CiberLATAMbywhalemate

Mexico tightens AML rules and bank biometrics

Mexico updated anti-money-laundering rules and the CNBV expanded biometric checks at banks, raising compliance and traceability demands.

Whalemate Labs · AI-assisted researchAug 20, 20264 min read

Mexico published Agreement 115/2026, which amends the LFPIORPI general rules, while the CNBV moved ahead with changes to the Banking Single Circular on biometric verification. Together, the measures raise the bar for risk-based controls, customer traceability, and technology upgrades, with some AML deadlines extending through 2028.

Mexico published Agreement 115/2026, which amends the General Rules under the LFPIORPI, while the CNBV moved ahead with changes to the Banking Single Circular on biometric verification. Together, the two measures raise the bar for cybersecurity, technology management, customer identification, and internal controls for banks, financial firms, and other obligated entities.

What changed in the anti-money-laundering rules?

Agreement 115/2026 does not amend the LFPIORPI itself, but rather the rules that implement it, and it shifts compliance away from a document-heavy model toward a risk-based one, giving greater weight to beneficial owner identification, transactional monitoring, and the use of technological tools.

The agreement was published on August 7, 2026, in the Official Gazette of the Federation, according to Garrigues, and it develops obligations introduced by the July 16, 2025 reform, according to KPMG. OVA.mx and PCGA.mx agree that the new framework includes a staggered rollout, with general enforcement starting on November 30, 2026.

Anti-money-laundering compliance timeline

Milestone Date Scope Source
General entry into force November 30, 2026 General validity of the rules Garrigues, OVA.mx
Risk-based assessment, policy manual, and customer classification March 1, 2027 Obligated entities OVA.mx
Automated monitoring mechanisms June 1, 2027 Obligated entities OVA.mx
First audit period January 1, 2028 Obligated entities OVA.mx

According to Garrigues, beyond the general November 30, 2026 effective date, there are additional deadlines for certain obligations through 2027. PCGA.mx expands that framework and says Agreement 115/2026 concentrates enforceability between 2026 and 2028, depending on the type of obligation and the entity covered.

Who does the new compliance framework affect?

The impact is not limited to the banking system. Kim Gómez Franco and Ibarra, Pacheco y González note that the reform reaches sectors such as real estate and trust-based transactions, where obligations tied to beneficial owner identification and fund traceability are being strengthened.

In that area, updating contracts, document management systems, and controls over information shared with banks becomes a direct task for compliance teams. B2B Mexico described the reform as historic because it overhauls rules in place since 2013, with limited adjustments in 2014 and 2020.

How does this intersect with banking biometrics?

The CNBV also adjusted its Banking Single Circular to expand biometric verification, with fingerprint and facial biometrics serving as alternative methods in certain in-person transactions, without one technique necessarily replacing the other.

AMITI details that the reform modifies Articles 51 Bis through 51 Bis 5 and replaces Annex 71, concentrating mandatory biometric verification in Level 3 and 4 accounts, which are tied to higher transaction capacities. That design narrows the initial operational scope, but it concentrates cybersecurity demands in segments where money laundering and fraud risks are higher.

The association also notes that the resolution published on July 1, 2026, in the Official Gazette gives credit institutions 90 business days, not calendar days, to make the required changes. That affects planning for biometric integrations and security testing.

What regulatory pressure is added by the transparency front?

At the same time, in August 2026 it was reported that the Supreme Court of Justice of the Nation gave CONDUSEF broader powers to sanction financial entities that hide customer information, reinforcing regulatory risk around transparency and data handling.

El Cronista also reported that the Court upheld rules allowing CONDUSEF to impose sanctions for poor debt collection practices. Infobae, meanwhile, cited an SCJN decision holding telecom companies responsible for negligence in identity verification when they enable SIM swapping fraud, a precedent that strengthens the link between robust authentication, cybersecurity, and vendor accountability across the financial and telecom ecosystems.

What place does technology have in this agenda?

The CNBV is already using artificial intelligence tools for supervision, according to an article by Revista IMEF, although its 2024 Annual Report does not mention any specific regulatory initiatives on AI applied to the financial sector. In that same context, QMA noted that under Mexico's new Cybersecurity Law, the private sector still operates under existing sector-specific frameworks, including CNBV regulations and the LFPDPPP.

For banks and supervised entities, the regulatory picture in August 2026 points to a common requirement, adapting systems, controls, and information flows to a stricter logic of risk, traceability, and verification, with deadlines that run through 2028.

Sources

View all