BUSINESS
BPI first Philippine universal bank with dual ISO certification
Bank of the Philippine Islands (BPI) has become the first universal bank in the Philippines to secure certifications for both ISO/IEC 27001:2022 and ISO/IEC 27701:2019, strengthening its information security and data privacy frameworks.
The ISO/IEC 27001:2022 certification covers information security management systems, while ISO/IEC 27701:2019 covers privacy information management systems. Both certifications were awarded by British Standards Institution (BSI) Group Philippines Inc.
Broad range of operations
The certifications cover a broad range of BPI operations, including its online and mobile banking platforms, inward and outward remittances, transaction banking and cash management services and contact center operations.
Unlike a one-time audit, the standards require organizations to maintain information security and privacy management systems through regular risk assessments, internal controls, audits, monitoring and operational improvements.
“These certifications affirm that BPI has implemented internationally recognized frameworks for managing information security and data privacy across critical banking services. More importantly, these reflect our commitment to making security and privacy an integral part of how we operate and how we serve our customers,” BPI president and CEO TG Limcaoco said.
Covering multiple customer-facing services
Limcaoco said the certifications cover multiple customer-facing services rather than being limited to a single system or function.
“What is particularly meaningful about this achievement is that these standards are not confined to a single system, channel, or function. They are applied across critical parts of how we serve our customers — from digital banking and payments to transaction banking and our customer support operations,” he said.
BPI said the certifications are intended to strengthen the protection of customer information and improve privacy management and accountability. For corporate and institutional clients, the certifications demonstrate the bank’s use of a globally aligned framework for managing information security and privacy risks.
Its information security efforts later expanded to include a comprehensive data privacy program, supporting compliance with the Data Privacy Act of 2012, the General Data Protection Regulation and relevant Bangko Sentral ng Pilipinas issuances, including Circulars 808 and 982.