You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

October 21, 2024

Fintech Insights: The Bank of Thailand’s Sandbox Framework for Fintech Innovation

One key component of Thailand’s support for the development of fintech innovations is its sandbox framework, supervised by the Bank of Thailand (BOT). This framework supports business operators in experimenting with new technologies under controlled conditions.

This article explores the structure and significance of the BOT’s sandbox program in driving fintech innovation in Thailand.

The BOT Sandbox Framework

In June 2024, the BOT updated its sandbox framework to provide a more comprehensive and flexible environment for testing fintech innovations. The framework allows participants to experiment with their ideas in a controlled and limited environment, balancing the need for innovation with the imperative of maintaining financial stability and consumer protection.

Three Types of Sandboxes

The BOT’s framework encompasses three distinct types of sandboxes: the Regulatory Sandbox, the Own Sandbox, and the Enhanced Regulatory Sandbox.

Regulatory Sandbox

The Regulatory Sandbox is a mandatory testing ground for certain BOT-licensed financial services to ensure that potentially impactful innovations are tested and evaluated before wide-scale implementation. Participation in this sandbox is a prerequisite for:

  • License applications for specific financial services.
  • Implementation of new technologies or innovations in existing licensed services.
  • Financial services that have the potential to become a structural element or standard of the Thai financial sector.

A prime example of a service requiring participation in the Regulatory Sandbox is the Thai QR code payment via PromptPay system, which involved various banks several years ago until the Bank of Thailand granted permission for these services to be provided to the general public.

Own Sandbox

The Own Sandbox is an optional program that the BOT encourages for financial service providers and fintech operators implementing new technologies. This sandbox provides a more flexible environment for testing innovations that may not require the same level of regulatory scrutiny as those in the Regulatory Sandbox.

Enhanced Regulatory Sandbox

The Enhanced Regulatory Sandbox is a specialized testing environment for new financial products or services that are not yet authorized by the BOT for regulated financial operators. This sandbox operates under the close supervision of the BOT and is conducted under controlled conditions with limitations on how the product or service can be offered and tested.

Benefits of the Sandbox Approach

The BOT’s sandbox framework offers notable benefits to both innovators and the broader financial ecosystem. Perhaps foremost is risk mitigation. By testing new technologies and business models in a controlled environment, potential risks can be identified and addressed before wider implementation. Participants can also gain insights into how their innovations fit within the existing regulatory framework. Additionally, the close monitoring enabled by the sandbox framework empowers the BOT to better safeguard consumer interests in a changing technological environment.

Conclusion

The BOT-supervised sandbox framework represents a significant commitment to fostering fintech innovation in Thailand. By providing structured environments for testing new technologies and business models, the BOT is helping to create a competitive fintech ecosystem while maintaining the stability of the financial sector.

This forward-thinking but responsible approach toward financial innovation has positioned Thailand as a potential leader in fintech development in Southeast Asia. Companies developing new technologies and considering market entry should understand and comply with the requirements and recommendations associated with the BOT-supervised sandbox framework, as this can prevent missteps and possibly even smooth their path launching new products and services in the Thailand market.

RELATED INSIGHTS​ 

August 13, 2026
On August 6, 2026, the National Bank of Cambodia (NBC) issued a notice calling on business owners that issue electronic money, such as e-wallet accounts and stored-value membership cards, to notify the central bank within 90 days. The notice targets businesses that are not licensed banking or financial institutions or payment service providers, but have been issuing e-money to facilitate payments within their own networks. Failure to notify the NBC may result in legal action. Background and Regulatory Basis The NBC has observed that certain businesses, including cafes, restaurants, transportation companies, entertainment centers, and gas stations, have been issuing e-money through e-wallet accounts in mobile apps or membership cards to facilitate customer payments for products or services within their own networks. Customers create e-wallet accounts and load balances to pay for goods or services at the issuing business. The NBC describes this as “single-purpose e-money.” Under the 1999 Law on Banking and Financial Institutions, providing payment facilities to customers forms part of the operations of banking and financial institutions and requires an NBC license. In addition, article 20 of the 2017 Prakas on the Management of Payment Service Institutions further prohibits legal entities other than banking and financial institutions and payment service institutions from issuing e-money. However, article 20 also provides that issuing e-money in certain limited cases does not require a license, but the NBC must be notified in advance in writing. A business may issue single-purpose e-money without a payment service institution license provided it meets all the following conditions and submits written notice to the NBC: The maximum balance per account is KHR 200,000 (approximately USD 50) or equivalent. The total aggregate balance across all accounts does not exceed KHR 800 million (approximately USD 200,000) or equivalent. The e-money is used to pay for products or
August 11, 2026
On July 27, 2026, the State Bank of Vietnam (SBV) released a draft decree proposing amendments to Decree No. 52/2024/ND-CP dated May 15, 2024, on non-cash payments (Decree 52). The draft decree would amend 17 of Decree 52’s 38 articles, with several key changes directly affecting providers of intermediary payment service (IPS). The key proposed changes affecting IPS providers are outlined below. Streamlining IPS Licensing Procedures A central objective of the draft decree is to simplify regulatory procedures for IPS providers. Notably, it would significantly reduce IPS licensing documentation requirements by removing the need to submit enterprise registration certificates, investment registration certificates, and documents evidencing the qualifications of the legal representative and general director. Instead, the SBV would retrieve this information directly from national business registration and other specialized databases, requesting additional documents only where the relevant information cannot be verified electronically or is incomplete. The draft decree also removes the current limit of two rounds for dossier supplementation and shortens processing timelines for several IPS licensing procedures such as issuance, amendment, and reissuance of IPS licenses. The processing time for new IPS license applications would be thereby reduced from 90 to 60 working days. In addition, several continuing IPS business conditions would be removed. For example, IPS providers would no longer be required to maintain certain representations relating to corporate restructuring or the legality of contributed capital. Likewise, the IPS project plan (đề án) would become a one-time application document rather than an ongoing licensing condition. If retained in the final decree, this change could provide IPS providers with significantly greater flexibility to implement post-licensing technology upgrades, system integrations, and corporate restructuring transactions without needing to revisit the originally approved project plan. The draft decree also removes the requirement for the SBV to consult the Ministry of Public
August 4, 2026
Tilleke & Gibbins has contributed the Vietnam chapter to Fintech 2027, a global guide published by Lexology Panoramic that provides comparative insights into the legal and regulatory frameworks governing fintech businesses across multiple jurisdictions. The Vietnam chapter offers a comprehensive overview of the country’s rapidly evolving fintech landscape, examining both the regulatory environment and practical considerations for businesses operating in or entering the Vietnamese market. Topics covered include: Fintech landscape and initiatives: General innovation climate; government and regulatory support Financial regulation: Regulatory bodies; regulated activities; consumer lending; secondary market loan trading; collective investment schemes; alternative investment funds; peer-to-peer and marketplace lending; crowdfunding; invoice trading; payment services; open banking; robo-advice; insurance products; credit references Cross-border regulation: Passporting; requirement for a local presence Sales and marketing: Restrictions on the promotion and marketing of financial products and services Cryptoassets and tokens: Distributed ledger technology; cryptoassets; token issuance Artificial intelligence: Regulatory framework governing AI systems and AI-enabled financial services Change of control: Notification and consent requirements for regulated businesses Financial crime: Anti-bribery and anti-money laundering procedures; regulatory guidance Data protection and cybersecurity: Data protection obligations; cybersecurity requirements applicable to fintech businesses Outsourcing and cloud computing: Outsourcing of material functions; use of cloud computing in the financial services industry Intellectual property rights: IP protection for software; employee- and contractor-created IP; joint ownership; trade secrets; branding; remedies for infringement Competition: Competition law issues affecting fintech businesses Tax: Incentives for innovation and investment; developments affecting tax and compliance obligations Immigration: Immigration options for recruiting skilled foreign personnel; special measures available through Vietnam’s international financial centers The chapter also examines a number of significant recent developments shaping Vietnam’s fintech sector, including the introduction of the country’s first comprehensive regulatory framework for cryptoassets, the adoption of a dedicated law on artificial intelligence, implementation of the banking regulatory sandbox,
August 3, 2026
On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026. Background The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements. Expanded Scope of Regulated Entities and Channels The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking. Strengthened Customer Authentication The draft introduces enhanced authentication requirements in three areas: Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits. Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases. Secure authentication factors. Key requirements include the following: “What-you-know” factors must