FSC Korea Revamps VASP Registration Manual: What Accounting Firms and CFOs Must Assess Now
South Korea's Financial Services Commission has announced a complete overhaul of the registration manual for virtual asset service providers, timed deliberately to align with tightened VASP registration rules already in force. The Financial Intelligence Unit and the Financial Supervisory Service are following up with a series of outreach sessions, going directly to VASPs to walk through what has changed. For accounting firms and CFOs with Korean crypto clients or Korean-domiciled operations, the revised manual is not a background update; it sets a new, concrete compliance baseline that touches AML documentation, internal controls, and ultimately the quality data that crypto compliance reporting tools must capture and preserve.
What the FSC Has Actually Done
A Full Revision, Not a Patch
The FSC's announcement describes the registration manual as having been "comprehensively revised" in response to the strengthened VASP notification regime. That language matters. A targeted amendment would tweak specific clauses; a full revision signals that the entire framework for how a VASP presents itself to the regulator has been reconsidered. Firms that benchmarked their compliance programmes against the previous manual cannot assume continuity. Every section needs to be read fresh.
The revision sits within a broader regulatory tightening that FSC Korea tightens VASP registration requirements has been building toward through 2025 and into 2026. The manual revision is the practical implementation layer: it tells VASPs exactly how to document and demonstrate compliance with the higher-level rules that were already adopted.
FIU and FSS Outreach Sessions
The FIU and the Financial Supervisory Service are running what the FSC describes as "outreach explanation sessions," visiting VASPs rather than expecting them to seek guidance independently. This is a notable regulatory posture. It suggests the authorities are aware that the revised requirements are substantive enough to warrant direct engagement, and it also means that any VASP that attends a session but fails to act on the guidance will have limited room to argue later that the requirements were unclear. For advisers, the existence of these sessions creates a useful reference point: if a client was present, the burden of understanding shifts firmly to them.
Why This Revision Matters Beyond Registration Paperwork
AML Controls Are the Core Issue
VASP registration in Korea is not a one-time filing exercise. The notification regime is tied directly to anti-money laundering obligations under the Act on Reporting and Using Specified Financial Transaction Information. A revised registration manual therefore ripples through a firm's entire AML architecture: transaction monitoring thresholds, customer due diligence procedures, suspicious transaction reporting chains, and the records a VASP must retain to demonstrate compliance on demand.
Accounting firms advising Korean VASPs, or auditing entities that hold Korean VASP licences, need to understand that a gap in the registration file is rarely just an administrative problem. Regulators treating registration as an AML gateway means that an incomplete or outdated filing can call the adequacy of the whole AML programme into question.
The Travel Rule Connection
Korea has already moved aggressively on the FATF travel rule. As covered when South Korea removes the crypto travel rule threshold, the removal of any minimum threshold means virtually all virtual asset transfers now carry originator and beneficiary data obligations. The revised registration manual is likely to reflect that expanded scope, requiring VASPs to demonstrate they have the systems in place to collect, transmit, and retain that data across all transfers, not just those above a prior floor. Compliance officers reviewing the manual should map each new registration requirement against existing travel rule infrastructure to identify gaps before the outreach sessions conclude.
Accounting and Audit Implications
What Changes for Accounting Firms
Firms providing compliance advisory or audit services to Korean VASPs face several immediate considerations.
First, scope of engagement letters may need updating. If a firm's retainer was scoped against the previous registration manual, clients may now expect advice that covers the revised requirements without an explicit fee discussion. Getting ahead of that conversation is both a commercial and a risk management issue.
Second, audit procedures for AML compliance opinions or agreed-upon procedures reports need to reference the current manual, not the superseded version. An opinion grounded in old documentation is a professional liability risk, particularly if the client subsequently faces regulatory scrutiny.
Third, the revised manual likely introduces or tightens documentary requirements around beneficial ownership, source-of-funds checks, and ongoing monitoring. Each of those areas generates records that need to be captured in a form that audit trails can follow. Firms using crypto accounting software to manage client compliance data should verify that the software's data fields and export formats align with what the new manual specifies for record-keeping. Gaps in digital asset accounting software coverage can create situations where the accounting record and the regulatory file tell different stories, which is exactly the kind of inconsistency that draws examiner attention.
What Changes for CFOs of Korean Crypto Businesses
CFOs sitting inside a Korean VASP, or a group that operates one, carry a different but equally pressing set of concerns.
Budget is the first practical question. If the revised manual requires enhanced due diligence systems, additional staffing for compliance functions, or third-party technology to meet new record-keeping standards, the cost hits the current financial year. CFOs who have not yet reviewed the manual against their existing compliance spend may be carrying an unquantified liability on the operational budget.
Risk disclosure is the second. For VASPs that are subsidiaries of listed groups or that report to institutional investors, a material change in the regulatory compliance environment in a core operating jurisdiction is the kind of development that should appear in risk registers and, where applicable, periodic disclosures. The revised manual and the regulatory direction of travel it represents qualify as a material regulatory development.
Third, internal controls over financial reporting intersect with AML controls more than many CFOs appreciate. Transaction monitoring flags feed into assessments of whether certain revenues are recognisable, whether customer balances are properly classified, and whether provisions for regulatory penalties are required. A revised AML framework is therefore not purely a compliance function matter; it has financial statement implications that the CFO owns.
Practical Next Steps for Advisers and Compliance Teams
Immediate Actions
The FIU and FSS outreach sessions create a natural deadline. Any VASP that has not reviewed the revised manual before those sessions close will have missed the most direct channel for clarifying ambiguities directly with the regulators. Advisers should be pushing clients to attend and to prepare specific questions about the areas where their current compliance architecture diverges most from the new requirements.
For accounting firms, a practical first step is a gap analysis: take the revised manual section by section, map each requirement against the client's current registration file and AML documentation, and produce a clear list of items that need remediation. That document becomes both a deliverable to the client and a record that the firm exercised appropriate professional diligence.
Record-Keeping and Data Architecture
The revised manual will impose specific record-keeping obligations. VASPs and their advisers should confirm that the data captured in crypto bookkeeping software and compliance platforms covers every field the manual requires, and that retention periods are set correctly. Korean AML legislation has specific retention windows for transaction records and customer identification data; the revised manual may introduce or clarify additional categories of records that must be kept within those windows.
Where firms use digital asset accounting software to aggregate on-chain data for compliance purposes, they should verify that the software can produce outputs that map cleanly to the reporting and record-keeping formats the new manual specifies. A data format that worked under the old regime may not satisfy the new documentary standards without modification.
Ongoing Monitoring and Future Updates
Korean crypto regulation has been moving at a pace that makes a static compliance programme inadequate. The FSC has signalled, through the combination of tightened registration rules and a fully revised manual, that it views VASPs as systemically significant enough to warrant detailed, ongoing supervision. Firms advising in this space should treat the manual revision as a prompt to establish a standing process for tracking FSC, FIU, and FSS guidance updates, rather than treating each new development as a one-off project.
Frequently Asked Questions
Who does the revised VASP registration manual apply to?
The revised manual applies to all entities operating as virtual asset service providers in South Korea and required to register under the Act on Reporting and Using Specified Financial Transaction Information. This includes exchanges, custodians, and other businesses that facilitate virtual asset transactions as defined under Korean law.
What is the purpose of the FIU and FSS outreach sessions?
The Financial Intelligence Unit and Financial Supervisory Service are conducting direct outreach to VASPs to explain the content of the revised registration manual. The sessions are designed to help VASPs understand the new requirements and to reduce the risk of non-compliant filings. Attendance does not substitute for full compliance, but it does create a clear record that the regulator communicated the requirements directly.
How does the revised manual interact with Korea's travel rule obligations?
Korea's travel rule currently applies to all virtual asset transfers regardless of value following the removal of any minimum threshold. The registration manual, as part of the broader AML notification regime, is expected to require VASPs to demonstrate they have systems capable of meeting those obligations across all transfers. VASPs should review their travel rule infrastructure alongside the new manual to confirm end-to-end coverage.
Does this affect accounting firms that are not themselves VASPs?
Yes, indirectly but materially. Firms that provide compliance advisory, audit, or agreed-upon procedures services to Korean VASPs must ensure their engagement scope, procedures, and opinions reference the revised manual. Using superseded documentation as the basis for a compliance opinion creates professional liability exposure if the client is later found non-compliant with the new requirements.
What should CFOs do right now?
CFOs of businesses operating Korean VASPs should obtain the revised manual, assess the gap between current compliance infrastructure and the new requirements, estimate the cost of remediation, update risk registers accordingly, and ensure the compliance function has a clear plan to address any gaps before the FIU and FSS outreach sessions conclude. Where material, the regulatory development should be reflected in periodic risk disclosures to boards and investors.
