AML and Anti-Bribery Compliance
Money laundering, terrorism financing and transnational bribery prevention programs.
SAGRILAFT and PTEE are the two compliance programs the Colombian Superintendency of Companies requires from a large part of the real sector. The first one addresses money laundering, terrorism financing and the proliferation of weapons of mass destruction; the second one, transnational bribery and corruption. Neither is a document that gets filed away: they are systems the company runs every day and has to be able to evidence the day the authority asks.
The first question —whether your company is covered— is the one most often answered badly, because the obligation does not depend on size alone and the criteria have changed across versions of the circular. From there, the work is building a program the board can approve, staff can actually run, and that leaves a documentary trail. The manual is the last piece, not the first.
Who this is for
- Companies that crossed the thresholds, or sit in a sector covered with no threshold, and have nothing in place.
- Companies with a generic manual and no procedure behind it.
- Corporate groups that need a common standard and separate programs per subsidiary.
- Exporters, bidders in public procurement and companies working through agents or intermediaries abroad.
- Companies in a sale process, taking in an investor, or joining a supply chain that demands evidence of compliance.
- Companies that have already received a request from the Superintendency or detected an internal irregularity.
We work from Bogotá with clients across Colombia: the written opinion on whether the duty applies, the implementation of the SAGRILAFT and the PTEE, the compliance officer, counterparty due diligence and the audit of the program, including responses to requests and investigations before the Superintendency of Companies.
Services within this area
Written opinion on whether your company must have a SAGRILAFT and a PTEE
We review your figures, corporate purpose and actual operations and deliver a written opinion: whether you are covered, under which regime and since when.
Learn more →SAGRILAFT implementation: risk matrix, manual and procedures
Risk diagnosis, documented matrix, a manual drafted on your real operation, due diligence procedures, red flags and training with records. Bogotá, Colombia.
Learn more →Business Transparency and Ethics Programme (PTEE)
Code of conduct, gifts and travel policy, whistleblowing channel, due diligence on agents and intermediaries, and anti-bribery contract clauses. Bogotá.
Learn more →SAGRILAFT and PTEE Consultant in Colombia
SAGRILAFT and PTEE implementation per Circular 100. Diagnostic, manual, training, compliance officer.
Learn more →Compliance officer appointment, training and ongoing support
Profile, duties, independence, appointment minute, registration filing, training for the appointee and ongoing external support for the role. Bogotá.
Learn more →Counterparty due diligence, beneficial ownership and UIAF reporting
We design know-your-counterparty: minimum information, beneficial ownership, list screening, PEPs, unusual transactions and reporting to the UIAF. Bogotá.
Learn more →SAGRILAFT and PTEE audit and preparation for a supervisory visit
External review of the programme against the applicable circular and your real operation, gap report, remediation plan and responses to requests. Bogotá.
Learn more →Corporate Compliance Advisory in Colombia
Integrated compliance programs: SAGRILAFT, PTEE, anti-bribery, data protection, antitrust.
Learn more →Frequently asked questions
How do I know whether my company has to implement SAGRILAFT? +
It turns on two things: whether the company exceeds the asset or revenue thresholds set out in the Superintendency of Companies' Basic Legal Circular, and whether it belongs to one of the sectors covered regardless of size. Both the thresholds and the list have changed across successive versions of the circular, so the answer is checked against the financial statements for the relevant cut-off date and against what the company actually does. We deliver that conclusion in writing.
What is the difference between SAGRILAFT and PTEE? +
They address different risks. SAGRILAFT targets money laundering, terrorism financing and the financing of the proliferation of weapons of mass destruction, and rests on knowing your counterparties. The PTEE targets transnational bribery, corruption and fraud, and rests on the code of conduct, the whistleblowing channel and due diligence on intermediaries and business partners. A company may be required to have one, both or neither.
Are SAGRILAFT and SARLAFT the same thing? +
No. SARLAFT is the financial sector system, required by the Financial Superintendency. SAGRILAFT is the real sector system, required by the Superintendency of Companies. The underlying risk-management logic is similar, but the scope, the supervising authority and the specific obligations differ, and a manual copied from the other regime usually creates more problems than it solves.
Who can be the compliance officer, and can it be someone external? +
It must be an individual with knowledge of the risk, functional independence from the areas being controlled, and a direct reporting line to the highest corporate body. The appointment is documented and registered with the Superintendency. The role is exercised from within the company, but where the appointee has no prior experience we provide ongoing external support: we train them, hand over the calendar of their obligations and review their reports with them.
We already have a manual. Is it usable or does it need redoing? +
It depends on what sits behind it. A generic manual, with no risk matrix built on the actual business, no procedures staff actually follow and no training records, is hard to defend in a review. What we do is audit the program against the applicable circular and against how the company really operates, and deliver a gap report with a remediation plan prioritised by risk. In many cases the structure is kept and the missing pieces are fixed.
What happens if the Superintendency inspects us or sends an information request? +
The authority reviews documentation, interviews the compliance officer and checks whether the program is genuinely applied, not merely written down. An information request carries a deadline, and what is filed shapes the discussion that follows. The first thing we do is confirm the date of service and the applicable deadline; from there we prepare the response and take on the technical defence in the administrative investigation, which can reach both the company and its directors and officers.
What does the client receive at the end of an implementation? +
An adopted program, not a folder. That includes the risk assessment, the documented matrix with the reasoning behind each rating, the manual drafted around the company's operations, the minutes approving it, the due diligence procedures and templates, the red flags with their escalation route, the supporting record of the compliance officer's appointment and the record of the training delivered.
Do we have to report to the UIAF, and is the counterparty told? +
Where the internal analysis concludes that a transaction is suspicious, a report must be filed with the UIAF. The rule worth being clear about from the outset is that the reported counterparty is not informed. That is why the procedure has to set out in writing who analyses the alert, who decides, and how the decision is documented, both when a report is filed and when the conclusion is that no report is due.
Ready to protect what you've built?
Every case starts with an honest conversation. Book 30 minutes, no commitment.
Book →