Colombia made open finance mandatory for entities supervised by the Superintendencia Financiera de Colombia, and it did not stop at the obligation to share. Before any data moves, the institution that holds it has to go back to the customer and confirm that the third party asking for it really was authorized (Decreto 0368 de 2026, Article 2.35.8.3.3).
What did Colombia's Decree 0368 actually change?
It replaced a voluntary arrangement with an obligation that has a calendar. Decree 0368 of 2026, issued on April 7, 2026 by the Ministry of Finance, rewrote Title 8 of Book 35 of Decree 2555 of 2010 and turned the open finance system into something supervised entities have to join rather than something they may join (Decreto 0368 de 2026, Article 1).
The system covers three categories of information: what products and services the customer holds, the information gathered when the customer was onboarded, and the general characteristics of the products participants offer. Only the first two involve the customer's personal data and require authorization. The third, the public shape of a product catalogue, does not (Decreto 0368 de 2026, Article 2.35.8.2.1).
Article 2.35.8.3.3 adds a second step
Most open finance frameworks stop at one act: the customer authorizes a third party to receive data, and the institution holding the data honours that authorization. Colombia wrote a second act into the rule.
The authorization itself has a defined minimum content. It has to identify the receiving third party by corporate name and domicile, list the personal data being authorized, and state the purpose of the processing, in language the holder can understand (Decreto 0368 de 2026, Article 2.35.8.3.2). Then, before any information circulates, the data provider has to confirm with the holder that the receiver does have that authorization. The confirmation has to show the minimum content of what was authorized, and it has to let the holder allow or refuse the transfer at that moment (Decreto 0368 de 2026, Article 2.35.8.3.3).
Two other articles sit next to it and are easy to miss. Granting, changing or revoking an authorization has to run through strong authentication (Article 2.35.8.3.4). And the holder keeps four standing rights: to see the authorization and get a copy of it, to revoke or update it, to refuse, and to be told how the data was used (Article 2.35.8.3.5).
Who answers for the consent when the product is embedded?
This is where the rule stops being a data question and becomes an architecture question. In an embedded arrangement, the interface belongs to one company and the regulated activity belongs to another. The customer sees one brand. The obligation to confirm the authorization sits with the entity that holds the data, which is the supervised one.
So the platform whose logo is on the screen does not carry the confirmation duty in the rule, and still carries all of the customer experience of it. The confirmation will reach the customer, in some channel, at some moment, possibly under a name the customer does not associate with the product they were using. If nobody designed that moment, it gets designed by default.
The practical questions are not legal ones. Which entity sends the confirmation. What it says. Whether the customer understands, at that point, which company is asking and on whose behalf. Whether a refusal at the confirmation step lands anywhere the platform can see it, or simply shows up later as a feature that silently does not work for that user.
The calendar the decree sets
The decree took effect the day after its publication in the official gazette, and the deadlines run from that date (Decreto 0368 de 2026, Article 5). Three of them matter for planning.
- Six months for the schedule. The Superintendencia Financiera de Colombia has to publish the work schedule for issuing the technical standards, which places it in October 2026 (Decreto 0368 de 2026, Article 4). The schedule has to cover, at minimum, transaction history for demand deposits and for credit products held by the customer (Article 3).
- Twelve months per standard, once each standard exists. Entities then have up to twelve months from the issuance of each standard to enable access to that category, and the regulator may extend that term once (Decreto 0368 de 2026, Article 2.35.8.3.7).
- Twelve months for the directory. The participant directory has to be operating, with its rules for registration, modification and withdrawal, within twelve months of the decree taking effect. The same deadline applies to the monitoring indicators (Decreto 0368 de 2026, Article 4).
The shape of that calendar is worth reading carefully. It sets a schedule of standards rather than one deadline for everybody. Each category gets its own twelve-month clock, starting when its standard is issued. Categories will go live at different times, and a product that depends on two of them inherits the later one.
What should a platform embedding financial products in Colombia do now?
The standards do not exist yet, so nothing can be built against them. What can be done in the meantime is the part that will not change when they arrive.
- Find out which supervised entity holds the data behind your product, by name. It is the one that will owe the confirmation, and the one whose name may appear in it.
- Ask how the confirmation will reach your customer, and in which channel. This is a product decision that the rule assigns to someone else.
- Decide what your product does when a holder refuses at the confirmation step. Silence is a decision here too.
- Map which of the three categories your use case actually needs. The third one carries no authorization requirement, and use cases that live entirely in it are not waiting on the same clock.
The wider version of this question, which entity has to hold the license for each piece of what you are offering, is a different article: what you can embed, and what needs a license. And the diligence questions to put to any provider before choosing one are in seven questions before choosing cross-border infrastructure.
Where this leaves an arrangement whose license is not its own
ATTRUS operates in Colombia through a locally compliant sponsor-institution framework, which is the same structure that sits under our embedded finance offering across the region. Under a rule like this one, that structure has a consequence worth stating plainly: the duties the decree creates land on supervised entities, and a platform building on top of one inherits the customer-facing side of those duties without inheriting the obligation itself.
That asymmetry is the thing to design around. It was there before April 2026 and it was invisible, because consent was a checkbox in an onboarding flow that nobody outside the flow ever saw. A rule that requires the holder to be asked a second time, by a different party, makes the chain visible to the customer. The companies that decided in advance what that moment looks like will be the ones it does not surprise.
Is open finance mandatory in Colombia?
Yes, for entities supervised by the Superintendencia Financiera de Colombia. Decree 0368 of 2026 replaced the previous voluntary framework and made participation an obligation for supervised providers, with a schedule of technical standards to be issued by the regulator (Decreto 0368 de 2026, Article 2.35.8.2.3).
What is the double consent requirement in Decree 0368?
Two acts, not one. The customer gives the receiving third party a prior, express and informed authorization identifying that third party, the data and the purpose. Separately, before any data moves, the institution holding the data confirms with the customer that the authorization exists, and gives the customer the chance to allow or refuse at that point (Articles 2.35.8.3.2 and 2.35.8.3.3).
When do Colombian entities have to be ready?
There is no single date. The regulator has six months from the decree taking effect to publish the schedule for issuing technical standards, which places it in October 2026. Each entity then has up to twelve months from the issuance of each standard to enable access for that category, extendable once (Articles 4 and 2.35.8.3.7).
Who is responsible for consent in an embedded finance product?
The confirmation duty in the decree sits with the entity that holds the data, which is the supervised one, not with the platform whose brand the customer sees. The platform still owns the experience of that moment: which name appears, in which channel, and what the product does if the customer refuses.