Verihubs Logo
Home Blog AML Compliance Philippines: How to Build a Program That Passes AMLC
12 min read KYC Published on July 24, 2026

AML Compliance Philippines: How to Build a Program That Passes AMLC

AML Compliance Philippines: How to Build a Program That Passes AMLC

AML compliance in the Philippines is operated through a written, risk-based Money Laundering and Terrorism Financing Prevention Program, commonly abbreviated MTPP. It must be approved by the board or equivalent governing body, and it must cover customer identification, ongoing monitoring, record retention, covered and suspicious transaction reporting, training, employee screening, internal audit, compliance officer designation, and the risks of new products and technologies. The AMLC publishes an outline, but states plainly that there is no one-size-fits-all MTPP.

AML Compliance, AMLA, and AMLC: Three Different Things

These terms get used interchangeably, and the confusion causes real problems when teams try to work out what they actually need to produce.

AMLA is the law: Republic Act No. 9160 as amended, defining the offence, the covered persons, the thresholds, and the penalties. The AMLC is the enforcement body: the financial intelligence unit that receives reports, issues guidance, examines covered persons, and prosecutes.

AML compliance is neither. It is the operating system you build so your institution actually does what the law requires, day after day, in a way an examiner can inspect. The law tells you the destination. The AMLC checks whether you arrived. Your program is how you travel.

The MTPP: Your Program Document

Every covered person needs a written Money Laundering and Terrorism Financing Prevention Program. Sector and issuance determine the acronym, so you will encounter MTPP, MLPP, and ML/TFPP referring to the same instrument, with newer versions folding in proliferation financing after RA 11521.

The core requirements are consistent. According to Respicio’s summary of the AMLC guidelines, the program must be written, risk-based, and approved by the board, governing body, partners, or sole proprietor, and it should cover customer identification, ongoing monitoring, record retention, covered transaction reporting, suspicious transaction reporting, training, employee screening, internal audit, compliance officer designation, and new product or technology risks.

For designated non-financial businesses and professions, the AMLC publishes an MTPP Outline setting out the minimum requirements under Section 9 of the 2021 AML/CTF Guidelines, issued through AMLC Regulatory Issuance No. 03, Series of 2021.

One line in that AMLC guidance deserves more attention than it gets: the outline is explicitly not the only acceptable format, because there is no one-size-fits-all MTPP given the different risks and business models of covered persons. Downloading a template and changing the company name produces a document that describes someone else’s institution. Examiners read for that.

Required Elements of a Philippine AML Program

ElementWhat it must establish
Customer identificationHow identity is verified at onboarding, per customer type and risk tier
Ongoing monitoringHow transactions are monitored and customer profiles refreshed over time
Record retentionRetention for at least five years, retrievable on AMLC request
Covered transaction reportingCTR detection, thresholds, and filing within five working days
Suspicious transaction reportingThe reporting chain, decision authority, and the next-working-day deadline
TrainingWho is trained, on what, how often, and how it is evidenced
Employee screeningPre-employment and ongoing screening of staff
Internal auditIndependent testing of the program and correction of findings
Compliance officerDesignation, authority, and reporting line
New products and technologyRisk assessment before launching new products or channels

Governance: Who Owns What

Philippine AML governance separates two roles deliberately, and blurring them is a finding waiting to happen.

The board or governing body approves the MTPP, including policies, procedures, and risk assessments. That sign-off is a formal statement that the institution’s approach aligns with regulatory requirements, and it carries accountability. The board also oversees implementation rather than delegating and disengaging.

The Compliance Officer translates policy into operation: implementing the program, advising the board on ML and TF matters, keeping measures current with emerging trends and detection techniques, and ensuring that infractions discovered through internal audit or through AMLC, BSP, or SEC examination are corrected immediately.

In the examination context, that word carries weight. A finding acknowledged but unremediated at the next examination is materially worse than the original finding, because it demonstrates that the correction mechanism itself does not work.

Risk Assessment Is the Foundation, Not a Formality

Everything in a risk-based program derives from the institutional risk assessment. Get it wrong and every downstream control is calibrated to the wrong threat.

A workable assessment covers customer risk, including PEPs, non-residents, and high-risk occupations; product risk, since a high-limit remittance product carries different exposure than a basic savings account; channel risk, where remote digital onboarding differs materially from in-branch; and geographic risk across both jurisdictions and domestic areas.

The output should be a documented rationale for why your controls are set where they are. When an examiner asks why your enhanced due diligence threshold sits at a particular level, “that is what the template said” is not an answer. The risk assessment is where the answer is supposed to live.

Where Philippine AML Programs Actually Fail

Four patterns recur, and none of them are exotic.

The template program. A borrowed MTPP that describes controls the institution does not operate. This surfaces the moment an examiner compares the written procedure to what staff actually do.

Outdated deadlines. Programs still specifying a five-working-day window for STR filing, when GoTRACS requires filing by the next working day from establishment of suspicion. Widely published guidance still carries the old figure, so this error propagates easily.

Sanctions handled as a reporting event. Programs that route a sanctions match into the STR process rather than the freeze process. As covered in our guide to sanctions screening, a confirmed match requires freezing without delay and a return to the AMLC within 24 hours, not an STR.

Internally contradictory timelines. A reporting chain that allots three days to review and two to escalate cannot meet a next-working-day obligation. The program disproves its own compliance on paper, and an examiner only has to read it.

What Examiners Look For

Examination is less about whether documents exist and more about whether the program is alive.

Expect scrutiny on the gap between written procedure and observed practice; whether the risk assessment justifies the control calibration; whether training happened and can be evidenced; whether internal audit findings were corrected and how quickly; whether CTR and STR filings were complete, accurate, and timely; whether decisions not to file were documented; and whether the compliance officer has genuine authority rather than a title.

That last point is where smaller institutions most often struggle. A compliance officer who cannot decline an account or escalate past a commercial manager is not exercising the authority the program claims they hold.

The CDD Layer Underneath Everything

Customer identification is the first required element for a reason. Every other control consumes its output.

Transaction monitoring compares activity against a customer profile built at onboarding. Sanctions and PEP screening runs against the identity captured at onboarding. Risk tiering depends on customer attributes recorded at onboarding. Where identity verification is weak, none of these controls fail loudly. They run normally against unreliable data and return clean results.

Verihubs eKYC API supplies that foundation for Philippine covered persons, with government ID verification across 15+ document types, biometric liveness detection, and deepfake detection built for BSP Circular 1170 requirements. It is one component of an AML program rather than the program itself, but it is the component every other control depends on.

Frequently Asked Questions About AML Compliance in the Philippines

What is an MTPP?

MTPP stands for Money Laundering and Terrorism Financing Prevention Program. It is the written, risk-based AML program every Philippine covered person must adopt, approved by the board or equivalent governing body. Depending on sector and issuance you may also see it called an MLPP or ML/TFPP, and newer versions incorporate proliferation financing following RA 11521.

What must a Philippine AML program contain?

At minimum: customer identification, ongoing monitoring, record retention, covered transaction reporting, suspicious transaction reporting, training, employee screening, internal audit, compliance officer designation, and assessment of new product and technology risks. The AMLC publishes an MTPP Outline reflecting Section 9 of the 2021 AML/CTF Guidelines.

Who approves the MTPP?

The board of directors, governing body, partners, or sole proprietor, depending on the structure of the covered person. Approval is a formal accountability step, and the board also carries oversight responsibility for implementation rather than only signing off on the document.

Can we use the AMLC MTPP template as-is?

Not without adaptation. The AMLC states that its outline is not the only acceptable format because there is no one-size-fits-all MTPP, given the different risks and business models of covered persons. A program that describes controls your institution does not actually operate is a finding rather than a defence.

What is the difference between AMLA and AML compliance?

AMLA is the law setting out obligations and penalties. AML compliance is the operating program an institution builds and runs to meet those obligations in practice, documented in the MTPP and inspected by the AMLC and the institution’s primary supervisor.

How long must AML records be retained in the Philippines?

At least five years from the transaction date or the termination of the business relationship, and records must be retrievable for AMLC inspection without delay.

A Program Is Judged on Whether It Runs, Not on Whether It Exists

The gap that examinations expose is rarely a missing document. It is the distance between a well-drafted MTPP and the actual behaviour of the institution: procedures nobody follows, timelines that contradict current rules, findings acknowledged and never fixed, a compliance officer with responsibility but no authority.

Closing that gap starts with making the mechanical parts genuinely reliable, so the judgment-dependent parts get the attention they need. Identity verification is the most mechanisable element in the whole program, and the one every other control silently depends on.

Verihubs eKYC API handles that layer for Philippine institutions, verifying government IDs, running biometric liveness, and detecting deepfakes at the point of onboarding, so the customer profiles your program is built around are ones you can actually rely on.

Talk to the Verihubs team about the CDD foundation of your AML compliance program.

View Blog