KYC Compliance for Fintech in Colombia (SFC & SARLAFT)
In-depth guide to KYC and AML compliance for fintech companies in Colombia, covering SFC regulations, SARLAFT requirements, crowdfunding rules, and UIAF reporting obligations.
Overview of Fintech Regulation in Colombia
A regulatory design that tries to hold innovation, consumer protection and financial integrity together has helped Colombia become one of Latin America's most dynamic fintech markets. Primary supervision sits with the Superintendencia Financiera de Colombia (SFC). Banks, insurers, capital markets and a widening set of fintech activities fall under that remit.
The country has stayed pragmatic. Existing financial rules carry most of the load, and dedicated frameworks appear when a new business model needs them. Crowdfunding platforms received their own regulatory space through Decree 1357 of 2018. Electronic deposits, digital payments and open finance initiatives followed in later instruments.
The SFC's Role in Fintech Oversight
Entities that carry on financial activities in Colombia sit under the SFC's comprehensive supervisory authority. Fintech oversight in particular covers:
- Licensing and authorization: Firms that supply regulated financial services must hold the right license, or they must operate through a licensed partner.
- Prudential requirements: Capital adequacy, risk management and corporate governance standards.
- Consumer protection: Transparency, fair dealing and complaint resolution mechanisms.
- AML/CFT compliance: Implementation and maintenance of the SARLAFT system.
Regular inspections form part of that model. Fines, operational restrictions and license revocations are available against non-compliant entities.
SARLAFT: Colombia's AML/CFT Compliance System
Colombia's mandatory AML/CFT risk management system is the Sistema de Administracion del Riesgo de Lavado de Activos y de la Financiacion del Terrorismo (SARLAFT). Every entity the SFC supervises must run it. The design is comprehensive and risk-based, aimed at preventing money laundering and terrorism financing.
SARLAFT Components
Regulated entities have to put the following in place:
- Policies: Board-approved AML/CFT policies that set the institution's risk appetite and compliance strategy.
- Procedures: Operational detail for customer identification, transaction monitoring, suspicious activity reporting and record keeping.
- Documentation: Full records of every SARLAFT element, risk assessments and methodology included.
- Organizational structure: A designated compliance officer with a direct line to the board, backed by adequate staff and resources.
- Technology infrastructure: Systems able to support customer screening, transaction monitoring and regulatory reporting.
- Training programs: Regular AML/CFT training for all employees, covering obligations and red flag indicators.
- Internal audit: Independent review of SARLAFT effectiveness on a regular basis.
Risk-Based Customer Classification
Customers must be placed in risk categories under SARLAFT. Factors used for that classification include:
- Customer type (individual vs. legal entity)
- Economic activity and industry sector
- Geographic location and jurisdictional risk
- Transaction volume and patterns
- Product and service risk profile
- PEP (Politically Exposed Person) status
Higher-risk customers trigger enhanced due diligence. That means more extensive documentation, senior management approval and more frequent monitoring.
KYC Requirements for Colombian Fintechs
Standard CDD for Individuals
Individual customers require Colombian fintechs to collect and verify:
- Cedula de Ciudadania: Colombia's national identification document for citizens, or Cedula de Extranjeria for foreign residents.
- Full legal name, date, and place of birth.
- Address and contact information.
- Economic activity and source of income.
- Tax identification number (NIT) where applicable.
- Declaration of funds origin for account opening and significant transactions.
CDD for Legal Entities
Corporate customers bring a separate set of requirements:
- Certificate of existence and legal representation from the Chamber of Commerce
- NIT (Numero de Identificacion Tributaria)
- Identification of beneficial owners holding 5% or more of capital
- Financial statements for the most recent fiscal year
- Board resolution authorizing the business relationship
Simplified KYC for Financial Inclusion
Financial inclusion has been treated as a policy priority, so simplified KYC is allowed on low-value products. Electronic deposits (depositos electronicos) and certain digital wallet products can be opened with lighter documentation, provided strict transaction and balance limits apply. That design has been instrumental in extending financial access to Colombia's unbanked population.
Both standard and simplified KYC flows are supported by Joinble's AI-powered identity verification, so Colombian fintechs can onboard customers at any tier and still keep full regulatory compliance. Foundational KYC concepts sit in our guide on what is KYC.
Decree 1357/2018: Crowdfunding Regulation
Collaborative financing (crowdfunding) in Colombia received a dedicated regulatory framework through Decree 1357 of 2018. Platforms register with the SFC and must meet SARLAFT requirements, including:
- Full KYC on all investors and project creators
- Investment limits based on investor classification (qualified vs. non-qualified)
- Ongoing monitoring of funded projects
- Transparent disclosure of risks and fees
- Anti-fraud controls and conflict of interest management
Crowdfunding platforms form a distinct category inside the Colombian financial system. Authorization is granted only after they show the SFC that their compliance infrastructure meets SARLAFT standards.
UIAF Reporting Obligations
The Unidad de Informacion y Analisis Financiero (UIAF) is Colombia's financial intelligence unit. Established channels carry reports from every SARLAFT-obligated entity:
Suspicious Transaction Reports (ROS)
Transactions or activities that raise a suspicion of money laundering or terrorism financing must be sent to the UIAF as a Reporte de Operaciones Sospechosas (ROS). Key aspects:
- Reports must be filed immediately upon detection, regardless of transaction amount.
- The tipping-off prohibition prevents entities from informing customers about filed reports.
- Quality of reports is monitored by the UIAF, and entities may receive feedback on reporting standards.
Cash Transaction Reports
Cash transactions above defined thresholds go to the UIAF through systematic reporting mechanisms.
Absence Reports
Reporting periods with no suspicious transactions still require a filing that confirms the absence of suspicious activity.
Technology and Digital Verification
Digital identity verification methods have been taken up progressively by the SFC, which treats them as relevant to fintech competitiveness and financial inclusion. Key developments include:
- Biometric verification: The Colombian government's biometric database, managed by the Registraduria Nacional, can be leveraged for identity confirmation.
- Video identification: Remote onboarding through video calls with trained agents is permitted under certain conditions.
- AI-powered document verification: Automated systems that validate Colombian cedulas and other documents against security features are widely accepted.
Those capabilities sit inside Joinble's platform. Colombian fintechs receive a compliant digital onboarding path that combines document verification, biometric matching and real-time sanctions screening in a single workflow.
Penalties and Enforcement
SARLAFT non-compliance is met with robust SFC enforcement tools:
- Administrative fines that can reach significant multiples of the minimum monthly wage
- Personal liability for compliance officers and directors who fail to implement adequate controls
- License revocation for systemic or repeated failures
- Criminal referrals to the Fiscalia General de la Nacion for suspected money laundering or terrorism financing facilitation
Frequently Asked Questions
What is SARLAFT and who must comply with it?
Colombia's mandatory AML/CFT risk management system is SARLAFT (Sistema de Administracion del Riesgo de Lavado de Activos y de la Financiacion del Terrorismo). All entities supervised by the SFC, fintech companies that provide regulated financial services among them, must implement SARLAFT.
What documents do Colombian fintechs need to collect for KYC?
The Cedula de Ciudadania is the primary document for individuals (or the Cedula de Extranjeria for foreigners). Proof of address, an economic activity declaration, source of funds and tax identification where applicable sit alongside it.
Is simplified KYC available for fintech products in Colombia?
Yes. Low-value products such as electronic deposits and certain digital wallets may use simplified KYC. Strict transaction and balance limits apply to these accounts, yet reduced documentation requirements support broader financial inclusion.
How do Colombian fintechs report suspicious transactions?
Reportes de Operaciones Sospechosas (ROS) carry suspicious transactions to the UIAF. Filing is required immediately upon detection, and the entity must not inform the customer about the report.
What are the requirements for crowdfunding platforms under Decree 1357/2018?
Registration with the SFC is required, together with full SARLAFT compliance, KYC on all investors and project creators, investment-limit enforcement, and transparent disclosure and anti-fraud controls.
Can Colombian fintechs use digital identity verification?
Yes. Permitted methods include biometric verification against national databases, AI-powered document validation and, under certain conditions, video identification. Solutions like Joinble's AI-powered platform help fintechs implement these methods compliantly.
Automate your compliance with AI Agents
Joinble's Agentic Identity platform reduces manual KYC reviews by up to 80%. Book a demo to see it in action.
Book a demoRelated compliance guides
KYC and AML Compliance for Fintech in Argentina (UIF & CNV)
Detailed guide to KYC and AML compliance for fintech companies in Argentina, covering UIF regulations, CNV securities oversight, BCRA PSP licensing, and the 2024 FATF/GAFILAT mutual evaluation.
KYC for Fintech in Bangladesh (BFIU and Bangladesh Bank)
Comprehensive guide to KYC, e-KYC and regulatory compliance for fintechs in Bangladesh under BFIU, Bangladesh Bank, MLPA 2012 and the e-KYC directive updated in 2026.
KYC & AML for Fintech in Canada (FINTRAC & PCMLTFA)
Complete guide to KYC, AML, and CTF compliance requirements for fintech and crypto companies operating in Canada under FINTRAC regulations.
Related articles
US Kills BOI Reporting: What KYC Teams Must Know
FinCEN permanently removed US beneficial ownership reporting on August 14, 2026. KYC obligations remain — and the EU is moving in the opposite direction.
ComplianceAMLR 2027: New KYC Rules for Real Estate, Luxury & Football
EU AMLR 2027 extends KYC obligations to real estate, luxury goods, and football. Fourteen months for sectors with zero compliance history to get it right.
ComplianceEU AI Act Article 50: Deepfake Rules Live—KYC Impact
EU AI Act Article 50 entered force on 2 August 2026. Here's what the deepfake disclosure mandate means for KYC compliance and fraud defence.