Mexico KYC & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Mexico.

Direct answer
What does the Mexico compliance checklist cover?
The Mexico checklist translates primary KYC, KYB and AML rules into 11 control areas and 44 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- National FIU
- Unidad de Inteligencia Financiera (UIF) within SHCP
- Core framework
- LFPIORPI, last reformed 16 July 2025, plus sector financial laws and general provisions
- Vulnerable-activity 24-hour notices
- Legacy cases remain operative; broadened 2025 scenarios, including attempted operations, depend on updated official notice annexes
- Routine vulnerable-activity notices
- By the 17th day of the immediately following month when the applicable article 17 notice threshold is met
- Retention
- At least 10 years for financial entities and, after the 2025 reform, generally for vulnerable-activity records
- Beneficial owner
- LFPIORPI control includes more than 25% voting rights; the separate tax-accounting test in the Federal Fiscal Code uses more than 15%
- Vulnerable-activity thresholds
- Activity-specific multiples of the daily UMA; apply the current UMA and six-month aggregation rule
- Financial-sector reporting
- Sector-specific relevant, unusual, internal-concern, 24-hour and other reports through the applicable supervisor channel
- Privacy authority
- Secretaria Anticorrupcion y Buen Gobierno under the 2025 private-sector data law
- Fintech authorization
- CNBV authorization, with inter-institutional approval, is required to organize and operate as an ITF
- FATF status
- FATF member; not named on the public call-for-action or increased-monitoring lists reviewed 31 July 2026
Implementation detail
Mexico compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities and licensingMexico has no single operating rulebook for every business. Resolve whether the entity is a regulated financial entity, an article 17 vulnerable-activity operator, both, or outside those perimeters before configuring controls.4 items+
Financial entities are subject to LFPIORPI and the special laws and general provisions governing their sector.
- Implementation action
- Classify the exact legal entity, product and activity; map SHCP, UIF, CNBV, CNSF, CONSAR and Banco de Mexico responsibilities and use the current sector rule set.
- Evidence to retain
- Perimeter memorandum, authorization and register extracts, authority matrix, current-rule inventory and counsel approval.
- Primary citation
- LFPIORPI arts. 13-16
Non-financial vulnerable activities are the activities and thresholds listed in LFPIORPI article 17, including covered real estate, credit, professional services, value instruments and virtual-asset services.
- Implementation action
- Test each Mexican and Mexico-directed service against every relevant article 17 limb, including activities conducted through trusts or other legal arrangements.
- Evidence to retain
- Activity map, threshold analysis, six-month aggregation logic, cross-border nexus assessment and signed applicability decision.
- Primary citation
- LFPIORPI arts. 17-19; SAT LFPIORPI criteria
A person carrying on a vulnerable activity must register and maintain its SAT portal status when the operative official format covers that person and activity.
- Implementation action
- For covered categories, complete registration before the first notice using valid RFC and e.firma credentials. Track the Regulation's Third Transitory deferral for article 17(XII)(D), persons acting through trusts or other legal arrangements, customs agencies and specified article 17(XIV) legal persons until the format expressly identifies them.
- Evidence to retain
- Applicability and transition check, registration receipt where available, portal profile, credential-control record, updates, owners and monitoring log.
- Primary citation
- LFPIORPI art. 18(IV Bis); 27 March 2026 Regulation decree transitory art. 3; SAT SPPLD obligations
Organizing and operating as a financial-technology institution requires CNBV authorization following the statutory inter-institutional process.
- Implementation action
- Do not market or operate regulated crowdfunding or electronic-payment-fund services without the required authorization; verify the live CNBV register and any Banco de Mexico permissions.
- Evidence to retain
- Perimeter opinion, application, authorization, register extract, conditions, launch approval and continuing-obligation map.
- Primary citation
- Fintech Law arts. 3, 11 and 35-45
02Governance, risk assessment and transitionFinancial-sector governance is set by sector provisions. For vulnerable activities, distinguish duties already in force from the staged article 18(VII-XI) duties whose commencement depends on revised general rules.4 items+
A legal person or legal arrangement carrying on vulnerable activities must designate and maintain a compliance representative; absent an accepted designation, statutory responsibility falls to the persons identified in article 20.
- Implementation action
- File and maintain the designation, protect the representative's identity, document deputies and escalation, and ensure annual training required by article 20.
- Evidence to retain
- Portal acceptance, appointment, role description, board minutes, confidentiality controls, training and succession plan.
- Primary citation
- LFPIORPI arts. 20 and 38
The 2025 reform added vulnerable-activity risk assessment, internal manual, group policy, annual training, automated monitoring and risk-based annual audit duties.
- Implementation action
- Build these controls now, but label their statutory commencement accurately and monitor revised general rules and SAT criteria for the applicable dates and minimum elements.
- Evidence to retain
- Transition tracker, official-source snapshots, risk assessment, manual, group standard, training plan, system specification and audit plan.
- Primary citation
- LFPIORPI art. 18(VII-XI); 16 July 2025 reform transitory arts. 2-3; SAT criteria
Financial entities and ITFs must maintain risk-based policies, automated systems, responsible governance, training and annual independent or internal review under their applicable sector provisions.
- Implementation action
- Map each requirement to the entity's exact general provisions and authorization conditions; do not transplant a bank threshold or deadline into another sector.
- Evidence to retain
- Enterprise and customer-risk methods, approved manual, committee records, officer certification, system tests, training and annual audit.
- Primary citation
- LFPIORPI art. 15; Fintech Law art. 58; applicable SHCP general provisions
Policies must cover customers, users, representatives, beneficial owners, products, channels, geography, PEPs, high-risk relationships and attempted operations.
- Implementation action
- Create legal-entity and sector-specific risk taxonomies and approval paths; record why simplified, standard or enhanced measures apply.
- Evidence to retain
- Risk factors, scoring method, overrides, approvals, quality assurance, model validation and change log.
- Primary citation
- LFPIORPI arts. 3, 18 and 20; applicable sector general provisions
03Natural-person KYC and representativesIdentification evidence and thresholds vary by sector and vulnerable activity. The control must bind a real person to reliable evidence and preserve the information required by the applicable official annex or sector provision.4 items+
A vulnerable-activity operator must directly identify and know its customer or user, verify identity using officially recognized documents or means, and retain a copy as required by the general rules.
- Implementation action
- Collect the applicable identity data, authenticate the evidence, bind it to the applicant, screen it for fraud and retain the required record before the activity proceeds.
- Evidence to retain
- Identity file, document images, authenticity result, biometric or liveness output where used, timestamps, reviewer and exceptions.
- Primary citation
- LFPIORPI art. 18(I); LFPIORPI General Rules annexes
For a business relationship, vulnerable-activity operators must obtain occupation or activity information, including by reference to RFC registration and updates.
- Implementation action
- Capture occupation, employer or business activity, purpose, expected activity and source information proportionate to risk; reconcile material inconsistencies.
- Evidence to retain
- RFC evidence, customer profile, purpose, expected activity, discrepancy resolution, approval and refresh schedule.
- Primary citation
- LFPIORPI art. 18(II)
A representative must be identified and their authority to act must be validated under the applicable identification rules.
- Implementation action
- Verify the representative as a natural person, obtain the mandate or power, check its scope and validity and link it to the customer file.
- Evidence to retain
- Representative KYC, power or mandate, registry or notarial check, authority analysis, expiry and approval.
- Primary citation
- LFPIORPI art. 18; General Rules annexes; applicable sector general provisions
If a vulnerable-activity customer or user refuses information or documents required by LFPIORPI, the operator must abstain from carrying out the act or operation.
- Implementation action
- Prevent completion, preserve the refusal and attempted-operation record, assess any operative legacy 24-hour notice case and the staged broadened article 18(VI) scenario, and avoid prohibited disclosure.
- Evidence to retain
- System block, refusal record, escalation, transition-aware notice decision, filing receipt if applicable and communication log.
- Primary citation
- LFPIORPI arts. 18(VI), 21 and 38; 27 March 2026 Regulation decree transitory art. 5
04KYB, registries and beneficial ownershipCustomer KYB, the customer's own corporate and tax filing duties, and AML beneficial-owner verification are separate controls. A registry result does not replace ownership and control analysis.4 items+
For a legal person, trust or other legal arrangement, a vulnerable-activity operator must obtain officially recognized evidence identifying the beneficial owner.
- Implementation action
- Trace ownership and control to natural persons, identify the person on whose behalf the act occurs and corroborate customer declarations with reliable independent sources.
- Evidence to retain
- Constitutional documents, RPC and PSM results, ownership chart, control analysis, declarations, corroboration and reviewer sign-off.
- Primary citation
- LFPIORPI arts. 3(III), 18(III) and 33 Bis-33 Quater
The LFPIORPI control test includes the ability to exercise more than 25% of voting rights, but also covers appointment power, contractual control and direction of administration, strategy or principal policies.
- Implementation action
- Do not use 25% as the sole beneficial-owner test; evaluate direct, indirect, contractual and de facto control and the ultimate beneficiary of the act or service.
- Evidence to retain
- Cap table, indirect calculations, voting and shareholder agreements, board rights, control memorandum and escalation.
- Primary citation
- LFPIORPI art. 3(III)
The Federal Fiscal Code creates a separate accounting record and on-request disclosure regime using a more-than-15% voting-control limb and a 15-calendar-day update duty after changes.
- Implementation action
- Maintain a distinct tax beneficial-controller file, update changes within 15 calendar days and be ready to respond to an SAT request within the statutory period.
- Evidence to retain
- Tax BO register, source documents, change log, 15-day control, SAT response pack and delivery receipt.
- Primary citation
- Federal Fiscal Code arts. 32-B Ter, 32-B Quater and 32-B Quinquies
Mercantile companies must maintain corporate ownership records and comply with applicable electronic notices, while the RPC and PSM publish different categories of corporate information.
- Implementation action
- Query the national RPC and PSM, obtain current corporate books and filings and reconcile inconsistencies; do not assume either public system is a complete AML beneficial-owner register.
- Evidence to retain
- RPC folio, PSM notices, shareholder or quota register, transfer records, discrepancy analysis and remediation.
- Primary citation
- General Law of Commercial Companies arts. 73, 128-129; LFPIORPI arts. 33 Bis-33 Ter; RPC and PSM guidance
05PEPs, EDD and remote onboardingPEP and enhanced measures depend on the applicable sector rules and, for the new vulnerable-activity framework, the revised general rules. Remote identity does not reduce the accountable entity's duty.4 items+
LFPIORPI now defines domestic and foreign PEPs and requires vulnerable-activity internal policies to identify and follow transactions involving PEPs.
- Implementation action
- Screen customers, users, representatives and beneficial owners; document the public function, relationship, risk, approval, source of wealth and source of funds where proportionate and required.
- Evidence to retain
- PEP screening, role and relationship analysis, approval, wealth and funds evidence, monitoring plan and review date.
- Primary citation
- LFPIORPI arts. 3(IX Bis) and 18(VIII)
High-risk and PEP customers require intensified monitoring under the added vulnerable-activity automated-monitoring provision once its staged commencement applies.
- Implementation action
- Implement intensified review now as a prudent control and track the general-rule commencement date before labelling it a currently operative statutory duty.
- Evidence to retain
- Transition note, high-risk flags, scenario settings, alert history, periodic review and approval.
- Primary citation
- LFPIORPI art. 18(X); 16 July 2025 reform transitory art. 3
Remote onboarding must satisfy the identity, authentication, record and technology conditions in the entity's applicable sector provisions or LFPIORPI rules.
- Implementation action
- Map each remote flow to the controlling annex or authorization, test presentation attacks and impersonation, provide accessible fallback and govern vendor changes.
- Evidence to retain
- Remote-onboarding legal map, vendor assessment, biometric tests, device and liveness results, accessibility testing and monitoring.
- Primary citation
- LFPIORPI art. 18(I); Fintech Law art. 56; applicable sector general provisions
Reliance on a vendor, agent or group service does not transfer the regulated entity's legal responsibility.
- Implementation action
- Contract for evidence access, audit rights, incident notice, data controls and exit; independently test the service and retain reconstructable decisions.
- Evidence to retain
- Contract, due diligence, control mapping, service reports, sample testing, incidents and exit plan.
- Primary citation
- LFPIORPI arts. 18 and 20; Fintech Law arts. 54-58; applicable sector provisions
06Monitoring, suspicious notices and confidentialityMexico uses different report classes and channels. A vulnerable-activity notice under LFPIORPI is not the same as a financial entity's unusual-operation report under sector provisions.4 items+
Vulnerable-activity operators must use the operative 24-hour route for legacy cases supported by current rules and formats; the 2025 expansion to broader suspicion and attempted-operation scenarios awaits the official annex update required by the 2026 Regulation transition.
- Implementation action
- Escalate all suspicion and attempted activity immediately, preserve the knowledge timestamp, file any currently supported legacy 24-hour notice, and obtain a current legal and format check for a broadened article 18(VI) scenario rather than assuming SPPLD accepts it.
- Evidence to retain
- Alert, facts and indicators, escalation time, rule and annex version, transition decision, filing and acknowledgement where applicable, attempted-operation flag and rationale.
- Primary citation
- LFPIORPI art. 18(VI); LFPIORPI Regulation art. 7 Bis; 27 March 2026 Regulation decree transitory art. 5; SAT SPPLD guidance
Financial entities submit unusual, 24-hour and other required reports to SHCP/UIF through the applicable supervisory channel and sector timetable.
- Implementation action
- Maintain a sector-specific reporting matrix and live portal credentials; do not use the vulnerable-activity day-17 rule for a bank, ITF, insurer or other financial entity.
- Evidence to retain
- Rule and report inventory, alert-to-filing timeline, report, supervisor receipt, quality review and regulatory correspondence.
- Primary citation
- LFPIORPI art. 15; Fintech Law art. 58; applicable SHCP general provisions
Financial-sector 24-hour reports apply in defined fact-based circumstances and to applicable blocked-person-list events under sector provisions.
- Implementation action
- Route facts immediately to the certified officer, apply the required restriction or suspension, file within the sector deadline and preserve the legal basis.
- Evidence to retain
- Knowledge timestamp, match adjudication, restriction record, report, acknowledgement, legal analysis and release authority.
- Primary citation
- Banking General Provisions 41 and blocked-person-list provisions; Fintech Law art. 58
Notice and report information, filer identities and protected compliance identities are confidential; staff must not disclose protected reporting information to unauthorized persons.
- Implementation action
- Apply least-privilege access, separate customer communications from reporting decisions, train personnel and obtain legal approval for any permitted disclosure.
- Evidence to retain
- Access logs, confidentiality labels, scripts, training, disclosure register and incident response.
- Primary citation
- LFPIORPI arts. 38-41 Bis; Fintech Law art. 58
07Threshold notices, payments, wires and agentsIdentification thresholds, article 17 notice thresholds, financial-sector relevant-operation reports and article 32 cash restrictions are different legal controls.4 items+
Routine vulnerable-activity notices are due by the 17th day of the immediately following month when the applicable article 17 notice threshold is met.
- Implementation action
- Maintain an activity-by-activity UMA matrix, apply the correct event date and six-month aggregation logic, file electronically and retain the receipt.
- Evidence to retain
- Threshold table, current UMA source, aggregation report, calendar, filing, acknowledgement and exception approval.
- Primary citation
- LFPIORPI arts. 17, 23-24; SAT threshold and SPPLD guidance
Certain cash, currency and precious-metal payments are prohibited at the article 32 UMA thresholds even if payment passes through a financial entity.
- Implementation action
- Block prohibited payment methods before settlement and distinguish the cash restriction from an article 17 notice or a sector relevant-operation report.
- Evidence to retain
- Payment-method rule, threshold test, invoices, settlement evidence, block logs and legal review.
- Primary citation
- LFPIORPI arts. 32-33
Financial-sector relevant-operation and other objective reports use sector-specific instruments, amounts, periods and channels.
- Implementation action
- Configure each licensed entity from its current general provisions; for banks, distinguish relevant cash-instrument reports, international-transfer reports, US-dollar cash reports and suspicious reports.
- Evidence to retain
- Sector configuration, report taxonomy, test cases, reconciliations, filings and supervisory receipts.
- Primary citation
- Banking General Provisions 34-41 and applicable formats; CNBV reporting guidance
Covered transfers require originator and beneficiary information under applicable financial-sector rules; article 17 virtual-asset operators must obtain and retain precise originator, recipient and beneficial-owner information as specified by general rules.
- Implementation action
- Capture required payer and payee data before execution, validate completeness, control intermediary data loss, reject or investigate deficient transfers and monitor secondary-rule detail.
- Evidence to retain
- Message fields, validation output, exception decision, repair record, screening, travel-rule mapping and audit sample.
- Primary citation
- Banking General Provisions; LFPIORPI art. 17(XVI)
08Targeted financial sanctions and blocked personsThe confidential Mexican blocked-person-list mechanism and public UN sanctions material are not interchangeable. The exact freeze, suspension, report and challenge process depends on the entity and sector rule.4 items+
Financial entities and ITFs must act on the confidential blocked-person list communicated by SHCP under their applicable statutes and provisions.
- Implementation action
- Screen at onboarding, before transactions and on list updates; adjudicate matches promptly, suspend or restrict as legally required, file the required report and release only on competent authority instruction.
- Evidence to retain
- List version, screening logs, match analysis, suspension record, report, authority communication and release approval.
- Primary citation
- Credit Institutions Law arts. 115 and 116; Fintech Law art. 58; applicable sector provisions
Current SAT guidance supports legacy 24-hour notices for specified fact-based or recognized-list cases; broadened article 18(VI) scenarios remain subject to the official-annex transition.
- Implementation action
- Do not assume a DNFBP has the same account-freeze power as a bank. Escalate immediately, file promptly where the current format supports the legacy case, document the transition analysis and obtain counsel for the exact measure.
- Evidence to retain
- List source, match rationale, legal authority, applicable annex version, transaction decision, notice if fileable, receipt and escalation.
- Primary citation
- LFPIORPI art. 18(VI); LFPIORPI Regulation art. 7 Bis; 27 March 2026 Regulation decree transitory art. 5; SAT guidance
UN Security Council sanctions lists and updates are authoritative screening inputs, but domestic implementation must follow Mexican law and the competent-authority route.
- Implementation action
- Monitor UN updates and Mexican communications, map each programme to the applicable domestic control and avoid releasing or freezing assets without documented authority.
- Evidence to retain
- UN list version, domestic mapping, screening results, authority contacts, licences or directions and decision log.
- Primary citation
- UN Security Council Consolidated List; applicable Mexican sector provisions
Blocked-person and sanctions information must be handled with confidentiality, procedural accuracy and controlled customer communications.
- Implementation action
- Use approved scripts, restrict the match file, preserve challenge and authority correspondence and prevent unauthorized disclosure of confidential list content.
- Evidence to retain
- Access control, communication script, case chronology, authority notices, challenge handling and quality review.
- Primary citation
- Credit Institutions Law arts. 115-116; Fintech Law art. 58
09Records, audit and regulator accessRetention starts and interruption rules differ. Preserve enough information to reconstruct the customer, authority, transaction, analysis, report and decision.4 items+
Financial entities must retain customer-identification and reported-activity records for at least ten years, subject to longer or more specific sector rules.
- Implementation action
- Map each record class and trigger, place legal holds where required and keep records readable, searchable and exportable for the full period.
- Evidence to retain
- Retention schedule, legal basis, trigger field, storage controls, retrieval test, holds and disposal approvals.
- Primary citation
- LFPIORPI art. 15(IV); applicable sector provisions
Vulnerable-activity operators generally must preserve supporting, identity, reconstruction, correspondence and analysis records for at least ten years from the activity; litigation interrupts and restarts the period as article 18 specifies.
- Implementation action
- Store physical or electronic records at the registered location as required, capture the activity date and implement litigation-hold interruption and restart logic.
- Evidence to retain
- Record inventory, registered-location control, transaction reconstruction, hold log, final-resolution date and disposal evidence.
- Primary citation
- LFPIORPI art. 18(IV)
SHCP and relevant supervisors may request information and conduct verification or supervision within their legal competence.
- Implementation action
- Maintain a regulator-response protocol, authenticate requests, preserve privilege where applicable, produce only responsive records and log every disclosure.
- Evidence to retain
- Request, authority validation, scope review, production set, delivery receipt, privilege log and remediation tracker.
- Primary citation
- LFPIORPI arts. 16, 22 Bis, 25 and 34-36; Fintech Law art. 58
Required annual audit or independent review must test effectiveness, not merely document existence, under the applicable sector rule or staged vulnerable-activity duty.
- Implementation action
- Set independence and competence criteria, sample end-to-end files, test reporting timeliness and data lineage, track findings and verify closure.
- Evidence to retain
- Audit scope, independence, workpapers, sample results, report, management actions and closure validation.
- Primary citation
- LFPIORPI art. 18(XI) and reform transitory art. 3; Fintech Law art. 58
10Privacy, biometrics and transfersAML duties can supply a legal basis or exception for necessary processing, but they do not remove privacy principles, security, transparency, purpose limitation or data-subject rights.4 items+
The 2025 Federal Law on Protection of Personal Data Held by Private Parties governs private-sector processing and is overseen by the Secretaria Anticorrupcion y Buen Gobierno.
- Implementation action
- Identify the controller and processors, document lawful grounds and exceptions, provide a compliant privacy notice and reconcile ARCO rights with mandatory AML retention and reporting.
- Evidence to retain
- Data inventory, role map, legal-basis register, privacy notice, consent or exception record, ARCO procedure and retention reconciliation.
- Primary citation
- LFPDPPP arts. 1-15 and 38-39
Financial or patrimonial data generally requires express consent and sensitive data requires express written consent, subject to statutory exceptions including processing required by law or legal relationship.
- Implementation action
- Classify identity, biometric, financial, sanctions and investigation data; document the exact legal requirement or consent and minimize collection to the stated purpose.
- Evidence to retain
- Data classification, consent evidence, statutory-exception memo, field minimization, access restrictions and periodic review.
- Primary citation
- LFPDPPP arts. 7-9 and 12
Controllers must maintain administrative, technical and physical security and immediately inform affected persons of breaches that significantly affect their patrimonial or moral rights.
- Implementation action
- Use risk-based security for identity and biometric data, maintain incident detection and an immediate notification workflow, and document whether the statutory significance test is met.
- Evidence to retain
- Security assessment, control set, incident log, impact analysis, notification, timestamps and post-incident remediation.
- Primary citation
- LFPDPPP arts. 18-20
Domestic and international transfers must follow the privacy notice and transfer rules, with consent unless a statutory exception applies; the recipient assumes corresponding obligations.
- Implementation action
- Map every vendor, group and authority transfer, flow down privacy obligations, document the exception or consent and control onward transfers and deletion.
- Evidence to retain
- Data-flow map, transfer register, notice, consent or exception, contract, due diligence and deletion confirmation.
- Primary citation
- LFPDPPP arts. 35-36
11Payments, fintech, virtual assets and launch evidenceAuthorization, AML status and virtual-asset treatment must be resolved separately. A technology label does not avoid a reserved financial activity or article 17 virtual-asset perimeter.4 items+
ITFs must maintain an AML risk methodology, customer controls, automated systems, committee and certified compliance officer, annual review, reports and at least ten-year records.
- Implementation action
- Map the product and operating model to Fintech Law article 58 and current general provisions, including blocked-person suspension and report taxonomies.
- Evidence to retain
- Authorization conditions, risk method, manual, committee minutes, officer certificate, system tests, audit and filings.
- Primary citation
- Fintech Law art. 58
ITFs and banks may conduct statutory virtual-asset operations only with the assets and prior Banco de Mexico authorization allowed under the Fintech Law and Circular 4/2019 framework.
- Implementation action
- Do not infer retail permission from use of distributed-ledger technology; obtain a written perimeter analysis and the required Banco de Mexico authorization before any covered operation.
- Evidence to retain
- Legal opinion, asset classification, Banco de Mexico correspondence or authorization, restrictions, customer disclosures and launch gate.
- Primary citation
- Fintech Law arts. 30-32 and 88; Banco de Mexico Circular 4/2019
A non-financial platform habitually and professionally exchanging, transferring, safeguarding or storing covered virtual assets for Mexican customers can fall within LFPIORPI article 17(XVI), including Mexico-directed services from abroad.
- Implementation action
- Assess territorial nexus, register if applicable, apply the 210-UMA transaction and 4-UMA fee notice limbs and aggregation, build originator-recipient data capability, and handle 24-hour cases under the current-format transition described in section 6.
- Evidence to retain
- Nexus opinion, registration, threshold engine, originator and recipient fields, applicable annex version, notices, receipts and change monitoring.
- Primary citation
- LFPIORPI art. 17(XVI); SAT virtual-asset criterion; 27 March 2026 Regulation decree transitory art. 5
Launch requires a current, source-backed decision for every applicable row and evidence that reporting, sanctions, privacy, record and incident workflows work end to end.
- Implementation action
- Run controlled dry tests without submitting fictional personal data to production regulator portals, close blockers and obtain legal, compliance, privacy, security and product sign-off.
- Evidence to retain
- Completed checklist, primary-source register, test results, defects and closure, approvals, effective dates and monitoring owner.
- Primary citation
- LFPIORPI arts. 15-25; Fintech Law arts. 11 and 58; LFPDPPP arts. 13-20
Primary-source register
28 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- LFPIORPI - current consolidated textChamber of Deputies · Primary legislation
- LFPIORPI reform history and 16 July 2025 decreeChamber of Deputies · Primary legislative history
- LFPIORPI Regulation reform of 27 March 2026Diario Oficial de la Federacion · Primary regulation
- Current LFPIORPI reform implementation criteriaSAT Prevention of Money Laundering Portal · Official current interpretation
- Vulnerable-activity obligations and reporting deadlinesSAT Prevention of Money Laundering Portal · Official compliance guidance
- Vulnerable-activity electronic reporting portalSAT Prevention of Money Laundering Portal · Official reporting channel
- Cash-use restrictions and UMA thresholdsSAT Prevention of Money Laundering Portal · Official threshold guidance
- Vulnerable-activity frequently asked questionsSAT Prevention of Money Laundering Portal · Official compliance guidance
- SAT criterion for Mexico-directed foreign virtual-asset servicesSAT Prevention of Money Laundering Portal · Official territorial-scope interpretation
- UIF role and mandateUnidad de Inteligencia Financiera · Official authority description
- UIF legal framework directoryUnidad de Inteligencia Financiera · Official legal directory
- CNBV current normativity directoryComision Nacional Bancaria y de Valores · Official supervisory directory
- Banking AML general-provisions amendment of 24 February 2017Diario Oficial de la Federacion · Historical primary regulatory instrument
- Latest banking article 115 AML general-provisions amendment, July 2026Diario Oficial de la Federacion · Current primary regulatory instrument
- Credit Institutions LawChamber of Deputies · Primary legislation
- CNBV AML/CFT supervisory and blocked-person-list descriptionComision Nacional Bancaria y de Valores · Official supervisor guidance
- Fintech Law - current consolidated textChamber of Deputies · Primary legislation
- Circular 4/2019 - virtual-asset operationsBanco de Mexico · Primary regulatory instrument
- Federal Fiscal Code - current consolidated textChamber of Deputies · Primary legislation
- General Law of Commercial CompaniesChamber of Deputies · Primary legislation
- Public Registry of Commerce - SIGER 2.0Secretaria de Economia · Official company registry
- What the Public Registry of Commerce recordsSecretaria de Economia · Official registry guidance
- Electronic Publications System for Commercial CompaniesSecretaria de Economia · Official filing guidance
- Federal Law on Protection of Personal Data Held by Private PartiesChamber of Deputies · Primary legislation
- FATF Mexico country and assessment pageFinancial Action Task Force · Official international assessment
- FATF jurisdictions under increased monitoring, 19 June 2026Financial Action Task Force · Official current-status source
- FATF high-risk jurisdictions subject to a call for action, 19 June 2026Financial Action Task Force · Official current-status source
- United Nations Security Council Consolidated ListUnited Nations Security Council · Official sanctions list
Direct answers
Mexico KYC, KYB and AML questions
Who receives AML reports and notices in Mexico?+
The UIF is Mexico's national FIU. Vulnerable-activity operators submit notices to UIF through SAT's SPPLD. Financial entities report through the channel and supervisor specified for their sector, commonly involving CNBV, CNSF or CONSAR.
Is every suspicious report due within 24 hours?+
No. Current vulnerable-activity rules and formats support specified legacy 24-hour cases. LFPIORPI article 18(VI) broadened the statutory scenarios to include attempted activity, but the March 2026 Regulation transition makes filing those expanded cases subject to updated official annexes. Financial entities use separate sector report classes and deadlines.
When are routine vulnerable-activity notices due?+
When the applicable article 17 notice threshold is met, the notice is generally due by the 17th day of the immediately following month through SPPLD. Separately assess any operative legacy 24-hour case and monitor the official annex update for the broadened article 18(VI) scenarios.
Is there one universal transaction threshold?+
No. LFPIORPI article 17 uses activity-specific daily-UMA multiples and a six-month aggregation rule. Financial-sector objective reports and article 32 cash restrictions are separate controls.
What beneficial-owner percentage applies?+
There is no percentage-only test. LFPIORPI includes control through more than 25% of voting rights plus appointment, contractual and management control. The separate Federal Fiscal Code beneficial-controller test includes more than 15% of voting rights and must be maintained as a distinct corporate tax record.
How long must AML records be kept?+
At least ten years is the LFPIORPI baseline for financial entities and, after the 2025 reform, generally for vulnerable-activity records. Apply longer or more specific sector rules and litigation-hold provisions where relevant.
Are the new vulnerable-activity risk and audit duties already fully operative?+
Their statutory text was added in 2025, but transitory article 3 makes LFPIORPI article 18(VII-XI) effective on dates set in revised general rules. Check the live SAT criteria and Diario Oficial before assigning a current legal commencement date.
Can a company rely only on the public company registry for KYB?+
No. RPC, PSM, corporate books, tax beneficial-controller records and AML beneficial-owner analysis have different purposes and coverage. Reconcile them and independently trace natural-person ownership and control.
Can an ITF or bank offer virtual-asset services without further approval?+
No. The Fintech Law restricts statutory virtual-asset operations to assets and prior authorization allowed by Banco de Mexico. A separate non-financial virtual-asset service can instead fall within LFPIORPI article 17(XVI).
Is Mexico on a FATF public list?+
Mexico was not named on the FATF increased-monitoring or call-for-action lists reviewed 31 July 2026. Mexico is a FATF member and remains subject to mutual-evaluation follow-up and a forthcoming fifth-round evaluation.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice, an authorization decision or a substitute for the operative Spanish text, sector provisions, official forms or regulator instructions. Reviewed 31 July 2026. Thresholds expressed in UMA change with the applicable official value. Confirm entity, activity, customer, transaction, aggregation, reporting channel, commencement date, sanctions route, privacy role and later developments with qualified Mexican counsel and the relevant authority before launch.