Kazakhstan’s Agency for Regulation and Development of the Financial Market (ARDFM) published a resolution adjusting banks’ internal anti-money laundering and countering the financing of terrorism (AML/CFT) controls. The document introduces strict biometric verification requirements for remote services and changes how banks assess client risks.
ARDFM Board Resolution No. 126, dated September 7, 2026, was published on the unified government portal on September 18. According to paragraph 5, the new requirements take effect 10 calendar days after their first official publication.
Risk profile for foreigners and digital nomads
A key change affects Resolution No. 86, which regulates bank risk management systems. The regulator removed subclause 4 of the second part of paragraph 111.
While the exact text of the removed subclause is missing from the published document card, regulatory context indicates this rule previously forced banks to automatically assign a high-risk level to specific client categories, including non-resident foreigners.
Enhanced due diligence must now be targeted. High risk will no longer apply by default based on citizenship, but rather through individual assessment if a bank identifies actual suspicions.
The rules also specify requirements for serving digital nomads (the e-Residency program). When opening an account for these clients, banks must thoroughly verify documents, conduct biometric identification, and apply a risk-based approach. Integrating this category into banking compliance rules means the financial sector is preparing the legal infrastructure to serve foreign professionals using digital profiles.
Strict biometrics and proxy oversight
The relaxation of formal risk criteria comes with tighter overall control over remote operations. The regulator is closing vulnerabilities tied to stolen data and third-party account management.
Under the revised paragraph 25 of the internal control rules, banks face an additional barrier when establishing business relationships through a proxy. Before executing any debit or credit operations on the account, the bank must biometrically authenticate the actual client, not just the authorized representative.
Strict requirements also apply to digital channels. When opening an account remotely, or changing the phone number or device used for mobile banking, banks must now use two-factor identification with mandatory biometrics.
Banks must use the National Bank of Kazakhstan’s Identity Data Exchange Center (IDEC) for this verification. Relying on a single state gateway standardizes the process: banks can no longer depend solely on their own facial recognition algorithms for critical operations.
Financial organizations must also store video conference session records or captured images for at least five years after ending a business relationship. The regulator explicitly requires liveness detection technology to protect systems against static photos or deepfakes.
New risk markers
ARDFM expanded the list of illegal activity indicators that automatically trigger a high ML/TF risk level. The updated list targets modern financial threats.
Banks must now flag clients whose transactions indicate:
- involvement in fraud and financial pyramids;
- illicit drug trafficking;
- payments to online casinos, foreign bookmakers, and sweepstakes lacking an official license in Kazakhstan.
Isolating payments to unlicensed gambling platforms as a distinct risk marker will require banks to reconfigure anti-fraud systems to better detect P2P transfers masking illegal bets.
Why it matters
These changes align with the regulator’s broader strategy to strengthen financial sector oversight and payment discipline. Finteqstan previously reported that ARDFM revoked a microfinance company's license to enforce compliance; the current AML/CFT amendments mark another step toward market transparency, this time in the banking segment.
The regulator is shifting its control mechanics: instead of automatic barriers based on formal criteria, banks are moving to targeted monitoring through strict biometrics.
Dropping the high-risk presumption for non-residents could simplify onboarding for legitimate expats. At the same time, mandatory biometrics via state systems for proxy operations or device changes aim to combat shadow schemes.