You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 18, 2026

Thailand Proposes Expanded KYC and Due Diligence for Cash-related Transactions

The Bank of Thailand (BOT) is seeking public comment on proposed amendments that would significantly expand know-your-customer (KYC) and customer due diligence (CDD) requirements for cash-related transactions at financial institutions (FIs) and specialized financial institutions (SFIs). Released on August 5, 2026, the proposed regulation would supersede BOT Notification No. 16/2569, which focused primarily on cash withdrawal transactions. The public comment period is open through September 3, 2026.

The amendments reflect concerns that FIs and SFIs may be used to facilitate the movement, concealment, and conversion of criminal proceeds, potentially damaging institutional operations and public confidence in the financial system.

Expanded Scope of Covered Transactions

The most significant change is the broadening of the definition of “cash-related transactions.” Previously, the regulation covered only cash withdrawals and uncrossed check withdrawals. The amended regulation extends coverage to include:

  • Cash deposits, check deposits, or receipt of funds from the public not in the form of deposit accounts;
  • Thai baht (THB) banknote exchange (different denominations);
  • Receipt of cash for issuing checks and drafts; and
  • Purchase, sale, or exchange of foreign banknotes.

Mandatory Identity Verification and Risk Management

For all cash-related transactions, FIs and SFIs must require customers, or authorized or delegated persons, to present identification or verify their identity before every transaction, including one-time (walk-in) transactions. Specific identification requirements vary by transaction type, customer nationality, and channel (branch vs. electronic).

FIs and SFIs must also establish comprehensive risk management processes and procedures for cash-related transactions. These requirements include identifying customers or authorized representatives in accordance with transaction-specific verification standards, analyzing customer behavior, implementing risk-management measures proportionate to the customer’s risk profile, and recording abnormal behavior in relevant systems. The BOT also encourages institutions to proactively guide customers toward transaction channels that offer greater traceability than cash.

For corporate customers in high-risk business sectors—including foreign exchange, real estate, gems, gold and other precious metals, and high-value luxury goods—FIs and SFIs must request additional information on the source of funds, assets, income, or wealth of the persons whose cash the entity is depositing.

Enhanced Due Diligence Threshold

When an unusual transaction is detected, or when a customer’s cash-related transactions across all channels—including branches, electronic branches/devices, and banking agents—total THB 5 million or more (or equivalent) within one day, the FI or SFI must take the following actions depending on the transaction type:

  • Withdrawals or uncrossed checks: Request information on the transaction purpose.
  • Deposits: Request information on the source of funds (and purpose, if conducted by an authorized person).
  • Money exchange: Request both the source of funds and the transaction purpose.

The institution must also assess whether the transaction is consistent with the customer’s profile and normal behavior. If inconsistencies, unreasonableness, or grounds for suspicion are found, the transaction must be classified as high-risk, triggering enhanced due diligence (EDD).

Refusal of Transactions and Escalation

If EDD cannot be completed but the customer provides a reasonable justification or demonstrates necessity for the cash-related transaction, the FI or SFI may proceed under its risk management framework, provided that a senior manager above the branch manager level approves and the customer is closely monitored. If the customer cannot demonstrate reasonable necessity, the institution must refuse the transaction and report it to the Anti-Money Laundering Office (AMLO) as required by law.

Monitoring, Reporting, and Customer Care

FIs and SFIs must establish processes to monitor, detect, and review customer cash-related transaction behavior, set appropriate risk levels, and regularly update these processes. They must also maintain records relating to customer identification, transaction purposes, source-of-funds information, transaction behavior, and information obtained through EDD reviews for regulatory, audit, and internal control purposes. Institutions must prepare and submit reports on abnormal financial behavior or cash-related transactions in the format prescribed by the BOT. Additionally, FIs and SFIs must have appropriate, prompt, and fair processes to assist customers adversely affected by cash-related transaction risk management measures where a transaction is later found not to be abnormal.

Proposed Effective DatesThe BOT has proposed an effective date of October 15, 2026, for the main provisions. Additional EDD requirements for specified legal entities would become effective on April 15, 2027. For SFIs, the timeline will be determined following Ministry of Finance consent.

Next Steps

FIs and SFIs should assess their cash-related transaction risk management frameworks for compliance gaps given the expanded scope. Corporate clients in high-risk industries—including real estate, gems and precious metals, foreign exchange, and luxury goods—should prepare for heightened source-of-funds due diligence. Comments may be submitted through September 3, 2026.

RELATED INSIGHTS​ 

May 9, 2024
As non-cash payments continue to surge in Vietnam, the requirement for strong security standards and a clear legislative framework for intermediary payment services (“IPS”) is becoming more and more critical. Recognizing this, the State Bank of Vietnam (“SBV”) has been working on a draft decree to supersede the outdated Decree No. 101/2012/ND-CP dated November 22, 2012, on non-cash payments (“Draft Non-Cash Payment Decree”), which will lay the groundwork for non-cash payments in general and the provision of IPS in particular. Building upon this, the SBV recently issued a draft circular to replace Circular No. 39/2014/TT-NHNN dated December 11, 2014, on IPS (“Circular 39”) (“Draft IPS Circular”), which will offer more detailed guidance on the provision of IPS in Vietnam on top of the Draft Non-Cash Payment Decree. The Draft IPS Circular will be applicable to (i) IPS providers; (ii) foreign organizations providing IPS in Vietnam; and (iii) organizations and individuals involved in the provision of IPS. Some key updates regarding the Draft IPS Circular are as follows: Scope of Application The Draft IPS Circular sets out further guidance for the provision of IPS as listed under the Draft Non-Cash Payment Decree, including: (i) electronic clearing services; (ii) electronic wallet (“e-wallet”) services; (iii) collection and payment support services; (iv) financial switching services; (v) international financial switching services; and (vi) electronic payment gateway services. Notably, the Draft IPS Circular has explicitly excluded from its scope of application the provision of accounts by goods/service providers to their customers solely for the purpose of payment within the systems of such providers (e.g., cards/coupons or service/transaction accounts of online game service providers, transportation service providers, or securities companies, etc.). Requirements on the Provision of IPS Electronic Clearing Services: The Draft IPS Circular introduces regulations to cover certain elements of electronic clearing services that have
April 30, 2024
On March 25, 2024, Thailand’s Securities and Exchange Commission (SEC) published an amendment to its Notification re: Public Digital Token Offering to strengthen governance for initial coin offerings (ICOs). The amendments took effect on April 16, 2024, and reflect the SEC’s commitment to creating a safer and more transparent ICO environment, enhancing investor protection, and building confidence in ICOs as a fundraising tool. The key changes are outlined below: New Checks and Balances Requirements The new regulations require digital token issuers to implement checks and balances to protect investor rights—including an annual audit requirement and measures to prevent and manage conflicts of interest. These measures must be clearly disclosed in the ICO filing documents. In addition, certain project-related decisions must be approved by the issuer’s board of directors, which is also responsible for the accountability of such decisions. Improved Rules Concerning Voting Rights The SEC has introduced rules concerning voting rights and procedures for digital token holders, particularly for token types that previously lacked regulatory clarity. These rules specify the procedures for soliciting votes, the rationale behind vote requests, and the criteria for determining voting outcomes. The new rules, however, do not apply to real estate-backed tokens or infrastructure-backed tokens. Enhanced Advertising Regulations The SEC has revised advertising guidelines to ensure that investors receive essential information. The updated rules now require all ICO advertising to be fair and informative and to avoid misleading content. Advertisements must include appropriate risk warnings and a credible source for any claims made. The notification also stresses that it is the responsibility of digital token issuers to strictly supervise and ensure that those who create advertisements with or for an issuer comply with all relevant advertising regulations, including the following: Warning of investment risk: Advertisements must include warnings about investment risks and contact information
April 4, 2024
On March 18, 2024, the president of the Supreme Court of Thailand announced the establishment of a specialized Technology Crime Division within the Criminal Court of Thailand. This represents a significant commitment to cybercrime within the Thai judiciary and a step forward in Thailand’s ability to investigate cybercrime. The rise in cybercrime investigations in recent years has made it increasingly difficult for Thailand’s traditional criminal courts to consider and issue enforcement orders in support of ongoing investigations in a timely manner. The new Technology Crime Division addresses this challenge. This new division has jurisdiction over cybercrime and technology-related crime, fraud or extortion using computers, and criminal offenses relating to personal data protection laws. In addition, this new division has jurisdiction over all requests from competent law enforcement officers seeking court orders under the Computer Crimes Act B.E. 2550, the Personal Data Protection Act B.E. 2562, and the Cybersecurity Act B.E. 2562. The Technology Crime Division will have trainees and judges with expertise in technology and cybercrime—not only to facilitate expert prosecution of cybercrime but also to offer critical and time-sensitive support to law enforcement investigations of alleged cybercrime. The Technology Crime Division is not yet operational. The president of the Supreme Court is expected to announce the division’s opening date in the coming months. For more details on Thailand’s measures for dealing with cybercrime, please contact Michael Ramirez at [email protected] or Piyawat Vitooraporn at [email protected].
March 27, 2024
The Bank of Thailand (BOT) has opened a public comment period on their consultation paper titled “Criteria for Supervising Virtual Banks” from March 19, 2024, to April 17, 2024. The consultation paper reveals that the BOT intends to apply traditional commercial bank supervisory standards to virtual banks. However, the BOT also explains that the wholly digital nature of the services offered by virtual banks necessitates additional regulatory supervision. Additional Supervisory Criteria for Virtual Banks Financial business group: If a virtual bank is within the same financial business group as other financial institutions, its parent company must structure the virtual bank to be under its own sole consolidated financial business group. After the virtual bank has undergone the “restricted phase” in its initial years of operation (see below), other financial institutions within the group are prohibited from extending credit to or engaging in transactions similar to lending activities with the virtual bank. Shareholding structure: If the increase in the financial institution system capital is higher than the actual capital injection resulting from the bank’s shareholding structure, the BOT aims to issue an additional regulation to supervise the capital of the virtual bank and financial institution system to prevent double counting. Operational risk: Virtual banks must not use a trademark or logo that bears resemblance to or implies association with other financial institutions or financial institution groups. Governance: Virtual banks must have at least one director and chief technology officer (CTO) with at least three years of experience in IT or digital service. Additionally, the CTO must work full-time for the virtual bank and may not be an employee of another legal entity. Restriction on related lending and related-party transactions: Virtual banks must obtain prior unanimous approval from their boards of directors before engaging in transactions with major shareholders or businesses