Siam Thanat Hack Co., Ltd.

Penetration testing under Bank of Thailand requirements

The Bank of Thailand defines security testing duties across several regulations, from the penetration testing guideline and iPentest to Mobile Banking and e-Money requirements. This page summarizes each one with links to the source documents.

What to consider when planning testing against BOT requirements

Confirm the institution's licence category and applicable notices first, then connect VA and penetration-testing activity to risk, change, and remediation evidence.

Thai infographic explaining: What to consider when planning testing against BOT requirements
Visual summary: What to consider when planning testing against BOT requirements
  • For entities in scope, SorNorChor 1/2564 clause 5.1.6 describes risk-based vulnerability assessment at least annually and after significant changes.
  • Penetration testing of public-network-connected applications and networks should be performed by appropriately independent specialists under the notice applicable to the institution.
  • Mobile Banking, iPentest, and e-Money have different control contexts, so scope must follow the actual service rather than reuse one testing cadence for every system.
  • Retain reports, remediation plans, and retest results linked to risk owners and change approval so evidence is auditable.

BANK OF THAILAND / ELECTRONIC MONEY

Bank of Thailand: e-Money and security testing

Notification SorNorChor 7/2561 identifies e-money control points that should become business-logic test cases; it is not a universal penetration-testing schedule for every operator.

Infographic explaining e-money security testing from limits and registration through refunds and transfer controls
Visual summary: turn e-money transaction flows into business-logic and abuse-case tests
  • First confirm that the service and licence type fall within the electronic-money rules under the Payment Systems Act.
  • Turn limits, balances, registration, loss reports, refunds, expiry, and transfers into test cases such as bypassing limits, duplicate refunds, or use after suspension.
  • SorNorChor 7/2561 does not directly prescribe a VA or Penetration Testing cadence, so scope must be matched to the IT-risk or Cyber Hygiene rules actually applicable to the operator.
Match the correct rule to scope

Before concluding which requirement applies, Compliance should confirm the licence, service significance, and the latest BOT notification.

BANK OF THAILAND / MOBILE BANKING

Bank of Thailand: Mobile Banking Security — BOT Circular 1218/2568 / Notification 4/2568

The notification sets minimum controls for financial institutions providing Mobile Banking, separating unauthorised-payment-fraud prevention from Mobile Banking security controls.

Infographic explaining Mobile Banking security from a customer and mobile app through API and bank systems
Visual summary: scope the Mobile App, API, authentication, and transaction as one service
  • It applies to financial institutions under the Financial Institution Business Act, and defines Mobile Banking as app-based mobile services that offer withdrawal, transfer, or payment.
  • Test fraud-impersonation controls together with step-up authentication for risky actions, transaction limits, and the response to fake apps or malware.
  • Test data, application, and device security together: encryption, tamper protection, session security, necessary permissions, and handling of rooted, jailbroken, or remote-controlled devices.
Match the correct rule to scope

The notification is a Mobile Banking control baseline; it does not set an independent Penetration Testing cadence. Apply it with the organisation's governing IT-risk requirements.

BANK OF THAILAND / INTELLIGENCE-LED TESTING

Bank of Thailand: iPentest — Circular 1252/2562

iPentest uses threat intelligence to build realistic scenarios and determine whether a bank's protection, detection, and response processes work together.

Infographic explaining the iPentest cycle from threat intelligence and scenarios through risk controls and remediation
Visual summary: iPentest gives evidence of Protect, Detect, and Respond within a controlled scope
  • Establish governance, owners, and tester-selection criteria before setting a scenario, so test risk has a clear decision path.
  • Use threat intelligence to scope critical functions, people, and protect, detect, and respond processes instead of only enumerating technical vulnerabilities.
  • Production testing can provide realism, while high-risk steps may move to UAT or pre-production when the rationale, scope, and impact are recorded.
Match the correct rule to scope

The 2019 circular was addressed to commercial banks. Confirm its current status and risk-based applicability with Compliance and the regulator before starting an engagement.

BANK OF THAILAND / CYBER HYGIENE

Bank of Thailand: VA and Penetration Testing — SorNorChor 1/2564

SorNorChor 1/2564 contains direct vulnerability-management and penetration-testing requirements for in-scope payment-system providers and operators.

Infographic explaining the VA and Penetration Testing cycle from risk ranking through assessment, testing, remediation and reporting
Visual summary: connect assets, risk, independent expertise, remediation, and retesting
  • For entities in scope, assess vulnerabilities across all systems according to risk at least annually and after significant changes.
  • Use independent specialists for Penetration Testing of applications and networks connected to public communications networks at least annually and after significant changes.
  • Route results to accountable owners, remediation plans, and retest evidence so the organisation can demonstrate that discovered risk was handled, not merely reported.
Match the correct rule to scope

The notification covers significant payment-system providers and regulated payment-system or payment-service businesses that are not financial institutions or specialised financial institutions. Confirm the organisation's status before applying a testing cadence.

Official source documents

Original files from the regulating authorities, hosted on sth.sh for convenience. Always defer to the latest version at the source link.

First-page preview ofIT risk supervision guideline requiring VA and penetration testing (SorNorChor 1/2564)

IT risk supervision guideline requiring VA and penetration testing (SorNorChor 1/2564)

By Bank of Thailand

Open document (PDF) Source

First-page preview ofMobile Banking security guideline (BOT Circular 1218/2568 / Notification 4/2568)

Mobile Banking security guideline (BOT Circular 1218/2568 / Notification 4/2568)

By Bank of Thailand

Open document (PDF) Source

First-page preview ofIntelligence-led penetration testing guideline (iPentest, Circular 1252/2562)

Intelligence-led penetration testing guideline (iPentest, Circular 1252/2562)

By Bank of Thailand

Open document (PDF) Source

First-page preview ofBiometric technology guideline, B.E. 2566 (2023)

Biometric technology guideline, B.E. 2566 (2023)

By Bank of Thailand

Open document (PDF) Source