You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 3, 2026

Bank of Thailand Proposes New Digital Channel Security Standards

On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026.

Background

The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements.

Expanded Scope of Regulated Entities and Channels

The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking.

Strengthened Customer Authentication

The draft introduces enhanced authentication requirements in three areas:

  • Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits.
  • Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases.
  • Secure authentication factors. Key requirements include the following:
    • “What-you-know” factors must protect against brute-force attacks.
    • “What-you-have” factors must use secure methods such as a registered mobile application with device binding or hard/soft tokens.
    • SMS OTPs must be discontinued for transaction authentication.
    • Biometric factors must use effective antispoofing technology, such as facial scanning, in compliance with the BOT’s guidelines on biometric technology in financial services.

Providers must cease sending SMS messages and emails containing embedded links and must establish incident response processes for counterfeit applications or websites.

Mobile Application Security Controls

Providers must ensure application integrity and block remote-access applications. Facial comparison with antispoofing technology is required for transfers exceeding THB 50,000 (approx. USD 1,490) per transaction or THB 200,000 (approx. USD 5,960) per day.

Next Steps

Affected financial service providers should assess their current systems against the draft requirements and consider submitting comments to the BOT by August 24, 2026.

RELATED INSIGHTS​ 

June 26, 2024
Tilleke & Gibbins’ Fintech Law in Southeast Asia provides fintech operators and service providers with an overview of relevant regulations across all of our full-service jurisdictions—Cambodia, Laos, Myanmar, Thailand, and Vietnam.
June 21, 2024
On June 4, Thailand’s Ministry of Commerce (MOC) issued a new notification on e-commerce business registration pursuant to the Commercial Registration Act B.E. 2499 (1956) (CRA), replacing a similar notification from 2010. The new notification (officially titled “Notification Re: Business Regulations that Commercial Operators Must Register and Businesses that Are Not Subject to the Commercial Registration Act, B.E. 2549 B.E. 2567”) took effect on June 5, 2024. While the previous notification required all individuals and legal entities engaged in regulated activities, such as selling goods or services online, to register their businesses with the local district office, the new notification effectively lifts this requirement for certain legal entities. The new notification clearly states that the CRA does not apply to regulated activities conducted by: Private limited companies, registered ordinary partnerships, and limited partnerships (i.e., legal entities under the Civil and Commercial Code); and Public limited companies (i.e., legal entities under the Public Limited Companies Act). Now that the new notification is in effect, limited companies and other specified legal entities are no longer required to register their e-commerce activities and obtain an e-commerce certificate from the MOC. E-commerce certificates previously issued to these legal entities are also voided by the new notification. Nevertheless, the requirement to register for direct marketing and obtain a direct marketing certificate under the Direct Sales and Direct Marketing Act B.E. 2545 (2002) remains in effect for any online sales or e-marketplace platforms administered by legal entities. Given the recent proactive enforcement of penalties for noncompliance with direct marketing registration requirements, we strongly advise business operators to assess whether their operations fall within the scope of direct marketing regulations and require a direct marketing certificate. For more information on e-commerce and direct marketing registration in Thailand, please contact Athistha (Nop) Chitranukroh at [email protected], Nopparat Lalitkomon
June 19, 2024
Vietnam’s financial landscape is set to further transform on July 1, 2024, when the government’s long-awaited Decree No. 52/2024/ND-CP dated May 15, 2024 (“Decree 52”), will officially replace Decree No. 101/2012/ND-CP dated November 22, 2012, on non-cash payments (“Decree 101”). Decree 52 marks an important milestone by introducing the country’s first-ever legal definition of e-money. In addition, the decree brings forth new updates to regulations governing payment and intermediary payment services, laying the groundwork for more comprehensive guidance that will be provided in draft circulars now being developed by the State Bank of Vietnam (SBV). Non-Cash Payment Instruments The new definition of non-cash payment instruments under Decree 52 expands upon the previous definition in Decree 101. Notably, it clearly specifies the issuing entities as payment service providers, financial companies licensed to issue credit cards, and e-wallet service providers. Additionally, the new definition further clarifies that bank cards include debit, credit, and prepaid cards, and adds e-wallets to the list of non-cash payment instruments. Unlawful non-cash payment instruments are still defined as those that are not otherwise specified. E-Money Prior to Decree 52, the concept of e-money lacked a precise legal definition, despite its growing prevalence in forms like prepaid cards and e-wallets. The absence of a clear framework for e-money led to confusion with terms like “cryptpcurrency” and “virtual currency” and left significant ambiguity on whether e-money includes certain instruments, such as online game cards and mobile money. Decree 52 addresses this issue by clearly defining e-money as value in Vietnamese dong (VND) stored electronically and prepaid by customers to banks, foreign bank branches, and e-wallet service providers. It also specifically designates e-wallets and prepaid cards as types of storage mechanisms for e-money. Non-Cash Payment Services Decree 52 categorizes non-cash payment services into services with and without client payment
June 19, 2024
On June 14, 2024, the Personal Data Protection Committee (PDPC) released a draft notification under the Personal Data Protection Act 2019 (PDPA), setting out criteria for how data controllers must delete, destroy, and de-identify personal data. According to the PDPA, a data subject can request that a data controller delete, destroy, or de-identify their personal data in any of the following circumstances: The personal data is no longer necessary for the purposes for which it was collected, used, or disclosed. The data subject has withdrawn their consent for the processing of the personal data, and no other lawful basis for processing remains. The data subject has objected to the processing of their personal data on grounds of legitimate interests or official tasks, the data controller has no other compelling grounds to refuse the request, and the data is not needed for legal claims. The data subject objects to the processing of their personal data for direct marketing purposes. The processing of personal data is unlawful. The draft stipulates that data controllers respond to a data subject’s request to delete, destroy, or de-identify personal data immediately, and within 60 days of receiving the request. If the data controller cannot fulfill the request immediately, they must take interim measures to ensure that the personal data is made difficult to collect, use, or disclose. This includes implementing measures such as preventing access to the data and applying appropriate security measures to protect the data from unauthorized use or disclosure. De-identification or Anonymization of Personal Data In certain circumstances, a data controller may opt to de-identify or anonymize personal data, rather than delete or destroy it. If doing so, the data controller must satisfy the following criteria: There must be a structured process to remove or eliminate all direct identifiers linked to the