You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

December 26, 2025

Thailand Issues Mandatory Guidelines Enhancing Digital Fraud Controls

The Bank of Thailand (BOT) has released the Guidelines for Digital Fraud Management, which took effect on December 17, 2025, incorporating certain amendments to the draft guidelines issued in March 2025. These official guidelines aim for end-to-end digital fraud prevention, with a particular focus on mule accounts, to enhance trust and security in Thailand’s financial system.

The guidelines apply to “financial service providers,” including:

  • Financial institutions and special financial institutions under the Financial Institution Business Act; and
  • Operators of Inter-institutional Fund Transfer System e-money services and e-fund transfer services under the Payment Systems Act.

Besides commercial banks and e-money operators that offer fund-transfer services, other providers may adopt requirements based on risk proportionality and baseline standards set out in the guidelines (for instance, an e-money operator that does not offer e-fund transfer services could consider implementing a fraud monitoring and detection system according to the risk level of its service).

The guidelines establish the following key requirements:

  • Policy and oversight. Directors and senior executives of financial service providers must adopt appropriate “end-to-end” fraud management policies and KPIs to manage digital fraud, covering prevention, monitoring, detection, management, resolution, and support for affected customers. The fraud management policy must be regularly reviewed, and whenever there is a situation or change that significantly affects the efficiency of the fraud management. Any significant update to the policy must first be approved by the board of the financial service provider. The BOT also encourages providers to collaborate in establishing industry standards aligned with applicable laws and regulations to ensure consistency and best practices across the sector.
  • Fraud management processes. Financial service providers must establish a clear framework for managing digital fraud throughout the customer lifecycle—from customer onboarding to service termination—covering at least the following processes:
    • Know your customer (KYC) and customer due diligence (CDD): The KYC procedure must also include identification of account operating objectives, and the financial service provider must conduct CDD according to the Anti-Money Laundering Act B.E. 2542 (1999).  If customer behavior signals that the customer is a potential owner of mule accounts (i.e., deposit or e-money accounts used as tools to receive and transfer funds obtained through the commission of technology crime), enhanced CDD must be applied. Providers must assess and classify customers based on their risk level for being mule account owners or fraud victims, using information from KYC, CDD, and reliable sources. Risk classifications must remain current and reflect prevailing circumstances.
    • Fraud monitoring and detection: Providers must develop proactive processes to detect and monitor unusual transactions and utilize data from multiple sources (e.g., Central Fraud Registry and data obtained from other financial service providers) to identify potential mule accounts and fraud. This may involve adopting new technologies (e.g., artificial intelligence) to enhance efficacy and stay ahead of emerging fraud techniques.
    • Action and response to fraud: Providers must develop swift and appropriate measures to prevent, limit, and promptly mitigate digital fraud damage, including handling suspected mule accounts. They must also respond clearly, fairly, and swiftly to support customers affected by fraud (e.g., by offering 24/7 customer support through dedicated hotlines and electronic channels, having clear timeframes for assisting customers affected by fraud incidents, and reporting to the BOT any incidents that cause widespread customer damage or affect the financial service provider’s reputation).
  • Information sharing. Financial service providers must have mechanisms to share accurate information promptly with one another, according to the framework under the law on technology crime suppression and other relevant laws, and must appoint a responsible person to coordinate and procure information necessary for any investigations.
  • Awareness. Financial service providers must proactively raise customers’ and the public’s awareness of digital fraud to prevent and reduce potential damage. Required actions include disseminating information on an easily accessible service channel (e.g., mobile app or infographic on social media). The BOT also encourages financial service providers to have customers take awareness tests.

RELATED INSIGHTS​ 

March 27, 2024
Last year, the government of Vietnam issued the Personal Data Protection Decree (PDPD), which took effect on July 1, 2023. The Department of Cybersecurity and High-Tech Crime Prevention and Control (referred to as “A05”) under the Ministry of Public Security (MPS) is tasked with implementing and enforcing the requirements under the PDPD. While a decree on sanctioning provisions for noncompliance with the PDPD is still pending issuance, further movements from the MPS/A05 indicate that it aims to start conducting its first inspections into PDPD compliance. This is the first time that companies and government agencies have been officially questioned by the MPS about their compliance with the PDPD. The purposes of this inspection program are (1) to evaluate the compliance status of a group of selected companies and government agencies and to understand challenges in complying with the PDPD requirements; (2) to propose sanctions for noncompliance; and (3) to collect information and comments for the development of the upcoming Personal Data Protection Law—not to spot noncompliance with the PDPD specifically. This round of inspection includes a number of companies in 14 sectors (including e-commerce, aviation, telecom, banking and finance, intermediary payment, insurance, gaming, education, healthcare, real estate, data processing services, ride hailing, etc.). The companies targeted by this inspection program must: (1) submit a report on compliance to the MPS/A05 by May 30, 2024 (this report is different from the data protection impact assessment (DPIA)/transfer impact assessment (TIA) submission requirements); and (2) coordinate with the MPS/A05 on any further investigation actions from June to August 2024. The inspection results will be available by September 2024. Key information to be reported includes, among others: (1) a description of the activities and measures carried out to implement the PDPD (such as protecting data subjects’ rights, performing administrative procedures, preventing violations, etc.)
March 18, 2024
Vietnam’s new Telecom Law 2023 was promulgated on November 24, 2023, and will take effect on July 1, 2024, for most telecom services. For three newly introduced telecom services—OTT telecom services, internet data center services, and cloud computing services—implementation and compliance will be delayed until January 1, 2025. These new services will be explored briefly below. The Ministry of Information Communication (MIC) is currently in the process of developing a number of decrees and circulars that will detail the implementation of the Telecom Law 2023, including one main decree that guides the new law in general. This decree is scheduled for prompt promulgation to coincide with the law’s effective date of July 1, 2024. The draft version of this decree, dated February 22, 2024 (“Draft Decree”), was shared for consultation with international organizations, associations, and enterprises by the Vietnam Telecom Agency (VNTA) in early March 2024 to gather feedback. The Draft Decree is expected to undergo further revisions before being sent to relevant state agencies for input and submission to the Ministry of Justice for assessment by the end of March 2024. The MIC anticipates submitting the subsequent version to the government by April 15, 2024.   New Telecom Services: OTT Telecom Services, IDC Services, and Cloud Computing Services In comparison to the Telecom Law 2009, the Telecom Law 2023 has three new telecom services: Basic telecommunications services on the internet (OTT telecom services) are defined as services whose primary functions including the sending, transmission, and receipt of information between two persons or a group of people using telecommunications services on the internet (Article 3.8 of the Telecom Law 2023). By incorporating the term “primary functions” into the definition, the Telecom Law 2023 aims to exclude services such as ride-hailing platforms where the primary function is transportation, not telecom
March 15, 2024
Vietnam’s fintech industry is booming, and the rapid emergence of tech startups and non-bank institutions offering innovative financial services has been outpacing existing regulations. This regulatory gap not only creates uncertainty for both innovators and consumers, but also poses a number of imminent risks in areas such as consumer protection, data privacy, cybersecurity, and anti-money laundering, among others. The State Bank of Vietnam (SBV) is stepping up to tackle these challenges by accelerating the promulgation of a long-awaited Fintech Sandbox Decree with the issuance of an updated draft (“Draft Fintech Sandbox Decree”) on March 4, 2024. The Draft Fintech Sandbox Decree establishes a controlled environment where fintech companies and financial institutions can test solutions that do not fall squarely within the parameters of existing regulations. The pilot activities will be limited in scope, scale, and duration, with a number of precautionary measures in place. The SBV will supervise this “sandbox” closely, effectively mitigating risks and gathering valuable data to inform future regulations. Who Can Participate in the Sandbox? Traditional financial institutions (credit institutions): Banks and other institutions licensed to provide financial services can participate in the sandbox to test new offerings or refine existing ones. Independent fintech companies: Startups and established companies specializing in fintech solutions can leverage the sandbox to pilot innovative ideas before seeking wider market adoption. Other relevant organizations involved in the pilot: Depending on the specific solution being tested, other entities may also be involved in the sandbox. Geographical scope: Limited to Vietnamese territory; cross-border testing is not allowed. Focusing on Three Solution Categories Earlier versions of the Draft Fintech Sandbox Decree included categories like blockchain technology and other innovative business models, but these were removed in the latest version. To allow the SBV to assess the associated risks and work on the solutions more
March 12, 2024
Thailand’s Ministry of Finance has issued the Notification re: Criteria, Methods and Conditions for Applying for and Issuing Licenses to Operate Virtual Bank Business, which was published in the Government Gazette on March 4, 2024. This notification opens an opportunity for qualified experts in technology, digital services, and diverse data usage fields to apply for virtual bank licenses to provide financial services through new digital channels. The main goal is to serve the financial needs of target groups that may not have received sufficient or tailored financial services from the traditional banking system. Licensing Timeline Application submission period: 6 months (March 20–September 19, 2024). Announcement of successful applicants: Mid-2025 (approx. 9 months–1 year from the end of the submission period) After the announcement, successful licensees must demonstrate their readiness to commence virtual bank operations within 1 year (extendable for up to 1 additional year) via the following: Having paid-up registered capital of THB 5 billion and plans to increase the paid-up registered capital to at least THB 10 billion after the initial business period; Establishment or adjustment of a financial business group; Procurement of human resources, IT systems, and relevant risk management tools. Number of Licenses to be Issued No written or specified limit, subject to the discretion of the Bank of Thailand (BOT). Key Qualifications Applicants must have the following: Experience and resources to support virtual banking operations according to the business model and plan. Expertise and experience in conducting business that utilizes technology and provides services through digital channels. Experience demonstrating the ability to obtain, access, manage, and utilize data, including development of systems or data connections to facilitate user activities, allowing them to use their data to conduct transactions with other providers. Criteria In assessing applicants’ qualifications for a virtual bank license, the BOT will consider