You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 13, 2024

Thailand Accepting Applications for Programmable Payment Regulatory Sandbox

The Bank of Thailand (BOT) has announced its new Enhanced Regulatory Sandbox, which provides an opportunity to experiment with currently restricted financial innovations under a controlled environment. The BOT is employing a thematic approach to determine the scope of technology or innovations that may participate in the Enhanced Regulatory Sandbox and will only accept applications in each theme for a limited period.

The first announced theme is “programmable payments,” which refers to payment and payment-related transactions with automatic execution upon the fulfillment of a predefined condition utilizing distributed ledger technology (DLT) and a smart contract or comparable technology in which electronic data units are issued on an electronic system or network. The application period for programmable payment testing in the Enhanced Regulatory Sandbox runs from June 13 to September 13, 2024.

A summary of the programmable payment testing framework under the Enhanced Regulatory Sandbox is provided below.

Scope

The Enhanced Regulatory Sandbox accepts applications for the following programmable payment activities:

  • Automated payment and settlement upon fulfillment of predefined conditions.
  • Escrow services with predefined delivery or transactional conditions.
  • Asset tokenization through issuance of digital tokens representing rights in an asset, with payment for tokens or payment of benefits or returns to holders of digital tokens occurring automatically when conditions are met.
  • Other testing related to the items mentioned above.

Requirements and Conditions

Programmable payment testing activities in the Enhanced Regulatory Sandbox must comply with the following requirements and conditions:

  • Electronic data units issued for programmable payment testing must be pegged to the Thai baht (THB) on a one-for-one basis (i.e., 1 unit = THB 1), with the float account storing THB equal to the value of the electronic data units issued.
  • Participants must define the redemption rights of the unitholders and proceed with the THB redemption according to the participants’ service level agreements.
  • Participants must have risk management, IT support, business continuity, and IT disaster recovery plans.
  • Participants must comply with know your customer (KYC), know your merchant (KYM), and customer due diligence (CDD) standards under the relevant laws and regulations of Thailand’s Anti-Money Laundering Office.
  • Participants must have a client suitability assessment process to prevent vulnerable customers from using services under the testing.
  • Participants must have measures to prevent the utilization of electronic data units for purposes outside the scope of testing (e.g., using the units as means of payment outside the scope of the test, listing the units on digital asset platforms, or using the units for investment or speculation purposes).

For more information on the BOT’s regulatory sandbox program, regulations on programmable payments, or any other aspect of fintech in Thailand, please contact Athistha (Nop) Chitranukroh at [email protected], Pornpan Wichawut at [email protected], or Rujaporn Paritsantik at [email protected].

RELATED INSIGHTS​ 

June 30, 2022
On May 30, 2022, Thailand’s Securities and Exchange Commission (SEC) announced that it would start regulating ready-to-use utility tokens, a type of digital token that had previously been exempted from the SEC’s approval and regulatory control. A public forum was open for comments from various stakeholders until June 29, 2022, and the draft regulation is expected to be issued soon. So far, the SEC has only supervised the issuance of not-ready-to-use utility tokens—digital tokens with the underlying right to acquire specific goods or services, which cannot be utilized upon issuance but at a later date. Due to the growing digital asset industry and lack of regulatory control, ready-to-use utility tokens have become more popular and many are listed for trading in digital asset exchanges. The SEC claimed that it is now necessary to regulate ready-to-use utility tokens as some issuers appeared to be exploiting the regulatory loophole to manipulate the price and supply of these tokens in both the primary and secondary markets, while providing insufficient data disclosure to investors. The SEC’s proposed principles include the following key points: Pre-Approval Requirements The same pre-approval requirement applicable to not-ready-to-use utility tokens will apply to ready-to-use utility tokens which an issuer intends to list on a digital asset exchange. This means that the issuer must proceed with the standard formalities, i.e., obtaining prior approval from the SEC, filing a draft prospectus, and offering the approved tokens via a SEC-approved ICO portal operator only. The SEC offers a fast-track (15 days) approval for qualifying ready-to-use utility tokens, which are those with plain-vanilla characteristics; with an offering price corresponding to the value of the underlying goods/services; for which the supply of goods and services does not vary with the price of the tokens (i.e., fixed coins); and which are not intended to be
February 21, 2022
On February 14, 2022, Thailand’s Securities and Exchange Commission (SEC) announced a public hearing period on proposed advertising regulations for digital asset businesses. The public hearing period is now open for general comments until March 15, 2022. In the announcement, the SEC expressed their intention to provide clear digital asset advertising principles that conform to regulations in other countries, such as Singapore, the UK, and Japan. The SEC, in a meeting on February 3, agreed that the principles to be developed should apply to all digital asset businesses operating in Thailand. During the public hearing period, any interested parties may comment on the SEC’s proposed principles, which include the following key points: Advertisements that educate, inform, or give facts about digital assets, investments or services, or that provide an overall picture of digital assets, must not exaggerate, distort, or conceal information, or otherwise mislead consumers. In addition, advertisements that refer to customer numbers must only indicate the number of customers who have received approval to open an account and who are ready to use the service. Advertisements must be clear and appropriate, provide a warning on investment risks, and include clear and noticeable SEC-mandated statements in the font size stipulated by the SEC. Advertisements that present positive information or suggest an opportunity to receive returns must provide a balanced view that also discloses negative information or states investment risks. Advertisements relating to cryptocurrencies can only be made via a business operator’s official channels (e.g., the operator’s website, app, or other official online channel), and cryptocurrency cannot be advertised in public areas (e.g., billboards, public transportation, websites, newspapers and periodicals, etc.). However, advertisements for the services of a digital assets business can still be made in public areas and other channels. For example, this can be understood as meaning that
October 19, 2021
On September 9, 2021, Laos announced a new pilot program to allow the mining and trading of cryptocurrency. Notification No. 1158, issued by the Prime Minister’s Office, provides for an electricity sale-purchase agreement with six companies involved in the pilot program. Under the notification, the six companies authorized by the prime minister to mine and trade cryptocurrency in Laos will pay a capped fee for energy they use in data processing or mining cryptocurrency. This effectively establishes a sandbox in which these six companies may mine and trade cryptocurrency—including on international cryptocurrency exchanges. The Ministry of Technology and Communications (MTC) is in charge of coordinating the program, together with the Ministry of Finance, the Bank of the Lao PDR, the Ministry of Planning and Investment, the Ministry of Energy and Mines, the Ministry of Public Security, and Électricité du Laos. The MTC is also charged with drafting the rules of the pilot program and setting the conditions on which the participating companies can mine, sell, and purchase cryptocurrency in Laos. One of the six selected companies will also act as a coordinator for the other companies and report to the government on any benefits of cryptocurrency observed during the pilot program. The next step is for the MTC to compile data analysis from each of the other government agencies and submit the conclusions to a meeting of the prime minister and the deputy prime ministers before the pilot program is implemented. The pilot program was originally scheduled to start in September, but there has not yet been any update on the implementation of the program, which nonetheless is expected to start in the near future.
October 19, 2021
In September 2021, the Bank of Thailand (BOT) issued its Guidelines on Data Governance to provide financial institutions with recommendations on how to ensure that their data governance will be in compliance with accepted international principles. While there are no penalties for noncompliance, financial institutions should view the recommendations as minimum standard expectations for their data governance in Thailand. The BOT guidelines set forth five main data governance principles: Data Governance Policy Financial institutions should set forth their data governance policy in writing in accordance with their business size, business operations, business complexity, and data risk. The policy should cover all types of data, including data related to services from third parties or business partners, as well as provide information on the data governance structure, data lifecycle management, protection of data security and data privacy, and incident management. Financial institutions should inform their employees and other relevant parties of the policy to ensure their compliance. In addition, the data governance policy must be approved by the designated board or committee of the financial institution, and be reviewed and revised in response to significant changes. Data Governance Structure Financial institutions should establish a data governance structure with three lines of defense, supervised by an oversight committee. The first line of defense comprises data management personnel, a data approver, and data users; the second comprises a risk management unit and a compliance unit; and the third is an audit unit. While the chosen data governance structure can be tailored to the characteristics of the institution, the structure should cover all of these roles and duties, and must not contravene the principle of checks and balances. The data governance structure should also be supported by sufficient personnel and equipment, as well as a clear plan—reviewed and revised as necessary—for building awareness at