On August 7, 2026, the Ministry of Finance and Public Credit published Agreement 115/2026 in the Official Gazette of the Federation, amending, adding, and repealing various provisions of the General Rules (RCG) referred to in the Federal Law for the Prevention and Identification of Operations with Illicit Proceeds (LFPIORPI).
The amendment is part of the regulatory implementation process resulting from the changes published in July 2025 to the LFPIORPI and the modifications to its Regulations. In general terms, it strengthens the preventive approach, requires more comprehensive risk management documentation, and expands obligations regarding identification, monitoring, training, systems, and auditing. For obligated parties, its practical significance lies in the need to promptly adjust their risk models, manuals, records, technological mechanisms, and corporate governance controls in accordance with a phased implementation schedule.
The concept of “Beneficial Owner” is repealed, and the definition of “Controlling Beneficiary” is reformulated, with a standardized threshold of 25% or more of the share capital or its equivalent.
Likewise, definitions related to the new obligations are incorporated, including those for National Risk Assessment, Risk Level, Internal Policy Manual, Automated Mechanisms, Data Message, Mitigants, and Transaction Profile.
The amendment updates the registration and enrollment system to cover four categories: individuals, corporations, trusts, and other legal entities. When a Vulnerable Activity is conducted through a trust or other legal entity, the information must be submitted in accordance with the new Annexes 2 Bis and 2 Ter and sent via the Portal’s tools.
If the obligated party is unable to process its own deregistration from the Registry, the SAT may do so directly, upon request by an interested party who provides the information and documentation proving such inability.
Digital documents sent by the SAT through the Portal must be opened within three business days of their dispatch; failure to do so will result in the notification being deemed to have been served on the fourth business day.
Consequently, obligated parties must check the Portal at least once every business day to promptly identify any requests, warnings, summonses, resolutions, or other communications from the authority.
The obligation to design and implement a risk assessment methodology has been introduced. The methodology must be included in the Internal Policy Manual or an equivalent document and describe the processes for identifying, analyzing, understanding, measuring, and mitigating the risks associated with Vulnerable Activities, Clients or Users, transactions, and delivery or distribution channels.
The methodology must include specific indicators related to the crimes set forth in Articles 139-Quater and 400-Bis of the Federal Criminal Code. For its implementation, information covering a period of no less than twelve months must be used; where no historical data exists, projected data may be used. Furthermore, the methodology must be updated upon the identification of new risks or changes in the National Risk Assessment and must be retained for ten years.
Obligated parties must have a risk assessment model, consistent with the Risk-Based Approach methodology, that allows for the individual classification of each Customer or User by Risk Level. The model must be set forth in the Internal Policy Manual.
The classification must include at least three levels: low, medium, and high. The risk level assessment must be conducted, as a general rule, at least every six months, and more frequently when the risk level is higher. Certain customers or users who are not residents of Mexico and are linked to high-risk countries or jurisdictions, as well as foreign Politically Exposed Persons (PEPs), must also be considered high risk, among others.
In the case of Politically Exposed Persons of Mexican nationality, additional risk factors must be determined to assess whether their transactional behavior reasonably corresponds to their income, functions, position, and responsibilities, based on the available information (Art. 23 Bis 3).
When a customer or user is classified as high risk, additional information regarding their primary activity must be requested, and their transactional behavior must be subject to stricter review and monitoring. Likewise, enhanced due diligence measures must be applied to obtain additional information on the source and destination of funds and on the related acts or transactions. These questionnaires may be completed remotely, via digital or electronic means, and must bear the electronic signature of the person completing them.
The reform strengthens the Know Your Customer policy by requiring obligated parties to define a Transactional Profile and monitor the expected behavior of each customer.
To this end, they must monitor their actions or transactions, identify significant deviations, and implement alerts to detect changes in the Transaction Profile. This profile must be evaluated at least every six months.
The new Chapter III-Quater defines domestic and foreign Politically Exposed Persons (PEPs) and includes provisions for treating family members and individuals with patrimonial or financial ties as PEPs.
For domestic PEPs, this status remains in effect for the year following the year in which they left office or, in certain cases, for the year following the relevant act or transaction.
The reform also provides for the screening of domestic PEPs through the FIU’s “PEP 2.0 Screening” application, a key tool for documenting identification and strengthening due diligence controls.
A specific chapter on the Controlling Beneficiary has been added. Entities engaged in Vulnerable Activities must establish internal criteria and procedures to identify the Controlling Beneficiary, document the procedure followed, retain the corresponding supporting documentation, and keep it up to date throughout the Business Relationship.
Identification must be carried out prior to the transaction or operation or, at the latest, upon establishing the business relationship. Limited exceptions are provided, primarily for clients or users listed on recognized stock exchanges and certain legal entities subject to simplified regimes.
The reform provides greater flexibility regarding the manner in which the single identification file is maintained. Obligated parties may maintain it in physical or electronic format, provided that all relevant data, documents, and supporting records are integrated into a single file.
The file must allow for the reconstruction of transactions or operations and must be made available to the FIU or the SAT upon request.
Chapter IV is renamed “Notices and Reports” and specifies the rules for determining the date of the act or transaction that triggers the calculation of the filing deadline. It also regulates specific scenarios related to virtual assets, custody, facilitation or intermediation, consideration, and co-ownership in leases.
The report indicating that no acts or transactions subject to a Notice have taken place (“zero report”) is retained and clarified; once submitted, it may not be modified or deleted. In addition, the Notice of Suspicion and the Notice Based on Facts or Indications are incorporated, both with a 24-hour filing deadline:
Notice Based on Suspicion. This applies when the obligated party identifies any unusual activity, conduct, or behavior by a Customer or User linked to possible crimes involving transactions with proceeds of crime or related offenses. To identify such activity, at least the following must be considered: amounts, frequency, payment methods, time periods and payment instruments, geographic area, and the type or nature of the act or transaction.
Notice Based on Facts or Indications. This applies when, based on information obtained from other public or private sources, an action, event, or occurrence related to a Client or User comes to light that suggests the funds used in their actions or transactions may be linked to potential crimes involving transactions with funds of illicit origin or related crimes.
Transactions Below the Threshold or Not Completed. Both notices may be submitted even if the act or transaction does not reach the amount or meet the conditions that would normally trigger a notice, and even when the transaction has not been completed, provided there is information available to identify the Customer or User or the person who attempted to carry it out.
The Internal Policy Manual serves as the cornerstone of the compliance program. It must include, among other elements, the Risk-Based Approach methodology; the criteria for identifying and verifying Customers or Users; risk classification; differentiated due diligence; procedures applicable to PEPs and Controlling Beneficiaries; the submission of Notices and Reports; record retention; training; internal control; auditing; and updates to the Manual itself.
Annual training and awareness programs must be implemented for the governing bodies, executives, officials, Compliance Officers, and relevant operational staff. The content must be consistent with the identified risks, include assessments, and be supported by records and other documentary evidence, which must be retained for at least ten years.
Selection procedures must also be established to verify the technical qualifications, experience, and good character of staff, as well as to collect signed statements regarding criminal history and disqualifications.
Automated mechanisms must be reasonably appropriate to the volume, nature, complexity, and risk of operations. They may consist of specialized computer systems or automated processes supported by spreadsheets, databases, or other equivalent means, provided that they are verifiable by the authority and allow, among other functions, for the retention and consultation of records, the consolidation of transactions by client or user, the feeding of data into the risk methodology, the execution of classification, the generation of alerts, and the retention of historical records for at least ten years.
An annual review of compliance with the LFPIORPI, its Regulations, and the RCG is established, covering the period from January 1 to December 31 of each year. The results must be presented to the governing body or the individual carrying out the Vulnerable Activity in order to evaluate the effectiveness of the measures implemented and to follow up on corrective actions.
The obligated party’s risk level—determined in accordance with its risk-based approach methodology—defines who must issue the audit report. For low or medium risk, the audit report may be issued by the internal audit or control department, provided it is independent of the Compliance Officer. If the risk is high, or if the obligated party so chooses, an independent external auditor must conduct the review.
The audit report must be prepared using a clear methodology and divided, at a minimum, into the following sections: introduction, scope, volume of information and sampling, audit process, findings, compliance results, and corrective actions and recommendations for improvement. The audit report must be submitted no later than the last business day of March.
The audit report and the supporting information and documentation must be retained for a period of no less than five years and made available to the SAT upon request.
As a general rule, the Agreement will enter into force on November 30, 2026, subject to the exceptions set forth in the following transitional provisions:
(a) Gap Analysis: It is recommended to conduct a comprehensive assessment of the current state of compliance with the new obligations in order to identify areas requiring priority adjustments.
(b) Phased Implementation Plan: Given that the reform includes different effective dates, it is advisable to design a work plan that allocates resources and assigns responsibilities in accordance with the implementation schedule, prioritizing obligations effective as of March 1, 2027.
(c) Internal Policy Manual: The Manual serves as the cornerstone of the compliance program. It is essential to update or, if necessary, develop the Manual to incorporate the Risk-Based Approach methodology, risk classification criteria, differentiated due diligence procedures, and other elements required by the RCG.
(d) Automated Mechanisms: It is recommended to evaluate the current technological infrastructure to determine whether it meets the requirements set forth in Article 41 of the RCG. It should be noted that automated mechanisms may range from specialized computer systems to processes supported by spreadsheets or databases, provided they can be verified by the regulatory authority.
(e) Training: The first annual training period runs from January 1 to December 31, 2027. It is recommended to design the program in advance, ensuring that it is consistent with the identified risks and includes evaluation mechanisms and documentary records, which must be retained for at least ten years.
(f) Audit: It is advisable to select an auditor—internal or external, depending on the risk level—in advance and to familiarize yourself with the minimum content of the audit report, given that the first audit period will run from January 1 to December 31, 2028.
(g) Non-compliance Risks: It is important to bear in mind that failure to comply with the obligations set forth in the LFPIORPI and its RCG may result in the imposition of fines, which are determined in accordance with Articles 53 and 54 of the Law. In addition, the audit report must include a financial projection of the amount of the corresponding fines in the event that the identified findings are not addressed.
At Mijares, we have extensive experience advising obligated parties on compliance with their anti-money laundering obligations. We are available to answer any questions you may have and assist you in bringing your organization into compliance with the new requirements.
For any related inquiries, please contact our Regulatory Compliance team.
Legal Notice: This Client Alert is for informational purposes only and does not constitute legal advice or a formal opinion on any specific matter. The information contained herein reflects a general analysis prepared by our attorneys based on information available at the time of publication. Any reproduction, citation, or reference to this content must be expressly attributed to Mijares and should not be construed as a public statement or comment made by the firm to the media.
Awards














