You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

February 26, 2016

The Business Collateral Act: Creating a Robust Framework for Credit Markets

Informed Counsel

Muhammad Yunus, the founder of Grameen Bank and a Nobel Peace Prize laureate, once observed that “credit markets were originally created to serve human needs; to provide businesses and individuals with capital to start or expand businesses or expand other financial needs.” In other words, without access to credit, many businesses that could prosper and make significant economic and social contributions would not flourish.

As anyone who has applied for a credit card or mortgage knows, banks generally go to great lengths to assess the overall creditworthiness of potential clients. Borrowers who are able to use their assets as collateral tend to improve their creditworthiness, and therefore provide the borrowers with greater access to capital.

In Thailand, however, the traditional methods of providing collateral have been limited. Notably, the requirement to deliver movable collateral to the security holder has prevented borrowers from using inventory, machinery, and vehicles used in the course of business, or raw materials to secure their debts.

In recognizing the need to have a robust legal framework for credit markets, Thailand enacted the Business Collateral Act B.E. 2558 (BCA) in 2015, with the majority of its provisions coming into force on July 1, 2016.

Overview of the BCA

The BCA establishes a new category of nominate contract called the “business collateral agreement,” in which a “security provider” places property with a “security receiver” as security against debt repayment, with no requirement to deliver the property to the security receiver. A security provider may be either a natural or juristic person, whereas a security receiver must be a financial institution or other class of persons prescribed by ministerial regulation. The security receiver will have the preferential right to receive repayment of a debt from the collateral before other creditors.

The business collateral agreement must be made in writing and registered at the Business Security Registration Office of the Department of Business Development (DBD). To register a business collateral agreement, the parties must provide certain information, such as details on the debt being secured, a description of the collateral, the maximum amount being secured by the collateral, and causes for enforcement under the business collateral agreement, among a number of other requirements.

Collateral under a business collateral agreement can derive from:

  1. a business;
  2. a right of claim;
  3. movable property used by the security provider in business operations, such as machinery, inventory, or raw materials used in the manufacture of goods;
  4. immovable property, in case the security provider directly operates an immovable property business; or
  5. intellectual property.

The Ministry of Commerce has the authority to prescribe further categories of property through promulgating regulations.

Practical Considerations – Using a Business as Collateral

As the majority of the BCA’s provisions have not yet come into effect, a number of unresolved issues will need to be addressed in practice. For instance, if a business is used as collateral, the security provider and security receiver must agree to the selection of one or several experts who will act as the “security enforcer.” The name and address of the security enforcer, as well as the rates it will charge for its services, must be registered at the DBD.

Acting as a security enforcer is a new service that requires a license, issued by the DBD for an initial period of three years. The security enforcer must proceed with enforcement over a business, which includes conducting a fact-finding inquiry, issuing a decision on whether cause exists to enforce the security, and assuming control of the business in a manner similar to a court-appointed receiver.

Since the role of security enforcer is a new licensed activity, using a business as collateral will not be possible until there are licensed security enforcers appointed by the parties. It is currently unclear how many license applications will be submitted to or approved by the DBD.

An additional point that will need to be clarified in practice concerns the interaction between the security enforcer and the courts. In principle, when a business is used as collateral, the enforcement procedures are designed to take place entirely outside of court. The BCA specifically states that objections to the security enforcer’s determinations on cause and enforcement under the business collateral agreement may not be made to the court, unless the fact-finding inquiry was not in line with prescribed bases and procedures, or the decision contains a material flaw on the facts or the legal points. Court decisions which overrule the findings and determinations of the security enforcer are something to watch for as the BCA develops in practice.

A further point of uncertainty is how the new legal regime of out-of-court security enforcement will coincide with existing laws, such as Thailand’s Bankruptcy Act. If the security receiver attempts to initiate security enforcement over the business of a security provider while bankruptcy proceedings of the security provider are concurrently being initiated at the Thai courts, it is unclear whether the security enforcer is required to be deferential to the bankruptcy proceedings.

A Major Shift?

While the BCA represents a major shift in the legal framework of secured transactions in Thailand, there are still a number of issues which need to be clarified in practice. Ultimately, whether the BCA proves to be helpful to Thai borrowers will depend on the extent to which it is relied upon by parties seeking to extend and obtain credit.

RELATED INSIGHTS​ 

August 11, 2026
On July 27, 2026, the State Bank of Vietnam (SBV) released a draft decree proposing amendments to Decree No. 52/2024/ND-CP dated May 15, 2024, on non-cash payments (Decree 52). The draft decree would amend 17 of Decree 52’s 38 articles, with several key changes directly affecting providers of intermediary payment service (IPS). The key proposed changes affecting IPS providers are outlined below. Streamlining IPS Licensing Procedures A central objective of the draft decree is to simplify regulatory procedures for IPS providers. Notably, it would significantly reduce IPS licensing documentation requirements by removing the need to submit enterprise registration certificates, investment registration certificates, and documents evidencing the qualifications of the legal representative and general director. Instead, the SBV would retrieve this information directly from national business registration and other specialized databases, requesting additional documents only where the relevant information cannot be verified electronically or is incomplete. The draft decree also removes the current limit of two rounds for dossier supplementation and shortens processing timelines for several IPS licensing procedures such as issuance, amendment, and reissuance of IPS licenses. The processing time for new IPS license applications would be thereby reduced from 90 to 60 working days. In addition, several continuing IPS business conditions would be removed. For example, IPS providers would no longer be required to maintain certain representations relating to corporate restructuring or the legality of contributed capital. Likewise, the IPS project plan (đề án) would become a one-time application document rather than an ongoing licensing condition. If retained in the final decree, this change could provide IPS providers with significantly greater flexibility to implement post-licensing technology upgrades, system integrations, and corporate restructuring transactions without needing to revisit the originally approved project plan. The draft decree also removes the requirement for the SBV to consult the Ministry of Public
August 3, 2026
On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026. Background The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements. Expanded Scope of Regulated Entities and Channels The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking. Strengthened Customer Authentication The draft introduces enhanced authentication requirements in three areas: Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits. Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases. Secure authentication factors. Key requirements include the following: “What-you-know” factors must
July 27, 2026
A new decree on penalties for violations related to the crypto asset market creates compliance risks for offshore crypto asset exchanges in Vietnam that do not hold, and practically cannot obtain, a Vietnamese license, and for Vietnamese users who continue to transact on those platforms. Decree No. 284/2026/ND-CP (Decree 284), issued by the government of Vietnam on July 16, 2026, formally establishes an administrative penalty framework for violations related to crypto assets and the crypto asset market. The decree takes effect on September 1, 2026, and will remain in force for the duration of the five-year pilot program under Resolution No. 05/2025/NQ-CP, which is scheduled to end in September 2030. Direct Penalties on Vietnamese Users The most immediate commercial risk to offshore platforms is that their Vietnamese users now face direct personal liability for using their exchanges. Vietnamese users who trade crypto assets outside of a Ministry of Finance-licensed service provider face fines of up to VND 50 million (approximately USD 1,900). Vietnamese users trading in crypto assets that are offered or issued to foreign users face higher penalties of up to VND 100 million (approximately USD 3,800). It is expected that Vietnamese users will be more willing to migrate away from offshore platforms now that there is a risk of real enforcement against them. Penalties on Unlicensed Service Providers Violations of providing crypto asset services or advertising crypto-related services without a license face fines of up to VND 200 million (approximately USD 7,700). Operating a crypto asset trading market without proper authorization falls within the same highest penalty bands. Organizations that violate issuance, provision, or disclosure rules may face fines of up to VND 200 million. Although the maximum administrative fine per violation is capped at VND 200 million for organizations and VND 100 million for individuals, these
July 17, 2026
On July 11, 2026, media reports conveyed key messages from Bank of Thailand (BOT) Governor Vitai Ratanakorn’s announcement of a sweeping regulatory crackdown on grey capital activities. The measures target high-value cash transactions, gold trading, and stablecoin flows, with new requirements set to take effect in the fourth quarter of 2026. The initiative aims to prevent financial institutions from facilitating shadow economy activity, money laundering—particularly through stablecoins—and capital flight, through enhanced compliance obligations on commercial banks across multiple transaction channels. Expanded Cash Controls Close the Deposit–Withdrawal Circuit New fourth-quarter guidelines will require individuals depositing THB 5 million or more in cash to formally verify the source of their funds. This builds on restrictions introduced in April 2026, which required anyone withdrawing 5 million baht or more in cash to provide their bank with verified commercial justification for why electronic transfers or checks could not be used. That initial measure caused high-value physical cash withdrawals to drop by 35 percent nationwide. The upcoming deposit-side requirement closes the circuit on large cash movements. The BOT is also assessing tracking mechanisms for high-value banknote swaps, specifically targeting individuals seeking to exchange large volumes of THB 1,000 notes into smaller THB 100 or THB 500 denominations without clear business justification. Governor Vitai emphasized that these measures require continuous deployment of multiple parallel strategies rather than short-term fixes. Tightened Bullion Reporting Frameworks Restrict Money Laundering Channels The BOT has also tightened reporting frameworks for gold trading to close money laundering loopholes and shield the Thai baht from speculative bullion volatility. Regulators identified a recurring pattern in which buyers purchased large quantities of gold through digital applications in the morning and then made same-day physical withdrawals from retail gold shops in the afternoon. Gold shops are reminded of their duties to flag and report cash