The National Agency of Perspective Projects (NAPP) approved new internal Anti-Money Laundering and Combating the Financing of Terrorism (AML/CFT) control rules for crypto market participants. As Spot.uz reports, the main operational change affects onboarding: service providers can now use third-party services to verify clients.
The amendments affect crypto exchanges, crypto shops, and other licensed companies handling crypto assets.
Outsourcing identification
Crypto platforms can now engage a third party for user identification and verification as part of due diligence measures. This involves specialized organizations that authenticate personal data.
Allowing KYC outsourcing lowers the barrier to launching new crypto projects, removing the need to develop complex in-house biometrics and document recognition systems.
Compliance and management requirements
Alongside simplifying verification, the regulator tightened corporate requirements for market participants. The employee responsible for internal control must now hold the position of deputy head. New providers must appoint this specialist and submit their personal data to NAPP within a month of receiving a license.
Additional restrictions target the geography of founders. Residents of countries not participating in international anti-money laundering cooperation cannot manage or own crypto companies. Providers must now document their understanding of the client’s business model and ownership structure.
If a crypto provider is part of an affiliated financial group, internal control rules must be developed at the group level. This includes unified procedures for information exchange, auditing, and risk management.
Secure communication channels
The procedure for interacting with law enforcement has changed. Providers must transmit information about suspicious transactions to the Department for Combating Economic Crimes of the Prosecutor General’s Office via secure channels. These include encrypted electronic systems, secure email, and a special personal account, access to which NAPP grants upon separate request.
If assets are frozen because client data matches lists of individuals involved in terrorism, the compliance officer must notify the user as quickly as possible and explain the procedure for resuming operations.