You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 15, 2024

Vietnam Revs Up Fintech Sector with Updated Draft of Sandbox Decree

Vietnam’s fintech industry is booming, and the rapid emergence of tech startups and non-bank institutions offering innovative financial services has been outpacing existing regulations. This regulatory gap not only creates uncertainty for both innovators and consumers, but also poses a number of imminent risks in areas such as consumer protection, data privacy, cybersecurity, and anti-money laundering, among others.

The State Bank of Vietnam (SBV) is stepping up to tackle these challenges by accelerating the promulgation of a long-awaited Fintech Sandbox Decree with the issuance of an updated draft (“Draft Fintech Sandbox Decree”) on March 4, 2024. The Draft Fintech Sandbox Decree establishes a controlled environment where fintech companies and financial institutions can test solutions that do not fall squarely within the parameters of existing regulations. The pilot activities will be limited in scope, scale, and duration, with a number of precautionary measures in place. The SBV will supervise this “sandbox” closely, effectively mitigating risks and gathering valuable data to inform future regulations.

Who Can Participate in the Sandbox?

  • Traditional financial institutions (credit institutions): Banks and other institutions licensed to provide financial services can participate in the sandbox to test new offerings or refine existing ones.
  • Independent fintech companies: Startups and established companies specializing in fintech solutions can leverage the sandbox to pilot innovative ideas before seeking wider market adoption.
  • Other relevant organizations involved in the pilot: Depending on the specific solution being tested, other entities may also be involved in the sandbox.
  • Geographical scope: Limited to Vietnamese territory; cross-border testing is not allowed.

Focusing on Three Solution Categories

Earlier versions of the Draft Fintech Sandbox Decree included categories like blockchain technology and other innovative business models, but these were removed in the latest version. To allow the SBV to assess the associated risks and work on the solutions more effectively, this version focuses only on the following three solutions:

  • Credit scoring: Fintech companies can pilot new credit scoring models to assess the creditworthiness of individuals or organizations.
  • Data sharing via Open Application Programming Interface (“Open API”): Secured data-sharing mechanisms using Open APIs can be tested within the sandbox.
  • Peer-to-peer lending (“P2P Lending”): Platforms that connect lenders and borrowers can be piloted in the sandbox.

Participation Conditions

Fintech companies must meet specific criteria depending on the solution they are piloting. The criteria will vary depending on the complexity and potential risks associated with the solution. For example, P2P lending platforms might face strict requirements on cybersecurity and network information security.

All participants must submit a registration dossier and obtain a Certificate of Participation from the SBV.

Monitoring and Risk Control

The SBV will closely monitor activities, evaluate participation, and assess the effectiveness of the piloted solutions, with a dedicated team to oversee activities within the sandbox, ensuring that participants comply with applicable regulations and that pilots are conducted safely and effectively.

Participating organizations are required to submit regular reports and provide ad hoc information on the pilot process, operational indicators, risks encountered, and the results of the pilot implementation to the SBV.

Customer Protection

Participating organizations have a responsibility to ensure customer rights and interests. This includes informing them about potential risks associated with using the piloted solution, obtaining their informed consent, and clearly outlining data privacy practices.

Participating organizations must implement robust security measures to safeguard customer data collected during the pilot program.

For dispute settlement, organizations are required to establish a customer complaint handling department and have clear mechanisms in place to address any disputes or complaints arising from the use of their piloted solutions.

Sandbox Conclusion

The pilot period will last a maximum of two years, with the SBV having the authority to adjust the length based on the actual implementation. After the pilot period, the SBV will decide on the next steps based on participating organizations’ reports, its own monitoring data, and any feedback received from relevant state authorities. Options will include terminating the pilot, certifying its completion, or extending the pilot period.

Participation in the Sandbox Mechanism does not guarantee an operating license or market approval for the piloted solutions.

Outlook

Once it is officially passed, it is hoped that the Fintech Sandbox Decree will usher in a new era of controlled experimentation in the sector, fostering a dynamic fintech ecosystem where innovation can thrive alongside robust regulations. By balancing innovation with consumer protection, cybersecurity, and data protection, it has the potential to transform Vietnam into a hub for groundbreaking fintech solutions, all while safeguarding the integrity of the financial system and consumers’ interests.

Now that the sandbox program has been streamlined to include only the three most prominent fintech solutions, the SBV might be able to speed up the official issuance of the Fintech Sandbox Decree.

RELATED INSIGHTS​ 

June 19, 2025
The Bank of Thailand (BOT) has released draft guidelines establishing principles for managing artificial intelligence (AI) risks in the financial sector. The draft guidelines provide a structured framework for the responsible adoption of AI technologies. Financial service providers will be able to use the guidelines as a reference to appropriately manage their risks in a manner that aligns with internationally recognized best practices. The BOT is accepting public comments on the draft guidelines until June 30, 2025. Scope and Application The draft guidelines apply to all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. These guidelines supplement existing BOT risk management guidelines covering IT risk management, third-party risk management, data governance, and market conduct. The guidelines define AI systems as systems that mimic human intelligence, including machine learning, deep learning, generative AI (such as large language models), and agentic AI. This definition specifically excludes rule-based automation systems like robotic process automation and condition matching. Key Risk Management Principles The guidelines lay out two main principles in managing AI risk. Governance: Financial service providers should define and establish clear roles and responsibilities for their personnel and AI system supervision structures to uphold FEAT (fairness, ethics, accountability, and transparency) principles as follows: Stakeholder roles and responsibilities. Financial service providers should define roles and responsibilities for boards and executives on AI risk oversight. Responsibilities include establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. AI system usage policy. The AI system usage policy should be aligned with organizational objectives, regulatory requirements, and FEAT principles. These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management
June 19, 2025
Thailand’s Electronic Transactions Development Agency (ETDA) has announced plans for increased enforcement of the Royal Decree on the Operation of Digital Platform Service Businesses That Are Subject to Prior Notification B.E. 2565 (2022). The ETDA outlined a comprehensive enforcement framework and review process during an online meeting with digital platform service operators on June 11, 2025. The ETDA’s enhanced enforcement approach includes systematic reviews of notification submissions, formal correction orders, and potential criminal penalties for noncompliance. Digital platform operators should immediately assess their current notification status and prepare for increased regulatory scrutiny. Review and Amendment of Previously Submitted Notification Data The ETDA will begin reviewing operation notification forms and annual reports submitted by digital platform service operators to assess each platform’s risk level and develop tailored regulatory obligations. In this comprehensive review process, the ETDA will: Examine the accuracy and completeness of submitted notification data; Request additional information as needed by phone or email; and Issue formal orders as needed requiring operators to correct or complete missing information. Operators who fail to comply with ETDA orders may face suspension of operations, revocation of their notification receipt, and public disclosure of their noncompliant status on the ETDA’s website. The ETDA will conduct follow-up workshops in July 2025 for operators whose data remains unclear or incomplete. Enforcement Framework and Penalties The ETDA outlined a three-tiered enforcement framework with escalating consequences for different types of violations, as follows: Failure to notify before commencing operations: Operators who begin services without proper notification may face criminal penalties under the Electronic Transactions Act, including up to one year of imprisonment, fines of up to THB 100,000 (approx. USD 3,070), or both. Additional consequences include suspension of operations and potential liability for company directors. Failure to correct or comply with official orders: Noncompliance with ETDA correction
June 13, 2025
In today’s digital age, cyberattacks have become a real threat to organizations worldwide. These attacks can range from phishing and malware to ransomware and distributed denial of service (DDoS) attacks. As the frequency and sophistication of these attacks increase, so does the importance of cybersecurity compliance. In the corporate world, compliance refers to the process of ensuring that a company and its employees adhere to all relevant laws, regulations, standards, and ethical practices—but it should not stop there. Compliance should also encompass asset recovery and disciplinary measures, which can both help organizations address incidents effectively and promote good governance. Cyberattacks are malicious attempts to access or damage a computer system or network, often carried out for financial gain, for political activism, or simply to cause disruption. For instance, a successful attack might involve an attacker creating an email address that closely resembles a legitimate one, perhaps by changing only one or two characters. That email address is then inserted into an existing conversation thread, making it appear as if the user with this email address was already part of the discussion. This tactic can easily deceive a recipient into believing the email was sent from a trusted source, thereby leading them to click on malicious links, provide sensitive information, or even make payments in accordance with the attacker’s request or instructions. Phishing attacks like these are particularly dangerous and can have a serious impact on the ongoing business of a corporation because they exploit the trust and familiarity established in the original email chain. Effective Mitigation Approaches Mechanisms for addressing the aftermath of a crisis provide important recourse to affected organizations, but effective compliance mechanisms can minimize the risk of such crises ever occurring. Companies should therefore prioritize preventative measures and implementation of effective crisis management schemes. Various legal
May 28, 2025
Tilleke & Gibbins attorneys in Vietnam have contributed the 2025 edition of Doing Business in Vietnam, a comprehensive Q&A-style resource from Thomson Reuters Practical Law that provides essential insights for companies navigating business operations in Vietnam. The guide presents a detailed overview of the country’s legal framework and regulatory environment, reflecting recent updates in Vietnamese legislation and practice. This annually updated guide offers key information on the following areas: Legal system: Structure of the Vietnamese judiciary and the role of codified law. Foreign investment: Conditions for market access, licensing requirements, foreign ownership restrictions, and investment incentives. Business vehicles: Formation and operation of legal entities, including limited liability companies, joint-stock companies, and representative offices. Employment: Employment contracts, social insurance, labor rights, and procedures for hiring foreign nationals. Tax: Overview of corporate income tax, personal income tax, value-added tax, and other tax obligations. Intellectual property: Procedures for protecting and enforcing patents, trademarks, copyrights, and other IP rights. Data protection: Compliance requirements under Vietnam’s data privacy laws, including the Personal Data Protection Decree. Competition law: Antitrust rules and regulatory oversight under the Law on Competition. Anti-bribery and corruption: Legal framework and enforcement practices aimed at curbing corrupt activities. E-commerce and digital business: Regulations governing online platforms, digital content, and cross-border services. Marketing and advertising: Laws and guidelines on advertising standards and consumer protection. Product regulation and liability: Safety requirements, product liability issues, and roles of relevant authorities. Doing Business in Vietnam is part of Practical Law’s global series of legal guides designed to support international practitioners and businesses. To access the most recent edition of the Vietnam guide, visit the Practical Law website and sign up for a free trial.