Georgia VASP registration & operations See our delivery model
Mon–Fri · 09:00–18:00
REGISTRATION BEGINS SUPERVISION

NBG Supervision and Enforcement for Georgian VASPs

Boards, administrators, compliance officers and investors

Registration places the Georgian VASP inside a continuing supervisory relationship. The National Bank can test whether the people, premises, systems, customer files, transactions, reports and management decisions still match the registered operating model, and it can require correction or apply measures when they do not.

What continuing supervision is designed to establish

The NBG’s task is not limited to confirming that policies remain on file. Supervision can examine whether owners and administrators remain suitable, whether the real products and countries match the registered model, whether the head office and responsible people remain available, and whether AML/CFT controls identify and manage risk in live activity.

For management, the practical standard is reproducibility. A responsible person should be able to retrieve a customer file, reconstruct a transaction, explain a wallet-risk decision, show the alert and investigation history, evidence any report, produce management information and demonstrate how a weakness was corrected.

Information requests, access and inspection

The supervisory framework permits the NBG to request information and records, inspect and access the relevant electronic system, and issue written instructions or additional requirements. An efficient response starts with a current evidence index, named owners and controlled facts. Last-minute document creation increases the risk of contradictions or incomplete records.

AML/CFT supervision follows the risk

The NBG’s 2024 VASP risk update describes a risk-based focus on organisational risk assessments, AML/CFT procedures, transaction-monitoring technology, customer-risk assignment and reassessment, unusual-transaction detection and management of virtual-asset typologies. Cash and kiosk activity, anonymity-enhancing tools, mixers, high-risk wallets and cross-chain movement should be addressed where relevant to the model.

The sanctions framework has evolved

NBG Governor Order No. 133/04 establishes the rules for determining, imposing and enforcing monetary fines on VASPs and administrators. Order No. 204/04 of 24 August 2026 introduced more granular penalties for departures from the agreed service scheme, inspection failures, unfulfilled written instructions, stablecoin reporting and other supervisory breaches.

The framework also permits non-monetary measures. Depending on seriousness, repetition and risk, the NBG may restrict operations, suspend or remove administrators, prohibit distributions or bonuses, require a controlling shareholder to relinquish control, or cancel registration. Repeated breaches may double the applicable monetary fine.

ENFORCEMENT EXPOSURE

When a Georgian VASP can face a GEL 20,000 fine

Order No. 133/04 classifies several failures as especially serious. A GEL 20,000 penalty can apply to a single specified control failure; it should not be read as the maximum exposure of an inspection.

GEL 20,000 No DLT-based unusual-transaction monitoring system, or a system functioning with material deficiencies.
GEL 20,000 Failure to perform or update the organisational and, where applicable, group-wide AML/CFT risk assessment.
GEL 20,000 No required electronic operational-record system, or failure to meet the transaction recording, logging and retrieval requirements of Order No. 94/04.
GEL 20,000 Providing virtual-asset services through an agent, contrary to Order No. 94/04.

Other penalties can apply per client, per transaction, per report, per requested document or per separate breach. The May 2025 amendment also allows the NBG, depending on the seriousness of AML/CFT breaches, to use supervisory sanctions such as restrictions on operations, administrator measures or deregistration instead of or after monetary fines.

2026 enforcement exampleFine
Operating contrary to the service scheme agreed with the NBGGEL 20,000
Each inspection document or item not supplied by the deadlineGEL 7,000
Obstructing an inspectionGEL 10,000
Each unfulfilled NBG written instructionGEL 5,000
Each missing, late, inaccurate or incomplete stablecoin monthly reportGEL 1,000

Stablecoin-specific violations can reach GEL 50,000 per occurrence. The applicable provision, facts and repetition history should be confirmed before quantifying exposure.

Published NBG example: GEL 465,000 aggregate fine

The NBG published an enforcement case in which SHER888 LLC was fined GEL 465,000 across multiple findings. One component alone was GEL 264,000 for 528 record-retention violations at GEL 500 each. View the NBG enforcement notice.

Registration cancellation is an operating risk

False or misleading information, obstruction, serious or repeated breaches, failure to maintain operating conditions, inability to demonstrate the system, prolonged inactivity or failure to remediate can undermine registration. The board should therefore treat regulatory status as an asset supported by controls, people, financial resources and timely decisions.

Material change must be assessed before release

Ownership, administrators, branches, kiosks, websites, applications, providers, custody, countries, products, systems and significant AML risks can alter the registered model. A change record should identify the legal requirement, risk impact, NBG approval or notification position, documents and configurations affected, testing and launch conditions.

The registration act must be visible through service channels

From 1 January 2026, registered VASPs must display or make the individual NBG registration act easily available through the spaces and channels where services are provided, including the head office, branches, self-service kiosks, website and application as applicable. This helps users distinguish a registered legal entity from an unregistered brand or lookalike service.

What useful board reporting looks like

  • High-risk customers and changes in customer-risk distribution.
  • Sanctions, PEP and wallet-risk decisions, including overrides.
  • Alert volumes, ageing, investigations and suspicious-activity decisions.
  • Cash, kiosk, self-hosted-wallet and high-risk counterparty exposure.
  • Reconciliation breaks, operational incidents and provider failures.
  • Capital adequacy, penetration-testing results, vulnerability scans and independent-assurance findings.
  • Staffing, competence, access and workload capacity.
  • Regulatory requests, material changes and overdue corrective actions.
  • Quality-assurance results, root causes, retesting and closure evidence.

Inspection-readiness programme

  1. Maintain the obligations, change and NBG-correspondence registers.
  2. Keep an indexed evidence room with current Georgian versions.
  3. Sample customer files, transactions, alerts and reports by risk.
  4. Test retrieval from the live system and critical providers.
  5. Rehearse interviews with administrators and control owners.
  6. Run a complete customer-to-report system demonstration.
  7. Track findings to evidence-based closure and board approval.

CryptoLicense.ge can coordinate inspection readiness, regulatory responses and remediation as a defined engagement or managed workstream. The operating company and its administrators remain the decision-makers and control owners.

LEGAL BASIS

Legislation and regulatory materials

Our regulatory assessments and implementation work are based on the Georgian legislation and National Bank of Georgia materials below. Legal texts available in our legislation library open on CryptoLicense.ge; the official Matsne source is linked at the bottom of each legal-text page.

CryptoLicense.ge Legal & Regulatory Team Legal review: 1 September 2026 Model-specific legal review required