Finance · Banking
Manila Halts Approvals for Digital Payment Operators Pending Fraud Review
A twelve-month freeze on licensing will let the central bank overhaul merchant verification rules and build a national QR database to trace transactions

KEY TAKEAWAYS
- ·The Bangko Sentral ng Pilipinas plans a twelve-month suspension on new payment system operator applications to redesign its licensing and risk management framework.
- ·A proposed National QR Code Merchant Database would consolidate seller identities, settlement accounts, and risk classifications, with an interim repository due within ninety days.
- ·High-risk merchants including casinos, gaming platforms, and remittance firms would face direct-only onboarding, stricter background checks, and transaction caps under the draft rule.
Licensing Freeze to Run Through 2027
The Bangko Sentral ng Pilipinas has drafted a rule that would block fresh entrants to the country's digital payment infrastructure for the next twelve months, buying time to redesign how it classifies and supervises operators.
Under the proposed circular, no applications to operate payment systems will be accepted or processed during the suspension. Entities already in the queue before the freeze takes effect will see their files reviewed but not approved or denied until the moratorium ends. The central bank says it needs breathing room to rethink its taxonomy of operators and the risk controls tied to each category.
The pause reflects a broader worry inside Bangko Sentral that rapid growth in mobile and QR code transactions has outpaced the ability of regulators and banks to track where money is going. Fraud complaints have climbed, and investigators say layered intermediary arrangements make it difficult to identify the seller behind a transaction or freeze suspicious flows in real time.
Direct Relationships and High-Risk Tiers
The draft rule would force banks and other supervised financial institutions to know precisely which merchant is receiving funds from every transaction they process. If the actual seller or the ultimate beneficiary cannot be identified, the institution must refuse or halt the payment.
Merchant acquisition, the service of accepting card or QR payments on behalf of sellers and forwarding the proceeds, would generally have to happen through a direct contractual link between the bank and the business. Intermediaries could still participate, but only if the bank retains full visibility into the chain and can trace funds at every step.
Certain categories of merchants would be allowed to onboard only through direct arrangements, with no intermediary layer permitted. That list includes casinos and gambling operators, gaming platforms that hold player funds, lawful adult-oriented businesses, licensed virtual asset service providers, and money service businesses such as remittance firms and currency exchangers. These sellers would also face more detailed background checks, continuous monitoring, and caps on transaction volume and settlement speed calibrated to their risk profile.
Institutions would be barred outright from working with merchants engaged in illegal activity or operating a regulated business without the necessary license.
Shared Accounts and Unique Identifiers
For merchants outside the high-risk tier, pooled settlement through a shared account or platform would remain possible, but only if each transaction carries a unique merchant identifier that allows it to be monitored, investigated, and reconciled separately. If merchant information is missing, wrong, or inaccessible, the institution must reject or suspend the transaction or the merchant relationship, except when a temporary technical glitch is covered by an incident management plan already on file.
The rule would also prohibit intermediaries from sub-delegating merchant acquisition to yet another party, preventing the creation of additional layers. Ancillary services, such as software hosting or customer support, could still be outsourced under existing central bank guidelines.
Any multi-layered arrangement deemed high-risk would need sign-off from the institution's board or equivalent governance body, quarterly management or compliance reviews, and an independent assurance exercise at least once a year.
National QR Merchant Registry
A second major piece of the draft is a National QR Code Merchant Database that would consolidate records on every business accepting payments through the country's standardized QR code scheme. The registry would store merchant names, business registration and license details, the payment service provider handling their transactions, settlement account information, beneficial owners, and a risk classification. It would also flag whether a merchant is active, restricted, suspended, or terminated.
When one institution updates a merchant's status, all other providers working with that same business would be notified automatically, triggering their own reviews and any necessary safeguards.
The central bank wants an interim secure repository stood up within ninety days of the rule taking effect. The full database must be operational within twelve months, with all active merchant records migrated and validated within fifteen months.
Incident Reporting and Transition Periods
Under the draft, institutions would have to report material fraud or scam incidents, sanctions violations, cybersecurity or data breaches, unlicensed activity, and illegal merchant conduct within twenty-four hours of discovery. A detailed incident report would be due within five business days. If the investigation cannot reasonably be completed by then, an interim report must be filed and a full report submitted within a timeframe approved by the supervising department. These obligations sit alongside existing requirements to report suspicious transactions to the country's Anti-Money Laundering Council.
For existing layered merchant arrangements, institutions would have six months from the rule's effective date to conduct a review and another six months from the review's completion to fix any gaps. Any relationship still out of compliance after twelve months would be subject to enforcement action.
Implications for Market Concentration
The licensing freeze arrives at a moment when the Philippines is already one of Southeast Asia's most crowded fintech markets, with dozens of e-wallet providers, payment gateways, and acquiring banks competing for merchant and consumer volume. Shutting the door to new operators for a year will likely cement the positions of incumbents and raise the barrier for late-stage startups hoping to secure a license before scaling.
At the same time, the merchant identification and database requirements will impose new operational costs on existing players, particularly those that rely on aggregator or platform models to onboard small merchants quickly. Institutions will need to invest in systems that can tag each transaction with a unique merchant identifier, reconcile payments in real time, and integrate with the national registry once it goes live.
The draft is open for comment, and the final version may shift in scope or timeline. But the direction is clear: Bangko Sentral wants tighter control over who processes payments in the Philippines and a clearer line of sight into where the money goes.
RELATED STORIES
Spot something wrong? Email editor@briefasia.com. We log every correction publicly.



