NOM-151 Compliance: A Guide for Financial Companies in Mexico
NOM-151 requires financial companies in Mexico to preserve the integrity of their data messages with retention certificates. Who must comply, what the standard demands, and how to prove it without paper.
What is NOM-151 and who does it apply to?
NOM-151-SCFI-2002 (updated 2016) is Mexico's official standard governing the preservation of electronic data messages and document digitization. If your company issues or receives electronic invoices, digital contracts, or any legally binding documents in electronic format, this standard applies.
For financial sector companies — investment funds, brokerage firms, insurers, fintechs, and sofomes — compliance is mandatory. Mexico's CNBV and CONDUSEF expect electronic records to be intact, accessible, and verifiable throughout their legally required retention periods.
The 4 pillars of NOM-151
1. Data message integrity
Every electronic document must remain unaltered from its creation. In practice, this means you need a certified timestamp seal issued by a PSC (Certification Service Provider) authorized by Mexico's Secretaria de Economia.
2. Preservation in original format
Printing a PDF and filing the paper copy doesn't count. The document must be preserved in the electronic medium in which it was generated, sent, or received. If your team downloads XML invoices from Mexico's SAT tax system and converts them to PDF without retaining the original XML, you're non-compliant.
3. Accessibility and availability
Documents must be retrievable throughout the legal retention period. For tax documents, that's a minimum of 5 years. For regulated financial documents, it can be 10 years or more depending on the specific regulation.
4. Traceability to original information
The preservation system must trace each document back to its origin: who created it, when, from where, and what chain of custody it has had.
Where Microsoft 365 fits
If your company uses Microsoft 365 as its work platform (Outlook for email, SharePoint for documents, Teams for communication), your data messages live there. The problem: Microsoft 365's default configuration does not meet NOM-151 requirements.
Common gaps
- Insufficient retention: Microsoft 365 E3 defaults to 90-day retention for deleted mailbox items. If an employee deletes an email containing a contract attachment and 90 days pass, it's gone permanently.
- No certified timestamps: Microsoft doesn't issue preservation certificates with Mexican PSC seals. You need a complementary solution.
- Shared mailboxes without audit trails: If a compliance team shares a mailbox, there's no individual-level record of who accessed which document and when.
- SharePoint without mandatory versioning: Without retention policies, any user can permanently delete documents.
How to configure M365 for compliance
1. Exchange retention policies: Configure 5-10 year retention on compliance-specific mailboxes. Use "litigation hold" or "retention policies" in the Microsoft 365 Compliance Center.
2. SharePoint retention labels: Apply mandatory retention labels to libraries storing financial documents. Block deletion during the regulatory retention period.
3. Unified audit logging: Enable Microsoft 365 advanced auditing to log every access, modification, and deletion event on regulated documents.
4. PSC integration: Integrate a timestamp service from a Mexican-authorized PSC to generate the preservation certificates that NOM-151 requires.
The real risk
Fines for NOM-151 non-compliance may seem modest, but the real exposure is document invalidation. If you can't prove the integrity of your electronic records during litigation or a CNBV regulatory audit, those documents lose their evidentiary value. For a financial company, that can mean losing a lawsuit, failing a regulatory review, or eroding investor confidence.
Quick compliance checklist
- [ ] Retention policies set to 5+ years for financial documents
- [ ] Advanced auditing enabled in Microsoft 365
- [ ] Certified timestamps from an authorized PSC implemented
- [ ] Mandatory versioning on SharePoint for regulated documents
- [ ] Documented data message preservation process
- [ ] Periodic recovery tests on archived documents
First step: know your posture
Before investing in PSC solutions or configuring advanced retention, you need to know where your Microsoft 365 tenant stands today. Our free scan evaluates the 155 Microsoft Graph rules of the 201-rule library — including retention configuration, audit settings, and data policies. The preview typically appears in minutes. The complete report is delivered on a best-effort basis, with a non-guaranteed estimated target of up to 1 hour. The 46 Azure Resource Manager controls require separate admin consent and Reader access.
Is your business protected?
A free Microsoft 365 audit—the automated scan delivers a preview in 90 seconds. Find risks before they become incidents.