Insights / Blog / Thought Leadership
Thought Leadership

What the BSP's Payment-Integrity Draft Means for Merchant Acquirers and QR Payment Providers

What the BSP's draft payment-integrity circular means for merchant acquirers and QR payment providers: direct-arrangement mandates, the National QR Merchant Database, and compliance timelines.

What the BSP's Payment-Integrity Draft Means for Merchant Acquirers and QR Payment Providers

When the BSP discovered that thousands of online casinos were disguised as beauty salons and bakeries on digital payment platforms, the response was structural. BSP Memorandum M-2026-017, issued in May 2026, restated a principle that acquirers and payment service providers had been treating as optional: AML accountability does not transfer to an intermediary. It stays with the institution. The draft circular that followed proposes the framework to enforce that principle across every layered merchant arrangement in the Philippine payment system.

This is an exposure draft, not a final regulation. The provisions described in this article reflect the draft as published for industry comment. The final circular may differ.

The draft matters because it addresses the specific architecture that makes merchant payment fraud difficult to detect: the intermediary layer. When an acquirer contracts with an aggregator, and the aggregator onboards merchants, the acquirer's visibility into who is actually receiving funds narrows. The BSP's draft closes that gap with three mechanisms: direct-arrangement mandates for high-risk sectors, a centralised merchant database, and explicit accountability rules for every party in the payment chain.

Why the BSP acted now

The trigger was not theoretical. BSP Deputy Governor Mamerto Tangonan confirmed that surveillance had flagged merchants accepting frequent small payments, some as low as fifty pesos, late at night through e-wallets and payment apps. Those payments were bets placed on illegal online casinos. The BSP shuttered over 8,000 merchant accounts for allegedly illegal activities.

The pattern exposed a structural weakness. Payment aggregators connect thousands of small businesses to formal payment channels. That intermediary layer can obscure who is actually receiving the money. A merchant registered as a bakery could be operating as an unlicensed casino, and the acquiring bank's systems would process the transactions without distinguishing one from the other.

Offshore platforms exploited the same architecture. Foreign prediction markets, stablecoin apps, and virtual-asset services offered QR Ph checkout to Philippine users through third-party intermediaries. A user would scan a QR Ph code with a local e-wallet, and the intermediary would handle fiat-to-crypto conversion and local settlement. The acquiring bank saw a generic merchant name.

BSP Memorandum M-2026-017 addressed the accountability question directly: a bank's AML obligations cannot be transferred, diminished, or substituted by an aggregator's involvement. The draft circular builds the operational requirements around that principle.

What the draft circular requires

Direct merchant arrangements for high-risk sectors

The draft mandates that certain business categories may operate only through a direct merchant arrangement with a BSP-supervised acquirer. No intermediary. The categories include virtual-asset service providers, online gambling operators, casinos, adult content platforms, and money service businesses.

Each direct arrangement requires enhanced due diligence and ongoing transaction monitoring, with the acquirer performing merchant verification, beneficial-ownership identification, settlement-limit enforcement, and transaction-level surveillance.

This provision ends the arrangement where a high-risk platform accesses Philippine payment rails through a chain of intermediaries, each assuming the next party has performed the due diligence.

The National QR Code Merchant Database

The BSP will establish, implement, and maintain a centralised database of merchants that accept payments under the National QR Code Standard (QR Ph). The database will hold verified merchant profiles, including registration details, store addresses, beneficial owners, settlement account holders, real-time risk ratings, and sanctions-screening status.

Banks and e-wallets will receive automated alerts and may restrict or block transfers from unverified merchants or undisclosed aggregators. The interim repository must be operational within 90 calendar days of the circular taking effect. The full database must be operational within 12 months, with all active merchant records migrated and validated within 15 months.

For compliance teams, this changes the screening calculus. A centralised merchant registry creates a reference point for onboarding verification and ongoing monitoring that does not depend on the aggregator's own records.

Acquirer accountability for layered arrangements

The draft restates and operationalises what M-2026-017 established as principle. Acquirers must maintain adequate visibility over underlying merchants and related payment activities, including access to sub-merchant information, transaction-level data, and merchant risk profiles. They must apply risk-based standards to onboarding and monitoring, conduct periodic reviews, and maintain clear triggers for restricting or terminating relationships with high-risk or non-compliant sub-merchants.

Aggregators retain their own obligations: merchant due diligence, risk-based onboarding and monitoring, risk mitigation, and suspicious transaction reporting for the sub-merchants they onboard. But the aggregator's compliance programme does not satisfy the acquirer's. Both are accountable independently.

Intermediaries are barred from subcontracting merchant acquisition to another party. The chain stops at one layer.

Twelve-month moratorium on new payment system operators

The draft suspends the acceptance and processing of applications for Operator of Payment System (OPS) registration for 12 months from the circular's effective date. Applications filed before the suspension will still be evaluated but cannot be approved or denied until the moratorium lifts.

The stated rationale: the BSP will use the period to conduct a comprehensive review of OPS taxonomy and licensing. The practical effect is that no new entrants can begin merchant-acquisition activities while the integrity framework is being implemented.

Compliance timelines in the draft

Compliance timeline
Five draft milestones, counted from the circular's effectivity
FyscalTech
90 days
Milestone
Interim merchant information repository operational
6 months
Milestone
Review of existing layered merchant arrangements
12 months
Milestone
Remediation of deficiencies
Milestone
Full National QR Code Merchant Database
Milestone
OPS registration moratorium ends
15 months
Milestone
All active merchant records migrated and validated
Source: BSP exposure draft as reported by TechRepublic, 7 September 2026. Draft only; final timelines may differ. Prepared by FyscalTech.
Milestone Deadline
Interim merchant information repository operational 90 calendar days from effectivity
Review of existing layered merchant arrangements 6 months from effectivity
Remediation of deficiencies in existing arrangements 12 months from effectivity (6 months after review)
Full National QR Code Merchant Database operational 12 months from effectivity
All active merchant records migrated and validated 15 months from effectivity
OPS registration moratorium ends 12 months from effectivity

Institutions with relationships still non-compliant after 12 months face enforcement action. The draft also provides for payment-license revocation for repeated violations.

What this means for your compliance programme

Merchant onboarding becomes a compliance function

If your institution acquires merchants through aggregators, the draft requires you to treat merchant onboarding with the same rigour as customer risk rating. You need direct access to the merchant's identity, beneficial ownership, business activity, and risk profile. "The aggregator handles onboarding" is not a defensible position under the draft.

Transaction monitoring must extend to sub-merchant level

Monitoring settlement-account activity in aggregate is insufficient under the draft. The acquirer needs transaction-level visibility into sub-merchant activity, with the capacity to detect anomalous patterns (high-frequency small-value transactions at unusual hours, for example) at the individual merchant level.

This has direct implications for AML monitoring software configuration. Your threshold calibration needs merchant-level granularity, not account-level aggregation.

Incident reporting tightens

Institutions must report material fraud, scams, or unauthorised merchant activity within 24 hours of detection, with a full investigation report within five business days. This sits alongside the existing BSP Circular 1193 risk-event reporting window and the standard STR filing obligation.

The database changes the screening landscape

Once the National QR Code Merchant Database is live, every QR Ph-enabled merchant will have a verified profile against which acquirers and payment providers can screen. Unverified merchants and undisclosed aggregators become visible. The AMLC and the BSP will have supervisory access to the same dataset.

For institutions using payment screening systems, this creates a new reference dataset alongside sanctions lists and PEP databases. The screening workflow will need to incorporate merchant-verification checks against the centralised registry.

What this draft does not do

It does not make the acquirer liable for fraud committed by a merchant. It makes the acquirer accountable for maintaining the controls that would detect and prevent that fraud.

It does not ban layered merchant arrangements. It bans them for specific high-risk sectors and imposes transparency and accountability requirements on all others.

It does not replace existing AML obligations. It adds merchant-specific requirements on top of BSP Circular 950's AML/CFT framework and the existing MORPS provisions on payment system integrity.

And it is not final. The draft is published for industry comment. Institutions should prepare for the operational requirements it signals, not treat the specific timelines as confirmed.

The compliance team's preparation checklist

First, audit your existing layered merchant arrangements. Identify every relationship where an aggregator or intermediary onboards merchants on your behalf. Map which merchants fall into the high-risk categories that the draft would require to move to direct arrangements.

Second, assess your visibility. Can you access sub-merchant identity, beneficial ownership, transaction-level data, and risk profiles today? If that information sits with the aggregator and you receive only settlement-level summaries, you have a gap the draft would make non-compliant.

Third, review your monitoring rules. Transaction monitoring configured at the settlement-account level will not detect the merchant-level patterns the draft expects acquirers to catch. If your AML platform does not support sub-merchant-level monitoring, evaluate what configuration changes or system capabilities are needed.

Fourth, prepare for the database. When the National QR Code Merchant Database goes live, your onboarding and screening workflows will need to incorporate verification against it. Assess whether your current systems can integrate with an external merchant registry.

If you want to see how sub-merchant monitoring, configurable screening, and risk-event reporting work inside a single AML platform, book a walkthrough of Fyscal ARCX and bring this checklist with you.

Merchant-level monitoring
See sub-merchant monitoring, configurable screening and risk-event reporting in Fyscal ARCX
Book a demo

Frequently asked questions

It is an exposure draft published by the Bangko Sentral ng Pilipinas proposing amendments to the Manual of Regulations for Payment Systems. The draft strengthens integrity controls for payment transactions by mandating direct merchant arrangements for high-risk sectors, establishing a National QR Code Merchant Database, and requiring acquirers to maintain visibility over sub-merchants in layered arrangements.
A layered merchant arrangement exists when an acquiring bank contracts with a payment aggregator or intermediary, and that intermediary onboards and manages the underlying merchants. The acquirer processes transactions for merchants it did not directly verify. The BSP draft requires acquirers to maintain full visibility over these merchants regardless of the intermediary layer.
No. The draft bans intermediary arrangements only for specific high-risk sectors: virtual-asset service providers, online gambling operators, casinos, adult content platforms, and money service businesses. These must use direct merchant arrangements with BSP-supervised acquirers. All other layered arrangements remain permitted but face stricter transparency and accountability requirements.
It is a centralised database the BSP will operate, holding verified profiles of all merchants that accept payments under the QR Ph standard. The database will include merchant registration details, beneficial owners, settlement account holders, risk ratings, and sanctions-screening status. Acquirers and payment providers will use it as a reference for onboarding verification and ongoing monitoring.
As of publication, the draft is still under industry review and is not yet final. The specific timelines in the draft (90 days to an interim repository, 12 months to the full database, 12 months for the OPS moratorium) would begin from the final circular's effective date once approved.
The draft adds merchant-specific requirements on top of existing AML/CFT obligations under BSP Circular 950, BSP Memorandum M-2026-017, and the MORPS framework. It does not replace those obligations. Institutions remain responsible for STR filing, customer due diligence, transaction monitoring, and sanctions screening under the existing regulatory framework.
Stay in the loop

Insights on modern finance, monthly.

No noise — just the engineering and strategy behind banking that scales.

Keep reading

Related articles