Skip to content
    AZC Legal
    From SAGRILAFT and PTEE to an Integrated System: What Changes for Companies in 2026?
    Back to Legal News

    From SAGRILAFT and PTEE to an Integrated System: What Changes for Companies in 2026?

    Also available in Spanish:Leer en español

    The new Circular from the Superintendencia de Sociedades seeks to ensure that companies do not limit themselves to having policies and manuals "on paper," but rather truly apply controls to prevent risks related to money laundering, terrorist financing, corruption, and bribery. This implies better knowledge of clients, suppliers, and other third parties, identifying who is behind the companies with which business is conducted, strengthening the role of the Compliance Officer, and leaving evidence that controls are indeed applied. In short, companies must adapt their prevention processes to their reality and demonstrate that compliance is part of their daily operations.

    Share article

    New challenges in corporate compliance: External Circular 100-000020 of 2026 from the Superintendencia de Sociedades

    Corporate compliance management continues to evolve as a fundamental element for the protection and sustainability of organizations. With the issuance of External Circular 100-000020 of 2026 from the Superintendencia de Sociedades, relevant changes are introduced regarding the prevention and management of risks associated with money laundering (ML), terrorist financing (TF), financing of the proliferation of weapons of mass destruction (FP), local corruption (C), and transnational bribery (ST).

    This article will address the main changes introduced by this new regulation and its impact on the corporate compliance model. The Circular proposes an evolution in the way organizations must manage these risks, strengthening the risk-based approach and promoting compliance systems tailored to the specific characteristics of each company.

    Throughout the article, we will analyze the main adjustments incorporated by the new regulation, the economic sectors subject to these obligations and the related CIIU codes, the modifications to compliance systems, the new challenges for administrators and compliance officers, as well as the actions that companies must implement to strengthen their prevention models.


    1. Obligated subjects

    Regarding obligated subjects, the Circular establishes that the Integrated System of Self-Control and Risk Management LA/FT/FP and C/ST must be implemented by commercial companies and branches of foreign companies subject to the supervision or control of the Superintendencia de Sociedades, provided they are not supervised by another entity and meet the criteria established in the regulation, whether due to their income or asset levels, or because they belong to certain economic sectors.

    For the general regime, the obligation applies when total income or total assets are equal to or greater than 4,929,017 UVB, equivalent to approximately COP 59,690 million for 2026. Additionally, the Circular establishes specific obligations for companies in certain sectors that, due to the nature of their activities, have a particular exposure to these risks. These include:

    • Real estate activities — CIIU 6810 and 6820
    • Trading of precious metals and stones — CIIU 4662, 0722, 3211, and 2421
    • Legal services — CIIU 6910
    • Accounting services — CIIU 6920
    • Vehicle trade — CIIU 4511, 4512, and G4541
    • Contributions in virtual assets — when equal to or greater than, individually or in the aggregate, 12,323 UVB
    • Special supervision sectors:
      • Commercial Self-Financing Plan Management Companies
      • Payroll Deduction Operating Companies
      • Companies engaged in Multilevel Marketing Activities
      • Cattle funds
      • Companies engaged in factoring activities

    On the other hand, the Circular maintains a Minimum Measures Regime applicable to certain sectors with a different level of exposure. This regime applies, among others, to activities such as real estate, legal services, accounting services, vehicle trade, pharmaceutical, construction, manufacturing, and mining-energy, when they meet lower economic requirements: income equal to or greater than 369,676 UVB (approximately COP 4,475 million) or assets equal to or greater than 616,127 UVB (approximately COP 7,460 million).

    The difference between these two regimes lies in the fact that the Self-Control and Risk Management System requires a more robust risk management structure, while the Minimum Measures Regime allows for simplified controls, but equally requires counterparty due diligence measures, identification of beneficial owners, training, and prevention mechanisms.


    2. New challenges for companies regarding the strengthening of compliance systems

    The new regulation is based on a fundamental premise: corporate compliance cannot be limited to so-called "paper compliance," understood as the formal existence of manuals, risk matrices, or internal policies, but must be consolidated as an active system of identification, evaluation, control, and ongoing monitoring of the risks to which each organization is exposed.

    Under this new approach, the Superintendencia de Sociedades requires that compliance systems respond to the specific reality of each company, considering factors such as the economic activity carried out, the sector to which it belongs, the jurisdictions where it operates, the characteristics of its counterparties, its products, services, and distribution channels. Consequently, one of the main challenges for companies will be to abandon standardized models or generic documents and build systems that are truly aligned with their particular risks and with the way they conduct their business.

    This change represents a cross-cutting challenge for organizations, as it involves not only the legal or compliance area but also the financial, commercial, purchasing, contracting, and administrative areas. Internal processes must be reviewed to ensure that risk identification and management is present in the company's strategic and operational decisions.

    In this context, due diligence acquires greater relevance. It will no longer be sufficient to have basic identification information; it will be necessary to move toward processes that allow verifying the identity of counterparties, knowing their ownership structure, identifying beneficial owners, and understanding the purpose of the business relationship.

    Companies must strengthen their processes for knowing clients, suppliers, contractors, partners, and other third parties with whom they maintain commercial or legal relationships, especially when there are factors that may increase risk exposure.

    Likewise, the independence and relevance of the Compliance Officer within the corporate structure is strengthened. The new regulation requires that obligated subjects have a principal Compliance Officer and an alternate, who must have the conditions of suitability, autonomy, sufficient access to information, and the necessary capabilities to carry out their functions effectively.

    This change represents a challenge for organizations, as it implies ensuring an adequate compliance structure, with clearly defined responsible parties and the real capacity to supervise, implement, and strengthen established controls. In this way, risk management ceases to be the exclusive responsibility of a specific area and becomes an essential component of corporate governance, where senior management must actively participate in building a culture of compliance.

    The Circular also establishes greater requirements regarding internal policies related to transparency and business ethics. Companies must review and strengthen their guidelines regarding situations such as:

    • Giving gifts and benefits to third parties.
    • Expenses related to food, lodging, and travel.
    • Political contributions and donations.
    • Lobbying activities.
    • Prevention of risks associated with the financing of the proliferation of weapons of mass destruction.

    Another fundamental aspect will be the ability to demonstrate the actual application of the implemented controls. Documentary traceability acquires greater importance, as companies must retain sufficient evidence to demonstrate the execution of their due diligence processes, the verifications carried out, the decisions adopted, and the responsible parties involved.

    In an eventual review by the Superintendencia de Sociedades, it will not be sufficient to demonstrate the existence of a written policy; it will be necessary to evidence that such policy was applied and that the identified risks were effectively managed.


    In this sense, External Circular 100-000020 of 2026 represents a change in the way organizations must approach corporate compliance. The main challenge will not only be to implement new documents or procedures but to develop a true culture of prevention, where risk management is part of the business strategy and contributes to protecting companies against legal, reputational, and operational contingencies.

    María Benavides

    Written by

    María Benavides

    Attorney

    October 5, 2026

    Questions about this topic?