MEXICO AML READINESS SELF-ASSESSMENT
Assess your organization’s readiness for Mexico’s updated AML requirements
A bilingual, 22-question self-assessment for persons and organizations that conduct—or may conduct—Vulnerable Activities under the LFPIORPI.
Identify potential blockers and material implementation gaps ahead of the March 1, 2027 regulatory milestone and subsequent phased requirements.
HOW THE SELF-ASSESSMENT WORKS
A focused assessment designed to support internal readiness discussions without requiring documents or sensitive operational information.
1. Consider applicability
Review whether your organization conducts—or may conduct—an Activity classified as Vulnerable under Article 17 of the LFPIORPI. The assessment does not make this legal determination for you.
3. Review your indicative result
Receive an immediate readiness result organized by domain, including potential blockers, material gaps, and suggested priorities.
2. Answer 22 structured questions
Evaluate the organization’s current state across the principal implementation domains. Responses should reflect measures that currently exist—not controls that are merely planned.
4. Download the executive summary
Generate a concise PDF intended to support internal discussion, assignment of responsibilities, and implementation planning.
BEFORE YOU BEGIN
Do not enter confidential, privileged, personal, financial, customer, transaction-level, or other sensitive information. The self-assessment requests structured, self-declared responses only and does not require supporting documents.
The result is indicative and educational. It is not the formal risk-based assessment required by the General Rules, does not establish legal applicability or compliance, and does not constitute certification or legal advice.
PRIVACY AND RESPONSIBLE USE
Designed to minimize the information you disclose
The self-assessment uses structured responses to generate an indicative result. It does not require supporting documents or confidential operational evidence.
Do not include personal data, customer names, transaction details, privileged information, credentials, financial records, or other sensitive information in any field.
Pilot infrastructure
During the current pilot, the self-assessment opens as a web application administered by RiskIntel Consulting using Google Workspace infrastructure. You will leave the RiskIntel website and continue on a Google-hosted domain.
This arrangement is temporary. Squarespace presents the assessment and provides the branded entry point; it does not process or store assessment responses.
Before beginning, review the applicable privacy notice and confirm that you understand the self-declared and indicative nature of the result.
BEGIN THE SELF-ASSESSMENT
The assessment opens in a new tab. You can select English or Spanish before starting.
The assessment is currently delivered through a Google-hosted web application administered by RiskIntel Consulting.
WHAT THE SELF-ASSESSMENT EXAMINES
The questions cover ten interconnected areas that affect whether implementation is operational, documented, and supportable.
Applicability and registration
Whether the organization has assessed the scope of its activities and completed the registrations and designations that may apply.
Governance
Whether responsibilities, oversight, resources, escalation, and implementation ownership are defined.
Customer identification, knowledge, and profile
Whether procedures support the identification and understanding of customers and their expected transactional activity.
Beneficial ownership
Whether the organization can identify, document, and update beneficial ownership information.
Politically exposed persons and higher-risk relationships
Whether relevant relationships can be identified, assessed, approved, and subject to enhanced measures.
22 Questions
Customer risk classification
Whether customers can be classified and reassessed using documented risk criteria.
Institutional risk assessment
Whether the organization has a documented risk-based methodology supported by relevant information and mitigating measures.
Data
Whether the information needed for implementation is complete, reliable, current, and reconcilable.
Technology and sustainability
Whether systems, automated mechanisms, resources, and operating capacity can support continuing compliance.
Manual and supporting evidence
Whether policies, procedures, decisions, controls, and implementation measures are documented and supportable.
Approximately 3 minutes
Available in English and Spanish