You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 19, 2025

Thailand Drafts AI Risk Management Guidelines for Financial Service Providers

The Bank of Thailand (BOT) has released draft guidelines establishing principles for managing artificial intelligence (AI) risks in the financial sector. The draft guidelines provide a structured framework for the responsible adoption of AI technologies. Financial service providers will be able to use the guidelines as a reference to appropriately manage their risks in a manner that aligns with internationally recognized best practices.

The BOT is accepting public comments on the draft guidelines until June 30, 2025.

Scope and Application

The draft guidelines apply to all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. These guidelines supplement existing BOT risk management guidelines covering IT risk management, third-party risk management, data governance, and market conduct.

The guidelines define AI systems as systems that mimic human intelligence, including machine learning, deep learning, generative AI (such as large language models), and agentic AI. This definition specifically excludes rule-based automation systems like robotic process automation and condition matching.

Key Risk Management Principles

The guidelines lay out two main principles in managing AI risk.

  1. Governance: Financial service providers should define and establish clear roles and responsibilities for their personnel and AI system supervision structures to uphold FEAT (fairness, ethics, accountability, and transparency) principles as follows:
    • Stakeholder roles and responsibilities. Financial service providers should define roles and responsibilities for boards and executives on AI risk oversight. Responsibilities include establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization.
    • AI system usage policy. The AI system usage policy should be aligned with organizational objectives, regulatory requirements, and FEAT principles. These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles.
    • Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. When AI systems are used in strategic functions or customer interactions (e.g., loan approval, account opening), human oversight must be integrated into decision-making processes. In customer interactions with AI systems, customers should be notified and have options to disable or bypass AI features.
  1. Development and security controls: Financial service providers should have risk controls covering the AI development and deployment lifecycle as follows:
    • Data risk. Financial service providers should have measures to assess and ensure the quality, accuracy, currency, volume, and diversity of data used in AI model training. They should also implement data leakage prevention measures.
    • Model development risk. Financial service providers should have (1) clear evaluation metrics for assessing model accuracy and reliability through ongoing testing and monitoring both before and after deployment and (2) measures to ensure the explainability of AI outcomes. For generative AI applications, there should be specific measures to reduce AI hallucination risks.
    • Cybersecurity risk. Financial service providers should have measures to prevent and detect emerging cyber threats targeting AI systems, based on established standards such as the OWASP Machine Learning Security Top 10.

For more details on any aspect of fintech, technology, and cybersecurity in Thailand, please contact Athistha Chitranukroh at [email protected], Nopparat Lalitkomon at [email protected], Pornpan Wichawut at [email protected], Napassorn Lertussavavivat at [email protected], or Rujaporn Paritsantik at [email protected].

RELATED INSIGHTS​ 

September 24, 2021
On September 15, 2021, Thailand’s Securities and Exchange Commission (SEC) announced a prospective new scheme that will enable small and medium enterprises (SMEs) and startups in Thailand to raise funds through public offerings. The SEC regulations to implement this new scheme are expected by the first quarter of 2022. Since 2019, the SEC has allowed SMEs and startups in Thailand to raise funds via private placements or crowdfunding. The new SEC scheme will allow SMEs and startups to raise funds on a larger scale via a new type of public offering (the so-called SME-PO). The SEC also plans to establish the “SME Board,” a secondary market for trading the stocks of SMEs. Under the new SEC scheme, SMEs and startups that wish to proceed with an SME-PO must be structured as public companies with investor protection mechanisms in accordance with the Public Company Act B.E. 2535 (1992). Although SEC representatives have previously indicated that SME-POs would be subject to an information-based approach instead of the normal approval process for public offerings, the September 15 announcement does not detail this further, beyond noting that the SEC may deem it appropriate in future to relax certain requirements such as filing for approval, appointment of an independent financial advisor, and fees. Investors in public offerings for SMEs and startups must be sophisticated investors who are risk-tolerant and well capitalized, such as institutional investors, private equity or venture capital firms, angel investors, or an SMEs’ own directors, employees, or affiliates. Tilleke & Gibbins will continue to follow the development of regulations for SME-POs, as the rules and criteria described here are still subject to change. For more information on fundraising alternatives for SMEs and startups, or on any aspect of capital markets regulations in Thailand, please contact Onunya Chanpen at [email protected] or Kobkit Thienpreecha
August 26, 2021
Background In Thailand, bad-faith domain name registrations can present a unique challenge to brand owners. According to the current domain registration policy, Thai domain names can be based on the registered name of a company or organization, or on a registered trademark, depending on the domain name category. When Thailand’s domain name registrar, the Thai Network Information Centre Foundation (THNIC), considers applications for new domain names, it examines only whether the applicant meets these criteria – and not whether the application has been led in bad faith, such as when a registered company uses someone else’s registered trademark without authorization. Domain name registration in Thailand is a first-to-file system, so if all criteria are met, THNIC must allow registration. There are no opposition or cancellation proceedings, making it impossible for an interested person, as well as THNIC itself, to invalidate a Thai-registered domain name. Disputes between two legitimate owners Disputes sometimes arise between trademark owners and Thai-registered companies, such as third-party companies, local distributors, or even authorized trademark licensees who exploit the policy gap identified above. For instance, in a recent case a brand owner found that its Thailand distributor had been able to register a company name containing its registered trademark, and subsequently register such name as a domain name, without the trademark owner’s consent. Fortunately, the two parties had a strong existing business relationship as supplier and distributor; through amicable negotiation, the local distributor agreed to withdraw the disputed domain name. However, if both parties had insisted on their legitimate rights over the disputed name, the case would have had to proceed to court, as THNIC does not get involved in such disputes and offers no dispute resolution mechanisms. Navigating the options Trademark owners facing such a dispute have two options: initiating proceedings with the Intellectual Property
August 18, 2021
On July 15, 2021, Thailand’s Electronic Transactions Development Agency (ETDA) announced a public hearing for their draft royal decree to regulate digital platforms (particularly e-commerce and e-service platforms) that provide services to people in Thailand. The draft royal decree is to be issued under the country’s Electronic Transactions Act B.E. 2544 (2001) and will be of particular concern to digital platform operators, which are defined as operators of intermediary digital platforms that provide a connection space for platform users to offer goods, services, or intangible property via a computer network, regardless of whether a contract is made on the digital platform. The key elements of the current draft royal decree are as follows: Extraterritorial scope. Operators of digital platforms located outside Thailand may be subject to the royal decree if the platform is intended to provide services to people in Thailand (evidenced by actions such as inclusion of Thai language, Thai currency, Thai domain names, and so on). Appointment of a local representative. A foreign digital platform operator that falls under the extraterritorial scope of the royal decree must appoint a local representative in Thailand, without limitation of liability. Notification requirements. Regulated digital platform operators must notify the ETDA of their operations via an online submission channel. The ETDA will also develop an online channel for consumers to check or verify the list of regulated digital platform operators. Further notification requirements and procedures are to be prescribed by the ETDA later. Platform-related requirements. The draft royal decree also sets various platform-related requirements, depending on the size of the digital platform operator (to be specified later). These requirements relate to the following: Terms and conditions; Content display; Content rating; Feedback mechanisms; Dispute settlement; Access and use of data; Control of advertisements; Notice and takedown measures; User verification processes; Suspension of