Georgia VASP registration & operations See our delivery model
Mon–Fri · 09:00–18:00
THE OPERATING BASELINE

Georgia VASP Registration Requirements

Registration requirements mapped to the operating model

The Georgian VASP framework functions as an operating-company test. Ownership, administrators, head office, service schemes, providers, systems, staffing, business plan and AML/CFT controls should tell one consistent story and be capable of verification.

Eligibility constraints to resolve before spending heavily

APPLICANT LLC or JSC

The general applicant is a Georgian legal entity established and registered as a limited liability or joint-stock company.

DELIVERY MODEL No VASP agent

Order No. 94/04 prohibits provision of virtual-asset services through an agent.

BUSINESS SCOPE VASP-focused entity

A standard VASP is generally restricted to VASP activity, necessary auxiliary activity and exchange of its own virtual assets.

PRODUCT LIMITS Model-specific restrictions

Examples include the prohibition on lending virtual assets to natural persons and controls on traceability-blocking technology.

SUPERVISORY CAPITAL GEL 150,000–350,000

The minimum depends on the registered services; at least 75% must be composed of primary capital.

1. Confirm that the activity is within the VASP perimeter

Map every customer instruction, asset, fiat leg, wallet/control function, provider and revenue stream. The statutory categories are exchange, transfer, safekeeping/administration, individual portfolio management, trading-platform administration, lending, and ICO/related services. The service must be performed for the benefit of another person.

2. Use an eligible Georgian applicant

The general VASP applicant should be a Georgian LLC or JSC. Corporate documents, decisions, registered/head-office information and contractual roles should match the service scheme. A foreign group entering through a Georgian subsidiary should be prepared to evidence the complete ownership and control chain.

3. Make ownership and control transparent

A significant share includes a direct or indirect holding of 10% or more of the capital or voting rights, as well as an interest that permits significant influence regardless of percentage. Significant owners and UBOs require identification and evidence sufficient to reconstruct who owns and controls the applicant. Business history, financial standing and solvency information should be consistent across natural-person and corporate layers. Nominee, trust or group arrangements need a clear legal and economic explanation.

4. Appoint administrators who can withstand fit-and-proper review

Administrators must meet the relevant knowledge/experience and integrity criteria. The rule addresses educational or management-experience expectations and bars specified criminal, financial and conduct circumstances. Where the only shareholder/partner is also the director, the rule requires at least two directors.

Management is not a signature service. At least one representative authorised to act for the VASP must meet the applicable physical-presence requirement in Georgia, and the people named in the dossier should be able to explain the business, controls and system.

5. Establish a compliant head office and organisation

The head office must be real, documented and suitable for supervisory access. If branches or on-site cash exchange are part of the model, additional premises, branch and video-surveillance requirements apply. The organisation chart and staffing plan should match customer volumes, operating hours, risk, technology and outsourced dependencies.

6. Capitalise the company for the registered services

The minimum supervisory capital is GEL 150,000 for exchange and/or transfer services, GEL 350,000 for a trading platform and GEL 250,000 for other ordinary VASP services. If several services are combined, the highest applicable amount—not the sum—applies. At least 75% must consist of primary-capital elements, and the VASP must remain above the applicable threshold throughout operation.

7. Present a functioning electronic system and risk framework

The application identifies the system, manufacturer, hosting/data location and functionality. The functionality must correspond to the proposed service and is subject to demonstration before registration is completed. The operating framework must also address operational and cyber risk, outsourcing, incidents, business continuity and IT disaster recovery. A newly registered VASP must obtain a qualified independent audit opinion on the framework within 12 months after registration.

8. Connect AML/CFT controls to the product and data

A VASP is an AML/CFT obliged person. The organisational risk assessment and internal instruction should connect customer acceptance, CDD/EDD, beneficial ownership, sanctions/PEP screening, source checks, counterparty VASP controls, blockchain/KYT monitoring, escalation, reporting, records, QA and training to the actual customer journey and system.

9. Build provider relationships into the regulatory file

Service schemes should identify the relevant banks, payment service providers, custodians, liquidity venues, foreign VASPs and other participants. Where foreign VASPs or payment providers are involved, the filing identifies them and their supervisors; regulated-provider contractual relationships also form part of the dossier.

10. Prepare a controlled Georgian-language dossier

Order No. 94/04 requires originals or notarised copies as applicable. Foreign-issued documents must be apostilled and/or legalised unless an exception applies, and appropriately certified Georgian translations are required. Version control matters because a changed provider, administrator, service flow or ownership fact can affect multiple annexes.

11. Treat the three-year plan as regulatory evidence

The business plan must include at least a three-year budget forecast and demonstrate that the applicant can implement appropriate systems, resources and procedures and intends to conduct activity in Georgia. Customer, volume and revenue assumptions should reconcile with staffing, providers, risk controls, system capacity and launch timing.

Transition. Providers registered before the 27 August 2026 amendments must implement the operational-risk and cybersecurity framework by 1 July 2027 and meet the general supervisory-capital requirement by 1 September 2027. Administrative proceedings commenced before the amendment entered into force are excluded under its transitional provision; the effect should be confirmed for the specific application and subsequent operation.

What can turn a filing problem into a refusal risk?

  • Failure to respond to an NBG information, demonstration or access request within the required period.
  • False information in the submitted documentation.
  • A service scheme that does not qualify as a permitted virtual-asset service or does not meet legal requirements.
  • A corrected scheme that becomes materially different from the one originally filed.
  • An electronic system that does not correspond to the filed service scheme when demonstrated.
  • Administrator suitability concerns or a head office/branch that does not satisfy the applicable requirements.
  • Failure to maintain the applicable capital threshold or critical/high-risk deficiencies in the operational-risk and cybersecurity framework.
LEGAL BASIS

Applicable legislation and regulatory materials

Our registration work is mapped to the current Georgian legal framework and the applicant’s actual operating model. Legal texts reproduced in the CryptoLicense.ge legislation library link to the official Matsne source from the relevant legal-text page.

CryptoLicense.ge Legal & Regulatory Team Eligibility, governance and operating requirements are mapped to the final service scheme and current filing facts.