2021-09-30 | 20/5Added
The Central Bank of Uzbekistan approves the Regulation establishing the procedure and conditions for the digital identification of individuals by banks, microfinance organizations, pawnshops, and payment organizations. The rules mandate the use of biometric passports, ID cards, or driving licenses, requiring real-time photo or video capture and automated comparison against the Central Information Base and the Terrorist Activities Registry. Financial institutions must implement risk-based limits on transactions and balances for digitally identified customers and retain all identification data, including photos and videos, for five years.
Get CBU alerts — same-day email on every new publication.
Resolution of the Board of the Central Bank of the Republic of Uzbekistan, registered on September 30, 2021, registration number 3322
Date of Entry into Force
30.09.2021
All
24.11.2025
01.08.2022
30.09.2021
Russian
Uzbek
Uzb
Uzb|Russian
[OKOZ:
1.07.00.00.00 Legislation on Finance and Credit. Banking Activity / 07.21.00.00 Banking Activity / 07.21.21.00 Other Issues of Banking Activity]
[TSZ:
Resolution of the Board of the Central Bank of the Republic of Uzbekistan
On Approval of the Regulation on the Procedure for Digital Identification of Customers
[Registered by the Ministry of Justice of the Republic of Uzbekistan on September 30, 2021, registration number 3322]
In accordance with the Laws of the Republic of Uzbekistan "On the Central Bank of the Republic of Uzbekistan" and "On Payments and Payment Systems", the Board of the Central Bank of the Republic of Uzbekistan resolves:
Approve the Regulation on the Procedure for Digital Identification of Customers in accordance with the appendix.
This resolution enters into force from the date of its official publication.
Chairman M. NURMURATOV
Tashkent city,
September 6, 2021,
No. 20/5
Agreed:
Head of the Department under the Prosecutor General's Office D. RAKHIMOV
August 31, 2021
Minister of Information Technologies and Communications of the Republic of Uzbekistan Sh. SADIKOV
September 6, 2021
APPENDIX
to the Resolution of the Board of the Central Bank of the Republic of Uzbekistan dated September 6, 2021, No. 20/5 resolution
REGULATION
on the Procedure for Digital Identification of Customers
[View the previous edition.]
This Regulation establishes the procedure and conditions for the digital identification of individuals (hereinafter referred to as customers) by banks, microfinance organizations, pawnshops, and payment organizations (hereinafter referred to as credit and payment organizations) in accordance with the Laws of the Republic of Uzbekistan "On the Central Bank of the Republic of Uzbekistan", "On Banks and Banking Activity", "On Payments and Payment Systems", and "On Combating the Legalization of Income Obtained from Criminal Activity, Financing of Terrorism and Financing of Proliferation of Weapons of Mass Destruction".
(amended by the Resolution of the Board of the Central Bank of the Republic of Uzbekistan dated July 8, 2022, No. 14/8 [resolution](/docs/6139060?ONDATE=01.08.2022 00#6139267) (registration number 3377, dated 01.08.2022), 01.08.2022, No. 10/22/3377/0696)
Chapter 1. General Provisions
internal control rules — internal control rules for combating the legalization of income obtained from criminal activity, financing of terrorism, and financing of proliferation of weapons of mass destruction in credit and payment organizations;
digital identification — the process of checking and confirming the identity of a customer based on the requirements established in this Regulation using information systems;
digital authentication — the process of checking and confirming the identity of a customer by automatically (without human intervention) comparing a photo or video image obtained in real-time from a previously identified customer with the initial identification data;
Registry — a list of persons involved or suspected of involvement in terrorist activities or proliferation of weapons of mass destruction, compiled by the Department for Combating Economic Crimes under the Prosecutor General's Office of the Republic of Uzbekistan based on information provided by state bodies implementing the fight against terrorism and proliferation of weapons of mass destruction and other competent bodies of the Republic of Uzbekistan, as well as information provided through official channels by competent bodies of foreign states and international organizations.
study, analyze, identify, assess, monitor, manage, document, and take measures to reduce the level of potential risks of legalization of income obtained from criminal activity, financing of terrorism, and financing of proliferation of weapons of mass destruction;
establish the procedure for digital identification of customers in their internal rules.
take necessary legal, organizational, and technical measures to protect customer identification data;
ensure the reliability and accuracy of identification data;
take measures against falsification, unauthorized alteration, and disclosure of identification data;
ensure control over the storage and use of identification data;
implement a system of measures to reduce and control operational risks related to information security in providing payment services, including ensuring security during digital identification of customers;
apply rules for multi-factor authentication (contacting the customer via mobile phone or sending an SMS message, or additionally checking and confirming the customer's identity via email and social networks) when using services of credit and payment organizations through communication channels;
apply necessary requirements for information security in accordance with other legislative acts in the field.
Chapter 2. Digital Identification of Customers
Digital identification is applied to citizens of the Republic of Uzbekistan, as well as to foreign citizens and stateless persons permanently or temporarily residing in the territory of the Republic of Uzbekistan.
In digital identification of customers, credit and payment organizations use the following methods:
checking and identifying the customer's identity by an employee of the credit and payment organization based on information provided by the customer;
checking and identifying the customer's identity in real-time without human intervention by the information systems of the credit and payment organization.
accept photos of the relevant parts of the identity document (biometric passport, identification ID card, or driving license of the new sample) containing information in accordance with the requirements of internal control rules;
accept a photo and/or video image of the customer in accordance with the requirements of this Regulation;
compare information with the central databases of physical and legal entities of the "Electronic Government" system (hereinafter referred to as the central database) by sending a request;
compare the photo located in the identity document with the photo and/or video image accepted in accordance with this Regulation, as well as with the photo located in the central database (if available);
check the mobile phone number used to contact the customer using a method that allows determining that the number is being used by this specific customer (contacting the mobile phone, sending an SMS message);
conduct verification in accordance with internal control rules, regardless of whether the customer belongs to the high-risk category.
A responsible employee of the credit and payment organization establishes an online video conference session with the customer to verify that the accepted documents belong to him/her.
a) receives in real-time the series and number of the identity document (biometric passport, identification ID card, or driving license of the new sample), or the personal identification number of the physical person and date of birth, or all of this information, as well as a photo or video image of the customer in accordance with this Regulation;
b) sends a request to the central database and receives the following personal data of the customer:
digital photo (if available);
personal identification number of the physical person (PIN);
date of issue, validity period, and place of issue of the biometric passport or identification ID card;
surname, first name, and patronymic (in Latin script) in the state language;
[View the previous edition.]
gender, country of birth, place of birth, nationality, citizenship, and information about place of residence or stay;
(the sixth paragraph of sub-paragraph "b" of paragraph 7 was amended by the Resolution of the Board of the Central Bank of the Republic of Uzbekistan dated November 14, 2025, No. 27/10 [resolution](/docs/-7852420?ONDATE=24.11.2025 00#-7861684) (registration number 3709, dated 21.11.2025), 24.11.2025, No. 10/25/3709/1082)
c) automatically (without human intervention) compares the photo received in real-time from the customer or the photo in the video image with the photo obtained from the central database (if available);
d) checks the mobile phone number used to contact the customer using a method that allows determining that the number is being used by this specific customer (contacting the mobile phone, sending an SMS message);
e) automatically (without human intervention) compares the accepted data with the Registry in accordance with internal control rules.
Credit and payment organizations use their own information systems or information systems provided by third parties on a contractual basis for digital identification of customers.
Information systems used for digital identification of customers must:
be located on servers within the territory of the Republic of Uzbekistan;
ensure mutual encryption of data transmission;
ensure the use of only photos and/or video images created in real-time;
be protected against substitution and tampering of photos and/or video images, and against the use of previously created photos and/or video images;
allow detection of attempts by customers to use photos and/or video images of other customers during identification.
the photo and/or video image must be in color;
the video image must be sound-enabled;
the presence of persons other than the customer in the photo and/or video image is not allowed;
the customer's face must not be partially or fully hidden, shadows must not fall on the customer's face, and the customer must not wear glasses covering the face (except for glasses with transparent lenses);
the customer's face must be clearly visible in the photo and/or video image.
Chapter 3. Application of Digital Identification
opening and managing electronic wallets;
opening and managing bank accounts, as well as bank cards;
cross-border money transfers using bank cards or electronic money systems;
online micro-lending.
the maximum amount of a single operation performed by the owner of electronic money;
the maximum amount of electronic money stored on a single electronic device of the owner of electronic money;
the total amount of transactions performed by the owner of electronic money during a calendar month;
the total amount of transactions performed by the owner of the bank account (card) during a calendar month;
the amount of online micro-loans.
Credit and payment organizations may establish limits for operations performed by each customer based on an assessment of the risk level for digital identification of customers and digital authentication of previously identified customers.
In this case, credit and payment organizations must conduct necessary verification and scoring analysis of customers in accordance with internal control rules.
Credit or payment organizations may remotely unblock relevant bank cards for customers who have undergone digital identification or digital authentication through information systems, provided that the customer is immediately notified via other communication channels.
Credit and payment organizations must take measures to detect and prevent attempts by customers to bypass established limits.
Customers are not digitally identified in the following cases:
if the customer and/or the operation being performed by the customer falls into the high-risk category in accordance with internal control rules;
if there is doubt about the authenticity of the information provided by the customer;
if there is doubt about the consistency of the photo in the identity document with the photo and/or video image obtained in accordance with this Regulation and the photo located in the central database (if available);
if the information obtained from the customer does not match the information located in the central database, or if it is impossible to check the consistency;
if the photo and/or video image does not meet the requirements of this Regulation;
if there are suspicions of legalization of income obtained from criminal activity, financing of terrorism, or financing of proliferation of weapons of mass destruction.
If all identification data of the customer partially or fully matches the data of a person included in the Registry during digital identification, credit and payment organizations must take measures provided for in their internal control rules.
Filling out and maintaining the customer questionnaire as a result of digital identification of the customer is carried out based on the requirements established in the internal control rules.
Chapter 4. Final Provisions
Credit and payment organizations are responsible for the quality of digital identification and digital authentication of customers.
Credit and payment organizations that have established digital identification of customers must submit a report to the Central Bank of the Republic of Uzbekistan within ten days containing the following information:
date of establishment of the system for digital identification of customers;
full description of the processes of digital identification of customers;
list of services provided to customers through digital identification by credit and payment organizations.
In addition to the information provided for in the internal control rules, credit and payment organizations must store photos and/or video images obtained from customers, documents recording the exact date and time when the customer's identity was checked and identified, as well as the results of data verification using the central database, together with customer questionnaires, for five years in accordance with internal control rules.
The information systems of credit and payment organizations must provide the opportunity to obtain timely information about customers who have undergone digital identification and digital authentication and their number.
Credit and payment organizations must comply with the requirements of this Regulation when making changes to the data obtained as a result of digital identification of customers.
This Regulation has been agreed upon with the Ministry of Information Technologies and Communications of the Republic of Uzbekistan and the Department for Combating Economic Crimes under the Prosecutor General's Office of the Republic of Uzbekistan.
(, dated 30.09.2021, No. 10/21/3322/0923; dated 01.08.2022, No. 10/22/3377/0696; dated 24.11.2025, No. 10/25/3709/1082)
Read the rest free
Amended 1 time · last 2025-11-24
Source: Central Bank of the Republic of Uzbekistan — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from CBU
We email you every new CBU publication the day it's published.