You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 21, 2023

New Regulations on Onshore Loans in Vietnam

On September 1, 2023, Circular No. 06/2023/TT-NHNN (“Circular 06”) issued by the State Bank of Vietnam on June 28, 2023, will take effect. This circular introduces noteworthy amendments to the regulations concerning the offering of onshore loans to customers by credit institutions (including commercial banks and foreign bank branches).

Introducing New Lending Restrictions but Loosening Refinancing Restrictions

Circular 06 introduces several new categories of loans that credit institutions are not allowed to provide. These include loans for depositing money in accounts; loans for making or acquiring capital contributions or shares in other companies which have not yet been listed on the securities market or registered for trading on the UPCoM system; and loans for paying capital contributions under capital contribution contracts, investment cooperation contracts, or business cooperation contracts for implementation of investment projects that fail to satisfy conditions for being put into business operation. [However, Circular No. 10/2023/TT-NHNN, issued shortly before Circular 06 was to take effect (see related story here), suspended the restrictions on the latter two categories until further notice.]

A new exception in Circular 06 allows credit institutions to offer loans for repaying foreign loans if the foreign loans were granted in the form of deferred payment for purchase of goods. Circular 06 also amends an exception of the previous regulations that new loans for repaying foreign loans or onshore loans from other credit institutions can be offered, as long as the term of the new loan does not exceed the remaining term of the original loan and the refinanced loan has not yet undergone any repayment rescheduling. This exception removes a requirement under the previous regulations that the original loan had to be made “for business purposes.”

Further, Circular 06 introduces the term “financial reimbursement” (“cho vay bù đắp tài chính” in Vietnamese) whereby credit institutions offer loans to customers to reimburse expenses advanced by the customer from its own capital, or capital borrowed from other individuals and non-bank entities, to implement plans or projects for business activities or living purposes.

Credit institutions are not allowed to offer financial reimbursement unless the borrowers can prove statutory conditions are satisfied. First, the borrowers must have used their own capital for paying costs incurred from their business project within the 12-month period before the date of the lending decision. Second, the costs to be reimbursed must be those that are listed in the usage plan approved by the credit institution for the loan for that business project. [The application of these conditions has also been suspended under Circular No. 10/2023/TT-NHNN. For the time being, loans for financial reimbursement are permissible.]

Conditions for Digital Lending by Credit Institutions

Circular 06 provides key conditions for digital lending. To provide digital lending, credit institutions are required to have a level-3 or higher information system used for carrying out digital lending activities. (Information systems are classified in increasing strictness from level-1 to level-5 based on standards for the types of information processed and their respective security level.)

Credit institutions are free to adopt their own measures and technologies for carrying out digital lending, but must satisfy certain requirements such as:

  • Adopting solutions and technologies for ensuring accuracy, confidentiality, and safety during the collection, use, and verification of information;
  • Adopting measures for examining, checking, updating, and verifying information (“eKYC”), and measures for preventing acts of forging, interfering with, and falsifying information;
  • Developing measures for monitoring, identifying, measuring, and controlling risks, and developing risk treatment plans; and
  • Assigning responsibilities to each individual or department for performance of digital lending activities and risk management and control.

The requirement to develop and implement an efficient and secure process of verifying a customer’s identity makes the measures and technologies for eKYC the most essential to minimize the risk of identity fraud. Specifically, for individuals who apply for loans for living purposes and wish to obtain the loans from the credit institution via digital lending as the first transaction for establishing the relationship with such credit institution, the eKYC process must be conducted properly to check and verify that the individuals are the ones conducting the e-transaction and have consented to the loan agreement.

In addition, credit institutions must store and manage, in a full and detailed manner, customer identification information and biometric data of their customers; sounds, images, videos and recordings (as applicable to customer identification); telephone numbers used for conducting transactions; and transaction logs.

The outstanding balance of loans for living purposes for an individual customer who has been identified or duly verified via digital lending may not exceed VND 100,000,000 (approximately USD 4,200).

Other Changes

Circular 06 sets out other new regulations. In particular, credit institutions and their customers may agree on a currency for loan repayment that is different from the lending currency. For a loan having one or more overdue payments, Circular 06 also provides for a more detailed repayment order than the previous regulations.

After issuance of Circular 06 by the State Bank of Vietnam, the Prime Minister requested a working session between Deputy Prime Minister Le Minh Khai and the Governor of the State Bank of Vietnam to study and amend certain unreasonable points in Circular 06 that would too heavily restrict loans to borrowers. There may be further loosening of the requirements in the near future.

[UPDATE: This meeting resulted in the issuance of a new circular on August 23, 2023, which suspended some of the restrictions found in Circular 06, as noted above.]

RELATED INSIGHTS​ 

December 26, 2025
The Bank of Thailand (BOT) has released the Guidelines for Digital Fraud Management, which took effect on December 17, 2025, incorporating certain amendments to the draft guidelines issued in March 2025. These official guidelines aim for end-to-end digital fraud prevention, with a particular focus on mule accounts, to enhance trust and security in Thailand’s financial system. The guidelines apply to “financial service providers,” including: Financial institutions and special financial institutions under the Financial Institution Business Act; and Operators of Inter-institutional Fund Transfer System e-money services and e-fund transfer services under the Payment Systems Act. Besides commercial banks and e-money operators that offer fund-transfer services, other providers may adopt requirements based on risk proportionality and baseline standards set out in the guidelines (for instance, an e-money operator that does not offer e-fund transfer services could consider implementing a fraud monitoring and detection system according to the risk level of its service). The guidelines establish the following key requirements: Policy and oversight. Directors and senior executives of financial service providers must adopt appropriate “end-to-end” fraud management policies and KPIs to manage digital fraud, covering prevention, monitoring, detection, management, resolution, and support for affected customers. The fraud management policy must be regularly reviewed, and whenever there is a situation or change that significantly affects the efficiency of the fraud management. Any significant update to the policy must first be approved by the board of the financial service provider. The BOT also encourages providers to collaborate in establishing industry standards aligned with applicable laws and regulations to ensure consistency and best practices across the sector. Fraud management processes. Financial service providers must establish a clear framework for managing digital fraud throughout the customer lifecycle—from customer onboarding to service termination—covering at least the following processes: Know your customer (KYC) and customer due diligence (CDD):
November 24, 2025
A recent warning from the Central Bank of Myanmar (CBM) against cryptocurrency use upholds the country’s ongoing strategy of enforcing strict prohibitions on unauthorized cryptocurrency activities while also promoting the controlled development of a central bank digital currency (CBDC). The CBM’s warning, issued November 16, 2025, reminded the public of announcements in May 2019 and a notification in May 2020 confirming that all online and offline cryptocurrency transactions are strictly prohibited. The CBM also clarified that no financial institution in Myanmar is authorized to deal with digital currencies. The warning highlighted global risks, such as money laundering, scams, tax evasion, hacking, and severe financial losses caused by price volatility and insufficient regulation. The CBM urged the public to use only legitimate banking channels and avoid illegal cryptocurrency activities. The warning comes five months after the CBM issued a notification announcing the formation of the Central Committee for the Issuance of a Central Bank Digital Currency. This committee includes senior CBM officials, representatives from relevant ministries and the banking sector, and technology experts. Its main role is to research CBDC models, test secure digital payment systems, and ensure that any future implementation aligns with Myanmar’s monetary policy and financial stability objectives. Taken together, these two actions illustrate the CBM’s continued pursuit of its dual strategy to promote innovation through CBDC development while prohibiting cryptocurrency use. Businesses should note that while CBDC pilot programs may appear in the future, cryptocurrencies remain off-limits.
September 24, 2025
On September 12, 2025, the Bank of Thailand (BOT) officially released its AI Risk Management Guidelines for Financial Service Providers, building upon the draft guidelines issued in June 2025. The guidelines reflect a balanced approach, encouraging innovation while safeguarding financial stability and consumer protection. The guidelines are targeted at all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. The guidelines apply to both AI systems developed in-house and those developed by third parties that are adopted for use by financial service providers. AI Risk Management Guidelines The two main pillars in managing AI risk are (1) governance of AI system implementation and (2) AI system development and security controls, consisting of the following key elements: 1. Governance Stakeholder roles and responsibilities. Boards and senior management assume accountability for decisions and operations involving AI systems, and are responsible for defining roles and responsibilities for AI oversight. This includes establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. Organizations are expected to foster internal capabilities to use AI securely and avoid overreliance that could compromise business continuity or customer service. AI system usage policy. Policies governing AI usage should align with organizational goals, regulatory obligations, and recognized responsible AI frameworks—such as the FEAT principles (fairness, ethics, accountability, and transparency). These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. Financial service providers should assess risks and impacts of AI usage on operations and customer services.
September 12, 2025
On September 10, 2025, Vietnam’s National Credit Information Center (CIC) reported to the Vietnam Cybersecurity Emergency Response Team (VNCERT) a suspected significant cybersecurity incident involving unauthorized access to the CIC’s credit information database. A hacker group has claimed responsibility and allegedly posted over 160 million records for sale, including sensitive personal and financial data. Implications for Banks and Financial Institutions Companies that share customers’ or potential customers’ personal data with the CIC for credit scoring or other purposes—and continue to act as a data controller for such data—may be obligated under Vietnam’s Personal Data Protection Decree (PDPD) and related regulations to: Notify A05 (Department of Cybersecurity and High-Tech Crime Prevention) and the State Bank of Vietnam without delay. Inform affected individuals if their personal data is at risk. Recommended Actions Companies that could be impacted by this data breach should take the following actions: Conduct an internal review of CIC-related data in their systems, and identify whether and how the systems have been affected by this incident. Assess whether to notify regulators and customers/potential customers. Enhance cybersecurity controls, monitor for suspicious activity, and implement additional safeguards to prevent secondary breaches.