In Uzbekistan, banks, payment organizations, and payment system operators may be required to implement round-the-clock detection of suspicious transactions and transfers. Depending on a determined risk level, they will be able to either process the transaction, temporarily halt it for client confirmation, or reject it entirely.
Requirements for anti-fraud systems
The draft regulation has been developed by the Central Bank. According to the plan, anti-fraud systems must operate 24/7, analyzing all operations at the moment they occur based on several criteria and scoring. If a transfer is blocked or temporarily rejected, the client must be notified immediately, the reason for the decision must be explained, and they must be informed about the next steps.
The draft also includes a requirement for additional verification in cases where signs of social engineering are detected—a method where attackers use deception or pressure to prompt a person to perform an operation themselves.
Data exchange and supervision
It is planned that banks and payment structures will be obliged to exchange information about new fraudulent schemes and suspicious operations. Furthermore, they must inform the Central Bank about serious incidents and provide a 24-hour reception for client inquiries. It is assumed that anti-fraud models will be audited at least once per quarter. The public can discuss this draft until October 9.
Previously, Uzbekistan introduced the InfoCards system, which allows bank cardholders to find out who and why their card was blocked; now, to obtain this information, one only needs to contact the bank that services the card directly.
