AML compliance in Uzbekistan: business duties and controls
Specific anti-money laundering duties do not apply to every LLC. They apply to the financial and non-financial organizations listed by law. Those organizations must operate internal controls, check customers and controlling persons, report a suspicious transaction by the end of the next business day, and retain the supporting materials for at least five years.
In brief:
- the full AML framework applies to organizations on the statutory list (Article 12), not to every company merely because it has a bank account;
- a regulated organization checks the customer, representative, owners and controlling persons, assesses risk, and continually compares transactions with the established customer profile;
- a suspicious transaction, including an attempted transaction, must be reported within one business day (Article 15);
- transaction and customer due-diligence records must be retained for at least five years (Article 21);
- management should first document whether the company falls within the statutory list and which sector rules apply to it.
Scope and obligated businesses
What counts as money laundering
Cash payment or an unusual transaction alone does not define money laundering. The law defines it as disguising the illicit origin (Article 3) of money or property obtained through criminal activity by transferring, converting or exchanging it, or by concealing its true nature, source, location, movement, ownership or associated rights.
Internal control does not require an employee to prove that a crime occurred. The employee must recognize a transaction that gives grounds for suspicion under the criteria approved for the relevant sector, document the analysis, and send the prescribed report. The organization and its compliance employee do not make the criminal-law determination.
The framework covers money laundering, terrorist financing and financing the proliferation of weapons of mass destruction. This article uses “AML/CFT/CPF” for those three connected areas.
Which businesses have specific obligations
The law generally covers legal entities, branches and representative offices conducting property transactions in and outside Uzbekistan (Article 1-1). The specific internal-control, due-diligence and reporting duties, however, are imposed on the organizations listed in Article 12:
| Category | Organizations covered |
| Financial services | banks and other credit organizations, the National Clearing Centre, money-transfer, payment and settlement organizations, and pawnshops |
| Capital markets and exchanges | securities-market participants, the Central Securities Depository, and exchange members |
| Insurance and leasing | insurers, reinsurers, insurance intermediaries, and organizations providing leasing services |
| Gaming and digital assets | lottery and other risk-based game operators, and crypto-asset service providers |
| Valuables and real estate | persons dealing in precious metals and stones, and persons providing services or participating in real-estate sale and purchase transactions |
| Legal and audit services | notaries, lawyers’ formations and audit organizations when preparing or carrying out transactions for clients |
An ordinary trading, manufacturing or service company does not become a regulated AML organization merely because it has a settlement account, makes a large payment or contracts with a foreign counterparty. Its bank or another regulated intermediary may nevertheless request incorporation documents, ownership information, proof of a representative’s authority, the transaction purpose and the source of funds as part of that intermediary’s own checks.
This article explains cross-sector AML/CFT/CPF duties; it does not cover licensing, capital or prudential reporting. The article on payment organizations explains licensing and Central Bank supervision, while the article on insurance activity covers licensing, reserves and NAPP supervision. Use those guides when the company operates in the corresponding regulated sector.
Internal controls and customer checks
What controls must the business establish
A regulated organization must combine four elements: state oversight (Article 4), internal control, customer due diligence and risk management. Compliance is a continuing process rather than a one-time approval of a policy.
Internal control must specify how reportable transactions are identified, how information is documented and protected, how employees are trained, and which criteria and indicators make a transaction reportable. The applicable sector rules are approved by the relevant authority (Article 6) together with the specially authorized state body. A bank, insurer, realtor and audit organization therefore cannot rely on one generic policy without checking its own rules.
The statutory minimum includes:
- adopting internal rules and allocating authority;
- identifying and verifying the customer, representative, owner and person controlling the customer;
- regularly updating data and continually reviewing the business relationship;
- identifying, assessing, documenting and mitigating risks;
- screening transaction participants against the list of persons involved or suspected of involvement in terrorist activity or weapons-of-mass-destruction proliferation;
- documenting the analysis of unusual transactions and reporting suspicious transactions;
- establishing procedures for refusal, termination, suspension and asset freezing.
These duties are imposed on regulated organizations (Article 15). The required structure of a control function or status of a responsible employee depends on the sector rules, transaction scale and risk. The written policy must match the actual process: who reviews the questionnaire, who decides, where the log is kept, how a report reaches the Department, and who monitors the deadline.
How to assess risk and check customers
Risk is assessed before or when a relationship begins and is reconsidered as the customer and its transactions change. At least once each year (Article 7-1), the organization must systematically study potential risks, record the result, and take proportionate mitigation measures. The assessment must support enhanced or simplified controls and the allocation of resources to higher risks.
Customer due diligence is required when entering into a relationship or carrying out a one-off transaction in the cases defined by sector rules, when a transaction is suspicious, and when previously obtained identity data may be unreliable. It has three core components (Article 7):
- verify the identity and authority of the customer and its representative using documents;
- identify the owner or person controlling a corporate customer by examining its ownership and governance structure;
- continually review the relationship and transactions to confirm that they accord with the information held about the customer and its activities.
The working file normally needs evidence for each conclusion: incorporation records, information about managers and participants, the representative’s authority, an ownership chart, the purpose of the relationship, the expected transaction profile, screening results and explanations for unusual activity. The exact file contents come from the applicable sector rules; the general statute does not replace them.
Calendar example. If the organization approved its annual risk assessment on 20 November 2025, the next documented assessment should be completed by 20 November 2026. If the owner, product, service channel or transaction geography changes before then, risk should be reassessed earlier rather than waiting for the annual cycle.
Reporting and refusal of transactions
Which transactions must be reported, and when
A report is required for a planned, ongoing or completed transaction that the organization classifies as suspicious under its sector rules. The statute also covers a transaction when a party resides, is located or is registered in a state that does not participate in international cooperation in this field. The criterion concerns the transaction and parties (Article 13), not its value alone.
Reports go to the Department for Combating Economic Crimes under the Prosecutor General’s Office. The deadline is no later than one business day after detection and also applies to an attempted transaction. The report and internal log should preserve the basis for suspicion, participant data, amount, date, measures taken and the documents supporting the assessment.
Deadline example. A responsible employee classifies a transaction as suspicious on Tuesday. If Wednesday is a business day, the report must be sent by Wednesday. Internal sign-off must be designed so that management review cannot push the filing beyond the statutory deadline.
An unusual feature does not by itself prove a crime. The organization applies the indicators for its sector, compares the transaction with the customer profile, documents the analysis and takes the action required by its rules. The principal statute does not set one universal monetary threshold that replaces this analysis for every listed sector.
When to refuse a transaction or end a relationship
If the organization cannot complete customer due diligence, it must refuse to open an account, carry out a transaction or enter into a business relationship, end an existing relationship, and report a suspicious transaction. Those steps form one statutory sequence (Article 15), rather than a menu from which the organization may choose one response.
A separate rule applies when a customer does not provide documents needed for identification: the organization must refuse the transaction (Article 16). The exception is the crediting of incoming funds to an individual’s or legal entity’s account. That exception does not automatically permit a later debit transaction without due diligence or remove a reporting duty where suspicion exists.
The refusal decision should be based on a recorded fact: which document or item of information was requested, why the applicable rule required it, what the customer supplied, which discrepancy remained, and who decided. This record distinguishes a mandatory refusal from an arbitrary termination of service.
Records, confidentiality and freezing
How to retain information and protect confidentiality
Transaction records, identification data and due-diligence materials must be retained for at least five years after the transaction or the end of the business relationship. A longer period applies if another relevant sector rule requires it. The file should enable a reviewer to reconstruct the checks, decision and source of information.
Providing information to the specially authorized authority in the prescribed manner does not breach protected secrecy (Article 18). That rule does not permit unnecessary internal disclosure or disclosure to a third party.
The organization must restrict access (Article 20) to AML information and prevent its dissemination. Access to questionnaires, reporting logs, correspondence with the Department and analysis files should be role-based, with a record of user activity.
Employees may not tell a customer that the customer is being monitored. The no-tipping-off rule (Article 19) covers the report, internal analysis and interaction with the authorities. A routine notice of refusal or restriction must not reveal protected AML information.
Retention example. If a one-off transaction occurs on 12 September 2026 and no customer relationship continues, the five-year minimum does not expire before 12 September 2031. For an ongoing customer, the relationship file is tied to the relationship’s termination, while individual transaction data must remain available for at least the required period after each transaction.
When to freeze assets and suspend a transaction
The special regime applies when a transaction participant is on the list of persons involved or suspected of involvement in terrorist activity or weapons-of-mass-destruction proliferation, or directly or indirectly owns or controls a participant. Those transactions must be reported and suspended (Article 14).
When identity data match fully, the organization must act immediately and without prior notice: suspend the transaction, except for crediting incoming funds to an account, and/or freeze the money or property. It must document the screening result and submit a report. The prohibition covers the listed person, a person acting on the listed person’s instructions, owned or controlled property, a controlled legal entity, and property derived from those assets. These cases are listed in the Regulation (paragraphs 26–31).
The frozen amount, measures taken and attempted transactions must be reported within one business day. For a false match, the person applies to the Department, which reviews the application within three business days. Once the organization receives information that the person was removed from the list or that a false match was confirmed, it resumes the transaction on the day of receipt and no later than the following business day.
Procedure example. A full match is found on Monday: the outgoing transaction is suspended immediately without calling the customer first, and the report is submitted by Tuesday if it is a business day. If a false-match notice arrives on Thursday, the transaction is resumed on Thursday and in all cases no later than Friday.
Supervision and liability
Who supervises compliance
The authorities that approved the rules for a sector and the specially authorized state body monitor compliance with those internal-control rules. Evidence should therefore be ready for both the sector regulator and the Department: current policies, appointment orders, access controls, training, risk assessments, questionnaires, logs, analyses, reports and proof that deadlines were met.
The Department may request information, analyze reports and maintain the list. On sufficient grounds, it may issue a binding direction (Article 9) suspending a transaction for no more than 30 business days. Its AML/CFT/CPF decisions are binding on organizations (Article 10).
Supervision example. If a direction specifies 30 business days, the organization must not treat that period as one calendar month. The responsible employee records the date and time of receipt, applies the working-day calendar, restricts the transaction for the stated period, and retains evidence of implementation and later resumption.
What liability applies
A breach of the rules on internal control, documentation and retention, risk assessment, refusal, reporting, freezing or suspension carries a fine of 6.600.000–13.200.000 sum (Article 179-3 of the Code of Administrative Liability). A repeat violation within one year carries a fine of 13.200.000–22.000.000 sum. Here, one BRV means the base calculation unit.
Calculation example. If one BRV is 440.000 sum, the range under the first part is 440.000 × 15 = 6.600.000 sum through 440.000 × 30 = 13.200.000 sum. The upper limit for a repeat violation is 440.000 × 50 = 22.000.000 sum. The website tokens recalculate automatically using the current BRV.
A procedural internal-control breach is not itself the offence of money laundering. Conduct that constitutes laundering of criminal proceeds is a separate crime punishable by five to ten years’ imprisonment (Article 243 of the Criminal Code). Management should distinguish the administrative exposure created by a defective process from the criminal exposure created by participation in the underlying scheme.
Changes and management checks
What changed in 2025–2026
- Instrument No. 3872 of 29 June 2026 introduces on 1 October 2026 an electronic system for assessing the risk that Article 12 organizations breach AML legislation. The risk score by itself is not a basis for an enforcement measure; as of this article’s update date, the rule is not yet in force.
- Resolution No. 3877 of 30 June 2026 introduces new internal-control rules for securities-market participants on 3 October 2026 and replaces the former Rules No. 2033. The new requirements remain future rules until that date.
- Resolution No. 3898 of 13 July 2026 introduces new rules for insurers, reinsurers and insurance intermediaries on 15 October 2026 and repeals the former Rules No. 2036. The current rules apply until the effective date.
What management should check before launch
Management should first confirm the company’s status under the statutory list, identify the regulator, and locate the current version of the sector rules. If the company is listed, use this sequence for the minimum implementation:
- approve internal rules, roles, independence of the responsible employee, and deputy arrangements;
- document the risk model, customer categories, data-update intervals, and annual assessment;
- establish identification of the customer, representative, owner and controlling person;
- implement ongoing transaction monitoring and list screening;
- assign authority for decisions on suspicion, refusal, suspension and freezing;
- configure Department reporting so the one-business-day deadline can be met when the primary employee is absent;
- restrict access, prohibit tipping off, and retain files for at least five years;
- keep evidence of implementation: orders, policy versions, training, logs, questionnaires, review results and proof of submission;
- prepare for the new rules if the organization operates in securities or insurance.
This sequence gives management an auditable system in which each requirement has an owner, document, deadline and completion record. A company outside the statutory list may still appoint an employee to assemble information promptly for bank checks and explain the economic purpose of an unusual transaction, but that voluntary arrangement should not be presented as a mandatory sector AML function.
Frequently asked questions
Must an ordinary LLC adopt AML rules?
Not necessarily. Specific internal-control and reporting duties apply to the categories expressly listed in Article 12. A manufacturing, trading or service LLC does not fall within the list merely because it has a bank account or a large contract. Its actual activities must still be checked: the same company may provide regulated payment, leasing, real-estate or other services and thereby become subject to sector rules.
What makes a transaction suspicious?
A suspicious transaction may be planned, ongoing or already completed and gives rise to a suspicion of money laundering, terrorist financing or proliferation financing. The organization applies the indicators in its sector rules and analyzes the customer, purpose, value, structure and economic rationale. An unusual feature triggers review and documentation; it does not automatically prove a crime.
May the business tell the customer about a report?
No. Employees of a regulated organization may not inform a customer that the customer is being monitored. Communications about a refusal, delay or restriction must not disclose the report, the content of internal analysis or the Department’s actions. Internally, access is limited to employees who need the information for their assigned duties.
How long must customer files be retained?
At least five years after the transaction or termination of the business relationship. The file includes the questionnaire, identification documents, ownership and control information, due-diligence materials, transaction data, correspondence and analysis required by sector rules. If another applicable act requires a longer period, the organization follows that longer requirement.
What if the customer does not provide documents?
If the missing document prevents identification or customer due diligence, a regulated organization refuses the account, transaction or relationship, ends an existing relationship, and assesses whether a suspicious-transaction report is required. The statute has an exception for crediting incoming funds to an account, but that exception does not automatically authorize a later debit without the required checks.
Tax and Legal
legal review and updates
4b Afrosiyob Street,
Tashkent, Uzbekistan
5 September 2026