Compliance Programs Under Georgian Law: What Is Mandatory
The most detailed statutory model for developing a corporate compliance program in Georgian law is the Georgian law on the prevention of money laundering and the financing of terrorism. In this corpus, Article 29 regulates the internal instruction and the compliance control system itself, Article 8 reflects the risk-based approach, Article 30 governs the group level, and Article 24 governs proportionality. This page is about program design — operational oversight and inspections are the subject of a sibling page.
For a company this means the documentary foundation of a compliance program must begin with Georgian statute rather than with international manuals: a program written otherwise will not withstand substantiation before the supervisory authority.
The Internal Instruction: the Core of the Program and Its Mandatory Elements
Under Article 29, the accountable person must introduce internal control policies, rules, systems and mechanisms proportionate to the nature and volume of its activity and the associated risks. To introduce the system, an internal instruction is developed, approved by the governing body or by a person holding leadership authority.
The internal instruction must define: the rights and duties of the head of the responsible person or structural unit and of its staff; staff selection rules for hiring persons of high qualification and reputation; the continuing staff training program; and an independent audit function for checking the effectiveness of the system.
The system must be headed at the top hierarchical level, with an effective opportunity to obtain information in due time and the right to decide independently on submitting reports; responsibility for effectiveness rests with a specific member of the governing body or a person holding leadership authority.
The Risk-Based Approach: the Design Principle of the Program
Article 8 requires the accountable person, considering the nature and volume of its activity, to introduce an effective system for assessing and managing risks. Assessment and recording proceed with appropriate periodicity, and for a head enterprise also at group level. The assessment is based on the client and the beneficial owner, the essence of their activity and its jurisdiction, the product, service or delivery channel, the transaction and other risk factors.
Before introducing a new technology, product or service, or before any other material change in business practice, the associated risks must be assessed. The client’s risk level is determined before a one-off transaction or the establishment of a relationship, and then periodically and upon material changes in circumstances. Effective measures are carried out to manage and reduce the identified risks.
In its assessment, the accountable person takes into account the national risk assessment report and action plan, as well as the instructions and recommendations of the Service and the supervisory authority. On request, it must substantiate to the supervisory authority that it assessed the risks properly and carried out effective measures — a program is judged by its documented ability to work, not by paper.
A Single Program at Group Level
Under Article 30, a head enterprise registered in Georgia must introduce a group-level compliance control system. Beyond the requirement of Article 29, it defines the rules for disseminating information among group members for preventive measures and risk assessment, the conditions under which the group compliance unit receives information on clients, beneficial owners and transactions, and confidentiality safeguards.
The group’s foreign leg matters too: a subsidiary or branch registered in another jurisdiction must apply the Georgian law’s requirements where local legislation is less strict. If the jurisdiction restricts compliance, the accountable person must take additional measures, and where necessary the supervisory authority may require restricting or terminating the activity of such a subsidiary or branch.
Proportionality in the Other Direction: Simplified Measures
Proportionality cuts both ways. Under Article 24, the accountable person may apply simplified preventive measures to a client assigned a lower risk level: verification of the client or beneficial owner after establishing the relationship, reduced frequency of updating identification data, and reduced frequency and volume of transaction monitoring within reasonable limits.
Simplification carries two conditions: sufficient information must be obtained to establish that the client is genuinely of lower risk, and simplified measures are prohibited where features of increased money-laundering or terrorism-financing risk are present. A program must therefore embed both escalation and simplification mechanisms, grounded in the same risk-based approach.
Frequently Asked Questions
Below are the most frequent questions about developing a compliance program.
Who approves the compliance program?
The internal instruction, in which the program takes shape, is approved by the governing body of the accountable person or by a person holding leadership authority.
Can one program cover the whole group?
Yes. The head enterprise must introduce a group-level compliance control system, which also defines the rules for disseminating information among members.
Is an independent audit function required?
Yes. Article 29 lists it as a mandatory element of the internal instruction, and it checks the effectiveness of the system.
When may simplified measures be applied?
Only toward a client assigned a lower risk level, on the basis of sufficient information, and never where features of increased risk are present.
What if a foreign subsidiary’s jurisdiction restricts compliance?
The accountable person must take additional measures; where necessary, the supervisory authority may require restriction or termination of that subsidiary’s or branch’s activity.
How We Help on Legal.ge
The lawyers of Legal.ge help you develop a compliance program: we draft the internal instruction proportional to the nature, volume and risks of your activity and structure the risk-assessment system and group-level rules. Contact us — a correctly designed program also reduces the burden when monitoring begins.
