Skip to content
InterPago ▸ SPEI and SPID audit and compliance

SPEI and SPID audit and compliance

What regulators examine at an institution connected to SPEI or SPID, what evidence you must retain, and where findings usually appear.

What does a SPEI or SPID audit review?

A payment audit verifies that your institution can demonstrate, with retained evidence, that every operation followed the scheme's rules and that the controls worked. It does not assess intentions or policy documents: it assesses records. If a control existed but left no trace, as far as the audit is concerned it did not exist.

This applies to internal reviewers and regulatory inspection alike, and to both SPEI and SPID. What differs between the two schemes is not the control framework, but the detail of the validations.

The five areas always examined

01

Per-operation traceability

Reconstructing any payment end to end: instruction, validations applied, signature, transmission, scheme response, receipt and reconciliation, with a time stamp at every step.

02

Access and segregation of duties

Who can initiate, approve and execute. Clear boundaries between development, operations, treasury and compliance, with a history of every permission change.

03

Key and certificate custody

Where private keys live, who touches them, how they rotate and what happened at each rotation. Dual custody must be demonstrable, not merely declared.

04

Contingency testing

Dated evidence that the backup modes were exercised and worked, with each drill result archived and its findings addressed.

05

Regulatory reporting

That reports were filed in the mandatory format and cadence, and that the institution retains the receipt for every submission.

What evidence you must be able to produce

AreaExpected evidenceTypical failure
OperationsImmutable, time-stamped log per transactionScattered records that cannot reconstruct the full cycle
AccessHistory of grants, revocations and permission changesPermissions accumulated across role changes
CryptographyRecord of every certificate and key rotationRotation performed, procedure undocumented
ContingencyDated results of every drillDrill executed with no evidence archived
ReportingCopy of the report plus its submission receiptReport filed without retaining the receipt
ReconciliationTrace of every break and how it was resolvedManual adjustments with no record of who and why

What SPID adds over SPEI

The control framework is shared, but a SPID audit additionally reviews:

  • Validation of RFC (tax registry) and LEI (legal entity identifier) for the legal entities involved in each operation.
  • The reinforced controls that apply to dollar operations.
  • Handling of instructions received outside the operating window, and evidence that they were processed on the next business day.
  • Reconciliation of the dollar balance against the banking core at the close of each session.

For the detail of each scheme, see SPEI integration and what SPID is, or the comparison in difference between SPEI and SPID.

Common mistakes that generate findings

The log cannot reconstruct the operation

Logs exist, but they live in separate systems and share no identifier. The auditor asks for one specific payment and the team spends days assembling the story. Tracing should be a query, not an investigation.

Permissions that accumulate

Someone changes department and keeps their previous access. Over time there are users who can both initiate and approve the same operation, which is precisely what segregation of duties exists to prevent.

Drills without evidence

Contingency was tested, but nobody archived the result. Without the dated record the test does not count, and the finding is raised exactly as if it had never happened.

Reconciliation fixed by hand

Breaks are corrected in spreadsheets outside the system. The balance ties out, but the trail of who adjusted what, and on what justification, is lost.

How InterPago solves it

The platform was designed so that evidence is a by-product of operating rather than a later project. Every inbound and outbound message lands in an immutable log with end-to-end tracing; access, approvals and key rotations are recorded automatically; regulatory reports are generated in the official format and cadence; and contingency drills run against our own simulator, producing results ready to archive.

When the inspection arrives, the question stops being whether the evidence can be assembled and becomes which date you want to query from.

Frequently asked questions

What does a SPEI or SPID audit review?

A payment audit reviews five areas: end-to-end traceability of every operation, access controls and segregation of duties, custody of cryptographic keys and certificates, evidence of contingency testing, and the timeliness and accuracy of regulatory reports. Evidence is the common thread: it is not enough for a control to exist, you have to be able to demonstrate it.

What evidence must an institution connected to SPEI retain?

Immutable, time-stamped logs of every operation, the history of operator access and approvals, records of every certificate and key rotation, dated results of contingency drills, and copies of regulatory reports along with their submission receipts. Retention must meet the periods set by the regulator.

How does auditing SPID differ from auditing SPEI?

The control framework is the same, but SPID adds the reinforced compliance validations that apply to dollar operations, including verification of RFC (tax registry) and LEI (legal entity identifier) for the legal entities involved. A SPID audit also reviews the operating window cutoff and how instructions received outside that window were handled.

What are the most common findings?

The most frequent are logs that cannot reconstruct a complete operation, users whose permissions accumulated across role changes, certificates rotated without a record of the procedure, contingency drills that were run but never evidenced, and reconciliation breaks resolved manually with no trace of who adjusted what and why.

Can audit evidence be prepared automatically?

Yes, if the platform was designed for it. When immutable traces, access records, and reports are produced as part of normal processing, preparing for an audit stops being a project and becomes a query. That is InterPago's approach: evidence is a by-product of operating, not a later effort.

See also the contingency modes, SPEI connection requirements or request a free assessment.

Ready to modernize your payment operations?

Whether you're starting from scratch or modernizing a legacy system, we'll help you get there, securely, on schedule, and with no obligation until you're ready.

sales@interpago.com.mx Raise a Ticket
Request a Demo