You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 19, 2025

Thailand Drafts AI Risk Management Guidelines for Financial Service Providers

The Bank of Thailand (BOT) has released draft guidelines establishing principles for managing artificial intelligence (AI) risks in the financial sector. The draft guidelines provide a structured framework for the responsible adoption of AI technologies. Financial service providers will be able to use the guidelines as a reference to appropriately manage their risks in a manner that aligns with internationally recognized best practices.

The BOT is accepting public comments on the draft guidelines until June 30, 2025.

Scope and Application

The draft guidelines apply to all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. These guidelines supplement existing BOT risk management guidelines covering IT risk management, third-party risk management, data governance, and market conduct.

The guidelines define AI systems as systems that mimic human intelligence, including machine learning, deep learning, generative AI (such as large language models), and agentic AI. This definition specifically excludes rule-based automation systems like robotic process automation and condition matching.

Key Risk Management Principles

The guidelines lay out two main principles in managing AI risk.

  1. Governance: Financial service providers should define and establish clear roles and responsibilities for their personnel and AI system supervision structures to uphold FEAT (fairness, ethics, accountability, and transparency) principles as follows:
    • Stakeholder roles and responsibilities. Financial service providers should define roles and responsibilities for boards and executives on AI risk oversight. Responsibilities include establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization.
    • AI system usage policy. The AI system usage policy should be aligned with organizational objectives, regulatory requirements, and FEAT principles. These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles.
    • Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. When AI systems are used in strategic functions or customer interactions (e.g., loan approval, account opening), human oversight must be integrated into decision-making processes. In customer interactions with AI systems, customers should be notified and have options to disable or bypass AI features.
  1. Development and security controls: Financial service providers should have risk controls covering the AI development and deployment lifecycle as follows:
    • Data risk. Financial service providers should have measures to assess and ensure the quality, accuracy, currency, volume, and diversity of data used in AI model training. They should also implement data leakage prevention measures.
    • Model development risk. Financial service providers should have (1) clear evaluation metrics for assessing model accuracy and reliability through ongoing testing and monitoring both before and after deployment and (2) measures to ensure the explainability of AI outcomes. For generative AI applications, there should be specific measures to reduce AI hallucination risks.
    • Cybersecurity risk. Financial service providers should have measures to prevent and detect emerging cyber threats targeting AI systems, based on established standards such as the OWASP Machine Learning Security Top 10.

For more details on any aspect of fintech, technology, and cybersecurity in Thailand, please contact Athistha Chitranukroh at [email protected], Nopparat Lalitkomon at [email protected], Pornpan Wichawut at [email protected], Napassorn Lertussavavivat at [email protected], or Rujaporn Paritsantik at [email protected].

RELATED INSIGHTS​ 

October 15, 2021
In September 2021, Thailand’s Electronic Transactions Development Agency (ETDA) issued an updated draft royal decree for digital platforms—a potentially far-reaching royal decree that was the subject of a public hearing in July 2021. The ETDA made the changes in response to a considerable amount of feedback and comments from business operators and other stakeholders. The key changes to the draft royal decree are outlined below. Definitions The updated draft broadens the definition of digital platforms subject to the royal decree by removing mention of offering goods, services, or intangible assets, and by deleting a phrase related to contract issues. As a result, “digital platform” currently refers to any intermediary digital platform that provides a connection space for “business operators on a digital platform” and “consumers” via a computer network. Similarly, the definitions of “business operators on a digital platform” and “consumers” have been amended by excluding the offering of intangible assets through digital platforms, and the draft emphasizes that business operators on a digital platform are not included in the definition of consumers. Notification Exemption Under the updated draft royal decree, a digital platform provider under the supervision of other authorities or falling under the Electronic Transactions Commission’s list of exempted digital platform providers is exempted from the requirement to notify the ETDA of the operation of its digital platform. The commission may also exempt any other digital platform service as it sees fit. Extraterritorial Effect The draft provisions subjecting certain digital platforms located outside Thailand to the royal decree and requiring them to appoint a local representative in Thailand have been updated by removing the requirement to issue a tax invoice to consumers in Thailand. Furthermore, the updated draft makes the local representative subject to the reporting obligations and cessation requirements, whereas these obligations were not prescribed in
October 14, 2021
As part of its membership in Lex Mundi, Tilleke & Gibbins has published an updated edition of its Guide to Doing Business in Thailand for 2021. This guide outlines all of the key factors for starting and operating a business in the Thai market. Issues covered include: Investment incentives Financial facilities Exchange controls Import and export regulations Structures for doing business Requirements for the Establishment of a Business Operation of the Business Cessation or Termination of the Business Labor legislation, relations, and supply Tax Immigration requirements This publication is part of Lex Mundi’s Guides to Doing Business series prepared by member firms in more than 100 jurisdictions worldwide. The guides serve as a useful resource when planning an international business strategy or researching a new market.
September 30, 2021
Thailand’s Board of Investment has consolidated its definition of promoted business activities in the digital space, replacing promotions for e-commerce, digital services, and software, with a single category for “Development of software, platform for digital services, or digital content.”
September 27, 2021
Multilaw has published its new Global Data Protection Guide, which collects expert advice from Multilaw’s member firms in over 50 jurisdictions globally. The guide provides answers to key issues concerning the fast-developing data protection and privacy laws around the world, and helps data protection officers and in-house counsel understand how the regulatory regime for data protection can affect their organizations in various jurisdictions. Each section of the guide identifies the main laws that govern data protection in that jurisdiction, and gives a detailed overview of the legal principles in place as well as the enforcement authorities responsible for overseeing compliance. The guide also covers issues related to data subject rights, data protection officers, impact assessments, data breach notification requirements, and cross border data transfers. The use of personal data in marketing is also considered, with specific information on electronic marketing rules, cookies, and marketing to businesses and consumers. Multilaw is a global network of carefully selected, independent law firms consisting of over 10,000 commercial lawyers in more than 100 countries, able to provide expert legal advice in complex environments around the globe. The full guide is available for free on the Multilaw website.