Sign up
Subscribe
Home / news / Uzbekistan changes P2P transfer and banking app login rules from 16 November
news

Uzbekistan changes P2P transfer and banking app login rules from 16 November

The Central Bank of Uzbekistan has approved amendments to the cybersecurity and fraud-prevention rules for remote financial services. The changes affect all banks and fintechs, including Click, Uzum, Payme, and other market players, and they matter because they push more responsibility for fraud losses onto payment providers themselves.

  1. P2P transfers through websites are now banned outright. The functionality moves to mobile apps, while the browser version will still allow users to log into their accounts but not send money. For operators that relied on web-based P2P flows, that is a meaningful cut in flexibility.
  2. When a user logs in from a new device, linked cards are automatically moved to inactive status. Re-enabling them is only possible through an OTP code. Biometric verification remains mandatory only for two cases: logging in from a new device and password recovery.
  3. For card linking, biometric checks have been removed. OTP is now sufficient. At the same time, banks and payment organizations can set their own criteria and limits for P2P transfers that do not require OTP confirmation. Previously, OTP was required for every such transaction without exceptions.
  4. The key shift is liability: companies processing transactions without additional identity checks now bear responsibility for customers’ fraud losses. In practice, that moves financial risk away from the user and onto the payment organization if the protection stack is not strong enough.
  5. For P2P traders, the browser route is no longer an option. Mass or semi-automated processing through web interfaces is out, and the flow is now tied to mobile apps, where bank-side controls are tighter. Device rotation also becomes more expensive operationally, because each new login can trigger OTP reactivation for linked cards.

For legitimate payment providers in gambling, the main takeaway is simple: if the bank now carries more of the fraud bill, it will also want more control over suspicious patterns. That usually means tighter monitoring around accounts with frequent P2P activity, rapid turnover, and profiles that do not look like ordinary retail users.

Weekly high-risk digest

Regulation, sanctions and payment news across your verticals — once a week, free.

Please check your inbox and click the link to confirm your subscription.

Please enter a valid email address!