2026-01-25 | BM 1226

Added · Updated

Guidelines for Prepaid Card Issuance by Banks

Licensed banks in Oman must adhere to new guidelines for issuing prepaid cards, effective February 1, 2026, which replace the need for case-by-case Central Bank approvals. The rules mandate board-approved policies, EMV-compliant technology, and strict AML/CFT controls, including simplified due diligence limits of RO 350 for low-risk reloadable cards and RO 50 for non-reloadable closed-loop gift cards. Banks are required to implement robust transaction monitoring, fraud risk management, and specific limits for co-branded cards and third-party agent distributions.

Central Bank of Oman logo

Oman

Central Bank of Oman

Click to view thumbnail

Central Bank of Oman البنك المركزي العماني

25 January 2026

Circular BM 1226

To: All Licensed Banks Operating in the Sultanate of Oman

After compliments,

Subject: Master Circular – Guidelines for Prepaid Card Issuance by Banks

  1. Globally, the use of prepaid cards as an alternative to cash is experiencing significant growth. These cards offer convenient access to funds paid in advance, making them a valuable tool for financial inclusion. Prepaid cards are also considered to be more convenient and adaptable because of their ease of use and acceptability worldwide.

  2. In line with Master Circular on Products and Service of Banks issued through BM 1198, which empowers banks to develop various products and services, Central Bank has decided to issue these guidelines for the issuance of Prepaid Cards by licensed Banks. These regulations aim to create a conducive and equitable environment for all existing and potential participants, eliminating the need for case-by-case approvals from the Central Bank for the issuance of prepaid card products, as well as ensure an adequate compliance with global best practices.

  3. These instructions have been developed in line with the international recommendations such as those issued by FATF to minimize the AML / CFT and other risks associated with the prepaid cards and also finalized after necessary consultation with the relevant stakeholders.

  4. These guidelines aim to promote safe, secure, and responsible issuance of prepaid cards within the Sultanate of Oman. Banks are advised to adhere to these guidelines which will become effective from February 1, 2026.

Best regards,

[Signature]

Ahmed Al Musalmi The Governor

Encl: Annexure


Master Circular on Prepaid Card Issuance by Banks

Master Circular

on

Prepaid Card Issuance by Banks

Page 3


Master Circular on Prepaid Card Issuance by Banks

Contents

  1. General and Regulatory Requirements ................................................................................. 5 2.1 Board Approval .................................................................................................................... 5 2.2 Technology .......................................................................................................................... 5 2.3 Testing and Launch .............................................................................................................. 5 2.4 Documentation .................................................................................................................... 5 2.5 Compliance and Regulatory Framework .............................................................................. 5 2.6 AML / CFT ............................................................................................................................ 6 2.7 Risk Identification and Documentation ............................................................................... 6 2.8 Customer Identification and Verification ............................................................................. 6 2.9 Transactions Monitoring ..................................................................................................... 7 2.10 Suspicious Activity Reporting ............................................................................................. 7 2.11 Fraud Risk Management .................................................................................................... 7 2.12 Limits for Stored Value of Prepaid Card ............................................................................ 7 2.13 Co-Branded Prepaid Cards ................................................................................................ 10 2.14 Sale/ Distribution of Prepaid Cards by Authorised Agent (Third Party) .............................. 11 2.15 Closed loop prepaid cards (Prepaid Gift cards) .................................................................. 12 2.16 Transparency ..................................................................................................................... 12 2.17 Risk Assessment ................................................................................................................ 12 2.18 Compliance with other Laws ............................................................................................. 12 2.19 Reporting .......................................................................................................................... 12 2.20 Issuance of Prepaid Cards to Minors .................................................................................. 13 2.21 Restrictions in usage .......................................................................................................... 13 2.22 Unutilized Balances ............................................................................................................ 13 2.23 Customer Grievance Redressal and Support ....................................................................... 13 2.24 Record Retention ............................................................................................................... 13 2.25 Card Validity ...................................................................................................................... 13 2.26 Transactions details ........................................................................................................... 14 2.27 Requirements for Fees ....................................................................................................... 14 2.28 Redemption procedures/charges ....................................................................................... 14 2.29 Internal Review .................................................................................................................. 14 2.30 Annual Assessment ............................................................................................................ 14

Page 2 of 13


Master Circular on Prepaid Card Issuance by Banks

Definitions

1.1 All the terms specified in this Circular shall have the same meaning as specified in the Banking Law 2/2025 and the National Payment Systems Law 08/2018 and other regulations issued thereunder, except for the following definitions:

1.1.1 Acquirer: The entity which maintains the relationship with the retailer, provides the infrastructure needed for accepting a card payment (e.g. access to the point of sale (POS) terminal or the payment services supporting an e-commerce website) and normally operates the account in which the proceeds of the sale transaction are deposited.

1.1.2 AML / CFT guidelines: Master Circular BM - 1187 on Instructions under Law on Combating Money Laundering and Terrorism Financing (Royal Degree 30/2016) and other related guidelines.

1.1.3 Authorised Agent (Third party): It is an entity authorised for the sale or distribution of prepaid cards to the customers, by the Issuing Bank under a formal agreement.

1.1.4 Central Bank: Central Bank of Oman

1.1.5 Circular on Products & Service of Banks: Master Circular on Products & Service of Banks issued through Circular BM - 1198.

1.1.6 Closed loop prepaid cards: A card that can only be used for purchases at a single, or among a limited network of merchants that participate in that specific network. These cards do not provide access to the global ATM network for cash withdrawals.

1.1.7 Customer: It refers to prepaid card holder who acquired it for the purchase of goods and services.

1.1.8 Fraud Risk Management Guidelines: Master Circular BM - 1153 on Fraud Risk Management.

1.1.9 Issuer / Issuing Bank: It refers to the Bank which issues the prepaid card to the customer under these guidelines.

1.1.10 National Payment Systems Law (NPSL): National Payment Systems Law issued in accordance with Royal Decree 8/2018 and other related regulations issued under the National Payment Systems Law.

Page 3 of 13


Master Circular on Prepaid Card Issuance by Banks

1.1.11 Open loop prepaid card: A card that enables the purchase of goods and services at any merchant where that brand of the card is accepted and also offers access to cash through alternate delivery channels like automated teller machine (ATM) that connects to the affiliated ATM network.

1.1.12 Outsourcing Guidelines: Master Circular BM - 1080 on Outsourcing.

1.1.13 Payments network operator: The entity that provides the technical platform to perform transactions with the card at ATMs or points of sale at merchants.

1.1.14 For the purpose of these regulations, prepaid card means an open loop prepaid card except mentioned otherwise.

1.2 It is imperative to note here that in case of a difference between the definition of a certain term mentioned in this document and the relevant Laws issued in the Sultanate of Oman, the definition as per the relevant Law shall prevail.

Page 4 of 13


Master Circular on Prepaid Card Issuance by Banks

2. General and Regulatory Requirements

2.1 Board Approval

2.1.1 The prepaid cards product should form part of the bank's comprehensive policy approved by the Board of Directors. This policy should address among others, aspects relating to scope, infrastructure, security, controls, and compliance with all regulatory requirements and Laws of the Sultanate.

2.2 Technology

2.2.1 Secure technology with features like end-to-end encryption and robust validation mechanisms is required to ensure confidentiality, integrity, authenticity, and non-repudiability of transactions and data. Prepaid cards should have standardized features and should be EMV-compliant / 'contactless' enabled.

2.2.2 Prepaid cards are considered as E-money and accordingly should be compliant with the provisions of National Payment Systems Law and the Regulations issued under the National Payment Systems Law. Licensed Banks issuing prepaid cards to its customers should follow guidelines under para 18.3 of Circular BM 1192 for custody account.

2.2.3 All prepaid card transactions (domestic and GCC) should be routed through OmanNet and GCC net respectively.

2.2.4 Banks are required to ensure compliance with the Cyber Security and Resilience framework (Circular BM - 1194) and related guidelines issued from time to time, in order to protect cardholders' data.

2.3 Testing and Launch

2.3.1 Before launch, the Bank must conduct a trial run, stress testing, back-up procedures, security review, and a soft launch. The adequacy of risk management infrastructure and processes should also be ensured.

2.4 Documentation

2.4.1 The rights and obligations of customers / bank should be clearly documented. Terms and conditions, including fees and charges (whenever updated), permitted uses, and grievance redressal procedures, must be provided to customers in writing.

2.5 Compliance and Regulatory Framework

2.5.1 Each prepaid card program needs to go through a robust review and approval process to ensure that all prepaid cards offered by the Bank adhere to the existing regulatory and legal requirements.

Page 5 of 13


Master Circular on Prepaid Card Issuance by Banks

2.6 AML / CFT

2.6.1 Banks must comply with all AML / CFT regulations and shall develop internal policies and controls to mitigate money laundering and terrorist financing risks associated with the prepaid cards. Issuing Bank will be responsible to ensure compliance of the Central Bank's AML / CFT regulations.

2.6.1.1 Prepaid cards can be abused to launder money or finance terrorist activities. For example, prepaid cards can be utilized in conjunction with, or as a replacement to, bulk cash smuggling.

2.6.1.2 Furthermore, money launderers use prepaid cards to deposit smaller amounts of illegally obtained money to avoid detection. These funds can then be merged and used as if they were legitimately earned (Structuring Deposits).

2.6.1.3 In addition, funds can be loaded onto prepaid cards in support of terrorist activities, such as purchasing various products and services.

2.7 Risk Identification and Documentation

2.7.1 Banks must conduct a thorough risk assessment prior to introducing prepaid card programs. This assessment should include potential risks that may arise in relation to the development, business practices use and specific characteristics of the prepaid card products being offered.

2.8 Customer Identification and Verification

2.8.1 As per FATF guidelines, open-loop reloadable prepaid cards increasingly operate in a manner similar to that of bank accounts. Banks are responsible for ensuring proper customer identification and verification procedures, especially when partnering with third-party distributors. The Bank can issue cards to non-customers but the Bank will be ultimately responsible for CDD. In case of issuance of prepaid card to high-risk customers such as residents from high-risk countries, the Bank needs to assess the risks and put in place suitable risk mitigants commensurate with the risks in line with the requirements on AML / CFT and fraud risk management.

Page 6 of 13


Master Circular on Prepaid Card Issuance by Banks

2.9 Transactions Monitoring

2.9.1 Banks shall put in place ongoing transactions monitoring systems which should be able to detect suspicious activity, based on money laundering and terrorism financing typologies and indicators. Such monitoring systems should take into consideration customer risks, products and services risks, country or geography risks, or delivery channel risks. The transaction monitoring system should also be able to recognize patterns of customer spending / usage across multiple accounts or products held by an individual or group, such as a customer holding multiple prepaid cards. In case of prepaid card issued to non-bank customer, transaction monitoring needs to be ensured by the issuing bank.

2.10 Suspicious Activity Reporting

2.10.1 Banks must diligently analyze customer transactions and activity to identify any unusual patterns or behaviors. In cases where a suspicious transaction is detected or there are reasonable grounds to suspect that funds are linked to criminal activity or terrorist financing, the Bank is obligated to report such suspicions to the appropriate authorities. Banks should maintain heightened vigilance for transactions or activities involving prepaid cards that lack a legitimate economic justification.

2.11 Fraud Risk Management

2.11.1 Banks must comply with the applicable instructions contained in Circular BM - 1153 on Fraud Risk Management. Furthermore, Banks should comprehensively review all their outsourcing arrangements in relation to Card Business including acceptability of counter-parties (including dependencies) covering among others, technical and financial capacities, safety and security, compliance record etc.

2.11.2 Prepaid card issuers shall offer and, where appropriate, require two-factor authentication for transactions, especially online, to enhance security and comply with applicable regulations.

2.12 Limits for Stored Value of Prepaid Card

2.12.1 Banks should develop a robust framework for setting limits on prepaid cards, considering prepaid card risk assessment, target market and intended use. Furthermore, Banks should set an aggregate limit for the institution, based on the total value of prepaid cards issued, the number of customers, and the institutions risk appetite.

Specifically, Banks should evaluate the associated risks and define maximum limits for all programs of Prepaid cards issued and distributed directly by the Bank to a customer. It should consider the risks factors associated with: use of cash, method of funding, distribution channels, the nature of funding sources and geographical outreach in line with

Page 7 of 13


Master Circular on Prepaid Card Issuance by Banks

attached Risk Matrix (Attachment-1). Besides above, when determining the suitability of a prepaid card scheme for a customer, banks should assess the customers risk profile considering different factors including intended use.

For each prepaid card program, banks should define and implement, daily and monthly limits for various types of transactions such as cash withdrawals, point-of-sale purchases, online transactions and international usage based on risk assessment.

2.12.2 Simplified due diligence approach for the issuance of prepaid cards

In addition to various prepaid cards programs defined by Banks as per section 2.12.1 above, Banks may apply simplified due diligence (SDD) criteria to enhance financial inclusion, for the customers considered low risk in line with requirements of Risk Matrix attached with these guidelines. The prepaid card scheme offered to customers enrolled using SDD shall comply with the following requirements:

CriteriaSimplified Due Diligence / Lower risk factors
Customer TypeRetail
CDDIdentification
Verification
Sanction screening
Transactions Monitoring

Page 8 of 13


Master Circular on Prepaid Card Issuance by Banks

CriteriaSimplified Due Diligence / Lower risk factors
Value LimitsMaximum limit and card per customer
Cash withdrawals/ Reloadable frequency and amount
Modes of funding• Funding through account held at a regulated financial institution only for the same customer with no third-party transfer allowed. <br> • Funding through Cash, Credit Cards and cryptocurrencies not allowed including earning from gain of trade in crypto.
Geographical limits• Domestic use only with issuance in local currency i.e., Omani Rial. <br> • Card shall not be allowed for cross-border transactions (allow online usage within Oman).
Segmentation of servicesAuthorised Agent (Third party)/ Outsourcing

Above prepaid card with SDD shall be in line with Article 4 of CBO Circular BM 1187. Further, Banks shall not apply simplified due diligence measures whenever there is a suspicion of money laundering or terrorism financing or proliferation financing or specific high-risk scenario/criteria.

The Central Bank may review any exceptionally high limits and may advise the Bank to revisit these limits keeping in view the risk identification and mitigation process adopted by the Bank.

Page 9 of 13


Master Circular on Prepaid Card Issuance by Banks

2.13 Co-Branded Prepaid Cards

2.13.1 Approval and Review The issuance of co-branded prepaid cards should be exclusively carried out by banks. The Central Bank may review co-branded prepaid card arrangements and may require reports on program operations.

2.13.2 Third-Party Due Diligence Banks are fully responsible for ensuring compliance with all regulations by any third-party co-branding partner. Agreements with co-branding partners should include review clauses.

2.13.3 Transparency and Risk Management The co-branded prepaid card arrangements should not have exclusivity clauses. Banks must address reputational and security risks associated with co-branding and implement suitable risk mitigation measures.

2.13.4 Limits and Verification The limits of the co-branded prepaid card shall also be decided in line with the criteria define above (Section 2.12: Limits for Stored Value of Prepaid Card), but the Bank has to ensure that the limits for co-branded cards should be lower than the normal prepaid cards. Banks should separately define tiered limits for co-branded prepaid cards:

a) issued by the bank to its own account holders, b) issued by the bank to non-customers (non-account holders), and c) issued by bank, and delivered by third party.

For options (a) and (b), the Bank has to comply with the CDD and AML/CFT guidelines issued by the Central Bank. For options (c), the limits should be kept at the lowest, with the merchant having the responsibility to obtain/ verify the bank-specified identity proof documents and hand over the records to the bank for retention. However, Banks remain ultimately responsible for complying with the CDD and AML/CFT guidelines.

Banks should also subject this process to audit and control, and ensure that all transactions are brought under AML / CFT monitoring framework/processes.

Page 10 of 13


Master Circular on Prepaid Card Issuance by Banks

2.14 Sale/ Distribution of Prepaid Cards by Authorised Agent (Third Party)

2.14.1 Banks can sale / distribute prepaid cards through its Authorised Agents (Third Party). These agents serve as intermediaries, allowing banks to expand their reach without having a physical presence in every location.

2.14.2 Banks shall develop a formal risk-based criteria duly approved by its Board for the selection of Authorised Agent.

2.14.3 The appointment of authorised agent will be through a formal written agreement that must explicitly define roles, responsibilities, and the scope of services.

2.14.4 The limits of the prepaid card's sale/ distribution through authorised agents shall also be decided in line with the criteria define above (Section 2.12: Limits for Stored Value of Prepaid Card), but the Bank has to ensure that the limits for such prepaid cards should be lower than the normal prepaid cards distributed by the Bank itself.

2.14.5 Authorised Agents have the responsibility to obtain/ verify the bank-specified identity proof documents and hand over the records to the bank for retention. However, Banks remain ultimately responsible for complying with the CDD and AML/CFT guidelines.

2.14.6 Banks will also remain responsible for compliance of all regulatory requirements including but not limited to CDD, customer support, error correction and dispute resolution under these or any other relevant guidelines issued from time to time.

2.14.7 Banks shall provide adequate training related to prepaid card issuance and record maintenance etc. on periodic basis to its Authorised Agents.

Banks should also subject this process to audit and control, and ensure that all transactions are brought under AML / CFT monitoring framework/ processes.

Page 11 of 13


Master Circular on Prepaid Card Issuance by Banks

2.15 Closed loop prepaid cards (Prepaid Gift cards)

2.15.1 Banks are allowed to issue closed loop pre-paid gift cards subject to the following conditions:

a) Maximum value shall not exceed Rial Omani 50. b) These cards shall not be reloadable. c) Cash withdrawal shall not be permitted for such cards. d) A closed loop card is not allowed to provide cross border payment functionality. e) CDD of the customers shall be maintained. (Separate CDD would not be required in case of updated CDD maintained by the Bank).

2.16 Transparency

2.16.1 Transparency and disclosures are crucial aspects of responsible Banking. Banks must ensure transparency in fees, charges, rewards, and customer rights. This includes providing SMS transaction alerts, free ATM statement access, and clear communication of grievance redressal procedures.

2.17 Risk Assessment

2.17.1 The Central Bank has attached a Risk Matrix in order to assess a series of risk factors recommended by FATF for the issuance of payment products and services including prepaid cards (Also part of Good and Poor Practices shared in April 2021). Although the list is not exhaustive, yet it helps to identify the risks connected with prepaid cards program. It is important to take a holistic approach when assessing the risks presented by prepaid card product. The risk assessment should be developed on a case-by-case basis, taking into consideration the specific features of the single product. Attachment-1.

2.18 Compliance with other Laws

2.18.1 Banks must comply with all applicable laws, including those related to data confidentiality, customer privacy, outsourcing arrangements, charges and promotional campaigns. Banks shall also remain in compliance with the relevant requirements provided in Financial Consumer Protection Regulatory Framework guidelines.

2.19 Reporting

2.19.1 Banks must submit an Annual return to the Manager Surveillance Department (SD) on prepaid cards program, including the number of cards issued, outstanding balances etc. as per Attachemnt-2. Banks will submit the return within 30 calendar days from the end of each year to SD.

Page 12 of 13


Master Circular on Prepaid Card Issuance by Banks

2.20 Issuance of Prepaid Cards to Minors

2.20.1 Issuing cards to minors requires adherence to specific regulations outlined in CBO Circular BM - 1205 and other related guidelines issued from time to time.

2.21 Restrictions in usage

2.21.1 Person to person transfers on the prepaid cards shall not be allowed. 2.21.2 Prepaid cards shall not be allowed to use for transactions with merchants or websites engaged in gambling, betting or lottery services; cryptocurrency exchanges or digital asset platforms; merchants blacklisted or flagged under AML/CFT guidelines; purchase of arms, ammunition, or military equipment, adult internet sites or shops etc.

2.22 Unutilized Balances

2.22.1 The unutilized balances in pre-paid cards should be treated as liability of the bank and reckoned accordingly for reserve requirements.

2.23 Customer Grievance Redressal and Support

2.23.1 The customer grievance redressal mechanism should be clearly defined and details of contact persons/ escalation procedures should be disclosed to customers upfront / made available in the bank's website. Customers must have access to 24/7 support via online and telephonic channels.

2.24 Record Retention

2.24.1 Banks shall maintain comprehensive records of the prepaid card program including necessary approvals, minutes of the meetings and any subsequent changes. Furthermore, Banks shall maintain the complete records related to sale, reloads, limits, CDD and transactions of the prepaid cards in accordance with the Central Bank 's regulations. Supervisory access to these documents should be available to the Central Bank examiners as and when deemed necessary.

2.25 Card Validity

2.25.1 Banks will decide the maximum validity of the prepaid instruments and these cannot be used after expiry. Depending on the issuer's policy, a new card may be issued, or the user may need to request renewal / refund.

Page 13 of 13


Master Circular on Prepaid Card Issuance by Banks

2.25.2 Banks have to ensure that a notification is sent to the prepaid card customers, reasonably before the actual expiry of a prepaid card (e.g., at least 30 days before the expiry of the card) so as to minimize the unused and unclaimed balances maintained with the Bank.

2.26 Transactions details

2.26.1 Banks shall ensure the provision of SMS alerts for all prepaid card transactions without exception. Additionally, Banks may provide customers with login access to bank's website and facilitate viewing transaction details of the prepaid cards.

2.27 Requirements for Fees

2.27.1 All fees must be justifiable relative to the actual cost of providing the service (e.g., card issuance, maintenance). Banks are required to provide a clear, standardized summary of all applicable fees upfront.

2.28 Redemption procedures/charges

2.28.1 The procedures / charges for redemption of outstanding balance in case of cancellation of card by the customer and after expiry of validity period need to be clearly communicated to the customer.

2.29 Internal Review

2.29.1 The product offering / processes should be subjected to review by internal audit, information security, compliance and risk management for mitigating various existing and emerging risks, and necessary adjustments should be made to the program wherever deemed necessary.

2.30 Annual Assessment

2.30.1 All prepaid card products shall be reviewed by the Bank at least once in a year to ensure compliance with above mentioned regulations or any other guidelines issued by the Central Bank from time to time.


Page 14 of 13


Attachment - 1

Risk matrix for assessing risk in relation to Prepaid cards and other electronic payment methods

CriteriaCash¹Higher risk factorsLower risk factors
CDDIdentificationanonymousanonymous
VerificationanonymousCustomer's identity (where obtained) is not verified on the basis of reliable, independent source documents, data or information
Monitoringnonenone
Record keepingRecords are generated for authorities through cross border declarationsElectronic transaction records are generated, but not retained or not made accessible to Law Enforcement Agencies (LEA) upon requestElectronic transaction records are retained and made accessible to LEA upon request
Value LimitsMax. amount stored on account / accounts per personRecords are generated for authorities through cross border declarationsno limit
Max. amount per transaction (incl. loading / withdrawal transactions)no limitno limit
Max. transaction frequencyno limitno limit
Methods of fundingNot ApplicableAnonymous funding sources (e.g. cash, money orders, anonymous NPMs); also multiple sources of funds, e.g. third partiesFunding through accounts held at a regulated financial institution or credit institution, or other identified sources which are subject to adequate AML/CFT obligations and oversight

¹ The 'cash' column is provided to allow a comparison between risk factors for Payment Method and cash, which represents a higher level of ML/TF risk.


Attachment - 1

CriteriaCash¹Higher risk factorsLower risk factors
Geographical limitsSome currencies are accepted more widely than others; currencies can be converted through intermediariesTransfer of funds or withdrawal across national bordersTransfer of funds or withdrawal only domestically
Usage LimitsNegotiability (merchant acceptance)Generally acceptedHigh number of accepting merchants / point of sale (POS) (e.g. through usage of VISA or MasterCard standard)
Utilityp2b, b2b, p2p, no online usage possiblep2b, b2b, p2p, online usage possible
WithdrawalNot ApplicableAnonymous and unlimited withdrawal (e.g. cash through ATMs)
Segmentation of servicesInteraction of service providersNot ApplicableSeveral independent service providers carrying out individual steps of the transaction without effective oversight and coordination
OutsourcingNot ApplicableSeveral singular steps are outsourced; outsourcing into other countries without appropriate safeguards; lack of oversight and clear lines of responsibility

Attachment-2

Details of All Prepaid Card Programs

Sr. No.Types of Prepaid Cards ProgramApplicable Limit (Rial Omani)Remarks, if any

Details of each Prepaid Card Program

Sr. No.Number of Prepaid Cards issuedOutstanding Amount (Rial Omani)Remarks, if any