Colombia tightens financial oversight
The Financial Superintendency opened a regulatory proposal, while DIAN added new cryptoasset reporting requirements.
Colombia’s Financial Superintendency published External Circular Draft 13 of 2026 and opened it to public comment through August 14, alongside an update to the Basic Financial Circular. On the crypto side, DIAN activated new reporting requirements starting with the 2026 tax year, while the Bank of the Republic said no significant incidents materialized on its platform during 2025-2026.
Colombia’s Financial Superintendency published External Circular Draft 13 of 2026 and opened it to outside comment until Friday, August 14 at 11:59 p.m., with submissions to normativa@superfinanciera.gov.co through a specific template. At the same time, the Bank of the Republic reported that between July 1, 2025 and June 30, 2026, no significant incidents materialized against its technology platform or the data hosted on it.
What is the Financial Superintendency’s regulatory proposal aiming to do?
External Circular Draft 13 of 2026 is intended to mitigate the effects tied to the national disaster situation declared under Decree 1171 of August 11, 2026, with instructions linked to operational risk management and continuity for supervised entities. The public filing identified the formal participation channel and kept the window for external comments open for a limited period.
The official text of the initiative and the summary from the Regulatory Studies Center both said the publication was made on August 13, 2026. vLex also logged the draft as Normatividad 13_2026 and confirmed the comment deadline. Finance Colombia, meanwhile, noted that the Superintendency typically processes its circular drafts through a specific filing and submission by institutional email, a mechanism that appears again in this case.
How are financial and information security matters moving?
The current version of the Basic Financial Circular, identified as External Circular 004 of 2026, was amended on August 12, 2026, introducing recent adjustments to the prudential framework applicable to supervised entities. The available material does not spell out the full scope of those changes, but places them within the broader regulatory movement around information security, risk management and operational compliance.
During the same period, the Bank of the Republic maintained in its general information security policy that there were no significant incidents on its platform or in its data during the reported period. That detail appears on its transparency portal and serves as an institutional reference point for the state of its technology exposure during that window.
What changed for cryptoassets in Colombia?
DIAN now requires reporting on cryptoasset operations, purchases, sales and holdings starting with tax year 2026, increasing information burdens for local providers tied to financial activity with virtual assets. Infobae Colombia also reported that the first filing under Resolution 000240 of 2025 is scheduled for May 2027.
The same outlet said that bill 510 of 2025, which sought a specific regulatory framework for service platforms with cryptoassets, was shelved under Article 190 of Law 5 of 1992, according to the official Chamber of Representatives record cited in its coverage. It also noted that the Financial Superintendency reiterated that it does not regulate, supervise, endorse or authorize businesses based on cryptoassets.
Infobae added that Colombia still has no special tax definition for cryptoassets or exclusive valuation method, leaving practical uncertainty for entities operating in the country. The outlet framed that as a tension between tougher reporting requirements and a framework that remains incomplete for the activity.
What other compliance fronts weigh on virtual asset providers?
Beyond DIAN’s tax framework, Colombia’s regime also includes anti-money laundering obligations for virtual asset service providers domiciled in the country or operating there. Cryptoveritas 360 said UIAF Resolution 314 of 2021 already requires suspicious activity reports and virtual asset transaction reports for VASPs, including exchanges between virtual assets and fiat currency, virtual asset-to-virtual asset exchanges, transfers, custody or administration.
The same analysis added that, alongside the CARF framework adopted by DIAN, there are also exogenous information reporting obligations for certain VASPs on conversions between legal tender and digital assets. Taken together, the regulatory picture leaves firms in the sector with two simultaneous compliance fronts, tax and anti-money laundering, while the debate over comprehensive supervision remains open.
Sources
- SuperFinanciera, Proyecto de Circular Externa, 13-ago-26cerlatam.com· Centro de Estudios Regulatorios (CERLATAM)
- Colombia's Financial Regulator Proposes Emergency Relief Rules For Earthquake-Affected Borrowers And Insurance Claimantsfinancecolombia.com· Finance Colombia
- Compra y venta de criptomonedas en Colombia seguirá sin reglas claras, pero con la Dian encima haciendo controlesinfobae.com· Infobae Colombia
- Proyecto de Normatividad num. 13_2026, Superintendencia Financieravlex.com.co· vLex Colombia
- Colombia Strengthens Controls Against Identity Theftbakermckenzie.com· Baker McKenzie
- Circular Básica Financiera (Circular Externa 004 de 2026)superfinanciera.gov.co· Superintendencia Financiera de Colombia
- Ley 2573: identidad digital como estándar obligatorio en Colombialatinpyme.com· Latinpyme
- Colombia - Cryptoveritas 360cryptoveritas360.com· Cryptoveritas 360
- Proyecto de Circular Externa 13 - 2026superfinanciera.gov.co· Superintendencia Financiera de Colombia
- Política general de seguridad de la informaciónbanrep.gov.co· Banco de la República de Colombia
- PSAV en Colombia | UIAF, SAGRILAFT y Cumplimiento Criptocryptoveritas360.com· Cryptoveritas 360



