Thailand - AI Risk Management Guidelines

Bank of Thailand Draft Policy on Risk Management of the Use of Artificial Intelligence Systems (Financial Sector AI Risk Guidelines)

Thailand

RAI-TH-NA-BTDRMXX-2025
Draft(Being written or scoped)
GuidelineGovernance and OversightRisk Management
Export PDF

The Bank of Thailand (BOT) published a draft 'Guiding Principles for Artificial Intelligence Risk Management' for consultation from 12 June to 30 June 2025. The draft sets out risk-based expectations for financial service providers on governance, lifecycle risk management, data quality, model testing (including generative AI), cybersecurity, vendor management and consumer protections aligned with FEAT (fairness, ethics, accountability, transparency) principles.

Summary

In June 2025 the Bank of Thailand released a draft policy titled Guiding Principles for Artificial Intelligence Risk Management aimed at financial service providers regulated under the Financial Institutions Business Act and payment-service providers under the Payment Systems Act. The draft (published for public consultation 12–30 June 2025) supplements existing BOT guidance on IT risk management, third-party risk management, data governance and market conduct by setting AI-specific expectations. The draft defines AI broadly to include machine learning, deep learning, generative AI (including large language models) and agentic AI, while excluding rule-based automation such as RPA and condition-matching systems. It organises the guidance into two main parts: (1) governance and FEAT-aligned institutional arrangements and (2) development, testing, deployment and security controls for AI systems.

On governance, the draft requires boards and senior management to understand and accept responsibility for AI risks, adopt an organisational AI policy aligned with fairness, ethics, accountability and transparency (FEAT), ensure clear role definitions across the three lines of defence, and invest in awareness and training. The guidance emphasises lifecycle risk management: materiality and risk classification of AI use-cases; inventories and model registries; pre-deployment assurance; ongoing monitoring for performance drift and fairness; and defined rollback and escalation procedures.

On technical controls, the draft sets out requirements for data quality and provenance, validation and out-of-sample testing, edge-case and adversarial scenario testing, explainability/documentation, use-case-specific performance metrics (accuracy, reliability, robustness), and mitigations for generative AI (e.g., retrieval-augmented generation, output verification). Cybersecurity sections address AI-specific threats (prompt injection, model inversion, data poisoning, adversarial attacks) and require integration of AI model security into existing cyber resilience frameworks. Third-party management expectations require due diligence, contractual safeguards, audit rights and controls for cross-border data and model hosting.

Consumer protection features include customer disclosure where AI materially affects decisions, options to opt-out or request human review in certain customer-facing use cases, and mechanisms to detect and remedy unfair treatment or harms. The draft also requires comprehensive documentation and audit trails for models and decisions, retention of test records and model lineage to support supervisory review. While the draft sets supervisory expectations, it does not itself specify new statutory fines in the document; enforcement is expected to be through the BOT's supervisory powers and existing legal instruments. The BOT invited comments (via a public-hearing page and an attached draft PDF) and provided contact details for its IT risk supervisory unit. The principal public sources are the BOT public-hearing page and the draft PDF published on the BOT site.

Full article

Read full text ↗

Overview

The Bank of Thailand (BOT) published for public consultation a draft entitled Guiding Principles for Artificial Intelligence Risk Management on 12 June 2025 and invited comments through 30 June 2025. The draft is targeted at financial institutions and payment-service providers under BOT supervision and supplements existing guidance on information-technology risk, third-party risk, data governance and market conduct. It defines AI to include machine learning, deep learning, generative AI such as large language models (LLMs) and agentic AI, and explicitly excludes simple rule-based automation such as robotic process automation (RPA). The draft organises expectations across governance (board and senior management oversight, FEAT principles), lifecycle risk management (inventory, classification and testing), development and deployment controls (data quality, model validation and cybersecurity) and consumer protections (disclosure, human review). The original draft and public-hearing announcement are available on the BOT website: BOT public-hearing page (12 June 2025) and the full draft PDF: BOT draft PDF (Guiding Principles for AI Risk Management).

Definitions

The draft provides precise definitions that frame obligations and scope. "AI system" covers systems that emulate human intelligence to learn, memorise, decide, operate and generate new content by learning from data, including ML, DL, generative models (LLMs) and agentic systems. Excluded are RPA and pre-defined condition-matching automation. "Financial service provider" means banks, specialised financial institutions and payment-system providers under the Financial Institutions Business Act and the Payment Systems Act. The draft also defines three principal risk categories—data risk, model-development risk (including hallucination and opacity), and AI-specific cybersecurity threats (prompt injection, model inversion, data poisoning, adversarial attacks)—to guide downstream controls and testing requirements.

Governance and Institutional Framework

The BOT draft places primary accountability with boards and senior management: boards must ensure an AI usage policy aligned with organisational strategy and FEAT (fairness, ethics, accountability, transparency) principles, approve risk appetite for AI use-cases, and oversee implementation. Management must assign clear responsibilities across the three lines of defence, create an AI governance function or centre of excellence where appropriate, and ensure workforce training and awareness. The guidance expects comprehensive AI inventories (model registries), categorisation by materiality and risk, and periodic reporting to the board. Governance expectations include formal change-management controls, pre-deployment approvals, and documented human-in-the-loop arrangements for material customer-facing or high-impact decisions. For reference and submission of comments the BOT provided the public-hearing page and the supporting PDF: BOT public-hearing page and draft PDF.

Key Focus Areas

The draft outlines core focus areas for risk management across the AI lifecycle. First, data governance: institutions must assess and ensure data quality, provenance, freshness, representativeness and appropriate labeling; implement privacy-preserving measures and cross-border safeguards where data or models are hosted offshore. Second, model development and validation: define metrics (accuracy, reliability, fairness, robustness), conduct out-of-sample and adversarial tests, and validate models on holdout and real-world data including edge cases. Third, generative-AI mitigations: for LLMs and other generative systems, the draft requires controls to reduce hallucinations (e.g., retrieval-augmented generation, factuality checks, constrained prompts), output verification and traceability of supporting sources. Fourth, cybersecurity and model security: integrate defenses against prompt injection, model inversion and poisoning; apply access controls, secrets management, and robust monitoring. Fifth, third-party and vendor management: perform due diligence, require contractual audit rights, and maintain contingency plans. Sixth, transparency and consumer protection: disclose material AI use to affected customers, provide mechanisms for human review or opt-out where decisions materially affect customers, and monitor outcomes to detect discriminatory or unfair treatment.

Implementation Framework

The draft advises a pragmatic, risk-based implementation approach. Steps include: (1) inventorying AI systems and classifying them by impact and materiality; (2) defining AI policies and governance structures; (3) integrating AI risk controls into existing IT and model-risk frameworks (MLOps, documentation and audit trails); (4) establishing pre-deployment assurance (validation, bias and robustness testing, security assessment) and operational controls (monitoring, drift detection, retraining criteria); and (5) codifying incident response and rollback procedures. The BOT expects institutions to adopt measurable KPIs for model performance and safety, maintain versioned records (model lineage), and implement continuous monitoring and periodic independent reviews. The draft recommends that organisations align development pipelines with privacy and data-protection obligations under Thailand's PDPA and applicable contractual commitments to third-party providers.

Monitoring and Evaluation

Ongoing monitoring is emphasised as essential. The draft requires continuous performance monitoring against pre-defined metrics, drift detection, fairness and discrimination checks, and logging sufficient to support investigations and audits. Institutions should maintain metrics dashboards, alerting thresholds, and processes for rapid remediation and rollback. Periodic independent model reviews and stress-testing (including adversarial scenarios) are recommended. Supervisory reporting lines should be established for material incidents, and institutions should retain records of tests, validation results and governance approvals for supervisory inspection.

Penalties, Liability, and Appeals

The draft itself is framed as supervisory guidance and does not set out a new standalone schedule of monetary fines. Enforcement is expected to be through the BOT's existing supervisory powers and existing legal frameworks (e.g., Financial Institutions Business Act, Payment Systems Act, and data-protection law). The BOT may apply corrective measures, require remediation plans, restrict or suspend use of AI systems, and apply public supervisory actions where necessary. Liability for legal claims or consumer redress remains governed by existing civil and consumer-protection laws; institutions are required to maintain channels for redress and have procedures to investigate and remediate customer harms arising from AI-driven decisions. The draft indicates institutions should document appeals or human-review processes for customers affected by AI decisions.

Relationship to Other Instruments

The draft is explicitly intended to complement, not replace, existing BOT guidance on information-technology risk management, third-party risk management, data governance and market conduct. It should be read together with Thailand's Personal Data Protection Act (PDPA), the Financial Institutions Business Act, the Payment Systems Act, and other sectoral regulations. The BOT positions the guidance as a sector-specific articulation of internationally accepted principles and intends it to fit within existing supervisory frameworks so that institutions can leverage existing compliance processes and controls. The BOT public-hearing page contains links and contextual references to those frameworks: BOT public-hearing page.

International Alignment

The draft aligns with internationally recognised good practice for AI in finance: risk-based oversight, lifecycle controls, model validation and explainability expectations comparable to supervisory work by authorities such as the Monetary Authority of Singapore, the UK PRA/FCA, and selected guidance emerging from EU and US regulatory initiatives. The BOT highlights FEAT principles (fairness, ethics, accountability, transparency) and references global approaches to generative AI safety, model security and third-party governance to help Thai financial institutions apply internationally accepted controls while remaining proportionate to risk and institutional size.

Implementation Timeline

PhaseTimingKey Actions
Consultation12 Jun 2025–30 Jun 2025Public comments, industry feedback (BOT public-hearing).
FinalisationH2 2025 (expected)BOT considers feedback, issues final guidance or supervisory expectations.
Adoption2026–2027Institutions implement governance, inventories, testing and monitoring per risk-based timelines; BOT supervisory follow-up.
Ongoing2026 onwardsContinuous monitoring, audits, independent reviews and supervisory engagement.

Sources and References

SourceType
(Public hearing) BOT page: Draft Guiding Principles for AI Risk Management (12 Jun 2025)Primary Source
(PDF) BOT - Guiding Principles for Artificial Intelligence Risk Management (Draft)Primary Source
Tilleke & Gibbins summary: Thailand Drafts AI Risk Management Guidelines for Financial Service Providers (19 Jun 2025)Secondary Analysis

Requirements for a company

What an organisation has to do under Thailand - AI Risk Management Guidelines, at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Draft). These requirements apply once the instrument takes effect and may change before then.

Must do

12
  • Establish a board-approved AI usage policy aligned with FEAT principles.Financial service providers under BOT supervision.
  • Maintain a comprehensive inventory of AI systems and classify them by materiality and risk.Financial service providers under BOT supervision.
  • Conduct pre-deployment testing and validation, including out-of-sample and adversarial tests.Financial service providers using AI systems.
  • Implement controls to reduce hallucinations, verify output, and trace sources for generative AI systems.Financial service providers using generative AI systems.
  • Integrate defenses against AI-specific cybersecurity threats like prompt injection, model inversion, and data poisoning.Financial service providers using AI systems.
  • Disclose material AI use to customers and provide mechanisms for human review or opt-out for affected decisions.Financial service providers using customer-facing AI.
  • +6 more in the table below

Must not do

0

Nothing in this category.

Should do

1
  • Conduct periodic independent model reviews and stress-testing, including adversarial scenarios.Financial service providers using AI systems.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Thailand - AI Risk Management Guidelines, most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Financial service providers under BOT supervision.Establish a board-approved AI usage policy aligned with FEAT principles.
boards must ensure an AI usage policy aligned with organisational strategy and FEAT principles
By 2027Governance and Institutional FrameworkCritical
2Financial service providers under BOT supervision.Maintain a comprehensive inventory of AI systems and classify them by materiality and risk.
The guidance expects comprehensive AI inventories (model registries), categorisation by materiality and risk
By 2027Governance and Institutional FrameworkCritical
3Financial service providers using AI systems.Conduct pre-deployment testing and validation, including out-of-sample and adversarial tests.
conduct out-of-sample and adversarial tests, and validate models on holdout and real-world data
Before deploymentKey Focus AreasCritical
4Financial service providers using generative AI systems.Implement controls to reduce hallucinations, verify output, and trace sources for generative AI systems.
the draft requires controls to reduce hallucinations (e.g., retrieval-augmented generation, factuality checks, constrained prompts), output verification and traceability of supporting sources
Before deploymentKey Focus AreasCritical
5Financial service providers using AI systems.Integrate defenses against AI-specific cybersecurity threats like prompt injection, model inversion, and data poisoning.
integrate defenses against prompt injection, model inversion and poisoning; apply access controls, secrets management, and robust monitoring
Before deploymentKey Focus AreasCritical
6Financial service providers using customer-facing AI.Disclose material AI use to customers and provide mechanisms for human review or opt-out for affected decisions.
disclose material AI use to affected customers, provide mechanisms for human review or opt-out where decisions materially affect customers
Before deploymentKey Focus AreasCritical
7Financial service providers using AI systems.Assess and ensure data quality, provenance, freshness, representativeness, and appropriate labeling for AI systems.
institutions must assess and ensure data quality, provenance, freshness, representativeness and appropriate labeling
Before deploymentKey Focus AreasCritical
8Financial service providers using third-party AI.Perform due diligence on third-party AI vendors, require contractual audit rights, and maintain contingency plans.
perform due diligence, require contractual audit rights, and maintain contingency plans
Before engaging third-party AIKey Focus AreasImportant
9Financial service providers under BOT supervision.Assign clear responsibilities for AI risk management across the three lines of defence.
Management must assign clear responsibilities across the three lines of defence
By 2027Governance and Institutional FrameworkImportant
10Financial service providers using AI systems.Codify incident response and rollback procedures for AI systems.
codifying incident response and rollback procedures.
By 2027Implementation FrameworkImportant
11Financial service providers using AI systems.Implement continuous monitoring for performance, drift detection, fairness, and discrimination checks.
continuous performance monitoring against pre-defined metrics, drift detection, fairness and discrimination checks
Upon deploymentMonitoring and EvaluationImportant
12Financial service providers using AI systems.Maintain versioned records of model lineage, tests, validation results, and governance approvals.
maintain versioned records (model lineage)
Upon deploymentImplementation FrameworkImportant
13Financial service providers using AI systems.Conduct periodic independent model reviews and stress-testing, including adversarial scenarios.
Periodic independent model reviews and stress-testing (including adversarial scenarios) are recommended.
OngoingMonitoring and EvaluationRecommended

© Regulations.AI · updated on 13-Jun-2026