You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

September 24, 2025

Thailand Issues AI Risk Management Guidelines for Financial Service Providers

On September 12, 2025, the Bank of Thailand (BOT) officially released its AI Risk Management Guidelines for Financial Service Providers, building upon the draft guidelines issued in June 2025. The guidelines reflect a balanced approach, encouraging innovation while safeguarding financial stability and consumer protection.

The guidelines are targeted at all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act.

The guidelines apply to both AI systems developed in-house and those developed by third parties that are adopted for use by financial service providers.

AI Risk Management Guidelines

The two main pillars in managing AI risk are (1) governance of AI system implementation and (2) AI system development and security controls, consisting of the following key elements:

1. Governance

  • Stakeholder roles and responsibilities. Boards and senior management assume accountability for decisions and operations involving AI systems, and are responsible for defining roles and responsibilities for AI oversight. This includes establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. Organizations are expected to foster internal capabilities to use AI securely and avoid overreliance that could compromise business continuity or customer service.
  • AI system usage policy. Policies governing AI usage should align with organizational goals, regulatory obligations, and recognized responsible AI frameworks—such as the FEAT principles (fairness, ethics, accountability, and transparency). These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles.
  • Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. Financial service providers should assess risks and impacts of AI usage on operations and customer services. Human oversight must be embedded in decision-making processes, with the degree of oversight calibrated to the level of risk and impact, especially when AI systems are used in strategic functions or customer interactions (e.g., loan approval or account opening). In customer interactions with AI systems, customers should be notified and have options to contact personnel of financial service providers.
  1. Development and security controls
  • Data risk. Financial service providers should have measures to assess and ensure the quality, accuracy, currentness, volume, and diversity of data used in AI model training. They should also implement data leakage prevention measures.
  • Model development risk. Financial service providers should have (1) clear evaluation metrics for assessing model accuracy and reliability through ongoing testing and monitoring, both before and after deployment, and (2) measures to ensure the explainability of AI outcomes. For generative AI applications, there should be specific measures to reduce AI hallucination risks by adopting techniques such as retrieval-augmented generation and prompt engineering. Financial service providers should also ensure explainability of AI outputs through documentation detailing model inputs, outputs, and parameters.
  • Cybersecurity risk. Financial service providers should have measures to prevent and detect emerging cyber threats targeting AI systems, based on established standards such as the OWASP Machine Learning Security Top 10.

In addition, the BOT emphasizes the importance of financial service providers strictly complying with applicable laws when adopting AI, including personal data protection laws and intellectual property laws.

RELATED INSIGHTS​ 

March 10, 2022
On March 7, 2022, the government of Vietnam issued Resolution No. 27/NQ-CP (“Resolution 27”) approving the promulgation of the latest version of the Draft Decree on Personal Data Protection (“Draft PDPD”) prepared by the Ministry of Public Security (“MPS”), and further instructed the MPS to pass this draft to the National Assembly’s Standing Committee for final consideration. Although the full content of the approved Draft PDPD has not been made available to the public, Resolution 27 clearly sets out several circumstances approved by the government in which processing of personal data can be carried out without the consent of the data subjects. In comparison with the corresponding provision under the widely seen version of the Draft PDPD made available to the public in February 2021 (“February Draft”), the main differences are as follows: If the data processing is necessary in response to an emergency situation that threatens the life, health, or safety of the data subject or other individual, the data controller, data processor, data controller/processor, or a third party can process the personal data without consent of the data subject, but they are responsible for proving that the situation is an emergency. The February Draft did not mention any requirement of proof. Moreover, “safety of the data subject or other individual” is a newly added criterion for personal data processing without consent under this circumstance. If the data processing is necessary because of national defense and security requirements, the processing must be carried out by competent authorities in accordance with other laws. The requirement that the processing must be carried out “by competent authorities” in this circumstance was not provided under the February Draft. Two circumstances have been removed: the processing of personal data in compliance with specific provisions that explicitly allow the processing of personal data without
March 8, 2022
On February 15, 2022, Thailand’s cabinet approved in principle a package of incentives to promote electric vehicle (EV) adoption in Thailand, with the aim of making the country an EV manufacturing hub in Asia. A week later, the cabinet approved further draft regulations including specific information on customs duty reductions and exemptions for certain types of imported EVs. The plan includes both tax and non-tax incentives from 2022 until 2025. In the first two years (2022–2023), the package incentivizes the widespread use of EVs in Thailand by providing exemption or reduction of import duties and excise tax, as well as subsidies to increase the demand for EVs and attract investment in the EV industry. These incentives will cover the importation of completely built up (CBU) cars and motorcycles, and the local manufacturing of completely knocked down (CKD) vehicles in Thailand. For the following two years (2024–2025), the plan promotes the use of domestically produced EVs by eliminating the exemption or reduction of import duties for CBU vehicles while maintaining the other incentives (e.g., reduced excise tax rates, and subsidies). The aim of this is to make the cost of CBU vehicles higher than locally produced vehicles to encourage operators to produce EVs in the country to meet increasing demand. Additional measures encourage the manufacturing of EVs in Thailand, including exemption of import duties for parts imported between 2022 and 2025, and treatment of the value of imported battery cells as a cost of local manufacturing (up to 15% of an EV’s retail price). This is beneficial to local manufacturers of EVs, as their activities will be entitled to a more generous incentive package than importation of EVs. At their meeting on February 22, 2022, Thailand’s cabinet further approved draft subordinate regulations, including specific reductions and exemptions of customs duty
February 21, 2022
On February 14, 2022, Thailand’s Securities and Exchange Commission (SEC) announced a public hearing period on proposed advertising regulations for digital asset businesses. The public hearing period is now open for general comments until March 15, 2022. In the announcement, the SEC expressed their intention to provide clear digital asset advertising principles that conform to regulations in other countries, such as Singapore, the UK, and Japan. The SEC, in a meeting on February 3, agreed that the principles to be developed should apply to all digital asset businesses operating in Thailand. During the public hearing period, any interested parties may comment on the SEC’s proposed principles, which include the following key points: Advertisements that educate, inform, or give facts about digital assets, investments or services, or that provide an overall picture of digital assets, must not exaggerate, distort, or conceal information, or otherwise mislead consumers. In addition, advertisements that refer to customer numbers must only indicate the number of customers who have received approval to open an account and who are ready to use the service. Advertisements must be clear and appropriate, provide a warning on investment risks, and include clear and noticeable SEC-mandated statements in the font size stipulated by the SEC. Advertisements that present positive information or suggest an opportunity to receive returns must provide a balanced view that also discloses negative information or states investment risks. Advertisements relating to cryptocurrencies can only be made via a business operator’s official channels (e.g., the operator’s website, app, or other official online channel), and cryptocurrency cannot be advertised in public areas (e.g., billboards, public transportation, websites, newspapers and periodicals, etc.). However, advertisements for the services of a digital assets business can still be made in public areas and other channels. For example, this can be understood as meaning that
February 15, 2022
The sale of counterfeit goods online is as damaging to government efforts and consumer safety as it is to the reputation of the e-commerce platforms and brand owners involved. In this guest piece, Andy Chua, senior vice president of the IP Rights Protection Team at e-commerce giant Lazada, joins Tilleke & Gibbins’ Suebsiri Taweepon and Ploynapa Julagasigorn to discuss how stakeholders can work together to combat the growing threat of counterfeits online – with recent efforts in Thailand a prime example of effective action. This article, which was first published in World Trademark Review, is the second in a two-part series about trademark enforcement against online counterfeits.   Technological developments, government policy and the covid-19 pandemic have brought about significant changes to the lifestyle and behaviour of ordinary consumers. Shopping increasingly takes place on e-commerce platforms as people become more familiar with online transactions, encouraging many sellers to turn their focus to online platforms. While this shift to online retail has brought benefits for many, it has also provided additional ways for sellers of counterfeit goods to peddle their wares. The sale of counterfeit goods online tarnishes the reputation of e-commerce platforms among users, compromises consumer trust in brand owners’ products and undermines public authorities’ efforts in enforcing anti-counterfeiting policies. This dynamic problem cannot be resolved by a single entity alone. Instead, all stakeholders need to work together to amplify their efforts in consumer and brand protection. Collaborating against counterfeits in Thailand We see such collaborations between stakeholders in regions such as Thailand, where the Department of Intellectual Property (DIP) has signed a memorandum of understanding (MOU) with various parties that are committed to combatting the spread of counterfeit products online. The inaugural signing ceremony for the MOU was held on 11 January 2021, with 20 initial signatories drawn