The Philippines' next mutual evaluation will be run by the Asia/Pacific Group on Money Laundering (APG) under the FATF's fifth-round methodology, with the technical compliance submission due on 31 March 2027. For transaction monitoring, the test is effectiveness: risk-based thresholds, tested rules, alerts decided promptly, and STRs filed with the AMLC on time.
The APG's published fifth-round schedule places the Philippines in its 2028 plenary cohort, which is when the report would be discussed and adopted. Onsite dates have not been published. The last round followed a similar rhythm: assessors were onsite from 15 to 28 November 2018, and the APG adopted the 2019 report in August 2019.
This briefing is the transaction-monitoring companion to our guide on what BSP-regulated institutions should be able to evidence. It covers what the fifth round changes for monitoring, where the Philippines stood last time, and the questions about thresholds, alert ageing and STRs that a monitoring programme should be able to answer from its own records.
When is the Philippines' next mutual evaluation, and why do people say 2027?
The assessment work happens in 2027 and the report is scheduled for 2028, so both years are correct depending on which milestone you mean.
The APG schedule lists the Philippines in the 2028 plenary alongside Bangladesh, Bhutan and Samoa, each with a technical compliance submission due on 31 March 2027. Philippine officials refer to the process as the 2027 evaluation. AMLC Executive Director Ronel Buenaventura has said a successful year would mean completing the critical preparatory work for it, and that reforms must be shown operating effectively in practice. Earlier planning documents pointed to 2026: the Palace's Memorandum Circular No. 37 in 2023 said another mutual evaluation would be conducted in 2026. The published APG schedule supersedes those references, so 31 March 2027 is the fixed date to plan against.
The evaluation is separate from the FATF grey list. The Philippines was placed under increased monitoring in June 2021 and removed on 21 February 2025. That exit does not carry a rating into the new round. The stakes after the report are also higher than before. Under the fifth-round procedures, a country has three years to address the deficiencies found, after which it automatically faces measures that can include public statements about outstanding gaps.
What does the fifth round change for transaction monitoring?
It places supervision and the private sector's preventive measures, including suspicious transaction reporting, in the same Immediate Outcome for financial institutions and VASPs.
Every evaluation scores two things. Technical compliance asks whether the laws and regulations meet the 40 FATF Recommendations. Effectiveness asks whether the system works, and it is rated across 11 Immediate Outcomes. The previous round, run under the 2013 methodology, rated supervision (IO.3) and preventive measures (IO.4) separately. The 2022 methodology, last updated in June 2026, reorganises them by sector. Immediate Outcome 3 now covers supervisors of financial institutions and VASPs and whether those institutions "adequately apply AML/CFT preventive measures, and report suspicious transactions." Immediate Outcome 4 applies the same structure to designated non-financial businesses and professions.
The practical effect is that the Philippines' IO.3 rating depends on what happens inside covered persons as well as on what BSP and the other supervisors do. A supervisor cannot show an effective outcome with circulars alone. It needs evidence that institutions detect unusual activity, decide on it promptly and report it. Institutions are not rated individually. However, assessors typically meet a sample of private-sector firms during the onsite visit, and the statistics and case examples that BSP, the SEC, the Insurance Commission and the AMLC present are drawn from institutions' own records.
How did the Philippines score on monitoring-related outcomes last time?
In 2019 the Philippines was rated Moderate on supervision, preventive measures and the use of financial intelligence, with specific concerns about the quality of reporting.

The report described the STR regime as still developing and noted "patterns of defensive reporting." It found that BSP had a prudent risk-based framework for banks, but that its thematic reviews had only recently begun and were not yet used effectively. Other supervisors' risk-based approaches were at an early stage. Banks applied a risk-based approach to customer due diligence and account monitoring, while most non-bank sectors were only starting to implement AML/CFT measures.
A good deal has changed since then. When the FATF removed the Philippines from increased monitoring, it credited risk-based supervision of DNFBPs, controls over casino junket risks, registration requirements for money transmitters, and greater use of financial intelligence. Those were action-plan items. The fifth round asks a broader question: whether these controls now produce results across every sector.
What will you be asked about thresholds?
Expect three questions: where each threshold came from, when it was last tested, and whether the system meets the baseline in BSP's rules.
Where did each threshold come from?
A threshold needs a reason tied to the institution's own risks. That usually means a line from each monitoring scenario back to the institutional risk assessment, and from there to the national risk picture. The AMLC has said the third National Risk Assessment will guide where it directs resources. A threshold left at a vendor default, or carried over from a system migration without review, has no risk rationale to show. The same logic applies to the customer risk ratings that many scenarios depend on, which is why a rating that never changes undermines the rules built on it.
For each scenario, the record should state the risk addressed, the data it runs on, the threshold value and its basis, who approved it and when.
When was it last tested, and by whom?
Thresholds drift as customer behaviour, products and volumes change. The evidence of maintenance is a dated log: below-the-line testing results, alert-to-STR conversion by scenario, the changes made and the reasons for them. Testing also has to be independent of the team that built the rules. A review by the people who designed a scenario confirms it does what they intended, which is not the same as confirming it meets the requirement. Our piece on what "independent" means for AML testing covers where that line sits.
Does the system meet the BSP baseline?
Section 922 of the Manual of Regulations for Banks sets out functions an electronic AML system must have. They include transaction monitoring that performs statistical analysis and profiling to detect unusual patterns of account activity, the ability to aggregate a customer's activity across multiple accounts, and the capability to record suspicious transactions and support the investigation of alerts. Watch-list monitoring is listed separately, and it is a different control from transaction monitoring. An institution should be able to show each function working, with examples.
How long do your transaction monitoring alerts wait before suspicion is established?
This is often the hardest of the three questions to answer from records, and it is where an on-time filing can hide a late decision.
Under the AMLC's Guidelines on Transaction Reporting and Compliance Submissions (GoTRACS, Regulatory Issuance No. 2, Series of 2024, issued 11 December 2024), an STR is due within the next working day from occurrence. For suspicious transactions, occurrence means the establishment of suspicion or the determination of the transaction's suspicious nature. The same guidelines require a covered person's MTPP to state the number of days needed for each procedure in the reporting chain, according to ACCRALAW's summary.
The filing clock therefore starts when the decision is made, not when the alert fires. The time between those two points is governed by the institution's own MTPP timeframes. BSP's MORB text, last amended on this point by Circular No. 950 in 2017, still states that the determination should be made within ten calendar days from the date of the transaction. BSP-supervised institutions should set MTPP timeframes that can be defended against both documents.
The evidence here is quantitative:
- the age of open alerts against the MTPP timeframe, reported regularly
- the median and slowest time from alert to decision, by scenario
- the backlog trend over the past twelve months
- each case that exceeded the timeframe, with the reason recorded
We have written separately about how institutions fall outside the filing window without realising it. For the evaluation, the point is narrower. An institution should be able to produce both timestamps, alert and determination, for any sample of cases an examiner picks.
Is filing on time enough to show that STRs work?
No. Timeliness is necessary, but assessors also look at whether reports are useful to the AMLC as financial intelligence.
Immediate Outcome 6 assesses how competent authorities use financial intelligence, and the suspicious transaction report is its main input from the private sector. The 2019 finding of defensive reporting described reports filed to protect the institution rather than to inform the FIU. A high filing volume with thin narratives does not help that rating. A lower volume of well-reasoned reports usually does.
The evidence is a periodic quality review of a sample of filed STRs, written narrative standards, any feedback received from the AMLC, and documented reasons for decisions not to file. If your team still uses "SAR" and "STR" interchangeably, our guide on which report applies where sets out the Philippine terms.
Does this apply to EMIs, VASPs and other non-bank covered persons?
Yes. Financial institutions and VASPs share Immediate Outcome 3 in the fifth round, so e-money issuers, remittance companies and crypto-asset service providers are assessed under the same outcome as banks.
In 2019, supervisors outside BSP's bank supervision were still at an early stage of risk-based supervision. The regulatory perimeter has widened since. The SEC's rules on crypto-asset service providers, Memorandum Circulars No. 4 and No. 5, Series of 2025, took effect on 5 July 2025. Money transmitter registration was one of the items the FATF recognised in February 2025.
Smaller institutions face the same questions with fewer people to answer them. The evidence can be proportionate, but it cannot be absent. A two-person compliance team still needs a threshold rationale, a testing record and an alert ageing report. Our overview of AML obligations for BSP-supervised fintechs after the grey-list exit covers the wider programme.
What should a covered person have ready before 31 March 2027?
Covered persons need an evidence file that answers the threshold, alert-ageing and STR questions from their own records.
Covered persons do not file the technical compliance submission; the government does. But supervisors and the AMLC will be assembling statistics and case examples for the country's submissions in the months around that date, and BSP examinations in the meantime are likely to ask for the same records.
| Evidence | What it shows | Usual owner |
|---|---|---|
| Threshold rationale for each scenario, linked to the risk assessment | Thresholds are risk-based | Compliance officer / MLRO |
| Dated tuning and testing log, with approvals | Rules are maintained | Transaction monitoring lead |
| Independent test report covering transaction monitoring | Testing is independent | Internal audit or independent tester |
| Alert ageing report against MTPP timeframes | Alerts are decided promptly | AML operations |
| Determination-to-filing report for every STR | Next-working-day filing is met | Compliance officer |
| Quality review of a sample of filed STRs | Reports are useful to the AMLC | Compliance officer |
| Board or senior management reporting on monitoring performance | Oversight is working | Compliance officer |
Start with the alert ageing report. It is built from data the monitoring system already holds, and it shows quickly whether the other items will be easy or hard to produce.
Where does this sit in your AML programme?
It sits mainly in Transaction Monitoring, with Case Management and Regulatory Reporting close behind.
Threshold rationale, testing and system functions are Transaction Monitoring evidence. Alert ageing depends on a case record that holds the alert, the investigation and the determination together, which is a Case Management function. Determination-to-filing timeliness and STR quality belong to Regulatory Reporting. Fyscal ARCX keeps each alert, investigation and disposition tied to one case record with its timestamps preserved, so the alert and determination dates an examiner asks for already exist when the request arrives.

