Licensing of payment systems and E-Money

September 25, 2026

Thailand is one of Southeast Asia's most powerful financial hubs, with a highly developed digital payment infrastructure (particularly thanks to the national PromptPay system). For Ukrainian fintech startups, payment gateway developers, and neobanks, entering this market opens access to a multi-million-strong, solvent audience.

‍

However, entering the market requires a flawless understanding of the local regulatory landscape, which is distinguished by strict requirements for capitalization and corporate governance.

‍

Regulatory foundation

‍

Until 2017, financial technology regulation in Thailand was fragmented and relied on disparate decrees, but the rapid growth of e-commerce and mobile payments forced the government to radically change its approach by adopting a single foundational document: the Payment Systems Act B.E. 2560. This law introduced a clear two-tier market-access architecture, where the Bank of Thailand (BOT) serves as the main supervisory, auditing, and operational body.

‍

BOT compliance officers and IT auditors conduct deep due diligence on the business model, verify the security architecture, and assess financial capacity. However, the BOT acts as a strict filter, while the final political and legal decision on issuing a license (Designated Payment Services License) is made by the Minister of Finance of Thailand. This dual system means the applicant must satisfy both the Central Bank's strict technocrats and the national interests of the relevant ministry.

‍

The Thai regulator does not use universal licenses, instead strictly tying authorization levels to the type of financial services, where the main barrier to entry and indicator of the seriousness of intentions is the size of the fully paid-up capital (Paid-up Capital). The regulator requires these funds to be physically deposited into the company's accounts before operations begin, ensuring the provider's financial stability.

‍

Depending on the business model, E-Money requires the highest level of trust and risk, with a capital requirement of at least 100 million Thai baht (about $2.7 million). This is the "Holy Grail" for fintechs planning to build ecosystems, super-apps (like GrabPay, TrueMoney, or the Ukrainian monobank), or issue prepaid cards for converting fiat into a digital balance (Open-loop systems). Because the provider accumulates public deposits, the company must have substantial own liquidity to cover operating expenses without touching segregated client funds.

‍

The next level is acquiring, which processes mass payments and requires 50 million THB (about $1.4 million) in capital. The acquirer acts as a bridge between merchants and global networks (Visa, Mastercard, JCB, or local PromptPay), does not store funds long-term, and bears direct financial responsibility for chargebacks and timely clearing.

‍

The best starting point for foreign startups is Payment Facilitating and Fund Transfer licenses with a threshold of 10 million THB (about $275,000). Payment Facilitators (PayFacs) are ideal for SaaS platforms and marketplaces, consolidating payments of small sellers under a single master account, while a Remittances license allows transit cross-border movement of fiat without creating e-wallets, making this model an excellent test drive of the market before scaling to full-fledged E-Money.

‍

Rounding out the infrastructure-level architecture are Payment System Operators - settlement system operators, clearing houses, and interbank switches with capital from 50 to 200 million THB. However, consortiums of the largest national banks build this level to serve the country's macroeconomy, and it is usually impractical for classic fintech startups.

‍

Corporate requirements and protection of client funds

‍

A company must be properly incorporated as a Thai juristic person to obtain a payment services license. Unlike many offshore or liberal European jurisdictions that allow companies to exploit financial licenses through foreign branches or permit fully remote corporate governance, the Thai regulator takes a conservative approach.

‍

The Bank of Thailand (BOT) imposes a strict, non-negotiable requirement for local management presence: a financial institution's board of directors must include at least one director of Thai nationality who holds permanent resident status in the Kingdom.

‍

This requirement is driven not by protectionism, but by national financial security and accountability. For supervisory authorities, it is critically important to have a physically accessible official who bears personal, and in some cases criminal, responsibility for violating compliance policies, money laundering, or misuse of client assets.

‍

Accordingly, such a local director cannot be an exclusively nominal figure on paper to satisfy bureaucratic requirements - they must possess real managerial powers, have access to internal financial reporting, and directly participate in communication with the regulator.

‍

Besides strict corporate governance, a fundamental pillar of Thai fintech regulation is the architecture of protecting Client Funds. It is built on the principle of absolute asset isolation to prevent bankruptcies and financial pyramids. E-Money issuers and payment facilitators must deposit all advance user payments into special segregated (trust) accounts opened exclusively in licensed commercial banks in Thailand.

‍

The law categorically requires separating these funds from the company's own working capital, which is used to pay salaries, marketing, software development, or office rent.

‍

Segregated user funds are inviolable: they are strictly forbidden to be used to credit other clients, hedge risks, invest, or cover the platform's current cash gaps. The Bank of Thailand requires 100% liquidity provision, which means a simple mathematical equality - the actual fiat balance in the segregated bank account can never be less than the sum of all outstanding electronic obligations to users in the system.

‍

To guarantee citizens' unhindered access to their own finances, the legislation sets a strict operational limit (SLA): the company must fulfill any lawful, verified user request to withdraw, transfer, or refund funds within a maximum of fifteen days. In practice, BOT audits closely monitor whether payment providers perform daily balance reconciliation and maintain flawless liquidity infrastructure to meet clients' financial needs instantly.

‍

AML and cybersecurity

‍

Modern Thai fintech requires not only significant financial capital but also a flawless technological infrastructure, which has become especially critical amid global cyber threats. The Bank of Thailand sets ultimate requirements for the information security of payment systems, effectively equating them to conservative banking standards.

‍

A basic condition for obtaining and maintaining a license is certification of the architecture to international information security management standards ISO/IEC 27001 and the payment card industry's PCI DSS. However, certificates alone are not enough: platforms must implement a complex ecosystem for real-time transaction monitoring, capable of automatically detecting anomalies and blocking suspicious behavioral patterns before clearing is completed.

‍

In addition, in daily client interactions, reliable multi-factor authentication (2FA), including biometric verification and dynamic passwords, has become not just a technical recommendation but a strict regulatory imperative to protect against unauthorized access to e-wallets.

‍

Alongside technological cybersecurity, the industry's biggest challenge has been the unprecedented strengthening of the compliance regime and anti-money laundering (AML) rules. In June 2026, the relevant Bank of Thailand Notification No. 25/2569 came into force, which radically changed the landscape of financial risk management in the Kingdom. This regulatory step became a direct and harsh response by the government to the rapid growth in the scale of financial fraud, in particular, the massive use of so-called "mule accounts" - fictitious profiles opened in the name of frontmen exclusively for the transit of stolen or illegally obtained funds.

‍

The regulator realized that traditional identification procedures can no longer stop organized criminal syndicates, so it shifted the focus from collecting formal documents to continuously and proactively analyzing client behavior throughout the account lifecycle.

‍

Under the new guidelines, payment providers must build an internal corporate governance structure based on the classic institutional "three lines of defense" model. The first line is the operational unit that directly interacts with clients (front office) and conducts initial screening. The second line consists of independent compliance and risk management officers who develop policies, analyze complex cases, and oversee the first line.

‍

The third line must necessarily be an independent internal or external audit that regularly tests the effectiveness of the company's security architecture. Within this model, fintech projects must apply Enhanced Due Diligence (EDD) mechanisms to any users or transactions that algorithms assign to high-risk groups, meticulously studying the sources of origin of their funds and the logical economic sense of financial operations.

‍

The most revolutionary and, at the same time, the most difficult-to-implement requirement of Notification No. 25/2569 was the delegation to private fintech companies of powers that were previously inherent mainly to law enforcement agencies.

‍

From now on, licensed payment providers not only have the right but are legally obliged to immediately stop transactions, limit functionality, or completely close accounts at the slightest suspicion of a client's involvement in fraudulent schemes or the use of their profile as a transit "mule." Companies can no longer wait for an official court order or a request from the police to block suspicious activity. The Bank of Thailand views delays or ignored "red flags" as complicity or gross negligence, which can trigger multi-million fines and irrevocable license revocation.

‍

Licensing procedure

‍

Obtaining a license in Thailand is not just a formal submission of papers, but a complex, multi-level marathon that requires flawless legal and technical structuring even before official contact with supervisory authorities.

‍

The procedure inevitably begins with a Pre-Approval stage, initiated by completing a detailed self-assessment questionnaire. Next comes a critical stage: a mandatory preliminary meeting with representatives of the Bank of Thailand (BOT), during which founders and key management must personally defend their business model, prove its financial viability, and present the IT architecture's resilience in detail. This meeting serves as a strict filter, allowing the regulator to screen out unprepared projects at the conception stage, saving resources for both parties and directing the applicant in the right legal direction.

‍

Only after successfully passing the initial consultations and approving all drafts does the company receive the green light to submit the final, 100% complete package of documents. From the moment the application is officially accepted, a regulated clock starts: the law allows exactly 60 business days to decide on full-fledged payment licenses, or 30 days for narrower categories of registration or specialized services.

‍

However, founders should distinguish between declared bureaucratic deadlines and realistic project launch timelines. In practice, the Thai authorization system takes much longer because of extensive parallel checks. The process necessarily includes a meticulous background audit of founders by the Anti-Money Laundering Office (AMLO), independent stress tests for IT systems, and multiple iterations of reconciling financial plans. That is why the full cycle from the start of document collection to the physical receipt of the license usually takes about 6–9 months.

‍

The final chord of this marathon is the long-awaited receipt of the official approval letter signed by the Ministry of Finance. However, even this prestigious document does not automatically open doors to clients.

‍

Being in the status of an approved licensee, the company is obliged to successfully pass the final hurdle - a Readiness Audit, during which inspectors verify whether the deployed infrastructure matches the promises that were declared on paper. After receiving an approval letter from the Ministry of Finance, the company must pass this readiness audit and begin operations within one year. The regulator set this strict deadline to combat so-called "shelf" companies: if the business does not launch on time, the license is automatically canceled, making it impossible to obtain Thai financial authorization solely to resell the project.

‍

Entering the Thai payment market is strategically complex, where the price of a mistake is measured in years of lost time and blocked capital. Successful integration into this ecosystem requires flawless business structuring aligned with the Bank of Thailand's conservative requirements, deep expertise in preparing internal compliance policies that reflect the latest regulatory notifications, and professional dialogue with supervisory authorities.

‍

Only this comprehensive approach to legal, technical, and financial planning can overcome bureaucratic barriers, ensure the unhindered opening of the necessary corporate and segregated bank accounts, and turn a startup into a full-fledged player in one of the most liquid and dynamic fintech markets in Southeast Asia.

‍

Connect with TUCC

‍

Stay updated with the latest market insights, legal guides, and networking opportunities within the Thai-Ukrainian business corridor.

‍

Website: thaiukraine.org

‍

Email: info@thaiukraine.org

‍

LinkedIn: Thai-Ukrainian Chamber of Commerce

Tags:

startups

e-commerce

trade

digital innovations