2025-10-15 | 133305

Added

REGULATION "On Minimum Requirements for the System of Counteracting Internal and External Fraud in Microfinance Organizations of the Kyrgyz Republic"

This Regulation, issued by the National Bank of the Kyrgyz Republic on October 15, 2025, mandates that all microfinance organizations (MFOs) offering remote services or attracting term deposits establish and maintain an effective anti-fraud system. MFOs must develop a Fraud Counteraction Policy, review it annually, and integrate it into their risk management. The anti-fraud system must assess fraud risk for every transaction, categorizing it as low, medium, or high, and MFOs must implement specific actions for each risk level, including client notification, transaction suspension for up to 30 days, and maintaining a register of suspicious identifiers. MFOs are also required to provide a 24/7 client function for reporting fraud, compensate clients for damages from transactions with prohibited identifiers, and conduct annual system testing, submitting effectiveness reports quarterly and testing results annually by February 1.

National Bank of the Kyrgyz Republic logo

Kyrgyzstan

National Bank of the Kyrgyz Republic

Click to view thumbnail

Go back

Print version

Date of creation: 2026-08-03

Appendix

to the Resolution of the Board of the National Bank of the Kyrgyz Republic

dated October 15, 2025 No. 2025-P-12/52-3-(NPA)

REGULATION

"On Minimum Requirements for the System of Counteracting Internal and External Fraud in Microfinance Organizations of the Kyrgyz Republic"

Chapter 1. General Provisions

  1. This Regulation "On Minimum Requirements for the System of Counteracting Internal and External Fraud in Microfinance Organizations" is applied as the main mechanism for counteracting internal and external fraud in the information systems of microfinance organizations, including in cases where the algorithms for counteracting internal and external fraud available in the information systems of microfinance organizations do not comply with the requirements of this Regulation.

  2. The requirements of this Regulation are mandatory for all microfinance organizations providing services through remote/distance service channels, as well as microfinance companies attracting term deposits (hereinafter - MFOs) based on a license (certificate) of the National Bank of the Kyrgyz Republic.

  3. MFOs are obliged to ensure the presence and effective functioning of a system for counteracting internal and external fraud (anti-fraud system) that corresponds to the scale, nature, and types of their activities.

  4. The system for counteracting internal and external fraud must be aimed at protecting the interests of clients and the MFO itself from fraudulent actions, including actions by employees, clients, third parties, and affiliated persons.

Chapter 2. Policy and Organizational Measures

  1. MFOs are obliged to develop and approve a Fraud Counteraction Policy in remote/distance service systems.

The Policy may be formalized as a separate document or be an integral part of the MFO's risk management policy.

The Policy must contain at least:

  • management's commitment, confirming adherence to protecting clients from internal and external fraud in remote/distance service systems;

  • principles for early detection, warning, and prevention of fraud in remote/distance service systems;

  • procedures for applying adequate and timely automated or semi-automated response measures to identified cases or attempts of fraud, proportionate to the assessed risk level;

  • liability measures in accordance with the legislation of the Kyrgyz Republic, applied to MFO employees for inaction or improper actions in the field of fraud counteraction, including threat monitoring, development and implementation of counteraction measures, and incident response.

The Policy is subject to review and update at least once a year.

Internal procedures and documents of MFOs regulating fraud counteraction in remote/distance service systems are subject to review as needed, but at least once every two years, taking into account the effectiveness of applied measures, best international practices, and current threats.

MFOs are obliged to integrate the above procedures and documents into the risk management system and ensure that all necessary MFO employees are familiar with them.

Chapter 3. Technical Implementation of Anti-Fraud Control

  1. MFOs are obliged to implement fraud counteraction systems in remote/distance service information systems to prevent both internal and external fraud. These systems must monitor and assess fraud risk for each transaction conducted through remote/distance service systems. The implementation of these systems is allowed in two ways:
  • as a separate, independent software or software-hardware complex interacting with all used automated remote/distance service systems;

  • by integrating a specialized fraud counteraction module directly into each of the used automated remote/distance service systems.

  1. The system for counteracting internal and external fraud in remote/distance service information systems must assess fraud risk for each transaction based on rules, templates, and analysis results.

The system for counteracting internal and external fraud must ensure at least:

  • basic transaction verification;

  • comparison with typical client behavioral patterns (if relevant data is available);

  • blocking or suspending suspicious transactions based on predefined criteria.

  1. When using software for counteracting internal and external fraud in information systems, MFOs must send a corresponding notification to the National Bank with a full description of the implemented architecture, operating principles, and applied risk assessment methods in accordance with the requirements of this Regulation.

  2. If full automation is not possible, manual analysis by responsible employees is permitted.

Chapter 4. Risk Categorization and Incident Actions

  1. As a result of fraud risk assessment, the system must assign at least one of three indicators:
  • low risk: transaction is safe;

  • medium risk: transaction is suspicious and may be fraudulent;

  • high risk: transaction is fraudulent.

  1. When a transaction is assigned a medium risk level based on a significant deviation from standard client behavior or the presence of a combination of factors, MFOs are obliged to ensure its mandatory verification. Verification can be performed automatically or manually by an authorized MFO employee. Based on the results of the verification, MFOs are obliged to perform one or more of the following actions:
  • immediately inform the client about a potentially fraudulent transaction using available communication channels (mobile application, phone, other);

  • stop the execution of the transaction until confirming data is received from the client, unequivocally indicating the absence of fraudulent intentions and the conscious execution of the operation;

  • re-evaluate the risk level and assign the transaction a new level: low or high;

  • make necessary changes to the rules and templates of the fraud counteraction system, supplementing them with identified signs of fraudulent operations discovered during the analysis of high-risk transactions;

  • ensure the storage of complete information about the conducted verification, including results, received data, information about employees who made decisions, and notifications provided to the client in the fraud counteraction system for at least 3 (three) years.

  1. A low risk level must be assigned to transactions that correspond to typical user behavior, have minor deviations from it, or have successfully passed verification after initially being assigned a medium risk level.

  2. MFOs are obliged to form and maintain an internal register of identifiers and attributes associated with suspicious or fraudulent activity when a high risk level is assigned.

The register must include at least:

  • phone numbers;

  • IDs of client accounts that performed suspicious actions;

  • devices from which logins were made, uncharacteristic for the given client;

  • other attributes identified during the analysis.

This register must be used for subsequent risk assessment of new applications or operations, with the possibility of blocking or additional verification.

  1. All operations related to the following must be subjected to fraud risk assessment:
  • issuance of microcredits;

  • change of key client information (contacts, details, etc.);

  • re-submission of a loan application within a short period;

  • transfer of borrowed funds to accounts previously noted in suspicious activity (including those obtained from the register);

  • repayment of debt from sources not previously associated with the client;

  • other operations determined by MFOs within their internal policy.

Chapter 5. Basic Signs of Fraudulent Operations

  1. The assessment of operations and applications must be based on a set of rules and templates that identify deviations in the client's behavioral profile or suspicious signs, including, but not limited to:
  • an anomalous increase in the number of loan applications submitted by one client or a group of clients;

  • similarity of applications (IP addresses, devices, amounts, etc.) from different clients;

  • discrepancy between the loan amount or terms and the typical borrower profile;

  • anomalous application submission time, uncharacteristic for the client;

  • use of a new mobile device;

  • multiple failed attempts to authorize in the system;

  • frequent change of contact information;

  • correspondence of the operation to signs of known fraud schemes;

  • discrepancy between personal data (housewife, unemployed, etc.) and the frequency and amount of transactions;

  • change in access mode, inclusion of new authorization methods or change of login method, uncharacteristic for the given client;

  • other criteria determined by MFOs within their fraud prevention policy.

Chapter 6. Obligation to Suspend Operations and Interact with Clients

  1. MFOs are obliged to block or suspend operations for a period of up to 30 days in the following cases:
  • upon identification of signs that correspond to the signs of fraudulent operations established in paragraph 15 of this Regulation;

  • in the absence of confirming information from the client, unequivocally indicating the independent execution of the operation;

  • upon client notification of fraudulent actions.

  1. MFOs must provide for the possibility for individuals to submit notifications of fraudulent actions in remote service systems and to generate relevant documents for subsequent referral to law enforcement agencies.

Such a possibility must be implemented as a separate function, ensuring:

  • 24/7 availability without the need to contact MFO branches;

  • the presence of a dedicated communication channel intended exclusively for transmitting notifications of fraudulent operations;

  • a simple, intuitive notification submission form, with the ability to specify key transaction parameters: date, amount, recipient details, description of circumstances, and availability of evidence;

  • automatic recording of the notification submission in MFO information systems with a timestamp and client identifier;

  • initiation of the transaction suspension and analysis procedure.

A notification submitted through the specified function is subject to immediate consideration and adoption of appropriate measures for transaction assessment, with subsequent informing of the client about the measures taken, including a recommendation to contact law enforcement agencies.

  1. MFOs are obliged to immediately inform the client about the suspension of an operation using available communication channels (mobile application, email, short message service (SMS), phone call, and other communication channels).

Chapter 7. Maintaining an Identifier List and Monitoring Repeats

  1. All transactions related to identifiers prohibited from servicing must be rejected with a corresponding client notification.

MFOs must develop internal procedures and documents regulating the procedure for entering identifiers into the register of those prohibited from servicing, as well as the procedure for excluding entries from it in case of errors or confirmation of independent operation by the client.

In case of identifying facts of transactions related to identifiers whose servicing is prohibited, as well as in case of identifying facts of violation of established requirements in accordance with the regulatory legal acts of the National Bank when providing loans, MFOs are obliged to compensate the client for damages caused by such a transaction.

  1. The register of identifiers prohibited from servicing may be supplemented manually by authorized MFO employees based on reliable information about the fraudulent nature of a particular client identifier, received from state bodies and the National Bank.

  2. The register of identifiers prohibited from servicing must be maintained securely, preventing unauthorized interference by MFO employees and third parties, ensuring the integrity and secure storage of records.

Access to the register is permitted only to authorized MFO employees using multi-factor authentication.

  1. Any changes in the system must be recorded in an event log, indicating the responsible person, time of changes, and grounds for adjustment. Information from the event log must be stored for at least 5 years.

Chapter 8. Evaluation of Anti-Fraud System Effectiveness

  1. MFOs must develop and implement systems for monitoring the effectiveness of fraud counteraction measures, including the following metrics:
  • number of prevented fraud cases;

  • proportion of false positives (erroneously blocked transactions);

  • average incident response time;

  • number of identified and documented fraud methods.

  1. The results of the effectiveness assessment are subject to documentation and submission to the National Bank at least once per quarter.

Chapter 9. Obligations for System Testing and Updating

  1. MFOs must regularly conduct testing of internal and external fraud counteraction systems to assess effectiveness, accuracy, and resilience to new threats.

Testing is conducted at least once a year, as well as when significant changes are made to the system.

The following types of testing are mandatory:

  • stress testing, consisting of simulating mass fraudulent attacks to check system resilience;

  • penetration security testing;

  • testing of new algorithms based on current fraud methods and types.

Based on the testing results, MFOs must, within 30 (thirty) working days, develop and implement appropriate corrective measures to eliminate identified high-criticality vulnerabilities; for other cases - 60 (sixty) working days. Deadlines may be extended based on the MFO's technical conclusion.

  1. MFOs must document testing results and submit them annually to the National Bank by February 1.

Testing documentation must be stored for at least 5 years.

Contacts

Public Reception

+996 (312) 61-04-86 +996 (312) 66-90-15 +1257, +1256

Consumer Protection Department

+996 (312) 66-90-15 +1671, +1666

Report Corruption

+996 (312) 66-90-15 +2120 +996 (312) 61-04-00

Automated Informer for Official Exchange Rates

+996 (312) 61-07-11

Numismatic Museum

+996 (312) 66-90-15 +1232 +996 (312) 61-24-14

E-mail

mail@nbkr.kg

For Media Relations

press@nbkr.kg

720010, Kyrgyz Republic, Bishkek, Kievskaya St., 189