ScopeThis memorandum is general informational and regulatory content; it is not a legal opinion applied to a specific business model, client, or case. Any application to a specific operational scenario requires additional analysis that takes into account the particular circumstances involved.
SCOPE OF THIS ANALYSIS
Introduction and scope
This memorandum analyzes the main changes introduced by the reform to the "General Rules referred to in the Federal Law for the Prevention and Identification of Transactions with Illegally-Sourced Funds" (the "Rules" or "RCG") contained in Acuerdo 115/2026, issued by the Ministry of Finance and Public Credit (the "SHCP" or the "Ministry"), published in the Federal Official Gazette ("DOF") on August 7, 2026 (the "Reform"). The analysis was prepared exclusively on the basis of the full text of Acuerdo 115/2026, together with the current text of the Federal Law for the Prevention and Identification of Transactions with Illegally-Sourced Funds (the "Law" or "LFPIORPI"), as last amended in the DOF on July 16, 2025, used solely to give context to the Rules' cross-references to the Law.
This memorandum is general informational and regulatory content; it is not a legal opinion applied to a specific business model, client, or case. Any application to a specific operational scenario requires additional analysis that takes into account the particular circumstances involved.
REGULATORY CONTEXT
Background and regulatory framework
The Rules were originally issued through Acuerdo 02/2013 (DOF, August 23, 2013) and amended through Acuerdo 09/2014 (DOF, July 24, 2014, clarified July 31, 2014) and Acuerdo 126/2020 (DOF, November 30, 2020, which incorporated the virtual-assets regime). For purposes of this memorandum, that body of rules constitutes the "Previous Text," substantially amended by Acuerdo 115/2026 as explained in sections 3 and 4 below.
The Reform should not be read in isolation, but as the administrative implementation of changes that, at a higher hierarchical level, were introduced by the reform to the LFPIORPI itself, published in the DOF on July 16, 2025, which replaced the concept of "Dueño Beneficiario" (Beneficial Owner) with "Beneficiario Controlador" (Controlling Beneficiary) (article 3, section III of the Law) and added section IX Bis to that article 3, defining "Persona Políticamente Expuesta" (Politically Exposed Person) with an express cross-reference to the general rules the Ministry issues for that purpose. Acuerdo 115/2026 accordingly aligns the Rules' terminology and obligations with that legal reform, and further develops, at the regulatory level, a set of new substantive obligations on risk management, customer knowledge, training and audit, detailed in section 4.
Acuerdo 115/2026 was signed by Édgar Abraham Amador Zamora, Minister of Finance and Public Credit, dated in Mexico City on July 24, 2026, and published in the DOF on August 7, 2026. It consists of a First Article that amends and adds an extensive number of articles and chapters to the Rules, a Second Article that amends, adds and repeals various Annexes, and twelve transitory articles that set the general effective date and a set of exceptions and deferred deadlines, analyzed in section 3 below.
Figure 01
Regulatory paradigm shift
TRANSITORY REGIME
Effective date and transitory regime
General rule on the effective date.
Under the First Transitory Article of Acuerdo 115/2026, the Reform takes effect on November 30, 2026, "except for the exceptions set out in the following transitory articles." In other words, most of the Reform's regulatory content — including the new definitions, the restructured chapters, and the general run of obligations described in section 4 — becomes enforceable from that date, subject to the exceptions described below. Because the transitory regime contains twelve articles with staggered deadlines, those who carry out Vulnerable Activities must build a specific implementation calendar rather than assume a single compliance date.
Risk-based approach assessment (Second Transitory Article).
The risk-based approach assessment referred to in the new Chapter II Quáter of the Rules must be available to the competent authorities, upon request, starting March 1, 2027. The information and factors considered in preparing it must correspond to the immediately preceding year; where information for the full year is not available, the information available from the start of the Vulnerable Activity through the date the assessment is prepared shall be used.
Updated Internal Policies Manual (Third Transitory Article).
Those whose ninety-calendar-day period to have their Internal Policies Manual under article 37 of the Rules has already elapsed must incorporate into that Manual the methodology referred to in Chapter II Quáter (risk-based approach) starting March 1, 2027, and make it available to the competent authorities upon request.
Risk Level, customer knowledge and Controlling Beneficiary (Fourth Transitory Article).
For acts or transactions carried out from March 1, 2027, those who carry out Vulnerable Activities must observe the new Chapters III Bis (classification of the Customer or User's Risk Level), III Ter (Customer or User knowledge) and III Quinquies (Controlling Beneficiary) of the Rules. In other words, while the Reform takes effect on November 30, 2026, the operational applicability of these three chapters — which, together with the risk-based approach, form the substantive core of the Reform — is deferred to March 1, 2027.
24-hour Reports based on facts or indicia (Fifth Transitory Article).
Filing the Reports referred to in articles 26 Bis, 26 Bis 1, 26 Bis 2 and the second paragraph of article 27 of the Rules (that is, the new regime for suspicion-based Reports or Reports based on facts or indicia within the following twenty-four hours) may begin six months after the effective date of the Resolution amending the official Report and Filing forms, which will provide for the express identification of this type of Report. This is therefore a deadline conditioned on a future event (the publication of that Resolution) rather than a fixed date, so those who carry out Vulnerable Activities should monitor SAT and UIF publications on this matter.
Personnel-screening procedures (Sixth Transitory Article).
The personnel-screening procedures referred to in article 39 Bis 2 of the Rules must apply to new hires made from March 1, 2027 onward; that is, they have no retroactive effect on personnel already hired by that date.
First training period (Seventh Transitory Article).
The first annual training period referred to in article 39 Bis of the Rules will run from January 1 through December 31, 2027.
First audit period (Eighth Transitory Article).
For purposes of article 42 of the Rules (annual audit obligation), the first review period will begin on January 1, 2028 and end on December 31 of that same year. Of the entire transitory regime, this is the deadline furthest out in time, suggesting the audit obligation developed under the new Chapter XIV was designed to operate once the model's other elements — risk methodology, customer classification, the Internal Policies Manual, and automated mechanisms — are already implemented and have been operating for a reasonable period.
Automated mechanisms (Ninth Transitory Article).
Those who carry out Vulnerable Activities must have the automated mechanisms referred to in Chapter XIII of the Rules in place no later than June 1, 2027, and those mechanisms must contain the information on acts or transactions carried out from that date onward.
Politically Exposed Persons search (Tenth Transitory Article).
Those who carry out Vulnerable Activities and Financial Entities may use the search referred to in article 23 Quáter 1 of the Rules (the "PEP Search 2.0" application) nine months after Acuerdo 115/2026 takes effect, that is, approximately by the end of August 2027.
Electronic notification system (Eleventh Transitory Article).
The Ministry must implement the technological mechanisms needed to operate the electronic-notification system referred to in article 6 of the Rules within eight months of the Agreement's effective date, that is, approximately by the end of July 2027. This is an obligation of the authority itself, not of the obligated parties.
Virtual Asset Service Providers (Twelfth Transitory Article).
Those who carry out the Vulnerable Activity set out in section XVI of article 17 of the Law (virtual assets) who are already registered on the Online Portal must update and submit the additional information referred to in article 10 Bis of the Rules within six months of the Agreement's effective date, that is, approximately by the end of May 2027.
Figure 02
Phased application 2026–2028
ARCHITECTURE SHIFT
Structural and substantive changes
The Reform adds eight entirely new chapters (Chapters II Ter, II Quáter, III Ter, III Quáter, III Quinquies, XII, XIII and XIV) and substantially amends five others (Chapters II, II Bis, III, III Bis and X). For each, this analysis first states how it was treated under the Previous Text (or notes that no provision existed at all) and then what the Reform requires from its effective date.
Figure 03
Structural map of chapters
Before the Reform, the Rules did not require designing a formal risk-assessment methodology: the compliance model revolved around building identification files and meeting the thresholds for filing Reports, with no chapter dedicated to risk management as such. With the Reform, this changes structurally.
The Reform adds Chapter II Quáter, titled "Risk-Based Approach," which is probably the Reform's most conceptually significant change. Under article 10 Septies, those who carry out Vulnerable Activities must design and implement a methodology to carry out a risk assessment derived from the acts or transactions they conduct, as well as from the Customers or Users with whom they conduct them, their transactions, and their delivery or distribution channels. That methodology must be set out in the Internal Policies Manual or in a separate document, and must describe all processes for identifying, analyzing, understanding, measuring and mitigating risks.
Article 10 Septies 1 requires the methodology to identify, at a minimum, the following risk elements: (a) acts or transactions; (b) type of Customer or User; (c) countries and geographic areas; and (d) transactions and delivery or distribution channels. It also requires using a measurement method that assigns a value to each element and identifying the "Mitigants" (defined in article 3, section XI Quinquies of the Rules as the policies, criteria, measures and procedures that help manage and reduce exposure to the identified risks) already implemented when the methodology is designed. A particularly relevant element is that those who carry out Vulnerable Activities must establish specific indicators tied to the offenses under articles 139 Quáter (terrorist financing) and 400 Bis (money laundering) of the Federal Criminal Code.
Article 10 Septies 2 requires using, at a minimum, information on the total number of Customers or Users, the number of acts or transactions, and the amount transacted over a period of no less than twelve months; where there is no transaction history over that period (for example, for newly established businesses), an initial methodology must be implemented using projected data, updated once the first twelve months of operation are complete. The methodology must be reviewed and, where appropriate, updated whenever new risks are detected, whenever the UIF's National Risk Assessment is updated, or within no more than twelve months of the results of its implementation becoming available. The SAT, for its part, retains the power to review and, where appropriate, flag adjustments to the methodology or the Mitigants when, among other scenarios, it considers that risk management was inadequate in the process of opening, limiting or terminating business relationships.
This risk-based approach is not a standalone chapter: it is the cross-cutting axis from which Chapter III Bis (classification of the Customer's Risk Level), Chapter III Ter (Customer knowledge and transactional profile), the reinforced content of the Internal Policies Manual (Chapter X), and the minimum requirements for automated mechanisms (Chapter XIII) all directly derive. Its correct implementation therefore conditions compliance with the rest of the model.
Figure 04
Architecture of the new AML model
Classification of the Customer or User's Risk Level (new Chapter III Bis, articles 23 Bis to 23 Bis 4)
Before the Reform, the Rules did not provide for individual Customer risk classification: due diligence depended mainly on the type of Customer (individual, legal entity, trust, among others) under the applicable Annex, without distinguishing low, medium or high risk levels. With the Reform, Chapter III Bis is added, introducing that classification as a standalone obligation.
The Rules add Chapter III Bis, which requires having a risk-assessment model consistent with the Chapter II Quáter methodology to classify each Customer or User by individual Risk Level. Article 23 Bis requires establishing at least three classifications: low, medium and high Risk Level, with additional intermediate levels allowed. The initial Risk Level must be determined using the information each Customer or User provides, and the assessment must be repeated at least every six months, more frequently as the Risk Level increases.
Article 23 Bis 2 details the risk factors to be considered, distinguishing between (a) inherent characteristics (the Customer's background, type of person, date of birth or incorporation, line of business or activity, nationality, place of residence, sources of income, and the nature and purpose of the relationship) and (b) transactional characteristics (type, volume, frequency and amount of the acts or transactions, number of counterparties, origin and destination of funds, monetary instrument and currency type). In addition, article 23 Bis 3 requires additional risk factors specifically applicable to Mexican-national Politically Exposed Persons, aimed at verifying that their transactional behavior is reasonable relative to their income, functions and level of responsibility.
Particularly notable is article 23 Bis 4, which establishes a mandatory (non-discretionary) high-risk rating for Customers or Users not resident in Mexican territory who are linked to, or have effects in, countries or jurisdictions that Mexican legislation treats as preferential tax regimes, or countries that Mexican authorities or international bodies of which Mexico is a member determine lack sufficient measures to prevent, detect and combat transactions with illegally-sourced funds, as well as for foreign Politically Exposed Persons. In these cases, those carrying out the Vulnerable Activity must document why those Customers entered into acts or transactions within Mexican territory, and the UIF will publish, through the Online Portal, the list of applicable countries and jurisdictions.
Figure 05
Risk Level pyramid
Figure 06
From factors to Risk Level
Customer or User knowledge and transactional profile (new Chapter III Ter, articles 23 Ter to 23 Ter 5)
Before the Reform, monitoring each Customer's transactions was, in essence, limited to the amount-accumulation mechanisms under article 19 of the Rules; there was no express obligation to build and monitor an individual "Transactional Profile," nor a dedicated alert system for detecting deviations from that profile. With the Reform, Chapter III Ter is added precisely to fill that gap.
The new Chapter III Ter requires preparing and observing a customer-knowledge policy that includes, at a minimum: policies and controls to mitigate risks aligned with the Chapter II Quáter methodology; procedures for following up on and monitoring acts or transactions; procedures for properly understanding each Customer's "Transactional Profile" (defined in article 3, section XI Sexties, as the set of elements that make it possible to identify the expected behavior of that Customer's acts or transactions, considering amount, frequency, geographic area, origin and destination of funds and economic activity, among others); the scenarios in which acts or transactions deviate from that profile; and the criteria for assigning and, where appropriate, changing the Risk Level.
Article 23 Ter 2 introduces the obligation to have and implement an alert system capable of timely detecting changes in a Customer's behavior or Transactional Profile that could fall within articles 139 Quáter or 400 Bis of the Federal Criminal Code. For high-Risk-Level Customers, article 23 Ter 3 requires obtaining more information on their predominant activity and conducting stricter review and monitoring, including identification questionnaires that may be carried out remotely, digitally or electronically, provided they carry an Electronic Signature covering the origin and destination of funds.
Article 23 Ter 4 details the enhanced measures applicable to high-Risk-Level Customers: for individuals, adopting enhanced measures to understand the origin and destination of funds and, where applicable, obtaining data on the spouse and economic dependents, as well as on companies and associations with which the Customer has ownership ties; for legal entities, obtaining more information about their principal shareholders or partners, verifying the information provided against the Ministry of Economy's electronic registries; and, for foreign Politically Exposed Persons, additionally obtaining documentation on the spouse and related persons. Finally, article 23 Ter 5 requires that, when a Customer is found to be a high-Risk-Level Politically Exposed Person, approval from an officer or equivalent must be obtained before continuing the relationship or transaction.
Figure 07
Customer lifecycle
Figure 08
Transactional profile: expected vs. observed
04 · SUBSTANTIVE CHANGES
Controlling Beneficiary and Politically Exposed Persons
Controlling Beneficiary (new Chapter III Quinquies, articles 23 Quinquies to 23 Quinquies 3)
Before the Reform, the Rules referred to this figure as "Dueño Beneficiario" (Beneficial Owner) (defined in the then-current section VII of article 3), and identifying it was resolved, in practice, through a simple knowledge statement included in each identification Annex, with no dedicated chapter, no order of precedence among criteria, and no specific rules for trusts or multi-tiered control structures. With the Reform, section VII of article 3 is expressly repealed and the concept is entirely rebuilt under the name "Beneficiario Controlador" (Controlling Beneficiary).
Consistent with the 2025 legal reform described in section 2.2, the Rules replace every reference to the former "Dueño Beneficiario" with "Beneficiario Controlador" throughout, and add Chapter III Quinquies, dedicated entirely to identifying it. Under article 23 Quinquies, those who carry out Vulnerable Activities must set out in their Internal Policies Manual the criteria, measures and procedures for identifying the Controlling Beneficiary, observing the following order of precedence: (i) the individual or group of individuals who, directly or indirectly, acquires, holds title to, or owns, under any legal title, twenty-five percent or more of the Customer's equity or capital stock; (ii) failing that, the person or group that controls the Customer through other means related to strategy, decision-making and the direction of its main policies; and (iii) failing that, the person holding the position of the most senior administrative officer or top management.
Article 23 Quinquies 1 develops specific rules for trusts, treating as the Controlling Beneficiary any individual who ultimately exercises effective control over the trust through contractual, legal or other powers, whether as trustee, settlor, beneficiary, protector or member of the technical committee. When such persons are themselves legal entities or legal structures, the individual who, going up the chain of ownership and control, ultimately exercises that control must be identified. Identification of the Controlling Beneficiary must take place before the act or transaction is carried out or, at the latest, when the Business Relationship is established, and must be documented, retained and kept up to date for the entire duration of that relationship.
Article 23 Quinquies 2 introduces two exceptions in which Controlling Beneficiary identification data need not be collected: (i) when the Customer is a trust or legal entity listed on Mexican stock exchanges or on foreign securities markets recognized under Mexican law, provided the corresponding ticker symbol, reference or identifier is supplied; and (ii) when the Customer is a legal entity of the type provided for in Annexes 4 Bis, 6 Bis, 7-A and 7 Bis A (essentially, public-law entities and specifically listed government or international bodies). Finally, article 23 Quinquies 3 allows the guidelines the UIF issues, with the SAT's prior opinion, to be taken into account for compliance with this Chapter.
List of Politically Exposed Persons (new Chapter III Quáter, articles 23 Quáter to 23 Quáter 2)
Before the Reform, the Rules had no dedicated chapter on Politically Exposed Persons: the relevant search relied directly on the Regulations (articles 45 Ter and 45 Quáter) and article 51 Ter of the Law, without the Rules developing the concept, specifying who is treated as a PEP, or formalizing the use of a specific search tool. With the Reform, Chapter III Quáter is added to expressly cover this subject.
Developing section IX Bis of article 3 of the Law (introduced in the 2025 legal reform), the Rules add Chapter III Quáter, which refines the concept of Politically Exposed Person ("PEP"), including heads of state or government, political leaders, senior government, judicial or military officials, senior executives of state-owned companies, and important officials or members of political parties and international organizations. Also treated as PEPs are the spouse, common-law partner, and relatives by blood or marriage up to the second degree, as well as associates or partners with whom the PEP has ownership ties. National PEPs retain that status for the year following the one in which they left office (with an additional extension rule when the act or transaction takes place within the year immediately preceding the loss of that status).
Article 23 Quáter 1 formalizes mandatory use of the "PEP Search 2.0" application on the UIF's official website for searching national PEPs, using the Advanced Electronic Signature used for the registration process. Financial Entities may request the UIF, by simple written request, to grant them access to that application, subject to compliance with their obligations to prevent transactions with illegally-sourced funds. Article 23 Quáter 2 requires authorities and public bodies to provide the UIF with the information listed in the new Annex 10 (personal data of public servants and their economic dependents), via an Excel-format file uploaded through the application itself.
04 · SUBSTANTIVE CHANGES
Virtual assets, VASPs and legal structures
Virtual assets and Virtual Asset Service Providers (amendment to Chapter II Bis and new articles 24 Bis 2 to 24 Bis 6)
Chapter II Bis already governed, since Acuerdo 126/2020, the registration of those who carry out the Vulnerable Activity of virtual assets, but the Rules did not detail the specific content required for Reports related to this type of transaction, nor did they define operational concepts such as custody, facilitation or intermediation of virtual assets. With the Reform, the documentation required for registration is expanded and a full block of articles (24 Bis 2 to 24 Bis 6) is added to fill that gap.
Chapter II Bis, retitled "Registration of Virtual Asset Service Providers," specifies the documentation such providers ("VASPs") must physically submit to the SAT, including a detailed list of individuals and legal entities holding an interest in their capital stock (with name, nationality, address, CURP and RFC, number of shares and par value) and the information corresponding to their Controlling Beneficiary. Existing articles 10 Ter and 10 Quáter remain unchanged as to the deadlines for correcting inconsistencies (five business days) and completing the registration process (thirty business days from when the SAT confirms in writing that it has received all the documentation).
The Rules add a full block of provisions on the content of Reports involving virtual assets (article 24 Bis 2), requiring precise information on the originator, the recipient and, where applicable, the Controlling Beneficiary, including name or corporate name, country or jurisdiction of residence, account or wallet identifier, date and time of the transaction, type of virtual asset, amount expressed in virtual assets and its equivalent in national currency, type of transaction, and the fee charged for the service. That information must be retained for ten years and delivered to the UIF, or to the SAT in exercise of its supervisory powers, upon request.
New articles 24 Bis 3 and 24 Bis 4 define, respectively, what is understood by custody or storage of virtual assets (when the VASP provides services or platforms that allow control, safekeeping or administration of virtual assets on a Customer's behalf) and by facilitation or intermediation (when the VASP provides infrastructure, interfaces or electronic platforms that connect, reconcile or match purchase, sale, exchange or custody transactions in virtual assets, even without holding control over them). When more than one VASP, domestic or foreign, takes part in a facilitation or intermediation transaction, each must independently comply with its own obligations toward its Customers or Users.
Article 24 Bis 5 introduces specific threshold-accumulation rules for subsection (b) of section XVI of article 17 of the Law (fees charged by the VASP): (i) when the transaction reaches or exceeds 210 times the daily UMA value, but the fee is less than 4 times that value, the Report is filed only under subsection (a) of section XVI; (ii) when the fee reaches or exceeds 4 times the daily UMA value, but the transaction amount is less than 210 times that value, the Report is filed only under subsection (b); and (iii) when both scenarios are met simultaneously, a single Report is filed, under subsection (a). These fees are determined individually for each transaction and are not subject to monthly accumulation.
Registration of those acting through trusts and other legal structures (new Chapter II Ter, articles 10 Sexies and 10 Sexies 1)
Before the Reform, the Rules did not provide a specific, unified registration, deregistration or update procedure for members of trusts or other legal structures (such as joint ventures) that carry out Vulnerable Activities; that information was, in practice, collected as part of the general registration process under article 4, with no standardized format. With the Reform, Chapter II Ter is added, introducing a dedicated tool.
Chapter II Ter is added to specifically govern the registration, deregistration and updating of members of trusts and other legal structures (for example, joint ventures — Asociaciones en Participación), through a tool published on the Online Portal that generates an XML file with the corresponding information under new Annexes 2 Bis (trusts) and 2 Ter (other legal structures), described in section 4.15. In the case of a joint venture, article 10 Sexies 1 expressly designates the managing partner (asociante) as responsible for registration, using its own Advanced Electronic Signature tied to the joint venture's Federal Taxpayer Registry number.
24-hour Reports based on facts or indicia (articles 26 Bis, 26 Bis 1 and 26 Bis 2)
Before the Reform, the urgent Report for facts or indicia already existed, but in a unified and more limited form: the (now repealed) first paragraph of article 27 provided, in a single scenario, that when a person carrying out Vulnerable Activities conducted an act or transaction subject to Report and had additional information, based on facts or indicia, that the funds might come from or be intended to further money-laundering-related offenses, the Report had to be filed with the UIF, through the SAT, within twenty-four hours of learning that information. The Reform does not eliminate this twenty-four-hour obligation: it splits it into three articles with distinct scenarios and extends it to cases not previously expressly covered.
Under new article 26 Bis, for purposes of the second paragraph of section VI of article 18 of the Law, the suspicion-based Report must be sent within twenty-four hours of the moment when, taking into account the information gathered to identify the Customer and the characteristics with which acts or transactions are commonly carried out, the person carrying out the Vulnerable Activity recognizes any unusual activity, conduct or behavior that could be linked to money-laundering-related offenses; this scenario corresponds, in essence, to what the now-repealed article 27 governed. New article 26 Bis 1 extends, for the first time, this twenty-four-hour obligation to cases where the suspicion arises from information obtained from other public or private sources (rather than solely from analysis of the transaction itself) — a scenario the Previous Text did not contemplate.
New article 26 Bis 2 clarifies, also for the first time, that these Reports may be filed even when the act or transaction does not meet the amount or condition to be reportable under article 17 of the Law, and even when the act or transaction was never completed, provided there is data available to identify the Customer or User, or the person who attempted to carry it out. Article 27, which survives with new wording, now only retains the obligation to file a Report, within the period set out in articles 26 Bis and 26 Bis 1, when dealing or attempting to deal with persons included in the list referred to in article 38 of the Rules (the UIF's prevention mechanisms). As explained in section 3.5, the practical operability of this twenty-four-hour regime is conditioned, under the Fifth Transitory Article, on publication of the Resolution updating the official Report and Filing forms.
Figure 09
24-hour Reports based on facts or indicia
Reinforced Internal Policies Manual (Chapter X, articles 37 to 37 Bis 3)
Before the Reform, article 37 already required having an Internal Policies Manual within ninety calendar days of registration, but the Rules did not specify its mandatory minimum content, so each obligated party had wide latitude in deciding what to include. With the Reform, article 37 is reworded to expressly refer to the Chapter II Quáter risk methodology, and article 37 Bis is added to set, for the first time, a mandatory minimum content.
Newly created article 37 Bis sets a mandatory minimum content for the Internal Policies Manual, made up of fourteen sections: criteria for identifying and knowing Customers; risk-classification mechanisms; due-diligence measures based on Risk Level; procedures for identifying and enhanced monitoring of PEPs; mechanisms to detect deviations from the Transactional Profile; procedures for filing Reports and Filings; information-retention mechanisms; mechanisms for monitoring and accumulating transactions; mechanisms for identifying persons on domestic or international watchlists; the functions and responsibilities of the Compliance Officer; training programs; internal-control, supervision and audit mechanisms; confidentiality measures; and procedures for updating the Manual itself.
Article 37 Bis 1 introduces a specific obligation for members of a Corporate Group: implementing centralized compliance policies and mechanisms, applicable to all majority-owned branches and affiliates, including foreign ones, provided they apply to all group members, allow information sharing for risk mitigation and identification purposes, and ensure each branch or affiliate complies individually. Article 37 Bis 2, in turn, allows those who determine they will not carry out acts or transactions under certain scenarios to be exempt from establishing policies for those scenarios, provided that fact is recorded in the Manual itself; the exemption ceases to apply the moment such acts or transactions are decided upon. Finally, article 37 Bis 3 confirms the SAT's power to order amendments to the Manual whenever it considers this necessary for compliance with the Rules.
Training and personnel screening (new Chapter XII, articles 39 to 39 Bis 2)
Before the Reform, the Rules had no chapter dedicated to training or personnel screening; there was no express obligation to provide annual training, to demonstrate the trainer's minimum experience, or to document screening procedures with signed statements from personnel. With the Reform, Chapter XII is added to fully cover this subject.
A full chapter dedicated to training and personnel screening is added. Article 39 Bis requires implementing training programs aimed at members of the board of directors, the sole administrator, officers, executives, the Compliance Officer and, in all cases, employees who work in public-facing areas, take part in Customer identification or knowledge, in filing Reports, or in audit activities. That training must be given at least once a year, and must cover, at a minimum, knowledge of the Law, the Regulations, the Rules and the Internal Policies Manual, the acts or transactions under article 17 of the Law, and the risks to which the person carrying out the Vulnerable Activity is exposed, in addition to content on techniques and trends for preventing the offenses under articles 139 Quáter and 400 Bis of the Federal Criminal Code. Those who provide the training must demonstrate at least five years of experience in the subject matter.
Article 39 Bis 1 requires retaining, for a minimum of ten years, documentary evidence of programs, workshops, materials, attendance lists, evaluations and corresponding certificates; issuing a certificate requires a knowledge evaluation, and the Internal Policies Manual must set out the measures applicable to those who do not achieve satisfactory results. Article 39 Bis 2, whose application to new hires is deferred to March 1, 2027 under the Sixth Transitory Article, requires establishing screening procedures that ensure personnel's technical quality, experience and good standing, including a signed statement confirming, among other things, that the person has not been convicted of property crimes and is not disqualified from engaging in commerce or holding public office.
Figure 10
Training: minimum universe of people
Automated mechanisms (new Chapter XIII, article 41)
Before the Reform, article 18, section X of the Law already required having automated mechanisms to monitor transactions, but the Rules did not specify the minimum functions those mechanisms had to fulfill. With the Reform, Chapter XIII is added, detailing for the first time a catalog of required minimum functions.
Article 41 requires the automated mechanisms referred to in section X of article 18 of the Law to be reasonably adequate to the volume, nature, complexity and risk of the person carrying out the Vulnerable Activity, and to perform, at a minimum, six functions: (i) retaining, updating and allowing lookup of the information in the identification files; (ii) grouping a given Customer's acts or transactions into a consolidated database to monitor and identify deviations from the Transactional Profile, and to carry out the accumulation required under the Law; (iii) supplying the information required by the Chapter II Quáter methodology; (iv) running the Chapter III Bis risk-assessment model, retaining historical Risk Level and Transactional Profile records for at least ten years; (v) running an alert system for high-Risk-Level Customers, PEPs, and persons on prevention lists or linked to high-risk jurisdictions; and (vi) monitoring the use of cash and precious metals under article 32 of the Law.
Figure 11
Six minimum functions of automated mechanisms
Mandatory annual audit (new Chapter XIV, articles 42 to 51)
Before the Reform, the Rules did not provide for any periodic audit obligation: compliance control depended entirely on whatever internal review, if any, each obligated party chose to carry out on its own initiative, with no minimum standards for content, frequency or the reviewer's qualifications. With the Reform, Chapter XIV is added, introducing this obligation for the first time.
For the first time in the Rules, the Reform introduces the obligation to undergo an annual audit. Under article 42, those who carry out Vulnerable Activities must maintain control measures that include a review, from January 1 through December 31 of each year, by an auditor from their internal audit area or by an independent external auditor, that assesses and opines on the effectiveness of compliance with the Law, the Regulations and the Rules. Results must be presented to the board of directors, the sole administrator, or general management, as applicable.
The Reform distinguishes the type of auditor required based on the obligated party's Risk Level: under article 44, when Risk is assessed as low or medium, the opinion may be issued by an internal audit or internal control area, independent of the Compliance Officer; under article 45, when a high Risk assessment applies or is chosen, the review must be carried out by an independent external auditor who meets specific requirements: a professional degree and license in law, accounting, finance, business administration, computer science or related fields; at least three years of experience in preventing transactions with illegally-sourced funds; a current certification issued by the UIF; no conviction for property crimes; no prior services rendered to the audited party during the audited period that would create a conflict of interest; and no service as the audited party's Compliance Officer during the audited period or the two years that follow.
Articles 47 to 49 detail the audit opinion's mandatory minimum content, which must be divided into sections covering presentation, scope, volume of information and sampling, the audit process, findings, compliance results and corrective actions. Article 48 establishes a five-tier scale of possible results for each obligation assessed: compliant, substantially compliant, partially compliant, non-compliant, and not applicable, each with objective rating criteria. Under article 50, the review and issuance of the opinion must take place within the first three months following the close of the audited year, delivered no later than the last business day of March, and article 51 requires retaining the opinion and its supporting documentation for at least five years. As noted in section 3.8, the first auditable period under the Eighth Transitory Article runs from January 1 through December 31, 2028.
04 · SUBSTANTIVE CHANGES
Information, simplification and repeals
Information exchange between Corporate Groups (amended Chapter VIII, article 35)
Information exchange between members of the same Corporate Group was already regulated before the Reform; the relevant change is that article 35 now expressly narrows its purpose and terms.
Under amended article 35, information exchange between persons who carry out Vulnerable Activities and belong to the same Corporate Group must be limited to cases whose purpose is to strengthen measures and procedures to prevent and detect acts or transactions that could serve to commit the offenses set out in articles 1 and 19 of the Regulations; must take place exclusively between two or more persons carrying out Vulnerable Activities within the same Corporate Group; may only be requested by the representative designated before the SAT; the response must be given in writing, signed by that representative, within a maximum of thirty business days; and the information received may only be used by the party that requested it. The article also requires ensuring the security and confidentiality of the exchanged information, through the mechanisms described in the Internal Policies Manual.
Relevant repeals
In addition to the additions described above, the Reform repeals various provisions whose elimination reduces or simplifies obligations that did exist under the Previous Text: (i) the second and third paragraphs of article 6, which allowed an informational alert about a pending document on the Online Portal to be sent to the registered email address before formal notification, and allowed that email address to be updated by the obligated party itself; with the Reform, that prior-alert mechanism disappears and only the formal Portal-based notification scheme remains; (ii) the second and third paragraphs of article 7, which empowered the SAT to update registration information on its own initiative based on data from other agencies and to notify the obligated party within the following ten business days; with the Reform, that power of unilateral SAT-driven updating is eliminated, and updating the registration becomes the responsibility of the person carrying out the Vulnerable Activity, under the current article 7; (iii) the first paragraph of article 27, replaced by the new scheme under articles 26 Bis, 26 Bis 1 and 26 Bis 2 described in section 4.8; and (iv) article 36 in its entirety, which governed acknowledgment of receipt of electronic notifications (providing that they took effect upon acknowledgment of receipt or, failing that, five business days after the authority made them available). This last repeal should not be read as a direct replacement by new article 36 Bis, since the latter governs a different matter — business days and hours for SAT actions and proceedings — so the Reform simply removes the specific acknowledgment-of-receipt rule without substituting an equivalent one within article 36 itself.
Likewise, section VII of article 3 (the definition of "Dueño Beneficiario"/Beneficial Owner) is repealed, consistent with its replacement by "Beneficiario Controlador"/Controlling Beneficiary explained in section 4.4, and item (v) of subsection (b) of Annex 6 Bis (relating to the knowledge statement for the Beneficial Owner of embassies, consulates and international organizations) is repealed, that matter now falling under the general Controlling Beneficiary regime.
04 · SUBSTANTIVE CHANGES
Annexes and complementary adjustments
Amendments to the Rules' Annexes
The Second Article of Acuerdo 115/2026 amends Annexes 1, 2, 3, 4, 4 Bis, 5, 6, 6 Bis, 7, 7 Bis, 8 and 9, mainly to: (i) replace every reference to "Dueño Beneficiario" (Beneficial Owner) with "Beneficiario Controlador" (Controlling Beneficiary); (ii) incorporate, into the legal-entity identification Annexes (Annexes 4, 4 Bis, 6, 6 Bis, 7 and 7 Bis), the obligation to collect complete data on the representative, legal proxy or person carrying out the act or transaction on behalf of the legal entity, including full name without abbreviations, date of birth, RFC or CURP, and identification data; and (iii) specify, in Annex 3 (individuals), the obligation to record the Customer's activity, occupation, profession or line of business when a Business Relationship is established.
Two entirely new Annexes are added: Annex 2 Bis, which sets out the identification data for registering those who act through a trust (data on the trust, the trustee, the individual delegate trustee, the settlors and the beneficiaries, distinguishing whether they are individuals, legal entities or trusts); and Annex 2 Ter, which sets out the corresponding data for those who act through another legal structure (for example, joint ventures), including data on the legal structure and on its members in their capacity as managing partner, participant or otherwise. Both Annexes form the documentary basis for the new Chapter II Ter described in section 4.7.
Finally, Annex 10 is added, listing the identification information authorities and agencies must provide to the UIF regarding public servants considered Politically Exposed Persons (personal data, area of assignment, address, dates of taking and leaving office, and data on economic dependents), under article 51 Ter of the Law and article 23 Quáter 2 of the Rules described in section 4.5.
Other specific adjustments: collegiate entities, confidentiality and general provisions (Chapters V, VI and VII)
Collegiate Entities (Chapter V). Before the Reform, article 29 required a Collegiate Entity's agreement request to contain the data and documents in Annex 9, without specifying a minimum retention period for that information. With the Reform, an express obligation is added for the Collegiate Entity to state in the agreement that the information and documentation in its possession will be retained for at least ten years from the date of the corresponding act or transaction.
Confidentiality (Chapter VI). Article 31 already imposed, before the Reform, a general confidentiality duty on members of the board of directors, officers, executives, the Compliance Officer, employees, proxies and agents of the person carrying out the Vulnerable Activity. With the Reform, that duty is reworded to expressly clarify that it also covers documentation relating to the identification and control structure of the Controlling Beneficiary, in line with new Chapter III Quinquies described in section 4.4.
Other obligations (Chapter VII). Article 34, which already required setting criteria to classify Customers by risk level, is reworded to expressly cross-reference the new Chapters III Bis and IV. Article 34 Ter is also added, clarifying that those who carry out Vulnerable Activities under Sections C and D of section XII of article 17 of the Law (essentially, notarial and similar public-faith services) must, as applicable, observe the new Chapters II Quáter, III Bis, III Ter, X, XII, XIII and XIV, in accordance with the powers granted to them under their own governing laws and regulatory provisions.
SVA View
From reading the rule to organizational implementation.
The following pages reserve space for two of SVA's interpretive figures: one to translate legal obligations into operational capabilities, and another to prioritize workstreams by time and complexity.
Figure 12
Organizational implementation map
Figure 13
Implementation priority matrix
CLOSING
Conclusions
Acuerdo 115/2026 is the most extensive reform the Rules have undergone since they were first issued in 2013, both in the number of chapters, articles and Annexes it amends, and in the regulatory-model shift it introduces: from a scheme centered predominantly on identification thresholds and Report filing, to a comprehensive risk-management scheme, with explicit assessment, classification, monitoring, training and audit obligations.
The Reform is, at once, the administrative implementation of the 2025 legal reform (Controlling Beneficiary, Politically Exposed Persons) and the vehicle through which a risk-based approach aligned with international standards is incorporated. The transitory regime, made up of twelve articles with deadlines staggered between November 30, 2026 and December 31, 2028, requires that those who carry out Vulnerable Activities not assume a single compliance date, but instead build a calendar differentiated by obligation, with March 1, 2027 particularly relevant as the date on which the substantive obligations of the new Chapters III Bis, III Ter and III Quinquies take effect.
KEY DATE
03 · 01 · 2027The date on which the substantive core of the new model takes effect.
HORIZON
12 · 31 · 2028Close of the first annual audit period contemplated by the transitory regime.

