Legal.geLegal.ge
AboutSpecialistsLibraryPricingBlogContact
LegalTools
...
Loading account
AboutSpecialistsLibraryPricingBlogContact
LegalTools
Loading account
Legal.ge

Georgia’s legal marketplace.

Quick Links

  • About Us
  • Specialists
  • Open tasks
  • Services
  • Laws & Codes
  • Firms
  • Organisations
  • Events
  • Blog
  • Contact

Legal

  • Legal library
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Contact

contact@legal.geNeed a lawyer? Find a specialist

Tbilisi, Georgia

Specialist Directory

Criminal Law AttorneyCriminal Law LawyerCivil Law AttorneyCivil Law LawyerCorporate & Commercial Law AttorneyCorporate & Commercial Law LawyerLabor & Employment Law AttorneyLabor & Employment Law LawyerTax Law AttorneyTax Law LawyerDispute Resolution & Litigation AttorneyDispute Resolution & Litigation Lawyer

© 2026 Legal.ge. All rights reserved.

Made with in Georgia

  1. Services
  2. Technology & Digital Law
  3. Blockchain & Cryptocurrency Law
  4. AML/KYC
  5. Anti-Money Laundering Compliance

Loading...

AML/KYC

Anti-Money Laundering Compliance

What does the law require of a compliance-control system?

An internal-control policy, rules, systems and mechanisms proportionate to the nature, volume and risks of the activity. The system is fixed by an internal instruction approved by the governing body or a person with managerial authority.

For how long is information kept?

The basic rule is 5 years: from the end of the business relationship or an occasional transaction, and transaction-related information from its preparation, conclusion or performance. A substantiated request can extend the period by up to a further 5 years.

When is a suspicious-transaction report filed?

A report on a suspicious transaction or an attempt to prepare, conclude or perform one is submitted to the Financial Monitoring Service; further categories may be set by normative act. Detection is the duty of your internal system.

Who is responsible for the system?

A designated person or unit whose position corresponds to the top hierarchical level, while effectiveness of the system is the responsibility of a member of the governing body or a person with managerial authority.

4 min·...

About this service

The law on the prevention of money laundering and terrorism financing does not impose on accountable persons a separate formality but an entire institution: the compliance-control system, which begins with risk assessment, is fixed by an internal instruction and continues with reports on suspicious transactions. This service helps accountable persons build and audit precisely that system — so that from the first day the requirements work in practice, not on paper.

The compliance-control system and the internal instruction

Under Article 29 of the law, the accountable person must implement an internal-control policy, rules, systems and mechanisms proportionate to the nature and volume of its activity and the related risks. For implementation, an internal instruction is drawn up, approved by the governing body or a person with managerial authority. The instruction defines, among other things: the rights and duties of the head of the responsible person or unit and its staff; staff selection rules; a continuing-training programme; and an independent audit function to verify the system's effectiveness. The responsible person's position must correspond to the top hierarchical level, and responsibility for the system's effectiveness must lie with a member of the governing body or a person with managerial authority — compliance is thus not a second-rate administrative chore; it stands at the level of management.

Risk assessment and management

Article 8 establishes the intellectual core of the system: taking into account the nature and volume of its activity, the accountable person must implement an effective system of risk assessment and management and, with appropriate periodicity, assess and record the risks connected with its activity — based on the client and beneficial owner, their activity and jurisdiction, the product and the means of delivery. Before introducing a new technology, product or service, the risks are assessed in advance. The client's risk level is determined before an occasional transaction and before establishing a relationship, then periodically and on material change. In the assessment, account must be taken of the national risk assessment and the guidance of the Service and the supervisory organ — and on the supervisory organ's demand the accountable person must substantiate that the risks were properly assessed.

Reporting suspicious transactions

Article 25 imposes the reporting duty: the accountable person must submit to the Financial Monitoring Service reports on suspicious transactions or attempts to prepare, conclude or perform them. The Service's chief may by normative act define further categories of transactions subject to reporting. In practice this means the compliance system must be built so that a suspicious transaction is identified through analysis of the circumstances and converted into a report — not awaited until the Service itself calls.

Record keeping

Article 27 regulates retention: the accountable person must keep the obtained information and the results of analysis, the client's account documentation and correspondence for 5 years from the end of the business relationship or the conclusion of an occasional transaction. Transaction-related information is kept for 5 years from preparation, conclusion or performance; submitted reports are likewise kept for 5 years. On a substantiated request the period may be extended by no more than a further 5 years. Information must be kept in a form enabling its immediate production, and for this purpose the accountable person creates an electronic system of data collection and processing — precisely the technical foundation without which the deadlines cannot be met.

Group-level control

Article 30 adds a burden for head enterprises: they must implement a group-level compliance-control system defining rules for the dissemination of information among group members, the supply to the responsible unit of information on clients and transactions, and mechanisms protecting the confidentiality of information. A subsidiary registered in another jurisdiction applies the Georgian requirements where local law is less strict — and where the jurisdiction restricts that performance, additional measures are taken and the supervisory organ is informed in due time.

How we can help

Our specialists build or re-verify your compliance-control system on exactly these elements: the internal instruction, the designation of the responsible person, the risk-assessment document, the reporting procedure, retention periods and the requirements for an electronic system. Where a system already exists we conduct an independent audit — both for presentation to the supervisory organ and for discovering your own gaps. Contact us for a concrete plan tailored to your organisation's size and risk profile.

Experience shows that a system works well when it is embedded in the organisation's real processes rather than existing as a separate document. Our approach therefore always begins with two questions: how does your business process actually run, and where are its weak points. From the answers come the instruction, the risk map and the monitoring rule that this particular organisation will genuinely use — and in communication with the supervisory organ it is exactly this difference that shows.

Such a system also saves time: when processes and responsibilities are written down in advance, preparing for an inspection takes hours instead of days, and staff act as the law requires — not because someone demands it, but because it is a natural part of their work.

Updated: ...

Verified against current law: 05/07/2026

Legal basis:

  • ფულის გათეთრებისა და ტერორიზმის დაფინანსების აღკვეთის ხელშეწყობის შესახებ

Find a Specialist

Professionals working in this field

Technology & Digital Law LawyerTechnology & Digital Law AttorneyTechnology & Digital Law Personal data protection officer