Onboarding a Mexican company takes seven documents: the certificate of tax status, the incorporation deed, the representative’s power of attorney, their voter ID card, a proof of address, the company’s e.firma and an email address somebody answers. None of them is exotic. They all arrive by email, as PDFs, often scanned.

And that is where the real work starts, and it is not reading them.

Verifying each document does not verify the company

A file can hold all seven documents, every one of them authentic, and still be wrong. The deed states one legal name; the tax certificate states a slightly different one because the company was renamed after incorporation. The power names an attorney; the ID card they sent belongs to someone else on the team. The e.firma about to sign belongs to a tax ID that is not the company being onboarded.

Each document, on its own, passes. The file, taken together, does not add up.

That comparison is the part a person does today, with seven PDFs open in tabs and a spreadsheet on the side. It is slow, it leaves no record, and it depends on who ran it that day.

The seven documents and what each one proves

They are worth separating by what they contribute, because they do not contribute the same thing:

  • Certificate of tax status. Proves the taxpayer exists at the SAT and where it stands today: active, suspended or cancelled. It is the one document in the file with a public registry to be checked against.
  • Incorporation deed. Proves who the company is and, above all, who controls it: shareholders with their stake, directors, attorneys-in-fact and their faculties, and the entry in the commercial registry.
  • Power of attorney. Proves who can sign for the company, with which faculties and until when.
  • Representative’s voter ID. Proves the attorney is a real person, current on the INE electoral roll.
  • Proof of address. Proves where it operates, and when the bill was issued.
  • e.firma. Proves the company can sign electronically today, not in the abstract: a certificate is revoked or expires without notice.
  • Verified email. Proves there is a live mailbox on the other side, and what kind of domain it is.

Each one is read and checked against its source where it has one. The certificate against the SAT registry. The card against the electoral roll. The CFDI on the bill against the SAT validator. All of that can already be done by API, document by document.

What none of them answers alone is the question that decides the onboarding.

Beneficial ownership does not come from a form

Identifying the beneficial owner is an obligation of the company doing the onboarding, not of the customer being onboarded. Asking the customer to type their controller’s name into a field turns a verification duty into a declaration: whoever signs it is the same person with a reason not to fill it in properly.

The data is already in the deed. It is in the shareholder table: each holder with their stake, or with the contribution that stake is computed from. Extracting that table, ordering it and flagging whoever reaches 25 per cent is a calculation, not a question.

With one nuance that matters: when a holder’s stake cannot be computed —the deed declares incomplete contributions, or the page is illegible— the result stays blank and does not count as a controller. Not having measured is not the same as having measured zero. A file that conflates the two reports as clean exactly what it could not see.

The twenty-six cross-checks

Once the seven documents have been read, the cross-check is mechanical. Twenty-six comparisons: sixteen between documents (or against their source) and ten that read what each document already said about itself:

  • The legal name on the deed against the one on the certificate, and the tax ID on each.
  • The corporate purpose in the deed against the economic activities registered with the SAT.
  • The taxpayer active, off the padrones the SAT publishes, and the data printed on the certificate against the record the SAT returns.
  • The grantor of the power against the company’s legal name.
  • The attorney on the power against the name on the ID card, and against the attorneys the deed names.
  • The card current on the electoral roll, and its image legible (no crop, blur or black and white).
  • The holder of the bill against the legal name, the issue date against the customary 90 days, and the bill’s postal code against the tax domicile on the certificate.
  • The tax ID on the e.firma against the one on the certificate, and an active certificate with more than 15 days ahead of it.
  • The verified email and its domain.
  • Each document’s own checklist and authenticity verdict (certificate, deed, power, bill); the ID card against RENAPO; and the most recently issued e.firma being active.

Each comparison returns one of three states, and the third is what makes the file useful: agrees, contradicts or not evaluable yet. That last one is not a tie: it means the document is missing or the source has not answered. A file that reported it as passed would let onboardings through on documents that never arrived.

That is why an empty file does not come back approved. It comes back under review: passing takes evidence, not an absence of contradictions.

What changes in the operation

Without the cross-check, the team reviews every file the same way, because there is no way to tell which one has a problem until it is opened. With it, the work reorders itself: files where all twenty-six checks agree move on their own, and attention goes to the ones that contradict —with the failing check and the document it came from already named.

And a trail is left. Every check stores its date, its result and the file it was read from. Six months later, “why did we approve this company?” has an answer that does not depend on anyone’s memory.

What is out of scope

Two things, and they are better said before an audit finds them.

First: the revocation of a power of attorney is not detected. A revoked power looks exactly like a live one; only the registry of the notary who granted it knows. The file reads the validity stated in the instrument, and when there is no end date it reports it as open-ended, never as expired.

Second: the decision is not ours. The file hands over the cross-checks, the evidence behind each one, the representative who can sign and the controlling owners. What happens to a file under review is set by each company’s own manual.

What to do now

If onboarding a company in your operation ends with someone comparing seven PDFs by hand, that comparison can now be requested by API: the documents go in one at a time and the file comes out with all twenty-six cross-checks resolved.

Upload a deed and a tax certificate and see what the cross-check returns. In the test environment it costs no balance.

See the KYB dossier for companies