RegTech — What the AML Law Actually Requires
Regulatory technology — software systems that help accountable persons perform their duties of preventing money laundering and terrorism financing — is most effective when built on the exact requirements of the law. The Georgian Law on Facilitating the Suppression of Money Laundering and Terrorism Financing defines five directions in this field: the recording and submission of information (Article 7), the manner and deadlines of submission (Article 26), the retention periods (Article 27), the compliance-control system (Article 29) and the group-level architecture (Article 30). This page explains these requirements from an engineering standpoint — what a system must deliver to be lawful.
Article 7 — Recording and Statistical Submission
Article 7 obliges the competent body, within its authority, to record and — at the request of the working group, within a reasonable time — to submit detailed statistical information: the number of reports submitted and selected for analysis, data exchanged with financial intelligence services of other jurisdictions, statistics of investigations and judgments, a list of seized property, and the number and types of inspections conducted by supervisory bodies. The systematic processing of this data is precisely the regulatory-technology layer that gives the authorities a systemic picture — and the accountable person's internal systems are the first link of this chain.
Article 26 — the Manner and Deadlines of Submission
Article 26 provides that reports and other information are submitted to the Financial Monitoring Service electronically or in writing, in the manner established by a subordinate act of the head of the Service — and here opens the main purpose of regulatory technology: the capacity of electronic transmission. The deadlines are strict: the report provided for the case where a grounded suspicion arises must be submitted to the Service on the very day the suspicion arises; information connected with the movement of cash or securities across the customs border of Georgia — no later than 5 working days from the movement; and information provided upon request — no later than 2 working days. A system that cannot support these deadlines fails a statutory requirement — which is why deadline control is part of the technological architecture, not a secondary detail.
Article 27 — the Five-Year Retention
Article 27 governs retention periods: the accountable person must keep the obtained information and the results of the analysis performed, as well as documentation and business correspondence connected with the client's account, for 5 years from the termination of the business relationship or the conclusion of a one-off transaction; information connected with a transaction — for 5 years from its preparation, conclusion or performance; submitted reports and other documents are likewise kept for 5 years. The period may be extended on the basis of a substantiated request by no more than 5 years. The same article requires that information be kept in a form allowing its immediate submission, and, in criminal prosecution, its use as evidence. It also directly obliges the accountable person, taking into account the nature and volume of its activity, to create an appropriate electronic system for the recording and processing of data — the law itself demands a technological solution.
Articles 29 and 30 — Internal Control and the Group Level
Article 29 defines the compliance-control system: the accountable person must implement such policies, rules, systems and mechanisms as are proportionate to the nature and volume of its activity and the associated risks. The internal instruction defines the responsible person, the rules for selecting staff and continuing training, and an independent audit. Article 30 rises to the banking-group level: supervision of a group's activity encompasses group compliance, and the systems architecture here requires unified management of the data of every member of the group.
Frequently Asked Questions
Below we answer the most frequent questions about regulatory technology.
For how long must data be retained?
For 5 years — both for client-identification data and for transaction-related data; on a substantiated request the period may be extended by no more than 5 years.
Within what deadline is a suspicious-transaction report submitted?
On the very day the grounded suspicion arises; information on the cross-border movement of cash — no later than 5 working days from the movement.
Is an electronic system mandatory?
Yes — the law directly obliges the accountable person to create an appropriate electronic system for the recording and processing of data.
What is the core of the compliance-control system?
Proportionality — the policies, rules, systems and mechanisms must match the nature, volume and risks of the activity.
How We Help on Legal.ge
On Legal.ge you can contact an experienced financial-law lawyer who translates a regulatory-technology project into the language of the law: defines the system's statutory requirements across all five directions, assesses the compliance of existing solutions against each of them, and assists in communication with the supervisory authority. Fill in the request form on the site and get a qualified consultation on Legal.ge.
