·By Ablola, Saribong & Gueco Law Offices · researched and citation-checked against the firm's law library

Open Finance Framework Philippines: What BSP Circular 1122 Requires

The Open Finance Framework in the Philippines lets customers share their financial data with qualified providers under BSP Circular No. 1122. Here is how it works.


The Open Finance Framework is the Bangko Sentral ng Pilipinas (BSP) policy that lets customers securely share their financial data with qualified parties. Adopted under BSP Circular No. 1122, Series of 2021, it is incorporated as Section 154 of the Manual of Regulations for Banks (MORB) and the corresponding sections of the Manual of Regulations for Non-Bank Financial Institutions (MORNBFI). Its core principle is consent: customer information is shared only with the customer's permission. The framework covers banks, other BSP-supervised financial institutions (BSFIs), and third-party providers (TPPs).

What open finance means under the framework

The circular defines Open Finance as the leveraging and sharing of customer-permissioned data among banks, other financial institutions, and TPPs to develop innovative financial solutions, promote greater transparency, and provide cross-selling opportunities.

The framework espouses consent-driven data portability, permissioned-access interoperability, and collaborative partnerships among financial institutions and TPPs. The "customers are the owners of their personal and financial information" principle applies: data is shared only with the customer's consent and only for products and services to which the customer subscribes.

"Customer-permissioned data" refers to data held by participants — such as transactions, personal identification data, and customer financial history — that the customer permits a third party to access, and which may be shared onward with fourth parties if covered by the customer's consent.

Who the framework covers

The framework covers the technology, information, and policies that enable customers to securely share financial data with qualified parties — either BSFIs or TPPs.

TPPs are external legal entities such as service providers, integrators, solutions vendors, and infrastructure support that interact with BSFIs to provide services to customers. They are classified as either an Account Information Service Provider (AISP) or a Payment Initiation Service Provider (PISP), though the Open Finance Oversight Committee (OFOC) may create other classifications.

An AISP processes data and provides an alternative access point to multiple sources of data other than payment transactions. A PISP is a registered operator of payment systems that carries out payment orders at the request of payment service users in connection with payment accounts held at other payment service providers.

Registration: who can participate

BSFIs with a composite rating of at least "3" under the Supervisory Assessment Framework (SAF), or its equivalent, are automatically eligible to become participants of the Open Finance Ecosystem. Those that do not meet the minimum rating must secure prior BSP approval and comply with applicable registration requirements set by the OFOC.

Participants not under BSP regulation and supervision are responsible for ensuring that their fourth parties comply with applicable laws, rules, and regulations.

The OFOC and the tiered standards

The BSP recognizes an Open Finance Oversight Committee (OFOC), an industry-led, self-governing body that exercises governance over the activities and participants of the ecosystem, subject to BSP regulation and supervision. The OFOC adopts membership rules, defines roles and responsibilities, and adopts standards, agreements, policies, and guidelines (Conventions) covering onboarding, API documentation, authorization, consent management, reciprocity, and consumer protection.

The OFOC issues Open Finance Standards, which are classified into five tiers based on data sensitivity, data type, and data holder type:

  • Tier 1 – Product and Service Information: read-only public data such as deposit and lending rates, credit card offerings, and service charges.
  • Tier 2 – Subscription and New Account Applications: customer acquisition, account opening, and digital application processes.
  • Tier 3 – Account Information: authenticated customer data such as account balance, credit card outstanding balance, transaction records, and credit score.
  • Tier 4 – Transactions: payments and other financial transactions initiated by customers.
  • Tier 5 – Others: more complex financial products or use cases not covered by Tiers 1 to 4.

Tier implementations are not necessarily sequential, and multiple tiers may be implemented simultaneously.

Consumer protection and data privacy

Participants must adopt customer awareness measures covering the safeguarding of information, use of the Open API, actual fees and charges, fair and equitable terms and conditions, and problem resolution procedures. Material risks must be disclosed clearly, fairly, and not misleadingly.

Every contract relating to the implementation or use of an Open API must contain a clause recognizing that customers have ownership over their data and all rights under Republic Act No. 10173 (Data Privacy Act of 2012). Participants must also maintain a prompt and effective dispute mechanism and provide opt-in and opt-out mechanisms so customers can withdraw or modify consent.

Frequently asked questions

Is open finance mandatory for banks in the Philippines? The framework sets standards for participants that intend to provide Open Access. BSFIs meeting the minimum SAF composite rating are automatically eligible to participate, while those below it must secure prior BSP approval.

What is the difference between an AISP and a PISP? An AISP provides an alternative access point to multiple sources of data other than payment transactions. A PISP carries out payment orders at the request of payment service users in connection with payment accounts held at other payment service providers.

Can customers withdraw their consent? Yes. Proper mechanisms must be in place to ensure customers are informed and can withdraw or modify the scope of their consent, with opt-in and opt-out mechanisms available at all times.

Practical takeaways

  • Open finance in the Philippines rests on consent: customer data is shared only with permission and only for subscribed products and services.
  • BSP Circular No. 1122 governs the framework, incorporated into the MORB and MORNBFI.
  • Participation depends on supervisory rating; BSFIs rated at least "3" under the SAF are automatically eligible.
  • Standards are tiered from public product information (Tier 1) to complex use cases (Tier 5).
  • Contracts involving Open APIs must recognize customer ownership and rights under the Data Privacy Act of 2012.

Primary sources

The rules discussed above are drawn from the following primary sources. Where the firm's library holds the document as a PDF it is embedded here in full; the rest are cited by title.

Open Finance FrameworkOpen in Law LibraryDownload PDF

  • REPUBLIC ACT NO. 11127 - AN ACT PROVIDING FOR THE REGULATION AND SUPERVISION OF PAYMENT SYSTEMS

This article is general information and not legal advice. For your specific situation, consult a lawyer or ask ASG Legal AI.

This topic sits within our Data Privacy & Cybersecurity practice.

Related reading

Have a question about this topic?

This article is general information, not legal advice. Ask ASG Legal AI for a cited, plain-language answer on your own situation — free, no sign-up.