10/07/26
As of 1 July 2026, the new third-party risk management requirements of the National Bank of Ukraine (the NBU) have come into force.
Since 26 June 2026, entities can apply for a Financial Inclusion Bank licence.
The NBU has updated authorisation requirements for financial companies, pawnshops, and payment service providers.
The NBU has launched a public consultation on proposed changes regarding the disclosure of banking, payment, financial, and insurance secrecy.
The NBU has proposed amendments have been introduced concerning inspections and business reputation requirements for collection agencies.
For financial market participants, this is a clear signal that now is the time to assess which of these developments may require updates to internal documentation, governance model, authorisation processes, and compliance controls.
On 1 July 2026, comprehensive amendments to the NBU regulatory framework on third-party risk management came into force. The new requirements apply to:
banks and banking groups;
financial payment service providers;
insurers.
This represents a systemic update of approaches to managing risks associated with engaging external suppliers, contractors, agents, technology operators and other counterparties. The purpose of the amendments is to strengthen the operational resilience of the financial sector and ensure business continuity of institutions amid increasing risks arising from the involvement of third parties.
The NBU expressly emphasises that the use of third-party services may create additional risks, inter alia, to:
business continuity of the institution;
fulfilment of obligations to clients;
information protection and cybersecurity;
compliance with legal requirements;
financial resilience of the institution.
These amendments are important for all institutions that actively use outsourcing, agency models, external IT solutions, cloud services, processing, call centres, KYC/AML solutions or other critical services provided by third-party providers.
In practice, the NBU expects supervised institutions to:
conduct an inventory of third-party relationships;
identify critical suppliers / critical agreements / important functions;
review internal policies, procedures and governance model;
strengthen counterparty due diligence;
update the contractual framework;
integrate third-party risk into the risk management system, compliance, operational resilience, information security and business continuity plan;
prepare exit / supplier replacement scenarios in case of critical failures or non-compliance.
For many market participants, this will mean not only reviewing individual agreements, but also reconsidering the entire outsourcing model and the management of dependencies on external counterparties.
The NBU has adopted a package of amendments to a number of regulations, effectively launching the model of a financial inclusion bank (FIB) in Ukraine.
starting from 26 June 2026, applications may be submitted to the NBU for obtaining an FIB licence;
a model of a limited banking licence is provided for both newly established institutions and through the reissuance of an existing bank licence;
FIBs will be able to engage commercial agents to provide financial payment services;
specific requirements for strategy, business plan, risk management system and internal control have been introduced for such banks;
certain requirements applicable to newly established and specialised banks will not apply to FIBs.
This is not merely a new licensing category, but a separate regulatory model designed to operate where traditional banking infrastructure is economically or physically inaccessible — primarily in frontline, de-occupied and sparsely populated areas.
For the market, this may mean:
a new format for expanding banks’ presence;
the potential entry of new players into the basic financial services niche;
a separate segment for investors and groups ready to operate under an inclusive access-to-financial-services model.
Resolution of the NBU Board No. 69 dated 24 June 2026 updated the authorization requirements for financial service providers, as well as providers of financial payment services and limited payment services. The main part of the amendments entered into force on 26 June 2026.
the assessment of the financial/property standing of participants or shareholders of a financial company or pawnshop that made additional contributions to the charter capital of up to 1 percent has been clarified;
pawnshops licensed to conduct currency operations in terms of trading in currency valuables in cash must develop activity plans (business plans) for 2027–2029 and submit them to the NBU by 31 December 2026;
requirements have been expanded for an individual investor from whom a financial institution may raise funds on the terms of subordinated debt;
new indicators of impeccable business reputation have been added in connection with influence over sanctioned legal entities and companies resident in an aggressor state;
the procedure for changing the scope of a licence for the provision of financial services and its revocation has been clarified;
a limitation has been established on the performance of duties by a key person of an insurer, a financial payment service provider, or a united or significant credit union for no more than 6 consecutive months;
the authorization conditions have also been aligned with legislative changes concerning the development of financial inclusion.
These amendments should be viewed not as a technical update, but as additional requirements for the authorization and fit & proper regime. Particular attention should be paid to:
capital structure;
sources of funding;
development/update of activity plans for 2027–2029 for pawnshops authorised to conduct trading in currency valuables;
reputational screening of owners, managers and related persons;
workforce planning for temporary performance of duties by key persons.
On 26 June 2026, the NBU published for public discussion draft amendments to regulations governing the procedure for disclosing:
banking secrecy;
secrecy of a payment service provider;
financial service secrecy;
insurance secrecy.
to update the rules for disclosing banking secrecy in line with current legislation;
to unify the approaches to the NBU obtaining information containing legally protected secrecy from supervised entities;
to supplement the procedure for banks providing information on the term of a bank deposit and the type of account of legal entities, individuals and individual entrepreneurs in response to requests from state enforcement authorities and private enforcement officers;
to remove the clarification that such information is provided to the NBU only during inspection/on-site audits or as part of off-site supervision.
The draft may have a direct impact on:
internal policies on confidential information;
procedures for handling requests from state authorities;
approaches to interaction with the NBU within supervisory procedures.
Comments on the draft are accepted until 6 July 2026.
Also on 26 June 2026, the NBU launched a public discussion on draft amendments concerning:
the procedure for conducting inspection audits of collection companies;
requirements for the business reputation of qualifying shareholders and managers of such companies.
to harmonise administrative proceedings following inspection audits;
to align the business reputation requirements for individuals who are qualifying shareholders and managers with the general approaches applicable in financial services markets;
to update the business reputation requirements for legal entities that are qualifying shareholders, including taking into account facts of transactions on capital markets involving unfair issuance.
For collection companies and their investors, this means the need to review:
reputational questionnaires;
due diligence approaches;
internal documents for registration and supervisory procedures.
Comments and proposals on the draft are accepted until 10 July 2026.
Implementation of the new requirements requires comprehensive preparation — from structuring the business model and developing business plans to licensing procedures with the NBU. The PwC Ukraine team has extensive experience supporting financial institutions on various regulatory and licensing matters and engaging with the NBU, and is ready to support companies at every stage:
Stage |
PwC Service |
Licensing and authorization
|
Preparation of the full document package for obtaining a licence/authorisation, development of key documents (including business plans) in line with regulatory requirements, support in communication with the NBU, and approval of key persons under the fit & proper framework |
AML/CFT
|
Design and implementation of the financial monitoring system, customer risk rating, transaction monitoring |
| Corporate governance | Establishment of corporate governance, internal control and risk management systems, development of relevant internal policies |
| Tax and legal support | Structuring, tax planning, regulatory compliance |
| Technology consulting | Selection and implementation of IT systems for payment services, cybersecurity |
| Third-Party Risk Management / Outsourcing | Review of existing agreements with suppliers and outsourcing providers; development of third-party risk management policies and procedures; integration of the requirements into existing internal documentation; classification of critical functions and service providers; and conducting due diligence of counterparties |
Vadym Romaniuk
Senior Manager, Head of Banking and Finance practice, Attorneys Association "PwC Legal in Ukraine"
Tel: +380 44 354 04 04
Mykola Aleksandrov
Manager, Banking and Finance, Attorneys Association "PwC Legal in Ukraine"
Tel: +380 44 354 0404