Regulatory compliance for active businesses in Mexico

Once a company has completed its initial setup—entity formation, RFC, RNIE, and IMSS—the real compliance work begins. Operating a business in Mexico generates ongoing obligations across at least five regulatory categories simultaneously. Most companies manage these reactively: they discover an obligation when an inspector arrives, a counterparty requests a compliance certificate, or an accountant flags a filing that was missed. That approach is expensive.

A regulatory compliance framework organizes your obligations by category, assigns ownership, establishes a calendar, and creates the documentation trail that supports your position in an audit.

What a compliance framework is—and is not

A compliance framework is not a policy manual sitting in a shared drive that no one reads. It is an operational system: a structured inventory of your regulatory obligations, the filing dates and frequencies, the responsible person for each obligation, and the documentation that proves the obligation was met.

For a company operating in Mexico, that inventory spans federal, state, and sector-specific requirements. The federal layer alone covers tax, labor, social security, environmental, anti-money laundering, and data privacy. Sector-specific layers add COFEPRIS for food and health products, SECTUR for tourism businesses, COFECE for companies with market power, and others. Building the framework means mapping all of these to your specific business activities.

The compliance stack by category

Tax compliance

The foundational tax obligations run through Mexico's Tax Administration Service (Servicio de Administración Tributaria, SAT) using the federal taxpayer ID (Registro Federal de Contribuyentes, RFC). Every commercial transaction must be documented with a CFDI (Comprobante Fiscal Digital por Internet)—Mexico's electronic invoice system. SAT receives copies of every CFDI issued and received, which means it has a real-time view of your declared revenue and deductible expenses.

Key recurring obligations:

Monthly IVA (value-added tax) declarations: Mexico's standard IVA rate is 16% (8% in the northern border region). Monthly IVA filings report VAT collected from clients and VAT paid to suppliers, with the net paid to or refunded from SAT. Filing is due by the 17th of the following month.

Monthly ISR (income tax) provisional payments: The ISR rate for corporations is 30%. Monthly provisional payments are calculated based on cumulative annual income, with the final annual return reconciling the total. Provisional payment filing deadline matches IVA: the 17th of the following month.

Annual ISR return: Due by March 31 of the following year for legal entities (March 30 for certain fiscal years). This is the definitive reconciliation of the year's income, deductions, and tax paid.

IMSS and INFONAVIT payroll taxes: Employer IMSS contributions are due by the 17th of the month following the payroll period (biweekly in most cases). INFONAVIT contributions follow the same schedule. Both are calculated per employee based on their base contribution salary (salario base de cotización, SBC), which includes the base salary plus the proportional value of bonuses, vacation premium, and other regular benefits.

CFDI-nomina (payroll receipts): Every salary payment to an employee must be documented with a CFDI-nomina issued within 24 hours of payment. These electronic payroll receipts are filed with SAT and constitute the official payroll record.

Labor compliance

Labor obligations under the LFT (Ley Federal del Trabajo) are ongoing and frequently inspected by STPS.

Employment contracts: Every employee must have a named employment contract specifying the type of work, working hours, salary, and benefits. Verbal or informal employment arrangements have no protection against an employment claim—and in Mexico, employment claims default to the worker's favor when documentation is absent.

Employee profit sharing (Participación de los Trabajadores en las Utilidades, PTU): Under LFT Article 117, companies must distribute 10% of their annual taxable income to eligible employees. The distribution must happen between April 1 and May 31 of the year following the fiscal year. Employees with fewer than 60 days worked during the year are generally excluded. PTU is calculated at the company level, not the project or division level.

Union considerations: Mexico's labor reform of 2019 introduced genuine union democracy requirements—workers must vote by secret ballot on union contracts, and all existing collective bargaining agreements required re-ratification. Companies that believed they had a compliant collective bargaining agreement without employee awareness now face genuine union activity if workers choose to organize under the new rules.

STPS workplace safety: The Occupational Health and Safety Management System (Sistema de Gestión de Seguridad y Salud en el Trabajo, SGSST) is mandatory for all companies with more than one employee. STPS inspectors can arrive unannounced. The inspection evaluates workplace safety conditions, emergency response plans, equipment maintenance records, and worker training documentation.

Environmental compliance

Not every business triggers environmental obligations, but more do than realize it.

Companies with any of the following activities must obtain environmental authorization from SEMARNAT (Ministry of Environment and Natural Resources; Secretaría de Medio Ambiente y Recursos Naturales) before beginning operations: projects with environmental impact in sensitive zones (coastal, forest, and wetland areas); companies with regulated air emissions; companies that generate or handle hazardous waste; and companies that discharge to water bodies.

Once authorized, ongoing compliance includes:

RETC (Pollutant Release and Transfer Register; Registro de Emisiones y Transferencia de Contaminantes): Companies with regulated emissions must file an annual RETC report with SEMARNAT by March 31, detailing the volume and nature of pollutants released or transferred during the previous year.

PROFEPA inspections: PROFEPA (Federal Environmental Protection Agency; The Procuraduría Federal de Protección al Ambiente conducts announced and unannounced inspections of companies subject to federal environmental jurisdiction. Non-compliance findings can result in fines (up to several million pesos), mandatory remediation plans, and temporary or permanent closure.

For companies in Quintana Roo—where coastal and wetland zones are pervasive—SEMARNAT authorization and PROFEPA compliance are not optional background items. They are core operating requirements that affect permitting for almost any physical operation.

AML compliance

The LFPIORPI (Ley Federal para la Prevención e Identificación de Operaciones con Recursos de Procedencia Ilícita) creates mandatory AML reporting obligations for companies engaged in "vulnerable activities"—a defined list of business activities that the government considers susceptible to money laundering.

The list of vulnerable activities includes:

  • Real estate development and brokerage (sale or lease above certain value thresholds)
  • Construction services for real estate projects above MXN 645,000 in value
  • Legal and accounting services involving certain types of transactions (entity formation, trust management, client funds management)
  • Vehicle sales (new and used, above threshold amounts)
  • Jewelry, precious metals, and art sales
  • Lottery, casino, and gaming operations
  • Financial leasing and factoring above thresholds

Companies engaged in these activities must:

  1. Identify and verify the identity of their clients (KYC procedures)
  2. Keep records of the transactions for five years
  3. File required reports with the UIF when transactions exceed specified cash thresholds (or when the transaction structure appears designed to avoid those thresholds)
  4. Designate a compliance officer responsible for the AML program

The UIF is Mexico's financial intelligence unit, operating within the Ministry of Finance (Secretaría de Hacienda y Crédito Público, SHCP). Failure to register, file required reports, or maintain required records triggers administrative fines and, in serious cases, criminal referral.

Many foreign companies operating in real estate development, hospitality, or professional services in Mexico are covered by LFPIORPI without realizing it. The hospitality sector in Quintana Roo—where hotel transactions regularly exceed threshold values and cash payments are common—is a particularly active area for UIF compliance attention.

Data privacy compliance

Mexico's Federal Law on Protection of Personal Data Held by Private Parties (Ley Federal de Protección de Datos Personales en Posesión de los Particulares, LFPDPPP) applies to any company that collects, stores, or processes personal data of Mexican individuals. The enforcement authority is INAI (Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales).

Core obligations under LFPDPPP:

Aviso de privacidad (privacy notice): Must be provided to individuals at the time their data is collected, specifying what data is collected, the purposes of processing, the legal basis, and how individuals can exercise their ARCO rights.

ARCO rights procedures: Individuals have the right to Access their data, Rectify incorrect data, Cancel (delete) their data, and Oppose its processing. Companies must have documented procedures for handling these requests within the legal timeframes (20 business days for most requests).

Data transfer agreements: If personal data is transferred to a third party or to a foreign entity, the LFPDPPP requires a data transfer agreement (clausulas contractuales) and, in some cases, the individual's prior consent.

Data security measures: Companies must implement appropriate technical and organizational measures to protect personal data from unauthorized access, loss, or disclosure.

INAI fines for LFPDPPP violations range from MXN 100 to 320,000 days of minimum wage (approximately MXN 12,000 to MXN 38.4 million at current rates), depending on the severity of the violation.

Sector-specific compliance

Beyond the general compliance stack, sector-specific agencies add their own layers:

COFEPRIS (Federal Commission for Protection against Health Risks; Comisión Federal para la Protección contra Riesgos Sanitarios): mandatory for food production and processing, restaurant operations, pharmaceutical manufacturing, medical device distribution, alcohol sales, and any business handling regulated health products. Permits must be obtained before operations begin and renewed periodically.

SECTUR (Ministry of Tourism; Secretaría de Turismo): Tourism businesses—hotels, tour operators, travel agencies, marinas, and diving centers—require SECTUR classification and registration. In Quintana Roo, COTELCIQ (the state hotel association) classification standards operate alongside federal SECTUR requirements.

COFECE (Federal Economic Competition Commission; Comisión Federal de Competencia Económica): Companies with significant market share in a relevant market, or those involved in mergers and acquisitions above notification thresholds, must engage with COFECE. Merger notification is required before closing transactions above the statutory thresholds (currently indexed annually to approximately MXN 2.5 billion in combined revenues or transaction value).

Building and running the compliance calendar

The most effective compliance frameworks we have seen share three characteristics:

Single owner per obligation: Not "the company" or "the legal department"—a named individual with a calendar reminder and accountability for the outcome.

Documentation generated in advance: The compliance calendar prompts document creation before the deadline, not after. An IMSS filing due on the 17th should have the SUA calculation completed and reviewed by the 15th.

Regular legal review: Regulations change. The LFPIORPI threshold amounts are indexed to the Unit of Measurement and Adjustment (Unidad de Medida y Actualización, UMA) and adjust annually. CFDI technical formats are updated by SAT periodically. A compliance calendar that was accurate in January may have gaps by June if no one is tracking regulatory updates.

The cost of non-compliance

SAT fines for omitted tax run between 20% and 75% of the omitted amount, plus surcharges of 1.47% per month from the due date. IMSS back contributions carry their own surcharge schedule. PROFEPA violations can force operations to close. INAI data privacy fines can reach tens of millions of pesos. UIF sanctions for AML non-compliance are administrative initially but can escalate to criminal referral.

More practically: a company with unresolved compliance gaps cannot obtain certain government contracts, cannot list on Mexican stock exchanges, and faces complicated due diligence when a buyer or investor looks at the books.

For help building or auditing your compliance framework, contact our team.

Frequently asked questions

PTU (Participación de los Trabajadores en las Utilidades) is the mandatory annual profit-sharing distribution under LFT Article 117. Companies must distribute 10% of their annual taxable income (as determined for ISR purposes) to eligible employees. The distribution is divided into two equal halves: one half distributed equally among all eligible employees based on days worked during the year, and the other half distributed proportionally based on each employee's salary. PTU must be paid between April 1 and May 31.

The LFPIORPI covers businesses engaged in real estate development or brokerage, construction for real estate, vehicle sales, jewelry and precious metals, gaming operations, legal services for entity formation or asset transfers, financial leasing and factoring, and others defined in the law. If your business activity appears on the list, you must register with the SAT as a regulated entity, implement KYC procedures, and file required reports with the UIF when covered transactions exceed statutory thresholds.

IMSS late filings generate automatic surcharges (actualizaciones) calculated from the due date at a rate indexed to inflation plus a fixed factor. The IMSS can also conduct employer audits and assess back contributions for periods where registration or reporting was incomplete. More significantly, workers whose IMSS contributions were not filed on time have gaps in their social security records, which can affect their healthcare coverage and pension contributions. This creates both regulatory exposure and labor relations risk.

Yes. Any food preparation and service operation—including hotel restaurants, bars, beach clubs, and kitchen facilities—requires COFEPRIS authorization. This includes the facility's health permit, approval of the food handling procedures, and periodic inspections. Alcohol service may require additional state-level licensing under the applicable state law. Operating a food service operation without COFEPRIS authorization can result in closure and fines.

COFECE merger notification is required when the transaction involves parties with combined Mexican revenues or assets above the statutory thresholds (currently approximately MXN 2.5 billion in combined value or MXN 848 million in the value of the assets being acquired in Mexico, indexed annually to the UMA). Notification must be filed before closing. Completing a notifiable transaction without COFECE authorization can result in the transaction being declared void and significant administrative fines.

More guidance for your business

Companies expanding their Mexican operations can also review our nearshoring legal guidance for sector-specific structuring and compliance considerations.