Your compliance officer hears that a firm in your sector has been told to expect an AML/CFT inspection and asks the obvious question: why them, and could we be next? Until this autumn the honest answer was "hard to say". Since 1 October 2026 there is a written method.
Short answer: the Department for Combating Economic Crimes under the Prosecutor General's Office (DCEC), which acts as Uzbekistan's financial intelligence unit (FIU), now scores every firm it supervises in an electronic system called "Risk analysis". Each firm gets up to 100 points on three scorecards. Firms in the low band (up to 61 points) are not inspected. Medium and high scores lead to preventive measures and inspections. The score itself cannot be the basis for a sanction, and the FIU may not ask you for documents to compute it.
Who is scored and where the data comes from
The DCEC's order No. 21 of 1 June 2026, registered as No. 3872 (lex.uz), applies to the organizations that carry out operations with funds or other property under art. 12 of the AML/CFT law: the reporting entities. The FIU scores only the organizations within its own supervisory competence. Analyzing and assessing anyone outside that competence is prohibited. The order does not list which sectors that covers. Under the AML/CFT law (art. 6), compliance with internal-control rules is monitored by the bodies that approved each sector's rules and also by the FIU, so check who approved the rules you follow.
The score is built from data the FIU already has or can get without touching your business:
- administrative data held by state bodies: licenses, permits and other documents;
- statistics and correlation analysis, including patterns seen in firms where violations were found before;
- complaints from companies and individuals;
- media, social networks and websites;
- results of control purchases;
- what you file yourself under AML/CFT law, including suspicious-transaction reports (STRs);
- information and requests from foreign authorities and international organizations;
- earlier studies of your compliance;
- data from other supervisory and law-enforcement bodies;
- other lawful sources, provided getting them does not affect your ordinary activity.
Two limits matter in practice. The FIU may not demand documents or information from you for the analysis. And the analysis may not suspend, obstruct or directly interfere with your activity.
How the score is built
The system holds three scorecards, each worth 100 points, and computes your risk level automatically and separately for each:
- organization of internal control (annex 1 to the Regulation);
- anti-money-laundering (annex 2);
- countering terrorism and proliferation financing (annex 3).
Each scorecard is a short list of main indicators, each with sub-indicators. One rule drives the arithmetic: if one or more sub-indicators are breached, the firm gets the main indicator's full points. There is no partial credit for getting most of an item right.
Scorecard 1: internal control (100 points)
| Main indicator | Points |
|---|---|
| No internal control service | 70 |
| Service not properly organized | 20 |
| Staff not trained | 5 |
| Late, incomplete or wrong answers to FIU requests | 5 |
Examples of sub-indicators:
- No internal control service: no officer appointed (also in branches); staff not registered in the FIU's information program; officer does not meet the legal requirements
- Service not properly organized: head of the service reports to lower management or is not independent; too few staff for the volume and risk; the FIU's information program not used regularly or at all
- Staff not trained: no qualification upgrading
Scorecard 2: anti-money-laundering (100 points)
| Main indicator | Points |
|---|---|
| Executing operations that should have been suspended | 80 |
| STR failures | 5 |
| Late, incomplete or wrong answers to FIU financial-analysis requests | 10 |
| Operations without the measures required for politically exposed persons or beneficial owners | 5 |
Examples of sub-indicators:
- Executing operations that should have been suspended: suspicious or high-risk operations run without CDD or enhanced CDD; breaching an order to suspend operations for up to 30 working days or to freeze funds; running operations your own rules say to suspend or refuse because identification or CDD was impossible
- STR failures: no STR on a suspicious operation; no report on a refused operation or returned funds; STRs filled in wrongly
- Late, incomplete or wrong answers to FIU financial-analysis requests: ordinary requests and requests under special control
Scorecard 3: terrorism and proliferation financing (100 points)
| Main indicator | Points |
|---|---|
| Executing operations that should have been suspended | 80 |
| Late, incomplete or wrong CFT information | 5 |
| Late action on FIU data for the high-risk client register or list changes | not stated (see note) |
| Failures in unfreezing and resuming operations | 5 |
| Unjustified suspensions without CDD | 5 |
Note on scorecard 3. The act prints no points for "late action on FIU data". The scorecard totals 100 and the other rows add up to 95, so the remainder is 5, but the act does not say so.
Examples of sub-indicators:
- Executing operations that should have been suspended: not freezing immediately for a listed person; cross-border operations without identifying the parties or screening them against the List; operations linked to high-risk territories without checking source and purpose; breaching a 30-working-day suspension order
- Late, incomplete or wrong CFT information: no report on permitted or frozen operations of listed persons; late answers to FIU requests; STRs filled in wrongly
- Late action on FIU data for the high-risk client register or list changes: data from the FIU's site or software not executed in time or not passed to branches; no reaction to changes in the terrorist list; slow execution of a suspension or freeze order where no harm followed
- Failures in unfreezing and resuming operations: listed person not told about the suspension or how to resume
- Unjustified suspensions without CDD: freezing operations unrelated to listed persons; not executing operations allowed to resume
The three risk levels
| Level | Points (as written in the Regulation) | What follows |
|---|---|---|
| High | 81 to 100 | preventive measures and inspections |
| Medium | 61 to 81 | preventive measures and inspections |
| Low | up to 61 | no inspections |
Two things in the text are not clean. The bands overlap at 81, which appears in both high and medium. And "up to 61" does not say whether exactly 61 is low or medium. We quote the bands as written; how the system resolves them is not stated in the act.
Read against the scorecards, the bands give a simple picture. A single 70- or 80-point item puts that scorecard in the medium band on its own. On scorecard 2 any second item then pushes it into high, and on scorecard 3 any second item with stated points does the same; on scorecard 1 only the 20-point item does, because 70 + 5 + 5 = 80 is still medium. This assumes each main indicator counts once: the tables say points are given "separately for each case" or "for each sub-indicator", and the act does not say how repeated breaches add up. Firms with only the small items (5, 10, 20 points) stay low on that scorecard. The act also speaks of the "overall points" of a firm but does not say how the three scorecards combine into one decision, so treat each one as able to put you on the list.
The analysis runs, as a rule, at least once a year. Inspections and preventive measures that follow may cover only AML/CFT/CPF compliance, nothing else. How often a high or a medium firm is inspected is not set in the order: it points to the general inspection rules (Presidential decree PF-184, the inspections regulation approved by resolution PQ-374, Cabinet resolutions 402 and 611).
What the score cannot do, and how to challenge it
The Regulation puts four limits on the system:
- No sanction from the score. Whatever the level, the risk score alone cannot be the basis for measures against your firm.
- No inspection from a faulty system. A system that does not meet the Cabinet's minimum requirements for risk-analysis systems (resolution 611) cannot be the basis for starting an inspection.
- No document requests for the scoring, and no interference with your work.
- No fishing outside the brief. Inspections that follow may only check AML/CFT/CPF compliance.
If you disagree with the result, you may complain to the higher body or to a court, under the general rules on appeals and courts. The order sets no deadline of its own for that. It also does not give you a right to see your score or be told of it, so you are likely to learn of it only when preventive measures or an inspection arrive.
How to keep your score low
The act gives you no way to see the score, but you can see the inputs. The heaviest items are the ones you control:
- Internal control exists on paper and in people. An officer appointed (and in branches), meeting the legal requirements, registered in the FIU's information program. Any gap here costs 70 points.
- Independence and headcount. The head of the service reports to the head of the firm, not to a lower manager, and has enough staff for your volume. Use the FIU's program regularly: not using it is a 20-point item.
- Suspensions and freezes are automatic. Listed-person matches freeze immediately and without notice; FIU suspension orders (up to 30 working days) are executed. These are the 80-point items on two scorecards.
- Screen every cross-border party against the List and check source and purpose for high-risk territories.
- Answer the FIU on time and in full. Late or wrong answers appear on all three scorecards.
- Train the team and keep the record: training is its own item.
Your STRs and answers to requests are themselves data sources for the score, so quality there pays twice.
What to do now
- Map your firm against the three tables above and mark every item where one sub-indicator could be breached.
- Check that your internal-control officer is registered in the FIU's information program and actually uses it.
- Test the freeze path: from a List match to a frozen account, how long does it take, and who acts if the officer is away?
- Set an internal deadline for FIU requests shorter than the one in the request.
- If an inspection notice arrives, check that it stays within AML/CFT/CPF scope; if you dispute the risk result, decide early between the higher body and the court.
Background on the whole regime is in our AML/CFT guide. A ready set of internal-control documents is the AML Policy Kit. Not sure where your firm stands? Talk to us.
Sources
- DCEC order No. 21 of 1 June 2026, reg. No. 3872, Regulation on the "Risk analysis" electronic system, in force 1 October 2026 (lex.uz). Quotations from the order are our translation of the Uzbek text.
- Law No. 660-II of 26 August 2004 on countering money laundering, terrorism financing and proliferation financing, art. 6 (lex.uz).
Where would your firm score?
We check AML/CFT programs of supervised firms against the FIU's risk-scoring criteria.
Book a call →