DeFi protocol frontend in Mexico
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Mexico without local incorporation, subject to AML obligations and low licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- No
- Licensing burden
- Low
- Last updated
- 2026-07-13
AML Obligations
- All DeFi protocol frontends serving Mexican residents must comply with the AML/CTF Law (Ley Federal para la Prevención e Identificación de Operaciones con Recursos de Procedencia Ilícita) as it classifies virtual asset operations by non-financial entities as 'vulnerable activities'
- Mandatory KYC for all providers serving Mexican residents
- Mandatory internal policies and transaction monitoring programs
- Reporting to the Financial Intelligence Unit (FIU) for transactions above thresholds
- AML/KYC obligations are mandatory for all providers serving Mexican residents, including DeFi frontends
Key Restrictions
- If operating as a non-financial entity (no Banxico authorization), the frontend must not offer client-facing custody services — those are reserved for financial institutions and are banned for the public
- If the frontend takes fees in a manner that constitutes a financial service (e.g., acting as a custodian or exchange), it may fall under Fintech Law requirements or require Banxico authorization, which has not been granted post-2019
- Security tokens (tokenized securities) accessible via the frontend would fall under the Securities Market Law, requiring separate compliance
- Stablecoins where the operator receives, manages, or safeguards public funds and enables redemption/transfer may fall under Fintech Law regulation
- Utility tokens staying on native platforms are typically outside regulation; payment tokens can fulfill obligations if contractually agreed but are not legal tender
Key Risks
- Enforcement risk: Mexico's FIU and SHCP actively enforce AML/CTF reporting; cartel-related money laundering cases (e.g., OFAC sanctions and US seizures for crypto laundering by Sinaloa Cartel) indicate heightened scrutiny of crypto flows
- Regulatory ambiguity: No approvals granted by Banxico post-2019 secondary rules for virtual asset operations, with fines up to $47,000 — creates uncertainty about whether fee-taking frontends require approval
- Banxico prohibits financial institutions from offering public-facing crypto services (Circular 4/2019); if the DeFi frontend is structured as or affiliated with a financial entity, it is banned from public operations
- AML classification as a 'vulnerable activity' is broad — unclear enforcement boundaries for purely non-custodial frontends vs. fee-collecting aggregators
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
AML/CTF Law (Ley Federal para la Prevención e Identificación de Operaciones con Recursos de Procedencia Ilícita): Classifies virtual asset operations by non-financial entities as vulnerable activities, requiring KYC, internal policies, transaction monitoring, and reporting to the Financial Intelligence Unit (FIU) for transactions over ~$58,000 MXN (645 UMAs) per client in six months.
AML/KYC: Mandatory for all providers serving Mexican residents, including:
Fintech Law (Ley para Regular las Instituciones de Tecnología Financiera): Defines virtual assets and grants Banxico regulatory powers but excludes non-financial custody from licensing.
Exchanges, Custody Providers, Payment Processors (Non-Financial Entities): No license or registration needed; services can be offered to the public if not reserved for regulated entities.
No approvals granted by Banxico post-2019 secondary rules, with fines up to $47,000 for violations.
Banxico: Regulates virtual assets for financial institutions; authorizes internal operations but bans client-facing custody.
Circular 4/2019 (Banxico): Limits financial entities to internal virtual asset operations with prior approval; bans public-facing services.
Federal AML Law (as amended 2018): Covers virtual asset transactions. https://www.diputados.gob.mx/LeyesBiblio/pdf/LFPIORPI_180818.pdf
Financial Intelligence Unit (FIU) and Ministry of Finance and Public Credit (SHCP): Enforce AML/CTF reporting for transactions above thresholds; SHCP oversees broader AML/CTF implementation.
Security tokens: Those representing or underlying securities (e.g., tokenized stocks or bonds) fall under Securities Market Law scope.
Certain stablecoins: If issuers receive, manage, safeguard public funds, and enable redemption/transfer, they may fall under the Fintech Law (Ley para Regular las Instituciones de Tecnología Financiera, March 2018).
Other cryptoassets: Not formally classified; utility tokens staying on native platforms are typically outside regulation, while payment tokens can fulfill obligations if contractually agreed. Virtual assets are not legal tender or currencies.
OFAC (Sept 26, 2023): Sanctioned Mario Alberto Jimenez Castro (Sinaloa Chapitos faction) for laundering via cryptocurrency. Elliptic
U.S. authorities (Nov 20, 2024): Seized $5.4M in three wallets (one VASP) for cartel money laundering. Same source.
U.S. authorities (Mar 17, 2023): Arrested Sergio Antonio Duarte Frias (Sinaloa) in Guatemala for laundering $869K narcotics proceeds via cryptocurrency. Same source.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — DeFi protocol frontends serving Mexican residents are permitted as non-financial entities without licensing, but must comply with AML/CTF vulnerable-activity obligations (KYC, internal policies, FIU reporting), cannot offer public-facing custody (reserved for financial institutions), and face increased risk if fee-taking blurs the line into regulated financial services.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?