You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

March 21, 2025

Vietnam’s Amended Securities Law: What You Need to Know

Vietnam’s Law on Securities of 2019 was one of several laws amended (“Amended Securities Law”) under the wide-ranging Law No. 56/2024/QH15 passed by the National Assembly on November 29, 2024. The amendments came into force on January 1, 2025, with certain provisions related to professional securities investors and the eligibility criteria for public companies becoming effective on January 1, 2026.

Below are some of the key points of the Amended Securities Law.

Changes to Professional Securities Investors

Professional securities investors (PSIs) are investors who have adequate financial capacity or securities qualifications and can participate in private placements and private funds, among other investment activities. Under the Amended Securities Law, foreign investors, including individuals and organizations, are now automatically classified as PSIs, without having to meet any requirements regarding financial capacity. This loosening of requirements is expected to attract more foreign investment.

However, from January 1, 2026, individual PSIs will only be able to purchase, trade, and transfer privately placed corporate bonds that: (i) have been given credit ratings and are secured by collateral, or (ii) have been given credit ratings and covered by payment guarantees from credit institutions. Meanwhile, institutional PSIs will not be bound by these restrictions relating to privately placed corporate bonds.

Protecting Shareholders in Private Securities Issuance

The Amended Securities Law introduces additional conditions for private issuance of shares, convertible bonds, and warrant-linked bonds by public companies, and revises the required contents in the issuance plans from “criteria and number of investors” to “number of shares, offering price, or principles for determining the offering price.” This change promotes shareholder supervision and protects minority shareholders from overly powerful boards of directors.

Expanded Powers of SSC

The Amended Securities Law grants the State Securities Commission (SSC) new powers to suspend and cancel private placements of securities and adds new circumstances for the SSC to cancel public offerings.

The SSC may suspend a registered private placement of securities for up to 60 days: (i) if the offering documents contain misleading information or omit material information that could impact investment decisions and cause damage to investors, or (ii) if the distribution of the securities does not comply with statutory requirements. The issuer must announce the suspension within 7 business days from the suspension and recall the issued securities upon the investor’s request as well as provide a refund to the investor within 15 days from the investor’s request. If deficiencies leading to the suspension are corrected, the SSC will issue a written notice of withdrawal of the suspension. As a result, such private placement will be allowed to proceed.

The SSC may cancel a registered private placement of securities if (i) the issuer fails to address deficiencies leading to the suspension within the suspension period; (ii) the offering documents or the distribution of the private placement of shares are found to have violated the law while the issued shares are not yet listed or registered for trading on the stock exchange; or (iii) the offering documents or the distribution of the securities upon completion of private placement are found to have breached the law. Cancellation of the private placement does not apply to offered shares, shares converted from convertible bonds, or shares purchased from warrants that have been listed or registered for trading on the stock exchange after the private placement.

Under the Amended Securities Law, the SSC may now cancel a public offering if the offering documents or the distribution of the public offering are found to have violated the law after the public offering, but before completion of procedures to be listed or registered for trading on the stock exchange.

Liability Framework for Public Companies, Shareholders, and Advisors

Previously, issuers, underwriters, auditors, and “certifying organizations” were liable for the legality, accuracy, and sufficiency of securities-related documents and reporting during public offerings or when registering securities for listing or trading. The Amended Securities Law extends this liability to private offerings of securities, public disclosures by public companies or their shareholders, and reporting of secondary trading of securities by investors. Further, advisors involved in these activities may be exposed to greater liability for their failure to adhere to professional standards.

This change pushes public companies, their shareholders, and advisors to be more accountable and enhance the transparency in the securities market. They must ensure that all documents and information related to public disclosures and securities trading do not have misleading information and comprehensively include all material facts that could influence decisions by investors, authorities, and other stakeholders.

Defining “Securities Market Manipulation”

The Amended Securities Law updates the acts of “securities market manipulation” as outlined in the 2015 Penal Code to align the definitions of securities market manipulation under securities law and criminal law, closing any gaps between the two. This change aims to imposes administrative liability for market manipulation that does not reach threshold for criminal liability.

Other Changes

The Amended Securities Law adds additional grounds for the cancellation of public company status, which include a public company (i) failing to publish its audited financial statements or annual shareholder meeting resolutions, for two consecutive years; (ii) failing to register its shares with the Vietnam Securities Depository and Clearing Corporation; or (iii) failing to register its shares for listing.

Privately issued corporate bonds offered before January 1, 2026, will adhere to the 2019 Securities and the 2020 Law on Enterprises until the principal and interest are fully paid. Privately issued corporate bonds disclosed to the stock exchange before January 1, 2026, but not yet distributed will follow the same laws until distribution is complete, after which they will comply with the Amended Securities Law.

A public company repurchasing shares from employees in accordance with an employee stock ownership program does not need to reduce charter capital, but only needs to report the total number of repurchased employee shares at the nearest annual general meeting of shareholders. Accordingly, the Amended Securities Law is implicitly reviving treasury shares as previously outlined in the expired 2006 Securities Law, allowing public companies to hold treasury shares after the effective date of the 2019 Securities Law for this limited case of repurchased employee shares. This amendment is paired with an exception to the 6-month blackout period for issuing new shares after a share repurchase for repurchase of shares from leaving employees according to the employee stock ownership program.

Outlook

The Amended Securities Law aims to significantly strengthen governance, increase robustness, and provide better protection for investors in Vietnam’s securities market. This initiative should help address evolving challenges, upgrade the local market, and ensure alignment with international practice.

RELATED INSIGHTS​ 

October 30, 2025
Recent events at a Thai listed company, where a proposal to remove the director was not successful, amid claims that a competitor was attempting to gain control of the company, illustrate how disputes over corporate control can unfold differently at the board level and shareholder level. At the board level, removing directors of a listed company mid-term to gain corporate control is not an easy task under Thai law, as it requires a higher threshold than appointing a new director, which typically only requires a simple majority vote in a listed company. At the shareholder level, Thailand’s tender offer and competition regimes add complexity where different shareholder groups act in concert to remove opposing board representatives or otherwise influence control. In this article, we will explore why the attempted removal of a director may fail, and how the tender offer regime may apply. Key Issues at a Glance Shareholder groups may seek to convene meetings to propose changes to board composition or company authority. Such proposals can be delayed or complicated by regulatory requirements and the need for additional disclosures. Regulatory authorities and minority shareholders may raise concerns when major shareholders coordinate to influence board control, especially if such actions could trigger tender offer or merger control obligations. Companies often respond by seeking further information on shareholder relationships and potential conflicts before proceeding. Why the Director Removal Failed Under Section 76 of the Public Limited Companies Act B.E. 2535 (as amended), the early removal of a director requires two conditions to be satisfied at the same meeting of shareholders: Headcount test: At least 75% of shareholders attending and entitled to vote must vote in favor. If multiple shareholders appoint the same person as proxy, each proxy is counted as a separate head for the purpose of the headcount test,
October 1, 2025
In September 2025, Thailand’s Securities and Exchange Commission (SEC) accused a company listed on the Stock Exchange of Thailand (SET), including its current and former directors, of concealing material information in connection with its filing registration and draft prospectus. This recent enforcement action demonstrates the serious consequences of making false statements or appearing to conceal material information in IPO filings and ongoing disclosures. In addition to being subject to criminal penalties, such actions can impact the eligibility of directors and executives to serve and may cause lasting reputational damage. Key Legal Risks The Securities and Exchange Act B.E. 2535 (1992) (as amended) imposes strict liability for making false statements or concealing material information in IPO registration statements and draft prospectuses. In such cases, investors can claim for damages, and there are also criminal penalties, including imprisonment for up to five years and substantial fines, may apply to the company, its directors, and responsible officers. However, misstatements or omissions in IPO filings do not, by themselves, disqualify directors or executives from holding office, whether arising from an SEC accusation or even a final court judgment. In contrast, for ongoing disclosures after listing, such as financial statements, annual reports, and meeting notices, false or misleading statements or concealment of material information can result in not only criminal liability but also immediate disqualification of directors and executives. If the SEC accuses a listed company or its directors or executives of such misstatements or omissions, those directors or executives are immediately disqualified from their positions, even before a final court judgment. Director and Executive Qualifications Directors and executives must meet the SEC’s specified standards of trustworthiness, as set out in the relevant rules. The SEC clearly defines characteristics that are considered to demonstrate a lack of trustworthiness. For ongoing disclosures, being involved in
September 24, 2025
On September 12, 2025, the Bank of Thailand (BOT) officially released its AI Risk Management Guidelines for Financial Service Providers, building upon the draft guidelines issued in June 2025. The guidelines reflect a balanced approach, encouraging innovation while safeguarding financial stability and consumer protection. The guidelines are targeted at all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. The guidelines apply to both AI systems developed in-house and those developed by third parties that are adopted for use by financial service providers. AI Risk Management Guidelines The two main pillars in managing AI risk are (1) governance of AI system implementation and (2) AI system development and security controls, consisting of the following key elements: 1. Governance Stakeholder roles and responsibilities. Boards and senior management assume accountability for decisions and operations involving AI systems, and are responsible for defining roles and responsibilities for AI oversight. This includes establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. Organizations are expected to foster internal capabilities to use AI securely and avoid overreliance that could compromise business continuity or customer service. AI system usage policy. Policies governing AI usage should align with organizational goals, regulatory obligations, and recognized responsible AI frameworks—such as the FEAT principles (fairness, ethics, accountability, and transparency). These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management throughout the AI lifecycle. Risk management should encompass the entire AI lifecycle, from establishing risk appetite to implementing continuous risk assessment and control measures tailored to specific use cases. Financial service providers should assess risks and impacts of AI usage on operations and customer services.
September 12, 2025
On September 10, 2025, Vietnam’s National Credit Information Center (CIC) reported to the Vietnam Cybersecurity Emergency Response Team (VNCERT) a suspected significant cybersecurity incident involving unauthorized access to the CIC’s credit information database. A hacker group has claimed responsibility and allegedly posted over 160 million records for sale, including sensitive personal and financial data. Implications for Banks and Financial Institutions Companies that share customers’ or potential customers’ personal data with the CIC for credit scoring or other purposes—and continue to act as a data controller for such data—may be obligated under Vietnam’s Personal Data Protection Decree (PDPD) and related regulations to: Notify A05 (Department of Cybersecurity and High-Tech Crime Prevention) and the State Bank of Vietnam without delay. Inform affected individuals if their personal data is at risk. Recommended Actions Companies that could be impacted by this data breach should take the following actions: Conduct an internal review of CIC-related data in their systems, and identify whether and how the systems have been affected by this incident. Assess whether to notify regulators and customers/potential customers. Enhance cybersecurity controls, monitor for suspicious activity, and implement additional safeguards to prevent secondary breaches.