AML Compliance for Philippine Gaming Operators: PAGCOR and RA 11930 Rules
Learn AML compliance requirements for Philippine gaming operators, including PAGCOR rules and RA 11930 reporting duties under the AMLA.
Gaming operators in the Philippines must comply with the Anti-Money Laundering Act (AMLA) as amended, and are supervised by the Anti-Money Laundering Council (AMLC) through the Philippine Amusement and Gaming Corporation (PAGCOR). A key recent development is Republic Act No. 11930, which amended the AMLA to expand covered transactions and strengthen reporting obligations. For gaming operators, compliance means registering with the AMLC, implementing a risk-based Customer Due Diligence (CDD) program, reporting covered and suspicious transactions, and ensuring that internal controls address the specific risks of the gaming sector.
What RA 11930 Means for Gaming Operators
Republic Act No. 11930, known as the Anti-OSAEC and Anti-CSAEM Act, primarily addresses online sexual abuse and exploitation of children. However, it also amended the Anti-Money Laundering Act of 2001. For gaming operators, the practical effect is a broader set of reporting duties and closer scrutiny of transactions that may be linked to illicit activity.
The IRR of RA 11930 defines terms that gaming operators should understand. For instance, a payment system provider (PSP) is defined as "an entity engaged in any monetary transaction which includes banks, flat or digital money service businesses including cryptocurrencies, credit card companies and other financial institutions." This means that gaming platforms using digital wallets, cryptocurrencies, or other non-bank payment channels are dealing with PSPs that themselves have AML obligations.
The IRR also covers internet intermediaries, which include "participative network platform providers including social media intermediaries" and entities that provide "a platform or site for blogging, video-sharing, picture-sharing, file-sharing sites, online gaming or instant messaging, among others." An online gaming operator that hosts user-generated content or facilitates chat features may fall within this definition.
Covered Transactions and Suspicious Transaction Reports
Under the AMLA, as amended, covered persons—including casinos and gaming operators supervised by PAGCOR—must report covered transactions and suspicious transactions to the AMLC.
- Covered transactions are those exceeding a certain threshold in a single banking day, as defined by AMLA rules. The AMLC has issued specific thresholds for casinos, and gaming operators must track cumulative transactions to determine if reporting is required.
- Suspicious transactions are those that have no underlying legal or trade obligation, are not commensurate with the client's business or financial capacity, or are structured to avoid reporting. These must be reported regardless of the amount.
RA 11930 adds a layer: transactions that may involve proceeds of child sexual abuse or exploitation, including online sexual abuse or exploitation of children (OSAEC) and child sexual abuse or exploitation materials (CSAEM), are now clearly within the scope of suspicious transaction reporting. The IRR states that any person with "direct knowledge of any form of the unlawful or prohibited acts" must report to authorities, and gaming operators are expected to cooperate with law enforcement in such cases.
Customer Due Diligence (CDD) Requirements
Gaming operators must implement a risk-based CDD program. This includes:
- Identifying and verifying the identity of customers using reliable, independent source documents.
- Understanding the nature and purpose of the business relationship.
- Conducting ongoing due diligence on the business relationship and scrutinizing transactions to ensure consistency with the customer's profile.
For gaming operators, this is particularly challenging because of the volume of transactions and the use of intermediaries. The AMLC requires that casinos and gaming operators apply CDD measures not only to direct customers but also to beneficial owners and, in some cases, to the source of funds.
Reporting Obligations and Deadlines
The AMLC requires covered persons to file:
- Covered Transaction Reports (CTRs) within five working days from the occurrence of the transaction, unless an extension has been granted.
- Suspicious Transaction Reports (STRs) within five working days from the time the covered person has knowledge or reasonable grounds to suspect that a transaction is suspicious.
These deadlines are set by AMLC regulations, and gaming operators must have systems in place to identify and report within these windows. Failure to file accurate and timely reports can result in administrative sanctions, fines, and even criminal liability for willful violation.
Internal Controls and Compliance Program
A compliant gaming operator should have:
- A designated compliance officer with direct access to senior management.
- An internal audit function that tests the effectiveness of AML controls.
- Employee training programs on AML and on the specific risks of OSAEC and CSAEM-related transactions.
- A record-keeping system that retains transaction records and identification data for at least five years from the date of the transaction or the closure of the account.
The AMLC also encourages covered persons to adopt a "know your customer" culture and to screen customers against watchlists, including those maintained by the AMLC and international bodies.
Frequently Asked Questions
Do online gaming operators need to register with the AMLC? Yes. Casinos and gaming operators supervised by PAGCOR are covered persons under the AMLA and must register with the AMLC. Online gaming operators, including those with PAGCOR licenses, are subject to the same obligations.
What happens if a gaming operator fails to report a suspicious transaction? Failure to report can result in administrative fines, suspension or revocation of the license, and criminal penalties for willful violations. The AMLC can also impose sanctions on directors and officers.
Are cryptocurrency payments subject to AML rules for gaming operators? Yes. The IRR of RA 11930 explicitly includes "digital money service businesses including cryptocurrencies" as payment system providers, and gaming operators must apply CDD and transaction monitoring to payments made through these channels.
Practical Takeaways
- Register and comply: Ensure the gaming operation is registered with the AMLC and is aware of its obligations as a covered person.
- Implement a risk-based CDD program: Verify customer identity, understand the source of funds, and monitor transactions for consistency with the customer profile.
- File reports on time: Track covered and suspicious transactions and file CTRs and STRs within the prescribed deadlines.
- Train staff: Educate employees on AML risks, including the specific indicators of OSAEC and CSAEM-related financial activity.
- Coordinate with authorities: Cooperate with the AMLC, PAGCOR, and law enforcement agencies in investigations and reporting under RA 11930.
This article is general information and not legal advice. For your specific situation, consult a lawyer or ask ASG Legal AI.
This article is general information and not legal advice. For your situation, ask ASG Legal AI or book a consultation.