You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 14, 2025

Bank of Thailand Releases Draft Guidelines for Digital Fraud Management

The Bank of Thailand (BOT) has published the Draft Guidelines for Digital Fraud Management, which aim to help financial service providers tackle digital fraud and ensure safety and trust in the Thai financial system. These draft guidelines, which are available for public comment until March 18, 2025, provide a comprehensive framework for financial service providers, covering prevention, detection, management, and resolution of digital fraud, as well as support for customers affected by fraud.

The BOT tentatively plans to implement these draft guidelines on April 1, 2025, along with circular letters on the minimum required measures for tackling “mule accounts” (deposit or e-money accounts used as tools to receive and transfer funds obtained through the commission of any offense) and measures to strengthen Thailand’s customer due diligence and enhanced due diligence procedures.

Under the draft guidelines, “financial service providers” include financial institutions and special financial institutions under the Financial Institution Business Act and payment providers under the Payment Systems Act.

Commercial banks, special financial institutions, and operators of transferable e-money services must adhere to every requirement in the draft guidelines. Other financial service providers (e.g., payment providers other than operators of transferable e-money services) can implement the draft guidelines as deemed appropriate to their services, products, and service channels.

Digital Fraud Management Requirements

The draft guidelines establish the following key requirements:

  • Policy and oversight. Directors and senior executives of financial service providers must set and adopt appropriate “end-to-end” fraud management policies and KPIs to manage digital fraud, covering prevention, monitoring, detection, management, resolution, and support for affected customers.
  • Fraud management processes. Financial service providers must establish a clear framework for managing digital fraud throughout the customer lifecycle, from customer onboarding to service termination, according to industry standards at a minimum and covering at least the following processes:
    • Know your customer (KYC) and customer due diligence (CDD): Providers must implement risk assessment processes to identify potential mule accounts, continuously monitor customer transaction behaviors, and regularly review and update customers’ risk levels. In addition, authentication processes must suit the (1) risk level of the transaction, (2) products and services, and (3) service channel.
    • Fraud monitoring and detection: Providers must develop proactive processes to detect and monitor unusual transactions and utilize data from various sources to identify potential mule accounts and fraud. This may involve adopting new technologies (e.g., artificial intelligence) to enhance efficacy and stay ahead of emerging fraud techniques.
    • Action and response to fraud: Providers must develop swift and appropriate measures to prevent, limit, and promptly mitigate digital fraud damage (e.g., by providing alerts to customers), including handling suspected mule accounts. They must also respond clearly, fairly, and swiftly to support customers affected by scams (e.g., by offering 24/7 customer support through dedicated hotlines and electronic channels, having service level agreements with timeframes to assist customers affected by fraud incidents, and reporting to the BOT any incidents that cause widespread customer damage or affect the financial service provider’s reputation).
  • Information sharing. Financial service providers must have mechanisms to share accurate information in a timely manner with one another and with relevant external agencies (e.g., Anti-Money Laundering Office, Royal Thai Police) to enhance collective fraud management efforts, and must appoint responsible persons to coordinate and procure information necessary for any investigations.
  • Awareness. Financial service providers must proactively raise customers’ and the public’s awareness of digital fraud to prevent and reduce potential damage. Required actions include implementing a practical method on an easily accessible service channel (e.g., mobile app or infographic on social media) at least once a month, and having customers take awareness tests when using mobile banking and transferable e-money services.

RELATED INSIGHTS​ 

October 7, 2024
Peer-to-peer (P2P) lending has been introduced as an additional option in Thailand’s fintech landscape. This innovative lending model offers new opportunities for both lenders and borrowers, while also presenting unique regulatory challenges. This article explores the current state of P2P lending in Thailand, focusing on the regulatory framework and the requirements for platform providers, borrowers, and lenders. Regulatory Framework for P2P Lending In Thailand, P2P lending platforms fall under the purview of Revolutionary Council Decree No. 58, which regulates lending businesses. The Bank of Thailand (BOT) recognizes the potential benefits of P2P lending platforms in providing lenders with new investment opportunities and offering borrowers additional sources of funds. A “P2P platform provider” is defined as a person who provides an electronic system or network for peer-to-peer lending. To ensure the security and stability of the P2P lending system and provide sufficient protection for platform users, the BOT has established a regulatory framework with specific requirements for P2P lending platforms. Regulatory Sandbox Requirement One unique aspect of Thailand’s approach to P2P lending regulation is the requirement for platforms to participate in a regulatory sandbox before applying for a P2P lending platform license. This sandbox approach allows the BOT to closely monitor and assess the operations of P2P platforms in a controlled environment before granting full operational licenses. Requirements for P2P Platform Providers To obtain a P2P lending platform license, applicants must meet several criteria, including: The applicant may not be a financial institution. The company must be incorporated in Thailand. A minimum paid-up registered capital of THB 5 million is required. At least 75% of the voting shares sold must be owned by Thai nationals. These requirements aim to ensure that P2P lending platforms have a significant local presence and adequate capital to operate responsibly. Regulations for Borrowers and Lenders
September 24, 2024
In recent years, Thailand has witnessed significant developments in its personal finance sector, particularly in alternative lending options. This article explores two key concepts in the Thai financial landscape: nano finance and personal loans. These alternative lending models, regulated by the Bank of Thailand (BOT), aim to provide more accessible financial services to individuals and small entrepreneurs who might have limited access to traditional funding sources. Nano Finance: Empowering Small Entrepreneurs The nano finance scheme under the BOT’s supervision is designed to provide funding to small entrepreneurs who might have limited access to traditional financial resources. One of the key features of this scheme is the ability of licensed nano finance providers to use alternative data in assessing loan applicants’ ability to repay (information-based lending). To implement this approach, nano finance providers must have an internal policy on credit approval that supports: Identifying scope and processes for utilizing alternative factors or technologies in determining debt repayment capacity, credit line limits for each loan applicant and total credit limits, and acceptable debt repayment targets; Having resources and personnel with sufficient knowledge, capability, experience, and expertise to operate efficiently and effectively, as well as clear checks and balances; Establishing guidelines for selecting and analyzing factors or financial models to evaluate or predict loan applicants’ ability and willingness to repay; Having an internal sandbox to test key success factors of the selected factors or models; and Having a process for monitoring and reviewing the application of the selected factors or models in assessing debt repayment capability. This approach allows nano finance providers to make more informed lending decisions based on a broader range of data, potentially increasing access to finance for small entrepreneurs who may not have traditional credit histories or collateral. Personal Loans The personal loan scheme under BOT supervision aims
September 20, 2024
On September 12, 2024, the Bank of Thailand (BOT) Notification Re: Virtual Bank Supervision Criteria took effect. According to this notification, virtual banks must adhere to standards for traditional commercial banks, along with additional requirements tailored to address virtual banks’ digital nature and corporate structure. Specific Requirements The concepts of supervision remain unchanged from the consultation paper titled “Criteria for Supervising Virtual Banks”. Some of the key additional provisions and details on supervision criteria relate to the following: Financial business groups: The notification identifies virtual banks as financial businesses, subject to the BOT’s regulations on financial business group supervision. If a virtual bank is a part of another financial institution’s financial business group, the virtual bank must be under a solo consolidated group. After the “initial phase” (see below), other financial institutions and companies within the financial business group are prohibited from extending credit to or engaging in transactions similar to lending activities with the virtual bank. Capital fund requirements: If other financial institutions’ investment in a virtual bank increases the capital fund in the financial system beyond a safe level and this poses a risk to other financial institutions, the BOT may order the relevant financial institution to maintain capital funds as the BOT deems appropriate. Service channels and outsourcing: Virtual banks must provide services solely through digital channels, except when necessary. For example, with the BOT’s approval, a virtual bank may use other commercial bank electronic branches via an ATM pool system, use a banking agent to serve customer needs for cash, or occasionally provide on-site services. Initial Phase The “initial phase” runs from the date that the virtual bank commences its operations until it receives the BOT’s approval to become fully operational. During this period, certain BOT supervisory requirements are relaxed as follows: Governance: Virtual banks in the initial phase may request
September 16, 2024
On July 23, 2024, the State Bank of Vietnam (SBV) published a draft circular regulating the implementation of open (publicly available) application programming interfaces, or Open APIs, in the banking industry (Draft Circular) to collect public comments. Open APIs in the banking sector are APIs of banks that allow third parties to process data for their own use or to provide products and services to customers. Urgent need Currently, the development of Open APIs in Vietnam is fragmented, with each bank using different API standards and security standards. There is no common standard for information technology systems, information storage, security, connectivity, or legal frameworks. Therefore, the promulgation of a regulation on Open APIs is urgently needed to create a clear legal basis and guidance for electronic banking transactions, especially in connecting to bank information systems and processing customer data safely, and creating new, innovative products and services to meet the increasing needs of customers. Cooperation of banks required The Draft Circular requires banks to provide Open API services to third parties for connection to the bank system and data processing. Banks have the right to refuse or suspend Open API services if third parties do not meet specified conditions. However, banks will be responsible for ensuring the quality and security of data, providing tools for customer data queries and revocation of third-party data processing rights, and coordinating with third parties and authorities to resolve issues. The Draft Circular standardizes Open API functions for all banks according to the Open API function list and the technical standards list specified in the Draft Circular. Open API service contract The template Open API service contract between banks and third parties using Open API services must have certain required contents such as provisions regarding confidentiality, data use purpose, and that the security level