Amendments to the General Rules of the LFPIORPI

August, 2026

News and Insights

Amendments to the General Rules of the LFPIORPI

Amendments to the General Rules of the LFPIORPI

On August 7, 2026, the Ministry of Finance and Public Credit (Secretaría de Hacienda y Crédito Público) published in the Federal Official Gazette (Diario Oficial de la Federación, “DOF”) the Resolution amending the General Rules under the Federal Law for the Prevention and Identification of Transactions with Illicit Proceeds (Ley Federal para la Prevención e Identificación de Operaciones con Recursos de Procedencia Ilícita, “LFPIORPI”). The amendments will generally enter into force on November 30, 2026, subject to a phased implementation schedule throughout 2027 and 2028.

This Resolution implements the statutory reform published on July 16, 2025, and establishes the scope and deadlines for the obligations set forth in Article 18, the enforceability of which had remained subject to the issuance of these Rules.

What changes for entities carrying out Vulnerable Activities?

Compliance will no longer focus primarily on maintaining customer files and filing Notices. Instead, obligated persons will be required to implement a comprehensive risk-based compliance system. They must design a documented methodology to identify, assess, understand and mitigate their risks, taking into account, at a minimum, the acts or transactions performed, the types of customers, geographic areas, transactions and channels used. As a general rule, the methodology must use information covering at least twelve months, take into account the National Risk Assessment and be reviewed whenever new risks arise or, as applicable, annually.

Based on this methodology, obligated persons must operate a model that individually classifies each Customer or User as low, medium or high risk; establishes the relevant transactional profile; reassesses such profile at least every six months; and implements alerts and enhanced due diligence measures. Foreign Politically Exposed Persons (“PEPs”) will be deemed high risk and, where a PEP is also classified as high risk, the business relationship or transaction must be approved by a senior officer.

Obligated persons must also maintain a robust Internal Policies Manual addressing, among other matters, employee screening and annual training procedures; automated mechanisms for transaction review, aggregation of amounts, monitoring of deviations from transactional profiles and generation of alerts; and an annual audit. The audit may be conducted internally for low- or medium-risk obligated persons, but must be external and independent where the risk level is high. Within corporate groups, the policies must also apply to branches and subsidiaries, without eliminating the individual responsibility of each entity.

Identification of Beneficial Owners

The 2025 amendment to the LFPIORPI had already replaced the merely declarative approach to Beneficial Owner identification. Where the Customer or User is a legal entity, trust or other legal arrangement, the obligated person must obtain documents or other officially recognized means that make it possible to identify its Beneficial Owner; a certification or statement provided by the customer is no longer sufficient. The new Rules now set out the procedure for complying with this obligation.

For legal entities, the following order of priority must be followed: (i) first, identify the individual or group of individuals who directly or indirectly own 25% or more of the equity; (ii) second, identify any individual who exercises control by other means over the entity’s strategy, principal decisions or policies; and, as a residual criterion, (iii) identify the highest-ranking administrative officer. In the case of trusts, the analysis must include settlors, beneficiaries, trustees, protectors, members of the technical committee and any other person exercising effective control, tracing the entire ownership or control chain until an individual is identified. The procedure must be documented, kept up to date throughout the business relationship and retained for ten years.

This obligation (identifying the Beneficial Owner of Customers or Users of a Vulnerable Activity) must be distinguished from the corporate obligations established under Articles 33 Bis and 33 Ter of the LFPIORPI, which apply to all commercial companies and require them to identify and retain information on their Beneficial Owner, register such information in the electronic system operated by the Ministry of Economy, and report transfers of shares or equity interests. The Resolution dated August 7 regulates the obligation applicable to persons or entities carrying out Vulnerable Activities, but does not replace the general corporate obligation of companies to identify their own Beneficial Owners.

These regulatory developments will also have an impact on companies that do not directly carry out Vulnerable Activities. Suppliers, landlords, real estate developers, notaries and other certifying public officials, intermediaries, service providers and other counterparties subject to the LFPIORPI can be expected to make broader and more frequent requests for information to identify and verify their customers’ Beneficial Owners.

Such requests may include corporate ownership structures, ownership chains, shareholder or partner ledgers and records, public deeds, agreements granting control rights, identification documents and supporting documentation relating to the individuals at the end of the ownership or control chain. Companies should therefore ensure that their corporate documentation is up to date and that their Beneficial Owners have been properly identified.

Key Dates

Date Obligations
November 30, 2026 General effective date of the amendments to the General Rules, subject to the exceptions and specific implementation dates described below.
March 1, 2027 The risk assessment must be available. Obligated parties that are already registered and for which the applicable 90-day period has elapsed must have an updated Internal Policies Manual. As of this date, the provisions relating to risk classification, customer due diligence, Beneficial Owner identification and personnel selection procedures for new hires will also become applicable.
During 2027 The first annual training period must be completed.
June 1, 2027 Automated mechanisms for transaction monitoring, aggregation of transaction amounts and generation of alerts must be operational.
2028 fiscal year This will be the first period subject to the annual effectiveness audit.

 

We recommend that our clients conduct an assessment to determine whether they carry out any Vulnerable Activity, including through trusts or other legal arrangements. Where applicable, they should: (i) assign responsible personnel and budget; (ii) update customer files and agreements; (iii) define the risk model; (iv) establish alert scenarios; (v) determine the technological requirements for implementing automated systems; and (vi) establish a schedule for training, (vii) audits and (viii) document updates.

To assess the specific implications of these amendments for your company and define an appropriate implementation strategy, we invite you to contact Cannizzo’s Compliance practice.

Yours sincerely,

Cannizzo