You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 3, 2026

Bank of Thailand Proposes New Digital Channel Security Standards

On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026.

Background

The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements.

Expanded Scope of Regulated Entities and Channels

The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking.

Strengthened Customer Authentication

The draft introduces enhanced authentication requirements in three areas:

  • Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits.
  • Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases.
  • Secure authentication factors. Key requirements include the following:
    • “What-you-know” factors must protect against brute-force attacks.
    • “What-you-have” factors must use secure methods such as a registered mobile application with device binding or hard/soft tokens.
    • SMS OTPs must be discontinued for transaction authentication.
    • Biometric factors must use effective antispoofing technology, such as facial scanning, in compliance with the BOT’s guidelines on biometric technology in financial services.

Providers must cease sending SMS messages and emails containing embedded links and must establish incident response processes for counterfeit applications or websites.

Mobile Application Security Controls

Providers must ensure application integrity and block remote-access applications. Facial comparison with antispoofing technology is required for transfers exceeding THB 50,000 (approx. USD 1,490) per transaction or THB 200,000 (approx. USD 5,960) per day.

Next Steps

Affected financial service providers should assess their current systems against the draft requirements and consider submitting comments to the BOT by August 24, 2026.

RELATED INSIGHTS​ 

January 21, 2025
Vietnam’s Ministry of Information and Communications has released the latest version of its draft Law on the Digital Technology Industry (DTI Law), marking a significant step toward comprehensive regulation of digital technologies and notably addressing artificial intelligence (AI). The draft law was deliberated in the National Assembly on January 6, 2025, and is expected to be adopted in May 2025. Once in effect, the law will modernize Vietnam’s existing information technology regulatory framework. Background Vietnam has been steadily building its regulatory framework for AI since January 2021, when the prime minister issued Decision No. 127/QD-TTg on the National Strategy for Research, Development, and Application of Artificial Intelligence until 2030. While various ministries have been tasked with issuing guidance documents and technical standards, Vietnam still lacks a comprehensive legal framework specifically addressing AI and digital technologies. The draft DTI Law aims to fill this gap by providing a structured approach to regulating the digital technology industry. Scope and Definitions The draft DTI Law establishes a broad framework governing digital technology industry activities, initiatives for developing the digital technology sector, and rights and obligations of organizations and individuals in the industry. The draft law also proposes the creation of various incentives, primarily in the form of tax benefits, for encouraging foreign direct investment, talent acquisition and development, and industry growth. The draft law introduces several important definitions, particularly around AI, which is defined as digital technology that simulates human intelligence to generate content, forecasts, suggestions, and decisions based on human-determined goals. The draft distinguishes between different categories of AI systems: High-risk AI systems: Those posing risks to health, safety, rights, and legitimate interests. High-impact AI systems: Distinguished by their broad scope, large user base, and significant computational resources for training. Standard AI systems: Basic systems that apply AI for automated analysis
January 20, 2025
Thailand’s official draft Platform Economy Act (PEA) was released on January 15, 2025, for public comment until February 15, 2025. The draft PEA is positioned as a general or overarching law for digital intermediary services and digital platform service businesses. The official release of the draft came after the sharing of the set of principles that would form the basis for the official draft PEA in November 2024. The draft PEA incorporates those principles and adds more detailed provisions. Especially notable is that the draft PEA requires all intermediary service providers and online platform operators—both Thai and foreign—to appoint a point of contact to liaise with the Electronic Transactions Development Agency (ETDA) if they have any users in Thailand. However, the draft PEA does not mandate establishment of a local entity in Thailand. Types of Intermediary Services The draft PEA sets out a three-tiered classification system for different types of service providers, ordered from fewest obligations to most: Intermediary services. Intermediary services are further divided into three subcategories: mere conduit, caching, and hosting. Each type of intermediary service has different safe harbor provisions, which define their scope and limitations. Online platform services. Online platform services are defined as involving “the provision of intermediary services in the hosting category that involve facilitating the matching of various types of users to enable transactions or interactions, whether or not a fee is charged. Additionally, such services may include other provisions to facilitate these transactions or interactions.” Key obligations for online platform providers include: Informing users of their rights and duties under relevant laws Implementing a notice-and-action mechanism Disclosing advertising information Publishing T&Cs, including details such as service fees, algorithms, and complaint management mechanisms. Very large online platform services. Very large online platform services (VLOPs) have extra duties beyond regular online platform services,
January 16, 2025
On January 13, 2025, Thailand’s cabinet approved in principle the draft Entertainment Complex Act, as proposed by the Ministry of Finance. This landmark legislative proposal, which would allow casinos as part of larger “entertainment complexes,” will now proceed through further parliamentary review and approval. Key provisions of the draft act are described below. Corporate structure: Entertainment complexes must be operated by Thai-registered limited companies or public limited companies with a minimum paid-up capital of THB 10 billion. Directors of the licensed entity must be individuals and have the qualifications and none of the prohibited characteristics specified in the draft act. The draft act does not impose restrictions on foreign-majority ownership structures; however, it is worth monitoring whether any amendments addressing this matter are introduced during the legislative process. Operating conditions: Each entertainment complex must be located in an area designated under a royal decree. It must also include at least four types of entertainment businesses listed in the annex to the draft act (e.g., shopping mall, hotel, sports stadium, amusement park), along with a casino. The allocation of casino space must comply with regulations to be specified at a later date. Licensing conditions: Licenses will be valid for 30 years, renewable in increments of up to 10 years. The license issuance fee is THB 5 billion, the annual fee is THB 1 billion, and the renewal fee is THB 5 billion. The Entertainment Complex Policy Committee, chaired by the prime minister, will review and approve applications. Online gambling restrictions: Licensees are prohibited from offering gambling through internet-connected systems or electronic devices that allow access from outside the casino premises. Labor requirements: Thai and foreign employee ratios must adhere to prescribed regulations. Land privileges: Lease agreements for land use are limited to 50 years. Renewal is permitted for up to
January 13, 2025
The State Bank of Vietnam’s Circular No. 50/2024/TT-NHNN regulating safety and security for the provision of online services in the banking sector (“Circular 50”), issued on October 31, 2024, took effect on January 1, 2025, with delayed effectiveness for certain provisions on (i) network, communication, and security systems, online banking application software, and mobile banking application software (July 1, 2025); (ii) transaction confirmation for payment transactions conducted via the straight-through processing method (January 1, 2026); and (iii) authentication forms and reporting obligations (July 1, 2026). The cybersecurity situation in Vietnam is complicated, and the banking and finance sector has been one of the top targets of high-tech criminals. Circular 50 seeks to enhance user protection by expanding the technical requirements to more services in the banking sector as well as standardizing how transactions are authenticated. Expanded Scope of Services Covered Previous regulations on safety and security of online services in the banking sector only covered banking services and intermediary payment services. Circular 50 expands the scope to include other services of credit institutions and foreign bank branches such as credit information services, foreign exchange services, securities depository services, and services related to factoring and letters of credit, which now need to comply with technical requirements and standards for online services such as firewalls and DMZ network barriers. Risk-Based Approach to Authentication Circular 50 sets out standards for payment transactions and card transactions by: Classifying various online transactions based on the type of client, the purpose of the transfer, the value of the specific transaction, and the total value of certain transactions during the day; and Applying various types of authentication for the corresponding types of online transactions, e.g., using passwords or PINs for small-value online transactions, and using OTPs (through SMS, voice, or email), biometric matching, or e-signatures for