You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 2, 2020

Regulations for Foreign Banks in Cambodia, Laos, Myanmar, and Vietnam

Informed Counsel

The  rapidly growing middle class in Southeast Asia is bringing with it increased household wealth, increased consumption, and increased investment. With that increase, the commercial banking sector has seen a boom in the more economically developed countries of Southeast Asia—especially in Thailand. A select few foreign banks have been very successful in Cambodia, Laos, Myanmar, and Vietnam (CLMV) for many years, but as many banks seek to replicate their Thai success in these new markets, the field looks likely to become much more crowded in coming years. Six major Thai banks are active in at least one other jurisdiction in mainland Southeast Asia, with some already operating across them all, and many larger international banks also beginning to take note.

Amid that background, this article examines the legal frameworks for banks seeking to operate in those jurisdictions, and addresses some current and upcoming developments that investors should note.

Cambodia

Cambodia’s legal framework is very favorable for foreign investors seeking to invest in the country’s banking sector, as there are no restrictions on foreign ownership. Therefore, banks and other financial institutions can be 100% foreign owned.

Foreign investors/banks may structure their banking investments/expansion in Cambodia by way of a subsidiary, a branch, or a representative office. Subsidiaries and branches are both permitted to engage in banking activities in Cambodia, and, for a subsidiary, a foreign investor could incorporate a bank in Cambodia and own 100% of its shares, or acquire the shares of an existing bank. Representative offices, however, are only allowed to conduct market research and other activities that do not generate income or profit.

Cambodian law allows for the formation of commercial banks (which may be structured as either subsidiaries, locally incorporated banks, or branches), specialized banks, and microfinance institutions. Commercial banks are legal entities licensed to carry out banking operations, including (1) credit operations for valuable consideration, (2) the collection of non-earmarked deposits, and (3) the provision of means of payment to customers and the processing of payments in Khmer riel or foreign exchange. Specialized banks, on the other hand, are banks that only operate one of the above activities (typically lending, and without accepting deposits from the public). 

Microfinance institutions (MFIs) provide financial services, such as loans and deposits, to poor and low-income households and to micro-enterprises. In general, MFIs are not permitted to collect deposits unless they obtain a separate license from the National Bank of Cambodia (NBC).

All banks operating in Cambodia must comply with the minimum capital requirements below.

Establishing a bank and obtaining a banking license is a two-step application process at the NBC—first, an application for in-principle approval from the NBC, and then upon satisfying certain conditions, an application for final approval. Application review and approval takes approximately six months. If the NBC grants the banking license, this will be published in the NBC bulletin and the Official Gazette of the Kingdom of Cambodia. 

Laos

The main relevant legislation is the Law on Commercial Banks No.56/NA, as amended, dated December 7, 2018. This addresses a number of issues with regard to operation of commercial banks in Laos.

Minimum Registered Capital

The minimum registered capital for commercial banks does not differ for local or foreign commercial banks to set up a bank in Laos and is currently set at LAK 500 billion (approx. USD 58 million), while the minimum registered capital for foreign commercial banks seeking to establish only a branch is LAK 300 billion (approx. USD 34.5 million). In-kind value may account for up to 10% of the registered capital. Capital-in-kind can be immovable property or movable property in Laos used in the operation of the business of the commercial bank.

Internal Governance

A board of directors with at least five members must be created. The term is three years, and members can be re-elected for up to three consecutive terms. The board must include at least one external member—someone who is not an employee of the commercial bank and who has no family connections or contractual relationship with, or business benefits related to, a shareholder or executive of the commercial bank. This prohibition extends to other business interests unrelated to the bank. For example, an external member cannot be employed even on a temporary or ad hoc basis by a bank shareholder’s other company. Internal governance also relies on three required committees—(1) the Governance Committee, (2) the Risk Management Committee, and (3) the Audit Committee—with the option of creating additional committees if desired. Eventually, a directors’ council consisting of the director and the deputy director must also be set up. Appointment and dismissal of executives must receive consent from the Bank of Laos (BOL), which is responsible for supervising commercial banks.

Banking Activities

The law permits commercial banking activities, which generally encompass the typical services provided by a commercial bank—including the sale and purchase of foreign currency, as well as an allowance for the BOL to approve specific activities that are not listed in the law.

A commercial bank investing in another company that is not in securities businesses, insurance businesses, or financial businesses as further discussed below can invest only up to 10% of the registered capital of the commercial bank and cannot end up controlling more than 20% of the total shares having voting rights in the target legal entity. Commercial banks can either set up their own entity or hold shares in securities businesses, insurance businesses, financial leasing operations,  or other types of financial business upon the BOL’s approval.

Foreign Financing of Commercial Banks

On December 10, 2019, the BOL issued Notice No. 684/BOL prohibiting financial institutions from obtaining loans from foreign legal entities or individuals that are not financial institutions or are not approved by the relevant authority of the country of origin for providing loans.

Myanmar

The Central Bank of Myanmar (CBM), the financial authority for the banking industry in Myanmar, has implemented a step-by-step approach toward modernization and development of the banking industry in Myanmar. This has moved from permitting only local entrepreneurs to set up banks, to allowing foreign bank operators to open bank representative offices, and then to allowing foreign bank branches to provide onshore wholesale banking services. Finally, on November 7, 2019, the CBM announced a new round of foreign bank licensing that will involve the opening of the retail banking market to foreign banks at the beginning of 2021.   

The CBM is currently requesting expressions of interest for a new licensing round. This round of foreign bank licensing will be open to foreign banks with representative offices in Myanmar, and will make two license types available: branch licenses and subsidiary licenses.

With a branch license, foreign banks will be able to engage in onshore wholesale banking business, as was already permitted for foreign bank branches in Myanmar. These branches require a minimum paid-in capital of USD 75 million for operation, of which USD 40 million must be locked-up for two years with the CBM. Apart from onshore wholesale banking, foreign bank branches are permitted, under Directive 9/2017 of the CBM, to provide export financing and related banking services for export financing to local companies. 

However, with a subsidiary license, from January 1, 2021, foreign banks will be permitted, with a minimum paid-in capital of USD 100 million, to conduct onshore retail banking activities. This will permit the establishment of up to 10 places of business or off-site ATMs—a huge development and major liberalizing step in the Myanmar banking sector.

Existing foreign bank branches will be permitted to convert to subsidiaries from June 2020, provided they have operated as a branch in Myanmar for at least three years.

A more recent change—with effect as from January 1, 2020—is that foreign ownership in a Myanmar bank exceeding 35% of the capital of the domestic bank is now permitted with the approval of the CBM on a case-by-case basis. Equity investment exceeding the 35% cap by foreign banks or financial institutions was previously outlawed by the CBM (under Circular 1/2019). However, the Myanmar Companies Law 2017 states that a local Myanmar company can only accept foreign equity investment of up to 35% without changing the status of the company to be “foreign owned.” Though there has not yet been clarification, it seems likely that, to be consistent with the Myanmar Companies Law, local banks would have to change their status to be foreign banks after accepting foreign investment of more than 35% of the bank’s capital (as calculated after the capital injection).

Vietnam

Vietnam is fairly open in terms of market access in the banking sector. Foreign investors may set up a commercial presence or purchase shares of an existing financial institution in Vietnam. A new commercial presence may be (1) a representative office, (2) a branch of a foreign bank, (3) a wholly foreign-owned commercial bank, (4) a finance company, (5) a financial leasing company, or (5) a microfinance institution.

While both foreign banks and other financial institutions may establish representative offices to carry out activities that do not generate income or profit, only foreign banks are permitted to set up branches to engage in banking activities such as lending, taking deposits, and account opening. Neither representative offices nor branches of foreign banks are considered legal entities, so foreign investors must take full responsibility for the activities of their representative offices or branches.

In theory, foreign investors may establish a wholly foreign-owned commercial bank under Vietnamese law. As of June 30, 2019, the State Bank of Vietnam (SBV) had licensed nine wholly foreign-owned banks. However, the issuing of new licenses for such banks will likely be limited or possibly even discontinued in the future. Thus, foreign banks may find it easier to set up a branch or a representative office.

As for purchasing shares of existing local banks, a foreign investor together with its affiliates must not exceed 20% ownership of the charter capital of a local commercial bank, and the aggregate ownership of all foreign investors in a local commercial bank is capped at 30% of its charter capital. The scope of operation of commercial banks in Vietnam includes a wide range of products and services, from traditional financial products to fund management and securities business.
In contrast, foreign investors may own 100% of the shares of a finance or financial leasing company in Vietnam. The company may engage in certain banking activities but cannot take deposits from individuals or provide payment services via clients’ accounts.

Microfinance institutions mainly provide services such as taking deposits from low-income individuals and households and micro-enterprises. As of June 30, 2019, there were only four licensed local microfinance institutions in Vietnam.

In order to set up a commercial presence in Vietnam, foreign investors must satisfy, among other conditions, the minimum legal capital requirement as follows:

To engage in banking activities, a foreign credit institution (e.g., banks, branches, and finance/financial leasing companies) must obtain an establishment and operation license upon satisfying conditions on legal capital and so on. The statutory timeline for issuing a banking license is approximately seven months, but in practice it often takes much longer. If the SBV grants the banking license, this will be published on the official website of the SBV and in three consecutive issues of a local daily newspaper (including online news).

Conclusion

The countries of mainland Southeast Asia offer good opportunities to foreign banks and investors looking to gain or strengthen their presence in the region. Banks currently in different stages of expansion in these countries—as well as those ready to embark on expansion in the region—should consider the various issues related to setting up, licensing, capital and operational requirements, permitted and restricted activities, and so on, as detailed in this article, to determine the relative ease of market entry and operation versus the potential risks and rewards of doing so. With careful planning and foresight each of these markets offers attractive opportunities for banking sector operators looking to expand.

RELATED INSIGHTS​ 

December 26, 2025
The Bank of Thailand (BOT) has released the Guidelines for Digital Fraud Management, which took effect on December 17, 2025, incorporating certain amendments to the draft guidelines issued in March 2025. These official guidelines aim for end-to-end digital fraud prevention, with a particular focus on mule accounts, to enhance trust and security in Thailand’s financial system. The guidelines apply to “financial service providers,” including: Financial institutions and special financial institutions under the Financial Institution Business Act; and Operators of Inter-institutional Fund Transfer System e-money services and e-fund transfer services under the Payment Systems Act. Besides commercial banks and e-money operators that offer fund-transfer services, other providers may adopt requirements based on risk proportionality and baseline standards set out in the guidelines (for instance, an e-money operator that does not offer e-fund transfer services could consider implementing a fraud monitoring and detection system according to the risk level of its service). The guidelines establish the following key requirements: Policy and oversight. Directors and senior executives of financial service providers must adopt appropriate “end-to-end” fraud management policies and KPIs to manage digital fraud, covering prevention, monitoring, detection, management, resolution, and support for affected customers. The fraud management policy must be regularly reviewed, and whenever there is a situation or change that significantly affects the efficiency of the fraud management. Any significant update to the policy must first be approved by the board of the financial service provider. The BOT also encourages providers to collaborate in establishing industry standards aligned with applicable laws and regulations to ensure consistency and best practices across the sector. Fraud management processes. Financial service providers must establish a clear framework for managing digital fraud throughout the customer lifecycle—from customer onboarding to service termination—covering at least the following processes: Know your customer (KYC) and customer due diligence (CDD):
November 24, 2025
A recent warning from the Central Bank of Myanmar (CBM) against cryptocurrency use upholds the country’s ongoing strategy of enforcing strict prohibitions on unauthorized cryptocurrency activities while also promoting the controlled development of a central bank digital currency (CBDC). The CBM’s warning, issued November 16, 2025, reminded the public of announcements in May 2019 and a notification in May 2020 confirming that all online and offline cryptocurrency transactions are strictly prohibited. The CBM also clarified that no financial institution in Myanmar is authorized to deal with digital currencies. The warning highlighted global risks, such as money laundering, scams, tax evasion, hacking, and severe financial losses caused by price volatility and insufficient regulation. The CBM urged the public to use only legitimate banking channels and avoid illegal cryptocurrency activities. The warning comes five months after the CBM issued a notification announcing the formation of the Central Committee for the Issuance of a Central Bank Digital Currency. This committee includes senior CBM officials, representatives from relevant ministries and the banking sector, and technology experts. Its main role is to research CBDC models, test secure digital payment systems, and ensure that any future implementation aligns with Myanmar’s monetary policy and financial stability objectives. Taken together, these two actions illustrate the CBM’s continued pursuit of its dual strategy to promote innovation through CBDC development while prohibiting cryptocurrency use. Businesses should note that while CBDC pilot programs may appear in the future, cryptocurrencies remain off-limits.
September 24, 2025
On September 12, 2025, the Bank of Thailand (BOT) officially released its AI Risk Management Guidelines for Financial Service Providers, building upon the draft guidelines issued in June 2025. The guidelines reflect a balanced approach, encouraging innovation while safeguarding financial stability and consumer protection. The guidelines are targeted at all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. The guidelines apply to both AI systems developed in-house and those developed by third parties that are adopted for use by financial service providers. AI Risk Management Guidelines The two main pillars in managing AI risk are (1) governance of AI system implementation and (2) AI system development and security controls, consisting of the following key elements: 1. Governance Stakeholder roles and responsibilities. Boards and senior management assume accountability for decisions and operations involving AI systems, and are responsible for defining roles and responsibilities for AI oversight. This includes establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. Organizations are expected to foster internal capabilities to use AI securely and avoid overreliance that could compromise business continuity or customer service. AI system usage policy. Policies governing AI usage should align with organizational goals, regulatory obligations, and recognized responsible AI frameworks—such as the FEAT principles (fairness, ethics, accountability, and transparency). These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. Financial service providers should assess risks and impacts of AI usage on operations and customer services.
September 12, 2025
On September 10, 2025, Vietnam’s National Credit Information Center (CIC) reported to the Vietnam Cybersecurity Emergency Response Team (VNCERT) a suspected significant cybersecurity incident involving unauthorized access to the CIC’s credit information database. A hacker group has claimed responsibility and allegedly posted over 160 million records for sale, including sensitive personal and financial data. Implications for Banks and Financial Institutions Companies that share customers’ or potential customers’ personal data with the CIC for credit scoring or other purposes—and continue to act as a data controller for such data—may be obligated under Vietnam’s Personal Data Protection Decree (PDPD) and related regulations to: Notify A05 (Department of Cybersecurity and High-Tech Crime Prevention) and the State Bank of Vietnam without delay. Inform affected individuals if their personal data is at risk. Recommended Actions Companies that could be impacted by this data breach should take the following actions: Conduct an internal review of CIC-related data in their systems, and identify whether and how the systems have been affected by this incident. Assess whether to notify regulators and customers/potential customers. Enhance cybersecurity controls, monitor for suspicious activity, and implement additional safeguards to prevent secondary breaches.