Verihubs Logo
Home Blog Insurance AML Philippines: Covered Person Checklist
10 min read • ID Check • Published on September 30, 2026

Insurance AML Philippines: Covered Person Checklist

Insurance AML Philippines: Covered Person Checklist

TL;DR: Insurance AML in the Philippines applies because the Anti-Money Laundering Act names insurance companies, pre-need companies, and every other entity the Insurance Commission regulates as covered persons. They must know their customers and beneficiaries, screen against sanctions and PEP lists, report covered and suspicious transactions to the AMLC, and keep records for five years.

Why the AMLA Treats Insurers as Covered Persons

First, the legal hook is Section 3(a)(2) of the AMLA, as amended by RA 10365. It lists “insurance companies, pre-need companies and all other persons supervised or regulated by the Insurance Commission” as covered persons. So the duty reaches beyond life insurers to pre-need firms, HMOs, mutual benefit associations, and brokers under Commission supervision.

The Commission also sits on the council that enforces the law. Under RA 11521, the AMLC consists of the BSP Governor as chair, with the Insurance Commissioner and the SEC Chairman as members. For a broader primer, our AMLC guide for covered persons covers registration and powers.

Risk is not equal across products, though. Life and investment-linked policies store value, allow early surrender, and pay third parties, so they draw most of the attention. Meanwhile, a one-year motor policy offers little room to move money. FATF’s 2018 risk-based guidance for the life insurance sector reflects the same logic, which is why a good program weights controls by product instead of applying one rulebook to everything.

How Money Laundering Shows Up in Insurance

Launderers like insurance because the money comes back looking clean. After all, a refund, a surrender value, or a claim payout arrives as a payment from a regulated insurer. For that reason, the red flags cluster around money leaving the policy, not just money coming in.

Red flagWhy it matters
Large single premium in cashPlaces cash into the financial system in one move
Cancellation soon after purchaseTurns dirty cash into an insurer refund
Overpayment followed by a refund requestCreates a clean payment for the excess
Premiums paid by an unrelated third partyHides the true source of funds
Beneficiary changed to an unrelated personMoves value to someone outside the profile

So notice the common thread. In each case, the policy works as a pipe rather than as protection, and the customer shows little interest in the cover itself.

Insurance AML Checklist: Eight Duties for Covered Persons

Next, use the eight points below to test an existing program. Each one maps to a legal duty and to the insurance-specific twist that generic AML guides tend to skip.

Duty 1: Register With the AMLC and Name a Compliance Officer

Before they can file reports, covered persons register with the AMLC. Then appoint a compliance officer with enough seniority to escalate cases and stop a payout. Without that authority, the role becomes a filing clerk.

Duty 2: Adopt a Board-Approved MTPP

The Money Laundering and Terrorism Financing Prevention Program (MTPP) is your written rulebook. It should name owners, thresholds, and escalation paths for each product line. Our walkthrough of AML compliance programs explains what a program must contain to pass AMLC review.

Duty 3: Assess Risk by Product, Channel, and Customer

To start, rank each product by how easily it can store and move value. Then add channel risk, such as agent-sold versus online, and customer risk. The Commission’s AML and CTF risk rating system, issued through Circular Letter 2020-08 on 24 February 2020, shows how the regulator itself scores regulated entities.

Duty 4: Identify Customers, Beneficiaries, and Beneficial Owners

Insurance, however, has an extra party most banks do not: the beneficiary. So verify the policyholder at onboarding and the beneficiary before payout, when the money actually moves. Verihubs ID verification confirms both parties against PhilSys, driver’s license, and SSS data. For corporate policyholders, trace the people behind the company, as our guide to identifying ultimate beneficial owners explains.

Duty 5: Screen Against Sanctions and PEP Lists

Ideally, screen names at onboarding, at every beneficiary change, and again at payout. Watchlist screening checks names against sanctions, terrorist, and politically exposed person lists and returns a risk flag on a match. A match on a PEP does not block the policy by itself, but it does trigger enhanced checks, which our explainer on handling politically exposed persons covers.

Duty 6: Monitor Insurance-Specific Red Flags

Generic bank rules often miss insurance patterns. Build alerts for early surrenders, free-look cancellations, overpayments, third-party premiums, and sudden beneficiary changes. Then review whether each alert closed for a real reason.

Duty 7: File CTRs and STRs on Time

Under RA 11521, a covered transaction is a cash or equivalent transaction above PHP 500,000 within one banking day. Section 9(c) of the AMLA sets a five-working-day reporting baseline, unless the AMLC prescribes a different period of up to 15 working days. According to the AMLC’s 2024 reporting guidelines (GoTRACS), STRs fall due by the next working day after the institution establishes suspicion.

Duty 8: Keep Records and Train Agents

Section 9(b) of the AMLA requires covered institutions to keep transaction records for five years. Also, train agents, since they meet the customer first and often see the cash. An agent who knows the red flags is the cheapest control in the program.

Common Gaps in Insurance AML Programs

Still, three gaps come up again and again. First, many insurers verify the policyholder but never re-verify the beneficiary at payout. Second, screening often runs once at onboarding, so a customer added to a sanctions list later goes unnoticed. Third, the Commission’s compliance questionnaire gave insurers a periodic self-check, yet Circular Letter 2023-06 suspended its submission. So check the Commission’s current advisories rather than assuming the old cycle still applies.

Frequently Asked Questions About Insurance AML in the Philippines

Does the AMLA apply to insurance companies?

Yes. Section 3(a)(2) of the AMLA, as amended, names insurance companies, pre-need companies, and all persons the Insurance Commission supervises or regulates as covered persons.

Does AML apply to non-life insurers?

Yes, because the law covers every entity the Insurance Commission regulates. In practice, however, life and investment-linked products carry more risk, so programs weight their controls toward those lines.

What is a covered transaction for an insurer?

Under RA 11521, it is a transaction in cash or an equivalent monetary instrument exceeding PHP 500,000 within one banking day.

When must an insurer file an STR?

The AMLA sets a five-working-day baseline, but according to the AMLC’s 2024 reporting guidelines, STRs fall due by the next working day after the insurer establishes suspicion.

Do insurers need to verify the beneficiary?

Yes. The beneficiary receives the money, so insurers should identify and screen them before payout, not only at policy issuance.

How long must insurers keep AML records?

Section 9(b) of the AMLA requires covered institutions to keep transaction records for five years from the transaction date.

Insurance AML Philippines Compliance Lives at the Payout

Today, most AML effort in insurance goes into onboarding. Yet the laundered money leaves through refunds, surrenders, and claims, often to someone other than the original customer. An insurer that screens and verifies again at payout closes the door launderers actually use.

Mapping these eight duties to your own workflow? Speak with Verihubs about screening and ID checks for IC-regulated firms.

Client Verihubs
Detect Suspicious Activities with Verihubs Watchlist Screening
Get FREE Trial
View Blog