CiberLATAMbywhalemate

Colombia tightens financial oversight

The Financial Superintendency opened a regulatory proposal, while DIAN added new cryptoasset reporting requirements.

Whalemate Labs · AI-assisted researchPublished:3 min read

Colombia’s Financial Superintendency published External Circular Draft 13 of 2026 and opened it to public comment through August 14, alongside an update to the Basic Financial Circular. On the crypto side, DIAN activated new reporting requirements starting with the 2026 tax year, while the Bank of the Republic said no significant incidents materialized on its platform during 2025-2026.

Colombia’s Financial Superintendency published External Circular Draft 13 of 2026 and opened it to outside comment until Friday, August 14 at 11:59 p.m., with submissions to normativa@superfinanciera.gov.co through a specific template. At the same time, the Bank of the Republic reported that between July 1, 2025 and June 30, 2026, no significant incidents materialized against its technology platform or the data hosted on it.

What is the Financial Superintendency’s regulatory proposal aiming to do?

External Circular Draft 13 of 2026 is intended to mitigate the effects tied to the national disaster situation declared under Decree 1171 of August 11, 2026, with instructions linked to operational risk management and continuity for supervised entities. The public filing identified the formal participation channel and kept the window for external comments open for a limited period.

The official text of the initiative and the summary from the Regulatory Studies Center both said the publication was made on August 13, 2026. vLex also logged the draft as Normatividad 13_2026 and confirmed the comment deadline. Finance Colombia, meanwhile, noted that the Superintendency typically processes its circular drafts through a specific filing and submission by institutional email, a mechanism that appears again in this case.

How are financial and information security matters moving?

The current version of the Basic Financial Circular, identified as External Circular 004 of 2026, was amended on August 12, 2026, introducing recent adjustments to the prudential framework applicable to supervised entities. The available material does not spell out the full scope of those changes, but places them within the broader regulatory movement around information security, risk management and operational compliance.

During the same period, the Bank of the Republic maintained in its general information security policy that there were no significant incidents on its platform or in its data during the reported period. That detail appears on its transparency portal and serves as an institutional reference point for the state of its technology exposure during that window.

What changed for cryptoassets in Colombia?

DIAN now requires reporting on cryptoasset operations, purchases, sales and holdings starting with tax year 2026, increasing information burdens for local providers tied to financial activity with virtual assets. Infobae Colombia also reported that the first filing under Resolution 000240 of 2025 is scheduled for May 2027.

The same outlet said that bill 510 of 2025, which sought a specific regulatory framework for service platforms with cryptoassets, was shelved under Article 190 of Law 5 of 1992, according to the official Chamber of Representatives record cited in its coverage. It also noted that the Financial Superintendency reiterated that it does not regulate, supervise, endorse or authorize businesses based on cryptoassets.

Infobae added that Colombia still has no special tax definition for cryptoassets or exclusive valuation method, leaving practical uncertainty for entities operating in the country. The outlet framed that as a tension between tougher reporting requirements and a framework that remains incomplete for the activity.

What other compliance fronts weigh on virtual asset providers?

Beyond DIAN’s tax framework, Colombia’s regime also includes anti-money laundering obligations for virtual asset service providers domiciled in the country or operating there. Cryptoveritas 360 said UIAF Resolution 314 of 2021 already requires suspicious activity reports and virtual asset transaction reports for VASPs, including exchanges between virtual assets and fiat currency, virtual asset-to-virtual asset exchanges, transfers, custody or administration.

The same analysis added that, alongside the CARF framework adopted by DIAN, there are also exogenous information reporting obligations for certain VASPs on conversions between legal tender and digital assets. Taken together, the regulatory picture leaves firms in the sector with two simultaneous compliance fronts, tax and anti-money laundering, while the debate over comprehensive supervision remains open.

Sources

View all