AML rules reform: New obligations for those carrying out Vulnerable Activities
AML rules reform for Vulnerable Activities
On 7 August 2026, the Official Gazette of the Federation (DOF) published amendments to the General Rules issued under Mexico's Federal Law for the Prevention and Identification of Transactions with Illicit Proceeds (LFPIORPI). These amendments complement the legislative reform enacted in July 2025 and establish the framework for complying with new anti-money laundering (AML) obligations.
The new provisions strengthen the regulatory framework applicable to businesses and individuals carrying out Vulnerable Activities, introducing enhanced requirements relating to risk management, customer due diligence, Beneficial Ownership identification, staff training, automated monitoring systems and compliance reviews.
Key AML compliance changes
Individuals and legal entities engaged in Vulnerable Activities will be required to strengthen their transaction monitoring, record-keeping and compliance procedures, as well as the assessment of customer and user risk profiles.
1. Risk-based approach
Obligated entities must design and implement a methodology to identify, assess, measure and mitigate risks associated with:
- Transactions performed;
- Customer and user types;
- Countries and geographical areas involved; and
- Distribution channels.
The results of these assessments must be incorporated into the organisation's internal policies and control framework.
2. Customer classification
The new rules require entities to implement customer segmentation models classifying customers and users, at a minimum, into low, medium and high-risk categories.
In addition, a transactional profile must be established and monitored for each customer, taking into account factors such as:
- Transaction values;
- Frequency of activity; and
- Source and destination of funds.
3. Beneficial Ownership identification
The rules strengthen obligations relating to the identification of the Beneficial Owner, introducing specific procedures for determining the individuals who, directly or indirectly, own, control or exercise effective influence over legal entities and trusts.
4. Politically Exposed Persons (PEPs)
Specific requirements have been introduced for identifying and assessing risks associated with Politically Exposed Persons (PEPs).
Among other matters, these include:
- Additional risk factors for domestic PEPs; and
- Enhanced due diligence and monitoring measures where a PEP is classified as high risk.
5. Updates to the Internal Policies Manual
The Internal Policies Manual must include, among other matters:
- Risk assessment methodologies;
- Customer identification and due diligence procedures;
- Risk classification criteria;
- Beneficial Ownership and PEP identification procedures;
- Regulatory reporting requirements;
- Record retention procedures;
- Training programmes;
- Internal controls; and
- Audit procedures.
6. Staff training and recruitment
Organisations must implement AML training programmes at least annually for personnel involved in compliance-related functions.
Additional requirements have also been introduced regarding the recruitment, selection and assessment of employees responsible for AML compliance activities.
7. Automated monitoring systems
Obligated entities must maintain systems capable of:
- managing customer records and files;
- monitoring and aggregating transactions;
- identifying deviations from transactional profiles;
- classifying customer risk levels; and
- generating alerts.
The regulation permits various technological solutions, ranging from dedicated compliance platforms to spreadsheets and databases, provided they meet the required functionality and can be verified by regulatory authorities.
8. Annual compliance audit
An annual review has been introduced to evaluate compliance with the LFPIORPI, its Regulations and the General Rules.
Depending on the entity's risk profile:
- Low and medium-risk entities: the review may be conducted internally through audit or compliance control functions that satisfy regulatory requirements.
- High-risk entities: the review must be performed by an independent external auditor certified by Mexico's Financial Intelligence Unit (UIF).
Key compliance deadlines
Date | Requirement |
| 30 November 2026 |
|
| 1 March 2027 |
|
| 1 January to 31 December 2027 |
|
| 1 June 2027 |
|
| 1 January to 31 December 2028 |
|
The audit report for the first compliance period must be prepared during the first quarter of 2029 and submitted no later than the last business day of March 2029.
Recommendations for businesses
Businesses engaged in Vulnerable Activities should assess the impact of these changes on their compliance frameworks and identify any enhancements required to meet the new regulatory expectations.
The same approach is recommended for organisations that engage suppliers or service providers subject to these obligations.
Particular focus on real estate leasing
One of the most common Vulnerable Activities encountered in day-to-day business operations is real estate leasing.
Under the LFPIORPI, granting rights of use or enjoyment over real estate constitutes a Vulnerable Activity where the monthly value exceeds 1,605 times the daily UMA value.
Furthermore, a regulatory filing is required where the monthly transaction value equals or exceeds 3,210 times the daily UMA value.
As a result, tenant companies may receive requests for information concerning their corporate structure and Beneficial Ownership from landlords subject to AML compliance obligations.
At Forvis Mazars in Mexico, our specialists can assist organisations in assessing the impact of these new requirements, implementing appropriate compliance measures and strengthening their governance and control frameworks to meet evolving regulatory expectations.