September 9, 2026 · 8min read
Law 2573 and What It Means for Telcos, Banks, and Merchants
When it comes to new account fraud, Identity theft has run the same playbook for years:
- Someone steals a consumer’s information and opens an account or credit line in their name, or logs into the account the consumer already has.
- They spend the money or run up the balance on the card, but they don’t make the payment.
- The consumer gets a late payment notice or a collection call. This is the first time they even know they have this account or the account has been compromised.
- Now the consumer has to prove they weren’t the one who opened the account.
- They file complaints, get buried in paperwork, and wait months for their name to clear, if at all.
The Superintendencia de Industria y Comercio (SIC) has received more than impersonation complaints since 2020. According to SIC, between 2022 and May 2026, out of the 13,983 claims filed through its consumer platform, 81% were against telcos.1
Colombia’s Law 2573 went into effect in May 2026. The law changes this scenario by requiring the entity best positioned to prove the truth to bear legal responsibility for approving the account. That is rarely the customer. It means the bank or the retail store that said yes.
Key Takeaways
- Law 2573, taking effect around November 2026, shifts legal liability for new account fraud by introducing a dynamic burden of proof.2
- Banks, telcos, and merchants in Colombia are now legally responsible for proving they opened an account securely, rather than forcing the customer to prove their innocence.
- Article 4 treats any product or service obtained in someone else’s name, in person or online, as impersonation. That includes a loan or a purchase from an existing account the real customer already had.
- Institutions must verify identities during onboarding and retain actual evidence of the process, including biometrics, IP addresses, and document checks. If an institution onboarded a criminal because it lacked mature fraud prevention processes, it must absorb the financial loss and erase the debt.
- Feedzai Digital Trust and Secure Onboarding ensure compliance by orchestrating identity checks, automatically logging proof of verification, and stopping fraudsters before accounts are funded.
What Law 2573 Means for Banks, Retailers, and Financial Institutions
The obvious read of Law 2573 is consumer protection paid for by institutions. But the law includes a second element the checklist misses, and it changes what a bank should actually build.
Ultimately, this law ensures two things: prevention and accountability. On prevention, it ensures financial institutions have sufficient digital fraud prevention and security to protect consumers from impersonation attacks. Meanwhile, accountability requires proving that FIs have verified the consumer’s identity at every stage of the digital banking lifecycle, or they are liable. The law calls this the dynamic burden of proof.
Colombia is not the first to move liability to the party best placed to prevent the loss. The card networks did it with the US EMV liability shift for counterfeit cards a decade ago. The UK did it for authorized push payment scams in 2024.3 Law 2573 does it for impersonation, and the only difference is that FIs must provide evidence to the consumer on request and may never refuse.
When will Law 2573 go into effect?
Law 2573 was signed on May 19, 2026, and will go into effect about six months later, around November 2026. Two paragraphs are already in force. Paragraph 1 of Article 5 orders the SIC and the Superintendencia Financiera to write identification protocols, and paragraph 2 is the consequence, requiring institutions to refund the money if they did not follow them.
The regulators are writing the detailed rules in that same window. That leaves you about a quarter to get ready.
What new responsibilities will banks, telcos, and merchants have under Law 2573?
Law 2573 asks six things of an institution. These requirements apply every time an organization says “yes”, whether opening an account or approving a transaction from an existing account.
- Verify identity and documents, demonstrate checks. Article 5 requires sufficient and reasonable digital security measures to establish that the person is who they say they are and that their documents are genuine. Under this obligation, financial institutions must check these documents at the moment of approval and provide a record that the review was conducted.
- Hand over what was received to the customer: Articles 2 and 5 articulate the dynamic burden of proof. Upon request, the institution provides the customer a copy of the information and documents submitted to approve the product or service. The text of the law says it may not refuse under any circumstance. It is important to note the language, “what was received.” Essentially, anything the approval relied on to make that decision must be shared with the customer.
- Move within 10 business days: Articles 5 and 7 require that complaints must be processed within 10 business days of filing. In that window, the institution compares the documents used to contract the disputed obligation against the ID the customer submits. If they do not match, the customer’s ID serves as summary proof, and the institution requests correction of the negative data and score, adds the “Víctima de Falsedad Personal” legend, and files its own fraud complaint. Petitions unanswered after 15 business days, extendable by eight, are deemed resolved in the customer’s favor.
- Stop collecting the moment the customer speaks: Article 8 states that when a customer reports impersonation, collection is suspended immediately, including interest and collection costs. The customer is told they have 20 business days to file with the Fiscalía. Then everyone waits for a court appointment. If the institution’s own verification finds evidence of impersonation, it releases the customer without waiting. What it can never do is decide there was no impersonation. Article 10 reserves that finding for the courts. If the customer never files, collection may resume with the back interest.
- Look harder at flagged identities, not lower. The “Víctima de Falsedad Personal” legend replaces the negative report. It cannot count as negative, cannot lower a risk rating, cannot alter a credit study. It has exactly one permitted use: intensified identity verification the next time that person applies. A flagged name means step-up, not decline.
- Pay for the gaps. An institution that did not follow the protocols, faced with a victim’s correction request, returns the money or erases the debt. Not pauses it. Not waiting for the other bank. Returns it.
Law 2573 Fraud Controls Requirements Can Help Banks Onboard More Good Customers
It is easy to read Law 2573 as one more cost. But the FIs that get it right will notice something the compliance memo did not mention. The signals that make a “yes” decision defensible are those that enable a bank to onboard more genuine customers more confidently and with less friction.
In Colombia, as everywhere, many good customers never make it through the onboarding process. Some are declined by mistake or false positives. Others get halfway through, hit a manual step-up or unnecessary friction, and leave. Those are people the bank paid to acquire, walking out at the last door. And once they are in, the ones the bank cannot recognize get an OTP for every login, payee change, or account change, and a good share of them give up there, too. Not to mention those step-ups are costly.
A bank that can distinguish a customer from an impersonator by how the session behaves can have fewer false declines at the door, fewer challenges for the person who is genuinely themselves, and the explainability the law requires as a byproduct of mature, modern fraud controls. Defensible and digital growth are not a trade-off. Read properly, the same signals do both.
How Feedzai Helps You Comply with Law 2573
Most banks know their customer at the front door and then trust them forever. A bank can recognize a document, a credential, a face, and still not know whether the person acting is the customer.
In 2025, the suspected fraud rate fell by 74% because criminals are bypassing onboarding and authentication controls using real stolen credentials or AI-driven synthetic credentials, so less fraud is being caught. The challenge for banks is no longer to verify a person once. It is to know whether the person is real, who they claim to be, and whether they keep acting like themselves across every channel and over time.
That is the gap between recognizing a customer and knowing one. Here’s how Feedzai closes that gap for FIs worldwide, leading to 42% fewer false positives, one in five fewer abandonments, and protection for over 25 billion digital banking sessions and over 1 billion consumers.
Stop Impersonation Before It Becomes an Obligation
Feedzai’s Secure Onboarding orchestrates passive and active signals from the bank’s own systems and any third party, preserving full fidelity in real time, and builds them into a complete applicant profile. The decision is made against the profile, not against a score. That changes what the bank can see. A synthetic identity built from real fragments passes each check on its own, but contextually, all the signals together, it gets stopped. A stolen cédula matches the bureau and fails the behavior read because someone pasted the number without knowing it. And because the profile links every application through behavioral biometrics, device and network intelligence, the bank does not just catch one impersonation attempt. It unravels the ring behind it.
The profile doesn’t stop after the onboarding decision. It adapts as new signals arrive, and it persists after the onboarding decision, which traditional onboarding solutions do not. So the same profile that stopped the ring at the door is what catches a dormant mule six months later, or first-party fraud, or an account takeover with stolen credentials.
Prevent ATO and APP Scams Throughout the Entire Digital Banking Session
At most banks, the tough questions fall silent once the onboarding decision is reached and the account is opened. Law 2573 makes that silence expensive, because the loan taken inside a hijacked account is now the bank’s to explain. Feedzai’s Digital Trust continuously updates a customer’s profile at every stage of every session for every identity. Any anomaly shows up as behavior that does not match the person who enrolled, made a loan request, requested a credit limit change, or added a new payee. The session terminates before the money moves.
Explain Every Decision, Completely
Every approval and every decline carries the reasons behind it. The sources consulted, the rules that fired, the model score, and the behavioral and device evidence from the session, written in the bank’s own decisioning language at the moment the decision was made and readable by an analyst, a customer, or a court.
- When a customer asks for a copy of what the approval relied on, the bank is ready.
- When a customer disputes a loan taken in their account, the bank can show who was there and release them under Article 10 the same day.
- When a supervisor asks whether the protocols were followed, the procedures are readily available.
Collectively, this is continuous adaptive trust. Trust that starts before the account does and grows with every login and every interaction for every identity and journey.
We will read the full policy the day it is published and share any updates. Until then, the most useful thing you can do is pick one real impersonation complaint from the last year and ask what you could have handed over and where the gaps are in establishing continuous adaptive trust. Thirty minutes with a real case tells more than any memo, and we are happy to sit on the other side of the table with you.
Want to see where you’re exposed before November? Let’s talk.
Footnotes
1 https://sedeelectronica.sic.gov.co/
2 https://www.alcaldiabogota.gov.co/sisjur/normas/Norma1.jsp?i=193210
All expertise and insights are from human Feedzaians, but we may leverage AI to enhance phrasing or efficiency. Welcome to the future.
