2025-09-26 | 8-930Added · Updated
Commercial banks must implement anti-fraud systems for remote services, assessing risk for all transactions and verifying medium-risk cases. Banks must compensate clients for unauthorized transactions unless client fault is proven, using operational risk capital. A prohibited identifier registry must be maintained with secure access and 5-year log retention. Effectiveness metrics are reported quarterly, and annual system testing is required, with critical vulnerabilities addressed within 30 working days.
Get NBKR alerts — same-day email on every new publication.
RESOLUTION OF THE BOARD OF THE NATIONAL BANK OF THE KYRGYZ REPUBLIC
of September 26, 2025 No. 2025-P-12/49-3-(NPA)
On Amendments to Certain Regulatory Legal Acts of the National Bank of the Kyrgyz Republic
In accordance with Articles 5, 9 and 64 of the Constitutional Law of the Kyrgyz Republic "On the National Bank of the Kyrgyz Republic", the Board of the National Bank of the Kyrgyz Republic resolves:
"On Approval of the Regulation "On Minimum Requirements for Operational Risk Management in Commercial Banks of the Kyrgyz Republic" dated December 15, 2005 No. 37/5;
"On Approval of the Instruction on Work with Bank Accounts, Accounts for Bank Deposits (Deposits)" dated October 31, 2012 No. 41/12.
within 3 (three) working days from the date of receipt of the relevant documents, publish this resolution on the official website of the National Bank of the Kyrgyz Republic;
after official publication, send this resolution to the Ministry of Justice of the Kyrgyz Republic for inclusion in the State Register of Regulatory Legal Acts of the Kyrgyz Republic.
This resolution enters into force after the expiration of 15 (fifteen) days from the date of official publication, except for paragraphs 15, 16, 17, and 18 of paragraph 1 of the Appendix to this resolution, which enter into force on March 1, 2026.
The Supervision Methodology Department must bring this resolution to the attention of commercial banks and the LLC "Union of Banks of Kyrgyzstan" within 3 (three) working days.
The "Board Secretariat" Department must bring this resolution to the attention of the Banking Supervision Department, the Legal Department, regional departments, and the Representation of the National Bank of the Kyrgyz Republic in the Batken Region within 3 (three) working days.
Control over the execution of this resolution is entrusted to the Member of the Board of the National Bank of the Kyrgyz Republic overseeing the Supervision Methodology Department.
| Chairman | M. Turgunbaev |
| Appendix to the Resolution of the Board of the National Bank of the Kyrgyz Republic of September 26, 2025 No. 2025-P-12/49-3-(NPA) |
AMENDMENTS
to certain regulatory legal acts of the National Bank of the Kyrgyz Republic
The Regulation "On Minimum Requirements for Operational Risk Management in Commercial Banks of the Kyrgyz Republic", approved by the aforementioned resolution, is supplemented with Chapter VI of the following content:
"VI. Minimum requirements for the system for combating internal and external fraud (anti-fraud)
6.1. The Bank is obliged to ensure the presence and effective functioning of a system for combating internal and external fraud (anti-fraud) in accordance with the requirements of this Chapter.
6.2. The requirements of this Chapter apply as the main mechanism for combating internal and external fraud in banking information systems, including in cases where the existing algorithms for combating internal and external fraud in banking information systems do not meet the requirements of this Chapter.
6.3. The Bank is obliged to develop, approve by the Board of Directors, and implement a Policy on Combating Fraud in Remote/Distant Banking Services (hereinafter - the Policy). The Policy may be оформлен as a separate document or be an integral part of the Bank's risk management policy.
The Policy must at least contain:
management's commitment, confirming the commitment to protecting clients from internal and external fraud in remote/distant banking services;
principles for early detection, prevention, and avoidance of fraud in remote/distant banking services;
the procedure for applying adequate and timely automated or semi-automated response measures to identified cases or attempts of fraud, commensurate with the assessed risk level;
liability measures in accordance with the legislation of the Kyrgyz Republic, applied to bank employees for inaction or improper action in the field of combating fraud, including threat monitoring, development and implementation of countermeasures, as well as response to incidents.
The Policy is subject to review and updating no less than once a year.
Internal procedures and documents of the Bank regulating the combating of fraud in remote/distant banking services are subject to review as necessary, but no less than once every two years, taking into account the effectiveness of applied measures, best international experience, and current threats.
The Bank is obliged to integrate the above procedures and documents into the risk management system and ensure that all necessary bank employees are familiar with them.
6.4. The Bank is obliged to implement fraud prevention systems in remote/distant banking service information systems to prevent both internal and external fraud.
These systems must ensure continuous monitoring and fraud risk assessment for each outgoing transaction conducted through remote/distant banking services, regardless of the amount, frequency, and history of previous transactions. Implementation of these systems is permitted in two ways:
as a separate, independent software or software-hardware complex interacting with all automated remote/distant banking service systems used by the bank;
by integrating a specialized anti-fraud module directly into each of the automated remote/distant banking service systems used by the bank.
6.5. When using software for combating internal and external fraud in banking information systems, the Bank must send a corresponding notification to the National Bank with a full description of the implemented architecture, operating principles, and risk assessment methods in accordance with the requirements of this Regulation.
6.6. The system for combating internal and external fraud in remote/distant service information systems must produce a fraud risk assessment for each outgoing transaction based on rules, behavioral models, templates, and analysis results. As a result of the fraud risk assessment, the system must assign at least one of three indicators:
low risk: the transaction is safe;
medium risk: the transaction is suspicious and may be fraudulent;
high risk: the transaction is fraudulent.
6.7. When assigning a medium risk level to a transaction based on a significant deviation from the client's standard behavior or the presence of a combination of factors, the Bank is obliged to ensure its mandatory verification. Verification can be performed automatically or manually by an authorized bank employee. Based on the verification results, the Bank is obliged to perform one or more of the following actions:
re-evaluate the risk level and assign a new level to the transaction: low or high;
make necessary changes to the rules and templates of the anti-fraud system in remote/distant banking services, supplementing them with identified signs of fraudulent operations detected during the analysis of transactions with a high risk level;
ensure storage of full information about the conducted verification, including results, obtained data, information about employees who made decisions, and notifications sent to the client in the remote banking services anti-fraud system. This information is subject to storage for at least 5 years from the date of the operation.
6.8. A low risk level must be assigned to transactions that correspond to typical user behavior, have minor deviations from it, or have passed successful verification after the initial assignment of a medium risk level.
6.9. The Bank has the right to suspend outgoing operations on the bank account for a period of up to 30 days in the following cases:
upon detection of signs corresponding to the fraud criteria established in paragraph 6.12 of this Regulation;
in the absence of information from the client confirming that the operation was performed independently;
upon notification from the client about fraudulent actions on their bank account.
The Bank must provide the ability in remote banking services for individuals to submit a notification about fraudulent actions on their bank account, as well as to generate a statement with the transaction(s) for subsequent appeal to law enforcement agencies.
This opportunity must be implemented as a separate function providing:
24/7 availability without the need to contact bank branches;
the presence of a separate communication channel intended exclusively for transmitting notifications about fraudulent operations;
a simple, intuitive form for submitting a notification, with the ability to specify key transaction parameters: date, amount, recipient details, description of circumstances, and availability of evidence;
automatic recording of the fact of submitting a notification in the bank's information systems with a timestamp and client identifier;
initiation of the procedure for suspension and analysis of the transaction.
A notification submitted through the specified function is subject to immediate consideration, and appropriate measures must be taken to assess the transaction, followed by informing the client of the measures taken, including a recommendation to contact law enforcement agencies.
The Bank is obliged to immediately inform the client about the suspension of the operation using available communication channels (mobile application, email, short message service (SMS), phone call, and others).
6.10. Systems for combating internal and external fraud in remote/distant banking service information systems are obliged to form and maintain a registry of identifiers and attributes prohibited for service, used in fraudulent operations, in the event of assigning a high risk level to a transaction. This registry must include at least the phone number, QR ID, service name (identifier) of the recipient or sender of the payment/banking system, as well as other identifiers and attributes related to fraudulent activity.
6.11. Fraud risk assessment must be subject to all transactions conducted through remote service systems and related to:
issuance of loans;
use of payment QR codes;
interbank and intra-bank fund transfers;
use of "GROSS"/"CLEARING" systems;
international fund transfers (SWIFT and other international money transfer systems);
withdrawal of cash;
acceptance of payments through POS-terminals;
transfer of funds to virtual asset wallets and accounts of foreign operators of virtual asset trading;
repayment of debt from sources not typical for the user;
use of prepaid cards for the purchase of goods and services;
crediting funds through deposit devices (cash-in devices);
transaction using virtual cards;
transfer to accounts and platforms of online casinos, gaming services, and betting sites;
other operations determined by the Bank within the framework of its policy on preventing fraud.
The Bank must determine specialized departments responsible for monitoring transactions in real-time, and if necessary, regularly supplement the list with new transactions subject to risk assessment, taking into account new fraud schemes and changes in digital security.
6.12. For the purpose of assessing fraud risk in conducting transactions, the Bank is obliged to use fraud criteria that serve as the basis for recognizing a transaction as suspicious or fraudulent.
Fraud criteria represent one or a combination of signs and behavioral models indicating a deviation from the client's standard activity and a potential attempt to commit a fraudulent transaction.
Applied fraud criteria must include, but are not limited to, the following signs:
anomalous transaction frequency: sudden increase in the number of transactions initiated or received by the client;
group anomalous activity: sudden growth in activity of a group of clients conducting transactions similar in amount, recipient, or type;
anomalous size (amount) of transactions: transactions for amounts not corresponding to the client's typical behavior, as well as making payments in categories of goods/services unfamiliar to the client;
anomalous geographical location: unusual geographical location (IP address), registration from a new mobile device, use of VPN or proxy servers;
anomalous time of operations: unusual time of day or day of the week for the client to conduct transactions;
multiple failed login attempts: repeated failed authorization attempts in the system;
frequent change of contact information: frequent change of contact details, especially before large transactions;
match with known fraud schemes: correspondence of the transaction to signs of known fraud schemes;
frequent returns or cancellations of transactions: unusually large number of returns or cancelled transactions;
use of suspicious recipients: transfer of funds to accounts of recipients identified as suspicious;
distribution of funds to many recipients: splitting transactions and distributing funds to a large number of recipients;
anomalous sources of fund replenishment: replenishment of the account from sources not typical for this client;
frequent linking and unlinking of payment instruments: frequent change of linked payment cards or accounts;
anomalous changes in access mode: changes in access mode, enabling new authorization methods or changing the login method, not typical for this client;
mismatch of questionnaire data (housewife, unemployed, etc.) with the frequency and amount of transactions;
participation of the client's account in splitting or consolidating funds and rapid transfer to another client's account in another bank;
replenishment of the card by different persons using different tools with subsequent withdrawal from the card;
other criteria determined by the Bank within the framework of its policy on preventing fraud.
6.13. All transactions regarding identifiers prohibited for service must be rejected with appropriate notification to the client.
The Bank must develop internal procedures and documents regulating the procedure for adding identifiers to the registry of prohibited identifiers, as well as the procedure for removing records from it in case of detection of errors or confirmation of independent conduct of the operation by the client.
In the event of detection of facts of conducting transactions regarding identifiers whose service is prohibited by the Bank, as well as facts of conducting transactions by an unauthorized person, except in cases where such transactions were committed due to the fault of the client themselves, or detection of facts of violation of established requirements provided for by regulatory legal acts of the National Bank in the provision of loans, the Bank is obliged to compensate the client for damages arising from such transactions.
Compensation for damages is made from capital reserved for covering operational risks and calculated in accordance with the regulatory legal acts of the National Bank.
6.14. The registry of identifiers prohibited for service may be supplemented manually by authorized bank employees based on reliable information about the fraudulent nature of a particular client identifier, obtained through government agencies and the National Bank, as a result of analysis of publications in local and foreign media, including network editions registered in the established order, or upon receipt of a significant number of similar client appeals regarding suspicious operations.
6.15. The registry of identifiers prohibited for service must be maintained securely, preventing unauthorized interference by bank employees and third parties, ensuring the integrity of records.
Access to the registry is permitted only to authorized bank employees using multi-factor authentication. Any changes in the system must be recorded in the event registration log with the responsible person, time of changes, and grounds for correction. Information from the event registration log must be stored for at least 5 years.
6.16. The Bank must develop and implement systems for monitoring the effectiveness of anti-fraud measures, including the following metrics:
the share of blocked suspicious operations that were subsequently confirmed as fraudulent (Precision);
the share of false positives (erroneously blocked transactions) (False positive rate);
the share of missed fraudulent operations among all confirmed cases (Recall);
average time to detect an incident (Mean time to detect);
average time to respond to an incident (Mean time to respond);
the number of identified and documented fraud methods;
the customer experience and system accuracy indicator, including feedback speed and the percentage of conflict resolution in favor of the client in case of erroneous blocking;
the quality indicator of maintaining the registry of prohibited identifiers (relevance, completeness, timeliness of updates).
The results of the effectiveness assessment are subject to documentation and submission to the National Bank no less than once (one) per quarter.
6.17. The Bank must regularly test systems for combating internal and external fraud to assess effectiveness, accuracy, and resilience to new threats.
Testing is conducted no less than once a year, as well as upon significant changes to the system.
The following types of testing are mandatory:
stress testing, consisting of modeling increased load and non-standard client behavior scenarios to assess the stability and effectiveness of the system;
penetration security testing;
testing of new algorithms based on current fraud methods.
Based on the testing results, the Bank must develop and implement appropriate corrective measures to eliminate identified high-criticality vulnerabilities within 30 working days, for other cases - 60 working days. Deadlines may be extended based on the Bank's technical conclusion.
The Bank must document the testing results and provide them to the National Bank annually.
Testing documentation is subject to storage for at least 5 years.".
The Instruction on Work with Bank Accounts, Accounts for Bank Deposits (Deposits), approved by the aforementioned resolution, is supplemented with paragraph 22-5 of the following content:
"22-5. In the event of detection of signs indicating a possible fraudulent nature of an outgoing operation, the Bank has the right to suspend the conduct of such operation for a period of up to 30 (thirty) days.
The procedure for detecting the specified signs, the algorithm for suspension and resumption of operations is established by regulatory legal acts of the National Bank establishing minimum requirements for the functioning of systems for combating internal and external fraud (anti-fraud).".
Read the rest free
Source: National Bank of the Kyrgyz Republic — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from NBKR
We email you every new NBKR publication the day it's published.