A serious VASP document checklist should show the prescribed form, legal purpose, issuer, freshness, translation status and the filing statement each record supports. The exact dossier varies by ownership, administrators, services, countries, branches, cash activity, providers and technology.
The core NBG filing structure
| Filing component | Purpose |
|---|---|
| Annex 1 — registration form | Applicant, contact/head-office and core registration information. |
| Annex 2 — virtual-asset services | The VASP services the applicant proposes to provide. |
| Annex 3 — administrators | Information for each administrator. |
| Annex 4 — significant owners / UBOs | Direct and indirect significant ownership and beneficial-ownership information. |
| Annex 5 — correspondence table | Maps the submitted evidence to the prescribed registration documentation. |
| Annex 7 — branches, where applicable | Detailed information on branches used in the proposed operating model. |
Corporate applicant and ownership evidence
Prepare the current Georgian registry extract and, for a JSC, the relevant shareholder-register evidence. Reconstruct the chain from the applicant through direct and indirect significant owners to the UBOs with identity/corporate records and documents that substantiate beneficial ownership. A significant share includes 10% or more of capital or voting rights and may also arise through significant influence regardless of percentage. The record should reflect the position at the date of the NBG application.
Administrator, owner and UBO background records
The dossier includes administrator identity plus education and work-experience evidence relevant to management of the proposed VASP activity. For administrators and direct/indirect significant owners and UBOs, the rule also calls for business-history and financial-standing information.
Criminal-record certificates can determine the filing date.
Certificates are required from the competent authority of every country in which the relevant administrator, significant owner or UBO was resident during the previous 10 years. At submission, a Georgian criminal-record certificate may be no more than 15 calendar days old; a foreign certificate may be no more than 60 calendar days old.
Official fee and applicant records
- Proof of payment of the GEL 5,000 VASP registration fee.
- Current applicant registry extract reflecting all changes at the application date.
- Corporate and governance evidence required to support the applicant’s structure and authorised decision-making.
Supervisory-capital evidence
Map each proposed activity to the applicable minimum—GEL 150,000 for exchange and/or transfer, GEL 350,000 for a trading platform and GEL 250,000 for other ordinary VASP services. The capital file should evidence the source, form and availability of the capital, distinguish primary from secondary elements and demonstrate that at least 75% of the minimum is primary capital. Where several services are proposed, document why the highest applicable threshold governs.
Website, application, head office and branch evidence
Provide evidence of the applicant’s ownership or right to use the service website(s), together with the URLs. If customers use an application, identify the application, placement/distribution location, manufacturer and manufacturer website. Rights to the real property used for the head office and branches are supported by a real-estate registry extract. Branch information is filed where applicable.
Where the model includes on-site cash exchange, the dossier also needs the applicable internal/external video-surveillance evidence for the head office and branches.
Service schemes — one of the highest-value parts of the file
The schematic description should show the complete movement of information, virtual assets and fiat funds from service initiation to completion and identify all relevant participants. If several services are planned, a separate scheme is submitted for each service. If the flow differs by virtual asset, separate asset-level schemes are needed; assets with identical schemes can be grouped and identified.
Providers and contractual relationships
If foreign VASPs or payment service providers participate in the scheme, list them and identify their supervisory authorities. The filing also includes information on contractual relationships with relevant NBG-licensed/registered or foreign-licensed/registered VASPs and payment providers. Provider due diligence should therefore be performed before names are embedded across the dossier.
Electronic-system evidence and demonstration readiness
The file identifies the system manufacturer, manufacturer website, system name and the location of customer-obligation and virtual-asset operation data. The manufacturer’s registry extract is part of the prescribed evidence. Most importantly, the system functionality must correspond to the proposed services and be demonstrable to the NBG before registration is completed.
Operational-risk, cybersecurity and assurance file
Prepare the operational-risk and cybersecurity framework, outsourcing and incident arrangements, business-continuity plan and embedded IT disaster-recovery plan. The compliance calendar should provide for annual penetration testing of critical and connected systems, risk-based testing of other systems at least every three years, additional testing after material critical-infrastructure changes and vulnerability scanning at least twice each year. A newly registered VASP must obtain a qualified, independent and current audit opinion on the framework within 12 months after registration.
Operational records, incident registers and consolidated management data should be capable of real-time retrieval. Versions of the risk framework must be retained for eight years after the VASP ceases providing services.
Three-year business plan and organisational structure
The business plan includes at least the next three years of budget forecasts and should demonstrate appropriate systems, resources and procedures and planned activity in Georgia. The organisational structure covers head-office units, functions and employee numbers and a development plan for the first six months after activity begins; branch functions are included where relevant.
AML/CFT documentation
The prescribed file includes the internal AML/CFT instruction and the organisational ML/TF risk assessment. The NBG may request information in questionnaire form in place of or in addition to the internal instruction and can review the material substantively on a risk-based basis. The application also contains the prescribed statement concerning implementation of the compliance-control system.
Foreign documents and Georgian translation
Documents are submitted as originals or notarised copies as required. Foreign-issued documents must be apostilled and/or legalised unless the law provides otherwise, and an appropriately certified Georgian translation is submitted. Translation should follow legal and factual sign-off; translating unstable drafts increases cost and version risk.
Minimum data-room control fields
| Control field | Why it matters |
|---|---|
| Requirement / annex reference | Shows what legal statement the document supports. |
| Responsible owner / external issuer | Makes collection and remediation accountable. |
| Jurisdiction / issue date / expiry | Controls freshness, especially criminal and corporate records. |
| Apostille / legalisation / translation | Prevents a formally incomplete foreign-document package. |
| Approved version / hash or version date | Stops superseded policies, schemes and contracts entering the filing. |
| Cross-document consistency | Tests names, owners, providers, services, volumes, roles and system facts across the complete dossier. |
Applicable legislation and regulatory materials
Our registration work is mapped to the current Georgian legal framework and the applicant’s actual operating model. Legal texts reproduced in the CryptoLicense.ge legislation library link to the official Matsne source from the relevant legal-text page.