Penetration testing under Bank of Thailand requirements
The Bank of Thailand defines security testing duties across several regulations, from the penetration testing guideline and iPentest to Mobile Banking and e-Money requirements. This page summarizes each one with links to the source documents.
What to consider when planning testing against BOT requirements
Confirm the institution's licence category and applicable notices first, then connect VA and penetration-testing activity to risk, change, and remediation evidence.

- For entities in scope, SorNorChor 1/2564 clause 5.1.6 describes risk-based vulnerability assessment at least annually and after significant changes.
- Penetration testing of public-network-connected applications and networks should be performed by appropriately independent specialists under the notice applicable to the institution.
- Mobile Banking, iPentest, and e-Money have different control contexts, so scope must follow the actual service rather than reuse one testing cadence for every system.
- Retain reports, remediation plans, and retest results linked to risk owners and change approval so evidence is auditable.
BANK OF THAILAND / ELECTRONIC MONEY
Bank of Thailand: e-Money and security testing
Notification SorNorChor 7/2561 identifies e-money control points that should become business-logic test cases; it is not a universal penetration-testing schedule for every operator.

- First confirm that the service and licence type fall within the electronic-money rules under the Payment Systems Act.
- Turn limits, balances, registration, loss reports, refunds, expiry, and transfers into test cases such as bypassing limits, duplicate refunds, or use after suspension.
- SorNorChor 7/2561 does not directly prescribe a VA or Penetration Testing cadence, so scope must be matched to the IT-risk or Cyber Hygiene rules actually applicable to the operator.
Before concluding which requirement applies, Compliance should confirm the licence, service significance, and the latest BOT notification.
BANK OF THAILAND / MOBILE BANKING
Bank of Thailand: Mobile Banking Security — BOT Circular 1218/2568 / Notification 4/2568
The notification sets minimum controls for financial institutions providing Mobile Banking, separating unauthorised-payment-fraud prevention from Mobile Banking security controls.

- It applies to financial institutions under the Financial Institution Business Act, and defines Mobile Banking as app-based mobile services that offer withdrawal, transfer, or payment.
- Test fraud-impersonation controls together with step-up authentication for risky actions, transaction limits, and the response to fake apps or malware.
- Test data, application, and device security together: encryption, tamper protection, session security, necessary permissions, and handling of rooted, jailbroken, or remote-controlled devices.
The notification is a Mobile Banking control baseline; it does not set an independent Penetration Testing cadence. Apply it with the organisation's governing IT-risk requirements.
BANK OF THAILAND / INTELLIGENCE-LED TESTING
Bank of Thailand: iPentest — Circular 1252/2562
iPentest uses threat intelligence to build realistic scenarios and determine whether a bank's protection, detection, and response processes work together.

- Establish governance, owners, and tester-selection criteria before setting a scenario, so test risk has a clear decision path.
- Use threat intelligence to scope critical functions, people, and protect, detect, and respond processes instead of only enumerating technical vulnerabilities.
- Production testing can provide realism, while high-risk steps may move to UAT or pre-production when the rationale, scope, and impact are recorded.
The 2019 circular was addressed to commercial banks. Confirm its current status and risk-based applicability with Compliance and the regulator before starting an engagement.
BANK OF THAILAND / CYBER HYGIENE
Bank of Thailand: VA and Penetration Testing — SorNorChor 1/2564
SorNorChor 1/2564 contains direct vulnerability-management and penetration-testing requirements for in-scope payment-system providers and operators.

- For entities in scope, assess vulnerabilities across all systems according to risk at least annually and after significant changes.
- Use independent specialists for Penetration Testing of applications and networks connected to public communications networks at least annually and after significant changes.
- Route results to accountable owners, remediation plans, and retest evidence so the organisation can demonstrate that discovered risk was handled, not merely reported.
The notification covers significant payment-system providers and regulated payment-system or payment-service businesses that are not financial institutions or specialised financial institutions. Confirm the organisation's status before applying a testing cadence.
