You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 22, 2025

Vietnam’s Draft Resolution on Financial Centers: Implications for Fintech and Banking

Tasked with implementing the Politburo’s policy outlined in Notice No. 47-TB/TW dated November 15, 2024, the prime minister of Vietnam issued Decision No. 1718/QD-TTg on December 31, 2024, appointing himself as the head of a steering committee dedicated to the establishment of an international financial center in Ho Chi Minh City and a regional financial center in Da Nang by 2025. The Ministry of Planning and Investment has subsequently drafted an outline for the National Assembly’s Resolution on the Establishment of Regional and International Financial Centers in Vietnam (“Draft Resolution”).

This Draft Resolution introduces two key policy groups: (i) policies governing the quantity, location, structure, organization, functions, and responsibilities of the financial centers; and (ii) policies applicable to various areas and matters within the financial centers.

Notably, under the Draft Resolution, fintech has been identified as a key sector, with a specific focus on the implementation of a “controlled sandbox” policy for business models involving virtual assets and cryptocurrencies. Under this framework, transactions related to virtual assets and cryptocurrencies will be permitted from July 1, 2026, subject to licensing, management, impact assessment, and risk oversight by the financial centers’ Management and Operations Committee.

Scope of Application and Key Principles

The Draft Resolution applies to a wide range of stakeholders, including investors, regulatory agencies, organizations, and individuals involved in the establishment, organization, and operation of regional and international financial centers in Vietnam. These financial centers will have clearly defined geographical boundaries and specific locations, which will be further specified and detailed by the People’s Committees of Ho Chi Minh City and Da Nang.

Companies successfully registered as members of these financial centers will benefit from special investor-friendly policy principles, which may differ from the general legal and regulatory framework applicable in other parts of Vietnam.

Most notably, the state will implement mechanisms and policies to encourage capital inflows, facilitate the adoption of advanced technology and modern management practices, and promote infrastructure development within the financial centers. The management agencies of the financial centers will apply specialized administrative procedures to meet investors’ needs in accordance with international standards and best practices. Additionally, where provisions of the Draft Resolution differ from existing laws, resolutions, or ordinances, the provisions of the Draft Resolution will prevail.

Policy Framework for Establishment and Governance of Financial Centers

The Draft Resolution outlines the framework for the establishment and governance of financial centers in Vietnam, which will include a comprehensive international financial center in Ho Chi Minh City and a regional-scale financial center in Da Nang. To ensure effective management and operations, the financial centers will be overseen by dedicated agencies, including a (i) management and operations committee, (ii) financial supervision committee, and (iii) international arbitration center.

The management and operations committee will be responsible for the overall administration and strategic oversight of the financial center. Its organizational structure will consist of a board of directors and several key departments, including strategic management, financial management, operations supervision, and management coordination.

The financial supervision committee will focus on ensuring compliance with international financial standards and regulations, fostering a transparent and integrity-driven environment. This committee will also comprise a board of directors supported by specialized departments, such as audit, legal, welfare, risk management, and governance and human resources.

Additionally, each financial center will host an international arbitration center, which will facilitate the resolution of disputes arising from investment and business activities within the financial ecosystem.

Specific Policies for Financial Centers

The Draft Resolution also sets forth specific policies that will govern key areas within the financial centers. These policies cover the membership registration system; currency, banking, and foreign exchange management; fintech; capital markets; personal and corporate income tax; immigration and residency; human resource training and development; labor, employment, and social security; strategic investments; land use and infrastructure development; and trade and business regulations. Furthermore, policies related to dispute resolution mechanisms for investment and business activities are also included.

A significant feature of the Draft Resolution is the introduction of a controlled sandbox policy for fintech enterprises, particularly those engaged in virtual assets and cryptocurrency-related business models. Under this framework, transactions involving virtual assets and cryptocurrencies will be clearly permitted within the financial centers starting from July 1, 2026. These transactions will be subject to licensing, regulatory oversight, impact assessment, and risk management measures administered by the Management and Operations Committee. Additionally, issues concerning anti-money laundering measures related to crypto assets and cryptocurrencies; the issuance, ownership, and trading of non-fungible tokens (NFTs) and utility tokens; and regulatory measures for crypto-asset mining activities (to limit risks to energy security and the environment) will be further regulated by the government.

In the domain of currency, banking, and foreign exchange management, the Draft Resolution proposes policies that reflect international best practices and address the practical needs of the financial centers. These policies include (i) anti-money laundering regulations, including those related to crypto assets; (ii) allowing financial transactions within the centers in both VND and freely convertible foreign currencies; and (iii) procedures and processes for priority areas in the financial centers for some traditional products in commercial banking activities.

The Draft Resolution also provides a streamlined regulatory framework for establishing and managing the operations of foreign credit institutions within the financial centers. Notably, banks and credit institutions headquartered in the centers will not be subject to foreign ownership restrictions or investment conditions when providing financial services within the centers or across borders. In addition, to align with international financial standards, the implementation of Basel III regulations is scheduled to commence on January 1, 2026. Furthermore, a digital banking model will be introduced, enabling commercial banks to offer advanced digital services within the financial centers from the same date.

Outlook

By establishing a structured regulatory framework, the forthcoming resolution aims to attract investment, drive financial innovation, and position Vietnam as a competitive player in the global financial landscape. A key highlight of the resolution is its focus on the fintech sector, particularly through initiatives such as the controlled sandbox for virtual assets and cryptocurrencies. This demonstrates Vietnam’s commitment to advancing digital transformation in financial services, fostering opportunities for fintech enterprises, and driving innovation across the industry.

RELATED INSIGHTS​ 

June 25, 2025
Generative artificial intelligence (GenAI) is no longer a distant innovation confined to science fiction and research labs; it has become an integral part of daily business operations worldwide. Employees across industries are adopting GenAI tools at a remarkable pace—including in Southeast Asia, where a tech-savvy workforce and widespread internet and mobile access have driven early adoption. The reality facing organizations today is clear: employees are integrating GenAI into their daily work, often without official approval or clear policies. This phenomenon, often called “Bring Your Own AI,” comes out of a disconnect between organizational governance and employee behavior and reveals the urgent need for proactive AI policies and oversight. For business leaders and legal teams, GenAI is both an opportunity and a challenge. On one hand, these tools can deliver real business value and boost efficiency. On the other, the unsanctioned and unmonitored use of GenAI introduces substantial legal risks, such as data privacy violations, confidentiality breaches, and intellectual property issues. The widespread adoption of GenAI tools by employees, regardless of official organizational stance or guidelines, demonstrates that prohibition is neither practical nor effective. A more strategic approach involves establishing comprehensive governance policies that encourage responsible AI use while managing the risks. Organizations that take the lead in developing GenAI governance policies are better positioned to benefit from its transformative potential. The question isn’t whether GenAI will change how we work, but how quickly organizations can put the right safeguards in place to manage this change successfully. Risks of GenAI Use The use of GenAI in business operations, whether sanctioned or not, exposes organizations to a unique set of risks. The following are particularly relevant: Data security and confidentiality: General GenAI tools in the market may transmit data to external servers, retain conversation histories, and use inputs for model training.
June 19, 2025
The Bank of Thailand (BOT) has released draft guidelines establishing principles for managing artificial intelligence (AI) risks in the financial sector. The draft guidelines provide a structured framework for the responsible adoption of AI technologies. Financial service providers will be able to use the guidelines as a reference to appropriately manage their risks in a manner that aligns with internationally recognized best practices. The BOT is accepting public comments on the draft guidelines until June 30, 2025. Scope and Application The draft guidelines apply to all financial service providers, including financial institutions and special financial institutions under the Financial Institution Business Act, as well as payment providers under the Payment Systems Act. These guidelines supplement existing BOT risk management guidelines covering IT risk management, third-party risk management, data governance, and market conduct. The guidelines define AI systems as systems that mimic human intelligence, including machine learning, deep learning, generative AI (such as large language models), and agentic AI. This definition specifically excludes rule-based automation systems like robotic process automation and condition matching. Key Risk Management Principles The guidelines lay out two main principles in managing AI risk. Governance: Financial service providers should define and establish clear roles and responsibilities for their personnel and AI system supervision structures to uphold FEAT (fairness, ethics, accountability, and transparency) principles as follows: Stakeholder roles and responsibilities. Financial service providers should define roles and responsibilities for boards and executives on AI risk oversight. Responsibilities include establishing an AI system usage policy, designating personnel responsible for AI risk management, and building awareness of AI-related risk within the organization. AI system usage policy. The AI system usage policy should be aligned with organizational objectives, regulatory requirements, and FEAT principles. These policies should be reviewed regularly to respond to technological advancements and evolving risk profiles. Risk management
June 19, 2025
Thailand’s Electronic Transactions Development Agency (ETDA) has announced plans for increased enforcement of the Royal Decree on the Operation of Digital Platform Service Businesses That Are Subject to Prior Notification B.E. 2565 (2022). The ETDA outlined a comprehensive enforcement framework and review process during an online meeting with digital platform service operators on June 11, 2025. The ETDA’s enhanced enforcement approach includes systematic reviews of notification submissions, formal correction orders, and potential criminal penalties for noncompliance. Digital platform operators should immediately assess their current notification status and prepare for increased regulatory scrutiny. Review and Amendment of Previously Submitted Notification Data The ETDA will begin reviewing operation notification forms and annual reports submitted by digital platform service operators to assess each platform’s risk level and develop tailored regulatory obligations. In this comprehensive review process, the ETDA will: Examine the accuracy and completeness of submitted notification data; Request additional information as needed by phone or email; and Issue formal orders as needed requiring operators to correct or complete missing information. Operators who fail to comply with ETDA orders may face suspension of operations, revocation of their notification receipt, and public disclosure of their noncompliant status on the ETDA’s website. The ETDA will conduct follow-up workshops in July 2025 for operators whose data remains unclear or incomplete. Enforcement Framework and Penalties The ETDA outlined a three-tiered enforcement framework with escalating consequences for different types of violations, as follows: Failure to notify before commencing operations: Operators who begin services without proper notification may face criminal penalties under the Electronic Transactions Act, including up to one year of imprisonment, fines of up to THB 100,000 (approx. USD 3,070), or both. Additional consequences include suspension of operations and potential liability for company directors. Failure to correct or comply with official orders: Noncompliance with ETDA correction
June 13, 2025
In today’s digital age, cyberattacks have become a real threat to organizations worldwide. These attacks can range from phishing and malware to ransomware and distributed denial of service (DDoS) attacks. As the frequency and sophistication of these attacks increase, so does the importance of cybersecurity compliance. In the corporate world, compliance refers to the process of ensuring that a company and its employees adhere to all relevant laws, regulations, standards, and ethical practices—but it should not stop there. Compliance should also encompass asset recovery and disciplinary measures, which can both help organizations address incidents effectively and promote good governance. Cyberattacks are malicious attempts to access or damage a computer system or network, often carried out for financial gain, for political activism, or simply to cause disruption. For instance, a successful attack might involve an attacker creating an email address that closely resembles a legitimate one, perhaps by changing only one or two characters. That email address is then inserted into an existing conversation thread, making it appear as if the user with this email address was already part of the discussion. This tactic can easily deceive a recipient into believing the email was sent from a trusted source, thereby leading them to click on malicious links, provide sensitive information, or even make payments in accordance with the attacker’s request or instructions. Phishing attacks like these are particularly dangerous and can have a serious impact on the ongoing business of a corporation because they exploit the trust and familiarity established in the original email chain. Effective Mitigation Approaches Mechanisms for addressing the aftermath of a crisis provide important recourse to affected organizations, but effective compliance mechanisms can minimize the risk of such crises ever occurring. Companies should therefore prioritize preventative measures and implementation of effective crisis management schemes. Various legal