Custody classification depends on practical control over a convertible virtual asset or an instrument enabling control, not on the label attached to the wallet product.
We examine key generation, signing authority, policy engines, recovery, omnibus or segregated accounting, withdrawals, reconciliation, outsourcing and incident response to determine what the Georgian entity actually controls and must evidence.
Regulatory classification
The Georgian VASP perimeter includes safekeeping and/or administration of convertible virtual assets or an instrument enabling control over them. A “non-custodial” label is therefore not conclusive if the operator can practically authorise, recover, redirect or otherwise control customer assets.
- Key and signing authority
- Omnibus or segregated records
- Withdrawal and recovery controls
- Outsourced custody responsibilities
Map every path by which an asset can be moved
The control analysis should cover seed and key creation, MPC or multisignature roles, policy engines, privileged access, recovery procedures, whitelisting, emergency actions and the circumstances in which staff or providers can influence a transfer.
Required custody evidence
A credible custody file links wallet architecture to customer ledgers, ownership records, approval matrices, withdrawal limits, reconciliation, backup and recovery tests, incident logs, provider contracts and responsibility for customer communications.
Principal control risks
Custody failures usually arise from unclear asset-control rights, weak segregation between customer and company assets, inconsistent on-chain and internal records, recovery arrangements that are not tested, or outsourced providers whose responsibilities are not reflected in the VASP’s controls.
“Non-custodial” must be true in the operating architecture
If the company or its provider can restore credentials, approve withdrawals, override policy, redirect transactions or otherwise exercise practical control, the legal analysis must address that capability rather than rely on product terminology.
Supervisory capital
Safekeeping and administration falls within the GEL 250,000 minimum-capital category. If the same VASP also administers a trading platform, the higher GEL 350,000 threshold applies. At least 75% of the applicable minimum must consist of primary capital.
Scope of our engagement
Our custody work can cover perimeter analysis, wallet and key-control mapping, customer-asset segregation, ledger and reconciliation design, withdrawal governance, provider due diligence, recovery and incident procedures, application evidence and control testing. We structure the engagement around the custody architecture actually proposed.
Control map
Identify every person, system and provider able to create, approve, recover or redirect asset movements.
Record integrity
Reconcile on-chain balances, customer entitlements, omnibus sub-ledgers and company holdings with clear ownership evidence.
Resilience evidence
Demonstrate recovery, privileged-access governance, incident handling and provider continuity before launch.
Custody control chain
A practical sequence used to test whether contracts, systems, providers and control ownership describe the same service.
Issues to resolve before filing
No. The analysis turns on actual control. If the operator can authorise, recover, redirect or otherwise exercise practical control over a customer’s virtual assets or the instrument enabling control, the custody perimeter must be assessed.
The assessment can include private keys, seed phrases, signing shares, recovery credentials, policy-engine permissions and other mechanisms that enable a person to exercise effective control. The technical implementation matters more than the marketing label.
The structure should identify customer ownership, wallet and sub-ledger mapping, company versus client balances, transaction history, fees, adjustments and reconciliation. Records should allow a specific customer entitlement to be established promptly and consistently.
Test normal approvals, limits, whitelisting, privileged access, lost-credential recovery, failed signing, emergency suspension, provider outage, ledger reconciliation and incident escalation. Keep evidence of the test, result, owner and remediation.
No automatic conclusion follows from outsourcing. The Georgian VASP still needs to understand and document the provider’s role, contractual allocation of responsibilities, customer disclosures, access rights, monitoring, incident escalation, continuity and the controls retained by the VASP.