Korea Revises VASP Registration Manual Ahead of August 20 AML Rules

South Korea’s Financial Intelligence Unit (KoFIU) and Financial Supervisory Service have published a substantially revised registration manual for virtual asset service providers (VASPs), setting out how firms should prepare for stricter entry and anti-money laundering requirements that take effect on 20 August 2026.
The revised manual was presented to the industry at a 13 August briefing in Seoul attended by representatives of DAXA, the Korea Fintech Industry Association, employees from all 28 currently reported VASPs and prospective applicants. The authorities said the manual is intended to translate the amended Act on Reporting and Using Specified Financial Transaction Information and its subordinate rules into practical registration procedures.
Shareholder scrutiny expands
One of the most significant changes is the expansion of persons subject to suitability review. Checks that previously focused on the VASP, its representative and executives will now extend to major shareholders. The scope can include the largest shareholder, significant shareholders, shareholders that are related parties of the largest shareholder and, where the largest shareholder is itself a company, certain persons higher in the ownership chain.
Applicants will be expected to identify all reportable major shareholders and provide information including their real names, nationalities and shareholdings, supported by shareholder registers and other evidence. KoFIU warned that businesses with multi-layered ownership structures or overseas shareholders may need substantial time to gather the required documents.
Financial condition, AML staffing and IT controls
The manual also explains how new financial-soundness and social-credit tests will be assessed. For the debt-ratio test, customer deposits held under Korea’s virtual-asset user protection framework are deducted from total liabilities when calculating the adjusted ratio. Authorities will also examine matters such as defaults, insolvency, bankruptcy or rehabilitation history and previous business suspensions, depending on the person being assessed.
For organisation and staffing, the authorities will examine whether a VASP has sufficient personnel dedicated to AML work, with the manual referring to at least four AML personnel, as well as the professional competence of the compliance officer. Relevant AML training, work experience or recognised qualifications can be considered. Some concurrent roles may be permitted depending on the firm’s business model, organisational scale and staffing arrangements.
The revised guidance also clarifies the treatment of IT infrastructure. Systems processing unique identification information or personal credit information must generally be located in Korea. Where cloud services are used, a server located in a Korean region can satisfy this requirement. This is narrower than the earlier consultation proposal, which would have applied a domestic-location requirement regardless of the type of information processed.
KoFIU said that after the amended rules take effect, organisation, staffing, IT infrastructure and internal-control arrangements will no longer be assessed only from submitted documents. Their adequacy and actual operation may be reviewed substantively, including through on-site inspections where necessary.
Major changes move to advance notification
The reporting process for material changes is also being tightened. Changes concerning major shareholders or the compliance framework will move from a post-change filing within 14 days to a filing at least 30 days before the change. Implementing a change before receiving acceptance of the advance filing may expose the VASP to criminal and administrative sanctions.
The manual further clarifies how reporting deadlines are calculated for changes such as company name, business location, contact information, ISMS certification and real-name deposit and withdrawal account arrangements.
Non-custodial wallet criteria clarified
KoFIU has also introduced more detailed criteria for determining whether non-custodial wallet services fall within VASP registration requirements. Authorities will consider whether the provider can independently transfer virtual assets, generate or decrypt private keys, whether separate keys and wallet addresses are created for each user, and whether the user remains the direct and substantive signer of transactions.
The revised manual is scheduled to be finalised and implemented on 20 August alongside the amended legislation. KoFIU and the Financial Supervisory Service said they will continue to collect operational feedback and provide industry support as the strengthened registration regime is introduced.
For compliance teams, the update is significant because Korea is moving beyond basic VASP registration toward a more substantive assessment of ownership, financial resilience, AML capability, technology controls and actual operating effectiveness.



