The Central Bank of Uzbekistan has developed general requirements for commercial banks, payment systems, and services aimed at detecting and preventing suspicious transactions. This draft regulatory act was posted on the SOVAZ portal for discussion of draft regulatory and legal acts.
The proposed rules establish requirements for anti-fraud systems, which must recognize transactions showing signs of theft of another person's property or the commission of other offenses. The systems must also identify operations conducted for illegal purposes or using funds obtained from illicit sources.
Responsibility for organizing the work of these anti-fraud systems will fall to the governing bodies of banks, payment systems, and services. These structures are obliged to approve anti-fraud strategies, ensure necessary financial and technical resources, and assess the effectiveness of the relevant systems at least once per quarter.
Risk assessment in the field of fraud prevention must be carried out at least annually. Furthermore, an unscheduled assessment will be required after significant technological changes or the launch of new products and remote service channels.
According to the draft, anti-fraud systems must operate around the clock, cover all remote service channels, and detect suspicious activity in real time. Criteria for identifying suspicious transactions must be based on a risk-based approach, providing stricter requirements for high-risk areas.
The rules also provide for the simultaneous use of multiple factors and a scoring system, as well as regular review of detection criteria considering new fraud schemes, changes in customer behavior, and incident statistics. The criteria must be measurable and objective, while the activity of the systems must be transparent and subject to supervision. The draft proposes updating indicators of suspicious transactions at least quarterly.
Each indicator in the anti-fraud system will be assigned a score depending on its significance. After evaluation, the transaction will be classified as carrying low, medium, or high risk.
