You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 18, 2026

Thailand Proposes Expanded KYC and Due Diligence for Cash-related Transactions

The Bank of Thailand (BOT) is seeking public comment on proposed amendments that would significantly expand know-your-customer (KYC) and customer due diligence (CDD) requirements for cash-related transactions at financial institutions (FIs) and specialized financial institutions (SFIs). Released on August 5, 2026, the proposed regulation would supersede BOT Notification No. 16/2569, which focused primarily on cash withdrawal transactions. The public comment period is open through September 3, 2026.

The amendments reflect concerns that FIs and SFIs may be used to facilitate the movement, concealment, and conversion of criminal proceeds, potentially damaging institutional operations and public confidence in the financial system.

Expanded Scope of Covered Transactions

The most significant change is the broadening of the definition of “cash-related transactions.” Previously, the regulation covered only cash withdrawals and uncrossed check withdrawals. The amended regulation extends coverage to include:

  • Cash deposits, check deposits, or receipt of funds from the public not in the form of deposit accounts;
  • Thai baht (THB) banknote exchange (different denominations);
  • Receipt of cash for issuing checks and drafts; and
  • Purchase, sale, or exchange of foreign banknotes.

Mandatory Identity Verification and Risk Management

For all cash-related transactions, FIs and SFIs must require customers, or authorized or delegated persons, to present identification or verify their identity before every transaction, including one-time (walk-in) transactions. Specific identification requirements vary by transaction type, customer nationality, and channel (branch vs. electronic).

FIs and SFIs must also establish comprehensive risk management processes and procedures for cash-related transactions. These requirements include identifying customers or authorized representatives in accordance with transaction-specific verification standards, analyzing customer behavior, implementing risk-management measures proportionate to the customer’s risk profile, and recording abnormal behavior in relevant systems. The BOT also encourages institutions to proactively guide customers toward transaction channels that offer greater traceability than cash.

For corporate customers in high-risk business sectors—including foreign exchange, real estate, gems, gold and other precious metals, and high-value luxury goods—FIs and SFIs must request additional information on the source of funds, assets, income, or wealth of the persons whose cash the entity is depositing.

Enhanced Due Diligence Threshold

When an unusual transaction is detected, or when a customer’s cash-related transactions across all channels—including branches, electronic branches/devices, and banking agents—total THB 5 million or more (or equivalent) within one day, the FI or SFI must take the following actions depending on the transaction type:

  • Withdrawals or uncrossed checks: Request information on the transaction purpose.
  • Deposits: Request information on the source of funds (and purpose, if conducted by an authorized person).
  • Money exchange: Request both the source of funds and the transaction purpose.

The institution must also assess whether the transaction is consistent with the customer’s profile and normal behavior. If inconsistencies, unreasonableness, or grounds for suspicion are found, the transaction must be classified as high-risk, triggering enhanced due diligence (EDD).

Refusal of Transactions and Escalation

If EDD cannot be completed but the customer provides a reasonable justification or demonstrates necessity for the cash-related transaction, the FI or SFI may proceed under its risk management framework, provided that a senior manager above the branch manager level approves and the customer is closely monitored. If the customer cannot demonstrate reasonable necessity, the institution must refuse the transaction and report it to the Anti-Money Laundering Office (AMLO) as required by law.

Monitoring, Reporting, and Customer Care

FIs and SFIs must establish processes to monitor, detect, and review customer cash-related transaction behavior, set appropriate risk levels, and regularly update these processes. They must also maintain records relating to customer identification, transaction purposes, source-of-funds information, transaction behavior, and information obtained through EDD reviews for regulatory, audit, and internal control purposes. Institutions must prepare and submit reports on abnormal financial behavior or cash-related transactions in the format prescribed by the BOT. Additionally, FIs and SFIs must have appropriate, prompt, and fair processes to assist customers adversely affected by cash-related transaction risk management measures where a transaction is later found not to be abnormal.

Proposed Effective DatesThe BOT has proposed an effective date of October 15, 2026, for the main provisions. Additional EDD requirements for specified legal entities would become effective on April 15, 2027. For SFIs, the timeline will be determined following Ministry of Finance consent.

Next Steps

FIs and SFIs should assess their cash-related transaction risk management frameworks for compliance gaps given the expanded scope. Corporate clients in high-risk industries—including real estate, gems and precious metals, foreign exchange, and luxury goods—should prepare for heightened source-of-funds due diligence. Comments may be submitted through September 3, 2026.

RELATED INSIGHTS​ 

September 10, 2024
In recent years, Thailand has witnessed a significant transformation in its financial landscape, particularly in the rapid adoption of financial technology (fintech). At the forefront of this evolution are electronic payment systems and services, which have revolutionized how individuals and businesses conduct financial transactions. This transformation has been driven by both traditional financial institutions and alternative financial service operators. Overseeing this dynamic landscape are two primary regulators: the Bank of Thailand (BOT) and the Securities and Exchange Commission (SEC). This article explores the development of electronic payment systems in Thailand, with a particular focus on the Payment Systems Act (PSA) of 2017 and its role in shaping the fintech ecosystem. Payment Systems Act In October 2017, Thailand took a significant step forward in regulating its burgeoning electronic payment sector by adopting the Payment Systems Act. This landmark legislation was designed to create and ensure electronic payment system stability and enhance consumer protection in the digital financial realm. The PSA establishes a comprehensive framework by categorizing electronic payment businesses into two main categories: payment systems and payment services. Electronic Payment Systems under the PSA The PSA recognizes two types of electronic payment systems that require specific licenses or registration: Central or network systems. These include systems that act as a center or network between service users for fund transfers, clearing, or settlement. Examples include: Inter-institution Fund Transfer System Payment card networks Settlement systems Systems of public interest. This category encompasses any other payment systems that may affect public interest, public confidence, or the stability and security of the payment infrastructure. Electronic Payment Services under the PSA The PSA also identifies several electronic payment services that require specific licenses or registration: Credit cards, debit cards, and ATM cards Electronic money E-payments Acquisition Payment facilitation Receipt of payment on behalf of others
August 29, 2024
Thailand’s Securities and Exchange Commission (SEC) has revised its regulations on digital asset operators and exchanges to impose stricter governance standards on digital asset business operators and to align digital asset exchange rules with international standards. The new regulations are laid out in SEC Notification No. GorThor. 23/2567 on the Criteria, Conditions, and Procedures for Operating a Digital Asset Business (No. 24) and SEC Notification No. GorLorThor. 24/2567 on Determination of Prohibited Qualifications for Directors and Executives of Digital Asset Business Operators (No. 5). These were published in the Government Gazette on August 16, 2024, with most of the provisions taking effect on the same date. Governance for Digital Asset Businesses The heightened standards for digital asset business operators aim to ensure efficient business supervision and appropriate response to operational risks. The new requirements mainly address: Board of directors composition. Large-sized digital asset business operators (i.e., those with at least 10,000 customers and holding customer assets of at least THB 500 million) who do not provide digital asset custodian services must have at least five directors, at least two of whom must be independent directors. In addition, the business operators must establish an audit committee, with at least two members being independent directors, to create an appropriate “check and balance” mechanism within the organizational structure. Current digital asset business operators must comply with the requirements within 180 days of the notification’s effective date. Qualifications of authorized directors and managers. Authorized directors and managers are now required to (1) either have at least one year of working experience in the digital asset field or have participated in a digital asset course from an SEC-approved list, and (2) participate in a good corporate governance course recognized by the SEC. Current authorized directors and managers who have not previously completed a good
August 23, 2024
Thailand’s Securities and Exchange Commission (SEC) amended its utility token supervisory framework by issuing seven notifications that came into effect on August 13, 2024. Ready-to-use utility tokens (tokens that can be used immediately to acquire specific goods or services), which were previously unregulated, are now subject to the supervisory scheme set forth by the seven new notifications in both primary and secondary markets. This is intended to provide an investor protection mechanism that responds to the characteristics, risks, and usage of the different types of ready-to-use utility tokens. Under the new notifications, ready-to-use utility tokens are categorized into two groups. These are detailed below. Group 1 Utility Tokens Group 1 utility tokens include ready-to-use utility tokens issued for consumption purposes or as a digital representation of a certificate. Examples include loyalty points, digital movie or concert tickets, NFTs, and carbon credits, among others. Principally, there is no change in the regulation of group 1 utility tokens under the new notifications. In the primary market, issuance of this type of token is not subject to the initial coin offering (ICO) requirements. In the secondary market, providing services related to group 1 utility tokens is not considered to be the same as operating a digital asset business with licensing requirements under the Emergency Decree on Digital Asset Businesses B.E. 2561 (2018). Licensed digital asset operators (including exchanges, brokers, and dealers) are not permitted to list or trade group 1 utility tokens. To provide services in relation to group 1 utility tokens, these licensed digital asset operators must establish a separate entity to provide those services and must not use names or messages that could cause the public to misunderstand that the separate entity is engaged in a digital asset business under SEC supervision. Group 2 Utility Tokens Group 2 utility tokens
June 26, 2024
Tilleke & Gibbins’ Fintech Law in Southeast Asia provides fintech operators and service providers with an overview of relevant regulations across all of our full-service jurisdictions—Cambodia, Laos, Myanmar, Thailand, and Vietnam.