Data Licensing
Datasets Live · API Q3 2026

Regulation, Rendered as Structured Data.

Every obligation parsed, classified by deontic type, and tied to legal citation, source text, and page. The register powers our live dashboard today, and the datasets license one-time on each jurisdiction page now. API delivery opens Q3 2026.

6,000+
Obligations
3
Regulations
SG / PH
Coverage
Obligation Register
BSP.MORB.2023.Sec921.p16.OBL3SHALLOBLIGATION

A covered person shall formulate a risk-based and tiered customer acceptance, identification and retention policy that involves reduced CDD for potentially low-risk clients and enhanced CDD for higher-risk accounts.

MORB Part IX, Sec. 921, p. 16 (2023)Customer Due DiligenceCDD/KYC
BSP.MORB.2023.Sec921.g.p24.OBL7SHOULDRECOMMENDATION

Moreover, the relying party should ensure that the third party's digital ID system enables the former to (i) immediately obtain the necessary information concerning the identity of the customer (including the assurance levels, where applicable); and (ii) take adequate steps to satisfy itself that the third party will make available copies or other appropriate forms of access to the identity evidence (documents, data and other relevant information) upon request without delay.

MORB Part IX, Sec. 921.g, p. 24 (2023)Customer Due DiligenceCDD/KYC
BSP.MORB.2023.Sec922.p30.OBL3SHALLOBLIGATION

They shall maintain a register of all STs that have been brought to the attention of senior management whether or not the same was reported to the AMLC.

MORB Part IX, Sec. 922, p. 30 (2023)Covered and Suspicious Transaction ReportingReporting
BSP.MORB.2023.Sec923.a-(2)(6).p32.OBL1SHALLOBLIGATION

Shall only include the account number or a unique transaction reference number, where the information accompanying the domestic wire transfer can be made available to the beneficiary financial institution and appropriate authorities by other effective means: Provided, That this number or identifier will permit the transaction to be traced back to the originator or the beneficiary.

MORB Part IX, Sec. 923.a-(2)(6), p. 32 (2023)Additional Preventive MeasuresWire Transfers
MAS.CH.2024.Sec4.1.p3.OBL1MUSTOBLIGATION

A relevant entity must ensure that every administrative account in respect of any operating system, database, application, security appliance or network device, is secured to prevent any unauthorised access to or use of such account.

MAS Notice FSM-N06 (Cyber Hygiene), paragraph 4.1, p. 3 (2024)Cyber Security RequirementsCyber Hygiene
MAS.OUT.2023.Sec12.4.p15.OBL1MUSTOBLIGATION

A bank in Singapore must document the due diligence checks required under paragraphs 12.2 and 12.3 and furnish the documentation to the Authority upon request.

MAS Notice 658 (Outsourced Relevant Services), paragraph 12.4, p. 15 (2023)Requirements Relating to Outsourced Relevant Services That Involve the Disclosure of Customer InformationOutsourcing
MAS.TRM.2021.Sec7.2.1.p23.OBL1SHOULDRECOMMENDATION

The FI should implement a configuration management process to maintain accurate information of its hardware and software to have visibility and effective control of its IT systems.

MAS TRM Guidelines, Section 7.2.1, p. 23 (2021)IT Service ManagementIT Service
MAS.TRM.2021.Sec3.1.2.p7.OBL1SHOULDRECOMMENDATION

Both the board of directors and senior management should have members with the knowledge to understand and manage technology risks, which include risks posed by cyber threats.

MAS TRM Guidelines, Sec. 3.1.2, p. 7 (2021)Technology Risk GovernanceGovernance
MAS.TRM.2021.Sec7.7.4.p26.OBL1SHOULDRECOMMENDATION

The FI should configure system events or alerts to provide an early indication of issues that may affect its IT systems’ performance and security.

MAS TRM Guidelines, Sec. 7.7.4, p. 26 (2021)IT Systems MonitoringMonitoring
BSP.MORB.2023.Sec911.a(1).p11.OBL1SHALLOBLIGATION

It shall conduct periodic compliance checking which covers, among others, evaluation of existing processes, policies and procedures including ongoing monitoring of performance by staff and officers involved in ML and TF prevention, reporting channels, effectiveness of the electronic money laundering transaction monitoring system and record retention system through sample testing and review of audit or examination reports.

MORB Part IX, Sec. 911.a(1), p. 11 (2023)Risk ManagementRisk Management
BSP.MORB.2023.Sec921.p16.OBL3SHALLOBLIGATION

A covered person shall formulate a risk-based and tiered customer acceptance, identification and retention policy that involves reduced CDD for potentially low-risk clients and enhanced CDD for higher-risk accounts.

MORB Part IX, Sec. 921, p. 16 (2023)Customer Due DiligenceCDD/KYC
BSP.MORB.2023.Sec921.g.p24.OBL7SHOULDRECOMMENDATION

Moreover, the relying party should ensure that the third party's digital ID system enables the former to (i) immediately obtain the necessary information concerning the identity of the customer (including the assurance levels, where applicable); and (ii) take adequate steps to satisfy itself that the third party will make available copies or other appropriate forms of access to the identity evidence (documents, data and other relevant information) upon request without delay.

MORB Part IX, Sec. 921.g, p. 24 (2023)Customer Due DiligenceCDD/KYC
BSP.MORB.2023.Sec922.p30.OBL3SHALLOBLIGATION

They shall maintain a register of all STs that have been brought to the attention of senior management whether or not the same was reported to the AMLC.

MORB Part IX, Sec. 922, p. 30 (2023)Covered and Suspicious Transaction ReportingReporting
BSP.MORB.2023.Sec923.a-(2)(6).p32.OBL1SHALLOBLIGATION

Shall only include the account number or a unique transaction reference number, where the information accompanying the domestic wire transfer can be made available to the beneficiary financial institution and appropriate authorities by other effective means: Provided, That this number or identifier will permit the transaction to be traced back to the originator or the beneficiary.

MORB Part IX, Sec. 923.a-(2)(6), p. 32 (2023)Additional Preventive MeasuresWire Transfers
MAS.CH.2024.Sec4.1.p3.OBL1MUSTOBLIGATION

A relevant entity must ensure that every administrative account in respect of any operating system, database, application, security appliance or network device, is secured to prevent any unauthorised access to or use of such account.

MAS Notice FSM-N06 (Cyber Hygiene), paragraph 4.1, p. 3 (2024)Cyber Security RequirementsCyber Hygiene
MAS.OUT.2023.Sec12.4.p15.OBL1MUSTOBLIGATION

A bank in Singapore must document the due diligence checks required under paragraphs 12.2 and 12.3 and furnish the documentation to the Authority upon request.

MAS Notice 658 (Outsourced Relevant Services), paragraph 12.4, p. 15 (2023)Requirements Relating to Outsourced Relevant Services That Involve the Disclosure of Customer InformationOutsourcing
MAS.TRM.2021.Sec7.2.1.p23.OBL1SHOULDRECOMMENDATION

The FI should implement a configuration management process to maintain accurate information of its hardware and software to have visibility and effective control of its IT systems.

MAS TRM Guidelines, Section 7.2.1, p. 23 (2021)IT Service ManagementIT Service
MAS.TRM.2021.Sec3.1.2.p7.OBL1SHOULDRECOMMENDATION

Both the board of directors and senior management should have members with the knowledge to understand and manage technology risks, which include risks posed by cyber threats.

MAS TRM Guidelines, Sec. 3.1.2, p. 7 (2021)Technology Risk GovernanceGovernance
MAS.TRM.2021.Sec7.7.4.p26.OBL1SHOULDRECOMMENDATION

The FI should configure system events or alerts to provide an early indication of issues that may affect its IT systems’ performance and security.

MAS TRM Guidelines, Sec. 7.7.4, p. 26 (2021)IT Systems MonitoringMonitoring
BSP.MORB.2023.Sec911.a(1).p11.OBL1SHALLOBLIGATION

It shall conduct periodic compliance checking which covers, among others, evaluation of existing processes, policies and procedures including ongoing monitoring of performance by staff and officers involved in ML and TF prevention, reporting channels, effectiveness of the electronic money laundering transaction monitoring system and record retention system through sample testing and review of audit or examination reports.

MORB Part IX, Sec. 911.a(1), p. 11 (2023)Risk ManagementRisk Management
License Terms

The Terms Your Legal Team Will Ask About.

One license model across every ProfytAI dataset, stated here in full. Pricing lives with each dataset on the data catalog; the full legal text ships inside every product as LICENSE.md.

License Scope
Every dataset is licensed one-time to a single organization for internal use. All staff of the licensed organization may use the data in internal registers, controls, policies, audit workpapers, and internal AI systems.
Versioning
Every release is dated and versioned with a change log. Each shipped JSON carries a versioned metadata envelope with a SHA-256 content hash, so you can verify exactly what you ingested.
Errata
If a data error is confirmed in a released version, the correction is made and the affected products are reissued free of charge to licensees of that version.
Updates
Datasets are point-in-time, never real-time. An annual update subscription that delivers each new version on reissuance is optional, never required. A free reissue ships when the regulator revises a licensed instrument within your licensed version's coverage.
Redistribution and OEM
Redistribution, OEM embedding, and multi-entity or multi-seat coverage are not part of the standard license. They are available under enterprise terms via a private offer. Talk to Us About Enterprise Terms.
Delivery
Instant download after purchase, with the Excel workbook, data dictionary, methodology, change log, and the JSON and CSV exports. Official regulator source documents are linked, not redistributed.
Evaluation
The free sample carries a free evaluation license. Every field of the full product ships on real records, so you can judge the depth before licensing.
Snowflake Marketplace
Datasets distributed through Snowflake Marketplace are delivered as a secure data share rather than as files, and each product is governed by its own agreement covering that delivery. Those agreements are published in full, and the free evaluation sample and the complete register are licensed on different terms. Read the free sample terms or the complete register terms.
Reliance
In licensing a dataset you confirm that you are relying on the terms stated here and in the licence delivered with the product, and not on any other statement, coverage figure, description, listing, or marketing material. Counts and coverage descriptions state what our published extraction methodology produced from the instrument versions cited in a release; they are not assurances that every applicable provision is captured. Nothing here limits liability for fraud.
Warranties
Datasets are supplied as is. We do not warrant completeness, accuracy, currency, or fitness for a particular purpose, and coverage figures describe what our published methodology produced from the instrument versions cited in the release rather than a guarantee that every provision is captured.
Liability
Our total liability for a dataset is capped at the fees paid for it in the twelve months preceding the claim, and we are not liable for indirect or consequential loss, lost profits, business interruption, or regulatory penalties. Nothing is excluded that cannot lawfully be excluded, including liability for fraud.
Governing Law
Singapore law, without regard to conflict-of-laws rules. Where a signed order or enterprise agreement conflicts with these terms, that agreement controls to the extent of the conflict.
Procurement Documents
A data dictionary, methodology and QA notes, and the license terms ship inside every product. Every dataset also carries a rights and permissions statement, written for due-diligence teams, setting out the basis on which regulatory text is reproduced, what is and is not redistributed, and the absence of any regulator endorsement. A signed DPA and security documentation are available on request.
Coverage and Rights

What Counts as an Obligation, and What We Leave Out.

A regulation does not enumerate its own duties, so every obligation register rests on an inclusion rule. Ours is stated here in full as to scope, and the detailed vocabulary it applies ships in the schema documentation with every product. It is visible in the data too: every record in a register carries the form it was recognised from, so your counsel can audit the judgement rather than take it on trust.

In the register

  • Provisions that place a duty, recommendation, or prohibition on a regulated entity
  • Recognised from the instrument's own duty-bearing language and imperative construction. The full vocabulary, and the field that records which form each obligation was recognised from, ship with the product
  • Binding and advisory duties both, separated by modal_strength so you can filter to the mandatory subset
  • The modal, its strength, and its deontic category on every record of an obligation register. Policy-statement and control-mapping products are built on those registers and carry their own fields

Generally not extracted

  • Permissions and discretions ("may", "can"). Confer a liberty, not a duty. There is nothing to comply with.
  • The regulator's own powers and intentions ("the Authority will…"). Bind the regulator, not you.
  • Definitions, headings, recitals, commencement and application provisions. Interpretive scaffolding rather than duties.
  • Contextual lead-ins that introduce a list. The duty sits in the items. Where a governing lead-in exists it travels with those items as context rather than becoming a record of its own.

These exclusions describe the design intent of the registers rather than a guarantee about every provision: a provision that places no duty on you is not an obligation, and carrying it would dilute the register. Extraction is selective and methodology-dependent, and reasonable readers may characterise provisions differently. Record counts describe what this methodology produces from the instrument versions cited in each product. They are not a representation that every provision a regulator, court, or auditor might characterise as an obligation is captured. Where you need the complete instrument text, it is free from the regulator and linked in every product.

Regulator Text
Obligations are quoted byte-exactly from the published instrument and always carry the issuing regulator, section, page, citation, and official URL. ProfytAI claims no rights in the regulatory text itself, only in the structuring, classification, and analysis around it.
Source Documents
Complete official instruments are never redistributed inside a product. They are free from the regulator, which remains the authoritative and current source, and every product links them.
No Endorsement
No regulator has reviewed, approved, endorsed, or certified ProfytAI or any analysis in these datasets. No regulator logo, seal, or crest appears in any product.
Not Legal Advice
These are regulatory information products, not legal advice and not a substitute for counsel. The verbatim text is the authority; derived and generated fields, including drafted policy statements, are produced for your review and remain your decision to adopt.
Rights Questions
Every product ships a RIGHTS_AND_PERMISSIONS.md written for due-diligence teams, stating the basis on which regulatory material is reproduced. Raise a rights concern through the contact form.

This page is a summary. The controlling document ships inside every product: LICENSE.md carries the licence grant and restrictions, and its reliance, coverage, and warranty terms (Section 8) state the basis on which the data may be relied on, governing across every channel including APIs, graph exports, and generated reports. Browse the data catalog.

Audit-Grade by Construction

Every Obligation Traces Back to the Page It Came From.

Extraction is verbatim and deterministic, not summarized. Every record includes verbatim source text, legal citation, page reference, and the official source link. Source-page capture images are included where licensed for redistribution.

Verbatim Text

Exact obligation wording as published, never paraphrased.

Legal Citation and Page

Section, clause, and page number for direct lookup.

Source Link and Capture

Official source link on every record. Source-page capture images where licensed for redistribution.

Extraction Timestamp

ISO timestamp of when the obligation was extracted from source, for audit trail and version control.

Delivery

Built for the Systems That Consume It.

  • REST API, JSON Native

    Query obligations by regulation, policy group, or citation. Stable identifiers across versions.

  • CSV Flat Files

    Bulk delivery for warehouses and pipelines that prefer tabular ingestion.

  • Versioned and Timestamped

    Every record is version-tagged. Amendment and supersession tracked where the regulator publishes it.

Sample Data

Representative excerpt. Full obligation records include additional fields.

GET/v1/regulatory/obligations/BSP.MORB.2023.Sec921.p16.OBL3
{
  "obligation_id": "BSP.MORB.2023.Sec921.p16.OBL3",
  "deontic": "OBLIGATION",
  "parsed_requirement": {
    "modal": "SHALL",
    "modal_strength": "mandatory",
    "deontic_category": "obligation",
    "matched_keyword": "shall",
    "is_negative": false
  },
  "obligation_type": "process",
  "covered_person_scope": ["all"],
  "is_criminal_offense": false,
  "verbatim_text": "A covered person shall formulate a risk-based and tiered customer acceptance, identification and retention policy that involves reduced CDD for potentially low-risk clients and enhanced CDD for higher-risk accounts.",
  "source": {
    "jurisdiction": "Philippines",
    "regulator": "Bangko Sentral ng Pilipinas (BSP)",
    "document_title": "Manual of Regulations for Banks",
    "document_version": "2023",
    "framework": "MORB",
    "section_number": "921",
    "section_title": "Customer Due Diligence",
    "legal_citation": "MORB, Sec. 921, p. 16 (2023 ed.)",
    "page_number": 16,
    "page_start": 16,
    "page_end": 16,
    "extraction_timestamp": "2026-06-17T10:05:38.073911+00:00",
    "ocr_confidence": 0.99
  },
  "last_updated": "2026-06-17T10:05:38.073911+00:00"
}
  
Register Interest
Coming Q3 2026

Get on the Early-Access List.

API licensing opens Q3 2026. Register now and we will reach out to discuss tiers, coverage, and indicative pricing for your use case.

Step 01

We Reach Out

A member of the team will contact you within two business days to discuss your use case.

Step 02

Scope and Tiers

We walk through coverage, delivery options, and indicative pricing for your needs.

Step 03

Early Access

Priority notification and onboarding when API licensing opens in Q3 2026.