BSP Anti-Money Laundering Regulations for Covered Institutions
Learn which institutions the BSP anti-money laundering regulations cover, their AML duties, and key rules under BSP Circular No. 950.
The BSP anti-money laundering regulations apply to all covered persons supervised and regulated by the Bangko Sentral ng Pilipinas (BSP). Under BSP Circular No. 950, these include banks, non-banks, quasi-banks (QBs), trust entities, non-stock savings and loan associations, pawnshops, foreign exchange dealers, money changers, remittance and transfer companies, electronic money issuers, and other financial institutions subject to BSP supervision under special laws — plus their subsidiaries and affiliates that are themselves covered persons, wherever located. Covered persons must adopt a written Money Laundering and Terrorist Financing Prevention Program (MLPP), conduct customer due diligence, monitor transactions, and report covered and suspicious transactions to the Anti-Money Laundering Council (AMLC).
Who counts as a covered person under BSP Circular No. 950
Section X802/4802Q of the BSP's AML regulations defines covered persons to include banks, non-banks, QBs, trust entities, non-stock savings and loan associations, pawnshops, foreign exchange dealers, money changers, remittance and transfer companies, electronic money issuers, and other financial institutions which under special laws are subject to BSP supervision and/or regulation.
The definition extends to subsidiaries and affiliates that are also covered persons, wherever they may be located. A subsidiary is an entity more than fifty percent (50%) of the outstanding voting stock of which is owned by a covered person. An affiliate is an entity at least twenty percent (20%) to not more than fifty percent (50%) of the voting stock of which is owned by a covered person.
If a covered person's branch, office, subsidiary, or affiliate based outside the Philippines is prohibited by local laws, regulations, or a supervisory directive from implementing the AML rules, it must formally notify the BSP, furnish a copy of the applicable law or directive, and apply additional measures or mitigating controls to manage money laundering and terrorist financing risks.
The policy behind the BSP AML framework
Section X801/4801Q sets out the declared policy. The BSP adopts the State's policies to protect the integrity and confidentiality of bank accounts and to ensure that the Philippines, and covered persons in particular, are not used as a money laundering site or conduit for the proceeds of an unlawful activity. The same provision expresses the policy to protect life, liberty, and property from acts of terrorism and to reinforce the fight against terrorism by criminalizing the financing of terrorism and related offenses.
Key definitions: covered transactions, suspicious transactions, and more
BSP Circular No. 950 defines the terms that drive compliance obligations.
A covered transaction (CT) is a transaction in cash or other equivalent monetary instrument exceeding five hundred thousand pesos (P500,000).
A suspicious transaction (ST) is a transaction with a covered person, regardless of the amount involved, where any of several circumstances exists. These include: no underlying legal or trade obligation, purpose, or economic justification; the client is not properly identified; the amount is not commensurate with the client's business or financial capacity; the transaction appears structured to avoid reporting requirements; the transaction deviates from the client's profile or past transactions; the transaction relates to an unlawful activity or money laundering offense; or any similar, analogous, or identical transaction. An unsuccessful attempt to transact, denied on any of these grounds, is likewise a suspicious transaction.
Money laundering is committed by any person who, knowing that a monetary instrument or property represents, involves, or relates to the proceeds of an unlawful activity, transacts, converts, transfers, disposes of, moves, acquires, possesses, or uses it; conceals or disguises its true nature, source, location, disposition, movement, or ownership; attempts or conspires to commit these acts; aids, abets, assists in, or counsels their commission; or performs or fails to perform any act that facilitates the offense. A covered person also commits money laundering if it knows a covered or suspicious transaction must be reported to the AMLC and fails to do so.
Risk management and the MLPP
Under Section X805/4805Q, all covered persons must develop sound risk management to address risks associated with money laundering and terrorist financing, such as reputational, operational, and compliance risks.
The board of directors bears oversight of the covered person's AML/CFT compliance management. Senior management oversees day-to-day management, ensures effective implementation of AML/CFT policies approved by the board, and establishes a structure that promotes accountability and transparency.
The compliance office manages the implementation of the MLPP and must have a direct reporting line to the board of directors or a board-level committee on AML and terrorist financing compliance matters. Its functions include ensuring compliance by officers and employees, correcting infractions found in audits or BSP examinations, informing staff of BSP and AMLC issuances, alerting senior management and the board to AML/CFT issues, and organizing AML training.
Every covered person must adopt a written MLPP consistent with the AMLA, its Revised Implementing Rules and Regulations, and the BSP rules, designed according to its corporate structure and risk profile. Where a covered person has branches, subsidiaries, affiliates, or offices within and/or outside the Philippines, a consolidated ML/TF risk management system applies on a group-wide basis.
Within six (6) months from effectivity of the amendments, covered persons were required to prepare and have available for inspection an updated MLPP approved by the board of directors. Each MLPP must thereafter be regularly updated at least once every two (2) years, with any revision approved by the board of directors or the country/regional head or its equivalent for local branches of foreign banks.
Customer due diligence and risk assessment
Section X806/4806Q requires a risk-based approach to customer due diligence (CDD) depending on the type of customer, business relationship, or nature of the product, transaction, or activity. CDD includes identifying and verifying the customer's true identity based on official documents or other reliable, independent sources; identifying the beneficial owner and taking reasonable measures to verify that identity; understanding the purpose and intended nature of the business relationship; and conducting ongoing due diligence on the relationship.
CDD must be undertaken when the covered person establishes business relations with a customer, undertakes an occasional but relevant business transaction for a customer without an existing relationship, suspects money laundering or terrorism financing, or doubts the veracity or adequacy of previously obtained customer identification data.
A relevant business transaction is one with a value exceeding P100,000, except money changing or remittance transactions; two or more linked transactions with an aggregate value exceeding P100,000; or, for remittance and money changing transactions, any transaction or linked transactions with an aggregate value exceeding P5,000.
Covered persons must maintain clear, written, and graduated customer acceptance and identification policies, with reduced CDD for low-risk clients and enhanced CDD for higher-risk accounts. Enhanced due diligence (EDD) applies to high-risk customers and requires additional customer information, validation procedures, senior management approval to commence or continue the relationship, enhanced ongoing monitoring, and, where applicable, a first payment through an account in the customer's name with a bank subject to similar CDD standards. If additional information cannot be obtained, or information is false or falsified, or validation is unsatisfactory, the covered person must deny the banking relationship, without prejudice to reporting a suspicious transaction to the AMLC.
Covered persons must also identify, understand, and assess their ML/TF risks arising from customers, countries or geographic areas, products, services, transactions, or delivery channels. The risk assessment must consider all relevant risk factors, document results and findings, and be updated periodically or as necessary, and must be made available to the BSP during examination.
Frequently asked questions
Who are covered persons under the BSP anti-money laundering regulations? They are banks, non-banks, QBs, trust entities, non-stock savings and loan associations, pawnshops, foreign exchange dealers, money changers, remittance and transfer companies, electronic money issuers, and other financial institutions subject to BSP supervision under special laws, including their subsidiaries and affiliates that are also covered persons.
What is a covered transaction under BSP rules? A covered transaction is a transaction in cash or other equivalent monetary instrument exceeding five hundred thousand pesos (P500,000).
What is the threshold for customer due diligence on occasional transactions? A relevant business transaction generally means one exceeding P100,000, or linked transactions aggregating more than P100,000. For remittance and money changing transactions, the threshold is an aggregate value exceeding P5,000.
Practical takeaways
- Know your category. Covered persons include a wide range of BSP-supervised institutions and their covered subsidiaries and affiliates, wherever located.
- Maintain a written MLPP. It must be board-approved, consistent with the AMLA and its RIRR, and updated at least once every two (2) years.
- Apply risk-based CDD. Use reduced, average, or enhanced due diligence depending on the customer's risk profile, and document how each customer was profiled.
- Watch the thresholds. Covered transactions exceed P500,000; relevant business transactions generally exceed P100,000, or P5,000 for remittance and money changing.
- Report and correct. Suspicious transactions must be reported to the AMLC regardless of amount, and deficiencies found in audits or BSP examinations must be immediately corrected.
Primary sources
The rules discussed above are drawn from the following issuances, embedded here in full for your reference.
Amendments to Part Eight or the Anti-Money Laundering Regulations of the Manual of Regulations for Banks and Manual of Regulations for Non-Bank Financial InstitutionsOpen in Law LibraryDownload PDF
This article is general information and not legal advice. For your specific situation, consult a lawyer or ask ASG Legal AI.
Related reading
Vendor due diligence in the Philippines helps companies screen third parties for corporate, anti-money laundering, and child-safety risks before onboarding.
How BSP Circular 1105 and Circular 1154 govern digital bank licensing in the Philippines, from the P1.0 billion capital rule to the application process.
Building an anti-money laundering compliance program in the Philippines? Learn the required MLPP, risk assessment, and due diligence rules.
Learn AML compliance requirements for Philippine gaming operators, including PAGCOR rules and RA 11930 reporting duties under the AMLA.
Have a question about this topic?
This article is general information, not legal advice. Ask ASG Legal AI for a cited, plain-language answer on your own situation — free, no sign-up.