Custody, not Compliance

Custody, Not Compliance: What Mexico’s e.firma Change Actually Signals | Symbiosis Effect
Canada–Mexico Corridor / Mexican Corporate Law / Cross-Border Governance
Risk thermometer with the indicator between Very High and Critical, labelled Very High–Critical Risk, for an unmanaged e.firma authority stack
Exposure-Based Rating (EBR)

Illustrative inherent exposure where e.firma custody and linked authority have not been consolidated or reviewed since the underlying powers were granted.

Assessment basis

This reflects the exposure of an unmanaged e.firma authority stack, not a finding about any specific company. It assumes a legacy power of attorney with broad scope, no consolidated register of digitally-linked representatives, and no recent review of who currently controls corporate e.firma credentials. Once authority scope, credential custody and platform linkages are consolidated, reviewed and documented, the exposure may be materially reduced toward a managed level. Residual risk still depends on the organization’s actual structure and controls.

Custody, Not Compliance:
What Mexico’s e.firma Change
Actually Signals

On July 17, 2026, a seemingly technical change took effect in Mexico. What it actually tests is whether a Canadian parent company can identify who can act for its Mexican subsidiary today, under what authority, and prove it with evidence.


Under IMSS Agreement ACDO.AS2.HCT.290626/176.P.DIR, the SAT-issued e.firma became the exclusive digital certificate for electronic acts before the Mexican Social Security Institute. The former NPIE credential is being eliminated, and the linkage of legal representatives must now be completed exclusively through IMSS’s Escritorio Virtual. The Agreement provides a 90-calendar-day transition period from its publication on July 16, after which the legacy mechanism disappears.

Mexican payroll, HR and legal teams will understandably treat this as a compliance implementation issue: is the e.firma current, has the representative been linked, will the company still be able to file electronically with IMSS. Those questions matter. But for a Canadian parent company, General Counsel or Board, they are only the first layer.

The more consequential question is who can exercise corporate authority through the credential, under what legal authority, subject to what controls, and whether the parent company can prove the answer. That is a governance question, and the new IMSS rule makes it harder to ignore.

The Architecture Matters

The e.firma framework is more complex than a username and password. A Mexican company has its own e.firma. The individual acting as its legal representative must also have a valid personal e.firma. For the initial issuance of a corporate e.firma, SAT requires the legal representative to establish the company’s existence and their authority, generally through corporate and notarial documentation, and the representative must already be registered with the RFC and hold a valid personal e.firma.

The new IMSS rule adds another layer. When a company authorizes a legal representative, administrator or similarly designated person to act on its behalf, the linkage must be made through Escritorio Virtual. The representative authenticates with their own e.firma, and the linkage is signed jointly by the representative and the represented company using their respective e.firmas.

That creates what can be described as an authority stack: corporate authority, notarial power, corporate e.firma, representative’s personal e.firma, digital platform linkage. Together, these form the practical ability to act for the company. Each element may be perfectly valid on its own. The governance risk appears in the relationship between them.

Legal authority defines what a person is entitled to do. Digital authority determines what that person may be practically capable of doing without returning to the parent company each time.

A power of attorney may have been granted years ago using broad language because broad powers were operationally convenient, at a time when exercising them required physical documents, notarial intervention and local coordination. Digital government has progressively removed much of that friction. The legal authority may be unchanged. The execution environment is not. The appropriate governance question is therefore not merely whether the power of attorney is still valid, but whether the organization would grant this same person this same authority today, knowing how easily it can now be exercised electronically.

Five Dimensions of e.firma Governance Exposure

Structure. Foreign-owned Mexican subsidiaries frequently accumulate powers of attorney over time as country managers, finance directors, external accountants and local lawyers rotate. Powers do not always disappear when operational responsibilities do. What matters is who should retain authority, not merely who currently needs access.

Authority. The power presented to SAT or maintained in corporate records may contain authority considerably broader than what IMSS filings require. A job title is not an authority matrix, and an organizational chart is not a power of attorney. If someone informally “only handles payroll,” the notarial instrument behind them may still authorize substantially more.

Custody. Once authority becomes digitally executable, credential governance becomes part of corporate governance: who controls or has access to the private-key credentials, where backups are stored, and whether Canadian management can revoke access quickly if necessary. SAT itself describes e.firma as having the legal validity of an autograph signature. It should not be treated as an ordinary system password.

Responsibility. A subsidiary can be fully compliant with the technical requirements of a government platform and still have weak internal controls over who is authorized to bind it. If a Canadian parent cannot identify who holds material authority in Mexico, the failure is no longer “we missed an IMSS requirement” — it becomes “we did not know who could act for our subsidiary, under what authority, or through which digital instruments.”

Evidence. What matters is whether the organization can produce the answer on request, not whether someone in Mexico happens to know it. A mature authority-control file identifies, at minimum: who holds powers of attorney and under what instrument, the precise scope of each, which individuals are currently linked in government systems, who controls the e.firma credentials, when each was last reviewed, and the process for revocation and escalation. An undocumented control and a nonexistent one are difficult to distinguish after an incident occurs.

Where This Lands on a Binational Risk Scale

The regulation is the trigger, not the risk itself. A binational assessment examines Mexico impact (what could occur operationally or legally if authority is misused or cannot be revoked quickly), Canada impact (what it means for board visibility and management’s ability to demonstrate supervision), likelihood (how probable it is that powers and credential custody have evolved without consolidated review), and control strength (whether the organization would detect a mismatch before an act occurs, or only after).

In an organization where powers are current, credentials are centrally controlled and Canadian management can produce the evidence, the exposure may sit at a moderate level. Change the facts: a broad legacy power, no recent review, credentials controlled locally by one person, no consolidated register, no Canadian record of who can currently act. The rating moves quickly toward the top of the scale, as reflected in the panel above.

Who in your organization can currently act electronically on behalf of the Mexican company? What legal authority supports that access, and does it still match what the organization intends? Can the Canadian parent produce that answer today, with documentary evidence, not after calling Mexico, not after asking the accountant, not after requesting copies from the notary?

If the answer to the third question is no, the organization most likely lacks reliable visibility over its own delegated authority, regardless of whether any specific act was unauthorized. That is the risk signal the July 2026 IMSS change makes easier to see — not one it created.

What looks like a credential migration is, underneath, an authority-governance event.
Canada–Mexico Governance Exposure Diagnostic

A structural review of whether your organization can demonstrate, with evidence, who holds authority to act for your Mexican subsidiary, how that authority is exercised, and who controls the instruments that make it possible.

Governance Exposure Diagnostic

Please do not include confidential or time-sensitive information at this stage. No attorney–client relationship is created by this request.

Regulatory framework referenced

This article refers to Acuerdo ACDO.AS2.HCT.290626/176.P.DIR of the Mexican Social Security Institute (IMSS), published in the Diario Oficial de la Federación on July 16, 2026, establishing the SAT-issued e.firma as the exclusive digital certificate for electronic acts before IMSS and the linkage of legal representatives through the Escritorio Virtual, with a 90-calendar-day transition period from publication.

About Mexican-Law Counsel

Jorge Gutierrez is a Foreign Legal Consultant in Mexican Law registered with the Barreau du Québec, based in Sherbrooke, Québec. He advises Canadian companies on Mexican-law governance, regulatory and fiduciary-control questions across the Canada–Mexico corridor. Canadian legal, tax and financial matters are addressed by the client’s own Canadian advisors.

Legal notice. This article provides general information and does not constitute legal advice. The e.firma and IMSS linkage requirements described are governed by the specific facts, corporate structure and instruments of each organization. Independent advice should be obtained before relying on this information.
Categories: