## EXECUTIVE SUMMARY

## Source details

**Canonical URL:** [EXECUTIVE SUMMARY](https://www.imf.org/-/media/files/publications/cr/2025/english/1uzbea2025004-source-pdf.pdf)

## Other formats

- [Markdown version](/-/media/files/publications/cr/2025/english/1uzbea2025004-source-pdf.pdf.md)
- [Structured JSON version](/-/media/files/publications/cr/2025/english/1uzbea2025004-source-pdf.pdf.json)

---

### Introduction and recent reforms
- Uzbekistan is transitioning to a market-based economy; authorities have undertaken reform measures that strengthened banking supervision.
- Key reforms and milestones:
  - 2019: new central bank law enhanced independence of the Central Bank of Uzbekistan (CBU) and set price and banking sector stability as its mandate.
  - 2020: Government of Uzbekistan’s (GoU) Banking Sector Reform Strategy laid foundation for privatizing many state-owned commercial banks (SOCBs) and changing their operating model toward commercially orientated and competitive system.
  - December 2023: CBU Board adopted the Guidelines on Risk-Based Supervision (GRBS).
  - As of November 2024: additional legislations have been drafted and are under consideration by the Parliament to (i) establish the Financial Stability Board and designate the CBU as the new Resolution Authority; and (ii) extend the deposit insurance system from physical persons to legal entities, introduce a limit to the protection of deposits (UZS 200 MN), and gradually reduce the term for the possible compensation to depositors (up to seven days).

### Legal and institutional constraints on the CBU
- Findings:
  - De jure independence in the Constitution (Article 151) and CBU Act; de facto independence limited by other legal instruments and responsibilities.
  - Assigning development responsibility to the CBU may conflict with its primary objective of ensuring the safety and soundness of banks.
  - Article 23 of the CBU Law does not provide for the duty to publicly disclose the reasons for removal of the Chair of the CBU Board.
  - The Law on Normative Legal Act (LNLA) requires the CBU to agree with the ‘Chamber of Commerce and Industry’ and subjects CBU regulations to Ministry of Justice (MOJ) registration that can be refused on technical and non-technical grounds.
- Recommendations (verbatim highlights):
  - Take action to ensure that the CBU’s independence is not only enshrined in the Constitution and in the CBU Law, but also protected in substance, including by avoiding that the responsibility for the implementation of development programs might compromise its operational independence.
  - Amend Article 102 of the LNLA to streamline the process for the adoption of regulations setting prudential standards by the CBU, e.g. no need for agreement with the Chamber of Commerce and Industry.
  - Amend Article 110 of the LNLA to narrow the Ministry of Justice’s power to refuse the registration of the CBU Regulations.
  - Enhance the transparency of the appointment and removal process of CBU Board members by introducing eligibility criteria and requiring that reasons for dismissal are publicly disclosed.

### Transition to risk-based supervision (RBS) and implementation challenges
- Status and timeline:
  - GRBS adopted December 2023; mirrors ECB methodology but on individual bank basis and excludes climate-related financial risks.
  - 2023: new methodology tested on 4 banks.
  - 2024: tested on 14 banks (tested with 14 banks in 2024).
  - 2025: planned assessment for all 36 banks (plan to conduct risk-based supervision for the rest of the banks in 2025).
- Key implementation issues:
  - RBS requires consistent, well-supported supervisory judgments; internal scrutiny limited (13 changes to the automatic rating during assessment of 14 banks in 2024).
  - Assessors found insufficient QA over curator adjustments to automatic ratings; recommendation to consider a quality assurance unit.
  - GRBS does not address climate-related financial risks nor operational resilience.
  - Off-site supervision of corporate governance needs strengthening; on-site inspections often do not include corporate governance and 80 percent of inspections are conducted within a 30-day limit that may constrain thorough credit-file reviews.
- Supervisory tools and curator role:
  - Combination of off-site supervision and on-site inspections used.
  - The ‘curator’ is focal point for off-site processes; curator may attend board meetings as an observer, creating reputational risk for the CBU.
  - No formalization of the curator role in Law or binding regulation; no cooling-off period before a curator can be hired by supervised banks.
  - Recommendations: formalize curator role (dos and don’ts) and introduce a cooling-off period.

### Supervisory reporting and information powers
- Current practice and deficiencies:
  - Reporting is collected only at solo level and based on internal accounting policy (RAFS/CBU Recommendations) instead of accounting principles and rules that are widely accepted internationally.
  - No supervisory reporting on climate-related financial risks; CBU draft strategy foresees integration by 2027.
  - CBU lacks power to request information from entities in the wider group irrespective of their activities.
  - Ad hoc information requests are channeled unstructured and less secure (via emails); CBU intends SupTech implementation to improve automation and data quality.
  - All banks provide the same data at same frequency and granularity; proportionality and risk-based reporting not yet adopted.
- Recommendations (selected):
  - collect prudential reports and statistical returns also on a consolidated basis;
  - improve data quality, validity checks and data safety for ad-hoc transfers and structure ad-hoc transfers with a secure channel;
  - reformulate supervisory reporting to rely on accounting principles widely accepted internationally;
  - collect information on banks’ exposure to climate-related financial risk;
  - enable CBU to request relevant information from entities in the wider group when material.

### Capital adequacy and Basel III transition
- Framework and metrics:
  - CBU declared transition to Basel III; banks required to observe a total capital adequacy requirement of 13 percent of risk weighted assets, which includes a capital conservation buffer of 3 percent.
  - As of end December 2023, the capital adequacy ratio (CAR) stands at 17.5 percent.
  - Specific domestic minimum ratios:
    - К1 = RC / TRWA – Regulatory Capital to Total Risk Weighted Assets is 13 percent
    - К2 = Tier I/TRWA – Tier 1 Capital to Total Risk Weighted Assets is 10 percent
    - К3 = CET 1/TRWA – CET 1 Capital to Total Risk Weighted Assets is 8 percent
  - Leverage ratio set at 6%.
- Deviations and gaps:
  - Capital definition not fully aligned with Basel Framework: subordinated debts (about 1/3 of Tier 2) do not meet the writing-off/conversion requirement.
  - Some deviations in RWA methodology for minor exposures (e.g., corporate bonds issued by mortgage refinancing companies risk weighted at 20 percent; exposures to MFIs risk weighted at 75 percent though CBU subsequently removed 75 percent and uses minimum 100 percent).
  - CBU identified 7 domestic systemically important banks (D-SIBs) but has not applied a systemic bank (D-SIB) buffer.
  - Lack of a Pillar II methodology means capital requirements are not calibrated to banks’ risk profile.
- Recommendations (verbatim highlights):
  - Adopt a Pillar 2 methodology to calibrate capital requirements to banks’ risk profile.
  - Set a capital buffer for D-SIBs.
  - Align the capital definition to the Basel Framework by tightening criteria for inclusion of common shares in CET1 and subordinated debts in Tier II.

### Credit risk, underwriting, and non-performing loans (NPLs)
- Underwriting and retail trends:
  - Some banks have relaxed underwriting standards in retail lending.
  - Mortgages allocated to households without official income: 60 percent in October 2023 and 43 percent in January 2024.
  - CBU estimated residential real estate prices are on average 28 percent discrepant from fundamentals.
  - Cases exist where microloans are used to repay mortgage loans.
  - Underestimation of borrower’s total indebtedness (DSTI) possible because ‘buy now pay later’ type loans are underreported in the credit bureau; BNPL underreporting: CBU captured 488 dealers; two major providers account for approximately two-thirds of the total gross merchandise volume and are captured and provide information to credit bureaus.
  - CBU measures: concentration limit on car loans set at 25 percent of loan portfolio (August 2023), DSTI extended to all loans (July 2024) and from January 1, 2025 DSTI will be decreased from 60 to 50 percent.
- NPL identification and provisioning issues:
  - CBU’s NPL criteria exclude credit impaired under IFRS 9 Stage 3.
    - As of December 2023: NPL ratio stood at 4.2 percent while IFRS Stage 3 loans are equal to 7.8 percent.
  - RAQP does not define forborne exposures; ‘assets with revised terms’ neglect borrower ‘financial difficulty’ and list of contractual changes constituting a ‘concession’ is not exhaustive.
  - Reclassification of assets as performing lacks a minimum ‘cure period’ (three months missing).
  - Conservative prudential write-off: write-off within three working days after classification as ‘loss’ reduces coverage ratios; coverage ratio (allowances to NPL) at system level was 37 percent as of December 2023 (69 percent if written off loans and associated provisions are considered).
- Recommendations (selected):
  - Expand NPL definition to include defaulted borrowers and IFRS 9 Stage 3 assets.
  - Align ‘assets with revised terms’ to forborne exposures by introducing ‘financial difficulty’ and flexible definition of ‘concessions’.
  - Introduce a minimum ‘cure period’ for reclassification and eliminate exceptions that obfuscate asset quality.

### Related‑party lending, SOCBs, and SOEs
- Findings:
  - SOCB lending to SOEs is not subject to qualitative related-party requirements and is not always on arm`s length commercial terms.
  - CBU has discretion regarding qualification of related parties and application of ‘more favorable terms’ but rarely exerts ‘reasoned judgments’.
  - Definition of related party excludes “members of the committees of the bank and of the parent bank who not responsible for bank risk management”: expression unclear and may create insider opportunities.
- Recommendations:
  - Intensify supervision of SOB lending to SOEs and require arm’s length commercial terms.
  - Exert reasoned judgment when assessing related‑party transactions and consider amending RCRRP Article 17 to remove ambiguous exceptions.

### Market, liquidity, and interest rate risks
- Market risk:
  - Amendments to the Regulation on Risk Management (RRM) registered by the MoJ in January 2025 and entering into force in April 2025 introduced definition of trading book, expanded market risk to derivative instruments, and broadened risk appetite requirements.
  - Supervisory reporting limited to notional amount of derivatives and does not incorporate fair value.
  - Recommendation: collect fair value of OTC derivatives and expand reporting/assessment to derivatives hedging risks other than FX.
- Interest rate risk in the banking book (IRRBB):
  - Amendments elevated IRRBB to a separate and material risk category (until April 2025 IRRBB was a sub-category of market risk).
  - Banks to be required to use methods quantifying EVE and NII under specified scenarios; implementation evidence limited.
  - Recommendations: require D-SIBs to calculate EVE under BCBS scenarios and implement Pillar 2 on IRRBB.
- Liquidity:
  - Banks maintain high liquidity reserves; minimum amount of liquid assets consists of 10 percent of total assets (Instant Liquidity Ratio ≥ 25 percent cited as a metric).
  - LCR and NSFR became effective from January 2016/2018 with minimum requirement of 100 percent since January 1, 2019 in local and foreign currencies.
  - CBU liquidity stress testing assumptions deemed insufficiently conservative (deposit outflow assumed at 2-3 percent; drawdown of credit line at 1-2 percent).
  - Liquidity requirements not calibrated to bank risk profile and systemic importance.

### Operational resilience and outsourcing
- Findings:
  - Operational resilience is underdeveloped in supervision: not incorporated in GRBS nor part of regulation on minimum requirements for inspection of banks.
  - No evidence CBU assessed banks’ mapping of critical operations, business continuity plans/testing, or third‑party risk management.
  - CBU has not issued a regulation on outsourcing of service providers.
- Recommendations:
  - Update GRBS with operational resilience chapter.
  - Assess banks’ operational resilience, mapping, business continuity testing, third-party risk.
  - Issue a regulation on outsourcing.

### Consolidated supervision and group‑wide risks
- Status and findings:
  - Consolidated supervision identified as a priority but not implemented: no Regulation issued to establish specifics of consolidated supervision (Article 48 BL) nor procedures for perimeter and methods of consolidation (Article 61 CBU Law).
  - Prudential requirements and supervisory reporting apply on solo level only.
  - CBU mapped 19 banking groups; requested technical assistance to advance consolidated supervision.
- Recommendations:
  - Accelerate implementation of consolidated supervision including perimeter definition, consolidated reporting, consolidated prudential requirements, and assessment of group‑wide risks.
  - Establish a clear deadline for implementation.

### Crisis management, resolution, and recovery
- Draft Law "On Resolution and Liquidation of Banks":
  - Will establish the Financial Stability Board (CBU to act as secretariat) and designate the CBU as the Resolution Authority.
  - Introduces resolution tools: transfer of assets and liabilities, designation of a bridge bank, enabling bail-in, designing and implementing a reorganization plan.
  - Deposit guarantee draft will cap insured deposits at UZS 200 MN and reduce payout times from twenty business days (Jan 2025) to fifteen (Jan 2026) and seven (Jan 2027); target Fund size five percent of total deposit base.
- CBU actions needed:
  - Prioritize conducting resolvability assessments of D‑SIBs and issuing regulation on recovery plans.
  - Once Resolution Law approved, put in place cooperation frameworks with Deposit Guarantee Agency, Ministry of Economy and Finance, Financial Stability Board, and other bodies.

### Key statistics and supervisory timelines (preserved verbatim)
- There are 36 banks operating in Uzbekistan; of these, 9 banks have a state share, and account for 67 percent of the banking system’s assets.
- The 27 private banks hold the remaining 33 percent of the banking system’s assets (UZB 242.8 trillion).
- Banking system’s total assets are equivalent to 55 percent of Gross Domestic Product (end 2023).
- Bank loans comprise of 40 percent of GDP.
- As of July 1, 2024, assets of the banking sector accounted for 94.6 percent of all assets of the financial system.
- Total number of supervised financial entities (Table total): 344; Volume of assets, billion UZS: 729 911; Share, %: 100
- 2023 real GDP growth: 6.7 percent.
- Consumer price inflation: 10.5 percent in 2024Q3.
- Core inflation: 7 percent.
- Mortgages allocated to households without official income: 60 percent in October 2023 and 43 percent in January 2024.
- CBU identified 7 D-SIBs.
- Banks CAR as of end December 2023: 17.5 percent.
- Capital adequacy requirement: 13 percent (includes capital conservation buffer of 3 percent).
- DSTI timeline and thresholds:
  - Until July 1st, 2024, DSTI limited to microloans at 50 percent;
  - from July 2024 the obligation extended to all loans to individuals and increased from 50 to 60 percent;
  - from January 1, 2025 it’s reduced again to 50 percent.
- As of December 2023: NPL ratio stood at 4.2 percent while IFRS Stage 3 loans are equal to 7.8 percent.
- Coverage ratio (allowances to NPL): 37 percent as of December 2023.
- CBU GRBS testing: tested with 14 banks in 2024; plan to conduct risk-based supervision for the rest of the banks in 2025.
- Macroprudential stress testing: conducted twice a year; adverse scenario time horizon: 3 years; Banks CAR under adverse scenario: 2023 -> 13.6 percent; 2024 -> 10.4 percent.

### Selected policy recommendations (consolidated and verbatim where provided)
- Formalize and protect CBU operational independence; clarify Board appointment/removal transparency and eligibility criteria.
- Amend LNLA and MOJ registration powers to streamline CBU prudential regulation adoption.
- Formalize the curator role and introduce a cooling-off period.
- Integrate climate-related financial risks into GRBS and supervisory reporting; implement climate risk sensitivity analysis and reporting templates by 2026.
- Adopt Pillar 2 methodology and introduce D‑SIB capital buffer.
- Align capital definition and RWA calculation with Basel Framework (tighten CET1, AT1, Tier 2 criteria; adjust RWAs e.g., exposures to MFIs to 100 percent).
- Expand NPL and forbearance definitions to align with IFRS 9 and Basel expectations; introduce minimum cure periods and stricter reclassification rules.
- Accelerate implementation of consolidated supervision and enable consolidated prudential reporting and powers to request information from the wider group.
- Operationalize the resolution framework: conduct resolvability assessments of D‑SIBs and require recovery plans.
- Improve liquidity stress-testing assumptions and calibrate liquidity requirements to banks’ risk profiles and systemic importance.
- Issue regulation on outsourcing and integrate operational resilience into supervisory processes.

*Source: EXECUTIVE SUMMARY — 1uzbea2025004-source-pdf*

### EXECUTIVE SUMMARY __________________________________________________________________________ 7

### EXECUTIVE SUMMARY

### Introduction and recent reforms
- Uzbekistan is transitioning to a market-based economy; authorities have undertaken reform measures that strengthened banking supervision.
- Key reforms and milestones:
  - 2019: new central bank law enhanced independence of the Central Bank of Uzbekistan (CBU) and set price and banking sector stability as its mandate.
  - 2020: Government of Uzbekistan’s (GoU) Banking Sector Reform Strategy laid foundation for privatizing many state-owned commercial banks (SOCBs) and changing their operating model toward commercially orientated and competitive system.
  - December 2023: CBU Board adopted the Guidelines on Risk-Based Supervision (GRBS).
  - As of November 2024: additional legislations have been drafted and are under consideration by the Parliament to (i) establish the Financial Stability Board and designate the CBU as the new Resolution Authority; and (ii) extend the deposit insurance system from physical persons to legal entities, introduce a limit to the protection of deposits (UZS 200 MN), and gradually reduce the term for the possible compensation to depositors (up to seven days).

### Legal and institutional constraints on the CBU
- While CBU independence is upheld in principle in the Constitution (Article 151) and in the CBU Act, other legal instruments limit the CBU:
  - Assigning development responsibility to the CBU may conflict with its primary objective of ensuring the safety and soundness of banks and the banking system.
  - Article 23 of the CBU Law does not provide for the duty to publicly disclose the reasons for removal of the Chair of the CBU Board.
- The Law on Normative Legal Act (LNLA) constrains the CBU’s ability to independently set its own regulations:
  - LNLA requires the CBU to agree with the ‘Chamber of Commerce and Industry’.
  - Ministry of Justice (MOJ) can refuse registration of CBU regulations on technical and non-technical grounds, including assessment of ‘requirements of legal and technical drafting’ and whether the regulation introduces ‘excessive administrative and other restrictions for physical persons and legal entities’.
  - These mechanisms weaken the CBU’s power to independently set prudential standards and go beyond consultation.

### Transition to risk-based supervision (RBS) and implementation challenges
- CBU has transitioned from compliance to RBS; GRBS adopted December 2023 is robust and more forward looking but:
  - GRBS does not address climate-related financial risks nor operational resilience.
  - Implementation timeline and testing:
    - 2023: new methodology tested on 4 banks.
    - 2024: tested on 14 banks.
    - 2025: planned assessment for all 36 banks.
  - Implementation challenges:
    - RBS requires consistent, well-supported supervisory judgments; internal scrutiny was limited (13 changes to the automatic rating during assessment of 14 banks in 2024) and assessors lack experience with the new methodology.
    - Off-site supervision of corporate governance needs strengthening.
- Supervisory tools and processes:
  - Combination of off-site supervision and on-site inspections used.
  - The ‘curator’ is focal point for off-site processes; curator may attend board meetings as an observer, creating reputational risk for the CBU.
    - Recommendation: formalize curator role in Law or binding regulation (dos and don’ts).
    - No cooling-off period before a curator can be hired by supervised banks.
  - On-site inspections generally conducted within a 30-day limit per internal regulation; this timeline may constrain thorough credit file reviews of corporate exposures.
  - On-site inspections should focus more in-depth on banks’ corporate governance.

### Supervisory reporting and information powers
- Supervisory reporting deficiencies:
  - Reporting is collected only at solo level and based on internal accounting policy instead of accounting principles and rules that are widely accepted internationally.
  - No supervisory reporting on climate-related financial risks.
  - CBU lacks power to request information from entities in the wider group.
  - Ad hoc information requests are channeled unstructured and less secure (via emails).
  - CBU has not fully shifted reporting to a risk-based approach leveraging proportionality.

### Capital adequacy and Basel III transition
- CBU declared transition to Basel III but weaknesses remain:
  - Banks required to observe a total capital adequacy requirement of 13 percent of risk weighted assets, which includes a capital conservation buffer of 3 percent.
  - As of end December 2023, the capital adequacy ratio (CAR) stands at 17.5 percent.
  - Capital definition not fully aligned with the Basel Framework: subordinated debts (about 1/3 of Tier 2) do not meet the writing-off/conversion requirement.
  - Some deviations exist in the methodology for risk weighted assets, albeit limited.
  - CBU identified 7 domestic systemically important banks (D-SIBs) but has not applied a systemic bank (D-SIB) buffer.
  - Lack of a Pillar II methodology means capital requirements are not calibrated to banks’ risk profile.

### Credit risk, underwriting, and non-performing loans (NPLs)
- Credit risk management weaknesses:
  - Some banks have relaxed underwriting standards in retail lending.
  - Mortgages allocated to households without official income: 60 percent in October 2023 and 43 percent in January 2024.
  - Discrepancy of about 28 percent between residential real estate prices and fundamental values.
  - Cases exist where microloans are used to repay mortgage loans.
  - Underestimation of borrower’s total indebtedness (DSTI) possible because ‘buy now pay later’ type loans are underreported in the credit bureau.
  - Recent concentration limit of 25 percent of the loan portfolio has constrained banks’ risk appetite for car loans.
- NPL identification and classification issues:
  - CBU’s NPL criteria do not include credit impaired under the applicable accounting framework (e.g., IFRS 9 Stage 3).
    - As of December 2023: NPL ratio stood at 4.2 percent while IFRS Stage 3 loans are equal to 7.8 percent.
  - No definition of forborne exposures; ‘assets with revised terms’ neglects borrower ‘financial difficulty’ and the list of contractual changes constituting a ‘concession’ is not exhaustive.
  - Reclassification of assets as performing lacks stringency; three months of a ‘cure period’ is missing.

### Related-party lending and SOCBs lending to SOEs
- SOCB lending to SOEs:
  - Not subject to qualitative requirements in place for related party transactions.
  - Lending from SOCBs to SOEs not always on arm`s length commercial terms.
  - CBU has discretion regarding qualification of related parties and application of ‘more favorable terms’ but rarely exerted ‘reasoned judgments’.

### Market, liquidity, and interest rate risks
- Recent amendments to the Regulation on Risk Management (RRM), registered by the MoJ in January 2025 and entering into force in April 2025, introduced:
  - Definition of trading book, expanded market risk to derivative instruments, and broadened risk appetite requirements for market risk.
  - Elevated interest rate risk in the banking book (IRRBB) to a separate and material risk category (until April 2025 IRRBB was a sub-category of market risk).
- Liquidity:
  - Banks continue to maintain high liquidity reserves, but liquidity requirements do not fully reflect the risk profile of banks.

### Operational resilience and outsourcing
- Oversight of banks’ ability to deliver critical operations under disruption is underdeveloped:
  - Operational resilience not incorporated in GRBS nor part of the regulation on minimum requirements for the inspection of banks.
  - No evidence CBU has assessed banks’ mapping of critical operations and interdependencies, business continuity plans and their testing, and third-party risk management.
  - CBU has not issued a regulation on outsourcing of service providers.

### Consolidated supervision and group-wide risks
- Consolidated supervision identified as a priority but not implemented:
  - Recommendation: CBU should issue a Regulation to establish specifics of consolidated supervision (Article 48 of the Banking Law (BL)) and procedures for determining perimeter and methods of consolidation (Article 61 of the CBU Law).
  - Prudential requirements and supervisory reporting should be expanded from individual to consolidated level.
  - CBU should assess how group-wide risks are managed and whether entities in the wider group may jeopardize the safety and soundness of the bank and the banking system.

### Crisis management, resolution, and recovery
- CBU should prioritize operationalizing the forthcoming crisis management framework:
  - Draft Law "On Resolution and Liquidation of Banks" will establish the Financial Stability Board (CBU to act as secretariat) and designate the CBU as the Resolution Authority.
  - CBU should prioritize conducting a resolvability assessment of D-SIBs and issuing a regulation on recovery plans.

*Source: EXECUTIVE SUMMARY — 1uzbea2025004-source-pdf*

### INTRODUCTION AND METHODOLOGY

### INTRODUCTION AND METHODOLOGY

### Introduction
- Assessment part of the Financial Sector Assessment Program (FSAP) mission by the IMF and the World Bank, performed during the first FSAP mission in November 2024.
- Reflects legal, regulatory, and supervisory frameworks in place as of November 2024.
- Not intended to represent analysis of the state of the banking sector or the crisis management framework, which are addressed in other parts of the FSAP.

### Information and Methodology Used for Assessment
- The CBU requested assessment according to the Revised BCP Methodology issued by the Basel Committee on Banking Supervision (BCBS) in April 2024.
- The CBU chose to be assessed against Essential Criteria (EC) and Additional Criteria (AC) but graded against Essential Criteria only.
  - Methodology assessment options:
    - (i) assessed and graded against only ECs,
    - (ii) assessed against both ACs and ECs, but graded only against ECs,
    - (iii) assessed and graded against both ECs and ACs.
  - This report grades only ECs.
- Assessment activities:
  - Reviewed framework of laws, rules, and guidance.
  - Extensive meetings with CBU officials and additional meetings with the Ministry of Economy and Finance, Financial Intelligence Unit (FIU), banking sector participants, external auditors, and other stakeholders.
  - Authorities provided a self-assessment and responses to additional questionnaires; access to supervisory documents and confidential files was facilitated.
  - Meetings with CBU staff responsible for banking supervision and external stakeholders were held confidentially; information from meetings is not directly ascribed in the report.
- Assessment context and proportionality:
  - Standards evaluated in context of Uzbekistan’s financial system’s sophistication and complexity.
  - BCPs adopt a proportionate approach; assessment recognizes supervisory practices should be commensurate with complexity, interconnectedness, size, risk profile, and cross-border operations of supervised banks.
  - Assessments are country-specific and time-dependent; ratings are not directly comparable across jurisdictions.
- Assessment team comprised Erika Balaikiene (IMF) and Ezio Caruso (World Bank).

### The 2024 Revised Core Principles (Box 1)
- Revision rationale:
  - Reflects regulatory and supervisory developments, structural changes in banking, and lessons from FSAP assessments since 2012.
  - Took account of countries’ implementation of Core Principles updated in 2012, COVID-19 pandemic impacts and policy responses, and FSAP assessments completed since 2013.
- Thematic updates included heightened attention to:
  - (i) financial risks;
  - (ii) operational resilience, including cyber security risks;
  - (iii) systemic risk and macroprudential supervision;
  - (iv) risks from structural transformations driven by climate change and digitalization of finance;
  - (v) sustained growth of nonbank financial intermediation;
  - (vi) evolving corporate governance and risk management practices, including sound risk culture and sustainable business models.
- Emphases and amendments:
  - Greater emphasis on systemic risk and sound risk management practices.
  - Raised expectations on supervisory assessment of risk, including analysis of banks’ business models and group-wide risks, and macroeconomic and nonbank build-up and concentration of risks.
  - Reinforced need for group-wide approach to supervision.
  - Significant updates to requirements regarding operational risk and operational resilience to ensure banks can withstand, adapt to, and recover from severe operational risk events.
  - Continued emphasis on supervisors’ powers, independence, and the expectation of actual use of powers in a forward-looking approach through early action.
  - 9 additional criteria upgraded to essential criteria.
  - Reaffirmed universal applicability and proportionality: proportionality should not dilute standards but ensure stringency through proportionate methods.

### Institutional and Market Structure — Overview

#### A. Institutional Structure
- The CBU regulates banks and ensures stable functioning of banking and payment systems.
  - CBU independence in carrying out tasks: Article 151 of the Constitution of the Republic of Uzbekistan.
  - Main objectives: ensure stability of (i) prices, (ii) the banking system, (iii) functioning of payment systems.
  - Making a profit is not the CBU’s goal (CBU Law, Article 5).
  - CBU may use “reasoned judgment when ... regulating and supervising banks” (CBU Law, Article 63).
- Other supervisory authorities:
  - Insurance companies and capital markets are licensed and supervised by the National Agency for Prospective Projects (NAPP).
  - CBU and NAPP have not signed a cooperation agreement; meetings and information sharing are irregular, which may raise risk of insufficient/effective supervision and delayed implementation of measures.

#### B. Overview of the Banking Sector
- Bank-centered financial system with high State presence.
  - As of July 1, 2024, assets of the banking sector accounted for 94.6 percent of all assets of the financial system.
  - There are 36 banks operating in Uzbekistan; of these, 9 banks have a state share, and account for 67 percent of the banking system’s assets.
    - Note: as of January 1, 2019, state share was 84 percent.
  - The 27 private banks hold the remaining 33 percent of the banking system’s assets (UZB 242.8 trillion).
  - Banking system’s total assets are equivalent to 55 percent of Gross Domestic Product (end 2023).
  - Bank loans comprise of 40 percent of GDP.
- Table 1 highlights (as of July 1, 2024):
  - Commercial banks: 36; Volume of assets, billion UZS: 690 424; Share, %: 94,6
  - Leasing organizations: 38; Volume of assets, billion UZS: 10 271; Share, %: 1,41
  - Insurance organizations: 35; Volume of assets, billion UZS: 10 212; Share, %: 1,40
  - Microfinance Organizations: 91; Volume of assets, billion UZS: 5 802; Share, %: 0,79
  - Mortgage Refinancing Company (KRI): 1; Volume of assets, billion UZS: 4 441; Share, %: 0,61
  - Fund for Guaranteeing Citizens' Deposits in Banks: 1; Volume of assets, billion UZS: 3 841; Share, %: 0,53
  - Payment Institutions: 47; Volume of assets, billion UZS: 3 157; Share, %: 0,43
  - Pawnshops: 90; Volume of assets, billion UZS: 413; Share, %: 0,06
  - Payment system operators: 3; Volume of assets, billion UZS: 989; Share, %: 0,14
  - Republican Currency Exchange: 1; Volume of assets, billion UZS: 293; Share, %: 0,04
  - Republican Stock Exchange: 1; Volume of assets, billion UZS: 67; Share, %: 0,01
  - Total: 344; Volume of assets, billion UZS: 729 911; Share, %: 100
- Footnote: In August 2024 a public bank was privatized.

### Preconditions for Effective Banking Supervision

#### A. Sound and Sustainable Macroeconomic Policies
- Economic performance and inflation:
  - 2023 real GDP growth: 6.7 percent.
  - First half of 2024: continuation of robust investment and consumption growth.
  - Consumer price inflation: 10.5 percent in 2024Q3.
  - Core inflation: 7 percent.
- Policy environment:
  - Authorities advancing market-oriented reforms while state footprint remains high.
  - Efforts to reduce state involvement in financial sector via governance modernization of state-owned banks, transformation programs, mandating commercial operations, and privatization.
- Macroprudential measures:
  - August 2023: CBU set a concentration limit on car loans to 25 percent of the loan portfolio.
  - July 2024: CBU extended debt service to income (DSTI) limit on all loans to individuals (originally applied only to microloans).
  - Starting on January 1, 2025, DSTI will be decreased from 60 to 50 percent.
  - July 2024: CBU tightened capital requirements for residential real estate and car loans by calibrating them to Loan to Value (LTV) ratio and DSTI.

#### B. Framework for Financial Stability Policy Formulation
- CBU’s semi-annual Financial Stability Report is main tool for dialogue on macroprudential policy and CBU’s Financial Stability Department monitors vulnerabilities and conducts macroprudential stress testing.
- Draft Law "On Resolution and Liquidation of Banks":
  - Will establish the Financial Stability Board; members, rights, and obligations regulated by legal acts of the President.
  - CBU to act as secretariat.
  - Board to meet at least once every six months and at request of CBU or members.
  - Main task: analyze systemic risk and deal with financial crises; an inter-departmental coordinating advisory body adopting recommendations by mutual agreement unless otherwise specified by President.

#### C. A Well-Developed Public Infrastructure
- Anti-corruption and judicial improvements:
  - Anti-Corruption Agency established in 2020; advanced legal framework, digitalization of government services, measures to detect conflicts of interest.
  - New Constitution (2023) improves independence of the Prosecutor General’s Office, Chamber of Accounts, and judiciary.
  - Supreme Board for the Selection of Judges strengthened selection procedures.
  - Government plans to introduce an international commercial court and launched a public procurement portal requiring bidders to disclose beneficial owners.
  - Draft Law on Asset Declaration will require public officials to report assets and income, to be available to the public.
- Insolvency regime:
  - April 2022 Law “On Insolvency” modernized insolvency system and introduced four restructuring options: i) pre-judicial rehabilitation, ii) judicial rehabilitation, iii) external management, iv) amicable agreement.
  - Introduced liquidation procedure for non-viable firms; state-owned companies now subject to insolvency regime.
  - Bankruptcy jurisdiction granted to Economic Courts.
  - New chapter on insolvency of consumers; from January 2023, bankruptcy can be designated for individuals whose debt exceeds a certain threshold.

#### D. Framework for Crisis Management, Recovery, and Resolution
- Draft Law "On Resolution and Liquidation of Banks":
  - Establishes the CBU as the new Resolution Authority.
  - Objectives: prevent systemic financial crises and reduce negative consequences by ensuring continuity of Central Bank's critical functions; protecting depositors' rights; reducing use of state budget for bank resolution.
  - Introduces resolution tools: transfer of assets and liabilities, designation of a bridge bank, enabling bail-in, designing and implementing a reorganization plan.
  - Identifies financing mechanisms for orderly bank resolution.
  - CBU to develop resolution plans for D-SIBs by identifying obstacles to resolution and requiring banks to remove them; may later develop plans for other banks.

#### E. Public Safety Net
- Deposit guarantee law improvements (draft):
  - Current Law "On Guarantees for the Protection of Citizens’ deposits in Banks" guarantees citizens' deposits in full; deposits of individual entrepreneurs and legal entities currently not covered.
  - Draft law will cover individuals and legal entities up to an insured deposit limit of UZS 200 MN (moving away from blanket guarantee).
  - Deposit Guarantee Agency estimated about 99.6 percent of depositors will be protected, including deposits in foreign currencies; deposit insurance payouts will be made in national currency.
- Operational features of draft law:
  - Payment term to be gradually reduced: from twenty business days starting in January 2025 to fifteen and seven in January 2026 and January 2027, respectively.
  - Target size of Guarantee Fund: five percent of the total amount of the banks’ deposit base.
  - Banks’ contributions:
    - one-time (0.1 percent of the minimum authorized capital);
    - quarterly (amount set by Agency’s Board by multiplying the calendar contribution rate by the deposit base);
    - special contributions to eliminate actual or possible deficit.
  - Agency entitled to take a budgetary loan from the State or credit from the CBU in case of Fund deficit.
  - Agency can finance resolution procedures within limits.
  - Fund resources may be invested in assets identified by law as low risk, convertible to cash within seven business days with little or no loss of value.
  - Draft law envisages interaction mechanisms between the Agency and the CBU, the Ministry of Economy and Finance, and other public bodies.

#### F. Effective Market Discipline
- (Section header present; substantive text for “Effective Market Discipline” not included in supplied content.)

*Source: INTRODUCTION AND METHODOLOGY (1uzbea2025004-source-pdf).*

### 13. The regulation on corporate governance (RCG) for banks delineates the

### 1uzbea2025004-source-pdf - 13. The regulation on corporate governance (RCG) for banks delineates the 

### Corporate governance framework and whistleblowing
- The RCG delineates responsibilities of banks’ managerial and operational structure.
- The RCG requires banks to post information on their website, contributing to market discipline.
- The RCG envisages a whistleblowing system to report to the banks’ board (or a committee) inappropriate or unethical behaviors.
- The law "On Joint-Stock Companies and Protection of Shareholders' Rights" increased legal protection of shareholders, including minority shareholders, strengthened responsibility of executive bodies and control over joint stock companies, and ensured information transparency for shareholders and investors.

### A. Responsibilities, Objectives, Powers, Independence, Accountability (CPs 1-2)
- The CBU’s power to set prudential standards is weakened by the LNLA: the LNLA requires the CBU to agree with the Chamber of Commerce and Industry regarding the content of its own Regulations.
- The Ministry of Justice can refuse registration of the CBU Regulations based on technical and non-technical merits, and this process has delayed setting prudential standards.
- The BL does not clearly empower the CBU to review activities of parent companies and affiliated companies to determine impact on bank safety and soundness.
- De jure independence exists in the Constitution and CBU Law, but de facto independence is weakened by attribution of responsibility to implement development programs beyond the CBU Law mandates (ensuring price and financial stability, and the functioning of the payment system).
- Legislative improvements suggested include:
  - Clarify eligibility criteria for CBU Board members (sound reputation, honesty/integrity, minimum years of professional experience).
  - Specify incompatibility criteria for the two independent members (e.g., not holding positions in Parliament or Government).
  - Article 23 of the CBU Law should provide for duty to publicly disclose reasons for removal of the Chair of the CBU Board.
  - Enable the Banking Supervisory Committee to adopt a ‘provisional motivated judgment’ for urgent supervisory action, with prompt post-decision hearing.

### B. Licensing, Changes in Control, and Major Acquisitions (CPs 4-7)
- The CBU recently increased the minimum capital; banks were given a transition period to achieve the level of UZS 500 BN by January 2025; some banks may not reach the required capital and the CBU restricted dividend distributions.
- In 2021-2023, the CBU received 7 applications for a banking license, of which 6 were approved; one was denied due to the precarious financial conditions of the applicant.
- Licensing process: two stages — issuance of a preliminary permit and issuance of a license.
- Shortcomings in licensing assessments:
  - Business plan evaluation is not comprehensive; justification of foreseen activity is superficial.
  - Sustainability of the bank's business model is not assessed.
  - Financials and forecasts are presented in only one (baseline) scenario.
  - No comparison with existing peers; competitiveness within the market is not assessed.
- Ownership change oversight:
  - Licensing Department evaluates proposed ownership changes; CBU can refuse or issue a preliminary permit.
  - Banks submit monthly reports on ownership structure for each shareholder owning one or more percent of the share in the authorized capital.
  - Evaluations do not provide detailed explanations of how the bank's business will continue after a transfer of control.
- Investments in non-financial activities:
  - Banks are prohibited from non-financial investments; allowed investments per Banking Law Article 7 are restricted by limits: entity level up to fifteen percent of the bank’s Tier1 capital; aggregated level up to fifty percent of the bank’s Tier 1 capital.
  - CBU does not require ex-ante or ex-post notification of acquisitions up to these limits; collects only quantitative information through prudential reporting.
  - Limits apply only on solo level, potentially leaving group entities’ investments unconstrained.

### C. Supervisory Approach, Tools and Reporting (CPs 8-10)
- The GRBS (2023) marked a transition to a risk-based approach; however the guideline does not incorporate climate-related financial risks, despite banks’ vulnerability to physical and transition risk.
- Full implementation challenges:
  - In 2024, there were 13 changes in the automatic rating during assessment of 14 banks’ risk profiles; scrutiny of each change has not been as intense as required.
- D-SIBs:
  - The CBU identified 7 D-SIBs and publicly disclosed the list and process to determine systemic importance.
  - The CBU has not conducted a resolvability assessment of D-SIBs.
- Supervisory processes and tools:
  - Combination of off-site supervision and on-site inspections is deployed.
  - The curator is a focal point for supervisory processes but the role is not formalized in Law or binding regulation; no cooling-off period before curator can be hired by supervised banks.
  - Insufficient evidence of separate meetings with independent directors.
  - No systematic system to track open findings beyond action plans.
  - No general duty for banks to notify the CBU in advance of substantive changes or material adverse developments.
  - Assessment of corporate governance is not systematically included in reports shared with assessors.
  - Effectiveness of on-site inspections can be improved:
    - Most inspections (80 percent) are conducted within the 30-day limit envisaged by internal regulation; this timeline may constrict thorough credit file review.
    - Corporate governance risk profile not mentioned in the Resolution ‘Minimum Requirements for Inspections in Banks, based on the Risk-Based Supervision Guidelines’ (August 2024).
- Reporting and data:
  - CBU collects prudential reports and statistical returns on a solo basis, not consolidated.
  - Ad hoc information requested in unstructured form via emails or less secure channels.
  - Supervisory reporting relies on CBU Recommendations based on internal accounting policy rather than widely accepted accounting principles and rules.
  - CBU does not collect information to assess materiality of climate-related financial risks.
  - All banks provide the same data at same frequency and granularity; proportionality and risk-based reporting has not been adopted.
  - CBU lacks power to request relevant information from entities in the wider group irrespective of activities.
  - CBU intends to proceed with a SupTech initiative to strengthen process and data accuracy/integrity.

### D. Corrective and Sanctioning Powers of Supervisors (CP 11)
- The regulatory framework allows early intervention and follow-up via supervisory tools.
- The CBU’s corrective measures and sanctions are broad and applied to banks (including SOBs), members of supervisory and management boards, key personnel, direct or indirect owners of substantial ownership, including the Beneficial Owner (BO).
- The CBU publishes statistics on measures and sanctions on its official website.
- Cooperation with other authorities (Deposit Guarantee Agency, Ministry of Economy and Finance, Financial Stability Board, Central Securities Depository) for orderly resolution of problem banks is not in place until the draft law "On Resolution and Liquidation of Banks" is approved and implemented.

### E. Cooperation, Consolidated and Cross-Border Banking Supervision (CPs 3, 12-13)
- The CBU is encouraged to sign an MoU or Agreement to strengthen cooperation with the NAPP; currently no formalised framework for cooperation and information exchange with NAPP.
- Meetings and information sharing among authorities are irregular.
- The CBU functions largely as a host supervisory authority rather than a home authority.
  - Only one Uzbek bank has a subsidiary abroad; assets are not significant to parent or host market.
  - Assets of foreign bank subsidiaries operating locally account for about 10 percent of total assets of the entire banking system.
  - There are subsidiaries significant and recognized as D-SIBs.
- Supervisory colleges:
  - Considering limited cross-border operations, no supervisory college established by the CBU; an MoU exists with the host country authority for the single foreign subsidiary.
  - A supervisory college exists in relation to the biggest subsidiaries operating in Uzbekistan (about 7 percent of total assets); the CBU has not been invited to join such a college and could formalize a request to the home supervisor.
- Consolidated supervision:
  - Consolidated supervision has been identified as a priority but not prioritized by the CBU.
  - No regulation issued to establish specifics of consolidated supervision (Article 48 BL) nor procedures for determining perimeter and methods of consolidation (CBU Law Article 61).
  - Prudential requirements apply only on an individual bank level.
  - The CBU has recently mapped 19 banking groups and requested technical assistance to advance consolidated supervision.

### F. Corporate Governance (CP 14) and Risk Management (CP 15)
- The CBU has a comprehensive corporate governance regulation recently strengthened; there is no requirement for a succession plan.
- The Risk Committee is not mandatory for D-SIBs.
- Corporate governance as an autonomous risk profile was introduced in 2023; supervisors are expected to evaluate corporate governance and risk management annually as separate components of risk assessment.
  - Off-site assessment of this pillar has not been fully tested in pilot phase (evidence of corporate governance analysis in only one out of four risk assessments).
- RRM (issued April 2023) and amendments:
  - Amendments registered by Ministry of Justice in January 2025 to become effective April 2025:
    - (i) expand risk coverage to IRRBB, country risk and operational resilience related risk;
    - (ii) require board’s approval for large exposures;
    - (iii) introduce new duties for risk management units: back testing of internal models and avoidance of undue reliance on external ratings;
    - (iv) provide for mandatory notification to the CBU of the CRO removal.
  - Amendments lack concrete implementation evidence.
  - Assessors could not find evidence CBU determines that (i) banks perform regular and independent validation and testing of models, and (ii) banks’ boards and senior management understand limitations and uncertainties of model outputs.
  - Revised RRM does not require public disclosure of CRO removal.
  - ‘Requirements for internal capital adequacy assessment procedures’ (RRM article 67-71) are optional for all banks regardless of size and domestic systemic importance.
  - CBU has not issued regulation defining content, updating and submission procedure for recovery plans.

### G. Capital Adequacy (CP 16)
- CBU declared voluntary implementation of Basel III, but capital definition deviates from the framework.
- Deviations exist in credit risk weighted assets for some minor exposures.
- Banks must comply with higher minimum capital requirements than Basel Framework, but capital definition lacks emphasis on elements permanently available to absorb losses on a going concern basis.
  - Some criteria for inclusion of common shares in CET1 are missing (distribution features).
  - Subordinated debts represent about 1/3 of the Tier 2 capital and do not meet the writing-off/conversion requirement.
- Lack of a Pillar II methodology and a systemic risk buffer for D-SIBs means capital requirements are not calibrated to banks’ risk profiles or systemic importance.

### H. Credit Risk and Problem Assets, Provisions and Reserves (CP 17–18)
- The CBU should scrutinize origination practices that might lead to accumulation of NPLs.
- RRM strengthened credit risk prudential framework; nevertheless some banks have relaxed underwriting standards in retail lending.
- Mortgage and household lending:
  - Share of mortgages allocated to households without official income stood at 43 percent in January 2024, down from 60 percent in October 2023.
  - CBU estimated residential real estate prices are on average 28 percent discrepant from fundamentals.
  - Cases where microloans are used to repay mortgage loans.
- Assessment of creditworthiness may underestimate total indebtedness (DSTI) since ‘buy now, pay later’ loans are underreported in the credit bureau.
- Car loans increased quickly and, in some cases, aggressively due to speculative activities in the secondary market; recent concentration limit on car loans is 25 percent of the loan portfolio.
- Problem exposures, provisions and reserves framework deficiencies:
  - Criteria for non-performing exposures are too narrow; they do not include defaulted exposures or credit impaired under applicable accounting framework (e.g., IFRS 9 Stage 3).
  - As of December 2023, the NPL ratio stood at 4.2 percent while IFRS Stage 3 loans are equal to 7.8 percent.
  - ‘Unlikely to pay’ (UTP) included in “unsatisfactory” but poor implementation practices observed.
  - Common reporting is under 90 days past due (dpd), with some exceptions.
  - No proper definition of forborne exposures; ‘assets with revised terms’ neglect the borrower’s ‘financial difficulty’ concept and list of contractual term changes does not capture all possible concessions.
  - First revision of terms does not change previous classification.
  - Exceptions may obfuscate true extent of asset quality (e.g., extension of grace period up to 6 months, or reduction of interest rate on national currency loans down to a level not lower than 2 p.p. of the CBU key rate do not lead to classification as restructured).
  - Reclassification procedures lack a ‘cure period’ of at least three months for assets other than those with ‘revised terms’.

### I. Risks (CP 19–25)
- (Content unit ends at heading "I. Risks (CP 19–25)" with no further text in supplied excerpt.)

*Source: https://www.imf.org/-/media/files/publications/cr/2025/english/1uzbea2025004-source-pdf.pdf*

### 33. Sovereign risk is not adequately incorporated into a banks’ risk assessment.  Overall,

### 33. Sovereign risk is not adequately incorporated into a banks’ risk assessment.  Overall,

### Sovereign exposures and capital impact
- Banking sector exposures to the sovereign, as estimated during the assessment, is UZS 102 bn, equal to 16.6 percent of total assets and 102 percent of total capital.
- Given the lack of a Pillar 2 framework, sovereign risk is not adequately incorporated into the banks’ risk assessment (for example, capital add-on for outlier banks).

### State‑owned enterprises (SOEs) and related‑party considerations
- While SOEs may not be subject to the related party limit, SOB transactions with SOEs should respect typical qualitative requirements of related party transactions:
  - Ensure transactions are conducted on an arms’ length basis.
  - Avoid conflicts of interest.
  - Are approved and monitored by the CBU.
- The CBU should intensify supervision of SOB lending to SOEs.
- The CBU has discretion regarding identification of related parties and application by banks of unlawful ‘more favorable terms’, but it has rarely exerted its ‘reasoned judgments’ on this topic.
- The definition of related party excludes ‘members of the committees of the bank and of the parent bank who not responsible for bank risk management’: the expression is unclear and might open opportunities for insiders’ abuse in transactions other than lending (for example, procurements).

### Country and transfer risk, provisioning
- Following Russia’s war in Ukraine, the CBU stepped up regulatory and supervisory efforts on country and transfer risk.
- The CBU does not properly ensure that country risk is sufficiently taken into account in the determination of provisions.

### Regulatory Risk Management (RRM) amendments, market risk and IRRBB
- Amendments to the RRM registered by the MoJ in January 2025 and set to enter into force in April 2025:
  - Introduce the definition of trading book.
  - Expand market risk to derivative instruments.
  - Broaden the risk appetite requirements for market risk.
  - Consider IRRBB as an autonomous and material risk.
- The CBU has not yet implemented these amendments, particularly:
  - New risk appetite requirements for market risk.
  - Supervision of IRRBB.
- Supervisory reporting is limited to the notional amount of derivatives and does not incorporate the fair value, making it difficult for the CBU to assess the materiality of this market risk subcategory.

### Liquidity risk management
- The CBU has a strong focus on liquidity risk management with a set of requirements to monitor banks’ liquidity.
- The minimum amount of liquid assets consists of 10 percent of total assets.
- Banks are obliged to report their liquidity positions daily.
- The LCR and the Net Stable Funding Ratio (NSFR) became effective from January 2016 through the phased-in approach.
- Since January 1, 2019, both ratios set a minimum requirement of 100 percent; the ratios should be fulfilled in local and in foreign currencies and in all currencies.
- Liquidity requirements are not calibrated to the bank’s risk profile and systemic importance.
- The CBU liquidity stress testing by the Prudential Supervision Department is based on scenarios not adequately conservative (for example, the assumptions on deposit outflow and drawdown of credit line was, respectively, only 2-3 percent and 1-2 percent).

### Operational resilience
- Amendments to the RRM incorporate operational resilience; nevertheless, oversight of banks’ ability to deliver critical operations under disruption is underdeveloped.
- Operational resilience is neither incorporated in the GRBS, nor part of the regulation on minimum requirements for the inspection of banks.
- No evidence of CBU assessment of banks’ mapping process of critical operations and interdependencies, business continuity plans and their testing, and third‑party risk management.
- The CBU has not issued a regulation on outsourcing services.

### Auditing and financial reporting (CPs 26–27)
- The Ministry of Economy and Finance is the ‘authorized state body’ in the field of accounting and audit activities.
- For banks, the CBU has the power to determine the composition and content of financial statements, as well the specifics of conducting audit in banks.
- The CBU has adopted regulations broadly aligned with international standards regarding financial reporting and external audit, but has not clarified differences between:
  - Banks’ financial statements prepared in accordance with IFRS.
  - Statements prepared in accordance with Regulation “On Requirements for the Accounting Policy and Financial Statements of Commercial Banks" (RAFS) No. 3337/2021.
- This dual regime places undue burden on banks.
- Article 75 of the BL requires an audit organization to ‘immediately inform the CBU about situations that lead to gross violations of the laws on banks and banking activities’, but it does not include ‘serious violations’ in the duty of communication.

### Disclosure and transparency (CP 28)
- The CBU has not implemented Pillar 3 of the Basel Framework.
- Adequate disclosure is requested to joint stock companies and, more specifically, for banks by the RCG (Article 53).
- Assessors found a sufficient level of disclosure on the same banks’ websites.
- Disclosure requirements do not include information related to:
  - Risk management strategies.
  - Risk exposures (for example, sovereign risk, climate risk).
- SOCBs do not disclose their exposures to SOEs as part of related party transactions.

### Abuse of financial services (CP 29) / AML/CFT
- The CBU has adopted a comprehensive approach to implement existing legislation and regulations for AML/CFT.
- The CBU performs an assessment of AML/CFT risk profile for all banks once a year and proceeds with the AML/CFT sectorial analysis for all financial sectors.
- Banks identified as “high” risk are subject to on-site inspection for the next year.
- There is a dedicated unit for AML/CFT on-site inspections to cover the whole financial sector; it consists of only 8 FTEs, suggesting resources for AML/CFT on-site inspections are not sufficient.
- Cooperation among authorities is positive and AML/CFT is a national priority.
- Positive evaluation from the Eurasian Group of combating money laundering and financing of terrorism (EAG) which found a strong level of supervision over financial institutions.

### Supervisory powers, responsibilities and legal framework (Detailed assessment highlights)
- CBU’s mission and supervisory mandate:
  - CBU Law Article 5 includes ‘to ensure the stability of the banking system’.
  - Article 11 mandates the CBU to use ‘reasoned judgment when ... regulating and supervising banks’.
  - Articles 60 and 61 set out regulatory and supervisory functions, exerted by the Banking Supervision Committee (Article 64).
- Banking Law (BL) Article 4 defines the CBU as a government authority regulating banking activities and exercising mandates for licensing, regulation and prudential supervision; BL Article 3 defines prudential supervision.
- Responsibilities and objectives of the CBU are publicly disclosed through the CBU Law, the BL, and CBU regulations.
- Primary objective of banking supervision is embedded in the objective to ensure the ‘stability of the banking system’ (CBL Article 5); consumer protection objectives (BL Chapter IX) exist and could create potential conflicts with financial stability when financial inclusion measures affect underwriting standards.
- CBU has separated the financial inclusion unit from the Department of Methodology of Regulating Credit Organizations’ (2023) to mitigate conflicts, but potential conflicts persist.
- Legal framework for prudential standards:
  - CBU issues Regulations binding on individuals and juridical persons (CBU Law Article 9).
  - BL Article 38 empowers the CBU to set prudential standards on:
    - capital adequacy
    - concentration risk (both ‘single-name’ and economic sector)
    - liquidity
    - limits to exposures to related party
    - limits for uncollateralized loans
    - assets classification and provisioning
    - accrual of interest on the bank's assets and their recording in the financial statements
    - limits to equity investments
    - requirements for the acquisition and ownership of real estate and other property
    - open currency position limits
    - other prudential standards established by the CBU in accordance with generally accepted international practice.
- Constraints on CBU regulatory power:
  - The LNLA requires draft normative legal acts be agreed with interested state bodies and registered by the Ministry of Justice (MoJ).
  - Drafts affecting business activities must be consulted with the Chamber of Commerce and Industry (LNLA, Article 102).
  - MoJ legal review can consider ‘excessive administrative and other restrictions’ and drafting requirements, which has led to refusals and regulatory delays.
  - Article 110 of the LNLA gives the MOF grounds to refuse registration if the draft is not agreed by all interested bodies or lacks specified documents.
  - Disagreements with Chamber of Commerce have required the CBU to justify powers over setting debt burden limits.
  - A draft regulation on risk management was refused by the MoJ on grounds of fragmentation and drafting technique errors, leading to significant regulatory delays.

_Italic: Source — Content unit from 1uzbea2025004-source-pdf (IMF assessment excerpt)._

### Chapter 7 of the BL (‘Measures and sanctions taken by the Central Bank for violations of

### Chapter 7 of the BL (‘Measures and sanctions taken by the Central Bank for violations of legislation on banks and banking activities’)

### Enforcement powers and scope
- The CBU can apply measures and sanctions against the bank, members of the supervisory board and the board, as well as key personnel of the bank responsible for violations specified in Articles 54, 55 and 56.
- Violations are classified as gross, serious and minor. Both gross and serious violations include non-compliance with prudential standards (see CP11).
- BL Article 51 (‘Supervisory Measures’) enables the CBU to require banks and banking groups to take immediate actions including:
  - ensuring and maintaining prudential capital standards in excess of the requirements set by the CBU;
  - submitting an action plan to ensure compliance with the BL;
  - early termination of powers or replacement of one or more members of the supervisory board;
  - applying individual reserve requirements (e.g. provisioning), providing additional reporting or disclosure, and fulfilling other instructions by the CBU.

### Powers to increase prudential requirements (capital, liquidity, other)
- Article 38 of the BL: CBU has the “right to establish additional premiums to the values of liquidity and capital adequacy ratios for banks, banking groups and systemically important banks, to cover potential losses arising from maximum changes in risk factors.”
- CBU RCAR (Chapter 3, par. 5): CBU can require banks to increase the size of their regulatory capital in cases of:
  - unsatisfactory  financial  situation  that  may  lead  to  unsecured  and  unstable  banking activity;
  - unsatisfactory forecasts profits;
  - high level of risks and off-balance items.
- RCAR (Chapter 7, par. 39): CBU may require higher capital adequacy coefficient based on risks including, but not limited to, large amounts of NPLs, net losses, high asset growth, high interest rate risk, or risk-based activities.
- Although RRLM No. 2709/2015 does not contemplate similar provisions, assessors considered BL powers sufficient to increase liquidity prudential requirements in relation to risk profile or systemic importance.
- Other measures under Article 51: individual reserve requirements (provisioning), additional reporting/disclosure, and other CBU instructions.

### Public consultation, disclosure, and timeliness of standards
- Banking laws, regulations and prudential standards are updated as necessary; subject to public consultation and published in a timely manner (EC4).
- Notable updates and instruments:
  - 2019: Senate approved a package of financial sector laws, including amendments to the CBL Law and revisitation to the BL.
  - May 2020: Strategy for Reforming the Banking System of the Republic of Uzbekistan for 2020-2025 approved.
  - 2020: CBU approved ‘Regulation on corporate governance of commercial banks’ No. 3254/2020.
  - 2023: Amendments to BL increased the minimum capital for banks (see CP 5).
  - April 2023: CBU approved Regulation on minimum requirements for the risk management system in banks and banking groups No 3427/2023.
  - 2024: Regulation "On the Procedure for Applying Measures and Sanctions in Relation to Banks and Non-Bank Credit Organizations" No 3492/2024.
- Public consultation process:
  - Article 24 of the LNLA: draft regulatory legal acts are posted by the CBU on the portal for public discussion; public discussion period cannot be less than fifteen days from posting.
  - Originator must justify rejection of comments.
  - BL Article 38: “The upcoming changes in prudential standards are officially announced by the Central Bank no later than one month prior to their enactment”.
  - Normative Legal Act must be published on official websites within one day after adoption; publication is mandatory prior to application (Article 38 LNLA).
  - Informal pre-consultation with banks occurs by sharing draft regulation. The Banking Association does not play an active role in executing this activity.

### Supervisory access and consolidated/foreign supervision (EC5, EC7)
- Legal provisions grant CBU full access to banks’ board, management, staff and records, including service providers, and power to review overall activities, domestic and cross-border:
  - CBU can access bank premises, board, management, staff and records during on-site inspections and through curators (see CP 8).
  - CBU Law Article 61: right to request and verify reports and other documents from credit institutions, related persons, banking groups, persons providing outsourced services, and associations.
  - BL Articles:
    - Article 45: banks must provide information necessary to assess compliance with prudential requirements.
    - Article 41: banks that outsource services must ensure provision of information to the CBU on outsourced services and operations.
    - Article 50: empowers CBU to receive/check reports and documents; check activities of banks and outsourced service providers; and use information systems and bank databases.
    - Article 47: CBU must annually approve a supervisory program including an inspection plan and may conduct additional inspections and thematic examinations.
- Supervision of foreign activities:
  - Article 31: Uzbekistan banks may open subsidiaries or branches abroad with CBU permission when:
    - (i) agreement on exchange of information exists between CBU and host supervisor;
    - (ii) host country legislation and application methodology do not impede CBU supervisory functions;
    - (iii) management and financial condition of the bank are sufficient for planned activities;
    - (iv) compliance with prudential standards and other BL requirements.
  - Article 48: CBU should exercise consolidated supervision in cases of creation of a banking group or determination by CBU of parent bank/member of banking group by “reasoned judgment”.
  - CBU has right to conclude written agreements on interaction/cooperation with foreign banking supervisory authorities.

- Limitations and recommendations (EC7):
  - BL does not define ‘parent company’ nor ‘companies affiliated with parent companies’; parent bank is defined (BL Article 3). Civil Code Article 68 defines “associate” company as dependent if another participating company has more than twenty percent of its voting shares.
  - CBU notes provisions (person related to a bank; persons subject to consolidated supervision Article 61, 64 and 66) and licensing powers over founder/acquirer/substantial owner (CP5, CP6) that enable supervisory reach over parents/affiliates.
  - If parent company and affiliates are foreign, CBU can rely on cooperation agreements and information exchanges (BL Article 68).
  - Assessors recommend legislative amendments to remove legal uncertainty and unambiguously vest CBU with powers to review activities of parent companies and affiliates to determine their impact on bank safety and soundness.
  - Assessors found no robust evidence that CBU reviews activities of parent companies and affiliates and assesses their impact on bank soundness.

### Corrective actions, sanctions, revocation and resolution (EC6)
- Corrective actions:
  - CBU Law Article 67: CBU can apply measures and sanctions to banks, direct and indirect shareholders (including BO), members of supervisory and management boards, and key personnel.
  - BL Article 51: CBU may require banks/banking groups to take immediate action in cases of:
    - inconsistency with BL requirements;
    - reasoned judgment about possible violation within next twelve months;
    - identification of risks affecting activities and/or information security.
- Sanctions (BL Articles 54–59; see CP11):
  - Fines when incomes from violating transactions can be quantified:
    - gross violation: fines could reach two times the amount of these income;
    - serious violation: one and a half times;
    - minor violation: the amount of these incomes.
  - If quantification not possible, fines could be:
    - gross violation: 5 percent of net profit of previous financial year, or 1 percent of total capital;
    - serious violation: 2 percent of net profit, or 0.5 percent of total capital;
    - minor violation: 1 percent of net profit, or 0.1 percent of total capital.
  - Other measures available to CBU are detailed under CP11.
- Revocation of bank license:
  - CBU may revoke license in case of gross violation (BL Article 57).
  - Other grounds include failure to comply with licensing conditions; losses exceeding ten percent of regulatory capital in three consecutive quarters or fifty percent of regulatory capital regardless of time period; onset of insolvency.
  - CBU has recently revoked 2 banking licenses (see CP11).
- Orderly resolution:
  - Some instruments exist for reorganization and liquidation, but broader mechanisms for orderly bank resolution are missing.
  - A draft Law "On Resolution and Liquidation of Banks" aims to enable CBU to cooperate and exchange information with state bodies and foreign supervisors during rehabilitation and liquidation; assessors noted draft exists but could not incorporate it prior to enactment.

### Assessment, findings and recommendations (Principle 1 and Principle 2)
- Assessment of Principle 1: Largely Compliant.
  - Finding:
    - CBU’s primary objective of banking supervision is to promote safety and soundness, but other objectives, including consumer protection and financial inclusion, are not subordinated.
    - BL does not clearly state CBU has power to review activities of parent companies and companies affiliated with parent companies to determine their impact on safety and soundness.
  - Recommendations:
    - Subordinate the CBU’s responsibility in consumer protection and financial inclusion and development to its primary objective to ensure the safety and soundness of banks and the banking system.
    - Empower the CBU to review the activities of parent companies and companies affiliated with parent companies to determine their impact on the safety and soundness of the bank.
- Principle 2 (Independence, accountability, resourcing and legal protection for supervisors):
  - Legal basis:
    - CBU legal status, powers and organization determined by Constitution, CBU Law and other legislation (CBU Law Article 3).
    - Article 151 of the Constitution: CBU shall be independent in carrying out its tasks.
  - Protections and limits to independence:
    - CBU makes decisions independently of other public authorities and governing bodies; CBU not liable for state debts and vice versa unless otherwise provided (CBU Law Article 3).
    - Inspection procedures determined by CBU independently; inspections carried out without consent/notification of state bodies (CBU Law Art. 66).
    - CBU prevented from providing loans or financial assistance to Government, participating in capital of banks, issuing guarantees for third parties (CBU Law Article 6).
    - Board can form reserves and special purpose funds; not allowed to transfer remainder of profits to State budget prior to consideration of CBU annual report (CBU Law Article 14).
    - CBU not entitled to use open market operations to finance State budget or buy government securities at initial placement (Article 34).
  - Evidence of discretion:
    - CBU applied sanctions to state-owned banks (SOBs) and prevented 4 of them from issuing new loans (not secured by funds) until NPLs reached 5 percent of total loans; removed a board member of a SOB; recommended changing head of risk management.
  - Limits to full discretion:
    - Legislation affecting business activities must be consulted/agreed with Chamber of Commerce and Industry and its entry into force is subject to MoJ registration (LNAL, Article 102). This limits full discretion to set prudential policy.
    - From policy setter standpoint, independence is limited by LNLA due to need for agreement with Chamber of Commerce and Industry and MoJ registration which can be refused on technical grounds.
  - Accountability:
    - CBU accountable to the Senate of the Oliy Majlis; Senate reviews annual report together with audit conclusion (CBU Law Article 8).

*Chapter 7 of the BL (‘Measures and sanctions taken by the Central Bank for violations of legislation on banks and banking activities’), as provided in the source content*

### conclusion of the audit organization is submitted for consideration by the Senate of the

### 1uzbea2025004-source-pdf - conclusion of the audit organization is submitted for consideration by the Senate of the

### Governance
- The supreme body of the CBU is the Executive Board (CBU Law, Article 18).
- The CBU Executive Board is vested with multiple prerogatives in banking regulation and supervision, including:
  - determines the calculation procedure and permissible values of prudential standards for banks, including domestic systemically important banks (D-SIBs) and banking groups;
  - approves the rules for financial transactions and accounting for banks;
  - makes decisions on the issuance, renewal and revocation of banking licenses;
  - approves the regulations and composition of the Banking Supervision Committee (see EC4) and hears its reports;
  - makes decisions on the banking system in accordance with the requirements of the legislation;
  - approves the minimum requirements for the activities of banks in the implementation of relationships with their customers (CBU Law, Article 20).

### Internal and External Audit
- The Internal Audit Service carries out internal audit of the CBU activity and reports to the Audit Committee (CBU Law, Article 16).
- The Audit Committee consists of three members, one of which is independent; members are appointed by the CBU Board of Directors to whom the Audit Committee is accountable for its activities.
- The CBU is subject to external audit, carried out annually by audit organizations in accordance with International Standards on Auditing.
- Information obtained by the external auditors is confidential and not subject to disclosure without his consent (CBU Law, Article 17).
- The CBU publishes an annual report on its official website annually. The assessors reviewed the last two CBU annual reports and found them a useful source of information in the field of financial stability of the banking system.

### EC2 — Appointment and Removal Process (Description and findings)
- The CBU Board of Directors consists of nine members:
  - the Chairman, who is Chairman of the CBU, is appointed for five years (CBU Law Article 23) and released from the position by the Senate of the Oliy Majlis of the Republic of Uzbekistan on the proposal of the President of the Republic of Uzbekistan (CBU Law Article 19);
  - the first Deputy Chairman and five deputies are appointed and dismissed by the President of the Republic of Uzbekistan on the proposal of the Chairman (CBU Law, Article 24). There is no term for these positions;
  - two independent members, approved by the Committee of the Senate of the Oliy Majlis of the Republic of Uzbekistan on the proposal of the Chairman of the Central Bank. CBU Law does not specify the term limit of the two independent members of the CBU Board of Directors.
- The law does not clarify eligibility criteria for Board members (for example, sound reputation, honesty/integrity, and minimum years of professional experience), nor incompatibility criteria (e.g. between CBU Board members and members of the Parliament/Government).
- The CBU noted that Article 25 of the CBU Law applies also to Board members (except independent members) as they are staff of the CBU; this Article, among other prescriptions, prevents them from engaging in any other types of paid activities, except for scientific and teaching activities. Such a ban should adequately cover incompatibility criteria.
- Independent members are not staff of the CBU; therefore, there are neither eligibility criteria nor incompatibility criteria for them.
- It would be opportune to also spell out eligibility criteria for Board members.

### Grounds for dismissal of senior officials
- Pursuant to Article 23 of the CBU Law, the CBU Chairman may be dismissed from his post on the following reasons:
  - expiration of the term of office
  - self-application for dismissal from the post, indicating the reasons
  - entry into legal force of the court's conviction against him
  - the impossibility of fulfilling the official duties for health reasons, based on the conclusion of the state medical commission
  - death or declaring as deceased by a court decision
  - committing actions incompatible with being in office, including gross violation of this Law and causing significant damage to the interests of the Central Bank.
- Under the Chairman’s proposal, the President of the Republic can dismiss the First Deputy and Deputy Chairmen from their positions on the following reasons:
  - application for dismissal from the post, indicating the reasons
  - entry into legal force of the court's conviction against them
  - impossibility to fulfill their official duties for health reasons, based on the

*https://www.imf.org/-/media/files/publications/cr/2025/english/1uzbea2025004-source-pdf.pdf*

### conclusion of the state medical commission

### conclusion of the state medical commission

### Transparency of dismissal and governance of the CBU Board
- Reasons for dismissal of the CBU Chairman are not required by law to be publicly disclosed.
- Recent case: termination of the mandate of the CBU Chairman occurred before the natural end of his term; CBU stated termination followed Council of the Senate of the Oliy Majlis Decision No. KQ-15-V, dated 11 December 2024, and was based on the Chairman’s formal application for dismissal which detailed reasons.  
- Assessors view: Article 23 of the CBU Law (‘self-application for dismissal from the post, indicating the reasons’) should be amended because it leaves the reason for termination obscure.
- The law is silent on the process for removal of the two independent members of the Board.
- Finding: The law does not clarify eligibility criteria for CBU Board members (e.g., sound reputation, honesty/integrity, minimum years of professional experience) nor specify incompatibility criteria for the two independent members (e.g., holding Parliament or Government positions).

### EC3 — Publication of supervisory objectives and Strategy for Reforming the Banking System (2020-2025)
- The CBU has not formally published supervisory objectives. In the last 4 years these objectives were tied to the Strategy for Reforming the Banking System of the Republic of Uzbekistan for 2020-2025 (Decree of the President dated May 12, 2020, No UP-5992).
- Strategy purpose: define goals, objectives and priorities for banking system transformation in 2020-2025 and identify solutions based on foreign experience and global trends.
- Strategy identifies four priority reform areas:
  - Increasing the efficiency of the banking system (corporate governance standards, abandoning subsidized lending, liberalize banking activities, attract strategic foreign investors, modernize services and infrastructure).
  - Ensuring financial stability (improve loan portfolio quality and risk management; moderate lending growth; corporate governance; introduce technological solutions; increase minimum capital; develop deposit insurance; conduct independent AQR of banks with state share; integrate credit bureaus; improve legislation on out-of-court settlement, bankruptcy, enforcement).
  - Reduce the state share in the banking sector (privatization proceeding in two phases; first institutional transformation 2020-2021; second sale of state stakes on competitive basis; retain state participation in three banks).
  - Increase availability and quality of financial services (target underserved segments; network of low-cost service points; develop non-bank credit institutions; National Strategy for Increasing Financial Inclusion; digital banking; measures to develop mortgage lending).
- CBU responsibilities under strategy (selected):
  - revision of the regulatory and supervisory framework, in accordance with the BL and the CBU Law;
  - revision of licensing regulations;
  - development and approval of regulatory legal acts considering BCBS recommendations;
  - curbing excessive growth of the loan portfolio by introducing capital buffers for systemically important banks;
  - developing transparency requirements and published information for banks;
  - enhancing staff capacity for oversight;
  - developing prompt corrective actions mechanism;
  - enhancing IT role in oversight, data exchange and reporting;
  - gradual reduction of non-core functions of banks;
  - development of consolidated supervision framework;
  - ensuring compliance with capital adequacy and liquidity requirements;
  - revision of corporate governance, internal control and risk management provisions;
  - requirements for reliable stress testing;
  - improving reporting system and automating reporting;
  - transition to risk-based supervision;
  - adopting a system of resolution and deposit insurance;
  - guidelines for management of concentration, liquidity, credit, operational, currency risks.
- Roadmap: Appendix II assigned deliverables to the CBU within specific timelines.
- Achievements in last four years (examples):
  - on-going transition to risk-based supervision;
  - revisiting the RCG;
  - revision of licensing regulations;
  - developing regulation for risk management;
  - increasing the minimum capital;
  - developing draft Law "On Bank Resolution and Liquidation";
  - issuing a regulation of the debt burden on individual borrowers.
- Areas where deadlines expired or objectives not yet met:
  - consolidated supervision (deadline for regulation expired in 2022);
  - amending regulation on asset quality and provisioning to align with Basel Framework and IFRS 9 (deadline 2022);
  - introducing a capital buffer for D-SIBs.

### EC4 — Internal governance, Banking Supervisory Committee and reasoned judgment
- CBU Board determines main activities (CBU Law, Article 18) and delegates regulatory and supervisory functions to the Banking Supervision Committee (CBU Law Article 64).
- Banking Supervisory Committee composition and meetings:
  - Composition approved by CBU Board (Regulation No3/3 January 2024; RBSC).
  - Number of members should be odd; currently 11 members:
    - (i) the Chairman is the First Deputy Chairman of the CBU Board (who does not have responsibility on monetary policy);
    - (ii) the Deputy Chairman of the CBU Board is also Deputy Chairman of the Committee;
    - (iii) 9 heads of key Departments (Currency Regulation and Balance of Payments, Inspection, Prudential Supervision of Banks, Financial Monitoring, Consumer Protection, Licensing, Methodology, Payment Systems, and Legal).
  - Meetings held as necessary, but at least twice a month.
- Committee tasks include approving annual program of prudential supervision; composition of banks’ supervisory board, management board and key personnel; issuing/refusing qualification certificates for external auditors; proposing licensing/registration decisions to CBU Board; restriction of profit distributions; authorization for early repayment of subordinated loans; establishment of additional liquidity and capital buffers including D-SIB buffer.
- Checks and balances: RBSC includes conflict of interest rules (Article 10) and agenda/decision procedures (Chapter 5).
- Reasoned Judgment:
  - Committee makes decisions based on ‘reasoned judgment’ for licensing, ‘persons acting in concert’, related party transactions, risk management and internal control, assets and liabilities.
  - Reasoned judgment = supervisory judgment; supervisory discretion should be anchored to facts.
  - Process respects defense rights: right to comments and right to be heard.
  - Gap identified: CBU cannot adopt a ‘provisional motivated judgment’ allowing the concerned party to be heard after a decision in urgent cases (e.g., resolution decisions, urgent actions to prevent significant damage). Assessors recommend ability to exert ‘provisional motivated judgment’ to enable urgent action with post-decision hearing.

### EC4 — Communication, transparency and conflict of interest rules
- CBU Law requires a communication policy to increase effectiveness of monetary policy and banking stability measures; communication includes analytical materials, reviews, statistics, interviews, speeches, press briefings.
- In line with Law No ZRU-369 and Presidential Decree dated 14.06.2022, CBU uses social networks (Telegram, Facebook, Twitter, Instagram, LinkedIn, Youtube) to enhance communication.
- CBU is required to publish and update on its official website: laws and normative acts in supervision/regulation of banks; recommendations for application; general criteria and methodologies used in testing systems and assessing risks; list of bank managers; bank statements data (except bank secrets); measures and sanctions taken (CBU Law, Article 69; CP 11). CBU publishes reasoned decisions related to preliminary permission to acquire bank shares (BL Art, 28).
- Conflict of interest rules in CBU Law:
  - Article 7: develop and implement policy to prevent, identify and manage conflicts of interest and corruption prevention measures mandatory for all employees.
  - Article 20: CBU Board to approve the policy.
  - Article 24: Chairman must ensure separation of mandates among deputies and heads of independent divisions to prevent conflicts.
  - RBSC paragraph 10: members of the Banking Supervisory Committee must notify conflicts, reflect this in decisions, and abstain from discussion where applicable.

### EC5 — Professionalism, integrity and anti-corruption measures
- Article 25 of the CBU Law: CBU determines procedures for assessing qualifications and professional level of employees.
- Recruiting: open competition; foreign language testing; interview process by expert group; monitored by Compliance-control and Internal Audit.
- Gender imbalance noted: limited number of females in managerial positions.
- Conflict of interest case: Compliance Unit found 21 employees had invested in shares of banks (staff from private sector who had not sold shares timely). Board requested sale; at assessment time all shares had been sold.
- Article 27 of CBU Law prohibits employees from:
  - engaging in other paid activities except scientific and teaching;
  - being members of supervisory boards of banks, economic management bodies and business entities;
  - disclosing or using bank secrets or other restricted information;
  - being involved in auditing financial/economic activities of business entities including banks and outsourced entities.
- Law "On Combating Corruption" (N ZRU-419) Articles 19 and 21: obligations of officials to act impartially and avoid personal interest leading to conflict; liabilities for violations.
- CBU documents to combat corruption (selected):
  - Anti-Corruption Policy No 21/8 dated 24.09.2022;
  - Regulation "On the Identification and Management of Conflicts of Interest" (No21/8 dated 24.09.2022);
  - Instruction on the study of candidates hired for work in the system of the Central Bank (No21/8 dated 09/24/2022);
  - Instruction on organization of training for employees in ethics and anti-corruption (No21/8 of 24.09.2022);
  - Regulations for receiving and considering reports of corrupt behavior and conflict of interest (No21/8 dated 24.09.2022);
  - Methodology for Assessing Corruption Risks (No21/8 dated 24.09.2022);
  - Procedure for Incentives for Employees Who Report Corruption Offenses (No8/13 dated March 25, 2023).
- CBU maintains a Register of conflicts of interest (Compliance Unit); employees fill ‘Declarations of Conflicts of Interest’ annually and at hiring/rotation; Register posted on "E-Anti-Corruption" (https://e-anticor.uz/oz).
- Rotation rule to mitigate regulatory capture: a supervisor may not oversee the same bank for more than three consecutive years.

### EC6 — Resources, staffing, training, technology and budgets
- Funding: CBU does not levy fees on banks; funds supervisory function through income from Central Banking activities.
- Staff numbers (as of September 2024):
  - 168 employees out of a total of 750 CBU staff work in the Banking Supervisory and Regulatory units.
  - Financial Stability Department analyzes factors affecting financial system stability and is in charge of macroprudential policy.
- Supervisory and regulatory unit (banks) staffing breakdown:
  - Directors and Deputy Directors 12
  - Inspection Department 65
  - Prudential Supervision Department of Banks 42
  - Department of Methodology for Regulating the Activities of Credit Institutions 22
  - Financial Monitoring Department 20
  - Department of Licensing and Permitting Procedures 19
  - In general, employees 168
- Prudential Supervision Department of Banks:
  - off-site supervision; 6 divisions:
    - Four divisions analyze banks (curators) — curators are CBU representatives in banks, appointed based on risk profile and systemic importance.
    - One division deals with supervisory reporting.
    - One division analyzes risks in the banking system.
  - Curators: 23 curators total; 7 oversee the 7 D-SIBs; remaining 16 are responsible for the other 29 banks.
- Inspection Department: on-site supervision; 9 divisions (4 inspect banks, 1 compliance risk inspection, 1 currency operations inspections, 1 at request of law enforcement, 1 coordination; other 3 inspect microfinance, pawnshops, payment institutions).
- Salary scale:
  - CBU staff not under civil servant remuneration discipline; terms determined by the Central Bank (Article 25 of CBL Law; Article 43 "On the State Civil Service" No ZRU-788 not applicable).
  - Salary = base salary + allowance (% of salary) calibrated to qualifications, skills, experience; additional allowance increases with length of service.
  - Remuneration package claimed sufficient to attract and retain qualified staff; low turnover noted.
- Ability to commission external experts:
  - Article 45 of the BL empowers CBU to hire external experts for supervisory functions; CBU has never done it.
- Budget for training:
  - 2023: 185 CBU employees (100 managers and 85 specialists) took part in 116 foreign training events (Austria, USA, China, Switzerland, Germany and the Russian Federation). Departments of Banking Regulation and Supervision: 29 courses with 53 employees.
  - First three quarters of 2024: 179 employees (43 from supervisory units) took part in 97 foreign training and seminars.
  - Training covered banking regulation and supervision, supervisory activities, monetary and macroprudential policy, currency regulation, IT, cybersecurity, fintech, audit, accounting, climate-related financial risks, green finance, supervision of cyber risks, operational resilience, managerial skills.
- Technology budget and SupTech:
  - CBU Board approved roadmap for SupTech implementation developed with World Bank.
  - Automation of supervisory reporting: first stage with KPMG completed; unified data model developed; data quality control mechanism developed; selecting vendor for second stage (see CP10, EC9).
  - Planned projects: electronic licensing system (e-Licensing) and Anti-Money Laundering Solution.
- Travel budget: costs for on-site work, cross-border cooperation and participation in international meetings covered by CBU’s own funds.

### EC7 — Resource planning and skills
- CBU training program for 2024-2026 classifies employees by target groups and applies targeted training approach; aims to develop hard, soft and digital competencies and mandatory training for existing and new employees.
- Assessors note: EC requires an annual resource planning exercise to assess short- and medium-term needs; CBU’s program addresses skillset needs but annual resource planning exercise was not demonstrated.
- Cybersecurity measure: Cyber Security Center (CERT) composed of 29 staff; 8 fully dedicated to banking supervision.

### EC8 — Risk-based allocation of supervisory resources
- BL requires CBU to consider risk profile and systemic importance when determining supervisory program and allocating resources (Article 47 of BL).
- Prudential supervision program includes:
  - banks identified by stress tests as showing significant financial stability risks or possible non-compliance;
  - systemically important banks;
  - banks requiring additional supervision per CBU judgment.
- Program contains procedures for supervisory functions, resource allocation, identifying banks for additional supervision, and bank inspection plan.
- CBU may take measures based on bank risk assessment: increase inspection frequency; additional reporting; thematic examinations.
- Strategy Chapter 6 requires transition to risk-based supervision and allocation of resources to large systemic banks and banks with high or deteriorating risk profiles.
- GRBS (No42/29 of December 23, 2023) pursues allocation proportional to level of risks.

### EC9 — Legal protection for supervisors and staff
- CBU Law Article 70: Legal protection of employees — CBU, its employees, external experts and interim managers, and others performing supervision duties shall be liable only for actions (inaction) committed in bad faith. CBU shall pay costs of representation in judicial and administrative proceedings connected to duties performed, including after termination of powers or completion of work.
- Civil Code Article 15: losses caused by adoption of unlawful acts by state bodies or unlawful actions/omissions of officials are subject to compensation by the State or citizens’ self-government body; compensation may be imposed on officials by court decision.
- Over past five years, three court proceedings on supervisory function; courts ruled in favor of the CBU (two revocation of bank licenses; one revocation of payment organization license). No pending cases or legal cases finding illegal actions by employees in performance of duties.

### Overall assessment of Principle 2 (Independence, governance, resources)
- Assessment: Materially Non-Compliant
- Key findings:
  - Material gap between de jure and de facto independence: CBU independence enshrined in Constitution and CBU Law but limited in substance.
  - Responsibility to implement development programs introduces a financial inclusion/development mandate beyond the three objectives in CBU Law (price and financial stability, functioning of payment system), negatively affecting operational independence.
  - CBU lacks full discretion to set prudential policies: draft normative legal acts affecting business must be agreed with Chamber of Commerce and Industry and are subject to MoJ registration; MoJ can refuse registration on technical and non-technical grounds. Need for agreement with Chamber of Commerce and Industry goes beyond normal consultation process.
  - CBU cannot adopt a ‘provisional motivated judgment’ for urgent actions.
  - CBU has not formally published supervisory objectives; strategy ending in 2025 requires stocktaking and redetermined priorities (e.g., complete transition to risk-based supervision; introduce consolidated supervision; introduce capital buffers for D-SIBs; align asset quality regulation and supervisory reporting to IFRS 9).
  - Staffing and resources: 168 employees oversee 36 banks (7 D-SIBs). No budget constraint was disclosed; training expanded to new risks including climate; cybersecurity hiring addressed gaps. CBU has power to hire external experts but has never done so.
- Findings summary (selected bullets):
  - material gap between de jure and de facto independence;
  - law does not clarify eligibility/incompatibility criteria for Board members;
  - Article 23 does not require public disclosure of reasons for dismissal of the Chairman;
  - CBU has not published supervisory objectives;
  - CBU cannot adopt provisional motivated judgment in urgencies.

### Recommendations (selected and verbatim where provided)
- Take action to ensure that the CBU’s independence is not only enshrined in the Constitution and in the CBU Law, but also protected in substance, including by avoiding that the responsibility for the implementation of development programs might compromise its operational independence.
- Amend Article 102 of the LNLA to streamline the process for the adoption of regulations setting prudential standards by the CBU, e.g. no need for agreement with the Chamber of Commerce and Industry.
- Amend Article 110 of the LNLA to narrow the Ministry of Justice’s power to refuse the registration of the CBU Regulations.
- Enhance the transparency of the appointment and removal process of CBU Board members by:
  - introducing in the CBU Law (Article 19 and 24) eligibility criteria (for example, sound reputation, honesty/integrity, and minimum years of professional experience) and, for the two independent members, also incompatibility criteria (for example, they should not be the Parliament or the Government), and
  - Amending Article 23 of the CBU Law and requiring that reasons for dismissal are publicly disclosed.
- As the 2020-2025 banking sector strategy is coming to its expiration, take stock of what has been achieved, and redetermine and regularly communicate supervisory priorities publicly.
- In case urgent action is needed (for example, classifying a borrower as a related party and preventing the bank from further lending), enable the CBU to adopt a “provisional motivated judgment,” giving the persons concerned the opportunity to be heard as soon as possible after taking its decision.

*Source: conclusion of the state medical commission — 1uzbea2025004-source-pdf*

### 2023.  It has been tested with 14 banks in 2024.  In 2025, the plan is to conduct risk-

### 1uzbea2025004-source-pdf - 2023.  It has been tested with 14 banks in 2024.  In 2025, the plan is to conduct risk-

### Legal and supervisory mandates
- Article 45 of the BL requires the CBU to oversee:
  - the systems, strategies, procedures and mechanisms used by banks to comply with prudential requirements
  - risks to which banks are or may be exposed, ensuring that risks are prudently managed and covered by regulatory compliance mechanisms, as well as capital and liquidity
  - compliance of banks with risk management and corporate governance requirements
- Article 46 of the BL tasks the CBU with review of banks’ systems, strategies, procedures and mechanisms to comply with banking legislation, and to assess existing and potential risks, including risks posed by individual banks to the financial system.

### Guidelines for Risk-Based Supervision (GRBS)
- Origin and scope:
  - The Strategy for Reforming the Banking System of the Republic of Uzbekistan for 2020-2025 instructed the CBU to adopt risk-based supervision.
  - The CBU prepared GRBS which constitute its Supervisory Manual covering on-site and off-site supervision of banks operating in Uzbekistan and their subsidiaries and branches abroad.
- Characteristics and approach:
  - Mirrors the European Central Bank methodology but is conducted on an individual bank basis (no consolidated supervision) and currently does not incorporate climate-related financial risk.
  - Emphasizes a forward-looking view, changes in supervision intensity, and different use of resources to enable early identification of issues.
- Testing and rollout:
  - Tested with 14 banks in 2024.
  - In 2025, the plan is to conduct risk-based supervision for the rest of the banks.

### Risk assessment methodology
- Main components (each evaluated on a four-point scale):
  - (i) business model (see CP9, EC4)
  - (ii) credit, market, operational risk, and interest rate risk in banking book (IRRBB)
  - (iii) capital adequacy and liquidity
  - (iv) Governance and Risk Management
- Elements evaluated:
  - inherent risk (‘gross risk’) — impact and probability based on multiple quantitative indicators
  - quality of risk management — policies, process, staff, internal control system
  - net risk — remaining risk after internal controls
  - net risk direction — forward-looking estimate of movement (improvement, stable, deterioration) over the next 12 months (time interval)
- Component-specific evaluation:
  - Business model: only inherent risk, net risk, and direction are evaluated
  - Capital and governance/risk management: only the quality of risk management, net risk, and net risk direction are evaluated
- Three assessment phases per component:
  - stage 1: gathering information from multiple sources
  - stage 2: automatic assessment based on pre-defined indicators and thresholds
  - stage 3: complements phase 2 to provide a more accurate picture of inherent risk and quality of risk management
- Final scoring and constrained judgment:
  - Final score determined by moving from the simple average for the four components; supervisor may adjust summary assessment using judgment.
  - Supervisors are allowed to move only by 1 step up and two steps down (‘constrained judgment’). In exceptional circumstances, this rule can be disregarded with documented justification.
- Uses of risk profile:
  - (i) bank’s supervision plan
  - (ii) supervisory measures
  - (iii) frequency and depth of information required from banks
- Pillar 2 and ICAAP:
  - Establishment of higher prudential requirements depending on the score is contemplated but not done by the CBU due to lack of Pillar 2 methodology.
  - Following pilot exercises, the CBU started requesting examined banks to prepare the ICAAP and some qualitative measures (e.g., internal limits to portfolio concentration).

### Peer comparisons and grouping
- Banks divided into peer groups: “large state-owned banks”, “state-owned banks”, “medium-sized banks”, “small banks”, “retail banks”.
- Supervisors should include peer comparisons in business model analysis; may use indicative classification by size and business model or create specialized peer groups based on criteria:
  - systemic/non-systemic nature (size, complexity, market share)
  - ownership (state/private)
  - business model (universal, retail, commercial)
- Peer group creation criteria include flexibility to allow dynamic analysis.

### Assessors’ findings and examples (2023–2024)
- Methodology gaps identified:
  - banks group structure: guidance does not address procedures for consolidated supervision nor methodologies to connect risks in the wider group (weighted under CP12)
  - climate related financial risk: guidelines silent on assessing physical and transition risk channels (see EC4)
  - resolvability: CBU has not conducted resolvability assessments, particularly needed for D-SIBs (including SOBs)
- Review of risk assessments:
  - The assessors examined 3 risk assessments conducted in 2023 (two private banks and a SOB) and 1 draft risk assessment conducted in 2024 (see CP12).
  - Key supervisory challenges raised by CBU in examples:
    - sustainability of business model due to aggressive growth in retail lending impacting asset quality, provisioning and profitability (private bank)
    - low margins of an SOB lending portfolio to state-owned enterprises; lack of analysis on efficiency of business lines; inadequate control on implementation of bank strategy
    - contested issuance of new loans to cover previous day-past due (evergreening) for SOB; questioned adequacy of reserves despite external consultant asset quality review
    - concentration risk: business line concentration (car loans) and top 20 borrowers
  - Recommendations made included preparation of ICAAP and governance/risk appetite improvements; some recommendations were ‘soft’ and did not fully address provisioning shortages.
  - A point of improvement: assessment of corporate governance—two letters did not mention deficiencies in supervisory or management boards (weighted under CP14).

### Reasoned judgment (Regulation and use)
- Legal framework:
  - Regulation “On the Procedure for the Formation and Use of a Reasoned Judgment by the Central Bank”, approved by Resolution of the CBU Board No 34/3 (September 2023), developed in accordance with Article 63 of the CBL.
- Sources of information for reasoned judgment include:
  - information from individuals and legal entities, international organizations, state authorities, foreign supervisory authorities, other open sources; documents collected by supervisory unit; photo, audio, video materials; transaction and related-party analyses; market value analyses; opinions and explanations from bank employees or related persons.
- Process and rights:
  - CBU can request information/explanations from banks or their founders/shareholders with deadlines; failure to provide is considered as information not available.
  - Draft conclusion sent to bank and beneficial owners; they have ten business days to submit a motivated response; absence of response is considered agreement.
  - Conclusion and response submitted to Banking Supervision Committee; a bank representative may be invited.
  - The Banking Supervision Committee decides whether to apply the reasoned judgment; banks/beneficial owners can appeal to the CBU’s Appeal Board or to court within ten days.
  - The CBU’s Appeal Board reviews appeals within fifteen days. Filing an appeal does not suspend execution of the Banking Supervision Committee’s decision.
  - Based on Committee’s decision, CBU may establish supervisory measures and apply measures and sanctions in accordance with law.
- Usage and expansion:
  - In 2023 the CBU exerted its reasoned judgment 6 times; in 2024 3 times.
  - The assessors examined 4 cases: in 2 cases CBU challenged economic interdependency and re-determined group of connected clients and sanctioned banks for breach of large exposure limits (see CP19); in 1 case deficiencies in reporting of large exposure were used to challenge risk management and internal control; in another case CBU challenged RWA calculation for certain corporate exposures.
  - Reasoned judgment has been used beyond Article 63 contexts (e.g., qualifying a bank as a D-SIB). Going forward, reasoned judgment should be expanded to determining capital and liquidity banks should hold in excess of minimums (Pillar 2 functions).

### Systemic importance assessment (EC2)
- Regulatory basis:
  - CBU Regulation No 4/13 “On the Procedure for Determining the Systemic Importance of Banks”, approved by the CBU Board the 18th of February 2023, defines systemically important bank and establishes criteria for identifying D-SIBs.
- Disclosure and frequency:
  - CBU publicly disclosed list of banks classified as D-SIBs and an outline of the process. Assessment is conducted quarterly.
- Criteria considered to identify D-SIBs include:
  - size (thresholds on assets, loan and leasing commitments, and trade finances)
  - interconnectedness with other banks — share of bank’s assets in/liabilities towards other banks in Uzbekistan to total assets in/liabilities towards other banks in Uzbekistan
  - substitutability/financial institution infrastructure:
    - share of volume and number of payments and transfers executed by a bank through RTGS and FPS over last 12 months relative to all banks
    - share of loans allocated by a bank across certain economic sectors relative to all banks across same sectors
    - share of individual deposits in the bank relative to total individual deposits in all banks
    - share of legal entities’ deposits in the bank relative to total legal entities’ deposits in all banks
    - indicator representing volume of bank’s financial services (loans and deposits) and number of service points (branches, mini-banks, bank service offices, ATMs, off-bank retail cash desks)
  - complexity — share of bank’s cross-border obligations in total cross-border obligations of all banks in Uzbekistan
- Method and decision:
  - Indicators standardized (value from 0 to 1), compared across banks and weighted.
  - Financial Stability Department provides data quarterly; submits calculation results for following year to Banking Supervision Committee by November 1 based on last four consecutive quarters.
  - A bank designated as systemically important if D-SIBs for three out of last four quarters and/or for last two quarters; Banking Supervision Committee may use reasoned judgment.
  - Starting from the end of 2024, Financial Stability Department will conduct the assessment; decision remains with Banking Supervision Committee.
- Outcomes:
  - CBU identified 7 D-SIBs under this assessment, 6 based on standard indicators and 1 based on motivated judgment.
  - For each D-SIB, 1 supervisor (curator) appointed from heads/deputy heads of Department of Prudential Supervision and 1 assistant assigned.
  - There are plans to implement capital buffer for D-SIBs.

### Compliance assessment process (EC3)
- Methods:
  - CBU assesses compliance with prudential standards and legal requirements by analyzing supervisory reporting, interacting with banks, and conducting on-site inspections.
  - A ‘Summary Report’ aggregates supervisory information from data submitted by banks in *.xlsx format and automatically calculates prudential standards identifying violations.
  - Interaction frequency varies: daily (foreign exchange position), monthly/quarterly (capital adequacy, liquidity ratios, large exposure limits).
  - Information on violations submitted to Banking Supervision Committee for decision.
- Legal support:
  - Banks obliged to comply with prudential standards (Article 38 BL), internal control and risk management requirements (Article 42 BL), and provide information necessary to assess compliance (Article 45 BL).
  - CBU has rights to receive/check reports, demand clarification, check activities of banks and outsourced parties, and use information systems and bank databases (Article 50 BL).

### Macroprudential stress testing and climate-related financial risks (EC4)
- Macroprudential stress testing:
  - Financial Stability Department conducts macroprudential stress testing twice a year, in conjunction with the Financial Stability Report.
  - Baseline scenario: continuation of current economic trends.
  - Adverse scenario: time horizon 3 years; models internal and external shocks (geopolitical tensions, heightened global recession risks, diminished domestic and external demand, increased volatility in international financial system).
  - Outcomes noted:
    - In 2023 adverse scenario, banks CAR remains above minimum (13.6 percent)
    - In 2024 adverse scenario, banks CAR would drop below the minimum (10.4 percent)
- Climate-related financial risks:
  - Not yet integrated in supervisory assessment.
  - CBU shared a draft strategy on management and supervision of climate-related financial risks in banking sector for 2025-2027:
    - Foresees regulatory actions including setting standards banks will be required or recommended to follow when managing climate-related risks, and supervisory actions to ensure compliance.
    - Financial Stability Department to assess how climate risks may impact financial system, including preparation of green dashboards and methodologies for climate stress testing.
    - Following issuance of supervisory guidelines (or regulation), banks will be required to submit self-assessments on climate risks and action plans; Department of Prudential Supervision will prepare methodological approach to review self-assessments (2025).
    - In 2026 the CBU will define reporting templates for periodic data submission on exposure to climate-related risks (e.g., sectoral breakdown of the loan portfolio; geographical location of clients; etc.).
    - CBU will conduct horizontal review of banks’ self-assessment and action plans and communicate feedback; Department of Prudential Supervision will integrate horizontal review results into banks’ business models, internal governance frameworks, or credit and operational risk profiles.
- Non-bank financial institutions:
  - Non-bank financial institutions are not material in Uzbekistan.

### Key statistics and timelines (preserved verbatim)
- Tested with 14 banks in 2024.
- Plan to conduct risk-based supervision for the rest of the banks in 2025.
- Net risk direction time horizon: the next 12 months (time interval).
- Constrained judgment movement: 1 step up and two steps down.
- In 2023 the CBU exerted reasoned judgment 6 times; in 2024 3 times.
- Macroprudential stress testing: conducted twice a year.
- Adverse scenario time horizon: 3 years.
- Banks CAR under adverse scenario: 2023 -> 13.6 percent; 2024 -> 10.4 percent.
- Financial Stability Department submits D-SIB calculations by November 1 of the reporting year, based on last four consecutive quarters.
- A bank designated D-SIB if systemically important for three out of the last four quarters and/or for the last two quarters.
- CBU identified 7 D-SIBs (6 based on standard indicators and 1 based on motivated judgment).

### Principal areas for methodological improvement (assessors’ view)
- Introduce procedures and methodologies for consolidated supervision and mapping risks across banking groups (banks group structure).
- Integrate climate-related financial risks into supervisory assessment and guidance (physical and transition risk channels).
- Conduct resolvability assessments for banks, particularly D-SIBs (including SOBs).
- Strengthen assessment of corporate governance in supervisory findings and communications.
- Develop Pillar 2 methodology to enable prudential requirements tied to risk-based scores and expand use of reasoned judgment to determine additional capital and liquidity requirements.

*Source: https://www.imf.org/-/media/files/publications/cr/2025/english/1uzbea2025004-source-pdf.pdf*

### conclusions will be reflected in the annual supervisory assessment process of banks. The

### 1uzbea2025004-source-pdf - conclusions will be reflected in the annual supervisory assessment process of banks. The

### Climate-related risks, monitoring and supervisory integration
- Full integration of Climate risks into supervisory activity is envisaged in 2027, including potential on-site inspection (i.e., by reviewing credit files and verifying whether banks are gathering relevant sustainability data from their clients, etc.).
- With the support of technical assistance, the Financial Stability Department aims also to conduct climate risk stress testing on both physical and transition risk.
- The CBU has already created a dashboard to monitor climate change and assess its impact on financial stability. This panel consists of data on:
  - results of economic activities that affect climate change;
  - financial indicators of greening processes; and
  - information on the scale of risks associated with climate change.
- According to the CBU self-assessment, 8 banks have developed ESG Guidelines.
- Finding: The Guideline for risk-based supervision does not incorporate climate related financial risk yet, although banks in Uzbekistan are vulnerable to physical and transition risk.
- Recommendation: Integrate climate-related financial risks in the risk-based supervisory approach by:
  - issuing guidelines for effective management of climate related financial risk by banks (BCBS, 2022);
  - conducting, or requiring banks to conduct, a climate risk sensitivity analysis; and
  - identifying outlier banks and adopting targeted measures (for example, more frequent reporting, periodic disclosure, transition plans) for those outliers.

### Physical and transition vulnerabilities
- Uzbekistan faces hydrometeorological hazards and natural disasters affecting the agricultural sector via seasonal flooding and droughts. Main physical risk drivers include: droughts, high temperatures, heat waves, heavy precipitation, mudflows, floods, and avalanches.
- Uzbekistan is described as one of the most energy-and resource-intensive countries in the world, implying transition risk given expected rapid population and economic growth will drive significant growth in emissions.
- Policy commitments and emissions context:
  - 2018: ratified the Paris Agreement and submitted an NDC to reduce GHGs per unit of GDP by 10 percent by 2030 from the 2010 baseline.
  - At COP26 in 2021, Uzbekistan increased its commitment to 35 percent.
  - In 2019, the power sector accounted for 74 percent of GHG emissions in Uzbekistan.
- Finding: These physical and transition risks make banks vulnerable to both risk types; the current supervisory guideline lacks climate risk incorporation.

### Non-Bank Financial Institutions (NBFI)
- The CBU views NBFIs as having limited impact on overall financial system stability.
- As of July 1, 2024, the ratio of NBFI assets (including Mortgage Refinancing Company of Uzbekistan, microfinance organizations, pawnshops and insurance companies) to the total financial system was 2.86%.

### EC5 — Build-up, transmission and system-wide risk (description and findings)
- Supervisor’s remit under EC5 includes identification, monitoring and assessment of:
  - (a) build-up and transmission of risks, trends and concentrations within and across the banking system;
  - (b) any emerging or system-wide risks which could impact banks and the banking system as a whole; and
  - (c) common behaviors by banks (e.g. procyclical actions), interlinkages and interconnections that may adversely affect stability.
- CBU noted specific risk build-ups:
  - increasing debt burden among the population;
  - accumulation of risk in mortgage lending;
  - concentration risk in the car loans segment.
- Foreign-currency loan exposure: 42.9 percent of total loans in Q2 2024 were foreign-currency denominated loans.
  - A recent Banking Supervisory Committee decision requires banks to only lend in FX to legal entities with income in the same currency as the loan; unhedged FX exposures may have built up prior to this decision.
- Population’s debt burden:
  - Loans to households account for around one third of total loans, of which mortgages account for 13 percent.
  - The population’s debt burden is significantly increasing; concerns appear in Financial Stability Reports (October 2023 and October 2024).
- Mortgage lending:
  - Financial Stability Report (October 2023) quantified the gap between market housing prices and fundamental values at 36 percent in the first half of 2023 and 28 percent in the first half of 2024.
  - Individuals lacking official income can qualify for mortgage loans based on unofficial income.
  - Stress tests conducted in 2023 and 2024 assumed house price declines of 20, 30, and 40 percent; in the most adverse scenarios a substantial portion of mortgage loans may lack adequate collateral.
  - The CBU tightened capital requirements to account for LTV and introduced other measures to mitigate credit risk.
- Car loans:
  - Car loan growth has outpaced other loan categories, driven by relaxed lending standards and speculative investment demand.
  - CBU measures: tightened capital requirements on car loans and introduced a concentration limit of 25 percent on car loans against the bank’s asset portfolio (2023).
  - These measures appear effective in reducing car loan growth (see FSR October 2024).
  - The concentration limit of 25 percent will force one bank to change its business model.
- Transmission, interlinkages and contagion (macro stress test approaches used in 2023):
  - First approach: losses from bank defaults linked to banks’ capital. Default of banks with CAR below 13 percent has minimal negative effect on overall system; defaults do not hinder other banks from meeting minimum capital requirements.
  - Second approach: assumes losses are not recoverable. Default of banks with CAR below 13 percent could lead to two additional banks failing to meet minimum capital requirements. However, those affected banks have negligible or no liabilities to other banks, and small share of interbank liabilities in total assets suggests low interconnectedness.

### EC6 — Resolvability assessment (description and findings)
- EC6 expects supervisor and resolution authority to assess bank resolvability considering risk profile and systemic importance and require remedial measures where necessary.
- Finding: The CBU has not assessed banks’ resolvability yet.
- Draft law “On Resolution and Liquidation of Banks”:
  - Identifies the CBU as Authority for resolution and liquidation of banks.
  - Requires the CBU to develop and annually review resolution plans for D-SIBs; may also develop plans for other banks performing critical functions.
  - Permits the CBU, upon identification of obstacles to resolution, to require the bank to develop an action plan within a deadline; if insufficient, the CBU may impose measures such as limiting risk, asset sales, simplifying ownership, amending the charter to remove obstacles to use of write-off and conversion tools.
  - The draft law envisages circumstances under which a bank is considered insolvent or with a high probability of insolvency (examples include inability to pay customer claims within two days; liabilities exceeding assets; capital adequacy ratios and capital reduced by fifty percent or more of the minimum amount established by the CBU; presence of any other circumstances that threaten the integrity of funds entrusted to the bank).
  - Envisages resolution tools: transfer of assets and liabilities; creation of a bridge bank; bail-in.
- Finding: The CBU has not started preparation of resolution plans for D-SIBs.

### EC7 — Framework for early intervention and resolution (description and findings)
- Framework elements exist in the Banking Law (BL) including recovery plan requirements (BL article 49) and provisions covering supervisory measures (Article 51), interim management (Article 52) and revocation of banking license (Article 77).
- Draft Law “On Resolution and Liquidation of Banks” will enable the CBU Board to decide to start resolution if all the following are present:
  - the bank is insolvent or there is a high probability of bank’s insolvency;
  - measures taken by the bank, banking group, shareholders, and CBU have not eliminated the high probability of insolvency and will not do so within six months; and
  - the bank is a D-SIB or one or more goals of reorganization cannot be achieved by compulsory liquidation.
- The draft law also envisages various resolution tools and defines insolvency indicators (see EC6).
- Finding: The framework for handling banks in build-up to and during stress is encapsulated in several BL provisions, but a Resolution Law was not approved by Parliament at time of assessment.

### EC8 — Regulatory perimeter and supervisory response (description and findings)
- Banks are not entitled to carry out financial transactions not specified in their license (BL Article 5); activities without a license are illegal and entail liability; income from such activities is withdrawn and appropriated by the State budget (BL Article 15).
- Article 33 of the RPAMS empowers the CBU to restrict and/or prohibit implementation of certain financial transactions or expansion of bank infrastructure for up to six months in cases of:
  - violation of legislation on financial transactions;
  - implementation of prohibited or restricted activities by banks;
  - violation of prudential standards by the bank.
- If the CBU becomes aware of activities outside the regulated area, it may transfer information to another competent state body.
- Assessment of Principle 8: Largely Compliant.
- Findings related to Principle 8:
  - The recent adoption of the GRBS (2023) is a milestone in transitioning to a risk-based approach.
  - The guideline does not incorporate climate-related financial risks.
  - Full implementation of risk-based supervision faces challenges: curators are asked to adjust automatic scores (moving one notch up or two down) to better reflect bank inherent risk; in 2024 there were 13 changes in the automatic rating during the assessment of risk profile (out of 14 banks examined).
  - The CBU claimed adjustments are subject to quality review by the Risk Analysis Division but did not provide robust evidence of such QA processes.
  - The CBU has identified 7 D-SIBs and publicly disclosed the assessment process for systemic importance.
  - The CBU has not conducted a resolvability assessment of D-SIBs and has not issued a Regulation on recovery plans; the law “On Resolution and Liquidation of Banks” will complete the framework.
- Recommendations related to Principle 8:
  - Integrate climate-related financial risks into the risk-based supervisory approach (see climate recommendations above).
  - Consider setting up a quality assurance unit to ensure adjustments to automatic ratings by curators are subject to systematic horizontal scrutiny.
  - Conduct a resolvability assessment for D-SIBs.

### Principle 9 — Supervisory techniques and tools (overview and EC1–EC4 findings)
- Principle 9: Supervisor uses appropriate range of techniques and tools, deploying resources proportionately to risk profile and systemic importance.
- EC1 — Mix of on-site and off-site supervision:
  - Department of Prudential Supervision of Banks (42 staff) handles off-site supervision, risk assessments and sanctions.
  - Supervisory functions frequency:
    - daily monitoring of compliance with prudential standards, balance sheet changes and loan portfolio quality;
    - weekly/monthly control of reserve creation, problem loans, large borrowers, early warning indicators;
    - quarterly study of internal audit/risk management reports and bank stress tests;
    - annual analysis of audited financial statements and annual risk assessment.
  - Institutional profile for each bank is updated every four months (consideration to update every 6 months). Profiles include ownership, governance, risk management resumes, business model, past inspections, significant changes.
  - Curator role: CBU representative in supervised entity who analyzes financial condition, monitors compliance, proposes inspections, may attend meetings as observer and access Board/Committee documents. Curator obligations include informing Banking Supervision Committee of non-compliance and observing professional secrecy.
  - Issues: Curator role is not formalized in Law or binding regulation and there is no cooling-off period before a curator can be hired by a bank that he/she supervises. Recommendation: formalize curator role and introduce a cooling-off period.
- EC1 — On-site inspections:
  - Inspection Department staff specialized by risk: corporate/retail, liquidity, operational risk, AML/CFT, and inspections at request of law enforcement.
  - Frequency and scope determined by CBU independently (CBU Law, Articles 46 and 66).
  - Transition from comprehensive to targeted inspections under the risk-based approach.
  - Regulation No 2217/2011 updated to envisage comprehensive, targeted and off-site control inspections.
  - August 2024: CBU Board approved Resolution No 28/2 ‘Minimum Requirements for Inspections in Banks, based on the Risk-Based Supervision Guidelines’ requiring assessment of business model, credit risk, operational risk, market risk, capital, and liquidity.
  - Article 15 of the inspection procedure: duration of each inspection should not exceed 30 calendar days; can be extended for up to 30 calendar days (an unlimited number of times) with Deputy Chairman permission. Assessors consider 30 days often insufficient and note draft revised regulation removes limitations on duration.
  - Assessors reviewed 5 onsite inspection reports; only one used new methodology. On-site inspections showed positive features (challenging off-site information quality, identifying understaffed risk management units and other shortcomings) but corporate governance assessment was absent in examined reports; Regulation is to be amended to include corporate governance assessment in first half of 2025.
  - Resource/time observation: with 9 inspection staff, number of loans examined (370 in one case and 270 in another) appears high given 30-day duration; CBU uses pre-visit portfolio sampling to improve efficiency.
  - On-site inspection under new methodology (targeted) appeared more effective (example: challenged excessive human intervention/overrides in credit scoring).
- EC2 — Planning and execution coherence:
  - Annual prudential supervision program (BL Article 47) includes banks identified by stress tests, D-SIBs, and banks requiring additional supervision.
  - Supervision program contains procedures for exercise of supervisory functions, allocation of resources, identification of banks requiring additional supervision, and inspection plan.
  - After risk profile assessment, curator develops individual supervisory plan; key points considered by Banking Supervisory Committee for inclusion into overall program.
  - Supervisory interaction matrix guides frequency of supervisory activities (every 3/2 years, annual, semiannual, quarterly, monthly) depending on bank category; factors include results of annual risk assessment and emerging topics.
  - 2024 supervisory plan focuses on credit risk, liquidity risk stress tests, financial stability indicators, risk-based supervision expansion, and daily monitoring of open currency position.
- EC2 — Coordination between on-site and off-site:
  - Internal procedure (Resolution No 17/10, May 2024) sets relations and document flow between Prudential Supervision and Inspection Departments.
  - Off-site assessment uses quantitative indicators; where insufficient qualitative information exists, qualitative ratings guide on-site inspections.
  - Ongoing interaction between off-site and inspection teams across supervisory cycle.
- EC3 — Range of information used and data reliability:
  - CBU uses: balance sheets, prudential reports, credit registry information, stress test results, banks’ reports, annual financial statements, internal audit reports, external auditor's reports, management letters, monthly statistical reports (deposits, loans, interest rates, currencies), and data from Department of Statistics and Research.
  - Curator plays a crucial role in forming a holistic view of bank risk profile.
  - Data reliability assessed via: (i) technical checks automated in supervisory reporting system; (ii) curator assessment of consistency between financial statements and regulatory reporting; (iii) data quality checks during on-site examinations.
- EC4 — Tools used to review safety and soundness:
  - (a) Analysis of financial statements and accounts: Prudential Supervision Department analyzes financial statements, balance sheet indicators and prudential reports for all banks; curators prepare analysis reports.
  - (b) Business model analysis: GRBS treats business model as separate component; forward-looking assessment focuses on viability (ability to generate acceptable returns over next 12 months) and sustainability (ability to bring acceptable profit over 1 to 3 years). Assessment stages include information collection and peer grouping by business model, size, complexity, risk profile, and ownership.
  - (c) Horizontal peer reviews: used as part of business model and comparative assessments.
  - (d) Corporate governance analysis: acknowledged as necessary though absent in some inspected reports; Regulation to be amended to include corporate governance assessment.
  - (e) Reviews of outcomes of bank stress tests: supervisory reviews include assessment of banks’ stress testing results.
  - (f) Supervisory stress tests: employed for assessments of capital and liquidity adequacy under adverse scenarios (macro and bank-specific stress testing referenced earlier).
- Findings related to supervisory techniques:
  - The institutional profile is a comprehensive off-site tool and was positively noted by assessors.
  - There is scope to improve formalization and safeguards around the curator role (legal/regulatory formalization and cooling-off period).
  - On-site inspection duration limits (30 calendar days) are often inadequate; draft revisions propose removing duration limits.
  - Quality assurance over curator adjustments to automatic ratings needs strengthening; consider setting up a QA unit.
  - The CBU has not yet completed resolvability assessments or recovery plan regulations; resolution law pending parliamentary approval.

*Source: 1uzbea2025004-source-pdf (Conclusions reflected in annual supervisory assessment process).*

### 3.  A  ‘DuPont’  analysis  is  conducted  to  decompose  the  profitability  drivers  and

### 3.  A  ‘DuPont’  analysis  is  conducted  to  decompose  the  profitability  drivers  and

### DuPont analysis process and supervisory rating stages
- DuPont analysis is used to decompose profitability drivers and understand the contribution of each element to the change to the return on equity (ROE).
- Automatic Rating:
  - Automatically assigns a rating to a bank based on a limited list of key indicators and related thresholds (ROE, net interest margins adjusted for loan losses provisioning, and cost to income ratio).
- Supervisor Assessment:
  - Supervisor completes the business model analysis using reasoned judgment and additional information to complement the standardized automated rating.
  - Qualitative inputs include swot analysis, external and internal dependencies, strength of franchising, trend of operational costs, changes in profitability, inefficient sale channels, business environment, projected financial performance execution capacity.
  - Supervisor forms a forward-looking opinion on viability and sustainability of a bank and adjusts the rating considering qualitative information (positioning compared with similar organizations, reputation with customers, track record in implementing strategic projects).
  - Assessors found that the CBU challenged the sustainability of the business model.

### Horizontal peer reviews
- CBU conducts horizontal reviews regularly, at least once a quarter.
- Topics are selected based on dynamics of main indicators and macroeconomic situation. Example: recent horizontal review of mortgage loans (see CP8, EC5).
- An anonymized peer review showed: as of January 2024, 43 percent of the mortgage credit portfolio was held by individuals without official wage and there were cases where microloans were used for mortgage payment (see CP 19).

### Analysis of corporate governance, risk management, and internal control systems
- The analysis of corporate governance was not clearly evident in on-site inspections examined or in the 2023 off-site risk assessment; improvements visible in the 2024 risk assessment.
- Analysis of risk management is more evident (see CP 15).
- Legal and regulatory basis:
  - Chapters 4 and 5 of the BL provide corporate governance and risk management requirements under CP14 and CP15.
  - Article 42 of the BL prescribes internal control requirements (see CP26).
  - The Guideline for risk-based supervision evaluates corporate governance and risk management as a separate component of a bank’s risk assessment.
- Questionnaire for governance assessment:
  - About 30 yes/no questions on Board, Senior Management, Risk Management, Internal audit, External audit, Disclosure.
  - The questionnaire produces an automatic score based on the number of ‘no’ answers.
  - Supervisor may adjust the score by increasing it by a maximum of 1 point or lowering it by a maximum of 2 points.
- Corporate governance assessment components listed in questionnaire:
  - Board: size, composition, qualification (including independent members), selection process, committees, functioning (approval of risk appetite, business plan, risk management strategy), corporate value and standards.
  - Senior Management: organization, duties and responsibilities, remuneration system, turnover.
  - Risk Management: independence, resources, access to the Board/Committees, reporting, compliance function.
  - Internal audit: audit plan, resources, report to board/audit committee.
  - External audit: selection process, implementation of recommendations.
  - Disclosure: timely, clear and accurate publication of information of corporate governance.

### Stress testing by banks and supervisory review
- Banks are required by CBU RRM to conduct stress tests at least once a quarter (see CP15, EC14); assessors considered this frequency too high to generate meaningful results.
- Banks send stress test results to the Prudential Supervision Department; curators use results when assessing risk profile.
- RRM indicates general conditions for designing scenarios on credit, market and liquidity stress tests (Article 16-19).
- Banks required to use stress test results in strategic and budget planning, capital and liquidity planning, and in developing policy and risk management processes.
- Guidelines on Risk Based Supervision (par. 54) allow banks to demonstrate to the CBU how they use stress test results for risk management and capital adequacy assessment purposes (see CP15, EC14).
- Prudential Supervision Department reviews bank stress tests and discusses deficiencies with banks.
- Historical supervisory actions:
  - 24.11.2018 CBU Board meeting (No37/9) studied state of stress tests by banks.
  - 26.11.2020 (No26/9): all banks required to develop stress testing scenarios based on their risk profile and approve reverse stress testing by January 15, 2021 on the impact of non-repayment of restructured loans due to the pandemic.
  - Evidence found that recommendations in 2020 led to changes of heads of risk management in two banks.

### Supervisory stress tests and scenario adequacy
- Department of Prudential Supervision conducts supervisory stress tests annually.
- 24.09.2022 CBU Board Resolution No21/1 considered results of credit risk stress testing and possible impact on capital adequacy; banks requested to analyze and elaborate measures taken.
- 2023 liquidity risk stress test was carried out due to observed deposit outflow; assessors found the scenario not adequately severe (weighted under CP 24).
- Supervisor communicates findings and requires banks to mitigate vulnerabilities that could affect safety, soundness, or stability of the banking system (including financial system stability interlinkages).

### Engagement, communication, and follow-up (EC5–EC10)
- Vulnerabilities discussion:
  - At least twice a year vulnerabilities are discussed at CBU Board meetings with bank participation.
  - In 2021 the CBU Board of Directors sent 71 letters to banks communicating findings on credit risk, liquidity risk, capital adequacy, prudential requirements, risk profile, restrictions to dividend distribution (see CP8).
- Internal audit evaluation (EC6):
  - CBU assessed internal audit functions; 2022 off-site supervision rated internal audit activities of a bank as unsatisfactory due to failure to complete tasks (monitoring reliability of financial statement).
  - Subsequent on-site inspection found further deficiencies; CBU applied sanctions and instructed disciplinary measures for certain employees.
  - Internal audit must be agreed with CBU at licensing stage (EC5). Regulation No 3302/2021 establishes internal audit requirements (see CP26).
  - Internal audit assessed during comprehensive inspection for independence, report quality, annual audit plan, structure and implementation.
- Engagement with boards and management (EC7):
  - Article 45 of the BL requires CBU to interact with banks to obtain information to assess adequacy of banks' capital to risk profiles.
  - Curators participate as observers in supervisory board meetings and meet with senior and middle management to assess business models.
  - Interaction with senior and middle management is frequent during on-site inspections; assessors did not find sufficient evidence of engagement with non-executive board members.
- Communication of findings (EC8):
  - In 2024 the Banking Supervision Committee sent 71 letters communicating off-site supervision findings; 33 were sent to SOBs and 40 to Chairmen of Management Boards.
  - The Banking Supervision Committee prevented 22 banks from distributing dividends; in 14 cases this was due to authorized capital being below the new minimum capital (UZS 500bn) required by January 2025 based on the BL (as of November 1, 2024).
  - CBU assessment: 9 of these 14 banks could reach the new minimum capital by retaining earnings; 5 would need a capital increase. If unsuccessful, CBU is considering forced transformation into microfinance banks (new category in a draft law under Parliament’s discussion) even though 4 of these banks’ business models are not focused on microfinance activities.
  - Microfinance banks’ minimum capital requirement is UZS 50bn, with maximum deposits they can collect UZS 200bn (in line with maximum guarantees amount by the Deposit Insurance Fund). These 4 banks would need to reduce current deposits if unable to raise capital.
  - Inspection reports: drawn up in three copies, signed by inspection team, managers and chief accountant; submitted to banks for an action plan.
  - Risk assessment results communicated to chairmen of Supervisory Boards and Management Boards via letter including main conclusions, requirements, and recommendations. Assessors examined 3 letters from 2023.
  - Assessors did not find sufficient evidence of separate meetings with independent directors.
  - CBU regularly holds meetings with audit companies to discuss common issues (see CP27, EC8).
- Follow-up activities (EC9):
  - CBU follows up on findings. Example: 2024 action plan for breaching large exposure limit followed by a fine due to non-fulfillment of action plan tasks.
  - Dividend restrictions were prolonged for several banks due to inability to meet new minimum authorized capital (see CP11, EC4).
  - Follow-up on action plans is generally appropriate and timely, with CBU tracking open findings. However, a system to systematically track open findings with banks (beyond action plans) is lacking. Institutional profile contains sanctions applied but not open findings.
- Notification requirements (EC10):
  - Several BL provisions require bank notifications to CBU, but assessors recommend a comprehensive mandatory notification requirement for all substantive changes in a bank’s activities, structure, and overall condition or as soon as they become aware of material adverse developments.
  - Specific notification obligations and timeframes:
    - Insolvency: BL Article 77 requires the bank's Board to immediately notify the CBU in cases of insolvency or risk of inability to meet customers’ claims.
    - Change in composition of shareholders: Article 26 obliges direct or indirect owners of substantial ownership to notify CBU within ten days in writing (including electronic form) for specified cases (1–4), and the bank must notify the CBU within one day from receipt of such notification.
    - Shareholders’ agreements: Article 27 requires notification to the CBU of agreements related to coordinated exercise of voting rights, coordinated activities of management, or rights to nominate a majority of board members.
    - Change affecting suitability of substantial shareholder: direct and indirect owners must notify CBU within five working days of circumstances affecting compliance with BL requirements.
    - Representative office or closure/divestment abroad: banks must notify the CBU within thirty days from the decision and provide information on impact on financial stability (BL Article 31).
    - Related party limits: Regulation No 3283/2020 allows a 10-day notification to avoid being considered a breach when a borrower subsequently becomes a related party, provided actions to comply are taken.
    - Breach of capital requirements: Regulation No. 2693/2015 requires banks that do not meet capital requirements to develop an action plan and submit it to the CBU within 30 days from the breach.
    - Banks must notify the CBU if a director no longer meets suitability requirements (See CP14, EC8).
    - Regulation No. 3224/2020 requires notification to CBU about incidents breaching confidentiality, integrity, access rights, technological process violations (par. 32), and virus origin/type (par. 82).

### Use of external experts, information systems, and independent reviews (EC11–AC1)
- Use of third parties (EC11):
  - BL Article 45 enables CBU to use external experts, but CBU has never used this provision.
- Information systems (EC12):
  - CBU uses supervisory reporting, State Register of Credit Information, and the Information Repository of the Banking System (ICBS) to process, monitor and analyze prudential information.
  - Data from information systems help identify areas for follow-up.
  - CBU Board approved a roadmap for implementation of SupTech to reach automation of supervisory reporting (see CP10).
- Periodic independent reviews (AC1):
  - CBU Internal Audit function conducts periodic independent verification and Article 16 of the CBU Law envisages internal audit of CBU activities carried out by the Internal Audit Service, accountable to the Audit Committee.
  - Audit Committee consists of three members, including one independent member.
  - Internal Audit has never assessed the adequacy and effectiveness of the range of supervisory tools and their use; this AC was not considered in the score.

### Assessment and key findings
- Assessment of Principle 9: Materially Non-Compliant.
- Key findings:
  - CBU deploys a combination of off-site supervision and on-site inspections to evaluate banks’ risk profile and internal control environment.
  - Institutional profile and the curator are valuable for off-site supervision; curator’s multiple interactions with banks (including board meetings) should be formalized to mitigate reputational risk for CBU.
  - Room to improve on-site inspections efficacy: most inspections (80 percent) are conducted within the 30-day internal regulation limit, which stretches resources and might affect robustness of credit file review (sampling occurs before visits).
  - Perimeter of on-site visits does not extend to corporate governance.
  - Off-site engagement with non-executive board members and separate meetings with independent directors should be expanded.

*Canonical source: https://www.imf.org/-/media/files/publications/cr/2025/english/1uzbea2025004-source-pdf.pdf*

### 1. The  role  of  the  curator  is  neither  formalized  in  the  Law  nor  in  a  binding  public

### 1. The role of the curator is neither formalized in the Law nor in a binding public

### Main findings
- The role of the curator is neither formalized in the Law nor in a binding public regulation.
- There is no cooling-off period before the curator could be hired by the bank that he/she supervises.
- The assessors did not find sufficient evidence of separate meetings held by the CBU with independent directors.
- A system enabling the CBU to systematically track open findings (beyond the case in which an action plan has been requested) is lacking.
- There is no general duty by banks to notify it in advance of any substantive changes in their activities, structure and overall condition, or as soon as they become aware of any material adverse developments.
- There is room for improving the on-site inspections effectiveness: most inspections (80 percent) are conducted within the 30-day limit set by the internal regulation and this strict timeline may constrict the ability to conduct a thorough credit file review considering the large number of corporate exposures examined.

*Source: IMF staff summary of chapter content.*

### 6. The on-site and off-site assessment of corporate governance is not systematically

### 6. The on-site and off-site assessment of corporate governance is not systematically included in the reports shared (one out four cases) and such a risk profile is even not mentioned by the new Resolution ‘Minimum Requirements for Inspections in Banks, based on the Risk-Based Supervision Guidelines’ (August 2024).

### Corporate governance — findings
- On-site and off-site assessment of corporate governance is included in reports in "one out four cases".
- The risk profile of corporate governance is not mentioned by the Resolution ‘Minimum Requirements for Inspections in Banks, based on the Risk-Based Supervision Guidelines’ (August 2024).
- Ad-hoc requests for additional information are:
  - burdensome for banks,
  - often provided in an unstructured form, via emails or other less secure channels.
- Supervisory reporting and tracking:
  - Open findings are not systematically tracked in the bank’s institutional profile.
  - There is not a mandatory notification requirement for substantive changes in an institution’s activities, structure, or material adverse developments.
- Inspection timing:
  - The current inspection period (per Article 15 of the Regulation ‘On the procedure for inspections of banks and their branch’) is considered too short; assessors recommend extension to a timeline of "60-90 days".

### Corporate governance — recommendations
- Formalize the role of the curator (do’s and don’t) in a binding regulation and introduce a cooling off period before the curator could be hired by the banks that he/she supervises.
- Enhance the off-site engagement with non-executive and independent board members.
- Systematically track open findings in the bank’s institutional profile.
- Seek a mandatory notification requirement for all substantive changes in an institution’s activities, structure, and overall condition, or as soon as they become aware of any material adverse developments.
- Amend Article 15 of the Regulation ‘On the procedure for inspections of banks and their branch’ and extend the inspection period to a more reasonable timeline (60-90 days).
- Enhance the off-site supervision of corporate governance and amend the Resolution ‘Minimum Requirements for Inspections in Banks, based on the Risk-Based Supervision Guidelines’ (August 2024) to expand the scope of on-site supervision to banks’ corporate governance.

*Italic: Source — IMF PDF chapter/section content supplied.*

### Principle 10 — Supervisory reporting (Assessment: Materially Non-Compliant)

#### Key elements of Principle 10
- The supervisor collects, reviews and analyses prudential reports and statistical returns from banks on both a solo and a consolidated basis, and independently verifies these reports through either on-site examinations or use of external experts.

#### Findings (EC1–EC9) — selected highlights
- EC1:
  - Article 50 of the BL establishes CBU’s right to receive and verify reports and other documents.
  - Banks submit financial and supervisory reports to the CBU; banks prepare and submit reports in the forms, manner and terms established by the CBU (BL Article 71).
  - Banks provide data on a daily, monthly, and quarterly basis.
  - Resolution of the Board of the Central Bank No 31/5 dated December 25, 2021 adopted Recommendations on banking reporting that establish reporting forms:
    - "Financial Reports of Commercial Banks on Banking Supervision", consisting of 24 tables, divided into 3 blocks (block 1 - Liquidity Analysis, Block 2 - Calculation of the Bank's Regulatory Capital, Block 3 - Other Reports);
    - "Breakdowns of Balance Sheet Accounts to Financial Statements of Commercial Banks on Banking Supervision", consisting of 10 tables.
  - Supervisory reporting includes on- and off-balance sheet assets and liabilities, profit and loss, capital adequacy, liquidity, significant positions, risk concentrations (including by economic sector, geography and currency), asset quality, loan loss reserves, related-party transactions, interest rate risk, market risk and other information.
  - For supervision purposes the information is collected only on a solo basis; consolidated reporting is provided "at the request of the CBU" but is not part of the basic supervisory reporting package.
  - The CBU has developed a draft “Strategy for the management and supervision of financial risks associated with climate change in the banking sector for 2024-2027” but supervisory reporting currently does not cover climate-related financial risks.
  - Ad-hoc information requests are made in unspecified forms and terms; information is often unstructured and sent via less secure channels.
- EC2:
  - Reporting instructions are based on domestic regulatory acts:
    - Regulation "On Requirements for the Accounting Policy and Financial Statements of Commercial Banks" (RAFS);
    - “Chart of Accounts for Accounting in Commercial Banks” (Reg. No. 3336 dated November 26, 2021).
  - Banks can apply IFRS; CBU has not clarified main differences between IFRS and RAFS.
- EC3:
  - Supervisor requires sound governance and control processes for valuations; banks responsible for integrity and reliability of reports (BL Article 71).
  - In prudential reporting:
    - government securities valued at nominal value due to absence of a yield curve;
    - investments recorded at nominal value, net of provisions;
    - loans and leases reported at remaining principal amount, net of provisions (i.e., not at amortized cost); accrued interest on loans recorded separately.
  - Supervisory reporting of OTC derivatives (as at 1.1.24 and 7.1.24) includes only notional value; fair value is missing.
- EC4:
  - No differentiation of reporting frequency or content by bank complexity, size, or risk profile; all banks are subject to the same standardized prudential reporting.
  - Prudential Supervision Department activities and frequencies:
    - daily: monitor compliance with prudential requirements, balance sheet positions, loan portfolio quality;
    - weekly/monthly: completeness of reserves, forborne positions, NPL changes, large borrowers and depositors, banks’ investments and shareholder changes;
    - quarterly: investigate internal audit reports, assess risk management information, analyze stress test results.
- EC5:
  - Periodic reporting is daily, monthly, or quarterly with deadlines; all banks provide reports with same frequency enabling comparisons.
  - Consolidated supervision is not in place (see CP12); no obligation for banks to provide consolidated supervisory reporting; consolidated prudential requirements have not been set.
- EC6:
  - BL Article 50 and Article 51 give CBU powers to receive information and require actions, including from related parties and persons subject to consolidated supervision, but do not explicitly cover the wider group irrespective of activities.
  - CBU Law (Article 55) enables exchange of statistical information with Government bodies, State Tax Committee, Bureau of Compulsory Enforcement, Agency of Statistics, but not automatic powers to request information from entities in the wider group irrespective of their activities.
- EC7:
  - Article 51 authorizes measures for failure to submit reports or submission of unreliable reports, including early termination of Supervisory Board members, replacement of board members, suspension of key employees for up to six months.
  - Banking Supervision Committee has applied penalties for incorrect and inaccurate regulatory reporting.
- EC8:
  - Division of Financial Reporting checks reports for correctness and applies technical checks comparing monthly/quarterly packages with daily ISBS system reports; reporting forms include checking formulas.
  - The number of "technical" errors has decreased significantly; curators apply in-depth analysis.
  - CBU approved a roadmap for SupTech with 5 projects, including automation of supervisory reporting; vendor selection for the second stage (Implementation of an automated reporting system in the CBU) is underway.
- EC9:
  - A unified data model was developed with KPMG's international consultants; supervisory reports split into granular data with verification rules.
  - A data quality control solution will be implemented in second phase.
  - Supervisory reports are improved annually; all changes reviewed by experts and approved by the Board of the CBU.

#### Assessment of Principle 10 — Materially Non-Compliant (summary of key findings)
- The CBU collects prudential reports and statistical returns on a solo basis, but not on a consolidated basis.
- The CBU requests ad hoc information in an unstructured form, via emails or other less secure channels.
- Supervisory reporting relies on CBU Recommendations which are based on internal accounting policy, instead of accounting principles and rules that are widely accepted internationally.
- The CBU does not collect information that allows for the assessment of the materiality of climate-related financial risks.
- All banks, despite size and business model, are obliged to provide the same data; the CBU has not properly shifted reporting to risk-based supervision and proportionality.
- Supervisory reporting on OTC derivatives is limited to notional amount and does not incorporate fair value.
- The CBU does not seem to have the power to request relevant information from any entities in the wider group, irrespective of their activities.

#### Recommendations for Principle 10
- The CBU should:
  - collect prudential reports and statistical returns also on a consolidated basis;
  - improve the data quality, validity checks and data safety for the ad-hoc data transfers and structure ad-hoc data transfers with a secure channel;
  - reformulate its recommendation on supervisory reporting to base accounting principles and rules on those that are widely accepted internationally, instead of internal accounting policy;
  - collect information on banks’ exposure to climate-related financial risk;
  - embed the proportionality principle in the supervisory reporting (e.g., the implementation of the SupTech Project could help address the above finding);
  - collect reporting on the fair value of OTC derivatives.
- The CBU should be enabled to request relevant information to any entities in the wider group, irrespective of their activities, when this information is material to the condition of the bank or to the assessment of the risks of the bank; or needed to support resolution planning.

*Italic: Source — IMF PDF chapter/section content supplied.*

### Principle 11 — Corrective and sanctioning powers of supervisors (Assessment: Largely Compliant)

#### Key elements of Principle 11
- The supervisor acts at an early stage to address unsafe and unsound practices and has an adequate range of supervisory tools, including license revocation.

#### Findings (EC1–EC9) — selected highlights
- Legal and regulatory framework:
  - CBU powers enshrined in the CBU Law, BL, and CBU Regulation on the Procedure for Applying Measure and Sanctions Against Banks and Non-Bank Credit Organization No. 3492/24 (RPAMS).
  - The CBU can raise concerns up to "twelve months before a possible violation takes place", in written form, at an appropriate level, and require follow-up via supervisory tools.
  - Relevant provisions include:
    - Article 61 of the CBU Law: binding orders to eliminate violations;
    - Article 63 of the CBU Law: apply measures and sanctions to banks, shareholders, BO, supervisory and management boards, key personnel;
    - Article 51 of the BL: supervisory measures including immediate actions for inconsistency, possible violations within twelve months, risks affecting activities or information security/cyber security;
    - Article 53 of the BL: apply measures and sanctions to bank and personnel, introduce risk-based approach for applying measures;
    - Articles 54-59 classify violations as gross, serious, and minor and identify measures and sanctions.
- Range of supervisory tools (examples):
  - ensuring and maintaining prudential capital above CBU requirements;
  - improving corporate governance, risk management, internal controls or a recovery plan;
  - submitting an action plan, implementing financial recovery measures, individual provisioning requirements;
  - restricting/prohibiting certain financial transactions, expansion of infrastructure;
  - directing net profit to increase authorized capital; restricting dividends; restricting remuneration; limiting deposit interest rates; additional reporting; instruction letters for cybersecurity; maintaining minimum liquid assets; convening extraordinary shareholders meetings; removal power (early termination/suspension of board/management/key personnel); interim management; revocation of license.
- Examples of measures applied:
  - dividend restrictions adopted vis a vis 22 banks; for 14 banks a ban adopted by Banking Supervisory Committee Resolution in May 2024 justified by probability of not meeting new minimum capital (BN 500 UZS) in force by January 2025;
  - restriction of credit operations (August 2021) preventing 4 state owned banks from issuing new loans beyond repaid loans until NPL share reached 5 percent;
  - statistical sanctions for incorrect reporting applied to state owned banks, foreign banks and other domestic banks;
  - prohibition to attract deposits exceeding 5 percent of liabilities; removal powers; revocation of 2 banking licenses (2020-2022).
- Procedural measures:
  - Instruction letters: deadlines not exceeding one year; bank must respond with deadlines; failure to eliminate violations triggers further measures.
  - Action plans required for certain violations; timelines include submitting plan within 10 days for CAR violations; CBU may send objections within 15 working days; bank must resubmit within 10 working days.
  - Specific thresholds: e.g., if share of problem assets in total assets amounts to ten percent or more, RPAMS empowers CBU to limit/prohibit certain operations.
- Sanctions regime:
  - Classification of violations and sanctions:
    - Gross violations: fines up to two times the income from violations or 5 percent of net profit or 1 percent of total capital; fines on individuals up to 100 percent of annual remuneration; revocation of license; publication of violations.
    - Serious violations: fines up to 1.5 times income or 2 percent of net profit or 0.5 percent of total capital; fines on individuals up to 75 percent of annual remuneration; publication possible.
    - Minor violations: fines up to income received or 1 percent of net profit or 0.1 percent of total capital; fines on individuals up to 50 percent of annual remuneration; written warnings.
  - Article 67 of the CBU Law allows the CBU "to apply several measures and (or) sanctions for the same violation simultaneously or sequentially" — assessors expressed concern this may violate the ne bis in idem principle (no double punishment).
- Ring-fencing:
  - No specific legal provisions for ring-fencing, but CBU may ban dividend distributions to foreign parent companies, challenge shared services pricing and reverse payments, and prohibit remittances if necessary.
  - Recommendation to incorporate specific legal provision for ring-fencing given presence of 7 foreign banks.
- Publication and appeals:
  - CBU required by CBL Article 69 to publish on its website information on measures and sanctions.
  - RPAMS requires publishing monthly statistics by the 10th of each month for prior month.
  - For gross or serious violations the CBU may publish names/details in mass media.
  - Decisions sent to bank/owner/manager within three working days; appeals to CBU Appeal Board or court within thirty days; Appeal Board considers within fifteen days.

#### Assessment of Principle 11 — Largely Compliant (summary)
- The regulatory framework enables early-stage interventions and a broad arsenal of corrective measures and sanctions.
- CBU applies measures to state-owned banks and private banks; measures are applied proportionately to gravity of situation.
- Concerns:
  - Cooperation and collaboration with relevant authorities (Deposit Guarantee Agency, the Ministry of Economy and Finance, the Financial Stability Board, the Central Securities Depository) for orderly resolution of a problem bank is not in place until the draft law "On Resolution and Liquidation of Banks" is approved and implemented.
  - CBL Article 67 could lead to violation of the ne bis in idem principle (International Covenant on Civil and Political Rights; Article 14.7).

#### Findings (explicit)
- Cooperation and collaboration with relevant authorities (Deposit Guarantee Agency, the Ministry of Economy and Finance, the Financial Stability Board, the Central Securities Depository) in deciding when and how to effect the orderly resolution of a problem bank is not in place until draft law "On Resolution and Liquidation of Banks" is approved and implemented.
- CBL Article 67 could lead to violation of the ne bis in idem principle.

#### Recommendations for Principle 11
- Once the draft law "On Resolution and Liquidation of Banks" is approved by the Parliament, put in place robust cooperation and collaboration with relevant authorities (Deposit Guarantee Agency, the Ministry of Economy and Finance, the Financial Stability Board, the Central Securities Depository) in deciding when and how to effect the orderly resolution of a problem bank.
- Reconsider the application of CBL Article 67 to avoid violation of the ne bis in idem principle.

*Italic: Source — IMF PDF chapter/section content supplied.*

### Principle 12 — Consolidated supervision

#### Key elements of Principle 12
- The supervisor supervises the banking group on a consolidated basis, adequately monitoring and applying prudential standards to all aspects of the group's business.

#### Findings (EC1–EC6) — selected highlights
- EC1:
  - BL Article 3 defines "banking group" as an association of financial institutions not a legal entity where parent bank controls other financial institutions.
  - BL Article 48 empowers the CBU to exercise consolidated supervision in cases of creation of a banking group or determination of parent bank/member by reasoned judgment.
  - Article 61 delegates to CBU the establishment of procedure for determining boundaries (perimeter) and methods of consolidation.
  - The CBU has not issued the regulation on consolidated supervision (deliverable in Strategy for Reforming the Banking System 2020-2025 due by end 2022).
  - CBU has mapped 19 banking groups (ownership structures and relationships) including corporates within the wider group, but there is neither assessment of how group-wide risks are managed nor actions taken when wider-group risks may jeopardize safety and soundness.
  - Technical assistance requested from World Bank and SECO to advance consolidated supervision.
- EC2:
  - BL Article 38 requires banking group compliance with prudential standards established by CBU.
  - CBU has not developed capital adequacy standards for banking groups aligned with international standards, nor applies liquidity standards to the whole group.
  - Large exposure and other prudential standards are applied on solo level; supervisory reporting on minimum prudential standards is also on solo level.
  - Reporting on related parties exists (see CP20) but is insufficient for consolidated analysis.
- EC3:
  - Only one domestic bank, a D-SIB, has a subsidiary abroad.
  - An intergovernmental agreement between CBU and the host supervisor regulates cooperation (see CP13).
  - Head office receives regular reports on prudential standards of subsidiary and may request other information if necessary.
- EC4:
  - CBU Article 61 confers right to inspect persons subject to consolidated supervision.
  - Field inspections of subsidiaries were organized until 2016; not since 2017 because subsidiary asset ratio about 3 percent and limited operations.
  - In 2022, CBU Prudential Supervision Department employees met the subsidiary and host supervisors.
  - Parent conducts annual audit of subsidiary and sends it to the CBU bank.
- EC5:
  - Assessors examined a draft risk assessment of the parent company: CBU challenged business model, high concentration risk, credit risk from state program loans, market risk (lack of risk appetite limits), operational risk (lack of business continuity plan), liquidity risk (deposit concentration, lack of contingency funding plan).
  - No evidence of supervisory review of companies affiliated with parent companies that have material impact on bank safety and soundness.
- EC6:
  - CBU instructed banks to limit foreign transactions with Russian banks and to improve counterparty screening and cross-border transactions.

*Italic: Source — IMF PDF chapter/section content supplied.*

### introduction of the right to unilaterally cancel agreements in case of undesirable

### introduction of the right to unilaterally cancel agreements in case of undesirable activities of the client in order not to fall under violations of international sanctions requirements

### Consolidated supervision (Principle 12)
- Assessment: Materially Non-Compliant
- Description and key findings:
  - CBU conducts supervision on an individual (solo) level.  
  - Prudential requirements apply only on an individual bank level.
  - The CBU has not issued a Regulation to establish the specifics of consolidated supervision (Article 48 BL) and perimeter and methods of consolidation (Article 61).
  - The CBU has recently mapped 19 banking groups.
  - Supervisory reporting does not allow the CBU to receive information on a consolidated basis for the banking group.
  - The CBU does not assess how group-wide risks are managed and if entities in the wider group may jeopardize the safety and soundness of the bank and the banking system.
  - The CBU highlighted that it focused on transition to risk-based supervision on a solo level.
  - The CBU has requested technical assistance on consolidated supervision.
- Findings (explicit bullets from source):
  - Prudential requirements apply only on an individual bank level.
  - The Strategy for Reforming the Banking system (2020-2025) identifies consolidated supervision as a priority area for regulatory and supervisory enhancement, but the CBU has not issued a regulation on consolidated supervision so far.
  - The CBU does not assess how group-wide risks are managed and if entities in the wider group may jeopardize the safety and soundness of the bank and the banking system.
  - The CBU is working on completing the mapping of the banking groups. The CBU has requested technical assistance on consolidated supervision.
- Recommendations:
  - Accelerate implementation of consolidated supervision, with focus on:
    - Definition and identification of banking groups (mapping, describing the perimeter of consolidation);
    - Development of consolidated reporting;
    - Prudential requirements should be set at the consolidated level;
    - Enhancing the internal supervisory manual and procedures (i.e. GRBS);
    - Enhancing coordination and information sharing.
  - Assess how group-wide risks are managed and if entities in the wider group may jeopardize the safety and soundness of the bank and the banking system.
  - A clear deadline to implement the framework should be established.

### Home-host relationships (Principle 13)
- Assessment: Compliant
- Context and overview:
  - Uzbekistan’s banks mainly operate in the local market. There is only one bank with a subsidiary abroad; the assets of that bank are not significant to the parent bank’s size nor to the market of the host country. The CBU is mostly operating as a host authority rather than a home authority.
  - Assets of subsidiaries established by foreign banks and operating in the local market account for about 10% of the total assets of the entire banking system.
  - There are subsidiaries which are significant in size and recognized as D-SIBs.
- Agreements and cooperation:
  - There is an Agreement signed with the host authority enabling exchange of information on all supervisory matters, including confidential information; parties are obliged to exchange and keep updated contact lists.
  - MoUs and Agreements are mostly used in cases of banks’ licensing and acquisition (CP5, CP6).
  - Cooperation with the NAPP (insurance and capital markets supervisor) is not formalized in an MOU; meetings and information sharing are irregular.
- Findings by essential criterion:
  - EC1: No supervisory college established for the one bank with a subsidiary abroad; CBU mainly acts as host authority.
  - EC2: Agreements and MoUs foresee appropriate and timely exchange of information; cooperation has not been tested in crisis situations.
  - EC3: Home and host authorities may initiate meetings; in 2022 staff of the Department of Prudential Supervision organized a meeting at the subsidiary premises.
  - EC4: Agreement signed on May 20, 2022; communication strategy not practiced as a college is not established; home supervisor typically informs host at least 25 working days before planned on-site inspection.
  - EC5: Resolution Authority has not been established; draft Law "On Resolution and Liquidation of Banks" is under consideration by the Legislative Chamber of the Oliy Majlis; MoU signed on September 10, 2021 includes a clause on crisis management.
  - EC6: Draft law on resolution envisages CBU cooperation and exchange of information with foreign regulatory bodies; CBU notifies relevant foreign supervisory authority of decisions related to resolution or liquidation of a foreign bank operating in Uzbekistan.
  - EC7: Prudential, inspection and regulatory reporting requirements imposed on local banks are similarly applied to foreign banks; CBU has the right to conclude written agreements for consolidated supervision (Article 48 BL).
  - EC8: 2022 Agreement states home supervisor has right to inspect cross-border institutions in host country if not contradicting host legislation; home supervisor shall notify host at least 25 business days before planned inspection.
  - EC9: Foreign subsidiaries in Uzbekistan are not shell banks; prudential requirements applied similarly to foreign subsidiaries.
  - EC10: Article 68 CBL provides for cooperation and information exchange with foreign supervisory authorities; CBU may conclude cooperation agreements including exchange of confidential information.
- Key finding:
  - While establishment of colleges is the responsibility of the home authority, the CBU, as host supervisor with shared interest in effective oversight, has not adequately engaged with the home supervisor to obtain comprehensive information on wider group risks or parent company risks.
- Recommendation:
  - Consider formalizing a request to the home supervisor of biggest subsidiaries operating in Uzbekistan to be invited to the existing supervisory college.

### Corporate governance (Principle 14 — EC1)
- Legal and regulatory framework:
  - The legal framework for banks’ corporate governance is spread across several laws and regulations; basic provisions are defined by the JSC.
  - Article 33 of the BL stipulates management bodies: general meeting of shareholders, the supervisory board and the management board.
  - Banks are obliged to develop and approve a corporate governance policy and an organizational structure that defines:
    - areas of responsibility;
    - procedures for identifying, managing, monitoring and informing about risks (including crisis simulation scenarios);
    - procedures for assessing liquidity and capital adequacy;
    - appropriate internal controls, including accounting procedures;
    - remuneration policies and practices that promote prudent and effective risk management.
  - Organizational structure, procedures and mechanisms must be comprehensive and consistent with the nature, scale and complexity of the risks inherent in the business model and activities.
- Supervisory board (Article 34 and related):
  - Competencies include: approval and control over strategic goals, corporate governance policy, risk identification/management/monitoring/reporting, maintaining capital adequacy, control over creation of reserves, approval of conflict of interest procedures, approval of plans to restore financial position, control over management board, quarterly hearings of management board reports, organizing internal audit and assessing management compliance, monitoring and evaluating effectiveness of business management system, submitting at least once a year to general meeting a report on supervisory and control activities, approving annual financial statements, ensuring integrity of accounting and financial reporting, ensuring compliance with CBU prudential requirements.
  - The number of supervisory board members must be an odd number, but not less than five people.
  - Decree of the President No. PD-300, September 11, 2023: independent members in supervisory boards should comprise at least 50 percent of members by the end of 2025.
  - Article 76.1 of the JST lists restrictions on who may be an independent member (examples include: not an employee of a government body or state enterprise; not worked in the company for the last three years; not a shareholder owning 5 or more percent; not an audit organization employee who provided auditing services during last three years; not been a supervisory board member for six consecutive years).
  - Chairman of the Supervisory Board is responsible for managing and ensuring effectiveness of the board’s activities and fostering trustful relationships; must ensure decisions are made based on independent exchange of opinions and thorough analysis.
  - The CBU RCG provides more granular requirements regarding functions and responsibilities of supervisory and management boards.
- Management board (Article 35 and Article 47 of the RCG):
  - Obligations include: implement strategic goals, corporate governance policy, internal policies for risk identification/management/monitoring/reporting, maintain capital adequacy, ensure appropriate and transparent organizational structure, exercise control over employees, implement annual business plan and report periodically to shareholders and supervisory board, perform other duties per charter and legislation.
  - Article 47 RCG: management board is executive body responsible for operational management in accordance with strategy and management system approved by supervisory board; assumes full responsibility for bank activities.
  - Management board required actions include establishing monitoring systems, reliable information systems, timely submission of reports to board, promptly informing supervisory board about deterioration in financial condition or breaches, developing procedures for hiring/dismissing/rotating/promoting employees and retaining qualified staff.
- EC2 contextual note:
  - The RCG defines requirements for effective corporate governance in banks.

*Source: 1uzbea2025004-source-pdf - introduction of the right to unilaterally cancel agreements in case of undesirable activities of the client in order not to fall under violations of international sanctions requirements*

### 1. clear distribution of powers and responsibilities stated in the internal

### 1. clear distribution of powers and responsibilities stated in the internal

### Overview: corporate governance as a separate risk assessment component
- Since 2023 the GRBS introduced the evaluation of corporate governance and risk management as a separate component of the bank’s risk assessment.
- The methodology is based on a questionnaire (about 30 yes/no questions) related to the board, senior management, risk management function, internal and external audit, and disclosure.
- The questionnaire produces an automatic score based on the number of ‘no’ questions. At the end of the assessment, the supervisor (‘curator’) may adjust the score by increasing it by 1 notch or lowering it by 2 notches.
- The Guideline foresees that the assessment should be proportionate to the size, complexity, structure, risk profile and business model of the bank.
- The assessment consists of three stages:
  - 1. Information/data collection (described in the Guidelines Chapter 12.2)
  - 2. Automatic score (performed by assessment of questionnaires)
  - 3. Supervisory assessment (supervisory judgement)

### Scope of the corporate governance evaluation (focus areas)
- The evaluation provides a comprehensive overview with a focus on risk control and is carried out in relation to three main aspects:
  - (i) the bank's internal governance structure (including key control functions such as risk management, internal audit, compliance);
  - (ii) the bank's overall risk management framework and risk culture;
  - (iii) the bank's risk infrastructure, internal data and reporting.

### Deployment and supervisory practices — findings and gaps
- Although introduced earlier by GRBS, the assessment of corporate governance has not been properly deployed yet.
- Example supervisory challenges identified in one of four risk assessments:
  - the number of independent members within the supervisory board;
  - the lack of a Risk Committee;
  - the Risk Management Unit was under the responsibility of the management board, but not the supervisory board;
  - the Chief Risk Officer has no veto power.
- During on-site inspections, inspectors review minutes of supervisory board meetings, minutes of audit and other committees, internal audit reports, and investigate information obtained after off-site evaluation.
- It is necessary to develop a more holistic view of banks’ corporate governance and conduct more comprehensive assessments of the implementation of banks’ corporate governance policies, processes, and practices, especially during on-site inspections, with particular focus on the effectiveness of the supervisory board (and its committees).

### EC3 — Board membership, qualifications, independence (description and findings)
- EC3 principle: The supervisor determines that board membership comprises individuals with a balance of skills, diversity and expertise, who collectively possess necessary qualifications commensurate with the size, complexity and risk profile of the bank. Board membership includes a sufficient number of experienced independent directors.36 Board members are qualified (individually and collectively), effective and exercise their “duty of care” and “duty of loyalty”.37
- Legal and regulatory provisions and practices:
  - Members of the supervisory board must comply with independence of judgments; a person may not be elected or shall be deprived of the right to be a member if:
    - 1. a person is or intends to become a member of the supervisory board of two or more banks, except when these banks belong to the same banking group;
    - 2. the powers of the person were terminated at the request of the CBU.
  - In accordance with BL Article 36, members of the supervisory board and the management board, as well as key personnel of the bank, should proceed through Fit-and-Proper evaluation: must have an impeccable business reputation, the experience, knowledge and skills necessary to ensure effective risk management of the bank, making informed decisions within their powers. The CBU interviews candidates.
  - The bank is obliged to ensure that members of the supervisory board and management board, as well as key personnel, constantly comply with the requirements of the legislation on banks and banking activities. The CBU approves candidatures before they start duties.
  - Article 3 of the RCG: members must demonstrate responsibility and enthusiasm, serve in good faith, performing activities with a sense of responsibility.
- Loyalty requirements include:
  - disclosure of all existing and potential conflicts of interest;
  - not using official position for personal purposes;
  - non-participation in decision-making in presence of a conflict of interest.
- Supervisory board assessment questions (per Guidelines):
  - 9 enhanced questions to investigate general responsibilities;
  - 5 questions on qualifications and composition;
  - 13 related to the structure and practices;
  - 4 to investigate remuneration;
  - 3 to investigate conflicts of interest.
- Assessors found limited evidence of implementation despite RBS and on-site assessments.

### EC4 — Nomination, appointment, renewal, committees (description and findings)
- EC4 principle: The supervisor determines that governance structures and processes for nominating and appointing board members are appropriate; boards regularly assess performance; board membership is regularly renewed; board structures include audit, risk, compensation and other committees with experienced, independent directors.
- Relevant legal/regulatory provisions and practices:
  - Article 34 of the BL: supervisory board duties include approval and control over implementation of strategic goals, corporate governance policy, procedure for preventing and resolving conflicts of interest, internal policies, identification/management/monitoring/communication of risks, maintaining capital adequacy.
  - Banking sector strategy: SOB corporate governance identified as a priority; several SOB boards recently renewed to bring in independent members.
  - To reach goal of ‘more than half’ independent members in each state-owned enterprise, including each state-owned bank, the state as shareholder appointed 25 directors (out of 32) from abroad to mitigate political interference.
  - Candidates must follow Fit-and-Proper procedure and get CBU permission prior to starting duties (Article 36 BL reiterated).
  - RCG Article 8: number and composition of supervisory board should be based on scale and nature of bank activity, ensure:
    - the ability to hold meetings periodically (at least once a quarter) with quorum;
    - possess collective experience and knowledge necessary for effective management and decision-making.
  - Boards may create special committees; Article 16 RCG stipulates Audit Committee is mandatory, regardless of size and complexity.
  - Committees must include at least three members of the supervisory board. A committee may not consist of the same group of members constituting another committee, nor may one member chair different committees at the same time.

### Audit Committee — mandated tasks (bulleted duties)
- Main tasks of the Audit Committee (RCG Article 16 and text):
  - participating in development and approval of financial reporting and internal audit policies;
  - monitoring submission, completeness, and reliability of supervisory, financial, and other reports;
  - preparing information for board meetings and submitting reports to the board on issues within its authority;
  - monitoring interaction between internal and external auditors;
  - considering appointment (dismissal) of the head of internal audit service and submitting proposals to the board;
  - reviewing quarterly reports of internal audit service and submitting them to the board;
  - evaluating effectiveness and appropriateness of internal control system and internal audit activities, reviewing internal audit inspection plan and periodicity, assessing head of internal audit performance and providing opinions;
  - meeting with head of internal audit at least once a quarter to discuss internal audit activities;
  - assisting board in evaluating proposals from external auditors and recommending selection;
  - making recommendations to board regarding maximum fees payable to external auditors and contract terms including termination;
  - assisting board in developing technical tasks for external auditors;
  - receiving internal and external audit reports and ensuring discrepancies and deficiencies are promptly addressed by management;
  - reviewing external audit reports and conclusions and submitting them to the board;
  - recommending replacement of unsatisfactory external auditors;
  - reviewing transparency, adequacy and accuracy of disclosed information;
  - preparing a report on its activities;
  - performing other tasks assigned by the board.

### Risk Management Committee — mandated tasks and supervisory view
- RCG Article 19: board may establish risk management committee; majority of members should not be related parties; chair should not be chair of the board.
- Main duties include:
  - reviewing documents related to risk management and internal control and providing recommendations to the board;
  - supervising development, adherence, and updating of risk appetite and risk management policies by management and structural unit responsible for risk management;
  - periodically reviewing risk assessment methods, including stress-testing techniques;
  - determining structure and format of risk-related information presented to the board and terms for submission;
  - proposing measures to reduce risks and take timely actions when risk profile is not aligned with approved risk appetite;
  - assessing alignment of compensation system with risk appetite;
  - accepting reports on existing and potential risks at least once every quarter and taking actions to mitigate risks;
  - assessing independence of employees responsible for risk management from other structural units involved in risk-taking;
  - participating in evaluations of heads of structural units responsible for risk management;
  - preparing quarterly reports on activities; performing other tasks assigned by the board.
- Supervisory assessors’ view: In line with proportionality and risk-based approach, the Risk Committee should be made mandatory for D-SIBs.

### Remuneration Committee — mandated tasks
- RCG Article 23: board may establish remuneration committee to ensure internal remuneration aligns with risk-taking, long-term strategy, risk appetite, financial results, internal control, legislative requirements.
- Main duties include:
  - participating in development of remuneration policy for board, management and key personnel and reviewing it at least once a year;
  - monitoring implementation and execution of remuneration policy and incentive programs;
  - monitoring implementation of remuneration and compensation decisions;
  - developing performance evaluation criteria for remuneration payments reflecting responsibilities and risk-taking levels;
  - conducting preliminary assessments of annual performance of board and management members and key personnel based on remuneration policy criteria and analyzing achievement of long-term goals if assigned by the board;
  - evaluating compliance of remuneration and compensation system with internal documents;
  - performing other tasks assigned by the board.

### EC5 — Board oversight of strategy, risk appetite, corporate culture (description and findings)
- EC5 principle: The supervisor determines that the bank’s board approves and oversees implementation of the bank’s strategic direction, risk appetite and strategy, related policies, establishes and communicates corporate culture and values (e.g. through a code of conduct)38, and establishes conflicts of interest policies and a strong control environment.
- Strategic goals and risk appetite:
  - Article 34 BL: duties of supervisory board include approval and control over implementation of strategic goals, corporate governance policy, procedure for preventing/resolving conflicts of interest, other internal policies including identification, management, monitoring and communication of risks, maintaining capital adequacy.
  - Risk appetite (RRM): aggregate value of all significant risks the bank is ready to accept to achieve strategic objectives; must be determined in Risk Appetite Statement and approved by Supervisory Board.
  - Risk Appetite Statement must comply with bank strategy, business plan and budget planning, and include key assumptions used in development process and procedures for approval of risk limits.
- Conflicts of interest and corporate culture:
  - Article 33 RCG: board must develop and implement policy for preventing and resolving conflicts of interest, establish procedures and monitor execution; banks must implement measures to prevent corruption, implement rules of ethical behavior and prevent conflicts of interest.
  - Article 37 RCG: board must adopt a code of ethics including corporate values and standards and ensure compliance by all employees including management bodies.
- Supervision:
  - Under Block ‘D’ of the RBS, issues related to implementation of strategic goals, risk appetite and their statements, conflicts of interest and corporate culture are assessed.
  - Examples provided where CBU challenged lack of control in implementation of banks’ strategy and deficiencies in risk appetite statements.
  - During on-site visits, inspectors consider limits of risk appetite, their expediency and threshold values.

### EC6 — Fit-and-proper, authority allocation, succession, oversight (description and findings)
- EC6 principle: The supervisor determines that the bank’s board, except where required otherwise by laws or regulations:
  - (a) has established fit and proper standards in selecting senior management and heads of the control functions;
  - (b) has developed effective processes to allocate authority, responsibility and accountability within the bank;
  - (c) maintains plans for succession; and
  - (d) actively and critically oversees senior management’s execution of board strategies, including monitoring performance of senior management and heads of control functions against established standards.
- As described in EC2 and EC5, by conducting risk-based assessment of the bank, supervisors also assess these aspects.

*Source: 1uzbea2025004-source-pdf - 1. clear distribution of powers and responsibilities stated in the internal*

### 1. evaluate  the  establishment  of  fit  and  proper  standards  for  senior  management

### 1. evaluate  the  establishment  of  fit  and  proper  standards  for  senior  management

### Oversight of senior management fit and propriety (EC7–EC10)
- EC7: Supervisor determines the board actively oversees the design and operation of the bank’s compensation system and that it has appropriate incentives aligned with prudent risk-taking and effective in addressing misconduct that potentially results in losses.
- Description and findings re EC7:
  - Main tasks of the Remuneration Committee are broadly described in EC4.
  - Remuneration paid to members of the supervisory board must be approved by a decision of the general meeting of shareholders.
  - Risk management unit and the compliance control service are involved in the development of the remuneration system.
  - Pursuant to RCG Article 27, the remuneration system should be in accordance with the bank's business plan, bank development strategy, goal and bank risk management policy, measures aimed at preventing conflicts of interest, and limiting the acceptance of high-level risks.
  - The remuneration system should be properly documented in the bank's internal policy and should include at least:
    - 1. permanent and variable compensations and incentive payments;
    - 2. the maximum amount of compensation and incentive payments;
    - 3. criteria for evaluating the work of members of the Board and the Management Board and key personnel;
    - 4. the procedure and terms for the payment of bonuses.
  - Supervisors should determine that the compensation system and related performance standards are consistent with long-term objectives and financial soundness of the bank. Within the existing framework, topics are evaluated under Blocks ‘B’ and ‘D’ of the RBS.

- EC8: Supervisor determines the board and senior management know and understand the bank’s operational structure and its risks, including those arising from structures that impede transparency, and that risks are effectively managed and mitigated.
- Description and findings re EC8:
  - Article 95 of the CBU Regulation No. 3252 requires persons nominated to supervisory and management boards to demonstrate a good understanding of the bank's activities and risks.
  - Experience, skills, and knowledge of members should collectively cover all areas where the bank is active.
  - Article 5 of the RCG requires Supervisory Board members to be aware of banking risks and to constantly improve knowledge and skills in banking and finance.
  - Article 10 requires reliance on internal control and risk management systems and effective control over supervisory board activities.
  - Supervisors determine these matters by performing banks’ risk assessments (see EC2).
  - Investigation questions include:
    - Do supervisory board members have knowledge, expertise, independence, access to information and influence necessary for proper supervision?
    - To what extent does the management system provide the management board with necessary information for effective management and monitoring?

- EC9: Laws, regulations or the supervisor require banks to notify the supervisor or publicly disclose as soon as they become aware of any material and bona fide information that may negatively affect the fitness and propriety of a board member or senior management.
- Description and findings re EC9:
  - Under the BL, banks must timely notify the CBU of any significant changes in activities, structure, general condition, or significant negative events, including violations of legal or prudential requirements, as soon as they become aware of them.
  - RCG requires management board members to refrain from actions leading to conflicts of interest and to immediately inform the supervisory board and eliminate conflicts.
  - Article 81 of Regulation No. 3252 obliges banks to constantly reassess the compliance of managers with law requirements.
  - Article 82 states if revaluation shows a director no longer meets requirements, the bank shall inform the CBU in writing within 3 working days from detection and take measures to eliminate the shortcoming.

- EC10: Supervisor has the power to require changes in board composition if individuals are not fulfilling duties related to these criteria.
- Description and findings re EC10:
  - Article 34 of the BL stipulates powers of supervisory board members may be terminated early at the request of the CBU.
  - Regulation on LIC establishes specific fit and proper criteria for founders, potential acquirers, supervisory and management board members, and key personnel.
  - CBU required banks with a state-owned share to change supervisory board composition to increase independent members.
  - Assessors were provided cases where CBU recommended or required removal/replacement of board members and key personnel (example: Resolution of the Banking Supervision Committee No 181/4 dated January 9, 2020).

### Assessment of Principle 14 — Corporate governance
- Rating: Largely Compliant
- Comments:
  - CBU has comprehensive regulation covering corporate governance arrangements in banks and banking groups.
  - Supervisory framework is tailored to size, complexity, structure, risk profile and business model; large/complex/high-risk banks expected to adopt enhanced governance structures.
  - Board responsibilities: approve and oversee strategic direction, risk appetite and strategy; establish corporate culture and values; ensure compliance; develop policy for preventing and resolving conflicts of interest.
  - Corporate governance as an autonomous risk profile in risk-based supervision introduced in 2023; supervisors expected to evaluate corporate governance and risk management annually per GRBS methodology.
  - Assessors did not find robust evidence of this assessment in documents shared by the CBU.

- Findings:
  - The CBU recently strengthened the RCG; shortcomings remain:
    - No requirement for a succession plan;
    - Risk Committee is not mandatory for D-SIBs.
  - Off-site risk assessment of corporate governance recently introduced in supervisory manual, but not fully tested in pilot phase (only one out of four risk assessments based on document shared).
  - New methodology for on-site inspection does not mention corporate governance (assessors note a draft amendment envisages such an extension).

- Recommendations:
  - RCG should consider requiring boards to develop succession plans and require D-SIBs to set a mandatory Risk Committee.
  - CBU should consider structurally embedding corporate governance assessment in off-site and on-site risk assessments.

### Principle 15 — Risk management process (EC1)
- Principle summary:
  - Supervisor determines banks have a comprehensive risk management process (including effective board and senior management oversight) to identify, measure, evaluate, monitor, report and control or mitigate all material risks, and to assess adequacy of capital, liquidity and sustainability of business models. Process is commensurate with risk profile and systemic importance.

- EC1: Board-approved risk management strategies and effective risk appetite framework; board ensures sound risk culture, consistent policies and processes, recognition of uncertainties in measurement, appropriate limits, and senior managers monitor and control material risks.
- Description and findings re EC1:
  - Article 42 of the BL obliges banks and banking groups to comply with CBU requirements for internal control and the risk management system; supervisory board obliged to control compliance with internal limits and oversee effectiveness of risk management.
  - Banking law delegates secondary regulation of risk management and internal control standards to the supervisor and enables assessment of compliance.
  - In April 2023 the CBU issued the RRM. An amendment registered by the Ministry of Justice in January 2025 will become effective the 21th of April 2025.
  - RRM Chapter 2 requires banks to establish a risk management system comprising:
    - the organizational structure of risk management;
    - risk management culture;
    - internal documents and management tools;
    - information system for risk management and reporting.
  - RRM Article 3 states the risk management system should ensure:
    - clear distribution of tasks, preventing potential conflicts of interest;
    - clear separation of duties by a system of three lines of defense;
    - timely identification, assessment and proper measurement of all material risks;
    - tools and systems for proper risk monitoring, reporting, control and mitigation;
    - reasonable pricing of bank's products;
    - completeness and proper documentation of risk management processes.
  - To ensure functioning of the risk management system, the supervisory board approves: organizational structure; risk-appetite statement; credit policy; risk management policies covering all material risks (liquidity, market, operational and compliance); policy for introducing new banking products; stress-test procedure.

- Sound risk culture requirements (RRM Article 24):
  - Management board responsible for creating risk management culture and ensuring:
    - staff informed about role in risk management;
    - responsibilities of each unit clearly defined;
    - continuous communication of corporate values;
    - standards for qualification and competence;
    - staff aware of the code of ethics;
    - properly organized internal and external communication;
    - training to ensure awareness of new/emerging risks.

- Policies, processes and limits:
  - RRM Article 29 requires supervisory board to approve risk management policies covering all material risks, approve risk limits for each material risk and measures for breaches.
  - Uncertainties attached to risk measurement: Article 29 foresees discussion of transactions/actions that may lead to violations, statement of risk appetite and policies; board empowered to take measures if risk profile does not correspond to approved risk appetite. There is no explicit requirement that uncertainties attached to risk measurement are recognized by the board.
  - Articles 10-11 require Risk Appetite Statement to include procedures and processes for approving risk limits and notification procedures for breaches. Risk Appetite Statement should define three limits:
    - low level that does not require mitigation of risks;
    - medium level, requiring a reduction in the risk level;
    - unacceptably high level, requiring risk mitigation.
  - Quantitative limits should be set on all risk types and determined based on size and complexity of bank operations and aligned with the bank’s risk appetite.

- Senior management monitoring and control (RRM Article 31):
  - Management board responsible for effective implementation of risk management system in accordance with risk appetite, risk management policy and other internal documents approved by supervisory board.

- Supervision and assessments:
  - From 2023 the CBU introduced regular assessments of banks’ risk profile; methodology described in the GRBS (see CP8 EC1).
  - GRBS supervisory manual sets modalities requiring supervisors to assess implementation of risk management through comprehensive structured analysis that includes assessment of inherent risk and quality of risk management implementation.
  - Annual risk assessment covers corporate governance and risk management.
  - Inputs to assess risk management include minutes of supervisory and management boards; minutes of committees (if established); documents adopted by boards and committees (including risk appetite statements and risk policies); banks’ organigrams; descriptions of functions; information about experience and skills recently obtained by board members and key personnel, among others.
  - Curators may participate in boards’ and committees’ meetings as part of on-going supervision and use observations to complement assessments.
  - CBU conducted a thematic review in several banks to assess how supervisory boards organized the risk management system and status of RRM implementation.
  - Until August 2024 on-site inspections followed CAMEL methodology which only partially covers assessment of risk management and corporate governance; during on-site inspection only certain topics (mostly regarding management of material risks) were covered.
  - Assessors examined three risk assessments conducted in 2023.

*Source: https://www.imf.org/-/media/files/publications/cr/2025/english/1uzbea2025004-source-pdf.pdf*

### 2024.  The  findings  and  observations  regarding  the  assessment  of  risk  management

### 2024. The findings and observations regarding the assessment of risk management system

### Summary findings (general)
- Established risk management and internal control processes usually only partially comply with the RRM provisions.
- Doubts were raised on independence of the risk management function; restricted powers of the Chief Risk Officer (CRO) were found.
- Assessors found evidence that the CBU challenged the lack of limits in the risk appetite (for example, on car loans, on loans to individual without official income, on operational risk, on market risk).
- The CBU will issue a letter expressing supervisors’ expectations for risk management more specifically after the RBS assessment is completed (December 2024).

### EC2 — Comprehensive risk management policies and processes
- Supervisor requires banks to have comprehensive risk management policies and processes to identify, measure, evaluate, monitor, report and control or mitigate all material risks.
- Supervisor determines adequacy of these processes:
  - (a) to provide a comprehensive bank-wide view of risk across all material risk types;
  - (b) for the risk profile and systemic importance of the bank;
  - (c) to assess risks arising from the macroeconomic environment affecting the markets in which the bank operates and to incorporate such assessments into the bank’s risk management process; and
  - (d) to assess risks that could materialize over longer time horizons (including risks related to digitalization, climate-related financial risks and emerging risks). Where appropriate, banks use scenario analysis as a tool.
- Description and findings:
  - The RRM requires banks to identify, measure, monitor and control all material risks.
  - In the RRM version published in April 2023, material risk included only credit risk, liquidity risk, market risk, operational risk and compliance risk; in the updated version, registered by the MoJ in January 2025, country risk and IRRBB were included among material risks.
  - The CBU draft strategy on the management and supervision of climate-related financial risks in the banking sector for 2025-2027 foresees the setting of standards that banks will be required or recommended to follow when managing climate-related risks.
  - Implementation of the process of identifying, measuring, monitoring and controlling risk must be supported by:
    - timely management information system; and
    - accurate and informative reports regarding financial condition, functional activity performance, and banks’ risk exposure.
  - To assess banks’ risk profile, the CBU collects an extensive package of information which includes risk policies and risk appetite statements, and quarterly stress test conducted by banks.
  - The adequacy of financial risk management processes is assessed during on-site inspections; assessors received four on-site inspection reports each containing CBU observations and recommendations.
  - CBU challenged two banks during on-site examinations due to breach of internal limit not being escalated by the risk management function to the supervisory board.

### EC3 — Documentation, alignment with risk appetite and limit breach procedures
- Supervisor determines that risk management strategies, policies, processes and limits are properly documented and aligned with the bank’s risk appetite statement and framework; regularly reviewed and communicated; and that adequate procedures are in place for breaches of risk limits.
- Description and findings:
  - Article 3 of the RRM requires completeness and documentation for risk management processes.
  - Banks develop and approve documents (strategies, risk statements, risk management policies) in accordance with minimum CBU requirements and provide these to the CBU yearly.
  - Policies and procedures are evaluated during off-site supervision and on-site inspections; shortcomings are communicated by letters requesting adjustments or elimination of deficiencies.
  - RRM Article 35 confers to the head of the risk management unit a veto power on key decisions of the management board and other executive bodies if implementation would violate risk appetite or approved limits.
  - In case of significant increase in risk, head of risk management should immediately request the management board to convene an extraordinary meeting of the supervisory board or risk management committee.
  - Assessors were provided with examples of letters/notifications sent to banks evidencing CBU challenge of banks’ risk management policies and processes.

### EC4 — Information to board and senior management on risks, capital and liquidity
- Supervisor determines that board and senior management obtain sufficient information and understand the nature and level of risk and implications/limitations of risk management information.
- Description and findings:
  - RRM requires supervisory and management boards to understand inherent risks and:
    1. ensure policies, strategies, and risk management framework are evaluated and updated at least once a year and upon significant change;
    2. ensure a risk management information system is in place providing accurate, complete, informative, timely and reliable information for supervisory and management boards to assess, monitor, and mitigate risks, evaluate effectiveness of implementation, and track achievement of bank targets.
  - Supervisors obtain banks’ internal information (risk policies, management information, internal reports, dashboards, reports on limit breaches) to determine if boards and senior management obtain sufficient information and understand risk nature, level and mitigation measures.
  - Credit risk is recognized as the most significant risk in the banking sector; RRM stipulates credit policy must be prepared as a separate document with wider requirements compared to other risks.

### EC5 — Internal capital and liquidity adequacy assessment processes (ICAAP)
- Supervisor determines banks have appropriate internal processes for assessing overall capital and liquidity adequacy and sustainability of business models; supervisor reviews and evaluates banks’ internal capital and liquidity adequacy assessments and strategies.
- Description and findings:
  - Article 29 of the RRM states supervisory board should determine internal capital adequacy assessment processes (ICAAP); requirements for ICAAP implementation are described in Chapter 7, Paragraph 6 of the RRM.
  - According to the RRM, ICAAP implementation is not mandatory (“the bank’s board may introduce internal processes for assessing capital adequacy”); banks may decide on any other internal approach.
  - In practice, banks use more simplified approaches to assess overall capital adequacy; these consider strategic goals and macroeconomic factors and align with proportionality principle.
  - Assessors consider that D-SIBs should be requested to prepare ICAAP.
  - Supervisory board approves banks’ capitalization plan which includes:
    - description of the capital planning process and tasks of relevant structural units;
    - methods used to meet capital requirements;
    - limits for capital levels and capital ratios;
    - measures to be taken in event of unforeseen events, including in terms of capital decrease.
  - Based on the capitalization plan, banks set limits on capital adequacy levels considering risk profile, risk appetite, quality of risk management, strategic goals and economic situation.
  - The CBU routinely assesses liquidity as part of ongoing off-site supervision and assesses a variety of liquidity ratios; liquidity assessment is mandatory for all full scope on-site inspections.
  - Recommendation: develop guidelines for the ICAAP to be followed by D-SIBs and consider making ICAAP mandatory for D-SIBs.

### EC6 — Use and validation of models
- Supervisor determines banks using models meet conditions: compliance with supervisory standards, boards and senior management understand limitations, and regular independent validation/testing of models is performed.
- Description and findings:
  - Currently, all banks use a standardized approach for measuring risks established by the CBU; models are not used for calculating capital requirements.
  - Banks use internal models for other purposes (e.g., customer solvency assessment, stress testing).
  - Recent amendment to the RRM, registered by the MOJ in January 2025, required the risk management division to regularly assess reliability and effectiveness of internal models (back testing) and to conduct stress tests.
  - Assessors did not find evidence that the CBU determines that banks perform regular and independent validation and testing of the models.
  - No evidence was found that the CBU determines that boards and senior management understand limitations and uncertainties of model outputs and inherent risks.

### EC7 — Risk management information systems (MIS)
- Supervisor determines banks have information systems adequate under normal and stress conditions for measuring, assessing and reporting exposures across all risk types; reports reflect risk profile and needs and are timely for board and senior management.
- Description and findings:
  - Article 40 of the RRM obliges banks to introduce a risk management information system that collects and summarizes information from all areas, reliably assesses risks and prepares risk reports; MIS should correspond to nature, scale and complexity of operations and ensure truthfulness, completeness and timely submission.
  - Regulation on Liquidity requires each bank to have an information system implementing effective control of liquidity position, timely and fully meeting management needs in business-as-usual and stressed conditions.
  - Supervisors assess MIS quality via banks’ risk assessment; GRBS provide methodology for MIS assessment; MIS is evaluated by assessing all material risks and during assessment of management and corporate governance.
  - During on-site inspections, CBU assesses completeness and effectiveness of systems, verifies support for monitoring and control of risks, and identifies limit breaches; assessors observed evidence that CBU verifies reliability of risk management reporting during on-site inspections.

### EC8 — Risk data aggregation and reporting capabilities
- Supervisor determines banks develop and maintain appropriate risk data aggregation and reporting capabilities commensurate with risk profile and systemic importance; board and senior management review and approve framework and ensure adequate resources.
- Description and findings:
  - Supervisors determine banks develop and maintain appropriate risk data aggregation and reporting capabilities; data quality and aggregation are subject to on-site reviews.
  - Assessors were provided with on-site reports identifying deficiencies in calculation of liquidity and capital indicators; banks performed internal investigations and sometimes found data aggregation errors in banking systems.
  - No evidence was found about the CBU’s determination that boards and senior management review and approve banks’ risk data aggregation and reporting framework.

### EC9 — Risks from new products, material modifications and major initiatives
- Supervisor determines banks have adequate policies and processes to ensure boards and senior management understand risks inherent in new products, material modifications, and major initiatives; such activities require board or specific committee approval.
- Description and findings:
  - Article 8 of the RRM requires Supervisory Board approval of bank policy on introduction of new products and assessment of:
    - economic feasibility;
    - compliance with regulator and internal requirements;
    - risks and impact on bank's risk profile;
    - ability to monitor and manage associated risks;
    - pricing correspondence with pricing policy;
    - bank's readiness to introduce new product (knowledge, staff, etc.).
  - RRM requires risk management involvement in evaluation and decision-making for new products (RRM Article 35).
  - Informal practice exists where banks inform supervisory authorities in advance of intentions to introduce new products; there is an example where a supervisor prevented a bank from introducing a new product (FX lending to self-employed individuals was banned because FX lending to natural persons is prohibited).

### EC10 — Risk management function resources, independence, authority, reporting and review
- Supervisor determines banks have risk management functions covering all material risks with sufficient resources, independence, authority and access to boards; duties segregated from risk-taking functions; risk management subject to regular internal audit review.
- Description and findings:
  - Requirements described in Chapter 5, Paragraph 4 of the RRM: supervisory board must ensure a risk management unit supervised and/or headed by a head of risk management with sufficient authority, independence, and resources, interacting with the supervisory board.
  - Risk management unit responsibilities include:
    - development of a risk management system, including policies, procedures, risk appetite strategy;
    - identification of significant current and potential risks;
    - participation in preparation of opinions on risks associated with new banking services prior to introduction;
    - risk assessment and determination of aggregated level(s) of risk appetite;
    - monitoring compliance with risk appetite levels;
    - development of early warning indicators and systems;
    - evaluating the effectiveness of pricing policy;
    - providing opinion on proposed new banking products prior to their introduction.

*Source: 1uzbea2025004-source-pdf - 2024. The findings and observations regarding the assessment of risk management system.*

### introduction;

### introduction

### Risk management independence and three lines of defense
- The risk management system shall provide for separation of the risk management and internal control functions from the bank’s operations by means of three lines of defense system (RRM Article 30).
- To ensure the independence of the risk management, RRM Article 30 requires that:
  - the unit reports directly to the supervisory board and the risk management committee (if established);
  - the head is appointed by and accountable to the supervisory board;
  - the amount of remuneration of managers and employees of the unit does not depend on the performance of the business lines responsible for the provision of banking services; at the same time, remuneration may depend on the overall financial condition of the bank;
  - situations in which bank management and other executives put pressure on managers and employees of this unit must be prevented;
  - managers of the unit should be able to directly discuss the state of risks in the bank with the supervisory board without notifying the management board;
  - number and qualification level of employees should ensure the fulfillment of the tasks and objectives of the RRM;
  - managers and employees are not allowed to participate in revenue-generating banking activities, nor are they allowed to serve on committees and various working groups unrelated to the department's operations, nor are they allowed to hold other positions at the same time;
  - hiring, dismissal and incentives for these employees are carried out by the Chairman of the board on the recommendations of the heads of the unit;
  - the unit should have full access to the information necessary to perform its duties.

### Internal audit assessment of the risk management system
- The Regulation of Internal Audit (RIA) requires the internal audit unit to assess the effectiveness of the risk management system (Article 19).
- When assessing the risk management system, internal audit unit should evaluate at least the following components (RIA Article 20):
  - the risk management unit, in particular its decisions and their compliance with the established functions and correct functioning of the risk management system (credit risk, liquidity risk, market risk, operational risk, compliance risk and others);
  - the risk appetite of the bank and compliance of bank's activities to the risk appetite;
  - the effectiveness of the internal procedure for informing the CBU, the supervisory and management board of the Bank, about issues and decisions taken within the framework of risk management, as well as major risks;
  - adequacy of risk management systems and processes to identify, measure, assess, control, respond to and report on risks;
  - integrity of information systems used in the framework of risk management, including accuracy, reliability and completeness of data;
  - risk assessment methodologies and models, including verification of the consistency of approaches and reliability of data used in these models.
- The assessors were provided with an example of internal audit of the risk management function.

### EC11 — CRO and dedicated risk management unit
- EC11 expectation: The supervisor requires larger and more complex banks to have a dedicated risk management unit overseen by a chief risk officer (CRO) or equivalent function. If the CRO of a bank is removed from their position for any reason, this should be done with the prior approval of the board and generally should be disclosed publicly. The bank should also discuss the reasons for such removal with its supervisor.
- Description and findings re EC11:
  - According to Article 30 of the RRM, regardless of the size and systemic importance of the bank, the board is obligated to establish a risk management unit as a structural unit responsible for managing risks and ensure their independence. The heads of this unit are appointed by the supervisory board and are accountable to the supervisory board.
  - In the original version of the RRM, there was no requirement for the removal of the CRO to be notified to the CBU; in the revised version, Banks must notify the Central Bank within five days if the CRO employment contract is terminated, specifying the grounds and reasons (par. 35-1).
  - There is an example where the CRO was removed according to the CBU’s decision.
  - One point of improvement, also in the new RRM, is the requirement to publicly disclose the CRO’s removal, still not addressed.

### EC12 — Standards for risk types
- EC12 expectation: The supervisor issues standards related to, in particular, credit risk, market risk, liquidity risk, interest rate risk in the banking book, operational risk and large exposures.
- Description and findings re EC12:
  - Regulation "On Requirements for the Risk Management System in Banks and Banking Groups" (RRM) determines requirements for managing credit, market, operational, liquidity and compliance risk.
  - RRM is supplemented by the set of regulations issued by the CBU related to credit risk, market risk, liquidity risk, operational risk, large exposure and, with the recent amendments, also IRRBB, country risk and operational resilience (see connected CPs).

### EC13 — Contingency arrangements and recovery plans
- EC13 expectation: The supervisor requires banks to have appropriate contingency arrangements, as an integral part of their risk management process, to address risks that may materialise and actions to be taken in stress conditions (including those that will pose a serious risk to their viability). If warranted by its risk profile and systemic importance, the contingency arrangements include robust and credible recovery plans. The supervisor assesses adequacy and feasibility and seeks improvements if deficiencies are identified.
- Description and findings re EC13:
  - Recovery plans:
    - Pursuant to Article 49 of the BL, at the request of the CBU, banks develop and submit a recovery plan, containing measures to restore financial health in the event of its deterioration.
    - A bank must update the recovery plan annually or after changes in the bank’s organizational structure, operations or financial position that may affect the recovery plan.
    - The bank’s recovery plan should reflect the impact of macroeconomic and financial crisis scenarios on the bank’s activities, including systemic events and risks for the bank.
    - It should also include a list of measures and indicators that determine the positions under which appropriate decisions should be made.
    - The CBU, within three months from the bank’s submission, reviews the recovery plan, assessing:
      - preservation and (or) restoration of the financial position while implementing the measures specified in the recovery plan;
      - ability to quickly and effectively implement the measures outlined in the recovery plan in the context of a financial crisis and reduce negative impacts on the banking and financial system.
    - If the recovery plan does not meet the above criteria, the CBU can require the bank to: (i) revise the recovery plan; (ii) make changes and additions to it; (iii) change activities to eliminate recovery deficiencies or obstacles to its implementation; (iv) reduce the risk profile; (v) recapitalize the bank; (vi) revise the strategy; (vii) change the organizational structure or risk management.
    - The parent bank of a banking group should develop a banking group recovery plan that includes measures taken at the group level to restore its financial position after a deterioration. The banking group recovery plan must comply with the requirements of the banking and banking legislation.
  - BL Article 49 delegated the CBU to establish the requirements for the content and updating, the procedure for submitting and evaluating the bank recovery plan; however, the CBU has not issued a Regulation on recovery plans. Banks have not submitted recovery plans to the CBU.
  - Article 21 of the RRM stipulates that based on the results of the stress testing, the bank must develop an emergency funding plan to foresee measures to be taken in case of liquidity shortfalls.
  - Amendments to the RRM registered by the MOJ (January 2025) stipulate that internal procedures for managing operational risk should include a plan to ensure the continuity and restoration of the bank's activities (see CP25, EC5). This plan is aimed at maintaining the bank's operational activity in the event of extraordinary and unforeseen operational interruptions.
  - Although the existing regulation describes different requirements for banks’ restoration, supervisors generally obtain restoration plans, emergency finding plans or plans for banks capitalization.
  - The assessors were provided with some examples of business continuity plans; however, no evidence was provided about the CBU’s assessment of them (see CP25).
  - As stated under CP24, EC6, the CBU assesses liquidity contingency funding plans once a year, prior to assessing the bank's risk profile. The assessment of this plan is incorporated into the overall liquidity risk assessment.

### EC14 — Forward-looking stress testing programmes
- EC14 expectation: The supervisor requires banks to have forward-looking stress testing programmes covering all material risks commensurate with their risk profile and systemic importance. Supervisory assessment ensures programmes capture material sources of risk, adopt plausible adverse scenarios, and integrate results into decision-making, risk management and capital/liquidity assessment.
- Description and findings re EC14:
  - RRM Article 14 states that stress testing should be done to complement the risk measurement system by estimating the potential loss of the bank in unusual and/or stressed market conditions by using scenarios to see the sensitivity of the bank’s performance to changes in risk factors and identifying influences that can have significant impact on the bank’s portfolios.
  - To implement stress-tests banks must prepare and approve procedures which must include:
    1. list of risks that are subject to stress testing;
    2. methodology and tools for stress testing of credit, liquidity, market and operational risks;
    3. dedicated unit to perform stress-test;
    4. management information procedure.
  - In developing scenarios and assumptions of stress testing, banks are guided by the following:
    1. scenarios must include all significant risks to which the bank is potentially exposed;
    2. the bank shall consider the relationship of various types of risks; takes a conservative approach in determining the assumptions of stress testing;

*Source: 1uzbea2025004-source-pdf - introduction*

### 3. consider severe changes in market conditions, such as: lack of access to capital

### 3. consider severe changes in market conditions, such as: lack of access to capital

### Stress testing framework and practices
- Stress tests must be carried out on a quarterly basis for credit, market, liquidity and operational risk according to the RRM (original requirement).
- Stress test results and proposed actions are communicated and discussed with senior management and units involved in liquidity risk management.
- The supervisory board shall integrate stress testing results into strategic and budget planning and use results to establish internal limits and to consider capital and liquidity adequacy under unforeseen circumstances.
- Banks provide the CBU with models, scenarios, and stress test results. Supervisors may require revisions or improvements if deficiencies are found.
- The CBU challenged stress tests conducted without proper consideration of the risk profile and instructed banks to develop and approve stress test scenarios for the next year.
- Assessors noted that requiring all banks to run quarterly stress tests for credit, market, liquidity and operational risk might not be fully risk-based and could affect quality and comprehensiveness of the exercise.
- The CBU agreed and revised the RRM to reduce the frequency of stress tests to annual (par. 15).

### EC15 — internal pricing, performance measurement and new product approval
- Principle statement: The supervisor assesses whether banks appropriately account for risks (including liquidity impacts) in internal pricing, performance measurement and new product approval processes for all significant business activities.
- Description: Article 22 of the RRM requires the bank’s risk management system to ensure reasonable pricing of products, taking into account the level of risks and costs assumed.
- On-site Inspection Department: periodically inspects banks’ pricing models to assess mechanisms for internal pricing, performance evaluation, and review/approval of new activities and products by supervisory and management boards.
- Assessment of Principle 15: Largely Compliant.

### Key findings related to Principle 15 and risk management framework
- The CBU issued (April 2023) a regulation on implementation of risk management setting expectations for comprehensive risk management, board and senior management oversight, identification/measurement/evaluation/monitoring/reporting/control/mitigation of material risks, and assessment of capital and liquidity adequacy relative to risk profile and market/macro conditions.
- Amendments to the RRM were released for consultation, registered by the MOJ (January 2025) and will become effective by April 2025. The amendments:
  - expand risk coverage to IRRBB, country risk and operational resilience related risk;
  - require board’s approval for large exposures;
  - introduce duties for risk management units including back testing of internal models and avoidance of reliance on external ratings;
  - provide for mandatory notification to the CBU of the CRO removal.
- Amendments do not foresee introduction of risks related to digitalization or climate-related financial risks, although the CBU shared a draft strategy on climate related financial risks.
- CBU introduced regular assessments of banks’ risk profile via the GRBS supervisory manual; the annual risk assessment should cover corporate governance and risk management.

- Specific findings:
  - the CBU has not issued a regulation to determine content, updating and procedure for submitting recovery plans.
  - the CBU has introduced ‘Requirements for internal capital adequacy assessment procedures’ (RRM article 67-71), but they are optional for all banks, regardless of size and domestic systemic importance.
  - assessors could not find evidence that (i) banks perform regular and independent validation and testing of models; (ii) banks’ boards and senior management understand limitations and uncertainties of model outputs.
  - the revised RRM does not contain a requirement to publicly disclose the CRO’s removal.

### Recommendations (CBU)
- Introduce a regulation for the preparation and submission of recovery plans.
- make mandatory for D-SIBs Requirements for internal capital adequacy assessment procedures’ 
- determine that (i) banks perform regular and independent validation and testing of the models, and (ii) the banks’ boards and senior management understand the limitations and uncertainties relating to the output of the models and the risk inherent in their use
- introduce the requirement to publicly disclose the CRO’s removal

### Principle 16 — Capital adequacy: framework and metrics
- Principle statement: The supervisor sets prudent and appropriate capital adequacy requirements that reflect risks and market/macroeconomic context; supervisor defines capital components with emphasis on loss-absorbing elements; for internationally active banks, capital requirements not less stringent than applicable Basel standards.
- EC1: Laws, regulations or the supervisor require banks to calculate and consistently observe prescribed capital requirements; qualifying components of capital are defined.
  - Banks are required by Law to calculate and consistently observe prescribed capital requirements.
  - CBL Article 61 empowers the CBU to establish ‘the procedure for calculating permissible value of prudential standards’.
  - BL Article 35 makes banks’ board accountable for maintaining capital adequacy; BL Article 38 obliges banks to comply with capital adequacy prudential standards and permissible values determined by the CBU.

### Capital Adequacy Requirements (Uzbekistan)
- Uzbekistan transitioned to Basel III and banks operate under:
  - credit risk standardized approach,
  - market risk standardized approach,
  - operational risk basic indicator approach (BIA).
- Capital Adequacy Requirements are higher than prescribed by the Basel Framework. Considering the Capital Conservation Buffer of 3 percent of RWA (subsumed into the total capital requirement), they are set at:
  - К1 = RC / TRWA – Regulatory Capital to Total Risk Weighted Assets is 13 percent
  - К2 = Tier I/TRWA – Tier 1 Capital to Total Risk Weighted Assets is 10 percent
  - К3 = CET 1/TRWA – CET 1 Capital to Total Risk Weighted Assets is 8 percent
- As at 1.1.24, the banking system CAR stood at 17.5 percent (versus a minimum requirement of 13 percent).

### Qualifying components of capital and assessors’ observations
- Regulation on Capital Adequacy Requirement for Commercial Banks No. 2693/2025 (RCAR) defines qualifying components (Chapter 3).
- Regulatory capital = Tier 1 + Tier 2; distribution of Tier I and II capital is equal, with each comprising 50% (until December 2022 Tier II was limited to 25 percent).
- Tier I capital consists of CET 1 and AT1.

- Common Equity Tier 1 (CET 1) includes:
  - fully paid ordinary shares or equivalent instruments when establishing a bank other than a joint-stock company, subject to listed criteria (perpetual, subordinated on liquidation, not guaranteed, etc.).
  - other CET 1 components fully compliant: (i) Share premium, (ii) Retained earnings (loss), (iii) minority interests.
  - banks can include in CET 1 a revaluation reserve developed from retained earnings to cover liabilities in cases of dramatic depreciation of the national currency.
- Assessors compared CET 1 features with Basel Framework para. 10.8 and found distribution features need modification: distributions should not be tied to amount paid at issuance; distributions must not be obligatory; no preferential distribution. CBU noted BL Article 13 covers the prohibition on issuer funding the instrument.

- Additional Tier I (AT1) includes:
  - fully paid non-cumulative perpetual preferred stock with specified characteristics (no redemption date, dividends discretionary, redemption only after CBU authorization and after at least than 10 years, etc.).
  - assessors found criteria need integration with Basel Framework para. 10.11, including explicit treatment of dividend/coupon discretion and prohibition on related-party purchases (not covered by BL Article 13).
  - other AT1 components: preferential share without credit-sensitive dividend feature, share premium over preferential shares, minority interests on Tier 1 instruments.
  - There are no AT1 instruments in circulation in Uzbekistan.

- Tier 2 includes:
  - net profit for the current year.
  - reserves created for standard loans in the amount of not more than 1.25 percent of the amount of risk weighted assets (RWA) after deductions.
  - obligations of mixed type (instruments with characteristics of equity and borrowed capital), up one third (1/3) of Tier I capital after deductions, if conditions met (fully paid, not collateralized, subordinated on liquidation, redeemable with CBU prior consent, cover reserves, do not give right to declare default; discretionary dividend/interest payment conditions specified).
  - assessors found RCAR requires only prior consent of the CBU for redemption of mixed-type obligations, whereas Basel Framework (para. 10.16 n. 5) permits calling instruments subject to replacement with same or better quality capital or demonstration that capital position remains well above minimum after call.
  - major deviation: subordinated debts can be included in Tier 2 capital even though they do not meet the write-off/conversion requirement (written off or conversion into CET 1 upon trigger event); CBU highlighted draft RCAR will envisage this condition. In Uzbekistan subordinated debt must be raised from legal entities (no physical person). They are about 1/3 of the Tier 2.
  - Tier 2 can include revaluation reserves capped at 45% of the difference between assessed value and original cost. Revaluation reserves are 0.4 percent of total capital.

- Regulatory adjustments: items deducted from CET 1 include:
  - intangible assets except bank’s software;
  - sum of all investments to non-consolidated group entities, including obligations which form capital of such entities (excluding investments made until December 1, 2023 to finance launch of renewable (energy-saving) energy sources);
  - investment in capital of other banks.

- Breach of minimum capital adequacy requirements triggers supervisory actions described under CP11, EC5.

### EC2 — internationally active banks and risk coverage
- There are no internationally active banks in Uzbekistan. There are 7 D-SIBs.
- Risk coverage: capital requirements cover credit, market, and operational risks.
- Operational risk: calculated under the basic indicator approach (15 percent of the average sum of gross income for last three years). CBU plans to move to the new standardized approach for operational risk but, given limited historical loss data (only one year available), plans to apply only the business indicator component (BIC), without the Internal Loss Multiplier (ILM).

- Method of calculation: RCAR Appendices I–V provide risk weight calculation methods. Assessors found two asset classes with slightly lower-than-expected risk weights (limited materiality):
  - Corporate bonds issued by mortgage refinancing companies (MRC) are risk weighted by 20 percent instead of 40, 75 or 150 percent depending on due diligence. One MRC exists in Uzbekistan; it is subject to prudential standards and supervision equivalent to banks and could be treated as exposure to financial institutions; as unrated, banks should apply the Standardized Credit Risk Assessment Approach (SCRA) and classify into 40, 75 or 150 percent bucket per Basel Framework para. 20.21 Table 7.
  - Exposures to Microfinance Institutions (MFI): risk weight reduced from 100 percent to 75 percent in 2023. CBU rationale: final borrower is a physical person or SME (similar to regulatory retail exposure). Assessors’ view: exposures to MFI could be treated as exposures to ‘other financial institutions’ (Basel Framework para. 20.40); as MFI are not subject to prudential standards and equivalent supervision, these exposures should be treated as exposures to corporates, attracting a RWA of 100 percent. At date of assessment banks’ exposure to MFI is not material.

*Source: 1uzbea2025004-source-pdf - 3. consider severe changes in market conditions, such as: lack of access to capital*

### 0.4 percent of total banks’ exposure.

### 0.4 percent of total banks’ exposure.

### Exposure to corporates
- With Board resolution 42/25 adopted in December 2023, loans to legal entities are risk weighted depending on the annual interest rate.
- RW varies from 100 percent to 200 percent.
- The Basel framework does not apply this criterion, because exposures to corporate risk are weighted based on the external rating.
- Since the minimum level of RW (100) in Uzbekistan is equal to the prudential treatment that the Basel framework envisages for exposure to unrated corporates (100), the assessors considered such an approach prudent.

### Residential real estate exposures
- The RCAR provides a risk weighted regime for residential real estate exposures that apparently is more conservative than that envisioned by the Basel Framework for ‘regulatory real estate exposures’.
- The prudent approach is justified by the risk associated with the local residential real estate market.
- The housing market in Uzbekistan is currently experiencing overvaluation, with housing prices on average 28 percent higher than the fundamental prices.
- Multiple social programs, some involving subsidies, make it challenging for the CBU to assess the default experience and credit losses associated with the exposures to the real estate market, as requested by the Basel Framework (para. 20.72).
- The CBU does not distinguish residential real estate exposures (i) that are NOT ‘materially dependent on cash flows generated by the property’ from those (ii) that are “materially dependent on cash flows generated by the property” (Basel Framework para. 20.70).

### Risk-weight regime differences (domestic vs Basel)
- In Uzbekistan the risk weight starts from 35 percent (instead of 20 percent) and could reach up to 150 percent (instead of 70 percent), depending not only on the LTV, but, from July 2024, also on the DSTI.

- Risk levels on loans to individuals for the purchase of a mortgage starting from July 1, 2024, in Uzbekistan (matrix reproduced from source):
  - DSTI < 60%
    - LTV <50%: 35%
    - 50% < LTV < 75%: 50%
    - 75% < LTV < 100%: 100%
    - 100% < LTV: 150%
  - 60% < DSTI or impossible to determine DSTI
    - LTV <50%: 50%
    - 50% < LTV < 75%: 100%
    - 75% < LTV < 100%: 150%
    - 100% < LTV: 150%

- Risk weights for regulatory residential real estate exposures that are not materially dependent on cash flows generated by the property (Basel Framework) differ from the domestic regime as noted above.

### LTV calculation, appraisal requirements, and gaps
- Banks calculate the LTV in accordance with Chapter 6 of the Regulation on the Conditions for Granting Mortgage Loans to Individuals No. 3269/2020.
- LTV is the ratio of the loan amount to the real estate collateral value, e.g. ‘the price of real estate formed based on market prices, including future losses, and assessed by an appraisal organization or determined in another manner not prohibited by law’.
- Collateral value should be updated every three years or when there are significant changes in the real estate market.
- The appraisal must be carried out in accordance with the procedure established by the ‘Law about evaluation of activities’. This Law:
  1. sets forth minimal requirements of independence for the evaluation organization, e.g. protecting it from interference by interested parties. It also requires a minimum number of appraisers with appropriate qualifications, the existence of the authorized fund, and an insurance policy (Art. 4).
  2. requires that the appraiser has a qualification certificate issued by an authorized body (Article 5) and prevent him/her from being founder/participant in more than one evaluation organization. It also identifies cases where the appraisal is not admissible due to conflict of interest between the client and the evaluation organization (Article 16).
  3. defines the market value as the most probable price in the conditions of competition in the open market, where the parties of the transaction act rationally and voluntarily in the direction of their interests, having all the necessary information (Article 7); and it requires, if a value different from the market value is determined, to specify the criteria for determining such a value and the reasons for rejecting the market value (Article 17).
  4. identifies the evaluation standards as the set of interrelated norms and rules, which determine concepts and principles of assessment; terms and definitions; requirements for value types; information requirements; assessment procedures; characteristics of the assessment methods; requirements for formalize the result (Article 9).
  5. Enunciates the rights of evaluation organizations (independent application of methods, use of the documents necessary for carrying out the evaluation, involve other evaluators and experts) and their obligations (compliance with legal requirements for assessment activities, ensure the confidentiality of information received from the customer, annual training courses (Article 14 and 15).
  6. provides for mandatory requirements of the contract of evaluation (Article 13) and the evaluation report (Article 17). The evaluation report should indicate the standards, the data used and their sources, and the limits of application of the obtained result. The value of the evaluation has the nature of a recommendation.

- Notwithstanding these requirements, the assessors could not find reference to the ‘prudent conservative evaluation criteria’ highlighted by the Basel framework, para. 20.72.

*Source: 1uzbea2025004-source-pdf - 0.4 percent of total banks’ exposure.*

### 20.75  letter  b),  e.g.  ‘to  ensure  that  the  value  of  the  property  is  appraised  in  a  prudently

### 1uzbea2025004-source-pdf - 20.75  letter  b),  e.g.  ‘to  ensure  that  the  value  of  the  property  is  appraised  in  a  prudently

### Valuation, collateral and residential real estate
- Valuations must exclude expectations on price increases and be adjusted for potential that current market price may be significantly above the value sustainable over the life of the loan.
- National supervisors should provide guidance setting out prudent valuation criteria where such guidance does not already exist under national law.
- Credible collateral valuations, including appraisals, are essential; deficiencies in valuations may call into question appraisal credibility and valuation report integrity.
- Banks’ use of third parties for valuation review does not diminish banks’ responsibility to comply with applicable laws and regulations.
- In light of an imbalance between high demand (stimulated by preferential mortgage loans, government subsidies, and migration driven by geopolitical tension) and constrained supply (Financial Stability Report 2023/1), banks should be recommended to request a revision of the evaluation from the appraiser when reports appear based upon deficiencies or omitted/incorrect information (for example, comparable properties not previously identified, property characteristics, or other information affecting conclusions).

### Car loans, DSTI, BNPL and collateral treatment
- From July 2024, RWA for car loans depends not only on LTV but also on DSTI.
- Doubts persist about reliability of DSTI because buy now pay later (BNPL) offered by dealers is underreported to the credit registry (see CP17).
- The collateral value of the vehicle is the price agreed upon in the collateral agreement.
- The CBU introduced a concentration limit in the car loan segment of 25 percent of the loan portfolio (see findings under Principle 17).
- An exemption in DSTI rules is granted up to 15 percent of the total number of all loans and microloans issued by the bank to individuals.

### Green supporting factor
- CBU phased out a green supporting factor that, until December 1, 2023, enabled banks to risk weight at 0 percent loans allocated to individuals and legal entities for launching renewable (energy-saving) energy sources (including large solar and wind power plants, solar panels, and small photoelectric plants).
- This practice was inconsistent with the Basel framework.

### Supervisor powers on capital and risks (EC3)
- Supervisor can impose a specific capital charge and/or limits on all material risk exposures, including risks not adequately transferred or mitigated through transactions (eg securitization).
- Both on-balance sheet and off-balance sheet risks are included in prescribed capital requirements.
- CBU has the “right to establish additional premiums to the values of liquidity and capital adequacy ratios for banks, banking groups and systemically important banks, to cover potential losses arising from maximum changes in risk factors” (Article 38 of the BL).
- RCAR (Chapter 2) mandates CBU to require banks to increase regulatory capital in cases of:
  - unsatisfactory financial situation that may lead to unsecured and unstable banking activity;
  - unsatisfactory forecasts of bank’s profits;
  - high level of banking risks and off-balance items.
- CBU may require banks to ensure a higher capital adequacy coefficient based on risks inherent in activities, economic conditions, and financial position (including, but not limited to, large amounts of NPLs, net losses, high asset growth, high interest rate risk, or risk-based activities RCAR Chapter 7, para. 39).
- Off-balance sheet items are included in capital requirements via credit conversion factor mechanism (RCAP Chapter 5) with values 100, 50 and 20 percent consistent with the Basel Framework.

### Capital framework: calibration, Pillar 2, buffers (EC4–EC7, ACs)
Findings
- Capital requirements are set at the same level for all banks; they do not yet reflect banks’ risk profile and systemic importance (no Pillar 2 methodology).
- Exception: a 2019 CBU board decision required an additional 100 basis points of capital to some banks identified as “high risk” based on a stress test; 10 banks are requested to hold a CAR of 14 percent.
- CBU has developed and tested a D-SIBs identification methodology but has not applied a systemic risk buffer to D-SIBs; there is a plan to implement a capital buffer for D-SIBs.
- Adequacy of provisioning, appropriateness of RWA calculation, quality of risk management and control are assessed by curators but not used to calibrate capital requirements to banks’ risk profile.
- Capital adequacy requirements are higher than the applicable Basel framework in some respects.
- The leverage ratio is set at 6% (double that of the Basel Framework). Its computation includes in the denominator “contingency accounts” (eg off-balance sheet items), generally converted through a 100 percent credit conversion factor, except:
  - derivatives measured by the “initial exposure method” used for capital adequacy purposes; and
  - any commitments unconditionally cancellable at any time by the bank without prior notice, which attract a credit conversion factor of 10%.

Additional criteria (AC)
- No internationally active banks in Uzbekistan.
- RRM requires consolidation reporting by the main bank of a banking group, but lack of consolidated supervision regulation means no requirement for adequate distribution of capital within different entities of a banking group according to allocation of risks.
- The only buffer in place is the CCB; D-SIBs buffer is not in place. Financial Stability Department is developing methodology for countercyclical capital buffer (CCyB).

Assessment of Principle 16
- Assessment: Materially Non-Compliant.
- Comments: Uzbekistan transitioned to Basel III and capital adequacy framework covers credit, market, and operational risks. Banks are required to observe higher capital requirements than the Basel Framework. However:
  - capital definition is not fully aligned with Basel III;
  - deviations in credit risk weighted assets exist (minor exposures);
  - no express requirement for a prudent evaluation of residential real estate (no expectations of price increase);
  - lack of Pillar 2 methodology;
  - no capital buffer for the 7 D-SIBs.

Principal findings (numerical and specific)
- 100 basis points additional capital imposed in 2019 on some banks; 10 banks requested to hold CAR of 14 percent.
- Leverage ratio set at 6%.
- The only buffer in place is CCB; D-SIB buffer not in place; 7 D-SIBs referenced as lacking buffer.

Recommendations (as stated)
- Adopt a Pillar 2 methodology to calibrate capital requirement to banks’ risk profile.
- Set a capital buffer for D-SIBs.
- Align the capital definition to the Basel Framework by tightening criteria for inclusion of common shares in CET1, subordinated debts in Tier II, in line with Basel Framework para. 10.8; 10.11; and 10.16 number 10.
- Align RWA calculation with the Basel Framework by:
  - (i) increasing RWAs for banks’ exposure to “Corporate bonds issued by mortgage refinancing companies” from 20 to 40, 75 or 150 percent, depending on the banks’ due diligence;
  - (ii) increasing to 100 percent the risk weight for banks’ exposure to MFIs;
  - (iii) distinguishing RWAs for residential real exposures that are NOT “materially dependent on cash flows generated by the property” from those that are “materially dependent on cash flows generated by the property” (Basel Framework para. 20.70);
  - (iv) introducing a requirement for “prudent conservative evaluation criteria” of residential real estate (e.g. no expectations on price increases).

### Internal assessments, ICAAP, stress testing and CCyB (EC5–EC6, EC14)
- RRM Chapter 6 introduces internal capital adequacy assessment procedures (Article 67-71) as an option for all banks; Articles empower CBU to require banks to adopt a forward-looking approach to capital management.
- CBU used its power to require banks to prepare ICAAP as an outcome of risk assessment, but it has not received ICAAP submissions yet.
- Banks conduct internal stress testing.
- ICAAP should be based on the bank’s strategy and enable continuous assessment of capital adequacy relative to risk profile.
- RRM requires Supervisory Board approval of the capital plan including:
  - description of capital planning process and tasks of structural units;
  - methods used by the bank to meet capital requirements;
  - all internal capital adequacy limits;
  - measures to be taken in case of unforeseen events, including capital increases and decreases.
- Considering recent entry into force of RRM provisions, concrete implementation of ICAAP has not started.
- Financial Stability Department monitors international experience with CCyB and sectoral CCyB (eg sectoral buffer for real estate).

### Credit risk framework and supervision (Principle 17)
Framework and requirements
- RRM, Section 2, Chapter 7, §1 Article 42 requires banks to implement a credit risk management system including:
  - established risk appetite for credit risk;
  - credit policy and credit risk management processes;
  - credit decision making process;
  - process of classifying asset quality and making provisions for potential losses on assets;
  - procedure for identifying and dealing with troubled assets;
  - credit risk stress testing procedure;
  - internal capital adequacy assessment procedures (if implemented);
  - credit risk reporting process.
- RAQP (Regulation on Assets Quality and Provisioning) No. 2696 (July 14, 2015) sets criteria for asset quality classification and reserve formation.
- Off-site analysis process (GRBS) comprises:
  - (i) gathering information to determine main sources of credit risk;
  - (ii) automatic rating based on indicators and thresholds (stock and flow NPL ratio, top 10 borrowers, credit growth);
  - (iii) supervisory assessment adjusting automated rating by assessing credit policy, underwriting rules, sub-portfolio composition, and sampling loan files.
- New “Minimum requirements for inspection in banks based on Guidelines for Risk-Based Banking Supervision” (August 2024) establishes forward-looking inspection elements including credit risk management processes, credit documentation, loan portfolio analysis, and borrowers’ creditworthiness assessment.

Key metrics, dates and thresholds (preserve exactly as in source)
- DSTI regime timeline and thresholds:
  - Until July 1st, 2024, DSTI limited to microloans at 50 percent;
  - from July 2024 the obligation extended to all loans to individuals and increased from 50 to 60 percent;
  - from January 1, 2025 it’s reduced again to 50 percent.
- The sum of interest payments and other charges (excluding principal repayments and penalties) on a loan or microloan issued to individuals by a bank should not exceed 0.3% per day of the outstanding principal balance.
- The sum of all payments, except the principal amount for a loan or microloan, including interest, brokerage fees, penalties (fines), and other liability measures should not exceed half of the loan amount per year.
- Banks should calculate DSTI using credit bureau data no more than 7 working days old.
- As of January 2024, 43 percent of mortgages are granted to a homeowner with unofficial income (60 percent as of October 2023).
- CBU estimate: on average, residential real estate prices are discrepant from fundamentals by 28 percent.
- CIAC database contains information on 15.4 million subjects (as of January 2024).
- In 2023 the number of credit history inquiries from CIAC reached 506.4 thousand.
- BNPL underreporting: according to CBU, 488 dealers are captured; two major providers (per KPMG analysis) account for approximately two-thirds of the total gross merchandise volume and are captured and provide information to credit bureaus.

Findings on underwriting and monitoring
- Some banks loosened underwriting standards in retail lending:
  - elevated share of mortgages to households without official income (43 percent Jan 2024; 60 percent Oct 2023);
  - DSTI may underestimate total indebtedness because BNPL is underreported;
  - car loans growth driven partly by speculative activities; concentration limit of 25 percent constrained banks’ risk appetite.
- An anomaly: RAQP par. 40 enables banks to provide additional credit funds on a current loan classified as “standard” without a thorough risk analysis.
- RRM does not require that transactions especially risky or not aligned with core business are approved by supervisory board or senior management (draft amendment under consultation to tie thresholds to regulatory capital is noted).

Supervisory oversight and board duties
- Curators receive banks’ credit risk policies annually and assess consistency with risk appetite.
- Banks’ Supervisory Board should approve risk management policy and credit policy per RRM.
- If credit risk approaches or breaches risk appetite limits, risk management unit must notify supervisory board, management board and risk committee within one day and propose corrective measures within five days.
- Evidence found in 2 out of 5 on-site inspection reports that banks failed to escalate breaches to supervisory board.
- Article 34 of BL requires Supervisory Board to supervise management board, including oversight of credit risk policy implementation.

Assessment of Principle 17
- Assessment: Largely Compliant.
- Findings (summary):
  - elevated share of mortgages to borrowers without official income (43 percent Jan 2024; 60 percent Oct 2023);
  - DSTI underestimation risk due to BNPL underreporting;
  - rapid car loan growth and speculative activity; concentration limit 25 percent;
  - RRM gap: no requirement for supervisory board/senior management approval of especially risky transactions;
  - RAQP para. 40 allows additional credit on “standard” loans without thorough risk analysis.
- Recommendations (as stated):
  - CBU should perform closer oversight of mortgage loans to further decrease share of mortgages to borrowers without official income and apply measures to banks not strictly monitoring adequate use.
  - CBU should ensure all BNPL providers (eg car dealers) report contracts to the credit bureau for proper DSTI assessment.
  - CBU should amend RAQP to require thorough risk analysis when providing additional credit funds on a loan classified as “standard” (Article 40).
  - CBU should amend RRM to require supervisory board or senior management approval for transactions especially risky or not aligned with the bank’s core business activities.

### Problem exposures, provisioning and reserves (Principle 18; EC1)
- Regulatory framework: BL, RRM and RAQP.
- RRM requires banks to implement credit risk management systems including classifying asset quality, making provisions, identifying and dealing with troubled assets, and risk management unit review of practices for identifying problem assets and provisioning.
- Classification of exposures includes off-balance items (unused credit lines, irrevocable commitments, trade finance, letters of credit, guarantees).
- RRM and RAQP set out processes and responsibilities for grading, monitoring, and timely identification of problem exposures.

*Source: Content unit from the IMF PDF 1uzbea2025004-source-pdf - 20.75 letter b), e.g. ‘to ensure that the value of the property is appraised in a prudently*

### Chapter 7, §1, par. 44);

### Chapter 7, §1, par. 44)

### RAQP scope and general rules
- RAQP expands the definition of ‘assets’ to off-balance sheet items in respect of which there is a credit risk (Article 1).
- Chapter 2 of the RAQP classifies banks’ assets (including also investments) into 5 categories: “standard”, “substandard”, “unsatisfactory”, “doubtful” and “loss”, with the last 3 categories being NPL.
- RAQP does not mention forborne exposures.
- Chapter 4 regulates ‘assets with revised terms’ (see EC9).
- RAQP tolerates that borrower has only one case of delay in repayment on the principal or interests for up to 30 days in the last 180 days (Chapter 2, par. 10).

### Asset classification criteria
- Standard
  - Assets for which there is no doubt about the timely repayment of debts.
  - For a legal entity (or an individual engaged in entrepreneurial activity): must be considered financially stable, have sufficient capital, a high level of profitability and sufficient cash inflow to meet all existing obligations, including its debt with the bank, have feasible strategic plans, the ability to compete in the market, produce good products and have a marketing plan for their products.
  - For an individual: must have a stable source of income and a sufficient level of income to pay for the loan and interest received from the bank, a good credit history, that fulfils the timely payments and other obligations for all previously received loans.
  - Collateral must be “well-secured”, notarized (if legislation provides) and registered; an entry on the rights of a commercial bank to the pledged property must be reflected in the collateral register. In case of non-payment of the loan, the bank has the right to freely and without restrictions foreclose on its collateral.
  - All documents submitted for security must be drawn up in accordance with the procedure established by law.
  - There should be no problems with the return of “standard” assets.

- Substandard
  - Borrower's financial condition is considered stable, but there are negative situations/trends that could raise doubts about repayment if not addressed.
  - At least one of the following factors is present:
    - doubts regarding the financial condition or control over collateral;
    - insufficient information in the credit documents or no documents about collateral;
    - over the past 180 days, several cases when payment on the principal and/or interest was past due up to 30 days;
    - past due debt on the principal and/or interest not exceeding 90 days for trusted assets (those allocated without collateral to borrowers with constant cash inflow, good reputation and credit history), and between 31 and 90 days for secured assets.

- Unsatisfactory
  - Classified as unsatisfactory if at least one of these factors:
    - the quality of the main sources of repayment are insufficient to pay the debt, necessitating identification of additional sources of repayment, including sale of pledged property and other fixed assets and extension of maturity;
    - the current financial position of the borrower or the projected inflow of his funds is not sufficient to repay the obligations;
    - insufficient level of the borrower's capital;
    - trends and forecasts regarding this industry are unstable;
    - the ratio of the bank's asset to the value of collateral exceeds the limit specified in the bank's internal documents (with the exception of trusted assets);
    - there is past due debt on the principal and/or interest, exceeding 91 days, but not more than 180 days (with the exception of debtors whose activities are seasonal).

- Doubtful
  - Along with characteristics of “unsatisfactory”, additional weaknesses make full return doubtful under existing conditions.
  - Assets with a high probability of losses, but with some positive factors, can be kept as doubtful and their classification as “loss” postponed until further clarification.
  - Assets are classified as doubtful in case of at least one of the following:
    - at least one of the criteria for unsatisfactory assets, plus other negative characteristics (lack of easily realizable collateral on the market or presence of unsecured assets or declaration of bankruptcy of the borrower);
    - possibility of partial repayment of the asset in the near future;
    - past due debt on the principal and (or) interest for a period, exceeding 181 days, but not more than 365 days.

- Loss
  - Classified as loss if they have not been returned, or there are factors or signs indicating they cannot be returned or have such a low value that it is impractical to continue accounting for them as part of the balance sheet.
  - Classification does not mean absolutely no liquidation value; banks should attempt to liquidate through sale of pledged property or take measures to ensure repayment.
  - Assets are classified as loss in case of one of the following:
    - assets recovered from the collateral have not been sold within one year from the date of acceptance into the balance sheet by the bank;
    - the real estate and other assets are unusable and not necessary for the implementation of banking activities (excluding real estate and other assets collected as collateral) or have not been sold or used within three years;
    - there is overdue debt on the principal and (or) interest for 366 days or more.

### Provisioning and reserves (EC2)
- Provisioning level (reserves) determined by Article 36 of the RAQP:
  - one percent when classified as "standard";
  - ten percent when classified as "substandard";
  - twenty-five percent when classified as "unsatisfactory";
  - fifty percent when classified as "doubtful";
  - one hundred percent when classified as "loss".
- Banks must form:
  - special reserves (RAQP Chapter 6, par. 36) to cover possible losses on assets classified as substandard, unsatisfactory, doubtful and loss; reserves should be formed separately for each asset in the same currency in which the asset is formed;
  - reserves for standard assets to cater for possible losses that might arise because of all or any specific type of bank’s activity; reserves must be formed in national currency before the end of each month.
- If factors indicate potential losses exceed established reserve norms, larger deductions should be made to the reserve (RAQP par. 37).

### IFRS 9 interaction and measurement differences
- The CBU has not issued a regulation to reconcile the prudential framework of assets classification with the accounting framework.
- Banks prepare financial statements using IFRS standards.
- Example comparators as of December 2023:
  - NPL ratio is 4.2 percent;
  - IFRS 9 Stage 3 loans stood at 7.8 percent.
- CBU explanation: most of the difference can be explained by the strict prudential write off rule, which requires banks to write off loans within three working days after they are classified as ‘loss’.
- Under IFRS 9, write off is connected to the lack of reasonable expectation of recovery (uncollectable loans IFRS 9, par. B 5.4.9) and banks have more discretion on timing.
- Treatment of the shortfall/excess of IFRS 9 Expected Credit Loss as compared to prudential reserves is uncertain in the absence of CBU clarification.

### Write-off rules and practices
- RAQP conservative write-off provisions:
  - An asset classified as ‘loss’ (365 days past due) should be reflected in off-balance sheet items within three working days and the corresponding special reserves should be reduced (RAQP Chapter 6, par, 38).
  - Transfer of loss and accrued interest from balance sheet to off-balance sheet does not cancel debts and interest; debt and interest should be reflected on off-balance sheet items for at least five years from the date of transfer (RAQP Chapter 8 par. 51).
  - Banks must send a letter of claim to the borrower or legal successor at least once a month about past due debt and provide an extract from off-balance sheet items; non-receipt of letters does not release borrower from obligations.
  - Internal audit and senior management must inform the Board in writing quarterly about measures taken to recover loss assets transferred to off-balance sheet items; Board puts measures on agenda of annual general meeting of shareholders.
  - If debt not paid within five years after transfer to off-balance sheet, or bank abandons asset, asset can be written off based on Board recommendation and decision at general meeting of shareholders.
- Effect on coverage ratios:
  - Conservative write off policy has reduced the coverage ratio (allowances to NPL) to 37 percent as of December 2023 (69 percent if written off loans and its associated provisions are considered).

### Supervisory governance and oversight (EC3, EC4, EC5)
- EC3: Supervisor requires bank’s board to approve and regularly review policies for classifying exposures, determining provisions and managing problem exposures and write-offs; board oversees management to ensure effective implementation.
  - Banks’ supervisory board responsible for ensuring effective implementation of the risk management system (RRM, Chapter 5, §2 par. 28).
  - RAQP Chapter 8, par. 49 assigns banks’ board and senior management full responsibility for ensuring continuous sufficient level of reserves.
  - GRBS collects banks’ credit policy during data gathering; CBU curators approve, submit, regularly check credit policies and control timely introduction of amendments.
  - Curators monitor creation of reserves and their trends via monthly supervisory report; onsite inspections verify board’s fulfillment and correctness of reserves.
  - On-site inspection reports show boards approve and regularly review policies, but variation exists among banks in implementation.

- EC4: Supervisor assesses adequacy of banks’ policies, processes, methodologies and organizational resources for establishing provisions and write-offs; ensures review and validation independent of risk-taking function.
  - CBU Inspection Department conducts regular inspections on asset quality, classification and adequacy of reserves; inspectors check internal procedures, sample individual loans, and assess alignment with realistic repayment and recovery expectations.
  - In two out of five inspections examined, assessors found evidence of reclassification of exposures and additional loan losses provisioning.
  - Concerns noted: sampling process not clear; inspection duration (22 business days) may not match inspection perimeter given hundreds of corporate exposures examined.
  - Inspection results submitted to Prudential Supervision Department and Banking Supervision Committee; outcomes discussed at CBU Board and banks instructed to develop action plans.
  - CBU assesses internal control system and pays particular attention to write-off rationale and decision-making.
  - Evidence found in one of four off-site risk assessments that the CBU challenged assignment of loan classification and reserve function to the Department of loan collection.
  - Regulation "On Requirements for Internal Audit in Commercial Banks" reg. No 3302/2021 requires Internal Audit Service to independently analyze and assess effectiveness of internal control, compliance with legislative acts, and timeliness of elimination of deficiencies.
  - Internal auditors check correctness of asset classification and prudential reporting; CBU assesses internal audit work including validation of provisioning methodology.

- EC5: Supervisor determines banks have adequate policies, processes and organizational resources for reviewing/classifying exposures, early identification of deteriorating exposures, ongoing oversight of problem exposures, and collecting past due obligations.
  - CBU assesses during offsite and onsite supervision that banks meet RRM requirements and pays special attention to systems for problem loans, debt collection processes and identification mechanisms for loans that may become problematic.
  - Results of these reviews submitted to Banking Supervision Committee; CBU controls implementation and assesses progress and effectiveness of measures.
  - Supervisory thresholds and signals:
    - When the share of non-performing assets exceeds ten percent of total assets, this may be a basis for CBU to determine executive management qualifications do not adhere to CBU requirements and consider Board oversight insufficient.
    - When non-income-generating assets exceed seventy percent of total assets this serves as an indicator of weakness of the bank’s credit policy; the assessors noted that this share (70 percent) is too high.
  - Banks should implement a process for managing non-performing assets (RRM Chapter 1).

*Chapter 7, §1, par. 44)*

### Chapter 5 Chapter 7, 5-§ par. 56) consisting of:

### Chapter 5 Chapter 7, 5-§ par. 56)

### Troubled asset management framework: scope and components
- Four core components identified:
  - 1) early identification of borrowers with a likelihood of financial difficulties;
  - 2) revision of the terms and conditions of the agreement concluded with the borrower;
  - 3) implementation of measures to terminate relations with the borrower in case of debt collection in judicial or out-of-court procedure;
  - 4) management of the recovered property.

### Governance and responsibilities
- Supervisory Board (RRM Chapter 8, 5-§, par. 57) should:
  - approve a policy for dealing with troubled assets;
  - quarterly examine the state of problem assets in the bank, analyze the causes and determine measures to reduce them;
  - define the responsibilities of the Management Board for dealing with problem assets and managing properties recovered from collateral.
- Management Board responsibilities include:
  - develop a policy for working with problem assets and submit it to the Supervisory Board for approval;
  - if necessary, approve the strategic plan for work with troubled assets;
  - quarterly report to the Supervisory Board on the status of troubled assets, the policy, and the implementation of the strategic plan;
  - decide on the management of troubled assets within the authority granted by the Supervisory Board;
  - revise the terms and conditions of the troubled asset;
  - decide on the management of foreclosed property within the authority given by the Supervisory Board;
  - define criteria for evaluating the performance of employees responsible for dealing with troubled assets and evaluate this process;
  - ensure the implementation of the necessary information systems for the management of troubled assets.

### Early identification and policy requirements (RRM Chapter 8, 5-§, par. 62)
- Banks should approve a troubled asset management policy covering:
  - classification of troubled assets;
  - procedure for early identification of troubled assets;
  - procedure for working with borrowers, criteria for transferring the loan to the structural unit specialized in working with troubled assets;
  - methods and tools to deal with problem assets, procedure for reviewing the terms of a problem asset, sale, write-off, foreclosure of collateral and recognition of the borrower as insolvent;
  - coordination procedure among structural subdivisions on work with problem assets, as well as interaction with organizations specialized in work with problem assets (if any);
  - lists and report on troubled assets;
  - procedure for assessing the efficiency of measures taken by the bank to manage problem assets.

### Specialized troubled-asset unit: structure, independence and functions (RRM Chapter 7, 5-§. par. 59 and 60)
- Structural and governance requirements:
  - separated from the structural units responsible for credit allocation and management;
  - accountable to a member of the management board who is not a member coordinating the activity of a business lines;
  - composed of a sufficient number of employees with adequate qualifications for the effective management of problem assets;
  - provided with the necessary software and hardware;
  - rewarded, if any, with incentives not dependent on the profitability indicators of bank’s loans (incentives may depend on the general financial conditions of the bank) to avoid conflict of interest and negative effect on independence and impartiality.
- Powers and operational tasks:
  - authority to request information from structural subdivisions;
  - an employee who participated in the decision to allocate an asset within a structural unit shall not participate in the management of this troubled asset;
  - conduct borrower assessment; develop proposals for revising terms and submit to management board for approval;
  - develop standardized solutions for managing problem assets and submit them for management board approval;
  - amend contracts under renegotiation or participate in new contract conclusion;
  - monitor borrower's compliance with renegotiated terms;
  - coordinate activities of bank's structural divisions in managing problem assets;
  - develop or participate in development of internal documents on problem asset management;
  - develop criteria for selecting organizations specialized in work with troubled assets, assess their efficiency and compliance with contract terms;
  - prepare reports on management of problem assets and submit them to the bank's management;
  - define terms and conditions for information systems needed to manage troubled assets.

### Strategic plan trigger, content and supervisory follow-up (RRM Chapter 8, 5-§, par. 63)
- Trigger:
  - If banks’ problem assets exceed five percent of total assets for the last 3 consecutive months, the bank should develop a strategic plan and establish specific goals and timelines for reducing problem assets.
- Strategic plan requirements:
  - (i) approved by the board for a minimum of one year;
  - (ii) delivered to the appropriate structural subdivisions of the bank;
  - (iii) submitted to the CBU within 15 days from the date of approval or amendment.
- Strategic plan must include:
  - reduction in the number of troubled assets and their size;
  - reduction in the amount of property recovered;
  - assessment of the bank's internal capabilities to reduce problem assets within the established timeframe;
  - assessment of external factors, including macroeconomic, legal, judicial and regulatory systems;
  - target volumes and ways to reduce problem assets in the loan portfolio segment;
  - measures taken based on the (segmented) loan portfolio.
- Supervisory enforcement:
  - Beyond the requirements set out in the strategic plans, the CBU may require these banks to stop lending until the NPL ratios goes below 5 percent.
  - Example: four state owned banks were prohibited from issuing new loans, in an amount exceeding the repaid loan, until the share of NPL is reduced below 5 percent.

### Debt collection stages and outcomes
- Collection process stages emphasized:
  - "Pre-collection" — clear criteria for early identification of borrowers with potential problems;
  - "Soft collection" — early intervention with borrowers showing signs of problems but willing to cooperate;
  - "Hard collection" — measures to restructure debt or terminate relations, using pre-trial collection methods like negotiations and written demands;
  - "Legal collection" — enforcement of debt through judicial procedures if prior methods fail.
- Outcomes and metrics:
  - Collections represent 20.3 percent of the total NPL reduction and reached UZS 24 trillion between 2020- H1 24.
  - CBU assesses that banks have set up the required workout units.

### Supervisory information access and reporting (EC6)
- Banks submit supervisory reporting on asset quality and provisioning on a monthly basis; the report includes collateral.
- RAQP requires prudential reports to reflect real asset quality (Chapter 1, Article 1, par. 2).
- CBU rights and practices:
  - right to request and verify reports and other documents, demand clarification (CBL Law Art. 61);
  - full access to information concerning classification of exposures, collateral and other risk mitigants, provisions and write-offs;
  - on-site inspections assess and verify reliability of classification, collateral and provisions.
- Information systems and documentation:
  - RRM Article 58 requires the board to ensure necessary information systems for the management of troubled assets;
  - troubled assets management unit should be provided with necessary software and hardware (RRM Article 60).

### Supervisory powers on classification and provisioning (EC7)
- CBU powers include requiring:
  - (a) revise policies, processes or methodologies for classification and provisioning;
  - (b) adjust classifications of exposures;
  - (c) increase levels of provisioning, reserves or capital;
  - (d) impose other remedial measures if necessary.
- Conditions for requiring more negative classification (RAQP Chapter 6, par. 41) include:
  - deterioration of the general condition of the loan portfolio of a bank;
  - change or lack of sufficient analysis and research on the issuance of loans;
  - actual losses incurred by a bank on loans issued in the same industry, sphere;
  - concentration of large assets;
  - unacceptable economic trends and conditions, in particular, a large concentration of borrowers in one or more industries or administrative-territorial unit;
  - other circumstances revealed from analysis of statements or inspections.
- CBU may require revision of reserves per RAQP and/or formation of additional reserves.

### Valuation of risk mitigants and collateral eligibility (EC8)
- For provisioning, CBU considers only the most liquid collateral eligible:
  1) pledge of government securities;
  2) foreign state governments and central banks’ guarantee or a pledge of securities issued by them with a risk level of 0 percent when calculating the bank's capital adequacy;
  3) multilateral development banks’ guarantee (World Bank, Asian Development Bank, Asian Infrastructure Investment Bank, European Bank for Reconstruction and Development, European Investment Bank, European Investment Fund, Islamic Development Bank and Development Banks of the Council of Europe);
  4) deposits or certificates of deposit in the creditor bank.
- Requirements for most liquid collateral:
  - securities, bank deposits, certificates of deposit must have a validity period not less than the maturity of the corresponding asset;
  - for deposits, (i) the bank must have the unconditional right to control these funds and dispose of them; (ii) the deposit must be kept in the appropriate account, and a condition must be established in the agreement on the possibility of disposing the deposit in the event of non-repayment or default by the borrower, as well as on the possibility of the borrower to voluntarily send this deposit to repay the asset secured by it; (iii) the bank must take necessary measures and establish control to prevent withdrawal of funds from the deposit before the asset repayment period.
- A haircut of 10 percent is prescribed on the most liquid collateral to cover currency mismatches between the assets and the guarantee.
- Other types of collateral (real estate, gold) are not eligible for provisioning purposes.

### Definitions, reclassifications and forbearance (EC9)
- Problem exposures:
  - RRM focuses on "troubled assets" (distressed assets) and does not formally define "problem exposures" but in practice these are treated synonymously (exposure where there is reason to believe that amounts due may not be collected per contractual terms).
- Non-performing exposures:
  - Non-performing assets include “unsatisfactory”, “doubtful” and “loss” assets, but do not expressly include defaulted exposures (no definition of default) nor credit impaired under applicable accounting (e.g., IFRS 9 Stage 3).
  - Poor practices noted: banks commonly report only under 90dpd; isolated practices include manual changes to classification and reporting only overdue amounts as non-performing.
- Reclassification to performing:
  - RAQP Chapter 2, par. 14, 17 and 20 allow reclassification to IV. standard or V. substandard when quality improves, but:
    - a minimum ‘cure period’ of at least three months is missing for general reclassification;
    - for ‘assets with revised terms’ a cure period exists: (i) ‘at least 3 consecutive repayments’ for unsatisfactory or doubtful; (ii) at least 6 months and not less than 10 percent of the principle for assets classified as loss.
- Forborne exposures:
  - RAQP does not define “forborne exposure” but defines “assets with revised terms”.
  - RAQP lacks definitions of bank’s ‘concession’ and borrower ‘financial difficulty’. The list of revised conditions is closed and omits some concessions (e.g., conversion of debt into equity, easing covenants).
  - RAQP Chapter 4 lists types of revised terms (lowering interest rate except some cases; reduction or partial cancellation of principal except reduction of unused part; refusal of part/all payments; deferral or extension of payment term; changing type of collateral except some cases; capitalization of interest; changing the borrower with application of one or more conditions).
  - At time of revision borrower should not have past due debts with all banks; credit quality must be “standard” or “substandard”; past due days under revised agreement for last 6 months should not exceed 60 days.
  - Certain changes do not count as revised terms (e.g., reduction in interest rate if after change not lower than +2 percentage points of the CBU key rate; changing currency/convert FX to local currency if interest rate not lower than +2 percentage points of CBU key rate; extending grace period up to 6 months under specified conditions).
  - Classification rules on repeated revisions:
    - first revision does not change previous classification in quality (asset cannot be classified in a better category);
    - second revision: quality must be one step lower than category before revision;
    - three or more revisions: quality is classified as "loss" and cannot be reclassified to a better category.

### Board reporting and internal controls (EC10–EC11)
- Banks Boards determine form, periodicity and volume of credit risk management reports including:
  - dynamics of restructured, troubled and written-off assets;
  - level and dynamics of provisions for potential losses;
  - status of work done on troubled assets.
- Internal Audit obligations:
  - provide information on status of problem assets, reserves and write-offs to management and Supervisory Board; quarterly reports on measures to work with bad assets.
- RAQP Chapter 3, par. 36.2 requires a special reserve to be formed separately for each asset in the same currency in which the asset is formed (individual item basis).

### System-wide monitoring: concentrations, NPL trends and provisioning (EC12 and assessment)
- CBU activities and data collection:
  - monthly analysis of risk concentration in banks' loan portfolios and system-wide; special attention to 50 largest borrowers.
  - Financial Stability Department conducts analysis on car loans and mortgages.
- Key statistics and trends:
  - coverage ratio (provisioning to NPL) at banks system level has dropped to 37 percent as of December 2023.
  - NPL ratio increased from 1.5 percent as of January 2020 to 6.2 percent in summer of 2021; declined to 4.2% as of October 2024.
  - IFRS 9 Stage 3 assets are equal to 7.8 percent as of December 2023, while NPL stands at 4.2 percent.
  - 79 percent of total NPLs as of August 2024 were corporate loans.
  - As of January 1, 2024, loans extended to 50 large borrowers constituted 24% (112 trillion UZS) of the loan portfolio of the banking system; within this, 70% (77 trillion UZS) were attributed to SOEs and 30% (35 trillion UZS) to private sector.
  - 77% of these loans (86 trillion UZS) were allocated in foreign currency.
  - Top 10 depositors represent about ¼ of the total deposit base; the Ministry of Finance and Economy represents 27 percent.
  - Geography: 46 percent of banks’ loans are disbursed to borrowers resident in Tashkent city.
  - Currency: 44 percent of loans are granted in foreign currency (majority in US $).
- CBU enforcement measures noted:
  - CBU Resolution n. 342/1 prevented four SOBs from issuing new loans in an amount exceeding repaid loans until NPL share reduced below 5 percent; may have accelerated write-offs by SOBs.
  - enforcement, from 2021 onwards, of accelerated write-off rule (three working days within classification of loan in loss category).
- Assessment conclusion (Principle 18): Materially Non-Compliant.
  - Key findings:
    - criteria for non-performing exposures are too narrow (excludes defaulted exposures and credit impaired under accounting);
    - no definition of forborne exposures; “assets with revised terms” not equivalent to forborne exposures; RAQP lacks concept of ‘financial difficulty’ and ‘concession’ and contains exceptions that obfuscate asset quality;
    - first revision of terms not affecting classification; reclassification processes lack minimum ‘cure period’.
  - Recommendations:
    - Expand the NPL definition in the RAQP to include defaulted borrowers and impaired credits (IFRS 9 Stage 3 assets).
    - Align the definition of ‘assets with revised terms’ to forborne exposures by introducing the concept of ‘financial difficulty’ and ‘concessions’.
    - Eliminate exceptions that obfuscate true asset quality (first revisions not impacting classification; extension of grace period up to 6 months; reduction of interest rate within certain band for loans in national currency).
    - Adopt a more defined, rigid approach for reclassification of assets from non-performing to performing (introduce a minimum ‘cure period’), and for movement between IFRS 9 Stage 2 and Stage 1.

### Concentration risk and large exposures (Principle 19): framework and supervisory practice
- Legal and regulatory basis:
  - Article 38 of the BL obliges banks to comply with prudential standards relating to maximum amount of risk per borrower or group, maximum size of large credit risks and investments, and concentration ratios by sector.
  - RRM requires credit policy to contain ‘requirements for credit concentration’ and credit risk reporting to include concentration information (RRM Chapter 3 par. 50; Chapter 7 par. 74).
  - Regulation on the Maximum Amount of Risk for one Borrower, a Group of Interconnected borrowers, including Person Related to the Bank No. 3283/2020 (RCRRP) sets large exposure limits and defines ‘group of related borrowers’.
- Scope and measurement:
  - Off-balance sheet commitments are included (unused credit lines, irrevocable commitments, other credit commitments, trade finance, letters of credit, guarantees); RCRRP includes derivatives and investments intended for sale.
  - Large exposure requirements are as stringent as Basel Framework for internationally active banks (noting there are no internationally active banks in Uzbekistan).
- Bank systems and supervisory assessment:
  - Banks must identify and document relationships between debtors and groups of connected counterparties, update at least annually (RCRRP, par. 14).
  - CBU checks IT infrastructure adequacy off-site and on-site; inspectors assess processes for identifying, monitoring, analyzing and controlling concentration risk.
  - Curators review banks’ policies and risk appetite annually and challenge concentrations where appropriate (examples: concentration on corporate lending at a state-owned bank; concentration on car loan segment at a private bank).
- Risk appetite and internal limits:
  - Risk appetite statement should indicate limits including:
    - largest share of loans in total assets;
    - maximum annual growth of loan portfolio volume;
    - maximum amount of risk per borrower, group of connected counterparties to tier 1 capital;
    - largest share of loan product types in total loan portfolio.
  - Notification and escalation: if credit risk approaches or breaches limits, risk management unit shall notify Supervisory Board, Management Board and Risk Management Committee within one day and propose corrective measures within five days.
- Supervisory reporting and monitoring:
  - Monthly supervisory reports include concentration by economic sectors and geography.
  - Nominative monthly report for each borrower/group of connected borrowers is required (RCRRP, par. 38).
  - CBU analyzes 50 largest borrowers and monitors top 10 depositors at bank and system level.
  - Measures to prevent concentration on car loans: limit of 25 percent of total loan portfolio for car loans; banks exceeding the limit prohibited from issuing new loans unless covered by repaid obligations on previously issued car loans; implementation monitored by monthly analysis.

*Source: https://www.imf.org/-/media/files/publications/cr/2025/english/1uzbea2025004-source-pdf.pdf*

### introduction of this requirement (2023), banks reduced the concentration of their

### introduction of this requirement (2023), banks reduced the concentration of their portfolio on car loans within the limit, expect from one bank which is currently under closer scrutiny by the CBU (given the high concentration on car loans, the bank is not adapting its business model to the new supervisory limit).

### Concentration risk — findings and supervisory action
- Banks’ direct and indirect exposure towards the sovereign, as estimated during the assessment, is UZS 102 BN, equal to 16.6 percent of total assets and 102 percent of total capital.
- Given the lack of a Pillar 2 framework, sovereign exposure risk is not incorporated in the banks’ risk assessment.
- The CBU introduced a 25 percent limit for the car loans segment; this provided the first positive result in curbing the growth of car loans, except for one bank under closer scrutiny for high concentration on car loans and not adapting its business model.
- Monthly supervisory reports on concentration risk include loan portfolio breakdowns (economic sectors, geographical distribution) and single-name exposures.
- The CBU analyzes the TOP-50 borrowers (about 1/4 of the banking system portfolio) and instructs banks to monitor their 20 largest borrowers (or groups of connected borrowers).
- Concentration monitoring includes:
  - products (e.g., 25 percent car loan limit);
  - top 50 borrowers;
  - geographical distribution (almost half of loans to borrowers resident in Tashkent city);
  - currencies (households cannot borrow in FX; legal entities must demonstrate income in the same currency they borrow in to naturally hedge FX exposure);
  - deposit concentration (top ten depositors equal to 17.3 percent).

- Finding: Bank exposures to the sovereign estimated at UZS 102 bn = 16.6 percent of total assets and 102 percent of total capital; not incorporated into risk assessment due to absence of Pillar 2 framework.
- Recommendation: The CBU should strictly monitor the sovereign-bank nexus, and incorporate stress test outcomes in the risk assessment.

### Large exposures and groups of connected counterparties (Principle 19 / EC5–EC6)
- Definition of "group of related counterparties" (RCRRP Chapter 2 para. 2-16) is based on control and/or economic dependence. Control criteria include, inter alia:
  - ownership or control of 20 percent or more of authorized capital;
  - same composition of participants or management bodies.
- Economic dependence criteria include, inter alia:
  - annual profit from transactions with the other party is 50% or more;
  - at least 50% of products of one party sold to the other and difficult to find another buyer;
  - more than 30% of borrower's obligations to the bank are repaid at the expense of another party;
  - borrower uses more than 30% of loan funds to finance the other party.
- Exemption: interconnectedness only via control by state administration bodies, Reconstruction and Development Fund of Uzbekistan, or international development banks, without economic relationship — not considered interconnected (consistent with Basel para. 30.32).
- Threshold for related studies: If risk for one borrower is 5 percent or more of first-tier capital, the bank should conduct related studies based on economic dependence.
- RCRRP enables CBU to exert reasoned judgment in applying the definition; between 2022 and 2023 the CBU applied this judgment in 5 cases and remapped corporate groups.
- Prudential limits (RCRRP):
  - a) maximum amount of risk for one borrower or group of interconnected borrowers ≤ 25% of bank's first-tier capital;
  - b) maximum amount of risk for unsecured credit and factoring services for one debtor or group ≤ 5% of bank's Tier 1 capital (except interbank operations, which are subject to sub a);
  - c) total amount of all large risks (each ≥ 10% of bank's Tier 1 capital) should not exceed 5 times bank's first-tier capital.
- RCRRP para. 22: excess amounts above prudential limits are deducted from Tier 1 capital starting from the reporting date; curator transmits violations to the Banking Supervision Committee which decides measures (warnings, fines) and requires remediation plans.
- Department of Prudential Supervision calculates maximum amount of risk for one borrower or group; CBU forms groups of interrelated borrowers when analyzing TOP-50 borrowers. Violations have led to rectification requests, fines, and warnings from on-site inspections.
- Assessment of Principle 19: Largely Compliant.

### Related parties (Principle 20) — definitions, limits, controls, and findings
- Legal definitions:
  - BL Article 24 defines ‘persons related to the bank’ (numbered elements 1–7 in BL).
  - RCRRP Article 17 defines ‘persons related to the bank’ (numbered elements 1–16).
  - The CBU may exercise discretion based on reasoned judgment; it has rarely done so.
- Scope: Prudential framework covers more than credit exposures; RCRRP addresses service contracts, asset purchases and sales via the concept of ‘more favorable terms’.
- Specific concerns:
  - Lending from SOCBs to SOEs is not considered a related party transaction and is not always on commercial terms; SOCB–SOE transactions should respect qualitative related-party requirements.
  - CBU should intensify supervision of SOCBs’ exposures to related parties, including SOEs.
- EC2 — prohibition of more favorable terms:
  - BL Article 44 prohibits transactions with related persons on more favorable terms than with unrelated persons.
  - RCRRP Article 24 clarifies examples of “more favorable conditions” (lower interest/fees, extended payment terms, mispricing, asset purchase at higher than market price, etc.).
  - The CBU can exert reasoned judgment and challenge “more favorable” terms; it has never done so.
- EC3 — board approval and conflict of interest:
  - BL Article 44: transactions with related persons require decision of the bank's supervisory board; if a party becomes related after contract signature, board must approve or terminate within thirty days.
  - RCRRP Article 27 prevents supervisory board members from participating in decisions where they are related parties; RCRRP Article 28–29 require full information in supervisory board decisions on related-party transactions.
  - Write-offs under more favorable conditions require supervisory board decision (RCRRP para. 26).
- EC4 — policies and processes to prevent conflicted persons participating:
  - RCG requires supervisory and management board members not to participate when conflict exists (para. 3), and to develop a conflicts-of-interest prevention policy (para. 34) including register requirements and periodic reporting (para. 35).
  - CBU oversight example: CBU challenged a bank for not maintaining the register of transactions with related parties.
- EC5 — limits, collateralization, deduction from capital:
  - Prudential limits:
    - maximum risk to one person related to the bank ≤ 25% of bank's Tier 1 capital;
    - maximum total risk to all persons related to the bank ≤ 50% of bank's Tier 1 capital.
  - Setting individual limits at 25% does not mitigate that the aggregate limit is 50%.
  - Deduction from capital: excess amount above prudential limits deducted from Tier 1 capital (RCRRP para. 22).
  - Collateralization: bank cannot issue loans without collateral to a related party (BL Article 44). RCRRP establishes minimum collateral requirement for credit to a person related to the bank or acting on their behalf (from 100 percent to 130 percent). If market value decreases, bank must restore compliance within 10 days.
  - Collateral eligibility is strict: only liquid assets (government guarantee/security) and cash (deposits in UZB sum/FX); haircut 30% for other securities.
- EC6 — identification, monitoring, independent review:
  - CBU reports it sent letters to banks about related-party violations; related parties fall under audit perimeter via credit risk.
  - The large exposures regime and related-party discipline are covered by same regulation and constrained by the same individual limit (25% Tier 1), but CBU states framework distinguishes terms, procedures, and limits for each category.
- EC7 — reporting and registers:
  - BL Article 44 obliges banks to maintain a separate register of transactions with related parties and notify the CBU before concluding transactions; notification contains borrower name but does not require CBU approval.
  - Banks submit monthly prudential reporting including related-party indicators; curators review and use public databases (www.orginfo.uz, www.stat.uz) to study potential relationships among borrowers.
- Assessment of Principle 20: Largely Compliant.
- Findings:
  - Lending by SOCBs to SOEs is not subject to qualitative related-party requirements (commercial terms, arm’s length).
  - CBU has discretion but has never exerted its reasoned judgments on related-party qualification or arm’s length principle.
  - RCRRP excludes “members of those committees not responsible for bank risk management” from the related-party definition — expression unclear and may open insider abuse opportunities in non-lending transactions (e.g., procurements).
- Recommendations:
  - Intensify supervision of SOBs exposures to related parties, including SOEs, requiring commercial terms and arm’s length transactions.
  - Exert reasoned judgment, as provided by the BL, when assessing related-party transactions (definition and market terms).
  - Amend RCRRP Article 17 to eliminate the exception “members of those committees not responsible for bank risk management” so these persons are also considered related parties (exceptions may be appropriate for transactions of a small amount).

### Country and transfer risk (Principle 21) — regulatory updates and supervisory practice
- Post-Ukraine war supervisory strengthening:
  - Government Working Group created February 2022, chaired by Prime Minister, with subgroups led by Deputy Prime Ministers assessing risks with Russia and Belarus.
  - CBU actions:
    - set up a Sanction Division within Financial Monitoring Department;
    - created analytical council (“compliance group”) with banks and CBU staff meeting weekly on sanction risks;
    - instructed banks to suspend cross-border transactions where participants are on US/EU block sanction lists;
    - tightened legal requirements for opening bank accounts by non-residents (expanded banks' right to refuse);
    - conducted stress testing on compliance risk;
    - developed risk matrices and rated sanction risk for clients and operations;
    - required banks to inform CBU about non-standard, complex, and economically unjustified cross-border transactions and payment schemes;
    - conducted daily monitoring of borrowed resources from Russian banks and instructed banks to reduce dependence on credit resources from Russian banks.
  - As of March 1, 2022, balances in correspondent accounts of Russian banks amounted to US $142.6 MN, of which US $87.3 MN were in banks that fell under sanction; at time of assessment these funds were recovered. There are still US$ 670 mn deposited by Uzbek banks in a Russian bank not under sanction.
- RRM (new Chapter 11, consultation/registered January 2025) defines country risk to include:
  - Transfer risk;
  - Sovereign risk;
  - Contagion risk.
- Country risk management requirements (RRM Chapter 11, article 124):
  - banks must introduce a country risk management system (board and management responsibilities);
  - Country risk policy and limits should be reviewed at least once a year or when concerns arise.
  - Policy should include organizational structure, identification/assessment/monitoring/control/mitigation/reporting requirements, report forms and periodicity, criteria for determining country risk, country and region limits, and description of cross-border operations.
- Operational requirements:
  - risk management unit to propose corrective measures within five working days when country risk increases significantly;
  - banks might conduct stress tests on country risk.
- Supervisory practice: CBU conducted intrusive monitoring of Uzbek banks’ exposures to Russian banks since 2022; daily monitoring for banks with major exposures.
- EC4 — provisioning:
  - RRM does not set fixed percentages or ranges of minimum provisioning per country.
  - CBU contends RAQP Article 21 (3) provides indirect provisioning via classification of assets placed in banks outside Uzbekistan based on ECAI ratings:
    - “standard” — investment grade rating from S&P, Fitch, Moody's or other ECAI recognized by Central Bank;
    - “substandard” — ratings below investment grade;
    - “loss” — overdue debts on principal and/or interest.
  - Assets classified as ‘substandard’ or ‘loss’ require provisioning of 10 percent and 100 percent respectively; however RAQP Article 21 (3) applies only to bank counterparties, not to all cross-border exposures or unrated counterparties.
- Finding: CBU does not properly ensure that country risk is sufficiently taken into account in determination of provisions.
- Recommendation: Introduce appropriate minimum provisioning per country risk considering prevailing conditions (in the form of fixed percentages or range for each country) or systematically assess adequacy of provisioning set aside by banks.
- Assessment of Principle 21: Compliant.
- Note: The CBU Board resolution (37/6) on amendments to the RRM, registered by Ministry of Justice (No. 3427-1), will come into force the 21st of April 2025; banks were given 3 months to adjust policies before amendments become binding.

### Market risk (Principle 22) — regulatory framework, supervision, and gaps
- RRM (April 2023) requirements:
  - Board must ensure a market risk management system that identifies, assesses, monitors, controls and reduces market risk (RRM Art 87).
  - An effective market risk management system should include: risk appetite, policies and procedures, tools for assessing and monitoring, market risk stress testing procedure, and reports on market risks.
  - Market risk defined to include:
    - interest rate risk in investment portfolio;
    - currency risk from FX fluctuations;
    - commodity risk for precious metals, stones, coins;
    - equity risk from changes in fair value of securities (RRM Article 89).
  - Requirement: Risk Department must notify supervisory board and management within one business day of a significant increase in market risk and propose corrective measures within five business days (RRM Article 91).
- January 2025 amendments to RRM:
  - introduced definition of trading book (art. 1);
  - expanded market risk to derivative instruments including derivatives with underlying shares (Article 89);
  - broadened risk appetite requirements to include:
    - maximum amount of value at risk (VaR) for all types of market risks (absolute and percentage of regulatory capital) with a high confidence level (at least 99 percent) over a 10-day period;
    - maximum amount of market risk in capital adequacy calculation (absolute and percentage of regulatory capital);
    - maximum amount of currency positions in the bank's major currencies.
- Supervision (GRBS methodology): market risk assessment stages — general information, sources of information, inherent market risk assessment — yielding an overall market risk management process rating.
- Monitoring:
  - CBU monitors compliance with minimum foreign exchange position requirements on a daily basis.
  - Six cases of violation of established FX limits identified in 2023; all discussed at Banking Supervision Committee.
- Market risk measurement and limits:
  - RRM requires Risk Management Information System to provide truthful, complete, flexible, and timely risk information (Reg. No3427, para. 40).
  - FX risk regulation (“Regulation on Open Foreign Exchange Positions”, registered May 7, 2021, No. 3301) sets limits:
    - The total amount of open foreign exchange positions / regulatory capital of the bank ≤ 15%;
    - The total amount of long foreign exchange positions / regulatory capital ≤ 15%;
    - The total amount of short foreign exchange positions / regulatory capital ≤ 15%;
    - The open position for each individual foreign currency / regulatory capital ≤ 10%.
  - Calculation includes FX derivative contingencies; data on FX derivative transactions subject to constant monitoring; information on derivatives other than FX is not collected and assessed.
- Controls and governance:
  - RRM prescribes three-lines-of-defense model and assigns responsibilities across first, second, third lines.
  - Head of risk department has veto power on management/committee decisions that violate risk appetite or limits (Reg. No3427, para. 35); must convene Supervisory Board or Risk Committee for urgent measures.
  - Supervisory Board responsible for approving risk limits and measures in event of breaches (RRM Article 28).
- Gaps and concerns:
  - Primary supervisory focus is on FX risks; other market risk categories (interest rate, commodity, equity, derivatives) are underestimated.
  - Lack of fair value reporting for derivatives other than FX: CBU collects OTC derivative notional amounts but not fair values — this limits supervisor’s assessment of market risk, e.g., the materiality of derivatives relative to total assets cannot be judged without fair value data.
  - RCAR incorporates market risk mainly via FX risk; interest rate, commodity prices, and credit spread risks are not yet taken into account in capital calculation.
- Capital buffer and losses:
  - Central Bank requires sufficient capital buffers to cover market risk; as of 2023, capital buffer for market risk amounted to 4 trillion soums.
  - Over the past two years there have been no losses on market risk.
- Assessment of Principle 22: (implicit within text) supervision and regulation expanded; main residual weaknesses relate to limited coverage of non-FX market risks, limited derivative fair-value data, and incomplete incorporation of market risk subcategories into capital calculations.

*Source: introduction of this requirement (2023), banks reduced the concentration of their portfolio on car loans within the limit, expect from one bank which is currently under closer scrutiny by the CBU (given the high concentration on car loans, the bank is not adapting its business model to the new supervisory limit).*

### 1. Collection of information for the qualitative analysis of market risk.

### 1. Collection of information for the qualitative analysis of market risk

### Assessment framework and process
- The assessment comprises three stages:
  - Collection of information for the qualitative analysis of market risk.
  - Automatic assessment of the qualitative parameters (survey-based, covering policies, processes and procedures, personnel, and internal control systems).
  - An oversight assessment covering broader aspects of risk management to make a final assessment.
- Results are ranked by levels: "Strong", "Compliant", "Weak" and "Non-compliant".
- The supervisory assessment evaluates risk management policy and internal control systems, including strategic planning, risk appetite, market risk limits, management procedures, and roles of participants.

### Assessment of Principle 22 (market risk) — summary
- Material compliance outcome: Materially Non Compliant
- Regulatory context and recent changes:
  - The CBU’s regulations require banks to maintain a market risk management system obliging them to: define risk appetite; establish risk management policies and procedures; describe methods for risk assessment and monitoring; conduct stress-tests; ensure effective management information system.
  - The revised version of the RRM corrected some deficiencies by:
    - introducing the definition of a trading book;
    - expanding market risk to derivative instruments;
    - broadening the risk appetite requirement for market risk.
  - These recent amendments will enter into force in April 2025.
- Observations on market exposures and data constraints:
  - As of January 1, 2024, banks' investments in securities amounted to 24.5 trillion soms, which corresponds to only 3.8% of the total assets of the banking system.
  - The CBU only collects data on the notional amount of OTC derivatives, which as of July 2024 (7.4 billion soums) was higher than the total net profit of the entire banking sector as per 2024 year-end (6.9 billion som).
  - The notional amount alone is reported as non‑immaterial, but proper evaluation of derivatives' materiality requires fair value, which is not collected.
- FX and derivatives monitoring:
  - Given high dollarization, currency risk is the main source of market risk; the CBU sets prudential limits on net open foreign exchange positions.
  - Banks use derivatives to hedge FX risk. The amendment to the RRM included derivatives in the market risk perimeter.
  - Even before amendments, FX derivatives were monitored by the CBU to assess compliance with prudential limits.
- Findings (Market risk / Derivatives):
  - Only recent amendments to the RRM, which will enter into force in April 2025, introduced the definition of trading book, expanded market risk to derivative instruments, and broadened the risk appetite requirements for market risk. The CBU has not yet implemented these amendments, particularly in relation to the new risk appetite requirements.
  - The CBU monitored FX derivatives for the purposes of assessing compliance with limits to net FX open position, but banks might use derivatives to hedge other risk (for example, IRRBB). This has not been reported and monitored.
  - Based on the information shared, supervisory reporting is limited to the notional amount of derivatives and does not incorporate the fair value, without which it is difficult for the CBU to assess the materiality of this market risk subcategory.
- Recommendations (Market risk / Derivatives):
  - Proceed with the supervisory implementation of the new market risk regulatory requirements.
  - Expand supervisory reporting and assessment of market risk to derivatives instruments hedging risk other than FX.
  - Collect also the fair value of OTC derivatives to better understand the materiality of this market risk subcategory.

### Principle 23 — Interest rate risk in the banking book (IRRBB)
- Principle statement (summary):
  - The supervisor determines that banks have adequate systems to identify, measure, evaluate, monitor, report and control or mitigate interest rate risk in the banking book on a timely basis. These systems consider the bank’s risk appetite, risk profile and market and macroeconomic conditions.
- Regulatory developments and definitions:
  - In the RRM (April 2023), IRRBB was described as part of market risk; there was no distinction between trading portfolio and banking book.
  - Amendments to the RRM (January 2025) define IRRBB as “the likelihood of incurring losses (damages) and/or failing to achieve planned income due to the impact of changes in market interest rates on the assets and liabilities in the banking.”
  - The January 2025 amendments:
    - define the banking book;
    - include IRRBB among the ‘significant risk’;
    - expand stress testing requirement to IRRBB (once a year);
    - expand general risk management requirements.
- Required IRRBB assessment methods (banks will be required by April 2025 to use at least one):
  - A method of quantitative assessment of changes in the economic value of a bank (EVE), which provides for the assessment of changes in the net value of cash flows on assets and liabilities of a bank.
  - A method for quantifying changes in net interest income (NII) in stress scenarios, including significant increases or decreases in interest rates.
- Required stress scenarios (to be covered by methods):
  - an increase in all interest rates;
  - a reduction in all interest rates;
  - an increase in long-term rates and decrease in short-term rates;
  - an increase in short-term rates and decrease in long-term rates;
  - a sharp increase in short-term rates;
  - a sharp decline in short-term rates.
- Other methodological requirements:
  - The methodology should include all bank operations subject to changes in interest rates and provide for a separate risk assessment for foreign currency transactions if their share exceeds 5% of total assets or liabilities.
  - Acceptable assumptions in valuation methods should be documented.
- Mortgage-specific regulation:
  - Regulation "On the Maximum Conditions for the Provision of Mortgage Loans to the Population" (No3269) requires banks to hedge interest rate risks arising from directing funds with a variable interest rate to mortgage loans with a fixed interest rate, and to consider differences between attracted resources and terms of mortgage loans, profitability of the mortgage portfolio and impact on regulated capital.
- Supervision practice and tools:
  - Under GRBS, the CBU applies two indicators for assessing IRRBB:
    - quantification of changes in the economic value of equity (EVE);
    - quantification of changes in net interest income (NII).
  - Since 2023, once a year the CBU assesses banks' exposure to interest rate risk (noted that this is not exactly IRRBB as defined in the newer RRM).
  - Banks’ risk strategy, risk appetite, risk level, risk management and risk control are evaluated during the risk assessment.
  - Banks provide information requested by curators on the risk management process; supervisors can review board reports and minutes and participate as observers in board discussions.
  - Banks' policies and strategies are reviewed and reconfirmed once a year, in the first quarter; approved or re-approved documents are forwarded to the bank curator.
- Gaps in supervisory data and assessment:
  - Banks are not required to provide supervision with results of their internal interest rate risk measurement systems, expressed in terms of the threat to both economic value and earnings, using standardized interest rate shocks on the banking book.
  - IRRBB until recently was not treated as a separate risk and the CBU did not assess the internal capital system of banks for IRRBB.
- Findings (IRRBB):
  - In the RRM issued in April 2023 (i) IRRBB was described as a sub-category of market risk, but not as an autonomous risk; (ii) trading book and banking book were not distinguished.
  - Although the amendments to the RRM (January 2025) consider IRRBB as an autonomous and significant risk, there is no evidence of sufficient implementation of supervision of IRRBB risk.
- Recommendations (IRRBB):
  - Require D-SIBs to calculate Economic Valuation of Equity (EVE) under the six scenarios prescribed by the BCBS.
  - Develop a challenger model to initiate supervisory dialogue with banks on their exposure to IRRBB.
  - Implement the Pillar 2 methodology on IRRBB.

### Principle 24 — Liquidity risk (selected points)
- Principle statement (summary):
  - The supervisor sets prudent and appropriate liquidity requirements, and determines that banks have strategies enabling prudent management of liquidity risk and compliance with liquidity requirements, considering the bank’s risk profile, market and macroeconomic conditions.
- Legal basis and definitions:
  - Article 38 of the BL requires banks and banking groups to comply with prudential requirements established by the CBU; the set of prudential requirements includes liquidity ratio.
  - The RRLM defines a bank's liquidity as the ability to finance the growth of a bank's assets and ensure that its obligations are met timely with no losses occurred.
- CBU liquidity requirements (as stated):
  - LCR ≥ 100% (in national and foreign currency);
  - NSFR ≥ 100% (in national and foreign currency);
  - Ratio of Highly Liquid Assets to total assets is 10%.

*IMF assessment excerpt from "1. Collection of information for the qualitative analysis of market risk."*

### 4. Instant Liquidity Ratio (Liquid Assets/Liabilities on Demand) ≥ 25%.

### 4. Instant Liquidity Ratio (Liquid Assets/Liabilities on Demand) ≥ 25%.

### Liquidity requirements and implementation timeline
- The LCR became effective from January 2016 through a phased-in approach:
  - from January 1, 2016 – 80%;
  - from January 1, 2017 – 90%;
  - from January 1, 2018 – 100%;
  - from January 1, 2019 – 100% in all currencies, in the national currency, in foreign currency (the sum of all foreign currencies).
- The Net Stable Funding Ratio (NSFR) became effective from January 2018 through a phased-in approach:
  - from January 1, 2018 – 100%;
  - from January 1, 2019 – 100% in all currencies, in national currency, in foreign currency (sum of all foreign currencies).
- CBU-calculated difference between LCR definitions:
  - LCR per Basel framework (internationally active banks) versus LCR calculated by the CBU: difference was 7 percentage points (177 versus 170 percent).
  - Adjustment to Basel framework could cause some banks to breach the local LCR in foreign currency due to very limited options for HQLA in foreign currencies in the market.

### Supervisory framework and calibration (EC2 — EC9)
- Liquidity requirements are set at the same level for all banks, due to the lack of a Pillar 2 methodology.
- CBU powers and practices:
  - Article 38 of the BL gives CBU power to impose liquidity ratios above the minimum, but CBU does not calibrate requirements to banks’ risk profiles.
  - CBU is gradually developing supervisory system: (i) introduce Pillar 1 requirements; (ii) plan to integrate ICAAP and ILAAP approaches.
- Liquidity management framework expectations (EC3–EC4):
  - RRM Chapter 8 requires banks to implement liquidity risk management systems including:
    - established risk appetite for liquidity risk;
    - liquidity risk management policies and processes;
    - liquidity risk assessment and monitoring tools;
    - procedure for intraday liquidity management;
    - stress testing of liquidity risk;
    - reporting on liquidity risk.
  - Quantitative elements of risk appetite must include:
    - minimum ratio of highly liquid assets in the bank's total assets;
    - thresholds for liquidity coverage ratio and net stable funding;
    - maximum permissible level of negative cumulative gap between cash inflows and outflows in terms of time intervals from 30 days to one year;
    - the largest amount of accumulation (concentration) of funds attributable to one largest depositor and (or) creditor and twenty largest depositors and (or) creditors, and related persons.
  - Intraday liquidity: Article 52-1 of the RRLMs requires the share of highly liquid assets of banks in total assets should not be less than 10 percent at the end of the business day (starting June 1, 2020).
  - Banks must implement a risk management information system (Article 40 of the RRM) ensuring truthfulness, completeness and timely reporting of risk information.
- Supervisory monitoring and assessments:
  - Curators monitor daily liquidity changes via HQLA dashboards.
  - CBU periodically assesses adequacy of banks' liquidity based on: LCR downward trends; growth/deterioration of loan portfolio; outflows on customer deposits; active borrowing in repo market; maturity gaps; currency imbalances; NSFR and other prudential liquidity ratios. Results submitted to senior management.
  - Detailed risk assessment carried out once a year in risk-based assessments; specific recommendations made per institution.
- Stress testing and contingency funding (EC5–EC7):
  - Article 51 RRLM: banks must conduct stress tests of liquidity at least once a quarter and develop contingency funding plans.
  - Requirements for high-quality unencumbered liquid assets (Article 4 RRLM):
    - Highly liquid assets should: have a low level of concentration and ease of selling in money or repo markets; be a proven reliable source of liquidity in any market conditions; not include liabilities of the financial institution or related persons; not be placed and not taken into account as collateral.
    - Ratio of highly liquid assets to total assets should be at least 10 percent.
  - Diversification: Article 28 RRLM requires a financial strategy to diversify resources and funding areas; paragraph 79 reg. No3427 requires liquidity policy to include diversification principles.
  - Contingency funding plans: reg. No3427 (reg. No3427, 04/18/2023) paragraph 21 requires emergency additional financing plan once a year with: detection procedure, sources and conditions, emergency resources, time to raise funds, decision-making procedures, reporting to CBU and boards. CBU assesses these plans once a year and incorporates into liquidity risk assessment.
  - Stress test findings: assessors found CBU liquidity stress test assumptions insufficiently conservative (deposit outflow assumed at just 2-3 percent; drawdown of credit line at only 1-2 percent).
- Foreign currency liquidity (EC8):
  - Daily open position limits and liquidity ratios (NSFR, LCR) apply in both local and foreign currencies.
  - RRM reg. No3427 paragraph 81 requires imbalance analysis by currency and time intervals.
  - CBU analyzes liquidity buffer sufficiency in different currencies daily; requests detailed reports if significant transfer to foreign currency is detected.
- Asset encumbrance (EC9):
  - Paragraph 38 RRLM: banks should monitor amount of liquid assets usable as collateral for secured funds from interbank market or CBU in stress.
  - Paragraph 48 RRLM: banks must determine share of securities not used to cover urgent liquidity needs (pledged securities/total securities portfolio).
  - Paragraph 84 reg. No3427 requires liquidity management procedures that assess liquidity of assets usable as collateral.

### Assessment of Principle 24 — Liquidity Risk (rating and findings)
- Assessment: Largely Compliant.
- Key findings:
  - Supervisors determine banks’ liquidity strategies, risk appetite, policies and processes during risk assessments, but liquidity requirements are not calibrated to banks’ risk profiles and systemic importance.
  - CBU liquidity stress testing uses scenarios and assumptions that are not adequately conservative (e.g., deposit outflow just 2-3 percent; drawdown of credit line only 1-2 percent).
- Recommendations:
  - Calibrate liquidity requirements to banks’ risk profile and systemic importance.
  - Strengthen liquidity risk stress testing by adopting more conservative assumptions in adverse scenarios.

### Operational risk and operational resilience (Principle 25) — summary of reforms, findings, and recommendations
- Regulatory changes:
  - Amendments to the RRM expand from operational risk to operational resilience: define operational resilience; require supervisory board review/approval of operational resilience approach; require senior management implementation; include business continuity and disaster recovery plans; require mapping of critical operations and interdependencies; provide change management requirements.
- RRM Chapter 10 requires an operational risk management system with:
  - bank's risk appetite for operational risk;
  - operational risk management policies and internal procedures;
  - tools for assessing and monitoring operational risks;
  - stress testing of operational risks;
  - operational resilience approach;
  - reporting on operational risks.
- Findings on implementation and supervisory practice:
  - The CBU revised regulations but implementation is at an infancy stage; operational resilience not yet incorporated into GRBS.
  - CBU has not started assessment of new operational resilience requirements; off-site GRBS questionnaire includes operational risk but not operational resilience.
  - CBU found weaknesses: lack of limits on operational risk in risk appetite; inadequate operational risk management function staffing and vacancies; lack of internal audit coverage on operational risk.
  - Banks have mapped critical operations in some cases (3 banks) and have business continuity plans, but CBU has not evidenced supervisory assessments of mapping or plans.
  - RIP (No. 3224/2020) requires information protection in automated banking systems, business continuity measures, backups, and restoration tests at least twice a year; however, RIP does not specify alternate site minimums (e.g., geographic distance) and fuel reserve requirement is at least one day.
  - Business continuity exercises are required by RRM amendments but CBU does not assess these tests.
  - ICT risk: RIP requires information security systems and an information security service; CBU assesses ICT risk in off-site/on-site work but evidence of IT inspections was limited. CBU intends technical assistance request on ICT risk to WB or IMF.
- Assessment of Principle 25: Materially Non-Compliant.
- Findings (Principle 25):
  - Operational resilience is neither incorporated into GRBS nor part of minimum inspection requirements.
  - No evidence CBU assessed banks’ mapping of critical operations, business continuity plans and testing, or third-party risk management.
  - CBU has not issued a regulation on outsourcing.
- Recommendations (Principle 25):
  - Update the GRBS with a chapter on operational resilience.
  - Assess banks’ operational resilience, including tolerance for disruption to critical operations, mapping of interconnectedness and interdependencies, incident management, business continuity plan testing, and third-party risk management.
  - Issue a regulation on outsourcing.

*Source: https://www.imf.org/-/media/files/publications/cr/2025/english/1uzbea2025004-source-pdf.pdf*

### Section  5  of  the  Annex  to  the  above  provision  contains  a  detailed  table  indicating  the

### Section 5 of the Annex — Internal Controls, AML/CFT Supervision, and Compliance Findings

### EC9 — Internal Audit, Compliance Function, Screening, and Training
- Supervisor determines banks have:
  - (a) requirements for internal audit and/or external experts to independently evaluate the relevant risk management policies, processes and controls. The supervisor has access to their reports;
  - (b) effective policies and processes to designate a compliance officer at the bank’s management level to manage the financial crimes compliance programme, and a dedicated officer to whom potential abuses of the bank’s financial services (including suspicious transactions) are reported;
  - (c) a compliance function with adequate powers, reporting independence, staff and other resources;
  - (d) adequate screening policies and processes to ensure high ethical and professional standards when hiring staff or when entering into an agency or outsourcing relationship;
  - (e) ongoing training programmes for their staff, including on CDD and methods to monitor and detect criminal and suspicious activities;
  - (f) policies and processes to report criminal activities by staff to competent authorities.

- Description and findings re EC9 — Internal Audit
  - According to the RIA, the Internal Audit service should be independent and responsible for assessing the effectiveness of the internal control, risk management and corporate governance system (see CP26, EC 4).
  - When assessing the risk management system, the internal audit assesses at least the following components:
    - the activities of the structural unit for risk management, including decisions made by this structural unit, as well as, based on the tasks and powers of the unit, the correctness of the organization of the risk management system (credit, liquidity risk, market, operational, compliance, etc.);
    - risk appetite of the bank and compliance of the bank's activities with risk appetite;
    - risk management, including providing information to the CBU, the supervisory board and the management board with information about major risks;
    - the correctness of the organization of the risk management system, including the definition, measurement, evaluation, management, timely action, and reporting processes;
    - integrity of information systems used within the framework of risk management, accuracy, reliability and completeness of these data.
  - Pursuant to RIA Article 19, the audit service should independently analyze and evaluate, among others, the effectiveness of internal control (including the fight against money laundering, terrorist financing and the financing of the proliferation of weapons of mass destruction, compliance control, etc.), risk management and corporate governance systems and their correct implementation, considering the bank's risk profile.
  - The Regulation "On the Procedure and Conditions for Admission to Banking Activities" (reg. No 3252, 30.06.2020) establishes specific criteria (fit and proper requirements) for compliance officer (see also CP26, EC3).
  - Decisions on the appointment and dismissal of the head and employees of the Internal Control Unit for AML, as well as the assessment of their performance and the amount of remuneration (salary, bonuses, etc.) are made exclusively by the supervisory board.
  - A person appointed to the position of the Head of Internal Control for AML shall:
    - know banking and financial legislation;
    - know international standards for combating money laundering, terrorist financing and the financing of proliferation of weapons of mass destruction;
    - have knowledge of the rules of accounting, as well as regularly undergo advanced training at specialized courses.

- Description and findings re EC9 — Internal Control for AML
  - Detailed descriptions of the requirements for organisation of internal control for AML/CFT in the bank are provided by the Rules on AML/CFT.
  - Chapter 2 of the Rules on AML/CFT requires the management or executive body of the bank to develop and adopt internal control rules, including requirements for the internal audit service of the bank to assess the effectiveness of internal control for AML/CFT purposes.
  - Internal control rules shall be executed by the bank considering the results of assessment of the degree of exposure of the bank's services to ML/TF risks, size, nature, and complexity of the bank.
  - Requirements for Internal Controls for AML stipulate that the bank shall appoint a person responsible for implementation and compliance with internal control regulations (the responsible employee) from among executives or other bank managers not below the level of head of the relevant structural unit, and identify employees or a unit whose competence includes AML/CFT issues (the AML/CFT unit).
  - The AML/CFT internal control organization program shall include description of division functions, interaction procedures with other divisions, branches, subsidiaries, functions and powers of the responsible employee, and interaction with management and executive bodies.
  - Powers vested in AML/CFT unit officers and employees include:
    - obtaining access to all bank premises, information systems, means of telecommunication, documents and files within the limits that allow carrying out their functions;
    - sending instructions to bank divisions regarding performance of operation with money and/or other property;
    - ensuring confidentiality of information received during performance of its functions;
    - ensuring safety of documents and files received from bank departments.
  - Article 21 of the Rules on AML/CFT: the purpose of the AML/CFT training and education program is to provide bank employees with knowledge and skills necessary for their compliance with AML/CFT legislation, internal control rules and other internal documents of the bank in the AML/CFT sphere.

### EC10 — Reporting Abuse of Bank Services and MIS
- Supervisor determines banks have clear policies and processes for staff to report abuse to local management and/or the dedicated officer, and adequate management information systems for timely information to boards, management and dedicated officers.
- Description and findings re EC10:
  - Article 6 of the Rules on AML/CFT requires banks to develop internal procedures on providing the Internal Control for AML with information on facts of violations of legislation related to AML/CFT.
  - Internal rules and/or amendments must be approved by the supervisory board.
  - Employees aware of violations (including ML, TF, CPF) must immediately inform these facts in writing to the head or staff of the Internal Control unit.
  - The procedure of interaction between staff (including head of internal control) must be described by internal documents.

### EC11 — Whistleblower Protection
- Laws provide that a member of staff who reports suspicious activity in good faith either internally or directly to the relevant authority cannot be held liable.
- Description and findings re EC11:
  - Article 41 of the RCG requires development and practice of an effective system for identifying unacceptable actions and reporting them.
  - The system must enable employees to notify the board of unacceptable and illegal activities while ensuring confidentiality and security.
  - Goals of the Whistleblowing System include:
    - encouragement for timely notification of possible unacceptable actions;
    - providing means (channels) for confidential and secure notification of unacceptable activities;
    - ensuring consistent and timely action on notifications of unacceptable conduct and informing notifiers of their rights;
    - ensuring that the Board appropriately monitors compliance with the rules governing the confidentiality of employee notifications of unacceptable conduct;
    - protection of the rights of the bank and its shareholders.

### EC12 — Domestic and Foreign Information Exchange for Supervisory Purposes
- Supervisor cooperates with relevant domestic and foreign financial sector authorities or exchanges information with them regarding suspected or actual criminal activities present in banks for supervisory purposes.
- Description and findings re EC12:
  - Collaboration includes:
    - meetings between CBU, FIU, and other relevant authorities to discuss specific issues to prevent money laundering;
    - regular meetings among the members of the Interdepartmental Commission;
    - prompt reporting to FIU of new typologies or unusual transactions disclosed by the CBU during on-site inspections;
    - an established cooperation and coordination forum – Compliance Academy – with representatives from banks, stock market and non-banks industries to enhance cooperation and coordination between CBU, dedicated authorities and market participants.
  - CBU has concluded agreements with supervisory authorities in of Kazakhstan, Georgia, Hungary, Russia (in total 26 MoUs and 8 Agreements are signed) on exchange of information to effectively perform functions in supervising subsidiaries and banking groups.
  - CBU cooperates with tax authorities in exchange of information related to suspicious transactions carried out by economic entities.
  - Assessors found domestic information-sharing approaches adequate; exchange of information with foreign supervisors might be strengthened in the AML/CFT field.
  - It was revealed that ‘curators’ do not participate in discussion on findings from AML/CFT on-site inspection (the discussion held among On-Site and Financial Monitoring departments).

### EC13 — In-house Expertise and Risk Guidance
- Supervisor has in-house resources with specialist expertise for addressing criminal activities detected in banks and regularly provides information on ML/TF/CPF risks to banks.
- Description and findings re EC13:
  - Article 7-1 of the Law on AML/CFT requires organizations providing financial transactions and bodies exercising monitoring and control over internal control compliance to systematically, at least once a year, analyze and identify possible risks connected to ML, TF and CPF; document results and take measures to reduce identified risks.
  - Results of risk assessments should be communicated to all bodies involved in combating ML/TF/CPF and organizations engaged in transactions with funds or other property.
  - FIU conducts efforts to counter laundering of illegally gained income and terrorism financing, and on prevention, revealing, suppression, disclosing and investigation of economic and financial offenses, including offering guidance to banks on emerging risks and typologies.
  - The Commission is obliged to ensure proper exchange of information in a timely manner.

### EC14 — Group-wide AML/CFT Programs and Information Sharing
- Supervisor determines banks have group-wide programs to address ML/TF/CPF, including policies and procedures for intra-group information sharing.
- Description and findings re EC14:
  - Clause 6-1 of the Rules on AML/CFT requires internal rules for a banking group to include:
    - rules and procedures to exchange necessary information and data to manage risks associated with the ML, TF and CPF and proper verification of clients;
    - ensuring compliance, internal control and internal audit functions at the group level;
    - protect the confidentiality and ensure proper use of data at a group level.
  - There is no properly organized consolidated supervision (see CP 12); accordingly, requirements for consolidated supervision in the field of AML/CFT are not implemented.

### Assessment of Principle 29 — Summary, Observations, and Recommendations
- Assessment of Principle 29: Largely Compliant
- Comments:
  - The CBU has adopted a comprehensive approach to implement existing legislation and regulations.
  - Cooperation and collaboration among authorities bring positive results and indicate AML/CFT risks are a national priority.
  - CBU has implemented a risk-based approach to supervision for banks and carries out off-site and on-site AML/CFT inspections.
  - Positive evaluation from EAG which found a strong level of supervision over financial institutions and that CBU takes a comprehensive approach to training supervised entities.
  - Observations for further improvement:
    - Results of AML/CFT inspections are discussed among onsite and financial monitoring staff; however, the curator does not participate in these discussions.
    - The on-site AML/CFT supervision team has been recently expanded to 8 people; however, as they are dedicated to financial market wide inspections, the available staff resources might be considered insufficient.
- Recommendations:
  - The CBU should continue to invest in its staffing and technology for AML/CFT supervision, including encouraging staff and managers to attain internationally recognized professional certificates.
  - The CBU should establish dedicated teams to cover significant and specialized risks such as those related to crypto asset activities or fraud. Currently, the team that supervises AML/CFT also handles other risks.

*Section 5 of the Annex — described in the provided content.*

### 6. Transfer of significant

### 6. Transfer of significant ownership

### Transfer of significant ownership (LC)
- The BL gives the CBU sufficient authority to approve or reject applications for major acquisitions and to impose prudential conditions on those acquisitions.
- The evaluation of the expected/foreseen bank’s business model after the transfer of control does not provide a detailed explanation of how the bank's activities will change after the mentioned transfer.

### Major acquisitions (LC)
- The CBU does not require ex-ante or ex-post notification of acquisitions up to 15 percent of the bank's total Tier 1 capital and collects only quantitative information through regular prudential reporting.
- The required information may not be sufficient to assess whether the acquisition poses undue risks to the bank or not.
- In the lack of prudential limits on consolidated level pertaining to major investments, the CBU might not be able to constrain acquisitions or investments made by entities (other than banks) belonging to the banking group which could nevertheless expose the bank to any undue risks or hinder effective supervision.

### Supervisory approach (LC)
- The Guideline for risk-based supervision is a milestone for the transition from compliance to a risk based-approach; however, the guideline does not incorporate climate-related financial risks while banks in Uzbekistan are vulnerable to physical and transition risk.
- In 2024, there were 13 changes in the automatic ratings during the assessment of banks’ risk profile (out of 14 banks examined) but the scrutiny of each upgrading and downgrading has not been as intense as required given that this is a new methodology.
- The CBU has not conducted a resolvability assessment of D-SIBs and has not issued a regulation on recovery plans (this has been weighted under CP11).

### Supervisory techniques and tools (MNC)
- The role of the curator is neither formalized in the Law nor in a binding public regulation.
- There is no cooling-off period before the curator can be hired by the bank that he/she supervises.
- The assessors did not find sufficient evidence of separate meetings held by the CBU with independent directors.
- A system enabling the CBU to systematically track open findings with banks (beyond the action plan) is lacking.
- There is no general duty by banks to notify the CBU in advance of any substantive changes in their activities, structure and overall condition, or as soon as they become aware of any material adverse developments.
- On-site inspections effectiveness can be improved: most inspections (80 percent) are conducted within the 30-day limit set by the internal regulation and this timeline may constrict the ability to conduct a thorough credit file review, considering the large number of corporate exposures examined.
- The offsite and on-site assessment of corporate governance is not systematically included in the report shared with the assessors (one out of four cases) and such risk profile is even not mentioned in the Resolution ‘Minimum Requirements for Inspection in Banks, based on the Risk-Based Supervisory Guidelines’ (August 2024).

### Supervisory reporting (MNC)
- The CBU collects prudential reports and statistical returns on solo basis, but not on consolidated basis.
- The CBU requests ad hoc information in an unstructured form, via emails or other less secure channels.
- Supervisory reporting relies on CBU Recommendations which are based on internal accounting policy, instead of accounting principles and rules that are widely accepted internationally.
- The CBU does not collect information that allows for the assessment of the materiality of climate-related financial risks.
- All banks, despite their size and business model, are obliged to provide the same data (and the same number of data points); the CBU has not shifted its approach on reporting to risk-based supervision leveraging on the principle of proportionality.
- The CBU does not have the power to request relevant information to any entities in the wider group, irrespective of their activities.

### Corrective and sanctioning powers of supervisors (LC)
- Cooperation and collaboration with relevant authorities (Deposit Guarantee Agency, the Ministry of Economy and Finance, the Financial Stability Board, the Central Securities Depository) in deciding when and how to effect the orderly resolution of a problem bank, is not in place until draft law "On Resolution and Liquidation of Banks" is approved and implemented.
- Article 67 of the CBL could lead to the violation of the ne bis in idem principle, that prohibits double punishment for the same offence.

### Consolidated supervision (MNC)
- Prudential requirements apply only on an individual bank level.
- The Strategy for Reforming the Banking system (2020-2025) identifies consolidated supervision as a priority area for regulatory and supervisory enhancement, but the CBU has not issued a regulation on consolidated supervision so far.
- The CBU does not assess how group-wide risks are managed and if entities in the wider group may jeopardize the safety and soundness of the bank and the banking system.
- The CBU is working on completing the mapping of the banking groups and has requested technical assistance on consolidated supervision.

### Home-host relationships (C)
- While the establishment of colleges is the responsibility of the home authority, the CBU, as host supervisor with shared interest in the effective supervisory oversight of the banking group, has not adequately engaged with the home supervisor to gain comprehensive information on the wider group risks or the parent company risks.

### Corporate governance (LC)
- The CBU recently strengthened the RCG; however, some shortcomings have not yet been addressed.
- There is no requirement for succession plans.
- The Risk Committee is not mandatory for D-SIBs.
- The off-site risk assessment of corporate governance has recently been introduced in the supervisory manual, but not fully tested in the pilot phase, based on the documents shared with the assessors.
- The new methodology for on-site inspection does not include corporate governance (the assessors take note that the draft amendment the methodology envisages such an extension).

### Risk management process (LC)
- The CBU has not issued a regulation to determine content, updating, and procedure for submitting recovery plans.
- The CBU has introduced ‘Requirements for internal capital adequacy assessment procedures’ (RRM Article 67-71) but they are optional for all banks, regardless of size and domestic systemic importance.
- No evidence that the CBU determines that (i) banks perform regular and independent validation and testing of the models; (ii) the banks’ boards and senior management understand the limitations and uncertainties relating to the output of the models and the risk inherent in their use.
- The revised RRM does not contain a requirement to publicly disclose the CRO removal.

### Capital adequacy (MNC)
- Capital requirements are not calibrated to banks’ risk profile and systemic importance.
- Although the CBU declared that it implemented Basel III, the capital definition deviates from the said framework. There are also deviations in the credit risk weighted assets, albeit for minor exposures.
- The capital does not give enough emphasis to those elements of capital permanently available to absorb losses on a going concern basis.
- Criteria for the inclusion of common shares in CET1 (see Basel Framework par. 10.8) do not include distribution features.
- Subordinated debts in the Tier II (see, Basel Framework par. 10.16 n. 10) do not meet the writing-off/conversion requirement.
- RWA calculation deviations from the Basel framework include:
  - Corporate bonds issued by mortgage refinancing companies are risk weighted by 20 percent, instead of 40, 75 or 150 percent, depending on the banks’ due diligence.
  - Banks’ exposure to MFIs are risk weighted at 75 percent; as MFIs are not subject to prudential standards and a level of supervision equivalent to that in place for banks, they should be treated as exposure to corporates and, since unrated, attract risk weights of 100 percent.
  - The CBU does not distinguish residential real exposures that are NOT ‘materially dependent on cash flows generated by the property’ from those that are “materially dependent on cash flows generated by the property (Basel Framework par. 20.70)”.
  - There is no express requirement for a ‘prudent conservative evaluation criteria’ for residential real estate (e.g. there should be no expectations on price increases).

### Credit risk (LC)
- Some banks were found to have loose underwriting standards in retail lending.
- Mortgages allocated to households without official income: 43 percent in January 2024, down from 60 percent in October 2023 (CBU thematic review).
- Residential real estate prices discrepancy estimated by the CBU at 28 percent on average.
- There are cases where microloans are used to repay the mortgage loan.
- Assessment of creditworthiness might underestimate the DSTI of obligors, since buy now pay later is underreported in the credit bureau.
- Car loans grew quickly, also due to some speculative activities in the secondary market; the recent concentration limit (25 percent of the loan portfolio) has constrained banks’ risk appetite.
- The RRM does not require that transactions that are especially risky or otherwise not aligned with the bank’s core business activities are approved by the supervisory board or the senior management.
- RAQP par. 40 enables banks to provide additional credit funds/resources on a current loan classified as ‘standard’ without a thorough risk analysis associated with possible losses.

### Problem assets, provisions, and reserves (MNC)
- The criteria for an exposure to be defined non-performing are too narrow.
- Non-performing exposures include “unsatisfactory’, ‘doubtful’ and ‘losses’ but they do not expressly include (i) defaulted exposures (there is no definition of default in the regulatory framework) and (ii) credit impaired under the applicable accounting framework (IFRS 9 Stage 3 assets are eqaul to 7.8 percent of total loan as at December 2023, while NPL stands at 4.2 percent).
- There is no definition of forborne exposures. ‘Assets with revised terms’ are not equivalent to forborne exposures because RAQP (i) neglects the concept of ‘financial difficulty’ of the borrowers and (ii) the list of ‘concessions’ is closed, instead of being flexible to capture all the ‘concessions’ that a bank might make to a borrower.
- The first revision of the terms of an asset does not change the previous classification in terms of quality.
- Some exceptions obfuscate the true extent of banks’ assets quality (examples: assets are not classified as ‘assets with revised terms’ in case of (a) reduction of interest rate on loans in national currency, when the interest rate, after the change, is not lower than 2 p.p. compared to the CBU key rate; (b) extension of the grace period up to 6 months).
- The process of reclassifying assets (other than those with revised terms) as performing is not stringent; a ‘cure period’ is missing.

### Concentration risk and large exposure limits (LC)
- Banks’ exposures to the sovereign as estimated during the assessment is UZS 102 BN, equal to 16.6 percent of total assets and 102 percent of total capital.
- Given the lack of a Pillar 2 framework, this risk is not incorporated in the banks’ risk assessment.

### Transactions with related parties (LC)
- Lending by SOBs to SOEs is not subject to the qualitative requirements in place for related party transactions, namely commercial terms and transactions on an arm’s length basis.
- Although the CBU has discretion regarding the qualification of related party and on the arm’s length principles, it has never exerted its ‘reasoned judgments’ on this topic.
- RCRRP excludes ‘members of those committees not responsible for bank risk management’. The expression is unclear and might open a window of opportunities for insiders’ abuse in transactions other than lending (for example, procurements).

### Country and transfer risks (C)
- The CBU does not properly ensure that country risk is sufficiently taken into account in the determination of provisions.

### Market risk (MNC)
- Recent amendments to the RRM, which will enter into force in April 2025, introduced the definition of trading book, expanded market risk to derivative instruments, and broadened the risk appetite requirements for market risk.
- The CBU has not yet implemented these amendments, particularly in relation to the new risk appetite requirements.
- The CBU monitored FX derivatives for the purposes of assessing compliance with limits to net FX open position, but banks might use derivatives to hedge other risk (for example, IRRBB). This has not been reported and monitored.
- Supervisory reporting is limited to the notional amount of derivatives and does not incorporate the fair value, making it difficult for the CBU to assess the materiality of this market risk subcategory.

### Interest rate risk in the banking book (MNC)
- In the RRM issued in April 2023, (i) IRRBB was described as a sub-category of market risk, but not as an autonomous risk; (ii) trading book and banking book were not distinguished.
- Amendments to the RRM (January 2025) consider IRRBB as an autonomous and material risk, but there is no evidence of sufficient implementation of supervision of IRRBB.

### Liquidity risk (LC)
- Supervisors determine banks’ liquidity management strategy, risk appetite, policies and processes during the risk assessment process but liquidity requirements are not calibrated to the bank’s risk profile and systemic importance.
- The LCR is not aligned with the Basel framework.
- The CBU liquidity stress testing is based on scenarios not adequately conservative (for example, the assumptions for deposit outflow was just 2-3 percent and the drawdown of credit line only 1-2 percent).

### Operational risk (MNC)
- Operational resilience is neither incorporated in the Guidelines for risk-based supervision, nor part of the minimum requirement for the inspection of banks.
- No evidence of assessment by the CBU of banks’ mapping process of critical operations and interdependencies, business continuity plans and their testing, and third-party risk management.
- The CBU has not issued a regulation on outsourcing.

### Internal control and audit (C)
- The RIA does not explicitly indicate that internal audit can or should review outsourced activities.

### Financial reporting and external audit (LC)
- The BL Article 75 requires an audit organization to ‘immediately inform the CBU about situations that lead to gross violations of the laws on banks and banking activities’; however, it excludes serious violations from the duty of communication.
- The CBU has not clarified the differences between banks’ financial statements prepared in accordance with IFRS and those prepared in accordance with CBU regulation 3337/2021, which places undue burden on banks.

### Disclosure and transparency (LC)
- Disclosure requirements do not include information related to (i) risk management strategies, (ii) risk exposures (for example, sovereign risk, climate risk).
- SOBs do not disclose their exposures to SOEs as part of related party transactions.

*Source: 1uzbea2025004-source-pdf - 6. Transfer of significant*

### 29. Abuse of financial services LC

### 29. Abuse of financial services LC

### Key findings
- The results of AML/CFT inspections are discussed among onsite and financial monitoring staff; however, the curator does not participate in these discussions.
- The on-site AML/CFT supervision team has been recently expanded to 8 people; however, as they are dedicated to financial market wide inspections, the available staff resources might be considered insufficient.

### Recommended actions (by Basel Core Principle)
- Principle 1
  - Subordinate the CBU’s responsibility in consumer protection and financial inclusion and development to its primary objective to ensure the safety and soundness of banks and the banking system.
  - Empower the CBU to review the activities of parent companies and of companies affiliated with parent companies to determine their impact on the safety and soundness of the bank.
- Principle 2
  - Take action to ensure that the CBU’s independence is not only enshrined in the Constitution and in the CBU Law, but also protected in substance, including by avoiding that the responsibility for the implementation of development programs might compromise its operational independence.
  - Amend Article 102 of the LNLA to streamline the process for the adoption of regulations setting prudential standards by the CBU, e.g. no need for agreement with the Chamber of Commerce and Industry.
  - Amend Article 110 of the LNLA to narrow the Ministry of Justice’s power to refuse the registration of the CBU Regulations.
  - Enhance the transparency of the appointment and removal process of CBU Board members by:
    - introducing in the CBU Law (Article 19 and 24) eligibility criteria (for example, sound reputation, honesty/integrity, and minimum years of professional experience) and, for the two independent members, also incompatibility criteria (for example, they should not be members of the Parliament or the Government), and
    - Amending Article 23 of the CBU Law and requiring that reasons for dismissal are publicly disclosed.
  - As the 2020-2025 banking sector strategy is coming to its expiration, take stock of what has been achieved, and redetermine and regularly communicate supervisory priorities publicly.
  - In case urgent action is needed (for example, classifying a borrower as a related party and preventing the bank from further lending), enable the CBU to adopt a “provisional motivated judgment,” giving the persons concerned the opportunity to be heard as soon as possible after taking its decision.
- Principle 3
  - Sign a cooperation agreement with NAPP (in a form acceptable to the parties), foreseeing regular meetings, agreeing on information that would be relevant to exchange on a regular basis, foreseeing the availability to exchange confidential information, and describing a channel for such information exchanges.
  - After the resolution authority is established, it is recommended to provide the principles for cooperation and prepare and implement the cooperation framework.
- Principle 4
  - Establish effective systems to monitor the use of the term ‘bank’ and derivation (including through digital platforms, social media, and advertisements) to avoid that the general public can be misled.
- Principle 5
  - Amend the CBU Regulation on ‘Procedure and Conditions of Authorisation of Banking Activities’ No. 3252 by enhancing requirements for the preparation of a business plan.
  - Strengthen the evaluation on business plan/business activities during the licensing by performing:
    - a detailed assessment of the performance;
    - a review regarding the complexity of the bank both from the organizational and business perspectives;
    - an evaluation of the sustainability of the business model;
    - an evaluation of the bank's forecasts for at least three years according to both baseline and stress scenarios;
    - an assessment of bank’s compliance with prudential requirements under the stress conditions;
    - a comparison with existing peers.
  - Prescribe that the criteria for evaluation of business plans for the process of issuing licenses are consistent with those applied in ongoing supervision.
- Principle 6
  - Strengthen the evaluation of the envisaged bank’s business model after the transfer of control occurs through criteria which are consistent with those applied in ongoing supervision.
- Principle 7
  - Implement a timely notification containing qualitative information about investments, and the bank’s ability to manage it.
  - Review major acquisitions or investments by other entities in the banking group to determine that these do not expose the bank to any undue risks or hinder effective supervision.
- Principle 8
  - Integrate climate-related financial risks in the risk-based supervisory approach by:
    - issuing guidelines for effective management of climate related financial risk by banks (BCBS, 2022);
    - conducting, or requiring banks to conduct, a climate risk sensitivity analysis; and
    - identifying outlier banks and adopting targeted measures (for example, more frequent reporting, periodic disclosure, transition plans) for those outliers.
  - Consider setting up a quality assurance unit to ensure that the adjustments to the automatic ratings made by the curators are subject to systematic horizontal scrutiny.
  - Conduct a resolvability assessment for D-SIBs.
- Principle 9
  - Formalize the role of the curator (do’s and don'ts) in a binding regulation and introduce a cooling off period before the curator could be hired by the banks that he/she supervises.
  - Enhance the off-site engagement with non-executive and independent board members.
  - Systematically track open findings in the bank’s institutional profile.
  - Require a mandatory notification requirement for all substantive changes in an institution’s activities, structure, and overall condition, or as soon as they become aware of any material adverse developments.
  - Amend Article 15 of the Regulation ‘On the procedure for inspections of banks and their branch’ and extend the inspection period to a more reasonable timeline (for example, 60-90 days).
  - Enhance the off-site and on-site supervision of corporate governance and amend the Resolution ‘Minimum Requirements for Inspections in Banks, based on the Risk-Based Supervision Guidelines’ (August 2024) to expand the scope of on-site supervision to banks’ corporate governance.
- Principle 10
  - The CBU should:
    - collect prudential reports and statistical returns also on consolidated basis;
    - improve the data quality, validity checks and data safety for the ad-hoc data transfers and structure ad-hoc data transfers with a secure channel;
    - reformulate its recommendation on supervisory reporting to be based on accounting principles and rules that are widely accepted internationally, instead of internal accounting policy;
    - collect information on banks’ exposure to climate-related financial risk; and
    - embed the proportionality principle in the supervisory reporting e.g.the implementation of the SupTech Project could help address the above finding.
  - The CBU should be enabled to request relevant information from any entities in the wider group, irrespective of their activities, when this information is material to the condition of the bank or to the assessment of the risks of the bank; or needed to support resolution planning.
- Principle 11
  - Once the draft law "On Resolution and Liquidation of Banks" is approved by the Parliament, put in place a robust cooperation and collaboration with relevant authorities (Deposit Guarantee Agency, the Ministry of Economy and Finance, the Financial Stability Board, the Central Securities Depository) in deciding when and how to effect the orderly resolution of a problem bank.
  - Reconsider the application of the CBL Article 67, to avoid violation of the ne bis in idem principle.
- Principle 12
  - Accelerate implementation of consolidated supervision with focus on these particular areas:
    - Definition and identification of banking groups (mapping, describing the perimeter of consolidation);
    - Development of consolidated reporting;
    - Prudential requirements should be set at the consolidated level;
    - Enhancing the internal supervisory manual and procedures (i.e. GRBS);
    - Enhancing coordination and information sharing;
    - Assessing how group-wide risks are managed and if entities in the wider group may jeopardize the safety and soundness of the bank and the banking system.
  - A clear deadline to implement the framework should be established.
- Principle 13
  - Consider formalizing a request to the home supervisor of biggest subsidiaries operating in Uzbekistan to be invited to the existing supervisory college.
- Principle 14
  - The RCG should consider requirements for the board to develop succession plans and a requirement for D-SiBs to mandatorily introduce(?) the Risk Committee.
  - The CBU should consider structurally embedding the corporate governance analysis in the offsite and onsite assessment of banks risk profile remuneration until the banks reimburse the public support.
- Principle 15
  - The CBU should:
    - Introduce a regulation for the preparation and submission by banks of recovery plans.
    - make mandatory for D-SIBs the ‘Requirements for internal capital adequacy assessment procedures’.
    - determine that (i) banks perform regular and independent validation and testing of the models; and (ii) the banks’ boards and senior management understand the limitations and uncertainties relating to the output of the models and the risk inherent in their use.
    - introduce the requirement to publicly disclose the CRO removal.
- Principle 16
  - Adopt a Pillar 2 methodology to calibrate capital requirements to banks’ risk profile.
  - Set a capital buffer for D-SIBs.
  - Align the capital definition to the Basel Framework by tightening the criteria for the inclusion of common shares in CET1, and subordinated debts in Tier II, in line with the Basel framework par. 10.8; 10.11; and 10.16 n. 10)
  - Align the RWA calculation with the Basel framework by:
    - (i) increasing RWAs for banks’ exposures to ‘Corporate bonds issued by mortgage refinancing companies’ from 20 to 40, 75 or 150 percent, depending on the banks’ due diligence;
    - (ii) increase to 100 percent risk weight assets for banks’ exposure to MFIs;
    - (iii) distinguishing RWAs for residential real exposures that are NOT ‘materially dependent on cash flows generated by the property’ from those that are ‘materially dependent on cash flows generated by the property’ (Basel Framework par. 20.70); and
    - (iv) introducing a requirement for ‘prudent conservative evaluation criteria’ of residential real estate (e.g. no expectations on price increases).
- Principle 17
  - CBU should perform a closer oversight of mortgage loans, aiming at a further decrease in the share of mortgages granted to borrowers without official income. It should also apply measures to those banks that do not strictly monitor the adequate use of those loans.
  - For a proper assessment of the DSTI, CBU should ensure that all buy now pay later providers (e.g., car dealers) report their contracts to the credit bureau.
  - CBU should amend RRM and require that banks transactions that are especially risky or otherwise not aligned with the bank’s core business activity are approved by the supervisory or the management board.
  - CBU should amend RAQP and require banks to carry out a thorough risk analysis associated with possible losses when providing additional credit funds/resources on a loan, even when it is classified as ‘standard’ (Article 40).
- Principle 18
  - Expand the NPL definition in the RAQP to include defaulted borrowers and impaired credits (IFRS 9 Stage 3 assets).
  - Align the definition of ‘assets with revised terms’ to forborne exposures, namely by introducing the concept of ‘financial difficulty’ and ‘concessions’.
  - Eliminate those exceptions that obfuscate the true extent of asests quality (first revisions of terms not impacting the classification, extension of the grace period up to 6 months, reduction of interest rate within a certain band for loans in national currency).
  - Adopt a more defined, rigid approach for the reclassification of assets from non-performing to performing (introduce a minimum ‘cure period’), and from IFRS 9 Stage 2 to Stage 1.
- Principle 19
  - The CBU should strictly monitor the sovereign-bank nexus, and stress test banks’ exposures to the sovereign, incorporate stress test outcomes in the risk assessment especially considering the lack of a Pillar 2 regime.
- Principle 20
  - Intensify supervision of SOB exposures to related parties, including SOEs, requiring the application of commercial terms and arm’s length transactions.
  - Exert reasoned judgment, as provided by the BL, when assessing related party transactions, either in terms of a definition or in relation to the market terms conditions.
  - Amend RCRRP Article 17 and eliminate the exception ‘members of those committees not responsible for bank risk management’ who should also be considered related parties (exceptions may be appropriate for transactions of a small amount).
- Principle 21
  - Introduce appropriate minimum provisioning per country risk considering prevailing conditions (in the form of fixed percentages or a range for each country) or systematically assess the adequacy of this provisioning set aside by banks.
- Principle 22
  - Proceed with the supervisory implementation of the new market risk regulatory requirements.
  - Expand supervisory reporting and assessment of market risk to derivatives instruments hedging risk other than FX.
  - Collect also the fair value of OTC derivatives to better understand the materiality of this market risk subcategory.
- Principle 23
  - Introduce the full set of requirements for IRRBB evaluation and mitigation.
  - Require D-SIBs to calculate EVE under the six scenarios prescribed by the BCBS.
  - Develop a challenger model to initiate a supervisory dialogue with banks on their exposure to IRRBB.
  - Implement the Pillar 2 methodology on IRRBB.
- Principle 24
  - Calibrate liquidity requirements to the banks’ risk profile and systemic importance.
  - Strengthen the liquidity risk stress-testing, by adopting more conservative assumption in the adverse scenarios.
- Principle 25
  - Update the Guideline for risk-based supervision, with a chapter on operational resilience.
  - Assess banks’ operational resilience, including tolerance for disruption to critical operations, mapping interconnectedness and interdependencies, incident management, business continuity plan testing, and third-party risk management.
  - Issue a regulation on outsourcing.
- Principle 26
  - Amend the RIA to introduce the duty of the Internal Audit to review outsourced activities.
- Principle 27
  - Amend Article 75 of the BL and include serious violations among those that external auditors should immediately communicate to the CBU.
  - The CBU should ensure that banks’ financial statements are prepared exclusively in accordance with accounting policies and practices that are widely accepted internationally.
- Principle 28
  - Amend RCG and require banks to disclose information related to (i) risk management strategies and (ii) risk exposures (for example, sovereign risk, climate risk).
  - Require SOBs to disclose their exposures to SOEs as part of related party transactions.
- Principle 29
  - The CBU should continue to invest in its staffing and technology for AML/CFT supervision, including encouraging staff and managers to attain internationally recognized professional certificates.
  - The CBU should establish dedicated teams to cover significant and specialized risks such as those related to crypto asset activities or fraud.

### Authorities’ response (CBU)
- The Central Bank of the Republic of Uzbekistan (CBU) welcomed the FSAP mission’s evaluation of the implementation of the Basel Core Principles for Effective Banking Supervision (BCP) and values the mission members’ professionalism and collaborative approach.
- The CBU stated the assessment provided invaluable insights, highlighted strengths and areas for enhancement, and affirmed commitment to translate recommendations into concrete measures to strengthen supervisory practices, reinforce financial stability, and support sustainable development of Uzbekistan’s banking system.
- The CBU views the FSAP as a significant milestone and validation of its efforts, noting progress in the legal framework, licensing regime, prudential regulatory framework, and the successful transition to risk-based supervision.
- The CBU noted that some weaknesses identified by the FSAP had been recognized earlier and were part of a reform pipeline initiated in 2019, including adoption of new versions of the Laws “On the Central Bank of the Republic of Uzbekistan” and “On Banks and Banking Activities”, a 2019 self-assessment against the BCP, and a comprehensive action plan.
- Since 2019, the CBU has revised its regulatory framework to align capital-adequacy and liquidity requirements with Basel III, strengthened corporate-governance, risk-management, and internal- and external-audit standards, and enhanced standards for large exposures, related-party transactions, asset classification, and provisioning. Risk-based supervision was introduced in 2023.
- The CBU noted that some areas remain pending (full implementation of Pillar 2 and Pillar 3 requirements, establishment of consolidated supervision, reinforcement of outsourcing standards) but are integral to the reform plan.
- Several key recommendations have already been implemented, including amendments to the Regulation “On requirements for the risk management system of banks and bank groups” (RRM), introducing new provisions addressing country risk and interest rate risk in the banking book (IRRBB), alongside strengthened frameworks for credit, operational and market risk management. The CBU is now working on their effective implementation.

*Republic of Uzbekistan — IMF Financial Sector Assessment Program (FSAP) chapter 29: Abuse of financial services LC*

### 46. To strengthen the regulatory capital definition in line with Basel framework, the CBU

### To strengthen the regulatory capital definition in line with Basel framework, the CBU

### Capital framework and risk weights
- RCAR amended to align inclusion requirements for AT1 instruments with Basel framework para. 10.11 to ensure their ability to absorb losses on a going concern basis.
- The previous 75 percent risk weight applied to banks’ exposures to microfinance institutions has been removed; for the calculation of risk-weighted assets a minimum of 100 percent risk weight is used.

### Corporate governance and supervision
- Corporate governance evaluations fully embedded within banks’ inspection framework.
- Integration reflected in the Minimum Requirements for Inspections Conducted Based on the Guidelines for Risk-Based Banking Supervision in Commercial Banks.
- On-site inspections explicitly include review of banks’ corporate governance arrangements to assess risk profile.

### Liquidity regulation
- RRLM amended to align LCR and NSFR requirements with Basel framework.
- Amendments include HQLA composition, 30-day inflow and outflow rates, and relevant RSF and ASF factors.

### Macroprudential policy enhancements
- New Regulation approved in April 2025 to allow application of borrower-based measures.
- Regulation encompasses requirements on DSTI ratio, LTV ratio and concentration limits on credit portfolio.
- DSTI calculations refined to include borrowers’ outstanding obligations to buy-now-pay-later services.

### Deposit insurance
- Law “On Guarantees for the Protection of Bank Deposits” adopted; entered into force on February 19, 2025.
- Law intended to improve deposit insurance system and align with core principles of the International Association of Deposit Insurers.

### Emerging risks, climate, operational resilience, and ICT
- Revised Basel Core Principles (updated in 2024) encompass new requirements on climate-related financial risks, operational resilience, and ICT risk; CBU has begun integrating these into supervisory and regulatory frameworks.
- CBU approved the Strategy for the Management and Supervision of Climate-Related Financial Risks with an action plan to embed climate risk management across its regulatory and supervisory framework.
- Operational-resilience requirements incorporated into RRM, mandating banks implement measures to prevent, respond to, and recover from operational disruptions.

### Supervisory reporting and data collection
- CBU contends BCP assessment understates progress in supervisory reporting, causing underestimation of grade on Core Principle 10.
- CBU collects consolidated financial reports on a quarterly basis including: balance sheet, profit and loss statement, cash flow, changes in equity statements, data on problem loans and other information.
- Same consolidated-reporting deficiency cited under Core Principle 12, resulting in a double penalty for a single shortfall (per CBU).
- Ad hoc reports submitted through secure IBM Lotus Notes platform accessible solely to registered Central Bank users.
- Redundant or repetitive fields are purged annually; volume of manually collected information is steadily decreasing.
- CBU is advancing implementation of SupTech to further strengthen supervisory reporting framework.

### Large-exposure regime
- CBU maintains large-exposure limits fully satisfy every essential criterion of Principle 19.
- RCRRP is entirely aligned with the Basel Framework’s Large Exposures requirements.
- Control relationships and economic interdependencies subject to oversight via regular on-site examinations and continuous off-site monitoring.

### Market-risk treatment and derivatives
- CBU accepts market-risk recommendation but indicates derivatives were previously covered under existing market-risk provisions even if not explicitly named.
- RRM revised to explicitly reference derivatives and define their treatment.
- Since January 2025, CBU collects detailed information on every derivative contract, enabling supervisors to request fair-value data for market-risk assessment.
- Banks required to record daily foreign-exchange gains and losses from derivative exposures in income statements.

### Remaining supervisory and regulatory priorities
- Areas for further development include:
  - further improving capital requirements, including introduction of CCyB and Pillar 2 add-ons;
  - full implementation of Pillar 3;
  - establishing a robust consolidated supervision regime;
  - refining asset classification and provisioning standards;
  - enhancing NPL resolution framework.

### Implementation roadmap and technical assistance
- A comprehensive Roadmap to support FSAP recommendations has been developed and is under interim discussion.
- Roadmap expected to be adopted by the CBU Board in the first half of 2025.
- Roadmap outlines legislative and regulatory reforms and further supervisory enhancements to be taken over the medium term.
- CBU expresses interest in follow-up technical assistance.

*Republic of Uzbekistan — Central Bank of Uzbekistan (CBU) statements as presented in the source material.*

---


_Source: https://www.imf.org/-/media/files/publications/cr/2025/english/1uzbea2025004-source-pdf.pdf_
