
VASP Regulation in Georgia: 2026 Legal Framework
Georgia requires persons conducting virtual asset service provider activity to register with the National Bank of Georgia. A project must classify its actual asset and funds flows, establish suitable ownership and management, implement AML/CFT and operational controls, and complete registration before regulated activity begins.
Why this issue changes business decisions
The product description should be converted into a transaction map: who sends fiat or virtual assets, who controls keys, who exchanges, transfers, stores or administers assets, which entities contract with the customer and where the technical and compliance functions sit. Classification cannot safely be based on a marketing label such as platform, protocol or software.
Registration is not a one-time document exercise. The provider must be able to operate its governance, customer risk assessment, monitoring, reporting, recordkeeping, security, complaints and outsourcing controls. Owners and managers should understand which responsibilities remain with the registered entity even when group companies or vendors perform tasks.
What the official Georgian sources show
NBG's official FAQ states that the virtual-asset legal framework has operated since 1 January 2023, VASP registration is mandatory, registered VASPs are obliged persons under AML/CFT law and NBG applies fit-and-proper and AML/CFT supervision. Official source
NBG also states that virtual assets are not legal tender and that payment use is generally prohibited except in cases permitted by the framework. Product and customer terms should not imply a broader payment status than the law allows. Official source
An NBG amendment effective from 1 January 2026 requires VASPs to display the registration act visibly in their head office, branches and website. Current application and operating rules must be checked directly because the framework continues to develop. Official source
Decisions to record before the company acts
Complete regulatory classification before launch, marketing or customer onboarding.
Confirm owners, managers, local functions and fit-and-proper evidence.
Build AML/CFT procedures around actual customers, geographies, assets and channels.
Review outsourcing, security, customer documents and website disclosures as one operating system.
Issues counsel should connect
Regulatory perimeter
Map each product, customer, asset, payment and custody flow against Georgian definitions and restrictions.
Entity and governance
Design ownership, management, fit-and-proper evidence, authority and local control arrangements.
Registration pack
Coordinate policies, business description, systems evidence and application materials required for the proposed activity.
AML/CFT framework
Prepare risk assessment, onboarding, monitoring, escalation, reporting and record controls with qualified compliance input.
Customer documents
Draft terms, disclosures, complaints, risk information, privacy and product-specific consent records.
Operations and outsourcing
Allocate security, resilience, data, audit and regulator-access responsibilities across vendors and group companies.
A practical sequence for this matter
- 1
Document the product and transaction flow without relying on marketing labels.
- 2
Issue a regulatory-perimeter and gap analysis against current NBG and statutory materials.
- 3
Confirm structure, owners, managers, compliance resources and technical dependencies.
- 4
Prepare application, governance, AML, customer and outsourcing documents.
- 5
Support regulatory questions, launch controls and an update process for rule changes.
Documents and evidence
- product and funds-flow diagrams
- business plan and financial model
- owner, beneficiary and manager information
- system architecture and outsourcing contracts
- AML/CFT risk assessment and procedures
- customer journey, terms and disclosures
- data map and security incident process
- capital, reserve or safeguarding evidence where applicable
Risks to test
- activity begins before classification or registration
- a group licence is assumed to cover Georgia
- product description differs from actual flows
- AML procedures are generic and unresourced
- outsourcing obscures responsibility or regulator access
- 2026 framework changes are omitted from launch planning
Official public sources used
This publication cites only legislation, registries and regulators. It does not rely on other law firms or competitor commentary as authority.