Insights / Blog / Insights
Insights

BSP Circular 1193 Risk Event Reports: The 24-Hour Clock and the 1%-of-Capital Test

BSP Circular 1193 requires an ML/TF/PF risk event report within 24 hours. How the 1% capital and material-impact tests work, with a decision tree.

BSP Circular 1193 Risk Event Reports: The 24-Hour Clock and the 1%-of-Capital Test

Under BSP Circular 1193, a covered institution must submit an ML/TF/PF Risk Event Report to the BSP within 24 hours of knowing, or when it should have known, of a significant event. An event is significant if the amount involved is 1% or more of total qualifying capital, or if the institution determines it has a material impact.

Circular 1193 amended Section 911 of the Manual of Regulations for Banks and Section 911-Q of the Manual of Regulations for Non-Bank Financial Institutions. It is an institution-level notification to the BSP, separate from the transaction-level filings made to the AMLC. Most compliance teams know the STR and CTR clocks well. Fewer have written down who decides what counts as a significant event, or how they would prove when they knew.

What is an ML/TF/PF risk event report under Circular 1193?

It is a notification to the BSP of a money laundering, terrorism financing, or proliferation financing incident that may present a material or adverse impact to the institution, to the financial system's posture, or to public confidence in it. Circular 1193 applies to covered persons, meaning BSP-supervised institutions, and replaces the earlier reporting language in Sections 911 and 911-Q.

Only significant events are reportable. The circular does not ask for a report on every ML/TF/PF-related incident, and it does not ask for a suspicion about a customer's transaction. The trigger is the effect of the event on the institution or the system. That is why it sits alongside the STR and CTR obligations instead of replacing either.

When does the 24-hour clock start?

It starts on the date of knowledge or discovery of the occurrence, which the circular explains as the time the event has been known or should have been known by the covered person. The wording matters. A deadline that runs from when you should have known makes your detection speed and your internal escalation records part of the compliance question.

Two practical points follow. First, the circular states 24 hours, not one working day, and the text reviewed for this piece does not exclude weekends or holidays, so the safer plan is a clock that runs continuously. Second, a late internal escalation does not move the start time. If an analyst identified the event on Friday afternoon and the compliance head heard on Monday, the question an examiner can ask is when the institution should have known.

What is the 1%-of-capital test, and what is the material-impact test?

There are two limbs, and meeting either one makes an event significant. The first is arithmetic: the amount involved represents one percent or more of the covered person's total qualifying capital. The second is a judgement: regardless of the amount, the covered person has determined that the incident has a material impact.

Illustration only: an institution with ₱5 billion in total qualifying capital would cross the first limb at ₱50 million. Below that figure, the second limb still applies. The circular gives examples of material impact, such as an incident affecting a significant number of customers or counterparties, or one with a cross-border element. Grant Thornton's summary of the circular also lists adverse media attention as an example, so confirm the exact wording of the examples against the current text before relying on it in a policy.

Decision tree
Is it a reportable ML/TF/PF risk event under BSP Circular 1193?
FyscalTech
An ML/TF/PF-related incident occurs or is discovered
Test 1: is the amount involved 1% or more of the covered person's total qualifying capital?
YES
SIGNIFICANT
Report to BSP within 24 hours
NO
Test 2: has the covered person determined the incident has a material impact, regardless of amount? (many customers or counterparties, cross-border element, adverse media)
YES
SIGNIFICANT
Report to BSP within 24 hours
NO
Not a Circular 1193 report on these facts. Record the determination and the reasoning, and keep watching: facts change.
The 24-hour clock runs from when the event is known, or should have been known, by the covered person. Source: BSP Circular No. 1193, Series of 2024.

The second limb is where policy matters most. Because the institution makes the determination, a defensible programme writes down in advance who makes it, what factors they consider, and where the decision is recorded. A determination made on the day, with reasons, is far easier to defend than one reconstructed later.

What does a risk event report have to contain?

Four things at minimum: the date of knowledge or discovery of the event, a brief description of the event including the amount involved, the initial root cause and the response actions taken or planned, and the impact to the covered person. That is a short document, and it can be drafted in hours only if the underlying facts are already recorded.

Submission is electronic. BSP's guidelines memorandum on risk event report submission, M-2024-016, sets out the template, and press coverage of the memorandum describes it as submitted by the institution's compliance officer together with a signed control proof list. Confirm the current template and sign-off requirements against the memorandum before building the workflow.

What happens after the report is filed?

The circular sets no fixed follow-up deadline in the text reviewed. It says the BSP may require additional information, documents, or updates as necessary, and may conduct a special or overseeing examination as warranted. Non-compliance is subject to the applicable monetary penalty under Sections 1102 and 1102-Q of the manuals, and the circular does not state an amount of its own.

In practice, the first report is a starting point. The institution should expect follow-up questions and keep its case file current, because the initial root cause is by definition provisional. A file that shows what was known at hour 24 and what was learned afterwards is stronger than one that only shows the final view.

How is a risk event report different from an STR or a CTR?

It goes to a different regulator, is triggered by a different question, and runs on a different clock. An STR is a transaction-level report to the AMLC about suspicion. A CTR is a threshold report to the AMLC. A risk event report is an institution-level notification to the BSP about a significant event.

Risk event report STR CTR
Goes to BSP AMLC (GoTRACS) AMLC (GoTRACS)
Triggered by A significant ML/TF/PF risk event Suspicion, once determined A covered transaction
Clock 24 hours from when the event is known or should have been known By 11:59:59 pm of the next working day from determination Within five working days

A single incident can engage more than one of these. Nothing in the circular makes one clock wait for another, so the safer assumption is that they run in parallel. Our guides to the STR and CTR filing windows, SAR versus STR, and writing a BSP-ready STR cover the AMLC side in detail.

What should an AMLCO have in place before the clock starts?

Six things, most of which are decisions and records rather than technology.

1

Define knowledge. Decide what counts as the moment of knowledge and where it is logged, with a timestamp, so the start of the 24 hours can be shown.

2

Name the decision-maker. Record who determines material impact, who covers them out of hours, and what factors they consider.

3

Know your number. Keep the current total qualifying capital figure and the resulting 1% amount where the on-call team can find them.

4

Pre-build the report. Hold the template, the four required content items, and the sign-off route ready before an event happens.

5

Plan for the weekend. A clock measured in hours does not wait for Monday, so cover nights, weekends, and holidays.

6

Record the decisions that were not reports. When an event is assessed and found not significant, write down why. That record is what shows the test was applied.

Lean teams feel this hardest. The rural and cooperative bank AML guide covers how a small compliance function can carry obligations designed for larger institutions.

Where does this fit in your AML program?

It is a Case Management and Regulatory Reporting discipline, and a governance one. The evidence an examiner would ask for is a dated record: when the event was identified, who assessed it, how the two tests were applied, when the report went out, and what followed.

FyscalTech's Case Management module writes every action on a case to a timestamped audit timeline that locks at closure, requires a written reason for each disposition, and lets compliance leadership configure workflows and case creation without an engineering ticket. Those are the raw materials for proving when an institution knew and what it decided. The module does not replace the judgement on whether an event is significant. For the wider reporting workflow, see our regulatory reporting playbook for mid-size fintechs and the complete BSP Circular 950 guide.

Reporting you can evidence
See how Fyscal ARCX Case Management records when you knew and what you decided
Book a demo

Frequently asked questions

It is a notification to the BSP of a significant money laundering, terrorism financing, or proliferation financing risk event at a covered institution. Circular 1193 requires it within 24 hours of knowledge or discovery, with the date of discovery, a description, initial root cause and response, and impact.
Twenty-four hours from the date of knowledge or discovery of the event, described as the time the event has been known or should have been known by the covered person. The circular states hours, not working days, so plan for a clock that runs continuously.
One of two ways an event becomes significant: the amount involved is one percent or more of the covered person's total qualifying capital. The other is a determination by the institution that the incident has a material impact, regardless of the amount involved.
No. Only significant events are reportable, meaning those that meet the 1% test or that the institution determines have a material impact. Institutions should still record the assessment of incidents they decide are not significant, with reasons.
No. An STR goes to the AMLC, concerns suspicion about a transaction, and is due by the next working day from determination. A risk event report goes to the BSP, concerns the effect of an event on the institution, and is due within 24 hours.
Fifteen calendar days after its publication in the Official Gazette or in a newspaper of general circulation. It amends Section 911 of the Manual of Regulations for Banks and Section 911-Q of the Manual of Regulations for Non-Bank Financial Institutions.
Stay in the loop

Insights on modern finance, monthly.

No noise — just the engineering and strategy behind banking that scales.

Keep reading

Related articles