Under BSP Circular 1193, a covered institution must submit an ML/TF/PF Risk Event Report to the BSP within 24 hours of knowing, or when it should have known, of a significant event. An event is significant if the amount involved is 1% or more of total qualifying capital, or if the institution determines it has a material impact.
Circular 1193 amended Section 911 of the Manual of Regulations for Banks and Section 911-Q of the Manual of Regulations for Non-Bank Financial Institutions. It is an institution-level notification to the BSP, separate from the transaction-level filings made to the AMLC. Most compliance teams know the STR and CTR clocks well. Fewer have written down who decides what counts as a significant event, or how they would prove when they knew.
What is an ML/TF/PF risk event report under Circular 1193?
It is a notification to the BSP of a money laundering, terrorism financing, or proliferation financing incident that may present a material or adverse impact to the institution, to the financial system's posture, or to public confidence in it. Circular 1193 applies to covered persons, meaning BSP-supervised institutions, and replaces the earlier reporting language in Sections 911 and 911-Q.
Only significant events are reportable. The circular does not ask for a report on every ML/TF/PF-related incident, and it does not ask for a suspicion about a customer's transaction. The trigger is the effect of the event on the institution or the system. That is why it sits alongside the STR and CTR obligations instead of replacing either.
When does the 24-hour clock start?
It starts on the date of knowledge or discovery of the occurrence, which the circular explains as the time the event has been known or should have been known by the covered person. The wording matters. A deadline that runs from when you should have known makes your detection speed and your internal escalation records part of the compliance question.
Two practical points follow. First, the circular states 24 hours, not one working day, and the text reviewed for this piece does not exclude weekends or holidays, so the safer plan is a clock that runs continuously. Second, a late internal escalation does not move the start time. If an analyst identified the event on Friday afternoon and the compliance head heard on Monday, the question an examiner can ask is when the institution should have known.
What is the 1%-of-capital test, and what is the material-impact test?
There are two limbs, and meeting either one makes an event significant. The first is arithmetic: the amount involved represents one percent or more of the covered person's total qualifying capital. The second is a judgement: regardless of the amount, the covered person has determined that the incident has a material impact.
Illustration only: an institution with ₱5 billion in total qualifying capital would cross the first limb at ₱50 million. Below that figure, the second limb still applies. The circular gives examples of material impact, such as an incident affecting a significant number of customers or counterparties, or one with a cross-border element. Grant Thornton's summary of the circular also lists adverse media attention as an example, so confirm the exact wording of the examples against the current text before relying on it in a policy.
Report to BSP within 24 hours
Report to BSP within 24 hours
The second limb is where policy matters most. Because the institution makes the determination, a defensible programme writes down in advance who makes it, what factors they consider, and where the decision is recorded. A determination made on the day, with reasons, is far easier to defend than one reconstructed later.
What does a risk event report have to contain?
Four things at minimum: the date of knowledge or discovery of the event, a brief description of the event including the amount involved, the initial root cause and the response actions taken or planned, and the impact to the covered person. That is a short document, and it can be drafted in hours only if the underlying facts are already recorded.
Submission is electronic. BSP's guidelines memorandum on risk event report submission, M-2024-016, sets out the template, and press coverage of the memorandum describes it as submitted by the institution's compliance officer together with a signed control proof list. Confirm the current template and sign-off requirements against the memorandum before building the workflow.
What happens after the report is filed?
The circular sets no fixed follow-up deadline in the text reviewed. It says the BSP may require additional information, documents, or updates as necessary, and may conduct a special or overseeing examination as warranted. Non-compliance is subject to the applicable monetary penalty under Sections 1102 and 1102-Q of the manuals, and the circular does not state an amount of its own.
In practice, the first report is a starting point. The institution should expect follow-up questions and keep its case file current, because the initial root cause is by definition provisional. A file that shows what was known at hour 24 and what was learned afterwards is stronger than one that only shows the final view.
How is a risk event report different from an STR or a CTR?
It goes to a different regulator, is triggered by a different question, and runs on a different clock. An STR is a transaction-level report to the AMLC about suspicion. A CTR is a threshold report to the AMLC. A risk event report is an institution-level notification to the BSP about a significant event.
| Risk event report | STR | CTR | |
|---|---|---|---|
| Goes to | BSP | AMLC (GoTRACS) | AMLC (GoTRACS) |
| Triggered by | A significant ML/TF/PF risk event | Suspicion, once determined | A covered transaction |
| Clock | 24 hours from when the event is known or should have been known | By 11:59:59 pm of the next working day from determination | Within five working days |
A single incident can engage more than one of these. Nothing in the circular makes one clock wait for another, so the safer assumption is that they run in parallel. Our guides to the STR and CTR filing windows, SAR versus STR, and writing a BSP-ready STR cover the AMLC side in detail.
What should an AMLCO have in place before the clock starts?
Six things, most of which are decisions and records rather than technology.
Define knowledge. Decide what counts as the moment of knowledge and where it is logged, with a timestamp, so the start of the 24 hours can be shown.
Name the decision-maker. Record who determines material impact, who covers them out of hours, and what factors they consider.
Know your number. Keep the current total qualifying capital figure and the resulting 1% amount where the on-call team can find them.
Pre-build the report. Hold the template, the four required content items, and the sign-off route ready before an event happens.
Plan for the weekend. A clock measured in hours does not wait for Monday, so cover nights, weekends, and holidays.
Record the decisions that were not reports. When an event is assessed and found not significant, write down why. That record is what shows the test was applied.
Lean teams feel this hardest. The rural and cooperative bank AML guide covers how a small compliance function can carry obligations designed for larger institutions.
Where does this fit in your AML program?
It is a Case Management and Regulatory Reporting discipline, and a governance one. The evidence an examiner would ask for is a dated record: when the event was identified, who assessed it, how the two tests were applied, when the report went out, and what followed.
FyscalTech's Case Management module writes every action on a case to a timestamped audit timeline that locks at closure, requires a written reason for each disposition, and lets compliance leadership configure workflows and case creation without an engineering ticket. Those are the raw materials for proving when an institution knew and what it decided. The module does not replace the judgement on whether an event is significant. For the wider reporting workflow, see our regulatory reporting playbook for mid-size fintechs and the complete BSP Circular 950 guide.

