South Korea KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in South Korea.
- Last reviewed
- Last reviewed:
- Version
- Version 1.2

Portable implementation guide
Get the PDF checklist
11 control areas · 44 implementation checks
Last reviewed: 25 September 2026 · Version 1.2
Download the checklistDirect answer
What does the South Korea compliance checklist cover?
The South Korea checklist translates primary KYC, KYB and AML rules into 11 control areas and 44 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- FIU
- Korea Financial Intelligence Unit (KoFIU)
- Primary AML law
- Act on Reporting and Using Specified Financial Transaction Information (FTRA), as in force
- STR timing
- Without delay after reasonable grounds for suspicion arise
- Cash threshold report
- KRW 10 million or more paid or received in cash, aggregated separately per trading day and same real name, subject to statutory exclusions
- AML retention
- Five years from termination of the relevant financial-transaction relationship, using the statutory termination event
- AML beneficial owner
- 25% voting ownership first, then largest holder or other control, then the representative as fallback
- Privacy authority
- Personal Information Protection Commission (PIPC)
- FATF public lists
- Not listed at 19 June 2026
Implementation detail
South Korea compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingMap the exact regulated activity and supervisor before applying this financial-sector checklist.4 items+
Determine whether the entity is a financial company or other reporting entity within the FTRA.
- Implementation action
- Map each banking, securities, insurance, cooperative, casino, electronic-finance, remittance and virtual-asset activity against the current FTRA and Enforcement Decree; document exclusions and the responsible sector supervisor.
- Evidence to retain
- Legal-entity chart, product and funds-flow inventory, perimeter memo, licence register and counsel confirmation.
- Primary citation
- FTRA Articles 2 and 15; FTRA Enforcement Decree Articles 2 and 15
Do not apply the financial-sector AML perimeter as a universal business rule.
- Implementation action
- For lawyers, accountants, real-estate businesses, dealers and other professionals, identify any separate sector duty and avoid describing them as FTRA reporting entities without a current legal basis.
- Evidence to retain
- Sector-by-sector applicability matrix, statutory sources and approved customer-scope decision.
- Primary citation
- FTRA Article 2; FATF Korea Follow-Up Report 2024, Recommendations 22, 23 and 28
Obtain each required payments or electronic-finance permission or registration before service.
- Implementation action
- Classify electronic currency, electronic funds transfer, debit, prepaid and payment-gateway services under the Electronic Financial Transactions Act and complete Financial Services Commission permission or registration unless a documented exemption applies.
- Evidence to retain
- Service classification, application, approval or registration, exemption analysis, conditions and change log.
- Primary citation
- Electronic Financial Transactions Act Articles 2 and 28
Register a covered virtual asset service provider with KoFIU.
- Implementation action
- File and maintain the FTRA registration, satisfy current information-security, real-name account where applicable, governance, systems, staffing, internal-control and fit-and-proper conditions, and track renewal and modification deadlines.
- Evidence to retain
- Perimeter analysis, registration acceptance, ISMS evidence, account evidence, governance pack, renewal calendar and change filings.
- Primary citation
- FTRA Articles 6-8; FTRA Enforcement Decree Articles 10-11 to 10-20, as amended effective 20 August 2026
02Governance and ML/TF risk managementCovered entities need accountable reporting, risk-based controls, training and independent evaluation.4 items+
Appoint the responsible reporting officer and maintain an internal reporting system.
- Implementation action
- Document appointment and dismissal, authority, escalation routes and access to KoFIU reporting channels; notify KoFIU where required.
- Evidence to retain
- Appointment record, notification, role description, delegation matrix and tested escalation workflow.
- Primary citation
- FTRA Article 5(1); FTRA Enforcement Decree Article 9
Maintain risk-based AML/CFT procedures and work guidelines.
- Implementation action
- Assess customer, product, channel, geography, transaction, new-technology and group risks and translate the results into proportionate CDD, monitoring, reporting and sanctions controls.
- Evidence to retain
- Risk methodology, current assessment, approved procedures, model inventory, change assessments and residual-risk decisions.
- Primary citation
- FTRA Article 5(1)-(4); FTRA Enforcement Decree Articles 4 and 9
Provide role-appropriate AML/CFT training and supervision.
- Implementation action
- Train relevant officers and employees at onboarding and periodically, test understanding, and supervise compliance with work guidelines.
- Evidence to retain
- Training content, attendance, assessment results, supervision reports and remediation records.
- Primary citation
- FTRA Article 5(1)3 and (4)
Independently evaluate the adequacy and effectiveness of the AML program.
- Implementation action
- Use a function independent from AML operations, set a risk-based scope and frequency, report findings to accountable management and verify closure.
- Evidence to retain
- Independence assessment, review plan, workpapers, report, management response and closure testing.
- Primary citation
- FTRA Article 5(3)2
03Natural-person identificationReal-name verification and FTRA CDD apply at relationship opening, scoped occasional-transaction thresholds and risk triggers.4 items+
Complete CDD when opening a new account or business relationship.
- Implementation action
- Identify and verify the customer's real name, address and contact information using reliable evidence before or at onboarding, subject only to a documented rule that permits later completion without delay.
- Evidence to retain
- Identity attributes, evidence source, verification result, timestamps, exception basis and completion record.
- Primary citation
- FTRA Article 5-2; FTRA Enforcement Decree Articles 10-2, 10-4 and 10-6; Act on Real Name Financial Transactions and Guarantee of Secrecy
Apply the correct occasional-transaction CDD threshold.
- Implementation action
- Trigger CDD at KRW 3 million for casino transactions, KRW 1 million equivalent for virtual-asset transactions, KRW 1 million equivalent for wire transfers, USD 10,000 equivalent for foreign-currency transactions, or KRW 10 million for other occasional financial transactions; do not treat one amount as universal.
- Evidence to retain
- Transaction classifier, aggregation logic where applicable, exchange-rate source, CDD trigger log and test cases.
- Primary citation
- FTRA Article 5-2(1)1; FTRA Enforcement Decree Article 10-3
Identify persons acting for a customer and verify their authority.
- Implementation action
- Collect the representative's identity, verify the mandate or corporate authority and link the person to the customer before accepting instructions.
- Evidence to retain
- Representative KYC, power of attorney or board authority, verification result and transaction audit trail.
- Primary citation
- FTRA Article 5-2; Financial Transaction Reports and Supervisory Regulation Article 38; KoFIU CDD guidance
Reject or terminate where required CDD cannot be completed.
- Implementation action
- Do not open the account or perform the new transaction when identity cannot be verified; terminate an existing relationship where the statutory condition applies and review whether an STR is required.
- Evidence to retain
- Information requests, refusal or termination decision, legal basis, customer communication and STR assessment.
- Primary citation
- FTRA Article 5-2(4)-(5)
04KYB, registries, and beneficial ownershipVerify legal existence, representatives and the natural persons who ultimately own or control the customer.4 items+
Verify legal-person or organization identity and existence.
- Implementation action
- Collect the real name, business type or establishment purpose, head-office and business locations, contact details and representative information; corroborate them with a current court commercial-register extract and other reliable documents.
- Evidence to retain
- Commercial-register extract, business registration, constitutional documents, representative verification and discrepancy log.
- Primary citation
- FTRA Enforcement Decree Article 10-4; Financial Transaction Reports and Supervisory Regulation Article 38; Commercial Act Article 34
Apply the statutory AML beneficial-owner cascade.
- Implementation action
- Identify the natural person holding at least 25% of issued voting shares or investment; if none can be identified, test the largest holder, appointment of a majority of management and other substantial control; if still none, identify the representative.
- Evidence to retain
- Layered ownership chart, voting and investment calculations, control analysis, identity verification and fallback rationale.
- Primary citation
- FTRA Article 5-2(1)1(b); FTRA Enforcement Decree Article 10-5(2)-(4)
Trace corporate owners to natural persons and resolve nominees or indirect control.
- Implementation action
- Look through each corporate layer, corroborate ownership and control independently, and escalate opaque or foreign structures rather than accepting the immediate shareholder as the beneficial owner.
- Evidence to retain
- Full chain, source extracts, shareholder registers, agreements, nominee analysis and enhanced review.
- Primary citation
- FTRA Enforcement Decree Article 10-5(3)-(4); KoFIU CDD guidance
Keep commercial-registration evidence separate from the AML beneficial-owner conclusion.
- Implementation action
- Use court registration and the company's shareholder register as KYB evidence, but perform the FTRA ownership-and-control test independently because basic or legal ownership evidence may not reveal ultimate control.
- Evidence to retain
- Registry extract, Commercial Act shareholder register, reconciliation and signed beneficial-owner determination.
- Primary citation
- Commercial Act Articles 34 and 352; FTRA Enforcement Decree Article 10-5; FATF Korea Mutual Evaluation 2020
05PEPs, enhanced due diligence, and remote onboardingHigher-risk customers require additional information and controls; Korea's PEP framework retains FATF-identified limitations.4 items+
Identify foreign PEP exposure and apply the required enhanced measures.
- Implementation action
- Screen the customer and beneficial owner for foreign PEP, family-member and close-associate status; obtain required senior approval, establish source of wealth and source of funds, and increase monitoring under the current KoFIU regulation.
- Evidence to retain
- Screening result, relationship map, approval, source corroboration and monitoring plan.
- Primary citation
- Financial Transaction Reports and Supervisory Regulation; FATF Korea Follow-Up Report 2024, Recommendation 12
Treat domestic and international-organization PEP coverage as a controlled legal gap.
- Implementation action
- Apply risk-based screening and enhanced review as an internal control where not expressly required, and confirm sector-specific rules; do not state that Korean law fully implements every FATF PEP category.
- Evidence to retain
- Legal-gap memo, approved risk policy, screening scope and exception decisions.
- Primary citation
- FATF Korea Follow-Up Report 2024, Recommendation 12
Perform enhanced CDD where ML/TF risk is high or actual ownership is doubtful.
- Implementation action
- Obtain and verify additional information including transaction purpose and source of funds, investigate inconsistencies and impose risk-appropriate approval and monitoring.
- Evidence to retain
- Risk trigger, enhanced questionnaire, source evidence, approval and review schedule.
- Primary citation
- FTRA Article 5-2(1)2; KoFIU CDD guidance
Control non-face-to-face identity and biometric processing.
- Implementation action
- Layer document, device, liveness and fraud controls. Where biometrics uniquely identify a person, establish a valid PIPA basis, obtain separate consent when relied upon, give required notices and apply enhanced security and deletion controls.
- Evidence to retain
- Method assessment, fraud tests, PIPA basis, consent and notice records, security review, retention schedule and vendor diligence.
- Primary citation
- PIPA Articles 15, 23, 29 and 30; Enforcement Decree of PIPA Article 18; PIPC Biometric Information Protection Guideline
06Monitoring and suspicious transaction reportingOngoing CDD and transaction monitoring must support prompt, confidential reporting to KoFIU.4 items+
Conduct ongoing, risk-based CDD and transaction monitoring.
- Implementation action
- Review transactions against customer activity, business, risk and source-of-funds information; set refresh cycles by risk and reverify when information is inconsistent, doubtful or materially changed.
- Evidence to retain
- Scenario inventory, alerts, case decisions, periodic reviews, refreshed CDD and quality testing.
- Primary citation
- FTRA Article 5; FTRA Enforcement Decree Article 10-6; KoFIU CDD guidance
File an STR with KoFIU without delay when the statutory suspicion test is met.
- Implementation action
- Record when reasonable grounds arose, state the grounds clearly and submit using the current KoFIU-prescribed form and channel without waiting for proof or a monetary threshold.
- Evidence to retain
- Alert chronology, information reviewed, suspicion decision, STR, submission receipt and timeliness test.
- Primary citation
- FTRA Article 4(1) and (3); FTRA Enforcement Decree Article 7; KoFIU STR guidance
Consider an STR after failed CDD, rejection or termination.
- Implementation action
- Route every statutory CDD refusal or relationship termination to the reporting officer for a documented suspicion assessment and preserve the decision.
- Evidence to retain
- Failed-CDD case, escalation, STR decision, filing receipt if applicable and closure approval.
- Primary citation
- FTRA Article 5-2(4)-(5); KoFIU CDD guidance
Protect STR information and prevent tipping off.
- Implementation action
- Restrict knowledge of an intended or filed STR to authorized internal use and any express legal exception; block customer-facing notes or disclosures that reveal the report.
- Evidence to retain
- Access controls, disclosure log, communication review, training and incident response.
- Primary citation
- FTRA Article 4(6)
07Cash reports, wires, and virtual-asset transfersCash aggregation, wire fields and virtual-asset travel rules use different scopes and thresholds.4 items+
Report covered large cash transactions.
- Implementation action
- Report to KoFIU within 30 days when KRW 10 million or more in cash is paid or received, aggregating payments and receipts separately over one trading day under the same real name at the same institution and applying only the statutory exclusions.
- Evidence to retain
- Cash ledger, same-name aggregation, exclusion logic, CTR, submission receipt and reconciliation.
- Primary citation
- FTRA Article 4-2; FTRA Enforcement Decree Articles 8-2 to 8-7; KoFIU CTR guidance
Detect structuring intended to avoid cash reporting.
- Implementation action
- Monitor linked and split transactions, investigate evasion indicators and file the required report or STR when the relevant statutory test is met.
- Evidence to retain
- Aggregation scenarios, linked-party logic, alert case, disposition and filing receipt.
- Primary citation
- FTRA Article 4-2(2); FTRA Enforcement Decree Article 8
Transmit prescribed originator and beneficiary information for covered wires.
- Implementation action
- For transfers above KRW 1 million domestically or USD 1,000 equivalent cross-border, populate the statutory originator and beneficiary fields, retain them and answer permitted domestic information requests within three business days.
- Evidence to retain
- Field mapping, message samples, threshold tests, request log, response timestamp and exception queue.
- Primary citation
- FTRA Article 5-3; FTRA Enforcement Decree Article 10-8
Apply the current virtual-asset travel rule and track the deferred expansion.
- Implementation action
- Until the 2026 amendment's later effective date, transmit the prescribed customer names and virtual-asset addresses for domestic VASP-to-VASP transfers of at least KRW 1 million and provide additional originator identifiers within three business days on a valid request. Prepare for all-size domestic coverage and the new overseas-transfer rules that take effect six months after promulgation.
- Evidence to retain
- Rule-version register, transfer controls, messages, request responses, transition plan and release testing.
- Primary citation
- FTRA Article 6(3); FTRA Enforcement Decree Article 10-10; FSC release of 11 August 2026
08Targeted financial sanctions and CPFKorean restricted-person measures require pre-transaction blocking, permission controls and prompt reporting.4 items+
Screen current FSC and incorporated UN restricted-person designations.
- Implementation action
- Screen customers, beneficial owners, controllers, representatives and transactions at onboarding, periodically and on list updates; assess entities owned or controlled under the applicable rules, not only exact names.
- Evidence to retain
- List source and timestamp, configuration, ownership-control analysis, match decisions and quality tests.
- Primary citation
- PFOPIA Article 4(1); PFOPIA Enforcement Decree; KoFIU CFT regime and current designation notices
Do not transact with or dispose of property for a restricted person without prior FSC approval.
- Implementation action
- Block the transaction or disposal before execution, preserve the property and case evidence, and seek FSC permission only through the statutory process.
- Evidence to retain
- Block timestamp, asset record, legal assessment, permission application and decision.
- Primary citation
- PFOPIA Article 4(4); KoFIU CFT regime
Report known terrorist- or proliferation-financing property without delay.
- Implementation action
- When an employee knows that transaction assets are TF/PF funds or that the counterparty is conducting a restricted transaction without permission, report without delay to the competent investigative authority and make the related KoFIU report.
- Evidence to retain
- Knowledge and escalation chronology, authority report, KoFIU filing, receipts and controlled communications.
- Primary citation
- PFOPIA Article 5(2); FTRA Article 4(1)3; KoFIU designated-person guidance
Test sanctions controls against Korea's FATF-identified TFS limitations.
- Implementation action
- Document how UN designations, domestic notices, ownership or control and update timing reach screening and blocking systems; treat known TF/PF TFS gaps as heightened control risk.
- Evidence to retain
- Gap assessment, list-update SLA, sample testing, remediation and senior risk acceptance.
- Primary citation
- FATF Korea Follow-Up Report 2024, Recommendations 6 and 7
09Records and regulator accessRetain reconstructable AML evidence for the statutory period and make it retrievable.3 items+
Retain AML reporting, CDD and transfer information for five years.
- Implementation action
- Start the five-year clock from the statutory termination of the financial-transaction relationship, including settlement of all claims and obligations for virtual-asset relationships, and preserve each required data category.
- Evidence to retain
- Record inventory, trigger-date logic, retention schedule, legal holds and sampled retrieval.
- Primary citation
- FTRA Article 5-4(1)-(2); FTRA Enforcement Decree Article 10-9
Preserve STR files separately and securely.
- Implementation action
- Keep the STR and supporting identification, transaction and suspicion-ground data segregated from ordinary transaction records with tightly limited access and auditable retrieval.
- Evidence to retain
- Repository configuration, access log, retention metadata, backup test and destruction approval.
- Primary citation
- FTRA Article 5-4; FTRA Enforcement Decree Article 10-9(1)-(3)
Support lawful KoFIU and supervisory access.
- Implementation action
- Maintain records in a form and location that permits timely production, with integrity, lineage, Korean-language context and confidentiality preserved.
- Evidence to retain
- Regulator-response procedure, data dictionary, immutable export, translation control and production log.
- Primary citation
- FTRA Articles 13 and 15; FTRA Enforcement Decree Article 10-9
10Privacy, biometrics, breaches, and transfersKYC data is also regulated personal information; AML retention does not displace PIPA controls outside its legal scope.6 items+
Implement the PIPA governance duties effective 11 September 2026.
- Implementation action
- Designate a personal information protection officer (CPO) unless the controller qualifies for the small-business exemption; where that exemption is used, document that the business owner or representative is deemed to be the CPO under PIPA Article 31(2). Give the CPO independent authority, access to specialist personnel and budget, and reporting access to the business owner or representative and board. If the controller meets the thresholds in Enforcement Decree Article 32(3), obtain board approval for each CPO designation, change or removal and submit the prescribed notice to PIPC within six months after the relevant event. For a qualifying controller whose CPO was already designated when the amended decree commenced, submit the notice within six months after 11 September 2026. A PIPC-approved extension may be available for unavoidable circumstances, within the decree's one-year limit. Track the separate ISMS-P mandate as a 1 July 2027 transition, not a current requirement.
- Evidence to retain
- CPO appointment and role charter, exemption or threshold analysis, deemed-CPO record where applicable, board minutes, six-month deadline calculation, PIPC filing and receipt, any extension decision, budget and staffing record, independence safeguards, reporting calendar and 1 July 2027 transition plan.
- Primary citation
- PIPA Article 31; PIPA Enforcement Decree Article 32 and supplementary provisions, as in force 11 September 2026; PIPC release of 10 September 2026
Establish and document a PIPA basis for each KYC processing purpose.
- Implementation action
- Map collection, use, sharing, outsourcing and retention to consent, statutory duty, contract necessity or another available basis; provide the required notices and collect only necessary data.
- Evidence to retain
- Processing register, legal-basis matrix, privacy notices, consent records, minimization review and retention schedule.
- Primary citation
- PIPA Articles 15, 17, 18, 21, 26 and 30
Protect resident registration numbers and sensitive biometric information.
- Implementation action
- Process resident registration numbers only under a specific statutory or other permitted condition, encrypt as required, and use separate consent or another express basis plus enhanced safeguards for biometric identifiers treated as sensitive information.
- Evidence to retain
- Authority mapping, separate consent where used, encryption proof, key controls, access review and deletion evidence.
- Primary citation
- PIPA Articles 23, 24, 24-2 and 29; Enforcement Decree of PIPA Article 18
Control cross-border personal-information transfers.
- Implementation action
- Use a permitted Article 28-8 route, give or disclose the prescribed transfer details, bind recipients to protective measures and monitor onward transfer and PIPC suspension risk.
- Evidence to retain
- Transfer map, Article 28-8 basis, notice or consent, recipient contract, security diligence and onward-transfer register.
- Primary citation
- PIPA Articles 28-8 and 28-9; Enforcement Decree of PIPA Articles 29-7 to 29-11
Operate separate 72-hour workflows for actual breaches, regulator reports and specified possible breaches.
- Implementation action
- When actual loss, theft, leakage, forgery, alteration or damage is known, notify affected persons within 72 hours, subject to the limited statutory exceptions, and provide follow-up details as they are confirmed. Report to PIPC or KISA within 72 hours only when the current decree criteria apply, including a breach involving at least 1,000 data subjects, sensitive or unique-identification information, or unlawful external access, subject to the decree's limited exception. Also notify affected persons within 72 hours when either possible-breach scenario in Enforcement Decree Article 39-2 is identified, and follow up if an actual breach is confirmed or ruled out.
- Evidence to retain
- Incident chronology, affected-person analysis, Article 39-2 possible-breach assessment, notification copies and timestamps, Article 40 regulator-reporting analysis, PIPC/KISA receipt where required, exception rationale and follow-up notices.
- Primary citation
- PIPA Article 34; PIPA Enforcement Decree Articles 39, 39-2, 39-3 and 40, as in force 11 September 2026
Scope privacy impact assessment correctly.
- Implementation action
- For public institutions establishing or changing a covered personal-information file, complete the statutory impact assessment before operation; for private high-risk biometric KYC, use an impact assessment as a documented risk control without mislabeling it universally mandatory.
- Evidence to retain
- Applicability decision, assessment, mitigations, approval and residual-risk register.
- Primary citation
- PIPA Article 33; operational control for non-statutory cases
11Practical evidence packsAssemble evidence that reconstructs legal scope, customer decisions, reporting and privacy compliance.3 items+
Maintain a complete onboarding and beneficial-ownership pack.
- Implementation action
- Link identity and legal-existence evidence, authority, ownership chain, 25% and control analysis, risk rating, PEP and sanctions results and approval.
- Evidence to retain
- One sampled file showing source provenance, timestamps, reviewer and unresolved issues.
- Primary citation
- Operational control supporting FTRA Article 5-2 and Enforcement Decree Articles 10-4 and 10-5
Maintain a reconstructable reporting and sanctions pack.
- Implementation action
- Link monitoring alert, suspicion or designation analysis, decision time, CTR or STR or authority report, submission receipt, confidentiality and blocked-property actions.
- Evidence to retain
- One sampled case with full chronology, filings, access record and management review.
- Primary citation
- Operational control supporting FTRA Articles 4 and 4-2 and PFOPIA Articles 4 and 5
Maintain a current regulatory-change pack.
- Implementation action
- Track the Korean controlling text, English translation lag, KoFIU notices, VASP deferred effective dates, FATF statements and PIPA amendments; assign owners and test changes before effective dates.
- Evidence to retain
- Source register, legal update log, impact assessment, approved implementation plan and post-change test.
- Primary citation
- Operational control supporting the FTRA, PFOPIA and PIPA frameworks
Primary-source register
26 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Financial Transaction Reports Act - current Korean textKorea Ministry of Government Legislation · Primary legislation
- FTRA - English statutory translationKorea Legislation Research Institute · Authoritative legal translation
- FTRA Enforcement Decree - current Korean textKorea Ministry of Government Legislation · Primary subordinate legislation
- KoFIU AML/CFT statutes and regulationsKorea Financial Intelligence Unit · Official legal index
- KoFIU AML/CFT regime and CDD guidanceKorea Financial Intelligence Unit · Official FIU guidance
- KoFIU customer due diligence guidanceKorea Financial Intelligence Unit · Official FIU guidance
- KoFIU suspicious transaction reporting guidanceKorea Financial Intelligence Unit · Official FIU guidance
- KoFIU currency transaction reporting guidanceKorea Financial Intelligence Unit · Official FIU guidance
- Approved 2026 VASP registration and AML rule changesFinancial Services Commission · Official regulatory release
- PFOPIA - English statutory textKorea Legislation Research Institute · Authoritative legal translation
- KoFIU counter-terrorist and proliferation-financing regimeKorea Financial Intelligence Unit · Official sanctions guidance
- KoFIU designated-person reporting guidanceKorea Financial Intelligence Unit · Official sanctions guidance
- KoFIU current notices and subordinate rulesKorea Financial Intelligence Unit · Official notice register
- Electronic Financial Transactions ActKorea Legislation Research Institute · Authoritative legal translation
- Commercial Act - registration and shareholder recordsKorea Legislation Research Institute · Authoritative legal translation
- Supreme Court registration servicesSupreme Court of Korea · Official registry guidance
- Personal Information Protection Act - current text and versionsKorea Legislation Research Institute · Authoritative legal translation
- PIPC laws and regulationsPersonal Information Protection Commission · Official privacy law index
- PIPC biometric information protection guidelinePersonal Information Protection Commission · Official privacy guidance
- PIPC personal-information breach reportingPersonal Information Protection Commission · Official incident guidance
- PIPA governance and breach amendments effective 11 September 2026Personal Information Protection Commission · Official amendment guidance
- FATF Korea follow-up report 2024FATF · Authoritative current assessment
- FATF Korea mutual evaluation 2020FATF · Authoritative mutual evaluation
- FATF jurisdictions under increased monitoring - 19 June 2026FATF · Authoritative current public list
- FATF high-risk jurisdictions subject to a call for action - 19 June 2026FATF · Authoritative current public list
- Official Taegeukgi design and constructionMinistry of the Interior and Safety · Official national-symbol guidance
Direct answers
South Korea KYC, KYB and AML questions
Who receives suspicious transaction reports?+
KoFIU, the Korea Financial Intelligence Unit, using the current prescribed reporting form and channel.
When must an STR be filed?+
Without delay after the reporting entity has reasonable grounds to suspect that received assets are illegal or that the counterparty is engaged in money laundering or terrorist financing. There is no minimum STR amount.
What cash activity is threshold-reportable?+
KRW 10 million or more paid or received in cash, with payments and receipts aggregated separately over one trading day under the same real name at the same financial institution, subject to statutory exclusions, is reportable within 30 days.
Is there one universal occasional-transaction CDD threshold?+
No. Current thresholds differ: KRW 3 million for casino transactions, KRW 1 million equivalent for virtual-asset transactions and wire transfers, USD 10,000 equivalent for foreign-currency transactions, and KRW 10 million for other occasional financial transactions.
How is an AML beneficial owner identified?+
Start with a natural person holding at least 25% of issued voting shares or investment. If none is identified, apply the largest-holder and other-control tests; if those fail, identify the representative. Trace corporate ownership through to natural persons.
How long are AML records kept?+
Five years from the statutory termination of the relevant financial-transaction relationship. The termination event depends on the transaction type; for a VASP relationship, it is when all claims and obligations from virtual-asset transactions are settled.
Must a VASP register?+
A covered VASP must register with KoFIU and satisfy the current acceptance and renewal conditions. Registration and travel-rule transition details changed in 2026, so operators must verify the current Korean text and KoFIU notices before launch.
What happens on a Korean restricted-person match?+
Do not execute a covered financial transaction or dispose of relevant property without prior FSC approval. Escalate and block the activity, and make the without-delay investigative-authority and KoFIU reports when the statutory knowledge tests are met.
What are PIPA's 72-hour breach duties?+
Known actual breaches generally require notice to affected persons within 72 hours, subject to limited exceptions. PIPC or KISA reporting within 72 hours applies only when the current decree criteria are met, including at least 1,000 affected data subjects, sensitive or unique-identification information, or unlawful external access. Separate notice applies to the specified possible-breach scenarios introduced in 2026.
Is South Korea on a FATF public list?+
No. The Republic of Korea was absent from both FATF public lists dated 19 June 2026. It remains subject to FATF mutual-evaluation follow-up, and absence from a list is not a low-risk finding.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 25 September 2026. Confirm the entity-specific FTRA perimeter, current KoFIU regulations and forms, sector licence, VASP transition dates, sanctions notices, privacy basis and any Korean-language source text with the competent authority and qualified Korean counsel before launch.