Publications

Garrigues

ELIGE TU PAÍS / ESCOLHA O SEU PAÍS / CHOOSE YOUR COUNTRY / WYBIERZ SWÓJ KRAJ / 选择您的国家

Mexico: New anti-money laundering rules require obligated parties to implement a comprehensive risk-based compliance framework by 2027

Mexico - 

Mexico has crystallised its anti-money laundering regulatory reform by imposing new compliance obligations on obligated parties. The rules set out how the risk-based approach is to be applied and establish deadlines for adapting processes, controls, audits and technology systems.

On 7 August 2026, Agreement 115/2026 -amending the General Rules (Reglas de Carácter General, RCG) issued under the Federal Law for the Prevention and Identification of Transactions Involving Proceeds of Illicit Origin (Ley Federal para la Prevención e Identificación de Operaciones con Recursos de Procedencia Ilícita, LFPIORPI)- was published in the Official Federal Gazette (Diario Oficial de la Federación).

The new RCG develop the obligations introduced by the reform to the LFPIORPI published on 16 July 2025 and will enter into force on 30 November 2026, except where specific deadlines apply to certain obligations.

The amended RCG constitute the long-awaited regulatory development needed to operationalize the new obligations the LFPIORPI imposed on parties carrying out vulnerable activities. The framework moves beyond its former emphasis on client identification, file assembly, transaction aggregation and the filing of notices, and now demands a comprehensive risk-based anti-money laundering compliance system. In this context, the RCG address, among other matters, the risk-based approach, customer due diligence, politically exposed persons ("PEPs"), the ultimate beneficial owner, automated mechanisms, and auditing.

In operational terms, the new regime calls for more than merely updating the internal policies manual. For many obligated parties it will entail reviewing -and, where necessary, redesigning- onboarding and know-your-customer processes; establishing a formal methodology to identify, measure and mitigate risks; classifying clients by risk level; defining and monitoring their transactional profiles; applying enhanced due diligence measures where appropriate; strengthening the identification of beneficial owners and PEPs; implementing verifiable automated alert systems; establishing procedures for 24-hour notices; reinforcing staff training and selection; and generating sufficient evidence for audit reviews. Accordingly, all decisions, controls and measures adopted must be justifiable and demonstrable to the authorities on the basis of the risk identified.

Regulatory evolution of the LFPIORPI framework

The publication of the new RCG completes the regulatory development initiated with the July 2025 reform to the LFPIORPI. Since then, the new compliance framework has been built in three stages:

Key developments in the amended RCG

  • Risk-based approach (chapter II quáter). The obligation to design and implement a risk assessment methodology is established, taking into account transactions, client types, geographical areas and distribution channels, as well as specific indicators linked to the offences set out in articles 139 quáter and 400 bis of the Federal Criminal Code.
  • Client risk classification (chapter III bis). An assessment model must be maintained that classifies clients or users by individual risk level -low, medium and high, at a minimum- and evaluates them at least every six months.
  • Customer due diligence (chapter III ter). A comprehensive policy is developed incorporating the transactional profile, an alert system, enhanced monitoring for high-risk clients and identification questionnaires, together with reinforced measures for PEPs and their spouses or economic dependants.
  • PEP list (chapter III quáter). The definition of politically exposed person -both domestic and foreign- is set out in detail, extending to spouses, common-law partners and relatives up to the second degree. Consultation shall be conducted through the FIU's Consulta PEP 2.0 application.
  • Ultimate beneficial owner (chapter III quinquies). Detailed criteria for identification are established, following an order of priority beginning with the natural person holding 25% or more of the share capital, followed by the person exercising control by other means and, ultimately, the most senior administrative officer. For trusts, a specific analysis is required to identify the natural persons who ultimately exercise effective control; where any relevant party is a legal entity or legal arrangement, the chain of ownership and control must be followed through to a natural person.
  • Notices on suspicion and on facts or indications (24-hour notice). Greater detail is provided on the notices that must be filed within 24 hours of the recognition of suspicious client activity or becoming aware of facts that may link funds to money laundering offences.
  • Internal policies manual (chapter X). Obligated parties must maintain an up-to-date manual containing at least 14 sections, including client identification criteria, risk classification mechanisms, due diligence procedures, functions of the designated compliance representative, training program and audit mechanisms.
  • Automated mechanisms (chapter XIII). Systems must be reasonably adequate to the volume and complexity of transactions. They may include specialist software, spreadsheets or databases, provided they fulfil functions related to record-keeping, aggregation, monitoring, risk classification and alert generation.
  • Aggregation rules and triggering date for each notice (articles 19, 24 bis and 24 bis 1). Aggregation over periods of up to six months is maintained and expressly linked to automated mechanisms. The RCG specify the date of the transaction to be taken into account for each vulnerable activity—a significant point, as the deadline for filing the notice runs from that date. It is also clarified that, as a rule, a notice must be filed for each transaction that, individually or by aggregation, reaches the reporting threshold, subject to specific criteria for certain activities. By way of example, for service or credit cards the relevant transaction is the accumulated monthly expenditure; for funds directed to a single real estate development, the transactions of the calendar month may be included in a single notice, subject to the conditions set out in the RCG.
  • Staff training and selection (chapter XII). Mandatory annual training program with minimum content requirements are imposed, along with personnel selection procedures to ensure technical quality, experience and integrity. Trainers must demonstrate at least five years' experience in AML and related offences.
  • Audit (chapter XIV). An annual review, covering January to December, is required—either by internal or external audit. For low- or medium-risk obligated parties, the review may be conducted through internal audit; for high-risk obligated parties, an independent external auditor holding a current FIU certification must be engaged. The audit report must contain findings, corrective actions and an individualised assessment of each obligation.
  • Trusts and other legal arrangements (chapter II ter). A registration and enrolment obligation is introduced for those carrying out vulnerable activities through trusts or other legal arrangements, including joint ventures (asociaciones en participación), with specific annexes and procedures created for these cases.
  • Virtual assets (articles 24 bis 2 to 24 bis 6). Specific obligations are detailed for virtual asset service providers (VASPs), including information to be retained on the originator, recipient and beneficial owner, as well as account or wallet identifiers and other data enabling traceability of each transaction.
  • Electronic notifications (article 6). Obligated parties are required to check the portal at least once every business day. Once an electronic notification has been sent and received, the obligated party has three business days to open the digital document; failing which, the notification shall be deemed served on the fourth business day.
  • Non-profit associations and entities (articles 38 bis, 38 bis 1 and 38 bis 2). The FIU must apply proportionate measures based on the terrorist financing risk to certain non-profit organisations. These measures may be applicable even where the organisation is not considered a vulnerable activity under article 17 of the Law.

Staggerd implementation deadlines

The amended RCG provide for a phased entry into force. The key dates are as follows:

Looking ahead

With the publication of the amended RCG, the regulatory development initiated with the July 2025 reform to the LFPIORPI is now complete. Obligated parties now have greater certainty regarding the scope and deadlines of the new obligations: general entry into force is set for 30 November 2026, and several of the obligations with the greatest operational impact must be implemented from 1 March 2027.

Implementation goes beyond a documentary update. For many obligated parties it will involve reviewing processes, assigning responsibilities, adapting technology tools, training staff and strengthening risk controls. It is therefore advisable to conduct a gap analysis without delay to define priorities, assign responsibilities and establish an implementation timeline aligned with the regulatory deadlines.

Timely action is particularly important given the authority's enhanced verification powers, which are reinforced through cross-referencing of official databases and artificial intelligence. Moreover, spontaneous compliance prior to the commencement of such powers may be taken into account by the authority and, in the circumstances provided by law, may result in the authority refraining from imposing sanctions. Anticipating implementation will therefore reduce the regulatory exposure associated with delayed adaptation.