You are using an outdated browser and your browsing experience will not be optimal. Please update to the latest version of Microsoft Edge, Google Chrome or Mozilla Firefox. Install Microsoft Edge

January 22, 2025

Vietnam’s Draft Resolution on Financial Centers: Implications for Fintech and Banking

Tasked with implementing the Politburo’s policy outlined in Notice No. 47-TB/TW dated November 15, 2024, the prime minister of Vietnam issued Decision No. 1718/QD-TTg on December 31, 2024, appointing himself as the head of a steering committee dedicated to the establishment of an international financial center in Ho Chi Minh City and a regional financial center in Da Nang by 2025. The Ministry of Planning and Investment has subsequently drafted an outline for the National Assembly’s Resolution on the Establishment of Regional and International Financial Centers in Vietnam (“Draft Resolution”).

This Draft Resolution introduces two key policy groups: (i) policies governing the quantity, location, structure, organization, functions, and responsibilities of the financial centers; and (ii) policies applicable to various areas and matters within the financial centers.

Notably, under the Draft Resolution, fintech has been identified as a key sector, with a specific focus on the implementation of a “controlled sandbox” policy for business models involving virtual assets and cryptocurrencies. Under this framework, transactions related to virtual assets and cryptocurrencies will be permitted from July 1, 2026, subject to licensing, management, impact assessment, and risk oversight by the financial centers’ Management and Operations Committee.

Scope of Application and Key Principles

The Draft Resolution applies to a wide range of stakeholders, including investors, regulatory agencies, organizations, and individuals involved in the establishment, organization, and operation of regional and international financial centers in Vietnam. These financial centers will have clearly defined geographical boundaries and specific locations, which will be further specified and detailed by the People’s Committees of Ho Chi Minh City and Da Nang.

Companies successfully registered as members of these financial centers will benefit from special investor-friendly policy principles, which may differ from the general legal and regulatory framework applicable in other parts of Vietnam.

Most notably, the state will implement mechanisms and policies to encourage capital inflows, facilitate the adoption of advanced technology and modern management practices, and promote infrastructure development within the financial centers. The management agencies of the financial centers will apply specialized administrative procedures to meet investors’ needs in accordance with international standards and best practices. Additionally, where provisions of the Draft Resolution differ from existing laws, resolutions, or ordinances, the provisions of the Draft Resolution will prevail.

Policy Framework for Establishment and Governance of Financial Centers

The Draft Resolution outlines the framework for the establishment and governance of financial centers in Vietnam, which will include a comprehensive international financial center in Ho Chi Minh City and a regional-scale financial center in Da Nang. To ensure effective management and operations, the financial centers will be overseen by dedicated agencies, including a (i) management and operations committee, (ii) financial supervision committee, and (iii) international arbitration center.

The management and operations committee will be responsible for the overall administration and strategic oversight of the financial center. Its organizational structure will consist of a board of directors and several key departments, including strategic management, financial management, operations supervision, and management coordination.

The financial supervision committee will focus on ensuring compliance with international financial standards and regulations, fostering a transparent and integrity-driven environment. This committee will also comprise a board of directors supported by specialized departments, such as audit, legal, welfare, risk management, and governance and human resources.

Additionally, each financial center will host an international arbitration center, which will facilitate the resolution of disputes arising from investment and business activities within the financial ecosystem.

Specific Policies for Financial Centers

The Draft Resolution also sets forth specific policies that will govern key areas within the financial centers. These policies cover the membership registration system; currency, banking, and foreign exchange management; fintech; capital markets; personal and corporate income tax; immigration and residency; human resource training and development; labor, employment, and social security; strategic investments; land use and infrastructure development; and trade and business regulations. Furthermore, policies related to dispute resolution mechanisms for investment and business activities are also included.

A significant feature of the Draft Resolution is the introduction of a controlled sandbox policy for fintech enterprises, particularly those engaged in virtual assets and cryptocurrency-related business models. Under this framework, transactions involving virtual assets and cryptocurrencies will be clearly permitted within the financial centers starting from July 1, 2026. These transactions will be subject to licensing, regulatory oversight, impact assessment, and risk management measures administered by the Management and Operations Committee. Additionally, issues concerning anti-money laundering measures related to crypto assets and cryptocurrencies; the issuance, ownership, and trading of non-fungible tokens (NFTs) and utility tokens; and regulatory measures for crypto-asset mining activities (to limit risks to energy security and the environment) will be further regulated by the government.

In the domain of currency, banking, and foreign exchange management, the Draft Resolution proposes policies that reflect international best practices and address the practical needs of the financial centers. These policies include (i) anti-money laundering regulations, including those related to crypto assets; (ii) allowing financial transactions within the centers in both VND and freely convertible foreign currencies; and (iii) procedures and processes for priority areas in the financial centers for some traditional products in commercial banking activities.

The Draft Resolution also provides a streamlined regulatory framework for establishing and managing the operations of foreign credit institutions within the financial centers. Notably, banks and credit institutions headquartered in the centers will not be subject to foreign ownership restrictions or investment conditions when providing financial services within the centers or across borders. In addition, to align with international financial standards, the implementation of Basel III regulations is scheduled to commence on January 1, 2026. Furthermore, a digital banking model will be introduced, enabling commercial banks to offer advanced digital services within the financial centers from the same date.

Outlook

By establishing a structured regulatory framework, the forthcoming resolution aims to attract investment, drive financial innovation, and position Vietnam as a competitive player in the global financial landscape. A key highlight of the resolution is its focus on the fintech sector, particularly through initiatives such as the controlled sandbox for virtual assets and cryptocurrencies. This demonstrates Vietnam’s commitment to advancing digital transformation in financial services, fostering opportunities for fintech enterprises, and driving innovation across the industry.

RELATED INSIGHTS​ 

April 4, 2024
On March 18, 2024, the president of the Supreme Court of Thailand announced the establishment of a specialized Technology Crime Division within the Criminal Court of Thailand. This represents a significant commitment to cybercrime within the Thai judiciary and a step forward in Thailand’s ability to investigate cybercrime. The rise in cybercrime investigations in recent years has made it increasingly difficult for Thailand’s traditional criminal courts to consider and issue enforcement orders in support of ongoing investigations in a timely manner. The new Technology Crime Division addresses this challenge. This new division has jurisdiction over cybercrime and technology-related crime, fraud or extortion using computers, and criminal offenses relating to personal data protection laws. In addition, this new division has jurisdiction over all requests from competent law enforcement officers seeking court orders under the Computer Crimes Act B.E. 2550, the Personal Data Protection Act B.E. 2562, and the Cybersecurity Act B.E. 2562. The Technology Crime Division will have trainees and judges with expertise in technology and cybercrime—not only to facilitate expert prosecution of cybercrime but also to offer critical and time-sensitive support to law enforcement investigations of alleged cybercrime. The Technology Crime Division is not yet operational. The president of the Supreme Court is expected to announce the division’s opening date in the coming months. For more details on Thailand’s measures for dealing with cybercrime, please contact Michael Ramirez at [email protected] or Piyawat Vitooraporn at [email protected].
March 29, 2024
Thailand’s Cybersecurity Regulating Committee (CRC) released a notification under the Cybersecurity Act on February 22, 2024, setting key operational obligations for critical information infrastructure (CII) organizations. The notification takes effect on June 20, 2024. CII organizations are state or private entities that carry out services related to national security, public services, banking and finance, information technology and telecommunications, transportation and logistics, energy and public utilities, or public health. CII organizations will be identified by the National Cyber Security Committee (NCSC) and notified of their status. The key obligations of CII organizations are laid out below. Reporting to the National Cyber Security Agency (NCSA) CII organizations must provide the following to the NCSA: A list of executive and operational staff, along with emergency contacts who can be reached within 60 minutes in the event of a cyber threat. The NCSA must be notified of any updates to this list within 15 days following any changes. A list of internal departments or individuals who are the responsible persons, owners, and holders of the computer systems, along with emergency contacts who can be reached within 60 minutes in the event of a cyber threat. The NCSA must be notified of any updates to this list at least 7 days prior to any changes (or within 15 days after the change if there is a necessary reason). Policies, Guidelines, and Procedures As specified in the National Cyber Security Committee (NCSC) guidelines, CII organizations must prepare the following internal documents by June 20, 2025: Cybersecurity practice guidelines, consisting of an inspection plan, risk assessment, and incident response plan. Cybersecurity standards framework, consisting of measures for risk identification, risk prevention, threat detection and monitoring, incident responses, and resilience and recovery. CII organizations must also prepare the following: Mechanisms, procedures, and steps for monitoring and detecting
March 29, 2024
Vietnam’s Ministry of Public Security (MPS) is drafting two reports to present to the government in May 2024 to advocate for the development and adoption of a Law on Personal Data Protection. These reports include an assessment of the policy impact of the proposal to develop a personal data protection law, and an assessment of the current state of social relations related to personal data protection. Decree No. 13/2023/ND-CP on Personal Data Protection (PDPD), adopted in April 2023, became the first comprehensive legal instrument on data protection in Vietnam. When the National Assembly was debating its text and adoption in 2022 and 2023, questions were raised as to the status of this new regulation and the legality to adopt a decree before a law. In accordance with the public announcements made throughout the development of the PDPD assuring that a law would be developed at a later stage, the MPS is now advocating for the development of a Personal Data Protection Law and has drafted the two reports pursuant to the Law on the Promulgation of Legal Documents. The main arguments advanced by the MPS in the two reports are as follows: As the right to privacy is enshrined in the Constitution, any restrictions thereof must be made through a law and not a decree. The MPS is notably referring to the lawful basis for processing and limited exceptions to consent under the PDPD. This may be a sign that the MPS intends to widen the exceptions to consent under the new law. The definitions of “personal data” and “personal data protection” need to be harmonized to consolidate the regulatory framework. The MPS indicates that there are 69 legal documents directly related to “personal data protection” in Vietnam with more than 10 different definitions, while “personal information” appears in
March 28, 2024
Recently, Vietnam has witnessed a dramatic increase in cyber fraud, causing significant financial losses and posing a grave threat to both Vietnamese and foreign entities. With the increasing reliance on digital technology and the widespread adoption of online platforms, the country has become fertile ground for cybercriminals to exploit vulnerabilities and conduct various fraudulent activities. This article aims to present an overview of addressing cyber fraud in Vietnam and offers practical advice for businesses to safeguard themselves from becoming victims of such illicit activities.