The Financial Services Commission office at Government Complex Seoul in Jongno-gu [Yonhap]
The Financial Services Commission office at Government Complex Seoul in Jongno-gu [Yonhap]

South Korea is tightening entry requirements for virtual asset service providers, extending scrutiny to the criminal records and financial soundness of major shareholders at the registration stage. Companies will also be required to file advance notice 30 days before changing major shareholders or their compliance frameworks, replacing the previous practice of reporting such changes after the fact.

The Korea Financial Intelligence Unit (KoFIU), an arm of the Financial Services Commission, and the Financial Supervisory Service held a briefing Thursday at Dream Plus Gangnam in Seoul for virtual asset service providers (VASPs) and prospective operators on the revised VASP registration manual. The revision follows an amendment to the Act on Reporting and Using Specified Financial Transaction Information — commonly known as the Special Financial Information Act — that passed the National Assembly in January and takes effect Aug. 20.

About 100 people attended the briefing, including officials from the Digital Asset Exchange Alliance (DAXA) and the Korea Fintech Industry Association, executives and staff from 28 VASPs already registered under the act, and prospective operators preparing to apply for registration.

"The virtual asset market has grown to exert broad influence on people's economic lives and the financial system — a very different situation from 2021, when the registration regime was first introduced," said Ha Ju-sik, KoFIU's director of regulatory operations planning. "To maintain trust in the virtual asset market, we need to rigorously examine the soundness of operators and their major shareholders from the point of entry."

The number of virtual asset users eligible to trade has nearly doubled, rising from about 5.58 million at end-2021 to about 11.13 million at end-2025. Market capitalization expanded from 55.2 trillion won ($39 billion) at end-2021 to 87.2 trillion won at end-2025.

KoFIU also said the legislative changes align with the strict entry-regulation standards recommended by the Financial Action Task Force (FATF) for operators and major shareholders, as well as the regulatory direction taken by major jurisdictions — including the EU's Markets in Crypto-Assets Regulation (MiCA) and ongoing discussions around the CLARITY Act in the United States.

Under the revised rules, the scope of shareholder review will expand significantly. In addition to the existing checks on operators, chief executives and executives, authorities will now examine the legal violation history, financial condition and social creditworthiness of the largest shareholder, major shareholders and shareholders who are specially related parties of the largest shareholder. Where the largest shareholder is a corporation, that corporation's own largest shareholder and chief executive may also fall within the scope of the registration review.

Operators will therefore need to verify not only direct shareholders but also specially related parties and upstream controlling relationships. Where a major shareholder is based overseas or where a controlling structure spans multiple entities, authorities said operators must prepare supporting documents such as shareholder registers.

Financial soundness criteria for operators have also been made more specific. When calculating the debt ratio, user deposits and similar liabilities will be deducted from total liabilities. Registration filings must separately state the adjusted total liabilities excluding such items.

The social creditworthiness review will check, for each operator, major shareholder, chief executive and executive, whether there is a history of debt default, designation as an insolvent financial institution, suspension of banking transactions due to dishonor, bankruptcy or rehabilitation proceedings, or the time elapsed since any business suspension order.

Standards for anti-money laundering (AML) staffing and organizational structure will also be raised. Operators must maintain at least four staff dedicated to AML work, and compliance officers will need to demonstrate expertise through completion of specialized training or relevant work experience or qualifications. Some concurrent roles will be permitted, however, taking into account the nature of the business, organizational size and staffing conditions.

On IT infrastructure, systems that process unique identification information or personal credit data must be located in South Korea — a relaxation from the pre-announcement draft, which would have required all IT systems to be kept domestically regardless of the type of information handled. Operators using cloud services will be considered compliant with the domestic-location requirement if their servers are based in South Korea.

Authorities added that while compliance frameworks have previously been verified mainly through submitted documents, they will now also assess whether those frameworks are actually functioning. On-site inspections will be conducted when necessary to confirm real-world operations.

The change-notification process is also being tightened. For matters relating to major shareholders and compliance frameworks, the existing requirement to report within 14 days after a change takes effect will be replaced by a pre-notification requirement 30 days before the change. KoFIU stressed that "because these matters constitute grounds for rejection or ex officio cancellation of registration, implementing a change before the notification is accepted could result in criminal punishment or administrative sanctions — operators must exercise particular caution."

Detailed rules for calculating change-notification deadlines have also been established. As a general principle, the deadline runs from the date the actual change occurs, with item-specific benchmarks: the date of registration for trade name and business address changes; the date of actual activation and use for contact information; the date of certificate receipt for Information Security Management System (ISMS) certification; and the contract start date for real-name verified deposit and withdrawal accounts.

New criteria have also been established for determining whether non-custodial wallets are subject to VASP registration. Personal non-custodial wallets in which the operator does not hold exclusive control over the private key may be exempt from the registration requirement.

Authorities said they will make the determination by examining four factors in combination: whether the operator can unilaterally transfer virtual assets; whether the operator can arbitrarily generate, access or decrypt private keys; whether individual private keys and wallet addresses are generated for each user; and whether the user is the substantive signing party for the private key.

KoFIU and the Financial Supervisory Service plan to finalize and implement the manual in time for the revised Special Financial Information Act's entry into force on Aug. 20. They will also operate a system for handling practical inquiries through industry associations, and will continue collecting feedback and suggestions for improvement from operators during the registration preparation process.

"We will work together to find solutions to on-the-ground concerns, within the bounds of preserving the integrity of the anti-money laundering framework," Ha said.


kyoung@heraldcorp.com