A Georgian VASP’s AML/CFT framework is an operating chain. Risk assessment determines who may be accepted and under what conditions; onboarding establishes identity and expected activity; monitoring tests whether reality remains consistent; investigations and reporting handle exceptions; and management information, testing and remediation show whether the system remains effective.
The complete control lifecycle
1. Risk assessment sets the control architecture
Assess products, customer and beneficial-owner types, countries, channels, assets, custody, cash, counterparties, transaction behaviour and technology. Distinguish inherent risk, the effectiveness of controls and residual risk. Management should approve prohibited activity, restricted activity, escalation thresholds and the capacity required to monitor the accepted business.
The NBG’s 2024 VASP sector risk update gives practical direction. It identifies customer-risk classification and reassessment, preventive measures and unusual or suspicious transaction detection as areas where applicant material has shown weaknesses. It also highlights the opacity and speed of virtual-asset transfers, self-hosted addresses, DeFi exposure, cash and kiosks, anonymity-enhancing assets, mixers or tumblers and cross-chain activity.
2. Onboarding must establish a usable customer story
KYC and KYB identify and verify the customer, legal existence, representatives, ownership and beneficial owners. The VASP also needs purpose, expected activity, countries, products, counterparties, source and economic rationale. Those facts are not administrative fields: they become the baseline against which later behaviour is monitored.
Enhanced due diligence should follow defined risk triggers. High-risk relationships need documented approval, stronger corroboration, appropriate source evidence, limits and review frequency. A customer should not remain “low risk” merely because the onboarding system never revisits the score.
3. Source of funds and source of virtual assets are related but distinct
For fiat, evidence may include income, business revenue, sale proceeds, investment records or bank history. For virtual assets, the VASP may also need acquisition records, exchange statements, wallet ownership or control, transaction history, mining or staking evidence and a coherent explanation of how the assets reached the relevant address. Source of wealth can be required to understand the broader economic capacity behind higher-risk activity.
4. Sanctions, PEP and adverse information controls need decisions
Screen customers, beneficial owners, representatives, relevant counterparties and wallet exposure using current data. Define true-match resolution, escalation, restriction, rejection and periodic or event-driven rescreening. A matching tool is not the control unless trained people can investigate, decide and preserve the basis.
5. Blockchain analytics and transaction monitoring work together
KYT can identify exposure to sanctioned or high-risk wallets, darknet or fraud typologies, mixers, privacy-enhancing services and complex movement across chains. Monitoring should distinguish direct and indirect exposure, recognise data and clustering uncertainty, and combine blockchain indicators with customer profile, amounts, velocity, counterparties and stated purpose.
Particular attention may be required where a customer repeatedly uses multiple hops, chain hopping or cross-chain bridges to obscure origin; routes assets through mixers or tumblers; receives from unexplained high-risk wallets; structures cash or kiosk transactions; or cannot substantiate how virtual assets were obtained. The response should be risk-based and legally grounded, not automatic panic or vendor-score outsourcing.
6. Alerts become investigations, not a backlog
Each scenario needs an owner, priority, service level and disposition standard. Investigators should have customer, beneficial-owner, transaction, wallet, device, source and prior-case context. Decisions to clear, request information, restrict, reject, exit or report should be consistent with policy and preserved in an audit trail.
7. Suspicious-activity reporting and confidentiality
The escalation route should protect confidentiality, permit timely consideration by the designated function and support reporting to the competent authority when legal criteria are met. Staff should understand that a commercial explanation or successful transaction does not by itself resolve a financial-crime concern.
8. Records and management information show control effectiveness
Retain the inputs, screenings, blockchain analysis, correspondence, decisions, approvals, reports and system logs needed to reconstruct the relationship and transaction. Management information should show high-risk customers, alerts received and aged, reporting decisions, overrides, restrictions, provider failures, false-positive trends, staffing capacity, repeat counterparties and remediation.
9. Testing and remediation close the loop
Quality assurance should sample risk, not only completed fields. Test high-risk customers, source decisions, sanctions matches, KYT alerts, suspicious-activity cases, self-hosted-wallet transfers and cash transactions. Internal assurance should identify root cause, owner, due date, corrective action and retest. Repeated exceptions should change risk appetite, training, staffing or system configuration.
What the NBG application should make visible
- An organisational risk assessment specific to the proposed services.
- Internal instructions that explain duties, decisions and escalation.
- Customer-risk methodology and reassessment triggers.
- Configured screening, monitoring and case workflows.
- Source-of-funds and source-of-virtual-assets evidence standards.
- Controls for counterparties, self-hosted wallets and required transfer information.
- Management oversight, record retrieval, testing and remediation.
- A functioning electronic-system demonstration using realistic scenarios.
Legislation and regulatory materials
Our regulatory assessments and implementation work are based on the Georgian legislation and National Bank of Georgia materials below. Legal texts available in our legislation library open on CryptoLicense.ge; the official Matsne source is linked at the bottom of each legal-text page.
- Law of Georgia on Facilitating the Prevention of Money Laundering and the Financing of Terrorism
- NBG Governor Order No. 94/04 — VASP registration, cancellation and regulation
- NBG — Internal Control Compliance Questionnaire for VASP applicants
- National Bank of Georgia — Update of the ML/TF Risk Assessment of the VASP Sector (2024)
- Georgian virtual-asset transfer information amendment
- NBG Governor Order No. 133/04 — VASP fines and enforcement
- NBG — published GEL 465,000 VASP enforcement case