You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 18, 2026

Thailand Proposes Expanded KYC and Due Diligence for Cash-related Transactions

The Bank of Thailand (BOT) is seeking public comment on proposed amendments that would significantly expand know-your-customer (KYC) and customer due diligence (CDD) requirements for cash-related transactions at financial institutions (FIs) and specialized financial institutions (SFIs). Released on August 5, 2026, the proposed regulation would supersede BOT Notification No. 16/2569, which focused primarily on cash withdrawal transactions. The public comment period is open through September 3, 2026.

The amendments reflect concerns that FIs and SFIs may be used to facilitate the movement, concealment, and conversion of criminal proceeds, potentially damaging institutional operations and public confidence in the financial system.

Expanded Scope of Covered Transactions

The most significant change is the broadening of the definition of “cash-related transactions.” Previously, the regulation covered only cash withdrawals and uncrossed check withdrawals. The amended regulation extends coverage to include:

  • Cash deposits, check deposits, or receipt of funds from the public not in the form of deposit accounts;
  • Thai baht (THB) banknote exchange (different denominations);
  • Receipt of cash for issuing checks and drafts; and
  • Purchase, sale, or exchange of foreign banknotes.

Mandatory Identity Verification and Risk Management

For all cash-related transactions, FIs and SFIs must require customers, or authorized or delegated persons, to present identification or verify their identity before every transaction, including one-time (walk-in) transactions. Specific identification requirements vary by transaction type, customer nationality, and channel (branch vs. electronic).

FIs and SFIs must also establish comprehensive risk management processes and procedures for cash-related transactions. These requirements include identifying customers or authorized representatives in accordance with transaction-specific verification standards, analyzing customer behavior, implementing risk-management measures proportionate to the customer’s risk profile, and recording abnormal behavior in relevant systems. The BOT also encourages institutions to proactively guide customers toward transaction channels that offer greater traceability than cash.

For corporate customers in high-risk business sectors—including foreign exchange, real estate, gems, gold and other precious metals, and high-value luxury goods—FIs and SFIs must request additional information on the source of funds, assets, income, or wealth of the persons whose cash the entity is depositing.

Enhanced Due Diligence Threshold

When an unusual transaction is detected, or when a customer’s cash-related transactions across all channels—including branches, electronic branches/devices, and banking agents—total THB 5 million or more (or equivalent) within one day, the FI or SFI must take the following actions depending on the transaction type:

  • Withdrawals or uncrossed checks: Request information on the transaction purpose.
  • Deposits: Request information on the source of funds (and purpose, if conducted by an authorized person).
  • Money exchange: Request both the source of funds and the transaction purpose.

The institution must also assess whether the transaction is consistent with the customer’s profile and normal behavior. If inconsistencies, unreasonableness, or grounds for suspicion are found, the transaction must be classified as high-risk, triggering enhanced due diligence (EDD).

Refusal of Transactions and Escalation

If EDD cannot be completed but the customer provides a reasonable justification or demonstrates necessity for the cash-related transaction, the FI or SFI may proceed under its risk management framework, provided that a senior manager above the branch manager level approves and the customer is closely monitored. If the customer cannot demonstrate reasonable necessity, the institution must refuse the transaction and report it to the Anti-Money Laundering Office (AMLO) as required by law.

Monitoring, Reporting, and Customer Care

FIs and SFIs must establish processes to monitor, detect, and review customer cash-related transaction behavior, set appropriate risk levels, and regularly update these processes. They must also maintain records relating to customer identification, transaction purposes, source-of-funds information, transaction behavior, and information obtained through EDD reviews for regulatory, audit, and internal control purposes. Institutions must prepare and submit reports on abnormal financial behavior or cash-related transactions in the format prescribed by the BOT. Additionally, FIs and SFIs must have appropriate, prompt, and fair processes to assist customers adversely affected by cash-related transaction risk management measures where a transaction is later found not to be abnormal.

Proposed Effective DatesThe BOT has proposed an effective date of October 15, 2026, for the main provisions. Additional EDD requirements for specified legal entities would become effective on April 15, 2027. For SFIs, the timeline will be determined following Ministry of Finance consent.

Next Steps

FIs and SFIs should assess their cash-related transaction risk management frameworks for compliance gaps given the expanded scope. Corporate clients in high-risk industries—including real estate, gems and precious metals, foreign exchange, and luxury goods—should prepare for heightened source-of-funds due diligence. Comments may be submitted through September 3, 2026.

RELATED INSIGHTS​ 

January 9, 2026
Thailand continues to advance its legal and regulatory framework for the technology sector, with several key laws undergoing review and proposed amendments. These developments reflect Thailand’s broader efforts to ensure that its regulatory landscape keeps pace with rapid technological change and aligns more closely with international standards and best practices. The following are key legal developments and proposed legislative reforms in 2026 that are expected to impact businesses operating in the technology sector and the broader Thai business landscape. Data Privacy and Cybersecurity Personal Data Protection Act B.E. 2562 (2019) Following the full enforcement of Thailand’s Personal Data Protection Act (PDPA) in June 2022, businesses and practitioners have identified practical implementation challenges and interpretative issues. These challenges were reflected in an effectiveness assessment conducted by the Personal Data Protection Committee (PDPC) in late 2024. The PDPC published a set of principles for public consultation to identify issues and directions for potential amendments to the PDPA. Key issues: Emerging issues include clarifying the definitions of “data controller,” “data processor,” and “criminal record”; revisiting the scope of sensitive personal data to better reflect Thailand’s context; proposing amendments to the hierarchy of legal bases to avoid misconceptions of consent as the default legal basis; and clarifying the required level of expressiveness for explicit consent, as well as rules for collecting personal data from other sources. Current status: The first round of public consultation has concluded. Next steps: The proposed amendments are proceeding to a revised draft following the consultation outcomes. Cybersecurity Act B.E. 2562 (2019) Thailand is moving forward with proposed amendments to enhance the effectiveness of its national cybersecurity framework, as evolving digital technologies bring new risks such as misinformation, system intrusions, and attacks on critical infrastructure, making cybersecurity a national priority. Key issues: The amendments aim to clarify and strengthen
January 6, 2026
Among the eight implementing decrees issued on December 18, 2025, to provide the legal framework for Vietnam’s new International Financial Centers (IFC), Decree No. 323/2025/ND‑CP serves the core function of officially establishing the IFC as a unified entity in two locations—Ho Chi Minh City and Da Nang—and setting out a plan for its development and governance. The key contents of the decree are summarized below. Location and Focus of IFCs The Vietnam International Financial Center in Ho Chi Minh City (VIFC‑HCMC) and the Vietnam International Financial Center in Da Nang (VIFC‑DN) are designed to attract capital, fintech, and international market participants under a dedicated regulatory framework. The IFCs will host functional zones for financial trading, banking, securities and commodities exchanges, offices, dispute resolution (via specialized court and international arbitration center), and related activities as set by the executive authority of each IFC. VIFC-HCMC, with a total area of 898 hectares in central Ho Chi Minh City, is oriented to develop a comprehensive and diverse financial ecosystem, providing traditional and specialized financial services, and leveraging synergies between financial services such as capital mobilization, investment, payment services, issuance and trading of financial products, asset management, fintech, and green financial services. VIFC-DN, with a total area of 300 hectares, is oriented to develop as a modern IFC, closely integrated with the innovation ecosystem, digital technology, and sustainable finance. VIFC-DN will establish a controlled testing platform for new financial models, taking the lead in the deployment and scaling of digital-asset products, digital payments, and specialized trading platforms and exchanges, while promoting supply chain finance, third-party services, and non-bank financial intermediaries to complement and support the traditional financial market, developing specialized, flexible, and innovative financial products. Near‑Term Priorities and Review Timeline In 2026, the government will prioritize completing the essential infrastructure and ensuring adequate
January 5, 2026
Resolution No. 222/2025/QH15 dated June 27, 2025, of the National Assembly of Vietnam (the “IFC Resolution” – see our previous article) set out the foundational legal framework for the establishment and development of Vietnam’s first-ever International Financial Centers (IFC). In furtherance of this framework, on December 18, 2025, the government of Vietnam issued eight implementing decrees to provide detailed regulatory guidance and to operationalize the IFC Resolution in practice. The Eight Implementing Decrees: An Integrated Regulatory Ecosystem The new decrees governing the IFC include the following: Decree No. 323/2025/ND-CP on the establishment of the IFC. Decree No. 324/2025/ND-CP on financial policies applicable within the IFC. Decree No. 325/2025/ND-CP on labor, employment, and social security within the IFC. Decree No. 326/2025/ND-CP on land and environmental matters within the IFC. Decree No. 327/2025/ND-CP on entry, exit, and residence of foreign nationals in the IFC. Decree No. 328/2025/ND-CP on the International Arbitration Center of the IFC. Decree No. 329/2025/ND-CP on banking licensing, foreign exchange management, and anti-money laundering and combating the financing of terrorism (AML/CFT) within the IFC. Decree No. 330/2025/ND-CP on the establishment and operation of commodity exchanges within the IFC. Taken as a whole, these eight decrees translate the IFC Resolution into a coherent and fully operational legal regime governing the establishment, organization, and functioning of Vietnam’s IFC. Collectively, they demonstrate that Vietnam’s IFC framework is best understood not as a collection of isolated incentives, but as a deliberately designed and integrated regulatory system. The Legal Architecture of the IFC: Four Interlocking Pillars Read together, the decrees seem to be designed to address four core regulatory questions from the outset: (i) what the IFC is, from a legal and institutional perspective; (ii) who may participate in the IFC and what activities are permitted; (iii) how people, capital, and projects operate
December 26, 2025
The Bank of Thailand (BOT) has released the Guidelines for Digital Fraud Management, which took effect on December 17, 2025, incorporating certain amendments to the draft guidelines issued in March 2025. These official guidelines aim for end-to-end digital fraud prevention, with a particular focus on mule accounts, to enhance trust and security in Thailand’s financial system. The guidelines apply to “financial service providers,” including: Financial institutions and special financial institutions under the Financial Institution Business Act; and Operators of Inter-institutional Fund Transfer System e-money services and e-fund transfer services under the Payment Systems Act. Besides commercial banks and e-money operators that offer fund-transfer services, other providers may adopt requirements based on risk proportionality and baseline standards set out in the guidelines (for instance, an e-money operator that does not offer e-fund transfer services could consider implementing a fraud monitoring and detection system according to the risk level of its service). The guidelines establish the following key requirements: Policy and oversight. Directors and senior executives of financial service providers must adopt appropriate “end-to-end” fraud management policies and KPIs to manage digital fraud, covering prevention, monitoring, detection, management, resolution, and support for affected customers. The fraud management policy must be regularly reviewed, and whenever there is a situation or change that significantly affects the efficiency of the fraud management. Any significant update to the policy must first be approved by the board of the financial service provider. The BOT also encourages providers to collaborate in establishing industry standards aligned with applicable laws and regulations to ensure consistency and best practices across the sector. Fraud management processes. Financial service providers must establish a clear framework for managing digital fraud throughout the customer lifecycle—from customer onboarding to service termination—covering at least the following processes: Know your customer (KYC) and customer due diligence (CDD):