20 July 2026
In brief
The Bangko Sentral ng Pilipinas (BSP) has issued M-2026-031, introducing a guidance paper on "Governance Principles for Artificial Intelligence (AI) in Financial Services." The guidance sets out supervisory expectations to support BSP-supervised financial institutions (BSFIs) in developing AI governance frameworks proportionate to their risk profiles and operational complexity. While compliance is voluntary, the principles are intended to promote ethical, transparent, and accountable AI adoption across the financial sector. The issuance highlights key risks such as data privacy, bias, and misuse of AI technologies.
Key takeaways
- BSFIs are encouraged to develop and formalize AI governance frameworks aligned with the BSP's principles and proportionate to their AI use.
- The guidance establishes five core principles, namely, Sustainability, Transparency, Accountability, Responsibility, and Security, or "STARS" in short, to underpin AI governance.
- The framework applies to financial institutions and to outsourced service providers involved in AI-related activities.
- Institutions should integrate governance controls across the AI system lifecycle, including planning, development, validation, deployment, and monitoring.
- The principles are non-binding but reflect minimum supervisory expectations and should serve to complement compliance with existing laws and regulations.
In more detail
The BSP, through M-2026-031, issued a guidance paper aimed at promoting the ethical and responsible use of AI in the financial sector. The document outlines a principles-based approach to AI governance and risk management, recognizing both the opportunities and risks associated with AI adoption. It sets out minimum supervisory expectations while allowing flexibility for institutions to tailor their frameworks based on their size, complexity, and level of AI maturity.
In particular, the guidance introduces governance principles, defines the scope of application, and maps out controls across the AI system lifecycle.
Benefits of AI Use by Financial Institutions
AI can offer significant benefits to financial institutions when deployed responsibly. It can enhance fraud detection and prevention by identifying unusual transaction patterns in real time, strengthen credit and market risk management through more sophisticated data analysis, improve customer experience through faster and more personalized services, and increase operational efficiency by automating repetitive processes such as document review, customer onboarding, regulatory reporting, and data entry. AI tools may also support more effective compliance monitoring, cybersecurity threat detection, and financial inclusion by enabling institutions to better understand customer needs and deliver services at scale.
These benefits, however, should not be pursued without appropriate guardrails. The BSP's STARS principles provide a practical governance lens for ensuring that AI-enabled innovation remains sustainable, transparent, accountable, responsible, and secure. In practice, this means that financial institutions should assess whether AI use cases generate long-term value, can be explained to relevant stakeholders, remain subject to clear human oversight, avoid unfair or discriminatory outcomes, and are protected by robust cybersecurity, data governance, validation, and monitoring controls.
Scope of Application
The guidance applies to all BSP-supervised or registered financial institutions and extends to outsourced service providers supporting AI-related activities under a shared responsibility model. It adopts a broad and principles-based approach that complements existing frameworks, including IT risk management and forthcoming model risk management regulations. The document emphasizes that it does not restrict technological innovation and must be implemented consistently with existing laws and regulations.
Voluntary and Non-binding Guidance
The governance principles are expressly non-binding and voluntary in nature. They are intended to guide institutions in developing internal AI governance policies and risk management frameworks rather than impose prescriptive requirements. The BSP positions the guidance as setting minimum supervisory expectations while signaling potential future regulatory developments as AI evolves.
STARS Principles of AI Governance
The guidance introduces the "STARS" framework, which articulates five core principles, namely:
- Sustainability: AI systems should deliver long-term value and consider environmental and societal impacts.
- Transparency: Institutions should ensure explainability, maintain AI inventories, disclose relevant information, and enable auditability of systems.
- Accountability: Roles and responsibilities across the AI lifecycle must be clearly defined, with human oversight retained over AI-driven decisions.
- Responsibility (Social Fairness): AI systems should avoid harmful or discriminatory outcomes, ensure proper data handling, and uphold data subject rights.
- Security: Institutions should implement robust cybersecurity and data quality controls, including risk assessments and monitoring of model performance.
AI System Lifecycle Controls
The guidance outlines an AI system lifecycle consisting of planning, development, validation, deployment, and monitoring phases. At each stage, institutions are expected to implement appropriate controls, including risk-based assessments, documentation, independent validation, testing, and continuous monitoring. The lifecycle is described as iterative, requiring ongoing intervention and adjustment to address emerging risks.
Interaction with Existing Laws and Frameworks
The guidance underscores that AI governance must align with existing Philippine laws and BSP regulations, including those on data privacy, consumer protection, IT risk management, and operational risk. It also references broader regulatory and international frameworks, indicating that AI governance should be integrated into an institution's overall governance and compliance structure.
Recommendation for Financial Institutions
The BSP recommends that financial institutions formally develop their own AI governance frameworks based on the principles outlined in the guidance. Embedding these principles into governance structures is intended to support responsible AI use, enhance resilience, and strengthen public trust in financial services.
How this affects your business
BSFIs should consider reviewing their existing governance structures, risk management frameworks, and internal policies to assess alignment with the principles set out in M-2026-031. In particular, institutions may wish to evaluate whether appropriate controls are in place across the AI system lifecycle, including documentation, validation, monitoring, and oversight mechanisms, and whether roles and accountabilities are clearly defined. Institutions that engage outsourced service providers for AI-related activities should also ensure that relevant contractual and oversight arrangements are consistent with the shared responsibility model contemplated in the guidance.
In sum, AI may be used to create value for the institution and its customers, including through improved fraud detection, risk analytics, customer service, compliance monitoring, operational efficiency, and financial inclusion, but these use cases must always be guided by the STARS principles. Organizations considering the adoption or broader use of AI may take this opportunity to formalize or enhance their AI governance frameworks in line with the BSP's principles-based approach, ensuring consistency with existing regulatory requirements. For further information on how this development may affect your organization, please feel free to reach out to our team in Quisumbing Torres, and we will be pleased to assist.