- Data
- Philippines / MORB
- Obligations
- MORB, Sec. 921.a-(1), p. 26 (2023 ed.)
Source Document
Manual of Regulations for Banks
BSP.MORB.2023.Sec921.a-(1).p26.OBL2
Manual of Regulations for Banks > 921 CUSTOMER DUE DILIGENCE > Ongoing monitoring of customers, accounts and transactions > (1)
Obligation Summary
Keep a written record of every step taken when refreshing a customer's information, and re-rate the customer's risk profile to reflect what the refresh found.
The covered person shall document the actions taken in connection with updating of customer’s records/information, and accordingly update customer’s risk profile.
MORB, Sec. 921.a-(1), p. 26 (2023 ed.) · Manual of Regulations for Banks · p. 26
Ongoing monitoring of customers, accounts and transactions.
a. Covered persons shall, on the basis of materiality and risk, ensure that pertinent identification information and documents collected under the CDD process are kept up-to-date and relevant by undertaking reviews of existing records, particularly for higher-risk categories of customers. The covered person shall document the actions taken in connection with updating of customer’s records/information, and accordingly update customer’s risk profile.
Covered persons shall establish a system that will enable them to understand the normal and reasonable account or business activity of customers to ensure that the customers’ accounts and transactions are consistent with their knowledge of the customers, and the latter’s commercial activities, risk profile, and source of funds and detect unusual or suspicious patterns of account activity. Thus, a risk- and materiality-based ongoing monitoring of customers’ accounts and transactions, including periodic sanction screening, should be part of a covered person’s customer due diligence.
What This Requires.
ProfytAI Regulatory Intelligence
Type: requirementRequires covered persons to document the actions taken when updating a customer's records or information, and to update the customer's risk profile accordingly.
Why This Exists
Creates an auditable trail of record-update activity and keeps the customer's risk profile aligned with the latest information, supporting consistent risk-based due diligence and supervisory review.
Implementation Considerations
Typically requires an auditable case record (who updated what, when, and why) attached to the customer file, together with a corresponding change to the customer's risk-rating field.
Interpretation Note · Imposes two linked duties, documenting the update actions and updating the risk profile; performing the risk-profile update does not by itself satisfy the documentation duty. Follows on from the records-review duty addressed in the same 'Ongoing monitoring' subsection.
This explanation is generated regulatory intelligence, traceable to the citation above.
The byte-exact verbatim text remains the authority you cite.
The captured source page, with this duty highlighted and stamped with its obligation ID, section, and page.
.p26.OBL2.png)