Decree 0849 of 2026: New Guidelines for Corporate Transparency and Ethics Programs
The National Government issued Decree 0849 of July 28, 2026, which adds a new section to Decree 1081 of 2015 related to Corporate Transparency and Ethics Programs (PTEE, for its Spanish acronym). This regulation seeks to strengthen corruption prevention mechanisms in the private sector and, in particular, to consolidate common standards for organizations subject to inspection, oversight, or control.
It incorporates a preventive approach based on risk management, transparency, due diligence, reporting mechanisms, corporate integrity, and the strengthening of internal control.
Therefore, before analyzing the content and guidelines set out in the annex, it is important to clarify that its application must be understood within the framework of the provisions issued by the relevant inspection, oversight, and control authorities.
For companies that already have a PTEE, it is advisable to conduct a general review in light of the new guidelines. Likewise, companies that are not currently required to implement a PTEE should keep ongoing track of the regulations applicable to them, considering that obligations may vary according to their sector, economic activity, and supervisory authority.
What Is the Purpose of Decree 0849 of 2026?
The main objective of the Decree is to establish a framework of Minimum Guidelines for PTEEs, so that inspection, oversight, and control authorities have a common standard when determining the content their supervised entities must comply with.
The rule distinguishes between the Minimum Guidelines and the Content of each PTEE. The former constitute the general framework established at the national level, while it is up to each supervisory authority to determine the specific content applicable to organizations, considering factors such as economic sector, risks, income and asset levels, number of employees, and corporate purpose.
This distinction is essential for companies: simply adopting the technical annex of Decree 0849 does not mean compliance with PTEE obligations if the competent authority has not yet determined the content applicable to the respective supervised entity.
For this reason, organizations must continuously monitor the provisions and administrative acts issued by the authorities that exercise inspection, oversight, or control over their activities.
What Minimum Guidelines Should Be Considered?
The Annex includes a set of components intended to help PTEEs move from being formal documents to becoming genuine management and prevention tools.
The main elements include:
- Scope and context of the organization.
- Management of corruption, bribery, and transnational bribery risks.
- Anti-bribery and anti-corruption measures.
- Conflict of interest management.
- Measures related to government contracting.
- Measures on lobbying.
- Measures on political campaign financing.
- Due diligence mechanisms.
- Integrity measures.
- Transparency in corporate management.
- Mechanisms for handling reports/complaints.
- Definition of roles and responsibilities.
- Disclosure and training.
- Audit and continuous improvement.
In this regard, the Technical Annex includes internal audit rules aimed at ensuring that books, records, inventories, financial statements, vouchers, and other documents contain accurate, complete, and up-to-date information, thereby strengthening the integrity of accounting information.
This shows that the fight against corruption should not be analyzed solely from a legal perspective. It also directly involves organizations' accounting, financial, administrative, and control processes.
A Risk-Based Approach
Decree 0849 promotes designing PTEEs according to the particular characteristics and risks of each organization.
In this regard, authorities must consider differentiated criteria related to company size, the nature of the supervised entity, the sector, the risks associated with its activity, and other relevant factors.
Accordingly, it is understood that an organization with domestic operations and a low level of risk exposure does not face the same scenarios as a company with international operations, government contracting, multiple suppliers, intermediaries, or higher-risk relationships.
This approach is important because it invites administrations to assess their company and keep this in mind when applying PTEEs, making it effective to properly identify, assess, and address risks, and subsequently translate them into concrete controls, defined responsible parties, monitoring mechanisms, and evidence of their functioning.
What Changes for Statutory Auditors (Revisoría Fiscal)?
One of the aspects generating the most interest among public accounting professionals is the express involvement of the statutory auditor (revisor fiscal).
The Decree establishes that, when a statutory auditor exists, they must assess the Corporate Transparency and Ethics Program and issue an opinion on it. The Technical Annex specifies that this assessment must consider both the existence of the program and its operational effectiveness, with the purpose of contributing to the organization's continuous improvement process.
This provision represents an element that must be carefully analyzed by audit firms and statutory auditors, especially because the regulation itself states that the inspection, oversight, and control authorities will determine the specific responsibilities that internal control and the statutory audit function will have, according to the characteristics of the sector, industry, or regulated market.
Consequently, the statutory auditor's work must consider the regulatory framework applicable to the entity, the requirements established by its supervisory authority, and the available evidence on the design and functioning of the PTEE.
What Should Companies Do?
Although actual implementation will depend on the content determined by the competent authority for each sector, organizations can begin strengthening their prevention systems now.
The main actions include:
- Identify the applicable supervisory authority.
The company must determine which entity exercises inspection, oversight, or control over its activities and what specific provisions currently apply to it. - Review the existing PTEE.
If the organization already has a program, it is advisable to evaluate its structure against the new Minimum Guidelines and against the particular provisions of its supervisory authority. - Update the risk matrix.
Corruption, bribery, and transnational bribery risks must be identified, assessed, and linked to concrete controls. - Strengthen due diligence. Knowledge of clients, suppliers, contractors, associates, beneficial owners, and other counterparties is an essential element in preventing risks.
- Review reporting channels.
The program must include accessible, confidential, and reliable mechanisms for reporting possible acts of corruption or ethical breaches, as well as whistleblower protection measures. - Document evidence of controls.
A policy or procedure is not enough if there is no evidence of its application, monitoring, and evaluation.
A New Challenge for Corporate Control and Management
Decree 0849 of 2026 represents an important shift in how Corporate Transparency and Ethics Programs are understood. Rather than a documentary requirement, the PTEE must become a tool integrated into strategy, risk management, internal control, and organizational culture.
For companies, this means strengthening their prevention mechanisms and generating sufficient evidence of their functioning. For auditors and statutory auditors, it means incorporating these elements into their evaluation processes, considering the scope defined by the regulation applicable to each entity.
Finally, it is important to remember that inspection, oversight, and control authorities have a transition period to review their legal frameworks and determine the necessary adjustments. For the first version of the Minimum Guidelines, the Decree establishes a three-month period for this review and, when adjustments are necessary, up to nine months to carry them out.
Therefore, 2026 becomes an opportune time for organizations not to wait for new requirements to be issued before reviewing their control systems, but rather to proactively assess their risks, policies, procedures, and prevention mechanisms.
In a business environment where transparency, trust, and proper risk management are increasingly decisive, having solid control systems not only contributes to regulatory compliance: it also protects reputation, strengthens decision-making, and generates sustainable value for the organization and its stakeholders.
Prepared by: María Angélica Mora – Senior Auditor. and
Fredy Alexander Pérez – Asistente Líder de Auditoría.
THIS DOCUMENT REFLECTS AN OPINION OF OUR FIRM. TAX AUTHORITIES MAY NOT AGREE WITH OUR POSITION. IF YOU WISH TO LEARN MORE ABOUT THIS TOPIC OR REQUIRE SPECIALIZED ADVICE, PLEASE DO NOT HESITATE TO CONTACT US, WE ARE HERE TO SERVE YOU.