How Does BSP Circular No. 1213 Protect Financial Accounts?
Introduction
Digital banking, electronic payments, and mobile wallets have increased access to financial services but have also created new avenues for phishing, account takeover, unauthorized transfers, and other forms of financial fraud. Philippine financial institutions are therefore required to maintain systems that can identify suspicious activity quickly and protect customers before losses become irreversible.
BSP Circular No. 1213, Series of 2025, implements the information-technology risk management requirements of the Anti-Financial Account Scamming Act, or AFASA. It strengthens the obligations of banks, non-bank financial institutions, payment service providers, and clearing switch operators to deploy automated and real-time fraud monitoring and detection systems.
What Is BSP Circular No. 1213?
BSP Circular No. 1213 amends the information-technology risk management provisions of the Manual of Regulations for Banks, the Manual of Regulations for Non-Bank Financial Institutions, and the Manual of Regulations for Payment Systems.
Its stated purpose is to implement the information-technology risk management requirements under Section 6 of R.A. No. 12010, or the Anti-Financial Account Scamming Act. The circular was approved by the Monetary Board through Resolution No. 521 dated May 22, 2025. [BSP Circular No. 1213 (2025)](#I1.0)
The circular applies to BSP-supervised financial institutions and clearing switch operators covered by the amended regulatory provisions. It raises the expected level of fraud prevention from general internal controls to technology-enabled systems capable of continuous monitoring, detection, and response.
What Does AFASA Require?
Section 6 of AFASA requires institutions to protect access to clients’ financial accounts through adequate risk management systems and controls. These controls include multi-factor authentication, fraud management systems, and account-owner enrollment and verification processes.
The controls must be proportionate and commensurate with the nature, size, and complexity of the institution’s operations. This means that a large universal bank, a digital bank, an electronic-money issuer, and a smaller financial institution may use different systems, provided that each system is adequate for the risks associated with its operations.
AFASA also creates an important liability distinction. An institution determined by the BSP to be compliant with adequate risk management systems and controls is not liable for losses arising from the offenses covered by the law. By contrast, an institution may be liable for restitution when it failed to employ adequate controls or failed to exercise the highest degree of diligence in preventing the loss or damage. A criminal conviction is not required before restitution may be imposed. [Anti-Financial Account Scamming Act](#L1.6)
What Is a Fraud Management System?
Under AFASA, a fraud management system is a comprehensive set of automated and real-time monitoring and detection systems used to identify and block disputed, suspicious, or other online transactions.
The definition has three important elements:
- Automated operation: the system should be capable of detecting and acting on risks without relying solely on manual review.
- Real-time or near-real-time monitoring: suspicious activity must be assessed promptly while a transaction or account event is occurring.
- Detection and blocking capability: the system should not merely record suspicious activity; it must be capable of preventing or interrupting transactions when the risk warrants intervention.
The institution’s system should be calibrated according to its products, transaction channels, customer base, and known fraud patterns. A system that exists only on paper, or that produces alerts without timely investigation and intervention, may not satisfy the statutory duty.
Required Technology and Security Controls
BSP Circular No. 1213 requires covered institutions to strengthen their information-technology risk management arrangements. Based on the circular’s stated amendments, the relevant controls include automated and real-time fraud management systems and transaction-monitoring capabilities suited to the institution’s risk profile.
The associated BSP requirements identify several technical measures that may be used to detect unusual activity, including the following:
| Control | Purpose |
|---|---|
| Transaction-velocity checks | Detect an unusual number or frequency of transactions within a specified period. |
| Geolocation monitoring | Identify transactions occurring from locations inconsistent with the customer’s normal activity or device history. |
| Behavioral-anomaly detection | Compare current activity with established customer behavior and identify significant deviations. |
| Multi-factor authentication | Require two or more verification factors before access or a covered transaction is authorized. |
| Account enrollment and verification controls | Confirm the identity of the account owner and the legitimacy of enrolled devices, accounts, and contact details. |
The precise configuration of each control may differ among institutions. The controlling standard is whether the combined measures are adequate, proportionate, and commensurate with the institution’s operations and risks.
How Should Institutions Design Their Fraud Systems?
Risk-based configuration
Institutions should begin with a documented assessment of the risks associated with each product and delivery channel. The assessment should consider transaction value, transaction frequency, customer behavior, device changes, geographic patterns, account age, beneficiary history, and known scam indicators.
Real-time transaction assessment
Fraud controls should evaluate transactions while they are being initiated or processed. Delayed review may be inadequate where the funds can be transferred immediately through electronic channels or withdrawn through multiple accounts.
Rules and behavioral analytics
A suitable system may combine fixed rules with behavioral analytics. Fixed rules can identify events such as unusual transaction velocity, rapid changes to account credentials, or transfers to newly added beneficiaries. Behavioral analytics can identify activity that departs materially from a customer’s established pattern even when no single transaction violates a preset rule.
Blocking, holding, or escalating transactions
Where a transaction presents a sufficiently high risk, the institution should have procedures for blocking, delaying, holding, or escalating the transaction for additional verification. The response should be proportionate to the risk and consistent with applicable BSP rules and the institution’s customer-protection procedures.
Human review and investigation
Automation does not eliminate the need for trained personnel. Institutions should maintain a process for investigating alerts, contacting customers through reliable channels, documenting decisions, and escalating suspected scams or account compromise to the appropriate internal and government authorities.
Other Controls Supporting AFASA Compliance
BSP guidance predating Circular No. 1213 identified additional controls for electronic payments and financial services. These include transaction notifications, a holding period before activating a new soft token, and a cooling-off period before implementing material account changes such as changes to a mobile number or email address.
Institutions have also been advised to use personalized one-time-password messages, prevent personnel from manually obtaining passwords or one-time-password credentials, establish dedicated customer assistance teams for suspected fraud, conduct customer education campaigns, and maintain strong fraud-surveillance mechanisms. [BSP Memorandum No. M-2022-015 (2022)](#I3.1)
These controls should be read together with the institution’s obligations under AFASA and the updated BSP information-technology risk management rules. They are especially relevant to social-engineering schemes in which fraudsters deceive customers into disclosing usernames, passwords, one-time passwords, account details, or other sensitive identifying information.
When May a Financial Institution Be Liable?
AFASA does not make every fraudulent transaction automatically compensable by the institution. Liability depends on whether the institution employed adequate risk management systems and controls and exercised the required degree of diligence.
The following conditions are material:
- The institution must have systems and controls appropriate to the nature, size, and complexity of its operations.
- The systems must be capable of protecting access to the customer’s financial account.
- The institution must exercise the highest degree of diligence in preventing losses arising from offenses covered by AFASA.
- Restitution may be required even without a criminal conviction.
- An institution’s BSP-determined compliance with the required systems and controls may shield it from liability for losses arising from the offenses covered by the statute.
Accordingly, institutions should preserve records showing system design, risk assessments, alert parameters, system performance, customer notifications, investigations, and remedial actions. These records may become important in a restitution claim, regulatory examination, or court proceeding.
Customer Protection and Fraud Reporting
Customers should promptly report unauthorized or suspicious transactions to the financial institution through its official channels. Delay may complicate the institution’s ability to hold or recover funds, investigate the transaction, and coordinate with other institutions or law-enforcement agencies.
Customers should also avoid sharing passwords, personal identification numbers, one-time passwords, card details, and other sensitive identifying information. Financial institutions should not ask customers to disclose credentials through unsolicited calls, messages, or links.
Earlier BSP guidance encouraged cooperation and information sharing among financial institutions and with law-enforcement authorities to support fraud investigation and recovery. Such sharing must remain consistent with applicable legal requirements on confidentiality, data protection, and proportionality.
Relationship With Bank Secrecy and Data Privacy Laws
Bank secrecy and data privacy rules remain applicable, but they do not prevent every disclosure connected with fraud investigation. In Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, et al., G.R. No. 273720, 2025, the Supreme Court held that the Cybercrime Prevention Act did not repeal the Bank Secrecy Law, while recognizing that a court-issued warrant to disclose computer data may authorize disclosure of account-holder identifying information in a cybercrime investigation. [Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, et al. (2025)](#J1.22)
The same decision recognized that AFASA authorizes BSP investigations and information sharing concerning financial accounts under investigation for violations of the statute. It further noted that the relevant restrictions on inquiry into or disclosure of deposits do not apply in the manner otherwise prohibited when the accounts are subject to a BSP investigation under AFASA, subject to the statute’s limitations. [Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, et al. (2025)](#J1.30)
Institutions should nevertheless disclose only information relevant to the legitimate investigative or regulatory purpose and should maintain appropriate records of the legal basis, requesting authority, scope, and recipient of the disclosure.
Illustrative Scenarios
Rapid transfers to a new beneficiary
A customer who normally makes small domestic payments suddenly adds a new beneficiary and initiates several high-value transfers within minutes. Transaction-velocity rules, beneficiary-risk scoring, and behavioral analytics should generate an alert and may justify additional verification or temporary intervention.
Unusual device and location combination
A customer’s account is accessed from a newly registered device and a location inconsistent with recent activity, followed by a password reset and fund transfer. Geolocation monitoring, device verification, multi-factor authentication, and cooling-off procedures may reduce the risk of unauthorized transfer.
Customer deceived through a phishing message
A customer discloses credentials after receiving a fraudulent message. The institution’s liability will depend on the facts, including the effectiveness of its authentication and fraud controls, the speed of its response, whether the transaction displayed warning signs, and whether the institution complied with the applicable AFASA and BSP requirements.
Compliance Measures for Financial Institutions
Financial institutions should consider the following measures:
- Conduct and periodically update institution-wide fraud and technology-risk assessments.
- Maintain automated, real-time fraud monitoring and detection systems appropriate to the institution’s products and transaction channels.
- Test transaction-velocity, geolocation, behavioral, device, and authentication controls against current fraud scenarios.
- Establish written procedures for blocking, holding, escalating, investigating, and resolving suspicious transactions.
- Document system performance, alert disposition, customer contact, recovery efforts, and regulatory reporting.
- Train personnel and customers on phishing, social engineering, credential protection, and official communication channels.
Conclusion
BSP Circular No. 1213 gives operational effect to AFASA’s requirement that financial institutions protect access to customer accounts through adequate and proportionate risk management controls. Its principal direction is clear: fraud prevention must be continuous, automated where appropriate, responsive to customer behavior, and capable of detecting or stopping suspicious online transactions.
Compliance should not be measured only by the existence of software or written policies. Institutions should be able to demonstrate that their controls are properly calibrated, regularly tested, actively monitored, and supported by timely human investigation and customer assistance. Customers, for their part, should report suspicious activity immediately and never disclose authentication credentials through unsolicited communications.
About Nicolas and De Vega Law Offices
Nicolas and de Vega Law Offices is a full-service law firm in the Philippines. You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines. You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

