Executive answer
A “SaaS” charge can contain remote application access, copying, modification, distribution, hosting, cloud capacity, implementation, support, maintenance, data and third-party purchases. Each component may have different functions, risks, base, method and tax treatment. The product or contract name does not decide.
First delineate what Mexico receives and may do. Then identify who provides, owns rights, contracts vendors, controls architecture and assumes risks. Only then determine whether there is a license, service, resale, reimbursement, cost contribution or other transaction and assess arm’s length, deduction, withholding, VAT, invoicing and reporting.
There is no universal software answer. Classification depends on Mexican law, the applicable treaty, contractual rights and conduct. A mark-up benchmark does not replace a legal and tax memo; withholding analysis does not replace pricing.
Component inventory
| Component | Question | Evidence | Possible analysis |
|---|---|---|---|
| SaaS access | Is functionality only remote? | users, terms, logs | access/service based on facts |
| Copy | May it reproduce locally? | license, installation | software rights |
| Modification | May it alter code? | repository, permissions | license/development |
| Distribution | May it sublicense or sell? | agreement, customers | exploitation right |
| Hosting | Who supplies infrastructure? | architecture, consumption | service/capacity |
| Support | Which level and staff? | tickets, SLA | service |
| Implementation | Is it a specific project? | SOW, milestones | service/project |
| Data | Who accesses and exploits? | rights, flows | asset/service based on facts |
| Third party | Who buys and controls? | invoice, agreement | resale/pass-through |
| Development | Who creates enhancements? | code, roadmap | DEMPE/service/intangible |
The last column is not a tax conclusion. It identifies issues requiring analysis.
Characterization tree
- Does Mexico obtain software rights or only functionality?
- May it copy, modify, distribute, sublicense or commercially exploit?
- Does the provider retain code, infrastructure and control?
- Are implementation, support or maintenance separable?
- Does the related party add value to a third-party license?
- Does it assume obligation, risk and control toward the vendor?
- Is cost passed through without change or function?
- Is there development or enhancement for Mexico or the group?
- Who owns enhancements and controls risks?
- Do agreement, invoice and architecture agree?
- Which law and treaty apply to the payment?
- Do components require separate prices and withholding?
Document every answer. “No code is delivered” is relevant but does not settle all treatment.
Access versus rights
In a typical SaaS model, a user accesses provider-hosted functions without rights to reproduce or exploit code. Corporate arrangements may nonetheless grant installation, APIs, customization, backup copies, development or sublicensing. Read schedules and conduct.
Define users, territory, devices, volume, storage and restrictions. A per-company fee may include available capacity; per-user fees depend on population. Reconcile active, not merely purchased, licenses.
If Mexico distributes the product to customers, analyze whether it is reseller, agent, licensee or provider. Rights and risks affect method and margin.
Separable services
Implementation may include configuration, migration, integration, testing and training. Support may mean help desk, maintenance, availability or development. Decide whether each can be separately purchased and has independent value.
Separation need not mean separate invoices. A bundled agreement may include a schedule allowing pricing and analysis by component. Avoid arbitrary allocations; use rates, hours, cost, comparables or relative value based on facts.
Document deliverables, people, tickets, levels and acceptance. A generic “support” fee without evidence may face substance questions.
Third-party licenses and reimbursements
A parent may negotiate global licenses and allocate cost. Determine whether it is purchasing agent, reseller or integrated provider. Does it choose the solution, negotiate, administer users, guarantee service, bear credit or integrate tools? Functions may deserve remuneration.
An exact invoice pass-through is not automatically neutral reimbursement. Benefit, allocation and recipient connection are needed. Check who is contractual party and entitled to use. A recipient absent from the license may lack authorization.
Separate pass-through costs from own services. If the center adds support, charge and document separately or through a transparent base. Avoid marking up taxes or no-value-added items without analysis.
Development and enhancements
Where Mexican teams configure or develop modules, map DEMPE: roadmap, code control, funding, testing, protection and exploitation. A customization may belong to customer, vendor or group based on agreement and facts.
Cost plus may remunerate routine development controlled elsewhere. Unique contributions or risk control may require another approach. Do not automatically label programmers routine.
Review open-source and third-party restrictions. Preserve repositories, tickets, decisions and employee/vendor assignments.
If one invoice bundles licenses, cloud, support and development, map the components before applying one mark-up or withholding rate.
Base and allocation keys
For global licenses, users, consumption, capacity, transactions or devices may serve as keys. The key should approximate benefit. Revenue rarely measures technology use alone. Identify reserved capacity even when unused.
Reconcile vendor invoice to pool, cleaning, key and charge. Remove entities without access and include actual beneficiaries. Control inactive licenses and overbuying. Document currency and true-up.
For infrastructure, measure storage, compute, traffic or instances. For support, weighted tickets or users. Do not mix drivers without cost segmentation.
Arm’s-length price
Direct comparables may exist in lists or third-party agreements, but compare volume, territory, rights, service levels and bundles. Enterprise discounts and minimum commitments matter. Public prices rarely include every condition.
Cost plus may fit own services where functions and comparables support it. Resale analysis may fit distribution. Unique intangibles may need another method. Record rejected alternatives.
Prevent double mark-ups in regional chains. Follow cost and value added by entity. A purchasing hub and an integrator may deserve different returns.
Withholding, treaty and VAT
Classify each payment under applicable rights and rules. Determine whether Mexican law and treaty treat the component as royalty, business profit, service or another category. Check residence, conditions and documentation. Do not borrow a rate from another product.
Digital payments may have distinct VAT and invoice consequences. Coordinate date, exchange, withholding, credit, import of services and remittance where relevant. This article does not replace legal analysis of the specific agreement.
If components differ, allocate consideration defensibly and document. Do not split artificially to reduce tax or aggregate merely for convenience.
Agreement and architecture
Legal and technology should review together. The agreement may say “cloud” while architecture shows local installation, or “license” while there is web access only. Diagram users, data, code, servers, vendors and flows.
Include rights, levels, security, privacy, continuity, enhancements, termination, data portability, audit, taxes and pricing. Identify responsibility for failure. Conduct should align.
Review end-vendor schedules and sublicense chain. The intercompany agreement cannot grant more than the related party owns.
Recommended file
- Component catalogue.
- Architecture and flow diagram.
- Vendor and intercompany agreements.
- Rights and restrictions.
- Users, consumption and benefit.
- Services and evidence.
- Development, DEMPE and ownership.
- Cost pool and keys.
- Method and comparables.
- Tax and treaty characterization.
- VAT, invoices and payment.
- Reconciliation and returns.
Risk signals
- One “IT services” description for everything.
- Agreement conflicts with architecture.
- Mexico pays for nonexistent users.
- Reimbursement without usage rights.
- Mark-up on the entire vendor invoice.
- Local development without assignment or pay.
- One tax rate for different components.
- Data without rights or controls.
- Chains with mark-up on mark-up.
- Invoice, calculation and ledger differ.
Illustration
The parent buys a global ERP, operates cloud and provides help desk. Mexico receives 300 users, implementation and support. Open the charge into third-party license, infrastructure, project and internal service. Users may allocate license; consumption, cloud; hours/milestones, implementation; tickets, support.
The parent negotiates and administers, so not everything is reimbursement. Its mark-up does not automatically apply to license cost. The agreement must authorize use, and tax analysis must characterize components. A schedule reconciles all to one invoice.
The outcome is operational and defensible: payment may remain consolidated while construction is transparent.
Governance
Technology maintains architecture, users and consumption; procurement keeps contracts; legal reviews rights and data; tax assesses withholding and VAT; transfer pricing reviews method; accounting reconciles. A committee approves tools and changes.
Review on renewal, cloud migration, module addition, vendor change, code development or user expansion. Policy should prevent shadow IT and charges without beneficiaries.
Monitor budget, use and margin quarterly. Year-end should not be the first reconciliation.
Security, continuity and data
Digital infrastructure also allocates risks. Identify who chooses controls, responds to incidents, purchases insurance, maintains backups and activates recovery. A center merely executing instructions may not control risk; one designing architecture and accepting outage consequences may add more value.
Document location, access, encryption, portability and deletion of data. Determine who may use analytics and derived models. These facts can affect price, agreement and regulation, although they do not automatically turn data into a separable intangible.
Service levels need measurement and consequences. Compare promised and actual availability, incidents and credits. If Mexico accepts a lower level or requires dedicated capacity, comparables should reflect it.
Digital invoice reconciliation
Prepare a schedule by component, vendor, currency, period, base, key, mark-up, tax and recipient. Trace the final invoice to agreement and original cost. Explain reservations, enterprise discounts, credits, abandoned licenses and true-ups.
Check accounting classification and ensure capitalized assets are not also charged as current expense. Coordinate accounts payable and fixed assets. One payment can cover several periods; allocate it correctly.
Compare procurement savings with service-center remuneration. A negotiated discount belongs in the pool unless the agreement and functions support another treatment. Do not let manual spreadsheet adjustments break the chain.
Implementation controls
During onboarding, record approved business case, expected users, project plan and acceptance. At go-live, reconcile actual licenses, integrations and support. After three months, remove inactive users and investigate unexpected consumption. At year-end, true up using controlled data.
For offboarding, preserve access termination, data return, license credits and residual obligations. Determine whether custom code remains usable and who owns it. A forgotten subscription can continue charging entities that receive no benefit.
Questions before approval
- Which functionality and rights does Mexico receive?
- Which services are separable?
- Who controls the vendor and architecture?
- Does the invoicing entity add value?
- Does every user or consumption item exist?
- Does the key reflect benefit?
- Does the mark-up apply to this base?
- Which tax treatment applies by component?
- Do agreement and architecture agree?
- Does the amount reconcile to accounting and payment?
- Are withholding and VAT supported separately?
- Which change triggers recharacterization?
Answers should link evidence and an owner. If the existing agreement cannot distinguish components, add a prospective schedule without fabricating history.
Audit response map
An efficient file answers four paths. Legal path: rights and chain. Technical path: architecture, access and service levels. Economic path: costs, keys, functions and method. Tax path: classification, withholding, VAT and reporting. Index documents once and cross-reference them rather than creating inconsistent copies.
Test one sample payment end to end. Start with bank and invoice, recalculate allocation, trace vendor cost, confirm user access, inspect the agreement and reproduce tax treatment. Expand sampling where deviations appear. This practical walk-through often identifies broken links that a high-level policy misses.
Sources and cutoff
This article was verified as of August 2, 2026. Consult current Mexican Income Tax Law, the SAT treaties and transfer pricing portal, the OECD Guidelines 2022 and the OECD country profile for Mexico. Verify the specific treaty and agreement.
Zugzwang’s Digital Charge Review separates rights, access, infrastructure, support, development and reimbursements to align pricing, withholding, agreements and records.