For a foreign company operating in Colombia through a subsidiary or branch, corporate governance tends to appear on the priority list much later than it should. The operation launches, incorporation formalities are handled, the local team is hired, and the structure of direction, control and accountability remains pending for when there is more time.
The problem is that moment rarely arrives by initiative. It arrives when the parent company requests a report that nobody knows how to produce, when a related-party transaction lacks documentation, or when the DIAN or Superintendencia de Sociedades requests information about the group structure that does not formally exist.
This article explains what Colombia requires in terms of corporate governance for foreign subsidiaries, what practices make the real difference, and how to build an internal control structure that works as a bridge between parent company standards and local requirements.
Corporate governance is the set of structures, principles, policies, and processes through which a company is directed, managed, and supervised. For a foreign subsidiary, that definition carries an additional layer of complexity: the governance structure must respond simultaneously to two frameworks: the parent company's, with its own control, reporting and corporate ethics standards, and Colombia's, with its own regulations, oversight authorities and formal requirements.
When those two frameworks are not aligned, the most frequent result is a subsidiary that formally meets minimum local requirements but does not produce the information the parent company needs for decision-making, lacks clarity about who approves what, and has no mechanisms to detect and report irregularities before they become contingencies..
Declaration of control situation and business group
When a foreign company exercises control over its Colombian subsidiary, it must formally declare that situation to the Chamber of Commerce under the Commercial Code and Law 222 of 1995. This declaration triggers additional obligations: the preparation of consolidated financial statements and a special report on related-party transactions to be presented to the shareholders' assembly.
Non-compliance is not a minor administrative detail: it is a corporate irregularity detectable in any due diligence process, Superintendencia de Sociedades audit, or DIAN review in the context of transfer pricing.
Related-party transaction policy
Every transaction between the Colombian subsidiary and its parent company, or between the subsidiary and other group companies, must have clear valuation, approval and documentation rules. This is not just good practice: it is a condition of tax deductibility and a transfer pricing regime requirement when amounts exceed the DIAN's established thresholds.
The absence of a formal related-party policy is the most frequent source of tax contingencies in foreign subsidiaries, especially in the first years of operation, when intercompany transactions are handled informally under the assumption that it is all within the same group.
Transparency and Business Ethics Program (PTEE)
Laws 2195 of 2022 and 1778 of 2016 promote and in some cases require formal transparency and corporate ethics programs. For foreign subsidiaries, this program is especially relevant because it connects directly with international anti-bribery standards that the parent company already implements globally. The local PTEE is the mechanism that gives those global standards real effect in the Colombian operation.
Anti-money laundering systems (SAGRLAFT/SARLAFT)
Depending on the sector and operation size, the subsidiary may be required to implement an anti-money laundering and terrorism financing risk management system, with risk matrices, counterparty due diligence procedures and suspicious transaction reporting mechanisms to the UIAF. For subsidiaries in high-risk sectors, this system is mandatory.
Clear separation of roles between ownership, governance and management
In many foreign subsidiaries, the local legal representative simultaneously acts as the sole liaison with the parent company, operational head of the business and point of contact with Colombian authorities. That concentration of roles creates opacity, dependency on specific individuals and difficulty for the parent company to understand what is actually happening in the subsidiary.
Best practice is to establish clear boundaries: who makes strategic decisions (shareholders' assembly or board), who executes them (local management), and who supervises them (Revisor Fiscal or internal auditor). That structure does not require a large organization: it can be implemented with two or three people with well-defined roles.
Board of directors or oversight committee with international perspective
For subsidiaries of a certain size or complexity, establishing a local board of directors, or at least an oversight committee with parent company participation, is the most effective tool for maintaining strategic alignment, detecting problems before they escalate and generating the decision traceability that any internal or external audit will require.
The technical recommendation is to include at least one third of independent members: people with no employment or ownership ties to the company, who bring objective judgment to long-term decisions. For a Colombian subsidiary of a European company, independent local perspective is especially valuable because it compensates for the knowledge the parent company has of European markets but not necessarily of the Colombian one.
Ethics code and effective whistleblower channel
A Code of Ethics and Conduct that remains a document on a server serves no real function. The ones that work are written in the language of the employees who must follow it, address concrete and recognizable situations of the local environment, and are accompanied by an anonymous reporting channel that generates real trust among those who use it.
For foreign subsidiaries, the whistleblower channel has an additional function: it is the path through which irregularities that the local team knows about but does not report to management can reach the parent company directly. That early warning function is worth more than the regulatory compliance that justifies its implementation.
Risk management framework aligned with parent company standards
The subsidiaries that best align with their European parent companies' requirements adopt internationally recognized risk management frameworks, such as COSO, ISO 31000, or the GRC (Governance, Risk and Compliance) frameworks already used by headquarters, and adapt them to the Colombian context rather than creating a parallel, incompatible system.
That alignment has an immediate practical benefit: the subsidiary's reports speak the same language as the parent company's control systems, reducing consolidation time and making it easier for the European internal audit director to understand what is happening in Colombia without intermediaries.
|
Phase |
Objective |
Key deliverables |
|
1. Corporate and legal diagnostic |
Map current compliance status against the Commercial Code, Law 222/1995 and sector-specific regulations |
Gap report - Register of pending formal obligations |
|
2. Formalization of bylaws and regulations |
Approve and document regulations for the supreme corporate body and board of directors |
Updated bylaws - Board regulations - Formalization minutes |
|
3. Related-party policy |
Define valuation, approval and documentation rules for intercompany transactions |
Approved policy - Approval procedures - Documentation templates |
|
4. PTEE and whistleblower channel |
Implement the ethics program and anonymous reporting channel |
Ethics code - Active channel - Internal investigation protocol |
|
5. Risk management framework |
Adopt a framework compatible with parent company standards |
Risk matrix - Treatment policies - Monitoring dashboard |
|
6. Audit and continuous improvement |
Integrate Revisoría Fiscal and/or internal audit with parent company reporting |
Periodic reports - Revisor opinion - Consolidated group report |