Thailand's SEC issued its Travel Rule for Digital Assets on September 2, 2026, developed with AMLO as an interim measure while AMLO finalizes its own rules under the Anti-Money Laundering Act. It applies to all licensed digital asset operators. Compliance deadline: February 27, 2027.
What’s required
- Written risk management policies for digital asset transfers, not folded into general AML procedures.
- Counterparty due diligence on every transfer: verify the receiving VASP, any intermediary VASP in the route, and ownership/control for self-hosted wallets.
- Originator/beneficiary data transmission with every transfer order, which is the standard FATF Recommendation 16 obligation.
- Five-year retention, retrievable on regulator request.
Why it matters for your team
- Six months is a short timeline. The deadline is 18 months out from the notification date, but really under six months from this announcement. If you’re still evaluating vendors, start now.
- Self-hosted wallet verification is the hard part. It requires actual technical verification (signature challenges, etc.), which means pulling in engineering early.
- Treat this as the initial version. AMLO’s permanent rules are still coming. Whatever you build should be flexible enough to absorb changes, not hard-coded to this notification.
- Check your counterparty coverage now. If key counterparty VASPs can’t yet exchange Travel Rule data, that’s a gap worth flagging before it becomes a blocker at go-live.
Where TRISA Envoy Fits In
None of this is unique to Thailand. It’s the same problem every Travel Rule jurisdiction creates: identify counterparty VASPs, exchange originator/beneficiary data reliably, and keep a clean audit trail, without slowing down transfers. TRISA Envoy is open source, so your compliance and engineering teams can inspect exactly how counterparty data is handled rather than trusting a closed black box. It’s built for direct VASP-to-VASP exchange, with no intermediary holding or routing your customer data. Messages are encrypted end-to-end between counterparties, and because it’s self-hosted, you keep control over where data lives and how long it’s retained, which matters when you’re already committing to five-year retention under Thai law. It’s also flexible enough to adapt as AMLO’s permanent rules take shape, instead of locking you into one regulator’s version of the requirements.
Source: https://www.sec.or.th/EN/Pages/News_Detail.aspx?SECID=13277
