Colombia KYC & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Colombia.

Direct answer
What does the Colombia compliance checklist cover?
The Colombia checklist translates primary KYC, KYB and AML rules into 11 control areas and 45 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- National FIU
- Unidad de Informacion y Analisis Financiero (UIAF)
- Financial sector
- SFC SARLAFT under Circular Basica Juridica, Part I, Title IV, Chapter IV
- Covered companies
- Superintendencia de Sociedades Chapter X SAGRILAFT
- Suspicious reporting
- Immediately to UIAF through SIREL when the applicable sector rule requires a ROS
- Objective reports
- Sector-specific; use the current UIAF resolution, technical annex and calendar
- RUB beneficial owner
- 5% or more ownership, voting rights or benefit, other control, then representative-legal fallback
- RUB update
- Test changes on the first day of January, April, July and October; update within the following month if changed
- Privacy authority
- Superintendencia de Industria y Comercio (SIC)
- Virtual assets
- UIAF Resolution 314 reporting applies to covered Colombia-domiciled providers; this is not itself a financial licence
- FATF status
- GAFILAT member; not on FATF public lists reviewed 1 August 2026
Implementation detail
Colombia compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities and licensingColombia uses multiple supervisor-specific risk systems. Determine the entity, activity, supervisor and reporting resolution before selecting a control framework.4 items+
UIAF receives, centralizes and analyzes information relevant to money laundering, predicate offences, terrorism financing and proliferation financing under Law 526.
- Implementation action
- Identify whether the entity is a reporting subject under a statute, supervisor circular or UIAF resolution and register the correct organization and users in SIREL.
- Evidence to retain
- Perimeter memo, applicable instrument, SIREL registration, user list and reporting calendar.
- Primary citation
- Law 526/1999 arts. 1-4 and 9
SFC-supervised entities must implement SARLAFT under the current Circular Basica Juridica and articles 102-107 of the Organic Statute of the Financial System.
- Implementation action
- Map the licensed entity and product to SARLAFT governance, stages, elements, CDD, monitoring, reporting and sanctions requirements.
- Evidence to retain
- SFC authorization, rule mapping, SARLAFT manual, risk methodology and system configuration.
- Primary citation
- Organic Statute of the Financial System arts. 102-107; SFC CBJ Part I, Title IV, Chapter IV
Companies within Chapter X scope must implement SAGRILAFT; thresholds and listed high-risk sectors determine coverage and can change.
- Implementation action
- Recalculate scope annually using the current Chapter X text, financial statements, sector and activity, and document whether SAGRILAFT or minimum measures apply.
- Evidence to retain
- Scope calculation, financials, industry code, board conclusion and implementation deadline.
- Primary citation
- Superintendencia de Sociedades Circular 100-000016/2020, Chapter X, as amended
Deposit-taking, electronic deposits, payment operation and other reserved financial activities require the appropriate SFC-authorized form; AML reporting status is not a licence.
- Implementation action
- Classify custody of customer funds, payment execution, transfers, acquiring and deposit features before launch and obtain authorization where required.
- Evidence to retain
- Regulatory classification, SFC authorization or no-licence analysis, product limits and launch gate.
- Primary citation
- Law 1735/2014 art. 1; Decree 2555/2010; Organic Statute of the Financial System
02Governance and risk assessmentThe applicable system must be owned by senior bodies, tailored to risk and supported by an independent compliance function.4 items+
SARLAFT entities must identify, measure, control and monitor ML/TF risk through approved policies, procedures, documentation, structure, technology, disclosure and training.
- Implementation action
- Assign board, legal-representative and compliance-officer responsibilities and map each SARLAFT stage and element to an accountable control owner.
- Evidence to retain
- Board minutes, appointments, manual, risk matrix, control inventory, reports and training records.
- Primary citation
- SFC CBJ Part I, Title IV, Chapter IV sections 4.1-4.2
SAGRILAFT subjects must design and approve a system proportionate to their risk factors and appoint a qualifying Compliance Officer.
- Implementation action
- Document risk factors, methodology, incompatibility checks, appointment, registration or reporting steps and resources.
- Evidence to retain
- Risk assessment, board approval, officer CV and certification, incompatibility review and filing receipt.
- Primary citation
- Superintendencia de Sociedades Chapter X sections 5.1-5.3
Risk assessments must cover counterparties, products, activities, channels and jurisdictions and be refreshed on the rule's schedule and material change.
- Implementation action
- Score inherent and residual risk, define appetite and escalation, validate inputs and update before entering a new market or product.
- Evidence to retain
- Methodology, data sources, heat map, approval, validation, change assessment and action plan.
- Primary citation
- SFC CBJ Part I, Title IV, Chapter IV; Superintendencia de Sociedades Chapter X section 5.2
Training, audit and compliance reporting must demonstrate operational effectiveness and remediation.
- Implementation action
- Deliver role-based training, independently sample controls, report to the competent body and track corrective actions to verified closure.
- Evidence to retain
- Training completion, audit plan, samples, officer reports, findings and closure evidence.
- Primary citation
- SFC CBJ Part I, Title IV, Chapter IV section 4.2; Superintendencia de Sociedades Chapter X sections 5.1.4 and 5.6
03Natural-person KYC and representativesDue diligence must identify the counterparty, understand the relationship and verify the person acting for another.4 items+
SARLAFT requires customer knowledge before establishing the relationship, subject only to specific permitted exceptions or simplified procedures.
- Implementation action
- Collect and verify name, identification, address, activity, contact and risk-relevant financial information against reliable sources before activation.
- Evidence to retain
- Application, identity evidence, authoritative checks, verification log, risk rating and approval.
- Primary citation
- SFC CBJ Part I, Title IV, Chapter IV section 4.2.2.2.1
SAGRILAFT due diligence applies to counterparties and requires reasonable measures to know identity, activity and ownership before or during the relationship according to risk.
- Implementation action
- Define counterparty categories, minimum fields, verification sources, risk triggers and periodic or event-driven refresh.
- Evidence to retain
- Counterparty file, validation output, profile, risk decision, refresh log and exception approval.
- Primary citation
- Superintendencia de Sociedades Chapter X sections 5.3.1-5.3.2
A representative, attorney or authorized person must be identified and their authority confirmed.
- Implementation action
- Verify the natural person, inspect the current mandate and confirm that requested transactions fall within its scope.
- Evidence to retain
- Identity result, power or appointment, registry confirmation, scope check and expiry control.
- Primary citation
- SFC CBJ Part I, Title IV, Chapter IV; Superintendencia de Sociedades Chapter X section 5.3.1
Remote onboarding must preserve reliable verification and address impersonation, fraud and channel risk.
- Implementation action
- Use layered document, database, device and, if proportionate, biometric checks; route mismatches and high-risk cases to enhanced review.
- Evidence to retain
- Channel assessment, verification logs, liveness or fraud tests, exception queue, reviewer decision and quality results.
- Primary citation
- SFC CBJ Part I, Title IV, Chapter IV sections 4.2.2.2 and 4.2.3; Law 1581/2012 arts. 5-6 and 17-18
04KYB, registries and beneficial ownershipChamber-of-commerce registration, RUT and RUB filings must be reconciled with, but never substituted for, risk-based KYB and AML beneficial-owner checks.4 items+
Legal-entity counterparties must be verified through current constitutional, tax and registry information and their representatives confirmed.
- Implementation action
- Obtain the certificate of existence and legal representation, RUT, constitutional documents, activity and governing persons and reconcile inconsistencies.
- Evidence to retain
- Chamber certificate, RUT, statutes, representative identity, activity proof, status and reconciliation log.
- Primary citation
- SFC CBJ Part I, Title IV, Chapter IV; Superintendencia de Sociedades Chapter X section 5.3.1
The statutory RUB test identifies a natural person holding 5% or more of capital or voting rights or benefiting from 5% or more of assets, returns or profits, then other control, then the representative-legal or higher-authority fallback.
- Implementation action
- Trace direct, indirect and joint ownership and benefit, test other control and document the fallback only after reasonable diligence.
- Evidence to retain
- Ownership chart, calculations, benefit and control analysis, natural-person verification and fallback rationale.
- Primary citation
- Tax Statute art. 631-5; DIAN Resolution 227/2025 arts. 1.4.1.5-1.4.1.7
Covered legal persons and unincorporated structures must file RUB information electronically; new obliged persons generally file within two months of the relevant registration or obligation event.
- Implementation action
- Confirm scope and exemptions, activate the RUT responsibility, submit accurate data through DIAN and retain the acknowledgement.
- Evidence to retain
- Scope memo, RUT status, RUB data pack, due-diligence record, filing and receipt.
- Primary citation
- Tax Statute art. 631-6; DIAN Resolution 227/2025 arts. 1.4.1.4 and 1.4.1.10
RUB changes are tested on 1 January, April, July and October and, if a change exists, updated within the following month.
- Implementation action
- Run quarterly ownership and control attestations, compare registry and customer data and file changes within the applicable window.
- Evidence to retain
- Quarterly attestation, change analysis, revised chart, filing, receipt and overdue escalation.
- Primary citation
- DIAN Resolution 227/2025 art. 1.4.1.11
05PEPs, EDD and onboarding decisionsPEPs and other heightened risks require enhanced review and approval, with definitions and lookback periods taken from the applicable regime.4 items+
SARLAFT and SAGRILAFT require PEP identification and enhanced treatment, including applicable associates and close persons under current definitions.
- Implementation action
- Screen domestic, foreign and international-organization PEPs, record the role and dates and apply the current post-office period.
- Evidence to retain
- PEP source, role and date record, relationship mapping, match decision and refresh history.
- Primary citation
- Decree 830/2021; SFC CBJ Part I, Title IV, Chapter IV; Superintendencia de Sociedades Circular 100-000015/2021
Enhanced due diligence is required for higher-risk counterparties, jurisdictions, products, channels and transactions.
- Implementation action
- Obtain senior approval where required, corroborate source of wealth and funds proportionately, increase monitoring and shorten review cycles.
- Evidence to retain
- EDD plan, corroboration, approval, monitoring settings, review and residual-risk decision.
- Primary citation
- SFC CBJ Part I, Title IV, Chapter IV section 4.2.2.2; Superintendencia de Sociedades Chapter X section 5.3.2
Reasonable measures must resolve beneficial ownership and transaction purpose; inability or refusal is a risk event, not a reason to record invented certainty.
- Implementation action
- Pause restricted activity, seek additional evidence, escalate unresolved cases, decline or exit where appropriate and assess a ROS confidentially.
- Evidence to retain
- Information requests, restriction, escalation, decision, ROS assessment and exit record.
- Primary citation
- Superintendencia de Sociedades Chapter X sections 5.3.1-5.3.2 and 5.5; SFC CBJ Part I, Title IV, Chapter IV
Simplified due diligence is available only where the applicable rule and documented lower risk permit it.
- Implementation action
- Define eligible products and customers, prohibit simplification when suspicion or higher risk exists and monitor continued eligibility.
- Evidence to retain
- Eligibility criteria, risk assessment, approval, monitoring and periodic sample testing.
- Primary citation
- SFC CBJ Part I, Title IV, Chapter IV section 4.2.2.2.1; Superintendencia de Sociedades Chapter X
06Monitoring, ROS and confidentialityA ROS is a confidential intelligence report, not a criminal complaint; reporting must follow the applicable sector rule and UIAF technical channel.4 items+
Transactions and counterparties must be monitored against their profile and risk so unusual activity is identified, analyzed and documented.
- Implementation action
- Implement scenarios and manual referrals, aggregate connected activity, investigate promptly and document both reported and closed outcomes.
- Evidence to retain
- Scenario inventory, data lineage, alerts, investigation workpapers, decisions and quality review.
- Primary citation
- SFC CBJ Part I, Title IV, Chapter IV sections 4.1.4 and 4.2.3; Superintendencia de Sociedades Chapter X section 5.4
When an operation is determined suspicious under the applicable framework, the obliged subject reports immediately to UIAF through SIREL.
- Implementation action
- Define decision authority, file the positive ROS without waiting for a periodic reporting window and retain the SIREL certificate.
- Evidence to retain
- Decision timestamp, ROS file, SIREL receipt, case link and timeliness metric.
- Primary citation
- Superintendencia de Sociedades Chapter X section 5.5; UIAF SIREL guidance; UIAF Resolution 314/2021 art. 4
ROS information is reserved and a report is not a criminal complaint or proof of crime.
- Implementation action
- Restrict access, avoid customer disclosure, separate service decisions from the report and control any authority response.
- Evidence to retain
- Access list, confidentiality acknowledgements, communication review, authority log and audit trail.
- Primary citation
- Law 526/1999 art. 9; SFC CBJ Part I, Title IV, Chapter IV; UIAF ROS guidance
Absence reports and objective transaction reports vary by sector, reporting resolution, technical annex and calendar.
- Implementation action
- Maintain a live obligation matrix and use the current UIAF sector page and annual calendar instead of applying another sector's threshold or due date.
- Evidence to retain
- Obligation matrix, source version, population reconciliation, submissions and receipts.
- Primary citation
- Law 526/1999 art. 4; applicable UIAF sector resolution and technical annex
07Payments, transfers, cash and agentsReserved financial activities and UIAF objective reports require separate classification. There is no single threshold for every Colombian operator.4 items+
Financial institutions must maintain transaction records and send the cash and other objective reports specified in the current SFC/UIAF instructions.
- Implementation action
- Implement the current technical annex fields, aggregation logic and reporting calendar for the institution's exact sector and product.
- Evidence to retain
- Rule version, transaction population, threshold test, report file, reconciliation and SIREL receipt.
- Primary citation
- SFC CBJ Part I, Title IV, Chapter IV section 4.2.7 and current UIAF annexes
A SEDPE is an SFC-supervised financial institution with the exclusive activities defined by Law 1735, including electronic deposits, payments, transfers and specified remittances.
- Implementation action
- Do not hold public funds or describe a product as a deposit outside an authorized form; map safeguarding and operational conditions before launch.
- Evidence to retain
- SFC authorization, corporate object, funds-flow diagram, safeguarding control, disclosures and launch approval.
- Primary citation
- Law 1735/2014 art. 1; Decree 2555/2010
Wire, transfer and payment data must support party identification, sanctions screening, monitoring and reconstruction under the applicable SARLAFT and payment rules.
- Implementation action
- Capture originator, beneficiary, account or wallet, institution, amount, currency, purpose and timestamps and stop deficient high-risk transfers.
- Evidence to retain
- Message schema, completeness rules, screening result, exception cases and reconciliation.
- Primary citation
- SFC CBJ Part I, Title IV, Chapter IV; Organic Statute of the Financial System arts. 102-107
Using correspondents, agents or outsourced technology does not transfer the regulated entity's accountability.
- Implementation action
- Due-diligence partners, contract for access and security, train relevant staff, monitor activity and maintain an exit and continuity plan.
- Evidence to retain
- Partner risk file, contract, training, monitoring, audit rights, incidents and exit test.
- Primary citation
- SFC CBJ Part I, Title IV, Chapter IV; Superintendencia de Sociedades Chapter X
08Targeted financial sanctionsBinding-list controls must distinguish Colombia's mandatory sources from foreign lists used as additional risk inputs.4 items+
UN Security Council lists are internationally binding for Colombia under article 20 of Law 1121 and the national coordination framework.
- Implementation action
- Screen counterparties, beneficial owners, representatives and transactions against the current UN Consolidated List at onboarding and on list changes.
- Evidence to retain
- Official source, update timestamps, screening logs, coverage tests and match rules.
- Primary citation
- Law 1121/2006 art. 20; UIAF UN Lists guidance
If a confirmed match to a UN list is identified, the entity must immediately notify UIAF and the Fiscalia General de la Nacion. Precautionary measures over assets are imposed through the Fiscalia and judicial process and must be implemented promptly when the resulting order is received.
- Implementation action
- Escalate the match immediately; notify UIAF and the Fiscalia through the prescribed channels; preserve assets and avoid making funds or property available while awaiting authority direction; then implement and document the precautionary order.
- Evidence to retain
- Match analysis, notification timestamps, asset inventory, UIAF and Fiscalia receipts, precautionary order and implementation record.
- Primary citation
- Law 1121/2006 art. 20; UIAF Guide for Implementation of UN Security Council Resolutions, steps 2-3
Foreign lists such as OFAC are not interchangeable with the binding-list basis, although they may be relevant to risk, contract or correspondent obligations.
- Implementation action
- Label each screening list by legal effect and apply a documented decision process for non-binding matches.
- Evidence to retain
- List taxonomy, legal-basis matrix, match disposition, contractual requirement and approval.
- Primary citation
- Law 1121/2006 art. 20; UIAF frequently asked questions on lists
False positives and delisting require verified identifier analysis and controlled release.
- Implementation action
- Compare all available identifiers, preserve the restriction during review and release only through the authorized process.
- Evidence to retain
- Identifier comparison, legal review, authority correspondence, release approval and audit trail.
- Primary citation
- SFC CBJ Part I, Title IV, Chapter IV; UIAF Guide for implementing UN Security Council resolutions
09Records, audit and regulator accessRetention varies by regime. Store each record to the longest applicable period and preserve its legal trigger.4 items+
SARLAFT records and reports must be retained and made available under the current SFC chapter and general financial record rules.
- Implementation action
- Map customer, transaction, alert, ROS, training and governance records to the exact SFC period and trigger and preserve confidential segregation.
- Evidence to retain
- Retention schedule, archive, trigger dates, retrieval tests, access logs and disposal control.
- Primary citation
- SFC CBJ Part I, Title IV, Chapter IV section 4.2.3.3; Law 962/2005 art. 28
SAGRILAFT documentation must be preserved for at least ten years, without prejudice to longer applicable rules.
- Implementation action
- Retain due diligence, ownership, monitoring, ROS assessment, governance and training evidence in reconstructable form.
- Evidence to retain
- Document index, immutable archive, legal holds, retrieval test and destruction log.
- Primary citation
- Superintendencia de Sociedades Chapter X section 5.6
RUB supporting documents and due diligence are retained while the person is a beneficial owner and for at least five years after loss of that status; liquidation has its own five-year trigger.
- Implementation action
- Track beneficial-owner start and end dates and apply the post-change or post-liquidation retention clock.
- Evidence to retain
- RUB record, supporting evidence, status dates, liquidation record, archive and disposal approval.
- Primary citation
- DIAN Resolution 227/2025 art. 1.4.1.18
UIAF and supervisors may request information within their legal competence and confidentiality requirements continue to apply.
- Implementation action
- Authenticate the request, preserve privilege where applicable, produce responsive records securely and log delivery and remediation.
- Evidence to retain
- Request, authority verification, production set, approval, secure receipt and action tracker.
- Primary citation
- Law 526/1999 arts. 3-4 and 9; Organic Statute of the Financial System arts. 102-107
10Privacy, biometrics and transfersLaw 1581 contains an AML-purpose database exclusion, but operational datasets and uses must be classified carefully rather than treating all KYC data as exempt.5 items+
Law 1581 applies to covered public and private databases and establishes purpose, freedom, truthfulness, transparency, restricted access, security and confidentiality principles.
- Implementation action
- Classify each KYC, fraud and AML dataset and purpose, document any article 2 exclusion narrowly and apply privacy controls to other processing.
- Evidence to retain
- Dataset inventory, applicability memo, purpose register, policy, authorization or exception and rights workflow.
- Primary citation
- Law 1581/2012 arts. 2 and 4-18; Decree 1074/2015 Chapter 25
Biometric data is sensitive data; processing is generally prohibited unless a statutory exception applies and enhanced safeguards are used.
- Implementation action
- Document the article 6 condition, necessity and proportionality, give the required notices, protect templates and provide a lawful alternative where appropriate.
- Evidence to retain
- Sensitive-data assessment, authorization or exception, notice, template security, access logs and alternative path.
- Primary citation
- Law 1581/2012 arts. 5-6 and 12
Controllers and processors must maintain security, confidentiality, policy and data-subject consultation and complaint processes.
- Implementation action
- Implement access, encryption, vendor and incident controls and meet the statutory response workflow for consultations and claims.
- Evidence to retain
- Security program, policy, requests register, response timestamps, incidents and remediation.
- Primary citation
- Law 1581/2012 arts. 14-18; Decree 1074/2015 Chapter 25
Personal-data security incidents must be reported to the SIC within fifteen business days after they are detected and brought to the attention of the person or area responsible for handling them, using RNBD where applicable or the SIC incident-reporting application.
- Implementation action
- Classify incidents promptly, record detection and internal-awareness timestamps, preserve evidence, determine the correct SIC channel and submit within fifteen business days.
- Evidence to retain
- Incident register, timestamp record, assessment, SIC or RNBD submission and receipt, containment and remediation evidence.
- Primary citation
- SIC Circular Unica, Title V, Chapter II, incident-reporting instructions
International transfers to countries without an adequate level require an article 26 exception or SIC conformity declaration; transmissions to processors require the applicable contract.
- Implementation action
- Distinguish transfer from transmission, verify destination status, implement the valid exception, declaration or processing contract and register details where required.
- Evidence to retain
- Data-flow map, destination assessment, authorization or exception, SIC declaration or contract and RNBD record.
- Primary citation
- Law 1581/2012 art. 26; Decree 1074/2015 arts. 2.2.2.25.5.1-2.2.2.25.5.2
11Virtual assets and launch evidenceUIAF reporting for virtual-asset service providers does not itself make virtual assets legal tender or authorize a reserved financial activity.4 items+
UIAF Resolution 314/2021 imposes reporting on covered natural and legal persons domiciled in Colombia that provide specified virtual-asset services for or on behalf of another person.
- Implementation action
- Map exchange, transfer, custody, administration and offering-related services to the Resolution and register the covered provider in SIREL.
- Evidence to retain
- Service and domicile analysis, SIREL registration, responsible user and reporting calendar.
- Primary citation
- UIAF Resolution 314/2021 arts. 1-3, as amended by Resolution 84/2022
Covered providers send ROS immediately and the customer and transaction reports defined by the current technical annexes and annual calendar.
- Implementation action
- Capture exact wallet and transaction identifiers, implement current report populations and validate files without submitting fictional production reports.
- Evidence to retain
- Data dictionary, wallet and hash quality checks, ROS workflow, report files, reconciliation and receipts.
- Primary citation
- UIAF Resolution 314/2021 arts. 4-7; UIAF 2026 virtual-assets reporting calendar
Virtual assets are not Colombian legal tender, currency or foreign exchange merely because UIAF reporting applies, and a model may still enter a reserved financial, securities or public-fund-taking perimeter.
- Implementation action
- Obtain a product-specific legal classification and block deposit, investment, securities, exchange or payment features until the competent perimeter is resolved.
- Evidence to retain
- Legal opinion, asset and service classification, SFC or Banco de la Republica correspondence, restrictions and disclosures.
- Primary citation
- Banco de la Republica Concept JD-S-CA-03422-2023; UIAF Resolution 314/2021
Launch requires end-to-end proof that applicable KYC, KYB, reporting, sanctions, privacy, records, licensing and incident controls operate correctly.
- Implementation action
- Run controlled dry tests, close defects and obtain legal, compliance, privacy, security and product approval before enabling customers.
- Evidence to retain
- Completed checklist, source register, test results, defect closure, approvals, effective dates and monitoring owner.
- Primary citation
- Law 526/1999; applicable SARLAFT or SAGRILAFT rule; Law 1581/2012
Primary-source register
33 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Law 526/1999 - UIAFSUIN-Juriscol · Primary legislation
- UIAF suspicious-operation reporting overviewUnidad de Informacion y Analisis Financiero · Official FIU guidance
- UIAF SIREL reporting portalUnidad de Informacion y Analisis Financiero · Official reporting channel
- SFC Circular Basica Juridica indexSuperintendencia Financiera de Colombia · Official regulatory directory
- SARLAFT Chapter IV textSuperintendencia Financiera de Colombia / UIAF · Primary regulatory instrument
- Organic Statute of the Financial SystemSecretaria Juridica Distrital · Primary legislation
- SAGRILAFT regulatory directory and current amendmentsSuperintendencia de Sociedades · Official regulatory directory
- SAGRILAFT Chapter X publication pageSuperintendencia de Sociedades · Primary regulatory instrument
- Circular Basica Juridica interactive text, adopted July 2026Superintendencia de Sociedades · Current official regulatory compilation
- Decree 830/2021 - politically exposed personsSUIN-Juriscol · Primary decree
- DIAN Resolution 164/2021 - annotated RUB rule and later compilation referencesDireccion de Impuestos y Aduanas Nacionales · Primary regulatory instrument
- DIAN Resolution 227/2025 - current unified tax compilation including RUBDireccion de Impuestos y Aduanas Nacionales · Current primary regulatory compilation
- RUB regulatory directoryDireccion de Impuestos y Aduanas Nacionales · Official registry guidance
- RUB electronic serviceDireccion de Impuestos y Aduanas Nacionales · Official beneficial-owner register
- Chambers of commerce / RUES business registerRegistro Unico Empresarial y Social · Official company registry network
- Law 1121/2006 - terrorist financing and binding listsSUIN-Juriscol · Primary legislation
- UIAF UN Security Council lists pageUnidad de Informacion y Analisis Financiero · Official sanctions guidance
- UIAF Guide for Implementation of UN Security Council ResolutionsUnidad de Informacion y Analisis Financiero · Official sanctions implementation guidance
- UIAF national-system rules and UN sanctions implementation guideUnidad de Informacion y Analisis Financiero · Official legal and guidance directory
- UN Security Council Consolidated ListUnited Nations Security Council · Official sanctions list
- Law 1581/2012 - personal data protectionSUIN-Juriscol · Primary legislation
- Decree 1074/2015 - commerce-sector consolidated decreeSUIN-Juriscol · Primary decree
- SIC personal-data protection authoritySuperintendencia de Industria y Comercio · Official regulator guidance
- SIC personal-data security-incident reporting instructionsSuperintendencia de Industria y Comercio · Official regulator guidance
- Law 1735/2014 - SEDPESUIN-Juriscol · Primary legislation
- SFC innovation licence guideSuperintendencia Financiera de Colombia · Official licensing guidance
- UIAF virtual-assets sector pageUnidad de Informacion y Analisis Financiero · Official reporting directory
- UIAF Resolution 314/2021 - virtual-asset providersUnidad de Informacion y Analisis Financiero · Primary regulatory instrument
- UIAF 2026 virtual-assets reporting calendarUnidad de Informacion y Analisis Financiero · Official reporting calendar
- Banco de la Republica virtual-assets legal characterizationBanco de la Republica · Official authority interpretation
- FATF Colombia country and assessment pageFinancial Action Task Force · Official international assessment
- FATF jurisdictions under increased monitoring, 19 June 2026Financial Action Task Force · Official current-status source
- FATF high-risk jurisdictions subject to a call for action, 19 June 2026Financial Action Task Force · Official current-status source
Direct answers
Colombia KYC, KYB and AML questions
Who receives suspicious operation reports in Colombia?+
UIAF receives ROS through SIREL from subjects obliged under their applicable sector law, supervisor circular or UIAF resolution.
When is a ROS due?+
A positive ROS is generally sent immediately once the operation is determined suspicious under the applicable sector framework. Do not wait for an objective-report or absence-report window.
Is there one universal transaction threshold?+
No. Cash, objective and absence reports depend on the sector, supervisor instrument, UIAF resolution, technical annex and current reporting calendar.
What is the beneficial-owner threshold?+
For RUB, the statutory test includes 5% or more ownership, voting rights or economic benefit, other control, and a representative-legal or higher-authority fallback. AML systems also require their own risk-based beneficial-owner diligence.
When must RUB data be updated?+
Covered persons test for changes on the first day of January, April, July and October. If information changed, they update within the following month.
How long are records retained?+
The period depends on the regime. SAGRILAFT documentation is retained for at least ten years. RUB support is retained while the person remains a beneficial owner and for at least five years after the status changes. Apply the current SFC rule to SARLAFT records.
Which sanctions lists are binding?+
UN Security Council lists are binding under article 20 of Law 1121. Other lists can be important risk or contractual inputs but require a separately documented legal effect.
Does a payments business need authorization?+
If it conducts reserved deposit-taking, SEDPE, payment-system or other financial activity, the appropriate SFC-authorized structure may be required. Resolve the precise funds flow and product perimeter before launch.
Does UIAF registration license a crypto business?+
No. Resolution 314 creates reporting duties for covered Colombia-domiciled virtual-asset providers; it does not by itself authorize deposit-taking, securities, exchange or another reserved financial activity.
Is Colombia on a FATF public list?+
Colombia was not named on the FATF increased-monitoring or call-for-action lists reviewed 1 August 2026. FATF/GAFILAT evaluation and follow-up findings remain relevant risk inputs.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice, a licence decision or a substitute for the operative Spanish text, supervisor circulars, UIAF technical annexes or reporting calendars. Reviewed 1 August 2026. Colombia's AML obligations, objective reports and thresholds are sector-specific. Confirm scope, current circular text, reporting taxonomy, licence perimeter and later developments with qualified Colombian counsel and the competent authority before launch.