Thailand (TH)
Lead Signal
Thailand's payments operating environment has crystallised into a coherent baseline this cycle, and the dominant structural signal is the June 2025 award of the country's first virtual-bank licences. On 19 June 2025 the Ministry of Finance approved virtual-bank licences for three consortia — SCB X (with WeBank and KakaoBank), Krungthai Bank (with Gulf, AIS and PTT OR), and ACM Holding/Ascend Money (CP Group, the TrueMoney operator, backed by Ant International) — selected from five applicants, with operations required within one year. The same event, captured structurally as the approval of Thailand's first virtual-bank applicants on 19 June 2025, marks a turning point with phased supervision and restrictions on integration with legacy banks, set against banking-system gross NPLs that rose to THB548bn in Q1 2025. The assessment is that these awards will restructure the Thai banking-payments landscape from 2026, pairing incumbents with regional digital banks and payments players. This is a market-structure liberalisation running alongside a tightening enforcement and consumer-protection posture — a dual direction that defines Thailand's current trajectory.
The analytical spine here is the bank versus non-bank access asymmetry. Thailand operates a mature, Bank of Thailand-centred regime under the Payment Systems Act B.E. 2560 (2017), in force 16 April 2018, consolidating prior e-payment laws under BOT oversight, with BOT maintaining a public register of Designated Payment Systems and Services providers. The non-bank PI/EMI licensing route is distinct from the bank pathway: commercial banks must apply for BOT approval to engage in e-Money business under Section 36 of the Financial Institutions Businesses Act B.E. 2551 (2008), in addition to payment-services law licensing. This makes Thailand a structurally accessible but foreign-ownership-constrained market.
Outlook
Three forward items frame the coming year. BOT is consulting the market on a dedicated THB-stablecoin regime, with reserve and redemption standards not yet statutory, expected during 2026. Project Nexus — the BIS Innovation Hub hub-and-spoke model connecting instant payment systems, with Nexus Global Payments established in Singapore — is on track for 2026 rollout with Thailand participating. And the three licensed virtual-bank consortia are required to begin operations within one year of the 19 June 2025 award, pointing to a 2026 commencement that will reshape competitive dynamics. The net direction is tightening on consumer-fraud and digital-asset enforcement while liberalising on market structure — a configuration that rewards operators able to engage BOT's licensing perimeter directly while absorbing a heavier fraud-loss allocation.
Other Developments
The consumer-protection environment tightened materially in April 2025. The Emergency Decree on Measures for the Prevention and Suppression of Technology Crimes (No.2) B.E. 2568, published 12 April 2025 and effective 13 April 2025, establishes a shared-liability framework where banks, telcos, digital-wallet providers and platforms are collectively responsible for scam losses assessed on negligence, with mandatory SMS screening, mule-account penalties and a victim compensation mechanism. The change materially shifts fraud-loss allocation onto operators. Consumer bodies, however, flag gaps: the Thailand Consumers Council reported 18,687 cyber-risk complaints between October 2024 and September 2025 and warned the decree lacks pre-transaction safeguards such as delayed transactions, calling for an automatic-liability system and a central compensation standard.
On digital money, the regime liberalised at the trading layer while holding the line on payments. On 16 March 2025 the SEC officially approved inclusion of USDC and USDT in the list of permitted cryptocurrencies for digital-asset transactions, following a February 2025 public consultation, while reaffirming the prohibition on using digital assets as a general means of payment for goods and services. In parallel, BOT's Programmable Payment Project under the Enhanced Regulatory Sandbox — the Thai-Baht-backed Stablecoin Sandbox — expanded in H2 2025 with participants testing escrow payments and tokenised-asset settlement, and BOT is consulting market participants on a dedicated THB-stablecoin regulatory framework; as of early 2026 there are no statutory requirements specifically applicable to stablecoins. The judgment is that Thailand admits USDT/USDC to regulated trading while preserving the means-of-payment prohibition, keeping stablecoins outside Thai retail payment instruments for now.
Enforcement sharpened in the digital-asset space: on 29 May 2025 the SEC identified Bybit, 1000X, CoinEx, OKX and XT.COM as operating illegally and filed complaints with the Economic Crime Suppression Division, with MDES blocking orders effective 28 June 2025 under the Royal Decree on Technology Crimes (No.2) B.E. 2568. On resilience, BOT released AI Risk Management Guidelines for Financial Service Providers on 12 September 2025, applicable to financial institutions and to payment providers under the Payment Systems Act.
Cross-Monitor Connections
Two AML/CFT surfaces are sourced from the Sentinel feed and routed for FIM analysis rather than analysed here. The Cabinet approved a substantial AMLA amendment package on 25 February 2025, expanding the predicate-offence list and clarifying AMLO's inspection authority as part of continued FATF alignment; and in its 2023 follow-up report Thailand was re-rated on Recommendations 1 and 26 from Partially to Largely Compliant, remaining in enhanced follow-up under the APG. Original illicit-finance analysis — mule-account typologies, scam-compound cross-border flows and QR-laundering — belongs to FIM. The anti-scam shared-liability decree and the SEC offshore-exchange enforcement also carry illicit-finance and sanctions-evasion significance beyond WPM payments scope and are flagged accordingly.
Domains
14 regulatory modules · click to expand the full sub-briefLicensing, Authorisation & Market Access
ConfirmedThailand's licensing perimeter is anchored in the Payment Systems Act B.E.
Stablecoins & Digital Money
HighThailand's digital-money posture liberalised at the trading layer in 2025 while preserving a firm payments boundary.
Consumer Protection & APP Fraud
HighThe Emergency Decree on Measures for the Prevention and Suppression of Technology Crimes (No.2) B.E.
Commercial Intelligence (M&A, Investment & Product)
HighThe dominant commercial event this cycle is the award of Thailand's first virtual-bank licences.
Conduct, Safeguarding & Promotions
ConfirmedBank of Thailand minimum operating requirements for payment providers include good governance, risk management, consumer protection, security standards, business continuity planning and KYC policies, with the stated aim of protecting retail customers; these are supplemented by the Consumer Protection Act, the Electronic Transactions Act and the PDPA.
Operational Resilience & Critical Infra
ConfirmedBank of Thailand released AI Risk Management Guidelines for Financial Service Providers on 12 September 2025, building on June 2025 drafts, applicable to financial institutions and to payment providers under the Payment Systems Act and structured around governance and AI development/security controls.
Full per-domain detail — all 14 modules
W1aConfirmedLicensing, Authorisation & Market Access
see this theme across all jurisdictions →5 claimsPSA B.E. 2560 (2017) three-tier Designated Payment Service licensing under BOT; non-bank PI/EMI route distinct from bank s.36 FIBA e-money approval; foreign ownership generally capped at 49% without BOI approval.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Licensing, Authorisation & Market Access
Thailand's licensing perimeter is anchored in the Payment Systems Act B.E. 2560 (2017), in force 16 April 2018, consolidating prior e-payment laws under Bank of Thailand oversight; BOT maintains a public register of Designated Payment Systems and Services providers. This is the supervisor and statute any payments operator must engage with to enter the Thai market, and non-bank applicants are eligible without a banking background.
The designated-services architecture flows from Section 16 of the PSA: the Minister of Finance, with BOT advice, designates credit/debit/ATM card services, electronic money, electronic fund transfer and money remittance as Designated Payment Services requiring a licence or registration. The structure is three-tier — e-payment service, e-money service and payment system operator — with direct licensing running roughly nine to fifteen months and foreign ownership generally capped at 49% without BOI approval. The non-bank PI/EMI route covers e-money, payment gateway/facilitation, e-money transfer, acquiring and payment-on-behalf.
The bank versus non-bank distinction is structural here. Commercial banks must apply for BOT approval to engage in e-Money business under Section 36 of the Financial Institutions Businesses Act B.E. 2551 (2008), in addition to payment-services law licensing — a separate s.36 FIBA approval pathway for bank-PSP e-money that runs parallel to the PSA designated-service route used by non-bank PIs and EMIs. The net effect is a market that is structurally accessible to non-bank entrants but foreign-ownership-constrained.
Outlook
The W1a baseline is established and confirmed. The licensing perimeter is stable; the live forward variable is how the three virtual-bank consortia, licensed in June 2025, operationalise within the bank-side approval framework as they commence operations during 2026.
PSA B.E. 2560 (2017) three-tier Designated Payment Service licensing under BOT; non-bank PI/EMI route distinct from bank s.36 FIBA e-money approval; foreign ownership generally capped at 49% without BOI approval.
Evidence — 5 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
USDT/USDC approved for regulated trading (16 Mar 2025); BOT THB-stablecoin Programmable Payment sandbox expanding; means-of-payment prohibition retained; dedicated statute pending.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Stablecoins & Digital Money
Thailand's digital-money posture liberalised at the trading layer in 2025 while preserving a firm payments boundary. On 16 March 2025 the SEC officially approved inclusion of USDC and USDT in the list of permitted cryptocurrencies for digital-asset transactions, following a February 2025 public consultation, while reaffirming the prohibition on using digital assets as a general means of payment for goods and services. Previously only BTC, ETH, XRP, XLM and certain BOT settlement-system tokens were approved. The approval admits USDT/USDC to regulated digital-asset trading, but the means-of-payment prohibition keeps stablecoins out of Thai retail payment instruments.
In parallel, BOT's Programmable Payment Project under the Enhanced Regulatory Sandbox — the Thai-Baht-backed Stablecoin Sandbox — expanded in H2 2025, with participants testing escrow payments and tokenised-asset settlement, and BOT is consulting market participants on a dedicated THB-stablecoin regulatory framework. As of early 2026 there are no statutory requirements specifically applicable to stablecoins, such as mandatory reserve composition or redemption at par; the framework is in development with no finalised THB-stablecoin statute as of mid-2026.
Outlook
The forward item is the dedicated THB-stablecoin regulatory framework, currently at consultation stage and expected during 2026, with reserve and redemption standards not yet statutory. Until that statute lands and the means-of-payment prohibition is revisited, stablecoins remain a regulated trading instrument rather than a payments instrument in Thailand.
USDT/USDC approved for regulated trading (16 Mar 2025); BOT THB-stablecoin Programmable Payment sandbox expanding; means-of-payment prohibition retained; dedicated statute pending.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Emergency Decree on Technology Crimes (No.2) B.E. 2568, effective 13 Apr 2025, establishes negligence-based shared liability among banks, telcos, e-wallets and platforms with mandatory SMS screening, mule-account penalties and victim compensation.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Consumer Protection & APP Fraud
The Emergency Decree on Measures for the Prevention and Suppression of Technology Crimes (No.2) B.E. 2568, published 12 April 2025 and effective 13 April 2025, establishes a shared-liability framework where banks, telcos, digital-wallet providers and platforms are collectively responsible for scam losses assessed on negligence, with mandatory SMS screening, mule-account penalties and a victim compensation mechanism. National Assembly approval followed on 28 May 2025. The framework materially shifts fraud-loss allocation onto banks, e-wallet providers, telcos and platforms operating in Thailand, and applies to both bank and non-bank actors.
Consumer bodies flag persistent gaps. The Thailand Consumers Council reported 18,687 cyber-risk complaints between October 2024 and September 2025 and warned the decree lacks pre-transaction safeguards such as delayed transactions, calling for an automatic-liability system and a central compensation standard. Gaps remain for self-authorised investment/APP-type fraud and for compensation standardisation.
Outlook
The module is tightening. The negligence-based shared-liability standard is the operative compliance and loss-allocation development for Thai payments operators. The open question is whether self-authorised fraud coverage and a standardised compensation mechanism follow; consumer-side pressure points in that direction.
Emergency Decree on Technology Crimes (No.2) B.E. 2568, effective 13 Apr 2025, establishes negligence-based shared liability among banks, telcos, e-wallets and platforms with mandatory SMS screening, mule-account penalties and victim compensation.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
W13HighCommercial Intelligence (M&A, Investment & Product)
see this theme across all jurisdictions →4 claimsThree virtual-bank licences awarded 19 Jun 2025 to SCB X (WeBank/KakaoBank), Krungthai (Gulf/AIS/PTT OR) and ACM Holding/Ascend Money (CP/Ant International); operations required within one year.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Commercial Intelligence (M&A, Investment & Product)
The dominant commercial event this cycle is the award of Thailand's first virtual-bank licences. On 19 June 2025 the Ministry of Finance approved virtual-bank licences for three consortia — SCB X (with WeBank and KakaoBank), Krungthai Bank (with Gulf, AIS and PTT OR), and ACM Holding/Ascend Money (CP Group, the TrueMoney operator, backed by Ant International) — selected from five applicants, with operations required within one year. This discrete licence-award event reshapes Thai banking and payments structure from 2026, pairing incumbents with regional digital banks and payments players. The deal value is not publicly disclosed; the event is classed as M&A, completed, with an event date of 19 June 2025.
A second consolidation event: in 2025 ERX, a Thai-licensed digital token exchange, was rebranded as KuCoin Thailand after being acquired by global exchange KuCoin, continuing its token-issuance and tokenisation focus under the KuCoin banner. This is M&A, completed, acquirer KuCoin, target ERX, value not publicly disclosed and an approximate 2025 event date.
Outlook
The module is active. The virtual-bank consortia are required to commence operations within one year of the June 2025 award, a 2026 milestone. The KuCoin-ERX acquisition signals digital-asset market consolidation, though its precise value, completion date and regulatory-approval status are undisclosed and flagged for future verification.
Three virtual-bank licences awarded 19 Jun 2025 to SCB X (WeBank/KakaoBank), Krungthai (Gulf/AIS/PTT OR) and ACM Holding/Ascend Money (CP/Ant International); operations required within one year.
Evidence — 4 structured claims
Key facts
- Content Tier
- D
- Sentinel Feed
- False
Event Findings
Conduct and safeguarding obligations for designated payment providers flow from BOT notifications under the PSA, covering governance, IT-risk, consumer protection, KYC, and customer-fund handling, supplemented by the Consumer Protection Act, Electronic Transactions Act, and PDPA. BOT has progressively raised AML-focused due diligence, IT-security and outsourcing standards and is advancing market-conduct and digital-fraud rules.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Conduct, Safeguarding & Financial Promotions
Bank of Thailand minimum operating requirements for payment providers include good governance, risk management, consumer protection, security standards, business continuity planning and KYC policies, with the stated aim of protecting retail customers; these are supplemented by the Consumer Protection Act, the Electronic Transactions Act and the PDPA. Conduct and safeguarding obligations flow from BOT notifications issued under the PSA, and a vulnerable-customer concept appears in the BOT Market Conduct notification FPG.6/2565. This conduct framework applies to both bank-PSP and non-bank PI/EMI providers.
A caveat is carried at module level: the specific vulnerable-customer language is not directly verifiable in the cited source, so the finding is held at High rather than Confirmed.
Outlook
The principal under-indexed area is customer-fund safeguarding mechanics for non-bank e-money and PI providers — segregation, trust-account or guarantee models. The PSA mandates customer-fund handling, but the specific protective mechanism is not directly evidenced in this cycle and is flagged for a next-cycle primary-source pull from BOT e-money notifications. Safeguarding and financial-promotion enforcement detail remains under-indexed.
Conduct and safeguarding obligations for designated payment providers flow from BOT notifications under the PSA, covering governance, IT-risk, consumer protection, KYC, and customer-fund handling, supplemented by the Consumer Protection Act, Electronic Transactions Act, and PDPA. BOT has progressively raised AML-focused due diligence, IT-security and outsourcing standards and is advancing market-conduct and digital-fraud rules.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Operational resilience for payment providers is governed by BOT IT-risk supervision and information-security notifications under the PSA, requiring business-continuity planning, incident response, backup systems and third-party/outsourcing oversight. BOT issued AI Risk Management Guidelines for financial service providers in September 2025 and aligns with the National Cybersecurity Act B.E. 2562 (2019).
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Operational Resilience & Critical Infrastructure
Bank of Thailand released AI Risk Management Guidelines for Financial Service Providers on 12 September 2025, building on June 2025 drafts, applicable to financial institutions and to payment providers under the Payment Systems Act and structured around governance and AI development/security controls. Resilience is supervised via BOT IT-risk notifications under the PSA and aligns with the National Cybersecurity Act B.E. 2562 (2019) and the Royal Decree on Technology Crimes (No.2) B.E. 2568.
Underpinning this, BOT supervises IT risk for payment-system-related service providers and requires an IT contingency plan within a business continuity plan, plus a backup computer system located remotely from the main computer centre. These obligations apply to both bank and non-bank providers.
Outlook
The resilience framework is advancing, with the AI guidelines the most recent layer over established BCP and IT-security supervision under the PSA. The trajectory is toward closer alignment of AI governance with existing IT-risk supervision; no statutory rupture is signalled for the period ahead.
Operational resilience for payment providers is governed by BOT IT-risk supervision and information-security notifications under the PSA, requiring business-continuity planning, incident response, backup systems and third-party/outsourcing oversight. BOT issued AI Risk Management Guidelines for financial service providers in September 2025 and aligns with the National Cybersecurity Act B.E. 2562 (2019).
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Card payments in Thailand operate over Visa, Mastercard and local networks under BOT supervision and PCI DSS, with BOT terms regulating card-fee collection and limiting additional surcharging except as permitted. Thailand does not operate an EU-style statutory interchange cap; pricing is governed by scheme rules plus BOT fairness/transparency terms. The national QR standard is BOT-mandated and interoperable.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Scheme & Network Compliance
Card processing in Thailand is supervised by BOT and must comply with PCI DSS; BOT terms regulate fair and transparent collection of credit-card fees, and providers cannot charge additional fees for card use except as permitted by BOT. Crucially, Thailand does not operate an EU-style statutory interchange cap; pricing is governed by scheme rules plus BOT fairness terms. The BOT-mandated interoperable QR standard and near-zero PromptPay MDR exert downward pressure on card economics, where card MDR runs approximately 1.5–2.5%.
At the scheme layer, under Visa Thailand scheme rules merchants must notify Visa and their acquirer 30 days before they begin surcharging, with stated factors governing whether surcharges are permitted. These obligations apply to both bank and non-bank participants.
Outlook
The module is stable. The absence of a statutory interchange cap is a regime feature, not a gap; actual interchange and MDR levels and any BOT fairness-term thresholds are not quantified beyond the approximate card MDR. Merchant-acquiring economics and the competitive dynamics of emerging-market QR rails are under-indexed relative to card-scheme framing and are flagged for future deepening.
Card payments in Thailand operate over Visa, Mastercard and local networks under BOT supervision and PCI DSS, with BOT terms regulating card-fee collection and limiting additional surcharging except as permitted. Thailand does not operate an EU-style statutory interchange cap; pricing is governed by scheme rules plus BOT fairness/transparency terms. The national QR standard is BOT-mandated and interoperable.
Evidence — 3 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Thailand is a regional leader in instant cross-border payments: its PromptPay rail launched the world's first real-time FPS linkage with Singapore's PayNow in 2021 and now connects via QR/FPS to Singapore, Malaysia, Indonesia, Vietnam, Cambodia, Lao PDR, Hong Kong, Japan and others under the ASEAN Regional Payment Connectivity initiative, with Project Nexus rollout in 2026. High-value cross-border FX settlement runs over BAHTNET PvP links.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Payment Corridor Dynamics
Thailand is a regional leader in instant cross-border account-to-account payments. MAS and BOT launched the PayNow-PromptPay linkage in 2021 — the first real-time payment-system linkage globally — enabling real-time transfers up to S$1,000/THB25,000 daily using a mobile number, completing within minutes versus one to two working days for legacy remittance. Corridor coverage now spans Singapore, Malaysia, Indonesia, Vietnam, Cambodia, Lao PDR, Hong Kong and Japan under the ASEAN Regional Payment Connectivity initiative.
The next structural layer is Project Nexus, launched by the BIS Innovation Hub with ASEAN central banks including Thailand, which creates a hub-and-spoke model connecting instant payment systems, with Nexus Global Payments established in Singapore and rollout on track for 2026. The cumulative assessment is that the 2021 linkage and expanding ASEAN QR/FPS connectivity, plus the 2026 Nexus rollout, position Thailand as a hub for low-cost real-time A2A corridors, eroding card and legacy-remittance economics.
Outlook
The corridor trajectory is expanding. Project Nexus is the dominant 2026 horizon item, moving from in-force-pending toward a multilateral hub-and-spoke connection of ASEAN instant-payment systems. The directional signal is continued corridor opening across the region.
Thailand is a regional leader in instant cross-border payments: its PromptPay rail launched the world's first real-time FPS linkage with Singapore's PayNow in 2021 and now connects via QR/FPS to Singapore, Malaysia, Indonesia, Vietnam, Cambodia, Lao PDR, Hong Kong, Japan and others under the ASEAN Regional Payment Connectivity initiative, with Project Nexus rollout in 2026. High-value cross-border FX settlement runs over BAHTNET PvP links.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Thailand's payments market is large, fragmented and competitive, anchored by mass-market PromptPay (90M+ registered accounts on a ~72M population) and a concentrated e-wallet segment led by TrueMoney (Ascend Money). Bank-PSP and fintech players coexist; foreign processors (2C2P, Opn, Adyen, Stripe, Checkout.com) typically enter via local licensing or partnership. Virtual banks awarded mid-2025 will reshape structure from 2026.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Industry Structure & Commercial Dynamics
The Thai e-wallet segment is concentrated: TrueMoney holds roughly 53% of the market with 17M+ active users, with Rabbit LINE Pay around 25% share. Most foreign operators enter via licensed Thai PSPs such as 2C2P (acquired by Ant in 2022), Opn, Adyen, Stripe and Checkout.com, shaping market-access strategy through local licensing or partnership. Mass-market PromptPay, with 79M+ IDs, anchors the A2A layer beneath this competitive non-bank wallet segment.
The structural turning point is the BOT/Ministry of Finance approval of Thailand's first virtual-bank applicants on 19 June 2025, with phased supervision and restrictions on integration with legacy banks; banking-system gross NPLs rose to THB548bn in Q1 2025. This is the structural-trend view of an event whose discrete deal mechanics sit in W13. Virtual banks awarded mid-2025 reshape market structure from 2026.
Outlook
The module trajectory is shifting. The three licensed consortia are required to begin operations within one year of the 19 June 2025 award, pointing to a 2026-Q2 commencement window that will restructure competitive dynamics between incumbents, non-bank wallets and new digital banks.
Thailand's payments market is large, fragmented and competitive, anchored by mass-market PromptPay (90M+ registered accounts on a ~72M population) and a concentrated e-wallet segment led by TrueMoney (Ascend Money). Bank-PSP and fintech players coexist; foreign processors (2C2P, Opn, Adyen, Stripe, Checkout.com) typically enter via local licensing or partnership. Virtual banks awarded mid-2025 will reshape structure from 2026.
Evidence — 3 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Enforcement in the payments-adjacent space is currently dominated by SEC digital-asset actions and cyber-fraud prosecutions. In 2025 the SEC pursued licence revocations and criminal complaints against unlicensed operators, blocked five offshore exchanges (Bybit, 1000X, CoinEx, OKX, XT.COM) from 28 June 2025, and in early 2026 filed criminal complaints over joint unlicensed exchange operations and Worldcoin-related trading. Cyber-fraud prosecutions under the 2025 Royal Decree carry up to 20-year sentences.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Legal & Litigation
Digital-asset enforcement sharpened in 2025. On 29 May 2025 the SEC identified Bybit, 1000X, CoinEx, OKX and XT.COM as operating illegally and filed complaints with the Economic Crime Suppression Division; MDES issued blocking orders effective 28 June 2025 under the Royal Decree on Technology Crimes (No.2) B.E. 2568. This is a dated dashboard entry: the announcement date is timezone-dependent (29–30 May 2025) while the 28 June 2025 blocking date is consistently confirmed; the finding is carried at Assessed.
Outlook
The litigation surface is escalating, driven by SEC enforcement and offshore-exchange blocking actions across 2025–2026. The directional read is continued enforcement against unlicensed foreign digital-asset operators following the expansion of regulatory scope to foreign platforms.
Enforcement in the payments-adjacent space is currently dominated by SEC digital-asset actions and cyber-fraud prosecutions. In 2025 the SEC pursued licence revocations and criminal complaints against unlicensed operators, blocked five offshore exchanges (Bybit, 1000X, CoinEx, OKX, XT.COM) from 28 June 2025, and in early 2026 filed criminal complaints over joint unlicensed exchange operations and Worldcoin-related trading. Cyber-fraud prosecutions under the 2025 Royal Decree carry up to 20-year sentences.
Evidence — 3 structured claims
Key facts
- Content Tier
- D
- Sentinel Feed
- False
Event Findings
Acquiring in Thailand is a PSA-designated payment service requiring a Designated Payment Service Licence; acquirers must route settlement through licensed banks, comply with PCI DSS, maintain fraud-prevention and cardholder-data protection, store and report transaction data to BOT, and apply AML/KYC with STR reporting to AMLO. Chargeback/dispute mechanics follow scheme rules incorporated through acquirer agreements.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Merchant Acquiring & Risk
Acquiring is a PSA-designated payment service requiring a Designated Payment Service Licence. BOT requires acquirers to route all settlements through licensed banks, comply with PCI DSS, implement fraud-prevention and cardholder-data protection, store transaction data and report to BOT, with AML/KYC checks and AMLO reporting; BOT may suspend or revoke acquiring licences for violations. Chargeback and dispute mechanics follow scheme rules incorporated through acquirer agreements. These obligations apply to both bank and non-bank acquirers.
Outlook
The module is stable. The settlement-routing-through-licensed-banks requirement preserves a structural dependency on bank infrastructure for non-bank acquirers, an asymmetry worth tracking as virtual banks and new processors enter the market from 2026.
Acquiring in Thailand is a PSA-designated payment service requiring a Designated Payment Service Licence; acquirers must route settlement through licensed banks, comply with PCI DSS, maintain fraud-prevention and cardholder-data protection, store and report transaction data to BOT, and apply AML/KYC with STR reporting to AMLO. Chargeback/dispute mechanics follow scheme rules incorporated through acquirer agreements.
Evidence — 3 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Thailand is highly innovation-active: PromptPay underpins instant A2A and QR, with PromptBiz for businesses, an active BOT regulatory sandbox, programmable-payment/THB-stablecoin testing, National Digital ID (NDID) for KYC, and ongoing retail CBDC and mBridge cross-border research. Open-banking remains early-stage (dStatement since 2022; API standards not yet finalised).
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Product Innovation & Market Development
Thailand's primary real-time rails are PromptPay, BAHTNET and PromptBiz. PromptPay, launched in 2016, settles in up to 60 seconds, 24/7, using a mobile number or national ID, operated by National ITMX with final interbank settlement via BAHTNET using ISO 20022 messaging. Open banking remains early-stage: dStatement has operated since January 2022, but API standards are not finalised, and NDID (2018) underpins reusable KYC. The rails serve both bank and non-bank participants.
Outlook
The module is active but with an unfinished product-access horizon. Open-banking API standards and a PSD-equivalent data-access framework remain unfinalised; dStatement is the only confirmed step, leaving the product-innovation horizon partly unspecified and flagged for future tracking.
Thailand is highly innovation-active: PromptPay underpins instant A2A and QR, with PromptBiz for businesses, an active BOT regulatory sandbox, programmable-payment/THB-stablecoin testing, National Digital ID (NDID) for KYC, and ongoing retail CBDC and mBridge cross-border research. Open-banking remains early-stage (dStatement since 2022; API standards not yet finalised).
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
sentinel.gi position carried: Thailand's AML/CFT regime is built on the Anti-Money Laundering Act B.E. 2542 (1999) and the CTPF Act B.E. 2559 (2016), with AMLO as FIU and supervisor. Thailand was grey-listed (2010/2011), exited in 2013/2015 and remains in APG enhanced follow-up; a February 2025 AMLA amendment package expanded predicate offences and reporting entities. Digital-asset operators are 'financial institutions' for AML purposes. Payments-context risks: mule accounts, QR-code laundering, cross-border scam-compound flows.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
AML/CFT & Financial Crime
This module is sourced from the Sentinel feed (sentinel.gi); original illicit-finance analysis is routed to FIM and is not re-analysed here. Per Sentinel, the Cabinet approved a substantial AMLA amendment package on 25 February 2025, expanding the predicate-offence list (including nominee shareholding and digital-asset offences), adding reporting-entity categories and clarifying AMLO's inspection authority, as part of continued FATF alignment. Thailand remains in APG enhanced follow-up. Also per Sentinel, in its 2023 follow-up report Thailand was re-rated on Recommendations 1 and 26 from Partially to Largely Compliant, now holding 33 Recommendations Compliant/Largely Compliant with 6 remaining Partially Compliant, and remains in enhanced follow-up under the APG. Digital-asset operators are treated as 'financial institutions' under AMLA via the Emergency Decree on Digital Asset Businesses s.7. These surfaces apply to both bank and non-bank actors.
Outlook
The AML/CFT surface is advancing under continued FATF alignment. Original analysis of mule-account typologies, scam-compound cross-border flows and QR-laundering is carried to FIM as a cross-monitor reference, not a WPM conclusion. See the Sentinel feed for the underlying intelligence.
sentinel.gi position carried: Thailand's AML/CFT regime is built on the Anti-Money Laundering Act B.E. 2542 (1999) and the CTPF Act B.E. 2559 (2016), with AMLO as FIU and supervisor. Thailand was grey-listed (2010/2011), exited in 2013/2015 and remains in APG enhanced follow-up; a February 2025 AMLA amendment package expanded predicate offences and reporting entities. Digital-asset operators are 'financial institutions' for AML purposes. Payments-context risks: mule accounts, QR-code laundering, cross-border scam-compound flows.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- True
Event Findings
W12ConfirmedCorrespondent Banking, Settlement & Access
see this theme across all jurisdictions →4 claimsBAHTNET (launched 24 May 1995) is BOT's RTGS system providing final, irrevocable settlement for high-value interbank transfers, accessible to institutions holding current accounts at BOT and to qualifying juristic persons under defined access criteria; it provides collateralised intraday liquidity and serves as the settlement backbone for PromptPay (via National ITMX). Cross-border PvP links (e.g. HKMA USD CHATS) support FX settlement and correspondent-banking relationships. BAHTNET has migrated to ISO 20022.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Correspondent Banking, Settlement & Access
The analytical spine of this module is the bank versus non-bank access asymmetry to settlement infrastructure. BAHTNET, launched 24 May 1995, is BOT's RTGS system providing final, irrevocable settlement for high-value interbank transfers, accessible to institutions with current accounts at BOT and qualifying juristic persons under defined Access Criteria. It provides unlimited collateralised intraday liquidity, settles in central bank money with immediate finality, and has migrated to ISO 20022; it is the settlement backbone for PromptPay via National ITMX, and was assessed against CPSS-IOSCO PFMI as a sound system. Access to central-bank-money settlement is structured around bank and qualifying-institution criteria, leaving non-bank PIs dependent on bank rails for final settlement.
On the cross-border layer, a payment-versus-payment link connects Hong Kong's USD RTGS system and Thailand's THB RTGS (BAHTNET), eliminating settlement risk in USD-THB FX transactions and creating correspondent-banking opportunities for Hong Kong banks serving Thai banks — a bank-PSP access enabler.
Outlook
The module is established. The settlement backbone and the USD-THB PvP link are stable, durable infrastructure. The persistent analytical tension is the dependency of non-bank providers on bank-held BOT accounts for final settlement, an asymmetry that the 2026 virtual-bank entrants may begin to reshape.
BAHTNET (launched 24 May 1995) is BOT's RTGS system providing final, irrevocable settlement for high-value interbank transfers, accessible to institutions holding current accounts at BOT and to qualifying juristic persons under defined access criteria; it provides collateralised intraday liquidity and serves as the settlement backbone for PromptPay (via National ITMX). Cross-border PvP links (e.g. HKMA USD CHATS) support FX settlement and correspondent-banking relationships. BAHTNET has migrated to ISO 20022.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False