You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 23, 2013

Licensing Exemptions for Foreign Securities Firms

Bangkok Post, Corporate Counsellor Column

The Stock Exchange of Thailand has taken many steps in recent years towards gradual liberalisation of the country’s capital market. For example, more foreign products are now permitted to be offered to Thai investors. This includes qualifying foreign exchange-traded funds, qualifying Asean Collective Investment Scheme and foreign-listed stocks with the intention of secondary listings on the SET. Exchange-control rules have also been relaxed, allowing Thai investors—both institutions and high net worth individuals—to invest in foreign capital markets.  

As a result, Thai mutual funds managed by private firms or government authorities have increasingly invested offshore, leading to numerous foreign mutual fund managers, investment banking and private equity firms focusing on Thailand as a new emerging market. Many of these entities have sought advice on the legal guidelines for approaching their prospective Thai investors.

There are several different regulated securities businesses. The licences to conduct those businesses currently are granted solely to banks and financial institutions and local securities companies, which are subject to heavy controls and compliance regulations.

Foreign securities firms generally are not permitted to conduct any securities businesses except as specifically exempted by Thailand’s Securities and Exchange Commission (SEC). For example, qualifying foreign securities firms wishing to offer services, not products, to Thai investors can enjoy exemptions for two securities businesses.

One is a discretionary investment management service or what is officially called a “private fund management service”, defined as “the management of funds of a person or group of persons who has authorised the management of investment to acquire benefit from securities, whether or not investment in other assets is also made, which management is conducted as an ordinary course of business, in consideration of a fee or other remuneration”.

According to SEC Notification Kor. Nor. 43/2549, qualifying foreign securities firms are automatically granted a general exemption to conduct this service without possessing a licence, if the following criteria are met:

  • The foreign securities firm has been licensed to conduct a securities business by a foreign regulator, which is an ordinary member of the International Organization of Securities Commissions (Iosco);
  • The foreign securities firm solicits and provides fund management services exclusively to any of the prescribed “institutional investors” in Thailand such as the GovernmentPension Fund, the Social Security Fund, insurance companies, commercial banks and securities companies, whether for their own accounts or the accounts of their institutional customers.

To qualify for the exemption, solicitations should be made only to institutional investors as defined in the notification.

Another type of securities business for which exemptions are available is investment advisory service, which means “giving advice in the normal course of business to the public whether directly or indirectly concerning the value of securities or the suitability of investing in those securities or the purchase or sale of any securities in consideration of a fee or other remuneration …”

This service is subject to SEC Notification No. Kor. Nor. 22/2544. It gives an exemption to qualifying foreign securities firms to give investment advice to Thai investors, without being licensed in Thailand, if the following criteria are met:

  • The foreign securities firm has been licensed to operate a securities business by a foreign regulator, which is an ordinary member of Iosco; and
  • The giving of advice is conducted in the following manner:

(a) In case of retail investors, the advice shall be conducted through Thai securities companies with proper licences;

(b) In case of institutional investors (same as above), the advice is specifically intended for institutional investors—a document showing the worst-case scenario of the investment in structured notes must be provided.

This essentially means qualifying foreign securities firms are free to solicit and be engaged by any Thai institutional investor to give advice on investments, provided the applicable regulatory requirements are met.

When conducting a securities business under the above exemptions, foreign securities firms should still observe conditions and restrictions imposed by other laws. For instance, the services should be provided on a cross-border basis. Otherwise, the foreign securities firm could be deemed to be “doing business in Thailand”, which would require a foreign business licence (FBL) under the Foreign Business Act.

Although it is probable an FBL could be obtained, the general post-FBL conditions such as establishing a physical branch office and bringing into Thailand an operating fund of at least 3 million baht could be an excessive burden.

Furthermore, representatives of the foreign securities firms sent to Thailand to conduct any business activities would require proper business visas from a Thai embassy or consulate and then work permits from the Employment Department.

Finally, any foreign securities firm wishing to open a representative office in Thailand for the purpose of being a contact point for its Thai investors can formally apply for a licence with the SEC, the process for which should be merely procedural.

RELATED INSIGHTS​ 

December 26, 2025
The Bank of Thailand (BOT) has released the Guidelines for Digital Fraud Management, which took effect on December 17, 2025, incorporating certain amendments to the draft guidelines issued in March 2025. These official guidelines aim for end-to-end digital fraud prevention, with a particular focus on mule accounts, to enhance trust and security in Thailand’s financial system. The guidelines apply to “financial service providers,” including: Financial institutions and special financial institutions under the Financial Institution Business Act; and Operators of Inter-institutional Fund Transfer System e-money services and e-fund transfer services under the Payment Systems Act. Besides commercial banks and e-money operators that offer fund-transfer services, other providers may adopt requirements based on risk proportionality and baseline standards set out in the guidelines (for instance, an e-money operator that does not offer e-fund transfer services could consider implementing a fraud monitoring and detection system according to the risk level of its service). The guidelines establish the following key requirements: Policy and oversight. Directors and senior executives of financial service providers must adopt appropriate “end-to-end” fraud management policies and KPIs to manage digital fraud, covering prevention, monitoring, detection, management, resolution, and support for affected customers. The fraud management policy must be regularly reviewed, and whenever there is a situation or change that significantly affects the efficiency of the fraud management. Any significant update to the policy must first be approved by the board of the financial service provider. The BOT also encourages providers to collaborate in establishing industry standards aligned with applicable laws and regulations to ensure consistency and best practices across the sector. Fraud management processes. Financial service providers must establish a clear framework for managing digital fraud throughout the customer lifecycle—from customer onboarding to service termination—covering at least the following processes: Know your customer (KYC) and customer due diligence (CDD):
November 24, 2025
A recent warning from the Central Bank of Myanmar (CBM) against cryptocurrency use upholds the country’s ongoing strategy of enforcing strict prohibitions on unauthorized cryptocurrency activities while also promoting the controlled development of a central bank digital currency (CBDC). The CBM’s warning, issued November 16, 2025, reminded the public of announcements in May 2019 and a notification in May 2020 confirming that all online and offline cryptocurrency transactions are strictly prohibited. The CBM also clarified that no financial institution in Myanmar is authorized to deal with digital currencies. The warning highlighted global risks, such as money laundering, scams, tax evasion, hacking, and severe financial losses caused by price volatility and insufficient regulation. The CBM urged the public to use only legitimate banking channels and avoid illegal cryptocurrency activities. The warning comes five months after the CBM issued a notification announcing the formation of the Central Committee for the Issuance of a Central Bank Digital Currency. This committee includes senior CBM officials, representatives from relevant ministries and the banking sector, and technology experts. Its main role is to research CBDC models, test secure digital payment systems, and ensure that any future implementation aligns with Myanmar’s monetary policy and financial stability objectives. Taken together, these two actions illustrate the CBM’s continued pursuit of its dual strategy to promote innovation through CBDC development while prohibiting cryptocurrency use. Businesses should note that while CBDC pilot programs may appear in the future, cryptocurrencies remain off-limits.
September 24, 2025
On September 12, 2025, the Bank of Thailand (BOT) officially released its AI Risk Management Guidelines for Financial Service Providers, building upon the draft guidelines issued in June 2025. The guidelines reflect a balanced approach, encouraging innovation while safeguarding financial stability and consumer protection. The guidelines are targeted at all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. The guidelines apply to both AI systems developed in-house and those developed by third parties that are adopted for use by financial service providers. AI Risk Management Guidelines The two main pillars in managing AI risk are (1) governance of AI system implementation and (2) AI system development and security controls, consisting of the following key elements: 1. Governance Stakeholder roles and responsibilities. Boards and senior management assume accountability for decisions and operations involving AI systems, and are responsible for defining roles and responsibilities for AI oversight. This includes establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. Organizations are expected to foster internal capabilities to use AI securely and avoid overreliance that could compromise business continuity or customer service. AI system usage policy. Policies governing AI usage should align with organizational goals, regulatory obligations, and recognized responsible AI frameworks—such as the FEAT principles (fairness, ethics, accountability, and transparency). These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. Financial service providers should assess risks and impacts of AI usage on operations and customer services.
September 12, 2025
On September 10, 2025, Vietnam’s National Credit Information Center (CIC) reported to the Vietnam Cybersecurity Emergency Response Team (VNCERT) a suspected significant cybersecurity incident involving unauthorized access to the CIC’s credit information database. A hacker group has claimed responsibility and allegedly posted over 160 million records for sale, including sensitive personal and financial data. Implications for Banks and Financial Institutions Companies that share customers’ or potential customers’ personal data with the CIC for credit scoring or other purposes—and continue to act as a data controller for such data—may be obligated under Vietnam’s Personal Data Protection Decree (PDPD) and related regulations to: Notify A05 (Department of Cybersecurity and High-Tech Crime Prevention) and the State Bank of Vietnam without delay. Inform affected individuals if their personal data is at risk. Recommended Actions Companies that could be impacted by this data breach should take the following actions: Conduct an internal review of CIC-related data in their systems, and identify whether and how the systems have been affected by this incident. Assess whether to notify regulators and customers/potential customers. Enhance cybersecurity controls, monitor for suspicious activity, and implement additional safeguards to prevent secondary breaches.