Thailand’s Securities and Exchange Commission has issued a Travel Rule for digital assets that requires licensed operators to collect transfer information, check counterparties, and verify ownership or control of self-hosted wallets.
The 2 September 2026 announcement says the measures are meant to give operators enough information to assess money-laundering risk and to limit the use of digital asset services in technology-related crime. The rules take effect on 27 February 2027.
How the rule was developed
The SEC says the framework grew out of work with the Anti-Money Laundering Office after a subcommittee on financial data connectivity asked both agencies to issue interim requirements while AMLO prepares rules under the Anti-Money Laundering Act. Public hearings on the proposed principles ran from March to April 2026. Hearings on the draft notification ran from June to July 2026. The commission states that most stakeholders agreed with the principles and the draft.
The related legal instrument cited in the announcement is Notification of the Office of the Securities and Exchange Commission No. Sor Thor. 9/2026, dated 25 August 2026. That notice addresses risk-management measures for the transfer and receipt of digital assets. The later effective date, the SEC says, is intended to give operators time to build systems for sending, receiving, and monitoring transfer information.
Earlier consultation materials published by the SEC described the same policy direction: apply an information-accompaniment requirement to digital asset operators that send or receive customer assets, collect data on customers and counterparties, and keep records for monitoring. Those hearing papers also noted that the approach was developed jointly with AMLO.
Duties placed on digital asset operators
The issued Travel Rule lists four main duties. Operators must first put in place policies and operating procedures for managing risks linked to sending and receiving digital assets.
Second, they must collect information on customers and counterparties; conduct due diligence on counterparties; verify the qualifications of the counterparty virtual asset service provider and of any intermediary operator placed on the transfer route; and verify ownership of, or control over, self-hosted wallets when assets are sent to or received from those wallets.
Third, the ordering operator must transmit originator and beneficiary information together with the transfer order to the receiving operator. Fourth, information that accompanies every digital asset transaction must be retained for at least five years in a form that a supervisory authority can retrieve or examine promptly.
The June draft notice already set out the same core elements: risk policies, collection of customer and counterparty data, checks on counterparties and self-hosted wallets, transmission of originator and beneficiary data, and multi-year record-keeping. The September announcement presents those elements as final operator duties rather than as a proposal.
The text does not publish a technical manual for how firms must prove control of a self-hosted wallet. It states the obligation and leaves the operating method to the policies operators are required to adopt.
Stated aims and the self-hosted wallet requirement
SEC Secretary-General Pornanong Budsaratragoon said the commission has treated as a priority the risk that digital asset operators could be used as channels for money laundering and technology-related crime. In the official statement, she said the Travel Rule should improve the ability to counter those crimes, reduce misuse of operators, reinforce firms’ responsibility for customer transactions, and strengthen anti-money laundering measures in line with FATF standards. She also said the requirements are intended to support confidence in Thailand’s digital asset ecosystem and longer-term links with international markets.
The self-hosted wallet clause is the provision that extends checks beyond transfers between licensed platforms. When a customer sends assets to, or receives assets from, a wallet that the user controls, the operator must verify ownership or control of that wallet.
The SEC’s earlier hearing document framed the Travel Rule as a tool to follow digital asset movements that pass through licensed businesses. The final notice keeps that scope and adds the explicit self-hosted verification duty.
Parallel work on Bitcoin and Ethereum ETFs
The Travel Rule sits beside a separate product-development track. As reported on 24 August 2026, by The Crypto Times, the SEC opened public comments on draft rules for crypto ETFs in Thailand and on proposed qualifications for foreign digital-asset custodians used by funds.
After an April–May hearing in which most respondents supported the framework, the commission said a crypto ETF would have to be a passive fund managed by an asset management company, listed only on the Stock Exchange of Thailand, and keep average net exposure of at least 80 percent of NAV to a single crypto asset.
In the first stage, the eligible assets would be Bitcoin and Ethereum. Custody would stay mainly with onshore DA custodians, with qualified foreign custodians possible later if the SEC judges that necessary.
Taken together, the two files show different tools for the same market. The Travel Rule governs how licensed operators collect, send, and keep transfer data, including checks on self-hosted wallets.
The ETF draft would let regulated funds give investors listed exposure to Bitcoin and Ethereum under fund-custody and disclosure rules. One measure tightens the trail of assets moving through operators. The other tests a listed product that would keep assets with licensed custodians rather than in customer self-hosted wallets. Comments on the ETF papers close on 20 September 2026; the Travel Rule itself takes effect on 27 February 2027.
For now, the Thai financial watchdog’s announcement presents the rule as an interim SEC measure pending AMLO regulations. It does not ban self-hosted wallets. It requires licensed operators that interact with those wallets to collect information, complete specified checks, pass originator and beneficiary data with the order, and keep the file for five years from 27 February 2027.
Also read: HashKey Joins DTCC Working Group as First Asian Digital Asset Provider
