BSP 1170
BSP 1170
BSP 1170
The Monetary Board, in its Flesolution No.4O2 dated 23 March 2023, approved the
amendments to the provisions of Section 921 of the Manual of Regulations for Banks (MORB)
and Section 92lQ of the Manual of Regulations for Non-Bank Financial lnstitutions
(MORNBFI) on customer due diligence, including guidelines on electronic Know-Your-
Customer (e-KYC) using digital identity (lD) system.
Section l. Section 921 of the MORB and Section 92lQ of the MORNBFI on customer due
diligence is hereby amended to read, as follows:
(l ) xxx;
xxx
(4) xxx.
Where a covered person is unable to comply with the relevant CDD measures,
considering risk-based approach, it shall (a) not open the account, commence
business relations, or perform the transaction; or (b) terminate the business
relationship; but in both cases, it shall consider filing a suspicious transaction report
(STR)in relation to the customer.
xxx
a. Minimuminformation/documentsrequired:
Unless otherwise stated in this Part, average CDD requires that the covered
person obtain from individual customers, at the time of account
opening/establishing the relationship, the following minimum information
and veriff the customer's identity with the official or valid identification
documents or other reliable, independent source documents, data, or
information:
(a) name of customer and/or Philsys Card Number (PCN )or the Philsys Number
(PSN ) derivative;
xxx
(g)xxx;
Pursuant to Republic Act No. llO55 or the Philippine ldentification System Act
and its Revised lmplementing Rules and Regulations (RIRR), the Philippine
ldentification System (PhilSys) is the government's central identification
platform for all citizens and resident aliens of the Philippines. An individual's
records in the Philsys shall be considered as an official and sufficient proof of
identity. Considering its identity proofing, enrolment, authentication and
identiry life cycle management processes, the PhilSys is considered a reliable and
independent source of veriffing the customer's identity. Where the PCN or PSN
derivative, orthe Philippine ldentification (PhillD)card, in physicalordigital form,
is presented by the customer, it shall be accepted as official and sufficient proof
of identity, subject to proper authentication, and the covered person shall no
longer require additional document to veriff the customer's identity.
xxx
(2) lf the official document presented is not the PhillD, PCN or PSN derivative, a
covered person may classiff identification documents based on its reliability
and ability to validate the information indicated in the identification
document with that provided by the customer and ensure that risks are
mitigated.
ln cases where the PhillD is presented, only the front portionface should be
photocopied/scanned. The PSN located at the back portion of the PhillD must
remain confidential subject to applicable laws and regulations. In this regard,
covered persons may only obtain either the PCN or PSN derivative indicated in the
PhillD presented as part of customer identification and verification.
Covered persons shall also comply with the required digitization of customer
records, as applicable, pursuant to relevant BSP and AMLC issuances.
Page 2 of5
Relief in case of calamity.ln case of a disastrous calamity xxx
The use of ICT in the conduct of face-to-face contact and/or interview may
be alfowed: Provided, That the covered person has measures in place to mitigate
the ML"ffF risks and that key CDD processes are documented or with adequate
audit trail.
xxx
When employing e-KYC using a digital lD system, the covered person should
ensure that it is anchored on, among others, robust, effective, and reliable
information and communication technology architecture. Where the tiering is
based on, among others, level of access and authentication assurance levels, it
shall adopt a tiered or risk-based e-KYC policies and procedures (e.9., low tier level
has access to basic authentication which requires minimum assurance levels or
controls; access to subsequent tier level and additional services requires higher
assurance/controls). Assurance levels refer to the extent of trustworthiness or
confidence in the reliability of each of the three (3)stages of the digital lD process,
from identity proofing and enrolment to authentication, and identity lifecycle
management. In implementlng e-KYC through digital lD system, the covered
person shall:
(2) Apply informed risk-based approach to reliance on digital lD system for CDD
that includes the requirement under item "(l)" above and ensure that the
assurance level/s are appropriate for the ML/[F risks presented by the
customer, product, delivery channel, geographical location, among others.
This will enable the implementation of a tiered customer identification and
acceptance process that leverages digital lD systems with various assurance
levels to support financial inclusion. For example. in case of non-face-to-face
channels, if the customer identification and verification depend on reliable,
independent digital lD system with appropriate risk mitigation measures,
this may pose normal risk, or even lower risk where higher assurance levels
are implemented. The assurance level will determine if the digital lD system
is reliable and independent for AMVCFT purposes.
In any case, the relying covered person has the ultimate responsibility for the
customer identification/verification process, and effective authentication, using
the digital lD system provided by the digital lD service provider, and ensure that
risk-based approach is applied in the use of the digital lD systems for customer
identification/verification and authentication.
The covered person shall ensure that its conduct of e-KYC compties with relevant
user consent and data sharing and protection lprivacy laws, rules and regulations
for data processing, storage, and management. All related transaction/s and their
attendant risks or obligations, including the roles and responsibilities of each
party involved, must be explicitly, clearly, and adequately provided by the
covered person, and are explained to, understood, and accepted by the
customer.
Page 4 of 5
Covered persons implementing e-KYC must perform customer identification and
verification process under the same standards equivalent to those for face-to-
face basis, and shall establish appropriate risk management processes.
Consistent with Section OO2 of the MORB/Section OO2Q of the MORNBF|, the
BSP may deploy appropriate supervisory enforcement actions to promote
adherence with the requirements set forth in this Section and bring about timely
corrective actions.
h. Trustee, nomineexxx
xxx
Section 2. The following transitory provision shall be incorporated as footnote to item "g." on
e-KYC under Section 92ll921Qof the MORB/MORNBFI:
Covered persons with existing e-KYC, using a digital lD system, at the time of the
effectivity of this Circular shall comply with the requirements prescribed herein within one
(1) year from effectivity of this Circular. For covered persons without existing e-KyC and
intend to adopt the same, they shall ensure strict compliance with the e-KYC requirements
prescribed in this Circular prior to implementation.
Section 3. This Circular shall take effect fifteen (15) calendar days following its publication
either in the official Gazette or in a newspaper of general circulation.
EDUARDO BOBIER
Officer-in harge
p-March2Cl23
Page 5 of 5