AML and KYC for a Georgian Company: What You Are Actually Required to Do
Which businesses fall under Georgia's anti-money-laundering law, what customer due diligence really requires, the UBO rules, the reporting duties to the Financial Monitoring Service, record retention, the sanctions dimension, and what supervisors look for in an inspection.
Georgia's anti-money-laundering framework sits in the Law of Georgia on Facilitating the Prevention of Money Laundering and the Financing of Terrorism, with the Financial Monitoring Service of Georgia as the financial intelligence unit and sector supervisors - the National Bank among them - overseeing the entities in their remit. If your company is an accountable entity under that law, compliance is not optional and not delegable.
The law defines accountable entities and requires them to apply a risk-based approach: identify and verify customers and beneficial owners, monitor the business relationship, keep records, and report suspicious activity to the Financial Monitoring Service of Georgia, under the supervision of the relevant sector supervisor.
Who is an accountable entity
The law lists the categories. Broadly they include:
- Banks, microfinance organisations, currency exchange points and lenders.
- Payment service providers and electronic money issuers.
- Virtual asset service providers.
- Insurance companies and brokers, and securities market participants.
- Casinos and organisers of games of chance.
- Notaries, and lawyers and accountants when carrying out defined transactions for clients.
- Company service providers - including those forming and administering companies, which is why a formation agent asks the questions it asks.
- Dealers in high-value goods, including real estate and precious metals, above defined thresholds.
If you are not an accountable entity, you still meet AML constantly - as a customer. Every bank, payment provider and formation agent that onboards your company is discharging its own obligations through you. Understanding the framework makes you a far easier client to onboard.
The risk-based approach, which comes first
Every duty below sits on top of one foundational obligation: the accountable entity must assess its own money-laundering and terrorism-financing risk and calibrate its controls to what it finds. The law does not ask for identical treatment of every customer; it asks for proportionate treatment, with more scrutiny where risk is higher and less where it is genuinely lower. That is why a credible programme starts with a documented, business-specific risk assessment covering customers, products, geographies and delivery channels - and why a template with the name changed is the first thing an inspection exposes.
Customer due diligence in practice
- Identify the customer and verify identity from reliable, independent sources.
- Identify the beneficial owner and take reasonable measures to verify that identity - looking through the chain, not stopping at the first company.
- Understand the purpose and intended nature of the business relationship.
- Conduct ongoing monitoring, keeping the information current and checking that transactions are consistent with what you know.
- Apply enhanced due diligence where risk is higher: politically exposed persons, higher-risk jurisdictions, complex or unusual structures, and non-face-to-face onboarding.
- Apply simplified measures only where the law permits and the risk assessment supports it.
Beneficial ownership
The beneficial owner is the natural person who ultimately owns or controls the customer. The working threshold is generally ownership or control of 25% or more of shares or voting rights, or control by other means. Where no such person can be identified, the senior managing official is treated as the beneficial owner - and that outcome should be documented, not used as a shortcut to avoid looking.
25%
Working UBO threshold
Shares or voting rights, or control by other means
5 years
Minimum retention
After the relationship or transaction ends
Natural persons
Where the chain must end
Every branch, not the first company
- Keep an ownership chart that reaches natural persons in every branch.
- Hold identity documents and proof of address for each beneficial owner.
- Record the basis of control - shareholding, voting agreement, or other means.
- Update within a short period of any change, and record when the information was last verified.
Politically exposed persons and enhanced due diligence
A politically exposed person - someone entrusted with a prominent public function, and often their family members and close associates - is not prohibited as a customer, but the relationship carries higher risk and therefore heavier controls. In practice enhanced due diligence means senior management approval before onboarding or continuing the relationship, reasonable measures to establish the source of wealth and source of funds, and closer, more frequent ongoing monitoring. The same enhanced posture applies to higher-risk jurisdictions, complex or opaque structures, and onboarding conducted without meeting the customer face to face.
Sanctions screening
Sanctions compliance runs alongside AML rather than inside it, and supervisors expect it to be operational. That means screening customers and, where relevant, beneficial owners and counterparties against the sanctions lists the business is exposed to, at onboarding and on an ongoing basis, with a documented procedure for handling matches and clearing false positives. A true match is not a monitoring alert to be worked through at leisure; it drives immediate decisions about whether the relationship or transaction can proceed at all.
Reporting duties
- Suspicious transaction reports to the Financial Monitoring Service, filed without tipping off the customer.
- Threshold-based reporting of defined transaction types, where the law requires it.
- Internal escalation to the appointed responsible officer, with the decision - reported or not - recorded either way.
Tipping off is its own offence. Once a suspicion is being considered or reported, the customer must not be told, directly or indirectly, that a report has been or may be made. Train staff so a well-meaning explanation to a customer does not become a breach.
| Grade | Typical profile | Due diligence | Review cycle |
|---|---|---|---|
| Low | Local customer, transparent ownership, simple activity | Standard | Every 3 years |
| Medium | Foreign owner, ordinary trading activity | Standard plus source-of-funds evidence | Annually |
| High | PEP, high-risk jurisdiction, cash-intensive or regulated activity | Enhanced, senior approval | Every 6 to 12 months |
| Unacceptable | Owner will not explain the business, sanctions exposure | Decline, and consider reporting | Not onboarded |
The responsible officer and internal controls
An accountable entity is expected to appoint a responsible officer for AML - a named, sufficiently senior person with the authority and independence to run the programme, receive internal escalations, decide on reporting, and act as the point of contact with the Financial Monitoring Service. Around that role sit the controls that make a programme real: written procedures kept current, staff training that is delivered and recorded, and independent testing that actually probes the files rather than blessing them. A responsible officer who cannot explain the system without reading from it is a finding waiting to happen.
The accountable entity that did not know it was one
A Georgian company brokers the sale of two commercial properties in a year, as a sideline to its main consulting work. Nobody in the company has heard of the AML law.
- 1Real-estate intermediation is among the activities that can make a business an accountable entity - the duty follows the activity, not the company's self-description.
- 2As an accountable entity it owes registration with the supervisor, customer due diligence on the parties, and reporting duties it has never performed.
- 3The gap surfaces when a counterparty's bank asks for the company's AML registration in the course of settling the second sale.
- 4The remediation - registration, a proportionate written programme, retro-documented due diligence where possible, and legal advice on the exposure for the period of non-compliance - costs multiples of what compliance from the start would have.
The company thought of itself as a consultancy that occasionally helped with property. The law read the same facts as a real-estate intermediary with AML duties. When an activity changes, the compliance question has to be re-asked - that is the whole lesson.
Illustrative. Which activities make a business accountable, and what each must do, follow the current law and supervisor rules.
Records and retention
Customer files, transaction records and the reasoning behind decisions are generally retained for at least five years after the relationship ends or the transaction is executed. Retention is not just storage: the file has to be reconstructable, so a supervisor can see who was onboarded, on what evidence, and why the risk rating was set where it was.
What an inspection actually looks for
The policy that was bought and never applied
An accountable entity purchases a template AML manual, files it, and continues onboarding customers the way it always has.
- 1The manual describes a risk-based approach, customer risk ratings and enhanced measures for higher-risk relationships.
- 2The customer files contain identity documents and nothing else: no risk rating, no source-of-funds enquiry, no screening record.
- 3An inspection compares the documented programme against the files, and the gap between them is the finding.
- 4The entity is in a worse position than one with no manual at all: it has documented the standard it holds itself to, and then not met it.
A programme you do not operate is evidence against you rather than protection. Write the procedure you will actually follow, and keep the record that shows you followed it.
Illustrative. Inspection scope and findings depend on the entity, the sector and the supervisor.
- A risk assessment that is specific to the business, not a template with the name changed.
- Evidence that the procedures were followed on real files, sampled at random.
- A named, empowered responsible officer who can explain the system without reading from it.
- Monitoring that produces alerts, and alerts that produce decisions.
- Training records, and independent testing that found something.
The single most common failure is a beautiful policy document and a customer file with no evidence in it. Supervisors test the file, not the policy.
General information, not legal advice. Whether your business is an accountable entity, and exactly what it must do, should be confirmed against the current law and your sector supervisor's rules.