You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

September 24, 2025

Thailand Issues AI Risk Management Guidelines for Financial Service Providers

On September 12, 2025, the Bank of Thailand (BOT) officially released its AI Risk Management Guidelines for Financial Service Providers, building upon the draft guidelines issued in June 2025. The guidelines reflect a balanced approach, encouraging innovation while safeguarding financial stability and consumer protection.

The guidelines are targeted at all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act.

The guidelines apply to both AI systems developed in-house and those developed by third parties that are adopted for use by financial service providers.

AI Risk Management Guidelines

The two main pillars in managing AI risk are (1) governance of AI system implementation and (2) AI system development and security controls, consisting of the following key elements:

1. Governance

  • Stakeholder roles and responsibilities. Boards and senior management assume accountability for decisions and operations involving AI systems, and are responsible for defining roles and responsibilities for AI oversight. This includes establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. Organizations are expected to foster internal capabilities to use AI securely and avoid overreliance that could compromise business continuity or customer service.
  • AI system usage policy. Policies governing AI usage should align with organizational goals, regulatory obligations, and recognized responsible AI frameworks—such as the FEAT principles (fairness, ethics, accountability, and transparency). These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles.
  • Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. Financial service providers should assess risks and impacts of AI usage on operations and customer services. Human oversight must be embedded in decision-making processes, with the degree of oversight calibrated to the level of risk and impact, especially when AI systems are used in strategic functions or customer interactions (e.g., loan approval or account opening). In customer interactions with AI systems, customers should be notified and have options to contact personnel of financial service providers.
  1. Development and security controls
  • Data risk. Financial service providers should have measures to assess and ensure the quality, accuracy, currentness, volume, and diversity of data used in AI model training. They should also implement data leakage prevention measures.
  • Model development risk. Financial service providers should have (1) clear evaluation metrics for assessing model accuracy and reliability through ongoing testing and monitoring, both before and after deployment, and (2) measures to ensure the explainability of AI outcomes. For generative AI applications, there should be specific measures to reduce AI hallucination risks by adopting techniques such as retrieval-augmented generation and prompt engineering. Financial service providers should also ensure explainability of AI outputs through documentation detailing model inputs, outputs, and parameters.
  • Cybersecurity risk. Financial service providers should have measures to prevent and detect emerging cyber threats targeting AI systems, based on established standards such as the OWASP Machine Learning Security Top 10.

In addition, the BOT emphasizes the importance of financial service providers strictly complying with applicable laws when adopting AI, including personal data protection laws and intellectual property laws.

RELATED INSIGHTS​ 

January 9, 2025
On January 1, 2025, Myanmar’s State Administration Council enacted Cybersecurity Law No. 1/2025, which aims to regulate various aspects of digital security and online activities. The law has not yet been implemented and will come into force on a date specified by the Myanmar president, who will also provide an official adoption and compliance timeline for individuals and organizations impacted by the new regulations. Below are some of the key provisions, implications, and penalties under the Cybersecurity Law. Extraterritorial penalties. The law contains an important provision that authorizes penalties against Myanmar citizens who are found guilty of violations, even if these occur outside the country’s borders. VPN definition and regulation. Virtual private networks (VPNs) are defined by this law as specific systems that function as backup networks by using technological means in order to ensure the safety of linking networks to each other. This definition sets the framework for subsequent regulations and penalties associated with VPN usage. The law does not restrict individuals or entities from using VPNs; it regulates VPN service providers. Penalties for unapproved VPN services. Establishing a VPN or providing VPN services without approval from the designated ministry (to be appointed later by the government) can result in significant penalties. For individuals, the punishment may be imprisonment for 1–6 months, a fine of MMK 1–10 million (approx. USD 476–4,760), or both, with the proceeds of the violation being confiscated. If the violator is a company or organization, the minimum fine will be MMK 10 million, and the proceeds will be confiscated. Government oversight. The ministry designated by the government is authorized to investigate and take control of cybersecurity services and digital platform services for national defense and security purposes, or upon request from a government department or organization in accordance with respective laws. Licensing requirements. The
January 9, 2025
Thailand’s Fiscal Policy Office (FPO) has released a draft of its planned Financial Business Hub Act, which is in line with the government’s aim of positioning Thailand as a regional financial hub and a critical player in the global economy. The draft act, on which the FPO is accepting comments until January 9, 2025, details the framework for promoting and attracting international financial businesses and related services to operate in Thailand, proposes various incentives, and outlines supervisory guidelines. This article examines key elements of the draft Financial Business Hub Act relevant to financial business operators. Incentivized Financial Businesses The draft act identifies the financial businesses to be promoted and incentivized. These target businesses include: Commercial banking businesses, Payment service businesses, Securities businesses, Derivatives businesses, Digital assets businesses, Insurance and reinsurance brokerage businesses, and Other financial-related businesses as determined by the Committee for the Supervision and Promotion of Financial Centers. Thailand’s finance minister explained that initially, the draft law intends to target businesses using an “out-out” model, which describes the raising of capital abroad for investment abroad, before expanding to an “out-in” model, in which capital is raised abroad for investment domestically. Therefore, the draft law currently specifies that the target businesses must only provide services to nonresidents without soliciting residents of Thailand to use their services. Authorization Targeted financial business operators will need to receive authorization from the Committee for the Supervision and Promotion of Financial Centers. The main eligibility criteria for authorization are the incorporation an entity (e.g., a company registered in Thailand, a branch of a foreign juristic person) with an office in designated areas to be specified in a royal decree (currently expected to be Bangkok and adjacent provinces) and the possession of other qualifications as prescribed in the draft act. Target businesses in Thailand will
January 6, 2025
On December 24, 2024, the government of Vietnam issued Decree No. 163/2024/ND-CP, providing guidelines for implementing the new Telecommunications Law that took effect on July 1, 2024 (“Decree 163”). This new decree replaces Decree No. 25/2011/ND-CP and its amendments (“Decree 25”) and took effect immediately upon issuance, with regulations on data center services, cloud computing services, and basic telecom services over the internet (“over-the-top” or OTT telecom services) having an official effective date of January 1, 2025. Decree 163 introduces substantial changes across the telecom sector, covering various aspects including service provision, licensing, standards and technical regulations, quality, passive infrastructure planning, dispute resolution, and more. Hence, it is necessary for enterprises to conduct a compliance review to identify gaps between the new decree and their business models, and take necessary steps to ensure lawful business operations in Vietnam. Below are some highlights of Decree 163. Expanded Scope of Services For basic telecom services, Decree 163 has introduced machine-to-machine (M2M) communication and classified it as a basic telecom service. This establishes a regulatory framework for IoT device communication, previously unregulated in Decree 25. For value-added telecom services, in light of the new Telecommunications Law, Decree 163 provides more detailed regulations for new telecom services such as data center services, cloud computing services, and OTT telecom services, which were not addressed in Decree 25. Regulation of Three New Telecom Services Expanding on the Telecommunications Law’s definitions of data center services, cloud computing services, and OTT telecom services, Decree 163 applies a light-touch management approach to regulate these three new services, as follows: Offshore providers: Cross-border service providers are exempt from signing commercial agreements with licensed local telecom companies. They only need to notify the Vietnam Telecommunications Authority (VNTA) using the prescribed procedures and forms before offering services. Onshore providers: The foreign
December 24, 2024
On November 30, 2024, the Data Law was officially promulgated after an accelerated preparation process that began in February 2024. The Data Law is set to take effect on July 1, 2025. Having extraterritorial effect, the Data Law will impact both local and foreign individuals and enterprises. As noted in our previous legal update, the Data Law governs digital data, the National Data Center, the National General Database, digital data products and services, digital data management, and the rights, obligations, and responsibilities of agencies, organizations, and individuals related to digital data activities. This legal update provides an overview of the Data Law, with a deep focus on the key provisions likely to impact businesses operating or offering services in Vietnam. New Data Definition and Classification The Data Law broadly defines “digital data” as data about objects, phenomena, and events, which can include one or a combination of audio, images, numbers, text, or symbols represented in digital format (hereinafter referred to as “data”). This definition is very broad and potentially covers any information recorded or represented in digital forms, including personal and nonpersonal data (such as business data, transactional data, trade secrets, etc.). Data is further categorized into different types that can be used by public bodies. However, the rights and obligations associated with each type of data are not clearly addressed. The data classification criteria include: The nature of data sharing (shared data, private data, open data); The importance of data (core data, important data, and other data); Any other criteria to meet the requirements of data administration, processing, and protection, as determined by the data owner. While the Data Law requires private organizations to categorize data based on its level of importance, it still grants these organizations the right to categorize data based on other criteria. Cross-Border Data