The Central Bank of Uzbekistan drafted general requirements for anti-fraud systems at commercial banks, payment organizations, and fintech services. As reported by Spot.uz, the document was published on the regulatory acts discussion portal.
Under the new rules, every transaction will undergo real-time scoring. The system will assign the operation to one of three risk levels. Low-risk payments will process without delays. For medium risk, the service will ask the client for additional confirmation. High-risk transactions will be blocked automatically.
The regulator requires anti-fraud systems to operate 24/7 and cover all remote service channels. Banks and fintech companies must review suspicious operation criteria at least quarterly, adapting them to new fraud schemes.
Strict deadlines for complaints
A separate section covers client relations. If an operation is rejected, the service must send the user a notification with the reason and recommendations.
Companies must accept complaints about suspicious deductions 24/7 via call centers, websites, or apps. They have 30 minutes to confirm receipt of the request, 24 hours for an initial check, and five calendar days for a final response. For complex cases, the deadline can be extended to 20 days.
In the event of major incidents—mass data compromise or the anti-fraud system going offline—market participants must notify the Central Bank within four hours. Companies will store the entire history of checks and decisions in encrypted form for at least five years.
The Central Bank is shifting fraud prevention from internal bank policy to a strictly regulated process with clear SLAs for response times to clients and the regulator.
Public discussion of the draft will last until October 9, 2026. The document will take effect three months after final approval.