CiberLATAMbywhalemate

Colombia: FNA and SFC update controls

FNA said it complies with Colombia’s risk rules, while the SFC issued a draft circular on global guarantees and ordered Fundación FG suspended.

Whalemate Labs · AI-assisted researchPublished:2 min read

The National Savings Fund said it complies with the Basic Financial Circular on its Integrated Risk Management System, and that it manages information security under the Financial Superintendency’s Basic Legal Circular and Decree 1008 of 2018. At the same time, Colombia’s Financial Superintendency published a draft circular on global guarantee schemes and ordered Fundación FG suspended for unauthorized fundraising.

The National Savings Fund, or FNA, said it complies with the Basic Financial Circular regarding its Integrated Risk Management System, and that it manages information security under the Financial Superintendency of Colombia’s Basic Legal Circular and Decree 1008 of 2018 on Digital Government policy. The disclosure appears in its institutional risk section and is dated 2026-09-08.

What did the Financial Superintendency publish on global guarantees?

Colombia’s Financial Superintendency published Draft External Circular 15 of 2026, with instructions on global guarantee schemes for supervised guarantee funds. It also opened an external comments channel through normativa@superfinanciera.gov.co, according to its official notice dated 2026-09-11.

That move adds to the updated obligations supervised entities face in risk governance and compliance evidence. In this case, the focus is on guarantee funds and how they document and manage their backing arrangements.

What did the Superintendency order Fundación FG to do?

The Financial Superintendency ordered Fundación FG, Administrador de Fideicomisos Civiles, to suspend unauthorized fundraising activities, as part of its supervisory duties over the financial sector and protection of financial consumers. The order was disclosed by the regulator itself on 2026-09-09.

The measure reinforces that supervision is not limited to technical guidance, but also includes intervention against operations the regulator considers unauthorized. In the same period, the supervisor combined a rulemaking proposal and a suspension order, two different signals about control of the financial perimeter.

What do the technical requirements mean for financial APIs?

The technical material cited says that, under regulatory frameworks such as those applied to open finance in Colombia, APIs that can move money, change identity status, or modify customer permissions must include strong authentication, least-privilege authorization, TLS encryption, network controls, and detailed event logging.

Among the measures mentioned by SysgenPro and NHIMG are OAuth 2.0 with client credentials, mTLS, IP whitelists, and full traceability of access and authorization events. The point is for those safeguards to demonstrate compliance and preserve evidence that can be used when the supervisor requests it.

The combination of robust authentication, permission control, and detailed logging is meant to reduce fraud exposure and support audits of data and payment flows. For financial institutions, the technical standard is no longer limited to connectivity, it also requires documentary proof of what each API allowed and when it did so.

Sources

View all