You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

April 4, 2017

Thailand: E-Insurance Regulations Issued – Effective August 2017

Thailand’s Office of Insurance Commission (OIC) has issued new notifications concerning the criteria, procedures, and conditions for (1) offering insurance policies for sale through electronic channels, (2) using electronic means as part of the sale of policies, (3) issuing policies through electronic channels, and (4) paying compensation for claims through electronic channels (Notifications). The Notifications will come into effect on August 26, 2017 (180 days after publication in the Government Gazette).

The key features of the Notifications are as follows:

  • “Offering for sale of policies via electronic channel” (Online Sale): An Online Sale is generally understood to be an end-to-end binding of an insurance contract. “Online Sale” is defined under the Notifications as soliciting, inducing, or arranging for customers to enter into an insurance policy by providing descriptions of insurance products through electronic channels, without the personal involvement of an insurance agent, an individual broker, or the insurer’s employees. The customers’ acceptances of their purchases are also made through electronic channels. Online Sale excludes the offering of insurance policies through telemarketing.

Insurers, brokers, and applicable banks (with a broker license) are permitted to conduct Online Sale. Apart from the requirements under the Notifications, Online Sale activities are also subject to requirements under OIC regulations on advertisement and insurance intermediaries’ market conduct.

  • Insurer’s authorization and reporting requirement: Brokers and applicable banks, with an insurer’s authorization, may also conduct Online Sales. Insurers are required to withdraw if there is any noncompliance with the Notifications by their intermediaries, and they must report such incident to the OIC within seven days.
  • Specific product filing requirement: Insurance product wording, offered through Online Sale, must receive prior approval from the OIC.
  • Premium remittance: Electronic payment of premiums must be made to the insurance company’s accounts only. Brokers may not collect premiums and are therefore paid commission directly by the insurer.
  • Confirmation calls: Once an Online Sale is made, insurers are required to seek confirmation from the customer through telephone calls or electronic channels, such as email, within seven days from the distribution of the policy.
  • Free-look period: When confirmation calls or online confirmations are made, customers must be notified of their right to a free-look period, which is a period of 15 days after they receive their insurance policies during which they may change their mind and cancel the policy. However, this is not applicable to all categories of insurance. For example, compulsory motor insurance and travel insurance are excluded.
  • Issuing e-policies: In issuing policies through electronic channels, an e-signature must be placed by the insurer. The e-signature must comply with reliability requirements under the Electronic Transactions Act B.E. 2544 (2001). For group insurance policies, the insurer must issue an insurance certificate along with other required information to each of the insured group members, unless agreed otherwise between the insurer and the group policy holder(s).
  • E-claim payments: Insured persons/beneficiaries must be identified through a process arranged by the insurer before any electronic claims compensation is made. Claims payment must only be made to the account of the insured person or the beneficiary, whichever is agreed upon in advance.
  • Security measures: Online Sales, using electronic means as part of the sale of policies, issuing policies electronically, and paying compensation for claims must comply with the levels of security measures prescribed under the Electronic Transactions Act and the requirements on IT security systems stipulated in the Notifications (e.g., IT systems for providing such online services must be certified by an independent certification body such as CISA, CISM, CISSP, or ISO 27001 Information Security Management). In addition, the IT systems must be registered with the OIC to conduct any of the activities above.
  • Outsourcing: Third-party outsourcing arrangements are subject to the specific requirements stipulated under the Notifications. 

Compliance with these Notifications is in addition to existing regulatory requirements under the Electronic Transactions Act and other laws that regulate online business.

In addition, the OIC has announced, for public hearing, a draft subordinating notification on IT security measures certification. The draft sets out greater details on conditions and criteria for certification of IT security measures as required under the Notifications. It is expected that the draft will be implemented in the near future, possibly by the end of 2017.

RELATED INSIGHTS​ 

February 19, 2021
Insurance specialists from Tilleke & Gibbins’ Bangkok office have provided an update to the Thailand chapter of Thomson Reuters’ Practical Law guide to insurance and reinsurance. The guide is a Q&A-style overview of insurance and reinsurance law in 41 jurisdictions worldwide. The Thailand contribution opens with a detailed overview of the insurance and reinsurance market in Thailand, including information on market trends, the available corporate structures, and relevant regulations. The Q&A is then separated into three main sections: Operating restrictions: licensing, ownership restrictions, ongoing requirements (compliance) and penalties for noncompliance, selling restrictions, and monitoring and disclosure requirements. Insurance and reinsurance policies: establishing an insurance claim, third party insurance claims, time limits, enforcement, remedies, and punitive damage claims. Other business concerns for insurance and reinsurance providers: insolvency, taxation, insurance and reinsurance dispute resolution, and legal reform. Practical Law produces a numbers of guides to key legal practice areas around the world for business lawyers. Tilleke & Gibbins contributes many overviews to these guides for all of the firm’s jurisdictions in Southeast Asia. To read the full Thailand insurance and reinsurance chapter, please visit the Practical Law website.
February 18, 2021
As you will no doubt know, on February 1, 2021, the Myanmar military declared a state of emergency in Myanmar for a period of one year. State Counsellor Daw Aung Sang Su Kyi was detained, as were the president and various significant political and civil leaders. Min Aung Hlaing, commander-in-chief of the Tatmadaw (Myanmar armed forces) has installed himself as chairman of the State Administration Council, the current administration. New sanctions The reaction of the Biden administration has been swift. On February 10, 2021, President Biden issued Executive Order 14014, which provides bases to impose sanctions on individuals and companies deemed by the US to, among other things: operate in the defense sector of Myanmar; be responsible for policies that undermine democratic processes in Myanmar; have taken actions to undermine democratic processes or institutions, or prohibit, limit, or penalize the exercise of free speech, in Myanmar; or be a spouse or child of the foregoing. On the next day, February 11, the US Office of Foreign Assets Control (OFAC), imposed sanctions under the new executive order on ten individuals—including General Min Aung Hlaing—and three companies, including Cancri Gems & Jewelry Co, Myanmar Imperial Jade Co, and Myanmar Ruby Enterprise.  All such individuals and companies have now been designated on the US list of specially designated nationals (SDNs). Effect of sanctions As a result of such sanctions, the property of these individuals or companies that is located in the US or is under the possession or control of US companies and citizens is frozen, and US companies and citizens are generally prohibited from dealing deal with any such property.  Reportedly, roughly USD 1 billion of funds belonging to the individuals and companies blocked on February 11 are located in the US and thus now frozen. The SDN list As many
January 13, 2021
Thailand’s Office of the Insurance Commission (OIC) recently issued two notifications—one for life-insurance companies and another for insurance companies—establishing key criteria and requirements for insurance companies to manage risks relating to IT and cybersecurity. The notifications, entitled Notifications Re: Criteria for the Supervision and Management of Risks Relating to Information Technology for Life/Non-life Insurance Companies B.E. 2563 (2020) came into effect on January 1, 2021, and cover eight major aspects of IT risk management as detailed below. IT Governance Insurance companies are required to monitor and manage IT risks and cyber threats in accordance with the size, characteristics, complexity, and context of their business operations, and each company should have at least one director with knowledge of, or past experience in, the field of information technology. IT Project Management Insurance companies are required to develop a written framework for IT project management, covering at least the commencement, implementation, and control of the project, as well as the project closing and post-project auditing. Companies must also appoint a committee for supervising and monitoring IT projects. IT Security Insurance companies are required to institute a written IT security policy, which must be reviewed at least once a year or upon implementing any significant changes. The policy must be approved by the board of directors, or a relevant subcommittee appointed by the board of directors. In outsourcing IT activities to third-party service providers, or entering into any arrangement that allows business partners to connect to or access the company’s IT system, insurance companies are required to specify their own criteria and procedures for the selection of third-party service providers, enter into a written service agreement and a service level agreement with the third-party provider, and conform with other requirements under the notifications. Insurance companies will also be required to comply with the OIC’s forthcoming