Table of Contents
Key Takeaway
- 📋 The Regulation: The Bangko Sentral ng Pilipinas issued Memorandum No. M-2026-031 on June 24, 2026, establishing five STARS principles — sustainability, transparency, accountability, responsibility, and security — for AI use in all BSP-supervised financial institutions.
- 🏦 Who Is Affected: All BSP-supervised financial institutions (BSFIs) plus outsourced service providers that support AI-related activities under a shared responsibility model — covering banks, e-wallets, payment providers, and fintech vendors.
- ⚙️ What BSFIs Must Do: Develop a formal AI Governance Framework proportionate to their AI system’s nature, extent, scale, complexity, and materiality, covering the full AI lifecycle: plan, develop, validate, deploy, and monitor.
- 👩💼 Named Official: BSP Deputy Governor Lyn I. Javier issued the guidance, stating that ethical and responsible AI use “can foster trust, strengthen resilience, and promote sustainable innovation within the financial ecosystem.”
- ⚡ Action for Professionals: Filipino banking, fintech, and IT professionals should review their organization’s AI systems against the STARS framework now — compliance expectations will tighten as BSP moves from guidance to enforcement.
The Bangko Sentral ng Pilipinas (BSP) issued Memorandum No. M-2026-031 on June 24, 2026, establishing governance principles for artificial intelligence in Philippine financial services. The guidance paper, titled “Governance Principles for Artificial Intelligence in Financial Services,” introduces five principles under the acronym STARS — sustainability, transparency, accountability, responsibility, and security — that all BSP-supervised financial institutions (BSFIs) must use to craft their own AI governance and risk management frameworks. The memorandum also covers outsourced service providers that support AI-related activities, creating a shared responsibility model that extends the requirements to fintech vendors and third-party AI providers.
“As artificial intelligence continues to advance and integrate into the financial sector, financial institutions must establish effective controls and safeguards against the attendant risks of AI adoption, such as data privacy concerns, bias leading to unfair and discriminatory practices, and misuse of technology, among others,” BSP Deputy Governor Lyn I. Javier said in the memorandum, as reported by BusinessWorld Online and confirmed by Asian Banking & Finance.
The BSP AI governance framework arrives as Philippine financial institutions accelerate AI adoption across credit scoring, fraud detection, customer service chatbots, and automated decision-making systems. For Filipino banking and fintech professionals, the STARS principles represent the first formal regulatory signal that AI in Philippine financial services will move from unregulated innovation to supervised governance. This guide breaks down what each principle means, what BSFIs must do to comply, and how Filipino professionals should prepare.
The Five STARS Principles for BSP AI Governance Explained
The STARS acronym defines five principles that must be considered at each stage of the AI system lifecycle: plan, develop, validate, deploy, and monitor. Here is what each principle requires:
| Principle | What It Means | What BSFIs Must Do |
|---|---|---|
| Sustainability | AI systems must be viable long-term, with adequate resources for maintenance, monitoring, and updates throughout their operational life. | Budget for ongoing AI maintenance, not just initial deployment. Ensure staff capacity to monitor and update AI models over time. |
| Transparency | AI decisions must be explainable to affected parties, including customers, regulators, and internal auditors. | Document how AI models make decisions. Provide customers with information when AI is used in products or services that affect them. |
| Accountability | Clear ownership and accountability for AI system outcomes, including designated roles for AI governance. | Assign a senior officer or committee responsible for AI governance. Establish escalation paths for AI-related incidents. |
| Responsibility | AI must be used ethically and in line with the institution’s values, with safeguards against bias and discrimination. | Test AI models for bias. Establish ethical guidelines for AI use cases. Prohibit AI applications that could discriminate against customers. |
| Security | AI systems must be protected against attacks, misuse, and unauthorized access, with robust cybersecurity controls. | Implement security testing for AI models. Protect training data from tampering. Monitor for adversarial attacks against AI systems. |
The lifecycle approach — plan, develop, validate, deploy, and monitor — means that BSP AI governance is not a one-time compliance exercise. Each principle must be applied continuously across the entire lifespan of an AI system, from initial planning through retirement. For context on how AI is transforming the Philippine economy more broadly, see our analysis of the P1.8 trillion AI economic opportunity.
What BSFIs Must Do Now to Comply with BSP AI Governance
Deputy Governor Javier recommended that financial institutions “formally develop their own AI Governance Framework, proportionate to the nature, extent, scale, complexity, and materiality of their AI systems, as well as the institution’s overall operational complexity and risk profile.” This means compliance is not one-size-fits-all — a major universal bank with hundreds of AI models faces different requirements than a rural bank using a single AI-powered credit scoring tool. Here is a practical step-by-step guide:
Step 1: Conduct an AI inventory. Map every AI system currently in use across the institution. This includes internally developed models, third-party vendor AI, open-source AI tools, and AI features embedded in software the institution already uses. For each system, document its purpose, data sources, decision-making role, and potential impact on customers.
Step 2: Assess risk and materiality. For each AI system in the inventory, assess its risk level based on the STARS principles. A credit scoring model that determines loan approvals carries higher risk than a chatbot that answers basic customer queries. Classify each system as low, medium, or high risk, and allocate governance resources accordingly.
Step 3: Develop an AI Governance Framework. Create a formal document that defines: the institution’s AI principles (aligned with STARS), roles and responsibilities for AI governance, risk assessment procedures, approval processes for new AI deployments, monitoring and audit requirements, and incident response protocols for AI-related failures.
Step 4: Establish a governance committee. Designate a senior officer or committee with authority over AI governance. This body should include representatives from IT security, risk management, compliance, legal, and business units. The committee must have the authority to approve, suspend, or terminate AI systems based on risk assessments.
Step 5: Implement continuous monitoring. AI models can drift over time — a model that was fair and accurate at deployment may become biased or unreliable as data patterns change. Establish monitoring procedures that track model performance, fairness metrics, and security indicators on an ongoing basis. For guidance on securing AI systems against emerging threats, see our coverage of the CSS webmail attack that targets AI email assistants.
The Shared Responsibility Model for Vendors
One of the most significant aspects of Memorandum No. M-2026-031 is its extension to outsourced service providers. The BSP AI governance framework creates a shared responsibility model that holds both the financial institution and its AI vendors accountable. This means that a bank using a third-party AI tool for fraud detection is responsible for ensuring that the vendor’s AI system complies with the STARS principles — not just the bank’s internal systems.
For Filipino fintech professionals working at AI vendors that serve Philippine banks, this creates new compliance requirements. Vendors should expect their bank clients to request AI governance documentation, model explainability reports, bias testing results, and security audit findings. Vendors that cannot provide these documents may lose contracts as BSFIs move to comply with the BSP guidance.
The shared responsibility model also extends to cloud providers, data processors, and any third party that supports AI-related activities. This is consistent with the BSP’s existing outsourcing supervision framework, which requires BSFIs to maintain accountability for outsourced functions. For a practical look at how AI transparency affects Filipino consumers, see our report on how 90% of Filipinos cannot tell AI voice from human.
How Filipino Professionals Should Prepare for BSP AI Governance
Whether you work at a bank, a fintech startup, or an AI vendor, the BSP AI governance framework creates both obligations and opportunities. Here is what Filipino professionals should do now:
For banking professionals: Ask your compliance or risk management team whether the institution has started developing its AI Governance Framework. If the process has not begun, volunteer to help with the AI inventory — this is the logical first step and positions you as a contributor to the governance process.
For fintech professionals: Review your company’s AI products against the STARS principles. Prepare documentation on model explainability, bias testing, and security measures. If your product serves Philippine banks, expect AI governance questions in your next vendor assessment.
For IT security professionals: The STARS security principle requires AI-specific security testing that goes beyond traditional application security. Familiarize yourself with AI attack vectors — adversarial inputs, model extraction, data poisoning, and prompt injection. These are distinct from traditional cybersecurity threats and require different defensive approaches.
For data professionals: The transparency and responsibility principles require robust data lineage and bias testing. Ensure that your data pipelines can trace the origin and transformation of training data, and that you have procedures for testing model outputs for discriminatory patterns.
For customer-facing professionals: The transparency principle may require institutions to inform customers when AI is used in decisions that affect them — loan approvals, credit limits, fraud flags, insurance claims. Prepare customer communication templates that explain AI involvement in clear, non-technical language.
What Comes Next for BSP AI Regulation
Memorandum No. M-2026-031 is a guidance paper, not a binding regulation. This means that BSFIs are expected to adopt the STARS principles voluntarily, with the understanding that formal regulations may follow. The BSP’s approach mirrors the phased regulatory strategy seen in other jurisdictions — guidance first, enforcement later — giving institutions time to build governance capacity before facing penalties for non-compliance.
However, the pace of AI adoption in Philippine financial services is accelerating. Major banks including BDO, BPI, Metrobank, and UnionBank have already deployed AI in credit scoring, fraud detection, and customer service. Digital banks like Maya and GoTyme are building their entire customer experience around AI. The BSP will likely move from guidance to formal regulation as AI usage deepens — and institutions that have already adopted the STARS framework will be ahead of the compliance curve.
For Filipino professionals, the opportunity is clear: AI governance is a new skill area that will be in demand as institutions move to comply with BSP expectations. Skills in AI risk assessment, model explainability, bias testing, and AI security will differentiate professionals who can navigate the regulatory landscape from those who cannot. For practical guidance on building AI skills that employers value, see our guide to digital financial security and the broader cybersecurity resources on worldngayon.com.
Frequently Asked Questions About BSP AI Governance
What is BSP AI governance?
BSP AI governance refers to the set of principles and expectations established by the Bangko Sentral ng Pilipinas through Memorandum No. M-2026-031 for how BSP-supervised financial institutions should develop, deploy, and monitor artificial intelligence systems. The framework is built on five STARS principles: sustainability, transparency, accountability, responsibility, and security.
Who must comply with the BSP AI governance memorandum?
All BSP-supervised financial institutions (BSFIs) must comply, including universal banks, commercial banks, digital banks, rural banks, e-wallet providers, and payment service providers. The memorandum also extends to outsourced service providers that support AI-related activities, creating a shared responsibility model that covers fintech vendors and third-party AI providers.
What are the five STARS principles for BSP AI governance?
The five STARS principles are: Sustainability (AI systems must be viable long-term), Transparency (AI decisions must be explainable), Accountability (clear ownership for AI outcomes), Responsibility (AI must be used ethically without bias), and Security (AI systems must be protected against attacks). Each principle must be applied across the AI lifecycle: plan, develop, validate, deploy, and monitor.
Is Memorandum No. M-2026-031 a binding regulation?
No, it is currently a guidance paper, not a binding regulation. BSFIs are expected to adopt the STARS principles voluntarily, with formal regulations likely to follow as AI adoption deepens in Philippine financial services. Institutions that adopt the framework now will be ahead when enforcement begins.
What should Filipino banking professionals do about BSP AI governance?
Filipino banking professionals should ask their compliance team whether the institution has started developing its AI Governance Framework. The logical first step is conducting an AI inventory — mapping every AI system in use, its purpose, data sources, and potential customer impact. This positions professionals as contributors to the governance process.
Does BSP AI governance apply to fintech vendors?
Yes. The memorandum creates a shared responsibility model that extends to outsourced service providers supporting AI-related activities. Vendors that serve Philippine banks should prepare AI governance documentation, model explainability reports, bias testing results, and security audit findings for their bank clients.
When did the BSP issue the AI governance memorandum?
The BSP issued Memorandum No. M-2026-031 on June 24, 2026. Deputy Governor Lyn I. Javier announced the guidance paper, which applies to all BSP-supervised financial institutions and their AI service providers.
Financial Disclaimer: This article is for informational purposes only and does not constitute legal, regulatory, or compliance advice. Financial institutions should consult the full text of BSP Memorandum No. M-2026-031 and engage qualified legal and compliance professionals for specific guidance on AI governance implementation.


