You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 28, 2021

Myanmar Issues New Guidelines for Non-Banking Financial Institutions

On January 26, 2021, the Central Bank of Myanmar (CBM) published Notification 1/2021 in relation to non-banking financial institutions (NBFIs). This notification, which took immediate effect and has far-reaching implications for NBFI operations in Myanmar, applies to NBFIs wishing to conduct finance company business, leasing business, or factoring business, which are defined in the Financial Institutions Law (2016) (FIL) as follows:

  • Finance company business is “business engaging primarily in financing the purchase of goods or services with funding other than deposits from the public.” Interest would be charged on such finance.
  • Leasing business is “the business of letting or sub-letting movable property on hire, regardless whether the letting is with or without an option to purchase the property.” An obvious example would be vehicle leasing.
  • Factoring business is “the business of financing accounts receivables.” This is when a business sells its accounts receivable at a discount.

The key provisions of the notification are summarized below.

NBFI Registration

To conduct any of the above businesses, an individual or company must apply for a registration certificate from the CBM by submitting the documents specified in the notification. The registration certificate may come with terms and conditions prescribed by the CBM on a case-by-case basis. It seems likely that these terms and conditions could include minimum capital requirements, but this remains to be seen.

Trading as an NBFI without a CBM certificate is punishable by two to five years imprisonment and a fine of MMK 500 million (approx. USD 375,000).

NBFI Certificate Revocation

The CBM has extensive powers to revoke the NBFI certificate in certain circumstances, including failure to comply with the terms and conditions of the registration certificate; conducting non-NBFI business; conducting business in a manner detrimental to the interests of consumers; failure to comply with anti-money laundering or counter terrorism laws and regulations; and so on.

Prohibition on Deposit Acceptance

The notification makes clear that, unlike a commercial bank, an NBFI may not accept a deposit, which is defined by the FIL as “a sum of money paid on terms under which it will be repaid or it is repayable, either wholly or in part, with any consideration in money or money’s worth and such repayment being either, on demand or at a time or in circumstances agreed by the person or an entity making the payment and the person receiving it.”

Foreign Ownership

Interestingly, the notification refers to changes in ownership from local to foreign control, or ceasing the status of a foreign company, which implies that 100% foreign-owned NBFIs will be permitted. From our discussions with the CBM it appears that foreign investment may be allowed on a case-by-case basis, but this has yet to be confirmed. If so, this would be an interesting new opportunity for foreign investors in the financial sector. Currently there are no foreign-owned NBFIs in Myanmar.

Further Provisions

Among other things, the notification continues to deal with interest rates that may be charged by an NBFI, fit and proper requirements for senior management, financial reporting to the CBM, and inspection by the CBM.

For more details on the CBM’s notification for NBFIs, or on any aspect of banking law in Myanmar, please contact Dr. Ross Taylor at [email protected] or +66 2056 5880.

RELATED INSIGHTS​ 

August 3, 2026
On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026. Background The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements. Expanded Scope of Regulated Entities and Channels The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking. Strengthened Customer Authentication The draft introduces enhanced authentication requirements in three areas: Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits. Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases. Secure authentication factors. Key requirements include the following: “What-you-know” factors must
July 27, 2026
A new decree on penalties for violations related to the crypto asset market creates compliance risks for offshore crypto asset exchanges in Vietnam that do not hold, and practically cannot obtain, a Vietnamese license, and for Vietnamese users who continue to transact on those platforms. Decree No. 284/2026/ND-CP (Decree 284), issued by the government of Vietnam on July 16, 2026, formally establishes an administrative penalty framework for violations related to crypto assets and the crypto asset market. The decree takes effect on September 1, 2026, and will remain in force for the duration of the five-year pilot program under Resolution No. 05/2025/NQ-CP, which is scheduled to end in September 2030. Direct Penalties on Vietnamese Users The most immediate commercial risk to offshore platforms is that their Vietnamese users now face direct personal liability for using their exchanges. Vietnamese users who trade crypto assets outside of a Ministry of Finance-licensed service provider face fines of up to VND 50 million (approximately USD 1,900). Vietnamese users trading in crypto assets that are offered or issued to foreign users face higher penalties of up to VND 100 million (approximately USD 3,800). It is expected that Vietnamese users will be more willing to migrate away from offshore platforms now that there is a risk of real enforcement against them. Penalties on Unlicensed Service Providers Violations of providing crypto asset services or advertising crypto-related services without a license face fines of up to VND 200 million (approximately USD 7,700). Operating a crypto asset trading market without proper authorization falls within the same highest penalty bands. Organizations that violate issuance, provision, or disclosure rules may face fines of up to VND 200 million. Although the maximum administrative fine per violation is capped at VND 200 million for organizations and VND 100 million for individuals, these
July 17, 2026
On July 11, 2026, media reports conveyed key messages from Bank of Thailand (BOT) Governor Vitai Ratanakorn’s announcement of a sweeping regulatory crackdown on grey capital activities. The measures target high-value cash transactions, gold trading, and stablecoin flows, with new requirements set to take effect in the fourth quarter of 2026. The initiative aims to prevent financial institutions from facilitating shadow economy activity, money laundering—particularly through stablecoins—and capital flight, through enhanced compliance obligations on commercial banks across multiple transaction channels. Expanded Cash Controls Close the Deposit–Withdrawal Circuit New fourth-quarter guidelines will require individuals depositing THB 5 million or more in cash to formally verify the source of their funds. This builds on restrictions introduced in April 2026, which required anyone withdrawing 5 million baht or more in cash to provide their bank with verified commercial justification for why electronic transfers or checks could not be used. That initial measure caused high-value physical cash withdrawals to drop by 35 percent nationwide. The upcoming deposit-side requirement closes the circuit on large cash movements. The BOT is also assessing tracking mechanisms for high-value banknote swaps, specifically targeting individuals seeking to exchange large volumes of THB 1,000 notes into smaller THB 100 or THB 500 denominations without clear business justification. Governor Vitai emphasized that these measures require continuous deployment of multiple parallel strategies rather than short-term fixes. Tightened Bullion Reporting Frameworks Restrict Money Laundering Channels The BOT has also tightened reporting frameworks for gold trading to close money laundering loopholes and shield the Thai baht from speculative bullion volatility. Regulators identified a recurring pattern in which buyers purchased large quantities of gold through digital applications in the morning and then made same-day physical withdrawals from retail gold shops in the afternoon. Gold shops are reminded of their duties to flag and report cash
June 23, 2026
On May 14, 2026, Thailand published a ministerial regulation in the Government Gazette to prescribe measures for prevention and suppression of technology crimes. The regulation creates a comprehensive procedural framework for returning money and digital assets to victims of technology crimes. It will take effect 90 days after publication (in mid-August 2026), giving affected entities a limited window to prepare. Mandatory Reporting Obligations for Financial Institutions When a deposit account, e-money account, or digital asset wallet is frozen in connection with a technology crime, the relevant financial institution or business operator must report transaction data to the Anti-Money Laundering Office (AMLO) via AMLO’s designated electronic system. Required data elements include account numbers (sender and receiver), names, identification or passport numbers, legal entity registration numbers, phone numbers, remaining balance, damage amount, transaction reference numbers, and the bank case ID. Institutions that already share data through the information-sharing system under the emergency decree are deemed to have satisfied this reporting obligation, creating an incentive for platform participation. When the Royal Thai Police or the Department of Special Investigation seize or freeze assets related to technology crimes, they must provide AMLO with investigation reports, complaint evidence, money-trail data, and account statements. Notification and Claims Process Once the AMLO secretary-general approves verified reports of a technology crime, the account information of persons connected to the crime will be published in the Government Gazette, triggering a 90-day window for victims to file claims and for related persons to file objections. Officers will also publish details on AMLO’s electronic media and send registered mail to identified victims, which will be deemed received after 7 days domestically or 15 days internationally. Victims have 90 days from the date the crime is published in the Government Gazette to file claims through AMLO’s electronic system. Claims must include