2019-03-20 | DOF 5554686

Added

Resolution reforming, adding, and repealing various General Provisions under Article 124 of the Popular Savings and Credit Law

The Secretariat of Finance and Public Credit amends the General Provisions for popular financial societies, community financial societies, and rural financial integration organisms to align with Financial Action Task Force (FATF) recommendations. The resolution prohibits simplified identification measures when money laundering or terrorist financing is suspected, mandates enhanced due diligence for politically exposed persons, and requires precise identification of originators and beneficiaries in electronic fund transfers regardless of amount. It also introduces obligations for entities to evaluate risks associated with new financial technologies, permits the use of electronic means for customer due diligence, and removes the requirement to submit training reports.

Secretaria de Hacienda y Credito Publico logo

Mexico

Secretaria de Hacienda y Credito Publico

Click to view thumbnail

DOF: 20/03/2019

RESOLUTION that reforms, adds, and repeals various of the General Provisions referred to in Article 124 of the Popular Savings and Credit Law

A seal with the National Coat of Arms, which reads: United Mexican States.- SHCP.- Secretariat of Finance and Public Credit.

RESOLUTION THAT REFORMS, ADDS, AND REPEALS VARIOUS OF THE GENERAL PROVISIONS REFERRED TO IN ARTICLE 124 OF THE POPULAR SAVINGS AND CREDIT LAW.

CARLOS MANUEL URZÚA MACÍAS, Secretary of Finance and Public Credit, based on the provisions of articles 31, fractions VIII and XXXIV, of the Organic Law of the Federal Public Administration; 46 Bis first paragraph and 124 of the Popular Savings and Credit Law, in exercise of the powers conferred upon me by article 6º, fraction XXXIV, of the Internal Regulations of the Secretariat of Finance and Public Credit, and having received the prior opinion of the National Banking and Securities Commission issued via letter number DGPORPIA/73865/2019 and 213-2/78633/5/2019 dated February 25, 2019; and

CONSIDERING

That during the 2016-2017 period, Mexico was evaluated within the framework of the Fourth Round of Mutual Evaluation of the Financial Action Task Force (FATF), in order to examine its level of compliance with international standards in matters of prevention of money laundering and financing of terrorism;

That as a result of the above, on January 3, 2018, the FATF published the "Mutual Evaluation Report" through which said intergovernmental body made various recommendations to Mexico in order to strengthen its regime for the prevention of money laundering and financing of terrorism;

That therefore, the Secretariat of Finance and Public Credit has considered making various modifications to the general provisions that establish the minimum criteria and procedures in matters of prevention of money laundering and financing of terrorism for the sector of popular financial societies, this with the objective of addressing the FATF recommendations and strengthening the regime in this matter;

That, in addition to the reform carried out on April 4, 2017 to the general provisions in matters of prevention of money laundering and financing of terrorism applicable to popular financial societies, community financial societies, with operation levels I to IV, and rural financial integration organisms, to help improve compliance with FATF Recommendations 1 and 10, it is specified in the legal framework the prohibition for popular financial societies, community financial societies, with operation levels I to IV, and rural financial integration organisms to carry out simplified identification measures for their clients or users when they suspect that the resources, assets, or values that said clients or users intend to use to carry out an operation, could be related to money laundering or financing of terrorism;

That, likewise, in compliance with FATF Recommendation 10, it is necessary to strengthen the legal framework regarding the identification and customer due diligence policy of popular financial societies, establishing the circumstances under which the identification process may be suspended, in order to prevent the commission of crimes of money laundering and financing of terrorism, among others; and, if applicable, to report the respective unusual operation report to the competent authority;

That to better address FATF Recommendation 12, it is convenient to establish that popular financial societies, community financial societies, with operation levels I to IV, and rural financial integration organisms determine whether the beneficial owners of their clients or users have the status of politically exposed persons, whether national or foreign, in accordance with applicable provisions, to be able to apply the appropriate customer due diligence measures;

That in accordance with FATF Recommendation 16, related to electronic fund transfers, in consideration of the modifications foreseen for the standardized message formats most used by financial entities in the international market for such operations, it is necessary to strengthen the client or user identification policy of popular financial societies, community financial societies, with operation levels I to IV, and rural financial integration organisms, in order to know with greater precision the information of the originator and beneficiary of the transfer in question to detect, and if applicable, prevent, the commission of crimes of operations with resources of illicit origin and financing of terrorism, for which reason, it is necessary that popular financial societies, community financial societies, with operation levels I to IV, and rural financial integration organisms identify, regardless of the amount of the operation, the clients or users who request to send the respective transfers, as well as the beneficiaries thereof, particularly when issuing the respective transfer orders or, in the case of international transfer orders received, the orderers thereof, and, as in other cases, maintain such information within the timeframes in which they are obligated and at the disposal of the competent authority, in addition to obliging said entities to establish criteria in their respective manuals that allow them to strengthen, with a risk-based approach, their regime for the prevention of money laundering and financing of terrorism on this matter;

That, on the other hand, given that popular financial societies, community financial societies, with operation levels I to IV, and rural financial integration organisms can provide financial services through new technologies, which have been recognized by the Mexican Government with the issuance of the Law to Regulate Financial Technology Institutions and its secondary provisions, in compliance with FATF Recommendation 15 and what is stated in the Report of January 3, 2018, it is necessary for these to evaluate the risk of providing financial services through said technologies, so it is convenient to establish such an obligation, prior to their implementation and development, as well as for their monitoring;

That, even though currently popular financial societies, community financial societies, with operation levels I to IV, and rural financial integration organisms comply with the obligation of customer due diligence in a presencial and traditional manner, with some exceptions recognized in the regulation, in the face of the existence of the digital era, new technologies, and electronic media, in the integration, conservation, maintenance, verification, etc., of data, information, and documents, it is necessary, as with other regulated participants in the matter, to recognize the legal possibility that popular financial societies, community financial societies, with operation levels I to IV, and rural financial integration organisms can comply with their obligations in matters of prevention of money laundering and financing of terrorism through said electronic media, of course with the responsibility of complying with the applicable regulations to the effect that they have the value that corresponds in law;

That, with the purpose of prioritizing efforts and resources in the new obligations established in this resolution, it is estimated convenient to eliminate the obligation for popular financial societies, community financial societies, with operation levels I to IV, and rural financial integration organisms to send the training report, without this implying that they should not have such training;

And after hearing the opinion of the National Banking and Securities Commission, I have deemed it appropriate to issue the following:

RESOLUTION THAT REFORMS, ADDS, AND REPEALS VARIOUS OF THE GENERAL PROVISIONS REFERRED TO IN ARTICLE 124 OF THE POPULAR SAVINGS AND CREDIT LAW

SINGLE ARTICLE.- The 2nd, fractions I to XXVIII; 3rd, third paragraph; 4th, first paragraph, fractions I to IX, third, fifth, seventh, and last paragraphs; 7th, first, third, and fourth paragraphs; 9th, first paragraph fractions I, II, subsection a); 10th; 11th, second paragraph; 12th; 14th, first, second, and third paragraphs; 15th, first, second, and third paragraphs; 17th; 23rd, first, second, and last paragraphs; 23-1st; 23-2nd; 23-3rd; 23-4th; 23-5th; becoming 23-6th; 24th, second paragraph; 26th, first paragraph; 27th, seventh paragraph; 28th; 29th; 30th, third, fourth, and last paragraphs; 31st, second paragraph, fraction II, subsection b); 33rd, first and last paragraphs; 34th, first paragraph; 41st, second and last paragraphs; 44th, first and third paragraphs; 46th, fractions I, I Bis, III, IX, X, and last paragraph; 47th, last paragraph; 50th, third paragraph fractions I, I Bis, IV, VII, and last paragraph; 52nd, fraction I, first paragraph; 54th, first paragraph, fractions II, first paragraph, V, IX Bis, and X; 60th, first paragraph; 61st, first, second, and third paragraphs; 64th, fractions II and III; 68th, 69th; 73rd, second paragraph; 75th, second paragraph; Annex 1; are REFORMED; the 2nd, fractions XXIX to XXXIX, renumbering the rest in order; 4th, second paragraph, renumbering the rest in order; 4th Bis; 7th, second paragraph, renumbering the rest in order; 10th Bis; 10th Ter; 17th Bis; 18th, fractions IV and V, second and third paragraphs, renumbering in order; 18th Bis; 23rd, third paragraph, renumbering the rest in order; 23-1st, second paragraph, renumbering the rest in order; 23-4th, first and second paragraphs; 23-5th, renumbering the following in order; 26th, second paragraph; 27th, fourth and eighth paragraphs, renumbering the rest in order; 31st, third and last paragraphs; 46th, fraction XI; 54th, fractions II, second paragraph V Bis and XI; 64th, last paragraph; 72-1st, last paragraph; a Chapter XV Bis titled "Novel Models"; 72-2nd; an Annex 2 are ADDED; and the 2nd, fractions XIII Bis and XVI Bis; 23-3rd, last paragraph; 52nd, last paragraph, all of them of the General Provisions referred to in Article 124 of the Popular Savings and Credit Law, are REPEALED, to remain as follows:

2nd.- . . .

I. Archive or Registry, the set of data and documents that are conserved or stored in printed format or in electronic, optical, or any other technology media, provided that, in these latter media, it is ensured that the information has remained intact and unaltered from the moment it was generated for the first time in its definitive form and is accessible for subsequent consultation, having as its purpose to integrate, conserve, and evidence the Operations of the Entities;

II. Beneficiary, . . .

III. Client, . . .

Natural persons who prove to the Entities subject to the tax regime applicable to natural persons with business activity under the terms of sections I and II of Chapter II of Title IV of the Income Tax Law, shall be considered as legal entities for the purposes of what is established in these Provisions, except for what refers to the integration of their file, which must be integrated in terms of what is established in fraction I of the 4th and, when applicable, the 4th Bis, 14th, 15th, and 16th of these Provisions, and in which the Entities must additionally require the Federal Taxpayer Registry key (with homoclave) and, if applicable, tax identification number and/or equivalent of said natural persons, as well as the country or countries that assigned them;

IV. Commission, . . .

V. Committee, . . .

VI. Supervision Committee, . . .

VII. Control, . . .

VIII. Concentrating Account, . . .

IX. Recipient, . . .

X. Device, the equipment that allows access to the worldwide network called Internet, which can be used to carry out account openings or celebrate contracts, as well as to carry out Operations;

XI. Entities, . . .

XII. Foreign Financial Entity, . . .

XIII. Federation, . . .

XIII. Bis.- Repealed.

XIV. Trust, . . .

XV.

Electronic Signature, the characteristics or data in electronic form recorded in a Data Message, or attached or logically associated with it by any technology, which are used to identify the subscriber or originator of the instruction of some Operation or financial service and indicate that the signer approves the information contained in the Data Message, and which produces the same legal effects as the handwritten signature;

XVI. Advanced Electronic Signature, . . .

XVI Bis.- Repealed.

XVII.

Geolocation, the geographic coordinates of latitude and longitude where the Device is located;

XVIII. Risk Level, . . .

XIX. Technological Infrastructure, the computer equipment, data processing and communications installations, equipment and communications networks, operating systems, databases, applications, and systems that Entities use to support their operations;

XX. Monetary Instrument, . . .

XXI. Law, . . .

XXII.

List of Blocked Persons . . .

XXIII. Compliance Manual, the document referred to in the 67th of these Provisions.

XXIV. Data Message, the information generated, sent, received, or archived by electronic, optical, or any other technology means, in accordance with the Commerce Code;

XXV. Mitigants, . . .

XXVI. Novel Model, that which for the provision of financial services uses tools or technological means with modalities different from those existing in the market at the time the temporary authorization referred to in the Law to Regulate Financial Technology Institutions is granted;

XXVII. Compliance Officer, . . .

XXVIII. Operations, . . .

XXIX.

Unusual Operation, . . .

XXX.

Concerning Internal Operation, . . .

XXXI.

Relevant Operation, . . .

XXXII. Politically Exposed Person, . . .

XXXIII.

Beneficial Owner, . . .

XXXIV. Resource Provider, . . .

XXXV. Risk, . . .

XXXVI. Secretariat, . . .

XXXVII. Obligated Subjects, the Entities, as well as persons, institutions, entities, or societies subject to the obligations referred to in articles 115 of the Credit Institutions Law, 108 Bis of the Savings for Retirement Systems Law, 91 of the Investment Funds Law, 212 and 226 Bis of the Securities Market Law, 492 of the Insurance and Surety Institutions Law, 129 of the Credit Unions Law, 71 and 72 of the Law to Regulate the Activities of Savings and Loan Cooperative Societies, 60 of the Organic Law of the National Development Bank for Agriculture, Rural, Forestry, and Fisheries, 95 and 95 Bis of the General Law of Organizations and Auxiliary Credit Activities, excluding exchange centers, and 58 of the Law to Regulate Financial Technology Institutions;

XXXVIII. Terms and Conditions, the legal bases and statements that Entities establish with their Clients through computer applications, interfaces, Internet pages, or any other electronic or digital communication medium in a format established by the Entity itself for the celebration of Operations, activities, or services with them, and

XXXIX. User, . . .

3rd.- . . .

. . .

The policy and guidelines mentioned above must form an integral part of the Entity's Compliance Manual.

4th.- Entities must integrate and conserve an identification file for each of their Clients, prior to these carrying out contributions to their social capital in person, the opening of an account, or the celebration of a contract to carry out Operations of any type.

To integrate the identification files of Clients, they must comply, at least with the following:

I.

In the case of Clients who are natural persons and who declare to the Entity to be of Mexican nationality or of foreign nationality under conditions of temporary resident or permanent resident status under the terms of the Migration Law, or in the capacity of diplomatic and consular representations under the terms of the Guidelines for the issuance of non-ordinary visas:

a)

The following identification data:

i.

Paternal surname, maternal surname, and name or names without abbreviations.

ii.

Gender.

iii.

Date of birth.

iv.

State of birth, when applicable.

v.

Country of birth.

vi.

Nationality.

vii.

Occupation, profession, activity, or business sector to which the Client is dedicated.

viii.

Private address at their place of residence (composed of the name of the street, avenue, or road in question, duly specified; exterior number and, if applicable, interior number; neighborhood or urbanization; borough, municipality, or similar political demarcation that corresponds, if applicable; city or population, state, province, department, or similar political demarcation that corresponds, if applicable; postal code, and country).

ix.

Phone number(s) where they can be located.

x.

Email address, if applicable.

xi.

Unique Population Registry Key, Federal Taxpayer Registry key (with homoclave), tax identification number and/or equivalent, as well as the country or countries that assigned them, when available.

xii.

Serial number of the Advanced Electronic Signature, when they have one.

In addition to the above, in the case of persons who have their place of residence abroad and, at the same time, have an address in national territory where they can receive correspondence addressed to them, the Entity must record in the file the data relating to said address, with the same elements contemplated in this fraction.

b)

Simple copy of the following documents:

i.

Personal identification, which must be, in all cases, an original official document issued by a competent authority, valid on the date of its presentation, containing the photograph, signature, and, if applicable, address of the Client.

For the purposes of what is provided in this subsection, the following documents issued by Mexican authorities shall be considered valid personal identification documents: the voter credential, the passport, the professional card, the national military service card, the consular enrollment certificate, the military identity card, the card of affiliation to the National Institute of Older Adults, the credentials and cards issued by the Mexican Social Security Institute, by the Institute of Social Security and Social Services for State Workers, by the Institute of Social Security for the Mexican Armed Forces, or by Popular Insurance, the driver's license, the credentials issued by federal, state, and municipal authorities, and the other national identifications that, if applicable, the Commission approves. Likewise, regarding natural persons of foreign nationality referred to in this fraction, in addition to those previously mentioned in this paragraph, the passport or passport card, or the documentation issued by the National Institute of Migration that accredits their migratory status, as well as the accreditation card issued by the Secretariat of Foreign Relations to diplomatic or consular bodies, shall be considered valid personal identification documents.

ii.

Certificate of the Unique Population Registry Key, issued by the Secretariat of the Interior, a document in which the assignment of the tax identification number and/or equivalent issued by a competent authority, as well as the Advanced Electronic Signature, if they have one, is recorded. It will not be necessary to present the certificate of the Unique Population Registry Key if it appears in another document or official identification.

Entities will not be obligated to collect, include, and conserve in the Client's corresponding identification file, a simple copy of the documents referred to in the previous paragraph, provided that the Entities integrate into the same the evidence in which it is recorded that the documents and/or the Client's data were presented and/or validated before the corresponding authority.

iii.

Proof of address, which may be any receipt for payment for home services such as, among others, electricity supply, telephone, natural gas, property tax, or water supply rights or bank statements, all of them with an age not greater than three months from their date of issuance, or the lease contract valid on the date of presentation by the Client, certificate of residence issued by municipal authority, the proof of registration before the Federal Taxpayer Registry, as well as the others that, if applicable, the Commission approves.

Notwithstanding the above, when the address stated in the contract celebrated by the Client with the Entity coincides with that of the Client's voter credential issued by a Mexican authority, in case they have been identified with the same, this will function as the proof of address referred to in the previous paragraph.

iv.

Declaration of the natural person, which may be granted in writing, by electronic, optical, or any other technology means that may be included in the account opening application documentation or the celebration of Operation or in the respective contract, in which it is recorded that said person acts for these purposes in their own name and on their own behalf or on behalf of a third party, as the case may be.

In the event that the natural person declares to the Entity that they act on behalf of a third party, said Entity must observe what is provided in fraction VI of this Provision regarding the Beneficial Owner of the resources involved in the corresponding account or contract.

v.

In the case where the natural person acts as an agent for another person, the respective Entity must collect and integrate into the identification file of the Client in question, a simple copy of the power of attorney or of the certified copy of the document issued by a public notary, as applicable, under the terms established in common legislation, which accredits the powers conferred upon the agent, as well as an official identification and proof of address of the agent, which meet the requirements indicated in this fraction I regarding said documents, independent of the data and documents relating to the principal.

II.

Regarding Clients who are legal entities of Mexican nationality:

a)

The following identification data:

i.

Name or trade name.

ii.

Commercial activity, activity, or corporate object.


iii.

Nationality.

iv.

Taxpayer Registry Key (with homoclave) and, where applicable, tax identification number and/or equivalent, as well as the country or countries that assigned them.

v.

Serial number of the Advanced Electronic Signature.

vi.

Address (composed of the name of the street, avenue, or thoroughfare in question, duly specified; exterior number and, where applicable, interior; neighborhood; borough or municipality or similar political demarcation that corresponds, where applicable, city or town; federal entity and postal code).

vii.

Telephone number(s) of said address.

viii.

Email address, where applicable.

ix.

Date of incorporation.

x.

Full first and last names, without abbreviations, of the administrator or administrators, director, general manager, or legal representative who, with their signature, can bind the legal entity for the purposes of opening an account, concluding a contract, or carrying out the Operation in question, derived from a valid, current official personal identification document issued by a competent authority, in accordance with what is provided in subsection b), item i., fraction I of this Provision.

b)

Simple copy of the following documents:

i.

Notarized copy or certified copy of the public instrument that certifies its legal existence, registered in the public registry corresponding to the nature of the legal entity, or of any instrument in which the data of its incorporation and its registration in said registry appear, or else, the document that, in accordance with the regime applicable to the legal entity in question, credibly certifies its existence.

In the event that the legal entity is of recent incorporation and, for this reason, is not yet registered in the public registry corresponding to its nature, the Entity in question must obtain a written document signed by a person legally authorized to certify its personality in terms of the public instrument that certifies its legal existence referred to in subsection b) item iv., of this fraction, in which the obligation to carry out the respective registration and to provide, in due course, the corresponding data to the Entity itself is stated.

ii.

Tax Identification Card issued by the Secretariat and, where applicable, the document in which the assignment of the tax identification number and/or equivalent issued by a competent authority appears, and certificate of the Advanced Electronic Signature.

iii.

Proof of address referred to in subsection a) of this fraction II, in terms of what is stated in subsection b) item iii., of the previous fraction I.

iv.

Notarized copy or certified copy of the instrument containing the powers of the representative or legal representatives, issued by a public notary, when not contained in the public instrument that certifies the legal existence of the legal entity in question, as well as the personal identification of each of said representatives, in accordance with subsection b), item i., of the previous fraction I.

In the case of federal, state, and municipal public dependencies and entities, as well as other Mexican legal entities of public law, to certify their legal existence as well as to prove the powers of their legal representatives and/or proxies, the provisions of the laws, regulations, decrees, or organic statutes that create and regulate their incorporation and operation shall apply, and where applicable, a copy of their appointment or public instrument issued by a notary, as appropriate.

c)

Client information that allows the Entity to know:

i.

Shareholder structure or social parts, as appropriate.

ii.

In the event that it has a Risk Grade other than low, its internal corporate structure; that is, the organizational chart of the legal entity Client, considering at least the full name and position of those individuals who hold positions between general director and the immediate lower hierarchy, as well as the full name and corresponding position of the members of its board of directors or equivalent.

Likewise, Entities must identify the Beneficial Owners of their legal entity Clients who exercise Control over them in terms of the second paragraph of fraction VII of the 2nd of these Provisions, in accordance with what is established in fraction VI of this Provision.

. . .

When the designated administrator is a legal entity or Trust, it shall be understood that Control is exercised by the natural person appointed as administrator by said legal entity or Trust.

For the purposes of this subsection, Entities must obtain a written declaration, by electronic, optical, or any other technology means, from the legal representative of the legal entity Client in question, in which it is indicated who their Beneficial Owners are in terms of this subsection.

In the event that Entities have indications that make the truthfulness of the declared information questionable, they must take reasonable measures to determine and identify the Beneficial Owners of the corresponding legal entity Client.

III.

In the case of Clients who are persons of foreign nationality, the Entity in question must observe the following:

a)

For the case of the natural person who declares to the Entity that they do not have the status of temporary resident or permanent resident in terms of the Migration Law, or in the capacity of diplomatic and consular representations in terms of the Guidelines for the issuance of non-ordinary visas:

i.

The respective identification file must contain the same data as those indicated in subsection a) of the previous fraction I, with the exception of the data of the federal entity of birth.

ii.

Collect and include in said file a simple copy of the following documents:

ii.1.

Passport or passport card and official document issued by the National Institute of Migration, when the latter is available, which certifies their entry or legal stay in the country or, the accreditation card issued by the Secretariat of Foreign Relations to diplomatic and consular bodies.

ii.2.

Document that certifies the Client's address at their place of residence, in terms of subsection b) item iii., of fraction I of this Provision.

ii.3.

Declaration in terms of subsection b), item iv., of fraction I of this Provision.

b)

For the case of foreign legal entities:

i.

The respective identification file must contain the following data recorded:

i.1.

Trade name or corporate name.

i.2.

Commercial activity, activity, or corporate purpose.

i.3.

Nationality.

i.4.

Taxpayer Registry Key (with homoclave) and/or tax identification number and/or equivalent, the country or countries that assigned them, and, where applicable, the serial number of the Advanced Electronic Signature.

i.5.

Address (composed of the name of the street, avenue, or thoroughfare in question, duly specified; exterior number and, where applicable, interior; neighborhood or urbanization; borough, municipality, or similar political demarcation that corresponds, where applicable; city or town, federal entity, state, province, department, or similar political demarcation that corresponds, where applicable; postal code and country).

i.6.

Telephone number(s) of said address.

i.7.

Email address, where applicable.

i.8.

Date of incorporation.

ii.

Collect and include in said file a simple copy of, at least, the following documents:

ii.1.

Document that credibly certifies their legal existence, document in which the assignment of the tax identification number and/or equivalent issued by a competent authority appears, as well as obtain the information and collect the data referred to in subsection c) of fraction II of this Provision.

The Entity must require that the document referred to in the previous paragraph be duly legalized or, in the event that the country where said document was issued is a party to the "Convention Abolishing the Requirement of Legalization for Foreign Public Documents," adopted in The Hague, Netherlands, on October 5, 1961, it will suffice that said document bear the apostille referred to by said Convention.

In the event that the respective Client does not present the document duly legalized or apostilled, it shall be the responsibility of the Entity to ensure the authenticity of said documentation.

ii.2.

Proof of address referred to in subsection b) above, in terms of what is stated in subsection b), item iii., of fraction I of this Provision.

ii.3.

Notarized copy or certified copy of the instrument containing the powers of the representative or legal representatives, issued by a public notary, when not contained in the document that credibly certifies the legal existence of the legal entity in question, as well as the personal identification of said representatives, in accordance with subsection b), item i., of fraction I or subsection a) of this fraction III, as appropriate.

In the case of those legal representatives who are outside the national territory and who do not have a passport or passport card, the personal identification must, in any case, be an original official document issued by a competent authority of the country of origin, valid on the date of its presentation, containing the photograph, signature, and, where applicable, address of the said representative.

For the purposes of the foregoing, driver's licenses and credentials issued by federal authorities or equivalents of the country in question shall be considered valid personal identification documents. The verification of the authenticity of said documents shall be the responsibility of the Entities.

IV.

In the case of the societies, dependencies, and entities referred to in Annex 1 of these Provisions:

a)

The following identification data:

i.

Trade name or corporate name.

ii.

Activity or corporate purpose.

iii.

Taxpayer Registry (with homoclave) and, where applicable, tax identification number and/or equivalent, as well as the country or countries that assigned them.

iv.

Serial number of the Advanced Electronic Signature, when they have it.

v.

Address (composed of the name of the street, exterior number and, where applicable, interior, neighborhood, city or town, borough or municipality, federal entity, and postal code).

vi.

Nationality.

vii.

Telephone number(s) of said address.

viii.

Email address, where applicable.

ix.

Full name without abbreviations of the administrator or administrators, director, general manager, or legal representative who, with their signature, can bind the society, dependency, or entity for the purposes of concluding the Operation in question.

b)

Simple copy of the following documents:

i.

Notarized copy or certified copy of the instrument containing the powers of the representative or legal representatives, issued by a public notary.

In the case of the representative of an Entity or brokerage house, the certification of appointment issued by a competent official in terms of article 90 of the Law or 129 of the Securities Market Law, as appropriate.

To certify the powers of the representatives of federal, state, and municipal public dependencies and entities, as well as other Mexican legal entities of public law, the provisions of the last paragraph of subsection b) of fraction II, of this Provision, shall apply.

ii.

Personal identification of such representatives, in accordance with subsection b), item i., of the previous fraction I.

Entities may apply the simplified measures referred to in this fraction, provided that said societies, dependencies, and entities have been classified as Clients with a Low Risk Grade in terms of the 27th of these Provisions.

V.

In the case of Resource Providers, the following data:

a)

In the case of natural persons:

i.

Paternal surname, maternal surname, and first name or names without abbreviations.

ii.

Date of birth.

iii.

Nationality.

iv.

Home address (composed of the name of the street, avenue, or thoroughfare in question, duly specified, exterior number and, where applicable, interior, neighborhood, city or town, borough or municipality, federal entity, and postal code).

v.

Taxpayer Registry Key (with homoclave), tax identification number and/or equivalent, the country or countries that assigned them, Unique Key of the Population Registry, as well as the serial number of the Advanced Electronic Signature, when they have them.

vi.

Occupation, profession, activity, or business sector to which the Resource Provider is dedicated.

b)

In the case of legal entities:

i.

Trade name or corporate name.

ii.

Nationality.

iii.

Taxpayer Registry Key (with homoclave) and, where applicable, tax identification number and/or equivalent, as well as the country or countries that assigned them.

iv.

Serial number of the Advanced Electronic Signature, when they have it.

v.

Address (composed of the name of the street, avenue, or thoroughfare in question, duly specified; exterior number and, where applicable, interior; neighborhood; city or town; borough or municipality; federal entity, and postal code).

Entities will not be obligated to collect the data referred to in this fraction, when it concerns a Concentrating Account or, if it is of another type, in the following cases:

When the account in question is used for the payment of payrolls or other benefits resulting from an employment relationship, or for the payment of the supply of goods or services derived from a commercial relationship.

When the Resource Providers are dependencies or entities of the Federal Public Administration, of Mexico City, or of any federal entity or municipality, that contribute resources to the respective account under support programs for the benefit of certain sectors of the population.

In the cases referred to in the 15th of these Provisions.

VI.

In the case of Beneficial Owners, the Entity must collect the same data and documents as those established in fractions I or III of this Provision, as appropriate. With respect to the address, it will suffice to obtain the data and the document of the address where they can be located.

When the obligation to identify the Beneficial Owner derives from a Client classified with a Low Risk Grade, the document referred to in item iii., of subsection b), of fraction I, as well as number ii.2., of item ii., of subsection b), of fraction III of this Provision, respectively, shall not be collected.

The foregoing, in accordance with the measures established for such purposes in their Compliance Manual, or in any other document or manual prepared by the Entities themselves.

Additionally, the Entity must identify if the Beneficial Owner is a Politically Exposed Person, and in the event of identifying them as such, they must comply with what is established in the 28th and 30th of these Provisions.

In the case of legal entities whose share certificates representing their social capital or securities representing said shares trade on any stock exchange in the country or in recognized foreign securities markets in terms of the General Provisions applicable to stock exchanges published in the Official Gazette of the Federation on May 15, 2017, and their respective modifications, as well as those subsidiaries in which they have a majority participation of more than fifty percent in their social capital, Entities will not be obligated to collect the aforementioned identification data, considering that they are subject to provisions on stock market disclosure of information.

The Secretariat will issue the guidelines that Entities may consider for compliance with what is provided in the first paragraph of this fraction, which will be made known through the electronic means established for such purposes by the Commission.

VII.

In the case of persons who appear as co-owners or authorized third parties in the account opened by the Client, as well as in the Operations carried out by them, Entities must observe the same requirements contemplated in this Provision for titular Clients.

VIII. With respect to Beneficiaries, Entities will collect at least the following data: paternal surname, maternal surname, and first name or names without abbreviations; home address (composed of the same elements as those indicated in subsection a) of fraction I of this Provision), when this is different from that of the account or contract holder, as well as the date of birth of each of them.

In the cases referred to in the 15th of these Provisions, Entities may collect the data of the Beneficiaries referred to in the previous paragraph, after the aforementioned accounts are opened, through the means determined by the Entities themselves; said means must be contemplated in the Compliance Manual of the Entity itself.

IX.

In the case of Trusts:

a)

It must contain the following data recorded:

i.

Number or reference of the Trust and, where applicable, Taxpayer Registry (with homoclave), tax identification number and/or equivalent, the country or countries that assigned them, as well as the serial number of the Advanced Electronic Signature.

ii.

Purpose of the Trust and, where applicable, indicate the vulnerable activity(ies) it carries out in terms of article 17 of the Federal Law for the Prevention and Identification of Operations with Resources of Illicit Origin.

iii.

Place and date of constitution or celebration of the Trust.

iv.

Trade name or corporate name of the fiduciary institution.

v.

Trusted assets (goods and rights).

vi.

Contributions by the settlors.

vii.

Identification data, in terms of this Provision, as appropriate, of the settlors, beneficiaries, fiduciary delegates, and, where applicable, members of the technical committee or equivalent governing body, legal representative(s) and legal proxy(ies).

Without prejudice to the foregoing, the Entity that does not act as fiduciary may comply with the obligation to collect data regarding members of the technical committee or equivalent governing body, indicating only the first name or names and paternal and maternal surnames, without abbreviations, of these, as well as their date of birth.

b)

Simple copy of the following documents:

i.

Contract, notarized copy, or certified copy of the public instrument that certifies the celebration or constitution of the Trust, registered, where applicable, in the public registry corresponding to its nature, or else, the document that, in accordance with the regime applicable to the Trust in question, credibly certifies its existence.

In the event that the Trust is of recent constitution and, for this reason, is not yet registered in the public registry corresponding to its nature, the Entity in question must obtain a written document signed by a person legally authorized to certify its personality in terms of the public instrument referred to in subsection b) item iii., of this fraction, in which the obligation to carry out the respective registration and to provide, in due course, the corresponding data to the Entity itself is stated.

ii.

Proof of address, in terms of what is stated in subsection b), item iii., of fraction I of this Provision.

iii.

Notarized copy or certified copy of the instrument containing the powers of the legal representative(s), legal proxy(ies), or fiduciary delegate(s), issued by a public notary, when not contained in the public instrument that certifies the legal existence of the Trust in question, as well as the personal identification of each of said representatives, proxies, or fiduciary delegates, in accordance with subsection b), item i., of fraction I of this Provision.

iv.

Tax Identification Card issued by the Secretariat and, where applicable, the document in which the assignment of the tax identification number and/or equivalent issued by a competent authority appears, as well as certificate of the Advanced Electronic Signature.

Entities must integrate the identification file of beneficiaries who are not individualized in the contract, at the moment they come to exercise their rights derived from the Trust contract. The obligation established in this paragraph will not be applicable to those Trusts where there is securities intermediation, in which case the obligation will fall on the financial entity that carries out said intermediation.

Entities will not be obligated to integrate the identification file when it concerns Trusts in which the contributions destined for labor benefits or social security for workers come from the workers themselves or from employers, and the settlor is always a public entity that allocates the funds in question for the aforementioned purposes.

With regard to the integration and conservation of identification files of beneficiaries in Trusts constituted to fulfill labor or social security benefits of a general nature, in which contributions are received from dependencies and entities of the Federal Public Administration, of Mexico City, or of a federal entity or municipality, or from companies, their unions, or persons belonging to both, Entities shall be subject to the following:

i.

The identification file of each of the beneficiaries may be integrated and conserved by the Client instead of the Entity. In this case, the Entity must contractually agree with the Client the obligation to keep said file available for its consultation and provide it to the Entity itself, so that it can present it to the Commission, at the moment when the latter so requires the Entity.

ii.

In the case referred to in the previous subsection, Entities must contractually agree with the Client that in substitution of them, the integration and conservation of the identification files of the beneficiaries include mechanisms for the Entities themselves to: (i) verify, randomly, that said files are integrated in accordance with what is stated in these Provisions, and (ii) conserve the identification file of those workers or personnel, once they cease to provide their services to the

Client. In any case, the Entities shall be responsible at all times for compliance with the obligations regarding Client identification established by these Provisions, to which effect, they must establish in the Compliance Manual the mechanisms they will adopt to comply with what is stated in this subsection.

The Trusts referred to in the preceding paragraph may include, among others, the following: Trusts based on pension funds with seniority premium plans; to establish multiple benefits or allowances; for mortgages to employees; for savings funds and mutual aid benefits.

Entities that conduct Operations with Trusts regarding which they do not act as trustees may comply with the obligation (a) to obtain the document referred to in numeral i., of subsection b) of this subsection, and (b) to comply with what is referred to in subsection VI of this Provision, respectively, through a certificate signed by the trustee delegate and the Compliance Officer of the financial entity, institution, or company acting as trustee, which must contain the information indicated in subsection a) above, as well as the obligation to keep such documentation available to the Secretariat and the Commission, in order to submit it upon request from the latter, within the timeframe established by said Commission.

...

Additionally to what is provided in the preceding paragraph, Entities must contractually agree with commission agents the obligation of these to (i) obtain, prior to opening accounts or concluding contracts, the information and documentation for the integration of the respective identification file; (ii) keep the files available to the Secretariat or the Commission and (iii) have mechanisms so that the Entities themselves can verify that the files are integrated in accordance with what is stated in these Provisions. In any case, the Entities shall be responsible for compliance with the obligations regarding Client identification established by these Provisions, to which effect, they must establish in the Compliance Manual the mechanisms they will adopt to comply with what is stated in the preceding paragraph.

...

When the provided identification documents show strikethroughs or corrections, the Entities must obtain another means of identification or, failing that, request two banking or commercial references and two personal references, which include the full first and last names without abbreviations, address composed of the same data as those stated in subsection I of this Provision, and phone number of the issuer, whose authenticity will be verified by the Entities with the persons who sign such references, before the account is opened or the respective contract is concluded.

...

Entities, when obtaining simple copies of the documents that must form part of the Client identification files, in accordance with what is stated by this Provision, must ensure that these are legible and compare them against the corresponding original documents that are physically in their view.

Entities may keep, in their Files or Records, separately the data and documents that should form part of their Clients' identification files, without needing to integrate both into a single physical file, provided they have automated systems that allow them to combine said data and documents for timely consultation by the Entities themselves or by the Secretariat or the Commission, upon request from the latter, in terms of these Provisions and other applicable regulations.

4th Bis.- Entities that receive contributions to their social capital, open an account, or conclude a contract through Devices in a non-presential manner for individual Clients of Mexican or foreign nationality, in accordance with what is established in Annex 2 of these Provisions, in addition to the identification data referred to in the 4th of these Provisions, as applicable, must require and obtain from their Clients, prior consent of these, the Geolocation of the Device from which they open the account or conclude the contract, as well as:

a) Voter ID key, if applicable.

b) Consent.

c) Email address or mobile phone number.

d) If applicable, account number and Standardized Banking Key (CLABE) in the credit institution or Foreign Financial Entity authorized to receive deposits, and which corresponds to the name referred to in the 4th, subsection I of these Provisions.

e) The declaration of the individual stating whether they act on their own behalf or on behalf of a third party; in case they declare that they act on behalf of a third party, they must adhere to what is stated in the 4th, subsection VI of these Provisions. This declaration may be established in the Terms and Conditions established by the Entity for this purpose.

f) The digital version of the valid official personal identification document from which the data referred to in this Provision originate, which must be preserved in accordance with the applicable Mexican Official Standard on digitization and preservation of Data Messages.

Entities must not carry out the receipt of contributions to their social capital, the opening of the account, or the conclusion of the contract in a non-presential manner with individual Clients of Mexican or foreign nationality, when they do not obtain the data regarding Geolocation.

The consent that Entities obtain from their Clients in terms of this Provision may be obtained through Electronic Signature, Advanced Electronic Signature, or in accordance with the general provisions issued by the Commission for this purpose. Such Client consent serves as proof to legally certify the contribution to the Entity's capital, the opening of the account, conclusion of the contract, or any operation carried out with the Entity in a non-presential manner.

A valid official personal identification document for the purposes of this Provision shall be understood to be the voter credential issued by the National Electoral Institute and other national or foreign identifications that, if applicable, are approved by the Commission.

Entities may obtain digital versions of the documentation referred to in this Provision in a non-presential manner and through optical means or any other technology.

The digital versions that Entities obtain for identification purposes must allow their verification in terms of these Provisions. Likewise, said digital versions must be kept in their Files or Records in accordance with these Provisions.

Entities must establish in their Compliance Manual the criteria and mechanisms they will adopt for compliance with what is stated in this Provision.

7th.- The Entity, prior to receiving contributions to its social capital, establishing or initiating a commercial relationship with a Client, must hold an in-person interview with this person or their legal representative in order to obtain the respective identification data and documents. The results of the interview must be recorded in writing or electronically and be contained in the Entity's Files or Records.

Regarding contributions to social capital, accounts opened, or contracts concluded in accordance with the 4th Bis of these Provisions, the interview referred to in the preceding paragraph may be conducted in a non-presential manner, using forms that interact with the Client, both in terms of what is stated in Annex 2 of these Provisions.

Regarding contributions to social capital, granting of credits or loans, accounts opened, or contracts concluded, as well as the situations referred to in the 15th of these Provisions, Entities may enter into agreements with third parties for the performance of the interview referred to in this Provision, which must be carried out in the terms established in articles 36 Bis 3 and 46 Bis second paragraph, of the Law and the general provisions issued by the Commission based on those articles. In any case, Entities falling under the situation provided for in this paragraph shall be responsible for compliance with the obligations regarding Client identification and knowledge established by these Provisions.

With regard to the accounts referred to in the 15th of these Provisions, Entities may carry out the remote reception or capture of data, in substitution of the aforementioned interview, provided that the Entity in question verifies the authenticity of the Client's data, for which they must adhere to the following procedure:

I. and II. . . .

...

...

9th. . . .

I. The entity that integrates and conserves said file must have the Client's consent for said entity to provide the data and documents related to their identification, or the digital version of these latter, to any of the entities that make up the financial group with which it intends to establish a commercial relationship, and

II.

...

a) They may exchange the data and documents, as well as the digital versions, related to the Client's identification, with the objective of establishing a new commercial relationship with the same;

b) and c) . . .

10th.- Entities are prohibited from receiving contributions to their social capital, concluding contracts, or maintaining anonymous accounts under fictitious names or in which the Client or Ultimate Beneficial Owner cannot be identified, so they may only conduct Operations with their Clients once they have met the identification requirements for them, in accordance with these Provisions.

10th Bis.- Entities may not apply the simplified measures provided for in this Chapter to their Clients when they have a well-founded suspicion or indications that the resources, assets, or values that their Clients intend to use to conduct an Operation might be related to the acts or conduct referred to in articles 139 Quáter or 400 Bis of the Federal Penal Code.

The policies, criteria, measures, and procedures that Entities develop to determine what is stated in the preceding paragraph must be documented in their Compliance Manual.

10th Ter.- Entities may suspend the identification process of their possible Client or User when they reasonably estimate:

I. That they might be related to acts or conduct referred to in articles 139 Quáter or 400 Bis of the Federal Penal Code.

II. That continuing with the identification process could prevent or alert the Client or User that the Entity considers the resources, assets, or values are related to acts or conduct referred to in articles 139 Quáter or 400 Bis of the Federal Penal Code.

III. When they identify the existence of Risks in accordance with the criteria they establish in the Compliance Manual.

In the event of carrying out the suspension referred to in this Provision, Entities must generate the corresponding 24-hour Unusual Operation Report with the information they have about the possible Client or User in question, which may be prepared manually.

The report referred to in the preceding paragraph must be sent to the Secretariat, through the Commission, within 24 hours counted from when the Entity becomes aware of the information stated in this Provision, through the corresponding official format.

For the purposes of what is established in this Provision, Entities must establish in their Compliance Manual, or in another document or manual prepared by the Entity itself, the necessary policies, criteria, measures, and procedures.

11th.- . . .

In the cases referred to in the 15th of these Provisions, Entities must verify the Beneficiary's data at the moment they present themselves to exercise their rights, in the terms in which the account in question was opened.

12th.- Regarding mandates or commissions that Entities are authorized to perform, they must invariably integrate the identification file of all parties involved in the signing of the respective instruments (mandator, mandatory, agent, principal), in the terms established in the 4th or 4th Bis of these Provisions, except when dealing with third parties referred to in stipulations for their benefit that are not individually identified in the mandate or commission contract respectively.

14th.- For the case of products and services other than those provided for in the 15th of these Provisions, which are considered by Entities as Low Risk, they may integrate the respective identification files of their Clients, subject to what is established in this Provision, only with the data stated in subsections I, II, or III of the 4th and 4th Bis, of these Provisions, as applicable according to the type of Client in question, as well as with the Client's personal identification data and, if applicable, that of their representative, which must be one of those contemplated in subsection b), numeral i., of subsection I of the 4th or the fourth paragraph of the 4th Bis of these Provisions, and which Entities are obliged to request to be presented as a prerequisite for opening the respective account.

What is provided in the preceding paragraph shall proceed provided that the Entity in question has established in its Compliance Manual, or in another document or manual prepared by it, the criteria and elements of analysis based on which it considers such products and services as Low Risk, including, among others, the maximum amount of permitted transactional levels for the purpose of continuing to consider said products within the Risk category indicated.

In the event that the transactional level of any of the products or services referred to in the first paragraph of this Provision exceeds the maximum amount established by the Entity for them to be considered as Low Risk, said Entity must proceed to integrate the respective Client identification file with all the corresponding information and documentation, in terms of what is provided in the 4th or 4th Bis, of these Provisions, as well as comply with the various obligations established therein.

...

15th.- Demand deposit accounts in national currency offered by Entities will be considered Low Risk and, therefore, may have simplified identification requirements, provided that, they are opened in person or in terms of what is provided in the 7th, fourth paragraph of these Provisions, and it concerns Clients who are individuals whose operation is limited to deposits equal to the equivalent in national currency to one thousand Units of Investment per Client, during a calendar month. Entities may integrate the respective identification files of their Clients only with the data relating to the full name, without abbreviations, date of birth, and address of these, which must be composed of the elements referred to in the 4th of these Provisions. In this case, the data relating to the Client's name and date of birth must be obtained from an official identification listed in said 4th of these Provisions.

Regarding contributions to social capital, accounts opened, or contracts concluded in a non-presential manner, Entities must integrate the identification files of their Clients with the data relating to the full name without abbreviations, gender, state of birth, date of birth, as well as address of these, composed of the elements referred to in the 4th of these Provisions.

Likewise, in the case of funds derived from the application of government support programs for the benefit of certain sectors of the population, Entities may receive deposits up to a maximum amount equivalent in national currency to six thousand Units of Investment per Client, during a calendar month, in addition to the previously mentioned maximum transactional level, provided that the resources come from said funds.

...

17th.-

For the execution of Operations through electronic, optical, or any other technology media, Entities must previously integrate the Client identification file in accordance with what is established in these Provisions, establish mechanisms to identify them in accordance with what is established in Annex 2 of these Provisions, as well as develop procedures to prevent the improper use of said media or technologies, which must be contained in their Compliance Manual.

17th Bis.- Entities must verify the data and documents that their possible Clients provide them to prove their identity.

The verification referred to in the preceding paragraph may be carried out in a non-presential manner in accordance with what is stated in Annex 2 of these Provisions, where applicable.

When dealing with Operations of Clients classified by Entities as Low Risk Grade, the verification referred to in the preceding paragraph may be done after the conclusion of the respective contract. In the cases referred to in this paragraph, Entities must inform their Clients that they cannot conduct Operations until the verification process referred to in this Provision is completed.

Entities must establish in their Compliance Manual the policies, criteria, measures, and procedures they will adopt for compliance with what is stated in this Provision.

The verification of the data and documents referred to in this Provision, obtained from their Clients, may be performed by third parties without this exempting Entities from compliance with the obligations provided for in these Provisions.

18th.- . . .

I. to III. . . .

IV.

Without prejudice to the other obligations and measures established in these Provisions, that Entity that accepts processing the sending of a national transfer of funds in foreign currency or an international transfer of funds requested by its Client or User, must obtain from said Client or User the following information regarding the Recipient or beneficiary of the transfer, whether natural or legal person, which must be conserved and accompany the transfer in question:

a) Name and surname or surnames that correspond or, if applicable, trade name or corporate name.

b) Identifier of the Recipient's or beneficiary's account, in case said account is used to process the transfer in question or, in the absence of said account, a unique reference number of said transfer that allows its tracking.

c) As much data as, if applicable, are provided by the Client or User and the system through which the transmission is made allows: Country of birth and date of birth, national identity number or address, as applicable to natural persons of Mexican or foreign nationality, or, in the case of legal persons, tax identification number and country that issued it or address.

V.

Without prejudice to the other obligations and measures established in these Provisions, that Entity that accepts receiving national transfers of funds in foreign currency or international transfers of funds directed to its Client or User in question, must obtain the following information regarding the person who ordered the national or international transfer, depending on whether it is a natural or legal person:

a) Name and surname or surnames or, if applicable, trade name or corporate name.

b) Identifier or reference of the originator's account, which allows tracing the transfer from its origin.

c) As much data as, if applicable, are transmitted by the entity sending the respective transfer: Country and date of birth, national identity number or address, as applicable to natural persons of Mexican or foreign nationality, or, in the case of legal persons, tax identification number and country that issued it or address.

Additionally, the Entities referred to in this subsection must have policies and procedures documented in their respective Compliance Manuals to which they must adhere to identify, at the time of receipt or subsequently, the transfers indicated in this same subsection that do not contain the information of the persons who order such transfers or of the Recipients or beneficiaries that should be included in such transfers in accordance with this Provision, as well as include in said Manuals, at least, the risk-based criteria they will use to determine if it is appropriate to execute, reject, or suspend the transfers they receive without the required information, as well as the actions they will take in follow-up to this.

Ordering or receiving Entities of fund transfers referred to in this Provision must verify the information provided by their Client or User in case there is a well-founded suspicion or indication that the resources might be related to the acts or conduct referred to in articles 139 Quáter or 400 Bis of the Federal Penal Code and, if applicable, generate the corresponding 24-hour Unusual Operation Report. The policies and procedures to carry out the verification referred to in this paragraph must be included in their respective Compliance Manual.

...

...

18th Bis.- Entities may obtain the data and documentation of their Users in terms of the 18th of these Provisions in a non-presential manner and through electronic, optical, or any other technology media, in accordance with what is provided in Annex 2 of these Provisions.

Entities that opt to integrate the User identification file in the terms provided for in the preceding paragraph, in addition to what is provided in the 18th of these Provisions, must require and

obtain from its Users, prior to their consent, the Geolocation of the Device from which the User

concludes the Operation, as well as their email address.

Entities shall not conclude Operations with Users in a non-presential manner if they do not collect

the data regarding Geolocation.

For the purposes of this Provision, a valid official personal identification document currently in force

shall be understood as the voter credential issued by the National Electoral Institute and other

national or foreign identifications that, as applicable, are approved by the Commission.

Entities are obligated to preserve documents in their Files or Records in accordance with the

present Provisions.

Digital versions of the documents that, as applicable, Entities collect for identification purposes

must allow for verification in terms of Annex 2 of these Provisions.

Entities must establish in the Compliance Manual, the criteria and mechanisms that they will

adopt to comply with what is stated in this Provision.

The information referred to in this Provision must be available to the Secretariat and the

Commission, upon request by the latter, within the timeframe established by the Commission itself.

23rd.- Entities will verify that the identification files of their corporate Clients, regardless of their Risk Level, contain all the data and documents provided for in the 4th of these Provisions, as well as that such data and documents are up to date, understanding that Entities may opt not to carry out the update of the latter, in case it concerns a corporate Client with a low Risk Level. This, in the terms and conditions that Entities establish in their own Compliance Manual. Likewise, they will verify, at least once a year, that the identification files of their Clients classified as High Risk Level, are up to date with all the data and documents provided for in the 4th, 4th Bis,

30th and

34th of these Provisions.

If during the course of a commercial relationship with a Client, the Entity in question detects significant changes in the usual transactional behavior of the latter, without there being a justified cause for it, or if doubts arise regarding the veracity or accuracy of the data or documents provided by the Client itself, among other circumstances that the Entity itself establishes in its Compliance Manual, it will reclassify said Client into the higher Risk Level corresponding, according to the results of the analysis that, as applicable, the Entity performs, and must verify and request the update of both the data

as well as the identification documents, among other measures that the Entity deems convenient.

Entities may comply with the obligation to update their Clients' files in accordance with this Provision in a non-presential manner, regardless of the method of account opening, and must, in any case, collect the data and documents that are applicable according to the type of

Client, and carry out the respective verification.

Entities must establish in their Compliance Manual, the policies, criteria, measures and

procedures that they will adopt to comply with what is stated in this Provision, including

the circumstances in which a visit to the domicile of Clients classified as High Risk Level must be carried out, in order to properly integrate the files and/or update the data and

documents corresponding, in which case the results of such a visit must be recorded in the

respective file.

23rd-1.- Entities must design and implement a methodology to carry out a Risk

Assessment of the Risks to which they are exposed derived from their products, services, Clients, Users,

countries or geographic areas, transactions and distribution or shipping channels with which they operate.

The design of the methodology referred to in the preceding paragraph must be established in its Compliance Manual, or in another document or manual prepared by the Entity, and must establish and

describe all the processes that will be carried out for the identification, measurement and mitigation of Risks

for which they must take into account, the Risk factors that they have identified for such effect, as well as

the information that is applicable given the context of each Entity contained in the national risk assessment

and its updates, which the Secretariat makes known to them through the Commission.

Regarding Entities that are part of financial groups in terms of the Law to Regulate Financial

Groupings, these must establish in the design of the methodology how the results of the methodology that, as applicable, they have implemented by the other financial entities that make up the corresponding group will be taken into account.

Likewise, Entities will carry out a Risk Assessment of the Risks to which they are exposed in

accordance with what is established in this Chapter, in advance of the launch or use of new products,

services, types of Clients and/or Users, countries or geographic areas, distribution or shipping channels and

transactions.

23rd-2.- Entities for the design of the Risk assessment methodology must comply with the

following:

I.

Identify the elements and indicators associated with each of them that explain how and to what

extent the Entity may be exposed to Risk, considering at least, the following elements:

a)

Products and services.

b)

Clients and Users.

c)

Countries and geographic areas.

d)

Transactions and distribution or shipping channels linked to the Operations of the Entity, with

its Clients and with its Users.

Within the process of identifying Risk indicators, the total of all

products, services, types of Clients and Users, countries or geographic areas, transactions and channels of

shipping or distribution, with which the Entity operates, must be considered.

II.

Use a method for the measurement of Risks that establishes a relationship between the indicators

and the element to which they belong referred to in the previous fraction I and assign a weight to each of them

consistently based on their importance to describe said Risks. In turn, a weight must be assigned

to each of the defined Risk elements consistently based on their

importance to describe the Risks to which the Entity is exposed.

III.

Identify the Mitigants that the Entity has implemented at the time of the design of the

methodology, considering all the policies, criteria, measures and internal procedures to which it refers

the 67th of these Provisions, as well as their effective application, in order to establish the effect that

these will have on the indicators and Risk elements indicated in the previous fraction I, as well as on

the Risk of the Entity.

23rd-3.- Entities must implement the designed methodology and obtain the results of the same

in order to know the Risks to which they are exposed. In the implementation of the methodology of

Risk assessment, Entities must ensure:

I.

That there are no inconsistencies between the information they incorporate into this and the one on file in their

automated systems.

II.

Use, at least, the information corresponding to the total number of Clients, number of

operations and amount operated corresponding to a period that cannot be less than twelve months.

When, derived from the results of the implementation of the Risk assessment methodology, it is

detected the existence of greater or new Risks for the Entities themselves, these must modify the

policies, criteria, measures and procedures that correspond, contained in the Compliance Manual, or

in another document or manual prepared by the Entity, in order to establish the Mitigants that

they consider necessary based on the identified Risks, as well as to maintain them at a level of

acceptable tolerance in accordance with what is established in the Compliance Manual.

The modifications to the policies, criteria, measures and internal procedures referred to in the preceding

paragraph, derived from the results of the implementation of the Risk assessment methodology,

must be carried out within a period not exceeding twelve months counted from when the Entity has the

results of its implementation and must be clearly identified and indicated, indicating at least the year and

month in which the results of the implementation of the methodology that gave rise to such modifications were obtained.

23rd-4.- The compliance and results of the obligations contained in this Chapter must be

reviewed and updated by Entities when the existence of new Risks is detected, when the national risk assessment is updated, or within a period not exceeding 12 months from when the Entity

has the results of its implementation. Such reviews and updates must be recorded in writing and be available to the Secretariat and the Commission, upon request by the latter, within the period

that the Commission itself establishes.

The Commission may review and, as applicable, order Entities to modify their Risk assessment methodology or their Mitigants, among other circumstances, when they do not consider a proper

Risk administration in the procedure and criterion(s) for the determination of the opening, limitation or

termination of a commercial relationship with their Clients or Users, which must be congruent with said

methodology, as well as request an action plan for them to adopt reinforced measures to manage and

mitigate their Risks.

Entities must preserve the information generated by reason of this Chapter during a

period not less than five years and provide it to the Secretariat and to the Commission, upon request by the latter,

within the period that the Commission itself establishes.

23rd-5.- Entities must comply with all the obligations contained in the present

Provisions, in concordance with the results generated by the Risk methodology referred to in this Chapter.

23rd-6.- The Commission, prior to the opinion of the Secretariat, will elaborate guidelines, guides and/or best practices

that Entities will consider for the better compliance with what is provided in this present Chapter, which will be made known through the electronic means established by the same.

24th.- . . .

Such policy must be an integral part of the Compliance Manual of each Entity.

. . .

26th.- For the purposes of these Provisions, the transactional profile of each of the Clients

will be based on the information they provide to the Entity and, as applicable, on that which the Entity has, regarding the amount, number, type, nature and frequency of the Operations that such Clients commonly carry out; the origin and destination of the resources involved; as well as on the knowledge that the employee or official of the Entity has regarding their portfolio of Clients, and on the other elements and

criteria that the Entities themselves determine in their Compliance Manual.

Regarding those Operations carried out in a non-presential manner, in addition to the elements for

determining the Client's transactional profile indicated in the preceding paragraph, the

Geolocation of the Device from which said Operation is carried out must be taken into account.

27th.- . . .

. . .

. . .

In the case of account opening or contract conclusion in a non-presential manner referred to

in the 4th

Bis of these Provisions, Entities must consider the information on Geolocation,

prior to the Client's consent, of the Device from which the Client carries out

the Operation, activity or

service with the respective Entity.

. . .

. . .

Entities, in the terms that their Compliance Manual provides for that effect, will apply to their

Clients who have been classified as High Risk Level, as well as to new Clients that

meet such characteristics, identification questionnaires that allow obtaining more information on the origin and

destination of the resources and the activities and Operations they carry out or intend to carry out.

The questionnaires referred to in the preceding paragraph may be carried out in a non-presential manner, by digital or electronic means, in order to ensure the veracity and security in their preparation, which in any case must contain the consent referred to in the 4th Bis of these Provisions, by the person who

signs it.

. . .

28th.- For cases where, prior to or after the start of the commercial relationship, an Entity detects that the person who intends to be a Client or who already is, as applicable, meets the requirements to be considered a Politically Exposed Person and, in addition, as High Risk Level, such Entity must, in accordance with what it establishes for that effect in its Compliance Manual, obtain the approval of a director or their equivalent who has specific powers to approve the opening or conclusion of such accounts or contracts, as applicable, in order to start or, as applicable, continue the commercial

relationship.

29th.- Prior to the opening of accounts or conclusion of contracts of Clients who, due to their

characteristics, could generate a high Risk for the Entity, at least one director or their equivalent who has specific powers to approve the opening or conclusion of such accounts or contracts,

as applicable, must grant in writing, in digital or electronic form, the respective approval.

Likewise, for the purposes referred to in fractions IV and V of the 50th of these Provisions,

Entities must provide in their Compliance Manual, the mechanisms for their respective

Compliance Officers to be aware of those Clients that are classified with a High Risk Level by the Entities themselves, as well as the procedures that must be carried out to process the

approval indicated in this Provision.

30th.- . . .

. . .

In the Operations carried out by Clients who have been classified as High Risk Level, the

Entities will adopt measures to know the origin of the resources and will seek to obtain the data

indicated in Chapter II of these Provisions, in the terms that their Compliance Manual provides for that effect, or in another document or manual prepared by them, regarding the spouse and

economic dependents of the Client, as well as the societies and associations with which they maintain

patrimonial links, in the case of natural persons, and, regarding legal persons, their main

shareholders or partners, as applicable, while in the case of Trusts, they will seek to collect the

same data regarding the spouse and economic dependents of the settlors and beneficiaries

who are natural persons, as well as the societies and associations with which they maintain patrimonial links and,

regarding settlors and beneficiaries who are legal persons, their corporate structure and their

main shareholders or partners, in the terms that their Compliance Manual provides for that effect, or in another

document or manual prepared by them.

Regarding foreign Politically Exposed Persons, Entities must obtain, in addition to the reference data, the documentation

indicated in Chapter II of these Provisions, regarding the natural and legal persons mentioned above in this paragraph.

Without prejudice to the foregoing, regarding corporate Clients whose titles representing their

share capital or securities representing such shares trade on any stock exchange in the country or in

foreign securities markets recognized as such in terms of the General Provisions applicable to stock exchanges published in the Official Gazette of the Federation on May 15, 2017 and

their respective modifications, as well as those subsidiaries of these in which they have a

majority participation of fifty percent in their share capital, Entities will not be obligated to collect the identification data mentioned above, considering that they are subject to provisions in

securities matters on information disclosure.

Entities, in the terms that their Compliance Manual provides for that effect, or in another

document or manual prepared by them, must develop mechanisms to establish the degree of

Risk of the Operations they carry out with Politically Exposed Persons of Mexican nationality and,

for that effect, Entities will determine if the transactional behavior reasonably corresponds to the

functions, level and responsibility of such persons, according to the knowledge and information that the

cited Entities have available.

31st.- . . .

. . .

I.

. . .

II.

. . .

a)

. . .

b)

Evaluate the controls they have, in order to determine that they comply with the

international standards applicable in matters of prevention of operations with resources of

illicit origin and terrorism financing. The criteria according to which Entities

will carry out the evaluation indicated in this subsection must be contemplated in the Manuals of

Compliance, or in another document or manual prepared by the Entity in question;

c) and d) . . .

In correspondent relationships, both Entities and their counterparts abroad must

document the obligations in matters of prevention of operations with resources of

illicit origin and terrorism financing to which each is subject in their countries. In order to comply

with what is established in this paragraph, Entities may request the prevention program of operations with

resources of illicit origin and terrorism financing from their counterpart abroad.

Likewise, the Entity prior to the correspondent relationship must gather available information that

allows it to have knowledge of the obligations in matters of prevention of operations with resources of

illicit origin and terrorism financing of the correspondent institution, as well as to know from the

publicly available information, the reputation of the institution and the quality of supervision, including if it has been the object or not of an investigation on operations with resources of illicit origin and/or

terrorism financing

33rd.- When an Entity has information based on indications or certain facts about that

one of its Clients acts on behalf of another person, without having declared it in accordance with what is

indicated in the 4th or 4th Bis of these Provisions, such Entity must request from the Client in question, information that allows it to identify the Beneficial Owner of the resources involved in the account,

contract or Operation respective, without prejudice to the duties of confidentiality towards third parties

that such Client has assumed by conventional means.

. . .

Both in the circumstances provided for in the preceding paragraphs of this Provision, and in that one in which

doubts arise in the Entity regarding the veracity or authenticity of the data or documents provided

by the Client or User for identification purposes, or regarding the transactional behavior of the Client

in question, the said Entity must carry out a specific and integral follow-up of the Operations

that such Client or User carries out, in accordance with what, for that effect, it establishes in its Compliance

Manual and, as applicable, submit them to the consideration of the Committee, who must rule and, in the event that it is appropriate, issue the report of Unusual Operation corresponding.

34th.- Without prejudice to what is stated in the 4th of these Provisions, Entities must

establish in their Compliance Manual, procedures to identify the Beneficial Owners of the resources used by Clients in their accounts or contracts, so they must:

I. to III. . . .

41st.- . . .

Each Entity must provide in its Compliance Manual, or in another document or manual

prepared by the Entity itself, the mechanisms based on which, those Operations that must be

presented to the Committee for the purposes of its ruling as Unusual Operations, must be

analyzed, including the antecedents and purposes of the same. In any case, the results of said examination must be recorded in writing and will be available to the Secretariat and the Commission, for at least ten years counted from the celebration of the Committee meeting in which such results were presented.

. . .

Likewise, in the process of determining Unusual Operations referred to in this

Provision, Entities must rely on their Compliance Manual, as well as on any other

document or manual prepared by the Entity itself and, in addition to this, they will consider the guidelines prepared for that effect by the Secretariat and by international organizations and intergovernmental groupings in matters of prevention and combat of operations with resources of illicit origin and of terrorism financing, of which Mexico is a member, which the Secretariat provides to them.

44th.- In case an Entity has information based on well-founded suspicions or indications, such as concrete facts from which it is inferred that, when attempting to carry out an Operation, the resources

might come from illicit activities or might be intended to favor, provide help, aid or cooperation of any kind for the commission of the crime provided for in Article 139 Quater of the Federal Penal Code, or that they could fall under the circumstances of Article 400 Bis of the same legal instrument,

that same Entity, in the event that it decides to accept said Operation, must send to the Secretariat, through the Commission, within 24 hours counted from when it knows said information, a

report of Unusual Operation, in which, in the column of description of the Operation, the legend " 24-hour Report " must be inserted. Likewise, in those cases where the Entity does not carry out the

Operation referred to in this paragraph, it must present to the Secretariat, through the Commission, the report of Unusual Operation in the terms indicated in this Provision regarding said

Clients or Users, and will provide, as applicable, all the information it has known about them.

. . .

For the purposes of what is provided in this Provision, Entities must establish in their Compliance Manual or in any other document or manual prepared by them, those in accordance with which their personnel, once they become aware of the information in question, must immediately make it known to the Entity's Compliance Officer, so that this officer fulfills the obligation to send the corresponding report.

...

46th.- ...

I.

Submit to the approval of the audit committee or its equivalent of the relevant Entity, the Compliance Manual, as well as any modifications thereto.

I Bis. Present to the board of directors or executive board of the Entity, as applicable, the results of the implementation of the methodology developed and implemented to carry out the Risk Assessment referred to in the previous Chapter II Bis;

II.

...

III.

Be informed of those Clients who, due to their characteristics, are classified with a High Risk Grade, according to the reports submitted to that effect by the Compliance Officer and, if applicable, formulate the recommendations deemed appropriate;

IV. to VIII. ...

IX.

Resolve other matters submitted to its consideration, related to the application of these Provisions;

X.

Ensure that the Entity, for the compliance with these Provisions, has the internal structures referred to in this Chapter, regarding organization, number of people, material and technological resources, in accordance with the results of the implementation of the methodology referred to in the previous Chapter II Bis, and

XI.

Ensure that the key referred to in 72nd-1 is requested and kept updated in the name of the Compliance Officer or Compliance Officer designated as interim, as applicable.

Each Entity must expressly establish in its Compliance Manual, or in any other document or manual prepared by the Entity itself, the mechanisms, processes, deadlines and moments, as the case may be, that must be observed in the performance of the functions indicated in this Provision.

47th.- ...

...

...

...

...

...

Entities that have fewer than twenty-five people on their staff, whether they perform functions for the same directly or indirectly through complementary service companies, will not be obliged to constitute and maintain the Committee referred to in this Provision. In the case provided for in this paragraph, the functions and obligations that should correspond to the Committee in accordance with what is stated in these Provisions, will be exercised by the Compliance Officer, except for that provided in fraction XI of the 46th of these Provisions, which will correspond to the general director or equivalent of the Entity.

50th.- ...

...

...

I.

Draft and submit to the consideration of the Committee the Compliance Manual, which contains the policies for the identification and knowledge of the Client and the User, and the criteria, measures and procedures that must be adopted to comply with what is provided in these Provisions;

I. Bis. Submit to the approval of the Committee the methodology designed to carry out the Risk Assessment referred to in the previous Chapter II Bis, as well as the results of its implementation;

II and III. ...

IV.

Make known to the Committee those Clients who, due to their characteristics, are classified with a High Risk Grade for the Entity itself;

V. and VI. ...

VII.

Act as a consultation instance within the Entity regarding the application of these Provisions, as well as of the Compliance Manual;

VIII. to XI. ...

...

...

Each Entity must expressly establish in its Compliance Manual, or in any other document or manual prepared by the Entity itself, the procedures in accordance with which the Compliance Officer will perform the functions and obligations established in this Provision and the manner in which it will document the compliance with them, if applicable.

52nd.- ...

I.

The provision of courses, at least once a year, which must be directed especially to the members of their respective boards of directors, executives, officials and employees, including those who work in customer service or resource administration areas, and which contemplate, among other aspects, those related to the content of the Compliance Manual, which the Entity has developed for the due compliance of these Provisions, as well as on the activities, products and services offered by the Entity.

...

II.

...

Paragraph repealed.

54th.- Each Entity, as part of its Technological Infrastructure, must have automated systems that develop, among others, the following functions:

I.

...

II.

Generate and securely transmit to the Secretariat, through the Commission, the information regarding the reports of Relevant Operations, cash operations in United States dollars, Unusual Operations, Internal Concerning Operations and international fund transfers referred to in these Provisions, as well as that which must be communicated to the Secretariat or to the Commission, in the terms and according to the deadlines established in these Provisions;

As an exception to what is stated in this fraction, Entities may manually generate the report referred to in the 10th Ter of these Provisions;

III. and IV. ...

V.

Execute the alert system contemplated in the 27th of these Provisions;

V Bis. Contribute to the detection, follow-up and analysis of possible Unusual Operations and Internal Concerning Operations, considering at least, the information that has been provided by the Client at the beginning of the commercial relationship, the historical records of the Operations carried out by this, the transactional behavior, the average balances and any other parameter that may provide more elements for the analysis of this type of Operations;

VI. to IX. ...

IX Bis. Provide the information that Entities will include in the methodology they must develop in accordance with what is established in the 23rd-1 of these Provisions;

X.

Execute an alert system regarding those Operations that are intended to be carried out with persons referred to in fraction X of the 41st of these Provisions, Politically Exposed Persons, in accordance with what is stated in the 71st of these Provisions, as well as with those who are within the List of Blocked Persons; and

XI.

Facilitate the verification of the data and documents provided non-presentially by the Client.

60th.- Entities must adopt selection procedures to ensure that their personnel have the necessary technical quality and experience, as well as honorability to carry out the activities that correspond to them, which must include the obtaining of a signed declaration by the official or employee in question, in which they will state the information relative to any other financial entity or those societies referred to in article 95 Bis of the General Law of Organizations and Auxiliary Credit Activities, in which they have previously worked, if applicable, as well as the fact of not having been sentenced for property crimes or disqualified from exercising commerce as a result of non-compliance with the legislation or to perform a job, position or commission in public service, or in the Mexican financial system. To this effect, the selection procedures referred to above must be contemplated in the Entity's Compliance Manual, or in any other document or manual prepared by the Entity itself.

...

61st.- Entities are obliged to preserve for a period of no less than ten years, counted from the execution of the Operation carried out by their Clients or Users, the following:

I.

The documentation and information that accredits the Operation in question once it has been celebrated;

II.

The data and documents that make up the identification files of their Clients, which must be preserved during the entire validity of the account or contract and, once these conclude, for the period referred to in this Provision, from the conclusion of the contractual relationship.

The identification file that Entities must preserve in terms of this Provision, must allow identifying the Client, as well as knowing the Operations they carry out with the Entity.

Likewise, those data and documents that must be collected from Users, must be preserved for the period mentioned above counted from the date on which the User carries out the Operation in question;

III.

The historical records of the Operations they carry out with their Clients;

IV.

Copy of the reports of Relevant Operations, cash operations in United States dollars, Unusual Operations, Internal Concerning Operations, and international fund transfers referred to in these Provisions, as well as the original or copy or accounting or financial record of all supporting documentation, which must be identified and preserved as such by the Entity itself for the same period;

The records of the reports submitted in accordance with these Provisions, as well as the records of the Operations celebrated, must allow knowing the manner and terms in which they were carried out, in accordance with the applicable legal provisions.

The preservation provided for in this Provision may be carried out by electronic or digital means, which must guarantee the security of the information and documentation collected from the Client or User.

...

64th.- ...

...

I.

...

II.

It may be requested only by officials authorized for such purposes, through a written document in which the reason and class of information required must be specified. The request referred to in this fraction may be sent electronically or digitally, ensuring the confidentiality of the information;

III.

The response to the information request made by an Entity must be sent in writing signed by officials authorized for such purposes, within a period that must not exceed 30 natural days counted from the date on which it was requested. The response to the request referred to in this fraction may be sent electronically or digitally, ensuring the confidentiality of the information;

IV. and V. ...

...

The Entity may preserve the information and documentation indicated in this paragraph in the Archives or Records that it keeps for such purposes to comply with these Provisions, guaranteeing the security and preservation of the information.

68th.- The Commission will be empowered to require Entities or through the Supervision Committee, to make modifications to their Compliance Manuals, as well as to the other documents indicated in them in these Provisions, when in its judgment it is necessary for the correct application of them.

69th.- The Commission, in exercise of the supervision powers conferred by the Law and other legal orders, will monitor that Entities, including in their case, their offices, branches, and agencies, both in national territory and abroad, comply with the obligations established in these Provisions, in the Compliance Manual of the Entity itself, as well as in any other document in which criteria, measures and procedures related to the compliance with these Provisions are established, and will impose the corresponding sanctions for non-compliance with the mentioned obligations, in the terms indicated in the Law and, likewise, may request at any time, the necessary information or documentation for the development of its powers.

72nd-1.- ...

Likewise, Entities must ensure that the key referred to in the previous paragraph, is kept updated in the name of the Compliance Officer or Compliance Officer designated as interim, as applicable.

CHAPTER XV BIS

NOVEL MODELS

72nd-2.- Entities that intend to obtain authorization from the Commission so that, through Novel Models, they carry out any of the Operations referred to in fraction XXVIII of the 2nd of these Provisions must:

I.

Identify and evaluate the risk to which they are exposed, prior to the launch of the product or service in question through Novel Models. The evaluation referred to in this fraction must be carried out in accordance with Chapter II Bis of these Provisions.

II.

Present the result of the evaluation referred to in the previous fraction to the Commission together with its authorization request.

III.

Comply with these Provisions, according to the cases, forms, terms, deadlines, conditions and exceptions that the Commission indicates in the respective authorization, prior opinion of the Secretariat.

73rd.- ...

Entities must adopt and implement mechanisms that allow identifying Clients or Users who are within the List of Blocked Persons, as well as any third party acting on behalf or for the account of the same, and those Operations they have carried out, carry out or intend to carry out. Such mechanisms must be provided for in the Compliance Manual of the Entity itself.

75th.- ...

Entities that, in terms of this Provision, have suspended acts, Operations or services with their Clients or Users, must immediately make their knowledge of this situation known in writing or through digital means, in which they must inform said Clients and Users of the grounds and cause or causes of such inclusion, as well as that, within ten business days following the day of receipt of the cited writing, they may go before the competent authority for the purposes of the 76th of these Provisions.

TRANSITIONAL PROVISIONS

First.- This Resolution will enter into force the day after its publication in the Official Gazette of the Federation.

Second.- The guidelines, interpretations and criteria issued by the Secretariat or by the Commission, based on what is provided in the Resolution of December 31, 2014 and subsequent Resolutions through which the General Provisions referred to in article 124 of the Savings and Popular Credit Law have been added or amended, will continue to be applicable insofar as they do not oppose what is established in this Resolution.

Third.- Entities must comply with the obligations contained in this Resolution, in the terms and in accordance with the deadlines indicated below:

I.

Four months counted from the entry into force of this Resolution to modify the Compliance Manual and present it to the Commission.

II.

Nine months counted from the date of entry into force of this Resolution, to modify the methodology referred to in Chapter II Bis.

III.

Eighteen months counted from the date of entry into force of this Resolution, to update the automated systems referred to in the 54th of the Provisions.

IV.

Twenty-four months counted from the date of entry into force of this Resolution, to collect the Geolocation of the Device from which the Client or User celebrates each Operation, referred to in these Provisions.

Fourth.- Entities are obliged to send the report referred to in the 10th Ter of these Provisions, once the Secretariat makes known the guide or guidelines for such effect through the electronic means indicated for such purpose.

Fifth.- Entities are obliged to comply with what is provided in Provision 18th, fraction IV, subsection c), and fraction V, subsection c), which are added in this instrument starting from November 1, 2020.

Annex 1

The simplified regime referred to in fraction IV of the 4th of these Provisions, will apply to the following societies, departments and entities:

Financial Technology Institutions.

Holding Companies of Financial Groups.

Investment Funds.

Investment Societies Specialized in Retirement Funds.

Operating Societies of Investment Funds.

Distributing Societies of Investment Fund Shares.

Credit Institutions.

National Development Bank for Agriculture, Rural, Forestry and Fisheries.

Brokerage Houses.

Exchange Houses.

Retirement Fund Administrators.

Insurance Institutions.

Mutual Insurance Societies.

Surety Institutions.

General Warehouses.

Savings and Loan Cooperative Societies.

Community Financial Societies.

Popular Financial Societies.

Multiple Purpose Financial Societies Regulated and Unregulated.

Credit Unions.

Value Issuing Societies.

Foreign Financial Entities.

Federal, state and municipal public departments and entities, as well as other Mexican public law legal persons.

Stock Exchanges.

Securities Depository Institutions.

Societies that administer systems to facilitate operations with securities.

Central Counterparties of Securities.

Societies authorized to operate with Novel Models in accordance with Title IV of the Law to Regulate Financial Technology Institutions.

Annex 2

Of non-presential identification

Article 1.- Entities, for the purposes of the identification of their Clients or potential Clients who are natural persons of Mexican nationality, in the non-presential celebration of contracts for the opening of deposit accounts always that it is agreed in the respective contracts that the sum of the credits during a calendar month does not exceed the equivalent in national currency to 30,000 UDIs, as well as commercial credits granted to natural persons with business activity and consumer credits, in both cases for amounts less than the equivalent in national currency to 60,000 UDIs, may adjust to what is provided by this article or, if applicable, to what is contained in the following Article 3:

I.

Obtain prior approval from the Commission.

II.

Require the natural person in question to send a form through the electronic medium established by the Entity itself, in which must be included, at least, the data referred to in the 4th Bis of these Provisions, as well as the product or service intended to be contracted.

The mentioned form must include a statement indicating that its submission to the Entity in question constitutes the consent of the person for their voice and image to be recorded when establishing a communication through an audiovisual medium and in real time between them.

Together with the form, Entities must require the applicant to send a color photograph of their valid voter ID card issued by the National Electoral Institute, on the front and back. Entities must require the applicant to take a color photograph of their face, using devices with cameras of at least 4 megapixel resolution, 24-bit color images, whose taking is only done online through the Entity's own technological tool to be sent in that same act.

Additionally, Entities must require the natural person to send in digital format the necessary documents to integrate and preserve their identification file in terms of what is provided by provision 4th of the General Provisions referred to in article 124 of the Savings and Popular Credit Law issued by the Secretariat or those that replace them.

III.

Once the duly filled form is received, they must verify if the applicant is a Client of the Entity and, in this case, verify the data of the form with the records of the Entity itself.

In addition to the above, Entities must confirm the existence of the Unique Population Registry Key with the National Population Registry, as well as that the data of this and those provided in the form coincide with each other.

Likewise, they must compare the photographs of the voter ID card and the face, in order to make the facial biometric recognition between them, ensuring that both coincide according to the level of reliability established in fraction IV of Article 4 of this Annex and, validate the security elements of the received voter ID card, in order to detect if said document presents alterations or inconsistencies, for which they must have the necessary technology for it.

Additionally, Entities must verify the coincidence of the data of the voter ID card issued by the National Electoral Institute listed below, with the records of the Institute itself:

a)

The Credential Identifier Code (CIC), which is printed on the voter ID card

b)

Year of registration.

c)

Voter Key.

d)

Number and year of issuance.

Entities must verify that the paternal surnames, maternal surnames and name or names, as they appear on the presented voter ID card, coincide with the records of the National Electoral Institute or the National Population Registry.

IV.

They must inform the applicant of the procedure that will be followed in the development of the real-time communication, what are the accesses to the media for its realization, as well as deliver a one-time code, which will be required from the applicant at the beginning of the communication.

V.

The communication must be carried out in accordance with the dialogue guides established by the Entities, and will be recorded and preserved without edits in its total duration. Additionally, Entities must observe the following:

a)

Register the time and date of the realization of the communication.

b)

Verify that the quality of the image and sound allow the full identification of the applicant, according to the parameters established by the Entities themselves for such purpose.

c)

Corroborate, during the communication with the applicant, the information that this has sent in the form and require him to show the rest of the documentation sent together with it.

In case the applicant is already a Client of the Entity, they must authenticate him using a Category 1 Authentication Factor in accordance with the general provisions for such effect

emit the Commission.

d)

Require the applicant to show their voter credential issued by the National Electoral Institute, both the front and back sides, confirming that it contains the same data and photograph as the credential sent along with the form.

e)

Take images of the applicant and the presented voter credential, on the front and back, in which the date and time they were taken will be stamped, obtained from a protected time server.

f)

Use specialized technology that allows them to achieve reliable identification of the interviewee, with the reliability level established in fraction IV of Article 4 of this Annex, ensuring that there is a match between their face, the photograph of said interviewee, and the photograph of the previously received voter credential. The foregoing will be a condition to proceed to the stage of formalizing the opening of the deposit or credit account to be contracted.

g)

Identify suspicious behavior patterns that might indicate that the person being interviewed is not who they claim to be.

VI.

The Entities shall suspend the contracting process with the applicant when any of the following cases occur:

a)

The image or sound quality does not allow for full identification of the applicant.

b)

The applicant does not present their voter credential; the data obtained from it does not match the records of the National Electoral Institute, or the result of the validation of the elements of the aforementioned voter credential, or of the biometric verifications of the applicant's face, does not reach the effectiveness or reliability level referred to in Article 4, fractions III and IV of this annex.

c)

The Unique Population Registry Key does not match the information in the National Population Registry.

d)

The one-time code required from the applicant is not confirmed by them.

e)

The Entity's personnel having the online communication identifies an atypical or risky situation, or has doubts about the authenticity of the voter credential or the identity of the applicant.

f)

Interruptions occur in the connection.

The technology used for these procedures must be approved by the risk manager or their equivalent or, if they do not have this, by the audit committee, the board of directors, or the sole administrator of the Entity.

Entities may agree during the online communication for the celebration of deposit account contracts referred to in this article, on the contracting of the Electronic Services referred to in the general provisions referred to in the Law associated with such accounts, without allowing that through the services contracted in accordance with what is established in this article, the celebration of operations charged to other accounts of the same Client is instructed. The foregoing prohibition will not apply when the Client goes to the offices to carry out the contracting of the Electronic Services.

Entities must provide in the contracts they conclude with their Clients that when these decide to omit requesting Category 1 Authentication Factor during the online communication referred to in this article and the Clients do not recognize contracts in their name for deposit accounts or credits referred to in this article with the described procedure, they will assume the risks and, therefore, the costs of the credits, making the corresponding clarifications before the credit information companies, as well as the cancellation of the deposit account or credit in question, when so claimed by the Client.

For the purposes of this Annex, Category 1 Authentication Factor and Electronic Services shall be understood as those defined in the General Provisions applicable to savings and popular credit entities, integration organisms, community financial societies, and rural financial integration organisms, referred to in the Savings and Popular Credit Law issued by the Commission or those that replace them.

The procedures established in the articles of this Annex will not be applicable when it comes to the contracts that Entities conclude with their Clients in terms of Chapter VIII of Title Fourth of the General Provisions applicable to savings and popular credit entities, integration organisms, community financial societies, and rural financial integration organisms, referred to in the Savings and Popular Credit Law issued by the Commission or those that replace them.

Article 2.- Entities must have the necessary means for the transmission and safeguarding of the information, data, and files generated in the procedures referred to in Article 1 of this Annex, which guarantee their integrity, the correct reading of the data, the impossibility of manipulation, as well as their adequate conservation and location.

Entities may use technological improvements that help compensate for the clarity of the images, approved by their risk manager or their equivalent or, if they do not have this, by the audit committee, the board of directors, or sole administrator, for such purposes, when identification documents are shown and facial recognition of the applicant is performed.

Article 3.- The Commission may approve non-presidential identification mechanisms for potential Clients other than those indicated in Article 1 of this Annex, provided that Entities demonstrate that the technology used, in the judgment of the Commission itself, is reliable to identify the natural person in question and verify the existence of the Unique Population Registry Key with the National Population Registry or some other verifiable identification element against the records of some Mexican authority, as well as the correspondence of the data.

Article 4.- Entities, when requesting the approvals referred to in Articles 1 and, where applicable, Article 3, must present the following:

I.

The detailed description of the process, which must be approved by the risk manager or their equivalent or, if they do not have this, by the audit committee, the board of directors, or sole administrator, as well as the technological infrastructure used in each part of it.

II.

Regarding identification mechanisms referred to in Article 3, the method of validation of the identification documents that will be admitted to carry out the contracting in question.

III.

Evidence that the means of verifying the validity of the identification documents of Clients or potential Clients have the effectiveness approved by the risk manager or their equivalent or, if they do not have this, by the audit committee, the board of directors, or sole administrator of the Entities.

IV.

Evidence that the facial identification recognitions used have the reliability level determined by the risk manager or their equivalent or, if they do not have this, by the audit committee, the board of directors, or sole administrator.

V.

The image and sound quality standards that will be required to carry out the online communication.

VI.

Where applicable, the description of the Authentication Factors that will be required from the Client.

VII.

The mechanisms through which they will ensure compliance with what is provided in Article 2 of this Annex.

When Entities intend to modify the procedures described in Articles 1 and, where applicable, Article 3 of this Annex, they will require prior approval from the Commission.

Mexico City, March 11, 2019. - The Secretary of Finance and Public Credit, Carlos Manuel Urzúa Macías. - Rubric.

In the document you are viewing, there may be text, characters, or objects that do not display correctly due to conversion to HTML format, so we recommend always taking the digitized image of the DOF or the PDF file of the edition as a reference. The content, form, and scope of published documents are the strict responsibility of their issuer.

CONSULT

BY DATE

Do

Lu

Ma

Mi

Ju

Vi

INDICATORS

Exchange Rate and Rates as of 08/28/2026

DOLLAR

16.9712 UDIS

8.808812 TIIE 28 DAYS

6.7559% TIIE 91 DAYS

6.7931% TIIE 182 DAYS

6.8474% TIIE DE FONDEO

6.50%

See more

SURVEYS

Did you like the new image of the Official Gazette website?

No

Yes

Official Gazette of the Federation

Río Amazonas No. 62, Col. Cuauhtémoc, C.P. 06500, Mexico City Tel. (55) 5093-3200, where you can access our service menu

Electronic address: dof.gob.mx

113

LEGAL NOTICE | SOME RIGHTS RESERVED © 2026

More like this from SHCP

SHCP published 14 documents in the last 30 days. We email you each new one the day it's published.

Topics
Share