Menu

BSP Circular No. 808 Compliance: IT Risk Management Requirement

BSP Circular No. 808 Compliance: IT Risk Management Requirement

A failed payment system, compromised customer account, or third-party technology outage can quickly become more than an IT problem for a financial institution. It can disrupt operations, expose sensitive information, affect customers, and raise questions about whether the organization had adequate controls in place. For banks and other BSP-supervised institutions in the Philippines, managing these risks requires more than responding when something goes wrong; it requires a structured approach to identifying, assessing, and controlling technology risks before they translate into business impact.

BSP Circular No. 808 establishes an important framework for managing these technology risks. But what exactly does the circular require? Who needs to comply? And how can institutions connect BSP’s Information Technology Risk Management (ITRM) expectations with internationally recognized frameworks such as ISO/IEC 27001?

This guide breaks down the BSP Circular 808 requirements, explains the major areas of IT risk management, and examines how ISO/IEC 27001 can complement a BSP-supervised institution’s broader information security program.

What Is BSP Circular No. 808?

BSP Circular No. 808, Series of 2013, is titled Guidelines on Information Technology Risk Management for All Banks and Other BSP Supervised Institutions. The circular amended the BSP's existing IT risk management framework to address the increasing use and dependence on technology within financial services. The circular states that Information Technology Risk Management (ITRM) should be integrated into an institution's overall risk management program. Rather than treating IT as a separate technical function, the framework connects technology risks with the institution's wider business and operational objectives.

The guidelines were also designed to serve as a BSP baseline requirement for BSP-supervised institutions. Their scope includes banks, non-banks with quasi-banking functions, non-bank electronic money issuers, and other non-bank institutions subject to BSP supervision or regulation. The guidelines can also apply to institutions with offshore data processing, where appropriate. This makes the circular particularly relevant as financial institutions in the Philippines increasingly rely on digital banking, electronic payments, cloud services, APIs, outsourced technology, and interconnected platforms.

Strengthen your information security with internationally recognized ISO/IEC 27001 Certification. Choose INTERCERT for independent third-party certification by experienced auditors.

What Are the Key BSP Circular 808 Requirements?

The BSP Circular 808 requirements establish a structured approach to managing technology-related risks across BSP-supervised institutions. Rather than treating IT risk as a purely technical concern, the framework connects technology governance, risk assessment, controls, security, auditing, operations, and third-party relationships with the institution’s broader risk management program.

IT Governance

Strong IT governance provides the foundation for effective technology risk management. Institutions are expected to establish appropriate organizational structures, policies, procedures, standards, and lines of accountability for managing IT risks. This includes clear oversight from senior management and the board, ensuring that technology decisions and risks remain aligned with business objectives. IT risk management should therefore be treated as an organizational responsibility rather than an issue delegated solely to the IT department.

Risk Identification and Assessment

A central element of BSP Circular 808 IT risk management is the ability to identify and assess the risks arising from an institution’s use of technology. This requires consideration of the systems and information supporting critical business functions, potential technology failures, security threats, and dependencies on external providers. Risk assessments should reflect the institution’s actual technology environment and business activities, allowing management to determine which risks could have the greatest operational, financial, security, or customer impact.

IT Controls

Risk identification needs to be followed by appropriate controls that address the risks identified. The BSP Circular 808 compliance requirements cover control areas including information security, systems development and change management, IT operations, electronic banking and electronic payment services, and IT outsourcing and vendor management. These controls should be appropriately designed, implemented, and periodically evaluated to determine whether they remain effective as systems, processes, and risks change.

Risk Measurement and Monitoring

Technology risks can change as institutions introduce new systems, modify existing infrastructure, adopt new digital services, or become more dependent on external technology providers. Circular 808 therefore incorporates risk measurement and monitoring into the broader ITRM framework. Institutions need processes for tracking identified risks, evaluating their significance, monitoring changes, and taking appropriate action when risk levels or control effectiveness change. This creates a more continuous approach to technology risk management rather than relying solely on periodic reviews or incident-driven responses. Therefore, BSP Circular 808 compliance is an ongoing risk management responsibility, not a one-time IT exercise.

What Does BSP Circular 808 Cover Beyond Cybersecurity?

One common mistake is to interpret Circular 808 entirely through a cybersecurity lens. Cybersecurity is important, but the framework covers a broader technology risk landscape. The BSP Manual of Regulations identifies separate areas for IT audit, information security, project management/development, acquisition and change management, IT operations, and IT outsourcing/vendor management. For example, a financial institution could have strong network security but still face significant risk from:

  • An inadequately controlled system change

  • Poorly managed privileged access

  • A technology vendor with inadequate security controls

  • Insufficient backup or recovery capabilities

  • Weak oversight of a critical application

  • Inadequate testing before a new system goes live

This broader perspective is one reason BSP Circular 808 compliance requirements need to be approached as an integrated IT risk management program.

How Does ISO 27001 Fit Into BSP Circular 808 Compliance?

ISO/IEC 27001 can complement BSP Circular No. 808 compliance by giving institutions a structured management-system approach to information security. While BSP’s Information Technology Risk Management (ITRM) framework addresses the broader management of technology risks, ISO/IEC 27001 focuses specifically on establishing and continually improving an Information Security Management System (ISMS). The connection becomes clearer when the two are viewed through their common risk-based principles:

  • Risk identification and assessment: BSP ITRM requires institutions to identify and assess technology risks. ISO/IEC 27001 similarly requires organizations to establish a systematic approach to information security risk assessment and treatment.

  • Governance and accountability: BSP places responsibility for IT risk management within the institution’s governance structure. ISO/IEC 27001 establishes defined roles, responsibilities, leadership involvement, and oversight for the ISMS.

  • Information security controls: BSP Circular 808 covers information security as part of its wider technology risk framework. ISO/IEC 27001 provides a structured approach to selecting, implementing, managing, and reviewing information security controls based on identified risks.

  • Risk monitoring and improvement: Both approaches place importance on ongoing monitoring rather than treating risk management as a one-time exercise. ISO/IEC 27001 specifically incorporates performance evaluation, corrective action, and continual improvement.

  • Third-party risk: BSP requirements address risks associated with IT outsourcing and technology service providers. ISO/IEC 27001 also addresses supplier relationships and the protection of information within third-party arrangements.

  • Control management: An ISO 27001-based ISMS can provide a consistent process for linking identified information security risks with appropriate controls, monitoring their effectiveness, and reviewing them as risks change.

It is important not to treat ISO 27001 certification as equivalent to BSP Circular 808 compliance. The two have different purposes. BSP requirements are regulatory obligations for BSP-supervised institutions in the Philippines, covering technology risk management across areas such as governance, information security, IT operations, project management, IT audit, and outsourcing. ISO/IEC 27001, on the other hand, is an international standard for establishing and managing an ISMS. For a bank or other BSP-supervised institution, an ISO 27001-based ISMS can therefore serve as one component of a broader IT risk management program, rather than a substitute for meeting BSP requirements.

The practical value is in the overlap. Institutions that already have mature ISO 27001 processes may have established practices for risk assessment, control management, monitoring, review, and continual improvement that can complement their BSP Circular 808 IT risk management activities. This can create a more consistent approach to managing information security risks while keeping regulatory requirements and ISO 27001 objectives clearly distinguished.

Where BSP Circular 808 Compliance Gets Challenging

Meeting BSP Circular 808 compliance requirements is not simply about having the right policies in place. For banks and other BSP-supervised institutions in the Philippines, the more difficult task is maintaining a technology risk management approach that remains effective as systems, services, vendors, and business priorities evolve.

IT risk cannot remain an IT-only responsibility

Technology risks can extend well beyond the IT department, affecting customer services, operational continuity, financial performance, reputation, and regulatory obligations. Effective Information Technology Risk Management (ITRM) therefore requires clear accountability across management and appropriate oversight at the board level.

Policies do not demonstrate effectiveness on their own

An institution may have extensive policies, procedures, and control documentation, yet still face weaknesses if those controls are not consistently applied or monitored. The focus should be on whether controls operate as intended, whether exceptions are identified, and whether issues lead to appropriate corrective action.

Third-party dependencies can create additional risk

Outsourcing a technology function does not transfer the institution’s responsibility for managing the associated risks. Cloud providers, technology service providers, software vendors, and other third parties can introduce security, availability, operational, and data-related risks that need to be assessed and monitored within the institution’s broader risk management framework.

Risk assessments need to influence control decisions

Identifying technology risks is only one part of the process. The results should inform control priorities, monitoring activities, resource allocation, and management decisions. When risk assessments and controls operate as separate exercises, institutions can struggle to determine whether their most significant technology risks are being addressed effectively.

Compliance cannot be treated as a point-in-time exercise

A technology environment can change significantly between assessments. New applications, cloud services, system modifications, vendors, integrations, and emerging threats can alter the institution’s risk profile. Maintaining compliance therefore requires ongoing risk monitoring and periodic review rather than relying solely on a completed assessment or audit.

Taken together, these challenges show why BSP Circular 808 IT risk management is better viewed as an ongoing governance discipline than a checklist. The objective is not simply to demonstrate that controls exist, but to maintain a risk management process that can adapt as the institution’s technology environment changes.

Demonstrate your commitment to information security with ISO/IEC 27001 Certification. Partner with INTERCERT for an impartial certification process aligned with international standards.

Why BSP Circular 808 Compliance Matters?

Mature BSP Circular No. 808 compliance is ultimately about more than passing a regulatory review. It provides a structured way for financial institutions in the Philippines to understand how technology affects business risk and whether appropriate mechanisms exist to manage that exposure. For banks and other BSP-supervised institutions, this can translate into stronger technology governance, clearer accountability, better visibility into information security risks, more disciplined vendor oversight, and greater operational resilience.

ISO/IEC 27001 can complement this effort by providing an internationally recognized ISMS framework built around risk management and continual improvement. The most effective approach is therefore not to treat BSP requirements and ISO 27001 as competing frameworks. Instead, organizations can map relevant requirements and controls, identify overlaps, address gaps, and maintain evidence that demonstrates how their information security and technology risk processes operate.

Connecting Regulatory Compliance with Information Security

Technology risk rarely stays confined to the technology function. A system failure can become an operational disruption, a vendor issue can become a security concern, and a control weakness can quickly become a regulatory matter. That is why BSP Circular No. 808 compliance is better viewed as an ongoing approach to understanding, managing, and monitoring technology risk rather than simply preparing for the next regulatory review.

For BSP-supervised institutions in the Philippines, the stronger approach is to connect governance, risk assessment, information security, IT controls, monitoring, and third-party oversight within a broader risk management program. ISO/IEC 27001 can add another layer of structure by establishing a risk-based ISMS with defined responsibilities, control management, performance evaluation, and continual improvement. It does not replace BSP requirements, but it can complement the institution’s wider IT risk management objectives.

For organizations pursuing ISO/IEC 27001 certification, INTERCERT provides independent third-party certification services backed by experienced auditors and an impartial, transparent certification process. This gives organizations an internationally recognized way to demonstrate that their ISMS has been independently evaluated against the ISO/IEC 27001 standard.

 

Frequently Asked Questions

How Can We Help You?

We are here to answer all your questions.


©2026 Intercert. All Rights Reserved