The existing regulation was approved on December 23, 2025, and registered by the Ministry of Justice on January 21, 2026. The proposed amendments are open for public discussion on the government's draft legislation portal until August 1 and may be revised following the consultation.

The changes would affect biometric identification, P2P transfers, customer notifications, card management, and technical security standards.

Biometric requirements to be revised

The draft introduces mandatory remote biometric identification during the initial registration in a banking application.

At the same time, it would relax biometric requirements for several other operations.

Under the current rules, users must complete biometric verification not only when recovering a password or logging in from a new device, but also when signing in, registering, and linking a bank card. The proposed amendments would retain mandatory biometrics only for password recovery and logins from new devices. Logging into an account, registering, and linking a bank card would no longer require biometric verification.

Similarly, linking a bank card would require only a one-time password (OTP) rather than both an OTP and biometric authentication.

Exception proposed for family-registered phone numbers

The Central Bank also proposes relaxing rules governing the verification of mobile phone numbers against an individual's Personal Identification Number of an Individual (PINFL).

Currently, registration and card linking are prohibited if a user's phone number is not registered under their own PINFL.

The draft would introduce an exception for close relatives. Registration would still be allowed if the phone number is registered in the name of a parent, sibling, spouse, or child, provided the family relationship is officially confirmed. The exemption would not apply to corporate phone numbers registered to legal entities.

Cards to be deactivated instead of unlinked

Another proposed change concerns security measures after users log in from a new device or recover a password.

At present, all bank cards linked to an account are automatically removed from the application, and the transaction history stored on the device is deleted.