Anti-Financial Account Scamming Act (AFASA) – Republic Act No. 12010

Inquire now

Duration 2 days – 14 hrs

 

Overview 

 

Republic Act No. 12010 (AFASA) strengthens the Philippines’ legal and operational response to financial account scamming, including money muling and social engineering schemes. It also sets expectations on institutional controls (e.g., MFA/Fraud Management System), temporary holding of disputed funds, and coordinated verification among institutions and account owners. 

 

Objectives 

 

  • Explain AFASA scope, key definitions, and the acts penalized (money muling, social engineering, related offenses). 
  • Interpret institutional duties to protect access to financial accounts using proportionate controls (e.g., MFA, Fraud Management System). 
  • Apply AFASA rules on temporary holding of funds in disputed transactions (up to the BSP-prescribed period not exceeding 30 calendar days, unless extended by court). 
  • Implement a practical workflow for coordinated verification (inter-institution + account owner), including understanding when bank secrecy/data privacy constraints do not apply during the process. 
  • Recognize penalties and risk exposures for individuals and organizations, and translate them into internal controls, SOPs, and staff playbooks. 
  • Align internal procedures with BSP information-sharing/inquiry mechanisms (high-level awareness) and governance requirements. 

 

Audience  

  • Compliance / Regulatory Affairs
  • Fraud Risk / Financial Crime / AML teams
  • Operations & Disputes / Chargebacks / Investigations
  • Customer Service / Contact Center leadership
  • Digital Channels / Product Owners
  • Information Security / Cybersecurity / IT Risk
  • Legal / Corporate Counsel
  • Branch / Field Operations (for customer escalations and reporting)

 

Pre- requisites   

  • Basic familiarity with digital banking/e-wallet flows (login, transfers, cash-in/out, card funding, etc.)
  • Working knowledge of KYC/identity verification and basic fraud concepts (phishing/social engineering)
  • For deeper implementation sessions: familiarity with your org’s dispute handling and fraud tooling (e.g., case management, FMS rules)

 

Course Outline 

 

Module 1 — Scam Landscape and Why AFASA Exists 

 

  • Common scam patterns in PH digital finance (money mules, account takeovers, phishing/vishing, fake “bank” calls)
  • Where scams break controls: onboarding, credentialing, recovery flows, payouts

 

Module 2 — AFASA 12010: Scope, Definitions, and Who is Covered 

 

  • Key terms (financial account, sensitive identifying information, institutions)
  • What counts as “financial account scamming” under AFASA Lawphil

 

Module 3 — Prohibited Acts and Offenses 

 

  • Money Muling Activities (using/allowing use of accounts; buying/renting/selling/lending accounts; recruitment) Lawphil
  • Social Engineering Schemes (misrepresentation + solicitation of sensitive info; use of electronic communications to obtain sensitive info leading to unauthorized access/control) Lawphil+1
  • “Other offenses” (aiding/abetting, attempts, fictitious accounts, buying/selling accounts) Lawphil
  • Economic sabotage conditions (overview) Lawphil

 

Module 4 — Penalties and Legal Consequences 

 

  • Penalties for money muling, social engineering, economic sabotage, and other offenses Lawphil
  • Account closure/forfeiture implications (high-level awareness) Lawphil+1

 

Module 5 — Institutional Responsibilities: Controls You’re Expected to Have 

 

  • Duty to protect access with adequate risk management systems and controls (e.g., MFA, Fraud Management System, enrollment/verification processes) Lawphil
  • What “proportionate and commensurate” controls mean in practice (tiering by risk/product/channel)
  • Translating AFASA to control mapping: people/process/tech + governance

 

Module 6 — Disputed Transactions: Temporary Hold + Coordinated Verification 

 

  • Temporary holding of funds: triggers, timelines, notifications, and constraints (incl. BSP-prescribed period not exceeding 30 days, unless extended by court) Lawphil+1
  • What counts as “disputed” and reasonable grounds (operational interpretation) Lawphil
  • Coordinated verification process: required collaboration and what it means operationally Lawphil
  • Bank secrecy/data privacy inapplicability during coordinated verification (what to document, how to protect data anyway) Lawphil
  • Malicious reporting awareness (why controls should prevent abuse) Lawphil

 

Module 7 — Enforcement, Inquiry, and Information Sharing 

 

  • High-level overview of BSP inquiry/information-sharing mechanics and confidentiality boundaries Lawphil+1
  • Awareness of CAPO and information-sharing agreements/process expectations (roles, request essentials) Bureau of the Treasury

 

Module 8 — Practical Workshop: Build Your AFASA Playbook 

 

Deliverables produced during the workshop:

  • AFASA-aligned Disputed Transaction Handling Flow (detect → hold → verify → release/return → report)
  • Escalation + comms templates (customer advisory script, internal escalation triggers)
  • Control checklist for MFA, account recovery, enrollment, payout friction, mule detection
  • Action plan: 30/60/90-day remediation roadmap (quick wins + backlog items).

Inquire now

Best selling courses

CLOUD COMPUTING

Terraform

Terraform is a configuration orchestration tool for building and managing infrastructure on cloud & data centers. The course is instructor-led, live training (onsite or remote), and is designed for Engineers with little or no previous experience managing infrastructure. The course talks about in-depth Terraform syntax and techniques used to automate the setup and deployment of infrastructure.

Duration  3 days – 21 hrs    Overview    The ITIL Leadership – Digital and IT Strategy training course is designed for senior IT professionals, managers, and leaders who seek to navigate the complex landscape of digital transformation and IT strategy. This course focuses on providing strategic insights, leadership skills, and practical approaches for aligning...

PROGRAMMING / CODING

Spring Architecture and Design

Spring Cloud is a platform for building Java-based distributed systems and microservices. Building complex enterprise applications is challenging. Any change made to a part of the systems could trigger the need for changing the design of the entire system. By the end of this training, participants will have a solid understanding of Service-Oriented Architecture (SOA) and Microservice Architecture as well practical experience using Spring Cloud and related Spring technologies for rapidly developing their own cloud-scale, cloud-ready microservices.

BUSINESS INTELLIGENCE

Dax

Duration 5 days – 35 hrs   Overview The DAX (Data Analysis Expressions) Training Course is designed to provide participants with a comprehensive understanding of DAX, the powerful formula language used in Power BI, Excel, and SQL Server Analysis Services. This course covers the essential concepts, functions, and techniques required to create advanced calculations and...

OPERATING SYSTEMS

Linux Fundamentals

Linux Fundamental provides students a thorough introduction to Linux™ for those who are new to the Linux environment. Delegates will learn how to manage files and directories, utilize the vi editor, work with Linux security mechanisms to protect files and programs, work with the Linux shell to control the flow and processing of data through pipelines, design and write shell programs of moderate complexity, and manage multiple concurrent processes in order to achieve higher utilization of Linux. They will learn how to perform basic operations on the system and how quickly to solve problem.

PROGRAMMING / CODING

Google Apps Script

The Google Apps Script training course give you a detailed knowledge on coding like Automating data calculation, Fetching and sending data from third party software like Trello & Salesforce, connecting different sheets, Documents and other tools, Setting a trigger based on an event. This course is ideal for someone who use google sheets and have no coding background.

This workshop teaches the participants how to design and develop server side applications using the event-driven, non-blocking model framework Node.js. This program inducts the participant in some of the advanced concepts of the JavaScript language so that the participant is well equipped to build end-to-end application using JavaScript.

Duration: 3 days – 21 hrs   Overview This training course is designed to provide participants with a comprehensive understanding of Portfolio Management and Contract Management, focusing on best practices, tools, and techniques. The course covers the strategic alignment of projects within a portfolio, effective management of contracts, risk management, and optimization of resources to...

// BG EARTH WHEN NOT PLAYING

We use cookies on our website to personalize your experience by storing your preferences and recognizing repeat visits. By clicking “Accept”, you agree to the use of all cookies. You can also select “Cookie Settings” to adjust your preferences and provide more specific consent. Cookie Policy