You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

June 5, 2026

Thailand’s Insurance Regulator Proposes Amendments to IT Risk Management Regulations

Thailand’s Office of Insurance Commission (OIC) has opened a public hearing on proposed amendments to the OIC Notification on Criteria for Information Technology Risk Governance and Management for Life Insurance and Non-Life Insurance Companies B.E. 2563 (2020) via the centralized Law platform. The public consultation period runs from May 8, 2026, to June 9, 2026.

The proposed amendments aim to elevate the IT risk governance and cybersecurity risk management framework to be more modern and aligned with international standards, with a focus on strengthening cyber resilience, enhancing the role of IT audits, and establishing data governance and data quality controls.

The parties affected by these amendments include life insurance companies, non-life insurance companies, and external IT auditors.

Key Changes

Elevated Role of Board of Directors

The proposed notification requires the company’s board of directors to oversee data governance, cybersecurity, and the responsible use of AI. Additionally, the board should include at least one director with IT knowledge or experience. Companies are also required to designate a head of security responsible for information security. The board’s duties are expanded to include oversight of data governance and AI usage, including establishing relevant policies and committees.

Enhanced IT Security and Cybersecurity

The revised notification consolidates the existing chapters on IT project management, IT security and cybersecurity to reduce redundancy, and introduces significant new measures. These include mandatory multi-factor authentication for material systems, enhanced data security measures such as data masking and data leakage prevention, security hardening requirements, web filtering, and mandatory vulnerability assessment and penetration testing at least annually. New requirements are also introduced for mobile application security, API security, and security measures for emerging technologies such as cloud computing and post quantum cryptography.

The cybersecurity framework now encompasses identification, protection, detection, response, and recovery. The draft also introduces source code review requirements for system development and mandates security controls when AI is used to support system development.

IT Risk Management and IT Compliance

The revised notification requires the appointment of a qualified IT risk officer with relevant knowledge and experience, and mandates risk reporting to management or the board at least annually. For IT compliance, companies must designate personnel responsible for monitoring, assessing, and reporting on regulatory compliance, including summarizing non-compliance incidents and remediation measures to the relevant committee.

Enhanced IT Audit Requirements

The draft introduces a requirement for external IT auditors to hold CISA or ISO/IEC 27001 lead auditor certifications. Audit planning must adopt a risk-based approach. Material systems must undergo a full-scope audit at least every three years, while high-risk systems require full-scope audits annually. In the event of a cyber attack, affected systems must be subject to a full-scope audit within the year the incident occurs, except where the incident occurs in the fourth quarter of the year.

Data Governance

A new Data Governance chapter is introduced as a regulatory requirement. Companies must establish data management processes throughout the data life cycle, covering data life cycle management, metadata management, data quality management, data risk management, data security, and data privacy. Data quality must be reviewed and reported at least annually.

AI Governance

A new AI Governance chapter requires companies using AI to establish policies and governance processes throughout the AI usage life cycle, with responsibilities divided according to the “three lines of defense” model. This covers both in-house development and third-party services, risk assessment and monitoring, AI performance evaluation, and data management in accordance with the AI governance guidelines.

Cyber Incident Reporting Framework

Currently, companies must report incidents involving critical information infrastructure to the OIC or other agencies as prescribed by law within 72 hours. The draft provides greater clarity on the types of incidents that must be reported, the information to be disclosed, and the agencies to be notified.

Recommended Actions for Insurance Companies

Life insurance and non-life insurance companies should assess the impact of these proposed changes on their current governance structures, risk management processes, and IT systems. Stakeholders may submit comments through the centralized Law platform until June 9, 2026.

RELATED INSIGHTS​ 

September 24, 2026
On September 15, 2026, Thailand’s Office of Insurance Commission (OIC) issued two notifications—one for life insurance and one for non-life insurance—amending the 2020 regulatory framework governing policy issuance and offering, agent and broker conduct, premium collection, and advertising. The amendments take effect on January 1, 2027. Electronic Policy Delivery and OIC Reporting Insurers must now deliver policies electronically by default, with printed copies required only where the policyholder opts out of electronic delivery. For life insurance, this requirement extends to coverage summaries and exclusion documents. Insurers must also electronically submit issued policies to the OIC immediately upon issuance. This is a significant new data-reporting obligation that requires system integration with the OIC’s platform. Risk Management, Sales Conduct, and License Misuse The notifications introduce several amendments and additional requirements in the areas of risk management, sales conduct, and license misuse: Internal risk management must now expressly cover advertising, policy offering, and sales agent information, including market conduct risk and reputational risk. Sales conducted through employees, agents, or brokers are subject to enhanced requirements, including verification of the seller’s identity and authority, disclosure of the purpose of contacting the customer, provision of complete and accurate policy information, customer assistance with application forms, and notification of the expected timing for policy delivery or insurer follow-up. For life insurance, customers must also be informed of their right to cancel the policy. For life insurance specifically, employees, agents, and brokers must submit insurance applications to the insurer at the earliest opportunity, and no later than the next business day. Using another person’s name or license, or allowing another person to use one’s own name or license, for the purpose of offering insurance for sale, listing in sales-related documents, or recording in the insurance policy is now expressly prohibited for both life and non-life insurance.
September 15, 2026
Insurance specialists from Tilleke & Gibbins in Bangkok have contributed the updated Thailand chapter to the newly released 2026 edition of Thomson Reuters’ Practical Law guide to insurance and reinsurance. The Thailand chapter offers a comprehensive Q&A-style overview of the legal and regulatory framework governing insurance and reinsurance in the country. It provides key insights for businesses, insurers, reinsurers, and intermediaries operating in or entering the Thai market. Key topics covered include: Market structure and common types of insurance Regulatory framework and oversight by the Office of Insurance Commission (OIC) Authorisation requirements for insurers, reinsurers, and intermediaries Ownership restrictions and foreign investment rules Corporate governance, capital requirements, and solvency obligations Reinsurance arrangements, including fronting, risk transfer, and common contractual clauses Policy content requirements, standard clauses, and consumer protections Claims procedures, statutory time limits, and subrogation rights Dispute resolution mechanisms, including OIC arbitration and court proceedings Insolvency protections for policyholders Tax treatment of insurance and reinsurance businesses in Thailand Recent legal developments, including updated OIC regulations and insurance licensing guidelines The 2026 edition reflects Thailand’s evolving regulatory environment, including ongoing legislative reforms to strengthen corporate governance, risk-based capital requirements, and digital media compliance in the insurance sector. It also highlights practical considerations for foreign insurers, reinsurers, and intermediaries seeking to participate in Thailand’s insurance market. Tilleke & Gibbins contributes regularly to the Practical Law series of guides for various jurisdictions in Southeast Asia, providing trusted legal insight for multinational companies. Access the full Thailand chapter below. Reproduced from Practical Law with the permission of the publishers. For further information, visit practicallaw.com.
August 20, 2026
As part of its membership in Lex Mundi, Tilleke & Gibbins has released the latest edition of its Guide to Doing Business in Thailand, providing an overview of the legal, regulatory, and commercial considerations for companies establishing or expanding operations in Thailand. The 2026 edition offers practical insight into the country’s business environment, investment framework, and operational requirements. The guide covers a wide range of topics relevant to foreign and domestic investors, including: Investment incentives and promotion schemes Financial facilities and banking regulations Exchange controls and money transfers Import and export regulations Business structures and incorporation options Requirements for establishing a business Operational and compliance considerations Business cessation and insolvency procedures Employment and labor laws Taxation Immigration and visa requirements Prepared by Tilleke & Gibbins lawyers across multiple practice areas, the publication outlines key aspects of doing business in Thailand, including foreign investment restrictions, regulatory compliance obligations, corporate structures, employment requirements, and recent legal and economic developments affecting investors. The publication forms part of Lex Mundi’s Country Guides series, a global collection of jurisdiction-specific reference materials prepared by member firms around the world. Together, these guides help companies evaluate opportunities, compare regulatory environments, and plan international business activities across multiple markets. The full Guide to Doing Business in Thailand 2026 is available through the button below.
August 14, 2026
Thailand’s Office of the Insurance Commission (OIC) has issued guidelines clarifying the boundaries between permissible and prohibited activities for unlicensed individuals—including influencers, bloggers, and content creators—when communicating about insurance products on social media. The Good Practice Guidelines for Persons Not Licensed as Insurance Agents or Brokers Regarding the Dissemination of Insurance Content Through Digital Media B.E. 2569 (2026) took effect on July 24, 2026. Activities Requiring a License The guidelines reserve the following activities for licensed agents and brokers: Soliciting or facilitating insurance contracts. Providing personalized advice on product suitability. Recommending policy cancellation to purchase promoted products. Creating links that facilitate contract formation. Receiving performance-based compensation tied to policies or premiums generated. Importantly, boilerplate disclaimers such as “this is not a recommendation to buy insurance” will not shield individuals from liability if the OIC views the content as personalized advice or solicitation. Permitted Activities Unlicensed persons may present general educational content about insurance—such as explaining terminology, sharing industry statistics, reporting news, or sharing personal experiences—provided the content does not target specific individuals to purchase from specific companies. The guidelines also set out best practices for communication, including presenting information in a fair and balanced manner that covers both benefits and limitations, encouraging consumers to read policy terms and consult licensed professionals, verifying information from credible sources before dissemination, and exercising special care when the audience may include vulnerable groups such as persons aged 60 and older. Prohibited Practices Prohibited practices include fear-based marketing, creating artificial urgency, omitting material limitations, making exaggerated claims, falsely claiming professional credentials, using fake engagement mechanisms, and sharing false or misleading content. The guidelines also reinforce the prohibitions under section 83 of the Life Insurance Act B.E. 2535 and section 78 of the Non-Life Insurance Act B.E. 2535 against soliciting insurance contracts with foreign operators