08 / 13 / 26
ANTI-MONEY LAUNDERING COMPLIANCE IS STRENGTHENED AND SHIFTS ITS FOCUS: THE AMENDMENT TO THE GENERAL RULES.
MEXICO CITY, MEXICO, August 13th, 2026 – On August 7, 2026, the Ministry of Finance and Public Credit (the “Ministry”) published in the Official Gazette of the Federation Resolution 115/2026 (the “Resolution”), which amends, adds and repeals various provisions of the General Rules (the “Rules”) issued under the Federal Law for the Prevention and Identification of Transactions with Illicitly Sourced Funds (the “Law”).
The publication of the Resolution is a significant step toward implementing the amendments to the Law, published on July 16, 2025, and to the Regulations of the Law, published on March 27, 2026, as it develops the rules for complying with the obligations introduced through those amendments and establishes new obligations applicable to those carrying out vulnerable activities under the Law (“Vulnerable Activities”).
More than a regulatory update, the new Rules represent a shift in the way compliance is managed with respect to Anti-Money Laundering (“AML”) for the obligated parties that carry out Vulnerable Activities. The model evolves from a documentary approach toward one grounded in risk, client knowledge, automated monitoring, internal controls and documentary evidence.
KEY CHANGES
1. Risk-Based Approach
Those carrying out Vulnerable Activities must design and implement a methodology to identify, analyze, understand, measure and mitigate the risks arising from the acts or transactions they carry out, from their Clients or Users, from their transactions and from the delivery or distribution channels. The methodology must consider, among other elements, the acts or transactions, types of Clients or Users, countries and geographic areas, transactions and channels, as well as the applicable information from the National Money Laundering and Terrorist Financing Risk Assessment.
In addition, they must have a risk assessment model to individually classify their Clients or Users into at least three risk levels: low, medium and high. The risk level must be assessed at least every six months, and more frequently as the Client’s or User’s risk increases.
The foregoing means that compliance no longer rests solely on static files: obligated parties must document their methodology, keep evidence of its implementation and update it when they detect new risks, when the National Money Laundering and Terrorist Financing Risk Assessment is updated or, in any event, within the timeframes set out in the Rules.
2. Internal Policies Manual
The new Rules establish the obligation to have an Internal Policies Manual within 90 calendar days of enrollment and registration as a Vulnerable Activity in the System of the Anti-Money Laundering Portal (the “Portal”). For those already registered and for whom that period has elapsed, the Manual must incorporate the new risk assessment methodology as of March 1, 2027.
Among other aspects, this Manual must address: (i) criteria for identifying and knowing the Client or User; (ii) risk classification mechanisms and due diligence measures consistent with such risk; (iii) procedures for the identification and enhanced monitoring of Politically Exposed Persons; (iv) mechanisms to detect transactions that depart from the transactional profile; (v) procedures for filing notices and reports and retaining information; (vi) transaction monitoring and aggregation mechanisms; (vii) mechanisms to identify persons included in lists issued by national authorities or international organizations; (viii) functions and responsibilities of the Compliance Officer; (ix) training programs; (x) internal control, supervision and audit mechanisms; (xi) confidentiality measures; and (xii) procedures for updating the Manual itself.
3. Greater depth in knowing the client and its beneficial owner
In the same vein, the new Rules establish specific criteria to identify the Beneficial Owner of Clients or Users that are legal entities or trusts, following an order of priority: (i) the individual or group of individuals who directly or indirectly acquires, holds or owns 25% or more of the capital stock; (ii) whoever exercises control by other means and takes part in the strategy, decision-making and direction of the main policies; and, as a last resort, (iii) whoever holds the highest-ranking management or senior executive position. The procedure followed must be documented and kept up to date.
Likewise, specific provisions are incorporated for the identification and treatment of Politically Exposed Persons (“PEP”). Foreign PEPs must be considered high risk; for Mexican PEPs, additional risk factors must be established to determine their risk level. In addition, the “Consulta PEP 2.0” lookup tool is contemplated on the official website of the Financial Intelligence Unit, which may be consulted nine months after the Resolution takes effect.
In this context, the KYC, client-file compilation and updating processes must be aligned with the new risk management model implemented through the Resolution.
4. New rules for filing Notices and Reports
The new Rules specify the circumstances for filing Notices and Reports through the Portal and introduce special Notices that must be submitted within the 24 hours following the occurrence of certain grounds for suspicion, facts or indicators relating to possible transactions with illicitly sourced funds, related offenses or the financial structures of criminal organizations (“24-Hour Notices”).
The main circumstances include: (i) unusual activities, conduct or behavior identified from the Client’s or User’s information and documentation and from the characteristics of their transactions; (ii) facts or indicators learned through public or private sources; and (iii) the circumstances relating to persons included in the lists contemplated by the Rules. These Notices may apply even when the transaction does not reach the ordinary Notice threshold or is not ultimately completed, provided there is data that makes it possible to identify the Client or User or the person who attempted to carry it out.
5. Training, personnel selection and compliance audit
A formal training program must be established, on at least an annual basis, aimed at the management bodies, executives, officers, the Compliance Officer and certain employees involved in dealing with the public, identifying or knowing the Client or User, filing Notices or auditing. Likewise, selection procedures must be established for new hires to help ensure the technical quality, experience and integrity of personnel. The first annual training period will run from January 1 to December 31, 2027.
An annual audit review of the effectiveness of compliance is also introduced. Where the obligated party’s risk is low or medium, the opinion may be issued by an audit or internal control area that is independent from the Compliance Officer; where the risk is high, or where the obligated party so chooses, the review and opinion must be carried out by an independent external auditor who meets the requirements set out in the Rules.
6. Automated Mechanisms
The new Rules establish the obligation to implement automated mechanisms reasonably appropriate to the volume, nature, complexity and risk of the transactions. Among other functions, these mechanisms must retain and update file information; consolidate and monitor transactions by Client or User; identify deviations from the transactional profile; support the aggregation of transactions; provide information for the risk methodology; run the risk assessment model; retain historical records of changes in risk and transactional profile for at least ten years; generate alerts regarding high-risk Clients or Users, PEPs and people included in certain lists; and monitor the use of cash and precious metals.
7. Trusts and other legal structures.
The new Rules incorporate specific provisions for those carrying out vulnerable activities through trusts or other legal structures.
Procedures are established for their enrollment and registration, as well as new annexes and information requirements relating to their participants or members.
KEY DATES
Although the new Rules will take effect on November 30, 2026, some obligations will have specific implementation deadlines after that date. The main ones include:
- The risk-based assessment must be available to the competent authorities, upon request, as of March 1, 2027. For those already registered and for whom the 90-calendar-day period to have their Internal Policies Manual has elapsed, the Manual must include the new methodology as of that same date. Likewise, the rules on risk-level classification, knowledge of the Client or User and Beneficial Owner will apply to acts or transactions carried out as of March 1, 2027.
- The Notices referred to in articles 26 Bis, 26 Bis 1, 26 Bis 2 and 27, second paragraph (24-Hour Notices), may be submitted six months after the resolution amending the official Notice and Report formats to expressly identify these new types of Notice takes effect.
- Personnel selection procedures must be tied to new hires made as of March 1, 2027.
- The first annual training period will run from January 1 to December 31, 2027.
- The first audit review period will run from January 1 to December 31, 2028.
- Automated mechanisms must be implemented no later than June 1, 2027 and contain the information on the acts or transactions carried out as of that date.
- The Ministry must implement the technological mechanisms necessary to operate the electronic notification system within the 8 months following the effective date of the Resolution. Once operational, those carrying out Vulnerable Activities must check the Portal’s electronic media at least once every business day.
- The “Consulta PEP 2.0” tool may be consulted 9 months after the Resolution takes effect.
HOW CAN YOU START COMPLYING?
Given that various obligations will become enforceable on a staggered basis, we recommend that our clients carrying out Vulnerable Activities not wait until the effective date to begin preparing.
In particular, we suggest:
- Diagnose. Identify the gaps between your current compliance model and the new obligations.
- Update. Review and, where appropriate, update the internal policies manual, KYC procedures and client files.
- Implement a risk methodology. Develop a methodology that makes it possible to classify, justify and update clients’ risk levels.
- Strengthen monitoring. Review current transaction-monitoring processes and determine the tools needed to meet the new requirements.
- Prepare personnel and the audit. Design the annual training program and begin preparing the mechanisms needed to evidence compliance and address future reviews.
The publication of the Resolution is the last significant regulatory piece needed to give effect to the obligations introduced in the amendment to the Law and its regulations. The new Rules entail a transition toward a compliance model based on risk, client knowledge, monitoring, training, automation and review.
At SMPS Legal, S.C. we are committed to advising in a preventive and not merely reactive way: reviewing our clients’ compliance in this area, correctly structuring their transactions, and designing internal policies manuals to shield clients and support them in the face of increasingly strict AML regulation.
In light of the foregoing, far from being an obstacle, for us this Resolution represents a valuable opportunity to properly strengthen our clients’ operations. We see this change as a natural step toward a more robust compliance culture that, when well-managed, not only reduces legal risks and fines but also translates into trust and competitiveness for every client that complies with the new requirements set out in the Resolution.
Our team is ready and available to support you in assessing the impact of the new provisions, diagnosing areas of opportunity, updating policies and procedures, and implementing the compliance plan detailed tailored to each client to meet the new deadlines established by the Rules.