You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 26, 2016

New e-Payment Service Regulations for SFIs: A Boon for Customer Confidence?

Informed Counsel

In today’s digital economy, financial technology (FinTech) is a major economic driving force. FinTech has transformed the private sector, resulting in a drastic shift in the way customers use financial services. Financial institutions, in particular, have taken significant strides to implement innovative platforms to facilitate financial transactions and payment methods for goods and services. As electronic services become more sophisticated and prevalent, however, greater regulatory scrutiny needs to be paid to the industry in order to protect end-users and prevent damage to the country’s economy.

Background

Commercial banks are veterans in the e-Payment service market. They are governed by the Royal Decree Regulating Electronic Payment Services B.E. 2551 (2008); relevant Notifications of the Electronic Transaction Commission (ETC); and applicable Notifications of the Bank of Thailand (BOT), which also closely monitors their business activities.

Specialized Financial Institutions (SFIs), which were established by the government to provide financial services to various sectors that are not sufficiently served by commercial banks, are also engaged in the e-Payment service market. Thailand’s regulatory authorities determined that the laws and regulations surrounding SFIs and their engagement in e-Payment service businesses were insufficient, and further regulations were needed.

The Royal Decree on e-Payment Services

On March 30, 2016, the government promulgated the Royal Decree Governing the Control and Supervision of Electronic Payment Service Businesses of Specialized Financial Institutions B.E. 2559 (2016). It took effect on July 28.

As with commercial banks, the Royal Decree of 2016 designates the BOT to control and supervise the e-Payment service businesses of the following SFIs: Government Savings Bank, Bank for Agriculture and Agricultural Cooperatives, Government Housing Bank, Islamic Bank of Thailand, Export-Import Bank of Thailand, Small and Medium Enterprise Development Bank of Thailand, Thai Credit Guarantee Corporation, and Secondary Mortgage Corporation.

The Royal Decree aims to standardize supervisory provisions and measures enforced on both private and state service providers. This should help ensure financial and commercial stability, prevent damage caused to the public, and build trust and credibility in the e-Payment system among the public.

In terms of substantive provisions, the Royal Decree categorizes e-Payment service business into three lists, which resemble the categories for commercial banks in the Royal Decree Regulating Electronic Payment Services B.E. 2551 (2008), as follows:

  • List A: e-Money services used for purchasing specific goods or services as specified in advance from an entrepreneur, excluding e-Money services used only for customers’ convenience without the procurement of any profit from issuing the card, as prescribed by the BOT with the approval of the ETC. These services require notification before business operations commence.
  • List B: Credit card network services, electronic draft capture services, transaction switching services for payments in one system, and e-Money services used for purchasing specific goods or services as specified in advance at a place which uses the same system for distributing and providing these goods or services. These services require registration before business operations commence.
  • List C: Clearing services, settlement services, e-Payment services through any devices or networks, transaction switching services for payment through several systems, payment service provider services, and e-Money services used for purchasing specific goods or services as specified in advance in which the place where the services were used was not limited and the system for distributing or providing the services is not the same. These services require a license before business operations commence. The license lasts for ten years.

The Royal Decree also empowers the ETC to set methods and service conditions on: (1) custody and disclosure of customers’ personal information; (2) examining and maintaining system security for consistent reliability; (3) express prescribing of any service fees; (4) receiving and the process to ratify customers’ complaints or disputes; and (5) accounting and reporting, among others.

In addition, depending on the type of business, the BOT may prescribe additional rules on: (1) issuing evidence for payment; (2) keeping money which will be sent; (3) prescribing the finality of transferred money which may be unconditionally and promptly utilized by the beneficiary; and (4) arranging an independent auditor for security.

Any service providers in List A and List B that fail to comply with these rules will be subject to an administrative fine and/or an order of the ETC to take appropriate corrective action. Any service providers in List C that fail to comply with these rules can be subject to corrective measures, suspension, or license revocation.

Implementation

Even though the Royal Decree came into force on July 28, its transitional provisions allow SFIs which have operated an e-Payment service business prior to this date to continue their operation until November 24, 2016. The SFIs that want to continue their business need to notify, register, or apply for a license in accordance with this Royal Decree from August 26 to September 25, 2016.

If the Royal Decree is effectively enforced, and both the BOT and the ETC undertake their supervisory authority properly, information technology systems and electronic platforms will be much safer for customers who interact with these SFIs. Improved security and protection will lead to greater credibility with customers, and this will entice considerably more people to use e-Payment services.

RELATED INSIGHTS​ 

March 19, 2025
On January 1, 2025, the Department of Business Development (DBD) in Thailand’s Ministry of Commerce implemented new stringent corporate registration screening measures in collaboration with several other government agencies to prevent entities from opening corporate mule accounts to commit criminal activities in Thailand. The DBD’s Order of the Office of Central Company and Partnership Registration No. 3/2024 stipulates a new method for registering the establishment of partnerships and limited companies for people who have been involved in underlying crimes or who are owners of bank accounts that are being used for underlying crime, as per the notification of the Anti-Online Scam Operation Center (AOC) to the Anti-Money Laundering Office (AMLO) and the collated AMLO list of such persons. The order establishes the following key requirements: Managing partners and directors of partnerships and limited companies, respectively, whose names have been listed by the AMLO as a person who is involved in an underlying offense, or as the owner of a bank account being used for the underlying offense, must appear before the registrar in person. The concerned persons cited on the AMLO list must provide valid documentation of their identity to the DBD registrar (e.g., national identification card, government official identification card, government or state enterprise employee identification card, alien identification card, passport, document used in lieu of a travel document, or other similar documents with photo identification). This collaboration between the DBD and various relevant government agencies aims to eradicate the problem of fraudsters using mule accounts set up under legally established entities to deceive the public. It also seeks to enhance checks and screening of corporate mule accounts that are used to carry out criminal activities such as money laundering or cybercrime. These actions are part of the Thai government’s broader policy to suppress economic crimes. For more
March 14, 2025
The Bank of Thailand (BOT) has published the Draft Guidelines for Digital Fraud Management, which aim to help financial service providers tackle digital fraud and ensure safety and trust in the Thai financial system. These draft guidelines, which are available for public comment until March 18, 2025, provide a comprehensive framework for financial service providers, covering prevention, detection, management, and resolution of digital fraud, as well as support for customers affected by fraud. The BOT tentatively plans to implement these draft guidelines on April 1, 2025, along with circular letters on the minimum required measures for tackling “mule accounts” (deposit or e-money accounts used as tools to receive and transfer funds obtained through the commission of any offense) and measures to strengthen Thailand’s customer due diligence and enhanced due diligence procedures. Under the draft guidelines, “financial service providers” include financial institutions and special financial institutions under the Financial Institution Business Act and payment providers under the Payment Systems Act. Commercial banks, special financial institutions, and operators of transferable e-money services must adhere to every requirement in the draft guidelines. Other financial service providers (e.g., payment providers other than operators of transferable e-money services) can implement the draft guidelines as deemed appropriate to their services, products, and service channels. Digital Fraud Management Requirements The draft guidelines establish the following key requirements: Policy and oversight. Directors and senior executives of financial service providers must set and adopt appropriate “end-to-end” fraud management policies and KPIs to manage digital fraud, covering prevention, monitoring, detection, management, resolution, and support for affected customers. Fraud management processes. Financial service providers must establish a clear framework for managing digital fraud throughout the customer lifecycle, from customer onboarding to service termination, according to industry standards at a minimum and covering at least the following processes: Know your customer
February 24, 2025
On January 31, 2025, the Bank of Thailand (BOT) announced a new Notification re: Responsible Lending, replacing a similar notification from 2023. This new notification provides updated measures to assist debtors in different circumstances and clear implementation guidelines for lenders, with the aim of resolving household debt issues. Scope The service providers covered by the notification include banks and nonbanks (e.g., credit card companies, asset management companies, licensed personal loan providers, and nano finance operators) that conduct lending business. New Requirements The notification’s core focus remains loan management throughout the lifecycle of a loan—from credit product development to legal proceedings and debt transfers to other creditors—but with further clarification and detail compared to the 2023 notification. The key revisions in the new notification are summarized below. Advertising standards: The notification tightens requirements in some areas and relaxes them in others. Stricter requirements: It is now clearly stipulated that the BOT oversees taglines that may encourage excessive borrowing. More examples of noncompliant statements are also added (e.g., “Elevate your lifestyle now, pay later”; “Get approved, even with credit challenges”). In addition, advertising material that contains multiple credit products should provide clear minimum and maximum interest rates, especially when there are significant differences in the interest rates of each product. Relaxed requirements: The required information for some marketing activities is now reduced. For example, in marketing events with staff promoting loan products and offering free giveaways, service providers have the discretion to provide effective interest rate information in the manner they deem appropriate, and the advertisement material can display only the mandatory warning statements without providing interest rate details. Encouraging customer financial discipline: The notification requires service providers to implement more elaborate and extensive tools to influence customer behavior (termed “nudging” by the BOT) at every stage of the lending cycle. This
February 19, 2025
On January 3, 2025, the Bank of the Lao PDR (BOL) issued Decision No. 11/BOL on the Use of Foreign Currency in Lao PDR, taking effect on the same date. This decision sets out the rules for using foreign currency in Laos and ensures the Lao kip (LAK) remains the primary currency while allowing flexibility for international transactions. Key points in the decision are outlined below. Permissible Activities for Foreign Currency The decision provides that authorized entities can use foreign currency as a secondary currency to LAK in the setting of cost and pricing structures, announcing and advertising prices, and making or receiving payments for goods and services that are imported or have manufacturing inputs imported from other countries. Otherwise, LAK is the only permitted currency. The decision also stipulates that foreign exchange must be conducted only via authorized commercial banks or foreign exchange markets. The exchange rate for setting costs, pricing structures, announcing and advertising prices, and making and receiving payments for goods and services in foreign currency must match the exchange rate announced by commercial banks from time to time. Businesses Allowed to Use Foreign Currency The decision allows certain businesses and organizations to use foreign currency. These entities are divided into two groups: those that need approval before using foreign currency, and those that can use it immediately. Enterprises that can use foreign currency with BOL approval include: Businesses that export goods or services and entities that lease or obtain concessions from the government, generating revenue in foreign currency through commercial banks. Enterprises that provide international freight and passenger transportation services. Enterprises that provide services related to cross-border logistics and warehousing. Enterprises located at international borders and airports, such as duty-free shops and restaurants. Enterprises that have obligations to make payments in foreign currency to other