EST · MMXXVI
Home/Jurisdictions/Georgia/Sanctions screening for crypto in Georgia
Compliance, AML & Travel Rule

Sanctions screening for crypto in Georgia

Sanctions screening for crypto in Georgia. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

A crypto exchange registered in Georgia – or routing transactions through a Georgian banking corridor – faces the same question early in its compliance buildout: which sanctions regime applies, who enforces it, and what does a defensible screening program actually look like in this jurisdiction? The answer is more demanding than many operators expect. Georgia maintains its own national sanctions list, applies United Nations Security Council measures as a matter of treaty obligation, and sits on a banking corridor that is closely monitored by correspondent banks in the European Union and the United States. A VASP (virtual asset service provider) that underestimates this triad risks account closures, frozen rails and, in serious cases, criminal referral.

Sanctions screening for crypto in Georgia requires real-time list matching across at least three layers – the national list maintained by the National Bank of Georgia, UN consolidated measures, and the de-facto extraterritorial reach of OFAC and EU restrictive measures that any USD- or EUR-adjacent banking relationship imports automatically. The Travel Rule (the obligation to pass originator and beneficiary data alongside a virtual-asset transfer) intersects directly with screening: you cannot screen a counterpart you have not identified. The sections below map the regulatory basis, the operational program, the cross-border banking dynamic, and the decision points an inbound business must resolve before going live.

What is the regulatory basis for sanctions screening in Georgia?

The National Bank of Georgia is the primary prudential and AML supervisor for financial institutions operating in the country, and its reach extends to entities that provide payment and exchange services involving virtual assets. Georgian AML legislation, aligned progressively with FATF Recommendation 15 (which requires states to apply AML/CFT measures to virtual assets and VASPs), establishes the baseline obligation: every covered entity must screen customers, beneficial owners and counterpart VASPs against applicable lists before and throughout a business relationship. The Georgian Ministry of Finance and the Financial Monitoring Service of Georgia (FinMS) share enforcement authority for anti-money-laundering matters, including sanctions-related failures.

Georgia is not a member of the EU, so EU restrictive measures do not bind Georgian entities as a matter of domestic law. However, the practical reach of those measures is wide. Any Georgian VASP that settles in EUR, holds a EUR-denominated account, or uses a correspondent bank that is itself subject to EU jurisdiction is exposed to secondary compliance expectations. The same applies to USD flows and the Office of Foreign Assets Control (OFAC): no sanctions designation authority against Georgian law, but real operational risk for any business that touches the dollar payment system. In our practice, we regularly advise Georgian and inbound operators that the effective compliance perimeter is the union of all four regimes – domestic, UN, OFAC and EU – not just the one that applies under domestic law.

The National Bank of Georgia has progressively tightened its supervisory expectations for virtual-asset businesses. Operators providing exchange, transfer or custodial services must register or license with the National Bank, implement a risk-based AML/CFT program, and demonstrate that program to examiners on request. The obligation to screen extends to institutional counterparties: a Georgian VASP that receives settlement from an offshore exchange must screen that exchange and its known ultimate beneficial owners, not merely the transaction itself.

Which crypto businesses in Georgia must implement sanctions screening?

Any entity conducting virtual-asset exchange, transfer, custody or brokerage services in or from Georgia is within scope of the national AML and sanctions framework, regardless of where its customers are located. The functional test – whether the business handles value on behalf of others using virtual assets – governs, not the marketing label the operator uses. Importantly, a business registered offshore but operating through Georgian infrastructure (banking, staff, wallet infrastructure) may trigger Georgian regulatory obligations even without a Georgian entity, depending on the nexus analysis the National Bank applies.

Inbound businesses often ask whether a single offshore licence satisfies Georgian AML expectations. It does not. A common assumption is that a VASP licence from a recognised offshore jurisdiction – the BVI, Cayman or Seychelles – eliminates the need to engage the Georgian AML regime. In practice, that assumption is incorrect. Georgian law looks at where the service is provided and where the customer relationship is managed, not where the entity was incorporated. An operator running sales, onboarding or support from Georgia while holding only an offshore licence is conducting a regulated activity under Georgian AML law without the required authorisation. The enforcement consequences – loss of banking access, regulatory referral, personal liability for directors – are entirely domestic and immediate.

The scope question also has a cross-border dimension for inbound European operators. A CASP authorised under MiCA (the EU's Markets in Crypto-Assets Regulation) and passporting into EU markets is not thereby licensed to serve Georgian customers or to operate from Georgian infrastructure. MiCA passporting is an EU/EEA instrument; it ends at the Georgian border. The operator needs a separate Georgian compliance posture, and, in many structures, a separate Georgian registration.

How should a VASP build its sanctions screening program in Georgia?

A defensible screening program in Georgia runs across five operational layers, each with a distinct technical and legal requirement. The first is list management: the program must integrate the Georgian national list, the UN Consolidated Sanctions List, OFAC's Specially Designated Nationals list and the EU consolidated list as a matter of operational practice – even where the latter two are not legally mandatory under Georgian domestic law – because the banking relationships that sustain the business require it.

The second layer is KYC framework (know-your-customer) integration. Sanctions screening produces false positives and missed hits unless the underlying customer data is current, structured and searchable. A VASP that collects identity data in unstructured formats, across multiple onboarding funnels, cannot run consistent screening. The National Bank expects a risk-based approach: enhanced due diligence for higher-risk customers, including politically exposed persons and customers from high-risk jurisdictions identified by FATF, with a documented rationale for each risk rating. Transaction monitoring – the third layer – ties screening to ongoing activity rather than limiting it to onboarding. Automated rules should flag structuring patterns, unusual counterpart VASPs and transfers to or from jurisdictions that carry elevated risk under FATF guidance.

The fourth layer is Travel Rule implementation. Under FATF Recommendation 16 (the Travel Rule as applied to virtual assets), a Georgian VASP must transmit originator and beneficiary information alongside any qualifying virtual-asset transfer. The de-minimis threshold and the technical messaging standard – whether ISO 20022, IVMS101 or a proprietary protocol – vary by bilateral arrangement and the receiving VASP's technical capability. In our cross-border practice, we see operators underestimate the Travel Rule onboarding burden: every institutional counterpart is effectively a new compliance relationship, not merely a routing entry. The fifth layer is sanctions-hit management: a documented escalation path, a hold procedure for matched transactions, and a clear reporting line to the MLRO (Money Laundering Reporting Officer) and, where required, to the Financial Monitoring Service.

Contextual bridge: The program structure above reflects the standard path for a well-resourced operator. The entity type, the customer geography and the banking corridor in use all modify the analysis significantly.

For a scoped assessment of your sanctions and AML program for Georgian operations, contact OBOLUS at info@oboluslaw.com. The standard path above is a starting point; your facts determine which elements require priority build-out. Map your options

How does the banking corridor affect sanctions exposure for crypto firms in Georgia?

Georgia's position as a regional banking corridor for digital-asset businesses creates a specific compliance dynamic that goes beyond what domestic AML law alone requires. Georgian banks that serve VASPs are themselves subject to correspondent banking relationships with EU and US institutions, and those correspondents routinely conduct transaction monitoring (automated surveillance of payment flows for sanctions and financial-crime indicators) on the flows they process. A Georgian VASP whose AML program is technically compliant with domestic law but whose transaction patterns trigger correspondent-bank surveillance rules will face account suspension regardless of its domestic regulatory status.

We have seen this pattern consistently in recent engagements. A crypto brokerage operating from Tbilisi with a clean Georgian registration loses its EUR correspondent account not because of any Georgian regulatory action, but because the EU bank running the correspondent relationship flags the volume of transfers to high-risk counterpart jurisdictions. The fix is not a better Georgian licence: it is a correspondent-bank-grade AML program from day one, covering the full list universe the bank applies, not just the Georgian domestic minimum.

The implication for inbound operators is direct. If you are selecting Georgia as an operating or holding jurisdiction partly because of its accessible banking environment, your sanctions screening program must be calibrated to the highest standard in your banking chain, not the lowest standard that satisfies local law. In practice, that standard is often OFAC's – because US dollar correspondent risk is the dominant concern for the major Georgian commercial banks.

How has cross-border sanctions compliance played out in practice?

In a recent matter, a payments company with Georgian and EU entities had structured its operations to route retail settlement through Georgia while holding MiCA-adjacent authorisation in an EU member state. When the EU bank running the correspondent relationship froze the Georgian account pending a sanctions review, the company had fewer than seventy-two hours before automated client refunds would fail. We engaged the bank's compliance team directly, provided the full OFAC and EU consolidated screening log for the preceding six months, and demonstrated that the flagged counterpart VASP had been deregistered from the AML-listed jurisdiction before any of the relevant transactions were processed. The account was reinstated and the company implemented a real-time list-update protocol tied to each transaction batch. The episode illustrates that a technically compliant program is not enough: you also need the documentation infrastructure to prove compliance on short notice.

What is the interaction between sanctions compliance and tax or corporate structure?

Sanctions screening obligations follow the operational and banking footprint of a business, not its legal form. A Georgian holding company that owns an offshore VASP, or an offshore parent that operates through a Georgian subsidiary, inherits compliance obligations at every node where regulated activity occurs. This has direct implications for corporate structuring decisions. An operator that creates a thin Georgian entity to access banking while placing substance offshore creates a mismatch: the entity with the banking relationship carries Georgian AML obligations it is not staffed to discharge, while the entity with the operations and the beneficial owners sits outside the supervisory perimeter.

Tax and banking structuring decisions therefore need to be made with the sanctions and AML obligations mapped first, not afterwards. In our practice, we regularly advise on the sequencing: the compliance posture shapes the entity structure, not the other way around. For a Georgian-based digital-asset business, the relevant tax considerations – the treatment of trading income, the VAT position on token transactions, the transfer-pricing analysis for a multi-entity group – are distinct questions, but they cannot be answered in isolation from where the regulated activity sits and what AML registrations that activity requires.

For inbound operators considering Georgia as part of a multi-jurisdictional structure alongside, for example, an EU MiCA authorisation or a Singapore MAS licence, the compliance stack runs across all three jurisdictions simultaneously. The Travel Rule obligations imposed by MAS, the CASP AML requirements under MiCA, and the Georgian domestic AML regime each impose independent obligations. Gaps between regimes – periods when a transfer has left the MAS perimeter but has not yet entered the MiCA perimeter – are the highest-risk moments, and the ones examiners in all three jurisdictions will probe first.

If a prior application stalled or a banking relationship broke down because of unresolved sanctions questions, a second read can identify the structural gap and the route back. Write to info@oboluslaw.com or map your options with us.

What governance does a Georgian VASP need for AML and sanctions oversight?

The MLRO role – the individual accountable to the Financial Monitoring Service and to senior management for AML and sanctions compliance – is not optional for a regulated entity in Georgia. The MLRO must have the seniority, the independence and the documented authority to suspend transactions, file suspicious activity reports, and escalate to external counsel or regulators without board approval. A common structural failure is embedding the MLRO function in an operations or finance role where commercial pressures create conflicts. Regulators in the leading hubs increasingly expect the MLRO to report directly to the board or the audit committee, not through a business-line head.

For smaller VASPs, the MLRO may be an individual director. For larger operations, a deputy MLRO and a clear succession plan are expected. In either case, the documented policies and procedures must be current, board-approved and tested at least annually against the live list environment and the current FATF guidance on virtual assets. An examiner visiting a Georgian VASP will ask to see the last three months of screening logs, the last suspicious transaction report filed, and the minutes evidencing board oversight of the AML program. The absence of any one of these does not produce a fine immediately; it produces a remediation notice that, if unresolved, escalates to licence suspension.

What is the decision matrix for an inbound operator considering Georgia?

The right compliance posture for a Georgian operation depends on three variables: the entity's customer geography, its banking corridor, and its institutional counterpart profile. An operator serving predominantly Georgian retail customers through Georgian banks, with no USD or EUR settlement, faces a comparatively contained compliance perimeter – primarily the domestic national list, UN measures, and FATF-baseline AML standards. The program is real but scoped.

An operator using Georgia as a regional hub – serving customers across the CIS, the Caucasus and the EU, settling in multiple currencies, and receiving flows from offshore VASPs – faces the full union of domestic, UN, OFAC and EU sanctions regimes as an operational matter, regardless of domestic legal obligations. That operator needs a program calibrated to correspondent-bank grade from the outset, with real-time list feeds, automated transaction monitoring, and a Travel Rule solution covering at least the EU and FATF-member counterpart VASPs it transacts with.

A third profile is the operator using a Georgian entity as a holding or treasury vehicle within a larger multi-jurisdictional group. That structure does not eliminate AML exposure at the Georgian node: if any regulated activity flows through the entity – even intra-group settlement – the Georgian AML registration obligation is triggered. Operators in this profile frequently underestimate the cost and timeline of bringing a Georgian entity into compliance after the fact, when the banking relationship is already live and the examiner is already asking questions.

In all three profiles, the decision to engage Georgian counsel and map the compliance stack before committing the corporate structure is materially cheaper than remediation. We map the licence, AML and banking stack across operating, custody and payment layers before you commit – not after a bank closure forces the question.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule, grounded in FATF Recommendation 16 as applied to virtual assets, requires a VASP to collect, verify and transmit the name, account identifier and, where applicable, the address or identification number of both the originator and the beneficiary alongside any qualifying virtual-asset transfer. The obligation applies at both ends of the transfer: the sending VASP must transmit the data, and the receiving VASP must obtain and screen it. Failure to implement a compliant Travel Rule solution exposes the VASP to regulatory sanction and, in many jurisdictions, to loss of banking access when correspondent banks detect unmatched flows.

Who must act as MLRO for a crypto firm?

Every regulated virtual-asset business must designate an individual as its MLRO (Money Laundering Reporting Officer) – the person accountable for the firm's AML and sanctions compliance, for filing suspicious activity or transaction reports with the relevant financial intelligence unit, and for escalating material risks to senior management or the board. The MLRO must have sufficient seniority and independence to act without commercial override. Regulators across the major VASP hubs, including the National Bank of Georgia, expect the MLRO to be named in the AML policy and to have documented authority over transaction holds and regulatory filings.

How do regulators audit crypto AML programs?

Regulators auditing a VASP's AML program typically request the current written AML policy and procedures, the most recent risk assessment, a sample of customer due-diligence files across risk tiers, the last three to six months of transaction-monitoring alerts and their resolution, evidence of Travel Rule compliance on a sample of transfers, and records of any suspicious transaction reports filed. They also test the governance layer: board minutes showing oversight of the AML function, evidence of MLRO training, and records of any third-party AML audit conducted. Gaps in documentation – rather than gaps in underlying compliance – are the most common examination finding for crypto firms.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the AML, sanctions and compliance programs that sit around regulated digital-asset operations. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence stack across operating, custody and payment layers before you commit – not after a compliance failure forces the question. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML program design, sanctions screening frameworks and VASP regulatory compliance across emerging and established digital-asset jurisdictions.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours