The existing regulation was approved on December 23, 2025, and registered by the Ministry of Justice on January 21, 2026. The proposed amendments are open for public discussion on the government's draft legislation portal until August 1 and may be revised following the consultation.
The changes would affect biometric identification, P2P transfers, customer notifications, card management, and technical security standards.
Biometric requirements to be revised
The draft introduces mandatory remote biometric identification during the initial registration in a banking application.
At the same time, it would relax biometric requirements for several other operations.
Under the current rules, users must complete biometric verification not only when recovering a password or logging in from a new device, but also when signing in, registering, and linking a bank card. The proposed amendments would retain mandatory biometrics only for password recovery and logins from new devices. Logging into an account, registering, and linking a bank card would no longer require biometric verification.
Similarly, linking a bank card would require only a one-time password (OTP) rather than both an OTP and biometric authentication.
Exception proposed for family-registered phone numbers
The Central Bank also proposes relaxing rules governing the verification of mobile phone numbers against an individual's Personal Identification Number of an Individual (PINFL).
Currently, registration and card linking are prohibited if a user's phone number is not registered under their own PINFL.
The draft would introduce an exception for close relatives. Registration would still be allowed if the phone number is registered in the name of a parent, sibling, spouse, or child, provided the family relationship is officially confirmed. The exemption would not apply to corporate phone numbers registered to legal entities.
Cards to be deactivated instead of unlinked
Another proposed change concerns security measures after users log in from a new device or recover a password.
At present, all bank cards linked to an account are automatically removed from the application, and the transaction history stored on the device is deleted.
Under the draft, linked cards would instead be switched to inactive status. Users could reactivate them by entering an OTP code. The requirement to delete transaction history would also be removed.
Greater flexibility for customer notifications
The amendments would also give banks and payment organizations more discretion over fraud warnings.
If malicious software or signs of remote access to a customer's device are detected, institutions are currently required to notify users by SMS. The draft would allow notifications to be sent either via SMS or push notifications within a mobile application.
The proposal also changes the rules for warning messages displayed before financial transactions.
Current regulations require fraud warnings before every transaction, including account transfers, P2P transfers, and service payments. Under the new approach, banks and payment organizations would determine which transactions require such warnings based on their internal fraud risk management policies.
P2P transfer rules could become more flexible
The Central Bank is also proposing changes to authentication requirements for person-to-person (P2P) transfers.
At present, every P2P transfer must be confirmed using an OTP code, while such transfers via websites are prohibited.
Under the draft, banks and payment organizations would be allowed to determine, based on their fraud risk policies, the criteria for requiring OTP confirmation and the maximum transfer amount that may be processed without mandatory verification by an anti-fraud system.
The amendments would also permit the use of SMS-based anti-fraud verification codes or other authentication methods instead of OTPs. The prohibition on P2P transfers through websites would remain unchanged.
Stronger privacy protection for cardholders
The draft also proposes stricter masking of cardholder information.
Current rules display the cardholder's full first name and only the initial of the surname. For transfers made using the recipient's phone number, the recipient's details are only partially concealed.
Under the proposed amendments, both the first name and surname of the transfer recipient's cardholder would be partially masked.
TLS requirement updated
The draft would also revise technical cybersecurity requirements.
Instead of requiring financial institutions to use Transport Layer Security (TLS) version 1.3 or higher, the regulation would require the use of a supported version of the TLS protocol, removing the reference to a specific version number.





