Why contingency is non-negotiable
Banxico’s Circular 14/2017 requires every SPEI participant to keep its contingency client (COA) operable and its staff drilled in using it, with documented activation procedures and periodic exercises. The alternate operations procedure (POA) covers corrections, reversals and adjustments, and the alternate system (ASA) applies to the highest-volume participants, roughly 3% or more of system operations. Contingency isn’t a “nice to have”: without it, a regulated institution can’t obtain or keep its participation. And when a primary system fails mid-operation, money movement must continue, customer impact compounds in minutes.
The three modes, in detail
Participant-Level Contingency
Participant-level fallback via batch file processing in tilde-delimited (~) format. Every transaction requires operator approval. Automatic activation when primary connection failure is detected. And something few vendors say out loud: in COA, transfers are not sent or credited in real time. It is degraded by design; its value is that money keeps moving and the evidence stays complete.
Alternate Operations Procedure
System-level alternate operation, used for corrections, reversals, and post-operation settlement adjustments when the primary system is unavailable.
Advanced Alternate System
Full backup system that replicates primary-system functionality. Automatic failover with minimal data loss.
Failover sequence
- Automatic incident detection (heartbeat, protocol timeout, connection error).
- Activation of the configured contingency, COA, POA, or ASA, without manual intervention where applicable.
- Operator validation to confirm the mode and scope of activation.
- Traffic resumes via the alternate channel.
- Primary system restored, catch-up reconciliation for operations processed in contingency.
- Post-incident report generated with timeline, decisions, and affected transactions.
Audit and regulatory reporting
Every activation, every operation processed in contingency, and every operator decision is recorded immutably. We automatically generate the artifacts required by the regulator:
- Contingency start and end timestamps
- Diff of transactions processed in alternate vs. primary mode
- Operator approvals with identity and timestamp
- Post-incident report in the regulator's format
- Evidence ready for regulatory audits
Mandatory annual drills
The regulator requires periodic contingency drills. Without a test environment, drills happen against production, risky and unworkable. Every project includes our multi-bank simulator server and a scripted drill harness, so your institution validates each mode without affecting real traffic.
Compliance checklist
- COA, POA and ASA procedure documentation
- Immutable logs and regulatory archival
- Annual drill records with evidence
- Operations manuals for the on-shift team
- Post-incident reports ready for the regulator
- Recovery plan with documented recovery time objectives and a zero data loss design
Frequently asked questions
What are COA, POA, and ASA?
They are the three contingency modes the central bank requires every SPEI/SPID participant to operate. COA is participant-level fallback via tilde-delimited batch files with operator approval. POA is system-level alternate operation for corrections and reversals. ASA is a full hot-standby backup system with automated failover.
Is contingency a separate system from SPEI or SPID?
No. Contingency is a backup layer that activates when the primary fails. It applies to SPEI, SPID, or both depending on configuration, and covers MXN and USD.
When does contingency activate?
Activation is triggered by failover scenarios, heartbeat loss, protocol timeout, or connection failure, not on demand. The configured mode (COA, POA, or ASA) starts automatically where applicable and the operator confirms scope.
Are contingency drills mandatory?
Yes. The regulator requires periodic contingency drills. Every project includes a multi-bank simulator and a scripted drill harness so your team validates each mode without affecting real traffic.
What recovery objectives can ASA hit?
ASA is designed so no confirmed payment is lost and alternate operation starts within minutes, proven in mandatory drills. It replicates primary-system state continuously and fails over automatically.
See also the guide: SPEI contingency, COA, POA and ASA explained.