ComplianceAugust 29, 20266 min
New post

Information security for fintechs in Colombia: what the SFC requires in 2026

In 2026, Colombian fintechs supervised by the SFC face a hardened regulatory framework: mandatory open finance (Decree 0368/2026), cybersecurity risk management (External Circular 007), and reinforced biometric data protection. ISO 27001 is the most direct way to demonstrate compliance.

In 2026, Colombian fintechs supervised by the Financial Superintendency of Colombia (SFC) face a significantly hardened regulatory framework: mandatory open finance (Decree 0368/2026), cybersecurity risk management required by External Circular 007, and reinforced protection of biometric data as sensitive information. ISO 27001 has become the most direct way to demonstrate compliance with this framework.

What changed with mandatory open finance in Colombia?

The new open finance framework, approved in April 2026 through Decree 0368, obliges SFC-supervised entities to share their customers' data —with explicit, traceable consent— through standardized APIs. This leaves behind the voluntary scheme in force since 2022. The SFC also published for comments (until August 10, 2026) External Circular Draft 10 of 2026, which updates the specific open-finance rules within the Basic Legal Circular.

What does the SFC specifically require regarding cybersecurity?

External Circular 007 establishes the minimum measures for cybersecurity risk management, adding to the already-existing operational-risk and information-security measures for SFC-supervised entities. In practice, this means a regulated fintech needs a formal management system — not just isolated technical controls — to demonstrate compliance under inspection.

What other regulations should a Colombian fintech know?

Key regulatory framework for Colombian fintechs (2026)

RegulationWhat it governs
SARLAFT 4.0 (External Circular 027/2020 + External Circular 006/2025)Prevention of money laundering and terrorist financing, with prevention and control phases
Laws 1581 and 1266Dual-track personal data protection (financial and general habeas data)
SIC External Circular 001/2025Classifies biometric data as sensitive data in the fintech context
Decree 0368/2026Mandatory open finance for SFC-supervised entities

Why does mandatory open finance make a certified ISMS more urgent?

Because sharing customer data through standardized APIs, with traceable consent, demands auditable security controls — exactly what an Information Security Management System under ISO 27001 formalizes. A fintech participating in the open-finance ecosystem without this level of formal control is exposed both to SFC observations and to losing the trust of the supervised entities it needs to interoperate with.

Does this apply only to supervised fintechs, or also to non-supervised providers?

It applies to both, albeit differently. Supervised entities have direct compliance obligations before the SFC. Non-supervised actors participating as third-party data recipients —for example, fintechs that don't yet qualify as supervised entities— still need to meet security and API-architecture standards to negotiate access with supervised entities. In both cases, holding ISO 27001 strengthens the negotiating position.

How to get started?

An initial diagnosis identifies exactly how prepared your fintech is against these requirements — before an SFC inspection or a data-access negotiation catches you off guard.

Regulatory sources: Decree 0368/2026, External Circular 007 (SFC), External Circulars 027/2020 and 006/2025 (SARLAFT 4.0), Laws 1581 and 1266, External Circular 001/2025 (SIC), External Circular Draft 10 of 2026 (SFC, under consultation until August 10, 2026).

#ISO27001#SFC#Colombia#Fintech#OpenFinance#Cybersecurity#SARLAFT#BiometricData#Compliance
Share:LinkedIn
Quick answerDetail

What does the SFC require from Colombian fintechs regarding information security in 2026?

In 2026 the SFC requires mandatory open finance (Decree 0368/2026) with standardized APIs and traceable consent, cybersecurity risk management (External Circular 007), SARLAFT 4.0, personal data protection (Laws 1581 and 1266), and biometric data as sensitive data (SIC Circular 001/2025). That framework demands a formal management system, not isolated controls — which is why ISO 27001 becomes the most direct way to demonstrate compliance, for both supervised entities and the non-supervised third parties that interoperate with them.

Written and reviewed by Rogelio Barajas González — certified Lead Auditor ISO 27001:2022 and ISO 9001:2015, with direct experience in SOC 1 Type 2 and SOC 2 Type 2. Founder of Barajas Advisory.

Verify his credentials on LinkedIn:linkedin.com/in/rogelio-barajas-gonzalez

Last updated: August 2026

This is one of nine real cases

Cicatrices de Nube — do you want the rest of the stories?

All nine documented cases —FinOps, Release Management, Service Delivery, Compliance, and AI governance— with a self-assessment checklist per chapter and an overall scorecard.

Download the free playbook

Does this resonate?

If you lead operations, technology, or teams at a SaaS company and recognize these situations, let's talk. No strings attached.

Schedule your diagnosis
Usually available

I respond within 2 hours max
Monday to Friday