Remote VASP serving residents in Uzbekistan
Foreign-incorporated entity that offers exchange, custody, or transfer services to residents of a jurisdiction without establishing a local entity or office.
Remote VASP is conditionally permitted in Uzbekistan with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- KYC/identification and verification of all clients (individuals: passport/national ID; legal entities: registration docs, directors, beneficial owners) — per uz.aml.identification-and-verification
- Ongoing due diligence: regular review of customer info, transaction scrutiny, risk categorization (low/medium/high) — per uz.aml.ongoing-due-diligence
- Enhanced Due Diligence (EDD) for high-risk clients including PEPs, high-risk geographic areas, and complex/anonymous transactions — per uz.aml.apply-enhanced-due-diligence-edd
- Beneficial ownership identification (e.g., >25% ownership threshold) — per uz.aml.beneficial-ownership-identify-and-take
- Source of funds/wealth verification for high-risk clients or transactions above threshold — per uz.aml.source-of-fundswealth-for-high-risk
- Suspicious transaction reporting to NAPP and relevant authorities — per uz.licensing.reporting-suspicious-transactions-to-napp
- Internal AML/CFT policies and procedures per FATF standards, including EAG commitments — per uz.licensing.amlcft-compliance-strict-adherence-to and uz.licensing.fatf-standards-uzbekistan-as-a
- Transaction monitoring for suspicious activities — per uz.licensing.monitoring-transactions-for-suspicious-activities
Key Restrictions
- Must be a legal entity registered in the Republic of Uzbekistan — per uz.licensing.legal-entity-status-the-applicant
- All virtual asset turnover and client data must be stored on servers physically located in Uzbekistan — per uz.licensing.data-storage-all-information-related
- Must integrate information systems with NAPP's unified information system for monitoring and supervision — per uz.licensing.integration-with-napp-systems-service
- Must obtain an information security certificate (e.g., ISO 27001) and conduct regular penetration testing — per uz.licensing.obtaining-an-information-security-certificate
- Directors and key personnel must meet qualification requirements including clean criminal record — per uz.licensing.qualified-personnel-directors-and-key
- Minimum authorized capital requirements apply as stipulated by NAPP — per uz.licensing.authorized-capital-compliance-with-the
Key Risks
- Unlicensed cross-border service to residents is likely unlawful; enforcement action by NAPP is probable for non-compliant remote operators
- Data localization and NAPP system integration requirements make true 'remote' (no local entity) service legally impossible
- Regulatory framework is still evolving — NAPP regularly issues clarifications and amendments, creating uncertainty
- Uzbekistan is an EAG member committed to FATF standards; future legislative changes may tighten requirements further
- No clear licensing pathway exists for foreign-incorporated entities without local registration
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
Legal Entity Status: The applicant must be a legal entity registered in the Republic of Uzbekistan.
Presidential Decree No. UP-106 "On measures for further development of the digital economy in the Republic of Uzbekistan" dated March 16, 2022. This decree established NAPP as the regulator and laid out the general principles.
Resolution of the Cabinet of Ministers No. 445 "On approval of the Regulation on the procedure for licensing the activities of service providers in the field of circulation of crypto-assets" dated August 22, 2022. This is the most critical document detailing licensing and operational requirements.
Authorized Capital: Compliance with the minimum authorized capital requirements as stipulated by NAPP (e.g., for crypto exchanges, it's often set at a significant amount in USD equivalent, which usually applies to other VASPs like custodians as well).
AML/CFT Compliance: Strict adherence to international Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) standards, including FATF recommendations. This involves:
Data Storage: All information related to virtual asset turnover and client data must be stored on servers located within the territory of the Republic of Uzbekistan.
Integration with NAPP Systems: Service providers must integrate their information systems with NAPP's unified information system for monitoring and supervision.
Obtaining an information security certificate (e.g., ISO 27001).
Qualified Personnel: Directors and key personnel must meet qualification requirements, including relevant experience and a clean criminal record.
Reporting suspicious transactions to NAPP and other relevant authorities.
FATF Standards: Uzbekistan, as a member of the Eurasian Group on Combating Money Laundering and Financing of Terrorism (EAG), is committed to implementing FATF standards. Future legislative changes are likely to reflect ongoing updates to FATF guidance on virtual assets, which may impact custody requirements, particularly regarding travel rule implementation and risk assessments.
Key Virtual Asset Specific Legislation:
Regulation on the Procedure for Carrying Out Anti-Money Laundering and Counter-Terrorism Financing Measures for Virtual Asset Market Participants (Registered by the Ministry of Justice on August 9, 2023, No. 3456).
Identification and Verification:
Apply Enhanced Due Diligence (EDD) for high-risk clients, transactions, or business relationships. This includes:
Beneficial Ownership: Identify and take reasonable measures to verify the identity of the beneficial owner(s) of the client. For legal entities, this typically means identifying individuals who own or control more than a specified percentage (e.g., 25%) of the company, or who otherwise exercise control through other means.
Source of Funds/Wealth: For high-risk clients or transactions exceeding a certain threshold, VASPs must identify and verify the source of funds or wealth involved.
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — a remote VASP serving Uzbekistan residents must establish a locally registered legal entity, obtain a NAPP license (high burden with minimum capital, ISO 27001, data localization), and comply with full AML/CFT obligations including KYC, EDD, and suspicious transaction reporting; pure cross-border service without local presence is not permitted.
Questions this verdict aims to answer
- May a non-resident provider serve residents from abroad?
- Does cross-border service trigger licensing, registration, or AML obligations?
- What enforcement risk exists for unlicensed remote operators?