Grade B AI-Researched

Georgia -- AML/CFT Compliance Regulatory Overview

Published: 2026-04-22 Updated: 2026-04-22 Author: SearXNG+LLM Version 1 Sources cited in: English (2)

Methodology

AI-generated synthesis from web search results.

Limitations

  • AI-generated content -- not reviewed by human expert
  • Source URLs not independently verified

Georgia has significantly updated its Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) framework to explicitly include Virtual Asset Service Providers (VASPs), aligning with the Financial Action Task Force (FATF) recommendations. This means VASPs operating in Georgia are subject to comprehensive AML/KYC obligations.

Here's a breakdown of the requirements:


AML/CFT Legislation for VASPs in Georgia

The primary legal and regulatory acts governing AML/CFT for VASPs in Georgia include:

  1. Law of Georgia on Facilitating the Suppression of Money Laundering and Terrorism Financing (Law N5183-IIs, adopted December 29, 2006, as amended): This is the fundamental AML/CFT law in Georgia. It was significantly amended in 2023 to explicitly include Virtual Asset Service Providers (VASPs) as "obliged entities" (or "reporting entities"), bringing them under the scope of AML/CFT regulations.
  2. National Bank of Georgia (NBG) Resolution N111/04 of July 13, 2023, "On Approving the Rules for Regulation of Activities of Virtual Asset Service Providers": This crucial resolution by the NBG provides detailed rules and guidelines for the licensing, supervision, and AML/CFT compliance of VASPs. It elaborates on the requirements stipulated in the main AML law.
  3. National Bank of Georgia (NBG) Ordinance N59/04 of April 2, 2024, "On the Approval of Rules for Reporting and Publication of Information by Virtual Asset Service Providers": This ordinance further specifies reporting and publication requirements, including those relevant for AML/CFT oversight.

Customer Due Diligence (CDD) Requirements

VASPs in Georgia, as obliged entities, must implement a risk-based approach to CDD, meaning the intensity of CDD measures should be commensurate with the identified risks. Key CDD requirements include:

  1. Identification and Verification of the Customer:
    • For Individuals: Obtaining and verifying details such as full name, date and place of birth, address, nationality, and identification document details (e.g., passport or ID card number, issuing authority, expiry date). Verification typically involves reliable, independent source documents or data.
    • For Legal Entities: Obtaining and verifying the legal entity's name, legal form, registration number, registered address, and the names of individuals authorized to act on behalf of the entity. Verification involves official corporate documents.
  2. Identification of Beneficial Owner(s):
    • Identifying the natural person(s) who ultimately own or control the customer, and verifying their identity. This applies to both individual and legal entity customers. For legal entities, this typically means identifying individuals holding 25% or more of the shares or voting rights, or otherwise exercising control.
  3. Purpose and Intended Nature of the Business Relationship:
    • Understanding the purpose and nature of the customer's activities and the intended business relationship with the VASP. This helps assess the risk profile.
  4. Ongoing Monitoring:
    • Continuously monitoring the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile, including the source of funds or wealth.
  5. Enhanced Due Diligence (EDD):
    • Applying EDD measures for higher-risk situations, such as relationships with Politically Exposed Persons (PEPs), customers from high-risk jurisdictions, or complex and unusual transactions. EDD may involve obtaining additional information on the source of funds/wealth, purpose of transactions, and senior management approval for the relationship.
  6. Simplified Due Diligence (SDD):
    • VASPs may apply SDD in specified lower-risk scenarios, as permitted by the NBG.

Suspicious Transaction Reporting (STR)

VASPs are legally obliged to report suspicious transactions to the financial intelligence unit (FIU) of Georgia:

  1. Identification of Suspicion: VASPs must establish systems and controls to identify transactions or activities that are unusual or give rise to a suspicion of money laundering or terrorism financing.
  2. Reporting Obligation: If a VASP knows, suspects, or has reasonable grounds to suspect that funds are the proceeds of a criminal activity, or are related to terrorism financing, it must promptly report this to the LEPL Financial Monitoring Service of Georgia.
  3. Content of Report: The report must include all available information concerning the customer, the transaction(s), and the grounds for suspicion.
  4. No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or any third party that a STR has been, or will be, submitted.

Record-Keeping Obligations

VASPs must maintain comprehensive records to support their AML/CFT compliance:

  1. Duration: Records must be kept for a period of at least five years following the termination of a business relationship or the date of an occasional transaction.
  2. Types of Records:
    • CDD Information: All documents and data obtained during the CDD process (identification documents, beneficial ownership information, risk assessments).
    • Transaction Records: Details of all transactions, including amounts, types of virtual assets, currencies involved, dates, times, and parties to the transaction. This should allow for the reconstruction of individual transactions.
    • Correspondence: Records of internal and external communication related to AML/CFT, including any STRs filed and the analysis supporting the decision to file or not file a report.
    • Risk Assessments: Documentation of institutional and customer-specific risk assessments.

Oversight Authority

The primary authorities overseeing AML/CFT compliance for VASPs in Georgia are:

  1. National Bank of Georgia (NBG):
    • The NBG is the main supervisory authority for VASPs in Georgia. It is responsible for licensing, regulating, and overseeing the compliance of VASPs with the AML/CFT framework, including CDD and record-keeping requirements, as well as general prudential regulation.
    • Website: https://www.nbg.gov.ge/
  2. LEPL Financial Monitoring Service of Georgia (FMS):
    • The FMS is Georgia's Financial Intelligence Unit (FIU). It is the central authority for receiving, analyzing, and disseminating suspicious transaction reports (STRs) and other financial intelligence to law enforcement agencies. VASPs report their STRs directly to the FMS.
    • Website: https://www.fms.ge/

In summary, Georgia has established a robust regulatory framework that brings VASPs firmly under the scope of its AML/CFT regime, reflecting its commitment to combating financial crime and aligning with international standards set by FATF. VASPs operating in or from Georgia must adhere to these stringent requirements to avoid penalties and operate legally.

Source Data

80%

Law of Georgia on Facilitating the Suppression of Money Laundering and Terrorism Financing (Law N5183-IIs, adopted December 29, 2006, as amended): This is the fundamental AML/CFT law in Georgia. It was significantly amended in 2023 to explicitly include Virtual Asset Service Providers (VASPs) as "obliged entities" (or "reporting entities"), bringing them under the scope of AML/CFT regulations.

80%

National Bank of Georgia (NBG) Resolution N111/04 of July 13, 2023, "On Approving the Rules for Regulation of Activities of Virtual Asset Service Providers": This crucial resolution by the NBG provides detailed rules and guidelines for the licensing, supervision, and AML/CFT compliance of VASPs. It elaborates on the requirements stipulated in the main AML law.

80%

National Bank of Georgia (NBG) Ordinance N59/04 of April 2, 2024, "On the Approval of Rules for Reporting and Publication of Information by Virtual Asset Service Providers": This ordinance further specifies reporting and publication requirements, including those relevant for AML/CFT oversight.

80%

For Individuals: Obtaining and verifying details such as full name, date and place of birth, address, nationality, and identification document details (e.g., passport or ID card number, issuing authority, expiry date). Verification typically involves reliable, independent source documents or data.

80%

For Legal Entities: Obtaining and verifying the legal entity's name, legal form, registration number, registered address, and the names of individuals authorized to act on behalf of the entity. Verification involves official corporate documents.

80%

Identifying the natural person(s) who ultimately own or control the customer, and verifying their identity. This applies to both individual and legal entity customers. For legal entities, this typically means identifying individuals holding 25% or more of the shares or voting rights, or otherwise exercising control.

80%

Understanding the purpose and nature of the customer's activities and the intended business relationship with the VASP. This helps assess the risk profile.

80%

Continuously monitoring the business relationship and transactions to ensure they are consistent with the VASP's knowledge of the customer, their business, and risk profile, including the source of funds or wealth.

80%

Applying EDD measures for higher-risk situations, such as relationships with Politically Exposed Persons (PEPs), customers from high-risk jurisdictions, or complex and unusual transactions. EDD may involve obtaining additional information on the source of funds/wealth, purpose of transactions, and senior management approval for the relationship.

80%

VASPs may apply SDD in specified lower-risk scenarios, as permitted by the NBG.

80%

Identification of Suspicion: VASPs must establish systems and controls to identify transactions or activities that are unusual or give rise to a suspicion of money laundering or terrorism financing.

80%

Reporting Obligation: If a VASP knows, suspects, or has reasonable grounds to suspect that funds are the proceeds of a criminal activity, or are related to terrorism financing, it must promptly report this to the LEPL Financial Monitoring Service of Georgia.

80%

Content of Report: The report must include all available information concerning the customer, the transaction(s), and the grounds for suspicion.

80%

No Tipping-Off: VASPs and their employees are prohibited from disclosing to the customer or any third party that a STR has been, or will be, submitted.

80%

Duration: Records must be kept for a period of at least five years following the termination of a business relationship or the date of an occasional transaction.

80%

CDD Information: All documents and data obtained during the CDD process (identification documents, beneficial ownership information, risk assessments).

80%

Transaction Records: Details of all transactions, including amounts, types of virtual assets, currencies involved, dates, times, and parties to the transaction. This should allow for the reconstruction of individual transactions.

80%

Correspondence: Records of internal and external communication related to AML/CFT, including any STRs filed and the analysis supporting the decision to file or not file a report.

80%

Risk Assessments: Documentation of institutional and customer-specific risk assessments.

80%

The NBG is the main supervisory authority for VASPs in Georgia. It is responsible for licensing, regulating, and overseeing the compliance of VASPs with the AML/CFT framework, including CDD and record-keeping requirements, as well as general prudential regulation.

80%

The FMS is Georgia's Financial Intelligence Unit (FIU). It is the central authority for receiving, analyzing, and disseminating suspicious transaction reports (STRs) and other financial intelligence to law enforcement agencies. VASPs report their STRs directly to the FMS.

27 fact(s) collected but awaiting source verification. View in explorer →

References

This article was generated by SearXNG+LLM .

Primary Sources

nbg.gov.ge. (n.d.). nbg.gov.ge. Retrieved April 22, 2026, from https://www.nbg.gov.ge/

Secondary Sources

fms.ge. (n.d.). fms.ge. Retrieved April 22, 2026, from https://www.fms.ge/

Edit History

2026-04-22 — auto-publish-pipeline: published — Auto-published: grade B

This article is maintained by AI research workers and reviewed by human editors. Learn about our methodology →