Open Banking and Facial Biometrics: The Two Sides of Mexico’s New CNBV Regulation
2026 is the year the CNBV is tightening two different bolts on the same problem. One rule governs how banks share data with each other: that’s Open Banking, under the Fintech Law. The other governs how they verify who the customer is before letting them operate: that’s biometrics, under the Single Banking Circular (CUB).
The first is moving slowly: eight years after the Fintech Law, the most valuable data tier still has no secondary regulation. The second just took a concrete step forward: since July 2, 2026, banks can (and in some cases must) verify customer identity with facial biometrics, not just fingerprints.
For compliance teams, the difference matters: one rule has been stalled on paper for eight years, while the other was published, took effect, and already has a compliance deadline running. This article covers both pieces: what each requires, why they’re connected, and what they mean for banks and fintechs.
What Open Banking Means Under Mexico’s Fintech Law
Mexico’s 2018 Fintech Law requires financial information to be shared through standardized APIs. Article 76 splits the model into three tiers: open data (products, fees, locations), aggregated data (anonymized statistics), and transactional data (customer history, with consent).
Only the first tier has full secondary regulation, published by the CNBV years ago. The other two tiers, the ones that would enable truly personalized financial products, like better credit offers based on a customer’s actual history, still lack technical rules, even though the legal deadline has passed.
Open Banking Timeline in Mexico
| Milestone | When | Status in 2026 |
| Fintech Law (general framework, Art. 76) | 2018 | In force |
| CNBV open-data provisions (tier 1) | Published by the CNBV | Implemented |
| Secondary rules for aggregated and transactional data (tiers 2-3) | Deadline passed under the Fintech Law | Not published |
| Injunction lawsuit against CNBV, Banxico, and SHCP over the delay | December 2025 | Pending |
The official text of the Fintech Law and its Article 76 is available from the Chamber of Deputies’ law library.
Five Years Behind, in Numbers and in Court
Mexico closed 2025 with roughly 795 active fintechs (Finnovista), an ecosystem that is consolidating more than growing. Open Banking Tracker lists 167 Mexican banks with some kind of public API, though depth varies widely: most meet only the minimum required for the open-data tier.
On December 10, 2025, two entrepreneurs filed an injunction lawsuit against the CNBV, Banxico, and the SHCP. Their claim: the CNBV has not issued the aggregated- and transactional-data regulation that the Fintech Law itself has required for five years.
Their argument is direct: the omission blocks business projects that depend on that tier of data. The context doesn’t help either: the CNBV is operating in 2026 with a 4.5% budget cut and has lost technical staff to the private sector.
«Open Finance isn’t just a technological innovation; it’s a fundamental building block for real financial inclusion and health.»
— Adrián Martínez Pérez, entrepreneur, in El Financiero (translated from Spanish).
Mexico by the Numbers: Open Banking and the Fintech Ecosystem
| Indicator | Figure | Source |
| Active fintechs in Mexico (2025) | ~795 | Finnovista |
| Banks with some kind of public API | 167 | Open Banking Tracker |
| CNBV budget cut (2026) | -4.5% | El Financiero |
The Piece That Did Move: The New CNBV Facial-Biometrics Rule
While transactional Open Banking waits, the CNBV moved fast on another front. On July 1, 2026, it amended the Single Banking Circular (CUB) to add facial biometrics as an identity-verification method for in-person transactions, alongside the fingerprint that had been, since 2017, the only biometric allowed. The rule took effect on July 2.
The measure doesn’t stand alone: since February 2026, the biometric CURP has been mandatory nationwide for high-value procedures, and identity theft in Mexico has also grown sharply according to industry reports. Banking, the civil registry, and now credit institutions are converging on the same standard: identity verified with biometric data, not just documents.
The reform applies to in-person transactions on tier-3 and tier-4 accounts (the higher-balance accounts with no deposit cap): opening tier-4 accounts, active transactions and payment methods tied to tiers 3-4, and cash withdrawals or transfers from tier-4 accounts, even when the account is held at another institution.
Banks have 90 business days to adapt their systems, until mid-November 2026. Those that already had their own biometric database must notify the CNBV within 30 calendar days.
What Annex 71 of the CUB Requires
| Element | Requirement | Detail |
| Identity verification | Minimum 90% match | Against records from the INE, SRE, SAT, or another federal authority |
| Anti-spoofing (facial) | ISO/IEC 30107-3 certification | Mandatory to prevent presentation attacks (photos, masks, screens) |
| Image quality | ISO/IEC 19794-5 | Frontal 2D capture, controlled environment, no glasses or accessories |
| Biometric databases | Sale or transfer prohibited | Between credit institutions or to third parties, per the resolution itself |
| Compliance deadline | 90 business days | Until mid-November 2026 |
The rule allows banks to rely on technology providers to build the required capture and verification infrastructure, though the resulting database remains the bank’s own.
The law prohibits selling, sharing, or transferring it to other institutions or third parties: hiring a provider is not the same as handing over custody of the data. See the legal analysis of the resolution amending the CUB from the law firm Basham, Ringe y Correa for further detail.
Why the Two Rules Are Connected
Open Banking only works if the data being shared is trustworthy from the source: an API that moves information about a misidentified customer doesn’t improve the system, it contaminates it.
The facial-biometrics rule isn’t formally part of the Fintech Law’s Open Banking chapter, but it solves a problem that belongs to it: guaranteeing that the data’s «owner» is who they claim to be, in the in-person channel still used by most Mexican financial users, according to industry surveys.
Put another way: finishing the transactional-data regulation won’t count for much if, once published, banks can’t guarantee the history they share belongs to the right person. Facial biometrics is, in that sense, a quiet prerequisite, without which full Open Finance wouldn’t make sense.
Two CNBV Rules, One Underlying Problem
| Rule | What it governs | Status in 2026 |
| Fintech Law, Art. 76 (Open Banking) | Sharing data between institutions via API | Only tier 1 (open data) operational |
| CUB, Art. 51 Bis and Annex 71 (biometrics) | Verifying identity in in-person transactions | In force since July 2, 90 days to comply |
The Compliance Challenges the New Rule Leaves Behind
Complying with Annex 71 isn’t just about installing a camera: it requires anti-spoofing certification, specific image quality, database segregation, and periodic audits. For mid-size banks and neobanks without an already-approved biometric provider, the 90-business-day deadline leaves little room to build that infrastructure from scratch.
Compliance Pains Under the New CNBV Rule
| Pain point | Why it matters | What it requires or solves |
| Anti-spoofing (liveness) certification | Annex 71 makes it mandatory, not optional | ISO/IEC 30107-3 certification against presentation attacks (photos, videos, masks) |
| Verification against INE/SRE with a 90% match | It’s the legal minimum threshold for authentication | Certified connectivity to official databases |
| Segregation and security of the bank’s own biometric database | The CNBV can suspend its use if it fails | Dedicated infrastructure, encryption, annual audit |
Facephi obtained iBeta’s ISO/IEC 30107-3 Level 2 certification in 2022 for its facial liveness technology, after it was subjected to attacks using masks, photographs, and animation software, none of which achieved fraudulent access.
That’s exactly the standard the new Annex 71 now requires from Mexican banks. But it’s a technical starting point, not an automatic guarantee of compliance: each bank must validate its own implementation with the CNBV.
Facephi also offers specific guidance on AML compliance in Mexico and on identity verification for fintech.
FAQ: Open Banking and Facial Biometrics in Mexico
It allows, and in some cases requires, banks to verify customer identity with facial recognition in in-person transactions, in addition to the fingerprint that was the only method allowed since 2017. It took effect on July 2, 2026.
In-person transactions on tier-3 and tier-4 accounts: opening tier-4 accounts, active transactions and payment methods on tiers 3-4, and cash withdrawals or transfers from tier-4 accounts, even if the account is held at another institution.
It requires anti-spoofing protection certified under ISO/IEC 30107-3 and image quality compliant with ISO/IEC 19794-5, both mandatory to prevent presentation attacks.
They’re separate rules, but connected: Open Banking (Article 76 of the Fintech Law) governs how data is shared between institutions, and facial biometrics governs how that data is verified as belonging to the right person from the start.
No. Only the open-data tier is operational; the aggregated- and transactional-data tiers still lack secondary regulation and are the subject of an injunction lawsuit filed in December 2025.
90 business days from the effective date, until mid-November 2026. Banks that already had their own biometric database must notify the CNBV within 30 calendar days.