[codicts-css-switcher id=”346″]

Global Law Experts Logo
aml compliance philippines

How to Build an AML/CFT Compliance Program for Companies in the Philippines (2026): Step‑by‑step Checklist

By Global Law Experts
– posted 30 minutes ago

AML compliance Philippines obligations have moved decisively from the exclusive domain of banks into the day‑to‑day risk agenda of ordinary companies, professional services firms and investors. This guide is written for in‑house counsel, compliance officers, company boards and professional advisers who need a practical, jurisdiction‑specific playbook rather than another summary of the law. It sets out a working checklist, policy manual outline, compliance officer job description, customer due diligence templates, suspicious transaction report escalation flow and an implementation timeline, grounded in the requirements enforced by the Anti‑Money Laundering Council (AMLC), the Bangko Sentral ng Pilipinas (BSP) and the Securities and Exchange Commission (SEC).

Because enforcement continues to concentrate on beneficial ownership accuracy, STR quality and documented corporate controls, the material below is structured so you can act on it immediately.

Overview, What this guide covers

This is a procedural guide. It walks through each component of an AML/CFT compliance program in the order you should build it, identifies who inside the organisation owns each task, and gives realistic durations. Where a legal requirement is stated, it is drawn from the AMLC, BSP, SEC, or the consolidated text of the Anti‑Money Laundering Act of 2001 (Republic Act No. 9160), as amended. Practitioner recommendations, for example, how to phrase an STR narrative or structure a governance matrix, reflect experience advising companies before Philippine regulators.

By the end of this guide you will have:

  • A policy manual outline covering the core AML policies your board should approve.
  • An AML Compliance Officer job description with the authority, independence and reporting lines regulators expect.
  • An STR/CTR escalation flow that respects confidentiality and tipping‑off rules.
  • A 90‑day implementation plan with responsibilities, durations and recordkeeping requirements.

Eligibility, Which companies and activities are in scope

Not every company carries identical obligations, but the trend of AML compliance Philippines regulation is to widen the net beyond traditional financial institutions. Understanding whether you are a covered person, and to what depth, is the first substantive decision.

Covered persons under AML legislation

The Anti‑Money Laundering Act (Republic Act No. 9160), as amended by Republic Act Nos. 9194, 10167, 10365, 10927 and 11521, identifies categories of covered persons. Broadly, these include:

  • Financial institutions. Banks, quasi‑banks, trust entities and other BSP‑supervised institutions, as well as insurance companies and securities dealers supervised by the Insurance Commission and the SEC respectively.
  • Casinos. Including internet‑ and ship‑based gaming operators, brought within the regime by Republic Act No. 10927.
  • Company service providers. Persons who, as a business, provide services such as forming companies, acting as (or arranging for another person to act as) a director or corporate secretary, providing a registered office or address, or acting as a nominee shareholder, added as covered persons by Republic Act No. 11521.
  • Designated non‑financial businesses and professions (DNFBPs). Including dealers in precious metals and precious stones for cash transactions above the regulatory threshold, real estate developers and brokers for covered transactions, and certain lawyers and accountants when they carry out defined transactions on behalf of clients (subject to applicable rules and privilege).

When a non‑financial corporate needs a program

Even where a company is not squarely a covered person, several risk triggers make a formal program advisable and, in practice, expected by counterparties and banks. These include dealing in large volumes of cash, offering trust or fiduciary services, facilitating cross‑border remittances or payments, holding client money, or operating complex or offshore ownership structures. A company sitting in a supply chain to regulated financial institutions will also be pushed to demonstrate controls. Where any of these apply, the minimum program requirements below should be treated as mandatory in substance.

Step‑by‑step: Build your AML/CFT compliance program

The following steps form the practical core of AML compliance Philippines implementation. Each step states why it matters, what to produce, and who owns it. The durations are consolidated in the timeline table that follows.

  1. Conduct a company‑level AML/CFT risk assessment.

    Why it matters: Every other control is calibrated to risk. A program that is not anchored to a documented assessment is the single most common enforcement finding.

    Scope and method: Assess risk across customers, products and services, delivery channels, and geographies. Score each on likelihood and impact using a simple matrix (for example, low/medium/high across each axis). Draw on transaction data, onboarding records, sanctions exposure and typologies published by the AMLC and FATF.

    Deliverable: A risk register with a mitigation plan, reviewed at least annually and after any material business change. Owner: Head of Compliance, supported where needed by an external consultant.

  2. Secure governance and board oversight.

    Why it matters: Regulators expect the board to own AML risk, not merely receive reports. Board minutes evidencing approval are frequently requested during examination.

    What to produce: A board resolution approving the AML/CFT policy, assigning senior‑management responsibility, and confirming the compliance officer’s authority and independence. Establish a reporting line from the compliance officer to the board or a board‑level committee. Owner: Board and General Counsel.

  3. Draft the AML/CFT policy and procedures manual.

    Why it matters: A generic, downloaded policy that does not reflect your actual operations is worse than no policy, it evidences awareness without implementation. Covered persons are required to have a written, board‑approved money laundering and terrorist financing prevention program.

    Required policy headings:

    • Customer due diligence and enhanced due diligence.
    • Suspicious transaction and covered transaction reporting.
    • Beneficial ownership identification and verification.
    • Record retention and data protection.
    • Sanctions and watchlist screening (including targeted financial sanctions).
    • Transaction monitoring.
    • Third‑party and outsourcing risk.
    • Training and independent audit.

    Owner: Compliance Officer with Legal.

  4. Appoint and register the AML Compliance Officer.

    Why it matters: The compliance officer is the linchpin of the program and, for covered persons, the point of accountability toward the AMLC. Covered persons must designate an officer with sufficient seniority, authority, independence and resources. Depending on entity type, registration or notification obligations arise with the AMLC or the relevant supervisory authority (BSP, SEC or Insurance Commission).

    Sample job description elements: ensuring policy implementation and periodic review; overseeing CDD and beneficial ownership verification; identifying, analysing and filing STRs and CTRs; acting as liaison with the AMLC; delivering staff training; and reporting to the board. Appoint a named backup officer to cover absences.

    Owner: Company Secretary and Compliance Officer.

  5. Implement customer due diligence and beneficial ownership verification.

    Why it matters: Corporate KYC in the Philippines is where most programs succeed or fail. Weak beneficial ownership verification is a priority enforcement theme.

    CDD levels:

    • Reduced/simplified due diligence, only where legal criteria are met and the lower risk is documented.
    • Standard due diligence, identify and verify the customer and beneficial owners from reliable, independent sources.
    • Enhanced due diligence, for higher‑risk customers, complex structures, politically exposed persons and higher‑risk jurisdictions; obtain additional documentation and senior sign‑off.

    Deliverable: A CDD checklist template capturing identity documents, corporate registration extracts, ownership charts and verification evidence. Owner: Compliance with frontline staff.

  6. Establish transaction monitoring and automated controls.

    Why it matters: Monitoring converts policy into detection. BSP‑supervised entities are expected to operate more sophisticated systems; smaller corporates may begin with rule‑based or manual review scaled to risk.

    What to build: A red‑flag catalogue, threshold rules, alert generation and a documented process for reviewing and closing alerts. Tune rules periodically to reduce noise and capture emerging typologies. Owner: IT, Compliance and any monitoring vendor.

  7. Set up STR/CTR identification and filing.

    Why it matters: Suspicious transaction report obligations in the Philippines carry strict confidentiality and tipping‑off prohibitions. A late or poorly reasoned report is a frequent criticism.

    Internal escalation flow: frontline staff raise a concern to the compliance officer; the officer analyses, documents the rationale and, where suspicion is confirmed, files the report through the AMLC’s electronic reporting channels within the timeframe prescribed by the AMLC. Covered transaction reports apply to single cash or monetary‑instrument transactions above the regulatory threshold set under the law (and, for casinos, the separate threshold applicable to them). Do not disclose the existence of a report to the customer or any unauthorised person.

    Sample STR narrative structure: who the parties are, what the transaction was, why it is suspicious (against which red flags), and what supporting evidence exists. Owner: Compliance Officer.

  8. Configure recordkeeping and data retention.

    Why it matters: The inability to produce records on request undermines an otherwise sound program and is itself a breach.

    What to do: Apply retention periods by document type consistent with AMLC and BSP guidance (detailed in the documents table below), store records securely, in compliance with the Data Privacy Act of 2012, and ensure they are retrievable. Owner: Compliance and IT.

  9. Deliver training, independent audit and continuous improvement.

    Why it matters: Controls decay without reinforcement and independent challenge.

    What to do: Provide mandatory initial training for frontline staff and officers, with at least annual refreshers and more frequent sessions for high‑risk roles. Commission periodic independent testing of the program, and track corrective actions to closure. Owner: HR, Compliance and Internal Audit.

  10. Build pre‑transaction and onboarding checks for high‑risk events.

    Why it matters: M&A, new high‑value clients and the onboarding of new beneficial owners are moments of concentrated risk.

    What to do: Apply enhanced due diligence to targets and counterparties, map beneficial ownership before completion, and record senior approval of any residual risk. Owner: Compliance with the deal team.

  11. Manage outsourcing, vendors and third‑party risk.

    Why it matters: Outsourcing a function does not outsource the obligation.

    What to do: Perform vendor due diligence, and include AML clauses in service agreements covering data access, cooperation with regulators, audit rights and confidentiality. Owner: Compliance and Procurement.

  12. Prepare incident response, investigations and regulatory reporting.

    Why it matters: When something goes wrong, the speed and quality of response shapes the regulatory outcome.

    What to do: Maintain an investigation protocol, internal memo templates, and clear criteria for notifying the regulator. Preserve evidence and document decisions contemporaneously. Owner: Compliance Officer and Legal.

Step, responsibility and duration timeline

Step Action Responsible (Who) Estimated duration
1 Conduct company‑level AML/CFT risk assessment and create risk register Head of Compliance / External consultant 2–4 weeks
2 Board approval of AML policy and assignment of responsibilities Board and General Counsel 1–2 weeks
3 Draft AML/CFT policy and procedures manual Compliance Officer and Legal 2–4 weeks
4 Appoint and register AML Compliance Officer (if applicable) Company Secretary / Compliance Officer 1–3 weeks (varies by regulator)
5 Implement CDD/KYC and beneficial ownership verification processes Compliance and Frontline staff 2–6 weeks
6 Deploy monitoring controls and tune alert rules IT / Compliance / Vendor 2–8 weeks
7 Establish STR/CTR internal escalation and filing process Compliance Officer 1–2 weeks
8 Staff training and roll‑out HR / Compliance Ongoing; initial rollout 1–2 weeks
9 Independent audit / testing Internal Audit / External Auditor 2–4 weeks per audit cycle

Required documents and recordkeeping

Effective AML compliance Philippines programs stand or fall on documentation. Retention rules apply by document type, and the practical standard is that records must be complete, secure and retrievable on regulator request. The periods below reflect AMLC and BSP guidance; where guidance offers a range, adopt the longer period as your default and confirm the applicable period with your supervisor.

Document Who prepares Where retained Retention period (typical)
AML/CFT policy and procedures manual Compliance Officer / Legal Compliance repository / intranet Life of company; keep superseded versions
Customer identification records (CDD files) Frontline staff / Compliance Secure electronic KYC repository At least 5 years after end of the relationship (longer if required by supervisor)
Beneficial ownership verification documents Compliance / Corporate Secretary BO register and compliance file At least 5 years after change or closure
STR and supporting analysis (internal memos) Compliance Officer Confidential incident log At least 5 years, per AMLC guidance
Transaction records, monitoring logs and system outputs IT / Compliance Encrypted logs At least 5 years; longer where an investigation is pending
Training records and attendance HR / Compliance HR system / compliance records 5 years or per policy

Note: where a transaction or account is the subject of an ongoing case or investigation, records must be retained until it is confirmed that the case has been closed. Verify current retention periods with the AMLC or your supervisor.

Timeline and deadlines

A disciplined company can stand up a credible program on a 90‑day cycle: weeks one to four for the risk assessment and board approval; weeks four to eight for the policy manual, compliance officer appointment and CDD design; weeks eight to twelve for monitoring, STR/CTR processes and the first training rollout. Independent testing follows once the controls have been operating. Note that specific registration and periodic filing deadlines vary by regulator and entity type, confirm your obligations directly with the AMLC, BSP or SEC as applicable, and diarise annual policy review and any periodic reporting dates so they are never missed.

Costs and fees

Budgeting realistically avoids the false economy of a program that cannot be sustained. The figures below are indicative only, vary considerably with firm size, scope and vendor selection, and should be confirmed against current market quotes.

Item Typical cost (indicative) Notes
External risk assessment / consultant Varies by firm size and scope Obtain quotes from qualified advisers
AML program drafting Varies with customisation Higher for tailored, multi‑entity programs
AML Compliance Officer salary Market‑dependent Varies by seniority and experience
Monitoring software (annual) Varies by vendor and integration Scales with transaction volume
Training (per employee / annual) Modest; scales with delivery method Online vs in‑person
Filing / registration fees Varies; some filings may carry no fee Verify current fees with the relevant regulator

What to expect from enforcement in 2026

The direction of AML compliance Philippines enforcement emphasises corporate‑level controls, the accuracy of beneficial ownership information and the quality, not merely the existence, of suspicious transaction reports. Examiners increasingly probe whether risk assessments genuinely drive controls, whether beneficial ownership is verified from independent sources rather than accepted on the customer’s word, and whether STR narratives explain the basis of suspicion rather than reciting boilerplate. These priorities are consistent with the Philippines’ ongoing commitments to strengthen its AML/CFT framework in line with FATF standards.

The likely practical effect for companies is threefold: stricter beneficial ownership verification with documented independent checks; richer, better‑reasoned STR narratives supported by preserved evidence; and demonstrable independent audit of the program with tracked corrective actions. Companies able to show a living, board‑owned program tend to fare materially better in any examination than those relying on a static manual.

Common pitfalls and enforcement

  • Generic policies without implementation. A downloaded manual that does not match operations evidences awareness without control and is a recurring finding.
  • Weak beneficial ownership verification. Accepting ownership declarations without independent checks is a priority concern, especially for layered or offshore structures.
  • Poor STR narratives. Reports that fail to articulate why a transaction is suspicious reduce their intelligence value and attract criticism.
  • Failure to preserve evidence. Missing or unretrievable records are themselves a breach and weaken any defence.
  • Tipping‑off. Disclosing a report to the customer breaches confidentiality rules and can trigger separate criminal liability under the Anti‑Money Laundering Act.

Consequences of non‑compliance range from administrative fines and sanctions imposed by the AMLC or the relevant supervisor to referral for criminal investigation and prosecution, alongside significant reputational damage. The severity depends on the regulator involved and the nature of the breach, but the pattern is clear: documented, well‑implemented controls are the most effective mitigation.

Corporate versus regulated financial institution obligations

Topic Non‑financial corporate (typical) Regulated financial institution
Mandatory registration with supervisor Depends on activity (e.g. casinos, company service providers, certain DNFBPs) Usually mandatory (BSP / SEC / Insurance Commission), with AMLC registration for reporting
Monitoring systems Manual or basic automated, scaled to risk Advanced monitoring and threshold tuning
STR/CTR filing expectations Lower volume, same reporting standard High volume; established reporting units
Regulatory examination frequency Less frequent Regular supervisory examinations

Conclusion

Building AML compliance Philippines capability is not a one‑off drafting exercise but a governed, evidenced and continuously improved program. Start with a documented risk assessment, secure genuine board ownership, appoint a properly empowered compliance officer, and make beneficial ownership verification and STR quality your points of excellence, the very areas enforcement is targeting. Companies that treat AML compliance Philippines obligations as a living system, supported by clear records and independent testing, will not only satisfy the AMLC, BSP and SEC but will also protect their reputation and their commercial relationships. Use the checklist, timeline and templates above as your implementation baseline, and confirm entity‑specific requirements directly with the regulators before you file.

For related guidance, see the Commercial practice, Philippines page.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Danielle Marie C. Tan at Morales & Justiniano, a member of the Global Law Experts network.

Sources

  1. Anti‑Money Laundering Council (AMLC)
  2. Bangko Sentral ng Pilipinas (BSP)
  3. Securities and Exchange Commission (Philippines)
  4. Official Gazette of the Republic of the Philippines
  5. The LawPhil Project (Arellano Law Foundation), consolidated statutes
  6. Financial Action Task Force (FATF)

FAQs

What are the minimum AML/CFT program requirements for companies in the Philippines?
At a minimum: a board‑approved AML/CFT prevention program, an appointed AML Compliance Officer, customer due diligence and beneficial ownership verification procedures, STR and CTR filing processes, recordkeeping, staff training and independent audit, all consistent with the Anti‑Money Laundering Act, its implementing rules, and applicable AMLC, BSP and SEC issuances.
A senior staff member with sufficient authority, independence and resources. Duties include ensuring policy implementation, overseeing CDD and beneficial ownership verification, analysing and filing STRs, acting as liaison with the AMLC, delivering training and reporting to the board. Covered persons should also register or notify the relevant supervisor and the AMLC as required.
CDD files, transaction and monitoring records, STR supporting documents, beneficial ownership records and training records. Under the Anti‑Money Laundering Act and its implementing rules, records must generally be kept for at least five years, often measured from the date of the transaction or the end of the relationship, and longer where a case is pending. When in doubt, apply the longer period and confirm with the AMLC or your supervisor.
File a suspicious transaction report promptly once suspicion is identified, within the timeframe prescribed by the AMLC, and never tip off the subject. File covered transaction reports for single cash or monetary‑instrument transactions above the regulatory threshold set under the law. Both are submitted electronically through the AMLC’s designated reporting channels in the manner the AMLC prescribes.
Identify and verify beneficial owners using reliable, independent sources such as company registries, corporate documents and reputable databases, obtain documentary evidence, and apply enhanced checks to complex or layered ownership structures. Record the verification and retain it in the beneficial ownership register. SEC‑registered corporations are also subject to beneficial ownership disclosure requirements in their General Information Sheet.
Administrative fines and sanctions, referral for criminal investigation and prosecution, and reputational harm. Severity depends on the regulator and the nature of the breach, with implementation gaps and record failures treated seriously.
Provide mandatory initial training for frontline staff and officers, with refresher training at least annually and more frequent sessions for high‑risk roles. Keep attendance and content records.
Only where the legal criteria are met and the lower risk is documented. Maintain a written risk justification consistent with supervisory guidance, and escalate to standard or enhanced due diligence whenever risk indicators appear.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

How to Build an AML/CFT Compliance Program for Companies in the Philippines (2026): Step‑by‑step Checklist

Send welcome message

Custom Message