Many companies find out they are a regulated party under Mexico’s AML law only when an audit arrives. Since the reform to the LFPIORPI published on July 16, 2025 —effective the next day— and the updated Regulation (published March 27, 2026), the net grew wider. If you run a vulnerable activity, the law reaches you regardless of your main line of business.
What is a vulnerable activity
A vulnerable activity is a lawful economic operation that, by its nature, can be used to launder money. Article 17 of the LFPIORPI lists them: games and raffles, loans, real estate, jewelry and precious metals, vehicles, armoring, art, virtual assets, professional services rendered on a client’s behalf, and real-estate development, among others. Running any of them makes you a regulated party.
What counts is your actual operation, not your corporate purpose. If you perform the activity in practice, the duty arises even if it is not in your charter.
The two thresholds to watch
The law sets two amounts, and mixing them up is costly:
• Identification threshold: above this, you must collect the client’s data and build a KYC file.
• Report threshold: always equal to or higher; above it, you must also report the operation to the tax authority.
Both are set in UMA, not pesos. The 2026 daily UMA is $117.31 and applies from February 1, 2026 to January 31, 2027. For example, jewelry and precious metals trigger identification at 805 UMA (about $94,435) and a report at 1,605 UMA (about $188,283).
Activities with no minimum
Some activities show no mercy: client identification is required from the first peso. That is the case for real- estate sales, certain loans and virtual-asset operations. There is no tolerance threshold: if you operate, you identify.
What the 2025 reform changed
The reform tightened the regime to align with GAFI (FATF) recommendations:
• Real-estate development is now a standalone vulnerable activity.
• Automated mechanisms and a risk-based approach are required for monitoring.
• Records must be kept for ten years for operations from July 17, 2025 onward.
This is a step up in demand, not a cosmetic tweak. Complying by hand no longer works. A platform like DYNAMI automates identification, builds the KYC file and watches the thresholds operation by operation, so none crosses the limit without your knowledge.
How to know if you comply
Four steps let you self-diagnose:
1. Match your actual activity to Article 17.
2. Compare each operation against its two thresholds.
3. Register on the tax authority’s AML portal (SPPLD), with your e.firma and RFC. 4. Appoint a compliance officer and build your files.
If you run more than one vulnerable activity, each carries its own duties.
Frequently asked questions
Does being a regulated party mean I did something illegal? No. Vulnerable activities are lawful; the law only
asks you to identify, report and keep records.
Is staying below the report threshold enough? Not always. A single client’s operations accumulate for up to six months; the total can trigger a report even if no single operation does.
What if I do not register? Running a vulnerable activity without complying exposes you to fines that start at 200 UMA and rise with the severity of the breach.