FSC Korea Revises VASP Registration Manual: What Accounting Firms and CFOs Must Assess Now
South Korea's Financial Services Commission (FSC), working alongside the Financial Intelligence Unit (FIU) and the Financial Supervisory Service (FSS), has completed a full overhaul of the manual governing virtual asset service provider (VASP) registration. The revision tightens what firms must demonstrate before and after notification, and the FIU is following up with a series of outreach briefings specifically designed to walk industry participants through the new requirements. For accounting firms, auditors, and CFOs with Korean VASP clients or cross-border digital asset exposure, the timing demands immediate attention.
What Has Changed in the Registration Manual
The FSC describes the revision as a comprehensive rewrite rather than a incremental update, driven by the broader tightening of the VASP notification regime that has been progressing through Korean financial regulation over the past year. The revised manual sets out updated procedural requirements, documentary standards, and AML/KYC benchmarks that applicants must satisfy to complete or maintain a valid VASP registration.
Scope of the Revision
The manual overhaul covers the full lifecycle of the notification process: initial application documentation, AML programme requirements, information security standards, and the ongoing obligations that registered VASPs must meet. The FIU has signalled that the revised standards reflect lessons from prior registration cycles, including cases where firms submitted incomplete or inadequate AML frameworks. Firms that were registered under earlier procedural guidance are not automatically grandfathered; the expectation is that existing registrants assess their current documentation against the new benchmarks.
The Outreach Briefing Programme
Rather than issuing the revised manual as a static publication, the FIU and FSS are conducting what the FSC describes as a "visiting briefing" series, taking the explanation directly to industry participants. These sessions give VASPs and their advisers the opportunity to ask procedural questions and clarify expectations before they submit or renew documentation. For accounting firms with VASP audit or advisory mandates, attending or monitoring the outputs of these sessions should be treated as a compliance intelligence task, not an optional extra.
Regulatory Context: Why This Revision Matters Now
This manual revision does not arrive in isolation. South Korea has been one of the more active jurisdictions in Asia for tightening its virtual asset regulatory perimeter over the past two years, and the VASP registration framework sits at the centre of that effort.
The Tightened Notification Regime
As covered in our earlier analysis of FSC Korea tightens VASP registration requirements, the underlying notification rules have already been strengthened, with enhanced scrutiny of AML programme quality, management fitness, and information security capability. The revised manual is the operational translation of those tightened rules into actionable procedural guidance. It tells firms not just what the rules require but exactly how to demonstrate compliance in their submitted documentation.
Travel Rule Enforcement as a Parallel Track
The manual revision sits alongside South Korea's decision to remove the threshold on Travel Rule obligations, a development analysed in detail in our piece on South Korea removes the crypto Travel Rule threshold. Together, these two measures signal a consistent policy direction: Korean regulators are raising the floor on what constitutes acceptable AML compliance for any firm touching virtual assets in the jurisdiction. A VASP that meets the old registration standard but has not updated its Travel Rule infrastructure may find its registration vulnerable at the next review.
Accounting and Audit Implications for B2B Practitioners
The practical consequences for accounting firms, auditors, and CFOs fall into several distinct categories.
Client Gap Assessments
Firms holding advisory or audit mandates for Korean VASPs should treat the publication of the revised manual as a trigger for a structured gap assessment. The assessment should compare the client's current AML policy documentation, KYC procedures, transaction monitoring parameters, and information security certifications against the specific requirements now set out in the new manual. Any gaps identified are potential registration vulnerabilities, not merely good-practice observations.
Audit Scope and Representation Letters
For auditors signing off on Korean VASP financial statements, the revised registration requirements have a direct bearing on going concern assessment. A VASP that cannot demonstrate compliance with the updated manual faces the risk of a registration challenge, which in turn affects the firm's legal ability to continue operating. Auditors should consider whether existing representation letters adequately address the client's compliance status under the revised regime, and whether any additional procedures are warranted.
CFO and Internal Control Responsibilities
CFOs at Korean VASPs bear direct responsibility for ensuring that the firm's compliance infrastructure matches the new manual's requirements. This is not solely a legal or compliance team matter. The AML programme, including its resourcing, its documented risk appetite, and its transaction monitoring logic, must be capable of surviving FIU scrutiny. Where crypto accounting software is used to generate transaction records or support compliance reporting, the outputs of that software need to be reconcilable with the documentation standards the revised manual requires. Gaps between system outputs and manual requirements create audit trails that regulators can and do examine.
Cross-Border Advisory Mandates
Accounting firms advising non-Korean clients who operate in or send transfers to Korean VASPs also have a role here. The revised registration standards affect the counterparty risk profile of any Korean VASP on a client's trading or custody roster. A Korean VASP that loses or struggles to maintain its registration becomes a compliance exposure for its overseas counterparties, potentially triggering enhanced due diligence requirements under those counterparties' own AML frameworks.
What Firms Should Do Before the Next FIU Inspection Cycle
The FIU's decision to run outreach briefings rather than simply publish the manual suggests it anticipates that many registered VASPs will need to update their documentation. That is a signal worth heeding.
Immediate Actions
Accounting firms and CFOs should take the following steps without waiting for a formal FIU review notice. First, obtain and read the revised manual in full, paying particular attention to any sections where the language has shifted from the prior version. Second, map the new requirements against the client's or firm's existing documentation to identify specific gaps rather than general areas of concern. Third, determine whether the firm or client has any outreach briefing sessions available to attend, either in person or via published summaries, and factor the clarifications provided into the gap analysis. Fourth, update AML policies, KYC procedures, and information security documentation where gaps are identified, and ensure that version control records show the update was made in response to the revised manual. Fifth, confirm that any digital asset accounting software or crypto bookkeeping software used for transaction record-keeping generates outputs consistent with the evidentiary standards the FIU expects in a registration review.
Longer-Term Compliance Posture
The pattern of Korean regulatory activity over the past year suggests that the revised manual is unlikely to be the final word. The FSC has shown a willingness to iterate quickly when it identifies gaps in the existing framework. Firms that build a standing process for benchmarking their compliance documentation against the current regulatory standard, rather than treating registration as a one-time exercise, will be better positioned to absorb future changes without scrambling. That means treating compliance documentation as a live asset, subject to regular review, rather than a static file submitted at registration and then left unchanged.
Frequently Asked Questions
Does the revised manual apply to VASPs already registered under the old framework?
The FSC's position is that the revised manual reflects the current regulatory standard. Existing registrants are expected to assess their documentation against the new requirements and update where necessary, rather than relying on their original registration as proof of ongoing compliance.
What does the FIU outreach briefing programme cover?
The visiting briefing sessions are designed to walk VASPs and their advisers through the changes in the revised manual and answer procedural questions. They are particularly useful for clarifying how the FIU expects certain requirements to be evidenced in submitted documentation.
How does the revised manual interact with South Korea's Travel Rule obligations?
The two measures operate in parallel. The revised registration manual sets the AML programme and documentation standard for maintaining a valid VASP notification, while the Travel Rule obligations govern how firms handle specific transaction data. A firm must satisfy both sets of requirements independently; compliance with one does not substitute for the other.
What is the specific risk for auditors signing off on Korean VASP accounts?
If a VASP's registration is at risk because its documentation does not meet the revised manual's standards, that is a going concern factor that auditors must consider. Audit teams should update their risk assessments and consider whether additional representations or procedures are needed in light of the revised requirements.
How should accounting firms document their response to this regulatory change?
Firms should record the gap assessment, the steps taken to address any gaps, and the updated documentation in a way that creates a clear audit trail. If the FIU later reviews a client's registration, the firm's work papers should be able to demonstrate that the compliance update was timely and substantive, not cosmetic.
