You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 8, 2025

Thailand Opens Public Hearing on Amended Reporting Requirements for Insurance Companies

Thailand’s Office of Insurance Commission (OIC) has opened a public hearing period on its amendments of notifications concerning the timeframe for an insurance company to submit its annual financial statements and financial and operating reports (called “XML reports”). The amended notifications also require insurance companies to submit some data sets from the quarterly capital maintenance reports and XML reports to the OIC in advance, before the full reports are submitted.

Key changes in these amended notifications are summarized below.

Financial Statements

Audited annual financial statements will need to be submitted to the OIC within two months from the last day of each calendar year (i.e., by the end of February of the following year), instead of within four months as currently required.

Capital Maintenance Reports

While the deadline for submitting quarterly capital maintenance reports is still 45 days from the last day of the quarter, the OIC will now require life and non-life insurance companies to submit a set of data from the report in advance, within 21 days from the last day of each quarter. This data set includes the following information from the capital maintenance report:

  • Form 1 – Calculation of Capital Adequacy Ratio (CAR)
  • Form 2 – Calculation of Total Capital Available (TCA)
  • Form 4 – Calculation of Capital for Insurance Risk (Table 4.1, 4.2, 4.4, and 4.5 for life insurance companies; Table 4.1 and 4.2 for non-life insurance companies)

Financial and Operating Reports (XML Reports)

Similar to the audited annual financial statement, the annual XML report will need to be submitted to the OIC within two months from the last day of each calendar year, instead of within the current four-month timeframe.

For quarterly XML reports, which must still be submitted within 45 days from the last day of each quarter, there is a new requirement for life and non-life insurance companies to submit a set of data from the XML report in advance, including the following information:

  • L1210 / NL1210 – Assets
  • L1220 / NL1220 – Liabilities and Equity
  • L1300 / NL1300 – Operating Report
  • L1400 / NL1400 – Equity
  • L3301 / NL3301 – List of Legal Assets and Liabilities

The above set of data, whether audited or unaudited, must be submitted to the OIC within 21 days from the last day of each quarter.

Outlook

The amended rules are set to take effect from September 1, 2025. It is therefore essential for insurance companies to prepare for the upcoming regulatory changes, as the timeframe for submitting the reports and the data sets will be tightened.

In the meantime, if there are any comments or concerns, the public hearing is open until August 18, 2025.

RELATED INSIGHTS​ 

June 30, 2026
Insurance specialists from Tilleke & Gibbins have provided an update to the Vietnam chapter of Thomson Reuters’ Practical Law guide to insurance and reinsurance. The guide is a Q&A-style overview of insurance and reinsurance law in jurisdictions worldwide. The Vietnam chapter provides a detailed overview of the legal framework for the insurance and reinsurance market in the country, covering the following issues: Regulatory framework for insurance and reinsurance Authorization for insurers, reinsurers, and insurance intermediaries Ownership restrictions Ongoing requirements Penalties for noncompliance Sales and marketing of insurance and reinsurance Transfer of risk Reinsurance contracts and risks Contracts and policies Claims Dispute resolution Insolvency Tax Practical Law, a legal reference resource from Thomson Reuters, publishes a range of guides for hundreds of jurisdictions and practice areas. The insurance and reinsurance guide is a valuable resource for legal practitioners, covering numerous jurisdictions worldwide. To view the latest version of the guide, please visit the Practical Law website and enroll in the free Practical Law trial to gain full access.
June 5, 2026
Thailand’s Office of Insurance Commission (OIC) has opened a public hearing on proposed amendments to the OIC Notification on Criteria for Information Technology Risk Governance and Management for Life Insurance and Non-Life Insurance Companies B.E. 2563 (2020) via the centralized Law platform. The public consultation period runs from May 8, 2026, to June 9, 2026. The proposed amendments aim to elevate the IT risk governance and cybersecurity risk management framework to be more modern and aligned with international standards, with a focus on strengthening cyber resilience, enhancing the role of IT audits, and establishing data governance and data quality controls. The parties affected by these amendments include life insurance companies, non-life insurance companies, and external IT auditors. Key Changes Elevated Role of Board of Directors The proposed notification requires the company’s board of directors to oversee data governance, cybersecurity, and the responsible use of AI. Additionally, the board should include at least one director with IT knowledge or experience. Companies are also required to designate a head of security responsible for information security. The board’s duties are expanded to include oversight of data governance and AI usage, including establishing relevant policies and committees. Enhanced IT Security and Cybersecurity The revised notification consolidates the existing chapters on IT project management, IT security and cybersecurity to reduce redundancy, and introduces significant new measures. These include mandatory multi-factor authentication for material systems, enhanced data security measures such as data masking and data leakage prevention, security hardening requirements, web filtering, and mandatory vulnerability assessment and penetration testing at least annually. New requirements are also introduced for mobile application security, API security, and security measures for emerging technologies such as cloud computing and post quantum cryptography. The cybersecurity framework now encompasses identification, protection, detection, response, and recovery. The draft also introduces source code review
April 9, 2026
Thailand’s Office of the Insurance Commission (OIC) has published two parallel sets of draft regulatory amendments for public hearing—one governing non-life insurance and the other governing life insurance. The proposed amendments would significantly revise the rules for issuing, offering, and selling insurance policies, as well as the conduct of agents, brokers, and banks. Stakeholders may submit comments until April 25, 2026. The key proposed changes are summarized below. Electronic Policy Delivery by Default Under both draft amendments, electronic delivery would become the default method for delivering insurance policies. A printed copy would be required only if the policyholder expressly opts out, and any such printed copy would be treated as a substitute for the electronic original. For life insurance, this requirement would also extend to coverage summaries and to exclusion documents. The OIC would also retain authority to approve alternative delivery methods for specific types of policies. Misuse of Licenses Both amendments would introduce an explicit prohibition against sales representatives using another person’s name or license, or allowing another person to use their name or license, in connection with the offering of insurance or in sales documentation and policies. Premium Collection Reforms Both amendments would introduce the premium collection reforms outlined below. Premium receipt accounts Insurers must ensure that sales representatives inform customers of the available payment channels, which are limited to channels that remit premiums into the insurer’s account. If a customer pays an insurance premium to an insurer’s employee, an insurance broker, or any other person, and the company acknowledges the payment by issuing an insurance policy or other documentary evidence of insurance coverage, the insurer would be deemed to have received the insurance premium. Written premium collection and refund guidelines Insurers would be required to prepare written internal guidelines covering premium collection and refund policies, risk
April 2, 2026
Thailand’s Personal Data Protection Act (PDPA) enforcement has entered a new phase, and the insurance industry is squarely in the regulatory spotlight. The Personal Data Protection Committee (PDPC) considers insurers “large-scale” processors of sensitive data—including health records, financial information, and biometric data—making the sector a focal point for enforcement action. In August 2025 alone, the PDPC issued administrative fines totaling THB 21.5 million, and fines for individual violations have ranged from THB 50,000 to THB 2 million. The PDPC has also deployed its “Eagle Eye Crawler,” an AI-driven surveillance tool that monitors websites around the clock for data leaks and noncompliant privacy notices. This article highlights the key regulatory developments directly affecting insurers and outlines practical steps toward compliance. What Has Changed: OIC and PDPC Alignment The Office of Insurance Commission (OIC) has synchronized its sector-specific rules with the PDPA through the Notification on Customer Personal Data Protection (No. 2) B.E. 2568 (2025). The combined effect of the PDPC’s general enforcement push and the OIC’s sectoral guidance creates four critical compliance areas for insurers. Consent unbundling. Consent for marketing must be strictly separated from the core insurance contract; bundling marketing consent into the policy application is no longer permissible. Agent and intermediary oversight. Insurance intermediaries are generally classified as data processors, meaning that insurers—as data controllers—must provide specific written instructions and security protocols to all agents and brokers. A 2026 enforcement trend shows controllers being held liable for the “weak security” of their vendors and downstream processors. Enhanced privacy notices. Insurers must provide a summary privacy notice alongside the full policy, plainly stating categories of data, purposes, lawful bases, disclosure recipients, cross-border transfers, retention periods, data subject rights, and easy marketing opt-out channels. DPO registration and ROPA. All organizations involved in “regular or systematic monitoring of data subjects on