Most companies think of a criminal defense lawyer when there is already a criminal complaint, a formal notice of charges or a search of their premises. By then, much of the damage —financial and reputational— is already done. criminal compliance, or cumplimiento penal in Spanish, takes the opposite route: managing the risk of an offense before it occurs, with controls that reduce the probability that the company or its executives end up in criminal proceedings.
Prevention is not a luxury for multinationals. In Colombia, a large part of the business fabric is required by law to implement prevention systems, and those that are not still benefit from doing so. A serious program protects two things at once: the assets and the continuity of the company, and the freedom of the people who run it.
In this guide we explain, from the logic of prevention, what a compliance program is, what the two great mandatory regimes in Colombia are —SAGRILAFT and the PTEE—, which offenses a program mitigates, how third-party due diligence is carried out and why a good program reduces the officers' criminal exposure. There is a thread running through the whole text that is worth fixing from the outset: in matters of corporate criminal risk two distinct liabilities coexist, the administrative liability of the legal person before the superintendencias and the criminal liability of the natural person before the courts. We do not address here how an executive who has already been charged is defended; that is another conversation. Here we explain how to avoid reaching that point.
The essentials
If you have two minutes, these are the points to keep in mind before going into detail:
- Criminal compliance is prevention. It manages the risk of an offense ex ante, with controls that act on the cause and not on the consequences.
- In Colombia criminal liability is, as a general rule, individual. It is natural persons who answer —legal representative, officers, certain employees—, not the company as an abstract entity.
- But the company is not left unscathed. It faces administrative penalties, extinción de dominio and, if it was used to commit offenses, the suspension or cancellation of its legal personality (art. 91 of Ley 906 de 2004).
- Two mandatory regimes supervised by the Superintendencia de Sociedades: SAGRILAFT, against laundering and terrorist financing, and the PTEE, against corruption and soborno transnacional.
- Cross-cutting axis: the legal person answers administratively and the natural person answers criminally, in parallel, for one and the same event. The penalty on the company operates "without prejudice" to the criminal liability of the legal representative (art. 2 of Ley 1778 de 2016).
- An effective program lowers the probability of the offense, helps demonstrate diligence and mitigates the company's penalty (art. 7 of Ley 1778 de 2016). A "paper" program protects no one.
From the fire to prevention: why acting ahead of time protects the company and its executives
The reactive logic —waiting for the Fiscalía to arrive— is the most expensive one. Once the proceedings have begun, defense fees, precautionary measures, the freezing of accounts, the loss of contracts and reputational wear pile up at the same time. Prevention inverts that equation: it costs a fraction and acts on the cause, not on the consequences. It is the difference between installing smoke detectors and calling the fire department when the building is already burning.
Think of an ordinary case. Your company hires a commercial intermediary to open up a market in another country; that intermediary, without your knowing it, pays a "commission" to a foreign official to speed up a permit. Months later, an authority detects the payment. With no prior controls, you have no way of showing that the company vetted the intermediary, set clear rules and monitored the operation: the company is exposed and so are its officers. With a serious program, by contrast, there is a documentary trail —due diligence, anti-corruption clauses, training— that marks the difference between a diligent organization and a negligent one.
It is worth clarifying a point that tends to cause confusion. As a general rule, in Colombia criminal liability is individual: in the face of an offense it is natural persons who answer —the legal representative, the officers, certain employees—, not the company as an abstract entity. But it does not follow from that that the company is left unscathed.
The legal person suffers severe consequences of its own: administrative penalties from the superintendencias, extinción de dominio over assets of unlawful origin or destination and —where the company has been used to commit offenses— the suspension or cancellation of its legal personality ordered by the criminal court. Preventing, then, protects two fronts at once: the company and those who run it.
This double effect is the key to criminal compliance. The personal criminal liability of the officers —when they are liable and how they are defended— we address in a separate analysis of the criminal liability of executives. Here we stay on the ground of prevention.
What a compliance program is and what elements it has
A compliance program is the set of policies, procedures and controls with which an organization identifies, prevents, detects and manages its legal risks; in criminal matters, above all money laundering, terrorist financing, corruption and bribery. It is not a document that gets filed away: it is a living system that is audited and improved. A perfect manual kept in a drawer is not a program; it is an alibi that fools no one.
Although each company adapts it to its size and its sector, national and international standards —the circulars of the Superintendencia de Sociedades and benchmarks such as the ISO 37001 anti-bribery standard— agree on a set of minimum elements. We review them one by one, with their practical logic and the mistake that is made most often.
- Commitment from top management. Without real backing from the board and senior management —budget, authority and example—, the program is paper. The typical mistake: approving a policy in the minutes and not assigning a single hour or a single peso to carrying it out. If the leadership is the first to skip the controls, no employee will take them seriously.
- Risk assessment. A diagnosis or matrix identifying where the company is exposed according to its activity, clients, geographies and counterparties. Not all companies carry the same risk: exporting software is not the same as operating with cash in border areas. The typical mistake: copying another company's matrix without looking at your own operation.
- Policies and code of conduct. Clear rules on gifts, hospitality, conflicts of interest, payments, hiring third parties and dealings with public officials. The typical mistake: drafting a generic, ambiguous code that nobody knows how to apply when the concrete case arrives —for example, whether or not an invitation from a supplier may be accepted.
- Compliance officer. A person in charge with independence, budget and direct access to management. The typical mistake: appointing as officer the very finance manager who approves the payments, so that the one who controls and the one who is controlled are the same person.
- Third-party due diligence. Knowing clients, suppliers and intermediaries before contracting, and not only at signing. It is the point through which most problems come in, and that is why we devote a section of its own to it below.
- Training. That employees and executives know how to recognize a red flag and know what to do with it. The typical mistake: an annual talk nobody remembers, with no record of attendance or assessment.
- Whistleblowing channel. A confidential —and so far as possible anonymous— route for reporting irregular conduct. The typical mistake: a mailbox nobody checks or, worse, one that exposes the whistleblower.
- Monitoring, audit and improvement. Reviewing that the controls work and correcting what fails. The typical mistake: not looking at the program again until the problem it was meant to prevent blows up.
In Colombia, these elements are not merely good practice: for many companies they are a legal obligation, channeled through two regimes supervised by the Superintendencia de Sociedades. SAGRILAFT, for the risk of laundering and terrorism; the PTEE, for the risk of corruption. Before going into each one, it is worth seeing clearly which offenses lie behind them.
The criminal risks that a good program mitigates
A compliance program does not pursue an abstract objective: it seeks to keep the company and its executives far from a handful of concrete offenses, all of them carrying severe penalties for the natural persons involved. Knowing them helps to understand why the controls are worth what they cost. These are the four cores of risk that corporate prevention addresses most often:
| Offense (Código Penal, Ley 599 de 2000) | Who is liable (natural person) | Imprisonment | Fine (SMMLV) |
|---|---|---|---|
| Money laundering (art. 323) | Whoever manages assets of unlawful origin or gives them the appearance of legality | 10 to 30 years | 1,000 to 50,000 |
| Failure to control (art. 325) | Board member, legal representative, officer or employee of a financial institution or savings and credit cooperative | 38 to 128 months | 133.33 to 15,000 |
| Administration of resources linked to terrorism (art. 345) | Whoever manages money or assets connected with terrorist activities | 6 to 12 years | 200 to 10,000 |
| Soborno transnacional (art. 433) | Whoever gives, promises or offers a benefit to a foreign public servant in connection with an international business deal | 9 to 15 years | 650 to 50,000 |
Money laundering is the central offense of the system: giving the appearance of legality to assets coming from unlawful activities. A program reduces the risk that the company becomes —knowingly or through carelessness— the vehicle that "cleans" that money. Terrorist financing, in its criminal form of administering resources linked to terrorist activities, shares the same prevention logic, and that is why SAGRILAFT deals with them together. Soborno transnacional, for its part, is the typical risk of companies that do business with the foreign public sector, and it is the heart of the PTEE.
There is a point executives tend to overlook: when the offense is committed by those who run the company, the penalty is not the same as for any private individual. The law makes the punishment heavier precisely for the officers.
The detail of the various financial and cyber offenses that threaten the company —from internal fraud to computer attacks— we develop in a specific guide on financial crimes.
SAGRILAFT: preventing money laundering and terrorist financing
The SAGRILAFT (Sistema de Autocontrol y Gestión del Riesgo Integral de Lavado de Activos, Financiación del Terrorismo y Financiamiento de la Proliferación de Armas de Destrucción Masiva — the self-control and integrated risk management system for money laundering, terrorist financing and the financing of the proliferation of weapons of mass destruction) is the prevention system the Superintendencia de Sociedades requires of companies in the real, non-financial sector. It is governed by Chapter X of the Circular Básica Jurídica, in the version amended by Circular Externa 100-000016 de 2020.
Which companies does it apply to?
The obligation depends on size and sector, measured as of December 31 of the immediately preceding year:
- General regime: companies supervised or controlled by the Superintendencia with total income or assets equal to or greater than 40,000 SMMLV.
- Higher-risk sectors: for activities such as real estate agents, trade in precious metals and stones, legal and accounting services, construction of buildings and civil works, or virtual asset services, the income threshold drops to 30,000 SMMLV.
Companies that do not reach those thresholds may fall under a regime of minimum measures, a lighter one. Checking which category your company falls into, and doing so every year, is the first step: the thresholds are matched against the close of the previous financial year, so a growing company can become a covered entity without realizing it.
What does it require?
- Appointing a compliance officer approved by the board of directors.
- Drawing up a risk matrix for money laundering and terrorist financing, and applying due diligence (knowledge of the client, of the counterparty and of the beneficial owner).
- Defining red flags and internal control procedures.
- Reporting suspicious transactions (ROS) and the other required reports to the UIAF (Unidad de Información y Análisis Financiero), the financial intelligence unit created by Ley 526 de 1999.
A concrete example. Suppose your company receives from a new client an advance payment far above the value of the order, with instructions to return the excess to a third party's account in another country. That is a textbook red flag. With SAGRILAFT up and running, the compliance officer documents the transaction, asks for explanations and, if the case warrants it, files a ROS with the UIAF. With no system, the payment comes in, is processed like any other and the company ends up entangled in somebody else's laundering operation.
Here it is essential not to confuse two levels. SAGRILAFT is an administrative duty: not having it, or having it badly, brings penalties from the Superintendencia. But the conduct it seeks to avoid consists of criminal offenses, carrying prison sentences for natural persons. And deliberately omitting the controls or the reports may itself amount to an offense.
The terrorist financing framework is completed by Ley 1121 de 2006, which structured prevention in the country and strengthened the UIAF as the financial intelligence unit that receives the reports. Note the difference in levels: the company that does not report answers before the Superintendencia (the administrative level); the person who deliberately omits the control or the report answers before the criminal courts (the individual level). The same event, two liabilities.
The PTEE and Ley 1778 de 2016: anti-corruption and soborno transnacional
The second great preventive regime is aimed at corruption. Its basis is Ley 1778 de 2016, amended in several respects by Ley 2195 de 2022, which introduced a decisive concept in Colombia: the administrative liability of legal persons for soborno transnacional; that is, for bribing —through employees, contractors, officers or associates— a foreign public servant in order to obtain or retain an international business deal.
Here the distinction between the administrative and the criminal can be seen with complete clarity, and the statute itself states it without circumlocution. The company answers administratively before the Superintendencia de Sociedades, with penalties that can be devastating. The natural person who pays or promises the bribe answers criminally for the offense of soborno transnacional. They are two parallel liabilities for one and the same event.
Jurisdiction to investigate and penalize the legal person lies with the Superintendencia de Sociedades (Colombia's corporate regulator), even where the conduct was committed abroad, provided the company responsible is domiciled in Colombia. And the penalties are not symbolic.
The PTEE: the program the law expects of you
To prevent that risk, the Superintendencia requires the Programa de Transparencia y Ética Empresarial (PTEE, the business transparency and ethics program), governed by Chapter XIII of the Circular Básica Jurídica (Circular Externa 100-000011 de 2021). It is an anti-corruption program with the elements already seen —risk assessment, policies, compliance officer, due diligence, whistleblowing channel and audit—, focused on dealings with the public sector and with international counterparties.
The following are covered, according to their figures as of December 31 of the previous year, among others:
- Companies with international business or transactions equal to or greater than 100 SMMLV and with total income or assets equal to or greater than 30,000 SMMLV (soborno transnacional risk).
- Those that entered into contracts with State entities for 500 SMMLV or more and have income or assets from 30,000 SMMLV, or belong to certain sectors identified by the Superintendencia (corruption risk).
Having a real PTEE is not merely complying for the sake of complying: the existence of an effective program is a factor the authority expressly weighs when calibrating penalties. A "paper" program, by contrast, protects no one.
It is worth looking at the two regimes side by side, because they share a structure but address different risks:
| SAGRILAFT | PTEE | |
|---|---|---|
| Risk it prevents | Money laundering, terrorist financing and the financing of weapons proliferation | Corruption and soborno transnacional |
| Governing rule | Circular Externa 100-000016 de 2020 (Chap. X, Circular Básica Jurídica) | Circular Externa 100-000011 de 2021 (Chap. XIII) and Ley 1778 de 2016 |
| Supervising authority | Superintendencia de Sociedades | Superintendencia de Sociedades |
| Signature tool | Suspicious transaction report (ROS) to the UIAF | Counterparty due diligence and whistleblowing channel |
| Associated criminal offenses | Arts. 323, 325 and 345 of the Código Penal | Art. 433 of the Código Penal |
The company's administrative liability versus the individual's criminal liability
This is the axis worth committing to memory, because understanding why prevention protects on two fronts at once depends on it. A single event —a bribe, a laundering transaction, a failure to control— can set two different machines in motion, with different logics, authorities and consequences. They do not compete with each other; they run in parallel.
| Criterion | Administrative liability | Criminal liability |
|---|---|---|
| Who is liable? | The legal person (the company) | The natural person (legal representative, officers, employees) |
| Before whom? | The Superintendencia de Sociedades or another supervisory authority | The Fiscalía General de la Nación (Prosecutor's Office) and criminal courts |
| What is at issue? | Breach of a duty (not having SAGRILAFT/PTEE, failing to report, failing to control) | The commission of an offense (laundering, bribery, failure to control) |
| Typical consequence | Fine, disqualification from contracting with the State, publication of the penalty | Imprisonment, fine and disqualification; and, for a company used to commit offenses, suspension of legal personality (art. 91) |
| Governing statute (example) | Ley 1778 de 2016 and the Superintendencia's circulars | Código Penal (Ley 599 de 2000) |
| Does one exclude the other? | No. They operate in parallel: the penalty on the company is "without prejudice" to the criminal liability of the natural person (art. 2 of Ley 1778 de 2016). | |
The practical consequence is easy to state and easy to forget: paying the administrative fine does not erase the executive's criminal case, and winning the criminal case does not cancel the penalty on the company. That is why a compliance program is designed to prevent the event —not to choose which of the two liabilities to bear— and why it is documented with care: the evidence serves in both scenarios.
Third-party due diligence: where the risk comes in
If one had to point to a single place through which most companies become contaminated, it would be this: third parties. Suppliers, distributors, agents, intermediaries, business associates and clients can drag the company into a criminal problem even though it never sought the offense. That is why third-party due diligence is the operational heart of any program: most cases of soborno transnacional and of laundering do not come in through the front door, but through a third party the company did not know well.
Doing it properly means, at a minimum:
- Know the third party before contracting: identity, actual activity, owners and beneficial owner —the flesh-and-blood person who ultimately benefits—.
- Check restricted-party lists (such as those of the UN and OFAC) and verify background and reputation.
- Include contractual clauses on anti-corruption and anti-money laundering, with rights of audit and termination if the third party defaults.
- Watch for red flags: payments to third countries with no apparent reason, disproportionate commissions, insistence on unnecessary intermediaries, invoices with no supporting documents, or resistance to handing over information.
An example. Your company is about to hire a "consultant" who promises to land a State contract in exchange for a 20 % commission, well above market, and refuses to explain what that money is spent on. Due diligence does not consist in signing and hoping: it consists in stopping, documenting the doubt and, if there is no reasonable explanation, not hiring. The common mistake is to treat these controls as a formality at the signing of the contract and not as monitoring that continues throughout the relationship. A third party who is clean today may cease to be so tomorrow.
Due diligence is also the best defense when it is the company itself that ends up being used by a third party as a vehicle for the offense; that scenario —the company as the victim— is covered in an article devoted to the company as victim.
Whistleblowing channels and protection of the whistleblower
No control detects everything. That is why the whistleblowing channel —a confidential and, so far as possible, anonymous ethics line— is one of the most effective tools: it turns every employee into an early sensor of irregular conduct. Many internal frauds and bribes are uncovered through a report, not through an audit.
For it to work, the channel needs two guarantees. First, confidentiality: whoever reports must be able to trust that their identity is protected. Second, freedom from retaliation: the company must undertake in writing that reporting in good faith will bring no adverse employment consequences. Both SAGRILAFT and the PTEE require having these mechanisms and dealing with reports seriously.
An example of what must not happen: an employee reports through the channel that a manager asks suppliers for "commissions", and weeks later that employee is transferred or dismissed on some pretext. The message the whole organization receives is unmistakable: reporting comes at a high price. From then on, the channel is dead. A channel nobody uses —or that punishes whoever uses it— is worse than not having one, because it creates a false sense of control and, on top of that, proves the company knew and did not act.
How the program reduces executives' criminal exposure
This is the point of greatest interest to anyone who runs a company. A compliance program is not an insurance policy that "erases" the offense —nothing does—, but it does bear on the officers' criminal exposure in three concrete ways:
- It lowers the probability. Fewer opportunities for an offense simply mean fewer proceedings. Most controls operate here: they keep the event from happening.
- It demonstrates diligence. Faced with an investigation, a real program —with evidence that it was applied— helps show that the executive acted with care and did not acquiesce in the event, which is relevant when their individual liability is argued.
- It mitigates the company's penalty. On the administrative side, the existence of an effective PTEE or SAGRILAFT is a factor the Superintendencia weighs in the company's favor.
The key word is effective. A cosmetic program, with no budget, no training and no audit, fools no one and may even aggravate the perception of negligence. Diligence is proven with documented facts —updated risk matrices, training records, reports acted upon, decisions not to contract—, not with manuals kept in a drawer. In a proceeding, the question will not be "did you have a manual?", but "what did you do the day the red flag appeared?".
First steps to implement a minimum program
There is no need to begin with a perfect system; what is needed is to begin well. A midsize company can set up a minimum viable program with an orderly route:
- Diagnosis. Establish whether your company is a covered entity under SAGRILAFT or the PTEE and assess its real risks according to sector, clients, geographies and operations.
- Backing from the leadership. Take the matter to the board and assign budget and authority; without this, the rest does not hold up.
- Compliance officer. Appoint a person in charge who has independence and no conflict of interest with the areas they must control.
- Policies and code of conduct. Draft them tailored to the company, not copied from a template, with concrete rules on gifts, payments and third parties.
- Due diligence and whistleblowing channel. Put them in place with clear procedures and defined owners.
- Training. Train employees and executives, tailored to each role, and keep a record of attendance and assessment.
- Audit and improvement. Review periodically that the controls work, correct what fails and document everything you do.
Documentation is not bureaucracy: it is the proof that the program exists and works on the day someone —an authority, a judge, a demanding client— asks. A program proportionate to the company's size and risk is worth far more than an ambitious one that nobody carries out.
What NOT to do
As important as knowing what to build is knowing what to avoid. These are the mistakes that, time and again, turn a program into a useless facade:
- Do not copy another company's manual and sign it as your own. A program that does not reflect your real operation prevents nothing and, before the authority, betrays that no serious risk assessment was ever carried out.
- Do not appoint as compliance officer someone who has a conflict of interest —for instance, the same person who approves the payments or closes the deals—. Independence is the essence of the role.
- Do not treat due diligence as a one-time formality. Knowing the third party at signing and never looking at them again leaves the door open for the whole relationship.
- Do not set up a whistleblowing channel without real protection for the whistleblower. If there is retaliation, the channel turns against the company: it proves it knew and did not protect.
- Do not ignore red flags in order not to lose a deal. The contract saved today by skipping a control is tomorrow's criminal case.
- Do not leave the program without budget or audit. A program that is neither carried out nor reviewed is, in a judge's eyes, confirmation of the negligence, not an excuse for it.
- Do not use the program as a public shield while the same conduct is tolerated inside. The contradiction between what is said and what is done aggravates; it does not mitigate.
Common myths
Mistaken ideas circulate around criminal compliance that lead companies not to act, or to act badly. They are worth dismantling:
Myth: "Compliance is only for large multinationals". Reality: the SAGRILAFT and PTEE thresholds reach many midsize Colombian companies, and serious counterparties demand controls from their suppliers regardless of size. Prevention does not depend on being large, but on being exposed.
Myth: "Since the company does not go to prison, the risk is lower". Reality: the company faces fines, disqualification from contracting, extinción de dominio (asset forfeiture) and even the suspension of its legal personality. And its officers —flesh-and-blood people— are indeed criminally liable.
Myth: "Having the manual is enough". Reality: a manual with no implementation, budget or audit does not protect; it may even aggravate the perception of negligence. What counts is the effective program, not the document.
Myth: "If an employee or an intermediary committed the offense, the company is not liable". Reality: Ley 1778 de 2016 holds the legal person liable precisely for the acts of its employees, contractors, officers or associates. Delegating does not transfer the risk.
Myth: "Compliance slows the business down". Reality: a well-designed program speeds up decisions —it defines in advance what is allowed and what is not— and opens doors, because more and more clients and allies demand counterparties with controls. Prevention is also a commercial argument.
Myth: "A program exempts me from liability". Reality: it does not exempt automatically. It reduces the probability of the offense and, if something happens, it helps demonstrate diligence and mitigates the administrative penalty. It is not an insurance policy; it is a barrier.
Checklist for a minimum viable compliance program
Use this list as a quick self-diagnosis. If you answer "no" or "I don't know" to several boxes, your company has work ahead of it:
- Have you checked this year whether your company is a covered entity under SAGRILAFT or the PTEE, using the figures as of December 31 of the previous year?
- Do you have a risk matrix built on your own operation, and not copied?
- Did the board or senior management back the program with budget and authority, and was it recorded in the minutes?
- Have you appointed a compliance officer with independence and no conflict of interest?
- Do you have a code of conduct with concrete rules on gifts, payments, conflicts of interest and third parties?
- Do you carry out due diligence on clients, suppliers and intermediaries before contracting, including the beneficial owner?
- Do your contracts include anti-corruption and anti-money-laundering clauses with rights of audit and termination?
- Do you check restricted-party lists and have you defined red flags?
- Do you have a confidential whistleblowing channel with effective protection for the whistleblower?
- Do you train employees and executives and keep a record of attendance?
- Do you report suspicious transactions to the UIAF when required?
- Do you audit the program periodically and document every control, decision and report?
In summary
Preventing criminal risk is, in the long run, cheaper and more dignified than defending against it. A well-designed compliance program protects the company's assets, its reputation and the peace of mind of those who run it; and it keeps in view the distinction that runs through this whole guide: the company's administrative liability and the natural person's criminal liability run in parallel, and only prevention acts on both at once. At Cafore Abogados we support the design and implementation of criminal compliance programs suited to your sector and your size, and we assess whether or not your company is covered by SAGRILAFT or the PTEE. If you would like to review your exposure, you can write to us or call us at 313 8411825.
Laws and case law cited
- Art. 323 of the Código Penal (Ley 599 de 2000) — defines the offense of money laundering; imprisonment of 10 to 30 years and a fine of 1,000 to 50,000 SMMLV. Source
- Art. 324 of the Código Penal (Ley 599 de 2000) — aggravates money laundering when it is committed by managers, officers or persons in charge of the legal person. Source
- Art. 325 of the Código Penal (Ley 599 de 2000) — defines the offense of failure to control by executives and employees of financial institutions and savings and credit cooperatives. Source
- Art. 325A of the Código Penal (Ley 599 de 2000) — defines the offense of failing to file reports with the UIAF on cash transactions. Source
- Art. 345 of the Código Penal (Ley 599 de 2000) — administration of resources connected with terrorist activities; imprisonment of 6 to 12 years and a fine of 200 to 10,000 SMMLV. Source
- Art. 433 of the Código Penal (Ley 599 de 2000) — defines the offense of soborno transnacional in the hands of the natural person; imprisonment of 9 to 15 years and a fine of 650 to 50,000 SMMLV. Source
- Art. 91 of Ley 906 de 2004 — allows the suspension or cancellation of legal personality used to commit offenses. Source
- Ley 1778 de 2016 (arts. 2, 3, 5, 7 and 23), as amended by Ley 2195 de 2022 — administrative liability of legal persons for soborno transnacional; jurisdiction of the Superintendencia de Sociedades; penalties; criteria for calibrating them; and business transparency and ethics programs (PTEE). Source
- Ley 2195 de 2022 — reforms the penalty regime of Ley 1778 de 2016 (arts. 19 to 25). Source
- Ley 526 de 1999 — creates the Unidad de Información y Análisis Financiero (UIAF), which receives and analyzes suspicious transaction reports. Source
- Ley 1121 de 2006 — framework for preventing terrorist financing and strengthening the UIAF. Source
- Circular Externa 100-000016 de 2020 — Chapter X, Superintendencia de Sociedades — governs SAGRILAFT and the thresholds for covered companies. Source
- Circular Externa 100-000011 de 2021 — Chapter XIII, Superintendencia de Sociedades — governs the PTEE (Programa de Transparencia y Ética Empresarial). Source
- Corte Constitucional, Sentencia SU-1184 de 2001 — posición de garante and duty of oversight (Código Penal, art. 25). Official text.
- Corte Constitucional, Sentencia C-320 de 1998 — limits on the liability of the legal person; no strict liability. Official text.
- Corte Constitucional, Sentencia C-843 de 1999 — unconstitutionality of penalties on legal persons without statutory definition. Official text.
- Corte Constitucional, Sentencia C-603 de 2016 — measures against the legal person used to commit offenses (art. 91 Ley 906; art. 34 Ley 1474). Official text.
- Corte Constitucional, Sentencia C-165 de 2019 — administrative regime for soborno transnacional (Ley 1778 de 2016). Official text.


