Skip to Content
LFPIORPI · Internal Controls & Reporting

AML Internal Reporting for Mexico: Stay Audit-Ready Under LFPIORPI

COX internal AML reporting for Mexico lets an obligated entity record suspicious or unusual operations, prepare the internal reports its compliance officer must keep and preserve an immutable audit trail, as the LFPIORPI and its rules require. It is designed for vulnerable activities that report to the SAT and the UIF.

Vulnerable Activities Immutable Audit Trail SAT XML Generation Internal Reporting

This content is for informational purposes only and does not constitute legal advice. Consult a qualified professional for your specific obligations.

What Does LFPIORPI Require for Internal Controls?

Mexico's anti-money laundering law imposes strict internal control and reporting obligations on businesses performing vulnerable activities. Here is what you must do:

Client Identification

Identify clients and beneficial owners when operations reach the identification threshold. Verify identity and collect KYC documentation.

Operation Monitoring

Track all vulnerable activity transactions, evaluate UMA-based thresholds, and accumulate operations over 6-month periods.

Suspicious Activity Detection

Detect and document unusual or suspicious operations. When there is suspicion, the notice is due within 24 hours even if the operation was not carried out (Law, Article 18, section VI; Regulation, Article 7 Bis).

Monthly SAT Reporting

Submit monthly notices ("Avisos") to SAT/UIF: including zero activity reports. Generate XML files in the exact format SAT requires.

Internal Control Mechanisms

Maintain documented internal controls, whistleblowing channels, and AML event tracking systems: critical for SAT audits and inspections.

10-Year Record Preservation

Preserve all compliance documentation for a minimum of 10 years (Art. 18, section IV). Records must be immutable and available for inspection at any time.

The Problem: Compliance Without the Right Tools

Most small and medium businesses in Mexico try to comply with LFPIORPI using spreadsheets, emails, and manual processes: leaving them exposed to serious risks.

Spreadsheet Chaos

Client data scattered across Excel files with no version control, no audit trail, and no structured reporting.

Missed Deadlines

Suspicions not reported within 24 hours. Monthly notices submitted late or not at all. Zero reports forgotten.

No Traceability

No way to prove who did what and when. During a SAT inspection, you cannot demonstrate your internal controls.

Heavy Fines

Fines range from 200 to 65,000 UMA, or 10% to 100% of the value of the operation for an omitted notice, and some activities can lose their permit.

The Solution: COX

A complete AML compliance platform designed for Mexico's vulnerable activities. From client onboarding to SAT XML generation: everything in one place, with a full internal reporting engine and immutable audit trail.

Transaction Registry

Record all vulnerable activity transactions with regime-aware forms. Automatic UMA threshold evaluation, 6-month accumulation tracking, and related operations detection within 24 hours.

SAT Report Generation

Create monthly AV reports with notices, parties, and operations. Validate, approve, and generate activity-specific XML files (MJR, INM, VEH, JYS, AVI) ready for the SAT SPPLD portal.

Internal Reporting & Audit

Anonymous whistleblowing channel, case investigation workflow, attempted operations tracking with 24-hour deadline enforcement, and an immutable compliance audit log.

Built for LFPIORPI Compliance: Feature by Feature

Every feature maps to a specific regulatory requirement, so you know exactly how COX keeps you compliant.

Internal Operations Reports

Receive reports about unusual or suspicious internal operations through a secure web form. Track each case from receipt through investigation to resolution.

Anonymous Whistleblowing Channel

A public URL: no login required: where employees, clients, or suppliers can submit anonymous reports with evidence files. CAPTCHA-protected and integrity-verified.

Attempted Operations (24h)

Register operations that were not completed, and the suspicion that makes them reportable. When there is suspicion, the system tracks the 24-hour deadline of the notice.

Case Investigation Workflow

Kanban-based case management: Received, In Investigation, Closed. Add follow-up notes, investigation results with mandatory justification, and track days open.

Risk Assessment & KYC

Configurable risk matrices with weighted scoring. Digital onboarding forms, document validation, PEP and sanctions screening, and beneficial owner verification.

SAT/UIF Report Generation

Activity-specific XML generation (MJR, INM, VEH, JYS, AVI). Snapshot-based for audit integrity. Supports regular reports and zero-activity reports.

Immutable Audit Trail

Every compliance event is automatically logged and cannot be modified or deleted. Meets the 10-year conservation requirement. Write-protected for regulatory integrity.

AML Audit Management

Document internal, external, and regulatory audits. Record findings, recommendations, and corrective actions. Immutable once completed. The first year audited under Agreement 115/2026 is 2028.

Role-Based Access Control

Analyst, Officer, and Manager roles ensure proper segregation of duties. Export controls, multi-company isolation, and per-user activity tracking.

Who Needs AML Internal Reporting in Mexico?

If your business performs any of these vulnerable activities under LFPIORPI, you are legally required to maintain internal controls and reporting systems.

Real Estate (INM)

Property developers, real estate agencies, notaries handling purchase-sale transactions above threshold values.

Jewelry & Merchandise (MJR)

Jewelers, watch dealers, art dealers, and luxury goods retailers selling above the UMA-based reporting threshold.

Vehicles (VEH)

Car dealerships, vehicle brokers, and any business involved in the sale of new or used motor vehicles.

Games & Raffles (JYS)

Casinos, lottery operators, raffle organizers, and gaming establishments handling prizes or wagers above thresholds.

Virtual Assets (AVI)

Cryptocurrency exchanges, digital asset platforms, and businesses dealing in virtual assets and tokens.

Professional Services

Notaries, lawyers, accountants, and brokers who act as intermediaries in regulated transactions.

Why Choose COX?

Purpose-built for Mexican AML compliance: not a generic tool adapted after the fact.

Fast Implementation

No API integration needed. Sign up, configure your company, and start registering transactions the same day.

Audit-Ready Always

Immutable audit trail, snapshot-based reports, and documented internal controls demonstrate compliance at any moment.

Credit-Based Pricing

Pay only for what you use. No heavy annual subscriptions. Credits stay valid for 12 months. Scale as you grow.

Ready for the New Rules

Built for the 2025 reform of the law, the 2026 reform of its Regulation and Agreement 115/2026: 24-hour notices, six-month accumulation, PEPs and the annual audit that starts with 2028.

Enterprise-Grade Security & Compliance

Encrypted Storage

All data encrypted at rest and in transit. Secure cloud hosting.

Immutable Logs

Write-protected audit trail. Records cannot be altered or deleted.

Role Segregation

Analyst, Officer, Manager roles. Multi-company isolation.

10-Year Retention

Meets the conservation period of LFPIORPI Art. 18, section IV.

Ready to Strengthen Your AML Internal Controls?

Join businesses across Mexico that trust COX to manage their LFPIORPI compliance. Get started in minutes: no API required.

Frequently Asked Questions

While the law does not explicitly mandate a "whistleblower portal," it requires obligated subjects to maintain internal control mechanisms, document suspicious operations, and keep audit trails. An internal reporting system is the most practical way to meet these requirements and demonstrate compliance during SAT/UIF inspections.

When there is suspicion, or facts or indications, that the funds may come from or be destined to a crime, the LFPIORPI requires a notice within 24 hours, even if the operation was not carried out (Article 18, section VI; Regulation, Article 7 Bis). An abandoned operation is not a reason in itself, and a client who refuses to identify themselves means you must abstain from the operation. COX tracks the 24-hour deadline from the moment the operation is recorded.

Yes. The SAT carries out verification visits and requests information, and since the 2026 reform of the Regulation (Article 10 Bis) it can rely on its own and third-party databases, with certified digital copies worth the same as the originals. Having a structured compliance system with organized records and immutable logs makes inspections significantly faster and demonstrates diligent compliance.

No. COX is a management tool that supports and documents the compliance officer's work. It automates data collection, screening, reporting, and audit trail generation: but legal responsibility remains with the obligated subject and their designated compliance officer.

COX uses a credit-based model: you pay only for the compliance operations you perform. No heavy annual subscriptions required. Credits are valid for 12 months. View our full pricing and plans for details.

Yes. When reporters choose to remain anonymous, nothing identifying is stored: no name, no email, no phone, and no record of the submission IP or browser. Connection data is kept only for reporters who choose to identify themselves, and only compliance managers can see it. Reporters receive a case reference code they can save for their records.

This page is for informational purposes only and does not constitute legal advice. LFPIORPI obligations vary depending on the type of vulnerable activity and business context. Consult a qualified AML professional for your specific requirements.

Escríbenos por WhatsApp