Research & Insights
REGULATORY / AML

Reform to Mexico's General AML/CFT Rules

What changes, when it applies, and how to prepare. An analysis of Acuerdo 115/2026 and the new risk-management model it imposes on those who carry out Vulnerable Activities.

ScopeThis memorandum is general informational and regulatory content; it is not a legal opinion applied to a specific business model, client, or case. Any application to a specific operational scenario requires additional analysis that takes into account the particular circumstances involved.

SCOPE OF THIS ANALYSIS

Introduction and scope

This memorandum analyzes the main changes introduced by the reform to the "General Rules referred to in the Federal Law for the Prevention and Identification of Transactions with Illegally-Sourced Funds" (the "Rules" or "RCG") contained in Acuerdo 115/2026, issued by the Ministry of Finance and Public Credit (the "SHCP" or the "Ministry"), published in the Federal Official Gazette ("DOF") on August 7, 2026 (the "Reform"). The analysis was prepared exclusively on the basis of the full text of Acuerdo 115/2026, together with the current text of the Federal Law for the Prevention and Identification of Transactions with Illegally-Sourced Funds (the "Law" or "LFPIORPI"), as last amended in the DOF on July 16, 2025, used solely to give context to the Rules' cross-references to the Law.

This memorandum is general informational and regulatory content; it is not a legal opinion applied to a specific business model, client, or case. Any application to a specific operational scenario requires additional analysis that takes into account the particular circumstances involved.

REGULATORY CONTEXT

Background and regulatory framework

The Rules were originally issued through Acuerdo 02/2013 (DOF, August 23, 2013) and amended through Acuerdo 09/2014 (DOF, July 24, 2014, clarified July 31, 2014) and Acuerdo 126/2020 (DOF, November 30, 2020, which incorporated the virtual-assets regime). For purposes of this memorandum, that body of rules constitutes the "Previous Text," substantially amended by Acuerdo 115/2026 as explained in sections 3 and 4 below.

The Reform should not be read in isolation, but as the administrative implementation of changes that, at a higher hierarchical level, were introduced by the reform to the LFPIORPI itself, published in the DOF on July 16, 2025, which replaced the concept of "Dueño Beneficiario" (Beneficial Owner) with "Beneficiario Controlador" (Controlling Beneficiary) (article 3, section III of the Law) and added section IX Bis to that article 3, defining "Persona Políticamente Expuesta" (Politically Exposed Person) with an express cross-reference to the general rules the Ministry issues for that purpose. Acuerdo 115/2026 accordingly aligns the Rules' terminology and obligations with that legal reform, and further develops, at the regulatory level, a set of new substantive obligations on risk management, customer knowledge, training and audit, detailed in section 4.

Acuerdo 115/2026 was signed by Édgar Abraham Amador Zamora, Minister of Finance and Public Credit, dated in Mexico City on July 24, 2026, and published in the DOF on August 7, 2026. It consists of a First Article that amends and adds an extensive number of articles and chapters to the Rules, a Second Article that amends, adds and repeals various Annexes, and twelve transitory articles that set the general effective date and a set of exceptions and deferred deadlines, analyzed in section 3 below.

Figure 01

Regulatory paradigm shift

SVA View
Contrast between the previous, linear and threshold-based model, and the Reform's model, continuous and based on risk management.Before · threshold-based complianceIdentifyAccumulateCross thresholdReportLinear sequence: the obligation arises once the transaction crosses the threshold.Now · comprehensive risk managementAssessClassifyKnowMonitorAlertMitigateAuditContinuous cycle: monitoring results feed back into the assessment instead of closing it.
From threshold-based compliance to comprehensive risk management. A conceptual synthesis of the structural transformation the Reform introduces.

TRANSITORY REGIME

Effective date and transitory regime

General rule on the effective date.

Under the First Transitory Article of Acuerdo 115/2026, the Reform takes effect on November 30, 2026, "except for the exceptions set out in the following transitory articles." In other words, most of the Reform's regulatory content — including the new definitions, the restructured chapters, and the general run of obligations described in section 4 — becomes enforceable from that date, subject to the exceptions described below. Because the transitory regime contains twelve articles with staggered deadlines, those who carry out Vulnerable Activities must build a specific implementation calendar rather than assume a single compliance date.

Risk-based approach assessment (Second Transitory Article).

The risk-based approach assessment referred to in the new Chapter II Quáter of the Rules must be available to the competent authorities, upon request, starting March 1, 2027. The information and factors considered in preparing it must correspond to the immediately preceding year; where information for the full year is not available, the information available from the start of the Vulnerable Activity through the date the assessment is prepared shall be used.

Updated Internal Policies Manual (Third Transitory Article).

Those whose ninety-calendar-day period to have their Internal Policies Manual under article 37 of the Rules has already elapsed must incorporate into that Manual the methodology referred to in Chapter II Quáter (risk-based approach) starting March 1, 2027, and make it available to the competent authorities upon request.

Risk Level, customer knowledge and Controlling Beneficiary (Fourth Transitory Article).

For acts or transactions carried out from March 1, 2027, those who carry out Vulnerable Activities must observe the new Chapters III Bis (classification of the Customer or User's Risk Level), III Ter (Customer or User knowledge) and III Quinquies (Controlling Beneficiary) of the Rules. In other words, while the Reform takes effect on November 30, 2026, the operational applicability of these three chapters — which, together with the risk-based approach, form the substantive core of the Reform — is deferred to March 1, 2027.

24-hour Reports based on facts or indicia (Fifth Transitory Article).

Filing the Reports referred to in articles 26 Bis, 26 Bis 1, 26 Bis 2 and the second paragraph of article 27 of the Rules (that is, the new regime for suspicion-based Reports or Reports based on facts or indicia within the following twenty-four hours) may begin six months after the effective date of the Resolution amending the official Report and Filing forms, which will provide for the express identification of this type of Report. This is therefore a deadline conditioned on a future event (the publication of that Resolution) rather than a fixed date, so those who carry out Vulnerable Activities should monitor SAT and UIF publications on this matter.

Personnel-screening procedures (Sixth Transitory Article).

The personnel-screening procedures referred to in article 39 Bis 2 of the Rules must apply to new hires made from March 1, 2027 onward; that is, they have no retroactive effect on personnel already hired by that date.

First training period (Seventh Transitory Article).

The first annual training period referred to in article 39 Bis of the Rules will run from January 1 through December 31, 2027.

First audit period (Eighth Transitory Article).

For purposes of article 42 of the Rules (annual audit obligation), the first review period will begin on January 1, 2028 and end on December 31 of that same year. Of the entire transitory regime, this is the deadline furthest out in time, suggesting the audit obligation developed under the new Chapter XIV was designed to operate once the model's other elements — risk methodology, customer classification, the Internal Policies Manual, and automated mechanisms — are already implemented and have been operating for a reasonable period.

Automated mechanisms (Ninth Transitory Article).

Those who carry out Vulnerable Activities must have the automated mechanisms referred to in Chapter XIII of the Rules in place no later than June 1, 2027, and those mechanisms must contain the information on acts or transactions carried out from that date onward.

Politically Exposed Persons search (Tenth Transitory Article).

Those who carry out Vulnerable Activities and Financial Entities may use the search referred to in article 23 Quáter 1 of the Rules (the "PEP Search 2.0" application) nine months after Acuerdo 115/2026 takes effect, that is, approximately by the end of August 2027.

Electronic notification system (Eleventh Transitory Article).

The Ministry must implement the technological mechanisms needed to operate the electronic-notification system referred to in article 6 of the Rules within eight months of the Agreement's effective date, that is, approximately by the end of July 2027. This is an obligation of the authority itself, not of the obligated parties.

Virtual Asset Service Providers (Twelfth Transitory Article).

Those who carry out the Vulnerable Activity set out in section XVI of article 17 of the Law (virtual assets) who are already registered on the Online Portal must update and submit the additional information referred to in article 10 Bis of the Rules within six months of the Agreement's effective date, that is, approximately by the end of May 2027.

Figure 02

Phased application 2026–2028

Regulatory
Timeline of the transitory regime: five milestones staggered between 2026 and 2028, plus a conditional deadline for 24-hour Reports.Transitory regime · twelve articlesNOV 30, 2026Generaleffective dateMAR 1, 2027Substantive core:Ch. III Bis, III Terand III QuinquiesMAY–JUN 2027VASPs and automatedmechanismsJUL–AUG 2027Notificationsand PEP Search2028First auditperiodExternal dependency24-hour Reports: six months after the Resolutionthat amends the official forms.There is no singlecompliance date: eachobligation runs on itsown timeline.
The twelve transitory articles do not set a single compliance date: each obligation takes effect on its own timeline.

ARCHITECTURE SHIFT

Structural and substantive changes

The Reform adds eight entirely new chapters (Chapters II Ter, II Quáter, III Ter, III Quáter, III Quinquies, XII, XIII and XIV) and substantially amends five others (Chapters II, II Bis, III, III Bis and X). For each, this analysis first states how it was treated under the Previous Text (or notes that no provision existed at all) and then what the Reform requires from its effective date.

Figure 03

Structural map of chapters

Regulatory
Regulatory column of the chapters affected by the Reform, distinguishing new chapters from amended ones.Regulatory structureWhere the transformation is concentratedCh. IDefinitions, virtual assets and VASPsScopeCh. II QuáterRisk-based approach assessmentRiskCh. III BisCustomer Risk Level classificationRiskCh. III TerCustomer knowledge and transactional profileCustomerCh. III QuáterList of Politically Exposed PersonsPEPCh. III QuinquiesControlling BeneficiaryCBCh. VIIIInformation exchange within Corporate GroupsInformationCh. XReinforced Internal Policies ManualManualCh. XIIStaff training and screeningPeopleCh. XIIIAutomated mechanismsSystemsCh. XIVMandatory annual auditAuditNew chapterAmended chapter
Where the regulatory transformation is concentrated and how the new layers are inserted around risk, customer, PEP, Controlling Beneficiary, the manual, training, systems and audit.
Previous text

Before the Reform, the Rules did not require designing a formal risk-assessment methodology: the compliance model revolved around building identification files and meeting the thresholds for filing Reports, with no chapter dedicated to risk management as such. With the Reform, this changes structurally.

The Reform adds Chapter II Quáter, titled "Risk-Based Approach," which is probably the Reform's most conceptually significant change. Under article 10 Septies, those who carry out Vulnerable Activities must design and implement a methodology to carry out a risk assessment derived from the acts or transactions they conduct, as well as from the Customers or Users with whom they conduct them, their transactions, and their delivery or distribution channels. That methodology must be set out in the Internal Policies Manual or in a separate document, and must describe all processes for identifying, analyzing, understanding, measuring and mitigating risks.

Article 10 Septies 1 requires the methodology to identify, at a minimum, the following risk elements: (a) acts or transactions; (b) type of Customer or User; (c) countries and geographic areas; and (d) transactions and delivery or distribution channels. It also requires using a measurement method that assigns a value to each element and identifying the "Mitigants" (defined in article 3, section XI Quinquies of the Rules as the policies, criteria, measures and procedures that help manage and reduce exposure to the identified risks) already implemented when the methodology is designed. A particularly relevant element is that those who carry out Vulnerable Activities must establish specific indicators tied to the offenses under articles 139 Quáter (terrorist financing) and 400 Bis (money laundering) of the Federal Criminal Code.

Article 10 Septies 2 requires using, at a minimum, information on the total number of Customers or Users, the number of acts or transactions, and the amount transacted over a period of no less than twelve months; where there is no transaction history over that period (for example, for newly established businesses), an initial methodology must be implemented using projected data, updated once the first twelve months of operation are complete. The methodology must be reviewed and, where appropriate, updated whenever new risks are detected, whenever the UIF's National Risk Assessment is updated, or within no more than twelve months of the results of its implementation becoming available. The SAT, for its part, retains the power to review and, where appropriate, flag adjustments to the methodology or the Mitigants when, among other scenarios, it considers that risk management was inadequate in the process of opening, limiting or terminating business relationships.

This risk-based approach is not a standalone chapter: it is the cross-cutting axis from which Chapter III Bis (classification of the Customer's Risk Level), Chapter III Ter (Customer knowledge and transactional profile), the reinforced content of the Internal Policies Manual (Chapter X), and the minimum requirements for automated mechanisms (Chapter XIII) all directly derive. Its correct implementation therefore conditions compliance with the rest of the model.

Figure 04

Architecture of the new AML model

SVA View
The risk-assessment methodology as the axis: it feeds the customer, monitoring and reporting layer, and rests on the manual, systems, training and audit layer.Conceptual architectureRisk-assessment methodologyChapter II Quáter · risk-based approachCustomeridentificationRisk LevelCh. III BisKnowledgeCh. III TerTransactionalprofileMonitoringand alertsReportsart. 26 BisCapabilities that sustain the whole modelPolicies ManualCh. XAutomated mechanismsCh. XIIITraining and screeningCh. XIIAnnual auditCh. XIVEach layer produces the evidence the next one needs to be defensible.
The risk-based approach operates as the pivotal axis: methodology, classification, profile, monitoring, reports, the manual, technology, training and audit all feed into each other.

Classification of the Customer or User's Risk Level (new Chapter III Bis, articles 23 Bis to 23 Bis 4)

Previous text

Before the Reform, the Rules did not provide for individual Customer risk classification: due diligence depended mainly on the type of Customer (individual, legal entity, trust, among others) under the applicable Annex, without distinguishing low, medium or high risk levels. With the Reform, Chapter III Bis is added, introducing that classification as a standalone obligation.

The Rules add Chapter III Bis, which requires having a risk-assessment model consistent with the Chapter II Quáter methodology to classify each Customer or User by individual Risk Level. Article 23 Bis requires establishing at least three classifications: low, medium and high Risk Level, with additional intermediate levels allowed. The initial Risk Level must be determined using the information each Customer or User provides, and the assessment must be repeated at least every six months, more frequently as the Risk Level increases.

Article 23 Bis 2 details the risk factors to be considered, distinguishing between (a) inherent characteristics (the Customer's background, type of person, date of birth or incorporation, line of business or activity, nationality, place of residence, sources of income, and the nature and purpose of the relationship) and (b) transactional characteristics (type, volume, frequency and amount of the acts or transactions, number of counterparties, origin and destination of funds, monetary instrument and currency type). In addition, article 23 Bis 3 requires additional risk factors specifically applicable to Mexican-national Politically Exposed Persons, aimed at verifying that their transactional behavior is reasonable relative to their income, functions and level of responsibility.

Particularly notable is article 23 Bis 4, which establishes a mandatory (non-discretionary) high-risk rating for Customers or Users not resident in Mexican territory who are linked to, or have effects in, countries or jurisdictions that Mexican legislation treats as preferential tax regimes, or countries that Mexican authorities or international bodies of which Mexico is a member determine lack sufficient measures to prevent, detect and combat transactions with illegally-sourced funds, as well as for foreign Politically Exposed Persons. In these cases, those carrying out the Vulnerable Activity must document why those Customers entered into acts or transactions within Mexican territory, and the UIF will publish, through the Online Portal, the list of applicable countries and jurisdictions.

Figure 05

Risk Level pyramid

Regulatory
Pyramid of three Risk Levels — low, medium and high — with the two scenarios in which a high rating is mandatory rather than discretionary.Article 23 BisThree classifications at a minimumHighMediumLowAdditional intermediate levels may be established.Reassessment at least every six months.Mandatory high riskPolitically Exposed PersonsAdditional risk factors to verify thattransactional behavior is reasonablerelative to income and functions.Art. 23 Bis 3Flagged jurisdictionsNon-residents linked to preferentialtax regimes or to countries flagged byauthorities or international bodies.Art. 23 Bis 4
Three classifications at a minimum, with two scenarios in which a high-risk rating is mandatory rather than discretionary.

Figure 06

From factors to Risk Level

Regulatory
Customer-inherent factors and transactional factors feed the Risk Level classification, with an additional layer for PEP, jurisdiction and non-residence.Articles 23 Bis 2 and 23 Bis 3Inherent characteristicsCustomer backgroundType of personBirth or incorporationLine of businessNationality and residenceSources of incomeNature and purposeTransactional characteristicsType of transactionVolume and frequencyAmountNumber of counterpartiesOrigin and destinationMonetary instrumentCurrency typeRisk LevelHighMediumLowLayer that raises the classificationPEPJurisdictionNon-residenceThe classification is determined with the information each Customer provides and is repeated at every review.
Inherent and transactional characteristics converge on the classification, with an additional layer that raises it for PEP status, jurisdiction or non-residence.

Customer or User knowledge and transactional profile (new Chapter III Ter, articles 23 Ter to 23 Ter 5)

Previous text

Before the Reform, monitoring each Customer's transactions was, in essence, limited to the amount-accumulation mechanisms under article 19 of the Rules; there was no express obligation to build and monitor an individual "Transactional Profile," nor a dedicated alert system for detecting deviations from that profile. With the Reform, Chapter III Ter is added precisely to fill that gap.

The new Chapter III Ter requires preparing and observing a customer-knowledge policy that includes, at a minimum: policies and controls to mitigate risks aligned with the Chapter II Quáter methodology; procedures for following up on and monitoring acts or transactions; procedures for properly understanding each Customer's "Transactional Profile" (defined in article 3, section XI Sexties, as the set of elements that make it possible to identify the expected behavior of that Customer's acts or transactions, considering amount, frequency, geographic area, origin and destination of funds and economic activity, among others); the scenarios in which acts or transactions deviate from that profile; and the criteria for assigning and, where appropriate, changing the Risk Level.

Article 23 Ter 2 introduces the obligation to have and implement an alert system capable of timely detecting changes in a Customer's behavior or Transactional Profile that could fall within articles 139 Quáter or 400 Bis of the Federal Criminal Code. For high-Risk-Level Customers, article 23 Ter 3 requires obtaining more information on their predominant activity and conducting stricter review and monitoring, including identification questionnaires that may be carried out remotely, digitally or electronically, provided they carry an Electronic Signature covering the origin and destination of funds.

Article 23 Ter 4 details the enhanced measures applicable to high-Risk-Level Customers: for individuals, adopting enhanced measures to understand the origin and destination of funds and, where applicable, obtaining data on the spouse and economic dependents, as well as on companies and associations with which the Customer has ownership ties; for legal entities, obtaining more information about their principal shareholders or partners, verifying the information provided against the Ministry of Economy's electronic registries; and, for foreign Politically Exposed Persons, additionally obtaining documentation on the spouse and related persons. Finally, article 23 Ter 5 requires that, when a Customer is found to be a high-Risk-Level Politically Exposed Person, approval from an officer or equivalent must be obtained before continuing the relationship or transaction.

Figure 07

Customer lifecycle

SVA View
Ten-step sequence of the Customer lifecycle, from onboarding to the Report, looping back to the Risk Level reassessment.Chapters III Bis and III Ter01Onboarding02Identificationand file03ControllingBeneficiary04PEP and listscreening05Initial RiskLevel06Transactionalprofile07Transactionand record08Continuousmonitoring09Alert andanalysis10Report andreviewReassessment at least every six monthsThe Report doesn't close the relationship: it feeds back into the risk level and the profile.
From onboarding to the Report, in ten steps. The Report doesn't close the relationship: it feeds back into the risk level and the transactional profile.

Figure 08

Transactional profile: expected vs. observed

SVA View
Comparison between the expected transaction range under the transactional profile and observed behavior, with two deviations that fall outside the band.Article 23 Ter · transactional profileTimeTransactionsDeviationDeviationExpected rangeAmountFrequencyGeographyOrigin and destinationBusiness activity
The deviation from the expected range is what triggers the alert. The figure illustrates the logic, not magnitudes: the rule does not set scales.

04 · SUBSTANTIVE CHANGES

Controlling Beneficiary and Politically Exposed Persons

Controlling Beneficiary (new Chapter III Quinquies, articles 23 Quinquies to 23 Quinquies 3)

Previous text

Before the Reform, the Rules referred to this figure as "Dueño Beneficiario" (Beneficial Owner) (defined in the then-current section VII of article 3), and identifying it was resolved, in practice, through a simple knowledge statement included in each identification Annex, with no dedicated chapter, no order of precedence among criteria, and no specific rules for trusts or multi-tiered control structures. With the Reform, section VII of article 3 is expressly repealed and the concept is entirely rebuilt under the name "Beneficiario Controlador" (Controlling Beneficiary).

Consistent with the 2025 legal reform described in section 2.2, the Rules replace every reference to the former "Dueño Beneficiario" with "Beneficiario Controlador" throughout, and add Chapter III Quinquies, dedicated entirely to identifying it. Under article 23 Quinquies, those who carry out Vulnerable Activities must set out in their Internal Policies Manual the criteria, measures and procedures for identifying the Controlling Beneficiary, observing the following order of precedence: (i) the individual or group of individuals who, directly or indirectly, acquires, holds title to, or owns, under any legal title, twenty-five percent or more of the Customer's equity or capital stock; (ii) failing that, the person or group that controls the Customer through other means related to strategy, decision-making and the direction of its main policies; and (iii) failing that, the person holding the position of the most senior administrative officer or top management.

Article 23 Quinquies 1 develops specific rules for trusts, treating as the Controlling Beneficiary any individual who ultimately exercises effective control over the trust through contractual, legal or other powers, whether as trustee, settlor, beneficiary, protector or member of the technical committee. When such persons are themselves legal entities or legal structures, the individual who, going up the chain of ownership and control, ultimately exercises that control must be identified. Identification of the Controlling Beneficiary must take place before the act or transaction is carried out or, at the latest, when the Business Relationship is established, and must be documented, retained and kept up to date for the entire duration of that relationship.

Article 23 Quinquies 2 introduces two exceptions in which Controlling Beneficiary identification data need not be collected: (i) when the Customer is a trust or legal entity listed on Mexican stock exchanges or on foreign securities markets recognized under Mexican law, provided the corresponding ticker symbol, reference or identifier is supplied; and (ii) when the Customer is a legal entity of the type provided for in Annexes 4 Bis, 6 Bis, 7-A and 7 Bis A (essentially, public-law entities and specifically listed government or international bodies). Finally, article 23 Quinquies 3 allows the guidelines the UIF issues, with the SAT's prior opinion, to be taken into account for compliance with this Chapter.

List of Politically Exposed Persons (new Chapter III Quáter, articles 23 Quáter to 23 Quáter 2)

Previous text

Before the Reform, the Rules had no dedicated chapter on Politically Exposed Persons: the relevant search relied directly on the Regulations (articles 45 Ter and 45 Quáter) and article 51 Ter of the Law, without the Rules developing the concept, specifying who is treated as a PEP, or formalizing the use of a specific search tool. With the Reform, Chapter III Quáter is added to expressly cover this subject.

Developing section IX Bis of article 3 of the Law (introduced in the 2025 legal reform), the Rules add Chapter III Quáter, which refines the concept of Politically Exposed Person ("PEP"), including heads of state or government, political leaders, senior government, judicial or military officials, senior executives of state-owned companies, and important officials or members of political parties and international organizations. Also treated as PEPs are the spouse, common-law partner, and relatives by blood or marriage up to the second degree, as well as associates or partners with whom the PEP has ownership ties. National PEPs retain that status for the year following the one in which they left office (with an additional extension rule when the act or transaction takes place within the year immediately preceding the loss of that status).

Article 23 Quáter 1 formalizes mandatory use of the "PEP Search 2.0" application on the UIF's official website for searching national PEPs, using the Advanced Electronic Signature used for the registration process. Financial Entities may request the UIF, by simple written request, to grant them access to that application, subject to compliance with their obligations to prevent transactions with illegally-sourced funds. Article 23 Quáter 2 requires authorities and public bodies to provide the UIF with the information listed in the new Annex 10 (personal data of public servants and their economic dependents), via an Excel-format file uploaded through the application itself.

04 · SUBSTANTIVE CHANGES

Virtual assets, VASPs and legal structures

Virtual assets and Virtual Asset Service Providers (amendment to Chapter II Bis and new articles 24 Bis 2 to 24 Bis 6)

Previous text

Chapter II Bis already governed, since Acuerdo 126/2020, the registration of those who carry out the Vulnerable Activity of virtual assets, but the Rules did not detail the specific content required for Reports related to this type of transaction, nor did they define operational concepts such as custody, facilitation or intermediation of virtual assets. With the Reform, the documentation required for registration is expanded and a full block of articles (24 Bis 2 to 24 Bis 6) is added to fill that gap.

Chapter II Bis, retitled "Registration of Virtual Asset Service Providers," specifies the documentation such providers ("VASPs") must physically submit to the SAT, including a detailed list of individuals and legal entities holding an interest in their capital stock (with name, nationality, address, CURP and RFC, number of shares and par value) and the information corresponding to their Controlling Beneficiary. Existing articles 10 Ter and 10 Quáter remain unchanged as to the deadlines for correcting inconsistencies (five business days) and completing the registration process (thirty business days from when the SAT confirms in writing that it has received all the documentation).

The Rules add a full block of provisions on the content of Reports involving virtual assets (article 24 Bis 2), requiring precise information on the originator, the recipient and, where applicable, the Controlling Beneficiary, including name or corporate name, country or jurisdiction of residence, account or wallet identifier, date and time of the transaction, type of virtual asset, amount expressed in virtual assets and its equivalent in national currency, type of transaction, and the fee charged for the service. That information must be retained for ten years and delivered to the UIF, or to the SAT in exercise of its supervisory powers, upon request.

New articles 24 Bis 3 and 24 Bis 4 define, respectively, what is understood by custody or storage of virtual assets (when the VASP provides services or platforms that allow control, safekeeping or administration of virtual assets on a Customer's behalf) and by facilitation or intermediation (when the VASP provides infrastructure, interfaces or electronic platforms that connect, reconcile or match purchase, sale, exchange or custody transactions in virtual assets, even without holding control over them). When more than one VASP, domestic or foreign, takes part in a facilitation or intermediation transaction, each must independently comply with its own obligations toward its Customers or Users.

Article 24 Bis 5 introduces specific threshold-accumulation rules for subsection (b) of section XVI of article 17 of the Law (fees charged by the VASP): (i) when the transaction reaches or exceeds 210 times the daily UMA value, but the fee is less than 4 times that value, the Report is filed only under subsection (a) of section XVI; (ii) when the fee reaches or exceeds 4 times the daily UMA value, but the transaction amount is less than 210 times that value, the Report is filed only under subsection (b); and (iii) when both scenarios are met simultaneously, a single Report is filed, under subsection (a). These fees are determined individually for each transaction and are not subject to monthly accumulation.

Registration of those acting through trusts and other legal structures (new Chapter II Ter, articles 10 Sexies and 10 Sexies 1)

Previous text

Before the Reform, the Rules did not provide a specific, unified registration, deregistration or update procedure for members of trusts or other legal structures (such as joint ventures) that carry out Vulnerable Activities; that information was, in practice, collected as part of the general registration process under article 4, with no standardized format. With the Reform, Chapter II Ter is added, introducing a dedicated tool.

Chapter II Ter is added to specifically govern the registration, deregistration and updating of members of trusts and other legal structures (for example, joint ventures — Asociaciones en Participación), through a tool published on the Online Portal that generates an XML file with the corresponding information under new Annexes 2 Bis (trusts) and 2 Ter (other legal structures), described in section 4.15. In the case of a joint venture, article 10 Sexies 1 expressly designates the managing partner (asociante) as responsible for registration, using its own Advanced Electronic Signature tied to the joint venture's Federal Taxpayer Registry number.

24-hour Reports based on facts or indicia (articles 26 Bis, 26 Bis 1 and 26 Bis 2)

Previous text

Before the Reform, the urgent Report for facts or indicia already existed, but in a unified and more limited form: the (now repealed) first paragraph of article 27 provided, in a single scenario, that when a person carrying out Vulnerable Activities conducted an act or transaction subject to Report and had additional information, based on facts or indicia, that the funds might come from or be intended to further money-laundering-related offenses, the Report had to be filed with the UIF, through the SAT, within twenty-four hours of learning that information. The Reform does not eliminate this twenty-four-hour obligation: it splits it into three articles with distinct scenarios and extends it to cases not previously expressly covered.

Under new article 26 Bis, for purposes of the second paragraph of section VI of article 18 of the Law, the suspicion-based Report must be sent within twenty-four hours of the moment when, taking into account the information gathered to identify the Customer and the characteristics with which acts or transactions are commonly carried out, the person carrying out the Vulnerable Activity recognizes any unusual activity, conduct or behavior that could be linked to money-laundering-related offenses; this scenario corresponds, in essence, to what the now-repealed article 27 governed. New article 26 Bis 1 extends, for the first time, this twenty-four-hour obligation to cases where the suspicion arises from information obtained from other public or private sources (rather than solely from analysis of the transaction itself) — a scenario the Previous Text did not contemplate.

New article 26 Bis 2 clarifies, also for the first time, that these Reports may be filed even when the act or transaction does not meet the amount or condition to be reportable under article 17 of the Law, and even when the act or transaction was never completed, provided there is data available to identify the Customer or User, or the person who attempted to carry it out. Article 27, which survives with new wording, now only retains the obligation to file a Report, within the period set out in articles 26 Bis and 26 Bis 1, when dealing or attempting to deal with persons included in the list referred to in article 38 of the Rules (the UIF's prevention mechanisms). As explained in section 3.5, the practical operability of this twenty-four-hour regime is conditioned, under the Fifth Transitory Article, on publication of the Resolution updating the official Report and Filing forms.

Figure 09

24-hour Reports based on facts or indicia

Regulatory
Decision tree for the 24-hour Report regime: suspicion may originate from the transaction or the Customer, or from other sources, and both converge on the same reporting duty.Articles 26 Bis, 26 Bis 1 and 26 Bis 2When the 24-hour Report is triggeredFact or indiciumArt. 26 BisSuspicion arising from the transaction or the CustomerThe transaction, or the Customer's orUser's behavior, gives grounds to presumean illegally-sourced fund.Art. 26 Bis 1Suspicion arising from other sourcesThe suspicion comes from informationother than the transaction itself:media, authorities, third parties or lists.Report within 24 hoursApplies even below the thresholdand even if the transaction never closes.Operational application subject to theamendment of the official forms.The deadline runs from when the fact or indicium is learned, not from when the transaction takes place.
Suspicion may arise from the transaction or the Customer, or from other sources, and both paths converge on the same duty. It applies even below the threshold.

Reinforced Internal Policies Manual (Chapter X, articles 37 to 37 Bis 3)

Previous text

Before the Reform, article 37 already required having an Internal Policies Manual within ninety calendar days of registration, but the Rules did not specify its mandatory minimum content, so each obligated party had wide latitude in deciding what to include. With the Reform, article 37 is reworded to expressly refer to the Chapter II Quáter risk methodology, and article 37 Bis is added to set, for the first time, a mandatory minimum content.

Newly created article 37 Bis sets a mandatory minimum content for the Internal Policies Manual, made up of fourteen sections: criteria for identifying and knowing Customers; risk-classification mechanisms; due-diligence measures based on Risk Level; procedures for identifying and enhanced monitoring of PEPs; mechanisms to detect deviations from the Transactional Profile; procedures for filing Reports and Filings; information-retention mechanisms; mechanisms for monitoring and accumulating transactions; mechanisms for identifying persons on domestic or international watchlists; the functions and responsibilities of the Compliance Officer; training programs; internal-control, supervision and audit mechanisms; confidentiality measures; and procedures for updating the Manual itself.

Article 37 Bis 1 introduces a specific obligation for members of a Corporate Group: implementing centralized compliance policies and mechanisms, applicable to all majority-owned branches and affiliates, including foreign ones, provided they apply to all group members, allow information sharing for risk mitigation and identification purposes, and ensure each branch or affiliate complies individually. Article 37 Bis 2, in turn, allows those who determine they will not carry out acts or transactions under certain scenarios to be exempt from establishing policies for those scenarios, provided that fact is recorded in the Manual itself; the exemption ceases to apply the moment such acts or transactions are decided upon. Finally, article 37 Bis 3 confirms the SAT's power to order amendments to the Manual whenever it considers this necessary for compliance with the Rules.

Training and personnel screening (new Chapter XII, articles 39 to 39 Bis 2)

Previous text

Before the Reform, the Rules had no chapter dedicated to training or personnel screening; there was no express obligation to provide annual training, to demonstrate the trainer's minimum experience, or to document screening procedures with signed statements from personnel. With the Reform, Chapter XII is added to fully cover this subject.

A full chapter dedicated to training and personnel screening is added. Article 39 Bis requires implementing training programs aimed at members of the board of directors, the sole administrator, officers, executives, the Compliance Officer and, in all cases, employees who work in public-facing areas, take part in Customer identification or knowledge, in filing Reports, or in audit activities. That training must be given at least once a year, and must cover, at a minimum, knowledge of the Law, the Regulations, the Rules and the Internal Policies Manual, the acts or transactions under article 17 of the Law, and the risks to which the person carrying out the Vulnerable Activity is exposed, in addition to content on techniques and trends for preventing the offenses under articles 139 Quáter and 400 Bis of the Federal Criminal Code. Those who provide the training must demonstrate at least five years of experience in the subject matter.

Article 39 Bis 1 requires retaining, for a minimum of ten years, documentary evidence of programs, workshops, materials, attendance lists, evaluations and corresponding certificates; issuing a certificate requires a knowledge evaluation, and the Internal Policies Manual must set out the measures applicable to those who do not achieve satisfactory results. Article 39 Bis 2, whose application to new hires is deferred to March 1, 2027 under the Sixth Transitory Article, requires establishing screening procedures that ensure personnel's technical quality, experience and good standing, including a signed statement confirming, among other things, that the person has not been convicted of property crimes and is not disqualified from engaging in commerce or holding public office.

Figure 10

Training: minimum universe of people

Regulatory
Annual training reaches the governing body, officers and management, the Compliance Officer, and staff in relevant areas.Chapter XII · articles 39 to 39 Bis 2Who training must reachTraining atleastonce a yearGoverningbodyOfficers andmanagementComplianceOfficerStaff in relevantareasTrainer with demonstrable experience in the subject matter.Documentary evidence kept for every training session held.
Annual training isn't limited to Compliance: it reaches the governing body, officers, and staff in relevant areas.

Automated mechanisms (new Chapter XIII, article 41)

Previous text

Before the Reform, article 18, section X of the Law already required having automated mechanisms to monitor transactions, but the Rules did not specify the minimum functions those mechanisms had to fulfill. With the Reform, Chapter XIII is added, detailing for the first time a catalog of required minimum functions.

Article 41 requires the automated mechanisms referred to in section X of article 18 of the Law to be reasonably adequate to the volume, nature, complexity and risk of the person carrying out the Vulnerable Activity, and to perform, at a minimum, six functions: (i) retaining, updating and allowing lookup of the information in the identification files; (ii) grouping a given Customer's acts or transactions into a consolidated database to monitor and identify deviations from the Transactional Profile, and to carry out the accumulation required under the Law; (iii) supplying the information required by the Chapter II Quáter methodology; (iv) running the Chapter III Bis risk-assessment model, retaining historical Risk Level and Transactional Profile records for at least ten years; (v) running an alert system for high-Risk-Level Customers, PEPs, and persons on prevention lists or linked to high-risk jurisdictions; and (vi) monitoring the use of cash and precious metals under article 32 of the Law.

Figure 11

Six minimum functions of automated mechanisms

Regulatory
The six minimum capabilities article 41 requires of automated mechanisms.Chapter XIII · article 41Having a system is not enough01FilesRetain and allow lookup of Customeridentification files.02ConsolidationGroup transaction informationby Customer.03MethodologyApply the Chapter II Quáterrisk-assessment methodology.04Risk and profileClassify the Risk Level and buildthe transactional profile.05AlertsGenerate alerts on deviationsfrom the expected profile.06Cash and metalsIdentify cash transactions andthose involving precious metals or gems.The six functions are cumulative: missing any one leaves the mechanism incomplete.
Article 41 translated into concrete capabilities. The six are cumulative: missing any one leaves the mechanism incomplete.

Mandatory annual audit (new Chapter XIV, articles 42 to 51)

Previous text

Before the Reform, the Rules did not provide for any periodic audit obligation: compliance control depended entirely on whatever internal review, if any, each obligated party chose to carry out on its own initiative, with no minimum standards for content, frequency or the reviewer's qualifications. With the Reform, Chapter XIV is added, introducing this obligation for the first time.

For the first time in the Rules, the Reform introduces the obligation to undergo an annual audit. Under article 42, those who carry out Vulnerable Activities must maintain control measures that include a review, from January 1 through December 31 of each year, by an auditor from their internal audit area or by an independent external auditor, that assesses and opines on the effectiveness of compliance with the Law, the Regulations and the Rules. Results must be presented to the board of directors, the sole administrator, or general management, as applicable.

The Reform distinguishes the type of auditor required based on the obligated party's Risk Level: under article 44, when Risk is assessed as low or medium, the opinion may be issued by an internal audit or internal control area, independent of the Compliance Officer; under article 45, when a high Risk assessment applies or is chosen, the review must be carried out by an independent external auditor who meets specific requirements: a professional degree and license in law, accounting, finance, business administration, computer science or related fields; at least three years of experience in preventing transactions with illegally-sourced funds; a current certification issued by the UIF; no conviction for property crimes; no prior services rendered to the audited party during the audited period that would create a conflict of interest; and no service as the audited party's Compliance Officer during the audited period or the two years that follow.

Articles 47 to 49 detail the audit opinion's mandatory minimum content, which must be divided into sections covering presentation, scope, volume of information and sampling, the audit process, findings, compliance results and corrective actions. Article 48 establishes a five-tier scale of possible results for each obligation assessed: compliant, substantially compliant, partially compliant, non-compliant, and not applicable, each with objective rating criteria. Under article 50, the review and issuance of the opinion must take place within the first three months following the close of the audited year, delivered no later than the last business day of March, and article 51 requires retaining the opinion and its supporting documentation for at least five years. As noted in section 3.8, the first auditable period under the Eighth Transitory Article runs from January 1 through December 31, 2028.

04 · SUBSTANTIVE CHANGES

Information, simplification and repeals

Information exchange between Corporate Groups (amended Chapter VIII, article 35)

Previous text

Information exchange between members of the same Corporate Group was already regulated before the Reform; the relevant change is that article 35 now expressly narrows its purpose and terms.

Under amended article 35, information exchange between persons who carry out Vulnerable Activities and belong to the same Corporate Group must be limited to cases whose purpose is to strengthen measures and procedures to prevent and detect acts or transactions that could serve to commit the offenses set out in articles 1 and 19 of the Regulations; must take place exclusively between two or more persons carrying out Vulnerable Activities within the same Corporate Group; may only be requested by the representative designated before the SAT; the response must be given in writing, signed by that representative, within a maximum of thirty business days; and the information received may only be used by the party that requested it. The article also requires ensuring the security and confidentiality of the exchanged information, through the mechanisms described in the Internal Policies Manual.

Relevant repeals

In addition to the additions described above, the Reform repeals various provisions whose elimination reduces or simplifies obligations that did exist under the Previous Text: (i) the second and third paragraphs of article 6, which allowed an informational alert about a pending document on the Online Portal to be sent to the registered email address before formal notification, and allowed that email address to be updated by the obligated party itself; with the Reform, that prior-alert mechanism disappears and only the formal Portal-based notification scheme remains; (ii) the second and third paragraphs of article 7, which empowered the SAT to update registration information on its own initiative based on data from other agencies and to notify the obligated party within the following ten business days; with the Reform, that power of unilateral SAT-driven updating is eliminated, and updating the registration becomes the responsibility of the person carrying out the Vulnerable Activity, under the current article 7; (iii) the first paragraph of article 27, replaced by the new scheme under articles 26 Bis, 26 Bis 1 and 26 Bis 2 described in section 4.8; and (iv) article 36 in its entirety, which governed acknowledgment of receipt of electronic notifications (providing that they took effect upon acknowledgment of receipt or, failing that, five business days after the authority made them available). This last repeal should not be read as a direct replacement by new article 36 Bis, since the latter governs a different matter — business days and hours for SAT actions and proceedings — so the Reform simply removes the specific acknowledgment-of-receipt rule without substituting an equivalent one within article 36 itself.

Likewise, section VII of article 3 (the definition of "Dueño Beneficiario"/Beneficial Owner) is repealed, consistent with its replacement by "Beneficiario Controlador"/Controlling Beneficiary explained in section 4.4, and item (v) of subsection (b) of Annex 6 Bis (relating to the knowledge statement for the Beneficial Owner of embassies, consulates and international organizations) is repealed, that matter now falling under the general Controlling Beneficiary regime.

04 · SUBSTANTIVE CHANGES

Annexes and complementary adjustments

Amendments to the Rules' Annexes

The Second Article of Acuerdo 115/2026 amends Annexes 1, 2, 3, 4, 4 Bis, 5, 6, 6 Bis, 7, 7 Bis, 8 and 9, mainly to: (i) replace every reference to "Dueño Beneficiario" (Beneficial Owner) with "Beneficiario Controlador" (Controlling Beneficiary); (ii) incorporate, into the legal-entity identification Annexes (Annexes 4, 4 Bis, 6, 6 Bis, 7 and 7 Bis), the obligation to collect complete data on the representative, legal proxy or person carrying out the act or transaction on behalf of the legal entity, including full name without abbreviations, date of birth, RFC or CURP, and identification data; and (iii) specify, in Annex 3 (individuals), the obligation to record the Customer's activity, occupation, profession or line of business when a Business Relationship is established.

Two entirely new Annexes are added: Annex 2 Bis, which sets out the identification data for registering those who act through a trust (data on the trust, the trustee, the individual delegate trustee, the settlors and the beneficiaries, distinguishing whether they are individuals, legal entities or trusts); and Annex 2 Ter, which sets out the corresponding data for those who act through another legal structure (for example, joint ventures), including data on the legal structure and on its members in their capacity as managing partner, participant or otherwise. Both Annexes form the documentary basis for the new Chapter II Ter described in section 4.7.

Finally, Annex 10 is added, listing the identification information authorities and agencies must provide to the UIF regarding public servants considered Politically Exposed Persons (personal data, area of assignment, address, dates of taking and leaving office, and data on economic dependents), under article 51 Ter of the Law and article 23 Quáter 2 of the Rules described in section 4.5.

Other specific adjustments: collegiate entities, confidentiality and general provisions (Chapters V, VI and VII)

Collegiate Entities (Chapter V). Before the Reform, article 29 required a Collegiate Entity's agreement request to contain the data and documents in Annex 9, without specifying a minimum retention period for that information. With the Reform, an express obligation is added for the Collegiate Entity to state in the agreement that the information and documentation in its possession will be retained for at least ten years from the date of the corresponding act or transaction.

Confidentiality (Chapter VI). Article 31 already imposed, before the Reform, a general confidentiality duty on members of the board of directors, officers, executives, the Compliance Officer, employees, proxies and agents of the person carrying out the Vulnerable Activity. With the Reform, that duty is reworded to expressly clarify that it also covers documentation relating to the identification and control structure of the Controlling Beneficiary, in line with new Chapter III Quinquies described in section 4.4.

Other obligations (Chapter VII). Article 34, which already required setting criteria to classify Customers by risk level, is reworded to expressly cross-reference the new Chapters III Bis and IV. Article 34 Ter is also added, clarifying that those who carry out Vulnerable Activities under Sections C and D of section XII of article 17 of the Law (essentially, notarial and similar public-faith services) must, as applicable, observe the new Chapters II Quáter, III Bis, III Ter, X, XII, XIII and XIV, in accordance with the powers granted to them under their own governing laws and regulatory provisions.

SVA View

From reading the rule to organizational implementation.

The following pages reserve space for two of SVA's interpretive figures: one to translate legal obligations into operational capabilities, and another to prioritize workstreams by time and complexity.

Figure 12

Organizational implementation map

SVA View
Matrix that translates each obligation into four implementation layers: legal basis, process, system and evidence.SVA View · implementationFrom regulatory obligation to operational capabilityEvery obligation needs all four layers to be implementable and, above all, defensible.LegalProcessSystemEvidenceRisk methodologyCh. II QuáterAnnual design and reviewAssessment engineMethodology documentCustomer knowledgeCh. III TerOnboarding and updatesDigital fileField traceabilityControlling Beneficiary and PEPCh. III Quáter and QuinquiesOrder of precedenceList screeningDated recordPolicies ManualCh. XApproval and rolloutVersion controlRead acknowledgment24-hour ReportsArt. 26 BisEscalation and on-callAlerts and formsDecision logTraining and screeningCh. XIIAnnual plan by roleAttendance recordsCertificatesAutomated mechanismsCh. XIIIConfigurationSix minimum functionsRecords and backupsAnnual auditCh. XIVProgram and findingsEvidence repositoryReport and follow-upThe evidence column is what gets reviewed in an inspection: without it, the other three can't be demonstrated.
From regulatory obligation to operational capability. Every obligation needs four layers — legal, process, system and evidence — to be implementable and defensible.

Figure 13

Implementation priority matrix

SVA View
Prioritization matrix by available time and implementation complexity, with the transitory regime's workstreams plotted across four quadrants.SVA View · prioritizationWhat should start firstStart nowLittle time, high complexityDesign and planMore time, high complexityQuick winsLittle time, low complexityScheduleMore time, low complexityMethodologyCustomer knowledgeCB and PEPManualStaff screeningAutomated mechanismsAuditTraining24-hour Reports← Less time availableMore time available →Implementation complexity →External dependency: its clock doesn't start until the official forms are amended.
An executive read on which workstreams should start first, based on available time and implementation complexity.

CLOSING

Conclusions

Acuerdo 115/2026 is the most extensive reform the Rules have undergone since they were first issued in 2013, both in the number of chapters, articles and Annexes it amends, and in the regulatory-model shift it introduces: from a scheme centered predominantly on identification thresholds and Report filing, to a comprehensive risk-management scheme, with explicit assessment, classification, monitoring, training and audit obligations.

The Reform is, at once, the administrative implementation of the 2025 legal reform (Controlling Beneficiary, Politically Exposed Persons) and the vehicle through which a risk-based approach aligned with international standards is incorporated. The transitory regime, made up of twelve articles with deadlines staggered between November 30, 2026 and December 31, 2028, requires that those who carry out Vulnerable Activities not assume a single compliance date, but instead build a calendar differentiated by obligation, with March 1, 2027 particularly relevant as the date on which the substantive obligations of the new Chapters III Bis, III Ter and III Quinquies take effect.

KEY DATE

03 · 01 · 2027

The date on which the substantive core of the new model takes effect.

HORIZON

12 · 31 · 2028

Close of the first annual audit period contemplated by the transitory regime.

About the authors

Carlos Cazares

Co-author

Carlos Cazares

Santiago Graf

Reviewer · Founding Partner

Santiago Graf

ACUERDO 115/2026August 7, 2026