BPI sets benchmark among Philippine universal banks with dual ISO certification

The Bank of the Philippine Islands (BPI) has reached a major milestone in its cybersecurity and privacy journey, reinforcing its commitment to safeguarding customer information and strengthening trust in an increasingly digital world.

[L-R] British Embassy’s Deputy Country Director Rachel Gancia; BSI Group Philippines Inc’s Managing Director Ava Taniajura; BPI’s President and CEO TG Limcaoco; British Embassy’s Country Director for Trade and Investment, Harry Rawicz-Szczerbo; BPI’s Chief Risk Officer Ma. Cristina Asis; Enterprise Information Security Officer & Head, Jonathan John Paz; and Data Privacy Officer Mody Villamor.

BPI achieved ISO/IEC 27001:2022 certification, the world's leading standard for Information Security Management Systems (ISMS), and ISO/IEC 27701:2019 certification for its Privacy Information Management System (PIMS). With these certifications, BPI becomes the first universal bank in the Philippines to achieve certification for both ISO/IEC 27001 and ISO/IEC 27701.

Awarded by The British Standards Institution (BSI) Group Philippines Inc., the certifications cover one of the broadest scopes in the local banking industry, including online and mobile banking platform management, inward and outward remittances, transaction banking-cash management services, and contact center operations. 

Beyond a one-time audit, ISO/IEC 27001:2022 and ISO/IEC 27701:2019 require organizations to maintain disciplined and continuously evolving approaches to information security and privacy management through regular risk assessments, internal controls, audits, monitoring, and operational improvements.

These certifications affirm that BPI has implemented internationally recognized frameworks for managing information security and data privacy across critical banking services. More importantly, these reflect our commitment to making security and privacy an integral part of how we operate and how we serve our customers,” said TG Limcaoco, BPI President and CEO.

“What is particularly meaningful about this achievement is that these standards are not confined to a single system, channel, or function. They are applied across critical parts of how we serve our customers – from digital banking and payments to transaction banking and our customer support operations. This breadth reflects the scale of our commitment: that wherever and however our customers interact with BPI, we are working to make their banking experience secure, resilient, and worthy of their trust,” he added.

By securing certification across these customer-facing services, BPI reinforces its role as a trusted financial institution committed to protecting the confidentiality, integrity, and availability of customer information while strengthening privacy management and accountability.

For customers, the dual certification means stronger protection of sensitive personal and financial information, more secure digital and cross-border transactions, and assurance that security and privacy controls are independently audited and continuously improved. 

For corporate and institutional clients, it demonstrates that BPI operates under a mature, globally aligned framework for managing information security and privacy risks.

BPI’s certification journey builds on more than two decades of strengthening its information security framework and governance practices. Since the early 2000s, BPI has progressively enhanced its information security policies, controls, and risk management capabilities to address evolving threats and support secure banking operations. Over time, these efforts expanded to include a comprehensive data privacy program, further strengthening BPI’s ability to protect customer information and align with global standards and regulatory requirements.

As part of its broader information security and privacy strategy, BPI continues to strengthen its commitment to global best practices in information security and privacy management, supporting compliance with key regulatory and international standards, including the Data Privacy Act of 2012, the General Data Protection Regulation (GDPR), and relevant Bangko Sentral ng Pilipinas (BSP) issuances such as Circulars 808 and 982.

More than a certification milestone, the achievement reinforces that information security and data privacy are shared responsibilities across BPI, and are enduring commitments to all its clients.


No comments