Corporate & Business Advisory

Regulatory Compliance

A periodic review of where the business is exposed — licences, employment, data, tax filings and sector rules — with a fix list ordered by risk, not by alphabet.

Talk to us

Tell us the situation and we will tell you what we think you should do — and what it will cost.

Who this is for

  • Companies that have grown faster than their paperwork
  • Businesses preparing for an inspection, audit or investment
  • Foreign-owned companies unsure which Thai rules apply to them
  • Directors who would rather find the problem than be told about it

What we handle

Scope of work

A structured review across licences, employment, data, tax and sector rules

Checking that every licence held is current, and that none is missing

Employment and social security compliance, with our HR practice

PDPA — what personal data you hold, on what basis, and the notices required

Corporate filings, registers and the governance record

A written report with a fix list ordered by risk and effort

How it works

How we run the matter

  1. Scope the review to the business, its sector and its size
  2. Collect the licences, filings, contracts and internal documents
  3. Test each area against the rules that actually apply
  4. Rank the findings by risk and by effort to fix
  5. Deliver the report and work through the fix list
  6. Set the next review date and the triggers for an early one

Documents to prepare

  • Company affidavit, articles and recent annual filings
  • Every licence and permit the business holds
  • Employment contracts, work rules and the staff list
  • Privacy notices and a description of the data you collect
  • Any correspondence from a regulator or inspector

Common questions

Licensing obtains a specific named licence for you. Regulatory compliance looks across the whole business and asks which obligations apply at all — including licences you did not know you needed, and rules that have nothing to do with licences. The two often run together: the review finds the gap, the licensing work closes it.
A written report listing each finding, the rule behind it, what could happen if it stays unfixed, and what fixing it involves — sorted so you can start at the top and stop when the remaining items no longer justify the effort. Not a list of everything that could theoretically apply to a Thai company.
It applies by what you do with personal data, not by how large you are — customer lists, CCTV, job applications and employee files all count. Smaller companies usually need a proportionate set of notices, consents and a retention practice rather than a compliance department.
Usually enough time to matter. A focused review before the visit finds what an inspector will look at first, and a documented correction already under way reads very differently from a violation discovered on the day. Tell us which authority is coming and we scope the review to them.
Annually for most businesses, and whenever something structural changes — a new activity, a new location, a first foreign hire, a new data practice. Compliance drifts quietly; the point of a fixed review date is that nobody has to notice the drift for it to be caught.

Speak to a lawyer

Legal problems are easier to manage when addressed early.