Information Technology Risk Supervision

Information Technology Risk Supervision

The Bank of Thailand (BOT) places great importance on supervising information technology (IT) risk among service providers involved in payment systems, including payment system providers, payment system business providers, and payment service business providers. BOT aims to ensure that these entities can effectively manage IT risks with adequate safeguards, maintain security, and respond promptly to cyber threats. This approach is intended to help maintain the stability and resilience of the country’s payment systems, ensuring that the public can continue to use these services without interruption.

Financial technology has advanced rapidly, offering a wide range of financial services.

The volume and value of transactions conducted through mobile applications have increased significantly, and payment systems have experienced exponential growth over the past two to three years. IT now plays a critical role in business operations, serving as an essential infrastructure that enhances efficiency, reduces operational costs, and improves access to financial services. Therefore, IT risks require robust and effective supervision to foster public confidence in the convenience, safety, and stability of payment services.

Financial Security in IT aspect

Moreover, monitoring significant irregular activities that could affect the service provision or overall business operations of providers, causing enterprise-wide impact or widespread impact on the payment system to ensure that payment system-related service providers (e-Payment) uphold IT and cyber risk management standards that are on par with international benchmarks and are prepared to support the future growth in transaction volume and diverse financial services.

 In B.E. 2564 (2021), BOT also raised the standards for IT and cyber risk management for payment system-related service providers to meet international benchmarks.

This was done by issuing IT risk management measures and minimum cyber hygiene practices for payment system-related service providers to implement.

Financial Security in IT aspect