SARLAFT vs SAGRILAFT in Colombia: Differences and Who Each One Covers
SARLAFT is run by entities supervised by the Financial Superintendence; SAGRILAFT by covered companies supervised by the Superintendence of Companies.
SARLAFT and SAGRILAFT prevent the same thing, money laundering and terrorist financing, but they do not bind the same parties and they are not supervised by the same authority. For a CFO at a foreign company that contracts with Colombian partners, the confusion is costly: a bank asks for one set of documents, a large client asks for another, and it is not clear who is asking for what.
At Soulbit Academy we compare the two systems: who supervises each, who it covers, what rule it rests on, what elements it requires and, above all, what each one asks of your company as a counterparty. We do not repeat SAGRILAFT thresholds here; they are in our guide to SAGRILAFT: which companies must comply and what to implement.
SARLAFT vs SAGRILAFT: the difference in one sentence
SARLAFT is the Money Laundering and Terrorist Financing Risk Management System run by entities supervised by the Financial Superintendence of Colombia, and SAGRILAFT is the equivalent self-control system for covered companies supervised by the Superintendence of Companies. The core difference is who implements it: a financial institution in one case, a company in the real economy in the other.
The rest follows from that. A financial institution handles other people's money, so its system centres on the client who opens a product and on the transactions that client moves. A real-economy company buys, sells and contracts, so its system centres on the counterparty: the client, the supplier, the distributor, the partner or the employee.
Both systems follow the same risk-management logic, have a compliance officer and lead to suspicious transaction reports sent to the UIAF, Colombia's Financial Information and Analysis Unit.
Who SARLAFT covers and who SAGRILAFT covers: supervisor and scope
SARLAFT covers entities under the supervision of the Financial Superintendence, such as banks, insurers and other financial-system entities, while SAGRILAFT covers companies, single-shareholder enterprises and branches of foreign companies supervised by the Superintendence of Companies that exceed the thresholds in its circular. A real-sector company does not implement SARLAFT; it would only do so if it also carried out an activity supervised by the Financial Superintendence. Confirm each case with your compliance officer.
One point matters to a CFO: SAGRILAFT is triggered by size. Being a supervised company is not enough; the company must exceed a revenue or asset threshold or belong to certain sectors. SARLAFT is triggered by nature: if the entity is supervised by the Financial Superintendence, the system is mandatory whatever its size.
| Criterion | SARLAFT | SAGRILAFT |
|---|---|---|
| Who implements it | Entities supervised by the Financial Superintendence of Colombia | Covered companies supervised by the Superintendence of Companies |
| What triggers it | The nature of the entity, with no size threshold | Exceeding revenue or asset thresholds, or belonging to certain sectors |
| Rulebook | Part I, Title IV, Chapter IV of the Financial Superintendence's Basic Legal Circular | Chapter IX of the Superintendence of Companies' Basic Legal Circular, after Circular 100-000020 of 2026 |
| Focus of due diligence | The client and its transactions at the entity | All counterparties: clients, suppliers, contractors, partners and employees |
| Who receives reports | UIAF | UIAF |
| Link to bribery and corruption | Not part of a business ethics programme | Merged with the PTEE into one system since July 2026 |
A company that opens an account at a bank is a client for the bank and falls under its SARLAFT. For its own buyers and suppliers it is a counterparty and falls under their SAGRILAFT. A foreign company dealing with Colombia will meet both.
Legal basis and elements of each system
SARLAFT is regulated in Part I, Title IV, Chapter IV of the Financial Superintendence's Basic Legal Circular, which develops articles 102 to 107 of the Financial System Organic Statute, and SAGRILAFT in Chapter IX of the Superintendence of Companies' Basic Legal Circular. According to the Financial Superintendence, entities must identify, measure, control and monitor risk through procedures documented in a manual.
Chapter IX of SAGRILAFT is new. Circular 100-000020 of 2026, dated 2 July 2026, introduced it and merged SAGRILAFT with the PTEE, the anti-corruption and transnational bribery programme, into the ML/TF/PF and C/TB Self-Control and Risk Management System. As of October 2026 it is the current reference, and companies already covered must adjust by 31 May 2027.
What elements does each system have?
Both share a risk-management structure, with their own vocabulary. SARLAFT brings together policies, procedures, an organisational structure with defined roles, a control body and technology to segment and monitor, plus training. SAGRILAFT brings together a policy, a manual, a risk matrix, due diligence, disclosure and training, and a compliance officer backed by the board.
The difference is in the detail. SARLAFT requires segmenting clients, products, channels and jurisdictions with technology tools. SAGRILAFT stresses that the system must reflect the real operation and not be a copied document.
What a bank asks of your company under SARLAFT
A bank asks your company for the documents that let it know the company as a client: who it is, who controls it, what it does, where its funds come from and what activity it expects. This is the know-your-client stage of SARLAFT. It happens before the product opens and repeats during the relationship.
In practice, a bank usually requests the following from a legal entity:
- An onboarding form with company data, activity and expected transactions.
- The certificate of existence and legal representation and the tax registration (RUT). A foreign company usually supplies the equivalent corporate registry extract, often apostilled and translated.
- ID of the legal representative and of any signatories.
- The ownership chain up to the beneficial owner, the natural person who exercises control.
- Financial statements and evidence of the origin of funds.
- A declaration on whether any shareholder or manager is a politically exposed person (PEP).
The Financial Superintendence does not set one closed list in the document we consulted: each entity defines its policy and form within the system. That is why two banks can ask for different lists and neither is in breach.
The bank also verifies the information against independent sources, checks binding lists and refreshes the data periodically. If the ownership, the legal representative or the type of transactions change, the sensible course is to tell the bank before it notices. An outdated profile can lead to blocks or to the end of the relationship.
Does the bank report to the UIAF if something does not add up?
Yes. The bank, as a supervised entity, sends the UIAF the suspicious transaction reports it detects in its clients' activity, and those reports are confidential: the bank cannot tell your company a report was made. Your best defence is a transaction profile consistent with your business and documents that support it.
What a SAGRILAFT-covered company asks of its suppliers and clients
A company covered by SAGRILAFT must apply due diligence to its counterparties, meaning its clients, suppliers, contractors and partners, by identifying them, learning their beneficial owner and understanding the purpose of the relationship. This sets it apart from a bank: the company watches not only who buys from it but also who it buys from.
The Financial Superintendence states that, for SARLAFT, suppliers and contractors are not clients. Under SAGRILAFT they are counterparties. A foreign company that has no Colombian obligation of its own can still receive a request from a large Colombian client as detailed as a bank's.
| Aspect | What a bank asks (SARLAFT) | What a covered company asks (SAGRILAFT) |
|---|---|---|
| Who is asked | The client it onboards | Clients, suppliers, contractors and other counterparties, by risk |
| Identification | Form, certificate of existence and legal representation, RUT and ID of the legal representative | Equivalent documents, as set by its policy |
| Beneficial owner | Ownership chain up to the controlling natural person | The same, with enhanced due diligence if it cannot be identified |
| Origin of funds | Declaration and evidence of the origin of funds and of the activity | Purpose of the commercial relationship and consistency of transactions |
| Binding lists | Checked at onboarding and continuously | Checked continuously, with a report to the UIAF on a match |
| Follow-up | Periodic update and transaction monitoring | Monitoring of transactions throughout the relationship |
A hypothetical example helps. A US software company bills a Colombian retail group covered by SAGRILAFT and also opens an account at a Colombian bank. The bank asks for its onboarding form and beneficial ownership. The client, before paying the first invoice, asks for the certificate of incorporation, the shareholder IDs and a list check. The documents almost overlap, and keeping them in one file avoids preparing the same package twice. This is an illustrative assumption, not a real case.
How to handle both regimes in practice
A single compliance file, with one current version of the corporate documents and the beneficial ownership chain, lets a company answer the bank and corporate clients with the same evidence. The same package answers the bank and the corporate clients, and each update is done once.
Five practices keep the work in order:
- Check whether your Colombian entity exceeds the Superintendence of Companies thresholds, using the financial statements at 31 December. The procedure is in the guide to covered companies.
- Keep a current file with the certificate of existence, tax ID, shareholder and legal representative IDs and financial statements.
- Document the beneficial owner and tell your bank and clients if it changes.
- Align the transaction profile with the real activity, because a sharp change triggers the alerts of any system.
- Apply due diligence to your own suppliers and clients, with a written procedure and list checks, as we explain in sanctions list screening in international payments.
The PTEE appears here only in passing: since July 2026 it shares a system with SAGRILAFT, so due diligence on a counterparty can cover money-laundering and bribery risk in one file. For PTEE detail, read the circular.
If your company moves international payments, the same file supports monitoring of each transaction. How that monitoring works is in KYT and AML in payments, and how a company is verified in what KYB is.
What Soulbit V1 delivers regarding SARLAFT and SAGRILAFT, and what it does not
Soulbit V1 does not comply with SARLAFT or SAGRILAFT on your company's behalf: both systems are obligations of each covered party, with its own compliance officer and risk matrix. Soulbit applies controls to its own operation, and that can give your finance team useful information.
Today Soulbit V1 verifies client companies through KYB, applies transaction monitoring (KYT) and AML controls to the payments it processes, operates with institutional custody and offers human support. Each payment leaves a trace your team can use to support its own due diligence.
What Soulbit V1 does not deliver matters just as much. It does not issue compliance certifications for your company, does not report to the UIAF on your behalf, does not draft your manual or risk matrix, does not replace the due diligence you must run on your counterparties and does not answer to a bank for the information you provide.
Does using Soulbit stop my bank from asking for documents?
No. The bank applies its own SARLAFT and will keep asking for what its policy requires, whatever the controls of any other payments provider. Soulbit V1 does not change that relationship or your company's obligations.
Frequently asked questions
What is the difference between SARLAFT and SAGRILAFT?
SARLAFT is the anti-money-laundering system run by entities supervised by the Financial Superintendence of Colombia, such as banks. SAGRILAFT is the system that covered companies supervised by the Superintendence of Companies must implement. Both prevent money laundering and terrorist financing, but the supervisor, the rulebook and the scope differ.
Does a Colombian company have to implement SARLAFT?
As a rule, no. SARLAFT is an obligation of entities supervised by the Financial Superintendence, not of a company in the real economy. What a company usually experiences is its bank's SARLAFT, which asks it for information as a client. A company above the Superintendence of Companies thresholds has a different duty: SAGRILAFT.
Why does a Colombian bank ask a foreign company for so many documents?
Because the bank, as a supervised entity, must know its clients, verify their information and monitor their transactions under its SARLAFT. That is why it asks for corporate records, the legal representative's ID, beneficial ownership details and the origin of funds. Declining to provide them can limit or end the relationship.
Is a supplier a client for SARLAFT purposes?
No. The Financial Superintendence states that, for SARLAFT, an entity's employees, suppliers and contractors are not considered clients. Under SAGRILAFT, however, a covered company treats clients, suppliers and contractors alike as counterparties and applies due diligence to them.
What does a SAGRILAFT-covered company ask its suppliers for?
It typically asks for proof of legal existence and representation, ID of the legal representative, the ownership chain up to the beneficial owner, the purpose of the commercial relationship and a check against binding sanctions lists. The scope depends on the risk of each counterparty and on the company's own due diligence policy.
Want your company to add stablecoins to its operations?
Join the Soulbit waitlist and start paying payroll, collecting and managing treasury without SWIFT.
Join the waitlist