2024-08-23 | 13/1Added
The Central Bank of Uzbekistan approves a regulation mandating payment system operators and payment service providers to implement specific information and cybersecurity measures, including authentication, fraud prevention, and cryptographic protection. The regulation requires these entities to establish dedicated security services, protect confidential and personal data, and ensure the security of remote information systems before deployment. It also stipulates that biometric data of customers must be stored within Uzbekistan, while other personal data may be stored abroad in compliance with the Law on Personal Data. The decision repeals a previous 2020 regulation and enters into force three months after official publication.
Get CBU alerts — same-day email on every new publication.
Resolution of the Board of the Central Bank of the Republic of Uzbekistan, registered on May 21, 2024, registration number 3513
Date of Entry into Force
August 23, 2024
All
August 3, 2026
August 23, 2024
Russian
Uzbek
Uzb
Uzb|Russian
[OKOS:
1.03.00.00.00 Civil Legislation / 03.11.00.00 Specific Types of Obligations / 03.11.17.00 Settlements (see also 07.21.03.00) / 03.11.17.06 Settlements via Plastic Cards and Electronic Payment Systems]
[TSZ:
Resolution of the Board of the Central Bank of the Republic of Uzbekistan
On Approval of the Regulation on Ensuring Information and Cybersecurity in Payment Systems and Taking Measures to Prevent Offenses Committed via Digital Technologies by Payment System Operators and Payment Service Providers approval
[Registered by the Ministry of Justice of the Republic of Uzbekistan on May 21, 2024, registration number 3513]
In accordance with the Laws of the Republic of Uzbekistan "On the Central Bank of the Republic of Uzbekistan" and "On Cybersecurity," and Decision No. PQ-381 of the President of the Republic of Uzbekistan dated November 30, 2023, "On Measures to Strengthen the Protection of Consumers of Digital Products (Services) and Combat Offenses Committed via Digital Technologies," the Board of the Central Bank of the Republic of Uzbekistan resolves:
[OKOS:
1.03.00.00.00 Civil Legislation / 03.11.00.00 Specific Types of Obligations / 03.11.17.00 Settlements (see also 07.21.03.00) / 03.11.17.06 Settlements via Plastic Cards and Electronic Payment Systems]
[OKOS:
1.01.00.00.00 Constitutional System / 01.14.00.00 Law-Making Activity of State Bodies / 01.14.05.00 Publication and Entry into Force of Normative Legal Acts]
The Decision of the Board of the Central Bank of the Republic of Uzbekistan dated June 11, 2020, No. 13/10 "On Approval of the Regulation on Ensuring Information Security in Payment Systems of Payment System Operators and Payment Service Providers" (registration number 3268, June 30, 2020) (National Database of Legal Acts, June 30, 2020, No. 10/20/3268/1112) is deemed to have lost its force.
This decision is coordinated with the State Security Service of the Republic of Uzbekistan, the Ministry of Digital Technologies, the Ministry of Internal Affairs, the National Agency for Strategic Projects, and the Center for the Development of Electronic Technologies.
[OKOS:
1.01.00.00.00 Constitutional System / 01.14.00.00 Law-Making Activity of State Bodies / 01.14.05.00 Publication and Entry into Force of Normative Legal Acts]
Chairman M. NURMURATOV
Tashkent,
April 24, 2024,
No. 13/1
Agreed:
Chairman of the State Security Service of the Republic of Uzbekistan A. AZIZOV
April 19, 2024
Head of the Center for the Development of Electronic Technologies O. KHODJAKBAROV
April 23, 2024
Director of the National Agency for Strategic Projects D. LI
April 23, 2024
Minister of Internal Affairs P. BOBOJONOV
April 1, 2024
Minister of Digital Technologies Sh. SHERMATOV
March 29, 2024
Appendix to the Decision of the Board of the Central Bank of the Republic of Uzbekistan dated April 24, 2024, No. 13/1 decision
APPENDIX
Regulation on Ensuring Information and Cybersecurity in Payment Systems and Taking Measures to Prevent Offenses Committed via Digital Technologies by Payment System Operators and Payment Service Providers
REGULATION
This Regulation establishes requirements for ensuring information and cybersecurity in payment systems of payment system operators and payment service providers, as well as for preventing offenses committed via digital technologies.
Chapter 1. General Provisions
authorization — granting a specific person or group of persons the right to perform certain actions;
authentication — the procedure for confirming the authenticity of a user, program, device, or data;
identification — assigning identifiers to subjects of payment systems and/or comparing identifiers with a specified list of identifiers;
cryptographic key — a sequence of symbols used for calculating or verifying an electronic digital signature, as well as for encryption and decryption;
remote service delivery system — a set of telecommunications tools, digital and information technologies, software, and equipment that ensures communication between users of payment services and providers of these services for the use of electronic services;
operators of important payment systems — a legal entity that is an operator of a payment system included in the list of important payment systems by the Central Bank of the Republic of Uzbekistan (hereinafter referred to as the Central Bank in the text), the interruption of which (downtime) in the operation of the payment system may lead to the emergence of risks in the payment services market of the Republic of Uzbekistan;
payment — the fulfillment of a monetary obligation with cash funds or the transfer of monetary funds using payment instruments;
payment agent — a legal entity that is not a bank that has concluded an agency agreement with a bank or payment organization to provide payment services;
payment subagent — a legal entity or individual entrepreneur that is not a bank that has concluded a sub-agency agreement with a payment agent to provide payment services;
payment organization — a legal entity that is not a bank, authorized to conduct activities to provide payment services;
payment system operators — legal entities conducting activities to ensure the operation of a payment system within the territory of the Republic of Uzbekistan;
participants of a payment system — banks that conduct settlements with the payment system operator and have concluded a contract regarding participation in payment systems;
providers of payment services — the Central Bank of the Republic of Uzbekistan, banks, payment organizations, payment agents, payment subagents;
clearing — the process of collecting, comparing, and recording monetary claims and obligations of participants of a payment system;
electronic money — unconditional and non-withdrawable monetary obligations of the electronic money issuer, stored in electronic form and accepted as a payment instrument in the electronic money system;
information object — information systems of various levels and purposes, telecommunications networks, technical means of information processing, premises where these means are installed and used, as well as separate premises intended for negotiations, including confidential negotiations;
anti-fraud system — a set of procedures aimed at preventing fraud committed in making payments using bank cards and accounts, mobile application accounts, and electronic wallets;
fraud — fraudulent actions committed using information technologies;
information security — the protection of information and supporting infrastructure from accidental or intentional natural or artificial influences that may cause unacceptable harm to subjects of information relations;
cybersecurity — the state of protection of the interests of the individual, society, and the state from external and internal threats in cyberspace;
security regime — a set of administrative-legal, organizational, engineering-technical, and other measures established by normative legal acts and technical regulation normative acts, ensuring the prevention of unauthorized use of the organization's confidential information.
Chapter 2. Protection of Information on Payments
[OKOS:
1.03.00.00.00 Civil Legislation / 03.11.00.00 Specific Types of Obligations / 03.11.17.00 Settlements (see also 07.21.03.00) / 03.11.17.06 Settlements via Plastic Cards and Electronic Payment Systems]
[OKOS:
1.03.00.00.00 Civil Legislation / 03.11.00.00 Specific Types of Obligations / 03.11.17.00 Settlements (see also 07.21.03.00) / 03.11.17.06 Settlements via Plastic Cards and Electronic Payment Systems]
introduce systems for identification, authentication, and authorization;
use methods to prevent unauthorized system access (login, password, biometric identification, two-factor authentication (2FA), etc.);
protect against falsification of payment documents and identification information, unauthorized modification, and presentation to third parties;
ensure and control the formation of payment information, verification of the authenticity of payment documents, and their processing and justified modifications;
ensure the delivery of payment documents to the original owner and prevent their dispatch to other persons;
take measures to prevent unauthorized copying, modification, deletion, and dispatch of information related to executed payments during storage;
ensure the safe (iron cabinet) storage of payment-related information transferred to an external storage provider and appoint responsible employee(s) for data storage;
control and account for software in information systems and ensure the continuous operation of interpretations of software, hardware-software devices, and software tools;
ensure that information systems are up-to-date (latest version), introducing new software interpretations into the information system after testing;
automatically form electronic records of processes for processing, transmitting, and storing payment information and ensure their storage;
establish information security and cybersecurity services, as well as services for taking measures against suspicious fraud operations in banks and payment systems, and control activities related to information security and cybersecurity and measures against suspicious (fraud) operations related to bank cards;
ensure the security of the computing network and cryptographic protection, protect against computer viruses, manage access to information systems, configure technical means, and apply other measures;
ensure the use of information security and cybersecurity services, as well as equipment, devices, hardware-software, and software technical means for taking measures against suspicious (fraud) operations related to bank cards, regularly improve them, establish usage procedures, perform technical maintenance and repair, and prevent unauthorized use in other cases;
protect against unauthorized access to applied technical means from all telecommunications networks, modification, deletion, and copying of data therein; prevent the loss (disappearance) of information; take measures to strengthen protection systems based on the analysis of unauthorized access to the information system or the occurrence of cybersecurity incidents.
detect codes (computer viruses) that harm the operational activities of computing equipment (servers, computers, etc.), ATMs, embossers, and payment terminals (depending on technical capabilities) and take measures to prevent their negative impact; use only licensed antivirus software in information systems, ensuring the relevance and updating of their types and databases; ensure the automatic operation of antivirus software; check all information received through the Internet and corporate networks through antivirus software.
the procedure for connecting, launching, using, and decommissioning cryptographic protection tools in automated systems; the procedure for restoring cryptographic protection tools in case of downtime, failure, and other emergency situations; the procedure for making changes to cryptographic protection software and technical documentation; the procedure for managing cryptographic keys; the procedure for applying organizational and technical methods for using, storing, and modifying cryptographic key carrier devices.
Payment system operators and providers of payment services must ensure information security and cybersecurity in information exchange with the Central Bank of the Republic of Uzbekistan.
The following measures must be taken to limit unauthorized access to and use of information objects of payment system operators and providers of payment services:
control physical impact on information objects, including ATMs, payment terminals, and electronic payment devices, and access to buildings and premises equipped with technical equipment; ensure physical protection (security regime) of technical means containing information granting the right to operate in payment systems (passwords, biometrics, and other data), including automated systems, programs, computing equipment, telecommunications equipment parameters, and structures used in making payments, and prevent unauthorized impact; control the access of employees of payment system operators and providers of payment services to information objects and introduce systems to protect against unauthorized dissemination of information; control work processes in rooms where servers and telecommunications equipment are located using video surveillance systems.
Payment system operators and providers of payment services must ensure the information security and cybersecurity of information systems containing the following information:
information about the balance of funds in bank (card) accounts; information about electronic money balances; information about executed payments; information including cashless settlements; payment information of interbank payment and clearing systems; cryptographic keys used to ensure cryptographic protection; confidential information processed in making payments (bank secrecy, personal data, and other information protected by law); See: Laws of the Republic of Uzbekistan "On Bank Secrecy" and "On Personal Data." information about customers' bank cards, accounts, and authentication status.
Before implementing and making changes to information systems providing remote payment services (mobile applications, internet banking, etc.) (hereinafter referred to as remote information systems in the text), payment system operators or providers of payment services must ensure the following:
ensure full testing (testing) of all functions related to payment transfer in remote information systems; conduct expertise of remote information systems based on technical specifications, their compliance with technical specifications and cybersecurity requirements, and submit expertise conclusions to the Central Bank based on the results; ensure the connection of remote information systems to the information security system at the cellular communication level, the Central Bank's centralized anti-fraud system, and modern biometric identification systems; develop instructions for using programs and ensure their relevance when presenting to customers; ensure changes are made to eliminate identified vulnerabilities; control the relevance of programs used by customers. Payment system operators or providers of payment services must restrict the use of the old interpretation (version) after introducing a new interpretation (version) of remote information systems and transition (update) to the new interpretation (version).
Payment system operators and providers of payment services must develop rules for information security and cybersecurity, as well as measures against suspicious (fraud) operations related to bank cards, taking into account the features of the information objects of the parties, their functions, responsibilities, and the requirements of this Regulation, for the exchange of mutual payment information and information related to payment information via telecommunications networks.
The agency contract concluded between the payment agent and the bank or payment organization for providing payment services must specify the responsibilities of the parties regarding information security.
The sub-agency contract concluded between the payment subagent and the payment agent for providing payment services must specify the responsibilities of the parties regarding information security.
Chapter 3. Confidentiality of Payment Information and Protection of Personal Data Therein
[OKOS:
1.12.00.00.00 Information and Informatization / 12.03.00.00 Information Resources. Use of Information Resources / 12.03.06.00 Personal Data and Their Protection]
[See previous](/docs/6933268?ONDATE=23.08.2024 00#8383960) edition.
Other types of personal data belonging to the customer may be stored and processed outside the territory of the Republic of Uzbekistan in accordance with Part 3 of Article 271 of the Law of the Republic of Uzbekistan "On Personal Data."
(Para 121 was introduced based on Decision No. 21/4 of the Board of the Central Bank of the Republic of Uzbekistan dated July 22, 2026 (registration number 3914, August 1, 2026) — , August 3, 2026, No. 10/26/3914/0809)
Chapter 4. Information Security and Cybersecurity Service
[OKOS:
1.12.00.00.00 Information and Informatization / 12.08.00.00 Information Security, Protection of Rights of Subjects of Information and Informatization (see also 16.04.03.00))]
taking measures to prevent unauthorized appropriation of funds through automated systems;
taking measures to prevent the disclosure of data to third parties;
submitting information to the Central Bank in a timely manner regarding identified information security and cybersecurity incidents, cyber threats, and cyberattacks arising in information and communication technology infrastructure;
analyzing the state of information security and cybersecurity in information and communication technology infrastructure, information systems, and resources at least twice a year in accordance with the requirements of this Regulation, internal rules, and procedures, taking into account information security and cybersecurity risks, and formalizing the results of the analysis with an act.
Chapter 5. Limiting Employee Authority in Information Systems
[OKOS:
1.12.00.00.00 Information and informatization / 12.04.00.00 Informatization. Information systems, technologies, and tools for their support / 12.04.02.00 Information systems, technologies, and tools for their support]
develop procedures and rules defining the right to work with information systems, reflect them in job descriptions, and ensure system usage procedures based on the relevant document (application, request, or other form);
form a list of responsible employees granted the right to work with information systems;
register actions related to defining and distributing rights to work with information systems;
periodically (at least twice a year) verify that rights to work with information systems are logically and correctly defined based on job duties;
control information security and cybersecurity during the operation and testing of information systems, as well as the correctness of granted rights to work with information systems;
take measures to ensure that information system users cannot change the rights granted by the information system and to restrict granting these rights to third parties.
conclude an agreement on non-disclosure of confidential and personal data;
perform work with payment-related and other protected information in information systems based on authorized procedures;
involve organizations with the relevant license and/or permit (if such activity is carried out based on a license or relevant permit);
develop measures to ensure data confidentiality during the design phase of information systems;
formalize measures for information security and cybersecurity (work performed, installed programs, devices, etc.), a clearly specified technical assignment, acceptance (plan for testing), and other relevant documents;
compile a list of software providers and organizations that developed and/or made changes to it;
determine approximate deadlines and conditions for the development and implementation of information systems;
ensure control by the information security and cybersecurity service and the employee responsible for informatization regarding the validity of changes made to information systems by involved organizations, their compliance with existing technical assignments, the absence of programs (system functions) foreign to the information system, and the positivity of test results.
After an organization that made changes to automated systems completes its duties or upon the expiration of the contract term, all confidential information known to it (identifiers, passwords, etc.) and system access rights must be changed by the information security and cybersecurity service.
Chapter 6. Protecting Information Networks from Attacks
[OKOS:
1.12.00.00.00 Information and informatization / 12.04.00.00 Informatization. Information systems, technologies, and tools for their support / 12.04.02.00 Information systems, technologies, and tools for their support;
2.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of rights of subjects of information and informatization (see also 16.04.03.00)]
network segmentation and the use of firewalls;
taking technical (cryptographic and other) and/or organizational measures to prevent unauthorized access to data received and transmitted through information networks, including the World Wide Web, and ensuring network data filtering (use of firewalls);
identification, multi-factor authentication, and authorization when making payments through information networks and websites (multi-factor authentication is not applied when making mobile and contactless payments);
identifying users using information networks and the World Wide Web, as well as servers and communication channels;
implementing employee use of World Wide Web resources through a proxy server, restricting access to websites not required for work, and recording accessed websites;
providing information systems with primary and backup communication channels;
protecting server networks (organizing demilitarized zones (DMZ));
closing unnecessary ports and stopping services on servers;
accounting for objects and resources accessing the information system;
multi-factor authentication of users when making mobile payments (SMS, QR-code, NFC, fingerprint, iris recognition, or other verification methods may be used);
ensuring information security and cybersecurity of payment data and information systems (databases) when accessing remotely using mobile devices;
establishing the procedure for using (single or multi-use) passwords applied for customer identification and authentication in remote services and other information systems, applying verification codes, sending single-use verification codes to the system in encrypted form, applying antifraud and biometric identification systems, and specifying the validity period of the code and other aspects;
recording identification information (IP address, MAC address, and other identifiers) about the device used when accessing automated systems;
applying intrusion detection and prevention systems.
Payment system operators and payment service providers may use information protection equipment of foreign organizations.
Payment system operators must establish technical and organizational measures, work procedures, and rules used for information exchange related to payments, and the implementation of these procedures must be ensured by payment service providers.
To strengthen information security and cybersecurity, the Network Address Translation Protocol (NAT), which allows changing IP addresses of network transit packets in the network protocol (TCP/IP), may be used. In this case, electronic journals of all connections through the network must be maintained showing original IP addresses and archived electronically in the prescribed manner.
See: Model Regulation on Electronic Archives approved by Order No. 89 of the Director of the
Uzbek State Standard 2875:2014 "Requirements for Data Centers. Ensuring Infrastructure and Information Security":
31. Important payment system operators must organize main information systems processing data and organize backup information systems in an area not closer than 50 kilometers from their location. In this case, main and backup information systems are organized within the territory of the Republic of Uzbekistan.
Important payment system operators must store data in information systems (electronic declarations and other payment-related data) in electronic archives in at least two copies (specifically, one copy each in the main and backup information systems).
Chapter 13. Establishing Continuous Operation of Payment Systems and Maintaining Electronic Archives
[OKOB:
1.12.00.00.00 Information and informatization / 12.04.00.00 Informatization. Information systems, technologies and tools for their support / 12.04.02.00 Information systems, technologies and tools for their support]
32. To ensure the continuous operation and stability of payment systems, the following measures must be taken:
33. Payment system operators who are not important payment system operators and payment service providers must organize main information systems processing data and organize backup information systems in an area not closer than 5 kilometers from their location. In this case, main and backup information systems are organized within the territory of the Republic of Uzbekistan.
Data in information systems (electronic declarations and other payment-related data) must be stored in electronic archives in at least two copies (specifically, one copy each in the main and backup information systems may be stored).
34. When the activities of payment system operators and payment service providers are terminated, the information resources of the existing electronic archive are handed over to state archives.
When the activities of payment system operators and payment service providers are terminated and merged with another organization, the electronic archive data are handed over to the electronic archive of the merging organization.
Chapter 14. Security Regime
[OKOB:
1.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of information and rights of subjects of information processes and informatization (see also 16.04.03.00)]
35. Payment system operators and payment service providers must be equipped with rooms for storing and processing payment-related data. These rooms must meet the following requirements:
Payment system operators and payment service providers may take additional security measures for rooms storing and processing payment-related data in addition to the requirements specified in this paragraph.
36. The storage period for all video surveillance data specified in this Regulation must not be less than one month.
37. Buildings of payment system operators and payment service providers must be equipped with necessary devices, organizational and technical means, and use relevant software in their protection.
Chapter 15. Control of the Payment Execution Process
[OKOB:
1.03.00.00.00 Civil Law / 03.11.00.00 Types of Obligations / 03.11.17.00 Settlements (see also 07.21.03.00) / 03.11.17.06 Settlements via plastic cards and electronic payment systems;
2.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of information and rights of subjects of information processes and informatization (see also 16.04.03.00)]
38. Payment system operators must carry out control and monitoring activities when taking information security and cybersecurity measures in their payment systems.
39. Payment system operators and payment service providers must analyze automated systems, applications, and information infrastructure objects for vulnerabilities regarding information security and cybersecurity, check them for unauthorized access at least twice a year, and control the absence of undocumented capabilities.
40. Payment system operators and payment service providers must submit a report to the Central Bank by April 1 of the following year at the latest, regarding the state of information security and cybersecurity.
Chapter 16. Service for Taking Measures Against Suspicious Fraud Operations in Banking and Payment Systems
[OKOB:
1.03.00.00.00 Civil Law / 03.11.00.00 Types of Obligations / 03.11.17.00 Settlements (see also 07.21.03.00) / 03.11.17.06 Settlements via plastic cards and electronic payment systems;
2.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.21.00.00 Banking Activity / 07.21.07.00 Issuance of Bank Cards and Operations Using Them;
3.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of information and rights of subjects of information processes and informatization (see also 16.04.03.00)]
41. Payment system operators, participants of the payment system, and payment organizations must include the following in the duties of the service for taking measures against suspicious (fraud) operations in banking and payment systems:
Chapter 17. Prevention of Payment Execution Without the Consent of Physical and Legal Entities
[OKOB:
1.03.00.00.00 Civil Law / 03.11.00.00 Types of Obligations / 03.11.17.00 Settlements (see also 07.21.03.00) / 03.11.17.06 Settlements via plastic cards and electronic payment systems;
2.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.21.00.00 Banking Activity / 07.21.07.00 Issuance of Bank Cards and Operations Using Them;
3.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of information and rights of subjects of information processes and informatization (see also 16.04.03.00)]
42. Payment system operators, participants of the payment system, and payment organizations define procedures for identifying operations that match the criteria for money transfers executed without the consent of physical and legal entities from bank cards, by analyzing the description, amount, and movement of money transfers executed without the consent of physical and legal entities in their risk management documents.
43. Payment system operators must introduce transactional anti-fraud systems and ensure their integration into the Central Bank's centralized anti-fraud system to prevent money transfers without the consent of physical and legal entities via bank cards.
44. Participants of the payment system and payment organizations must introduce session-based anti-fraud systems and ensure their integration into the Central Bank's centralized anti-fraud system.
45. When operations matching the criteria for money transfers executed without the consent of physical and legal entities via bank cards are identified at participants of the payment system and payment organizations, the execution of the order submitted for this operation is carried out within the framework of anti-fraud systems.
46. Payment system operators, participants of the payment system, and payment organizations must perform the following to prevent payments executed without the consent of physical and legal entities:
47. In cases where payments are executed without the consent of physical and legal entities by payment system operators, participants of the payment system, and payment organizations, the temporary restriction (blocking) of the use of bank cards, accounts, accounts in mobile applications, and electronic wallets involved is lifted during the period of temporary restriction (blocking) of their use, provided there are no other grounds for their restriction (blocking) in legislative acts.
48. The criteria for money transfers executed without the consent of physical and legal entities are determined based on the decision of the management of the Central Bank.
Chapter 18. Ensuring Information and Cybersecurity When Using EPOS Terminals
[OKOB:
1.03.00.00.00 Civil Law / 03.11.00.00 Types of Obligations / 03.11.17.00 Settlements (see also 07.21.03.00) / 03.11.17.06 Settlements via plastic cards and electronic payment systems;
2.12.00.00.00 Information and informatization / 12.08.00.00 Information security, protection of information and rights of subjects of information processes and informatization (see also 16.04.03.00)]
49. Payment system operators, participants of the payment system, and payment organizations must perform the following to ensure information security and cybersecurity when using EPOS terminals:
50. Payment system operators and participants of the payment system must take measures to stop the use of EPOS terminals or disconnect these terminals in accordance with the mandatory directive of the Central Bank to limit or stop the execution of suspicious (fraud) operations.
Chapter 19. Final Provisions
51. Persons guilty of violating the requirements of this Regulation are liable in the manner established by legislative acts.
(, 22.05.2024, No. 10/24/3513/0359; 03.08.2026, No. 10/26/3914/0809)
Read the rest free
This document supersedes: Regulation on Ensuring Information Security in Payment Systems by Payment System Operators and Payment Service Providers
Source: Central Bank of the Republic of Uzbekistan — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works