- Aug 13, 2026
- 8 min read
Why Transaction Monitoring Automation Is Mandatory for Mexican Financial Institutions
Mexico’s 2025 AML reform introduced new automated transaction monitoring requirements. Here’s what businesses need to know.

From July 2025 to August 2026, Mexico's National Banking and Securities Commission (CNBV) has imposed millions of dollars in fines on financial institutions for deficiencies in automated systems for detecting, monitoring, and reporting operations.
In July 2025, Mexico amended its key AML framework to require automated mechanisms for monitoring user behavior. But why did Mexico take this step? Transaction monitoring automation is now standard for most major financial institutions worldwide, but it’s not something other regulators have so far felt the need to enforce.
It’s time to take a closer look at what exactly Mexican regulators require, why this change has happened, and key steps to build a compliant transaction monitoring program in Mexico.
Mexico's transaction monitoring mandate
Mexico's transaction monitoring rules form part of the country’s wider AML landscape, which is made up of a number of regulations (and their amendments) plus regulator guidelines.
Mexico’s key AML rules are set out in:
- The Federal Law for the Prevention and Identification of Operations with Resources of Illicit Origin (commonly known as the “Anti-Money Laundering Law” or LFPIORPI), together with applicable General Rules and Reglamento, establishes Mexico’s general AML framework and baseline AML obligations.
- The Law to Regulate Financial Technology Institutions (the "FinTech Law") oversees ITFs, including crowdfunding institutions and electronic payment fund institutions. Its AML/CFT requirements are supplemented by the General Provisions under Article 58 of the FinTech Law.
- The Credit Institutions Law establishes the regulatory framework for Mexico’s banking and credit sector and sets requirements for government oversight. Its AML/CFT framework is supported by the General Provisions under Article 115 of the Credit Institutions Law.
Automated transaction monitoring in Mexico
Automated monitoring is not a new requirement for CNBV-supervised financial institutions. Mexico's existing sector-specific AML rules have long required certain financial institutions to maintain automated systems that support the management and monitoring of customer information and transactions. The General Provisions issued under Article 115 of the Credit Institutions Law require banks to have automated systems that not only manage customer and transaction records but also detect and monitor unusual operations, generate regulatory reports, and flag transactions involving blocked or politically exposed persons. Similarly, the AML provisions applicable to FinTech institutions require automated systems for functions including customer-data management, transaction reporting, and the detection and reporting of unusual operations.
The July 2025 reform to the LFPIORPI added a new, explicit requirement for businesses carrying out Actividades Vulnerables, or vulnerable activities. Article 18, Section X requires them to have automated mechanisms that enable continuous monitoring of customer and user activities or transactions, identify activity outside their transactional profiles, and provide enhanced monitoring for politically exposed and high-risk customers.
Importantly, the new Article 18, Sections VII–XI obligations do not all apply immediately upon publication of the 2025 reform. Following the August 2026 amendments to the General Rules, the automated mechanisms required by Article 18(X) must be in place by June 1, 2027. Businesses subject to the LFPIORPI should therefore distinguish these new requirements from the automated-monitoring obligations that already applied to regulated financial institutions.
Who’s affected?
Mexico’s automated transaction monitoring requirements apply to two broad groups: financial institutions that already had sector-specific requirements, and entities carrying out Actividades Vulnerables that are subject to the new LFPIORPI requirements.
Financial institutions with existing automated-monitoring requirements
These include:
- Credit institutions ( banks) subject to the AML provisions issued under Article 115 of the Credit Institutions Law. Their rules include automated monitoring of transactional operations to detect potential unusual operations.
- Financial technology institutions (FinTechs) regulated under General Provisions under Article 58 of the FinTech Law, including crowdfunding institutions and electronic payment funds institutions. The CNBV identifies automated systems as one of their existing AML/CFT obligations.
Entities affected by the new LFPIORPI requirement
The 2025 reform introduced an explicit automated-monitoring requirement for persons and businesses carrying out the Actividades Vulnerables covered by Article 17 of the LFPIORPI. These include:
- Casinos, lotteries, and other gambling activities
- Certain issuance and commercialization of cards and other payment instruments
- Issuance and commercialization of travelers' checks
- Loans, credits, and guarantees provided outside the financial sector
- Real estate development and certain real estate transactions
- Dealing in precious metals, precious stones, jewelry, and watches
- Art dealing and auctions
- Commercialization and distribution of certain vehicles, aircraft, and vessels
- Armoring and security services for vehicles and real estate
- Transportation and custody of money or securities
- Certain independent professional services
- Notarial and other public-faith activities
- Receipt of donations by certain nonprofit organizations
- Certain customs and foreign-trade services
- Granting rights to use or enjoy real estate
- Certain virtual-asset activities conducted outside the regulated financial sector
Why manual review no longer works
Mexico has made strong progress on tackling money laundering in recent years, significantly improving its overall compliance with the internationally recognized standards set by the Financial Action Task Force (FATF). However, the problem is still widespread, and there is clearly more work to do.
Manual, spreadsheet-driven, or spot-check transaction reviews made sense for spotting signs of financial crime when transaction volumes were lower and cross-border payment rails were slower. But Mexico's financial system now processes enormous volumes of card transactions, electronic payments, digital transfers, and remittances, meaning manual transaction monitoring can’t keep pace.
And the volume of digital transactions is growing. For example, in 2024, 23.7% of people in Mexico used electronic transfers as a means of payment, up from just 8.2% in 2021, according to research by the CNBV and the National Institute of Statistics and Geography (INEGI). The CNBV’s 2025 Financial Inclusion Outlook, published in 2026, reports that Mexico recorded 9.1 billion transfers and transactions in 2024, up 16% from 2023. It also reports more than 68,000 transfers per 10,000 adults. Given the often instantaneous or near-instantaneous nature of these transactions, carrying out real-time monitoring manually is simply not realistic.
The tactics used by criminals are also becoming more sophisticated and targeted, and often involve automation to make their activities harder to detect. Increasingly, AML and anti-fraud efforts must rely on equally sophisticated analysis of behavior patterns and other more subtle indicators hidden in vast amounts of transaction data—something that manual handling cannot achieve.
Mexico’s move to compulsory automation of transaction monitoring systems reflects these concerns about the limitations of manual analysis, investigation, and reporting of suspicious activity. The goal is to make these processes more consistent and reliable, so that illicit flows are harder to move undetected through Mexico's financial and non-financial regulated sectors.
What automated transaction monitoring changes
Moving to automated monitoring means every transaction can be checked against a customer's risk profile and historical behavior in real time, rather than in scheduled batches. Suspicious patterns can then be flagged and escalated within minutes instead of days.
Automation can also significantly improve audit transparency by creating an uninterrupted evidentiary record. Instead of a compliance officer's notes or a periodic report, an automated transaction monitoring system, including AI transaction monitoring, generates a continuous, timestamped log of what was monitored, what was flagged, how it was investigated, and what action followed. This record provides critical proof that transaction monitoring is being carried out in line with regulatory requirements.
Suggested read: Suspicious Transaction Reports (STRs): The Latest Guidance for Regulated Businesses
Rules vs. models: Choosing the right approach to automated transaction monitoring
Automated transaction monitoring systems can be rules-based, model-based, or a hybrid of the two.
- Rules-based transaction monitoring uses predefined rules, criteria, and thresholds to flag transactions or customer activity that may require further investigation. Rules can reflect regulatory requirements, an institution's risk assessment, and known money laundering and terrorist financing typologies. This approach can be effective for detecting defined risk patterns, but it may generate false positives and requires regular review and adjustment as risks, customer behavior, and regulatory requirements evolve.
- Model-based transaction monitoring uses machine learning trained on transaction and behavioral data to identify suspicious activity. It can surface hidden patterns that rules-based approaches may miss. However, it requires high-quality training data and ongoing retraining as typologies evolve. Model-based transaction monitoring doesn't automatically reflect new regulatory requirements; that still depends on human-led model governance.
- Hybrid transaction monitoring combines rules that trigger direct actions for higher-risk scenarios with rules that assign risk scores to lower-risk signals. These scores can be aggregated with other risk signals, and a combined score that reaches a defined threshold can trigger an action, such as an alert or escalation. This approach can provide more nuanced risk assessment than relying on individual rules alone.
The importance of good raw data in automated transaction monitoring
Transaction monitoring automation is only as good as the data feeding it. Every automated monitoring engine, whether it's rule-based, model-driven, or a hybrid of both, depends on a continuous, accurate, well-structured feed of data. This includes account balances, transaction metadata, counterparty details, device and channel information, and historical customer behavior. This information will be supplied by an institution’s core banking system, which manages its foundational operations and acts as the single source of truth for transaction data.
This is where many institutions' automation efforts fall down. A monitoring system might be configured with sophisticated detection rules, but if it only receives batch files once a day, or if customer risk-profile data lives in a separate, poorly synced system, the monitoring layer is working from stale or incomplete information. The CNBV's expectations of real-time transaction limits, immediate step-up authentication, and an audit-ready log of every decision cannot be met if the underlying data pipeline introduces delays or gaps.
Institutions building or upgrading their monitoring programs need to treat this data pipeline as the foundation of their compliance stack. They must ensure their monitoring systems receive transaction data in real time, that customer risk profiles and KYC data are unified rather than siloed, and that the monitoring platform can process all of this without the need for manual reconciliation.
CNBV penalties for skipping automation
Institutions that fail to comply with automated transaction monitoring requirements in Mexico can face huge fines. Already in 2026, multiple fines have been issued, with some exceeding $1 million per compliance breach.
In serious cases, the CNBV may impose additional administrative measures and revoke an institution’s authorization to operate.
Receiving these sorts of sanctions can do massive harm to an institution’s reputation.
A compliance roadmap for the Mexico mandate
Achieving compliance with Mexico’s automated transaction monitoring requirements is a multi-step process. The following provides a general overview of key processes regulated institutions should carry out, but the specific approach required must be tailored to the individual company.
- Carry out an organizational risk assessment. Map your customer base, products, and channels against the Mexican AML requirements that apply to your organization, including the AML Law, CUB, Credit Institutions Law, and the General Provisions issued under Article 115 of the Credit Institutions Law. Use this assessment to identify where monitoring gaps are most likely to exist.
- Take a risk-based approach. Transaction monitoring should be tailored to the individual risk profile of each customer, so higher-risk customers are watched more closely than lower-risk ones.
- Audit your existing framework. Identify any processes, such as large-cash flagging, high-risk client reviews, and unusual-activity registries, that still rely on manual review or periodic batch checks rather than continuous, real-time screening. These will need to be moved over to automated monitoring as part of your implementation. Submit Reportes de Operaciones Inusuales, or Suspicious Transaction Reports, whenever suspicious activity is discovered.
- Procure an appropriate automated transaction monitoring solution. This must be able to meet the regulatory requirements, including for continuous monitoring and enhanced monitoring for high-risk users. It must also have the capacity to handle the volume of transactions you need to monitor and scale with your business.
- Fix the data pipeline. As covered above, an automated monitoring system is only ever as effective as the data it is fed. You must confirm that transaction data reaches the monitoring platform in real time and in a unified format with no gaps.
- Align rules and models to Mexican reporting requirements, including relevant thresholds and reporting deadlines.
- Create comprehensive audit trails. Every alert, escalation, and resolution should be logged automatically, so you can provide any evidence financial intelligence units (FIUs) and regulators may require when making a report or during an audit.
- Commission an independent audit. As outlined in our guide to passing a CNBV AML audit, an internal or third-party review can surface the same gaps regulators look for, giving you time to fix them.
- Train staff on the automated system. This training must be ongoing, ensuring everyone using the system knows how to operate it effectively and fulfill their role in your AML framework.
- Continuously review and refine the system. Fraud typologies and money laundering methods evolve, so a monitoring system configured for 2024's risks won't necessarily catch 2026's. You must make sure your system can catch the latest signs of financial crime to maintain compliance.
Suggested read: How to Pass CNBV AML Audits in Mexico: A Complete Compliance Guide
FAQ: Mandatory transaction monitoring automation in Mexico
-
Is transaction monitoring automation mandatory for banks in Mexico?
Yes. Mexican banks have been subject to requirements for automated systems that support transaction monitoring under the General Provisions under Article 115 of the Credit Institutions Law. The July 2025 LFPIORPI reform introduced additional automated-monitoring requirements for entities carrying out certain Vulnerable Activities.
-
What is the deadline for obliged institutions to comply with the automated monitoring requirement?
Persons carrying out Vulnerable Activities must have the automated mechanisms required under Chapter XIII of the General Rules in place no later than June 1, 2027. These mechanisms must contain information on acts and operations carried out from that date onward. This deadline applies to the new LFPIORPI automated-monitoring requirement and does not represent a new compliance deadline for CNBV-supervised institutions, such as credit institutions and FinTechs, which were already subject to automated-system requirements.
-
What are the penalties for not complying?
Penalties depend on the type of entity and the specific AML requirement that has been breached. Financial institutions are subject to sanctions under their respective sector-specific laws, while persons carrying out Vulnerable Activities under Article 17 may face fines under the LFPIORPI. For certain serious breaches, these fines can range from 10,000 to 65,000 times the daily value of the Unit of Measure and Update (UMA), or from 10% to 100% of the value of the relevant act or operation, whichever is greater.
-
What is AML transaction monitoring?
AML transaction monitoring is the ongoing process of reviewing customer transactions to identify activity that may indicate money laundering, terrorist financing, or other financial crime. It compares transactions against a customer's expected behavior, risk profile, and applicable regulatory thresholds. Anomalies are flagged for investigation and, where appropriate, reports must be filed with relevant financial intelligence units such as Mexico's UIF (Unidad de Inteligencia Financiera).
-
What is transaction monitoring?
Transaction monitoring, more broadly, is the practice of tracking and analyzing financial transactions to detect suspicious activity. It is required across banking, payments, FinTech, and other regulated sectors, and can cover fraud detection as well as AML obligations.
-
What does the CNBV require for transaction monitoring?
The CNBV requires regulated institutions to implement automated, real-time transaction monitoring, taking a risk-based approach with AML checks tailored to customers’ individual risk profiles. Suspicious transactions must be promptly investigated and, where reporting thresholds are met, Suspicious Activity Reports must be submitted to the UIF.
-
What counts as automated transaction monitoring?
Under the July 2025 amendments to Mexico's AML framework, persons carrying out Vulnerable Activities must have automated mechanisms that continuously monitor the acts or operations they conduct with clients or users. These mechanisms must identify transactions or activities that do not fit the client's or user's transactional profile and support enhanced monitoring of clients or users who are considered high-risk or Politically Exposed Persons (PEPs).
Relevant articles
- Article
- Jul 14, 2026
- 10 min read
Learn how to create an AML compliance policy covering CDD, MLRO duties, SAR filing, and audits, and get a free FINRA template to help you get started.

- Article
- 3 weeks ago
- 13 min read

What is Sumsub anyway?
Not everyone loves compliance—but we do. Sumsub helps businesses verify users, prevent fraud, and meet regulatory requirements anywhere in the world, without compromises. From neobanks to mobility apps, we make sure honest users get in, and bad actors stay out.


