2026-08-11 | 87500Added
The government approved a revision to the Enforcement Decree of the Act on Reporting and Using Specified Financial Transaction Information, imposing stricter registration requirements and enhanced anti-money laundering duties on virtual asset service providers (VASPs). VASPs must maintain a debt ratio of 200 percent or below, have no defaults in the past three years, and meet specific cybersecurity and internal control standards. The travel rule for virtual asset transfers is expanded to apply to all transaction amounts between registered VASPs, requiring both originators and beneficiaries to secure information. Transfers to overseas entities are permitted under certain conditions, but transfers of KRW10 million or more to overseas VASPs or digital wallet service providers must be reported to the Korea Financial Intelligence Unit (KoFIU). These updated rules take effect from August 20, 2026, with other changes becoming effective six months after promulgation.
Press Releases
NaverBlog
KakaoStory
Copy URL
Rules Change Approved to Strengthen Registration and Anti-Money Laundering Requirements of VASPs Aug 11, 2026
The Financial Services Commission announced that the government approved a revision bill for the Enforcement Decree of the Act on Reporting and Using Specified Financial Transaction Information (the “Act” hereinafter) at the cabinet meeting held on August 11. With the revised rules in place, virtual asset service providers (VASPs) will be subject to stricter registration requirements and enhanced anti-money laundering (AML) duty in their handling of virtual asset transfers.
Key Revision Details
The rules change provide details regarding the registration requirements of VASPs, the notification of sanctions imposed on retired employees, the strengthened AML duty for virtual asset transfers (travel rule transactions), and the enhanced customer due diligence (CDD) requirement.
I. Enhanced Entry Rules and Registration Requirements
Expanded scope of major shareholders
The scope of major shareholders falling under the scrutiny for the entry registration of a VASP will be expanded to include the chief executive officer or controlling shareholder of the company, and the largest shareholder and company representative if the largest shareholder is a corporate entity.
Conditions for non-acceptance of registration
First, VASPs should meet the following financial soundness and social credibility requirements for registration or otherwise face non-acceptance of registration.
More specifically, VASPs (a) should maintain a debt ratio of 200 percent or below, (b) should not have been in default in the past three years, and (c) should not have been identified as an insolvent financial institution or have had its operating license or registration revoked in the past in violation of financial laws.
Executive officers (including CEOs) of VASPs need to meet specific qualifications prescribed under the Act on Corporate Governance of Financial Companies.
Largest shareholders of VASPs (a) should not have been a largest shareholder or a specially associated entity to an insolvent financial institution or a financial institution that has had its operating license or registration revoked previously, (b) should demonstrate a debt ratio of 200 percent or below, and (c) should meet specific qualifications prescribed under the Act on Corporate Governance of Financial Companies.
Second, VASPs should meet the following requirements—(a) the human resources and organizational capacity equipped with an adequate level of expertise required for conducting virtual asset transactions, (b) the computing system and the physical infrastructure needed to ensure the maintenance of cybersecurity and proper handling of security breaches, and (c) the internal control mechanisms required to ensure the maintenance of effective AML and user protection capacities.
Third, VASPs (including largest shareholders and executive officers) should be clear of past criminal penalties (monetary fine or above) for violating AML duties or other financial laws in the past. However, for largest shareholders, if the violation was a minor offense or the criminal penalty was imposed in a dual liability case, an exemption will be granted.
II. AML Duty on Virtual Asset Transfers
The travel rule currently in place for virtual asset transfers of KRW1,000,000 or more taking place between registered VASPs will be expanded to transactions of all sizes taking place between registered VASPs. In this regard, the beneficiary (recipient) will newly become subject to the duty to secure information provided by the originator (sender). This expanded application of the travel rule for virtual asset transfers of all amounts is intended to help close regulatory loophole and more effectively prevent money laundering.
Virtual asset transfers taking place between a domestically registered VASP and an overseas VASP and/or digital wallet service provider will be allowed on certain conditions—for instance, (a) virtual asset transfers to low-risk overseas VASPs, (b) when the sender and the recipient are the same entity, and (c) with high-risk transactions prohibited. In addition, virtual asset transfers of KRW10 million or more to an overseas VASP and/or digital wallet service provider should be reported to the Korea Financial Intelligence Unit (KoFIU) regardless of the level of risk involved in transactions to reassure the prevention of money laundering via overseas VASPs or digital wallet service providers and to boost transparency in virtual asset transfers.
III. Notification of Sanctions on Retired Employees
Notification for certain types of sanctions imposed on the retired employees of VASPs will be communicated via the Financial Supervisory Service and/or other related organizations.
IV. Other Regulatory Updates
Under the revised rules, VASPs should make sure to appropriately perform their customer due diligence (CDD) duty, and a more rigorous form of CDD will be required if there exists a concern for money laundering and for high-risk individuals and for the use of high-risk products or services.
Further Plan
The updated rules regarding the registration of VASPs and the notification of sanctions on retired employees will take effect from August 20, 2026, while other rules change will become effective six months after promulgation.
An updated version of the registration manual has been prepared and is made available for VASPs to provide more clear information about the updated registration procedures, required documents, deadlines and so on. Together with the FSS, the KoFIU plans to hold an information session for VASPs on August 13.
The KoFIU will continue to work on the prevention of money laundering and the protection of virtual asset users pursuant to the Act and make sure to effectively supervise VASPs and travel rule transactions.
PREV
Anti-Vishing Information Sharing via ASAP Available for Financial, Telecom and Investigation Data
NEXT
No results found.
List
Related Materials
Mar 30, 2026
Rules Change Proposed on VASPs to Strengthen Registration and Anti-money Laundering Requirements