CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

Korea's FSC Rules on Travel Rule, Tokenization, and Scam Liability: What Compliance Teams Must Know Now

CryptaCount Editorial · · 10 min read
AML / KYC / LICENSING Korea's FSC Rules on Travel Rule, Tokenization, andScam Liability: What Compliance Teams Must Know Now

South Korea's Digital Asset Basic Act (DABA) is still in legislative consultation, but the Financial Services Commission has not been waiting for it. Through 2026, the FSC has issued a series of binding interim rules that are already reshaping compliance obligations for virtual asset service providers (VASPs) operating in or connecting to the Korean market. A zero-threshold Travel Rule, a phased tokenized securities roadmap, and sharpened exchange accountability for scam losses are all either live or have locked-in effective dates. For compliance officers and CFOs, the relevant question is no longer what DABA might eventually require; it is what Korean law requires right now.

Korea's FSC Rules on Travel Rule, Tokenization, and Scam Liability: What Compliance Teams Must Know Now

Two-Phase Regulation: What Is Already Law

Korea's digital asset regulatory architecture runs on two tracks. The first, the Act on the Protection of Virtual Asset Users (VAUPA), took effect in July 2024 and established the current baseline. Under VAUPA, exchanges must hold customer deposits at licensed banks, segregate customer assets from proprietary funds, maintain insurance or reserves against hacking losses, and actively monitor for suspicious transactions. Market manipulation carries explicit penalties.

The Digital Asset Basic Act represents the intended second phase: a comprehensive licensing regime for digital asset service providers, issuance and disclosure rules, and market-abuse prohibitions. As of late September 2026, DABA remains under active negotiation between the government, the ruling Democratic Party, and industry participants. Current estimates place full implementation no earlier than late 2026 at the earliest, with exchange licensing applications potentially opening in Q4 2026 or early 2027 and licensing decisions running through 2027.

Where DABA Negotiations Stand

Two sticking points are holding up the bill. The FSC and the Bank of Korea disagree on who should be permitted to issue won-denominated stablecoins: one proposal would require commercial banks to hold at least a 50% stake in any stablecoin issuer. Separately, regulators have proposed capping a major shareholder's equity stake in a digital asset exchange at 20%, a cap the industry has publicly opposed. Regulators have also signalled a preference for phased rollout rather than a single implementation date, specifically to avoid market disruption.

What DABA Would Introduce When It Passes

DABA's market-entry framework operates on three tracks. Trading, brokerage, and custody businesses would require formal authorisation, with applicants needing to demonstrate cybersecurity competence, compliance infrastructure, and qualified personnel. Collective management, wallet management, and advisory businesses would sit on a lighter registration track. Order transmission and certain advisory-adjacent services would only require a notification filing, though this track would largely exclude foreign entities. A fourth mechanism under Article 90(1) of the bill would allow the FSC to designate qualifying brokers as exchanges, expanding their functions rather than creating a separate licence category.

On the issuance side, stablecoins would require full authorisation: proof of a redemption mechanism, a reserve plan, and KRW 500 million in minimum capital, with issuance restricted to domestic corporations. General digital assets would follow a lighter notification path, requiring standardised disclosures on issuer information, technical architecture, and a user protection plan. A new Trading Support Eligibility Committee would review exchange listing decisions within one month and hold power to order delistings over disclosure failures, security incidents, or user protection concerns.

Custody providers under DABA would be required to maintain user registries and hold assets under deemed-trust status, with no arbitrary restrictions on deposits or withdrawals permitted.

The Travel Rule Change: From Threshold to Zero-Floor

This is the most operationally significant near-term change, and it has a firm effective date.

Korea's Cabinet has approved amendments to the existing Travel Rule that eliminate the current KRW 1,000,000 de minimis threshold (approximately USD 707 at recent rates). The amendment takes effect on 19 February 2027. From that date, registered VASPs must collect and transmit originator and beneficiary information on every transaction, regardless of value.

Operational Implications for Compliance Teams

Under the current framework, Travel Rule data collection and transmission is triggered only when a transfer exceeds KRW 1,000,000. The amended rule eliminates that trigger entirely. This is not an incremental adjustment; it is a structural change to how transaction monitoring must be architected.

Compliance teams need to assess several things before February 2027. First, whether their current VASP-to-VASP data transmission infrastructure can handle full-volume, continuous data flows rather than threshold-triggered batches. Second, whether counterparty VASP identification processes scale to every outgoing transfer, not just larger ones. Third, whether internal data retention and audit-trail systems are capable of capturing and storing the expanded data set in a format that satisfies FSC examination requirements.

For firms running crypto accounting software or digital asset accounting software that integrates compliance data with books and records, the February 2027 change will also affect data inputs. Every transaction will now carry an associated compliance record, and that linkage needs to flow cleanly into the accounting layer. Firms that have built workflows assuming threshold-filtered data will need to revisit those integrations before the deadline.

Parallel Travel Rule tightening in other jurisdictions, including the FATF-aligned moves underway in the EU and Singapore, means this direction of travel is global. Korea is simply moving faster than most on the zero-threshold question.

Tokenized Securities: The FSC's Phased Roadmap

On 4 September 2026, the FSC announced a phased roadmap for tokenized securities infrastructure, designed to open institutional access to digital assets under defined guardrails.

What Is Already in Force

Amendments to the Capital Markets Act took effect on 3 February 2026. Those amendments extend distribution rules to investment contract securities, including fractional investment securities. That layer of the framework is live today.

What Takes Effect in February 2027

Two further changes take effect on 4 February 2027. First, OTC brokerage provisions under the Capital Markets Act will legalise multi-party OTC trading through licensed operators, replacing the previous single-buyer, single-seller structure and creating the legal basis for a secondary market in tokenized assets. Second, the Electronic Securities Act's distributed ledger-based issuance regime will come into force. This introduces legal definitions for "distributed ledger" and "distributed ledger-registered stock," giving token-form securities legal effect for the first time under Korean law. It also creates a new "issuer account management institution" system, allowing issuers to register and manage securities directly on a distributed ledger without routing through a traditional intermediary.

Phase 1 of the FSC's roadmap launches when these provisions take effect, permitting tokenization of privately pooled money market funds, institutional bonds, unlisted stocks via trust structures, and publicly offered fractional investment securities. Individual subscription access is part of the intended scope, though the precise rollout sequencing remains subject to FSC guidance.

For accounting teams, the February 2027 tokenized securities regime raises immediate classification questions. Securities issued under the Electronic Securities Act's DLT regime will carry legal status as registered securities, which distinguishes them from crypto assets held under VAUPA. That distinction will affect how they are recognised, measured, and disclosed in financial statements, whether under IFRS as applied in Korea or under internal management accounting policies. Firms advising institutional clients building exposure to tokenized Korean securities will need clear policies on these points before the regime goes live. For a broader view of how tokenization accounting challenges are emerging across jurisdictions, see our coverage of tokenization accounting implications firms need to track.

Exchange Scam Liability: Sharper Accountability for Voice Phishing

The FSC has also sharpened exchange accountability for voice-phishing and scam-related losses. Under the evolving framework, exchanges face direct responsibility where they fail to detect or prevent fraudulent transactions that exploit their platforms. This sits alongside existing capital and custody requirements under VAUPA.

Compliance and AML Implications

For AML compliance teams, this creates a specific operational requirement: transaction monitoring systems must be capable of flagging patterns consistent with voice-phishing attack vectors, not only standard suspicious transaction indicators. Korean voice-phishing schemes frequently involve rapid asset movement across multiple accounts following an initial deposit made under social engineering, a pattern that requires behavioural detection logic rather than simple rule-based screening.

This is directly relevant to the crypto accounting software and crypto bookkeeping software configurations that feed AML alert data. If the monitoring system only flags transactions above a certain value or frequency threshold, it may miss the rapid-dispersion patterns associated with scam proceeds. The FSC's accountability framework means that a missed flag can now translate into direct liability for the exchange, not simply a regulatory note. For more on how blockchain behavioural detection is being applied to these fraud patterns globally, see our article on how behavioral detection flags suspect wallets in pig-butchering scam cases.

International Context: Where Korea Sits Among Peers

Korea Blockchain Week draws compliance and institutional participants from across the Asia-Pacific region, and the FSC's interim rule-making sits within a broader regional pattern.

Singapore's Monetary Authority has continued tightening its Payment Services Act licensing requirements and expanded its Travel Rule scope. Japan's Financial Services Agency has been updating its VASP registration framework and applying FATF recommendations directly to registered operators. The United States is progressing through multiple legislative tracks, including broker reporting rules and stablecoin legislation, on a timeline that remains contested in Congress.

What distinguishes Korea's current position is the combination of a detailed pending framework (DABA) with a set of interim rules that are already operationally demanding. Compliance officers cannot defer preparation until DABA passes. The Travel Rule amendment, the tokenized securities regime, and the scam liability framework each have binding effective dates that predate any realistic DABA implementation timeline.

Korea's FSC Rules on Travel Rule, Tokenization, and Scam Liability: What Compliance Teams Must Know Now

Frequently Asked Questions

When does Korea's zero-threshold Travel Rule take effect?

The Cabinet-approved amendment takes effect on 19 February 2027. From that date, VASPs registered in Korea must collect and transmit originator and beneficiary information on every transaction, regardless of value. The current KRW 1,000,000 threshold will no longer apply.

Does the Digital Asset Basic Act need to pass before exchanges face new obligations?

No. The existing VAUPA framework already imposes binding obligations on exchanges, including asset segregation, bank custody of customer deposits, reserve or insurance requirements, and suspicious transaction monitoring. The FSC's interim rules on Travel Rule compliance, tokenized securities, and scam liability add further obligations under existing statutory authority. DABA will introduce a licensing layer on top of these, but the current framework is already operationally demanding.

How does the February 2027 tokenized securities regime affect accounting treatment?

Securities issued under the Electronic Securities Act's distributed ledger regime will carry legal status as registered securities under Korean law. This distinguishes them from crypto assets governed by VAUPA. Accounting teams will need to determine the appropriate recognition and measurement treatment under IFRS (as adopted in Korea), assess whether existing financial instrument policies cover DLT-registered securities, and confirm disclosure requirements with auditors before exposure builds. The classification question is not yet resolved by authoritative guidance, making early policy-setting essential.

What does the exchange scam liability framework require in practice?

The FSC's sharpened accountability framework means exchanges can face direct responsibility for voice-phishing and scam losses where monitoring systems failed to detect the relevant patterns. In practice, this requires transaction monitoring logic capable of identifying rapid-dispersion behaviour following initial deposits, patterns typical of social-engineering-driven fraud. Standard rule-based screens that focus on single large transactions are unlikely to be sufficient.

Is Korea's Travel Rule change consistent with FATF standards?

FATF Recommendation 16 requires jurisdictions to apply Travel Rule data collection to virtual asset transfers and sets out minimum data requirements, but it does not itself mandate a zero-threshold approach. Korea's move to eliminate the de minimis threshold goes further than the FATF baseline and aligns with the direction several jurisdictions are exploring. Firms operating across multiple jurisdictions should note that Korean compliance requirements will be stricter than FATF minimum standards once the amendment takes effect.

Source: TRM Labs

KR#stablecoinsGeneralAdoptedAML/KYC & Licensing

Related articles

AML/KYC & Licensing
Korea Overhauls Its VASP Registration Manual: What Accounting Firms and CFOs Must Assess Now
AML/KYC & Licensing
Korea Rewrites Its VASP Registration Manual: What Accounting Firms and CFOs Must Assess Now
AML/KYC & Licensing
FSC Korea Revises VASP Registration Manual: What Accounting Firms and CFOs Must Assess Now
AML/KYC & Licensing
FSC Korea Revamps VASP Registration Manual: What Accounting Firms and CFOs Must Assess Now