EST · MMXXVI
Home/Jurisdictions/Digital-Asset Licensing in South Korea: What Businesses Need to Know
Licensing & Registration

Digital-Asset Licensing in South Korea: What Businesses Need to Know

Digital-Asset Licensing in South Korea: What Businesses Need to Know. Cross-border digital-asset legal counsel for business – licensing, disputes and structurin

Digital-Asset Licensing in South Korea: What Businesses Need to Know

Operating a virtual asset service provider (VASP) in South Korea without completing the required registration exposes a business to enforcement action, account termination by domestic banks, and potential criminal liability for its principals. South Korea's Act on Reporting and Using Specified Financial Transaction Information – commonly called the Special Financial Information Act (SpecFI Act) – brought all virtual asset exchanges, custodians, brokers and transfer agents under a mandatory reporting and registration regime administered by the Financial Intelligence Unit (FIU) of the Financial Services Commission (FSC). That regime has since been reinforced by the Virtual Asset User Protection Act, which entered force in 2024 and added investor-protection obligations on top of the baseline AML/registration requirements. For any business targeting South Korean users, holding South Korean client assets, or simply routing transactions through South Korean banking, a clear-eyed assessment of the registration obligation is the starting point – not an afterthought.

This page maps the regulatory regime, explains who needs to register and what the process involves, addresses the cross-border complications that most inbound operators underestimate, and sets out how OBOLUS supports businesses at each stage of that process.

The Regulatory Regime: FSC, FIU and the Dual-Track Framework

South Korea's digital-asset regulatory architecture rests on two legislative pillars that operate together, not as alternatives. The SpecFI Act establishes the foundational VASP reporting and registration requirement: any entity carrying on specified virtual asset business in Korea must register with the FIU and meet AML/CFT conditions as a precondition. The Virtual Asset User Protection Act then layers on obligations around asset segregation, cold-storage requirements, reserve management, prohibited trading practices and civil liability to users. Together, they create a regulatory perimeter that is narrower in some respects than the EU's MiCA regime – it is predominantly conduct and AML-driven, not a full prudential authorisation – but it is enforced with notable firmness.

Oversight sits with the Financial Services Commission at the policy level and the FIU at the transactional and reporting level. The FSC retains authority over the broader financial-system classification of virtual assets, and the Financial Supervisory Service (FSS) conducts on-the-ground inspection of licensed entities. Inbound operators must therefore track three separate agencies. That architecture differs meaningfully from, say, the UAE's VARA model (a single activity-based regulator) or Singapore's MAS (a unified Payment Services Act regime). South Korea's layered structure means a single compliance breach can trigger parallel FIU, FSS and FSC consequences simultaneously.

In our licensing practice, we consistently see inbound operators underestimate the FSS inspection dimension. Registration with the FIU does not close the compliance file; it opens the supervisory relationship.

Who Needs to Register in South Korea?

Any entity that exchanges virtual assets for fiat currency or other virtual assets, stores or manages virtual assets on behalf of third parties, or facilitates virtual asset transfers must register under the SpecFI Act.

The registration obligation attaches to the activity, not to the corporate domicile. A Cayman-incorporated exchange that actively markets to South Korean residents, settles transactions denominated in Korean Won, or operates an app available to Korean users is squarely within the perimeter. The FIU has made clear that substance-over-form analysis applies: using a foreign entity with a local sales operation does not avoid the obligation.

In our cross-border practice, this is one of the most common structural errors we encounter. An operator incorporates an exchange vehicle in a well-regarded offshore seat – the BVI FSC or Cayman CIMA – and assumes that entity's registration is sufficient for its Korean user base. It is not. The SpecFI Act's extraterritorial reach means any meaningful engagement with the Korean market triggers a registration analysis. The only defensible position is a formal legal opinion on nexus, followed by a registration filing if nexus is present.

To understand whether your current structure creates a Korean registration exposure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard registration path. Your facts – the entity, the user base, the banking – change the analysis.

What Are the Registration Conditions Under the SpecFI Act?

To register as a VASP under the SpecFI Act, an entity must satisfy four threshold conditions simultaneously: it must hold a valid Information Security Management System (ISMS) certificate issued by the Korea Internet and Security Agency (KISA); it must maintain a real-name verified bank account with a Korean domestic bank; its representatives and major shareholders must pass a negative-history screening; and it must demonstrate an AML/CFT program that meets the FIU's requirements, including appointment of a compliance officer and implementation of the Travel Rule (the FATF obligation to pass originator and beneficiary data with virtual asset transfers).

The ISMS certification condition is the single greatest practical obstacle for inbound operators. KISA audits the applicant's information security controls across a scope that includes physical infrastructure, access management, incident response and cryptographic key management. For an entity without domestic IT infrastructure, meeting the ISMS standard requires either establishing a genuine Korean operational presence or structuring through a local entity that already holds or is pursuing certification. The audit cycle alone takes a material amount of time, and the certification must be in place before the FIU registration can complete.

The real-name banking requirement is equally demanding. Domestic Korean banks – under FSS guidance – conduct their own enhanced due-diligence review of VASP applicants before agreeing to provide the required dedicated virtual-asset accounts. In practice, a small number of banks actively service VASPs, and their appetite has varied considerably across market cycles. An operator that cannot secure a banking partner cannot register. Banking relationship-building therefore runs in parallel with, not after, the legal registration process.

How Does the Virtual Asset User Protection Act Change the Picture?

The Virtual Asset User Protection Act, which entered force in 2024, materially extends the compliance obligations of a registered VASP beyond the baseline AML/registration layer.

Its core obligations include: mandatory segregation of user assets from the operator's proprietary assets, with at least a defined proportion of user assets held in cold storage; requirements to maintain a reserve fund against operational losses; a prohibition on using user assets for the operator's own purposes; and specific obligations around market manipulation, insider trading and unfair trading practices in virtual assets. The Act also creates a direct civil-liability mechanism: users can sue for losses caused by the operator's breach of its obligations, without needing to show fraud.

For operators accustomed to lighter regimes, these obligations represent a qualitative shift. The cold-storage and segregation rules impose genuine operational cost. The civil-liability provision means that a compliance failure is not merely a regulatory event but a litigation exposure. In our practice, we advise operators entering South Korea to model the operational cost of the User Protection Act requirements at the same time as they model the registration path – they are inseparable from a business-planning perspective.

The Act also grants the FSC and FSS enhanced supervisory powers, including the authority to request data and conduct inspections on shorter timelines than before. Registered VASPs should expect a more active supervisory relationship than the FIU-registration framing might initially suggest.

The Cross-Border Reality: Where the Entity Sits Versus Where the Users Are

South Korea's approach to cross-border VASP activity is one of the most assertive in Asia. The jurisdictional reach of the SpecFI Act is anchored to the activity and the user, not the corporate seat. That creates a specific problem for operators structured in the major offshore or mid-shore licensing hubs.

An entity licensed under Singapore's MAS Payment Services Act, for example, holds a legitimate VASP authorisation in one of Asia's most respected regimes. But that Singapore licence does not confer any standing in South Korea. If the same entity serves Korean users, it must separately register under the SpecFI Act. The same logic applies to a VARA-licensed Dubai entity, a BVI-registered VASP, or a MiCA-authorised EU operator. Each jurisdiction addresses its own perimeter; none grants passporting rights into Korea.

This multi-licence reality is not merely theoretical. In our cross-border licensing practice, operators we advise routinely maintain parallel registrations in three or more jurisdictions to support a genuinely global user base. The Korean stack – FIU registration, ISMS certification, domestic banking, Travel Rule compliance and User Protection Act obligations – represents one of the more demanding layers in that stack. Operators building an Asia-Pacific presence typically must decide whether to register directly in Korea, to geo-restrict Korean users (with the compliance complexity that entails), or to structure through a joint venture with an entity that already holds ISMS certification and banking access.

Tax and banking interactions add a further dimension. Korean-source income may be subject to corporate tax obligations even for foreign entities if a permanent establishment is deemed to exist – and operating a Korean-facing VASP with local infrastructure creates a credible permanent establishment argument.

The Travel Rule in South Korea: What Operators Must Implement

South Korea implemented the Travel Rule – the FATF Recommendation 15 obligation to attach originator and beneficiary information to virtual asset transfers – through the SpecFI Act regime, with the FIU as the supervising authority.

Registered VASPs must transmit originator name, account identifier and transaction details alongside transfers above the applicable threshold. Where both the sending and receiving institution are Korean VASPs, the data exchange must occur through a designated Travel Rule solution. The two principal Travel Rule solutions operating in the Korean market are operated by industry-led consortia, and VASPs are expected to integrate with a solution prior to commencing business, not after.

The cross-border Travel Rule interaction – where a Korean VASP sends to or receives from a foreign VASP – presents the greater compliance challenge. Many jurisdictions have implemented Travel Rule obligations on different timelines and with different technical standards. A Korean registered VASP sending to a counterpart in a jurisdiction that has not yet implemented the Travel Rule must apply its own risk-based approach to the gap. Regulators in the leading hubs increasingly expect documented policies on that gap, not silence.

In our practice, we advise operators to treat Travel Rule integration as a pre-launch requirement, not a post-launch remediation task. The FIU has been active in enforcement in this area. A VASP that commences operations without operational Travel Rule compliance risks both a supervisory notice and jeopardising its banking relationship.

How South Korea Compares for an Inbound Operator

South Korea offers genuine commercial opportunity – a large, technically sophisticated retail and institutional market with deep liquidity – but it is not a light-touch jurisdiction for operators. The registration barrier is high by regional standards, particularly because of the ISMS certification requirement and the domestic banking condition. For context:

Singapore's MAS regime under the Payment Services Act is broadly comparable in ambition but processes applications through a single regulator, MAS, without a parallel ISMS-certification requirement from a separate government agency. Hong Kong's SFC VATP licensing regime is demanding on capital and governance but operates within a single regulatory window. VARA in Dubai is activity-based and sector-specific but similarly avoids the dual-agency complexity of Korea's FIU-plus-KISA structure.

For an inbound operator, the decision matrix typically looks like this. An operator with an existing Korean corporate entity, domestic IT infrastructure, and a relationship with a major Korean bank is well-positioned to pursue FIU registration as a primary market entry. The ISMS audit can proceed in parallel with the legal preparation work, and the banking condition is less of an obstacle when the relationship pre-exists the application.

An operator entering Korea from scratch – a foreign-incorporated entity without domestic infrastructure – faces a materially longer and more expensive path. In that profile, a joint-venture or white-label structure with an existing Korean VASP, or a phased approach in which Korean users are geo-restricted pending registration, may be the more rational first step. We map these options, including their respective banking and tax implications, before operators commit capital to either path.

A common assumption we encounter is that an offshore licence – a BVI FSC registration, a Cayman CIMA filing – is sufficient to serve a global user base, including Korean users. It is not. The SpecFI Act's activity-based jurisdiction means that where your users are located is the determinative question, not where your legal entity sits. Operating on the basis of a single offshore registration while actively serving Korean users is one of the clearest enforcement risks in the Korean digital-asset market today.

If a prior application stalled, a banking relationship was declined, or you need a second opinion on your current Korean structure, write to OBOLUS at info@oboluslaw.com. A structural read can surface the specific pressure point and the path forward.

A Recent Matter: Resolving a Korean Registration Gap

In a recent licensing matter, a well-capitalized exchange operator – licensed under an Asian VASP regime and serving a global user base – discovered that its Korean user cohort had grown to a level that created an unambiguous SpecFI Act registration obligation. The operator had not registered, had no ISMS certification, and had no domestic banking relationship. We were engaged to conduct a rapid nexus analysis, map the three-track registration path (legal preparation, KISA engagement, banking relationship development), and advise on a compliant geo-restriction protocol for the interim period while registration was being pursued. The matter resolved with a structured registration engagement underway and the operator's Korean user cohort properly documented and reported within the applicable AML timelines. The key lesson: a registration obligation does not become smaller or more manageable by being deferred.

When Should You Engage Counsel on Korean VASP Registration?

Engaging counsel at the earliest stage of Korea market entry – before a corporate structure is committed, before a bank is approached, before users are onboarded – produces materially better outcomes than engaging after a problem has crystallized.

The reasons are structural. The ISMS certification must be in place before registration completes; starting that process early determines the entire timeline. The banking relationship must be secured before registration can proceed; banks conduct their own due diligence, and a well-prepared legal package materially improves that process. The User Protection Act obligations must be built into the product from launch, not retrofitted.

Conversely, operators who engage counsel after receiving an FIU enforcement notice, after a bank declines to provide virtual-asset accounts, or after a compliance gap is identified in a supervisory inspection are managing a crisis rather than a process. The regulatory costs, the management distraction and, in some cases, the risk to the operator's principals are significantly higher in that posture.

Regulators in the leading hubs increasingly expect operators to demonstrate genuine compliance readiness, not paper registration. South Korea's FSS, in particular, conducts post-registration inspections that probe the depth of the compliance program, not merely its existence. An operator that registered but did not build a genuine AML/CFT and User Protection Act compliance program will encounter that gap during inspection.

In our licensing practice, we regularly advise on the sequencing of ISMS, banking, and legal registration tracks, and on the self-assessment tools operators can use to benchmark their compliance readiness against FIU and FSS expectations before those expectations are tested by a supervisory event.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

In South Korea, the timeline for VASP registration under the SpecFI Act is primarily determined by the ISMS certification process conducted by KISA, which typically takes a material number of months, and by the time required to secure a domestic real-name banking relationship. Both tracks run in parallel with the legal preparation work. Other jurisdictions – Singapore, Malta, Lithuania – vary considerably. In our practice, we map the realistic timeline at the outset so that operators can plan product launch and banking around it, rather than discovering a gap after commitments have been made.

Which jurisdiction is best for licensing my crypto business?

There is no single best jurisdiction: the optimal licence stack depends on where your users are, the activity you conduct, your banking needs, and your tax and structuring preferences. South Korea is a high-barrier but commercially significant market for Asia-Pacific operators. Singapore, Dubai, Malta, and the BVI offer different combinations of access, cost, speed and regulatory recognition. A business serving Korean users cannot substitute any of those regimes for direct Korean FIU registration. We map the licence, banking and tax stack across the relevant jurisdictions before operators commit to a structure.

Do I need a separate custody licence?

In South Korea, custody of virtual assets on behalf of third parties falls within the SpecFI Act's definition of a VASP activity, so a standalone custodian must register under that regime. The Virtual Asset User Protection Act adds segregation and cold-storage obligations that specifically address custody risk. In other jurisdictions – the EU under MiCA, Singapore under the Payment Services Act, Hong Kong under the SFC VATP regime – custody is addressed as a distinct regulated activity with its own conditions. Whether a separate custody licence is required, or whether custody is covered under a broader VASP or exchange authorisation, turns on the specific activity scope and the jurisdiction's treatment of it.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – so that the registration path, the banking relationship and the compliance program are built together, not sequenced against each other. We also work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications where disputes arise. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in VASP registration strategy for inbound operators across the Asia-Pacific region, with particular focus on multi-track licensing processes that combine regulatory, banking and compliance workstreams.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours