You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 19, 2025

Thailand Drafts AI Risk Management Guidelines for Financial Service Providers

The Bank of Thailand (BOT) has released draft guidelines establishing principles for managing artificial intelligence (AI) risks in the financial sector. The draft guidelines provide a structured framework for the responsible adoption of AI technologies. Financial service providers will be able to use the guidelines as a reference to appropriately manage their risks in a manner that aligns with internationally recognized best practices.

The BOT is accepting public comments on the draft guidelines until June 30, 2025.

Scope and Application

The draft guidelines apply to all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. These guidelines supplement existing BOT risk management guidelines covering IT risk management, third-party risk management, data governance, and market conduct.

The guidelines define AI systems as systems that mimic human intelligence, including machine learning, deep learning, generative AI (such as large language models), and agentic AI. This definition specifically excludes rule-based automation systems like robotic process automation and condition matching.

Key Risk Management Principles

The guidelines lay out two main principles in managing AI risk.

  1. Governance: Financial service providers should define and establish clear roles and responsibilities for their personnel and AI system supervision structures to uphold FEAT (fairness, ethics, accountability, and transparency) principles as follows:
    • Stakeholder roles and responsibilities. Financial service providers should define roles and responsibilities for boards and executives on AI risk oversight. Responsibilities include establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization.
    • AI system usage policy. The AI system usage policy should be aligned with organizational objectives, regulatory requirements, and FEAT principles. These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles.
    • Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. When AI systems are used in strategic functions or customer interactions (e.g., loan approval, account opening), human oversight must be integrated into decision-making processes. In customer interactions with AI systems, customers should be notified and have options to disable or bypass AI features.
  1. Development and security controls: Financial service providers should have risk controls covering the AI development and deployment lifecycle as follows:
    • Data risk. Financial service providers should have measures to assess and ensure the quality, accuracy, currency, volume, and diversity of data used in AI model training. They should also implement data leakage prevention measures.
    • Model development risk. Financial service providers should have (1) clear evaluation metrics for assessing model accuracy and reliability through ongoing testing and monitoring both before and after deployment and (2) measures to ensure the explainability of AI outcomes. For generative AI applications, there should be specific measures to reduce AI hallucination risks.
    • Cybersecurity risk. Financial service providers should have measures to prevent and detect emerging cyber threats targeting AI systems, based on established standards such as the OWASP Machine Learning Security Top 10.

For more details on any aspect of fintech, technology, and cybersecurity in Thailand, please contact Athistha Chitranukroh at [email protected], Nopparat Lalitkomon at [email protected], Pornpan Wichawut at [email protected], Napassorn Lertussavavivat at [email protected], or Rujaporn Paritsantik at [email protected].

RELATED INSIGHTS​ 

April 18, 2023
On April 17, 2023, the Vietnamese government issued Decree No. 13/2023/ND on the Protection of Personal Data (“PDPD”), following extensive public consultations and multiple rounds of review since the first release of its draft version in February 2021. This is a long-awaited legal instrument which is designed to be the very first comprehensive regulation on the protection of personal data in Vietnam. The PDPD is set to take effect on July 1, 2023, without any transitional period. All Vietnamese and foreign organizations and individuals located in Vietnam and/or directly participating in or related to personal data processing activities in Vietnam must comply with the PDPD. As expected, the PDPD sets out significantly new requirements on the processing of personal data. The most critical provisions include: Eight principles for the processing of personal data: (i) lawfulness, (ii) transparency, (iii) purpose limitation, (iv) data minimization, (v) accuracy, (vi) integrity, confidentiality, and security, (iv) storage limitation, and (viii) accountability (Article 3). Critical new definitions and concepts, notably including personal data (Article 2.1); basic personal data (Article 2.3); sensitive data (Article 2.4); data subject (Article 2.6); data controller (Article 2.9); data processor (Article 2.10); parties controlling and processing personal data (Article 2.11); third parties (Article 2.12); and cross-border transfer of personal data (Article 2.14). Eleven data subject rights, including the right to know; right to consent; right to access; right to withdraw consent; right to delete data; right to restrict data processing; right to request the provision of data; right to object to data processing; right to complain, denounce and initiate lawsuits; right to claim compensation for damage; and right to self-defense (Article 9). Specific responsibilities of data controllers (Article 38), data processors (Article 39) and third parties (Article 41). Specific requirements in the exercise of data subject rights (Articles 14-16). Rules on
April 17, 2023
Since the issuance last October of Decree No. 71/2022/ND-CP (“Decree 71”), the differentiation of film vs. non-film content has become increasingly important for pay-TV service providers in Vietnam, because they are subject to completely different licensing requirements. With the effectiveness of Decree 71 on January 1, 2023, overseas providers of over-the-top (OTT) pay-TV services, including video on demand (VOD) content, to Vietnamese users are subject to licensing requirements and the establishment of a local presence in Vietnam. Meanwhile, the new Cinema Law promulgated on June 15, 2022, and its guiding Decree No. 131/2022/ND-CP dated December 31, 2022—both of which also took effect on January 1, 2023—do not impose any licensing requirements on film disseminators. Although there are ambiguities in Decree 71’s wording, the Ministry of Information and Communication (MIC) and the Authority for Broadcasting and Electronic Information (ABEI) under the MIC have confirmed orally in a closed industry meeting, without written confirmation, that for VOD film-only content, OTT pay-TV service providers are exempted from the licensing requirements of Decree 71 and are instead subject to regulations of the Cinema Law. This is why film vs. non-film content has become critical in shaping the business models of overseas pay-TV service providers. In this article, we provide an overview of the current regulations and draft regulations with regard to the classification/rating of film content under the regulations of the Cinema Law and its sub-laws, and the classification/rating of non-film content under the regulations of Decree 71.   Film Classification/Rating Under the Cinema Law, “films” are defined to include feature films, documentaries, cartoons, and films of combined genres. The law explicitly provides that “films” do not include recorded products for disseminating news, art shows, video games, recorded products that show the activities of one or more people and describe events and situations,
March 30, 2023
Digital asset litigation is one of the most cutting-edge types of litigation in Thailand. There are factual, technical, regulatory, and legal challenges and hurdles for the parties to the dispute throughout all procedural stages. This is mainly because digital assets are different in nature from more conventional types of assets, as they are digitally created and used on a blockchain network. Legal Status The first issue to be aware of in approaching digital asset litigation is the legal status of digital assets. Under Thai law, there are two key terms concerning digital assets’ legal status: “thing” and “property.” Things are tangible objects, while property provides a much wider range of meaning. Property could be anything—including intangible objects that may be of value and able to be appropriated. It is fairly clear that digital assets are not a “thing” since they are not tangible. However, determining whether digital assets are “property” is even more complicated. Although digital assets are intangible objects, one might argue that, unlike fiat money, they do not have any inherent value but are rather conferred value based on certain people’s perspective. (For example, the Bank of Thailand expressed this opinion of bitcoin in 2014.) Some may even argue that digital assets cannot be possessed and therefore cannot be appropriated. According to these arguments, digital assets should not be regarded as a property either. Legal Grounds Determining whether digital assets are things, property, or something else altogether is crucial to any subsequent litigation. In Thailand, the party initiating the lawsuit (the plaintiff) generally has to state the relevant legal grounds for the complaint—that is, the different relevant legal provisions that the court is to apply to the case. These provisions of Thai laws mostly refer only to “things” or to “property,” not both. This often means that
March 20, 2023
Thailand has enacted new legislation to counter cybercrime and scams. The Royal Decree on Measures for Protection and Suppression of Technology Crimes B.E. 2566 (2023) (“Cybercrime Decree”) was published in the Government Gazette on March 16, 2023, and took effect the following day. The Cybercrime Decree provides a new legal tool to interrupt the money-laundering process and aims to crack down on cybercrime perpetrators and scammers by providing stronger legal measures applying to certain types of offenders that had not been sufficiently covered by existing laws. This new legislation grants victims the right to have commercial banks and online payment platforms freeze suspicious transactions and obligates these banks and platforms to comply with such requests. It further requires these banks and platforms—as well as other service providers—to share data for the prompt prevention and suppression of cybercrime. The key rights, duties, and offenses established by the Cybercrime Decree are detailed below. Freezing Transactions The Cybercrime Decree requires commercial banks and online payment platforms to temporarily freeze (for 72 hours) any related transactions of their account holders upon receipt of an alert from the account holder that he or she is the victim of cybercrime. Victims can report these illicit transactions by phone or electronic means. If by phone, the relevant bank or platform must document the call. The victim must file a police complaint about the illicit transaction within 72 hours of the freeze being made. A police inquiry officer will then notify the bank or platform about the complaint, and the transaction freeze must be maintained for seven days from the filing of the complaint with the police. The police will then determine whether it is necessary to keep the transaction frozen for longer than seven days. If the seven days lapse without a further order to freeze the