South Korea is moving ahead with stricter anti-money-laundering controls for the crypto sector after the Cabinet approved a revised enforcement decree under the Act on Reporting and Using Specified Financial Transaction Information. The changes tighten how virtual asset service providers are screened for registration and broaden compliance duties tied to virtual-asset transfers.

The Financial Intelligence Unit said the revision is designed to strengthen oversight of registered operators and close gaps that could be used to avoid existing rules. One of the most notable changes is the expansion of the travel rule so it applies to all transfers between registered crypto businesses, regardless of transaction size.

Broader scrutiny for VASP registrations

The revised decree raises the bar for VASP filings by widening the scope of shareholder reviews and adding clearer grounds for rejection. Review targets will now include major shareholders who have the power to appoint a chief executive or a majority of the board. When the largest shareholder is a corporation, its own largest shareholder and representative will also be subject to review.

Authorities will be allowed to reject filings on financial and compliance grounds set out in the revision. The decree requires a debt ratio of 200% or less and excludes applicants with a history of default or similar conduct. It also bars operators considered financially troubled, as well as those whose licenses have previously been revoked. Existing operators will be given a one-year grace period to meet these requirements.

Operational standards and user-protection controls

In addition to ownership and financial screening, VASPs will have to demonstrate that they can operate with adequate internal safeguards. The decree requires professional staff, appropriate IT and security systems, and internal controls aimed at protecting users.

These standards will not apply overnight to firms already in the market. Existing operators will have a one-year grace period to satisfy the new operational and user-protection requirements, matching the transition period provided for other registration-related changes.

Travel rule expanded to all transfers

South Korea is also removing the transaction threshold for the travel rule when transfers occur between registered operators. Under the revised AML framework, the rule will cover all virtual-asset transfers between such businesses, regardless of amount, in an effort to prevent attempts to evade regulation by splitting transactions into smaller pieces.

The obligations on receiving platforms are also being tightened. Operators that receive transfers must verify remittance information and will be able to request any missing data. They may also refuse a transfer if the required information is not properly provided.

Overseas exchanges, personal wallets and implementation timeline

The decree also increases oversight of transfers involving overseas exchanges and personal wallets. Transactions with overseas platforms classified as low risk will be permitted, while other overseas transfers will be allowed only when the sender and recipient are the same person. High-risk transactions will be banned.

For operators handling transfers worth 10 million won, or about $7,200, or more, the rules require the use of their own suspicious-transaction monitoring systems. The VASP registration provisions will take effect on Aug. 20, while the expanded travel rule and the overseas and external-wallet measures will take effect six months after promulgation.

The FIU said it plans to publish a filing manual and, together with the Financial Supervisory Service, hold a briefing for VASPs and related parties on Aug. 13. That briefing is the next confirmed step as the industry prepares for the staged rollout of the new rules.

Source: en.bloomingbit.io