You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 27, 2024

Thailand Updates Customer Codes for Heightened Money Laundering Risk

On May 17, 2024, Thailand’s Anti-Money Laundering Office (AMLO) issued an amended Notification Concerning the Rules for Designating or Reviewing the List of High-Risk Customers Who Require Close Monitoring under the Ministerial Regulation on Customer Due Diligence B.E. 2563 (2020). This notification, which took effect the following day, updates the previous version of the notification from 2022 to cover cybercrimes listed under the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes B.E. 2566 (2023). The amended notification sets out the steps that all financial institutions in Thailand must take to manage money laundering risks and to comply with the AMLO’s mandatory Guidelines on Customer Due Diligence.

Under the new notification, account holders suspected of engaging in or facilitating technological crimes, as recorded by the Anti Online Scam Operation Center (AOC), are to be classified as “high-risk persons.” The notification includes provisions for listing high-risk customers under two specific codes:

  • HR-03-1: This code applies to individuals who are the subject of either a petition or a complaint related to a predicate offense accepted by the relevant inquiry officer and recorded as a criminal case. It also covers individuals whose bank accounts are suspected of being used to conduct transactions related to crimes under the Emergency Decree on Measures for the Prevention and Suppression of Technological Crimes B.E. 2566 (2023), with victims seeking prosecution. The names of individuals in this category are received from responsible agencies according to the Criminal Procedure Code or the AOC and are documented in a publicly accessible online notification system.
  • HR-03-2: This code is for individuals involved in the commission of a predicate offense or those whose bank accounts are suspected of being used in such offenses, but whose cases have not been accepted or numbered by the relevant inquiry officer. Names under this category are provided by agencies such as the Royal Thai Police, the Financial Investigation Division, the Cooperation and Standard Development Division, banks, or other sources in Thailand.

These updated rules aim to ensure that relevant individuals and their transactions are closely supervised, thus enhancing the efficiency of monitoring high-risk customers and preventing technological crimes.

For more information on this new notification, or on any aspect of Thailand’s anti-money laundering regulations, please contact Chitchai Punsan at [email protected] or Panisara Moleegul at [email protected].

RELATED INSIGHTS​ 

June 19, 2025
The Bank of Thailand (BOT) has released draft guidelines establishing principles for managing artificial intelligence (AI) risks in the financial sector. The draft guidelines provide a structured framework for the responsible adoption of AI technologies. Financial service providers will be able to use the guidelines as a reference to appropriately manage their risks in a manner that aligns with internationally recognized best practices. The BOT is accepting public comments on the draft guidelines until June 30, 2025. Scope and Application The draft guidelines apply to all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. These guidelines supplement existing BOT risk management guidelines covering IT risk management, third-party risk management, data governance, and market conduct. The guidelines define AI systems as systems that mimic human intelligence, including machine learning, deep learning, generative AI (such as large language models), and agentic AI. This definition specifically excludes rule-based automation systems like robotic process automation and condition matching. Key Risk Management Principles The guidelines lay out two main principles in managing AI risk. Governance: Financial service providers should define and establish clear roles and responsibilities for their personnel and AI system supervision structures to uphold FEAT (fairness, ethics, accountability, and transparency) principles as follows: Stakeholder roles and responsibilities. Financial service providers should define roles and responsibilities for boards and executives on AI risk oversight. Responsibilities include establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. AI system usage policy. The AI system usage policy should be aligned with organizational objectives, regulatory requirements, and FEAT principles. These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management
June 16, 2025
Thailand has amended its primary anticorruption law to provide robust new protections and direct assistance to whistleblowers. The Organic Act on Anti-Corruption (No. 2) B.E. 2568 (2025) was published in the Government Gazette on June 5, 2025, and came into force the following day. The amendment introduces a clear framework for safeguarding and supporting individuals who report graft. The amendment addresses a critical gap in the previous legislation by establishing formal mechanisms to protect and assist those who come forward with information. The key changes aim to shield whistleblowers from retaliatory legal and disciplinary actions, thereby encouraging more citizens to participate in exposing corruption without fear of reprisal. Key updates to the law are discussed below. Whistleblower Immunity The amendment clarifies and strengthens legal immunity by revising section 132 of Thailand’s original anticorruption law from 2018. Under the revised section, individuals who provide good-faith statements, information, evidence, or opinions to the National Anti-Corruption Commission (NACC) regarding offenses under its jurisdiction will be protected from civil, criminal, and disciplinary liability. This protection is explicitly extended to individuals who provide information to other state agencies tasked by the NACC to investigate corruption, such as the Public Sector Anti-Corruption Commission or the whistleblower’s own supervisors. Protection and Assistance A new section added to the law establishes a clear and swift process for activating protections. When the NACC learns that a whistleblower is facing legal complaints, criminal charges, or disciplinary action due to their report, the commission must review the matter and decide on providing protection within 15 days. If the NACC determines that the whistleblower acted in good faith, its office is required to provide immediate assistance. Legal and Financial Support Another newly introduced section outlines a wide range of assistance measures the NACC office can provide in civil and criminal cases
June 12, 2025
Thailand’s Ministry of Finance has issued a royal decree placing the business of hire purchase and leasing of cars and motorcycles under the scope of the Financial Institution Business Act B.E. 2551 (2008), effective December 2, 2025. This is to ensure appropriate regulatory oversight of these business activities, as they function similarly to credit granting and serve as a source of funding for the public with a broad impact on the overall economic system and consumers at large. The business operators that this royal decree applies to include corporate entities engaging regularly in the business of hire purchase or leasing of cars or motorcycles, currently excluding: Financial institutions and specialized financial institutions. Individuals operating such businesses (noncorporate entities). Cooperatives. Key regulatory obligations of this royal decree include the following: Business operators must disclose interest rates, service fees, and other relevant business information to the public and report to the Bank of Thailand (BOT). Business operators must display how the annual percentage rate (APR), including all annual charges covering interest and service fees, is calculated. Business operators must maintain accurate accounting records in accordance with recognized accounting standards. The BOT may issue warnings or suspend operations if business operators fail to comply with this royal decree or act unfairly in a way that may result in serious harm to customers. Directors, managers, and responsible persons of any business operator that violates this royal decree may also be subject to the prescribed penalties. Before the royal decree takes effect, business operators should conduct internal assessments and engage with counsel to prepare for regulatory implementation. The BOT is expected to issue further subordinate regulations and guidance regarding: Interest, service fees, deposits, collateral, benefits, and penalties that may be charged by business operators. Contract content, methods of benefit calculation, and format in conducting
June 6, 2025
As from July 1, 2025, as part of its ongoing efforts to digitalize and streamline the delivery of public services, the Vietnamese government will officially conduct administrative procedures, both online and offline, only via electronic identity (“e-ID”) accounts on the VNeID platform. In particular: Online administrative procedures carried out via the National Public Service Portal or via information systems for administrative procedures at the ministerial or provincial level are required to be implemented by using e-ID accounts only. When receiving dossiers, authorities will be required to check and verify the e-IDs of companies or individuals responsible for conducting administrative procedures. Further, it is worth noting that to complete the registration of an e-ID account for a company, the legal representative of the company must hold a level-2 e-ID account. Compliance Considerations Vietnam’s first regulation of e-ID accounts for individuals and organizations was issued in Decree No. 59/2022/ND-CP dated September 5, 2022, on electronic authentication and identification. This decree was subsequently replaced by Decree No. 69/2024/ND-CP dated June 25, 2024, which governs the same matters. Registration and operation of e-ID accounts are centralized through VNeID, a digital ID app developed by the National Population Data Center under the Ministry of Public Security of Vietnam. Although the registration of e-ID accounts for companies is not explicitly mandated by law, the absence of an e-ID account may hinder companies from completing administrative procedures, including licensing and reporting obligations. Such non-compliance could consequently result in administrative penalties. To mitigate unexpected non-compliance and administrative fines due to the lack of an e-ID account, companies should be well prepared for and implement the registration of a company e-ID account as soon as possible.