Get your branches ready for the facial biometrics the CNBV requires, before the deadline
Facial biometrics becomes one of the identity verification methods for in person operations. With our technology, already certified, you meet the requirement on time and avoid penalties.
70
business days left to comply
90%
minimum match against INE/SRE
ISO 30107-3
the certification Annex 71 requires
Book a demo
Trusted by banks across Latin America
The solution
Everything the regulation requires, in a single platform
Capture, verification, database and evidence: every Annex 71 requirement, covered.
The certification the regulation requires
Passive liveness certified iBeta Level 2 under ISO/IEC 30107-3, the requirement of Annex 71. We add anti-injection and anti-deepfake defense on top.
Verification against INE and SRE
Fingerprint online against the registry and facial matched 1:1 against the record, ≥90% in seconds, with automatic documentary evidence of every verification.
On-prem or dedicated deployment
Segregated infrastructure, independent network and encryption in transit and at rest, as Annex 71 requires. No single point of failure.
Operational within the deadline
API-first plus SDKs for branch, ATM and kiosk. Employees first (a natural pilot), then the network. In weeks.
Still evaluating? Download the 2026 CNBV Compliance Pocket Guide
A one-pager with the essentials of the resolution: what it requires, who it applies to, deadlines and the Annex 71 checklist.
The regulation
The regulatory roadmap: four milestones that define the project
Phase 1 · Start
Jul 2, 2026
Entry into force
The resolution becomes legally active (day after DOF publication). All credit institutions must begin alignment.
Phase 2 · Notice
~Aug 1, 2026
Existing DB notice
Banks with an active biometric database file a formal notice via Annex 75, stating dates and biometric types. No fee or penalty.
30 calendar days
Phase 3 · Deadline
Late Oct / Early Nov 2026
Full compliance
Alignment with all amended articles and the Annex 71 infrastructure specs, including facial biometrics systems.
70 business days · estimated
Ongoing
Steady state
Modality restriction
Databases are limited to fingerprint and facial data (Annex 71); iris and voice remain prohibited until the CNBV issues further technical amendments.
The product in operation
Enroll once. Verify across every channel
A single biometric engine and a single Annex 71-compliant database: the same identity in branch, ATM, kiosk, app and web.
Assisted: enrollment
Mandatory by regulation for the first capture: at the teller window, guided by an employee, with automatic quality validation.
Unassisted: authentication
The enrolled customer verifies on their own (1:1 match): ATM, kiosk, app or web, where the regulation allows it.
Mixed: the typical deployment
Assisted enrollment + authentication on any channel. One biometric template, automatic evidence of every operation.
For compliance and AML teams
CNBV-ready from day one
Every verification is traced with the documentary evidence required by art. 51 Bis 2, which the CNBV may request at any time.
- Support for the Annex 75 notice and the annual validation with Internal controller.
- Documented accessibility mechanisms for people with physical impairments.
- Explainable traceability of every decision: when the CNBV asks, there will be an answer.
Why Facephi
What makes the difference in a CNBV project
Capabilities the resolution turns into requirements, and where other providers tend to fall short.
|
Key capability for the regulation |
Facephi |
Other providers |
|---|---|---|
| Facial multibiometrics + fingerprint: the only two biometrics the CUB admits |
Both
|
Facial only
|
| Fingerprint verified online against INE/SRE and facial matched 1:1 against the record |
Both
|
Partial
|
| Duplicate identity detection (1:N deduplication, required at first capture) | ||
| Full traceability of every verification: the documentary evidence the CNBV requests | ||
| Configurable data residency by region (on-prem / dedicated infrastructure) |
Provider dependent
|
|
| Adaptation to a new identity document (e.g. a new INE credential) |
2 days
|
Up to 4 weeks
|
| Behavioral biometrics for continuous fraud prevention |
Comparison based on internal market analysis (2025) against the main identity verification providers present in Mexico.
Aligned with global standards
The credentials a compliance team needs to sign off
Certified ethical technology, compliant with international data protection rules and standards.
ISO/IEC 30107-3 · iBeta L2
Certified presentation attack detection: the mandatory requirement of the new Annex 71.
NIST FPAD & FRTE/FRVT
Independently validated biometric accuracy: the basis of 1:N deduplication.
ISO 27001 + ISO 22301
Information security and business continuity.
Gartner®
Recognized in the Hype Cycle for Digital Identity 2025.
Success stories
Banks already verifying identity with Facephi
Frequently asked questions
The CNBV resolution, made clear
Published in the DOF on July 1, 2026, it amends the Circular Única de Bancos and incorporates facial biometrics, alongside fingerprint, as a mechanism for identifying and authenticating customers in in-person operations. Fingerprint is verified online against the INE, SRE or another federal authority (minimum 90% match); facial is matched 1:1 against the customer record or the institutional database.
Mexican credit institutions: commercial banks and development banks. It applies to in-person operations by individuals linked to level 3 and 4 accounts, even when the account was opened at another institution.
90 business days from entry into force (July 2, 2026): approximately until mid-November 2026. Banks with a biometric database already in place must also notify the CNBV within 30 calendar days.
Presentation attack detection under ISO/IEC 30107-3 or Face Verification Certification, 1:N deduplication under NIST FRVT, image quality under ISO 19794-5 and the ICAO standard, assisted capture in a controlled environment, and dedicated, segregated infrastructure with encryption and documentary evidence.
Yes. Art. 51 Bis 2 of the CUB expressly allows contracting third parties for the services to build the biometric databases, always under the Annex 71 requirements.
No. It is optional. Customer identity is initially verified against the official authority database (INE or SRE). Organizations may also build and use their own biometric database for subsequent verifications of enrolled customers. Certified capture technology and connectivity with the INE or SRE verification services are required.