The 254 institutions supervised by Colombia’s Superintendencia Financiera (SFC) manage 1,732 trillion pesos, and 87% of that money is not theirs: it is deposits from the public, borrowing from other banks, third-party funds. That single figure explains why a bank is organised the way it is. Anyone operating with other people’s money needs someone watching how much risk it takes, and someone else watching that it stays within the law.
A note on scale: Colombian financial reporting uses the long scale, where billón means a million millions. “Trillion” here means 10¹², which is what a Colombian reader sees as billón.
This guide lays out that full structure and focuses on the distinction most often blurred: Risk and Compliance are not the same function, even though both sit in the second line of defence and both are independent of the business.
The embedded map is in Spanish, since it reproduces the Colombian regulatory vocabulary; the acronyms are explained below.
Three lines of defence
The skeleton is the three-lines model:
- First line — the business. Retail banking, corporate banking, treasury, the credit factory, operations, channels. It takes the risk and owns it: it is first responsible for controlling it.
- Second line — oversight. It sets the framework, measures, sets limits and challenges the first line. This is where Risk and Compliance split.
- Third line — internal audit. It manages nothing: it assesses whether the first two lines work, and reports to the Audit Committee.
Above sits governance — the board of directors and its Risk, Audit, AML (SARLAFT), ALCO and Credit committees — which approves the framework and the risk appetite. That approval cannot be delegated. Outside the perimeter sit the SFC, the statutory auditor (revisoría fiscal), the financial intelligence unit (UIAF), external auditors and rating agencies.
Two functions answering different questions
| Risk | Compliance | |
|---|---|---|
| Core question | How much loss can we tolerate, and what capital backs it? | Are we operating within the rules and our own ethics? |
| Nature | Taken on purpose and rewarded with return | Neither sought nor rewarded: only avoided |
| Logic | Optimisation between risk and return | Binary: you comply or you don’t |
| Base regulation | SIAR — External Circular 018 of 2021 | SARLAFT 4.0 — External Circular 027 of 2020 |
| Led by | CRO or head of Risk | Compliance Officer, personally accountable to the SFC |
| If it fails | Financial loss, portfolio deterioration, capital erosion | Fines, personal sanctions, criminal exposure, loss of correspondent banks |
The row that says the most is the logic. Risk has an optimum: a bank that took no credit risk would not lend, and would have no business. Compliance has no “optimal level of non-compliance”. That is why they cannot report to the same head: whoever optimises is tempted to negotiate, and whoever guards the rules should not be able to.
Risk: what is taken on purpose
Under the CRO sit three families:
- Financial risks: credit (SARC), market (SARM), liquidity (SARL), interest-rate risk in the banking book, and counterparty risk.
- Non-financial risks: operational (SARO), information security and cybersecurity, business continuity, and environmental, social and climate risk.
- Capital and models: the risk appetite statement, capital adequacy with its stress tests, and independent model validation.
Since 2021 the SFC groups them into a single system, the SIAR (Integrated Risk Management System), which requires them to be managed together rather than as silos.
Compliance: what is only avoided
The core is anti-money-laundering and counter-terrorist financing. SARLAFT 4.0 takes a risk-based approach across four factors — customer, product, channel and jurisdiction — and covers know-your-customer, monitoring of unusual transactions, suspicious activity reports to the UIAF, and screening against sanctions lists and politically exposed persons.
Around that core sit regulatory compliance (the regulatory inventory, financial consumer protection, FATCA/CRS tax reporting, the foreign-exchange regime) and conduct: market abuse, conflicts of interest, anti-corruption and the whistleblowing channel.
One detail that makes the difference: the Compliance Officer takes office before the SFC and answers personally. It is not a role a bank can quietly reassign.
The grey zone
Some topics sit in Risk at one bank and in Compliance or Legal at another: fraud (it is operational risk, but its investigation touches Compliance), legal risk, personal data protection, conduct risk, cybersecurity and reputational risk, which no one originates because it is the consequence of failures on either side.
There is no single answer. What a supervisor checks is that each topic is explicitly assigned, with no gaps.
One template for every system
SARC, SARM, SARL, SARO and SARLAFT share the same anatomy: identification, measurement, control and monitoring, supported by policies, procedures, documentation, structure, control bodies, technology, disclosure and training. Anyone who understands the template can rebuild any of them.
Where it all comes from
Colombian regulation is the local translation of Basel. Pillar I sets minimum capital for credit, market and operational risk; Pillar II requires the bank to assess its own risks and show its capital covers them; Pillar III demands disclosure so the market disciplines poor risk management. Basel III added the capital buffers and liquidity ratios, which entered Colombian rules through Decree 1477 of 2018.
What changed in 2026
On 14 April 2026 the SFC issued the Circular Básica Financiera (External Circular 004 of 2026), replacing the former Circular Básica Contable y Financiera after a consolidation process. Its first part is risk management itself. If you cite a rule, check it against the new circular.
Who this map is for
For anyone starting out in banking who needs to find their place on the org chart; for anyone selling technology or services to a bank who needs to know who decides what; for anyone preparing an interview in risk, fraud or compliance; and for anyone reading the sector’s financial statements who wants to understand why 87% leverage is normal for a bank and alarming for any other company. That comparison is in the analysis of the three regulators, and the sector’s figures in the financial sector X-ray.
This map is study material, not regulatory advice.
Sources
- Circular Básica Financiera (External Circular 004 of 2026) — Superintendencia Financiera
- Consolidation of the Circular Básica Contable y Financiera completed — Superintendencia Financiera
- Colombia implements SIAR and SARE — Garrigues
- Instructions on AML/CFT risk management (SARLAFT 4.0) — Garrigues
- The compliance officer: duties and responsibilities — Infolaft
Explore the dashboard
Interactive: filter, hover over the bars, and open the tables. Open full screen →