CiberLATAMbywhalemate

Mexico tightens AML rules and bank biometrics

Mexico expanded anti-money-laundering rules and the CNBV broadened biometric checks in banks, raising risk and traceability demands.

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

Mexico published Agreement 115/2026, which reforms the General Rules under the LFPIORPI, while the CNBV updated the Single Banking Circular to expand biometric validation in face-to-face transactions and focus it on level 3 and 4 accounts.

Update August 23, 2026: the CNBV implemented its biometric reform through changes to the Single Banking Circular published in the Official Gazette on July 1, 2026. Mandatory validation was concentrated in level 3 and 4 accounts, and each institution may choose either fingerprint or facial biometrics.

Mexico published Agreement 115/2026, which reforms the General Rules under the LFPIORPI, while the CNBV moved ahead with changes to the Single Banking Circular on biometric validation. Taken together, the two measures raise cybersecurity, technology management, customer identification and internal control requirements for banks, finance companies and other regulated entities.

What changed in the anti-money-laundering rules?

Agreement 115/2026 does not change the LFPIORPI itself, but rather the rules that implement it. It shifts compliance away from a document-heavy approach toward a risk-based model, with greater emphasis on identifying the beneficial owner, transaction monitoring and the use of technology tools.

The agreement was published in the Official Gazette of the Federation on August 7, 2026, according to Garrigues, and it develops obligations introduced by the July 16, 2025 reform, according to KPMG. OVA.mx and PCGA.mx both say the new framework includes a phased implementation schedule, with general entry into force on November 30, 2026.

AML compliance timeline

Milestone Date Scope Source
General entry into force November 30, 2026 General validity of the rules Garrigues, OVA.mx
Risk-based assessment, policy manual and customer classification March 1, 2027 Regulated entities OVA.mx
Automated monitoring mechanisms June 1, 2027 Regulated entities OVA.mx
First audit period January 1, 2028 Regulated entities OVA.mx

According to Garrigues, beyond the general effective date of November 30, 2026, there are additional deadlines for certain obligations extending into 2027. PCGA.mx expands that schedule and says Agreement 115/2026 concentrates enforceability between 2026 and 2028, depending on the type of obligation and the entity covered.

Who does the new compliance framework apply to?

The impact is not limited to banking. Kim Gómez Franco and Ibarra, Pacheco y González say the reform reaches sectors such as real estate and trust-based transactions, where it strengthens requirements for identifying the beneficial owner and tracing funds.

In that context, updating contracts, document management systems and controls over information shared with banks becomes a direct task for compliance teams. B2B Mexico described the reform as historic because it comprehensively changes rules that had been in place since 2013, with minor revisions in 2014 and 2020.

How does this intersect with bank biometrics?

The CNBV updated its Single Banking Circular through amendments published in the Official Gazette of the Federation on July 1, 2026. Those changes alter Articles 51 Bis through 51 Bis 5 and replace Annex 71 of the general provisions applicable to credit institutions. Mandatory biometric validation is concentrated in level 3 and 4 accounts and requires at least one biometric method, either fingerprint or facial biometrics, at the institution’s discretion.

AMITI says the reform does not require replacing fingerprints with facial biometrics, but instead adds that technology as an option for face-to-face transactions subject to biometric validation. In practice, each bank can decide which method to use based on its processes and technical capabilities.

The group also notes that the resolution published on July 1, 2026 in the Official Gazette gives credit institutions 90 business days, not calendar days, to make the necessary changes. That affects planning for biometric integrations and security testing.

What regulatory pressure is coming from transparency?

At the same time, reports in August 2026 said Mexico’s Supreme Court gave CONDUSEF broader authority to sanction financial institutions that hide customer information, reinforcing regulatory risk around transparency and data handling.

El Cronista also reported that the Court upheld rules allowing CONDUSEF to impose sanctions for poor debt-collection practices. Infobae, for its part, reported a SCJN decision holding telecom companies responsible for negligence in identity verification when they enable SIM-swapping fraud, an example that reinforces the link between strong authentication, cybersecurity and provider accountability across the financial and telecom ecosystems.

What role does technology play in this agenda?

The CNBV already uses artificial intelligence tools for supervision, according to a Revista IMEF article, although its 2024 Annual Report does not mention specific regulatory initiatives on AI in the financial sector. In that same framework, QMA noted that under Mexico’s new Cybersecurity Law, the private sector still operates under existing sector-specific frameworks, including CNBV regulations and the LFPDPPP.

For banks and supervised entities, the regulatory picture in August 2026 points to a common requirement, adapting systems, controls and information flows to a stricter model of risk, traceability and verification, with deadlines extending into 2028.

Sources

View all