You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

October 9, 2017

Thailand: New Risk Management Regulation for Insurance Companies to Take Effect in February 2018

The Office of the Insurance Commission (OIC) has issued notifications applicable to life and non-life insurance companies, which are intended to emphasize the importance of internal risk management in insurance companies. The notifications were published in the Government Gazette  on September 1, 2017, and will take effect 180 days later on February 28, 2018.

The notifications contain several requirements that life and non-life insurance companies must comply with:

  • A Risk Management Committee (RC) must be established, with at least one member being a director, and the others being company executives or qualified persons with an understanding of enterprise risks. The RC will be required to convene and provide a report to the board of directors quarterly. Foreign insurers in Thailand may satisfy this requirement by utilizing an RC established at their company headquarters or regional office.
  • A risk management function must be set up to manage and monitor enterprise risks and produce status reports on all risks to the company.
  • A risk officer (i.e., the head of the risk management function) must be appointed. The company must report the appointment or withdrawal of the risk officer to the OIC within 30 days.
  • A risk management framework and policy, and three-year business plan, must be submitted to the OIC annually. Potential risks arising from the business plan, and the top ten recorded risks to the company, must be mentioned in these documents.
  • An internal audit department must be assigned to monitor and assess the company’s compliance with its risk management framework and policy, and report assessment results to an audit committee or the board of directors at least annually.
  • The company must inform employees about the objectives and benefits of risk management, and provide training sessions to employees to integrate a risk management culture into everyday business operations.

It is important to note that the OIC may require any specific insurance company (or the entire industry) to perform “stress tests” on a case-by-case basis.

RELATED INSIGHTS​ 

February 19, 2021
Insurance specialists from Tilleke & Gibbins’ Bangkok office have provided an update to the Thailand chapter of Thomson Reuters’ Practical Law guide to insurance and reinsurance. The guide is a Q&A-style overview of insurance and reinsurance law in 41 jurisdictions worldwide. The Thailand contribution opens with a detailed overview of the insurance and reinsurance market in Thailand, including information on market trends, the available corporate structures, and relevant regulations. The Q&A is then separated into three main sections: Operating restrictions: licensing, ownership restrictions, ongoing requirements (compliance) and penalties for noncompliance, selling restrictions, and monitoring and disclosure requirements. Insurance and reinsurance policies: establishing an insurance claim, third party insurance claims, time limits, enforcement, remedies, and punitive damage claims. Other business concerns for insurance and reinsurance providers: insolvency, taxation, insurance and reinsurance dispute resolution, and legal reform. Practical Law produces a numbers of guides to key legal practice areas around the world for business lawyers. Tilleke & Gibbins contributes many overviews to these guides for all of the firm’s jurisdictions in Southeast Asia. To read the full Thailand insurance and reinsurance chapter, please visit the Practical Law website.
February 18, 2021
As you will no doubt know, on February 1, 2021, the Myanmar military declared a state of emergency in Myanmar for a period of one year. State Counsellor Daw Aung Sang Su Kyi was detained, as were the president and various significant political and civil leaders. Min Aung Hlaing, commander-in-chief of the Tatmadaw (Myanmar armed forces) has installed himself as chairman of the State Administration Council, the current administration. New sanctions The reaction of the Biden administration has been swift. On February 10, 2021, President Biden issued Executive Order 14014, which provides bases to impose sanctions on individuals and companies deemed by the US to, among other things: operate in the defense sector of Myanmar; be responsible for policies that undermine democratic processes in Myanmar; have taken actions to undermine democratic processes or institutions, or prohibit, limit, or penalize the exercise of free speech, in Myanmar; or be a spouse or child of the foregoing. On the next day, February 11, the US Office of Foreign Assets Control (OFAC), imposed sanctions under the new executive order on ten individuals—including General Min Aung Hlaing—and three companies, including Cancri Gems & Jewelry Co, Myanmar Imperial Jade Co, and Myanmar Ruby Enterprise.  All such individuals and companies have now been designated on the US list of specially designated nationals (SDNs). Effect of sanctions As a result of such sanctions, the property of these individuals or companies that is located in the US or is under the possession or control of US companies and citizens is frozen, and US companies and citizens are generally prohibited from dealing deal with any such property.  Reportedly, roughly USD 1 billion of funds belonging to the individuals and companies blocked on February 11 are located in the US and thus now frozen. The SDN list As many
January 13, 2021
Thailand’s Office of the Insurance Commission (OIC) recently issued two notifications—one for life-insurance companies and another for insurance companies—establishing key criteria and requirements for insurance companies to manage risks relating to IT and cybersecurity. The notifications, entitled Notifications Re: Criteria for the Supervision and Management of Risks Relating to Information Technology for Life/Non-life Insurance Companies B.E. 2563 (2020) came into effect on January 1, 2021, and cover eight major aspects of IT risk management as detailed below. IT Governance Insurance companies are required to monitor and manage IT risks and cyber threats in accordance with the size, characteristics, complexity, and context of their business operations, and each company should have at least one director with knowledge of, or past experience in, the field of information technology. IT Project Management Insurance companies are required to develop a written framework for IT project management, covering at least the commencement, implementation, and control of the project, as well as the project closing and post-project auditing. Companies must also appoint a committee for supervising and monitoring IT projects. IT Security Insurance companies are required to institute a written IT security policy, which must be reviewed at least once a year or upon implementing any significant changes. The policy must be approved by the board of directors, or a relevant subcommittee appointed by the board of directors. In outsourcing IT activities to third-party service providers, or entering into any arrangement that allows business partners to connect to or access the company’s IT system, insurance companies are required to specify their own criteria and procedures for the selection of third-party service providers, enter into a written service agreement and a service level agreement with the third-party provider, and conform with other requirements under the notifications. Insurance companies will also be required to comply with the OIC’s forthcoming