You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 3, 2026

Bank of Thailand Proposes New Digital Channel Security Standards

On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026.

Background

The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements.

Expanded Scope of Regulated Entities and Channels

The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking.

Strengthened Customer Authentication

The draft introduces enhanced authentication requirements in three areas:

  • Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits.
  • Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases.
  • Secure authentication factors. Key requirements include the following:
    • “What-you-know” factors must protect against brute-force attacks.
    • “What-you-have” factors must use secure methods such as a registered mobile application with device binding or hard/soft tokens.
    • SMS OTPs must be discontinued for transaction authentication.
    • Biometric factors must use effective antispoofing technology, such as facial scanning, in compliance with the BOT’s guidelines on biometric technology in financial services.

Providers must cease sending SMS messages and emails containing embedded links and must establish incident response processes for counterfeit applications or websites.

Mobile Application Security Controls

Providers must ensure application integrity and block remote-access applications. Facial comparison with antispoofing technology is required for transfers exceeding THB 50,000 (approx. USD 1,490) per transaction or THB 200,000 (approx. USD 5,960) per day.

Next Steps

Affected financial service providers should assess their current systems against the draft requirements and consider submitting comments to the BOT by August 24, 2026.

RELATED INSIGHTS​ 

January 29, 2026
Following the recent enactment of a comprehensive legal framework addressing sexual harassment, Thailand has launched a fast-track judicial process enabling victims of online sexual harassment to obtain court orders suspending and removing obscene content from the internet. On January 26, 2026, the Office of the Judiciary introduced the “Take It Down” procedure through the Court Integral Online Service (CIOS) platform, providing victims with their first direct, expedited pathway to halt the spread of online content that violates the new legal provisions against sexual harassment. This new remedy stems from section 284/4 of the Penal Code, introduced through the Act Amending the Penal Code (No. 30) B.E. 2568, which took effect on December 30, 2025. Under section 284/4, an injured person or a competent official may petition the court to suspend dissemination of violating data and remove the data from computer systems within a court-specified period. The court may also direct system controllers, service providers, or competent authorities to carry out the order and report back within 15 days. Filing through the CIOS Platform The CIOS platform serves as the primary electronic channel for these petitions. Key features include: Individuals can file online without appearing in person and may submit petitions at any time the system is available. Users must complete digital identity verification via the ThaID application to access the CIOS. Petitions under section 284/4 are limited to requests to suspend or remove violating content. Claims for monetary damages must be pursued separately, including via separate proceedings or prefiling mediation. Streamlined Review Process The submission workflow is end-to-end electronic, and the system provides step-by-step guidance. After submission, court staff review the petition before presenting it to a judge for consideration. The court may conduct an online inquiry to obtain additional information, and in-person attendance is required only if deemed
January 23, 2026
On December 31, 2025, the State Bank of Vietnam (SBV) issued Circular No. 72/2025/TT-NHNN (Circular 72), establishing a streamlined foreign exchange framework for Vietnam’s International Financial Center (IFC). Circular 72, which took effect on the same day, implements core provisions of Decree No. 329/2025/ND-CP and marks a fundamental shift from ex ante licensing to ex post supervision for IFC member enterprises and foreign investors. These changes are designed to accelerate capital flows, reduce compliance costs, and position Vietnam as a competitive regional financial hub by granting IFC members substantially greater autonomy in currency transactions, borrowing, lending, and investment activities. Key provisions for IFC members to note are discussed below. Use of Foreign Currency and Payments within the IFC Vietnam generally requires the use of Vietnamese dong for transactions within the country, with limited exceptions. This can be burdensome for foreign investors, who may be unfamiliar with all the foreign exchange rules they must comply with. Under the new regulation, IFC member enterprises and foreign investors gain the ability to transact, list prices, and settle obligations in foreign currency when dealing with other IFC members or offshore counterparties, avoiding currency risk and conversion friction. With respect to individuals and organizations located within Vietnam who are not IFC members, the use of foreign currency must continue to comply with general restrictions on foreign exchange usage within Vietnam. Dual-Track Account System for IFC Members The new regulation introduces a two-tier account structure that differentiates transactions by purpose and counterparty. IFC member enterprises must use a designated foreign currency capital account at an IFC member bank for four specified activities: Borrowing from offshore individuals and organizations Lending to offshore entities and domestic borrowers Outbound investing from the IFC Investing elsewhere in Vietnam from the IFC All other foreign exchange transactions—including operational receipts, vendor
January 22, 2026
On January 20, 2026, Vietnam’s Ministry of Finance (MOF) issued Decision No. 96/QD-BTC to formally launch pilot administrative procedures for licensing crypto asset trading market services in Vietnam. The decision took immediate effect and implements the government’s pilot crypto asset market program under Resolution No. 05/2025/NQ-CP. Notably, competent authorities have now begun accepting license applications, marking the first time Vietnam has operationalized a licensing pathway for crypto trading market operators. Administrative Procedures and Applications The decision stipulates procedures for (i) granting, (ii) adjusting, and (iii) revoking licenses to provide services for organizing crypto asset trading markets. It provides detailed, step-by-step guidance for each procedure, including dossier composition, internal review stages, coordination mechanisms, and statutory timelines. These procedures apply specifically to entities seeking to organize and operate crypto asset trading markets within Vietnam’s pilot regulatory framework. The MOF is the authority responsible for reviewing and deciding on the above procedures, with the State Securities Commission acting as the receiving, coordinating, and procedural focal point. For licensing applications, the MOF will coordinate with multiple authorities, including the State Bank of Vietnam and the Ministry of Public Security, particularly in relation to anti-money laundering, cybersecurity, system safety, and risk control requirements. Applications may be submitted in person, by post, or electronically via the National Public Service Portal or the administrative procedure information system, in line with applicable regulations. Statutory processing timelines vary depending on the specific procedure and stage involved. For applications to obtain a license to organize a crypto asset trading market, the process is conducted in multiple phases: The MOF will issue an initial written response within 20 working days from receipt of a complete and valid initial dossier, following which, upon submission of the full set of required documents, the MOF will complete substantive review and issue the license
January 21, 2026
On January 16, 2026, Thailand’s Electronic Transactions Committee released for public comment a draft notification that would require social media platforms operating in Thailand to implement identity verification for all user accounts and advertisers, with enhanced scrutiny for high-risk advertising activities. If finalized in its current form, the Notification on Measures to Prevent Technology Crime for Social Media Service Providers would take effect 180 days after publication in the Government Gazette, fundamentally changing how platforms verify users and monetize advertising services. The public comment period is open through February 2, 2026. Mandatory User and Advertiser Identity Verification The draft establishes a universal requirement that all social media service providers implement identity verification measures for every user account. The draft imposes stricter verification obligations for advertisers than for general users. Before publishing any advertisement, platforms must verify the advertiser’s identity at a level sufficient to identify the advertiser, unless the advertiser has previously completed verification. Risk-Based Advertisement Verification The identification requirements for advertisers will be more stringent in the following cases: The advertiser has a history of user complaints or has previously violated the platform’s terms of service. The advertisement involves finance, investment, loans, sensitive personal data, or content flagged as potentially involving cybercrime. The advertisement specifically targets vulnerable groups, such as the elderly or other at-risk demographics. In such cases, platforms must conduct identity verification using government-issued identification documents and must confirm the accuracy, authenticity, and currency of these documents with the issuing government agencies. Alternatively, platforms may verify identity through an eligible digital identity verification and authentication system provider. Information Retention Platforms must retain specific information for each advertiser, including the name of the individual or juristic person and any representatives, government-issued identification documents such as ID cards, passports, or certificates of incorporation, and reachable contact information including