Compliance Hub

Fraud Prevention for Philippine Banks: AFASA, BSP Requirements and What They Mean in Practice

Site Logo
Tookitaki
28 Aug 2026
5 min
read

The one-year transition period under BSP Circular 1213 expired on 30 June 2026. Bangko Sentral-supervised financial institutions (BSFIs) are therefore expected to comply with enhanced standards covering real-time fraud monitoring, authentication, device security, customer controls and transaction records.

The circular does not impose a blanket ban on one-time passwords sent by SMS or email. It requires BSFIs to limit the use of authentication mechanisms that can be shared with or intercepted by third parties. Institutions offering complex electronic payment and financial services and processing an average monthly network transaction value of at least PHP 75 million over the preceding six months must adopt stronger authentication mechanisms.

The legal framework behind these requirements is Republic Act No. 12010, the Anti-Financial Account Scamming Act (AFASA). Approved on 20 July 2024, AFASA defines and penalises money-mule activity, specified social-engineering schemes and related offences. It also makes adequate fraud controls, coordinated verification and the preservation of disputed funds direct responsibilities for institutions under BSP supervision.

For compliance, fraud, technology and operations teams, the important question is not simply whether an institution has a fraud tool. It is whether its controls can identify and block suspicious activity in real time, support stronger authentication, preserve disputed funds when the regulatory grounds are met and produce an auditable response across the payment chain.

Talk to an Expert

The fraud problem AFASA was written to address

Fraud in the Philippines increasingly combines human manipulation with the speed and reach of digital financial services. Data presented by BSP Deputy Governor indicated that social engineering, account takeover and identity theft collectively accounted for 76% of reported cyber-fraud losses in 2025.

Separately, Tookitaki and the AFC Ecosystem's 2024 Philippines Financial Crime Landscape Report recorded more than 3,000 account-takeover incidents associated with approximately PHP 409 million in reported losses.

Mobile wallets and instant-payment infrastructure increase both the scale and speed at which fraud can move. GCash reported 39.1 million monthly active users in 2025, while InstaPay enables Philippine-peso transfers between participating institutions almost immediately, 24 hours a day. BSP describes funds transferred through InstaPay as being credited almost immediately and with finality. This narrows the time available to detect fraud and preserve recoverable funds.

Investment scams have also targeted Overseas Filipino Workers and other digitally active consumers, often through prolonged social engineering. However, not every investment scam automatically falls within AFASA's statutory definition of a social-engineering scheme. Under AFASA, that offence involves obtaining sensitive identifying information through deception or fraud, resulting in unauthorised access and control over a person's financial account.

AFASA and the three BSP implementing circulars

AFASA establishes the statutory framework. It requires institutions to protect access to financial accounts through adequate, proportionate risk-management systems and controls, including multi-factor authentication, fraud management systems and account-owner enrolment and verification processes. It also establishes rules on restitution, temporary holding of disputed funds, coordinated verification and BSP inquiry into financial accounts.

BSP Circular 1213: fraud monitoring, authentication and customer controls

Circular 1213 implements the information-technology-risk-management provisions of AFASA. It requires automated and real-time fraud monitoring and detection systems capable of identifying and blocking disputed, suspicious or fraudulent online transactions.

For BSFIs that both offer complex electronic payment and financial services and meet the PHP 75 million average monthly network-value threshold, the circular requires a robust FMS incorporating:

  • Transaction-velocity checks and risk-based thresholds
  • Monitoring of mobile-device and account-information changes
  • Geolocation monitoring
  • Blacklist screening involving unsecure merchants, devices and IP addresses
  • Detection of behavioural and collective transactional anomalies

The circular also requires or addresses strong device fingerprinting, a transaction-pause period following key account changes, restrictions on unsecured devices and unauthorised automation tools, descriptive transaction notifications, payee-verification mechanisms, a customer-controlled kill switch, revocation of third-party access, a money-lock feature, configurable transaction limits and detailed transaction-log retention for at least five years.

On authentication, all BSFIs must limit the use of interceptable mechanisms such as OTPs sent by SMS or email. Covered BSFIs meeting the complex-service and transaction-value conditions must use strong authentication mechanisms such as biometric or behavioural-biometric authentication, passwordless authentication or adaptive authentication.

BSP Circular 1214: inquiry into financial accounts

Circular 1214 sets out the procedures through which the BSP's Consumer Account Protection Office (CAPO) may inquire into financial accounts that may have been involved in an AFASA prohibited act. For qualifying inquiries, specified bank-secrecy, foreign-currency-deposit, non-stock-savings-and-loan and data-privacy restrictions do not apply.

This authority is not unrestricted. CAPO must follow the prescribed process and determine that sufficient grounds support a well-founded belief that a prohibited act has been committed and that the account may have been involved. An institution receiving an inquiry order must comply with the order and submit the required account information and supporting records within the prescribed period.

BSP Circular 1215: temporary holding and coordinated verification

Circular 1215 governs electronic fund transfers that meet the definition of a disputed transaction. A dispute may arise from an account-owner complaint, information received from another institution or detection by an institution's FMS, provided there are reasonable grounds under AFASA and the BSP rules.

A qualifying disputed amount may initially be held for up to five calendar days and, where the prescribed conditions are met, for up to 25 additional calendar days. The total regulatory holding period therefore cannot exceed 30 calendar days unless extended by a competent court. Improperly holding funds or retaining them beyond the permitted period can also expose an institution to regulatory action.

The coordinated-verification process involves the relevant originating institution, receiving institution, subsequent receiving institutions, payment-system participants, account owners and other parties specified in the applicable protocol. Verification must continue even where the funds have already left the banking system. Institutions therefore need the operational capability to receive requests, trace transaction chains, preserve available funds, communicate with other participants and document their decisions.

afasa_compliance_featured_under_200kb

Institutional liability and customer restitution under AFASA

AFASA makes fraud prevention a potential financial liability, but it does not establish automatic reimbursement for every fraud complaint. An institution may be liable to restore funds where it fails to employ adequate risk-management systems and controls or fails to exercise the highest degree of diligence in preventing loss or damage arising from the offences covered by AFASA. A criminal conviction is not required before restitution can be ordered.

The Act also provides a statutory safe harbour: an institution determined by the BSP to be compliant with the requirements for adequate risk-management systems and controls is not liable for loss or damage arising from the offences specified in Sections 4 and 5 of AFASA. This is a BSP compliance determination, not a protection that an institution can simply claim through self-certification.

Separately, an institution that fails to hold disputed funds when required under AFASA and the applicable BSP rules may be liable for loss or damage arising from that failure, including restitution of the disputed amount. Liability therefore depends on the applicable facts, regulatory duties, institutional conduct and the connection between a control failure and the loss.

What an effective fraud programme looks like under AFASA

Real-time detection in the payment flow. A compliant FMS must be automated and real time, with the ability to identify and block suspect online transactions. For instant-payment use cases, institutions should integrate fraud evaluation early enough in the payment flow to intervene before suspicious funds are released, while aligning the design with their payment architecture and applicable scheme rules.

Risk-based strong authentication. Circular 1213 does not require identical friction for every customer action. Adaptive authentication can adjust the challenge using signals such as the device, location, behaviour, transaction value and beneficiary. Higher-risk activity can trigger additional verification while routine activity receives a proportionate experience.

Device and account-change intelligence. Device fingerprinting and monitoring of changes to mobile numbers, email addresses and registered devices can identify account-takeover risk. A device change associated with a SIM swap may contribute a useful risk signal, but device fingerprinting alone does not prove that a SIM swap has occurred.

Customer-controlled safeguards. Kill switches, money locks, access revocation and configurable transaction limits give customers practical ways to reduce exposure. These controls must be supported by proper authentication, clear communication and operational processes for restoring access.

Coordinated disputed-transaction response. Institutions need more than a customer-service process for sending complaints. They also need a receive-side process for incoming hold and verification requests, transaction-chain tracing, time-bound decision-making, communication with other institutions and complete audit trails.

Mule-account detection. Indicators such as multiple unrelated inflows followed by rapid aggregation or onward transfer can often be detected from activity within an account. Cross-account, counterparty and network analysis strengthens this capability by revealing clusters, shared beneficiaries and movement across multiple accounts or institutions.

Connected fraud and AML intelligence. Mule accounts, account takeover and movement of scam proceeds can generate both fraud and money-laundering risk. Connecting fraud and AML data, scenarios and investigations can reduce blind spots, although AFASA does not itself require institutions to operate fraud and AML on a single technology platform.

Fraud programme gaps institutions should test

Rather than treating the following as confirmed findings across the industry, institutions can use them as review questions when assessing operational readiness:

  • Is the institution still relying heavily on interceptable SMS or email OTPs for higher-risk activity without adequate compensating controls?
  • Does the FMS evaluate and block suspicious online transactions in real time, or does part of the process still depend on post-transaction batch review?
  • Are all five required FMS mechanisms implemented where the complex-service and PHP 75 million threshold conditions apply?
  • Can the institution receive and act on temporary-hold and verification requests from other institutions within the prescribed timeframes?
  • Are kill-switch, money-lock, access-revocation and configurable-limit functions operational and adequately authenticated?
  • Can fraud and AML investigators connect mule activity, account takeover, suspicious transaction patterns and related cases across customers and counterparties?
  • Are FMS calibration, stress testing, independent review, audit trails and five-year transaction-log retention demonstrable to supervisors?

How Tookitaki’s FinCense can support AFASA-aligned fraud prevention

FinCense brings fraud detection and AML transaction monitoring onto a shared detection and investigation platform. It draws on intelligence from the Anti-Financial Crime (AFC) Ecosystem, a regional community of financial institutions and financial-crime specialists contributing typologies, risk indicators and emerging-threat insights.

Where FinCense is integrated into an institution's payment flow, its fraud-monitoring capabilities can evaluate transaction activity in real time using rules, behavioural patterns, customer context and typology-based indicators. Automated Threshold Tuning can help calibrate thresholds to customer segments and transaction behaviour. Tookitaki deployments have achieved false-positive reductions of up to 70% in specific implementations; actual results depend on the institution's data, controls and operating environment.

FinCense Case Manager can support internal investigation, escalation and audit-trail requirements associated with disputed transactions. End-to-end compliance with Circular 1215 may also require integration with payment systems, fund-hold controls, inter-institutional communication processes and BSP reporting workflows.

FinCense can therefore support important elements of an AFASA-aligned fraud programme, but deploying any technology platform does not by itself establish regulatory compliance or confer AFASA's statutory liability protection. Compliance depends on the institution's complete control environment, governance, procedures, integrations and operational performance.

For a detailed explanation of how fraud and AML monitoring can operate through a connected detection environment, see Tookitaki's FRAML guide.

Book a demo to explore how FinCense can support real-time fraud monitoring, mule-account detection and connected fraud and AML investigations for Philippine financial institutions.

Frequently asked questions

What is AFASA?

AFASA is Republic Act No. 12010, the Anti-Financial Account Scamming Act. It defines and penalises money-mule activities, specified social-engineering schemes and related offences. It also requires BSP-supervised institutions to maintain adequate and proportionate controls, establishes temporary-hold and coordinated-verification mechanisms and sets out circumstances in which institutions may be liable for restitution.

What did BSP Circular 1213 require and when was the deadline?

Circular 1213 strengthened BSP's technology-risk rules for electronic financial services. It requires automated and real-time fraud monitoring, stronger device and account protections, customer-control features, transaction records and a shared-accountability framework. Its one-year transition period expired on 30 June 2026. The circular limits the use of SMS and email OTPs; it does not impose a universal blanket prohibition on them.

Which institutions are subject to the enhanced FMS mechanisms?

The detailed robust-FMS requirements apply to BSFIs that offer complex electronic payment and financial services and handle an average monthly network transaction value of at least PHP 75 million over the preceding six months. Other requirements in Circular 1213 have broader application across BSFIs and relevant payment-system operators.

What does BSP Circular 1215 require?

Circular 1215 establishes procedures for temporarily holding qualifying disputed funds and conducting coordinated verification across the relevant institutions and account owners. An initial hold may last up to five calendar days, with a possible extension of up to 25 additional days. The process includes transaction tracing and verification even where the disputed funds have already left the banking system.

Does AFASA require banks to compensate every fraud victim?

No. AFASA does not create automatic reimbursement for every fraud claim. It provides for restitution where an institution fails to employ adequate controls, fails to exercise the highest degree of diligence or fails to hold disputed funds when required, subject to the facts and applicable BSP rules. Institutions determined by the BSP to have adequate and compliant controls receive the statutory protection described in Section 6 of AFASA.

Why does InstaPay make real-time fraud prevention important?

InstaPay makes funds available to recipients almost immediately and with finality, reducing the time available to identify fraud and preserve funds. Real-time monitoring and rapid coordinated response improve the likelihood that suspicious activity can be stopped or investigated before the proceeds are moved through additional accounts.

Talk to an Expert

Ready to Streamline Your Anti-Financial Crime Compliance?

Our Thought Leadership Guides

Blogs
24 Aug 2026
5 min
read

Pawned Condos, Hidden Money Trails: The AML Risk Behind Pasay’s Sangla-Kolekta Scam

Explore AML lessons from Pasay’s sangla-kolekta condo scam, where fake property claims exposed risks around victim funds, cash collection and mule accounts.

Pawned Condos, Hidden Money Trails: The AML Risk Behind Pasay’s Sangla-Kolekta Scam
Blogs
21 Aug 2026
6 min
read

Sanctions Screening in New Zealand: Legal Requirements and Good Practices for Financial Institutions

Understand sanctions screening requirements in New Zealand, including UN sanctions, the Russia Sanctions Act 2022, DIA supervision, screening obligations and good practices for financial institutions.

Sanctions Screening in New Zealand: Legal Requirements and Good Practices for Financial Institutions
Blogs
21 Aug 2026
7 min
read

Sanctions Screening in the Philippines: BSP and AMLC Requirements

Understand sanctions screening requirements in the Philippines, including BSP and AMLC rules, targeted financial sanctions, re-screening, freeze obligations, reporting, and good practices for financial institutions.

Sanctions Screening in the Philippines: BSP and AMLC Requirements