Compliance with NBU Resolution No. 58: Audit of Authentication and Payment Data Protection

Compliance with NBU Resolution No. 58: Audit of Authentication and Payment Data Protection

Audit, gap analysis and consultancy on authentication and improved authentication in the payments market.

BDO in Ukraine provides audit, compliance assessment and advisory services to payment service providers regarding compliance with the requirements of NBU Board Resolution No. 58 dated 03 May 2023.


NBU Resolution No. 58 approves the Regulations on authentication and the application of improved authentication in the payments market. The document sets out requirements for payment service providers regarding user authentication, the application of improved authentication, the protection of the confidentiality and integrity of sensitive payment data, and electronic interaction between parties involved in payment transactions. 

Compliance with these requirements is essential for reducing the risk of fraud, safeguarding payment transactions, ensuring the security of remote channels and preparing for regulatory scrutiny by the National Bank of Ukraine. The requirements of the Regulations apply to payment service providers but do not apply to providers of limited payment services. 

NBU statistics illustrate the scale of risks facing the payment market. In the year Resolution No. 58 was adopted, 272 thousand unauthorised payment card transactions were recorded, resulting in losses of UAH 833 million. Of these incidents, 83% occurred online, while 80% of total losses were attributable to social engineering schemes, where customers themselves disclosed sensitive information, authentication codes, or other data that enabled fraudsters to gain access to their funds.

In the following year, despite a decline in the number of fraudulent transactions, total losses increased to UAH 1.1 billion (37%), with 93% of losses linked to online fraud.

Actual cyber incidents further demonstrate the scale of the threat. In one exposed phishing operation alone, more than 1,000 individuals were affected, with losses estimated at approximately UAH 160 million. 


NBU data on payment fraud: 272 thousand unauthorised transactions, UAH 833 million in losses, losses rising to UAH 1.1 billion, and UAH 160 million linked to one exposed phishing operation


These figures highlight why robust authentication measures, payment data protection, compromised-factor controls, and fraud monitoring are critical components of risk management for payment service providers.

BDO in Ukraine assists companies in assessing their current status regarding authentication, improved authentication, payment data protection, transaction monitoring and internal controls, as well as in preparing a practical action plan to ensure compliance with the NBU’s requirements.

Who needs this service

This service will be useful to organisations that provide payment services or support technological, operational or information processes related to payment transactions.

In particular, it is relevant for:

  • banks 
  • non-bank payment service providers 
  • financial institutions providing payment services 
  • payment institutions 
  • payment service operators 
  • issuers of payment instruments 
  • acquirers 
  • processing centres 
  • companies providing remote service channels 
  • organisations handling sensitive payment data. 


Resolution No. 58 is particularly important for companies that provide payment services via remote channels, use mobile or web applications, process payment instructions, and employ OTP, biometrics, electronic signatures, cryptographic means, behavioural analytics or other authentication mechanisms.


What is included in the service from BDO in Ukraine

  • Analysis of the applicability of the NBU Resolution No. 58

We support you in determining which requirements of Resolution No. 58 apply to your company, payment services, user interaction channels, IT solutions, payment transactions and internal procedures.

  • Assessment of user authentication for payment services

BDO analyses how a company identifies and authenticates users of payment services or authorised representatives of corporate users during electronic interactions. The Regulation stipulates that such electronic interactions may only take place following the authentication of the user or authorised representative. 

  • Assessment of improved authentication

We verify whether the improved authentication procedure complies with the NBU’s requirements. According to the Regulation, improved authentication involves the use of two or more elements from different categories: knowledge, possession and inherence, in particular biometric or other unique characteristics of the user.

  • Assessment of the protection of sensitive payment data

BDO assesses how the company safeguards the confidentiality, integrity, availability and traceability of sensitive payment data. Such data includes, in particular, individual account details, cryptographic keys, access passwords, transaction codes and other information that could be used to carry out unauthorised or fraudulent activities. 

  • Assessment of transaction monitoring and fraud risks

We analyse the mechanisms for monitoring payment transactions to detect unauthorised or fraudulent activities. The regulation stipulates that such mechanisms must be based on an analysis of transactions, considering user behaviour and risk factors, including compromised authentication credentials, transaction amounts, fraud scenarios, signs of malicious software, and atypical use of the device or software. 

  • Audit of payment transaction security measures

BDO reviews the documentation, assessment and testing of security measures designed to protect payment transactions. Resolution No. 58 stipulates that a payment service provider should document security measures and assess their compliance with the NBU’s requirements regarding data protection, cyber security and information security when providing payment services. 

  • Gap analysis and compliance roadmap

Based on the results of the assessment, we identify gaps between the company’s current status and the requirements of Resolution No. 58, and draw up a list of non-compliances, risks and practical recommendations for addressing them.


Key audit areas 

As part of this service, BDO in Ukraine can assess:

  • applicability of the requirements of the NBU Resolution No. 58 to the company’s operations
  • user authentication procedures for payment services 
  • application of improved authentication 
  • use of authentication factors: knowledge, possession, inherent characteristics 
  • generation and verification of an authentication code 
  • protection of sensitive payment data 
  • security of remote channels 
  • monitoring of transactions and fraud scenarios 
  • control of compromised authentication factors 
  • malware risk management 
  • monitoring of atypical or anomalous device usage 
  • locking and unlocking authentication procedures 
  • documentation of security measures 
  • internal policies, procedures and regulations 
  • readiness to provide the NBU with a report on the compliance and completeness of security measures. 


Results of the compliance audit against the NBU Resolution No. 58

Following the collaboration, the client receives a structured assessment of compliance with the requirements of Resolution No. 58 and a practical action plan to address any identified gaps.

The client receives:

  • analysis of the applicability of the requirements of the NBU Resolution No. 58 
  • assessment of current authentication procedures 
  • assessment of improved authentication 
  • analysis of the protection of sensitive payment data 
  • assessment of transaction monitoring and fraud risks 
  • review of payment transaction security measures 
  • gap analysis of processes, controls and documentation 
  • list of inconsistencies and areas for improvement 
  • practical recommendations for addressing gaps 
  • roadmap for bringing processes into compliance 
  • support in preparing a report on the compliance and completeness of security measures. 


The Regulation stipulates that the outcome of the audit is an assessment and a report on the compliance and completeness of the security measures implemented by the payment service provider, and that such a report should be submitted to the regulator upon request by the NBU. 


Consulting on internal documentation

BDO in Ukraine can assist with the preparation, updating or improvement of the internal documents required to comply with the provisions of the NBU Resolution No. 58.

We can assist with the development or review of:

  • user authentication policies 
  • improved authentication procedures 
  • rules for the protection of sensitive payment data 
  • procedures for monitoring payment transactions 
  • fraud detection scenarios 
  • locking and unlocking authentication procedures 
  • regulations for working with remote channels 
  • requirements for OTP, biometrics, electronic signatures or other authentication factors 
  • procedures for responding to compromised authentication factors 
  • internal compliance checklists against Resolution No. 58 
  • reporting templates for assessing the compliance and completeness of security measures. 


Benefits of working with BDO in Ukraine

  • Practical understanding of the NBU’s requirements

We support clients in interpreting the requirements of Resolution No. 58 and applying them to specific payment services, remote channels, IT solutions and the company’s operating model.

  • Comprehensive view of authentication and cybersecurity

BDO assesses not only the formal existence of procedures, but also how mechanisms for authentication, monitoring, payment data protection, fraud risk management and incident response actually work.

  • Experience in the financial sector

The team of BDO cooperates with banks, financial institutions and payment market companies for whom compliance with the NBU requirements, the protection of payment transactions and the security of remote channels are of critical importance.

  • Practical recommendations for implementation

The client receives not only findings but also a clear action plan setting out priorities, areas of responsibility and recommendations for improving processes, controls and documentation.


How we work

  • We determine the applicability of the requirements

We analyse whether the requirements of Resolution No. 58 apply to the company, its payment services, electronic communication channels, payment transactions and technological model.

  • We assess the current situation

We review procedures for authentication, improved authentication, the protection of sensitive payment data, transaction monitoring, documentation and internal controls.

  • We identify gaps and risks

We compile a list of non-compliances, weaknesses, operational risks, IT risks, fraud risks and areas requiring improvement.

  • We prepare recommendations

We provide practical recommendations for updating processes, controls, documentation, technological solutions and approaches to monitoring payment transactions.

  • We support the implementation of changes

Where necessary, we support the client during the implementation of the roadmap, the preparation of documentation, the configuration of controls or preparations for engagement with the NBU.


Why choose BDO in Ukraine

BDO in Ukraine combines expertise in audit, IT risks, information security, cyber security, payment processes and regulatory compliance. We help companies assess their compliance with NBU requirements and build a practical model for managing authentication, payment data protection and fraud risks.

Our team will help you determine how the NBU Resolution No. 58 affects your operations, which processes need updating and what steps need to be taken to ensure compliance.

Order compliance audit against the NBU Resolution No. 58

If your company is a payment service provider or facilitates payment transactions via remote channels, BDO in Ukraine will support you to assess your compliance with the requirements of the NBU Resolution No. 58 and prepare a practical roadmap for implementing the necessary changes.

Contact BDO in Ukraine to receive an independent assessment, a gap analysis and recommendations regarding authentication, improved authentication and the protection of payment data.

Key Contact

Andrii Borenkov

Andrii Borenkov, CFA

Partner, Head of Advisory
View bio

FAQ (Поширені запитання)

Authentication — the process of identifying and verifying a payment service user or an authorized representative during electronic interactions. 

Compliance audit — the review and assessment of compliance with the requirements of NBU Resolution No. 58, including authentication procedures, payment data protection, transaction monitoring, and security controls. 

Sensitive payment data — personal credentials, cryptographic keys, access passwords, transaction codes, and other information that may be used to carry out unauthorized or fraudulent activities. 

Remote channels — service channels through which payment services are provided and electronic interactions with users are conducted. 

Electronic signature — one of the authentication mechanisms used in the provision of payment services. 

Acquirer — a participant in the payment market subject to the requirements of NBU Resolution No. 58 in connection with the provision of payment services. 

Payment data protection — ensuring the confidentiality, integrity, availability, and traceability of sensitive payment data. 

Information security — a set of measures, whose compliance are assessed as part of the review of payment transaction security. 

Authentication code — a code whose generation and validation are assessed as part of authentication requirements. 

Cryptographic keys — a category of sensitive payment data whose protection is evaluated when assessing compliance with NBU Resolution No. 58. 

Payment transaction monitoring — the analysis of payment transactions to detect unauthorized or fraudulent activities, considering user behaviour and risk factors. 

Payment service provider — an organization subject to the requirements of the Regulation approved by NBU Resolution No. 58. 

Payment transaction — a transaction whose security, monitoring and protection are assessed as part of compliance with NBU Resolution No. 58. 

Payment services — services for which the applicability and fulfilment of the requirements of NBU Resolution No. 58 are assessed. 

Improved authentication — an authentication procedure that requires the use of two or more elements from different categories: knowledge, possession, and inherence, including biometric or other unique user characteristics. 

NBU Resolution No. 58 — the Resolution of the Board of the NBU dated 3 May 2023, approving the Regulation on authentication and the application of improved authentication in the payment market. 

Processing center — an organization belonging to a category of market participants for whom compliance with the requirements of NBU Resolution No. 58 is relevant when processing payment transactions. 

Regulatory compliance — adherence to the requirements of the NBU and readiness for regulatory oversight. 

Social engineering — fraudulent schemes in which customers voluntarily disclose data, codes or other information to fraudsters, enabling unauthorized access to funds. 

Authentication factors — authentication elements that fall into the categories of knowledge, possession and inherence. 

Fraud — unauthorized or deceptive activities, the risks of which are assessed through payment transaction monitoring, fraud scenario analysis and related control mechanisms.