The Central Bank of Uzbekistan updated information security requirements for remote financial services. The main changes simplify the customer journey: the regulator allowed using someone else’s phone number for registration and canceled blanket confirmation for P2P transfers. The document is published on the Lex.uz portal.
What happened
Users can now register in banking and payment apps using a phone number registered to a close relative: parents, spouses, children, siblings, or in-laws. Using corporate numbers for this purpose is prohibited. The requirement to pass remote biometric identification during registration remains.
The regulator also reduced the scenarios where biometrics are mandatory. Linking a bank card inside an app no longer requires it—the client just needs to enter a one-time OTP code. Biometric confirmation is only required when logging into an account from a new device or recovering a password.
Country and market
Until now, Uzbekistan’s fintech operated under strict, universal security requirements that often complicated the user experience. For example, mandatory confirmation of every transfer or strictly linking a phone number to a passport created friction for clients.
The new rules give banks and payment organizations more freedom. Mandatory OTP confirmation for all P2P transfers is canceled. Financial institutions will now independently determine which operations need an additional code and set maximum transfer amounts without confirmation.
Privacy rules also changed. For transfers by card number, apps will partially hide the recipient’s first and last name. Previously, apps could display the full first name and the first letter of the last name.
Why it matters
The relaxations solve a real market problem: in Uzbekistan, phone numbers are often registered to one family member, preventing other relatives from fully using digital services.
The regulator shifts focus from blanket control to a risk-oriented approach, allowing banks to balance fraud protection and customer convenience themselves.
What’s next
For banks, this means reconfiguring their anti-fraud systems. They must independently define scenarios for showing fraud warnings, choose notification channels for compromised devices (SMS or push), and update data display logic for P2P transfers.