How Does AFASA Change Philippine Fintech Compliance?
Introduction
The Anti-Financial Account Scamming Act introduces major responsibilities for Philippine digital banks, e-wallet operators, payment service providers, and other financial institutions. By criminalizing social engineering schemes and money muling, Republic Act No. 12010 shifts fraud prevention from a largely reactive function to a continuing institutional responsibility.
The law also requires covered institutions to protect access to financial accounts through proportionate security controls, including multi-factor authentication, fraud management systems, and account-owner verification. Institutions that fail to employ adequate controls may be required to return lost funds even without a criminal conviction.
For fintech companies, compliance now involves more than cybersecurity policies. It affects product design, customer onboarding, transaction monitoring, incident response, dispute handling, fund restitution, employee training, and coordination with the Bangko Sentral ng Pilipinas.
What Is the Anti-Financial Account Scamming Act?
Republic Act No. 12010, known as the Anti-Financial Account Scamming Act or AFASA, regulates the use of financial accounts and penalizes schemes that use financial accounts to obtain money or financial information through deception, unauthorized access, or other fraudulent conduct.
The law applies to financial institutions and other providers under BSP supervision, including banks, non-bank financial institutions, payment service providers, and other institutions offering financial products or services. Its policy is to protect financial consumers and prevent financial accounts from being used in fraudulent activities. ([Anti-Financial Account Scamming Act (AFASA)](#L1.0))
Which Fintech Companies Are Covered?
AFASA covers institutions under the jurisdiction of the BSP. This generally includes digital banks, electronic-money issuers, payment service providers, banks offering mobile or online banking, and other BSP-supervised entities that maintain or process financial accounts.
The law defines a financial account broadly. It may include an account used to access financial products or services covered by the Financial Products and Services Consumer Protection Act. Consequently, coverage is not limited to traditional deposit accounts and may extend to digital wallets, payment accounts, and similar accounts used for financial services.
Fintech companies should therefore assess their activities based on the financial service actually provided, not merely on the label used for the product. A platform described as a wallet, marketplace, payment application, or digital account may still fall within the law if it enables access to regulated financial products or services.
What Conduct Does AFASA Penalize?
Social engineering schemes
AFASA criminalizes social engineering schemes involving the acquisition of sensitive identifying information through deception or fraud for the purpose of gaining unauthorized access to a financial account. Examples include impersonating a bank employee, sending deceptive electronic communications, or falsely representing that a customer must disclose an OTP, password, or other credential.
In Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, et al., G.R. No. 273720, 2025, the Supreme Court discussed a “vhishing” incident in which a victim was deceived into giving an OTP after being promised rewards. The decision recognized AFASA’s treatment of social engineering as a form of financial cybercrime. ([Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, et al. (2025)](#J1.30))
Money muling
The statute also criminalizes money muling. This generally involves the use of a person’s financial account to receive, transfer, withdraw, or otherwise move proceeds connected with fraudulent activity.
The risk is not limited to organized criminal groups. A person who lends an account, receives funds for another person, or allows a wallet to be used without sufficient verification may become involved in a prohibited transaction. Fintech companies must therefore identify suspicious account behavior and maintain controls against the recruitment or use of account holders as intermediaries.
What New Account-Protection Duties Apply?
Section 6 of AFASA requires institutions to ensure that access to client financial accounts is protected by adequate risk-management systems and controls. These controls must be proportionate and commensurate with the institution’s nature, size, and operational complexity.
The law specifically identifies the following controls:
- Multi-factor authentication, requiring at least two verification factors;
- Fraud management systems capable of automated, real-time monitoring and detection;
- Account-owner enrollment and verification processes; and
- Other safeguards appropriate to the institution’s operations and risk profile.
The requirement is not satisfied merely by having a written cybersecurity policy. The controls must operate effectively in actual customer transactions, account enrollment, credential recovery, device changes, fund transfers, and fraud investigations.
What Technical Controls Should Fintechs Maintain?
BSP Memorandum No. M-2024-029 reiterates that BSP-supervised financial institutions must employ adequate systems and controls to protect financial accounts. It refers to information-technology and cybersecurity controls under the Manual of Regulations for Banks, the Manual of Regulations for Non-Bank Financial Institutions, and related BSP rules. ([BSP Memorandum No. M-2024-029 (2024)](#I1.0))
BSP Circular No. 1213 further amended information-technology risk-management rules to implement the account-protection requirements of AFASA. The amendments address fraud-management systems and related technology controls for BSP-supervised financial institutions and payment-system participants. ([BSP Circular No. 1213 (2025)](#I3.0))
Depending on the institution and product, an effective control environment may include:
- Transaction-velocity and frequency monitoring;
- Device, location, and behavioral analysis;
- Risk-based transaction authentication;
- Controls over new-device enrollment and password recovery;
- Real-time blocking or review of suspicious transactions;
- Clear audit trails and non-repudiation controls; and
- Escalation procedures for high-risk or disputed activity.
The appropriate controls depend on the product’s size, complexity, customer base, transaction volume, and exposure to fraud. A control that may be proportionate for a small account product may be inadequate for an institution processing high-value transfers or operating a large digital wallet network.
When Can a Fintech Company Be Liable for Customer Losses?
AFASA distinguishes between institutions that comply with adequate risk-management requirements and those that fail to meet them. An institution determined by the BSP to be compliant with the required controls is not liable under Section 6 for losses arising from the offenses covered by the law, without prejudice to other liabilities under existing law and BSP regulations.
By contrast, an institution may be liable for restitution when it fails to employ adequate risk-management systems and controls or fails to exercise the highest degree of diligence in preventing loss or damage arising from the covered offenses.
Criminal conviction is not required before restitution may be ordered. This means that a customer’s restitution claim may depend on the institution’s compliance, diligence, transaction controls, and handling of the incident, rather than on the successful prosecution of the fraudster. ([Anti-Financial Account Scamming Act (AFASA)](#L1.6))
Fintech companies should preserve evidence showing how controls operated at the time of the transaction. Relevant records may include authentication logs, device information, alerts, customer notifications, risk scores, call recordings, investigation notes, and the institution’s response to the customer’s report.
Can Disputed Funds Be Temporarily Held?
AFASA allows BSP-supervised institutions to temporarily hold funds subject to a disputed transaction for a period not exceeding 30 calendar days, subject to the grounds and procedures prescribed by law and applicable BSP regulations.
BSP Memorandum No. M-2024-030 reiterates the 30-calendar-day limit and discusses the protection of consumer assets against fraud and misuse. A fund hold is a protective measure while the transaction is reviewed; it is not a final determination that the account holder or recipient committed an offense. ([BSP Memorandum No. M-2024-030 (2024)](#I5.3))
Operational policies should therefore specify who may authorize a hold, what evidence is required, how the affected customer will be notified, how the account is monitored during the hold, and how the funds will be released, returned, or otherwise handled after the investigation.
What Information May Be Shared During Investigations?
AFASA gives the BSP authority to investigate financial accounts and share relevant information with law-enforcement and other competent authorities, subject to the law’s limitations. Section 13 also allows the BSP or its authorized officers to apply for cybercrime warrants and related orders under the Cybercrime Prevention Act.
In Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, et al., the Supreme Court held that a bank may qualify as a service provider under the Cybercrime Prevention Act because it processes and stores computerized data for customers. The Court further held that a court-issued warrant to disclose computer data may permit the disclosure of account-holder identification information without violating bank-secrecy rules, while the confidentiality of deposit information remains subject to the applicable statutory exceptions. ([Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, et al. (2025)](#J1.22))
The decision also recognized the interaction among the Cybercrime Prevention Act, the Data Privacy Act, and AFASA in authorized cybercrime investigations. Disclosure must still be connected to a lawful purpose and must comply with the applicable warrant, order, statutory authority, and procedural safeguards. ([Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, et al. (2025)](#J1.28))
How Does AFASA Interact with Data Privacy?
Fintech companies remain responsible for protecting customer information. At the same time, data privacy rules do not prevent all disclosures to the BSP, law-enforcement agencies, or other public authorities.
Information necessary for the performance of legally authorized public functions may be processed under the Data Privacy Act, subject to the limits of the applicable law and the purpose for which the information is requested. Processing should remain proportionate, secure, documented, and limited to information reasonably necessary for the investigation or regulatory function.
Internal procedures should distinguish between:
- Routine customer-service disclosures;
- Fraud-investigation disclosures;
- Disclosures made pursuant to a court-issued warrant or order;
- Regulatory submissions to the BSP; and
- Emergency actions required to protect customers or prevent further loss.
Each category should have an identified legal basis, approving officer, recordkeeping requirement, and information-security control.
What Should Digital Banks and E-Wallet Providers Do?
Compliance officers and senior management should treat AFASA as an enterprise-wide obligation. The following measures are appropriate starting points:
- Map all financial accounts and services. Identify every account type, payment function, transfer channel, access method, and third-party service connected to the institution’s systems.
- Test authentication and enrollment controls. Review account opening, device registration, password recovery, OTP delivery, SIM changes, and changes to customer contact details.
- Assess fraud-monitoring capability. Determine whether suspicious transactions can be detected and acted upon in real time, including unusual velocity, device changes, location anomalies, and behavioral deviations.
- Establish a 30-day fund-hold process. Define the grounds, approvals, notices, investigation steps, and final disposition of disputed funds.
- Document restitution decisions. Records should explain the institution’s controls, the customer’s actions, the transaction history, the investigation performed, and the reason for granting or denying restitution.
- Improve customer warnings. Customers should receive clear warnings that institutions will not request passwords, PINs, or OTPs through deceptive calls, messages, or links.
- Control third-party access. Agents, outsourced service providers, merchants, and technology vendors should be subject to contractual security, monitoring, reporting, and audit requirements.
- Conduct regular independent testing. Fraud controls should be tested through simulations, red-team exercises, incident reviews, and assessments of false positives and false negatives.
Typical Examples
Example 1: Deceptive OTP request. A fraudster impersonates a bank employee and persuades a customer to disclose an OTP. The customer suffers an unauthorized transfer. The institution should examine the authentication process, warnings, transaction-monitoring alerts, response time, and whether its controls were adequate and properly implemented.
Example 2: Suspicious wallet pass-through activity. A newly opened wallet receives multiple transfers from unrelated persons and rapidly sends the funds to another account. The pattern may indicate money muling. The provider should apply risk-based monitoring, investigate the account, preserve records, and take authorized protective action.
Example 3: Disputed transfer reported promptly. A customer reports an unauthorized transaction and identifies the recipient account. The institution may consider a temporary fund hold if the statutory and regulatory grounds exist, but the hold cannot exceed 30 calendar days under the applicable AFASA authority.
What Are the Main Legal Risks for Fintech Companies?
The most significant risks are not limited to the criminal acts of fraudsters. Institutions may also face regulatory scrutiny, restitution claims, data-protection issues, consumer complaints, and reputational harm when their systems fail to detect or prevent suspicious activity.
Special Commercial Courts are designated to hear certain cases involving banking, bank secrecy, and related financial laws under the Supreme Court’s rules on the expansion of cases cognizable by Special Commercial Courts. ([A.M. No. 3-3-3-SC (2021)](#J2.5))
Fintech companies should therefore preserve a complete compliance record. A well-documented system showing risk assessment, control testing, incident response, customer communication, and management oversight may be material in demonstrating that the institution exercised the diligence required by law.
Conclusion
AFASA changes the compliance expectations for Philippine fintech companies. Digital banks, e-wallet providers, payment service providers, and other covered institutions must maintain effective account-protection controls, detect suspicious activity, respond promptly to disputed transactions, and be prepared to restore funds when statutory requirements are not met.
The immediate priority should be a documented review of authentication, fraud monitoring, account enrollment, customer warnings, fund holds, restitution, data sharing, and third-party controls. Senior management should ensure that these measures are operational, tested, and proportionate to the institution’s actual risk profile.
AFASA compliance is therefore not solely a legal or information-technology function. It requires coordinated responsibility among the board, senior management, compliance officers, cybersecurity teams, fraud investigators, customer-service personnel, legal counsel, and outsourced service providers.
About Nicolas and De Vega Law Offices
Nicolas and de Vega Law Offices is a full-service law firm in the Philippines. You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines. You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

