2026-04-24 | 96/04Added
The National Bank of Georgia approves the Procedure for Participation in the Payment System, establishing mandatory requirements for licensed commercial banks, microbanks, registered significant payment service providers, and license applicants to join the National Bank’s monetary funds payment system via direct technical integration. Participants must satisfy strict criteria regarding cybersecurity, operational risk management, anti-money laundering compliance, and business continuity, including annual independent audits, penetration testing, and vulnerability scanning. The National Bank reviews applications within 60 calendar days, with the authority to reject applications containing critical risks, suspend or terminate participation for non-compliance, and impose supervisory measures or fines for violations.
Get NBG alerts — same-day email on every new publication.
Order No. 96/04 of the President of the National Bank of Georgia 24 April 2026 Tbilisi
On Approval of the Procedure for Participation in the Payment System of the National Bank of Georgia
On the basis of sub-paragraph "z" of paragraph 1 of Article 15 and paragraph 1 of Article 63 of the Organic Law of Georgia "On the National Bank of Georgia", I order:
Article 1
The Procedure for Participation in the Payment System of the National Bank of Georgia, attached hereto, is approved.
Article 2
This Order shall enter into force from the moment of its publication.
President of the National Bank of Georgia
Natela Turnava
Procedure for Participation in the Payment System of the National Bank of Georgia
Article 1. General Provisions
Article 2. Criteria for Participation in the Payment System
http://www.matsne.gov.ge 22001000018011016987
a) To ensure cybersecurity:
a.a) Have formalized processes and effective control mechanisms, and employ qualified staff. Formalized processes ensuring cybersecurity must serve to protect information during storage (data-at-rest), transmission (data-in-transit), processing (data-in-use), and destruction; a.b) Have implemented cybersecurity risk management policies and procedures, which must be approved by management; a.c) Have a recent registry of cybersecurity risks with indications of effective control mechanisms, which must be approved by management; a.d) Conduct cybersecurity awareness training and simulations for employees at least once a year; a.e) Ensure effective control mechanisms for network and system security, which include the management of security configurations and the existence of intrusion detection and prevention mechanisms; a.f) Ensure effective control mechanisms for the confidentiality, integrity, and availability of information in its possession, including information reflecting users' personal data and financial transactions, including data encryption; a.g) Ensure effective management of the system development lifecycle; a.h) Ensure effective access control mechanisms in accordance with strong authentication, roles, and responsibilities; a.i) Maintain accounting records (so-called "logs") reflecting access to systems and information, and monitor them; a.j) Conduct penetration testing on all systems connected to the network. Penetration testing must be conducted by highly qualified and experienced specialists; a.k) Conduct network vulnerability scanning at least twice a year; a.l) Have implemented plans for responding to system disruptions and cyberattacks; a.m) Have implemented a cybersecurity incident management policy and procedure, which must also include the immediate sharing of information with the National Bank; b) Have policies and procedures for operational risk management approved and implemented by management, which must at least include:
b.a) The responsibilities and authorities of the structural unit/person responsible for operational risk management; b.b) Tools for the identification, recording, analysis, escalation, assessment, and mitigation of operational risks; b.c) Preventive and detective procedures and mechanisms for control and monitoring, which in turn include tools for the detection and minimization of fraudulent operations in payment systems; b.d) A policy and procedure for fraud risk management; b.e) The definition, monitoring, and response measures for risk maps and key risk indicators, which in turn include integration processes with payment systems; b.f) Business continuity management, including the recovery component from disasters. The Subject must have a developed and formalized Business Continuity Plan (BCP), which also includes the management of the continuity of the Payment System's business processes and the recovery plan for the associated information technology infrastructure (DRP). The Business Continuity Plan must use scenario analysis approaches with risk-oriented critical scenarios, appropriate assessments, and recovery procedures. Scenarios must take into account critical internal/external factors, outsourcing processes, and service providers. Scenarios must be subject to qualitative and quantitative assessment (e.g., Business Impact Analysis – BIA). Scenarios must define the Recovery Time Objective (RTO) and Recovery Point Objective (RPO) for process recovery. The testing of the Business Continuity Plan must be conducted regularly, at least once a year. The results of the testing must be recorded and formalized. The Subject must review and periodically update the Business Continuity Plan; b.g) Precision risk management, which includes ensuring the accuracy of data and reporting related to the process; b.h) Recording of manually performed processes within the Payment System and assessing their impact on operational risk; b.i) A procedure for reporting significant operational risks; b.j) Policies and procedures for the assessment and approval of new products, activities, processes, and systems; b.k) The assessment, management, and monitoring of risks associated with significant and/or critical outsourcing processes of the Payment System; b.l) Policies and procedures for the adequacy and security of information systems and technologies, which also include the independent assessment of information systems and technologies associated with payment systems on a regular basis, as well as upon significant changes, using a risk-based approach; b.m) A plan for periodic measures to raise awareness and qualification regarding operational risks; b.n) Issues regarding the regular review and update of operational risk policies and procedures; c) Have implemented policies and procedures developed to facilitate the prevention of money laundering and terrorist financing, as well as the compliance with sanctions regimes. Furthermore, participation in the Payment
System does not exempt Subjects participating in the Payment System from the obligations to comply with the legislation on the prevention of money laundering and terrorist financing and the requirements established by sanctions regimes regarding each other; d) If the Subject plans to or conducts cross-border transfers, it must have a registered and connected (connected) BIC code in the SWIFT system, otherwise, a non-connected (non-connected) BIC code is permitted.
http://www.matsne.gov.ge 22001000018011016987
Article 3. Decision on the Subject's Compliance with Established Requirements
Article 4. Participation in the Payment System and Obligations of the Subject
Article 5. Supervisory Measures and/or Sanctions
In the event of violation of the requirements provided for in this Procedure, the National Bank is authorized to use supervisory measures and/or sanctions (including monetary fines) defined by the legislation of Georgia.
http://www.matsne.gov.ge 22001000018011016987
Read the rest free
Source: National Bank of Georgia — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from NBG
We email you every new NBG publication the day it's published.