Custody, Not Compliance:
What Mexico’s e.firma Change
Actually Signals
On July 17, 2026, a seemingly technical change took effect in Mexico. What it actually tests is whether a Canadian parent company can identify who can act for its Mexican subsidiary today, under what authority, and prove it with evidence.
Under IMSS Agreement ACDO.AS2.HCT.290626/176.P.DIR, the SAT-issued e.firma became the exclusive digital certificate for electronic acts before the Mexican Social Security Institute. The former NPIE credential is being eliminated, and the linkage of legal representatives must now be completed exclusively through IMSS’s Escritorio Virtual. The Agreement provides a 90-calendar-day transition period from its publication on July 16, after which the legacy mechanism disappears.
Mexican payroll, HR and legal teams will understandably treat this as a compliance implementation issue: is the e.firma current, has the representative been linked, will the company still be able to file electronically with IMSS. Those questions matter. But for a Canadian parent company, General Counsel or Board, they are only the first layer.
The more consequential question is who can exercise corporate authority through the credential, under what legal authority, subject to what controls, and whether the parent company can prove the answer. That is a governance question, and the new IMSS rule makes it harder to ignore.
The Architecture Matters
The e.firma framework is more complex than a username and password. A Mexican company has its own e.firma. The individual acting as its legal representative must also have a valid personal e.firma. For the initial issuance of a corporate e.firma, SAT requires the legal representative to establish the company’s existence and their authority, generally through corporate and notarial documentation, and the representative must already be registered with the RFC and hold a valid personal e.firma.
The new IMSS rule adds another layer. When a company authorizes a legal representative, administrator or similarly designated person to act on its behalf, the linkage must be made through Escritorio Virtual. The representative authenticates with their own e.firma, and the linkage is signed jointly by the representative and the represented company using their respective e.firmas.
That creates what can be described as an authority stack: corporate authority, notarial power, corporate e.firma, representative’s personal e.firma, digital platform linkage. Together, these form the practical ability to act for the company. Each element may be perfectly valid on its own. The governance risk appears in the relationship between them.
A power of attorney may have been granted years ago using broad language because broad powers were operationally convenient, at a time when exercising them required physical documents, notarial intervention and local coordination. Digital government has progressively removed much of that friction. The legal authority may be unchanged. The execution environment is not. The appropriate governance question is therefore not merely whether the power of attorney is still valid, but whether the organization would grant this same person this same authority today, knowing how easily it can now be exercised electronically.
Five Dimensions of e.firma Governance Exposure
Structure. Foreign-owned Mexican subsidiaries frequently accumulate powers of attorney over time as country managers, finance directors, external accountants and local lawyers rotate. Powers do not always disappear when operational responsibilities do. What matters is who should retain authority, not merely who currently needs access.
Authority. The power presented to SAT or maintained in corporate records may contain authority considerably broader than what IMSS filings require. A job title is not an authority matrix, and an organizational chart is not a power of attorney. If someone informally “only handles payroll,” the notarial instrument behind them may still authorize substantially more.
Custody. Once authority becomes digitally executable, credential governance becomes part of corporate governance: who controls or has access to the private-key credentials, where backups are stored, and whether Canadian management can revoke access quickly if necessary. SAT itself describes e.firma as having the legal validity of an autograph signature. It should not be treated as an ordinary system password.
Responsibility. A subsidiary can be fully compliant with the technical requirements of a government platform and still have weak internal controls over who is authorized to bind it. If a Canadian parent cannot identify who holds material authority in Mexico, the failure is no longer “we missed an IMSS requirement” — it becomes “we did not know who could act for our subsidiary, under what authority, or through which digital instruments.”
Evidence. What matters is whether the organization can produce the answer on request, not whether someone in Mexico happens to know it. A mature authority-control file identifies, at minimum: who holds powers of attorney and under what instrument, the precise scope of each, which individuals are currently linked in government systems, who controls the e.firma credentials, when each was last reviewed, and the process for revocation and escalation. An undocumented control and a nonexistent one are difficult to distinguish after an incident occurs.
Where This Lands on a Binational Risk Scale
The regulation is the trigger, not the risk itself. A binational assessment examines Mexico impact (what could occur operationally or legally if authority is misused or cannot be revoked quickly), Canada impact (what it means for board visibility and management’s ability to demonstrate supervision), likelihood (how probable it is that powers and credential custody have evolved without consolidated review), and control strength (whether the organization would detect a mismatch before an act occurs, or only after).
In an organization where powers are current, credentials are centrally controlled and Canadian management can produce the evidence, the exposure may sit at a moderate level. Change the facts: a broad legacy power, no recent review, credentials controlled locally by one person, no consolidated register, no Canadian record of who can currently act. The rating moves quickly toward the top of the scale, as reflected in the panel above.
If the answer to the third question is no, the organization most likely lacks reliable visibility over its own delegated authority, regardless of whether any specific act was unauthorized. That is the risk signal the July 2026 IMSS change makes easier to see — not one it created.
A structural review of whether your organization can demonstrate, with evidence, who holds authority to act for your Mexican subsidiary, how that authority is exercised, and who controls the instruments that make it possible.
Governance Exposure DiagnosticPlease do not include confidential or time-sensitive information at this stage. No attorney–client relationship is created by this request.
This article refers to Acuerdo ACDO.AS2.HCT.290626/176.P.DIR of the Mexican Social Security Institute (IMSS), published in the Diario Oficial de la Federación on July 16, 2026, establishing the SAT-issued e.firma as the exclusive digital certificate for electronic acts before IMSS and the linkage of legal representatives through the Escritorio Virtual, with a 90-calendar-day transition period from publication.
Jorge Gutierrez is a Foreign Legal Consultant in Mexican Law registered with the Barreau du Québec, based in Sherbrooke, Québec. He advises Canadian companies on Mexican-law governance, regulatory and fiduciary-control questions across the Canada–Mexico corridor. Canadian legal, tax and financial matters are addressed by the client’s own Canadian advisors.




