DeFi protocol frontend in Uzbekistan
Operates a web frontend or aggregator that interacts with permissionless smart contracts on behalf of users. May or may not screen users / restrict regions.
DeFi frontend is conditionally permitted in Uzbekistan with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Full KYC/identification of all users (passport/national ID, name, DOB, address, nationality) under NAPP's AML/CFT Regulation (registered Aug 9, 2023, No. 3456)
- Beneficial ownership identification for legal-entity users (25%+ ownership threshold)
- Ongoing transaction monitoring — scrutinize transactions against customer risk profile
- Risk categorization of clients (low/medium/high) with Enhanced Due Diligence (EDD) for high-risk clients (PEPs, high-risk jurisdictions, anonymous-tech transactions, unusual complex transactions)
- Source of funds/wealth verification for high-risk clients or transactions above threshold
- Suspicious transaction reporting to NAPP and relevant authorities
- Integration with NAPP's unified information system for real-time monitoring and supervision
- All client/transaction data must be stored on servers physically located in Uzbekistan
- Regular review of customer information, especially for high-risk clients
Key Restrictions
- Operator must be a legal entity registered in Uzbekistan (uz.licensing.legal-entity-status-the-applicant)
- Must obtain a NAPP license under the framework established by Cabinet Resolution No. 445 (Aug 22, 2022) — the licensing framework is designed for VASPs/crypto-exchanges, not explicitly for DeFi frontends, creating classification ambiguity
- All data must be hosted on servers physically located in Uzbekistan (uz.licensing.data-storage-all-information-related)
- Information systems must integrate with NAPP's unified monitoring information system
- Minimum authorized capital requirements apply (significant USD-equivalent amount set by NAPP)
- ISO 27001 (or equivalent) information security certification required
- Regular penetration testing and security audits required
- Directors and key personnel must meet NAPP qualification requirements and have clean criminal records
- Geofencing may be required de facto since frontend would be subject to full licensing as a crypto service provider — no carve-out for decentralized protocols or frontends
Key Risks
- Regulatory classification ambiguity: Uzbekistan's licensing framework covers 'service providers in the field of circulation of crypto-assets' and does not explicitly distinguish DeFi protocol frontends from centralized VASPs, creating risk of unlicensed activity
- Fee-taking (e.g., frontend swap fees, routing fees) would likely trigger classification as a regulated crypto service provider requiring a full license
- NAPP has broad supervisory powers and can interpret any interface facilitating crypto services as a licensable activity
- FATF/EAG compliance pressure may lead to further tightening — Uzbekistan is an EAG member committed to FATF standards
- Operating without a license or without full KYC/geofencing exposes operators to potential enforcement action, fines, or criminal liability under Uzbek AML law
- Data localization requirement creates operational friction for globally-operated frontends with offshore infrastructure
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Presidential Decree No. UP-106 "On measures for further development of the digital economy in the Republic of Uzbekistan" dated March 16, 2022. This decree established NAPP as the regulator and laid out the general principles.
Resolution of the Cabinet of Ministers No. 445 "On approval of the Regulation on the procedure for licensing the activities of service providers in the field of circulation of crypto-assets" dated August 22, 2022. This is the most critical document detailing licensing and operational requirements.
Legal Entity Status: The applicant must be a legal entity registered in the Republic of Uzbekistan.
Authorized Capital: Compliance with the minimum authorized capital requirements as stipulated by NAPP (e.g., for crypto exchanges, it's often set at a significant amount in USD equivalent, which usually applies to other VASPs like custodians as well).
AML/CFT Compliance: Strict adherence to international Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) standards, including FATF recommendations. This involves:
Developing and implementing internal AML/CFT policies and procedures.
Conducting Know Your Customer (KYC) for all clients.
Monitoring transactions for suspicious activities.
Reporting suspicious transactions to NAPP and other relevant authorities.
IT Security: Implementation of robust information security systems, including:
Obtaining an information security certificate (e.g., ISO 27001).
Data Storage: All information related to virtual asset turnover and client data must be stored on servers located within the territory of the Republic of Uzbekistan.
Integration with NAPP Systems: Service providers must integrate their information systems with NAPP's unified information system for monitoring and supervision.
Qualified Personnel: Directors and key personnel must meet qualification requirements, including relevant experience and a clean criminal record.
Internal Control System: Establishment of an effective internal control system to manage operational risks.
Presidential Decree No. PD-269 of September 2, 2022, "On Measures for the Further Development of the Regulatory Framework for the Circulation of Virtual Assets."
Cabinet of Ministers Resolution No. 592 of October 18, 2022, "On Approval of the Regulation on the Procedure for Licensing the Activities of Virtual Assets Stores and the Regulation on the Procedure for Licensing the Activities of Cryptocurrency Exchanges."
Regulation on the Procedure for Carrying Out Anti-Money Laundering and Counter-Terrorism Financing Measures for Virtual Asset Market Participants (Registered by the Ministry of Justice on August 9, 2023, No. 3456).
Identification and Verification:
Source of Funds/Wealth: For high-risk clients or transactions exceeding a certain threshold, VASPs must identify and verify the source of funds or wealth involved.
Beneficial Ownership: Identify and take reasonable measures to verify the identity of the beneficial owner(s) of the client. For legal entities, this typically means identifying individuals who own or control more than a specified percentage (e.g., 25%) of the company, or who otherwise exercise control through other means.
Categorize clients based on their ML/TF risk (e.g., low, medium, high).
Apply Enhanced Due Diligence (EDD) for high-risk clients, transactions, or business relationships. This includes:
Politically Exposed Persons (PEPs) and their family members/close associates.
Clients from high-risk geographic areas (as identified by FATF or NAPP).
Unusual or complex transactions without an apparent economic or lawful purpose.
FATF Standards: Uzbekistan, as a member of the Eurasian Group on Combating Money Laundering and Financing of Terrorism (EAG), is committed to implementing FATF standards. Future legislative changes are likely to reflect ongoing updates to FATF guidance on virtual assets, which may impact custody requirements, particularly regarding travel rule implementation and risk assessments.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — Operating a DeFi protocol frontend in/from Uzbekistan requires full NAPP licensing as a crypto service provider (legal entity, local data storage, KYC for all users, AML program, IT security certification), because the framework does not distinguish decentralized from centralized services; any fee-taking or user-facing interface likely triggers licensable activity.
Questions this verdict aims to answer
- Is operating the frontend a regulated activity even if the protocol is decentralized?
- What geofencing or KYC obligations apply?
- Does fee-taking change classification?