EST · MMXXVI
Home/Jurisdictions/Georgia/PSP and acquiring agreement in Georgia: Legal Requirements for Businesses
Banking, Payments & EMI Onboarding

PSP and acquiring agreement in Georgia: Legal Requirements for Businesses

Psp and acquiring agreement in Georgia. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Operating a payment service provider or acquiring business in Georgia without understanding the regulated perimeter is a fast route to frozen rails and enforcement action. Georgia – the South Caucasus republic with a progressively open financial-services regime supervised by the National Bank of Georgia (NBG) – has become a genuine destination for cross-border digital-asset and fintech operators seeking affordable access to SEPA-adjacent and CIS payment corridors. But the legal requirements for PSP agreements, acquiring arrangements and crypto-related banking are more structured than they appear on first inspection.

A PSP agreement (a contract between a merchant and a licensed payment service provider authorising acceptance of card and digital payments) sits at the intersection of Georgian payment regulation, international card-scheme rules and, increasingly, virtual-asset service obligations. Businesses entering Georgia without mapping that intersection risk the exact outcome they came to avoid: account closure, contract termination and regulatory exposure. This page sets out the regulated basis, the inbound process, the cross-border interaction with tax and banking, and the decision points that matter before you commit.

The regulatory perimeter for payments in Georgia

In Georgia, payment services are regulated by the National Bank of Georgia under the applicable payment-services and anti-money-laundering provisions, and a business accepting or routing payments commercially must either hold a licence or operate through a licenced intermediary. The NBG issues payment institution licences to entities established in Georgia; foreign entities that wish to offer payment services to Georgian merchants or consumers typically cannot do so from outside the country without a Georgian-registered presence or a licenced local partner. That perimeter is firm.

Acquiring – the specific service of processing card transactions on behalf of merchants and settling the proceeds – requires that the acquirer hold, or be sponsored by, a party that holds, the necessary payment institution status under NBG rules and must satisfy the card-scheme (Visa, Mastercard) principal-member or member-affiliate requirements in parallel. The National Bank of Georgia is the single prudential and conduct supervisor for payment institutions. There is no separate fintech sandbox that removes the licencing requirement for commercial-scale operations.

For crypto-specific PSP arrangements, Georgia applies a layered reading: a VASP (virtual asset service provider) that also processes fiat on behalf of clients may fall under both the virtual-asset provisions and the payment-services provisions simultaneously. Operating across both layers without dual authorisation is the single most common structural error we see in inbound mandates. Operators arriving from EU or CIS jurisdictions regularly assume their home-country authorisation travels with them. It does not.

Who needs a PSP licence in Georgia?

Any business that routinely executes payment transactions, issues payment instruments, operates a payment account or provides money-remittance services to merchants or end-users in Georgia on a commercial basis requires a payment institution licence from the NBG or must contract with a licenced party that is itself responsible for the regulated activity. The test is functional, not formal: the label a business puts on its service is irrelevant if the economic substance constitutes a regulated payment activity.

Inbound digital-asset businesses typically encounter the requirement in one of three ways. First, a crypto exchange that settles fiat withdrawals to Georgian bank accounts is, in practice, routing payment transactions through the Georgian financial system and may need either a payment licence or a banking partnership agreement that places the regulated activity squarely on the partner bank. Second, a token issuance platform that allows fiat subscription via card is providing a card-acceptance service – acquiring – that requires the acquiring party to be licenced. Third, a stablecoin or e-money issuer distributing to Georgian users must assess whether the issuance itself, independently of distribution, triggers NBG authorisation requirements.

A common assumption is that white-labelling a licenced PSP's rails is always a clean solution. It can be – but the contractual structure must correctly allocate regulated-activity responsibility. An undisclosed principal arrangement, or a revenue-share model that obscures the true operator, can cause the NBG to look through the arrangement and find an unlicenced principal. We map the contractual and operational flow before recommending the structure.

What does the inbound PSP application process look like?

Establishing a Georgian-licenced payment institution requires incorporating a limited-liability or joint-stock company in Georgia and then applying to the National Bank of Georgia for a payment institution licence. The application covers the corporate governance structure, the business plan and projected transaction volumes, the AML/CFT programme (aligned to FATF standards, which Georgia formally adopts), the IT and operational resilience framework, and the beneficial-ownership disclosure for all qualifying shareholders.

The NBG conducts a fitness-and-propriety assessment of all directors and significant shareholders. The application timeline varies by complexity and completeness of submission – operators should plan for a process measured in months rather than weeks, and incomplete applications restart the clock. We prepare the full documentation package and manage the regulator dialogue; in our experience, the most common delay is the AML programme narrative, which regulators scrutinise closely for crypto-adjacent applicants.

For businesses that need operational speed, the alternative is a partnership agreement with an existing Georgian-licenced PSP. This route avoids the licencing timeline but requires careful contractual design: the licence-holder must genuinely perform the regulated activity and must not function as a shell for an unlicenced operator. The NBG has authority to examine the substance of such arrangements.

A further procedural element: card-scheme membership or sponsorship runs in parallel with NBG licencing and follows Visa and Mastercard's own due-diligence timelines. The two processes are independent but interdependent – NBG authorisation alone does not make a business a card acquirer. Mapping both tracks at the outset avoids the common mistake of completing NBG work only to face months of additional delay at scheme level.

The process above describes the standard path. Your facts – the entity structure, the user base, the fiat rails you intend to use and the crypto-asset layer sitting above them – change the analysis materially. For a scoped assessment of your specific situation, contact OBOLUS at info@oboluslaw.com.

How does crypto banking interact with Georgian fiat rails?

Georgia's commercial banking sector is relatively open to virtual-asset businesses by regional standards, but the risk-appetite gap between different banks is wide, and the terms on which any given bank will onboard a VASP depend heavily on the VASP's AML programme, its transaction-monitoring capability and the jurisdictional provenance of its client funds.

The typical fiat-rail architecture for a Georgian-based VASP runs: a Georgian bank account for fiat settlement, a licenced PSP agreement for card acceptance and merchant acquiring, and a correspondent-banking arrangement for USD and EUR cross-border flows. Each layer has its own onboarding requirement. The bank assesses the VASP's beneficial ownership, the source-of-funds narrative and the transaction-monitoring framework. The PSP assesses the merchant's business model and chargeback profile. The correspondent bank assesses the downstream bank's VASP exposure. A weakness at any single layer can cause the whole structure to fail.

The Travel Rule – the FATF obligation to pass originator and beneficiary information with virtual-asset transfers – applies to Georgian VASPs and is a condition of maintaining banking relationships with international counterparties. Georgian banks onboarding a VASP will ask for evidence of Travel Rule compliance as part of their own correspondent-banking obligations. Operators who cannot demonstrate a technical solution for Travel Rule data transmission will find their banking options sharply limited.

In our cross-border practice, we have seen Georgian banking relationships unravel not because the VASP lacked a Georgian licence but because its AML programme failed to address the risk categories its banking partner was itself obligated to manage for its correspondent. The solution is to design the AML programme with the banking partner's own regulatory obligations in mind – a point many operators miss when they treat AML compliance as a box-checking exercise.

How does EMI onboarding work for a Georgia-based VASP?

An EMI (electronic money institution) onboarding arrangement – where a VASP uses an EU or UK licenced e-money institution to hold client fiat and execute payments while the VASP handles the crypto layer – is a widely used structure for Georgian-based operators who need SEPA access or GBP payment capability without establishing a separate EU or UK entity. The arrangement works legally when the EMI genuinely performs the regulated e-money and payment functions and the VASP's role is correctly characterised as a technology or agency layer above it.

The onboarding process with an EU EMI requires the VASP to satisfy the EMI's own due-diligence framework, which is typically built on the EMI's FCA or national competent authority obligations. That means submitting: a full corporate structure chart, beneficial-ownership documentation, the AML/CFT policy, evidence of transaction-monitoring capability, a description of the VASP's own regulatory status in Georgia, and – increasingly – a MiCA readiness assessment if the VASP intends to serve EU customers. EMIs that operate under EU or MiCA-adjacent frameworks are under intensifying pressure from ESMA and national regulators to manage their VASP-client exposure carefully.

From a Georgian legal perspective, the VASP using an EMI for fiat rails must ensure that the client-money flows visible to Georgian tax authorities and the NBG are consistent with the described structure. A mismatch between the contractual architecture and the actual money flows is a significant compliance risk. We structure these arrangements end-to-end, mapping the contractual position under Georgian law, the EMI's home-jurisdiction obligations and the cross-border tax treatment simultaneously.

If a prior EMI application stalled or an existing banking relationship was closed, a second-look analysis can identify the structural reason and the path forward. Write to OBOLUS at info@oboluslaw.com or message us via t.me/oboluslaw.

What is the cross-border tax interaction for a Georgian PSP structure?

Georgia operates a territorial tax system, meaning that Georgian-resident companies are taxed on Georgian-source income, and income genuinely generated outside Georgia by a Georgian entity is not subject to Georgian corporate income tax under the Estonian-model CIT regime Georgia adopted. This creates a structurally attractive position for payment businesses that route international transaction volume through a Georgian licenced entity, but the attraction is conditional on the substance being real: the entity must have genuine management and control in Georgia, genuine employees or contractors performing the regulated functions, and genuine economic activity that supports the territorial character of the income.

The interaction with the PSP licence is direct. An NBG-licenced payment institution performing genuine acquiring and settlement functions in Georgia can, correctly structured, achieve a low effective tax rate on the income it generates from international merchants. But a shell entity that holds a Georgian licence while actual operations and decision-making occur elsewhere does not achieve the territorial benefit and may trigger permanent-establishment exposure in the jurisdiction where operations genuinely occur.

For crypto-specific income – trading revenue, staking rewards, token-issuance proceeds – the Georgian tax treatment turns on how the NBG and the Georgian Revenue Service characterise the activity. Georgia does not yet have a MiCA-equivalent comprehensive crypto-asset regulation, so classification questions remain live. We work with Georgian tax counsel to map the income characterisation risk before the structure is committed.

Value-added tax treatment of payment and crypto services in Georgia follows Georgian VAT law, which broadly exempts financial services from VAT but contains category-specific rules that can produce unexpected liability for certain crypto-related activities. A VAT analysis is a standard component of our pre-commitment review.

A recent PSP onboarding matter

In a recent mandate, a European-incorporated crypto exchange sought to establish Georgian PSP infrastructure to serve CIS merchants and route fiat settlement through Georgian correspondent banking. The business had assumed its existing EU-registered entity could contract directly with Georgian merchants as a PSP without a Georgian licence or a local licenced partner. Our initial review identified that the proposed arrangement placed regulated acquiring activity directly on the EU entity without NBG authorisation, exposing the business to enforcement and to card-scheme suspension. We restructured the arrangement: a Georgian subsidiary was incorporated and applied for payment-institution status; a bridge PSP agreement was negotiated with an existing Georgian-licenced acquirer to cover the operational period during the application; and the AML programme was rewritten to satisfy both the NBG's FATF-aligned requirements and the onboarding criteria of the target Georgian banking partner. The business was live on Georgian rails within the application window, without enforcement exposure.

Which structure fits your profile?

The right structure depends on your operational timeline, transaction volume and the jurisdictions from which your clients come. Three broad profiles account for most inbound mandates.

Profile A – the fast-entry operator needs Georgian fiat rails within a short operational window and has transaction volumes below the threshold at which the economics of a standalone NBG licence make sense. The correct instrument is a commercial PSP partnership agreement with a Georgian-licenced acquirer, properly structured to place regulated-activity responsibility on the licensed party. The risk is counterparty dependency; the mitigation is a contractual framework that preserves operational continuity and the right to migrate to a direct licence as volume grows.

Profile B – the scaling exchange or custodian intends to make Georgia a primary operational hub, processes material transaction volume with Georgian-resident merchants or users, and needs direct control over its payment rails. The correct instrument is a direct NBG payment-institution licence, developed in parallel with card-scheme membership. The timeline is measured in months; the capital requirement is set by the NBG on a category basis and should be confirmed against current published requirements. The risk is application timeline uncertainty; the mitigation is thorough pre-submission preparation.

Profile C – the cross-border structure uses a Georgian entity as one layer in a multi-jurisdiction payment stack (for example, a Georgian PSP entity feeding into an EU EMI for SEPA access and a separate custodian entity for crypto assets). This is the most complex profile and requires the Georgian legal analysis, the EMI relationship structuring and the Georgian tax substance question to be addressed simultaneously. A gap in any one layer will compromise the others.

In our practice, operators who commit to a structure before completing the full legal mapping – licence layer, banking layer, tax layer – consistently encounter the same problem: a single layer that was not designed for their facts disrupts the whole stack. We map the three layers as one mandate rather than three disconnected workstreams.

What are the most common legal mistakes in Georgian PSP structures?

The most common mistake is assuming that a contract with a Georgian-licenced PSP automatically insulates an unlicenced operator from regulatory scrutiny. The NBG has the authority to examine the substance of PSP relationships and, where it finds that an unlicenced party is the true commercial principal, can treat that party as operating without authorisation. The contractual allocation of regulated-activity responsibility must match the operational reality.

The second common mistake is treating AML compliance as a one-time document exercise. Georgian banks and PSPs that are themselves supervised by the NBG expect their VASP and fintech clients to maintain living AML programmes – with updated risk assessments, transaction-monitoring calibration and staff training records. A programme written at onboarding and not updated after the first year of operation is a frequent cause of account closure.

The third mistake is the myth that a single offshore licence is enough to serve clients globally. A Georgian-incorporated VASP serving EU clients may require MiCA CASP authorisation or at minimum a regulatory analysis of whether each EU member state's transitional provisions apply. A Georgian PSP routing transactions through UK correspondent banking may attract FCA financial-promotion rules if it markets to UK users. The Georgian licence solves the Georgian regulatory question. It does not dissolve the regulatory questions in the jurisdictions where users sit, where banking lives or where the token is listed.

A fourth structural error: failing to register for the Travel Rule before opening a banking relationship. Georgian correspondent banks increasingly require written evidence of Travel Rule compliance capability – a technical solution, a policy and a testing record – as a condition of initial onboarding, not as a post-onboarding requirement. Arriving at the banking conversation without that documentation delays onboarding or terminates it.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily because the account-holder's AML programme, transaction-monitoring records or beneficial-ownership disclosure does not satisfy the bank's own regulatory obligations to its correspondent banks. A VASP that cannot demonstrate a current, operational compliance framework – including Travel Rule capability, updated risk assessments and documented monitoring results – presents a compliance liability that most banks will not absorb. A structural review before onboarding, rather than after closure, materially improves the outcome.

How can a VASP onboard with an EMI?

A VASP onboards with an EMI by satisfying the EMI's own due-diligence framework, which reflects the EMI's obligations to its national regulator. Required documentation typically includes a full corporate structure and beneficial-ownership chart, a current AML/CFT policy, evidence of transaction-monitoring capability, the VASP's own regulatory status documentation and a clear description of the business model and client base. EMIs operating under EU frameworks increasingly require a MiCA readiness assessment for VASPs serving EU customers. Preparation of a coherent, regulator-grade disclosure package is the most effective way to accelerate EMI onboarding.

What does client-money safeguarding require?

Client-money safeguarding requires that a payment institution or EMI hold client funds in a manner that keeps them legally and operationally separate from the institution's own assets, so that client funds are not at risk in an insolvency. The specific safeguarding method – designated bank accounts, insurance or a guarantee – and the timing of the safeguarding obligation vary by jurisdiction and licence category. In Georgia, the NBG sets the applicable safeguarding requirements for payment institutions; for EMI-based structures, the EMI's home-jurisdiction rules govern. Both must be addressed in the contractual architecture.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, banking and tax stack across operating, custody and payment layers before you commit – and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in payment-services licensing, VASP regulatory perimeters and cross-border AML compliance for digital-asset businesses entering emerging and transitional markets.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours