The National Bank of Georgia (“NBG”) has introduced significant changes to the regulatory framework applicable to Virtual Asset Service Providers (“VASP”). The amendments expand the scope of regulatory supervision beyond anti-money laundering and counter-terrorist financing requirements and introduce additional requirements relating to registration, risk management, regulatory capital, stable virtual assets, reporting, and sanctions. The updated framework is intended to increase transparency in the virtual asset market and strengthen consumer protection.
The amendments affect the rules governing the registration, deregistration, and regulation of VASPs, the imposition and enforcement of monetary penalties against VASPs and their administrators, the initial offering of stable virtual assets, and reporting requirements applicable to stable virtual assets.
- NBG supervision of VASPs now goes beyond AML/CFT to risk management, solvency and institutional soundness.
- Stable virtual asset reserves may consist only of liquid assets, with new bank concentration limits.
- Minimum regulatory capital ranges from GEL 150,000 to GEL 350,000, depending on the service.
- Critical systems need annual penetration testing, and an independent audit is due within 12 months of registration.
- Fines reach GEL 50,000, doubled for repeated violations, and registration can be revoked.
Expanded Regulatory Supervision
The NBG’s supervisory role over VASPs has historically focused primarily on anti-money laundering and counter-terrorist financing compliance. Under the amended framework, however, regulatory oversight extends to a broader range of operational and financial matters.
VASPs are now subject to requirements concerning risk management, financial solvency, and overall institutional soundness. The NBG may assess whether a VASP has adequate mechanisms for identifying and managing operational and financial risks, maintains sufficient capital to support its continued operations, and has appropriate financial and organizational structures in place.
As a result, VASPs are required to consider regulatory compliance across their operations rather than limiting their compliance framework to AML/CFT requirements.
Regulation of Stable Virtual Assets
The amended framework introduces more detailed requirements for stable virtual assets. Under Georgian legal framework, a stable virtual asset is a convertible virtual asset expressed or denominated in units, the value of which is pegged to the value of the fiat. A stable virtual asset may be linked to a fiat currency, including the Georgian lari or a foreign currency, and its reserves may consist only of liquid assets. The possibility of backing a stable virtual asset with other types of assets is therefore excluded under the new framework.
The amendments also introduce concentration limits for fiat currency reserves held with commercial banks and microbanks. Where reserves do not exceed GEL 5 million, the entire amount may be placed with a single bank, provided that the amount does not exceed 10% of that bank’s share capital. Where reserves exceed GEL 5 million, the amount held with a single bank may not exceed 50% of the issuer’s total fiat reserves, while the 10% limitation based on the relevant bank’s share capital continues to apply. Institutions belonging to the same banking group are treated as a single entity for purposes of these limits.
- Entire amount may be placed with a single bank
- Must not exceed 10% of that bank’s share capital
- Max 50% of total fiat reserves with a single bank
- The 10% share capital limit still applies
If a reserve concentration requirement is breached, the issuer must immediately notify the NBG and remedy the deficiency within the period specified by the regulator, which may not exceed two business days.
The amended framework also establishes additional documentation requirements for stable virtual asset issuers. These include corporate governance documentation, regulatory capital documentation, an audit report, and the relevant offering document. For VASPs that were already conducting a stable virtual asset offering, the deadline for submitting the required documentation and audit report has been extended from six months to one year.
Risk Management and Information Security
The new regulations introduce a formal risk management framework for VASPs. Each VASP is required to maintain policies and procedures appropriate to the scale and nature of its business and addressing relevant operational, cybersecurity, technological, and fraud risks.
Risk management policies and their records must be retained for at least eight years following termination of the relevant service. VASPs must also maintain business continuity arrangements, data protection measures, regular backups, and secure customer authentication mechanisms. Activities conducted through the relevant systems must be recorded in real time.
The framework further introduces periodic testing requirements. Critical systems connected to the network must undergo penetration testing at least annually, while other systems must be tested at least once every three years. Within 12 months of registration, the VASP must submit an independent audit report to the NBG. Where testing identifies a critical deficiency, the NBG may revoke the VASP’s registration.
Minimum Capital
The amended legislation establishes minimum regulatory capital requirements based on the services provided by a VASP. The minimum amount is GEL 150,000 for the exchange or transfer of virtual assets, GEL 350,000 for the administration of a trading platform, and GEL 250,000 for other services. Where a VASP provides several services, the highest applicable capital requirement must be maintained.
Exchange or transfer of virtual assets
Other services
Administration of a trading platform
Several services? The highest applicable requirement applies. Core capital must be at least 75% of total regulatory capital, and secondary capital no more than one-third of core capital.
The amendments also regulate the composition of regulatory capital. Core capital must constitute at least 75% of total regulatory capital and may include reserves, charter capital, and retained earnings. Core capital must be permanent, fully paid, capable of absorbing losses immediately, and classified as equity under IFRS. It also ranks last in the order of claims in the event of bankruptcy or liquidation. Changes to the terms of convertible debt included in core capital require the NBG’s prior approval.
Secondary capital may not exceed one-third of core capital and primarily consists of subordinated debt or equivalent instruments. Such instruments must generally have an original maturity of at least five years, are subject to regulatory amortization during the final five years before maturity, and may not contain step-up interest provisions. Early redemption is permitted only after five years and with the NBG’s prior consent, subject to replacement with capital of the same or higher quality.
The regulations also restrict the circumstances in which subordinated debt may be repaid and require such debt to be raised only from the VASP’s owners, partners, shareholders, or beneficial owners. Borrowing from natural persons for these purposes is prohibited.
Where a VASP experiences a capital deficit, it must immediately notify the NBG, submit a capital restoration plan within five business days, and cease the distribution of dividends and bonuses. The NBG may also impose a fine in connection with a capital deficit.
Penalties and Supervisory Measures
The amended framework introduces a more structured penalty regime for VASPs and their administrators. Violations are divided into several categories, including breaches of general regulatory requirements, violations relating to stable virtual assets, and AML/CFT violations.
General regulatory breaches include violations of registration requirements, provision of inaccurate information, failure to comply with accounting or reporting obligations, and failure to comply with NBG requirements or instructions. Depending on the nature of the violation, monetary fines range from GEL 500 to GEL 50,000, with the applicable fine doubled in cases of repeated violations.
Separate penalties apply to violations relating to stable virtual assets. Fines range from GEL 1,000 for incorrect, incomplete, or late monthly reporting on stable virtual assets to GEL 50,000 for certain more serious violations, including gross violations of initial offering requirements or breaches of reserve asset management requirements.
The amended framework also provides for specific sanctions in relation to AML/CFT compliance. These include a GEL 20,000 fine for failure to properly identify suspicious and/or related transactions, a GEL 10,000 fine for failure to use the required specialized electronic system for recording clients and transactions, and a GEL 20,000 fine for failing to maintain the required data recording and processing system under the Anti-Money Laundering Law. Additional fines apply to failures relating to customer due diligence and the provision of information to the NBG, including a GEL 3,000 fine for failure to determine the nature of a customer’s business and a GEL 1,000 fine for providing incorrect or incomplete information requested by the NBG outside an inspection process.
| Violation | Fine |
|---|---|
| General regulatory breaches | |
| Registration, inaccurate information, accounting or reporting, NBG instructions | GEL 500 to 50,000 doubled if repeated |
| Stable virtual assets | |
| Incorrect, incomplete or late monthly reporting | GEL 1,000 |
| Gross offering violations or reserve management breaches | up to GEL 50,000 |
| AML/CFT | |
| Failure to identify suspicious and/or related transactions | GEL 20,000 |
| Failure to maintain the required data recording and processing system | GEL 20,000 |
| Not using the specialized electronic system for clients and transactions | GEL 10,000 |
| Failure to determine the nature of a customer’s business | GEL 3,000 |
| Incorrect or incomplete information requested outside an inspection | GEL 1,000 |
The NBG may also impose measures other than monetary penalties. Depending on the circumstances, these may include a written warning, suspension of signatory authority, removal of an administrator, restrictions on the distribution of profits, dividends, or bonuses and on salary increases, restrictions on certain operations of the VASP, requirements concerning the owner’s control of the company, and revocation of the VASP’s registration.
The amendments introduced by the NBG significantly broaden the regulatory framework applicable to VASPs in Georgia. For VASPs, the updated framework therefore creates a more comprehensive set of ongoing regulatory obligations. In particular, providers should ensure that their authorized service activities, capital structure, risk management policies, information security arrangements, stable virtual asset activities, reporting processes, and internal compliance systems are aligned with the amended requirements.
About Andersen in Georgia
At Andersen Georgia, we advise virtual asset service providers, stable virtual asset issuers and investors on Georgia’s virtual asset regulation. Our team supports clients with NBG registration, regulatory capital, risk management and information security frameworks, AML/CFT compliance, and the practical application of the amended NBG requirements.
Stay VASP Compliant.
From regulatory capital and stable virtual asset reserves to risk management and AML/CFT, our team helps VASPs align with the amended NBG framework.
