BSP Memoranda BSP Memoranda No. M-2017-031BSP Memoranda No. M-2017-031 2017-10-04T00:00:00.000+08:00

Clarification on the Deadline for Compliance with the Requirement of Circular No. 958 dated 28 April 2017

BANOKo SeNrnaL No PIUIpINAS OFFICE OF THE DEPUW GOVERNOR SUPERVISION AND EXAMINATION SECTOR MEMORANDUM NO. M-2017-!31 To : ALL BSP-SUPERVISED FINANCIAL INSTITUTIONS (BSFlsf Subject : Clarification on the Deadline for Compliance with the Requirement of Circular No. 958 dated 28 April 2017 BSP Circular No. 958 dated 28 April 2OI7 requires all concerned BSP- supervised financial institutions (BSFls) to adopt multi-factor authentication (MFA) techniques for sensitive communications and/or high risk transactions by 30 September 20L7.In this regard, the BSP reiterates that non-compliance with the aforementioned requirement shall be classified as a "serious offense" pursuant to Appendix 67 of the Manual of Regulations for Banks (MORB) which shall be subject to monetary sanctions provided under Sections/Subsection X199 and 4199Q and 4196N.9 of the MORB and Manual of Regulations for Non-Bank Financial Institutions (MORNBFI). Alternatively, non or partially compliant BSFIs should undertake the following pending full implementation of their MFA solutions within the initially committed timeline: 1. Disable functionalities used to facilitate sensitive communications and/or high risk transactions as defined in Circular No. 958; or 2. lmplement acceptable interim/compensating controls to mitigate the risk of fraud and protect cardholders. For information and compliance. ,/ o..ou" r 2oL7 i!. f',il,il:irr 51.. l.r'1aht.t 1*i].t lr'1,lnit.t. i,tirl:pi:irri:s .

Open the source record ↗

More in BSP Memoranda

Want an analysis of this document?

Ask ASG Legal AI to summarize it, compare it with other rulings, or explain how it applies to your situation — it researches from this same library.