Compliance with Laws,
Regulations, and Procedure

Compliance with Laws,
Regulations, and
Procedure

Compliance Function and Oversight

SCBX’s Compliance function, under the leadership of the Chief Legal and Compliance Officer, plays a strategic role in maneuvering the overall compliance framework across the Group. By actively monitoring regulatory developments and constantly conducting a review as well as promoting consistent compliance practices across entities, the function helps safeguard the Group’s integrity and resilience to allow its business to continue to grow in a responsible and sustainable manner. Structured monthly reporting to the Audit Committee—a Board-level committee—ensures that emerging compliance risks are promptly escalated and addressed at the highest level, whereby this proactive governance mechanism serves as an important measure to mitigate potential non-compliance risks for the Group. Notably, SCBX Group has not incurred any fines or settlements exceeding US$100 million in the past three years (2022–2024).

SCBX Group is steadfast in our commitment to conducting business with the highest standards of integrity and in full compliance with relevant international standards, laws, regulations, and regulatory requirements. The Group emphasize promoting knowledge and understanding among employees, ensuring accurate and consistent application through regular communication and training sessions. These include mandatory financial risk prevention programs for all employees across both headquarters and branch operations.

In 2025, SCBX Group continued to enhance workforce readiness for the digital era by strengthening skills and literacy. The AI Foundation program remained among the mandatory courses at SCBX Group to equip human capital to effectively and responsibly leverage AI technologies, alongside other foundational courses on governance.

Training on 8 mandatory courses
Course Percentage of employees
completing the course in 2022
Personal Data Protection Act 99%
Cybersecurity Awareness 98%
Anti-money Laundering and Counter
Terrorist Financing
98%
Code of Conduct 98%
Operational Risk Management 98%
SCB Safety First 98%
Anti-corruption and Bribery 99%
Market Conduct 99%
AI Foundation+ : Prompt + 99%
Training on 8 mandatory courses
Course Percentage of employees
completing the course in 2022
Personal Data Protection Act 99 %
Cybersecurity Awareness 92 %
Anti-money Laundering and
Counter Terrorist Financing
95 %
Code of Conduct 91 %
Operational Risk Management 97 %
SCB Safety First 89 %
Anti-corruption and Bribery 91 %
Market Conduct 97 %

Business Ethics

SCBX Group is committed to conducting business with integrity, transparency, and accountability toward all stakeholder groups. Upholding these principles, the Group requires all executives, directors, and employees to complete training, formally acknowledge, and strictly comply with the SCBX Financial Group Business Code of Conduct, as well as undergo a mandatory training session every year to reinforce understanding and ensure consistent application.

Furthermore, SCBX Group has extended the scope of good governance standards throughout the value chain by requiring all business partners to formally acknowledge and comply with the SCBX Group Supplier Code of Conduct prior to commencing work. This requirement ensures that suppliers’ business practices are aligned with SCBX Group’s sustainability principles and ethical standards.

Anti-corruption and Bribery

SCBX Group is steadfast in the commitment to conducting business with transparency and integrity, enforcing a zero-tolerance policy toward corruption and bribery and require all directors, executives, and employees to strictly comply with the SCBX Financial Group’s Anti-Corruption and Bribery Policy.

The Bank has been a declared member of Collective Action Coalition Against Corruption (CAC) since 2010 and became a certified member in 2017 to date. At the same time, the Bank continues to enforce a No Gift Policy to demonstrate the Bank’s commitment to transparent business conduct, adherence to the code of conduct, and compliance with the Anti-corruption and Bribery Policy.

Anti-money Laundering and Prevention

SCBX Group prioritize the prevention of the group’s businesses from being misused as a channels for money laundering, terrorism financing, or the proliferation of weapons of mass destruction. The Group has established comprehensive anti-money laundering and counter-terrorism financing policies and procedures—all of which are consistently communicated organizationwide to empower subsidiaries to develop and implement their own frameworks in alignment with Group-level guidelines. This approach ensures a uniform and effective standard of compliance with applicable laws, international standards, and business ethics, while strengthening the Group’s ability to prevent and mitigate risks to SCBX Group—particularly within the banking segment- from being associated with money laundering, terrorism financing, or proliferation-related activities.

The Group, through SCB, also continues to develop and improve internal systems and processes to keep up with the new operating context in the digital era and protect the Bank from being victimized by criminals or terrorists through money laundering or crimes involving the financing of terrorism or the proliferation of weapons of mass destruction. In addition, staff training is organized to continuously enhance their knowledge and understanding, such as by:

  • Mandatory AML/CTF training for all employees
  • Mandatory AML/CTF training for relevant personnel
  • Training and refresher sessions by internal legal or compliance managers
  • Training by external experts

Protecting Personal Data

SCBX Group recognizes that respect for ‘privacy’ is a fundamental human right and a cornerstone of trust in the digital economy. Therefore, the Group designates the protection of personal data as a key risk area, encompassing information technology, legal compliance, and reputational considerations. The Group adopt a group-wide risk management approach through Privacy Policy, governance mechanisms, and an effective risk management framework—to safeguard personal data and sustain the confidence of customers and stakeholders.

Governance of Data Privacy Protection

SCBX Group has established a governance structure for personal data protection that promotes active engagement across all organizational levels—from the Board of Directors to operational employees. The Board of Directors is responsible for formulating policies on personal data risk management and appointing the Risk Oversight Committee to supervise data protection practices across all entities. This ensures that all subsidiaries are equipped with appropriate policies, strategies, and controls to manage cyber risks and uphold comprehensive legal compliance in relation to personal data, both in terms of data utilization and governance. The Risk Management Committee is entrusted with overseeing the Group’s overall risk landscape through monitoring and governance processes. The Risk Office and Data Protection Officer are responsible for promoting best practices and reviewing business operations to ensure alignment with the Personal Data Protection Act B.E. 2562 (2019). Furthermore, SCBX Group has centralized data and AI expertise within SCB Data X Co. Ltd., which serves as the Group’s Center of Excellence on data. DataX plays a pivotal role in establishing best practices in data sharing, data governance, data analysis, and personal data protection across the SCBX ecosystem.

Data Privacy Protection and Management

SCBX Group has established comprehensive Personal Data Breach Management Guidelines to provide a consistent framework as a reference for preventing and responding to incidents across all subsidiaries. The Group also place strong emphasis on raising awareness among employees through regular training, communication, and internal engagement activities. Furthermore, SCBX Group instituted disciplinary measures to address violations or negligence that result in damage to customers’ personal data. In addition, SCBX Group has implemented internal processes to ensure that the collection, use, disclosure, and destruction of customers’ and employees’ data strictly comply with the Personal Data Protection Act (PDPA) and relevant regulations. The Group also monitors the use of personal data for secondary purposes, ensuring that such use is strictly within the scope of consent granted by customers and employees.

Explore
Strengthened Foundation

ทำความรู้จัก รากฐานความยั่งยืนที่แข็งแรง

Explore
Strengthened
Foundation

ทำความรู้จัก รากฐานความยั่งยืน
ที่แข็งแรง

Explore
Strengthened Foundation

Get to know the strong foundation of sustainability

Explore
Strengthened
Foundation

Get to know the strong
foundation of sustainability

  • Corporate Governance

  • Risk Management

  • Unlock New Capacity and Develop High-potential Talents

  • Become ‘The Most Admired Organization’ People Want to Work with

  • Establish the Best Business Practice with Good Governance in Place