Starting Feb. 19, South Korean virtual asset providers must refuse any incoming transfer missing required sender and recipient information — not flag it, refuse it — and the obligation reaches firms with no Korean entity. Jay Park, a digital asset regulation researcher, reads the decree itself to lay out what the rule requires and why it previews the tighter self-hosted-wallet controls the EU is weighing.
Starting in February, South Korean virtual asset providers must refuse any incoming transfer that arrives without the required originator and beneficiary information. The transfer won’t be flagged or held for remediation; it will be refused.
The obligation sits with the receiving institution in Seoul, but the consequences land on whoever owns outbound flows at the sending firm, wherever that firm is based, and it applies whether or not you have a Korean entity.
The deadline is firm — Feb. 19, 2027 — but much of what the rule requires is undefined because the criteria they depend on haven’t been written yet. It’s a scoping problem most compliance teams will recognize and an early test of self-hosted wallet restrictions the EU is still deciding whether to adopt.
What English-language coverage gets wrong
Korea issued the rules Aug. 18 as Presidential Decree No. 36592, an amendment to the enforcement decree of its main anti-money laundering law, the Act on Reporting and Using Specified Financial Transaction Information. Most English-language coverage has treated it as a single change, but it takes effect in two stages. Most of the decree kicked in Aug. 20, but a handful of provisions, including the transfer rules, were held back six months, to Feb. 19, 2027: Articles 10-2, 10-5(6), 10-10 and 10-20 and parts of 16-2.
The August changes tightened provider registration, adding financial-soundness tests, screening of major shareholders and requirements for organization and internal controls. The February changes cover transfers. Article 10-10 governs the information that must travel with a transfer between providers and eliminates the old value threshold below which no information had to be sent. Article 10-20 lays out the measures providers must take, including for transfers involving foreign providers and for addresses the provider doesn’t exclusively control. In other words, self-hosted wallets.
The distinction tells you what’s in force today. As of this writing, Korean providers are subject to the new registration standards but not the new transfer standards. English-language summaries saying Korea already restricts withdrawals to self-custody wallets are describing what will happen in February.
Coverage has also attributed a requirement to the decree that isn’t in it. The rule has been widely reported in English as allowing transfers to a personal wallet only when the sender and recipient are the same person. That requirement doesn’t appear in Article 10-10 or Article 10-20. It comes from Financial Services Commission press material that accompanied the amendment, and that material has already been revised once.
Most compliance professionals know a regulator’s press release isn’t the law, but it’s easy to lose sight of that under deadline pressure. Press material describes intent and is written to be quoted, but the decree is written to be applied.
Banks Are Joining the Race to Issue Stablecoins; Can Their Compliance Teams Keep Up With the Risks?
Controls and infrastructure banks have built over decades were designed for a different speed of money
Read moreDetailsWhat’s still undefined
The phrase “as determined and published by the Commissioner of the Korea Financial Intelligence Unit” appears six times in Article 10-20 alone and seven times across the two articles. Each time, it hands off an operative criterion to an FIU notice that hasn’t been issued: how a provider shows it controls an address, what evidence satisfies the requirement and how foreign providers should be risk-classified.
So the decree sets the date and the structure of the obligation but leaves the substance to documents that don’t exist yet. Korean firms face a fixed deadline with no published standard to build to.
None of this is unique to Korea. Leaving the details to secondary legislation is routine in most jurisdictions, and compliance teams deal with it every year. The Korean case is useful because the deadline is fixed, the gaps are visible and it’s happening first.
That said, waiting is not necessary and likely not wise. You can build the data-capture layer, since Article 10-10 already specifies the categories of information required; counterparty attestation workflows for transfers to Korean providers; and an exception-handling path for refused transfers, since refusal is the required outcome under Article 10-20, item 6, when information isn’t provided on request.
Two things have to wait, because both are delegated to the unpublished notices: the evidentiary standard for showing control of a receiving address and any risk tiering of foreign counterparties.
What to do before February
Whatever your jurisdiction, the Korean case points to a short checklist:
- Identify every counterparty that will fall under the February rules, including indirect exposure through intermediaries.
- Build to what the decree already specifies (information fields and a request-then-refuse sequence) and document which controls are waiting on delegated criteria instead of leaving them blank.
- Treat refusal as an expected outcome, not an incident. Decide now who gets notified, what the customer is told and how the transfer is unwound.
- Read the instrument itself. If an English summary is the only source available, mark the control as provisional until someone has checked the original text.
- Watch for the delegated notices. In Korea, that means the FIU; in your jurisdiction, it’s whichever body is responsible for the criteria your regulator has deferred.
The stakes extend beyond Korea. Under Regulation (EU) 2023/1113, the European Commission must report by June 30, 2027, on whether to limit, control or prohibit transfers involving self-hosted addresses. Korea’s rules take effect four months before that deadline. Whatever goes wrong in Seoul in the first quarter of 2027 — refused transfers, failed attestations, criteria published late — will be evidence European and US compliance teams can study before their own regulators take up the same question.


Jay Park is a digital asset regulation researcher. He publishes the operative text of Korea’s virtual asset transfer provisions in the original alongside a working English translation on Tegong, an independent Korean-language site. 










