Colombia's Statutory Law 2573 of May 19, 2026 changed the rules for financial entities, credit institutions, telecom operators and businesses that approve or finance products. The regulation protects victims of identity theft against charges and negative reports stemming from fraud, and its provisions will be fully enforceable by November 2026.
What changes with this law?
The most significant shift is conceptual: the victim no longer bears the burden of proof — the entity does. If a customer reports identity theft, the responsibility to prove that the verification process was adequate falls on the service provider. If it cannot demonstrate this, it loses the right to collect and must absorb the loss.
The five obligations the law imposes
- Verify identity with sufficient and reasonable measures: Article 5 requires digital security measures that effectively establish the veracity of identity. The law does not mandate a specific technology, but it does require a demonstrable result.
- Immediately suspend charges upon an identity theft complaint: When a claim is filed, the entity must suspend capital, interest and collection costs, and flag the account as "Victim of Personal Fraud" with information operators, without affecting the holder's credit score.
- Deliver all onboarding evidence: At the request of the alleged victim, the entity must provide copies of all documents used to approve the product. Refusal is not permitted.
- Assume the dynamic burden of proof: Proof lies with whoever is in the best position to provide it: the entity. If it cannot demonstrate that its verification worked, it loses the right to collect and absorbs the loss.
- Preserve verifiable and traceable evidence: Documents, biometric results, scores, IP addresses, device data and anti-fraud engine decisions form the file that the SIC and the Superfinanciera will require.

What is the real risk?
Beyond Law 2573 itself, the regulation is linked to the Habeas Data Law (Law 1266 of 2008) and the Data Protection Law (Law 1581 of 2012). Failures in verification and evidence preservation expose entities to fines of up to 2,000 SMLMV and the suspension of data processing in digital channels.
What will regulators ask in a claim?
Under the dynamic burden of proof, every digital onboarding is a potential evidentiary file. Supervisors and judges will ask:
- Who signed up and how was their identity validated?
- Was the person physically present — not a photo, video or deepfake?
- Did the same face attempt to link with other identities?
- What controls were applied and what result did each produce?
- Is the evidence intact and protected?
- Can the file be reconstructed within the legal deadlines?
How to prepare before November 2026?
Before the law becomes fully enforceable, each entity must honestly answer: Do we maintain a complete evidentiary file for every digital onboarding? Does our liveness check detect photos, videos and deepfakes, or is it just a selfie? Can we deliver onboarding evidence within the deadlines the law requires? Do we have a protocol for immediate suspension of charges? Do legal, fraud, risk and technology teams act in a coordinated way when facing claims?
If any answer raises doubts, the time to act is now.
