

Compliance Function and Oversight
SCBX’s Compliance function is overseen by the Chief Legal and Compliance Officer, who is the senior executive responsible for both Legal and Compliance functions and acts as the Head of Compliance for SCBX. This integrated leadership structure ensures a comprehensive strategic oversight, while maintaining appropriate independent oversight on compliance matters through a direct functional reporting line to the Audit Committee per the Bank of Thailand regulatory requirement. Notably, SCBX Group has not recorded any provisions for fines or settlements related to ESG issues in its audited accounts for the financial year 2025. Furthermore, SCBX Group has not incurred any fines or settlements exceeding US$100 million in the past three years (2023-2025). Therefore, the combined total value of fines or settlements over the period where each fine or settlement exceeded US$100 million is THB 0.
SCBX Group is steadfast in our commitment to conducting business with the highest standards of integrity and in full compliance with relevant international standards, laws, regulations, and regulatory requirements. The Group emphasize promoting knowledge and understanding among employees, ensuring accurate and consistent application through regular communication and training sessions. These include mandatory financial risk prevention programs for all employees across both headquarters and branch operations.
In 2025, SCBX Group continued to enhance workforce readiness for the digital era by strengthening skills and literacy. The AI Foundation program remained among the mandatory courses at SCBX Group to equip human capital to effectively and responsibly leverage AI technologies, alongside other foundational courses on governance.
Training on 8 mandatory courses
| Course | Percentage of employees completing the course in 2025 |
|---|---|
| Personal Data Protection Act | 99% |
| Cybersecurity Awareness | 98% |
| Anti-money Laundering and Counter Terrorist Financing |
98% |
| Code of Conduct | 98% |
| Operational Risk Management | 98% |
| SCB Safety First | 98% |
| Anti-corruption and Bribery | 98% |
| Market Conduct | 99% |
| AI Foundation | 99% |

Business Ethics
SCBX Group is committed to conducting business with integrity, transparency, and accountability toward all stakeholder groups. Upholding these principles, the Group requires all executives, directors, and employees to complete training, formally acknowledge, and strictly comply with the SCBX Financial Group Business Code of Conduct, as well as undergo a mandatory training session every year to reinforce understanding and ensure consistent application.
Furthermore, SCBX Group has extended the scope of good governance standards throughout the value chain by requiring all business partners to formally acknowledge and comply with the SCBX Group Supplier Code of Conduct prior to commencing work. This requirement ensures that suppliers’ business practices are aligned with SCBX Group’s sustainability principles and ethical standards.

Anti-corruption and Bribery
SCBX Group is steadfast in the commitment to conducting business with transparency and integrity, enforcing a zero-tolerance policy toward corruption and bribery and require all directors, executives, and employees to strictly comply with the SCBX Financial Group’s Anti-Corruption and Bribery Policy.
The Bank has been a declared member of Collective Action Coalition Against Corruption (CAC) since 2010 and became a certified member in 2017 to date. At the same time, the Bank continues to enforce a No Gift Policy to demonstrate the Bank’s commitment to transparent business conduct, adherence to the code of conduct, and compliance with the Anti-corruption and Bribery Policy.

Anti-Corruption and Anti-Bribery (ABC) Policy/Framework
We maintain a strict zero-tolerance approach toward all forms of corruption and bribery across our operations. This commitment is embedded in our Anti-Corruption and Anti-Bribery Policy, which establishes clear principles and expected behaviors for employees.
The Policy is readily accessible via the Company’s intranet and official website to ensure transparency and ease of reference. The content provides a comprehensive guidance on SCBX’s practices regarding ABC, including definitions and practical examples of bribery and corruption risks, such as gifts and entertainment, facilitation payments, political contributions, and improper inducements. It also clearly outlines roles and responsibilities across all levels of the organization to reinforce accountability in preventing, detecting, and responding to misconduct.
Communication and Awareness
We ensure that our anti-corruption expectations are consistently and comprehensively communicated to all employees and relevant stakeholders. The Policy is formally communicated through multiple channels, including employee onboarding programs, internal communication platforms, and periodic awareness campaigns.
We also reinforce awareness and understanding of anti-corruption and bribery practice through mandatory anti-corruption training for all employees, including new hires. This includes:
- Mandatory e-learning for all employees, required upon joining and annually thereafter
- Training content covering key risk areas, practical scenarios, and expected responses
- Continuous reinforcement through periodic awareness initiatives and targeted communications
These training programs are designed not only to ensure awareness but also to strengthen employees’ ability to identify, assess, and appropriately respond to corruption risks in their day-to-day responsibilities. Staff’s completion of training is monitored to ensure full coverage across the organization, and non-completion is followed up to maintain compliance. Moreover, staff are required to pass a test at the end of the ABC training with the score of 80% and above to complete the training.
(1) To address corruption in any operation of the organization, ABC risk would be assessed and tested per a risk-based approach per the compliance risk assessment framework. Rectification and preventive measures would be established and deployed to fix and safeguard the firm in countering any practices that may deem to be in violation of the ABC Policy/Framework.
(2) SCBX’s zero-tolerance stance on ABC extends beyond the organization. Business partners, suppliers, and vendors are required to adhere to our anti-corruption standards through contractual obligations. As to those suppliers of the Firm that have their own ABC Policy/Framework, their Policy/Framework must at least be consistent with SCBX’s.

Anti-money Laundering and Prevention
SCBX Group prioritize the prevention of the group’s businesses from being misused as a channels for money laundering, terrorism financing, or the proliferation of weapons of mass destruction. The Group has established comprehensive anti-money laundering and counter-terrorism financing policies and procedures—all of which are consistently communicated organizationwide to empower subsidiaries to develop and implement their own frameworks in alignment with Group-level guidelines. This approach ensures a uniform and effective standard of compliance with applicable laws, international standards, and business ethics, while strengthening the Group’s ability to prevent and mitigate risks to SCBX Group—particularly within the banking segment- from being associated with money laundering, terrorism financing, or proliferation-related activities.
The Group, through SCB, also continues to develop and improve internal systems and processes to keep up with the new operating context in the digital era and protect the Bank from being victimized by criminals or terrorists through money laundering or crimes involving the financing of terrorism or the proliferation of weapons of mass destruction. In addition, staff training is organized to continuously enhance their knowledge and understanding, such as by:
- Mandatory AML/CTF training for all employees
- Mandatory AML/CTF training for relevant personnel
- Training and refresher sessions by internal legal or compliance managers
- Training by external experts
Protecting Personal Data
SCBX Group recognizes that respect for ‘privacy’ is a fundamental human right and a cornerstone of trust in the digital economy. Therefore, the Group designates the protection of personal data as a key risk area, encompassing information technology, legal compliance, and reputational considerations. The Group adopt a group-wide risk management approach through Privacy Policy, governance mechanisms, and an effective risk management framework—to safeguard personal data and sustain the confidence of customers and stakeholders.


Governance of Data Privacy Protection
SCBX Group has established a governance structure for personal data protection that promotes active engagement across all organizational levels—from the Board of Directors to operational employees. The Board of Directors is responsible for formulating policies on personal data risk management and appointing the Risk Oversight Committee to supervise data protection practices across all entities. This ensures that all subsidiaries are equipped with appropriate policies, strategies, and controls to manage cyber risks and uphold comprehensive legal compliance in relation to personal data, both in terms of data utilization and governance. The Risk Management Committee is entrusted with overseeing the Group’s overall risk landscape through monitoring and governance processes. The Risk Office and Data Protection Officer are responsible for promoting best practices and reviewing business operations to ensure alignment with the Personal Data Protection Act B.E. 2562 (2019). Furthermore, SCBX Group has centralized data and AI expertise within SCB Data X Co. Ltd., which serves as the Group’s Center of Excellence on data. DataX plays a pivotal role in establishing best practices in data sharing, data governance, data analysis, and personal data protection across the SCBX ecosystem.
Data Privacy Protection and Management
SCBX Group has established comprehensive Personal Data Breach Management Guidelines to provide a consistent framework as a reference for preventing and responding to incidents across all subsidiaries. The Group also place strong emphasis on raising awareness among employees through regular training, communication, and internal engagement activities. Furthermore, SCBX Group instituted disciplinary measures to address violations or negligence that result in damage to customers’ personal data. In addition, SCBX Group has implemented internal processes to ensure that the collection, use, disclosure, and destruction of customers’ and employees’ data strictly comply with the Personal Data Protection Act (PDPA) and relevant regulations. The Group also monitors the use of personal data for secondary purposes, ensuring that such use is strictly within the scope of consent granted by customers and employees.


