Operating a virtual asset service without proper authorisation in South Korea exposes a business to immediate enforcement action, frozen banking relationships, and potential criminal liability for directors. The Financial Intelligence Unit, known as the FIU, administers the VASP reporting regime under the Act on Reporting and Using Specified Financial Transaction Information – commonly called the Specified Financial Information Act or SFIA. That regime compels every entity providing virtual asset services to Korean users to register before it touches a single transaction. The risk calculus is unambiguous: a business that delays registration does not operate in a legal grey area; it operates unlawfully.
This page sets out the regulated basis, the registration process, the cross-border complications that catch inbound operators off guard, and the practical decision points that separate a clean application from a stalled one.
What activities require VASP registration in South Korea?
Any entity that exchanges, transfers, stores, manages, or intermediates virtual assets for Korean users must register with the FIU as a VASP before commencing operations. The Specified Financial Information Act defines virtual asset services broadly. Exchange services – spot trading between virtual assets and fiat, or between virtual assets – sit squarely inside the perimeter. So do custody and wallet services that hold assets on behalf of users, OTC brokerage, and transfer services that move assets between wallets on behalf of customers.
The practical reach extends to foreign operators. A business incorporated outside Korea that solicits or serves Korean-resident users is treated as conducting regulated activity in Korea. This is not a theoretical risk. The FIU has signaled an expectation that platform operators with material Korean user bases seek registration regardless of where the corporate entity sits. In our licensing practice, we regularly advise clients who discover this cross-border reach only after their Korean user numbers have grown significantly.
The threshold question for a structuring decision is therefore not where the company is incorporated but where the users are. A Delaware LLC, a BVI entity, or an EU-passported CASP under MiCA – none of these automatically satisfies the Korean registration obligation if the platform actively serves Korean retail users.
Why does the ISMS-P certification requirement change everything?
A VASP registration in South Korea requires the applicant to hold, or be in the process of obtaining, an ISMS-P certification (Information Security Management System with Personal Information Protection) issued by the Korea Internet and Security Agency (KISA). This requirement is not a procedural formality. It is a substantive security and privacy audit that independently assesses an organization's information security governance, technical controls, and personal-data handling practices.
ISMS-P certification is time-consuming and operationally intensive. The process involves a document review of the applicant's security policies, an on-site audit of technical infrastructure, and a formal assessment panel. The timeline from application to certification varies based on the applicant's existing security posture, but the process is measured in months rather than weeks. A business that begins its VASP registration planning without first scoping the ISMS-P requirement routinely discovers that certification – not the FIU application itself – is the critical path item.
For an inbound foreign operator, this creates a specific structuring challenge. The ISMS-P audit examines actual operational infrastructure. A foreign entity that processes Korean user data on servers located outside Korea must carefully consider how its data flows and technical architecture will be assessed. We have seen applications stall at this stage because the technical-readiness groundwork had not been completed before the FIU submission.
The practical sequence for a well-advised applicant is: scope the security architecture, engage a KISA-accredited audit body, run the ISMS-P process concurrently with the corporate and AML preparation, and ensure that certification – or at minimum a credible certification roadmap – is in place before the FIU filing.
How does the real-name banking requirement affect the application?
Registered VASPs in South Korea that offer fiat-to-virtual asset exchange must operate fiat settlement through a real-name verified account arrangement with a licensed Korean bank. This means the VASP must partner with a domestic bank that has conducted its own due diligence on the exchange and agreed to provide a dedicated real-name verification service for the exchange's users. Without such an arrangement, the VASP may not lawfully accept Korean won deposits from retail customers.
The banking relationship is not automatic. Korean banks apply their own risk appetite and conduct independent AML/KYC assessments of prospective VASP partners. The number of banks actively willing to onboard new VASP clients has historically been limited, and a bank's willingness to engage is contingent on the VASP's compliance infrastructure, transaction volumes, and governance quality. An application that clears the FIU but fails to secure banking is, in practice, an application that cannot operate the core business.
For a foreign operator entering Korea, the banking question is as consequential as the regulatory question. In our cross-border practice, we advise clients to treat bank relationship development as a parallel workstream – not a downstream task. The bank will want to see the ISMS-P certification, the AML programme documentation, the governance structure, and the beneficial ownership chain before agreeing to engage. This pre-banking due diligence process takes time and should begin early in the application timeline.
An operator that cannot demonstrate a credible path to a real-name bank account is unlikely to complete a viable registration for fiat-enabled exchange services. Custody-only or virtual-asset-to-virtual-asset businesses are not subject to the same fiat-settlement requirement, which creates a structural optionality that some inbound operators use as a phased entry approach.
To map the licence, banking and compliance stack for your Korean market entry, write to OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your entity structure, user base geography, and service scope change the analysis materially.
What AML/CFT obligations apply to registered Korean VASPs?
Registered VASPs in South Korea must implement a full AML/CFT programme aligned with FATF Recommendations, including the Travel Rule obligation to pass originator and beneficiary data with virtual asset transfers. The Korean Travel Rule framework applies to transfers above a prescribed threshold; the specific threshold is set under the applicable provisions and is subject to regulatory update, so current figures should be confirmed against the live regulatory text.
The AML obligations are substantive. They include customer due diligence, enhanced due diligence for higher-risk relationships, transaction monitoring, suspicious transaction reporting to the FIU, and record-keeping. The FIU supervises compliance and has authority to impose corrective measures, suspend operations, or revoke registration for deficiencies.
The Travel Rule requirement has a cross-border dimension that catches many operators. When a Korean-registered VASP transfers virtual assets to or from a foreign VASP, it must pass the required originator and beneficiary data. If the counterparty VASP is not Travel Rule compliant – because it is in a jurisdiction that has not yet fully implemented FATF Recommendation 15 – the Korean VASP faces a compliance decision about whether to proceed with the transfer. Operators we advise regularly build technical Travel Rule solutions into their compliance architecture before the FIU application, rather than treating it as a post-registration implementation task.
Stablecoin handling deserves a specific note. USDT and USDC, as the dominant stablecoin instruments, sit inside the VASP perimeter. Tether and Circle hold contract-level freeze authority over their issued tokens and generally act on law-enforcement or court direction. A Korean-registered VASP handling stablecoins should understand this operational reality when designing its user-fund management and compliance response protocols.
How should a foreign business structure its Korean presence?
A foreign operator seeking VASP registration in South Korea typically needs to establish a Korean-law corporate entity – most commonly a Yuhan Hoesa (limited liability company) or Jusik Hoesa (joint-stock company) – because the FIU registration framework is calibrated to Korean-registered legal persons. A branch of a foreign company is a structurally more complex path and raises additional AML attribution questions.
The entity question is intertwined with the tax and cross-border structuring decision. A Korean subsidiary that processes Korean user activity will be subject to Korean corporate tax on its Korean-source income. Transfer pricing rules apply to inter-company arrangements with the foreign parent, and the Korean National Tax Service scrutinises related-party transactions in the digital-asset sector. We consistently advise clients to engage cross-border tax counsel alongside their licensing counsel from the outset – not once the structure is already set.
There is also a capital and financial soundness expectation embedded in the FIU assessment, though specific capital thresholds are set under the applicable regulatory provisions and should be confirmed against current requirements. The governance expectation is clear: a credible Korean management team with authority to direct the local entity, rather than a shell presence with all real decision-making located abroad, is likely to be viewed more favorably by both the FIU and prospective banking partners.
For a group that already holds a licence in another jurisdiction – an EU CASP under MiCA, a Singapore MAS DPT licence, or a Hong Kong SFC VATP authorisation – there is no mutual recognition or passporting arrangement with Korea. The Korean registration is a standalone requirement. The foreign licence may, however, serve as evidence of the operator's compliance culture and governance quality, which can support both the FIU application and the bank relationship discussion.
A cross-border licensing matter: phased Korean entry
In a recent licensing engagement, a digital-asset exchange already authorised in a leading Asia-Pacific regime sought to expand into the Korean market. The operator had assumed its existing compliance programme would substantially satisfy the Korean requirements. On review, we identified three material gaps: the ISMS-P certification had not been scoped at all, the operator's technical infrastructure routed Korean user data through servers in a third country in a manner that complicated the KISA audit, and no Korean bank had been approached. We restructured the project timeline to run the ISMS-P process and the bank relationship discussions as parallel workstreams, advised on a server infrastructure adjustment to simplify the audit, and mapped the Korean corporate structure against the group's existing tax treaty position. The operator achieved certification and secured a banking commitment within the revised timeline.
Which operator profile should pursue Korean registration – and when?
The decision to register in South Korea turns on three variables: the existing or projected Korean user base, the service scope (fiat-enabled exchange versus custody-only versus VA-to-VA), and the operator's readiness to invest in the ISMS-P and banking processes.
For a well-capitalised exchange with a significant Korean user base, the registration obligation is not optional – it is a legal requirement. The operative question is whether the operator has the security infrastructure, governance quality, and banking relationships to complete a credible application. Entering the process underprepared is worse than taking additional time to prepare: a rejected or incomplete application creates a compliance record that complicates future attempts.
For a mid-stage operator with a smaller Korean user base, the decision involves a practical assessment of the market opportunity against the investment required. The ISMS-P, the corporate setup, and the banking process collectively represent a significant commitment. Some operators in this profile choose to geo-restrict Korean users until they are ready to register properly, rather than accept the legal exposure of serving them without authorisation.
For a custody-only or institutional-focused operator, the absence of the fiat-settlement requirement reduces the banking dependency and simplifies the operational compliance picture. This profile often represents the most tractable entry point for an inbound foreign operator that wants to establish a Korean presence before building toward a full exchange registration.
Regardless of profile, the common thread in the cases we advise is that early preparation – starting the ISMS-P scope, engaging Korean counsel, and opening banking conversations well in advance of the FIU filing – determines whether the application succeeds on the first submission or requires costly remediation.
If a prior application stalled or a banking relationship fell through, a second read of the structural issues can surface the underlying cause and the route forward. Contact OBOLUS at info@oboluslaw.com to scope a review.
Is an offshore licence sufficient for serving Korean users?
A common assumption among inbound operators is that a licence in a well-regarded offshore or international financial centre – the BVI, Cayman, Malta, or even a MiCA-passported EU entity – is sufficient to serve Korean users legally. This assumption is incorrect, and acting on it creates compounding risk.
The Korean VASP registration regime operates on a substance-over-structure principle: the question is not where the entity is domiciled but whether it provides virtual asset services to Korean-resident users. An operator that holds a BVI FSC registration or a Cayman CIMA licence and actively markets to Korean users is, under the Specified Financial Information Act, conducting unregistered virtual asset service activity in Korea. The enforcement consequences – suspension of access to Korean payment rails, regulatory orders, and potential criminal liability for responsible officers – are not mitigated by the offshore licence.
The legitimate role of an offshore structure in a Korean market entry is as the group holding company or intellectual-property vehicle, not as the regulated operating entity serving Korean users. The Korean VASP registration is a local, entity-specific requirement, and no foreign licence substitutes for it. Operators we advise who have relied on offshore licences to serve Korean users typically face a structured remediation process: establishing a Korean entity, building the compliance programme, and then regularising the registration status before enforcement escalates.
Related at OBOLUS
Related at OBOLUS
- Licensing and Registration for Digital-Asset Businesses – how we scope and manage the full licence stack across operating, custody, and payment layers.
- Crypto Exchange Licensing in Turkey – the regulatory process and cross-border structuring considerations for Turkey's emerging exchange licence regime.
- Crypto Fund Formation in the United Kingdom – FCA registration, fund structuring, and the UK financial-promotion regime for digital-asset funds.
FAQ
How long does a crypto licence take to obtain?
In South Korea, the VASP registration timeline is driven primarily by the ISMS-P certification process, which is measured in months and cannot be abbreviated significantly. The FIU application itself follows, with a review period that varies depending on the completeness of the submission and the regulator's current workload. Across other jurisdictions, timelines range from a matter of weeks in some offshore registries to six months or more in larger regulated markets. The honest answer is that timeline depends heavily on prior preparation.
Which jurisdiction is best for licensing my crypto business?
There is no single best jurisdiction for every business. The right licensing home depends on the service type, the user base geography, the operator's banking relationships, and the group's tax structure. A business serving Korean users needs Korean registration regardless of where its holding entity sits. A business seeking EU access needs a MiCA CASP authorisation. A business with institutional clients may prioritise Singapore, Hong Kong, or the ADGM. We map the jurisdiction stack to the specific business model before recommending a structure.
Do I need a separate custody licence?
In South Korea, custody of virtual assets on behalf of users is itself a regulated VASP activity, so a custody business requires its own registration. Whether that registration is the same as or separate from an exchange registration depends on how the services are structured and presented to the FIU. In other jurisdictions – for example under MiCA in the EU, or under the SFC regime in Hong Kong – custody is a distinct regulated activity with its own authorisation requirements and capital obligations. Bundling or separating the activities is a structuring decision that should be made before the application, not after.
About OBOLUS
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers, and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking, and compliance architecture that sits around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody, and payment layers before you commit – so the structure is right before the first application lands on a regulator's desk. Our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when things go wrong. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialist in inbound market-entry licensing across Asia-Pacific and the Middle East, with a focus on VASP registration, exchange authorisation, and cross-border compliance architecture.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.