logo

How AI-era risks test the limits of bank-level controls in the Philippines

Add The Asian Banker on Google
Discover more trusted banking and financial services insights by adding The Asian Banker as a preferred source on Google.
How AI-era risks test the limits of bank-level controls in the Philippines
  • 160

As Philippine banks expand artificial intelligence (AI) in fraud detection and daily operations, banking and cybersecurity leaders at TAB Finance Philippines mapped a widening set of risks that extend beyond individual institutions, requiring stronger coordination across the financial ecosystem.

Philippine banks are extending AI deeper into fraud detection just as fraud itself becomes a problem no single bank can solve alone. AI, real-time payments and increasingly sophisticated scams are compressing the time banks have to respond, while identity, devices, telecommunications, transaction histories and account relationships have fused into one ecosystem, where a weakness in any part creates risk everywhere else.

The response spans three levels: banks are strengthening authentication, behavioural monitoring and AI governance; industry participants are calling for greater fraud-intelligence sharing; and regulators and government are developing frameworks for cybersecurity and AI use.

Fraud evolves faster than defences

Marlon P. Sorongon, chief information security officer (CISO) at Maybank Philippines, said the bank combines authentication and authorisation with behavioural analysis and geolocation checks to assess whether activity is consistent with a customer's expected pattern. An unusual change in location, device activity or transaction value triggers additional validation, including direct contact with the customer. Fraud controls need to evolve alongside new threats. He said, as banks introduce new technologies, they also need to assess the loopholes and weaknesses those technologies create.

The nature of the threat has changed as much as its scale. "Fraudulent transactions have changed significantly. Fifteen years ago, threat actors were interrupting or shutting down systems as a major threat. Today, criminals do not need firearms to steal money from a bank," he said.

Jonah Dunca, CISO and deputy data privacy officer at PETNET, said the company conducts customer due diligence and enhanced due diligence for higher-risk situations, using AI to identify patterns and behavioural changes that can flag a transaction for review. He added that fraud prevention requires investment not only in technology and cybersecurity but also in people, training and awareness.

Angel Redoble, chairman and founding president of the Philippine Institute of Cyber Security Professionals, said threat actors monitor improvements made by banks, wallets and other digital platforms, learn how those systems work and adapt their methods accordingly, a cycle in which static defences fall behind quickly. "Threat actors do not take holidays," he said. "Defenders may want work-life balance, but criminals continue operating."

A related but distinct authentication gap sits inside banks themselves. Bangko Sentral ng Pilipinas (BSP), in Memorandum M-2026-034 dated 6 July 2026, recommends that supervised institutions discontinue SMS- and password-based authentication for administrative and privileged access and replace them with hardware-based multi-factor authentication. The measure is intended to mitigate AI-driven social engineering against staff and internal systems rather than customer logins.

Identity fraud crosses institutional boundaries

Individual bank controls cannot address fraud involving identities, devices or accounts that span multiple institutions. Sorongon said cross-sector fraud requires organisations to work together. "Cross-sector fraud and fraudsters need to be addressed by organisations across sectors and ultimately, globally," he said.

Redoble said conventional know-your-customer checks, a passport, a driving licence, a video or camera-based verification, establish who opened an account, not who is using it today. Fraudsters have become more adept at using other people's faces and identification documents, which is why banks need continuous identity assurance: linking that initial record to the device being used, transactional data, behavioural patterns and relationships with other accounts.

“That ecosystem extends beyond banks and their customers to data providers, telecommunications and SIM-card providers, government agencies and regulators, and weaknesses anywhere in that chain create risk elsewhere,” Redoble said. He cited SIM registration and dormant bank accounts as examples of areas fraudsters have exploited, and argued that participants across the chain need to address the problem together rather than separately.

Sorongon identified a specific gap: "At present, we do not have a centralised fraud database, nor do we have centralised monitoring of fraudsters across the financial ecosystem." He pointed to the Anti-Financial Account Scamming Act (AFASA), Republic Act 12010 of 20 July 2024, as the closest existing legal framework to this problem. It authorises institutions to temporarily hold funds subject to a disputed transaction for up to 30 calendar days, requires a coordinated verification process between the institutions and account owners involved, and gives BSP authority to investigate flagged accounts and to issue rules on information-sharing with law enforcement, addressing money muling and account-level fraud without providing the centralised database or cross-industry monitoring Sorongon described.

AFASA expressly disapplies the Data Privacy Act and Bank Secrecy Law during its coordinated verification process. Outside that mechanism, Redoble said, organisations still cannot share customer or threat data without considering the Data Privacy Act and other confidentiality obligations, creating legal and compliance risk if handled carelessly. He said AI could narrow that gap by potentially distributing information about an identified attack, such as a malicious IP address, to other AI-enabled systems within seconds, making speed rather than willingness to share the binding constraint.

Urs Bolt, international resource director at TAB Global and independent board advisor, said identity assurance increasingly needs to account for biometrics and the mobile environment, since the same identity risks extend beyond banking apps to the wider digital platforms customers use for commerce and other everyday activities. He added that education, training and awareness remain part of that response, not just technology.

Authentication, behavioural analysis and transaction monitoring sit inside each institution's risk function. Information held elsewhere in the financial and digital ecosystem, by contrast, requires cooperation across institutions and sectors that no bank can arrange alone.

AI governance puts accountability at the centre

Romina Angeliz Marcaida, AI policy and governance head at UnionBank, said AI applications should be assessed according to their level of risk, with appropriate controls and guardrails. Management committees and boards should review AI governance and models, supported by documented policies and risk assessments throughout the process. Her central principle was that "accountability follows authority": where an AI system has authority to make a decision, institutions need to establish who can override it and maintain evidence of how the decision was made and what data was accessed.

BSP's June 2026 governance guidance is consistent with that principle. Memorandum No. M-2026-031 says accountability must be clearly defined among management, developers and relevant stakeholders, while humans remain ultimately accountable for decisions made with AI systems. It calls for human oversight, clear ownership across the AI lifecycle and effective challenge by boards, and extends to vendors and outsourced service providers through a shared-responsibility model based on what each party can control.

John Howard Medina, former board member of BancNet, raised the same principle from the customer-facing side. "We cannot simply rely on a bot to make a credit decision," he said. "At the end of the day, a human still needs to be involved." BSP's framework states the same point in risk terms: human oversight should be commensurate with the risks arising from AI use, and AI outputs should not replace or diminish human responsibility.

Patricia Manasan, AI execution and innovation head at Security Bank, said banks need to protect customers and their data as they adopt AI, given the volume of customer information financial institutions hold. BSP's guidance places that requirement inside the AI system lifecycle, requiring institutions to define roles and accountabilities, assess risks, document decisions, test systems and monitor performance. The framework is non-binding and voluntary, but it still sets out BSP's supervisory expectations: institutions are expected to build their own AI governance frameworks, proportionate to the scale, complexity, materiality and risk profile of their AI use, that meet the minimum standards the guidance describes.

Government's role is coordination and implementation

Marlon Umali, CISO of City Savings Bank, called for a National Cybersecurity Plan with strong leadership and clear accountability, saying government can help banks establish guardrails for responsible AI use. That plan already exists. The Department of Information and Communications Technology (DICT) leads the National Cybersecurity Plan (NCSP) 2023-2028, a whole-of-nation framework whose own outcomes include strengthening the National Cybersecurity Inter-Agency Committee (NCIAC) as "the convergence point for implementing cybersecurity policies and strategies", building a national cybersecurity threat database that would partly address the broader information-sharing gap Sorongon described from the banking side, and proposing new legislative measures to strengthen cybersecurity. It also includes measures to develop cybersecurity career positions and competency standards, and separately, training pathways covering cybersecurity, AI and other emerging technologies.

The legislative piece has since moved. The House of Representatives passed House Bill 9605 on third and final reading on 12 August 2026. The bill would establish a National Cybersecurity Agency and transfer cybersecurity functions from the Department of Information and Communications Technology (DICT) to it. The measure now awaits transmittal to the Senate. Whether the NCIAC-strengthening and threat-database commitments have progressed to a similar degree has not been independently confirmed.

BSP's governance principles for AI state that AI applications "transcend sectoral boundaries" and set out a principles-based approach for the financial sector. The guidance is organised around five principles, known as STARS: sustainability, transparency, accountability, responsibility and security, mapped across the AI system lifecycle from planning through monitoring.

Georg Steiger, CEO and co-founder of Billease, argued for guidance that allows financial institutions to adopt AI while maintaining safeguards. "The focus should be on providing guidance that helps banks adopt AI while maintaining an appropriate balance between innovation and safeguards," he said. Lito Villanueva, chief innovation and inclusion officer and executive vice president at Rizal Commercial Banking Corporation, pointed to proposed legislation concerning AI and the longer-term implications of agentic systems.

The regulatory response involves multiple layers operating in parallel rather than one government decision: BSP's financial-sector supervision, national cybersecurity policy and broader government AI policy, alongside each institution's own governance framework.

Governance must keep pace with deployment

Marcaida said the next 12 months should focus on a "business-realisation framework" to measure AI's value to organisations, employees and customers alongside its risks.
Manasan said Security Bank is targeting AI for 30% to 40% of low-risk, manual and repetitive tasks by 2030, subject to confidence in its decisions.

How far that extends depends on where responsibility sits. Authentication, behavioural monitoring and AI governance can be strengthened within individual institutions, while cross-institution fraud intelligence, identity assurance and national coordination require action beyond any one bank. That includes addressing the centralised fraud database and cross-institution identity monitoring gaps that AFASA does not close, and a legislative track still awaiting Senate action. Until those gaps close, individual banks will keep extending controls to manage their own exposure without resolving fraud that moves between institutions.

Chat with us WhatsApp