BSP's AI Governance Principles Now Cover Your Vendor's Model
Key takeaways: BSP Memorandum No. M-2026-031, dated 24 June 2026, issues Governance Principles for Artificial Intelligence in Financial Services — five principles the BSP groups as STARS: Sustainability, Transparency, Accountability, Responsibility, Security. They are voluntary and non-binding, and the BSP describes them as its minimum supervisory expectations for AI adoption. They apply to all BSP-supervised financial institutions, proportionate to the scale, complexity and materiality of each institution's AI systems. They also reach third-party providers under a shared-responsibility model: where an AI system supporting the bank's decisions was built and run by someone else, the supervised institution remains accountable for managing the risks attached to it.
Most Philippine banks running an AI or statistical component anywhere in credit assessment did not build that component themselves. It arrived inside a core banking module, a scoring service, or a vendor platform bought precisely so the bank would not have to build it. BSP Memorandum No. M-2026-031 speaks to that arrangement directly, and it is the part of the memorandum most likely to land on a credit risk team's desk first.
What does BSP Memorandum M-2026-031 actually say?
Dated 24 June 2026, the memorandum sets out Governance Principles for Artificial Intelligence in Financial Services. The BSP groups five principles under the acronym STARS — Sustainability, Transparency, Accountability, Responsibility, and Security — and frames them as guidance for institutions building their own AI governance and risk management frameworks rather than as a prescriptive rulebook.
Three features of the memorandum shape how it will be felt in practice.
It applies to all BSP-supervised financial institutions. There is no asset-size carve-out and no exemption for institutions that only consume AI rather than develop it.
It is proportionate. The BSP expects implementation to track the scale, complexity and materiality of an institution's AI systems, as well as the institution's own operational complexity and risk profile. A thrift bank running one vendor scoring model is not being asked to stand up the same governance apparatus as a universal bank running twenty across lending, collections, and fraud.
It is voluntary and non-binding, and the BSP has simultaneously described the principles as its minimum supervisory expectations for AI adoption. Both statements sit in the same guidance. For planning purposes, the second one is the operative one.
Why does "voluntary" not settle the question?
Supervisory expectations tend to show up in an examination conversation well before they show up in a binding circular. A principle the BSP has published, named, and described as its minimum expectation is a reasonable thing for an examiner to ask about — not as a finding, but as a question about how the institution thought about it.
That is a low bar and a specific one. It does not require a bank to have solved AI governance. It requires the bank to be able to describe, in its own words, which AI or model-assisted components touch a credit decision, who owns each one, and what happens when one of them produces an output the credit committee disagrees with.
For a lot of institutions that inventory does not exist in one place yet. The model sits with IT or with the vendor. The credit policy sits with credit. The outsourcing contract sits with legal or procurement. The memorandum's practical effect is to make someone assemble all three into a single answer.
What does the shared-responsibility provision mean for a model you bought?
This is the provision with the sharpest operational edge. The guidance covers third-party service providers supporting AI-related activities under a shared-responsibility model, and it holds the supervised institution accountable for managing the risks linked to those outsourced systems.
Read plainly: buying the model does not move the accountability with it.
That matters because the standard commercial arrangement pushes in the opposite direction. A vendor supplies a score, a flag, or a ranked queue. The contract covers uptime, support, and data handling. It rarely covers whether the bank can reconstruct, on demand, why a particular borrower was flagged — which inputs moved, which thresholds were crossed, what the model was trained to optimise for.
Under a shared-responsibility framing, that gap is the bank's to close, not the vendor's to leave open. Practically, three questions decide whether an institution is on solid ground:
- Can the bank obtain, from the provider, a description of what the model uses as inputs and how its outputs are meant to be interpreted?
- Can the bank reproduce the reasoning behind a specific decision after the fact, rather than only the aggregate accuracy statistics from the vendor's validation deck?
- Does the contract oblige the provider to support the bank when a supervisor, a credit committee, or a borrower asks a specific question about a specific case?
If the honest answer to any of those is no, the exposure sits with the institution, not the supplier. That is worth a conversation before it is worth a project.
Which of the five principles will credit teams feel first?
Transparency and Accountability, on the evidence of how credit processes are actually built.
The memorandum names them as principles. It does not prescribe a technique for meeting them, and it does not define a required standard of model explainability — that reading would be an overstatement of what the guidance contains. What it does is put both words in front of institutions that, in many cases, have adopted a model on the strength of accuracy and speed without settling who answers for a specific output.
Credit teams already know the shape of this problem from a different direction. Manual borrower spreading under the existing credit risk management expectations — BSP Circulars 855 and 439 — has always been constrained less by whether analysis happens than by how often and how consistently it happens across a portfolio. Annual review cycles, uneven analyst judgment, and a queue that grows faster than the team are familiar constraints.
An AI or statistical layer is usually bought to relieve exactly those constraints, and it often does. The trade is that judgment which used to live in an analyst's write-up now lives in a system's output. Where the write-up could be reread, the output has to be reconstructed. Transparency and Accountability are the two principles that ask whether the institution can still do the reconstructing.
The distinction that matters here is between a model's accuracy and a model's auditability. They are measured differently and they fail differently. Accuracy is established once, in validation, against historical data. Auditability is exercised repeatedly, case by case, usually under time pressure and usually because somebody has already disagreed with the result.
How does proportionality change the answer for a smaller bank?
Proportionality is the part most likely to be misread as an exemption, and it is not one.
A thrift bank or rural bank running a single vendor-supplied scoring component has a smaller governance obligation than a universal bank running a portfolio of models. Smaller is not zero. The proportionate version of this work is short: name the AI-assisted components that touch a credit decision, name an owner for each, record what the institution can and cannot reconstruct about each one, and note where a provider's cooperation would be needed to close a gap.
That document fits on a few pages. It is also the document an examiner is most likely to ask for, and the one that is most awkward to assemble under time pressure — because the information lives in three departments and one external contract.
For institutions where SME and commercial lending is the growth line, this work has a second use beyond supervision. The same inventory that answers a supervisory question also shows the credit committee where its own monitoring is thin: which exposures are reviewed continuously, which are reviewed annually, and which are reviewed when something has already gone wrong.
A short checklist against the five principles
The memorandum does not publish a compliance checklist, and this is not one. It is a working translation of the five named principles into questions a Philippine credit risk team can answer with what it already has on file.
| STARS principle | A question a credit team can answer this quarter | |---|---| | Sustainability | Which AI-assisted components in the credit process are we committed to for the next three years, and what happens to the process if a provider withdraws one? | | Transparency | For a specific flagged borrower, can we describe which inputs drove the result, in language a credit committee understands? | | Accountability | Who inside the bank owns each model-assisted step — by name, not by department? | | Responsibility | Where a model's output conflicts with an analyst's judgment, what is the documented override path, and how often has it been used? | | Security | What borrower data leaves the institution to reach a third-party model, under what contractual terms, and who reviewed those terms most recently? |
None of these require a model rebuild. They require someone to write down answers the institution mostly already has, scattered.
Where this sits in the 2026 supervisory arc
M-2026-031 is not an isolated document. It follows a run of 2026 issuances that have steadily raised what a supervised institution is expected to see, continuously, about credit exposure — rather than what it is expected to file, periodically.
The direction is consistent. Supervisory attention keeps moving from the existence of a process toward the institution's ability to demonstrate the process at the level of an individual decision. An AI component that improves speed and consistency serves that direction. An AI component nobody inside the bank can explain works against it, however well it validated.
The institutions that will find this straightforward are the ones that treat the inventory as a governance artefact they maintain, rather than a document they produce when asked. That is a modest amount of work done early, instead of a difficult amount done late.
Every provision described above is sourced to BSP Memorandum No. M-2026-031 (dated 24 June 2026, Governance Principles for Artificial Intelligence in Financial Services) and to existing BSP Circulars 855 and 439 on credit risk management. No figures in this article are estimated or assumed, and no requirement is attributed to the memorandum that it does not contain. Last updated 29 July 2026.

