EST · MMXXVI
Home/Jurisdictions/Georgia/Licence renewal and variation in Georgia
Licensing & Registration

Licence renewal and variation in Georgia

Licence renewal and variation in Georgia. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Maintaining a current, correctly-scoped digital-asset licence in Georgia is not a formality. An operator whose authorisation lapses – or whose activities drift beyond the permitted scope – faces the same enforcement consequences as a business that never registered at all. With the National Bank of Georgia (NBG) tightening supervision under the country's virtual-asset service provider regime and with correspondent banks scrutinising the licensing status of their crypto-business clients, a stale or mis-scoped authorisation is an operational liability, not merely a compliance gap. This page sets out how renewal and variation work in Georgia, where the cross-border pressure points arise, and what the decision looks like for an operator managing a multi-entity structure.

How Georgia regulates virtual-asset service providers

Georgia operates a dedicated VASP registration and licensing regime administered by the National Bank of Georgia, the single regulator for payment services, banking and, increasingly, virtual-asset activities. The NBG has consolidated oversight of crypto-business activity under its broader financial-services supervisory mandate, and operators – whether offering exchange, transfer, custody or brokerage services in or from Georgian territory – must hold the appropriate authorisation before commencing activity. The regime is aligned in principle with FATF Recommendation 15 obligations, meaning AML/CFT controls, customer due-diligence standards and, for cross-border transfers, the Travel Rule (the obligation to pass originator and beneficiary data alongside a virtual-asset transfer) are embedded in the licensing conditions, not bolt-on requirements. Businesses that obtained an early registration under Georgia's original lighter-touch regime now face the practical question of what renewing or varying that authorisation looks like under a more demanding supervisory model.

The NBG issues authorisations that are activity-specific. An exchange licence does not automatically cover custody; a payment-transfer authorisation does not confer brokerage rights. This activity-based model is consistent with the approach taken by leading hubs – VARA in Dubai and the MAS Payment Services Act framework in Singapore operate on the same logic. For a Georgian-licensed entity serving a cross-border client base, the scope of the original authorisation therefore determines both what it can do and, critically, what a variation application must address if the business model evolves.

What is licence renewal in Georgia and when is it required?

Licence renewal in Georgia is the formal process by which an existing authorisation is extended for a further regulatory period before the current term expires. The NBG sets the procedural requirements and the renewal filing window; operators are expected to submit renewal documentation within the window specified in their authorisation or in NBG guidance, not at the point of expiry. Filing late – or worse, continuing to operate on an expired licence while awaiting renewal – exposes the business to regulatory sanction, potential suspension of activity and, in a banking context, grounds for a correspondent or local bank to close the account. In our practice, the renewal filing window and the supporting-document requirements are the two points where operators most frequently miscalculate the lead time needed.

The supporting documentation for renewal typically mirrors the initial application: up-to-date AML/CFT policies, current beneficial-ownership disclosure, evidence of the compliance function, financial statements and – where applicable – the Travel Rule implementation record showing that the business is correctly passing originator and beneficiary data on transfers. The NBG may also require updated fitness-and-propriety confirmations for controllers and senior managers if there has been any change in the corporate structure since the prior filing. Operators we advise routinely underestimate how much lead time is needed to assemble a clean document pack, particularly where the entity has a multi-jurisdictional shareholder chain and corporate-registry certificates must be apostilled and translated.

What does a licence variation involve?

A variation is required whenever the licensed entity proposes to add a new regulated activity, remove an existing one, or change a material condition of the authorisation – such as the permitted client categories, the asset classes covered, or the geographic scope of permitted operations. The NBG treats a variation as a substantive application, not an administrative amendment. That means a fresh assessment of whether the business has the people, systems and capital to support the expanded or altered scope. In practice, a variation application for adding custody services to an existing exchange licence will require the operator to demonstrate segregation arrangements, key-person expertise in custody operations and enhanced AML controls appropriate to a safeguarding function – all before the new activity commences.

Operators considering a variation should also assess whether the proposed change triggers obligations in other jurisdictions where the entity or its affiliates operate. A Georgian-licensed exchange adding stablecoin issuance, for example, would need to consider how that activity is classified under the MiCA regime if the entity passports into the EU, and whether a separate authorisation is required in any jurisdiction where EU users are served. MiCA draws a clear distinction between a CASP (Crypto-Asset Service Provider) providing exchange services and an entity issuing an asset-referenced token (ART) or e-money token (EMT) – the latter requires issuer-level authorisation, not just CASP registration. This cross-border interaction between a Georgian variation and the MiCA perimeter is a live issue for operators building towards a broader European client base.

For a scoped review of your current authorisation and what renewal or variation requires, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the banking relationships – change the analysis. Map your options

What does the renewal or variation process look like in practice?

The renewal and variation process at the NBG follows a staged submission and review model. The operator prepares the application package, submits it through the NBG's prescribed channel, and the regulator conducts a completeness review before moving to substantive assessment. Incomplete filings are returned, resetting the clock – a material risk for renewal applications where the expiry date is a hard deadline. The substantive review period varies by activity type and the complexity of the application; the NBG may issue requests for further information during this phase, and the response window is fixed. Missing an information request deadline is treated as a material deficiency.

The process broadly breaks into four steps for both renewal and variation:

  • Pre-filing review: audit the existing authorisation scope against current activity; identify any de-facto variation that has already occurred without regulatory approval; rectify before filing.
  • Document assembly: compile updated corporate, compliance and financial materials; obtain and authenticate third-country corporate certificates; update AML/CFT policy documentation to reflect current FATF standards.
  • Filing and completeness: submit to the NBG within the applicable window; respond promptly to any completeness queries.
  • Substantive review and approval: the NBG assesses the application; conditions may be attached to the renewed or varied authorisation; the operator confirms acceptance.

For a variation that adds a materially new activity, the operator should also consider whether a parallel banking review is required. Correspondent banks and Georgian commercial banks that service crypto businesses will often require sight of the varied authorisation – and may want prior comfort that the variation has been approved – before processing transactions for the new activity. Planning the banking conversation alongside the regulatory application avoids a gap between regulatory approval and operational launch.

How does Georgian licensing interact with cross-border banking and tax?

A Georgian VASP licence operates in a specific jurisdictional context, but the business it covers is rarely limited to Georgian users or Georgian payment rails. Cross-border interaction creates three distinct pressure points for renewal and variation work.

First, banking. Correspondent banks operating in major financial centres apply their own AML due-diligence standards when reviewing crypto-business clients. A renewal filing that reveals a material gap in the operator's AML record – for example, Travel Rule non-compliance on cross-border transfers – can trigger a bank review of the relationship, independent of the Georgian regulatory outcome. Operators we advise are increasingly seeing correspondent-banking requirements shape the AML documentation standard they adopt for their NBG filing, rather than the other way around. The two processes feed each other.

Second, tax structuring. The entity holding the Georgian licence may be the operating entity, but the group structure may place the intellectual property, treasury or parent holding function in a different jurisdiction. A variation that changes the Georgian entity's revenue streams – for example, adding a proprietary trading or staking function – can shift the transfer-pricing baseline for intra-group service fees and requires review of whether the Georgian entity's functional profile is still correctly described in the group's transfer-pricing documentation. We have seen this issue surface at renewal stage when updated financials reveal that the entity's actual activity has diverged from its documented function.

Third, FATF mutual evaluation exposure. Georgia's standing in the FATF evaluation cycle influences how counterpart regulators and banks assess Georgian-licensed entities. Operators should monitor the current FATF assessment of Georgia and factor any action-plan items into their compliance posture – not just for the NBG filing, but for the narrative they present to banking partners and to regulators in jurisdictions where the entity holds parallel authorisations or is applying for one.

A practical illustration: variation triggering a cross-border compliance review

In a recent matter, a payments-focused virtual-asset business holding a Georgian licence sought to add a custody activity following client demand for a safeguarding function. The variation application itself was straightforward in scope. What the pre-filing review surfaced was that the entity's AML controls had not been updated to reflect the Travel Rule obligations that a custody function – involving the receipt and dispatch of virtual assets on behalf of clients – would trigger. The entity's existing AML policy referenced exchange-service obligations only. We worked with the compliance team to rebuild the AML framework before filing, coordinating with allied counsel in a second jurisdiction where the entity held a parallel registration. The variation was approved, and the banking partner was briefed on the updated compliance framework in advance of the new activity going live. The client avoided a post-approval gap where the activity was licensed but the banking rails were not ready.

What are the most common mistakes in renewal and variation filings?

Late-stage discovery of de-facto variation is the single most common problem. An operator expands the assets it supports, begins serving a new client category, or starts providing a service that sits at the edge of its authorisation – without seeking prior approval. By the time the renewal filing arrives, the entity is operating partly outside its licensed scope. The NBG filing then either discloses the gap (triggering an enforcement conversation) or obscures it (compounding the risk). Neither outcome is acceptable. The correct approach is a pre-filing scope audit conducted before the renewal window opens.

A second common mistake is underestimating the document-authentication burden for entities with international shareholder structures. A Georgian renewal filing that requires current certificates of good standing, apostilles and notarised translations from multiple jurisdictions takes weeks – sometimes longer – to assemble. Starting that process at the point of filing, rather than two to three months before, regularly causes delay.

A third mistake is treating the renewal as an administrative event rather than a regulatory conversation. The NBG, like most supervisors in the leading digital-asset hubs, uses renewal as an opportunity to assess whether the operator's compliance posture has kept pace with regulatory developments. An operator that files a renewal package that looks identical to its original application – without updating AML/CFT policies, Travel Rule procedures or the beneficial-ownership disclosures – signals to the regulator that the business has not evolved its compliance function. That signal carries risk even where there is nothing formally deficient in the filing.

If a prior filing has stalled or raised questions from the NBG, a structured second review can identify the gap and the route back. Write to OBOLUS at info@oboluslaw.com. If the banking relationship has also been affected, we can address both tracks in a single mandate. Map your options

Which operators need renewal now versus a variation – a decision guide

The answer to whether an operator needs renewal, variation or both turns on three variables: what the current authorisation covers, what the entity is doing today, and where it intends to go.

Profile A – Exchange operator, unchanged activity, approaching expiry. This business needs a straight renewal. The priority is the pre-filing scope audit (to confirm no de-facto variation has crept in), document assembly and filing within the NBG window. The timeline is dominated by document preparation, not the regulatory review.

Profile B – Exchange operator adding custody. This business needs a variation, and the variation should be filed and approved before the custody activity commences. The compliance function must be rebuilt to cover a safeguarding mandate. If the renewal date is also approaching, the two applications may be coordinated, but the variation has the longer preparation lead time and should be started first.

Profile C – Multi-jurisdictional group with a Georgian operating entity. This business needs renewal in Georgia and, likely, a cross-jurisdictional licensing review. The Georgian renewal is a natural inflection point at which to audit whether the group's licensing stack – operating licence, custody authorisation, payment-transfer registration, any EU CASP authorisation – remains consistent with the actual activity being conducted from each entity. We structure these reviews as a single mandate rather than parallel workstreams.

Profile D – Operator whose activity has expanded beyond the current licence scope. This operator needs to disclose to the NBG and to seek a variation, ideally before the NBG identifies the gap through supervisory interaction. Early voluntary disclosure in most regulatory environments is treated more favourably than discovery. A pre-disclosure review to scope the exposure and structure the conversation with the regulator is the first step.

Addressing the assumption that a single offshore licence covers global operations

A common assumption among early-stage crypto operators is that a single registration – whether in Georgia, a Caribbean jurisdiction or a less demanding European jurisdiction – provides sufficient regulatory cover to serve clients across multiple markets. It does not. The licensing obligation is triggered by where clients are located and what services are provided to them, not solely by where the operating entity is incorporated or registered. An entity licensed in Georgia but serving clients in EU member states faces MiCA obligations – either a CASP authorisation in a member state or the obligation to operate within the applicable third-country provisions. An entity serving US users faces federal and state money-transmitter licensing requirements that a Georgian VASP registration cannot satisfy.

The practical consequence is that renewal and variation work in Georgia should always be conducted with an eye on the global licensing map. A renewal that confirms a Georgian licence is current and correctly scoped is not the end of the compliance story – it is one layer of a stack that must be managed as a whole. In our cross-border practice, we map the licence requirements across the operating, custody and payment layers in every jurisdiction where clients are served or assets are held, before a client commits to a structure. That map is what determines whether the Georgian licence is the anchor entity or one component in a multi-jurisdiction authorisation chain.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

The timeline varies by jurisdiction and activity type. In Georgia, the NBG's review period for a new VASP authorisation depends on application complexity and document completeness. Incomplete filings reset the clock. For renewal applications, the filing window is set by the authorisation itself, and the substantive review is generally shorter – but document assembly for entities with multi-jurisdictional ownership can take several weeks before filing even begins. We describe the expected phases qualitatively at the outset of each engagement rather than committing to a fixed number of weeks, because regulator responsiveness and document-authentication delays are outside any adviser's control.

Which jurisdiction is best for licensing my crypto business?

There is no universal answer. The right jurisdiction depends on where your clients are, what activities you conduct, what your banking requirements are, and what corporate tax position you are targeting. Georgia offers a relatively accessible entry point with a civil-law system and a maturing VASP regime, but it is not a substitute for EU, UK or US authorisation if those markets are material to your revenue. The decision involves mapping the full licence, banking and tax stack before committing to a structure – and that analysis should reflect where your business is going, not just where it is today.

Do I need a separate custody licence?

In most flagship jurisdictions, yes. Custody – holding or controlling virtual assets on behalf of clients – is treated as a distinct regulated activity from exchange or transfer services. Under the VARA regime in Dubai, MiCA in the EU and the MAS Payment Services Act in Singapore, a separate authorisation or activity-specific licence condition is required before a business may offer safeguarding. In Georgia, the NBG's activity-based framework follows similar logic: an exchange authorisation does not automatically confer custody rights. An operator adding custody to an existing activity must seek a variation of its authorisation before commencing that service.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, banking and tax stack across operating, custody and payment layers before our clients commit – structuring licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in VASP authorisation, renewal and variation strategy across common-law and civil-law regimes.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours