·By Ablola, Saribong & Gueco Law Offices · researched and citation-checked against the firm's law library

BSP Open Finance Framework Explained: Circular No. 1122

The BSP Open Finance Framework under Circular No. 1122 lets customers share their financial data securely with qualified providers. Here is how it works.


The BSP Open Finance Framework is the Bangko Sentral ng Pilipinas' policy for letting customers securely share their financial data with qualified parties. It was adopted under Circular No. 1122, Series of 2021, and is incorporated into the Manual of Regulations for Banks (MORB) and the Manual of Regulations for Non-Bank Financial Institutions (MORNBFI). Its core principle: customer data is shared only with the customer's consent, and customers own their data.

What the Open Finance Framework covers

The Framework covers the technology, information, and policies that enable customers to securely share their financial data with qualified parties — either BSP-supervised financial institutions (BSFIs) or third-party providers (TPPs).

It rests on consent-driven data portability, permissioned access, interoperability, and collaborative partnerships. Under the "customers are the owners of their personal and transaction data" principle, financial information is shared only with the customer's consent and only for the products and services the customer subscribes to.

Who the participants are

The Framework defines its key players clearly:

  • Account Information Service Provider (AISP) — processes data and provides an alternative access point to multiple data sources other than payment transactions.
  • Payment Initiation Service Provider (PISP) — a registered operator of payment systems that carries out payment orders at the request of payment service users, in connection with payment accounts held at other payment service providers.
  • Third Party Providers (TPPs) — external entities such as service providers, integrators, solutions vendors, or infrastructure support that interact with BSFIs to provide services to customers. They are classified as AISP and/or PISP.
  • Open API publisher — the participant that keeps or is the custodian of customer data.
  • Third party — a participant with open access to customer-permissioned data residing in another participant (the publisher) through the Open API.
  • Fourth party — an outsourcing partner or service provider of a third party.

The five tiers of Open Finance data

The Open Finance Standards are classified into five tiers based on data sensitivity, data type, and data holder type. Tier implementations are not necessarily sequential, and multiple tiers may occur simultaneously:

  1. Tier 1 – Product and Service Information. Read-only public data such as deposit and lending rates, credit card offerings, and service charges.
  2. Tier 2 – Subscription and New Account Applications. Customer acquisition and account opening, including digital application and submission of supporting documents for deposits, loans, debit and credit cards, and other financial products.
  3. Tier 3 – Account Information. Personal financial information of authenticated customers, such as account balance, credit card outstanding balance, transaction records, credit limit change, and credit score.
  4. Tier 4 – Transactions. Payments and other financial transactions, including scheduled payments and transfers initiated by customers.
  5. Tier 5 – Others. More complex financial products or use cases not covered by Tiers 1 to 4.

Who may participate

BSFIs with a composite rating of at least "3" under the Supervisory Assessment Framework (SAFr), or its equivalent, are automatically eligible to become participants of the Open Finance Ecosystem. Those that do not meet the minimum rating must secure prior Bangko Sentral approval and comply with applicable registration requirements set by the Open Finance Oversight Committee (OFOC).

The OFOC is an industry-led, self-governing body that exercises governance over the activities and participants of the Open Finance Ecosystem, subject to the regulation and supervision of the Bangko Sentral. It adopts membership and participation rules, defines the roles of the Committee and participants, and adopts standards, agreements, policies, and guidelines (Conventions) covering registration, API specifications, authorization, disclosure, consent management, reciprocity, and consumer protection.

Consumer protection and data privacy

Participants must adopt customer awareness measures covering the safeguarding of information, use of the Open API, actual fees and charges, fair and equitable terms and conditions, and problem resolution procedures. Material risks must be disclosed in a manner that is clear, fair, and not misleading.

Each contract relating to the implementation or use of an Open API must contain a clause recognizing that customers have ownership over their data collected and processed through the transaction, and that they have all the rights enumerated under R.A. No. 10173 (Data Privacy Act of 2012). While customer and transaction data are in the custody of the Open API publisher, customers' rights to control the use of such data are limited only by the boundaries of their consent.

Customers must also be given opt-in and opt-out mechanisms, and must be periodically informed of how their data is being used and the period for which it will be used.

Compliance timeline

Under the transitory provision, all existing API arrangements prior to the issuance of the Circular must comply with its requirements within one (1) year from effectivity. In cases awaiting policy-setting or further clarifications, the compliance timetable is determined by the OFOC.

The Circular took effect fifteen (15) calendar days following its publication in the Official Gazette or any newspaper of general circulation.

Frequently asked questions

What is the BSP Open Finance Framework? It is the policy under BSP Circular No. 1122 that allows customers to securely share their financial data with BSFIs and third-party providers, based on consent, to develop innovative financial products and services.

Do I need to give consent before my data is shared? Yes. Under the Framework, customer data is shared only with the customer's consent, and customers are the owners of their personal and transaction data.

What is the OFOC in open finance? The Open Finance Oversight Committee is an industry-led, self-governing body that exercises governance over the Open Finance Ecosystem, subject to Bangko Sentral supervision.

Practical takeaways

  • The Open Finance Framework was adopted under BSP Circular No. 1122, Series of 2021, and is incorporated into the MORB and MORNBFI.
  • Data sharing is consent-driven: customers own their data and must authorize how it is used.
  • Open Finance data is classified into five tiers, from public product information to complex financial use cases.
  • BSFIs rated at least "3" under the SAFr are automatically eligible to participate; others need prior BSP approval.
  • Existing API arrangements had one year from effectivity to comply.

Primary sources

The rules discussed above are drawn from the following issuances, embedded here in full for your reference.

Open Finance FrameworkOpen in Law LibraryDownload PDF

This article is general information and not legal advice. For your specific situation, consult a lawyer or ask ASG Legal AI.

Related reading

Have a question about this topic?

This article is general information, not legal advice. Ask ASG Legal AI for a cited, plain-language answer on your own situation — free, no sign-up.