Turn the company’s risk model into a complete customer, counterparty, transaction, investigation and remediation lifecycle.
Begin with geography, customer type, channels, products, assets, custody, cash, counterparties and expected behaviour. Connect the risk assessment to onboarding, KYC/KYB, UBO, source of funds and virtual assets, sanctions/PEP, KYT, monitoring, alerts, investigation, reporting, records, management information, testing and remediation.
Service overview
The framework must be demonstrable in live customer files, alert handling, investigations, reporting and management oversight—not only described in policy.
- Enterprise, product and customer risk assessments
- KYC/KYB, UBO and source-of-assets workflows
- PEP, sanctions and adverse-information controls
- KYT, high-risk wallet and counterparty scenarios


Turn risk appetite into product rules
Customer acceptance, geography, assets, transaction patterns, counterparties and self-hosted wallets must move from policy language into onboarding, monitoring, cases and management decisions.
The operating test
A reviewer can follow one customer from onboarding through transaction monitoring, escalation, reporting and quality assurance.
From sector risk to an operating control chain
We connect Risk Assessment → Onboarding → KYC/KYB → UBO → source of funds and virtual assets → sanctions/PEP → KYT → monitoring → alerts → investigation → reporting → records → management information → testing → remediation. Cash, kiosks, self-hosted wallets, high-risk wallet exposure, mixers and cross-chain activity are included where the model creates them.
Where control frameworks lose credibility
Customer risk stays unchanged after onboarding, blockchain analytics runs on default settings, source checks cover fiat but not virtual assets, or alerts are closed without investigation evidence. We repair the workflow and configuration behind the wording, then test it with representative cases.
What you can expect from us
We begin with the live model and current evidence, agree the decisions and dependencies, then issue a written scope. You may engage us for advice and review only, for a defined implementation module, or for the complete build and regulatory coordination. The quotation caps our professional fee for the agreed assumptions and separates the GEL 5,000 official registration fee, translations, personnel, office, software, assurance and other third-party costs.
Founder decision
Agree the product perimeter, markets, counterparties and risk appetite before costly build work.
Operating evidence
Connect each claim to an accountable person, configured control, record and test result.
Launch consequence
Carry approved assumptions into filing, banking, provider onboarding and supervised operations.

Questions we address in this workstream
The assessment should reflect the applicant’s products, customers, beneficial owners, countries, channels, assets, custody, cash, counterparties, expected behaviour and technology. It should distinguish inherent risk, control effectiveness and residual risk, then drive acceptance, enhanced review, limits, monitoring and management decisions.
Use a risk-based combination of acquisition or exchange records, wallet ownership or control, transaction history, blockchain analysis, mining or staking records, business purpose and the customer’s broader economic profile. The evidence should explain the actual assets reaching the relevant address, not only the origin of fiat.
Relevant scenarios can include sanctioned or high-risk wallets, mixers or tumblers, privacy-enhancing technology, direct and indirect exposure, multiple hops, chain hopping, cross-chain bridges and self-hosted wallets. Vendor scores are inputs; the VASP must define investigation, restriction, rejection, reporting and record standards.
Cash can reduce transparency and create linked or structured transaction risk. The operating model should connect customer identification, source review, limits, linked-transaction detection, surveillance, staff escalation, system-availability stop rules, reconciliation and location-level management information.
A reviewer should be able to follow a high-risk customer and complex transaction from onboarding through customer-risk reassessment, screening, KYT, alert, investigation, decision, any report, management oversight and later testing. Quality assurance and remediation should show root cause, accountable owner, retest and closure.
Applicable legislation and regulatory materials
- National Bank of Georgia — VASP questions and answers
- NBG Governor Order No. 94/04 — VASP registration, cancellation and regulation
- Law of Georgia on Facilitating the Prevention of Money Laundering and the Financing of Terrorism
- National Bank of Georgia — Update of the ML/TF Risk Assessment of the VASP Sector (2024)
- NBG — Internal Control Compliance Questionnaire for VASP applicants
- NBG Governor Order No. 133/04 — VASP fines and enforcement


