NAPP Proposes Stricter Controls for Crypto Service Providers
Tashkent, Uzbekistan (UzDaily.uz) — The National Agency for Prospective Projects (NAPP) has published draft amendments to internal control rules for crypto asset service providers, introducing stricter requirements for responsible employees, executives, and anti-money laundering procedures.
Under the draft, employees responsible for organizing and implementing internal control will be required to hold positions as deputy heads. Currently, these functions can be performed by executive staff representatives.
A new crypto asset service provider will have to appoint a responsible employee and submit their personal data to NAPP within one month of receiving a license.
At the same time, it is proposed to tighten requirements for executives of crypto service providers. They must not be residents of states that do not participate in international cooperation on anti-money laundering.
Companies registered in such countries will also be barred from becoming founders of a provider.
The proposed requirements for appointing, training, and educating employees include qualification and business reputation criteria. In addition, providers will be required to understand the customer's business, as well as its ownership and management structure.
The draft provides for the possibility of engaging a third party to identify and verify customers as part of due diligence. A specialized organization that confirms the authenticity of personal data is proposed as such a third party.
Specific requirements are set for providers that have controlled or affiliated entities conducting transactions with funds or other property. In such cases, internal rules must be developed using a group approach.
In particular, the rules must establish an information-sharing procedure to manage the risks of laundering criminal proceeds, ensure group-level alignment of compliance control, audit, and anti-money laundering functions, and enable obtaining necessary customer, account, and transaction information from branches and subsidiaries. Proper confidentiality protection for the received information must be guaranteed.
The amendments also clarify the procedure for transmitting suspicious transaction reports. Crypto service providers will be required to send such notifications to the Department for Combating Economic Crimes under the Prosecutor General's Office via secure communication channels.
Secure channels are proposed to include electronic data transmission systems with cryptographic protection, including encryption, secure email addresses, and a personal account in a dedicated system. To connect to the personal account, an organization must submit a request to NAPP detailing company and responsible employee data.
If a transaction is suspended or assets are frozen because a customer is included in the list of individuals involved in or suspected of involvement in terrorism, the responsible employee must notify the customer as quickly as possible.
Furthermore, the employee will need to explain the procedure for resuming the transaction.
Public discussion of the draft amendments will continue until 22 August.