Verihubs Logo
Home Blog AMLA Philippines: The Complete Compliance Guide (2026)
14 min read KYC Published on June 26, 2026

AMLA Philippines: The Complete Compliance Guide (2026)

AMLA Philippines: The Complete Compliance Guide (2026)

AMLA, the Anti-Money Laundering Act, is the Philippines’ primary law criminalizing money laundering under Republic Act No. 9160 (enacted 2001). It has been amended five times, most recently by RA 11521 in 2021, which added VASPs, real estate brokers, and POGO operators as covered persons and strengthened AMLC powers.

The Philippines came off the FATF grey list in February 2025 after completing all 18 required reforms under AMLA’s expanded framework. Banks, fintechs, e-wallets, and all covered persons must comply with AMLA’s CDD, reporting, and record-keeping obligations or face imprisonment of 7 to 14 years and fines starting at PHP 3 million.

What Is AMLA? Definition and Meaning

In the Philippines, the abbreviation refers specifically to Republic Act No. 9160, enacted on September 29, 2001. AMLA is the cornerstone of the Philippine legal framework against money laundering and terrorism financing. It defines money laundering, establishes who must comply, sets out which transactions require reporting, and prescribes penalties for violations.

Money laundering under AMLA is the act of transacting, converting, transferring, disposing, moving, acquiring, possessing, or using proceeds of any unlawful activity with the intent to conceal or disguise the illicit origin of those funds. The law does not require a completed concealment. Attempting to launder funds, or assisting someone in doing so, is equally punishable.

The AMLC (Anti-Money Laundering Council) is the government body responsible for implementing and enforcing AMLA. In simple terms, AMLA provides the legal framework, while the AMLC oversees its enforcement.

AMLA Amendments: From RA 9160 to RA 11521

Since its enactment, AMLA has been amended five times, with each amendment expanding its coverage and strengthening enforcement requirements. As a result, the compliance obligations under the law have evolved significantly over the past two decades.

LawYearKey Changes
RA 9160 (AMLA)2001Original enactment. Established AMLC, defined covered transactions, set reporting obligations for banks and financial institutions.
RA 91942003Expanded definition of money laundering. Strengthened AMLC investigation powers. Broadened the list of predicate offenses.
RA 101672012Gave AMLC authority to freeze assets and conduct bank inquiries in terrorism financing cases without prior court order.
RA 103652013Expanded covered persons to include real estate brokers, dealers in precious metals, and company service providers. Aligned with FATF 2012 recommendations.
RA 109272017Added casinos (land-based, online, and ship-based) as covered persons. Set PHP 5 million CTR threshold for casino cash transactions.
RA 115212021Added VASPs (crypto exchanges), POGO operators, and their service providers. Added tax crimes as predicate offenses. Strengthened AMLC freeze order powers. Introduced targeted financial sanctions for proliferation financing.

According to Philippine News Agency reporting in January 2021, RA 11521 was enacted as part of efforts to address the Philippines’ AML/CFT deficiencies and avoid placement on the Financial Action Task Force (FATF) grey list.

However, the Philippines was placed on the FATF grey list in June 2021. Nevertheless, the reforms introduced through RA 11521 formed part of the broader measures that strengthened the country’s AML/CFT framework.

As a result, these reforms helped support the Philippines’ eventual removal from the FATF grey list in February 2025.

AMLA Philippines amendments timeline from RA 9160 2001 to RA 11521 2021

What Is Money Laundering Under AMLA?

AUnder AMLA, reportable transactions fall into two main categories: covered transactions and suspicious transactions.

For covered transactions, Covered Transaction Reports (CTRs) are mandatory when a single cash transaction, or a series of related cash transactions, exceeds the applicable threshold within a single banking day. The threshold depends on the type of covered person:

  • Banks, e-wallets, and most financial institutions: cash transactions exceeding PHP 500,000
  • Casinos: cash transactions exceeding PHP 5,000,000
  • Real estate developers and brokers: single cash transactions exceeding PHP 7,500,000, as introduced by RA 11521

Suspicious Transaction Reports (STRs), however, work differently. There is no minimum transaction amount for an STR. Instead, a transaction must be reported when it has no clear legal or economic purpose, is inconsistent with the customer’s known profile, appears structured to avoid reporting requirements, or otherwise raises AML red flags.

For example, patterns such as smurfing and structuring, where large sums are divided into smaller transactions to stay below reporting thresholds, can trigger STR obligations.

The two reports also have different filing deadlines, which is an important distinction for covered persons. Under AMLA, the baseline reporting period is five working days. However, AMLC Regulatory Issuance No. 2, Series of 2024, also known as GoTRACS, requires STRs to be filed through the AMLC File Transfer and Reporting Facility by the next working day from the occurrence of the suspicious transaction. CTRs, meanwhile, remain subject to the five-working-day reporting period.

Importantly, the concept of “occurrence” affects when the STR reporting clock begins. For STRs, occurrence does not necessarily refer to the date when the transaction took place. Instead, GoTRACS defines it based on when the covered person establishes the suspicion or determines the suspicious nature of the transaction.

This distinction matters because a suspicious transaction may only become identifiable after the initial transaction has taken place. Consequently, compliance teams need to document when they established the suspicion and ensure that the internal review and reporting process can meet the applicable deadline.

Who Are Covered Persons Under AMLA?

AMLA’s compliance obligations apply to all “covered persons,” which include:

  • Banks, quasi-banks, trust entities, and BSP-supervised institutions
  • Insurance companies, pre-need companies, and HMOs
  • Securities dealers, brokers, and investment companies
  • Money service businesses: remittance agents, money changers, foreign exchange dealers
  • Virtual asset service providers (VASPs): crypto exchanges and digital asset platforms
  • Financing and lending companies
  • Real estate developers and brokers for qualifying transactions
  • Casinos, including online and ship-based casinos
  • Jewelry dealers and dealers in precious metals for transactions above PHP 1 million
  • Company service providers, lawyers, and accountants in specific circumstances

AMLA Compliance Obligations for Covered Persons

Under AMLA, every covered person has four core compliance obligations, regardless of its size or sector. These requirements cover customer due diligence, transaction reporting, record keeping, and the implementation of an AML/CTF compliance program.

Customer Due Diligence (CDD)

First, covered persons must verify the identity of customers when establishing a business relationship, maintain the relevant records, and update customer information based on the customer’s risk profile. CDD may also require collecting source of funds documentation, particularly for high-risk customers.

For PEPs and other customers who present elevated risks, Enhanced Due Diligence (EDD) may apply. In addition, BSP Circular 1230, issued in February 2026, raised the threshold for applying EDD to certain cash withdrawals from PHP 500,000 to PHP 1 million.

Transaction Reporting

Next, covered persons must report covered and suspicious transactions to the AMLC within the applicable reporting period. CTRs are generally filed within five working days through GoTRACS, while STRs must be filed by the next working day from the establishment of suspicion.

At the same time, covered persons must avoid tipping off customers about the filing or existence of an STR, as doing so can carry criminal liability. Because the STR reporting window is so short, institutions need an internal process that can review, validate, escalate, and make reporting decisions within a single working day.

Record Keeping

Covered persons must retain customer identification documents and transaction records for at least five years after the date of the transaction or the termination of the business relationship, as applicable. These records must also be available to the AMLC when requested.

AML/CTF Compliance Program

Finally, each covered person must conduct an institutional risk assessment and maintain a written AML/CTF compliance program. The program should establish appropriate internal controls, employee training, audit procedures, monitoring processes, and escalation protocols.

Moreover, the compliance program cannot remain static. Covered persons must regularly review and update it to reflect changes in their risk profile, business activities, applicable regulations, and AML/CFT risks.

AMLA Penalties for Money Laundering in the Philippines

Under Republic Act No. 9160, as amended by RA 11521, violations of AMLA can result in criminal penalties, fines, and other sanctions. The applicable penalties depend on the nature of the violation and the provision breached. Key penalties include:

OffenseImprisonmentFine
Money laundering conviction7 to 14 yearsPHP 3 million minimum, up to twice the laundered amount
Negligent money laundering (unknowing facilitation)4 to 7 yearsPHP 1.5 million to PHP 3 million
Failure to report covered/suspicious transactions6 months to 4 yearsPHP 100,000 to PHP 500,000, or imprisonment, or both
Tipping off3 to 8 yearsPHP 500,000 to PHP 1 million

These penalties apply to both the institution and the individual officers responsible. A bank that fails to file an STR faces exposure; so does the compliance officer who missed it.

AMLA and the FATF Grey List: The Philippine Compliance Context

The Financial Action Task Force (FATF) added the Philippines to its grey list in June 2021 because of strategic deficiencies in the country’s AML/CTF framework. Despite the recent enactment of RA 11521, the Philippines still had significant gaps to address under the FATF action plan.

Over the following years, the Philippine government and the AMLC implemented reforms aimed at addressing these deficiencies. These measures included strengthening the supervision of virtual asset service providers (VASPs), expanding the coverage and supervision of designated non-financial businesses and professions (DNFBPs), improving the AMLC’s investigative capacity, and strengthening enforcement against money laundering and related financial crimes.

As a result of these broader reforms, the FATF removed the Philippines from its grey list in February 2025 after confirming that the country had completed the required action plan and addressed the identified deficiencies.

For covered persons, however, the grey list exit does not mean that AML/CFT compliance requirements have become less important. Instead, it reinforces the need for effective, risk-based compliance programs and stronger implementation of existing controls. Covered persons that have not reviewed their AMLA compliance programs since the reforms introduced after 2021 may therefore be operating with outdated policies, procedures, and risk controls.

AMLA in Banking: What Does It Mean for a Bank Customer?

When a bank asks customers about their source of funds, requests additional documentation for large deposits, or declines a transaction without explanation, you are seeing AMLA requirements in practice. Banks are not being intrusive arbitrarily. Instead, AMLA requires them to understand the nature and purpose of their customers’ funds and report transactions that do not fit the customer’s known profile or raise other AML concerns.

Individual customers feel AMLA compliance in three concrete ways: having documentation ready for large transactions, expecting additional questions when transaction patterns look unusual, and understanding that a bank’s CDD procedures are a legal obligation, not optional customer service.

Frequently Asked Questions About AMLA in the Philippines

What does AMLA stand for in the Philippines?
AMLA stands for Anti-Money Laundering Act, officially Republic Act No. 9160, enacted on September 29, 2001. It is the Philippines’ primary law criminalizing money laundering and establishing compliance obligations for banks, fintechs, and other covered persons.
What is the AMLA threshold in the Philippines?
The general cash transaction threshold triggering a Covered Transaction Report (CTR) is PHP 500,000 per banking day for most financial institutions. The threshold is PHP 5 million for casinos and PHP 7.5 million for real estate transactions. These are reporting thresholds, not laundering thresholds. Any transaction regardless of amount must be reported if it raises suspicious activity indicators.
What are predicate offenses under AMLA?
Predicate offenses are the underlying crimes whose proceeds can constitute money laundering. Under AMLA as amended by RA 11521, these include drug trafficking, kidnapping, robbery, estafa, plunder, trafficking in persons, illegal gambling, terrorism financing, tax crimes, and violations of the Strategic Trade Management Act, among others.
Did the Philippines pass the FATF review?
Yes. In February 2025, the FATF removed the Philippines from its grey list after the country completed all 18 required reforms. The Philippines had been under increased monitoring since June 2021. The grey list exit reflects sustained improvements in AMLA enforcement, VASP supervision, and AMLC investigation capacity.
What is the difference between AMLA and AMLC?
AMLA is the law (Republic Act No. 9160). AMLC is the Anti-Money Laundering Council, the government body established by AMLA to implement and enforce it. AMLA defines obligations and penalties; AMLC has the authority to investigate, freeze assets, and prosecute violations.
Is AMLA compliance required for fintech companies in the Philippines?
Yes. Fintech companies operating as e-money issuers, lending companies, financing companies, or virtual asset service providers are covered persons under AMLA as amended by RA 11521. They must register with the AMLC, implement CDD, file CTRs and STRs, and maintain a written AML/CTF compliance program.

AMLA Compliance Is Not a One-Time Setup

Ironically, the institutions most likely to face AMLC scrutiny are not those that tried to cheat the system. They are those that set up compliance once, then stopped. The most common AMLA compliance failure among Philippine fintechs and digital banks is treating compliance as a setup task rather than an ongoing operational function. AMLA obligations do not stop after the AMLC registration is approved. They require live CDD at every onboarding, STR review on every flagged transaction, record archiving on every customer interaction, and program updates every time regulations change.

The identity verification layer is where this starts. eKYC Philippines infrastructure needs to be capable of verifying government IDs, detect synthetic identities, and support ongoing monitoring at scale. Verihubs eKYC API provides that layer, covering 9 Philippine document types including PhilSys, passport, driver’s licence, UMID, and SSS ID with AI liveness detection and deepfake prevention, built for the compliance requirements of BSP, AMLC, and RA 11521.

Talk to the Verihubs team about building AMLA-compliant eKYC into your onboarding workflow.

View Blog