The amendments to the regulation on minimum requirements for information security, cybersecurity and fraud prevention in remote financial services were approved by the Central Bank on August 14 and published on Lex.uz.

The changes revise user identification requirements, simplify person-to-person (P2P) card transfers and give banks and payment organizations greater flexibility in setting certain risk-control procedures. The amendments had been submitted for public discussion in late July.

Remote biometric identification will remain mandatory when users register for banking and payment applications. However, registration will also be permitted using a phone number registered to a close relative, including a parent, sibling, spouse, child or the relatives of a spouse.

The exception does not apply to corporate phone numbers registered to legal entities.

Biometric verification will now be required only when a user logs in from a new device or recovers a password. When linking a bank card to an account, users will only need to enter a one-time password (OTP), whereas biometric verification was previously required.

Cards linked to an account will not be unlinked when a user accesses the account from a new device or recovers a password. Instead, they will be temporarily deactivated and can be reactivated using an OTP code.

Banks and payment organizations will be allowed to choose how to notify customers when malicious software or signs of a compromised device are detected. They may use either SMS or push notifications, replacing the previous requirement to send such warnings by SMS.

Financial organizations will also be able to determine which transactions require advance risk warnings under their own risk-management policies.

Previously, a warning confirming that a transaction was being made by the customer rather than a fraudster had to be displayed for every transaction, including transfers and payments for services.

The updated rules remove the mandatory use of OTP verification for all P2P transfers. Banks and payment organizations will instead be able to establish their own criteria for transactions requiring additional confirmation, as well as set a maximum amount that can be transferred without confirmation.

At the same time, both the first and last names of transfer recipients will be partially masked. Under the previous rules, applications could display the cardholder’s first name and the first letter of their surname.

The amendments also revise requirements for the use of Transport Layer Security (TLS).

Financial organizations will no longer be required to use TLS version 1.3 or higher specifically. Instead, they will be allowed to use a supported version of the security protocol.

The changes are intended to adjust existing security and fraud-prevention requirements while giving financial service providers greater flexibility in managing authentication and transaction risks.