You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

September 24, 2025

Thailand Issues AI Risk Management Guidelines for Financial Service Providers

On September 12, 2025, the Bank of Thailand (BOT) officially released its AI Risk Management Guidelines for Financial Service Providers, building upon the draft guidelines issued in June 2025. The guidelines reflect a balanced approach, encouraging innovation while safeguarding financial stability and consumer protection.

The guidelines are targeted at all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act.

The guidelines apply to both AI systems developed in-house and those developed by third parties that are adopted for use by financial service providers.

AI Risk Management Guidelines

The two main pillars in managing AI risk are (1) governance of AI system implementation and (2) AI system development and security controls, consisting of the following key elements:

1. Governance

  • Stakeholder roles and responsibilities. Boards and senior management assume accountability for decisions and operations involving AI systems, and are responsible for defining roles and responsibilities for AI oversight. This includes establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. Organizations are expected to foster internal capabilities to use AI securely and avoid overreliance that could compromise business continuity or customer service.
  • AI system usage policy. Policies governing AI usage should align with organizational goals, regulatory obligations, and recognized responsible AI frameworks—such as the FEAT principles (fairness, ethics, accountability, and transparency). These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles.
  • Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. Financial service providers should assess risks and impacts of AI usage on operations and customer services. Human oversight must be embedded in decision-making processes, with the degree of oversight calibrated to the level of risk and impact, especially when AI systems are used in strategic functions or customer interactions (e.g., loan approval or account opening). In customer interactions with AI systems, customers should be notified and have options to contact personnel of financial service providers.
  1. Development and security controls
  • Data risk. Financial service providers should have measures to assess and ensure the quality, accuracy, currentness, volume, and diversity of data used in AI model training. They should also implement data leakage prevention measures.
  • Model development risk. Financial service providers should have (1) clear evaluation metrics for assessing model accuracy and reliability through ongoing testing and monitoring, both before and after deployment, and (2) measures to ensure the explainability of AI outcomes. For generative AI applications, there should be specific measures to reduce AI hallucination risks by adopting techniques such as retrieval-augmented generation and prompt engineering. Financial service providers should also ensure explainability of AI outputs through documentation detailing model inputs, outputs, and parameters.
  • Cybersecurity risk. Financial service providers should have measures to prevent and detect emerging cyber threats targeting AI systems, based on established standards such as the OWASP Machine Learning Security Top 10.

In addition, the BOT emphasizes the importance of financial service providers strictly complying with applicable laws when adopting AI, including personal data protection laws and intellectual property laws.

RELATED INSIGHTS​ 

October 21, 2022
On September 21, 2022, the Electronic Transactions Development Agency (ETDA) held another public hearing on the draft Royal Decree on Digital Platforms and its sub-regulations. This updated draft Royal Decree on Digital Platforms (which is subsequent to a previous round of updates last year) is anticipated to be the final draft before it is proposed to the king for endorsement. Thereafter, it will be published in the Government Gazette and will become effective 240 days after the publication date. The key issues under the latest draft royal decree are as follows: Exemption for certain regulated businesses. The current draft royal decree exempts business operators that are regulated by the Bank of Thailand or the Securities and Exchange Commission, as well as digital platforms operated by government agencies for noncommercial purposes, from the application of the royal decree. Nevertheless, these business operators must ensure that their digital platform has transparency, fairness, and standards which are not less than those required under the Royal Decree. Definition of digital platform. According to the public hearing, the definition of a digital platform has been amended to exclude digital platforms that are used to offer the goods or services of a digital platform provider or its affiliate acting on its behalf, regardless of whether the offering of such goods or services is made to a third party or the affiliate. Appointment of a local contact. Instead of appointing a local representative with no limit of liability, the current draft royal decree only requires offshore digital platform providers to appoint a local contact to coordinate with the ETDA. The local contact must not operate any business in Thailand under the Foreign Business Act. Notification of the ETDA. Digital platforms as defined under the royal decree must notify the ETDA of certain information—such as the name
October 20, 2022
On October 1, 2022, the Vietnamese government promulgated Decree No. 71/2022/ND-CP (“Decree 71”) amending and supplementing Decree No. 06/2016/ND-CP (“Decree 06”) on the Management, Provision, and Use of Radio and Television Services. Decree 71 will take effect on January 1, 2023, at the same time as the new Cinema Law. Decree 71 is the result of the government’s long-time attempt to regulate the cross-border provision of “over-the-top” (OTT) television services, which deliver TV content to viewers over the internet, bypassing the traditional broadcast, cable, and satellite platforms, as well as to reinforce the requirements for content on demand. The key issues of Decree 71 are set out below. 1. Expanded Scope of Application Decree 71 expands the scope of Decree 06 to clearly cover OTT video-on-demand (VOD) services by amending some definitions: “Radio and TV services” is redefined to mean “services which provide intact domestic program channels and foreign program channels, on-demand radio and TV content [newly added], and value-added service content to users over radio and TV transmission and broadcasting infrastructure. Radio and TV services can be provided directly to service users without the use of storage or delay devices (online radio and TV services), or upon the specific request of subscribers (on-demand radio and TV services).” “On-demand radio and TV content” is newly defined to include “films, domestic programs, and foreign programs.” Films (phim in Vietnamese) follow the definition under the Cinema Law, and in this context include movies/feature films as well as what would be considered “TV shows” or “TV series” (e.g., scripted comedies and dramas) in other countries. Domestic and foreign “programs,” on the other hand, follow the definition of radio and TV programs under Article 3.10 of the Press Law: “a collection of news and articles in spoken or visual press about a topic
October 7, 2022
Thailand’s Office of the Personal Data Protection Committee (PDPC) has opened a public hearing period on its draft notification regarding cross-border transfer of personal data. The public hearing is open through October 24. The notification, once issued, will supplement the principle of cross-border transfer of personal data outside of Thailand set out in the Personal Data Protection Act (PDPA). The notification sets out the following key matters: Definitions “Transfer of personal data” means any sending or transferring of personal data by a transferor of personal data, either by way of a physical transfer or a remote transfer through a computer system or an internet network to the recipient of the personal data. It does not include sending personal data through an intermediary by transiting between computer systems or internet networks, or any storing or retaining of personal data, either permanently or temporarily, by a cloud computing service provider, whereby the personal data transferor and the personal data recipient (1) are not making the order, (2) are not involved with any data selection or the content of the personal data sent and received through the computer systems or internet networks, or (3) have the purpose of entering into an agreement or any juristic act. “Binding corporate rules” means the agreed terms or policy on personal data protection made between the personal data transferor and the personal data recipient to establish appropriate measures for safeguarding personal data within a group of corporations or companies. “Standard contractual clauses” means the contractual terms made between the personal data transferor and the personal data recipient to establish appropriate measures for safeguarding personal data. “Code of conduct” means a code that sets out the obligations of a personal data transferor and a personal data recipient outside of Thailand. “Certification” means an undertaking in relation to
September 21, 2022
Thailand’s Personal Data Protection Committee (PDPC) has released separate guidelines for data controllers to follow in obtaining data subjects’ consent and notifying data subjects of required information (i.e., regarding collection, use, or disclosure of their personal data). By following the guidelines, data controllers can mitigate the risk of violating the Personal Data Protection Act B.E. 2562 (2019) (PDPA). The Guidelines on Obtaining Consent from the Data Subject according to the PDPA and the Guidelines on Notification of Purposes and Details upon the Collection of Personal Data from the Data Subject according to the PDPA were issued on September 7, 2022. Consent Guidelines The PDPC’s guidelines on obtaining consent list the requirements for consent to be considered valid. These requirements include stipulations on timing of requests, elements that need to be included in requests, and the nature of requests. For instance, consent must be obtained before or at the time of obtaining personal data, and data subjects must be informed of both the purposes and details of the personal data handling, among other specific requirements. In turn, there must be a clear affirmative act of the data subject in giving consent. Obtaining consent from minors is subject to more stringent requirements, and data controllers should implement appropriate identification and age-verification measures when collecting personal data about minors. The guidelines give two sets of requirements, depending on the age of the minor—between 10 and 20, and under 10. In general, with the older age group, parental consent is not required in all circumstances, while for the younger age group, parental consent is compulsory for giving consent on behalf of the minor. For a person deemed to be “incompetent” or “quasi-incompetent,” consent must always be given by the legal guardian. Notification Guidelines The guidelines on notifying data subjects when collecting personal data