If your company runs a regulated activity in Mexico — real estate development, lending, dealing in precious metals or jewelry, certain professional services — Mexico’s Anti-Money Laundering Law (LFPIORPI) now imposes a hard, dated obligation that a global compliance program does not automatically satisfy. On 7 August 2026, Mexico published Acuerdo 115/2026 in the Federal Official Gazette (DOF). It turned five long-dormant obligations from the July 2025 reform into operable rules with deadlines. The one most likely to catch a foreign operator off guard is the requirement for automated monitoring mechanisms under the new Article 41. From 1 June 2027, filing records is no longer enough: you must show the SAT a system that consolidates each client’s activity, runs a risk model, and fires alerts — and produce that evidence in the form Mexican authorities inspect.
What Acuerdo 115/2026 changed
Acuerdo 115/2026 does not create a new statute. It amends the General Rules that have governed LFPIORPI since 2013, and it operationalizes the obligations added by the reform published on 16 July 2025. It enters into force on 30 November 2026, but the heaviest duties are staggered across at least eleven separate deadlines running into 2028. For a foreign group, the practical takeaway is simple: the Mexican entity’s obligations are now concrete, dated, and evidence-shaped — not principles you can map onto an existing global policy and call done.
Two deadlines to lock in
Two dates matter most. By 1 March 2027, your Mexican operation must have its risk-based methodology, internal manual, client classification, KYC file and beneficial-owner procedure in place. By 1 June 2027, the automated monitoring mechanism must be operating, and it must record every act or operation carried out from that date forward (Transitorio Noveno). A program launched years ago at headquarters does not “count” retroactively for Mexico — the Article 41 clock starts on the Mexican deadline, with Mexican data.
The six Art. 41 functions
Article 41 sets six minimum functions the mechanism must perform:
- Preserve, update and allow consultation of the single client identification file.
- Consolidate each client’s operations to detect deviations from the transactional profile and accumulate operations under Art. 17.
- Feed the risk methodology built under the new risk-based chapter.
- Run the risk-grade classification model and keep its history for at least ten years.
- Run an alert system for high-risk clients, PEPs and list matches.
- Monitor the use of cash and precious metals under Art. 32.
The rule is deliberately technology-neutral — it accepts anything from specialized software to spreadsheet-based processes — but for any operator with real client volume, the six functions plus a ten-year audit trail push hard toward a dedicated platform.
Why global tooling isn’t enough
Here is the trap for international operators. A group-level transaction-monitoring stack may already flag suspicious flows — but it rarely produces what Article 41 demands in Mexico: a single identification file in the Mexican format, a risk-grade history retained for ten years, PEP checks run against Mexico’s official PEP 2.0 consultation, cash and precious-metals monitoring keyed to Art. 32, and — above all — an audit trail the SAT can inspect on its own terms. The obligation is not “detect the transaction.” It is “prove, in Mexican evidentiary form, that you detected it.” That gap is exactly what DÝNAMI by Cumbre Asesores is built to close: it sits at the Mexican layer of your compliance stack and converts monitoring into Article 41 evidence — the identification file, the ten-year risk-grade history, list and PEP consultation, and a SAT-ready trail — without asking you to rip out the global program you already run.
What the SAT can fine you
Non-compliance with the Article 18 obligations — where most of the new duties live — is sanctioned in UMA (Unidad de Medida y Actualización). Fines run from 200 to 2,000 UMA per breached obligation. With the 2026 UMA at 117.31 pesos, that is roughly 23,462 to 234,620 pesos per obligation, and breaches compound one obligation at a time. For a foreign parent, the sharper cost is usually structural: a Mexican subsidiary that cannot evidence its monitoring becomes a finding in group audits and a red flag in any transaction due diligence.
Frequently asked questions
Does our global AML system satisfy Article 41? Not automatically. It may perform the detection, but Article 41 is about Mexican-format evidence and a SAT-inspectable trail. The six functions must be demonstrable locally, in Mexico.
Who is a “sujeto obligado” here? Any person or entity performing an Actividad Vulnerable in Mexico — real estate, lending, precious metals, certain professional services and more — regardless of where the parent is domiciled.
Can we use spreadsheets? The rule allows it in principle. In practice, the ten-year risk-grade history, consolidated monitoring and mandatory alert system make spreadsheets fragile for anything above very low volume.
When exactly must the mechanism operate? By 1 June 2027, and it must record operations carried out from that date onward.