On-shore VASP in Uzbekistan
Locally-incorporated VASP that operates under full local jurisdiction, holding all required licenses and registrations.
On-shore VASP is conditionally permitted in Uzbekistan with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- Develop and implement internal AML/CFT policies and procedures (uz.licensing.developing-and-implementing-internal-amlcft)
- Conduct Know Your Customer (KYC) for all clients (uz.licensing.conducting-know-your-customer-kyc)
- Monitor transactions for suspicious activities (uz.licensing.monitoring-transactions-for-suspicious-activities)
- Report suspicious transactions to NAPP and other relevant authorities (uz.licensing.reporting-suspicious-transactions-to-napp)
- Identify and verify individuals via reliable, independent sources (passport, national ID) including name, DOB, address, nationality (uz.aml.identification-and-verification, uz.aml.individuals-obtain-and-verify-identity)
- Identify and verify legal entities (name, address, registration, directors, beneficial owners) (uz.aml.legal-entities-obtain-and-verify)
- Identify and verify beneficial owners (>25% ownership or control) (uz.aml.beneficial-ownership-identify-and-take)
- Identify source of funds/wealth for high-risk clients or transactions exceeding threshold (uz.aml.source-of-fundswealth-for-high-risk)
- Apply Enhanced Due Diligence (EDD) for PEPs, high-risk geographies, complex/anonymous transactions (uz.aml.apply-enhanced-due-diligence-edd, uz.aml.politically-exposed-persons-peps-and, uz.aml.clients-from-high-risk-geographic-areas)
- Categorize clients by ML/TF risk profile (low, medium, high) and apply simplified or enhanced CDD accordingly (uz.aml.categorize-clients-based-on-their, uz.aml.apply-simplified-cdd-for-low-risk)
- Ongoing review of customer information and transaction scrutiny to ensure consistency with risk profile (uz.aml.regularly-review-existing-customer-information, uz.aml.scrutinize-transactions-undertaken-by-clients)
- Comply with the Regulation on AML/CFT Measures for Virtual Asset Market Participants (registered Aug 9, 2023, No. 3456) (uz.aml.regulation-on-the-procedure-for)
Key Restrictions
- Must be a legal entity registered in Uzbekistan (uz.licensing.legal-entity-status-the-applicant)
- All data related to virtual asset turnover and client data must be stored on servers physically located in Uzbekistan (uz.licensing.data-storage-all-information-related)
- Must integrate information systems with NAPP's unified monitoring and supervision system (uz.licensing.integration-with-napp-systems-service)
- Must obtain an information security certificate (e.g., ISO 27001) and conduct regular penetration testing and security audits (uz.licensing.obtaining-an-information-security-certificate, uz.licensing.conducting-regular-penetration-testing-and)
- Must meet minimum authorized capital requirements stipulated by NAPP (uz.licensing.authorized-capital-compliance-with-the)
- Directors and key personnel must meet qualification requirements including a clean criminal record (uz.licensing.qualified-personnel-directors-and-key)
- Transactions with virtual assets outside of licensed platforms are generally prohibited (uz.tax.transactions-outside-of-licensed-platforms)
- Virtual assets cannot be used for payments for goods/services within Uzbekistan (uz.tax.it-also-bans-anonymous-transactions)
- Anonymous transactions are banned (uz.tax.it-also-bans-anonymous-transactions)
Key Risks
- NAPP regularly issues clarifications and amendments — regulatory framework is evolving and may change with short notice (uz.licensing.ongoing-refinement-napp-regularly-issues)
- FATF standards via EAG membership may drive future legislative changes impacting operational requirements (uz.licensing.fatf-standards-uzbekistan-as-a)
- High licensing burden with significant capital, IT security, and data localization requirements — non-compliance can lead to revocation
- Transactions outside licensed platforms are prohibited, creating a closed market that depends entirely on NAPP licensing
- Enforcement precedent is limited given the nascent regulatory framework — unclear how aggressively NAPP enforces against non-compliance
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Presidential Decree No. UP-106 "On measures for further development of the digital economy in the Republic of Uzbekistan" dated March 16, 2022. This decree established NAPP as the regulator and laid out the general principles.
Resolution of the Cabinet of Ministers No. 445 "On approval of the Regulation on the procedure for licensing the activities of service providers in the field of circulation of crypto-assets" dated August 22, 2022. This is the most critical document detailing licensing and operational requirements.
Legal Entity Status: The applicant must be a legal entity registered in the Republic of Uzbekistan.
Authorized Capital: Compliance with the minimum authorized capital requirements as stipulated by NAPP (e.g., for crypto exchanges, it's often set at a significant amount in USD equivalent, which usually applies to other VASPs like custodians as well).
AML/CFT Compliance: Strict adherence to international Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) standards, including FATF recommendations. This involves:
Developing and implementing internal AML/CFT policies and procedures.
Conducting Know Your Customer (KYC) for all clients.
Monitoring transactions for suspicious activities.
Reporting suspicious transactions to NAPP and other relevant authorities.
IT Security: Implementation of robust information security systems, including:
Obtaining an information security certificate (e.g., ISO 27001).
Conducting regular penetration testing and security audits.
Data Storage: All information related to virtual asset turnover and client data must be stored on servers located within the territory of the Republic of Uzbekistan.
Integration with NAPP Systems: Service providers must integrate their information systems with NAPP's unified information system for monitoring and supervision.
Qualified Personnel: Directors and key personnel must meet qualification requirements, including relevant experience and a clean criminal record.
Ongoing Refinement: NAPP regularly issues clarifications, guidance, and proposes amendments to existing acts. It is advisable to consult NAPP's official resources for the most up-to-date information.
FATF Standards: Uzbekistan, as a member of the Eurasian Group on Combating Money Laundering and Financing of Terrorism (EAG), is committed to implementing FATF standards. Future legislative changes are likely to reflect ongoing updates to FATF guidance on virtual assets, which may impact custody requirements, particularly regarding travel rule implementation and risk assessments.
Regulation on the Procedure for Carrying Out Anti-Money Laundering and Counter-Terrorism Financing Measures for Virtual Asset Market Participants (Registered by the Ministry of Justice on August 9, 2023, No. 3456).
Identification and Verification:
Individuals: Obtain and verify identity through reliable, independent sources (e.g., passport, national ID card). This includes name, date of birth, place of birth, address, nationality, and ID document details.
Legal Entities: Obtain and verify legal name, legal form, address, registration number, articles of incorporation, names of directors and senior management, and proof of legal existence.
Source of Funds/Wealth: For high-risk clients or transactions exceeding a certain threshold, VASPs must identify and verify the source of funds or wealth involved.
Beneficial Ownership: Identify and take reasonable measures to verify the identity of the beneficial owner(s) of the client. For legal entities, this typically means identifying individuals who own or control more than a specified percentage (e.g., 25%) of the company, or who otherwise exercise control through other means.
Apply Enhanced Due Diligence (EDD) for high-risk clients, transactions, or business relationships. This includes:
Politically Exposed Persons (PEPs) and their family members/close associates.
Clients from high-risk geographic areas (as identified by FATF or NAPP).
Categorize clients based on their ML/TF risk (e.g., low, medium, high).
Apply simplified CDD for low-risk clients/transactions where appropriate.
Regularly review existing customer information to ensure it is up-to-date and relevant, especially for high-risk clients.
Scrutinize transactions undertaken by clients to ensure they are consistent with the VASP's knowledge of the client, their business, and risk profile.
Transactions outside of licensed platforms are generally prohibited.
It also bans anonymous transactions and the use of virtual assets for payments for goods/services within Uzbekistan.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- medium
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — On-shore VASPs are permitted in Uzbekistan but require a NAPP license, local incorporation, data localization, IT security certification, AML/CFT program implementation, minimum authorized capital, and integration with NAPP's monitoring systems; virtual asset transactions by users are tax-exempt but anonymous transactions and payments for goods/services are banned.
Questions this verdict aims to answer
- What license(s) are required to operate locally?
- What capital, governance, and reporting obligations apply?
- What is the application process and timeline?