Legal.geLegal.ge
SpecialistsLibraryPricing
More
AboutBlogContact
LegalTools
...
Loading account
AboutSpecialistsLibraryPricingBlogContact
LegalTools
Loading account
Legal.ge

Georgia’s legal marketplace.

Download on the App StoreLegal.ge for iPhone

Quick Links

  • About Us
  • Specialists
  • Open tasks
  • Services
  • Laws & Codes
  • Firms
  • Organisations
  • Events
  • Blog
  • Contact

Legal

  • Legal library
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Contact

contact@legal.geNeed a lawyer? Find a specialist

Tbilisi, Georgia

© 2026 Legal.ge. All rights reserved.

Made with in Georgia

  1. Services
  2. Crypto & Blockchain Services
  3. Crypto Regulation & Legal Advisory
  4. AML, KYC & Compliance
  5. Outsourced AML Officer for VASPs — Compliance Retainer

Services

0 services available

Loading...

AML, KYC & Compliance

Outsourced AML Officer for VASPs — Compliance Retainer

Why does a virtual asset service provider need a compliance function?

Because Article 3 of the law on the suppression of money laundering and terrorism financing names the virtual asset service provider among accountable persons, and Article 29 requires every accountable person to implement a compliance control system and designate a responsible person.

Which thresholds apply to one-off transactions?

The general threshold is 15,000 GEL or its equivalent in foreign currency, but for one-off transactions associated with convertible virtual asset services Article 11 sets a lower threshold: 1,000 US dollars, 1,000 euros or 3,000 GEL. For transfers of funds the threshold is 3,000 GEL.

Can providers identify clients electronically?

Yes. Article 12 permits identification without face-to-face contact, electronically — under the procedure established by the supervisory authority and agreed operational procedures ensuring effective risk management. Anonymous and fictitiously named accounts are prohibited.

What does outsourcing cover day to day?

Risk-based client assessment, threshold control, periodic review, detection of and reaction to suspicious transactions regardless of thresholds, updates to the internal instruction, and communication with the supervisory authority — all through the mechanism defined by Article 29.

7 min·23 Sep 2026

What an Outsourced Compliance Function Is and Who Needs One

The Law of Georgia on Facilitating the Suppression of Money Laundering and the Financing of Terrorism imposes on accountable persons the obligations to apply preventive measures and to implement a compliance control system. Inside those obligations sits concrete, day-to-day work: identifying and verifying customers, assessing risks, maintaining the internal instruction, training employees and preparing for independent audit. Precisely this work can be handed to an experienced specialist under a retainer (outsourcing) format — a recurring service in which the compliance function is performed not by an in-house employee but by a provider acting in the name of the accountable person and under its internal instruction.

This format is particularly relevant for virtual asset service providers. Article 3 of the law lists, within the group of financial institutions, the virtual asset service provider by name. The same article brings currency exchange bureaus, microfinance organisations, payment service providers and others into the circle of accountable persons, yet the virtual asset sphere stands apart because the law sets a distinctly lower identification threshold for one-off transactions associated with it — more on this below.

Grounds for Preventive Measures and Monetary Thresholds — Article 11

Article 11 determines when an accountable person must apply preventive measures. The grounds are: establishing a business relationship; concluding a one-off transaction where the amount of the transaction or the aggregate amount of related transactions exceeds 15,000 GEL or its equivalent in foreign currency; a one-off transfer of funds where the amount or aggregate amount exceeds 3,000 GEL or its equivalent; and doubting the accuracy or compliance of identification data. The general 15,000-lar threshold is not the only one: where a one-off transaction is associated with the provision of services in convertible virtual assets, the identification obligation arises at a threshold of 1,000 US dollars, 1,000 euros or 3,000 GEL.

For the virtual asset sphere this norm is foundational: most market operations fall exactly within this range, so practically every meaningful client becomes subject to identification. Moreover, the fourth paragraph of the article provides that where money laundering or terrorism financing is suspected, preventive measures are applied regardless of the monetary threshold or any other reservation — thresholds are only the first filter, and they cease to operate once suspicion arises. Detecting suspicious circumstances is precisely the step where an experienced compliance specialist's daily monitoring changes the quality of decisions.

How the Measures Are Carried Out — Article 12

Article 12 requires that preventive measures be applied according to the client's risk level — before concluding a one-off transaction and before establishing a business relationship, and also periodically while the relationship continues and when material circumstances related to the client change. Compliance is thus not a one-off procedure but a recurring cycle that is revisited as the client's risk profile evolves.

The same article permits defined flexibility: where lower money laundering and terrorism financing risks exist, verification of the client and/or beneficial owner may be completed after the business relationship is established, if this is necessary to avoid interrupting customer service — but the measures must be completed as soon as possible within reasonable limits. Opening or maintaining anonymous or fictitiously named accounts is prohibited. An accountable person may apply preventive measures electronically, without face-to-face contact with the client — according to the procedure established by the supervisory authority and with operationally and technically agreed procedures that ensure effective management of risks. The list of identification data and the rules for electronic identification are likewise determined by acts of the supervisory authority, so processes must be built within exactly those frameworks.

The Compliance Control System and the Responsible Person — Article 29

Article 29 requires the accountable person to implement internal control policies, rules, systems and mechanisms that are proportional to the nature and volume of its activity and the associated risks. To implement the system, an internal instruction is developed, approved by the governing body or a person holding leadership authority. Among other matters, the instruction defines the rights and duties of the responsible person or head of the structural unit and of the employees for the functioning of the system; the rules for selecting employees — hiring persons of high qualification and reputation; a continuing training programme for employees; and an independent audit function to verify the effectiveness of the system.

The hierarchical requirements also live here: the position of the responsible person or head of the structural unit must correspond to the top hierarchical (management) level; the accountable person must designate a member of its governing body or a person with leadership authority who will be responsible for the effectiveness of the system; and the responsible person must have an effective opportunity to timely obtain the information needed for their functions and to decide independently on the submission of reports. It is from these last elements that the legal architecture of outsourcing is born: the internal instruction must embed a mechanism that gives the external specialist access to information and independence of decision, while final responsibility remains with the management.

What the Outsourcing Package on Legal.ge Includes

Our service is a recurring compliance retainer built on the norms described above and developing in stages:

  • risk assessment according to the nature and volume of the activity and the client base — as the foundation of the system's proportionality;
  • drafting the internal instruction and preparing it for approval by the governing body, with blocks on the responsible person's rights and duties, selection, training and audit;
  • building client identification and verification processes, including control of one-off transaction thresholds and the specific thresholds of the virtual asset sphere;
  • ongoing monitoring: periodic review, reaction to changes in risk profiles, and application of measures upon suspicion regardless of thresholds;
  • communication with the supervisory authority and work on matters requiring agreement with it.

We understand that every provider's profile differs: one focuses on exchange services, another on storage and transfers. That is why the package always begins with an audit: we assess the existing processes, record the gaps and build a plan that makes the compliance control system proportional to your business.

Frequently Asked Questions

Can the compliance function be fully transferred to an external specialist?

Performing the function — yes; transferring final responsibility — no. Article 29 requires the accountable person itself to implement the compliance control system, its governing body approves the internal instruction, and it is a member of the governing body or a person with leadership authority who answers for the system's effectiveness. The essence of outsourcing is a mechanism under which the external specialist runs the daily procedures, while decisions and responsibility legally remain with the accountable person.

Which amounts trigger identification in the virtual asset sphere?

Under sub-paragraph "b" of the first paragraph of Article 11, for a one-off transaction associated with convertible virtual asset services the threshold is 1,000 US dollars, 1,000 euros or 3,000 GEL — instead of the general 15,000-lar threshold. For one-off transfers of funds the threshold is 3,000 GEL, and upon suspicion preventive measures apply regardless of the monetary threshold.

What must the internal instruction contain?

Under the second paragraph of Article 29 — among other matters — the rights and duties of the responsible person or head of the structural unit and of employees, employee selection rules for hiring highly qualified and reputable persons, a continuing training programme, and an independent audit function to check the system's effectiveness.

Why is periodic review of clients necessary?

Because Article 12 requires preventive measures according to the client's risk level — before the transaction and before establishing the relationship, and also periodically during the relationship and upon changes in material circumstances. A one-off check does not satisfy this requirement: the system is a living process.

How We Help on Legal.ge

On Legal.ge we build and run compliance control systems for virtual asset service providers: we draft internal instructions, design identification and monitoring processes, and — in a recurring retainer format — deliver the performance of the responsible person's function. Contact us to discuss your profile and receive a concrete compliance plan.

Updated: 24 Sep 2026