What an Outsourced Compliance Function Is and Who Needs One
The Law of Georgia on Facilitating the Suppression of Money Laundering and the Financing of Terrorism imposes on accountable persons the obligations to apply preventive measures and to implement a compliance control system. Inside those obligations sits concrete, day-to-day work: identifying and verifying customers, assessing risks, maintaining the internal instruction, training employees and preparing for independent audit. Precisely this work can be handed to an experienced specialist under a retainer (outsourcing) format — a recurring service in which the compliance function is performed not by an in-house employee but by a provider acting in the name of the accountable person and under its internal instruction.
This format is particularly relevant for virtual asset service providers. Article 3 of the law lists, within the group of financial institutions, the virtual asset service provider by name. The same article brings currency exchange bureaus, microfinance organisations, payment service providers and others into the circle of accountable persons, yet the virtual asset sphere stands apart because the law sets a distinctly lower identification threshold for one-off transactions associated with it — more on this below.
Grounds for Preventive Measures and Monetary Thresholds — Article 11
Article 11 determines when an accountable person must apply preventive measures. The grounds are: establishing a business relationship; concluding a one-off transaction where the amount of the transaction or the aggregate amount of related transactions exceeds 15,000 GEL or its equivalent in foreign currency; a one-off transfer of funds where the amount or aggregate amount exceeds 3,000 GEL or its equivalent; and doubting the accuracy or compliance of identification data. The general 15,000-lar threshold is not the only one: where a one-off transaction is associated with the provision of services in convertible virtual assets, the identification obligation arises at a threshold of 1,000 US dollars, 1,000 euros or 3,000 GEL.
For the virtual asset sphere this norm is foundational: most market operations fall exactly within this range, so practically every meaningful client becomes subject to identification. Moreover, the fourth paragraph of the article provides that where money laundering or terrorism financing is suspected, preventive measures are applied regardless of the monetary threshold or any other reservation — thresholds are only the first filter, and they cease to operate once suspicion arises. Detecting suspicious circumstances is precisely the step where an experienced compliance specialist's daily monitoring changes the quality of decisions.
How the Measures Are Carried Out — Article 12
Article 12 requires that preventive measures be applied according to the client's risk level — before concluding a one-off transaction and before establishing a business relationship, and also periodically while the relationship continues and when material circumstances related to the client change. Compliance is thus not a one-off procedure but a recurring cycle that is revisited as the client's risk profile evolves.
The same article permits defined flexibility: where lower money laundering and terrorism financing risks exist, verification of the client and/or beneficial owner may be completed after the business relationship is established, if this is necessary to avoid interrupting customer service — but the measures must be completed as soon as possible within reasonable limits. Opening or maintaining anonymous or fictitiously named accounts is prohibited. An accountable person may apply preventive measures electronically, without face-to-face contact with the client — according to the procedure established by the supervisory authority and with operationally and technically agreed procedures that ensure effective management of risks. The list of identification data and the rules for electronic identification are likewise determined by acts of the supervisory authority, so processes must be built within exactly those frameworks.
The Compliance Control System and the Responsible Person — Article 29
Article 29 requires the accountable person to implement internal control policies, rules, systems and mechanisms that are proportional to the nature and volume of its activity and the associated risks. To implement the system, an internal instruction is developed, approved by the governing body or a person holding leadership authority. Among other matters, the instruction defines the rights and duties of the responsible person or head of the structural unit and of the employees for the functioning of the system; the rules for selecting employees — hiring persons of high qualification and reputation; a continuing training programme for employees; and an independent audit function to verify the effectiveness of the system.
The hierarchical requirements also live here: the position of the responsible person or head of the structural unit must correspond to the top hierarchical (management) level; the accountable person must designate a member of its governing body or a person with leadership authority who will be responsible for the effectiveness of the system; and the responsible person must have an effective opportunity to timely obtain the information needed for their functions and to decide independently on the submission of reports. It is from these last elements that the legal architecture of outsourcing is born: the internal instruction must embed a mechanism that gives the external specialist access to information and independence of decision, while final responsibility remains with the management.
What the Outsourcing Package on Legal.ge Includes
Our service is a recurring compliance retainer built on the norms described above and developing in stages:
- risk assessment according to the nature and volume of the activity and the client base — as the foundation of the system's proportionality;
- drafting the internal instruction and preparing it for approval by the governing body, with blocks on the responsible person's rights and duties, selection, training and audit;
- building client identification and verification processes, including control of one-off transaction thresholds and the specific thresholds of the virtual asset sphere;
- ongoing monitoring: periodic review, reaction to changes in risk profiles, and application of measures upon suspicion regardless of thresholds;
- communication with the supervisory authority and work on matters requiring agreement with it.
We understand that every provider's profile differs: one focuses on exchange services, another on storage and transfers. That is why the package always begins with an audit: we assess the existing processes, record the gaps and build a plan that makes the compliance control system proportional to your business.
Frequently Asked Questions
Can the compliance function be fully transferred to an external specialist?
Performing the function — yes; transferring final responsibility — no. Article 29 requires the accountable person itself to implement the compliance control system, its governing body approves the internal instruction, and it is a member of the governing body or a person with leadership authority who answers for the system's effectiveness. The essence of outsourcing is a mechanism under which the external specialist runs the daily procedures, while decisions and responsibility legally remain with the accountable person.
Which amounts trigger identification in the virtual asset sphere?
Under sub-paragraph "b" of the first paragraph of Article 11, for a one-off transaction associated with convertible virtual asset services the threshold is 1,000 US dollars, 1,000 euros or 3,000 GEL — instead of the general 15,000-lar threshold. For one-off transfers of funds the threshold is 3,000 GEL, and upon suspicion preventive measures apply regardless of the monetary threshold.
What must the internal instruction contain?
Under the second paragraph of Article 29 — among other matters — the rights and duties of the responsible person or head of the structural unit and of employees, employee selection rules for hiring highly qualified and reputable persons, a continuing training programme, and an independent audit function to check the system's effectiveness.
Why is periodic review of clients necessary?
Because Article 12 requires preventive measures according to the client's risk level — before the transaction and before establishing the relationship, and also periodically during the relationship and upon changes in material circumstances. A one-off check does not satisfy this requirement: the system is a living process.
How We Help on Legal.ge
On Legal.ge we build and run compliance control systems for virtual asset service providers: we draft internal instructions, design identification and monitoring processes, and — in a recurring retainer format — deliver the performance of the responsible person's function. Contact us to discuss your profile and receive a concrete compliance plan.
