Resources

Colombia’s Open Finance Roadmap: Moving from Mandate to Operational

Business milestones or achievement to reach goal or success, progress development, vision to see target destination, step to success, businessman look on telescope to see success trophy milestone.
Structure

An Ozone API & Finerio Connect Article

The shift in Colombia’s regulatory framework from an optional model to a mandatory requirement was paramount in setting clear, unified expectations across the entire financial ecosystem. With Open Finance officially backed by law since April 2026, the market’s focus has now turned to the critical transition from legal mandate to operational reality.

Rather than a single enforcement date, this transition follows a deliberate, multi-stage implementation roadmap:

  • End of 2026: Finalisation and release of official technical specifications.
  • Early 2027: Deployment of the Directory of Participants and operational governance guidelines.
  • Late 2027 / Early 2028: Ecosystem-wide production readiness and live data flows.

Understanding this rollout schedule is essential for financial institutions as they budget, build, and align their Open Finance technology roadmaps over the coming cycles.

Two Legal Instruments with Two Different Jobs

Decree 1297 of 2022 created Colombia’s original, voluntary Open Finance scheme. Most of it has since been superseded, but two pieces survive: the digital-ecosystems provisions in Title 9 and the payment-initiation rules in Book 17.

External Circular 004 of 2024, issued by the Superintendencia Financiera de Colombia (SFC) on 7 February 2024, created Chapter IX (Open Finance rules) and Chapter X (technology commercialization) of the Basic Legal Circular, including the technical and security profile. It was published while the scheme was still voluntary.

Decree 0368 of 2026, in force since 10 April 2026, replaced Title 8 of Book 35 of Decree 2555 entirely and repealed Title 10. This is the instrument that made the SFC mandatory. A draft External Circular is currently in public consultation, with comments closed as of 10 August 2026, to rewrite Chapter IX in line with the new decree.

Mandatory, not Operational

Decree 0368 sets the obligation. The SFC is expected to issue the standards that entities would need to build against until October 2026. Without those standards, there’s nothing to exchange data on. The realistic projection for real data exchange in Colombia is 2028.

The latest date that does matter is technical, not legal: the transition regime for the February 2024 security profile (External Circular 004) expired on 7 August 2026, after two six-month extensions on top of the original 18 months. Entities have not yet seen full technical compliance.

Once a data standard for a given category is issued, an exposure clock starts for that category specifically, not from the decree itself. It runs 12 months, extendable once by up to 6 months, plus a further 6 months solely for large-company data. That puts the ceiling at 18 months for individuals and MSMEs, and 24 months for large companies. The SFC has its own deadlines here too: a standardisation schedule due within 6 months of the decree, around October 2026, and a Participants Directory with monitoring indicators due within 12 months, around April 2027.

ElementStatus
Obligation of the SFA (Decree 0368)Current from 10-Apr-2026
Remaining Chapter IX of the Basic Legal Circular: third-party receiver linkage, operational cybersecurity, data processing, and disclosure obligationsCurrent and Mandatory from Aug-2024
Chapter X, provision of technology services and infrastructureCurrent and Mandatory from Feb-2025
Technical Profile of Number 3.2: FAPI 2.0, OAuth 2.0, Mutual TLS, JSON, REST, ISO 20022 as a dictionaryPublished since February 2024. Enforceable around August 7, 2026
Timeline of standardizationWithout defining. Maximum deadline until around October 2026
Data standards by categoryWithout defining. The decree does not set a deadline for issuing them
Participants Directory and Tracking IndicatorsWithout defining. Maximum deadline until around April 2027
Own sanctioning regime of the SFADoes Not Exist

The Broadest Mandated Universe

There’s no official entity count yet. The working estimate is 175 to 185 entities across 12 license types: credit institutions, SEDPE electronic-deposit and payment issuers, trust companies, securities and commodities brokers, pension and severance fund administrators, crowdfunding platforms, insurers, and specialized credit entities. In June 2026, the SFC convened 153 of them across four technical sessions, drawing over 260 attendees.

Unlike Chile’s two-group structure or Peru’s four waves, Colombia sets no size thresholds, no groups, and no simplified regime. Every entity starts the same clock the moment a standard for its data category is issued.

Access obligations run only toward third-party recipients supervised by the SFC, which today is a small number: 11 regulated fintechs (9 SEDPE issuers and 2 crowdfunding platforms), as of July 2026. The much larger population of unregulated fintechs, estimated at 365 to 560 by industry sources, can only access data through voluntary bilateral schemes. Once a bank opens such a scheme, it can’t discriminate arbitrarily within it. It has to publish clear, objective, verifiable criteria and document every access decision.

Monetising Access

Colombia is unique in that a monetisation scheme is already in force, and it’s built on cost recovery, not margin. Four rules govern it: billing must track query or usage volume, only availability, security, and quality costs are recoverable, costs must apply equally to all recipients, and the underlying data itself can never be charged for. No shared cost methodology or independent tariff auditor exists. The government explicitly declined the regulator’s recommendation to create one, so each entity currently sets its own tariff.

A Two-Screen Consent Model

Consent works in two steps. First, the third-party recipient requests authorisation, which must include five minimum elements: identity, data scope, processing purpose, duration, and clear, simple, precise language. Second, the data-provider entity confirms with the account holder before any information moves. General or open-ended authorisations are prohibited, and so is conditioning a product or service on granting authorisation. Account holders keep four guaranteed rights: to know or copy the authorisation, revoke or update it, refuse it, and get an explanation of how their data was used.

Data itself splits into three categories: account and product data (authorisation required), KYC and onboarding data (authorisation required), and general product-catalogue information (no authorisation needed). The only hard quantitative rule in the decree is 12 months of transaction history for demand deposits. Notably, derived or analytics data, meaning anything an entity creates by processing the raw data, sits entirely outside the mandatory-access regime.

What’s Still Missing, by Design

The decree leaves a long list of operational questions to be closed by contract and architecture rather than regulation: no maximum consent duration or renewal rule, no defined revocation mechanism or propagation deadline, no data-latency standard, no minimum history requirement outside demand deposits, no service levels or traffic limits at all, no mandated consent-management panel, no rules on sensitive data or cross-border transfer, no civil-liability framework, no dispute-resolution process, and no dedicated sanctioning regime for missed deadlines.

That’s not a gap that resolves itself. Entities operating in Colombia today need to close it themselves, through bilateral contracts and platform design, well ahead of whenever the SFC’s own standards arrive.

What’s Next?

Following the most recent milestone of 7 August 2026, when the technical-profile transition regime expired, the standardisation schedule (due around October 2026) and the Participants Directory (due around April 2027) are the markers worth tracking.

Ozone API and Finerio Connect are already live in Colombia, building the infrastructure that lets institutions operate correctly under a law that’s binding today, while staying ready for standards that are still, by design, unwritten.

How Ozone API and Finerio Connect Can Help

Ozone API and Finerio Connect work in the same way here. Ozone API supplies the standards-compliant, FAPI-certified platform built by the original architects of the UK Open Banking standard, giving an entity a technical foundation that already meets global security profiles even while awaiting Colombia’s own final standards. Finerio Connect supports where the current decree has gaps: live commercial and deployment experience, already running Open Finance ecosystems in Colombia, Chile, and Guatemala ahead of regulators rather than waiting for them. Between them, an entity can close the gaps Decree 0368 leaves open, consent duration, revocation, liability, dispute resolution, through contract and architecture now, on infrastructure built to adapt once the SFC’s standards for those categories finally land.

Speak to the team today to get started.

Recommended articles

Milestone to reach goal or success target, strategy to progress achievement, leadership planning or advancement, improvement step to mission objective, businessman on mountain looking for next target.
Resources

Chile’s Open Finance System: Your Guide to Get Started

An Ozone API & Finerio Connect Article Most Open Finance debates in Latin America still centre on what the rules will say, but not Chile. The Sistema de Finanzas Abiertas (SFA) is defined in law, its technical annex is published, and every deadline that matters is already counting down. What’s left isn’t interpretation, it’s execution....

Ozone API and Finerio Connect
25, Aug 2026
Business crossroad, decision to choosing choice, success direction challenge, right or wrong opportunity, option, alternative selection businessman thinking make decision to choose business direction.
Resources

A Look at Peru: Two Open Finance Paths at Once

An Ozone API & Finerio Connect Article Peru is a market in the region where the final rulebook hasn’t been shared yet, and that’s precisely what makes it different. Ozone API and Finerio Connect track Chile, Colombia, and Peru as three distinct paths to the same destination, and Peru has only recently finished allowing market...

Ozone API and Finerio Connect
25, Aug 2026
Protection shield to protect from security threat, safety risk or hazard crisis chance, business resilience to win and survive, defense trust control, businessman run with protection shield strength.
Resources

What is FAPI? Financial-Grade API Explained

FAPI is the OpenID Foundation’s security profile for OAuth 2.0 and OpenID Connect, purpose-built for APIs that enable access to financial accounts to ensure the security model is “bank grade”, for example to access sensitive financial data, or to initiate transactions . In other words, it takes the two protocols and removes the insecure choices....

Ozone API
29, Jul 2026