Georgia VASP registration & operations See our delivery model
Mon–Fri · 09:00–18:00
BUSINESS-MODEL IMPLEMENTATION

Crypto Custody and Wallet Services in Georgia

VASP legal, compliance and technology team working through an implementation plan

Crypto Custody and Wallet Services in Georgia

Custody classification depends on practical control over a convertible virtual asset or an instrument enabling control, not on the label attached to the wallet product.

We examine key generation, signing authority, policy engines, recovery, omnibus or segregated accounting, withdrawals, reconciliation, outsourcing and incident response to determine what the Georgian entity actually controls and must evidence.

For custodians, wallet operators and infrastructure teams

Regulatory classification

The Georgian VASP perimeter includes safekeeping and/or administration of convertible virtual assets or an instrument enabling control over them. A “non-custodial” label is therefore not conclusive if the operator can practically authorise, recover, redirect or otherwise control customer assets.

  • Key and signing authority
  • Omnibus or segregated records
  • Withdrawal and recovery controls
  • Outsourced custody responsibilities
Project team reviewing Georgian VASP implementation evidence
Compliance and technology specialists reviewing operational controls

Map every path by which an asset can be moved

The control analysis should cover seed and key creation, MPC or multisignature roles, policy engines, privileged access, recovery procedures, whitelisting, emergency actions and the circumstances in which staff or providers can influence a transfer.

Required custody evidence

A credible custody file links wallet architecture to customer ledgers, ownership records, approval matrices, withdrawal limits, reconciliation, backup and recovery tests, incident logs, provider contracts and responsibility for customer communications.

Principal control risks

Custody failures usually arise from unclear asset-control rights, weak segregation between customer and company assets, inconsistent on-chain and internal records, recovery arrangements that are not tested, or outsourced providers whose responsibilities are not reflected in the VASP’s controls.

CONTROL RISK

“Non-custodial” must be true in the operating architecture

If the company or its provider can restore credentials, approve withdrawals, override policy, redirect transactions or otherwise exercise practical control, the legal analysis must address that capability rather than rely on product terminology.

Supervisory capital

Safekeeping and administration falls within the GEL 250,000 minimum-capital category. If the same VASP also administers a trading platform, the higher GEL 350,000 threshold applies. At least 75% of the applicable minimum must consist of primary capital.

Scope of our engagement

Our custody work can cover perimeter analysis, wallet and key-control mapping, customer-asset segregation, ledger and reconciliation design, withdrawal governance, provider due diligence, recovery and incident procedures, application evidence and control testing. We structure the engagement around the custody architecture actually proposed.

Control map

Identify every person, system and provider able to create, approve, recover or redirect asset movements.

Record integrity

Reconcile on-chain balances, customer entitlements, omnibus sub-ledgers and company holdings with clear ownership evidence.

Resilience evidence

Demonstrate recovery, privileged-access governance, incident handling and provider continuity before launch.

OPERATING MODEL

Custody control chain

A practical sequence used to test whether contracts, systems, providers and control ownership describe the same service.

01 Client onboarding
02 Wallet/key allocation
03 Approval & signing
04 Blockchain settlement
05 Ledger reconciliation
06 Recovery & incident response

Issues to resolve before filing

No. The analysis turns on actual control. If the operator can authorise, recover, redirect or otherwise exercise practical control over a customer’s virtual assets or the instrument enabling control, the custody perimeter must be assessed.

The assessment can include private keys, seed phrases, signing shares, recovery credentials, policy-engine permissions and other mechanisms that enable a person to exercise effective control. The technical implementation matters more than the marketing label.

The structure should identify customer ownership, wallet and sub-ledger mapping, company versus client balances, transaction history, fees, adjustments and reconciliation. Records should allow a specific customer entitlement to be established promptly and consistently.

Test normal approvals, limits, whitelisting, privileged access, lost-credential recovery, failed signing, emergency suspension, provider outage, ledger reconciliation and incident escalation. Keep evidence of the test, result, owner and remediation.

No automatic conclusion follows from outsourcing. The Georgian VASP still needs to understand and document the provider’s role, contractual allocation of responsibilities, customer disclosures, access rights, monitoring, incident escalation, continuity and the controls retained by the VASP.

LEGAL BASIS

Primary legal and regulatory references

CryptoLicense.ge Legal & Regulatory Team Final classification is confirmed against the client’s actual operating model before filing

Build for registration. Operate for supervision.