You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 3, 2026

Bank of Thailand Proposes New Digital Channel Security Standards

On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026.

Background

The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements.

Expanded Scope of Regulated Entities and Channels

The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking.

Strengthened Customer Authentication

The draft introduces enhanced authentication requirements in three areas:

  • Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits.
  • Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases.
  • Secure authentication factors. Key requirements include the following:
    • “What-you-know” factors must protect against brute-force attacks.
    • “What-you-have” factors must use secure methods such as a registered mobile application with device binding or hard/soft tokens.
    • SMS OTPs must be discontinued for transaction authentication.
    • Biometric factors must use effective antispoofing technology, such as facial scanning, in compliance with the BOT’s guidelines on biometric technology in financial services.

Providers must cease sending SMS messages and emails containing embedded links and must establish incident response processes for counterfeit applications or websites.

Mobile Application Security Controls

Providers must ensure application integrity and block remote-access applications. Facial comparison with antispoofing technology is required for transfers exceeding THB 50,000 (approx. USD 1,490) per transaction or THB 200,000 (approx. USD 5,960) per day.

Next Steps

Affected financial service providers should assess their current systems against the draft requirements and consider submitting comments to the BOT by August 24, 2026.

RELATED INSIGHTS​ 

August 11, 2022
In July 2022, the Thai cabinet approved in principle a royal decree exempting some businesses and other entities from parts of the Personal Data Protection Act B.E. 2562 (PDPA). The draft royal decree proposes to exempt certain business operators and activities from the requirements of the following portions of the PDPA: Chapter II: Personal Data Protection – Consent, notification, cross-border transfer of the personal data requirements, etc. Chapter III: Rights of the Data Subject – Requirements and criteria on data subject rights. Chapter V: Complaints – Requirements on the submission of complaints to the Office of the Personal Data Protection Commission. Chapter VI: Civil Liability – Conditions in relation to the civil liability of a data controller or data processor. Chapter VII: Penalties – Administrative and criminal penalties. The proposed exemptions would apply to three main categories of business operators and activities: 1. Data controllers acting on government requests in adherence with specific laws for the following purposes: State security and public safety. Exempted operations include activities intended to safeguard state security, intelligence, and information relating to national security, as well as efforts to maintain fiscal and economic security and public security. Also exempt are prevention and suppression of certain criminal activities, such as money laundering, drug trafficking, transnational threats and terrorism, transnational crime, and human trafficking; activities to bolster anticorruption or cybersecurity efforts; and actions relating to public health, sanitation to prevent epidemics, and protection of public life, health, and property. Taxation. Exempted activities include those related to tax collection under laws that are the responsibility of the Revenue Department, Customs Department, or Excise Department. This also extends to any action relating to the enforcement of taxation fees or duties, and actions related to social security, the performance of obligations, or international cooperation. Risk mitigation, monitoring, and surveillance.
July 31, 2022
Thailand’s Securities and Exchange Commission (SEC) has announced three new regulatory requirements, which primarily require digital asset business operators to provide investors with training or a knowledge test on cryptocurrencies and to disclose information about the quality of their service and IT usage capacity. The amended SEC notification detailing these new obligations was promulgated on July 1, 2022; however, the measures come into effect separately, as detailed below. Training or Testing on Cryptocurrency From August 30, 2022, cryptocurrency exchanges, brokers, and dealers must provide guidance and education to their clients on basic asset allocation suitable to their capacity. These types of digital asset business operators must also provide for training or a knowledge test on cryptocurrency. The content should at least cover cryptocurrency, blockchain technology, digital wallets, and an overview of the market and investments. The following types of clients are exempted from these requirements: Existing clients of the digital asset business operators before July 1, 2022; New clients of the operator who already have experience investing in cryptocurrency before using the service of the business operator; and Institutional investors, ultra-high-net-worth investors, and high-net-worth investors. If the clients are legal entities other than those mentioned above, their representatives or appointed persons are required to undergo training or testing. The training or knowledge test is a prerequisite to using a digital asset business operator’s services. Operators are not allowed to provide their services to clients who do not undergo training or testing. Disclosure of Service Quality and IT Usage Capacity From January 1, 2023, cryptocurrency/digital token exchanges, brokers, and dealers are required to disclose to the SEC information about the quality of their services (including any technological errors and complaints from clients), and their IT usage capacity. For more information about the latest SEC rules and regulations for digital assets,
July 25, 2022
Vietnam’s current Law on E-Transactions was passed in 2005 and has been effective since March 1, 2006. This law is considered a framework law, developed based on the Model Law on E-Commerce of the United Nations Commission on International Trade Law (UNCITRAL). According to the Ministry of Information and Communications (MIC), over the past 17 years, the implementation and application of e-transactions has shown significant evolution in certain areas demanding high levels of international integration, such as banking and e-commerce, but has faced difficulties in other areas due to a lack of detailed guidance. In addition, with the strong growth and breakthrough development of digital technologies such as artificial intelligence, big data, biometrics, and blockchain, and in the context of the ongoing Industrial Revolution 4.0 and the development of digital government, digital economy, and digital society, the 2005 Law on E-Transactions has revealed its shortcomings. Therefore, the government of Vietnam has entrusted the MIC to take the lead in drafting a new Law on E-Transactions, which will replace the old 2005 law in order to meet the country’s development needs. Accordingly, the MIC published a Draft Law on E-Transactions (“Draft Law”) for public consultation from May 4 to July 4, 2022. The latest accessible version of the Draft Law at the time of writing is Version 4. The effective date of the Draft Law is still not yet determined, though this law is expected to be submitted to the National Assembly for its review and comments in October 2022 and approval in May 2023. The following are some key contents of the Draft Law: 1. Scope of Application Unlike the current law, which explicitly excludes certain areas such as the issuance of certificates of land use rights and marriage certificates from the scope of application, the Draft Law attempts
July 19, 2022
On June 23, 2022, Thailand’s Securities and Exchange Commission (SEC) opened a public hearing period on regulatory controls for initial coin offering (ICO) portals that serve as financial advisors to digital token issuers. The proposed measures aim to prevent conflicts of interest; allow ICO portals to outsource certain functions; and establish additional notification obligations for ICO portals. The public hearing is open for general comments until July 23, 2022, and the new legislation is expected to be issued soon after that. During the public hearing period, any interested parties can comment on the SEC’s proposed principles. The key proposed points are outlined below. Conflicts of Interest Similar to SEC-approved financial advisors for securities offerings, ICO portals must be clear of conflicts of interest when representing issuers in a coin offering. According to the draft regulation, the following conflicts of interest are prohibited: The ICO portal (and certain individuals as specified by the SEC) directly or indirectly holds a prohibited amount of shares in the issuer, its affiliates, or its subsidiaries. If the issuer is not a listed company, any shareholding or portion thereof is prohibited. If the issuer is a listed company on the Stock Exchange of Thailand (SET), the shares held by the ICO platform may not total more than five percent of the total voting rights. The issuer (and certain individuals as specified by the SEC) directly or indirectly holds shares in the ICO portal in any amount if the ICO portal is not a listed company, or totaling more than five percent of the voting rights if the ICO portal is listed on the SET. Any of the ICO portal’s directors or executives, or the head of the department responsible for screening the ICO project, is also a director in the issuer. The ICO portal has