You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

December 17, 2018

Lex Mundi Anticorruption Compliance Guide—Cambodia Report

Lex Mundi

Partner and director of Tilleke & Gibbins’ Phnom Penh office, Jay Cohen, and advisor, Sophea Sin have contributed their expertise and knowledge to the Cambodia section of the global Anticorruption Compliance Guide  produced by Lex Mundi, the world’s largest network of independent law firms. Their detailed responses give considerable insight into anti-bribery and corruption legislation in Cambodia—all of which was enacted within the last ten years—specifically on laws relating to anti-bribery and corruption, criminal liabilities, and penalties for violations.

This comprehensive and interactive guide provides local insight on anti-bribery and corruption regimes in 78 jurisdictions globally. Reports follow a question and answer format, with responses provided appropriately and thoroughly by a Lex Mundi member firm from each respective jurisdiction. In addition to contributing the Cambodia report for the guide, Tilleke & Gibbins’ legal professionals also supplied the responses for the reports covering Laos, Myanmar, Thailand, and Vietnam.

To view the full Cambodia report, please download the PDF below. For reports from the other 77 jurisdictions, please visit Lex Mundi’s website.

RELATED INSIGHTS​ 

June 10, 2026
For multinational franchisors operating in Thailand, a key risk after franchise termination is that former outlets may continue operating in ways that could easily mislead consumers into believing they remain within the authorized network. To justify such operations, former franchisees often argue that the termination was invalid or ineffective. As a result, these cases are often treated as contractual disputes, making it difficult for franchisors to obtain injunctive relief before a final judgment confirms that the termination was lawful. Franchisors face significant commercial and reputational harm during lengthy proceedings, including consumer confusion, disruption to franchise restructuring, and damage to brand reputation and customer trust. In an encouraging development, the Thai court in a 2025 case responded to the problem of unauthorized post-termination franchise operations by granting interim relief, recognizing broader brand and consumer harm, and awarding substantial damages, highlighting a successful litigation strategy of framing the dispute not merely as a contractual termination issue but as trademark infringement causing ongoing commercial injury. The Subway Case From December 2024 to mid-2025, an unauthorized “Subway®” franchise operation in Thailand attracted substantial public and media attention. Reports and online discussions about unauthorized Subway® stores circulated widely after complaints arose about food quality and customer experience at certain outlets that were allegedly operating after their franchise rights had expired. Because these stores continued to use Subway® trademarks, trade dress, and overall commercial appearance, many consumers were unable to distinguish them from authorized operations, resulting in reputational risks and customer confusion that affected the franchisor’s brand and franchise system in Thailand. Subway treated this matter with the utmost seriousness and moved promptly to protect its brand, franchise system, and customers. It filed a civil action with the IP&IT Court seeking a permanent injunction and damages. During the proceedings, the court granted a preliminary injunction
June 9, 2026
On April 28, 2026, the Central Bank of Myanmar (CBM) issued Notification No. 18/2026 introducing the new Foreign Remittance Business Regulations. The new regulations apply to companies intending to operate foreign remittance businesses in Myanmar that are not licensed banks, non-bank financial institutions, or other financial institutions. The regulations supersede and replace the previous regulatory framework governing foreign remittance businesses under CBM Notification No. 21/2019. While the overall structure remains familiar, the new regulations introduce more detailed requirements for licensing, operations, reporting, and compliance, with a stronger focus on transparency and regulatory oversight. Broader Licensing Requirements Under the new regulations, applicants must submit detailed business plans describing the use of information technology and mobile platforms, along with clear plans for handling remittances from workers abroad and resolving customer complaints. Financial Thresholds and Reporting Requirements The baseline financial thresholds remain unchanged. Licensees must maintain a security deposit of MMK 100 million in an escrow account, along with a separate revolving fund dedicated solely to remittance operations. The new regulations introduce more structured reporting obligations. Licensees are now required to submit daily remittance transaction data by the next business day before noon, in addition to monthly and periodic reporting requirements. Foreign bank account statements must also be submitted regularly, and licensees must provide updates on business operations every six months. Strengthened AML and CFT Framework The new regulations place a greater emphasis on anti-money laundering (AML) and counter financing of terrorism (CFT), with tighter controls over management changes. Any changes in shareholding, share transfers, or the appointment of key management personnel such as the managing director require prior approval from the CBM. Licensing Fees and Validity The new regulations increase licensing costs, while maintaining the same validity period of three years. The new regulations provide more detailed grounds for suspension and
June 5, 2026
On May 25, 2026, Vietnam’s Ministry of Health issued Circular No. 16/2026/TT-BYT governing free-of-charge medicine support programs for medical establishments (Circular 16). Circular 16 will take effect on July 10, 2026, replacing Circular No. 31/2018/TT-BYT, which currently regulates the same subject matter. Circular 16 introduces several significant changes compared to the existing legal framework. Removal of Prior Approval Requirement Under the current regulations, free-of-charge medicine support programs are divided into two categories: (1) entirely free-of-charge provision of medicines for all types of drugs and (2) partially free-of-charge provision applicable only to brand-name drugs under patent protection or drugs whose generic products with identical active ingredients and dosage forms are available in Vietnam. Under the current regulations, partially free-of-charge programs are subject to mandatory registration with the competent authority, while entirely free-of-charge programs could be implemented without prior approval. A key reform under Circular 16 is that it stipulates only entirely free-of-charge medicine support programs applicable to all types of medicines, thereby eliminating the partially free-of-charge category. In addition, free-of-charge medicine support programs may be carried out solely based on a written agreement between the pharmaceutical company and the medical establishment, without any requirement for prior approval from competent authorities prior to implementation. Written Agreement Requirements Circular 16 requires the pharmaceutical company and medical establishment to enter into a written agreement in accordance with a prescribed template. This agreement must include the following compulsory information: Information on the supported medicines Form of support (entirely free-of-charge provision to patients) Quantity of medicines provided Target patient groups and applicable indications Duration of the program Rights and obligations of each party Transitional provisions on the protection of patients’ rights upon completion of the program The agreement may contain other contents as agreed by the parties, provided that these do not contradict applicable laws.
June 5, 2026
Thailand’s Office of Insurance Commission (OIC) has opened a public hearing on proposed amendments to the OIC Notification on Criteria for Information Technology Risk Governance and Management for Life Insurance and Non-Life Insurance Companies B.E. 2563 (2020) via the centralized Law platform. The public consultation period runs from May 8, 2026, to June 9, 2026. The proposed amendments aim to elevate the IT risk governance and cybersecurity risk management framework to be more modern and aligned with international standards, with a focus on strengthening cyber resilience, enhancing the role of IT audits, and establishing data governance and data quality controls. The parties affected by these amendments include life insurance companies, non-life insurance companies, and external IT auditors. Key Changes Elevated Role of Board of Directors The proposed notification requires the company’s board of directors to oversee data governance, cybersecurity, and the responsible use of AI. Additionally, the board should include at least one director with IT knowledge or experience. Companies are also required to designate a head of security responsible for information security. The board’s duties are expanded to include oversight of data governance and AI usage, including establishing relevant policies and committees. Enhanced IT Security and Cybersecurity The revised notification consolidates the existing chapters on IT project management, IT security and cybersecurity to reduce redundancy, and introduces significant new measures. These include mandatory multi-factor authentication for material systems, enhanced data security measures such as data masking and data leakage prevention, security hardening requirements, web filtering, and mandatory vulnerability assessment and penetration testing at least annually. New requirements are also introduced for mobile application security, API security, and security measures for emerging technologies such as cloud computing and post quantum cryptography. The cybersecurity framework now encompasses identification, protection, detection, response, and recovery. The draft also introduces source code review