КПА
All documents
Source: № 17742 min read

Unified insurance database (USDB) — Resolution No. 177

LegislationData & modelsDigital insurance

Unified Insurance Database (USDB (ЕСБД)): Requirements for the Operating Entity (Resolution No. 177)

Reference card for a regulatory legal act. The full text is available in the official «Adilet» system (adilet.zan.kz).

Requisites

Parameter Value
Type of act Resolution of the Board of the Agency of the RK for Financial Market Regulation (AFN)
Number and date No. 177 of 25 June 2007
Status In force (as of June 2026)
Official code V070004860_

Subject of the document

It establishes the requirements for the entity responsible for forming and maintaining the Unified Insurance Database (USDB (ЕСБД)). The legal basis of the USDB is Article 80 of the Law «On Insurance Activity»; this Resolution sets out the procedure for maintaining the database, the composition of the information held, and the conditions for providing insurance reports to its recipients.

Relevance for actuarial practice

  • The USDB is a key source of anonymised insurance data for actuarial research, the construction of mortality/morbidity tables, and loss-ratio analysis.
  • It is one of the four blocks of the Chamber's legislative initiatives: including the actuaries' association in the list of recipients of detailed anonymised information and introducing an "anonymised statistical insurance report".
  • It relates to the "collect once, use many" principle in the simplification of insurers' reporting.

Official source

Full text in force: adilet.zan.kz/rus/docs/V070004860_. Files in the repository: docs/Law/ЕСБД — Требования к организации ….


English Translation (Auto-generated)

Official source: Adilet / https://adilet.zan.kz/rus/docs/V070004860_ The relevance of the editorial office has been verified: 2026-06-20.

Footnote: Footnote. The title is as amended by the Resolution of the Board of the National Bank of the Republic of Kazakhstan dated January 28, 2016 No. 12 (shall come into force ten calendar days after the day of its first official publication).

In order to implement the Law of the Republic of Kazakhstan “On Insurance Activities”, the Board of the Agency of the Republic of Kazakhstan for Regulation and Supervision of the Financial Market and Financial Organizations (hereinafter referred to as the Agency) DECIDES:

  1. Approve the attached Requirements for the organization’s activities in creating and maintaining a database.

2. This resolution comes into effect upon the expiration of fourteen days from the date of state registration with the Ministry of Justice of the Republic of Kazakhstan.

3. Department of supervision of insurance market entities and other financial organizations (Karakulova D.Sh.):

  1. together with the Legal Department (Baisynov M.B.) take measures for state registration of this resolution with the Ministry of Justice of the Republic of Kazakhstan;

  2. within ten days from the date of state registration with the Ministry of Justice of the Republic of Kazakhstan, bring this resolution to the attention of interested divisions of the Agency, insurance (reinsurance) organizations, the organization that creates and maintains the database, and the Association of Legal Entities "Association of Financiers of Kazakhstan".

4. The Service of the Chairman of the Agency (Zabortseva E.N.) ensure the publication of this resolution in the media of the Republic of Kazakhstan.

5. Entrust control over the implementation of this resolution to the Deputy Chairman of the Agency G.N. Uzbekov.

Chairman

Approved by Resolution of the Board of the Agency of the Republic of Kazakhstan for Regulation and Supervision of the Financial Market and Financial Organizations dated June 25, 2007 N 177

Requirements for the organization's activities in creating and maintaining a database

Footnote: Footnote. Title of the Instruction as amended by the Resolution of the Board of the National Bank of the Republic of Kazakhstan dated January 28, 2016 No. 12 (shall be brought into force ten calendar days after the day of its first official publication).

These Requirements for the activities of an organization in the formation and maintenance of a database (hereinafter referred to as the Requirements) are developed in accordance with the Law of the Republic of Kazakhstan “On Insurance Activities” (hereinafter referred to as the Law on Insurance Activities) and establish requirements for the activities of an organization in the formation and maintenance of a database (hereinafter referred to as the Organization), including requirements for the information process, the formation of a security system and the establishment of minimum requirements for electronic equipment, the safety of a unified insurance database (hereinafter referred to as the database), and premises.

The collection, processing and protection of personal data in accordance with the Requirements are carried out in accordance with the Law of the Republic of Kazakhstan “On Personal Data and Their Protection.

Chapter 1. General provisions

  1. The Requirements use the basic concepts established by the Law on Insurance Activities, the Law of the Republic of Kazakhstan “On Electronic Documents and Electronic Digital Signatures”, as well as the following concepts:

  1. information systems security administrator (hereinafter referred to as the administrator) - an employee of the Organization and the database user, ensuring the functioning of the system for electronic receipt and (or) transmission of data, implementing measures to protect them, generating incoming and (or) transmitted information, taking into account its functions and powers;

2) information security policy – ​​norms and practices governing the management, protection and distribution of restricted information;

3) authentication – confirmation of the authenticity of the subject or object of access by determining the correspondence of the presented access credentials to those available in the system;

4) database user - information providers specified in paragraph 3 of Article 80 of the Law on Insurance Activities and recipients of the insurance report specified in subparagraphs 3) and 3-1) of paragraph 4 of Article 80 of the Law on Insurance Activities, participating in the information system for the formation and use of insurance reports in accordance with the requirements of the laws of the Republic of Kazakhstan;

5) responsible person - an employee of the Organization and the user of the database who ensures the functioning and control of means of protecting information from unauthorized access;

6) malicious software (computer viruses, network worms and similar software) - a set of executable code capable of creating copies of itself (partially or completely identical to the original) and introducing them into various objects and (or) resources of computer systems, networks without the knowledge of the database user;

7) real-time mode - the operating mode of the information system for the generation and use of insurance reports, ensuring the receipt, processing and exchange of information until 16.00 Astana time on the day following the day of concluding the insurance contract;

8) key information – cryptographic keys and electronic digital signature keys;

9) operator - an employee of the database user who directly receives, collects, processes, transmits and receives information using the security system;

10) services in proactive mode - the Organization’s services for notifying the database subject, provided without the submission of an application by the database subject;

11) information system for the generation and use of insurance reports - a set of information technologies, information networks and their software and hardware intended for implementation by the Organization, information providers specified in paragraph 3 of Article 80 of the Law on Insurance Activities, recipients of insurance reports (except for the subject of the database) information processes;

12) measures to protect the information system for the generation and use of insurance reports - organizational and technical measures aimed at ensuring the safe functioning of the information system for the generation and use of insurance reports, including software and hardware protection of electronic means and computers from unauthorized access, ensuring control of access to installed software and information, providing means of delineating the powers of registered users;

13) insurer - an insurance organization, a branch of a non-resident insurance (reinsurance) organization of the Republic of Kazakhstan, carrying out activities for the conclusion and execution of insurance contracts on the basis of the relevant license of the authorized body;

14) identifier – a unique personal code and (or) name assigned to a subject and (or) object of the system, and intended for regulated access to the system and (or) to system resources;

15) identification – the process of assigning or determining the correspondence of the identifier presented to gain access to the system and (or) to the system resource to the list of identifiers available in the system;

16) authorized body - a state body that regulates, controls and supervises the financial market and financial organizations.

2. Information providers and recipients of the insurance report (except for persons specified in subparagraphs 1), 1-1), 2), 2-1), 4), 6), 7), 8), 9), 10) and 11) of paragraph 4 of Article 80 of the Law on Insurance Activity) ensure compliance with the organizational, technological conditions and requirements established by the legislation of the Republic of Kazakhstan on insurance and insurance activities, credit bureaus and the formation of credit histories and informatization, as well as those arising from agreements concluded with the Organization on the provision of information and (or) receipt of insurance reports.

2-2. The internal rules establishing the procedure for the activities of the Organization contain the following information:

  1. the procedure for concluding an agreement on the provision of information and (or) receipt of insurance reports;

  2. list and forms of insurance reports submitted from the database;

  3. types, timing (frequency), volume of information contained in insurance reports, and the procedure for obtaining insurance reports;

  4. the procedure for paying for services for providing information from the database;

  5. types, volume, terms (frequency), procedure for providing information for the formation of a database;

  6. rights and obligations of the Organization, information provider and recipient of the insurance report;

  7. responsibility of the Organization, the information provider and the recipient of the insurance report;

  8. operating mode of the Organization.

2-3. In addition to the functions of the Organization established in paragraph 7 of Article 79 of the Law on Insurance Activities, the Organization:

  1. develops and provides specialized software to automate the activities of recipients of insurance reports;

2) provides services in a proactive mode, the procedure for the provision of which is determined by the Organization independently, taking into account the restrictions established by the Law on Insurance Activities and the Requirements.

Chapter 2. Generation and use of insurance reports

3. To generate insurance reports, agreements are concluded between the Organization and the information providers specified in subparagraphs 1) and 1-1) of paragraph 3 of Article 80 of the Insurance Law on the provision of information and (or) receipt of insurance reports.

Requirements for the content of the agreement on the provision of information and (or) receipt of insurance reports are established by Article 83 of the Law on Insurance Activities.

4. Registration in the Organization of information providers specified in paragraph 3 of Article 80 of the Law on Insurance Activities is carried out in accordance with Article 84 of the Law on Insurance Activities.

5. When a request is received from the recipients of the insurance report specified in paragraph 4 of Article 80 of the Law on Insurance Activities to submit an insurance report on paper, the Organization submits the report to such recipients within two working days from the date of receipt of the request.

The provision of an insurance report to the persons specified in paragraph 4 of Article 80 of the Law on Insurance Activities is carried out in accordance with paragraph 6 of Article 80 of the Law on Insurance Activities.

The request of recipients of insurance reports to provide an insurance report in electronic form is confirmed in one of the following ways:

  1. means of biometric identification;

2) electronic digital signature;

3) generating and entering a one-time password.

The processes of biometric identification, the use of electronic digital signatures, as well as the generation and sending of a one-time password are determined by the Organization taking into account the requirements established by the legislation of the Republic of Kazakhstan in the field of digitalization, electronic document and electronic signature, as well as requirements in the field of information security and personal data protection.

6. Excluded by Resolution of the Board of the Agency of the Republic of Kazakhstan for Regulation and Supervision of the Financial Market and Financial Organizations dated 09/03/2010 No. 137 (shall be enforced upon the expiration of ten calendar days after the day of its first official publication).

7. Excluded by Resolution of the Board of the Agency of the Republic of Kazakhstan for Regulation and Supervision of the Financial Market and Financial Organizations dated 09/03/2010 No. 137 (shall be enforced upon the expiration of ten calendar days after the day of its first official publication).

8. Excluded by the Resolution of the Board of the Agency of the Republic of Kazakhstan for Regulation and Supervision of the Financial Market and Financial Organizations dated December 27, 2010 No. 183 (to be put into effect after 14 calendar days from the date of its state registration in the Ministry of Justice of the Republic of Kazakhstan).

9. The insurance report for the database subject must contain information about all provided insurance reports, indicating the date of issue, name and details of the recipients of the insurance report.

10. When providing an insurance report, the Organization indicates all providers of information and the date of receipt of this information by the Organization.

10-1. The information provider specified in subparagraph 1) of paragraph 3 of Article 80 of the Law on Insurance Activities submits to the Organization the information provided for by the Resolution of the Board of the Agency of the Republic of Kazakhstan for Regulation and Supervision of the Financial Market and Financial Organizations dated March 1, 2010 No. 25 “On approval of the Requirements for the implementation by an insurance organization, a branch of a non-resident insurance organization of the Republic of Kazakhstan of insurance activities, including in relations with participants in the insurance market, to the agency agreement, concluded between an insurance organization and an insurance agent, and the powers of the insurance agent to carry out intermediary activities in the insurance market, as well as the minimum training program for insurance agents and requirements for the training procedure", registered in the Register of State Registration of Normative Legal Acts under No. 6164, for compulsory types of insurance, under co-insurance agreements within the framework of compulsory types of insurance (except for imputed insurance) - in real time, for voluntary types of insurance, under contracts coinsurance within the framework of imputed and voluntary types of insurance, under reinsurance contracts, joint reinsurance - no later than the 6th (sixth) working day of the month following the reporting month.

11. The information provider specified in subparagraph 1) paragraph 3 of Article 80 of the Law on Insurance Activities submits to the Organization the information provided for by the Resolution of the Board of the National Bank of the Republic of Kazakhstan dated October 29, 2018 No. 269 “On establishing Requirements for the content and procedure for issuing insurance policies”, registered in the Register of State Registration of Normative Legal Acts under No. 17806, in real time on mandatory types of insurance, under co-insurance agreements within the framework of compulsory types of insurance (except for imputed insurance) and no later than the 6 (sixth) working day of the month following the reporting month for voluntary types of insurance, under co-insurance agreements within the framework of imputed and voluntary types of insurance, reinsurance and joint reinsurance.

11-1. For vehicles temporarily entering (imported) into the territory of the Republic of Kazakhstan, when concluding a contract of compulsory insurance of civil liability of vehicle owners, the information provider specified in subparagraph 1) of paragraph 3 of Article 80 of the Law on Insurance Activities provides the following information in real time:

  1. type of insurance contract (standard, complex);

2) a unique insurance contract number assigned by the Organization;

3) validity period of the insurance policy;

4) information about the applicant:

last name, first name, patronymic (if any), date of birth, place of residence (for an individual);

series, number, date of issue of the driver's license, driving experience (for an individual);

name, location (for a legal entity);

sign of residence (resident or non-resident of the Republic of Kazakhstan);

5) information about the vehicle:

a document confirming the registration of the vehicle for the period of import;

type of vehicle in accordance with the Law of the Republic of Kazakhstan “On compulsory insurance of civil liability of vehicle owners” (hereinafter referred to as the Law on Compulsory Insurance);

year of issue;

body number;

6) information about the insured (insured):

last name, first name, patronymic (if any), date of birth, place of residence;

series, number, date of issue of the driver's license, driving experience.

11-2. The information provider specified in subparagraph 1-1) of paragraph 3 of Article 80 of the Law on Insurance Activities provides the Organization with information within the guaranteed classes (types) of insurance included in the system for guaranteeing insurance payments on the basis of an information provision agreement concluded with the Organization.

11-3. The information provider specified in subparagraph 1-2) of paragraph 3 of Article 80 of the Law on Insurance Activities provides the Organization with information on pension annuity agreements concluded within the framework of the Social Code of the Republic of Kazakhstan.

12. Excluded by Resolution of the Board of the Agency of the Republic of Kazakhstan for Regulation and Supervision of the Financial Market and Financial Organizations dated 09/03/2010 No. 137 (shall be enforced upon the expiration of ten calendar days after the day of its first official publication).

13. The organization assigns a unique number to the contract of compulsory insurance of civil liability of vehicle owners in the following order:

  1. entry by the insurer of information about the policyholder (insured), the vehicle (vehicles) into the database based on the insured’s application for concluding a contract of compulsory insurance of civil liability of vehicle owners;

2) generation of an insurance report in the database containing information necessary for inclusion in the insurance policy;

3) assignment of a unique number to the insurance policy, which is the insurance policy number.

13-1. The organization assigns a unique number to the concluded contract of compulsory (with the exception of compulsory insurance of civil liability of vehicle owners), voluntary insurance in the database.

14. Excluded by the Resolution of the Board of the Agency of the Republic of Kazakhstan for Regulation and Supervision of the Financial Market and Financial Organizations dated 09/03/2010 No. 137 (shall be enforced upon the expiration of ten calendar days after the day of its first official publication).

15. Issuance of insurance reports from the database to the recipients of the insurance report specified in paragraph 4 of Article 80 of the Law on Insurance Activities is carried out depending on the levels of access and type of insurance reports in accordance with paragraph 5 of Article 80 of the Law on Insurance Activities.

16. Excluded by Resolution of the Board of the Agency of the Republic of Kazakhstan for Regulation and Supervision of the Financial Market and Financial Organizations dated 09/03/2010 No. 137 (shall be enforced upon the expiration of ten calendar days after the day of its first official publication).

17. Excluded by the Resolution of the Board of the Agency of the Republic of Kazakhstan for Regulation and Supervision of the Financial Market and Financial Organizations dated 09/03/2010 No. 137 (shall be enforced upon the expiration of ten calendar days after the day of its first official publication).

18. For the purpose of justified application of the amount of the insurance premium, employees of the recipient of the insurance report specified in subparagraph 1) paragraph 3 of Article 80 of the Law on Insurance Activities, whose job responsibilities include the conclusion of compulsory insurance contracts for civil liability of vehicle owners, receive an insurance report on the class assigned to the database subject (the presence or absence of insured events for the database subject) in accordance with Resolution of the Board of the National Bank of the Republic of Kazakhstan dated May 30, 2016 No. 140 “On approval of the Rules for the calculation and application of the coefficient according to the “bonus-malus” system for calculating the insurance premium for compulsory civil liability insurance of vehicle owners,” registered in the Register of State Registration of Normative Legal Acts under No. 13928.

Chapter 3. Information process

19. The functioning of the information system for the generation and use of insurance reports ensures:

  1. coordination and controllability of the activities of its participants within the framework of agreed procedures and technological parameters;

  2. unification of the software and hardware used;

  3. information security, including eliminating the possibility of information disclosure;

  4. introduction of highly efficient technologies;

  5. flexible and efficient resource management;

  6. increase in the quality of services.

20. The organization and database users provide:

  1. data entry control;

  2. the ability to calculate document parameters (document numbers, communication code, contract number, etc.);

  3. generation of summary information;

  4. creating backup copies, archiving data;

  5. use of information systems that have standard security measures, with control over access rights;

  6. the presence of regulated procedures for providing and receiving electronic messages;

  7. the ability to prepare analytical and statistical reports.

21. The process of development, implementation and maintenance of information systems includes determining the stages of development, the procedure for making changes, acceptance, testing and putting into commercial operation, requirements for documenting all stages.

22. The development, implementation and maintenance of information systems by the Organization is carried out in accordance with the standards and internal documents of the Organization in force on the territory of the Republic of Kazakhstan.

23. The development of information systems is carried out by the Organization on the basis of technical specifications approved by their first manager.

The organization ensures the ability to receive information from information providers or establishes appropriate requirements for the software they use. In the case of independent software development by database users, it is agreed with the Organization.

24. In order to exclude unauthorized changes to the software and (or) information system data, if it is necessary to make changes (to eliminate deficiencies or improve the system) in the software, the process of making changes is carried out in accordance with the technical specifications, standards in force in the territory of the Republic of Kazakhstan, and internal documents of the Organization.

Chapter 4. Conditions for the exchange of information between the Organization and database users

25. The exchange of information between database users and the Organization is carried out through a special automated system that meets the requirements of the legislation of the Republic of Kazakhstan on informatization and technical regulation.

26. Information provided by the information provider is returned by the Organization without its use in the information system for the formation and use of insurance reports, in the event of its incorrect or incomplete registration, or the data of the information provider, the recipient of the insurance report, or the subject of the database does not comply with the requirements for the information system used.

26-1. The organization exchanges data with information providers and recipients of the insurance report via dedicated communication channels or via the Internet resources, provided:

  1. the presence of a main channel with a capacity of at least 10 (ten) megabits per second;

2) the presence of a wireless backup channel with a capacity of at least 2 (two) megabits per second;

3) using channels from different providers;

4) using channels exclusively for exchanging information with information providers and recipients of insurance reports.

Chapter 5. Formation of a security system

27. The information system for the generation and use of insurance reports provides:

  1. confidentiality of information - protection from disclosure of information during its storage, processing or transmission through communication channels;

  2. security of information - protection from damage, integrity and security from unauthorized modification, addition, copying or deletion during its storage, processing or transmission via communication channels;

  3. availability - protection from the use by one user of data and other information system resources intended for sharing, interception of information messages and (or) data with their subsequent delay, as well as from interception of information messages and (or) data with their subsequent delay.

28. The basic component of mandatory measures to ensure the security of the information system for the generation and use of insurance reports is the use of an integrated approach to the creation of an information security system.

29. An integrated approach to creating an information security system includes analysis and assessment of risks, including through technical channels of information leakage, taking into account the nature and importance of the information being protected, and monitoring the security of electronic document processing technology.

30. The organization and database users take actions to promptly identify suspicious activities in real time and include activities aimed at establishing:

  1. atypical behavior (of users, programs or equipment);

  2. the beginning of unauthorized intrusion activity or the use of malicious software.

31. The main areas providing an integrated approach to information security at the software and hardware level are:

  1. safety circuit;

  2. internal corporate security;

  3. corporate security management.

32. The security circuit is designed to ensure the protection of the information system for the generation and use of insurance reports (hereinafter referred to as the Security Circuit). The security loop protects central and additional offices (branches, representative offices, remote offices), information flows between them, as well as information resources stored on servers and workstations for external connections of the information system with other networks.

33. Security procedures of the Organization and database users are designed to control unauthorized intrusions and anti-virus protection, ensure their internal information security and require the need to build and maintain a system that ensures the division of users into groups in accordance with their status and rights, as well as the division of resources according to their level of confidentiality.

34. Corporate security management, within the framework of a comprehensive security system for the Organization and database users, is ensured by constant monitoring of compliance with the general requirements of the information security policy, prompt adjustments to it and increasing its level.

35. Improving the level of security includes:

  1. determination of information security policy;

  2. establishing the boundaries within which the information security regime is expected to be maintained;

  3. conducting a risk assessment;

  4. selection of countermeasures and risk management;

  5. selection of tools and controls that ensure information security.

36. The information security policy contains a description of the composition of the information system used, a list of users, their rights (depending on their official position and the nature of the functions performed) to access information, software and hardware and determines:

  1. general directions of work in the field of information security;

  2. the purpose and objectives of protecting the information system;

  3. basic principles and methods of achieving the required level of security;

  4. identification of officials responsible for developing the necessary requirements defining the information security policy;

  5. identification of departments responsible for the creation and maintenance of information systems and their protection systems;

  6. measures to prevent violations of the security regime of information systems in the event of force majeure circumstances, which include natural disasters, accidents, fires, power outages, damage to communication lines, riots, strikes, military operations.

37. The organization and database users provide:

  1. compliance of the management decisions, technologies, approaches and specific software and hardware used with the current legislation of the Republic of Kazakhstan;

  2. adoption of internal documents on the organization of information system security.

38. The procedural level of information protection includes security measures taken by the Organization and database users in the following areas:

  1. personnel management;

  2. physical protection;

  3. responding to security violations;

  4. planning of restoration work.

39. Algorithms used to protect information during user authentication and data transfer are certified in the Republic of Kazakhstan in accordance with the requirements of the state standard of the Republic of Kazakhstan ST RK 1073-2007 "Means of cryptographic information protection. General technical requirements."

40. The information protection plan includes the following measures:

  1. organizational;

  2. software and hardware.

41. Organizational security measures include:

  1. physical protection of information systems;

  2. maintaining the operability of information systems related to information security;

  3. establishing for each user the appropriate access right necessary to fulfill his assigned job responsibilities and ensure interchangeability;

  4. planning of restoration work.

42. Physical protection is divided into:

  1. physical access control;

  2. fire safety measures;

  3. protection of supporting infrastructure;

  4. protection against data interception, protection of mobile systems.

43. Measures to maintain the functionality of information systems are divided into:

  1. user support - providing advice on information security issues, identifying common errors and providing reminders with recommendations for common situations;

  2. software support - control of licensed (certified) software purity;

  3. configuration management - control and recording of changes made to the software and technical configuration;

  4. backup to restore the information system and data in the event of an accident and other force majeure circumstances;

  5. management of data carriers - the procedure for recording, handling and storage;

  6. documentation - an up-to-date reflection of the current state of affairs.

44. In case of violation of the security regime of information systems, the responsible persons, the administrator, shall:

  1. implementation of operational measures in order to reduce the harm caused;

  2. analysis and assessment of available information about violations - studying the incident, identifying repeated violations, developing measures to improve the protection system.

44-1. The organization provides information about events and circumstances that resulted in the unavailability or incorrect operation of the unified insurance database, as a result of which insurance (reinsurance) organizations were not able to enter into contracts and (or) fulfill obligations to policyholders (insured, beneficiaries) for twenty-four hours or more.

The organization ensures that the information specified in part one of this paragraph is submitted to the authorized body no later than two working days from the start of these events.

45. Backup and recovery after loss of functionality of the information system are determined by the requirements established in the Organization and among database users.

45-1. The Organization ensures the availability of a backup server for storing copies of information about the subjects of the unified insurance database located outside the boundaries of the locality in which the Organization is located.

Chapter 6. Minimum requirements for electronic equipment, database security and premises

46. ​​The user's software is installed on a specially designated personal computer that has a passport - a description of the workplace with detailed data on its location, configuration, as well as hardware and software installed on it.

47. It is not permitted to operate the user’s personal computer and install software on it that is not related to the purposes of preparing, processing, transmitting or maintaining electronic documents as part of participation in the information system for the generation and use of insurance reports.

48. The user’s personal computer is equipped with a security complex, including means of identifying and authenticating users, the ability to maintain electronic logs during the storage period of electronic documents, in order to control activities related to access to the computer and user actions.

49. One system user name by which the user is identified when entering information systems must correspond to one individual.

50. Passport - a description of the workplace is signed by the heads of the Organization and the user and is kept by the responsible person.

51. The user’s personal computer is equipped with a means of ensuring software integrity.

52. The system unit of the user’s personal computer is sealed or sealed by the responsible person. If necessary, access to the system unit is carried out in the presence of a responsible person. Upon completion of the work, the system unit is sealed or sealed by the responsible person.

53. The procedure for accessing resources (disk space, directories, network resources, databases and others) allocated for accumulating information in them for transmission to the information environment using a security system, obtaining information from the information environment, storing, archiving or other processing of information excludes the possibility of unauthorized access to these resources.

54. Carrying out and monitoring work on cryptographic protection is carried out by a responsible person who performs:

  1. accounting, storage and maintenance of cryptographic protection software;

  2. generation of cryptographic keys, receipt, accounting, storage and issuance of information media containing keys;

  3. maintaining a list of cryptographic key owners;

  4. providing owners of cryptographic keys with the necessary instructions.

56. The location where the workplace of the user with access to limited access insurance reports is located, and the security means for the premises must exclude the possibility of uncontrolled entry into this premises by persons not allowed to the user’s workplace.

Technical means of protecting the workplace must prevent unauthorized access to the workplace.

57. The technical premises of the Organization must be located in a protected area, have combination locks and access registration means.

When the Organization's premises are located on the first or last floors of buildings, as well as when there are balconies and fire escapes next to the windows, the windows of the premises are equipped with metal bars.

58. Technical protection means for the Organization’s premises must exclude the possibility of uncontrolled entry into this premises by persons. Admission to work in the Organization is carried out in accordance with its regulations and the job responsibilities of employees.

Chapter 7. Other issues of database activity

59. An internal act of the Organization and the user determines the procedure for working with the security system, including:

  1. the procedure for appointing employees who are assigned the duties of a responsible person, administrator, operator;

  2. operating mode;

  3. the rights and obligations of the responsible person, administrator and operator, including their job descriptions;

  4. a list of employees admitted to the operator’s workplace.

60. Responsible persons:

  1. ensure mandatory identification and authentication procedures for access to information system resources;

  2. do not allow unauthorized users to gain access to information resources;

  3. control the regularity of backup of information processed by the information system;

  4. conduct scheduled and unscheduled checks of the reliability of protection of system resources;

  5. provide protection of information resources connected to the global Internet using hardware firewalls "FireWall";

  6. take measures to repel the threat and identify intruders using hardware that combines both an intrusion detection system (IDS) and an intrusion prevention system (IPS (IDPS));

  7. ensure the functionality of protection against information leakage through removable media (floppy disks, flash cards, external hard drives and others);

  8. regularly review the event log, conduct analysis of records where there have been attempts at unauthorized access to information;

  9. constantly carry out anti-virus preventative work.

61. The responsible person, administrator, operator give a written commitment to non-disclosure and non-dissemination of information that has become known to them in the course of performing their official duties.

62. When the user’s employees (responsible person, administrator or operator) are dismissed, an unscheduled change of key information of the organization is made, of which the Organization is notified. The new key information is effective from the date of their dismissal.

63. Excluded by the Resolution of the Board of the Agency of the Republic of Kazakhstan for Regulation and Supervision of the Financial Market and Financial Organizations dated December 27, 2010 No. 183 (to be put into effect after 14 calendar days from the date of its state registration in the Ministry of Justice of the Republic of Kazakhstan).

64. The procedure for storing and using external media with key information excludes the possibility of unauthorized access to them.

65. When generating and transmitting an electronic message, the Organization and the user carry out protective actions in accordance with the procedure established by them for the use of software-cryptographic protection and electronic digital signature.

66. In the event of a violation of the procedure for protective actions or its disclosure, the party that established this violation immediately notifies the other party and takes measures to eliminate the consequences.

67. Excluded by Resolution of the Board of the National Bank of the Republic of Kazakhstan dated January 28, 2016 No. 12 (shall be enforced upon the expiration of ten calendar days after the day of its first official publication).

Chapter 8. Final provisions

Footnote: Footnote. Chapter 8 was excluded by Resolution of the Board of the National Bank of the Republic of Kazakhstan dated January 28, 2016 No. 12 (shall be enforced ten calendar days after the day of its first official publication).

Appendix to the Requirements for the activities of the organization for the formation and maintenance of a database

Footnote: Footnote. The instructions are supplemented by Appendix 1 in accordance with the resolution of the Board of the Agency of the Republic of Kazakhstan for Regulation and Supervision of the Financial Market and Financial Organizations dated 09/03/2010 No. 137 (shall come into force ten calendar days after the day of its first official publication); as amended by the Resolution of the Board of the Agency of the Republic of Kazakhstan for Regulation and Development of the Financial Market dated December 23, 2025 No. 82 (shall be enforced upon the expiration of ten calendar days after the day of its first official publication).

Form

Act of putting the database management system into commercial operation__________________________________________________________________________ (name of the Organization for the formation and maintenance of the database)

""_________ 20___ date ____________________place of compilation

In accordance with paragraph 5 of Article 79 of the Law of the Republic of Kazakhstan “On Insurance Activities” (hereinafter referred to as the Law on Insurance Activities), a commission was created with the following composition: representatives of the authorized body (indicate position, surname, first name, patronymic (if any): ________________________________________________________________________________________________________________________________________________, which drew up this act of putting the database management system into commercial operation Organization for the formation and maintenance of the database data. (name) Representatives of the Organization for the formation and maintenance of the database participate in the work of the commission (indicate position, surname, first name, patronymic (if any)): _____________________________________________________________________________________________________________________________________________________________________________________________________________ Information regarding concluded agreements for the provision of information with information providers specified in paragraph 3 of Article 80 of the Law on Insurance:

No. Name of the information provider Contract number and conclusion date Test result Explanations of the test result 1 Insurers 1.1 … 2 Authorized state body exercising state control over database subjects 2.1 … 3 Other persons 3.1 … 4 Total (number)

Organization of the information process for the formation and issuance of insurance reports: Description of the database management system: ________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________ Results of testing the information process with information providers who have entered into an agreement on the provision of information: ________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________ Summary of explanations from representatives of the Organization for the formation and maintenance of the database: ________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________ The Commission checked technical and other documents, agreements for the provision of information with information providers specified in paragraph 3 of Article 80 of the Law on Insurance Activities, the Organization for the formation and maintenance of the database , (name) examined its database management systems and other objects intended for organizing the information process for the formation and issuance of insurance reports and established that this Organization for the formation and maintenance database______________________________________________________________________________________________________________________________ready (not ready) for putting the database management system into commercial operation. The organization for the formation and maintenance of the database presented the following documents relating to the organization of the information process for the generation and issuance of insurance reports, the database management system and testing of the information process, which are attached to the commission’s act: The act is drawn up in two copies and one copy each transferred to: the authorized body; Organization for the formation and maintenance of the database. Members of the commission (last name, first name, patronymic (if any), signature and date of signing): ________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________________ Representatives of the Organization for the formation and maintenance of the database (last name, first name, patronymic (if any), signature and date signing):_______________________________________________________________________________________________________________________________Head of the Organization for the formation and maintenance of the database (last name, first name, patronymic (if any), signature and date of signing):

Appendix 2 to Instructions for creating and maintaining a database

ACT on the compliance of the Organization, the information provider specified in subparagraph 1) of paragraph 3 of Article 80 of the Law on Insurance Activities, with the requirements for starting its activities in the information services market and its fulfillment of organizational, technical, technological and other conditions for software protection, formation of information systems and information resources________ ____________________ date, place of preparation

Footnote: Footnote. Appendix 2 as amended by the resolutions of the Board of the Agency of the Republic of Kazakhstan for Regulation and Supervision of the Financial Market and Financial Organizations dated 09/03/2010 No. 137 (shall be brought into force ten calendar days after the day of its first official publication); dated December 27, 2010 No. 183 (shall be enforced upon expiration of 14 calendar days from the date of its state registration in the Ministry of Justice of the Republic of Kazakhstan).

This act of readiness of the Organization, information provider,

specified in subparagraph 1) paragraph 3 of Article 80 of the Law on Insurance

activity, to the beginning of its activities in the information services market and its implementation of organizational and technical measures, technological requirements for software protection, compliance with the requirements for the formation and operation of information systems used to create an electronic database of insurance reports and means of its protection, compiled by the commission in the following composition:

  1. representatives of the authorized body:




  1. representatives of the Organization, the information provider specified

in subparagraph 1) paragraph 3 of article 80 of the Insurance Law

activities:





Description of the objects surveyed and documents studied by the commission:




Brief content of the explanations of the representatives of the Organization,

information provider specified in subparagraph 1) of paragraph 3 of Article 80

Law on Insurance Activities, and other persons present:





Review by the commission of technical and other documents of the Organization,

information provider specified in subparagraph 1) of paragraph 3 of Article 80

of the Law on Insurance Activities, ______________________________, an examination of its technical premises, electronic computer equipment, communication systems and protective devices and other objects intended to work in the system for generating an electronic database of insurance reports established


(complies/does not correspond to the requirements

requirements and sufficient/insufficient to start continuing

activities of the organization in the information services market).

The organization or provider of the information specified in

subparagraph 1) paragraph 3 of Article 80 of the Law on Insurance Activities, presented technical documentation and other documents that are attached to the commission’s report.

The act was drawn up in two copies and one copy each

transmitted:

authorized body;

The organization or information provider specified in subparagraph

  1. paragraph 3 of Article 80 of the Law on Insurance Activities.

Members of the commission:




Representative of the audited organization: