You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

December 7, 2020

Anti-Money Laundering Law in Thailand Due to be Updated

Informed Counsel

Thailand’s legal framework for preventing transactions that are deliberately designed to conceal the unlawful origin of funds is primarily contained within the Anti-Money Laundering Act B.E. 2542 (1999) (AMLA), as amended. As international money laundering practices evolve and emerge over time, prevention measures must evolve with them. Therefore the Financial Action Task Force (FATF) recently recommended amendments to the AMLA, along with the Counter Terrorism and Proliferation of Weapons of Mass Destruction Financing Act B.E. 2559 (2016) (CFTA), in order to be consistent with the latest international standards. The amendments passed through the public hearing stage on June 15, 2020, and the laws will now continue through the cabinet and parliament.

Key Draft Amendments to the AMLA

The definition of “financial institution” is expanded to include operators of many financial technology services, including:

  • asset management and digital asset businesses;
  • trustees in capital market trusts;
  • derivatives businesses;
  • authorized juristic persons under foreign exchange controls;
  • personal loan businesses;
  • nano- and pico-finance businesses;
  • peer-to-peer lending businesses;
  • crowdfunding platforms;
  • regulated e-payment systems and services;
  • non-bank credit card service providers; and
  • additional businesses related to financial services or financial technology services at risk for money laundering (by further announcement in ministerial regulations).

The definition of “professions” (formerly known as “section-16 professions”) is expanded to include additional occupations and businesses, such as accounting, auditing, auto trading and leasing, legal consulting, and additional professions at risk for money laundering (by further announcement in ministerial regulations).

For cash transactions exceeding the prescribed threshold, parties in the listed professions are assigned recordkeeping duties in addition to their current reporting duties.

The authority and power of the Anti-Money Laundering Office are expanded to include acting as a central financial intelligence agency to regulate, check, and rate the operations of companies and branches both within and outside of Thailand.

Key Draft Amendments to the CFTA

  • A channel is established for section-6 designated persons (i.e. people who have been listed as a terrorist by the U.N. Security Council) to submit a petition for reconsideration and delisting to the U.N. Security Council via Thailand’s Ministry of Foreign Affairs.
  • If a designated person’s funds and assets are frozen, qualifying financial institutions and professions are given an exemption that enables them to deposit funds (e.g., due payments, interest, etc.) earned prior to the freeze into the frozen account.

Additional Updates to CDD Regulations

In addition to the above draft amendments, the new Ministerial Regulation on Customer Due Diligence B.E. 2563 (2020) came into force on August 12, 2020. This repealed and replaced the former version from 2013 (as amended), and contains the following key updates:

  • The definition of a “Politically Exposed Person” (PEP) has been amended for clarity and ease of compliance, according to the FATF recommendations. Also, certain new definitions have been added, such as “senior management,” “family member,” “intimate person,” “business relationship,” “risk,” and “reliable source of information.”
  • The measures to assess, manage, and relieve risks have been streamlined for consistency with international standards. For example, reduction of a customer’s risk level now requires approval from senior management. Foreign PEPs and customers from any country in the FATF list of high-risk jurisdictions are to be treated as high-risk customers, whereas domestic PEPs are subject to CDD for risk assessment.
  • customer due diligence (CDD) and know-your-customer measures have been enhanced for certain types of customers, such as juristic persons, trusts, and so on.
  • Reporting entities are excused from identifying the beneficial owners of certain types of customers, such as governmental authorities, special financial institutions, listed companies, mutual funds, and so on.
  • For international electronic transfer of funds below THB 50,000 (approximately USD 1,600), the transferring financial institution must also transmit information about the transferor and transferee to the receiving financial institution.

The new amendments and additional updates to the anti-money laundering regulations give more certainty to many issues that were ambiguous before. This will be beneficial for both regulators and the public since less interpretation is needed in order to apply the regulations, and there is therefore less room for ambiguity or error. In addition, the amendments to the AMLA make Thailand’s anti-money laundering regulations more relevant and better suited to fighting modern money laundering schemes that utilize new technological innovations and financial technologies. As a result, entities that are now included in the definition of “financial institution” and “profession” will need to be more aware of the obligations that they will need to comply with. Finally, the amendments to the CFTA include the establishment of the petition submission channel, which has been a persistent obstruction to legal proceedings and will be a great relief for regulators and institutions alike.

We expect that these revisions will lead to positive changes for many financial institutions in Thailand, as well as for those foreign banks that operate (or wish to establish a presence) in Thailand. However, they make it more important than ever for such institutions to ensure strict compliance with the law.

RELATED INSIGHTS​ 

November 24, 2025
A recent warning from the Central Bank of Myanmar (CBM) against cryptocurrency use upholds the country’s ongoing strategy of enforcing strict prohibitions on unauthorized cryptocurrency activities while also promoting the controlled development of a central bank digital currency (CBDC). The CBM’s warning, issued November 16, 2025, reminded the public of announcements in May 2019 and a notification in May 2020 confirming that all online and offline cryptocurrency transactions are strictly prohibited. The CBM also clarified that no financial institution in Myanmar is authorized to deal with digital currencies. The warning highlighted global risks, such as money laundering, scams, tax evasion, hacking, and severe financial losses caused by price volatility and insufficient regulation. The CBM urged the public to use only legitimate banking channels and avoid illegal cryptocurrency activities. The warning comes five months after the CBM issued a notification announcing the formation of the Central Committee for the Issuance of a Central Bank Digital Currency. This committee includes senior CBM officials, representatives from relevant ministries and the banking sector, and technology experts. Its main role is to research CBDC models, test secure digital payment systems, and ensure that any future implementation aligns with Myanmar’s monetary policy and financial stability objectives. Taken together, these two actions illustrate the CBM’s continued pursuit of its dual strategy to promote innovation through CBDC development while prohibiting cryptocurrency use. Businesses should note that while CBDC pilot programs may appear in the future, cryptocurrencies remain off-limits.
September 24, 2025
On September 12, 2025, the Bank of Thailand (BOT) officially released its AI Risk Management Guidelines for Financial Service Providers, building upon the draft guidelines issued in June 2025. The guidelines reflect a balanced approach, encouraging innovation while safeguarding financial stability and consumer protection. The guidelines are targeted at all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. The guidelines apply to both AI systems developed in-house and those developed by third parties that are adopted for use by financial service providers. AI Risk Management Guidelines The two main pillars in managing AI risk are (1) governance of AI system implementation and (2) AI system development and security controls, consisting of the following key elements: 1. Governance Stakeholder roles and responsibilities. Boards and senior management assume accountability for decisions and operations involving AI systems, and are responsible for defining roles and responsibilities for AI oversight. This includes establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. Organizations are expected to foster internal capabilities to use AI securely and avoid overreliance that could compromise business continuity or customer service. AI system usage policy. Policies governing AI usage should align with organizational goals, regulatory obligations, and recognized responsible AI frameworks—such as the FEAT principles (fairness, ethics, accountability, and transparency). These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. Financial service providers should assess risks and impacts of AI usage on operations and customer services.
September 12, 2025
On September 10, 2025, Vietnam’s National Credit Information Center (CIC) reported to the Vietnam Cybersecurity Emergency Response Team (VNCERT) a suspected significant cybersecurity incident involving unauthorized access to the CIC’s credit information database. A hacker group has claimed responsibility and allegedly posted over 160 million records for sale, including sensitive personal and financial data. Implications for Banks and Financial Institutions Companies that share customers’ or potential customers’ personal data with the CIC for credit scoring or other purposes—and continue to act as a data controller for such data—may be obligated under Vietnam’s Personal Data Protection Decree (PDPD) and related regulations to: Notify A05 (Department of Cybersecurity and High-Tech Crime Prevention) and the State Bank of Vietnam without delay. Inform affected individuals if their personal data is at risk. Recommended Actions Companies that could be impacted by this data breach should take the following actions: Conduct an internal review of CIC-related data in their systems, and identify whether and how the systems have been affected by this incident. Assess whether to notify regulators and customers/potential customers. Enhance cybersecurity controls, monitor for suspicious activity, and implement additional safeguards to prevent secondary breaches.
September 11, 2025
Thailand traditionally has had a reputation as a “crossroads” for numerous illegal activities and of the laundering of significant sums of tainted money. Member of the Financial Action Task Force (FATF)? No. Any Egmont members? Yes. Thailand’s Anti-Money Laundering Office (AMLO) is a member of the Egmont Group. Regulation The relevant law, known as the Anti-Money Laundering Act (the Act), was passed in March 1999 with the aim of combating not only the drug trade but also other illicit activities, such as corruption, criminal fraud and prostitution. There have been a number of changes and updates to the Act, the most recent one in late 2015, in which the Act was amended to include: Additional predicate offences such as offences relating to human trafficking, online gambling and offences relating to unfair practices relating to derivatives and agricultural commodity futures. Broader scope of money laundering offence. Non-disclosure obligations to applicable financial institutions and reporting entities. Compulsory training to financial institutions and reporting entities’ employees responsible to monitor and ensure compliance with the Act. Retention period. Enhanced penalties Additionally, discussions did take place mooting further changes to the Act, set out in 2020 and 2021 drafts. Proposed changes included suggestions to expand the definitions of financial institutes, predicate offences and professions, as well as to impose greater reporting and due diligence responsibilities on companies subject to the Act. However, recent amendments to the Act in 2022 only included minor procedural and substantive changes that did not materially alter or expand the Act. The most notable amendments were changes to an injured party’s rights to claim damages caused by a predicate offence and the rights of beneficiaries claiming assets seized by the government in connection with a predicate offence. Financial intelligence unit Of the total number of transactions reported to AMLO annually,