Philippines KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Philippines.
- Last reviewed
- Last reviewed:
- Version
- Version 1.0

Portable implementation guide
Get the PDF checklist
11 control areas · 39 implementation checks
Last reviewed: 25 September 2026 · Version 1.0
Download the checklistDirect answer
What does the Philippines compliance checklist cover?
The Philippines checklist translates primary KYC, KYB and AML rules into 11 control areas and 39 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- FIU
- Anti-Money Laundering Council (AMLC)
- Primary AML rules
- AMLA, as amended, implementing rules and sector-supervisor regulations
- CTR / STR timing
- Generally within 5 working days from occurrence; AMLC may prescribe a different period not exceeding 15 working days
- General covered transaction
- Cash or equivalent monetary instrument exceeding PHP 500,000 within 1 banking day; separate sector thresholds apply
- AML retention
- Generally 5 years, with transaction, account-closure or relationship-end triggers depending on record type
- Banking BO test
- 20% is an ownership indicator, followed by control-by-other-means and senior-managing-official fallback
- Privacy breach
- Notify the NPC and affected data subjects within 72 hours when the mandatory-notification test is met
- FATF public lists
- Not listed at 19 June 2026; exited increased monitoring on 21 February 2025
Implementation detail
Philippines compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingClassify the entity, activity and competent supervisor before relying on a control or launching a service.4 items+
Determine whether each activity is performed by a covered person.
- Implementation action
- Map financial institutions, securities and insurance businesses, casinos, designated non-financial businesses and professions, real-estate developers and brokers, and other in-scope activities to the current AMLA and implementing rules; document exclusions and the supervising authority.
- Evidence to retain
- Entity chart, activity and funds-flow inventory, statutory mapping, supervisor analysis and counsel sign-off.
- Primary citation
- AMLA, section 3(a), as amended; 2018 IRR, Rule 4, as amended
Register with the AMLC where the covered-person rules require it.
- Implementation action
- Complete current covered-person registration, appoint authorised users and compliance personnel, maintain AMLC portal access and keep registration particulars current before filing reports.
- Evidence to retain
- Certificate or provisional certificate of registration, appointments, portal enrolment, user-access review and change log.
- Primary citation
- AMLA, sections 7 and 9; AMLC covered-person registration requirements
Obtain each sector licence or registration before regulated activity.
- Implementation action
- Confirm BSP, SEC, Insurance Commission, PAGCOR or other applicable authority requirements for the actual service, including payment-system operation, merchant acquisition, money service, casino and financial-product activity.
- Evidence to retain
- Perimeter memorandum, application, licence or registration, conditions, regulator correspondence and renewal calendar.
- Primary citation
- Applicable sector law and supervisor issuance; National Payment Systems Act and current BSP payment rules where applicable
Do not treat offshore gaming as a licensable AMLA activity.
- Implementation action
- Block any business model involving prohibited offshore gaming, POGO content, services, hubs or facilitation; treat detected activity as a legal and suspicious-transaction escalation, not as a registration opportunity.
- Evidence to retain
- Product prohibition, customer and merchant screening, escalation record, exit decision and STR assessment.
- Primary citation
- Republic Act No. 12312, sections 4, 5 and 8
02Governance and ML/TF/PF risk assessmentThe programme must be risk-based, approved, resourced and tested for the entity's actual exposure.3 items+
Maintain a documented institutional ML, TF and PF risk assessment.
- Implementation action
- Assess customers, countries, products, services, transactions, delivery channels, technology and outsourcing and update the assessment before material change and when official risk information changes.
- Evidence to retain
- Methodology, current assessment, data sources, approval, residual-risk decisions and remediation plan.
- Primary citation
- 2018 IRR, Rules 15 and 16, as amended; applicable sector-supervisor AML rules
Maintain an approved prevention programme and accountable compliance function.
- Implementation action
- Assign board and senior-management oversight and a sufficiently independent compliance officer; document controls for CDD, monitoring, reporting, sanctions, records, training and regulatory response.
- Evidence to retain
- Approved programme, appointments, committee minutes, reporting packs, training and issue log.
- Primary citation
- AMLA, section 9; 2018 IRR, Rule 16, as amended
Independently test programme design and operation.
- Implementation action
- Use a risk-based audit scope and competent reviewers to test customer files, beneficial ownership, reporting clocks, sanctions, data quality and remediation to verified closure.
- Evidence to retain
- Audit plan, independence assessment, sample record, findings, management response and closure tests.
- Primary citation
- 2018 IRR, Rule 16, as amended; applicable BSP, SEC, IC or PAGCOR rules
03Natural-person identificationCDD applies at relationship, relevant occasional-transaction, suspicion and prior-data-doubt triggers.4 items+
Identify and verify every natural-person customer using reliable sources.
- Implementation action
- Collect the prescribed identity attributes, verify official identity evidence or other reliable independent data, resolve inconsistencies and prohibit anonymous or fictitious-name accounts.
- Evidence to retain
- Customer record, identity evidence, source provenance, verification result, timestamp and discrepancy resolution.
- Primary citation
- AMLA, section 9(a); 2018 IRR, Rules 17 and 18; BSP MORB section 921 for BSP-supervised institutions
Apply the correct CDD trigger and threshold.
- Implementation action
- Configure relationship opening, relevant occasional transactions, suspicion and doubt about prior identification; for BSP-supervised institutions apply the current relevant-business-transaction thresholds and linked-transaction aggregation without generalising them to other sectors.
- Evidence to retain
- Sector trigger matrix, aggregation logic, tested scenarios, rule version and exceptions.
- Primary citation
- 2018 IRR, Rule 18; BSP MORB section 921(b)-(d)
Verify representatives and authority.
- Implementation action
- Identify and verify each person acting for a customer and establish the mandate and its limits before accepting instructions or granting access.
- Evidence to retain
- Representative KYC, authority document, verification result, scope limits and activity log.
- Primary citation
- AMLA, section 9(a); 2018 IRR, Rule 18
Control failed CDD and tipping-off risk.
- Implementation action
- Where required CDD cannot be completed, do not open or perform the transaction, or terminate the relationship as the applicable rule requires, and consider an STR. If continuing CDD would tip off the customer, stop that inquiry and follow the authorised STR and monitoring procedure.
- Evidence to retain
- CDD gap, restriction or exit record, decision approval, suspicion assessment and filing receipt where applicable.
- Primary citation
- 2018 IRR, Rule 18; BSP MORB section 921(a)
04KYB, registries, and beneficial ownershipVerify legal existence, authorised persons, ownership and control; keep AML tests separate from corporate disclosure.4 items+
Verify legal-person or arrangement identity and existence.
- Implementation action
- Obtain current registration, constitutional, address, business-purpose, officer, partner, trustee and authority information from the SEC, another competent registry and reliable independent sources.
- Evidence to retain
- Registry extract, constitutional documents, licences, officer list, mandates and discrepancy log.
- Primary citation
- AMLA, section 9(a); 2018 IRR, Rule 18
Identify the natural persons who ultimately own or control the customer.
- Implementation action
- Trace the ownership chain and control by other means. For BSP-supervised institutions, treat at least 20% ownership as an ownership indicator, then apply control-by-other-means and senior-managing-official fallback rules; do not export that sector formulation without checking the governing rule.
- Evidence to retain
- Layered ownership chart, percentage calculations, registry evidence, control analysis, verified identities and fallback rationale.
- Primary citation
- BSP MORB definition of beneficial owner and section 921(a); 2018 IRR, Rule 18
Identify relevant legal-arrangement parties.
- Implementation action
- For trusts and comparable arrangements, identify and verify the trustee or equivalent, settlor, beneficiaries or classes, protectors and every other natural person exercising ultimate effective control as the applicable rule requires.
- Evidence to retain
- Trust deed, party schedule, control powers, entitlement analysis and verified identities.
- Primary citation
- 2018 IRR, Rule 18; applicable sector-supervisor CDD rules
Maintain current SEC beneficial-ownership disclosures separately.
- Implementation action
- Apply SEC Memorandum Circular No. 15, series of 2025, and the current HARBOR Beneficial Ownership Declaration process; reconcile filings to the customer file but do not treat a filing as conclusive AML ownership evidence.
- Evidence to retain
- BO analysis, declarations, HARBOR receipt, annual filing, change log and discrepancy escalation.
- Primary citation
- SEC Memorandum Circular No. 15, series of 2025; SEC 2026 reportorial requirements
05PEPs, enhanced due diligence, and remote onboardingPolitical exposure, higher risk and non-face-to-face delivery require stronger, documented measures.3 items+
Identify relevant politically exposed persons and relationships.
- Implementation action
- Screen customers and beneficial owners for domestic, foreign and international-organisation PEP status and applicable immediate-family and close-associate relationships; refresh results risk-sensitively.
- Evidence to retain
- Screening result, source, relationship map, rationale and refresh history.
- Primary citation
- 2018 IRR, Rule 18; BSP MORB section 923 for BSP-supervised institutions
Apply enhanced due diligence when risk or the applicable rule requires it.
- Implementation action
- Obtain required senior approval, corroborate source of wealth and source of funds, obtain additional purpose information and increase monitoring frequency and depth.
- Evidence to retain
- Trigger, approval, source corroboration, enhanced monitoring plan and periodic reviews.
- Primary citation
- 2018 IRR, Rule 18; BSP MORB section 923
Control remote identity and biometric risk.
- Implementation action
- Validate document authenticity, liveness, impersonation and device risk; assess the legal basis, necessity, proportionality and security of biometric processing before use.
- Evidence to retain
- Method assessment, fraud tests, consent or other lawful basis, privacy impact assessment, vendor diligence and exceptions.
- Primary citation
- Data Privacy Act, sections 12, 13 and 20; NPC Circular No. 2023-06; applicable sector e-KYC rules
06Monitoring and suspicious transaction reportingMonitor against expected activity and report suspicion to the AMLC without waiting for a monetary threshold.4 items+
Conduct ongoing due diligence and transaction monitoring.
- Implementation action
- Keep identity, ownership and risk information current and scrutinise activity against the customer's profile, purpose, capacity and expected source of funds; investigate deviations promptly.
- Evidence to retain
- Monitoring scenarios, alerts, case analysis, refresh record and dispositions.
- Primary citation
- 2018 IRR, Rule 18; BSP MORB section 921(a)
Identify suspicious transactions and attempts regardless of amount.
- Implementation action
- Assess the statutory indicators, including no lawful purpose, failed identification, inconsistency with capacity or profile, structuring and connection to unlawful activity; include unsuccessful attempts where the rule applies.
- Evidence to retain
- Alert chronology, facts reviewed, indicator mapping, decision-maker and outcome.
- Primary citation
- AMLA, section 3(b-1); applicable implementing and sector rules
File CTRs and STRs within the applicable reporting clock.
- Implementation action
- Submit through the current AMLC electronic route generally within five working days from occurrence, subject to any current AMLC-prescribed alternative not exceeding fifteen working days. For an STR, record when suspicious nature was determined and apply the sector rule governing that determination period.
- Evidence to retain
- Occurrence and decision timestamps, report, validation output, AMLC acknowledgement and any supplemental submission.
- Primary citation
- AMLA, section 9(c); BSP MORB section 922; current AMLC portal and reporting notices
Protect report confidentiality and prevent tipping off.
- Implementation action
- Restrict CTR, STR, suspicion and AMLC-request information to authorised need-to-know access and review every disclosure against the statutory safe harbour and prohibition.
- Evidence to retain
- Access matrix, disclosure log, legal review, training and incident record.
- Primary citation
- AMLA, section 9(c)
07Threshold reports, wires, payments, and virtual assetsAmounts, aggregation, report type and licensing are activity-specific.4 items+
Apply the general covered-transaction threshold only to its statutory scope.
- Implementation action
- Report cash or equivalent monetary-instrument transactions exceeding PHP 500,000 within one banking day when the general rule applies; aggregate as required and keep the amount distinct from CDD or sector thresholds.
- Evidence to retain
- Transaction data, aggregation result, scope analysis, CTR and AMLC acknowledgement.
- Primary citation
- AMLA, section 3(b), as amended
Apply casino and real-estate thresholds only to those covered persons.
- Implementation action
- For casinos assess a single casino cash transaction exceeding PHP 5 million; for real-estate developers and brokers assess a single cash transaction exceeding PHP 7.5 million. Do not apply either amount outside its statutory sector and transaction type.
- Evidence to retain
- Sector classification, cash evidence, threshold calculation, report and exception analysis.
- Primary citation
- AMLA, section 3(b), as amended by Republic Act No. 11521; Republic Act No. 10927 for casinos
Carry required originator and beneficiary information through wire transfers.
- Implementation action
- For BSP-supervised institutions, collect, validate and transmit the fields required for transfers below and at or above PHP 50,000, preserve traceability and repair, reject or restrict incomplete transfers according to the governing rule.
- Evidence to retain
- Field matrix, payment-message samples, validation tests, repair queue and rejection record.
- Primary citation
- BSP MORB section 923, fund/wire transfer provisions
Obtain current payment and virtual-asset authority before launch.
- Implementation action
- Register as an operator of payment systems and obtain a merchant-acquisition licence where applicable. For VASP activity, assess BSP Circular No. 1108, current MORNBFI rules and the continuing new-licence moratorium before making any availability claim.
- Evidence to retain
- Service and funds-flow map, OPS registration, merchant-acquisition licence, VASP legal analysis, authority and conditions.
- Primary citation
- National Payment Systems Act; BSP Circular Nos. 1049, 1108 and 1198; BSP Memorandum No. M-2025-031
08Targeted financial sanctionsSanctions controls must detect designated persons, ownership and control and support immediate preservation.3 items+
Screen relevant persons and transactions against current designations.
- Implementation action
- Screen customers, beneficial owners, controllers, representatives and transactions at onboarding, during the relationship and when UN, AMLC or Anti-Terrorism Council designations change; assess indirect ownership and control.
- Evidence to retain
- List inventory, update logs, configuration tests, match analysis and disposition.
- Primary citation
- Republic Act No. 10168; Republic Act No. 11479; AMLA section 10(b) as amended
Freeze and preserve covered property without delay.
- Implementation action
- On an applicable designation or freeze order, immediately block dealing and availability, preserve the specified and related property, follow the current AMLC return and notification route and release only under verified authority.
- Evidence to retain
- Match and ownership-control analysis, freeze timestamp, return or report, system blocks and authority correspondence.
- Primary citation
- Republic Act No. 10168, sections 11 and 16; Republic Act No. 11479, section 36; AMLA section 10(b)
Maintain distinct terrorism- and proliferation-financing procedures.
- Implementation action
- Map the applicable designation, freeze, exemption, delisting and unfreezing route for terrorism and UN proliferation sanctions and test both direct and indirect availability scenarios.
- Evidence to retain
- Legal map, procedure, list-update record, scenario tests, training and escalation log.
- Primary citation
- Republic Act No. 10168; AMLA sections 3(o)-(p), 7(15) and 10(b), as amended by Republic Act No. 11521
09Records and regulator accessRecords must reconstruct identity, ownership, transactions and reporting from the correct retention trigger.3 items+
Retain transaction records for at least five years from the transaction date.
- Implementation action
- Preserve sufficient data and documents to reconstruct each transaction, subject to any longer legal hold, sector requirement or AMLC direction.
- Evidence to retain
- Retention schedule, archive sample, reconstruction test, holds and deletion approvals.
- Primary citation
- AMLA, section 9(b); BSP MORB section 924
Retain customer records from the correct relationship trigger.
- Implementation action
- Keep customer identification and transaction documents while the account exists and for at least five years after account closure, relationship termination or the occasional transaction, as applicable; preserve longer when a case remains unresolved.
- Evidence to retain
- Trigger calculations, customer archive, case hold, retrieval test and deletion log.
- Primary citation
- AMLA, section 9(b); BSP MORB section 924
Make records securely and promptly available to competent authorities.
- Implementation action
- Use stable identifiers and access controls so CDD, beneficial ownership, monitoring, reports, approvals and correspondence can be reconstructed and produced without delay through an authenticated route.
- Evidence to retain
- Sample case pack, access review, request register, production index and delivery receipt.
- Primary citation
- AMLA, sections 7 and 9; applicable sector-supervisor access rules
10Privacy, biometrics, breaches, and transfersKYC data remains subject to purpose, proportionality, security and accountability controls.4 items+
Document the lawful basis and proportionality of KYC processing.
- Implementation action
- Map each identity, biometric, screening and monitoring field to consent, legal obligation or another valid basis; provide the required notice, minimise collection and keep data accurate.
- Evidence to retain
- Data inventory, lawful-basis map, notices, consent where used, field justification and correction process.
- Primary citation
- Data Privacy Act, sections 11-13 and 16; DPA IRR
Conduct privacy impact assessment and implement current security measures.
- Implementation action
- Assess each personal-data processing system, designate accountable privacy personnel, maintain the required privacy management and incident programmes, and implement risk-appropriate organisational, physical and technical controls.
- Evidence to retain
- PIA, DPO and system registration analysis, privacy programme, access reviews, tests and training.
- Primary citation
- Data Privacy Act, section 20; NPC Circular Nos. 2022-04 and 2023-06
Notify qualifying personal-data breaches within 72 hours.
- Implementation action
- Assess the mandatory-notification test and notify the NPC and affected data subjects within 72 hours upon knowledge or reasonable belief that a notifiable breach occurred, using available information and documenting any authorised delay.
- Evidence to retain
- Incident chronology, risk assessment, NPC submission, data-subject notice, delay rationale and remediation.
- Primary citation
- DPA IRR, section 38; NPC Circular No. 16-03
Control processors and cross-border transfers.
- Implementation action
- Use contracts and due diligence to preserve confidentiality, security, incident cooperation, deletion and audit; remain accountable for transferred personal data and document the applicable recipient protections.
- Evidence to retain
- Vendor assessment, contract, subprocessor register, transfer map, safeguards and monitoring.
- Primary citation
- Data Privacy Act, sections 14 and 21; DPA IRR, sections 43-45
11Practical evidence packsEvidence should reproduce onboarding, reporting, sanctions and launch decisions end to end.3 items+
Maintain a reconstructable onboarding pack.
- Implementation action
- Bundle identity, representative authority, KYB, ownership and control, PEP and sanctions screening, risk, approvals, privacy records and exceptions under stable identifiers.
- Evidence to retain
- Complete sampled onboarding pack and retrieval result.
- Primary citation
- Operational control supporting AMLA section 9 and 2018 IRR Rule 18
Maintain a reconstructable reporting and sanctions pack.
- Implementation action
- Link transactions, alerts, analysis, occurrence and decision times, report, acknowledgement, supplements, freeze actions, authority communications and access logs.
- Evidence to retain
- Complete sampled case pack, timeline and controlled access log.
- Primary citation
- Operational control supporting AMLA sections 9(c) and 10 and Republic Act No. 10168
Maintain a regulator-scoped launch pack.
- Implementation action
- Record covered-person analysis, permissions, current sources, reporting readiness, BO filing, sanctions procedure, privacy registration scope, vendor controls, prohibited POGO screening and validation before launch or material change.
- Evidence to retain
- Signed launch pack, source register, regulator map, uncertainty log, tests and approvals.
- Primary citation
- Official sources listed below
Primary-source register
22 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Anti-Money Laundering Act of 2001Bangko Sentral ng Pilipinas · Primary legislation
- Republic Act No. 11521 - AMLA amendmentsLawphil · Primary legislation
- BSP regulations and current manuals indexBangko Sentral ng Pilipinas · Official regulatory index
- BSP AML/CFT Regulations - MORB Part IXBangko Sentral ng Pilipinas · Official supervisory regulation
- AMLC portal for registration and reportingAnti-Money Laundering Council · Official filing portal
- AMLC covered persons - other covered personsAnti-Money Laundering Council · Official perimeter and registration guidance
- Terrorism Financing Prevention and Suppression ActLawphil · Primary legislation
- Anti-Terrorism Act of 2020Lawphil · Primary legislation
- Anti-POGO Act of 2025Lawphil · Primary legislation
- BSP Circular No. 1108 - VASP guidelinesBangko Sentral ng Pilipinas · Official supervisory regulation
- BSP Memorandum No. M-2025-031 - continued VASP licence moratoriumBangko Sentral ng Pilipinas · Official supervisory issuance
- BSP payments and settlements regulatory frameworkBangko Sentral ng Pilipinas · Official regulatory guidance
- SEC Memorandum Circular No. 15, series of 2025Securities and Exchange Commission · Official beneficial-ownership rules
- SEC reportorial requirements for corporationsSecurities and Exchange Commission · Official registry guidance
- Data Privacy Act of 2012National Privacy Commission · Primary legislation
- Implementing Rules and Regulations of the Data Privacy ActNational Privacy Commission · Official regulation
- NPC advisories and circularsNational Privacy Commission · Official regulatory index
- FATF Philippines country profileFATF · Authoritative current assessment
- FATF Philippines exit from increased monitoring - 21 February 2025FATF · Authoritative status statement
- FATF jurisdictions under increased monitoring - 19 June 2026FATF · Authoritative current status
- FATF high-risk jurisdictions subject to a call for action - 19 June 2026FATF · Authoritative current status
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
Direct answers
Philippines KYC, KYB and AML questions
Who receives covered and suspicious transaction reports?+
The Anti-Money Laundering Council, the Philippines' financial intelligence unit, through its current authorised electronic reporting route.
When must an STR be filed?+
Generally within five working days from occurrence, subject to a different AMLC-prescribed period not exceeding fifteen working days. For suspicion, occurrence is tied to the determination of suspicious nature under the applicable sector rule, so the decision chronology must be recorded.
What is the general covered-transaction threshold?+
Cash or another equivalent monetary instrument exceeding PHP 500,000 within one banking day. Casinos and real-estate covered persons have separate statutory cash thresholds and transaction scopes.
Is there one universal CDD threshold?+
No. Relationship opening, suspicion and doubt about prior data can trigger CDD without a monetary threshold. Occasional-transaction thresholds are sector-specific and must not be confused with CTR amounts.
How is beneficial ownership determined?+
Trace ultimate ownership and control to natural persons. For BSP-supervised institutions, 20% ownership is an indicator, followed by control by other means and a senior-managing-official fallback. Current SEC disclosure is separate and does not replace AML CDD.
How long are AML records retained?+
Generally at least five years, but the clock differs by record: transaction date, account closure, relationship termination or occasional-transaction date. Records connected to an unresolved case may need longer preservation.
Can an offshore gaming operation obtain a Philippine licence?+
No. Republic Act No. 12312 bans offshore gaming operations and related services and revoked the authority to issue such licences. Older AMLA references do not create a lawful route.
Can a new VASP obtain a BSP licence?+
Do not assume so. BSP Memorandum No. M-2025-031 continued the moratorium on new VASP licences from 1 September 2025, subject to reassessment. Confirm current BSP policy before planning launch.
What happens on a sanctions match or freeze order?+
Confirm identifiers and ownership or control, immediately preserve covered property and prevent dealing as the applicable order and law require, file the current AMLC return or report and release only under verified authority.
When is a personal-data breach notified?+
When the mandatory-notification test is met, notify the NPC and affected data subjects within 72 hours upon knowledge or reasonable belief that the qualifying breach occurred, subject only to the limited authorised-delay rules.
Is the Philippines on a FATF public list?+
No. The Philippines exited increased monitoring on 21 February 2025 and was absent from both FATF public lists dated 19 June 2026. FATF asked it to sustain improvements with APG; absence from a list is not a low-risk finding.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 25 September 2026. Confirm the covered-person perimeter, current AMLC reporting specifications and portal notices, sector-supervisor rules, sanctions orders, licensing availability, SEC HARBOR filing requirements and privacy registration scope with the competent authority and qualified Philippine counsel before launch.