16.2 Record Retention, Suspicious Transactions, and Continuing Education
Key Takeaways
- AMLA and BSP fiduciary/trust expectations as taught on the UCP require minimum retention of KYC and transaction records for at least five (5) years.
- Suspicious Transaction Reports (STRs) are driven by red-flag indicators and can be required regardless of amount—even below the PHP 500,000 covered threshold.
- Covered-transaction reports and STRs answer different questions: threshold vs suspicion; both may apply to the same activity.
- Maintaining Certified UITF Sales Person / CUSP-related status requires continuing education; TOAP materials commonly frame an annual minimum on the order of about six CE units.
- Incomplete records, ignored suspicion, or lapsed CE each threaten regulatory fitness—process and maintenance are part of professional ethics, not afterthoughts.
From onboarding controls to institutional memory
Section 16.1 taught KYC, the PHP 500,000 covered-transaction idea, and structuring. Controls fail if the bank cannot later prove what it knew and did. AMLA and BSP fiduciary rules as taught for the UCP therefore emphasize record retention, suspicious transaction handling, and—looking past the exam—continuing education so certified marketers stay current.
Think of three time horizons:
| Horizon | Duty |
|---|---|
| Day 0 | Identify, verify, assess, decide admit/escalate |
| Day 0–n | Monitor, report covered/suspicious activity, keep files complete |
| Year after year | Retain records ≥5 years; complete CE; refresh competence |
Record retention: minimum five years
The number to memorize
For UCP purposes, retain KYC and transaction records for a minimum of five (5) years under AMLA and BSP fiduciary / trust recordkeeping expectations as presented in program teaching.
What “records” typically include in a trust/UITF setting (conceptual list):
- Customer identification and verification documents
- Beneficial ownership information and corporate packs
- Account opening / participation agreements and related forms
- CSA, RDS, and other disclosure acknowledgments where held in the client file
- Transaction tickets: subscriptions, redemptions, switches, and supporting payment references
- Correspondence and internal notes material to AML or fiduciary decisions
- Reports and escalation files related to covered or suspicious activity (per bank policy)
Why five years matters
| Reason | Explanation |
|---|---|
| Investigation trail | AMLC, BSP, or internal audit may reconstruct events years later |
| Staff turnover | The original RM may have left; the file must speak |
| Client disputes | Suitability and disclosure debates need documentary proof |
| Exam logic | “Keep forever” and “keep 1 year only” are common wrong options |
Practical conduct rules for marketers
- Never discard client identity packs early “to free drawer space.”
- Never alter historical forms after the fact to fix an audit finding without authorized amendment procedures.
- Complete contemporaneous notes when escalating AML concerns—memory is not a record.
- Follow bank electronic archive rules; retention is a system duty, but your incomplete uploads become institutional gaps.
Retention starts from the required reference point under policy (often end of relationship / last transaction / creation date depending on record type—exam items usually test the five-year minimum duration, not obscure indexing mechanics). If an option says “retain only until the next CSA update in three years,” that is too short relative to the five-year AML/fiduciary teaching floor.
Suspicious transactions: indicators, not amounts
Definition for exam use
A suspicious transaction is one where, based on circumstances and red-flag indicators, there is reasonable ground to suspect that the funds relate to unlawful activity, money laundering, terrorist financing, or that the transaction is structured or otherwise designed to evade controls—regardless of the amount.
That last phrase is the discriminator:
| Report type | Primary trigger |
|---|---|
| Covered transaction | Meets threshold (PHP 500,000 single banking day as commonly taught) |
| Suspicious transaction (STR) | Meets suspicion indicators—any amount |
A PHP 80,000 subscription can be suspicious. A PHP 2,000,000 payroll-funded investment can be covered yet not suspicious if fully explained. A PHP 520,000 cash deal with fake IDs can be both covered-threshold relevant and suspicious.
Indicator library (UITF-flavored)
Suspicious indicators often tested or implied:
- Client is secretive, aggressive, or threatening when asked basic KYC questions
- Inconsistent stories about source of funds across visits
- Use of aliases, borrowed IDs, or reluctance to appear in person without reason
- Structuring patterns near PHP 500,000
- Third-party payments with no legitimate relationship explanation
- Activity incompatible with known occupation, age, or stated purpose
- Rapid in-and-out (subscribe then redeem quickly) without investment rationale
- Attempts to involve staff in concealment (“huwag mong isulat,” “//report later”)
- Negative news / adverse media or internal watchlist hits (handled via bank AML process)
What marketing personnel actually do
You typically do not personally file an STR with AMLC as a lone actor. You:
- Recognize the indicator
- Do not tip off the client in a way that compromises the investigation (“tipping off” is a serious concern in AML culture)
- Escalate immediately to the bank’s AML compliance officer / unit with facts
- Preserve records and follow instructions on whether to proceed, freeze, exit, or continue under enhanced monitoring
- Avoid destroying evidence or coaching the client on how to “clean” the story
Tip-off caution (exam-aware)
Telling a client “we are filing a suspicious report on you, so withdraw everything tonight” can undermine controls. Professional response: remain factual, continue required process, and let AML specialists manage client communication strategy. You may still refuse incomplete KYC or decline a transaction under policy without delivering a running commentary on internal reporting.
Worked STR scenarios
Scenario 1 — small amount, strong suspicion
A walk-in with no stable address tries three times to open a UITF using different spellings of a name and pays PHP 95,000 in cash from a plastic bag, refusing to state employment.
STR thinking: Yes—indicators present regardless of amount below PHP 500,000. Escalate; do not open on incomplete identity.
Scenario 2 — large amount, clean story
A long-time client sells a documented real property, provides notarized deed and bank credit of sale proceeds, and invests PHP 3,000,000 in a bond UITF consistent with CSA.
Thinking: Large activity may engage covered/large-transaction processes; suspicion is not automatic if CDD is strong. Still follow bank large-ticket and source-of-funds procedures.
Scenario 3 — both tracks
PHP 500,000 same-day cash from a client who asks how to avoid “AML headaches” and offers a “tip” to the RM.
Thinking: Threshold and suspicion (structuring intent / bribery attempt). Escalate on both tracks; do not process as a normal sale.
Covered vs suspicious: decision table
| Situation | Covered lens | Suspicious lens |
|---|---|---|
| PHP 500,000+ single banking day, clean KYC | Likely covered | Not automatic STR |
| PHP 120,000 with fake ID attempt | Below covered threshold alone | Suspicious |
| Three × PHP 490,000 to avoid reporting | Substance may still be threshold-relevant | Suspicious structuring |
| PHP 10,000 monthly auto-invest, documented salary | Usually neither drama | Ordinary |
Continuing education: keeping CUSP / certified status
Passing the UCP Qualifying Exam is a knowledge gate, not a lifetime waiver. TOAP and participating institutions expect certified UITF marketing personnel to complete continuing education (CE) to maintain Certified UITF Sales Person / CUSP-related status.
The CE figure taught for this guide
Program and industry materials commonly present an annual CE requirement on the order of about six (6) units to maintain certified status. Frame it on the exam as:
Continuing education is required to maintain certification / CUSP status, with about six CE units per year as the standard TOAP-referenced benchmark in training materials—confirm the current year’s exact unit count, accredited courses, and deadlines with your bank’s trust training or compliance desk.
Why CE exists:
| Theme | Examples |
|---|---|
| Regulatory refresh | Circular updates, disclosure template changes |
| Product literacy | New fund classes, fee or feature changes |
| Conduct & AML | Misselling cases, KYC/STR refreshers, conflict scenarios |
| Market competence | Rates, risk, and investor-communication updates |
CE failures are professional failures
If CE lapses, the institution may remove you from the authorized sellers list even though you once scored 90% on the written exam. From an ethics angle, continuing to solicit UITFs while knowingly outside authorized status is a conduct problem, not a paperwork trifle.
Link CE to Section 1.2’s certification path and to Section 15.2’s professional standards: integrity includes staying currently qualified.
Putting records, STR, and CE on one timeline
Open relationship → complete KYC/CDD + suitability/disclosures
↓
Monitor activity → covered reports when threshold met; STR path when indicators appear
↓
Retain KYC & transaction records ≥ 5 years
↓
Each year → complete required CE (~6 units commonly referenced) to keep certified status
↓
Escalate early; never structure, tip off, or discard files to “help” a client
Exam traps for this section
- STR only when amount ≥ PHP 500,000 — false; suspicion is amount-independent.
- Covered report automatically means the client is guilty — false; covered is threshold process.
- Retention of 1–3 years is enough because CSA renews every 3 years — false vs 5-year minimum teaching.
- Marketers should always tell clients an STR was filed — tipping-off risk; follow AML unit guidance.
- CE is optional once you pass UCP — false; CE maintains certified/CUSP status.
- Six CE units is a guess with no program basis — treat ~6 units as the commonly taught annual benchmark while confirming current TOAP/bank schedules.
Closing memory set
- Records: KYC + transactions ≥ 5 years.
- STR: indicators regardless of amount; escalate, don’t tip off.
- Covered ≠ suspicious (threshold vs suspicion); both can apply.
- CE: required to maintain certification; ~6 units/year commonly referenced.
- Process + memory + maintenance = professional AML and CUSP fitness.
What is the minimum record-retention period for KYC and transaction records commonly taught under AMLA and BSP fiduciary rules for the UCP?
When must suspicious transaction concerns be raised relative to the PHP 500,000 covered threshold?
Which statement best describes continuing education for certified UITF marketing personnel / CUSP-related status?
A client attempts a PHP 75,000 UITF subscription with contradictory source-of-funds stories and refuses standard identification. What is the most appropriate personnel response?