A physical cash or kiosk network is not simply an online exchange with a machine attached. Each location changes customer identification, sanctions and transaction monitoring, cash security, surveillance, staff conduct, receipts, record retrieval, system resilience and the evidence required for supervision.
Exchange through a kiosk is a virtual-asset service
The National Bank’s public VASP guidance expressly includes exchange through kiosks. The applicant should map the customer, cash, virtual-asset and information journey for every channel: staffed branch, automated kiosk, cash desk, website and mobile application.
Locations belong in the registered operating model
Branches and kiosks should not appear after filing as an informal distribution experiment. The application and change process need to identify the locations, rights to use them, responsible staff or service providers, system connection, asset and cash limits, security controls, customer notices and the route by which management can monitor activity.
Surveillance and retention
Cash-facing points are subject to specific video-surveillance requirements. The operating design should provide usable coverage of the customer and transaction area, controlled access to recordings and retention for at least 30 days, while also addressing privacy notices, authorised retrieval and incident preservation. Camera placement and image quality should be tested against the actual counter or kiosk, not approved from a floor plan alone.
Do not operate through a system failure
A branch or kiosk should not provide the service when the required electronic system or control connection is unavailable. Business-continuity procedures must distinguish safe suspension from unsafe manual workarounds. Staff need clear stop rules, customer communication, cash and asset reconciliation, incident escalation and controlled restart.
Cash intensifies AML/CFT and security risk
The risk assessment should consider structuring, rapid repeat transactions, linked customers, third-party cash, stolen identity, sanctions exposure, high-risk wallets, mule behaviour, false receipts, robbery and insider collusion. Customer and transaction limits, enhanced checks, blockchain analytics, exception approval and post-event quality assurance should be configured as one workflow.
What a location file should contain
- Address, ownership/lease and permitted-use evidence.
- Floor plan, camera map, retention and retrieval test.
- Kiosk or terminal identifier, software version and system architecture.
- Responsible personnel, training and access rights.
- Cash loading, collection, limits, reconciliation and discrepancy handling.
- Customer journey, receipts, fees, disclosures and complaint route.
- KYC, sanctions, KYT, linked-transaction and escalation rules.
- Outage, incident, physical-security and controlled-restart procedures.
How we assist
CryptoLicense.ge can integrate location design into the VASP application, AML framework, technology build and demonstration. For an existing registered VASP, we can assess whether a proposed branch or kiosk is a material change and prepare the operational evidence before launch.
Official materials used for this guide
These links support the editorial baseline; the explanation above is written for founders and operators. Current consolidated legislation and later official instruments take priority.