Thai AI Governance Framework: BOT, ETDA, NCSA Guidelines and Technical AI Security Testing
Document 25680178 is a policy guideline for financial service providers to reference and apply according to their AI use. It is not a continuous penetration-testing mandate for all organizations.
- Target Audience
- Financial institutions, specialized financial institutions and regulated payment system or service operators within BOT scope, plus organizations adopting ETDA and NCSA guidance
- Mandatory Frequency
- Select testing and review cycles for risk, AI use and data or model changes, distinguishing guidance from binding obligations.
- Required Scope
- Data, model and cyber risks, GenAI governance, and the draft EIA assessment of eight principles across seven categories
- Non-Compliance Risk
- Data leakage, erroneous outputs, bias, drift and excessive tool permissions
BOT policy guideline Wor 5994/2568 and its scope
Document 25680178 is a policy guideline for financial service providers to reference and apply according to their AI use. It is not a continuous penetration-testing mandate for all organizations.

Check BOT policy scope, ETDA guidance including the draft EIA, and NCSA guidance before selecting risk-based assessment.
- BOT Wor 5994/2568 — Data, model and cyber risks
- ETDA guidance — GenAI and the draft EIA Playbook
- NCSA guidance — Security across the AI lifecycle
- Assess by risk — Test, remediate and verify
- The scope includes financial institutions, specialized financial institutions, and regulated payment system and payment service operators.
- The guideline identifies data risks, model-development risks and cyber threats, with management proportionate to the AI use case.
- Consider data quality and security, model testing, monitoring and third-party risks alongside the other applicable rules.
- Select technical tests and review cycles for actual risk and applicable obligations. This policy guideline does not itself establish a fixed testing cycle or a new penalty regime.
ETDA GenAI governance and the draft EIA Playbook
The 2024 GenAI Governance Guideline supports organizational governance. The referenced EIA Playbook remains marked as a draft dated 11 September 2026.
- Assess intended GenAI use, accountable roles, and data, output and operational risks before procurement and adoption.
- EIA references ten UNESCO ethical principles. Scoping addresses two, and principles-based assessment addresses the remaining eight across seven categories before impact mapping. It is not a four- or six-dimension framework.
- Categories cover safety, fairness, sustainability, privacy, human oversight, accountability, and a combined category for transparency and explainability with awareness and literacy.
- EIA evaluates socio-technical impacts and safeguards. It is not an AI penetration-test certificate, and a draft is not enacted law.
NCSA guidance for AI security across the lifecycle
Use NCSA guidance to support governance and security across the AI lifecycle. Check document scope and status before treating guidance as an organizational obligation.
- Identify accountable owners, assets, data and AI risks, including external integrations.
- Plan controls for data, models, deployed systems, monitoring and incident response for the organization context.
- Connect testing evidence to remediation, risk review and system changes. See the linked NCSA AI Security guide for source-specific detail.
Recommended AI penetration testing and red teaming
The following STH recommendations provide technical evidence to complement governance. They are not a common mandatory checklist imposed by all three agencies.
- For LLM applications, test direct and indirect prompt injection, disclosure boundaries and authorized tool use.
- For RAG, verify source-document authorization, tenant isolation and knowledge-base ingestion using synthetic data.
- Test accuracy, bias and drift for relevant use cases. Separate model-quality results from vulnerability and access-control findings.
- Define acceptance criteria, human oversight, safe stopping where needed and retesting. Accountable owners should decide using evidence and impact.
Requirements and Testing Scope Matrix
Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.
| Reference | Mandate Title | Scope Required | Testing Cycle |
|---|---|---|---|
| BOT policy guideline Wor 5994/2568 | BOT policy guideline Wor 5994/2568 and its scope | Document 25680178 is a policy guideline for financial service providers to reference and apply according to their AI use. It is not a continuous penetration-testing mandate for all organizations. | According to applicable scope and service risk, not a universal testing cycle |
| ETDA GenAI 2024 and draft EIA Playbook | ETDA GenAI governance and the draft EIA Playbook | The 2024 GenAI Governance Guideline supports organizational governance. The referenced EIA Playbook remains marked as a draft dated 11 September 2026. | According to applicable scope and service risk, not a universal testing cycle |
| NCSA AI Security Guidelines 2568 | NCSA guidance for AI security across the lifecycle | Use NCSA guidance to support governance and security across the AI lifecycle. Check document scope and status before treating guidance as an organizational obligation. | According to applicable scope and service risk, not a universal testing cycle |
| STH assessment recommendations | Recommended AI penetration testing and red teaming | The following STH recommendations provide technical evidence to complement governance. They are not a common mandatory checklist imposed by all three agencies. | According to applicable scope and service risk, not a universal testing cycle |
Compliance Readiness Self-Assessment
Select items your organization has completed to evaluate your readiness score.
Frequently Asked Questions (FAQ)
Key answers and practical guidance addressing common compliance questions.
Who is within BOT Wor 5994/2568 scope?
The scope includes financial institutions, specialized financial institutions, and regulated payment system and payment service operators. Document 25680178 is a policy guideline for financial service providers to reference and apply according to their AI use. It is not a continuous penetration-testing mandate for all organizations.
Is the EIA Playbook law or an AI penetration-test certificate?
EIA evaluates socio-technical impacts and safeguards. It is not an AI penetration-test certificate, and a draft is not enacted law. EIA references ten UNESCO ethical principles. Scoping addresses two, and principles-based assessment addresses the remaining eight across seven categories before impact mapping. It is not a four- or six-dimension framework.
How should third-party AI integrations be assessed?
For LLM applications, test direct and indirect prompt injection, disclosure boundaries and authorized tool use. For RAG, verify source-document authorization, tenant isolation and knowledge-base ingestion using synthetic data.
