Bank of the Philippine Islands has achieved two international certifications covering information security and data privacy, reinforcing its cybersecurity and privacy management framework across several customer-facing banking services.
BPI received ISO/IEC 27001:2022 certification for its Information Security Management System and ISO/IEC 27701:2019 certification for its Privacy Information Management System. This achievement makes BPI the first universal bank in the Philippines to be certified under both standards.
COVERING CRITICAL BANKING SERVICES
The certifications were awarded by BSI Group Philippines and cover a broad range of BPI services, including online and mobile banking platform management, inward and outward remittances, transaction banking and cash management services, and contact center operations.
The scope is significant because the standards are applied across multiple customer touchpoints rather than being limited to a single platform or department.
ISO/IEC 27001:2022 focuses on structured information security management, while ISO/IEC 27701:2019 extends that framework into privacy information management. Both require ongoing risk assessments, internal controls, audits, monitoring, and operational improvements rather than a one-time compliance exercise.
SECURITY AND PRIVACY BUILT INTO OPERATIONS
“These certifications affirm that BPI has implemented internationally recognized frameworks for managing information security and data privacy across critical banking services,” said TG Limcaoco, BPI president and CEO.
“More importantly, these reflect our commitment to making security and privacy an integral part of how we operate and how we serve our customers.”
Limcaoco said the standards apply across digital banking, payments, transaction banking, and customer support operations, reflecting a broader approach to information protection across the bank.
WHAT IT MEANS FOR CUSTOMERS
For individual customers, BPI says the dual certification means stronger protection for sensitive personal and financial information, greater security for digital and cross-border transactions, and independently audited controls subject to continuous improvement.
For corporate and institutional clients, the certification signals that BPI operates under a globally aligned framework for managing information security and privacy risks.
The bank also positions the achievement as part of a longer-term effort to protect the confidentiality, integrity, and availability of customer information while strengthening accountability around data privacy.
BUILT ON MORE THAN TWO DECADES OF SECURITY WORK
BPI says its certification journey builds on more than two decades of strengthening information security and governance practices.
Since the early 2000s, the bank has progressively developed its information security policies, controls, and risk management capabilities to respond to evolving threats and support secure banking operations. These efforts later expanded into a broader data privacy program aligned with international standards and local regulatory requirements.
ALIGNING WITH LOCAL AND GLOBAL STANDARDS
As part of its broader information security and privacy strategy, BPI continues to align its practices with the Data Privacy Act of 2012, the General Data Protection Regulation, and relevant Bangko Sentral ng Pilipinas issuances, including Circulars 808 and 982.
The bank frames the dual ISO certification as more than a compliance milestone, emphasizing that information security and privacy management require shared responsibility across the organization and continuous improvement over time.