Money laundering and terrorist financing prevention
Anti-money laundering and anti-corruption policy
A risk-based approach under Resolution 2328 of 2025, integrated with the Corporate Transparency and Ethics Programme.
The SARLAFT system at RIBELL S.A.S. accounts for the company’s own risks and materiality in relation to money laundering, terrorist financing and the financing of weapons of mass destruction. The business, its operation, its size and the geographies in which it operates have all been analysed under the risk-based approach set out in Resolution 2328 of 2025. The risk matrix is the central instrument for identifying, recording, segmenting, assessing, measuring and auditing how risk evolves, on the premise that greater risk calls for greater control.
In line with Resolution 14673 of 2025, the company adopts a policy of zero tolerance for corruption and transnational bribery, integrating SARLAFT with its Corporate Transparency and Ethics Programme (PTEE).
Applicable policies:
- Confidentiality. Employees maintain strict confidentiality regarding requests and inspections by the authorities and regarding reports submitted to the Financial Information and Analysis Unit (UIAF).
- Counterparty due diligence. Suppliers, contractors and employees complete an onboarding process that includes screening against Colombia’s binding lists (article 20 of Law 1121 of 2006), the OFAC list and the European Union and United Nations lists.
- Cash transactions. The company does not use cash as a means of collection or payment; all transactions are settled through the Colombian financial system.
- Virtual assets. Cryptocurrencies and other virtual assets are not used; all transactions are carried out in legal tender.
- Reporting to the UIAF. Suspicious transactions are reported immediately through SIREL, and a nil report is filed within ten days of the end of each period when none are detected.
- Annual communication and training for employees, management and relevant counterparties.
The company’s highest governing body has appointed a Compliance Officer, responsible for auditing the system at least once a year, reporting on it and ensuring it is updated every two years, or sooner where regulation requires.
