BSP AI Governance Guidelines 2026: What Philippine Banks Need to Do Now

The BSP has defined a clear set of principles for responsible AI in financial services. The real challenge for Philippine banks is turning those principles into a continuous, evidence-driven operating model that can govern AI from assessment and authorization through ongoing monitoring.

BSP AI Governance Guidelines 2026: What Philippine Banks Need to Do Now

The BSP has defined the principles. The harder question is how banks turn them into an operating discipline.

AI is moving rapidly into the core of financial services.

It is being used for fraud detection, credit assessment, customer service, document processing, risk analysis, software development, and increasingly autonomous workflows.

But there is a problem.

Many organizations still govern AI as if it were simply another technology project.

It isn't.

An AI system can influence whether a customer receives a financial product, expose sensitive information, produce unfair outcomes, generate unreliable recommendations, or create operational risk long after the original development team has moved on.

That is why the Bangko Sentral ng Pilipinas (BSP) Governance Principles for Artificial Intelligence (AI) in Financial Services, issued in June 2026, is an important development.

The guidance is principles-based and voluntary, but its direction is clear: financial institutions should develop their own AI governance frameworks, proportionate to the nature, scale, complexity and materiality of their AI systems, and operationalize those principles across the AI lifecycle.

For banks, the question is therefore changing.

It is no longer simply:

Do we have an AI policy?

The more important question is:

Can we demonstrate that every material AI system is understood, governed, controlled and continuously monitored?

The BSP has moved the conversation beyond AI policy

The BSP organizes its principles around STARS:

  • S — Sustainability
  • T — Transparency
  • A — Accountability
  • R — Responsibility
  • S — Security

These principles cover much more than traditional model governance.

Transparency includes maintaining a centralized AI inventory, documenting decisions and ensuring auditability.

Accountability requires clear ownership, human oversight and escalation mechanisms.

Responsibility addresses fairness, data rights and potential harm.

Security extends beyond conventional cybersecurity to AI-specific threats, data quality, bias and hallucination.

Most importantly, these principles are intended to operate across the AI system lifecycle.

The BSP defines that lifecycle as:

PLAN → DEVELOP → VALIDATE → DEPLOY → MONITOR.

That is the important shift.

AI governance is not a document. It is an operating process.


The real challenge is operationalization

The principles themselves are not particularly difficult to understand.

The harder problem is putting them into practice across a growing AI portfolio.

Imagine a bank with dozens or hundreds of AI systems across business units.

One team maintains the model inventory.

Another manages policies.

Risk conducts assessments.

Developers run evaluations.

Compliance maps regulatory requirements.

Technology teams monitor production systems.

Internal audit asks for evidence.

Each function may be doing its job.

But are those activities connected?

For a specific AI system, can the bank answer:

  • What exactly is this system?
  • What is it being used for?
  • Who owns it?
  • What risks does it introduce?
  • Which controls are required?
  • Are those controls actually operating?
  • What evidence supports that conclusion?
  • Who validated the system?
  • Who authorized it for production?
  • What has changed since the last assessment?
  • Is the previous assurance still valid?

This is where AI governance becomes difficult.

The problem is often not the absence of controls.

It is the absence of a connected operating model.


A different way to think about AI governance

Our experience building AI governance systems has led us to a simple principle:

Every AI system should have a continuously maintained assurance state.

Instead of treating inventory, risk, controls, testing, evidence, compliance and monitoring as separate activities, we connect them through a repeatable flow:

KNOW → ASSESS → GOVERN → PROVE → ASSURE → AUTHORIZE → MONITOR

We call this AssuranceFlow.

The idea is straightforward:

Know the AI. Assess its readiness. Govern the risk. Prove the controls. Establish assurance. Make the decision. Keep assurance current.

This is not intended to replace the BSP principles.

It is a practical way of operationalizing them.


1. KNOW — What AI do we actually have?

You cannot govern what you cannot see.

The first step is establishing an authoritative record of every material AI system.

The BSP specifically calls for maintaining and updating a centralized AI inventory as part of transparency.

But an inventory should be more than a spreadsheet containing model names.

For each AI system, an organization should understand:

  • Purpose and intended use
  • Business and technical ownership
  • AI type and capabilities
  • Models, agents and datasets
  • Users and affected populations
  • Deployment environment
  • Decision-making context
  • Materiality and risk
  • Current lifecycle status

This creates the foundation for everything that follows.


2. ASSESS — Is the AI appropriate for its intended use?

The next question is not simply:

Does the model work?

It is:

Is this AI system appropriate for the context in which it will be used?

That requires looking at:

Purpose → Capability → Impact → Risk → Governance Requirements

A customer-service assistant and an AI system influencing credit decisions may both use AI, but they should not be governed identically.

The level of governance should reflect potential impact.

This aligns directly with the BSP's principle that governance and risk management should be proportionate to the nature, extent, scale, complexity and materiality of AI systems.

Assessment establishes the baseline.

But assessment alone is not assurance.


3. GOVERN — What should be true?

Once the risks are understood, governance needs to become concrete.

What controls are required?

Who owns them?

What human oversight is needed?

What policies apply?

What guardrails should exist?

What approvals are required?

This is where many governance programs stop.

They define what should happen.

But assurance requires the next question:

Can we demonstrate that it is actually happening?

4. PROVE — Can we demonstrate it?

This is one of the most important distinctions in AI governance.

A bank can say:

"Human oversight is in place."

But what evidence demonstrates it?

A policy can say:

"The model is tested for bias."

Where are the results?

A team can say:

"The AI is continuously monitored."

What is being monitored? How frequently? What happens when something goes wrong?

PROVE connects governance requirements to evidence.

Evidence may include:

  • Evaluation results
  • Runtime telemetry
  • Test results
  • Policies and procedures
  • Approvals
  • Data governance records
  • Human oversight records
  • Monitoring data
  • Incident records

The principle is simple:

Governance establishes what should be true. Evidence demonstrates what is true.

This is consistent with the BSP's emphasis on documentation, auditability, testing and monitoring throughout the AI lifecycle.


5. ASSURE — Can we rely on the evidence?

Evidence alone is not assurance.

A collection of documents, test results and performance scores does not automatically tell an organization whether an AI system is acceptable.

Assurance requires evaluating:

  • Control effectiveness
  • Evidence sufficiency
  • Evidence freshness
  • Residual risk
  • Compliance requirements
  • Outstanding issues

This creates an important distinction between performance and assurance.

An AI system can have excellent accuracy while still having an ineffective privacy control.

A generative AI system can produce impressive responses while lacking sufficient human oversight.

A model can perform well in testing while lacking sufficient evidence for its intended production context.

Therefore:

A strong performance score does not override an ineffective mandatory control.

This distinction is critical when AI systems move from experimentation into production.


6. AUTHORIZE — What decision should the organization make?

Assurance should ultimately support a decision.

Depending on the institution's risk appetite and governance policies, an AI system may be:

READY

The required assurance conditions are satisfied.

READY WITH CONDITIONS

The system can proceed subject to defined and documented conditions.

NOT READY

Required controls, evidence or assurance conditions are not satisfied.

The technology should support the decision, but the organization remains accountable for it.

That is consistent with the BSP's emphasis on human responsibility and accountability for AI-related decisions.


7. MONITOR — Is the assurance still valid?

This is where the traditional "AI approval" mindset breaks down.

AI systems change.

Models change.

Datasets change.

Prompts change.

Agents change.

Vendors change.

Integrations change.

Use cases change.

Regulatory expectations change.

A system that was appropriately assessed and authorized six months ago may no longer have the same risk or assurance profile today.

The BSP guidance explicitly calls for ongoing monitoring, updated business continuity planning and processes for addressing system irregularities.

This is why we think of assurance as a state, not a certificate.


The real value is the connection

The individual components of AI governance are not new.

Banks already have:

  • Risk assessments
  • Policies
  • Model validation
  • Security controls
  • Compliance reviews
  • Testing
  • Monitoring
  • Internal audit
  • Vendor governance

The harder problem is connecting them.

For every material AI system, there should be a traceable chain:

AI System → Risk → Control → Evaluation → Evidence → Assurance → Decision

If a system is classified as high risk, we should be able to explain why.

If a control is considered effective, we should be able to show the evidence.

If an AI system is not ready for production, we should be able to identify which requirement failed.

If the system changes, we should know whether reassessment is required.

This is the difference between having AI governance activities and operating an AI governance system.


What Philippine banks should do now

The BSP does not require every financial institution to build the same governance architecture.

But there is a practical sequence.

1. Build the AI inventory

Know where AI exists across the organization, including AI services provided by third parties.

2. Establish ownership

Every material AI system should have clearly defined business, technology and governance accountability.

3. Assess materiality and risk

Not every AI system requires the same level of scrutiny.

4. Map risks to controls

Translate governance principles into controls that can actually be implemented and monitored.

5. Define evidence requirements

For important controls, determine what evidence will demonstrate effectiveness.

6. Establish authorization gates

Production decisions should be based on defined assurance criteria rather than informal approval.

7. Continuously monitor

Track performance, controls, evidence freshness, incidents and material changes.

8. Make reassessment change-driven

A material change to a model, dataset, agent, architecture, vendor or use case should trigger the appropriate governance response.


From compliance to continuous assurance

Perhaps the most important implication of the BSP guidance is the shift from AI compliance to AI accountability.

The future of AI governance will not be defined by how many policies an organization has.

It will be defined by whether the organization can demonstrate control over the AI systems it operates.

A mature financial institution should eventually be able to answer, at any point:

What AI do we have?
What is it allowed to do?
What could go wrong?
What controls are required?
Are those controls working?
What evidence proves that?
Who is accountable?
Is the system currently authorized?
What has changed since the last assessment?

These questions move AI governance from documentation into operational discipline.

And that, ultimately, is what makes the BSP guidance significant.

It gives Philippine financial institutions a principles-based foundation for responsible AI.

The next challenge is building the operating machinery around those principles.

AI governance should not be a point-in-time approval. It should be a continuously maintained state of knowledge, control, evidence and accountability.

The banks that build that discipline early will be better positioned to do something equally important: move faster with AI without losing control of the risks that come with it.