What the Bank of Thailand Has Proposed
The draft builds directly on the BOT’s 2024 Mobile Banking Security Notification, which set minimum security standards for financial institutions, specialised financial institutions, and e-money providers. That earlier framework reduced “money-draining app” fraud sharply. However, criminals adapted and moved toward nonbank providers and internet banking. In response, the BOT now proposes a broader and tougher rulebook for digital banking security in Thailand. This trend mirrors the tighter cyber-governance standards already advancing across the financial sector, as seen in Thailand’s insurance cybersecurity reforms.
Importantly, this is still a draft. The public comment period runs through 24 August 2026, and the final text may change. As a result, businesses should treat the proposal as a strong signal of regulatory direction rather than a settled legal obligation. Even so, the direction of travel is clear, and early preparation will pay off.
Who Now Falls Within Scope
The most significant shift is the wider net. The current rules apply only to a limited set of providers. By contrast, the draft expands coverage across both the entities regulated and the channels protected.
On the entity side, the draft would add:
- Credit card providers that offer fund transfers to third parties at other financial service providers.
- Credit providers that offer cash withdrawal services to individual retail customers.
On the channel side, the draft would extend mandatory protection to internet banking, not just mobile applications. Consequently, many businesses that previously sat outside the mobile-banking rulebook would fall squarely within scope. Fintech lenders and card issuers, in particular, should review their status early.
The End of SMS OTPs and the Shift to Biometrics
For years, the SMS one-time password has been the backbone of transaction authentication in Thailand. The draft would retire it. Instead, providers would need stronger authentication factors that fraudsters cannot easily intercept or socially engineer.
Biometric verification sits at the centre of this shift. Under the proposal, providers must use facial comparison with effective antispoofing technology for higher-value transactions. Specifically, the draft would require this biometric check for:
- Transfers exceeding THB 50,000 per transaction; or
- Cumulative transfers exceeding THB 200,000 per day.
In addition, the draft targets the phishing links that fuel modern scams. Providers would need to stop sending SMS messages and emails that contain embedded links. Moreover, they would need clear incident-response processes to handle counterfeit applications and spoofed websites. Together, these measures aim to close the gaps that scammers currently exploit.
Stronger Rules for Enrollment, Device Changes, and Transfers
Beyond biometrics, the draft strengthens authentication across the customer journey. Three areas stand out.
Service enrollment and device changes
Providers would need rigorous identity verification when a customer enrolls or switches devices. They would also need to notify customers of the result through an out-of-band channel. Furthermore, the draft encourages risk controls such as cooling-off periods and temporary transaction limits after a device change. These steps slow down account takeovers. They also complement the wider push toward verified digital identity, echoed in Thailand’s advertiser identity verification rules.
Transaction-level authentication
The draft requires two-factor authentication for sensitive actions. These include fund transfers, cardless ATM withdrawals, and requests to raise transaction limits. Therefore, a single compromised credential should no longer be enough to drain an account.
Secure authentication factors
Finally, the draft sets standards for the factors themselves. “What-you-know” factors, such as PINs, must meet stricter design rules, while biometric factors must resist spoofing. In practice, this pushes providers toward layered, fraud-resistant authentication rather than a single shared secret. These safeguards also dovetail with Thailand’s broader electronic-transactions and digital-identity framework overseen by the Electronic Transactions Development Agency.
What Financial Businesses Should Do Before the Rules Take Effect
The consultation window is short, but the implementation effort will be substantial. Accordingly, affected businesses should act on several fronts.
First, assess scope. Determine whether your entity and each of your digital channels would fall within the expanded framework. Second, map your current authentication methods against the draft’s requirements, and flag every reliance on SMS OTPs. Third, plan the biometric build. Facial comparison with antispoofing requires reliable technology, vendor due diligence, and careful handling of biometric data under the Personal Data Protection Act. The same biometric-and-authentication questions arise under Thailand’s electronic transactions law, which recognises biometric e-signatures subject to PDPA safeguards.
Fourth, review customer communications. Removing embedded links from SMS and email will affect marketing, servicing, and fraud-alert workflows alike. Fifth, prepare an incident-response playbook for counterfeit apps and spoofed sites. Finally, consider submitting comments during the consultation. Well-reasoned industry feedback can shape the final text, especially on implementation timelines and technical thresholds.
Frequently Asked Questions
Are the new Thailand digital banking security rules already in force?
Which businesses would the draft cover?
When would facial biometric verification be required?
Will SMS one-time passwords still be allowed?
How should we prepare during the consultation period?
Need Guidance on Thailand Digital Banking Security?
Lex Bangkok advises banks, fintechs, card issuers, and lenders on Thailand’s evolving financial-services regulation, from BOT compliance to PDPA-compliant biometric deployment. Our team turns complex regulatory change into a clear, actionable plan for your business.
Schedule a Consultation