BSP Compliance Documentation for Financial Services in the Philippines
The Bangko Sentral ng Pilipinas requires extensive documentation from banks, NBFIs, and fintechs. Here's how to review your compliance documentation systematically.
The Bangko Sentral ng Pilipinas (BSP) regulates all banks, non-bank financial institutions (NBFIs), and an expanding range of fintech companies operating in the Philippines. BSP's regulatory framework — codified in the Manual of Regulations for Banks (MORB) and the Manual of Regulations for Non-Bank Financial Institutions (MORNBFI) — creates extensive documentation requirements across governance, risk management, AML/CFT, technology risk, consumer protection, and capital adequacy.
BSP has significantly modernised its regulatory approach, with particular focus on digital banking, open finance, cybersecurity, and financial inclusion. The licensing of digital banks, the issuance of the Open Finance Framework, and enhanced technology risk management circulars have created new documentation requirements for both traditional and digital financial institutions.
What BSP Requires
Key BSP Regulatory Frameworks
| Framework | Reference | Key Documentation |
|---|---|---|
| Corporate Governance | MORB Part II | Board charter, committee mandates, governance policies, fit and proper assessments |
| Risk Management | MORB Part III | Enterprise risk management framework, risk appetite statement, risk reporting |
| AML/CFT | MORB Part VIII / AMLA (as amended) | AML policy, CDD procedures, transaction monitoring, covered and suspicious transaction reporting |
| Technology Risk Management | BSP Circular 808 (and amendments) | IT governance, cybersecurity, IT audit, business continuity |
| Consumer Protection | BSP Circular 857 / Financial Consumer Protection Framework | Consumer assistance policy, complaint handling, product disclosure |
| Outsourcing | BSP Circular 899 | Outsourcing policy, risk assessment, contracts, notification |
| Capital Adequacy | MORB Part IV | Capital adequacy computation, stress testing, ICAAP |
| Digital Banking | BSP Circular 1105 | Digital bank-specific governance, technology, and operational requirements |
Technology Risk Management
BSP Circular 808 (as amended) establishes comprehensive technology risk requirements:
| Area | Documentation Required |
|---|---|
| IT governance | IT strategic plan, IT steering committee records, IT risk management framework |
| Information security | Information security policy, access control, encryption, network security |
| Cybersecurity | Cyber resilience framework, threat assessment, vulnerability management, incident response |
| IT operations | Change management, capacity planning, system administration procedures |
| IT audit | Annual IT risk assessment, IT audit plan and reports, findings tracking |
| Business continuity | IT disaster recovery plan, testing records, alternate site arrangements |
| Electronic banking | E-banking risk assessment, customer authentication, fraud management |
| Cloud computing | Cloud risk assessment, BSP notification, data residency compliance |
| Digital channels | Mobile banking security, API security, digital onboarding security |
AML/CFT Compliance
The Anti-Money Laundering Act (AMLA) as amended, and BSP's implementing rules require:
| Requirement | Documentation |
|---|---|
| Money Laundering and Terrorist Financing Prevention Programme (MTPP) | Board-approved comprehensive programme |
| Customer Due Diligence | Risk-based CDD procedures, customer risk rating methodology |
| Enhanced Due Diligence | EDD for high-risk customers — PEPs, high-risk jurisdictions, complex structures |
| Covered Transaction Reports (CTRs) | Reports for transactions exceeding PHP 500,000 (or equivalent) |
| Suspicious Transaction Reports (STRs) | STR procedures, filing with AMLC |
| Record keeping | All CDD and transaction records retained for minimum 5 years |
| Compliance officer | Designated AML compliance officer at senior management level |
| Training | AML/CFT training for all relevant officers and employees |
| Independent audit | Annual independent testing of the MTPP |
| Sanctions screening | Screening against UN, OFAC, and Philippine domestic sanctions lists |
Consumer Protection
BSP's Financial Consumer Protection Framework requires:
| Requirement | Documentation |
|---|---|
| Consumer Assistance Management System (CAMS) | Documented complaint handling process with prescribed timelines |
| Product disclosure | Product features, terms, fees, and risks disclosed before sale |
| Fair treatment | Policies ensuring fair treatment throughout the customer lifecycle |
| Financial literacy | Consumer education initiatives and documentation |
| Data privacy | Compliance with the Data Privacy Act of 2012 in customer data handling |
| Redress | Internal dispute resolution procedures, escalation to BSP if unresolved |
Common Compliance Failures
1. Technology Risk Documentation Gaps
- IT governance framework not aligned with the board-approved IT strategic plan
- Cybersecurity framework not covering threat intelligence and advanced persistent threats
- Penetration testing not conducted annually or scope too narrow
- IT audit findings not tracked to timely closure — recurring findings
- Cloud computing arrangements not notified to BSP as required
- Digital channel risk assessments not updated when new features are deployed
- IT disaster recovery testing not conducted or test results not documented
2. AML/CFT Deficiencies
- Customer risk rating methodology not documented or not applied consistently
- Transaction monitoring thresholds not calibrated to the institution's risk profile
- CTRs filed late or with incomplete information
- STR analysis and filing rationale not documented
- Sanctions screening gaps — not covering all required sanctions lists
- MTPP not updated for recent AMLA amendments
- Independent testing of MTPP not conducted annually
3. Governance Documentation Shortfalls
- Board committee mandates not covering all BSP-required responsibilities
- Fit and proper assessments for directors and senior officers incomplete or outdated
- Related party transaction governance inadequately documented
- Board risk reporting insufficient — particularly for technology and cybersecurity risk
- Minutes of board and committee meetings not evidencing adequate challenge and oversight
4. Consumer Protection Failures
- CAMS not meeting BSP-prescribed complaint resolution timelines
- Product disclosure documents not covering all required information
- Customer complaints register not maintained or not accessible for BSP examination
- Financial consumer protection policies not reviewed annually
- No documented procedure for handling customer data privacy requests
Building a BSP Compliance Documentation Review Process
Step 1: Regulatory Mapping
| BSP Requirement | Document | Owner | Last Reviewed | Status |
|---|---|---|---|---|
| IT governance | IT Strategic Plan | CTO | January 2026 | ✅ Current |
| Cybersecurity | Cyber Resilience Framework | CISO | November 2025 | ✅ Current |
| IT audit | IT Audit Report | Internal Audit | September 2025 | ⚠️ Annual audit due |
| AML/CFT | MTPP | Chief Compliance Officer | October 2025 | ✅ Current |
| AML/CFT | Independent MTPP Testing | External Auditor | June 2025 | ⚠️ Annual testing due |
| Corporate Governance | Board Charter | Corporate Secretary | August 2025 | ✅ Current |
| Consumer Protection | CAMS Policy | Customer Service Head | December 2025 | ✅ Current |
| Outsourcing | Outsourcing Policy | Risk | July 2025 | ⚠️ New outsourcing arrangement not assessed |
| Cloud computing | Cloud Risk Assessment | IT Risk | May 2025 | ❌ Overdue — new cloud service added |
Step 2: Implement Review Cycles
| Document Type | Review Frequency | Triggered Review |
|---|---|---|
| Technology risk policies | Annually | BSP circular, significant incident, IT audit finding |
| AML/CFT (MTPP) | Annually | AMLA amendment, AMLC guidance, audit finding |
| Governance documents | Annually | Board composition change, BSP guidance |
| Consumer protection | Annually | Complaint trend analysis, BSP feedback |
| Cloud risk assessments | Annually per arrangement | New cloud service, provider incident |
| IT disaster recovery | Annually (plan) + annually (testing) | Significant infrastructure change, test findings |
Step 3: Pre-Examination Preparation
BSP conducts regular examinations. Before any examination:
- All policies and procedures current and board-approved where required
- IT audit findings tracked with management responses and closure evidence
- AML/CFT — MTPP current, CTRs and STRs filed on time, independent testing completed
- Consumer complaints register current with resolution timelines documented
- Governance documentation current — board and committee minutes available
- Technology risk documentation covering all BSP Circular 808 requirements
- Outsourcing arrangements documented and BSP-notified where required
- Capital adequacy reports current
Using AI to Review BSP Compliance Documentation
Practical Example
In TeamBench, you could configure a reviewer:
Reviewer name: BSP Compliance Documentation Reviewer
System prompt:
You are a BSP compliance documentation reviewer for Philippine financial institutions. Review policies, procedures, risk assessments, and governance documents against the Manual of Regulations for Banks (MORB), BSP circulars (particularly Circular 808 for technology risk), AMLA requirements, and the Financial Consumer Protection Framework. Check for: completeness (all BSP-required elements addressed), consistency (no contradictions across documents), currency (current BSP circular references), specificity (tailored to the institution), and governance quality (board and committee documentation evidencing oversight). Flag specific gaps with the BSP regulation or circular reference. Use Philippine English.
Evaluation criteria:
- Regulatory Completeness (weight: 3) — All applicable BSP requirements addressed
- Consistency (weight: 3) — No contradictions across documents
- Currency (weight: 2) — Current BSP circulars and AMLA provisions referenced
- Specificity (weight: 2) — Tailored to the institution, not generic templates
- Structure (weight: 1) — Professional presentation, clear organisation
Quality gate: Minimum score: 85.
Upload relevant BSP circulars, MORB sections, and your institution's risk management framework into a Knowledge Base.
Frequently Asked Questions
How does BSP conduct examinations?
BSP uses a risk-based supervisory approach: off-site surveillance (analysis of regulatory reports), on-site examinations (scheduled, covering specific risk areas), thematic examinations (industry-wide assessments), and supervisory enforcement actions. Examination frequency depends on the institution's risk profile and systemic importance.
What are the penalties for BSP non-compliance?
BSP can impose: monetary penalties (fines per day of violation), cease and desist orders, suspension of operations, revocation of banking licence, and sanctions against directors and officers (including disqualification). For AML/CFT violations, penalties under AMLA include imprisonment and substantial fines.
Does BSP regulate fintech companies?
BSP regulates fintech companies based on their activities: digital banks (licensed under Circular 1105), electronic money issuers (EMIs), virtual asset service providers (VASPs), and operators of payment systems (OPS). Each category has specific licensing and compliance documentation requirements.
How do we handle BSP notification for cloud computing?
BSP requires prior notification (not approval) for material cloud outsourcing arrangements. The notification should include: description of the cloud service, cloud service provider details, risk assessment results, data residency arrangements, and contractual safeguards. BSP may raise concerns that must be addressed before proceeding.
What's the timeline for filing CTRs and STRs?
CTRs must be filed within 5 business days of the transaction. STRs must be filed within 5 business days of the determination of suspicion. Late filing attracts penalties. Document the analysis timeline for STRs — the clock starts from when you determine the transaction is suspicious, not from the transaction date.
How do digital banks differ in documentation requirements?
Digital banks must meet all standard BSP requirements plus additional Circular 1105 requirements: enhanced technology risk governance, digital-native customer onboarding documentation, technology infrastructure resilience documentation, and financial inclusion strategy documentation. The documentation burden is essentially higher than for traditional banks.
Key Takeaways
- BSP's regulatory framework spans governance, risk management, AML/CFT, technology risk, consumer protection, and capital adequacy — each with specific documentation requirements.
- Technology risk management (Circular 808) is a major supervisory focus — covering IT governance, cybersecurity, cloud computing, and digital channel security.
- AML/CFT compliance under AMLA requires a comprehensive MTPP, risk-based CDD, CTR/STR filing, sanctions screening, and annual independent testing.
- Common failures include technology risk documentation gaps, AML/CFT deficiencies, governance shortfalls, and consumer protection non-compliance.
- Map every document to its BSP regulation and track review dates, owners, and status.
- Digital banks and fintechs face enhanced documentation requirements on top of standard BSP expectations.
- AI-assisted review can check completeness, consistency, currency, and specificity across your documentation portfolio, but cannot replace BSP regulatory judgement or security testing.
- Implement annual review cycles aligned with BSP examination schedules and triggered reviews for circular updates.
This article provides general information about BSP compliance documentation requirements and is not regulatory or legal advice. Always consult the Bangko Sentral ng Pilipinas for current regulations and seek qualified compliance advice for your specific situation.