South Korea Removes Crypto Travel Rule Threshold: What Accounting Firms and CFOs Must Assess Now
South Korea has eliminated the 1 million won (roughly $700) minimum that previously allowed small crypto transfers to bypass Travel Rule data-sharing requirements. Every transfer between registered virtual asset service providers (VASPs) will now carry full sender and recipient information obligations, regardless of value. The Cabinet has passed amendments to the Enforcement Decree of the Act on Reporting and Using Specified Financial Transaction Information, and the expanded Travel Rule provisions will take effect six months after promulgation. For accounting firms, auditors, and CFOs with clients operating in or transacting with Korean crypto markets, the compliance surface has widened materially overnight.
What the Decree Actually Changes
The threshold is gone entirely
Under the previous framework, only transfers at or above 1 million won triggered Travel Rule obligations between registered VASPs. That floor is being removed. The Financial Intelligence Unit (FIU) was explicit about its reasoning: the threshold created a straightforward structuring opportunity. The FIU cited one documented case where a user deposited approximately 200 million won into a crypto exchange and then executed 216 separate USDT withdrawals, each kept just below the 1 million won limit, to avoid triggering data collection. Removing the threshold closes that gap entirely.
Receiving platforms take on new obligations
The amendments place affirmative duties on receiving VASPs, not just sending platforms. Receiving platforms must now collect both sender and recipient information. Critically, if required data is missing, the platform may request it and is permitted to reject the transaction if the information is not provided. This shifts AML gatekeeping responsibilities downstream in the transfer chain and means that receiving platforms can no longer accept transfers passively and resolve data gaps after the fact.
The New Framework for Overseas Exchanges and Personal Wallets
Perhaps the most operationally complex part of the decree is its treatment of transfers that touch overseas crypto exchanges or self-hosted (personal) wallets. South Korean authorities noted that suspected money laundering involving these channels has been increasing as gaps in the existing AML framework were identified. The new rules create a tiered approach.
Tiered risk-based controls
Registered local VASPs must now make an affirmative determination, based on counterparty risk, about which transfers they will permit. Transfers to overseas exchanges assessed as low-risk will generally be allowed. Transfers involving other foreign exchanges and personal wallets will generally be permitted only when the sending and receiving parties are confirmed to be the same individual. This is a meaningful constraint: it effectively limits outbound transfers to personal wallets to self-transfers that can be evidenced, and requires VASPs to have a documented risk-assessment process for each foreign counterparty.
Suspicious transaction monitoring at 10 million won
Each registered VASP must now build and operate its own suspicious transaction monitoring system specifically covering transfers of at least 10 million won that involve foreign exchanges or personal wallets. This is not a discretionary enhancement. It is a mandatory infrastructure requirement, and it sits alongside the broader VASP registration standards that are also being tightened under the same decree.
Strengthened VASP Registration Requirements
The decree does not stop at transfer rules. It also raises the bar for VASP registration itself, extending scrutiny to financial health, internal controls, staffing levels, technical infrastructure, and major shareholders. The registration provisions take effect on 20 August 2026. Existing registered providers benefit from a one-year transition period to meet some of the new financial, staffing, infrastructure, and internal control standards, but the registration changes themselves are not deferred.
For accounting firms advising clients who hold or are seeking VASP registration in Korea, the expanded criteria mean that compliance assessments now need to cover a broader set of organisational and governance factors, not just the AML policies that have historically been the primary focus. The FSC Korea VASP registration tightening before August 2026 outlined earlier requirements that this decree now builds upon, so the two sets of obligations need to be read together.
Accounting and AML Implications for Firms and CFOs
Transaction data completeness is now a hard requirement
Any client that operates as a Korean VASP or routes transfers through Korean platforms needs to treat sender and recipient data fields as mandatory, not best-effort. The permission to reject transactions for missing data will be exercised. Firms reviewing their clients' transaction records using crypto accounting software should build validation checks that flag incomplete counterparty data, because a rejected transfer also generates an accounting event that needs to be recorded and explained.
The foreign-wallet and overseas-exchange risk tier needs documentation
For CFOs and finance teams at Korean VASPs, the requirement to classify each overseas exchange counterparty by risk level is a new governance task. It needs to sit in a written policy, be reviewed periodically, and be defensible to the FIU on request. Transfers to personal wallets require evidence that the sender and recipient are the same person, which means the verification workflow needs to be designed, documented, and logged in a way that your digital asset accounting software can surface during an audit.
Suspicious transaction monitoring infrastructure
The 10 million won monitoring threshold for foreign-exchange and personal-wallet transfers is a systems requirement. Firms advising Korean VASPs should assess whether current transaction monitoring tools can apply a separate rule set for this specific transfer category. If the monitoring logic is embedded in a general AML system, it may need reconfiguration to isolate these transfers and generate the right alerts. This is also an audit consideration: auditors will want to see evidence that the monitoring system is operating and that alerts are being investigated and documented.
The six-month window is shorter than it looks
Six months from promulgation sounds like a comfortable runway. In practice, for a firm that needs to redesign data-collection workflows, update counterparty risk classifications, and build or reconfigure a transaction monitoring system, it is tight. Accounting teams should map the implementation tasks against the effective date now and flag any dependencies on technology vendors or regulatory guidance that could compress the timeline further.
The FSC Korea crypto enforcement actions from earlier this year demonstrate that Korean regulators are prepared to act against VASPs that fall short of AML standards. The decree signals that the enforcement posture is not softening.
Practical Next Steps for Accounting Firms and CFOs
Immediate actions before the effective dates
First, identify all clients with Korean VASP registration or material transfer volumes through Korean platforms. Second, map those clients' current Travel Rule data-collection processes against the new zero-threshold requirement and identify where data gaps exist. Third, assess whether each client has a documented counterparty risk-classification process for overseas exchanges, and draft or update that policy. Fourth, review the 10 million won monitoring requirement and confirm that current systems can apply it. Fifth, for clients pursuing or holding VASP registration, update the compliance assessment to reflect the new registration standards taking effect on 20 August 2026.
Crypto accounting software used to support Korean clients should be reviewed for its ability to capture counterparty metadata at the transaction level, because that data is now a regulatory asset, not just an operational detail.
Frequently Asked Questions
When does the expanded Travel Rule take effect?
The expanded Travel Rule and other transfer-related AML requirements take effect six months after the decree is promulgated. The VASP registration provisions take effect on 20 August 2026, with a one-year transition for some financial, staffing, infrastructure, and internal control standards for existing providers.
Does the zero-threshold apply to transfers involving personal wallets?
The zero-threshold on Travel Rule data collection applies to transfers between registered VASPs. Transfers involving personal wallets and overseas exchanges are handled under a separate tiered risk framework: they are generally permitted only when the sender and recipient are confirmed to be the same person, and they are subject to the new suspicious transaction monitoring requirement at 10 million won.
What must receiving VASPs do differently under the new rules?
Receiving VASPs must affirmatively collect sender and recipient information on all incoming transfers. If required data is missing, they may request it and are permitted to reject the transaction if it is not provided. This is a change from a model where receiving platforms played a more passive role.
How should a firm document the counterparty risk-classification process?
The decree requires registered VASPs to make risk-based determinations about which transfers to permit, particularly for overseas exchange counterparties. That determination should be recorded in a written policy, applied consistently, and logged at the transaction level. The classification criteria, the review frequency, and any exceptions should all be documented and available for regulatory inspection.
Is the 10 million won monitoring threshold a new reporting obligation to the FIU?
The decree requires VASPs to establish suspicious transaction monitoring systems for transfers of at least 10 million won involving foreign exchanges or personal wallets. The monitoring system must identify and flag suspicious activity. Whether a flagged transaction then generates a suspicious transaction report to the FIU depends on the outcome of the investigation, consistent with existing reporting obligations under Korean AML law.
Source: Cointelegraph
