You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 19, 2025

Thailand Drafts AI Risk Management Guidelines for Financial Service Providers

The Bank of Thailand (BOT) has released draft guidelines establishing principles for managing artificial intelligence (AI) risks in the financial sector. The draft guidelines provide a structured framework for the responsible adoption of AI technologies. Financial service providers will be able to use the guidelines as a reference to appropriately manage their risks in a manner that aligns with internationally recognized best practices.

The BOT is accepting public comments on the draft guidelines until June 30, 2025.

Scope and Application

The draft guidelines apply to all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. These guidelines supplement existing BOT risk management guidelines covering IT risk management, third-party risk management, data governance, and market conduct.

The guidelines define AI systems as systems that mimic human intelligence, including machine learning, deep learning, generative AI (such as large language models), and agentic AI. This definition specifically excludes rule-based automation systems like robotic process automation and condition matching.

Key Risk Management Principles

The guidelines lay out two main principles in managing AI risk.

  1. Governance: Financial service providers should define and establish clear roles and responsibilities for their personnel and AI system supervision structures to uphold FEAT (fairness, ethics, accountability, and transparency) principles as follows:
    • Stakeholder roles and responsibilities. Financial service providers should define roles and responsibilities for boards and executives on AI risk oversight. Responsibilities include establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization.
    • AI system usage policy. The AI system usage policy should be aligned with organizational objectives, regulatory requirements, and FEAT principles. These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles.
    • Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. When AI systems are used in strategic functions or customer interactions (e.g., loan approval, account opening), human oversight must be integrated into decision-making processes. In customer interactions with AI systems, customers should be notified and have options to disable or bypass AI features.
  1. Development and security controls: Financial service providers should have risk controls covering the AI development and deployment lifecycle as follows:
    • Data risk. Financial service providers should have measures to assess and ensure the quality, accuracy, currency, volume, and diversity of data used in AI model training. They should also implement data leakage prevention measures.
    • Model development risk. Financial service providers should have (1) clear evaluation metrics for assessing model accuracy and reliability through ongoing testing and monitoring both before and after deployment and (2) measures to ensure the explainability of AI outcomes. For generative AI applications, there should be specific measures to reduce AI hallucination risks.
    • Cybersecurity risk. Financial service providers should have measures to prevent and detect emerging cyber threats targeting AI systems, based on established standards such as the OWASP Machine Learning Security Top 10.

For more details on any aspect of fintech, technology, and cybersecurity in Thailand, please contact Athistha Chitranukroh at [email protected], Nopparat Lalitkomon at [email protected], Pornpan Wichawut at [email protected], Napassorn Lertussavavivat at [email protected], or Rujaporn Paritsantik at [email protected].

RELATED INSIGHTS​ 

February 28, 2023
Influencer marketing and the creation of sponsored content is an increasingly popular way for brands to reach their target audience. Although there is no universal definition of an “influencer,” the term is broadly used to describe people who are able to affect purchasing decisions of others through their relationship with their audience. In the context of social media and the creator economy, influencers are usually people with significant followings on platforms such as Instagram, TikTok, Twitch, or YouTube who are viewed as celebrities, opinion leaders, trendsetters, or experts in their respective field. Based on a study conducted by Nielsen in 2022, 80% of social media users in Asia who follow influencers are likely to purchase products recommended by the influencers. Brand owners should be aware of five key legal considerations when entering into influencer marketing agreements. 1. Making informed decisions through due diligence Every collaboration with an influencer is a business relationship. Brands must conduct thorough due diligence on potential influencers prior to engaging them. This may include deep dives into the individual’s old social media posts, as well as requests for disclosure of prior controversial incidents and existing brand associations. For example, a health and fitness brand may not want—for both legal and commercial reasons—to be publicly associated with an influencer who is a brand ambassador of electronic cigarettes, no matter how impressive the latter’s Instagram following or deadlift record is. Brands should also ensure that their influencer marketing agreements include relevant representations and warranties that the influencer has not and will not commit a crime or act in a way that may cause negative publicity for the brand. This may include racist, extremist, homophobic, violent, or misogynistic acts, or any other acts that are obscene or against public order. 2. Clearly defining the scope of engagement Brands
February 26, 2023
Vietnam’s Ministry of Information and Communications (MIC) has been working to replace the outdated 2009 Telecom Law with a new version more suited to today’s digital economy. A draft Telecom Law was made available for public consultation from October 27 to December 27, 2022. On January 17, 2023, the MIC submitted an amended draft (the “Draft”) to the Ministry of Justice for appraisal (the Vietnamese version of the Draft and accompanying documents in the dossier can be accessed here). The Draft is scheduled to be discussed by the National Assembly in May 2023 and submitted for approval in October 2023. The key content and changes of the Draft as compared to the existing law are set out below. 1. Licensing Telecom Services For domestic enterprises, the 2009 Telecom Law only provides two types of licenses—telecom network establishment licenses and telecom service business licenses—without differentiating the conditions and licensing procedures for various types of telecom services. This no longer meets management requirements and does not encourage enterprises to participate in providing new services on already existing infrastructure. Although the Draft retains the two main types of licenses—licenses to provide telecom services with network establishment for a term of not more than 15 years; and licenses to provide telecom services without network establishment with a term of no more than 10 years—it also provides different licensing conditions for different types of telecom service provision, with three kinds of licensing: (i) individual licenses for certain enterprises with specific conditions and obligations based on telecom management objectives at the time of licensing; (ii) class licenses for businesses that meet the prescribed licensing conditions; and (iii) registration, which requires businesses only to submit registration information according to the prescribed form to be licensed. In addition, to avoid the situation of licensed telecom network enterprises
February 24, 2023
Noppparat Lalitkomon, head of Tilleke & Gibbins’ data protection team in Thailand, has prepared the Thailand contribution for the Data Privacy Trends and Topics Report, published by Lex Mundi. The report provides brief overviews of recent and upcoming regulatory and legal developments concerning data privacy in the jurisdictions of Lex Mundi member firms in 53 jurisdictions around the world. Drawing on the expertise of Lex Mundi member firms from around the world, the report features local insights to help businesses handle cross-border data and cybersecurity challenges. Lex Mundi has also compiled a global overview of how firms in each region assess the likelihood of significant changes to the data protection landscape in 2023. Notably, Asia and the Pacific is identified as the region most likely to undergo changes, with 73% of reporting firms expecting significant developments in their jurisdictions. The report containing all 53 contributions—grouped by world region—is available on the Lex Mundi website or through the button below.
February 16, 2023
Thailand has issued a Royal Decree on the Supervision of Regulated Digital Identification Authentication and Verification Service Businesses B.E. 2565 (2022) (the “Royal Decree”), aimed at regulating business operators that provide digital identification authentication and verification services (“Digital ID Services”). The Royal Decree was published in the Government Gazette in December 2022, and will take effect 180 days from the publication date, i.e., on June 21, 2023. The key details and requirements of the Royal Decree are as follows: Regulated Digital ID Services Under the Royal Decree, the provision of the following Digital ID Services requires prior approval from the Electronic Transaction Development Agency: Identity verification service – Services for collecting and identifying information relating to the identity of a person, and verifying the connections between the person and the identity. Authenticator issuance and management service – Services relating to the connection between a person who has passed the identification process with an authenticator, and managing actions which are used to identify a person. Authentication service – A process to authenticate a person by inspecting his/her authenticator. Digital ID networks/systems – Provision of networks or systems used to exchange information for digital identification purposes, excluding services provided by an intermediary. Exempted Digital ID Services The Royal Decree also specifies a list of Digital ID Services that are exempted from supervision under the Royal Decree, as follows: Issuance of certificates to support the use of electronic signatures in accordance with the Electronic Transaction Act. Digital ID Services conducted for use within the operator’s own business only, and which do not involve the provision of such services to third parties. Other Digital ID Services as prescribed by the Electronic Transaction Committee. Qualifications of Business Operators The types of business operators qualified to operate Digital ID Services include (i) private limited companies;