CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

South Korea Bill Expands FIU Powers Over Unregistered Crypto Firms

CryptaCount Editorial · · 10 min read
AML / KYC / LICENSING South Korea Bill Expands FIU PowersOver Unregistered Crypto Firms

South Korea's Financial Intelligence Unit may soon gain direct investigative authority over unregistered virtual asset service providers, bypassing a referral chain that has historically let suspected illegal operators go unpunished. A bill introduced by ten People Power Party lawmakers on 21 August 2026 would amend the Act on Reporting and Using Specified Financial Transaction Information to give the FIU powers it currently lacks: the ability to investigate alleged violations itself, file complaints with relevant authorities, and provide intelligence directly to criminal investigators. For accounting firms, auditors, and CFOs serving clients in or connected to the South Korean market, the proposal signals a tightening enforcement environment that warrants immediate attention.

South Korea Bill Expands FIU Powers Over Unregistered Crypto Firms

What the Current Law Says and Why It Falls Short

Under the existing framework, crypto companies that serve South Korean customers are required to register with the FIU. The regulator actively monitors the market and has referred suspected illegal operators to police and other investigative authorities. The problem is what happens next.

The Referral Gap in Practice

Between August 2022 and August 2025, the FIU referred 25 suspected unregistered virtual asset service providers to investigative authorities. Police suspended investigations or preliminary inquiries into 23 of those 25 cases. The companies and individuals involved were reportedly based overseas, which may have complicated jurisdictional reach, but the outcome is the same: a near-total enforcement failure on referrals originating from the FIU's own intelligence work.

As of June 2026, 28 providers held valid FIU registration. The regulator had by that point referred 40 suspected illegal operators to investigative authorities, a figure that illustrates the scale of the suspected non-compliance problem relative to the registered base. The current law gives the FIU the tools to spot violations but not the power to pursue them.

What the Proposed Bill Would Change

Lawmaker Eom Tae-young and nine colleagues have proposed adding a new provision to the Act on Reporting and Using Specified Financial Transaction Information. The bill targets the gap between detection and enforcement by restructuring who can act and how.

Expanded Investigative Authority for the FIU

The proposal would allow the FIU to investigate and analyse alleged violations of the registration requirement on its own initiative, rather than handing off a referral and waiting. It would also allow the agency to file complaints directly with relevant authorities and to request that criminal investigations be opened. In effect, the FIU would become a more active participant in enforcement rather than a passive intelligence supplier.

Public Reporting Rights

A second element of the bill is noteworthy from a compliance culture standpoint: it would allow any person to report a suspected violation to the FIU. This whistleblower-style mechanism could significantly expand the volume and variety of intelligence the FIU receives, including tip-offs from customers, counterparties, or industry participants who suspect an operator is serving Korean users without registration.

Legislative Status

The bill is at the introduction stage. It must pass the National Assembly before it can amend the existing law. No timeline for a vote has been confirmed, and the legislation could be amended, delayed, or rejected during committee review. Accounting professionals should monitor its progress, but firms advising clients with Korean user bases should not wait for Royal Assent to act.

Why This Matters for Accounting Firms and CFOs

The practical implications of this bill break down across three dimensions: client risk exposure, audit and due diligence obligations, and the systems needed to track evolving registration status.

Client Exposure to FIU Scrutiny

Any digital asset business that accepts South Korean customers and is not registered with the FIU is, under the existing law, already operating illegally. What changes under the proposed bill is the probability and speed of enforcement. If the FIU no longer has to rely on police to follow up its referrals, the lag between detection and action compresses. Clients that have been relying on the practical sluggishness of the referral process as a de facto grace period face a materially different risk profile if the bill passes.

Accounting firms should identify which clients have, or could have, South Korean user exposure. This includes exchange operators, DeFi protocols with Korean-language interfaces, NFT platforms, and asset managers offering digital asset products to Korean retail or institutional investors. Any of these could fall within the FIU's definition of a virtual asset service provider subject to registration.

Due Diligence and Audit Implications

For firms conducting AML due diligence on VASP counterparties, the Korea registration status of a counterparty becomes a more material consideration once the FIU has direct enforcement teeth. A registered-in-Korea status check should be built into onboarding workflows for any VASP with a Korean user base, not treated as a one-time exercise but as a periodic verification. See our detailed breakdown of VASP onboarding and AML due diligence: the framework financial institutions need for the broader methodology.

Auditors reviewing financial statements that include digital asset revenue streams should also consider whether management disclosures adequately reflect the regulatory risk associated with Korean market exposure. If a client generates material revenue from Korean users without FIU registration, that is a contingent liability that may require disclosure, provisioning, or at minimum a clear note in the risk section of the accounts.

CFO-Level Considerations

CFOs at digital asset businesses with cross-border operations need to assess two things. First, whether their entity is currently registered or exempt in Korea. Second, whether the proposed whistleblower mechanism creates any near-term risk of a complaint being lodged by a disgruntled customer or competitor. The public reporting element of the bill means that the enforcement funnel could widen even before the FIU deploys its own investigative resources.

Finance teams using digital asset accounting software to track revenue by jurisdiction should ensure their systems can segment Korean user revenue clearly. If enforcement escalates and the FIU demands records, having clean, jurisdiction-attributed books is far better than reconstructing transaction data after the fact. Robust crypto bookkeeping software with jurisdiction tagging is not optional for firms with meaningful Korean exposure.

How This Fits Korea's Broader Regulatory Trajectory

This bill does not arrive in isolation. South Korea has been systematically tightening its virtual asset regulatory architecture over the past several years. The FIU's registration regime for VASPs, the Act on Reporting and Using Specified Financial Transaction Information, and the more recent Virtual Asset User Protection Act together form a layered framework that is becoming more, not less, demanding.

Recent Regulatory Context

Earlier in 2026, the Financial Services Commission revised its VASP registration manual, tightening the documentation and operational requirements for firms seeking or maintaining registration. Our analysis of Korea's revised VASP registration manual covers what those changes mean for firms in practice. The proposed FIU enforcement bill sits logically alongside that revision: the FSC raises the bar for registration, and the FIU gains the powers to pursue those who don't clear it.

The 40 suspected illegal operators referred to investigative authorities as of June 2026, against just 28 registered providers, suggests the FIU already believes the unregistered segment is substantially larger than the compliant one. Lawmakers are responding to that imbalance by trying to close the enforcement gap that has allowed suspected violators to operate with relative impunity.

Cross-Border Reach

The fact that most of the 23 suspended referrals involved overseas-based companies is significant. It suggests that the current system fails precisely at the point where enforcement is hardest, against foreign operators with no local legal presence. The bill's design, giving the FIU the power to file complaints and request criminal investigations directly, may be intended partly to create a stronger paper trail that supports international cooperation requests, Mutual Legal Assistance Treaty applications, or coordination with foreign regulators. Whether that actually improves the cross-border enforcement rate remains to be seen, but the intent is clear.

Accounting and Tax Implications: What to Document Now

Regardless of whether the bill passes in its current form, the enforcement attention it reflects creates immediate obligations for well-advised firms.

Registration Status as a Financial Statement Risk Factor

Any material Korean market exposure at an unregistered VASP should be assessed for its impact on going concern judgements, contingent liability disclosures, and revenue recognition. If regulatory action could result in a forced exit from the Korean market, the revenue associated with that market may need to be treated with more caution in forward-looking estimates.

Tax Considerations for Cross-Border Operators

Korean tax rules for virtual assets have also been evolving. Firms generating income from Korean users need to be alert to permanent establishment risk if their operational footprint in Korea grows beyond what a pure digital service model would suggest. Regulatory registration, even if legally required, can sometimes be read by tax authorities as evidence of a taxable presence. Legal and tax counsel should assess this risk in parallel with the compliance question.

Using Crypto Accounting Software to Stay Ahead

Firms that use crypto accounting software capable of jurisdiction-level transaction attribution will be better placed to respond quickly if the FIU or a tax authority requests records. Ledger-level data that can be filtered by user country, transaction type, and date range is the foundation of any credible response to a regulatory inquiry. Building that capability now, before any enforcement action, is materially cheaper than reconstructing it under pressure. This is also the kind of structured record-keeping that supports a clean audit trail for any future registration application in Korea.

South Korea Bill Expands FIU Powers Over Unregistered Crypto Firms

Frequently Asked Questions

Who must register with South Korea's FIU?

Any business providing virtual asset services to South Korean customers is required to register with the Financial Intelligence Unit under the Act on Reporting and Using Specified Financial Transaction Information. This includes exchange services, wallet services, and other intermediary functions, regardless of whether the operator is based inside or outside Korea.

What does the proposed bill actually add to existing law?

The bill would give the FIU the power to investigate alleged violations itself, file complaints with relevant authorities, and request criminal investigations directly. Currently, the FIU can only refer suspected illegal operators to police and other agencies, with no guarantee those referrals are acted upon. The bill also introduces a public reporting mechanism, allowing any person to notify the FIU of a suspected violation.

Does this bill apply to overseas firms serving Korean users?

The registration requirement under existing law already applies to overseas firms that serve South Korean customers. The bill is partly a response to the failure of the current system to enforce that requirement against foreign operators. Whether expanded FIU powers will translate into effective cross-border enforcement is uncertain, but the legal obligation for overseas firms is not new.

What should accounting firms do right now, before the bill passes?

Identify all clients with Korean user exposure and verify their FIU registration status. For unregistered clients, quantify the revenue at risk and assess whether that exposure creates a contingent liability requiring disclosure. Review AML due diligence workflows to include Korean registration checks for VASP counterparties. Ensure transaction data is attributed by jurisdiction in whatever digital asset accounting software the firm uses.

Could the whistleblower provision create immediate risk even before the bill passes?

The public reporting mechanism only takes effect if the bill is enacted. However, the current law already allows individuals to report suspected violations to police or prosecutors directly. The bill would create a more structured, FIU-facing channel for such reports. Firms should not assume that the absence of an official whistleblower mechanism means no one is reporting them today.

Source: Cointelegraph

KRGeneralProposedAML/KYC & Licensing

Related articles

AML/KYC & Licensing
South Korea to Bring Digital Assets Under State Asset Management: What Accounting Firms and CFOs Must Act On Now
AML/KYC & Licensing
BitGo Korea Secures VASP Registration Ahead of Stricter Entry Rules
AML/KYC & Licensing
South Korea Blocks Polymarket: What the Illegal Gambling Ruling Means for Accounting Firms and CFOs
AML/KYC & Licensing
Korea Overhauls Its VASP Registration Manual: What Accounting Firms and CFOs Must Assess Now