SFC/SARLAFTColombiaFintech

KYC Compliance for Fintech in Colombia (SFC & SARLAFT)

In-depth guide to KYC and AML compliance for fintech companies in Colombia, covering SFC regulations, SARLAFT requirements, crowdfunding rules, and UIAF reporting obligations.

Overview of Fintech Regulation in Colombia

A regulatory design that tries to hold innovation, consumer protection and financial integrity together has helped Colombia become one of Latin America's most dynamic fintech markets. Primary supervision sits with the Superintendencia Financiera de Colombia (SFC). Banks, insurers, capital markets and a widening set of fintech activities fall under that remit.

The country has stayed pragmatic. Existing financial rules carry most of the load, and dedicated frameworks appear when a new business model needs them. Crowdfunding platforms received their own regulatory space through Decree 1357 of 2018. Electronic deposits, digital payments and open finance initiatives followed in later instruments.

The SFC's Role in Fintech Oversight

Entities that carry on financial activities in Colombia sit under the SFC's comprehensive supervisory authority. Fintech oversight in particular covers:

  • Licensing and authorization: Firms that supply regulated financial services must hold the right license, or they must operate through a licensed partner.
  • Prudential requirements: Capital adequacy, risk management and corporate governance standards.
  • Consumer protection: Transparency, fair dealing and complaint resolution mechanisms.
  • AML/CFT compliance: Implementation and maintenance of the SARLAFT system.

Regular inspections form part of that model. Fines, operational restrictions and license revocations are available against non-compliant entities.

SARLAFT: Colombia's AML/CFT Compliance System

Colombia's mandatory AML/CFT risk management system is the Sistema de Administracion del Riesgo de Lavado de Activos y de la Financiacion del Terrorismo (SARLAFT). Every entity the SFC supervises must run it. The design is comprehensive and risk-based, aimed at preventing money laundering and terrorism financing.

SARLAFT Components

Regulated entities have to put the following in place:

  • Policies: Board-approved AML/CFT policies that set the institution's risk appetite and compliance strategy.
  • Procedures: Operational detail for customer identification, transaction monitoring, suspicious activity reporting and record keeping.
  • Documentation: Full records of every SARLAFT element, risk assessments and methodology included.
  • Organizational structure: A designated compliance officer with a direct line to the board, backed by adequate staff and resources.
  • Technology infrastructure: Systems able to support customer screening, transaction monitoring and regulatory reporting.
  • Training programs: Regular AML/CFT training for all employees, covering obligations and red flag indicators.
  • Internal audit: Independent review of SARLAFT effectiveness on a regular basis.

Risk-Based Customer Classification

Customers must be placed in risk categories under SARLAFT. Factors used for that classification include:

  • Customer type (individual vs. legal entity)
  • Economic activity and industry sector
  • Geographic location and jurisdictional risk
  • Transaction volume and patterns
  • Product and service risk profile
  • PEP (Politically Exposed Person) status

Higher-risk customers trigger enhanced due diligence. That means more extensive documentation, senior management approval and more frequent monitoring.

KYC Requirements for Colombian Fintechs

Standard CDD for Individuals

Individual customers require Colombian fintechs to collect and verify:

  • Cedula de Ciudadania: Colombia's national identification document for citizens, or Cedula de Extranjeria for foreign residents.
  • Full legal name, date, and place of birth.
  • Address and contact information.
  • Economic activity and source of income.
  • Tax identification number (NIT) where applicable.
  • Declaration of funds origin for account opening and significant transactions.

Corporate customers bring a separate set of requirements:

  • Certificate of existence and legal representation from the Chamber of Commerce
  • NIT (Numero de Identificacion Tributaria)
  • Identification of beneficial owners holding 5% or more of capital
  • Financial statements for the most recent fiscal year
  • Board resolution authorizing the business relationship

Simplified KYC for Financial Inclusion

Financial inclusion has been treated as a policy priority, so simplified KYC is allowed on low-value products. Electronic deposits (depositos electronicos) and certain digital wallet products can be opened with lighter documentation, provided strict transaction and balance limits apply. That design has been instrumental in extending financial access to Colombia's unbanked population.

Both standard and simplified KYC flows are supported by Joinble's AI-powered identity verification, so Colombian fintechs can onboard customers at any tier and still keep full regulatory compliance. Foundational KYC concepts sit in our guide on what is KYC.

Decree 1357/2018: Crowdfunding Regulation

Collaborative financing (crowdfunding) in Colombia received a dedicated regulatory framework through Decree 1357 of 2018. Platforms register with the SFC and must meet SARLAFT requirements, including:

  • Full KYC on all investors and project creators
  • Investment limits based on investor classification (qualified vs. non-qualified)
  • Ongoing monitoring of funded projects
  • Transparent disclosure of risks and fees
  • Anti-fraud controls and conflict of interest management

Crowdfunding platforms form a distinct category inside the Colombian financial system. Authorization is granted only after they show the SFC that their compliance infrastructure meets SARLAFT standards.

UIAF Reporting Obligations

The Unidad de Informacion y Analisis Financiero (UIAF) is Colombia's financial intelligence unit. Established channels carry reports from every SARLAFT-obligated entity:

Suspicious Transaction Reports (ROS)

Transactions or activities that raise a suspicion of money laundering or terrorism financing must be sent to the UIAF as a Reporte de Operaciones Sospechosas (ROS). Key aspects:

  • Reports must be filed immediately upon detection, regardless of transaction amount.
  • The tipping-off prohibition prevents entities from informing customers about filed reports.
  • Quality of reports is monitored by the UIAF, and entities may receive feedback on reporting standards.

Cash Transaction Reports

Cash transactions above defined thresholds go to the UIAF through systematic reporting mechanisms.

Absence Reports

Reporting periods with no suspicious transactions still require a filing that confirms the absence of suspicious activity.

Technology and Digital Verification

Digital identity verification methods have been taken up progressively by the SFC, which treats them as relevant to fintech competitiveness and financial inclusion. Key developments include:

  • Biometric verification: The Colombian government's biometric database, managed by the Registraduria Nacional, can be leveraged for identity confirmation.
  • Video identification: Remote onboarding through video calls with trained agents is permitted under certain conditions.
  • AI-powered document verification: Automated systems that validate Colombian cedulas and other documents against security features are widely accepted.

Those capabilities sit inside Joinble's platform. Colombian fintechs receive a compliant digital onboarding path that combines document verification, biometric matching and real-time sanctions screening in a single workflow.

Penalties and Enforcement

SARLAFT non-compliance is met with robust SFC enforcement tools:

  • Administrative fines that can reach significant multiples of the minimum monthly wage
  • Personal liability for compliance officers and directors who fail to implement adequate controls
  • License revocation for systemic or repeated failures
  • Criminal referrals to the Fiscalia General de la Nacion for suspected money laundering or terrorism financing facilitation

Frequently Asked Questions

What is SARLAFT and who must comply with it?

Colombia's mandatory AML/CFT risk management system is SARLAFT (Sistema de Administracion del Riesgo de Lavado de Activos y de la Financiacion del Terrorismo). All entities supervised by the SFC, fintech companies that provide regulated financial services among them, must implement SARLAFT.

What documents do Colombian fintechs need to collect for KYC?

The Cedula de Ciudadania is the primary document for individuals (or the Cedula de Extranjeria for foreigners). Proof of address, an economic activity declaration, source of funds and tax identification where applicable sit alongside it.

Is simplified KYC available for fintech products in Colombia?

Yes. Low-value products such as electronic deposits and certain digital wallets may use simplified KYC. Strict transaction and balance limits apply to these accounts, yet reduced documentation requirements support broader financial inclusion.

How do Colombian fintechs report suspicious transactions?

Reportes de Operaciones Sospechosas (ROS) carry suspicious transactions to the UIAF. Filing is required immediately upon detection, and the entity must not inform the customer about the report.

What are the requirements for crowdfunding platforms under Decree 1357/2018?

Registration with the SFC is required, together with full SARLAFT compliance, KYC on all investors and project creators, investment-limit enforcement, and transparent disclosure and anti-fraud controls.

Can Colombian fintechs use digital identity verification?

Yes. Permitted methods include biometric verification against national databases, AI-powered document validation and, under certain conditions, video identification. Solutions like Joinble's AI-powered platform help fintechs implement these methods compliantly.

Automate your compliance with AI Agents

Joinble's Agentic Identity platform reduces manual KYC reviews by up to 80%. Book a demo to see it in action.

Book a demo