What is SAGRILAFT and which companies does it apply to?
SAGRILAFT is the comprehensive self-control and risk management system for money laundering, terrorism financing and financing of the proliferation of weapons of mass destruction that Colombia's Superintendence of Companies requires from real-sector companies. Whether it applies depends on revenue or asset thresholds and on the sector the company operates in. In 2026 the Superintendence issued a new Basic Legal Circular (External Circular 100-000020 of July 2, 2026) that unifies the SAGRILAFT and Business Transparency and Ethics Programme obligations into a single chapter and changed the unit of measure of the thresholds. Confirm the values in force in the Superintendence's official text before deciding whether your company is covered.
What is the difference between SAGRILAFT and SARLAFT?
They are parallel regimes with different supervisors. SARLAFT is the money laundering and terrorism financing risk management system of the Financial Superintendence, applicable to the entities it supervises — banks, insurers, trust companies, brokers. SAGRILAFT is the Superintendence of Companies regime for real-sector companies. Other superintendences have additionally adopted sector-specific SARLAFT schemes for their supervised entities. Writing them as if they were a single rule is a frequent mistake and leads to demanding requirements from a supplier that do not apply to it.
What happens if a Mexican supplier does not have a valid REPSE?
Two simultaneous effects. The labour one: article 1004-C of the Federal Labour Law provides for a fine of 2,000 to 50,000 times the UMA, applied both to the party providing the service without registration and to the party benefiting from it, so the contracting company is a direct subject of the penalty. The tax one: without valid registration, payments for specialised services carry no deduction or crediting effects under article 15-D of the Federal Tax Code, and the contracting party must verify the registration at the time of payment and collect payroll, withholding and contribution receipts in order to deduct. The REPSE registry is public, so the check is free and takes a minute.
Is a private company required to request the SAT 32-D opinion from its supplier?
Not under that article. Article 32-D of the Federal Tax Code bars the Federal Public Administration — not private companies dealing with each other — from contracting with parties that are not current on their tax obligations. Requiring the compliance opinion in a B2B relationship is a very reasonable and widespread control practice, but it rests on the contract and on internal procurement policy, not on a legal mandate. The distinction is worth making: presenting it to a supplier as a legal obligation weakens the rest of your requirements when someone checks.
How do I verify whether a Peruvian supplier is "Habido" at SUNAT, and what happens if it is not?
You look up the RUC free of charge on the public SUNAT portal. Check two separate fields: the taxpayer status must be active and the condition of the tax domicile must be "Habido". If the condition is "No habido", the clear effect written in the law is that expenses supported by receipts issued while it held that condition are not deductible for income tax, unless the condition was lifted by December 31 of the tax year (article 44, subparagraph j, of the Income Tax Law). On the IGV input tax credit it is worth being more cautious: the text in force of article 19 of the IGV Law does not establish an automatic loss on that ground and the Tax Court's case law is not uniform, although the contingency exists and worsens if the transaction is poorly documented.
What does Chile require of a company regarding its suppliers?
Chile has no enabling registry like the Mexican REPSE, so control lives in the contract and across three fronts. First, Law 20,393 on corporate criminal liability, applicable with the amendments of Law 21,595 since September 1, 2024, which broadened the catalogue of offences and raised the standard of the prevention model. Second, the subcontracting regime: the principal company is jointly and severally liable for the contractor's labour and social security obligations, and that liability drops to subsidiary only if it exercises the rights to information — the F30-1 certificate from the Labour Directorate — and to withhold payments. Third, personal data protection: Law 21,719 comes fully into force on December 1, 2026 and creates an agency with sanctioning powers, so clauses with suppliers that process data are best updated before that date.
How often should a supplier's due diligence be refreshed?
It depends on the risk level assigned to it, and that is precisely why you segment. For low-risk suppliers — standardised goods, small amounts, no access to data or premises — an annual review or one at contract renewal usually suffices. For medium risk, half-yearly. For high risk — access to systems or data, operational criticality, links to politically exposed persons, regulated sectors — documentary review should be at least half-yearly and restricted-list screening continuous. Beyond periodicity there are triggers: a change of legal representative, beneficial owner or shareholding reopens the analysis without waiting for the date.
Can supplier compliance be automated?
The mechanical part can be automated, and that is most of the work and almost all of the error: requesting documents from the supplier, reading the data off the document, tracking expiry dates, blocking onboarding when a mandatory requirement is missing, screening restricted lists and alerting when something changes. What is not automated is judgement: classifying a third party's risk, analysing a match that survives identity validation and approving an exception remain decisions for your compliance officer. A well-set-up system does not replace those decisions, it orders them and leaves the trail you will be asked for later.