Business

Uzbekistan’s Central Bank proposes new checks for P2P transfers

The draft keeps the ban on website transfers and retains biometrics for registration and selected account actions.

Kashkadarya regional branch building of the Central Bank of Uzbekistan

The Central Bank of Uzbekistan has opened a draft for public consultation that would change user identification in banking apps and controls on P2P transfers.

The consultation runs from 22 July to 1 August 2026. The document has not been adopted; if approved, it would take effect after official publication.

The draft would require remote biometric identification when a user first registers. Registration could also use a phone number belonging to a parent, sibling, spouse or child if the relationship is confirmed under the prescribed procedure.

A separate one-time password would replace biometrics when a registered user links a bank card in the ordinary way. For an existing account, biometric checks would remain in place for password recovery and access from a new device.

The draft also proposes several changes for payment providers:

  • each provider would set its own criteria for one-time-password confirmation and the maximum P2P transfer allowed without anti-fraud approval; the draft sets no single national threshold;
  • card-to-card transfers through websites would remain prohibited;
  • password recovery or access from a new device would make every linked card inactive, with reactivation available through a one-time password;
  • a malware or remote-control warning could be delivered by push notification or SMS.

Users’ first and last names and recipient cardholder details would be displayed in partially masked form. Warnings before financial transactions would depend on each provider’s risk-management policy.

The requirement to use TLS 1.3 or later would be replaced by wording referring to a supported secure TLS version. The draft does not expressly authorize a particular older version or set an implementation date.

Rustam AbduazizovРедактор