CiberLATAMbywhalemate

Colombia tightens fiduciary risk controls

Colombia opens a public consultation on identity validation while Decree 510 imposes new fiduciary risk reporting duties.

Whalemate Labs · AI-assisted researchPublished:2 min read

Colombia’s Superintendency of Industry and Commerce opened a public consultation on identity validation and personal data protection, while Decree 510 strengthens fiduciary firms’ duties to document, classify and report fiduciary risks. At the same time, the Financial Superintendency warned about impersonation schemes and fake representatives.

Colombia’s Superintendency of Industry and Commerce has opened a public consultation on identity validation and personal data protection, while Decree 510 has expanded the obligations of fiduciary firms to document and report risks. At the same time, the Financial Superintendency warned about impersonation schemes and fake representatives, putting fraud, identity, and document control at the center of the regulatory agenda.

What changed with Decree 510 for fiduciary firms?

Decree 510 introduced a new framework into Colombia’s fiduciary regime and requires fiduciary firms to maintain a documented analysis of fiduciary risks from the pre-contract stage, through contract execution, and until liquidation. That analysis must identify and classify risks by asset type, assess likelihood and impact, define treatments, establish control and mitigation measures, and report the results to corporate governance bodies.

Recent guidance cited by LexLatin and Notaría 19 de Bogotá agrees that the reform now clearly separates fiduciary risks from non-fiduciary risks. The first are tied to the fiduciary service and the company’s compliance obligations, while the second cover the risks inherent in the underlying business.

That shift has a direct impact on the operational risk management models used by supervised entities. It also makes the fiduciary risk analysis tool a central element of the new regulation, subject to approval and oversight by Colombia’s Financial Superintendency.

What does the SIC consultation on identity seek?

The SIC public consultation aims to strengthen identity validation and personal data protection, with an explicit goal of preventing identity theft. Public participation remains open until September 25, 2026, in a short regulatory window focused on fraud and authentication.

Baker McKenzie also outlined the implementation schedule. The consultation phase runs from September 8 to 25, 2026, participant selection will take place from September 28 to October 2, working sessions are scheduled for October 5 to 16, the proposed protocol will be published on November 2, and the final regulation will be issued on November 20, 2026.

What did the Financial Superintendency warn about?

The Financial Superintendency issued public warnings about impersonation cases and fake representatives who present themselves as acting on behalf of the agency. According to alerts reported by Legal Abogados and Semana, the cases include offers for supposed loans, credit cards, and other financial products.

The recommendations focus on strengthening third-party validation, payments, and document handling inside companies, along with avoiding the disclosure of personal or financial information or making transfers when offers of that kind appear. Coinfomania also reported that the authority has issued alerts about high-yield investment promises, with extraordinary returns in a short period, as part of the same fraud and impersonation prevention effort.

Sources

View all