You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 14, 2025

Bank of Thailand Releases Draft Guidelines for Digital Fraud Management

The Bank of Thailand (BOT) has published the Draft Guidelines for Digital Fraud Management, which aim to help financial service providers tackle digital fraud and ensure safety and trust in the Thai financial system. These draft guidelines, which are available for public comment until March 18, 2025, provide a comprehensive framework for financial service providers, covering prevention, detection, management, and resolution of digital fraud, as well as support for customers affected by fraud.

The BOT tentatively plans to implement these draft guidelines on April 1, 2025, along with circular letters on the minimum required measures for tackling “mule accounts” (deposit or e-money accounts used as tools to receive and transfer funds obtained through the commission of any offense) and measures to strengthen Thailand’s customer due diligence and enhanced due diligence procedures.

Under the draft guidelines, “financial service providers” include financial institutions and special financial institutions under the Financial Institution Business Act and payment providers under the Payment Systems Act.

Commercial banks, special financial institutions, and operators of transferable e-money services must adhere to every requirement in the draft guidelines. Other financial service providers (e.g., payment providers other than operators of transferable e-money services) can implement the draft guidelines as deemed appropriate to their services, products, and service channels.

Digital Fraud Management Requirements

The draft guidelines establish the following key requirements:

  • Policy and oversight. Directors and senior executives of financial service providers must set and adopt appropriate “end-to-end” fraud management policies and KPIs to manage digital fraud, covering prevention, monitoring, detection, management, resolution, and support for affected customers.
  • Fraud management processes. Financial service providers must establish a clear framework for managing digital fraud throughout the customer lifecycle, from customer onboarding to service termination, according to industry standards at a minimum and covering at least the following processes:
    • Know your customer (KYC) and customer due diligence (CDD): Providers must implement risk assessment processes to identify potential mule accounts, continuously monitor customer transaction behaviors, and regularly review and update customers’ risk levels. In addition, authentication processes must suit the (1) risk level of the transaction, (2) products and services, and (3) service channel.
    • Fraud monitoring and detection: Providers must develop proactive processes to detect and monitor unusual transactions and utilize data from various sources to identify potential mule accounts and fraud. This may involve adopting new technologies (e.g., artificial intelligence) to enhance efficacy and stay ahead of emerging fraud techniques.
    • Action and response to fraud: Providers must develop swift and appropriate measures to prevent, limit, and promptly mitigate digital fraud damage (e.g., by providing alerts to customers), including handling suspected mule accounts. They must also respond clearly, fairly, and swiftly to support customers affected by scams (e.g., by offering 24/7 customer support through dedicated hotlines and electronic channels, having service level agreements with timeframes to assist customers affected by fraud incidents, and reporting to the BOT any incidents that cause widespread customer damage or affect the financial service provider’s reputation).
  • Information sharing. Financial service providers must have mechanisms to share accurate information in a timely manner with one another and with relevant external agencies (e.g., Anti-Money Laundering Office, Royal Thai Police) to enhance collective fraud management efforts, and must appoint responsible persons to coordinate and procure information necessary for any investigations.
  • Awareness. Financial service providers must proactively raise customers’ and the public’s awareness of digital fraud to prevent and reduce potential damage. Required actions include implementing a practical method on an easily accessible service channel (e.g., mobile app or infographic on social media) at least once a month, and having customers take awareness tests when using mobile banking and transferable e-money services.

RELATED INSIGHTS​ 

June 23, 2026
On May 14, 2026, Thailand published a ministerial regulation in the Government Gazette to prescribe measures for prevention and suppression of technology crimes. The regulation creates a comprehensive procedural framework for returning money and digital assets to victims of technology crimes. It will take effect 90 days after publication (in mid-August 2026), giving affected entities a limited window to prepare. Mandatory Reporting Obligations for Financial Institutions When a deposit account, e-money account, or digital asset wallet is frozen in connection with a technology crime, the relevant financial institution or business operator must report transaction data to the Anti-Money Laundering Office (AMLO) via AMLO’s designated electronic system. Required data elements include account numbers (sender and receiver), names, identification or passport numbers, legal entity registration numbers, phone numbers, remaining balance, damage amount, transaction reference numbers, and the bank case ID. Institutions that already share data through the information-sharing system under the emergency decree are deemed to have satisfied this reporting obligation, creating an incentive for platform participation. When the Royal Thai Police or the Department of Special Investigation seize or freeze assets related to technology crimes, they must provide AMLO with investigation reports, complaint evidence, money-trail data, and account statements. Notification and Claims Process Once the AMLO secretary-general approves verified reports of a technology crime, the account information of persons connected to the crime will be published in the Government Gazette, triggering a 90-day window for victims to file claims and for related persons to file objections. Officers will also publish details on AMLO’s electronic media and send registered mail to identified victims, which will be deemed received after 7 days domestically or 15 days internationally. Victims have 90 days from the date the crime is published in the Government Gazette to file claims through AMLO’s electronic system. Claims must include
May 25, 2026
Thailand published new rules on May 1, 2026, establishing clear procedures for how the Anti-Money Laundering Office (AMLO) handles digital assets seized during criminal and money laundering investigations. Taking effect the following day, the Regulation of the Anti-Money Laundering Board on the Custody and Management of Seized or Frozen Assets (No. 3) B.E. 2569 applies to digital asset businesses, cryptocurrency holders, and anyone subject to asset seizure under Thailand’s anti-money laundering laws. For the first time, authorities now have a detailed roadmap for transferring seized digital property from private or foreign control into secure state custody. Digital asset businesses holding customer assets under investigation must be prepared to comply with these rules compelling repatriation of such assets in enforcement actions. Expanded Definition of Digital Assets The regulation defines digital assets to include not only those covered by Thailand’s existing digital asset business law but also any other property that can be stored using the same methods as digital assets. This broad formulation means the custody rules will apply to emerging blockchain-based assets and tokenized property that may not yet fall within the statutory definition of a digital asset business, giving authorities flexibility as the technology evolves. Mandatory Transfer to Domestic Custody When digital assets are held with service providers outside Thailand, AMLO will first attempt to transfer them to an account the office maintains with a licensed domestic digital asset business operator. If the domestic operator does not support that particular asset, the office will instead move the assets to its own cold wallet (offline, internet-isolated storage system). If neither option is feasible, the seizing official will report the situation to the Anti-Money Laundering Committee for alternative instructions. A similar hierarchy governs assets held in an accused party’s private wallet or by any third party that is not a
April 23, 2026
Vietnam has progressively positioned blockchain as a strategic technology within its broader digital transformation agenda over the past decade. From early policy orientations to more recent legislative developments, the regulatory approach has gradually shifted from high-level recognition to more concrete legal integration. Against this backdrop, a new draft decree regulating activities relating to product and goods identification, authentication, and traceability (the “Draft Decree”) marks a notable turning point. Rather than merely referencing blockchain as a policy priority, the Draft Decree incorporates blockchain directly into a nationwide regulatory system, positioning it as part of the underlying infrastructure for data governance and public administration in relation to the management, verification, and traceability of product-related data. Evolution of Vietnam’s Blockchain Legal Framework: The Draft Decree in Context Vietnam’s blockchain legal framework has developed in several distinct phases. The first phase, beginning around 2019, was characterized by high-level policy recognition in several resolutions of the Party Central Committee. Particularly, blockchain was identified as part of the broader category of digital technologies critical to industrial modernization and participation in the Fourth Industrial Revolution. These resolutions did not regulate blockchain directly, but established its strategic importance at the national level. The second phase (2023 to 2025) saw the introduction of national strategies and technology policies that more explicitly recognized blockchain as a priority technology. Those policies collectively signaled a clear policy commitment to developing blockchain infrastructure and applications. However, these instruments remained largely at a policy-level and did not establish binding regulatory frameworks. The third phase (from 2025) involves the gradual integration of blockchain into sectoral legislation. Laws such as the Law on Digital Technology Industry (2025), the Law on Personal Data Protection (2025), and the Law on Science, Technology, and Innovation (2025) have introduced concepts such as digital assets, crypto assets, and even specific
March 5, 2026
Thailand’s Securities and Exchange Commission (SEC) has filed a criminal complaint against a licensed digital asset broker, its overseas trading platform, and its executives for allegedly operating an unlicensed digital asset exchange targeting Thai customers. The case marks an escalation in the SEC’s enforcement efforts against unlicensed offshore platforms that attempt to serve Thai users through local licensed entities. Criminal Complaint On February 20, 2026, the SEC filed a criminal complaint with the Economic Crime Suppression Division against a local licensed digital asset broker, its overseas global trading platform, and its executives. The SEC alleges that the parties violated the Digital Asset Business Emergency Decree B.E. 2561 (2018) by cooperatively operating a digital asset exchange business on a cross-border basis since 2023 without the required SEC license. According to the SEC, the local broker promoted the overseas platform’s services to the public through Thai-language posts on social media channels, with services available exclusively to customers residing in Thailand. Access to the global platform was provided through the local broker’s website and mobile application. Customers who registered for the local broker’s services were automatically granted access to the global platform without having to undergo a separate identity verification process. The SEC also found that the local broker provided back-office system support services to the global platform. The SEC considers these activities to constitute joint operation of an unlicensed digital asset exchange. The former executives of the local broker are being held liable as the responsible persons during the relevant period. The SEC emphasized that the complaint initiates the criminal process, and the decision to prosecute or convict the accused parties will ultimately be made by law enforcement authorities and the criminal courts. Platform Blocking The SEC has also coordinated with the Ministry of Digital Economy and Society to block public