Reference guide · Country-by-country framework · 2026

    Supplier Compliance & Risk in LATAM: the country-by-country guide

    What each country requires when you onboard a supplier — Colombia, Mexico, Peru and Chile — how to segment your base by risk level, which documents to request at each level and how to sustain control after approval. Every obligation cited here links to its official source.

    By Oscar Gamboa, CEO of EGIXIA · Updated August 11, 2026

    Read the guide

    Full guide on this page · the PDF downloads with no form

    Cover of the Egixia LATAM Supplier Compliance & Risk Checklist 2026
    Downloadable checklist

    The guide explains the framework. The PDF checklist is the working list.

    The PDF gathers the country checks into a printable list your team can take into the onboarding meeting. This page is the living version: it is reviewed whenever regulations change and it prevails if anything differs from the PDF.

    Direct download, no form and no sign-up.

    Executive summary

    Third-party risk is not controlled with loose documents, it is controlled with a process. Most procurement teams in Latin America request the same complete file from every supplier, archive it and never look at it again: that produces heavy folders and thin control. A programme that works does the opposite — it classifies first, demands in proportion to risk and keeps watching after approval — and leaves dated evidence of every check.

    This guide arranges that process into five decisions (segment, verify, screen, monitor and escalate) and gathers the regulatory framework of the four countries where most regional onboarding happens. Every obligation, deadline or penalty below links to its official source, and anything we could not confirm against an official source was not published. This is management reference material: it does not replace the legal advice each organisation must validate with its local counsel.

    Who this guide is for

    Third-party compliance is decided across four tables that rarely read the same document. This guide is written so all four can work from the same framework.

    Procurement directors and managers

    Accountable for onboarding not stalling the operation, and for no supplier entering without the level of verification it deserves.

    Finance and Internal Control

    The ones who absorb the cost when a payment loses deductibility, when a joint liability appears or when a critical supplier fails.

    Compliance officers and Legal

    The ones answering to the regulator for the money-laundering, corruption and bribery prevention programme, and for the traceability of every decision.

    Information Technology

    The ones assessing suppliers that connect to your systems or process personal data, and defining what security evidence is required of them.

    The four risks a third party introduces

    Before requesting a single document it helps to know what the organisation is protecting itself against. Third-party risks fall into four families and each is mitigated with different controls: confusing them leads to requesting financial statements where a data-processing clause was what was missing.

    Operational risk

    Disruption of critical supply, quality failures or missed deadlines that halt production. Mitigated with criticality analysis, contingency plans and alternate suppliers, not with paperwork.

    Financial risk

    Supplier insolvency, fraud, cost overruns or liabilities arriving through joint responsibility. Mitigated with financial assessment and by controlling the contractor's labour and social security obligations.

    Legal and AML/CFT risk

    Administrative penalties, money laundering, corruption, bribery and corporate criminal liability. It is the one that varies most by country and the one that organises this guide.

    Information risk

    Data leakage, cybersecurity incidents and loss of intellectual property when the third party connects to your systems or processes personal data. Mitigated with contractual requirements and technical evidence the buyer decides to demand.

    Guiding principle: proportionality. Not every supplier needs the same level of control. Demanding a cloud provider's file from a stationery vendor does not make the operation safer: it makes it slower, and the team ends up approving by exception exactly when it matters.

    Segmentation by risk level

    Segmentation is the first decision and it determines everything else: how much documentation is required, how often it is reviewed and who can approve. It happens before the commercial relationship starts, not after the first invoice arrives.

    LevelAssignment criteriaDocumentary requirementsMonitoring frequencyApproval required
    LowStandardised goods, low amounts, no access to data or premises.Tax ID (RUT/RFC/RUC), bank certificate and electronic invoicing.Annual or on renewalProcurement analyst
    MediumSpecialised services, recurring contracts, mid-size amounts, minor subcontracting.Financial statements, commercial references and valid tax and labour certificates.Half-yearlyProcurement manager
    HighAccess to systems or data, operational criticality, links to politically exposed persons, regulated sectors.Enhanced due diligence, beneficial ownership, full restricted-list screening and anti-corruption and audit clauses.Monthly or continuousCompliance committee or Legal

    Write down the criteria that assign each level. If classification depends on the judgement of whoever registers the supplier, two analysts will classify the same third party differently and the policy stops being auditable.

    Documentary due diligence: five steps that leave a trail

    Due diligence does not end when the supplier sends the files. It ends when there is a record of what was requested, what arrived, who validated it, against which source and what was decided. That trail is what a regulator or an auditor will ask for, and it is the first thing lost when the file lives in shared folders.

    1. 1Collect
    2. 2Verify
    3. 3Validate
    4. 4Approve
    5. 5Retain

    Critical document categories in LATAM

    Corporate

    Certificate of incorporation and legal representation, corporate minutes and identification of the beneficial owner: who actually controls the company, not just who signs.

    Tax

    Valid tax registration and evidence of the taxpayer's standing before each country's authority, with the date of the query.

    Financial

    Financial statements, bank certificates and liquidity indicators, required according to risk level and contract size.

    Compliance

    Anti-corruption policy, code of ethics, conflict-of-interest declaration and evidence of screening against national and international restricted lists.

    Labour and information security

    Evidence of social security contributions and compliance with the applicable subcontracting regime; and, when the supplier processes data or connects to your systems, the security evidence you as the buyer decide to require (valid certifications, penetration test results, data-processing clauses).

    Country-by-country regulatory framework

    Latin America does not have a single supplier onboarding regime: it has four different logics. Colombia revolves around a supervised self-control system, Mexico around an enabling registry with immediate tax effects, Peru around the supplier's tax standing and Chile around corporate criminal liability and the subcontracting regime. A regional corporate policy can unify the process, but not the requirements.

    Informational content, not legal advice. Regulations change and thresholds are updated: always confirm the text in force at the official source linked for each country and validate your policy with local counsel before applying it. Egixia does not certify or guarantee compliance with any regulation.

    Colombia

    SAGRILAFT · Superintendence of Companies

    SAGRILAFT is the self-control and risk management system for money laundering, terrorism financing and financing of the proliferation of weapons of mass destruction that the Superintendence of Companies requires from real-sector companies. It is not the same as SARLAFT, the equivalent regime run by the Financial Superintendence for the entities it supervises, nor the same as the sector-specific SARLAFT schemes adopted by other superintendences: treating them as synonyms leads to applying the wrong rule. In 2026 the Superintendence of Companies issued a new Basic Legal Circular — External Circular 100-000020 of July 2, 2026 — which unifies into a single chapter the obligations previously split between SAGRILAFT and the Business Transparency and Ethics Programme (PTEE). That reform also changed the unit of measure for the applicability thresholds: confirm them in the official text before setting your policy, not in third-party summaries.

    What to verify

    • Existence and legal representation: Chamber of Commerce certificate and RUES lookup. The web lookup is informational; the certificate is what carries evidentiary weight.
    • Restricted lists: OFAC (SDN list) and the UN Security Council Consolidated List, plus any national disqualification lists that apply to your sector.
    • Beneficial ownership: identify who actually controls the company, to rule out shell companies and nominees.
    • Tax standing: valid RUT and a dated lookup of the RUT status at the DIAN.
    • Social security: evidence of contributions for the relevant period, particularly where personnel work on your premises.
    • Politically exposed persons (PEPs): screening of the supplier, its shareholders and their close associates.

    Where to verify it (official sources)

    What happens if you do not verify

    The Superintendence of Companies may impose fines, successive or not, of up to 200 monthly statutory minimum wages on those who breach its orders, the law or the bylaws (article 86, paragraph 3, of Law 222 of 1995). We publish the multiple rather than a peso amount on purpose: the minimum wage is adjusted every year and any fixed figure goes stale. Beyond the administrative exposure sit directors' liability and the reputational damage of trading with a sanctioned counterparty.

    Open the Colombia supplier compliance kit (Excel)

    Mexico

    REPSE and tax effects · STPS, SAT, IMSS and INFONAVIT

    The labour subcontracting reform, published in the Official Gazette of the Federation on April 23, 2021, banned personnel subcontracting and created the Registry of Specialised Services or Specialised Works Providers (REPSE) before the Ministry of Labour and Social Welfare. The registration is renewed every three years and the registry is public and searchable online. Mexico is the case where non-compliance bites fastest, because it hits through the labour route and the tax route at the same time.

    What to verify

    • Valid REPSE: search the public STPS registry by tax ID or company name and keep dated evidence. The check repeats at every payment, not only at onboarding.
    • Deductibility: without valid registration, payments for specialised services carry no deduction or crediting effects (article 15-D of the Federal Tax Code). The contracting party must verify the registration and collect payroll receipts, withholding evidence and proof of IMSS and INFONAVIT contributions (article 27, section V, of the Income Tax Law, and article 5, section II, of the VAT Law).
    • ICSOE at the IMSS and SISUB at INFONAVIT: filed by the service provider every four months. Ask for the filing receipt, because the contracting party is jointly liable for the contractor's social security obligations (article 15-A of the Social Security Law).
    • SAT tax compliance opinion. A nuance worth knowing: article 32-D of the Federal Tax Code requires it of the Federal Public Administration before contracting; between private parties it is not a legal obligation but a control you agree by contract. It is a sound practice, but do not present it to your supplier as a mandate of that article.
    • On the REPSE folio in the CFDI: including it on the service invoice is a widespread control practice, not a formal requirement of the tax receipt. What is enforceable is verifying the registration at the time of payment and keeping the evidence.

    Where to verify it (official sources)

    What happens if you do not verify

    The fine for providing subcontracting services without the registration runs from 2,000 to 50,000 times the Unit of Measure and Update (UMA), and article 1004-C of the Federal Labour Law applies it equally to the party providing the service and to the party benefiting from it: the contracting company is a direct subject of the penalty, not a bystander. We publish the multiple because INEGI updates the UMA value every year, and the peso figures in circulation usually come from stale values. On top of the fine sits the tax effect, which in practice weighs more: payments stop being deductible and the related VAT stops being creditable.

    Open the Mexico supplier compliance kit (Excel)

    Peru

    SUNAT · the supplier's tax standing

    In Peru the control rests on two fields of the Single Taxpayer Registry (RUC) that are confused all the time: the taxpayer's status — active, temporarily suspended, deregistered — and the condition of its tax domicile — located ("Habido"), not found or "No habido". They are separate, independent fields, both are looked up free of charge on the public SUNAT portal, and both must be recorded with the date of the query.

    What to verify

    • RUC with active status and "Habido" condition, verified at contracting and again at the time of each material payment.
    • Income tax: expenses supported by a receipt issued by a taxpayer that was "no habido" on the issue date are not deductible, unless that condition has been lifted by December 31 of the tax year (article 44, subparagraph j, of the Income Tax Law). This is the clear effect, written in the law and citable.
    • IGV — that is the name of the tax in Peru, not IVA: contracting a "no habido" supplier is a genuine contingency, but it should not be presented as an automatic loss of the input tax credit. The text in force of article 19 of the IGV Law does not put it in those terms and the Tax Court's case law is not uniform. What is enforceable in every case: that the transaction is real, properly documented and settled through the banking system.
    • Validity of powers of attorney: a certificate of validity of power from SUNARP, confirming that whoever signs is still empowered to bind the company.

    Where to verify it (official sources)

    What happens if you do not verify

    The concrete consequence is usually not a fine for contracting, but the disallowance of the expense: the tax authority can reassess the income tax deduction supported by receipts from a "no habido" supplier, with the unpaid tax, interest and any applicable penalty. That is why the date of the lookup matters as much as its result, and why it is worth checking again before paying rather than only at onboarding.

    Chile

    Law 20,393, subcontracting and data protection

    Chile has no enabling supplier registry equivalent to the Mexican REPSE, so control shifts to the contract. A Chilean buyer has to cover three separate fronts: the company's own criminal liability for offences committed in its interest, the labour obligations passed on by the subcontracting regime, and the processing of personal data, whose standard is about to change.

    What to verify

    • Corporate criminal liability: Law 20,393 applies with the amendments of Law 21,595 (Economic Crimes Law) as of September 1, 2024, which broadened the catalogue of predicate offences and raised the standard required of the crime prevention model.
    • Certification of the prevention model: as of September 1, 2024 the obligation for certifying entities to be registered with the CMF was repealed, and with it the validity of that registry and of its entries. Asking a supplier today for a certificate issued under that registry no longer applies: what is assessed is that the model exists, operates and is reviewed.
    • Subcontracting: request the Certificate of Compliance with Labour and Social Security Obligations (F30-1) from the Labour Directorate. The principal company is jointly and severally liable for the contractor's labour and social security obligations, and that liability drops to subsidiary only if it exercises its rights to information and to withhold payments.
    • Payment terms: Law 21,131 sets 30 calendar days from receipt of the invoice, with a narrow option to agree an exceptional term in writing and register it with the Ministry of Economy.
    • Personal data: Law 21,719 was published on December 13, 2024, comes fully into force on December 1, 2026 and creates the Personal Data Protection Agency. If the supplier will process personal data, the clauses are best written to that standard now rather than waiting for the effective date.
    • Existence of the company: Registry of Companies and Corporations, and the third-party tax standing lookup at the Internal Revenue Service.

    Where to verify it (official sources)

    What happens if you do not verify

    The dominant risk in Chile does not arrive as a registry fine, it arrives by two routes. The first is labour: if you do not exercise the rights to information and withholding, the principal company is jointly and severally liable for the contractor's labour and social security debts, and those debts are collected in full. The second is criminal: Law 20,393 allows the company itself to be sanctioned for offences committed in its interest when the duty of direction and supervision failed, and a poorly controlled third party is one of the entry points.

    Restricted-list alerts: investigate before blocking

    A restricted-list hit is not a conviction. Namesakes and partial matches are frequent, and a process that blocks automatically on any alert ends up being switched off by the operation itself. The protocol must be the same every time and it must be written down.

    1. 1

      Initial alert

      Detection of the match on international or national lists, with automatic logging of the date, the source consulted and the search term.

    2. 2

      Identity validation

      Rule out the namesake by cross-checking ID number, incorporation date, address and ownership structure. Most alerts die here.

    3. 3

      Risk analysis

      If the match holds, assess its nature and severity: a binding financial sanction is not the same as a local administrative disqualification or an adverse media hit.

    4. 4

      Escalation

      Take the case to the compliance committee or to Legal. The decision is not made by whoever registered the supplier: separating who detects from who decides is what makes the process defensible.

    5. 5

      Decision and record

      Block, conditional approval with mitigating measures, or approval — always with the residual risk analysis documented and with a name, a date and an expiry for the exception.

    Continuous monitoring: control does not end at signature

    Onboarding photographs a moment. Restricted lists are updated daily, certificates expire and a supplier's ownership structure can change without notice. A file approved fourteen months ago says nothing about today's supplier.

    Expiry dates

    Automatic alerts 30 to 60 days before certifications, insurance policies, enabling registrations or operating licences expire, so renewal is not settled on payment day.

    Structural changes

    Detection of changes in legal representation, beneficial ownership or shareholding — the ones that reopen the restricted-list analysis.

    Periodic review

    Full documentary review according to risk level — annual, half-yearly or continuous — and on-site audits for critical suppliers.

    How to measure progress

    A third-party compliance programme is managed with four indicators. Each organisation sets its own targets according to its risk appetite and starting point: here we define what each one measures, not what value yours should have.

    Due diligence coverage

    Share of active suppliers with a complete, valid file for the risk level they were assigned. It is the indicator that most quickly reveals whether the policy is applied or merely exists.

    Onboarding cycle time

    Days from the onboarding request to final approval. Measuring it by risk level avoids the average trap, which hides that low-risk suppliers are paying for the high-risk process.

    Alert resolution

    Percentage of matches investigated, dismissed or escalated within the deadline set by internal policy. A queue of unresolved alerts is open exposure, not an administrative backlog.

    Preventive blocks

    Number of high-risk third parties stopped before resources were committed or a contract signed. It is the only indicator that shows the value of the programme in positive terms.

    We do not publish benchmark values for these indicators: the ones circulating in the market rarely explain the base they were calculated on, and a target borrowed from an organisation with a different risk profile becomes an arbitrary goal.

    Risks and limits of the process

    A supplier compliance programme has known blind spots. Naming them in advance keeps them from appearing as a surprise in the first audit.

    False positives on restricted lists

    Namesakes and partial matches delay legitimate contracting. Without analytical judgement and complementary documentary validation, the process is abandoned or everything gets approved by exception.

    Document obsolescence

    Tax and commercial documents expire often. A file that was complete on approval day can be incomplete three months later, and under manual control that is invisible until the audit.

    Regional regulatory disparity

    Requirements vary substantially between countries, as the previous section shows. A global corporate policy can unify the process and the roles, but it has to leave room for local law.

    The nature of this guide

    It is a management reference framework. It does not replace the legal, tax or cybersecurity advice each company must validate with its internal and external advisors, and Egixia does not certify or guarantee compliance with any regulation.

    How EGIXIA supports this process

    EGIXIA helps large Latin American companies simplify their entire procurement cycle. On the third-party side, that means turning the process described above into a flow with an owner and with evidence: the supplier uploads its own documents to a self-service portal, the system tracks expiry dates, onboarding does not advance while a mandatory requirement is missing, and every check is recorded with a date and an owner.

    What the tool does not do is decide for your compliance officer. Risk classification, the analysis of a match that survives identity validation and the final approval remain your organisation's decisions; the system orders them, documents them and keeps them from getting lost.

    Validation against external sources via API is enabled per project, according to the client's policies.

    Which tool to use when

    This guide answers what each country requires. The pieces below solve different moments of the supplier lifecycle and complement it rather than repeat it.

    Frequently asked questions

    What is SAGRILAFT and which companies does it apply to?

    SAGRILAFT is the comprehensive self-control and risk management system for money laundering, terrorism financing and financing of the proliferation of weapons of mass destruction that Colombia's Superintendence of Companies requires from real-sector companies. Whether it applies depends on revenue or asset thresholds and on the sector the company operates in. In 2026 the Superintendence issued a new Basic Legal Circular (External Circular 100-000020 of July 2, 2026) that unifies the SAGRILAFT and Business Transparency and Ethics Programme obligations into a single chapter and changed the unit of measure of the thresholds. Confirm the values in force in the Superintendence's official text before deciding whether your company is covered.

    What is the difference between SAGRILAFT and SARLAFT?

    They are parallel regimes with different supervisors. SARLAFT is the money laundering and terrorism financing risk management system of the Financial Superintendence, applicable to the entities it supervises — banks, insurers, trust companies, brokers. SAGRILAFT is the Superintendence of Companies regime for real-sector companies. Other superintendences have additionally adopted sector-specific SARLAFT schemes for their supervised entities. Writing them as if they were a single rule is a frequent mistake and leads to demanding requirements from a supplier that do not apply to it.

    What happens if a Mexican supplier does not have a valid REPSE?

    Two simultaneous effects. The labour one: article 1004-C of the Federal Labour Law provides for a fine of 2,000 to 50,000 times the UMA, applied both to the party providing the service without registration and to the party benefiting from it, so the contracting company is a direct subject of the penalty. The tax one: without valid registration, payments for specialised services carry no deduction or crediting effects under article 15-D of the Federal Tax Code, and the contracting party must verify the registration at the time of payment and collect payroll, withholding and contribution receipts in order to deduct. The REPSE registry is public, so the check is free and takes a minute.

    Is a private company required to request the SAT 32-D opinion from its supplier?

    Not under that article. Article 32-D of the Federal Tax Code bars the Federal Public Administration — not private companies dealing with each other — from contracting with parties that are not current on their tax obligations. Requiring the compliance opinion in a B2B relationship is a very reasonable and widespread control practice, but it rests on the contract and on internal procurement policy, not on a legal mandate. The distinction is worth making: presenting it to a supplier as a legal obligation weakens the rest of your requirements when someone checks.

    How do I verify whether a Peruvian supplier is "Habido" at SUNAT, and what happens if it is not?

    You look up the RUC free of charge on the public SUNAT portal. Check two separate fields: the taxpayer status must be active and the condition of the tax domicile must be "Habido". If the condition is "No habido", the clear effect written in the law is that expenses supported by receipts issued while it held that condition are not deductible for income tax, unless the condition was lifted by December 31 of the tax year (article 44, subparagraph j, of the Income Tax Law). On the IGV input tax credit it is worth being more cautious: the text in force of article 19 of the IGV Law does not establish an automatic loss on that ground and the Tax Court's case law is not uniform, although the contingency exists and worsens if the transaction is poorly documented.

    What does Chile require of a company regarding its suppliers?

    Chile has no enabling registry like the Mexican REPSE, so control lives in the contract and across three fronts. First, Law 20,393 on corporate criminal liability, applicable with the amendments of Law 21,595 since September 1, 2024, which broadened the catalogue of offences and raised the standard of the prevention model. Second, the subcontracting regime: the principal company is jointly and severally liable for the contractor's labour and social security obligations, and that liability drops to subsidiary only if it exercises the rights to information — the F30-1 certificate from the Labour Directorate — and to withhold payments. Third, personal data protection: Law 21,719 comes fully into force on December 1, 2026 and creates an agency with sanctioning powers, so clauses with suppliers that process data are best updated before that date.

    How often should a supplier's due diligence be refreshed?

    It depends on the risk level assigned to it, and that is precisely why you segment. For low-risk suppliers — standardised goods, small amounts, no access to data or premises — an annual review or one at contract renewal usually suffices. For medium risk, half-yearly. For high risk — access to systems or data, operational criticality, links to politically exposed persons, regulated sectors — documentary review should be at least half-yearly and restricted-list screening continuous. Beyond periodicity there are triggers: a change of legal representative, beneficial owner or shareholding reopens the analysis without waiting for the date.

    Can supplier compliance be automated?

    The mechanical part can be automated, and that is most of the work and almost all of the error: requesting documents from the supplier, reading the data off the document, tracking expiry dates, blocking onboarding when a mandatory requirement is missing, screening restricted lists and alerting when something changes. What is not automated is judgement: classifying a third party's risk, analysing a match that survives identity validation and approving an exception remain decisions for your compliance officer. A well-set-up system does not replace those decisions, it orders them and leaves the trail you will be asked for later.

    Download the PDF checklist

    The printable version of the country checks, laid out as a control list for the onboarding meeting. No form and no sign-up.

    Follow us on LinkedIn for new guides, templates and notices when supplier compliance regulations change in the region.

    Follow Egixia on LinkedIn

    References and official sources

    Sources consulted and verified on August 11, 2026. Every obligation, deadline or penalty cited in this guide comes from one of them; anything we could not confirm against an official source was not published.

    1. [1]Superintendence of Companies (Colombia). Regulations in force and Basic Legal Circular. https://www.supersociedades.gov.co/web/nuestra-entidad/normativa
    2. [2]Superintendence of Companies (Colombia). Announcement of External Circulars 100-000019 and 100-000020 of 2026, unifying SAGRILAFT and PTEE into a single chapter (July 2, 2026). https://www.supersociedades.gov.co/noticias-supersociedades/-/asset_publisher/atwl/content/superintendencia-de-sociedades-expide-nuevas-circulares-para-fortalecer-la-transparencia-la-seguridad-jur%C3%ADdica-y-el-cumplimiento-empresarial
    3. [3]Law 222 of 1995 (Colombia), article 86, paragraph 3 — sanctioning power of up to 200 monthly statutory minimum wages. Gestor Normativo, Función Pública. https://www.funcionpublica.gov.co/eva/gestornormativo/norma.php?i=6739
    4. [4]RUES — Colombian Single Business and Social Registry. Existence and registration lookup. https://www.rues.org.co/
    5. [5]DIAN (Colombia). RUT status lookup. https://muisca.dian.gov.co/WebRutMuisca/DefConsultaEstadoRUT.faces
    6. [6]OFAC, U.S. Department of the Treasury. Sanctions list search tool (SDN). https://ofac.treasury.gov/sanctions-list-search-tool
    7. [7]UN Security Council. Consolidated Sanctions List. https://www.un.org/securitycouncil/content/un-sc-consolidated-list
    8. [8]Official Gazette of the Federation (Mexico). Labour subcontracting reform decree, April 23, 2021 — creates the REPSE and adds article 15-D of the CFF, 1004-C of the LFT and 15-A of the LSS. https://dof.gob.mx/nota_detalle.php?codigo=5616745&fecha=23/04/2021
    9. [9]STPS (Mexico). Public REPSE registry lookup. https://repse.stps.gob.mx/
    10. [10]STPS (Mexico). Labour subcontracting reform. https://www.gob.mx/stps/articulos/reforma-en-materia-de-subcontratacion
    11. [11]INEGI (Mexico). Value of the Unit of Measure and Update (UMA), updated annually. https://www.inegi.org.mx/temas/uma/
    12. [12]IMSS (Mexico). ICSOE — information return on specialised services and works contracts. https://www.imss.gob.mx/icsoe
    13. [13]SAT (Mexico). Tax compliance opinion lookup (article 32-D of the CFF). https://portalsat.plataforma.sat.gob.mx/32D/faces/pages/consultaOpinion.jsf
    14. [14]SUNAT (Peru). Public RUC lookup: taxpayer status and tax domicile condition. https://e-consultaruc.sunat.gob.pe/cl-ti-itmrconsruc/FrameCriterioBusquedaWeb.jsp
    15. [15]SUNAT (Peru). Non-deductible expenses — article 44, subparagraph j, of the Income Tax Law. https://renta.sunat.gob.pe/empresas/gastos-no-deducibles
    16. [16]SUNAT (Peru). Consolidated text of the IGV Law, input tax credit chapter (articles 18 and 19). https://www.sunat.gob.pe/legislacion/tributaria/igv/ley/capitul6.htm
    17. [17]SUNARP (Peru). Certificate of validity of power granted by a legal entity. https://www.gob.pe/380-inscribir-poder-notarial-en-sunarp-solicitar-certificado-de-vigencia-de-poder-otorgado-por-persona-juridica
    18. [18]National Congress Library (Chile). Law 20,393 on the criminal liability of legal entities. https://www.bcn.cl/leychile/navegar?idNorma=1008668
    19. [19]CMF (Chile). Certifying entities for crime prevention models: repeal of the registration requirement as of September 1, 2024. https://www.cmfchile.cl/portal/principal/613/w3-propertyvalue-18578.html
    20. [20]Labour Directorate (Chile). Certificate of Compliance with Labour and Social Security Obligations (F30-1). https://www.dt.gob.cl/portal/1626/w3-article-100359.html
    21. [21]National Congress Library (Chile). Law 21,719 on personal data protection, published December 13, 2024, fully in force on December 1, 2026. https://www.bcn.cl/leychile/navegar?i=1209272
    22. [22]Registry of Companies and Corporations (Chile). Verification of existence and representation. https://www.registrodeempresasysociedades.cl/
    23. [23]SII (Chile). Third-party tax standing lookup. https://www.sii.cl/como_se_hace_para/situacion_trib_terceros.html

    Turn third-party control into a repeatable process

    We will show you this framework running on your real supplier base: self-service portal, expiry tracking and dated evidence on every check.

    Request a demo