Money Service Business Philippines: AMLA Compliance Guide
A money service business in the Philippines is a remittance and transfer company, money changer, or foreign exchange dealer, collectively regulated by the BSP and treated as a covered person under AMLA.
Two registrations are required, not one: BSP authority to operate, and separate registration with the AMLC Secretariat for covered and suspicious transaction reporting.
The framework has also moved. BSP Circular No. 1206 amended Sections 901-N and 902-N of the MORNBFI and consolidated MSB rules into a new M-Regulations book, so guidance citing only Circular 942 points at a superseded structure.
What Is a Money Service Business (MSB)?
MSB is a regulatory grouping rather than a business model. The BSP uses it to cover three activities that share one characteristic: they move value between people without holding it as a deposit.
The activity at the centre is money or value transfer service, which BSP Circular No. 942 defined as financial services involving the acceptance of cash, cheques, other monetary instruments, or other stores of value, and the payment of a corresponding sum in cash or another form to a beneficiary by means of a communication, message, transfer, or through a clearing network.
Under the AMLC’s Revised Implementing Rules, foreign exchange dealers, money changers, and remittance and transfer companies sit within the list of covered persons supervised or regulated by the BSP, alongside banks, quasi-banks, trust entities, pawnshops, non-stock savings and loan associations, and electronic money issuers.
MSB Types: Remittance, Foreign Exchange, Money Changer
Remittance and Transfer Company (RTC)
Accepts funds for transfer to a beneficiary, domestically or internationally. This is the largest category by volume in the Philippines for obvious structural reasons, given the scale of inbound overseas worker remittances.
Money Changer (MC)
Exchanges one currency for another as a business.
Foreign Exchange Dealer (FXD)
Deals in foreign currency, with overlapping activity to money changing depending on how the business is structured.
The regulatory perimeter reaches beyond these three, and that is where firms most often discover they are in scope unexpectedly. Remittance Platform Providers, defined as entities providing shared platform or IT infrastructure and maintaining settlement accounts to fund remittance transactions, fall inside it. So do agent structures: Remittance Direct Agents acting on behalf of a third party engaged in remittance business, Remittance Agent Network Providers, and Remittance Sub-agents.
A technology company that believed it was supplying software to remitters can find itself inside the perimeter on the platform-provider definition. The test is what the arrangement does, not how the contract describes it.
BSP Registration vs AMLC Registration
These are separate obligations to separate authorities, and completing one does not discharge the other.
| BSP | AMLC Secretariat | |
|---|---|---|
| Purpose | Authority to operate as an MSB | Registration for transaction reporting |
| What it enables | Lawful conduct of the business | Submission of CTRs and STRs |
| Timing | Before commencing operations | Alongside becoming a covered person |
| Ongoing duties | Notifications, prior approvals, activity reports | Reporting on the prescribed deadlines |
| Consequence of gaps | Monetary penalties on the firm and its directors and officers | Non-submission treated as a reporting failure |
BSP registration is staged rather than a single filing. The process runs through obtaining a letter of no objection to register articles with the SEC or Cooperative Development Authority indicating the purpose to operate as an MSB, and then applying for authority to establish and operate as an MSB, with documentary requirements including business permits and, where applicable, a list of remittance tie-up partners.
Older material refers to a BSP Certificate of Registration, while current BSP licensing material describes a Certificate of Authority to Establish and Operate as MSB. Both terms remain in circulation, which is worth knowing when reading guidance of uncertain vintage.

Ongoing BSP obligations after registration
Registration is not the end of the relationship. MSBs must notify the BSP on commencement of operations, accreditation of new remittance sub-agents, changes of tie-up partners, transfer of location, and closure of business. Prior BSP approval is required for any change in ownership or control, and activity level reports are submitted on an ongoing basis.
The sub-agent notification duty is the one that most often slips, because sub-agent networks change faster than compliance calendars do.
Why MSBs Are Treated as High-Risk Covered Persons
The sector’s risk profile follows from its structure rather than from any assumption about the people running it.
Transactions are frequently cash-in and cash-out, which breaks the audit trail that account-to-account movement preserves. Many customers are occasional rather than account-holding, so there is no relationship history to compare behaviour against. Cross-border corridors carry inherent exposure. And agent and sub-agent networks distribute the customer-facing function across many locations and operators, each of which becomes a control point the head office does not directly staff.
That last feature is the structural one. An MSB’s compliance programme has to operate through people it does not employ, in locations it does not control, which is a materially harder problem than running the same programme inside a bank branch network.
Scale gives a sense of the surface area involved. BSP figures reported in 2018 put registered MSBs at more than 18,000, comprising around 5,300 head offices and 12,700 branches, with roughly 6,700 also operating as BSP-authorised pawnshops.
CDD and EDD Obligations for MSB Customers
MSBs carry the same customer due diligence obligations as any covered person: identify the customer, verify identity against reliable evidence, understand the purpose of the transaction, and monitor on an ongoing basis. Average due diligence applies by default, and reduced due diligence requires documented risk profiling to support it.
Two features of MSB operations make this harder to execute than in a bank.
Occasional customers are the norm rather than the exception. A remittance sender may transact once, which means identification and verification must complete inside a single short interaction with no relationship history to draw on.
Verification happens at the counter, often by agent staff rather than by employees of the registered MSB. The quality of a compliance programme designed at head office is determined by execution at hundreds of locations, which is why automated verification tends to deliver more consistency gain in this sector than in any other.
Enhanced due diligence applies where risk is higher, including politically exposed persons, non-residents, and customers whose transaction patterns diverge from their stated profile.
CTR and STR Filing for MSBs
Reporting obligations follow the general framework. Covered transaction reports apply to single cash transactions exceeding PHP 500,000 in one banking day for most covered persons, filed within five working days from occurrence. Suspicious transaction reports carry no minimum amount and are due by the next working day from the establishment of suspicion under GoTRACS.
Our guide to the STR covers the filing chain and deadline in full, including the point that many published guides still cite a superseded five-working-day STR figure.
Three practical complications are specific to this sector. Structuring across agent locations is easy for a customer to attempt and hard for an agent to see, since each location observes only its own transactions. Aggregation across a network therefore has to happen centrally rather than at the counter. And the reporting obligation sits with the registered MSB regardless of which agent handled the transaction, so the escalation path from a sub-agent counter to the compliance officer is part of the reporting chain rather than an internal courtesy.
Post-FATF Exit: What Changed for the Sector
The Philippines was removed from the FATF grey list in February 2025 after completing the reforms in its action plan, and remittance was among the sectors under scrutiny during that period.
Coming off the list did not lower the bar. Two things followed instead. Supervisory attention shifted from demonstrating that rules exist to demonstrating that they work in practice, which is examination of effectiveness rather than of documentation. And the reforms accepted as evidence of progress now function as the baseline an examiner expects to find operating.
Sector-level obligations were also expanded through the same period. RA 11521 brought virtual asset service providers, real estate brokers, and POGO operators into the covered person definition, and BSP Circular No. 1206 addressed VASPs in the same instrument that restructured the MSB framework, which reflects how closely the two sit in the regulatory picture.
For an MSB, the practical translation is that a written AML compliance program is now assessed against what agents actually do at the counter, and our guide to the AMLC covers the supervisory relationship in more detail.
Frequently Asked Questions About MSBs in the Philippines
What qualifies as a money service business in the Philippines?
- Remittance and transfer companies, money changers, and foreign exchange dealers, collectively regulated by the BSP as MSBs. The perimeter also reaches remittance platform providers that supply shared platform infrastructure and maintain settlement accounts, along with remittance direct agents, agent network providers, and sub-agents.
Do MSBs need to register with both the BSP and the AMLC?
- Yes. BSP registration confers authority to operate as an MSB. Separate registration with the AMLC Secretariat is required for covered and suspicious transaction reporting purposes. Completing one does not discharge the other.
Is BSP Circular 942 still the governing rule for MSBs?
- Not on its own. Circular 942, dated 20 January 2017, placed MSBs within BSP regulation and remains the source of key definitions. BSP Circular No. 1206 subsequently amended Sections 901-N and 902-N of the MORNBFI and consolidated the MSB framework into a new M-Regulations book, so guidance citing only Circular 942 reflects a superseded structure.
What must an MSB notify the BSP about after registration?
- Commencement of operations, accreditation of new remittance sub-agents, changes of tie-up partners, transfer of location, and closure of business. Prior BSP approval is required for any change in ownership or control, and activity level reports are submitted on an ongoing basis.
Are MSB reporting thresholds different from those of banks?
- The general framework applies. Covered transaction reports cover single cash transactions exceeding PHP 500,000 in one banking day for most covered persons, filed within five working days from occurrence, while suspicious transaction reports have no minimum amount and are due the next working day from the establishment of suspicion.
Who is responsible when a sub-agent fails to perform CDD?
- The registered MSB carries the obligation. Agent and sub-agent networks distribute the customer-facing function, but the reporting and due diligence duties sit with the covered person, which is why escalation paths from agent counters to the compliance officer form part of the reporting chain.
A Compliance Programme That Has to Work Through Other People’s Staff
Most AML guidance implicitly assumes the institution employs everyone who touches a customer. For an MSB that assumption fails at the first agent location.
The compliance officer writes the procedure, and it is executed by counter staff at hundreds of sites, employed by other businesses, trained to varying standards, under commercial pressure to complete transactions quickly. Documentation quality varies. So does the judgment applied to a customer whose story does not quite fit.
Automated verification narrows that variance, because the identity check runs identically regardless of who is standing at the counter. It does not solve agent oversight, and no vendor should claim it does. What it removes is the part of the variance that comes from asking untrained staff to assess documents by eye.
Verihubs eKYC API covers 15+ Philippine government ID types with PhilSys authentication, biometric liveness, and deepfake detection, delivering the same verification standard at every location in a network.
Talk to the Verihubs team about consistent customer verification across an agent network.