Thailand’s Securities and Exchange Commission (SEC) opened a public consultation on 26 June 2026 on a draft notification that would formally introduce the Travel Rule for Digital Assets, a framework requiring licensed digital asset operators to collect, transmit, and retain counterparty information for every transfer they process.
The consultation follows an earlier round of stakeholder engagement in March and April 2026, the results of which were broadly supportive, and reflects the SEC’s ongoing efforts to align Thailand’s digital asset regulatory framework with international anti-money laundering (AML) standards.
What is the Travel Rule?
The Travel Rule takes its name from FATF Recommendation 16, which has long required traditional financial institutions to pass originator and beneficiary information alongside wire transfers. FATF extended this requirement to virtual asset service providers (VASPs) as part of its updated standards, and Thailand’s proposed framework represents its formal implementation within the digital asset sector.
The draft notification arises from coordinated action between the SEC and the Anti-Money Laundering Office (AMLO). A sub-committee on financial data integration, established to improve monitoring of suspicious transactions, resolved that the two agencies should issue joint guidance for digital asset operators while AMLO prepares longer-term rules under the Anti-Money Laundering Act. Working together, the SEC and AMLO developed risk management standards requiring operators to attach identifying information to all digital asset transfers, supporting law enforcement’s ability to trace and disrupt technology-enabled financial crime.
The SEC has stated that the framework is intended to strengthen Thailand’s capacity to monitor digital asset transaction flows, prevent the use of digital assets in technology-enabled crime, and reduce the risk that licensed operators are used as conduits for money laundering or terrorist financing without imposing disproportionate compliance costs on the industry.
Alignment with FATF standards also carries commercial implications: operators in jurisdictions with established Travel Rule regimes are increasingly required to confirm that their counterparty service providers meet equivalent standards before transacting. Compliance may therefore affect the ability of Thai operators to access and maintain international business relationships.
Following the March–April 2026 consultation, in which stakeholder feedback was broadly supportive, the SEC revised the framework for clarity and proportionality. The current consultation presents the resulting draft notification for formal comment.
Key Obligations Under the Proposed Rules
The draft notification imposes obligations across three areas:
Policies, Procedures, and Record-Keeping
All digital asset operators must establish internal policies and operational procedures governing the risk management of digital asset transfers. This means identifying information on both the transferring customer and their counterparty, verifying the status and qualifications of the counterparty’s service provider, and, where a transfer involves an un-hosted wallet, verifying ownership or control of that wallet before processing the transaction.
Transaction records must also be retained for a minimum of five years. For the first two years of that period, records must be maintained in a format that permits immediate access and review by the relevant regulatory authority.
Obligations of the Ordering Operator
Where an operator is acting as the Ordering Digital Asset Operator, that is, the entity initiating the transfer on behalf of its customer, it must transmit the required originator and beneficiary information to the Beneficiary Digital Asset Operator alongside the transfer instruction. Where an Intermediary Digital Asset Operator forms part of the transfer chain, the ordering operator must also verify that intermediary’s qualifications and take additional steps as prescribed to ensure the transaction trail remains complete and traceable throughout.
Obligations of the Beneficiary Operator
Operators receiving digital asset transfers must have risk management measures in place to collect and verify the required originator and beneficiary information, whether the transfer originates from another operator or from a customer directly.
Self-Hosted Wallets
Transfers involving self-hosted wallets, wallets held and controlled directly by the user outside of a custodial service, attract specific obligations under the proposed rules. Operators must verify that the customer owns or controls the relevant wallet before a transfer is processed. Given the technical and operational considerations involved, operators should assess whether their current onboarding and transaction monitoring infrastructure is capable of meeting this requirement in practice.
What This Means for Operators Now
It is important to note that the Travel Rule for Digital Assets remains at the consultation stage. The draft notification is not yet law, and the framework may be subject to further revision before it is formally enacted.
That said, the Travel Rule is not a new concept. It reflects FATF standards that have been implemented across numerous jurisdictions, and the obligations it proposes are broadly consistent with what international counterparties and correspondent service providers already expect of compliant VASPs.
Operators are therefore well advised to treat the proposed framework as sound compliance practice regardless of its current legislative status. Building the requisite policies, data collection workflows, and record-keeping infrastructure ahead of enactment reduces implementation risk and positions operators favourably for regulatory scrutiny when the rules do come into force.
Operators can therefore start by:
- Assessing current KYC/AML procedures, transaction monitoring systems, and record-keeping infrastructure against the proposed requirements, with particular attention to self-hosted wallet handling and data retention timelines.
- Considering whether existing technology solutions are capable of collecting and transmitting the required originator and beneficiary data in real time alongside transfer instructions.
- Treating compliance with the Travel Rule framework as a baseline standard of operational practice, irrespective of the timeline for formal enactment.
For legal advice on digital asset regulatory compliance, AML/CFT obligations, or any other matters in Thailand’s digital asset sector, please contact our Technology, Crypto, and Web3 team at [email protected].
This article is provided for general information purposes only and does not constitute legal advice. While care has been taken to ensure accuracy at the time of writing, laws and regulatory instruments may change. Specific advice should be sought for individual circumstances.
