COMPLII
Subscribe
Colombia · SARLAFT

SARLAFT compliance built into your AML platform

Complii gives regulated operators and obligated entities in Colombia a complete operational stack for SARLAFT — from the inherent/residual risk matrix to KYC, list screening, transaction monitoring, and audit-ready evidence.

Colombian SARLAFT requires you to identify, measure, mitigate, and monitor LA/FT/FP risk across every counterparty relationship. Complii turns those obligations into configured workflows — not disconnected spreadsheets — with a Colombia SARLAFT methodology pack, a 17-step setup wizard, and supervisor-ready exports.

  • Colombia SARLAFT template: contraparte, producto, canal, geografía, activos virtuales
  • Inherent → residual → final scoring with mapped controls (screening, KYC, TM, IV)
  • Matrix builder: weights, L×I grid, EDD/senior-review thresholds, population monitoring
  • Listas vinculantes: OFAC, UN, EU, Colombia + PEP + automatic rescreening
  • UBO at 5% (Ley 2155), identity verification, document vinculación requirements
  • TM for operaciones inusuales/sospechosas → cases → audit trail for ROS evidence

Policy manuals, training records, and UIAF SIREL ROS/AROS filing remain organizational processes — Complii operationalizes detection, diligence, monitoring, and evidence.

Complii risk methodology dashboard for SARLAFT

Colombia LA/FT pack

Inherent → residual → final risk

Weighted factors or Likelihood × Impact grid with EDD and senior-review thresholds.

Designed for Colombia SARLAFT

One platform for the operational controls supervisors expect — not another spreadsheet.

  • Colombia LA/FT
  • UIAF LA/FT
  • UBO 5% · Ley 2155

17

Guided SARLAFT setup steps

UIAF

National LA/FT framework

1-click

Activate SARLAFT methodology template

100%

Immutable audit trail on actions

Platform modules included for SARLAFT

SARLAFT is not a separate product — it is how Complii's core AML platform is configured for Colombia. Every module below connects on the same UCID identity graph.

Customers & onboarding

Individual and business vinculación, custom fields, import/API, duplicate detection, and customer risk summaries.

Document intelligence

Document types, requirement trees, formato de vinculación checklists, AI validation, and expiration tracking.

Identity verification

Public KYC flows, document capture, liveness/face match, screening at completion, and webhook notifications.

Screening & watchlists

Sanctions, PEP, adverse media, Colombia lists, custom lists, presets, explainable matches, and batch rescreening.

Risk methodology & policy

Colombia SARLAFT template, company rules, signals, country risk, matrix builder, and methodology assessments per customer.

Transaction monitoring

Scenario library, real-time alerts, structuring/velocity/corridor rules, explainable payloads, and auto-case routing.

Cases & investigations

Alert-to-case workflow, evidence linking, analyst notes, disposition, and structured ROS preparation support.

Corporate intelligence (KYB)

Legal entity workspace, ownership graph, UBO calculation at 5%, enrichment, and corporate EDD reviews.

Audit & compliance log

Immutable who/what/when records across screening, risk changes, case actions, and configuration updates.

Developer API

Programmatic customer onboarding, transaction ingestion, screening, and webhooks for core banking or ERP integration.

Aligned with Colombian SARLAFT requirements

Complii maps each SARLAFT obligation to a concrete module — so your compliance team can demonstrate how risk is identified, mitigated, monitored, and investigated.

The platform supports the full risk cycle expected under SARLAFT: design the methodology, apply it at onboarding, keep it current through continuous due diligence, detect unusual and suspicious operations, investigate with documented evidence, and retain records for supervisor examination.

  • Arts. 5.6.5–5.6.6 — SARLAFT policy implementation via configurable methodology and control mapping
  • Arts. 5.6.7–5.6.10 — Inherent/residual risk matrix, factor weighting, control effectiveness, and acceptable risk levels
  • Art. 5.6.11 — Debida diligencia, DDI for PEP/high risk, identity verification, and document retention
  • Arts. 5.6.10.4, 5.6.11.6 — Risk population monitoring and technology-supported unusual/suspicious operation detection
  • Arts. 5.6.11.4, 5.6.12 — Documentation, case evidence, and investigation records for supervisor review
  • Art. 5.6.11.2.f — Permanent consultation of binding international and national lists
  • Art. 5.6.11.2.b — Beneficial owner identification at 5% threshold (Ley 2155)
  • Art. 5.6.11.6 — Automated tools for monitoring, alerting, and case management

Likelihood × Impact risk matrix

Configurable 5×5 grid with acceptance thresholds — export CSV/JSON for board approval.

I 1I 2I 3I 4I 5
L 1
4
8
12
16
20
L 2
8
16
24
32
40
L 3
12
24
36
48
60
L 4
16
32
48
64
80
L 5
20
40
60
80
100
LowMediumHighCritical

SARLAFT requirements → Complii module mapping

See exactly which regulatory article each platform capability addresses — useful for supervisor examinations and internal SARLAFT documentation.

Art. 5.6.5Risk Methodology

LA/FT/FP risk matrix design

Activate the Colombia SARLAFT template with five SARLAFT dimensions, auto-assigned factor options, and control mappings (listas vinculantes, debida diligencia, DDI, monitoreo, verificación de identidad).

Art. 5.6.10Risk Engine

Risk measurement and control

Company rules and signals feed observed risk; methodology computes inherent, residual (after control coverage), and final score per customer. Treatment profiles enforce EDD gates.

Art. 5.6.11.2.eAutomatic Screening

Continuous due diligence

Schedule automatic rescreening of your customer base when lists update or on a recurring calendar — not just at onboarding.

Art. 5.6.11.1Document Intelligence

Formato de vinculación

Define required documents per customer type: ID, tax ID (NIT/RUT), source of funds declaration, powers of attorney, and legal entity supporting documents.

Art. 5.6.11.2.fScreening

Binding list consultation

Screen against OFAC, UN consolidated, EU, and Colombia vinculante lists with configurable presets, match explanations, and analyst review workflow.

Art. 5.6.11.2.aIdentity Verification

Identity verification

Remote onboarding with document capture, liveness detection, face match, and automatic screening upon IV completion.

Art. 5.6.11.2.bCorporate Intelligence

Beneficial owner (5%)

Map ownership chains, calculate UBOs at the Ley 2155 5% threshold, screen related parties, and complete structured KYB/EDD reviews.

Art. 5.6.10.3.cTransaction Monitoring

Unusual operations detection

Velocity, amount, corridor, and pattern scenarios with explainable alert payloads tied to UCID clusters and customer context.

Art. 5.6.12Cases

Suspicious operations investigation

Investigate alerts in cases with linked transactions, screening hits, documents, and analyst disposition — evidence package for ROS preparation.

Art. 5.6.11.4Audit Log

SARLAFT documentation & retention

Demonstrate who verified documents, when screenings ran, how risk scores changed, and how cases were closed — supporting five-year retention requirements.

End-to-end SARLAFT operational flow

From methodology design through investigation — every step produces evidence on the same tenant-scoped identity graph.

Risk methodology

Activate the Colombia SARLAFT template, tune dimensions, weights, and L×I matrix.

Due diligence

KYC/KYB, identity verification, document requirements, and onboarding.

List screening

Sanctions, PEP, Colombia lists, presets, and automatic rescreening.

TM & alerts

Unusual/suspicious scenarios with auto-case routing.

Cases

Analyst workflow, evidence, disposition, and ROS preparation support.

Audit & export

Immutable logs, matrix export, methodology versioning.

What Complii delivers for SARLAFT

Every capability below is available today — configured through the in-app SARLAFT setup wizard after you subscribe.

Each card summarizes a Complii module with the specific SARLAFT controls it operationalizes. Subscribers get the full platform; the Colombia SARLAFT pack and setup wizard accelerate configuration.

Colombia SARLAFT methodology template
Metodología

Colombia SARLAFT methodology template

One-click activation of the Colombia SARLAFT global pack — dimensions, factor options, auto-assignment rules, and mapped controls aligned to SARLAFT requirements.

  • Five dimensions: contraparte, producto/servicio, canal, geografía, activos virtuales
  • Auto-assignment from customer type, PEP status, country risk, and triggered signals
  • Control coverage reduces inherent to residual risk (screening, KYC, TM, IV, docs)
  • Final score = max(residual, observed detection score) — detections always raise risk
  • Per-customer methodology panel with factor breakdown and required actions (EDD, senior review)
Risk matrix builder
Matriz

Risk matrix builder

Customize the methodology your board approves — weights, scores, acceptance thresholds, and exports — without leaving the platform.

  • Edit dimension weights and factor inherent scores per tenant
  • 5×5 Likelihood × Impact grid as alternative scoring method
  • Acceptance thresholds: standard DD, enhanced monitoring, EDD, senior review, exit
  • Population monitoring: inherent vs residual distributions and monthly trends
  • Board snapshots and CSV/JSON export for supervisor and external audit
Customer onboarding & documents
KYC

Customer onboarding & documents

Complete vinculación workflow for natural and legal persons with document intelligence and optional AI-assisted extraction.

  • Customer types: individual, business, with custom fields for sector-specific data
  • Document requirement trees by customer type and risk level
  • Document manager with categories, expiration alerts, and AI validation
  • Bulk customer import and public API for ERP/core banking integration
  • UCID identity resolution links related customers, addresses, and accounts
Screening & watchlists
Listas

Screening & watchlists

Permanent list consultation with explainable matching — the operational backbone of Art. 5.6.11.2.f.

  • Global sanctions: OFAC SDN, UN consolidated, EU, and other international lists
  • Colombia vinculante lists and tenant custom watchlists
  • PEP detection and adverse media screening
  • Configurable presets (strict/balanced) and automatic screening on create/update
  • Analyst review with match evidence, false positive disposition, and audit trail
Country & jurisdiction risk
Geografía

Country & jurisdiction risk

Geographic risk scores feed the geografía dimension and EDD triggers for non-cooperative jurisdictions.

  • Per-country risk score configuration (0–100) at tenant level
  • Auto-assigns high-risk geography factors when country score exceeds threshold
  • Supports FATF grey/black list jurisdictions and internal risk appetite
  • Integrates with methodology assessment and company risk rules
Corporate intelligence & 5% UBO
UBO

Corporate intelligence & 5% UBO

KYB beyond checkbox compliance — ownership transparency required for legal entity contrapartes under Ley 2155.

  • Legal entity workspace linked to Business customers and UCID
  • Ownership graph: directors, officers, shareholders, control relationships
  • UBO calculation at 5% threshold with missing-UBO and complexity warnings
  • Screening and PEP checks on related parties in the ownership chain
  • Structured corporate reviews (KYB/EDD) with billable usage tracking
Transaction monitoring
Monitoreo

Transaction monitoring

Detect operaciones inusuales y sospechosas with explainable, real-time scenario evaluation.

  • Scenario types: velocity, amount thresholds, structuring, corridor, and custom rules
  • Real-time evaluation on transaction ingest (API or import)
  • UCID-level alerts with participant context and risk summary
  • Auto-case creation when alert severity meets your threshold
  • Explainable payloads showing which rules fired and why
Investigations & ROS workflow
Casos

Investigations & ROS workflow

Structured investigation from alert to disposition — the evidence layer before filing ROS in UIAF SIREL.

  • Cases from TM alerts, screening hits, or manual creation
  • Link evidence: transactions, documents, screening results, risk assessments
  • Analyst notes, assignment, and disposition (true match, false positive, escalate)
  • Supports compliance officer review before ROS submission
  • Full case history in audit log for supervisor examination
In-app SARLAFT setup wizard
Guía

In-app SARLAFT setup wizard

17-step guided configuration exclusive to subscribers — with green checks for auto-detected completion.

  • Four phases: methodology, due diligence, monitoring, reporting & governance
  • Direct links to every Complii configuration page
  • Auto-detection: methodology active, rules, presets, TM, IV, UBO threshold
  • Manual checklist for external items: policy, manual, compliance officer, SIREL
Audit trail & exports
Auditoría

Audit trail & exports

Prove your SARLAFT controls work — who did what, when, and on which customer.

  • Immutable audit log across all modules with role attribution
  • Screening history, risk score changes, and case dispositions
  • Methodology assessment history per customer
  • Matrix and methodology snapshot export for board approval
  • Customer data export for regulatory requests

17-step SARLAFT setup wizard (included for subscribers)

After subscribing, your compliance team gets a guided checklist inside Complii — not a PDF manual.

Green checks appear automatically when Complii detects completed configuration. Steps marked manual/external cover organizational requirements outside the platform (policy, Oficial de Cumplimiento, SIREL filing).

Phase 1 · Risk methodology

Arts. 5.6.5–5.6.10

  • Activate Colombia SARLAFT methodology

    Enable the Colombia SARLAFT template under Risk Methodology with SARLAFT dimensions and control mappings.

  • Configure country risk scores

    Set scores for Colombia, high-risk, and non-cooperative jurisdictions for the geografía factor.

  • Configure company risk rules

    Tune PEP, sanctions, KYC gap, and geographic signals that feed observed risk scores.

Phase 2 · Due diligence (KYC)

Art. 5.6.11

  • Screening presets (listas vinculantes)

    Ensure UN, OFAC, EU, and Colombia lists are in scope with appropriate match sensitivity.

  • Enable ongoing rescreening

    Schedule automatic rescreening for continuous due diligence (debida diligencia continua).

  • Onboarding document requirements

    Match formato de vinculación: ID, NIT, source of funds, and entity supporting documents.

  • Identity verification flows

    Biometric or document-based IV for remote onboarding channels.

  • Beneficial owner at 5%

    Corporate Intelligence with UBO threshold at 5% per Ley 2155.

Phase 3 · Monitoring

Arts. 5.6.10.4, 5.6.11.6

  • TM scenarios

    Detect structuring, velocity, high amounts, and corridor risks — operaciones inusuales.

  • Auto-case from TM alerts

    Open investigation cases automatically when alerts meet severity threshold.

  • Case investigation workflow

    Document analyst review, notes, and disposition before ROS escalation.

  • Risk population dashboard

    Monitor portfolio risk distribution and methodology assessments.

Phase 4 · Reporting & governance

Arts. 5.6.8, 5.6.12

  • ROS via SIREL (external filing)

    Document investigation in Cases; compliance officer files ROS immediately in UIAF SIREL.

  • Monthly AROS (external filing)

    If no ROS in the month, submit Ausencia de ROS within 10 days via SIREL.

  • Audit trail & evidence

    Verify immutable logs for screenings, risk changes, and case actions (Art. 5.6.11.4).

  • Policy & manual (external)

    Board-approved política LA/FT/FP, manual de procedimientos, and código de ética.

  • Compliance officer (external)

    Designate Oficial de Cumplimiento, UIAF e-learning, notify competent supervisory authority.

Spreadsheets vs. operational SARLAFT

Supervisors expect demonstrable controls — not a folder of policies without systems behind them.

Without integrated tooling

  • Risk matrix in Excel with no link to live customer inherent/residual scores
  • KYC in one tool, listas in another, monitoreo in a third — no unified identity
  • No case evidence package when the Oficial de Cumplimiento prepares a ROS
  • Cannot show inherent vs residual population trends to junta directiva
  • UBO tracked manually; no ownership graph or 5% threshold calculation
  • Rescreening is ad hoc — continuous due diligence (Art. 5.6.11.2.e) not operationalized

With Complii SARLAFT

  • Colombia SARLAFT methodology with live inherent/residual/final scoring per customer
  • Screening, risk, TM, and cases on the same UCID identity graph
  • 17-step SARLAFT wizard with auto-detected configuration status
  • Matrix CSV/JSON and methodology snapshots for board and supervisor
  • Cases link transactions, screening, documents, and risk for ROS preparation
  • Risk dashboard and matrix monitoring show portfolio-level LA/FT exposure

Go live in five phases

Most operators activate the template and complete core configuration in days — not months.

  1. 1

    Subscribe & activate

    Create your tenant and activate the Colombia SARLAFT methodology template.

  2. 2

    Run the SARLAFT wizard

    Follow the in-app guide — country risk, rules, presets, TM scenarios, UBO threshold.

  3. 3

    Onboard contrapartes

    Import or API-create customers with KYC, documents, screening, and risk assessment.

  4. 4

    Monitor operations

    TM scenarios detect unusual/suspicious activity; alerts route to analysts automatically.

  5. 5

    Investigate & evidence

    Cases, audit logs, and exports support ROS preparation and supervisor examinations.

Frequently asked questions

Is SARLAFT a separate product or add-on?

No. SARLAFT is operationalized through Complii's core AML platform. You subscribe to Complii, activate the Colombia SARLAFT methodology template, and follow the in-app setup wizard. No separate SARLAFT license is required.

Who needs SARLAFT in Colombia?

SARLAFT obligations apply to multiple regulated sectors and activities in Colombia — not only one industry. Complii provides a Colombia SARLAFT methodology pack plus global templates you can customize. Your legal or compliance advisor can confirm which framework applies to your entity.

Does Complii file ROS in UIAF SIREL?

No. ROS, AROS, and Reportes Objetivos are filed directly by your Oficial de Cumplimiento through UIAF SIREL. Complii provides case management, investigation evidence, and audit logs to support that process.

Can we export the risk matrix for board approval?

Yes. The matrix builder exports CSV and JSON including dimensions, factor scores, L×I grid, and acceptance thresholds. You can also create immutable methodology snapshots when the board approves a version.

How long does implementation take?

Most operators activate the template and complete core configuration (methodology, screening, country risk, TM scenarios) within days using the setup wizard. Full organizational items (policy, manual, officer designation) follow your internal governance timeline.

What stays outside the platform

SARLAFT requires organizational elements Complii does not replace. The platform focuses on operational controls and the evidence those governance processes depend on.

  • Board-approved política LA/FT/FP, manual de procedimientos, and código de ética (Arts. 5.6.6–5.6.7)
  • Designation of Oficial de Cumplimiento, UIAF e-learning certification, and notification to your competent supervisory authority as required
  • Staff capacitación records and internal ethics training documentation
  • Direct filing of ROS, AROS, and Reportes Objetivos through UIAF SIREL (Art. 5.6.12)

Ready to operationalize SARLAFT?

Talk to our team about Colombia SARLAFT onboarding or start a subscription and activate the Colombia LA/FT pack today.