anexo 71 cnbv
Analysis

The CNBV’s Biometric Reform: What Mexican Banks Need to Decide Before November 2026

The new provisions published by the CNBV on July 1, 2026 give banks 90 business days to add facial recognition, alongside fingerprint verification, as a verification mechanism for higher-risk in-person operations. Read that way, in the executive summary, it sounds like just another technical adjustment.

But the interesting part starts once you stop reading the executive summary and get into the operation. That’s where three decisions surface that can make the difference between simply complying with the new provisions and arriving with a solution built to hold up in the years ahead:

  • Enrollment and authentication are not the same process. The biometric match changes depending on whether it’s the first time a customer is registered, or a later transaction.
  • Outsourcing the technology is allowed. A bank can rely on a provider to operate the biometric database, but accountability for the data still rests with the bank.
  • The branch is no longer an exception. Biometric verification now becomes a requirement in the in-person channel too, for higher-risk operations.

These are three nuances that the text of the regulation mentions, but whose operational implications aren’t always obvious, at a moment when the evolution of digital fraud in Mexico had already been pushing the sector toward stricter identity controls in the in-person channel as well.

The New Provisions, Anexo 71 at a Glance

Field Detail
Published DOF, July 1, 2026
Effective date July 2, 2026
General compliance deadline 90 business days (Third Transitory Provision), through late October / early November 2026
Who it applies to Higher-risk in-person operations on level 3 and level 4 accounts
What it authorizes Facial recognition as a biometric data point in addition to fingerprint
Transitional notice (existing databases) Anexo 75, within 30 calendar days of the effective date (Second Transitory Provision)
Ordinary notice (new databases) Anexo 75, within 20 business days of the database’s first use (Art. 51 Bis 2)

What Is Anexo 71 of the CNBV?de la CNBV? 

Anexo 71 is the technical annex of the General Provisions Applicable to Credit Institutions issued by the National Banking and Securities Commission (CNBV), known in the industry as the Circular Única de Bancos. It sets out the requirements a bank must meet to capture and use fingerprints and facial biometrics as identification mechanisms.

The previous version of the annex only covered fingerprints. This reform replaces it entirely and adds the face with its own technical requirements: it’s not a minor addition, it’s a full section of the annex with its own standards for image quality, liveness detection, and deduplication.

Complying with Anexo 71 is a short-term goal. Choosing a biometric architecture that keeps working as the regulation evolves is a strategic decision.

The question isn’t whether it’s convenient, or whether facial recognition should be added at all. That decision was essentially settled by the CNBV. The real decision is where to build the biometric capability: as a one-off project to meet a rule, or as cross-functional infrastructure for digital identity.

Who Do the New Provisions Apply to, and Since When? 

LasThe new provisions don’t apply to all banking operations equally. The obligation is concentrated on those where identity theft would have the greatest impact.

In practical terms:

  • Level 3 accounts are products with a reinforced file and operating limits defined by regulation.
  • Level 4 accounts correspond to the traditional bank account, with no deposit limit and greater exposure to fraud and money laundering.

The regulator placed the requirement exactly where identity theft has the most consequences, and that’s the first thing that should determine which processes to review before others.

What Changes for Banks

The biggest challenge of Annex 71 is not implementing biometrics. Most financial institutions already use biometric capabilities in at least one channel, particularly for digital onboarding.

The real challenge is ensuring that the same level of security is consistently applied across branches, in-person transactions, and every other touchpoint where customers interact with the bank.

Fingerprint Verification vs. Facial Verification: Confusing Them Can Be Costly

The distinction here is important, because Annex 71 actually defines two separate verification stages, and confusing them can lead to an incorrectly designed end-to-end workflow. The new provisions should not be interpreted as requiring banks to query a government authority every time a customer performs a transaction. That is not what the regulation says. Instead, it requires institutions to establish a reliable biometric record and then use it to authenticate customers during subsequent transactions.

This distinction has significant implications for technology architecture, response times, and reliance on external services.

Criteria Fingerprint Verification (Enrollment) Facial Verification (Authentication)
Compared Against INE, SRE, or another federal authority The institution’s own biometric database
Matching Type 1:1 match against the external record 1:1 match against the internal record
Match Threshold Minimum 90% (to be confirmed against the official text published in the DOF) Not defined as a percentage against a third party; this is an internal verification process
When It Applies Customer enrollment in the biometric database (initial registration) Every subsequent transaction, once the customer has been enrolled
External Dependency Yes, during enrollment No; the regulation requires matching only against the institution’s own database

When the customer is enrolled in the biometric database

The first time an institution registers a customer’s biometric data, whether fingerprint or face, it has to match it against the records of an external authority: INE, SRE, Mexico’s tax authority, or another federal agency that offers that verification service. The annex itself sets a minimum match rate of 90% for this comparison. This is usually read as “the requirement of the new provisions,” and that’s true, but it’s only the first half.

When the customer is already enrolled and performs a new transaction

The second stage is the authentication of a customer who has already been enrolled. Here, the comparison is also a 1:1 match, but it is no longer performed against the INE or SRE for every transaction. Instead, it is matched against the institution’s own biometric database. The regulation is explicit on this point: verification must be carried out exclusively against the information stored in each institution’s biometric database.

Designing this second workflow as if it required querying an external authority again introduces unnecessary dependencies and latency that the new provisions do not require.

Can a Bank Use a Third-Party Biometric Provider?

It is worth clarifying a point that has caused some confusion in the first weeks following the publication of the new rules: Article 51 Bis 2 explicitly allows banks to engage a third-party provider to build and operate their biometric database.

What it does not allow is for the information in that database to be sold, transferred, shared, or made interoperable with other institutions or third parties for identity verification purposes. These are two different issues. Hiring a provider to deliver the service is a permitted business decision; allowing biometric data to circulate outside the institution’s control is not, regardless of who operates the platform.

For compliance teams, this changes the key question when evaluating biometric technology. The issue is not whether the provider can operate the verification process—the regulation already allows that. The real question is what logical segregation, encryption, and auditability controls the provider offers, so the institution can demonstrate, if requested by the CNBV, that it retains effective ownership, governance, and control over the biometric data, even when the biometric engine is operated by a third party.

What Does the Regulation Require, and How Does Technology Address It?

Annex 71 Requirement Facephi
ISO/IEC 30107-3 Presentation Attack Detection (Liveness Detection) ✅ iBeta Level 1 and Level 2 Certified
Deduplication in accordance with NIST FRVT ✅ NIST-Evaluated Technology
ISO 19794 Image Quality Compliance ✅ Compliant
Information Security ✅ ISO 27001, SOC 2 Type II, ENS High

Data Governance: Board of Directors Approval

There is an important nuance here before assuming that every biometric database must be approved by the Board of Directors. The Board approval required under Articles 51 Bis 3 and 51 Bis 5 does not apply to the standard process set out in Article 51 Bis 2. It applies only when an institution intends to use an identification mechanism or identity document that differs from those already established in the regulation and therefore requires special authorization from the CNBV. In those cases, the detailed description of the proposed mechanism must be approved by the Board before it is submitted to the CNBV.

In other words, if a bank follows the standard process described in the new provisions, Board approval is not a mandatory regulatory step. However, if the institution plans to propose an alternative approach—such as a different type of device, a different standard, or a different verification workflow—it must obtain Board approval before presenting the proposal to the CNBV. Each institution should determine which of these two scenarios applies, as the internal approval process differs significantly depending on the path chosen.

Branches Are No Longer Outside the Scope of the Change

For years, biometric investment has been focused on remote onboarding and digital channels, while physical branches operated under a convenient assumption: if the customer is present in person, much of the identity risk has already been addressed. The new provisions eliminate that assumption.

For Level 3 and Level 4 accounts, physical presence is no longer sufficient to exempt customers from formal biometric verification. Branches must now meet the same standards for traceability, encryption, and liveness detection that are already required in remote channels.

A bank with a robust biometric engine for its digital channels but a manual or poorly traceable process in its branches does not simply have a product gap to close—it has an architectural decision to make.

And that decision is likely to extend well beyond compliance with these new CNBV provisions.

Compliance Checklist: Decisions Banks Should Make Before November

If this resolution makes one thing clear, it is that the challenge is no longer purely regulatory. It is also technological and operational. 

What Questions Should a CIO or Compliance Officer Be Asking Today?

Does my solution cover only branches, or all customer channels?
Can I demonstrate end-to-end traceability of biometric data?
Is my architecture flexible enough to support future regulatory changes?
Does my provider already hold certifications such as ISO/IEC 30107-3 and NIST evaluations?
Am I building a solution to meet the November deadline, or a platform that will still be fit for purpose five years from now?

The deadline to adapt to the new provisions ends in November. But the important decision starts much earlier: complying with Anexo 71 is the starting point for designing an architecture that won’t need to be rebuilt with the next regulatory update.

Institutions that use this update to build a biometric architecture prepared for future regulatory demands will likely avoid redesigning their processes every time the rule changes.

Meeting the deadline is the immediate goal. Building a digital identity capability ready for what’s coming is the real strategic decision.

Bruno Rivadeneyra signs this analysis from his experience in compliance and digital identity. If your institution is evaluating how to comply with Anexo 71 within the deadline, the CNBV and LFPIORPI compliance guide goes deeper into the technical and operational requirements this article describes.

It is the technical annex to the Single Circular for Banks (Circular Única de Bancos) that establishes the requirements for capturing and using fingerprints and facial biometrics as identity verification mechanisms in the Mexican banking sector. It replaces the previous version, which covered fingerprint verification only.

Credit institutions supervised by the CNBV, for higher-risk in-person transactions involving Level 3 and Level 4 accounts.

No. When enrolling a customer, fingerprints and facial biometrics are matched against the INE, SRE, or another federal authority, with a minimum match rate of 90%. When the customer is already registered and performs a new transaction, the match is 1:1 against the institution’s own biometric database, not against an external authority.

Yes. The regulation explicitly allows it. What it does not allow is for the information contained in that database to be sold, transferred, shared, or made interoperable between institutions or with third parties for verification purposes.

Not necessarily. Board approval is required when the institution proposes an identification mechanism or document that differs from those already established in the regulation and requires special authorization from the CNBV to use it.

The CNBV may request additional information and, if it identifies serious or repeated non-compliance, it may order the partial or total, temporary or permanent suspension of the use of the biometric database, after granting the institution the right to a hearing.

No. Annex 71 regulates biometric verification within the Single Circular for Banks (Circular Única de Bancos) and operates alongside the anti-money laundering obligations established under LFPIORPI, which remain in force.

La CNBV puede requerir información adicional y, si detecta incumplimientos graves o reiterados, instruir la suspensión parcial o total, temporal o definitiva, del uso de la base de datos biométrica, previo derecho de audiencia a la institución.

No. El Anexo 71 regula la verificación biométrica dentro de la Circular Única de Bancos, y convive con las obligaciones de prevención de lavado de dinero de la LFPIORPI, que siguen vigentes.

Ready to protect your users?

Discover how Facephi's biometric technology can safeguard your identity verification process.

Facephi Facephi Identity Platform Onboarding Authentication UX Consultancy Facephi Builder Facephi Central Services Fraud Intelligence Platform Identity Fabric KYB Platform Teseo Identity Wallet IDV Suite Cuentas Mula Behavioural Biometrics Linkedin YouTube X Facebook
Secret Link