The resolution mandates revised customer identification requirements, biometric verification procedures, and remote account opening controls that are core KYC processes for managing identity verification risk during account onboarding.
Mandatory inheritance: KYC is a child of Authentication, which must be raised as the secondary tag per the tagging logic protocol.
Obligation
The resolution mandates revised customer identification requirements and new biometric verification procedures that credit institutions must implement during account opening, which constitutes Controls Implementation of preventive identity-verification measures.
The requirement for credit institutions to notify the Commission within 20 business days of implementing biometric systems represents a Reporting obligation to the regulator, though this is secondary to the primary control-deployment duty.
Activity
The resolution modifies customer identification and account-opening requirements for credit institutions across multiple account levels, which falls within the customer onboarding activity scope of establishing new retail customer relationships through identification and due diligence checks.
The amendments introduce biometric verification and 'Proof of Life' requirements for account opening procedures, which relate to identity verification controls; however, this is primarily a procedural/technical control enhancement rather than a core business activity, warranting human review of secondary classification.
Themes
The update introduces biometric authentication requirements and 'Proof of Life' technical tests for account opening procedures, which directly address robust customer authentication using multiple independent elements for specified financial actions.
The revised customer identification requirements and establishment of biometric information databases reflect broader data protection and privacy obligations governing how customer personal data is collected, used and secured.
Functions
The update introduces new customer identification, biometric verification, and account-opening requirements that directly impact how credit institutions must operate their account-opening and customer onboarding processes.
Information Security has a secondary role in implementing and maintaining the biometric information databases and 'Proof of Life' algorithmic verification systems, though the primary operational burden falls on account-opening and servicing teams.
2026-07-15 15:05:01·pdonofrio@vixio.com
Meta Id
3325391
Content ID
3333873
GUID
ea7d7ab6f208ea64278e6cfca536e9a2
Pipeline Progress
🔄 Pipeline Journey
⏱
19s
total
✓
Queued15:04:41
+0s
✓
Metadata15:04:41
+0s
✓
S3 Content15:04:41
+1s
✓
Extracted15:04:42
+5s
✓
LLM Gen15:04:47
+13s
✓
Stored15:05:00
TITLE: Mexico's National Banking and Securities Commission Modifies General Provisions for Credit Institutions
BODY:
On July 14, 2026, the National Banking and Securities Commission (Comisión Nacional Bancaria y de Valores) published a resolution modifying the general provisions applicable to credit institutions in Mexico's Official Journal (Diario Oficial de la Federación).
The resolution harmonises the regulatory framework following amendments issued by Mexico's central bank, Banco de México, and the Ministry of Finance and Public Credit (Secretaría de Hacienda y Crédito Público). On June 17, 2026, Banco de México introduced a new operational tier called "Level 2 Bis" in the classification of sight deposit accounts through Circular 11/2026, which modified Circular 3/2012. The resolution updates general provisions to accommodate this new account classification alongside existing Levels 1, 2, 3, and 4.
Key amendments include: revised customer identification requirements for presential and non-presential account opening across all account levels; updated provisions for electronic banking contracting; introduction of "Proof of Life" requirements—technical tests using algorithms to verify biometric characteristics and confirm a living subject is present during account opening procedures; establishment of biometric information databases for customer identity verification; and modified requirements for remote account opening for Level 2 Bis and Level 4 accounts, as well as consumer and commercial credit contracts. The resolution also repeals Article 316 Bis 9 and Annex 63 from the existing general provisions. Credit institutions must notify the Commission within 20 business days of implementing biometric verification systems.
The resolution entered into force on July 15, 2026, the day following publication. These amendments strengthen regulatory coherence and provide legal certainty to credit institutions and their customers.