You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 31, 2020

Bank of Thailand Revamps Know-Your-Customer Procedures for E-Money Service Operators

Informed Counsel

A recent notification from the Bank of Thailand (BOT) has introduced new know-your-customer (KYC) guidelines for e-money businesses, updating the country’s regulatory regime to accommodate the greater variety of e-money services that have come into the market. The new regulations better differentiate between the types of risk relating to each product, and are expected to help e-money service providers overcome difficulties in identifying their customers.

Notification Sor Nor Chor 1/2563 Re: Know Your Customer Regulations for Activating the Use of e-Money Services was issued by the BOT on March 13, 2020, supplementing the KYC requirements for e-money services stipulated under the Anti-Money Laundering Act B.E. 2542 (1999) (AMLA). The notification came into force on May 6, 2020.

Identification and Verification               

The KYC procedures that e-money service operators must adopt are a two-stage process—first identifying, and then verifying, customers. In doing so, they must ensure that the information received is actually the customer’s information, and that the information is correct, true, and up to date.                

The notification sets out specific KYC requirements for different product offerings so that e-money service providers will be able to adapt their procedures to suit the level of risk for each product. For non-transferable payments for products or services in Thailand, e-money services must follow the customer identification and verification procedural requirements in the AMLA. For transferable payments for products or services (whether in Thailand or not), e-money services must conduct additional face-to-face or non-face-to-face verification of customers. 

For face-to-face verification, e-money services must confirm that the information and evidence received for verification is correct, true, up to date, and from a reliable source (e.g., the National Credit Bureau). Service operators must also prove that the information provided by the customer is the customer’s own information and proof of identity. If a smart ID card is provided as evidence, the card must be validated with a smart card reader and verified through a government electronic inspection system (e.g., National Digital ID).

When face-to-face verification is not possible, or not a preferred option, in addition to confirming and verifying the information received, operators must obtain a photograph of the customer and record it using advanced technology that adheres to accepted standards, in order to verify the customer’s identity by comparing the individual’s face with the biometric information embedded in the smart ID card. E-money payment or transfer services that have implemented measures to minimize risks in line with the AMLA’s criteria for low-risk services (such as regulated e-payment services) may confirm the information and evidence used for verification themselves, similar to the requirements for face-to-face confirmation.   

For corporate customers, the procedures must enable the identification and verification of the corporate entity’s authorized person, in addition to the KYC procedures set out by the AMLA (meaning that corporate customers must provide the company name, objectives, address, phone number, etc.). This can be any procedure that meets the standards set out in the BOT’s notification—for example, an e-money service may designate an employee to be in charge of a corporate customer and validate that the information received is correct, true, and up to date. Evidence is also required to prove that the person using the e-money service for the first time is authorized to do so by the corporate entity.    

As part of their internal risk-management procedures, e-money services must implement other KYC procedures for corporate customers when there are temporary technical difficulties that could prevent compliance with any of the above verification requirements.   

The BOT notification also allows e-money service operators to verify customers using the national digital ID system, either alone or in conjunction with the procedures outlined above.    

When a customer of one e-money service intends to activate or use another type of e-money service with the same provider, operators that have already implemented the KYC requirements in the regulations for activating or changing of the type of e-money service, and have kept the customer’s information correct and up to date, should follow authentication procedures that are secure and able to prove the customer’s genuine identity and correlation with the risk level of the relevant product or service. For example, an operator could use a biometric comparison technology to verify customers. 

Other Requirements

Other requirements under the BOT notification include implementing policies, risk management measures, and internal controls to ensure that risk management systems for KYC procedures are appropriate, concise, and aligned with the relevant product and activation channels. In addition, a secured storage system for customer information must be maintained.

E-money service providers that want to implement any other KYC process will need to obtain approval from the BOT and, if necessary, test any new technology in the BOT’s regulatory sandbox.

Compliance Steps and Exemption Requests

E-money services should be in compliance with the BOT’s KYC notification by November 2, 2020. In advance of that compliance, by July 5, 2020, existing services need to have submitted a clear operating plan to the BOT showing how they would bring their operations into compliance with the regulations. Service providers are also required to notify the BOT immediately upon achieving full compliance with the regulations.   

E-money services that are unable to comply with the regulations may submit an exemption request (in writing or electronically) to the BOT, detailing the reasons for not being able to comply with the regulations. Upon receipt, the BOT will consider whether to approve the exemption.
 

RELATED INSIGHTS​ 

March 27, 2026
In response to the rapid advancement of artificial intelligence (AI) and evolving global digital trends, Thailand has undertaken significant efforts to establish a comprehensive national policy framework aimed at fostering an AI ecosystem. This framework seeks to promote the responsible development and deployment of AI technology to enhance Thailand’s economic competitiveness and improve quality of life, with targeted implementation by 2027. In furtherance of this national AI policy, regulatory authorities have initiated efforts to develop and refine the applicable legal framework, including the drafting of Thailand’s first unified AI legislation. Pending the composing and enactment of such comprehensive legislation, sector-specific regulators have proactively issued guidelines applicable to regulated entities within their respective jurisdictions, including financial institutions, banks, insurance companies, securities and derivatives business operators, and digital asset service providers. Concurrently, cross-sectoral regulatory bodies, notably the Personal Data Protection Committee (PDPC) and the National Cyber Security Agency (NCSA), have promulgated guidelines applicable to all business operators within their regulatory purview. While unified AI legislation has not been enacted, the design, development and use of AI in Thailand in various industries is still subject to existing sector-specific legislation. National AI policy The Thai cabinet approved the Thailand National AI Strategy and Action Plan (2022-2027) in July 2022, aiming to establish an AI development and application ecosystem by 2027. The strategy is built around five pillars: Preparing social, ethical, legal and regulatory readiness for AI; Developing national infrastructure; Increasing human capability and AI education; Driving AI technology and innovation; and Promoting AI adoption in public and private sectors. The above-mentioned national AI committee, under the National Digital Economy and Society Committee (NDESC), was established in August 2022, chaired by the prime minister. Comprehensive legislation Following the national AI strategy, the government has been developing comprehensive AI legislation to govern and promote AI
March 20, 2026
Thailand’s Board of Investment (BOI) now requires data center projects to demonstrate measurable benefits for local workforce development, R&D, SME capability, and domestic supply chains to qualify for corporate income tax (CIT) exemptions. BOI Notification No. Por. 3/2569, issued on February 6, 2026, updates the requirements for projects seeking promotion under BOI category 8.2.1 (data centers). All data center projects must now submit and implement plans covering development of Thai human resources and domestic supply chain support before benefiting from any CIT exemption. Human Resources Development Plan The BOI seeks to promote local talent development beyond basic training. Plans must include the following elements: Training for data center design, construction, and operations targeting vocational students, engineering and ICT undergraduates and postgraduates, and energy and building personnel in Thailand. Joint curricula with Thai universities and technical institutes. Collaborative R&D with Thai nationals or institutions in areas including AI, resource allocation, high-performance computing, and data center hardware and systems. Thai SME upskilling in electrical and energy systems and IT services. Domestic Supply Chain Support Plan Plans must demonstrate knowledge transfer in design, construction, cooling, security, and power and water management. Projects must also include usage or installation of domestically manufactured equipment or engage specialist domestic entities. Criteria for BOI Evaluation The BOI will assess data center operators’ eligibility for CIT incentives based on two criteria: Scale requirement: Training and joint-curriculum initiatives must reach a total participants equal to at least 10 times the project headcount and run for the duration of the CIT incentive. If this threshold is not met, the applicant must also implement continuous R&D or SME skills-development plans throughout the incentive period. Substantiality test: Supply-chain plans must be substantive, meet industry standards, and show measurable development of the domestic digital and data center supply base. To ensure compliance,
March 19, 2026
Thailand’s Electronic Transactions Development Agency (ETDA), which describes itself as a “co-creation regulator” working collaboratively with industry rather than imposing top-down rules, has unveiled its regulatory roadmap for digital platform businesses under the Royal Decree on Digital Platform Service Businesses B.E. 2565 (2022). The 2026 regulatory approach is guided by three core principles—“practicable, verifiable, shared responsibility”—aimed at elevating digital services to be safe, transparent, and fair. These principles inform ETDA’s 2026 priorities, which focus on three key dimensions: product and service standards on platforms, fair competition and fee transparency, and online fraud prevention. Product and Service Standards ETDA’s 2026 agenda addresses product and service standards across several platform categories: Online marketplace platforms. The Notification on Additional Measures for Online Marketplace Platforms under Section 18(2) came into force on December 31, 2025, designating 21 marketplace platforms that must verify products and merchants. Among other obligations, covered platforms must remove or suspend substandard products under the “notice and take down” principle. The ETDA has collaborated with the Food and Drug Administration and the Thai Industrial Standards Institute to develop inspection manuals and coordinate compliance procedures. Social commerce. The ETDA is preparing a new notification under Section 18(2) specifically targeting social commerce platforms with sales support functions, aiming to align regulation with evolving digital market conditions. Ride sharing. Since the postponement of the deadline to comply with the ETDA’s notification on ride-sharing platforms to March 31, 2026, the ETDA has supported drivers in registering with the Department of Land Transport through the Driver Verify registration system, which has already issued certifications to approximately 27,900 riders. The ETDA is also examining structural issues relating to appropriate insurance packages, motorcycle engine capacity expansion, and fair leasing fees and contract transfer costs in coordination with the Department of Land Transport, the Office of Insurance Commission,
March 19, 2026
Thailand’s Personal Data Protection Committee (PDPC) has launched a public consultation period to gather input for a forthcoming set of guidelines under the country’s Personal Data Protection Act (PDPA). This initiative follows the PDPC’s issuance of guidelines on consent and notification requirements in September 2022. The main consultation period, using an online questionnaire to gather feedback, runs until March 23, 2026. In addition, an interview-style online session for private-sector participants was held on March 17, and a two-day in-person event will be held on April 1–2—this is already fully booked and  walk-ins will not be accepted, but the session will be livestreamed on the PDPC’s Facebook page. The PDPC will use the public feedback to design draft guidelines that accurately reflect the operational realities of both public and private organizations, after which the guidelines will be shared with the public. Consultation Scope The PDPC has identified six priority areas for which upcoming guidance may be issued: Legal bases for processing: The online questionnaire assesses respondents’ understanding of consent requirements and seeks views on priority issues, such as explanations of the legal bases and considerations for selecting an appropriate legal basis depending on the nature of the processing activity. Security measures and data breach notification: The questionnaire examines respondents’ understanding of data breach reporting and security measure obligations. Topics proposed for inclusion in the guidelines include data breach prevention measures, incident response plans, risk assessment methods, and reporting procedures. Data protection officers: Respondents are invited to share their expectations regarding the DPO’s role and their experiences in contacting a DPO. The survey also asks respondents to identify priority issues, such as response timeframes for data subject requests and complaint procedures. Marketing and direct marketing: The online questionnaire seeks input on preferred topics for guidance, including individuals’ rights to refuse marketing