Philippines · Bangko Sentral ng Pilipinas
BSP's AI governance principles, STARS
Every principle in BSP Memorandum M-2026-031 and what it actually asks for, the five lifecycle stages, the disclosure standard people tend to overstate, and what the frontier-AI companion adds.
Covers: BSP M-2026-031 (Annex A, June 2026), BSP M-2026-034Published September 26, 2026
What M-2026-031 is
BSP Memorandum No. M-2026-031, dated 24 June 2026 and signed by Deputy Governor Lyn I. Javier of the Financial Supervision Sector, issues a guidance paper as Annex A: “Governance Principles for Artificial Intelligence (AI) in Financial Services,” dated June 2026 and running nine pages.
Its AI System definition is adapted from the OECD’s 2019 definition and ISO/IEC 22989:2022, and the paper states the definition is function-based, covering narrow AI, generative AI, and agentic AI. That matters: BSP is not creating separate regulatory tiers for different kinds of AI. The only distinction drawn in passing is that evaluation procedures for generative AI differ from those for predictive models. There is no frontier-AI category here; that lives in the companion memorandum.
Non-binding, and also minimum supervisory expectations
The status of this paper is more interesting than a summary usually makes it. Annex A says the principles “are non-binding and compliance is voluntary in nature.” The same paragraph says they “provide minimum supervisory expectations for AI adoption.” Both phrases are BSP’s. The memorandum’s operative sentence is a recommendation: it is recommended that financial institutions formally develop their own AI Governance Framework.
The STARS principles, one by one
S, Sustainability. The value created should be materially beneficial to the whole financial ecosystem. It has two limbs. The environmental limb asks institutions to minimize the carbon footprint of AI, implement energy-efficiently, consider power consumption and runtime metrics and predicted cost over time at the conceptualization stage, reduce e-waste, and use green computing. The social limb asks for human-centered AI in which human values are at the core, plus workforce development and capacity building.
T, Transparency. Information should be readily available and tailored to the knowledge and expertise of intended users, who must be able to answer how an output was derived and why a recommendation was made, so as to avoid blind reliance. Five concrete requirements follow:
- Maintain a centralized AI inventory.
- Notify users when AI output is used in the product or process, via terms and conditions or other documentation.
- Support auditability: document the design process, decision-making, error tracking and resolution, algorithm build options, and data sources.
- Define mitigation procedures for identified risks, errors, and uncertainties, and review all AI systems regularly.
- Hold outsourced service providers to the same transparency standard, through documentation or system performance reports.
A, Accountability. The paper is direct here: while AI systems provide recommendations, humans are ultimately accountable for decisions made, and the output of AI systems should not replace or diminish human responsibility. It asks for human oversight guardrails across the lifecycle, segregation of roles including oversight functions and effective challenge by the board of directors and proper execution by senior management, and escalation and remediation mechanisms. Two specifics worth noting: the head of AI development and deployment is expected to have competence in AI, data science and finance, and BSP expects to be enabled to monitor and review the algorithm.
R, Responsibility, framed as social fairness.Training data should be well-prepared, well-represented, and free from unauthorized interference, with no harmful effects on minority or vulnerable groups. It requires respect for data-subject rights with clear opt-in and opt-out mechanisms, citing RA 10173, RA 7394, and NPC Advisory 2023-01 on deceptive design patterns.
S, Security. Regular risk-based vulnerability assessment, with defenses against AI-specific threats such as adversarial attacks and data poisoning, testing and incident response extended to cover AI models, and monitoring of data quality and model performance to detect anomalies such as bias and hallucination early on.
The five AI lifecycle stages
Annex A sets controls across five stages: Plan, Develop, Validate, Deploy, Monitor. Two are worth calling out because they are the ones most often missing in practice.
- Validate: validation must be performed by a team independent from the one that developed the model, results must be reproducible, and the process must be able to challenge any decision, output, or result.
- Monitor: business continuity planning must cover AI-related disruptions, and there must be a defined regression process.
What you must actually tell customers
This is the point most worth getting right, because it is easy to overstate in both directions. The requirement is that users are notified when the AI’s output is being used in the product or is included in the process, by incorporating that information into the product’s terms and conditions or other relevant documentation, and that all relevant caveats are disclosed particularly where there is a risk of misinterpretation or misuse. Caveats are defined as the data used and collected, the system’s limitations, and the scope of interpretation.
So: a terms-and-conditions level notification standard, plus caveat disclosure. It is not a right to a per-decision explanation, and it is not an adverse-action notice regime of the kind US lending law uses. Anyone describing this memorandum as requiring banks to explain individual AI decisions to customers has gone further than the text does.
The Model Risk Management framework is still forthcoming
Annex A’s Scope section says the forthcoming Model Risk Management framework will tackle algorithmic fairness and model risks. That framework has not landed. The only MRM document BSP hosts is a June 2025 exposure draft, and it still carries a blank circular number, a blank Monetary Board resolution number, and a blank date. The draft would amend the relevant MORB and MORNBFI sections and carries a two-year transitory period.
The existing rules it sits on top of
Annex A lists fifteen pertinent existing issuances, not only circulars. Alongside RA 10173 (Data Privacy Act), RA 8293 (Intellectual Property Code), RA 7394 (Consumer Act) and RA 11765 (Financial Products and Services Consumer Protection Act), it cites eight BSP circulars, the DTI’s AI Roadmap 2.0, a draft DICT and CSC joint memorandum circular on ethical AI in government, and Project Sapiens, BSP’s own 2024 thematic review on the use of AI and ML in Philippine financial services.
- Circular 808: Guidelines on Information Technology Risk Management (2013).
- Circular 982: Enhanced Guidelines on Information Security Management (2017).
- Circular 1160: Regulations on Financial Consumer Protection, implementing RA 11765 (2022).
- Circular 1140: Fraud Management Systems and Consumer Education and Awareness (2022).
- Circular 989: Guidelines on the Conduct of Stress Testing Exercises (2018).
- Circular 971: Guidelines on Risk Governance (2017).
- Circular 900: Guidelines on Operational Risk Management (2016).
- Circular 855: Guidelines on Sound Credit Risk Management Practices (2014).
Note for anyone cross-referencing: Circular 982 is information security management, not corporate governance. Corporate governance is a different circular, and conflating the two is an easy mistake to make from the numbering alone.
M-2026-034: frontier AI as a cyber threat
The companion memorandum, dated 6 July 2026, is a cybersecurity issuance rather than an AI-ethics one. Its premise is that frontier AI systems can identify software vulnerabilities, generate exploit pathways, and execute multi-stage cyberattacks with minimal human intervention. Its six recommendations:
- Enhance attack-surface visibility, through inventories of externally reachable assets, cloud resources, identities, and dependencies.
- Strengthen foundational controls: credential hygiene, multi-factor authentication, least privilege.
- Apply micro-segmentation and zero trust, compress patch timeliness, and replace end-of-life systems.
- Reinforce authentication: adopt hardware-key MFA such as FIDO2 or WebAuthn, smart cards, or certificate-based authentication, and discontinue password and SMS or push authentication for all administrative and privileged access.
- Adopt AI-enabled defenses, including virtual patching.
- Update business continuity management and planning for AI-enabled threats.
The fourth is the sharpest and the most operationally demanding: discontinuing SMS and push authentication for privileged access is a concrete change with a real migration cost, and it is stated plainly.
How Nova AIS lines up against it
Several STARS asks are architectural rather than procedural, which is the part worth designing for rather than documenting after the fact. Nova AIS puts a permission model and an immutable audit trail under the systems built on it, so the Transparency requirement’s auditability limb, documenting decision-making, error tracking, and data sources, is answerable from the record rather than reconstructed. The Accountability principle’s insistence that humans remain ultimately accountable is the same design preference we apply generally: keep a person in the decision path for anything with legal effect.
The centralized AI inventory and the independent-validation requirement under the Validate stage are organizational obligations that no vendor can discharge for you. Worth planning for separately from any tooling decision.
Common questions.
- What is BSP Memorandum M-2026-031?
- A memorandum dated 24 June 2026, signed by Deputy Governor Lyn I. Javier of the Financial Supervision Sector, issuing a nine-page guidance paper titled “Governance Principles for Artificial Intelligence (AI) in Financial Services” as Annex A. The paper sets out five principles under the acronym STARS: Sustainability, Transparency, Accountability, Responsibility, and Security.
- Are the BSP AI governance principles mandatory?
- BSP describes them both ways in the same passage. Annex A states the principles “are non-binding and compliance is voluntary in nature,” and in the same paragraph states that they “provide minimum supervisory expectations for AI adoption.” The memorandum's operative verb is recommendation: it is recommended that financial institutions formally develop their own AI Governance Framework. In practice, treat them as supervisory expectations that a BSP examiner can reasonably ask about, rather than as rules carrying their own penalty.
- What does STARS stand for?
- Sustainability, Transparency, Accountability, Responsibility, and Security. Sustainability covers environmental cost and human-centered design. Transparency covers the AI inventory, customer disclosure, auditability, mitigation procedures, and outsourced service providers. Accountability places ultimate responsibility on humans, not the system. Responsibility covers social fairness and training data. Security covers AI-specific threats such as adversarial attacks and data poisoning.
- Does BSP require banks to explain individual AI decisions to customers?
- Not at that level. The disclosure requirement under Transparency is that users are notified when AI output is being used in the product or process, by putting that information in the product's terms and conditions or other relevant documentation, with all relevant caveats disclosed where there is a risk of misinterpretation or misuse. That is a terms-and-conditions notification standard, not a per-decision adverse-action explanation right.
- Has BSP issued its Model Risk Management circular?
- No. Annex A's own Scope section refers to “the forthcoming Model Risk Management (MRM) framework” that will tackle algorithmic fairness and model risks. The only MRM document BSP hosts is a June 2025 exposure draft, which still carries a blank circular number, a blank Monetary Board resolution number, and a blank date. Do not cite an MRM circular number, because there is not yet one to cite.
- What does M-2026-034 cover?
- A companion memorandum dated 6 July 2026 on managing emerging risks from frontier AI systems. It is a cybersecurity issuance rather than an AI-ethics one, premised on frontier AI being able to identify software vulnerabilities, generate exploit pathways, and execute multi-stage cyberattacks with minimal human intervention. Its sharpest recommendation is to adopt hardware-key MFA such as FIDO2 or WebAuthn, smart cards, or certificate-based authentication, and to discontinue password and SMS or push authentication for all administrative and privileged access.