SHCP Issues Anti-Money Laundering Rules for Vulnerable Sectors
By Duncan Randall | Journalist & Industry Analyst -
Tue, 08/11/2026 - 10:31
Mexico’s Ministry of Finance and Public Credit has enacted new General Rules under the LFPIORPI, establishing a mandatory Risk-Based Approach for non-financial entities performing designated Vulnerable Activities. The regulations require companies across real estate, cryptocurrency, trust services, and non-profit sectors to implement risk management methodologies, enhanced due diligence, and automated monitoring systems aligned with Financial Action Task Force standards. Featuring a phased implementation through 2029, the framework replaces uniform compliance with risk-proportional oversight to strengthen financial system integrity and regulatory certainty.
——
The Ministry of Finance and Public Credit (SHCP) published new General Rules under the Federal Law for the Prevention and Identification of Operations with Resources of Illicit Origin (LFPIORPI) in the Official Gazette of the Federation. The regulations establish a mandatory Risk-Based Approach (EBR) for entities performing Vulnerable Activities, replacing uniform compliance protocols with risk-proportional obligations.
The regulatory framework develops provisions established in legislative reforms to the LFPIORPI and its general regulations, seeking to align Mexico's anti-money laundering framework with international recommendations from the Financial Action Task Force (FATF). According to SHCP, the rules aim to "provide greater legal certainty and a homogeneous application of provisions" by defining specific requirements for designated non-financial businesses and professions, alongside clear supervisory guidelines for enforcement authorities.
The reform marks a structural transition away from traditional compliance models that applied uniform basic identification procedures and equal risk assumptions across all clients, products, and sectors. Under the new framework, entities engaged in designated Vulnerable Activities — including real estate development, virtual asset trading, trust services, cash custody, and prepaid card issuance — must adopt structured risk management methodologies. Businesses are required to identify, evaluate, classify, and document risks tied to specific clients, operations, products, services, operating channels, and geographic locations.
This regulatory overhaul follows a gradual decline in notices for vulnerable activities, with 1Y25 data released by the Financial Intelligence Unit (UIF) revealing a 15% drop compared to 2024. Notices involving virtual assets fell 57% year-over-year following the July 2025 LFPIORPI threshold adjustments, while service and credit cards generated over 2.1 million notices and cash custody transfers accounted for 1.3 million notices during the year. Silvia Matus, Anti-Money Laundering Partner at BHR México, noted that expanded reporting mandates, lower reporting thresholds, and technological adoption are reshaping how compliance teams submit regulatory alerts to authorities.
Key Provisions
The newly published General Rules introduce 112 primary modifications structured across 12 core compliance areas. Key changes include mandatory client classification, enhanced customer due diligence (KYC), updated identification parameters for Controlling Beneficiaries, and formal compliance frameworks for Politically Exposed Persons (PEPs). Obligated entities must also establish an Internal Policies Manual, institute employee selection and training protocols, deploy automated transaction monitoring mechanisms, and implement electronic notification systems.
The provisions also establish specialized controls for trusts, legal arrangements, and Non-Profit Organizations (OSFL), alongside a mandatory 24-hour urgent notice mechanism for high-risk operations. Under a proportional compliance model, obligations and supervisory actions are calibrated according to the risk level inherent to each Vulnerable Activity, optimizing resource allocation while strengthening internal compliance governance.
Supervisory and verification activities conducted by SHCP and its administrative units will similarly transition to a risk-based model. Regulatory inspections will focus on high-risk sectors and activities displaying elevated exposure to illicit financial flows, moving away from uniform oversight toward smart, risk-adjusted supervision. To support compliance readiness, authorities established a six-month training period focused on new legal obligations for non-profit organizations and other designated vulnerable entities.
Implementation of the new framework will follow a phased schedule to allow companies to adjust internal software, compliance manuals, staff training, and operational workflows. Following the August 2026 publication of the rules, SHCP will publish updated reporting layouts for notices in the Official Gazette of the Federation in November 2026. The General Rules will officially enter into force in March 2027, followed by the mandatory adoption of the new reporting layouts in June 2027. Obligated entities will complete their first annual audit period between January and December 2028, with the deadline for submitting the initial formal audit opinion set for March 2029.







