Published December 18, 2024 · Updated May 29, 2026 · Fabio Castro Forero

Criminal compliance: how to prevent criminal risk in your company

Guide to Why a Corporate Criminal Lawyer Is Key to Business Protection: key requirements, evidence, risks and when legal advice may be needed in Colombia.

Category Corporate Law Published December 18, 2024 Updated May 29, 2026 Author Fabio Castro Forero
Corporate Criminal LawCorporate Criminal Riskcriminal complaintcompany

Criminal risk

Do not improvise a defense or a complaint. Organize the facts, evidence and timeline before presenting a version that may be difficult to correct later.

Most companies think of a criminal defense lawyer when there is already a criminal complaint, a formal notice of charges or a search of their premises. By then, much of the damage —financial and reputational— is already done. criminal compliance, or cumplimiento penal in Spanish, takes the opposite route: managing the risk of an offense before it occurs, with controls that reduce the probability that the company or its executives end up in criminal proceedings.

Prevention is not a luxury for multinationals. In Colombia, a large part of the business fabric is required by law to implement prevention systems, and those that are not still benefit from doing so. A serious program protects two things at once: the assets and the continuity of the company, and the freedom of the people who run it.

In this guide we explain, from the logic of prevention, what a compliance program is, what the two great mandatory regimes in Colombia are —SAGRILAFT and the PTEE—, which offenses a program mitigates, how third-party due diligence is carried out and why a good program reduces the officers' criminal exposure. There is a thread running through the whole text that is worth fixing from the outset: in matters of corporate criminal risk two distinct liabilities coexist, the administrative liability of the legal person before the superintendencias and the criminal liability of the natural person before the courts. We do not address here how an executive who has already been charged is defended; that is another conversation. Here we explain how to avoid reaching that point.

The essentials

If you have two minutes, these are the points to keep in mind before going into detail:

  • Criminal compliance is prevention. It manages the risk of an offense ex ante, with controls that act on the cause and not on the consequences.
  • In Colombia criminal liability is, as a general rule, individual. It is natural persons who answer —legal representative, officers, certain employees—, not the company as an abstract entity.
  • But the company is not left unscathed. It faces administrative penalties, extinción de dominio and, if it was used to commit offenses, the suspension or cancellation of its legal personality (art. 91 of Ley 906 de 2004).
  • Two mandatory regimes supervised by the Superintendencia de Sociedades: SAGRILAFT, against laundering and terrorist financing, and the PTEE, against corruption and soborno transnacional.
  • Cross-cutting axis: the legal person answers administratively and the natural person answers criminally, in parallel, for one and the same event. The penalty on the company operates "without prejudice" to the criminal liability of the legal representative (art. 2 of Ley 1778 de 2016).
  • An effective program lowers the probability of the offense, helps demonstrate diligence and mitigates the company's penalty (art. 7 of Ley 1778 de 2016). A "paper" program protects no one.

From the fire to prevention: why acting ahead of time protects the company and its executives

The reactive logic —waiting for the Fiscalía to arrive— is the most expensive one. Once the proceedings have begun, defense fees, precautionary measures, the freezing of accounts, the loss of contracts and reputational wear pile up at the same time. Prevention inverts that equation: it costs a fraction and acts on the cause, not on the consequences. It is the difference between installing smoke detectors and calling the fire department when the building is already burning.

Think of an ordinary case. Your company hires a commercial intermediary to open up a market in another country; that intermediary, without your knowing it, pays a "commission" to a foreign official to speed up a permit. Months later, an authority detects the payment. With no prior controls, you have no way of showing that the company vetted the intermediary, set clear rules and monitored the operation: the company is exposed and so are its officers. With a serious program, by contrast, there is a documentary trail —due diligence, anti-corruption clauses, training— that marks the difference between a diligent organization and a negligent one.

It is worth clarifying a point that tends to cause confusion. As a general rule, in Colombia criminal liability is individual: in the face of an offense it is natural persons who answer —the legal representative, the officers, certain employees—, not the company as an abstract entity. But it does not follow from that that the company is left unscathed.

The legal person suffers severe consequences of its own: administrative penalties from the superintendencias, extinción de dominio over assets of unlawful origin or destination and —where the company has been used to commit offenses— the suspension or cancellation of its legal personality ordered by the criminal court. Preventing, then, protects two fronts at once: the company and those who run it.

Legal basis — Art. 91 of Ley 906 de 2004 At the request of the Fiscalía and before the formal accusation, the juez de control de garantías (the judge who oversees constitutional guarantees at the pre-trial stage) may order the suspension of legal personality or the temporary closure of establishments open to the public where there are well-founded grounds to infer that they have been devoted, wholly or in part, to carrying on criminal activities. In the judgment of conviction, those measures may become permanent. Moreover, following a 2021 reform, anyone who has been suspended or canceled is barred from incorporating new legal entities with the same corporate purpose until the final decision. The company, although it is not "convicted" in the strict sense, can indeed disappear because of the offense committed through it.

This double effect is the key to criminal compliance. The personal criminal liability of the officers —when they are liable and how they are defended— we address in a separate analysis of the criminal liability of executives. Here we stay on the ground of prevention.

What a compliance program is and what elements it has

A compliance program is the set of policies, procedures and controls with which an organization identifies, prevents, detects and manages its legal risks; in criminal matters, above all money laundering, terrorist financing, corruption and bribery. It is not a document that gets filed away: it is a living system that is audited and improved. A perfect manual kept in a drawer is not a program; it is an alibi that fools no one.

Although each company adapts it to its size and its sector, national and international standards —the circulars of the Superintendencia de Sociedades and benchmarks such as the ISO 37001 anti-bribery standard— agree on a set of minimum elements. We review them one by one, with their practical logic and the mistake that is made most often.

  • Commitment from top management. Without real backing from the board and senior management —budget, authority and example—, the program is paper. The typical mistake: approving a policy in the minutes and not assigning a single hour or a single peso to carrying it out. If the leadership is the first to skip the controls, no employee will take them seriously.
  • Risk assessment. A diagnosis or matrix identifying where the company is exposed according to its activity, clients, geographies and counterparties. Not all companies carry the same risk: exporting software is not the same as operating with cash in border areas. The typical mistake: copying another company's matrix without looking at your own operation.
  • Policies and code of conduct. Clear rules on gifts, hospitality, conflicts of interest, payments, hiring third parties and dealings with public officials. The typical mistake: drafting a generic, ambiguous code that nobody knows how to apply when the concrete case arrives —for example, whether or not an invitation from a supplier may be accepted.
  • Compliance officer. A person in charge with independence, budget and direct access to management. The typical mistake: appointing as officer the very finance manager who approves the payments, so that the one who controls and the one who is controlled are the same person.
  • Third-party due diligence. Knowing clients, suppliers and intermediaries before contracting, and not only at signing. It is the point through which most problems come in, and that is why we devote a section of its own to it below.
  • Training. That employees and executives know how to recognize a red flag and know what to do with it. The typical mistake: an annual talk nobody remembers, with no record of attendance or assessment.
  • Whistleblowing channel. A confidential —and so far as possible anonymous— route for reporting irregular conduct. The typical mistake: a mailbox nobody checks or, worse, one that exposes the whistleblower.
  • Monitoring, audit and improvement. Reviewing that the controls work and correcting what fails. The typical mistake: not looking at the program again until the problem it was meant to prevent blows up.

In Colombia, these elements are not merely good practice: for many companies they are a legal obligation, channeled through two regimes supervised by the Superintendencia de Sociedades. SAGRILAFT, for the risk of laundering and terrorism; the PTEE, for the risk of corruption. Before going into each one, it is worth seeing clearly which offenses lie behind them.

The criminal risks that a good program mitigates

A compliance program does not pursue an abstract objective: it seeks to keep the company and its executives far from a handful of concrete offenses, all of them carrying severe penalties for the natural persons involved. Knowing them helps to understand why the controls are worth what they cost. These are the four cores of risk that corporate prevention addresses most often:

Offense (Código Penal, Ley 599 de 2000)Who is liable (natural person)ImprisonmentFine (SMMLV)
Money laundering (art. 323)Whoever manages assets of unlawful origin or gives them the appearance of legality10 to 30 years1,000 to 50,000
Failure to control (art. 325)Board member, legal representative, officer or employee of a financial institution or savings and credit cooperative38 to 128 months133.33 to 15,000
Administration of resources linked to terrorism (art. 345)Whoever manages money or assets connected with terrorist activities6 to 12 years200 to 10,000
Soborno transnacional (art. 433)Whoever gives, promises or offers a benefit to a foreign public servant in connection with an international business deal9 to 15 years650 to 50,000

Money laundering is the central offense of the system: giving the appearance of legality to assets coming from unlawful activities. A program reduces the risk that the company becomes —knowingly or through carelessness— the vehicle that "cleans" that money. Terrorist financing, in its criminal form of administering resources linked to terrorist activities, shares the same prevention logic, and that is why SAGRILAFT deals with them together. Soborno transnacional, for its part, is the typical risk of companies that do business with the foreign public sector, and it is the heart of the PTEE.

There is a point executives tend to overlook: when the offense is committed by those who run the company, the penalty is not the same as for any private individual. The law makes the punishment heavier precisely for the officers.

Legal basis — Art. 324 of the Código Penal (Ley 599 de 2000) The penalties for money laundering are increased by one third to one half where the conduct is carried out by someone belonging to a legal person, company or organization devoted to laundering, and by one half to three quarters where it is carried out by the managers, officers or persons in charge of those legal persons. Being in charge aggravates liability; it does not dilute it.
Legal basis — Art. 345 of the Código Penal (Ley 599 de 2000) The administration of resources connected with terrorist activities —managing money or assets linked to those activities— is punished with imprisonment of six (6) to twelve (12) years and a fine of two hundred (200) to ten thousand (10,000) SMLMV. It is the statutory offense that, together with Ley 1121 de 2006, underpins the terrorist financing side of SAGRILAFT.

The detail of the various financial and cyber offenses that threaten the company —from internal fraud to computer attacks— we develop in a specific guide on financial crimes.

SAGRILAFT: preventing money laundering and terrorist financing

Nota de vigencia — agosto de 2026. Esta sección describe el marco de las Circulares Externas 100-000016 de 2020 y 100-000011 de 2021. Ambas fueron derogadas por la Circular Externa 100-000020 del 2 de julio de 2026, que expidió una nueva Circular Básica Jurídica: SAGRILAFT y PTEE quedaron unificados en el Capítulo IX y los umbrales dejaron de expresarse en SMMLV para pasar a UVB. Los umbrales que se citan a continuación corresponden al régimen anterior y se conservan como referencia histórica. Si su empresa está evaluando hoy si es sujeto obligado, verifique el Capítulo IX vigente.

The SAGRILAFT (Sistema de Autocontrol y Gestión del Riesgo Integral de Lavado de Activos, Financiación del Terrorismo y Financiamiento de la Proliferación de Armas de Destrucción Masiva — the self-control and integrated risk management system for money laundering, terrorist financing and the financing of the proliferation of weapons of mass destruction) is the prevention system the Superintendencia de Sociedades requires of companies in the real, non-financial sector. It is governed by Chapter X of the Circular Básica Jurídica, in the version amended by Circular Externa 100-000016 de 2020.

Which companies does it apply to?

The obligation depends on size and sector, measured as of December 31 of the immediately preceding year:

  • General regime: companies supervised or controlled by the Superintendencia with total income or assets equal to or greater than 40,000 SMMLV.
  • Higher-risk sectors: for activities such as real estate agents, trade in precious metals and stones, legal and accounting services, construction of buildings and civil works, or virtual asset services, the income threshold drops to 30,000 SMMLV.

Companies that do not reach those thresholds may fall under a regime of minimum measures, a lighter one. Checking which category your company falls into, and doing so every year, is the first step: the thresholds are matched against the close of the previous financial year, so a growing company can become a covered entity without realizing it.

What does it require?

  • Appointing a compliance officer approved by the board of directors.
  • Drawing up a risk matrix for money laundering and terrorist financing, and applying due diligence (knowledge of the client, of the counterparty and of the beneficial owner).
  • Defining red flags and internal control procedures.
  • Reporting suspicious transactions (ROS) and the other required reports to the UIAF (Unidad de Información y Análisis Financiero), the financial intelligence unit created by Ley 526 de 1999.

A concrete example. Suppose your company receives from a new client an advance payment far above the value of the order, with instructions to return the excess to a third party's account in another country. That is a textbook red flag. With SAGRILAFT up and running, the compliance officer documents the transaction, asks for explanations and, if the case warrants it, files a ROS with the UIAF. With no system, the payment comes in, is processed like any other and the company ends up entangled in somebody else's laundering operation.

Here it is essential not to confuse two levels. SAGRILAFT is an administrative duty: not having it, or having it badly, brings penalties from the Superintendencia. But the conduct it seeks to avoid consists of criminal offenses, carrying prison sentences for natural persons. And deliberately omitting the controls or the reports may itself amount to an offense.

Legal basis — Art. 323 of the Código Penal (Ley 599 de 2000) Money laundering —acquiring, safeguarding, investing, transporting, transforming, holding in custody or managing assets whose direct or indirect origin lies in activities such as drug trafficking, extortion, illicit enrichment or corruption, or giving them the appearance of legality— is punished, for that conduct alone, with imprisonment of ten (10) to thirty (30) years and a fine of one thousand (1,000) to fifty thousand (50,000) SMLMV. It is the central offense that SAGRILAFT seeks to prevent.
Legal basis — Art. 325 of the Código Penal (Ley 599 de 2000) Failure to control punishes the board member, legal representative, officer or employee of a financial institution or of cooperatives carrying on savings and credit activities who, in order to conceal or cover up the unlawful origin of the money, omits the control mechanisms over cash transactions: imprisonment of thirty-eight (38) to one hundred twenty-eight (128) months and a fine of 133.33 to 15,000 SMLMV. Not controlling can be, in itself, an offense.
Legal basis — Art. 325A of the Código Penal (Ley 599 de 2000) Failure to file reports on cash transactions punishes those subject to UIAF oversight who deliberately omit the reports to that entity on transactions, movement or storage of cash: imprisonment of thirty-eight (38) to one hundred twenty-eight (128) months and a fine of 133.33 to 15,000 SMLMV. The report to the UIAF is not a formality: deliberately omitting it carries criminal consequences.

The terrorist financing framework is completed by Ley 1121 de 2006, which structured prevention in the country and strengthened the UIAF as the financial intelligence unit that receives the reports. Note the difference in levels: the company that does not report answers before the Superintendencia (the administrative level); the person who deliberately omits the control or the report answers before the criminal courts (the individual level). The same event, two liabilities.

The PTEE and Ley 1778 de 2016: anti-corruption and soborno transnacional

Nota de vigencia — agosto de 2026. El PTEE dejó de regularse en el Capítulo XIII: la Circular Externa 100-000020 del 2 de julio de 2026 derogó la Circular Externa 100-000011 de 2021 y trasladó la materia al Capítulo IX, unificada con el SAGRILAFT. Los umbrales de esta sección corresponden al régimen anterior.

The second great preventive regime is aimed at corruption. Its basis is Ley 1778 de 2016, amended in several respects by Ley 2195 de 2022, which introduced a decisive concept in Colombia: the administrative liability of legal persons for soborno transnacional; that is, for bribing —through employees, contractors, officers or associates— a foreign public servant in order to obtain or retain an international business deal.

Here the distinction between the administrative and the criminal can be seen with complete clarity, and the statute itself states it without circumlocution. The company answers administratively before the Superintendencia de Sociedades, with penalties that can be devastating. The natural person who pays or promises the bribe answers criminally for the offense of soborno transnacional. They are two parallel liabilities for one and the same event.

Legal basis — Art. 2 of Ley 1778 de 2016 (as amended by Ley 2195 de 2022) Legal persons that, through their employees, contractors, officers or associates, give, offer or promise a foreign public servant sums of money, objects of value or any other benefit, in exchange for performing, omitting or delaying an act in connection with an international business deal or transaction, "shall be penalized administratively on the terms established by this statute, without prejudice to any criminal liability of the legal representative of the legal person". In a single sentence, the statute draws the two liabilities.

Jurisdiction to investigate and penalize the legal person lies with the Superintendencia de Sociedades (Colombia's corporate regulator), even where the conduct was committed abroad, provided the company responsible is domiciled in Colombia. And the penalties are not symbolic.

Legal basis — Art. 5 of Ley 1778 de 2016 (as amended by Ley 2195 de 2022) A legal person found responsible for soborno transnacional (transnational bribery) may be subject to: a fine of up to two hundred thousand (200,000) SMMLV (monthly minimum wages), to which is added the greater of the benefit obtained or sought; disqualification from contracting with the State for up to twenty (20) years; publication of an extract of the penalty for up to one (1) year; and a ban on receiving government incentives or subsidies for a period of ten (10) years. Jurisdiction lies with the Superintendencia de Sociedades.
Legal basis — Art. 433 of the Código Penal (Colombia's Criminal Code, Ley 599 de 2000) Soborno transnacional —giving, promising or offering money or benefits to a foreign public servant in order to favor an international business deal or transaction— is punished, in the hands of the natural person, with imprisonment of nine (9) to fifteen (15) years, disqualification from exercising public rights and functions for the same term, and a fine of six hundred fifty (650) to fifty thousand (50,000) SMLMV. The company's administrative penalty operates "without prejudice" to this individual criminal liability.

The PTEE: the program the law expects of you

To prevent that risk, the Superintendencia requires the Programa de Transparencia y Ética Empresarial (PTEE, the business transparency and ethics program), governed by Chapter XIII of the Circular Básica Jurídica (Circular Externa 100-000011 de 2021). It is an anti-corruption program with the elements already seen —risk assessment, policies, compliance officer, due diligence, whistleblowing channel and audit—, focused on dealings with the public sector and with international counterparties.

The following are covered, according to their figures as of December 31 of the previous year, among others:

  • Companies with international business or transactions equal to or greater than 100 SMMLV and with total income or assets equal to or greater than 30,000 SMMLV (soborno transnacional risk).
  • Those that entered into contracts with State entities for 500 SMMLV or more and have income or assets from 30,000 SMMLV, or belong to certain sectors identified by the Superintendencia (corruption risk).

Having a real PTEE is not merely complying for the sake of complying: the existence of an effective program is a factor the authority expressly weighs when calibrating penalties. A "paper" program, by contrast, protects no one.

Legal basis — Art. 23 of Ley 1778 de 2016 (as amended by Ley 2195 de 2022) The Superintendencia de Sociedades promotes, among the companies under its supervision, the adoption of business transparency and ethics programs that include audit mechanisms and mechanisms to prevent soborno transnacional, and it determines their content and who is covered according to sector, risks, assets, income, number of employees and corporate purpose. This is the legal foundation of the PTEE that the circular later spells out.

It is worth looking at the two regimes side by side, because they share a structure but address different risks:

 SAGRILAFTPTEE
Risk it preventsMoney laundering, terrorist financing and the financing of weapons proliferationCorruption and soborno transnacional
Governing ruleCircular Externa 100-000016 de 2020 (Chap. X, Circular Básica Jurídica)Circular Externa 100-000011 de 2021 (Chap. XIII) and Ley 1778 de 2016
Supervising authoritySuperintendencia de SociedadesSuperintendencia de Sociedades
Signature toolSuspicious transaction report (ROS) to the UIAFCounterparty due diligence and whistleblowing channel
Associated criminal offensesArts. 323, 325 and 345 of the Código PenalArt. 433 of the Código Penal
Corte Constitucional, Sentencia C-165 de 2019. It upheld the administrative regime for soborno transnacional (Ley 1778 de 2016): the superintendencias may investigate the company, provided they do not carry out steps reserved to the courts. This is administrative liability, not criminal liability. Official text.

The company's administrative liability versus the individual's criminal liability

This is the axis worth committing to memory, because understanding why prevention protects on two fronts at once depends on it. A single event —a bribe, a laundering transaction, a failure to control— can set two different machines in motion, with different logics, authorities and consequences. They do not compete with each other; they run in parallel.

CriterionAdministrative liabilityCriminal liability
Who is liable?The legal person (the company)The natural person (legal representative, officers, employees)
Before whom?The Superintendencia de Sociedades or another supervisory authorityThe Fiscalía General de la Nación (Prosecutor's Office) and criminal courts
What is at issue?Breach of a duty (not having SAGRILAFT/PTEE, failing to report, failing to control)The commission of an offense (laundering, bribery, failure to control)
Typical consequenceFine, disqualification from contracting with the State, publication of the penaltyImprisonment, fine and disqualification; and, for a company used to commit offenses, suspension of legal personality (art. 91)
Governing statute (example)Ley 1778 de 2016 and the Superintendencia's circularsCódigo Penal (Ley 599 de 2000)
Does one exclude the other?No. They operate in parallel: the penalty on the company is "without prejudice" to the criminal liability of the natural person (art. 2 of Ley 1778 de 2016).

The practical consequence is easy to state and easy to forget: paying the administrative fine does not erase the executive's criminal case, and winning the criminal case does not cancel the penalty on the company. That is why a compliance program is designed to prevent the event —not to choose which of the two liabilities to bear— and why it is documented with care: the evidence serves in both scenarios.

Corte Constitucional, Sentencias C-320 de 1998 and C-843 de 1999. They established that the legal person is not criminally liable as such: the Court rejected strict liability (C-320 de 1998) and struck down a provision that imposed penalties on it without defining them (C-843 de 1999).
Corte Constitucional, Sentencia C-603 de 2016. What is available are measures against the company used to commit offenses —suspension or cancellation of its legal personality (Ley 906 de 2004, art. 91; Ley 1474 de 2011, art. 34)—, which the victim may request after the formulación de imputación (the formal notice of charges). Official text.

Third-party due diligence: where the risk comes in

If one had to point to a single place through which most companies become contaminated, it would be this: third parties. Suppliers, distributors, agents, intermediaries, business associates and clients can drag the company into a criminal problem even though it never sought the offense. That is why third-party due diligence is the operational heart of any program: most cases of soborno transnacional and of laundering do not come in through the front door, but through a third party the company did not know well.

Doing it properly means, at a minimum:

  • Know the third party before contracting: identity, actual activity, owners and beneficial owner —the flesh-and-blood person who ultimately benefits—.
  • Check restricted-party lists (such as those of the UN and OFAC) and verify background and reputation.
  • Include contractual clauses on anti-corruption and anti-money laundering, with rights of audit and termination if the third party defaults.
  • Watch for red flags: payments to third countries with no apparent reason, disproportionate commissions, insistence on unnecessary intermediaries, invoices with no supporting documents, or resistance to handing over information.

An example. Your company is about to hire a "consultant" who promises to land a State contract in exchange for a 20 % commission, well above market, and refuses to explain what that money is spent on. Due diligence does not consist in signing and hoping: it consists in stopping, documenting the doubt and, if there is no reasonable explanation, not hiring. The common mistake is to treat these controls as a formality at the signing of the contract and not as monitoring that continues throughout the relationship. A third party who is clean today may cease to be so tomorrow.

Due diligence is also the best defense when it is the company itself that ends up being used by a third party as a vehicle for the offense; that scenario —the company as the victim— is covered in an article devoted to the company as victim.

Whistleblowing channels and protection of the whistleblower

No control detects everything. That is why the whistleblowing channel —a confidential and, so far as possible, anonymous ethics line— is one of the most effective tools: it turns every employee into an early sensor of irregular conduct. Many internal frauds and bribes are uncovered through a report, not through an audit.

For it to work, the channel needs two guarantees. First, confidentiality: whoever reports must be able to trust that their identity is protected. Second, freedom from retaliation: the company must undertake in writing that reporting in good faith will bring no adverse employment consequences. Both SAGRILAFT and the PTEE require having these mechanisms and dealing with reports seriously.

An example of what must not happen: an employee reports through the channel that a manager asks suppliers for "commissions", and weeks later that employee is transferred or dismissed on some pretext. The message the whole organization receives is unmistakable: reporting comes at a high price. From then on, the channel is dead. A channel nobody uses —or that punishes whoever uses it— is worse than not having one, because it creates a false sense of control and, on top of that, proves the company knew and did not act.

How the program reduces executives' criminal exposure

This is the point of greatest interest to anyone who runs a company. A compliance program is not an insurance policy that "erases" the offense —nothing does—, but it does bear on the officers' criminal exposure in three concrete ways:

  • It lowers the probability. Fewer opportunities for an offense simply mean fewer proceedings. Most controls operate here: they keep the event from happening.
  • It demonstrates diligence. Faced with an investigation, a real program —with evidence that it was applied— helps show that the executive acted with care and did not acquiesce in the event, which is relevant when their individual liability is argued.
  • It mitigates the company's penalty. On the administrative side, the existence of an effective PTEE or SAGRILAFT is a factor the Superintendencia weighs in the company's favor.
Legal basis — Art. 7 of Ley 1778 de 2016 Among the criteria for calibrating penalties on the legal person, the statute expressly includes "the existence, implementation and effectiveness of business transparency and ethics programs or of anti-corruption mechanisms within the company". Having a real and demonstrable program is not cosmetic: it is a mitigating factor the authority must consider.

The key word is effective. A cosmetic program, with no budget, no training and no audit, fools no one and may even aggravate the perception of negligence. Diligence is proven with documented facts —updated risk matrices, training records, reports acted upon, decisions not to contract—, not with manuals kept in a drawer. In a proceeding, the question will not be "did you have a manual?", but "what did you do the day the red flag appeared?".

Corte Constitucional, Sentencia SU-1184 de 2001. The foundation of the duty of oversight that structures the program is the posición de garante (the duty to avert a risk within one's own control; Código Penal, art. 25): whoever controls a source of risk in their sphere is liable for what they fail to prevent. Official text.

First steps to implement a minimum program

There is no need to begin with a perfect system; what is needed is to begin well. A midsize company can set up a minimum viable program with an orderly route:

  1. Diagnosis. Establish whether your company is a covered entity under SAGRILAFT or the PTEE and assess its real risks according to sector, clients, geographies and operations.
  2. Backing from the leadership. Take the matter to the board and assign budget and authority; without this, the rest does not hold up.
  3. Compliance officer. Appoint a person in charge who has independence and no conflict of interest with the areas they must control.
  4. Policies and code of conduct. Draft them tailored to the company, not copied from a template, with concrete rules on gifts, payments and third parties.
  5. Due diligence and whistleblowing channel. Put them in place with clear procedures and defined owners.
  6. Training. Train employees and executives, tailored to each role, and keep a record of attendance and assessment.
  7. Audit and improvement. Review periodically that the controls work, correct what fails and document everything you do.

Documentation is not bureaucracy: it is the proof that the program exists and works on the day someone —an authority, a judge, a demanding client— asks. A program proportionate to the company's size and risk is worth far more than an ambitious one that nobody carries out.

What NOT to do

As important as knowing what to build is knowing what to avoid. These are the mistakes that, time and again, turn a program into a useless facade:

  • Do not copy another company's manual and sign it as your own. A program that does not reflect your real operation prevents nothing and, before the authority, betrays that no serious risk assessment was ever carried out.
  • Do not appoint as compliance officer someone who has a conflict of interest —for instance, the same person who approves the payments or closes the deals—. Independence is the essence of the role.
  • Do not treat due diligence as a one-time formality. Knowing the third party at signing and never looking at them again leaves the door open for the whole relationship.
  • Do not set up a whistleblowing channel without real protection for the whistleblower. If there is retaliation, the channel turns against the company: it proves it knew and did not protect.
  • Do not ignore red flags in order not to lose a deal. The contract saved today by skipping a control is tomorrow's criminal case.
  • Do not leave the program without budget or audit. A program that is neither carried out nor reviewed is, in a judge's eyes, confirmation of the negligence, not an excuse for it.
  • Do not use the program as a public shield while the same conduct is tolerated inside. The contradiction between what is said and what is done aggravates; it does not mitigate.

Common myths

Mistaken ideas circulate around criminal compliance that lead companies not to act, or to act badly. They are worth dismantling:

Myth: "Compliance is only for large multinationals". Reality: the SAGRILAFT and PTEE thresholds reach many midsize Colombian companies, and serious counterparties demand controls from their suppliers regardless of size. Prevention does not depend on being large, but on being exposed.

Myth: "Since the company does not go to prison, the risk is lower". Reality: the company faces fines, disqualification from contracting, extinción de dominio (asset forfeiture) and even the suspension of its legal personality. And its officers —flesh-and-blood people— are indeed criminally liable.

Myth: "Having the manual is enough". Reality: a manual with no implementation, budget or audit does not protect; it may even aggravate the perception of negligence. What counts is the effective program, not the document.

Myth: "If an employee or an intermediary committed the offense, the company is not liable". Reality: Ley 1778 de 2016 holds the legal person liable precisely for the acts of its employees, contractors, officers or associates. Delegating does not transfer the risk.

Myth: "Compliance slows the business down". Reality: a well-designed program speeds up decisions —it defines in advance what is allowed and what is not— and opens doors, because more and more clients and allies demand counterparties with controls. Prevention is also a commercial argument.

Myth: "A program exempts me from liability". Reality: it does not exempt automatically. It reduces the probability of the offense and, if something happens, it helps demonstrate diligence and mitigates the administrative penalty. It is not an insurance policy; it is a barrier.

Checklist for a minimum viable compliance program

Use this list as a quick self-diagnosis. If you answer "no" or "I don't know" to several boxes, your company has work ahead of it:

  • Have you checked this year whether your company is a covered entity under SAGRILAFT or the PTEE, using the figures as of December 31 of the previous year?
  • Do you have a risk matrix built on your own operation, and not copied?
  • Did the board or senior management back the program with budget and authority, and was it recorded in the minutes?
  • Have you appointed a compliance officer with independence and no conflict of interest?
  • Do you have a code of conduct with concrete rules on gifts, payments, conflicts of interest and third parties?
  • Do you carry out due diligence on clients, suppliers and intermediaries before contracting, including the beneficial owner?
  • Do your contracts include anti-corruption and anti-money-laundering clauses with rights of audit and termination?
  • Do you check restricted-party lists and have you defined red flags?
  • Do you have a confidential whistleblowing channel with effective protection for the whistleblower?
  • Do you train employees and executives and keep a record of attendance?
  • Do you report suspicious transactions to the UIAF when required?
  • Do you audit the program periodically and document every control, decision and report?

In summary

Preventing criminal risk is, in the long run, cheaper and more dignified than defending against it. A well-designed compliance program protects the company's assets, its reputation and the peace of mind of those who run it; and it keeps in view the distinction that runs through this whole guide: the company's administrative liability and the natural person's criminal liability run in parallel, and only prevention acts on both at once. At Cafore Abogados we support the design and implementation of criminal compliance programs suited to your sector and your size, and we assess whether or not your company is covered by SAGRILAFT or the PTEE. If you would like to review your exposure, you can write to us or call us at 313 8411825.

Laws and case law cited

  • Art. 323 of the Código Penal (Ley 599 de 2000) — defines the offense of money laundering; imprisonment of 10 to 30 years and a fine of 1,000 to 50,000 SMMLV. Source
  • Art. 324 of the Código Penal (Ley 599 de 2000) — aggravates money laundering when it is committed by managers, officers or persons in charge of the legal person. Source
  • Art. 325 of the Código Penal (Ley 599 de 2000) — defines the offense of failure to control by executives and employees of financial institutions and savings and credit cooperatives. Source
  • Art. 325A of the Código Penal (Ley 599 de 2000) — defines the offense of failing to file reports with the UIAF on cash transactions. Source
  • Art. 345 of the Código Penal (Ley 599 de 2000) — administration of resources connected with terrorist activities; imprisonment of 6 to 12 years and a fine of 200 to 10,000 SMMLV. Source
  • Art. 433 of the Código Penal (Ley 599 de 2000) — defines the offense of soborno transnacional in the hands of the natural person; imprisonment of 9 to 15 years and a fine of 650 to 50,000 SMMLV. Source
  • Art. 91 of Ley 906 de 2004 — allows the suspension or cancellation of legal personality used to commit offenses. Source
  • Ley 1778 de 2016 (arts. 2, 3, 5, 7 and 23), as amended by Ley 2195 de 2022 — administrative liability of legal persons for soborno transnacional; jurisdiction of the Superintendencia de Sociedades; penalties; criteria for calibrating them; and business transparency and ethics programs (PTEE). Source
  • Ley 2195 de 2022 — reforms the penalty regime of Ley 1778 de 2016 (arts. 19 to 25). Source
  • Ley 526 de 1999 — creates the Unidad de Información y Análisis Financiero (UIAF), which receives and analyzes suspicious transaction reports. Source
  • Ley 1121 de 2006 — framework for preventing terrorist financing and strengthening the UIAF. Source
  • Circular Externa 100-000016 de 2020 — Chapter X, Superintendencia de Sociedades — governs SAGRILAFT and the thresholds for covered companies. Source
  • Circular Externa 100-000011 de 2021 — Chapter XIII, Superintendencia de Sociedades — governs the PTEE (Programa de Transparencia y Ética Empresarial). Source
  • Corte Constitucional, Sentencia SU-1184 de 2001 — posición de garante and duty of oversight (Código Penal, art. 25). Official text.
  • Corte Constitucional, Sentencia C-320 de 1998 — limits on the liability of the legal person; no strict liability. Official text.
  • Corte Constitucional, Sentencia C-843 de 1999 — unconstitutionality of penalties on legal persons without statutory definition. Official text.
  • Corte Constitucional, Sentencia C-603 de 2016 — measures against the legal person used to commit offenses (art. 91 Ley 906; art. 34 Ley 1474). Official text.
  • Corte Constitucional, Sentencia C-165 de 2019 — administrative regime for soborno transnacional (Ley 1778 de 2016). Official text.

We answer your questions

Frequently asked questions

Is my company required to implement SAGRILAFT?
It depends on size and sector, measured as of December 31 of the previous year. In general, if it had income or assets equal to or greater than 40,000 SMMLV; in higher-risk sectors (real estate, precious metals and stones, virtual assets, among others), from 30,000 SMMLV in income. It is worth checking every year, because a growing company can become a covered entity without noticing.
How do SAGRILAFT and the PTEE differ?
SAGRILAFT prevents money laundering and terrorist financing; the PTEE prevents corruption and soborno transnacional. Both are supervised by the Superintendencia de Sociedades and share a structure (compliance officer, risk matrix, due diligence, whistleblowing channel and audit), but they address different risks and have thresholds of their own.
What happens if I do not report a suspicious transaction to the UIAF?
Beyond the administrative penalty for breaching SAGRILAFT, deliberately omitting the controls or the reports may itself amount to an offense: failure to control (art. 325) for executives of financial institutions, or failure to file reports with the UIAF on cash transactions (art. 325A of the Código Penal) for those subject to its oversight.
Is criminal compliance worth it if my company is not required to have it?
Yes. Even if it does not reach the thresholds, a proportionate program reduces real risks, makes business easier with counterparties that demand it and protects the officers. Prevention does not depend on the size of the company, but on its exposure to risk.

To go deeper

Keep informing yourself

Related guides that expand on the key points of this article.

Does your case need professional support?

Resolve your case with professional support

Tell us about your situation and we will guide you on the most appropriate path, the timelines and the costs.