BOT Framework for Safeguarding the Financial Sector from Illicit Activities: New Supervisory Expectations for Financial Institutions and Payment Providers
The Bank of Thailand (BOT), together with financial institutions and regulated financial service providers, has formally launched the Framework for Safeguarding the Financial Sector from Illicit Activities, a sector-wide initiative intended to prevent the financial system from being used to facilitate technology-enabled crime, corruption, money laundering, fraud, and other illicit activities. The Framework represents a significant supervisory development for banks, payment service providers, e-money operators, foreign exchange businesses, and non-bank lenders. While the Framework itself is principally a cooperation and policy framework rather than a standalone regulation imposing penalties, the BOT has expressly indicated that it will strengthen regulations, minimum standards, and supervisory oversight to promote consistent implementation across the financial sector. Accordingly, regulated entities should view the Framework not merely as a statement of policy, but as an indication of the direction in which future supervisory expectations and regulatory requirements are likely to develop.
Five Core Principles:
The Framework is built around five principles that participating institutions are expected to apply in a manner appropriate to their business models and risk profiles. First, preventing misuse of the financial sector should form part of leadership and corporate governance, with boards and senior management responsible for establishing policies, strategic direction, oversight arrangements, and adequate resources. Second, institutions should translate those commitments into effective standards and execution, including appropriate minimum standards for monitoring, detection, and risk response, with periodic review as risks evolve. Third, institutions are expected to develop expertise and data-driven capabilities, using data, technology, and specialized knowledge to improve monitoring and detection. Fourth, the Framework emphasizes collaboration and collective intelligence, including exchanges of information, intelligence, fraud typologies, risk indicators, and best practices among financial institutions, government authorities, private-sector organizations, and other relevant stakeholders, subject to applicable legal frameworks. Finally, preventive measures should pursue balanced objectives, taking into account financial inclusion, fair competition, innovation, customer convenience, and the need to avoid unnecessary burdens on legitimate users.
From Policy Framework to Operational Controls:
The significance of the Framework becomes clearer when the commitments of the BOT and participating industry groups are considered. The BOT intends to strengthen KYC, Customer Due Diligence (CDD), and Enhanced Due Diligence (EDD) standards, including end-to-end controls against mule accounts. It also plans to strengthen Know Your Merchant (KYM) requirements and oversight of high-risk merchants, particularly in payment acceptance services. Other areas identified for enhanced controls include high-value cash transactions, conversion of illicit proceeds into assets that are more difficult to trace, digital financial service security, and standards applicable to non-bank operators.
Financial institutions and industry associations have correspondingly committed to stronger customer identification and due diligence, greater scrutiny of high-risk accounts and cash transactions, and increased use of data and technology to identify unusual transactions and behavioral patterns. Banks are expected to integrate internal information with trusted external sources and use customer profiles, behavioral information, and transaction inflow/outflow patterns to identify links among accounts and suspicious activity. Payment service providers are expected to strengthen KYM throughout the merchant lifecycle, including enhanced merchant screening and behavioral monitoring, while non-bank lenders are expected to strengthen their assessment of customers, related parties, transactions, and sources of funds. The Framework also contemplates databases of high-risk persons and merchants, links with the Central Fraud Registry, and development of industry-wide AML/CFT operational guidelines.
Data Sharing Becomes a Central Compliance Issue:
One of the most consequential elements of the Framework is its emphasis on information sharing. The BOT intends to analyze linkages and share risk patterns, behavioral indicators, and information concerning individuals, legal entities, and merchants identified as high risk. It also envisages greater data exchange and collaborative analytics involving regulatory authorities, law enforcement agencies, and other government bodies. Financial institutions and payment providers will likewise be expected to contribute relevant information, including unusual transaction patterns, merchant information, fraud intelligence, and other indicators that may assist in identifying misuse of the financial system.
This creates an important intersection between financial-crime prevention and personal data protection. The Framework expressly recognizes that information exchange must occur within applicable legal frameworks. Consequently, an expectation or request to share information for fraud prevention purposes should not automatically be treated as removing the need for analysis under the Personal Data Protection Act (PDPA). Institutions should identify an appropriate lawful basis for each relevant processing and disclosure activity, determine whether the data collected and shared are necessary and proportionate to the stated purpose, establish appropriate retention periods, and implement access controls and security safeguards. Data accuracy will be particularly important where information is used to classify a person or merchant as high risk or to restrict access to financial services.
High-Risk and Blacklist Databases Require Particular Attention:
The contemplated development and sharing of high-risk-person and merchant information raises additional governance considerations. A risk indicator used merely to trigger additional review is materially different from a blacklist that automatically results in account restrictions, rejection of onboarding, termination of services, or other adverse consequences. Institutions should therefore consider establishing clear criteria for inclusion and removal, defining the evidentiary threshold required for a high-risk designation, controlling who may submit or amend records, periodically reviewing whether information remains accurate and relevant, and establishing escalation or review procedures where a designation may materially affect a customer.
These issues become more significant as databases are interconnected across institutions or with centralized fraud information systems. Incorrect, outdated, or insufficiently verified information could potentially propagate across the financial sector and affect an individual or business beyond the institution that originally generated the risk indicator. Governance of shared databases should therefore address not only cybersecurity and access management but also data provenance, accuracy, correction procedures, retention, accountability, and the distinction between intelligence suggesting risk and verified findings of unlawful conduct.
What Financial Institutions and Payment Providers Should Do Now
Although detailed minimum standards will continue to develop, regulated entities should consider conducting a readiness assessment against the Framework now rather than waiting for individual implementing measures. This should include reviewing whether board and senior-management oversight adequately covers financial-crime and fraud risks; mapping existing KYC/CDD/EDD and KYM controls against the emerging supervisory direction; assessing high-value cash and unusual-transaction monitoring; reviewing the use of AI, behavioral analytics, and external data sources; and identifying existing or planned information-sharing arrangements with other institutions, industry bodies, regulators, and law-enforcement agencies. Particular attention should be given to the interface between financial-crime controls and the institution’s PDPA, cybersecurity, data governance, outsourcing, and third-party risk frameworks.
Institutions should also document the legal and governance architecture supporting fraud-related data processing before broader industry sharing becomes operational. This may include reviewing privacy notices, records of processing activities, data-sharing agreements or protocols, retention schedules, access matrices, security controls, procedures for correcting inaccurate risk information, and the allocation of responsibilities among compliance, AML, fraud, privacy, cybersecurity, legal, and business teams. Where automated tools or risk-scoring systems are used to identify high-risk customers or transactions, institutions should also consider whether their governance arrangements provide sufficient human oversight and mechanisms to manage false positives and unintended customer impacts.
Key Takeaways:
The Framework marks a shift toward a more coordinated, intelligence-led approach to protecting the financial sector from illicit activities. Although it is not, by itself, a standalone penal regulation, the BOT has expressly signaled further development of regulations, minimum standards, and supervisory oversight, making the Framework an important indicator of future compliance expectations.
For financial institutions, payment providers, and other regulated non-banks, the immediate priorities are to assess existing KYC/CDD/EDD and KYM controls, strengthen technology-based detection and high-risk transaction monitoring, and prepare for substantially greater information sharing across the financial ecosystem. At the same time, fraud prevention and financial-crime objectives must be reconciled with PDPA requirements, cybersecurity controls, proportionality, data accuracy, retention, and appropriate governance of high-risk and blacklist databases.
The next major development to monitor will be the BOT’s issuance or enhancement of minimum standards, regulations, supervisory guidelines, or operational requirements implementing the Framework. Those measures are likely to determine when the Framework moves from a high-level sector commitment to more concrete and enforceable compliance expectations.
Author: Panisa Suwanmatajarn, Managing Partner.
Other Articles
- Social Media Advertising: New Advertiser Verification Requirements Take Effect Soon
- Thailand Revises Visa Exemption Scheme: 30-Day Stay and Revised List of Eligible Countries
- PDPA: When CCTV Becomes Biometric Processing
- PDPA: Cross-Border Data Transfer Compliance for Bank Z Under Thailand’s Data Protection Law – Key Takeaways
- PDPA: Does Removing a Name Make Data Anonymous?
- PDPA: Disclosure of Personal Data to Third Parties for Legal Proceedings