2019-03-21 | DOF 5554779Added
The Secretariat of Finance and Public Credit amends the General Provisions for Multiple-Object Financial Societies to align with Financial Action Task Force (FATF) recommendations, specifically prohibiting simplified customer identification when money laundering or terrorist financing is suspected. The resolution mandates the assessment of risks associated with new technologies and the identification of politically exposed persons, while introducing definitions for novel models and electronic compliance methods. It also removes the obligation to submit training reports, allowing entities to focus resources on these new preventive measures.
DOF: 21/03/2019
RESOLUTION that reforms, adds and repeals various of the General Provisions referred to in Article 115 of the Credit Institutions Law in relation to Article 87-D of the General Law of Organizations and Auxiliary Credit Activities and 95-Bis of this latter legislation, applicable to multiple-object financial societies.
At the margin a seal with the National Coat of Arms, which says: United Mexican States.- SHCP.- Secretariat of Finance and Public Credit.
RESOLUTION THAT REFORMS, ADDS AND REPEALS VARIOUS OF THE GENERAL PROVISIONS REFERRED TO IN ARTICLES 115 OF THE CREDIT INSTITUTIONS LAW IN RELATION WITH 87-D OF THE GENERAL LAW OF ORGANIZATIONS AND AUXILIARY CREDIT ACTIVITIES AND 95-BIS OF THIS LATTER LEGISLATION, APPLICABLE TO MULTIPLE-OBJECT FINANCIAL SOCIETIES
CARLOS MANUEL URZÚA MACÍAS, Secretary of Finance and Public Credit, based on what is provided by articles 31, fractions VIII and XXXIV, of the Organic Law of the Federal Public Administration; 115 of the Credit Institutions Law and 95 Bis and 87-D of the General Law of Organizations and Auxiliary Credit Activities, in exercise of the powers conferred upon me by article 6, fraction XXXIV, of the Internal Regulations of the Secretariat of Finance and Public Credit, and having received the prior opinion of the National Banking and Securities Commission issued through letter number DGPORPIA/73665/ 2019 and 213-2/78557/2/2019 dated January 25, 2019; and
CONSIDERING
That during the 2016-2017 period, Mexico was evaluated within the framework of the Fourth Round of Mutual Evaluation of the Financial Action Task Force (FATF), in order to examine its level of compliance with international standards in matters of prevention of money laundering and terrorist financing;
That as a result of the above, on January 3, 2018, the FATF published the "Mutual Evaluation Report" through which this intergovernmental entity made various recommendations to Mexico in order to strengthen its regime for the prevention of money laundering and terrorist financing;
That therefore, the Secretariat of Finance and Public Credit has considered making various modifications to the general provisions that establish the minimum criteria and procedures in matters of prevention of money laundering and terrorist financing for multiple-object financial societies, regulated and unregulated, this with the object of attending the recommendations of the FATF and strengthening the regime in this matter;
That additionally to the reform carried out on March 9, 2017 to the general provisions in matters of prevention of money laundering and terrorist financing applicable to multiple-object financial societies, regulated and unregulated, to help improve compliance with FATF Recommendations 1 and 10, it is specified in the legal framework the prohibition for multiple-object financial societies, regulated and unregulated, to carry out simplified identification measures for their clients or users when they suspect that the resources, assets or values that said clients or users intend to use to carry out an operation, could be related to money laundering or terrorist financing;
That likewise, in compliance with FATF Recommendation 10, it is necessary to strengthen the legal framework regarding the identification and customer knowledge policy for multiple-object financial societies, regulated and unregulated, establishing the circumstances in which they may suspend the identification process, in order to prevent the commission of crimes of money laundering and terrorist financing, among others; and in its case, report to the competent authority the respective unusual operation report;
That to better attend to FATF Recommendation 12, it is convenient to establish that multiple-object financial societies, regulated and unregulated, determine if the beneficial owners of their clients or users have the status of politically exposed persons, whether national or foreign in accordance with the applicable provisions, to be in a position to apply the appropriate customer due diligence measures;
That on the other hand, given that multiple-object financial societies, regulated and unregulated, can provide financial services through new technologies, which have been recognized by the Mexican Government with the issuance of the Law to Regulate Financial Technology Institutions and its secondary provisions, in compliance with FATF Recommendation 15 and what is stated in the Report of January 3, 2018, it is necessary that these evaluate the risk of providing financial services through said technologies, so it is convenient to establish such obligation, prior to its implementation and development, as well as for its monitoring;
That even though currently multiple-object financial societies, regulated and unregulated, comply with the obligation of customer due diligence in a presencial and traditional manner, except for some exceptions recognized in the norm, in the existence of the digital era, new technologies and electronic media, in the integration, conservation, maintenance, verification, etc., of data, information and documents, it is necessary, as with other regulated participants in the matter, to recognize the legal possibility that multiple-object financial societies, regulated and unregulated, can comply with their obligations in matters of prevention of money laundering and terrorist financing through said electronic media, of course with the responsibility that they comply with the applicable norms to the effect that they have the value that corresponds in law;
That with the purpose of prioritizing efforts and resources in the new obligations established in this resolution, it is estimated convenient to eliminate the obligation for regulated and unregulated multiple-object financial societies to send the training report, without this implying that they should not have such training, and;
That once the opinion of the National Banking and Securities Commission has been heard, I have deemed it appropriate to issue the following:
RESOLUTION THAT REFORMS, ADDS AND REPEALS VARIOUS OF THE GENERAL PROVISIONS REFERRED TO IN ARTICLES 115 OF THE CREDIT INSTITUTIONS LAW IN RELATION WITH 87-D OF THE GENERAL LAW OF ORGANIZATIONS AND AUXILIARY CREDIT ACTIVITIES AND 95-BIS OF THIS LATTER LEGISLATION, APPLICABLE TO MULTIPLE-OBJECT FINANCIAL SOCIETIES
SINGLE ARTICLE.- The 1st, first paragraph; 2nd, fractions I to XXIII; 3rd, third paragraph; 4th, fractions I to IX and first, second, third, fourth, sixth and last paragraphs; 5th; 7th, first and third paragraphs; 9th, first paragraph fraction I and fraction II, subsection a); 10th; 12th; 13th Bis; 14th, fifth paragraph; 15th, second paragraph and sixth paragraph, fraction II, subsection b); 16th, second paragraph, fraction I and third paragraph; 17th, first, second and last paragraphs; 17th-1; 17th-2; 17th-3; 17th-4 and 17th-5 becoming 17th-6; 18th, second paragraph; 21st, seventh and penultimate paragraphs; 22nd; 23rd; 24th, third, fourth and last paragraphs; 25th; 26th, first paragraph; 29th, first paragraph; 30th, second and last paragraphs; 33rd, first and third paragraphs; 34th, first paragraph; 35th, first paragraph, fractions I first paragraph, I Bis, II, first paragraph, III and last paragraph; 36th, last paragraph; 39th, third paragraph, fractions I, I Bis, IV, VI, VII, IX, X, and last paragraph; 40th, first paragraph; 41st, first paragraph fraction I; 43rd, first paragraph, fractions II, V, IX Bis and X; 44th, first paragraph; 45th, first paragraph; 46th, first and last paragraphs; 49th, first paragraph; 50th, second paragraph; 51st, first, second and last paragraphs; 52nd, last paragraph; 54th, first, eighth and last paragraphs; 55th; 56th; 57th; 58th, first paragraph; 59th; 60th, last paragraph; 61st, second paragraph; 63rd, second paragraph; Annex 1; are REFORMED; the 2nd fractions XXIV to XXXVI; 4th Ter; 7th, second paragraph, renumbering the rest in order; 10th-Bis; 10th-Ter; 13th Ter; 17th, third paragraph, renumbering in order; 17th-1, second paragraph, renumbering the rest in order; 17th-4, first and second paragraphs; 17th-5, renumbering the next in order; 20th, second paragraph; 21st, sixth and eighth paragraphs, renumbering the rest in order; 35th, fractions XI and XII; 43rd, fractions II, second paragraph, V Bis and XI; 51st, third paragraph renumbering the rest in order, 60th, second paragraph, renumbering the rest in order; a Chapter XII Bis titled "Novel Models"; 60th-1; Annex 2; and are REPEALED the 2nd, fractions VII Bis, VII Ter, VIII Bis, IX Bis IX Ter and XXXII, before XIX;
41st, last paragraph; all of them of the General Provisions referred to in articles 115 of the Credit Institutions Law in relation with 87-D of the General Law of Organizations and Auxiliary Credit Activities and 95-Bis of this latter legislation, applicable to multiple-object financial societies, to remain as follows:
1st.- These Provisions have as their object to establish, in accordance with what is provided by article 115 of the Credit Institutions Law, 71 and 72 of the Law to Regulate the Activities of Savings and Loan Cooperative Societies, 124 of the Popular Savings and Credit Law and 129 of the Credit Unions Law applicable by express provision of article 87-D of the General Law of Organizations and Auxiliary Credit Activities in the case of regulated multiple-object financial societies, and by article 95 Bis of this latter legislation when it comes to unregulated multiple-object financial societies, on the one hand, the minimum measures and procedures that both types of multiple-object financial societies are obliged to observe to prevent and detect acts, omissions or operations that could favor, provide help, aid or cooperation of any kind for the commission of the crime provided for in Article 139 Quater of the Federal Penal Code or that could be located in the circumstances of Article 400 Bis of the same Code and, on the other hand, the terms and modalities according to which said societies must present to the Secretariat of Finance and Public Credit, through the National Banking and Securities Commission, reports on the acts, operations and services they carry out with their clients and users related to the circumstances provided for in articles 139 Quater or 400 Bis cited, as well as those carried out by members of their respective boards of directors or in their case, sole administrator, or their executives, officials, employees and agents, that could be located in said circumstances or contravene or undermine the adequate application of these Provisions.
...
...
...
2nd .-. . .
I. Archive or Record, the set of data and documents that are conserved or stored in printed format or in electronic, optical or any other technology media, provided that, in these latter media, it is ensured that the information has remained intact and unaltered from the moment it was generated for the first time in its definitive form and is accessible for subsequent consultation, having as purpose to integrate, conserve and evidence the Operations of the Entities;
II. Beneficiary ,. . .
III. Client ,. . .
Natural persons who prove to the Entities subject to the tax regime applicable to natural persons with business activity in terms of sections I and II of Chapter II of Title IV of the Income Tax Law, will be considered as legal entities for the purposes of what is established in these Provisions, except for what refers to the integration of the file of these, which must be carried out in terms of what is established in fraction I of the 4th and, when applicable, in the 4th Ter and in the 13th of these Provisions and, in which, the Entities must additionally require the Federal Taxpayer Registry key (with homoclave) of said natural persons;
IV. Commission ,. . .
V. Committee ,. . .
VI. Control ,. . .
VII. Concentrating Account ,. . .
VII Bis.- Repealed.
VII Ter.- Repealed.
VIII. Device, the equipment that allows access to the worldwide network called Internet, which can be used to celebrate contracts and carry out Operations;
VIII Bis.- Repealed.
IX. Entities ,. . .
IX Bis.- Repealed.
IX Ter.- Repealed.
X. Foreign Financial Entity ,. . .
XI. Trust ,. . .
XII. Electronic Signature , to the traits or data in electronic form recorded in a Data Message, or attached or logically associated with it by any technology, which are used to identify the subscriber or originator of the instruction of some Operation or financial service and indicate that the signer approves the information contained in the Data Message, and that produces the same legal effects as the autograph signature;
XIII. Advanced Electronic Signature ,. . .
XIV. Geolocation ,
the geographic coordinates of latitude and longitude where the
Device is located;
XV. Degree of Risk ,. . .
XVI. Technological Infrastructure , to the computer equipment, data processing and communications installations, equipment and communications networks, operating systems, databases, applications and systems that Entities use to support their operations;
XVII.
Monetary Instrument ,. . .
XVIII. Blocked Persons List ,. . .
XIX. Compliance Manual ,
to the document referred to in the 54th of these Provisions;
XX. Data Message ,
to the information generated, sent, received or archived by electronic, optical or any other technology means, in accordance with the Code of Commerce;
XXI. Mitigants ,. . .
XXII. Novel Model ,
to that which for the provision of financial services uses tools or technological means with modalities different from those existing in the market at the moment when the temporary authorization referred to in the Law to Regulate Financial Technology Institutions is granted;
XXIII. Compliance Officer ,. . .
XXIV. Operations ,. . .
XXV. Unusual Operation ,. . .
XXVI. Internal Concerning Operation ,. . .
XXVII. Relevant Operation ,. . .
XXVIII. Politically Exposed Person ,. . .
XXIX. Beneficial Owner ,. . .
XXX. Resource Provider ,. . .
XXXI. Risk ,. . .
XXXII. Repealed.
XXXIII. Secretariat ,. . .
XXXIV. Obligated Subjects , to the entities or societies subject to the obligations referred to in articles 115 of the Credit Institutions Law, 71 and 72 of the Law to Regulate the Activities of Savings and Loan Cooperative Societies, 124 of the Popular Savings and Credit Law and 58 of the Law to Regulate Financial Technology Institutions;
XXXV.
Terms and Conditions ,
to the legal bases and statements that Entities establish with
their Clients through computer applications, interfaces, Internet pages or any other electronic or digital communication medium in a format established by the Entity itself for the celebration
of
Operations, activities or services with these, and
XXXVI. User ,. . .
3rd .-. . .
...
The policy and guidelines mentioned above must form an integral part of the Entity's Compliance Manual.
4th. - The Entities must integrate and conserve an identification file of each of their Clients prior to them celebrating, in a presencial manner, a contract to carry out Operations of any type.
To integrate the identification files of the Clients they must comply, at least with the following:
I.
In the case of Clients who are natural persons who declare to the Entity to be of Mexican nationality or of foreign nationality under conditions of temporary resident or permanent resident stay, in terms of the Migration Law, or in the capacity of diplomatic and consular representative in terms of the Guidelines for the issuance of non-ordinary visas:
a)
The following identification data:
i.
Paternal surname, maternal surname, if applicable, and name or names without abbreviations.
ii.
Gender.
iii.
Date of birth.
iv.
State of birth, when applicable.
v.
Country of birth.
vi.
Nationality.
vii.
Occupation, profession, activity or business sector to which the Client is dedicated.
viii.
Private address at their place of residence (composed of the name of the street, avenue or route
in question, duly specified; exterior number and, if applicable, interior; neighborhood or
urbanization; borough or municipality or similar political demarcation that corresponds, if applicable;
city or population, state, province, department or similar political demarcation that corresponds, if applicable; postal code and country).
ix.
Phone number(s) where they can be located.
x.
Email, if applicable.
xi.
Unique Population Registry Key, Federal Taxpayer Registry key (with
homoclave), tax identification number and/or equivalent, as well as the country or countries that assigned them, when available.
xii.
Serial number of the Advanced Electronic Signature, when they have it.
In addition to the above, regarding persons who have their place of residence abroad and, at the
same time, have an address in national territory where they can receive correspondence addressed to them, the
Entity must record in the file the data related to said address, with the same elements as
those contemplated in this fraction.
b)
Simple copy of the following documents:
i.
Personal identification, which must be, in all cases, an original official document issued by
competent authority, valid on the date of its presentation, containing the photograph, signature and,
if applicable, address of the Client itself.
For the purposes of what is provided by this subsection, the following documents issued by Mexican authorities will be considered as valid personal identification documents: the voter credential, the passport, the professional card, the national military service card, the consular enrollment certificate, the military identity card, the affiliation card to the National Institute of Older Adults, the credentials and cards issued by the Mexican Institute of Social Security, by the Institute of Social Security and Services for State Workers, by the Social Security Institute for the Mexican Armed Forces or by Popular Insurance, the driver's license, the credentials issued by federal, state and municipal authorities, the identity statements issued by municipal authorities and the other national identifications that, if applicable, the Commission approves. Likewise, regarding the natural persons of foreign nationality referred to in this fraction, in addition to those previously referred to in this paragraph, the passport or passport card or the documentation issued by the National Institute of Migration that accredits their migratory status, as well as the accreditation card issued by the Secretariat of Foreign Affairs to diplomatic or consular bodies will be considered as valid personal identification documents.
ii.
Certificate of the Unique Population Registry Key, issued by the Secretariat of
Governance, document in which the assignment of the tax identification number and/or equivalent issued by competent authority, as well as of the Advanced Electronic Signature, when they have them, is recorded. It will not be necessary to present the certificate of the Unique Population Registry Key if it appears in another document or official identification.
The Entities will not be obliged to collect, include and conserve in the Client's identification file corresponding, simple copy of the documents referred to in the previous paragraph, provided that the Entities integrate into it, the evidence in which it is recorded that the documents and/or the Client's data were presented and/or validated before the corresponding authority.
iii.
Proof of address, which may be any receipt for payment for home services such as, among others, supply of electricity, telephone, natural gas, property tax or rights for water supply or bank statements, all of them with an age not greater than three months from their date of issuance, or the lease contract valid on the date of presentation by the Client, certificate of residence issued by municipal authority, the proof of registration before the Federal Taxpayer Registry, as well as the others that, if applicable, the Commission approves.
Notwithstanding the above, when the address declared in the contract celebrated by the Client with the Entity coincides with that of the Client's voter credential issued by Mexican authority, in case that they have been identified with the same, this will function as the proof of address referred to in the previous paragraph.
iv.
Declaration of the natural person, granted in writing, by optical means or by any other technology, which may be included in the application documentation for the celebration of Operation or in the respective contract, in which it is recorded that said person acts for these purposes in their own name and on their own account or on behalf of a third party, as the case may be.
In the event that the natural person declares to the Entity that they act on behalf of a third party, said Entity must observe what is provided in fraction VI of this provision regarding the Beneficial Owner of the resources involved in the corresponding contract.
v.
In the event that the natural person acts as an agent of another person, the respective Entity must collect and integrate into the identification file of the Client in question, simple copy of the power of attorney or of the certified copy of the document issued by a public notary, as applicable, in the terms established in common legislation, which accredits the powers conferred to the agent, as well as an official identification and proof of address of the agent, which comply with the requirements indicated in this fraction I regarding said documents, independent of the data and documents related to the principal.
II.
Regarding Clients who are legal entities of Mexican nationality:
a)
The following identification data:
i.
Trade name or corporate name.
ii.
Commercial activity, activity or corporate purpose.
iii.
Nationality.
iv.
Federal Taxpayer Registry key (with homoclave) and, if applicable, number of
tax identification and/or equivalent, as well as the country or countries that assigned them.
v.
Serial number of the Advanced Electronic Signature, when they have it.
vi.
Address (composed of the name of the street, avenue, or road in question, duly specified; exterior number and, if applicable, interior number; neighborhood; borough or municipality or similar political demarcation corresponding, if applicable; city or town; federal entity and postal code).
vii.
Phone number(s) for said address.
viii.
Email address, if applicable.
ix.
Date of incorporation.
x.
Name or names and paternal and maternal surnames, without abbreviations, of the administrator or administrators, director, general manager, or legal representative who, with their signature, can bind the legal entity for the purposes of entering into a contract or carrying out the Operation in question, derived from a valid, official, current personal identification document issued by a competent authority, in accordance with what is provided in numeral i., subsection b), fraction I of this provision.
b)
Simple copy of the following documents:
i.
Notarized copy or certified copy of the public instrument that accredits its legal existence, registered in the corresponding public registry, according to the nature of the legal entity, or of any instrument in which the data of its incorporation and its registration in said registry appear, or else, the document that, according to the regime applicable to the legal entity in question, credibly accredits its existence.
In the event that the legal entity is of recent incorporation and, for this reason, is not yet registered in the corresponding public registry according to its nature, the Entity in question must obtain a written document signed by a person legally authorized to accredit its personality in terms of the public instrument that accredits its legal existence referred to in subsection b) numeral iv., of this fraction, in which the obligation to carry out the respective registration and to provide, in due course, the data corresponding to the Entity itself is stated.
ii.
Tax Identification Card issued by the Ministry and, if applicable, the document in which the assignment of the tax identification number and/or equivalent issued by a competent authority appears, and proof of the Advanced Electronic Signature.
iii.
Proof of address referred to in subsection a) of this fraction II, in terms of what is stated in subsection b), numeral iii., of the previous fraction I.
iv.
Notarized copy or certified copy of the instrument containing the powers of the representative or legal representatives, issued by a public notary, when they are not contained in the public instrument that accredits the legal existence of the legal entity in question, as well as the personal identification of each of said representatives, in accordance with subsection b), numeral i., of the previous fraction I.
Regarding federal, state, and municipal public departments and entities, as well as other Mexican legal entities of public law, to accredit their legal existence as well as to prove the powers of their legal representatives and/or proxies, the laws, regulations, decrees, or organic statutes that create and regulate their constitution and operation shall apply, and if applicable, a copy of their appointment or public instrument issued by a notary, as appropriate.
The Entities must record in the client identification file of the Entity that is a currency exchange center, money transmitter, or other Entity, the registration data granted to them by the Commission or the National Commission for the Protection and Defense of Users of Financial Services, as appropriate, which must be obtained from the public records under the charge of said commissions.
c)
Client information that allows the Entity to know:
i.
Shareholder structure or social parts, as appropriate.
ii.
In the event that it has a Risk Grade different from low, its internal corporate structure; that is, the organizational chart of the client legal entity, considering at least the full name and position of those individuals who hold positions between general director and the immediate lower hierarchy, as well as the full name and corresponding position of the members of its board of directors or equivalent.
Likewise, the Entities must identify the Beneficial Owners of their corporate clients that exercise Control over them in terms of the second paragraph of fraction VI of the 2nd of these Provisions, in accordance with what is established in fraction VI of this provision.
When there is no natural person who owns or controls, directly or indirectly, a percentage equal to or greater than 25% of the capital or voting rights of the legal entity in question, or who by other means exercises Control, direct or indirect, of the legal entity, it will be considered that the administrator or administrators thereof exercise said Control, understanding that the natural person designated for such effect exercises administration.
When the designated administrator is a legal entity or Trust, it will be understood that Control is exercised by the natural person appointed as administrator by said legal entity or Trust.
For the purposes of this subsection, the Entities must obtain a written declaration, by electronic, optical, or any other technology means, from the legal representative of the corporate client in question, in which it is indicated who their Beneficial Owners are in terms of this subsection.
In the event that the Entities have indications that make the truthfulness of the declared information questionable, they must take reasonable measures to determine and identify the Beneficial Owners of the corresponding corporate client.
III.
Regarding Clients who are persons of foreign nationality, the Entity in question must observe the following:
a)
For the case of the natural person who declares to the Entity that they do not have the condition of temporary resident or permanent resident in terms of the Migration Law, or the quality of diplomatic and consular representative in terms of the Guidelines for the issuance of non-ordinary visas:
i.
The respective identification file must contain the same data as those indicated in subsection a) of the previous fraction I, with the exception of the data of the federal entity of birth.
ii.
Collect and include in said file a simple copy of the following documents:
ii.1.
Passport or passport card and official document issued by the National Institute of Migration, when the latter is available, which accredits their entry or legal stay in the country or, alternatively, the accreditation card issued by the Ministry of Foreign Affairs to diplomatic and consular bodies.
ii.2.
Document that accredits the Client's address at their place of residence, in terms of subsection b) numeral iii., of fraction I of this provision.
ii.3.
Declaration in terms of subsection b), numeral iv., of fraction I of this provision.
b)
For the case of foreign legal entities:
i.
The respective identification file must contain the following data recorded:
i.1.
Trade name or corporate name.
i.2.
Commercial activity, activity, or corporate purpose.
i.3.
Nationality.
i.4.
Federal Taxpayer Registry Key (with homoclave) and/or tax identification number and/or equivalent, the country or countries that assigned them, and, if applicable, the serial number of the Advanced Electronic Signature.
i.5.
Address (composed of the name of the street, avenue, or road in question, duly specified; exterior number and, if applicable, interior number; neighborhood or urbanization; borough or municipality or similar political demarcation corresponding, if applicable; city or town, federal entity, state, province, department, or similar political demarcation corresponding, if applicable; postal code and country).
i.6.
Phone number(s) for said address.
i.7.
Email address, if applicable.
i.8.
Date of incorporation.
ii.
Collect and include in said file a simple copy of, at least, the following documents:
ii.1.
Document that credibly proves its legal existence, document in which the assignment of the tax identification number and/or equivalent issued by a competent authority appears, as well as obtaining the information and collecting the data referred to in subsection c), of fraction II of this provision.
The Entity must require that the document referred to in the previous paragraph be duly legalized or, in the event that the country where said document was issued is a party to the "Convention Abolishing the Requirement of Legalization for Foreign Public Documents," adopted in The Hague, Netherlands, on October 5, 1961, it will suffice that said document bear the apostille referred to by said Convention.
In the event that the respective Client does not present the document duly legalized or apostilled, it will be the responsibility of the Entity to ensure the authenticity of said documentation.
ii.2.
Proof of address referred to in number i.5., of numeral i of this subsection b) above, in terms of what is stated in subsection b), numeral iii., of fraction I of this provision.
ii.3.
Notarized copy or certified copy of the instrument containing the powers of the representative or legal representatives, issued by a public notary, when they are not contained in the document that credibly proves the legal existence of the legal entity in question, as well as the personal identification of said representatives, in accordance with subsection b), numeral i., of fraction I or subsection a), numeral ii, number ii.1., of this fraction III, as appropriate.
In the case of those legal representatives who are outside the national territory and who do not have a passport or passport card, the personal identification must, in any case, be an original official document issued by a competent authority of the country of origin, current on the date of its presentation, containing the photograph, signature, and, if applicable, address of the said representative.
For the purposes of the foregoing, driver's licenses and credentials issued by federal authorities or equivalents of the country in question will be considered as valid personal identification documents. The verification of the authenticity of said documents will be the responsibility of the Entities.
IV.
Regarding the societies, departments, and entities referred to in Annex 1 of these Provisions:
a)
The following identification data:
i.
Trade name or corporate name.
ii.
Activity or corporate purpose.
iii.
Federal Taxpayer Registry (with homoclave) and, if applicable, tax identification number and/or equivalent, as well as the country or countries that assigned them.
iv.
Serial number of the Advanced Electronic Signature, when they have it.
v.
Address (composed of the name of the street, exterior number and, if applicable, interior number, neighborhood, city or town, borough or municipality, federal entity, and postal code).
vi.
Nationality.
vii.
Phone number(s) for said address.
viii.
Email address, if applicable.
ix.
Full name without abbreviations of the administrator or administrators, director, general manager, or legal representative who, with their signature, can bind the society, department, or entity for the purposes of entering into the Operation in question.
b)
Simple copy of the following documents:
i.
Notarized copy or certified copy of the instrument containing the powers of the representative or legal representatives, issued by a public notary.
Regarding the representative of a credit institution, the certification of appointment issued by a competent official in terms of Article 90 of the Credit Institutions Law.
To accredit the powers of the representatives of federal, state, and municipal public departments and entities, as well as other Mexican legal entities of public law, the provisions in the penultimate paragraph of subsection b) of fraction II of this provision shall apply.
ii.
Personal identification of such representatives, in accordance with subsection b), numeral i., of the previous fraction I.
The Entities may apply the simplified measures referred to in this fraction, provided that the aforementioned societies, departments, and entities have been classified as Clients with a Low Risk Grade in terms of the 21st of these Provisions.
V.
Regarding Resource Providers, the following data:
a)
In the case of natural persons:
i.
Paternal surname, maternal surname, if applicable, and name or names without abbreviations.
ii.
Date of birth.
iii.
Nationality.
iv.
Home address (composed of the name of the street, avenue, or road in question, duly specified, exterior number and, if applicable, interior number, neighborhood, city or town, borough or municipality, federal entity, and postal code).
v.
Federal Taxpayer Registry Key (with homoclave), tax identification number and/or equivalent, the country or countries that assigned them, Unique Registry of Population Key, as well as the serial number of the Advanced Electronic Signature, when they have them.
vi.
Occupation, profession, activity, or business sector to which the Resource Provider is dedicated.
b)
In the case of legal entities:
i.
Trade name or corporate name.
ii.
Nationality.
iii.
Federal Taxpayer Registry Key (with homoclave) and, if applicable, tax identification number and/or equivalent, as well as the country or countries that assigned them.
iv.
Serial number of the Advanced Electronic Signature, when they have it.
v.
Address (composed of the name of the street, avenue, or road in question, duly specified, exterior number and, if applicable, interior number, neighborhood, city or town, borough or municipality, federal entity, and postal code).
The Entities will not be obligated to collect the data referred to in this fraction in the following cases:
When the Resource Providers are departments and entities of the Federal Public Administration, of the City of Mexico, or of any federal entity or municipality, that contribute resources for the payment of the respective credit under support programs for the benefit of certain sectors of the population.
In the cases referred to in fraction I of the 13th of these Provisions.
VI.
Regarding Beneficial Owners, the Entity must collect the same data and documents as those established in fractions I or III, subsection a) of this provision, as appropriate. With respect to the address, it will suffice to obtain the data and the document of the address where they can be located.
When the obligation to identify the Beneficial Owner derives from a Client classified with a Low Risk Grade, the document referred to in numeral iii., of subsection b), of fraction I, as well as number ii.2., of numeral ii., of subsection b), of fraction III of this provision, respectively, shall not be collected.
The foregoing, in accordance with the measures established for such purposes in their Compliance Manual, or in another document or manual prepared by the Entities themselves.
Additionally, the Entity must identify if the Beneficial Owner is a Politically Exposed Person, and if identified as such, must comply with what is established in the 22nd and 24th of these Provisions.
Regarding legal entities whose titles representing their social capital or securities representing said shares trade on any stock exchange in the country or in recognized foreign securities markets in terms of the general provisions applicable to stock exchanges published in the Official Journal of the Federation on May 15, 2017, and their respective modifications, as well as those subsidiaries in which they have a majority participation of over fifty percent in their social capital, the Entities will not be obligated to collect the aforementioned identification data, considering that they are subject to provisions in matters of stock exchange on information disclosure.
The Ministry will issue guidelines that the Entities may consider for compliance with what is provided in the first paragraph of this fraction, which will be made known through the electronic means established for such purposes by the Commission.
VII. Regarding persons who appear as co-grantees, joint obligors, or third parties authorized in the Operation carried out by the Client, the Entities must observe the same requirements contemplated in this Provision for the granted Clients.
Likewise, regarding those persons who appear as debtors of the collection rights acquired through a financial factoring operation, the Entities must observe the same requirements contemplated in this provision for the Clients.
VIII. With respect to Beneficiaries, the Entities will collect at least the following data: paternal surname, maternal surname, if applicable, and name or names without abbreviations; home address (composed of the same elements as those indicated in subsection a) of fraction I of this provision), when this is different from that of the contract holder, as well as the date of birth of each of them.
In the cases referred to in fraction I of the 13th of these Provisions, the Entities may collect the data of the Beneficiaries referred to in the previous paragraph, after said contracts or Operations have been carried out, through the means determined by the Entities themselves; said means must be contemplated in the Compliance Manual of the Entity itself.
IX.
Regarding Trusts:
a)
It must contain the following data recorded:
i.
Number or reference of the Trust and, if applicable, Federal Taxpayer Registry (with homoclave), tax identification number and/or equivalent, the country or countries that assigned them, as well as the serial number of the Advanced Electronic Signature.
ii.
Purpose of the Trust and, if applicable, indicate the vulnerable activity(ies) it carries out in terms of Article 17 of the Federal Law for the Prevention and Identification of Operations with Resources of Illicit Origin.
iii.
Place and date of constitution or celebration of the Trust.
iv.
Trade name or corporate name of the fiduciary institution.
v.
Trusted assets (goods and rights).
vi.
Contributions of the settlors.
vii.
Identification data, in terms of this provision, as appropriate, of the settlors, beneficiaries, fiduciary delegates, and, if applicable, members of the technical committee or equivalent governing body, legal representative(s) and legal proxy(ies).
Without prejudice to the foregoing, the Entity that does not act as fiduciary may comply with the obligation to collect data regarding members of the technical committee or equivalent governing body, indicating only the name or names and paternal and maternal surnames, without abbreviations, of these, as well as their date of birth.
b)
Simple copy of the following documents:
i.
Contract, notarized copy, or certified copy of the public instrument that accredits the celebration or constitution of the Trust, registered, if applicable, in the corresponding public registry, or else, the document that, according to the regime applicable to the Trust in question, credibly accredits its existence.
In the event that the Trust is of recent constitution and, for this reason, is not yet registered in the corresponding public registry according to its nature, the Entity in question must obtain a written document signed by a person legally authorized to accredit its personality in terms of the public instrument referred to in subsection b) numeral iii., of this fraction, in which the obligation to carry out the respective registration and to provide, in due course, the data corresponding to the Entity itself is stated.
ii.
Proof of address, in terms of what is stated in subsection b), numeral iii., of fraction I of this provision.
iii.
Notarized copy or certified copy of the instrument containing the powers of the legal representative(s), legal proxy(ies), or fiduciary delegate(s), issued by a public notary, when they are not contained in the public instrument that accredits the legal existence of the Trust in question, as well as the personal identification of each of said representatives, proxies, or fiduciary delegates, in accordance with subsection b), numeral i., of fraction I of this provision.
iv.
Tax Identification Card issued by the Ministry and, if applicable, the document in which the assignment of the tax identification number and/or equivalent issued by a competent authority appears, as well as proof of the Advanced Electronic Signature.
The Entities must integrate the identification file of the beneficiaries who are not individualized in the contract, at the moment when they go to exercise their rights derived from the Trust contract. The obligation established in this paragraph will not be applicable for those Trusts where there is intermediation of securities, in which case the obligation will fall on the financial entity that carries out said intermediation.
The Entities will not be obligated to integrate the identification file when it comes to Trusts in which the contributions destined for labor benefits or social security for workers come from the workers themselves or from the employers, and the settlor is always a public entity that allocates the funds in question for the aforementioned purposes.
With respect to the integration and conservation of the identification files of beneficiaries in Trusts that are constituted to fulfill labor or social security benefits of a general nature, in which contributions are received from the departments and entities of the Federal Public Administration, of the City of Mexico or of a federal entity or municipality, as well as from other Mexican legal entities of public law or from companies, their unions, or persons belonging to both, the Entities will be subject to the following:
a)
The identification file of each of the beneficiaries may be integrated and conserved by the Client instead of the Entity. In this case, the Entity must contractually agree with the Client the obligation to keep said file available for consultation by the Entity and
provide it to the Entity itself, so that it may present it to the Commission, at the moment when the latter so requires of the Entity.
b)
In the case referred to in the preceding subsection, the Entities must contractually agree with the Client that, in substitution for them, the Client will compile and retain the identification files of the trustors, and establish mechanisms so that the Entities themselves may: (i) verify, on a random basis, that such files are compiled in accordance with the provisions set forth in these General Provisions, and (ii) retain the identification file of those workers or personnel once they cease to provide their services to the Client. In any case, the Entities will be responsible at all times for compliance with the obligations regarding Client identification established by these General Provisions, for which purpose they must establish in the Compliance Manual the mechanisms they will adopt to comply with the provisions of this subsection.
Trusts that are constituted to fulfill general labor or social security benefits referred to in the preceding paragraph may include, among others, the following: Trusts based on pension funds with seniority premium plans; to establish multiple benefits or allowances; for mortgage loans to employees; for savings funds and mutual aid boxes.
Entities that conduct Operations with Trusts in respect of which they do not act as trustees may comply with the obligation (a) to obtain the document referred to in numeral i. of subsection b) of this subsection, and (b) referred to in subsection VI of this provision, respectively, through a certificate signed by the trustee delegate and the Compliance Officer of the entity, institution, or company acting as trustee, which must contain the information indicated in subsection a) above, as well as the obligation to keep such documentation available to the Secretariat and the Commission, in order to transmit them, upon request of the latter, within the timeframe established by the Commission itself.
When the provided identification documents contain strikethroughs or amendments, the Entities must obtain another means of identification or, in default thereof, request two banking or commercial references and two personal references, which must include the first and last names without abbreviations, the full address composed of the same data as indicated in subsection I of this provision, and the phone number of the issuer, the authenticity of which will be verified by the Entities with the persons who sign such references, before the respective contract is executed.
. . .
Entities, when obtaining simple copies of the documents that must form part of the Client identification files, in accordance with the provisions of this disposition, must ensure that these are legible and compare them against the corresponding original documents that are physically present.
. . .
Entities may keep, in their Files or Records, separately the data and documents that must form part of their Clients' identification files, without the need to integrate them into a single physical file, provided they have automated systems that allow them to combine such data and documents for timely consultation by the Entities themselves or by the Secretariat or the Commission, upon request of the latter, in accordance with these General Provisions and any others applicable.
4th Ter.- Entities that enter into a contract through Non-presential Devices with individual Clients of Mexican or foreign nationality, in accordance with the provisions of Annex 2 of these General Provisions or, in the case of multiple-object financial companies regulated that maintain patrimonial links with a credit institution, in accordance with the general provisions issued by the Commission, in addition to the identification data, as applicable, referred to in the 4th of these General Provisions, must require and obtain from their Clients, with their prior consent, the Geolocation of the Device from which they execute the contract, as well as:
a)
Voter Key, if applicable.
b)
Consent.
c)
Email or mobile phone number.
d)
If applicable, account number and Standardized Banking Key (CLABE) in the financial entity or Authorized Foreign Financial Entity permitted to receive deposits, and which corresponds to the name referred to in the 4th, subsection I, subsection a), numeral i., of these General Provisions.
e)
The declaration of the individual stating whether they act on their own behalf or on behalf of a third party; in the event they declare that they act on behalf of a third party, the provisions of the 4th, subsection VI of these General Provisions shall apply. Such declaration may be established in the Terms and Conditions established by the Entity for this purpose.
f)
The digital version of the valid, current official personal identification document from which the data referred to in this provision originate, which must be preserved in accordance with the applicable Mexican Official Standard on digitalization and preservation of Data Messages.
Entities must not carry out the non-presential execution of contracts with individual Clients of Mexican or foreign nationality when they have not obtained the data regarding Geolocation.
The consent that Entities obtain from their Clients in accordance with this provision may be obtained through Electronic Signature, Advanced Electronic Signature, or in accordance with Annex 2 of these General Provisions or, in the case of multiple-object financial companies that maintain patrimonial links with a credit institution, in accordance with the general provisions issued by the Commission. Such Client consent legally evidences the execution of the contract or the Operation conducted with the Entity in a non-presential manner.
For the purposes of this provision, a valid, current official personal identification document shall be understood to be the voter credential issued by the National Electoral Institute and other national or foreign identifications that, if applicable, are approved by the Commission.
Entities may obtain the digital versions of the documentation referred to in this Provision in a non-presential manner and through electronic, optical, or any other technology means.
The digital versions that Entities obtain for identification purposes must allow for verification in accordance with these General Provisions. Furthermore, such digital versions must be preserved in their Files or Records in accordance with these General Provisions.
Entities must establish in their Compliance Manual the criteria and mechanisms they will adopt to comply with the provisions of this disposition.
5th.- Regarding the framework or adhesion contract executed by an Entity with the Client, under which the Entity itself issues credit cards to persons other than the holder of said contract, the Entity may agree with the respective Client that the latter directly obtain from the cardholders or holders of said credit cards the identification documents corresponding to them, in accordance with the provisions of subsections I, II, or III of the 4th of these General Provisions, and, in turn, the Entity must agree with the Client that they will keep said documents available for the Entity's consultation and, if applicable, present them to the Commission at the moment the latter so requires of the Entity.
7th.- The Entity, prior to establishing or initiating a commercial relationship with a Client, must hold an in-person interview with the Client or their legal representative, in order to obtain the respective identification data and documents. The results of the interview must be recorded in writing or electronically and be kept in the Entity's Files or Records.
In the case of contracts executed in accordance with the 4th Ter of these General Provisions, the interview referred to in the preceding paragraph may be conducted in a non-presential manner, using forms that interact with the Client, in accordance with Annex 2 of these General Provisions or, in the case of multiple-object financial companies that maintain patrimonial links with a credit institution, in accordance with the general provisions issued by the Commission.
Entities may enter into agreements with third parties to conduct the interview referred to in this provision. In any case, Entities falling under the circumstance provided in this paragraph will be responsible for compliance with the obligations regarding Client identification and knowledge established by these General Provisions.
. . .
. . .
9th.- . . .
I.
The entity that compiles and retains said file must have the Client's consent for said entity to provide the data and documents related to their identification, or the digital version of the latter, to any of the entities forming the financial group with which it intends to establish a commercial relationship, and
II.
. . .
a)
They may exchange the data and documents related to Client identification, as well as the digital versions thereof, in order to establish a new commercial relationship with the same;
b) and c)
. . .
10th.- Entities are prohibited from executing contracts or maintaining anonymous accounts, under fictitious names, or in which the Client or Beneficial Owner cannot be identified; therefore, they may only conduct Operations with their Clients when they have fulfilled the identification requirements for them, in accordance with these General Provisions.
10th Bis.- Entities may not apply the simplified measures provided for in this Chapter to their Clients when they have a well-founded suspicion or indications that the funds, assets, or values that their Clients intend to use to conduct an Operation might be related to the acts or conduct referred to in Articles 139 Quater or 400 Bis of the Federal Penal Code.
The policies, criteria, measures, and procedures that Entities develop to determine the aforementioned must be documented in their Compliance Manual.
10th Ter.- Entities may suspend the identification process of their potential Client or User when they reasonably estimate:
I.
That they might be related to acts or conduct referred to in Articles 139 Quater or 400 Bis of the Federal Penal Code.
II.
That continuing with the identification process could prevent or alert the Client or User that the Entity considers the funds, assets, or values to be related to acts or conduct referred to in Articles 139 Quater or 400 Bis of the Federal Penal Code.
III.
When they identify the existence of Risks in accordance with the criteria established in their Compliance Manual.
In the event of carrying out the suspension referred to in this provision, Entities must generate the corresponding Unusual Operation Report within 24 hours, with the information they have regarding the potential Client or User in question, which may be prepared manually.
The report referred to in the preceding paragraph must be transmitted to the Secretariat, through the Commission, within 24 hours counted from the moment the Entity becomes aware of the information indicated in this provision, using the corresponding official format.
For the purposes of the provisions of this disposition, Entities must establish in their Compliance Manual, or in another document or manual prepared by the Entity itself, the necessary policies, criteria, measures, and procedures.
12th.- In the case of mandates or commissions that Entities are authorized to perform, they must invariably compile the identification file of all parties involved in the signing of the respective instruments (mandator, mandatory, commissioner, principal), in the terms established in the 4th or 4th Ter of these General Provisions, except when it concerns third parties referred to in stipulations for their benefit that are not individually identified in the respective mandate or commission contract.
13th Bis.- For the execution of Operations through electronic, optical, or any other technology means, Entities must previously compile the Client identification file in accordance with these General Provisions, establish mechanisms to identify them in accordance with Annex 2 of these General Provisions or, in the case of multiple-object financial companies that maintain patrimonial links with a credit institution, in accordance with the general provisions issued by the Commission, as well as develop procedures to prevent the improper use of such means or technology, which must be contained in their Compliance Manual.
13th Ter.- Entities must verify the data and documents that their potential Clients provide to prove their identity.
The verification referred to in the preceding paragraph may be conducted in a non-presential manner in accordance with Annex 2 of these General Provisions or, in the case of multiple-object financial companies that maintain patrimonial links with a credit institution, in accordance with the general provisions issued by the Commission, insofar as applicable.
When it concerns Operations of Clients classified by Entities as Low Risk, the verification referred to in the first paragraph of this provision may be performed after the execution of the respective contract. In the cases referred to in this paragraph, Entities must inform their Clients that they will not be able to conduct Operations until the verification process referred to in this provision is concluded.
Entities must establish in their Compliance Manual the policies, criteria, measures, and procedures they will adopt to comply with the provisions of this disposition.
The verification of the data and documents referred to in this provision, obtained from their Clients, may be performed by third parties without exempting the Entities from compliance with the obligations provided in these General Provisions.
14th .-. . .
. . .
. . .
. . .
Entities must preserve the information contemplated in this provision to provide it to the Secretariat and the Commission, upon request of the latter.
. . .
. . .
15th.-. . .
In the case of Users falling under the aforementioned circumstance, Entities must obtain and preserve in the systems referred to in the 43rd of these General Provisions the data indicated in the 4th or 4th Ter of said Provisions, depending on whether they are individuals or legal entities, including information corresponding to third parties who, through the User, carry out the operation in question.
. . .
. . .
. . .
For the purposes of the provisions of the preceding paragraph, Entities must obtain from the issuers of said payment means the following:
I. . . .
II. . . .
a)
. . .
b)
Evaluate the controls they have, in order to determine that they comply with the applicable international standards in matters of prevention of operations with funds of illicit origin and financing of terrorism. The criteria according to which Entities will carry out the evaluation indicated in this subsection must be contemplated in their Compliance Manual, or in another document or manual prepared by the Entity in question, and
c)
. . .
. . .
16th .- . . .
. . .
I.
The data referred to in subsections I, II, III, and IX of the 4th or the first paragraph of the 4th Ter of these General Provisions, depending on whether they are individuals, legal entities, or Trusts, regardless of whether they are Clients or Users, as well as occupation or profession, activity, corporate purpose, business line, or purpose of the Trust;
II. . . .
III. . . .
Entities must preserve the information contemplated in this provision to provide it to the Secretariat and the Commission, upon request of the latter.
. . .
17th.- Entities will verify that the identification files of their corporate Clients, regardless of their Risk Grade, contain all the data and documents provided for in the 4th of these General Provisions, as well as that said data and documents are up to date, understanding that Entities may choose not to carry out the update of the latter if it concerns a corporate Client with a Low Risk Grade. The foregoing, in the terms and conditions established by Entities in their own Compliance Manual. Similarly, they will verify, at least once a year, that the identification files of their Clients classified as High Risk contain, in an updated manner, all the data and documents provided for in the 4th, 4th Ter, 24th, and 26th of these General Provisions.
If during the course of a commercial relationship with a Client, the Entity in question detects significant changes in the Client's usual transactional behavior, without a justified cause for it, or if doubts arise regarding the veracity or accuracy of the data or documents provided by the Client itself, among other circumstances established by the Entity itself in its Compliance Manual, it will reclassify said Client into the corresponding higher Risk Grade, according to the results of the analysis that, if applicable, the Entity performs, and must verify and request the update of both the data and identification documents, among other measures the Entity deems convenient.
Entities may comply with the obligation to update their Clients' files in accordance with this provision in a non-presential manner, regardless of the form of contract execution, always obtaining the data and documents applicable according to the type of Client, and carrying out the respective verification.
Entities must establish in their Compliance Manual the policies, criteria, measures, and procedures they will adopt to comply with the provisions of this disposition, including the circumstances in which a visit to the domicile of Clients classified as High Risk must be conducted, in order to properly compile the files and/or update the corresponding data and documents, in which case a record of the results of such visit must be left in the respective file.
17th-1.- Entities must design and implement a methodology to carry out a Risk Evaluation of the risks to which they are exposed derived from their products, services, Clients, Users, countries or geographic areas, transactions, and sending or distribution channels with which they operate.
The design of the methodology referred to in the preceding paragraph must be established in their Compliance Manual, or in another document or manual prepared by the Entity, and must establish and describe all processes that will be carried out for the identification, measurement, and mitigation of Risks, for which they must take into account the Risk factors identified for this purpose, as well as the information applicable given the context of each Entity contained in the national risk evaluation and its updates that the Secretariat makes known to them through the Commission.
In the case of Entities that are part of financial groups in terms of the Law to Regulate Financial Groupings, they must establish in the design of the methodology how the results of the methodology that, if applicable, have been implemented by the other financial entities forming the corresponding group will be taken into account.
Likewise, Entities will carry out an evaluation of the Risks to which they are exposed in accordance with the provisions of this Chapter, prior to the launch or use of new products, services, types of Clients and/or Users, countries or geographic areas, sending or distribution channels, and transactions.
17th-2.- For the design of the Risk Evaluation methodology, Entities must comply with the following:
I.
Identify the elements and indicators associated with each of them that explain how and to what extent the Entity may be exposed to Risk, considering at least the following elements:
a)
Products and services.
b)
Clients and Users.
c)
Countries and geographic areas.
d)
Transactions and sending or distribution channels linked to the Entity's Operations, with its Clients and with its Users.
Within the process of identifying Risk indicators, the total of products, services, types of Clients and Users, countries or geographic areas, transactions, and sending or distribution channels with which the Entity operates must be considered.
II.
Use a method for the measurement of Risks that establishes a relationship between the indicators referred to in the preceding subsection I and the element to which they belong, as well as assign a weight to each of them consistently based on their importance to describe said Risks. In turn, a weight must be assigned to each of the defined Risk elements consistently based on their importance to describe the Risks to which the Entity is exposed.
III.
Identify the Mitigants that the Entity has implemented at the time of the design of the methodology, considering all internal policies, criteria, measures, and procedures referred to in the 54th of these General Provisions, as well as their effective application, in order to establish the effect these will have on the indicators and Risk elements indicated in the preceding subsection I, as well as on the Entity's Risk.
17th-3.- Entities must implement the designed methodology and obtain the results thereof in order to know the Risks to which they are exposed. In the implementation of the Risk Evaluation methodology, Entities must ensure:
I.
That there be no inconsistencies between the information incorporated into this and that which is in their automated systems.
II.
Use, at least, the information corresponding to the total number of Clients, number of operations, and amount operated corresponding to a period that shall not be less than twelve months.
When, as a result of the implementation of the Risk assessment methodology, the existence of greater or new Risks for the Entities themselves is detected, these shall modify the policies, criteria, measures, and procedures corresponding to them, contained in the Compliance Manual, or in any other document or manual prepared by the Entity, in order to establish the Mitigants that it considers necessary based on the identified Risks, as well as to maintain them at an acceptable tolerance level in accordance with what is established in the Compliance Manual.
The modifications to the internal policies, criteria, measures, and procedures referred to in the preceding paragraph, derived from the results of the implementation of the Risk assessment methodology, shall be carried out within a period not exceeding twelve months from the date the Entity has the results of its implementation and shall be clearly identified and indicated, indicating at least the year and month in which the results of the implementation of the methodology that gave rise to such modifications were obtained.
17th-4.- The compliance and results of the obligations contained in this Chapter shall be reviewed and updated by the Entities: when the existence of new Risks is detected, when the national risk assessment is updated, or within a period not exceeding 12 months from the date the Entity has the results of its implementation. Such reviews and updates shall be in writing and available to the Secretariat and the Commission, at the request of the latter, within the period established by the Commission itself.
The Commission may review and, if appropriate, order the Entities to modify their Risk assessment methodology or their Mitigants, among other cases, when it does not consider proper Risk management in the procedure and criteria for determining the start, limitation, or termination of a commercial relationship with its Clients or Users, which must be congruent with said methodology, as well as to request an action plan so that they adopt reinforced measures to manage and mitigate their Risks.
The Entities shall retain the information generated by reason of this Chapter for a period of not less than five years and provide it to the Secretariat and to the Commission, at the request of the latter, within the period that the Commission itself establishes.
17th-5.- The Entities shall comply with all the obligations contained in these Provisions, in accordance with the results generated by their methodologies referred to in this Chapter.
17th-6.- The Commission, prior to the opinion of the Secretariat, will prepare guidelines, guides and/or best practices that the Entities will consider for the better compliance with what is provided in this present Chapter, which will be made known through the electronic means established by the same.
18th .-. . .
Such policy shall be an integral part of the Compliance Manual of each Entity.
20th .-. . .
In the case of those Operations carried out remotely, in addition to the elements for determining the transactional profile of the Client indicated in the preceding paragraph, the Entity shall take into account the Geolocation of the Device from which said Operation is carried out.
21st .-. . .
. . .
. . .
. . .
. . .
In the case of the celebration of contracts remotely referred to in the 4th Ter of these Provisions, the Entities shall consider the Geolocation information of the Device from which the Client carries out the Operation, activity or service with the respective Entity.
The Entities, in the terms that their own Compliance Manual provides for this purpose, will apply to their Clients who have been classified as High Risk Grade, as well as to new Clients who meet such character, identification questionnaires that allow obtaining more information about the origin and destination of resources and the activities and Operations they carry out or intend to carry out.
The questionnaires referred to in the preceding paragraph may be carried out remotely, by digital or electronic means, in order to ensure truthfulness and security in their preparation, which in any case shall contain the consent referred to in the 4th Ter of these Provisions, by the person who signs them.
To determine the Risk Grade in which Clients should be located, as well as whether they should be considered Politically Exposed Persons, each of the Entities will establish in its Compliance Manual the criteria conducive to that end, which take into account, among other aspects, the Client's background, profession, activity or business sector, the origin and destination of their resources, the place of their residence, the methodology referred to in Chapter II Bis of these Provisions and the other circumstances determined by the Entity itself.
22nd.- For cases where, prior to or after the start of the commercial relationship, an Entity detects that the person who intends to be a Client or who already is, as appropriate, meets the requirements to be considered a Politically Exposed Person and, in addition, of High Risk Grade, said Entity shall, in accordance with what it establishes for this purpose in its Compliance Manual, obtain the approval of an executive or equivalent who has specific powers to approve the celebration of such contracts or Operations, as appropriate, in order to start or, if applicable, continue the commercial relationship.
23rd.- Prior to the celebration of contracts or Operations of Clients who, due to their characteristics, could generate a high Risk for the Entity, at least one executive or equivalent who has specific powers to approve the celebration of such contracts, shall grant, in writing, in digital or electronic form, the respective approval. Likewise, for the purposes referred to in fractions IV and V of the 39th of these Provisions, the Entities shall provide in their Compliance Manual the mechanisms so that their respective Compliance Officers have knowledge of those Clients who are classified with a High Risk Grade by the Entities themselves, as well as the procedures that must be carried out to process the approval indicated in this provision.
24th .-. . .
. . .
In the Operations carried out by Clients who have been classified as High Risk Grade, the Entities will adopt measures to know the origin of the resources, and will seek to obtain the data indicated in Chapter II of these Provisions, in the terms that their Compliance Manual provides for this purpose, or in any other document or manual prepared by them, regarding the spouse and economic dependents of the Client, as well as the societies and associations with which they maintain patrimonial links, in the case of natural persons, and, in the case of legal persons, their main shareholders or partners, as appropriate, while in the case of Trusts, they will seek to collect the same data regarding the spouse and economic dependents of the settlors and beneficiaries who are natural persons, as well as the societies and associations with which they maintain patrimonial links and, regarding settlors and beneficiaries who are legal persons, their corporate structure and their main shareholders or partners, in the terms that their Compliance Manual provides for this purpose, or in any other document or manual prepared by them. In the case of foreign Politically Exposed Persons, the Entities shall obtain, in addition to the reference data, the documentation indicated in Chapter II of these Provisions, regarding the natural and legal persons mentioned above in this paragraph.
Without prejudice to the foregoing, in the case of legal person Clients whose titles representing their share capital or securities representing said shares trade on any stock exchange in the country or in foreign securities markets recognized as such in terms of the general provisions applicable to stock exchanges published in the Official Journal of the Federation on May 15, 2017 and their respective modifications, as well as those subsidiaries in which they have a majority participation of fifty percent in their share capital, the Entities will not be obliged to collect the aforementioned identification data, considering that they are subject to provisions in matters of stock exchange on information disclosure.
The Entities, in the terms that their Compliance Manual provides for this purpose, or in any other document or manual prepared by them, shall develop mechanisms to establish the degree of Risk of the Operations they carry out with Politically Exposed Persons of Mexican nationality and, for this purpose, the Entities will determine if the transactional behavior reasonably corresponds to the functions, level and responsibility of said persons, according to the knowledge and information available to said Entities.
25th.- When an Entity has information based on indications or certain facts about the fact that one of its Clients acts on behalf of another person, without having declared it in accordance with what is indicated in the 4th or 4th Ter of these Provisions, said Entity shall request information from the Client in question that allows it to identify the Beneficial Owner of the resources involved in the respective contract or Operation, without prejudice to the duties of confidentiality towards third parties that said Client has assumed by conventional means.
Both in the case provided for in the preceding paragraph of this provision, and in that in which doubts arise in the Entity regarding the truthfulness or authenticity of the data or documents provided by the Client or User for identification purposes, or regarding the transactional behavior of the Client in question, said Entity shall carry out a specific and comprehensive follow-up of the Operations that said Client or User carries out, in accordance with what it establishes for this purpose in its Compliance Manual and, if applicable, submit them to the consideration of the Committee, who shall rule and, in the event that it proceeds, issue the report of Unusual Operation corresponding.
26th.- Without prejudice to what is stated in the 4th of these Provisions, the Entities shall establish in their Compliance Manual, procedures to identify the Beneficial Owners of the resources used by Clients in their contracts, so they shall:
I. to III.
. . .
29th.- For each Unusual Operation detected by an Entity, it shall remit to the Secretariat, through the Commission, the corresponding report, within the three business days following counted from the conclusion of the Committee session that rules it as such. For the purposes of carrying out the aforementioned ruling, the Entity through its Committee, will have a period that will not exceed sixty natural days counted from the moment the alert is generated through its system, model, process or by the employee of the Entity, whichever occurs first.
. . .
30th.-. . .
Each Entity shall provide in its Compliance Manual, or in any other document or manual prepared by the Entity itself, the mechanisms based on which the background and purposes of those Operations that, in accordance with these Provisions, must be presented to the Committee for the purposes of their ruling as Unusual Operations shall be examined. In any case, the results of said examination shall be in writing and available to the Secretariat and to the Commission, for at least ten years counted from the celebration of the Committee session in which such results were presented.
. . .
Likewise, in the process of determining the Unusual Operations referred to in this provision, the Entities shall rely on their Compliance Manual, as well as any other document or manual prepared by the Entity itself and, in addition to this, they will consider the guidelines prepared for this purpose by the Secretariat and by international organizations and intergovernmental groupings in matters of prevention and combat of operations with resources of illicit origin and of financing of terrorism, of which Mexico is a member, which said Secretariat provides them.
33rd.- In the event that an Entity has information based on well-founded suspicions or indications, such as concrete facts from which it is clear that, when attempting to carry out an Operation, the resources could come from illicit activities or could be intended to favor, provide help, assistance or cooperation of any kind for the commission of the crime provided for in article 139 Quater of the Federal Penal Code, or that they could be located in the cases of article 400 Bis of the same legal order, that same Entity, in the event that it decides to accept said Operation, shall remit to the Secretariat, through the Commission, within 24 hours counted from the moment it knows said information, a report of Unusual Operation, in which, in the column of description of the Operation, the legend " 24-hour Report " shall be inserted. Likewise, in those cases where the Entity does not carry out the Operation referred to in this paragraph, it shall present to the Secretariat, through the Commission, the report of Unusual Operation in the terms indicated in this provision regarding said Clients or Users, and will provide, if applicable, all the information it has known about them.
. . .
For the purposes of what is provided in this provision, the Entities shall establish in their Compliance Manual or in any other document or manual prepared by them, those in accordance with which their personnel, once they know the information in question, must make it known immediately to the Compliance Officer of the Entity, so that this fulfills the obligation to send the corresponding report.
. . .
34th.- For each Internal Concerning Operation detected by an Entity, it shall remit to the Secretariat, through the Commission, the corresponding report, within the three business days following counted from the conclusion of the Committee session that rules it as such. For the purposes of carrying out the aforementioned ruling, the Entity through its Committee, will have a period that will not exceed sixty natural days counted from the moment said Entity detects said Operation, through its system, model, process or by any employee of the same, whichever occurs first.
. . .
. . .
35th .-. . .
I.
Submit to the approval of the audit committee of the Entity in question, the Compliance Manual, as well as any modification to it.
. . .
I. Bis. Present to the board of directors or sole administrator of the Entity, as appropriate, the results of the implementation of the methodology elaborated and implemented to carry out the Risk assessment referred to in the previous Chapter II Bis;
II.
Act as the competent instance to know the results obtained by the internal audit area of the Entity or, if applicable, by the independent external auditor referred to in the 52nd of these Provisions, regarding the valuation of the effectiveness of the policies, criteria, measures and procedures contained in the Compliance Manual, in order to adopt the necessary actions tending to correct flaws, deficiencies or omissions.
. . .
III.
Know of those Clients who, due to their characteristics, are classified with a High Risk Grade, according to the reports that the Compliance Officer presents to it for this purpose and, if applicable, formulate the recommendations it deems appropriate;
IV. to X . . . .
XI.
Ensure that the key referred to in the 60th is requested and kept updated in the name of the Compliance Officer or Compliance Officer who is designated as interim, as appropriate, and
XII.
Carry out the other necessary actions for the adequate compliance of its functions and obligations.
Each Entity shall expressly establish in its Compliance Manual, or in any other document or manual prepared by the Entity itself, the mechanisms, processes, deadlines and moments, as the case may be, that must be observed in the performance of the functions indicated in this provision.
36th .-. . .
. . .
. . .
. . .
. . .
Entities that have fewer than twenty-five people on their staff, whether they perform functions for the same directly or indirectly through complementary service companies, will not be obliged to constitute and maintain the Committee referred to in this provision. In the case provided for in this paragraph, the functions and obligations that should correspond to the Committee in accordance with what is indicated in these Provisions, will be exercised by the Compliance Officer, except for that provided in fraction XI of the 35th of these Provisions, which will correspond to the general director or equivalent of the Entity.
39th .-. . .
. . .
. . .
I.
Prepare and submit to the consideration of the Committee the Compliance Manual, which contains the policies of identification and knowledge of the Client and the User, and the criteria, measures and procedures that must be adopted to comply with what is provided in these Provisions;
I. Bis. Submit to the approval of the Committee the methodology designed to carry out the Risk assessment referred to in the previous Chapter II Bis, as well as the results of its implementation;
II. and III . . . .
IV.
Make known to the Committee those Clients who, due to their characteristics, are classified with a High Risk Grade for the Entity itself;
V.
. . .
VI.
Send to the Secretariat, through the Commission, the reports of Operations referred to in the 33rd of these Provisions, as well as those it considers urgent, and inform the Committee of this, in its next session;
VII.
Act as a consultation instance within the Entity regarding the application of these Provisions, as well as of the Compliance Manual;
VIII . . . .
IX.
Receive and verify that the Entity responds, in the terms of the applicable legal provisions, to the requests for information and documentation, as well as to the orders of seizure or unlocking of Operations that, through the Commission, are formulated by the competent authorities in matters of prevention, investigation, prosecution and sanction of conduct that could update the cases provided for in articles 139 Quater or 400 Bis of the Federal Penal Code; likewise, verify that the Entity has appropriate procedures to ensure that it complies with what is provided in the 63rd of these Provisions.
X. Act as a link between the Committee, the Secretariat and the Commission, for matters regarding the application of these Provisions, and
XI . . . .
. . .
. . .
Each Entity shall expressly establish in its Compliance Manual, or in any other document or manual prepared by the Entity itself, the procedures in accordance with which the Compliance Officer will perform the functions and obligations established in this provision and the way in which it will document the compliance with them, if applicable.
40th.- The Entity shall inform the Secretariat, through the Commission, through electronic means and in the official format issued for this purpose by said Secretariat, in accordance with the terms and specifications that the latter indicates, the following:
I. to III. . . .
41st.-. . .
I. The provision of courses, at least once a year, which shall be directed especially to the members of their respective boards of directors or sole administrator, if applicable, executives, members of the Committee, Compliance Officer, as well as officials, employees and proxies, including those who work in customer service or resource administration areas, and which contemplate, among other aspects, those related to the content of the Compliance Manual, which the Entity has developed for the due compliance of these Provisions, as well as on the activities, products and services offered by the Entity.
. . .
II. . . .
Paragraph repealed.
43rd.- Each Entity, as part of its Technological Infrastructure, shall have automated systems that develop, among others, the following functions:
I . . . .
II. Generate and transmit securely to the Secretariat, through the Commission, the information regarding the reports of Relevant Operations, Unusual Operations and Internal Concerning Operations referred to in these Provisions, as well as that which must be communicated to the Secretariat or to the Commission, in the terms and in accordance with the deadlines established in these Provisions.
As an exception to what is stated in this fraction, the Entities may generate manually the report referred to in the 10th Ter of these Provisions;
III. and IV . . . .
V.
Execute the alert system contemplated in the 21st of these Provisions;
V. Bis. Contribute to the detection, follow-up and analysis of possible Unusual Operations and Internal Concerning Operations, considering at least, the information that has been provided by the Client at the start of the commercial relationship, the historical records of the Operations carried out by this, the transactional behavior, the average balances and any other parameter that can provide more elements for the analysis of this type of Operations;
VI. to IX . . . .
IX. Bis.
Provide the information that the Entities will include in the methodology they must elaborate in accordance with what is established in the 17th-1 of these Provisions;
X.
Execute an alert system regarding those operations that are intended to be carried out with persons referred to in fraction X of the 30th of these Provisions, with Politically Exposed Persons, in accordance with what is stated in the 58th of these Provisions, as well as with those who
find themselves within the Blocked Persons List, and
XI.
Facilitate the verification of data and documents provided remotely by the Client.
44th.- The members of the board of directors or sole administrator, as the case may be, those of the Committee, the Compliance Officer, as well as executives, officials, employees, and agents of the Entities, must maintain absolute confidentiality regarding information related to the reports provided for in these Provisions, except when requested by the Secretariat, through the Commission, and other authorities expressly empowered to do so or in the case provided for in Chapter XI Bis of these Provisions.
. . .
45th.- The compliance with the obligation incumbent upon the Entities, the members of the board of directors or sole administrator, as the case may be, of the Committees, Compliance Officers, as well as of the executives, officials, employees, and agents of the Entities, to send to the Secretariat, through the Commission, the reports and information referred to in these Provisions, shall not constitute a violation of restrictions on the disclosure of information imposed by contract or by any legal provision and shall not imply any type of liability.
. . .
46th.- The Entities must provide to the Secretariat, through the Commission, all the information and documentation they request, including that containing images, related to the reports provided for in these Provisions. In the event that the Secretariat, through the Commission, requests an Entity a copy of the identification file of any of its Clients or Users, the latter must send all the data and copy of all the documentation that, in accordance with what is provided in these Provisions, should be part of the respective file. In the case where the Secretariat requests other related information, the Entity must present all the other information and copy of all the documentation that, regarding said Client or User, is in its possession.
. . .
. . .
For the purposes of what is stated in this Provision, the information and documentation required by the Commission must be presented directly in the administrative unit of the same that is designated for such effects, and must be contained in a closed envelope in order to prevent persons outside said unit from having access to the referenced information and documentation.
49th.- The Entities must adopt selection procedures to ensure that their personnel have the technical quality and experience necessary, as well as honorability, to carry out the activities corresponding to them, which must include obtaining a signed declaration by the official or employee in question, in which they will state information regarding any other financial entity or those societies referred to in Article 95 Bis of the General Law of Organizations and Auxiliary Activities of Credit in which they have previously worked, as appropriate, as well as the fact of not having been sentenced for property crimes or disqualified from exercising commerce as a result of non-compliance with legislation or to hold employment, position, or commission in public service, or in the Mexican financial system. To this effect, the aforementioned selection procedures must be included in the Entity's Compliance Manual, or in another document or manual developed by the Entity itself.
. . .
50th.-. . .
When it is impossible for the Entities to apply what is provided in these Provisions in their offices, branches, agencies, and subsidiaries located abroad, the Entities will inform in writing of such situation to the Secretariat, through the Commission, within a period not exceeding twenty business days following the conclusion of the procedures that, for this effect, they have carried out.
. . .
51st.- The Entities are obligated to preserve for a period of no less than ten years, counted from the execution of the Operation carried out by their Clients or Users, the following:
I.
The documentation and information that accredits the Operation in question once it has been concluded.
II.
The data and documents that make up the identification files of their Clients, which must be preserved during the entire validity of the account or contract, and once these conclude, for the period referred to in this provision, from the conclusion of the contractual relationship.
The identification file that the Entities must preserve in terms of this provision must allow identifying the Client, as well as knowing the Operations they carry out with the Entity. Likewise, those data and documents that must be collected from Users, must be preserved for the aforementioned period counted from the date on which the User carries out the Operation in question.
III.
The historical records of the Operations they carry out with their Clients.
IV.
Copy of the reports of Relevant Operations, Unusual Operations, and Concerning Internal Operations referred to in these Provisions, as well as the original or copy or accounting or financial record of all supporting documentation, which must be identified and preserved as such by the Entity itself for the same period.
The records of the reports submitted in accordance with these Provisions, as well as those of the records of the Operations carried out, must allow knowing the manner and terms in which these were carried out, in accordance with the applicable legal provisions.
The preservation provided for in this provision may be carried out by electronic or digital means, which must guarantee the security of the information and documentation collected from the Client or User. For this effect, the Entities will comply with the criteria that, in accordance with the General Law of Organizations and Auxiliary Activities of Credit and these Provisions, are applicable.
52nd.-. . .
. . .
The information referred to in this provision must be preserved by the Entity for a period of no less than five years, and sent to the Commission within sixty calendar days following the closure of the exercise to which the review corresponds, in the electronic media that the latter indicates.
54th.- Each Entity must prepare and send to the Commission, through the electronic media that it indicates, a document in which said Entity develops its respective policies of identification and knowledge of the Client and User, as well as the criteria, measures, and internal procedures that it must adopt to comply with what is provided in these Provisions, and to manage the Risks to which it is exposed in accordance with the results of the implementation of the methodology referred to in Chapter II Bis of these Provisions.
. . .
. . .
. . .
. . .
. . .
. . .
The criteria, measures, procedures, and other information related to the compliance with the present Provisions, which are contained in documents other than those referred to in the paragraph above, must be available to the Commission, for the purposes of what is established in Article 56 of these Provisions.
. . .
. . .
The Commission must, at the request of the Secretariat, send it a copy of the documents referred to in this provision.
55th.- The Commission is empowered to request directly from the Entities or through the association to which, as appropriate, they belong, to make modifications to their Compliance Manuals, as well as to the other documents indicated in these Provisions, when in its judgment it is necessary for the correct application of them.
56th.- The Commission, in exercise of the supervisory powers conferred upon it by the General Law of Organizations and Auxiliary Activities of Credit, and other legal orders, will monitor that the Entities, including, as appropriate, their offices, branches, agencies, and subsidiaries, both in national territory and in the foreign country, comply with the obligations established in these Provisions, in the Manual of Compliance of the Entity itself, as well as in any other document in which criteria are established, measures, and procedures related to the compliance with these Provisions, and will impose the sanctions corresponding to the failure to comply with the aforementioned obligations, in the terms indicated in the applicable legislation and, likewise, may request at any time, the information or documentation necessary for the development of its powers.
57th.- For the purposes of imposing sanctions for non-compliance with what is established in the present Provisions, non-compliance shall be considered those cases in which the Entities present incomplete, illegible, or erroneous information, or when the electronic medium does not comply with the technical specifications indicated by the Secretariat or the Commission, as appropriate.
58th.- The Secretariat, after hearing the opinion of the Commission, will make known to the Entities, in an enumerative manner, the list of public positions that will be considered as Politically Exposed Persons nationally and will make it available to the Entities themselves, through its portal on the world wide web known as the Internet.
. . .
59th.- The Secretariat may interpret, for administrative purposes, the content of the present Provisions, as well as determine the scope of their application, provided that the Entities, associations, or societies in which they are affiliated, and national authorities that for the compliance of their functions so require, request it, for which it will hear the opinion of the Commission.
60th.-. . .
The Entities must ensure that the key referred to in the previous paragraph remains updated in the name of the Compliance Officer or Compliance Officer who is designated as interim, as appropriate.
Likewise, in the case that the Entities referred to in the first paragraph of this provision disappear due to a merger or spin-off, the Commission must be informed, within ten business days following the registration of the act in the Public Registry of Commerce, the data of the Entity that is created or designated to assume the obligation to preserve the information referred to in these Provisions. In the case that the Entity is dissolved, it must be subject to what is provided in the General Law of Commercial Societies, regarding the preservation of the information with which the Entity in question has.
Chapter XII Bis
Novel Models
60th-1.- The Entities that intend to obtain authorization from the competent authority, so that, through Novel Models, carry out any of the Operations referred to in fraction XXIV of Article 2 of the present Provisions must:
I.
Identify and evaluate the Risk to which they are exposed, prior to the launch of the product or service of which it is through Novel Models. The evaluation referred to in this fraction must be carried out in accordance with Chapter II Bis of these Provisions.
II.
Present the result of the evaluation referred to in the previous fraction to the Commission together with its request for authorization.
III.
Comply with these Provisions, according to the cases, forms, terms, deadlines, conditions, and exceptions that the respective authorization indicates from the competent authority, prior opinion of the Secretariat.
61st.-. . .
The Entities must adopt and implement mechanisms that allow identifying the Clients or Users who are within the List of Blocked Persons, as well as any third party who acts on behalf of or for the account of the same, and those Operations that they have carried out, carry out, or that intend to carry out. These mechanisms must be provided for in the Compliance Manual of the Entity itself.
63rd.-. . .
The Entities that, in terms of this provision, have suspended acts, Operations, or services with their Clients or Users, must immediately make their knowledge of such situation known in writing or through digital media, in which it must be informed to said Clients and Users that they may go before the competent authority for the purposes of Article 64 of these Provisions.
TRANSITIONAL PROVISIONS
First.- This Resolution will enter into force the day following its publication in the Official Journal of the Federation.
Second.- The guidelines, interpretations, and criteria issued by the Secretariat or by the Commission, based on what is provided in the Resolution of March 17, 2011, and subsequent Resolutions through which the General Provisions referred to in Article 115 of the Credit Institutions Law in relation to Article 87-D of the General Law of Organizations and Auxiliary Activities of Credit and 95-Bis of this latter legislation, applicable to the multiple-object financial societies, will continue to be applicable insofar as they do not oppose what is established in this Resolution.
Third.- The Entities must comply with the obligations contained in this Resolution, in the terms and in accordance with the deadlines indicated below:
I.
Four months counted from the entry into force of this Resolution to modify the Compliance Manual and present it to the Commission.
II.
Nine months counted from the date of entry into force of this Resolution, to modify the methodology referred to in Chapter II Bis.
III.
Eighteen months counted from the date of entry into force of this Resolution, to update the automated systems referred to in Article 43 of the Provisions.
IV.
Twenty-four months counted from the date of entry into force of this Resolution, to collect the Geolocation of the Device from which the Client or User carries out each Operation, referred to in these Provisions.
Fourth.- The Entities are obligated to send the report referred to in Article 10 Ter of these Provisions, once the Secretariat makes known the guide or guidelines for such effect through the electronic media that it indicates for this effect.
Fifth.- The circumstances for the celebration of non-presidential contracts with Clients who are natural persons of foreign nationality, in accordance with what is established in Article 4 Ter of these Provisions, will enter into force on the date on which the Secretariat issues the corresponding identification mechanisms.
Annex 1
The simplified regime referred to in fraction IV of Article 4 of these provisions, will apply to the following societies, dependencies, and entities:
Financial Technology Institutions.
Controlling Societies of Financial Groups.
Investment Funds.
Investment Societies Specialized in Retirement Funds.
Operating Societies of Investment Funds.
Distributing Societies of Investment Fund Shares.
Credit Institutions.
National Financial Institution for Agricultural, Rural, Forestry, and Fisheries Development.
Brokerage Houses.
Exchange Houses.
Retirement Fund Administrators.
Insurance Institutions.
Mutual Insurance Societies.
Surety Institutions.
General Warehouses.
Savings and Loan Cooperative Societies.
Popular Financial Societies.
Community Financial Societies.
Regulated and Unregulated Multiple-Object Financial Societies.
Credit Unions.
Securities Issuers.
Foreign Financial Entities.
Federal, state, and municipal public dependencies and entities, as well as other Mexican legal persons of public law.
Stock Exchanges.
Securities Depository Institutions.
Societies that administer systems to facilitate operations with securities.
Central Securities Counterparties.
Societies authorized to operate with Novel Models in accordance with Title IV of the Law for Regulating Financial Technology Institutions.
Annex 2
Of remote identification
Article 1.- The Entities, except for regulated multiple-object financial societies that maintain patrimonial links with a credit institution, for the purposes of identifying their Clients or potential Clients who are natural persons of Mexican nationality, in the non-presidential celebration of credit contracts granted to natural persons or natural persons with business activity and who do not have real estate guarantees, for amounts less than the equivalent in national currency to 60,000 Investment Units, may adjust to what is provided by this article; in other contracting scenarios, the aforementioned Entities must observe what is contained in Article 3 below:
I.
Obtain prior approval from the Commission.
For the purposes of this fraction, the Entity must present the approval request through a free-form letter addressed to the Commission, which must resolve in accordance with the deadlines provided in the applicable financial law.
II.
Require the natural person in question to send a form through the electronic medium established by the Entity itself, in which the data referred to in Article 4 Ter of these Provisions must be included, at least.
The aforementioned form must include a statement indicating that its submission to the Entity in question constitutes the consent of the person for their voice and image to be recorded when establishing a communication through an audiovisual medium and in real time between them.
Together with the form, the Entities must require the applicant to send a color photograph of their valid voter credential issued by the National Electoral Institute, by the front and back. The Entities must require that the applicant takes a color photograph of their face, using devices with cameras of resolution of, at least, 4 mega pixels, color images of 24 bits, whose taking is only carried out online through the Entity's own technological tool to be sent in that same act.
Additionally, the Entities must require that the natural person sends in digital format the documents necessary to integrate and preserve their identification file in terms of what is provided by Article 4 Ter of these Provisions.
III.
Once the duly filled form is received, they must verify if the applicant is a Client of the Entity and, in this case, verify the data of the form with the records of the Entity itself.
In addition to the above, the Entities must confirm the existence of the Unique Population Registry Key with the National Population Registry, as well as that the data of this and the provided in the form coincide with each other.
Likewise, they must compare the photographs of the voter credential and the face, in order to make the facial biometric recognition between them, ensuring that both coincide in accordance with the level of reliability established in fraction IV of Article 4 of this Annex and, validate the elements of security of the received voter credential, in order to detect if said document presents alterations or inconsistencies, for which they must have the necessary technology for this.
Additionally, the Entities must verify the coincidence of the data of the voter credential issued by the National Electoral Institute listed below, with the records of the Institute itself:
a)
The Credential Identifier Code (CIC), which is printed on the voter credential
b)
Year of registration.
c)
Voter key.
d)
Number and year of issuance.
The Entities must verify that the paternal surnames, maternal surnames, and name or names, as they appear on the presented voter credential, coincide with the records of the National Electoral Institute or the National Population Registry.
IV.
They must inform the applicant of the procedure that will be followed in the development of the real-time communication, what are the accesses to the media for its realization, as well as deliver a one-time use code, which will be required from the applicant at the beginning of the communication.
V.
The communication must be carried out in accordance with the dialogue guides established by the Entities, and will be recorded and preserved without edits for its entire duration. Additionally, the Entities must observe the following:
a)
Register the time and date of the realization of the communication.
b)
Verify that the quality of the image and sound allow the full identification of the applicant, according to the parameters that the Entities themselves establish for this effect.
c)
Corroborate, during the communication with the applicant, the information that he has sent in the form and require him to show the other documentation that was sent together with this.
In the case that the applicant is already a Client of the Entity, they must authenticate him using an authentication factor, understanding by this, the information obtained through the application of questionnaires to the Client, by remote operators, in which data are required that the Client knows. In no case can the forms be composed solely of data that have been included in printed or electronic communications sent by the Institutions to their Clients.
The Entities, in the use of forms to verify the identity of their Clients, must observe the following:
Define in advance the questionnaires that will be practiced by remote operators, preventing them from being used in a discretionary manner.
Validate at least one of the answers provided by their Clients, through computer tools, without the operator being able to consult or know in advance the Client's authentication data.
d)
Require the applicant to show their voter credential issued by the National Electoral Institute, both on the front and back side, confirming that it contains the same data and photograph of the credential that they sent along with the form.
e)
Take images of the applicant and of the presented voter credential, by the front and back side, in which the date and time in which they were taken will be stamped, obtained from a protected time server.
f)
Use specialized technology that allows them to achieve a reliable identification of the interviewee, with the level of reliability established in fraction IV of Article 4 of this Annex,
ensuring that there is a match between their face, the photograph of said interviewee, and that of the voter credential previously received. The foregoing will be a condition to proceed to the formalization stage of the credit contract.
g)
Identify suspicious behavior patterns that might indicate that the person being interviewed is not who they claim to be.
VI.
The Entities shall suspend the contracting process with the applicant when any of the following cases occur:
a)
The image or sound quality does not allow for full identification of the applicant.
b)
The applicant does not present their voter credential; the data obtained from it does not match the records of the National Electoral Institute, or the result of the validation of the elements of the aforementioned voter credential, or of the biometric verifications of the applicant's face, does not reach the effectiveness or level of reliability referred to in Article 4, fractions III and IV of this Annex.
c)
The Unique Population Registry Key does not match the information in the National Population Registry.
d)
The one-time code required from the applicant is not confirmed by them.
e)
The Entity's personnel involved in the online communication identify an atypical or risky situation, or have doubts about the authenticity of the voter credential or the identity of the applicant.
f)
Interruptions occur in the connection.
To determine the amount indicated in the first paragraph of this article, the value of the Investment Unit on the date of celebration of the contract must be used, considering its equivalence in national currency published by the Bank of Mexico in the Official Gazette of the Federation.
The technology used for these procedures must be approved by the risk officer or their equivalent, or, in the absence thereof, by the audit committee, board of directors, or sole administrator of the Entity.
Regulated multiple-object financial societies must provide in the contracts they enter into with their Clients that when they decide to omit requesting the authentication factor during the online communication referred to in this article and the Clients do not recognize the credit contracts referred to in this article with the described procedure, these entities will assume the risks and, therefore, the costs of the credits, making the corresponding clarifications to the credit information societies, as well as the cancellation of the credit in question, when so requested by the Client.
Article 2.- The Entities referred to in the previous article must have the necessary means for the transmission and safeguarding of the information, data, and files generated in the procedures referred to in Article 1 of this Annex, which guarantee their integrity, the correct reading of the data, the impossibility of manipulation, as well as their adequate conservation and location.
The Entities referred to in the previous article may use technological improvements that help compensate for the clarity of the images, approved by their risk officer or their equivalent, in the absence thereof, by the audit committee, board of directors, or sole administrator, for such purposes, when identification documents are shown and facial recognition of the applicant is performed.
Article 3.- The Commission may approve non-presential identification mechanisms for potential clients other than those indicated in Article 1 of this Annex, provided that the Entities referred to in said article demonstrate that the technology used, in the judgment of the Commission itself, is reliable for identifying the natural person in question and that the existence of the Unique Population Registry Key is verified with the National Population Registry or some other verifiable identification element against the records of some Mexican authority, as well as the correspondence of the data.
Article 4.- The Entities, when requesting the approvals referred to in Article 1 and, where applicable, Article 3, must present the following:
I.
The detailed description of the process, which must be approved by the risk officer or their equivalent, or, in the absence thereof, by the audit committee, board of directors, or sole administrator, as well as the Technological Infrastructure employed in each part of it.
II.
Regarding identification mechanisms referred to in Article 3, the method of validation of the identification documents that will be admitted to carry out the contracting in question.
III.
Evidence that the means of verifying the validity of the identification documents of Clients or potential Clients have the effectiveness approved by the risk officer or their equivalent, or, in the absence thereof, by the audit committee, board of directors, or sole administrator of the Entities.
IV.
Evidence that the facial identification recognitions used have the level of reliability determined by the risk officer or their equivalent, or, in the absence thereof, by the audit committee, board of directors, or sole administrator of the Entity.
V.
The image and sound quality standards that will be required to carry out the online communication.
VI.
Where applicable, the description of the authentication factors that will be required from the Client.
VII.
The mechanisms through which compliance with what is provided in Article 2 of this Annex will be ensured.
When Entities intend to modify the procedures described in Article 1 and, where applicable, Article 3 of this Annex, they will require prior approval from the Commission.
Mexico City, March 11, 2019. - The Secretary of Finance and Public Credit, Carlos Manuel Urzúa Macías. - Signature.
In the document you are viewing, there may be text, characters, or objects that do not display correctly due to conversion to HTML format, so we recommend always taking the digitized image of the DOF or the PDF file of the edition as a reference. The content, form, and scope of published documents are the strict responsibility of their issuer.
CONSULT
BY DATE
Do Mo Tu We Th Fr Sa
INDICATORS
Exchange Rate and Rates as of 08/28/2026
DOLLAR 16.9712 UDIS 8.808812 TIIE 28 DAYS 6.7559% TIIE 91 DAYS 6.7931% TIIE 182 DAYS 6.8474% TIIE DE FONDEO 6.50%
See more
SURVEYS
Did you like the new look of the Official Gazette of the Federation website?
No Yes
Official Gazette of the Federation
Río Amazonas No. 62, Col. Cuauhtémoc, C.P. 06500, Mexico City Tel. (55) 5093-3200, where you can access our menu of services
Electronic address: dof.gob.mx
113
LEGAL NOTICE | SOME RIGHTS RESERVED © 2026