You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 21, 2023

New Regulations on Onshore Loans in Vietnam

On September 1, 2023, Circular No. 06/2023/TT-NHNN (“Circular 06”) issued by the State Bank of Vietnam on June 28, 2023, will take effect. This circular introduces noteworthy amendments to the regulations concerning the offering of onshore loans to customers by credit institutions (including commercial banks and foreign bank branches).

Introducing New Lending Restrictions but Loosening Refinancing Restrictions

Circular 06 introduces several new categories of loans that credit institutions are not allowed to provide. These include loans for depositing money in accounts; loans for making or acquiring capital contributions or shares in other companies which have not yet been listed on the securities market or registered for trading on the UPCoM system; and loans for paying capital contributions under capital contribution contracts, investment cooperation contracts, or business cooperation contracts for implementation of investment projects that fail to satisfy conditions for being put into business operation. [However, Circular No. 10/2023/TT-NHNN, issued shortly before Circular 06 was to take effect (see related story here), suspended the restrictions on the latter two categories until further notice.]

A new exception in Circular 06 allows credit institutions to offer loans for repaying foreign loans if the foreign loans were granted in the form of deferred payment for purchase of goods. Circular 06 also amends an exception of the previous regulations that new loans for repaying foreign loans or onshore loans from other credit institutions can be offered, as long as the term of the new loan does not exceed the remaining term of the original loan and the refinanced loan has not yet undergone any repayment rescheduling. This exception removes a requirement under the previous regulations that the original loan had to be made “for business purposes.”

Further, Circular 06 introduces the term “financial reimbursement” (“cho vay bù đắp tài chính” in Vietnamese) whereby credit institutions offer loans to customers to reimburse expenses advanced by the customer from its own capital, or capital borrowed from other individuals and non-bank entities, to implement plans or projects for business activities or living purposes.

Credit institutions are not allowed to offer financial reimbursement unless the borrowers can prove statutory conditions are satisfied. First, the borrowers must have used their own capital for paying costs incurred from their business project within the 12-month period before the date of the lending decision. Second, the costs to be reimbursed must be those that are listed in the usage plan approved by the credit institution for the loan for that business project. [The application of these conditions has also been suspended under Circular No. 10/2023/TT-NHNN. For the time being, loans for financial reimbursement are permissible.]

Conditions for Digital Lending by Credit Institutions

Circular 06 provides key conditions for digital lending. To provide digital lending, credit institutions are required to have a level-3 or higher information system used for carrying out digital lending activities. (Information systems are classified in increasing strictness from level-1 to level-5 based on standards for the types of information processed and their respective security level.)

Credit institutions are free to adopt their own measures and technologies for carrying out digital lending, but must satisfy certain requirements such as:

  • Adopting solutions and technologies for ensuring accuracy, confidentiality, and safety during the collection, use, and verification of information;
  • Adopting measures for examining, checking, updating, and verifying information (“eKYC”), and measures for preventing acts of forging, interfering with, and falsifying information;
  • Developing measures for monitoring, identifying, measuring, and controlling risks, and developing risk treatment plans; and
  • Assigning responsibilities to each individual or department for performance of digital lending activities and risk management and control.

The requirement to develop and implement an efficient and secure process of verifying a customer’s identity makes the measures and technologies for eKYC the most essential to minimize the risk of identity fraud. Specifically, for individuals who apply for loans for living purposes and wish to obtain the loans from the credit institution via digital lending as the first transaction for establishing the relationship with such credit institution, the eKYC process must be conducted properly to check and verify that the individuals are the ones conducting the e-transaction and have consented to the loan agreement.

In addition, credit institutions must store and manage, in a full and detailed manner, customer identification information and biometric data of their customers; sounds, images, videos and recordings (as applicable to customer identification); telephone numbers used for conducting transactions; and transaction logs.

The outstanding balance of loans for living purposes for an individual customer who has been identified or duly verified via digital lending may not exceed VND 100,000,000 (approximately USD 4,200).

Other Changes

Circular 06 sets out other new regulations. In particular, credit institutions and their customers may agree on a currency for loan repayment that is different from the lending currency. For a loan having one or more overdue payments, Circular 06 also provides for a more detailed repayment order than the previous regulations.

After issuance of Circular 06 by the State Bank of Vietnam, the Prime Minister requested a working session between Deputy Prime Minister Le Minh Khai and the Governor of the State Bank of Vietnam to study and amend certain unreasonable points in Circular 06 that would too heavily restrict loans to borrowers. There may be further loosening of the requirements in the near future.

[UPDATE: This meeting resulted in the issuance of a new circular on August 23, 2023, which suspended some of the restrictions found in Circular 06, as noted above.]

RELATED INSIGHTS​ 

February 17, 2025
Thailand’s draft Emergency Decree on Technology Crimes Suppression, which we covered in a client alert in January 2025 primarily addressed to telecom operators and financial institutions, is expected to have significant implications for a wide range of business operators.  The draft emergency decree has already been approved by the cabinet but may undergo further developments as it continues in the legislative process. In this article, we will highlight the material impacts of the draft emergency decree on overseas and local fintech operators. Expanded Definition of “Technology Crimes” The definition of “technology crimes” now includes the following acts of forgery or alteration: Forging or altering the identity of individuals and biometric characteristics by utilizing computer or communication systems or other electronic means to commit offenses. Forging or altering symbols, trademarks, or seals of groups (e.g., foundations, community enterprises) or juristic persons, including acts by juristic persons using individuals or juristic persons as nominal directors or shareholders, regardless of whether such individuals or legal juristic persons reside in Thailand. Forging or altering digital or online platforms, regardless of the platform’s location or legal status. Individuals who conspire, utilize, assist, or support the commission of these offenses will face the same penalties as the principal offender. Business Operator Definition The scope of “business operators” is now expanded to cover various fintech and digital asset operators beyond those under the Payment Systems Act (PSA). The draft emergency decree now includes the following operators, whether they are legally authorized or not: Business operators under the PSA and business operators who operate “as if” they are payment system operators Business operators under the Royal Decree on Digital Asset Businesses or business operators who operate “as if” they are digital asset business operators. Foreign exchange business operators. Disclosure and Exchange of Information Business operators must disclose
January 30, 2025
The Thai cabinet has approved a draft amendment of the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes as proposed by the Ministry of Digital Economy and Society to strengthen measures against technological crimes, particularly targeting call center scams and cyber fraud. Following the Council of State’s review, the emergency decree will be become effective immediately upon its enactment and publication in the Government Gazette. While the draft amendment is not yet publicly available, the government recently indicated that the emergency decree aims to empower authorities with decisive measures to combat cybercrime effectively. It underscores the shared responsibility among various sectors, including banking, telecommunications, and online platforms, in safeguarding against technological crimes. Key provisions of the draft amendment of the emergency decree include: Telecommunications provider obligations: Telecommunications service providers must suspend SIM cards associated with criminal activities. The National Broadcasting and Telecommunications Commission and mobile service providers themselves are authorized to temporarily suspend mobile phone numbers if there is reasonable suspicion of involvement in criminal activities. Banking responsibilities: Financial institutions are required to promptly report mule accounts to the Anti-Money Laundering Office to facilitate quick restitution to victims. The Anti-Money Laundering Transaction Committee is empowered to order the return of funds to victims without requiring a final court ruling. Penalties for noncompliance: The amended emergency decree introduces penalties for noncompliance by regulated entities that fail to prevent criminal activities for offenses related to technology crimes in the following cases: Digital asset services: Those engaged in the buying, selling, or exchanging of digital assets, such as cryptocurrencies and digital tokens, as well as digital asset businesses that launder money obtained from online crimes by converting it into digital currency, will be subject to imprisonment for up to one year, a fine of up to THB 100,000,
January 22, 2025
Tasked with implementing the Politburo’s policy outlined in Notice No. 47-TB/TW dated November 15, 2024, the prime minister of Vietnam issued Decision No. 1718/QD-TTg on December 31, 2024, appointing himself as the head of a steering committee dedicated to the establishment of an international financial center in Ho Chi Minh City and a regional financial center in Da Nang by 2025. The Ministry of Planning and Investment has subsequently drafted an outline for the National Assembly’s Resolution on the Establishment of Regional and International Financial Centers in Vietnam (“Draft Resolution”). This Draft Resolution introduces two key policy groups: (i) policies governing the quantity, location, structure, organization, functions, and responsibilities of the financial centers; and (ii) policies applicable to various areas and matters within the financial centers. Notably, under the Draft Resolution, fintech has been identified as a key sector, with a specific focus on the implementation of a “controlled sandbox” policy for business models involving virtual assets and cryptocurrencies. Under this framework, transactions related to virtual assets and cryptocurrencies will be permitted from July 1, 2026, subject to licensing, management, impact assessment, and risk oversight by the financial centers’ Management and Operations Committee. Scope of Application and Key Principles The Draft Resolution applies to a wide range of stakeholders, including investors, regulatory agencies, organizations, and individuals involved in the establishment, organization, and operation of regional and international financial centers in Vietnam. These financial centers will have clearly defined geographical boundaries and specific locations, which will be further specified and detailed by the People’s Committees of Ho Chi Minh City and Da Nang. Companies successfully registered as members of these financial centers will benefit from special investor-friendly policy principles, which may differ from the general legal and regulatory framework applicable in other parts of Vietnam. Most notably, the state will
January 13, 2025
The State Bank of Vietnam’s Circular No. 50/2024/TT-NHNN regulating safety and security for the provision of online services in the banking sector (“Circular 50”), issued on October 31, 2024, took effect on January 1, 2025, with delayed effectiveness for certain provisions on (i) network, communication, and security systems, online banking application software, and mobile banking application software (July 1, 2025); (ii) transaction confirmation for payment transactions conducted via the straight-through processing method (January 1, 2026); and (iii) authentication forms and reporting obligations (July 1, 2026). The cybersecurity situation in Vietnam is complicated, and the banking and finance sector has been one of the top targets of high-tech criminals. Circular 50 seeks to enhance user protection by expanding the technical requirements to more services in the banking sector as well as standardizing how transactions are authenticated. Expanded Scope of Services Covered Previous regulations on safety and security of online services in the banking sector only covered banking services and intermediary payment services. Circular 50 expands the scope to include other services of credit institutions and foreign bank branches such as credit information services, foreign exchange services, securities depository services, and services related to factoring and letters of credit, which now need to comply with technical requirements and standards for online services such as firewalls and DMZ network barriers. Risk-Based Approach to Authentication Circular 50 sets out standards for payment transactions and card transactions by: Classifying various online transactions based on the type of client, the purpose of the transfer, the value of the specific transaction, and the total value of certain transactions during the day; and Applying various types of authentication for the corresponding types of online transactions, e.g., using passwords or PINs for small-value online transactions, and using OTPs (through SMS, voice, or email), biometric matching, or e-signatures for