
Andrii Borenkov, CFA
Audit, gap analysis and consultancy on authentication and improved authentication in the payments market.
BDO in Ukraine provides audit, compliance assessment and advisory services to payment service providers regarding compliance with the requirements of NBU Board Resolution No. 58 dated 03 May 2023.
NBU Resolution No. 58 approves the Regulations on authentication and the application of improved authentication in the payments market. The document sets out requirements for payment service providers regarding user authentication, the application of improved authentication, the protection of the confidentiality and integrity of sensitive payment data, and electronic interaction between parties involved in payment transactions.
Compliance with these requirements is essential for reducing the risk of fraud, safeguarding payment transactions, ensuring the security of remote channels and preparing for regulatory scrutiny by the National Bank of Ukraine. The requirements of the Regulations apply to payment service providers but do not apply to providers of limited payment services.
NBU statistics illustrate the scale of risks facing the payment market. In the year Resolution No. 58 was adopted, 272 thousand unauthorised payment card transactions were recorded, resulting in losses of UAH 833 million. Of these incidents, 83% occurred online, while 80% of total losses were attributable to social engineering schemes, where customers themselves disclosed sensitive information, authentication codes, or other data that enabled fraudsters to gain access to their funds.
In the following year, despite a decline in the number of fraudulent transactions, total losses increased to UAH 1.1 billion (37%), with 93% of losses linked to online fraud.
Actual cyber incidents further demonstrate the scale of the threat. In one exposed phishing operation alone, more than 1,000 individuals were affected, with losses estimated at approximately UAH 160 million.

These figures highlight why robust authentication measures, payment data protection, compromised-factor controls, and fraud monitoring are critical components of risk management for payment service providers.
BDO in Ukraine assists companies in assessing their current status regarding authentication, improved authentication, payment data protection, transaction monitoring and internal controls, as well as in preparing a practical action plan to ensure compliance with the NBU’s requirements.
Who needs this service
This service will be useful to organisations that provide payment services or support technological, operational or information processes related to payment transactions.
In particular, it is relevant for:
Resolution No. 58 is particularly important for companies that provide payment services via remote channels, use mobile or web applications, process payment instructions, and employ OTP, biometrics, electronic signatures, cryptographic means, behavioural analytics or other authentication mechanisms.
What is included in the service from BDO in Ukraine
We support you in determining which requirements of Resolution No. 58 apply to your company, payment services, user interaction channels, IT solutions, payment transactions and internal procedures.
BDO analyses how a company identifies and authenticates users of payment services or authorised representatives of corporate users during electronic interactions. The Regulation stipulates that such electronic interactions may only take place following the authentication of the user or authorised representative.
We verify whether the improved authentication procedure complies with the NBU’s requirements. According to the Regulation, improved authentication involves the use of two or more elements from different categories: knowledge, possession and inherence, in particular biometric or other unique characteristics of the user.
BDO assesses how the company safeguards the confidentiality, integrity, availability and traceability of sensitive payment data. Such data includes, in particular, individual account details, cryptographic keys, access passwords, transaction codes and other information that could be used to carry out unauthorised or fraudulent activities.
We analyse the mechanisms for monitoring payment transactions to detect unauthorised or fraudulent activities. The regulation stipulates that such mechanisms must be based on an analysis of transactions, considering user behaviour and risk factors, including compromised authentication credentials, transaction amounts, fraud scenarios, signs of malicious software, and atypical use of the device or software.
BDO reviews the documentation, assessment and testing of security measures designed to protect payment transactions. Resolution No. 58 stipulates that a payment service provider should document security measures and assess their compliance with the NBU’s requirements regarding data protection, cyber security and information security when providing payment services.
Based on the results of the assessment, we identify gaps between the company’s current status and the requirements of Resolution No. 58, and draw up a list of non-compliances, risks and practical recommendations for addressing them.
Key audit areas
As part of this service, BDO in Ukraine can assess:
Results of the compliance audit against the NBU Resolution No. 58
Following the collaboration, the client receives a structured assessment of compliance with the requirements of Resolution No. 58 and a practical action plan to address any identified gaps.
The client receives:
The Regulation stipulates that the outcome of the audit is an assessment and a report on the compliance and completeness of the security measures implemented by the payment service provider, and that such a report should be submitted to the regulator upon request by the NBU.
Consulting on internal documentation
BDO in Ukraine can assist with the preparation, updating or improvement of the internal documents required to comply with the provisions of the NBU Resolution No. 58.
We can assist with the development or review of:
Benefits of working with BDO in Ukraine
We support clients in interpreting the requirements of Resolution No. 58 and applying them to specific payment services, remote channels, IT solutions and the company’s operating model.
BDO assesses not only the formal existence of procedures, but also how mechanisms for authentication, monitoring, payment data protection, fraud risk management and incident response actually work.
The team of BDO cooperates with banks, financial institutions and payment market companies for whom compliance with the NBU requirements, the protection of payment transactions and the security of remote channels are of critical importance.
The client receives not only findings but also a clear action plan setting out priorities, areas of responsibility and recommendations for improving processes, controls and documentation.
How we work
We analyse whether the requirements of Resolution No. 58 apply to the company, its payment services, electronic communication channels, payment transactions and technological model.
We review procedures for authentication, improved authentication, the protection of sensitive payment data, transaction monitoring, documentation and internal controls.
We compile a list of non-compliances, weaknesses, operational risks, IT risks, fraud risks and areas requiring improvement.
We provide practical recommendations for updating processes, controls, documentation, technological solutions and approaches to monitoring payment transactions.
Where necessary, we support the client during the implementation of the roadmap, the preparation of documentation, the configuration of controls or preparations for engagement with the NBU.
Why choose BDO in Ukraine
BDO in Ukraine combines expertise in audit, IT risks, information security, cyber security, payment processes and regulatory compliance. We help companies assess their compliance with NBU requirements and build a practical model for managing authentication, payment data protection and fraud risks.
Our team will help you determine how the NBU Resolution No. 58 affects your operations, which processes need updating and what steps need to be taken to ensure compliance.
Order compliance audit against the NBU Resolution No. 58
If your company is a payment service provider or facilitates payment transactions via remote channels, BDO in Ukraine will support you to assess your compliance with the requirements of the NBU Resolution No. 58 and prepare a practical roadmap for implementing the necessary changes.
Contact BDO in Ukraine to receive an independent assessment, a gap analysis and recommendations regarding authentication, improved authentication and the protection of payment data.