Compliance Monitoring: the Regime of Operational Oversight
Designing a compliance program is a matter of design; monitoring is about how that design works in daily practice and how the state verifies it. The law on the prevention of money laundering and terrorism financing creates two layers here: internal ongoing monitoring and external inspection, with the consequences of non-compliance set out separately.
This page is precisely about operational control: how preventive measures are carried out during the life of a relationship, how risks are reassessed, and who checks the system from outside.
Internal Ongoing Monitoring
Under Article 12, the accountable person applies preventive measures according to the client’s risk level before a one-off transaction and before establishing a business relationship, and also with appropriate periodicity — during the relationship and upon material changes in the client’s circumstances. Monitoring is thus not a one-off check: it spans the entire life of the relationship.
Verification has a degree of flexibility: at lower risk, verification of the client or beneficial owner may be completed after the relationship is established, where this is necessary to avoid interrupting service — but it must then be completed as quickly as possible within reasonable limits. Opening or maintaining an anonymous or fictitiously named account is categorically prohibited; electronic identification follows the procedure established by the supervisory authority and agreed technical procedures.
The technical side of identification is regulated in detail as well: a financial institution is empowered to open an account before verification, where the execution of operations on the account in the client's name or by the client's order is prohibited until the verification is completed; preventive measures may be carried out electronically, without direct contact with the client; and the list of identification data is determined by a subordinate act of the head of the service.
Article 8 gives monitoring its substantive core: the accountable person periodically assesses and records the risks connected with its activity — for a head enterprise, also at group level; the client’s risk level is determined before a one-off transaction and before establishing the relationship, and then periodically and upon material changes. Before introducing a new technology, product or service, the associated risks are assessed in advance.
Article 8 also enumerates the grounds of risk assessment: the client and the beneficial owner, the essence of their activity and the jurisdiction of their location, the product, the service or its delivery channel, the transaction and other risk factors. To manage and reduce the identified risks the accountable person carries out effective measures, and in the assessment it considers the national risk-assessment report and the action plan, the guidance and recommendations of the service and the supervisory authority — the results of the national report are also reflected in the system.
External Oversight: Inspection and Risk Level
Under Article 38, the supervisory authority must ensure compliance with the law and subordinate acts through remote and/or on-site inspection. The type and frequency of inspection are determined on the basis of the nature, volume, diversity and risk level of the accountable person’s activity — supervision itself is risk-based.
The authority may request and receive necessary information, including confidential information, for conducting inspections or determining the risk level; it determines the risk level periodically and upon material changes, taking into account the national risk-assessment report. It issues guidance and methodological recommendations and, upon a violation, determines and applies appropriate supervisory measures.
Consequences of Non-Compliance
Article 43-1 provides that failure to perform requirements established by the law first triggers a warning, and repetition of the same act entails a fine of 1 000 lari. An important note: by the law’s own definition this sanction does not cover accountable persons — their response runs through a different system of supervisory measures. Planning your monitoring therefore starts with determining which status your company holds under this law.
Documentation here matters as much as the measures themselves: at the supervisory authority’s request, the accountable person must substantiate that it assessed the risks properly and carried out effective measures to manage them. That substantiation is only possible when each assessment, update and decision is recorded in the internal system in due time.
Frequently Asked Questions
Below are the most frequent questions about compliance monitoring.
When does inspection happen and how often?
Inspection may be remote or on-site; its type and frequency depend on the risk level, which the supervisory authority determines periodically.
Can verification be completed later?
At lower risk, yes — after the relationship is established, where necessary to avoid interrupting service, but as quickly as possible.
Are anonymous accounts allowed?
No. Opening or maintaining an anonymous or fictitiously named account is prohibited.
What fine is provided?
Failure first triggers a warning; repetition entails a fine of 1 000 lari; this rule does not apply to accountable persons.
Who runs risk reassessment?
The accountable person itself — with appropriate periodicity, before new products and upon material changes.
How We Help on Legal.ge
The lawyers of Legal.ge help you build the monitoring system: we plan the periodicity of preventive measures, prepare risk reassessment, and assist in responding to information requests from the supervisory authority. Contact us — monitoring is one of the few processes that cannot be assembled retroactively on the day of an inspection.
