Thailand KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Thailand.
- Last reviewed
- Last reviewed:
- Version
- Version 1.0

Portable implementation guide
Get the PDF checklist
11 control areas · 38 implementation checks
Last reviewed: 26 September 2026 · Version 1.0
Download the checklistDirect answer
What does the Thailand compliance checklist cover?
The Thailand checklist translates primary KYC, KYB and AML rules into 11 control areas and 38 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- FIU
- Anti-Money Laundering Office (AMLO)
- Primary AML rules
- Anti-Money Laundering Act B.E. 2542, as amended, and CDD Regulation B.E. 2563
- STR timing
- File through AMLO within the applicable statutory or prescribed period; do not wait for a monetary threshold
- Threshold reports
- Transaction type and reporting-person specific; use the current AMLO schedules and aggregation rules
- AML records
- CDD and transaction records have distinct statutory periods; preserve longer when AMLO directs or a matter remains active
- Wire information
- Cross-border transfers at THB 50,000 or more are a documented information breakpoint under the assessed framework
- Privacy breach
- Notify the PDPC without delay and, where feasible, within 72 hours when the statutory risk test is met
- FATF public lists
- Not listed at 19 June 2026; APG member
Implementation detail
Thailand compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingClassify the entity, activity and supervisor before applying any control or threshold.3 items+
Determine whether each activity is performed by a reporting person.
- Implementation action
- Map financial-institution and section 16 professional activities to the current AMLA perimeter, amendments and subordinate instruments; document exclusions and the competent supervisor.
- Evidence to retain
- Entity chart, product and funds-flow inventory, perimeter memorandum, source extracts and counsel sign-off.
- Primary citation
- AMLA sections 3, 13 and 16, as amended
Obtain every sector licence, registration or approval before launch.
- Implementation action
- Confirm BOT, SEC, Office of Insurance Commission or other authority requirements for the actual payment, e-money, securities, insurance, money-transfer, foreign-exchange or digital-asset service.
- Evidence to retain
- Perimeter analysis, application, licence or registration, conditions and renewal calendar.
- Primary citation
- Payment Systems Act B.E. 2560; Emergency Decree on Digital Asset Businesses B.E. 2561, as amended; applicable sector law
Maintain current AMLO reporting access and accountable contacts.
- Implementation action
- Enrol authorised users in AMLO's current reporting channel, test access, protect credentials and update appointments and entity details.
- Evidence to retain
- Enrolment, user register, access test, appointments and change log.
- Primary citation
- AMLA sections 13 and 16; AMLO transaction-reporting rules and portal guidance
02Governance and ML/TF/PF risk assessmentControls must be risk-based, approved, resourced and independently tested.3 items+
Maintain a documented institutional ML/TF/PF risk assessment.
- Implementation action
- Assess customers, countries, products, services, transactions, channels, technology, agents and outsourcing; update before material change and when official risk information changes.
- Evidence to retain
- Methodology, current assessment, data sources, approval, residual-risk decisions and remediation plan.
- Primary citation
- CDD Regulation B.E. 2563; AMLO institutional-risk guidance
Maintain approved AML/CFT/CPF policies and accountable governance.
- Implementation action
- Assign board and senior-management oversight and an empowered compliance function; document CDD, monitoring, reporting, sanctions, records, training and escalation.
- Evidence to retain
- Approved programme, appointments, committee minutes, reports, training and issue log.
- Primary citation
- AMLA and CDD Regulation B.E. 2563; applicable AMLO and sector rules
Independently test design and operating effectiveness.
- Implementation action
- Use a risk-based audit scope to sample customer files, ownership, reporting clocks, sanctions, data quality, agents and remediation.
- Evidence to retain
- Audit plan, independence record, samples, findings, management response and closure tests.
- Primary citation
- CDD Regulation B.E. 2563; applicable supervisor rules
03Natural-person identificationIdentity controls apply at relationship, applicable occasional-transaction, suspicion and prior-data-doubt triggers.4 items+
Identify and verify natural-person customers.
- Implementation action
- Collect prescribed identity attributes and verify them from reliable independent evidence; resolve discrepancies and prohibit anonymous or fictitious-name relationships.
- Evidence to retain
- Customer record, identity evidence, verification source, timestamp and discrepancy resolution.
- Primary citation
- CDD Regulation B.E. 2563, customer identification and verification provisions
Apply the correct CDD trigger and sector threshold.
- Implementation action
- Configure relationship opening, applicable occasional transactions, suspicion and doubt about prior information. Maintain a versioned sector matrix rather than applying one monetary threshold to every business.
- Evidence to retain
- Trigger matrix, linked-transaction logic, tested scenarios, rule version and exceptions.
- Primary citation
- CDD Regulation B.E. 2563; applicable AMLO and sector notifications
Verify representatives and their authority.
- Implementation action
- Identify and verify each person acting for a customer and establish the mandate and its limits before accepting instructions or access.
- Evidence to retain
- Representative KYC, authority instrument, verification, scope limits and activity log.
- Primary citation
- CDD Regulation B.E. 2563
Control failed CDD and tipping-off risk.
- Implementation action
- Where required CDD cannot be completed, do not establish or continue the relationship or transaction as the governing rule requires, assess an STR and avoid alerting the customer.
- Evidence to retain
- CDD gap, restriction or exit decision, approvals, suspicion assessment and filing evidence.
- Primary citation
- CDD Regulation B.E. 2563; AMLA suspicious-reporting and confidentiality provisions
04KYB, registries, and beneficial ownershipVerify legal existence, authorised persons and natural-person ownership or control; registry evidence is not conclusive AML proof.4 items+
Verify each legal person or arrangement.
- Implementation action
- Obtain current Department of Business Development or other competent registry evidence, constitutional documents, purpose, address, directors, partners, trustees and authorised persons.
- Evidence to retain
- Certified registry material, constitutional documents, licences, mandates and discrepancy log.
- Primary citation
- CDD Regulation B.E. 2563; Civil and Commercial Code; applicable registry rules
Identify and verify beneficial owners through ownership and control.
- Implementation action
- Trace the chain to natural persons, assess control by other means and apply the senior-managing-person fallback only when no natural person is identified under the governing test; record every step.
- Evidence to retain
- Ownership chart, calculations, registry evidence, control analysis, verified identities and fallback rationale.
- Primary citation
- CDD Regulation B.E. 2563; AMLO beneficial-owner identification guidance
Identify parties to trusts and comparable arrangements.
- Implementation action
- Identify and verify the settlor, trustee or equivalent, protector where relevant, beneficiaries or classes and every natural person exercising ultimate effective control.
- Evidence to retain
- Trust instrument, party schedule, control powers, entitlement analysis and verified identities.
- Primary citation
- CDD Regulation B.E. 2563
Reconcile corporate filings without treating them as dispositive.
- Implementation action
- Keep DBD registrations and shareholder information current, compare them with the AML ownership analysis and investigate inconsistencies or nominee indicators.
- Evidence to retain
- DBD extracts, shareholder records, reconciliation, nominee-risk review and escalation.
- Primary citation
- Civil and Commercial Code; DBD registration guidance; CDD Regulation B.E. 2563
05PEPs, enhanced due diligence, and remote onboardingPolitical exposure, higher risk and remote delivery require stronger measures.3 items+
Identify politically exposed persons and relevant relationships.
- Implementation action
- Screen customers and beneficial owners for domestic, foreign and international-organisation PEP status and the relationships covered by the current AMLO notification; refresh risk-sensitively.
- Evidence to retain
- Screening result, source, relationship map, rationale and refresh history.
- Primary citation
- CDD Regulation B.E. 2563; AMLO Notification on Politically Exposed Persons effective 2 February 2026
Apply enhanced due diligence when higher risk requires it.
- Implementation action
- Obtain required senior approval, corroborate source of wealth and funds, obtain additional purpose information and increase monitoring frequency and depth.
- Evidence to retain
- Risk trigger, approval, corroboration, enhanced plan and periodic reviews.
- Primary citation
- CDD Regulation B.E. 2563
Control non-face-to-face identity and biometric processing.
- Implementation action
- Validate document authenticity, liveness, impersonation and device risk; document the PDPA lawful basis, necessity, security and retention of biometric or identity data.
- Evidence to retain
- Method assessment, fraud tests, privacy assessment, vendor diligence and exception log.
- Primary citation
- CDD Regulation B.E. 2563; Personal Data Protection Act B.E. 2562 sections 24, 26 and 37
06Monitoring and suspicious transaction reportingMonitor against expected activity and report suspicion to AMLO without waiting for a threshold.4 items+
Conduct ongoing due diligence and transaction monitoring.
- Implementation action
- Keep identity, ownership and risk information current and scrutinise activity against purpose, profile, capacity and expected source of funds; investigate deviations promptly.
- Evidence to retain
- Monitoring scenarios, alerts, case analysis, refresh history and dispositions.
- Primary citation
- CDD Regulation B.E. 2563
Detect and assess suspicious transactions and attempts regardless of amount.
- Implementation action
- Map the statutory suspicion indicators and relevant attempted activity, record the facts and escalate promptly to the authorised decision-maker.
- Evidence to retain
- Alert chronology, indicator mapping, analysis, decision and supporting records.
- Primary citation
- AMLA sections 3 and 13, as amended
File STRs through the current AMLO route within the applicable period.
- Implementation action
- Record when suspicion arose, apply the current statutory or prescribed clock, submit the correct report and retain acknowledgement and any supplement. Do not invent a portal or deadline from an obsolete form.
- Evidence to retain
- Decision timestamp, report, validation result, AMLO acknowledgement and supplement log.
- Primary citation
- AMLA section 13; current AMLO reporting rules and portal guidance
Protect reporting confidentiality and prevent tipping off.
- Implementation action
- Restrict STR, suspicion and AMLO-request information to authorised need-to-know access; legally review disclosures and customer communications.
- Evidence to retain
- Access matrix, disclosure log, legal review, training and incident record.
- Primary citation
- AMLA confidentiality and tipping-off provisions
07Threshold reports, wires, payments, and digital assetsAmounts, aggregation, report type and licensing are transaction- and sector-specific.4 items+
Apply transaction-reporting thresholds only with their legal scope.
- Implementation action
- Maintain the current AMLO schedule for cash, property and other prescribed transactions by reporting-person type; preserve aggregation and exception logic and do not confuse reporting amounts with CDD triggers.
- Evidence to retain
- Versioned threshold matrix, transaction data, aggregation test, reports and acknowledgements.
- Primary citation
- AMLA section 13; ministerial regulations prescribing reportable transactions
Carry required originator and beneficiary information in transfers.
- Implementation action
- For cross-border transfers at THB 50,000 or more, apply the information requirements documented in Thailand's assessed framework; for every transfer apply any stricter current sector rule and repair, reject or restrict incomplete messages.
- Evidence to retain
- Field matrix, payment-message samples, validation tests, repair queue and rejection record.
- Primary citation
- CDD Regulation B.E. 2563 and AMLO electronic-transfer notification; APG Thailand follow-up assessment
Obtain payment-system permission before providing regulated services.
- Implementation action
- Map the service to designated payment systems and designated payment services and obtain the required Ministry of Finance licence or BOT registration before commencement.
- Evidence to retain
- Service map, legal analysis, licence or registration, conditions and agent inventory.
- Primary citation
- Payment Systems Act B.E. 2560; BOT payment-system oversight guidance
Obtain digital-asset authority and apply the current travel-rule controls.
- Implementation action
- Classify exchange, broker, dealer, advisory, fund management, custodial-wallet and ICO activities; obtain required approval and implement the SEC travel-rule and KYC/CDD requirements in force for the service.
- Evidence to retain
- Activity analysis, licence, SEC correspondence, KYC/CDD configuration, transfer-data tests and exceptions.
- Primary citation
- Emergency Decree on Digital Asset Businesses B.E. 2561, as amended in 2025; SEC digital-asset rules and September 2026 travel-rule announcement
08Targeted financial sanctionsControls must detect designated persons, ownership and control and support freezing without delay.3 items+
Screen relevant persons and transactions against current designations.
- Implementation action
- Screen customers, beneficial owners, controllers, representatives and transactions at onboarding, during the relationship and when UN or Thai designations change; assess indirect ownership and control.
- Evidence to retain
- List inventory, update logs, configuration tests, match analysis and disposition.
- Primary citation
- Counter-Terrorism and Proliferation of Weapons of Mass Destruction Financing Act B.E. 2559
Freeze designated property without delay and report through the verified route.
- Implementation action
- On an applicable designation, immediately prevent dealing or availability, preserve related property and follow the current AMLO notification, reporting, exemption and release process.
- Evidence to retain
- Match and control analysis, freeze timestamp, report, system blocks and authority correspondence.
- Primary citation
- Counter-Terrorism and Proliferation of Weapons of Mass Destruction Financing Act B.E. 2559
Maintain distinct TF and PF sanctions procedures.
- Implementation action
- Map designation, freezing, reporting, exemption, delisting and unfreezing routes for terrorism and proliferation and test direct and indirect availability scenarios.
- Evidence to retain
- Legal map, procedure, list-update record, scenario tests and escalation log.
- Primary citation
- Counter-Terrorism and Proliferation of Weapons of Mass Destruction Financing Act B.E. 2559; applicable AMLO rules
09Records and regulator accessRecords must reconstruct identity, ownership, transactions, reporting and decisions from the correct trigger.3 items+
Retain transaction and CDD records for their distinct legal periods.
- Implementation action
- Apply the current statutory period and trigger to each record class, preserve records longer for an active case or AMLO direction and do not collapse all records into one retention rule.
- Evidence to retain
- Retention schedule, trigger calculations, archive samples, legal holds and deletion approvals.
- Primary citation
- AMLA sections 22 and 22/1, as amended; CDD record-retention regulations
Preserve evidence in a form that reconstructs each transaction and relationship.
- Implementation action
- Link identity, ownership, risk, instructions, transaction data, alerts, reports, sanctions actions, approvals and communications under stable identifiers.
- Evidence to retain
- Sample case pack, lineage report, retrieval test and access log.
- Primary citation
- AMLA sections 21-22/1; CDD Regulation B.E. 2563
Provide records securely to authenticated competent authorities.
- Implementation action
- Maintain a controlled request process that validates authority, preserves confidentiality and records the material produced and delivery route.
- Evidence to retain
- Request register, authority validation, production index, approval and receipt.
- Primary citation
- AMLA; applicable AMLO and sector-supervisor powers
10Privacy, biometrics, breaches, and transfersAML processing remains subject to PDPA purpose, lawful-basis, security and accountability controls.4 items+
Document a lawful basis and proportionality for KYC processing.
- Implementation action
- Map identity, biometric, screening and monitoring fields to legal obligation, consent or another valid basis; provide notice, minimise collection and maintain accuracy.
- Evidence to retain
- Data inventory, lawful-basis map, notices, consent where relied upon, field justification and correction process.
- Primary citation
- Personal Data Protection Act B.E. 2562 sections 19, 23-26 and 37
Implement security and processor accountability.
- Implementation action
- Use risk-appropriate organisational and technical safeguards, access controls, processor terms, deletion controls and incident cooperation; review sensitive-data vendors.
- Evidence to retain
- Security assessment, access review, contracts, subprocessor register, tests and training.
- Primary citation
- Personal Data Protection Act B.E. 2562 sections 37 and 40
Notify qualifying personal-data breaches on the statutory clock.
- Implementation action
- Assess likely risk to individuals and notify the PDPC without delay and, where feasible, within 72 hours; notify affected persons without delay when high risk is likely, documenting any exception or delay.
- Evidence to retain
- Incident chronology, risk assessment, PDPC notice, data-subject notice and remediation.
- Primary citation
- Personal Data Protection Act B.E. 2562 section 37(4)
Control cross-border personal-data transfers.
- Implementation action
- Map destinations and onward transfers, assess adequacy or another lawful transfer mechanism and preserve enforceable safeguards, security and data-subject rights.
- Evidence to retain
- Transfer map, mechanism analysis, contracts, recipient assessment and monitoring.
- Primary citation
- Personal Data Protection Act B.E. 2562 sections 28-29; current PDPC cross-border rules
11Practical evidence packsEvidence should reproduce onboarding, reporting, sanctions and launch decisions end to end.3 items+
Maintain a reconstructable onboarding pack.
- Implementation action
- Bundle identity, representative authority, KYB, ownership and control, PEP and sanctions screening, risk, approvals, privacy records and exceptions.
- Evidence to retain
- Complete sampled onboarding pack and retrieval result.
- Primary citation
- Operational control supporting AMLA and CDD Regulation B.E. 2563
Maintain a reconstructable reporting and sanctions pack.
- Implementation action
- Link transactions, alerts, analysis, decision times, report, acknowledgement, freeze actions, authority communications and access logs.
- Evidence to retain
- Complete sampled case pack, timeline and controlled access log.
- Primary citation
- Operational control supporting AMLA section 13 and the CTPF Act B.E. 2559
Maintain a regulator-scoped launch pack.
- Implementation action
- Record perimeter, permissions, current sources, reporting readiness, ownership analysis, sanctions, privacy transfers, agents, vendor controls and validation before launch or material change.
- Evidence to retain
- Signed launch pack, source register, regulator map, uncertainty log, tests and approvals.
- Primary citation
- Official sources listed below
Primary-source register
21 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Anti-Money Laundering Office main portalAMLO · Official FIU and regulator portal
- AMLO supervisory laws and ministerial regulations indexAMLO · Official legal index
- AMLO CDD guidance indexAMLO · Official regulatory guidance
- AMLO customer-risk and beneficial-owner guidanceAMLO · Official regulatory guidance
- AMLO 2026 politically exposed persons notification noticeAMLO · Official regulatory notice
- AMLO reporting and customer-identification guidanceAMLO · Official reporting guidance
- AMLO designated-person list portalAMLO · Official sanctions portal
- Payment Systems Act oversightBank of Thailand · Official regulatory guidance
- Notifications under the Payment Systems ActBank of Thailand · Official regulatory index
- BOT KYC rules for e-money service activationBank of Thailand · Official supervisory regulation
- Digital Asset BusinessesSecurities and Exchange Commission Thailand · Official licensing and rules portal
- Emergency Decree on Digital Asset Businesses, consolidated English textSecurities and Exchange Commission Thailand · Primary legislation
- SEC 2026 enhanced KYC/CDD guidelinesSecurities and Exchange Commission Thailand · Official supervisory guidance
- SEC 2026 digital-asset travel-rule announcementSecurities and Exchange Commission Thailand · Official supervisory notice
- Department of Business DevelopmentDepartment of Business Development · Official company registry portal
- Personal Data Protection CommissionPDPC Thailand · Official privacy authority portal
- Thailand 2023 sixth enhanced follow-up reportFATF / APG · Authoritative assessment
- FATF jurisdictions under increased monitoring - 19 June 2026FATF · Authoritative current status
- FATF high-risk jurisdictions subject to a call for action - 19 June 2026FATF · Authoritative current status
- FATF FSRB Guest Initiative announcementFATF · Authoritative current status
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
Direct answers
Thailand KYC, KYB and AML questions
Who receives suspicious transaction reports?+
The Anti-Money Laundering Office, Thailand's financial intelligence unit, through its current authorised reporting route.
When must an STR be filed?+
Use the applicable AMLA and current AMLO reporting period measured from the legally relevant event or determination. Record the chronology and do not rely on an obsolete form or wait for a threshold.
Is there one universal transaction-reporting threshold?+
No. Cash, property and other prescribed transaction reports are tied to transaction type, reporting-person category, current ministerial schedules and aggregation rules.
Is there one universal CDD threshold?+
No. Relationship opening, suspicion and doubt about prior information can trigger CDD without a monetary amount; occasional-transaction triggers vary by sector and service.
How is beneficial ownership determined?+
Trace ownership and control to natural persons, assess control by other means and use the senior-managing-person fallback only under the governing rule. Registry information supports but does not replace that analysis.
How long are AML records retained?+
Apply the current period and trigger separately to transaction, identification and CDD records, and preserve longer for an active matter or authority direction. Confirm the schedule for the reporting-person category.
What applies to cross-border wire transfers?+
The assessed Thai framework uses THB 50,000 as an information breakpoint for cross-border transfers. Apply any stricter current sector rule and ensure incomplete transfers are repaired, rejected or restricted as required.
Can a payment or digital-asset service launch without approval?+
No. Map the precise service to BOT or SEC licensing, registration and approval requirements before launch; AML compliance does not substitute for permission.
What happens on a sanctions match?+
Verify identifiers and ownership or control, freeze applicable property without delay, prevent dealing or availability and follow the current AMLO report, exemption and release route.
When is a personal-data breach notified?+
Notify the PDPC without delay and, where feasible, within 72 hours when the breach is likely to create risk; notify affected persons without delay when high risk is likely, subject to the statutory exceptions.
Is Thailand on a FATF public list?+
No. Thailand was absent from both FATF public lists dated 19 June 2026. It is an APG member; absence from a public list is not a low-risk finding.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 26 September 2026. English materials do not replace controlling Thai-language instruments. Confirm the reporting-person perimeter, current AMLO forms and electronic route, sector thresholds, licensing, sanctions directions, registry filings and PDPA transfer rules with the competent authority and qualified Thai counsel before launch.