Skip to content
TB
TeamBenchResources

BSP Compliance Documentation for Financial Services in the Philippines

The Bangko Sentral ng Pilipinas requires extensive documentation from banks, NBFIs, and fintechs. Here's how to review your compliance documentation systematically.

TeamBench· Content Quality PlatformFebruary 9, 202611 min read

The Bangko Sentral ng Pilipinas (BSP) regulates all banks, non-bank financial institutions (NBFIs), and an expanding range of fintech companies operating in the Philippines. BSP's regulatory framework — codified in the Manual of Regulations for Banks (MORB) and the Manual of Regulations for Non-Bank Financial Institutions (MORNBFI) — creates extensive documentation requirements across governance, risk management, AML/CFT, technology risk, consumer protection, and capital adequacy.

BSP has significantly modernised its regulatory approach, with particular focus on digital banking, open finance, cybersecurity, and financial inclusion. The licensing of digital banks, the issuance of the Open Finance Framework, and enhanced technology risk management circulars have created new documentation requirements for both traditional and digital financial institutions.

What BSP Requires

Key BSP Regulatory Frameworks

FrameworkReferenceKey Documentation
Corporate GovernanceMORB Part IIBoard charter, committee mandates, governance policies, fit and proper assessments
Risk ManagementMORB Part IIIEnterprise risk management framework, risk appetite statement, risk reporting
AML/CFTMORB Part VIII / AMLA (as amended)AML policy, CDD procedures, transaction monitoring, covered and suspicious transaction reporting
Technology Risk ManagementBSP Circular 808 (and amendments)IT governance, cybersecurity, IT audit, business continuity
Consumer ProtectionBSP Circular 857 / Financial Consumer Protection FrameworkConsumer assistance policy, complaint handling, product disclosure
OutsourcingBSP Circular 899Outsourcing policy, risk assessment, contracts, notification
Capital AdequacyMORB Part IVCapital adequacy computation, stress testing, ICAAP
Digital BankingBSP Circular 1105Digital bank-specific governance, technology, and operational requirements

Technology Risk Management

BSP Circular 808 (as amended) establishes comprehensive technology risk requirements:

AreaDocumentation Required
IT governanceIT strategic plan, IT steering committee records, IT risk management framework
Information securityInformation security policy, access control, encryption, network security
CybersecurityCyber resilience framework, threat assessment, vulnerability management, incident response
IT operationsChange management, capacity planning, system administration procedures
IT auditAnnual IT risk assessment, IT audit plan and reports, findings tracking
Business continuityIT disaster recovery plan, testing records, alternate site arrangements
Electronic bankingE-banking risk assessment, customer authentication, fraud management
Cloud computingCloud risk assessment, BSP notification, data residency compliance
Digital channelsMobile banking security, API security, digital onboarding security

AML/CFT Compliance

The Anti-Money Laundering Act (AMLA) as amended, and BSP's implementing rules require:

RequirementDocumentation
Money Laundering and Terrorist Financing Prevention Programme (MTPP)Board-approved comprehensive programme
Customer Due DiligenceRisk-based CDD procedures, customer risk rating methodology
Enhanced Due DiligenceEDD for high-risk customers — PEPs, high-risk jurisdictions, complex structures
Covered Transaction Reports (CTRs)Reports for transactions exceeding PHP 500,000 (or equivalent)
Suspicious Transaction Reports (STRs)STR procedures, filing with AMLC
Record keepingAll CDD and transaction records retained for minimum 5 years
Compliance officerDesignated AML compliance officer at senior management level
TrainingAML/CFT training for all relevant officers and employees
Independent auditAnnual independent testing of the MTPP
Sanctions screeningScreening against UN, OFAC, and Philippine domestic sanctions lists

Consumer Protection

BSP's Financial Consumer Protection Framework requires:

RequirementDocumentation
Consumer Assistance Management System (CAMS)Documented complaint handling process with prescribed timelines
Product disclosureProduct features, terms, fees, and risks disclosed before sale
Fair treatmentPolicies ensuring fair treatment throughout the customer lifecycle
Financial literacyConsumer education initiatives and documentation
Data privacyCompliance with the Data Privacy Act of 2012 in customer data handling
RedressInternal dispute resolution procedures, escalation to BSP if unresolved

Common Compliance Failures

1. Technology Risk Documentation Gaps

  • IT governance framework not aligned with the board-approved IT strategic plan
  • Cybersecurity framework not covering threat intelligence and advanced persistent threats
  • Penetration testing not conducted annually or scope too narrow
  • IT audit findings not tracked to timely closure — recurring findings
  • Cloud computing arrangements not notified to BSP as required
  • Digital channel risk assessments not updated when new features are deployed
  • IT disaster recovery testing not conducted or test results not documented

2. AML/CFT Deficiencies

  • Customer risk rating methodology not documented or not applied consistently
  • Transaction monitoring thresholds not calibrated to the institution's risk profile
  • CTRs filed late or with incomplete information
  • STR analysis and filing rationale not documented
  • Sanctions screening gaps — not covering all required sanctions lists
  • MTPP not updated for recent AMLA amendments
  • Independent testing of MTPP not conducted annually

3. Governance Documentation Shortfalls

  • Board committee mandates not covering all BSP-required responsibilities
  • Fit and proper assessments for directors and senior officers incomplete or outdated
  • Related party transaction governance inadequately documented
  • Board risk reporting insufficient — particularly for technology and cybersecurity risk
  • Minutes of board and committee meetings not evidencing adequate challenge and oversight

4. Consumer Protection Failures

  • CAMS not meeting BSP-prescribed complaint resolution timelines
  • Product disclosure documents not covering all required information
  • Customer complaints register not maintained or not accessible for BSP examination
  • Financial consumer protection policies not reviewed annually
  • No documented procedure for handling customer data privacy requests

Building a BSP Compliance Documentation Review Process

Step 1: Regulatory Mapping

BSP RequirementDocumentOwnerLast ReviewedStatus
IT governanceIT Strategic PlanCTOJanuary 2026✅ Current
CybersecurityCyber Resilience FrameworkCISONovember 2025✅ Current
IT auditIT Audit ReportInternal AuditSeptember 2025⚠️ Annual audit due
AML/CFTMTPPChief Compliance OfficerOctober 2025✅ Current
AML/CFTIndependent MTPP TestingExternal AuditorJune 2025⚠️ Annual testing due
Corporate GovernanceBoard CharterCorporate SecretaryAugust 2025✅ Current
Consumer ProtectionCAMS PolicyCustomer Service HeadDecember 2025✅ Current
OutsourcingOutsourcing PolicyRiskJuly 2025⚠️ New outsourcing arrangement not assessed
Cloud computingCloud Risk AssessmentIT RiskMay 2025❌ Overdue — new cloud service added

Step 2: Implement Review Cycles

Document TypeReview FrequencyTriggered Review
Technology risk policiesAnnuallyBSP circular, significant incident, IT audit finding
AML/CFT (MTPP)AnnuallyAMLA amendment, AMLC guidance, audit finding
Governance documentsAnnuallyBoard composition change, BSP guidance
Consumer protectionAnnuallyComplaint trend analysis, BSP feedback
Cloud risk assessmentsAnnually per arrangementNew cloud service, provider incident
IT disaster recoveryAnnually (plan) + annually (testing)Significant infrastructure change, test findings

Step 3: Pre-Examination Preparation

BSP conducts regular examinations. Before any examination:

  • All policies and procedures current and board-approved where required
  • IT audit findings tracked with management responses and closure evidence
  • AML/CFT — MTPP current, CTRs and STRs filed on time, independent testing completed
  • Consumer complaints register current with resolution timelines documented
  • Governance documentation current — board and committee minutes available
  • Technology risk documentation covering all BSP Circular 808 requirements
  • Outsourcing arrangements documented and BSP-notified where required
  • Capital adequacy reports current

Using AI to Review BSP Compliance Documentation

Practical Example

In TeamBench, you could configure a reviewer:

Reviewer name: BSP Compliance Documentation Reviewer

System prompt:

You are a BSP compliance documentation reviewer for Philippine financial institutions. Review policies, procedures, risk assessments, and governance documents against the Manual of Regulations for Banks (MORB), BSP circulars (particularly Circular 808 for technology risk), AMLA requirements, and the Financial Consumer Protection Framework. Check for: completeness (all BSP-required elements addressed), consistency (no contradictions across documents), currency (current BSP circular references), specificity (tailored to the institution), and governance quality (board and committee documentation evidencing oversight). Flag specific gaps with the BSP regulation or circular reference. Use Philippine English.

Evaluation criteria:

  • Regulatory Completeness (weight: 3) — All applicable BSP requirements addressed
  • Consistency (weight: 3) — No contradictions across documents
  • Currency (weight: 2) — Current BSP circulars and AMLA provisions referenced
  • Specificity (weight: 2) — Tailored to the institution, not generic templates
  • Structure (weight: 1) — Professional presentation, clear organisation

Quality gate: Minimum score: 85.

Upload relevant BSP circulars, MORB sections, and your institution's risk management framework into a Knowledge Base.

Frequently Asked Questions

How does BSP conduct examinations?

BSP uses a risk-based supervisory approach: off-site surveillance (analysis of regulatory reports), on-site examinations (scheduled, covering specific risk areas), thematic examinations (industry-wide assessments), and supervisory enforcement actions. Examination frequency depends on the institution's risk profile and systemic importance.

What are the penalties for BSP non-compliance?

BSP can impose: monetary penalties (fines per day of violation), cease and desist orders, suspension of operations, revocation of banking licence, and sanctions against directors and officers (including disqualification). For AML/CFT violations, penalties under AMLA include imprisonment and substantial fines.

Does BSP regulate fintech companies?

BSP regulates fintech companies based on their activities: digital banks (licensed under Circular 1105), electronic money issuers (EMIs), virtual asset service providers (VASPs), and operators of payment systems (OPS). Each category has specific licensing and compliance documentation requirements.

How do we handle BSP notification for cloud computing?

BSP requires prior notification (not approval) for material cloud outsourcing arrangements. The notification should include: description of the cloud service, cloud service provider details, risk assessment results, data residency arrangements, and contractual safeguards. BSP may raise concerns that must be addressed before proceeding.

What's the timeline for filing CTRs and STRs?

CTRs must be filed within 5 business days of the transaction. STRs must be filed within 5 business days of the determination of suspicion. Late filing attracts penalties. Document the analysis timeline for STRs — the clock starts from when you determine the transaction is suspicious, not from the transaction date.

How do digital banks differ in documentation requirements?

Digital banks must meet all standard BSP requirements plus additional Circular 1105 requirements: enhanced technology risk governance, digital-native customer onboarding documentation, technology infrastructure resilience documentation, and financial inclusion strategy documentation. The documentation burden is essentially higher than for traditional banks.

Key Takeaways

  • BSP's regulatory framework spans governance, risk management, AML/CFT, technology risk, consumer protection, and capital adequacy — each with specific documentation requirements.
  • Technology risk management (Circular 808) is a major supervisory focus — covering IT governance, cybersecurity, cloud computing, and digital channel security.
  • AML/CFT compliance under AMLA requires a comprehensive MTPP, risk-based CDD, CTR/STR filing, sanctions screening, and annual independent testing.
  • Common failures include technology risk documentation gaps, AML/CFT deficiencies, governance shortfalls, and consumer protection non-compliance.
  • Map every document to its BSP regulation and track review dates, owners, and status.
  • Digital banks and fintechs face enhanced documentation requirements on top of standard BSP expectations.
  • AI-assisted review can check completeness, consistency, currency, and specificity across your documentation portfolio, but cannot replace BSP regulatory judgement or security testing.
  • Implement annual review cycles aligned with BSP examination schedules and triggered reviews for circular updates.

This article provides general information about BSP compliance documentation requirements and is not regulatory or legal advice. Always consult the Bangko Sentral ng Pilipinas for current regulations and seek qualified compliance advice for your specific situation.

bspcompliancefinancial-servicesbankingdocumentationphilippines

Need consistent content quality across your team?

TeamBench lets you create custom AI reviewers that score content against your specific criteria. Submit content, get instant scored feedback, and improve with one click.

  • Create custom AI reviewers for your brand
  • Score content against your specific criteria
  • Instant feedback, one-click improvement
  • Free to start — no credit card required