
General articles are free for 24 hours after publish.
BSP Plans Year-Long Pause on New Payment System Operators
The Bangko Sentral ng Pilipinas (BSP) plans to suspend the registration of new payment system operators for one year. This move aims to enhance the traceability of merchant payments, curb fraud, and strengthen the integrity of the financial system, particularly concerning QR code transactions.
The Bangko Sentral ng Pilipinas (BSP) is planning to temporarily halt the registration of new payment system operators for a period of one year. This strategic pause is intended to implement stricter safeguards aimed at enhancing the traceability of merchant payments and curbing fraudulent and illicit transactions within the financial system. According to a draft circular released by the central bank, the BSP will suspend the acceptance and processing of new applications from entities seeking to operate payment systems. These operators, known as OPS, are crucial for facilitating payment and fund transfer arrangements. The BSP has articulated that this suspension is necessary to conduct a thorough and holistic review of the existing OPS taxonomy and licensing framework, taking into account associated risk management protocols and regulatory considerations. While applications that have already been submitted prior to the commencement of the suspension will continue to undergo evaluation, no new applications will be approved or denied until the suspension period concludes. The proposed 12-month pause is set to take effect from the date the circular is officially enacted. During this period, any entity will be prohibited from initiating activities that mandate registration, unless explicitly authorized by the BSP under current regulations. The draft proposal also outlines the creation of a centralized database for all merchants that accept payments through Quick Response (QR) code systems. Furthermore, it introduces more stringent controls over payment arrangements that involve intermediaries between financial institutions and the sellers or merchants. A key requirement for BSP-supervised institutions (BSIs) will be to accurately identify the actual merchant who is the ultimate recipient of the payment proceeds. The BSP has emphasized that a BSI authorized for merchant acquisition must not process or continue to process a transaction if the merchant cannot be identified or if the transaction cannot be reconciled to the same merchant. Merchant acquisition involves accepting and processing payments on behalf of sellers and transferring the funds to them. The proposed framework generally mandates that this service should be rendered through a direct relationship between the authorized institution and the merchant. Certain categories of businesses are slated to be accepted only through direct arrangements and will be subjected to more extensive background checks, closer monitoring, and transaction and settlement limits that are proportionate to their inherent risks. These specific business types include casinos and other gambling operators, gaming-related providers that directly handle player funds or gaming proceeds, lawful adult-oriented businesses, regulated virtual asset service providers, and money service businesses such as remittance companies and money changers. Institutions will be explicitly prohibited from maintaining merchant relationships that involve illegal activities or regulated businesses operating without the requisite authorization. For other categories of merchants, payment arrangements involving intermediaries may still be permissible, provided that the institutions involved can adequately identify all parties, trace the flow of funds, and exercise effective oversight. The proposal stipulates that payments intended for multiple merchants, even if processed through a shared account, platform, or QR-enabled channel, must ensure that each individual transaction can be distinctly linked to a unique merchant identifier and can be separately monitored, investigated, and reconciled. In instances where merchant information is missing, inaccurate, or inaccessible, institutions will be required to reject or suspend the affected transaction or merchant. Exceptions may apply for temporary technical issues that are covered by documented safeguards approved within their incident management framework. Intermediaries will also be barred from delegating or subcontracting merchant acquisition responsibilities to any other party, including the addition of further intermediary tiers. Ancillary support services may still be outsourced in compliance with applicable BSP rules. High-risk layered arrangements will necessitate approval from the institution’s board or an equivalent governing body, along with management or compliance reviews conducted at least quarterly and independent assurance assessments performed at least annually. In a separate but related initiative, the proposed National QR Code Merchant Database aims to consolidate comprehensive information on businesses that accept payments utilizing the national QR code standard. The database's records will encompass merchant identities, business registration and licensing details, payment providers, settlement accounts, ownership information, and risk classifications. It will also indicate the operational status of a merchant, such as active, restricted, suspended, or terminated. Any changes in a merchant’s status will be promptly communicated to other payment service providers that maintain relationships with the same business. This notification is intended to prompt their own reviews and the implementation of appropriate safeguards. An interim secure merchant information repository is required to be established within 90 calendar days of the circular's effectivity. The full database is expected to be operational within 12 months, with all active merchant records successfully migrated and validated within 15 months. The draft circular also mandates that material fraud or scam incidents, breaches of sanctions, cybersecurity or data access breaches, instances of unlicensed activity, and illegal merchant activities must be reported to the BSP within 24 hours of their detection. A complete incident report is due within five business days. If a thorough investigation cannot be reasonably concluded within this timeframe, an interim report will be required, with the full report to be submitted within a period approved by the relevant supervising department. These reporting obligations are distinct from the requirements to report suspicious transactions under the applicable Anti-Money Laundering Council (AMLC) rules. For existing payment arrangements that involve multiple layers, institutions will be granted a period of six months from the circular's effectivity to conduct a review of their merchant relationships. Following this review, they will have an additional six months to address any identified deficiencies. Merchant relationships that remain noncompliant after this 12-month period will be subject to enforcement actions by the BSP. Information source: Philstar Business
Original source
Philstar Business