You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 19, 2025

Thailand Drafts AI Risk Management Guidelines for Financial Service Providers

The Bank of Thailand (BOT) has released draft guidelines establishing principles for managing artificial intelligence (AI) risks in the financial sector. The draft guidelines provide a structured framework for the responsible adoption of AI technologies. Financial service providers will be able to use the guidelines as a reference to appropriately manage their risks in a manner that aligns with internationally recognized best practices.

The BOT is accepting public comments on the draft guidelines until June 30, 2025.

Scope and Application

The draft guidelines apply to all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. These guidelines supplement existing BOT risk management guidelines covering IT risk management, third-party risk management, data governance, and market conduct.

The guidelines define AI systems as systems that mimic human intelligence, including machine learning, deep learning, generative AI (such as large language models), and agentic AI. This definition specifically excludes rule-based automation systems like robotic process automation and condition matching.

Key Risk Management Principles

The guidelines lay out two main principles in managing AI risk.

  1. Governance: Financial service providers should define and establish clear roles and responsibilities for their personnel and AI system supervision structures to uphold FEAT (fairness, ethics, accountability, and transparency) principles as follows:
    • Stakeholder roles and responsibilities. Financial service providers should define roles and responsibilities for boards and executives on AI risk oversight. Responsibilities include establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization.
    • AI system usage policy. The AI system usage policy should be aligned with organizational objectives, regulatory requirements, and FEAT principles. These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles.
    • Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. When AI systems are used in strategic functions or customer interactions (e.g., loan approval, account opening), human oversight must be integrated into decision-making processes. In customer interactions with AI systems, customers should be notified and have options to disable or bypass AI features.
  1. Development and security controls: Financial service providers should have risk controls covering the AI development and deployment lifecycle as follows:
    • Data risk. Financial service providers should have measures to assess and ensure the quality, accuracy, currency, volume, and diversity of data used in AI model training. They should also implement data leakage prevention measures.
    • Model development risk. Financial service providers should have (1) clear evaluation metrics for assessing model accuracy and reliability through ongoing testing and monitoring both before and after deployment and (2) measures to ensure the explainability of AI outcomes. For generative AI applications, there should be specific measures to reduce AI hallucination risks.
    • Cybersecurity risk. Financial service providers should have measures to prevent and detect emerging cyber threats targeting AI systems, based on established standards such as the OWASP Machine Learning Security Top 10.

For more details on any aspect of fintech, technology, and cybersecurity in Thailand, please contact Athistha Chitranukroh at [email protected], Nopparat Lalitkomon at [email protected], Pornpan Wichawut at [email protected], Napassorn Lertussavavivat at [email protected], or Rujaporn Paritsantik at [email protected].

RELATED INSIGHTS​ 

November 8, 2024
On October 31, 2024, Thailand’s Office of the Personal Data Protection Committee (PDPC) opened a public consultation period on its draft notifications—one directed at data controllers and another at data processors—regarding exemptions from the requirement to create and maintain records of processing activities (ROPAs) under the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The draft notification for data controllers aims to amend and revoke certain aspects of the first ROPA exemption notification issued in June 2022 and outlines the criteria for data controllers to be exempted from the obligation to prepare and maintain such records. Although it is officially titled “Notification of the Personal Data Protection Committee on Exemption from Record-Keeping Requirements for Small Business Data Controllers,” this draft notification applies to all types of exempted data controllers (see list below), and not only small businesses. The draft notification for data processors is new and does not replace any prior notification. The criteria under both draft notifications exempt certain data controllers and data processors from the obligation to maintain ROPAs, but exempted data controllers are not free from the obligation to retain information on the rejection of data subjects’ requests to exercise certain rights under the PDPA. While these criteria remain consistent with the June 2022 ROPA exemption notification, there are a few key takeaways from the notifications, as detailed below. Types of Exempted Parties The draft notification on data controllers adds condominium and housing estate juristic persons, as well as individuals, to the list of parties eligible for an exemption, while removing internet cafes from the list. The new draft notification for data processors mirrors the corresponding list in the draft notification for data controllers. The complete list of parties eligible for ROPA exemptions under the draft notifications is as follows: SMEs according to the law on
November 4, 2024
Crowdfunding has emerged as a promising option for raising capital, particularly for startups and small businesses. In Thailand, investment-based crowdfunding falls primarily under the regulatory purview of the Securities and Exchange Commission (SEC). The SEC is responsible for licensing and overseeing crowdfunding portals, ensuring compliance with regulatory requirements while ensuring investor protection and market integrity. The crowdfunding regulations in Thailand allow non-publicly traded companies to raise funds by offering equity and debentures for sale through SEC-licensed crowdfunding portals. This framework opens new possibilities for businesses seeking alternative funding sources and for investors looking for new opportunities.  Crowdfunding Portals Under Thai regulations, “crowdfunding portals” are defined as websites, mobile phone applications, or other similar electronic media developed for offering securities for sale. To operate a crowdfunding portal in Thailand, applicants must meet several key requirements: Incorporation: The applicant must be incorporated in Thailand. This requirement ensures that the portal operator has a significant local presence and is subject to Thai law. Minimum capital: A minimum paid-up registered capital of THB 5 million is required. This capital requirement helps ensure that portal operators have sufficient financial resources to maintain their operations. Operational readiness: The applicant must have crowdfunding portal systems ready for use upon applying to the SEC for approval to operate. This requirement demonstrates the applicant’s technical capability and readiness to provide crowdfunding services. These requirements are designed to ensure that crowdfunding portal operators are well-capitalized, technologically prepared, and committed to operating within the Thai market. Business and Investment Implications The regulatory framework for crowdfunding in Thailand offers non-publicly traded companies with an additional avenue for raising funds, as licensed crowdfunding portals provide a structured and regulated environment for fundraising. However, companies must ensure compliance with SEC regulations when offering securities through these platforms. For investors, crowdfunding offers new investment
October 21, 2024
One key component of Thailand’s support for the development of fintech innovations is its sandbox framework, supervised by the Bank of Thailand (BOT). This framework supports business operators in experimenting with new technologies under controlled conditions. This article explores the structure and significance of the BOT’s sandbox program in driving fintech innovation in Thailand. The BOT Sandbox Framework In June 2024, the BOT updated its sandbox framework to provide a more comprehensive and flexible environment for testing fintech innovations. The framework allows participants to experiment with their ideas in a controlled and limited environment, balancing the need for innovation with the imperative of maintaining financial stability and consumer protection. Three Types of Sandboxes The BOT’s framework encompasses three distinct types of sandboxes: the Regulatory Sandbox, the Own Sandbox, and the Enhanced Regulatory Sandbox. Regulatory Sandbox The Regulatory Sandbox is a mandatory testing ground for certain BOT-licensed financial services to ensure that potentially impactful innovations are tested and evaluated before wide-scale implementation. Participation in this sandbox is a prerequisite for: License applications for specific financial services. Implementation of new technologies or innovations in existing licensed services. Financial services that have the potential to become a structural element or standard of the Thai financial sector. A prime example of a service requiring participation in the Regulatory Sandbox is the Thai QR code payment via PromptPay system, which involved various banks several years ago until the Bank of Thailand granted permission for these services to be provided to the general public. Own Sandbox The Own Sandbox is an optional program that the BOT encourages for financial service providers and fintech operators implementing new technologies. This sandbox provides a more flexible environment for testing innovations that may not require the same level of regulatory scrutiny as those in the Regulatory Sandbox. Enhanced Regulatory
October 20, 2024
Following the U.S. Securities and Exchange Commission’s approval of spot Bitcoin ETFs, Thailand’s Securities and Exchange Commission (SEC) is reassessing regulations on the investments of mutual funds and private funds (collectively “Funds”). The SEC has launched a public consultation on new draft notifications introducing  the new asset classes that can be held by Funds, and aims to bring these rules into effect on January 1, 2025. The highlights of these changes are set out below. Eligible New Asset Classes The new asset classes that can be held by Funds can be categorized into two types—investment tokens and crypto assets—and the determination will focus on substance over form. Investment tokens: If the substance involves raising funds, regardless of what the assets are called, and they are legally issued and offered or approved by home regulators that are members of the International Organization of Securities Commissions (IOSCO), Funds can invest in these types of assets as transferable securities within the permitted ratio. Crypto assets: The eligible crypto assets which Funds are entitled to hold focus on crypto ETFs or offshore funds investing in crypto assets, and they are subject to investment limits. Funds can hold crypto assets directly, but only temporarily, and only for the purpose of purchasing, selling, or exchanging the crypto assets, not speculative purposes. The notifications state that Funds may hold Bitcoin/Ethereum for no longer than five business days and USDT/USDC for no more than one month. Investment Limits Typically, the rules segregate investment limits into listed and non-listed digital assets, and the limits depend on the sophistication of the investors in the Funds. In general, UI Funds (mutual funds offered to institutional investors or ultra-high net worth investors) can invest in these new asset classes without any limitations, although net exposure to other crypto assets  –  which