South Korea's FIU Adjusts Specific Financial Information Act Enforcement Decree: Removes Mandatory Reporting for Crypto Transfers Over 10 Million Won

South Korea's FIU Adjusts Specific Financial Information Act Enforcement Decree: Removes Mandatory Reporting for Crypto Transfers Over 10 Million Won

N
News Editor
2026-06-05 05:00:50
South Korea's Financial Intelligence Unit (FIU) has eliminated the mandatory reporting obligation for virtual asset transfers exceeding 10 million won, shifting to internal risk management by exchanges. The Travel Rule now applies to all amounts, enhanced due diligence is performed only when deemed high-risk, small businesses get a one-year grace period on debt ratio requirements, and overseas cloud services are allowed. The revised decree takes effect on August 20, 2026.
South KoreaFIUSpecific Financial Information ActCryptoAMLTravel Rule

After incorporating industry feedback, South Korea's Financial Intelligence Unit (FIU) has made a pivotal adjustment to the enforcement decree of the Specific Financial Information Act, officially abolishing the mandatory reporting requirement for single virtual asset transfers exceeding 10 million won. Under the original draft, domestic virtual asset service providers (VASPs) were required to file a report with the FIU for any outgoing transfer of 10 million won or more, regardless of the associated money laundering risk. The new revision eliminates this obligation entirely, instead requiring exchanges and relevant operators to establish their own internal risk management systems to monitor, evaluate, and address potential illicit flows. The move marks a significant shift in Korea’s anti-money laundering (AML) strategy from rigid, rule-based reporting to a more principles-oriented, risk-based approach that grants firms greater operational autonomy.

The adjustment stems from widespread industry pushback. The mandatory reporting requirement was viewed as adding undue compliance costs without effectively distinguishing high-risk transactions from routine ones, creating unnecessary friction. After gathering and reviewing operator input, the FIU concluded that, by leveraging existing KYC and transaction monitoring infrastructure and strengthening VASPs’ internal risk assessment capabilities, the same AML objectives could be achieved. Discontinuing the obligation therefore represents a direct response to industry concerns and reflects a broader global trend towards principle-based—rather than prescriptive—AML regulation.

Travel Rule Extended to All Transaction Amounts

In a simultaneous tightening of information-sharing requirements, the revision expands the Travel Rule’s scope from the previous threshold of 1 million won and above to all amounts, regardless of size. South Korea had previously applied the Financial Action Task Force’s (FATF) Travel Rule only to transfers of 1 million won or more, leaving smaller-value transactions potentially outside the information exchange net. Once the new rule takes effect, every virtual asset transfer—no matter how small—will require the transmission of sender and recipient information, significantly closing loopholes that could be exploited through structuring. In parallel, enhanced due diligence (EDD) for high-risk or suspicious transactions has been shifted from a mandatory obligation to a discretionary assessment: VASPs will be required to perform deeper customer verification only when they themselves determine that a transaction carries exceptionally high risk. This grants operators greater operational flexibility while also demanding stronger internal risk identification capabilities.

Flexible Provisions on Financial Ratios and System Deployment

The revised decree also introduces transitional support for smaller VASPs. Previously, applicants were required to have a debt ratio not exceeding 200%; the amendment now grants such small operators a one-year grace period, giving them adequate time to restructure their finances and avoid being forced out of the market by an abrupt compliance cliff. Another notable change concerns the physical location of AML computer equipment: the original plan required that servers handling anti-money laundering data be physically located within South Korea, while the updated provision permits the use of overseas cloud services. This adjustment aligns with the financial industry’s widespread adoption of cloud infrastructure and substantially lowers compliance complexity for firms that rely on global cloud providers for data storage and processing.

From the withdrawal of mandatory reporting to the blanket application of the Travel Rule, together with the debt-ratio grace period and cloud service permission, the amendment significantly enhances the regulatory framework’s flexibility and practical feasibility while preserving fundamental AML safeguards. Striking a careful balance between enforcement and elasticity serves as the latest hallmark of Korea’s crypto oversight, with the revised decree set to enter into force on August 20, 2026.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.