You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 18, 2026

Thailand Proposes Expanded KYC and Due Diligence for Cash-related Transactions

The Bank of Thailand (BOT) is seeking public comment on proposed amendments that would significantly expand know-your-customer (KYC) and customer due diligence (CDD) requirements for cash-related transactions at financial institutions (FIs) and specialized financial institutions (SFIs). Released on August 5, 2026, the proposed regulation would supersede BOT Notification No. 16/2569, which focused primarily on cash withdrawal transactions. The public comment period is open through September 3, 2026.

The amendments reflect concerns that FIs and SFIs may be used to facilitate the movement, concealment, and conversion of criminal proceeds, potentially damaging institutional operations and public confidence in the financial system.

Expanded Scope of Covered Transactions

The most significant change is the broadening of the definition of “cash-related transactions.” Previously, the regulation covered only cash withdrawals and uncrossed check withdrawals. The amended regulation extends coverage to include:

  • Cash deposits, check deposits, or receipt of funds from the public not in the form of deposit accounts;
  • Thai baht (THB) banknote exchange (different denominations);
  • Receipt of cash for issuing checks and drafts; and
  • Purchase, sale, or exchange of foreign banknotes.

Mandatory Identity Verification and Risk Management

For all cash-related transactions, FIs and SFIs must require customers, or authorized or delegated persons, to present identification or verify their identity before every transaction, including one-time (walk-in) transactions. Specific identification requirements vary by transaction type, customer nationality, and channel (branch vs. electronic).

FIs and SFIs must also establish comprehensive risk management processes and procedures for cash-related transactions. These requirements include identifying customers or authorized representatives in accordance with transaction-specific verification standards, analyzing customer behavior, implementing risk-management measures proportionate to the customer’s risk profile, and recording abnormal behavior in relevant systems. The BOT also encourages institutions to proactively guide customers toward transaction channels that offer greater traceability than cash.

For corporate customers in high-risk business sectors—including foreign exchange, real estate, gems, gold and other precious metals, and high-value luxury goods—FIs and SFIs must request additional information on the source of funds, assets, income, or wealth of the persons whose cash the entity is depositing.

Enhanced Due Diligence Threshold

When an unusual transaction is detected, or when a customer’s cash-related transactions across all channels—including branches, electronic branches/devices, and banking agents—total THB 5 million or more (or equivalent) within one day, the FI or SFI must take the following actions depending on the transaction type:

  • Withdrawals or uncrossed checks: Request information on the transaction purpose.
  • Deposits: Request information on the source of funds (and purpose, if conducted by an authorized person).
  • Money exchange: Request both the source of funds and the transaction purpose.

The institution must also assess whether the transaction is consistent with the customer’s profile and normal behavior. If inconsistencies, unreasonableness, or grounds for suspicion are found, the transaction must be classified as high-risk, triggering enhanced due diligence (EDD).

Refusal of Transactions and Escalation

If EDD cannot be completed but the customer provides a reasonable justification or demonstrates necessity for the cash-related transaction, the FI or SFI may proceed under its risk management framework, provided that a senior manager above the branch manager level approves and the customer is closely monitored. If the customer cannot demonstrate reasonable necessity, the institution must refuse the transaction and report it to the Anti-Money Laundering Office (AMLO) as required by law.

Monitoring, Reporting, and Customer Care

FIs and SFIs must establish processes to monitor, detect, and review customer cash-related transaction behavior, set appropriate risk levels, and regularly update these processes. They must also maintain records relating to customer identification, transaction purposes, source-of-funds information, transaction behavior, and information obtained through EDD reviews for regulatory, audit, and internal control purposes. Institutions must prepare and submit reports on abnormal financial behavior or cash-related transactions in the format prescribed by the BOT. Additionally, FIs and SFIs must have appropriate, prompt, and fair processes to assist customers adversely affected by cash-related transaction risk management measures where a transaction is later found not to be abnormal.

Proposed Effective DatesThe BOT has proposed an effective date of October 15, 2026, for the main provisions. Additional EDD requirements for specified legal entities would become effective on April 15, 2027. For SFIs, the timeline will be determined following Ministry of Finance consent.

Next Steps

FIs and SFIs should assess their cash-related transaction risk management frameworks for compliance gaps given the expanded scope. Corporate clients in high-risk industries—including real estate, gems and precious metals, foreign exchange, and luxury goods—should prepare for heightened source-of-funds due diligence. Comments may be submitted through September 3, 2026.

RELATED INSIGHTS​ 

July 24, 2025
Thai authorities have escalated efforts to block unlawful cross-border digital asset business operators. On June 19, 2025, the Ministry of Digital Economy and Society (MDES) issued a notification empowering it to ban internet access to operations or services offered by digital asset business operators who lack licenses from the Thailand Securities and Exchange Commission (SEC) under the Emergency Decree on Digital Asset Businesses B.E. 2561 (2018). This ban, issued under the 2023 Royal Decree on Measures for the Prevention and Suppression of Technology Crime, particularly aims to block Thai users’ access to services offered by unlicensed offshore digital asset providers via their own apps or websites or through public social media platforms. Compliance Requirements The notification requires internet service providers and social media platforms selected by MDES to immediately impose internet access restrictions on identified apps, websites, and IP addresses of illegal operators upon receiving MDES orders. Takedown Orders There are two tracks for competent officials at MDES to issue orders to operators: If the competent official is notified by the SEC of licensing noncompliance by a particular digital asset business operator, the competent official can issue a takedown order to the operator upon approval from the permanent secretary of MDES. If the competent official independently discovers, or receives a complaint from any third party other than the SEC, that a digital asset business operator may have violated licensing requirements, the competent official can ask the SEC to verify and confirm the relevant facts and noncompliance before seeking approval from the permanent secretary of MDES to issue the takedown order. Streamlined Enforcement Prior to this notification, the SEC could obtain takedown orders only from Thai courts under the 2007 Computer Crime Act to take down or block access to unlicensed digital asset platforms and apps. This was a relatively
July 11, 2025
Vietnam’s recent embrace of “regulatory sandboxes” reflects a deliberate policy choice to balance the need for robust oversight with an equally pressing imperative to catalyze innovation. A sandbox is a controlled, time-bound framework in which businesses may pilot emerging technologies, products, or business models under relaxed or tailor-made regulatory requirements, thereby allowing regulators to observe risks in real time while innovators validate commercial viability without bearing the full weight of the traditional compliance regime. By issuing sandbox regulations, the government of Vietnam is signaling its commitment to accelerating digital transformation, attracting investment, and developing a knowledge-based economy, all while safeguarding financial stability, consumer protection, and national security. This strategy is embodied in a suite of instruments that together establish sector-specific sandboxes: Decree No. 94/2025/ND-CP on the Regulatory Sandbox in the Banking Sector (Fintech Sandbox Decree), effective July 1, 2025. Law on Digital Technology Industry (DTI Law), effective January 1, 2026, and Law on Science, Technology and Innovation (STI Law), effective October 1, 2025. Resolution No. 222/2025/QH15 on International Financial Centers (IFC Resolution), effective September 1, 2025. In addition, a draft resolution on the pilot implementation of the crypto-asset market (Draft Crypto Pilot Resolution) is expected to introduce a dedicated sandbox for crypto-asset service providers later this year, further underscoring Vietnam’s holistic, forward-looking approach to regulating emerging technologies. Below is a brief summary of all the regulatory sandboxes, who they are open for, and what businesses are attracted. Fintech Sandbox Decree Under the Fintech Sandbox Decree, besides credit institutions and foreign bank branches, fintech companies operating in Vietnam can apply for a Certificate of Sandbox Participation issued by the State Bank of Vietnam to operate any of the following services in Vietnam: Credit scoring: A solution applicable to information technology systems of credit institutions, branches of foreign banks, and fintech
July 2, 2025
On June 27, 2025, Vietnam’s National Assembly adopted a Resolution on International Financial Centers in Vietnam (“IFC Resolution”), which is set to take effect September 1, 2025, putting forward major policy breakthroughs on multiple fronts. The IFC Resolution has the goal of turning Ho Chi Minh City and Da Nang into leading international financial centers with autonomy and tools to compete, thereby raising Vietnam’s position in the global financial network, in association with economic growth drivers. Below are some of the key points of the IFC Resolution, which has notable changes from previous drafts (see our articles on Vietnam’s Draft Resolution on Financial Centers: Implications for Fintech and Banking and Vietnam’s Emerging Regulatory Landscape for Blockchain and Cryptocurrency), including: The removal of the Central Supervisory Agency. The addition of a definition of international financial centers, which are specific geographic areas in Ho Chi Minh City and Da Nang with members entitled to special policies. The addition of a list of entities eligible for membership, and entitlement to the special policies. Major Policy Breakthroughs The IFC Resolution introduces specific policies in the following areas: Liberalization of foreign exchange control for members, including policies such as open foreign exchange use between members and exemption from foreign exchange control procedures for 100% foreign-owned members. Specialized licensing for members to establish and operate single-member limited liability banks and foreign bank branches with the ability to apply accounting standards, debt classification, risk provisions, and prudential ratios according to the owner’s policies. Creation of a capital market for innovative startups, including a crowdfunding mechanism or private placement mechanism through a licensed platform, and development of a green finance market with green certification. Creation of a regulatory sandbox for fintech technologies, products, services, and business models not yet prescribed by law, offering exemption from compliance with
June 19, 2025
The Bank of Thailand (BOT) has released draft guidelines establishing principles for managing artificial intelligence (AI) risks in the financial sector. The draft guidelines provide a structured framework for the responsible adoption of AI technologies. Financial service providers will be able to use the guidelines as a reference to appropriately manage their risks in a manner that aligns with internationally recognized best practices. The BOT is accepting public comments on the draft guidelines until June 30, 2025. Scope and Application The draft guidelines apply to all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. These guidelines supplement existing BOT risk management guidelines covering IT risk management, third-party risk management, data governance, and market conduct. The guidelines define AI systems as systems that mimic human intelligence, including machine learning, deep learning, generative AI (such as large language models), and agentic AI. This definition specifically excludes rule-based automation systems like robotic process automation and condition matching. Key Risk Management Principles The guidelines lay out two main principles in managing AI risk. Governance: Financial service providers should define and establish clear roles and responsibilities for their personnel and AI system supervision structures to uphold FEAT (fairness, ethics, accountability, and transparency) principles as follows: Stakeholder roles and responsibilities. Financial service providers should define roles and responsibilities for boards and executives on AI risk oversight. Responsibilities include establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. AI system usage policy. The AI system usage policy should be aligned with organizational objectives, regulatory requirements, and FEAT principles. These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management