You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 19, 2025

Thailand Drafts AI Risk Management Guidelines for Financial Service Providers

The Bank of Thailand (BOT) has released draft guidelines establishing principles for managing artificial intelligence (AI) risks in the financial sector. The draft guidelines provide a structured framework for the responsible adoption of AI technologies. Financial service providers will be able to use the guidelines as a reference to appropriately manage their risks in a manner that aligns with internationally recognized best practices.

The BOT is accepting public comments on the draft guidelines until June 30, 2025.

Scope and Application

The draft guidelines apply to all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. These guidelines supplement existing BOT risk management guidelines covering IT risk management, third-party risk management, data governance, and market conduct.

The guidelines define AI systems as systems that mimic human intelligence, including machine learning, deep learning, generative AI (such as large language models), and agentic AI. This definition specifically excludes rule-based automation systems like robotic process automation and condition matching.

Key Risk Management Principles

The guidelines lay out two main principles in managing AI risk.

  1. Governance: Financial service providers should define and establish clear roles and responsibilities for their personnel and AI system supervision structures to uphold FEAT (fairness, ethics, accountability, and transparency) principles as follows:
    • Stakeholder roles and responsibilities. Financial service providers should define roles and responsibilities for boards and executives on AI risk oversight. Responsibilities include establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization.
    • AI system usage policy. The AI system usage policy should be aligned with organizational objectives, regulatory requirements, and FEAT principles. These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles.
    • Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. When AI systems are used in strategic functions or customer interactions (e.g., loan approval, account opening), human oversight must be integrated into decision-making processes. In customer interactions with AI systems, customers should be notified and have options to disable or bypass AI features.
  1. Development and security controls: Financial service providers should have risk controls covering the AI development and deployment lifecycle as follows:
    • Data risk. Financial service providers should have measures to assess and ensure the quality, accuracy, currency, volume, and diversity of data used in AI model training. They should also implement data leakage prevention measures.
    • Model development risk. Financial service providers should have (1) clear evaluation metrics for assessing model accuracy and reliability through ongoing testing and monitoring both before and after deployment and (2) measures to ensure the explainability of AI outcomes. For generative AI applications, there should be specific measures to reduce AI hallucination risks.
    • Cybersecurity risk. Financial service providers should have measures to prevent and detect emerging cyber threats targeting AI systems, based on established standards such as the OWASP Machine Learning Security Top 10.

For more details on any aspect of fintech, technology, and cybersecurity in Thailand, please contact Athistha Chitranukroh at [email protected], Nopparat Lalitkomon at [email protected], Pornpan Wichawut at [email protected], Napassorn Lertussavavivat at [email protected], or Rujaporn Paritsantik at [email protected].

RELATED INSIGHTS​ 

May 15, 2023
Southeast Asia’s remarkable growth as a destination for foreign investment—including a 42 percent increase in 2021, according to a joint ASEAN-UNCTAD report—has brought with it innovation as well as the desire to protect that innovation. Investors are increasingly seeking to patent the proprietary technology that is a crucial component of so many businesses today, and a burning question for patent applicants is whether artificial intelligence (AI) technology and software are patentable in Southeast Asia. The short answer is that it depends, as the patent laws in Southeast Asia are not uniform. Is it Patentable? While AI tools tend to be newer, the older and more familiar question is whether computer software is patentable, and many jurisdictions do have specific rules on this issue. Pure software, or software characterized only by source code, may not be patentable, but it can be protected under copyright laws. AI-related software may involve complex algorithms, datasets, and training methodologies that can be challenging to disclose in a manner that satisfies the enablement requirement in practice. Algorithms, mathematical methods, and abstract ideas are often considered non-patentable subject matter in many jurisdictions. While software implementing AI may involve innovative algorithms, securing patents for algorithms alone can be challenging in some jurisdictions. Also, the patent laws of Indonesia, Myanmar, Thailand, and Vietnam specifically list computer programs as unpatentable subject matter. However, a possible workaround would be to describe the software as connected to a tangible medium. This method could overcome an unpatentable subject matter rejection during substantive examination. Furthermore, in Indonesia, a computer program can be patentable if its characteristics (i.e., instructions) have a technical effect and function to solve a tangible or intangible problem. The most liberal of Southeast Asia’s patent regimes—Singapore’s—even addresses AI innovations. The country has a special fast-track scheme for examining AI patent
May 9, 2023
The significance of artificial intelligence (AI) is rapidly increasing worldwide, and Southeast Asia is no exception, as it plays a leading role in the technological development of many industries. AI has already proven its importance for driving business growth in areas such as e-commerce, finance, and healthcare, but its remarkable potential also raises concerns around privacy. As AI systems are designed to collect and process large amounts of data to improve their operation, it is necessary to balance the development of technology with the protection of individuals’ privacy. Current Frameworks in Southeast Asia This concern has been on regional policymakers’ agendas for many years. The ASEAN Framework on Personal Data Protection, which was adopted in 2016, is not legally binding and has no enforcement mechanism, but it serves as a guide for ASEAN member states in developing their own data protection laws and regulations. Domestic data privacy laws are currently in force in five ASEAN member countries—Indonesia, Malaysia, the Philippines, Thailand, and Singapore—while Vietnam’s Personal Data Protection Decree is scheduled to take effect on July 1, 2023. This presents a challenge for ASEAN members, as adopting AI-related technology can further complicate data protection efforts due to the amount of personal data AI systems collect, as well as the complexity of the data used to train the AI algorithm. Some ASEAN members have also made progress in regulating AI. For instance, Singapore released the Model AI Governance Framework in 2019 and launched the AI Governance Testing Framework and Toolkit in 2022—the world’s first such framework. Similarly, Thailand issued the Artificial Intelligence Ethics Guideline in 2019 to help government agencies in the development, promotion, and use of AI, and in 2023 adopted the Thailand Artificial Intelligence Guidelines to help the private sector develop AI-related work. These guidelines primarily focus on principles
April 25, 2023
As in many countries around the world, IP laws in Southeast Asia do not currently specify whether works generated by artificial intelligence (AI) are protected by copyright, and there is also uncertainty surrounding the issue of ownership with respect to works created by AI. While changes to the IP legal framework are expected to respond to the rapid development of AI technologies, existing copyright laws of most countries in Southeast Asia explicitly impose the requirement of a human author for copyright protection to arise. AI-Generated Works and the Law This is similar to the position in the United States, where the US Copyright Office issued a policy statement in March 2023 reiterating the US Copyright Act’s requirement of human authorship to register copyright works. The policy document states that when an AI technology determines the expressive elements of the output, the generated materials do not fulfil the human authorship requirement. However, the US Copyright Office also clarified that certain works containing AI-generated materials may nonetheless contain sufficient human authorship for a copyright claim, such as when a human selects or arranges the AI-generated materials in a sufficiently creative way for the resulting work as a whole to constitute an original work of authorship, or when an artist modifies material originally generated by AI technology to a degree that meets the standard for copyright protection. This is distinguishable from the position in countries such as the UK and Hong Kong, where absent specific provisions addressing AI-generated works, such works may arguably be considered by some as computer-generated works, with authorship assigned to the person who arranges for creation of the work. New Challenges from Generative AI The ongoing legal uncertainties surrounding the ownership and protection of AI-generated works create practical challenges for businesses that use or develop generative AI tools.
April 21, 2023
After a protracted period of deliberation, the Vietnamese government ultimately passed the country’s “historic,” first-ever Personal Data Protection Decree (“PDPD”) on April 17, 2023, as Decree No. 13/2023/ND-CP. The PDPD is a landmark legal instrument that integrates all of Vietnam’s disparate data protection legislation, with the potential to bring them closer to the EU’s General Data Protection Regulation (“GDPR”) requirements. (The PDPD, however, will not replace these existing regulations but will concurrently exist with them.) Scheduled to take effect on July 1, 2023, with basically no grace period (save in limited cases), the PDPD will apply to both domestic and foreign individuals/entities that directly engage in or relate to personal data processing activities in Vietnam. As the PDPD continues to be a magnet for public attention, we take a closer look at its key provisions and some initial implications for businesses below. 1. Definition and Classification of Personal Data The PDPD defines personal data as information on an electronic medium in the form of symbols, letters, numbers, photos, sounds, or the like that is associated with or helps to identify a specific individual. Information that helps to identify a specific individual is further clarified as information generated from an individual’s activities that, when combined with other data and stored information, can identify a particular person. Personal data is split into two different categories—basic personal data and sensitive personal data. Basic personal data includes name, date of birth, gender, nationality, personal photos, phone number, identification number, marriage status, history of one’s cyberspace activities, and so on. Sensitive personal data, on the other hand, is more private and, if violated, will jeopardize a person’s legitimate rights and interests. Accordingly, sensitive personal data comprises, among other things, political and religious views, health status and private life information as recorded in medical records,