MEXICO AML READINESS SELF-ASSESSMENT

Assess your organization’s readiness for Mexico’s updated AML requirements

A bilingual, 22-question self-assessment for persons and organizations that conduct—or may conduct—Vulnerable Activities under the LFPIORPI.

Identify potential blockers and material implementation gaps ahead of the March 1, 2027 regulatory milestone and subsequent phased requirements.

HOW THE SELF-ASSESSMENT WORKS

A focused assessment designed to support internal readiness discussions without requiring documents or sensitive operational information.

1. Consider applicability

Review whether your organization conducts—or may conduct—an Activity classified as Vulnerable under Article 17 of the LFPIORPI. The assessment does not make this legal determination for you.

3. Review your indicative result

Receive an immediate readiness result organized by domain, including potential blockers, material gaps, and suggested priorities.

2. Answer 22 structured questions

Evaluate the organization’s current state across the principal implementation domains. Responses should reflect measures that currently exist—not controls that are merely planned.

4. Download the executive summary

Generate a concise PDF intended to support internal discussion, assignment of responsibilities, and implementation planning.

BEFORE YOU BEGIN

Do not enter confidential, privileged, personal, financial, customer, transaction-level, or other sensitive information. The self-assessment requests structured, self-declared responses only and does not require supporting documents.

The result is indicative and educational. It is not the formal risk-based assessment required by the General Rules, does not establish legal applicability or compliance, and does not constitute certification or legal advice.

PRIVACY AND RESPONSIBLE USE

Designed to minimize the information you disclose

The self-assessment uses structured responses to generate an indicative result. It does not require supporting documents or confidential operational evidence.

Do not include personal data, customer names, transaction details, privileged information, credentials, financial records, or other sensitive information in any field.

Pilot infrastructure

During the current pilot, the self-assessment opens as a web application administered by RiskIntel Consulting using Google Workspace infrastructure. You will leave the RiskIntel website and continue on a Google-hosted domain.

This arrangement is temporary. Squarespace presents the assessment and provides the branded entry point; it does not process or store assessment responses.

Before beginning, review the applicable privacy notice and confirm that you understand the self-declared and indicative nature of the result.

BEGIN THE SELF-ASSESSMENT

The assessment opens in a new tab. You can select English or Spanish before starting.

The assessment is currently delivered through a Google-hosted web application administered by RiskIntel Consulting.

WHAT THE SELF-ASSESSMENT EXAMINES

The questions cover ten interconnected areas that affect whether implementation is operational, documented, and supportable.

Applicability and registration

Whether the organization has assessed the scope of its activities and completed the registrations and designations that may apply.

Governance

Whether responsibilities, oversight, resources, escalation, and implementation ownership are defined.

Customer identification, knowledge, and profile

Whether procedures support the identification and understanding of customers and their expected transactional activity.

Beneficial ownership

Whether the organization can identify, document, and update beneficial ownership information.

Politically exposed persons and higher-risk relationships

Whether relevant relationships can be identified, assessed, approved, and subject to enhanced measures.

22 Questions

Customer risk classification

Whether customers can be classified and reassessed using documented risk criteria.

Institutional risk assessment

Whether the organization has a documented risk-based methodology supported by relevant information and mitigating measures.

Data

Whether the information needed for implementation is complete, reliable, current, and reconcilable.

Technology and sustainability

Whether systems, automated mechanisms, resources, and operating capacity can support continuing compliance.

Manual and supporting evidence

Whether policies, procedures, decisions, controls, and implementation measures are documented and supportable.

Approximately 3 minutes

Available in English and Spanish