Skip to Content
Mexico: LFPIORPI, its Regulation and the 2026 General Rules

Anti-Money Laundering Compliance in Mexico: the Law, the Regulation and the New General Rules

COX is PLD software for those who carry out vulnerable activities in Mexico: it identifies the client, assesses their risk, controls thresholds and accumulation and generates the XML notices for the SAT portal, with the file the LFPIORPI requires you to keep for ten years. Built for notaries, real estate firms, jewellers and the other obligated parties.

Vulnerable Activities Audit-Ready Files XML for the SAT PEP and List Screening

This information is provided for informational purposes and does not constitute legal advice. Consult a qualified professional about your specific obligations.

What Changed: Three Reforms, Three Dates

The Mexican framework changed in three steps, and each one has its own date. Mixing them up is the most common mistake when reading the new obligations.

The law: DOF 16 July 2025

In force since 17 July 2025. It sets the Article 17 thresholds in UMA, adds new activities, creates the 24-hour notice for suspicion even when the operation was not carried out, raises record keeping to ten years and adds five obligations: risk assessment, internal policy manual, annual training, automated monitoring and an annual audit.

The Regulation: DOF 27 March 2026

In force since 28 March 2026. Thresholds are measured without taxes, operations are accumulated over up to six months, Article 7 Bis covers the notice when the operation was not concluded, Article 21 Bis links operations in games within 24 hours and Chapter Six Bis deals with politically exposed persons.

The General Rules: Agreement 115/2026

Published in the DOF on 7 August 2026 and in force from 30 November 2026, with deadlines staggered until 2028. It sets out how to assess risk, grade each client, identify PEPs and the beneficial owner, and what the manual, the training, the automated mechanisms and the audit must contain.

The Calendar of Agreement 115/2026

Date What applies
30 November 2026 General entry into force of the amended General Rules.
1 March 2027 The risk-based assessment must be available to the authorities; the manual must include the risk methodology; client risk grading, know-your-client and beneficial owner rules apply to the operations carried out from that date.
January to December 2027 First annual training period.
1 June 2027 Deadline for the automated monitoring mechanisms.
August 2027 PEP checks in the UIF's Consulta PEP 2.0 application, nine months after the entry into force.
January to December 2028 First audited period. The first audit report is due by the last business day of March 2029.
The 24-hour notices depend on a format. The obligation is in the law since 17 July 2025, but the Rules allow sending those notices six months after the UIF publishes the Resolution that updates the official formats and provides for them.

Sources: LFPIORPI, last reform DOF 16/07/2025; its Regulation, reform DOF 27/03/2026; Agreement 115/2026 amending the General Rules, DOF 07/08/2026.

Eight Points of the New Framework

What an obligated party has to do differently, with the provision that says so.

Advanced electronic signature (e.firma)

Registration, notices and reports are filed electronically with the RFC and a valid e.firma. A legal entity, trust or other legal arrangement signs with the e.firma of its own RFC, never with its representative's.

One notice per operation, and the zero report

Each operation that meets the threshold, alone or accumulated, gets its own notice, filed by the 17th of the following month. A month without reportable operations is declared with a zero report, which cannot be changed once sent.

Six-month accumulation

Operations with the same client are accumulated by type of activity over up to six months, and the notice is due as soon as the sum reaches the threshold, even before the period ends (Regulation, Article 7).

The three 24-hour notices

Within 24 hours of suspecting the client, of learning facts or indications from other sources, or of finding the client on the UIF's list. They are filed even if the operation was not carried out or is below the threshold. An abandoned operation is not a reason in itself: what triggers the notice is the suspicion.

A risk grade for every client

At least three grades (low, medium and high), assigned when the relationship starts and reviewed at least every six months. Non-residents linked to countries with preferential tax regimes or deficient anti-money laundering measures, and foreign PEPs, are high risk by rule.

Ten years of records

The supporting information of each activity, notices, reports and acknowledgements are kept for at least ten years (Law, Article 18, section IV; Regulation, Article 20).

Politically exposed persons

A national PEP keeps that status for one year after leaving office. The spouse, the partner and relatives up to the second degree are treated as PEPs. The UIF keeps the list of PEPs, and its Consulta PEP 2.0 application answers when the client cannot be classified.

Annual audit, from 2028

Every calendar year is audited, internally or externally when your own risk is low or medium, and by an external auditor certified by the UIF when it is high. The first audited year is 2028, and the report is due by the last business day of the following March.

Who Must Comply: Vulnerable Activities

Article 17 of the LFPIORPI lists the activities with the highest exposure to money laundering. If your business is on this list, the law applies to you.

  • Real estate: construction, development and brokerage of property, and the funds received for real estate developments
  • Precious metals and stones, jewellery and watches: their trade in any form
  • Vehicles: land, sea and air vehicles, new and used
  • Notaries, public brokers and facilitators: public attestation of the acts the law lists
  • Independent professional services: when the professional prepares or carries out the operations the law lists for a client
  • Leasing of property: rights of use or enjoyment of real estate
  • Games with bets, contests and raffles: sale of tickets and payment of prizes
  • Armouring: of vehicles and property
  • Transport and custody of cash or valuables
  • Virtual assets: platforms that exchange, transfer or hold them for their clients
  • Service, credit and prepaid cards: issued by non-financial entities
  • Donations: received by non-profit associations and companies
Is your business on this list? Then the law requires you to identify clients, assess risk, file notices with the SAT and keep files for ten years. Failing to file a notice is fined with 10,000 to 65,000 UMA, or 10% to 100% of the value of the operation when that is higher.

Your Obligations as an Obligated Party

What you have to do, explained clearly

Client Identification

  • Identify every individual or legal entity with whom you carry out a vulnerable activity
  • Verify identity with valid official documents and keep a copy
  • If the client refuses to provide the information, abstain from the operation (Article 21)

Beneficial Owner

  • The law defines control as the vote over more than 25% of the capital, among other means (Article 3, section III)
  • The Rules set the order: whoever holds 25% or more of the capital, then whoever controls by other means, then the most senior manager
  • The Federal Tax Code is a separate regime and measures more than 15% for tax purposes

Risk Assessment

  • A documented methodology for your own risks, reviewed within twelve months of its results
  • A risk grade for each client, reviewed at least every six months
  • Enhanced measures for high-risk clients and PEPs

Notices to the SAT

  • File a notice when an operation, alone or accumulated over six months, reaches the threshold
  • By the 17th of the following month, or a zero report when there was nothing to report
  • Within 24 hours when there is suspicion, facts or indications, or a match with the UIF's list

Record Keeping and Manual

  • Keep files, documents and notices for at least ten years
  • An internal policy manual within 90 calendar days of registration
  • Annual training with an assessment, and its evidence kept for ten years

Annual Audit

  • A yearly review of how effective your compliance is, first for 2028
  • Findings with corrective actions, deadlines and owners
  • The report and its support kept for at least five years

How COX Helps You

Each function of the platform covers a regulatory obligation. No complex integrations, quick implementation.

Digital Onboarding

Send your clients a secure form to collect identification documents, a selfie, a photo of the facade and contact details. No paper, no queues.

PEP and Sanctions List Screening

Screen your clients against PEP registers, international sanctions and your own internal lists, with a configurable match score to reduce false positives.

Automated Risk Assessment

Configure your risk matrix with weighted indices (sector, country, PEP status, products and more) and classify each client as low, medium or high risk.

Audit-Ready Files

Each client has a complete file with documents, screening results, risk assessment, decision history and an action log, ready for a SAT verification.

XML Notices for the SAT

Generate the XML files of vulnerable activity notices in the SAT format, such as MJR, INM, VEH, JYS and AVI, ready to upload to the anti-money laundering portal.

Transaction Monitoring

Record financial and vulnerable activity transactions. The system evaluates the UMA thresholds, accumulates by period and flags the operations to identify and to report.

Complete Traceability

Every action is recorded with user, date and time, in an immutable compliance log designed for the ten years of record keeping the law requires.

Everything in One Place

Clients, transactions, notices, alerts and files together. No more scattered spreadsheets or paper files that are hard to find.

Why Choose COX?

Designed for obligated parties that need to comply quickly and well.

Quick Implementation

No months-long projects. Configure the platform and start working in days, without your own infrastructure or complex integrations.

Made for Vulnerable Activities

Not a generic system adapted after the fact: UMA thresholds, SAT catalogues, XML notices and the record of attempted operations are part of the product.

Practical Compliance

Not just theory: tools that produce the documents, reports and files the SAT will ask you for, ready for an audit from day one.

Encrypted Data
Immutable Log
Role-Based Access Control
Secure Cloud Hosting

Get Ready Before 30 November 2026

Do not wait for the first SAT verification. COX gives you the tools to comply with the LFPIORPI and its General Rules from day one.

Frequently Asked Questions

Clear answers for obligated parties and compliance officers

Failing an Article 18 obligation is fined with 200 to 2,000 UMA. Failing to file a notice, or taking part in cash operations the law prohibits, is fined with 10,000 to 65,000 UMA, or 10% to 100% of the value of the operation when that is higher. Some activities can also lose their permit, and giving false information for a notice is a crime punished with 2 to 8 years in prison.

Only when there is suspicion, or facts or indications, that the funds may come from or be destined to a crime: then the notice is due within 24 hours, even if the operation was not carried out, as long as you have data that identify who attempted it. An abandoned operation is not a reason in itself. If the client refuses to give the information, the law tells you to abstain from the operation. The 24-hour notices can be sent six months after the UIF publishes the formats that provide for them.

Agreement 115/2026 enters into force on 30 November 2026. The risk assessment and the client rules apply from 1 March 2027, the first training period is 2027, the automated mechanisms are due by 1 June 2027 and the first audited year is 2028.

Yes. Registration, notices and reports are signed with the advanced electronic signature (e.firma) of the RFC of whoever carries out the activity. A legal entity or trust uses the e.firma of its own RFC, never its representative's. If you do not have one yet, request it from the SAT.

At least ten years: the supporting information of each activity, the notices, the reports and their acknowledgements. The audit report and its support are kept for at least five years. COX keeps all of it organised and at hand.

Yes. The LFPIORPI applies to individuals and to legal entities that carry out vulnerable activities. An individual complies personally; a legal entity designates a Representative in Charge of Compliance, and until that designation is accepted the obligations fall on its board or sole administrator.

Multiply the number of UMA the law sets for each activity by the daily value of the UMA. Since the 2026 reform of the Regulation, taxes are left out when checking the threshold, but the notice reports the total amount with taxes. COX calculates these thresholds automatically.

No. COX is a management tool that supports and documents the work of the person in charge of compliance. It automates data collection, screening and documentation, but the legal responsibility stays with the obligated party and its designated compliance representative.

Yes. COX generates the XML files of vulnerable activity notices in the format of the SAT anti-money laundering portal, including MJR (precious metals, jewellery and watches), INM (real estate), VEH (vehicles), JYS (games with bets, contests and raffles) and AVI (virtual assets). The files are ready to upload to the portal.

This page gives general information about regulatory obligations in Mexico and does not constitute legal advice. Obligated parties should consult qualified professionals to determine their specific obligations under the LFPIORPI, its Regulation and its General Rules. Sources: DOF of 16/07/2025, 27/03/2026 and 07/08/2026.

Escríbenos por WhatsApp