You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 3, 2026

Bank of Thailand Proposes New Digital Channel Security Standards

On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026.

Background

The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements.

Expanded Scope of Regulated Entities and Channels

The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking.

Strengthened Customer Authentication

The draft introduces enhanced authentication requirements in three areas:

  • Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits.
  • Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases.
  • Secure authentication factors. Key requirements include the following:
    • “What-you-know” factors must protect against brute-force attacks.
    • “What-you-have” factors must use secure methods such as a registered mobile application with device binding or hard/soft tokens.
    • SMS OTPs must be discontinued for transaction authentication.
    • Biometric factors must use effective antispoofing technology, such as facial scanning, in compliance with the BOT’s guidelines on biometric technology in financial services.

Providers must cease sending SMS messages and emails containing embedded links and must establish incident response processes for counterfeit applications or websites.

Mobile Application Security Controls

Providers must ensure application integrity and block remote-access applications. Facial comparison with antispoofing technology is required for transfers exceeding THB 50,000 (approx. USD 1,490) per transaction or THB 200,000 (approx. USD 5,960) per day.

Next Steps

Affected financial service providers should assess their current systems against the draft requirements and consider submitting comments to the BOT by August 24, 2026.

RELATED INSIGHTS​ 

September 30, 2021
Thailand’s Board of Investment has consolidated its definition of promoted business activities in the digital space, replacing promotions for e-commerce, digital services, and software, with a single category for “Development of software, platform for digital services, or digital content.”
September 27, 2021
Multilaw has published its new Global Data Protection Guide, which collects expert advice from Multilaw’s member firms in over 50 jurisdictions globally. The guide provides answers to key issues concerning the fast-developing data protection and privacy laws around the world, and helps data protection officers and in-house counsel understand how the regulatory regime for data protection can affect their organizations in various jurisdictions. Each section of the guide identifies the main laws that govern data protection in that jurisdiction, and gives a detailed overview of the legal principles in place as well as the enforcement authorities responsible for overseeing compliance. The guide also covers issues related to data subject rights, data protection officers, impact assessments, data breach notification requirements, and cross border data transfers. The use of personal data in marketing is also considered, with specific information on electronic marketing rules, cookies, and marketing to businesses and consumers. Multilaw is a global network of carefully selected, independent law firms consisting of over 10,000 commercial lawyers in more than 100 countries, able to provide expert legal advice in complex environments around the globe. The full guide is available for free on the Multilaw website.
September 24, 2021
On September 15, 2021, Thailand’s Securities and Exchange Commission (SEC) announced a prospective new scheme that will enable small and medium enterprises (SMEs) and startups in Thailand to raise funds through public offerings. The SEC regulations to implement this new scheme are expected by the first quarter of 2022. Since 2019, the SEC has allowed SMEs and startups in Thailand to raise funds via private placements or crowdfunding. The new SEC scheme will allow SMEs and startups to raise funds on a larger scale via a new type of public offering (the so-called SME-PO). The SEC also plans to establish the “SME Board,” a secondary market for trading the stocks of SMEs. Under the new SEC scheme, SMEs and startups that wish to proceed with an SME-PO must be structured as public companies with investor protection mechanisms in accordance with the Public Company Act B.E. 2535 (1992). Although SEC representatives have previously indicated that SME-POs would be subject to an information-based approach instead of the normal approval process for public offerings, the September 15 announcement does not detail this further, beyond noting that the SEC may deem it appropriate in future to relax certain requirements such as filing for approval, appointment of an independent financial advisor, and fees. Investors in public offerings for SMEs and startups must be sophisticated investors who are risk-tolerant and well capitalized, such as institutional investors, private equity or venture capital firms, angel investors, or an SMEs’ own directors, employees, or affiliates. Tilleke & Gibbins will continue to follow the development of regulations for SME-POs, as the rules and criteria described here are still subject to change. For more information on fundraising alternatives for SMEs and startups, or on any aspect of capital markets regulations in Thailand, please contact Onunya Chanpen at [email protected] or Kobkit Thienpreecha