Sep 10, 2026aml compliancepagcorinternet gaming licenseamlc registrationmtppphilippines gaming

AML Compliance for Internet Gaming Licensees in the Philippines: A PAGCOR Guide

Learn the AML/CTPF compliance requirements PAGCOR imposes on Philippine internet gaming licensees, from AMLC registration to the MTPP and compliance officer.


If you operate an internet gaming license under PAGCOR, you are a "covered person" under the Anti-Money Laundering Act of 2001, as amended (AMLA). That means you must register with the Anti-Money Laundering Council (AMLC), assess your money laundering and terrorism financing risks, appoint a compliance officer, adopt a written Money Laundering and Terrorism Financing Prevention Program (MTPP), and report covered and suspicious transactions. PAGCOR's Supervision and Enforcement Department, working with its Offshore Gaming Licensing Department, issued an AML/CTPF Compliance Guide for Internet Gaming Licensees and Authorized Providers to help new and prospective licensees meet these obligations.

What the AMLA requires of gaming licensees

Under Section 9(c) of the AMLA, covered persons must report covered and suspicious transactions to the AMLC. To transmit these reports, a covered person must first register with the AMLC to gain access to the AMLC Portal.

The AMLA also penalizes non-compliance. A covered person who knows that a covered or suspicious transaction should be reported and fails to do so may be guilty of money laundering under the last paragraph of Section 4 of the AMLA. The PAGCOR guide references Sections 49, 50, 51, and 52 of the 2021 AML/CTF Guidelines for Designated Non-Financial Businesses and Professions (DNFBPs), along with the 2021 AMLC Registration and Reporting Guidelines.

Register with the AMLC first

Registration is the gateway to every other reporting obligation. Without AMLC Portal access, a licensee cannot file the covered transaction reports (CTRs) and suspicious transaction reports (STRs) that the law requires.

A covered transaction refers to a single transaction involving an amount in excess of Five Hundred Thousand Pesos (Php500,000.00) or its equivalent in any other currency. A suspicious transaction is defined under paragraph (b-1), Section 3 of the AMLA, and is reported regardless of amount.

Conduct an institutional risk assessment

The licensee must identify, assess, and understand its own AML/CTF risks and document its findings. The PAGCOR guide lists the areas to cover: customers, business, products and services, geographical exposures, transactions, delivery channels, and size.

The institutional risk assessment (IRA) serves as the foundation for establishing controls that mitigate the identified risks. It must be kept up to date through periodic review, conducted at least once every two (2) years or as PAGCOR or the AMLC may determine, and submitted to PAGCOR and/or the AMLC when required. The guide cites Section 5(a to f) of the 2021 AML/CTF Guidelines for DNFBPs.

Appoint a compliance officer and a record-keeping officer

The licensee or authorized provider must designate a compliance officer of senior management status, with the authority and a direct line of communication to the Board of Directors or other governing body, or to the partners or sole proprietor, as the case may be. This officer ensures day-to-day compliance with AML/CTF obligations. The guide cites Section 8 of the 2021 AML/CTF Guidelines for DNFBPs.

A separate officer must be designated to be responsible and accountable for all record-keeping requirements under the AMLA and its rules, and to make those records readily available to the AMLC or PAGCOR upon request.

Adopt a written MTPP

The Board of Directors, governing body, partners, or sole proprietor must approve a comprehensive, risk-based MTPP, and the compliance officer implements it. The MTPP must be in writing, consistent with the AMLA, and reflect the licensee's corporate structure and risk profile.

The PAGCOR guide lists the critical areas the MTPP should cover, including:

  • Customer identification process and ongoing monitoring (Sections 21, 34, 35, 36)
  • Face-to-face contact (Section 30)
  • Risk-based customer due diligence (Sections 11, 17, 18, 19, 20, 23, 24, 25, 26, 27, 29, 31, 32, 37, 38)
  • Politically Exposed Persons (Section 33)
  • Minimum customer information and identification documents (Section 22)
  • Record keeping and retention (Sections 8, 13, 39, 40, 41, 42)
  • Covered transaction reporting (Sections 43, 44, and the 2021 ARRG)
  • Suspicious transaction reporting, including a red-flag system and a reporting chain leading to a Board-level or approved committee that decides whether to file with the AMLC (Sections 12, 28, 45, 46, 47, and the 2021 ARRG)
  • Continuous AML/CTF training for directors, responsible officers, and employees (Section 14)
  • Risk-based screening and recruitment (Section 14)
  • Internal audit and independent audit (Section 10)
  • Cooperation with the AMLC (Section 15)
  • Targeted financial sanctions (Section 58 and the AMLC 2021 Sanctions Guidelines)

The MTPP document itself typically follows a standard structure: an overview with company profile and legal framework; governance and oversight covering the institutional risk assessment, internal controls, compliance management, and hiring; policies and procedures on customer due diligence, transaction reporting, record-keeping, training, and targeted financial sanctions; plus forms, templates, and an updating mechanism.

Frequently asked questions

Do PAGCOR internet gaming licensees need to register with the AMLC? Yes. Covered persons must report covered and suspicious transactions to the AMLC under Section 9(c) of the AMLA, and registration is required to access the AMLC Portal and transmit those reports.

How often must the institutional risk assessment be updated? At least once every two (2) years, or as PAGCOR or the AMLC may determine. It must also be kept up to date through periodic review.

What is the threshold for a covered transaction? A single transaction involving an amount in excess of Five Hundred Thousand Pesos (Php500,000.00) or its equivalent in any other currency. Suspicious transactions are reportable regardless of amount.

Practical takeaways

  • Register with the AMLC early so the licensee can access the Portal and file CTRs and STRs.
  • Document a risk-based institutional risk assessment covering customers, products, channels, geography, and size, and review it at least every two years.
  • Appoint a senior management compliance officer with a direct line to the Board, plus a separate record-keeping officer.
  • Put the MTPP in writing, have it approved at the Board or proprietor level, and align it with the critical areas listed in the PAGCOR guide.
  • Build a suspicious transaction reporting chain with a red-flag system and a clear decision-maker for AMLC filings.

Primary sources

The rules discussed above are drawn from the following PAGCOR issuances, embedded here in full for your reference.

Anti-Money Laundering/Countering Terrorism and Proliferation Financing (AML/CTPF) Compliance GuideOpen in Law LibraryDownload PDF

This article is general information and not legal advice. For your specific situation, consult a lawyer or ask ASG Legal AI.

Have a question about this topic?

This article is general information, not legal advice. Ask ASG Legal AI for a cited, plain-language answer on your own situation — free, no sign-up.

AML Compliance for Internet Gaming Licensees in the Philippines: A PAGCOR Guide · Ablola, Saribong & Gueco