← Regulations / Colombia / Operating Models / Custodial SaaS

Custodial wallet / SaaS in Colombia

Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).

Conditional AI-Generated · Unreviewed

Custodial SaaS is conditionally permitted in Colombia with a local entity, subject to AML obligations and medium licensing burden.

Verdict Details

Permitted
conditional
Local entity required
Yes
Licensing burden
Medium
Last updated
2026-07-13

AML Obligations

  • All VASPs (including custodial wallet/SaaS providers) are 'obliged entities' and must register with and report to the Unidad de Información y Análisis Financiero (UIAF) under Law 526 of 1999.
  • Implement comprehensive AML/CFT policies and procedures under UIAF Resolution 314/2021 (SARLAFT).
  • Conduct customer due diligence (CDD) including verification of national ID (Cédula de Ciudadanía), NIT for entities, and beneficial owners (≥25% ownership).
  • Apply risk-based approach — Enhanced Due Diligence (EDD) for PEPs, high-risk jurisdictions, high-value or unusual transactions.
  • Continuously monitor transactions and report suspicious transactions (SARs) to the UIAF.
  • Screen against UN Security Council sanctions (incorporated via presidential decrees and UIAF mandate).
  • Train personnel on AML/CFT obligations.
  • If the SaaS provider partners with a regulated financial institution via the La Arenera sandbox, additional SFC-imposed AML/CFT reporting obligations may apply at the institutional level.
  • White-label clients who are themselves VASPs likely bear separate direct AML obligations as obliged entities under UIAF rules.

Key Restrictions

  • No specific 'crypto custody license' exists — operators function in a grey area unless they enter the La Arenera regulatory sandbox (Decree 1234 of 2020 / Circular Externa 021 de 2023).
  • To interact with the traditional financial system (e.g., fiat on/off ramps through Colombian banks), the operator generally needs to participate in La Arenera in partnership with a regulated financial institution.
  • Client crypto assets must be segregated from the firm's own assets (general principle under Colombian financial law — Estatuto Orgánico del Sistema Financiero, Decree 663 of 1993).
  • No mandatory insurance or bonding requirements exist for unregulated crypto custodians; insurance applies only if the operator is a regulated financial institution.
  • No specific cold storage mandates, though robust cybersecurity measures are expected under general data protection law (Ley 1581 de 2012).
  • If the custodial wallet service crosses into activities falling under existing financial services laws (payment services, collective investment schemes, securities), SFC licensing would be triggered.

Key Risks

  • Enforcement precedent: The SIC and Fiscalía have aggressively pursued unregistered financial intermediation and pyramid schemes involving crypto (OmegaPro, Daily Cop, Generación Zoe), imposing fines in the hundreds of millions to billions of COP and pursuing criminal charges.
  • Regulatory ambiguity: Custodial wallet/SaaS providers operate in a grey area — not formally licensed, but subject to AML/CFT obligations; the line between 'custody' and 'unauthorized financial intermediation' is not clearly defined.
  • Sandbox dependency: The only structured path to regulatory clarity involves the La Arenera sandbox, which is temporary and limited in scope; exiting the sandbox without a permanent licensing framework creates uncertainty.
  • White-label liability risk: The SaaS provider may face enforcement action if its white-label client misuses the platform for fraud or unregistered financial intermediation, given the SIC's focus on promoters and intermediaries.

Evidence

This verdict synthesizes the following facts. Each fact links to its primary source(s).

custody 70% confidence

In Colombia, standalone virtual asset service providers (VASPs) offering services related to virtual assets are not supervised by the Superintendencia Financiera de Colombia (SFC) as traditional financial market institutions, but they are now directly subject to specific AML/CTF and reporting obligations (notably UIAF Resolution 314‑2021) and to an emerging, VASP‑focused regulatory framework that goes beyond the earlier situation where only already‑regulated financial entities were within SFC‑linked oversight when their traditional services touched crypto.

custody 60% confidence

However, if a firm engaged in crypto custody also conducts activities that fall under existing financial services laws (e.g., operating as a payment service provider, managing collective investment schemes, or issuing securities), then it would be subject to the SFC's licensing and supervision requirements for those specific activities.

custody 100% confidence

The "La Arenera" Regulatory Sandbox: This is the closest Colombia has to a structured approach for crypto firms.

custody 100% confidence

Decree 1234 of 2020 established the framework for innovative projects in financial technologies (FinTech) within a regulatory sandbox (known as "La Arenera").

custody 90% confidence

Custody Aspect: While not a "custody license," participating crypto platforms in the sandbox, especially those handling client funds/assets, are subject to heightened scrutiny regarding risk management, cybersecurity, and consumer protection. Some projects involving the intermediation of crypto assets have been approved, which inherently involves some form of custody.

custody 90% confidence

Separation: Client assets must be clearly segregated from the firm's own assets to protect clients in case of firm insolvency.

custody 90% confidence

Fiduciary Duty: Entities holding client assets (e.g., fiduciaries, custodians) have a fiduciary duty to act in the best interest of their clients.

custody 90% confidence

These principles are deeply embedded in Colombian financial law (e.g., Estatuto Orgánico del Sistema Financiero (Decree 663 of 1993)) and would likely be extended to crypto custody if a firm operates under SFC oversight.

custody 100% confidence

General Cybersecurity & Data Protection: Colombia has general data protection laws (Ley 1581 de 2012) that require entities handling personal data to implement appropriate security measures. While not directly about asset storage, it sets a precedent for strong cybersecurity.

licensing 20% confidence

Similar to exchanges, there's no specific license for crypto custody services. If custody is offered in a way that interacts with the traditional financial system or involves managing significant client funds, participation in the La Arenera sandbox would be the route for formal approval and supervision.

licensing 20% confidence

Interaction with Financial System: If an exchange seeks to offer fiat currency on/off-ramps through Colombian banks, it generally needs to participate in the SFC's Regulatory Sandbox ("La Arenera") in partnership with a regulated financial institution. This sandbox allows for supervised pilot programs.

licensing 20% confidence

Registration Regime (AML/CFT): Colombia primarily operates a registration regime for AML/CFT purposes. All VASPs, regardless of whether they are licensed or participating in the sandbox, are considered "obliged entities" by the Unidad de Información y Análisis Financiero (UIAF) and must:

licensing 20% confidence

Exchanges (Virtual Asset Service Providers - VASPs):

licensing 20% confidence

General Operation: VASPs operating without direct interaction with the traditional financial system (e.g., direct fiat on/off-ramps via banks) are primarily subject to AML/CFT obligations but are not licensed by the SFC. They operate in a somewhat "grey area" from a licensing perspective, though the UIAF views them as obliged entities for AML purposes.

licensing 20% confidence

Ongoing Development: Ley 2143 of 2021 mandated the SFC to propose a comprehensive regulatory framework for crypto assets, indicating a future move towards a more formal licensing system.

licensing 20% confidence

AML/CFT Obligations: All VASPs are subject to Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT) requirements, regardless of whether they are licensed or not.

licensing 95% confidence

Regulatory Sandbox (La Arenera): The closest mechanism for innovation is the SFC's La Arenera, a regulatory sandbox established under Circular Externa 021 de 2023. This allows financial entities (and in certain cases, non-supervised entities in partnership with supervised ones) to test innovative financial services, including those involving crypto assets, under a controlled environment with temporary waivers or specific authorizations. However, participating in La Arenera does not exempt a token from being classified as a security; rather, it allows for a structured dialogue and potential adaptation of regulations if a security token is being tested.

aml 20% confidence

Law 526 of 1999: This law created the Financial Information and Analysis Unit (UIAF) and established its functions as Colombia's Financial Intelligence Unit (FIU). It is the foundational law for AML/CFT in the country.

aml 20% confidence

Decree 1068 of 2015 (as modified by Decree 169 of 2020): This crucial decree explicitly incorporates "virtual assets" into the scope of assets and operations that the UIAF must analyze to prevent money laundering and terrorism financing. It empowers the UIAF to establish reporting requirements for entities involved in operations with virtual assets.

aml 20% confidence

Circular Externa 026 de 2020 (Superintendencia Financiera de Colombia - SFC): While this circular is primarily directed at financial institutions supervised by the SFC regarding the risks associated with operations with crypto assets, it sets a clear expectation for how the traditional financial system should approach virtual assets. It indirectly pressures VASPs to adhere to robust AML/CFT practices if they wish to interact with the regulated financial sector.

aml 20% confidence

FATF Recommendations: As a country committed to international AML/CFT standards, Colombia aligns its regulations with the FATF Recommendations. Recommendation 15 specifically targets new technologies, including virtual assets and VASPs, requiring them to be regulated for AML/CFT purposes, licensed or registered, and subject to effective systems for monitoring and ensuring compliance.

aml 100% confidence

Resolución 314 de 2021 de la UIAF: Por la cual se imparten instrucciones relacionadas con el SARLAFT a los proveedores de servicios de activos virtuales.

aml 20% confidence

Risk-Based Approach: VASPs must implement a risk-based approach to CDD. This means applying enhanced due diligence (EDD) for higher-risk customers (e.g., Politically Exposed Persons - PEPs, customers from high-risk jurisdictions, complex corporate structures, high-value transactions, or unusual transaction patterns) and simplified due diligence (SDD) for lower-risk customers.

aml 20% confidence

Ongoing Monitoring: Continuous scrutiny of transactions undertaken throughout the course of the relationship to ensure that they are consistent with the VASP's knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.

aml 100% confidence

UN Sanctions: As a member state of the United Nations, Colombia is legally obligated to implement sanctions imposed by the UN Security Council. UIAF Resolution 314/2021 directly references adherence to UN Security Council resolutions as a core component of ML/TF risk management. This includes asset freezes and other restrictions against listed individuals and entities.

enforcement 100% confidence

Entity Targeted: OmegaPro Group (an international alleged Ponzi scheme), its local promoters, influencers, and related entities operating in Colombia (e.g., Bux Corp, Smart Business Corp). Violation Type: Unregistered and unauthorized financial intermediation, operating a multi-level marketing scheme that promised high returns without proper backing, misleading advertising, consumer fraud, and alleged pyramid scheme. Outcome: SIC ordered the cessation of all promotion and operations of OmegaPro-related schemes in Colombia, imposed significant fines, and mandated restitution to affected consumers. The Fiscalía has pursued criminal charges, leading to arrests of key promoters and the freezing of assets. Many victims have lost significant sums, and the full extent of recovery is uncertain.

enforcement 100% confidence

Entity Targeted: Daily Cop S.A.S. and its founders/promoters (e.g., Camilo Andrés Suárez Aldana, David Mateo Suárez Aldana). Violation Type: Alleged pyramid scheme, unauthorized and illegal financial intermediation using cryptocurrencies as a front, offering unrealistic returns, consumer fraud. Outcome: SIC issued a definitive resolution ordering the immediate cessation of Daily Cop's activities, imposing fines, and requiring restitution. The Fiscalía subsequently arrested key figures behind the scheme and initiated criminal proceedings, uncovering millions of dollars in alleged fraud.

enforcement 96% confidence

Entity Targeted: Local promoters and affiliates of the international Generación Zoe scheme operating in Colombia. Violation Type: Alleged illegal financial intermediation, fraud, and operating a Ponzi/pyramid scheme under the guise of coaching and crypto investments. Penalty Amount: Arrests and criminal charges against Colombian operators. Assets linked to the scheme were seized. Outcome: Colombian authorities, working with international counterparts, arrested individuals linked to Generación Zoe's operations in the country. Criminal proceedings are ongoing for charges related to aggravated fraud and illegal financial intermediation. Outcome: Provided valuable insights for future regulation, demonstrating a willingness by the SFC to study and understand crypto operations under controlled conditions.

Verdict Attribution

Source:
AI-Generated · Unreviewed
AI synthesized:
2026-07-13 (deepseek-chat)
Last updated:
2026-07-13
Confidence:
medium

This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.

Conditional — custodial wallet/SaaS providers may operate in Colombia as unlicensed VASPs subject to UIAF AML/CFT obligations, but to interact with the traditional financial system or obtain formal regulatory cover they must enter the La Arenera sandbox in partnership with a regulated entity; no specific custody license, segregation, insurance, or cold storage mandates exist, creating significant grey-area risk.

Questions this verdict aims to answer

  • What custody license / qualified-custodian status applies?
  • What segregation, insurance, and proof-of-reserves rules apply?
  • What AML obligations attach to the SaaS vs the white-label client?