ADVERTISEMENT
Supervision & Enforcement
01:48 AM 30th July 2026 GMT+00:00
Thai Banks Caught Between Industrialised Crime and Hardening Supervision
Analysis by Manesh Samtani
ADVERTISEMENT
Thai banks are being squeezed by the challenges of industrial-scale criminal enterprises and a wave of aggressive new regulatory demands.
Thailand’s banks are facing a structural squeeze, caught between criminal networks that are industrialising at scale across Southeast Asia, and regulators who are significantly raising supervisory expectations. Between these pressures sit financial institutions that are grappling with the burden of legacy systems, internal silos, a one-way flow of regulatory demands, and a talent model not built for this pace of change.
That tension defined a recent closed-door roundtable in Bangkok, where senior financial crime leaders described a threat environment that is evolving faster than their institutional architecture, and regulatory expectations that are hardening just as rapidly.
The session, hosted by Regulation Asia and SymphonyAI, brought together senior bankers to discuss how the industry is responding to criminal ecosystems that now operate with the coordination, scale and efficiency of legitimate corporate enterprises.
Crime at ecosystem scale
Kristina Amerhauser, Head of the Mekong Observatory at the Global Initiative against Transnational Organized Crime (GI-TOC), framed the scale of the challenge.
Financial crime in the region, she said, has become embedded in cross-border economic flows. Scam syndicates operate as coordinated networks, layering fraud, human trafficking, corruption and money laundering into integrated business models.
“The fraud transfers are one type of transfer that we're tracking within the financial industry, but there are many more transfers that we can track,” Amerhauser said, pointing to payments for human smuggling, bribes to officials and operational expenses for scam compounds.
The exposure extends well beyond banks. Transportation, construction and utilities can all become unwitting enablers of these ecosystems, she explained.
Ryan Winch, Transnational Crime and Technology Programme Manager for the Regional Support Office of the Bali Process (RSO), highlighted the human dimension behind the numbers. He described organised groups “building out criminal cities”, such as KK Park in Myanmar, where tens of thousands of trafficked individuals are forced to run scam operations.
These networks coordinate openly on Telegram, where channels facilitate the buying and selling of Thai citizens’ personal data and even trafficked individuals. The scale and organisation of these operations have shifted the problem from episodic fraud to industrialised crime, Winch said.
“This is about people being tortured, abused, confined for months and years on end, held for ransom.” Emphasising the banking industry’s role, Winch said, “If the money laundering is not able to succeed, the profit motive for these operations rapidly diminishes.”
A regulator moving faster
Against this backdrop, Thai regulators are tightening expectations. Participants described a marked shift over the past year in the posture of the Bank of Thailand (BOT), which has adopted a significantly more assertive approach to supervisory engagement.
The dynamic stands in contrast to other jurisdictions in the region, such as Indonesia, where roundtable participants noted there was 'very little push by the regulator', leaving banks feeling they 'had to do it alone'.
“Since last year, BOT has changed its roles and expectations,” said a former Anti-Money Laundering Office (AMLO) official now leading the financial crime division at one of the participating banks. “They are making more and more requests. The requirements from the BOT are even more stringent than those from AMLO.”
Account freeze obligations that once ran in days are now compressed into hours under new technology crime rules. Meanwhile, reporting requirements have expanded. Participants said the BOT is increasingly requesting STR-like submissions and advocating for a “COSMIC-style” information-sharing platform inspired by the Singapore model.
Some in the industry described the approach as aggressive. One senior compliance leader called it “too much” and “too aggressive”, citing overlapping obligations and unclear jurisdictional boundaries.
Participants questioned the effectiveness of this top-down pressure, pointing to a lack of a functional feedback loop. Banks are being asked to provide more data, faster, but receive little in return on how that information is used or whether it leads to better outcomes.
Even when intelligence is shared back to the banks, its utility can be limited. One participant noted that information received from regulators can be “super high level”, making it “quite burdensome for our investigators” to act on. There are also questions about mandate clarity. AMLO remains Thailand’s primary financial intelligence unit, but is focused on asset freezes and victim restitution. Several participants suggested this has created a perceived supervisory gap, with the central bank moving to fill a space not traditionally within its remit.
The regulatory response, in short, is accelerating, and banks are struggling to keep pace.
Internal fragmentation under pressure
Even as criminal networks are industrialising and scaling up, and regulators are toughening their approach to financial crime, many banks remain structurally fragmented. Fraud and AML functions continue to operate separately, with very little coordination.
Fraud typically sits under risk management, and AML under compliance. While joint committees do exist for the purpose of facilitating collaboration, day-to-day workflows remain siloed. A compliance head at a large domestic bank said attempts to unify these functions face cultural and structural resistance.
There are also skills gaps, the participants explained. Compliance professionals tend to have legal backgrounds. However, modern analytics requires data scientists and engineers. Yet, attracting and retaining technical talent remains difficult.
Data scientists are often reluctant to work in highly regulated environments constrained by procedural controls, one senior banker said. “They don't want to scope themselves down to just focusing on rules and regulatory requirements. It’s hard to get the right people to the job we need them to do.”
A technology arms race, with limits
Technology upgrades are underway, but they are slow. “Certain technology upgrade projects, including tuning your transaction monitoring system, take years,” one investigations head said.
Legacy KYC systems were also cited as a recurring weakness. One executive described their institution’s platform as “quite obsolete, to be honest... an internally developed, very aged system.”
For Thai subsidiaries of international banks, upgrades require approval at the group level, which often has different timelines and priorities. “One size doesn't fit all,” said a participant from an overseas bank operating locally. “If the group says no, nothing can happen in Thailand, making it difficult to respond nimbly to urgent local regulatory demands.
Artificial intelligence (AI) presents both an opportunity and threat. Winch noted that AI can generate convincing fake passports in minutes, to be used to bypass a bank’s KYC checks. At the same time, banks see AI as essential to handling rising case volumes. Yet implementation remains tentative.
Investigators often trust “their own eyes and not AI”, said a regional AML officer, citing concerns about hallucinations. Manual processes persist – including reviewing handwritten police reports that AI tools struggle to interpret.
Amber Zhang, AML Consultant at SymphonyAI, said most enterprise AI projects fail because data teams do not understand compliance business logic. According to Zhang, the solution lies in building a unified “compliance data layer” and adopting subject-centric investigation platforms that integrate data across silos.
“You must have a platform that will be able to ingest all the data, all the expertise from anywhere,” she said. AI agents, she added, can automate workflows, map networks and draft STR narratives, provided a human remains in the loop.
The bankers at the roundtable expressed a desire to speed up and scale up projects that leverage AI, but it was clear these initiatives were being held up by factors out of their control.
A structural squeeze
The discussion revealed an industry under pressure from both sides – criminal networks that are coordinating at scale and regenerating quickly when disrupted; and regulators that are compressing deadlines yet demanding visible results, often without a clear feedback loop to demonstrate the impact of these efforts.
Banks are working to upgrade legacy systems, reconcile internal silos and compete for scarce resources and technical talent, all while operating under escalating scrutiny. To keep up, the banks are prioritising work to automate manual processes, sharpen alert quality and build more holistic views of risk.
But the deeper challenge is speed. Criminal networks are moving faster. Supervisors are moving faster. The question is whether bank structures, systems, teams, and decision-making processes can keep pace. Incremental upgrades may not suffice. Matching industrialised crime and accelerated supervision will require organisational change, not just new tools.
--
This article was produced by Regulation Asia in collaboration with SymphonyAI, which provides AI-native financial crime compliance and risk management solutions for financial institutions.
Read SymphonyAI's leader’s guide and learn how to transform financial crime compliance from reactive operations into an always-on, intelligence-led advantage.





