ADVERTISEMENT

BSP: Banks cannot pass anti-money laundering liability to payment aggregators

Published May 11, 2026 12:00 am

At A Glance

  • Philippine banks must strengthen safeguards against money laundering and terrorism financing across all payment activities, the Bangko Sentral ng Pilipinas (BSP) ordered, warning that banks remain accountable for violations even when using third-party payment aggregators.

Philippine banks must strengthen safeguards against money laundering and terrorism financing across all payment activities, the Bangko Sentral ng Pilipinas (BSP) ordered, warning that banks remain accountable for violations even when using third-party payment aggregators.

Under Memorandum No. 2026-017 issued last Friday, May 8, the central bank directed all BSP-supervised financial institutions (BSFIs) to maintain rigorous onboarding and monitoring processes to prevent the financial system from being used for illegal transactions.

Notably, the new rule clarified that the participation of payment aggregators in the payment chain cannot “transfer, diminish, or substitute” the legal obligations of banks providing the underlying settlement services and access to payment rails.

“[Banks] are expected to retain primary responsibility for anti-money laundering and counter-terrorism and proliferation of weapon of mass destruction financing (AML/CTPF) compliance for merchant payment activities, whether conducted as the originating financial institution (OFI) or the receiving financial institution (RFI), through payment aggregators or similar intermediaries,” the memo read.

A payment aggregator is an entity that facilitates the acceptance and processing of transactions for multiple merchants by providing them access to payment services, rails, and settlement.

Some payment aggregators operating in the Philippines include PayMongo, DragonPay, and Xendit.

These entities are responsible for onboarding and managing merchants, often transacting on their behalf while maintaining independent obligations for AML and risk monitoring.

While efficient for scaling digital payments, the BSP noted that this intermediary role creates additional operational layers that must not obscure regulatory visibility.

To address this, the BSP clarified that “payment aggregators or similar entities bear independent and commensurate AML/CTPF responsibilities” regarding their specific roles in onboarding and controlling sub-merchant access.

These responsibilities include conducting merchant due diligence, implementing risk mitigation measures, and “suspicious transaction reporting, in accordance with the above regulations.”

However, the BSP stressed that responsibility ultimately remains with the banks.

Even as aggregators manage their own functions, the regulator said banks “retain primary responsibility for AML/CTPF risks associated with settlement accounts.”

To comply with the directive, banks are now required to maintain “adequate visibility over the underlying merchants and related payment activities.”

Banks must also ensure they have “sufficient access to sub-merchant information, transaction-level data, and merchant risk profiles.”

Additionally, the new rule stressed that banks cannot take a passive approach to oversight.

They are expected to apply risk-based standards when onboarding and monitoring sub-merchants.

Banks must also conduct “periodic reviews with clear triggers for restricting or terminating relationships involving high-risk or non-compliant sub-merchants.”

To prevent the commingling of funds, the memo also said accounts must be properly classified.

Banks are required to ensure that account openings follow the Manual of Regulations for Payment Systems (MORPS) definition of a merchant account, which refers to a transaction account used to receive funds from merchant payment activities.

To maintain the integrity of these transactions, banks were instructed to “maintain clear and effective differentiation between merchant accounts and personal accounts” based on the nature and risk characteristics of the activity.

Further, the BSP raised concerns over the growing incidence of digital payment fraud, particularly involving the exploitation of quick-response (QR) code technology.

As such, banks must implement appropriate risk-based measures to prevent and detect mule merchants, including the unauthorized use or misuse of QR codes by individuals or entities other than registered merchants.

Related Tags

Bangko Sentral ng Pilipinas (BSP) Banks QRPH anti-money laundering/countering the financing of terrorism (AML/CFT)
ADVERTISEMENT
.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1561_widget.title }}

.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1562_widget.title }}

.most-popular .layout-ratio{ padding-bottom: 79.13%; } @media (min-width: 768px) and (max-width: 1024px) { .widget-title { font-size: 15px !important; } }

{{ articles_filter_1563_widget.title }}

{{ articles_filter_1564_widget.title }}

.mb-article-details { position: relative; } .mb-article-details .article-body-preview, .mb-article-details .article-body-summary{ font-size: 17px; line-height: 30px; font-family: "Libre Caslon Text", serif; color: #000; } .mb-article-details .article-body-preview iframe , .mb-article-details .article-body-summary iframe{ width: 100%; margin: auto; } .read-more-background { background: linear-gradient(180deg, color(display-p3 1.000 1.000 1.000 / 0) 13.75%, color(display-p3 1.000 1.000 1.000 / 0.8) 30.79%, color(display-p3 1.000 1.000 1.000) 72.5%); position: absolute; height: 200px; width: 100%; bottom: 0; display: flex; justify-content: center; align-items: center; padding: 0; } .read-more-background a{ color: #000; } .read-more-btn { padding: 17px 45px; font-family: Inter; font-weight: 700; font-size: 18px; line-height: 16px; text-align: center; vertical-align: middle; border: 1px solid black; background-color: white; } .hidden { display: none; }
function initializeAllSwipers() { // Get all hidden inputs with cms_article_id document.querySelectorAll('[id^="cms_article_id_"]').forEach(function (input) { const cmsArticleId = input.value; const articleSelector = '#article-' + cmsArticleId + ' .body_images'; const swiperElement = document.querySelector(articleSelector); if (swiperElement && !swiperElement.classList.contains('swiper-initialized')) { new Swiper(articleSelector, { loop: true, pagination: false, navigation: { nextEl: '#article-' + cmsArticleId + ' .swiper-button-next', prevEl: '#article-' + cmsArticleId + ' .swiper-button-prev', }, }); } }); } setTimeout(initializeAllSwipers, 3000); const intersectionObserver = new IntersectionObserver( (entries) => { entries.forEach((entry) => { if (entry.isIntersecting) { const newUrl = entry.target.getAttribute("data-url"); if (newUrl) { history.pushState(null, null, newUrl); let article = entry.target; // Extract metadata const author = article.querySelector('.author-section').textContent.replace('By', '').trim(); const section = article.querySelector('.section-info ').textContent.replace(' ', ' '); const title = article.querySelector('.article-title h1').textContent; // Parse URL for Chartbeat path format const parsedUrl = new URL(newUrl, window.location.origin); const cleanUrl = parsedUrl.host + parsedUrl.pathname; // Update Chartbeat configuration if (typeof window._sf_async_config !== 'undefined') { window._sf_async_config.path = cleanUrl; window._sf_async_config.sections = section; window._sf_async_config.authors = author; } // Track virtual page view with Chartbeat if (typeof pSUPERFLY !== 'undefined' && typeof pSUPERFLY.virtualPage === 'function') { try { pSUPERFLY.virtualPage({ path: cleanUrl, title: title, sections: section, authors: author }); } catch (error) { console.error('ping error', error); } } // Optional: Update document title if (title && title !== document.title) { document.title = title; } } } }); }, { threshold: 0.1 } ); function showArticleBody(button) { const article = button.closest("article"); const summary = article.querySelector(".article-body-summary"); const body = article.querySelector(".article-body-preview"); const readMoreSection = article.querySelector(".read-more-background"); // Hide summary and read-more section summary.style.display = "none"; readMoreSection.style.display = "none"; // Show the full article body body.classList.remove("hidden"); } document.addEventListener("DOMContentLoaded", () => { let loadCount = 0; // Track how many times articles are loaded const offset = [1, 2, 3, 4, 5, 6, 7, 8, 9, 10]; // Offset values const currentUrl = window.location.pathname.substring(1); let isLoading = false; // Prevent multiple calls if (!currentUrl) { console.log("Current URL is invalid."); return; } const sentinel = document.getElementById("load-more-sentinel"); if (!sentinel) { console.log("Sentinel element not found."); return; } function isSentinelVisible() { const rect = sentinel.getBoundingClientRect(); return ( rect.top < window.innerHeight && rect.bottom >= 0 ); } function onScroll() { if (isLoading) return; if (isSentinelVisible()) { if (loadCount >= offset.length) { console.log("Maximum load attempts reached."); window.removeEventListener("scroll", onScroll); return; } isLoading = true; const currentOffset = offset[loadCount]; window.loadMoreItems().then(() => { let article = document.querySelector('#widget_1690 > div:nth-last-of-type(2) article'); intersectionObserver.observe(article) loadCount++; }).catch(error => { console.error("Error loading more items:", error); }).finally(() => { isLoading = false; }); } } window.addEventListener("scroll", onScroll); });

Sign up by email to receive news.