July 15, 2026
.png)
Thailand is taking another major step toward aligning its digital asset regulatory framework with international AML standards. The Securities and Exchange Commission (SEC), together with the Anti-Money Laundering Office (AMLO), has launched a public consultation on the implementation of the Travel Rule for digital asset businesses.
If adopted, the new framework will significantly affect licensed exchanges, brokers, dealers, custodians, and other digital asset operators by introducing mandatory information-sharing requirements, enhanced wallet verification, and new risk-management obligations.
The introduction of the Travel Rule represents another significant step in Thailand's efforts to strengthen the regulatory framework for digital assets and align it with internationally recognised anti-money laundering (AML) standards.
According to the Securities and Exchange Commission (SEC) of Thailand, the proposed framework has been developed in cooperation with the Anti-Money Laundering Office (AMLO) following a resolution of the Subcommittee on Financial Data Connectivity for Enhancing the Monitoring of Suspicious Financial Transactions. The initiative aims to establish a risk management framework that requires digital asset business operators to ensure that relevant information accompanies every digital asset transfer, thereby improving transaction monitoring and preventing the misuse of digital assets in technology-related crimes.
The SEC further explains that the proposed rules are intended to ensure that digital asset business operators possess sufficient information to assess and manage money laundering risks, strengthen the ability to trace digital asset transactions, prevent the use of digital asset services as a channel for money laundering and cybercrime, and bring Thailand's regulatory framework into line with international standards.
From a business perspective, the proposal goes beyond introducing a new compliance obligation. It reflects Thailand's broader objective of building a more transparent, internationally compatible digital asset ecosystem capable of supporting cross-border cooperation, increasing market confidence and facilitating relationships with foreign virtual asset service providers (VASPs). As more jurisdictions implement the FATF Travel Rule, compliance with equivalent standards is increasingly becoming a prerequisite for maintaining international business relationships and accessing global digital asset markets.
The proposed framework will not apply to all participants in the cryptocurrency market. According to the SEC's proposal, the Travel Rule requirements will apply to digital asset business operators that send or receive digital assets on behalf of their customers.
This category includes, among others:
The SEC further emphasises that digital asset business operators must establish and implement appropriate internal risk management policies and procedures for digital asset transfers. These measures include collecting and transmitting the required customer information, conducting due diligence on counterparties and digital asset service providers, and verifying ownership or control of self-hosted wallets from which digital assets are transferred or to which they are received. In addition, operators will be required to retain transfer-related records for at least five years, with the records being readily accessible for regulatory inspection during the first two years.
From a business perspective, the implementation of the Travel Rule extends far beyond introducing a technical requirement to exchange transaction data. Licensed operators will need to review and update their AML policies and procedures, customer onboarding processes, counterparty and wallet verification practices, transaction monitoring controls, and internal risk management frameworks to ensure full compliance with the new regulatory requirements.
One of the core elements of the proposed Travel Rule framework is the obligation for digital asset business operators to ensure that specified information accompanies qualifying digital asset transfers. According to the SEC, this information is intended to enable operators to verify transactions, manage money-laundering risks, enhance transaction traceability, and prevent the misuse of digital assets for money laundering, terrorist financing, and technology-related crime.
Under the proposed rules, an ordering digital asset business operator must transmit the digital asset transfer order together with the relevant transaction information to the beneficiary digital asset business operator. The transmitted information must include details relating to both the originator and the beneficiary of the transfer.
For the person initiating the transfer, operators will generally be required to collect and, where applicable, transmit information such as:
For the recipient of the transfer, operators will likewise be required to collect and transmit information, including:
Beyond transmitting customer information, the SEC also proposes that digital asset business operators implement comprehensive risk management measures governing both outgoing and incoming digital asset transfers. These measures include collecting customer and counterparty information for AML purposes, verifying counterparties where required, maintaining appropriate controls over transfer processes and retaining information accompanying digital asset transfers for at least five years.
From a practical perspective, these requirements mean that compliance with the Travel Rule will extend well beyond the technical exchange of customer information between service providers. Digital asset business operators will need to integrate data collection, customer due diligence, counterparty verification, transaction monitoring, and record-keeping into a single operational framework that supports regulatory compliance throughout the lifecycle of every qualifying digital asset transfer.
One of the key messages of the SEC's proposal is that the Travel Rule should not be viewed merely as an obligation to transmit customer information during digital asset transfers. Instead, the proposed framework requires digital asset business operators to establish a comprehensive risk management system governing both outgoing and incoming digital asset transfers.
The SEC proposes that every digital asset business operator establish documented policies and operating procedures specifically addressing the management of risks associated with the transfer and receipt of digital assets. These policies should define how Travel Rule requirements are implemented in practice, allocate responsibilities within the organisation and ensure that compliance measures are applied consistently across all relevant business activities.
The proposed framework requires operators to implement risk management measures that support AML verification throughout the lifecycle of a digital asset transfer. This includes collecting information about customers and their counterparties, assessing the risks associated with each transfer, and ensuring that sufficient information is available to identify potentially suspicious activity. According to the SEC, these measures are intended to strengthen operators' ability to manage money-laundering risks while supporting the prevention of cybercrime and terrorist financing.
A significant new obligation concerns the verification of counterparties involved in digital asset transfers. Operators will be required to verify the qualifications of the counterparty's digital asset business operator or digital asset service provider (VASP) before processing qualifying transfers. When intermediary operators participate in the transfer chain, their qualifications must also be verified, and additional measures must be implemented to ensure that the transaction route can be continuously and fully monitored.
The SEC also places particular emphasis on transaction monitoring. By requiring information to accompany every qualifying transfer, operators should be able to trace the origin and destination of digital assets, identify unusual transaction patterns and support ongoing monitoring of digital asset movements. This information forms part of the operator's broader AML risk management framework rather than serving solely as a reporting requirement.
The proposed rules require operators to retain information accompanying every digital asset transfer for at least five years. Furthermore, during the first two years, such records must be maintained in a manner that allows the supervisory authority to retrieve or examine them immediately upon request. These requirements are intended to facilitate regulatory supervision, investigations and audit activities.
Although the draft notification does not expressly prescribe a separate employee training programme, the requirement to establish formal policies, operating procedures and an effective risk management system necessarily implies that operators must ensure their personnel understand and consistently apply the new requirements. In practice, implementing the Travel Rule will require organisations to update internal controls, assign clear compliance responsibilities, and ensure that operational staff are capable of performing customer due diligence, counterparty verification, wallet verification, and transaction monitoring in accordance with the new regulatory framework.
From a business perspective, the proposed framework demonstrates that the Travel Rule is intended to become an integral part of an operator's overall AML compliance programme. Compliance will therefore require not only technical solutions for transmitting customer information, but also comprehensive governance, documented procedures, effective risk management, operational controls and ongoing oversight of digital asset transfers.
The proposed Travel Rule framework marks one of the most significant regulatory developments for Thailand's digital asset sector in recent years. Rather than introducing a standalone reporting obligation, the SEC is proposing a comprehensive framework that integrates customer due diligence, transaction monitoring, counterparty verification, record-keeping and risk management into a single compliance model aligned with international AML standards.
For digital asset business operators, implementation will require considerably more than a technical solution for exchanging customer information. Businesses should expect to review and update their AML policies and procedures, enhance KYC and onboarding processes, establish mechanisms for verifying counterparties and self-hosted wallets, strengthen transaction monitoring systems and ensure that internal governance and record-keeping practices comply with the new regulatory expectations.
Although these changes will inevitably increase compliance costs and operational complexity, they are also expected to strengthen the credibility of Thailand's digital asset market. Alignment with the FATF Travel Rule will facilitate cooperation with foreign Virtual Asset Service Providers (VASPs), support relationships with financial institutions and demonstrate that Thai licensed operators maintain AML controls consistent with internationally recognised standards.
Businesses that begin preparing during the consultation period will be in a stronger position to implement the new requirements efficiently once the rules enter into force, while also reducing implementation risks and maintaining uninterrupted access to domestic and cross-border digital asset markets.
Stay updated with the latest market insights, legal guides, and networking opportunities within the Thai-Ukrainian business corridor.
Website: thaiukraine.org
Email: info@thaiukraine.org
LinkedIn: Thai-Ukrainian Chamber of Commerce