25 years
of experience
We have obtained
20+ Awards
Time in Mexico

From the Amendment to the Federal Law on the Prevention and Identification of Transactions Involving Illicit Funds to the General Rules: The Path to Compliance with Anti-Money Laundering Regulations

On July 16, 2025, the Decree amending and adding various provisions to the Federal Law for the Prevention and Identification of Transactions Involving Proceeds of Illicit Activities (“LFPIORPI” or “the Law”), as well as Article 400 Bis of the Federal Criminal Code, was published in the Official Gazette of the Federation (“DOF”), with the aim of strengthening the National Anti-Money Laundering System and fulfilling Mexico’s commitments to the Financial Action Task Force (“FATF”). Essentially, this reform expanded the list of Vulnerable Activities; modified the definition of Controlling Beneficiary and added obligations regarding its identification; incorporated various authorities into the National Anti-Money Laundering System; established an annual audit as a requirement; adjusted the rules governing the self-correction process; and introduced mandatory annual training for the Compliance Officer, among other changes.

A significant portion of these obligations was subject to the update of the LFPIORPI Regulations (the “Regulations”) and the General Rules (“RCG”). The first part of this update came in March 2026, with an amendment to the Regulations that clarified the powers of the Tax Administration Service (“SAT”), the logic behind the aggregation of transactions and the 24-hour notice requirement, and the regime applicable to Politically Exposed Persons (“PEPs”), among other aspects. The second part—and the central focus of this analysis—is the amendment to the RCG issued by the Ministry of Finance and Public Credit on August 7, 2026.

This reform of the RCG introduces twelve key areas of change, ranging from the Risk-Based Approach to the Controlling Beneficiary, automated monitoring mechanisms, and the annual audit, with the obligations taking effect in phases between 2026 and 2028. This analysis focuses on those twelve key areas and what they mean for the day-to-day operations of regulated entities, and concludes with a timeline that chronologically outlines the recommended actions for compliance. For each key area, the source of the obligation is indicated—whether in the Law or the Regulations—since the RCG, for the most part, do not create new obligations but rather operationally complement the aforementioned reforms.

Registration and Reporting of Vulnerable Activities

The reform strengthens the registration process for Vulnerable Activities. Article 17 of the Law defines who engages in Vulnerable Activities, and Article 18, Section IV Bis, requires them to register with the Registry through the Portal. The RCG adds a specific registration regime for those acting through trusts or other legal entities, such as joint ventures.

The reforms are particularly relevant for those who offer virtual asset exchange services. Those who have not yet registered must submit the information required under Article 10 Bis when applying for registration on the Portal; those who were already registered prior to the entry into force of the amendments to the RCG must update their information no later than May 30, 2027 (six months following the entry into force, in accordance with Transitory Provision No. 12). In addition, several of the identification annexes were amended with substantive changes that require updating internal processes and forms. The most significant changes are: (i) the express exclusion of the professional license as a valid identification document in all Annexes pertaining to clients or users; (ii) the replacement of the questionnaire regarding the Controlling Beneficiary with an obligation to effectively identify the Controlling Beneficiary, applicable to legal entities, trusts, and international organizations; (iii) the inclusion of two new Annexes (2 Bis and 2 Ter) that require mapping and recording the complete structure of trusts and other legal entities through which the Vulnerable Activity is conducted; (iv) the express authorization of electronic signatures for the declaration regarding the Controlling Beneficiary in files pertaining to individuals, which allows for the remote formalization of client onboarding processes; and (v) the obligation to identify the Controlling Beneficiary of the Member Entity itself when requesting the agreement for the collective filing of reports.

Risk-Based Approach

The requirement to adopt a Risk-Based Approach (“RBA”) is not established by the RCG. It was incorporated following the amendment to Article 18, Section VII, of the LFPIORPI, which requires those engaged in Vulnerable Activities to conduct an assessment to identify, analyze, and mitigate risks posed by their clients or users. However, the transitional provisions of the Act made its entry into force contingent upon the RCG. Therefore, following the amendment to the RCG, Chapter II-Quater incorporated the requirement to have a methodology that must allow for the identification, analysis, understanding, measurement, and mitigation of risks arising from Vulnerable Activities, taking into account at least the type of acts or operations performed, the customers or users, the countries and geographic areas involved, as well as the transactions and channels used. Existing controls or mitigating measures must also be identified, and their effective implementation must be evaluated. The methodology must be set forth in the Internal Policies Manual or another document, take into account applicable information from the National Risk Assessment and its updates, and be based on operational data covering a period of no less than twelve months. Furthermore, there must be consistency between the data used for the assessment and that contained in automated systems.

An important point is that the assessment must also be conducted before implementing new media, channels, formats, products, or services, or before targeting new types of customers or users. This incorporates risk analysis into decisions that previously might have been considered primarily commercial or operational. Furthermore, the SAT may review the methodology and mitigating measures, require adjustments, and request action plans; thus, the assessment becomes a supervisable component of the compliance system and not merely an internal document. It must be made available to the authority, upon request, as of March 1, 2027.

Risk Level and Transaction Profile

The reform introduces a second level of analysis: in addition to the overall risk to which the regulated entity is exposed, the individual risk level of each customer or user must be assessed.

Article 23 Bis requires the establishment of at least three risk categories: low, medium, and high; Article 23 Bis 1 mandates that the customer or user be reassessed at least every six months, with the frequency increased when their risk level is higher. To determine the risk category, Article 23 Bis 2 considers factors such as:

  • economic activity
  • nationality
  • residence
  • sources of income
  • Purpose of the Relationship 
  • volume 
  • frequency
  • total volume of transactions
  • origin
  • allocation of resources.

The Transactional Profile is also formally introduced, which aims to determine the expected behavior of each customer by taking into account the available information, the number and amount of transactions, their frequency, and the origin and destination of the funds. On that basis, an alert system must be implemented to identify changes or deviations in their behavior in a timely manner.

Previously, the 2025 reform amended Article 18, Section I of the LFPIORPI to strengthen the obligation to identify and personally verify clients or users and to verify their identity. The key aspect of this reform is that the obligation to “identify and understand” is divided into a documentation component and a monitoring component throughout the business relationship, distinguishing between two complementary obligations: identification (compiling the file with the client’s or user’s data and documents at the start of the relationship) and understanding the client (comprehending their activities, the source of their funds, and their expected behavior during the business relationship); the reform reinforces the latter in particular. While previously it was already required to verify at least once a year that client or user files were complete and up to date, now understanding the client must also extend to their behavior throughout the relationship.

In practice, a transaction that individually does not exceed the threshold may trigger an alert if it deviates significantly from what the regulated entity knows about the customer. Thus, the information gathered during the identification process is no longer merely documentary and begins to have implications for monitoring, risk classification, and the eventual filing of reports. These internal policies of entities engaged in Vulnerable Activities must be fully defined by March 1, 2027. 

Politically Exposed Persons

The new RCG include a specific chapter on Politically Exposed Persons. Pursuant to Article 23-Quater, a PEP is defined as a natural person who holds or has held relevant public office, in Mexico or abroad, such as heads of state or government, political leaders, high-ranking government, judicial, or military officials, senior executives of state-owned enterprises, and officials or prominent members of political parties and international organizations. This category also includes spouses, common-law partners, relatives by blood or marriage up to the second degree, and partners or associates with financial ties. A domestic PEP retains that status for one year following separation from office.

To verify this status, Article 23-Quater 1 introduces, for the first time, the option to consult the “Consulta PEP 2.0” application of the Financial Intelligence Unit (“UIF”), a mechanism that may be used both by those engaged in Vulnerable Activities—using their Advanced Electronic Signature—and by Financial Institutions, subject to authorization by the UIF. When a customer or user is a PEP and also has a high risk rating, enhanced due diligence measures must be applied: obtaining approval from a senior manager, or documenting the reasons—when the person conducting the Vulnerable Activity is an individual—before entering into the transaction or operation; and, in the case of foreign PEPs, collecting additional documentation. The PEP 2.0 query tool will be available nine months after the regulations take effect. Given that the amendment to the General Regulatory Framework (RCG) will take effect on November 30, 2026, the tool is expected to become available for use as of August 30, 2027.

Controlling Beneficiary

The July 2025 legal reform already modified the concept of “Controlling Beneficiary”: it reduced the control threshold from 50% to 25%, created Chapter IV Bis requiring registration with the Ministry of Economy, and equated the term with “ultimate beneficiary” and “beneficial owner.” 

However, the RCG elaborate on the operational aspects of those obligations. Previously, the RCG did not contain any section dedicated to the Controlling Beneficiary; the identification of the then-called “Beneficial Owner” was addressed through a few references in Article 12 and its annexes. The new RCG create Chapter III Quinquies, “On the Controlling Beneficiary” (Articles 23 Quinquies through 23 Quinquies 3), which constitutes the most significant development in this area; within this chapter, they introduce a hierarchical methodology to identify, in all cases, the Controlling Beneficiary of a corporate client and, where applicable, of individual clients. A sequential order is now established, consisting of first identifying whoever directly or indirectly holds 25% or more of the share capital; if this does not allow for identification, whoever exercises control through other means related to strategy, management, or decision-making; and, failing that, the highest-ranking officer.

In the case of trusts, the new RCG specify for the first time who may be considered a Controlling Beneficiary (trustees, settlors, beneficiaries, protectors, members of the technical committee) and require tracing the chain of ownership and control upward when any of these parties is itself a legal entity or legal structure, until reaching the individual who ultimately exercises control.

It is important to distinguish this identification—which regulated entities perform with respect to their customers—from a separate and broader obligation introduced by the Law in 2025 in Chapter IV Bis: the obligation for business entities themselves to identify their own Controlling Beneficiary and record that information in the electronic system to be administered by the Ministry of Economy (Articles 33 Bis and 33 Ter of the Act). The amended General Regulatory Rules (RCG) do not address this corporate obligation, but only the identification obligation of those engaged in vulnerable activities with respect to their customers; therefore, both regimes coexist in parallel.

Furthermore, the new RCG expressly require that the procedure followed to identify the Controlling Beneficiary—not just the result—be documented, that the supporting information and records be retained, and that they be kept up to date throughout the duration of the business relationship. A closed list of exceptions is also reaffirmed, under which it will not be necessary to collect the Controlling Beneficiary’s information: when the client is listed on a Mexican stock exchange or on recognized foreign markets, or when the client is one of the legal entities listed in Annexes 4 Bis, 6 Bis, 7-A, and 7 Bis-A of the RCG.

Another significant change is that the RCG links the identification of the Controlling Beneficiary to the new risk assessment methodology, which has also been newly established: Article 23 Bis 4 of the RCG requires that certain nonresident customers associated with high-risk jurisdictions or preferential tax regimes, as well as foreign Politically Exposed Persons, be classified as high risk.

In addition, Article 23 Quinquies 3 authorizes the FIU to issue guidelines, following consultation with the SAT, for compliance with this entire chapter; these guidelines will be published on the website without the need to amend the RCG. 

24-Hour Notices

In addition to the notification system based on amounts, the amendment specifies the 24-hour Notice (Article 7 Bis of the Regulations), which applies even when the transaction is not ultimately concluded, and details the Reports, a concept that the amended Regulation incorporated as a separate category in Article 2 (defined as those filed in accordance with general rules), distinct from Notices, over which the SAT exercises authority for receipt and supervision.

Reports of Suspicion 

The reform links the new Transaction Profiles and alert systems to the filing of a Suspicion Report. Based on knowledge of the customer and their expected behavior, transactions or conduct that deviate from that profile must be detected, analyzed, and assessed to determine whether there are elements linking them to transactions involving funds of illicit origin. A deviation from the Transaction Profile triggers an alert and requires analysis, but does not automatically necessitate filing a Suspicion Report within 24 hours: such a report is only required when the analysis reveals evidence linking the transaction to funds of illicit origin and allows for the identification of the person involved.

InternalPoliciesManual

The Internal Policy Manual is a requirement under Article 18, Section VIII of the Law, which refers to the RCG for its implementation. Previously, the RCG already required a document setting forth guidelines for customer identification and certain internal criteria, measures, and procedures; however, the new RCG replace that approach with a comprehensive Internal Policy Manual, which must incorporate the risk methodology and contain procedures related to customer identification and knowledge, risk classification, due diligence, PEPs, transaction profiles, alerts, accumulation of transactions, training, auditing, and other elements required by the RCG.

In addition, the Manual must establish the criteria for determining the initiation, limitation, or termination of business relationships, which must be consistent with the risk methodology. The SAT may even order modifications when it deems them necessary for proper compliance with the Rules. The updated Manual, including the risk methodology as well as the other requirements of the Manual stipulated in the current RCG, must be available as of March 1, 2027.

Automated Mechanisms 

Monitoring through automated mechanisms is a requirement under Article 18, Section X of the Law, which was incorporated in 2025; the operational details were set forth in the General Tax Regulations (RCG). Automated mechanisms may be implemented using spreadsheets, databases, or other equivalent means—not necessarily specialized software—provided they fulfill the required functions and can be verified by the authority.

These mechanisms must, among other functions, allow for the storage and retrieval of records, the consolidation of transactions carried out by a single customer, the detection of deviations from the customer’s Transaction Profile, the aggregation of data, the feeding of the risk methodology, the execution of the customer classification model, and the generation of alerts. In addition, the history of changes to the Risk Level and Transaction Profile must be retained for a period of no less than ten years, and these mechanisms must be implemented no later than June 1, 2027.

Electronic Notifications

The reform also modifies the authority’s notification system. Checking the Portal, which was previously required every two weeks, is now mandatory at least once per business day (Articles 5 and 6 of the RCG), and electronic notification is deemed to have been delivered on the fourth business day following its dispatch, even if the obligated party has not opened it. In practice, it is advisable to designate a person responsible for the daily check and a substitute, and to maintain an access log, since the deadlines will run regardless of whether the Portal is checked or not.

Audit

The new RCG also complement the requirement to submit the annual audit provided for in Article 18, Section XI of the Law, which took effect in 2025; the audit must cover the period from January 1 to December 31 of each year, and the audit report must be submitted no later than the last business day of March following the year under audit. 

In accordance with Article 12 Bis of the Regulation, which already requires obtaining and retaining the findings of internal or external audits, as well as documentation verifying the correction of observations or inconsistencies, the RCG provide more detailed regulations regarding the frequency, scope, and evidence required to support this process. 

The audit aims to assess the consistency between the provisions of the Internal Policy Manual, the risk methodology, and customer classification, and what actually occurs in operations. 

The type of auditor will depend on the regulated entity’s risk level: when the risk is low or medium, an internal audit is sufficient, and it may be conducted voluntarily by an external, independent person; if the risk is high, then the audit must be conducted by an external, independent person. This person must hold a valid certification issued by the FIU and comply with strict rules regarding independence from the regulated entity.

The first annual audit period will run from January 1 to December 31, 2028, and the audit report must be delivered to the auditee no later than the last business day of March 2029. The supporting documentation for that report, as well as evidence of the correction of findings, must be retained for a period of no less than five years, in accordance with Article 51 of the RCG, counted from the date the report is delivered, and submitted to the SAT when requested. 

Training and Selection

The new RCG guidelines now outline the minimum training content, its relationship to the EBR methodology, the required experience of those who deliver the training, the evidence that must be retained, and the requirements applicable to the selection process. 

Entities engaged in Vulnerable Activities must implement training programs for members of the board of directors, the sole administrator, executives, officers, the Compliance Officer, and employees who interact with the public, identify customers, send notices, or conduct audits. 

Courses must be offered at least once a year, be consistent with the risk methodology, and be taught by individuals with at least five years of experience in the field. Documentary evidence of the training must be retained for a minimum of ten years (Article 39 Bis 1).

Furthermore, during the hiring process, a signed statement must be obtained regarding the candidate’s prior experience in regulated sectors and confirming the absence of convictions for property crimes or disqualifications. 

Nonprofit Associations and Organizations

The reform also includes specific measures targeting associations and nonprofit organizations. Pursuant to Articles 38 Bis through 38 Bis 2, the Financial Intelligence Unit (UIF) will apply proportionate, risk-based measures related to the offense set forth in Article 139 Quater of the Federal Criminal Code, which will include training and outreach programs, as well as the monitoring of transactions involving high-risk donors or countries. 

Compliance Schedule

Date RationaleRecommended Action
August 7, 2026Publication in the Official Gazette of the Federation (DOF) of Agreement 115/2026 (amendment to the General Tax Regulations). It is issued pursuant to Article 6, Section VII of the Law.N/A
November 30, 2026General entry into force of the new RCG (First Transitory Provision). This stems from the transitional provisions of the 2025 Law reform, which deferred the effective date of the RCG.As of that date, the new RCGs become mandatory, and the deadlines described in this timeline begin to run.
January 1, 2027Start of the first annual training period (Transitory Provision No. 7; Art. 39 Bis). Law: Art. 18, subpar. IX, and Art. 20.Conduct, at least once a year, training courses or workshops for the board of directors, the sole administrator, executives, officials, the Compliance Officer, and staff who interact with the public, identify customers, send notices, or conduct audits (Art. 39 Bis).
March 1, 2027Risk methodology available to the authority upon request (Second Transitory Provision). Law: Art. 18, Section VII (and Art. 19, simplified measures based on risk).Make the Risk-Based Approach methodology available to the authority upon request.
March 1, 2027Updated Internal Policies Manual, including the risk methodology (Third Transitory Provision). Law: Art. 18, Section VIII.Have an updated Internal Policy Manual that incorporates the risk methodology, as well as the criteria and procedures for complying with each of the obligations related to AML/CFT (Art. 37 Bis).
March 1, 2027Classification by Risk Level, Transaction Profile, and Controlling Beneficiary Procedure applicable to acts or transactions (Fourth Transitory Provision). Law: Art. 18, subsections I and III.Classify transactions or operations by risk level (low, medium, or high) and transaction profile, and document the procedure for identifying the Controlling Beneficiary.
March 1, 2027New personnel selection procedures applicable to new hires (Transitory Provision Six; Art. 39 Bis 2). Law: Art. 18, para. IX.Apply the personnel selection procedures to new hires, including the signed statement provided for in Article 39 Bis 2.
May 30, 2027Deadline (6 months from the effective date) to update the information required under Article 10 Bis, applicable to those who regularly and professionally offer virtual asset exchange services.Service providers with virtual assets already registered prior to the entry into force of the amendments to the RCG must update and submit the information required under Article 10 Bis.
June 1, 2027Deadline for implementing automated mechanisms (Transitory Provision No. 9; Art. 41). Law: Art. 18, para. X.Automated mechanisms must fulfill the functions set forth in Article 41 of the RCG.
July 30, 2027Deadline (8 months from the effective date) for the Secretariat to implement the electronic notification system.Obligation applicable to the Secretariat.
No later than August 30, 2027Deadline (9 months from the effective date) for making inquiries to the Financial Intelligence Unit (FIU) regarding Politically Exposed Persons (PEPs) available through the Consulta PEP 2.0 application.As of this date, the FIU may be consulted when it cannot be determined whether a customer or user is a politically exposed person.
December 31, 2027End of the first annual training period (Transitory Provision No. 7). Law: Art. 18, para. IX, and Art. 20.Retain documentary evidence of the training for a minimum period of ten years (Art. 39 Bis 1).
January 1, 2028Beginning of fiscal year 2028, the first period subject to annual audit (Eighth Transitory Provision; Art. 42). Law: Art. 18, subpar. XI; Regulations: Art. 12 Bis.Begin compiling evidence for fiscal year 2028 (risk methodology, customer classification, transaction profile, alerts, and other controls outlined in the Internal Policies Manual) to support the corresponding internal or external audit.
December 31, 2028End of fiscal year 2028, the period covered by the first annual audit.The deadline for the auditor to assess compliance effectiveness for 2028 and issue the audit opinion begins on this date.
Last business day of March 2029 Deadline for issuing the audit opinion for the first annual audit, covering fiscal year 2028.Receive the audit report and present the results to the board of directors, senior management, or equivalent body; follow up on corrective action programs.
Date to be determinedThe new notices must be sent 6 months after the resolution establishing the new official forms takes effect.No action is required until the resolution establishing the new official forms is published; once it takes effect, there will be a 6-month period to comply.

Conclusion

This reform shifts the focus from compliance with a documentary model—complete files, timely filings—to a model of continuous monitoring, in which customer due diligence, risk classification, and automated monitoring must be consistently maintained and available for review by the SAT at any time. Regulated entities that currently comply only with the documentation standard will face, in 2027 and 2028, requirements for traceability, technology, and evidence that cannot be improvised on the fly.

The March and June 2027 deadlines leave less than a year of actual leeway to: (i) redesign the EBR methodology and the Internal Policy Manual; (ii) build or adapt the automated mechanisms required by Article 41; and (iii) determine whether the 2028 audit will be conducted by internal staff or whether it will be necessary to hire an external auditor certified by the FIU—a decision that should be made well in advance.

If your organization engages in Vulnerable Activities and wishes to assess the specific impact of the reforms, our AML/CFT compliance team is available to conduct a gap analysis against these obligations and support your implementation roadmap.

 

For more information on the amendment to the LFPIORPI Regulations, visit