You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 19, 2025

Thailand Drafts AI Risk Management Guidelines for Financial Service Providers

The Bank of Thailand (BOT) has released draft guidelines establishing principles for managing artificial intelligence (AI) risks in the financial sector. The draft guidelines provide a structured framework for the responsible adoption of AI technologies. Financial service providers will be able to use the guidelines as a reference to appropriately manage their risks in a manner that aligns with internationally recognized best practices.

The BOT is accepting public comments on the draft guidelines until June 30, 2025.

Scope and Application

The draft guidelines apply to all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. These guidelines supplement existing BOT risk management guidelines covering IT risk management, third-party risk management, data governance, and market conduct.

The guidelines define AI systems as systems that mimic human intelligence, including machine learning, deep learning, generative AI (such as large language models), and agentic AI. This definition specifically excludes rule-based automation systems like robotic process automation and condition matching.

Key Risk Management Principles

The guidelines lay out two main principles in managing AI risk.

  1. Governance: Financial service providers should define and establish clear roles and responsibilities for their personnel and AI system supervision structures to uphold FEAT (fairness, ethics, accountability, and transparency) principles as follows:
    • Stakeholder roles and responsibilities. Financial service providers should define roles and responsibilities for boards and executives on AI risk oversight. Responsibilities include establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization.
    • AI system usage policy. The AI system usage policy should be aligned with organizational objectives, regulatory requirements, and FEAT principles. These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles.
    • Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. When AI systems are used in strategic functions or customer interactions (e.g., loan approval, account opening), human oversight must be integrated into decision-making processes. In customer interactions with AI systems, customers should be notified and have options to disable or bypass AI features.
  1. Development and security controls: Financial service providers should have risk controls covering the AI development and deployment lifecycle as follows:
    • Data risk. Financial service providers should have measures to assess and ensure the quality, accuracy, currency, volume, and diversity of data used in AI model training. They should also implement data leakage prevention measures.
    • Model development risk. Financial service providers should have (1) clear evaluation metrics for assessing model accuracy and reliability through ongoing testing and monitoring both before and after deployment and (2) measures to ensure the explainability of AI outcomes. For generative AI applications, there should be specific measures to reduce AI hallucination risks.
    • Cybersecurity risk. Financial service providers should have measures to prevent and detect emerging cyber threats targeting AI systems, based on established standards such as the OWASP Machine Learning Security Top 10.

For more details on any aspect of fintech, technology, and cybersecurity in Thailand, please contact Athistha Chitranukroh at [email protected], Nopparat Lalitkomon at [email protected], Pornpan Wichawut at [email protected], Napassorn Lertussavavivat at [email protected], or Rujaporn Paritsantik at [email protected].

RELATED INSIGHTS​ 

November 14, 2024
In recent years, Thailand has taken significant steps to regulate and integrate digital assets into its financial ecosystem. This article explores the regulatory framework governing digital asset businesses in Thailand, focusing on the key legislation, regulated activities, and recent developments in this rapidly evolving sector. Regulatory Environment In 2018, Thailand enacted the Emergency Decree on Digital Asset Businesses, marking a pivotal moment in the country’s approach to cryptocurrencies and digital tokens. This decree, supervised by the Securities and Exchange Commission (SEC) and the Ministry of Finance, provides a comprehensive regulatory framework for both the primary and secondary markets of digital assets. For the primary market, the decree regulates the issuance and sale of digital assets through initial coin offerings (ICOs). A key feature of this regulation is the requirement for ICOs to be conducted through SEC-approved ICO portals. This approach aims to provide a structured and supervised environment for companies seeking to raise funds through digital token sales. In the secondary market, the decree outlines the regulatory framework for various digital asset intermediaries, including digital asset exchanges, brokers, dealers, advisory services, fund managers, and custodians. In implementing its digital asset-related policies, the SEC imposes ongoing obligations on licensed digital asset intermediaries. These include restrictions on the listing of certain digital assets on digital asset exchanges, and limitations on intermediaries facilitating digital assets as a means of payment. Regulatory Trends and Outlook The SEC has demonstrated a commitment to regularly revising its digital asset regulations to keep pace with global trends and market developments. A notable example of this approach is the SEC’s efforts to refine the classification of nonregulated ready-to-use utility tokens by dividing these tokens into two groups: Group 1: Ready-to-use utility tokens issued for consumption purposes or as a digital representation of a certificate (e.g., NFTs with
November 13, 2024
Thailand’s Electronic Transactions Committee has publicized a new draft notification detailing additional duties for specific marketplace digital platform service operators under Section 18(2) of the Royal Decree on Operation of Digital Platform Service Businesses Subject to Prior Notification B.E. 2565 (2022). The draft notification, which is open for public comments until November 30, 2024, aims to provide enhanced protection for users of “specific marketplace platforms” (defined below). Some key points of the draft notification are detailed below. Scope The draft notification applies to “marketplace digital platform services,” which refers to digital platform services that serve as an intermediary for buying or exchanging goods and provide services to facilitate sale transactions, such as providing communication systems (e.g., chat features), shopping carts, delivery arrangements, and supplemental payment processing facilitation. “Specific marketplace platforms” refers to Section 18(2) of the Royal Decree on Digital Platform Services, which covers digital platform services that pose risks to financial and commercial security, the reliability and credibility of data messaging systems, or potential harm to the public, and that have a high level of potential impact based on the criteria for assessing the impact of digital platform service operations. Key Obligations Registration. The draft notification requires the marketplace operators mentioned above to be registered as legal entities in Thailand. Terms and conditions. The draft notification details additional obligations relating to marketplace operators’ terms and conditions: In addition to existing obligations prescribed in the Royal Decree and the relevant subordinate laws, the draft notification emphasizes that the terms and conditions must be in Thai, clear, accessible, and understandable, and may include graphical elements to aid explanation. The terms and conditions must prescribe conditions relating to the sale of products subject to specific standards, such as those restricted under the Food Act, the Drugs Act, and the Industrial Product
November 11, 2024
The Vietnamese government has demonstrated a strong commitment to building a digital government, digital economy, and digital society through its recently issued national strategy on digital infrastructure. Under Decision No. 1132/QD-TTg dated October 19, 2024, on “Digital Infrastructure Strategy to 2025 with Orientation to 2030,” the government will create supportive conditions for both domestic and international businesses to invest in digital infrastructure with cybersecurity as a priority. Recognized as vital to the economy, this digital infrastructure will consist of four main components: (i) telecommunications and internet infrastructure, (ii) data infrastructure, (iii) physical-digital infrastructure, and (iv) digital utility infrastructure, including digital technology as a service. Key goals for 2025 include universal fiber optic access for households, 100% 5G coverage across all provinces and cities, deployment of at least two new international undersea fiber optic cables, establishment of AI data centers, development of green-standard data centers, and platforms for IoT, AI, big data, blockchain, and cybersecurity. By 2030, goals include fiber access with speeds of at least 1 Gbps, 5G coverage for 99% of the population, readiness for 6G trials, six additional international undersea fiber optic cables, development of a hyperscale data center, and positioning Vietnam as a digital hub. To achieve these goals, the government has outlined some core tasks, creating significant opportunities for both foreign and domestic investors: Developing telecommunications and internet infrastructure for widespread fiber optic and 5G access, while preparing for emerging technologies like 6G, Open RAN, satellite, and IpV6. Telecommunication enterprises will jointly invest in and share the use of international fiber optic cable routes to ensure efficient capacity utilization and optimize investment capital. Attracting foreign and domestic investment to establish hyperscale data centers and cloud computing services that meet global standards. Creating physical-digital infrastructure by integrating technology across key sectors such as transportation, energy, healthcare,
November 8, 2024
On October 31, 2024, Thailand’s Office of the Personal Data Protection Committee (PDPC) opened a public consultation period on its draft notifications—one directed at data controllers and another at data processors—regarding exemptions from the requirement to create and maintain records of processing activities (ROPAs) under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The draft notification for data controllers aims to amend and revoke certain aspects of the first ROPA exemption notification issued in June 2022 and outlines the criteria for data controllers to be exempted from the obligation to prepare and maintain such records. Although it is officially titled “Notification of the Personal Data Protection Committee on Exemption from Record-Keeping Requirements for Small Business Data Controllers,” this draft notification applies to all types of exempted data controllers (see list below), and not only small businesses. The draft notification for data processors is new and does not replace any prior notification. The criteria under both draft notifications exempt certain data controllers and data processors from the obligation to maintain ROPAs, but exempted data controllers are not free from the obligation to retain information on the rejection of data subjects’ requests to exercise certain rights under the PDPA. While these criteria remain consistent with the June 2022 ROPA exemption notification, there are a few key takeaways from the notifications, as detailed below. Types of Exempted Parties The draft notification on data controllers adds condominium and housing estate juristic persons, as well as individuals, to the list of parties eligible for an exemption, while removing internet cafes from the list. The new draft notification for data processors mirrors the corresponding list in the draft notification for data controllers. The complete list of parties eligible for ROPA exemptions under the draft notifications is as follows: SMEs according to the law on