Georgia VASP registration & operations See our delivery model
Mon–Fri · 09:00–18:00
REGISTRATION STARTS SUPERVISION

Operating and Maintaining a Georgian VASP

Supervision, change control and operating continuity

NBG registration is the start of a supervised operating cycle. The registered VASP must maintain the people, premises, systems, records and controls supporting its approved service scheme and manage material changes before they create a mismatch with the registration file.

Material-change deadlines should sit inside product and corporate governance

Change category Timing / regulatory treatment
Name or legal form Information and supporting documents are submitted to the NBG within 10 calendar days after the change.
Ordinary registered-address change Generally submitted within 10 calendar days after the change. If the new address will be used for specified on-site cash exchange, the planned change is treated in advance.
New cash-service branch; service stop/new service; service-scheme/component change; website or app change; other material increase in ML/TF risk Written information and the relevant documents are generally submitted at least 30 calendar days before implementation.
Administrator or significant owner / UBO change or addition Planned change is submitted in advance; after complete information/documents are received, the NBG issues consent or a reasoned refusal no later than one month.
Significant-share transactions governed by the ownership-control rule The applicable information/documents are submitted before the change in accordance with the specific ownership-control requirements.

Internal approval should therefore ask a regulatory question before commercial approval: does this change alter an NBG-filed fact, service scheme, participant, channel, ownership/control position or material AML/CFT risk?

Maintain the operating baseline

Governance Fit-and-proper administrators, authorised representation, board oversight and documented decisions.
Georgia presence Compliant head office, applicable representative presence and staff capable of meeting supervisory access requirements.
System integrity Service functionality, records, access, logs, reconciliation and monitoring aligned with the registered scheme.
Supervisory capital Maintain the applicable GEL 150,000, GEL 250,000 or GEL 350,000 threshold, with at least 75% composed of primary capital.
AML/CFT operations CDD/EDD, beneficial ownership, sanctions/PEP, blockchain/KYT monitoring, escalation, reporting and record retention working in live cases.
Provider control Current contracts, due diligence, service monitoring, incidents, exits and replacements assessed against the registered scheme.
Evidence retrieval Management and the NBG should be able to retrieve and understand customer, transaction, alert, report, provider and change records.

Do not let the company drift away from its registered scheme

Product teams can change a VASP faster than the board notices: a new asset, country, wallet flow, PSP, app, website, custody leg or outsourced component can alter the regulatory facts. Keep a change register tied to the service schemes and require legal/compliance review before implementation.

Operational continuity is a registration issue

The head office, responsible people and electronic system must remain available for supervision. The risk framework must address operational and cyber risk, outsourcing, business continuity, IT disaster recovery, incidents and reporting. Critical and connected systems require annual penetration testing, other systems require risk-based testing at least every three years, and vulnerability scanning is required at least twice annually. Failure of core supervisory or monitoring capability is not merely an IT incident; it can create enforcement and registration risk.

Transition dates for existing VASPs. The operational-risk and cybersecurity framework must be implemented by 1 July 2027. The general supervisory-capital requirement must be met by 1 September 2027. A newly registered VASP must obtain the framework and independent audit opinion within 12 months after registration.

Inactivity can put the registration at risk

Order No. 94/04 includes deregistration grounds where a VASP does not provide virtual-asset service within six months after registration or ceases activity for more than six months. Other grounds include false registration information, specified repeated reporting failures, systematic/material rule breaches, lack of the required unusual-transaction detection system, obstruction of inspection, failure to provide requested information, a missing/non-compliant head office, operation outside the filed service scheme and failure to continue meeting registration requirements.

ENFORCEMENT EXPOSURE

Monetary penalties can aggregate well beyond one headline fine.

The current framework includes GEL 20,000 for operating outside the NBG-agreed service scheme, GEL 10,000 for obstructing an inspection, GEL 7,000 for each missing inspection item and GEL 5,000 for each unfulfilled written instruction. Separate client-, transaction-, report- or breach-based failures can accumulate, and repeated violations may double the fine.

NBG published example: GEL 465,000 aggregate VASP fine

The practical lesson is to manage controls as operating evidence: prevention, monitoring, escalation, records and remediation must work consistently across the customer and transaction population.

See our VASP supervision and enforcement analysis →

The first 90 days should be treated as controlled production

  • Confirm staff permissions and segregation of duties against approved roles.
  • Sample real onboarding files, sanctions/PEP results and beneficial-ownership decisions.
  • Review KYT/blockchain alerts, case ageing and suspicious-activity escalation.
  • Reconcile customer obligations, fiat/virtual-asset movements and system records.
  • Test regulatory and management reports before deadlines arrive.
  • Confirm capital adequacy and complete scheduled penetration tests, vulnerability scans and independent assurance.
  • Check provider incidents, service levels, complaints, security events and open remediation.
  • Compare actual customers, countries, volumes and products with the business plan and risk assessment.

Board information should show both risk and capacity

Useful management information includes high-risk customers, onboarding exceptions, alert backlog/ageing, blocked or rejected transactions, suspicious-activity decisions, reconciliation breaks, provider incidents, complaints, staffing capacity, training, system issues and overdue remediation. Board oversight is weak if it receives policy confirmations but cannot see operational pressure.

LEGAL BASIS

Applicable legislation and regulatory materials

Our registration work is mapped to the current Georgian legal framework and the applicant’s actual operating model. Legal texts reproduced in the CryptoLicense.ge legislation library link to the official Matsne source from the relevant legal-text page.

CryptoLicense.ge Legal & Regulatory Team Change-control and ongoing-compliance obligations are applied to the VASP’s live registered scheme and current operating facts.