You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 3, 2026

Bank of Thailand Proposes New Digital Channel Security Standards

On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026.

Background

The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements.

Expanded Scope of Regulated Entities and Channels

The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking.

Strengthened Customer Authentication

The draft introduces enhanced authentication requirements in three areas:

  • Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits.
  • Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases.
  • Secure authentication factors. Key requirements include the following:
    • “What-you-know” factors must protect against brute-force attacks.
    • “What-you-have” factors must use secure methods such as a registered mobile application with device binding or hard/soft tokens.
    • SMS OTPs must be discontinued for transaction authentication.
    • Biometric factors must use effective antispoofing technology, such as facial scanning, in compliance with the BOT’s guidelines on biometric technology in financial services.

Providers must cease sending SMS messages and emails containing embedded links and must establish incident response processes for counterfeit applications or websites.

Mobile Application Security Controls

Providers must ensure application integrity and block remote-access applications. Facial comparison with antispoofing technology is required for transfers exceeding THB 50,000 (approx. USD 1,490) per transaction or THB 200,000 (approx. USD 5,960) per day.

Next Steps

Affected financial service providers should assess their current systems against the draft requirements and consider submitting comments to the BOT by August 24, 2026.

RELATED INSIGHTS​ 

October 19, 2021
On September 9, 2021, Laos announced a new pilot program to allow the mining and trading of cryptocurrency. Notification No. 1158, issued by the Prime Minister’s Office, provides for an electricity sale-purchase agreement with six companies involved in the pilot program. Under the notification, the six companies authorized by the prime minister to mine and trade cryptocurrency in Laos will pay a capped fee for energy they use in data processing or mining cryptocurrency. This effectively establishes a sandbox in which these six companies may mine and trade cryptocurrency—including on international cryptocurrency exchanges. The Ministry of Technology and Communications (MTC) is in charge of coordinating the program, together with the Ministry of Finance, the Bank of the Lao PDR, the Ministry of Planning and Investment, the Ministry of Energy and Mines, the Ministry of Public Security, and Électricité du Laos. The MTC is also charged with drafting the rules of the pilot program and setting the conditions on which the participating companies can mine, sell, and purchase cryptocurrency in Laos. One of the six selected companies will also act as a coordinator for the other companies and report to the government on any benefits of cryptocurrency observed during the pilot program. The next step is for the MTC to compile data analysis from each of the other government agencies and submit the conclusions to a meeting of the prime minister and the deputy prime ministers before the pilot program is implemented. The pilot program was originally scheduled to start in September, but there has not yet been any update on the implementation of the program, which nonetheless is expected to start in the near future.
October 19, 2021
In September 2021, the Bank of Thailand (BOT) issued its Guidelines on Data Governance to provide financial institutions with recommendations on how to ensure that their data governance will be in compliance with accepted international principles. While there are no penalties for noncompliance, financial institutions should view the recommendations as minimum standard expectations for their data governance in Thailand. The BOT guidelines set forth five main data governance principles: Data Governance Policy Financial institutions should set forth their data governance policy in writing in accordance with their business size, business operations, business complexity, and data risk. The policy should cover all types of data, including data related to services from third parties or business partners, as well as provide information on the data governance structure, data lifecycle management, protection of data security and data privacy, and incident management. Financial institutions should inform their employees and other relevant parties of the policy to ensure their compliance. In addition, the data governance policy must be approved by the designated board or committee of the financial institution, and be reviewed and revised in response to significant changes. Data Governance Structure Financial institutions should establish a data governance structure with three lines of defense, supervised by an oversight committee. The first line of defense comprises data management personnel, a data approver, and data users; the second comprises a risk management unit and a compliance unit; and the third is an audit unit. While the chosen data governance structure can be tailored to the characteristics of the institution, the structure should cover all of these roles and duties, and must not contravene the principle of checks and balances. The data governance structure should also be supported by sufficient personnel and equipment, as well as a clear plan—reviewed and revised as necessary—for building awareness at
October 15, 2021
In September 2021, Thailand’s Electronic Transactions Development Agency (ETDA) issued an updated draft royal decree for digital platforms—a potentially far-reaching royal decree that was the subject of a public hearing in July 2021. The ETDA made the changes in response to a considerable amount of feedback and comments from business operators and other stakeholders. The key changes to the draft royal decree are outlined below. Definitions The updated draft broadens the definition of digital platforms subject to the royal decree by removing mention of offering goods, services, or intangible assets, and by deleting a phrase related to contract issues. As a result, “digital platform” currently refers to any intermediary digital platform that provides a connection space for “business operators on a digital platform” and “consumers” via a computer network. Similarly, the definitions of “business operators on a digital platform” and “consumers” have been amended by excluding the offering of intangible assets through digital platforms, and the draft emphasizes that business operators on a digital platform are not included in the definition of consumers. Notification Exemption Under the updated draft royal decree, a digital platform provider under the supervision of other authorities or falling under the Electronic Transactions Commission’s list of exempted digital platform providers is exempted from the requirement to notify the ETDA of the operation of its digital platform. The commission may also exempt any other digital platform service as it sees fit. Extraterritorial Effect The draft provisions subjecting certain digital platforms located outside Thailand to the royal decree and requiring them to appoint a local representative in Thailand have been updated by removing the requirement to issue a tax invoice to consumers in Thailand. Furthermore, the updated draft makes the local representative subject to the reporting obligations and cessation requirements, whereas these obligations were not prescribed in
October 14, 2021
As part of its membership in Lex Mundi, Tilleke & Gibbins has published an updated edition of its Guide to Doing Business in Thailand for 2021. This guide outlines all of the key factors for starting and operating a business in the Thai market. Issues covered include: Investment incentives Financial facilities Exchange controls Import and export regulations Structures for doing business Requirements for the Establishment of a Business Operation of the Business Cessation or Termination of the Business Labor legislation, relations, and supply Tax Immigration requirements This publication is part of Lex Mundi’s Guides to Doing Business series prepared by member firms in more than 100 jurisdictions worldwide. The guides serve as a useful resource when planning an international business strategy or researching a new market.