EST · MMXXVI
Home/Jurisdictions/South Korea/Sanctions screening for crypto in South Korea
Compliance, AML & Travel Rule

Sanctions screening for crypto in South Korea

Sanctions screening for crypto in South Korea. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Sanctions Screening for Crypto in South Korea

A virtual asset service provider expanding into the South Korean market quickly learns that sanctions screening (the real-time comparison of customers, counterparties and transaction flows against government-designated lists) sits at the operational core of the country's crypto compliance regime. South Korea's Act on Reporting and Using Specified Financial Transaction Information – commonly called the SPTFA or the Special Act – and the broader AML/CFT framework administered by the Korea Financial Intelligence Unit (KoFIU) together create obligations that are not optional add-ons. They are licence conditions. Operating without a properly implemented sanctions screening program puts banking access, KoFIU registration, and ultimately the ability to serve Korean users at risk.

This page explains the regulated basis for sanctions screening in South Korea, the process an inbound business must follow, the cross-border complications that arise when the corporate structure spans multiple jurisdictions, and the decision points a general counsel needs to address before committing to the market.

The Regulatory Basis for Sanctions Screening in South Korea

Sanctions obligations for crypto businesses in South Korea flow from two sources operating in parallel. The first is domestic AML/CFT law. Under the SPTFA, every virtual asset business operator (VABO) – the South Korean analogue to a VASP (virtual asset service provider) – must register with KoFIU before commencing operations. That registration requires evidence of a functioning AML/CFT program. Sanctions screening is a mandatory component of that program.

The second source is the country's dedicated sanctions architecture. South Korea maintains its own designation regime under the Act on International Peace and Security Maintenance and implements UN Security Council resolutions – including those targeting the Democratic People's Republic of Korea (DPRK) – through domestic statutory instruments. Crypto businesses must screen against both the domestic designation list and the UN consolidated list. They must also apply controls against OFAC's Specially Designated Nationals list for any USD-denominated or US-nexus transaction, because US dollar correspondent banking underpins most settlement rails globally.

The three-source obligation – domestic, UN, OFAC – is a reality we see consistently in cross-border practices. An operator that screens only against one list carries material residual risk on the others.

Who Must Comply with South Korea's Crypto Sanctions Rules?

Every VABO registered or seeking registration with KoFIU falls within the mandatory screening perimeter. The category is defined by activity, not by corporate domicile. An exchange incorporated in Singapore but operating a Korean-language platform that onboards Korean users, processes Korean won deposits, or connects to Korean banking rails is within scope. Regulatory perimeter in South Korea follows function and user nexus.

In our cross-border practice, we regularly advise clients who assume that holding a licence in another jurisdiction – say, a Digital Payment Token service licence in Singapore under the Payment Services Act administered by the Monetary Authority of Singapore (MAS) – gives them a compliant basis to serve Korean users. It does not. South Korean regulation applies to the Korean activity layer. The offshore licence governs the offshore entity; KoFIU registration governs the Korean-facing activity.

The scope extends to custodians, over-the-counter desks, stablecoin issuers, and transfer agents where those activities involve Korean counterparties or Korean-won settlement. Decentralised protocols are not exempt from the analysis; KoFIU has made clear that the economic substance and user nexus determine coverage, not the technical architecture.

To map whether your business activity triggers South Korean VABO obligations, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the banking rails – change the analysis considerably.

What Does the KoFIU Registration Process Require?

KoFIU registration is the gateway, and sanctions screening documentation is one of its critical pre-conditions. The application requires the operator to demonstrate, before registration is granted, that its AML/CFT program is operational – not planned, not drafted, but implemented and tested.

The program documentation must cover several interconnected elements. First, a written AML/CFT policy that explicitly addresses virtual asset risks, including exposure to high-risk jurisdictions. Second, a Customer Due Diligence (CDD) framework – including Enhanced Due Diligence (EDD) procedures for politically exposed persons, high-risk countries and unusual transaction patterns. Third, a transaction monitoring system capable of detecting layering patterns specific to crypto – rapid multi-hop transfers, conversion between asset classes, and privacy-coin exposure. Fourth, and directly relevant here, a sanctions screening process that covers onboarding, real-time transaction review and periodic rescreening of the existing customer base.

KoFIU also requires designation of an AML compliance officer and – for entities that clear a defined size threshold – an independent internal audit function. The compliance officer must have the authority and the access to halt transactions pending review. In practice, for a small to mid-size operator, this is often the same individual as the MLRO, though the roles carry distinct accountability lines.

The timeline for KoFIU processing is not fixed by statute at a hard deadline. In our experience of guiding clients through comparable registration exercises in the major hubs, applicants who submit complete, well-prepared documentation can expect a process measured in weeks rather than months. Incomplete submissions – particularly those lacking sanctions screening procedure manuals or transaction monitoring system specifications – trigger requests for additional information that extend the process materially.

How Does the Travel Rule Apply to Korean Crypto Transfers?

The Travel Rule – the FATF obligation requiring VABOs to collect and transmit originator and beneficiary data with every qualifying virtual asset transfer – is in force in South Korea, implemented through amendments to the SPTFA. Compliance is not elective. A VABO that sends or receives a virtual asset transfer above the applicable threshold without the required accompanying data is in breach of its KoFIU registration conditions.

The specific data fields required align with the FATF Recommendations, particularly Recommendation 16. They include the originator's name, account identifier and address, and corresponding beneficiary data. The obligation applies whether the transfer originates domestically or crosses a border. For outbound transfers to a VASP in another jurisdiction that has not implemented the Travel Rule, the Korean VABO cannot simply omit the data; it must assess the counterparty's compliance posture and apply risk-based controls.

The cross-border dimension creates a practical problem that operators regularly underestimate. When a Korean VASP sends funds to a VASP in a jurisdiction where the Travel Rule is not yet uniformly enforced, the Korean operator remains liable under KoFIU rules for the adequacy of its own process. The solution is not to avoid those transfers but to document the risk assessment, apply counterparty due diligence, and in some cases decline transfers to unregistered entities in high-risk jurisdictions.

South Korea also applies the Travel Rule concept to stablecoin transfers. An operator that processes USDT or USDC flows for Korean clients must apply the same data capture and transmission obligations as it would to a Bitcoin or Ethereum transfer above the threshold. This catches a number of operators by surprise, particularly those that treat stablecoin flows as a purely banking-adjacent activity.

How Do Banking Rails Interact with Crypto Sanctions Obligations in Korea?

The interaction between Korean commercial banking and crypto sanctions compliance is one of the most operationally demanding aspects of market entry. Under the SPTFA framework, a VABO must maintain a real-name verified account at a Korean bank – meaning the exchange's corporate account and its customer fiat on-ramp/off-ramp must be through a domestic financial institution that has itself completed counterparty due diligence on the VABO.

Korean commercial banks have historically approached VABO relationships with caution. A bank that provides real-name services to a VABO becomes, in effect, a secondary AML control point. It will conduct its own sanctions review of the VABO and will typically require evidence that the operator's own screening program meets standards comparable to those the bank applies to its own customers. Banks have been known to decline or exit relationships where the VABO's screening documentation is inadequate – regardless of whether KoFIU registration was technically obtained.

This creates a two-layer sanctions risk. The operator must satisfy KoFIU's AML standards to obtain registration, and must independently satisfy its banking partner's standards to maintain fiat rails. A failure at either layer effectively disables the business. We have seen this pattern in our cross-border practice: an operator that invested heavily in the KoFIU application but treated the banking relationship as a secondary concern discovered that the bank's internal AML team required substantially more documentation – including a detailed sanctions screening manual and audit trail – before the real-name account was approved.

If your banking relationship in Korea is under review or has stalled, contact OBOLUS at info@oboluslaw.com to assess the compliance gap and the structural options.

What Cross-Border Structuring Considerations Apply to DPRK Risk?

DPRK exposure is the dominant sanctions risk for any crypto business with Korean-market activity. UN Security Council resolutions impose comprehensive asset-freeze and transaction-prohibition measures on DPRK entities and individuals. South Korea implements those measures directly. Separately, OFAC has issued specific guidance on virtual currency and the DPRK, including designations of specific wallet addresses used by state-linked threat actors.

For an operator running a global order book or processing cross-border transfers, DPRK-nexus risk arises not only from direct counterparty exposure but from intermediary transaction chains. A transfer that passes through one or more hops before reaching the Korean VASP may originate with, or be routed through, a sanctioned address. Blockchain analytics tools – those provided by forensic partners such as Chainalysis, TRM Labs and Elliptic – are generally expected by KoFIU and by Korean commercial banks as a component of a credible transaction monitoring framework.

The cross-border structuring question for an operator with entities in multiple jurisdictions is: which entity bears the primary KoFIU obligation, and how do sanctions controls flow across the group? A common approach is to locate the KoFIU-registered VABO in a Korean subsidiary, maintain the broader group's compliance policy at the parent level, and require the Korean entity to implement a local addendum that addresses SPTFA-specific obligations including the domestic designation list and DPRK screens. The Korean compliance officer must have line visibility into the group's global watchlist and be able to act on it independently.

Operators we advise routinely discover that the group-level compliance policy was drafted for a single-jurisdiction context and does not address the layered multi-regulator scenario that arises once a second or third regulated entity is added. The OBOLUS compliance scoping process maps the policy architecture across the group before a new market is entered.

A Practical Illustration

In a recent compliance structuring matter, a custodian operating under a European CASP (crypto-asset service provider) authorisation under MiCA sought to extend services to Korean institutional clients. The client had an existing group AML policy drafted to satisfy the European regime but had not addressed KoFIU registration or the SPTFA's VABO requirements. We mapped the Korean activity layer, identified that the proposed service model triggered VABO obligations, and restructured the client-facing flow to route Korean-institutional business through a locally registered entity. We then drafted the KoFIU-compliant AML/CFT policy, including a sanctions screening manual that covered the domestic designation list, the UN consolidated list, and OFAC. The banking introduction followed once the documentation package was complete. The process concluded within a single quarter.

What Compliance Mistakes Do Crypto Firms Make in Korea?

The most consistent mistake is treating KoFIU registration as the end of the compliance journey rather than the beginning. Registration demonstrates that the program was implemented at a point in time. KoFIU expects evidence of ongoing operation: transaction monitoring logs, sanctions alert resolution records, periodic customer rescreening, and internal audit findings. An operator that built a program to pass registration but did not maintain it faces enforcement risk at the next supervisory review.

A second common error is failing to update screening lists in near-real time. Designation events – whether a new OFAC SDN listing or a UN Security Council resolution amendment – create immediate compliance obligations. An operator that screens against a list updated weekly rather than daily carries the gap as a sanctions risk. South Korean regulators and Korean commercial banks both expect list currency consistent with the speed of the market.

A third error is the myth that a single offshore licence resolves the Korean compliance obligation. A common assumption is that registering a holding entity in a permissive jurisdiction and routing Korean business through it insulates the operator from SPTFA requirements. It does not. Regulators examine economic substance and user nexus. The Korean-facing activity triggers Korean regulatory obligations regardless of where the contracting entity is domiciled. The offshore structure may still be commercially useful for tax or capital efficiency purposes – but it does not substitute for KoFIU registration.

Related at OBOLUS

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule, drawn from FATF Recommendation 16, requires a VASP to collect and transmit the originator's name, account identifier and physical address – along with corresponding beneficiary data – with every virtual asset transfer that meets or exceeds the applicable threshold. The obligation applies to both outbound and inbound transfers. In South Korea, the SPTFA implements these requirements, and non-compliance constitutes a breach of KoFIU registration conditions. The data must travel with the transaction, not be held passively by the sending firm.

Who must act as MLRO for a crypto firm?

A Money Laundering Reporting Officer (MLRO) must be a sufficiently senior individual with the authority to halt transactions, file suspicious transaction reports, and escalate compliance concerns without commercial interference. In South Korea, KoFIU requires designation of a dedicated AML compliance officer, who in practice carries equivalent responsibilities. The officer must understand both the firm's product architecture and the specific risks – including DPRK-linked transaction patterns – relevant to the Korean market. For cross-border groups, the Korean compliance officer requires clear escalation lines to, but operational independence from, the group function.

How do regulators audit crypto AML programs?

KoFIU and Korean commercial banking partners both review AML programs through a combination of documentation review and operational testing. Regulators typically examine written policies, transaction monitoring system configurations, sanctions alert disposition logs, CDD file samples and internal audit reports. They look for evidence that the program operates in practice, not merely on paper. A common audit finding is that alert resolution timelines are excessive or that rescreening of the existing customer base is not performed on a periodic basis. Cross-border operators should expect that the Korean review will focus specifically on DPRK exposure controls and Travel Rule data completeness.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, banking and compliance stack across operating, custody and payment layers before you commit to a market – identifying gaps before regulators or banking partners do. We work alongside forensic partners to convert on-chain evidence into court-ready disclosure applications where enforcement becomes necessary. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialist in VASP registration, AML/CFT program architecture and sanctions screening obligations across Asian and European markets.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours