Crypto business security: which rules are binding
There is no separate cybersecurity statute for the crypto business in Georgia — not for exchanges and not for wallet-service providers. The binding legal frame that imposes security and control requirements on such a business flows from its status as an accountable person: by listing the virtual asset service provider among financial institutions, the Law of Georgia on the Prevention of Money Laundering and Terrorism Financing obliges it to implement a compliance control system and to ensure that transfers are accompanied by the required accompanying information. On this page we explain what this means in practice and what consequences a breach carries.
Accountable-person status and its circle
The law defines three groups of accountable persons: financial institutions, persons engaged in non-financial activity and public institutions. The virtual asset service provider is listed directly among financial institutions — alongside commercial banks, microfinance organizations, payment service providers and others. The crypto business thus receives its security standards not from a stand-alone act but from the common regime extended to the whole financial sector. Moreover, the law's requirements extend to other persons conditionally: an advocate or a notary, for example, becomes an accountable person where he or she serves a client in matters that include the management of money, securities or convertible virtual assets, management of a bank account, creation of a legal person or the purchase and sale of shares. Certain forms of professional activity — including the giving of legal advice and representation before a court — fall outside these requirements.
Convertible virtual asset transfers and accompanying information
The law separately defines the operation of a transfer of a convertible virtual asset: an operation performed by digital means, by or on the instruction or with the consent of the initiator, to make a convertible virtual asset available to a recipient; the initiator and the recipient may be one and the same person. Two direct requirements attach to these operations. First, the virtual asset service provider must ensure that a transfer or receipt of a convertible virtual asset is accompanied by accompanying information determined under the procedure established by the supervisory organ. Second, the provider of the recipient of a convertible virtual asset must examine whether a ground exists for submitting a report where the transfer does not fully contain the identification data of the initiator or the recipient in accordance with the established procedure. Technically this means that the transfer system must be built from the start so that accompanying data are recorded and retained — retrofitting this onto a running platform is far more expensive.
The compliance control system: the real security frame
The law obliges the accountable person to implement internal control policies, rules, systems and mechanisms that are proportionate to the character and volume of its activity and to the associated money laundering and terrorism financing risks. For the implementation an internal instruction is elaborated, approved by the governing body or a person with managerial authority. The instruction defines, among other matters, the rights and duties of the person or unit responsible for the functioning of the compliance control system; the rules for selecting employees of high qualification and reputation for employment; a continuing training programme; and an independent audit function to check the effectiveness of the system. The accountable person must supply the responsible persons with information effectively and in due time and grant them the right to take independent decisions. The position of the head of compliance must correspond to a senior management level, and a member of the governing body or a person with managerial authority is responsible for the system's effectiveness. These documents and roles — not a generic security certificate — are the crypto business security standard in Georgian law.
Liability and the real boundary
The law attaches a sanction for non-fulfilment of the requirements it establishes: failure by a person to comply results in a warning, and a repeated commission of the same act in a fine of 1 000 lari. Under this norm an accountable person within the article's list is not implied — a separate, special liability regime applies to it, placed in a separate chapter and outside the subject of this page. The real damage often lies not in the fine but in the restriction of activity and reputation: for a provider under supervision, a defect in the control system is directly reflected in client trust and partner relationships.
How we can help
We help the crypto business understand the mandatory regime: we determine whether your model falls within the definition of an accountable person, draft the internal instruction and the description of the compliance control system, and plan the legal requirements for embedding accompanying information into the platform. Contact us — we will assess your situation under the current legislation.
In practice the compliance control system in a crypto business consists of three layers: a documentary layer, meaning the approved instruction and policies; an organisational layer, meaning the responsible person or unit, its right to take independent decisions and its accountability to the top level; and a technical layer, meaning transfer monitoring, the recording of accompanying information and data retention. The proportionality requirement of the law means that the systems of a small provider and of a large platform will differ, yet all three layers are equally necessary for both: a defect in any one of them invalidates the whole system. In our experience it is usually the technical layer that remains neglected, with the instruction written but the platform unable to retain the accompanying data.
