You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 27, 2024

Thailand Updates Customer Codes for Heightened Money Laundering Risk

On May 17, 2024, Thailand’s Anti-Money Laundering Office (AMLO) issued an amended Notification Concerning the Rules for Designating or Reviewing the List of High-Risk Customers Who Require Close Monitoring under the Ministerial Regulation on Customer Due Diligence B.E. 2563 (2020). This notification, which took effect the following day, updates the previous version of the notification from 2022 to cover cybercrimes listed under the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes B.E. 2566 (2023). The amended notification sets out the steps that all financial institutions in Thailand must take to manage money laundering risks and to comply with the AMLO’s mandatory Guidelines on Customer Due Diligence.

Under the new notification, account holders suspected of engaging in or facilitating technological crimes, as recorded by the Anti Online Scam Operation Center (AOC), are to be classified as “high-risk persons.” The notification includes provisions for listing high-risk customers under two specific codes:

  • HR-03-1: This code applies to individuals who are the subject of either a petition or a complaint related to a predicate offense accepted by the relevant inquiry officer and recorded as a criminal case. It also covers individuals whose bank accounts are suspected of being used to conduct transactions related to crimes under the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes B.E. 2566 (2023), with victims seeking prosecution. The names of individuals in this category are received from responsible agencies according to the Criminal Procedure Code or the AOC and are documented in a publicly accessible online notification system.
  • HR-03-2: This code is for individuals involved in the commission of a predicate offense or those whose bank accounts are suspected of being used in such offenses, but whose cases have not been accepted or numbered by the relevant inquiry officer. Names under this category are provided by agencies such as the Royal Thai Police, the Financial Investigation Division, the Cooperation and Standard Development Division, banks, or other sources in Thailand.

These updated rules aim to ensure that relevant individuals and their transactions are closely supervised, thus enhancing the efficiency of monitoring high-risk customers and preventing technological crimes.

For more information on this new notification, or on any aspect of Thailand’s anti-money laundering regulations, please contact Chitchai Punsan at [email protected] or Panisara Moleegul at [email protected].

RELATED INSIGHTS​ 

September 24, 2025
On September 12, 2025, the Bank of Thailand (BOT) officially released its AI Risk Management Guidelines for Financial Service Providers, building upon the draft guidelines issued in June 2025. The guidelines reflect a balanced approach, encouraging innovation while safeguarding financial stability and consumer protection. The guidelines are targeted at all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. The guidelines apply to both AI systems developed in-house and those developed by third parties that are adopted for use by financial service providers. AI Risk Management Guidelines The two main pillars in managing AI risk are (1) governance of AI system implementation and (2) AI system development and security controls, consisting of the following key elements: 1. Governance Stakeholder roles and responsibilities. Boards and senior management assume accountability for decisions and operations involving AI systems, and are responsible for defining roles and responsibilities for AI oversight. This includes establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. Organizations are expected to foster internal capabilities to use AI securely and avoid overreliance that could compromise business continuity or customer service. AI system usage policy. Policies governing AI usage should align with organizational goals, regulatory obligations, and recognized responsible AI frameworks—such as the FEAT principles (fairness, ethics, accountability, and transparency). These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. Financial service providers should assess risks and impacts of AI usage on operations and customer services.
September 12, 2025
On September 10, 2025, Vietnam’s National Credit Information Center (CIC) reported to the Vietnam Cybersecurity Emergency Response Team (VNCERT) a suspected significant cybersecurity incident involving unauthorized access to the CIC’s credit information database. A hacker group has claimed responsibility and allegedly posted over 160 million records for sale, including sensitive personal and financial data. Implications for Banks and Financial Institutions Companies that share customers’ or potential customers’ personal data with the CIC for credit scoring or other purposes—and continue to act as a data controller for such data—may be obligated under Vietnam’s Personal Data Protection Decree (PDPD) and related regulations to: Notify A05 (Department of Cybersecurity and High-Tech Crime Prevention) and the State Bank of Vietnam without delay. Inform affected individuals if their personal data is at risk. Recommended Actions Companies that could be impacted by this data breach should take the following actions: Conduct an internal review of CIC-related data in their systems, and identify whether and how the systems have been affected by this incident. Assess whether to notify regulators and customers/potential customers. Enhance cybersecurity controls, monitor for suspicious activity, and implement additional safeguards to prevent secondary breaches.
September 11, 2025
Thailand traditionally has had a reputation as a “crossroads” for numerous illegal activities and of the laundering of significant sums of tainted money. Member of the Financial Action Task Force (FATF)? No. Any Egmont members? Yes. Thailand’s Anti-Money Laundering Office (AMLO) is a member of the Egmont Group. Regulation The relevant law, known as the Anti-Money Laundering Act (the Act), was passed in March 1999 with the aim of combating not only the drug trade but also other illicit activities, such as corruption, criminal fraud and prostitution. There have been a number of changes and updates to the Act, the most recent one in late 2015, in which the Act was amended to include: Additional predicate offences such as offences relating to human trafficking, online gambling and offences relating to unfair practices relating to derivatives and agricultural commodity futures. Broader scope of money laundering offence. Non-disclosure obligations to applicable financial institutions and reporting entities. Compulsory training to financial institutions and reporting entities’ employees responsible to monitor and ensure compliance with the Act. Retention period. Enhanced penalties Additionally, discussions did take place mooting further changes to the Act, set out in 2020 and 2021 drafts. Proposed changes included suggestions to expand the definitions of financial institutes, predicate offences and professions, as well as to impose greater reporting and due diligence responsibilities on companies subject to the Act. However, recent amendments to the Act in 2022 only included minor procedural and substantive changes that did not materially alter or expand the Act. The most notable amendments were changes to an injured party’s rights to claim damages caused by a predicate offence and the rights of beneficiaries claiming assets seized by the government in connection with a predicate offence. Financial intelligence unit Of the total number of transactions reported to AMLO annually,
August 25, 2025
To implement the recently issued Resolution on International Financial Centers in Vietnam (“IFC Resolution”), which is set to take effect on September 1, 2025 (see our previous article), the government of Vietnam is making every effort to formulate and issue guiding decrees—up to eight in total—before the effective date of the resolution. These decrees will establish key principles, define the rights and obligations of stakeholders, and outline permissible business activities within the IFCs, and serve as a foundation for the legal framework of the IFCs. Below are highlights of two draft decrees that have been released for public consultation. Draft Decree on IFC Establishment Ho Chi Minh City: The IFC in Ho Chi Minh City will focus on capital markets integrated with asset management services, fund management, insurance, financial products and financial derivatives; banking systems and money market products; fintech and financial innovation through sandbox mechanisms; specialized exchanges and new trading platforms; commodity markets, commodity and commodity derivatives exchanges linked to domestic and international physical commodity markets; and regional supply chain services, logistics hubs, maritime transport, and seaport infrastructure. Da Nang: The IFC in Da Nang will mainly develop green finance and commercial finance for SMEs and innovative enterprises, non-resident organizations and individuals (i.e., offshore financial services); cross-border trade activities linked to free trade zones, high-tech zones, new economic zones, and industrial zones; pilot control mechanisms for emerging models, such as digital assets, cryptocurrencies, and digital payments and transfers; new exchanges and trading platforms; investment funds, remittance funds, and small and medium fund management companies; startups in financial solutions for consumer services, tourism, e-commerce, logistics, and services within free trade zones; and related support, advisory, development, and legal services. Incentives: The People’s Committees of Ho Chi Minh City and Da Nang will need to decide on their list of