Our Expert in Mexico
No results available
Mexico’s anti‑money‑laundering rules require obliged businesses to build robust compliance frameworks under the Federal Law for the Prevention and Identification of Operations with Resources of Illicit Origin (Ley Federal para la Prevención e Identificación de Operaciones con Recursos de Procedencia Ilícita, or LFPIORPI) and its implementing regulations and general rules (Reglas de Carácter General). Best‑practice compliance turns on a risk‑based methodology, individual client files with defined risk tiers, identification of beneficial owners, sector‑specific duties for virtual asset service providers (VASPs), and transaction monitoring proportionate to volume and risk. This article explains who is caught, what should be in place, and the practical steps compliance officers, general counsel and multinational group legal teams should take.
Businesses should confirm the exact obligations and any applicable transitional deadlines against the current text of the LFPIORPI and the general rules published in the Diario Oficial de la Federación (DOF).
This article is for informational purposes only and does not constitute legal advice. Obliged businesses should seek tailored counsel on how the rules apply to their specific activities, and should verify the current text of the law and its regulations before acting.
The LFPIORPI is the primary statute. It is complemented by its implementing Regulation (Reglamento) and by general rules issued by the Secretaría de Hacienda y Crédito Público (SHCP) that give practical effect to the law. Together these instruments convert what can be treated as a form‑filling exercise into a genuine risk‑management discipline. Good practice requires obliged businesses to move from static, one‑size‑fits‑all controls to dynamic, evidence‑based programmes that can be audited and defended before supervisors.
The substantive pillars of a sound AML programme in Mexico are:
| Topic | Basic/static approach | Risk‑based approach | Practical impact |
|---|---|---|---|
| Risk methodology | General identification duties; limited risk differentiation | Documented risk‑based methodology across client, geography and channel | Must build, document and maintain a defensible scoring model |
| Client files & review cadence | Identification records with no fixed internal review interval | Individual files tiered by risk, reviewed on a defined cadence | Requires ongoing monitoring workflow and update logs |
| Beneficial owner | Identification of control less clearly quantified | Ownership‑or‑control threshold applied per current rules for entities and trusts | BO verification and evidence retention for corporate clients |
| VASP duties | Limited sector‑specific traceability | Transaction traceability, enhanced monitoring and reporting | System and process build for virtual asset businesses |
| Monitoring | Manual or minimal monitoring | Monitoring proportionate to volume and risk | Technology investment and calibration governance |
| Data retention | Ad hoc retention | Retention for the statutory period under the LFPIORPI | Storage, security and cross‑border retention planning |
The LFPIORPI regulates persons and entities carrying out actividades vulnerables (vulnerable activities), a defined list of transactions and business lines considered susceptible to money laundering. Note that certain financial‑sector entities (such as banks and securities intermediaries) are supervised under separate AML provisions administered through the CNBV rather than the vulnerable‑activities regime of the LFPIORPI. Understanding whether your business performs a vulnerable activity, and under which regime, is the first and most important compliance question.
The following categories illustrate who typically falls within scope, though the statutory definitions must be checked against each business model:
The Barra Mexicana, Colegio de Abogados provides useful guidance on the professional and ethical dimensions for lawyers whose services fall within the vulnerable‑activity net, particularly around confidentiality and the tension with reporting duties.
Before investing in systems, run a structured scope test:
Because obliged businesses must be able to evidence their reasoning, a documented scope test is itself a compliance artefact that supervisors may request.
One of the most operationally significant elements of any AML programme is the identification of the beneficial owner (BO), the natural person who ultimately owns or controls a legal entity or trust. Mexican requirements draw on widely recognised international standards articulated by the Financial Action Task Force (FATF). The precise ownership or control percentage that triggers identification should be confirmed against the current LFPIORPI general rules and, where applicable, the beneficial‑owner provisions of the Código Fiscal de la Federación, before applying a fixed figure in your procedures.
Under a compliant programme, obliged businesses must look through corporate and trust structures to identify the natural persons who ultimately own or control the client, or who otherwise exercise effective control. This is more demanding than recording a named contact: the ultimate human beneficiaries must be identified and verified, and the analysis documented.
Each client file should contain the BO analysis, supporting corporate documents, identity verification for each identified beneficial owner, and a dated record of when the assessment was performed and last reviewed. Because BO information can change, it should be refreshed on the review cadence discussed below. Good practice makes the file, not the individual transaction, the unit of compliance.
The risk‑based methodology is the engine of an effective programme. It determines how clients are classified, how often they are reviewed, and what enhanced measures apply. A methodology that cannot be explained, tested or reproduced will not satisfy supervisors.
At minimum, the methodology should assess risk across three axes:
Each axis should feed a scoring model that produces an overall classification of low, medium or high risk. The model should be transparent, weighted according to the business’s risk appetite, and calibrated to the actual client base. A simplified illustrative matrix:
| Factor | Low risk | Medium risk | High risk |
|---|---|---|---|
| Client type | Individual, transparent structure | Domestic entity, moderate complexity | Complex/opaque structure, PEP involvement |
| Geography | Domestic, low‑risk jurisdictions | Mixed exposure | Higher‑risk or sanctioned jurisdictions |
| Channel | Face‑to‑face, verified | Remote with strong verification | Anonymous or virtual‑asset heavy |
| Review cadence | Periodic baseline | Periodic baseline | More frequent plus enhanced monitoring |
Individual client files should be reviewed periodically and whenever a material change occurs, with the review documented and any change in risk tier recorded. Set the review interval by risk tier and confirm any minimum periods required by the applicable rules. A robust process assigns clear ownership, triggers enhanced measures automatically when a client moves to high risk, and retains prior versions so the evolution of the assessment is auditable. FATF guidance underpins this risk‑based approach and can be cited to justify the methodology’s design where supervisors question its proportionality.
Where the methodology classifies a client as high risk, including politically exposed persons (personas políticamente expuestas), obliged businesses should apply enhanced due diligence. This is not optional layering; it is the point at which the risk‑based model translates into concrete controls.
PEP status should be identified at onboarding and re‑checked during periodic reviews, because high‑risk relationships presume continuous, not one‑off, scrutiny.
VASPs are among the sectors most affected by evolving AML requirements. The obligations reflect concerns raised by the Unidad de Inteligencia Financiera (UIF) and align with FATF standards on virtual assets, requiring providers to build systems capable of tracing value across transactions and retaining data over the periods required by law.
VASPs should implement traceability so that the origin, destination and parties to virtual asset transactions can be reconstructed. In practice this means capturing counterparty information, linking transactions to identified users, and maintaining the integrity of that data for supervisory review, consistent with the FATF “travel rule” for virtual assets.
Relevant user and transaction data must be retained for the period required by the LFPIORPI and its regulations. Confirm the applicable retention period against the current rules, and treat retention as a substantial storage, security and governance commitment: records must remain accessible, tamper‑evident and recoverable across the full period, even where underlying systems are replaced.
Adequate traceability is not merely storing raw ledger data. It requires that data be structured, searchable and mapped to verified customer identities, so that a specific transaction can be traced end‑to‑end and produced in an intelligible format on request from the UIF.
Where VASPs interact with foreign platforms or correspondents, they must consider how counterparty information is exchanged and how retention and traceability duties operate across borders. Businesses in this space should design onboarding of platform counterparties to capture the information their Mexican obligations require.
Good practice requires transaction‑monitoring capability proportionate to the business’s transaction volume and risk profile. Proportionality is deliberately flexible: a high‑volume institution and a small professional services firm are not expected to deploy identical technology, but both must be able to detect and escalate suspicious patterns systematically.
Businesses can procure specialist monitoring software or build in‑house capability. The decision should turn on transaction volume, complexity, internal expertise and total cost of ownership, including calibration and maintenance, not just licence fees.
Systems should be tested and validated before go‑live and recalibrated periodically. Retain calibration logs, false‑positive analyses and validation reports; supervisors will expect evidence that the system is not merely installed but demonstrably effective and proportionate. “We bought a tool” is not, by itself, compliance.
Whether responding to a new reform with a transitional calendar or simply maturing an existing programme, sequencing matters. Confirm any binding effective dates and transitional deadlines against the version of the general rules published in the DOF, and build your internal milestones around them.
Allocate clear ownership: compliance leads the methodology and files; IT owns the monitoring build; senior management owns high‑risk approvals and audit oversight. Documenting who does what, and by when, is essential to demonstrate that the programme has been operationalised, not merely acknowledged.
For multinational groups, the challenge is reconciling a global AML programme with Mexico‑specific obligations. A group policy that works elsewhere may not satisfy Mexican rules, particularly on retention periods and local review cadences.
Run a Mexico‑specific gap analysis comparing the group programme against local requirements: risk methodology, BO identification, review cadence, VASP retention and transaction monitoring. Where global standards fall short, localise the Mexican programme.
Groups must decide whether to adopt the global policy with a Mexican addendum, or to maintain a standalone localised policy. Either can work, provided the Mexican entity can demonstrate full compliance with local rules on its own terms.
Statutory retention duties and cross‑border data transfers can create conflicts with group data policies and foreign data‑protection regimes. Group‑level BO data sharing must also respect confidentiality obligations and Mexican personal‑data protection law. These tensions should be resolved before go‑live. Groups weighing whether local specialist support is required should consider guidance on when you need a capital markets lawyer in Mexico.
Compliance is not merely good practice, non‑compliance carries real consequences. The SHCP (through the UIF and the Servicio de Administración Tributaria, SAT, for vulnerable‑activity supervision) and, for regulated financial entities, the CNBV hold supervisory and enforcement powers under the applicable AML framework.
Because a mature programme is more auditable, deficiencies are also more visible. Judgments of the Suprema Corte de Justicia de la Nación may, over time, clarify the boundaries of scope and BO disputes, and should be monitored as the framework evolves.
To move from theory to implementation, obliged businesses should assemble a core set of working documents:
These artefacts translate directly into the audit trail supervisors expect.
Mexico’s AML framework requires obliged businesses to build genuine, auditable compliance programmes rather than tick‑box records. The practical priorities are clear: confirm scope, build a documented risk‑based methodology, identify beneficial owners against the current threshold, meet the VASP traceability and statutory retention duties, and deploy monitoring proportionate to volume. Businesses that treat compliance as a structured, ongoing discipline, and that verify obligations against the live text of the LFPIORPI and its general rules, will be best placed to demonstrate compliance and manage enforcement risk. Given the cross‑border and cross‑practice reach of these rules, obliged businesses should consider a bespoke gap analysis tailored to their activities and structure.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Jonatan Graham Canedo at Graham Abogados S.C., a member of the Global Law Experts network.
posted 33 minutes ago
posted 58 minutes ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message