The Legal Foundation of Records Management in Georgia
Records management is a business term, but the most concrete, directly applicable set of rules in Georgian law is established by the law on the prevention of money laundering and the financing of terrorism. That law defines what an accountable person must retain, in what form, for how long, and under what confidentiality constraints. The three angles — the retention duty, the form, and confidentiality — are examined separately below.
Records management here is not a matter of choice or good will: five-year retention of documentation and the ability to produce it immediately are direct legal requirements, and their breach attracts sanctions.
What Is Retained and for How Long: the Five-Year Terms
Under Article 27, the accountable person must retain information obtained in accordance with the law’s requirements and the results of analyses carried out, together with documentation connected with the client’s account and business correspondence, for 5 years from the termination of the business relationship or the conclusion of a one-off transaction. The clock starts when the relationship with the client ends, not when the document is created.
Under the same article, information connected with a transaction that allows full retrieval of information about the transaction is retained for 5 years from its preparation, conclusion or execution. In addition, reports and other information submitted to the Service, as well as written instructions and written protocols, are retained for the same 5-year term. One and the same five-year standard thus covers both client records and the regulatory archive proper.
The term may be extended on the basis of a substantiated request of the Service or the supervisory authority, by not more than 5 years. The practical conclusion is clear: five years is a minimum, and a company’s internal rules must be able to account for that possibility.
Form and Quality: How the Information Must Be Kept
The law does not end its requirement with the deadline. Information is retained in a form that allows its immediate provision to a competent authority and, in criminal prosecution, its use as evidence as well. This means the archive must be searchable and capable of being produced before a court — not merely existing.
The accountable person is obliged, taking into account the nature and volume of its activity, to create an appropriate electronic system for the recording and processing of data, which retains information for these purposes and serves the detection of linked, unusual and suspicious transactions. The form of submission is likewise precisely defined: information is submitted to the Service electronically or in writing, in the manner established by a subordinate normative act of the head of the Service.
Confidentiality: the Prohibitions Attached to Records
Article 28 prohibits the accountable person, its managers and employees from informing the client or any other person that measures are being or will be carried out to study an unusual transaction or detect a suspicious one, that a report has been or will be submitted to the Service, or that other measures defined by law are being carried out.
Exceptions are provided by law: presenting information to a competent body in the manner established by Georgian legislation is not a violation, nor is the dissemination of information among members of a single group where a group-level compliance control system has been introduced. The same article prohibits disclosing the identity of the employee who carries out the measures or submits the report, and the accountable person must protect that employee from threats, discriminatory treatment or other unlawful influence.
Why This Is Compliance-Critical
The quality of records management is a defensive instrument toward the supervisory authority: a properly organized archive lets a company respond immediately to a Service request, which encompasses any information the Service needs for its purposes, including confidential information. Likewise, documented analysis results about the study of unusual transactions are the evidence that the company took reasonable measures. The design of the records system is therefore an integral part of the compliance program, not a technical detail.
Frequently Asked Questions
Below we answer the most frequent questions about records management.
For how long must documentation be retained?
For 5 years — from the termination of the business relationship or the conclusion of a one-off transaction; transaction information runs from its preparation, conclusion or execution; submitted reports and written protocols carry the same term.
Can the retention period be extended?
Yes. On the basis of a substantiated request of the Service or the supervisory authority, the term may be extended by not more than 5 years.
Is electronic retention acceptable?
Yes. The law directly requires the creation of an appropriate electronic system for recording and processing data, which also serves the detection of linked, unusual and suspicious transactions.
May the client be notified about a report?
No. Article 28 prohibits this; the exceptions are only the cases provided by law, including dissemination among members of one group under a group-level system.
Who may request information from the archive?
The Service requests information aligned with its functions, including confidential information; the form of submission is defined by a subordinate act of the head of the Service.
How We Help on Legal.ge
The lawyers of Legal.ge help you design a records management system: we define what your company’s archive must capture, structure the procedure for five-year retention and immediate production, and reflect it in the internal instruction. Get in touch — a properly organized archive is the cheapest insurance in dealings with the regulator.
