Skip to main content
Didit Raises $7.5M to Build the Infrastructure for Identity and Fraud
Didit
Latin America

Identity verification
built for Colombia Flag of Colombia

Cédula de Ciudadanía and Cédula de Extranjería on one session, cross-checked against the Registraduría with biometric face-match, $0.33 full KYC, 500 free every month.

Backed by
Y CombinatorRobinhood Ventures
GBTC Finance
Bondex
Crnogorski Telekom
UCSF Neuroscape
Shiply
Adelantos

Trusted by 2,000+ organizations worldwide.

Country brief

How identity verification works in Colombia.

The fraud surface and the frameworks an engineering or compliance lead needs before scoping an integration.
Fraud landscape
Three pressures shape Colombian identity fraud: synthetic Cédulas riding the wave of fintech credit and Nequi / Daviplata wallet onboarding, document forgery across the legacy yellow Cédula and the new digital Cédula Digital formats, and remittance-corridor mule networks routing Venezuelan and Ecuadorian flows through Colombian fintechs. Didit scores 200+ real-time fraud signals on every session, face morph, replay, injection, document tampering, device intelligence, IP geolocation.
Compliance frameworks
  • SARLAFT 4.0 (Circular Básica Jurídica)
  • Ley 526/1999 (UIAF)
  • Ley 1581/2012 (Datos Personales)
  • Decreto 1377/2013
  • Ley 2294/2023 (Ley de Fintech)
  • FATF 40 recommendations
Regulators

Who supervises identity verification in Colombia.

These are the supervisors a Colombia verification flow has to answer to. One Didit hosted flow + one audit log covers every one of them, no separate integration per agency.
  • SFC

    Superintendencia Financiera de Colombia, prudential supervisor for banks, SEDPEs, fintech credit firms and securities markets. Owns the SARLAFT 4.0 framework.

  • UIAF

    Unidad de Información y Análisis Financiero, Colombia's Financial Intelligence Unit. Receives Reportes de Operación Sospechosa under Ley 526/1999.

  • SIC

    Superintendencia de Industria y Comercio, supervises Ley 1581/2012 (Datos Personales) and Decreto 1377/2013. Governs every identity verification on Colombian residents.

  • DIAN

    Dirección de Impuestos y Aduanas Nacionales, tax and customs authority. Operates the NIT and tax-residency registries used in KYB and treasury onboarding.

  • Banco de la República

    Central bank and prudential authority for foreign-exchange operations, payment systems and reserve management.

Verification flow · One API

Four modules. One verification.

ID, biometric, AML, and a Colombia database cross-check, composed on one workflow, billed per success, returned in one report.
01 · ID

Capture and read the ID.

Captured on any phone, auto-classified, OCR-parsed, and template-verified.

  • Cédula de Ciudadanía (yellow card and Cédula Digital), Cédula de Extranjería, Permiso por Protección Temporal (PPT), Pasaporte (with the chip read on e-Passports), and Licencia de Conducción.
  • Returns the name, Cédula number, date of birth, sex, and expiry.
Read the docs
Stage 01Capture and read the ID
  • Cédula de Ciudadanía · Cédula Digital
  • Cédula de Extranjería · Permiso por Protección Temporal (PPT)
  • Pasaporte, chip read on e-Passport
02 · Biometric

Match the face. Prove it's a real person..

Selfie confirmed live and matched against the ID portrait.

  • Duplicate check: 1:N face search across existing users. Free.
  • Active liveness ($0.15) for elevated-risk flows, user turns or blinks.
Read the docs
Stage 02Match the face. Prove it's a real person.
  • Selfie on any phone or laptop camera
  • Mobile-handoff QR when the user starts on desktop
03 · AML

Screen for sanctions, PEPs, and adverse media.

Didit screens the user's name against the global pool of 1,300+ sanctions, Politically Exposed Persons (PEP), and adverse-media lists, plus every Colombian regulatory watchlist (SFC Administrative and Final Sanctions, SIC, DIAN, Fiscalía General, Superintendencia de Economía Solidaria, Superintendencia de Puertos y Transporte, Rama Judicial, Contraloría de Santander, SECOP, AMV).

Severity-scored. Ongoing monitoring ($0.07/user/yr) re-checks daily and fires a webhook on new hits.

Read the docs
Stage 03Screen for sanctions, PEPs, and adverse media

Screen for sanctions, PEPs, and adverse media , see the docs for the full module surface.

04 · Registry

Cross-check against the Registraduría.

Cross-checked against the authoritative civil registry.

  • The `col_cedula` check ($0.20, no end-user consent required) is the fast provider-backed Cédula lookup, personal_number + document_type in, normalised identification fields out.
  • The `col_national_id` check ($0.95, ~75% coverage, consent required) hits the Registraduría Nacional del Estado Civil directly, first_name, last_name, date_of_birth, personal_number in, full validation envelope out (name match score, DOB match, identification match).
Read the docs
Stage 04Cross-check against the Registraduría

Cross-check against the Registraduría , see the docs for the full module surface.

Documents covered

Every Colombia document Didit accepts.

One row per accepted credential, flag, document name, document type. Live from the Didit Business Console.
Compliant by design

Open a new country in one click. We do the hard work.

We open the local subsidiaries, secure the licenses, run the penetration tests, earn the certifications, and align with every new regulation. To ship verifications in a new country, flip a toggle. 220+ countries live, audited and pen-tested every quarter, the only identity provider an EU member-state government has formally called safer than in-person verification.
Read the security & compliance dossier
EU financial sandbox
Tesoro · SEPBLAC · BdE
ISO/IEC 27001
Information security · 2026
SOC 2 · Type I
AICPA · 2026
iBeta Level 1 PAD
NIST / NIAP · 2026
GDPR
EU 2016/679
DORA
EU 2022/2554
MiCA
EU 2023/1114
AMLD6 · eIDAS 2.0
EU-aligned by design
FAQ

Common questions about Colombia.

What does Didit ship?

Didit is the infrastructure layer for identity and fraud. One Application Programming Interface (API), 25+ composable modules across four product lines:

  • User Verification (KYC, know your customer), Identity Document Verification, liveness, face match, Anti-Money Laundering (AML) screening, Internet Protocol (IP) analysis. $0.33 per full bundle.
  • Business Verification (KYB, know your business), registry, Ultimate Beneficial Owner (UBO), officers, entity AML, plus a linked KYC session per UBO.
  • Transaction Monitoring, real-time rule engine, case management, Suspicious Activity Report (SAR) workflow.
  • Wallet Screening (KYT, know your transaction), on-chain wallet risk at $0.15 per check, or bring your own screening provider and run it inside Didit.

Compose any module into a workflow with the visual no-code builder, ship in 5 minutes, 500 verifications free every month, forever.

How is Didit different from a single-product Know Your Customer (KYC) vendor?

Most identity vendors sell one slice, a KYC check, an Anti-Money Laundering (AML) list, a wallet screen. Didit ships the infrastructure underneath all of them, and the gap shows up on six axes:

  • Pricing. Public price on every module, $0.33 for a full KYC, 500 verifications free every month, no minimums, no contracts. Single-product vendors hide six-figure minimums behind a sales call.
  • Access. Sandbox in one click, self-serve from day one, production keys on signup. Single-product vendors gate the sandbox behind a contract, months to evaluate.
  • Developer experience. Public docs, a Model Context Protocol (MCP) server for Claude Code and Cursor, and native Software Development Kits (SDKs) for Web, iOS, Android, React Native, and Flutter. Integrate in 5 minutes with an AI agent or in a working afternoon by hand.
  • User experience. Highest pass rates in the market, sub-2-second end-to-end inference, country-specialised capture flows, 48+ languages out of the box.
  • Flexibility. One /v3/ Application Programming Interface (API) composes 25+ modules across KYC, Know Your Business (KYB), Transaction Monitoring, and Wallet Screening (KYT, know your transaction). A KYB session spawns a linked KYC for every Ultimate Beneficial Owner (UBO); a flagged transaction spawns a step-up KYC remediation, same session, same webhook contract, same audit trail. Single-product vendors sell one shape of KYC and stop there.
  • AI-era fraud. 200+ real-time fraud signals scored on every session, deepfake, injection, synthetic-ID, document forgery, face-morph, device intelligence, replay. Single-product vendors treat deepfake and injection detection as roadmap items, not defaults.

Common in fintech and crypto, the same architecture fits marketplaces, iGaming, mobility, and any vertical where you need to know who someone is and what they are doing.

What does it cost? Is anything actually free?

500 verifications free every month, forever, on every account. No credit card. No sales call. No expiry.

Above the free tier, every module has a public per-success price on didit.me/pricing, $0.33 per full KYC bundle, $0.15 per Identity Document Verification, $0.15 per Wallet Screening, $0.20 per Anti-Money Laundering (AML) Screening, $0.10 per liveness, $0.05 per face match, $0.03 per Internet Protocol (IP) analysis.

Pay-as-you-go, no minimums, no overage surprises. Volume discounts kick in automatically as you grow.

Which Colombian regulator covers identity verification on a digital onboarding?

Four sit on top of every Colombian identity-verification flow:

  • Superintendencia Financiera de Colombia (SFC), sets onboarding requirements for banks, Sociedades Especializadas en Depósitos y Pagos Electrónicos (SEDPE), fintech credit firms and securities markets under SARLAFT 4.0 (the Sistema de Administración del Riesgo de Lavado de Activos y Financiación del Terrorismo).
  • Unidad de Información y Análisis Financiero (UIAF), Colombia's Financial Intelligence Unit. Receives Reportes de Operación Sospechosa under Ley 526/1999.
  • Superintendencia de Industria y Comercio (SIC), supervises Ley 1581/2012 (Datos Personales) and Decreto 1377/2013. Governs how the verification data is captured, stored and disclosed.
  • Dirección de Impuestos y Aduanas Nacionales (DIAN), operates the NIT and tax-residency registries used in KYB and treasury onboarding.

Didit ships the hosted flow + the audit log + the watchlist coverage to satisfy all four at the same time, same POST /v3/session/ workflow, same JSON report, same SOC 2 Type 1 + ISO/IEC 27001 evidence pack.

Does Didit cross-check Colombian identities against the Registraduría?

Yes, via two Database Validation services (POST /v3/database-validation/):

  • `col_national_id`, hits the Registraduría Nacional del Estado Civil directly. $0.95 per successful query, ~75% coverage, requires end-user consent. Inputs: first_name, last_name, date_of_birth, personal_number. Returns identification_number, date_of_birth, name_match_score, and the verification envelope.
  • `col_cedula`, fast provider-backed Cédula lookup. $0.20 per successful query, no consent gate, ID + document_type in, normalised identification fields out.

Both are documented at docs.didit.me/api-reference/database-validation/colombia/.

Is Didit ready for SARLAFT 4.0 onboarding for SFC-supervised entities?

Yes. SARLAFT 4.0 (the Circular Básica Jurídica chapter on Lavado de Activos y Financiación del Terrorismo) is the framework every SFC-supervised entity, bank, SEDPE, fintech credit firm, securities broker, runs onboarding under.

Didit covers the full stack on one workflow:

  • Identity Document Verification + Active Liveness + Face Match 1:1 for the tier-1 onboarding check.
  • `col_national_id` Database Validation against the Registraduría, the authoritative source UIAF + SFC expect.
  • AML Screening ($0.20 per check) against the global pool plus Colombian regulatory watchlists (SFC Administrative + Final Sanctions, SIC, DIAN, Fiscalía General, AMV, SECOP, PEP registers).
  • Ongoing AML monitoring ($0.07 per user / year) for the SARLAFT 4.0 periodic-review obligation.
  • Wallet Screening (KYT) at $0.15 per check for on-chain exposure assessment under the new Colombian crypto guidance.
How long does it take to integrate Didit in Colombia?

5 minutes to a working sandbox, a weekend to a production flow.

  • Sign up at business.didit.me, grab an API key, call POST /v3/session/ with a workflow_id that wires ID Verification + Active Liveness + Face Match + AML + Registraduría database, done.
  • AI-agent path: paste the integration prompt at docs.didit.me/integration/integration-prompt into Claude Code, Cursor, Codex, Devin, Aider, or Replit Agent. The agent provisions the application, builds the workflow, wires the webhook, and runs a smoke test.
  • Five SDKs share the same session model: Web, iOS, Android, React Native, Flutter.

The first 500 verifications every month are free, forever, pilot the full Colombia stack at zero cost before flipping production traffic.

Which language does the hosted verification flow use for Colombian users?

Colombian Spanish, auto-detected from the user's browser / device locale. The hosted UI ships in 48+ languages; Colombian users land on the Spanish flow by default. English is also live on the same flow for cross-border or expat users.

The document-recognition layer is decoupled from the UI layer, capture works in any language, and the admin console can be set independently to whichever language your compliance team prefers.

What does the Colombia verification cost end-to-end?

Per-module public pricing, pay only for what runs on the session:

  • ID Verification, $0.15 per document check.
  • Passive Liveness, $0.10. Active Liveness, $0.15.
  • Face Match 1:1, $0.05. Face Search 1:N, free.
  • AML Screening, $0.20 per check. Ongoing AML, $0.07 per user / year.
  • `col_cedula` (provider-backed), $0.20 per successful query.
  • `col_national_id` (Registraduría, ~75% coverage), $0.95 per successful query.

The full KYC bundle (Identity + Passive Liveness + Face Match + IP Analysis) is `$0.33`, same anchor price worldwide, no Colombia surcharge. 500 verifications free every month, no credit card. Volume discounts auto-apply above the free tier; Enterprise adds a custom Master Services Agreement (MSA) and data-residency choice.

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page