BANKING AND FINANCE / by Miguel Gallardo Guerra
The discussion surrounding instant payments, real-time transfers, and payment infrastructure has taken on increasing global significance. In various jurisdictions, the modernization of payment systems is no longer viewed solely as an operational improvement or a competitive advantage. It is now understood as a strategic component of financial inclusion, economic efficiency, competition, traceability, and the resilience of the financial system.
In this context, it is natural to wonder what Mexico can learn from international experience. The question is particularly relevant because the country already has infrastructure that places it in a key position within the regional conversation on digital payments.
The Interbank Electronic Payment System, hereinafter referred to as “SPEI,” enables virtually immediate transfers between accounts at different financial institutions and operates continuously. Services have also been developed on this infrastructure to facilitate the initiation and receipt of payments via mobile devices.
However, international trends show that the value of instant payments does not depend solely on the existence of a technological means to move funds quickly. It also depends on how regulation, operational governance, and institutional coordination support that infrastructure.
Speed alone isn't enough
One of the key lessons learned internationally is that instant payments should not be analyzed solely from the perspective of speed. The ability to credit funds in seconds represents a significant advance, but it does not in and of itself guarantee a more secure, competitive, or reliable payments ecosystem.
For these benefits to be realized, there must be clear rules regarding access to the system, participant responsibilities, interoperability standards, user authentication, operational continuity, information security, incident response, and the handling of unrecognized transactions.
In other words, immediacy must be built on a foundation of control, legal certainty, and trust.
This consideration is particularly important because, in a system that processes transactions in seconds, the window of opportunity to stop or correct a transfer after it has been executed may be limited. Therefore, regulation and internal controls must increasingly focus on the stages prior to transaction authorization.
These controls include validating beneficiary data, identifying unusual patterns, strong authentication, clearly displaying warnings to users, and timely monitoring of transactions.
Interoperability, Competition, and Access
Another important principle is interoperability. The modernization of payment systems has been accompanied by discussions regarding non-discriminatory access, message standardization, compatibility between infrastructures, and the reduction of excessive dependence on certain participants.
For Mexico, this point is particularly important given the growth of models involving banks, electronic payment providers, financial companies, aggregators, technology providers, and companies that offer payment initiation, processing, or reconciliation solutions.
Technological infrastructure can facilitate interoperability, but its sustainable implementation requires sufficiently robust legal and operational definitions. It must be specified who can access the system, under what conditions, through what contracts and standards, with what information, and subject to what risk management obligations.
Access should promote competition and innovation, but it cannot be achieved through an indefinite transfer of risks to direct participants or end users.
Mexico isn't starting from scratch
Mexico has a robust legal, technological, and institutional framework. The SPEI is the primary infrastructure for interbank electronic transfers and has enabled the development of various financial and technological models that rely on the receipt and transmission of funds in near real time.
In addition, Mexican regulations have evolved to address issues that align with international trends, including indirect participation in the SPEI, the use of third parties, risk management, cybersecurity, and user experience.
Indirect participation allows certain entities to access the system's services through a direct participant. This arrangement broadens access opportunities, but it also makes it necessary to precisely define the responsibilities of each party.
The existence of a technological connection does not eliminate the need to identify which entity is responsible for customer authentication, transaction monitoring, service continuity, information retention, handling complaints, and incident management.
Furthermore, recent amendments to the SPEI Rules—in particular Circular 9/2026, published in the Official Gazette of the Federation on June 17, 2026—reflect increased regulatory attention to the way users initiate transfers from mobile devices. This development is significant because it recognizes that the user experience is also part of the control environment.
The way an application displays the originating account, the payee, the amount, the reference, the transaction status, and any prior warnings can have a direct impact on the risk of error or fraud. Consequently, the interface is no longer merely a business or design decision; it also becomes a relevant issue from a regulatory perspective.
Risk Management and Fraud Prevention
Instant payments offer clear benefits, but they also alter exposure to operational, technological, and fraud risks.
The faster a system is, the less time there is typically to identify an anomaly, confirm an instruction, or halt an operation before resources are allocated. For this reason, preventive controls take on central importance.
One area where Mexico could improve is by continuing to strengthen the validation mechanisms that take place before transfers are authorized. The information displayed to the user must be clear enough to allow the user to identify errors or inconsistencies before confirming the transaction.
Fraud prevention also requires collaboration. Financial institutions, technology providers, telecommunications companies, and authorities may each have different pieces of information regarding the same suspicious transaction.
The development of mechanisms for information sharing could strengthen the system’s response capacity, provided that applicable obligations regarding the protection of personal data, financial confidentiality, information security, and the prevention of transactions involving funds of illicit origin are respected.
Traceability and Allocation of Responsibilities
In modern payment systems, it's not just important that the transaction takes place. It's also important that it can be reconstructed, audited, and explained.
Traceability requires retaining sufficient information regarding the initiation, authentication, processing, settlement, and crediting of a transfer. It also requires that the responsibilities among direct participants, indirect participants, and technology providers be clearly documented.
This clarity is particularly important when a single transaction involves different entities and service providers. Operational fragmentation should not result in uncertainty for the user or make it difficult to determine who is responsible for handling a complaint, investigating an incident, or addressing a failure.
Contracts between participants and technology providers must adequately reflect these responsibilities. It is not enough to simply establish service levels; obligations related to security, continuity, collaboration, information retention, auditing, incident response, and regulatory compliance must also be addressed.
The Next Step for Mexico
Mexico doesn't need to start from scratch. It has a well-established infrastructure, proactive authorities, and a market with a high level of technology adoption.
True international learning is not just about adopting faster speeds or new features. It involves recognizing that instant payments are part of a broader transformation of the financial system.
This transformation requires that efficiency, competitiveness, regulatory compliance, user protection, traceability, cybersecurity, and resilience advance in a coordinated manner.
For Mexico, examining international experience should not be an exercise in automatically replicating foreign models. It should be an opportunity to identify principles that strengthen the functioning of the domestic market and to determine which issues should be addressed through regulatory provisions, internal rules, technical standards, or contractual agreements.
The next phase of instant payments will not depend solely on how quickly funds can be transferred. It will depend on the system’s ability to do so in a secure, interoperable, understandable, and legally reliable manner.


For more information, please contact us at:
mgallardo@bgbg.mx
Visit the
