The Philippines, as a rapidly growing financial hub in Southeast Asia, has established a robust regulatory framework to combat money laundering and terrorist financing. Central to this framework is the Anti-Money Laundering Act (AMLA) and its implementing rules, which apply to all financial institutions, including Virtual Asset Service Providers (VASPs). To operate legally in the country, VASPs must obtain a BSP VASP license from the Bangko Sentral ng Pilipinas (BSP)—the central monetary authority of the Philippines. A critical component of this licensing process is conducting a thorough AML check Philippines BSP VASP license to ensure compliance with national and international standards.

This comprehensive guide explores the essential aspects of AML check Philippines BSP VASP license requirements, the regulatory landscape, and best practices for VASPs seeking to establish a compliant and secure operation in the Philippines. Whether you're a startup or an established crypto business, understanding these obligations is key to maintaining trust, avoiding penalties, and fostering long-term growth in the digital asset ecosystem.


The Regulatory Landscape: BSP and AML Compliance in the Philippines

The Role of the Bangko Sentral ng Pilipinas (BSP)

The Bangko Sentral ng Pilipinas (BSP) is the primary regulator responsible for overseeing financial institutions, including VASPs, in the Philippines. As the central bank, the BSP enforces the Anti-Money Laundering Act of 2001 (AMLA), as amended, and its implementing rules and regulations. These laws are designed to prevent money laundering, terrorist financing, and proliferation financing by requiring financial institutions to implement robust Anti-Money Laundering and Counter-Terrorist Financing (AML/CFT) measures.

Under the BSP VASP license, virtual asset service providers—such as cryptocurrency exchanges, wallet providers, and custodians—are classified as "covered persons" under the AMLA. This means they must comply with stringent customer due diligence (CDD), transaction monitoring, suspicious activity reporting, and record-keeping requirements. Failure to comply can result in severe penalties, including fines, license revocation, and criminal liability for responsible officers.

Key AML Laws and Regulations Affecting VASPs

The regulatory framework governing AML check Philippines BSP VASP license compliance includes several key pieces of legislation and guidelines:

  • Anti-Money Laundering Act (AMLA) of 2001 (Republic Act No. 9160), as amended by Republic Act No. 10167, Republic Act No. 10365, and Republic Act No. 11521
  • Implementing Rules and Regulations (IRR) of the AMLA, issued by the Anti-Money Laundering Council (AMLC)
  • BSP Circulars and Memoranda, particularly BSP Memorandum on Virtual Asset Service Providers (VASPs) and BSP Circular No. 1108, which outlines licensing and operational guidelines for VASPs
  • Guidelines on Anti-Money Laundering and Counter-Terrorist Financing for VASPs, issued jointly by the BSP and AMLC
  • Republic Act No. 11439 (Anti-Terrorism Act of 2020), which strengthens measures against terrorist financing

These regulations require VASPs to implement a risk-based approach to AML/CFT, meaning the depth and scope of compliance measures should be proportional to the level of risk associated with their operations. For instance, a VASP dealing with high-risk jurisdictions or large-value transactions must conduct enhanced due diligence (EDD).

Why AML Compliance Matters for BSP VASP License Holders

Obtaining a BSP VASP license is not just a legal requirement—it is a cornerstone of operational legitimacy and market trust. AML compliance serves multiple critical functions:

  • Legal Compliance: Operating without a BSP VASP license or failing to meet AML obligations can lead to administrative sanctions, fines, or criminal charges under the AMLA.
  • Reputation Protection: Non-compliance can damage a VASP’s reputation, leading to loss of customer trust and investor confidence.
  • Access to Banking and Financial Services: Banks and payment processors are more likely to partner with compliant VASPs, ensuring seamless fiat on/off-ramps.
  • Global Market Entry: Compliance with Philippine AML standards enhances a VASP’s ability to expand into other regulated markets, such as the EU (under MiCA) or Singapore (under MAS).
  • Prevention of Financial Crime: Robust AML controls help prevent the use of digital assets for illicit activities, protecting the broader financial system.

In summary, a thorough AML check Philippines BSP VASP license process is not optional—it is a foundational requirement for any VASP seeking to operate legally and sustainably in the Philippines.


Step-by-Step Guide to AML Check for BSP VASP License Applicants

Step 1: Determine Applicability and Licensing Requirements

Before initiating the AML check Philippines BSP VASP license process, VASPs must first confirm whether they fall under the BSP’s regulatory scope. According to BSP Circular No. 1108, a VASP is defined as any entity that provides one or more of the following services:

  • Exchange between virtual assets and fiat currencies
  • Exchange between one or more forms of virtual assets
  • Transfer of virtual assets
  • Safekeeping or administration of virtual assets or instruments enabling control over virtual assets
  • Participation in and provision of financial services related to an issuer’s offer or sale of a virtual asset

If your business falls within this definition, you must apply for a BSP VASP license and undergo a comprehensive AML check. The BSP requires applicants to submit detailed documentation, including a business plan, organizational structure, risk assessment, and AML/CFT policies.

Step 2: Conduct a Business Risk Assessment

A critical component of the AML check Philippines BSP VASP license process is performing a Business Risk Assessment (BRA). This assessment identifies the inherent risks associated with your VASP’s operations, customer base, geographic exposure, and transaction patterns.

The BSP expects VASPs to categorize risks into three levels:

  1. Low Risk: Simple products, low-value transactions, and customers from low-risk jurisdictions.
  2. Medium Risk: Standard products, moderate transaction volumes, and customers from medium-risk jurisdictions.
  3. High Risk: Complex products, high-value transactions, customers from high-risk jurisdictions, or involvement in peer-to-peer (P2P) transactions.

For high-risk customers or transactions, enhanced due diligence (EDD) measures must be applied, such as:

  • Obtaining additional identification documents
  • Verifying the source of funds
  • Conducting ongoing monitoring
  • Seeking senior management approval for onboarding

The BRA must be documented and updated annually or whenever significant changes occur in the business model or regulatory environment.

Step 3: Implement Customer Due Diligence (CDD) and Know Your Customer (KYC) Procedures

One of the most critical aspects of the AML check Philippines BSP VASP license is the implementation of robust Customer Due Diligence (CDD) and Know Your Customer (KYC) procedures. These measures are designed to verify the identity of customers, assess their risk profiles, and monitor their transactions for suspicious activity.

The BSP requires VASPs to collect and verify the following customer information:

  • Full name
  • Date of birth
  • Address
  • Government-issued ID (e.g., passport, driver’s license, national ID)
  • Proof of address (e.g., utility bill, bank statement)
  • Tax Identification Number (TIN)
  • Source of funds (for high-risk customers)

For corporate customers, additional documentation is required, including:

  • Certificate of Incorporation
  • Articles of Incorporation
  • List of beneficial owners (BOs) with at least 25% ownership
  • Board resolution authorizing the transaction

VASPs must also conduct ongoing monitoring of customer transactions to detect unusual patterns, such as sudden large transactions, frequent transfers to high-risk jurisdictions, or structuring of payments to avoid detection.

Step 4: Establish Transaction Monitoring and Reporting Systems

A key requirement of the AML check Philippines BSP VASP license is the implementation of an automated transaction monitoring system. This system should be capable of detecting and flagging suspicious transactions in real time based on predefined risk indicators.

The BSP expects VASPs to monitor the following types of transactions:

  • Transactions exceeding PHP 500,000 (or its equivalent in foreign currency)
  • Unusual patterns, such as rapid successive transactions just below the reporting threshold
  • Transactions involving high-risk jurisdictions or sanctioned entities
  • Transactions with no apparent economic or lawful purpose

When suspicious activity is detected, VASPs must file a Suspicious Transaction Report (STR) with the Anti-Money Laundering Council (AMLC) within five (5) working days. Failure to report suspicious transactions can result in severe penalties, including imprisonment and fines.

Additionally, VASPs must submit a Currency Transaction Report (CTR) for cash transactions exceeding PHP 500,000. These reports must be filed electronically through the AMLC’s reporting portal.

Step 5: Develop Internal Policies, Procedures, and Training Programs

To ensure compliance with the AML check Philippines BSP VASP license requirements, VASPs must establish comprehensive internal policies and procedures. These documents should outline the VASP’s approach to AML/CFT, including:

  • AML/CFT Policy Statement: A high-level document signed by senior management outlining the VASP’s commitment to AML compliance.
  • Customer Acceptance Policy: Criteria for onboarding customers, including risk thresholds and prohibited jurisdictions.
  • Transaction Monitoring Policy: Guidelines for detecting and reporting suspicious transactions.
  • Record-Keeping Policy: Requirements for storing customer identification documents, transaction records, and reports for at least five (5) years.
  • Sanctions Screening Policy: Procedures for screening customers and transactions against sanctions lists (e.g., UN, OFAC, EU, BSP).

Furthermore, VASPs must implement a regular AML/CFT training program for employees, particularly those involved in customer onboarding, transaction monitoring, and compliance reporting. Training should cover:

  • Recognizing red flags of money laundering and terrorist financing
  • Proper handling of customer information and data privacy
  • Reporting procedures for suspicious transactions
  • Updates on regulatory changes and enforcement actions

Training records must be maintained and updated annually to demonstrate compliance during BSP inspections.

Step 6: Engage an Independent AML Audit and Compliance Review

Before submitting an application for a BSP VASP license, it is advisable for VASPs to engage an independent AML auditor or compliance consultant to conduct a pre-licensing review. This audit assesses the VASP’s AML/CFT framework against BSP and AMLC requirements and identifies any gaps or deficiencies.

A typical AML audit covers:

  • Review of customer due diligence records
  • Assessment of transaction monitoring systems
  • Evaluation of internal policies and training programs
  • Testing of suspicious transaction reporting procedures
  • Verification of record-keeping practices

The findings of the audit should be addressed and remediated before the BSP license application is submitted. A clean audit report can significantly enhance the VASP’s credibility and streamline the licensing process.


Common Challenges in AML Compliance for VASPs in the Philippines

Challenge 1: Rapidly Evolving Regulatory Landscape

The regulatory environment for VASPs in the Philippines is still evolving, with new guidelines and circulars being issued regularly. For example, the BSP has recently updated its VASP guidelines to align with international standards, such as the Financial Action Task Force (FATF) Travel Rule. Keeping up with these changes can be challenging for VASPs, particularly startups with limited compliance resources.

To address this challenge, VASPs should:

  • Subscribe to regulatory updates from the BSP and AMLC
  • Join industry associations, such as the Blockchain Association of the Philippines (BAP)
  • Engage legal and compliance consultants with expertise in Philippine AML laws
  • Participate in AML/CFT training programs and workshops

Challenge 2: High Cost of Compliance Infrastructure

Implementing a robust AML/CFT framework requires significant investment in technology, personnel, and training. For example, automated transaction monitoring systems, KYC software, and sanctions screening tools can be expensive, particularly for small and medium-sized VASPs.

To mitigate costs, VASPs can consider the following strategies:

  • Outsourcing: Partnering with third-party compliance service providers for KYC, transaction monitoring, and reporting.
  • Open-Source Tools: Utilizing open-source AML software for basic transaction monitoring and record-keeping.
  • Regulatory Sandbox: Applying for the BSP’s Regulatory Sandbox to test innovative AML solutions with reduced compliance costs.
  • Government Grants: Exploring funding opportunities from the Department of Science and Technology (DOST) or Department of Trade and Industry (DTI) for digital asset innovation.

Challenge 3: Balancing Customer Experience with Compliance

One of the biggest challenges for VASPs is maintaining a seamless customer experience while adhering to strict AML requirements. Lengthy KYC processes, frequent identity verification requests, and transaction delays can frustrate users and drive them to less compliant competitors.

To strike a balance, VASPs can implement the following best practices:

  • Risk-Based KYC: Applying simplified due diligence for low-risk customers and enhanced due diligence only when necessary.
  • Automated Identity Verification: Using AI-powered KYC solutions to streamline identity verification and reduce manual processes.
  • Customer Education: Providing clear guidance on AML requirements and the importance of compliance to build trust and transparency.
  • Tiered Onboarding: Offering different levels of access based on the customer’s risk profile and verification status.

Challenge 4: Cross-Border Transaction Risks

Many VASPs in the Philippines facilitate cross-border transactions, exposing them to risks associated with foreign jurisdictions. For example, transactions involving high-risk countries or sanctioned entities can trigger AML obligations in multiple jurisdictions.

To manage cross-border risks, VASPs should:

  • Screen Customers and Transactions: Against international sanctions lists, such as OFAC, EU, and UN lists.
  • Monitor Geographic Exposure: Regularly assess the risk profiles of customers from high-risk jurisdictions.
  • Collaborate with Foreign Regulators: Engage with regulators in other jurisdictions to share information and best practices.
  • Implement the FATF Travel Rule: Ensure compliance with the FATF Travel Rule, which requires VASPs to share originator and beneficiary information for transactions exceeding USD 1,000.

Challenge
James Richardson
James Richardson
Senior Crypto Market Analyst

Understanding the Critical Role of AML Checks for Philippines BSP VASP License Holders

As a Senior Crypto Market Analyst with over a decade of experience in digital asset ecosystems, I’ve observed that the Philippines’ Bangko Sentral ng Pilipinas (BSP) has established one of the most rigorous regulatory frameworks for Virtual Asset Service Providers (VASPs) in Southeast Asia. The BSP’s VASP licensing regime is not merely a compliance checkbox—it is a cornerstone of market integrity and investor protection in a region where crypto adoption is accelerating rapidly. A robust Anti-Money Laundering (AML) framework is central to this regime, particularly given the Philippines’ historical challenges with financial crime and its growing role as a crypto hub. For VASPs operating under a BSP license, implementing a thorough AML check is not optional; it is a legal and operational imperative that directly impacts credibility, market access, and long-term sustainability.

From a practical standpoint, an effective AML check in the Philippines must go beyond basic transaction monitoring. It requires a multi-layered approach that includes customer due diligence (CDD), enhanced due diligence (EDD) for high-risk clients, real-time transaction screening against global sanctions lists, and continuous monitoring of suspicious activity. The BSP’s guidelines, aligned with FATF Recommendations, mandate that VASPs maintain comprehensive records, report suspicious transactions to the Anti-Money Laundering Council (AMLC), and conduct regular internal audits. Failure to meet these standards can result in severe penalties, including license revocation. For institutional players and serious market entrants, demonstrating a proactive AML posture is a key differentiator—it signals trustworthiness to regulators, partners, and customers alike. In my analysis, VASPs that invest in advanced AML technologies and foster a culture of compliance will not only survive but thrive in the Philippines’ evolving digital asset landscape.