You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

September 3, 2020

Thailand Introduces Stringent Requirements for Distribution of Insurance Products

On July 31, 2020, Thailand’s Office of Insurance Commission (OIC) imposed a host of new measures aimed at regulating the issuance of insurance policies and the conduct and duties of insurance agents and brokers.

These measures are contained in two new notifications: the Notification re: Conditions Relating to the Issuing and Offering of Insurance Policies of Insurance Companies; and the Notification re: Duties of Life and Non-life Insurance Agents, Brokers, and Banks. The key provisions to note are identified below.

General Duties of Insurance Companies

  • Insurance companies must institute a quality control system for the sale of insurance policies and provision of services. This should also cover the development of new insurance products and administrative and monitoring systems for the offering of insurance products. Such systems must also be approved by the company’s board of directors.
  • If an insurance company finds that an intermediary fails to comply with the requirements of the new notifications, the company must immediately revoke the intermediary’s authority to offer insurance products for sale on behalf of the insurance company, and keep a record of any such noncompliance for the OIC’s inspection.
  • Insurance companies must comply with the OIC Notification regarding Criteria, Procedures, and Conditions for Enterprise Risk Management (ERM) and Own Risk and Solvency Assessment (ORSA). 

General Duties of Intermediaries

  • The general and specific duties of intermediaries under the new notifications are very similar to those given in previous notifications, with changes of wording for conciseness. However, the new notifications do add a new general duty as well as an exception:
  • Intermediaries are required to thoroughly study the details and coverage of insurance policies before conducting any sales, and to ensure that the insurance policies offered are suitable for each customer’s purposes, risk appetite, and ability to pay premiums.
  • Intermediaries may fix a condition for the customers to enter into an insurance contract in order to receive services, or enter into a transaction, provided that the purpose of the condition is to directly prevent a risk associated with the provision of service or entry into the transaction.

Offering Insurance Products via Employees or Staff (Face-to-Face)

  • The new notifications repeal the OIC notification regarding digital face-to-face measures during the COVID-19 pandemic. However, the new notifications also provide an exemption for face-to-face sales to be carried out digitally (e.g., by voice, video, and images), provided there is a justifiable necessity to do so and the customer in question consents to a digital face-to-face meeting. Insurance companies and intermediaries must arrange for appropriate systems and sales processes to accommodate this, such as communication records, quality control, and personal data protection.
  • For offering unit-linked or universal life insurance policies, intermediaries are required to pass the relevant training and register with the OIC in accordance with the criteria prescribed by the OIC.

Offering Insurance Products via Bancassurance

  • Upon receiving a customer’s consent, banks can now offer insurance products outside of their offices. However, banks must comply with the requirements for this, which will be prescribed by the OIC in due course.

Offering Insurance Products via Telesales

  • The new notifications also prescribe the minimum requirements for intermediaries arranging systems or procedures to carry out telesales. These include a voice recording system and storage, a do-not-call list, policies and procedures for lawful collection and retention of customers’ data, and a risk management or business continuity plan.

Receipt, Retention, and Remittance of Premiums

  • For the sale of insurance products via the digital face-to-face channel, or if the intermediaries are licensed business operators under the laws relating to the Payment System Act, the premium must be remitted directly to the company’s account.

Information Disclosure and Handling of Customer Data

  • Companies must disclose information about their intermediaries to customers, and must keep that information up to date.
  • Corporate brokers and banks must also disclose information about employees who offer insurance policies on their behalf, and must keep that information up to date.
  • Insurance companies and intermediaries must implement a system or procedure for the collection, retention, and protection of customer data in compliance with the Personal Data Protection Act B.E. 2562 (2019).

Penalties

  • Any breach of the conditions specified in the new notifications is a criminal offense, with the offender subject to the penalties specified in the Non-Life Insurance Act B.E. 2535 (1992).

For advice on complying with these new regulations, or for any other information on insurance business in Thailand, please contact the Tilleke & Gibbins insurance team at [email protected], [email protected], or [email protected].

RELATED INSIGHTS​ 

June 30, 2026
Tilleke & Gibbins’ insurance specialists in Bangkok provided Thomson Reuters’ latest country update on Thailand’s regulatory framework for the insurance industry. The country update, which is part of Thomson Reuters’ extensive Regulatory Intelligence offerings, contains information and guidance for insurers active in the Thai market. The guide covers the following topics in detail: Permission to operate; Legal and regulatory considerations for domestic and international insurers; Capital reserve requirements; Investment management and markets; The Office of Insurance Commission’s arbitration system for handling complaints; Creditor hierarchy; Rehabilitation of non-life insurance companies; and Personal data protection requirements for insurers. Thomson Reuters Regulatory Intelligence is a service that provides with curated news, analysis, and data across jurisdictions to help legal, risk, and compliance professionals manage compliance and mitigate global risk. The full Thailand insurance country update is available by subscription to Regulatory Intelligence on the Thomson Reuters website.
June 30, 2026
Insurance specialists from Tilleke & Gibbins have provided an update to the Vietnam chapter of Thomson Reuters’ Practical Law guide to insurance and reinsurance. The guide is a Q&A-style overview of insurance and reinsurance law in jurisdictions worldwide. The Vietnam chapter provides a detailed overview of the legal framework for the insurance and reinsurance market in the country, covering the following issues: Regulatory framework for insurance and reinsurance Authorization for insurers, reinsurers, and insurance intermediaries Ownership restrictions Ongoing requirements Penalties for noncompliance Sales and marketing of insurance and reinsurance Transfer of risk Reinsurance contracts and risks Contracts and policies Claims Dispute resolution Insolvency Tax Practical Law, a legal reference resource from Thomson Reuters, publishes a range of guides for hundreds of jurisdictions and practice areas. The insurance and reinsurance guide is a valuable resource for legal practitioners, covering numerous jurisdictions worldwide. To view the latest version of the guide, please visit the Practical Law website and enroll in the free Practical Law trial to gain full access.
June 5, 2026
Thailand’s Office of Insurance Commission (OIC) has opened a public hearing on proposed amendments to the OIC Notification on Criteria for Information Technology Risk Governance and Management for Life Insurance and Non-Life Insurance Companies B.E. 2563 (2020) via the centralized Law platform. The public consultation period runs from May 8, 2026, to June 9, 2026. The proposed amendments aim to elevate the IT risk governance and cybersecurity risk management framework to be more modern and aligned with international standards, with a focus on strengthening cyber resilience, enhancing the role of IT audits, and establishing data governance and data quality controls. The parties affected by these amendments include life insurance companies, non-life insurance companies, and external IT auditors. Key Changes Elevated Role of Board of Directors The proposed notification requires the company’s board of directors to oversee data governance, cybersecurity, and the responsible use of AI. Additionally, the board should include at least one director with IT knowledge or experience. Companies are also required to designate a head of security responsible for information security. The board’s duties are expanded to include oversight of data governance and AI usage, including establishing relevant policies and committees. Enhanced IT Security and Cybersecurity The revised notification consolidates the existing chapters on IT project management, IT security and cybersecurity to reduce redundancy, and introduces significant new measures. These include mandatory multi-factor authentication for material systems, enhanced data security measures such as data masking and data leakage prevention, security hardening requirements, web filtering, and mandatory vulnerability assessment and penetration testing at least annually. New requirements are also introduced for mobile application security, API security, and security measures for emerging technologies such as cloud computing and post quantum cryptography. The cybersecurity framework now encompasses identification, protection, detection, response, and recovery. The draft also introduces source code review
April 9, 2026
Thailand’s Office of the Insurance Commission (OIC) has published two parallel sets of draft regulatory amendments for public hearing—one governing non-life insurance and the other governing life insurance. The proposed amendments would significantly revise the rules for issuing, offering, and selling insurance policies, as well as the conduct of agents, brokers, and banks. Stakeholders may submit comments until April 25, 2026. The key proposed changes are summarized below. Electronic Policy Delivery by Default Under both draft amendments, electronic delivery would become the default method for delivering insurance policies. A printed copy would be required only if the policyholder expressly opts out, and any such printed copy would be treated as a substitute for the electronic original. For life insurance, this requirement would also extend to coverage summaries and to exclusion documents. The OIC would also retain authority to approve alternative delivery methods for specific types of policies. Misuse of Licenses Both amendments would introduce an explicit prohibition against sales representatives using another person’s name or license, or allowing another person to use their name or license, in connection with the offering of insurance or in sales documentation and policies. Premium Collection Reforms Both amendments would introduce the premium collection reforms outlined below. Premium receipt accounts Insurers must ensure that sales representatives inform customers of the available payment channels, which are limited to channels that remit premiums into the insurer’s account. If a customer pays an insurance premium to an insurer’s employee, an insurance broker, or any other person, and the company acknowledges the payment by issuing an insurance policy or other documentary evidence of insurance coverage, the insurer would be deemed to have received the insurance premium. Written premium collection and refund guidelines Insurers would be required to prepare written internal guidelines covering premium collection and refund policies, risk