You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 18, 2026

Thailand Proposes Expanded KYC and Due Diligence for Cash-related Transactions

The Bank of Thailand (BOT) is seeking public comment on proposed amendments that would significantly expand know-your-customer (KYC) and customer due diligence (CDD) requirements for cash-related transactions at financial institutions (FIs) and specialized financial institutions (SFIs). Released on August 5, 2026, the proposed regulation would supersede BOT Notification No. 16/2569, which focused primarily on cash withdrawal transactions. The public comment period is open through September 3, 2026.

The amendments reflect concerns that FIs and SFIs may be used to facilitate the movement, concealment, and conversion of criminal proceeds, potentially damaging institutional operations and public confidence in the financial system.

Expanded Scope of Covered Transactions

The most significant change is the broadening of the definition of “cash-related transactions.” Previously, the regulation covered only cash withdrawals and uncrossed check withdrawals. The amended regulation extends coverage to include:

  • Cash deposits, check deposits, or receipt of funds from the public not in the form of deposit accounts;
  • Thai baht (THB) banknote exchange (different denominations);
  • Receipt of cash for issuing checks and drafts; and
  • Purchase, sale, or exchange of foreign banknotes.

Mandatory Identity Verification and Risk Management

For all cash-related transactions, FIs and SFIs must require customers, or authorized or delegated persons, to present identification or verify their identity before every transaction, including one-time (walk-in) transactions. Specific identification requirements vary by transaction type, customer nationality, and channel (branch vs. electronic).

FIs and SFIs must also establish comprehensive risk management processes and procedures for cash-related transactions. These requirements include identifying customers or authorized representatives in accordance with transaction-specific verification standards, analyzing customer behavior, implementing risk-management measures proportionate to the customer’s risk profile, and recording abnormal behavior in relevant systems. The BOT also encourages institutions to proactively guide customers toward transaction channels that offer greater traceability than cash.

For corporate customers in high-risk business sectors—including foreign exchange, real estate, gems, gold and other precious metals, and high-value luxury goods—FIs and SFIs must request additional information on the source of funds, assets, income, or wealth of the persons whose cash the entity is depositing.

Enhanced Due Diligence Threshold

When an unusual transaction is detected, or when a customer’s cash-related transactions across all channels—including branches, electronic branches/devices, and banking agents—total THB 5 million or more (or equivalent) within one day, the FI or SFI must take the following actions depending on the transaction type:

  • Withdrawals or uncrossed checks: Request information on the transaction purpose.
  • Deposits: Request information on the source of funds (and purpose, if conducted by an authorized person).
  • Money exchange: Request both the source of funds and the transaction purpose.

The institution must also assess whether the transaction is consistent with the customer’s profile and normal behavior. If inconsistencies, unreasonableness, or grounds for suspicion are found, the transaction must be classified as high-risk, triggering enhanced due diligence (EDD).

Refusal of Transactions and Escalation

If EDD cannot be completed but the customer provides a reasonable justification or demonstrates necessity for the cash-related transaction, the FI or SFI may proceed under its risk management framework, provided that a senior manager above the branch manager level approves and the customer is closely monitored. If the customer cannot demonstrate reasonable necessity, the institution must refuse the transaction and report it to the Anti-Money Laundering Office (AMLO) as required by law.

Monitoring, Reporting, and Customer Care

FIs and SFIs must establish processes to monitor, detect, and review customer cash-related transaction behavior, set appropriate risk levels, and regularly update these processes. They must also maintain records relating to customer identification, transaction purposes, source-of-funds information, transaction behavior, and information obtained through EDD reviews for regulatory, audit, and internal control purposes. Institutions must prepare and submit reports on abnormal financial behavior or cash-related transactions in the format prescribed by the BOT. Additionally, FIs and SFIs must have appropriate, prompt, and fair processes to assist customers adversely affected by cash-related transaction risk management measures where a transaction is later found not to be abnormal.

Proposed Effective DatesThe BOT has proposed an effective date of October 15, 2026, for the main provisions. Additional EDD requirements for specified legal entities would become effective on April 15, 2027. For SFIs, the timeline will be determined following Ministry of Finance consent.

Next Steps

FIs and SFIs should assess their cash-related transaction risk management frameworks for compliance gaps given the expanded scope. Corporate clients in high-risk industries—including real estate, gems and precious metals, foreign exchange, and luxury goods—should prepare for heightened source-of-funds due diligence. Comments may be submitted through September 3, 2026.

RELATED INSIGHTS​ 

March 14, 2025
The Bank of Thailand (BOT) has published the Draft Guidelines for Digital Fraud Management, which aim to help financial service providers tackle digital fraud and ensure safety and trust in the Thai financial system. These draft guidelines, which are available for public comment until March 18, 2025, provide a comprehensive framework for financial service providers, covering prevention, detection, management, and resolution of digital fraud, as well as support for customers affected by fraud. The BOT tentatively plans to implement these draft guidelines on April 1, 2025, along with circular letters on the minimum required measures for tackling “mule accounts” (deposit or e-money accounts used as tools to receive and transfer funds obtained through the commission of any offense) and measures to strengthen Thailand’s customer due diligence and enhanced due diligence procedures. Under the draft guidelines, “financial service providers” include financial institutions and special financial institutions under the Financial Institution Business Act and payment providers under the Payment Systems Act. Commercial banks, special financial institutions, and operators of transferable e-money services must adhere to every requirement in the draft guidelines. Other financial service providers (e.g., payment providers other than operators of transferable e-money services) can implement the draft guidelines as deemed appropriate to their services, products, and service channels. Digital Fraud Management Requirements The draft guidelines establish the following key requirements: Policy and oversight. Directors and senior executives of financial service providers must set and adopt appropriate “end-to-end” fraud management policies and KPIs to manage digital fraud, covering prevention, monitoring, detection, management, resolution, and support for affected customers. Fraud management processes. Financial service providers must establish a clear framework for managing digital fraud throughout the customer lifecycle, from customer onboarding to service termination, according to industry standards at a minimum and covering at least the following processes: Know your customer
March 10, 2025
Thailand’s Securities and Exchange Commission (SEC) will officially add USD Coin (USDC) and Tether (USDT) to its list of approved cryptocurrencies for use in digital asset transactions on March 16, 2025. The addition is a significant move that expands Thailand’s digital asset market, aiming to enhance market flexibility and provide more payment options for investors and traders in Thailand’s digital asset ecosystem. Under the SEC regulations, digital asset operators, including digital token issuers, ICO portals, and digital asset exchanges, are only permitted to accept, conduct transactions with, and use “approved cryptocurrencies” as trading pairs. After the addition of USDC and USDT, the full list of approved cryptocurrencies will include: Bitcoin (BTC) Ethereum (ETH) Ripple (XRP) Stellar (XLM) Tether (USDT) USD Coin (USDC) Other cryptocurrencies used for testing programmable payments under the enhanced regulatory sandbox in accordance with the Bank of Thailand’s rules and conditions. For more information on these new additions, or on any aspect of digital assets and cryptocurrency in Thailand, please contact Kobkit Thienpreecha at [email protected], Pornpan Wichawut at [email protected], Napassorn Lertussavavivat at [email protected], or Rujaporn Paritsantik at [email protected].
February 24, 2025
On January 31, 2025, the Bank of Thailand (BOT) announced a new Notification re: Responsible Lending, replacing a similar notification from 2023. This new notification provides updated measures to assist debtors in different circumstances and clear implementation guidelines for lenders, with the aim of resolving household debt issues. Scope The service providers covered by the notification include banks and nonbanks (e.g., credit card companies, asset management companies, licensed personal loan providers, and nano finance operators) that conduct lending business. New Requirements The notification’s core focus remains loan management throughout the lifecycle of a loan—from credit product development to legal proceedings and debt transfers to other creditors—but with further clarification and detail compared to the 2023 notification. The key revisions in the new notification are summarized below. Advertising standards: The notification tightens requirements in some areas and relaxes them in others. Stricter requirements: It is now clearly stipulated that the BOT oversees taglines that may encourage excessive borrowing. More examples of noncompliant statements are also added (e.g., “Elevate your lifestyle now, pay later”; “Get approved, even with credit challenges”). In addition, advertising material that contains multiple credit products should provide clear minimum and maximum interest rates, especially when there are significant differences in the interest rates of each product. Relaxed requirements: The required information for some marketing activities is now reduced. For example, in marketing events with staff promoting loan products and offering free giveaways, service providers have the discretion to provide effective interest rate information in the manner they deem appropriate, and the advertisement material can display only the mandatory warning statements without providing interest rate details. Encouraging customer financial discipline: The notification requires service providers to implement more elaborate and extensive tools to influence customer behavior (termed “nudging” by the BOT) at every stage of the lending cycle. This
February 17, 2025
Thailand’s draft Emergency Decree on Technology Crimes Suppression, which we covered in a client alert in January 2025 primarily addressed to telecom operators and financial institutions, is expected to have significant implications for a wide range of business operators.  The draft emergency decree has already been approved by the cabinet but may undergo further developments as it continues in the legislative process. In this article, we will highlight the material impacts of the draft emergency decree on overseas and local fintech operators. Expanded Definition of “Technology Crimes” The definition of “technology crimes” now includes the following acts of forgery or alteration: Forging or altering the identity of individuals and biometric characteristics by utilizing computer or communication systems or other electronic means to commit offenses. Forging or altering symbols, trademarks, or seals of groups (e.g., foundations, community enterprises) or juristic persons, including acts by juristic persons using individuals or juristic persons as nominal directors or shareholders, regardless of whether such individuals or legal juristic persons reside in Thailand. Forging or altering digital or online platforms, regardless of the platform’s location or legal status. Individuals who conspire, utilize, assist, or support the commission of these offenses will face the same penalties as the principal offender. Business Operator Definition The scope of “business operators” is now expanded to cover various fintech and digital asset operators beyond those under the Payment Systems Act (PSA). The draft emergency decree now includes the following operators, whether they are legally authorized or not: Business operators under the PSA and business operators who operate “as if” they are payment system operators Business operators under the Royal Decree on Digital Asset Businesses or business operators who operate “as if” they are digital asset business operators. Foreign exchange business operators. Disclosure and Exchange of Information Business operators must disclose