
Know Your Customer obligations in the Philippines sit across several statutes and a set of BSP issuances that have changed meaningfully in recent years, most significantly to permit electronic verification that previously required a branch visit.
This guide sets out who the obligations apply to, what they require in practice, what the consequences of getting it wrong look like, and where automation genuinely helps rather than simply moving the work.
This is general guidance, not legal advice. Regulatory issuances are updated regularly. Confirm current requirements with the BSP, the AMLC, or your own counsel before relying on anything here.
Who the obligations apply to
The reach is wider than most businesses assume. It is not only banks.
- BSP-supervised financial institutions — universal, commercial, thrift, rural and cooperative banks, and digital banks.
- Non-bank financial institutions under BSP supervision, including e-money issuers.
- Virtual asset service providers.
- Lending and financing companies regulated by the SEC.
- Other covered persons under the Anti-Money Laundering Act, including insurance companies and certain designated non-financial businesses and professions.
If your business opens accounts, extends credit, holds customer funds, or facilitates transfers, assume KYC obligations apply until you confirm otherwise.
The legal framework
Anti-Money Laundering Act (RA 9160, as amended)
The foundation. Covered persons must identify and record the true identity of their customers, permanent or occasional, natural or juridical, and must report certain transactions to the Anti-Money Laundering Council.
BSP Circular 1170
Amended the customer due diligence provisions of the Manual of Regulations for Banks and its non-bank equivalent. It establishes a risk-based approach to due diligence and sets out guidelines for electronic KYC using a digital ID system. This is the issuance that makes remote onboarding viable.
Philippine Identification System Act (RA 11055)
Established PhilSys. Under the BSP's rules, a person's PhilSys record is recognised as official and sufficient proof of identity in physical or digital form, authenticated against the PhilSys Card Number or its derivatives together with a biometric or demographic factor. Institutions wanting to use PhilSys-enabled e-KYC must first meet the Philippine Statistics Authority's requirements for relying parties.
Terrorism Financing Prevention and Suppression Act (RA 10168)
Extends the framework to terrorism financing and gives the AMLC investigative and asset-freezing powers. In practice, this means monitoring systems must be designed to flag terrorism-financing indicators, not only money-laundering patterns.
Data Privacy Act (RA 10173)
Runs alongside the rest. Identity documents and biometric data are personal information, and collecting them for KYC does not exempt you from obligations around storage, access, retention and breach notification.
What customer due diligence requires in practice
At onboarding
- Identify the customer and verify that identity against a valid, acceptable identification document.
- For corporate customers, establish beneficial ownership and verify it — not only the entity but the people behind it.
- Establish the purpose and intended nature of the relationship.
- Assign a risk rating that determines the depth of due diligence applied.
Enhanced due diligence
Higher-risk customers require more. Common triggers include politically exposed persons, non-residents, customers with complex or opaque ownership structures, and relationships involving higher-risk jurisdictions. Enhanced due diligence means deeper verification, senior approval, and closer ongoing scrutiny.
When due diligence cannot be completed
This is the provision most often overlooked. If a covered person is unable to complete the required due diligence measures, it must not open the account, commence the relationship or perform the transaction, or must terminate an existing relationship. It should also consider filing a suspicious transaction report. Proceeding anyway, on the basis that the customer seems legitimate, is itself the breach.
Ongoing monitoring
KYC is not a one-time gate. Customer profiles must be kept current and transaction patterns monitored so that activity inconsistent with the profile can be identified. A customer verified correctly three years ago and never reviewed since is not a compliant relationship.
Reporting
- Covered transactions above the prescribed threshold, currently PHP 500,000, must be reported to the AMLC.
- Suspicious transactions must be reported regardless of amount.
- Records must be retained for the period prescribed and produced on request.
What non-compliance costs
The penalties under the AMLA include substantial fines and imprisonment, with the severity depending on the violation. Beyond the statutory penalties, the practical consequences tend to be more damaging:
- Regulatory findings that trigger remediation programmes — expensive, disruptive, and visible to the board.
- Restrictions on licence or product approvals, which can stall a roadmap for quarters.
- Correspondent banking relationships becoming harder to maintain.
- Reputational damage, which for a consumer-facing financial product is difficult to price and slow to recover from.
Sector by sector
Banking and digital banking
The strictest standard, full customer due diligence, and the highest volumes. For digital banks, the tension is sharpest: the entire proposition is onboarding without a branch, and the compliance obligation is identical to an institution with one.
Fintech and e-money
E-money issuers and payment platforms are covered persons and are supervised accordingly. The common failure mode here is treating compliance as a launch milestone rather than an operating function: building verification to satisfy the licence application, then not maintaining ongoing monitoring as volumes grow. Scale exposes that gap quickly, and usually at the worst moment.
Lending and financing
SEC-regulated lenders follow the non-bank rules and often apply more flexible policies for small-ticket products, but remain bound by AMLA. Identity verification typically sits alongside income and employment checks, so the same document pipeline serves both.
Insurance
Covered under the AMLA framework with the Insurance Commission represented on the AMLC. Due diligence obligations attach at policy issuance and again at claims, which is a point some operations under-serve.
Where automation helps
OCR and KYC automation does not make you compliant. It makes consistent compliance achievable at volume, which is a different claim and a more honest one.
- Consistency. The same checks applied to every application, rather than varying with reviewer experience and time of day.
- Evidence. A structured, timestamped record of every check on every application. When a regulator asks how a decision was reached, this is the difference between an answer and an archaeology project.
- Ongoing monitoring. Continuous review of transaction patterns against profile is not realistically a manual task at any scale.
- PhilSys authentication. Verification against an authoritative source rather than visual inspection of a document.
- Preserving judgement where it belongs. Routine cases clear automatically; enhanced due diligence cases reach a human with the evidence already assembled.
One caution worth stating plainly: automation does not transfer accountability. You remain the covered person. If a vendor's system misses something, the finding lands on you — which is why the due diligence you do on a verification provider matters as much as the due diligence the provider performs.
The bottom line
Philippine KYC regulation is demanding but not obstructive. BSP Circular 1170 and PhilSys removed the requirement for in-person verification that once made digital onboarding impossible. What remains is an obligation to verify reliably, apply proportionate scrutiny, monitor continuously, and be able to evidence all of it.
Most compliance failures are not decisions to cut corners. They are processes that worked at a hundred applications a month and were never rebuilt for a thousand.
Tritel provides OCR and KYC automation in the Philippines, including PhilSys-enabled verification as a PSA Relying Partner. Book a free consultation to discuss how your verification process holds up at the volumes you are planning for.
