2025-10-15 | 133305Added
This Regulation, issued by the National Bank of the Kyrgyz Republic on October 15, 2025, mandates that all microfinance organizations (MFOs) offering remote services or attracting term deposits establish and maintain an effective anti-fraud system. MFOs must develop a Fraud Counteraction Policy, review it annually, and integrate it into their risk management. The anti-fraud system must assess fraud risk for every transaction, categorizing it as low, medium, or high, and MFOs must implement specific actions for each risk level, including client notification, transaction suspension for up to 30 days, and maintaining a register of suspicious identifiers. MFOs are also required to provide a 24/7 client function for reporting fraud, compensate clients for damages from transactions with prohibited identifiers, and conduct annual system testing, submitting effectiveness reports quarterly and testing results annually by February 1.
Go back
Print version
Date of creation: 2026-08-03
Appendix
to the Resolution of the Board of the National Bank of the Kyrgyz Republic
dated October 15, 2025 No. 2025-P-12/52-3-(NPA)
REGULATION
"On Minimum Requirements for the System of Counteracting Internal and External Fraud in Microfinance Organizations of the Kyrgyz Republic"
Chapter 1. General Provisions
This Regulation "On Minimum Requirements for the System of Counteracting Internal and External Fraud in Microfinance Organizations" is applied as the main mechanism for counteracting internal and external fraud in the information systems of microfinance organizations, including in cases where the algorithms for counteracting internal and external fraud available in the information systems of microfinance organizations do not comply with the requirements of this Regulation.
The requirements of this Regulation are mandatory for all microfinance organizations providing services through remote/distance service channels, as well as microfinance companies attracting term deposits (hereinafter - MFOs) based on a license (certificate) of the National Bank of the Kyrgyz Republic.
MFOs are obliged to ensure the presence and effective functioning of a system for counteracting internal and external fraud (anti-fraud system) that corresponds to the scale, nature, and types of their activities.
The system for counteracting internal and external fraud must be aimed at protecting the interests of clients and the MFO itself from fraudulent actions, including actions by employees, clients, third parties, and affiliated persons.
Chapter 2. Policy and Organizational Measures
The Policy may be formalized as a separate document or be an integral part of the MFO's risk management policy.
The Policy must contain at least:
management's commitment, confirming adherence to protecting clients from internal and external fraud in remote/distance service systems;
principles for early detection, warning, and prevention of fraud in remote/distance service systems;
procedures for applying adequate and timely automated or semi-automated response measures to identified cases or attempts of fraud, proportionate to the assessed risk level;
liability measures in accordance with the legislation of the Kyrgyz Republic, applied to MFO employees for inaction or improper actions in the field of fraud counteraction, including threat monitoring, development and implementation of counteraction measures, and incident response.
The Policy is subject to review and update at least once a year.
Internal procedures and documents of MFOs regulating fraud counteraction in remote/distance service systems are subject to review as needed, but at least once every two years, taking into account the effectiveness of applied measures, best international practices, and current threats.
MFOs are obliged to integrate the above procedures and documents into the risk management system and ensure that all necessary MFO employees are familiar with them.
Chapter 3. Technical Implementation of Anti-Fraud Control
as a separate, independent software or software-hardware complex interacting with all used automated remote/distance service systems;
by integrating a specialized fraud counteraction module directly into each of the used automated remote/distance service systems.
The system for counteracting internal and external fraud must ensure at least:
basic transaction verification;
comparison with typical client behavioral patterns (if relevant data is available);
blocking or suspending suspicious transactions based on predefined criteria.
When using software for counteracting internal and external fraud in information systems, MFOs must send a corresponding notification to the National Bank with a full description of the implemented architecture, operating principles, and applied risk assessment methods in accordance with the requirements of this Regulation.
If full automation is not possible, manual analysis by responsible employees is permitted.
Chapter 4. Risk Categorization and Incident Actions
low risk: transaction is safe;
medium risk: transaction is suspicious and may be fraudulent;
high risk: transaction is fraudulent.
immediately inform the client about a potentially fraudulent transaction using available communication channels (mobile application, phone, other);
stop the execution of the transaction until confirming data is received from the client, unequivocally indicating the absence of fraudulent intentions and the conscious execution of the operation;
re-evaluate the risk level and assign the transaction a new level: low or high;
make necessary changes to the rules and templates of the fraud counteraction system, supplementing them with identified signs of fraudulent operations discovered during the analysis of high-risk transactions;
ensure the storage of complete information about the conducted verification, including results, received data, information about employees who made decisions, and notifications provided to the client in the fraud counteraction system for at least 3 (three) years.
A low risk level must be assigned to transactions that correspond to typical user behavior, have minor deviations from it, or have successfully passed verification after initially being assigned a medium risk level.
MFOs are obliged to form and maintain an internal register of identifiers and attributes associated with suspicious or fraudulent activity when a high risk level is assigned.
The register must include at least:
phone numbers;
IDs of client accounts that performed suspicious actions;
devices from which logins were made, uncharacteristic for the given client;
other attributes identified during the analysis.
This register must be used for subsequent risk assessment of new applications or operations, with the possibility of blocking or additional verification.
issuance of microcredits;
change of key client information (contacts, details, etc.);
re-submission of a loan application within a short period;
transfer of borrowed funds to accounts previously noted in suspicious activity (including those obtained from the register);
repayment of debt from sources not previously associated with the client;
other operations determined by MFOs within their internal policy.
Chapter 5. Basic Signs of Fraudulent Operations
an anomalous increase in the number of loan applications submitted by one client or a group of clients;
similarity of applications (IP addresses, devices, amounts, etc.) from different clients;
discrepancy between the loan amount or terms and the typical borrower profile;
anomalous application submission time, uncharacteristic for the client;
use of a new mobile device;
multiple failed attempts to authorize in the system;
frequent change of contact information;
correspondence of the operation to signs of known fraud schemes;
discrepancy between personal data (housewife, unemployed, etc.) and the frequency and amount of transactions;
change in access mode, inclusion of new authorization methods or change of login method, uncharacteristic for the given client;
other criteria determined by MFOs within their fraud prevention policy.
Chapter 6. Obligation to Suspend Operations and Interact with Clients
upon identification of signs that correspond to the signs of fraudulent operations established in paragraph 15 of this Regulation;
in the absence of confirming information from the client, unequivocally indicating the independent execution of the operation;
upon client notification of fraudulent actions.
Such a possibility must be implemented as a separate function, ensuring:
24/7 availability without the need to contact MFO branches;
the presence of a dedicated communication channel intended exclusively for transmitting notifications of fraudulent operations;
a simple, intuitive notification submission form, with the ability to specify key transaction parameters: date, amount, recipient details, description of circumstances, and availability of evidence;
automatic recording of the notification submission in MFO information systems with a timestamp and client identifier;
initiation of the transaction suspension and analysis procedure.
A notification submitted through the specified function is subject to immediate consideration and adoption of appropriate measures for transaction assessment, with subsequent informing of the client about the measures taken, including a recommendation to contact law enforcement agencies.
Chapter 7. Maintaining an Identifier List and Monitoring Repeats
MFOs must develop internal procedures and documents regulating the procedure for entering identifiers into the register of those prohibited from servicing, as well as the procedure for excluding entries from it in case of errors or confirmation of independent operation by the client.
In case of identifying facts of transactions related to identifiers whose servicing is prohibited, as well as in case of identifying facts of violation of established requirements in accordance with the regulatory legal acts of the National Bank when providing loans, MFOs are obliged to compensate the client for damages caused by such a transaction.
The register of identifiers prohibited from servicing may be supplemented manually by authorized MFO employees based on reliable information about the fraudulent nature of a particular client identifier, received from state bodies and the National Bank.
The register of identifiers prohibited from servicing must be maintained securely, preventing unauthorized interference by MFO employees and third parties, ensuring the integrity and secure storage of records.
Access to the register is permitted only to authorized MFO employees using multi-factor authentication.
Chapter 8. Evaluation of Anti-Fraud System Effectiveness
number of prevented fraud cases;
proportion of false positives (erroneously blocked transactions);
average incident response time;
number of identified and documented fraud methods.
Chapter 9. Obligations for System Testing and Updating
Testing is conducted at least once a year, as well as when significant changes are made to the system.
The following types of testing are mandatory:
stress testing, consisting of simulating mass fraudulent attacks to check system resilience;
penetration security testing;
testing of new algorithms based on current fraud methods and types.
Based on the testing results, MFOs must, within 30 (thirty) working days, develop and implement appropriate corrective measures to eliminate identified high-criticality vulnerabilities; for other cases - 60 (sixty) working days. Deadlines may be extended based on the MFO's technical conclusion.
Testing documentation must be stored for at least 5 years.
Contacts
Public Reception
+996 (312) 61-04-86 +996 (312) 66-90-15 +1257, +1256
Consumer Protection Department
+996 (312) 66-90-15 +1671, +1666
Report Corruption
+996 (312) 66-90-15 +2120 +996 (312) 61-04-00
Automated Informer for Official Exchange Rates
+996 (312) 61-07-11
Numismatic Museum
+996 (312) 66-90-15 +1232 +996 (312) 61-24-14
For Media Relations
720010, Kyrgyz Republic, Bishkek, Kievskaya St., 189