You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 19, 2025

Thailand Drafts AI Risk Management Guidelines for Financial Service Providers

The Bank of Thailand (BOT) has released draft guidelines establishing principles for managing artificial intelligence (AI) risks in the financial sector. The draft guidelines provide a structured framework for the responsible adoption of AI technologies. Financial service providers will be able to use the guidelines as a reference to appropriately manage their risks in a manner that aligns with internationally recognized best practices.

The BOT is accepting public comments on the draft guidelines until June 30, 2025.

Scope and Application

The draft guidelines apply to all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. These guidelines supplement existing BOT risk management guidelines covering IT risk management, third-party risk management, data governance, and market conduct.

The guidelines define AI systems as systems that mimic human intelligence, including machine learning, deep learning, generative AI (such as large language models), and agentic AI. This definition specifically excludes rule-based automation systems like robotic process automation and condition matching.

Key Risk Management Principles

The guidelines lay out two main principles in managing AI risk.

  1. Governance: Financial service providers should define and establish clear roles and responsibilities for their personnel and AI system supervision structures to uphold FEAT (fairness, ethics, accountability, and transparency) principles as follows:
    • Stakeholder roles and responsibilities. Financial service providers should define roles and responsibilities for boards and executives on AI risk oversight. Responsibilities include establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization.
    • AI system usage policy. The AI system usage policy should be aligned with organizational objectives, regulatory requirements, and FEAT principles. These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles.
    • Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. When AI systems are used in strategic functions or customer interactions (e.g., loan approval, account opening), human oversight must be integrated into decision-making processes. In customer interactions with AI systems, customers should be notified and have options to disable or bypass AI features.
  1. Development and security controls: Financial service providers should have risk controls covering the AI development and deployment lifecycle as follows:
    • Data risk. Financial service providers should have measures to assess and ensure the quality, accuracy, currency, volume, and diversity of data used in AI model training. They should also implement data leakage prevention measures.
    • Model development risk. Financial service providers should have (1) clear evaluation metrics for assessing model accuracy and reliability through ongoing testing and monitoring both before and after deployment and (2) measures to ensure the explainability of AI outcomes. For generative AI applications, there should be specific measures to reduce AI hallucination risks.
    • Cybersecurity risk. Financial service providers should have measures to prevent and detect emerging cyber threats targeting AI systems, based on established standards such as the OWASP Machine Learning Security Top 10.

For more details on any aspect of fintech, technology, and cybersecurity in Thailand, please contact Athistha Chitranukroh at [email protected], Nopparat Lalitkomon at [email protected], Pornpan Wichawut at [email protected], Napassorn Lertussavavivat at [email protected], or Rujaporn Paritsantik at [email protected].

RELATED INSIGHTS​ 

July 31, 2022
Thailand’s Securities and Exchange Commission (SEC) has announced three new regulatory requirements, which primarily require digital asset business operators to provide investors with training or a knowledge test on cryptocurrencies and to disclose information about the quality of their service and IT usage capacity. The amended SEC notification detailing these new obligations was promulgated on July 1, 2022; however, the measures come into effect separately, as detailed below. Training or Testing on Cryptocurrency From August 30, 2022, cryptocurrency exchanges, brokers, and dealers must provide guidance and education to their clients on basic asset allocation suitable to their capacity. These types of digital asset business operators must also provide for training or a knowledge test on cryptocurrency. The content should at least cover cryptocurrency, blockchain technology, digital wallets, and an overview of the market and investments. The following types of clients are exempted from these requirements: Existing clients of the digital asset business operators before July 1, 2022; New clients of the operator who already have experience investing in cryptocurrency before using the service of the business operator; and Institutional investors, ultra-high-net-worth investors, and high-net-worth investors. If the clients are legal entities other than those mentioned above, their representatives or appointed persons are required to undergo training or testing. The training or knowledge test is a prerequisite to using a digital asset business operator’s services. Operators are not allowed to provide their services to clients who do not undergo training or testing. Disclosure of Service Quality and IT Usage Capacity From January 1, 2023, cryptocurrency/digital token exchanges, brokers, and dealers are required to disclose to the SEC information about the quality of their services (including any technological errors and complaints from clients), and their IT usage capacity. For more information about the latest SEC rules and regulations for digital assets,
July 25, 2022
Vietnam’s current Law on E-Transactions was passed in 2005 and has been effective since March 1, 2006. This law is considered a framework law, developed based on the Model Law on E-Commerce of the United Nations Commission on International Trade Law (UNCITRAL). According to the Ministry of Information and Communications (MIC), over the past 17 years, the implementation and application of e-transactions has shown significant evolution in certain areas demanding high levels of international integration, such as banking and e-commerce, but has faced difficulties in other areas due to a lack of detailed guidance. In addition, with the strong growth and breakthrough development of digital technologies such as artificial intelligence, big data, biometrics, and blockchain, and in the context of the ongoing Industrial Revolution 4.0 and the development of digital government, digital economy, and digital society, the 2005 Law on E-Transactions has revealed its shortcomings. Therefore, the government of Vietnam has entrusted the MIC to take the lead in drafting a new Law on E-Transactions, which will replace the old 2005 law in order to meet the country’s development needs. Accordingly, the MIC published a Draft Law on E-Transactions (“Draft Law”) for public consultation from May 4 to July 4, 2022. The latest accessible version of the Draft Law at the time of writing is Version 4. The effective date of the Draft Law is still not yet determined, though this law is expected to be submitted to the National Assembly for its review and comments in October 2022 and approval in May 2023. The following are some key contents of the Draft Law: 1. Scope of Application Unlike the current law, which explicitly excludes certain areas such as the issuance of certificates of land use rights and marriage certificates from the scope of application, the Draft Law attempts
July 19, 2022
On June 23, 2022, Thailand’s Securities and Exchange Commission (SEC) opened a public hearing period on regulatory controls for initial coin offering (ICO) portals that serve as financial advisors to digital token issuers. The proposed measures aim to prevent conflicts of interest; allow ICO portals to outsource certain functions; and establish additional notification obligations for ICO portals. The public hearing is open for general comments until July 23, 2022, and the new legislation is expected to be issued soon after that. During the public hearing period, any interested parties can comment on the SEC’s proposed principles. The key proposed points are outlined below. Conflicts of Interest Similar to SEC-approved financial advisors for securities offerings, ICO portals must be clear of conflicts of interest when representing issuers in a coin offering. According to the draft regulation, the following conflicts of interest are prohibited: The ICO portal (and certain individuals as specified by the SEC) directly or indirectly holds a prohibited amount of shares in the issuer, its affiliates, or its subsidiaries. If the issuer is not a listed company, any shareholding or portion thereof is prohibited. If the issuer is a listed company on the Stock Exchange of Thailand (SET), the shares held by the ICO platform may not total more than five percent of the total voting rights. The issuer (and certain individuals as specified by the SEC) directly or indirectly holds shares in the ICO portal in any amount if the ICO portal is not a listed company, or totaling more than five percent of the voting rights if the ICO portal is listed on the SET. Any of the ICO portal’s directors or executives, or the head of the department responsible for screening the ICO project, is also a director in the issuer. The ICO portal has
June 30, 2022
On May 30, 2022, Thailand’s Securities and Exchange Commission (SEC) announced that it would start regulating ready-to-use utility tokens, a type of digital token that had previously been exempted from the SEC’s approval and regulatory control. A public forum was open for comments from various stakeholders until June 29, 2022, and the draft regulation is expected to be issued soon. So far, the SEC has only supervised the issuance of not-ready-to-use utility tokens—digital tokens with the underlying right to acquire specific goods or services, which cannot be utilized upon issuance but at a later date. Due to the growing digital asset industry and lack of regulatory control, ready-to-use utility tokens have become more popular and many are listed for trading in digital asset exchanges. The SEC claimed that it is now necessary to regulate ready-to-use utility tokens as some issuers appeared to be exploiting the regulatory loophole to manipulate the price and supply of these tokens in both the primary and secondary markets, while providing insufficient data disclosure to investors. The SEC’s proposed principles include the following key points: Pre-Approval Requirements The same pre-approval requirement applicable to not-ready-to-use utility tokens will apply to ready-to-use utility tokens which an issuer intends to list on a digital asset exchange. This means that the issuer must proceed with the standard formalities, i.e., obtaining prior approval from the SEC, filing a draft prospectus, and offering the approved tokens via a SEC-approved ICO portal operator only. The SEC offers a fast-track (15 days) approval for qualifying ready-to-use utility tokens, which are those with plain-vanilla characteristics; with an offering price corresponding to the value of the underlying goods/services; for which the supply of goods and services does not vary with the price of the tokens (i.e., fixed coins); and which are not intended to be