Commercial and Taxation Laws › Banking Law › Anti-Money Laundering (RA 9160, as amended by RA 9194, 10167, 10365, 10927, 11521, 11930, and 12312)
1. Covered Persons and Their Obligations
Covered Institutions
- Banks, non-banks, quasi–banks, trust entities, foreign exchange dealers, pawnshops, money changers, remittance and transfer companies and other similar entities and all other persons and their subsidiaries and affiliates supervised or regulated by the BSP;
- Insurance companies, pre-need companies and all other persons supervised or regulated by the Insurance Commission;
- Those who are:
- Securities dealers, brokers, salesmen, investment houses and other similar entities managing securities or rendering services as investment agent, advisor, or consultant,
- Mutual funds, close – end investment companies, common trust funds, pre – need companies and other similar entities
- Foreign exchange corporations, money changers, money payment, remittance and transfer companies and other similar entities, and
- Other entities administering or otherwise dealing in currency, commodities or financial derivatives based thereon, valuable objects, cash substitutes and other similar monetary instruments or property supervised or regulated by the Securities and Exchange Commission (SEC).
- Jewelry dealers in precious metals, who, as a business, trade in precious metals, for transactions in excess of Php1,000,000.
- Company service providers which, as a business, provide any of the following services to third parties:
- Acting as a formation agent of juridical persons;
- Acting as, or arranging for another person to act as:
- director or corporate secretary of a company
- partner of a partnership, or
- A similar position in relation to other juridical persons;
- Providing a registered office, business address or accommodation, correspondence or administrative address for a company, a partnership or any other legal person or arrangement; and
- Acting as, or arranging for another person to act as, a nominee shareholder for another person
- Persons who provide any of the following services:
- Managing of client money, securities or other assets
- Management of bank, savings or securities accounts
- Organization of contributions for the creation, operation or management of companies; and
- Creation, operation or management of juridical persons or arrangements and buying or selling business entities [Sec. 1]1.
- Casinos, including internet and ship-based casinos, with respect to their casino cash transactions related to their gaming operations [Sec. 1].
The term ‘covered persons’ excludes lawyers and accountants acting as independent legal professionals:
- in relation to information concerning their clients; or
- where disclosure of information would compromise client confidences or the attorney-client relationship.
Provided:
- that these lawyers and accountants are authorized to practice in the Philippines and
- shall continue to be subject to the provisions of their respective codes of conduct and/or professional responsibility or any of its amendments [Sec. 1].
Obligations of Covered Institutions
- Customer Identification
- Record Keeping
- Reporting of Covered and Suspicious Transactions
Customer Identification
Covered institutions shall:
- Establish and record a true identity of its clients, based on official documents
- Maintain a system of verifying the true identity of their clients
- In case of corporate clients, require a system to verify:
- Legal existence and organizational structure; and
- Authority and identification of persons purporting to act on their behalf
Anonymous accounts, accounts under fictitious names, and all other similar accounts shall be absolutely prohibited. Peso and foreign currency non- checking numbered accounts shall be allowed. The BSP may conduct annual testing solely limited to the determination of the existence and true identity of the owners of such accounts [Sec. 9]2.
Record Keeping
All records of all transactions of covered institutions shall be maintained and safely stored for five (5) years from the dates of transactions.
With respect to closed accounts, the records on customer identification, account files and business correspondence, shall be preserved and safely stored for at least five (5) years from the dates when they were closed.
Reporting of Covered and Suspicious Transactions
General Rule: Covered persons shall report to the AMLC all covered and suspicious transactions within five (5) working days from their occurrence.
Exception: If the Anti Money Laundering Council (AMLC) prescribed a longer period not exceeding fifteen (15) working days [Sec. 9(c)]3.
When reporting covered transactions to the AMLC:
- Covered persons and their officers, and employees are prohibited from communicating, directly or indirectly, in any manner, to any person, entity, or the media:
- The fact that a covered or suspicious transaction has been reported or is about to be reported;
- The contents thereof;
- Any other information in relation thereto; and
- Neither may such reporting be published or aired in any manner or form by the mass media, electronic mail, or other similar devices [Sec. 9, RA 10365]4.
In case of violation, criminal liability ensues as against the concerned officer and employee of the covered person and media.
Anti-money laundering regulations
Republic Act No. 91605, otherwise known as the Anti-Money Laundering Act, as amended (AMLA) and its 2018 implementing rules and regulations6 (IRR) impose certain obligations upon covered persons to ensure that the Philippines will not be used as a money laundering site for the proceeds of any unlawful activity. Below are the key obligations of covered persons under the AMLA and its IRR.
Customer due diligence (CDD) obligations
Under the AMLA IRR, covered persons must conduct CDD for the following purposes:
- to identify the customer, and its agents and beneficial owners;
- to determine the risk posed by each customer;
- to establish, maintain, close or terminate the account or business relationship; and
- to assess the level of monitoring to be applied.
CDD measures must be undertaken when:
- establishing business or professional relationship;
- carrying out occasional transactions above PHP100,000 or any other threshold as may be determined by the relevant supervising authority, with notice to the Anti-Money Laundering Council (AMLC), including situations where the transaction is carried out in a single operation or in several operations that appear to be linked;
- carrying out occasional wire transfers under certain circumstances;
- there is a suspicion of money laundering/terrorism financing (ML/TF), regardless of any exemptions or thresholds; or
- the covered person has doubts about the veracity or adequacy of previously obtained identification information and/or data.
Further, the AMLA IRR requires covered persons to apply CDD requirements to existing customers on the basis of materiality and risk, and conduct due diligence on existing relationships at appropriate times, taking into account whether and when CDD measures have previously been undertaken and the adequacy of information and document obtained.
In conducting CDD, the covered persons must adopt appropriate CDD measures following a risk-based approach, which include the following procedures:
Customer identification process - covered persons shall identify and record the true identity of their customers, whether permanent or occasional, and whether natural or juridical person, or legal arrangement.
Note that in case the customer engages in a transaction with a covered person for the first time, the covered person must require the customer to present the original and submit a clear copy of, at least, one identification document (ID). In case the ID presented does not bear any photo of the customer, or the photo-bearing ID or a copy thereof does not clearly show the face of the customer, a covered person may utilize information and communication technology or any other technology to take the photo of the customer.
Customer verification process - covered persons shall implement and maintain a system of verifying the true identity of their clients, including validating the truthfulness of the information and confirming the authenticity of the identification documents presented, submitted and provided by the customer, using reliable and independent sources, documents, data, or information.
The covered persons must independently verify the collected data during customer identification process, through any of the following:
- face-to-face contact;
- use of information and communication technology;
- by confirming the authenticity of the identification documents to the issuing office;
- reliance on third parties and service providers; or
- such other methods of validation based on reliable and independent sources, documents, data, or information.
Identification and verification of agents - covered persons shall verify that any person purporting to act on behalf of a customer is so authorized and identify and verify the identity of that person.
The covered person must verify the validity of the authority of the agent. In case of doubt as to whether the person purporting to act on behalf of the customer is being used as a dummy in circumvention of existing laws, the covered person must apply enhanced due diligence and file a suspicious transaction report, if warranted.
Beneficial ownership verification - covered persons shall identify the beneficial owner and take reasonable measures to verify the identity of the beneficial owner, using the relevant information or data obtained from reliable sources, such that the covered person is satisfied that it knows who the beneficial owner is.
The covered person must obtain a copy of the written document evidencing the relationship and apply the same standards for assessing the risk profile and determining the standard of CDD to be applied to both.
Determination of the purpose of relationship - covered persons shall understand and, as appropriate, obtain information on, the purpose and intended nature of the account, transaction, or the business or professional relationship with their customers.
Ongoing monitoring process - covered persons shall, on the basis of materiality and risk, conduct ongoing monitoring by establishing a system that will enable them to understand the normal and reasonable account or business activity of customers, and scrutinize transactions undertaken throughout the course of the business or professional relationship to ensure that the customers’ accounts, including transactions being conducted, are consistent with the covered person’s knowledge of its customer, their business and risk profile, including where necessary, the source of funds.
Covered persons must develop a clear set of criteria for customer risk profiling and assessment, which must include at least three of the following:
- The nature of the service or product to be availed of by the customers;
- The purpose of the account or transaction;
- The source of fund and source of wealth;
- The nature of business and/or employment;
- Country of origin and residence of operations, or the fact that a customer came from a high- risk jurisdiction or geographical area;
- Watchlist of individuals and entities engaged in illegal activities or terrorist related activities as circularized by the BSP, AMLC, and other international entities or organizations, such as the Office of Foreign Assets Control of the U.S. Department of the Treasury and United Nations Sanctions List;
- The existence of suspicious transaction indicators; and
- Such other factors as the covered persons may deem reasonable or necessary to consider in assessing the risk of a customer, including the amount of funds to be transacted by a customer or the size of transactions undertaken, regularity or duration of the transaction, and/or are included in the negative list.
Where the risks are higher, covered persons must conduct enhanced due diligence. On the other hand, where lower risks of ML/TF have been identified, through an adequate analysis of risk by the covered person, reduced due diligence procedures may be applied.
Transaction reporting
Covered persons must report both covered and suspicious transactions to the AMLC within five working days of occurrence, unless the AMLC prescribes a different period not exceeding 15 working days; they must also comply with applicable AMLC registration and reporting guidelines.
Record keeping
Under the AMLA IRR7, covered persons are required to maintain and safely store for five years from the dates of transactions all records of customer identification and transactions documents. Further, covered persons must keep the electronic copies of all covered and suspicious transaction reports, for at least five years from the dates of submission to the AMLC. In addition, covered persons shall keep all records obtained through CDD, account files and business correspondence, and the results of any analysis undertaken, for, at least, five years following the closure of account, termination of the business or professional relationship or after the date of the occasional transaction.
If a case has been filed in court involving the account, records must be retained and safely kept beyond the five-year period, until it is officially confirmed by the AMLC Secretariat that the case has been resolved, decided, or terminated with finality.
Adoption of a money laundering and terrorist financing prevention program (MTPP)
Under the AMLA IRR8, covered persons must formulate and implement a comprehensive and risk-based MTPP that is compliant with the AMLA9 and Republic Act 1016810 (otherwise known as Terrorism Financing Prevention and Suppression Act or TFPSA), their respective IRR, and other AMLC issuances, and the AML/CTF guidelines of their supervising authorities. The MTPP must be commensurate to the size and risk profile of the covered person. The covered person must consider the results of the national risk assessment and its own risk assessment in the development and/or updating of its MTPP. The MTPP shall be in writing and shall include, at the minimum, internal policies, controls, and procedures on the following:
- risk management;
- compliance management setup, including the designation of a compliance officer at the management level or creation of compliance unit;
- screening procedures to ensure high standards when hiring employees;
- continuing education and training program;
- independent audit function;
- details of implementation of CDD, record-keeping and reporting requirements;
- compliance with freeze, bank inquiry and asset preservation orders, and all directives of the AMLC;
- adequate safeguards on the confidentiality and use of information exchange, including safeguards to prevent tipping-off; and
- cooperation with the AMLC and supervising authority.
Designation of an AML compliance officer
Covered persons must designate an AML compliance officer or create a compliance unit, responsible for the covered person’s day-to-day compliance with the AMLA and TFPSA, their respective IRR, and other AMLC issuances. The internal auditor, general manager, or proprietor, as the case may be, shall be the compliance officer in case the resources of the covered person hamper the establishment of the compliance unit. The compliance officer or the head of the compliance unit must be of senior management level.
Authorities
- , Sec. 1
- , Sec. 9
- 2018 Implementing Rules and Regulations of Republic Act No. 9160
- AMLA
- AMLA IRR
- RA 10365, Sec. 9
- RA 9160
- RA 9160, Sec. 9
- Republic Act 10168