You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

December 28, 2023

Laos Updates the Law on Commercial Banks

On October 13, 2023, Laos’ official gazette published the amended Law on Commercial Banks No. 39/NA dated July 17, 2023. The amended law came into effect on September 15, 2023, following its promulgation by the president of Laos.

Below are some of the significant changes.

Registered Capital

Under the amended law, the minimum registered capital for establishing a commercial bank has been increased from LAK 500 billion (approx. USD 24.2 million) to LAK 1 trillion (approx. USD 48.4 million), while the minimum registered capital for Lao branches of foreign commercial banks has been raised from LAK 300 billion (approx. USD 14.5 million) to LAK 600 billion (approx. USD 29 million).

Currently, the Bank of Lao PDR (BOL) is preparing a new regulation that will define the timeframe within which banks established in Laos before the enactment of the amended law must increase their registered capital.

This change is not as significant as it may seem. Since the last Law on Commercial Banks (which also stipulated an increase in registered capital), Laos has seen a sharp depreciation of the Lao kip against foreign currencies. The increase of capital mandated by the amended law is meant to compensate for this depreciation.

Change of Status of a Commercial Bank of a Brand of a Foreign Commercial Bank

Another article in the amended law outlines two scenarios in which banks may alter their status. First, a foreign commercial bank in Laos holding 100% shares may change its status to a Lao branch of a foreign commercial bank. Conversely, a Lao branch of a foreign commercial bank may elevate its status to that of a foreign commercial bank holding 100% shares. In both cases, the bank must request a business operating license from the BOL corresponding to its new status, requiring it to meet certain conditions. Importantly, this change in status pertains only to the legal classification and is not to alter commitments to depositors and creditors, or fulfillment of tax obligations.

Appointment of the Management Board

The amended law introduces a requirement for the Management Board to meet at least once every three months; however, the law remains unchanged regarding the governance structure, number, and terms of the members of the Management Board. The board’s term also remains three years, and members may be consecutively reappointed for up to three terms.

The Management Board continues to consist of at least five members (i.e., a chairman, a deputy chairman, and other members appointed by shareholders with approval from the BOL). Among those members, one must be an “external member”—that is, someone who is not an employee, has no family relatives in the bank, and has no contractual relationship or business benefit with any shareholders or board members of the bank.

The qualifications are not dramatically amended in the new law. The members should have a “good history,” and a new emphasis is placed on members not having been sanctioned for misdeeds, such as asset misappropriation, document forgery, money laundering, financing of terrorism, human trafficking, bribery, narcotics offenses, or wrongdoings in relation to finance, currency, or corrupt behavior.

The Management Board is still assisted by the mandatory committees (i.e., Governance Committee, Risk Management Committee, Audit Committee, and any other committee deemed necessary by the Management Board).

Recordkeeping

The amended law provides that the following documents must be kept at the bank’s headquarters:

  • Articles of association, internal policies, handbooks, and other required documents;
  • Shareholders’ registry;
  • Records and resolutions of the shareholders’ meetings;
  • Records and resolutions of the meetings of the Management Board and its committees;
  • Records of the status of the business, the bank’s transactions, and other financial matters;
  • Records of each customer’s transactions, credit documents, and accounts;
  • Internal and external audit reports; and
  • Other documents deemed necessary by the BOL.

For branches of foreign commercial banks, documents must be kept at the branch established in Laos.

Previously, the law provided that documents, along with electronic records, must be kept for at least ten years. The amended law now adds that this information must be kept 10 years after the relevant document or transaction is effectuated or from when a contract is terminated.

Lao Bankers’ Association

The amended law establishes the Lao Bankers’ Association (LBA) for the purpose of managing and coordinating activities between commercial banks in Laos. The LBA’s objectives include providing assistance, holding consultations, facilitating exchanges on various banking matters, enhancing banking business operations and experiences, and addressing issues or concerns of the LBA’s members with relevant government agencies. Both commercial banks and Lao branches of foreign banks are to hold equal membership status within the LBA, and the LBA’s activities must be conducted in accordance with its articles of association, which have been approved by the BOL.

Takeaways

The amended Law on Commercial Banks updates some of the rules for Laos’ banking system while maintaining a steady continuation of most existing principles and guidelines. Commercial banks in Laos (including branches of foreign banks) should ensure timely compliance with the changes—particularly the increased minimum registered capital requirements—and take note of how the country’s regulatory environment for commercial banks is evolving.

RELATED INSIGHTS​ 

August 3, 2026
On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026. Background The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements. Expanded Scope of Regulated Entities and Channels The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking. Strengthened Customer Authentication The draft introduces enhanced authentication requirements in three areas: Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits. Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases. Secure authentication factors. Key requirements include the following: “What-you-know” factors must
July 27, 2026
A new decree on penalties for violations related to the crypto asset market creates compliance risks for offshore crypto asset exchanges in Vietnam that do not hold, and practically cannot obtain, a Vietnamese license, and for Vietnamese users who continue to transact on those platforms. Decree No. 284/2026/ND-CP (Decree 284), issued by the government of Vietnam on July 16, 2026, formally establishes an administrative penalty framework for violations related to crypto assets and the crypto asset market. The decree takes effect on September 1, 2026, and will remain in force for the duration of the five-year pilot program under Resolution No. 05/2025/NQ-CP, which is scheduled to end in September 2030. Direct Penalties on Vietnamese Users The most immediate commercial risk to offshore platforms is that their Vietnamese users now face direct personal liability for using their exchanges. Vietnamese users who trade crypto assets outside of a Ministry of Finance-licensed service provider face fines of up to VND 50 million (approximately USD 1,900). Vietnamese users trading in crypto assets that are offered or issued to foreign users face higher penalties of up to VND 100 million (approximately USD 3,800). It is expected that Vietnamese users will be more willing to migrate away from offshore platforms now that there is a risk of real enforcement against them. Penalties on Unlicensed Service Providers Violations of providing crypto asset services or advertising crypto-related services without a license face fines of up to VND 200 million (approximately USD 7,700). Operating a crypto asset trading market without proper authorization falls within the same highest penalty bands. Organizations that violate issuance, provision, or disclosure rules may face fines of up to VND 200 million. Although the maximum administrative fine per violation is capped at VND 200 million for organizations and VND 100 million for individuals, these
July 17, 2026
On July 11, 2026, media reports conveyed key messages from Bank of Thailand (BOT) Governor Vitai Ratanakorn’s announcement of a sweeping regulatory crackdown on grey capital activities. The measures target high-value cash transactions, gold trading, and stablecoin flows, with new requirements set to take effect in the fourth quarter of 2026. The initiative aims to prevent financial institutions from facilitating shadow economy activity, money laundering—particularly through stablecoins—and capital flight, through enhanced compliance obligations on commercial banks across multiple transaction channels. Expanded Cash Controls Close the Deposit–Withdrawal Circuit New fourth-quarter guidelines will require individuals depositing THB 5 million or more in cash to formally verify the source of their funds. This builds on restrictions introduced in April 2026, which required anyone withdrawing 5 million baht or more in cash to provide their bank with verified commercial justification for why electronic transfers or checks could not be used. That initial measure caused high-value physical cash withdrawals to drop by 35 percent nationwide. The upcoming deposit-side requirement closes the circuit on large cash movements. The BOT is also assessing tracking mechanisms for high-value banknote swaps, specifically targeting individuals seeking to exchange large volumes of THB 1,000 notes into smaller THB 100 or THB 500 denominations without clear business justification. Governor Vitai emphasized that these measures require continuous deployment of multiple parallel strategies rather than short-term fixes. Tightened Bullion Reporting Frameworks Restrict Money Laundering Channels The BOT has also tightened reporting frameworks for gold trading to close money laundering loopholes and shield the Thai baht from speculative bullion volatility. Regulators identified a recurring pattern in which buyers purchased large quantities of gold through digital applications in the morning and then made same-day physical withdrawals from retail gold shops in the afternoon. Gold shops are reminded of their duties to flag and report cash
June 23, 2026
On May 14, 2026, Thailand published a ministerial regulation in the Government Gazette to prescribe measures for prevention and suppression of technology crimes. The regulation creates a comprehensive procedural framework for returning money and digital assets to victims of technology crimes. It will take effect 90 days after publication (in mid-August 2026), giving affected entities a limited window to prepare. Mandatory Reporting Obligations for Financial Institutions When a deposit account, e-money account, or digital asset wallet is frozen in connection with a technology crime, the relevant financial institution or business operator must report transaction data to the Anti-Money Laundering Office (AMLO) via AMLO’s designated electronic system. Required data elements include account numbers (sender and receiver), names, identification or passport numbers, legal entity registration numbers, phone numbers, remaining balance, damage amount, transaction reference numbers, and the bank case ID. Institutions that already share data through the information-sharing system under the emergency decree are deemed to have satisfied this reporting obligation, creating an incentive for platform participation. When the Royal Thai Police or the Department of Special Investigation seize or freeze assets related to technology crimes, they must provide AMLO with investigation reports, complaint evidence, money-trail data, and account statements. Notification and Claims Process Once the AMLO secretary-general approves verified reports of a technology crime, the account information of persons connected to the crime will be published in the Government Gazette, triggering a 90-day window for victims to file claims and for related persons to file objections. Officers will also publish details on AMLO’s electronic media and send registered mail to identified victims, which will be deemed received after 7 days domestically or 15 days internationally. Victims have 90 days from the date the crime is published in the Government Gazette to file claims through AMLO’s electronic system. Claims must include