Colombie KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Colombie.
- Dernière revue
- Dernière revue:
- Version
- Version 1.2

Réponse directe
Que couvre la checklist de conformité pour Colombie ?
La checklist pour Colombie traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 45 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- National FIU
- Unidad de Informacion y Analisis Financiero (UIAF)
- Financial sector
- SFC SARLAFT under Circular Basica Juridica, Part I, Title IV, Chapter IV
- Covered companies
- Superintendencia de Sociedades Chapter X SAGRILAFT
- Suspicious reporting
- Immediately to UIAF through SIREL when the applicable sector rule requires a ROS
- Objective reports
- Sector-specific; use the current UIAF resolution, technical annex and calendar
- RUB beneficial owner
- 5% or more ownership, voting rights or benefit, other control, then representative-legal fallback
- RUB update
- Test changes on the first day of January, April, July and October; update within the following month if changed
- Privacy authority
- Superintendencia de Industria y Comercio (SIC)
- Virtual assets
- UIAF Resolution 314 reporting applies to covered Colombia-domiciled providers; this is not itself a financial licence
- FATF status
- GAFILAT member; not on FATF public lists reviewed 1 August 2026
Détail d’implémentation
Exigences et actions de conformité pour Colombie
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities and licensingColombia uses multiple supervisor-specific risk systems. Determine the entity, activity, supervisor and reporting resolution before selecting a control framework.4 éléments+
UIAF receives, centralizes and analyzes information relevant to money laundering, predicate offences, terrorism financing and proliferation financing under Law 526.
- Action d’implémentation
- Identify whether the entity is a reporting subject under a statute, supervisor circular or UIAF resolution and register the correct organization and users in SIREL.
- Preuves à conserver
- Perimeter memo, applicable instrument, SIREL registration, user list and reporting calendar.
- Source primaire
- Law 526/1999 arts. 1-4 and 9
SFC-supervised entities must implement SARLAFT under the current Circular Basica Juridica and articles 102-107 of the Organic Statute of the Financial System.
- Action d’implémentation
- Map the licensed entity and product to SARLAFT governance, stages, elements, CDD, monitoring, reporting and sanctions requirements.
- Preuves à conserver
- SFC authorization, rule mapping, SARLAFT manual, risk methodology and system configuration.
- Source primaire
- Organic Statute of the Financial System arts. 102-107; SFC CBJ Part I, Title IV, Chapter IV
Companies within Chapter X scope must implement SAGRILAFT; thresholds and listed high-risk sectors determine coverage and can change.
- Action d’implémentation
- Recalculate scope annually using the current Chapter X text, financial statements, sector and activity, and document whether SAGRILAFT or minimum measures apply.
- Preuves à conserver
- Scope calculation, financials, industry code, board conclusion and implementation deadline.
- Source primaire
- Superintendencia de Sociedades Circular 100-000016/2020, Chapter X, as amended
Deposit-taking, electronic deposits, payment operation and other reserved financial activities require the appropriate SFC-authorized form; AML reporting status is not a licence.
- Action d’implémentation
- Classify custody of customer funds, payment execution, transfers, acquiring and deposit features before launch and obtain authorization where required.
- Preuves à conserver
- Regulatory classification, SFC authorization or no-licence analysis, product limits and launch gate.
- Source primaire
- Law 1735/2014 art. 1; Decree 2555/2010; Organic Statute of the Financial System
02Governance and risk assessmentThe applicable system must be owned by senior bodies, tailored to risk and supported by an independent compliance function.4 éléments+
SARLAFT entities must identify, measure, control and monitor ML/TF risk through approved policies, procedures, documentation, structure, technology, disclosure and training.
- Action d’implémentation
- Assign board, legal-representative and compliance-officer responsibilities and map each SARLAFT stage and element to an accountable control owner.
- Preuves à conserver
- Board minutes, appointments, manual, risk matrix, control inventory, reports and training records.
- Source primaire
- SFC CBJ Part I, Title IV, Chapter IV sections 4.1-4.2
SAGRILAFT subjects must design and approve a system proportionate to their risk factors and appoint a qualifying Compliance Officer.
- Action d’implémentation
- Document risk factors, methodology, incompatibility checks, appointment, registration or reporting steps and resources.
- Preuves à conserver
- Risk assessment, board approval, officer CV and certification, incompatibility review and filing receipt.
- Source primaire
- Superintendencia de Sociedades Chapter X sections 5.1-5.3
Risk assessments must cover counterparties, products, activities, channels and jurisdictions and be refreshed on the rule's schedule and material change.
- Action d’implémentation
- Score inherent and residual risk, define appetite and escalation, validate inputs and update before entering a new market or product.
- Preuves à conserver
- Methodology, data sources, heat map, approval, validation, change assessment and action plan.
- Source primaire
- SFC CBJ Part I, Title IV, Chapter IV; Superintendencia de Sociedades Chapter X section 5.2
Training, audit and compliance reporting must demonstrate operational effectiveness and remediation.
- Action d’implémentation
- Deliver role-based training, independently sample controls, report to the competent body and track corrective actions to verified closure.
- Preuves à conserver
- Training completion, audit plan, samples, officer reports, findings and closure evidence.
- Source primaire
- SFC CBJ Part I, Title IV, Chapter IV section 4.2; Superintendencia de Sociedades Chapter X sections 5.1.4 and 5.6
03Natural-person KYC and representativesDue diligence must identify the counterparty, understand the relationship and verify the person acting for another.4 éléments+
SARLAFT requires customer knowledge before establishing the relationship, subject only to specific permitted exceptions or simplified procedures.
- Action d’implémentation
- Collect and verify name, identification, address, activity, contact and risk-relevant financial information against reliable sources before activation.
- Preuves à conserver
- Application, identity evidence, authoritative checks, verification log, risk rating and approval.
- Source primaire
- SFC CBJ Part I, Title IV, Chapter IV section 4.2.2.2.1
SAGRILAFT due diligence applies to counterparties and requires reasonable measures to know identity, activity and ownership before or during the relationship according to risk.
- Action d’implémentation
- Define counterparty categories, minimum fields, verification sources, risk triggers and periodic or event-driven refresh.
- Preuves à conserver
- Counterparty file, validation output, profile, risk decision, refresh log and exception approval.
- Source primaire
- Superintendencia de Sociedades Chapter X sections 5.3.1-5.3.2
A representative, attorney or authorized person must be identified and their authority confirmed.
- Action d’implémentation
- Verify the natural person, inspect the current mandate and confirm that requested transactions fall within its scope.
- Preuves à conserver
- Identity result, power or appointment, registry confirmation, scope check and expiry control.
- Source primaire
- SFC CBJ Part I, Title IV, Chapter IV; Superintendencia de Sociedades Chapter X section 5.3.1
Remote onboarding must preserve reliable verification and address impersonation, fraud and channel risk.
- Action d’implémentation
- Use layered document, database, device and, if proportionate, biometric checks; route mismatches and high-risk cases to enhanced review.
- Preuves à conserver
- Channel assessment, verification logs, liveness or fraud tests, exception queue, reviewer decision and quality results.
- Source primaire
- SFC CBJ Part I, Title IV, Chapter IV sections 4.2.2.2 and 4.2.3; Law 1581/2012 arts. 5-6 and 17-18
04KYB, registries and beneficial ownershipChamber-of-commerce registration, RUT and RUB filings must be reconciled with, but never substituted for, risk-based KYB and AML beneficial-owner checks.4 éléments+
Legal-entity counterparties must be verified through current constitutional, tax and registry information and their representatives confirmed.
- Action d’implémentation
- Obtain the certificate of existence and legal representation, RUT, constitutional documents, activity and governing persons and reconcile inconsistencies.
- Preuves à conserver
- Chamber certificate, RUT, statutes, representative identity, activity proof, status and reconciliation log.
- Source primaire
- SFC CBJ Part I, Title IV, Chapter IV; Superintendencia de Sociedades Chapter X section 5.3.1
The statutory RUB test identifies a natural person holding 5% or more of capital or voting rights or benefiting from 5% or more of assets, returns or profits, then other control, then the representative-legal or higher-authority fallback.
- Action d’implémentation
- Trace direct, indirect and joint ownership and benefit, test other control and document the fallback only after reasonable diligence.
- Preuves à conserver
- Ownership chart, calculations, benefit and control analysis, natural-person verification and fallback rationale.
- Source primaire
- Tax Statute art. 631-5; DIAN Resolution 227/2025 arts. 1.4.1.5-1.4.1.7
Covered legal persons and unincorporated structures must file RUB information electronically; new obliged persons generally file within two months of the relevant registration or obligation event.
- Action d’implémentation
- Confirm scope and exemptions, activate the RUT responsibility, submit accurate data through DIAN and retain the acknowledgement.
- Preuves à conserver
- Scope memo, RUT status, RUB data pack, due-diligence record, filing and receipt.
- Source primaire
- Tax Statute art. 631-6; DIAN Resolution 227/2025 arts. 1.4.1.4 and 1.4.1.10
RUB changes are tested on 1 January, April, July and October and, if a change exists, updated within the following month.
- Action d’implémentation
- Run quarterly ownership and control attestations, compare registry and customer data and file changes within the applicable window.
- Preuves à conserver
- Quarterly attestation, change analysis, revised chart, filing, receipt and overdue escalation.
- Source primaire
- DIAN Resolution 227/2025 art. 1.4.1.11
05PEPs, EDD and onboarding decisionsPEPs and other heightened risks require enhanced review and approval, with definitions and lookback periods taken from the applicable regime.4 éléments+
SARLAFT and SAGRILAFT require PEP identification and enhanced treatment, including applicable associates and close persons under current definitions.
- Action d’implémentation
- Screen domestic, foreign and international-organization PEPs, record the role and dates and apply the current post-office period.
- Preuves à conserver
- PEP source, role and date record, relationship mapping, match decision and refresh history.
- Source primaire
- Decree 830/2021; SFC CBJ Part I, Title IV, Chapter IV; Superintendencia de Sociedades Circular 100-000015/2021
Enhanced due diligence is required for higher-risk counterparties, jurisdictions, products, channels and transactions.
- Action d’implémentation
- Obtain senior approval where required, corroborate source of wealth and funds proportionately, increase monitoring and shorten review cycles.
- Preuves à conserver
- EDD plan, corroboration, approval, monitoring settings, review and residual-risk decision.
- Source primaire
- SFC CBJ Part I, Title IV, Chapter IV section 4.2.2.2; Superintendencia de Sociedades Chapter X section 5.3.2
Reasonable measures must resolve beneficial ownership and transaction purpose; inability or refusal is a risk event, not a reason to record invented certainty.
- Action d’implémentation
- Pause restricted activity, seek additional evidence, escalate unresolved cases, decline or exit where appropriate and assess a ROS confidentially.
- Preuves à conserver
- Information requests, restriction, escalation, decision, ROS assessment and exit record.
- Source primaire
- Superintendencia de Sociedades Chapter X sections 5.3.1-5.3.2 and 5.5; SFC CBJ Part I, Title IV, Chapter IV
Simplified due diligence is available only where the applicable rule and documented lower risk permit it.
- Action d’implémentation
- Define eligible products and customers, prohibit simplification when suspicion or higher risk exists and monitor continued eligibility.
- Preuves à conserver
- Eligibility criteria, risk assessment, approval, monitoring and periodic sample testing.
- Source primaire
- SFC CBJ Part I, Title IV, Chapter IV section 4.2.2.2.1; Superintendencia de Sociedades Chapter X
06Monitoring, ROS and confidentialityA ROS is a confidential intelligence report, not a criminal complaint; reporting must follow the applicable sector rule and UIAF technical channel.4 éléments+
Transactions and counterparties must be monitored against their profile and risk so unusual activity is identified, analyzed and documented.
- Action d’implémentation
- Implement scenarios and manual referrals, aggregate connected activity, investigate promptly and document both reported and closed outcomes.
- Preuves à conserver
- Scenario inventory, data lineage, alerts, investigation workpapers, decisions and quality review.
- Source primaire
- SFC CBJ Part I, Title IV, Chapter IV sections 4.1.4 and 4.2.3; Superintendencia de Sociedades Chapter X section 5.4
When an operation is determined suspicious under the applicable framework, the obliged subject reports immediately to UIAF through SIREL.
- Action d’implémentation
- Define decision authority, file the positive ROS without waiting for a periodic reporting window and retain the SIREL certificate.
- Preuves à conserver
- Decision timestamp, ROS file, SIREL receipt, case link and timeliness metric.
- Source primaire
- Superintendencia de Sociedades Chapter X section 5.5; UIAF SIREL guidance; UIAF Resolution 314/2021 art. 4
ROS information is reserved and a report is not a criminal complaint or proof of crime.
- Action d’implémentation
- Restrict access, avoid customer disclosure, separate service decisions from the report and control any authority response.
- Preuves à conserver
- Access list, confidentiality acknowledgements, communication review, authority log and audit trail.
- Source primaire
- Law 526/1999 art. 9; SFC CBJ Part I, Title IV, Chapter IV; UIAF ROS guidance
Absence reports and objective transaction reports vary by sector, reporting resolution, technical annex and calendar.
- Action d’implémentation
- Maintain a live obligation matrix and use the current UIAF sector page and annual calendar instead of applying another sector's threshold or due date.
- Preuves à conserver
- Obligation matrix, source version, population reconciliation, submissions and receipts.
- Source primaire
- Law 526/1999 art. 4; applicable UIAF sector resolution and technical annex
07Payments, transfers, cash and agentsReserved financial activities and UIAF objective reports require separate classification. There is no single threshold for every Colombian operator.4 éléments+
Financial institutions must maintain transaction records and send the cash and other objective reports specified in the current SFC/UIAF instructions.
- Action d’implémentation
- Implement the current technical annex fields, aggregation logic and reporting calendar for the institution's exact sector and product.
- Preuves à conserver
- Rule version, transaction population, threshold test, report file, reconciliation and SIREL receipt.
- Source primaire
- SFC CBJ Part I, Title IV, Chapter IV section 4.2.7 and current UIAF annexes
A SEDPE is an SFC-supervised financial institution with the exclusive activities defined by Law 1735, including electronic deposits, payments, transfers and specified remittances.
- Action d’implémentation
- Do not hold public funds or describe a product as a deposit outside an authorized form; map safeguarding and operational conditions before launch.
- Preuves à conserver
- SFC authorization, corporate object, funds-flow diagram, safeguarding control, disclosures and launch approval.
- Source primaire
- Law 1735/2014 art. 1; Decree 2555/2010
Wire, transfer and payment data must support party identification, sanctions screening, monitoring and reconstruction under the applicable SARLAFT and payment rules.
- Action d’implémentation
- Capture originator, beneficiary, account or wallet, institution, amount, currency, purpose and timestamps and stop deficient high-risk transfers.
- Preuves à conserver
- Message schema, completeness rules, screening result, exception cases and reconciliation.
- Source primaire
- SFC CBJ Part I, Title IV, Chapter IV; Organic Statute of the Financial System arts. 102-107
Using correspondents, agents or outsourced technology does not transfer the regulated entity's accountability.
- Action d’implémentation
- Due-diligence partners, contract for access and security, train relevant staff, monitor activity and maintain an exit and continuity plan.
- Preuves à conserver
- Partner risk file, contract, training, monitoring, audit rights, incidents and exit test.
- Source primaire
- SFC CBJ Part I, Title IV, Chapter IV; Superintendencia de Sociedades Chapter X
08Targeted financial sanctionsBinding-list controls must distinguish Colombia's mandatory sources from foreign lists used as additional risk inputs.4 éléments+
UN Security Council lists are internationally binding for Colombia under article 20 of Law 1121 and the national coordination framework.
- Action d’implémentation
- Screen counterparties, beneficial owners, representatives and transactions against the current UN Consolidated List at onboarding and on list changes.
- Preuves à conserver
- Official source, update timestamps, screening logs, coverage tests and match rules.
- Source primaire
- Law 1121/2006 art. 20; UIAF UN Lists guidance
If a confirmed match to a UN list is identified, the entity must immediately notify UIAF and the Fiscalia General de la Nacion. Precautionary measures over assets are imposed through the Fiscalia and judicial process and must be implemented promptly when the resulting order is received.
- Action d’implémentation
- Escalate the match immediately; notify UIAF and the Fiscalia through the prescribed channels; preserve assets and avoid making funds or property available while awaiting authority direction; then implement and document the precautionary order.
- Preuves à conserver
- Match analysis, notification timestamps, asset inventory, UIAF and Fiscalia receipts, precautionary order and implementation record.
- Source primaire
- Law 1121/2006 art. 20; UIAF Guide for Implementation of UN Security Council Resolutions, steps 2-3
Foreign lists such as OFAC are not interchangeable with the binding-list basis, although they may be relevant to risk, contract or correspondent obligations.
- Action d’implémentation
- Label each screening list by legal effect and apply a documented decision process for non-binding matches.
- Preuves à conserver
- List taxonomy, legal-basis matrix, match disposition, contractual requirement and approval.
- Source primaire
- Law 1121/2006 art. 20; UIAF frequently asked questions on lists
False positives and delisting require verified identifier analysis and controlled release.
- Action d’implémentation
- Compare all available identifiers, preserve the restriction during review and release only through the authorized process.
- Preuves à conserver
- Identifier comparison, legal review, authority correspondence, release approval and audit trail.
- Source primaire
- SFC CBJ Part I, Title IV, Chapter IV; UIAF Guide for implementing UN Security Council resolutions
09Records, audit and regulator accessRetention varies by regime. Store each record to the longest applicable period and preserve its legal trigger.4 éléments+
SARLAFT records and reports must be retained and made available under the current SFC chapter and general financial record rules.
- Action d’implémentation
- Map customer, transaction, alert, ROS, training and governance records to the exact SFC period and trigger and preserve confidential segregation.
- Preuves à conserver
- Retention schedule, archive, trigger dates, retrieval tests, access logs and disposal control.
- Source primaire
- SFC CBJ Part I, Title IV, Chapter IV section 4.2.3.3; Law 962/2005 art. 28
SAGRILAFT documentation must be preserved for at least ten years, without prejudice to longer applicable rules.
- Action d’implémentation
- Retain due diligence, ownership, monitoring, ROS assessment, governance and training evidence in reconstructable form.
- Preuves à conserver
- Document index, immutable archive, legal holds, retrieval test and destruction log.
- Source primaire
- Superintendencia de Sociedades Chapter X section 5.6
RUB supporting documents and due diligence are retained while the person is a beneficial owner and for at least five years after loss of that status; liquidation has its own five-year trigger.
- Action d’implémentation
- Track beneficial-owner start and end dates and apply the post-change or post-liquidation retention clock.
- Preuves à conserver
- RUB record, supporting evidence, status dates, liquidation record, archive and disposal approval.
- Source primaire
- DIAN Resolution 227/2025 art. 1.4.1.18
UIAF and supervisors may request information within their legal competence and confidentiality requirements continue to apply.
- Action d’implémentation
- Authenticate the request, preserve privilege where applicable, produce responsive records securely and log delivery and remediation.
- Preuves à conserver
- Request, authority verification, production set, approval, secure receipt and action tracker.
- Source primaire
- Law 526/1999 arts. 3-4 and 9; Organic Statute of the Financial System arts. 102-107
10Privacy, biometrics and transfersLaw 1581 contains an AML-purpose database exclusion, but operational datasets and uses must be classified carefully rather than treating all KYC data as exempt.5 éléments+
Law 1581 applies to covered public and private databases and establishes purpose, freedom, truthfulness, transparency, restricted access, security and confidentiality principles.
- Action d’implémentation
- Classify each KYC, fraud and AML dataset and purpose, document any article 2 exclusion narrowly and apply privacy controls to other processing.
- Preuves à conserver
- Dataset inventory, applicability memo, purpose register, policy, authorization or exception and rights workflow.
- Source primaire
- Law 1581/2012 arts. 2 and 4-18; Decree 1074/2015 Chapter 25
Biometric data is sensitive data; processing is generally prohibited unless a statutory exception applies and enhanced safeguards are used.
- Action d’implémentation
- Document the article 6 condition, necessity and proportionality, give the required notices, protect templates and provide a lawful alternative where appropriate.
- Preuves à conserver
- Sensitive-data assessment, authorization or exception, notice, template security, access logs and alternative path.
- Source primaire
- Law 1581/2012 arts. 5-6 and 12
Controllers and processors must maintain security, confidentiality, policy and data-subject consultation and complaint processes.
- Action d’implémentation
- Implement access, encryption, vendor and incident controls and meet the statutory response workflow for consultations and claims.
- Preuves à conserver
- Security program, policy, requests register, response timestamps, incidents and remediation.
- Source primaire
- Law 1581/2012 arts. 14-18; Decree 1074/2015 Chapter 25
Personal-data security incidents must be reported to the SIC within fifteen business days after they are detected and brought to the attention of the person or area responsible for handling them, using RNBD where applicable or the SIC incident-reporting application.
- Action d’implémentation
- Classify incidents promptly, record detection and internal-awareness timestamps, preserve evidence, determine the correct SIC channel and submit within fifteen business days.
- Preuves à conserver
- Incident register, timestamp record, assessment, SIC or RNBD submission and receipt, containment and remediation evidence.
- Source primaire
- SIC Circular Unica, Title V, Chapter II, incident-reporting instructions
International transfers to countries without an adequate level require an article 26 exception or SIC conformity declaration; transmissions to processors require the applicable contract.
- Action d’implémentation
- Distinguish transfer from transmission, verify destination status, implement the valid exception, declaration or processing contract and register details where required.
- Preuves à conserver
- Data-flow map, destination assessment, authorization or exception, SIC declaration or contract and RNBD record.
- Source primaire
- Law 1581/2012 art. 26; Decree 1074/2015 arts. 2.2.2.25.5.1-2.2.2.25.5.2
11Virtual assets and launch evidenceUIAF reporting for virtual-asset service providers does not itself make virtual assets legal tender or authorize a reserved financial activity.4 éléments+
UIAF Resolution 314/2021 imposes reporting on covered natural and legal persons domiciled in Colombia that provide specified virtual-asset services for or on behalf of another person.
- Action d’implémentation
- Map exchange, transfer, custody, administration and offering-related services to the Resolution and register the covered provider in SIREL.
- Preuves à conserver
- Service and domicile analysis, SIREL registration, responsible user and reporting calendar.
- Source primaire
- UIAF Resolution 314/2021 arts. 1-3, as amended by Resolution 84/2022
Covered providers send ROS immediately and the customer and transaction reports defined by the current technical annexes and annual calendar.
- Action d’implémentation
- Capture exact wallet and transaction identifiers, implement current report populations and validate files without submitting fictional production reports.
- Preuves à conserver
- Data dictionary, wallet and hash quality checks, ROS workflow, report files, reconciliation and receipts.
- Source primaire
- UIAF Resolution 314/2021 arts. 4-7; UIAF 2026 virtual-assets reporting calendar
Virtual assets are not Colombian legal tender, currency or foreign exchange merely because UIAF reporting applies, and a model may still enter a reserved financial, securities or public-fund-taking perimeter.
- Action d’implémentation
- Obtain a product-specific legal classification and block deposit, investment, securities, exchange or payment features until the competent perimeter is resolved.
- Preuves à conserver
- Legal opinion, asset and service classification, SFC or Banco de la Republica correspondence, restrictions and disclosures.
- Source primaire
- Banco de la Republica Concept JD-S-CA-03422-2023; UIAF Resolution 314/2021
Launch requires end-to-end proof that applicable KYC, KYB, reporting, sanctions, privacy, records, licensing and incident controls operate correctly.
- Action d’implémentation
- Run controlled dry tests, close defects and obtain legal, compliance, privacy, security and product approval before enabling customers.
- Preuves à conserver
- Completed checklist, source register, test results, defect closure, approvals, effective dates and monitoring owner.
- Source primaire
- Law 526/1999; applicable SARLAFT or SAGRILAFT rule; Law 1581/2012
Registre des sources primaires
33 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Law 526/1999 - UIAFSUIN-Juriscol · Primary legislation
- UIAF suspicious-operation reporting overviewUnidad de Informacion y Analisis Financiero · Official FIU guidance
- UIAF SIREL reporting portalUnidad de Informacion y Analisis Financiero · Official reporting channel
- SFC Circular Basica Juridica indexSuperintendencia Financiera de Colombia · Official regulatory directory
- SARLAFT Chapter IV textSuperintendencia Financiera de Colombia / UIAF · Primary regulatory instrument
- Organic Statute of the Financial SystemSecretaria Juridica Distrital · Primary legislation
- SAGRILAFT regulatory directory and current amendmentsSuperintendencia de Sociedades · Official regulatory directory
- SAGRILAFT Chapter X publication pageSuperintendencia de Sociedades · Primary regulatory instrument
- Circular Basica Juridica interactive text, adopted July 2026Superintendencia de Sociedades · Current official regulatory compilation
- Decree 830/2021 - politically exposed personsSUIN-Juriscol · Primary decree
- DIAN Resolution 164/2021 - annotated RUB rule and later compilation referencesDireccion de Impuestos y Aduanas Nacionales · Primary regulatory instrument
- DIAN Resolution 227/2025 - current unified tax compilation including RUBDireccion de Impuestos y Aduanas Nacionales · Current primary regulatory compilation
- RUB regulatory directoryDireccion de Impuestos y Aduanas Nacionales · Official registry guidance
- RUB electronic serviceDireccion de Impuestos y Aduanas Nacionales · Official beneficial-owner register
- Chambers of commerce / RUES business registerRegistro Unico Empresarial y Social · Official company registry network
- Law 1121/2006 - terrorist financing and binding listsSUIN-Juriscol · Primary legislation
- UIAF UN Security Council lists pageUnidad de Informacion y Analisis Financiero · Official sanctions guidance
- UIAF Guide for Implementation of UN Security Council ResolutionsUnidad de Informacion y Analisis Financiero · Official sanctions implementation guidance
- UIAF national-system rules and UN sanctions implementation guideUnidad de Informacion y Analisis Financiero · Official legal and guidance directory
- UN Security Council Consolidated ListUnited Nations Security Council · Official sanctions list
- Law 1581/2012 - personal data protectionSUIN-Juriscol · Primary legislation
- Decree 1074/2015 - commerce-sector consolidated decreeSUIN-Juriscol · Primary decree
- SIC personal-data protection authoritySuperintendencia de Industria y Comercio · Official regulator guidance
- SIC personal-data security-incident reporting instructionsSuperintendencia de Industria y Comercio · Official regulator guidance
- Law 1735/2014 - SEDPESUIN-Juriscol · Primary legislation
- SFC innovation licence guideSuperintendencia Financiera de Colombia · Official licensing guidance
- UIAF virtual-assets sector pageUnidad de Informacion y Analisis Financiero · Official reporting directory
- UIAF Resolution 314/2021 - virtual-asset providersUnidad de Informacion y Analisis Financiero · Primary regulatory instrument
- UIAF 2026 virtual-assets reporting calendarUnidad de Informacion y Analisis Financiero · Official reporting calendar
- Banco de la Republica virtual-assets legal characterizationBanco de la Republica · Official authority interpretation
- FATF Colombia country and assessment pageFinancial Action Task Force · Official international assessment
- FATF jurisdictions under increased monitoring, 19 June 2026Financial Action Task Force · Official current-status source
- FATF high-risk jurisdictions subject to a call for action, 19 June 2026Financial Action Task Force · Official current-status source
Réponses directes
Questions KYC, KYB et AML pour Colombie
Who receives suspicious operation reports in Colombia?+
UIAF receives ROS through SIREL from subjects obliged under their applicable sector law, supervisor circular or UIAF resolution.
When is a ROS due?+
A positive ROS is generally sent immediately once the operation is determined suspicious under the applicable sector framework. Do not wait for an objective-report or absence-report window.
Is there one universal transaction threshold?+
No. Cash, objective and absence reports depend on the sector, supervisor instrument, UIAF resolution, technical annex and current reporting calendar.
What is the beneficial-owner threshold?+
For RUB, the statutory test includes 5% or more ownership, voting rights or economic benefit, other control, and a representative-legal or higher-authority fallback. AML systems also require their own risk-based beneficial-owner diligence.
When must RUB data be updated?+
Covered persons test for changes on the first day of January, April, July and October. If information changed, they update within the following month.
How long are records retained?+
The period depends on the regime. SAGRILAFT documentation is retained for at least ten years. RUB support is retained while the person remains a beneficial owner and for at least five years after the status changes. Apply the current SFC rule to SARLAFT records.
Which sanctions lists are binding?+
UN Security Council lists are binding under article 20 of Law 1121. Other lists can be important risk or contractual inputs but require a separately documented legal effect.
Does a payments business need authorization?+
If it conducts reserved deposit-taking, SEDPE, payment-system or other financial activity, the appropriate SFC-authorized structure may be required. Resolve the precise funds flow and product perimeter before launch.
Does UIAF registration license a crypto business?+
No. Resolution 314 creates reporting duties for covered Colombia-domiciled virtual-asset providers; it does not by itself authorize deposit-taking, securities, exchange or another reserved financial activity.
Is Colombia on a FATF public list?+
Colombia was not named on the FATF increased-monitoring or call-for-action lists reviewed 1 August 2026. FATF/GAFILAT evaluation and follow-up findings remain relevant risk inputs.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
General regulatory information, not legal advice, a licence decision or a substitute for the operative Spanish text, supervisor circulars, UIAF technical annexes or reporting calendars. Reviewed 1 August 2026. Colombia's AML obligations, objective reports and thresholds are sector-specific. Confirm scope, current circular text, reporting taxonomy, licence perimeter and later developments with qualified Colombian counsel and the competent authority before launch.