You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 26, 2016

New e-Payment Service Regulations for SFIs: A Boon for Customer Confidence?

Informed Counsel

In today’s digital economy, financial technology (FinTech) is a major economic driving force. FinTech has transformed the private sector, resulting in a drastic shift in the way customers use financial services. Financial institutions, in particular, have taken significant strides to implement innovative platforms to facilitate financial transactions and payment methods for goods and services. As electronic services become more sophisticated and prevalent, however, greater regulatory scrutiny needs to be paid to the industry in order to protect end-users and prevent damage to the country’s economy.

Background

Commercial banks are veterans in the e-Payment service market. They are governed by the Royal Decree Regulating Electronic Payment Services B.E. 2551 (2008); relevant Notifications of the Electronic Transaction Commission (ETC); and applicable Notifications of the Bank of Thailand (BOT), which also closely monitors their business activities.

Specialized Financial Institutions (SFIs), which were established by the government to provide financial services to various sectors that are not sufficiently served by commercial banks, are also engaged in the e-Payment service market. Thailand’s regulatory authorities determined that the laws and regulations surrounding SFIs and their engagement in e-Payment service businesses were insufficient, and further regulations were needed.

The Royal Decree on e-Payment Services

On March 30, 2016, the government promulgated the Royal Decree Governing the Control and Supervision of Electronic Payment Service Businesses of Specialized Financial Institutions B.E. 2559 (2016). It took effect on July 28.

As with commercial banks, the Royal Decree of 2016 designates the BOT to control and supervise the e-Payment service businesses of the following SFIs: Government Savings Bank, Bank for Agriculture and Agricultural Cooperatives, Government Housing Bank, Islamic Bank of Thailand, Export-Import Bank of Thailand, Small and Medium Enterprise Development Bank of Thailand, Thai Credit Guarantee Corporation, and Secondary Mortgage Corporation.

The Royal Decree aims to standardize supervisory provisions and measures enforced on both private and state service providers. This should help ensure financial and commercial stability, prevent damage caused to the public, and build trust and credibility in the e-Payment system among the public.

In terms of substantive provisions, the Royal Decree categorizes e-Payment service business into three lists, which resemble the categories for commercial banks in the Royal Decree Regulating Electronic Payment Services B.E. 2551 (2008), as follows:

  • List A: e-Money services used for purchasing specific goods or services as specified in advance from an entrepreneur, excluding e-Money services used only for customers’ convenience without the procurement of any profit from issuing the card, as prescribed by the BOT with the approval of the ETC. These services require notification before business operations commence.
  • List B: Credit card network services, electronic draft capture services, transaction switching services for payments in one system, and e-Money services used for purchasing specific goods or services as specified in advance at a place which uses the same system for distributing and providing these goods or services. These services require registration before business operations commence.
  • List C: Clearing services, settlement services, e-Payment services through any devices or networks, transaction switching services for payment through several systems, payment service provider services, and e-Money services used for purchasing specific goods or services as specified in advance in which the place where the services were used was not limited and the system for distributing or providing the services is not the same. These services require a license before business operations commence. The license lasts for ten years.

The Royal Decree also empowers the ETC to set methods and service conditions on: (1) custody and disclosure of customers’ personal information; (2) examining and maintaining system security for consistent reliability; (3) express prescribing of any service fees; (4) receiving and the process to ratify customers’ complaints or disputes; and (5) accounting and reporting, among others.

In addition, depending on the type of business, the BOT may prescribe additional rules on: (1) issuing evidence for payment; (2) keeping money which will be sent; (3) prescribing the finality of transferred money which may be unconditionally and promptly utilized by the beneficiary; and (4) arranging an independent auditor for security.

Any service providers in List A and List B that fail to comply with these rules will be subject to an administrative fine and/or an order of the ETC to take appropriate corrective action. Any service providers in List C that fail to comply with these rules can be subject to corrective measures, suspension, or license revocation.

Implementation

Even though the Royal Decree came into force on July 28, its transitional provisions allow SFIs which have operated an e-Payment service business prior to this date to continue their operation until November 24, 2016. The SFIs that want to continue their business need to notify, register, or apply for a license in accordance with this Royal Decree from August 26 to September 25, 2016.

If the Royal Decree is effectively enforced, and both the BOT and the ETC undertake their supervisory authority properly, information technology systems and electronic platforms will be much safer for customers who interact with these SFIs. Improved security and protection will lead to greater credibility with customers, and this will entice considerably more people to use e-Payment services.

RELATED INSIGHTS​ 

February 17, 2025
Thailand’s draft Emergency Decree on Technology Crimes Suppression, which we covered in a client alert in January 2025 primarily addressed to telecom operators and financial institutions, is expected to have significant implications for a wide range of business operators.  The draft emergency decree has already been approved by the cabinet but may undergo further developments as it continues in the legislative process. In this article, we will highlight the material impacts of the draft emergency decree on overseas and local fintech operators. Expanded Definition of “Technology Crimes” The definition of “technology crimes” now includes the following acts of forgery or alteration: Forging or altering the identity of individuals and biometric characteristics by utilizing computer or communication systems or other electronic means to commit offenses. Forging or altering symbols, trademarks, or seals of groups (e.g., foundations, community enterprises) or juristic persons, including acts by juristic persons using individuals or juristic persons as nominal directors or shareholders, regardless of whether such individuals or legal juristic persons reside in Thailand. Forging or altering digital or online platforms, regardless of the platform’s location or legal status. Individuals who conspire, utilize, assist, or support the commission of these offenses will face the same penalties as the principal offender. Business Operator Definition The scope of “business operators” is now expanded to cover various fintech and digital asset operators beyond those under the Payment Systems Act (PSA). The draft emergency decree now includes the following operators, whether they are legally authorized or not: Business operators under the PSA and business operators who operate “as if” they are payment system operators Business operators under the Royal Decree on Digital Asset Businesses or business operators who operate “as if” they are digital asset business operators. Foreign exchange business operators. Disclosure and Exchange of Information Business operators must disclose
January 30, 2025
The Thai cabinet has approved a draft amendment of the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes as proposed by the Ministry of Digital Economy and Society to strengthen measures against technological crimes, particularly targeting call center scams and cyber fraud. Following the Council of State’s review, the emergency decree will be become effective immediately upon its enactment and publication in the Government Gazette. While the draft amendment is not yet publicly available, the government recently indicated that the emergency decree aims to empower authorities with decisive measures to combat cybercrime effectively. It underscores the shared responsibility among various sectors, including banking, telecommunications, and online platforms, in safeguarding against technological crimes. Key provisions of the draft amendment of the emergency decree include: Telecommunications provider obligations: Telecommunications service providers must suspend SIM cards associated with criminal activities. The National Broadcasting and Telecommunications Commission and mobile service providers themselves are authorized to temporarily suspend mobile phone numbers if there is reasonable suspicion of involvement in criminal activities. Banking responsibilities: Financial institutions are required to promptly report mule accounts to the Anti-Money Laundering Office to facilitate quick restitution to victims. The Anti-Money Laundering Transaction Committee is empowered to order the return of funds to victims without requiring a final court ruling. Penalties for noncompliance: The amended emergency decree introduces penalties for noncompliance by regulated entities that fail to prevent criminal activities for offenses related to technology crimes in the following cases: Digital asset services: Those engaged in the buying, selling, or exchanging of digital assets, such as cryptocurrencies and digital tokens, as well as digital asset businesses that launder money obtained from online crimes by converting it into digital currency, will be subject to imprisonment for up to one year, a fine of up to THB 100,000,
January 22, 2025
Tasked with implementing the Politburo’s policy outlined in Notice No. 47-TB/TW dated November 15, 2024, the prime minister of Vietnam issued Decision No. 1718/QD-TTg on December 31, 2024, appointing himself as the head of a steering committee dedicated to the establishment of an international financial center in Ho Chi Minh City and a regional financial center in Da Nang by 2025. The Ministry of Planning and Investment has subsequently drafted an outline for the National Assembly’s Resolution on the Establishment of Regional and International Financial Centers in Vietnam (“Draft Resolution”). This Draft Resolution introduces two key policy groups: (i) policies governing the quantity, location, structure, organization, functions, and responsibilities of the financial centers; and (ii) policies applicable to various areas and matters within the financial centers. Notably, under the Draft Resolution, fintech has been identified as a key sector, with a specific focus on the implementation of a “controlled sandbox” policy for business models involving virtual assets and cryptocurrencies. Under this framework, transactions related to virtual assets and cryptocurrencies will be permitted from July 1, 2026, subject to licensing, management, impact assessment, and risk oversight by the financial centers’ Management and Operations Committee. Scope of Application and Key Principles The Draft Resolution applies to a wide range of stakeholders, including investors, regulatory agencies, organizations, and individuals involved in the establishment, organization, and operation of regional and international financial centers in Vietnam. These financial centers will have clearly defined geographical boundaries and specific locations, which will be further specified and detailed by the People’s Committees of Ho Chi Minh City and Da Nang. Companies successfully registered as members of these financial centers will benefit from special investor-friendly policy principles, which may differ from the general legal and regulatory framework applicable in other parts of Vietnam. Most notably, the state will
January 13, 2025
The State Bank of Vietnam’s Circular No. 50/2024/TT-NHNN regulating safety and security for the provision of online services in the banking sector (“Circular 50”), issued on October 31, 2024, took effect on January 1, 2025, with delayed effectiveness for certain provisions on (i) network, communication, and security systems, online banking application software, and mobile banking application software (July 1, 2025); (ii) transaction confirmation for payment transactions conducted via the straight-through processing method (January 1, 2026); and (iii) authentication forms and reporting obligations (July 1, 2026). The cybersecurity situation in Vietnam is complicated, and the banking and finance sector has been one of the top targets of high-tech criminals. Circular 50 seeks to enhance user protection by expanding the technical requirements to more services in the banking sector as well as standardizing how transactions are authenticated. Expanded Scope of Services Covered Previous regulations on safety and security of online services in the banking sector only covered banking services and intermediary payment services. Circular 50 expands the scope to include other services of credit institutions and foreign bank branches such as credit information services, foreign exchange services, securities depository services, and services related to factoring and letters of credit, which now need to comply with technical requirements and standards for online services such as firewalls and DMZ network barriers. Risk-Based Approach to Authentication Circular 50 sets out standards for payment transactions and card transactions by: Classifying various online transactions based on the type of client, the purpose of the transfer, the value of the specific transaction, and the total value of certain transactions during the day; and Applying various types of authentication for the corresponding types of online transactions, e.g., using passwords or PINs for small-value online transactions, and using OTPs (through SMS, voice, or email), biometric matching, or e-signatures for