You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 17, 2026

Thailand Issues New Group-Wide Insurance Risk Supervision Rules

Thailand’s Office of Insurance Commission (OIC) has introduced comprehensive group-wide supervision requirements for insurers operating within corporate groups. Published on February 26, 2026, in two separate notifications in the Government Gazette, the new rules establish parallel frameworks for life and non-life insurance companies. Both notifications take effect on July 1, 2026, and impose significant new requirements on insurance business groups. Affected insurers should begin reviewing their group structures, governance frameworks, and risk management systems now to ensure timely compliance.

The notifications aim to ensure that group-level operations are orderly, stable, and reliable, and prevent the accumulation of systemic risk that could undermine public confidence in the insurance sector. Both notifications share a substantially parallel structure and require insurers to assess and manage the financial position, risk exposure, reliability, and corporate governance of their entire insurance business group on a comprehensive and ongoing basis.

The regulations introduce definitions for several key terms. An “insurance business group” encompasses the insurer together with its ultimate parent company, parent companies, subsidiaries, and related companies. The “head of the insurance business group” is the entity responsible for overseeing group-wide supervision, operations, and governance. An “ultimate parent company” is one that exercises control without itself being controlled by another entity.

Key Requirements

The notifications establish the following core obligations for insurers:

  • Group structure and shareholding reporting: Insurers must report the organizational chart and shareholding structure of their insurance business group—covering the ultimate parent company, parent companies, subsidiaries, and related entities—to the OIC registrar by June of each year, and whenever material changes occur. The regulations prescribe specific thresholds for determining when shareholding proportions constitute control.
  • Corporate governance standards: Board members, executives, and authorized persons of the ultimate parent company or parent company must not be disqualified (e.g., bankrupt individuals, persons convicted of property-related fraud, or persons removed from directorship for misconduct), and their qualifications must be reported to the OIC registrar annually by June of each year and whenever any disqualifying characteristic arises. Additionally, the head of the insurance business group must appoint a dedicated unit or committee for group-level supervision, with authority and responsibilities proportionate to the group’s size, nature, and complexity.
  • Intragroup transactions: All transactions between group entities must be conducted on an arm’s-length basis, with pricing and conditions comparable to those between independent third parties. Insurers must report intragroup transactions to the OIC registrar, ensuring transparency in areas including underwriting, investments, shared services, transfer pricing, mergers, assignments, and other related-party dealings. Where a group entity is located outside Thailand, its impact on the group’s capital, reserves, and risk exposure must not adversely affect the group.
  • Reinsurance: Insurers with intragroup reinsurance arrangements must report those transactions, disclose information relating to intragroup reinsurance in accordance with applicable accounting standards, and manage the risk arising from intragroup reinsurance arrangements.
  • Enterprise risk management and ORSA: Insurers must ensure that insurance business groups implement an enterprise risk management (ERM) framework and conducts an own risk and solvency assessment (ORSA). Group ERM/ORSA reports must be submitted to the OIC registrar. The ERM framework must, at a minimum, include identification of key risk indicators and an acceptable risk appetite; monitoring, evaluation, and control processes with clear reporting lines; internal control and audit mechanisms consistent with the group’s operations; a business continuity management (BCM) plan; and determination of risk limits appropriate to the group’s scale and complexity.
  • Risk management policy and internal audit: The head of the group must establish board-approved, group-wide risk management policies aligned with the group’s business plan and strategy. Internal audit procedures must be established and their effectiveness reported to the OIC registrar regularly. Adequate staff with relevant knowledge, skills, and experience must be allocated at every operational level.
  • Reporting and disclosure: Insurers must file periodic reports with the OIC registrar, including shareholding structure and corporate governance reports, by June of each year. Financial statements of the ultimate parent company or parent company, for fiscal years ending from 2025 onward, must also be submitted to the OIC registrar within six months from the end of each calendar year.

While both notifications take effect on July 1, 2026, transitional provisions grant grace periods for certain requirements. For the year 2026, only reports relating to the following aspects must to be filed with the OIC registrar by July 31, 2026:

  • Intragroup transactions
  • Intragroup reinsurance arrangements
  • Group structure and shareholding structure of insurance business groups
  • Disqualification of board members, executives, and authorized persons of ultimate parent companies or parent companies
  • Structure, authority, and responsibilities of business units or committees supervising insurance business groups
  • Financial statements of ultimate parent companies or parent companies for fiscal years ending in 2025

Recommended Actions

Affected life and non-life insurers operating within corporate groups in Thailand should consider taking the following steps ahead of the July 1, 2026, effective date:

  • Map the insurance business group. Confirm the full group structure, including the ultimate parent company, parent companies, subsidiaries, and related entities, and prepare the required shareholding and organizational charts for filing by July 31, 2026.
  • Review corporate governance. Verify that all board members, executives, and authorized persons of the ultimate parent company and any other parent companies satisfy the qualification requirements and are free from disqualifying characteristics.
  • Assess intragroup transactions. Audit all intragroup transactions for arm’s length compliance and prepare the necessary disclosures for the OIC registrar.
  • Develop or enhance ERM and ORSA frameworks. Ensure that a group-level ERM framework and ORSA process are in place, including key risk indicators, risk appetite, risk limits, BCM plans, and internal audit mechanisms.
  • Establish a dedicated group supervision function. Appoint or formalize the unit or committee responsible for group-level oversight, with clearly defined authority and responsibilities.

RELATED INSIGHTS​ 

June 30, 2026
Tilleke & Gibbins’ insurance specialists in Bangkok provided Thomson Reuters’ latest country update on Thailand’s regulatory framework for the insurance industry. The country update, which is part of Thomson Reuters’ extensive Regulatory Intelligence offerings, contains information and guidance for insurers active in the Thai market. The guide covers the following topics in detail: Permission to operate; Legal and regulatory considerations for domestic and international insurers; Capital reserve requirements; Investment management and markets; The Office of Insurance Commission’s arbitration system for handling complaints; Creditor hierarchy; Rehabilitation of non-life insurance companies; and Personal data protection requirements for insurers. Thomson Reuters Regulatory Intelligence is a service that provides with curated news, analysis, and data across jurisdictions to help legal, risk, and compliance professionals manage compliance and mitigate global risk. The full Thailand insurance country update is available by subscription to Regulatory Intelligence on the Thomson Reuters website.
June 30, 2026
Insurance specialists from Tilleke & Gibbins have provided an update to the Vietnam chapter of Thomson Reuters’ Practical Law guide to insurance and reinsurance. The guide is a Q&A-style overview of insurance and reinsurance law in jurisdictions worldwide. The Vietnam chapter provides a detailed overview of the legal framework for the insurance and reinsurance market in the country, covering the following issues: Regulatory framework for insurance and reinsurance Authorization for insurers, reinsurers, and insurance intermediaries Ownership restrictions Ongoing requirements Penalties for noncompliance Sales and marketing of insurance and reinsurance Transfer of risk Reinsurance contracts and risks Contracts and policies Claims Dispute resolution Insolvency Tax Practical Law, a legal reference resource from Thomson Reuters, publishes a range of guides for hundreds of jurisdictions and practice areas. The insurance and reinsurance guide is a valuable resource for legal practitioners, covering numerous jurisdictions worldwide. To view the latest version of the guide, please visit the Practical Law website and enroll in the free Practical Law trial to gain full access.
June 5, 2026
Thailand’s Office of Insurance Commission (OIC) has opened a public hearing on proposed amendments to the OIC Notification on Criteria for Information Technology Risk Governance and Management for Life Insurance and Non-Life Insurance Companies B.E. 2563 (2020) via the centralized Law platform. The public consultation period runs from May 8, 2026, to June 9, 2026. The proposed amendments aim to elevate the IT risk governance and cybersecurity risk management framework to be more modern and aligned with international standards, with a focus on strengthening cyber resilience, enhancing the role of IT audits, and establishing data governance and data quality controls. The parties affected by these amendments include life insurance companies, non-life insurance companies, and external IT auditors. Key Changes Elevated Role of Board of Directors The proposed notification requires the company’s board of directors to oversee data governance, cybersecurity, and the responsible use of AI. Additionally, the board should include at least one director with IT knowledge or experience. Companies are also required to designate a head of security responsible for information security. The board’s duties are expanded to include oversight of data governance and AI usage, including establishing relevant policies and committees. Enhanced IT Security and Cybersecurity The revised notification consolidates the existing chapters on IT project management, IT security and cybersecurity to reduce redundancy, and introduces significant new measures. These include mandatory multi-factor authentication for material systems, enhanced data security measures such as data masking and data leakage prevention, security hardening requirements, web filtering, and mandatory vulnerability assessment and penetration testing at least annually. New requirements are also introduced for mobile application security, API security, and security measures for emerging technologies such as cloud computing and post quantum cryptography. The cybersecurity framework now encompasses identification, protection, detection, response, and recovery. The draft also introduces source code review
April 9, 2026
Thailand’s Office of the Insurance Commission (OIC) has published two parallel sets of draft regulatory amendments for public hearing—one governing non-life insurance and the other governing life insurance. The proposed amendments would significantly revise the rules for issuing, offering, and selling insurance policies, as well as the conduct of agents, brokers, and banks. Stakeholders may submit comments until April 25, 2026. The key proposed changes are summarized below. Electronic Policy Delivery by Default Under both draft amendments, electronic delivery would become the default method for delivering insurance policies. A printed copy would be required only if the policyholder expressly opts out, and any such printed copy would be treated as a substitute for the electronic original. For life insurance, this requirement would also extend to coverage summaries and to exclusion documents. The OIC would also retain authority to approve alternative delivery methods for specific types of policies. Misuse of Licenses Both amendments would introduce an explicit prohibition against sales representatives using another person’s name or license, or allowing another person to use their name or license, in connection with the offering of insurance or in sales documentation and policies. Premium Collection Reforms Both amendments would introduce the premium collection reforms outlined below. Premium receipt accounts Insurers must ensure that sales representatives inform customers of the available payment channels, which are limited to channels that remit premiums into the insurer’s account. If a customer pays an insurance premium to an insurer’s employee, an insurance broker, or any other person, and the company acknowledges the payment by issuing an insurance policy or other documentary evidence of insurance coverage, the insurer would be deemed to have received the insurance premium. Written premium collection and refund guidelines Insurers would be required to prepare written internal guidelines covering premium collection and refund policies, risk