The Enforcement Reality
BSP Circular 950 is the Bangko Sentral ng Pilipinas' primary AML/CFT implementation directive for Philippine covered institutions. It sets requirements across four areas: customer due diligence (CDD), suspicious and covered transaction reporting, PEP and sanctions screening, and audit trail documentation. Under AMLC's GoTRACS framework, Suspicious Transaction Reports must be filed by the next working day following determination of suspicion, while Covered Transaction Reports must be filed within five working days of a cash transaction of ₱500,000 or more.
Compliance is assessed through BSP's ongoing supervisory examination cycle, with non-compliance carrying monetary penalties under the Manual of Regulations for Banks. Philippine financial institutions are supervised differently than the AML programmes many of them were designed under: BSP's examination posture has shifted from checking whether a compliance framework exists to testing whether it produces reliable, auditable outcomes under volume and under scrutiny. The gap between what a programme says on paper and what it can actually demonstrate, the AML Compliance Gap, is where most examination findings originate, and it widens as transaction volumes and regulatory expectations both grow.
The June 30, 2026 deadline under BSP Circular 1213 has passed. That circular concerns fraud-authentication controls under the Anti-Financial Account Scamming Act (AFASA), not AML directly, but it reflects the same posture shift running through Circular 950: BSP expects institutions to demonstrate controls, not just document them.
AMLC has documented enforcement actions against covered institutions for STR filing failures under the Anti-Money Laundering Act (AMLA, RA 9160), with monetary penalties imposed under the Manual of Regulations for Banks and corrective action orders following repeated findings. BSP Circular 950 governs the AML/CFT framework for every Philippine covered institution, universal banks, rural banks, cooperative banks, e-money issuers, and virtual asset service providers under AMLA jurisdiction, as a standing supervisory relationship, not a one-time compliance project.
What BSP Circular 950 Actually Requires
Circular 950 establishes compliance requirements across four key areas: customer due diligence and beneficial ownership identification, consistent with FATF Recommendation 24; transaction monitoring and STR/CTR filing, with clearly differentiated filing windows; PEP and sanctions screening against AMLC's designated persons list and the UN Consolidated Sanctions List; and audit trail and documentation standards for regulatory examination and defence.
The area most often mishandled is the second one, because STRs and CTRs operate on different clocks.
| Report trigger | Filing window | Legal basis |
|---|---|---|
| CTR — cash transaction (or equivalent) ≥ ₱500,000 | 5 working days from occurrence | AMLA RA 9160, as amended |
| STR — determination of suspicion (any amount) | Next working day from determination | AMLC RI No. 2, Series of 2024 (GoTRACS) |
Practical consequence: an analyst who detects suspicious activity on Monday but doesn't formally determine it suspicious until Wednesday has a Wednesday start date for the STR clock, and a Thursday deadline, not a following-Monday one. AMLC's GoTRACS logs every submission with a timestamp; the first thing a BSP examiner typically asks for is the STR submission log for the last 12 months, checking for cases where the determination date and filing date are more than one working day apart.
CDD and audit trail failures often share a root cause: data sitting in disconnected systems. When a KYC risk classification lives apart from the transaction monitoring system, an analyst reviewing an alert has to cross-reference platforms before acting, and under a next-working-day STR clock, that cross-referencing time is not free.
Where Institutions Are Actually Failing
Rural banks and cooperative banks running manual, spreadsheet-based STR processes were built for a lower-volume, longer-window era; they weren't built for a next-working-day clock, and the gap is structural, not behavioural.
E-money issuers face a different problem: transaction volumes have outpaced transaction-monitoring rule sets. Alert fatigue is a resource and governance question for the CRO and compliance team, not just a configuration question for the transaction monitoring administrator. At high volume, even a well-calibrated system can leave analysts spending disproportionate time triaging lower-risk alerts instead of focusing on genuine threats.
Newly licensed VASPs carry a version of the same risk from day one: regulatory approval confirms the entity is licensed, not that its AML programme is calibrated to Circular 950 standards. Across all three institution types, the common failure pattern is the same: tool fragmentation that breaks the audit trail exactly where a BSP examiner looks first, the connection between the flagged alert and the filed STR.
None of this is unique to Southeast Asia, tool fragmentation is a global AML problem, but the next-working-day STR clock makes the cost of fragmentation higher here than in jurisdictions still running on longer windows.
What BSP Examiners Actually Test For
BSP's AML supervisory approach increasingly resembles an evidence-extraction model rather than a checklist review: examiners select a specific case and ask the institution to prove it was handled correctly, rather than asking whether a policy exists.
- "Produce your transaction monitoring rule change log for the last 12 months, with approval timestamps and approver IDs." A record showing who approved each rule, when, and with what rationale. Institutions that can produce this demonstrate governance; institutions that cannot suggest either ad-hoc administration or manual processes where the paper trail doesn't exist.
- "How long does it take to produce a complete audit trail for a named case?" Regulators don't need speed for its own sake, they need to know your system can reconstruct the full decision chain. If you rebuild it manually after the fact from multiple systems, that's a control gap.
- "What is your false positive rate, and what have you done to improve it?" BSP's AML/CFT Risk Rating System depends on institutions demonstrating a calibrated, risk-based approach. An institution that has never measured its false positive rate can't show that calibration, or that it's managing analyst time effectively.
- "Walk me through your last three STR filings, from alert generation to GoTRACS submission, with particular attention to the determination date." This is where the next-working-day window becomes operationally critical. Examiners look for the gap between when suspicion was formally determined and when the report was filed. If that gap exceeds one working day without documented justification, it's a finding.
- "How are CDD programme changes documented and approved?" When your AML programme changes, risk tiers, screening protocols, CDD procedures, examiners want to see the approval chain and the effective date. Ad-hoc changes and undocumented updates are findings.
An institution that can produce three clean STRs but can't narrate the reproducible workflow behind them is showing a process that may not hold up under volume or scrutiny.
Closing the Compliance Gap
Closing this gap requires a few specific things from any AML platform operating in the Philippine market: STR and CTR forms that pre-populate from investigation case data, so analysts review and submit rather than rebuild narratives under time pressure; a determination-to-filing countdown that runs automatically and separately for the next-working-day STR clock and the five-working-day CTR clock; an audit trail native to the system rather than reconstructed after the fact, so examiners can follow the decision chain without asking for manual extraction; and a way to reduce duplicate investigative work on the same underlying risk, so analysts spend time on genuine threats rather than fatigue.
FT AML Solution is built around this workflow. Its Transaction Monitoring module includes a Suppression Window, the platform's primary differentiator, which blocks repeat alerts on the same customer-rule combination while that risk is already under investigation, reducing alert volume by up to 75%. That's what gives analysts room to focus on the STR determinations that actually need next-working-day attention, instead of re-triaging the same flagged pattern.
Its Case Management module provides an integrated investigation workspace where alert context, customer history, transaction patterns, and CDD details live in one view, eliminating the cross-reference delays that blow past the STR deadline. Its Regulatory Reporting module pre-populates STR and CTR forms directly from case data, with an automatic countdown and escalation alerts if a filing deadline approaches, so compliance officers can manage the window without spreadsheets.
Frequently Asked Questions
What is BSP Circular 950?
BSP Circular 950, Series of 2017, is the Bangko Sentral ng Pilipinas' AML/CFT implementation directive for all Philippine covered institutions. It specifies requirements for customer due diligence, transaction monitoring, suspicious transaction reporting, covered transaction reporting, politically exposed person screening, sanctions screening, and audit trail maintenance.
What is the STR filing deadline in the Philippines?
Under AMLC's GoTRACS framework, a covered institution must file a Suspicious Transaction Report by the next working day following the date on which a transaction is formally determined to be suspicious.
Is the CTR deadline the same as the STR deadline?
No. Covered Transaction Reports, triggered by a cash transaction of ₱500,000 or more, must be filed within five working days of the transaction's occurrence, a longer window than the next-working-day STR standard.
What is AMLC GoTRACS?
GoTRACS is the AMLC's digital framework for STR and CTR submission. Established under AMLC Regulatory Issuance No. 2, Series of 2024, it logs every filing with a timestamp and is accessible to BSP examiners for supervisory review.
What does a BSP AML examination look for?
BSP AML examinations test evidence rather than policy. Examiners typically request transaction monitoring rule change logs with approval timestamps, audit trail production for specific cases, false-positive rate trends, STR/CTR submission timeliness records, and documentation of customer due diligence programme changes.
What penalties apply for STR/CTR filing violations?
Per the Manual of Regulations for Banks (Appendix Q-26), non-compliance with AML/CFT reporting requirements carries monetary penalties up to ₱1,000,000 per violation or ₱100,000 per day for continuing violations. The ₱500,000 figure often cited is the CTR trigger threshold for cash transactions, not a fine.

