How Must Banks and E-Wallets Share Responsibility for Disputed Funds?

How Must Banks and E-Wallets Share Responsibility for Disputed Funds?

Introduction

Digital fund transfers often pass through several banks, electronic money issuers, payment platforms, and other financial institutions. When a transaction is disputed, the funds may move across multiple accounts before the receiving institution receives a complaint or fraud alert. This creates a need for coordinated investigation, temporary holding of funds, information sharing, and clear allocation of responsibility among participating institutions.

Philippine law now provides a specific system for addressing disputed electronic transactions. The Anti-Financial Account Scamming Act, or R.A. No. 12010, authorizes covered institutions to temporarily hold disputed funds and requires institutions and account owners to participate in a coordinated verification process. BSP Circular No. 1215, Series of 2025, supplies operational rules for tracing disputed transactions, exchanging relevant information, and determining responsibility for losses.

The objective is not to impose automatic liability on every institution in the transaction chain. Rather, responsibility depends on the institution’s role, its legal and regulatory duties, the adequacy of its controls, and whether it complied with the required investigation and holding procedures.

Governing Philippine Laws and Regulations

R.A. No. 12010 applies to financial accounts and institutions within the authority of the Bangko Sentral ng Pilipinas. It addresses social engineering schemes, money muling, unauthorized access, disputed transactions, and the institutional duties connected with preventing and investigating financial account scams.

Under Section 6 of R.A. No. 12010, institutions must protect access to financial accounts through adequate risk management systems and controls. These may include multi-factor authentication, fraud management systems, and account-owner enrollment and verification procedures. The controls must be proportionate and commensurate with the institution’s nature, size, and operational complexity.

An institution determined by the BSP to be compliant with adequate risk management requirements is not liable for losses arising from the offenses covered by the law. Conversely, an institution may be liable for restitution when it failed to employ adequate controls or failed to exercise the highest degree of diligence in preventing the resulting loss. A criminal conviction is not required before restitution may be ordered.

R.A. No. 12010 is supplemented by BSP Circular No. 1215, Series of 2025, titled “Regulations on the Temporary Holding of Funds Subject of Disputed Transactions and Coordinated Verification Process.” The circular applies to BSP-supervised institutions and establishes procedures for temporary holding, transaction tracing, information sharing, verification, release, and allocation of losses.

The Financial Products and Services Consumer Protection Act, R.A. No. 11765, also remains relevant. Under Section 13, a financial service provider is responsible for the acts and omissions of its directors, trustees, officers, employees, and agents in marketing and transacting with financial consumers. It is also solidarily liable with accredited third-party service providers for their acts or omissions in those activities.

What Is a Disputed Transaction?

Under R.A. No. 12010, a transaction may be treated as disputed when an institution has reasonable grounds to believe that it appears to be:

  • Unusual;
  • Without a clear economic purpose;
  • From an unknown or illegal source, or connected with unlawful activity; or
  • Facilitated through a social engineering scheme.

The reasonable grounds may arise from information provided by another institution, a complaint filed by an aggrieved party, or a finding generated by the institution’s fraud management system. The institution does not need to wait for a final finding of fraud before taking the temporary measures authorized by law.

A disputed transaction may involve a single transfer or a chain of transfers. For example, funds initially sent from a bank account may be transferred to an e-wallet, then to another e-wallet, and finally to a bank account. Each participating institution must examine the transaction in the context of the available transaction history and information received from other institutions.

Temporary Holding of Disputed Funds

R.A. No. 12010 authorizes institutions to temporarily hold funds subject of a disputed transaction for the period prescribed by the BSP. The holding period may not exceed 30 calendar days, unless it is extended by a court of competent jurisdiction.

The institution must promptly notify the BSP whenever it temporarily holds disputed funds. The institution must also act in accordance with BSP rules concerning the grounds, procedure, documentation, verification, release, and monitoring of the funds.

An institution, including its directors, trustees, officers, and employees, does not incur administrative, criminal, or civil liability for holding disputed funds when the holding is performed in accordance with R.A. No. 12010 and applicable BSP rules and regulations.

The authority to hold funds is not unlimited. It must be connected to a disputed transaction and exercised under the procedures established by the BSP. A blanket or indefinite restriction unsupported by a transaction-specific basis may expose the institution to regulatory or consumer-protection concerns.

Coordinated Verification Across Banks and E-Wallets

Upon receiving a complaint, information from another institution, or a fraud-management-system alert, the institutions and account owners involved must initiate a coordinated verification process. This duty applies whether the disputed funds remain within the banking system or have already moved to another platform.

The process is intended to establish the movement of funds and determine whether the transaction was legitimate, unauthorized, induced by deception, connected with money muling, or related to another unlawful activity. Institutions should therefore preserve and compare the relevant transaction records, including:

  • The originating and beneficiary account details;
  • The date, time, amount, and reference number of each transfer;
  • The payment channel, device, or platform used;
  • The succeeding transfers or withdrawals involving the disputed funds; and
  • Account-owner and transaction-authentication information relevant to the inquiry.

BSP Circular No. 1215 requires industry procedures for tracing disputed transactions in real time or near real time. The system must be capable of generating and recording a visible disputed-transaction chain and of triggering alerts and temporary holding measures for the institutions involved.

The circular also requires institutions to establish a mechanism for settling disputes and determining liability for losses among participating BSP-supervised institutions. This means that banks and e-wallet providers should not treat the matter solely as a bilateral dispute with the complaining customer. They must also assess the conduct and compliance of the other institutions that handled the funds.

Information Sharing and Bank Secrecy

During the coordinated verification process, the provisions of R.A. No. 1405, as amended; R.A. No. 6426; R.A. No. 8367; and R.A. No. 10173 do not apply in the manner that would prevent the verification authorized by R.A. No. 12010.

This does not mean that institutions may disclose information without controls. BSP Circular No. 1215 requires information shared during the process to be handled securely, with access limited to authorized persons and authorized purposes. Institutions must preserve confidentiality, integrity, and security while permitting the information exchange necessary to trace the disputed funds.

The Supreme Court has also recognized the statutory basis for disclosing relevant financial-account information in cybercrime investigations. In Eastwest Rural Bank v. Philippine National Police Anti-Cybercrime Group, et al., G.R. No. 273720, 2025, the Court explained that the Cybercrime Prevention Act, the Data Privacy Act, and R.A. No. 12010 may permit disclosure of relevant account information when the statutory safeguards are observed.

The decision distinguished identifying information and transaction information from an unrestricted public disclosure of bank deposits. Institutions should disclose only information relevant to the authorized investigation and should document the legal basis, recipient, purpose, and scope of every disclosure.

Release of the Disputed Funds

Under BSP Circular No. 1215, the appropriate institution must release the disputed funds upon the lapse of the initial or extended holding period, or earlier upon confirmation that the transaction was legitimate, unless a recognized exception applies.

Release may be withheld when:

  • A court of competent jurisdiction has extended the holding period;
  • The beneficiary account owner has executed a written waiver of any claim over the funds; or
  • The information gathered reasonably indicates that the funds are derived from or related to money muling, unlawful activities, illegal sources, a social engineering scheme, or similar circumstances.

The end of the temporary holding period does not by itself determine civil, criminal, or regulatory liability. It determines whether the institution may continue holding the funds under the temporary-holding mechanism. Separate legal processes may still apply, including court proceedings, criminal investigation, restitution, or action under the Anti-Money Laundering Act.

Allocation of Responsibility Among Institutions

Shared accountability does not necessarily mean equal liability. The allocation of responsibility should consider the conduct and legal duties of each institution involved in the transaction chain.

Institutional conductPossible legal consequence
Failure to maintain adequate authentication, fraud monitoring, or account-verification controlsPossible restitution or liability under Section 6 of R.A. No. 12010
Failure to temporarily hold disputed funds when requiredPossible liability for loss or damage, including restitution of the disputed funds under Section 9 of R.A. No. 12010
Failure to report or coordinate after receiving a valid fraud alertPossible regulatory action and increased exposure in determining institutional responsibility
Unauthorized or excessive disclosure of customer informationPossible liability under applicable banking, privacy, consumer-protection, and other laws
Compliance with required controls and proceduresMay support the institution’s defense against liability, subject to BSP findings and the facts of the transaction

Section 9 of R.A. No. 12010 specifically addresses failure to temporarily hold disputed funds. An institution that fails to hold funds when required may be liable for the resulting loss or damage, including restitution to the account owner. The issue is therefore not only whether fraud occurred, but also whether the institution responded properly after receiving information that should have prompted action.

R.A. No. 11765 likewise requires financial service providers to account for the acts or omissions of their authorized representatives and certain accredited third-party service providers. Outsourcing payment processing, customer support, fraud monitoring, or other functions does not automatically eliminate the provider’s responsibilities to financial consumers.

Account Number Matching and Transaction Processing

For domestic account-to-account electronic payments under the National Retail Payment System, account-number matching may be sufficient to implement a transaction. The originating institution and receiving institution must inform customers that the account number may control the execution of the payment.

This rule does not prevent institutions from applying additional procedures required by anti-money laundering rules, R.A. No. 12010, or other applicable laws. It also does not eliminate the institution’s duties when a transaction becomes disputed or when the institution receives information indicating possible fraud.

Accordingly, an institution may rely on account-number matching for ordinary payment execution while still being required to investigate and respond to a later fraud complaint. The ordinary processing rule and the disputed-transaction rules serve different purposes.

Recommended Inter-Agency Compliance Procedure

Banks and e-wallet providers should maintain a written inter-institution procedure containing at least the following steps:

  1. Receive and classify the alert. Record whether the alert came from a customer complaint, another institution, a law-enforcement request, or the institution’s fraud management system.
  2. Identify the transaction chain. Trace the originating transfer, beneficiary account, subsequent transfers, withdrawals, conversions, and other movements connected with the disputed funds.
  3. Apply temporary holding measures. Hold the funds when the statutory and regulatory grounds exist, notify the BSP promptly, and record the date and time when the holding began.
  4. Exchange relevant information securely. Share the information needed for verification through approved channels and restrict access to authorized personnel.
  5. Obtain account-owner cooperation. Inform the affected account owners of their responsibilities, the applicable timelines, and the documents or explanations required for verification.
  6. Determine the outcome. Release the funds when legitimacy is confirmed or the holding period expires, unless a recognized exception applies. If loss occurred, assess the responsibility of each participating institution based on its controls and conduct.
  7. Preserve the records. Keep the alert, communications, transaction trail, authentication records, investigation results, and release or restitution decision for the period required by applicable rules.

Common Compliance Risks

Delayed coordination. Funds may be withdrawn or transferred quickly. An institution that waits for a formal court order before performing actions that the law and BSP rules require may increase the resulting loss.

Incomplete transaction tracing. Reviewing only the first transfer may conceal the movement of funds through several bank and e-wallet accounts. The investigation should reconstruct the entire available chain.

Overbroad information sharing. The statutory exception for coordinated verification does not authorize unrestricted disclosure. Institutions should apply necessity, proportionality, security, and purpose limitations.

Failure to distinguish authentication from authorization. A transaction may have passed an authentication step but still be disputed because the customer was deceived, induced through social engineering, or otherwise deprived of meaningful authorization.

Improper release of funds. Release decisions should be supported by the verification record and should account for court extensions, written waivers, and findings connecting the funds with unlawful activity or social engineering.

Illustrative Scenario

A customer’s bank account is compromised after the customer is deceived into revealing sensitive identifying information. The funds are transferred to an e-wallet and then divided among two other accounts.

The customer reports the transaction to the bank. The bank should assess whether the transaction is disputed, notify the relevant institutions, and initiate the coordinated verification process. The e-wallet providers should trace the incoming and outgoing transfers, temporarily hold funds still within their control when the requirements are met, and provide relevant information through secure channels.

If one institution failed to employ adequate controls, ignored a valid fraud alert, or failed to hold funds as required, that conduct may affect the allocation of restitution and other liability. The mere fact that an institution was part of the transaction chain does not, without more, establish equal responsibility for the entire loss.

Final Observations

Philippine law now treats disputed digital transfers as an inter-institutional problem. Banks and e-wallet providers must be prepared to identify transaction chains, temporarily hold suspicious funds for no more than 30 calendar days unless a court extends the period, coordinate verification, exchange relevant information securely, and document the basis for every decision.

Financial institutions should regularly test their fraud management systems, maintain direct escalation channels with other institutions, and adopt written procedures for holding, tracing, releasing, and allocating disputed funds. They should also train personnel to distinguish ordinary payment processing from the heightened duties that arise once a transaction is reasonably disputed.

For customers, prompt reporting remains important. A complaint should include the transaction date, amount, reference number, account or wallet details, communications with suspected fraudsters, and any supporting authentication or device information. Early and complete reporting increases the likelihood that funds can be identified and held before they leave the regulated financial system.

About Nicolas and De Vega Law Offices

 Nicolas and de Vega Law Offices is a full-service law firm in the Philippines.  You may visit us at the 16th Flr., Suite 1607 AIC Burgundy Empire Tower, ADB Ave., Ortigas Center, 1605 Pasig City, Metro Manila, Philippines.  You may also call us at +632 84706126, +632 84706130, +632 84016392 or e-mail us at [email protected]. Visit our website https://ndvlaw.com.

SEARCH