Why translated risk frameworks fail in Central Asian banks
Frameworks imported from European parent institutions describe a business model, a regulatory environment and a risk profile that do not match the market they land in.
Coming soonNazor.ai helps banks, payment providers and humanitarian organisations across Uzbekistan and Central Asia find the exposures their frameworks were never built to catch — in operations, in compliance, and in the technology arriving faster than the controls around it.
Whether the organisation is a bank in Tashkent or an aid programme running cash transfers across a border, the same gaps recur.
A risk framework translated from a European parent or a donor template describes an organisation that isn't yours. It passes review and catches nothing.
Scoring models, fraud engines, beneficiary databases and payment rails deployed quickly, bought from vendors, and owned by no one in the second line.
Assessment cycles run because they are required. The findings don't change decisions, and the residual risk ratings haven't moved in three years.
Two sectors, and genuine depth in both — twenty years split between commercial banking and international humanitarian assurance.
Institutions modernising under regulatory pressure, adopting technology faster than governance can follow, and answering to supervisors who are still writing the rules.
Organisations delivering in difficult environments under donor scrutiny, where a compliance failure costs the grant and the operation behind it.
Scoped to a defined outcome and a fixed fee. No open-ended retainers to start, and no team of juniors learning on your time.
Assessment of what exists against the standard that applies to you, then design and embedding of what is missing. Built around how the organisation actually operates rather than lifted from a template.
Where AI enters the organisation, what it decides, and who answers when it decides wrong. Vendor assessment, model controls, and the governance structure a regulator or donor will eventually ask to see.
Control testing, audit readiness and independent review. Twenty years on both sides of the audit table, including regional internal audit across four countries and focal point for institutional and donor reviews.
Working sessions rather than slide decks. Risk and audit teams leave with methodology they can run themselves; boards and senior management leave knowing which questions to put to their own people.
Registered and operating in Uzbekistan. Expanding by following the work rather than announcing it first.
Home market. The firm is registered in Tashkent and delivers here directly, in person, with no intermediary.
An active focus across the region. A local branch is registered once an engagement is signed, rather than maintained ahead of demand.
Specialist partners across the Gulf and Levant join engagements where sanctions exposure, Islamic finance or donor compliance calls for it. Regional presence follows demand.
You will be working with Mashal Sabti. Not an account manager, and not a team of consultants two years out of university.
Twenty years in risk and compliance, split between commercial banking and international humanitarian assurance. Seven of those across two periods at Standard Chartered, the second ending as Head of Governance and Control after leading consumer banking operations and technology risk.
Then four years building risk functions from nothing — first as Executive Manager for operational risk and information security at Egyptian Arab Land Bank, then across branches and subsidiaries as AVP of operational risk at Jordan Ahli Bank. Two years of independent consulting followed, advising and training risk teams across several industries.
Most recently, Risk and Assurance Manager for the International Committee of the Red Cross, covering the Near and Middle East region and then Afghanistan from a base in Uzbekistan. That work involved sanctions exposure, cash controls in conflict environments, and partner due diligence where the cost of getting it wrong went well beyond an audit finding.
Alongside the practice, a law degree and a master's in international commercial law and technology from the University of Manchester. That combination is unusual in this field, and it is why the advice covers where liability actually sits — in the contract, in the vendor agreement, in the regulation — and not only where the control gap is.
Education
Certification
Most begin with a scoped assessment. It costs less, proves the value, and tells both of us whether the larger piece of work is worth doing.
An hour on what you are facing. If the answer is that you do not need outside help, that is a legitimate outcome and I will say so.
Scope, deliverables, timeline and a fixed fee. No hourly billing, and no scope that expands after signature.
On site with your teams. Document review, process walkthroughs, control testing and interviews — done in person, because the risk that matters rarely appears in the documentation.
What was found, ranked by exposure, with remediation sequenced by what is urgent and what is achievable. Presented to management and, where useful, to the board.
Recommendations that sit in a report change nothing. Continued support is available where you want the work embedded rather than delivered.
Writing on risk, regulation and emerging technology in Central Asian and frontier markets.
Frameworks imported from European parent institutions describe a business model, a regulatory environment and a risk profile that do not match the market they land in.
Coming soonScoring and fraud tools arrive through procurement, not through risk. By the time the second line is asked about them, they are already making decisions.
Coming soonWhat donors expect, what field reality allows, and how to build a control set that survives both an audit and an operating environment that changes weekly.
Coming soonAnnouncements, engagements and speaking.
The firm is registered in Tashkent and open for engagements with financial institutions and humanitarian organisations across Uzbekistan and the wider region.
Tell me what you are dealing with — a framework that is not working, a system nobody can explain, a supervisory finding, a donor audit coming. The first conversation costs nothing and carries no obligation.