SAGRILAFT in Colombia: Which Companies Must Comply and What to Implement
SAGRILAFT is Colombia's anti-money-laundering system for companies supervised by the Superintendence of Companies, mandatory from 4,929,017 UVB in revenue or assets.
SAGRILAFT is the self-control system through which a company in Colombia prevents itself from being used for money laundering or terrorist financing, and the Superintendence of Companies requires it from firms above certain revenue or asset thresholds. For a CFO, or for a foreign group with a Colombian subsidiary, the questions are practical: is our entity covered, and what does implementing it actually involve? The rules changed in July 2026, so much of what was published earlier is out of date.
At Soulbit Academy we explain who must comply, at what thresholds, what the system contains, who answers for it and how reports reach the UIAF. Acronyms are explained as they appear.
SAGRILAFT in 2026: what it is and what Circular 100-000020 changed
SAGRILAFT is the Spanish acronym for the system of self-control and risk management for money laundering, terrorist financing and proliferation financing, and since 2 July 2026 it is merged with PTEE into a single system. This comes from Circular 100-000020 of 2026, issued by the Superintendence of Companies (Supersociedades), which renewed the Basic Legal Circular.
PTEE is the Business Transparency and Ethics Programme, covering corruption and transnational bribery. Chapter IX now brings both under one name: the System of Self-Control and Risk Management for LA/FT/FP and C/ST. LA/FT/FP stands for money laundering, terrorist financing and proliferation financing. C/ST stands for corruption and transnational bribery.
Three practical effects follow. First, one policy, one manual and one risk matrix replace two parallel programmes. Second, thresholds move from minimum monthly wages to UVB, the basic value unit. Third, there is a deadline: companies already obligated must adjust by 31 May 2027, and their existing systems remain valid until then.
As of 1 October 2026 the circular has been issued and is no longer a draft. The UIAF, the Financial Information and Analysis Unit, continues to receive suspicious transaction reports.
Which companies must comply with SAGRILAFT: thresholds and sectors
Companies, single-shareholder enterprises and branches of foreign companies supervised by Supersociedades must comply if their total revenue or total assets on 31 December of the previous year were at least 4,929,017 UVB. They must not already be supervised by another authority under a special regime for their activity.
Some sectors have a lower threshold. Real estate agents, precious metals and stones, legal services, accounting services, construction and vehicle sales are covered by the full system from 3,696,762 UVB in revenue or assets, when the registered activity matches the CIIU codes in the circular. Other regimes apply with no figures: commercial self-financing companies, payroll-deduction lenders, multilevel marketing, cattle funds and supervised factoring.
| Regime | Who is covered | Threshold in the circular | Approximate equivalent |
|---|---|---|---|
| Full system, general criterion | Companies, single-shareholder enterprises and branches of foreign companies supervised by Supersociedades | Total revenue or total assets from 4,929,017 UVB | About COP 59,690 million |
| Full system, risk sectors | Real estate, precious metals and stones, legal services, accounting services, construction and vehicle sales | Revenue or assets from 3,696,762 UVB | About COP 44,768 million |
| Full system, virtual assets | Anyone receiving virtual asset contributions or providing exchange, transfer or custody services | From 12,323 UVB in contributions or operations; services also need revenue from 369,676 UVB or assets from 616,127 UVB | About COP 149 million in operations |
| Full system, special regimes | Commercial self-financing, payroll-deduction lenders, multilevel marketing, cattle funds, supervised factoring | No figure threshold | Not applicable |
| Minimum measures regime | Real estate, metals, legal, accounting, vehicles, pharmaceutical, infrastructure and construction, manufacturing and mining-energy, with the listed CIIU codes | Revenue from 369,676 UVB or assets from 616,127 UVB | About COP 4,477 million in revenue or COP 7,461 million in assets |
The UVB is the basic value unit that the tax authority, DIAN, sets each year, so the peso conversion changes annually. Calculate the threshold with the current official value and compare it with your financial statements at 31 December.
What is the minimum measures regime?
It is a lighter version of the system for companies in the listed sectors that pass a low threshold but not the full-system one. It includes yearly training, due diligence on counterparties and reporting to the UIAF, and the board or highest corporate body approves it.
Consider a hypothetical case. A European group owns a Colombian subsidiary that sells vehicles (under a CIIU code included in the circular's list) with revenue of COP 10,000 million. That is far below the full-system threshold for the sector, about COP 44,768 million, but above the minimum measures threshold of about COP 4,477 million. If Supersociedades supervises the subsidiary, it should implement the minimum measures regime. These figures are an illustrative assumption, not a real client.
The obligation attaches to the Colombian entity, not to the foreign parent. The circular lets the compliance officer of a parent or controlling company serve all obligated entities of the group, as long as the officer is domiciled in Colombia. Whether Supersociedades supervises a given subsidiary depends on separate criteria, so confirm it with local counsel.
What a SAGRILAFT system must contain
A SAGRILAFT system must contain at least a policy and a procedures manual, a risk matrix, due diligence on counterparties, training and disclosure, and a compliance officer backed by the board. The circular warns against paper compliance, meaning documents copied from other companies that do not reflect the actual business.
The risk matrix runs through four stages: identification, assessment, control and monitoring. The company classifies risk factors by sector, geography, third parties, intermediaries and channels, measures each risk and designs controls to reduce the residual risk.
The circular also requires specific policies: gifts, travel expenses, political contributions, donations, lobbying, proliferation financing, public contracting and a code of ethics, each with internal controls and sanctions.
| System element | What the circular requires | Who is responsible |
|---|---|---|
| Policy and manual | Conduct rules and procedures adapted to the company's own risks, with senior management commitment | Board, which approves it in minutes, and legal representative |
| Risk matrix | Identification, assessment, control and monitoring of LA/FT/FP and C/ST risks | Compliance officer, with the legal representative |
| Due diligence | Identify the counterparty, its beneficial owner and the purpose of the relationship, and monitor transactions continuously | Legal representative and the areas that onboard third parties |
| Training and disclosure | At least once a year, with a record of attendees, date and topics | Compliance officer |
| Reporting to the UIAF | A ROS when a suspicious operation is detected and a quarterly AROS if there was none | Compliance officer |
| Record keeping | Complete documents and records, with date and time, of due diligence and reports | The obligated company |
The compliance officer, board and legal representative under SAGRILAFT
The compliance officer is the individual who implements, runs and supervises the system, and reports directly to the board or to the highest corporate body if there is no board. The board appoints a principal officer and an alternate, and gives them resources and autonomy.
The circular sets the requirements. The officer needs a professional degree and one year of experience in compliance and LA/FT/FP and C/ST risk management. Knowledge must be shown through a specialisation, a master's degree or a diploma of at least 90 hours, and refreshed at least every three years. The officer must be domiciled in Colombia, cannot serve more than ten obligated companies and cannot sit on management bodies.
The board approves the system in minutes, reviews the officer's reports and sets criteria for onboarding politically exposed persons (PEP). The legal representative proposes the system with the officer, assigns resources, decides on onboarding and certifies compliance to the Superintendence on request.
The statutory auditor, where one exists, must also report suspicious operations to the UIAF. Hiring technology or advisers helps run the system, but responsibility stays with the company.
Due diligence and reporting to the UIAF under SAGRILAFT
Due diligence is the process by which the company identifies each counterparty, verifies its identity from independent sources, learns who its beneficial owner is and understands why the commercial relationship exists. The circular also requires monitoring transactions throughout the relationship.
Enhanced due diligence applies when risk is higher, such as PEP counterparties, structures with no identifiable beneficial owner or operations with red flags. The legal representative decides, and everything must be documented with date and time.
How is a suspicious operation reported to the UIAF?
The company files a suspicious operation report (ROS) with the UIAF through SIREL, the unit's online reporting system. A ROS is not a criminal complaint and does not require certainty that a crime occurred: it is enough that the operation fits the definition of suspicious. The report is confidential.
If a quarter passes with no ROS, the compliance officer files an absence-of-report notice (AROS) within ten calendar days after the quarter ends. When a counterparty appears on binding lists, the company must report it to the UIAF and inform the Attorney General's office. That is why sanctions list checks are continuous, a topic we cover in sanctions list screening for international payments.
Anyone dealing in virtual assets must take reasonable steps to identify the counterparty and the asset risks. Monitoring each payment complements that identification, as we explain in KYT and AML in payments.
Penalties, deadlines and how long SAGRILAFT applies
Failing to follow the chapter's instructions can lead to administrative investigations and sanctions against the company, its administrators, the compliance officer and the statutory auditor. The basis is article 86, item 3, of Law 222 of 1995, which allows successive or single fines of up to 200 monthly minimum wages, without prejudice to actions by other authorities.
The circular adds that, under article 313 of Law 2294 of 2023, the Superintendence sets fines in UVB, at the value in force when imposed.
Two calendar rules apply. A company that becomes obligated for the first time after 31 December 2026 must have the system running by 31 May of the following year. And a company that stops meeting the requirements remains obligated for two more years under the full system and one more year under the minimum measures regime. For those already obligated, the adjustment deadline is 31 May 2027.
What Soulbit V1 delivers on SAGRILAFT, and what it does not
Soulbit V1 does not implement your company's SAGRILAFT and does not replace your compliance officer: the system, the risk matrix and the UIAF reports are the duty of each obligated company. Soulbit applies controls to its own operation, and that can give your finance team useful information.
Today Soulbit V1 verifies business clients through KYB, applies transaction monitoring (KYT) and AML controls to the payments it processes, operates with institutional custody and offers human support. Each payment leaves a trace your team can use as accounting support and as input to due diligence on your own counterparties, as we describe in payment traceability for the accounting close and in what KYB is.
What Soulbit V1 does not deliver matters just as much. It does not certify your company's compliance, file UIAF reports on your behalf, draft your risk matrix or manual, or replace the due diligence you owe on your own customers and suppliers.
Does using Soulbit make my company SAGRILAFT-compliant?
No. A payments provider's controls cover the payments that pass through it, while your company's system covers all its counterparties, processes and decisions. Designing, approving and supervising that system remains the responsibility of your board, legal representative and compliance officer.
Frequently asked questions
Which companies must implement SAGRILAFT in Colombia?
Companies, single-shareholder enterprises and branches of foreign companies supervised by the Superintendence of Companies (Supersociedades) must implement it if their total revenue or total assets on 31 December of the prior year reached 4,929,017 UVB. Some sectors are covered from 3,696,762 UVB, under Circular 100-000020 of 2026.
Does a Colombian subsidiary of a foreign group need its own system?
Yes, if that Colombian entity is supervised by Supersociedades and meets a threshold, because the obligation attaches to the Colombian company or branch. The circular allows one compliance officer to serve every obligated entity of the same group, provided the officer is domiciled in Colombia.
What does UIAF stand for and what does it do?
UIAF is the Financial Information and Analysis Unit, Colombia's financial intelligence unit. It receives suspicious transaction reports (ROS) through its online platform, SIREL. A ROS is confidential and is not a criminal complaint.
Is SAGRILAFT still a separate regime from PTEE?
No. Circular 100-000020 of 2 July 2026 merged SAGRILAFT and PTEE, the corruption and transnational bribery programme, into one System in Chapter IX of the Basic Legal Circular. Companies already obligated must adjust by 31 May 2027, and their current systems stay valid until then.
What are the penalties for not implementing the system?
Supersociedades can open investigations and sanction the company, its administrators, the compliance officer and the statutory auditor, under article 86 of Law 222 of 1995. The circular states that fines are set in UVB, at the value in force when they are imposed.
Want your company to add stablecoins to its operations?
Join the Soulbit waitlist and start paying payroll, collecting and managing treasury without SWIFT.
Join the waitlist