When the BSP discovered that thousands of online casinos were disguised as beauty salons and bakeries on digital payment platforms, the response was structural. BSP Memorandum M-2026-017, issued in May 2026, restated a principle that acquirers and payment service providers had been treating as optional: AML accountability does not transfer to an intermediary. It stays with the institution. The draft circular that followed proposes the framework to enforce that principle across every layered merchant arrangement in the Philippine payment system.
This is an exposure draft, not a final regulation. The provisions described in this article reflect the draft as published for industry comment. The final circular may differ.
The draft matters because it addresses the specific architecture that makes merchant payment fraud difficult to detect: the intermediary layer. When an acquirer contracts with an aggregator, and the aggregator onboards merchants, the acquirer's visibility into who is actually receiving funds narrows. The BSP's draft closes that gap with three mechanisms: direct-arrangement mandates for high-risk sectors, a centralised merchant database, and explicit accountability rules for every party in the payment chain.
Why the BSP acted now
The trigger was not theoretical. BSP Deputy Governor Mamerto Tangonan confirmed that surveillance had flagged merchants accepting frequent small payments, some as low as fifty pesos, late at night through e-wallets and payment apps. Those payments were bets placed on illegal online casinos. The BSP shuttered over 8,000 merchant accounts for allegedly illegal activities.
The pattern exposed a structural weakness. Payment aggregators connect thousands of small businesses to formal payment channels. That intermediary layer can obscure who is actually receiving the money. A merchant registered as a bakery could be operating as an unlicensed casino, and the acquiring bank's systems would process the transactions without distinguishing one from the other.
Offshore platforms exploited the same architecture. Foreign prediction markets, stablecoin apps, and virtual-asset services offered QR Ph checkout to Philippine users through third-party intermediaries. A user would scan a QR Ph code with a local e-wallet, and the intermediary would handle fiat-to-crypto conversion and local settlement. The acquiring bank saw a generic merchant name.
BSP Memorandum M-2026-017 addressed the accountability question directly: a bank's AML obligations cannot be transferred, diminished, or substituted by an aggregator's involvement. The draft circular builds the operational requirements around that principle.
What the draft circular requires
Direct merchant arrangements for high-risk sectors
The draft mandates that certain business categories may operate only through a direct merchant arrangement with a BSP-supervised acquirer. No intermediary. The categories include virtual-asset service providers, online gambling operators, casinos, adult content platforms, and money service businesses.
Each direct arrangement requires enhanced due diligence and ongoing transaction monitoring, with the acquirer performing merchant verification, beneficial-ownership identification, settlement-limit enforcement, and transaction-level surveillance.
This provision ends the arrangement where a high-risk platform accesses Philippine payment rails through a chain of intermediaries, each assuming the next party has performed the due diligence.
The National QR Code Merchant Database
The BSP will establish, implement, and maintain a centralised database of merchants that accept payments under the National QR Code Standard (QR Ph). The database will hold verified merchant profiles, including registration details, store addresses, beneficial owners, settlement account holders, real-time risk ratings, and sanctions-screening status.
Banks and e-wallets will receive automated alerts and may restrict or block transfers from unverified merchants or undisclosed aggregators. The interim repository must be operational within 90 calendar days of the circular taking effect. The full database must be operational within 12 months, with all active merchant records migrated and validated within 15 months.
For compliance teams, this changes the screening calculus. A centralised merchant registry creates a reference point for onboarding verification and ongoing monitoring that does not depend on the aggregator's own records.
Acquirer accountability for layered arrangements
The draft restates and operationalises what M-2026-017 established as principle. Acquirers must maintain adequate visibility over underlying merchants and related payment activities, including access to sub-merchant information, transaction-level data, and merchant risk profiles. They must apply risk-based standards to onboarding and monitoring, conduct periodic reviews, and maintain clear triggers for restricting or terminating relationships with high-risk or non-compliant sub-merchants.
Aggregators retain their own obligations: merchant due diligence, risk-based onboarding and monitoring, risk mitigation, and suspicious transaction reporting for the sub-merchants they onboard. But the aggregator's compliance programme does not satisfy the acquirer's. Both are accountable independently.
Intermediaries are barred from subcontracting merchant acquisition to another party. The chain stops at one layer.
Twelve-month moratorium on new payment system operators
The draft suspends the acceptance and processing of applications for Operator of Payment System (OPS) registration for 12 months from the circular's effective date. Applications filed before the suspension will still be evaluated but cannot be approved or denied until the moratorium lifts.
The stated rationale: the BSP will use the period to conduct a comprehensive review of OPS taxonomy and licensing. The practical effect is that no new entrants can begin merchant-acquisition activities while the integrity framework is being implemented.
Compliance timelines in the draft

| Milestone | Deadline |
|---|---|
| Interim merchant information repository operational | 90 calendar days from effectivity |
| Review of existing layered merchant arrangements | 6 months from effectivity |
| Remediation of deficiencies in existing arrangements | 12 months from effectivity (6 months after review) |
| Full National QR Code Merchant Database operational | 12 months from effectivity |
| All active merchant records migrated and validated | 15 months from effectivity |
| OPS registration moratorium ends | 12 months from effectivity |
Institutions with relationships still non-compliant after 12 months face enforcement action. The draft also provides for payment-license revocation for repeated violations.
What this means for your compliance programme
Merchant onboarding becomes a compliance function
If your institution acquires merchants through aggregators, the draft requires you to treat merchant onboarding with the same rigour as customer risk rating. You need direct access to the merchant's identity, beneficial ownership, business activity, and risk profile. "The aggregator handles onboarding" is not a defensible position under the draft.
Transaction monitoring must extend to sub-merchant level
Monitoring settlement-account activity in aggregate is insufficient under the draft. The acquirer needs transaction-level visibility into sub-merchant activity, with the capacity to detect anomalous patterns (high-frequency small-value transactions at unusual hours, for example) at the individual merchant level.
This has direct implications for AML monitoring software configuration. Your threshold calibration needs merchant-level granularity, not account-level aggregation.
Incident reporting tightens
Institutions must report material fraud, scams, or unauthorised merchant activity within 24 hours of detection, with a full investigation report within five business days. This sits alongside the existing BSP Circular 1193 risk-event reporting window and the standard STR filing obligation.
The database changes the screening landscape
Once the National QR Code Merchant Database is live, every QR Ph-enabled merchant will have a verified profile against which acquirers and payment providers can screen. Unverified merchants and undisclosed aggregators become visible. The AMLC and the BSP will have supervisory access to the same dataset.
For institutions using payment screening systems, this creates a new reference dataset alongside sanctions lists and PEP databases. The screening workflow will need to incorporate merchant-verification checks against the centralised registry.
What this draft does not do
It does not make the acquirer liable for fraud committed by a merchant. It makes the acquirer accountable for maintaining the controls that would detect and prevent that fraud.
It does not ban layered merchant arrangements. It bans them for specific high-risk sectors and imposes transparency and accountability requirements on all others.
It does not replace existing AML obligations. It adds merchant-specific requirements on top of BSP Circular 950's AML/CFT framework and the existing MORPS provisions on payment system integrity.
And it is not final. The draft is published for industry comment. Institutions should prepare for the operational requirements it signals, not treat the specific timelines as confirmed.
The compliance team's preparation checklist
First, audit your existing layered merchant arrangements. Identify every relationship where an aggregator or intermediary onboards merchants on your behalf. Map which merchants fall into the high-risk categories that the draft would require to move to direct arrangements.
Second, assess your visibility. Can you access sub-merchant identity, beneficial ownership, transaction-level data, and risk profiles today? If that information sits with the aggregator and you receive only settlement-level summaries, you have a gap the draft would make non-compliant.
Third, review your monitoring rules. Transaction monitoring configured at the settlement-account level will not detect the merchant-level patterns the draft expects acquirers to catch. If your AML platform does not support sub-merchant-level monitoring, evaluate what configuration changes or system capabilities are needed.
Fourth, prepare for the database. When the National QR Code Merchant Database goes live, your onboarding and screening workflows will need to incorporate verification against it. Assess whether your current systems can integrate with an external merchant registry.
If you want to see how sub-merchant monitoring, configurable screening, and risk-event reporting work inside a single AML platform, book a walkthrough of Fyscal ARCX and bring this checklist with you.
