[codicts-css-switcher id=”346″]

Global Law Experts Logo
mexico anti-money-laundering rules

Mexico's Anti‑money‑laundering Rules Under the LFPIORPI: What Obliged Businesses Should Have in Place

By Global Law Experts
– posted 1 hour ago

Mexico’s anti‑money‑laundering rules require obliged businesses to build robust compliance frameworks under the Federal Law for the Prevention and Identification of Operations with Resources of Illicit Origin (Ley Federal para la Prevención e Identificación de Operaciones con Recursos de Procedencia Ilícita, or LFPIORPI) and its implementing regulations and general rules (Reglas de Carácter General). Best‑practice compliance turns on a risk‑based methodology, individual client files with defined risk tiers, identification of beneficial owners, sector‑specific duties for virtual asset service providers (VASPs), and transaction monitoring proportionate to volume and risk. This article explains who is caught, what should be in place, and the practical steps compliance officers, general counsel and multinational group legal teams should take.

Businesses should confirm the exact obligations and any applicable transitional deadlines against the current text of the LFPIORPI and the general rules published in the Diario Oficial de la Federación (DOF).

This article is for informational purposes only and does not constitute legal advice. Obliged businesses should seek tailored counsel on how the rules apply to their specific activities, and should verify the current text of the law and its regulations before acting.

The regulatory architecture, statute, regulation and general rules

The LFPIORPI is the primary statute. It is complemented by its implementing Regulation (Reglamento) and by general rules issued by the Secretaría de Hacienda y Crédito Público (SHCP) that give practical effect to the law. Together these instruments convert what can be treated as a form‑filling exercise into a genuine risk‑management discipline. Good practice requires obliged businesses to move from static, one‑size‑fits‑all controls to dynamic, evidence‑based programmes that can be audited and defended before supervisors.

The substantive pillars of a sound AML programme in Mexico are:

  • Risk‑based methodology. An obliged business should adopt a documented methodology that scores clients and operations by risk across defined axes, rather than treating all clients identically.
  • Individual client files with risk tiering. Each client should have a file classifying the associated risk, with documented periodic review.
  • Beneficial owner (BO) identification. Beneficial owners of legal entities and trusts should be identified, and the applicable ownership or control threshold verified against the current rules, with evidence retained on file.
  • VASP‑specific duties. Virtual asset service providers face traceability, monitoring and reporting requirements consistent with international standards.
  • Transaction monitoring. Obliged businesses should deploy monitoring proportionate to their transaction volume and risk profile.
  • Recordkeeping. Records must be retained for the periods required by the LFPIORPI and its regulations.

Quick comparison: static versus risk‑based AML compliance

Topic Basic/static approach Risk‑based approach Practical impact
Risk methodology General identification duties; limited risk differentiation Documented risk‑based methodology across client, geography and channel Must build, document and maintain a defensible scoring model
Client files & review cadence Identification records with no fixed internal review interval Individual files tiered by risk, reviewed on a defined cadence Requires ongoing monitoring workflow and update logs
Beneficial owner Identification of control less clearly quantified Ownership‑or‑control threshold applied per current rules for entities and trusts BO verification and evidence retention for corporate clients
VASP duties Limited sector‑specific traceability Transaction traceability, enhanced monitoring and reporting System and process build for virtual asset businesses
Monitoring Manual or minimal monitoring Monitoring proportionate to volume and risk Technology investment and calibration governance
Data retention Ad hoc retention Retention for the statutory period under the LFPIORPI Storage, security and cross‑border retention planning

Who is caught, scope of “vulnerable activities” and impacted sectors

The LFPIORPI regulates persons and entities carrying out actividades vulnerables (vulnerable activities), a defined list of transactions and business lines considered susceptible to money laundering. Note that certain financial‑sector entities (such as banks and securities intermediaries) are supervised under separate AML provisions administered through the CNBV rather than the vulnerable‑activities regime of the LFPIORPI. Understanding whether your business performs a vulnerable activity, and under which regime, is the first and most important compliance question.

Exemplar sectors and activities

The following categories illustrate who typically falls within scope, though the statutory definitions must be checked against each business model:

  • Financial institutions and brokers. Banks, securities intermediaries and other regulated financial entities, subject to their own sector‑specific AML rules.
  • Virtual asset service providers. Businesses that carry out operations with virtual assets, to the extent regulated under Mexican law.
  • Real estate professionals. Those involved in the purchase and sale of property.
  • Legal and accounting services. Professionals providing certain services, such as forming or managing companies, administering assets or handling client funds, where those services meet the statutory definition.
  • Trust and corporate service providers. Those administering trusts (fideicomisos) or acting for corporate structures within the vulnerable‑activity definitions.

The Barra Mexicana, Colegio de Abogados provides useful guidance on the professional and ethical dimensions for lawyers whose services fall within the vulnerable‑activity net, particularly around confidentiality and the tension with reporting duties.

How to run a scope test for your business

Before investing in systems, run a structured scope test:

  1. Map every product, service and transaction line against the statutory list of vulnerable activities in the LFPIORPI.
  2. Identify whether any activity exceeds the applicable identification or reporting thresholds set out in the law and its general rules.
  3. Confirm whether the activity is carried out habitually or professionally.
  4. Document the conclusion, including where you determine an activity is not in scope, so the analysis is auditable.
  5. Re‑run the test whenever you launch new products or enter new markets.

Because obliged businesses must be able to evidence their reasoning, a documented scope test is itself a compliance artefact that supervisors may request.

Beneficial ownership: identification and practical steps

One of the most operationally significant elements of any AML programme is the identification of the beneficial owner (BO), the natural person who ultimately owns or controls a legal entity or trust. Mexican requirements draw on widely recognised international standards articulated by the Financial Action Task Force (FATF). The precise ownership or control percentage that triggers identification should be confirmed against the current LFPIORPI general rules and, where applicable, the beneficial‑owner provisions of the Código Fiscal de la Federación, before applying a fixed figure in your procedures.

Legal standard and how it differs from basic identification

Under a compliant programme, obliged businesses must look through corporate and trust structures to identify the natural persons who ultimately own or control the client, or who otherwise exercise effective control. This is more demanding than recording a named contact: the ultimate human beneficiaries must be identified and verified, and the analysis documented.

Identification steps for corporate structures and trusts

  • Obtain the ownership chain and capital structure for corporate clients, including intermediate holding entities.
  • For trusts, identify settlors, trustees, beneficiaries and any person exercising ultimate effective control.
  • Determine which natural persons meet the applicable ownership‑or‑control threshold.
  • Where no person meets the threshold, document the alternative control analysis and identify senior managing officials as appropriate.

Recordkeeping and verification evidence

Each client file should contain the BO analysis, supporting corporate documents, identity verification for each identified beneficial owner, and a dated record of when the assessment was performed and last reviewed. Because BO information can change, it should be refreshed on the review cadence discussed below. Good practice makes the file, not the individual transaction, the unit of compliance.

Risk‑based methodology, required elements and a template approach

The risk‑based methodology is the engine of an effective programme. It determines how clients are classified, how often they are reviewed, and what enhanced measures apply. A methodology that cannot be explained, tested or reproduced will not satisfy supervisors.

Core axes: client, geography and channel

At minimum, the methodology should assess risk across three axes:

  • Client risk. The nature of the client, its structure, its beneficial owners, and whether it involves politically exposed persons (PEPs).
  • Geographic risk. The jurisdictions connected to the client and the transaction, including higher‑risk countries identified by international bodies.
  • Channel risk. How the relationship and transactions are conducted, face‑to‑face, remote, intermediated or through virtual assets.

Risk scoring and tiering

Each axis should feed a scoring model that produces an overall classification of low, medium or high risk. The model should be transparent, weighted according to the business’s risk appetite, and calibrated to the actual client base. A simplified illustrative matrix:

Factor Low risk Medium risk High risk
Client type Individual, transparent structure Domestic entity, moderate complexity Complex/opaque structure, PEP involvement
Geography Domestic, low‑risk jurisdictions Mixed exposure Higher‑risk or sanctioned jurisdictions
Channel Face‑to‑face, verified Remote with strong verification Anonymous or virtual‑asset heavy
Review cadence Periodic baseline Periodic baseline More frequent plus enhanced monitoring

Periodic review process and record templates

Individual client files should be reviewed periodically and whenever a material change occurs, with the review documented and any change in risk tier recorded. Set the review interval by risk tier and confirm any minimum periods required by the applicable rules. A robust process assigns clear ownership, triggers enhanced measures automatically when a client moves to high risk, and retains prior versions so the evolution of the assessment is auditable. FATF guidance underpins this risk‑based approach and can be cited to justify the methodology’s design where supervisors question its proportionality.

Enhanced measures for high‑risk clients and PEPs

Where the methodology classifies a client as high risk, including politically exposed persons (personas políticamente expuestas), obliged businesses should apply enhanced due diligence. This is not optional layering; it is the point at which the risk‑based model translates into concrete controls.

Enhanced due diligence steps

  • Senior approval. Obtain sign‑off from senior management before establishing or continuing a high‑risk relationship.
  • Source of funds and wealth. Conduct a deeper enquiry into the origin of funds and overall wealth.
  • Transaction limits and controls. Apply tighter thresholds and additional approvals for high‑risk activity.
  • Intensified monitoring. Increase the frequency and sensitivity of transaction monitoring for the relationship.

PEP status should be identified at onboarding and re‑checked during periodic reviews, because high‑risk relationships presume continuous, not one‑off, scrutiny.

Virtual asset service providers, traceability and retention obligations

VASPs are among the sectors most affected by evolving AML requirements. The obligations reflect concerns raised by the Unidad de Inteligencia Financiera (UIF) and align with FATF standards on virtual assets, requiring providers to build systems capable of tracing value across transactions and retaining data over the periods required by law.

Transaction traceability requirements

VASPs should implement traceability so that the origin, destination and parties to virtual asset transactions can be reconstructed. In practice this means capturing counterparty information, linking transactions to identified users, and maintaining the integrity of that data for supervisory review, consistent with the FATF “travel rule” for virtual assets.

Retention obligation

Relevant user and transaction data must be retained for the period required by the LFPIORPI and its regulations. Confirm the applicable retention period against the current rules, and treat retention as a substantial storage, security and governance commitment: records must remain accessible, tamper‑evident and recoverable across the full period, even where underlying systems are replaced.

What constitutes adequate traceability

Adequate traceability is not merely storing raw ledger data. It requires that data be structured, searchable and mapped to verified customer identities, so that a specific transaction can be traced end‑to‑end and produced in an intelligible format on request from the UIF.

Interactions with cross‑border VASPs and correspondent platforms

Where VASPs interact with foreign platforms or correspondents, they must consider how counterparty information is exchanged and how retention and traceability duties operate across borders. Businesses in this space should design onboarding of platform counterparties to capture the information their Mexican obligations require.

Automated monitoring systems, what “proportionate to volume” means

Good practice requires transaction‑monitoring capability proportionate to the business’s transaction volume and risk profile. Proportionality is deliberately flexible: a high‑volume institution and a small professional services firm are not expected to deploy identical technology, but both must be able to detect and escalate suspicious patterns systematically.

Vendor and in‑house options

Businesses can procure specialist monitoring software or build in‑house capability. The decision should turn on transaction volume, complexity, internal expertise and total cost of ownership, including calibration and maintenance, not just licence fees.

Minimum functional requirements

  • Alerting. Rule‑based and, where appropriate, behavioural alerts on unusual activity.
  • Audit trail. Immutable logs of alerts, dispositions and decisions.
  • Subject‑matter review. Workflow enabling qualified staff to review, escalate or clear alerts.
  • Calibration records. Documentation of thresholds and tuning changes over time.

Test, validation and calibration

Systems should be tested and validated before go‑live and recalibrated periodically. Retain calibration logs, false‑positive analyses and validation reports; supervisors will expect evidence that the system is not merely installed but demonstrably effective and proportionate. “We bought a tool” is not, by itself, compliance.

Compliance roadmap and immediate action plan

Whether responding to a new reform with a transitional calendar or simply maturing an existing programme, sequencing matters. Confirm any binding effective dates and transitional deadlines against the version of the general rules published in the DOF, and build your internal milestones around them.

Short‑term checklist for the next 90 days

  1. Complete a scope test confirming which activities are caught, and under which regime.
  2. Draft or update the risk‑based methodology framework.
  3. Design the individual client file template with risk tiering and BO fields.
  4. Begin BO identification for existing high‑value clients.
  5. Scope automated monitoring options and start vendor evaluation.
  6. Assign a responsible compliance officer and governance structure.
  7. Build a training and audit roadmap mapped to your internal milestones.

Responsibilities and delegation

Allocate clear ownership: compliance leads the methodology and files; IT owns the monitoring build; senior management owns high‑risk approvals and audit oversight. Documenting who does what, and by when, is essential to demonstrate that the programme has been operationalised, not merely acknowledged.

Cross‑border groups, aligning global AML programs with Mexican requirements

For multinational groups, the challenge is reconciling a global AML programme with Mexico‑specific obligations. A group policy that works elsewhere may not satisfy Mexican rules, particularly on retention periods and local review cadences.

Gap analysis template

Run a Mexico‑specific gap analysis comparing the group programme against local requirements: risk methodology, BO identification, review cadence, VASP retention and transaction monitoring. Where global standards fall short, localise the Mexican programme.

Group versus localised policies

Groups must decide whether to adopt the global policy with a Mexican addendum, or to maintain a standalone localised policy. Either can work, provided the Mexican entity can demonstrate full compliance with local rules on its own terms.

Data residency, retention and confidentiality

Statutory retention duties and cross‑border data transfers can create conflicts with group data policies and foreign data‑protection regimes. Group‑level BO data sharing must also respect confidentiality obligations and Mexican personal‑data protection law. These tensions should be resolved before go‑live. Groups weighing whether local specialist support is required should consider guidance on when you need a capital markets lawyer in Mexico.

Enforcement risk, penalties and supervisory approach

Compliance is not merely good practice, non‑compliance carries real consequences. The SHCP (through the UIF and the Servicio de Administración Tributaria, SAT, for vulnerable‑activity supervision) and, for regulated financial entities, the CNBV hold supervisory and enforcement powers under the applicable AML framework.

Supervisory powers and consequences

  • Administrative penalties. Financial sanctions for failures in identification, reporting, recordkeeping or programme maintenance, at the levels set out in the LFPIORPI.
  • Criminal referral triggers. Serious breaches connected to illicit‑origin operations can lead to criminal exposure under the Código Penal Federal.
  • Supervisory scrutiny. Expect requests for methodology documentation, client files, monitoring calibration records and audit reports.

Because a mature programme is more auditable, deficiencies are also more visible. Judgments of the Suprema Corte de Justicia de la Nación may, over time, clarify the boundaries of scope and BO disputes, and should be monitored as the framework evolves.

Practical templates and annexes

To move from theory to implementation, obliged businesses should assemble a core set of working documents:

  • Risk methodology checklist. A template capturing the client, geography and channel axes and scoring logic.
  • Client file index. A standard structure for identity, BO analysis, risk tier and review history.
  • BO questionnaire. A standardised form to capture ownership chains and control.
  • Vendor RFP checklist. Functional requirements for transaction‑monitoring procurement.
  • Sample policy clause for VASPs. Draft language covering traceability and statutory retention.

These artefacts translate directly into the audit trail supervisors expect.

Conclusion: building an auditable AML programme

Mexico’s AML framework requires obliged businesses to build genuine, auditable compliance programmes rather than tick‑box records. The practical priorities are clear: confirm scope, build a documented risk‑based methodology, identify beneficial owners against the current threshold, meet the VASP traceability and statutory retention duties, and deploy monitoring proportionate to volume. Businesses that treat compliance as a structured, ongoing discipline, and that verify obligations against the live text of the LFPIORPI and its general rules, will be best placed to demonstrate compliance and manage enforcement risk. Given the cross‑border and cross‑practice reach of these rules, obliged businesses should consider a bespoke gap analysis tailored to their activities and structure.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Jonatan Graham Canedo at Graham Abogados S.C., a member of the Global Law Experts network.

Sources

  1. Diario Oficial de la Federación (DOF)
  2. Cámara de Diputados, Leyes Federales (including the LFPIORPI)
  3. Secretaría de Hacienda y Crédito Público (SHCP)
  4. Portal de Prevención de Lavado de Dinero (SAT), vulnerable activities
  5. Comisión Nacional Bancaria y de Valores (CNBV)
  6. Financial Action Task Force (FATF)
  7. Barra Mexicana, Colegio de Abogados, A.C.
  8. UN Office on Drugs and Crime (UNODC), Money‑laundering guidance
  9. Suprema Corte de Justicia de la Nación (SCJN)

FAQs

Who must comply with Mexico's AML rules?
Any person or entity performing “vulnerable activities” under the LFPIORPI, including many professional service providers, real estate brokers and VASPs, as well as regulated financial institutions under their own sector‑specific AML rules. Use the scope‑test checklist in this article to confirm whether your activities are caught and under which regime.
Obliged businesses must identify the natural persons who ultimately own or control a client. Confirm the applicable ownership‑or‑control threshold against the current general rules, implement BO verification, and retain supporting evidence in each individual client file.
Virtual asset service providers should implement transaction traceability, retain relevant user and transaction data for the statutory period, and integrate enhanced monitoring and reporting consistent with FATF standards.
Individual client files should be reviewed periodically, with the interval driven by risk tier and any minimum period set by the rules, and whenever a material change occurs, with documented updates and enhanced measures applied to high‑risk clients.
Conduct a Mexico‑specific gap analysis, localise documentation, confirm retention policies meet Mexican requirements, and ensure audit cycles map to Mexican timelines and personal‑data rules.
Proportionality reflects transaction volume, client‑base complexity and risk profile. At minimum, systems must generate auditable alerts, maintain logs and retain calibration records.
Check the consolidated text of the LFPIORPI, its Regulation, and the SHCP general rules as published in the Diario Oficial de la Federación, together with UIF and CNBV guidance, before finalising any procedure.
Amit Mishra Joins as Exclusive Commercial Litigation Member in India | GLE News
By Global Law Experts

posted 48 minutes ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Mexico's Anti‑money‑laundering Rules Under the LFPIORPI: What Obliged Businesses Should Have in Place

Send welcome message

Custom Message