Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Korea's Crypto Transfer Rules Take Effect in 35 Days With No Published CriteriaRegulations & Laws
5 min readFor Compliance Officers

Korea's Crypto Transfer Rules Take Effect in 35 Days With No Published Criteria

What Happened

On August 18, 2026, South Korea issued Presidential Decree No. 36592, amending the enforcement rules under the Act on Reporting and Using Specified Financial Transaction Information. The decree takes effect in two stages: most provisions went live on August 20, but Articles 10-2, 10-5(6), 10-10, 10-20, and portions of 16-2 were delayed until February 19, 2027.

The February provisions introduce a strict transfer rule. Virtual asset providers receiving transfers into South Korea must refuse any transaction that arrives without required originator and beneficiary information. Not flag it. Not hold it for remediation. Refuse it.

The obligation applies to the receiving institution in Seoul, but the compliance burden lands on whoever controls outbound flows at the sending firm, regardless of where that firm is based or whether it has a Korean entity.

The problem: as of this writing, the Korea Financial Intelligence Unit hasn't published the notices that define how providers satisfy the rule's core requirements.

Timeline

August 18, 2026: Presidential Decree No. 36592 issued
August 20, 2026: Registration provisions take effect (financial-soundness tests, shareholder screening, organizational controls)
February 19, 2027: Transfer provisions take effect (Articles 10-10, 10-20)
June 30, 2027: European Commission deadline to report on self-hosted wallet restrictions under Regulation (EU) 2023/1113

Between now and February 19, the Korea Financial Intelligence Unit must issue notices defining:

  • How a provider demonstrates control of an address
  • What evidence satisfies the requirement
  • How foreign providers should be risk-classified

Those notices don't exist yet. Korean firms face a fixed deadline with no published standard to build toward.

Control Gaps in Compliance Programs

This isn't a breach teardown. It's a regulatory design problem that exposes three control gaps common to compliance programs facing undefined criteria:

Gap 1: No fallback for delegated rulemaking delays
Article 10-20 uses the phrase "as determined and published by the Commissioner of the Korea Financial Intelligence Unit" six times in a single article. Each instance hands an operative criterion to secondary legislation. When that legislation doesn't arrive, you're building to a requirement you can't verify.

Gap 2: Treating press material as law
English-language coverage widely reported that Korea's rules allow transfers to self-custody wallets only when sender and recipient are the same person. That requirement doesn't appear in Article 10-10 or Article 10-20. It came from Financial Services Commission press material accompanying the amendment, which has since been revised. The decree is what gets enforced, not the press release.

Gap 3: No process for refused transfers
Article 10-20, item 6, makes refusal the required outcome when information isn't provided on request. Most compliance teams treat refusal as an incident, not an expected operational state. That means no documented workflow for who gets notified, what the customer is told, or how the transfer is unwound.

What the Relevant Standard Requires

Article 10-10 eliminates the old value threshold below which no information had to be sent and specifies the categories of information required to travel with a transfer between providers.

Article 10-20 lays out the measures providers must take, including for transfers involving foreign providers and for addresses the provider doesn't exclusively control (self-hosted wallets).

The FATF Recommendations, which underpin most national AML/CFT regimes, require financial institutions to obtain and hold required originator and beneficiary information for wire transfers. FATF Recommendation 16 (the "Travel Rule") applies to virtual asset transfers and requires institutions to assess and mitigate the money laundering and terrorist financing risks of new products and business practices.

Korea's decree goes further by mandating refusal rather than flagging or holding for review. That's a design choice, not a FATF requirement, and it shifts the operational burden from detection to prevention.

Lessons and Action Items for Your Team

Lesson 1: Build to what you can verify
Article 10-10 already specifies the information fields required. You can build the data-capture layer now. You can design counterparty attestation workflows for transfers to Korean providers. You can document an exception-handling path for refused transfers.

What you can't do is finalize the evidentiary standard for proving control of a receiving address or complete any risk tiering of foreign counterparties, because both are delegated to unpublished notices.

Document which controls are waiting on delegated criteria. Don't leave them blank. Mark them as provisional and note the dependency.

Action: Map every control to its source
For each requirement in your Korean transfer control set, note whether it comes from the decree itself, from delegated criteria you're waiting on, or from press material. If an English summary is your only source, mark the control as provisional until someone reviews the original Korean text.

Lesson 2: Refusal is the expected outcome, not an edge case
If a transfer arrives without required information and the sending firm doesn't provide it on request, Article 10-20 requires refusal. That's not a system failure. It's compliance.

Your incident response runbook shouldn't be the document that explains what happens when you refuse a transfer. You need a separate operational workflow.

Action: Define the refusal workflow now
Document who gets notified when a transfer is refused, what message the customer receives, how the funds are returned (if applicable), and what gets logged. Decide whether refusals trigger a counterparty review or a relationship re-evaluation. Test the workflow before February 19.

Lesson 3: Korea is the pilot for EU and US rules
Regulation (EU) 2023/1113 requires the European Commission to report by June 30, 2027, on whether to limit, control, or prohibit transfers involving self-hosted addresses. Korea's rules take effect four months before that deadline.

Whatever goes wrong in Seoul in Q1 2027 will be evidence European and US compliance teams can study before their own regulators take up the same question.

Action: Treat Korea as your early-warning system
Identify every counterparty that will fall under Korea's February rules, including indirect exposure through intermediaries. Monitor what happens when the Korea Financial Intelligence Unit publishes its notices. Track refused transfers, failed attestations, and any criteria published late. That's data you'll use when the EU and US finalize their own self-hosted wallet restrictions.

Lesson 4: Don't wait for perfect clarity
Leaving details to secondary legislation is routine. Compliance teams deal with it every year. The Korean case is useful because the deadline is fixed, the gaps are visible, and it's happening first.

Waiting isn't necessary and likely isn't wise. You can't finalize everything, but you can build the infrastructure that doesn't depend on the missing notices.

Action: Build the request-then-refuse sequence
Article 10-20 already defines the structure: request information, then refuse if it isn't provided. Implement that sequence now. The evidentiary standard may change, but the workflow won't.

Application Security Isn’t Optional Anymore.

You Might Also Like