You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 3, 2026

Bank of Thailand Proposes New Digital Channel Security Standards

On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026.

Background

The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements.

Expanded Scope of Regulated Entities and Channels

The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking.

Strengthened Customer Authentication

The draft introduces enhanced authentication requirements in three areas:

  • Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits.
  • Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases.
  • Secure authentication factors. Key requirements include the following:
    • “What-you-know” factors must protect against brute-force attacks.
    • “What-you-have” factors must use secure methods such as a registered mobile application with device binding or hard/soft tokens.
    • SMS OTPs must be discontinued for transaction authentication.
    • Biometric factors must use effective antispoofing technology, such as facial scanning, in compliance with the BOT’s guidelines on biometric technology in financial services.

Providers must cease sending SMS messages and emails containing embedded links and must establish incident response processes for counterfeit applications or websites.

Mobile Application Security Controls

Providers must ensure application integrity and block remote-access applications. Facial comparison with antispoofing technology is required for transfers exceeding THB 50,000 (approx. USD 1,490) per transaction or THB 200,000 (approx. USD 5,960) per day.

Next Steps

Affected financial service providers should assess their current systems against the draft requirements and consider submitting comments to the BOT by August 24, 2026.

RELATED INSIGHTS​ 

January 23, 2024
The Bank of Thailand (BOT) has issued a new notification to sustainably address Thailand’s household debt problems by establishing responsible and fair lending requirements for lending service providers throughout their lending journey. Notification No. SorKorChor. 7/2566 Re: Provision of Responsible and Fair Lending was announced on December 21, 2023, and took effect on January 1, 2024. The lending service providers this notification applies to include both commercial banks and nonbank business operators (e.g., personal loan business operators, nano-financing business operators, and credit card business operators). The key principle of this notification is to provide criteria for responsible and fair lending that supplement market conduct principles, covering eight areas in the debt cycle: Lending product development. Service providers must offer lending products that are suitable to customers’ needs and repayment capabilities, avoiding encouragement of excessive debt. Loan interest rates should align with the borrower’s risk profile and credit characteristics (risk-based pricing) to ensure fair contract conditions. Advertising. Service providers must prepare and control advertisements with “correct and clear” content, presenting complete and comparable conditions, interest rates, and various fees to customers. The advertisements should not encourage excessive debt, enabling customers to make informed decisions and promoting financial discipline. Sales. In the selling process, service providers must ensure that customers receive complete, accurate, and unexaggerated information that facilitates appropriate consideration of decisions based on a correct understanding of the product or service. Products should also align with customers’ purposes or needs for fund utilization, avoiding encouragement of excessive debt. Consideration of debt repayment ability (affordability). Service providers must be conscientious in considering customers’ debt repayment ability, taking into account all obligations and residual income. Promotion of discipline and financial management. Service providers must provide important information and warnings to debtors, including regular reminders to promote responsible borrowing. Helping debtors with persistent debt.
January 19, 2024
On November 24, 2023, the National Assembly of the Socialist Republic of Vietnam adopted Law No. 24/2023/QH15 on Telecommunications (“Telecom Law 2023”) after a lengthy period of extensive discussions and revisions. The Telecom Law 2023 is set to take effect on July 1, 2024, except for the requirements relating to basic telecom services on the internet (otherwise known as over-the-top services, or “OTT”), data center services, and cloud computing services, which will take effect on January 1, 2025. Some important highlights of the Telecom Law 2023 are discussed below. Updates on Telecom License Requirements With a few exceptions and save for certain types of telecom services, enterprises in Vietnam are required to obtain Telecom Licenses in order to provide telecom services. There are two types of Telecom Licenses: licenses for the provision of telecom services, and licenses for telecom operations. Telecom Licenses can be granted in two forms. The first is separate licensing, which is for telecom services with network infrastructures that use radio frequencies or operate in areas with special requirements set by the government. The second is group licensing, which covers telecom services with network infrastructure (except in certain cases), telecom services without network infrastructure (except in certain cases), and telecom operations. New Regulations for OTT, Data Center, and Cloud Computing Services The Telecom Law 2023 provides the definitions for OTT services, data center services, and cloud computing services, recognizing them as different types of telecom services. It also outlines the rights and obligations of service providers in these fields. Regarding market-entry conditions, foreign direct investments in OTT services, data center services, and cloud computing services are subject to no restrictions on share ownership ratio or capital contribution. Foreign investors can establish 100% foreign-owned enterprises in Vietnam to offer these services. Enterprises offering these services are not
January 12, 2024
Thailand’s Revenue Department (RD) has issued a notification requiring electronic platforms to report their revenue from business operators on their platform. With this information, the RD intends to track business operators’ income from the sale of goods and services through electronic platforms in order to facilitate accurate and efficient tax collection. The notification, which was enacted on December 27, 2023, took effect on January 1, 2024. Under the notification, electronic platforms are required to compile a “special account” containing information on the revenue received from each business operator on their platform and submit it to the RD through the department’s electronic reporting system within 150 days of the end of the fiscal year. The notification defines “electronic platforms” as entities that intermediate between business operators (i.e., sellers of goods or providers of services via the electronic platform) and consumers for the purpose of enabling electronic transactions between the parties. This covers online marketplace operators, ride-hailing operators, food delivery operators, and so on. This reporting requirement applies to electronic platforms registered in Thailand that have (or previously had, starting from the notification’s effective date) annual revenue exceeding THB 1 billion (approx. USD 28.5 million), except for electronic platforms under the supervision of the Bank of Thailand or the Office of the Securities and Exchange Commission, such as payment service providers and cryptocurrency exchanges. Electronic platforms can appoint a third party to prepare and submit the required special account information to the RD on their behalf. Compliance Steps As the requirements established by this notification mean that the RD will now have direct access to information on the income earned by vendors and merchants on electronic platforms, these business operators—whether corporate or individual—should ensure that they faithfully disclose their earnings, submit tax payments correctly, and file income tax returns in a
January 9, 2024
As of January 1, 2024, all films distributed in cyberspace in Vietnam must display ratings and warnings (if required) for viewers, following the phased-in effectiveness of Decree No. 131/2022/ND-CP of the Government dated December 31, 2022, guiding the implementation of the Law on Cinematography (Decree 131). While Decree 131 took effect on January 1, 2023 (the same date as the Law on Cinematography), it provided a grace period of one year for films to be distributed in cyberspace without the display of ratings or warnings. Now, for continued distribution in cyberspace of such films, distributors must add ratings and warnings in compliance with regulations issued under Circular No. 05/2023/TT-BVHTTDL of the Ministry of Culture, Sports and Tourism (MOCST) dated April 5, 2023 (Circular 05). Film Rating Film distributors can either carry out the film rating by themselves or request the MOCST to provide the rating. In the former case, the distributor must request the MOCST to recognize its eligibility for self-rating. (Based on our experience successfully obtaining this recognition for a client, this procedure may take about two to three months for completion, depending on the availability of required information and materials.) If a distributor cannot obtain recognition for film self-rating eligibility, it must request the MOCST to provide the film rating for each and every film it distributes in cyberspace. Display of Ratings and Warnings Circular 05 requires that the film rating must be displayed clearly and prominently in the introduction of a film in order for a user to make an informed decision to access that film or not. Moreover, the rating must be displayed on the left or right corner of the screen during the entire distribution time. Warning contents must be in words or sound which must be displayed three seconds after the beginning of