🛡 Trust & Compliance

เราโปร่งใสว่าใช้กฎหมายและมาตรฐานสากลใดในการดูแลข้อมูลและการเงินของท่าน

17
พ.ร.บ.ที่ปฏิบัติตาม
22+
มาตรฐาน TFRS / TAS
8
TSA · ผู้สอบบัญชี
12+
ISO Standards
196+
Audit Points
ในระบบ
72hr
PDPA Breach SLA

🔍 Auditor Portal · สำหรับผู้สอบบัญชี CPA/TA

PKKT Cortex เป็นระบบเดียวในไทยที่ออกแบบ Auditor Portal ตั้งแต่ day 1 · ผู้สอบบัญชีไม่ใช่ "user รอง" · แต่เป็น persona หลัก ที่มี workflow เฉพาะ

Independence

🔒 TSA 220 · Quality Control

  • Independence check · auditor ห้าม audit งานตัวเอง
  • Engagement letter · กำหนด scope ก่อนเริ่ม
  • Partner review · 2-level approval
  • Conflict of interest disclosure
Documentation

📁 TSA 230 · Audit Documentation

  • Working papers · เก็บ 7 ปีตามมาตรฐาน
  • Sealed storage · ไม่สามารถแก้หลัง archive
  • Hash chain · proof of integrity (blockchain-like)
  • Export PDF · พร้อมยื่นกรมพัฒนาธุรกิจ
Risk Assess

📊 TSA 315 · 330 · Risk Assessment

  • Risk register · per-account · per-cycle
  • Material misstatement · auto-flag
  • Control matrix · design + operating effectiveness
  • Audit response · เชื่อมกับ working paper
Evidence

🔍 TSA 500 · 530 · Audit Evidence

  • Sampling tool · statistical + judgmental
  • Confirmation letter · auto-generate
  • Analytical procedure · ratio + trend
  • AJE queue · auditor adjusting entries
Accounting Est

📐 TSA 540 · Accounting Estimates

  • Allowance for doubtful debts · age-based
  • Depreciation review · useful life challenge
  • Inventory valuation · NRV vs cost
  • Provision · expected credit loss (ECL)
Period Lock

🔐 Period Lock + Audit Trail

  • Locked period · ลูกค้าแก้ไม่ได้
  • Unlock request · audit approves
  • 196+ audit points · ทุก mutation
  • Event sourcing · replay any state
💡 ทำไม Auditor Portal สำคัญ?

ทุกกิจการต้องส่งงบให้ผู้สอบบัญชี · แต่ปัจจุบัน auditor ต้อง ขอเอกสารกลับไปกลับมา 50+ ครั้ง ใช้เวลา 2-4 สัปดาห์ · PKKT รวม auditor เข้าระบบเลย → ตรวจสอบ realtime · ผ่านงบใน 3-5 วัน · ลด audit fee 30-50%

→ CPA/TA สมัครฟรี (ตลอดชีพ · ไม่จำกัดจำนวนลูกค้า)

🔬 Engineering Transparency · เปิดเผยทุกตัวเลข

ระบบบัญชีต้อง เชื่อถือได้ · เราจึงไม่ปกปิดอะไร · ทุกไฟล์ในระบบมี คะแนน architecture + speed เปิดเผยให้ super_admin ดูได้ · ใช้ Refactor Tracker ติดตามว่าตรงไหนยังเก่า ตรงไหนใหม่

📐 8 Architecture Pillars

ทุกไฟล์ต้องมี: Events · Use Case · Repository · Audit · Feature Flag · CQRS · PSR-strict · DI · target score ≥ 95

⚡ Speed Score

วัด performance pattern: cache · LIMIT · indexed WHERE · async · ลด N+1 · SELECT * · sync HTTP · target ≥ 80

🧪 Test Framework (R6.0 Wave 2)

Pure-PHP test runner · 26+ tests · ทุก event · use case · listener · CI-ready · exit code 0/1

🎯 Refactor Tracker

Dashboard เปิดเผยทุกไฟล์: คะแนน · status (NEW/HYBRID/LEGACY) · planned action · wave · priority · 100% transparent

📜 กฎหมายไทยที่เราปฏิบัติตาม

ทุก process ของเราอ้างอิงตามกฎหมายต่อไปนี้ · ระบุมาตราชัดเจนใน source code

ภาษี/บัญชี

📊 ประมวลรัษฎากร

  • มาตรา 50 — WHT
  • มาตรา 79, 80 — VAT 7%
  • มาตรา 86/4 — ใบกำกับภาษีเต็มรูป
  • มาตรา 87/3 — เก็บเอกสาร 5 ปี
  • มาตรา 83 — ภ.พ.30 monthly
PDPA

🔒 พ.ร.บ.คุ้มครองข้อมูลส่วนบุคคล 2562

  • มาตรา 19 — Granular consent
  • มาตรา 24 — Lawful basis
  • มาตรา 30-37 — Data subject rights
  • มาตรา 37(4) — 72hr breach notice
  • มาตรา 28 — Cross-border transfer (SCC)
บัญชี

📚 พ.ร.บ.การบัญชี 2543

  • มาตรา 7 — ผู้มีหน้าที่จัดทำบัญชี
  • มาตรา 11 — งบการเงิน
  • มาตรา 14 — เก็บบัญชี ≥5 ปี
แรงงาน

👥 พ.ร.บ.คุ้มครองแรงงาน 2541

  • มาตรา 23, 41 — เวลาทำงาน + OT
  • มาตรา 30 — Annual leave ≥6 วัน
  • มาตรา 61-63 — OT rate 1.5/2/3x
  • มาตรา 118 — Severance pay
  • ประกาศคณะกรรมการค่าจ้าง 2569
ความปลอดภัย

💻 พ.ร.บ.คอมพิวเตอร์ 2550

  • มาตรา 5-12 — Cybercrime offenses
  • มาตรา 26 — Log retention 90 วัน
สัญญา

⚖ ปพพ. (Civil & Commercial Code)

  • มาตรา 5 — สุจริต
  • มาตรา 354 — เสนอ-สนอง (electronic)
  • มาตรา 193/30 — อายุความ 10 ปี
  • มาตรา 219 — เหตุสุดวิสัย
สิทธิ์ดิจิทัล

📝 พ.ร.บ.ธุรกรรมอิเล็กทรอนิกส์ 2544

  • มาตรา 7 — ลายมือชื่อ e-signature
  • มาตรา 9 — สัญญาอิเล็กทรอนิกส์
  • มาตรา 26-31 — ใบรับรอง (e-Tax)
ภาษีพิเศษ

🎁 พ.ร.ฎ. 802 พ.ศ. 2569

  • SMEs หักได้ 200% สำหรับ digital software
  • ใช้ปี 2569-2570
  • ลด effective price ลง ~20-40%

📊 มาตรฐานบัญชีที่เราใช้

หลัก

TFRS for NPAEs

มาตรฐานการรายงานทางการเงินสำหรับ SMEs · ออกโดยสภาวิชาชีพบัญชี (FAP)

  • บทที่ 6-23 ครบถ้วน
  • หมายเหตุประกอบงบการเงิน 15 notes auto
  • ลูกค้าประหยัด ฿5-15K/ปี
เลือกใช้

TFRS Full Set

  • TFRS 9 — Financial Instruments (ECL)
  • TFRS 10 — Consolidation
  • TFRS 13 — Fair Value
  • TFRS 15 — Revenue Recognition
  • TFRS 16 — Leases (full amortization)
เลือกใช้

TAS Full Set

  • TAS 1, 2, 7 — Presentation, Inventory, CF
  • TAS 16 — PPE
  • TAS 24 — Related Party
  • TAS 33 — EPS
  • TAS 36 — Impairment
  • TAS 37, 40 — Provisions, Investment Property

🌐 มาตรฐาน ISO ที่เราอ้างอิง

เราใช้แนวทางตามมาตรฐานสากล (best practice) แม้ยังไม่ได้ certified แต่ทุก control มีในระบบ

Security

ISO/IEC 27001:2022

Information Security Management System (ISMS)

  • A.5 — Organizational controls
  • A.8 — Asset management
  • A.9 — Access control · MFA · bcrypt
  • A.10 — Cryptography (AES-256, TLS 1.3)
  • A.12 — Operations · audit logs 5 ปี
  • A.16 — Incident management
  • A.17 — Business continuity · backup
Privacy

ISO/IEC 27701:2019

Privacy Information Management (extends 27001)

  • Consent records (immutable)
  • DSR fulfillment 30-day SLA
  • Data flow mapping
  • Sub-processor list
  • Auto-purge cron · 13 PII tables
Quality

ISO 9001:2015

Quality Management System (QMS)

  • 7.5 — Document control + versioning
  • 9.1.2 — Customer satisfaction
  • 9.2 — Internal audit
  • 9.3 — Management review
  • 10.2 — CAPA · non-conformity
Risk

ISO 31000:2018 · 27005:2022

Risk Management

  • Risk register (heat map)
  • Likelihood × Impact (1-25)
  • Treatment options 4 ประเภท
  • Quarterly review cycle
Continuity

ISO 22301:2019

Business Continuity Management

  • Daily automated backup
  • Monthly restore test
  • RPO ≤24h · RTO ≤4h
  • Disaster recovery plan
AI

ISO/IEC 42001:2023

AI Management System

  • AI risk assessment
  • Human oversight on tax advice
  • Disclaimer · transparency
  • Cost capping (AI Cache)
Format

ISO 8601 · 4217 · 3166 · 639

Data interchange formats

  • ISO 8601 — Date/time (Y-m-d\TH:i:sP)
  • ISO 4217 — Currency (THB · USD ฯลฯ)
  • ISO 3166 — Country (TH · US ฯลฯ)
  • ISO 639 — Language (th · en)
  • ISO 20022 — Bank file format
Software

ISO/IEC 25010:2011

Software Product Quality

  • Hexagonal Architecture
  • Functional suitability
  • Reliability · Usability
  • Security · Maintainability

⚙ Internal Processes (กระบวนการภายใน)

ทุก process มีเอกสาร มี audit trail · ตรวจสอบได้

🚨 Incident Response

Standard: ISO 27035 + PDPA ม.37(4)

  1. Detection · auto-classify severity
  2. DPO notified (HIGH/CRITICAL within 1-4hr)
  3. 72-hour clock if data breach
  4. PDPC notification + reference number
  5. Data subjects notified (if rights affected)
  6. Root cause analysis + lessons learned
  7. CAPA created in audit findings

🎯 Risk Management

Standard: ISO 31000 + ISO 27005

  1. Identify (10 default risks seeded)
  2. Score = Likelihood × Impact (1-25)
  3. Treat: Avoid · Reduce · Transfer · Accept
  4. Quarterly review of HIGH/CRITICAL
  5. Annual review of all risks
  6. Heat map dashboard for management

🔍 Internal Audit

Standard: ISO 19011 + 9001 9.2 + 27001 9.2

  1. 21 control areas covered
  2. Quarterly rotation (5 areas/Q)
  3. Findings: Major/Minor/Observation/Strength
  4. SLA: Major 7d · Minor 30d · Obs 90d
  5. CAPA → Owner + Due date
  6. Annual full audit

📄 Document Control

Standard: ISO 9001 7.5 + 27001 7.5

  1. Versioned (v1 · v2 · v3...)
  2. SHA-256 integrity hash
  3. Approval workflow (draft → review → approved)
  4. Auto-supersede previous version
  5. Annual review reminder
  6. 17 essential policies seeded

🔒 Data Subject Rights

Law: PDPA ม.30-37

  1. Privacy Center self-service
  2. Export JSON (Right to Portability ม.34)
  3. Erasure request (ม.32)
  4. Consent toggle (ม.20 — easy as grant)
  5. 30-day SLA enforced
  6. DPO admin queue

🗑 Auto-Purge

Law: PDPA ม.37(3) · ป.รัษฎากร 87/3

  1. Daily 03:00 cron
  2. 13 PII tables covered
  3. Retention rules per legal basis
  4. Conflict resolution (longest applicable)
  5. Audit trail in pdpa_purge_log
  6. Dry-run preview available

📋 เอกสารสำคัญ (เปิดสาธารณะ)

เอกสารเวอร์ชั่นมีผลลิงก์
เงื่อนไขการใช้บริการv2026.05.1010 พ.ค. 2569ดูเอกสาร →
นโยบายความเป็นส่วนตัวv2026.05.1010 พ.ค. 2569ดูเอกสาร →
Privacy Center · ข้อมูลของฉันเข้าสู่ระบบ →
Compliance Center (admin)super admin →

🤝 Sub-processors (พันธมิตรที่เราใช้)

Providerวัตถุประสงค์ที่ตั้งข้อมูลSafeguard
CloudPanel (Hetzner)Server hosting🇹🇭 ThailandISO 27001
LINE CorporationOAuth · Messaging🇯🇵🇹🇭SCC + LINE BCR
Beam LighthousePromptPay payment🇹🇭BoT regulated
Anthropic ClaudeAI vision/OCR (เลือก)🇺🇸SCC · Trust Center
OpenAI GPT-4AI chat (เลือก)🇺🇸SCC · DPA signed

มีคำถามเรื่อง compliance?

ติดต่อ DPO ของเราที่ dpo@pkkt.app

📖 อ่านนโยบายเต็ม 🔒 จัดการข้อมูลของฉัน