You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 19, 2025

Thailand Drafts AI Risk Management Guidelines for Financial Service Providers

The Bank of Thailand (BOT) has released draft guidelines establishing principles for managing artificial intelligence (AI) risks in the financial sector. The draft guidelines provide a structured framework for the responsible adoption of AI technologies. Financial service providers will be able to use the guidelines as a reference to appropriately manage their risks in a manner that aligns with internationally recognized best practices.

The BOT is accepting public comments on the draft guidelines until June 30, 2025.

Scope and Application

The draft guidelines apply to all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. These guidelines supplement existing BOT risk management guidelines covering IT risk management, third-party risk management, data governance, and market conduct.

The guidelines define AI systems as systems that mimic human intelligence, including machine learning, deep learning, generative AI (such as large language models), and agentic AI. This definition specifically excludes rule-based automation systems like robotic process automation and condition matching.

Key Risk Management Principles

The guidelines lay out two main principles in managing AI risk.

  1. Governance: Financial service providers should define and establish clear roles and responsibilities for their personnel and AI system supervision structures to uphold FEAT (fairness, ethics, accountability, and transparency) principles as follows:
    • Stakeholder roles and responsibilities. Financial service providers should define roles and responsibilities for boards and executives on AI risk oversight. Responsibilities include establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization.
    • AI system usage policy. The AI system usage policy should be aligned with organizational objectives, regulatory requirements, and FEAT principles. These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles.
    • Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. When AI systems are used in strategic functions or customer interactions (e.g., loan approval, account opening), human oversight must be integrated into decision-making processes. In customer interactions with AI systems, customers should be notified and have options to disable or bypass AI features.
  1. Development and security controls: Financial service providers should have risk controls covering the AI development and deployment lifecycle as follows:
    • Data risk. Financial service providers should have measures to assess and ensure the quality, accuracy, currency, volume, and diversity of data used in AI model training. They should also implement data leakage prevention measures.
    • Model development risk. Financial service providers should have (1) clear evaluation metrics for assessing model accuracy and reliability through ongoing testing and monitoring both before and after deployment and (2) measures to ensure the explainability of AI outcomes. For generative AI applications, there should be specific measures to reduce AI hallucination risks.
    • Cybersecurity risk. Financial service providers should have measures to prevent and detect emerging cyber threats targeting AI systems, based on established standards such as the OWASP Machine Learning Security Top 10.

For more details on any aspect of fintech, technology, and cybersecurity in Thailand, please contact Athistha Chitranukroh at [email protected], Nopparat Lalitkomon at [email protected], Pornpan Wichawut at [email protected], Napassorn Lertussavavivat at [email protected], or Rujaporn Paritsantik at [email protected].

RELATED INSIGHTS​ 

November 24, 2021
Attorneys from Tilleke & Gibbins have provided the latest update to the Thailand contribution to Doing Business in…, a Q&A-style guide published by Thomson Reuters Practical Law that presents an overview of the legal framework for doing business in 63 jurisdictions worldwide. The Thailand chapter of the guide outlines Thailand’s legal system and key laws applicable to foreign companies doing business in the country. The chapter specifically covers the following main topics: Legal system: Thailand’s court system and codified legal system. Foreign investment: Lists of reserved business activities, restrictions on doing business with certain jurisdictions, exchange controls and currency regulations, and grants and incentives available to investors. Business vehicles: Ordinary partnerships, registered ordinary partnerships, limited partnerships, private limited companies, and public companies. Environment: Main laws and regulations, factory operation. Employment: Laws, employment contract requirements, work permits, and termination and redundancy. Tax: Taxes on employment, tax and nontax resident employees and businesses, corporate income tax, value added tax, special business tax, municipal tax, stamp duty, dividends, interest, intellectual property royalties. Competition: Important aspects of Thailand’s regulatory regime surrounding competition, centered around the updated Trade Competition Act. Antibribery and corruption: Laws, compliance requirements, regulatory authority. Intellectual property: Patents, trademarks, registered and unregistered designs, and copyright. Marketing agreements and advertising: Regulation of marketing agreements, Thailand’s Consumer Protection Act, direct marketing, role of the Consumer Protection Board and Food and Drug Administration. E-commerce: E-commerce laws and regulations, marketing and sales via online platforms. Data protection: An outline of Thailand’s Personal Data Protection Act. Product liability: Procedures and regulations for product liability and product safety, including the Unsafe Goods Liability Act and the Consumer Case Procedure Act. Product liability: Key regulatory authorities for trade competition, environmental issues, and financial services. To browse, download, or print the Thailand chapter, please visit the Practical Law website.
October 25, 2021
Michael Ramirez, a counsel in Tilleke & Gibbins’ dispute resolution group in Bangkok, has updated the firm’s contribution to the Global Attorney-Client Privilege Guide, published by Lex Mundi. The newly expanded guide provides information on what constitutes attorney-client privilege in over 70 countries around the world. The Thailand section of the guide contains in-depth information on the function and applications of attorney-client privilege in Thailand (or, as explained in the guide, an equivalent concept enshrined in Thai law), including coverage of the following topics: Privilege in corporations Common interest doctrine Litigation funding Crime-fraud exception Work product doctrine/litigation privilege Other privileges including mediation, accountant-client and settlement negotiation The interactive guide features expert contributions by Lex Mundi member firms from jurisdictions worldwide. Readers can browse the contributions, generate country-specific reports, and compare attorney-client privilege in multiple jurisdictions. For more information, please visit the Lex Mundi website.
October 19, 2021
On September 9, 2021, Laos announced a new pilot program to allow the mining and trading of cryptocurrency. Notification No. 1158, issued by the Prime Minister’s Office, provides for an electricity sale-purchase agreement with six companies involved in the pilot program. Under the notification, the six companies authorized by the prime minister to mine and trade cryptocurrency in Laos will pay a capped fee for energy they use in data processing or mining cryptocurrency. This effectively establishes a sandbox in which these six companies may mine and trade cryptocurrency—including on international cryptocurrency exchanges. The Ministry of Technology and Communications (MTC) is in charge of coordinating the program, together with the Ministry of Finance, the Bank of the Lao PDR, the Ministry of Planning and Investment, the Ministry of Energy and Mines, the Ministry of Public Security, and Électricité du Laos. The MTC is also charged with drafting the rules of the pilot program and setting the conditions on which the participating companies can mine, sell, and purchase cryptocurrency in Laos. One of the six selected companies will also act as a coordinator for the other companies and report to the government on any benefits of cryptocurrency observed during the pilot program. The next step is for the MTC to compile data analysis from each of the other government agencies and submit the conclusions to a meeting of the prime minister and the deputy prime ministers before the pilot program is implemented. The pilot program was originally scheduled to start in September, but there has not yet been any update on the implementation of the program, which nonetheless is expected to start in the near future.
October 19, 2021
In September 2021, the Bank of Thailand (BOT) issued its Guidelines on Data Governance to provide financial institutions with recommendations on how to ensure that their data governance will be in compliance with accepted international principles. While there are no penalties for noncompliance, financial institutions should view the recommendations as minimum standard expectations for their data governance in Thailand. The BOT guidelines set forth five main data governance principles: Data Governance Policy Financial institutions should set forth their data governance policy in writing in accordance with their business size, business operations, business complexity, and data risk. The policy should cover all types of data, including data related to services from third parties or business partners, as well as provide information on the data governance structure, data lifecycle management, protection of data security and data privacy, and incident management. Financial institutions should inform their employees and other relevant parties of the policy to ensure their compliance. In addition, the data governance policy must be approved by the designated board or committee of the financial institution, and be reviewed and revised in response to significant changes. Data Governance Structure Financial institutions should establish a data governance structure with three lines of defense, supervised by an oversight committee. The first line of defense comprises data management personnel, a data approver, and data users; the second comprises a risk management unit and a compliance unit; and the third is an audit unit. While the chosen data governance structure can be tailored to the characteristics of the institution, the structure should cover all of these roles and duties, and must not contravene the principle of checks and balances. The data governance structure should also be supported by sufficient personnel and equipment, as well as a clear plan—reviewed and revised as necessary—for building awareness at