You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 3, 2026

Bank of Thailand Proposes New Digital Channel Security Standards

On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026.

Background

The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements.

Expanded Scope of Regulated Entities and Channels

The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking.

Strengthened Customer Authentication

The draft introduces enhanced authentication requirements in three areas:

  • Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits.
  • Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases.
  • Secure authentication factors. Key requirements include the following:
    • “What-you-know” factors must protect against brute-force attacks.
    • “What-you-have” factors must use secure methods such as a registered mobile application with device binding or hard/soft tokens.
    • SMS OTPs must be discontinued for transaction authentication.
    • Biometric factors must use effective antispoofing technology, such as facial scanning, in compliance with the BOT’s guidelines on biometric technology in financial services.

Providers must cease sending SMS messages and emails containing embedded links and must establish incident response processes for counterfeit applications or websites.

Mobile Application Security Controls

Providers must ensure application integrity and block remote-access applications. Facial comparison with antispoofing technology is required for transfers exceeding THB 50,000 (approx. USD 1,490) per transaction or THB 200,000 (approx. USD 5,960) per day.

Next Steps

Affected financial service providers should assess their current systems against the draft requirements and consider submitting comments to the BOT by August 24, 2026.

RELATED INSIGHTS​ 

January 19, 2022
Thailand has completed the establishment of the Personal Data Protection Commission (PDPC), the regulator under the country’s Personal Data Protection Act B.E. 2562 (PDPA), strongly indicating that the planned full enforcement of the PDPA on June 1, 2022, is likely to proceed as scheduled. The establishment of the PDPC was finalized on January 18, 2022, when the Announcement of the Prime Minister’s Office on the Appointment of Chairperson and Honorary Members of the PDPC was published in the Government Gazette. As stipulated in the PDPA, the PDPC consists of: The chairperson, appointed based on knowledge, skills, and experience; The vice-chairperson, who is the permanent secretary of the Ministry of Digital Economy and Society; Five commission members, designated based on their positions in certain government agencies (as prescribed under the PDPA); and Nine honorary commission members appointed based on knowledge, skills, and experience in personal data protection, consumer protection, technology and telecommunication, social science, law, health, finance, or other relevant fields. As the vice-chairperson and the five commission members are appointed to the PDPC based on their positions, the January 18 announcement appointing the chairperson and the nine honorary commission members completes the formation of the PDPC. The full enforcement of the PDPA has been previously postponed, and many businesses had expressed concern that another extension would be forthcoming before the current enforcement date. However, the successful establishment of the PDPC is a fundamental prerequisite to enforcement and indicates that the effective date of the PDPA on June 1, 2022, is unlikely to be further postponed. In addition, the PDPA’s draft subordinate regulations that were the subject of a series of public hearings last year are likely to be issued in the near future. Companies and other organizations that are not yet compliant with the PDPA should now assess their
January 12, 2022
Thailand’s Board of Investment (BOI) recently published BOI Notification No. Sor. 8/2564, which extends the scope of investment promotion covering electronic vehicle (EV) industry manufacturers to include the production of “automotive platforms” for electric vehicles, and creates a new category of BOI promoted activities covering the manufacture of electric bicycles (E-bikes). Automotive Platforms The following investment promotion categories have been extended: 4.24 – Manufacture of Battery Electric Vehicles 4.26 – Manufacture of Electric Battery Tricycles 4.27 – Manufacture of Electric Battery Busses and Trucks These categories now include the manufacture of “automotive platforms”—which must include an energy storage system, charging module, and front and rear axle module—benefiting from similar tax incentives and subject to additional conditions, as detailed below. New BOI Promotional Category for E-Bike Production The BOI has also introduced a new category, No. 4.28, covering the manufacture of E-bikes. Projects under this category will be eligible for a three-year CIT exemption with an additional one-year exemption if certain criteria are met. Applications for this category must cover the manufacture of E-bikes, the manufacture or sourcing of electric batteries, and a management plan for used batteries. In addition to the general conditions for EV projects (industrial standards, manufacturing timelines, etc.), the BOI has also imposed the following conditions specific to E-bike projects: E-bike frames must be produced from light-weight materials such as aluminum alloy, chromium–molybdenum alloy steel (chrome moly), titanium alloy, and carbon fiber; and E-bike batteries must adopt environmentally-friendly technology. Interestingly the BOI allows E-bike production lines to jointly use manufacturing lines for ordinary bicycles. However, the sale of ordinary bicycles is regarded as non-BOI-promoted income and will not be entitled to BOI tax incentives. These new provisions, intended to stimulate both local and foreign investments in the electric automotive industry, seem to complete the BOI promotion
December 8, 2021
On February 9, 2021, Vietnam’s Ministry of Public Security (MPS) released the full text of the Draft Decree on Personal Data Protection (“Draft PDPD”) for public consultation, after having released an outline in December 2019, with an ambitious goal for the Draft PDPD to be promulgated and take effect on December 1, 2021. This date has now passed and the Draft PDPD remains unissued, with no concrete details on when the situation will change. Many new contents have been introduced in the Draft PDPD (please see our previous articles here and here). In this article, we take a deeper look at the issues that have attracted the most attention from national and international stakeholders as they wait for the draft to be finalized and promulgated. Please click below to read the full article.