Georgia VASP registration & operations See our delivery model
Mon–Fri · 09:00–18:00
FROM POLICY TO WORKING CONTROL

AML/CFT Obligations for Georgian VASPs

VASP founders, administrators and compliance teams

A Georgian VASP’s AML/CFT framework is an operating chain. Risk assessment determines who may be accepted and under what conditions; onboarding establishes identity and expected activity; monitoring tests whether reality remains consistent; investigations and reporting handle exceptions; and management information, testing and remediation show whether the system remains effective.

The complete control lifecycle

Risk AssessmentOnboardingKYC/KYBUBOSoF/SoVASanctions & PEPKYTMonitoringAlertsInvestigationReportingRecordsManagement InformationTestingRemediation

1. Risk assessment sets the control architecture

Assess products, customer and beneficial-owner types, countries, channels, assets, custody, cash, counterparties, transaction behaviour and technology. Distinguish inherent risk, the effectiveness of controls and residual risk. Management should approve prohibited activity, restricted activity, escalation thresholds and the capacity required to monitor the accepted business.

The NBG’s 2024 VASP sector risk update gives practical direction. It identifies customer-risk classification and reassessment, preventive measures and unusual or suspicious transaction detection as areas where applicant material has shown weaknesses. It also highlights the opacity and speed of virtual-asset transfers, self-hosted addresses, DeFi exposure, cash and kiosks, anonymity-enhancing assets, mixers or tumblers and cross-chain activity.

2. Onboarding must establish a usable customer story

KYC and KYB identify and verify the customer, legal existence, representatives, ownership and beneficial owners. The VASP also needs purpose, expected activity, countries, products, counterparties, source and economic rationale. Those facts are not administrative fields: they become the baseline against which later behaviour is monitored.

Enhanced due diligence should follow defined risk triggers. High-risk relationships need documented approval, stronger corroboration, appropriate source evidence, limits and review frequency. A customer should not remain “low risk” merely because the onboarding system never revisits the score.

3. Source of funds and source of virtual assets are related but distinct

For fiat, evidence may include income, business revenue, sale proceeds, investment records or bank history. For virtual assets, the VASP may also need acquisition records, exchange statements, wallet ownership or control, transaction history, mining or staking evidence and a coherent explanation of how the assets reached the relevant address. Source of wealth can be required to understand the broader economic capacity behind higher-risk activity.

4. Sanctions, PEP and adverse information controls need decisions

Screen customers, beneficial owners, representatives, relevant counterparties and wallet exposure using current data. Define true-match resolution, escalation, restriction, rejection and periodic or event-driven rescreening. A matching tool is not the control unless trained people can investigate, decide and preserve the basis.

5. Blockchain analytics and transaction monitoring work together

KYT can identify exposure to sanctioned or high-risk wallets, darknet or fraud typologies, mixers, privacy-enhancing services and complex movement across chains. Monitoring should distinguish direct and indirect exposure, recognise data and clustering uncertainty, and combine blockchain indicators with customer profile, amounts, velocity, counterparties and stated purpose.

Particular attention may be required where a customer repeatedly uses multiple hops, chain hopping or cross-chain bridges to obscure origin; routes assets through mixers or tumblers; receives from unexplained high-risk wallets; structures cash or kiosk transactions; or cannot substantiate how virtual assets were obtained. The response should be risk-based and legally grounded, not automatic panic or vendor-score outsourcing.

6. Alerts become investigations, not a backlog

Each scenario needs an owner, priority, service level and disposition standard. Investigators should have customer, beneficial-owner, transaction, wallet, device, source and prior-case context. Decisions to clear, request information, restrict, reject, exit or report should be consistent with policy and preserved in an audit trail.

7. Suspicious-activity reporting and confidentiality

The escalation route should protect confidentiality, permit timely consideration by the designated function and support reporting to the competent authority when legal criteria are met. Staff should understand that a commercial explanation or successful transaction does not by itself resolve a financial-crime concern.

8. Records and management information show control effectiveness

Retain the inputs, screenings, blockchain analysis, correspondence, decisions, approvals, reports and system logs needed to reconstruct the relationship and transaction. Management information should show high-risk customers, alerts received and aged, reporting decisions, overrides, restrictions, provider failures, false-positive trends, staffing capacity, repeat counterparties and remediation.

9. Testing and remediation close the loop

Quality assurance should sample risk, not only completed fields. Test high-risk customers, source decisions, sanctions matches, KYT alerts, suspicious-activity cases, self-hosted-wallet transfers and cash transactions. Internal assurance should identify root cause, owner, due date, corrective action and retest. Repeated exceptions should change risk appetite, training, staffing or system configuration.

What the NBG application should make visible

  • An organisational risk assessment specific to the proposed services.
  • Internal instructions that explain duties, decisions and escalation.
  • Customer-risk methodology and reassessment triggers.
  • Configured screening, monitoring and case workflows.
  • Source-of-funds and source-of-virtual-assets evidence standards.
  • Controls for counterparties, self-hosted wallets and required transfer information.
  • Management oversight, record retrieval, testing and remediation.
  • A functioning electronic-system demonstration using realistic scenarios.
LEGAL BASIS

Legislation and regulatory materials

Our regulatory assessments and implementation work are based on the Georgian legislation and National Bank of Georgia materials below. Legal texts available in our legislation library open on CryptoLicense.ge; the official Matsne source is linked at the bottom of each legal-text page.

CryptoLicense.ge Legal & Regulatory Team Legal review: 24 August 2026 Model-specific legal review required