Insights / Blog / Regulatory Thought Leadership
Regulatory Thought Leadership

The Philippines Has Cleared 18 of the FATF's Action Items. Five of Them Depend on What Your Institution Does Every Day.

The grey-list exit was a state-level achievement. The next mutual evaluation, in 2027, is decided by what individual institutions can actually show.

The Philippines Has Cleared 18 of the FATF's Action Items. Five of Them Depend on What Your Institution Does Every Day.

The Philippines was taken off the Financial Action Task Force’s grey list on 21 February 2025, having fulfilled all 18 action points agreed when it was placed on the list in June 2021. Those action points were directed at the state, namely the AMLC, the SEC, law enforcement agencies, and prosecutors, not directly at individual financial institutions. Several of them, though, could only be met through the actual activities of covered institutions at the operational level: a regulator cannot show it is carrying out risk-based supervision unless institutions keep supervisable programmes in place, and cannot demonstrate greater use of financial intelligence unless institutions file reports that are actually usable.

The next mutual evaluation is due in 2027. The difference that will matter between now and then is between institutions that cleared the exit on the basis of documentation, and institutions where the necessary capabilities are actually running day to day.

A note on terminology for readers outside the Philippines: the local term for a Suspicious Activity Report (SAR) is the Suspicious Transaction Report (STR), and the filing procedures differ. STRs must be filed by the next working day after suspicion has been finally determined; Covered Transaction Reports (CTRs), relating to cash transactions of ₱500,000 or more, must be filed within five working days. Documentation prepared for US institutions often confuses these timeframes.

The grey-list exit is, broadly and accurately, regarded as a national achievement. It was the result of coordinated work by AMLC, the BSP, the SEC, law enforcement, and prosecutors, and the economic benefits, reduced friction in correspondent banking relationships, smoother remittance flows, improved investor perception, are genuine.

It also carries a particular risk of being misread. Because the action plan was directed at the government, an organisation might assume the work happened elsewhere and that it only received the results. That interpretation holds until the next mutual evaluation, when the question changes from “has the state fulfilled its commitments” to “is the regime actually effective in practice,” with effectiveness largely determined by what individual institutions can show.

Five of the 18 action items have direct operational dependencies on the institutions in question, and it’s with respect to these that the gap between a compliant document and a working process becomes visible.

What was actually on the list

On 25 June 2021, the Philippines was placed on the FATF grey list over deficiencies in supervision of high-risk sectors, delays in enforcement, and weaknesses in beneficial-ownership identification. The agreed action plan had 18 items.

FATF’s October 2024 plenary judged the plan substantially completed. FATF President Elisa de Anda Madrazo made the finding public, the Asia/Pacific Joint Group carried out an on-site verification visit in January 2025, and the country was removed from the list at FATF’s plenary session in Paris on 21 February 2025.

The action points, as stated in FATF’s own evaluations and reported by the AMLC, included: showing risk-based supervision over Designated Non-Financial Businesses and Professions; showing that supervisors use AML/CFT controls to reduce risks linked to casino junkets; implementing new registration requirements for Money or Value Transfer Services and sanctioning unregistered operators; improving law enforcement’s access to accurate, up-to-date beneficial ownership information; demonstrating increased use of financial intelligence and more money laundering investigations and prosecutions in line with risk; demonstrating an increase in terrorist financing cases identified, investigated, and prosecuted; implementing measures for the non-profit sector; and enhancing the effectiveness of targeted financial sanctions. Most of these are state functions, a bank won’t prosecute anyone, but proving several of them requires input from institutions, and that dependence is worth examining.

The five with operational dependencies

First: practical financial intelligence. Increasing the use of financial intelligence and money laundering investigations in line with risk depends on the quality of documents institutions submit. A regulator can’t build an investigation on a report that identifies no suspect, gives a reason for suspicion inconsistent with its own account, or is too vague to act on. The extent to which authorities can show effective use of financial intelligence is capped by the quality of the reports they receive.

Second: the accuracy of beneficial ownership. The commitment to accurate, up-to-date beneficial ownership information applies to both institutions and registries. When an institution’s CDD file records the name of whoever signed the account-opening form rather than the person who actually controls the entity, the beneficial ownership data is correct in name only. Having signing authority isn’t the same as having control, and the discrepancy only surfaces when someone checks for it.

Third: supervisable programmes. Demonstrating risk-based supervision requires something that is actually supervisable, a written, current risk assessment, controls aligned with that assessment, and proof the two are linked. Even if the written programme or the actual practice looks fine in isolation, a divergence between the two means supervision isn’t succeeding.

Fourth: detecting terrorist financing, as distinct from money laundering. Increasing identification, investigation, and prosecution of terrorist financing cases depends on institutions surfacing them in the first place. Terrorist financing patterns differ structurally from money laundering: amounts are usually small, sources are generally legitimate, and the transaction sequence bears little resemblance to layering. Detection methods tuned only to money laundering typologies systematically under-refer terrorist financing.

Fifth: timely filing holds even at high volume. The STR clock starts running the moment suspicion is determined, not on the transaction date or the alert date, and it runs on the next working day regardless of volume. An institution can meet that deadline reliably at low volume using manual methods and still miss it as volume rises, unless timeliness is tracked submission by submission in a format an examiner can review directly.

Why this reads differently before 2027

The Philippines’ next mutual evaluation, in 2027, will use FATF’s current assessment methodology, which weighs demonstrated effectiveness rather than technical compliance alone. That distinction is the key issue.

Technical compliance asks whether a country has the necessary laws, regulations, and institutional structure in place. Effectiveness asks whether the system produces real-world results: whether suspicious activity is actually detected, whether available financial intelligence can actually be used, whether supervision actually changes institutional behaviour. A jurisdiction can score well on the first and still fall short on the second, and recent regional assessments have shown that even jurisdictions strong in some respects still fall short in certain effectiveness areas.

For a single institution, the right question isn’t whether its programme met requirements at some point in time, it’s whether the programme produces evidence of being effective: reports that assist investigations, beneficial ownership information that reflects real control, filing timeliness that holds under volume, and a decision trail an examiner can follow.

Closing the gap

Each of the five dependencies above maps to whether an institution has something actually running. Fyscal Arcx’s Regulatory Reporting module fills in STR and CTR forms directly from case data, with separate countdowns for the next-working-day STR window and the five-working-day CTR window, covering both the usability requirement (a filing built on a complete case record) and the timeliness requirement (a tracked deadline rather than a remembered one). Case Management keeps a continuous, accumulating record with references between entities, making beneficial ownership and control visible across linked parties and generating the decision trail that makes a programme supervisable. Transaction Monitoring includes rule types and typology templates aggregated across multiple accounts and time windows, needed to detect TF patterns that don’t resemble ML layering and to catch structuring a single-transaction threshold check would miss. And Name Screening returns explainable, per-field results against sanctions, PEP, and adverse media data, with continuous rescreening as new entries are added, turning a screening decision into evidence rather than an assertion.

See how Fyscal Arcx turns AML compliance from documentation into demonstrable operations.
Book a demo

Frequently asked questions

On 21 February 2025, after clearing all 18 action items agreed when it was listed on 25 June 2021. FATF’s October 2024 plenary found the plan substantially completed, followed by a final on-site visit in January 2025.
A Suspicious Activity Report (SAR) is the term used in the United States and several other jurisdictions. The Philippine equivalent is the Suspicious Transaction Report (STR), which must be filed by the next working day after suspicion is determined with finality.
Under AMLA, a transaction is suspicious regardless of amount if there is no legal or economic justification, the client is not properly identified, the amount is not commensurate with the client’s capacity, it appears structured to avoid reporting thresholds, it deviates from the client’s profile, or it relates to unlawful activity.
Not directly. The action plan was addressed to the Philippine government. However, several items could only be satisfied through institutional inputs, such as the quality of financial intelligence filed and the accuracy of beneficial ownership information collected.
The next mutual evaluation is scheduled for 2027 and will assess demonstrated effectiveness rather than technical compliance alone.
Stay in the loop

Insights on modern finance, monthly.

No noise — just the engineering and strategy behind banking that scales.

Keep reading

Related articles