On October 29, 2024, Senator Javier Corral, from the dominant party's caucus, presented a proposal to amend the Federal Law for the Prevention and Identification of Operations with Resources of Illicit Origin (LFPIORPI) and the Federal Penal Code (CPF). This initiative is part of Mexico's ongoing efforts to align its financial regulations with the recommendations of the Financial Action Task Force (FATF), especially in preparation for the mutual evaluations of 2025.
On October 29, 2024, Senator Javier Corral, from the dominant party's caucus, presented a proposal to amend the Federal Law for the Prevention and Identification of Operations with Resources of Illicit Origin (LFPIORPI) and the Federal Penal Code (CPF). This initiative is part of Mexico's ongoing efforts to align its financial regulations with the recommendations of the Financial Action Task Force (FATF), especially in preparation for the mutual evaluations of 2025.
Key Aspects of the Reform Proposal:
1. Inclusion of Terrorism Financing: The proposal seeks to explicitly add provisions against terrorism financing in the LFPIORPI, alongside existing anti-money laundering (AML) regulations.
2. Strengthening of Powers for the Financial Intelligence Unit (UIF): The reform includes provisions to expand the authority of the UIF, allowing it to access information on Politically Exposed Persons (PEP) and other obligated subjects. Additionally, the proposal establishes the UIF's status as a victim or offended party in criminal proceedings for operations with resources of illicit origin.
3. Transparency and Identification of the Final Beneficiary: The initiative requires the registration of final beneficiaries in corporate entities and the obligation to report any changes in ownership. Furthermore, the bill introduces a precise definition of “Controlling Beneficiary” in the LFPIORPI, reducing the identification threshold of participation in the entity from 50% to 25%. Commercial entities must identify and register their Controlling Beneficiaries through an electronic system managed by the Ministry of Economy of Mexico. This Controlling Beneficiary registry complements the partner update notice currently managed by the Tax Administration Service (SAT). However, unlike the General Law of Commercial Companies, the LFPIORPI establishes penalties for non-compliance with this registry for obligated subjects, with fines ranging from 2,000 to 10,000 times the UMA (Unit of Measure and Update).
4. New Obligations and Expansion of Scope: The list of vulnerable activities under the LFPIORPI would be expanded to include virtual asset exchanges conducted with Mexican nationals from another jurisdiction. Additionally, the proposal includes the obligation to comply with the “travel rule”; that is, to collect and provide information on virtual asset transactions of the originator, the recipient, and, if applicable, the Controlling Beneficiary. Likewise, the obligations provided in Article 18 of the LFPIORPI would be modified as follows:
a) Identification and Knowledge. Section I would expand its scope to include not only the identification of clients or users but also the obligation to know them directly.
b) Documentation. Section III would require obtaining documentation that allows the identification of the Controlling Beneficiary of clients or users who are legal entities, trusts, or other legal figures, regardless of whether it is in their possession or not. In the case of the client or user being an individual, a declaration would be collected regarding whether they are aware of the existence of a Controlling Beneficiary and, if applicable, the documentation to identify them.
c) Record Keeping. Section IV would specify what supporting information must be retained by those conducting vulnerable activities (records of operations that allow the reconstruction of individual operations, commercial correspondence, and results of prior analyses conducted).
d) 24-Hour Notices. Section VI would include the submission of 24-hour notices based on the guidelines issued by the authority and general rules.
e) RBA. A Section VII would be added to provide for the obligation to carry out an assessment with a risk-based approach, in terms of the general rules, that allows identifying, analyzing, understanding, and mitigating risks both of the obligated subjects and the clients or users.
f) Internal Policies Manual and Automated Mechanisms. A Section VIII and X would be added to establish that those conducting vulnerable activities must develop an internal policies manual containing the criteria, measures, and procedures necessary to comply with the obligations provided in the law. They must also establish automated mechanisms to conduct ongoing monitoring of their clients' or users' operations to identify those that do not fall within their transactional profile. Additionally, if the obligated subjects are part of a corporate group, policies applicable to all majority-owned branches and subsidiaries, including foreign ones, must be implemented for the prevention of crimes with resources of illicit origin and terrorism financing.
g) Personnel Selection and Training. A Section IX would be added to contain the obligation to develop processes for personnel selection, as well as to adopt annual training programs aimed at those who are part of the management body, executives, compliance officers, and employees who have direct contact with clients or users.
h) Audit. A Section XI would be added to indicate the obligation to have a review by the internal audit area or an external auditor, when the risk of the person conducting the vulnerable activity is high, to evaluate and report in a calendar year the effectiveness of compliance with the obligations provided in the law and its secondary regulations.
5. Introduction of New Vulnerable Activities in the Real Estate Sector: A section is added