
September, 2026
News and Insights
Compliance Radar
Compliance Radar
We would like to share some recent developments that illustrate why compliance should form part of the overall business strategy rather than operate as a standalone function.
Understanding how regulations or actions taken by regulatory authorities may affect the business enables companies to integrate controls into their commercial and operational processes, anticipate necessary adjustments, and make better-informed decisions before an investigation, regulatory reform, or system deficiency develops into a risk or potential liability.
In this edition, we analyze several developments that illustrate this connection: an antitrust investigation, the upcoming update to the formats for anti-money laundering Notices and Reports, increased attention to supply chain integrity, and an investigation related to a potential exposure of personal data.
CNA investigates rules governing access to Mexican professional soccer
On September 14, 2026, the Investigative Authority of the National Antitrust Commission (Comisión Nacional Antimonopolio, “CNA”) published in the Official Gazette of the Federation (Diario Oficial de la Federación, “DOF”) the initiation of an ex officio investigation, IO-001-2026, into the possible commission of relative monopolistic practices in the market for the “affiliation, organization of, and access to federated professional soccer competitions in Mexico, as well as similar or related services.”
The investigation will examine conduct that may increase costs, hinder operations, or reduce the demand faced by other market participants.
Although the case concerns professional soccer, the underlying risk is not exclusive to that sector. In the business context, similar concerns may arise when a company’s rules or commercial decisions make it more difficult for customers, suppliers, distributors, or competitors to conduct their activities under normal market conditions.
The case is a reminder that antitrust risks may arise from seemingly ordinary business decisions: how distributors are selected, what conditions are imposed on suppliers, who may access a platform or network, how discounts and exclusivity arrangements are structured, or what criteria determine the entry or continued participation of third parties.
What do we recommend?
From a compliance perspective, companies should review not only whether expressly anticompetitive agreements exist, but also those commercial, contractual, and operational policies that may have the effect of making it more difficult for other market participants to enter or remain in the market or to compete effectively.
AML: New Notice and Report formats on the way
On September 14, 2026, the Comprehensive Regulatory Governance Platform (Plataforma Integral de Gobernanza Regulatoria) was updated to include a draft Resolution updating the official formats for Notices and Reports under the Federal Law for the Prevention and Identification of Transactions with Illicit Proceeds (Ley Federal para la Prevención e Identificación de Operaciones con Recursos de Procedencia Ilícita). As of the closing of this edition, the Resolution has not yet been published in the Official Gazette of the Federation.
The draft adapts the formats to the 2025 and 2026 reforms to Mexico’s AML regime. Among the main changes, it introduces fields for reporting information on the Beneficial Owner (Beneficiario Controlador) and updates the information that must be provided regarding customers or users and the transactions carried out. The obligation to identify the Beneficial Owner does not originate with these new formats; rather, the draft incorporates this information into the framework through which Notices are filed.
The draft also introduces specific formats for new Vulnerable Activities (Actividades Vulnerables), including Annex 5-B, applicable to the receipt of funds intended for real estate developments, and Annex 12-C, applicable to certain acts carried out before facilitators in alternative dispute resolution mechanisms. It also introduces Annex 14-A for filing 24-hour Notices related to foreign trade transactions.
The draft provides that the new formats will begin to be used on June 1, 2027. The same date would apply to the Notices provided for under Articles 26 Bis, 26 Bis 1, 26 Bis 2, and 27 of the Rules, including 24-hour Notices. The formats currently in force would remain available until June 30, 2027, solely for purposes of amending Notices previously filed using those formats, and would cease to be available as of July 1.
What do we recommend?
For the time being, companies should review the new formats and identify the additional information that will need to be collected and reported, particularly regarding the Beneficial Owner and the transactions carried out. This will make it possible to anticipate any adjustments that may be required to files, processes, and systems.
We also recommend monitoring the publication of the Resolution in the Official Gazette of the Federation, as it will be necessary to confirm whether the final text maintains the dates and conditions contemplated in the draft. In the meantime, the formats currently in force should continue to be used.
U.S. calls for greater private-sector participation to strengthen supply chains in Mexico
On September 16, 2026, the U.S. Department of State published the Presidential Determination on Major Drug Transit or Major Illicit Drug Producing Countries for Fiscal Year 2027. Mexico remains among the 23 countries identified. The determination itself clarifies that inclusion on the list does not, in itself, constitute a negative assessment of a government’s efforts and may reflect geographic, commercial, and economic factors. Mexico was not included in the additional category for countries that, in the view of the United States, had failed to make sufficient efforts; that determination applied only to Afghanistan, Bolivia, Burma, and Colombia.
For the private sector, the most relevant point is that the document expressly states that Mexico should strengthen the integrity of its supply chains through greater participation by private industry and significantly increase inspections at ports of entry. The determination does not create a new obligation for Mexican companies, but it does demonstrate that controls relating to supply chains, foreign trade, and third parties form part of the U.S. agenda to combat drug trafficking and of its cooperation with Mexico.
What do we recommend?
Companies engaged in import, export, transportation, or warehousing activities should review whether their controls allow them to identify who participates in their commercial supply chains, what goods are being moved, along which routes, and under what conditions. This includes conducting due diligence on suppliers, customers, customs brokers, carriers, and intermediaries; maintaining documentary traceability of shipments; establishing alerts for unusual routes, volumes, or instructions; and implementing mechanisms to escalate transactions that are inconsistent with the expected commercial profile.
Companies should also consider integrating these controls with their AML, foreign trade, sanctions, and third-party risk management frameworks.
Data Protection: SABG Investigates Potential Exposure Attributed to Aeroméxico
On September 20, 2026, the Anti-Corruption and Good Governance Ministry (“SABG”) reported that, as a result of active forensic monitoring for potential security incidents, it identified a publication dated September 18. This post offered a database, allegedly linked to Aeroméxico, containing over 15 million records. According to the authority, the information could include full names, email addresses, phone numbers, dates of birth, and registration dates. The Secretariat obtained a sample of 100,092 records and initiated an investigation “ex officio” to determine potential liability regarding the compromised databases.
Aeroméxico announced that it had launched an investigation to verify the authenticity of the information, determine its source, and establish the scope of any potential impact. Based on available information, the company stated that it has not identified any exposure of financial information, payment card data, or account passwords, and that its operations remain unaffected.
Beyond this specific case, the development is significant because it demonstrates active oversight regarding personal data protection. The authority is capable of identifying indicators in external sources and launching investigations on its own initiative, without waiting for a formal complaint. For companies, this narrows the gap between the public emergence of a potential incident and regulatory scrutiny.
What do we recommend?
Review incident response protocols to ensure they allow for action even when a potential exposure is detected outside the organization’s own systems. The process should enable the preservation of evidence, the rapid identification of potentially affected data and data subjects, the assessment of notification obligations, the coordination of communications with the authority and data subjects, and the documentation of decisions made. It is also advisable to evaluate external source monitoring mechanisms and include critical vendors and third parties in response exercises.
Yours sincerely,
Cannizzo

