You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 23, 2024

Bank of Thailand Implements New Responsible Lending Regulation

The Bank of Thailand (BOT) has issued a new notification to sustainably address Thailand’s household debt problems by establishing responsible and fair lending requirements for lending service providers throughout their lending journey.

Notification No. SorKorChor. 7/2566 Re: Provision of Responsible and Fair Lending was announced on December 21, 2023, and took effect on January 1, 2024. The lending service providers this notification applies to include both commercial banks and nonbank business operators (e.g., personal loan business operators, nano-financing business operators, and credit card business operators).

The key principle of this notification is to provide criteria for responsible and fair lending that supplement market conduct principles, covering eight areas in the debt cycle:

  • Lending product development. Service providers must offer lending products that are suitable to customers’ needs and repayment capabilities, avoiding encouragement of excessive debt. Loan interest rates should align with the borrower’s risk profile and credit characteristics (risk-based pricing) to ensure fair contract conditions.
  • Advertising. Service providers must prepare and control advertisements with “correct and clear” content, presenting complete and comparable conditions, interest rates, and various fees to customers. The advertisements should not encourage excessive debt, enabling customers to make informed decisions and promoting financial discipline.
  • Sales. In the selling process, service providers must ensure that customers receive complete, accurate, and unexaggerated information that facilitates appropriate consideration of decisions based on a correct understanding of the product or service. Products should also align with customers’ purposes or needs for fund utilization, avoiding encouragement of excessive debt.
  • Consideration of debt repayment ability (affordability). Service providers must be conscientious in considering customers’ debt repayment ability, taking into account all obligations and residual income.
  • Promotion of discipline and financial management. Service providers must provide important information and warnings to debtors, including regular reminders to promote responsible borrowing.
  • Helping debtors with persistent debt. Service providers must convey essential information to make debtors aware of the negative effects of persistent debt. This includes establishing standard guidelines for helping debtors find an appropriate way to settle their debts.
  • Helping debtors with debt repayment issues. Service providers must promptly propose debt restructuring guidelines in line with debtors’ ability to repay as soon as debtors begin to show signs of repayment problems.
  • Legal proceedings and debt sales to other creditors. Upon request, service providers must inform debtors of their rights and important information when legal action has been taken. Additionally, debtors should be afforded an opportunity to engage in mediation regarding their debt problems. This includes providing appropriate debt repayment conditions after debt has been sold and transferred.

For more information on this BOT notification, or on any aspect of conducting financial or lending business in Thailand, please contact Athistha (Nop) Chitranukroh at [email protected], Pornpan Wichawut at [email protected], or Karnravee Jitvilai at [email protected].

RELATED INSIGHTS​ 

August 13, 2026
On August 6, 2026, the National Bank of Cambodia (NBC) issued a notice calling on business owners that issue electronic money, such as e-wallet accounts and stored-value membership cards, to notify the central bank within 90 days. The notice targets businesses that are not licensed banking or financial institutions or payment service providers, but have been issuing e-money to facilitate payments within their own networks. Failure to notify the NBC may result in legal action. Background and Regulatory Basis The NBC has observed that certain businesses, including cafes, restaurants, transportation companies, entertainment centers, and gas stations, have been issuing e-money through e-wallet accounts in mobile apps or membership cards to facilitate customer payments for products or services within their own networks. Customers create e-wallet accounts and load balances to pay for goods or services at the issuing business. The NBC describes this as “single-purpose e-money.” Under the 1999 Law on Banking and Financial Institutions, providing payment facilities to customers forms part of the operations of banking and financial institutions and requires an NBC license. In addition, article 20 of the 2017 Prakas on the Management of Payment Service Institutions further prohibits legal entities other than banking and financial institutions and payment service institutions from issuing e-money. However, article 20 also provides that issuing e-money in certain limited cases does not require a license, but the NBC must be notified in advance in writing. A business may issue single-purpose e-money without a payment service institution license provided it meets all the following conditions and submits written notice to the NBC: The maximum balance per account is KHR 200,000 (approximately USD 50) or equivalent. The total aggregate balance across all accounts does not exceed KHR 800 million (approximately USD 200,000) or equivalent. The e-money is used to pay for products or
August 11, 2026
On July 27, 2026, the State Bank of Vietnam (SBV) released a draft decree proposing amendments to Decree No. 52/2024/ND-CP dated May 15, 2024, on non-cash payments (Decree 52). The draft decree would amend 17 of Decree 52’s 38 articles, with several key changes directly affecting providers of intermediary payment service (IPS). The key proposed changes affecting IPS providers are outlined below. Streamlining IPS Licensing Procedures A central objective of the draft decree is to simplify regulatory procedures for IPS providers. Notably, it would significantly reduce IPS licensing documentation requirements by removing the need to submit enterprise registration certificates, investment registration certificates, and documents evidencing the qualifications of the legal representative and general director. Instead, the SBV would retrieve this information directly from national business registration and other specialized databases, requesting additional documents only where the relevant information cannot be verified electronically or is incomplete. The draft decree also removes the current limit of two rounds for dossier supplementation and shortens processing timelines for several IPS licensing procedures such as issuance, amendment, and reissuance of IPS licenses. The processing time for new IPS license applications would be thereby reduced from 90 to 60 working days. In addition, several continuing IPS business conditions would be removed. For example, IPS providers would no longer be required to maintain certain representations relating to corporate restructuring or the legality of contributed capital. Likewise, the IPS project plan (đề án) would become a one-time application document rather than an ongoing licensing condition. If retained in the final decree, this change could provide IPS providers with significantly greater flexibility to implement post-licensing technology upgrades, system integrations, and corporate restructuring transactions without needing to revisit the originally approved project plan. The draft decree also removes the requirement for the SBV to consult the Ministry of Public
August 4, 2026
Tilleke & Gibbins has contributed the Vietnam chapter to Fintech 2027, a global guide published by Lexology Panoramic that provides comparative insights into the legal and regulatory frameworks governing fintech businesses across multiple jurisdictions. The Vietnam chapter offers a comprehensive overview of the country’s rapidly evolving fintech landscape, examining both the regulatory environment and practical considerations for businesses operating in or entering the Vietnamese market. Topics covered include: Fintech landscape and initiatives: General innovation climate; government and regulatory support Financial regulation: Regulatory bodies; regulated activities; consumer lending; secondary market loan trading; collective investment schemes; alternative investment funds; peer-to-peer and marketplace lending; crowdfunding; invoice trading; payment services; open banking; robo-advice; insurance products; credit references Cross-border regulation: Passporting; requirement for a local presence Sales and marketing: Restrictions on the promotion and marketing of financial products and services Cryptoassets and tokens: Distributed ledger technology; cryptoassets; token issuance Artificial intelligence: Regulatory framework governing AI systems and AI-enabled financial services Change of control: Notification and consent requirements for regulated businesses Financial crime: Anti-bribery and anti-money laundering procedures; regulatory guidance Data protection and cybersecurity: Data protection obligations; cybersecurity requirements applicable to fintech businesses Outsourcing and cloud computing: Outsourcing of material functions; use of cloud computing in the financial services industry Intellectual property rights: IP protection for software; employee- and contractor-created IP; joint ownership; trade secrets; branding; remedies for infringement Competition: Competition law issues affecting fintech businesses Tax: Incentives for innovation and investment; developments affecting tax and compliance obligations Immigration: Immigration options for recruiting skilled foreign personnel; special measures available through Vietnam’s international financial centers The chapter also examines a number of significant recent developments shaping Vietnam’s fintech sector, including the introduction of the country’s first comprehensive regulatory framework for cryptoassets, the adoption of a dedicated law on artificial intelligence, implementation of the banking regulatory sandbox,
August 3, 2026
On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026. Background The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements. Expanded Scope of Regulated Entities and Channels The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking. Strengthened Customer Authentication The draft introduces enhanced authentication requirements in three areas: Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits. Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases. Secure authentication factors. Key requirements include the following: “What-you-know” factors must