You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

September 24, 2025

Thailand Issues AI Risk Management Guidelines for Financial Service Providers

On September 12, 2025, the Bank of Thailand (BOT) officially released its AI Risk Management Guidelines for Financial Service Providers, building upon the draft guidelines issued in June 2025. The guidelines reflect a balanced approach, encouraging innovation while safeguarding financial stability and consumer protection.

The guidelines are targeted at all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act.

The guidelines apply to both AI systems developed in-house and those developed by third parties that are adopted for use by financial service providers.

AI Risk Management Guidelines

The two main pillars in managing AI risk are (1) governance of AI system implementation and (2) AI system development and security controls, consisting of the following key elements:

1. Governance

  • Stakeholder roles and responsibilities. Boards and senior management assume accountability for decisions and operations involving AI systems, and are responsible for defining roles and responsibilities for AI oversight. This includes establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. Organizations are expected to foster internal capabilities to use AI securely and avoid overreliance that could compromise business continuity or customer service.
  • AI system usage policy. Policies governing AI usage should align with organizational goals, regulatory obligations, and recognized responsible AI frameworks—such as the FEAT principles (fairness, ethics, accountability, and transparency). These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles.
  • Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. Financial service providers should assess risks and impacts of AI usage on operations and customer services. Human oversight must be embedded in decision-making processes, with the degree of oversight calibrated to the level of risk and impact, especially when AI systems are used in strategic functions or customer interactions (e.g., loan approval or account opening). In customer interactions with AI systems, customers should be notified and have options to contact personnel of financial service providers.
  1. Development and security controls
  • Data risk. Financial service providers should have measures to assess and ensure the quality, accuracy, currentness, volume, and diversity of data used in AI model training. They should also implement data leakage prevention measures.
  • Model development risk. Financial service providers should have (1) clear evaluation metrics for assessing model accuracy and reliability through ongoing testing and monitoring, both before and after deployment, and (2) measures to ensure the explainability of AI outcomes. For generative AI applications, there should be specific measures to reduce AI hallucination risks by adopting techniques such as retrieval-augmented generation and prompt engineering. Financial service providers should also ensure explainability of AI outputs through documentation detailing model inputs, outputs, and parameters.
  • Cybersecurity risk. Financial service providers should have measures to prevent and detect emerging cyber threats targeting AI systems, based on established standards such as the OWASP Machine Learning Security Top 10.

In addition, the BOT emphasizes the importance of financial service providers strictly complying with applicable laws when adopting AI, including personal data protection laws and intellectual property laws.

RELATED INSIGHTS​ 

September 24, 2024
In recent years, Thailand has witnessed significant developments in its personal finance sector, particularly in alternative lending options. This article explores two key concepts in the Thai financial landscape: nano finance and personal loans. These alternative lending models, regulated by the Bank of Thailand (BOT), aim to provide more accessible financial services to individuals and small entrepreneurs who might have limited access to traditional funding sources. Nano Finance: Empowering Small Entrepreneurs The nano finance scheme under the BOT’s supervision is designed to provide funding to small entrepreneurs who might have limited access to traditional financial resources. One of the key features of this scheme is the ability of licensed nano finance providers to use alternative data in assessing loan applicants’ ability to repay (information-based lending). To implement this approach, nano finance providers must have an internal policy on credit approval that supports: Identifying scope and processes for utilizing alternative factors or technologies in determining debt repayment capacity, credit line limits for each loan applicant and total credit limits, and acceptable debt repayment targets; Having resources and personnel with sufficient knowledge, capability, experience, and expertise to operate efficiently and effectively, as well as clear checks and balances; Establishing guidelines for selecting and analyzing factors or financial models to evaluate or predict loan applicants’ ability and willingness to repay; Having an internal sandbox to test key success factors of the selected factors or models; and Having a process for monitoring and reviewing the application of the selected factors or models in assessing debt repayment capability. This approach allows nano finance providers to make more informed lending decisions based on a broader range of data, potentially increasing access to finance for small entrepreneurs who may not have traditional credit histories or collateral. Personal Loans The personal loan scheme under BOT supervision aims
September 20, 2024
On September 12, 2024, the Bank of Thailand (BOT) Notification Re: Virtual Bank Supervision Criteria took effect. According to this notification, virtual banks must adhere to standards for traditional commercial banks, along with additional requirements tailored to address virtual banks’ digital nature and corporate structure. Specific Requirements The concepts of supervision remain unchanged from the consultation paper titled “Criteria for Supervising Virtual Banks”. Some of the key additional provisions and details on supervision criteria relate to the following: Financial business groups: The notification identifies virtual banks as financial businesses, subject to the BOT’s regulations on financial business group supervision. If a virtual bank is a part of another financial institution’s financial business group, the virtual bank must be under a solo consolidated group. After the “initial phase” (see below), other financial institutions and companies within the financial business group are prohibited from extending credit to or engaging in transactions similar to lending activities with the virtual bank. Capital fund requirements: If other financial institutions’ investment in a virtual bank increases the capital fund in the financial system beyond a safe level and this poses a risk to other financial institutions, the BOT may order the relevant financial institution to maintain capital funds as the BOT deems appropriate. Service channels and outsourcing: Virtual banks must provide services solely through digital channels, except when necessary. For example, with the BOT’s approval, a virtual bank may use other commercial bank electronic branches via an ATM pool system, use a banking agent to serve customer needs for cash, or occasionally provide on-site services. Initial Phase The “initial phase” runs from the date that the virtual bank commences its operations until it receives the BOT’s approval to become fully operational. During this period, certain BOT supervisory requirements are relaxed as follows: Governance: Virtual banks in the initial phase may request
September 16, 2024
On July 23, 2024, the State Bank of Vietnam (SBV) published a draft circular regulating the implementation of open (publicly available) application programming interfaces, or Open APIs, in the banking industry (Draft Circular) to collect public comments. Open APIs in the banking sector are APIs of banks that allow third parties to process data for their own use or to provide products and services to customers. Urgent need Currently, the development of Open APIs in Vietnam is fragmented, with each bank using different API standards and security standards. There is no common standard for information technology systems, information storage, security, connectivity, or legal frameworks. Therefore, the promulgation of a regulation on Open APIs is urgently needed to create a clear legal basis and guidance for electronic banking transactions, especially in connecting to bank information systems and processing customer data safely, and creating new, innovative products and services to meet the increasing needs of customers. Cooperation of banks required The Draft Circular requires banks to provide Open API services to third parties for connection to the bank system and data processing. Banks have the right to refuse or suspend Open API services if third parties do not meet specified conditions. However, banks will be responsible for ensuring the quality and security of data, providing tools for customer data queries and revocation of third-party data processing rights, and coordinating with third parties and authorities to resolve issues. The Draft Circular standardizes Open API functions for all banks according to the Open API function list and the technical standards list specified in the Draft Circular. Open API service contract The template Open API service contract between banks and third parties using Open API services must have certain required contents such as provisions regarding confidentiality, data use purpose, and that the security level
September 10, 2024
In recent years, Thailand has witnessed a significant transformation in its financial landscape, particularly in the rapid adoption of financial technology (fintech). At the forefront of this evolution are electronic payment systems and services, which have revolutionized how individuals and businesses conduct financial transactions. This transformation has been driven by both traditional financial institutions and alternative financial service operators. Overseeing this dynamic landscape are two primary regulators: the Bank of Thailand (BOT) and the Securities and Exchange Commission (SEC). This article explores the development of electronic payment systems in Thailand, with a particular focus on the Payment Systems Act (PSA) of 2017 and its role in shaping the fintech ecosystem. Payment Systems Act In October 2017, Thailand took a significant step forward in regulating its burgeoning electronic payment sector by adopting the Payment Systems Act. This landmark legislation was designed to create and ensure electronic payment system stability and enhance consumer protection in the digital financial realm. The PSA establishes a comprehensive framework by categorizing electronic payment businesses into two main categories: payment systems and payment services. Electronic Payment Systems under the PSA The PSA recognizes two types of electronic payment systems that require specific licenses or registration: Central or network systems. These include systems that act as a center or network between service users for fund transfers, clearing, or settlement. Examples include: Inter-institution Fund Transfer System Payment card networks Settlement systems Systems of public interest. This category encompasses any other payment systems that may affect public interest, public confidence, or the stability and security of the payment infrastructure. Electronic Payment Services under the PSA The PSA also identifies several electronic payment services that require specific licenses or registration: Credit cards, debit cards, and ATM cards Electronic money E-payments Acquisition Payment facilitation Receipt of payment on behalf of others