Skip to main content

Thailand Digital Banking Security: What the 2026 BOT Draft Rules Mean

Thailand digital banking security is about to enter a stricter era. On 23 July 2026, the Bank of Thailand (BOT) released a draft Notification on Digital Channel Security for public consultation, and the proposal would reshape how banks, card issuers, and lenders protect their customers online. Above all, the draft signals the end of the SMS one-time password and the arrival of mandatory facial biometrics for high-value transfers. For any international business that offers payment, credit, or banking services in Thailand, these changes deserve close attention now, well before they become binding.

What the Bank of Thailand Has Proposed

The draft builds directly on the BOT’s 2024 Mobile Banking Security Notification, which set minimum security standards for financial institutions, specialised financial institutions, and e-money providers. That earlier framework reduced “money-draining app” fraud sharply. However, criminals adapted and moved toward nonbank providers and internet banking. In response, the BOT now proposes a broader and tougher rulebook for digital banking security in Thailand. This trend mirrors the tighter cyber-governance standards already advancing across the financial sector, as seen in Thailand’s insurance cybersecurity reforms.

Importantly, this is still a draft. The public comment period runs through 24 August 2026, and the final text may change. As a result, businesses should treat the proposal as a strong signal of regulatory direction rather than a settled legal obligation. Even so, the direction of travel is clear, and early preparation will pay off.

Key Takeaway: The BOT’s draft Notification on Digital Channel Security is open for consultation until 24 August 2026. It is not yet in force. Nevertheless, it maps out where Thailand’s online banking security rules are heading, so affected firms should plan ahead rather than wait for the final version.

Who Now Falls Within Scope

The most significant shift is the wider net. The current rules apply only to a limited set of providers. By contrast, the draft expands coverage across both the entities regulated and the channels protected.

On the entity side, the draft would add:

  • Credit card providers that offer fund transfers to third parties at other financial service providers.
  • Credit providers that offer cash withdrawal services to individual retail customers.

On the channel side, the draft would extend mandatory protection to internet banking, not just mobile applications. Consequently, many businesses that previously sat outside the mobile-banking rulebook would fall squarely within scope. Fintech lenders and card issuers, in particular, should review their status early.

Key Takeaway: If your business issues cards, extends consumer credit, or lets customers move money online, the draft may capture you for the first time. Confirm your regulatory status before the framework is finalised.

The End of SMS OTPs and the Shift to Biometrics

For years, the SMS one-time password has been the backbone of transaction authentication in Thailand. The draft would retire it. Instead, providers would need stronger authentication factors that fraudsters cannot easily intercept or socially engineer.

Biometric verification sits at the centre of this shift. Under the proposal, providers must use facial comparison with effective antispoofing technology for higher-value transactions. Specifically, the draft would require this biometric check for:

  • Transfers exceeding THB 50,000 per transaction; or
  • Cumulative transfers exceeding THB 200,000 per day.

In addition, the draft targets the phishing links that fuel modern scams. Providers would need to stop sending SMS messages and emails that contain embedded links. Moreover, they would need clear incident-response processes to handle counterfeit applications and spoofed websites. Together, these measures aim to close the gaps that scammers currently exploit.

Key Takeaway: The draft would phase out SMS OTPs, mandate facial biometrics with antispoofing for transfers above THB 50,000 per transaction or THB 200,000 per day, and ban embedded links in customer SMS and email. Firms should begin scoping the technology and vendor changes these steps require.

Stronger Rules for Enrollment, Device Changes, and Transfers

Beyond biometrics, the draft strengthens authentication across the customer journey. Three areas stand out.

Service enrollment and device changes

Providers would need rigorous identity verification when a customer enrolls or switches devices. They would also need to notify customers of the result through an out-of-band channel. Furthermore, the draft encourages risk controls such as cooling-off periods and temporary transaction limits after a device change. These steps slow down account takeovers. They also complement the wider push toward verified digital identity, echoed in Thailand’s advertiser identity verification rules.

Transaction-level authentication

The draft requires two-factor authentication for sensitive actions. These include fund transfers, cardless ATM withdrawals, and requests to raise transaction limits. Therefore, a single compromised credential should no longer be enough to drain an account.

Secure authentication factors

Finally, the draft sets standards for the factors themselves. “What-you-know” factors, such as PINs, must meet stricter design rules, while biometric factors must resist spoofing. In practice, this pushes providers toward layered, fraud-resistant authentication rather than a single shared secret. These safeguards also dovetail with Thailand’s broader electronic-transactions and digital-identity framework overseen by the Electronic Transactions Development Agency.

Key Takeaway: Enrollment and device changes would demand tighter identity checks and out-of-band alerts, while transfers, cardless withdrawals, and limit increases would require two-factor authentication. Review your onboarding and step-up authentication flows against these proposals now.

What Financial Businesses Should Do Before the Rules Take Effect

The consultation window is short, but the implementation effort will be substantial. Accordingly, affected businesses should act on several fronts.

First, assess scope. Determine whether your entity and each of your digital channels would fall within the expanded framework. Second, map your current authentication methods against the draft’s requirements, and flag every reliance on SMS OTPs. Third, plan the biometric build. Facial comparison with antispoofing requires reliable technology, vendor due diligence, and careful handling of biometric data under the Personal Data Protection Act. The same biometric-and-authentication questions arise under Thailand’s electronic transactions law, which recognises biometric e-signatures subject to PDPA safeguards.

Fourth, review customer communications. Removing embedded links from SMS and email will affect marketing, servicing, and fraud-alert workflows alike. Fifth, prepare an incident-response playbook for counterfeit apps and spoofed sites. Finally, consider submitting comments during the consultation. Well-reasoned industry feedback can shape the final text, especially on implementation timelines and technical thresholds.

Regulatory status note: The measures described here come from a draft BOT Notification issued for public consultation on 23 July 2026, with comments accepted until 24 August 2026. They are proposed, not yet legally binding, and the final requirements may differ. This article is general information, not legal advice. Businesses should obtain tailored advice before making compliance decisions.

Frequently Asked Questions

Are the new Thailand digital banking security rules already in force?
No. The Bank of Thailand released the draft Notification on Digital Channel Security for public consultation on 23 July 2026, with comments accepted through 24 August 2026. The measures are proposed and may change before any final version takes effect. Businesses should monitor the BOT for the finalised text and its commencement date.
Which businesses would the draft cover?
The draft would keep coverage of financial institutions, specialised financial institutions, and e-money providers, and it would add credit card providers that offer third-party fund transfers and credit providers that offer cash withdrawals to retail customers. It would also extend protection from mobile apps to internet banking. Card issuers and consumer lenders should check their status early.
When would facial biometric verification be required?
Under the proposal, providers must use facial comparison with antispoofing technology for transfers exceeding THB 50,000 per transaction or cumulative transfers exceeding THB 200,000 per day. The requirement aligns with the BOT’s guidelines on biometric technology in financial services.
Will SMS one-time passwords still be allowed?
The draft would phase out SMS OTPs for transaction authentication in favour of stronger factors. It would also require providers to stop sending SMS and email messages that contain embedded links, which are a common vector for phishing scams.
How should we prepare during the consultation period?
Confirm whether the framework would apply to your entity and channels, inventory every use of SMS OTPs, plan the biometric and two-factor build, revise link-free customer communications, and draft an incident-response plan for counterfeit apps and sites. You may also submit comments to help shape the final rules. Experienced Thai counsel can help you scope obligations and manage biometric data lawfully.

Need Guidance on Thailand Digital Banking Security?

Lex Bangkok advises banks, fintechs, card issuers, and lenders on Thailand’s evolving financial-services regulation, from BOT compliance to PDPA-compliant biometric deployment. Our team turns complex regulatory change into a clear, actionable plan for your business.

Schedule a Consultation