You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 19, 2025

Thailand Drafts AI Risk Management Guidelines for Financial Service Providers

The Bank of Thailand (BOT) has released draft guidelines establishing principles for managing artificial intelligence (AI) risks in the financial sector. The draft guidelines provide a structured framework for the responsible adoption of AI technologies. Financial service providers will be able to use the guidelines as a reference to appropriately manage their risks in a manner that aligns with internationally recognized best practices.

The BOT is accepting public comments on the draft guidelines until June 30, 2025.

Scope and Application

The draft guidelines apply to all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. These guidelines supplement existing BOT risk management guidelines covering IT risk management, third-party risk management, data governance, and market conduct.

The guidelines define AI systems as systems that mimic human intelligence, including machine learning, deep learning, generative AI (such as large language models), and agentic AI. This definition specifically excludes rule-based automation systems like robotic process automation and condition matching.

Key Risk Management Principles

The guidelines lay out two main principles in managing AI risk.

  1. Governance: Financial service providers should define and establish clear roles and responsibilities for their personnel and AI system supervision structures to uphold FEAT (fairness, ethics, accountability, and transparency) principles as follows:
    • Stakeholder roles and responsibilities. Financial service providers should define roles and responsibilities for boards and executives on AI risk oversight. Responsibilities include establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization.
    • AI system usage policy. The AI system usage policy should be aligned with organizational objectives, regulatory requirements, and FEAT principles. These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles.
    • Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. When AI systems are used in strategic functions or customer interactions (e.g., loan approval, account opening), human oversight must be integrated into decision-making processes. In customer interactions with AI systems, customers should be notified and have options to disable or bypass AI features.
  1. Development and security controls: Financial service providers should have risk controls covering the AI development and deployment lifecycle as follows:
    • Data risk. Financial service providers should have measures to assess and ensure the quality, accuracy, currency, volume, and diversity of data used in AI model training. They should also implement data leakage prevention measures.
    • Model development risk. Financial service providers should have (1) clear evaluation metrics for assessing model accuracy and reliability through ongoing testing and monitoring both before and after deployment and (2) measures to ensure the explainability of AI outcomes. For generative AI applications, there should be specific measures to reduce AI hallucination risks.
    • Cybersecurity risk. Financial service providers should have measures to prevent and detect emerging cyber threats targeting AI systems, based on established standards such as the OWASP Machine Learning Security Top 10.

For more details on any aspect of fintech, technology, and cybersecurity in Thailand, please contact Athistha Chitranukroh at [email protected], Nopparat Lalitkomon at [email protected], Pornpan Wichawut at [email protected], Napassorn Lertussavavivat at [email protected], or Rujaporn Paritsantik at [email protected].

RELATED INSIGHTS​ 

January 30, 2024
Thailand has made its draft Platform Economy Act (the “Draft PEA”) available to relevant entities in certain industries. The Draft PEA aims to regulate and standardize digital platform service business operations and protect consumers and other stakeholders. Once the Draft PEA becomes law, the Royal Decree on the Operation of Digital Platform Service Businesses that are subject to Prior Notification B.E. 2565 (2022) and the relevant provisions under the Electronic Transactions Act B.E. 2544 (2001), as amended, will cease to have effect. The key provisions of the Draft PEA are summarized below. Definitions The definitions of the key terms under the Draft PEA are substantially similar to the definitions of the key terms under the royal decree mentioned above. According to the Draft PEA, “digital platform services” refers to the provision of electronic intermediary services that manage data to facilitate connection, through computer networks, between business users, consumers, or users, regardless of whether remuneration is charged. Exemption The Draft PEA does not apply to digital platform services (DPSs) that are regulated by specific laws and have rules guaranteeing transparency and fairness, or that follow operational standards no less stringent than those required in the Draft PEA. Nonetheless, the Electronic Transactions Development Agency (ETDA) can request or link data relating to exempted DPSs from the relevant supervisory authorities. Extraterritorial Effect Offshore DPSs with certain characteristics are also subject to the obligations under the Draft PEA and will have to appoint a coordinating person in Thailand. However, offshore DPSs will not have to establish a business in Thailand. General Responsibilities and Obligations The Draft PEA sets out the following requirements: DPSs with (1) at least THB 100 million (approx. USD 2.8 million) in annual revenue from providing the DPSs in Thailand before deducting expenses, or (2) more than 10,000 monthly users
January 24, 2024
On 17 April 2023, the Vietnamese government issued the Personal Data Protection Decree, which is set to take effect 1 July 2023 without any transitional period. The PDPD is considered to be the first comprehensive document on data protection in Vietnam. Accordingly, it provides detailed regulations on the rights of data subjects, consent requirements and requirements for data processing impact assessments and outbound transfer impact assessments. In 2024, the adoption of the Law on the Protection of Consumer Rights and the Law on Electronic Transactions will play a vital role regarding data protection. The LPCR will require traders to obtain consent to collect consumer data and establish a mechanism enabling consumers to select the information they consent to traders collecting. Consumers must also be allowed to express consent in a suitable form. For special processing purposes — such as sharing, disclosure, or transfer of personal data to third parties, and use of personal data to send advertisements and to introduce products — the LPCR requires a mechanism which enables data subjects to clearly opt in to give, or not give, their consent. This requirement is similar to procedures currently required for regulated stakeholders under the PDPD. In the same vein, the LET strictly forbids the acts of trading data to protect Vietnamese personal data. The government is anticipated to provide more details relating to data privacy guidelines after the issuance of the Draft Law on Telecommunications. Accordingly, the draft requires enterprises to provide the requisite information — such as service user’s name and address, number and location of transmitting or receiving servers, call times, IP address and other personal information supplied by the service user when entering a contract — to the relevant authority, as per a request which is made in accordance with the law. Amendments to Decree
January 24, 2024
Thailand’s Personal Data Protection Act came into full effect on 1 June 2022 and various subordinate regulations have since been issued by the Personal Data Protection Committee. These include regulations on security measures to be implemented by data controllers, data breach notification requirements, a mandatory obligation to appoint a data protection officer when the processing activity requires regular monitoring of personal data or a system due to the large scale of personal data, administrative measures and data processors’ record of processing activities. As some areas under the PDPA still require further clarifications, a series of public consultations for the remaining draft subordinate regulations is anticipated in 2024. Potential areas include data protection impact assessments and cross-border transfers of personal data, which are crucial for organizations and particularly for entities with establishments in other jurisdictions. PDPA enforcement by Thai regulators was silent until the last quarter of 2023, when the PDPC published details about complaints that have been lodged to the Expert Committee. The committee is designated by virtue of the PDPA and has the power to make determinations related to imposing administrative fines and other penalties. Enforcement in 2024 is expected to become more active and potentially more serious, which means organizations should pay closer attention to ensure compliance with the PDPA. Similar to the GDPR, the PDPA also has extraterritorial effect. Once the subordinate regulation on international cooperation has been issued by the PDPC, this should clarify how PDPA enforcement against organizations located outside of Thailand will be conducted by Thai regulators. With respect to sector-specific data protection legislation, in September 2023, Thailand’s National Broadcasting and Telecommunications Commission issued the Notification of the NBTC Re: Measures to Protect Telecommunications Service Users’ Rights in regard to Personal Data, Privacy Rights, and Freedom of Telecommunications, which replaces the previous notification.
January 23, 2024
The Bank of Thailand (BOT) has issued a new notification to sustainably address Thailand’s household debt problems by establishing responsible and fair lending requirements for lending service providers throughout their lending journey. Notification No. SorKorChor. 7/2566 Re: Provision of Responsible and Fair Lending was announced on December 21, 2023, and took effect on January 1, 2024. The lending service providers this notification applies to include both commercial banks and nonbank business operators (e.g., personal loan business operators, nano-financing business operators, and credit card business operators). The key principle of this notification is to provide criteria for responsible and fair lending that supplement market conduct principles, covering eight areas in the debt cycle: Lending product development. Service providers must offer lending products that are suitable to customers’ needs and repayment capabilities, avoiding encouragement of excessive debt. Loan interest rates should align with the borrower’s risk profile and credit characteristics (risk-based pricing) to ensure fair contract conditions. Advertising. Service providers must prepare and control advertisements with “correct and clear” content, presenting complete and comparable conditions, interest rates, and various fees to customers. The advertisements should not encourage excessive debt, enabling customers to make informed decisions and promoting financial discipline. Sales. In the selling process, service providers must ensure that customers receive complete, accurate, and unexaggerated information that facilitates appropriate consideration of decisions based on a correct understanding of the product or service. Products should also align with customers’ purposes or needs for fund utilization, avoiding encouragement of excessive debt. Consideration of debt repayment ability (affordability). Service providers must be conscientious in considering customers’ debt repayment ability, taking into account all obligations and residual income. Promotion of discipline and financial management. Service providers must provide important information and warnings to debtors, including regular reminders to promote responsible borrowing. Helping debtors with persistent debt.