Colombia: FNA and SFC update controls
FNA said it complies with Colombia’s risk rules, while the SFC issued a draft circular on global guarantees and ordered Fundación FG suspended.
The National Savings Fund said it complies with the Basic Financial Circular on its Integrated Risk Management System, and that it manages information security under the Financial Superintendency’s Basic Legal Circular and Decree 1008 of 2018. At the same time, Colombia’s Financial Superintendency published a draft circular on global guarantee schemes and ordered Fundación FG suspended for unauthorized fundraising.
The National Savings Fund, or FNA, said it complies with the Basic Financial Circular regarding its Integrated Risk Management System, and that it manages information security under the Financial Superintendency of Colombia’s Basic Legal Circular and Decree 1008 of 2018 on Digital Government policy. The disclosure appears in its institutional risk section and is dated 2026-09-08.
What did the Financial Superintendency publish on global guarantees?
Colombia’s Financial Superintendency published Draft External Circular 15 of 2026, with instructions on global guarantee schemes for supervised guarantee funds. It also opened an external comments channel through normativa@superfinanciera.gov.co, according to its official notice dated 2026-09-11.
That move adds to the updated obligations supervised entities face in risk governance and compliance evidence. In this case, the focus is on guarantee funds and how they document and manage their backing arrangements.
What did the Superintendency order Fundación FG to do?
The Financial Superintendency ordered Fundación FG, Administrador de Fideicomisos Civiles, to suspend unauthorized fundraising activities, as part of its supervisory duties over the financial sector and protection of financial consumers. The order was disclosed by the regulator itself on 2026-09-09.
The measure reinforces that supervision is not limited to technical guidance, but also includes intervention against operations the regulator considers unauthorized. In the same period, the supervisor combined a rulemaking proposal and a suspension order, two different signals about control of the financial perimeter.
What do the technical requirements mean for financial APIs?
The technical material cited says that, under regulatory frameworks such as those applied to open finance in Colombia, APIs that can move money, change identity status, or modify customer permissions must include strong authentication, least-privilege authorization, TLS encryption, network controls, and detailed event logging.
Among the measures mentioned by SysgenPro and NHIMG are OAuth 2.0 with client credentials, mTLS, IP whitelists, and full traceability of access and authorization events. The point is for those safeguards to demonstrate compliance and preserve evidence that can be used when the supervisor requests it.
The combination of robust authentication, permission control, and detailed logging is meant to reduce fraud exposure and support audits of data and payment flows. For financial institutions, the technical standard is no longer limited to connectivity, it also requires documentary proof of what each API allowed and when it did so.
Sources
- Proyecto de Circular Externa 15 - 2026superfinanciera.gov.co· Superintendencia Financiera de Colombia
- Finance API Integration Controls for Audit-Ready Data Flowssysgenpro.com· SysgenPro
- Colombia: SIC Opens Consultation on Identity Verification Systemsbakermckenzie.com· Baker McKenzie
- Consulta pública SIC Colombia 2026: refuerzo de validación de identidad y protección de datospulzo.com· Pulzo
- Riesgos institucionales - FNAfna.gov.co· Fondo Nacional del Ahorro
- Ley 2573 de 2026: nuevas medidas frente a la suplantación de identidadafic.com.co· AFIC
- Circular 004 de 2024 SFC: guía de cumplimientoopensurix.com· Opensurix
- Boletín 8 de 2026 – Circular Reglamentaria Externa DSP-465banrep.gov.co· Banco de la República de Colombia
- Why do insecure APIs create regulatory and operational risk in digital payments?nhimg.org· NHIMG
- Noticias – orden de suspensión a Fundación FG – Administrador de Fideicomisos Civilessuperfinanciera.gov.co· Superintendencia Financiera de ColombiaUnverified URL
- Colombia’s Data Protection Reform: What Reclassifying Biometrics as Sensitive Data Means for Banksfacephi.com· Facephi Observatory
- Law 2573 Compliance: A 2026 Guide for Banksfeedzai.com· Feedzai
- Reforma Ley 1581: biometría como dato sensiblefacephi.com· Facephi Observatory



