For a digital-asset business expanding into Asia, South Korea presents a stark paradox: one of the world's most active crypto retail markets sits behind some of the most demanding correspondent banking controls anywhere in the region. Obtaining correspondent banking access – the interbank relationships that allow a foreign or locally licensed entity to move fiat in and out of the Korean won system – is not a formality. It is a gating decision that determines whether a cross-border payments or crypto operation can function at all.
South Korea's domestic banking sector operates under the supervision of the Financial Services Commission (FSC) and the Financial Supervisory Service (FSS), which jointly administer the framework governing virtual asset service providers. Under the Act on Reporting and Using Specified Financial Transaction Information (commonly called the VASP reporting regime), any entity providing virtual asset services in or into South Korea must register with the Korea Financial Intelligence Unit (KoFIU) and, critically, secure a real-name verified bank account with a domestic licensed financial institution before that registration is complete. That second requirement – the bank account prerequisite – is the chokepoint that defeats most inbound operators before they file a single document.
This page maps the legal basis for that requirement, the process an inbound business must work through, the cross-border banking and tax interactions that follow, and the points at which outside counsel changes the outcome.
Why Correspondent Banking Access Is the Hard Problem in South Korea
South Korea's VASP regime is unusual globally because it makes a domestic banking relationship a precondition of registration, not a consequence of it. Most regimes license first and leave banking to commercial negotiation. The FSC and KoFIU position inverts that logic: without a real-name verified account (a dedicated account held by the VASP at a domestic bank, matching the VASP's registered identity), the entity cannot process client deposits and withdrawals in Korean won and cannot complete VASP registration.
Domestic banks have responded to that responsibility by applying de-risking standards that go well beyond the statutory minimum. In our practice, operators arrive having already approached multiple institutions only to receive no response or a quiet refusal after an extended diligence period. The banks apply a proprietary AML/CFT scoring model – informed by the FSC's supervisory expectations and the FATF Recommendations, including Recommendation 15 on virtual assets – and they weigh the reputational and compliance cost of holding a crypto VASP account against any commercial benefit.
The correspondent dimension compounds this. A Korean domestic bank that grants the required account may itself need to square that position with its own correspondent partners in USD clearing, EUR clearing or JPY clearing – partners that may themselves have adopted restrictive policies toward crypto-exposed counterparties. Operating without the right account and licence risks enforcement action from KoFIU, frozen settlement rails and the loss of the entire Korean market position.
The VASP Registration Framework and Its Banking Preconditions
Under the VASP reporting regime administered by KoFIU, a virtual asset business operator (VABO) must satisfy four conditions before registration is effective: ISMS (Information Security Management System) certification, a real-name verified bank account, registered capital meeting the applicable standard, and AML/CFT policies that satisfy the KoFIU compliance framework. The bank account condition is not delegable and cannot be deferred.
The ISMS certification is issued by the Korea Internet and Security Agency (KISA) and typically takes several months of preparation and audit before it is granted. The bank account condition runs in parallel – and in practice, banks will not open the account until the ISMS certification process is well advanced and the VASP can demonstrate a credible compliance programme. The sequencing matters: operators that approach banks before the compliance infrastructure is in place almost always fail at the first meeting.
For an inbound foreign business, there is an additional threshold question: whether the entity needs to establish a domestic Korean legal presence (a local corporation or branch) or whether an overseas entity can satisfy the registration conditions directly. Regulators in the leading hubs increasingly expect domestically incorporated or locally present entities when the service involves Korean-resident clients and Korean-won settlement. Working through that question early – before committing to an entity structure – materially changes the cost and timeline of the whole exercise.
How Do Domestic Banks Evaluate a VASP Account Application?
Korean domestic banks evaluate a VASP account application through a multi-stage proprietary diligence process that mirrors the FSC's supervisory expectations but is conducted by the bank's own compliance, legal and reputational risk committees. The process is not publicly documented, and banks are not obliged to give reasons for a refusal.
In our cross-border practice, the following factors consistently determine the outcome. First, ownership and beneficial ownership transparency: the bank will map the full corporate structure, identify every material shareholder and trace ultimate beneficial owners, often requiring certified translations of foreign corporate registry materials. Second, the jurisdiction of incorporation and any existing licences held: an entity licensed under a recognised regime – for instance, under the MAS Payment Services Act in Singapore, or under the FCA's MLR registration in the UK – carries demonstrably more weight than an entity with no prior regulatory history. Third, the scope of business: a pure OTC or custody operation presents a different risk profile than a retail spot exchange with high-volume retail throughput. Fourth, the AML/CFT programme itself: the bank will assess whether the VASP's transaction monitoring, Travel Rule compliance and suspicious activity reporting systems are credible, documented and tested.
The Travel Rule (the obligation to pass originator and beneficiary data with a virtual asset transfer) is a specific examination point. South Korea's implementation requires covered entities to transmit and receive the required data fields on transfers above the applicable threshold. A VASP that cannot demonstrate compliant Travel Rule infrastructure is unlikely to pass the bank's diligence, regardless of the quality of its other compliance systems.
The bank account condition means that banking diligence and regulatory registration are effectively concurrent processes. An operator that sequences them sequentially – licensing first, banking second – will typically extend its go-live timeline by many months.
CTA #1: The process above describes the standard path. Your facts – the entity structure, the user base, the product scope – change the analysis materially. To map your specific entry route before committing to an entity or a bank relationship, contact OBOLUS at info@oboluslaw.com or map your options here.
Cross-Border Banking and the Correspondent Layer
Even after a Korean domestic bank grants the real-name verified account, the correspondent banking layer introduces a second risk. Most Korean banks settle USD transactions through major US correspondent banks, EUR transactions through European clearing relationships, and USD/KRW FX through the domestic interbank market. Each of those correspondent relationships is governed by the correspondent bank's own risk appetite, which may include restrictions on crypto-related exposure.
A VASP that holds a Korean domestic account but that sends or receives cross-border wires from a crypto-exposed entity in another jurisdiction may find that individual transactions are blocked or returned by the correspondent, even where the domestic bank itself is willing to service the account. This is the layer that most operators underestimate. The Korean bank may be fully supportive; its USD correspondent may not be.
The structural response to this risk involves several levers. One is banking diversification: maintaining accounts in multiple jurisdictions so that Korean won settlement is handled locally while USD or EUR flows are routed through an entity in a more correspondent-friendly regime. Another is the use of a licensed EMI (electronic money institution) in a jurisdiction where EMI onboarding for digital-asset businesses is better developed – for instance, within the EU under MiCA-aligned supervision, or through a regulated payments entity in Singapore under the MAS Payment Services Act. The EMI provides the IBAN or account infrastructure for fiat inflows and outflows outside Korea, reducing the direct exposure of the Korean domestic account to cross-border crypto flows.
Tax interaction is a further consideration. South Korea taxes gains on virtual assets, and the applicable regime has been subject to legislative revision over several years. The interaction between a Korean-resident VASP entity, a foreign parent or holding structure, and the allocation of profit and withholding obligations requires careful structuring. We regularly advise on the tax layer as part of the entry analysis – not as a separate exercise but because the entity structure that optimises for banking access does not always optimise for tax efficiency, and the tension between those objectives needs to be resolved before incorporation.
What a Credible Entry Process Looks Like
A structured market-entry process for South Korea typically proceeds through five stages, each of which generates the documentary foundation for the next.
The first stage is a pre-entry legal and compliance audit: mapping the business model, the user base, the product scope and the existing compliance programme against the KoFIU registration requirements and the bank's expected diligence criteria. This stage surfaces gaps early – before any regulatory or banking contact – and allows the operator to address them before presenting to a bank.
The second stage is entity structuring: deciding whether to incorporate a Korean company, establish a branch, or explore whether the operator's existing structure allows it to satisfy the registration conditions directly. This decision intersects with tax, corporate governance and the operator's group structure.
The third stage is ISMS preparation: engaging a KISA-accredited certification body, preparing the technical and operational documentation, and running the pre-audit process. ISMS certification is not a legal matter in the strict sense, but the scope of systems and data that must be covered has legal implications, and the certification timetable drives the overall project plan.
The fourth stage is bank selection and approach: identifying the domestic banks that have demonstrated willingness to onboard VASPs, preparing the diligence package in the form those banks expect, and managing the bank's compliance committee process. Allied counsel in the relevant jurisdiction coordinates the local banking relationship.
The fifth stage is KoFIU registration: once the bank account is in place and the ISMS certification is complete, filing the registration and responding to any KoFIU queries. Registration does not grant a positive licence; it is a reporting obligation. But its completion is the trigger for lawful operation.
Who Actually Needs to Register in South Korea?
The perimeter of the VASP reporting regime covers entities that operate exchange services, custody services, transfer services and related virtual asset activities for Korean-resident users. An operator that has no Korean-resident users and no KRW settlement may take the position that registration is not required. In our practice, we have seen operators take that position and later discover that Korean-resident traffic was higher than their geolocation data indicated, or that a KRW payment rail was in use through an intermediary.
The threshold question – whether you are inside or outside the Korean regulatory perimeter – is not always answerable from the marketing materials alone. It requires a careful review of the actual user base, the settlement flows, any Korean-language services and the distribution channels. Operators we advise routinely find that a light-touch initial analysis missed a material exposure.
A foreign operator that is clearly outside the perimeter may still face the correspondent banking problem in a different form: its Korean banking partners or Korean institutional clients may impose their own compliance requirements as a condition of the relationship, effectively importing the KoFIU registration standard as a commercial prerequisite even where it is not strictly a legal one.
In Practice: A Cross-Border Payments Restructure
In a recent matter, a payments company with an existing EU regulatory authorisation sought to extend its operations to Korean-resident users and KRW settlement. The entity had assumed that its EU licence – obtained under a well-developed European regime – would provide sufficient comfort to a Korean domestic bank. It did not. The bank's compliance committee identified the mismatch between the EU licence scope and the Korean VASP registration requirement, and declined to open the account pending Korean registration. We advised on the dual-track approach: pursuing KoFIU registration for the Korean entity while restructuring the cross-border settlement architecture to route non-KRW flows through the existing EU entity, avoiding the correspondent banking exposure in the interim. The Korean entity secured its bank account and completed registration within the expected timeline, and the group's settlement architecture was rationalised to reflect the two-entity structure. No client funds were at risk during the transition, and the operator was able to onboard Korean institutional clients before the end of the project.
The Common Misconception: One Licence Is Enough
A common assumption in the digital-asset industry is that a single offshore or remote licence provides a compliant basis for serving clients globally, including in South Korea. That assumption is incorrect for almost every meaningful financial services regime, and it is particularly incorrect for South Korea, where the VASP reporting regime explicitly applies to entities serving Korean-resident users regardless of where the entity is incorporated.
The practical consequence is not merely a regulatory fine risk. It is a banking risk: the Korean domestic bank that the operator needs for KRW settlement will conduct its own regulatory analysis and will not open an account for an entity it believes is operating outside the registration framework. The offshore licence, in that context, is counterproductive – it signals to the bank that the operator has attempted to avoid the local regime rather than comply with it.
Regulators in the leading hubs increasingly expect operators to take a jurisdiction-by-jurisdiction compliance posture rather than a single-licence-global-reach approach. The banking community has absorbed that expectation and prices it into account decisions.
Decision Point: When to Engage Counsel
The decision point for engaging external counsel is earlier than most operators expect. By the time an operator has been refused a bank account once, the refusal is on record with the bank's compliance systems. A second approach – to the same bank or to a different one – will often surface that prior refusal in the market diligence process. First impressions in a small, tightly connected domestic banking market are durable.
Profile A: an operator with an existing EU or Singapore licence, a credible compliance programme and a clear Korean user-base rationale. The right move is a structured dual-track entry – ISMS preparation concurrent with bank selection and approach, supported by local counsel. Timeline from decision to KoFIU registration is typically measured in months, not weeks, and depends heavily on ISMS certification speed.
Profile B: an operator at the pre-entry stage with no prior regulatory history and a product that is exchange-adjacent (a hybrid custody and OTC service, for example). The entry process requires more groundwork – establishing the compliance infrastructure, potentially obtaining a preliminary regulatory authorisation in a well-regarded regime first, and then approaching Korea as the second or third jurisdiction. The additional phase adds time but materially improves the probability of a successful bank onboarding.
Profile C: an operator that has already been refused a bank account or has received a KoFIU query. The response window is short. A forensic review of what the bank's compliance committee actually saw – which requires reconstructing the diligence package and identifying the specific gap – is the first step. In our practice, a structural reason is almost always identifiable, and a route back exists, but it requires a reset rather than a resubmission of the same materials.
CTA #2: If a prior application stalled or a bank account was closed, a second read of the underlying structure can surface the reason and map the route back. Reach our banking and licensing desk at info@oboluslaw.com or start here.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – how we structure fiat rails, EMI relationships and payment licence stacks for crypto operators.
- Client-Funds Safeguarding in Mauritius – the safeguarding framework under the VAITOS Act and how it interacts with cross-border banking structures.
- EU MiCA vs. United Kingdom: Where to License a Crypto Business – a comparative analysis of the two most referenced European licensing regimes for inbound operators.
FAQ
Why do banks close crypto company accounts?
Banks close or decline to open crypto company accounts primarily because of de-risking decisions driven by AML/CFT compliance cost, correspondent banking pressure and reputational risk assessment. Most domestic banks apply a proprietary scoring model that weighs the compliance burden of holding a crypto-exposed account against the commercial value of the relationship. Where the VASP's compliance programme is undocumented, its ownership structure is opaque, or its licence status is unclear, the bank's risk committee will typically decline rather than invest in extended diligence. The refusal is rarely personal – it is systemic.
How can a VASP onboard with an EMI?
A VASP (virtual asset service provider) can onboard with a licensed EMI (electronic money institution) by presenting a complete compliance package that demonstrates AML/CFT programme quality, beneficial ownership clarity, licence status in the VASP's operating jurisdiction, and a credible business model with identified counterparties. Most EMIs that accept VASPs have a designated crypto onboarding process, which is more rigorous than their standard business account process. Enhanced due diligence, transaction monitoring agreements and volume caps are common conditions of onboarding. Engaging counsel before approaching the EMI significantly improves the quality of the submission.
What does client-money safeguarding require?
Client-money safeguarding requires a licensed entity to hold client funds in a manner that segregates them from the firm's own funds and protects them in the event of the firm's insolvency. The specific requirements – whether statutory trust, designated accounts, insurance, or a combination – vary by jurisdiction and licence type. In South Korea, the VASP reporting regime sets expectations around the segregation of client virtual assets. In EMI-regulated jurisdictions, safeguarding rules typically require client funds to be held in a segregated account with a credit institution or invested in secure liquid assets. Structuring safeguarding correctly across a multi-entity group requires jurisdiction-by-jurisdiction analysis.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – so the structure your business builds on is the one that holds. We advise crypto exchanges, custodians, token issuers and funds across more than seventy licensing jurisdictions. To discuss your situation, contact info@oboluslaw.com or message us via t.me/oboluslaw.
By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP registration requirements, banking access conditions and cross-border compliance programme design for digital-asset businesses entering Asian and European markets.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.