The following text refers to the Federal Law for the Prevention and Identification of Transactions with Resources of Illicit Origin and its Regulations.
On August 23, 2013, the General Rules (the "Rules") referred to in the Federal Law for the Prevention and Identification of Transactions with Resources of Illicit Origin and its Regulations were published in the Official Gazette of the Federation. To read the full text of Agreement 02/2013 by which the Rules are issued, click here. Capitalized terms not defined in this summary were defined in the summary of the Law or in the summary of the Regulations. To read the summary of the Law, click here; to read the summary of the Regulations, click here. Alternatively, to read these and other summaries, consult the electronic version at www.vonwobeser_pageysierra.com. PURPOSE The Rules have two main objectives: first, to establish measures and procedures so that those who carry out Vulnerable Activities (in accordance with Article 17 of the Law) prevent and detect transactions with resources of illicit origin; and second, to establish the terms for filing the Notices. DEFINITIONS The Rules set forth the definitions of certain words used in the Regulations and in the Law. Although the definitions established are numerous, mention should be made of some of them that indirectly determine some of the scope of the Law. Beneficiary: the person designated by the holder of an agreement or contract entered into with a person who carries out a Vulnerable Activity so that, in the event of the death of such holder, the designated person may exercise before it the rights arising from the respective agreement or contract; Controlling Beneficiary or Beneficial Owner: the person or group of persons who: a) Through another person or by any act, obtains the benefit derived therefrom and is the one who ultimately exercises the rights of use, enjoyment, benefit, exploitation or disposition of a good or service, or b) Exercises control over that legal entity that, in its capacity as Client or User, carries out acts or transactions with a person who performs a Vulnerable Activity, as well as the persons on whose behalf any of them is entered into. A person or group of persons is deemed to control a legal entity when, through the ownership of securities, by contract or any other act, it may: i) Impose, directly or indirectly, decisions at the general shareholders', partners' or equivalent bodies' meetings, or appoint or remove the majority of the directors, administrators or their equivalents; ii) Hold ownership of the rights that allow, directly or indirectly, the exercise of the vote with respect to more than fifty percent of the capital stock, or iii) Direct, directly or indirectly, the administration, strategy or main policies thereof; Client or User: any individual or legal entity, as well as trusts, that enter into acts or transactions with those who carry out Vulnerable Activities; IDENTIFICATION OF THOSE WHO CARRY OUT VULNERABLE ACTIVITIES In accordance with Article 17 of the Law (On Vulnerable Activities), certain Vulnerable Activities will be subject to identification and, in some cases, to Notice to the Authorities. To this end, the Regulations establish in their Articles 12 and 13 (On Obligations) the obligation that those who carry out Vulnerable Activities must be registered (or be enrolled) in the Federal Taxpayers Registry and have a valid Advanced Electronic Signature in order to register before the SAT and to be able to file the Notices. In addition, the Regulations establish that the information set forth in the Rules must also be submitted. These Rules, in turn, establish that individuals must submit the information indicated in Annex 1 of the Rules and that legal entities must submit the information indicated in Annex 2. Once the SAT receives the information described above, it will issue an electronic acknowledgment of registration and enrollment and will grant access to the electronic means for receiving any notices, reports or communications from the SAT, the UIF or the Ministry of Finance and Public Credit. Persons who have registered and cease to carry out Vulnerable Activities must, through the same means, deregister from the system. Legal entities, in accordance with Article 20 of the Law, must designate their representative in charge of filing the Notices with the information referred to in Annex 2. IDENTIFICATION OF THE CLIENT AND USER OF THOSE WHO CARRY OUT VULNERABLE ACTIVITIES Those who carry out Vulnerable Activities must prepare and observe policies for the identification of Clients or Users. In accordance with Article 37 of the Rules, such document must be made available to the UIF or the SAT within 90 days of the registration and enrollment for the filing of Notices referred to in the paragraphs above. Those who carry out Vulnerable Activities must also keep a single identification file for each of their Clients or Users. The files of each Client will be prepared in accordance with what the Rules establish in their annexes. In the case of an individual of Mexican nationality or of foreign nationality with temporary or permanent residence in Mexico, the data indicated in Annex 3 of the Rules must be recorded. With respect to a legal entity of Mexican nationality, the data indicated in Annex 4 of the Rules must be recorded. With respect to foreign individual visitors or those with a migratory status different from those established above, the data indicated in Annex 5 of the Rules must be recorded. With respect to foreign legal entities, the data indicated in Annex 6 of the Rules must be recorded. With respect to the legal entities, agencies and bodies listed in Annex 7-A, to whom the simplified regime will be applicable, the information referred to in Annex 7 must be recorded. If the client or user of the person who carries out the Vulnerable Activity are those persons identified in Annex 7-A and they have been considered as low risk in accordance with the guides and best practices disclosed by the UIF, then the simplified measures may be applied. With respect to trusts, the data indicated in Annex 8 of the Rules must be recorded. With respect to the Beneficial Owner, the person who carries out the Vulnerable Activities must record the data indicated in Annexes 3, 4, 5, 6 or 8, as applicable. It will be the responsibility of the person who carries out the Vulnerable Activities to ensure that the information is authentic (or to request additional references), legible, to cross-check it against the originals, to keep a copy of all the data and documents in the file, and to have it available for consultation by the Authorities. In the case of business groups, the file of each client or user may be integrated by any of the persons that make up the group. The foregoing may be carried out provided that certain conditions are met, such as obtaining the client's authorization and entering into agreements among the group's companies to guarantee the availability and control of the information. In the event that beneficiaries are designated in a transaction, the same information regarding them must be requested under the terms described above. The simplified measures for compliance with the obligations for clients or users considered low risk will consist of integrating the identification files with only the data indicated in Annexes 3, 4, 5, 6 or 8 of the Rules. It is the responsibility of the person who carries out transactions by electronic means to provide for identification and for the prevention of the improper use of the means of communication through the implementation of internal policies. Those who carry out Vulnerable Activities will establish mechanisms to monitor and aggregate the acts individually carried out by their clients or users in amounts equal to or greater than those indicated in the identification thresholds, and will aggregate the acts and transactions over periods of at least six months. Those who carry out the Vulnerable Activities consisting of the marketing of credit, service and prepaid cards (or any other scheme for storing monetary value) or those who market traveler's checks, must provide information on the use and destination of the funds. The files of each client must be reviewed at least once a year to verify that they contain the data provided for in Articles 12 and 16 of the Rules. When the person who carries out the Vulnerable Activity has information based on indications or facts that one of the clients is acting on behalf of another person, it must request information that allows the beneficial owner to be identified. The person who carries out Vulnerable Activities must refrain from entering into transactions with those who fail to submit the required information. NOTICES The Notices must be filed before the UIF, through the SAT, by electronic means, using the RFC number and the FIEL in the official formats. Those who carry out Vulnerable Activities and have not carried out acts or transactions subject to Notice during the corresponding month must submit, in the official format, a report in which only the changes corresponding to the identification of the person who carries out the activity will be completed, as well as the indication that during the corresponding period no acts or transactions subject to Notice were carried out. RESERVE AND CONFIDENTIALITY OF THE INFORMATION Those who carry out Vulnerable Activities or any of their members, board of directors, representatives, officers, etc., must keep confidential the information relating to the acts or transactions related to the Vulnerable Activities. The persons subject to this obligation will be prohibited from alerting: (i) Their clients or users about any reference made to them in the Notices; (i) Their clients, users or any third party regarding any of the requirements for information, documentation, data or images provided for in the Law and the Regulations; and, (ii) Their clients, users or any third party about the existence or filing of seizure orders issued by the competent authorities before they are executed. EXCHANGE OF INFORMATION AMONG THOSE WHO CARRY OUT VULNERABLE ACTIVITIES Those who carry out Vulnerable Activities and form part of a business group may exchange information on business relationships they have established with their clients and users in those cases where the purpose is to prevent the commission of crimes related to resources of illicit origin. The exchange will be carried out under strict rules that guarantee the security and confidentiality of the information exchanged. GENERAL PROVISIONS Those who carry out Vulnerable Activities must access the electronic means (through which notices will be served) on a periodic basis. Notices will take effect at the moment their receipt is acknowledged or, as the case may be, on the fifth business day following the date on which the authority sends the notices and makes them available in the electronic means. Those who carry out Vulnerable Activities must, within 90 days of registration and enrollment, have documents in which they develop their guidelines for the identification of clients and users, as well as the criteria, measures and internal procedures they must adopt to comply with the provisions of the Law, the Regulations and the Rules. Mention is made of the obligation to establish the internal procedures to verify and update the data provided; to consider a client or user as low risk; procedures to prevent the improper use of electronic means and to guarantee the security and confidentiality of the information shared among parties of a business group. The UIF may issue and disclose guides or best practices for the development of training programs for compliance with the obligations established by the Law, the Regulations, the Rules and other applicable provisions. TRANSITORY PROVISIONS The Rules entered into force on September 1, 2013. Should you have any questions or comments regarding the content of this summary, the provisions contained in the Law, the Regulations, the Rules or any other applicable provision related to transactions with resources of illicit origin, please do not hesitate to contact us. Andrés Nieto, Partner: + 52 55 5 258 10 00, anieto@vwys.com.mx Luis Alberto King, Associate: + 52 55 5 258 10 00, lking@vwys.com.mx To access the PDF version of this document, please click here.