Compliance Hub

KYC Requirements for Philippine Banks: AMLA, BSP obligations, and What Compliance Teams Need to Know in 2026

Site Logo
Tookitaki
21 Sep 2026
6 min
read

The Philippines was removed from the FATF list of jurisdictions under increased monitoring on February 21, 2025. That removal reflected improvements to the country's AML/CFT framework, but it did not reduce the underlying obligations for banks. BSP and AMLC requirements remain the operating baseline for KYC and CDD programmes.

For KYC and CDD programmes, institutions should focus on substantive verification, beneficial-owner tracing, risk-based assessment and ongoing review. These are regulatory expectations under the AMLA framework and BSP rules; claims about specific BSP examination or remediation findings should be supported by a published source rather than presented as universal findings.

This guide covers the AMLA framework, how BSP circulars translate it into operational obligations, what the three tiers of CDD require in practice, and where Philippine KYC programmes most commonly fall short.

Talk to an Expert

The legal framework: AMLA and its amendments

The Anti-Money Laundering Act (Republic Act 9160, 2001) is the foundational legislation. It has been amended by RA 9194, RA 10167, RA 10365, RA 10927 (which designated casinos as covered persons), and RA 11521 in 2021, among other related measures. The 2021 amendments expanded the framework and strengthened AMLC powers. VASPs should be described by reference to the AMLA, its implementing rules and applicable BSP registration and supervision requirements, rather than as a blanket category of BSP-registered entities.

AMLA and its implementing rules make KYC a legal obligation, not a best practice. The framework requires covered persons to establish and maintain systems for verifying customers' true identities, identifying beneficial owners and persons exercising control, understanding the purpose and intended nature of relationships, keeping records, and reporting covered and suspicious transactions to the AMLC.

For a bank-focused guide, the primary scope is BSP-supervised covered persons, including universal, commercial, thrift, rural, cooperative and digital banks, quasi-banks, trust entities and other BSP-supervised financial institutions. AMLA also covers other sectors, including money service businesses, e-money issuers, insurers, securities and investment businesses, casinos and certain other covered persons under the statute and its implementing rules. VASP coverage and supervision should be checked against the current AMLC and BSP rules applicable to the entity.

The BSP operationalises AMLA through its Manual of Regulations for Banks (MORB), circulars and related issuances. Circulars 706, 950 and 1022 are historical AML/CFT issuances, but the current consolidated MORB Part IX should be treated as the primary operational reference for banks.

BSP Circulars 706, 950, and 1022: what they require

BSP Circular 706 (2011) established an earlier AML/CFT regulatory framework for BSP-supervised institutions, including customer identification, risk management, monitoring and record-keeping requirements. Banks should consult the current MORB Part IX for the operative requirements and any subsequent amendments.

BSP Circular 950 (2017) amended Part Eight of the MORB and MORNBFI AML regulations. It should not be described as a circular specifically limited to financial-inclusion or basic-deposit products. Reduced or simplified due diligence may be available for qualifying lower-risk relationships under current rules, but it does not remove the obligation to identify customers, assess risk and apply applicable screening and monitoring controls.

BSP Circular 1022 (2018) amended the AML/CFT framework, including beneficial-owner tests, risk-based CDD and the use of information and communication technology. It allows face-to-face and/or personal-interview requirements to be supported by ICT where risks are mitigated and the process is documented. It does not prescribe a universal video-identification and real-time-liveness recipe. Current e-KYC and digital-ID requirements are risk-based and are set out in the current MORB.

When KYC must be performed

Under the current MORB, CDD is required when establishing a business relationship, undertaking a relevant occasional transaction for a non-customer, when there is suspicion, or when the institution doubts the veracity or adequacy of previously obtained identification data.

  1. Before establishing a business relationship, customer identification and verification should be completed before the relationship is established, subject to the limited risk-managed circumstances permitted by the MORB.
  2. For relevant occasional transactions: for banks, the relevant threshold is generally a transaction exceeding PHP 100,000, including linked transactions; remittance and money-changing businesses have a PHP 5,000 threshold. These thresholds are distinct from the PHP 500,000 covered-transaction reporting threshold.
  3. For wire transfers, the applicable rules require originator and beneficiary information and risk-based controls. A wire transfer does not automatically mean that a completely new CDD process must be performed for an already-identified customer.
  4. When suspicion arises, CDD obligations apply regardless of amount, subject to the rules that permit an institution not to pursue CDD where doing so would tip off the customer and an STR should instead be considered.

The inability to complete CDD to the required standard is grounds for declining to onboard a customer, not proceeding with the relevant transaction, or ending an existing relationship. The institution should also consider whether an STR is appropriate.

Three tiers of CDD

Simplified due diligence may apply to qualifying lower-risk customers and relationships, such as certain government entities or regulated financial institutions, where the risk assessment supports it. Simplified CDD does not mean no CDD: the institution must document the rationale and continue applying appropriate monitoring and controls.

Standard CDD is the baseline for all other customers. It requires:

  • Customer identification: full legal name, government-issued identification document type and number, date of birth (individuals), place of incorporation and registration number (entities)
  • Verification of identity against reliable, independent sources — not simply collecting copies of documents but confirming that the identity presented is genuine
  • Beneficial ownership identification for corporate customers (see below for the applicable threshold)
  • Documentation of the purpose and intended nature of the business relationship
  • Ongoing monitoring of the relationship against the customer's stated profile

Enhanced due diligence applies to higher-risk customers and situations. The current MORB requires risk-based enhanced measures, including the following circumstances:

  • Politically Exposed Persons (PEPs): Foreign PEP relationships require reasonable measures to establish source of wealth and source of funds, senior approval before establishing or continuing the relationship, and enhanced ongoing monitoring. Immediate family members and qualifying close associates are included in the PEP framework. Domestic and international-organisation PEPs are also assessed, with enhanced measures applied where the relationship is higher risk.
  • Non-face-to-face customers: Where identification is conducted remotely, including through digital or e-wallet channels, the institution should apply risk-based controls and additional safeguards appropriate to the digital-ID and onboarding risks.
  • High-risk jurisdictions: A connection to a jurisdiction identified by FATF or another competent authority as presenting higher risk should inform the risk assessment. EDD or proportionate countermeasures may be required, but the treatment should not be described as an automatic rule for every customer or transaction connected to a grey- or black-listed jurisdiction.
  • Transactions with no clear economic purpose or that are inconsistent with the customer's known profile should be investigated under the institution's risk-based CDD and transaction-monitoring procedures. The institution may need to apply EDD, decline or suspend the activity, and/or file an STR; EDD is not automatically a mandatory pre-processing step for every such transaction.

EDD is not satisfied by collecting additional documents. BSP examiners look for evidence that the information gathered was used in the risk assessment — generic source of wealth declarations that are not substantiated are inadequate EDD, not completed EDD.

philippines_kyc_featured_under_200kb

Beneficial ownership: the 20% threshold

The Philippine AML framework uses 20% ownership as an indication of direct or indirect ownership for beneficial-owner analysis. It is not a stand-alone rule that replaces the wider control tests. Institutions must identify natural persons who ultimately own or control the customer, including control through other means, and use the senior managing official fallback where no beneficial owner can otherwise be identified.

Where no natural person meets the ownership indication, the institution must identify the natural persons who exercise effective control through other means and, where necessary, the senior managing official. Layered ownership must be analysed through the chain; the 20% indication should not be presented as a simple cumulative mathematical test that resolves every structure.

Institutions should be able to evidence how they traced beneficial ownership through corporate chains, nominee arrangements and control relationships. Any statement that BSP examinations consistently identify a particular failure pattern should be supported by a specific published supervisory source.

Digital onboarding and eKYC

The current BSP framework permits risk-based digital identification and the use of reliable digital-ID systems, subject to appropriate identity assurance, fraud and cybersecurity controls, consent and documentation. Circular 1022 itself does not mandate a universal video-identification or real-time-liveness process. For PhilSys-based verification, banks should describe the relevant PSA/BSP service and current technical availability accurately rather than treating a particular API implementation as a permanent regulatory requirement.

The digital verification method should be documented in the CDD record, including the method used, the data or evidence relied on, the outcome and relevant timestamps. The institution remains responsible for the reliability of the process; a photograph of an ID alone may be insufficient where the risk controls do not establish identity or prevent impersonation.

For digital banks and e-money issuers, including Mynt's GCash business and BSP-licensed digital banks, eKYC is an important onboarding channel. The digital onboarding framework does not reduce the CDD obligations that apply to other onboarding methods. Any count of licensed digital banks should be stated with an as-of date because licences and institutional status can change.

AMLC reporting: CTRs, STRs, and GoTRACS

When KYC reveals or later monitoring detects reportable activity, two reporting obligations are triggered.

Currency Transaction Reports (CTRs) must be filed for covered transactions involving cash or an equivalent monetary instrument exceeding PHP 500,000 in one banking day, including linked transactions, subject to applicable AMLC rules and any deferred-reporting provisions.

Suspicious Transaction Reports (STRs) are filed based on the date the institution determines that a transaction is suspicious. Under the current BSP MORB, covered and suspicious transaction reports are generally submitted within five working days, unless the AMLC prescribes a different period within the permitted limit; the institution must generally determine suspicious status within 10 calendar days.

Both CTRs and STRs are filed through the AMLC's GoTRACS platform (Governance, Transaction Reporting, and Compliance System). GoTRACS is the mandatory reporting interface — paper or email submissions are not accepted. Institutions without automated STR and CTR generation connected to their transaction monitoring and case management systems face a manual filing burden that creates both delay risk and documentation fragmentation.

Common KYC failures in BSP examinations

Verification that stops at document collection. Institutions collect copies of government IDs but do not verify their authenticity against reliable sources. Document collection is not document verification. The BSP requirement is to verify identity against independent & reliable sources, not to file a copy.

Beneficial ownership not traced to natural persons. Corporate customers are identified at the entity level. Shareholders who are themselves companies are accepted without looking through to the ultimate individual owners. Nominee arrangements are not investigated.

EDD documentation without substantive assessment. EDD files contain sources of wealth declarations and bank statements but no evidence that the information was reviewed, assessed, or used to update the risk rating. The document exists; the assessment does not.

PEP controls should cover domestic, foreign and international-organisation PEPs, together with immediate family members and qualifying close associates. The measures and review frequency should be risk-based; avoid suggesting that every PEP automatically receives identical treatment.

Static risk profiles. Customer risk ratings are assigned at onboarding and not revisited. Customers whose transaction behaviour has changed materially since onboarding i.e. higher volumes, new counterparties, new business activities — retain their original risk rating without periodic review.

STR filing delays. Suspicion is identified during transaction monitoring or case review but is not escalated within the applicable AMLC/BSP reporting deadline. Case-management systems with deadline tracking can help reduce this risk.

How Tookitaki’s FinCense supports Philippine KYC compliance

KYC and ongoing monitoring are connected obligations — the customer risk rating established at onboarding must reflect information that transaction monitoring continuously updates. Running KYC in an onboarding system and transaction monitoring in a separate platform creates the static profile problem that BSP examiners find most frequently: the profile at onboarding does not change even as the customer's behaviour does.

FinCense connects customer risk profiling with transaction monitoring on a unified platform. Customer risk ratings are updated as transaction monitoring alerts and case findings accumulate, rather than remaining fixed at the onboarding assessment. The beneficial ownership data collected during CDD feeds directly into the screening workflow — the same customer record that holds KYC documentation holds the screening event log and the transaction monitoring history.

For institutions managing STR filing, FinCense case management can connect investigation workflows to report preparation and expose the applicable filing deadline at the investigation-record level. The institution remains responsible for filing through the AMLC's prescribed channel and for meeting the applicable legal deadline.

Book a demo to see how FinCense helps with KYC and CDD for Philippine banks, including risk rating and integration with AMLC GoTRACS reporting.

Frequently asked questions

What is the beneficial ownership threshold for Philippine banks under AMLA?

The Philippine AML framework uses 20% ownership as an indication for beneficial-owner analysis. Institutions must also assess control through other means and identify the senior managing official where no beneficial owner can otherwise be identified.

What are the STR filing deadlines under AMLA for Philippine banks?

Under the current BSP MORB, covered and suspicious transaction reports are generally filed within five working days, unless the AMLC prescribes a different period within the permitted limit. For suspicious transactions, the clock is linked to the date of determination, and the institution must generally make that determination within 10 calendar days. Cash transactions involve cash or an equivalent monetary instrument exceeding PHP 500,000 in one banking day.

Does BSP allow digital or eKYC onboarding for Philippine banks?

Yes. BSP rules permit risk-based digital identification and ICT-supported onboarding where the institution mitigates the relevant risks and documents the process.

What is the CTR & STR threshold under AMLA?

Cash transactions involve cash or an equivalent monetary instrument exceeding PHP 500,000 in one banking day, including linked transactions. Suspicious transactions have no minimum amount: a transaction may require an STR regardless of value when the statutory suspicious-transaction indicators apply.

Which BSP circulars govern KYC requirements for Philippine banks?

The current MORB Part IX is the primary operational reference for bank KYC and AML/CFT requirements. Circulars 706, 950 and 1022 remain relevant historical issuances, but they should be described accurately and read together with subsequent amendments, AMLC rules and the current MORB. The framework rests on AMLA (RA 9160), as amended, including RA 10927 and RA 11521.

Talk to an Expert

Ready to Streamline Your Anti-Financial Crime Compliance?

Our Thought Leadership Guides

Blogs
21 Sep 2026
5 min
read

The Company Was Real. The Business Wasn’t: Thailand’s Corporate Mule Account Risk

Explore AML lessons from Thailand’s corporate mule account case, where fake companies, business accounts and scam proceeds exposed money trail risks.

The Company Was Real. The Business Wasn’t: Thailand’s Corporate Mule Account Risk
Blogs
21 Sep 2026
6 min
read

KYC Requirements in New Zealand: AML/CFT Act Obligations for Banks and Reporting Entities

New Zealand AML/CFT KYC requirements for banks and reporting entities, updated for the June 2025 customer risk-rating rule, the 2026 reforms and DIA's sole-supervisor model.

KYC Requirements in New Zealand: AML/CFT Act Obligations for Banks and Reporting Entities
Blogs
15 Sep 2026
5 min
read

Ghost Cars, Fake Loans, Real Money Trails: Sydney’s AUD 95 Million Fraud Probe

Explore AML lessons from Sydney’s AUD 95 million loan-fraud probe, where ghost cars, fake documents and professional facilitation exposed money trail risks.

Ghost Cars, Fake Loans, Real Money Trails: Sydney’s AUD 95 Million Fraud Probe