Georgia VASP registration & operations See our delivery model
Mon–Fri · 09:00–18:00
THE APPLICATION IS AN OPERATING-COMPANY EXAMINATION

What the NBG Examines in a Georgia VASP Application

Founders, administrators, counsel, compliance and technology leads

The National Bank of Georgia does not examine a Georgian VASP application as a collection of unrelated forms. It examines whether one identifiable company—with transparent owners, suitable administrators, real premises, sufficient resources, working controls and a functioning electronic system—can deliver the services described in the filing and remain capable of supervision after registration.

The governing question: does the whole file describe one credible business?

A strong application has internal logic. The services named in the registration form appear in the customer journeys; the journeys agree with the fiat, virtual-asset and information-flow diagrams; the flows identify every material provider; the providers appear in contracts and due-diligence records; and the business plan pays for the people and systems needed to operate the controls. When one annex describes an institutional transfer business and another assumes walk-in cash exchange, the problem is not editorial—it is uncertainty about the applicant’s real model.

We therefore treat preparation as an examination of propositions. For every important statement, the project asks: who owns it, what control makes it true, where is the record, and can management demonstrate it in the system?

1. Regulatory perimeter and service architecture

The NBG needs to understand what the Georgian company will actually do for another person. Exchange, transfer, custody or administration, individual portfolio management, trading-platform administration, permitted business lending and initial-offering activity create different control and evidence requirements. Product labels such as “broker,” “wallet,” “OTC,” “non-custodial” or “technology platform” are not a substitute for mapping instructions, control, execution, settlement and revenue.

Each distinct service should have a schematic description showing the customer, payer or asset sender, beneficiary, intermediary, counterparty VASP, payment provider and any other participant. If assets or procedures differ, separate diagrams may be necessary. The applicant should also identify websites, applications, electronic-system providers, custody arrangements, liquidity venues and contractual dependencies.

2. Applicant, ownership and source evidence

The general applicant is a Georgian LLC or JSC. The NBG can look through direct shareholders to indirect significant owners and natural-person beneficial owners. Identity and corporate records must reconcile across jurisdictions, while reputation, solvency, business history and source evidence must explain how the company will be funded and who ultimately controls it.

Complexity is not automatically disqualifying, but unexplained holding companies, inconsistent percentages, late ownership changes or unsupported funding can turn a straightforward review into a prolonged evidence exercise. A professional file includes a dated ownership chart, legal records for every layer, UBO analysis, source narrative and a transaction trail that agrees with the capital and business plan.

3. Administrators, competence and real authority

Administrators are assessed as people who will direct the business, not names inserted into forms. The evidence should cover identity, education, professional record, relevant experience, reputation, criminal-record status, financial standing, conflicts and time commitment. The combined management team should make sense for the services, customers, transaction volumes, cash exposure and technology described.

The registration rule also requires an authorised representative to be present in Georgia for the prescribed monthly period. Presence should be supported by actual decision rights, system access, working arrangements, delegation and absence cover. A director who cannot explain the product, retrieve a record or authorise a response is not a persuasive substance solution.

4. Head office, organisation and economic substance

The actual head office is a working and supervisory access point. The NBG may need access to responsible people, documents and the electronic system. The premises, organisation chart, role descriptions, staffing plan and three-year budget should therefore show how the company will operate in Georgia, not merely where mail will be received.

Outsourcing is compatible with a credible model when the Georgian VASP retains knowledge, decision-making, access and oversight. Contracts should establish service levels, audit and evidence rights, incident notification, data access, continuity and exit. “The vendor does that” is not a complete explanation where the applicant remains responsible for the customer and control.

5. AML/CFT risk assessment and internal controls

The applicant must submit AML/CFT internal instructions and an organisational risk assessment, and the NBG may request information through its VASP compliance questionnaire. The NBG’s 2024 sector risk update confirms that review is concerned with substance: customer-risk assignment and reassessment, preventive measures, unusual and suspicious transaction detection, and the ability of technology and staff to apply the rules.

The risk assessment should connect customers, countries, products, delivery channels, assets, custody, cash, counterparties and expected behaviour to acceptance rules, KYC/KYB, beneficial ownership, source of funds, source of virtual assets, sanctions and PEP controls, blockchain analytics, alert investigation, reporting and management information.

6. Functioning electronic system and transaction monitoring

The rule requires information about the electronic system and provides for demonstration before the registration process concludes. A system demonstration should not be a vendor slideshow. Management should be able to trace a representative customer from onboarding through screening, wallet or order activity, transaction monitoring, alerts, investigation, decisions, reporting, reconciliation and audit logs.

For virtual assets, monitoring needs both customer context and blockchain context. The control environment should recognise exposure to high-risk or sanctioned wallets, anonymity-enhancing assets, mixers or tumblers, multiple-hop exposure, chain hopping and cross-chain bridges. Vendor labels and risk scores require calibrated rules, documented uncertainty and human decisions.

7. Business plan, financial resources and launch realism

The three-year plan should connect customer and volume assumptions to revenue, staff, office, providers, systems, security, assurance and operating costs. A technically impressive filing can still be unconvincing if the company has no budget for monitoring analysts, compliance independence, system subscriptions or incident response. Forecasts should also agree with transaction limits, target countries and launch phases.

8. Questions, access and evidence during review

The statutory decision period follows submission of the prescribed complete information and documents. It can pause when the NBG requests correction, clarification, additional evidence or access. Responses should be controlled across the whole dossier: changing a country list can affect sanctions risk, business forecasts, provider contracts, monitoring rules and customer disclosures.

Founder’s preparation test: choose one high-risk customer and one complex transaction. Can the responsible director explain why the relationship was accepted, show the source evidence, reproduce the monitoring decision, identify every provider and retrieve the complete audit trail from Georgia?

How we prepare an application for examination

  1. Freeze the intended service and customer model.
  2. Build a regulatory, asset, money and information-flow map.
  3. Reconcile company, ownership, funding and administrator evidence.
  4. Translate the risk assessment into policies, system rules and responsible roles.
  5. Test customer files, transactions, alerts, reports, logs and continuity scenarios.
  6. Cross-check every annex against the business plan and live system.
  7. Prepare Georgian-language controlled versions and a response register.
  8. Rehearse management interviews, office access and the system demonstration.
PRIMARY LEGAL SOURCES

Official materials used for this guide

These links support the editorial baseline; the explanation above is written for founders and operators. Current consolidated legislation and later official instruments take priority.

CryptoLicense.ge Regulatory Desk Updated: 23 August 2026 Model-specific legal review required