You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 4, 2017

Thailand: E-Insurance Regulations Issued – Effective August 2017

Thailand’s Office of Insurance Commission (OIC) has issued new notifications concerning the criteria, procedures, and conditions for (1) offering insurance policies for sale through electronic channels, (2) using electronic means as part of the sale of policies, (3) issuing policies through electronic channels, and (4) paying compensation for claims through electronic channels (Notifications). The Notifications will come into effect on August 26, 2017 (180 days after publication in the Government Gazette).

The key features of the Notifications are as follows:

  • “Offering for sale of policies via electronic channel” (Online Sale): An Online Sale is generally understood to be an end-to-end binding of an insurance contract. “Online Sale” is defined under the Notifications as soliciting, inducing, or arranging for customers to enter into an insurance policy by providing descriptions of insurance products through electronic channels, without the personal involvement of an insurance agent, an individual broker, or the insurer’s employees. The customers’ acceptances of their purchases are also made through electronic channels. Online Sale excludes the offering of insurance policies through telemarketing.

Insurers, brokers, and applicable banks (with a broker license) are permitted to conduct Online Sale. Apart from the requirements under the Notifications, Online Sale activities are also subject to requirements under OIC regulations on advertisement and insurance intermediaries’ market conduct.

  • Insurer’s authorization and reporting requirement: Brokers and applicable banks, with an insurer’s authorization, may also conduct Online Sales. Insurers are required to withdraw if there is any noncompliance with the Notifications by their intermediaries, and they must report such incident to the OIC within seven days.
  • Specific product filing requirement: Insurance product wording, offered through Online Sale, must receive prior approval from the OIC.
  • Premium remittance: Electronic payment of premiums must be made to the insurance company’s accounts only. Brokers may not collect premiums and are therefore paid commission directly by the insurer.
  • Confirmation calls: Once an Online Sale is made, insurers are required to seek confirmation from the customer through telephone calls or electronic channels, such as email, within seven days from the distribution of the policy.
  • Free-look period: When confirmation calls or online confirmations are made, customers must be notified of their right to a free-look period, which is a period of 15 days after they receive their insurance policies during which they may change their mind and cancel the policy. However, this is not applicable to all categories of insurance. For example, compulsory motor insurance and travel insurance are excluded.
  • Issuing e-policies: In issuing policies through electronic channels, an e-signature must be placed by the insurer. The e-signature must comply with reliability requirements under the Electronic Transactions Act B.E. 2544 (2001). For group insurance policies, the insurer must issue an insurance certificate along with other required information to each of the insured group members, unless agreed otherwise between the insurer and the group policy holder(s).
  • E-claim payments: Insured persons/beneficiaries must be identified through a process arranged by the insurer before any electronic claims compensation is made. Claims payment must only be made to the account of the insured person or the beneficiary, whichever is agreed upon in advance.
  • Security measures: Online Sales, using electronic means as part of the sale of policies, issuing policies electronically, and paying compensation for claims must comply with the levels of security measures prescribed under the Electronic Transactions Act and the requirements on IT security systems stipulated in the Notifications (e.g., IT systems for providing such online services must be certified by an independent certification body such as CISA, CISM, CISSP, or ISO 27001 Information Security Management). In addition, the IT systems must be registered with the OIC to conduct any of the activities above.
  • Outsourcing: Third-party outsourcing arrangements are subject to the specific requirements stipulated under the Notifications. 

Compliance with these Notifications is in addition to existing regulatory requirements under the Electronic Transactions Act and other laws that regulate online business.

In addition, the OIC has announced, for public hearing, a draft subordinating notification on IT security measures certification. The draft sets out greater details on conditions and criteria for certification of IT security measures as required under the Notifications. It is expected that the draft will be implemented in the near future, possibly by the end of 2017.

RELATED INSIGHTS​ 

June 30, 2026
Tilleke & Gibbins’ insurance specialists in Bangkok provided Thomson Reuters’ latest country update on Thailand’s regulatory framework for the insurance industry. The country update, which is part of Thomson Reuters’ extensive Regulatory Intelligence offerings, contains information and guidance for insurers active in the Thai market. The guide covers the following topics in detail: Permission to operate; Legal and regulatory considerations for domestic and international insurers; Capital reserve requirements; Investment management and markets; The Office of Insurance Commission’s arbitration system for handling complaints; Creditor hierarchy; Rehabilitation of non-life insurance companies; and Personal data protection requirements for insurers. Thomson Reuters Regulatory Intelligence is a service that provides with curated news, analysis, and data across jurisdictions to help legal, risk, and compliance professionals manage compliance and mitigate global risk. The full Thailand insurance country update is available by subscription to Regulatory Intelligence on the Thomson Reuters website.
June 30, 2026
Insurance specialists from Tilleke & Gibbins have provided an update to the Vietnam chapter of Thomson Reuters’ Practical Law guide to insurance and reinsurance. The guide is a Q&A-style overview of insurance and reinsurance law in jurisdictions worldwide. The Vietnam chapter provides a detailed overview of the legal framework for the insurance and reinsurance market in the country, covering the following issues: Regulatory framework for insurance and reinsurance Authorization for insurers, reinsurers, and insurance intermediaries Ownership restrictions Ongoing requirements Penalties for noncompliance Sales and marketing of insurance and reinsurance Transfer of risk Reinsurance contracts and risks Contracts and policies Claims Dispute resolution Insolvency Tax Practical Law, a legal reference resource from Thomson Reuters, publishes a range of guides for hundreds of jurisdictions and practice areas. The insurance and reinsurance guide is a valuable resource for legal practitioners, covering numerous jurisdictions worldwide. To view the latest version of the guide, please visit the Practical Law website and enroll in the free Practical Law trial to gain full access.
June 5, 2026
Thailand’s Office of Insurance Commission (OIC) has opened a public hearing on proposed amendments to the OIC Notification on Criteria for Information Technology Risk Governance and Management for Life Insurance and Non-Life Insurance Companies B.E. 2563 (2020) via the centralized Law platform. The public consultation period runs from May 8, 2026, to June 9, 2026. The proposed amendments aim to elevate the IT risk governance and cybersecurity risk management framework to be more modern and aligned with international standards, with a focus on strengthening cyber resilience, enhancing the role of IT audits, and establishing data governance and data quality controls. The parties affected by these amendments include life insurance companies, non-life insurance companies, and external IT auditors. Key Changes Elevated Role of Board of Directors The proposed notification requires the company’s board of directors to oversee data governance, cybersecurity, and the responsible use of AI. Additionally, the board should include at least one director with IT knowledge or experience. Companies are also required to designate a head of security responsible for information security. The board’s duties are expanded to include oversight of data governance and AI usage, including establishing relevant policies and committees. Enhanced IT Security and Cybersecurity The revised notification consolidates the existing chapters on IT project management, IT security and cybersecurity to reduce redundancy, and introduces significant new measures. These include mandatory multi-factor authentication for material systems, enhanced data security measures such as data masking and data leakage prevention, security hardening requirements, web filtering, and mandatory vulnerability assessment and penetration testing at least annually. New requirements are also introduced for mobile application security, API security, and security measures for emerging technologies such as cloud computing and post quantum cryptography. The cybersecurity framework now encompasses identification, protection, detection, response, and recovery. The draft also introduces source code review
April 9, 2026
Thailand’s Office of the Insurance Commission (OIC) has published two parallel sets of draft regulatory amendments for public hearing—one governing non-life insurance and the other governing life insurance. The proposed amendments would significantly revise the rules for issuing, offering, and selling insurance policies, as well as the conduct of agents, brokers, and banks. Stakeholders may submit comments until April 25, 2026. The key proposed changes are summarized below. Electronic Policy Delivery by Default Under both draft amendments, electronic delivery would become the default method for delivering insurance policies. A printed copy would be required only if the policyholder expressly opts out, and any such printed copy would be treated as a substitute for the electronic original. For life insurance, this requirement would also extend to coverage summaries and to exclusion documents. The OIC would also retain authority to approve alternative delivery methods for specific types of policies. Misuse of Licenses Both amendments would introduce an explicit prohibition against sales representatives using another person’s name or license, or allowing another person to use their name or license, in connection with the offering of insurance or in sales documentation and policies. Premium Collection Reforms Both amendments would introduce the premium collection reforms outlined below. Premium receipt accounts Insurers must ensure that sales representatives inform customers of the available payment channels, which are limited to channels that remit premiums into the insurer’s account. If a customer pays an insurance premium to an insurer’s employee, an insurance broker, or any other person, and the company acknowledges the payment by issuing an insurance policy or other documentary evidence of insurance coverage, the insurer would be deemed to have received the insurance premium. Written premium collection and refund guidelines Insurers would be required to prepare written internal guidelines covering premium collection and refund policies, risk