DeFi protocol frontend in Colombia
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Colombia with a local entity, subject to AML obligations and medium licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- Medium
- Last updated
- 2026-07-13
AML Obligations
- All VASPs (including DeFi frontends operating as obliged entities) must register with the UIAF for AML/CTF purposes per Resolución 314 de 2021.
- Implement risk-based AML/CTF policies and procedures per UIAF Resolution 314/2021.
- Conduct comprehensive Customer Due Diligence (CDD) including identification of beneficial owners (≥25% ownership) and PEPs.
- Ongoing monitoring of transactions to ensure consistency with customer risk profile.
- Report Suspicious Transaction Reports (STRs/SARs) to the UIAF.
- Train personnel on AML/CTF obligations.
- Screen against UN sanctions lists (implemented via presidential decrees and UIAF mandate).
Key Restrictions
- Cannot engage in unauthorized mass capture of public funds — this triggers SIC enforcement and criminal liability under Fiscalía.
- If the frontend takes fees or intermediation (e.g., routing user funds through a proprietary intermediary smart contract), it may be classified as unlicensed financial intermediation.
- Geofencing (region restriction) of Colombian users is advisable unless the operator registers for AML/CTF compliance with UIAF and implements full KYC/CDD.
- No ability to offer direct fiat on/off-ramps via Colombian banks without entering the SFC's La Arenera regulatory sandbox in partnership with a regulated financial institution.
- Cryptocurrencies are not legal tender; no specific DeFi/crypto framework exists — operators operate in a regulatory grey area outside of SFC supervision unless they touch the financial system.
Key Risks
- Enforcement precedent: SIC has fined and shut down crypto-related operations (OmegaPro, Daily Cop) for unauthorized resource capture; Fiscalía has brought criminal charges for illegal financial intermediation and money laundering.
- Regulatory ambiguity: No clear guidance on whether a non-custodial frontend that merely aggregates permissionless smart contracts is a VASP subject to UIAF registration.
- If the frontend charges fees (e.g., swap fees, routing fees), it increases the risk of being treated as an unlicensed financial intermediary, triggering SIC enforcement.
- Data protection obligations under Ley 1581 de 2012 apply if the frontend collects any personal data from Colombian users.
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Exchanges (Virtual Asset Service Providers - VASPs):
General Operation: VASPs operating without direct interaction with the traditional financial system (e.g., direct fiat on/off-ramps via banks) are primarily subject to AML/CFT obligations but are not licensed by the SFC. They operate in a somewhat "grey area" from a licensing perspective, though the UIAF views them as obliged entities for AML purposes.
AML/CFT Obligations: All VASPs are subject to Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT) requirements, regardless of whether they are licensed or not.
Registration Regime (AML/CFT): Colombia primarily operates a registration regime for AML/CFT purposes. All VASPs, regardless of whether they are licensed or participating in the sandbox, are considered "obliged entities" by the Unidad de Información y Análisis Financiero (UIAF) and must:
Resolución 314 de 2021 de la UIAF: Por la cual se imparten instrucciones relacionadas con el SARLAFT a los proveedores de servicios de activos virtuales.
Identification and Verification of Customers:
Identification and verification of beneficial owners (typically individuals holding 25% or more of the company's shares or voting rights, or exercising control through other means).
Risk-Based Approach: VASPs must implement a risk-based approach to CDD. This means applying enhanced due diligence (EDD) for higher-risk customers (e.g., Politically Exposed Persons - PEPs, customers from high-risk jurisdictions, complex corporate structures, high-value transactions, or unusual transaction patterns) and simplified due diligence (SDD) for lower-risk customers.
Report suspicious transactions (SARs) to the UIAF.
Ongoing Monitoring: Continuous scrutiny of transactions undertaken throughout the course of the relationship to ensure that they are consistent with the VASP's knowledge of the customer, their business, and risk profile, including, where necessary, the source of funds.
UN Sanctions: As a member state of the United Nations, Colombia is legally obligated to implement sanctions imposed by the UN Security Council. UIAF Resolution 314/2021 directly references adherence to UN Security Council resolutions as a core component of ML/TF risk management. This includes asset freezes and other restrictions against listed individuals and entities.
Cryptocurrencies are not legal tender in Colombia.
They are not regulated by the SFC as financial products or securities, unless they exhibit characteristics that make them fall under existing definitions (e.g., a security token).
In Colombia, standalone virtual asset service providers (VASPs) offering services related to virtual assets are not supervised by the Superintendencia Financiera de Colombia (SFC) as traditional financial market institutions, but they are now directly subject to specific AML/CTF and reporting obligations (notably UIAF Resolution 314‑2021) and to an emerging, VASP‑focused regulatory framework that goes beyond the earlier situation where only already‑regulated financial entities were within SFC‑linked oversight when their traditional services touched crypto.
Entity Targeted: OmegaPro Group (an international alleged Ponzi scheme), its local promoters, influencers, and related entities operating in Colombia (e.g., Bux Corp, Smart Business Corp). Violation Type: Unregistered and unauthorized financial intermediation, operating a multi-level marketing scheme that promised high returns without proper backing, misleading advertising, consumer fraud, and alleged pyramid scheme. Outcome: SIC ordered the cessation of all promotion and operations of OmegaPro-related schemes in Colombia, imposed significant fines, and mandated restitution to affected consumers. The Fiscalía has pursued criminal charges, leading to arrests of key promoters and the freezing of assets. Many victims have lost significant sums, and the full extent of recovery is uncertain.
Entity Targeted: Daily Cop S.A.S. and its founders/promoters (e.g., Camilo Andrés Suárez Aldana, David Mateo Suárez Aldana). Violation Type: Alleged pyramid scheme, unauthorized and illegal financial intermediation using cryptocurrencies as a front, offering unrealistic returns, consumer fraud. Outcome: SIC issued a definitive resolution ordering the immediate cessation of Daily Cop's activities, imposing fines, and requiring restitution. The Fiscalía subsequently arrested key figures behind the scheme and initiated criminal proceedings, uncovering millions of dollars in alleged fraud.
Entity Targeted: Local promoters and affiliates of the international Generación Zoe scheme operating in Colombia. Violation Type: Alleged illegal financial intermediation, fraud, and operating a Ponzi/pyramid scheme under the guise of coaching and crypto investments. Penalty Amount: Arrests and criminal charges against Colombian operators. Assets linked to the scheme were seized. Outcome: Colombian authorities, working with international counterparts, arrested individuals linked to Generación Zoe's operations in the country. Criminal proceedings are ongoing for charges related to aggravated fraud and illegal financial intermediation. Outcome: Provided valuable insights for future regulation, demonstrating a willingness by the SFC to study and understand crypto operations under controlled conditions.
Outcome: SIC ordered the cessation of all promotion and operations of OmegaPro-related schemes in Colombia, imposed significant fines, and mandated restitution to affected consumers. The Fiscalía has pursued criminal charges, leading to arrests of key promoters and the freezing of assets. Many victims have lost significant sums, and the full extent of recovery is uncertain.
Outcome: SIC issued a definitive resolution ordering the immediate cessation of Daily Cop's activities, imposing fines, and requiring restitution. The Fiscalía subsequently arrested key figures behind the scheme and initiated criminal proceedings, uncovering millions of dollars in alleged fraud.
SIC: Fines in the hundreds of millions of Colombian Pesos (COP) against promoters and entities. For instance, in August 2022, the SIC sanctioned "Smart Business Corp SAS," "Bux Corp SAS," and several individuals involved with OmegaPro, imposing fines totaling over COP $2.400 million (approx. USD $600,000 at the time) and ordering the immediate cessation of activities and restitution to affected consumers. Further fines and orders against other promoters followed.
SIC: Imposed fines of over COP $500 million (approx. USD $125,000 at the time) against the company and its managers, ordered the immediate cessation of its operations, and mandated the return of funds to investors.
Ley 1581 de 2012 (Protección de Datos Personales): https://www.funcionpublica.gov.co/eva/gestornormativo/norma.php?i=49981
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a DeFi protocol frontend serving Colombian residents may operate but is subject to UIAF AML/CTF registration (with CDD, ongoing monitoring, and SAR obligations) and faces significant enforcement risk if it takes fees or intermediaries user funds, which could be treated as unlicensed financial intermediation by the SIC and Fiscalía.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?