horso by themebuzz

Client Identification

If your company operates in Mexico and performs a vulnerable activity, knowing you are a regulated party under the Anti-Money Laundering law (LFPIORPI) is only the first step. The obligation that is most often neglected —and the first thing the tax authority (SAT) checks in an audit— is not filing the notice: it is building an identification file for every client. Article 18 requires it from the first transaction that exceeds the identification threshold, and the July 16, 2025 reform (published in the Federal Official Gazette) raised the bar.

What the AML law requires

The identification file —Mexico’s Know Your Customer (KYC)— is the set of data and documents proving who your client is before you transact. It is the evidence you show, during a review, that you knew the party you did business with. Without a complete file, the transaction is exposed even if the notice was filed on time.

What the file must contain

An official ID is the starting point, not the file. A properly built file gathers, at minimum: a valid official ID, the tax registry (CURP/RFC), proof of address, and the client’s line of business. For transactions above the reporting threshold, add a statement that the client acts on their own behalf — or the identification of the third-party beneficiary.

The beneficial owner

When the client is a company, the file grows: incorporation deed, tax ID, the legal representative’s power of attorney and ID, and —critically since 2025— the beneficial owner identification. The reform added Articles 33 Bis, Ter and Quáter, requiring companies to identify and register the individual who ultimately controls or benefits from the entity. Recording who signs is no longer enough.

Keep records for 10 years

One of the reform’s costliest changes: Article 18, section IV raised the retention period from 5 to 10 years, for operations carried out on or after July 17, 2025. A file destroyed too early is an infraction in itself —even if it was properly built at the time.

What the SAT reviews

In an on-site verification, the inspector looks for traceability: that every above-threshold transaction has a complete file, that the beneficial owner is documented, and that records are kept for the legal term. Failure to build the file, or poor recordkeeping, is penalized alongside missing notices, with fines from 200 up to 65,000 UMA. Note that Article 55 allows a one-time, penalty-free correction if you act before the verification begins. The reform also added risk-based assessment, an internal policy manual, annual training, automated monitoring and audit duties (sections VII to XI) —but to be precise, these take effect only once the pending General Rules are published. What is enforceable today is identification, the file, the beneficial owner, and the 10-year retention.

Compliance without friction

The file is a living obligation: IDs expire, addresses change, and a counterparty can land on the SAT’s 69-B blacklist tomorrow. Tracking that by hand, client by client, for ten years, is where compliance breaks.

DYNAMI builds each client’s identification file from onboarding, screens automatically against the UIF, OFAC, UN and PEP lists, and flags the moment an ID expires or a counterparty enters a restricted list. It also records each client’s transactional profile —the automated mechanism the law now anticipates— and guarantees the 10-year retention without relying on a physical folder. It turns Article 18 from a manual, auditable burden into a process that monitors itself.

Frequently asked questions

Does it apply to one-offs?

Yes. The duty to identify arises from the transaction amount —the Article 17 identification threshold — not from whether the client is recurring. A one-time client above the threshold needs a complete file.

Is an ID copy enough?

It is the start, not the file. You also need the tax registry, proof of address, line of business and —for companies— the incorporation deed, the representative’s power of attorney, and the beneficial owner statement.

What if the client refuses?

The law requires you to abstain from the transaction when the client refuses to provide identification data. Documenting that refusal protects you; proceeding without a file exposes you.

Are saved PDFs enough?

Saving is half the job. You must prove complete integration, 10-year retention and traceability during an audit. A loose folder of files does not evidence control; a system with an audit trail does.

Post Comment

Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *