these

Provisions;

XXIV. to XXXVI. ...

4th Ter.- The Entities that enter into a contract through Devices in a non-presidential manner with

Clients, natural or legal persons, both of Mexican nationality, according to what is established in the

Annex 2 of these Provisions or, in the case of regulated multiple-object financial societies that maintain patrimonial links with a credit institution, according to the general provisions issued by the Commission, in addition to the identification data,

referred to in Article 4 of these Provisions, as applicable, must request and obtain from their Clients, the Geolocation

of the Device from which they enter into the contract, as well as:

I. Regarding Clients who are natural persons declaring to the Entity to be of Mexican nationality:

a) Repealed.

b) Consent that may be obtained through Electronic Signature or Advanced Electronic Signature.

Such consent serves as proof to legally establish the celebration of the contract carried out with the

Entity in a non-presidential manner.

c) ...

d) In its case, Standardized Banking Key (CLABE) of an account opened in any financial entity or

Foreign Financial Entity authorized to receive deposits, whose holder coincides with the name referred to in

Article 4, fraction I, of these Provisions.

e) The statement by the natural person indicating that they act on their own behalf. Such

statement may be established in the Terms and Conditions established to that effect by the Entity.

f) The digital version of the valid official personal identification document from which the

data referred to in this provision originate.

g) The digital version of the proof of address, which may be any of those indicated in subsection b),

numeral iii. of fraction I of Article 4 of these Provisions.

However, when the declared address coincides with that of the voter credential of the Client

issued by Mexican authority, in case they have been identified with the same, this will function as the

proof of address referred to in this subsection.

II. Regarding Clients who are legal persons of Mexican nationality:

a) Email.

b) In its case, Standardized Banking Key (CLABE) of an account opened in any financial entity or

Foreign Financial Entities authorized to receive deposits, whose holder coincides with the

designation or corporate name referred to in Article 4, fraction II, of these Provisions.

c) Consent that may be obtained through Electronic Signature or Advanced Electronic Signature, of the

legal representative. Such consent serves as proof to legally establish the celebration of the

contract carried out with the Entity in a non-presidential manner.

d) The information referred to in Article 4, fraction II, subsection c) and fraction VI of these Provisions.

e) The digital version of the identification documents referred to in Article 4, fraction II, subsection b) of the

present Provisions, with the exception of those indicated in numeral ii of the same subsection.

The Entities shall not carry out the celebration of the contract in a non-presidential manner when they do not

collect the data related to Geolocation.

The Entities shall not be obligated to collect the data related to Geolocation regarding the

societies, dependencies, and entities referred to in Annex 1 of these Provisions,

provided that the aforementioned societies, dependencies, and entities had been classified as Clients with

a Low Risk Grade in terms of Article 21st of these Provisions.

Repealed paragraph.

A valid official personal identification document for the purposes of compliance with the

present Provision shall be understood as the voter credential issued by the National Electoral Institute in the country or through the

consular offices of the Ministry of Foreign Affairs abroad, the passport, and the

consular registration certificate.

...

The digital version of the valid official personal identification document that the Entities collect

for identification purposes must allow its verification in terms of these Provisions.

Additionally, the digital versions of the documents that the Entities collect must be

preserved in their Files or Records in accordance with these Provisions. The Entities must

preserve the documents in accordance with the Mexican official standard on digitalization and preservation of

Data Messages applicable or consider an international standard whenever the compliance standard

has at least the requirements of the Mexican official standard and does not contravene it.

...

5th.- Regarding the framework or adhesion contract entered into by an Entity with the Client, under

which the Entity itself issues credit cards to persons other than the holder of said contract, the Entity

may agree with the respective Client the obligation that the latter directly collect from the

cardholders or holders of said credit cards, the data and/or identification documents that correspond

to them, according to what is established in fractions I, II, or III of Article 4 of these

Provisions and, at the same time, the Entity must agree with the Client that they will keep the referred data or

documents available for the Entity's consultation and, if applicable, present them to the Commission at

the moment that the latter so requests from the Entity.

7th.- ...

Regarding contracts entered into in accordance with Article 4th Ter of these Provisions, in substitution of the

interview referred to in the previous paragraph, the Entities may establish the Technological Mechanisms

of Identification referred to in Annex 2 of these Provisions or, in the case of societies

multiple-object financial that maintain patrimonial links with a credit institution, according to

the general provisions issued by the Commission.

...

With respect to the contracts and operations referred to in fraction I of Article 13th of these Provisions, the

Entities may carry out the reception or capture of the data remotely, in substitution of the

interview mentioned in the first paragraph of this provision, provided that the Entity in question,

verifies the authenticity of the Client's data, for which, either directly or through a third party,

it must make a consultation to the National Population Registry in order to integrate the Unique Key of the Population Registry of the Client and validate that the data provided remotely by the same, with the exception

of the address, coincide with the records existing in the databases of said Registry.

The validation of the identification data referred to in this Provision may be carried out through

different procedures than those indicated in the previous paragraph, with prior authorization of the Commission, with

the opinion of the Ministry. Such request must be made through trade associations.

8th.- The Entities must preserve, as part of the identification file of each of their

Clients, the data and documents mentioned in the provisions of this Chapter, if applicable, the

document containing the results of the interview or of the Technological Identification Mechanisms referred to in

Article 7th, as applicable, the one referring to the visit referred to in Article 17th,

if applicable, and the questionnaire provided for in Article 21st of these Provisions.

13th Bis.- For the carrying out of Operations through electronic, optical, or any other

technology, the Entities must previously integrate the Client's identification file in accordance with what is established in these Provisions, establish mechanisms to identify the same, as well as

develop procedures to prevent the improper use of said means or technologies, which must

be contained in their Compliance Manual or in any other document or manual prepared by the

Entity itself.

20th.- ...

Regarding those Operations carried out in a non-presidential manner, in addition to the elements for

determining the Client's transactional profile indicated in the previous paragraph, the Entity must take into account the Geolocation of the Device from which said Operation is carried out,

The Geolocation referred to in the previous paragraph may cover the various Operations carried out by

the Client in the active session within the Internet page or mobile application, among other developments

technological, which the Entities themselves make available to their Clients to carry them out.

Entities will not be obligated to take into account the data related to Geolocation in terms of this Provision, regarding the societies, dependencies, and entities referred to in Annex 1 of these Provisions, provided that said societies, dependencies, and entities have been classified as Clients with a Low Risk Grade in terms of the 21st of these Provisions.

21st.-

...

...

...

...

...

In the case of the celebration of contracts in a non-presential manner referred to in the 4th Ter of these Provisions, Entities must consider the Device Geolocation information from which the Client carries out the Operation, activity, or service with the respective Entity.

Entities will not be obligated to consider Geolocation information in terms of this Provision, regarding the societies, dependencies, and entities referred to in Annex 1 of these Provisions, provided that said societies, dependencies, and entities have been classified as Clients with a Low Risk Grade in terms of this Provision.

...

...

To determine the Risk Grade in which Clients should be located, as well as whether they should be considered Politically Exposed Persons, each Entity will establish in its Compliance Manual the criteria conducive to that end, which take into account, among other aspects, the Client's background, profession, activity or business sector, the origin and destination of its resources, place of residence, Geolocation, the methodology referred to in Chapter II Bis of these Provisions, and the other circumstances determined by the Entity itself.

23rd.- Prior to the celebration of contracts or Operations of Clients who, due to their characteristics, are classified with a High Risk Grade by the Entity, at least one executive or equivalent who has specific powers to approve the celebration of such contracts must grant, in writing, digitally or electronically, the respective approval. Likewise, for the purposes referred to in fractions IV and V of the 39th of these Provisions, Entities must provide in their Compliance Manual the mechanisms so that their respective Compliance Officers have knowledge of those Clients that are classified with a High Risk Grade by the Entities themselves, as well as the procedures that must be carried out to process the approval indicated in this provision.

29th.- For each Unusual Operation detected by an Entity, it must send to the Secretariat, through the Commission, the corresponding report, within three business days following the day on which the Committee session that adjudicates it as such concludes. For the purpose of carrying out the aforementioned adjudication, the Entity, through its Committee, will have a period that will not exceed sixty calendar days counted from when the alert is generated through its system, model, process, or by an employee of the Entity, whichever occurs first.

...

34th.- For each Concerning Internal Operation detected by an Entity, it must send to the Secretariat, through the Commission, the corresponding report, within three business days following the day on which the Committee session that adjudicates it as such concludes. For the purpose of carrying out the aforementioned adjudication, the Entity, through its Committee, will have a period that will not exceed sixty calendar days counted from when said Entity detects that Operation, through its system, model, process, or by any employee thereof, whichever occurs first.

...

...

35th.- Each Entity must have a collegiate body called "Communication and Control Committee" which will have, at a minimum, the following functions and obligations:

I.

Submit to the approval of the Entity's audit committee the Compliance Manual, as well as any modification thereto.

In the case of that Entity that does not have an audit committee, it will correspond to its own Committee or its board of directors or general manager to approve the document indicated in this fraction;

I. Bis. to XII.

...

...

39th Bis.- The Committee of each Entity or, its board of directors or general manager as applicable, may appoint an Entity official who will temporarily exercise the functions of Compliance Officer, in compliance with its obligations under these Provisions, for up to ninety calendar days during a calendar year, counted from when the official designated as Compliance Officer leaves, has their appointment revoked, or is unable to perform the assignment in question.

...

...

The Interim Compliance Officer must perform the functions and obligations indicated in these Provisions, until the moment the revocation indicated in fraction II of the 40th of these Provisions is reported.

40th.- ...

I.

The full name and surname without abbreviations of the official who has been designated as Compliance Officer, as well as the other information provided in the indicated format, within ten business days following the date on which the respective designation was made;

II.

The revocation of the designation of the Compliance Officer or Interim Compliance Officer who had been designated in terms of what is established in both the 39th and 39th Bis of these Provisions, as applicable, within ten business days following the date on which it occurred, whether by determination of the Entity, rejection of the assignment, termination of employment, or impossibility, as well as the other information provided in the indicated format, and

III. The full name and surname without abbreviations of the official who has been designated as Compliance Officer in terms of what is established in the 39th Bis of these Provisions, as well as the other information provided in the indicated format, within ten business days following the date on which it occurred.

61st.-...

Entities must adopt and implement mechanisms that allow identifying Clients or Users who are within the List of Blocked Persons, as well as any third party acting on behalf or for the account of the same, and those Operations that they have carried out, are carrying out, or intend to carry out. Such mechanisms must be provided for in the Compliance Manual of the Entity itself.

62nd.- ...

I. to VI. ...

VII. Those that appear in the list of taxpayers referred to in the fourth paragraph of article 69-B of the Federal Tax Code.

65th.- ...

I. to IV. ...

V. They are in the situation referred to in the sixth paragraph of article 69-B of the Federal Tax Code.

...

Annex 2

...

Chapter I " Object "

Article 1.- This Annex aims to establish the minimum measures and procedures that Entities, with the exception of regulated multiple-object financial societies that maintain patrimonial links with a credit institution, must observe in order to comply with the 4th Ter of these Provisions, without prejudice to the compliance with the various obligations established therein.

Chapter II " Thresholds for non-presential identification "

Article 2.- Entities must observe the following thresholds by type of Technological Identification Mechanism and product on which they request authorization from the Commission for the purposes of complying with the 4th Ter of these Provisions:

I. Regarding the Technological Identification Mechanism provided for in article 4 of this Annex, with respect to Entities, for the purposes of identifying their applicants, in the non-presential celebration of credit contracts granted to individuals, individuals with business activity, or legal entities, all of Mexican nationality, and which do not have real estate collateral, it must be agreed in the respective contracts that the credit line or amount granted does not exceed the equivalent in national currency to 30,000 Investment Units.

II. Regarding the Technological Identification Mechanism provided for in article 5 of this Annex, with respect to Entities, for the purposes of identifying their applicants, in the non-presential celebration of credit contracts granted to individuals or individuals with business activity or legal entities, all of Mexican nationality, and which do not have real estate collateral, it must be agreed in the respective contracts that the credit line or amount granted does not exceed the equivalent in national currency to 60,000 Investment Units.

Entities must take as the reference value of the Investment Units referred to in this article, that applicable for the last day of the calendar month preceding that in which the contract level calculation is carried out for the granting of the credit in question.

Chapter III " Technological Identification Mechanisms "

Article 3.- Entities may opt for one or both of the Technological Identification Mechanisms indicated in articles 4 or 5 subject to the thresholds indicated in article 2 of this Annex.

Without prejudice to the foregoing, additionally, Entities may carry out the Technological Identification Mechanism referred to in article 5 of this Annex subject to the thresholds referred to in fraction I of article 2 of this Annex.

Article 4.- Entities must have technology that allows identifying the applicant through a recording containing image and sound, which must be preserved without edits in its total duration throughout the validity of the contract and, once it concludes, for a period of at least ten years from the conclusion of the contractual relationship.

Additionally, during the development of the Technological Identification Mechanism referred to in the preceding paragraph, Entities must observe the following:

a) Register the time and date of its realization obtained from a protected time server.

b) Implement it through automated tools that allow its recording and subsequent reproduction.

c) Verify that the quality of the image and sound allows full identification of the applicant, according to the parameters established by the Entities themselves for this purpose.

d) Require the applicant to show the valid identification document sent along with the form referred to in fraction III of article 7 of this Annex, both the front and back sides, verifying that it contains the same data and photograph as the valid identification document previously sent.

e) Use specialized technology that allows them to achieve reliable identification of the applicant, ensuring that there is a match between their face and that of the valid identification document previously sent.

f) Perform a liveness test on the applicant during the implementation of the Technological Identification Mechanisms.

For the purposes of the foregoing, a liveness test will be understood as technical tests based on algorithms, to measure and analyze the anatomical characteristics or voluntary and involuntary reactions of the applicant, in order to determine if a biometric sample is being captured from a subject with life present at the capture point.

Article 5.- Entities must verify the match of the applicant's biometric information either with the records of the National Electoral Institute, the Secretariat of Foreign Relations, or with those of any other Mexican authority that provides a biometric information verification service.

In the event that the biometric information referred to in the preceding paragraph is the applicant's fingerprints, Entities must ensure that the applications or means they have available ensure that the fingerprint is obtained directly from the applicant, that is, a live fingerprint test, avoiding the recording of fingerprints from impressions on any material that intends to simulate another person's fingerprint or images that pursue such an end, and have security measures that guarantee that the stored, processed, or sent information through said applications or means is not known or used by unauthorized third parties, as well as authenticate that the fingerprint obtained from the applicant coincides, at least, by ninety percent with the records of the databases of either the National Electoral Institute, the Secretariat of Foreign Relations, or with those of any other Mexican authority that provides a biometric information verification service.

Additionally, Entities must have technology that allows identifying the applicant through a recording containing image and, if applicable, sound, which must be preserved without edits in its total duration throughout the validity of the contract and, once it concludes, for a period of at least ten years from the conclusion of the contractual relationship, and must observe the requirements referred to in article 4, second paragraph of this Annex. To comply with item c), it will be necessary to verify the quality of the sound when applicable.

Article 6.- In the event that the National Electoral Institute, the Secretariat of Foreign Relations, or any other Mexican authority that provides a biometric information verification service, cannot respond to the biometric information verification requests referred to in article 5 of this Annex due to technical or communication failures attributable to the corresponding Mexican authority, Entities may, if they have the corresponding authorization, carry out the Technological Identification Mechanism of article 4 of Annex 2, subject to the corresponding limits.

Chapter IV " Requirements "

Article 7.- Additionally, for the purposes of what is established in this Annex, Entities must:

I.

Obtain prior authorization from the Commission.

Authorization referred to in the preceding paragraph will not be necessary when Entities comply with the thresholds referred to in article 2, fraction I of this Annex and carry out the Technological Identification Mechanism referred to in article 5 of this Annex. In this case, Entities must inform the Commission in advance of the products and the date on which they will begin offering them, through the electronic means indicated by the latter.

Likewise, Entities must observe what is established in fractions II to VII of this article, as well as the requirements provided for in articles 8 and 9 of this Annex. Entities must conserve all the information and supporting documentation, which must be available to the Commission, at its request, within the timeframe established by the Commission itself.

For the purposes of this fraction, the Entity must present the authorization request through a free-form letter addressed to the Commission, which must resolve according to the timeframes provided for in the applicable financial law.

II. Require the applicant to declare whether they are already a Client of the Entity. In the event that the declaration is affirmative, the Entity must observe what is provided for in fraction IV of this article. Regardless of the applicant's declaration, the Entity must complete their identification file according to the product they intend to contract.

III. Require the applicant who has declared not to be a Client of the Entity to send a form through the electronic medium established by the Entity for this purpose, in which the identification data referred to in the 4th Ter of these Provisions must be included at a minimum.

The aforementioned form must include a statement indicating that its submission to the Entity in question constitutes the applicant's acceptance for their image and, if applicable, their voice to be recorded in one of the Technological Identification Mechanisms referred to in Chapter III of this Annex. This statement may be made through automated tools that allow its recording and subsequent reproduction.

IV. In the event that the applicant declares being a Client of the Entity, it must verify at a minimum the data of full name, Client number, and Unique Population Registry Key of the Client, as well as the other data it determines itself in order to corroborate against its own records that, in fact, it is a Client, and in case it is so, the Entity must authenticate them with a category 3 authentication factor.

A category 3 authentication factor will be understood as the information contained, received, or generated by electronic means or devices, as well as that obtained by dynamic single-use password generators. Such means or devices must be provided by the Entities to their Clients and the information contained, received, or generated by them must meet the following characteristics:

a) Have properties that prevent duplication or alteration.

b) Be dynamic information that cannot be used more than once.

c) Have a validity that cannot exceed two minutes.

d) Not be known prior to its generation and use by the Entity's officials, employees, representatives, or agents, or by third parties.

In the event that the verification referred to in the first paragraph of this fraction is successful, the Entity may proceed to the contracting of the products provided for in article 2 of this Annex, without the need to carry out what is established in the following fractions V to VIII.

When the verification referred to in this fraction is not successful, the Entity must observe the same requirements provided for in this Annex for applicants who declare not to be Clients.

V. If the Entity corroborates that the applicant is not its Client, together with the form referred to in fraction III of this article, it must require the applicant to send a color photograph of one of the valid identification documents, referred to in the 4th Ter of these Provisions, front and back, and verify the security elements, in order to detect if they present alterations or inconsistencies, for which they must have the necessary technology for this.

Repealed.

Repealed.

...

Repealed.

Regarding the voter credential issued by the National Electoral Institute in the country or through the consular offices of the Secretariat of Foreign Relations abroad, Entities must verify the match of the data listed below, with the records of the Institute itself or with those of any other Mexican authority that provides a verification service regarding said identification document:

a) The Credential Identifier Code (CIC), which is printed on the voter credential or, if applicable, the Optical Character Recognition Code (OCR)

b) to d) ...

Entities must verify that the paternal and maternal surnames and name or names, as they appear on the presented voter credential, match the records of the National Electoral Institute or the National Population Registry or with those of any other Mexican authority that provides a verification service for said identification document.

Regarding the Mexican passport issued by the Secretariat of Foreign Relations in the country or through its consular offices abroad, Entities must verify the match of the data mentioned below with the records of the Secretariat itself or with those of any other Mexican authority that provides a verification service regarding said identification document:

a) The Optical Character Recognition Code (OCR).

b) Paternal and maternal surnames and name(s), as they appear on the Mexican passport.

c) Passport Number.

In the case of the consular enrollment certificate issued by the consular offices of the Secretariat of Foreign Relations abroad, Entities must verify the match of the data mentioned below with the records of the Secretariat itself or with those of any other Mexican authority that provides a verification service regarding said identification document:

a) Paternal and maternal surnames and name(s), as they appear on the consular enrollment certificate.

b) Issue date and expiration date.

c) Document number.

Additionally, Entities must require the applicant to send in digital format the necessary documents to integrate and conserve their identification file in terms of what is provided for in the 4th Ter of these Provisions.

VI. Inform the applicant of the procedure that will be followed in the Technological Identification Mechanism corresponding, provided for in Chapter III of this Annex, and what are the accesses to the means for its realization, as well as deliver a single-use code, which will be required from the applicant at the beginning of the Technological Identification Mechanism in question.

Repealed.

VII. Entities must suspend the applicant's contracting process when any of the following cases occur:

a) The quality of the image and, if applicable, that of the sound, do not allow full identification of the applicant.

b) The applicant does not present the valid identification document previously sent along with the form referred to in fraction III of article 7 of this Annex, the data obtained from this does not match the records of the National Electoral Institute, the Secretariat of Foreign Relations, the National Population Registry, or with those of any other Mexican authority that provides a biometric information verification service regarding said identification document, or the result of the validation of the elements of the aforementioned documents, or of the biometric verifications of the applicant's face referred to in article 5 above, does not reach the effectiveness or level of reliability referred to in fraction VII of article 9 of this Annex.

c) and d) ...

e) Atypical or risky situations occur, or the Entity has doubts about the authenticity of the valid identification document or the identity of the applicant.

Repealed.

Repealed.

In the event of suspension of the contracting process for the causes mentioned in the preceding subsections,

Entities must store the information and documentation obtained for at least 30

calendar days, with the objective that, in the event of resuming the contracting processes, it is corroborated that the

information is consistent. Additionally, the aforementioned information and documentation must be

used by the Entities in the controls provided for in these Provisions.

For the case of Clients or applicants who are legal entities, for the purposes of identifying their

attorneys-in-fact or legal representatives, the Entities must observe the same procedures indicated

in this article, with the exception that, for the case of applicants who declare not to be Clients, the

sending of the form referred to in fraction III of this article, must be done via file signed

with the Advanced Electronic Signature of the legal entity in question.

The technology used for the procedures referred to in this Annex must be approved

by the risk officer or their equivalent or, in the event of not having this, by the audit committee, the

board of directors or sole administrator of the Entity.

Repealed.

Article 8.- The Entities must have the necessary means for the transmission and safeguarding of

the information, data, and files generated in the identification procedures referred to in Article

7 of this Annex, which guarantee the integrity of such information, as well as the correct reading of

the data and the impossibility of its manipulation, as well as its adequate security, conservation and

location.

The Entities referred to in the previous article may use technological improvements that help to

compensate for the clarity of the images, when any of the valid identification documents

is shown and the facial recognition of the applicant is performed, which must be approved by their risk officer

or their equivalent or, in the event of not having this, by the audit committee, the board of

directors or sole administrator.

Chapter V "Other Provisions"

Repealed.

Article 9.- The Entities, when requesting the authorization referred to in article 7, must present the

following:

I. Detailed description of the non-presential identification process, as well as the Technological Infrastructure

used in each part of this, specifying the function of each component of said infrastructure, which must be approved by the risk officer or their equivalent or, in the event of not having this, by the audit committee, the board of directors or sole administrator.

Likewise, the Entities must include all technology providers involved in the

Technological Infrastructure and, if applicable, the main applications used for the referred process and their

interrelation.

II. Description of the electronic means used so that applicants send, if applicable, the

form and documents through a secure channel considering, at least, the type of transmission from the device to the node that receives the form information, such as Hyper Text Transfer Protocol Secure, or

Transport Layer Security version 1.2 or higher.

III. Name of the certification service provider authorized by the Ministry of Economy used

for the conservation of the digital version of any of the valid identification documents, referred to in

4th Ter of these Provisions, in accordance with the Official Mexican Standard on digitalization and

conservation of Data Messages applicable or consider an international standard whenever the standard

of compliance has at least the requirements of the Mexican official standard and does not contravene it.

IV. Network diagram showing all components of the Technological Infrastructure that form

part of the non-presential identification process, including the segregation of communication networks and

perimeter security equipment, considering redundancy schemes.

Repealed.

V. Detailed information on whether the images of valid identification documents, recordings and

biometric information will be kept in service provider facilities or the Entity's own facilities, describing the controls for access management and mechanisms for their storage.

VI. Evidence that the means of verifying the validity of identification documents have the

effectiveness approved by the risk officer or their equivalent or, in the event of not having this, by the

audit committee, the board of directors or sole administrator.

VII. If applicable, evidence that the systems, tools, or mechanisms used for

facial identification recognitions or the verifications of any other biometric element that are

used have the level of reliability determined by the risk officer or their equivalent or, in the event of not

having this, by the audit committee, the board of directors or sole administrator of the

Entity.

VIII. If applicable, detailed information on the calibration tests for the systems, tools, or

mechanisms used for facial identification recognitions or the verifications of any other

biometric element that are used.

These tests must be performed in accordance with the thresholds established by the Entity, which

must contemplate the results of these tests, and the adjustments of the validation engine derived from them.

The Entities must accompany their authorization request with evidence of all of the above.

IX. Image quality standards and, if applicable, sound quality standards.

X. If applicable, the technical description of Authentication Factors category 3 that will be required to

corroborate that an applicant is a Client of the Entity, in accordance with what is provided in article 7 of this

Annex, as well as the characteristics of the one-time code.

XI. Mechanisms through which they will transmit and securely safeguard the information, data

and documents generated in the non-presential identification procedure.

XII. Mechanisms used to guarantee the integrity, correct reading, impossibility of manipulation and

adequate security, conservation, and location of the information, data, and documents referred to in the

present Annex.

XIII. Encryption mechanisms in the communication channels used in the non-presential identification

process, indicating the information that will be transmitted through each of said channels.

XIV. Mechanisms used for access management to systems, as well as policies for

access management, which include the use of robust passwords.

XV. Policies and procedures for information security incident management.

XVI. Mechanisms or tools used for monitoring and blocking contracting processes that present

the situations described in subsection e) of fraction VII of article 7 of this Annex.

XVII. Conduct tests aimed at detecting vulnerabilities and threats, as well as penetration

tests on the different components of the Technological Infrastructure used in the process, whether

own or third-party. The aforementioned penetration tests must be performed by an independent third

party that has personnel with technical capacity demonstrable through specialized industry certifications

in the subject matter.

The Entities must provide evidence to the Commission of the performance of the tests referred to in

fractions VIII and XVII of this article, before implementing the scheme that has been authorized to them in accordance with article 7 of this Annex.

It shall be the responsibility of the Entities that hire third parties to store, process, and transmit

information in the non-presential contracting process, the surveillance of compliance with this article, at

least once a year, as well as the obligation to have the evidence supporting it, which they must

have available to the Commission at all times.

When the Entities intend to modify any of the procedures they have authorized to give

compliance to article 4 or article 5, as applicable, of this Annex, they will require prior

authorization from the Commission.

Transitional Provisions

First.- This Resolution will enter into force the day after its publication in the Official Journal of the

Federal Federation except for what is provided in the following Transitional Provisions.

Second.- The guidelines, interpretations, and criteria issued by the Ministry or by the Commission, based

on what is established in the Resolution of December 31, 2014, and subsequent Resolutions

through which the General Provisions referred to in

articles 115 of the Credit Institutions Law in relation to 87-D of the General Law of

Organizations and Auxiliary Credit Activities and 95-Bis of this latter legislation, applicable to multi-object

financial societies, will continue to be applicable insofar as they do not conflict with what is

established in this Resolution.

Third.- Multi-object financial societies that have obtained approval from the

National Banking and Securities Commission for the non-presential identification mechanisms under Annex 2 of

the General Provisions referred to in articles 115 of the Credit Institutions Law

in relation to 87-D of the General Law of Organizations and Auxiliary Credit Activities and 95-Bis of

this latter legislation, applicable to multi-object financial societies, in force prior to

the entry into force of this Resolution, will have a period of twelve months, counted from the

entry into force of this Resolution, to submit to said Commission a new request for approval in

compliance with article 7, fraction I of Annex 2 that is reformed with this instrument.

The authorization referred to in the preceding paragraph will remain in force until such time as the National Banking

and Securities Commission resolves on the approval request that the multi-object financial societies

have presented to said Commission in accordance with Annex 2 of the General Provisions

referred to in articles 115 of the Credit Institutions Law in relation to

87-D of the General Law of Organizations and Auxiliary Credit Activities and 95-Bis of this latter

legislation, applicable to multi-object financial societies, which are reformed with this

Resolution.

Fourth.- The Entities must comply with the obligations contained in this

Resolution, in the terms and in accordance with the deadlines indicated below:

I. Four months counted from the entry into force of this Resolution to modify the

Compliance Manual and present it to the Commission.

II. Nine months counted from the date of entry into force of this Resolution, to

modify the methodology referred to in Chapter II Bis.

III. Eighteen months counted from the date of entry into force of this Resolution, to

update the automated systems referred to in 43rd of the Provisions.

Fifth.- In the event that the Entities update the scenario provided for in article 7, fraction I, second paragraph

of Annex 2 that is reformed with this Resolution, they must inform via email

prevencion.lavado@cnbv.gob.mx, through a free-form letter addressed to the General Directorates of

Prevention of Operations with Illicit Proceeds A and B of the Commission, the situation provided for in

said article until the Commission establishes the appropriate electronic means for the Entities to

comply with what is provided in said article.

Sixth.- Those references to beneficial owner that are provided for in other normative frameworks, guidelines, or guides issued by competent authorities in matters of prevention of operations with

illicit proceeds and financing of terrorism other than these Provisions, as well as in

public consultation databases under the responsibility of competent authorities, the Entities may

equate them to the defined term of Beneficial Owner referred to in these Provisions.

Mexico City, August 25, 2021.- The Secretary of Finance and Public Credit, Rogelio

Eduardo Ramírez de la O.- Signature.

In the document you are viewing, there may be text, characters, or objects that do not display correctly due to conversion to HTML format, so we recommend always taking the digitized image of the DOF or the PDF file of the edition as reference. The content, form, and scope of published documents are the strict responsibility of their issuer.

CONSULT

BY DATE

Do Mo Tu We Th Fr Sa

INDICATORS

Exchange Rate and Rates as of 08/28/2026

DOLLAR

16.9712 UDIS

8.808812 TIIE 28 DAYS

6.7559% TIIE 91 DAYS

6.7931% TIIE 182 DAYS

6.8474% TIIE DE FONDEO

6.50%

See more

SURVEYS

Did you like the new look of the Official Journal of the Federal Federation website?

No

Yes

Official Journal of the Federal Federation

Río Amazonas No. 62, Col. Cuauhtémoc, C.P. 06500, Mexico City Tel. (55) 5093-3200, where you can access our service menu

Electronic address: dof.gob.mx

113

LEGAL NOTICE | SOME RIGHTS RESERVED © 2026

More like this from SHCP

SHCP published 14 documents in the last 30 days. We email you each new one the day it's published.

Topics
Share