Thaïlande KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Thaïlande.
- Dernière revue
- Dernière revue:
- Version
- Version 1.0

Guide d’implémentation portable
Obtenir la checklist PDF
11 domaines de contrôle · 38 contrôles d’implémentation
Dernière revue: 26 September 2026 · Version 1.0
Télécharger la checklistRéponse directe
Que couvre la checklist de conformité pour Thaïlande ?
La checklist pour Thaïlande traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 38 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- FIU
- Anti-Money Laundering Office (AMLO)
- Primary AML rules
- Anti-Money Laundering Act B.E. 2542, as amended, and CDD Regulation B.E. 2563
- STR timing
- File through AMLO within the applicable statutory or prescribed period; do not wait for a monetary threshold
- Threshold reports
- Transaction type and reporting-person specific; use the current AMLO schedules and aggregation rules
- AML records
- CDD and transaction records have distinct statutory periods; preserve longer when AMLO directs or a matter remains active
- Wire information
- Cross-border transfers at THB 50,000 or more are a documented information breakpoint under the assessed framework
- Privacy breach
- Notify the PDPC without delay and, where feasible, within 72 hours when the statutory risk test is met
- FATF public lists
- Not listed at 19 June 2026; APG member
Détail d’implémentation
Exigences et actions de conformité pour Thaïlande
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities, and licensingClassify the entity, activity and supervisor before applying any control or threshold.3 éléments+
Determine whether each activity is performed by a reporting person.
- Action d’implémentation
- Map financial-institution and section 16 professional activities to the current AMLA perimeter, amendments and subordinate instruments; document exclusions and the competent supervisor.
- Preuves à conserver
- Entity chart, product and funds-flow inventory, perimeter memorandum, source extracts and counsel sign-off.
- Source primaire
- AMLA sections 3, 13 and 16, as amended
Obtain every sector licence, registration or approval before launch.
- Action d’implémentation
- Confirm BOT, SEC, Office of Insurance Commission or other authority requirements for the actual payment, e-money, securities, insurance, money-transfer, foreign-exchange or digital-asset service.
- Preuves à conserver
- Perimeter analysis, application, licence or registration, conditions and renewal calendar.
- Source primaire
- Payment Systems Act B.E. 2560; Emergency Decree on Digital Asset Businesses B.E. 2561, as amended; applicable sector law
Maintain current AMLO reporting access and accountable contacts.
- Action d’implémentation
- Enrol authorised users in AMLO's current reporting channel, test access, protect credentials and update appointments and entity details.
- Preuves à conserver
- Enrolment, user register, access test, appointments and change log.
- Source primaire
- AMLA sections 13 and 16; AMLO transaction-reporting rules and portal guidance
02Governance and ML/TF/PF risk assessmentControls must be risk-based, approved, resourced and independently tested.3 éléments+
Maintain a documented institutional ML/TF/PF risk assessment.
- Action d’implémentation
- Assess customers, countries, products, services, transactions, channels, technology, agents and outsourcing; update before material change and when official risk information changes.
- Preuves à conserver
- Methodology, current assessment, data sources, approval, residual-risk decisions and remediation plan.
- Source primaire
- CDD Regulation B.E. 2563; AMLO institutional-risk guidance
Maintain approved AML/CFT/CPF policies and accountable governance.
- Action d’implémentation
- Assign board and senior-management oversight and an empowered compliance function; document CDD, monitoring, reporting, sanctions, records, training and escalation.
- Preuves à conserver
- Approved programme, appointments, committee minutes, reports, training and issue log.
- Source primaire
- AMLA and CDD Regulation B.E. 2563; applicable AMLO and sector rules
Independently test design and operating effectiveness.
- Action d’implémentation
- Use a risk-based audit scope to sample customer files, ownership, reporting clocks, sanctions, data quality, agents and remediation.
- Preuves à conserver
- Audit plan, independence record, samples, findings, management response and closure tests.
- Source primaire
- CDD Regulation B.E. 2563; applicable supervisor rules
03Natural-person identificationIdentity controls apply at relationship, applicable occasional-transaction, suspicion and prior-data-doubt triggers.4 éléments+
Identify and verify natural-person customers.
- Action d’implémentation
- Collect prescribed identity attributes and verify them from reliable independent evidence; resolve discrepancies and prohibit anonymous or fictitious-name relationships.
- Preuves à conserver
- Customer record, identity evidence, verification source, timestamp and discrepancy resolution.
- Source primaire
- CDD Regulation B.E. 2563, customer identification and verification provisions
Apply the correct CDD trigger and sector threshold.
- Action d’implémentation
- Configure relationship opening, applicable occasional transactions, suspicion and doubt about prior information. Maintain a versioned sector matrix rather than applying one monetary threshold to every business.
- Preuves à conserver
- Trigger matrix, linked-transaction logic, tested scenarios, rule version and exceptions.
- Source primaire
- CDD Regulation B.E. 2563; applicable AMLO and sector notifications
Verify representatives and their authority.
- Action d’implémentation
- Identify and verify each person acting for a customer and establish the mandate and its limits before accepting instructions or access.
- Preuves à conserver
- Representative KYC, authority instrument, verification, scope limits and activity log.
- Source primaire
- CDD Regulation B.E. 2563
Control failed CDD and tipping-off risk.
- Action d’implémentation
- Where required CDD cannot be completed, do not establish or continue the relationship or transaction as the governing rule requires, assess an STR and avoid alerting the customer.
- Preuves à conserver
- CDD gap, restriction or exit decision, approvals, suspicion assessment and filing evidence.
- Source primaire
- CDD Regulation B.E. 2563; AMLA suspicious-reporting and confidentiality provisions
04KYB, registries, and beneficial ownershipVerify legal existence, authorised persons and natural-person ownership or control; registry evidence is not conclusive AML proof.4 éléments+
Verify each legal person or arrangement.
- Action d’implémentation
- Obtain current Department of Business Development or other competent registry evidence, constitutional documents, purpose, address, directors, partners, trustees and authorised persons.
- Preuves à conserver
- Certified registry material, constitutional documents, licences, mandates and discrepancy log.
- Source primaire
- CDD Regulation B.E. 2563; Civil and Commercial Code; applicable registry rules
Identify and verify beneficial owners through ownership and control.
- Action d’implémentation
- Trace the chain to natural persons, assess control by other means and apply the senior-managing-person fallback only when no natural person is identified under the governing test; record every step.
- Preuves à conserver
- Ownership chart, calculations, registry evidence, control analysis, verified identities and fallback rationale.
- Source primaire
- CDD Regulation B.E. 2563; AMLO beneficial-owner identification guidance
Identify parties to trusts and comparable arrangements.
- Action d’implémentation
- Identify and verify the settlor, trustee or equivalent, protector where relevant, beneficiaries or classes and every natural person exercising ultimate effective control.
- Preuves à conserver
- Trust instrument, party schedule, control powers, entitlement analysis and verified identities.
- Source primaire
- CDD Regulation B.E. 2563
Reconcile corporate filings without treating them as dispositive.
- Action d’implémentation
- Keep DBD registrations and shareholder information current, compare them with the AML ownership analysis and investigate inconsistencies or nominee indicators.
- Preuves à conserver
- DBD extracts, shareholder records, reconciliation, nominee-risk review and escalation.
- Source primaire
- Civil and Commercial Code; DBD registration guidance; CDD Regulation B.E. 2563
05PEPs, enhanced due diligence, and remote onboardingPolitical exposure, higher risk and remote delivery require stronger measures.3 éléments+
Identify politically exposed persons and relevant relationships.
- Action d’implémentation
- Screen customers and beneficial owners for domestic, foreign and international-organisation PEP status and the relationships covered by the current AMLO notification; refresh risk-sensitively.
- Preuves à conserver
- Screening result, source, relationship map, rationale and refresh history.
- Source primaire
- CDD Regulation B.E. 2563; AMLO Notification on Politically Exposed Persons effective 2 February 2026
Apply enhanced due diligence when higher risk requires it.
- Action d’implémentation
- Obtain required senior approval, corroborate source of wealth and funds, obtain additional purpose information and increase monitoring frequency and depth.
- Preuves à conserver
- Risk trigger, approval, corroboration, enhanced plan and periodic reviews.
- Source primaire
- CDD Regulation B.E. 2563
Control non-face-to-face identity and biometric processing.
- Action d’implémentation
- Validate document authenticity, liveness, impersonation and device risk; document the PDPA lawful basis, necessity, security and retention of biometric or identity data.
- Preuves à conserver
- Method assessment, fraud tests, privacy assessment, vendor diligence and exception log.
- Source primaire
- CDD Regulation B.E. 2563; Personal Data Protection Act B.E. 2562 sections 24, 26 and 37
06Monitoring and suspicious transaction reportingMonitor against expected activity and report suspicion to AMLO without waiting for a threshold.4 éléments+
Conduct ongoing due diligence and transaction monitoring.
- Action d’implémentation
- Keep identity, ownership and risk information current and scrutinise activity against purpose, profile, capacity and expected source of funds; investigate deviations promptly.
- Preuves à conserver
- Monitoring scenarios, alerts, case analysis, refresh history and dispositions.
- Source primaire
- CDD Regulation B.E. 2563
Detect and assess suspicious transactions and attempts regardless of amount.
- Action d’implémentation
- Map the statutory suspicion indicators and relevant attempted activity, record the facts and escalate promptly to the authorised decision-maker.
- Preuves à conserver
- Alert chronology, indicator mapping, analysis, decision and supporting records.
- Source primaire
- AMLA sections 3 and 13, as amended
File STRs through the current AMLO route within the applicable period.
- Action d’implémentation
- Record when suspicion arose, apply the current statutory or prescribed clock, submit the correct report and retain acknowledgement and any supplement. Do not invent a portal or deadline from an obsolete form.
- Preuves à conserver
- Decision timestamp, report, validation result, AMLO acknowledgement and supplement log.
- Source primaire
- AMLA section 13; current AMLO reporting rules and portal guidance
Protect reporting confidentiality and prevent tipping off.
- Action d’implémentation
- Restrict STR, suspicion and AMLO-request information to authorised need-to-know access; legally review disclosures and customer communications.
- Preuves à conserver
- Access matrix, disclosure log, legal review, training and incident record.
- Source primaire
- AMLA confidentiality and tipping-off provisions
07Threshold reports, wires, payments, and digital assetsAmounts, aggregation, report type and licensing are transaction- and sector-specific.4 éléments+
Apply transaction-reporting thresholds only with their legal scope.
- Action d’implémentation
- Maintain the current AMLO schedule for cash, property and other prescribed transactions by reporting-person type; preserve aggregation and exception logic and do not confuse reporting amounts with CDD triggers.
- Preuves à conserver
- Versioned threshold matrix, transaction data, aggregation test, reports and acknowledgements.
- Source primaire
- AMLA section 13; ministerial regulations prescribing reportable transactions
Carry required originator and beneficiary information in transfers.
- Action d’implémentation
- For cross-border transfers at THB 50,000 or more, apply the information requirements documented in Thailand's assessed framework; for every transfer apply any stricter current sector rule and repair, reject or restrict incomplete messages.
- Preuves à conserver
- Field matrix, payment-message samples, validation tests, repair queue and rejection record.
- Source primaire
- CDD Regulation B.E. 2563 and AMLO electronic-transfer notification; APG Thailand follow-up assessment
Obtain payment-system permission before providing regulated services.
- Action d’implémentation
- Map the service to designated payment systems and designated payment services and obtain the required Ministry of Finance licence or BOT registration before commencement.
- Preuves à conserver
- Service map, legal analysis, licence or registration, conditions and agent inventory.
- Source primaire
- Payment Systems Act B.E. 2560; BOT payment-system oversight guidance
Obtain digital-asset authority and apply the current travel-rule controls.
- Action d’implémentation
- Classify exchange, broker, dealer, advisory, fund management, custodial-wallet and ICO activities; obtain required approval and implement the SEC travel-rule and KYC/CDD requirements in force for the service.
- Preuves à conserver
- Activity analysis, licence, SEC correspondence, KYC/CDD configuration, transfer-data tests and exceptions.
- Source primaire
- Emergency Decree on Digital Asset Businesses B.E. 2561, as amended in 2025; SEC digital-asset rules and September 2026 travel-rule announcement
08Targeted financial sanctionsControls must detect designated persons, ownership and control and support freezing without delay.3 éléments+
Screen relevant persons and transactions against current designations.
- Action d’implémentation
- Screen customers, beneficial owners, controllers, representatives and transactions at onboarding, during the relationship and when UN or Thai designations change; assess indirect ownership and control.
- Preuves à conserver
- List inventory, update logs, configuration tests, match analysis and disposition.
- Source primaire
- Counter-Terrorism and Proliferation of Weapons of Mass Destruction Financing Act B.E. 2559
Freeze designated property without delay and report through the verified route.
- Action d’implémentation
- On an applicable designation, immediately prevent dealing or availability, preserve related property and follow the current AMLO notification, reporting, exemption and release process.
- Preuves à conserver
- Match and control analysis, freeze timestamp, report, system blocks and authority correspondence.
- Source primaire
- Counter-Terrorism and Proliferation of Weapons of Mass Destruction Financing Act B.E. 2559
Maintain distinct TF and PF sanctions procedures.
- Action d’implémentation
- Map designation, freezing, reporting, exemption, delisting and unfreezing routes for terrorism and proliferation and test direct and indirect availability scenarios.
- Preuves à conserver
- Legal map, procedure, list-update record, scenario tests and escalation log.
- Source primaire
- Counter-Terrorism and Proliferation of Weapons of Mass Destruction Financing Act B.E. 2559; applicable AMLO rules
09Records and regulator accessRecords must reconstruct identity, ownership, transactions, reporting and decisions from the correct trigger.3 éléments+
Retain transaction and CDD records for their distinct legal periods.
- Action d’implémentation
- Apply the current statutory period and trigger to each record class, preserve records longer for an active case or AMLO direction and do not collapse all records into one retention rule.
- Preuves à conserver
- Retention schedule, trigger calculations, archive samples, legal holds and deletion approvals.
- Source primaire
- AMLA sections 22 and 22/1, as amended; CDD record-retention regulations
Preserve evidence in a form that reconstructs each transaction and relationship.
- Action d’implémentation
- Link identity, ownership, risk, instructions, transaction data, alerts, reports, sanctions actions, approvals and communications under stable identifiers.
- Preuves à conserver
- Sample case pack, lineage report, retrieval test and access log.
- Source primaire
- AMLA sections 21-22/1; CDD Regulation B.E. 2563
Provide records securely to authenticated competent authorities.
- Action d’implémentation
- Maintain a controlled request process that validates authority, preserves confidentiality and records the material produced and delivery route.
- Preuves à conserver
- Request register, authority validation, production index, approval and receipt.
- Source primaire
- AMLA; applicable AMLO and sector-supervisor powers
10Privacy, biometrics, breaches, and transfersAML processing remains subject to PDPA purpose, lawful-basis, security and accountability controls.4 éléments+
Document a lawful basis and proportionality for KYC processing.
- Action d’implémentation
- Map identity, biometric, screening and monitoring fields to legal obligation, consent or another valid basis; provide notice, minimise collection and maintain accuracy.
- Preuves à conserver
- Data inventory, lawful-basis map, notices, consent where relied upon, field justification and correction process.
- Source primaire
- Personal Data Protection Act B.E. 2562 sections 19, 23-26 and 37
Implement security and processor accountability.
- Action d’implémentation
- Use risk-appropriate organisational and technical safeguards, access controls, processor terms, deletion controls and incident cooperation; review sensitive-data vendors.
- Preuves à conserver
- Security assessment, access review, contracts, subprocessor register, tests and training.
- Source primaire
- Personal Data Protection Act B.E. 2562 sections 37 and 40
Notify qualifying personal-data breaches on the statutory clock.
- Action d’implémentation
- Assess likely risk to individuals and notify the PDPC without delay and, where feasible, within 72 hours; notify affected persons without delay when high risk is likely, documenting any exception or delay.
- Preuves à conserver
- Incident chronology, risk assessment, PDPC notice, data-subject notice and remediation.
- Source primaire
- Personal Data Protection Act B.E. 2562 section 37(4)
Control cross-border personal-data transfers.
- Action d’implémentation
- Map destinations and onward transfers, assess adequacy or another lawful transfer mechanism and preserve enforceable safeguards, security and data-subject rights.
- Preuves à conserver
- Transfer map, mechanism analysis, contracts, recipient assessment and monitoring.
- Source primaire
- Personal Data Protection Act B.E. 2562 sections 28-29; current PDPC cross-border rules
11Practical evidence packsEvidence should reproduce onboarding, reporting, sanctions and launch decisions end to end.3 éléments+
Maintain a reconstructable onboarding pack.
- Action d’implémentation
- Bundle identity, representative authority, KYB, ownership and control, PEP and sanctions screening, risk, approvals, privacy records and exceptions.
- Preuves à conserver
- Complete sampled onboarding pack and retrieval result.
- Source primaire
- Operational control supporting AMLA and CDD Regulation B.E. 2563
Maintain a reconstructable reporting and sanctions pack.
- Action d’implémentation
- Link transactions, alerts, analysis, decision times, report, acknowledgement, freeze actions, authority communications and access logs.
- Preuves à conserver
- Complete sampled case pack, timeline and controlled access log.
- Source primaire
- Operational control supporting AMLA section 13 and the CTPF Act B.E. 2559
Maintain a regulator-scoped launch pack.
- Action d’implémentation
- Record perimeter, permissions, current sources, reporting readiness, ownership analysis, sanctions, privacy transfers, agents, vendor controls and validation before launch or material change.
- Preuves à conserver
- Signed launch pack, source register, regulator map, uncertainty log, tests and approvals.
- Source primaire
- Official sources listed below
Registre des sources primaires
21 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Anti-Money Laundering Office main portalAMLO · Official FIU and regulator portal
- AMLO supervisory laws and ministerial regulations indexAMLO · Official legal index
- AMLO CDD guidance indexAMLO · Official regulatory guidance
- AMLO customer-risk and beneficial-owner guidanceAMLO · Official regulatory guidance
- AMLO 2026 politically exposed persons notification noticeAMLO · Official regulatory notice
- AMLO reporting and customer-identification guidanceAMLO · Official reporting guidance
- AMLO designated-person list portalAMLO · Official sanctions portal
- Payment Systems Act oversightBank of Thailand · Official regulatory guidance
- Notifications under the Payment Systems ActBank of Thailand · Official regulatory index
- BOT KYC rules for e-money service activationBank of Thailand · Official supervisory regulation
- Digital Asset BusinessesSecurities and Exchange Commission Thailand · Official licensing and rules portal
- Emergency Decree on Digital Asset Businesses, consolidated English textSecurities and Exchange Commission Thailand · Primary legislation
- SEC 2026 enhanced KYC/CDD guidelinesSecurities and Exchange Commission Thailand · Official supervisory guidance
- SEC 2026 digital-asset travel-rule announcementSecurities and Exchange Commission Thailand · Official supervisory notice
- Department of Business DevelopmentDepartment of Business Development · Official company registry portal
- Personal Data Protection CommissionPDPC Thailand · Official privacy authority portal
- Thailand 2023 sixth enhanced follow-up reportFATF / APG · Authoritative assessment
- FATF jurisdictions under increased monitoring - 19 June 2026FATF · Authoritative current status
- FATF high-risk jurisdictions subject to a call for action - 19 June 2026FATF · Authoritative current status
- FATF FSRB Guest Initiative announcementFATF · Authoritative current status
- United Nations Security Council consolidated sanctions listUnited Nations · Authoritative sanctions list
Réponses directes
Questions KYC, KYB et AML pour Thaïlande
Who receives suspicious transaction reports?+
The Anti-Money Laundering Office, Thailand's financial intelligence unit, through its current authorised reporting route.
When must an STR be filed?+
Use the applicable AMLA and current AMLO reporting period measured from the legally relevant event or determination. Record the chronology and do not rely on an obsolete form or wait for a threshold.
Is there one universal transaction-reporting threshold?+
No. Cash, property and other prescribed transaction reports are tied to transaction type, reporting-person category, current ministerial schedules and aggregation rules.
Is there one universal CDD threshold?+
No. Relationship opening, suspicion and doubt about prior information can trigger CDD without a monetary amount; occasional-transaction triggers vary by sector and service.
How is beneficial ownership determined?+
Trace ownership and control to natural persons, assess control by other means and use the senior-managing-person fallback only under the governing rule. Registry information supports but does not replace that analysis.
How long are AML records retained?+
Apply the current period and trigger separately to transaction, identification and CDD records, and preserve longer for an active matter or authority direction. Confirm the schedule for the reporting-person category.
What applies to cross-border wire transfers?+
The assessed Thai framework uses THB 50,000 as an information breakpoint for cross-border transfers. Apply any stricter current sector rule and ensure incomplete transfers are repaired, rejected or restricted as required.
Can a payment or digital-asset service launch without approval?+
No. Map the precise service to BOT or SEC licensing, registration and approval requirements before launch; AML compliance does not substitute for permission.
What happens on a sanctions match?+
Verify identifiers and ownership or control, freeze applicable property without delay, prevent dealing or availability and follow the current AMLO report, exemption and release route.
When is a personal-data breach notified?+
Notify the PDPC without delay and, where feasible, within 72 hours when the breach is likely to create risk; notify affected persons without delay when high risk is likely, subject to the statutory exceptions.
Is Thailand on a FATF public list?+
No. Thailand was absent from both FATF public lists dated 19 June 2026. It is an APG member; absence from a public list is not a low-risk finding.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 26 September 2026. English materials do not replace controlling Thai-language instruments. Confirm the reporting-person perimeter, current AMLO forms and electronic route, sector thresholds, licensing, sanctions directions, registry filings and PDPA transfer rules with the competent authority and qualified Thai counsel before launch.