You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

August 29, 2024

Thailand Updates Requirements for Digital Asset Business Governance and Exchange Rules

Thailand’s Securities and Exchange Commission (SEC) has revised its regulations on digital asset operators and exchanges to impose stricter governance standards on digital asset business operators and to align digital asset exchange rules with international standards. The new regulations are laid out in SEC Notification No. GorThor. 23/2567 on the Criteria, Conditions, and Procedures for Operating a Digital Asset Business (No. 24) and SEC Notification No. GorLorThor. 24/2567 on Determination of Prohibited Qualifications for Directors and Executives of Digital Asset Business Operators (No. 5). These were published in the Government Gazette on August 16, 2024, with most of the provisions taking effect on the same date.

Governance for Digital Asset Businesses

The heightened standards for digital asset business operators aim to ensure efficient business supervision and appropriate response to operational risks. The new requirements mainly address:

  • Board of directors composition. Large-sized digital asset business operators (i.e., those with at least 10,000 customers and holding customer assets of at least THB 500 million) who do not provide digital asset custodian services must have at least five directors, at least two of whom must be independent directors. In addition, the business operators must establish an audit committee, with at least two members being independent directors, to create an appropriate “check and balance” mechanism within the organizational structure. Current digital asset business operators must comply with the requirements within 180 days of the notification’s effective date.
  • Qualifications of authorized directors and managers. Authorized directors and managers are now required to (1) either have at least one year of working experience in the digital asset field or have participated in a digital asset course from an SEC-approved list, and (2) participate in a good corporate governance course recognized by the SEC. Current authorized directors and managers who have not previously completed a good corporate governance training course must complete such a course within one year of the notification’s effective date.
  • Management and operational structures. Check-and-balance mechanisms are required for every major operational system. Business operators must establish a customer asset management policy, and all customer assets in the business operator’s custody must be managed according to the security risk and by separate personnel from other operational personnel that may have a conflict of interest. Business operators must also provide a customer service system that is suitable to the risk and complexity levels of the relevant types of digital assets.

Exchange Rules

The SEC has also introduced new minimum requirements for digital asset exchange rules, which must be approved by the SEC. The key updates include:

  • Listing and delisting rules. As indicated by a new utility token supervisory scheme that was issued days earlier, group 1 utility tokens are not allowed to be listed on the exchange. (Group 1 utility tokens are those issued for consumption purposes or as a digital representation of a certificate, such as loyalty points, concert tickets, NFTs, and carbon credits.) In addition, listing rules now require adoption of the “silent period” concept, whereby tokens offered for sale below the market price cannot be listed in the six months after the offering. In terms of issuer disclosure, digital asset exchanges must now require digital token issuers to disclose information as stipulated by the SEC.
  • Trading, clearing, and settlement rules. Digital asset exchanges are now required to have a real-time trade monitoring system to detect abnormal trades, and daily monitoring reports must be submitted to the SEC. If the digital asset exchange finds suspicious action, it must promptly report this to the SEC. The digital asset exchange must also have signposting to inform investors about potential risks from investing in certain tokens.
  • Market makers. Digital asset exchanges with market makers must have rules on qualifications, scope of work, ongoing performance supervision, and noncompliance measures relating to market makers.

For more information on these new notifications, or on any aspect of digital assets and cryptocurrency in Thailand, please contact Kobkit Thienpreecha at [email protected], Pornpan Wichawut at [email protected], Napassorn Lertussavavivat at [email protected], or Rujaporn Paritsantik at [email protected].

RELATED INSIGHTS​ 

June 18, 2024
On June 1, 2024, Thailand’s Securities and Exchange Commission (SEC) issued four notifications amending existing regulations to recognize sustainability-related tokens and institute specific measures for regulating them. These tokens are intended to offer diverse sustainability-related products to ESG funds in Thailand and drive the growth of a sustainable digital economy in the country. The key points in the notifications are summarized below. Definitions Under the notifications, sustainability-related tokens are classified into four types: Green tokens: Digital tokens specifically intended to incentivize or fund projects that promote environmental sustainability. Social tokens: Digital tokens specifically intended to support and fund initiatives that contribute to social welfare. Sustainability tokens: Digital tokens intended to support projects that enhance both environmental and social welfare through funding and incentives. Sustainability-linked tokens: Digital tokens intended to fund activities that promote sustainability. This includes tokens that have adjustable returns based on the performance of the issuing entity or its affiliates in meeting specified sustainability-related goals or outcomes. The offering of sustainability-related tokens is subject to Thailand’s general requirements for token offerings: (1) approval from the SEC and (2) filing the registration statements and the draft prospectus with the SEC before marketing and offering the sustainability-related tokens to public investors in Thailand, unless exempted. The sustainability-related tokens must be offered through an SEC-approved ICO portal, which will assume a role similar to that of a financial adviser and an underwriter in a public offering of securities. Sustainability-Related Token Offerings In addition to complying with the general requirements for token offerings, sustainability-related token offerings must comply with the following measures: Issuer disclosure: The issuer must disclose certain sustainability information, both before and after the offering, according to standards comparable to those of nationally or internationally recognized green, social, and sustainable bonds (GSSBs) and sustainability-linked bonds (SLBs)—such as the principles
June 13, 2024
The Bank of Thailand (BOT) has announced its new Enhanced Regulatory Sandbox, which provides an opportunity to experiment with currently restricted financial innovations under a controlled environment. The BOT is employing a thematic approach to determine the scope of technology or innovations that may participate in the Enhanced Regulatory Sandbox and will only accept applications in each theme for a limited period. The first announced theme is “programmable payments,” which refers to payment and payment-related transactions with automatic execution upon the fulfillment of a predefined condition utilizing distributed ledger technology (DLT) and a smart contract or comparable technology in which electronic data units are issued on an electronic system or network. The application period for programmable payment testing in the Enhanced Regulatory Sandbox runs from June 13 to September 13, 2024. A summary of the programmable payment testing framework under the Enhanced Regulatory Sandbox is provided below. Scope The Enhanced Regulatory Sandbox accepts applications for the following programmable payment activities: Automated payment and settlement upon fulfillment of predefined conditions. Escrow services with predefined delivery or transactional conditions. Asset tokenization through issuance of digital tokens representing rights in an asset, with payment for tokens or payment of benefits or returns to holders of digital tokens occurring automatically when conditions are met. Other testing related to the items mentioned above. Requirements and Conditions Programmable payment testing activities in the Enhanced Regulatory Sandbox must comply with the following requirements and conditions: Electronic data units issued for programmable payment testing must be pegged to the Thai baht (THB) on a one-for-one basis (i.e., 1 unit = THB 1), with the float account storing THB equal to the value of the electronic data units issued. Participants must define the redemption rights of the unitholders and proceed with the THB redemption according to the participants’
June 3, 2024
On May 24, 2024, the Central Bank of Myanmar (“CBM”) issued a public notice warning individuals against participating in the sale, purchase, exchange, or transfer of unregulated digital currencies, as well as unauthorized money transfers. The CBM has indicated its readiness to enforce regulations by closing bank accounts and pursuing legal action, which may result in imprisonment, fines, or both, in accordance with the Central Bank of Myanmar Law, the Anti-Money Laundering Law and the Financial Institutions Law. The CBM is the sole legal entity authorized to issue currency in Myanmar, as stipulated in the Central Bank of Myanmar Law. The CBM does not recognize digital currencies as official currency, nor has it granted permission to financial institutions within Myanmar to trade them. The existing legal framework, comprising the Foreign Exchange Management Law and the Financial Institutions Law, further cements the illegality of cryptocurrency transactions within the nation’s borders. Four years ago, in May 2020, the CBM issued Notification No. 9/2020, prohibiting all persons residing in Myanmar from engaging in the sale, purchase, or exchange of unregulated digital currencies. The list of prohibited currencies includes widely recognized cryptocurrencies such as Bitcoin (BTC), Litecoin (LTD), Ethereum (ETH), and Perfect Money (PM), with a particular emphasis on transactions conducted through personal Facebook accounts and web pages. Before the issuance of the 2020 notification, the CBM had announced that anyone engaging in digital currency transactions did so at their own risk, but no enforcement measures were being taken at the time. However, after the 2020 notification was issued, the CBM has pursued legal action against persons involved in illegal currency conversion and unauthorized hundi money transfers using Tether (USDT). These enforcement measures have included shutting down bank accounts and initiating legal proceedings under the Anti-Money Laundering Law and the Financial Institutions Law.
May 15, 2024
On May 1, 2024, Thailand’s National Cyber Security Committee (NCSC) published the draft NCSC Notification Re: Cloud Cybersecurity Standards for a public hearing period, which was open until May 14, 2024. These standards have been drafted to drive the country’s cloud-first policy with the aim of minimizing risks from cyber threats to cloud services utilized by government agencies, supervising or regulating organizations, and critical information infrastructure (CII) organizations. The key points of the draft Cloud Cybersecurity Standards are below. Scope The standards apply to government agencies, supervising or regulating organizations, and CII organizations under the Cybersecurity Act B.E. 2562 (2019), as well as cloud service providers (defined below). The standards prescribe cloud system cybersecurity measures for cloud service customers (defined below) and providers only to the extent that the service is provided to the in-scope organizations outlined above. Definitions Cloud service customers (CSCs): In-scope organizations that have a formal contractual agreement to use cloud services provided by a cloud service provider. Cloud service providers (CSPs): Persons who enable cloud services to be used by a cloud service customer, responsible for maintaining infrastructure, platforms, and software that enable provision of the cloud services and for managing these resources to ensure their accessibility, security, and scalability for their cloud service customers. Application In-scope organizations that will use or have been using cloud services must comply with the Cloud Cybersecurity Standards by taking into account their data or technology information systems’ level of impact, as specified in the previously issued Notification of the NCSC Re: Standards for Defining the Security Category for Data and Information Systems B.E. 2566 (2023). The impact level related to personal data is to be rated as being at least at the medium level, and the minimum standards for that level specified in the draft Cloud Cybersecurity Standards