Our Expert in Philippines
No results available
AML compliance Philippines obligations have moved decisively from the exclusive domain of banks into the day‑to‑day risk agenda of ordinary companies, professional services firms and investors. This guide is written for in‑house counsel, compliance officers, company boards and professional advisers who need a practical, jurisdiction‑specific playbook rather than another summary of the law. It sets out a working checklist, policy manual outline, compliance officer job description, customer due diligence templates, suspicious transaction report escalation flow and an implementation timeline, grounded in the requirements enforced by the Anti‑Money Laundering Council (AMLC), the Bangko Sentral ng Pilipinas (BSP) and the Securities and Exchange Commission (SEC).
Because enforcement continues to concentrate on beneficial ownership accuracy, STR quality and documented corporate controls, the material below is structured so you can act on it immediately.
This is a procedural guide. It walks through each component of an AML/CFT compliance program in the order you should build it, identifies who inside the organisation owns each task, and gives realistic durations. Where a legal requirement is stated, it is drawn from the AMLC, BSP, SEC, or the consolidated text of the Anti‑Money Laundering Act of 2001 (Republic Act No. 9160), as amended. Practitioner recommendations, for example, how to phrase an STR narrative or structure a governance matrix, reflect experience advising companies before Philippine regulators.
By the end of this guide you will have:
Not every company carries identical obligations, but the trend of AML compliance Philippines regulation is to widen the net beyond traditional financial institutions. Understanding whether you are a covered person, and to what depth, is the first substantive decision.
The Anti‑Money Laundering Act (Republic Act No. 9160), as amended by Republic Act Nos. 9194, 10167, 10365, 10927 and 11521, identifies categories of covered persons. Broadly, these include:
Even where a company is not squarely a covered person, several risk triggers make a formal program advisable and, in practice, expected by counterparties and banks. These include dealing in large volumes of cash, offering trust or fiduciary services, facilitating cross‑border remittances or payments, holding client money, or operating complex or offshore ownership structures. A company sitting in a supply chain to regulated financial institutions will also be pushed to demonstrate controls. Where any of these apply, the minimum program requirements below should be treated as mandatory in substance.
The following steps form the practical core of AML compliance Philippines implementation. Each step states why it matters, what to produce, and who owns it. The durations are consolidated in the timeline table that follows.
Why it matters: Every other control is calibrated to risk. A program that is not anchored to a documented assessment is the single most common enforcement finding.
Scope and method: Assess risk across customers, products and services, delivery channels, and geographies. Score each on likelihood and impact using a simple matrix (for example, low/medium/high across each axis). Draw on transaction data, onboarding records, sanctions exposure and typologies published by the AMLC and FATF.
Deliverable: A risk register with a mitigation plan, reviewed at least annually and after any material business change. Owner: Head of Compliance, supported where needed by an external consultant.
Why it matters: Regulators expect the board to own AML risk, not merely receive reports. Board minutes evidencing approval are frequently requested during examination.
What to produce: A board resolution approving the AML/CFT policy, assigning senior‑management responsibility, and confirming the compliance officer’s authority and independence. Establish a reporting line from the compliance officer to the board or a board‑level committee. Owner: Board and General Counsel.
Why it matters: A generic, downloaded policy that does not reflect your actual operations is worse than no policy, it evidences awareness without implementation. Covered persons are required to have a written, board‑approved money laundering and terrorist financing prevention program.
Required policy headings:
Owner: Compliance Officer with Legal.
Why it matters: The compliance officer is the linchpin of the program and, for covered persons, the point of accountability toward the AMLC. Covered persons must designate an officer with sufficient seniority, authority, independence and resources. Depending on entity type, registration or notification obligations arise with the AMLC or the relevant supervisory authority (BSP, SEC or Insurance Commission).
Sample job description elements: ensuring policy implementation and periodic review; overseeing CDD and beneficial ownership verification; identifying, analysing and filing STRs and CTRs; acting as liaison with the AMLC; delivering staff training; and reporting to the board. Appoint a named backup officer to cover absences.
Owner: Company Secretary and Compliance Officer.
Why it matters: Corporate KYC in the Philippines is where most programs succeed or fail. Weak beneficial ownership verification is a priority enforcement theme.
CDD levels:
Deliverable: A CDD checklist template capturing identity documents, corporate registration extracts, ownership charts and verification evidence. Owner: Compliance with frontline staff.
Why it matters: Monitoring converts policy into detection. BSP‑supervised entities are expected to operate more sophisticated systems; smaller corporates may begin with rule‑based or manual review scaled to risk.
What to build: A red‑flag catalogue, threshold rules, alert generation and a documented process for reviewing and closing alerts. Tune rules periodically to reduce noise and capture emerging typologies. Owner: IT, Compliance and any monitoring vendor.
Why it matters: Suspicious transaction report obligations in the Philippines carry strict confidentiality and tipping‑off prohibitions. A late or poorly reasoned report is a frequent criticism.
Internal escalation flow: frontline staff raise a concern to the compliance officer; the officer analyses, documents the rationale and, where suspicion is confirmed, files the report through the AMLC’s electronic reporting channels within the timeframe prescribed by the AMLC. Covered transaction reports apply to single cash or monetary‑instrument transactions above the regulatory threshold set under the law (and, for casinos, the separate threshold applicable to them). Do not disclose the existence of a report to the customer or any unauthorised person.
Sample STR narrative structure: who the parties are, what the transaction was, why it is suspicious (against which red flags), and what supporting evidence exists. Owner: Compliance Officer.
Why it matters: The inability to produce records on request undermines an otherwise sound program and is itself a breach.
What to do: Apply retention periods by document type consistent with AMLC and BSP guidance (detailed in the documents table below), store records securely, in compliance with the Data Privacy Act of 2012, and ensure they are retrievable. Owner: Compliance and IT.
Why it matters: Controls decay without reinforcement and independent challenge.
What to do: Provide mandatory initial training for frontline staff and officers, with at least annual refreshers and more frequent sessions for high‑risk roles. Commission periodic independent testing of the program, and track corrective actions to closure. Owner: HR, Compliance and Internal Audit.
Why it matters: M&A, new high‑value clients and the onboarding of new beneficial owners are moments of concentrated risk.
What to do: Apply enhanced due diligence to targets and counterparties, map beneficial ownership before completion, and record senior approval of any residual risk. Owner: Compliance with the deal team.
Why it matters: Outsourcing a function does not outsource the obligation.
What to do: Perform vendor due diligence, and include AML clauses in service agreements covering data access, cooperation with regulators, audit rights and confidentiality. Owner: Compliance and Procurement.
Why it matters: When something goes wrong, the speed and quality of response shapes the regulatory outcome.
What to do: Maintain an investigation protocol, internal memo templates, and clear criteria for notifying the regulator. Preserve evidence and document decisions contemporaneously. Owner: Compliance Officer and Legal.
| Step | Action | Responsible (Who) | Estimated duration |
|---|---|---|---|
| 1 | Conduct company‑level AML/CFT risk assessment and create risk register | Head of Compliance / External consultant | 2–4 weeks |
| 2 | Board approval of AML policy and assignment of responsibilities | Board and General Counsel | 1–2 weeks |
| 3 | Draft AML/CFT policy and procedures manual | Compliance Officer and Legal | 2–4 weeks |
| 4 | Appoint and register AML Compliance Officer (if applicable) | Company Secretary / Compliance Officer | 1–3 weeks (varies by regulator) |
| 5 | Implement CDD/KYC and beneficial ownership verification processes | Compliance and Frontline staff | 2–6 weeks |
| 6 | Deploy monitoring controls and tune alert rules | IT / Compliance / Vendor | 2–8 weeks |
| 7 | Establish STR/CTR internal escalation and filing process | Compliance Officer | 1–2 weeks |
| 8 | Staff training and roll‑out | HR / Compliance | Ongoing; initial rollout 1–2 weeks |
| 9 | Independent audit / testing | Internal Audit / External Auditor | 2–4 weeks per audit cycle |
Effective AML compliance Philippines programs stand or fall on documentation. Retention rules apply by document type, and the practical standard is that records must be complete, secure and retrievable on regulator request. The periods below reflect AMLC and BSP guidance; where guidance offers a range, adopt the longer period as your default and confirm the applicable period with your supervisor.
| Document | Who prepares | Where retained | Retention period (typical) |
|---|---|---|---|
| AML/CFT policy and procedures manual | Compliance Officer / Legal | Compliance repository / intranet | Life of company; keep superseded versions |
| Customer identification records (CDD files) | Frontline staff / Compliance | Secure electronic KYC repository | At least 5 years after end of the relationship (longer if required by supervisor) |
| Beneficial ownership verification documents | Compliance / Corporate Secretary | BO register and compliance file | At least 5 years after change or closure |
| STR and supporting analysis (internal memos) | Compliance Officer | Confidential incident log | At least 5 years, per AMLC guidance |
| Transaction records, monitoring logs and system outputs | IT / Compliance | Encrypted logs | At least 5 years; longer where an investigation is pending |
| Training records and attendance | HR / Compliance | HR system / compliance records | 5 years or per policy |
Note: where a transaction or account is the subject of an ongoing case or investigation, records must be retained until it is confirmed that the case has been closed. Verify current retention periods with the AMLC or your supervisor.
A disciplined company can stand up a credible program on a 90‑day cycle: weeks one to four for the risk assessment and board approval; weeks four to eight for the policy manual, compliance officer appointment and CDD design; weeks eight to twelve for monitoring, STR/CTR processes and the first training rollout. Independent testing follows once the controls have been operating. Note that specific registration and periodic filing deadlines vary by regulator and entity type, confirm your obligations directly with the AMLC, BSP or SEC as applicable, and diarise annual policy review and any periodic reporting dates so they are never missed.
Budgeting realistically avoids the false economy of a program that cannot be sustained. The figures below are indicative only, vary considerably with firm size, scope and vendor selection, and should be confirmed against current market quotes.
| Item | Typical cost (indicative) | Notes |
|---|---|---|
| External risk assessment / consultant | Varies by firm size and scope | Obtain quotes from qualified advisers |
| AML program drafting | Varies with customisation | Higher for tailored, multi‑entity programs |
| AML Compliance Officer salary | Market‑dependent | Varies by seniority and experience |
| Monitoring software (annual) | Varies by vendor and integration | Scales with transaction volume |
| Training (per employee / annual) | Modest; scales with delivery method | Online vs in‑person |
| Filing / registration fees | Varies; some filings may carry no fee | Verify current fees with the relevant regulator |
The direction of AML compliance Philippines enforcement emphasises corporate‑level controls, the accuracy of beneficial ownership information and the quality, not merely the existence, of suspicious transaction reports. Examiners increasingly probe whether risk assessments genuinely drive controls, whether beneficial ownership is verified from independent sources rather than accepted on the customer’s word, and whether STR narratives explain the basis of suspicion rather than reciting boilerplate. These priorities are consistent with the Philippines’ ongoing commitments to strengthen its AML/CFT framework in line with FATF standards.
The likely practical effect for companies is threefold: stricter beneficial ownership verification with documented independent checks; richer, better‑reasoned STR narratives supported by preserved evidence; and demonstrable independent audit of the program with tracked corrective actions. Companies able to show a living, board‑owned program tend to fare materially better in any examination than those relying on a static manual.
Consequences of non‑compliance range from administrative fines and sanctions imposed by the AMLC or the relevant supervisor to referral for criminal investigation and prosecution, alongside significant reputational damage. The severity depends on the regulator involved and the nature of the breach, but the pattern is clear: documented, well‑implemented controls are the most effective mitigation.
| Topic | Non‑financial corporate (typical) | Regulated financial institution |
|---|---|---|
| Mandatory registration with supervisor | Depends on activity (e.g. casinos, company service providers, certain DNFBPs) | Usually mandatory (BSP / SEC / Insurance Commission), with AMLC registration for reporting |
| Monitoring systems | Manual or basic automated, scaled to risk | Advanced monitoring and threshold tuning |
| STR/CTR filing expectations | Lower volume, same reporting standard | High volume; established reporting units |
| Regulatory examination frequency | Less frequent | Regular supervisory examinations |
Building AML compliance Philippines capability is not a one‑off drafting exercise but a governed, evidenced and continuously improved program. Start with a documented risk assessment, secure genuine board ownership, appoint a properly empowered compliance officer, and make beneficial ownership verification and STR quality your points of excellence, the very areas enforcement is targeting. Companies that treat AML compliance Philippines obligations as a living system, supported by clear records and independent testing, will not only satisfy the AMLC, BSP and SEC but will also protect their reputation and their commercial relationships. Use the checklist, timeline and templates above as your implementation baseline, and confirm entity‑specific requirements directly with the regulators before you file.
For related guidance, see the Commercial practice, Philippines page.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Danielle Marie C. Tan at Morales & Justiniano, a member of the Global Law Experts network.
posted 1 hour ago
posted 2 hours ago
posted 3 hours ago
posted 4 hours ago
posted 5 hours ago
posted 6 hours ago
posted 6 hours ago
posted 7 hours ago
posted 8 hours ago
posted 9 hours ago
posted 10 hours ago
posted 11 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message