No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • The Business of GRC
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Financial Services

Inside Korea’s Overhaul of Crypto Transfer Rules

Korea will provide early, in-force test of tighter self-hosted-wallet controls under consideration in EU

by Jay Park
October 2, 2026
in Financial Services
South Korea crypto transfer rules

CCI illustration by Jennifer L. Gaskin

Starting Feb. 19, South Korean virtual asset providers must refuse any incoming transfer missing required sender and recipient information — not flag it, refuse it — and the obligation reaches firms with no Korean entity. Jay Park, a digital asset regulation researcher, reads the decree itself to lay out what the rule requires and why it previews the tighter self-hosted-wallet controls the EU is weighing.

Starting in February, South Korean virtual asset providers must refuse any incoming transfer that arrives without the required originator and beneficiary information. The transfer won’t be flagged or held for remediation; it will be refused. 

The obligation sits with the receiving institution in Seoul, but the consequences land on whoever owns outbound flows at the sending firm, wherever that firm is based, and it applies whether or not you have a Korean entity. 

The deadline is firm — Feb. 19, 2027 — but much of what the rule requires is undefined because the criteria they depend on haven’t been written yet. It’s a scoping problem most compliance teams will recognize and an early test of self-hosted wallet restrictions the EU is still deciding whether to adopt.

What English-language coverage gets wrong

Korea issued the rules Aug. 18 as Presidential Decree No. 36592, an amendment to the enforcement decree of its main anti-money laundering law, the Act on Reporting and Using Specified Financial Transaction Information. Most English-language coverage has treated it as a single change, but it takes effect in two stages. Most of the decree kicked in Aug. 20, but a handful of provisions, including the transfer rules, were held back six months, to Feb. 19, 2027: Articles 10-2, 10-5(6), 10-10 and 10-20 and parts of 16-2. 

The August changes tightened provider registration, adding financial-soundness tests, screening of major shareholders and requirements for organization and internal controls. The February changes cover transfers. Article 10-10 governs the information that must travel with a transfer between providers and eliminates the old value threshold below which no information had to be sent. Article 10-20 lays out the measures providers must take, including for transfers involving foreign providers and for addresses the provider doesn’t exclusively control. In other words, self-hosted wallets.

The distinction tells you what’s in force today. As of this writing, Korean providers are subject to the new registration standards but not the new transfer standards. English-language summaries saying Korea already restricts withdrawals to self-custody wallets are describing what will happen in February.

Coverage has also attributed a requirement to the decree that isn’t in it. The rule has been widely reported in English as allowing transfers to a personal wallet only when the sender and recipient are the same person. That requirement doesn’t appear in Article 10-10 or Article 10-20. It comes from Financial Services Commission press material that accompanied the amendment, and that material has already been revised once.

Most compliance professionals know a regulator’s press release isn’t the law, but it’s easy to lose sight of that under deadline pressure. Press material describes intent and is written to be quoted, but the decree is written to be applied. 

crypto tokens on background
Financial Services

Banks Are Joining the Race to Issue Stablecoins; Can Their Compliance Teams Keep Up With the Risks?

by David Soiles and Manish Chopra
March 13, 2026

Controls and infrastructure banks have built over decades were designed for a different speed of money

Read moreDetails

What’s still undefined

The phrase “as determined and published by the Commissioner of the Korea Financial Intelligence Unit” appears six times in Article 10-20 alone and seven times across the two articles. Each time, it hands off an operative criterion to an FIU notice that hasn’t been issued: how a provider shows it controls an address, what evidence satisfies the requirement and how foreign providers should be risk-classified.

So the decree sets the date and the structure of the obligation but leaves the substance to documents that don’t exist yet. Korean firms face a fixed deadline with no published standard to build to.

None of this is unique to Korea. Leaving the details to secondary legislation is routine in most jurisdictions, and compliance teams deal with it every year. The Korean case is useful because the deadline is fixed, the gaps are visible and it’s happening first. 

That said, waiting is not necessary and likely not wise. You can build the data-capture layer, since Article 10-10 already specifies the categories of information required; counterparty attestation workflows for transfers to Korean providers; and an exception-handling path for refused transfers, since refusal is the required outcome under Article 10-20, item 6, when information isn’t provided on request.

Two things have to wait, because both are delegated to the unpublished notices: the evidentiary standard for showing control of a receiving address and any risk tiering of foreign counterparties.

What to do before February

Whatever your jurisdiction, the Korean case points to a short checklist:

  • Identify every counterparty that will fall under the February rules, including indirect exposure through intermediaries.
  • Build to what the decree already specifies (information fields and a request-then-refuse sequence) and document which controls are waiting on delegated criteria instead of leaving them blank.
  • Treat refusal as an expected outcome, not an incident. Decide now who gets notified, what the customer is told and how the transfer is unwound.
  • Read the instrument itself. If an English summary is the only source available, mark the control as provisional until someone has checked the original text.
  • Watch for the delegated notices. In Korea, that means the FIU; in your jurisdiction, it’s whichever body is responsible for the criteria your regulator has deferred.

The stakes extend beyond Korea. Under Regulation (EU) 2023/1113, the European Commission must report by June 30, 2027, on whether to limit, control or prohibit transfers involving self-hosted addresses. Korea’s rules take effect four months before that deadline. Whatever goes wrong in Seoul in the first quarter of 2027 — refused transfers, failed attestations, criteria published late — will be evidence European and US compliance teams can study before their own regulators take up the same question.

Tags: AMLCryptocurrency
Previous Post

No US Person, No Dollars, Still Sanctioned: Exploring Treasury’s Evolving Approach on Iran

Jay Park

Jay Park

Jay Park is a digital asset regulation researcher. He publishes the operative text of Korea’s virtual asset transfer provisions in the original alongside a working English translation on Tegong, an independent Korean-language site.

Related Posts

blockchain conceptual art

How Blockchain Intelligence Became Essential to Corporate Compliance

by Finn Grant
September 8, 2026

Crypto was initially built on the promise of permissionless finance, a system with no gatekeepers, no intermediaries and no paperwork....

cjeu building luxembourg

What the EU’s Italian Cases Mean for Sanctions & AML Compliance

by Henry Mander and Aki Corsoni-Husain
August 31, 2026

Two CJEU rulings on trust structures signal that regulators will look past legal title to who actually benefits, decides and...

shell game cups and dice

Has the CTA Saga Finally Ended?

by Jennifer L. Gaskin
August 19, 2026

Beneficial ownership reporting rules that once applied to more than 30 million corporate entities in the US now have just...

uae flag

The Day My Job Description Changed: Compliance & Personal Liability

by Amarjeet Singh
June 16, 2026

A UAE compliance officer explains what Federal Decree Law No. 10 of 2025 means in practice and why the profession...

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • The Business of GRC
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights