You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 3, 2026

Bank of Thailand Proposes New Digital Channel Security Standards

On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026.

Background

The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements.

Expanded Scope of Regulated Entities and Channels

The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking.

Strengthened Customer Authentication

The draft introduces enhanced authentication requirements in three areas:

  • Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits.
  • Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases.
  • Secure authentication factors. Key requirements include the following:
    • “What-you-know” factors must protect against brute-force attacks.
    • “What-you-have” factors must use secure methods such as a registered mobile application with device binding or hard/soft tokens.
    • SMS OTPs must be discontinued for transaction authentication.
    • Biometric factors must use effective antispoofing technology, such as facial scanning, in compliance with the BOT’s guidelines on biometric technology in financial services.

Providers must cease sending SMS messages and emails containing embedded links and must establish incident response processes for counterfeit applications or websites.

Mobile Application Security Controls

Providers must ensure application integrity and block remote-access applications. Facial comparison with antispoofing technology is required for transfers exceeding THB 50,000 (approx. USD 1,490) per transaction or THB 200,000 (approx. USD 5,960) per day.

Next Steps

Affected financial service providers should assess their current systems against the draft requirements and consider submitting comments to the BOT by August 24, 2026.

RELATED INSIGHTS​ 

March 10, 2022
On March 7, 2022, the government of Vietnam issued Resolution No. 27/NQ-CP (“Resolution 27”) approving the promulgation of the latest version of the Draft Decree on Personal Data Protection (“Draft PDPD”) prepared by the Ministry of Public Security (“MPS”), and further instructed the MPS to pass this draft to the National Assembly’s Standing Committee for final consideration. Although the full content of the approved Draft PDPD has not been made available to the public, Resolution 27 clearly sets out several circumstances approved by the government in which processing of personal data can be carried out without the consent of the data subjects. In comparison with the corresponding provision under the widely seen version of the Draft PDPD made available to the public in February 2021 (“February Draft”), the main differences are as follows: If the data processing is necessary in response to an emergency situation that threatens the life, health, or safety of the data subject or other individual, the data controller, data processor, data controller/processor, or a third party can process the personal data without consent of the data subject, but they are responsible for proving that the situation is an emergency. The February Draft did not mention any requirement of proof. Moreover, “safety of the data subject or other individual” is a newly added criterion for personal data processing without consent under this circumstance. If the data processing is necessary because of national defense and security requirements, the processing must be carried out by competent authorities in accordance with other laws. The requirement that the processing must be carried out “by competent authorities” in this circumstance was not provided under the February Draft. Two circumstances have been removed: the processing of personal data in compliance with specific provisions that explicitly allow the processing of personal data without
March 8, 2022
On February 15, 2022, Thailand’s cabinet approved in principle a package of incentives to promote electric vehicle (EV) adoption in Thailand, with the aim of making the country an EV manufacturing hub in Asia. A week later, the cabinet approved further draft regulations including specific information on customs duty reductions and exemptions for certain types of imported EVs. The plan includes both tax and non-tax incentives from 2022 until 2025. In the first two years (2022–2023), the package incentivizes the widespread use of EVs in Thailand by providing exemption or reduction of import duties and excise tax, as well as subsidies to increase the demand for EVs and attract investment in the EV industry. These incentives will cover the importation of completely built up (CBU) cars and motorcycles, and the local manufacturing of completely knocked down (CKD) vehicles in Thailand. For the following two years (2024–2025), the plan promotes the use of domestically produced EVs by eliminating the exemption or reduction of import duties for CBU vehicles while maintaining the other incentives (e.g., reduced excise tax rates, and subsidies). The aim of this is to make the cost of CBU vehicles higher than locally produced vehicles to encourage operators to produce EVs in the country to meet increasing demand. Additional measures encourage the manufacturing of EVs in Thailand, including exemption of import duties for parts imported between 2022 and 2025, and treatment of the value of imported battery cells as a cost of local manufacturing (up to 15% of an EV’s retail price). This is beneficial to local manufacturers of EVs, as their activities will be entitled to a more generous incentive package than importation of EVs. At their meeting on February 22, 2022, Thailand’s cabinet further approved draft subordinate regulations, including specific reductions and exemptions of customs duty
February 21, 2022
On February 14, 2022, Thailand’s Securities and Exchange Commission (SEC) announced a public hearing period on proposed advertising regulations for digital asset businesses. The public hearing period is now open for general comments until March 15, 2022. In the announcement, the SEC expressed their intention to provide clear digital asset advertising principles that conform to regulations in other countries, such as Singapore, the UK, and Japan. The SEC, in a meeting on February 3, agreed that the principles to be developed should apply to all digital asset businesses operating in Thailand. During the public hearing period, any interested parties may comment on the SEC’s proposed principles, which include the following key points: Advertisements that educate, inform, or give facts about digital assets, investments or services, or that provide an overall picture of digital assets, must not exaggerate, distort, or conceal information, or otherwise mislead consumers. In addition, advertisements that refer to customer numbers must only indicate the number of customers who have received approval to open an account and who are ready to use the service. Advertisements must be clear and appropriate, provide a warning on investment risks, and include clear and noticeable SEC-mandated statements in the font size stipulated by the SEC. Advertisements that present positive information or suggest an opportunity to receive returns must provide a balanced view that also discloses negative information or states investment risks. Advertisements relating to cryptocurrencies can only be made via a business operator’s official channels (e.g., the operator’s website, app, or other official online channel), and cryptocurrency cannot be advertised in public areas (e.g., billboards, public transportation, websites, newspapers and periodicals, etc.). However, advertisements for the services of a digital assets business can still be made in public areas and other channels. For example, this can be understood as meaning that
February 15, 2022
The sale of counterfeit goods online is as damaging to government efforts and consumer safety as it is to the reputation of the e-commerce platforms and brand owners involved. In this guest piece, Andy Chua, senior vice president of the IP Rights Protection Team at e-commerce giant Lazada, joins Tilleke & Gibbins’ Suebsiri Taweepon and Ploynapa Julagasigorn to discuss how stakeholders can work together to combat the growing threat of counterfeits online – with recent efforts in Thailand a prime example of effective action. This article, which was first published in World Trademark Review, is the second in a two-part series about trademark enforcement against online counterfeits.   Technological developments, government policy and the covid-19 pandemic have brought about significant changes to the lifestyle and behaviour of ordinary consumers. Shopping increasingly takes place on e-commerce platforms as people become more familiar with online transactions, encouraging many sellers to turn their focus to online platforms. While this shift to online retail has brought benefits for many, it has also provided additional ways for sellers of counterfeit goods to peddle their wares. The sale of counterfeit goods online tarnishes the reputation of e-commerce platforms among users, compromises consumer trust in brand owners’ products and undermines public authorities’ efforts in enforcing anti-counterfeiting policies. This dynamic problem cannot be resolved by a single entity alone. Instead, all stakeholders need to work together to amplify their efforts in consumer and brand protection. Collaborating against counterfeits in Thailand We see such collaborations between stakeholders in regions such as Thailand, where the Department of Intellectual Property (DIP) has signed a memorandum of understanding (MOU) with various parties that are committed to combatting the spread of counterfeit products online. The inaugural signing ceremony for the MOU was held on 11 January 2021, with 20 initial signatories drawn