AMENDMENTS TO THE GENERAL RULES OF THE ANTI-MONEY LAUNDERING MEXICAN LAW

WRITTEN BY

On August 7, 2026, the Agreement amending the General Rules referred to in the Federal Law for the Prevention and Identification of Transactions with Funds from Illicit Origins (the “Anti-Money Laundering Rules” or “AML Rules”) was published in the Official Gazette of the Federation (“DOF”).

These amendments substantially raise the regulatory compliance standard regarding the prevention of money laundering and terrorist financing for those carrying out Vulnerable Activities in Mexico, aligning the regime of non-financial activities with the standards of the National Risk Assessment (“ENR”) issued by the Financial Intelligence Unit (“UIF”) and the recommendations of the Financial Action Task Force (FATF).

Below, we summarize the core aspects of the reform, its operational impact, the transitional timeline for its entry into force, and our practical recommendations.

  1. Risk-Based Approach (RBA)

Those carrying out Vulnerable Activities must design and implement a mandatory risk assessment methodology tailored to their operations, clients, geographic areas, and distribution channels.

  • Client Classification: The methodology must allow clients to be classified into three risk levels: low, medium, and high.
  • Factors to consider: To design the model, the following must be weighed:
    o The act or transaction performed.
    o The information and documentation provided by the client.
    o The geographic area and jurisdiction involved.
    o The transactions, monetary instruments, and delivery or distribution channels utilized.
    o The findings and updates of the National Risk Assessment (ENR).
  1. Order of Precedence for the Identification of the Controlling Beneficiary

To identify the Controlling Beneficiary of clients that are legal entities or legal structures, the rule establishes a mandatory order of precedence:

  1. First Criterion (Ownership/Participation): Identify the individual or group of individuals who, directly or indirectly, acquires, holds, or possesses under any title 25% or more of the shareholding structure or capital stock of the client.
  2. Second Criterion (Effective Control): If the previous scenario does not apply, identify the individual or group of individuals who exercises effective control through other means (those who decisively influence the strategy, direction, or decision-making of the entity).
  3. Third Criterion (Management/Administration): Likewise, of the previous scenario does not apply, identify the individual who holds the position of the highest-ranking administrative officer or senior management.


Note: The search procedure and the preservation of evidence supporting the determination made must be fully documented.

  1. Mandatory Content of the Internal Policies Manual
  • The Internal Compliance Policies Manual must be updated to integrate a total of 14 mandatory elements, which include:
  • Criteria for the identification, knowledge, and segmentation of the client risk levels.
  • Transaction monitoring mechanisms and alerts to detect unusual operations or operations inconsistent with the client’s profile.
  • Procedures for consulting and identifying individuals included in national and international restrictive lists (“blacklists”).
  • Clear delimitation of functions and responsibilities of the designated compliance representative.
  • Security measures and protocols to guarantee the strict confidentiality of information.

The Tax Administration Service (“SAT”) retains the power to require adjustments or modifications to the Manual whenever it deems it necessary for the correct application of the regulatory framework.

  1. Filing of Notices and New Official Templates

The Amendment introduces specific operational details regarding how Notices for the performance of Vulnerable Activities must be structured and submitted. Although the filings will continue to be processed through the SAT’s online AML Portal (Sistema del Portal en Internet de Prevención de Lavado de Dinero or “SPPLD”), regulated entities must consider the following:

  • Update of Templates and Additional Fields: Official electronic templates (XML files) will undergo modifications to request more detailed information reflecting the implementation of the Risk-Based Approach (RBA). It will be mandatory to include data regarding the client’s risk classification at the time of reporting the transaction.
  • • Alerts and 24-Hour Urgent Notices: The expedited reporting mechanism has been strengthened. Whenever automated monitoring systems detect a transaction that is unusual, inconsistent with the client’s transactional profile, or matches any restrictive list (“blacklist”), the regulated entity must file a 24-Hour Notice starting from the moment the confirmed alert is generated by the system, without waiting for the ordinary monthly deadline.
  • Integration of Acknowledgments of Receipt: Internal compliance manuals must now incorporate the technical procedures to safeguard and link the electronic acknowledgments of receipt (acuses de aceptación) issued by the SAT portal directly to the unique identification file of each client.
  1. Specific Provisions for Operations through Trusts

In order to close corporate opacity gaps, the amended rules place a particular emphasis on transactions carried out through fiduciary structures (fideicomisos). Those performing Vulnerable Activities with clients acting through trusts are obligated to:

  • Comprehensive Identification of the Parties: It will not be sufficient to identify only the trustee (fiduciario). The regulated entity must collect reliable information and documentation to fully identify the trustor (fideicomitente), the beneficiaries (fideicomisarios, whether designated or eventual), and, crucially, the members of the Technical Committee (Comité Técnico) or trust delegates.
  • Controlling Beneficiary in Fiduciary Structures: When a trust holds shares in a legal entity (or vice versa), the order of precedence to identify the Controlling Beneficiary must be applied by piercing the fiduciary veil. It must be documented which individual exercises effective control over the trust estate, or who holds veto power or final decision-making authority within the Technical Committee.
  • Update of Client Files: Regulated entities will need to review their historical files of clients that are trusts to request the necessary trust agreements and subsequent amendments to properly map these new compliance obligations.
  1. Audit, Automated Monitoring, Training, and Staff Selection

6.1. Annual Audit

An obligation is established to submit the effectiveness of compliance measures and controls to an annual review:

  • Internal Audit: This will only proceed when the risk of the entity carrying out the Vulnerable Activity is classified as low or medium according to the risk assessment methodology. The internal control or internal audit department must have functional independence and be accredited through annual training programs.
  • Independent External Audit: This will be mandatory when the regulated entity is classified as high risk, or when it voluntarily chooses this modality. The external auditor must have a professional degree, professional license, three years of verifiable prior experience, and a current certification issued by the UIF.
    Report to Governing Bodies: The audit results and opinions must be presented to the Board of Directors, Sole Administrator, or General Manager to evaluate the measures and implement the appropriate corrective actions.

6.2. Automated Monitoring Mechanisms

Technological systems are required (which can vary depending on volume and complexity, from specialized software to database solutions or consolidated spreadsheets) capable of:

  • Grouping operations by client in a consolidated manner for the accumulation of amounts.
  • Generating automatic alerts on deviations from the transactional profile.
  • Monitoring the use of cash and precious metals.
  • Preserving historical records of risk changes for a minimum period of 10 years.

6.3. Training Programs and Staff Selection

  • Training: A mandatory annual plan focused on the regulatory framework, the internal manual, and specific risks. Trainers must demonstrate at least 5 years of technical experience in anti-money laundering matters.
  • Staff Selection: Hiring filters must be implemented to verify technical quality and moral suitability. Hired personnel must sign a declaration under oath stating that they have not been sentenced for property crimes or disqualified from practicing commerce or public service.
  1. Entry into Force Timeline and Transitional Provisions

The Agreement generally enters into force on November 30, 2026. However, the transitional provisions contemplate specific deadlines for the gradual implementation of the various obligations:

Obligation / Requirement
Date of Entry into Force / Compliance
General entry into force of the Reform November 30, 2026
Implementation of the Risk-Based Assessment (RBA) March 1, 2027
Update of the Internal Policies Manual March 1, 2027
Classification of Client Risk Levels March 1, 2027
Application of the Controlling Beneficiary precedence criteria March 1, 2027
Application of Staff Selection procedures
March 1, 2027
Launch of Automated Monitoring Mechanisms

June 1, 2027

First annual period of mandatory Training January 1 to December 31, 2027
First review period of mandatory Audit January 1 to December 31, 2028

  1. Practical Recommendations

Even though certain obligations have a vacatio legis period extending into 2027 and 2028, structuring the methodology and adapting systems requires substantial interdisciplinary technical work. We recommend our clients and interested parties to:

  1. Design the Risk Methodology: Begin identifying internal risk factors and developing the client segmentation model in accordance with the ENR guidelines.
  2. Review and Update the Compliance Manual: Adjust internal policies to cover the 14 items required by the AML Rules.
  3. Evaluate the Type of Audit Required: Determine whether an internal or external audit is appropriate based on the risk profile and verify the qualification requirements of the auditor.
  4. Adapt Hiring Filters: Update labor files with the sworn declarations and requirements demanded for operating and compliance personnel.

At RGR, we are currently preparing the relevant adjustments to comply with the new AML Rules for our clients. Should you require support in the regulatory evaluation or the implementation of the measures described above, we would be pleased to assist you.

“The information contained in this publication is of a general nature and is provided for informational purposes only. It does not constitute legal advice, nor does it substitute a specific analysis of any particular matter. Our firm shall not be liable for the use given to this publication. For legal advice regarding a specific issue, please contact Alberto Ríos Zertuche Ortuño (arzo@rgr.com.mx) Joaquín Alonso Aparicio (jalonso@rgr.com.mx or José Domingo Pérez Galindo (jperez@rgr.com.mx). © 2026 Ríos Zertuche, González, Lutteroth y Rodríguez®. All rights reserved.”