South Korea's Financial Intelligence Unit (FIU) has amended the Regulation on Reporting and Supervision of Specific Financial Transaction Information, implementing changes to the parent Act that took effect the same day. The amendment reaches virtual asset service providers (VASPs) generally, and specifically those that transact with foreign VASPs or private (unhosted) wallets, along with entities subject to the reporting/change-reporting regime and their major shareholders. It took effect on 20 August 2026.

What changed

  • Enhanced due diligence timing (Art. 23-2). Where a transaction is judged to carry significantly elevated money-laundering risk, enhanced customer due diligence must now be completed *before* the transaction takes place, not after.
  • Major shareholder disclosure (Art. 27(3)–(4)). VASP reporting filings must now specify particular items and attached documents concerning major shareholders, reflecting the parent Act's new major-shareholder reporting requirement.
  • Change-reporting shifts from after-the-fact to prior notice (Art. 27(6)). Changes involving major shareholders, or involving a VASP's organization/personnel, IT systems, and internal-control framework for legal compliance, must now be reported *before* the change takes effect, rather than reported afterward.
  • Grounds for rejecting a report specified (Art. 27(8)–(9), Attachments 2–3). The regulation now sets out concrete standards for two areas that, if unmet, can result in a report being refused: (i) sound financial standing and social creditworthiness, and (ii) the adequacy of organization/personnel, IT systems, and internal-control framework for virtual-asset-related legal compliance.
  • Standards for transfers involving foreign VASPs or private wallets (Art. 28-2). New transaction-permission standards apply where a VASP conducts a virtual asset transfer with a foreign VASP or a private wallet, and the duty to evaluate foreign VASP counterparties is now specified in more detail.

There is no single quantitative threshold triggering these duties; applicability is assessed case by case based on risk and the nature of the reporting event.

What this means for you

  • If you are a licensed or reporting VASP in Korea: Review your customer due diligence workflow to confirm enhanced checks are completed *before* — not after — high-risk transactions.
  • If you are preparing a reporting or change-reporting filing: Confirm which categories now require prior reporting (major shareholder changes; organization, IT, and internal-control changes) versus after-the-fact reporting, since filing late in the wrong category can now result in your report being refused rather than merely delayed.
  • If your major shareholders have changed or are changing: Prepare the specific disclosure items and attachments now required under Article 27(3)–(4) before submitting.
  • If you transact with foreign VASPs or facilitate transfers to/from private wallets: Check the new transaction-permission standards under Article 28-2 and confirm your counterparty-evaluation process for foreign VASPs meets the specified requirements before continuing such transfers.
  • If you are a foreign VASP seeking a Korean counterparty relationship: Expect Korean VASPs to apply a more formalized evaluation process to your institution under the new Article 28-2 standards.

Source: https://www.law.go.kr/행정규칙/%ED%8A%B9%EC%A0%95%20%EA%B8%88%EC%9C%B5%EA%B1%B0%EB%9E%98%EC%A0%95%EB%B3%B4%20%EB%B3%B4%EA%B3%A0%20%EB%B0%8F%20%EA%B0%90%EB%8F%85%EA%B7%9C%EC%A0%95