BSP Regulatory Sandbox Framework: How Circular 1153 Works
BSP Circular No. 1153 institutionalized the Regulatory Sandbox Framework, letting firms test new financial products live under BSP supervision.
The Regulatory Sandbox Framework is the Bangko Sentral ng Pilipinas (BSP) program that allows firms to test new financial products or technologies in a controlled, time-bound, live environment under BSP supervision. It was institutionalized through BSP Circular No. 1153, Series of 2022, following Monetary Board Resolution No. 1217 dated 18 August 2022, and is incorporated as Section 115 of the Manual of Regulations for Banks (MORB) and the corresponding sections of the Manual of Regulations for Non-Bank Financial Institutions (MORNBFl).
The framework applies to BSP-Supervised Financial Institutions (BSFIs), third-party service providers of BSFIs, other BSP-registered institutions, and new players intending to offer or use an emerging or new technology to deliver financial products or services within the BSP's regulatory purview.
What is a regulatory sandbox under Circular 1153?
A Regulatory Sandbox is defined in the Circular as a controlled, time-bound, live testing environment, which may feature regulatory waivers at the regulator's discretion. The testing environment may involve limits or parameters within which Participants must operate.
The policy behind the framework is to foster an enabling environment for responsible innovation that promotes an inclusive digital financial ecosystem complemented by sound risk management. The BSP describes this as a "test-and-learn" approach, now institutionalized to promote a more active, evidence-based, and results-driven assessment of new and emerging financial solutions.
Importantly, the Circular is explicit that the sandbox is not intended and cannot be used to circumvent existing laws and regulations under the guise of proposing new and innovative products or services.
Who may apply, and what must the innovation show?
Applicants must meet the eligibility standards set out in the Circular. The financial solution must either:
- Use new or emerging technology, or utilize an existing technology in an innovative manner, supported by justification such as a business case or market research; or
- Bridge a market gap in the delivery of financial products or services, supported by research submitted to the BSP.
The applicant must also demonstrate capability to deploy the solution through a roll-out plan or strategy; provide an initial test plan with test case scenarios and expected outcomes; identify significant risks (including money laundering and terrorist financing, IT and cybersecurity, data integrity and data privacy, market acceptability, consumer protection, and project implementation risks) together with proposed safeguards; identify Key Performance Indicators; and provide an acceptable exit and transition strategy regardless of the outcome.
Examples of new or emerging technology cited in the Circular include artificial intelligence/machine learning, Internet-of-Things, 5G, cloud computing, robotic process/business automation, quantum computing, and decentralized ledger technologies, among others.
The four-stage sandbox process
Each regulatory sandbox undergoes a four-stage process: Application, Evaluation, Testing, and Exit.
Application Stage. Applicants submit, at a minimum, a Letter of Intent signed by the president or an officer of equivalent rank; a corporate secretary's certificate on board approval of the intent to apply; an accomplished Regulatory Sandbox Application Form; an Eligibility Self-assessment Checklist; and a Test Plan. The BSP may request additional documents.
Evaluation Stage. The BSP evaluates the documents for completeness, correctness, and suitability based on the eligibility standards. It reserves the right to reject an application on the merits. Applicants who do not meet the standards are notified of the reasons, without prejudice to filing a new application after a cooling-off period of six (6) months from release of the result.
Testing Stage. Eligible applicants, now called Participants, proceed to testing, which has two phases: the testing design phase and testing implementation. The BSP approves the test plan and issues a Letter to Proceed with the Test Implementation. Testing duration can range from 3 to 12 months from the go-live date, depending on the complexity of the proposed solution.
Exit Stage. A comprehensive evaluation takes place, and the Participant prepares a final report detailing the end-to-end results and the exit scenario, subject to BSP approval.
How long can testing run, and can it be extended?
A Participant must implement the sandbox for a period no longer than twelve (12) months from the go-live date. A Participant may request an extension or adjustment by filing at least 30 calendar days before expiration of the testing period. The proposed extension should not exceed 12 months, and no further extension is allowed after the initial request is granted, to prevent the perpetuity of sandbox experiments.
What happens after a successful test?
Participants whose sandbox activities are assessed as successful and whose products or services are deemed fit for public consumption shall be issued an authority to operate. The Participant must formally apply to operate and offer the product or service for public use, including any proposed new regulations or changes to existing regulations.
The Sandbox Oversight Team endorses the product or service for approval by the appropriate approving authorities within the BSP, and the requirements and processing timelines for an authority to offer Electronic Products and Financial Services apply. Despite a successful sandbox test, the approving authorities reserve the right to approve or disapprove the proposed product or service.
Consumer protection and data privacy
Participants must adopt measures to protect consumers. Customers should be informed that the product or service is under the regulatory sandbox platform and that their availment is part of the pilot implementation, and they should be informed of all possible risks. Customers must also be informed of complaints handling and dispute resolution procedures.
On data privacy, all sandbox experimentation must follow the rules on data sharing, data privacy, and data protection in all implementation phases. Customers should be informed that they own the data collected and processed through the transaction and that they have all the rights enumerated under Philippine data privacy laws, known as Republic Act 10173 or the Data Privacy Act of 2012.
Frequently asked questions
Who can join the BSP regulatory sandbox? BSFIs, third-party service providers of BSFIs, other BSP-registered institutions, and new players that intend to offer or use an emerging or new technology to deliver financial products or services within the BSP's regulatory purview.
How long is the BSP sandbox testing period? Testing can range from 3 to 12 months from the go-live date, depending on the complexity of the proposed solution, with a possible extension of up to 12 months subject to BSP approval.
What is the "regulatory sandbox lite"? It is a simplified approach the BSP may advise applicants to use. It is generally shorter than the entire regulatory sandbox process and is limited to BSFIs, to encourage digitalization or participation in the electronic offering or delivery of financial products or services already within the scope of existing regulations.
Practical takeaways
- The Regulatory Sandbox Framework is institutionalized under BSP Circular No. 1153, Series of 2022, as Section 115 of the MORB and the corresponding MORNBFl sections.
- A sandbox is a controlled, time-bound, live testing environment that may involve regulatory waivers at the BSP's discretion.
- Applicants must show an innovative or gap-bridging solution, a roll-out plan, a test plan, risk identification with safeguards, KPIs, and an exit strategy.
- Testing runs no longer than 12 months from go-live, with a possible extension of up to 12 months, and no further extension after that.
- The sandbox cannot be used to circumvent existing laws and regulations.
Primary sources
The rules discussed above are drawn from the following issuances, embedded here in full for your reference.
Regulatory Sandbox FrameworkOpen in Law LibraryDownload PDF
This article is general information and not legal advice. For your specific situation, consult a lawyer or ask ASG Legal AI.
Related reading
VASP license Philippines requirements explained: secure a BSP Certificate of Authority as a money service business, meet capital rules, and comply with Circular 1108.
Foreign exchange rules for foreign investors in the Philippines: BSP registration, reporting deadlines, and penalties under Circular No. 1197 explained.
AMLC registration in the Philippines applies to banks, pawnshops, money changers, e-money issuers and other covered persons. Know if your business must register.
A quasi-banking license in the Philippines allows a non-bank to borrow funds from the public. Learn who qualifies, what the BSP requires, and what happens on failure.
Have a question about this topic?
This article is general information, not legal advice. Ask ASG Legal AI for a cited, plain-language answer on your own situation — free, no sign-up.