EMI Onboarding for VASPs in Georgia: Legal Requirements for Businesses
A virtual asset service provider seeking fiat rails in Georgia faces a banking environment that is more open than most of its European counterparts – yet one that still demands a clear legal and compliance architecture before an EMI (electronic money institution) or correspondent bank will open a payment account. The core question is not simply whether Georgia allows crypto businesses to bank; it is what documentation, licensing basis and AML posture the receiving institution requires before it will onboard a VASP (virtual asset service provider). Getting that answer wrong means frozen rails, delayed operations and, in the worst case, enforcement exposure in the jurisdictions where the business actually serves users.
Georgia does not operate a MiCA-style CASP authorisation regime. Its regulatory posture for VASPs is lighter than the EU average – a position that attracts inbound crypto businesses but also creates ambiguity that EMIs and correspondent banks use as a reason to decline or delay onboarding. Operators we advise consistently encounter the same pattern: the Georgian entity is clean on paper, but the payment account application stalls because the operator cannot demonstrate how it manages its cross-border AML obligations, its Travel Rule compliance posture or its ultimate beneficial ownership chain.
This page sets out the legal requirements, the inbound-business process and the cross-border interaction points that determine whether a VASP can successfully onboard with a Georgian EMI or payment institution.
Georgia's Regulatory Posture for Virtual Assets
Georgia's framework for crypto businesses sits primarily within its general anti-money-laundering legislation and the oversight of the National Bank of Georgia (NBG), rather than in a dedicated VASP-licensing regime comparable to VARA in Dubai or the Payment Services Act regime administered by MAS in Singapore. The NBG supervises payment services, money transfers and electronic money issuance. Crypto-to-crypto activity, by contrast, currently falls outside a mandatory NBG licensing requirement for most operators – though that boundary is narrow and fact-sensitive.
What this means in practice is that a VASP operating in Georgia may not need an NBG licence for its core digital-asset activity, but it almost certainly needs one – or a specific AML/CFT registration – to accept or transmit fiat funds at scale. The absence of a mandatory crypto licence is not a compliance free pass. EMIs and Georgian commercial banks apply their own due-diligence standards, and those standards track FATF Recommendation 15 on virtual assets regardless of whether Georgian statute law has codified every element.
In our practice, we see inbound operators assume that Georgia's lighter-touch environment means documentation requirements are correspondingly light. That assumption is wrong. The NBG's AML supervisory expectations, and those of every EMI we have engaged with in this jurisdiction, are substantively aligned with the FATF baseline – including originator and beneficiary data obligations under the Travel Rule (the obligation to pass originator and beneficiary data with a virtual-asset transfer).
What Does an EMI Actually Require from a VASP?
An EMI onboarding a VASP in Georgia will conduct a risk-tiered due-diligence review that typically addresses six areas: corporate structure and UBO chain, regulatory status in the jurisdictions where the VASP serves users, AML/KYC programme documentation, Travel Rule solution, transaction monitoring approach and financial projections tied to expected fiat flow volumes.
The corporate structure piece is often where applications stall. A VASP incorporated in Georgia but with beneficial owners in a higher-risk jurisdiction, or with a customer base concentrated in FATF-grey-listed countries, will face enhanced due diligence from the outset. Operators we advise are asked to produce a corporate group chart, source-of-funds documentation for the capitalisation of the Georgian entity and, in some cases, personal financial statements from UBOs above a defined ownership threshold.
The AML/KYC programme documentation is more specific than many first-time applicants expect. The EMI wants to see a written AML policy, a named compliance officer, a risk-appetite statement that addresses crypto-specific risks (mixer exposure, DeFi interaction, peer-to-peer transaction risk) and evidence that the programme is actually implemented rather than drafted and filed. A policy document without transaction-monitoring rules or escalation procedures will not satisfy the review.
Travel Rule compliance is increasingly a hard requirement rather than a preferred feature. EMIs we have engaged with in this market treat Travel Rule readiness as a threshold question: if the VASP cannot demonstrate that it passes originator and beneficiary data on transfers above the applicable threshold – and cannot name the technical solution it uses to do so – the onboarding process stops.
The contextual bridge: the process above describes a standard path. Your facts – the entity structure, the user base geography, the fiat volumes anticipated – change the analysis materially.
For a scoped assessment of your EMI onboarding position in Georgia, contact OBOLUS at info@oboluslaw.com or map your options.
Which Businesses Need an NBG Licence to Access Fiat Rails?
A business needs NBG authorisation when it conducts regulated payment services or electronic money issuance in Georgia – not simply because it holds or transfers crypto assets. The threshold question is whether the fiat side of the operation constitutes a payment service under Georgian law, which follows a broadly similar perimeter to the EU Payment Services Directive framework, though it is not identical to it.
For a VASP, this typically means that a business operating a crypto exchange with Georgian-currency deposit and withdrawal functionality is engaged in a regulated activity for the fiat leg of that operation. A pure crypto-to-crypto business that routes its fiat in and out through a third-party licensed payment institution – rather than holding client fiat funds itself – may fall outside the NBG licensing perimeter. That distinction is fact-sensitive and should not be assumed without legal analysis.
Businesses that do hold client fiat – for instance, crypto brokers or OTC desks that receive GEL or USD from customers and hold it pending conversion – are likely to need either an NBG payment institution authorisation or to operate via a licensed Georgian bank or EMI as a settlement agent. The second model is more common for inbound VASPs without an existing Georgian presence, and it is the model that drives most EMI onboarding mandates we handle in this jurisdiction.
How Does the EMI Onboarding Process Work in Georgia?
The EMI onboarding process in Georgia for a VASP typically moves through four phases: pre-application positioning, documentation submission, compliance-officer review and, where the institution requires it, a committee decision for higher-risk profiles.
The pre-application phase is the most commercially significant and the most commonly skipped. It involves mapping the VASP's regulatory status in every jurisdiction where it has licensed or registered operations, identifying whether any of those jurisdictions are FATF-grey-listed, and building the narrative that the EMI's compliance team will use to justify the relationship to its own regulator. Operators who arrive at a Georgian EMI with a single-page company profile and a passported EU licence – expecting the EU authorisation to carry the weight of the application – routinely find that the EMI still requires jurisdiction-by-jurisdiction analysis of where the VASP's customers are and how it manages compliance in each location.
The documentation phase involves assembling the core file: certificate of incorporation and constitutional documents, UBO declarations and supporting KYC for each beneficial owner above the applicable threshold, a compliance manual or AML policy, a Travel Rule implementation statement, audited or management accounts, and a transaction-volume projection. Some Georgian EMIs also request a legal opinion confirming the VASP's regulatory status in its home jurisdiction.
The compliance-officer review is typically the longest phase. Timelines vary by institution and by the complexity of the applicant's structure. Simple structures with clean AML documentation and a well-established compliance programme can clear review in a matter of weeks. Complex group structures, multi-jurisdictional ownership chains or customer bases that include higher-risk geographies extend the review materially.
Where a committee decision is required – usually for VASPs classified as higher-risk by the EMI – the process adds an additional layer and a longer timeline. In our cross-border practice, we have seen committee reviews add several weeks to the overall process, and we structure the documentation file specifically to reduce the probability that a matter escalates to committee rather than clearing at the compliance-officer level.
Cross-Border Interaction: Licensing, Tax and Banking
A Georgian EMI relationship does not operate in isolation. Every VASP using Georgian fiat rails is simultaneously managing its regulatory obligations in the jurisdictions where its users are located – and those obligations interact with the Georgian banking relationship in ways that are not always obvious at the outset.
The most common cross-border tension we see is between the VASP's home licence (often an EU CASP authorisation under MiCA, or a VARA licence in Dubai, or an SFC-licensed VATP in Hong Kong) and the geographic scope of that licence. A common assumption is that a single offshore licence is enough to serve clients globally – that is not correct. MiCA passporting, for instance, covers EU and EEA member states; it does not authorise a VASP to serve users in the US, the UK or Gulf jurisdictions without separate analysis and, in most cases, separate authorisation. A Georgian EMI that identifies a material discrepancy between the VASP's licensed scope and its actual customer geography will treat that as an enhanced-risk indicator.
Tax interaction is a parallel consideration. Georgia operates a territorial tax regime: income earned outside Georgia by a Georgian-registered business is not subject to Georgian corporate tax provided the structure meets the applicable conditions. This territorial position is a genuine attraction for crypto businesses, but it requires the operational substance of the business to be genuinely Georgian – not simply a mailbox entity. EMIs apply the same substance test when they assess whether the Georgian entity is the real seat of the operation or a booking vehicle for a business effectively run elsewhere.
Banking diversification is the third cross-border variable. Operators we advise rarely rely on a single payment account in a single jurisdiction. A Georgian EMI account for GEL and USD settlement, combined with an EU SEPA account for euro settlement and a correspondent banking relationship in a Gulf hub for AED flows, is a typical multi-rail architecture. Structuring those rails so that each relationship is compliant in its own jurisdiction – and that the overall architecture does not create a regulatory gap – is the advisory work that precedes, not follows, EMI onboarding.
Common Mistakes That Stall VASP EMI Onboarding in Georgia
The most frequent reason a VASP's EMI application stalls in Georgia is not a hard regulatory bar; it is a documentation or positioning failure that could have been avoided. We see the same pattern repeatedly.
First: UBO chains that are unclear, multi-layered or routed through holding structures in jurisdictions the EMI cannot easily assess. The institution's compliance team will not invest hours of research to reconstruct an ownership chain the applicant should have mapped itself. If the UBO chain runs through more than two layers of holding companies before reaching a natural person, the file needs to explain each layer and provide KYC at every relevant level.
Second: a compliance manual that is generic rather than specific to the VASP's actual business. A policy that does not address the specific risk categories present in the VASP's activity – whether that is DeFi, stablecoin issuance, OTC dealing or custody – signals to the EMI that the programme is theoretical rather than operational.
Third: the Travel Rule gap. Operators who acknowledge the Travel Rule obligation but cannot name a deployed technical solution are effectively telling the EMI that their AML programme has a structural hole. That is a category of risk that most institutions will not accept, particularly as Travel Rule enforcement across the major hubs tightens.
Fourth: a mismatch between the fiat volumes projected in the onboarding application and the VASP's actual business scale. Understating projected volumes to reduce the institution's risk perception is a common instinct; it routinely backfires when actual flows exceed the stated figures and trigger a review of the relationship.
In a recent matter, a crypto payments business sought to onboard with a Georgian payment institution after its EU correspondent banking relationship was closed without explanation. The business had a valid EU AML registration but had not maintained its Travel Rule solution after a vendor change. We restructured the compliance file, documented the new Travel Rule implementation and presented a revised UBO disclosure; the account was opened within a commercially reasonable timeline. No specific fees or capital figures attach to that outcome – the structure of the matter is the lesson, not the numbers.
If a prior application stalled or an account was closed, a second review can identify the structural reason and the route back. Contact OBOLUS at info@oboluslaw.com or map your options.
Decision Matrix: Which VASP Profile Should Consider Georgian EMI Onboarding?
Georgian EMI onboarding is not the right solution for every VASP. The decision depends on the operator's business model, its user geography and its existing regulatory footprint.
Profile A is the EU-based crypto exchange looking for supplementary GEL and USD settlement rails outside the EU banking system. This operator already holds a MiCA CASP authorisation or an equivalent national licence and needs fiat access in a jurisdiction with a lighter cost base. The Georgian EMI relationship makes sense here as a secondary rail, provided the exchange can demonstrate that its Georgian customer flows are genuinely segregated from its EU business and that the AML programme covers both.
Profile B is the emerging-markets-focused crypto broker or OTC desk that serves clients across Eastern Europe, Central Asia and the Caucasus. For this operator, a Georgian banking relationship is often the primary fiat settlement mechanism. The key risk is that the customer geographies include FATF-grey-listed jurisdictions; the onboarding file must address that risk explicitly rather than hoping the institution will not probe it.
Profile C is the token issuer or DeFi protocol seeking a fiat off-ramp for treasury management. This profile is typically less straightforward. Georgian EMIs are generally comfortable with exchange and brokerage activity; custody and DeFi-adjacent structures raise questions about the nature of the fiat flows that require careful positioning. The timeline for onboarding in this profile is longer, and the documentation requirements are higher.
Profile D is the business that has already been declined by a Georgian EMI or had an account closed. This is a distinct situation requiring a pre-application diagnostic before a new approach is made. Re-applying without addressing the root cause of the original decline will produce the same result.
The AML/CFT and Travel Rule Posture Georgian EMIs Expect
Georgia is a FATF member and has committed to implementing FATF Recommendation 15, which requires VASPs to collect and transmit originator and beneficiary information on virtual-asset transfers above the applicable threshold – the Travel Rule. The NBG expects financial institutions it supervises, including payment institutions, to apply FATF-aligned AML/CFT standards when onboarding and monitoring higher-risk customers such as VASPs.
What this means for the VASP seeking Georgian fiat rails is that the AML/CFT posture it presents to the EMI must be substantively FATF-compliant, even where Georgian statute has not yet transposed every element of the FATF recommendations in full detail. Institutions that get this wrong – by presenting a compliance programme calibrated to a lighter standard – are effectively telling the EMI that they are behind the curve on international standards that the EMI's own regulator applies.
Travel Rule technical readiness is the clearest signal of AML maturity in the eyes of a Georgian EMI compliance team. A VASP that can demonstrate an active deployment of a recognised Travel Rule solution, with evidence of counterparty outreach to unhosted wallet situations, is positioned materially better than one that acknowledges the obligation without the implementation.
Customer due diligence documentation should be calibrated to the VASP's actual risk categories. A stablecoin-focused business has different risk exposure to a derivatives trading platform; the AML policy should reflect that specificity. Regulators in the leading hubs increasingly expect crypto-specific risk assessments rather than generic financial-services AML policies adapted by find-and-replace.
- Maintain an up-to-date written AML/KYC policy specific to your business model.
- Name a compliance officer with documented responsibility and authority.
- Deploy a Travel Rule solution and document counterparty engagement.
- Conduct and record a crypto-specific business risk assessment annually.
- Maintain transaction monitoring rules calibrated to your transaction types and volumes.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital Asset Businesses – the full practice overview for fiat-rail strategy and account access
- Fiat On/Off-Ramp Banking in Abu Dhabi Global Market (ADGM) – fiat access in the Gulf for operators building a multi-hub payment stack
- Redemption and Liquidity Terms for Early-Stage Founders – structuring fiat liquidity obligations where banking access is a fund-level question
FAQ
Why do banks close crypto company accounts?
Banks close crypto company accounts primarily because of perceived AML risk that the institution cannot adequately assess or price. Common triggers include an unclear UBO chain, a compliance programme that does not address crypto-specific risks, a mismatch between stated and actual transaction volumes, Travel Rule non-compliance or a customer geography that includes FATF-grey-listed jurisdictions. In most cases, the closure is not a hard regulatory prohibition – it is a risk-appetite decision that a stronger compliance posture and clearer documentation can often reverse.
How can a VASP onboard with an EMI?
A VASP onboards with an EMI by presenting a documentation file that demonstrates clean corporate structure, a FATF-aligned AML/KYC programme, Travel Rule readiness and a realistic projection of fiat flows. The process typically moves through pre-application positioning, documentation submission and a compliance review. The timeline depends on the complexity of the VASP's structure and the risk tier the institution assigns to the application. A structured pre-application engagement – mapping the regulatory status in each user jurisdiction before submission – materially improves the probability and speed of a successful outcome.
What does client-money safeguarding require?
Client-money safeguarding in the context of a payment institution or EMI requires the institution to hold client funds separately from its own operating funds, typically in a designated safeguarding account at a credit institution or in eligible liquid assets. For a VASP using a Georgian EMI as its fiat settlement provider, the safeguarding obligation sits with the EMI rather than the VASP – but the VASP must understand what that protection covers and, critically, what it does not cover when fiat funds are in transit or held pending conversion. Operators with material fiat balances should confirm the safeguarding model in writing before committing to the relationship.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – so the fiat-rail architecture is built on solid legal ground from the outset. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP regulatory posture, AML/CFT programme assessment and EMI onboarding strategy for digital-asset businesses in emerging and transitional jurisdictions.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.