Is an ethics hotline mandatory in Mexico? Yes — but not just any mechanism complies with the law

NOM-035 requires a secure and confidential mechanism for receiving reports. Learn what that really means and why many internal channels fall short.

Equipo revisando un caso de cumplimiento

If you’re considering an ethics hotline for your company, you’ve probably already run into contradictory information. Some articles talk about European laws that require one, others mention multimillion-dollar fines, and it isn’t always clear how much of that actually applies in Mexico.

There’s a reason for the confusion: much of the Spanish-language content on this topic is written with Spain’s or the European Union’s regulations in mind, and those differ from Mexico’s. Here we answer specifically for Mexico, with the standard that does apply — and with a nuance almost nobody explains well.

The short answer

Yes. NOM-035 requires workplaces in Mexico to have secure and confidential mechanisms for receiving reports of workplace violence and of practices that undermine a favorable organizational environment.

The part almost nobody explains is that the obligation isn’t just to have “something” — it’s that this something meets both conditions at the same time. A physical suggestion box, an inbox shared by several people in HR, or “report it to your manager” may technically exist, but they rarely guarantee real security and confidentiality.

A figure few Mexican companies stop to consider

According to a KPMG study on financial crime in Mexico, 7 out of 10 companies in the country have been victims of internal fraud, at an average cost of more than 1.4 million pesos per incident. And according to the ACFE’s Report to the Nations (global data), 43% of occupational fraud cases are detected through tips — the most effective detection source, ahead of internal audits and management reviews.

Without a mechanism people actually use, much of that information never arrives. And as we’ll see, “having a hotline” and “having a hotline people use” aren’t always the same thing.

What NOM-035 actually says about reporting mechanisms

What the standard requires

NOM-035-STPS-2018, published by Mexico’s Ministry of Labor and Social Welfare (STPS) in the Official Gazette of the Federation on October 23, 2018, aims to identify, analyze, and prevent psychosocial risk factors in the workplace. Among its provisions, it establishes that workplaces must have secure and confidential mechanisms for receiving reports of practices contrary to a favorable organizational environment and of acts of workplace violence.

What “secure and confidential” really means (and why many internal channels fall short)

This is where most companies get a surprise when they review what they already have. In practice, a genuinely secure and confidential mechanism should guarantee:

  • That coworkers or managers can’t work out who reported during the company’s normal process
  • That access to the information is limited to those who actually need to handle it, not open to the whole HR team
  • That there is a documented chain of custody, not an informal channel with no record
  • That the person reporting has real assurance there will be no retaliation, not just a verbal promise

A physical box in the office can be seen by anyone walking by. A shared inbox can be read by several people on the team, even without bad intent. Neither is necessarily illegal on its own, but both make it hard to show — to an inspector or to your own employees — that the mechanism is truly secure and confidential, not merely that it exists.

Who it applies to

The standard applies to every workplace in Mexico, regardless of size. What varies with headcount is the scope of other specific obligations (such as administering diagnostic questionnaires), but the obligation to have a mechanism for receiving workplace violence complaints applies across the board.

This specific obligation is the legal minimum. Many companies extend the same mechanism to also cover fraud, corruption, and other misconduct, even though the law doesn’t require it in the same way there.

The risks of not having a mechanism that truly complies

Not having a genuinely secure and confidential mechanism — even if “something” exists on paper — carries real risks: cases that go straight to social media before the company hears about them, employees who stop trusting the reporting process because they sense there’s no real confidentiality, and exposure in an STPS inspection if what exists doesn’t meet the standard the regulation requires.

Signs you’re exposed, even if your current mechanism “exists on paper”

  • Your current mechanism depends on a single person or a shared inbox in HR
  • You have more than 50–100 employees and several layers of management
  • You’ve already dealt with a sensitive case without a formal channel to receive it
  • Your foreign parent company or your investors expect broader compliance standards
  • You have no way to prove to an inspector that your mechanism is secure and confidential in practice

If any of these sound familiar, the next step is deciding how you’ll run a mechanism that does comply: in-house, or with an independent third party.

Frequently asked questions

What happens if my company doesn’t comply with NOM-035?

The STPS can impose fines, with amounts that depend on the specific violation, the size of the company, and other aggravating factors. Fines are calculated in UMAs (Mexico’s Unit of Measure and Update), whose peso value is updated every year, so if you need the exact current amount, we recommend confirming it directly with the STPS or a labor law specialist.

Is “confidential” the same as “anonymous”?

No. Confidential means the reporter’s identity is protected and handled discreetly. Anonymous means that identity isn’t collected at all. NOM-035 requires confidentiality, not necessarily complete anonymity, although many companies offer both options to give reporters more confidence.

Does the same obligation apply to small companies?

The obligation to have a mechanism for receiving workplace violence complaints applies across the board, regardless of size. What varies with headcount are other specific obligations under the standard.

Does an internal hotline comply with NOM-035, or does it have to be external?

The standard doesn’t require the channel to be run by an outside third party — technically, an internal mechanism can comply. The point isn’t who runs it, but whether it genuinely guarantees security and confidentiality. Many companies discover, when they review their own processes, that what they have today doesn’t really meet that standard, even if “something” exists on paper.

Are there fines for not having reporting mechanisms for fraud or corruption?

No, because no Mexican law generally requires one for that kind of misconduct. The reason to implement it there is prevention and good practice, not direct regulatory compliance.

Ethic Lines Service combines technology with a team of professionals who receive, review, and follow up on every case using a defined methodology, meeting the security and confidentiality standards the regulation requires — whether you need to comply with NOM-035, prevent fraud, or strengthen your ethical culture.

Person reviewing the Ethic Lines platform on a laptop

Sources cited: NOM-035-STPS-2018, published in Mexico’s Official Gazette of the Federation (DOF), October 23, 2018. KPMG, Impacto de los delitos financieros en México (The impact of financial crime in Mexico). ACFE, Occupational Fraud 2024: A Report to the Nations.

Ethic Lines

Let's talk

🕐 30 min

📹 Video call (Google Meet)

Tell us what your team needs and we will show you how Ethic Lines works in 30 minutes, no strings attached.

Book a call

Email or call us and we will suggest a time.

contacto@ethiclines.com

+52 55 8008 1308