CiberLATAMbywhalemate

Colombia tightens financial security rules

Superfinanciera names new internal leaders and advances a regulatory agenda covering open finance and digital identity.

Whalemate Labs · AI-assisted researchPublished:3 min read

In August 2026, Colombia’s Financial Superintendence formalized internal appointments for information security, business continuity, personal data protection and compliance, while advancing a regulatory agenda that covers open finance, identity spoofing and compliance systems for supervised firms.

New internal roles at the Superfinanciera

In August 2026, Colombia’s Financial Superintendence published in the Minhacienda Bulletin, Superintendence chapter, the appointment of the people responsible for the Information Security and Business Continuity Officer role, the Personal Data Protection Officer role, and the Compliance function inside the agency itself. The notice appears as Bulletin 827, dated August 11, 2026, and provides the official backdrop for the agency’s internal moves and regulatory agenda.

The Superintendence’s 2026 resolutions page also confirms that Resolution 0877 of June 11, 2026 created the Information Security and Business Continuity Officer and Personal Data Protection Officer positions, and adopted the compliance function within the institution.

Open finance, risk and data

At the same time, the Financial Superintendence put External Circular Draft 10 of 2026 out for comment to update the rules for the Open Finance System in line with Decree 368 of 2026, with new instructions on risk management, information security, data handling and incident reporting for supervised entities operating open finance schemes, according to an analysis published by Ladob.

That same analysis says supervised entities already operating use cases under External Circular 004 of 2024 would have until April 7, 2027 to align with the new instructions. That deadline appears in regulatory summaries cited by the outlet, although the detail remains pending official confirmation in the available draft text.

Impersonation and new obligations

Law 2573 of 2026 also reshapes the digital security front. Colombian national media describe the statute as raising digital security standards and creating a dynamic burden of proof in identity spoofing cases tied to financial transactions, giving affected consumers more tools in credit fraud cases.

Baker McKenzie adds that the law strengthens protections against identity theft by imposing new obligations on financial institutions to suspend collection actions once notified of a presumed spoofing claim, along with verification and documentation duties. The same analysis says financial institutions, telecom providers and merchants must implement digital security measures and reasonable identity verification mechanisms, and process spoofing complaints within 10 business days.

Unified SAGRILAFT-PTEE system

On the corporate compliance side, Baker McKenzie reported that the new Basic Legal Circular issued by the Superintendence of Companies on July 2, 2026 expressly repealed the previous SAGRILAFT and PTEE regimes, along with all amending circulars issued between 2020 and 2024. According to the same analysis, the unified compliance system for money laundering, terrorist financing, proliferation financing, corruption and bribery took effect upon publication.

The firm also said the new framework requires companies and branches of foreign companies subject to the Superintendence of Companies’ oversight or control that meet certain thresholds, now set at 4,929,017 UVB in annual income or assets. Entities already covered under the former regimes would have until May 31, 2027 to adapt to the integrated system.

Taken together, the measures leave banks, subsidiaries of regional groups and other supervised entities facing tighter requirements across information security, data protection, anti-fraud controls and corporate compliance programs.

Sources

View all