You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

July 11, 2014

Microinsurance Needs a Push to Reach Potential in Thailand

Bangkok Post, Corporate Counsellor Column

In order to expand the availability of life and non-life insurance policies to those who are unable to afford standard premiums, the Office of the Insurance Commission (OIC) has been promoting microinsurance in Thailand.

As the word suggests, a microinsurance policy carries a low premium and limited coverage. The policies are largely standardized and have simpler wording (approved by the OIC), containing all possible information that the customer might need to know about the policy. The policies also have a simplified claims process and are available through more convenient channels of sale.

From a public policy standpoint, microinsurance is aimed at providing financial protection in respect of personal risks, addressing perceived problems in Thailand’s pension system, reducing debt owed to loan sharks, addressing social inequality, and increasing savings. Multiple insurance companies, insurance industry associations, and the OIC have been involved in its development.

Premiums and Coverage

Microinsurance premiums range from THB 200 to THB 1,000 per year, depending on the product. Several policies are available, including life insurance, residential fire insurance, personal accident insurance, and life/savings insurance, among others.

One of the first products to be launched is “Microinsurance 200.” In line with its name, it has an annual premium of only THB 200. It provides coverage of up to THB 100,000, depending on the type of loss. Specifically, coverage is divided into three categories:

  1. THB 100,000 for accidental death, loss of hand, foot, or eyesight, or permanent disability, due to causes other than those listed under item 2;
  2. THB 50,000 for accidental death, loss of hand, foot, or eyesight, or permanent disability, due to motorcycle accident (whether as the driver or a rider of a motorcycle), or in the case of murder or assault; or
  3. THB 10,000 for funeral expenses due to death from illness (after the first 120 days of the policy term).

Conditions

Eligibility to purchase Microinsurance 200 and to make claims against it is subject to certain conditions. Among these, the customer must be aged 20 to 60 years old, and once issued, the policy cannot be cancelled or revoked. In addition, a customer cannot purchase more than two policies, regardless of the insurance company used, and any excess policies (i.e., third, fourth, and onwards) are ineffective. Provisions exist for refunds in case a customer purchases too many.

Distribution Channels

Microinsurance can be purchased via nontraditional channels, such as through Counter Service at 7-Eleven, Tesco Lotus, and certain convenience stores. The OIC regulations provide that microinsurance products can only be offered for sale via staff of the insurance company at the points of sale located at the insurance company; insurance agents or brokers; insurance agents for microinsurance; or auto-distribution machines.

Microinsurance agents and brokers are subject to a more lax licensing regime, to encourage people to sell microinsurance and increase its availability. This is logical, given that microinsurance is targeted at a different demographic, compared to that of traditional insurance. As for auto-distribution machines, these are subject to approval by the OIC, and are not yet available. Despite the apparent ease of access to microinsurance, the OIC still maintains a tight regulatory grip on the industry, which provides protection for consumers.

The sales process has been simplified as well. Regulations require that insurance companies require each of the sales channels to request certain information from each customer. In practice, a customer need only scan his or her identification card at the point of sale and input a mobile phone number. After that, the customer can pay the premium, and a payment slip is issued on the spot.

For some categories of microinsurance, a certificate of insurance is also issued on the spot, and the coverage becomes effective immediately. For other types of insurance, additional information may be required from the customer before the policy becomes effective. In such a case, a customer would typically receive a phone call after purchase requesting such additional information.

For example, in the case of some types of life insurance, information may be sought on the customer’s health condition. If the customer is approved, the insurance company would send a confirmation text message, and the coverage would then become effective. Afterwards, a microinsurance certificate is sent to the customer’s home address. Then, insurance companies are obliged to report the results of the sale to the OIC.

Clearly, purchasing microinsurance is a very quick and easy process. Nevertheless, reports thus far indicate that the uptake of microinsurance has fallen below expectations. There could be any number of reasons for this. Going forward, the insurance industry will need to consider modifying its business model in order to effectively reach out to customers, and it will have to reduce the administrative costs related to the promotion of microinsurance. The OIC will also need to create a regulatory environment suitable for the proliferation of microinsurance in Thailand.

RELATED INSIGHTS​ 

June 5, 2026
Thailand’s Office of Insurance Commission (OIC) has opened a public hearing on proposed amendments to the OIC Notification on Criteria for Information Technology Risk Governance and Management for Life Insurance and Non-Life Insurance Companies B.E. 2563 (2020) via the centralized Law platform. The public consultation period runs from May 8, 2026, to June 9, 2026. The proposed amendments aim to elevate the IT risk governance and cybersecurity risk management framework to be more modern and aligned with international standards, with a focus on strengthening cyber resilience, enhancing the role of IT audits, and establishing data governance and data quality controls. The parties affected by these amendments include life insurance companies, non-life insurance companies, and external IT auditors. Key Changes Elevated Role of Board of Directors The proposed notification requires the company’s board of directors to oversee data governance, cybersecurity, and the responsible use of AI. Additionally, the board should include at least one director with IT knowledge or experience. Companies are also required to designate a head of security responsible for information security. The board’s duties are expanded to include oversight of data governance and AI usage, including establishing relevant policies and committees. Enhanced IT Security and Cybersecurity The revised notification consolidates the existing chapters on IT project management, IT security and cybersecurity to reduce redundancy, and introduces significant new measures. These include mandatory multi-factor authentication for material systems, enhanced data security measures such as data masking and data leakage prevention, security hardening requirements, web filtering, and mandatory vulnerability assessment and penetration testing at least annually. New requirements are also introduced for mobile application security, API security, and security measures for emerging technologies such as cloud computing and post quantum cryptography. The cybersecurity framework now encompasses identification, protection, detection, response, and recovery. The draft also introduces source code review
April 9, 2026
Thailand’s Office of the Insurance Commission (OIC) has published two parallel sets of draft regulatory amendments for public hearing—one governing non-life insurance and the other governing life insurance. The proposed amendments would significantly revise the rules for issuing, offering, and selling insurance policies, as well as the conduct of agents, brokers, and banks. Stakeholders may submit comments until April 25, 2026. The key proposed changes are summarized below. Electronic Policy Delivery by Default Under both draft amendments, electronic delivery would become the default method for delivering insurance policies. A printed copy would be required only if the policyholder expressly opts out, and any such printed copy would be treated as a substitute for the electronic original. For life insurance, this requirement would also extend to coverage summaries and to exclusion documents. The OIC would also retain authority to approve alternative delivery methods for specific types of policies. Misuse of Licenses Both amendments would introduce an explicit prohibition against sales representatives using another person’s name or license, or allowing another person to use their name or license, in connection with the offering of insurance or in sales documentation and policies. Premium Collection Reforms Both amendments would introduce the premium collection reforms outlined below. Premium receipt accounts Insurers must ensure that sales representatives inform customers of the available payment channels, which are limited to channels that remit premiums into the insurer’s account. If a customer pays an insurance premium to an insurer’s employee, an insurance broker, or any other person, and the company acknowledges the payment by issuing an insurance policy or other documentary evidence of insurance coverage, the insurer would be deemed to have received the insurance premium. Written premium collection and refund guidelines Insurers would be required to prepare written internal guidelines covering premium collection and refund policies, risk
April 2, 2026
Thailand’s Personal Data Protection Act (PDPA) enforcement has entered a new phase, and the insurance industry is squarely in the regulatory spotlight. The Personal Data Protection Committee (PDPC) considers insurers “large-scale” processors of sensitive data—including health records, financial information, and biometric data—making the sector a focal point for enforcement action. In August 2025 alone, the PDPC issued administrative fines totaling THB 21.5 million, and fines for individual violations have ranged from THB 50,000 to THB 2 million. The PDPC has also deployed its “Eagle Eye Crawler,” an AI-driven surveillance tool that monitors websites around the clock for data leaks and noncompliant privacy notices. This article highlights the key regulatory developments directly affecting insurers and outlines practical steps toward compliance. What Has Changed: OIC and PDPC Alignment The Office of Insurance Commission (OIC) has synchronized its sector-specific rules with the PDPA through the Notification on Customer Personal Data Protection (No. 2) B.E. 2568 (2025). The combined effect of the PDPC’s general enforcement push and the OIC’s sectoral guidance creates four critical compliance areas for insurers. Consent unbundling. Consent for marketing must be strictly separated from the core insurance contract; bundling marketing consent into the policy application is no longer permissible. Agent and intermediary oversight. Insurance intermediaries are generally classified as data processors, meaning that insurers—as data controllers—must provide specific written instructions and security protocols to all agents and brokers. A 2026 enforcement trend shows controllers being held liable for the “weak security” of their vendors and downstream processors. Enhanced privacy notices. Insurers must provide a summary privacy notice alongside the full policy, plainly stating categories of data, purposes, lawful bases, disclosure recipients, cross-border transfers, retention periods, data subject rights, and easy marketing opt-out channels. DPO registration and ROPA. All organizations involved in “regular or systematic monitoring of data subjects on
March 17, 2026
Thailand’s Office of Insurance Commission (OIC) has introduced comprehensive group-wide supervision requirements for insurers operating within corporate groups. Published on February 26, 2026, in two separate notifications in the Government Gazette, the new rules establish parallel frameworks for life and non-life insurance companies. Both notifications take effect on July 1, 2026, and impose significant new requirements on insurance business groups. Affected insurers should begin reviewing their group structures, governance frameworks, and risk management systems now to ensure timely compliance. The notifications aim to ensure that group-level operations are orderly, stable, and reliable, and prevent the accumulation of systemic risk that could undermine public confidence in the insurance sector. Both notifications share a substantially parallel structure and require insurers to assess and manage the financial position, risk exposure, reliability, and corporate governance of their entire insurance business group on a comprehensive and ongoing basis. The regulations introduce definitions for several key terms. An “insurance business group” encompasses the insurer together with its ultimate parent company, parent companies, subsidiaries, and related companies. The “head of the insurance business group” is the entity responsible for overseeing group-wide supervision, operations, and governance. An “ultimate parent company” is one that exercises control without itself being controlled by another entity. Key Requirements The notifications establish the following core obligations for insurers: Group structure and shareholding reporting: Insurers must report the organizational chart and shareholding structure of their insurance business group—covering the ultimate parent company, parent companies, subsidiaries, and related entities—to the OIC registrar by June of each year, and whenever material changes occur. The regulations prescribe specific thresholds for determining when shareholding proportions constitute control. Corporate governance standards: Board members, executives, and authorized persons of the ultimate parent company or parent company must not be disqualified (e.g., bankrupt individuals, persons convicted of property-related fraud, or