You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 23, 2016

Thailand: New Regulations for Financial Institutions on Accepting Deposits and Receiving Money from the Public

The Thai government recently promulgated new regulations for financial institutions on accepting deposits or receiving money from the public. The regulations aim to enhance the security and stability of these processes, and therefore improve the credibility of commercial banking business.

Under Bank of Thailand Notification SorNorSor 7/2559, financial institutions must set up mechanisms to ensure effective and accurate identification and verification of their customers, commonly referred to as “Know Your Customer” (KYC).

The regulations impose strict requirements and restrictions on accepting deposits of money or receiving money from the public via electronic means. This service is now restricted to natural persons, and financial institutions that provide this service must ensure that their e-KYC is available and effective. Risk management must also be improved.

The standard of the identification and verification process must be the same as services rendered to customers who are physically present at banks. If customers are not available in person, financial institutions must use electronic devices, such as video conferencing equipment, to enable bank officers to interview and observe a customer’s behavior on a real-time basis.

If financial institutions accept deposits of money or receive money from the public through a virtual teller machine, kiosk, computer, or other electronic device, they must examine the information and identification documents of their customers by using a smart card reader. They may use the government’s identification and verification system or its fingerprint verification system, together with their smart card reader, to be more accurate.

In addition, if financial institutions accept deposits of money or receive money from the public through applications prepared by themselves and run on the electronic devices of their consumers, including mobile phones, they must use the government’s identification and verification system together with its fingerprint verification system.

Financial institutions have until the end of this year to improve their internal systems, standards, and risk management. As these changes come into effect, both commercial banks and their customers will need to be prepared for a much higher level of scrutiny when financial institutions accept deposits and receive money from the public.

If you have any questions about these regulations or other banking-related matters, please contact Cynthia M. Pornavalai at [email protected] or +66 2653 5559.

RELATED INSIGHTS​ 

June 19, 2025
The Bank of Thailand (BOT) has released draft guidelines establishing principles for managing artificial intelligence (AI) risks in the financial sector. The draft guidelines provide a structured framework for the responsible adoption of AI technologies. Financial service providers will be able to use the guidelines as a reference to appropriately manage their risks in a manner that aligns with internationally recognized best practices. The BOT is accepting public comments on the draft guidelines until June 30, 2025. Scope and Application The draft guidelines apply to all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. These guidelines supplement existing BOT risk management guidelines covering IT risk management, third-party risk management, data governance, and market conduct. The guidelines define AI systems as systems that mimic human intelligence, including machine learning, deep learning, generative AI (such as large language models), and agentic AI. This definition specifically excludes rule-based automation systems like robotic process automation and condition matching. Key Risk Management Principles The guidelines lay out two main principles in managing AI risk. Governance: Financial service providers should define and establish clear roles and responsibilities for their personnel and AI system supervision structures to uphold FEAT (fairness, ethics, accountability, and transparency) principles as follows: Stakeholder roles and responsibilities. Financial service providers should define roles and responsibilities for boards and executives on AI risk oversight. Responsibilities include establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. AI system usage policy. The AI system usage policy should be aligned with organizational objectives, regulatory requirements, and FEAT principles. These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management
June 12, 2025
Thailand’s Ministry of Finance has issued a royal decree placing the business of hire purchase and leasing of cars and motorcycles under the scope of the Financial Institution Business Act B.E. 2551 (2008), effective December 2, 2025. This is to ensure appropriate regulatory oversight of these business activities, as they function similarly to credit granting and serve as a source of funding for the public with a broad impact on the overall economic system and consumers at large. The business operators that this royal decree applies to include corporate entities engaging regularly in the business of hire purchase or leasing of cars or motorcycles, currently excluding: Financial institutions and specialized financial institutions. Individuals operating such businesses (noncorporate entities). Cooperatives. Key regulatory obligations of this royal decree include the following: Business operators must disclose interest rates, service fees, and other relevant business information to the public and report to the Bank of Thailand (BOT). Business operators must display how the annual percentage rate (APR), including all annual charges covering interest and service fees, is calculated. Business operators must maintain accurate accounting records in accordance with recognized accounting standards. The BOT may issue warnings or suspend operations if business operators fail to comply with this royal decree or act unfairly in a way that may result in serious harm to customers. Directors, managers, and responsible persons of any business operator that violates this royal decree may also be subject to the prescribed penalties. Before the royal decree takes effect, business operators should conduct internal assessments and engage with counsel to prepare for regulatory implementation. The BOT is expected to issue further subordinate regulations and guidance regarding: Interest, service fees, deposits, collateral, benefits, and penalties that may be charged by business operators. Contract content, methods of benefit calculation, and format in conducting
May 28, 2025
Tilleke & Gibbins attorneys in Vietnam have contributed the 2025 edition of Doing Business in Vietnam, a comprehensive Q&A-style resource from Thomson Reuters Practical Law that provides essential insights for companies navigating business operations in Vietnam. The guide presents a detailed overview of the country’s legal framework and regulatory environment, reflecting recent updates in Vietnamese legislation and practice. This annually updated guide offers key information on the following areas: Legal system: Structure of the Vietnamese judiciary and the role of codified law. Foreign investment: Conditions for market access, licensing requirements, foreign ownership restrictions, and investment incentives. Business vehicles: Formation and operation of legal entities, including limited liability companies, joint-stock companies, and representative offices. Employment: Employment contracts, social insurance, labor rights, and procedures for hiring foreign nationals. Tax: Overview of corporate income tax, personal income tax, value-added tax, and other tax obligations. Intellectual property: Procedures for protecting and enforcing patents, trademarks, copyrights, and other IP rights. Data protection: Compliance requirements under Vietnam’s data privacy laws, including the Personal Data Protection Decree. Competition law: Antitrust rules and regulatory oversight under the Law on Competition. Anti-bribery and corruption: Legal framework and enforcement practices aimed at curbing corrupt activities. E-commerce and digital business: Regulations governing online platforms, digital content, and cross-border services. Marketing and advertising: Laws and guidelines on advertising standards and consumer protection. Product regulation and liability: Safety requirements, product liability issues, and roles of relevant authorities. Doing Business in Vietnam is part of Practical Law’s global series of legal guides designed to support international practitioners and businesses. To access the most recent edition of the Vietnam guide, visit the Practical Law website and sign up for a free trial.
May 5, 2025
On April 29, 2025, the government of Vietnam promulgated Decree No. 94/2025/ND-CP with regulations on a controlled “sandbox” for innovative fintech solutions in the banking sector (Decree 94). The decree aims to promote innovation, modernize banking, and enhance financial inclusion while assessing risks and benefits of fintech solutions in a controlled testing environment. Fintech Sandbox Currently, the fintech sandbox focuses on three specific areas: Credit scoring Open API data sharing Peer-to-peer (P2P) lending Eligible participants for the fintech sandbox include: Credit institutions and foreign bank branches (except for P2P lending) Fintech companies operating in Vietnam Cross-border supply by foreign providers is not included in the sandbox framework. Eligible participants are permitted to provide fintech solutions only within the scope specified in the Certificate of Sandbox Participation issued by the State Bank of Vietnam in consultation with other ministries. P2P lending companies face specific restrictions within the fintech sandbox, including prohibitions against: Providing security for customer loans Operating as a customer (i.e., P2P lender or borrower) Providing P2P lending solutions to pawn shops The maximum sandbox period is two years, with the possibility of extension as permitted by law. The outcomes of the fintech sandbox will serve as a practical basis for authorities to develop and refine future fintech regulations. It is worth noting that participation in the sandbox does not guarantee that participants will meet relevant business and investment conditions that may be stipulated in future regulations. Decree 94 will take effect on July 1, 2025, signaling that the Vietnamese government intends to take a proactive approach to fostering fintech development. Implications Parties interested in participating in the fintech sandbox should begin preparing now to be ready to apply for a Certificate of Sandbox Participation when the decree takes effect.