
Travel Rule to Take Effect in Thailand in February 2027
The Securities and Exchange Commission (SEC) of Thailand published on 31 August Notification of the Office of the SEC No. Sor Thor. 9/2569, establishing formal risk management mandates for the transfer and receipt of digital assets, including the implementation of the Travel Rule. Following extensive rounds of public consultation, the new regulation will come to force on 27 February 2027 giving in-scope Digital Assets Business Operators (VASPs) 180 days to get ready for the launch.
For VASPs licensed in Thailand, the Notification replaces interim practices with mandatory operational requirements governing counterparty due diligence, automated data exchange, and unhosted wallet risk management. The Notification aligns closely requirements set out under the Financial Action Task Force Recommendation 16:
1. Key Scope & Information Tiering
The Notification draws a wide scope of VA-activities and provides for de minimis approach regarding the data requirements:
● Regulatory Scope: Scope includes operators managing cryptographic keys directly or via delegates, proprietary asset transfers, fund managers, and digital asset advisers with transfer authority.
● De Minimis Threshold (< THB 30,000, about USD 900): VASPs must collect and transmit originator and beneficiary names, wallet addresses, and account numbers (or unique transaction references).
● Standard Tier (≥ THB 30,000): Transfers require full attributes, including originator physical address, date of birth (for natural persons), beneficiary country/city, and government-issued identification numbers or Legal Entity Identifiers (LEI) for juristic persons.
● Data Transmission Timing: Data must be submitted immediately—either prior to or simultaneously with the transfer instruction (except for direct interactions with self-hosted wallets, of which ownership should be verified for transactions above the de minimis threshold).
● Record Retention: Records must be retained for at least 5 years and be immediately available for regulatory inspection.
2. Counterparty & Wallet Controls
The Notification draws a strict operational boundary between hosted VASPs and self-hosted wallets:
● Hosted VASP Transfers: Ordering operators must conduct risk-appropriate analytics prior to broadcast. Hosted counterparties must be operating legally in their home jurisdiction, and not located in FATF “blacklist” jurisdictions. Analytics must confirm the counterparty does not utilise obfuscation technology to sever the transfer path.
● Intermediary VASPs: Netting or batching transfers does not dilute data obligations. Intermediary operators must qualify downstream rails and ensure full underlying data accompanies the transaction.
● Self-Hosted Wallets: For transactions equal to or exceeding THB 30,000, operators are required to verify ownership or control of the self-hosted wallet before sending or crediting funds.
3. Inbound Flow & Pre-Transaction Compliance
On receipt, Chapter 4 of the Notification mandates complete processing before granting beneficiary access:
● Incomplete Data Handling: Missing data from an self-hosted wallet transfer presents a hard block. Incomplete Travel Rule payloads from hosted VASPs require documented risk measures and immediate follow-up before crediting the asset to the beneficiary.
● Sanctions Screening: Immediate screening is mandatory against local enforcement lists, including Thailand’s technology-crime list and designated persons under CFT/PF frameworks.
Operational Readiness: The Four Core Capabilities
Implementation, rather than policy design, is now the challenge facing Thai VASPs. While South Korea just strengthened its requirement to scrap the de minimis threshold and Thailand maintains its THB 30,000 tier, VASPs in both markets join their global peers in countering operational challenges: maintaining audit-ready, real-time flows across nested rails and self-hosted environments.
To achieve compliance ahead of February 2027, VASPs require four foundational capabilities:
● Automated VASP Discovery & Due Diligence: Instantly identifying counterparty regulatory status, even when the receiving jurisdiction faces a "Sunrise" implementation gap.
● Immediate & Secure Data Exchange: End to end encryption while transmitting PII pre-broadcast without introducing operational friction or manual processing delays.
● Unhosted Wallet Verification: Pre-determining wallet types via analytics and executing cryptographic proof-of-ownership for transfers at or above THB 30,000.
● Structured Exception Handling: Managing messaging failures, missing payloads, and client notifications programmatically without halting legitimate client activity.
How VerifyVASP Empowers Thai VASPs for Objective-based Compliance
VerifyVASP provides a verified-network, end-to-end compliance ecosystem engineered specifically to meet the high-throughput, secure demands of regulatory frameworks like Notification No. Sor Thor. 9/2569:

● Verified Alliance Network: Solves counterparty risk through strict onboarding due diligence (including KYB modelled after FATF Recommendation 10 and a comprehensive questionnaire adapted from the Wolfsberg Counterparty Due-Diligence Questionnaire for the Virtual Assets industry), decentralised enclave architecture, and real-time, end-to-end encrypted messaging.

● VerifyName: Enhanced risk mitigation measure of verified first party transfers where counterparty is non-obliged or presents as a higher risk during due-diligence, VerifyName eliminates "bad payload" holds and prevents misdirected transfers.
● VerifyWallet: Delivers seamless, secure ownership and control verification for unhosted wallets directly inside the VASP’s user interface, meeting Thailand's THB 30,000 verification mandate without compromising UX.
Empowering Thai VASPs for local and global requirements
VerifyVASP was architected for FATF alignment from the outset by the industry, for the industry, which is why we are able to meet international best standards as a natural consequence rather than a retrofit:
● Independent Big Four assessment of our responses to FATF's Travel Rule solution provider guiding questions (2023).
● SOC 2 Type II audit, renewed annually since our first assessment, now in its fourth consecutive year.
● Only GLEIF-accredited LEI Validation Agent for the virtual asset industry, supporting unique legal entity identification in line with EU and UK Travel Rule requirements and FATF's emphasis on legal-entity-level counterparty due diligence.
● Active standards participation through the ISO 20022 Payments and Technical Support Standards Evaluation Groups, working toward interoperable, FATF-aligned Travel Rule messaging globally.
● Scale validated in actual production: over USD 550 billion processed, 22 million-plus verifications, and 150+ member VASPs across 30+ jurisdictions, giving our FATF-alignment claims a production track record that is rare in this industry.
● Zero-incident record since 2019, underpinning both our AML/CFT assurances and our technology risk management posture under frameworks like Singapore's TRM Guidelines and the EU's DORA.
As the 180-day countdown starts ahead of the implementation deadline, VerifyVASP remains actively engaged with regulatory authorities and is committed to conducting local industry working groups in Thailand, supporting VASPs with technical integration, return-handling protocols, and nested transfer workflows to get ready for the 27 February 2027 due date.
If you would like to discuss how VerifyVASP can help your current or upcoming Thai-licensed VASPs meet the new Travel Rule requirements, please get in touch with our team.