Anti-Money Laundering Rules for Gaming Operators in the Philippines
Anti-money laundering rules for gaming operators in the Philippines: AMLC registration, risk assessment, compliance officer, and MTPP requirements.
Gaming operators in the Philippines are covered persons under the Anti-Money Laundering Act of 2001, as amended (AMLA). That means they must register with the Anti-Money Laundering Council (AMLC), report covered and suspicious transactions, assess their money laundering and terrorism financing risks, appoint a compliance officer, and adopt a written Money Laundering/Terrorism Financing Prevention Program (MTPP). PAGCOR's Anti-Money Laundering/Countering Terrorism and Proliferation Financing (AML/CTPF) Compliance Guide for Internet Gaming Licensees and Authorized Providers lays out these obligations. Failure to report a transaction that the law requires to be reported can expose a covered person to a money laundering charge.
Who counts as a covered person
Under Section 9(c) of the AMLA, covered persons are obligated to report covered and suspicious transactions to the AMLC. To transmit these reports, a covered person must first register with the AMLC to gain access to the AMLC Portal.
A covered transaction is a single transaction involving an amount in excess of Five Hundred Thousand Pesos (Php500,000.00) or its equivalent in any other currency. A suspicious transaction is defined under paragraph (b-1), Section 3 of the AMLA, regardless of amount.
The guide warns that a covered person who knows that a covered or suspicious transaction is required to be reported and fails to do so shall be guilty of money laundering under the last paragraph of Section 4 of the AMLA.
Registration and reporting with the AMLC
Registration is the gateway to compliance. Without AMLC Portal access, an operator cannot file Covered Transaction Reports (CTRs) or Suspicious Transaction Reports (STRs). The guide cites Sections 49, 50, 51, and 52 of the 2021 AML/CTF Guidelines for DNFBPs and the 2021 AMLC Registration and Reporting Guidelines (ARRG) as the governing references.
Suspicious transaction reporting is not a single filing. It requires a system — electronic or manual — for flagging, monitoring, and reporting transactions that qualify as suspicious, regardless of amount, and that raise a "red flag." It also requires a reporting chain under which a suspicious transaction is processed, and the designation of a senior officer who ultimately decides whether a report is filed with the AMLC. The guide cites Sections 12, 28, 45, 46, and 47 of the 2021 AML/CTF Guidelines for DNFBPs, read with the 2021 ARRG, for this element.
Institutional risk assessment
Every licensee must identify, assess, and understand its own AML/CTF risks and document its findings. The guide lists the areas to cover:
- Customers
- Business
- Products and services
- Geographical exposures
- Transactions
- Delivery channels
- Size
The results of this Institutional Risk Assessment (IRA) serve as the foundation for establishing appropriate and sufficient controls to mitigate the identified risks. The IRA must be kept up to date through periodic review, conducted at least once every two (2) years or as PAGCOR or the AMLC may determine, and submitted to PAGCOR and/or the AMLC when required. The reference is Section 5(a to f) of the 2021 AML/CTF Guidelines for DNFBPs.
Compliance officer and record-keeping officer
The licensee must designate a compliance officer of senior management status, with the authority and mandate to maintain a direct line of communication to the Board of Directors or other governing body, or to the partners or sole proprietor, as the case may be. This officer ensures day-to-day compliance with AML/CTF obligations. The reference is Section 8 of the 2021 AML/CTF Guidelines for DNFBPs.
Separately, the licensee must designate a record-keeping officer responsible and accountable for all record-keeping requirements under the AMLA and its rules. This officer makes records readily available to the AMLC or PAGCOR upon request. The same Section 8 reference applies.
The Money Laundering/Terrorism Financing Prevention Program
The Board of Directors, governing body, partners, or sole proprietor must approve — and the compliance officer must implement — a comprehensive, risk-based MTPP. It must be in writing, consistent with the AMLA, and reflect the entity's corporate structure and risk profile.
The guide identifies the critical areas the MTPP should address, including:
- Customer identification process, including acceptance policies and ongoing monitoring (Sections 21, 34, 35, 36)
- Face-to-face contact (Section 30)
- Risk-based customer due diligence (Sections 11, 17, 18, 19, 20, 23, 24, 25, 26, 27, 29, 31, 32, 37, 38)
- Politically exposed persons (Section 33)
- Minimum customer information and identification documents (Section 22)
- Record keeping and retention (Sections 8, 13, 39, 40, 41, 42)
- Covered transaction reporting (Sections 43, 44, and the 2021 ARRG)
- Suspicious transaction reporting (Sections 12, 28, 45, 46, 47, and the 2021 ARRG)
- AML/CTF training for directors, responsible officers, and employees (Section 14)
- Risk-based screening and recruitment (Section 14)
- Internal audit and independent audit program (Section 10)
- Cooperation with the AMLC (Section 15)
- New business practices, services, technologies, and products (Section 16)
- Notification requirements (Section 53)
- Targeted financial sanctions (Section 58 and the AMLC 2021 Sanctions Guidelines)
The MTPP document itself follows a standard structure: an overview with company profile and legal framework; governance and oversight covering institutional risk assessment, internal controls, compliance management, and hiring; policies and procedures on customer due diligence, transaction reporting, record retention, and targeted financial sanctions; plus forms, approving authority, and updating provisions.
Frequently asked questions
Do Philippine gaming operators need to register with the AMLC? Yes. Under Section 9(c) of the AMLA, covered persons must report covered and suspicious transactions to the AMLC, and registration is required to access the AMLC Portal and transmit those reports.
How often must a gaming operator conduct an institutional risk assessment? At least once every two (2) years, or as PAGCOR or the AMLC may determine. The assessment must be kept current through periodic review and submitted when required.
What happens if an operator fails to report a covered or suspicious transaction? A covered person who knows that a reportable transaction exists and fails to report it shall be guilty of money laundering under the last paragraph of Section 4 of the AMLA.
Practical takeaways
- Register with the AMLC to obtain Portal access before any CTR or STR can be filed.
- Conduct and document an institutional risk assessment at least every two years, covering customers, products, transactions, delivery channels, geography, and size.
- Appoint a senior-management compliance officer and a separate record-keeping officer.
- Adopt a written, board-approved MTPP that addresses customer due diligence, PEPs, record retention, transaction reporting, training, audit, and targeted financial sanctions.
- Build a suspicious transaction reporting chain with a designated senior officer empowered to decide whether to file with the AMLC.
Primary sources
The rules discussed above are drawn from the following issuances, embedded here in full for your reference.
Gaming Site Regulatory Manual ver. 3.0 ( Bingo Games)Open in Law LibraryDownload PDF
Anti-Money Laundering/Countering Terrorism and Proliferation Financing (AML/CTPF) Compliance GuideOpen in Law LibraryDownload PDF
This article is general information and not legal advice. For your specific situation, consult a lawyer or ask ASG Legal AI.
This topic sits within our Gaming & PAGCOR Licensing practice.
Related reading
Vendor due diligence in the Philippines helps companies screen third parties for corporate, anti-money laundering, and child-safety risks before onboarding.
A PIGO licence is a PAGCOR Gaming License that lets an operator run online gaming through an accredited remote gaming platform in the Philippines.
Learn which institutions the BSP anti-money laundering regulations cover, their AML duties, and key rules under BSP Circular No. 950.
A PAGCOR gaming licence may be suspended or revoked for serious or repeated violations. Learn the grounds, the due process, and the penalties involved.
Have a question about this topic?
This article is general information, not legal advice. Ask ASG Legal AI for a cited, plain-language answer on your own situation — free, no sign-up.