Georgia VASP registration & operations See our delivery model
Mon–Fri · 09:00–18:00
FIX THE OPERATING GAP, NOT ONLY THE WORDING

Common Georgia VASP Application Weaknesses—and How to Fix Them

Founders and teams preparing, revising or rescuing a VASP application

A VASP application usually becomes difficult for an understandable reason: the company, product, people, controls and technology were developed in separate workstreams and no one reconciled them into one operating story. The most effective response is not to add more generic text. It is to identify the factual or control gap and repair the business behind the statement.

Weakness 1 — the activity is described by brand language

Terms such as exchange, broker, wallet, OTC desk, marketplace or payment layer can hide who receives the instruction, controls the asset, executes the transaction and contracts with the customer. This ambiguity spreads into the AML framework, provider contracts and financial plan.

Repair: map each service from first customer contact to final settlement. Identify legal entities, control points, wallets and accounts, fiat and virtual-asset legs, fees and every material third party. Classify the facts only after the map is complete.

Weakness 2 — ownership and funding do not reconcile

Common problems include stale corporate extracts, percentages that differ between charts and registers, unexplained intermediary companies, uncertain UBO conclusions, capital arriving from a person not described in the file, or source documents that do not connect to the actual transfer.

Repair: create one dated ownership and funding pack with documents for every layer, a clear UBO analysis, source narrative, bank or transaction evidence and consistency controls. Resolve changes before translation and filing.

Weakness 3 — administrators look qualified on paper but cannot operate the model

A CV is not a governance system. A director may have general business experience yet lack time, access or relevant knowledge of custody, exchange operations, AML escalation, technology and provider oversight. Name-only local appointments create a visible gap between legal responsibility and real authority.

Repair: define responsibilities first, assess candidates against them, allocate reserved matters and system permissions, plan presence and cover, train using the real product, and retain evidence of decisions and competence.

Weakness 4 — the risk assessment is generic

The NBG’s 2024 sector risk update points to weaknesses in AML internal instructions, preventive measures, customer-risk assignment and reassessment, and detection of suspicious or unusual transactions. A downloaded risk matrix that does not identify the applicant’s countries, cash exposure, assets, channels, customers, counterparties and transaction behaviour cannot drive meaningful controls.

Repair: assess inherent risk by product and channel, define control effectiveness, set residual-risk decisions and connect each risk factor to acceptance, EDD, limits, monitoring, review frequency and management information.

Weakness 5 — customer risk does not change when behaviour changes

Initial onboarding data can become stale. A customer may add new corridors, transact through different wallets, increase velocity, interact with higher-risk counterparties or move from a low-risk declared purpose into unexplained behaviour.

Repair: define event-driven triggers and periodic review. Connect transaction and wallet activity to customer-risk reassessment, source requests, enhanced approval, limits and—where required—exit or reporting.

Weakness 6 — blockchain analytics exists but is not governed

A KYT vendor can identify risk indicators, but it does not decide the VASP’s response. Weak implementations use default thresholds, do not distinguish direct from indirect exposure, ignore clustering uncertainty, and have no rules for mixers, privacy-enhancing technology, chain hopping, cross-chain bridges or self-hosted wallets.

Repair: document data sources and limitations; calibrate scenarios to products and customer risk; define hold, reject, investigate and escalation rules; record human decisions; test false positives and missed cases; and report alert quality and backlog to management.

Weakness 7 — source checks stop at fiat

For virtual-asset activity, a bank statement alone may not explain where the crypto came from. The VASP may need evidence of acquisition, wallet ownership or control, transaction history, exchange records, business purpose and the source of wealth supporting the activity.

Repair: create risk-based source-of-funds and source-of-virtual-assets workflows. Specify acceptable evidence, corroboration, escalation, record retention and how blockchain information is reconciled with customer explanations.

Weakness 8 — cash, branch and kiosk risks are treated as an afterthought

Cash reduces the transparency available from bank rails and can enable linked or structured transactions. Physical locations also add video-surveillance, staff-conduct, security, reconciliation, outage and record-retrieval risks. The 2024 NBG risk update treats cash-facing activity and kiosks as requiring elevated attention.

Repair: design location-level limits, linked-transaction logic, customer identification, cash source review, staff escalation, surveillance, daily reconciliation, system-availability stop rules and management reporting before the channel launches.

Weakness 9 — policies and the electronic system disagree

The manual promises four-eye approval, enhanced monitoring or a prohibited-country block, while the system permits a single user, does not create the alert, or cannot retrieve the decision record. This is especially damaging because it can be exposed in a demonstration.

Repair: build a control-to-configuration matrix. For every important rule, identify the system setting, responsible role, test case, output record, exception route and evidence of periodic review.

Weakness 10 — the business plan does not pay for the control environment

High-volume retail or cash activity cannot credibly be supported by a nominal team, thin vendor budget and no assurance or continuity capacity. Conversely, an inflated organisation chart with no hiring plan or cash flow is not more persuasive.

Repair: translate volumes, hours, customers, alerts and locations into workload. Reconcile staff start dates, provider costs, office, security, training and assurance with launch stages and downside scenarios.

Weakness 11 — regulatory responses create new contradictions

A fast answer to an NBG question can accidentally change a product, provider, country or responsibility without updating related annexes. This creates a moving target and weakens management credibility.

Repair: run every response through an impact check covering forms, flows, contracts, risk assessment, policies, system configuration, forecasts, staffing and translation. Keep one approved facts register.

A professional remediation sequence

StepOutput
DiagnoseRequirement-to-evidence gap register and root-cause analysis
DecideFounder decisions on scope, countries, providers, people and risk appetite
BuildWorking governance, control, system or evidence correction
ReconcileUpdated forms, flows, policies, contracts, plan and translations
TestCustomer, transaction, alert, report and demonstration scenarios
CloseApproved evidence pack with owner, date, test and residual risk
PRIMARY LEGAL SOURCES

Official materials used for this guide

These links support the editorial baseline; the explanation above is written for founders and operators. Current consolidated legislation and later official instruments take priority.

CryptoLicense.ge Regulatory Desk Updated: 23 August 2026 Model-specific legal review required