Key provisions of the VASP AML registration regime
The regime places virtual asset service providers inside South Korea’s AML/CFT reporting framework. The Act treats a VASP as a covered financial company category and connects virtual asset transactions to the statute’s reporting, customer due diligence, recordkeeping, and supervisory architecture. Its purpose is not to create a general crypto market conduct code; it is primarily an AML/CFT statute designed to support reporting and use of specified financial transaction information.
- KoFIU reporting before operation: A VASP, including a person intending to operate the business, must report company identity and prescribed business details to the Commissioner of the Korea Financial Intelligence Unit. Material changes also require a change report.
- Registration gatekeepers: KoFIU may refuse to accept a report where a VASP lacks information security management system certification, does not use a real-name verified deposit and withdrawal account where required, has specified disqualifying convictions, or has had a report cancelled within the statutory lookback period.
- AML duties after registration: Registered VASPs are subject to AML duties that include customer identification, suspicious transaction reporting, travel-rule obligations, and supervisory inspection. Article 8 also requires customer transaction details to be managed separately for reporting purposes.
- Foreign VASP reach: Chapter III applies to VASP financial transactions outside Korea where the activity has a domestic impact, making foreign services targeting Korean users part of the registration analysis.