2023-07-19 | 4/11Added · Updated
The Board of Directors of the Central Bank of the Republic of Uzbekistan approves the Regulation establishing requirements for the risk management systems of banks and banking groups, effective July 19, 2023. The regulation mandates that banks implement a risk management system based on a three-line defense model, define risk appetite statements, and establish quantitative risk limits. It requires periodic calculation and submission of consolidated prudential norms for banking groups, annual stress testing of credit, liquidity, and market risks, and the development of emergency financing plans based on stress test results. Additionally, the resolution invalidates certain prior departmental normative legal acts listed in Appendix 2.
Resolution of the Board of Directors of the Central Bank of the Republic of Uzbekistan, registered on April 18, 2023, registration number 3427
Date of Entry into Force
July 19, 2023
All
July 27, 2026
August 9, 2025
April 25, 2025
July 19, 2023
View
Russian Uzbek O’zb Uzb|Russian
[ OKOS: 1. 07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.21.00.00 Banking Activity / 07.21.01.00 General Issues] [ TSZ: 1. Finance / Banks and other credit institutions. Credits]
Resolution of the Board of Directors of the Central Bank of the Republic of Uzbekistan
On Approval of the Regulation on Requirements for Risk Management Systems of Banks and Banking Groups
[Registered by the Ministry of Justice of the Republic of Uzbekistan on April 18, 2023, registration number 3427]
In accordance with the Laws of the Republic of Uzbekistan "On the Central Bank of the Republic of Uzbekistan" and "On Banks and Banking Activity", as well as the Decree of the President of the Republic of Uzbekistan No. PF-5992 dated May 12, 2020 "On the Strategy for Reforming the Banking System of the Republic of Uzbekistan for 2020–2025", the Board of Directors of the Central Bank of the Republic of Uzbekistan resolves:
Approve the Regulation on Requirements for Risk Management Systems of Banks and Banking Groups in accordance with Appendix 1.
Recognize as having lost their force certain departmental normative legal acts adopted by the Central Bank of the Republic of Uzbekistan in accordance with Appendix 2.
This resolution enters into force three months after the date of its official publication.
Chairman M. NURMURATOV
Tashkent city,
March 7, 2023,
No. 4/11
Appendix 1 to the Resolution of the Board of Directors of the Central Bank of the Republic of Uzbekistan dated March 7, 2023, No. 4/11
REGULATION
On Requirements for Risk Management Systems of Banks and Banking Groups
See previous edition.
This Regulation establishes requirements for risk management systems of commercial banks, microfinance banks, as well as banks and microfinance banks conducting Islamic banking activity (hereinafter referred to as "banks") and banking groups. (amended by the Resolution of the Board of Directors of the Central Bank of the Republic of Uzbekistan No. 19/10 dated July 8, 2026 (registration number 3427-2, dated July 27, 2026) — , July 27, 2026, No. 10/26/3427-2/0788)
Section I. Organization of the Risk Management System of Banks and Banking Groups
Chapter 1. General Provisions
credit risk — the possibility of suffering losses (losses) or not receiving planned income resulting from the failure (or inadequate performance) of the debtor's obligations to the bank within the terms and/or conditions specified in the contract or legislative acts;
liquidity risk — the possibility of suffering losses (losses) or not receiving planned income resulting from the bank's inability to fulfill its obligations on time;
market risk — the possibility of suffering losses (losses) or not receiving planned income resulting from changes in exchange rates, interest rates, and prices of financial instruments;
compliance risk — the possibility of suffering losses (losses) or not receiving planned income resulting from non-compliance with the legislative acts of the Republic of Uzbekistan, internal documents of the bank, as well as documents of foreign countries that may affect the bank's activities; (amended by the fifth bullet point of paragraph 1 of the Resolution of the Board of Directors of the Central Bank of the Republic of Uzbekistan No. 37/6 dated December 5, 2024 (registration number 3427-1, dated January 21, 2025) — , January 24, 2025, No. 10/25/3427-1/0066. Date of entry into force — April 25, 2025)
operational risk — the possibility of suffering losses (losses) or not receiving planned income resulting from inadequacy of the bank's internal processes, intentional or negligent actions of employees or other persons, errors in the bank's internal systems, or the impact of external events;
interest rate risk in the banking book — the possibility of suffering losses (losses) or not receiving planned income resulting from the impact of changes in market interest rates on the bank's assets and liabilities in the banking book;
country risk — the possibility of suffering losses (losses) or not receiving planned income resulting from political, economic, social situations in a foreign country or other changes in that country; (amended by the seventh and eighth bullet points of paragraph 1 based on the Resolution of the Board of Directors of the Central Bank of the Republic of Uzbekistan No. 37/6 dated December 5, 2024 (registration number 3427-1, dated January 21, 2025) — , January 24, 2025, No. 10/25/3427-1/0066. Date of entry into force — April 24, 2025)
risk appetite — the amount of all significant risks (both in aggregate and individually for each) that the bank is willing to accept in achieving its strategic goals and business plan indicators;
risk appetite statement — a document approved by the bank's supervisory board (hereinafter referred to as "supervisory board") that defines the bank's risk appetite;
risk limits — the quantitative distribution of risk appetite across the bank's activity directions, products, and other criteria for the purpose of limiting the level (amount) of risks;
risk profile — the amount of significant risks existing at a specified date in the bank (both in aggregate for all significant risks and individually for each);
stress testing — the assessment of the potential impact of events (risks) that have a low probability but could occur on the bank's financial condition;
significant risks — the bank's credit, liquidity, market, operational, compliance, country risks, and interest rate risk in the banking book; (amended by the fourteenth bullet point of paragraph 1 of the Resolution of the Board of Directors of the Central Bank of the Republic of Uzbekistan No. 37/6 dated December 5, 2024 (registration number 3427-1, dated January 21, 2025) — , January 24, 2025, No. 10/25/3427-1/0066. Date of entry into force — April 25, 2025)
risk management system — a system aimed at systematic identification, measurement, monitoring, control, reporting, and reduction of all risks related to the bank's activities, as well as the system of interaction between the bank's governing bodies and departments responsible for risk management;
trading portfolio — a collection of financial instruments purchased for subsequent sale and/or hedging risks with the aim of profiting from short-term fluctuations in the prices of financial instruments by the bank;
banking portfolio — a collection of assets and liabilities held on the bank's balance sheet or off-balance sheet items until maturity, which are not included in the trading portfolio;
operational resilience — the ability of the bank to ensure the continuity of critical operations in emergency situations and unforeseen circumstances;
critical operation — an operation carried out by the bank, interruptions (stoppages) in which could significantly disrupt the stability of the bank's activities and/or the stability of the banking system. (amended by bullet points based on the Resolution of the Board of Directors of the Central Bank of the Republic of Uzbekistan No. 37/6 dated December 5, 2024 (registration number 3427-1, dated January 21, 2025) — , January 24, 2025, No. 10/25/3427-1/0066. Date of entry into force — April 24, 2025)
Chapter 2. Risk Management System
the organizational structure of risk management;
the culture of risk management;
the bank's internal processes, documents, and tools for risk management;
an information system intended for risk management and preparation of reports.
a clear distribution of tasks, responsibilities, and authorities among all structural divisions and employees of the bank regarding risk management, taking into account conflicts of interest;
the separation of departments responsible for risk management from the department responsible for internal control through the formation of a three-line defense model in accordance with paragraph 4 of this Regulation;
the coverage of at least significant risks in all directions of the bank's activities and its organizational structure;
the objective and timely identification, assessment, and monitoring of significant risks, the preparation of reports on them, their control, and reduction;
the formation of prices established for bank services taking into account the risks and costs associated with these services;
the completeness and documentation of risk management processes.
first line of defense — structural divisions directly responsible for providing bank services. These divisions accept risks and provide reports on the current management of risks;
second line of defense — departments responsible for risk management and other departments with supervisory functions. These divisions identify and manage risks;
third line of defense — internal audit service. This division checks and evaluates the risk management system.
4¹. The bank's risk management system may include other risks besides significant ones, depending on the characteristics of the bank's activities.
In this case, the bank must ensure that these risks are identified on time, assessed, monitored, reported on, controlled, and reduced. (amended by paragraph 4¹ based on the Resolution of the Board of Directors of the Central Bank of the Republic of Uzbekistan No. 37/6 dated December 5, 2024 (registration number 3427-1, dated January 21, 2025) — , January 24, 2025, No. 10/25/3427-1/0066. Date of entry into force — April 25, 2025)
If the bank is the parent bank of a banking group, it must prepare consolidated financial and regulatory reports for the banking group and manage risks arising in the banking group based on these reports.
The parent bank consolidates the balance sheets of financial institutions belonging to the banking group based on International Financial Reporting Standards (IFRS).
The parent bank periodically calculates (at least once a year) consolidated prudential norms for the banking group, including capital adequacy ratios, liquidity ratios, maximum exposure to a single borrower or a group of related borrowers, and maximum exposure to related parties of banks. The parent bank must submit these calculations to the Central Bank within one month from the date the bank's annual financial report is submitted to the Central Bank. (amended by the last sentence of paragraph 7 based on the Resolution of the Board of Directors of the Central Bank of the Republic of Uzbekistan No. 37/6 dated December 5, 2024 (registration number 3427-1, dated January 21, 2025) — , January 24, 2025, No. 10/25/3427-1/0066. Date of entry into force — April 24, 2025)
Chapter 3. Internal Documents of the Bank Regarding Risk Management
§ 1. Organization of Preparation of Internal Documents of the Bank Regarding Risk Management
risk appetite statement;
credit (financing) policy (hereinafter referred to as "credit policy"); (amended by the third bullet point of paragraph 8 of the Resolution of the Board of Directors of the Central Bank of the Republic of Uzbekistan No. 19/10 dated July 8, 2026 (registration number 3427-2, dated July 27, 2026) — , July 27, 2026, No. 10/26/3427-2/0788)
risk management policy (policies) including methodologies for identifying each significant risk;
policy for introducing new products of the bank;
procedure for conducting stress tests;
plan for restoring the bank's financial condition;
organizational structure of risk management;
other documents in accordance with this Regulation.
§ 2. Bank's Risk Appetite Statement and Risk Limits
correspond to the bank's strategy, business plan, budget planning, and internal documents of the bank specified in paragraph 8 of this Regulation; (amended by the second bullet point of paragraph 10 of the Resolution of the Board of Directors of the Central Bank of the Republic of Uzbekistan No. 37/6 dated December 5, 2024 (registration number 3427-1, dated January 21, 2025) — , January 24, 2025, No. 10/25/3427-1/0066. Date of entry into force — April 25, 2025)
include the main assumptions used in the process of forming risk appetite;
include procedures for approving risk limits, continuous monitoring, and preparing reports on them;
define the form and procedure for notifying the bank's governing bodies, relevant structural divisions, and employees in case of violation of risk limits;
include the methodology and procedure for calculating indicators included in the risk appetite, including the composition of responsible employees and/or structural divisions participating in the calculation of risk appetite levels;
include quantitative indicators used in determining the aggregate amount of each significant risk, as well as qualitative characteristics defining the basis for accepting and reducing risks by the bank;
set acceptable levels higher than the established minimum levels for capital adequacy and liquidity ratios;
take into account bank expectations and stress test results;
take into account documents related to the bank's organizational structure and employee incentives;
be developed in a format that allows monitoring compliance with the risk appetite.
low level requiring no reduction in risk levels;
medium level requiring reduction in risk levels;
high level requiring reduction in risk levels.
To reduce the bank's susceptibility to significant risks, the bank must establish quantitative limits for significant risks. These risk limits must be within the scope of the risk appetite.
Risk limits must be established taking into account the volume and complexity of bank operations.
§ 3. Procedure for Conducting Stress Tests in the Bank
the list of risks subject to stress testing;
methodologies and tools for stress testing credit, liquidity, market, operational, country risks, and interest rate risk in the banking book; (amended by the third bullet point of paragraph 14 of the Resolution of the Board of Directors of the Central Bank of the Republic of Uzbekistan No. 37/6 dated December 5, 2024 (registration number 3427-1, dated January 21, 2025) — , January 24, 2025, No. 10/25/3427-1/0066. Date of entry into force — April 25, 2025)
structural divisions participating in stress testing, their tasks, responsibilities, and authorities in this process;
the procedure for reviewing stress test results and submitting them to the supervisory board, the risk management committee (if established), and the bank's management.
Stress testing in the bank must be conducted at least once a year. (amended by paragraph 15 of the Resolution of the Board of Directors of the Central Bank of the Republic of Uzbekistan No. 37/6 dated December 5, 2024 (registration number 3427-1, dated January 21, 2025) — , January 24, 2025, No. 10/25/3427-1/0066. Date of entry into force — April 25, 2025)
When stress testing credit risk, the bank must take into account:
the general economic situation in the country, including a decline in the country's economic indicators, slowdown in economic growth at the country level and across sectors of the economy;
the bank's specific internal factors, including the characteristics of the bank's lending (financing) activities and the composition of the credit (financing) portfolio (hereinafter referred to as "credit portfolio"). (amended by the third bullet point of paragraph 16 of the Resolution of the Board of Directors of the Central Bank of the Republic of Uzbekistan No. 19/10 dated July 8, 2026 (registration number 3427-2, dated July 27, 2026) — , July 27, 2026, No. 10/26/3427-2/0788)
scenario related to the emergence of a stress situation in the bank against the background of a stable state of the country's economy, including deterioration of asset quality, accumulation (concentration) of liabilities, significant decrease in highly liquid assets, downgrade of the bank's credit rating, information attack on the bank, problems related to the bank's shareholders;
scenario related to the emergence of a stress situation in the bank resulting from a crisis in the country's banking system.
withdrawal of funds of physical and legal entities from the bank;
devaluation of highly liquid assets in the bank and/or lack of opportunity to use them;
loss or significant decrease in the ability to attract funds;
loss or significant decrease in the ability to attract financial resources from the interbank resource market;
significant decrease in the ability to redistribute liquidity from one currency to another.
changes in exchange rates of foreign currencies in the open currency position;
changes in market prices of financial instruments;
changes in variable interest rates in the market at various levels;
changes in revenues on interest-rate-sensitive financial instruments resulting from changes in market interest rates;
changes in the bank's profitability indicators;
changes in the difference between interest rates on attracted and placed funds by the bank.
The bank must apply stress test results in planning the bank's strategy and budget, including capital and liquidity, and in developing bank policies and the risk management process.
Based on stress test results, the bank must develop an emergency additional financing plan for the bank (hereinafter referred to as "emergency financing plan") once a year.
The emergency financing plan must include:
the procedure for identifying liquidity crisis in the bank, including early warning indicators regarding liquidity risk and notification of the supervisory board and bank management to take measures against liquidity crisis;
a list of countermeasures and their priority levels considering various sources of liquidity, their availability, conditions for attracting (using) liquidity sources, and their stability, aimed at ensuring liquidity and covering cash flow shortages in emergency situations;
sources available for use in emergency situations;
the time required to attract additional funds from liquidity sources in emergency situations;
the procedure for decision-making and interaction, including necessary measures for decision-making and responsible persons for decision-making;
the procedure for submitting information to the Central Bank regarding the causes of liquidity crisis in the bank and measures taken to eliminate them;
the procedure for submitting reports to the supervisory board and bank management.
§ 4. Introduction of New Products by the Bank
A relevant decision must be adopted, assessed, and documented regarding the introduction of new products in the bank.
The following must be assessed when introducing a new product of the bank:
the economic justification of the project for introducing the bank's new product;
the compliance of the bank's new product with the requirements established by legislative acts and the bank's internal documents;
the risks associated with the bank's new product, their impact on the bank's risk profile, risk appetite, prudential norms, including capital adequacy and liquidity indicators, as well as profitability levels;
the availability of sufficient internal tools for monitoring and managing risks associated with the bank's new product;
the compliance of the price set for the bank's new product with the bank's pricing policy;
the bank's readiness to introduce the new product, including the availability of qualified staff for introducing the new product, uninterrupted service provision, and modifications made to the technological infrastructure.
Chapter 4. Culture of Risk Management in Banks
The supervisory board is responsible for the formation of the culture of risk management in the bank.
To ensure the culture of risk management in the bank, the following measures must be taken:
information must be provided to employees about their role in risk management, informing them that they are responsible for compliance with the risk appetite and risk limits established by the bank;
the bank's corporate values, competence standards, code of ethics, and other relevant internal documents must be constantly brought to the attention of employees, and supervision in this area must be established;
the bank's management and employees must be informed about the application of disciplinary measures for unacceptable behavior and/or rule violations, and supervision over this matter must be carried out;
seminars and trainings must be conducted so that employees have knowledge about significant risks and their duties in managing these risks;
internal and external communication systems that are constantly open to everyone in the bank must be organized.
Chapter 5. Organizational Structure of Risk Management
§ 1. Organization of Activities of the Organizational Structure of Risk Management
The organizational structure of risk management must provide for a clear distribution of tasks, responsibilities, and authorities among participants involved in risk management in the bank.
The organizational structure of risk management must consist of:
the supervisory board;
Risk management committee established under the Supervisory Board (if established) and the audit committee;
Internal audit service;
Bank management;
Credit committee, committee responsible for managing bank assets and liabilities;
Structural subdivision responsible for risk management (hereinafter referred to in the text as the risk subdivision);
Structural subdivision responsible for managing compliance risk;
Other committees and structural subdivisions responsible for monitoring significant risks;
Structural subdivisions responsible for providing bank services.
Section 2. Duties of the Supervisory Board in Risk Management
The Supervisory Board is responsible for ensuring the effective implementation of the risk management system in accordance with the requirements of this Regulation and other legislative acts, and for exercising control over it.
To ensure risk management, the Supervisory Board must perform the following duties:
approve the internal documents specified in paragraph 8 of this Regulation and exercise control over their implementation, compliance, and timely updates;
approve risk limits for each significant risk and the measures necessary to be taken in case of breach of these limits;
constantly evaluate the organizational structure of the bank's risk management and ensure its effectiveness;
review the methodology for assessing risks used by the bank at least once a year;
approve the pricing policy for bank products and services, taking into account costs and risks;
determine the form, frequency, and volume of reports on risk management, review these reports, and continuously monitor their accuracy and fairness;
organize the implementation of the information system for risk management and reporting and control the work in this area;
form a risk management culture and ensure its acceptable level;
exercise control over the elimination of deficiencies identified in the risk management system, including the consideration and implementation of suggestions and comments provided by the internal audit service, external auditors, the Central Bank, and other regulatory authorities;
discuss in detail the risk appetite statement, risk management policy (policies), and (or) operations or actions that may lead to a breach of risk limits;
take necessary measures to reduce risks if the bank's risk profile does not correspond or is expected not to correspond to the approved risk appetite;
determine tiered requirements for bank capital based on internal processes for assessing capital adequacy (ICAAP) (if implemented), stress tests, and risk characteristics;
if the bank is the main bank of a banking group, review reports submitted by the risk subdivision on consolidated prudential norms, determine measures to eliminate identified deficiencies, and control their implementation; See previous edition.
make decisions on entering into major risk transactions. In this context, a major risk is understood as risks for a borrower or a group of interrelated borrowers with a total amount equal to or exceeding 10 percent of the bank's Tier 1 capital. (Paragraph 29 was supplemented with a bullet point based on Resolution No. 37/6 of the Management Board of the Central Bank of the Republic of Uzbekistan dated December 5, 2024 (Registration No. 3427-1, dated 21.01.2025) — , dated 24.01.2025, No. 10/25/3427-1/0066. Entry into force date — April 24, 2025)
To ensure the independence of the risk subdivision and the structural subdivision responsible for managing compliance risk, these subdivisions:
must report directly to the Supervisory Board and the risk management committee (if established);
their heads must be appointed by the Supervisory Board and be accountable to the Supervisory Board;
the amount of incentives for their heads must be determined by the Supervisory Board, the remuneration committee (if established), or the risk management committee (if established);
the amount of incentives for their heads and employees must not depend on the results of the activities of structural subdivisions responsible for providing bank services. In this case, the amount of incentives may depend on the overall financial condition of the bank;
measures must be taken to prevent situations where bank management and other executive officers exert pressure on their heads and employees;
their heads must have the opportunity to conduct direct discussions with the Supervisory Board regarding the state of risks in the bank without informing bank management;
it must be ensured that their heads continuously work between the Supervisory Board and the risk management committee (if established);
the number and qualification level of their employees must correspond to the tasks and objectives defined in this Regulation and the bank's internal documents;
their heads and employees must not conduct bank operations related to receiving income, nor participate in the composition of committees and various working groups unrelated to the subdivision's activities, nor hold other positions simultaneously;
the hiring, dismissal, and determination of incentive amounts for their employees must be carried out by the Chairman of the Bank Management based on the recommendations of the heads of these structural subdivisions;
they must have the opportunity to fully use the information necessary for performing their duties.
Section 3. Duties of Bank Management in Risk Management
Bank Management must ensure the effective operation of the risk management system in accordance with the risk appetite statement, risk management policy (policies), and other internal documents of the bank approved by the Supervisory Board.
Bank Management must perform the following duties related to risk management:
approve detailed procedures and measures as needed based on policies and documents approved by the Supervisory Board within its authority, and evaluate their relevance and appropriateness at least once a year;
take necessary measures to implement the organizational structure of risk management, ensuring that employees at all levels of the bank are aware of their duties in risk management;
create the necessary conditions for the risk subdivision and the structural subdivision responsible for managing compliance risk to effectively perform their duties;
ensure the full implementation of processes aimed at analyzing all significant risks arising in the bank and ensuring their compliance with the bank's risk appetite;
ensure that prices (tariffs) for bank services are set taking into account the associated risks and costs;
ensure the preparation and quarterly submission to the Supervisory Board of reports reflecting information on the state of risks in the bank, breaches of risk appetite, significant changes in bank activities, and new bank products;
develop measures to eliminate deficiencies in the risk management system and implement suggestions and comments provided by the internal audit service, audit organizations, the Central Bank, and other regulatory authorities, and submit them to the Supervisory Board for approval; See previous edition.
submit reports on significant risks and measures to reduce them to the Central Bank quarterly, and stress test results at least once a year. (Paragraph 32 was supplemented with a bullet point based on Resolution No. 37/6 of the Management Board of the Central Bank of the Republic of Uzbekistan dated December 5, 2024 (Registration No. 3427-1, dated 21.01.2025) — , dated 24.01.2025, No. 10/25/3427-1/0066. Entry into force date — April 24, 2025)
Section 4. Duties of the Risk Subdivision
A regulation defining the duties, obligations, and powers of the risk subdivision in the bank must be developed and approved by the Supervisory Board.
The risk subdivision must perform the following duties:
develop and ensure the relevance of methodologies and tools used to analyze the impact of various factors on the bank's financial condition, risk profile, capital, and liquidity; See previous edition.
develop or participate in the development of methods for assessing credit, market, operational, liquidity, country risks, and interest rate risks arising in the bank portfolio; (The third bullet point of paragraph 34 was amended in the edition of Resolution No. 37/6 of the Management Board of the Central Bank of the Republic of Uzbekistan dated December 5, 2024 (Registration No. 3427-1, dated 21.01.2025) — , dated 24.01.2025, No. 10/25/3427-1/0066. Entry into force date — April 25, 2025)
ensure the timely identification, assessment, monitoring, reporting, control, and reduction of significant risks;
develop and implement early warning systems regarding the occurrence or imminent occurrence of situations causing risks. These systems must be used to identify, monitor, and develop necessary recommendations for approaching or breaching approved risk appetite and risk limits;
evaluate the relevance and effectiveness of the internal documents specified in paragraph 8 of this Regulation and prepare recommendations for their improvement;
review the risk assessment methods developed by the risk subdivision, including rating methods and (or) scoring systems for assessing credit risk;
evaluate the effectiveness of pricing policy to ensure that prices for bank services are formed taking into associated risks and costs; See previous edition.
evaluate risks associated with loans (financing) (hereinafter referred to in the text as loans), including the processes of identifying problematic assets, classifying asset quality, and assessing the appropriateness of forming reserves to cover potential losses; (The ninth bullet point of paragraph 34 was amended in the edition of Resolution No. 19/10 of the Management Board of the Central Bank of the Republic of Uzbekistan dated July 8, 2026 (Registration No. 3427-2, dated 27.07.2026) — , dated 27.07.2026, No. 10/26/3427-2/0788)
prepare conclusions on risks associated with new bank products before their introduction;
conduct stress tests;
evaluate the bank's risk profile and its compliance with the bank's risk appetite and risk limits at least once a year; See previous edition.
submit reports on credit, liquidity, market, operational, country risks, and interest rate risks in the bank portfolio, including existing or expected risks and measures to reduce them, to the Supervisory Board and the risk management committee (if established) quarterly, and to Bank Management at least once a month; (The thirteenth bullet point of paragraph 34 was amended in the edition of Resolution No. 37/6 of the Management Board of the Central Bank of the Republic of Uzbekistan dated December 5, 2024 (Registration No. 3427-1, dated 21.01.2025) — , dated 24.01.2025, No. 10/25/3427-1/0066. Entry into force date — April 25, 2025)
organize training and seminars at least once a year to form relevant knowledge among bank employees about significant risks;
submit proposals to the Supervisory Board or the risk management committee (if established) and Bank Management on determining tiered requirements for bank capital based on internal processes for assessing capital adequacy (ICAAP) (if implemented), stress tests, and risk characteristics;
if the bank is the main bank of a banking group, continuously analyze consolidated prudential norms and submit consolidated reports to the Supervisory Board, including information on the state of consolidated prudential norms, associated risks, and proposals for their elimination; See previous edition.
regularly assess the reliability and effectiveness of the bank's internal models intended for identifying, measuring, monitoring, and controlling risks, as well as conducting stress tests. (Paragraph 34 was supplemented with a bullet point based on Resolution No. 37/6 of the Management Board of the Central Bank of the Republic of Uzbekistan dated December 5, 2024 (Registration No. 3427-1, dated 21.01.2025) — , dated 24.01.2025, No. 10/25/3427-1/0066. Entry into force date — April 24, 2025)
submit relevant reports of the risk subdivision to the Supervisory Board, the risk management committee (if established), and Bank Management;
apply a veto (right of prohibition) to decisions of Bank Management and committees established at the head office that cause a breach of the bank's risk appetite or risk limits (strategic planning, planning capital and liquidity levels, introduction of new bank products and services, development of employee incentive policies, provision of large loans, implementation of investment operations) and immediately inform the Supervisory Board about this;
if decisions of Bank Management on risks differ significantly from the risk subdivision's comments, inform the Supervisory Board or the risk management committee (if established) about this;
submit proposals to the Supervisory Board, the risk management committee (if established), and Bank Management to reduce the impact of risks on the bank's financial condition, capital, and liquidity;
if the level of risks increases significantly and there is a need to take urgent measures, appeal to Bank Management to convene an emergency meeting of the Supervisory Board or the risk management committee (if established);
coordinate work on risk management, obtain and aggregate information necessary for risk management from relevant subdivisions. See previous edition.
35-1. If the employment contract with the head of the risk subdivision is terminated, the bank must provide information to the Central Bank within 5 days from the date the decision on termination of the employment contract is made, indicating the grounds and reasons for termination. (Paragraph 35-1 was added based on Resolution No. 37/6 of the Management Board of the Central Bank of the Republic of Uzbekistan dated December 5, 2024 (Registration No. 3427-1, dated 21.01.2025) — , dated 24.01.2025, No. 10/25/3427-1/0066. Entry into force date — April 25, 2025)
Section 5. Duties of the Structural Subdivision Responsible for Managing Compliance Risk See previous edition.
To control compliance with legislative acts, documents of foreign countries that may affect bank activities, and the bank's internal documents, a structural subdivision responsible for managing compliance risk must be established, and a regulation defining its duties, obligations, and powers must be developed and approved by the Supervisory Board. (Paragraph 36 was amended in the edition of Resolution No. 37/6 of the Management Board of the Central Bank of the Republic of Uzbekistan dated December 5, 2024 (Registration No. 3427-1, dated 21.01.2025) — , dated 24.01.2025, No. 10/25/3427-1/0066. Entry into force date — April 25, 2025)
The structural subdivision responsible for managing compliance risk must perform the following duties:
develop a policy on managing compliance risk and submit it to the Supervisory Board for approval;
develop and implement procedures and processes for identifying, assessing, monitoring, and controlling compliance risk;
develop and implement internal documents aimed at combating the legalization of income from criminal activities, financing of terrorism, and financing of the proliferation of weapons of mass destruction;
manage risks related to conflicts of interest that may arise in all links of the bank's organizational structure, and immediately inform the Supervisory Board or its committees if situations indicating the existence of a conflict of interest are identified;
identify, assess, and establish monitoring of compliance risks related to bank activities, including the introduction of new bank products;
provide recommendations to Bank Management on managing compliance risk, as well as provide employees of the bank with concepts regarding legislation, rules, and standards related to bank activities, monitor changes in them, continuously evaluate the impact of these changes on bank activities, and ensure that appropriate changes are made to the bank's internal documents;
coordinate activities aimed at familiarizing bank employees with legislative acts and the requirements of the bank's internal documents, as well as conduct training sessions for employees on compliance with legislative requirements;
prepare conclusions on compliance risks related to the introduction of new bank products, amendments to existing products, and changes in bank activities;
prepare and submit quarterly reports to the Supervisory Board or the risk management committee (if established) and Bank Management on managing compliance risk, including information on identified violations, deficiencies, and their causes, and reports on reducing and eliminating compliance risks;
participate in the development of the bank's internal documents specified in paragraph 8 of this Regulation.
The structural subdivision responsible for managing compliance risk must develop an annual plan for checking the compliance of other structural subdivisions with legislative acts and the bank's internal documents, and for training employees on issues of managing compliance risk, and submit it to the Supervisory Board or the risk management committee (if established) for approval.
The head of the structural subdivision responsible for managing compliance risk must submit a report on the work performed to the Supervisory Board or the risk management committee (if established) at least twice a year.
Chapter 6. Information System for Risk Management and Reporting
An information system for risk management must be implemented in the bank, which allows collecting and aggregating information on all areas of bank activity, reliably assessing risks in the context of the bank and banking groups, and preparing reports on risks.
The information system for risk management must correspond to the nature, volume, and complexity of bank operations and must ensure:
the fairness of information on risks;
the completeness and flexibility of information;
the formation and timely submission of reports.
Section II. Requirements for Risk Management
Chapter 7. Requirements for Managing Credit Risk
Section 1. Credit Risk Management System
A credit risk management system serving to identify, assess, monitor, control, and reduce credit risk must be implemented in the bank.
The credit risk management system must include:
the established risk appetite for credit risk;
credit policy and credit risk management processes;
the process of making decisions on granting credit;
the process of classifying asset quality and forming reserves to cover potential losses on assets;
the procedure for identifying problematic assets and working with them;
the procedure for stress testing credit risk;
internal processes for assessing capital adequacy (ICAAP) (if implemented);
the process of reporting on credit risk.
the bank's claims on credit, including debt, credit, microcredit, microloan, leasing, overdraft (debit balance on customers' deposit accounts), factoring, Islamic finance operations; (The second bullet point of paragraph 44 was amended in the edition of Resolution No. 19/10 of the Management Board of the Central Bank of the Republic of Uzbekistan dated July 8, 2026 (Registration No. 3427-2, dated 27.07.2026) — , dated 27.07.2026, No. 10/26/3427-2/0788)
funds that must be received from banks and other financial organizations;
off-balance sheet liabilities with existing credit risk, including unused credit lines, uncallable liabilities, other liabilities for lending, trade financing (letters of credit, guarantees, and sureties);
claims on the bank's balance sheet for derivative instruments and other assets with existing credit risk.
Section 2. Requirements for Risk Appetite for Credit Risk
The bank's risk appetite statement must specify the bank's risk appetite for credit risk, which involves the total credit risks the bank is ready to accept in achieving its strategic goals and business plan indicators.
The risk appetite for credit risk must include the following quantitative indicators:
the maximum amount of the share of loans in the bank's total assets;
the maximum level of annual growth of the credit portfolio (in all currencies and in the context of each currency);
the maximum amount of the ratio of risk for a single borrower, a group of interrelated borrowers, including persons related to the bank, to the bank's Tier 1 capital;
the maximum amount of the share of types of credit products in the bank's total credit portfolio;
the maximum amount of the share of problematic assets (loans) in the bank's total credit portfolio and in the context of types of credit products.
3-§. Requirements for Credit Policy and Credit Risk Management
The process of organizing lending and managing credit risk in a bank must be carried out within the framework of the credit policy approved by the Supervisory Board.
For the purpose of organizing the lending process in a bank, the credit policy must include:
a description of the main directions of asset allocation in the presence of credit risk, including target directions of lending by economic sector, currency type, term, collateral type, and/or credit products; (See previous edition).
a description of the process of reviewing (ordering) credit applications, approving them, and making decisions to grant or refuse credit; (Paragraph 49 was supplemented with the third subparagraph based on Resolution No. 37/6 of the Board of the Central Bank of the Republic of Uzbekistan dated December 5, 2024 (Registration No. 3427-1, dated January 21, 2025) — , dated January 24, 2025, No. 10/25/3427-1/0066. Entry into force date — April 24, 2025)
general principles for assessing borrowers' solvency and analyzing their financial condition; (See previous edition).
a description of lending limits taking into account the results of the analysis of borrowers' solvency; (Paragraph 49 was supplemented with the fifth subparagraph based on Resolution No. 37/6 of the Board of the Central Bank of the Republic of Uzbekistan dated December 5, 2024 (Registration No. 3427-1, dated January 21, 2025) — , dated January 24, 2025, No. 10/25/3427-1/0066. Entry into force date — April 24, 2025)
requirements for the types of collateral and their valuation, and the degree of secured nature of the credit (debt);
requirements for granting unsecured loans (reliance-based loans);
general principles for setting prices (tariffs) for credit products; (See previous edition).
clear boundaries of responsibility among the bank's management bodies, committees, and structural subdivisions, including branches, in making decisions on credit allocation; (The ninth subparagraph of Paragraph 49 was edited in accordance with Resolution No. 37/6 of the Board of the Central Bank of the Republic of Uzbekistan dated December 5, 2024 (Registration No. 3427-1, dated January 21, 2025) — , dated January 24, 2025, No. 10/25/3427-1/0066. Entry into force date — April 25, 2025)
the powers of all persons responsible for lending;
the frequency of credit committee meetings and their reporting to the bank's management bodies.
the organizational structure of the risk management system, taking into account the distribution of duties, powers, and obligations of the participants in the credit risk management system, as well as the procedure for interaction;
the procedure for defining the boundaries of credit risk;
the procedure for identifying, assessing, monitoring, controlling, reducing credit risk, and reporting on credit risk;
requirements for implementing credit risk management and monitoring; (See previous edition).
requirements for the early (initial stage) identification of problematic assets; (The sixth subparagraph of Paragraph 50 was edited in accordance with Resolution No. 19/10 of the Board of the Central Bank of the Republic of Uzbekistan dated July 8, 2026 (Registration No. 3427-2, dated July 27, 2026) — , dated July 27, 2026, No. 10/26/3427-2/0788)
requirements regarding the accumulation (concentration) of credits, including by credit products, economic sectors, regions, type of collateral security, currency, and borrower groups;
requirements for stress-testing credit risk;
the forms of reports prepared on credit risk control, the procedure for their submission, and their frequency.
the identification, assessment, monitoring, control, and reduction of credit risk;
the list of documents that the borrower must submit to the bank;
the transparent registration and review of credit applications, and the assessment of borrowers' solvency;
the analysis of the borrower's ability to repay the credit and their financial condition if the borrower takes a credit in foreign currency;
the making of decisions on lending, including the provision of credits or the refusal of an application for lending;
the frequency of meetings of the credit committee(s);
the valuation of collateral;
the review of credit terms;
the exchange of information among participants in the credit risk management process;
the stress-testing of credit risk;
the preparation of reports submitted to the Central Bank on credit risk and the verification of their reliability. (See previous edition).
51-1. The Supervisory Board must control the following in the management of credit risks:
that credits are allocated within the bank's risk appetite, including within the framework of the risk management strategy and business plan;
that the credit allocation process is reflected in the bank's credit policy and relevant documents;
that it has an information system covering:
51-2. For the purpose of effective management of credit risk, the bank must take into account:
the diversification of the credit portfolio;
the debt burden level of borrowers;
the ratio of the credit to the value of the collateral (if the credit is secured);
the share of insured credits in total credits and the level of accumulation (concentration) with respect to insurance organizations;
the financial condition of guarantors (sureties), including insurers; (See previous edition).
the expected maximum losses in the credit portfolio, the share of problematic assets, and the level of written-off assets. (The seventh subparagraph of Paragraph 51-2 was edited in accordance with Resolution No. 19/10 of the Board of the Central Bank of the Republic of Uzbekistan dated July 8, 2026 (Registration No. 3427-2, dated July 27, 2026) — , dated July 27, 2026, No. 10/26/3427-2/0788)
51-3. When assessing credit risk for a counterparty that has rating scores issued by rating agencies, the bank must not be limited to using these rating scores but must take measures to independently and objectively comprehensively assess the financial condition of such counterparty. (Paragraphs 51-1 to 51-3 were introduced based on Resolution No. 37/6 of the Board of the Central Bank of the Republic of Uzbekistan dated December 5, 2024 (Registration No. 3427-1, dated January 21, 2025) — , dated January 24, 2025, No. 10/25/3427-1/0066. Entry into force date — April 25, 2025)
4-§. Requirements for Monitoring Credits
To ensure the timely repayment of credits and to identify problems at the initial stage, the bank must develop and implement a system for monitoring credits individually and by portfolio.
The credit monitoring system includes:
the formation and maintenance of the borrower's credit documents (in electronic or paper form);
the verification of the borrower's credit documents;
the monitoring of the targeted use of the credit (if the targeted use is specified in the credit agreement);
the monitoring of the borrower's financial condition and the fulfillment of the terms of the credit agreement regarding the payment of principal debt and interest;
the monitoring of the borrower's compliance with other terms of the credit agreement;
the monitoring of the availability, sufficiency, and integrity of collateral, as well as the re-evaluation of its market value;
the monitoring of the volume of credit risk and the sufficiency of reserves for covering potential losses thereon. (See previous edition).
53-1. The assessment and re-assessment of the market value of the collateral subject to the credit is carried out within the deadlines established by the bank's internal documents in accordance with the Law of the Republic of Uzbekistan "On Valuation Activities" and other legislative acts.
53-2. The procedure and principles for assessing and re-assessing the market value of the collateral subject to the credit must be approved by the bank's management. (Paragraphs 53-1 and 53-2 were introduced based on Resolution No. 37/6 of the Board of the Central Bank of the Republic of Uzbekistan dated December 5, 2024 (Registration No. 3427-1, dated January 21, 2025) — , dated January 24, 2025, No. 10/25/3427-1/0066. Entry into force date — April 25, 2025)
The types of credit monitoring, the procedure for conducting them, and their frequency must be determined based on the volume of the bank's credit portfolio, the type of credit, its amount, the level of risk, and other factors.
The structural subdivision responsible for monitoring credits must establish a system for informing the bank's management about problems related to the repayment of credits.
5-§. Requirements for Identifying and Working with Problematic Assets
first stage — early identification of borrowers who may face financial difficulties;
second stage — re-examination of the terms of the contract concluded with the borrower;
third stage — implementation of measures aimed at terminating relations with the borrower using out-of-court and/or court methods of debt recovery;
fourth stage — management of recovered property.
approving the policy for working with problematic assets;
studying the state of problematic assets in the bank quarterly, analyzing the causes of the emergence of problematic assets, and determining measures to reduce problematic assets;
defining the duties of the bank's management in working with problematic assets and managing recovered property;
other duties in accordance with this Regulation and legislative acts.
developing a draft policy for working with problematic assets and submitting it to the Supervisory Board for approval;
developing a strategic plan for working with problematic assets (hereinafter referred to as the strategic plan) if necessary, or approving it if authorized by the Supervisory Board;
submitting reports to the Supervisory Board quarterly on the state of problematic assets in the bank, the implementation of the policy for working with problematic assets, and, if necessary, the strategic plan;
making decisions on the management of problematic assets within the scope of powers granted by the Supervisory Board;
making decisions on the management of recovered property within the scope of powers granted by the Supervisory Board;
establishing criteria for evaluating the effectiveness of the activities of employees responsible for working with problematic assets and evaluating this process;
ensuring the introduction of necessary information systems for managing problematic assets.
The bank must organize a separate structural subdivision specialized in working with problematic assets (hereinafter referred to as the problematic assets working subdivision) and ensure its impartiality and independence.
For the purpose of ensuring the impartiality and independence of the problematic assets working subdivision, this structural subdivision:
must be separate from the structural subdivisions responsible for credit allocation and credit risk management;
must be subordinate to a member of the bank's management other than the member responsible for coordinating the activities of the structural subdivisions responsible for carrying out bank asset operations;
must have a sufficient number and qualification of employees for the effective management of the bank's problematic assets;
must be provided with necessary software and technical support; (See previous edition).
the amount of incentives for employees must not depend on the profitability indicators of the bank's credits and/or Islamic finance operations, nor should it create future conflicts of interest or affect their independence and impartiality. In this regard, the amount of incentives may depend on the overall financial condition of the bank; (The sixth subparagraph of Paragraph 60 was edited in accordance with Resolution No. 19/10 of the Board of the Central Bank of the Republic of Uzbekistan dated July 8, 2026 (Registration No. 3427-2, dated July 27, 2026) — , dated July 27, 2026, No. 10/26/3427-2/0788)
must have the authority to request necessary information, including minutes, records, and other documents (in electronic and/or paper form) from relevant structural subdivisions for its activities;
if an employee who participated in making a decision to allocate an asset as part of another structural subdivision before being included in the staff list, and this asset becomes problematic, they must not participate in its management.
assessing the borrowers of problematic assets;
developing proposals for re-examining the terms of problematic assets and submitting them to the bank's management for approval;
developing standardized decisions on the management of problematic assets and submitting them to the bank's management for approval;
participating in making amendments to the contract of a problematic asset whose terms are being re-examined or concluding a new contract for this asset;
controlling the borrower's compliance with the updated terms after the asset terms have been re-examined;
coordinating the activities of the bank's structural subdivisions in managing problematic assets;
developing or participating in the development of the bank's internal documents on the management of problematic assets;
preparing reports on the management of problematic assets and submitting them to the bank's management;
establishing requirements for information systems necessary for the management of problematic assets;
developing or participating in the development of the bank's internal documents related to the process of re-examining asset terms.
the description of problematic assets;
the procedure for early identification of problematic assets;
measures after the identification of problematic assets, including the procedure for working with debtors and the criteria for transferring credits to the problematic assets working subdivision;
the methods and tools used by the bank in working with problematic assets, including re-examining problematic asset terms, selling them, writing them off, directing recovery to collateral security, and the procedure for declaring the borrower insolvent;
the procedure for interaction between the bank's structural subdivisions in working with problematic assets;
the list and forms of reports on problematic assets;
the procedure for evaluating the effectiveness of measures taken by the bank in managing problematic assets. (See previous edition).
62-1. The bank's management must periodically (at least once a year) evaluate the effectiveness of the policy for working with problematic assets and submit the results of the evaluation to the Supervisory Board within 5 days from the day the evaluation results are ready, and to the Central Bank within 15 days. (Paragraph 62-1 was introduced based on Resolution No. 37/6 of the Board of the Central Bank of the Republic of Uzbekistan dated December 5, 2024 (Registration No. 3427-1, dated January 21, 2025) — , dated January 24, 2025, No. 10/25/3427-1/0066. Entry into force date — April 25, 2025)
If the share of the bank's problematic assets in total assets exceeds five percent for five consecutive months within the last three months, the bank must develop a strategic plan and specify clear goals and deadlines for reducing the share of problematic assets in it.
The strategic plan:
must be approved by the Supervisory Board or, if authorized, by the bank's management for a period of not less than one year;
must be communicated to the relevant structural subdivisions of the bank;
must be submitted to the Central Bank within 15 days from the date of approval or amendment.
the reduction of the amount and volume of problematic assets;
the reduction of the volume of recovered property from problematic assets;
an assessment of the bank's internal capabilities for working with problematic assets, including reducing problematic assets within the specified timeframe;
an assessment of external factors, including macroeconomic, legal, judicial, and regulatory system conditions;
target quantitative indicators and methods for reducing problematic assets by credit portfolio (including mortgages, consumer credits, credits granted under state programs, credits to small business and other entrepreneurial entities) (including re-examining problematic asset terms, selling them, writing them off, directing recovery to collateral security, and declaring the borrower insolvent);
measures to be taken by groups (segmented) credit portfolios.
the borrower's refusal to contact the bank;
the borrower's submission of information about their financial condition late and/or in an incomplete volume, and the bank's doubt about the reliability of this information;
the failure to make payments on principal debt and interest on time;
the failure to submit necessary financial reports or documents for conducting credit monitoring;
the commercial, operational, and/or financial difficulties of the borrower;
the violation of the terms of the credit agreement;
the borrower's request to re-examine credit terms due to a worsening of their financial situation;
known negative information about the borrower;
external factors that may have a negative impact on the borrower's financial condition.
6-§. Requirements for Internal Processes for Assessing Capital Adequacy (ICAAP)
The Supervisory Board may introduce internal processes for assessing capital adequacy in the bank to ensure the effectiveness of the management process.
Internal processes for assessing capital adequacy must ensure the opportunity to constantly assess the bank's risk profile and the adequacy of the bank's capital adequacy level with respect to it.
Internal processes for assessing capital adequacy are developed based on the bank's internal documents, including the bank's strategy, and are specified in a separate document approved by the Supervisory Board. Within the framework of internal processes for assessing capital adequacy, the bank:
defines, assesses, measures, and prepares reports on the risks necessary for internal calculation of capital adequacy;
must plan capital sources and maintain them at the necessary level to ensure the adequacy of the capital adequacy level with respect to the risk profile.
In internal processes for assessing capital adequacy, the bank's strategic goals and their relationship with macroeconomic factors are taken into account.
To ensure the effectiveness of internal processes for assessing capital adequacy, the Supervisory Board approves a capital plan including:
7-§. Requirements for Reports on Credit Risk
The form, frequency, and volume of reports on credit risk management are determined by the Supervisory Board or the bank's management.
Reports on credit risk must include the following information:
the level (concentration) of credit portfolio accumulation;
the volume and dynamics of the credit portfolio, including the dynamics of the volume of re-examined, problematic, and written-off assets;
the level of credit risk, including situations of approaching or violating the established boundaries for credit risk;
the level and dynamics of risk for interrelated borrowers;
the level and dynamics of reserves formed to cover potential losses;
the status of work being done on problematic assets;
the share and dynamics of credits allocated in deviation from the credit policy;
the level and dynamics of the credit portfolio taking into account risks;
the results of stress testing on credit risk.
8-Chapter. Requirements for Managing Liquidity Risk
1-§. Liquidity Risk Management System
A liquidity risk management system serving to identify, assess, monitor, control, and reduce liquidity risk must be introduced in the bank.
The liquidity risk management system includes:
the risk appetite for liquidity risk;
the policy and procedures for managing liquidity risk;
the tools for assessing and monitoring liquidity risk;
the procedure for managing liquidity during the bank's working day;
the conduct of stress testing on liquidity risk;
the reporting on liquidity risk.
2-§. Requirements for Risk Appetite for Liquidity Risk
The bank's statement of risk appetite for liquidity risk must include the risk appetite for liquidity risk to ensure the full and timely fulfillment of the bank's payment (settlement) obligations to the Central Bank without emergency assistance during stress periods.
The risk appetite for liquidity risk must include the following quantitative indicators:
the minimum share of high-liquidity assets in total assets;
the boundary indicators of the liquidity coverage ratio coefficient and the net stable funding ratio coefficient;
the maximum value of the negative generalized difference between cash inflows and outflows in the time interval of 30 days to one year, determined based on the analysis of mismatches between the terms of liabilities and assets;
the maximum value of the accumulation (concentration) of funds related to the bank's single largest depositor and/or creditor, as well as the twenty largest depositors and/or creditors, and persons related to them.
3-§. Requirements for Liquidity Risk Management Policy and Procedures
the organizational structure of the liquidity risk management system, taking into account the distribution of duties, powers, and responsibilities of the participants in the risk management system and their interaction procedures;
the procedure for establishing liquidity risk limits;
the requirements for identifying, assessing, monitoring, controlling, mitigating liquidity risk, and reporting on liquidity risk;
the procedure for managing liquidity risk during the bank's working day;
the principles of diversification of assets and funding sources;
the list and composition of alternative sources in case of inability to attract resources from the market and counterparties;
the requirements for stress-testing liquidity risk;
the forms of reports on liquidity risk, the procedure for their submission, and their frequency.
These processes may include:
the procedure for identifying, assessing, monitoring, controlling, and reducing liquidity risk;
the requirements for the volume and composition (structure) of highly liquid assets that the bank plans to hold to cover potential liquidity shortages;
the list of stable funding sources;
the list of early warning indicators of liquidity shortage occurrence or potential occurrence;
the procedure for identifying, approving, and reviewing the assumptions used to assess liquidity risk;
the procedure for information exchange among participants in the liquidity risk management process, including the forms and deadlines for information submission;
the procedure for stress-testing liquidity risk;
the procedure for preparing and verifying the reliability of reports submitted to the Central Bank on liquidity risk.
Section 4. Requirements for Liquidity Risk Management and Monitoring
liquidity coefficients and mandatory reserve requirements established by the Central Bank;
accumulation (concentration) of obligations to major counterparties (creditors and depositors);
expected and/or contractual maturity mismatches of assets and liabilities (cash flow mismatches) in main currencies and time intervals independently established by the bank;
the volume, currency, and main characteristics of assets owned by the bank that are not included in the category of highly liquid assets but can be pledged to attract additional financing from the secondary market in stress-test scenarios;
the interdependence between the bank's existing liquidity risk and other types of risks.
situations where internal limits established by the bank approach the prudential norms of the Central Bank;
the emergence or worsening of mismatches in the maturity of assets and liabilities within thirty days, ninety days, and one year;
an increase in the difference between the currencies of the bank's highly liquid assets and liabilities;
an intensification of deposit withdrawal situations due to internal and external factors, including macroeconomic and socio-political conditions;
an increase in risks related to off-balance sheet items and the bank's contingent liabilities;
actual or potential violation of contractual terms that could lead to the early repayment of obligations by counterparties;
a reduction in credit lines that can be drawn from other banks;
the rapid increase in assets due to various factors, including unstable sources;
the spread of negative information about the bank in the mass media;
a decrease in the bank's credit rating (if available);
an increase in costs associated with funding assets;
a shortening of the average repayment period for obligations;
situations that may have a negative impact on the liquidity risk profile, including an increase in the volume of the bank's problem assets or its operating at a loss;
difficulties in attracting long-term funding sources.
The following systems must be established in the bank to identify the following situations:
accumulation (concentration) of large amounts of obligations;
the emergence of liquidity shortage and/or a decrease in the opportunity to ensure liquidity;
a significant decrease in the volume of highly liquid assets;
the occurrence of changes in the market that may lead to liquidity-related problems.
Section 5. Requirements for Managing Liquidity During the Bank's Working Day
a description of the participants in the liquidity risk management process during the bank's working day, their duties, powers, responsibilities, and interaction procedures;
monitoring of the liquidity situation taking into account the daily expected income and expenses;
the determination of the volume of potential liquidity shortage that may arise during the bank's working day;
the identification of major customers forming the main part of the volume of funds inflow or outflow and the forecasting of income or expenses for them;
situations requiring a separate procedure for working with liquidity risk during the bank's working day;
the assessment of the liquidity of assets owned by the bank that can be used as collateral to attract additional financing;
the procedure for managing liquidity in stressful situations during the bank's working day.
Section 6. Requirements for Reports on Liquidity Risk
The form, frequency, and volume of reports on liquidity risk are determined by the Supervisory Board or the bank's management.
Reports on liquidity risk must include the following information:
the bank's indicators and their dynamics regarding liquidity coefficients and mandatory reserve requirements established by the Central Bank;
the volume, composition, and dynamics of highly liquid assets;
the level and dynamics of other liquidity indicators, their compliance with established limits, and the results of the analysis of mismatches regarding them;
violations of liquidity limits, limit values, reasons for limit violations, and proposals for eliminating the situation;
the level and dynamics of the accumulation (concentration) of assets and liabilities for major counterparties (including related counterparties, sources);
the results of liquidity risk assessment during the bank's working day;
early warning indicators of liquidity risk (if necessary);
the results of stress-testing liquidity risk.
Chapter 9. Requirements for Market Risk Management
Section 1. The Bank's Market Risk Management System
A market risk management system serving to identify, assess, monitor, control, and reduce market risk must be implemented in the bank.
An effective market risk management system must include:
risk appetite for market risk;
market risk management policy and procedures;
tools for assessing and monitoring market risk;
the procedure for conducting stress tests on market risk;
reports on market risk.
Interest rate risk arising in the bank's trading portfolio due to unexpected changes in market interest rates affecting the value of securities, other fixed-income financial instruments, and derivatives of securities;
Currency risk arising as a result of fluctuations in foreign exchange rates affecting the value of the bank's assets, liabilities, and off-balance sheet items;
Commodity risk arising due to changes in the market value of precious metals, stones, and coins;
Equity market risk arising due to changes in the current (fair) value of shares and derivatives of securities whose underlying asset is a share, as a result of changes in the issuer's activities or fluctuations in the securities market.
the absence of any legal obstacles to sale or hedging;
acquisition for the purpose of subsequent sale to profit from short-term price fluctuations;
regular re-evaluation of fair value.
A significant increase in market risk must be defined in the bank's internal documents.
91-1. Risk appetite for market risk must include the following quantitative indicators:
the maximum amount of risk-weighted value covering a 10-day period with a high confidence level (at least 99 percent) for market risks (in absolute value and as a percentage of the bank's regulatory capital);
the maximum amount of the sum of market risks in the capital adequacy calculation (in absolute value and as a percentage of the bank's regulatory capital);
the maximum amount of currency positions in the bank's main currencies.
Section 2. Requirements for Market Risk Management Policy and Procedures
Market risk is managed in accordance with the market risk management policy and other internal documents of the bank.
The market risk management policy must include:
the organizational structure of the market risk management system, including the distribution of duties, powers, and responsibilities of the participants in the risk management system and their interaction procedures;
the procedure for establishing market risk limits;
the identification, assessment, monitoring, control, reduction, and reporting on market risk;
the procedure for stress-testing market risk;
the forms of reports on market risk prepared for the Supervisory Board and the bank's management, the procedure for their submission, and their frequency.
These procedures must include:
the procedure for identifying, assessing, monitoring, controlling, hedging, and reporting on market risk;
the tools, indicators, methods, and techniques necessary for identifying market risk;
the list of foreign currencies and financial instruments in which operations may be conducted;
the procedure for information exchange among participants in the market risk management process;
the procedure for preparing and verifying the reliability of reports submitted to the Central Bank on market risk.
Section 3. Requirements for Reports on Market Risk
The form, frequency, and volume of reports on market risk are determined by the Supervisory Board or the bank's management.
Reports on market risk must include the following information:
information on the volume and description of each type of market risk associated with assets, liabilities, off-balance sheet items, cash flows, and products where market risk exists;
information on the violation of established limits for market risks;
the results of stress tests conducted on market risk.
Chapter 10. Requirements for Operational Risk Management in Banks
Section 1. Operational Risk Management System in Banks
An operational risk management system serving to identify, assess, monitor, control, and reduce operational risk must be implemented in the bank.
Operational risk arises in the following situations:
internal fraud;
external fraud;
employee management and labor protection;
the bank's clients, products, and business practices;
instability in the bank's activities and problems in its internal systems;
problems in making payments and submitting payment orders.
theft or fraud;
bribery or abuse of position;
providing incorrect or incomplete information;
engaging in activities not specified in the bank's license or internal documents;
intentional destruction, damage, or misappropriation of assets;
misappropriation of funds held by the bank by other persons;
using information related to bank secrecy or commercial secrecy for personal gain;
participation in money laundering practices from criminal activities;
theft or destruction of documents in the bank;
carrying out bank operations without relevant documents (payment documents, credit documents, etc.) or with forged documents;
failure to conclude pledge agreements or illegal disposal of pledged property.
theft, fraud, or robbery committed against the bank;
violation of the security of the bank's information systems, cyberattacks, theft of information;
misappropriation of funds using forged documents.
employees filing claims regarding employee remuneration (compensation);
physical injury to a bank employee and third parties;
violation of labor legislation, labor protection, and hygiene rules;
discrimination of employees in labor relations;
disclosure of employees' personal data and confidential information.
defects in bank services and products or their forced transfer to clients, provision of incorrect advice to clients, excessive deduction of payments;
violation of disclosure requirements;
misuse of confidential information;
money laundering from criminal activities;
market manipulation;
conducting financial operations not specified in the license;
failure to meet requirements for client identification and verification.
Risks related to instability in the bank's activities and problems in its internal systems may arise as a result of interruptions in the operation of systems necessary for carrying out the bank's activities.
Risks related to making payments and submitting payment orders may arise in the following situations:
deficiencies in monitoring payment operations and preparing reports on them;
errors in attracting clients and document processing;
improper management of client accounts, problems related to trading partners and suppliers;
errors in data entry and storage, bookkeeping;
deficiencies in identifying the borrower's belonging to a group of related borrowers;
problems related to sending payment documents;
incompleteness of documents related to clients, failure to submit reports to the Central Bank and other bodies in accordance with legislation;
unauthorized use of clients' accounts.
the bank's risk appetite for operational risk;
the policy and internal procedures for managing operational risks;
tools for assessing and monitoring operational risk;
the procedure for conducting stress tests on operational risks;
the procedure for ensuring operational resilience;
reports on operational risks.
Section 2. Requirements for Operational Risk Management Policy and Procedures
The bank must manage operational risks within the framework of the operational risk management policy and relevant internal procedures.
The operational risk management policy must include:
the organizational structure of the operational risk management system, including the distribution of duties, powers, and responsibilities of the relevant structural subdivisions and their interaction procedures;
the procedure for establishing operational risk limits;
the requirements for identifying, assessing, monitoring, controlling, reducing operational risks, and reporting on operational risk;
criteria for identifying operational risk situations;
the procedure for stress-testing operational risk;
the forms of reports prepared on operational risk, the procedure for their submission, and their frequency.
These procedures must be developed taking into account the nature and complexity of the bank's activities.
the procedure for identifying, assessing, monitoring, controlling, and reducing operational risks;
the criteria for identifying operational risk situations, the procedure for assessing them, and the procedure for conveying information about such situations to the bank's management;
the classification procedure and criteria for types of operational risk situations;
a description of the main tools used in managing operational risks and the procedure for their use, including the procedure for maintaining an internal database of operational risk situations;
a clear separation of tasks related to managing operational risk and compliance risk to prevent duplication;
the procedure for information exchange among participants in the operational risk management process, including the types, forms, and deadlines for information submission;
the procedure for stress-testing operational risk;
the procedure for preparing and verifying the reliability of reports submitted to the Central Bank on operational risks.
109-1. The Supervisory Board must approve the procedure for ensuring the bank's operational resilience, taking into account the bank's risk appetite.
109-2. The bank's management must implement the procedure for ensuring the bank's operational resilience, having correctly distributed the bank's financial, technical, and other resources.
109-3. The procedure for ensuring operational resilience includes:
the bank's business continuity and recovery plan (hereinafter referred to as the recovery plan);
the procedure for testing the recovery plan.
109-4. The recovery plan is a set of measures aimed at ensuring the continuity of the bank's critical operations in emergency situations and unforeseen circumstances.
The recovery plan provides for:
the list of the bank's critical operations;
the list of employees, tools, processes, data, and third parties necessary for the bank to carry out critical operations in emergency situations and unforeseen circumstances;
a description of the sequence of actions to ensure the continuity and recovery of the bank's critical operations;
the procedure for carrying out internal and external communications of the bank in emergency situations and unforeseen circumstances;
a description of the time required to recover the bank's critical operations;
the minimum amount of resources necessary to ensure the continuity and recovery of the bank's critical operations.
109-5. The recovery plan must be tested at least once a year or in the event of significant changes in the bank's activities.
In this case, the following are checked:
the protection of the bank's critical operations regardless of the severity of the interruption in the bank's activities;
the bank's ability to operate effectively in emergency situations and unforeseen circumstances and the assurance of the bank's return to normal operations.
109-6. While preparing to test the recovery plan, the bank must take into account:
the testing of this system in general and by separating it into individual parts to assess the reliability of the system for ensuring the continuity of the bank's activities;
the limitation of the impact of emergency situations arising during the testing process on the bank's activities;
the clear definition of the goals and objectives of the test;
the formation of a list of employees responsible for conducting the test.
Recovery plan tests must be carried out based on scenarios that include emergency situations and unforeseen circumstances that may occur, even though they have serious consequences for the bank.
Employees responsible for testing the recovery plan must:
monitor and evaluate test results;
prepare a report containing a description of the test process and results, as well as measures to be taken by the bank to improve operational resilience;
coordinate the report with the structural subdivisions of the bank involved in the recovery plan test;
submit the report for approval to the bank's management.
Section 3. Requirements for Assessment and Monitoring of Operational Risk
creation, maintenance, and analysis of existing data in the internal operational risk incident database;
analysis of the results of inspections conducted by the internal audit service and external auditors;
Key Risk Indicators (KRIs) of risk.
employee turnover;
the ratio of the amount of fines paid by the bank to the bank's total revenue;
the share of all allocated loans in total allocated loans that show signs of fraud in their allocation;
the duration of the operation of the bank's systems, which function in a limited mode as a result of technical, technological failures, or power outages;
the share of agreements found to be concluded in violation of legislation in all agreements.
the date the incident occurred, was detected, and was registered;
the employee who caused the incident;
the structural subdivision responsible for detecting and investigating the incident;
description of the incident and reasons for its occurrence; See previous edition.
losses (losses) arising as a result of operational risk incidents; ((The sixth paragraph of Item 112 was introduced in the edition of Resolution No. 37/6 of the Board of the Central Bank of the Republic of Uzbekistan dated December 5, 2024 (registration number 3427-1, dated January 21, 2025) — , dated January 24, 2025, No. 10/25/3427-1/0066. Entry into force date — April 25, 2025)
the type of risk associated with the incident, including credit risk, market risk;
openness or closedness of the incident. See previous edition.
Data in the bank's database of internal operational risk incidents must be grouped by participants of the banking group, structural subdivisions of the bank, and bank operations (transactions).
When maintaining the bank's database of internal operational risk incidents, the bank must take into account:
classification of the operational risk incident;
detection and recording of losses (losses) associated with the operational risk incident;
registration of the operational risk incident;
updating information on operational risk incidents;
updating information sources on operational risk incidents. ((Items 1121 and 1122 were introduced on the basis of Resolution No. 37/6 of the Board of the Central Bank of the Republic of Uzbekistan dated December 5, 2024 (registration number 3427-1, dated January 21, 2025) — , dated January 24, 2025, No. 10/25/3427-1/0066. Entry into force date — April 25, 2025)
criteria for classifying operational risk incidents as significant;
the procedure for forming a working group to investigate significant operational risk incidents and the procedure for conducting the investigation;
the procedure for notifying the bank's management and relevant structural subdivisions of the investigation results, approving measures to reduce the consequences of the incident and prevent such incidents in the future.
A significant increase in operational risk must be defined in the bank's internal documents.
Section 4. Requirements for Reports on Operational Risk
The form, frequency, and volume of reports on operational risk are determined by the supervisory board or bank management.
Reports on operational risk must include the following information:
summary data accumulated in the internal operational risk incident database, including analysis of their dynamics compared to previous periods;
significant operational risk incidents, the causes of their occurrence, and measures aimed at preventing such incidents in the future;
information on the violation of established limits of operational risk by the bank;
results of stress tests conducted on operational risk.
Chapter 11. Requirements for Compliance Risk Management
Section 1. Compliance Risk Management System
The bank must implement a compliance risk management system to identify, assess, monitor, control, and mitigate compliance risk.
The compliance risk management system must include:
compliance risk management policy and procedures;
reporting on compliance risk.
the organizational structure of the compliance risk management system, including the distribution of functions, powers, and responsibilities of relevant structural subdivisions, as well as the procedure for their interaction;
identification, assessment, monitoring, control, mitigation, and reporting on compliance risk;
report forms, the procedure for their submission, and frequency.
These procedures must be developed taking into account the nature and complexity of the bank's activities and may comply with requirements established by the Central Bank and legislative acts.
These procedures may include:
the procedure for identifying, assessing, monitoring, controlling, and mitigating compliance risk;
the procedure for ensuring the bank's activities comply with legislative acts;
the procedure for exchanging information among participants in the compliance risk management process;
the procedure for training bank employees to ensure they are informed about legislative acts and the bank's internal documents.
information received from employees regarding unacceptable behavior in the bank;
internal operational risk incident database;
customer complaints;
reports of the internal audit service and external auditors;
information received from the Central Bank and other relevant authorities;
information identified by employees of the structural subdivision responsible for compliance risk management from other sources, including results of conducted inspections.
When compliance risk arises, including when legislative requirements are violated, the structural subdivision responsible for compliance risk management must timely notify the supervisory board and bank management and propose relevant corrective measures. See previous edition.
To ensure financial stability and continuity of cross-border operations, the bank must:
identify and assess risks related to compliance with legislative requirements of foreign countries that may affect bank activities;
identify and assess risks related to the termination of correspondent relationships with foreign banks. ((Item 1221 was introduced on the basis of Resolution No. 37/6 of the Board of the Central Bank of the Republic of Uzbekistan dated December 5, 2024 (registration number 3427-1, dated January 21, 2025) — , dated January 24, 2025, No. 10/25/3427-1/0066. Entry into force date — April 25, 2025)
Section 2. Requirements for Reports on Compliance Risk
The structural subdivision responsible for compliance risk management must submit reports on compliance risk to the supervisory board and the risk management committee (if established) quarterly, and to the bank's management at least once a month.
Reports on compliance risk must include the following information:
violation of legislative acts applicable to bank activities and requirements of the bank's internal documents;
violation by bank employees of the requirements of the bank's code of ethics;
submission of unreliable reports to the Central Bank and other relevant authorities;
consequences for bank activities resulting from changes in legislation;
conflicts of interest;
training sessions conducted for bank employees by the structural subdivision responsible for compliance risk management. See previous edition.
Chapter 111. Requirements for Country Risk Management
Section 1. Country Risk Management System
The supervisory board and bank management must implement a country risk management system to identify, assess, monitor, control, and mitigate country risk.
Country risk arising in the bank includes:
risks related to payments arising from the borrower's inability to fulfill its obligations due to the introduction of restrictions in a foreign country, including restrictions on currency operations;
sovereign risk arising from the inability or refusal of a foreign country's government to fulfill contractual obligations;
contagion risk arising from adverse events in one country leading to the inability of borrowers in another country to fulfill their obligations.
country risk management policy and procedures;
the procedure for submitting reports on country risk.
Section 2. Requirements for Country Risk Management Policy and Procedures
the organizational structure of the country risk management system, including the distribution of functions, powers, and responsibilities of structural subdivisions responsible for country risk management (hereinafter referred to as the relevant structural subdivision (employees)) and the procedure for their interaction;
requirements for identifying, assessing, monitoring, controlling, mitigating, and reporting on country risk;
report forms, the procedure for their submission, and frequency;
criteria for identifying and analyzing country risk;
country risk limits, including the bank's overall limit for cross-border operations, as well as individual limits for countries and/or regions;
description of cross-border financial operations carried out by the bank.
These procedures must be developed taking into account the nature and complexity of the bank's activities related to foreign countries and must comply with requirements established by the Central Bank and legislative acts.
These procedures must include:
the procedure for identifying, assessing, monitoring, controlling, and mitigating country risk;
the procedure for ensuring the bank's activities comply with country risk limits;
the procedure for exchanging information among participants in the country risk management process;
reporting on country risk.
continuously analyze the situation (political, economic, social, etc.) in foreign countries;
evaluate the requirements of documents of foreign countries that may affect bank activities;
evaluate the impact of country risk on the bank's financial condition;
formalize the results of analysis and evaluation in the appropriate manner;
ensure timely submission of reports on country risk to the bank's supervisory board and management.
economic growth rates;
volume and structure of external debt;
volume of international reserves;
government budget balance;
dynamics of the national currency exchange rate;
trade balance;
access to international financial markets;
development level of the financial system;
social, legal, and political situation.
The country risk policy and limits must be reviewed at least once a year or regularly when there are risks of an increase in country risk for a specific country.
A significant increase in country risk must be defined in the bank's internal documents.
Section 3. Requirements for Reports on Country Risk
Chapter 112. Requirements for Managing Interest Rate Risk Arising in the Bank Portfolio
Section 1. Interest Rate Risk Management System in the Bank Portfolio
A system for managing interest rate risk arising in the bank portfolio must be implemented in the bank to identify, assess, monitor, control, and mitigate such risk.
An effective system for managing interest rate risk arising in the bank portfolio must include:
risk appetite for interest rate risk arising in the bank portfolio;
policy and procedures for managing interest rate risk arising in the bank portfolio;
tools for assessing and monitoring interest rate risk arising in the bank portfolio;
procedure for conducting stress tests on interest rate risk arising in the bank portfolio;
reports on interest rate risk arising in the bank portfolio.
repricing risk arising from changes in interest rates on bank assets and liabilities, including off-balance sheet items, over different periods;
basis risk arising from changes in market interest rates (indices) on which bank assets or liabilities, including off-balance sheet items, are based, if these rates (indices) differ from each other;
option risk arising from customers' right to change the amount or timing of payments on bank assets or liabilities, including off-balance sheet items, and their use of this right.
Section 2. Requirements for Interest Rate Risk Management Policy and Procedures in the Bank Portfolio
Interest rate risk arising in the bank portfolio is managed in accordance with the bank's policy and other internal documents.
The policy for managing interest rate risk arising in the bank portfolio must include:
the organizational structure of the interest rate risk management system, including the distribution of functions, powers, responsibilities, and interaction procedures among participants in the risk management system;
procedure for establishing limits for interest rate risk arising in the bank portfolio;
identification, assessment, monitoring, control, mitigation, and reporting on interest rate risk arising in the bank portfolio;
procedure for stress testing interest rate risk arising in the bank portfolio;
report forms prepared for the supervisory board and bank management on interest rate risk arising in the bank portfolio, the procedure for their submission, and frequency.
This procedure must include:
the procedure for identifying, assessing, monitoring, controlling, hedging, and reporting on interest rate risk arising in the bank portfolio;
tools, indicators, methods, and techniques necessary for identifying interest rate risk arising in the bank portfolio;
the procedure for exchanging information among participants in the interest rate risk management process;
the procedure for preparing and verifying the reliability of the report on interest rate risk arising in the bank portfolio submitted to the Central Bank.
the impact on the bank's capital of changes in the current net value of assets and liabilities in the bank portfolio resulting from changes in market interest rates;
the impact of changes in market interest rates on the bank's net interest income for the bank portfolio.
increase in all interest rates;
decrease in all interest rates;
decrease in short-term interest rates and increase in long-term interest rates;
increase in short-term interest rates and decrease in long-term interest rates;
sharp increase in short-term interest rates;
sharp decrease in short-term interest rates.
Section 3. Requirements for Reports on Interest Rate Risk Arising in the Bank Portfolio
The form, frequency, and volume of reports on interest rate risk arising in the bank portfolio are determined by the supervisory board or bank management.
Reports on interest rate risk arising in the bank portfolio must include the following information:
data on the volume and description of each type of interest rate risk arising in the bank portfolio;
information on the violation of established limits for interest rate risk arising in the bank portfolio;
results of stress tests conducted on interest rate risk arising in the bank portfolio. ((Chapters 111 and 112 were introduced on the basis of Resolution No. 37/6 of the Board of the Central Bank of the Republic of Uzbekistan dated December 5, 2024 (registration number 3427-1, dated January 21, 2025) — , dated January 24, 2025, No. 10/25/3427-1/0066. Entry into force date — April 25, 2025)
Chapter 12. Final Provisions
Appendix 2 to Resolution No. 4/11 of the Board of the Central Bank of the Republic of Uzbekistan dated March 7, 2023
LIST
of departmental normative-legal acts recognized as lost in force
Resolution No. 14/2 of the Board of the Central Bank of the Republic of Uzbekistan dated May 7, 2011 "On Approval of the Regulation on Requirements for Risk Management of Commercial Banks" (registration number 2229, dated May 25, 2011) (Collection of Legislation of the Republic of Uzbekistan, 2011, No. 20-21, Article 216).
Resolution No. 8/7 of the Board of the Central Bank of the Republic of Uzbekistan dated March 26, 2016 "On Amendments to Item 2 of the Regulation on Requirements for Risk Management of Commercial Banks" (registration number 2229-1, dated April 18, 2016) (Collection of Legislation of the Republic of Uzbekistan, 2016, No. 16, Article 161). ((, dated April 19, 2023, No. 10/23/3427/0218; dated January 24, 2025, No. 10/25/3427-1/0066; dated August 9, 2025, No. 10/25/3658/0713; dated July 27, 2026, No. 10/26/3427-2/0788)
More like this from CBU
We email you every new CBU publication the day it's published.