You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

December 1, 2016

Thailand: Office of Insurance Commission Approves Draft Notifications on e-Insurance

On November 29, the Office of Insurance Commission (OIC) in Thailand announced that it had approved, in principle, draft notifications that set out the criteria, procedures, and conditions for the issuing and offering for sale of both life and general insurance products through online channels.

The key features of the draft notifications are as follows:   

  • Insurance companies, brokers, and banks are permitted to sell insurance products through online channels. 
  • The wording of all insurance policies sold electronically must receive prior approval from the OIC, and insurance intermediaries may only sell policies electronically once they have received permission from the insurance company.
  • Confirmation calls are required within seven days from the issuance of an insurance policy. Insurance companies must record confirmation calls and keep the record for the period prescribed by law.
  • Strict liability has been imposed on insurance companies over their intermediaries in relation to the provisions of the notifications. The insurance companies must ensure that their intermediaries rigorously comply with the regulations, and they must withdraw permission from the intermediaries if any violations are found.
  • Insurance companies must establish a secured system for transacting online to prevent any data breaches. The secured system must align with the standards required by the Electronic Transactions Act and other related regulations.

If an insurance company makes use of a third-party service in order to pay a claim to the insured, the company must report the name of the third party to the OIC and must ensure that security measures are held to the standards of e-transaction laws. Insurance companies are responsible for ensuring that third-party service providers comply with all related regulations.

In addition to registering with the OIC, insurance companies, brokers, and banks are still required to register with other competent government authorities in order to comply with other applicable laws.

The OIC has indicated that it will arrange for another round of market consultation, and it aims to implement these regulations urgently, by early 2017.

If you have any questions, please contact Athistha (Nop) Chitranukroh, of counsel in Tilleke & Gibbins’ corporate and commercial group, at [email protected] or +66 2056 5600.

RELATED INSIGHTS​ 

August 14, 2026
Thailand’s Office of the Insurance Commission (OIC) has issued guidelines clarifying the boundaries between permissible and prohibited activities for unlicensed individuals—including influencers, bloggers, and content creators—when communicating about insurance products on social media. The Good Practice Guidelines for Persons Not Licensed as Insurance Agents or Brokers Regarding the Dissemination of Insurance Content Through Digital Media B.E. 2569 (2026) took effect on July 24, 2026. Activities Requiring a License The guidelines reserve the following activities for licensed agents and brokers: Soliciting or facilitating insurance contracts. Providing personalized advice on product suitability. Recommending policy cancellation to purchase promoted products. Creating links that facilitate contract formation. Receiving performance-based compensation tied to policies or premiums generated. Importantly, boilerplate disclaimers such as “this is not a recommendation to buy insurance” will not shield individuals from liability if the OIC views the content as personalized advice or solicitation. Permitted Activities Unlicensed persons may present general educational content about insurance—such as explaining terminology, sharing industry statistics, reporting news, or sharing personal experiences—provided the content does not target specific individuals to purchase from specific companies. The guidelines also set out best practices for communication, including presenting information in a fair and balanced manner that covers both benefits and limitations, encouraging consumers to read policy terms and consult licensed professionals, verifying information from credible sources before dissemination, and exercising special care when the audience may include vulnerable groups such as persons aged 60 and older. Prohibited Practices Prohibited practices include fear-based marketing, creating artificial urgency, omitting material limitations, making exaggerated claims, falsely claiming professional credentials, using fake engagement mechanisms, and sharing false or misleading content. The guidelines also reinforce the prohibitions under section 83 of the Life Insurance Act B.E. 2535 and section 78 of the Non-Life Insurance Act B.E. 2535 against soliciting insurance contracts with foreign operators
June 30, 2026
Tilleke & Gibbins’ insurance specialists in Bangkok provided Thomson Reuters’ latest country update on Thailand’s regulatory framework for the insurance industry. The country update, which is part of Thomson Reuters’ extensive Regulatory Intelligence offerings, contains information and guidance for insurers active in the Thai market. The guide covers the following topics in detail: Permission to operate; Legal and regulatory considerations for domestic and international insurers; Capital reserve requirements; Investment management and markets; The Office of Insurance Commission’s arbitration system for handling complaints; Creditor hierarchy; Rehabilitation of non-life insurance companies; and Personal data protection requirements for insurers. Thomson Reuters Regulatory Intelligence is a service that provides with curated news, analysis, and data across jurisdictions to help legal, risk, and compliance professionals manage compliance and mitigate global risk. The full Thailand insurance country update is available by subscription to Regulatory Intelligence on the Thomson Reuters website.
June 30, 2026
Insurance specialists from Tilleke & Gibbins have provided an update to the Vietnam chapter of Thomson Reuters’ Practical Law guide to insurance and reinsurance. The guide is a Q&A-style overview of insurance and reinsurance law in jurisdictions worldwide. The Vietnam chapter provides a detailed overview of the legal framework for the insurance and reinsurance market in the country, covering the following issues: Regulatory framework for insurance and reinsurance Authorization for insurers, reinsurers, and insurance intermediaries Ownership restrictions Ongoing requirements Penalties for noncompliance Sales and marketing of insurance and reinsurance Transfer of risk Reinsurance contracts and risks Contracts and policies Claims Dispute resolution Insolvency Tax Practical Law, a legal reference resource from Thomson Reuters, publishes a range of guides for hundreds of jurisdictions and practice areas. The insurance and reinsurance guide is a valuable resource for legal practitioners, covering numerous jurisdictions worldwide. To view the latest version of the guide, please visit the Practical Law website and enroll in the free Practical Law trial to gain full access.
June 5, 2026
Thailand’s Office of Insurance Commission (OIC) has opened a public hearing on proposed amendments to the OIC Notification on Criteria for Information Technology Risk Governance and Management for Life Insurance and Non-Life Insurance Companies B.E. 2563 (2020) via the centralized Law platform. The public consultation period runs from May 8, 2026, to June 9, 2026. The proposed amendments aim to elevate the IT risk governance and cybersecurity risk management framework to be more modern and aligned with international standards, with a focus on strengthening cyber resilience, enhancing the role of IT audits, and establishing data governance and data quality controls. The parties affected by these amendments include life insurance companies, non-life insurance companies, and external IT auditors. Key Changes Elevated Role of Board of Directors The proposed notification requires the company’s board of directors to oversee data governance, cybersecurity, and the responsible use of AI. Additionally, the board should include at least one director with IT knowledge or experience. Companies are also required to designate a head of security responsible for information security. The board’s duties are expanded to include oversight of data governance and AI usage, including establishing relevant policies and committees. Enhanced IT Security and Cybersecurity The revised notification consolidates the existing chapters on IT project management, IT security and cybersecurity to reduce redundancy, and introduces significant new measures. These include mandatory multi-factor authentication for material systems, enhanced data security measures such as data masking and data leakage prevention, security hardening requirements, web filtering, and mandatory vulnerability assessment and penetration testing at least annually. New requirements are also introduced for mobile application security, API security, and security measures for emerging technologies such as cloud computing and post quantum cryptography. The cybersecurity framework now encompasses identification, protection, detection, response, and recovery. The draft also introduces source code review