In brief

On 7 August 2026, the Ministry of Finance and Public Credit (Secretaría de Hacienda y Crédito Público, SHCP) published in the Official Gazette of the Federation amendments to the General Rules ("Rules”) of the Federal Law for the Prevention and Identification of Transactions with Illicitly Sourced Funds (“Anti-Money Laundering Law”), which develop a substantial part of the regulatory framework derived from the amendments enacted in July 2025 and March 2026.

These amendments represent a significant shift in the compliance framework. Entities carrying out Vulnerable Activities will need to transition from a framework primarily focused on customer file maintenance and the filing of Notices, to a preventive system, designed to identify, assess, and monitor the risks associated with their clients, transactions, and business models.

Key takeaways

Among the most relevant changes, the new Rules regulate several aspects related to the identification of the ultimate beneficial owner, including a new criterion and order of priority for determining the ultimate beneficial owner, as well as the information and documentation that must be collected. It should be noted that, the guidelines governing the registry of ultimate beneficial owners before the Ministry of Economy remain pending; therefore, there is still uncertainty regarding the applicable procedures, forms, deadlines and updating mechanisms.

In addition, obligated parties should use the transitional period to conduct a gap analysis, update their risk methodologies, review customer due diligence and ultimate beneficial owner identification procedures, create or strengthen their monitoring tools, update their internal manuals, training programs and audit processes, and prepare an implementation plan in line with the different effective dates.

The main topics covered are:

  • Ultimate beneficial owner.
  • Risk-based approach.
  • Customer risk classification, KYC procedures and transactional profile.
  • Politically Exposed Persons (PEPs).
  • Internal policies manual.
  • Automated mechanisms.
  • Notices based on suspicion or indications.
  • Training and personnel selection.
  • Audit.
  • Virtual asset service providers.
  • Electronic notices.

Although the Resolution will enter into force on 30 November 2026, several obligations will be subject to specific transitional periods during 2027 and even 2028. In addition, certain obligations under the amendment to the Anti-Money Laundering Law remain subject to supplementary regulations or to the implementation of operational mechanisms by the competent authorities; therefore, it will be important to monitor any future provisions and criteria issued in this regard.

In more detail

Main changes

The Rules develop a significant portion of the obligations introduced by the 2025 amendment to the Anti-Money Laundering Law and establish a more robust compliance framework for those carrying out vulnerable activities. Some of the most relevant changes are summarized below:
 
Obligation Key points Effective date
Ultimate beneficial owner
Rules are developed to identify, document, update and retain information on the ultimate beneficial owner. For legal entities, an order of priority must be followed based on direct or indirect ownership of 25% or more, control by other means, including decision-making and policy-setting authority and, failing that, the highest-ranking management officers. Criteria are also provided for trusts and other legal arrangements. Entities that carry out vulnerable activities are no longer obliged to collect information form clients or users that are listed in a stock exchange.
1 March 2027 
Risk-based approach A risk-based approach is incorporated for those carrying out vulnerable activities. Regulated parties must have a documented methodology to assess risks based on their operations, customers, jurisdictions, delivery channels and mitigating factors, incorporate it into the Internal Policies Manual, maintain supporting documentation for at least ten years and address any adjustments requested by the Tax Administration Service (SAT).
1 March 2027
Customer risk classification, KYC procedures and transactional profile
Obligated parties must directly know and classify them by risk level and apply due diligence measures consistent with that classification. They must also implement KYC procedures, determine and monitor the expected transactional profile, detect relevant deviations and enhance measures for high-risk customers.
1 March 2027
Politically Exposed Persons 
The Rules regulate the identification and treatment of Politically Exposed Persons, including domestic and foreign PEPs, relevant family members and associates. The Rules provide for the use of the Financial Intelligence Unit’s Consulta PEP 2.0 and the adoption of additional factors to assess whether their transactional behavior is reasonable based on their profile.
The query through Consulta PEP 2.0 may be made nine months after the effective date of the Resolution.
Internal policies manual
Regulated parties must have an Internal Policies Manual documenting criteria for identification, KYC procedures, risk classification, due diligence, monitoring, filing of notices, retention of information, restricted lists, training, internal control, audit and the duties of the representative responsible for compliance.
For previously registered parties whose 90-day period has expired, the updated manual must be available as of 1 March 2027.
Automated mechanisms
Automated mechanisms must be implemented in line with the volume, nature, complexity and risk of the transactions. These mechanisms must allow regulated parties to retain files, consolidate transactions, monitor deviations, use of cash and precious metals, feed the risk methodology, generate alerts and monitor high-risk customers, PEPs, listed persons and high-risk jurisdictions.
They must be implemented no later than 1 June 2027 and include information on acts or transactions carried out as from that date.
Notices based on suspicion or indications
Rules are incorporated for filing notices within 24 hours following the identification of conduct, facts or indications that may be related to operations with funds from illicit sources crimes. This obligation may apply even if the transaction does not meet ordinary notice thresholds or has not been completed.
They may be submitted six months after the effective date of the resolution amending the official notice and report forms to expressly provide for this type of notice.
Training and personnel selection
Formal annual training obligations are established for management bodies, officers, relevant personnel and representatives responsible for compliance. Training and evaluation must be documented and retained for ten years. Personnel selection procedures and statements of integrity are also incorporated.
The personnel selection procedures will apply to new hires as of March 1, 2027.
The first annual training period will cover the period from 1 January to 31 December 2027.
Audit
The annual review of the effectiveness of compliance with the Anti-Money Laundering Law is now regulated. Where an entity’s risk level is classified as low- or medium-risk, the review may be conducted by an internal function that is independent from the compliance function. Where the entity’s risk level is classified as high, the review must be carried out by an independent external auditor. The resulting audit report must identify any findings, corrective actions, responsible parties, implementation timelines, and the potential economic exposure arising from any compliance deficiencies detected.
The first audit period will begin on 1 January 2028 and end on 31 December 2028.
Digital assets service providers
The requirements applicable to digital asset service providers are updated, including registration, corporate information, ultimate beneficial owner, traceability, custody, storage, facilitation and intermediation of digital assets. Criteria are also specified to determine notices based on the amount of the transaction or consideration.
Previously registered parties must update and submit the information required under the Rules within six months following the effective date of the Resolution.
Electronic notifications
An electronic notification regime through the Internet Portal is incorporated. Regulated parties must check it at least once each business day. Recipients will have three business days to access the notified document. If the document is not accessed within that period, the notification will be deemed served on the fourth business day.
The SHCP must implement the technological mechanisms within eight months following the effective date of the Resolution.
Proceedings, deadlines, and filings before the Tax Administration Service The new Rules clarify that administrative actions and proceedings must be carried out during business days and hours. Non-business days, including the general vacation periods and suspension of activities established by the SAT in the Miscellaneous Tax Resolution, will not be counted for purposes of calculating deadlines. Filings related to the Anti-Money Laundering Law must be submitted directly to the authorized SAT offices. When the interested party is located outside the state where the competent office is located, documents may be sent through Mexican Postal Service by certified mail with acknowledgment of receipt. Additionally, if a person refuses to receive a summons or the address is closed, the summons may be posted in a visible place, provided that the SAT prepares a record documenting the circumstances.  30 November 2026

 

Recommendations

The publication of Agreement 115/2026 transforms several of the amendments introduced to the Anti-Money Laundering Law in 2025 into actionable compliance obligations. Accordingly, we recommend that entities carrying out Vulnerable Activities begin preparing for implementation well in advance, taking into account the specific effective dates applicable to each obligation.

At Baker McKenzie, we are available to assist clients in assessing the impact of these changes, conducting compliance gap assessments, developing risk assessment methodologies, updating compliance manuals and customer files, reviewing monitoring mechanisms, and preparing for the new training and audit requirements.

If you would like to discuss how these changes may affect your organization, please contact your Baker McKenzie team. We would be pleased to assist you and address any questions you may have.

 
Explore More Insight