You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

December 21, 2018

Thailand’s OIC Issues New Regulations for Providing Insurance, Effective January 1, 2019

Thailand’s Office of Insurance Commission (the OIC) has issued two sets of requirements—collectively called the OIC Notifications Re: Conditions Relating to Issuing and Offering Insurance Policies of Insurance Companies, and Duties of Non-life Insurance Agents, Brokers and Banks 2018 (the Notifications)—imposing practical new requirements on life and non-life insurance and reinsurance companies in Thailand.

The key provisions are listed below, and are applicable to both life and non-life insurance unless expressly specified otherwise. All provisions come into force on January 1, 2019.

Corporate Culture

  • The board of directors and the executives must produce an internal policy, a business plan, and a business strategy, in writing, for the purpose of promoting tangible and effective fair dealing with customers. These must be rolled out to all of the company’s employees and insurance intermediaries.
  • Companies must conduct risk management in respect of conducting business, exercising fair treatment, and dealing with customers, including:
  • Preparing and developing product wording and premium rates;
  • Advertising and the offering insurance products;
  • Collecting, storing, and securing customers’ personal data;
  • Servicing insureds;
  • Handling claim compensation and monitory benefits according to policies; and
  • Handling complaints.

Conduct in respect to the issuance of insurance products

  • After concluding a sale, companies must issue the policy and send it to the insured with a summary of the coverage and the exclusions. In the case of a group policy, the documents must be sent to the policy holder or the insured. The insured members of the group policy must be provided with an insurance certificate, including a summary of the coverage, the exclusions and the conditions.
  • In the event of a renewal, where there is no change to the coverage and conditions, the company may choose to send a renewal certificate to the policy holder/insured/group members, upon their request, instead of the whole policy. This is not applicable insurance products that the insured is legally required to procure.

Conduct in respect to the issuance of insurance products

  • Conduct in respect to offering insurance products
  • Companies must ensure that their intermediaries comply with the Notifications. If they do not comply, and the intermediary fails to rectify their incompliance, they must be de-authorized no later than seven days from the deadline that the company provides for rectification. The company must notify the OIC of the non-compliance and the outcome.
  • Permitted distribution channels include offering by:
  1. Employees or staff;
  2. Phone (telesales);
  3. Bancassuance;
  4. Post;
  5. Electronic means; and
  6. Other means.

Premium remittances can only be made to the company’s account for products offered through channels (2), (3) and (4).

  • Companies must publicly disclose the details of their intermediaries (e.g. names and license numbers).
  • When offering insurance products, the company/intermediary must:
  • Explain that the information provided in the application must be true and complete and the consequence of incompliance;
  • Clearly identify the insurer, which is the product issuer;
  • Create no disturbance or annoyance to the customer and immediately stop the sale when the customer declines;
  • Provide information about the premium amount, payment period, and insured period (separately from any other financial product offered together in a bundle—customers must be informed of any such bundling);
  • State how the customer information was obtained upon the customer’s request;
  • NOT, in order to procure a sale, induce the insured to cancel another insurance policy; provide untrue or misleading information, or omit any material information; or require the customers to buy insurance as a condition for providing other services.
  • Telesales:
  • The offering must be by employees, staff, agents, brokers, or banks, which have been authorized by the company. Companies must submit the name of authorized persons to the OIC within 7 days of authorization.
  • Calls can only be made from Monday to Saturday between 8.30am and 7.00pm.
  • For non-life products, a minimum 30-day free look period is required, except for compulsory motor and micro-insurance (fire).
  • Calls cannot be made to the customers who have made a “do not call” request for a period of at least six months. Companies must keep a “do not call list” and make it readily available upon request from the OIC.
  • Calls must be recorded, and recordings can only be made with the prior consent of the customers. Telesales scripts must be approved by the company in advance.
  • A confirmation call must be made within seven days.
  • Sales by post
  • Sales can only be made by the company, agent, broker, and bancassurance, and the customer must express their intention to buy the insurance policy by post.
  • The company must provide (and ensure that its intermediaries provide):
  • Name, address, and phone number, by which the company can be contacted;
  • OIC approved product wording;
  • Payment channel and coverage commencement date;
  • Insured term; and
  • Certificate of insurance (if applicable).

The name and the contact details of any intermediaries must also be provided to the customer.

After sales service

Companies must have a complaints system and process, including provisions on policy cancellation and premium refunds.

For advice on how to comply with these new regulations, or for any other information, please contact Athistha (Nop) Chitranukroh on [email protected] or +662 056 5600

RELATED INSIGHTS​ 

April 2, 2026
Thailand’s Personal Data Protection Act (PDPA) enforcement has entered a new phase, and the insurance industry is squarely in the regulatory spotlight. The Personal Data Protection Committee (PDPC) considers insurers “large-scale” processors of sensitive data—including health records, financial information, and biometric data—making the sector a focal point for enforcement action. In August 2025 alone, the PDPC issued administrative fines totaling THB 21.5 million, and fines for individual violations have ranged from THB 50,000 to THB 2 million. The PDPC has also deployed its “Eagle Eye Crawler,” an AI-driven surveillance tool that monitors websites around the clock for data leaks and noncompliant privacy notices. This article highlights the key regulatory developments directly affecting insurers and outlines practical steps toward compliance. What Has Changed: OIC and PDPC Alignment The Office of Insurance Commission (OIC) has synchronized its sector-specific rules with the PDPA through the Notification on Customer Personal Data Protection (No. 2) B.E. 2568 (2025). The combined effect of the PDPC’s general enforcement push and the OIC’s sectoral guidance creates four critical compliance areas for insurers. Consent unbundling. Consent for marketing must be strictly separated from the core insurance contract; bundling marketing consent into the policy application is no longer permissible. Agent and intermediary oversight. Insurance intermediaries are generally classified as data processors, meaning that insurers—as data controllers—must provide specific written instructions and security protocols to all agents and brokers. A 2026 enforcement trend shows controllers being held liable for the “weak security” of their vendors and downstream processors. Enhanced privacy notices. Insurers must provide a summary privacy notice alongside the full policy, plainly stating categories of data, purposes, lawful bases, disclosure recipients, cross-border transfers, retention periods, data subject rights, and easy marketing opt-out channels. DPO registration and ROPA. All organizations involved in “regular or systematic monitoring of data subjects on
March 17, 2026
Thailand’s Office of Insurance Commission (OIC) has introduced comprehensive group-wide supervision requirements for insurers operating within corporate groups. Published on February 26, 2026, in two separate notifications in the Government Gazette, the new rules establish parallel frameworks for life and non-life insurance companies. Both notifications take effect on July 1, 2026, and impose significant new requirements on insurance business groups. Affected insurers should begin reviewing their group structures, governance frameworks, and risk management systems now to ensure timely compliance. The notifications aim to ensure that group-level operations are orderly, stable, and reliable, and prevent the accumulation of systemic risk that could undermine public confidence in the insurance sector. Both notifications share a substantially parallel structure and require insurers to assess and manage the financial position, risk exposure, reliability, and corporate governance of their entire insurance business group on a comprehensive and ongoing basis. The regulations introduce definitions for several key terms. An “insurance business group” encompasses the insurer together with its ultimate parent company, parent companies, subsidiaries, and related companies. The “head of the insurance business group” is the entity responsible for overseeing group-wide supervision, operations, and governance. An “ultimate parent company” is one that exercises control without itself being controlled by another entity. Key Requirements The notifications establish the following core obligations for insurers: Group structure and shareholding reporting: Insurers must report the organizational chart and shareholding structure of their insurance business group—covering the ultimate parent company, parent companies, subsidiaries, and related entities—to the OIC registrar by June of each year, and whenever material changes occur. The regulations prescribe specific thresholds for determining when shareholding proportions constitute control. Corporate governance standards: Board members, executives, and authorized persons of the ultimate parent company or parent company must not be disqualified (e.g., bankrupt individuals, persons convicted of property-related fraud, or
January 22, 2026
On December 10, 2025, Vietnam’s National Assembly enacted Law No. 139/2025/QH15 amending the Law on Insurance Business. The amendment, effective from January 1, 2026, introduces various changes in an effort to lift restrictions and hurdles for insurance businesses. Key points that may impact the activities of stakeholders in Vietnam’s insurance market are highlighted below. Management Personnel Qualifications To broaden the talent pool while ensuring competency standards, the amended law opens up the positions of director or general director to more candidates. Previously, candidates were required to hold either (i) a university degree or higher in insurance or (ii) a university degree in another discipline and an insurance certificate issued by a qualified insurance training institution. Now, candidates holding a university degree or higher in economics, finance, banking, law, business administration, accounting, or auditing, with at least one insurance‑related module, are also accepted. These changes are expected to mitigate the ongoing challenges faced by insurers in recruiting suitably qualified candidates for key executive positions, while still maintaining appropriate professional standards. Fewer Registrations for Insurance Businesses As part of the legislature’s broader initiative to reduce administrative burdens across all business sectors, the amended Law on Insurance Business relaxes registration requirements for the insurance industry, notably: Insurance enterprises and foreign non‑life insurance branches are no longer required to register and obtain prior approval from the Ministry of Finance (MOF) for their methodologies and bases for calculating premiums for motor vehicle insurance products (excluding compulsory civil liability insurance for motor vehicle owners). Instead, insurance enterprises are now only required to notify the MOF before applying or amending these methodologies. While life insurers must continue to register with the MOF their principles for separating owners’ equity from insurance premium funds, non‑life insurance enterprises and foreign non‑life insurance branches are now only required to notify
August 8, 2025
Thailand’s Office of Insurance Commission (OIC) has opened a public hearing period on its amendments of notifications concerning the timeframe for an insurance company to submit its annual financial statements and financial and operating reports (called “XML reports”). The amended notifications also require insurance companies to submit some data sets from the quarterly capital maintenance reports and XML reports to the OIC in advance, before the full reports are submitted. Key changes in these amended notifications are summarized below. Financial Statements Audited annual financial statements will need to be submitted to the OIC within two months from the last day of each calendar year (i.e., by the end of February of the following year), instead of within four months as currently required. Capital Maintenance Reports While the deadline for submitting quarterly capital maintenance reports is still 45 days from the last day of the quarter, the OIC will now require life and non-life insurance companies to submit a set of data from the report in advance, within 21 days from the last day of each quarter. This data set includes the following information from the capital maintenance report: Form 1 – Calculation of Capital Adequacy Ratio (CAR) Form 2 – Calculation of Total Capital Available (TCA) Form 4 – Calculation of Capital for Insurance Risk (Table 4.1, 4.2, 4.4, and 4.5 for life insurance companies; Table 4.1 and 4.2 for non-life insurance companies) Financial and Operating Reports (XML Reports) Similar to the audited annual financial statement, the annual XML report will need to be submitted to the OIC within two months from the last day of each calendar year, instead of within the current four-month timeframe. For quarterly XML reports, which must still be submitted within 45 days from the last day of each quarter, there is a new