Executive answer
A maturity model helps the CFO and board assess whether intercompany operations depend on annual reaction or a governed system. This model uses five levels and eight domains: governance, perimeter, policy, data, execution, monitoring, evidence and controversy/technology. It is not a certification; it prioritizes investment.
The target is not always level five. A small operation may need proportionate controls; a multinational with loans, services, maquila and adjustments requires greater integration. Scores should reflect evidence, risk and capacity rather than perception.
Methodology cutoff: August 2, 2026. Adapt the model to current Mexican law, annual rules, treaties, industry, systems and audits. The assessment does not replace compliance or assurance.
Level 1: reactive
The group identifies transactions at year-end, prepares the study separately and responds when a problem occurs. Owners and data are informal.
Risk: omissions and late evidence.
Level 2: documented
Policies, agreements, calendar and owners exist, but execution remains manual and siloed. Reconciliation is annual.
Risk: documents without conduct.
Level 3: controlled
Processes have RACI, defined data, monthly review, exceptions and evidence. Adjustments are decided before close.
A practical target for many companies.
Level 4: integrated
ERP, tax, treasury, legal and operations share data and controls. Dashboards and workflows connect policy with invoicing and accounting.
Risk: technology dependency.
Level 5: adaptive
The system anticipates change, simulates scenarios, automates under governance and learns from audits. Controls adapt to risk.
It does not mean human-free autonomy.
Domain 1: governance
Assess sponsor, committee, RACI, policies, escalation, decisions and board reporting. Look for minutes and execution.
An organization chart is not governance proof.
Request an assessment to score evidence by domain, define a target level and build a proportionate intercompany-control roadmap.
Domain 2: perimeter
Measure identification of parties, entities, accounts, agreements and transactions. Inventory reconciles to the ledger and systems.
No perimeter means no control.
Domain 3: policy
Review delineation, method, range, adjustments, exceptions and updates. Compare agreements with conduct.
Generic policies score low.
Domain 4: data
Assess master data, sources, lineage, quality, segmentation, calendar and owners. Measure errors.
An uncontrolled critical spreadsheet limits maturity.
Domain 5: execution
Observe prices, orders, invoices, journals, withholding, payments and reconciliation. Test samples.
Policy should reach the transaction.
Domain 6: monitoring
Review KPIs, margins, alerts, forecast, deviations, decisions and true-ups. Confirm frequency and closure.
A dashboard without action is not a control.
Domain 7: evidence
Assess agreements, FAR, deliverables, benefit tests, benchmarks, approvals, receipts and retention. Look for traceability.
More files do not equal better evidence.
Domain 8: controversy and technology
Measure defense files, request protocols, precedents, access, automation, security and continuity.
Technology needs governance.
Scoring scale
Score design and operation separately from zero to five. Design asks whether the control exists; operation whether it works with evidence.
Do not average away a critical absence.
Evidence
Use documents, interviews, samples and walk-throughs. Every score links to proof.
Self-assessment without evidence is preliminary.
Materiality
Weight amount, volume, jurisdiction, complexity, audit and double tax. A large loan may need a higher control level than average.
Targets vary by process.
Inherent risk
Measure before controls: transaction, country, method, data and change. Then assess residual risk.
Prioritize high-residual gaps.
Heat map
Cross domains and entities. Use defined colors rather than decoration. Include exposure and action.
The board needs risk concentration.
RACI
Assign responsible, accountable, consulted and informed roles for inventory, policy, invoicing, adjustment, return and defense.
Avoid two approvers with no owner.
Calendar
Connect monthly, quarterly and annual cycles. Include legal deadlines and internal pre-close dates.
Measure completion.
Preventive controls
Approved masters, agreements before operation, configured prices, monthly evidence and access restrictions prevent error.
Validate design.
Detective controls
Reconciliation, margin analysis, exceptions, duplicates and invoice review find deviations.
Define tolerance.
Corrective controls
Remediation, adjustments, data correction, training and escalation address issues. Record root cause.
Do not repeat exceptions.
Automation
Automate after standardization. Test interfaces, access and rollback. Maintain human review.
PT-099 covers AI.
ERP
Review masters, pricing rules, currencies, centers, eliminations and reporting. Do not assume tax configuration exists.
Document ownership.
Services
Control inventory, benefit, costs, keys, markup, invoices and evidence. Monthly certification improves maturity.
Sample regularly.
Loans
Control capacity, agreement, disbursement, rate, interest, payment, limits and renewal. Alert before maturity.
Reconcile treasury.
Distribution
Monitor sales, costs, expenses, inventory, promotions and margin. Explain losses.
Do not adjust without cause.
Maquila
Control assets, costs, Safe Harbor bases and forecasts. Reconcile monthly.
Do not wait for annual close.
Adjustments
Define type, calculation, approval, invoice, accounting, tax and notice. Rehearse execution.
Avoid late true-ups.
Compliance
Connect the study, DIM appendix, Local File, ISSIF, SIPRED and returns. Use one source of truth.
Document differences.
Audits
Maintain protocol, RACI, index and version control. Rehearse responses.
Measure time.
Maturity KPIs
Track inventoried transactions, current agreements, reconciliations, exceptions, margin, evidence, timely adjustments, filings and repeat findings.
Do not reward document volume.
Roadmap
Prioritize quick wins, foundations, integration and optimization. Every initiative has risk, benefit, owner, cost and date.
Do not attempt level five in a quarter.
First 90 days
Month one covers perimeter and governance. Month two covers policy, data and critical controls. Month three pilots monitoring and evidence.
Report progress.
Budget
Connect initiatives to exposure, hours and avoided cost. Include ongoing operation.
Do not fund a tool without a process.
Board reporting
Present five messages: risk, level, gaps, decisions and roadmap. Include events since the last review.
Avoid excessive detail.
Internal audit
It validates design and operation, samples and tracks remediation while preserving independence.
It does not replace the owner.
Reassessment
Repeat annually and after restructuring, acquisition, ERP, audit or reform. Compare evidence rather than scores alone.
Record trend.
Warning signs
Warnings include unsupported scoring, uniform targets, technology treated as maturity, unexecuted controls, unclear ownership, repeat findings or dashboards without decisions.
Correct the method.
Checklist
Confirm governance, perimeter, policy, data, execution, monitoring, evidence, controversy, technology, risk, design, operation, owner and roadmap.
Approve target levels.
Illustrative example
A group rates itself level four because it has an ERP. Sampling finds services without evidence and late manual adjustments. Technology design is high; operation and evidence are level two. The roadmap prioritizes inventory and monthly close.
The score is corrected.
Intercompany Controls Maturity Assessment product
It includes interviews, evidence, domain scores, heat map, risks, quick wins, roadmap and board report. It distinguishes design and operation.
It is not certification.
Quality assurance
A second reviewer challenges scores, checks samples and tests whether recommendations address root cause. Management accepts residual risk only with an owner and review date.
The final report preserves evidence and scoring rationale for next year’s comparison.
Interview and workshop method
Start with the sponsor and owners from tax, accounting, treasury, legal, operations, technology and internal audit. Use a common guide, but request actual examples: the latest new transaction, close, adjustment and information request. Compare answers across functions. A policy that tax considers current may be unknown to accounts payable.
Then walk a transaction from agreement to return. Select services, a loan and distribution or manufacturing. Identify inputs, decisions, systems, approvals, outputs and evidence. The objective is not a comfortable consensus score; it is to locate failures in design, execution or coordination.
Score calibration
Define observable anchors. Level one depends on individuals and reaction; level two has documents but irregular execution; level three operates evidenced controls; level four integrates processes and data; level five learns from metrics and adapts. One advanced tool cannot raise every domain.
Score design and operation separately. A well-written control can receive four for design and one for operation if no use sample exists. Use the lower score where a critical capability leaves a material entity or process uncovered. Document exceptions so averages do not hide risk.
Evidence sampling
Select entities and transactions for materiality, complexity, change and exposure rather than convenience. Include a close period, an ordinary period and an exception. For every control request owner, frequency, population, sample, result, exception and remediation. Verify the file’s date and origin.
Do not award maturity for isolated screenshots. Seek repetition across cycles and traceability from data to approval. Record limitations where no complete population exists. Internal audit may reproduce part of the sample to challenge selection and conclusion.
Target operating model
Define which decisions remain local, which the group centralizes and which require coordination. Assign owners for policy, data, transaction, monitoring, adjustment, documentation and controversy. Design forums and escalation thresholds. The target reflects size, jurisdictions, volume, ERP and risk; not every company needs level five.
Describe technology after the process. Specify master data, integrations, access controls, reconciliations and logs. Retain a manual contingency. The target model should operate with approved owners, calendar and budget.
Dependency map
Sequence initiatives by prerequisite. Do not automate monitoring without an inventory or fix returns without reconciliation. A common sequence is perimeter, policy, master data, contractual execution, monthly close, adjustments, evidence, returns and analytics. Mark dependencies on ERP, procurement, invoicing and consolidation.
The map prevents promising tool benefits before correcting source data. It also shows which enterprise program can accelerate or block the roadmap. Every dependency receives an owner, date, decision and alternative.
Remediation governance
Turn each priority gap into an action with root cause, risk, deliverable, owner, resources, date, interim control and closure criterion. The committee reviews overdue work and blockers, not just percentages. An action closes when evidence proves design and implementation; drafting a policy is insufficient.
Measure benefits through identified transactions, timely closes, fewer adjustments, passed reconciliations, complete files and rework hours. Record accepted residual risk with approver and review date. At six and twelve months, repeat samples to confirm that improvement persists.
Executive validation
Before the board receives the result, domain owners confirm facts and the sponsor challenges priorities, funding and target levels. The report states limitations, uncovered populations and disagreements. This prevents a precise-looking score from creating false assurance.
The board should approve direction and risk appetite, not every control detail. Management retains the evidence and converts decisions into funded actions with accountable owners.
Conclusion
Intercompany maturity is not measured by study length or purchased software. It is the ability to prevent, detect, correct and demonstrate.
A proportionate model helps the CFO invest where risk and evidence show the greatest need.
Request an Intercompany Controls Maturity Assessment to measure eight domains, define targets and build an executive roadmap.
Verified official sources
- Mexican Chamber of Deputies, current Income Tax Law.
- Mexican Chamber of Deputies, current Federal Tax Code.
- SAT, 2026 tax rules microsite.
- OECD, Transfer Pricing Guidelines 2022.
- NIST, AI Risk Management Framework for AI controls.
Verification closed on August 2, 2026. This is a technical model that should be adapted to the group.