Colombia SFC publishes GERCO draft
Colombia’s Financial Superintendence opened the GERCO draft for comments until Sept. 15.
Colombia’s Financial Superintendence published Draft External Circular 14 of 2026, setting instructions for managing conduct risk that affects financial consumers. Comments are due by Sept. 15 at 5:00 p.m., while the agency also shared notices on open finance and supervised innovation.
Colombia’s Financial Superintendence published Draft External Circular 14 of 2026, which sets instructions for managing conduct risk that affects financial consumers, known as GERCO. The agency opened the text for public comment until Sept. 15 at 5:00 p.m. At the same time, it also circulated notices on open finance information exchange standards and on its controlled experimentation framework.
What does the GERCO proposal set out?
The draft reorganizes how conduct risk is handled and, according to the CERLATAM analysis cited, separates it from the prior SARCO framework to place it in an autonomous chapter within the management of conduct risk affecting the financial consumer. That approach, according to the same analysis, is preventive, proportional, and covers the entire product lifecycle, including digital channels and third parties.
The Superintendence’s official publication was not accompanied in the material by the full text of the instructions, but it did include notice that the document is available for public comment. CERLATAM also said the Financial Superintendence clarifies that not every operational or technology failure will be treated as a GERCO event, only those linked to conduct or practices that affect the consumer or the market.
Who would the regulatory changes apply to?
CERLATAM’s analysis says the draft introduces an explicit list of supervised entities required to implement the new conduct risk management scheme. The material does not spell out all of those entities here, but it does indicate that the scope would not be generic, instead limited by that regulatory list.
On another front, the Financial Superintendence said on its official X account that Sept. 15 is the deadline to comment on information exchange standards in the open finance system. In that message, it asked readers to review the draft rule and send comments before 5:00 p.m.
How does this fit with innovation and cyber supervision?
The Financial Superintendence also said controlled experimentation strengthens oversight of financial innovation. In that text, it explained that the SFC Sandbox serves as an experimentation space to understand changes in financial product and service models, identify risks, and generate evidence useful for supervision and regulation.
That regulatory move comes as the banking sector, according to Asobancaria’s 2025 Sectoral Management Report cited by El Universal, increased spending on digital transformation, innovation, and cybersecurity. The report also said 65.7% of the banking sector reported using artificial intelligence, machine learning, or other advanced analytics tools for early threat detection, up 13.6 percentage points from 2024.
Outside the regulatory sphere, the market is also keeping a close watch on data protection and fraud. Radar Tecnológico said, citing the 2026 Financial Agenda, that Colombia sees 997 data thefts, 63 identity theft cases, and 94 cyberattacks per second against banking entities every day, although the note did not provide methodological details on how those figures were measured.
What do compliance and traceability schemes require today?
Different technical materials on financial compliance in Colombia agree that traceability is the core of controls. Piranirisk said the SAGRILAFT and SARLAFT 2.0 frameworks require full traceability of sanctions list and PEP checks, with tamper-proof audit logs showing who reviewed each alert, what justification was attached, and what final decision was made.
The same analysis added that anti-money laundering compliance solutions should automatically synchronize international lists such as OFAC and the UN, without manual uploads, and generate regulatory reports that can show the Financial Superintendence and the UIF the full history of analysis, decisions, and evidence tied to each alert. Amezquita, meanwhile, recommended that entities subject to the regime keep manuals, risk matrices, due diligence evidence, monitoring records, reports to authorities, and training materials.
Amezquita’s material also suggested that after each SARLAFT report, entities maintain tracking dashboards documenting the finding, priority level, responsible area, action, target date, status, pending evidence, and closing date. In the same vein, Nequi told Semana that under its new structure it is a supervised entity by the Financial Superintendence and that user deposits are backed by Fogafín’s deposit insurance, while Noticias Caracol reported that the company is now formally operating as Nequi S.A. Compañía de Financiamiento.
Sources
- Publicación en X sobre estándares de intercambio de información en finanzas abiertasx.com· Superintendencia Financiera de Colombia
- 8 claves para elegir software AML en financieras 2026piranirisk.com· Piranirisk
- Colombia enfrenta una nueva generación de fraude financieroradartecnologico.com· Radar Tecnológico
- Superintendencia Financiera de Colombia, Proyecto de Circular Externa 14-2026cerlatam.com· CERLATAM
- Informe del revisor fiscal sobre SARLAFT: revisión y controlamezquita.com.co· Amezquita
- La experimentación controlada fortalece la supervisión de la innovación financierasuperfinanciera.gov.co· Superintendencia Financiera de Colombia
- Proyecto de Circular Externa 14 - 2026superfinanciera.gov.co· Superintendencia Financiera de Colombia
- Un Estudio del Comercio Electrónico en Colombia para 2026todoecommerce.com· Todoecommerce
- Nequi se separa de Bancolombia hoy: la entidad explica qué cambiará para los usuariosnoticiascaracol.com· Noticias Caracol
- Nequi se transforma desde hoy y responde a la principal duda de sus usuarios: cuidado con los ataquessemana.com· Semana
- Bancos invirtieron $3,6 billones en innovación digital y ciberseguridad en 2025eluniversal.com.co· El Universal



