You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

November 4, 2019

Securities and Banking Regulations in Thailand 2019 – Thomson Reuters Compliance Complete

Compliance Complete (Thomson Reuters Accelus)

Tilleke & Gibbins’ banking and finance specialists contributed the latest update on Thailand’s regulatory framework for the banking and securities sectors to Thomson Reuters Accelus Compliance Complete, a comprehensive guide to global risk and compliance information. The following topics are covered in detail:

  • The Bank of Thailand
  • Forms of financial institutions
  • Thailand’s Financial Sector Master Plan – Phases I, II, and III
  • Foreign Exchange Regulations
  • Banking Secrecy: Penalties for unlawful disclosure and exceptions
  • Outsourcing: Restrictions and conditions
  • Financial technology
  • Anti-money laundering
  • The Securities and Exchange Commission and rules for various securities-related activities and transactions
  • Investment by Foreigners in the Stock Exchange of Thailand

The PDF of the Thailand section is available below. It was originally published by Compliance Complete (Thomas Reuters Accelus).

RELATED INSIGHTS​ 

August 20, 2026
As part of its membership in Lex Mundi, Tilleke & Gibbins has released the latest edition of its Guide to Doing Business in Thailand, providing an overview of the legal, regulatory, and commercial considerations for companies establishing or expanding operations in Thailand. The 2026 edition offers practical insight into the country’s business environment, investment framework, and operational requirements. The guide covers a wide range of topics relevant to foreign and domestic investors, including: Investment incentives and promotion schemes Financial facilities and banking regulations Exchange controls and money transfers Import and export regulations Business structures and incorporation options Requirements for establishing a business Operational and compliance considerations Business cessation and insolvency procedures Employment and labor laws Taxation Immigration and visa requirements Prepared by Tilleke & Gibbins lawyers across multiple practice areas, the publication outlines key aspects of doing business in Thailand, including foreign investment restrictions, regulatory compliance obligations, corporate structures, employment requirements, and recent legal and economic developments affecting investors. The publication forms part of Lex Mundi’s Country Guides series, a global collection of jurisdiction-specific reference materials prepared by member firms around the world. Together, these guides help companies evaluate opportunities, compare regulatory environments, and plan international business activities across multiple markets. The full Guide to Doing Business in Thailand 2026 is available through the button below.
August 18, 2026
The Bank of Thailand (BOT) is seeking public comment on proposed amendments that would significantly expand know-your-customer (KYC) and customer due diligence (CDD) requirements for cash-related transactions at financial institutions (FIs) and specialized financial institutions (SFIs). Released on August 5, 2026, the proposed regulation would supersede BOT Notification No. 16/2569, which focused primarily on cash withdrawal transactions. The public comment period is open through September 3, 2026. The amendments reflect concerns that FIs and SFIs may be used to facilitate the movement, concealment, and conversion of criminal proceeds, potentially damaging institutional operations and public confidence in the financial system. Expanded Scope of Covered Transactions The most significant change is the broadening of the definition of “cash-related transactions.” Previously, the regulation covered only cash withdrawals and uncrossed check withdrawals. The amended regulation extends coverage to include: Cash deposits, check deposits, or receipt of funds from the public not in the form of deposit accounts; Thai baht (THB) banknote exchange (different denominations); Receipt of cash for issuing checks and drafts; and Purchase, sale, or exchange of foreign banknotes. Mandatory Identity Verification and Risk Management For all cash-related transactions, FIs and SFIs must require customers, or authorized or delegated persons, to present identification or verify their identity before every transaction, including one-time (walk-in) transactions. Specific identification requirements vary by transaction type, customer nationality, and channel (branch vs. electronic). FIs and SFIs must also establish comprehensive risk management processes and procedures for cash-related transactions. These requirements include identifying customers or authorized representatives in accordance with transaction-specific verification standards, analyzing customer behavior, implementing risk-management measures proportionate to the customer’s risk profile, and recording abnormal behavior in relevant systems. The BOT also encourages institutions to proactively guide customers toward transaction channels that offer greater traceability than cash. For corporate customers in high-risk business sectors—including foreign
August 11, 2026
On July 27, 2026, the State Bank of Vietnam (SBV) released a draft decree proposing amendments to Decree No. 52/2024/ND-CP dated May 15, 2024, on non-cash payments (Decree 52). The draft decree would amend 17 of Decree 52’s 38 articles, with several key changes directly affecting providers of intermediary payment service (IPS). The key proposed changes affecting IPS providers are outlined below. Streamlining IPS Licensing Procedures A central objective of the draft decree is to simplify regulatory procedures for IPS providers. Notably, it would significantly reduce IPS licensing documentation requirements by removing the need to submit enterprise registration certificates, investment registration certificates, and documents evidencing the qualifications of the legal representative and general director. Instead, the SBV would retrieve this information directly from national business registration and other specialized databases, requesting additional documents only where the relevant information cannot be verified electronically or is incomplete. The draft decree also removes the current limit of two rounds for dossier supplementation and shortens processing timelines for several IPS licensing procedures such as issuance, amendment, and reissuance of IPS licenses. The processing time for new IPS license applications would be thereby reduced from 90 to 60 working days. In addition, several continuing IPS business conditions would be removed. For example, IPS providers would no longer be required to maintain certain representations relating to corporate restructuring or the legality of contributed capital. Likewise, the IPS project plan (đề án) would become a one-time application document rather than an ongoing licensing condition. If retained in the final decree, this change could provide IPS providers with significantly greater flexibility to implement post-licensing technology upgrades, system integrations, and corporate restructuring transactions without needing to revisit the originally approved project plan. The draft decree also removes the requirement for the SBV to consult the Ministry of Public
August 3, 2026
On July 23, 2026, the Bank of Thailand (BOT) released for public comment its draft Notification on Digital Channel Security, which would significantly expand the scope and stringency of Thailand’s existing mobile banking security framework. If finalized in its current form, the draft notification would extend mandatory security requirements to credit card providers and credit providers, cover internet banking in addition to mobile applications, phase out SMS one-time passwords (OTPs) for transaction authentication, and introduce biometric verification requirements for high-value transactions. The public comment period is open through August 24, 2026. Background The BOT’s existing Mobile Banking Security Notification, issued in 2024, sets minimum security standards for financial institutions, specialized financial institutions (SFIs), and e-money providers, significantly reducing “money-draining app” fraud. However, fraudsters have since shifted to nonbank providers and internet banking channels, prompting the BOT to propose broader security requirements. Expanded Scope of Regulated Entities and Channels The existing Mobile Banking Security Notification covers only financial institutions, SFIs, and e-money providers offering mobile banking services. The draft expands coverage in two key areas: entities and channels. On the entity side, it adds credit card providers and credit providers that offer fund transfers to third parties at other financial service providers or that provide cash withdrawal services to individual retail customers. On the channel side, it broadens coverage to include internet banking in addition to mobile banking. Strengthened Customer Authentication The draft introduces enhanced authentication requirements in three areas: Service enrollment and device changes. Providers must implement rigorous identity verification, notify customers of enrollment results through out-of-band communication channels, and adopt risk-mitigation measures such as cooling-off periods and temporary transaction limits. Transaction-level authentication. Providers must use two-factor authentication for fund transfers, cardless ATM withdrawals, and transaction limit increases. Secure authentication factors. Key requirements include the following: “What-you-know” factors must