Operating a crypto exchange in South Korea without proper regulatory authorisation is one of the fastest routes to enforcement action in the Asia-Pacific region. The Financial Intelligence Unit of Korea – the Korea Financial Intelligence Unit (KFIU) – sits within the Financial Services Commission (FSC) and administers a mandatory VASP (virtual asset service provider) registration regime that applies to any business offering virtual-asset trading, custody or transfer services to persons located in Korea. For an inbound business, the question is not whether the regime applies – it almost certainly does – but whether the business can satisfy the conditions before it opens a single trading pair.
This page maps the legal basis, the process, the cross-border complications, and the decision points a board needs before committing capital to a Korean market entry.
What Does the Korean VASP Regime Actually Cover?
The Korean regime captures a broader set of activities than many operators expect. Under the Act on Reporting and Use of Specific Financial Transaction Information (commonly called the Specific Financial Information Act, or SFIA), any business that conducts virtual-asset sales and purchases, exchanges between virtual assets, transfers of virtual assets, safekeeping and administration of virtual assets, or brokerage services in any of those activities must register with the KFIU. The definition follows the FATF Recommendation 15 model: substance governs, not the marketing label. A platform calling itself a "token swap aggregator" or a "DeFi front-end" is not automatically outside the perimeter; the functional analysis determines whether registration is required.
Notably, the regime applies on a territorial basis with an extraterritorial effect that catches foreign operators actively soliciting or serving Korean users. In our cross-border practice, we have seen platforms assume that incorporation outside Korea insulates them from Korean law. It does not. If the platform is marketed in the Korean language, if Korean payment methods are integrated, or if the user base is substantially Korean, the KFIU takes the position that the activity is occurring in Korea and registration obligations follow.
The FSC has made clear that operating without registration is a criminal offence, not merely a civil regulatory breach. Enforcement action can include criminal referral, operational shutdown orders and the freezing of Korean banking relationships – which for most exchanges means an immediate halt to fiat on-ramps and off-ramps.
Who Must Register – and What Is the ISMS Certification Condition?
Registration is mandatory for every business that falls within the SFIA's VASP definition and that has a commercial nexus to Korea. There is no de minimis threshold tied to transaction volume or user count in the publicly stated registration conditions; the trigger is the activity itself. The two foundational pre-conditions that the KFIU applies before accepting a registration application are the requirements that have caused the most difficulty for inbound businesses.
First, the VASP must hold a valid ISMS (Information Security Management System) certification, issued by the Korea Internet and Security Agency (KISA). This certification is substantive. It requires the applicant to demonstrate that its systems meet a defined set of information-security controls across its technology infrastructure, and the assessment process typically runs for several months before a certificate is issued. For a business that has not yet built Korean-market infrastructure, obtaining the ISMS certification is usually the longest single item on the critical path.
Second, the VASP must maintain a real-name verified bank account – called a real-name account – with a Korean bank that itself holds an ISMS certification. The bank opens the account only after completing its own due diligence on the exchange, which in practice mirrors a full AML/CFT onboarding of the business as a counterparty. Korean banks have been restrictive in opening these accounts, particularly for foreign-controlled entities. The banking condition is not administrative; it is a genuine gatekeeper. Without a real-name bank account, the registration cannot be completed, and fiat settlement cannot lawfully occur.
In addition, the VASP must maintain an AML/CFT programme aligned with FATF standards, appoint a designated compliance officer, and report to the KFIU on suspicious transactions and cross-border transfers. The Travel Rule (the obligation to pass originator and beneficiary information with a virtual-asset transfer) applies above the applicable threshold set by Korean regulation, consistent with FATF Recommendation 15.
For a scoped assessment of your Korea market-entry structure, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the banking jurisdictions – change the analysis materially. Map your options.
What Does the Registration Process Involve – and How Long Does It Take?
The KFIU registration process has several distinct phases, and the overall timeline depends heavily on how early the applicant begins the ISMS certification and banking workstreams. The two run in parallel rather than sequentially, but both must be completed before the registration file is submitted.
The ISMS certification process involves a gap analysis, remediation, and a formal assessment by KISA. For a business deploying fresh infrastructure in Korea, the assessment cycle generally spans a meaningful number of months. For a business that already operates internationally with mature information-security controls, the timeline may be shorter, but the assessment still covers Korean-specific requirements and cannot be substituted by a foreign ISO 27001 or SOC 2 certification alone.
The banking workstream runs concurrently. The applicant approaches a Korean bank – one that itself holds ISMS certification – and undergoes a due diligence process that covers corporate governance, beneficial ownership, the AML programme, source-of-funds documentation and the business model. Banks vary in their appetite for this type of client relationship. Some have paused new account openings for exchanges entirely at different points in recent years; others are open to the right applicant profile. The selection of the banking partner and the preparation of the diligence package is a determinative element of the overall timeline.
Once ISMS certification is in hand and a real-name account has been confirmed, the KFIU registration application itself is submitted. The KFIU reviews for completeness and compliance. Deficiencies result in requests for additional information, which extend the timeline. There is no publicly stated clock for KFIU review; applicants should plan for a period of weeks to months depending on the complexity of the application.
In aggregate, a well-prepared applicant who begins the ISMS and banking workstreams simultaneously should plan for a total process that spans the better part of a year. Poorly prepared applications – particularly those where the AML programme is incomplete or beneficial-ownership documentation is unclear – take materially longer. In our practice, we have seen Korea market-entry projects that stalled for extended periods because the banking workstream was not started early enough and the exchange had to restart with a second bank after the first declined.
How Does Entity Structure and Cross-Border Tax Interact With a Korean Operation?
Korea market entry rarely happens in isolation. Most exchanges entering Korea already operate under a licence or registration in another jurisdiction – MiCA in the EU, the Singapore Payment Services Act regime administered by MAS, or the SFC's VATP regime in Hong Kong. The Korean VASP registration does not replace those and is not recognised as equivalent to them. Each jurisdiction's obligations run in parallel.
The entity question matters. A Korean subsidiary or branch of a foreign holding company can apply for VASP registration, but the KFIU and the banking partner will look through to the ultimate beneficial owners and the parent group's regulatory standing. A group with enforcement history or pending investigations in another jurisdiction will face elevated scrutiny. An entity that sits behind a layered offshore structure without clear beneficial-ownership disclosure will struggle to satisfy the banking diligence threshold.
From a tax perspective, operating through a Korean entity triggers Korean corporate income tax obligations and, depending on the business model, Korean VAT considerations. The Korean National Tax Service takes an active interest in the tax treatment of virtual-asset transactions. Gains on virtual-asset disposals by individuals are taxed under Korean law, and while the corporate tax treatment of exchange revenues is governed by general corporate tax principles, specific issues around token inventory, trading gains and fee income benefit from early structuring attention. Cross-border intercompany flows – management fees, technology licences, intra-group funding – must be structured at arm's length under Korean transfer pricing rules.
Banking for Korean operations runs through the real-name account for fiat settlement, but the exchange's treasury management, cold-wallet custody and liquidity reserves will typically sit in a combination of the Korean banking relationship and international accounts held through the group structure. Korean foreign exchange regulations apply to cross-border capital flows, and the reporting obligations for significant cross-border transactions are separate from the KFIU reporting requirements.
What Are the AML, Travel Rule and Ongoing Compliance Obligations?
The Korean AML regime for VASPs is enforced by the KFIU under the SFIA framework and aligns closely with the FATF standards that most leading jurisdictions have adopted. The obligations are ongoing from the date of registration and are not satisfied by a one-time filing.
The compliance programme must cover customer due diligence (CDD) and enhanced due diligence (EDD) for higher-risk relationships, transaction monitoring, suspicious transaction reporting (STR) and currency transaction reporting (CTR) above the applicable threshold. The Travel Rule applies to virtual-asset transfers above the applicable Korean threshold, requiring the originating VASP to pass originator name, account and transaction information to the beneficiary VASP. Korean-registered VASPs must use a Travel Rule solution that is capable of exchanging data with counterparty VASPs globally. This has practical implications for which solution a business deploys – interoperability with the protocols used by the major Korean exchanges already in the market is a practical necessity.
The KFIU conducts examinations of registered VASPs. Deficiencies identified in an examination can lead to corrective requirements, supervisory measures or, in serious cases, referral for criminal investigation. The compliance officer appointed at registration carries personal accountability in the Korean legal framework. The appointment is not a formality; regulators expect the compliance officer to be a substantive decision-maker with access to transaction data and the authority to file reports independently.
How This Works in Practice: An Inbound Exchange
In a recent licensing matter, a digital-asset exchange incorporated outside Asia sought to enter the Korean market and began preparing a VASP registration application. The operator had an existing licence in a major EU jurisdiction under the prior national VASP regime and assumed that regulatory standing in Europe would accelerate the Korean process. We were engaged to review the structure and advise on the registration pathway. Our assessment identified two gaps immediately: the ISMS certification process had not been started, and the operator had approached a Korean bank that had, at that time, paused new exchange account openings. We redirected the banking workstream to a second institution that remained open to the applicant's profile and began the ISMS readiness work in parallel. The application was ultimately submitted on a timeline that met the operator's commercial opening date. The experience illustrates a consistent pattern: the legal framework in Korea is navigable for a well-prepared business, but the banking condition and the ISMS timeline require early and concurrent action, not sequential completion.
What Are the Most Common Mistakes Inbound Businesses Make?
In our cross-border licensing practice, we see a repeating set of errors from businesses attempting Korean market entry without adequate preparation. The first – and most costly – is treating the real-name bank account as a downstream step. Every item on the KFIU registration checklist can be prepared in parallel with the banking workstream, but the bank account is often the longest gating factor and should be initiated before any other element of the application is begun.
The second common mistake is conflating the ISMS certification with an existing international information-security accreditation. KISA applies Korean-specific assessment criteria. Businesses that have invested in ISO 27001 or comparable certifications for their international operations find that those investments are relevant background but not a substitute. The KISA assessment must be completed independently.
A third error is structuring the Korean entity to minimise tax without adequate consideration of how that structure reads to a Korean bank during AML diligence. A holding structure that makes commercial sense from a corporate-tax perspective may present beneficial-ownership disclosure challenges that the bank cannot resolve. The two workstreams – tax structuring and banking diligence – must be reviewed together before the structure is finalised.
A common assumption among operators is that a single offshore VASP registration or licence is sufficient to serve Korean users legally. That is not correct. The Korean regime applies to activity directed at Korean users regardless of where the operating entity is incorporated. Running Korean-language marketing from a foreign entity without Korean VASP registration exposes the business to the criminal sanctions the SFIA prescribes for unregistered activity.
If a prior Korean market-entry attempt stalled or a banking relationship was declined, a structural review can surface the reason and the route forward. Write to OBOLUS at info@oboluslaw.com or Map your options.
Is a Korea Entry the Right Decision for Your Business Profile?
Korea is one of the highest-volume retail crypto markets in the world. The concentration of trading activity among a small number of domestic exchanges, the strong local banking infrastructure, and the high level of consumer familiarity with digital assets make it a commercially significant market. The cost of entry – in time, compliance infrastructure and banking relationship-building – is also among the highest in the Asia-Pacific region. The decision is not simply a legal one.
For a business with an established operating base in Singapore, Hong Kong or Japan, a Korean subsidiary adds a separately licensed, separately banked, ISMS-certified layer to the group structure. The compliance overhead is real and ongoing. The Specific Financial Information Act obligations do not reduce once registration is granted; they expand as the business grows and the KFIU's examination programme intensifies.
For a business that is earlier in its licensing journey, a staged approach may be more appropriate. Obtaining a MAS licence in Singapore or an SFC VATP approval in Hong Kong first, building a compliance track record, and then approaching Korea with a demonstrable regulatory standing produces a stronger application profile than attempting a Korean registration as a first-mover licensing play.
Profile A: An established exchange with MAS or SFC licensing, a mature AML programme, clean beneficial-ownership disclosure and a strong balance sheet. This profile is well-positioned for Korean registration. The ISMS and banking workstreams are the primary variables; the regulatory substance is largely in place. Timeline: meaningful months, determined by the ISMS assessment and banking diligence cycle.
Profile B: An early-stage exchange with no existing major-jurisdiction licence, a lean compliance function and a holding structure optimised for tax efficiency without reference to banking disclosure. This profile faces the highest Korean entry risk. The banking condition is the most likely gating failure, and a declined account opening has no automatic appeal mechanism. The recommended path is to licence first in a jurisdiction with a more streamlined process, build the compliance infrastructure, then pursue Korea as a second market.
Profile C: A foreign exchange with a significant existing Korean user base but no Korean registration. This profile is the highest-risk position of all. Operating outside the regime while actively serving Korean users is the scenario the KFIU's enforcement programme is designed to address. Regularisation – either through registration or a structured wind-down of Korean user relationships – is the only legally defensible path.
Related at OBOLUS
- Licensing and registration for digital-asset businesses – our cross-jurisdictional licensing practice across 70+ regimes
- VARA licence applications: what recent enforcement tells operators – practical lessons from VARA's evolving enforcement posture
- Token sale agreement drafting: practical lessons for boards – structuring token issuance to withstand regulatory scrutiny
FAQ
How long does a crypto licence take to obtain?
In Korea, the VASP registration timeline is determined primarily by two workstreams: ISMS certification through KISA, and real-name bank account opening with a qualifying Korean bank. Both typically span several months. The overall process – from initiating ISMS readiness work to a completed KFIU registration – is generally measured in many months for a well-prepared applicant, and longer where the AML programme is incomplete or beneficial-ownership documentation requires extensive clarification. Other jurisdictions vary significantly: some offshore regimes complete registration in a matter of weeks; major licensing regimes such as MiCA or MAS can take a year or more.
Which jurisdiction is best for licensing my crypto business?
There is no single best jurisdiction. The right answer depends on where your users are, where your banking sits, what activities you conduct, and the compliance maturity of your business. Korea is a commercially significant market with demanding entry conditions. Singapore under the Payment Services Act, Hong Kong under the SFC VATP regime, and EU jurisdictions under MiCA offer different profiles of regulatory rigour, speed, and market access. A staged approach – licensing first in a jurisdiction that matches your current compliance infrastructure, then expanding – is typically more sustainable than targeting the most commercially attractive market without the preparation to satisfy its conditions.
Do I need a separate custody licence?
In Korea, safekeeping and administration of virtual assets is one of the enumerated VASP activities under the Specific Financial Information Act. A business that provides custody as a standalone service – rather than incidentally as part of an exchange operation – must be registered for that activity. The registration covers the specific activities the business conducts, and an exchange that also provides custody to third parties should confirm that its KFIU registration encompasses both activity types. In other leading jurisdictions, such as under MiCA or the MAS regime, custody is typically a separately authorised activity with its own capital and operational requirements.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – so our clients enter markets with their structure validated, not discovered under pressure. Digital assets are the whole of our practice. To discuss your Korea market-entry or broader licensing situation, contact info@oboluslaw.com or message us via t.me/oboluslaw.
By Aisha Tan, Licensing and Jurisdictions Analyst – specialising in Asia-Pacific VASP registration and cross-border licence structuring for exchange and custody businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.