You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 25, 2013

AEC: Moving Toward a Common Market for Financial Services

Bangkok Post, Corporate Counsellor Column

A common market for financial services will be one of the major components of the ASEAN Economic Community when it takes effect at the end of 2015. This will represent a significant change for securities regulation in Thailand, where the Securities and Exchange Act, subject to some exceptions, places substantial restrictions on the offering of foreign securities in Thailand.

The change is occurring in phases. As one of the early changes, an exception has been made with respect to the offering of foreign mutual funds—or foreign collective investment schemes, as they are called in the SEC regulations.

Mutual fund management is among the securities businesses regulated under the Securities and Exchange Act. The Act defines mutual fund management as the management of investments under a mutual fund project by issuing investment units of each project for sale to the public, and using the proceeds to invest in, or seek profit from holding securities, derivatives, or any other properties, or to invest in or seek profit by other means.

The law provides that a securities business can be undertaken only by a limited company, a public limited company, or a financial institution established in accordance with other laws, after obtaining a license from the Minister of Finance on the recommendation of the SEC. The SEC licensing process is quite thorough, and there are numerous restrictions and requirements.

The securities company may set up and manage a mutual fund only when its application to set up the fund has been approved by the SEC in accordance with the regulations of the Capital Market Supervisory Board, which is also an extensive process.

Chapter 3 of the Securities and Exchange Act sets out the basic provisions for public offerings of securities. On the topic of mutual funds, it is written in a way that it does not apply to the offer for sale of newly issued investment units of a securities company licensed to manage mutual funds. However, in the case of a foreign company operating a foreign mutual fund, such company would not have undergone the licensing process, and thus would not be able to avail itself of the exception. Clearly, this would create a barrier to the cross-border offering of mutual funds within ASEAN.

To address this issue, a special exception exists for collective investment schemes established in certain ASEAN countries, which have been approved by their home regulators. The exception applies only to ASEAN countries whose securities regulators are members of IOSCO (the International Organization of Securities Commissions) in the category of Signatory A to the Multilateral Memorandum of Understanding on Consultation, Cooperation and Exchange of Information.

In brief, the regulation provides an exemption from the requirements of Chapter 3 of the Act, for those foreign collective investments that meet certain conditions. Importantly, all units of such funds can be offered only to institutional or high-net-worth investors (each as defined in SEC regulations).

Among other requirements, the foreign collective investment scheme has to have a brokerage firm (licensed by the Thai SEC) responsible for trading its units in Thailand, as an authorized representative. The fund must also have a representative in Thailand to handle disclosing and sending information to investors, as required by law or regulations of the relevant home regulator. The local representative must also be appointed to receive notices, orders, warrants, and any other documents, on behalf of the foreign fund or the person responsible for operating it.

To meet the conditions for the exception, the foreign fund must be subject to regulation, which is similar to that provided by the Thai SEC. For example, it must have an investment policy that provides for investment in similar assets and investment ratios for mutual funds under the relevant SEC notification. The foreign fund must have actually been offered for sale in the jurisdiction in which it is regulated by its home regulator, and it must not be subject to a prohibition imposed by the home regulator with respect to trading in units of the scheme.

There are also requirements for the person responsible for undertaking the foreign collective investment scheme. This person must be subject to supervision by its home regulator, and the home regulator must have the authority to impose sanctions or order the responsible person to act or refrain from acting, in the case of any action likely to damage investors’ interests. Such person must not be subject to a suspension or revocation order imposed by the home regulator, and must not have a record of violating laws or regulations pertaining to disclosure of material information to investors or to the home regulator.

Securities companies that act as authorized representatives for trading the securities are also subject to their own set of rules. Among these, a securities company may only offer those foreign funds that the Thai SEC has examined, approved, and listed on its website. The verification process is addressed in a separate regulatory notification and requires extensive documentation and information.

This regulation is a major step forward, in that it provides a pathway for foreign collective investment schemes to be offered lawfully in Thailand. Although the above is just a summary and other requirements apply, it is evident that the SEC’s approach provides for freer trade in financial services, while maintaining investor protection. The ultimate winner is the investor, as more mutual funds awill be offered in Thailand from sources across eligible ASEAN member countries.

RELATED INSIGHTS​ 

December 26, 2025
The Bank of Thailand (BOT) has released the Guidelines for Digital Fraud Management, which took effect on December 17, 2025, incorporating certain amendments to the draft guidelines issued in March 2025. These official guidelines aim for end-to-end digital fraud prevention, with a particular focus on mule accounts, to enhance trust and security in Thailand’s financial system. The guidelines apply to “financial service providers,” including: Financial institutions and special financial institutions under the Financial Institution Business Act; and Operators of Inter-institutional Fund Transfer System e-money services and e-fund transfer services under the Payment Systems Act. Besides commercial banks and e-money operators that offer fund-transfer services, other providers may adopt requirements based on risk proportionality and baseline standards set out in the guidelines (for instance, an e-money operator that does not offer e-fund transfer services could consider implementing a fraud monitoring and detection system according to the risk level of its service). The guidelines establish the following key requirements: Policy and oversight. Directors and senior executives of financial service providers must adopt appropriate “end-to-end” fraud management policies and KPIs to manage digital fraud, covering prevention, monitoring, detection, management, resolution, and support for affected customers. The fraud management policy must be regularly reviewed, and whenever there is a situation or change that significantly affects the efficiency of the fraud management. Any significant update to the policy must first be approved by the board of the financial service provider. The BOT also encourages providers to collaborate in establishing industry standards aligned with applicable laws and regulations to ensure consistency and best practices across the sector. Fraud management processes. Financial service providers must establish a clear framework for managing digital fraud throughout the customer lifecycle—from customer onboarding to service termination—covering at least the following processes: Know your customer (KYC) and customer due diligence (CDD):
November 24, 2025
A recent warning from the Central Bank of Myanmar (CBM) against cryptocurrency use upholds the country’s ongoing strategy of enforcing strict prohibitions on unauthorized cryptocurrency activities while also promoting the controlled development of a central bank digital currency (CBDC). The CBM’s warning, issued November 16, 2025, reminded the public of announcements in May 2019 and a notification in May 2020 confirming that all online and offline cryptocurrency transactions are strictly prohibited. The CBM also clarified that no financial institution in Myanmar is authorized to deal with digital currencies. The warning highlighted global risks, such as money laundering, scams, tax evasion, hacking, and severe financial losses caused by price volatility and insufficient regulation. The CBM urged the public to use only legitimate banking channels and avoid illegal cryptocurrency activities. The warning comes five months after the CBM issued a notification announcing the formation of the Central Committee for the Issuance of a Central Bank Digital Currency. This committee includes senior CBM officials, representatives from relevant ministries and the banking sector, and technology experts. Its main role is to research CBDC models, test secure digital payment systems, and ensure that any future implementation aligns with Myanmar’s monetary policy and financial stability objectives. Taken together, these two actions illustrate the CBM’s continued pursuit of its dual strategy to promote innovation through CBDC development while prohibiting cryptocurrency use. Businesses should note that while CBDC pilot programs may appear in the future, cryptocurrencies remain off-limits.
September 24, 2025
On September 12, 2025, the Bank of Thailand (BOT) officially released its AI Risk Management Guidelines for Financial Service Providers, building upon the draft guidelines issued in June 2025. The guidelines reflect a balanced approach, encouraging innovation while safeguarding financial stability and consumer protection. The guidelines are targeted at all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. The guidelines apply to both AI systems developed in-house and those developed by third parties that are adopted for use by financial service providers. AI Risk Management Guidelines The two main pillars in managing AI risk are (1) governance of AI system implementation and (2) AI system development and security controls, consisting of the following key elements: 1. Governance Stakeholder roles and responsibilities. Boards and senior management assume accountability for decisions and operations involving AI systems, and are responsible for defining roles and responsibilities for AI oversight. This includes establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. Organizations are expected to foster internal capabilities to use AI securely and avoid overreliance that could compromise business continuity or customer service. AI system usage policy. Policies governing AI usage should align with organizational goals, regulatory obligations, and recognized responsible AI frameworks—such as the FEAT principles (fairness, ethics, accountability, and transparency). These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. Financial service providers should assess risks and impacts of AI usage on operations and customer services.
September 12, 2025
On September 10, 2025, Vietnam’s National Credit Information Center (CIC) reported to the Vietnam Cybersecurity Emergency Response Team (VNCERT) a suspected significant cybersecurity incident involving unauthorized access to the CIC’s credit information database. A hacker group has claimed responsibility and allegedly posted over 160 million records for sale, including sensitive personal and financial data. Implications for Banks and Financial Institutions Companies that share customers’ or potential customers’ personal data with the CIC for credit scoring or other purposes—and continue to act as a data controller for such data—may be obligated under Vietnam’s Personal Data Protection Decree (PDPD) and related regulations to: Notify A05 (Department of Cybersecurity and High-Tech Crime Prevention) and the State Bank of Vietnam without delay. Inform affected individuals if their personal data is at risk. Recommended Actions Companies that could be impacted by this data breach should take the following actions: Conduct an internal review of CIC-related data in their systems, and identify whether and how the systems have been affected by this incident. Assess whether to notify regulators and customers/potential customers. Enhance cybersecurity controls, monitor for suspicious activity, and implement additional safeguards to prevent secondary breaches.