Thailand’s Securities and Exchange Commission has announced a crypto Travel Rule that will require regulated digital asset operators to collect counterparty information, verify control of self-hosted wallets and retain transfer records for at least five years.
The requirements take effect on February 27, 2027, giving exchanges and other covered operators nearly six months to prepare their data-sharing, due-diligence and transaction-monitoring systems. An underlying SEC notification is dated August 25, while the regulator publicly announced the final framework on September 2.
What covered operators must do
The framework applies to the transfer and receipt of digital assets by operators supervised in Thailand. Firms must establish policies and procedures for managing transfer-related risks and collect information about both their customers and the counterparties to a transaction.
Operators must also conduct due diligence on counterparties and verify the status of a counterparty virtual-asset service provider. Where an intermediary operator participates in the transfer route, that intermediary is included in the checks described by the SEC.
For outgoing transfers, the ordering operator must send originator and beneficiary information with the transfer instruction to the receiving counterparty provider. This moves the compliance obligation beyond keeping customer records internally: the required information must accompany the transaction between covered firms.
Self-hosted wallets create a separate verification step
Transfers involving self-hosted wallets receive explicit treatment. When a customer sends assets to, or receives assets from, such a wallet, the operator must verify ownership of or control over the wallet.
The SEC announcement does not prescribe a single technical method for that verification. Operators will therefore need to translate the obligation into documented controls that fit their risk models and customer journeys. The practical implementation could affect withdrawal and deposit workflows, but the final choice of verification methods should not be inferred from the announcement alone.
For payment platforms and wallet providers, that distinction matters. A transfer to another regulated provider can rely on institution-to-institution information exchange and counterparty checks. A transfer to a self-hosted address lacks that regulated counterparty, so the customer-facing proof of control becomes an additional compliance checkpoint.
Records must remain retrievable for five years
Covered firms must keep the information accompanying every digital asset transaction for at least five years. The records must be maintained in a form that allows the supervisory authority to retrieve or inspect them promptly.
That requirement has consequences for more than storage capacity. Operators will need reliable links among transfer messages, customer files, counterparty reviews and wallet-control evidence. They will also need retention and retrieval processes that preserve those links across system changes and vendor relationships.
Implementation follows two consultations
The final framework follows a consultation on its principles during March and April 2026 and a second consultation on draft rules during June and July. The SEC said most respondents supported the proposals.
The regulator developed the interim requirements in coordination with Thailand’s Anti-Money Laundering Office while that agency prepares rules under the Anti-Money Laundering Act. The SEC described the measures as part of efforts to reduce money-laundering, terrorist-financing and technology-related crime risks in digital asset services.
For firms serving Thai customers, the immediate task is a readiness assessment: map which transfers fall within the rules, identify where originator and beneficiary data must be exchanged, define how counterparty providers will be reviewed, and determine how self-hosted wallet control will be evidenced and retained. The February effective date makes these operational requirements a near-term compliance program rather than a policy proposal.