About this service
The risk-based approach is the central idea of the law on the prevention of money laundering and terrorism financing: not every client and every transaction is equally dangerous, and measures must correspond to the risk. Legal risk assessment is precisely the application of that logic: identifying, classifying and planning measures around the risks of an accountable person's processes, clients and products — according to the methodology established by law. This service helps conduct and document that assessment so the result is substantiated for the supervisory organ and usable for the business.
The risk-assessment methodology
Article 8 lays the foundation: taking into account the nature and volume of its activity, the accountable person must implement an effective system of risk assessment and management and assess risks on the basis of the client and beneficial owner, their activity and jurisdiction, the product, service or means of its delivery, and the transaction. Before introducing a new technology or product the risks are assessed in advance, and the client's risk level is determined before an occasional transaction and before establishing a relationship. The national risk assessment and the guidance of the Service and the supervisory organ must be taken into account. It is here that the work of legal risk assessment is born: from a general requirement to a concrete, substantiated, periodically updated document.
Low risk and the simplified approach
Article 9 addresses low-risk services: by normative act of the head of the Service, in strictly limited cases, the accountable person may be released from individual requirements when providing a service containing low risks — the exception must be properly substantiated and extend to a specific group or activity. The law gives a concrete example: a payment service by an electronic-money instrument may fall under a simplified regime where the instrument permits transfers only for payment of goods or services, the amount stored on it at any time does not exceed 500 lari, the monthly transfer limit is 500 lari and anonymous top-up is excluded; in that case the monetary threshold may even rise to 1 500 lari under established conditions. The example shows the logic well: simplification is earned by the product's architecture, not by wish.
Enhanced measures at heightened risk
Article 18 regulates the other end of the mechanism: with a heightened-risk client, in addition to the basic preventive measures, the accountable person must obtain additional information on the client's and beneficiary's assets and activity; increase the frequency of updating identification data; obtain additional information on the purposes and grounds of transactions; obtain the management's permission to establish or continue the relationship; take reasonable measures to establish the origin of assets, funds and convertible virtual assets; and conduct enhanced monitoring. A rise in risk thus demands a deepening of procedure — and this requirement must itself be written into the document.
High-risk jurisdictions
Article 19 adds the geographic dimension: a high-risk jurisdiction is a country or territory whose prevention system has serious deficiencies, and the list of such jurisdictions is approved by the National Bank upon the Service's submission. A client's connection — registration or transaction intermediary — with such a jurisdiction triggers enhanced measures. Exceptions exist — for example, for a Georgian citizen or a foreigner with a residence permit — which again confirms the risk-based logic: the decider is risk, not citizenship.
Unusual transactions
Article 20 establishes the instrument of daily practice: an unusual transaction is a complex, unusually large transaction or an unusual combination of transactions with no apparent economic or lawful purpose. Such a transaction is studied — its purpose and grounds are established, and where necessary enhanced monitoring is engaged to detect a suspicious transaction. On the supervisory organ's demand the accountable person must substantiate that it studied the unusual transaction and took reasonable measures. In the legal risk-assessment document it is precisely these criteria that must be translated onto your specific products and client base.
How we can help
Our specialists will conduct a full risk assessment of your organisation: risk-profiling of client categories, products and transaction channels; identifying low-risk segments where the law permits simplification; the criteria of heightened risk and the algorithm of enhanced measures; and the rules of practice connected with high-risk jurisdictions. The result is a substantiated, periodically updated document that works equally for supervision and for the business. Contact us — and let us begin with your risk map.
A final note from practice: a risk-assessment document is alive only when it follows the changes of the business. Launching a new product, attracting a new segment or adding a partner channel — each of these events is an occasion to update the assessment. Our team performs these updates on a schedule, so that your document always reflects present reality — not the reality of the year when it was once written. Let us also note the document's value in contested situations: when the supervisory organ begins asking about the measures chosen for a specific client, the first piece of evidence is precisely the methodology — why the segment was assigned its risk, which criteria were applied and how they are recorded. An organisation with a built methodology answers in minutes; one without it reconstructs the logic afterwards, and such reconstruction rarely looks convincing.
