·By Ablola, Saribong & Gueco Law Offices · researched and citation-checked against the firm's law library

AML Compliance Program in the Philippines: What the Law Requires

Building an anti-money laundering compliance program in the Philippines? Learn the required MLPP, risk assessment, and due diligence rules.


An anti-money laundering (AML) compliance program in the Philippines is built around a written Money Laundering and Terrorist Financing Prevention Program (MLPP) that covered persons must adopt, have approved by their board of directors, and keep available for inspection. Under the Bangko Sentral ng Pilipinas (BSP) rules, the program must cover risk management, customer due diligence, suspicious transaction reporting, training, and internal audit. The board sets the tone; the compliance office runs the program day to day.

Who must maintain an AML compliance program

The rules apply to all covered persons supervised and regulated by the Bangko Sentral. These include banks, non-banks, quasi-banks, trust entities, non-stock savings and loan associations, pawnshops, foreign exchange dealers, money changers, remittance and transfer companies, electronic money issuers, and other financial institutions that special laws place under BSP supervision or regulation — including their subsidiaries and affiliates, wherever located.

If a branch, office, subsidiary, or affiliate abroad cannot implement the rules because of local law, it must formally notify the Bangko Sentral, furnish a copy of the conflicting law or directive, and apply additional measures to manage the money laundering and terrorist financing risks.

The MLPP: the core document

Every covered person must adopt an MLPP that is consistent with the Anti-Money Laundering Act (AMLA), as amended, its Revised Implementing Rules and Regulations, and the BSP rules, and designed around its own corporate structure and risk profile. It must be in writing.

The MLPP must contain detailed procedures for the major AMLA requirements, including a reporting chain for suspicious transactions and the designation of a board-level or approved committee that ultimately decides whether to file a report with the Anti-Money Laundering Council (AMLC). If resources do not permit a committee, the compliance officer may perform this function, provided the board is informed of the decision.

The MLPP must also include an effective and continuous AML/CFT training program, a mechanism ensuring audit and examination findings are immediately corrected, and the designation of an AML compliance officer who may serve as liaison with the Bangko Sentral and the AMLC.

Covered persons must prepare and have available for inspection an updated MLPP approved by the board of directors. Each MLPP must be regularly updated at least once every two years, and any revision likewise requires board approval.

Governance: board, senior management, and the compliance office

The board of directors must ensure adequate oversight of the covered person's AML/CFT compliance management. Senior management oversees day-to-day management, ensures effective implementation of board-approved AML/CFT policies, and establishes a structure that promotes accountability, transparency, and checks and balances.

The compliance office manages the implementation of the MLPP. To preserve independence, it must have a direct reporting line to the board of directors or a board-level or approved committee on all AML and terrorist financing compliance matters. Its functions include conducting periodic compliance checking, ensuring that infractions found in audits or BSP examinations are immediately corrected, informing officers and employees of relevant BSP and AMLC issuances, alerting senior management and the board when AML/CFT issues are not being addressed, and organizing AML training.

Where a covered person has branches, subsidiaries, or offices here or abroad, a group-wide compliance officer — or the parent entity's compliance officer — oversees AML/CFT compliance across the group.

Risk assessment and risk-based customer due diligence

Covered persons must identify, understand, and assess their ML/TF risks arising from customers, countries or geographic areas, products, services, transactions, and delivery channels. The methodology must suit the nature and complexity of the business. The assessment must consider all relevant risk factors, document results and findings, and be updated periodically or as needed. It must also be made available to the Bangko Sentral during examination.

New products and business practices — including new delivery mechanisms and new technologies — must be assessed for ML/TF risk before launch, as part of product development.

Customer due diligence follows a risk-based approach. It includes identifying the customer and verifying identity based on official documents or other reliable, independent sources; identifying the beneficial owner and taking reasonable measures to verify that identity; understanding the purpose and intended nature of the business relationship; and conducting ongoing due diligence and scrutiny of transactions.

Due diligence is required when establishing business relations, when undertaking an occasional but relevant business transaction for a customer without an existing relationship, when there is suspicion of money laundering or terrorism financing, or when there is doubt about previously obtained customer identification data.

A relevant business transaction generally means one exceeding P100,000, two or more linked transactions with an aggregate value exceeding P100,000, or — for remittance and money changing — a transaction or linked transactions exceeding P5,000.

Covered persons must adopt clear, written, graduated customer acceptance and identification policies. These should ensure the financially or socially disadvantaged are not denied access to financial services while preventing suspicious individuals or entities from opening accounts. Enhanced due diligence applies to high-risk customers; reduced due diligence may apply to low-risk ones.

Monitoring, reporting, and internal audit

Covered persons must adopt an AML/CFT monitoring system capable of generating timely, accurate, and complete reports. Universal and commercial banks, and covered persons considered complex, must adopt an electronic AML system capable of monitoring ML/TF risks and generating reports for the board and senior management. Covered persons not required to adopt an electronic system must still have the means to comply.

The internal audit function must determine the efficiency of the electronic monitoring system's functionalities where one is in place. Audit results must be communicated to the board, open to BSP examiners, and promptly shared with the compliance office to monitor corrective actions.

The AMLA also makes it a money laundering offense for a covered person who, knowing that a covered or suspicious transaction must be reported to the AMLC, fails to do so.

Frequently asked questions

What is an MLPP in the Philippines? It is the Money Laundering and Terrorist Financing Prevention Program — the written AML/CFT program that covered persons must adopt, have approved by the board, and keep available for inspection.

How often must the MLPP be updated? At least once every two years, and any revision must be approved by the board of directors.

When is customer due diligence required? When establishing business relations, when undertaking a relevant occasional transaction, when money laundering or terrorism financing is suspected, or when there is doubt about previously obtained customer identification data.

Practical takeaways

  • Adopt a written MLPP consistent with the AMLA, its RIRR, and BSP rules, tailored to your corporate structure and risk profile.
  • Secure board approval for the MLPP and every update; review it at least every two years.
  • Give the compliance office a direct reporting line to the board and assign clear AML/CFT functions.
  • Conduct and document a risk assessment covering customers, geography, products, services, and delivery channels — and assess new products before launch.
  • Apply risk-based customer due diligence, with enhanced measures for high-risk customers, and maintain monitoring and internal audit systems.

Primary sources

The rules discussed above are drawn from the following primary sources. Where the firm's library holds the document as a PDF it is embedded here in full; the rest are cited by title.

Amendments to Part Eight or the Anti-Money Laundering Regulations of the Manual of Regulations for Banks and Manual of Regulations for Non-Bank Financial InstitutionsOpen in Law LibraryDownload PDF

  • IRR of REPUBLIC ACT NO. 11930 - THE IMPLEMENTING RULES AND REGULATIONS OF REPUBLIC ACT NO. 11930, OR AN ACT PUNISHING ONLINE SEXUAL ABUSE OR EXPLOITATION OF CHILDREN, PENALIZING THE PRODUCTION, DISTRIBUTION, POSSESSION AND ACCESS OF CHILD SEXUAL ABUSE OR EXPLOITATION MATERIALS, AMENDING REPUBLIC ACT NO. 9160, OTHERWISE KNOWN AS THE "ANTI-MONEY LAUNDERING ACT OF 2001", AS AMENDED AND REPEALING REPUBLIC ACT NO. 9775, OTHERWISE KNOWN AS THE "ANTI-CHILD PORNOGRAPHY ACT OF 2009"

This article is general information and not legal advice. For your specific situation, consult a lawyer or ask ASG Legal AI.

Related reading

Have a question about this topic?

This article is general information, not legal advice. Ask ASG Legal AI for a cited, plain-language answer on your own situation — free, no sign-up.