Sanctions Screening in the Philippines: BSP and AMLC Requirements
When the Philippines exited the FATF grey list in February 2025, targeted financial sanctions were part of the story.
Among the improvements recognised by the Financial Action Task Force (FATF) was the Philippines' work to strengthen the effectiveness of its targeted financial sanctions (TFS) framework for both terrorist financing (TF) and proliferation financing (PF).
For Philippine financial institutions, this means sanctions screening should not be viewed simply as a watchlist check performed during customer onboarding. BSP-supervised financial institutions are expected to maintain controls capable of identifying designated persons and entities, screening existing customers when new designations are issued, and implementing applicable targeted financial sanctions without delay.
The distinction between the legal requirement and the technology used to meet it is important. Philippine rules prescribe outcomes such as screening relevant parties, implementing applicable sanctions without delay and reporting target matches. Institutions then need controls proportionate to their business, customer base and transaction volumes to achieve those outcomes effectively.
This guide explains the current Philippine sanctions screening framework, what BSP-supervised institutions are expected to screen, what "freeze without delay" means operationally, how reporting to the Anti-Money Laundering Council (AMLC) works, and the good practices institutions can adopt to build an effective sanctions programme.

The Philippine Targeted Financial Sanctions Framework
Targeted financial sanctions in the Philippines primarily address terrorism, terrorist financing and proliferation financing.
For BSP-supervised financial institutions, the starting point is understanding which designations must be reflected in their sanctions controls.
UN Security Council Designations
Philippine institutions must account for applicable United Nations Security Council designations relating to terrorism, terrorist financing and proliferation financing.
These include relevant designations under UN sanctions regimes covering terrorist organisations and individuals, as well as proliferation-related sanctions involving jurisdictions such as the Democratic People's Republic of Korea (DPRK).
UN designations can change at any time. This creates an important operational requirement: sanctions databases and existing customer records need to be updated and screened when new designations are published.
BSP guidance states that relevant designations must be incorporated into institutions' sanctions databases without delay.
Anti-Terrorism Council Designations
The Anti-Terrorism Act of 2020 established a domestic designation mechanism through the Anti-Terrorism Council (ATC).
Individuals, organisations, associations or groups designated under the applicable Philippine framework may become subject to targeted financial sanctions.
BSP-supervised institutions therefore need to ensure that relevant ATC designations are included in their sanctions screening controls.
Court of Appeals Proscription
Philippine institutions must also account for persons and organisations proscribed through the applicable Court of Appeals process.
Together with applicable UNSC and ATC designations, these form part of the minimum targeted financial sanctions coverage expected of BSP-supervised financial institutions.
What About OFAC, EU and Other International Sanctions Lists?
Sanctions imposed by foreign jurisdictions should be distinguished from mandatory Philippine targeted financial sanctions.
BSP guidance allows supervised financial institutions to include foreign or supranational sanctions designations—such as those maintained by the US Office of Foreign Assets Control (OFAC) or the European Union—based on the results of their sanctions risk assessment.
For example, an institution with significant US-dollar payment activity, US correspondent banking relationships or international counterparties may determine that OFAC screening is necessary as part of its broader sanctions risk management framework.
Similarly, institutions with meaningful European exposure may determine that EU or UK sanctions should form part of their screening coverage.
The important distinction is:
Applicable Philippine TFS designations are mandatory. Additional foreign sanctions coverage should reflect the institution's legal, correspondent banking, geographic and sanctions-risk exposure.
TFS Is Rule-Based; Supporting Controls Are Risk-Based
An important principle in the Philippine framework is that implementation of applicable targeted financial sanctions is rule-based rather than optional based on risk appetite.
An institution cannot decide not to apply an applicable targeted financial sanction because a customer or transaction has otherwise been assessed as low risk.
Where a relevant designation applies, the sanction must be implemented.
Risk assessment instead helps determine how institutions design the controls surrounding this obligation—including screening architecture, matching thresholds, transaction controls, governance, escalation procedures and monitoring.
This distinction is important when designing a sanctions programme:
The obligation to implement applicable TFS is rule-based. The controls used to manage sanctions exposure should be calibrated to risk.
BSP Requirements for Sanctions Screening
BSP guidance is relatively specific about who should be screened.
At a minimum, BSP-supervised financial institutions should conduct sanctions screening on relevant information concerning:
- customers;
- customer names and aliases;
- beneficial owners;
- persons acting on behalf of customers;
- authorised signatories;
- transactors and non-account holders;
- counterparties; and
- relevant information contained in wire transfers and trade transactions.
This makes sanctions screening broader than simply checking the name appearing on an account.
When Should Customers Be Screened?
BSP guidance establishes two important points in the customer lifecycle.
At onboarding
Screening should occur during the establishment of the business relationship or opening of the account, or at the latest before the first transaction is conducted.
This allows the institution to identify whether the prospective customer, beneficial owner or other relevant party is subject to applicable sanctions before financial activity begins.
When new designations are issued
Screening does not end at onboarding.
BSP guidance states that institutions should conduct screening periodically throughout the relationship, particularly when new designations or updates are issued.
Importantly, new designations should be screened against the institution's existing customer base without delay.
A customer who did not appear on a sanctions list when an account was opened may subsequently become designated. Institutions therefore need an ongoing mechanism capable of identifying this change.
What Does "Without Delay" Mean for Sanctions Screening?
"Without delay" is an important concept in targeted financial sanctions.
It should not be interpreted as allowing an institution to wait until its next convenient monthly or quarterly screening cycle after a new designation becomes effective.
Relevant designations need to be incorporated into the institution's sanctions controls promptly, and new designations should be screened against the existing customer base without delay.
For institutions with large customer populations, manual processes can make this difficult.
Automated list ingestion and event-driven customer re-screening are therefore strong operational practices because they reduce the gap between a designation becoming effective and the institution identifying a potential match.
The legal objective is timely implementation of targeted financial sanctions. Automation is one practical way of achieving that objective at scale.
Screening Wire Transfers and Transactions
BSP sanctions guidance also expects institutions to screen relevant parties and information associated with wire transfers and trade transactions.
This can include information concerning originators, beneficiaries and other relevant parties or transaction details.
Institutions should design transaction-screening controls according to the type of payment, applicable regulatory requirements and the risk that a prohibited transaction could be completed before a sanctions concern is identified.
This does not mean every Philippine payment rail is subject to an identical universal technological requirement for "real-time sanctions screening."
The appropriate screening point can depend on the transaction type and applicable BSP requirements.
For payment flows where processing a transaction involving a designated person could result in a prohibited dealing, screening before execution can be an important control.
Beneficial Ownership Screening
Sanctions exposure can exist behind a corporate customer even where the legal entity itself does not appear on a sanctions list.
BSP's screening guidance specifically includes beneficial owners within the minimum sanctions-screening scope.
Institutions therefore need to connect information collected during customer due diligence and beneficial ownership verification with their sanctions screening process.
For example, a company may not itself appear on a sanctions list, while an individual who ultimately owns or controls the company may be designated.
Screening only the company name can therefore leave an important gap.
What Happens When Sanctions Screening Generates a Match?
Not every sanctions-screening alert means the customer is a designated person.
A robust process should distinguish between a simple name match, a potential target match and a confirmed target match.
Name match
A screening system may initially identify a similarity between a customer or transaction party and a person appearing on a sanctions list.
The institution should investigate the alert using available identifying information such as:
- full name;
- aliases;
- date of birth;
- nationality;
- address;
- passport or identification details;
- place of birth;
- corporate information; and
- beneficial ownership information.
Potential target match
A potential target match may arise where identifying information substantially corresponds with a designated person but the institution cannot conclusively establish or exclude the identity.
Institutions should follow the applicable AMLC procedures for potential target matches, including relevant freezing or holding, confirmation and reporting requirements.
Target match
Where the institution determines that the customer, account holder, beneficial owner or relevant party is the designated person or entity, the applicable targeted financial sanctions must be implemented.
This distinction is important.
A sanctions alert is not automatically a confirmed sanctions match.
Effective sanctions screening therefore requires both accurate matching and a controlled investigation process for resolving alerts.
Freeze Without Delay: Understanding the 24-Hour Requirement
One common source of confusion is the "24-hour freeze requirement."
The obligation should not be interpreted as giving an institution 24 hours after identifying a target match before it needs to act.
For a confirmed target match subject to applicable targeted financial sanctions, assets should be frozen without prior notice and without delay.
BSP guidance describes this as acting within a matter of hours.
The 24-hour period is relevant to particular reporting requirements following the freeze, including submission of the applicable detailed return.
Operationally, institutions therefore need to distinguish between:
Freeze action: implement the applicable freeze without delay.
Reporting: submit the required information to AMLC within the applicable reporting timeframe.
This distinction matters because waiting 24 hours to freeze an identified sanctioned party could be inconsistent with the requirement to implement targeted financial sanctions without delay.
AMLC Reporting for Sanctions Matches
Sanctions-related reporting should also be distinguished from ordinary Covered Transaction Report (CTR) filing.
A sanctions match is not automatically a CTR
Covered Transaction Reports are generally triggered by transactions meeting applicable statutory thresholds and conditions.
The fact that a transaction involves a designated or potentially designated person does not mean that every such transaction automatically becomes a CTR regardless of amount.
Instead, targeted financial sanctions have specific reporting procedures.
Target and potential target matches
Under current AMLC reporting guidance, covered persons have specific reporting obligations for target matches and potential target matches, including reporting through the appropriate TFS/STR mechanism.
Institutions need to follow current AMLC procedures and GoTRACS reporting requirements when these situations arise.
Suspicious transaction reporting
Transactions or attempted transactions associated with terrorism, terrorist financing, designated persons or related activity may also trigger suspicious transaction reporting obligations.
Importantly, sanctions/TFS reporting can involve special procedures and timelines.
Compliance teams should therefore avoid treating all sanctions alerts as ordinary STRs subject to one generic reporting timetable.
The correct workflow depends on whether the alert is a name match, potential target match, confirmed target match or related suspicious activity.
Record Keeping and Auditability
Effective sanctions compliance requires an institution to demonstrate not only that screening took place, but also what happened after an alert was generated.
Relevant AML/CFT records are generally subject to applicable statutory record-retention requirements, including five-year retention requirements for relevant records.
From an operational perspective, institutions should maintain an audit trail showing:
- when screening occurred;
- which customer, beneficial owner or transaction party was screened;
- which sanctions data was used;
- the designation or list information applicable at the time;
- what potential matches were generated;
- the identifiers considered during investigation;
- analyst decisions and rationale;
- escalation and approvals;
- freeze actions, where applicable; and
- associated AMLC reporting.
This allows the institution to reconstruct how a particular sanctions decision was made.
Virtual Asset Service Providers and Sanctions Screening
Virtual asset service providers operating within the Philippine regulatory framework are subject to applicable AML/CFT and targeted financial sanctions obligations.
The same fundamental principle applies: VASPs need controls capable of identifying designated persons and preventing prohibited activity.
Identity screening
Customers, beneficial owners and other relevant parties should be screened in accordance with applicable requirements.
Transaction controls
Virtual asset transfers create additional information that may be relevant to sanctions risk.
Unlike traditional bank transfers, blockchain transactions can contain wallet addresses and other on-chain indicators that institutions can analyse alongside customer identity.
Blockchain address screening as an additional control
Some foreign sanctions authorities, particularly OFAC, identify virtual currency addresses associated with designated persons.
For Philippine VASPs whose sanctions risk assessment, international activities, counterparties or legal exposure make OFAC relevant, screening blockchain addresses against applicable sanctions data can provide an additional layer of protection.
This should be distinguished from suggesting that OFAC wallet-address screening is universally mandated by Philippine law.
Rather, blockchain analytics and wallet-address screening can be valuable additional controls for VASPs whose sanctions exposure warrants them.
What Effective Sanctions Screening Looks Like in Practice
Meeting regulatory requirements requires more than access to a sanctions database.
Appropriate list coverage
Institutions should ensure their sanctions databases include all designations required under the applicable Philippine TFS framework.
Additional foreign lists such as OFAC, EU or UK sanctions can then be incorporated based on the institution's sanctions risk assessment and international exposure.
Timely list updates
Relevant new designations need to be incorporated into screening controls without delay.
At meaningful customer volumes, automated list ingestion can substantially reduce the operational risk associated with manually downloading and uploading sanctions data.
Re-screening of existing customers
New designations should be screened against existing customers without delay.
Automated event-driven re-screening can help institutions identify newly designated customers or beneficial owners faster than periodic manual reviews.
Fuzzy name matching and alias coverage
Sanctions lists frequently contain aliases and names transliterated from languages and scripts including Arabic, Russian and Korean.
Exact string matching alone can therefore miss relevant matches.
Fuzzy and phonetic matching, configurable similarity thresholds and comprehensive alias coverage can help institutions identify spelling and transliteration variations while managing false positives.
For a deeper look at how AI-powered two-pass matching can improve screening accuracy while reducing false positives, read our guide on AI-Powered AML Screening: How Two-Pass Matching Cuts False Positives by 60–70%.
Beneficial ownership screening
Customer due diligence and beneficial ownership information should feed into sanctions screening.
Checking only the corporate entity name can leave an institution exposed where the relevant sanctions risk arises through an owner or controlling person.
False-positive management
Name screening inevitably generates false positives.
Effective systems need to help investigators distinguish genuine matches from unrelated individuals using information such as date of birth, nationality, address, identification numbers and other available identifiers.
Just as importantly, the institution should document why an alert was cleared.
Explainable alert resolution
A regulator, auditor or internal compliance reviewer should be able to understand:
- why an alert was generated;
- what information matched;
- what information did not match;
- which identifiers the analyst considered; and
- why the institution confirmed or dismissed the alert.
Screening technology therefore needs to support investigation and auditability—not simply name matching.

Common Gaps Institutions Should Test For
Institutions should regularly test their sanctions programmes for weaknesses such as:
Screening only at onboarding. Customers are screened when accounts are opened but not promptly re-screened following new designations.
Incomplete mandatory list coverage. Relevant UNSC, ATC or other applicable domestic designations are missing from the sanctions database.
Foreign lists treated incorrectly. OFAC or other foreign lists are either assumed to be universally mandatory or ignored despite significant international exposure.
Weak alias coverage. Screening checks primary names but fails to consider aliases and alternative spellings.
Manual list management. Updated sanctions data relies on staff manually downloading and uploading lists, creating delays between designation and screening.
Beneficial owners excluded. Corporate customers are screened, but the individuals who ultimately own or control them are not incorporated into the screening process.
Poor match resolution. Alerts are closed without sufficient supporting identifiers or documented rationale.
No reconstructable audit trail. The institution cannot establish what data was screened, when it was screened, why an alert occurred or how the analyst reached a decision.
Disconnected screening and AML investigations. Sanctions alerts, transaction monitoring alerts and AMLC reporting are handled across separate workflows, making it difficult to reconstruct the complete financial crime risk picture.
How Tookitaki’s FinCense Supports Philippine Sanctions Screening
Sanctions screening becomes significantly harder when it operates independently from the broader AML compliance environment.
A sanctions alert may need to be investigated alongside customer due diligence information, transaction-monitoring activity etc. A confirmed target or potential target match may also trigger freezing and AMLC reporting workflows.
When these processes operate across disconnected systems, compliance teams need to manually reconstruct the relationship between the customer, screening alert, transaction activity and regulatory action.
FinCense brings sanctions screening into an integrated financial crime compliance environment.
Screening can cover relevant customer ownership information, with alerts capturing information such as match scores, identifiers and analyst decisions.
Screening alerts feed directly into case management, allowing investigators to examine sanctions concerns alongside relevant customer and transaction-monitoring information within the same investigation environment.
For institutions operating at scale, capabilities such as automated sanctions-data updates, fuzzy matching, alias handling, configurable thresholds, alert investigation and auditable decision-making can help translate regulatory obligations into effective operational controls.
Book a demo to see how FinCense's Screening module can support sanctions screening and broader AML/CFT compliance for Philippine financial institutions.
Frequently Asked Questions
What sanctions lists must Philippine financial institutions screen against?
BSP-supervised financial institutions should ensure their sanctions databases cover applicable targeted financial sanctions designations.
At a minimum, this includes relevant UN Security Council designations relating to terrorism, terrorist financing and proliferation financing, together with applicable domestic designations such as those made by the Anti-Terrorism Council and relevant Court of Appeals proscriptions.
Foreign sanctions lists such as OFAC or EU sanctions may also be incorporated based on the institution's sanctions risk assessment, international activities, counterparties and correspondent banking exposure.
Do Philippine institutions have to re-screen existing customers?
Yes.
BSP guidance states that screening should occur periodically during the business relationship, particularly when new designations or updates are issued.
Importantly, all new designations should be screened against the existing customer base without delay.
What does the 24-hour sanctions requirement mean?
A confirmed target match subject to applicable targeted financial sanctions should be frozen without prior notice and without delay.
The 24-hour period should not be interpreted as a grace period for freezing.
Rather, applicable AMLC rules require particular reports or detailed returns following implementation of the freeze within specified timeframes.
Institutions should therefore distinguish between the obligation to freeze without delay and the subsequent reporting deadline.
Does every sanctions match generate a Covered Transaction Report?
No.
A sanctions match does not automatically make a transaction a CTR regardless of amount.
Target and potential target matches are subject to specific targeted financial sanctions and AMLC reporting procedures. Depending on the circumstances, suspicious transaction reporting requirements may also apply.
Institutions should follow current AMLC and GoTRACS procedures for the relevant type of match.
Are Philippine financial institutions required to screen against OFAC?
OFAC sanctions are not automatically part of the minimum Philippine TFS list coverage simply because an institution operates in the Philippines.
BSP allows institutions to incorporate foreign sanctions designations such as OFAC and EU lists based on their sanctions risk assessment.
For institutions with US-dollar exposure, US correspondent relationships or other relevant international exposure, OFAC screening may nevertheless be an important component of the institution's sanctions risk management framework.
Do VASPs in the Philippines have sanctions screening obligations?
Yes.
VASPs within the Philippine AML/CFT regulatory framework need to comply with applicable targeted financial sanctions requirements.
In addition to identity screening, VASPs may consider blockchain analytics and wallet-address screening where appropriate to their sanctions exposure.
For VASPs with relevant OFAC or international exposure, screening virtual currency addresses associated with foreign sanctions designations can provide an additional control, but it should not be described as a universal Philippine statutory requirement.
Do beneficial owners need to be screened?
Yes.
BSP sanctions-screening guidance specifically includes beneficial owners among the parties that should be covered by sanctions screening.
Institutions should therefore ensure that beneficial ownership information collected during customer due diligence feeds into the sanctions-screening process.
How quickly must new sanctions designations be incorporated?
BSP guidance states that applicable designations should be updated in institutions' sanctions databases without delay.
New designations should likewise be screened against the existing customer base without delay.
For institutions operating at significant scale, automated sanctions-data updates and event-driven re-screening can help meet this expectation more reliably than manual list-management processes.
Experience the most intelligent AML and fraud prevention platform
Experience the most intelligent AML and fraud prevention platform
Experience the most intelligent AML and fraud prevention platform
Top AML Scenarios in ASEAN

The Role of AML Software in Compliance

The Role of AML Software in Compliance





