You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 19, 2025

Thailand Drafts AI Risk Management Guidelines for Financial Service Providers

The Bank of Thailand (BOT) has released draft guidelines establishing principles for managing artificial intelligence (AI) risks in the financial sector. The draft guidelines provide a structured framework for the responsible adoption of AI technologies. Financial service providers will be able to use the guidelines as a reference to appropriately manage their risks in a manner that aligns with internationally recognized best practices.

The BOT is accepting public comments on the draft guidelines until June 30, 2025.

Scope and Application

The draft guidelines apply to all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. These guidelines supplement existing BOT risk management guidelines covering IT risk management, third-party risk management, data governance, and market conduct.

The guidelines define AI systems as systems that mimic human intelligence, including machine learning, deep learning, generative AI (such as large language models), and agentic AI. This definition specifically excludes rule-based automation systems like robotic process automation and condition matching.

Key Risk Management Principles

The guidelines lay out two main principles in managing AI risk.

  1. Governance: Financial service providers should define and establish clear roles and responsibilities for their personnel and AI system supervision structures to uphold FEAT (fairness, ethics, accountability, and transparency) principles as follows:
    • Stakeholder roles and responsibilities. Financial service providers should define roles and responsibilities for boards and executives on AI risk oversight. Responsibilities include establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization.
    • AI system usage policy. The AI system usage policy should be aligned with organizational objectives, regulatory requirements, and FEAT principles. These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles.
    • Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. When AI systems are used in strategic functions or customer interactions (e.g., loan approval, account opening), human oversight must be integrated into decision-making processes. In customer interactions with AI systems, customers should be notified and have options to disable or bypass AI features.
  1. Development and security controls: Financial service providers should have risk controls covering the AI development and deployment lifecycle as follows:
    • Data risk. Financial service providers should have measures to assess and ensure the quality, accuracy, currency, volume, and diversity of data used in AI model training. They should also implement data leakage prevention measures.
    • Model development risk. Financial service providers should have (1) clear evaluation metrics for assessing model accuracy and reliability through ongoing testing and monitoring both before and after deployment and (2) measures to ensure the explainability of AI outcomes. For generative AI applications, there should be specific measures to reduce AI hallucination risks.
    • Cybersecurity risk. Financial service providers should have measures to prevent and detect emerging cyber threats targeting AI systems, based on established standards such as the OWASP Machine Learning Security Top 10.

For more details on any aspect of fintech, technology, and cybersecurity in Thailand, please contact Athistha Chitranukroh at [email protected], Nopparat Lalitkomon at [email protected], Pornpan Wichawut at [email protected], Napassorn Lertussavavivat at [email protected], or Rujaporn Paritsantik at [email protected].

RELATED INSIGHTS​ 

March 17, 2025
Tilleke & Gibbins has contributed the Cambodia, Myanmar, Thailand, and Vietnam chapters to Data Protection and Cybersecurity Regulation in Southeast Asia, a wide-ranging guide published by Drew Network Asia (DNA). The resource provides a comprehensive overview of data protection and cybersecurity laws across the region, offering practical insight into compliance requirements and regulatory developments affecting organizations that handle personal data or operate digital services in Southeast Asia. The guide begins with a regional overview, including the broader ASEAN context and cooperation initiatives. Jurisdiction-specific chapters follow a consistent structure—covering data privacy and governance obligations, security requirements and breach notification, outsourcing and cross-border data transfers, and broader accountability and compliance measures. This format allows readers to compare regulatory approaches across markets such as Brunei, Indonesia, Malaysia, the Philippines, Singapore, and others. In addition to the country chapters, the publication addresses cybersecurity and privacy engineering challenges, providing guidance for organizations and outlining obligations applicable to data controllers, processors, and intermediaries. A dedicated section on data breach management across ASEAN examines notification requirements, response considerations, and practical steps for managing incidents in a regional or global context. The guide is intended to serve as a practical reference, and the authors note that specific legal requirements may vary depending on sector, processing activity, or evolving legislation. Readers seeking more detailed advice can contact the practitioners listed in each chapter. The full guide is available for download using the button below or directly from the DNA website.
March 14, 2025
The Bank of Thailand (BOT) has published the Draft Guidelines for Digital Fraud Management, which aim to help financial service providers tackle digital fraud and ensure safety and trust in the Thai financial system. These draft guidelines, which are available for public comment until March 18, 2025, provide a comprehensive framework for financial service providers, covering prevention, detection, management, and resolution of digital fraud, as well as support for customers affected by fraud. The BOT tentatively plans to implement these draft guidelines on April 1, 2025, along with circular letters on the minimum required measures for tackling “mule accounts” (deposit or e-money accounts used as tools to receive and transfer funds obtained through the commission of any offense) and measures to strengthen Thailand’s customer due diligence and enhanced due diligence procedures. Under the draft guidelines, “financial service providers” include financial institutions and special financial institutions under the Financial Institution Business Act and payment providers under the Payment Systems Act. Commercial banks, special financial institutions, and operators of transferable e-money services must adhere to every requirement in the draft guidelines. Other financial service providers (e.g., payment providers other than operators of transferable e-money services) can implement the draft guidelines as deemed appropriate to their services, products, and service channels. Digital Fraud Management Requirements The draft guidelines establish the following key requirements: Policy and oversight. Directors and senior executives of financial service providers must set and adopt appropriate “end-to-end” fraud management policies and KPIs to manage digital fraud, covering prevention, monitoring, detection, management, resolution, and support for affected customers. Fraud management processes. Financial service providers must establish a clear framework for managing digital fraud throughout the customer lifecycle, from customer onboarding to service termination, according to industry standards at a minimum and covering at least the following processes: Know your customer
March 13, 2025
Vietnam’s Ministry of Finance has released a draft Decree on Tax Administration for E-Commerce and Digital Platforms (“Draft Decree”), introducing significant tax compliance obligations that could reshape how digital platforms, and individuals and business households conducting business through the platforms, manage their tax responsibilities. Aimed at strengthening tax enforcement, the Draft Decree requires e-commerce and digital platforms to actively track and withhold taxes from business households and individual sellers, and remit payments to tax authorities. While it has not yet been promulgated, the Draft Decree is expected to take effect on April 1, 2025, leaving platforms with a limited window to prepare for compliance. Who Is Affected by the New Tax Rules? The Draft Decree significantly broadens the tax administration scope beyond traditional e-commerce platforms to cover a wide range of digital economy participants. Specifically, the Draft Decree places direct tax-related responsibilities on two major categories (collectively, “Regulated Operators”): E-commerce and digital platforms with payment functions (e.g., platforms that process buyer payments via e-wallets, bank transfers, cards, or cash-on-delivery); and Other digital-economy players that enable e-commerce transactions, including (i) intermediary service platforms connecting service providers with consumers, (ii) digital content platforms, (iii) online advertising providers, (iv) cloud computing and data storage providers, (v) social media platforms engaged in business activities (e.g., live-stream, in-app transactions), (vi) online education, gaming, and digital entertainment platforms generating revenue from digital transactions, (vii) Vietnam-based partners of foreign digital service providers facilitating local payments for overseas platforms, and (viii) intermediary payment service providers handling financial transactions for e-commerce activities. Under the Draft Decree, Regulated Operators will be required to track, report, and enforce tax compliance for both resident and nonresident individuals and households conducting business through their platforms (“Sellers”). What New Tax Obligations Do Platforms Face? Onshore platforms For the first time, Regulated Operators will
March 10, 2025
Thailand’s Securities and Exchange Commission (SEC) will officially add USD Coin (USDC) and Tether (USDT) to its list of approved cryptocurrencies for use in digital asset transactions on March 16, 2025. The addition is a significant move that expands Thailand’s digital asset market, aiming to enhance market flexibility and provide more payment options for investors and traders in Thailand’s digital asset ecosystem. Under the SEC regulations, digital asset operators, including digital token issuers, ICO portals, and digital asset exchanges, are only permitted to accept, conduct transactions with, and use “approved cryptocurrencies” as trading pairs. After the addition of USDC and USDT, the full list of approved cryptocurrencies will include: Bitcoin (BTC) Ethereum (ETH) Ripple (XRP) Stellar (XLM) Tether (USDT) USD Coin (USDC) Other cryptocurrencies used for testing programmable payments under the enhanced regulatory sandbox in accordance with the Bank of Thailand’s rules and conditions. For more information on these new additions, or on any aspect of digital assets and cryptocurrency in Thailand, please contact Kobkit Thienpreecha at [email protected], Pornpan Wichawut at [email protected], Napassorn Lertussavavivat at [email protected], or Rujaporn Paritsantik at [email protected].