Anti-Money Laundering in Latin America for Companies: What Colombia, Mexico and Brazil Require
Colombia covers companies by size and sector, Mexico by vulnerable activity and Brazil by a statutory list of obliged persons: three triggers for one goal.
A foreign group with subsidiaries in Colombia, Mexico and Brazil soon finds that "anti-money laundering" is not one rule set but three. The head office usually asks whether a single policy will do. The answer depends on who is covered in each country, to whom they report and what a bank or a large customer will ask of them anyway.
At Soulbit Academy we lay out the comparison as of October 2026: framework law, authority, who is covered, what the company must put in place, where it reports and how breaches are punished. Colombian thresholds are not repeated here; they are in our guide to SAGRILAFT: which companies are covered and what to implement.
Anti-Money Laundering in Latin America for Companies: Three Triggers, One Goal
Anti-money laundering rules for companies in Latin America follow the same international risk-management model, but what triggers the duty differs by country. Colombia covers supervised companies by size and sector, Mexico covers anyone who carries out a vulnerable activity listed in the law, and Brazil covers those named in a statutory list of obliged persons.
All three share familiar building blocks: identify the customer and its beneficial owner, keep records and report suspicious transactions to a financial intelligence unit. The statute, the authority, the formats and the penalties differ.
| Criterion | Colombia | Mexico | Brazil |
|---|---|---|---|
| Framework | Chapter IX of the Superintendence of Companies' Basic Legal Circular (SAGRILAFT and PTEE); Financial Superintendence rules (SARLAFT) | Federal Law for the Prevention and Identification of Transactions with Resources of Illicit Origin (LFPIORPI) | Law 9,613 of 1998, as amended |
| Supervisor | Superintendence of Companies for the real sector; Financial Superintendence for financial entities | Ministry of Finance and Public Credit | COAF and each obliged person's sector regulator |
| What triggers the duty | Nature of the entity, or exceeding the thresholds and sectors set by the supervisor | Carrying out a vulnerable activity under article 17 | Being listed in article 9 of the law |
| Where to report | UIAF | Notices to the Ministry through its electronic portal | COAF, through the Siscoaf system |
| Suspicion report | Suspicious transaction report (ROS) to the UIAF | Notice within 24 hours of the suspicion | Communication to the COAF within 24 hours |
| General penalties | Administrative penalties by the supervisor | Fines expressed in UMA units, and prison for supplying false information | Warning, fine, disqualification of managers and withdrawal of authorization |
Colombia: SAGRILAFT for the Real Sector, SARLAFT for Finance, and the UIAF
Colombia has two systems, depending on who the company is. SARLAFT is run by entities supervised by the Financial Superintendence, such as banks, and SAGRILAFT by companies supervised by the Superintendence of Companies that exceed the thresholds or belong to the sectors set in its circular. Both end in suspicious transaction reports to the UIAF, the Financial Information and Analysis Unit.
The practical difference is in our SARLAFT and SAGRILAFT comparison. The latest change is External Circular 100-000020 of the Superintendence of Companies, dated July 2, 2026, which merged SAGRILAFT and the PTEE into Chapter IX of the Basic Legal Circular. Companies already covered must adjust by May 31, 2027 at the latest. The business-ethics program is explained in our PTEE guide.
A covered Colombian company must have a policy approved by its highest corporate body, a manual, a risk matrix, counterparty due diligence, training and a compliance officer. A subsidiary below the thresholds has no duty of its own, but its bank and large customers will still request documents.
What is distinctive about Colombia compared with Mexico and Brazil?
In Colombia a real-sector company's duty depends on thresholds and sectors set by circular; in Mexico and Brazil it depends on the activity, and in Mexico each section of article 17 adds minimum amounts in UMA. A small company may therefore fall outside SAGRILAFT yet be bound in Mexico if its transactions exceed the amount for its section.
Mexico: the LFPIORPI Regulates Vulnerable Activities, Not Types of Company
The Federal Law for the Prevention and Identification of Transactions with Resources of Illicit Origin asks what a company does, not what it is. According to the current text on the Chamber of Deputies site, last amended on July 16, 2025, article 17 lists the vulnerable activities and article 18 sets what whoever performs them must do.
Article 17 covers, among others, real estate development, trading in precious metals and vehicles, certain independent professional services, notarial services, customs agent services and the habitual and professional exchange of virtual assets. Each item has its own amounts, expressed in multiples of the daily UMA value, for identifying the customer and filing a notice.
A company that performs none of these activities is not covered merely because it is large or moves money, although it can be a customer of those who do.
The July 2025 reform changed several items of article 18. Whoever performs a vulnerable activity must, under the current text:
- identify and verify customers with official documents and, for legal entities, identify the controlling beneficial owner;
- keep supporting records, as a rule for at least ten years, and register in the registry of vulnerable activities;
- file notices with the Ministry of Finance and, where there is suspicion, within 24 hours, even if the transaction did not take place;
- assess risks on a risk-based approach and write an internal policy manual.
How is non-compliance punished in Mexico?
The law combines administrative fines and crimes. Under articles 53 and 54, breaching article 18 duties is fined between 200 and 2,000 times the daily UMA value, and failing to file notices between 10,000 and 65,000 times the UMA, or 10% to 100% of the transaction value, whichever is greater. Article 62 also punishes with two to eight years in prison anyone who supplies false information for a notice. The UMA value changes every year.
Brazil: Law 9,613, Obliged Persons and the COAF
In Brazil the duty comes from being listed in article 9 of Law 9,613 of 1998. It covers those who, permanently or occasionally, raise, intermediate or invest third-party funds, trade foreign currency or gold, or custody and trade securities. Its sole paragraph adds, among others, insurers, card administrators, factoring and leasing companies, real estate development, jewelry and luxury goods dealers, and advisory, consulting, accounting or audit services in certain transactions.
A manufacturer whose activity is not on the list has no such duty of its own, although its bank does and will pass it on as a customer.
Article 10 requires obliged persons to identify customers, keep records of transactions above the limit set by the competent authority (since the 2022 amendment, including virtual assets), adopt internal controls proportionate to their size and register with their regulator. Article 11 requires reporting suspicious proposals or transactions to the COAF within 24 hours, without informing anyone.
The COAF is Brazil's financial intelligence unit, a public body created by article 14 to receive, examine and identify suspicious occurrences and apply administrative penalties. Reports go through the Siscoaf system: under the official Brazilian services portal, you must first register with your regulator and then enable access to the system.
Article 12 penalties apply to obliged persons and their managers: warning, fine, temporary disqualification for up to ten years from serving as a manager, and cancellation or suspension of authorization. In its current wording the fine is capped by reference to twice the transaction value, twice the actual profit obtained or expected, or R$ 20,000,000.
What a Company Operating in All Three Countries Is Asked For
A company operating in all three countries faces three kinds of demands: its own, if it is covered; those of its banks, which treat it as a customer; and those of large customers, which treat it as a counterparty. All of them want to know who stands behind the company and where the money comes from.
A hypothetical example: a European group with subsidiaries in Colombia, Mexico and Brazil checks in Colombia whether the local company exceeds the SAGRILAFT thresholds, in Mexico whether it performs an article 17 activity and in Brazil whether it falls under article 9. It is an illustrative assumption, and the answer may differ by subsidiary.
| What is required | Colombia | Mexico | Brazil |
|---|---|---|---|
| Identify customer and beneficial owner | Yes, under SARLAFT at the bank and SAGRILAFT at the covered company | Yes, with official documents; for legal entities, the controlling beneficial owner | Yes, with an up-to-date customer register |
| Policy and manual | Policy, manual and risk matrix | Internal policy manual and risk assessment | Internal policies and controls proportionate to size |
| Compliance officer | Designated compliance officer | As set by the Ministry's general rules | As set by each obliged person's regulator |
| Record keeping | As set by the system manual and supervisor rules | As a rule, at least ten years | As set by the competent authority |
| Suspicion report | ROS to the UIAF | Notice within 24 hours | Communication to the COAF within 24 hours |
| Prior registration | Compliance officer appointment and reporting channel to the UIAF | Entry in the registry of vulnerable activities | Registration with the regulator and Siscoaf enablement |
A common file keeps the work orderly: certificate of incorporation for each entity, ownership structure down to the controlling individual and a description of the business. If the company moves international payments, it also supports sanctions list screening and the monitoring described in KYT and AML in payments.
What a Single Compliance System Does Not Solve
A single compliance system organizes management across the three countries but does not replace each entity's local obligations. There are four limits.
The first is that the duty belongs to each legal entity: a Colombian parent that complies with SAGRILAFT does not thereby comply with the LFPIORPI through its Mexican subsidiary.
The second is that reports are local. Each notice is filed with that country's authority, in its format, and is confidential.
The third is that rules change: the Mexican reform of July 2025 amended articles 17 and 18, and the Colombian circular of July 2026 reorganized SAGRILAFT.
The fourth is that no system stops a bank or customer from asking for its own documents. To see how a company is verified, read what KYB is.
What Soulbit V1 Delivers Against These Regimes, and What It Does Not
Soulbit V1 does not satisfy any country's anti-money laundering rules on behalf of your company: each regime described is an obligation of each covered entity, with its own officers, manuals and reports.
Today Soulbit V1 verifies business customers through KYB, applies transaction monitoring (KYT) and AML controls to the payments it processes, operates with institutional custody and provides human support. Each payment leaves a trail your team can use to support its own due diligence. The local bank rail in Soulbit V1 exists only in Colombia.
What Soulbit V1 does not deliver matters just as much. It does not file notices with the UIAF, the COAF or the Mexican Ministry of Finance on your company's behalf, does not write your manual or issue compliance certificates, does not determine whether your company is a covered entity and does not replace your compliance officer. This article also makes no claim about which regime applies to Soulbit as an operator.
Frequently asked questions
Which laws govern anti-money laundering for companies in Colombia, Mexico and Brazil?
In Mexico it is the Federal Law for the Prevention and Identification of Transactions with Resources of Illicit Origin (LFPIORPI), and in Brazil Law 9,613 of 1998. Colombia has no single statute for companies: SAGRILAFT is set by Superintendence of Companies circulars and SARLAFT by Financial Superintendence rules.
Who receives suspicious activity reports in each country?
In Colombia the UIAF receives them, in Brazil the COAF, and in Mexico the Ministry of Finance and Public Credit through notices filed on its electronic portal. Reports are confidential, and the law bars the reporting entity from telling the person concerned.
Must a foreign group set up an AML system in all three countries?
Not automatically. In Colombia it depends on the thresholds and sectors set by the Superintendence of Companies, in Mexico on carrying out a vulnerable activity listed in article 17 of the LFPIORPI, and in Brazil on being among the obliged persons in article 9 of Law 9,613. A group can be covered in one country and not in another.
How quickly must a suspicious transaction be reported?
In Mexico and Brazil the law sets 24 hours from the suspicion or from learning of the transaction. In Colombia the deadline and procedure come from the supervisor's rules and the UIAF's instructions, so the company's manual and the current instructions must be checked.
Can one group-wide compliance manual cover all three countries?
A common core can, such as beneficial-owner identification and record keeping. But each country sets its own registrations, formats, authorities and deadlines, so the manual needs local annexes and someone who knows each rule.
Want your company to add stablecoins to its operations?
Join the Soulbit waitlist and start paying payroll, collecting and managing treasury without SWIFT.
Join the waitlist