NBG registration is the start of a supervised operating cycle. The registered VASP must maintain the people, premises, systems, records and controls supporting its approved service scheme and manage material changes before they create a mismatch with the registration file.
Material-change deadlines should sit inside product and corporate governance
| Change category | Timing / regulatory treatment |
|---|---|
| Name or legal form | Information and supporting documents are submitted to the NBG within 10 calendar days after the change. |
| Ordinary registered-address change | Generally submitted within 10 calendar days after the change. If the new address will be used for specified on-site cash exchange, the planned change is treated in advance. |
| New cash-service branch; service stop/new service; service-scheme/component change; website or app change; other material increase in ML/TF risk | Written information and the relevant documents are generally submitted at least 30 calendar days before implementation. |
| Administrator or significant owner / UBO change or addition | Planned change is submitted in advance; after complete information/documents are received, the NBG issues consent or a reasoned refusal no later than one month. |
| Significant-share transactions governed by the ownership-control rule | The applicable information/documents are submitted before the change in accordance with the specific ownership-control requirements. |
Internal approval should therefore ask a regulatory question before commercial approval: does this change alter an NBG-filed fact, service scheme, participant, channel, ownership/control position or material AML/CFT risk?
Maintain the operating baseline
Do not let the company drift away from its registered scheme
Product teams can change a VASP faster than the board notices: a new asset, country, wallet flow, PSP, app, website, custody leg or outsourced component can alter the regulatory facts. Keep a change register tied to the service schemes and require legal/compliance review before implementation.
Operational continuity is a registration issue
The head office, responsible people and electronic system must remain available for supervision. The risk framework must address operational and cyber risk, outsourcing, business continuity, IT disaster recovery, incidents and reporting. Critical and connected systems require annual penetration testing, other systems require risk-based testing at least every three years, and vulnerability scanning is required at least twice annually. Failure of core supervisory or monitoring capability is not merely an IT incident; it can create enforcement and registration risk.
Inactivity can put the registration at risk
Order No. 94/04 includes deregistration grounds where a VASP does not provide virtual-asset service within six months after registration or ceases activity for more than six months. Other grounds include false registration information, specified repeated reporting failures, systematic/material rule breaches, lack of the required unusual-transaction detection system, obstruction of inspection, failure to provide requested information, a missing/non-compliant head office, operation outside the filed service scheme and failure to continue meeting registration requirements.
Monetary penalties can aggregate well beyond one headline fine.
The current framework includes GEL 20,000 for operating outside the NBG-agreed service scheme, GEL 10,000 for obstructing an inspection, GEL 7,000 for each missing inspection item and GEL 5,000 for each unfulfilled written instruction. Separate client-, transaction-, report- or breach-based failures can accumulate, and repeated violations may double the fine.
The practical lesson is to manage controls as operating evidence: prevention, monitoring, escalation, records and remediation must work consistently across the customer and transaction population.
The first 90 days should be treated as controlled production
- Confirm staff permissions and segregation of duties against approved roles.
- Sample real onboarding files, sanctions/PEP results and beneficial-ownership decisions.
- Review KYT/blockchain alerts, case ageing and suspicious-activity escalation.
- Reconcile customer obligations, fiat/virtual-asset movements and system records.
- Test regulatory and management reports before deadlines arrive.
- Confirm capital adequacy and complete scheduled penetration tests, vulnerability scans and independent assurance.
- Check provider incidents, service levels, complaints, security events and open remediation.
- Compare actual customers, countries, volumes and products with the business plan and risk assessment.
Board information should show both risk and capacity
Useful management information includes high-risk customers, onboarding exceptions, alert backlog/ageing, blocked or rejected transactions, suspicious-activity decisions, reconciliation breaks, provider incidents, complaints, staffing capacity, training, system issues and overdue remediation. Board oversight is weak if it receives policy confirmations but cannot see operational pressure.
Applicable legislation and regulatory materials
Our registration work is mapped to the current Georgian legal framework and the applicant’s actual operating model. Legal texts reproduced in the CryptoLicense.ge legislation library link to the official Matsne source from the relevant legal-text page.