13.4 Compliance Framework and Money Laundering Prevention Program (MLPP)
Key Takeaways
SEC-supervised covered persons, such as broker-dealers, investment houses, and investment companies, must adopt a board-approved Money Laundering and Terrorist Financing Prevention Program (MTPP).
The Board of Directors bears ultimate responsibility for AML/CFT compliance, including MTPP approval, adequate resourcing, and oversight of audit and examination findings.
The AML Compliance Officer must be a senior officer with independence from revenue-generating business units and direct access to the Board of Directors.
Independent, risk-based testing of the MTPP must be performed separately from the AMLCO and the activities reviewed, with findings reported to the board or a board committee.
Under SEC MC No. 29, Series of 2020, applicants file a sworn certification instead of the MTPP and submit the MTPP to AMLD-EIPD within 10 days of licensing.
13.4 Compliance Framework and Money Laundering Prevention Program (MLPP)
In the Philippine capital markets, regulatory compliance is not merely an advisory function; it is an affirmative institutional obligation. The Securities and Exchange Commission (SEC), in coordination with the Anti-Money Laundering Council (AMLC), enforces comprehensive institutional governance rules across all capital market intermediaries. Under SEC Memorandum Circular No. 16, Series of 2018, as amended (the SEC AML/CFT Guidelines), and SEC Memorandum Circular No. 29, Series of 2020 on MTPP submission and monitoring and the 2018 Implementing Rules and Regulations (IRR) of the AMLA, covered institutions must establish a sound and dynamic internal defense system against financial crime.
Scope of Covered Persons Under SEC Supervision
Under Section 3(a)(3) of AMLA, as amended, and the SEC AML/CFT Guidelines, Covered Persons under SEC supervision include:
- Securities dealers, brokers, and salesmen, including trading participants of the PSE.
- Investment houses and other persons managing securities or rendering services as investment agent, advisor, or consultant, such as fund managers and investment company advisers.
- Mutual funds, closed-end investment companies, common trust funds, and similar persons.
- Other SEC-supervised entities administering or dealing in currency, commodities or financial derivatives based on them, valuable objects, cash substitutes, and similar monetary instruments or property.
- Financing and lending companies once paid-up capital reaches ₱10 million or foreign equity exceeds 40%; they remain covered even if capital or foreign equity later falls below the threshold, unless the SEC declares otherwise (SEC MC No. 29, Series of 2020, Section 5).
The Money Laundering and Terrorist Financing Prevention Program (MTPP / MLPP)
Every SEC-covered institution is legally mandated to formulate, adopt, and operationalize a comprehensive, written compliance manual known as the Money Laundering and Terrorist Financing Prevention Program (MTPP), traditionally referred to as the Money Laundering Prevention Program (MLPP).
┌─────────────────────────────────────────────────────────────────────────────┐
│ CORE COMPONENTS OF AN MTPP / MLPP │
└─────────────────────────────────────────────────────────────────────────────┘
1. Governance & Oversight 2. Risk-Based CDD & KYC
• Board approval & ownership • Customer Due Diligence tiers
• Independent AMLCO role • Beneficial ownership verification
• Adequate compliance resources • PEP screening & enhanced diligence
3. Monitoring & Reporting 4. Internal Controls & Audit
• Automated rule-based alerts • Risk-based independent testing
• Electronic CTR/STR filings • Findings to board or committee
• Five-year record retention • Role-based staff training
Mandatory Minimum Contents of the MTPP
Under the SEC AML/CFT Guidelines and MTPP submission rules, an institutional MTPP must be customized to the firm's specific risk profile, customer base, product offerings, and delivery channels. It must contain:
- Detailed Customer Due Diligence (CDD) / Know-Your-Customer (KYC) Guidelines: Clear procedures for verifying natural persons, corporate entities, trusts, and identifying the natural persons who ultimately own or control the customer (beneficial owners).
- Risk Assessment Framework: Institutional Enterprise-Wide Risk Assessment (EWRA) methodologies classifying clients into low, normal, and high-risk tiers (e.g., Politically Exposed Persons or PEPs).
- Screening and Onboarding Controls: Screening against UN Security Council sanctions lists, domestic AMLC freeze lists, and targeted financial sanctions databases.
- Transaction Monitoring and Alert Handling: Clear thresholds and behavioral triggers for detecting suspicious trading (such as wash sales, unusual volume spikes, or rapid redemptions).
- Reporting Mechanisms: Protocols ensuring that Covered Transaction Reports (CTRs) are filed within five (5) working days, and Suspicious Transaction Reports (STRs) are filed within the prescribed regulatory window.
- Record Retention Rules: Policies guaranteeing that all KYC files, account records, and trading data are preserved for at least five (5) years from the transaction date or account closure.
Mandatory Board Approval and Biennial Updating
- Formal Board Approval: The MTPP must be formally approved by the Board of Directors (or highest governing body in non-corporate entities) and documented in the official corporate minutes.
- Periodic Updating: The MTPP is not a static document. It must be reviewed and updated at least once every two (2) years, or sooner whenever there are material changes in AML/CFT legislation, SEC rules, or emerging institutional risk typologies.
Board of Directors and Senior Management Governance
A central tenet of the SEC AML/CFT governance regime is that compliance begins at the highest corporate echelon.
Ultimate Responsibility of the Board of Directors
Under Philippine law, the Board of Directors bears ultimate responsibility for the firm's AML compliance. The Board cannot contract away or delegate this legal accountability. Specific board duties include:
- Setting an uncompromising "Tone at the Top" that prioritizes ethical conduct and legal compliance over commercial trading revenues.
- Ensuring the MTPP is fully implemented, resourced, and enforced throughout all branches and divisions.
- Allocating sufficient financial, technological, and human capital to the compliance department.
- Periodically reviewing AML management information reports, audit findings, and regulatory examination results.
Role of Senior Management
Senior Management is tasked with the operational execution of board policies:
- Overseeing the day-to-day administration of the MTPP across front-office, operations, and IT units.
- Ensuring that high-risk client relationships (such as foreign PEPs or high-net-worth accounts from higher-risk jurisdictions) receive prior written approval from senior management before onboarding.
- Establishing escalation protocols for handling compliance breaches and transaction alerts.
The Anti-Money Laundering Compliance Officer (AMLCO)
Every covered institution must formally appoint a designated Anti-Money Laundering Compliance Officer (AMLCO). Smaller broker-dealers often combine the AML role with the general compliance function, while larger institutions may keep a dedicated AML officer; either way, the designated officer needs the authority and independence described below.
┌─────────────────────────────────────────────────────────────────────────────┐
│ THE STATUTORY ROLE OF THE AMLCO │
└─────────────────────────────────────────────────────────────────────────────┘
DIRECT ACCESS LINE ORGANIZATIONAL INDEPENDENCE
┌────────────────────────┐ ┌────────────────────────┐
│ Board of Directors │ │ Complete separation │
│ & Audit Committee │ │ from revenue units │
└───────────▲────────────┘ └───────────▲────────────┘
│ │
└────────────────────┬────────────────────┘
│
┌──────────────┴──────────────┐
│ AML Compliance Officer │
│ (AMLCO) │
└──────────────┬──────────────┘
│
┌───────────────────────┼───────────────────────┐
▼ ▼ ▼
MTPP Implementation Transaction Surveillance AMLC / SEC Liaison
& EWRA Risk Assessment & Timely CTR / STR Filings & Examination Support
Key Qualifications and Governance Safeguards
- Senior Management Stature: The AMLCO must be a senior officer possessing sufficient authority, seniority, and standing within the corporate hierarchy to challenge business decisions and enforce compliance.
- Direct Reporting Lines: The AMLCO must have direct, unrestricted access to the Board of Directors and the Board Audit/Risk Committee, bypassing intermediate commercial managers.
- Freedom from Conflicts of Interest: To preserve objectivity, the AMLCO should not hold trading, sales, or other revenue-generating positions whose activities the AMLCO must monitor. Combining those roles undermines the independence the AML/CFT framework requires.
- Core Functions:
- Monitoring day-to-day compliance with the MTPP, AMLA, and SEC circulars.
- Overseeing transaction surveillance systems and ensuring the confidentiality and timeliness of CTR and STR transmissions to the AMLC.
- Serving as the institutional liaison officer with the AMLC and the SEC during compliance audits and regulatory inspections.
- Coordinating enterprise-wide money laundering risk assessments.
Independent Internal Audit Oversight
Independent testing is the third-line check on whether the MTPP works in practice. The audit or review function must be independent of the AMLCO and the activities being tested. Its program should be risk-based and sufficiently frequent to assess the institution's exposure, material changes, prior findings, and control performance.
Testing should cover governance and board oversight, customer identification and beneficial ownership, risk rating and enhanced due diligence, transaction-monitoring alerts, CTR and STR filing controls, sanctions and targeted-financial-sanctions screening, record retention, training, and remediation of earlier findings. Results and unresolved deficiencies should be reported to the board or the appropriate board committee and tracked to closure.
The governing point is independence and effective periodic testing, not a fabricated universal calendar frequency. The AMLCO administers and monitors the program but must not give independent assurance over the AMLCO's own work.
Mandatory Employee Training Programs
Covered persons must provide effective, role-appropriate AML/CFT training to responsible directors, officers, and personnel. New personnel need instruction before they perform relevant duties, and continuing training should reflect job exposure, regulatory change, emerging typologies, terrorism and proliferation-financing risks, sanctions obligations, red flags, reporting, and the tipping-off prohibition. The institution documents participation and assesses whether personnel can apply the controls in practice.
Governance Roles Comparison Matrix
| Governance Organ | Primary AML Role | Key Responsibilities | Reporting Line |
|---|---|---|---|
| Board of Directors | Ultimate Oversight | Approves MTPP; allocates budget; sets Tone at the Top | Shareholders / Regulators |
| Senior Management | Operational Execution | Approves high-risk clients; implements board policies | Board of Directors |
| AMLCO | Compliance Oversight | Daily MTPP administration; surveillance; files CTR/STR | Direct to Board / Audit Comm. |
| Internal Audit | Independent Assurance | Risk-based periodic testing of governance, controls, files, reporting, and remediation | Directly to Board / appropriate Board Committee |
| All Staff | First-Line Execution | Onboarding KYC; identifying red flags; no tipping off | Department Heads / AMLCO |
Practical Exam Traps and Regulatory Pitfalls
- Trap 1: Who Bears Ultimate Legal Responsibility. Exam questions frequently ask whether the AMLCO, the external auditor, or the Board bears ultimate legal responsibility for AML compliance. The Board of Directors bears ultimate legal responsibility. The AMLCO executes the program, but the Board is accountable.
- Trap 2: AMLCO Concurrently Running Trading Operations. Look out for scenarios where a small brokerage assigns the AMLCO to also handle proprietary trading or sales to cut overhead. This is a serious independence failure: the AMLCO must be independent of the commercial business lines it monitors.
- Trap 3: Audit Independence. The AMLCO monitors the program but cannot provide independent assurance over the AMLCO’s own work. Independent, risk-based testing must reach the board or the appropriate board committee.
- Trap 4: MTPP Review Cycle. Memorize the updating threshold: the MTPP must be formally updated at least once every two (2) years (biennially), not every three or five years.
- Trap 5: Training Is Role-Specific. Training must reach responsible directors, officers, and personnel and should reflect each role’s exposure; a generic attendance sheet is not evidence that staff can identify and escalate red flags.
Application-stage sworn certification (SEC MC No. 29, Series of 2020)
SEC Memorandum Circular No. 29, Series of 2020 changed the application-stage filing method, not the obligation to maintain a working program. An applicant for registration or a secondary license no longer attaches the MTPP. Instead, it submits a Sworn Certification, signed by its Compliance Officer, Corporate Secretary, or Resident Agent, that the MTPP has been prepared, noted, and approved by its Board of Directors (or by the country, regional, or area head for a local branch of a foreign covered person). A copy must be stamped received by the Anti-Money Laundering Division of the Enforcement and Investor Protection Department (AMLD-EIPD) before the application is accepted. The certification includes an undertaking to submit hard and soft copies of the MTPP to AMLD-EIPD within ten (10) days from receipt of the Certificate of Registration or secondary license. Therefore, “certification instead of attachment” must never be mistaken for “no MTPP required.”
Under the SEC AML/CFT Guidelines and MTPP rules, which governing body bears ultimate legal responsibility for the adoption, implementation, and oversight of a covered institution's Money Laundering and Terrorist Financing Prevention Program (MTPP/MLPP)?
The Head of Brokerage Operations and Settlement.
The external independent financial statement auditor.
The Board of Directors of the covered institution.
The Securities and Exchange Commission's Enforcement and Investor Protection Department.
Which operational condition is mandatory regarding the appointment and role of an Anti-Money Laundering Compliance Officer (AMLCO) in a registered broker-dealer firm?
The AMLCO must concurrently serve as the Chief Financial Officer or Head of Proprietary Trading to ensure cost efficiency.
The AMLCO must be a senior officer with sufficient independence, direct access to the Board of Directors, and freedom from operational or commercial conflicts of interest.
The AMLCO may only report to the corporate sales manager and cannot communicate with regulatory agencies without marketing approval.
The AMLCO must be an external practicing attorney who works strictly on a part-time retainer basis.
Which standard best describes independent testing of a securities broker-dealer’s MTPP under the SEC AML/CFT framework?
Testing is optional unless a customer has already been convicted of money laundering.
The AMLCO should independently audit the AMLCO’s own work without reporting findings to the board.
The marketing department should review the program only when client complaints increase.
A function independent of the AMLCO and the activities reviewed should perform risk-based periodic testing and report material findings and remediation to the board or appropriate board committee.
Sections you finish are checked off in the contents.