BANGKOK, THAILAND – Thailand’s banks tightened digital transfer limits in 2026, forcing many customers to use face scans and branch visits for payments above 50,000 baht.
Hospital bills collide with new transfer cap
At the start of 2026, patients in Thai hospitals who tried to settle bills of around 120,000 baht via app often found their transfers blocked at 50,000 baht. What appeared to be a technical fault turned out to be a deliberate security measure affecting customers of Krungsri Bank and other institutions.
In Thailand, medical bills were typically paid after treatment, but a new digital barrier now stopped immediate payments once they exceeded the standard threshold. The money remained in the account, yet access via app was throttled to prevent larger outflows without extra checks.
Regulatory 50,000-baht threshold for digital payments
The 50,000-baht limit, roughly 1,370 euros, was set as a regulatory benchmark for most digital transactions nationwide in 2026. It marked the point at which a simple PIN authorisation ended and mandatory biometric verification by the bank began.
Once a single transfer or the sum of all daily payments hit that level, the system automatically blocked further payments. The intention was to ensure that high-value sums could not leave an account without additional identity verification.
Central bank order to tighten surveillance
Behind the stricter controls stood the Bank of Thailand (BOT) as the country’s central bank. It had issued broad anti–financial crime guidelines the previous year, which banks were now rolling out across the board.
Banks were required by law to monitor customer accounts more closely and adjust transaction limits dynamically. The BOT aimed to make Thailand’s financial sector safer by placing technical hurdles in front of rapid transfers to anonymous accounts.
Tool against call centre scams and online fraud
Thailand had long fought sophisticated fraud networks, often operating via call centres and pushing victims to send large sums quickly. A low standard limit of 50,000 baht served as a barrier, depriving criminals of the ability to empty accounts in a single step.
By capping daily losses unless a biometric release took place, the system bought valuable time. It gave victims and bank security teams a better chance to spot suspicious transfers, block them and freeze accounts before more damage occurred.
Why older customers face stricter rules
Data from Thai authorities indicated that people over 65 were particularly targeted by online fraudsters. The Bank of Thailand therefore treated seniors as a group in special need of protection, prompting banks to configure app security algorithms more conservatively for them.
Many older customers experienced frequent limit cuts as a restriction, but banks described them as a digital seat belt. These protections could be adjusted case by case once the account holder had proven their identity beyond doubt.
Outpatient visits rarely hit the limit
In Thailand’s health system, a clear distinction was made between outpatient and inpatient care. Ordinary doctor visits were paid after consultation, but such bills rarely breached the 50,000-baht line, so many users barely noticed the new rules in that segment.
By contrast, inpatient stays and planned surgery often generated six-figure invoices. In private hospitals, deposits or credit card pre-authorisations at admission were common, and patients without a verified profile now quickly ran into the app’s technical ceiling.
Private clinics demand large deposits
Many well-known private clinics requested advance payments for major procedures, especially from patients without Thai social security or direct-billing insurance. These deposits frequently ranged between 20 and 50 percent of estimated total costs.
If an operation was priced at 300,000 baht, the deposit alone far exceeded the new standard limit, and missing biometric activation in the banking app could delay treatment. Customers were therefore advised to coordinate such payments with their bank in advance.
Biometrics at the core of new security model
A central element of the new architecture was the collection of biometric data, above all facial recognition embedded directly in mobile banking apps. Only clients who had registered their face scan with the bank could authorise transfers above the 50,000-baht standard limit.
The technology offered stronger protection than passwords, which could be spied out or guessed, while biometric traits were unique. Banks tied each biometric profile firmly to both the mobile device and the customer’s account to maximise identity security for every transaction.
Face scan becomes mandatory for large transfers
From 2026, the face scan was no longer an optional feature but a technical requirement for high-value transfers. When users entered an amount above the threshold, the app automatically activated the smartphone’s front camera for biometric confirmation.
If the scan failed or no biometric data were stored, the transaction was immediately cancelled. The face scan thus became a modern replacement for the handwritten signature, shielding users from unauthorised high-value transfers via a misused device.
Why app sliders stop at 50,000 baht
Limit management ran through the settings of mobile banking apps such as Krungsri’s KMA. Customers could see a slider for their daily transfer frame, but it only moved beyond 50,000 baht once identity verification had been completed.
Many tried unsuccessfully to raise the ceiling themselves and were blocked by system rules because the app required in-branch verification before accepting higher amounts. After that one-off administrative step, the digital lock was lifted and limits could be raised flexibly up to two million baht.
Branch visit required for higher limits
In 2026, anyone stuck at the 50,000-baht cap and needing more had to visit a bank branch in person. Activation by call centre or by simply uploading documents through the app was no longer allowed for security reasons.
The visit enabled staff to capture biometric data securely, comparing the customer’s face with their identity document and storing the profile in encrypted form. This process was usually needed only once and paved the way for unrestricted future app use.
‘Dip-chip’ passport checks at the counter
A key detail in-branch was the so-called “Dip-Chip” procedure, where a passport or Thai ID card was inserted into a special reader. The device pulled data directly from the document’s microchip, preventing typing errors and helping to block fake IDs.
For foreign customers this meant that the original passport was mandatory, as even certified copies were not accepted. During the process, the bank’s system communicated with immigration databases to verify the validity of the passport and visa in real time.
Passport and phone needed for enrolment
Customers who wanted to adjust their limits at a Krungsri Bank branch had to bring their current passport in original form. It was the only document accepted for biometric registration of non-Thai nationals, who also had to ensure that entry stamps and validity were up to date.
Staff additionally required the smartphone with the installed and registered banking app to link the biometric profile to the device. Once this match was confirmed, the user could immediately set a higher daily limit in the app for future payments.
Older phones risk permanent low caps
The new security functions also depended on capable hardware, including a quality camera and a recent operating system. Older phones without current security updates were often no longer supported by banks.
If a device failed biometric checks, the app did not allow face verification and the account effectively remained capped at 50,000 baht. Customers using outdated technology then had to visit branches and process larger payments at the counter.
Customers can dial limits up and down
Once biometric registration was completed, the Krungsri app offered considerable flexibility. Customers could temporarily raise their daily limit, for example to 500,000 baht for a major purchase, and then immediately reduce it back to the protective standard.
Each increase in the limit required a new face scan, making abuse by third parties highly unlikely. Security-conscious users were encouraged to keep low everyday limits while opening their digital vault only when strictly necessary.
Crackdown on mule accounts
A major objective of the Bank of Thailand was the elimination of “mule accounts” used to launder stolen funds. Criminals often bought accounts from low-income individuals, but these holders could not simply appear for face scans in branches on demand.
The 50,000-baht cap therefore rendered such accounts largely useless for large-scale transfers. The rule put heavy pressure on the black market for banking credentials and, by limiting flows through straw men, reinforced the integrity of Thailand’s financial system.
Stricter than many European standards
Many European customers viewed Thailand’s banking rules as unusually strict. While simple passwords or SMS codes still played a central role in places like Germany, Thai institutions relied consistently on biometrics in light of a higher cybercrime volume in Southeast Asia.
The country’s banks were seen as advanced in fraud prevention, even if onboarding felt cumbersome. Those who complied with the system benefited from a level of protection for digital assets that, according to the article, exceeded typical European standards.
Advice: enrol biometrics before an emergency
Customers were urged not to postpone biometric registration until facing an emergency such as bail or a sudden hospital bill. In such cases, there was often no time for a branch visit before a high-value transfer became necessary.
Readers were encouraged to check their app settings and visit a Krungsri branch if attempts to raise limits above 50,000 baht triggered error messages. Early verification, the article concluded, provided calm and security for future financial transactions under Thailand’s tightened 2026 rules.
