An NBG VASP application should describe one operating model consistently across the prescribed forms, ownership and management evidence, service-flow schemes, electronic system, business plan and AML/CFT framework.
A Georgian VASP filing is not a bundle of corporate certificates. Order No. 94/04 requires prescribed application forms together with evidence on the applicant, administrators, significant and beneficial owners, head office, digital channels, providers, service flows, electronic system, three-year business plan, organisation and AML/CFT controls. The National Bank may request additional information, a system demonstration and access to the applicant’s head office or branches before deciding the application.
1. Regulatory classification must match the actual service flow
The application should start with what the Georgian company will actually do for another person: exchange, transfer, custody or administration, individual portfolio management, trading-platform administration, lending, ICO activity or a combination of those services. Commercial labels such as “broker”, “wallet”, “remittance” or “platform” are not enough.
Order No. 94/04 requires a schematic description of the movement of information, virtual assets and funds from the beginning to the end of each service, identifying the relevant participants. If several services are planned, a separate scheme is required for each service; where the flow differs by virtual asset, that difference also needs to be shown. Foreign VASPs and payment-service providers involved in the scheme must be identified together with their supervisory authorities.
2. Ownership and administrators form part of the regulatory case
The NBG file needs a transparent ownership chain through significant direct and indirect owners to beneficial owners, together with identity, financial-background and suitability information. Administrators and persons responsible for managing the VASP activity must be supported by education and/or relevant experience evidence.
Criminal-record evidence is jurisdiction-sensitive and time-sensitive. The application rules look back across countries of residence during the preceding ten years, while certificate freshness differs for Georgian and foreign documents. These dependencies should be scheduled before the intended filing date rather than collected at random. See the VASP application documents checklist for the filing sequence.
3. The head office, system and digital channels must exist as an operating environment
The applicant must evidence its right to use the head office and, where relevant, branches. Website ownership or usage rights and application details must also be documented. For the electronic system, the filing includes manufacturer and system information, where customer obligations and transaction data are recorded, and evidence that functionality corresponds to the planned service.
4. The three-year business plan must reconcile with the organisation
The business plan must include at least a three-year budget forecast and demonstrate that the applicant can implement appropriate systems, resources and procedures while carrying out the activity in Georgia. The organisational structure should identify head-office units, their functions and employee numbers, and include a development plan for the first six months after operations begin.
Forecast customers, transaction volumes, fees, providers and channels should therefore reconcile with staffing, technology capacity, compliance workload and operating expenditure. A commercially ambitious forecast paired with a materially under-resourced operating structure creates an obvious credibility gap.
5. AML/CFT documentation must describe the same business
The application includes the internal AML/CFT instruction or policy-procedure framework and the organisational ML/TF risk assessment, together with the prescribed declaration on the compliance-control system. These documents should use the same customer types, countries, products, channels, providers and transaction flows described elsewhere in the application.
The AML file should not be drafted as an independent template and reconciled later. Service architecture determines risk architecture.
6. Registration risk is broader than missing paperwork
Order No. 94/04 gives the NBG refusal grounds that go directly to operating credibility. Examples include:
- false information in the filing;
- a service scheme that does not fall within the statutory VASP perimeter or otherwise fails legal requirements;
- a corrected scheme that becomes materially different from the model originally filed;
- an electronic system that does not correspond to the service scheme;
- a head office or branch that cannot meet the applicable requirements;
- administrator-related concerns affecting effective, safe and prudent management or business continuity; and
- failure to respond within the applicable information or deficiency-remediation period.
7. Control legalisation, translation and version history
Documents are generally filed as originals or notarised copies. Foreign-issued documents may require apostille or legalisation unless an exception applies, and the prescribed documentation must be supported by duly certified Georgian translations. Translation should therefore begin from approved source versions, not moving drafts.
A controlled evidence matrix should identify the source document, final Georgian version, responsible owner and the exact application statement it supports. Responses to NBG questions should be reconciled against the whole dossier before submission.
8. Rehearse the regulator-facing operating story
Before filing, an administrator should be able to explain one representative customer journey from onboarding through funding, transaction or transfer, AML/sanctions/KYT review, settlement, reconciliation, record retention and reporting—and show the relevant system evidence. The same exercise should be run for an adverse event such as a sanctions hit, blockchain alert, failed withdrawal, provider outage or reconciliation break.
Build the dossier in the same order the operating model has to make sense
Each layer should support the next; none should describe a different business.