You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

October 2, 2019

Thomson Reuters Country Guides: Money Laundering – Thailand Chapter

Thomson Reuters Country Guides

This country profile looks at Thailand, which traditionally has had a reputation as a “crossroads” for numerous illegal activities and of the laundering of significant sums of tainted money.

Member of the Financial Action Task Force (FATF)? No.

Any Egmont members?  Yes. Thailand’s Anti-Money Laundering Office (AMLO) is a member of the Egmont Group.

Regulation

The law, known as the Anti-Money Laundering Act (the Act), was passed in March 1999 with the aim of combating not only the drug trade, but other illicit activities, such as corruption, criminal fraud and prostitution.

There have been a number of changes and updates to the Act, the most recent one in late 2015, in which the Act was amended to include:
  • Additional predicate offenses such as offenses relating to human trafficking, online gambling and offenses relating to unfair practices relating to derivatives and agricultural commodity futures.
  • Broader scope of money laundering offense.
  • Non-disclosure obligations to applicable financial institutions and reporting entities.
  • Compulsory training to financial institutions and reporting entities’ employees responsible to monitor and ensure compliance with the Act.
  • Retention period.
  • Enhanced penalties.

Financial intelligence unit

Of the total number of transactions reported to AMLO annually, a relatively small portion result in further investigation for violation of the Act. That said, the trend is for more active participation and enforcement by AMLO in recent years.

Targeted crimes

Currently, the Act covers the transfer or conversion of funds or property obtained from the following predicate offenses:

  1. Offenses relating to narcotics
  2. Human trafficking and offense of sexuality and prostitution
  3. Fraud against the public
  4. Fraud involving financial institutions
  5. Abuse of position by a government official
  6. Extortion
  7. Trade in contraband
  8. Terrorism
  9. Gambling offences, including online gambling, with particular emphasis on large scale organization of gambling games
  10. Participation in racketeering groups or participation in a criminal association
  11. Receiving stolen property only as it constitutes assisting in the selling, buying, pawning or receiving, in any way, property obtained from the commission of an offence with the nature of business conduct
  12. Counterfeiting or alteration of currencies, seals, stamps and tickets with the nature of business conduct
  13. Criminal trading only where it is associated with the counterfeiting or violating of intellectual property rights to goods or the commission of an offense under the laws on the protection of intellectual property rights with the nature of business conduct
  14. Forgery of a document of right, electronic cards or passports with a nature of regular or business conduct
  15. The unlawful use, holding, or possessing of natural resources or a process of illegal exploitation of natural resources with a nature of business conduct
  16. The commission of an offense relating to murder or grievous bodily injury which leads to the acquisition of assets
  17. Restraining or confining a person only where it is to demand or obtain benefits or to negotiate for any benefits
  18. Theft, extortion, blackmail, robbery, gang-robbery, fraud or misappropriation with a nature of regular conduct
  19. Acts of piracy under anti-piracy law
  20. Unfair securities trading practice under the law on securities and stock exchange or unfair futures trading under the law on futures contracts or unfair practice which affect trading price of agricultural futures under the law on agricultural futures trading
  21. Offenses related to arms and arms equipment which is or may be used in combat or war under the law on arms control

Money laundering offense

Under the Act, it is a crime to transfer, convert or receive the transfer of funds or property arising from the above referenced criminal offences for the purpose of hiding or concealing the source of the funds.

Penalty:

  • Natural person: imprisonment for a term of one year to 10 years and/or a fine of 20,000 to 200,000 baht.
  • Juristic person: a fine of 200,000 to 1,000,000 baht.

It is also important to note that the March 2008 amendments include provisions targeted specifically at government officials, whereby the aforementioned fines and maximum prison sentences are doubled for government officials and can be tripled if certain categories of government officials are involved in a conspiracy to commit a money laundering offence. This represents a concerted effort to tackle the consistent problem of institutional corruption in Thailand.

Banking transactions are a primary activity subject to scrutiny under the Act, but other financial transactions are also covered. For example, an individual who secretly uses money from a drug sale to purchase shares of publicly traded stocks on the Stock Exchange of Thailand could be prosecuted under the Act. Furthermore, a corrupt government official who uses money obtained from a bribe to then purchase land runs the risk of being exposed, having the land confiscated and being subject to double-scale fines. Even property developers, who knowingly hold or accept money for concealment that they know is derived from one of the stated criminal offences, can be subject to enforcement under the Act.

Enforcement officials can seize, without a warrant, money or property connected with the commission of one of the enumerated criminal offences or a money laundering offence. In such cases, the owner of the seized property must be able to demonstrate that the property is unrelated to the commission of one of the enumerated crimes, or a money laundering offence, in order to recover the property.

Reporting requirements

A key provision of the Act is the requirement that financial institutions and other reporting entities that tend to be used as vehicles for money laundering report all cash transactions of 2 million baht or more. Property transactions in excess of 5 million baht must also be reported. Also required for reporting are all suspicious transactions that may be related to one of the enumerated criminal offences, are more complex than normal, lack economic plausibility, or appear to have been undertaken to avoid compliance with the anti-money laundering law. For such transactions, the financial institutions must require their customers to provide a detailed record of the transactions. The latter requirement is generally left to the practical discretion of the financial institution which must then choose between customer confidentiality concerns and compliance with the Act.

The AMLO has also implemented separate regulations which require all persons entering or leaving Thailand to declare currency in their possession where the amount meets or exceeds certain statutory minimum levels.

Failure to comply with the Act’s reporting requirements is punishable by a fine of up to 1 million baht and a daily fine of up to 10,000 baht a day through the period of violation or not acting correctly. Filing a false report is punishable by imprisonment of up to two years and/or a fine of 50,000 to 500,000 baht.

Thailand has made great progress in its legislative efforts to combat illicit crime and the transfer of funds related to such crimes. While much has been done and the laws are in place, ultimate success depends on the practical enforcement of the law.

RELATED INSIGHTS​ 

December 3, 2025
Recent high-profile corporate fraud and accounting scandals have brought increased scrutiny to governance, compliance, and enforcement practices in Thailand, highlighting the legal and practical challenges facing companies operating in the country. As regulators and law enforcement authorities sharpen their focus on financial misconduct, cybercrime, and corruption, businesses must navigate a complex and evolving investigative landscape. Tilleke & Gibbins’ investigations and compliance team examines these issues in the Thailand chapter of The Practitioner’s Guide to Global Investigations – Tenth Edition, published by Global Investigations Review (GIR). The chapter provides a detailed overview of Thailand’s legal framework for corporate investigations, offering practical guidance for companies and counsel responding to regulatory and criminal scrutiny. The Thailand chapter covers key topics including corporate criminal liability, enforcement priorities, internal investigations, data protection considerations, dawn raids, whistleblowing, cyber-related investigations, and cross-border cooperation. It also addresses emerging issues such as cybersecurity enforcement, economic sanctions compliance, and anticipated developments affecting investigations in Thailand. The chapter is authored by John Frangos, Chitchai Punsan, Alongkorn Tongmee, Michael Ramirez, Piyawat Vitooraporn, and Michelle McLeod. The Thailand chapter is available as a PDF below, and the full guide can be accessed on the GIR website.
November 24, 2025
A recent warning from the Central Bank of Myanmar (CBM) against cryptocurrency use upholds the country’s ongoing strategy of enforcing strict prohibitions on unauthorized cryptocurrency activities while also promoting the controlled development of a central bank digital currency (CBDC). The CBM’s warning, issued November 16, 2025, reminded the public of announcements in May 2019 and a notification in May 2020 confirming that all online and offline cryptocurrency transactions are strictly prohibited. The CBM also clarified that no financial institution in Myanmar is authorized to deal with digital currencies. The warning highlighted global risks, such as money laundering, scams, tax evasion, hacking, and severe financial losses caused by price volatility and insufficient regulation. The CBM urged the public to use only legitimate banking channels and avoid illegal cryptocurrency activities. The warning comes five months after the CBM issued a notification announcing the formation of the Central Committee for the Issuance of a Central Bank Digital Currency. This committee includes senior CBM officials, representatives from relevant ministries and the banking sector, and technology experts. Its main role is to research CBDC models, test secure digital payment systems, and ensure that any future implementation aligns with Myanmar’s monetary policy and financial stability objectives. Taken together, these two actions illustrate the CBM’s continued pursuit of its dual strategy to promote innovation through CBDC development while prohibiting cryptocurrency use. Businesses should note that while CBDC pilot programs may appear in the future, cryptocurrencies remain off-limits.
September 24, 2025
On September 12, 2025, the Bank of Thailand (BOT) officially released its AI Risk Management Guidelines for Financial Service Providers, building upon the draft guidelines issued in June 2025. The guidelines reflect a balanced approach, encouraging innovation while safeguarding financial stability and consumer protection. The guidelines are targeted at all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. The guidelines apply to both AI systems developed in-house and those developed by third parties that are adopted for use by financial service providers. AI Risk Management Guidelines The two main pillars in managing AI risk are (1) governance of AI system implementation and (2) AI system development and security controls, consisting of the following key elements: 1. Governance Stakeholder roles and responsibilities. Boards and senior management assume accountability for decisions and operations involving AI systems, and are responsible for defining roles and responsibilities for AI oversight. This includes establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. Organizations are expected to foster internal capabilities to use AI securely and avoid overreliance that could compromise business continuity or customer service. AI system usage policy. Policies governing AI usage should align with organizational goals, regulatory obligations, and recognized responsible AI frameworks—such as the FEAT principles (fairness, ethics, accountability, and transparency). These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. Financial service providers should assess risks and impacts of AI usage on operations and customer services.
September 12, 2025
On September 10, 2025, Vietnam’s National Credit Information Center (CIC) reported to the Vietnam Cybersecurity Emergency Response Team (VNCERT) a suspected significant cybersecurity incident involving unauthorized access to the CIC’s credit information database. A hacker group has claimed responsibility and allegedly posted over 160 million records for sale, including sensitive personal and financial data. Implications for Banks and Financial Institutions Companies that share customers’ or potential customers’ personal data with the CIC for credit scoring or other purposes—and continue to act as a data controller for such data—may be obligated under Vietnam’s Personal Data Protection Decree (PDPD) and related regulations to: Notify A05 (Department of Cybersecurity and High-Tech Crime Prevention) and the State Bank of Vietnam without delay. Inform affected individuals if their personal data is at risk. Recommended Actions Companies that could be impacted by this data breach should take the following actions: Conduct an internal review of CIC-related data in their systems, and identify whether and how the systems have been affected by this incident. Assess whether to notify regulators and customers/potential customers. Enhance cybersecurity controls, monitor for suspicious activity, and implement additional safeguards to prevent secondary breaches.