South Korea’s FIU Sets Crypto Transfer Rules for Overseas Exchanges, Personal Wallets
Summary
- The FIU has established new standards for allowing and restricting virtual-asset transfer transactions with overseas virtual-asset operators and personal wallets.
- Domestic virtual-asset service providers will assess overseas operators’ anti-money laundering systems and their compliance with FATF standards, and restrict transfer transactions when risks are high.
- Virtual-asset service providers will face tougher registration review standards, including a debt ratio of 200% or less, stricter financial soundness and internal control requirements, and enhanced customer due diligence.
Forecast Trend Report by Period



South Korea’s Financial Intelligence Unit has introduced new standards governing when domestic virtual-asset service providers may transfer crypto assets to and from overseas exchanges and personal wallets. The rules restrict transfers involving high-risk overseas operators. They also, in principle, allow transfers involving personal wallets only when the exchange customer and the counterparty are the same person.
According to the industry on Aug. 24, the FIU recently revised the supervisory rules under the Act on Reporting and Using Specified Financial Transaction Information. Under the amendments, domestic virtual-asset service providers must assess the identity and anti-money laundering controls of overseas virtual-asset operators before establishing a business relationship. They must also periodically reassess those operators while the relationship is maintained.
Transfers may be permitted following a risk assessment if the overseas operator is based in a country that effectively implements Financial Action Task Force recommendations, meets obligations comparable to those in South Korea on customer due diligence, suspicious transaction reporting and the provision of virtual-asset transfer information, and holds the required licenses and approvals.
By contrast, domestic operators must restrict virtual-asset transfers with overseas operators based in high-risk countries designated by the FATF or with operators that lack required licenses until the relevant risks are resolved. For overseas operators that do not fall under those high-risk criteria but still fail to meet all of the approval requirements, transfers are allowed only when the customer and the person sending or receiving the virtual asset are the same.
The FIU also codified standards for transactions involving personal wallets. If money-laundering risk is deemed significantly elevated, the transaction must be restricted. Even when that is not the case, transfers are, in principle, allowed only when the exchange customer and the owner of the personal wallet are the same person. Transfers required by law or carried out under the lawful exercise of authority by a state agency are exempt. The rules covering overseas exchanges and personal wallets will take effect six months after the notice was issued.
The standards for reviewing virtual-asset business registration filings were also tightened. Applicants will be required to submit the real names of major shareholders, their shareholding status, nationality, and address or location during the filing process. Material changes involving major shareholders, as well as organizations and personnel, computer systems and internal control systems related to legal compliance, will also shift from post-reporting to prior reporting.
The revised rules also spell out requirements for financial soundness and internal controls. Virtual-asset service providers must, in principle, keep their debt ratio at 200% or less as of the end of the most recent quarter. They must secure at least four staff members for anti-money laundering work, including a compliance officer and a reporting officer. The FIU also introduced standards on the experience and expertise required for compliance officers and information-technology personnel. Registration reviews will also cover IT and internal-control requirements, including security systems, data backup and procedures to protect user assets.
Customer due diligence for high-risk transactions will also be strengthened. If money-laundering risk is found to have risen significantly during transaction monitoring or risk assessment after an initial customer review, enhanced due diligence must be conducted again before the next financial transaction takes place.
The notice took effect on Aug. 20, 2026. Some provisions, including the standards for transfer transactions with overseas virtual-asset operators and personal wallets, will apply six months after issuance. Some financial soundness and internal-control standards for already registered virtual-asset service providers will also be subject to a one-year grace period.
Minseung Kang
minriver@bloomingbit.ioBlockchain journalist | Writer of Trade Now & Altcoin Now, must-read content for investors.