Every obligation parsed, classified by deontic type, and tied to legal citation, source text, and page. The register powers our live dashboard today, and the datasets license one-time on each jurisdiction page now. API delivery opens Q3 2026.
A covered person shall formulate a risk-based and tiered customer acceptance, identification and retention policy that involves reduced CDD for potentially low-risk clients and enhanced CDD for higher-risk accounts.
Moreover, the relying party should ensure that the third party's digital ID system enables the former to (i) immediately obtain the necessary information concerning the identity of the customer (including the assurance levels, where applicable); and (ii) take adequate steps to satisfy itself that the third party will make available copies or other appropriate forms of access to the identity evidence (documents, data and other relevant information) upon request without delay.
They shall maintain a register of all STs that have been brought to the attention of senior management whether or not the same was reported to the AMLC.
Shall only include the account number or a unique transaction reference number, where the information accompanying the domestic wire transfer can be made available to the beneficiary financial institution and appropriate authorities by other effective means: Provided, That this number or identifier will permit the transaction to be traced back to the originator or the beneficiary.
A relevant entity must ensure that every administrative account in respect of any operating system, database, application, security appliance or network device, is secured to prevent any unauthorised access to or use of such account.
A bank in Singapore must document the due diligence checks required under paragraphs 12.2 and 12.3 and furnish the documentation to the Authority upon request.
The FI should implement a configuration management process to maintain accurate information of its hardware and software to have visibility and effective control of its IT systems.
Both the board of directors and senior management should have members with the knowledge to understand and manage technology risks, which include risks posed by cyber threats.
The FI should configure system events or alerts to provide an early indication of issues that may affect its IT systems’ performance and security.
It shall conduct periodic compliance checking which covers, among others, evaluation of existing processes, policies and procedures including ongoing monitoring of performance by staff and officers involved in ML and TF prevention, reporting channels, effectiveness of the electronic money laundering transaction monitoring system and record retention system through sample testing and review of audit or examination reports.
A covered person shall formulate a risk-based and tiered customer acceptance, identification and retention policy that involves reduced CDD for potentially low-risk clients and enhanced CDD for higher-risk accounts.
Moreover, the relying party should ensure that the third party's digital ID system enables the former to (i) immediately obtain the necessary information concerning the identity of the customer (including the assurance levels, where applicable); and (ii) take adequate steps to satisfy itself that the third party will make available copies or other appropriate forms of access to the identity evidence (documents, data and other relevant information) upon request without delay.
They shall maintain a register of all STs that have been brought to the attention of senior management whether or not the same was reported to the AMLC.
Shall only include the account number or a unique transaction reference number, where the information accompanying the domestic wire transfer can be made available to the beneficiary financial institution and appropriate authorities by other effective means: Provided, That this number or identifier will permit the transaction to be traced back to the originator or the beneficiary.
A relevant entity must ensure that every administrative account in respect of any operating system, database, application, security appliance or network device, is secured to prevent any unauthorised access to or use of such account.
A bank in Singapore must document the due diligence checks required under paragraphs 12.2 and 12.3 and furnish the documentation to the Authority upon request.
The FI should implement a configuration management process to maintain accurate information of its hardware and software to have visibility and effective control of its IT systems.
Both the board of directors and senior management should have members with the knowledge to understand and manage technology risks, which include risks posed by cyber threats.
The FI should configure system events or alerts to provide an early indication of issues that may affect its IT systems’ performance and security.
It shall conduct periodic compliance checking which covers, among others, evaluation of existing processes, policies and procedures including ongoing monitoring of performance by staff and officers involved in ML and TF prevention, reporting channels, effectiveness of the electronic money laundering transaction monitoring system and record retention system through sample testing and review of audit or examination reports.
One license model across every ProfytAI dataset, stated here in full. Pricing lives with each dataset on the data catalog; the full legal text ships inside every product as LICENSE.md.
A regulation does not enumerate its own duties, so every obligation register rests on an inclusion rule. Ours is stated here in full as to scope, and the detailed vocabulary it applies ships in the schema documentation with every product. It is visible in the data too: every record in a register carries the form it was recognised from, so your counsel can audit the judgement rather than take it on trust.
These exclusions describe the design intent of the registers rather than a guarantee about every provision: a provision that places no duty on you is not an obligation, and carrying it would dilute the register. Extraction is selective and methodology-dependent, and reasonable readers may characterise provisions differently. Record counts describe what this methodology produces from the instrument versions cited in each product. They are not a representation that every provision a regulator, court, or auditor might characterise as an obligation is captured. Where you need the complete instrument text, it is free from the regulator and linked in every product.
This page is a summary. The controlling document ships inside every product: LICENSE.md carries the licence grant and restrictions, and its reliance, coverage, and warranty terms (Section 8) state the basis on which the data may be relied on, governing across every channel including APIs, graph exports, and generated reports. Browse the data catalog.
Extraction is verbatim and deterministic, not summarized. Every record includes verbatim source text, legal citation, page reference, and the official source link. Source-page capture images are included where licensed for redistribution.
Verbatim Text
Exact obligation wording as published, never paraphrased.
Legal Citation and Page
Section, clause, and page number for direct lookup.
Source Link and Capture
Official source link on every record. Source-page capture images where licensed for redistribution.
Extraction Timestamp
ISO timestamp of when the obligation was extracted from source, for audit trail and version control.
REST API, JSON Native
Query obligations by regulation, policy group, or citation. Stable identifiers across versions.
CSV Flat Files
Bulk delivery for warehouses and pipelines that prefer tabular ingestion.
Versioned and Timestamped
Every record is version-tagged. Amendment and supersession tracked where the regulator publishes it.
Representative excerpt. Full obligation records include additional fields.
{
"obligation_id": "BSP.MORB.2023.Sec921.p16.OBL3",
"deontic": "OBLIGATION",
"parsed_requirement": {
"modal": "SHALL",
"modal_strength": "mandatory",
"deontic_category": "obligation",
"matched_keyword": "shall",
"is_negative": false
},
"obligation_type": "process",
"covered_person_scope": ["all"],
"is_criminal_offense": false,
"verbatim_text": "A covered person shall formulate a risk-based and tiered customer acceptance, identification and retention policy that involves reduced CDD for potentially low-risk clients and enhanced CDD for higher-risk accounts.",
"source": {
"jurisdiction": "Philippines",
"regulator": "Bangko Sentral ng Pilipinas (BSP)",
"document_title": "Manual of Regulations for Banks",
"document_version": "2023",
"framework": "MORB",
"section_number": "921",
"section_title": "Customer Due Diligence",
"legal_citation": "MORB, Sec. 921, p. 16 (2023 ed.)",
"page_number": 16,
"page_start": 16,
"page_end": 16,
"extraction_timestamp": "2026-06-17T10:05:38.073911+00:00",
"ocr_confidence": 0.99
},
"last_updated": "2026-06-17T10:05:38.073911+00:00"
}
…API licensing opens Q3 2026. Register now and we will reach out to discuss tiers, coverage, and indicative pricing for your use case.
We Reach Out
A member of the team will contact you within two business days to discuss your use case.
Scope and Tiers
We walk through coverage, delivery options, and indicative pricing for your needs.
Early Access
Priority notification and onboarding when API licensing opens in Q3 2026.