Corée du Sud KYC, KYB & AML compliance checklist
Une checklist pratique et sourcée pour mettre en œuvre les exigences KYC, KYB et AML en Corée du Sud.
- Dernière revue
- Dernière revue:
- Version
- Version 1.2

Guide d’implémentation portable
Obtenir la checklist PDF
11 domaines de contrôle · 44 contrôles d’implémentation
Dernière revue: 25 September 2026 · Version 1.2
Télécharger la checklistRéponse directe
Que couvre la checklist de conformité pour Corée du Sud ?
La checklist pour Corée du Sud traduit les principales règles KYC, KYB et AML en 11 domaines de contrôle et 44 contrôles d’implémentation, avec les autorités, obligations de déclaration et preuves à conserver.
Faits réglementaires clés
- FIU
- Korea Financial Intelligence Unit (KoFIU)
- Primary AML law
- Act on Reporting and Using Specified Financial Transaction Information (FTRA), as in force
- STR timing
- Without delay after reasonable grounds for suspicion arise
- Cash threshold report
- KRW 10 million or more paid or received in cash, aggregated separately per trading day and same real name, subject to statutory exclusions
- AML retention
- Five years from termination of the relevant financial-transaction relationship, using the statutory termination event
- AML beneficial owner
- 25% voting ownership first, then largest holder or other control, then the representative as fallback
- Privacy authority
- Personal Information Protection Commission (PIPC)
- FATF public lists
- Not listed at 19 June 2026
Détail d’implémentation
Exigences et actions de conformité pour Corée du Sud
Ouvrez chaque domaine pour consulter l’exigence, l’action recommandée, les preuves à conserver et la source primaire utilisée.
01Scope, authorities, and licensingMap the exact regulated activity and supervisor before applying this financial-sector checklist.4 éléments+
Determine whether the entity is a financial company or other reporting entity within the FTRA.
- Action d’implémentation
- Map each banking, securities, insurance, cooperative, casino, electronic-finance, remittance and virtual-asset activity against the current FTRA and Enforcement Decree; document exclusions and the responsible sector supervisor.
- Preuves à conserver
- Legal-entity chart, product and funds-flow inventory, perimeter memo, licence register and counsel confirmation.
- Source primaire
- FTRA Articles 2 and 15; FTRA Enforcement Decree Articles 2 and 15
Do not apply the financial-sector AML perimeter as a universal business rule.
- Action d’implémentation
- For lawyers, accountants, real-estate businesses, dealers and other professionals, identify any separate sector duty and avoid describing them as FTRA reporting entities without a current legal basis.
- Preuves à conserver
- Sector-by-sector applicability matrix, statutory sources and approved customer-scope decision.
- Source primaire
- FTRA Article 2; FATF Korea Follow-Up Report 2024, Recommendations 22, 23 and 28
Obtain each required payments or electronic-finance permission or registration before service.
- Action d’implémentation
- Classify electronic currency, electronic funds transfer, debit, prepaid and payment-gateway services under the Electronic Financial Transactions Act and complete Financial Services Commission permission or registration unless a documented exemption applies.
- Preuves à conserver
- Service classification, application, approval or registration, exemption analysis, conditions and change log.
- Source primaire
- Electronic Financial Transactions Act Articles 2 and 28
Register a covered virtual asset service provider with KoFIU.
- Action d’implémentation
- File and maintain the FTRA registration, satisfy current information-security, real-name account where applicable, governance, systems, staffing, internal-control and fit-and-proper conditions, and track renewal and modification deadlines.
- Preuves à conserver
- Perimeter analysis, registration acceptance, ISMS evidence, account evidence, governance pack, renewal calendar and change filings.
- Source primaire
- FTRA Articles 6-8; FTRA Enforcement Decree Articles 10-11 to 10-20, as amended effective 20 August 2026
02Governance and ML/TF risk managementCovered entities need accountable reporting, risk-based controls, training and independent evaluation.4 éléments+
Appoint the responsible reporting officer and maintain an internal reporting system.
- Action d’implémentation
- Document appointment and dismissal, authority, escalation routes and access to KoFIU reporting channels; notify KoFIU where required.
- Preuves à conserver
- Appointment record, notification, role description, delegation matrix and tested escalation workflow.
- Source primaire
- FTRA Article 5(1); FTRA Enforcement Decree Article 9
Maintain risk-based AML/CFT procedures and work guidelines.
- Action d’implémentation
- Assess customer, product, channel, geography, transaction, new-technology and group risks and translate the results into proportionate CDD, monitoring, reporting and sanctions controls.
- Preuves à conserver
- Risk methodology, current assessment, approved procedures, model inventory, change assessments and residual-risk decisions.
- Source primaire
- FTRA Article 5(1)-(4); FTRA Enforcement Decree Articles 4 and 9
Provide role-appropriate AML/CFT training and supervision.
- Action d’implémentation
- Train relevant officers and employees at onboarding and periodically, test understanding, and supervise compliance with work guidelines.
- Preuves à conserver
- Training content, attendance, assessment results, supervision reports and remediation records.
- Source primaire
- FTRA Article 5(1)3 and (4)
Independently evaluate the adequacy and effectiveness of the AML program.
- Action d’implémentation
- Use a function independent from AML operations, set a risk-based scope and frequency, report findings to accountable management and verify closure.
- Preuves à conserver
- Independence assessment, review plan, workpapers, report, management response and closure testing.
- Source primaire
- FTRA Article 5(3)2
03Natural-person identificationReal-name verification and FTRA CDD apply at relationship opening, scoped occasional-transaction thresholds and risk triggers.4 éléments+
Complete CDD when opening a new account or business relationship.
- Action d’implémentation
- Identify and verify the customer's real name, address and contact information using reliable evidence before or at onboarding, subject only to a documented rule that permits later completion without delay.
- Preuves à conserver
- Identity attributes, evidence source, verification result, timestamps, exception basis and completion record.
- Source primaire
- FTRA Article 5-2; FTRA Enforcement Decree Articles 10-2, 10-4 and 10-6; Act on Real Name Financial Transactions and Guarantee of Secrecy
Apply the correct occasional-transaction CDD threshold.
- Action d’implémentation
- Trigger CDD at KRW 3 million for casino transactions, KRW 1 million equivalent for virtual-asset transactions, KRW 1 million equivalent for wire transfers, USD 10,000 equivalent for foreign-currency transactions, or KRW 10 million for other occasional financial transactions; do not treat one amount as universal.
- Preuves à conserver
- Transaction classifier, aggregation logic where applicable, exchange-rate source, CDD trigger log and test cases.
- Source primaire
- FTRA Article 5-2(1)1; FTRA Enforcement Decree Article 10-3
Identify persons acting for a customer and verify their authority.
- Action d’implémentation
- Collect the representative's identity, verify the mandate or corporate authority and link the person to the customer before accepting instructions.
- Preuves à conserver
- Representative KYC, power of attorney or board authority, verification result and transaction audit trail.
- Source primaire
- FTRA Article 5-2; Financial Transaction Reports and Supervisory Regulation Article 38; KoFIU CDD guidance
Reject or terminate where required CDD cannot be completed.
- Action d’implémentation
- Do not open the account or perform the new transaction when identity cannot be verified; terminate an existing relationship where the statutory condition applies and review whether an STR is required.
- Preuves à conserver
- Information requests, refusal or termination decision, legal basis, customer communication and STR assessment.
- Source primaire
- FTRA Article 5-2(4)-(5)
04KYB, registries, and beneficial ownershipVerify legal existence, representatives and the natural persons who ultimately own or control the customer.4 éléments+
Verify legal-person or organization identity and existence.
- Action d’implémentation
- Collect the real name, business type or establishment purpose, head-office and business locations, contact details and representative information; corroborate them with a current court commercial-register extract and other reliable documents.
- Preuves à conserver
- Commercial-register extract, business registration, constitutional documents, representative verification and discrepancy log.
- Source primaire
- FTRA Enforcement Decree Article 10-4; Financial Transaction Reports and Supervisory Regulation Article 38; Commercial Act Article 34
Apply the statutory AML beneficial-owner cascade.
- Action d’implémentation
- Identify the natural person holding at least 25% of issued voting shares or investment; if none can be identified, test the largest holder, appointment of a majority of management and other substantial control; if still none, identify the representative.
- Preuves à conserver
- Layered ownership chart, voting and investment calculations, control analysis, identity verification and fallback rationale.
- Source primaire
- FTRA Article 5-2(1)1(b); FTRA Enforcement Decree Article 10-5(2)-(4)
Trace corporate owners to natural persons and resolve nominees or indirect control.
- Action d’implémentation
- Look through each corporate layer, corroborate ownership and control independently, and escalate opaque or foreign structures rather than accepting the immediate shareholder as the beneficial owner.
- Preuves à conserver
- Full chain, source extracts, shareholder registers, agreements, nominee analysis and enhanced review.
- Source primaire
- FTRA Enforcement Decree Article 10-5(3)-(4); KoFIU CDD guidance
Keep commercial-registration evidence separate from the AML beneficial-owner conclusion.
- Action d’implémentation
- Use court registration and the company's shareholder register as KYB evidence, but perform the FTRA ownership-and-control test independently because basic or legal ownership evidence may not reveal ultimate control.
- Preuves à conserver
- Registry extract, Commercial Act shareholder register, reconciliation and signed beneficial-owner determination.
- Source primaire
- Commercial Act Articles 34 and 352; FTRA Enforcement Decree Article 10-5; FATF Korea Mutual Evaluation 2020
05PEPs, enhanced due diligence, and remote onboardingHigher-risk customers require additional information and controls; Korea's PEP framework retains FATF-identified limitations.4 éléments+
Identify foreign PEP exposure and apply the required enhanced measures.
- Action d’implémentation
- Screen the customer and beneficial owner for foreign PEP, family-member and close-associate status; obtain required senior approval, establish source of wealth and source of funds, and increase monitoring under the current KoFIU regulation.
- Preuves à conserver
- Screening result, relationship map, approval, source corroboration and monitoring plan.
- Source primaire
- Financial Transaction Reports and Supervisory Regulation; FATF Korea Follow-Up Report 2024, Recommendation 12
Treat domestic and international-organization PEP coverage as a controlled legal gap.
- Action d’implémentation
- Apply risk-based screening and enhanced review as an internal control where not expressly required, and confirm sector-specific rules; do not state that Korean law fully implements every FATF PEP category.
- Preuves à conserver
- Legal-gap memo, approved risk policy, screening scope and exception decisions.
- Source primaire
- FATF Korea Follow-Up Report 2024, Recommendation 12
Perform enhanced CDD where ML/TF risk is high or actual ownership is doubtful.
- Action d’implémentation
- Obtain and verify additional information including transaction purpose and source of funds, investigate inconsistencies and impose risk-appropriate approval and monitoring.
- Preuves à conserver
- Risk trigger, enhanced questionnaire, source evidence, approval and review schedule.
- Source primaire
- FTRA Article 5-2(1)2; KoFIU CDD guidance
Control non-face-to-face identity and biometric processing.
- Action d’implémentation
- Layer document, device, liveness and fraud controls. Where biometrics uniquely identify a person, establish a valid PIPA basis, obtain separate consent when relied upon, give required notices and apply enhanced security and deletion controls.
- Preuves à conserver
- Method assessment, fraud tests, PIPA basis, consent and notice records, security review, retention schedule and vendor diligence.
- Source primaire
- PIPA Articles 15, 23, 29 and 30; Enforcement Decree of PIPA Article 18; PIPC Biometric Information Protection Guideline
06Monitoring and suspicious transaction reportingOngoing CDD and transaction monitoring must support prompt, confidential reporting to KoFIU.4 éléments+
Conduct ongoing, risk-based CDD and transaction monitoring.
- Action d’implémentation
- Review transactions against customer activity, business, risk and source-of-funds information; set refresh cycles by risk and reverify when information is inconsistent, doubtful or materially changed.
- Preuves à conserver
- Scenario inventory, alerts, case decisions, periodic reviews, refreshed CDD and quality testing.
- Source primaire
- FTRA Article 5; FTRA Enforcement Decree Article 10-6; KoFIU CDD guidance
File an STR with KoFIU without delay when the statutory suspicion test is met.
- Action d’implémentation
- Record when reasonable grounds arose, state the grounds clearly and submit using the current KoFIU-prescribed form and channel without waiting for proof or a monetary threshold.
- Preuves à conserver
- Alert chronology, information reviewed, suspicion decision, STR, submission receipt and timeliness test.
- Source primaire
- FTRA Article 4(1) and (3); FTRA Enforcement Decree Article 7; KoFIU STR guidance
Consider an STR after failed CDD, rejection or termination.
- Action d’implémentation
- Route every statutory CDD refusal or relationship termination to the reporting officer for a documented suspicion assessment and preserve the decision.
- Preuves à conserver
- Failed-CDD case, escalation, STR decision, filing receipt if applicable and closure approval.
- Source primaire
- FTRA Article 5-2(4)-(5); KoFIU CDD guidance
Protect STR information and prevent tipping off.
- Action d’implémentation
- Restrict knowledge of an intended or filed STR to authorized internal use and any express legal exception; block customer-facing notes or disclosures that reveal the report.
- Preuves à conserver
- Access controls, disclosure log, communication review, training and incident response.
- Source primaire
- FTRA Article 4(6)
07Cash reports, wires, and virtual-asset transfersCash aggregation, wire fields and virtual-asset travel rules use different scopes and thresholds.4 éléments+
Report covered large cash transactions.
- Action d’implémentation
- Report to KoFIU within 30 days when KRW 10 million or more in cash is paid or received, aggregating payments and receipts separately over one trading day under the same real name at the same institution and applying only the statutory exclusions.
- Preuves à conserver
- Cash ledger, same-name aggregation, exclusion logic, CTR, submission receipt and reconciliation.
- Source primaire
- FTRA Article 4-2; FTRA Enforcement Decree Articles 8-2 to 8-7; KoFIU CTR guidance
Detect structuring intended to avoid cash reporting.
- Action d’implémentation
- Monitor linked and split transactions, investigate evasion indicators and file the required report or STR when the relevant statutory test is met.
- Preuves à conserver
- Aggregation scenarios, linked-party logic, alert case, disposition and filing receipt.
- Source primaire
- FTRA Article 4-2(2); FTRA Enforcement Decree Article 8
Transmit prescribed originator and beneficiary information for covered wires.
- Action d’implémentation
- For transfers above KRW 1 million domestically or USD 1,000 equivalent cross-border, populate the statutory originator and beneficiary fields, retain them and answer permitted domestic information requests within three business days.
- Preuves à conserver
- Field mapping, message samples, threshold tests, request log, response timestamp and exception queue.
- Source primaire
- FTRA Article 5-3; FTRA Enforcement Decree Article 10-8
Apply the current virtual-asset travel rule and track the deferred expansion.
- Action d’implémentation
- Until the 2026 amendment's later effective date, transmit the prescribed customer names and virtual-asset addresses for domestic VASP-to-VASP transfers of at least KRW 1 million and provide additional originator identifiers within three business days on a valid request. Prepare for all-size domestic coverage and the new overseas-transfer rules that take effect six months after promulgation.
- Preuves à conserver
- Rule-version register, transfer controls, messages, request responses, transition plan and release testing.
- Source primaire
- FTRA Article 6(3); FTRA Enforcement Decree Article 10-10; FSC release of 11 August 2026
08Targeted financial sanctions and CPFKorean restricted-person measures require pre-transaction blocking, permission controls and prompt reporting.4 éléments+
Screen current FSC and incorporated UN restricted-person designations.
- Action d’implémentation
- Screen customers, beneficial owners, controllers, representatives and transactions at onboarding, periodically and on list updates; assess entities owned or controlled under the applicable rules, not only exact names.
- Preuves à conserver
- List source and timestamp, configuration, ownership-control analysis, match decisions and quality tests.
- Source primaire
- PFOPIA Article 4(1); PFOPIA Enforcement Decree; KoFIU CFT regime and current designation notices
Do not transact with or dispose of property for a restricted person without prior FSC approval.
- Action d’implémentation
- Block the transaction or disposal before execution, preserve the property and case evidence, and seek FSC permission only through the statutory process.
- Preuves à conserver
- Block timestamp, asset record, legal assessment, permission application and decision.
- Source primaire
- PFOPIA Article 4(4); KoFIU CFT regime
Report known terrorist- or proliferation-financing property without delay.
- Action d’implémentation
- When an employee knows that transaction assets are TF/PF funds or that the counterparty is conducting a restricted transaction without permission, report without delay to the competent investigative authority and make the related KoFIU report.
- Preuves à conserver
- Knowledge and escalation chronology, authority report, KoFIU filing, receipts and controlled communications.
- Source primaire
- PFOPIA Article 5(2); FTRA Article 4(1)3; KoFIU designated-person guidance
Test sanctions controls against Korea's FATF-identified TFS limitations.
- Action d’implémentation
- Document how UN designations, domestic notices, ownership or control and update timing reach screening and blocking systems; treat known TF/PF TFS gaps as heightened control risk.
- Preuves à conserver
- Gap assessment, list-update SLA, sample testing, remediation and senior risk acceptance.
- Source primaire
- FATF Korea Follow-Up Report 2024, Recommendations 6 and 7
09Records and regulator accessRetain reconstructable AML evidence for the statutory period and make it retrievable.3 éléments+
Retain AML reporting, CDD and transfer information for five years.
- Action d’implémentation
- Start the five-year clock from the statutory termination of the financial-transaction relationship, including settlement of all claims and obligations for virtual-asset relationships, and preserve each required data category.
- Preuves à conserver
- Record inventory, trigger-date logic, retention schedule, legal holds and sampled retrieval.
- Source primaire
- FTRA Article 5-4(1)-(2); FTRA Enforcement Decree Article 10-9
Preserve STR files separately and securely.
- Action d’implémentation
- Keep the STR and supporting identification, transaction and suspicion-ground data segregated from ordinary transaction records with tightly limited access and auditable retrieval.
- Preuves à conserver
- Repository configuration, access log, retention metadata, backup test and destruction approval.
- Source primaire
- FTRA Article 5-4; FTRA Enforcement Decree Article 10-9(1)-(3)
Support lawful KoFIU and supervisory access.
- Action d’implémentation
- Maintain records in a form and location that permits timely production, with integrity, lineage, Korean-language context and confidentiality preserved.
- Preuves à conserver
- Regulator-response procedure, data dictionary, immutable export, translation control and production log.
- Source primaire
- FTRA Articles 13 and 15; FTRA Enforcement Decree Article 10-9
10Privacy, biometrics, breaches, and transfersKYC data is also regulated personal information; AML retention does not displace PIPA controls outside its legal scope.6 éléments+
Implement the PIPA governance duties effective 11 September 2026.
- Action d’implémentation
- Designate a personal information protection officer (CPO) unless the controller qualifies for the small-business exemption; where that exemption is used, document that the business owner or representative is deemed to be the CPO under PIPA Article 31(2). Give the CPO independent authority, access to specialist personnel and budget, and reporting access to the business owner or representative and board. If the controller meets the thresholds in Enforcement Decree Article 32(3), obtain board approval for each CPO designation, change or removal and submit the prescribed notice to PIPC within six months after the relevant event. For a qualifying controller whose CPO was already designated when the amended decree commenced, submit the notice within six months after 11 September 2026. A PIPC-approved extension may be available for unavoidable circumstances, within the decree's one-year limit. Track the separate ISMS-P mandate as a 1 July 2027 transition, not a current requirement.
- Preuves à conserver
- CPO appointment and role charter, exemption or threshold analysis, deemed-CPO record where applicable, board minutes, six-month deadline calculation, PIPC filing and receipt, any extension decision, budget and staffing record, independence safeguards, reporting calendar and 1 July 2027 transition plan.
- Source primaire
- PIPA Article 31; PIPA Enforcement Decree Article 32 and supplementary provisions, as in force 11 September 2026; PIPC release of 10 September 2026
Establish and document a PIPA basis for each KYC processing purpose.
- Action d’implémentation
- Map collection, use, sharing, outsourcing and retention to consent, statutory duty, contract necessity or another available basis; provide the required notices and collect only necessary data.
- Preuves à conserver
- Processing register, legal-basis matrix, privacy notices, consent records, minimization review and retention schedule.
- Source primaire
- PIPA Articles 15, 17, 18, 21, 26 and 30
Protect resident registration numbers and sensitive biometric information.
- Action d’implémentation
- Process resident registration numbers only under a specific statutory or other permitted condition, encrypt as required, and use separate consent or another express basis plus enhanced safeguards for biometric identifiers treated as sensitive information.
- Preuves à conserver
- Authority mapping, separate consent where used, encryption proof, key controls, access review and deletion evidence.
- Source primaire
- PIPA Articles 23, 24, 24-2 and 29; Enforcement Decree of PIPA Article 18
Control cross-border personal-information transfers.
- Action d’implémentation
- Use a permitted Article 28-8 route, give or disclose the prescribed transfer details, bind recipients to protective measures and monitor onward transfer and PIPC suspension risk.
- Preuves à conserver
- Transfer map, Article 28-8 basis, notice or consent, recipient contract, security diligence and onward-transfer register.
- Source primaire
- PIPA Articles 28-8 and 28-9; Enforcement Decree of PIPA Articles 29-7 to 29-11
Operate separate 72-hour workflows for actual breaches, regulator reports and specified possible breaches.
- Action d’implémentation
- When actual loss, theft, leakage, forgery, alteration or damage is known, notify affected persons within 72 hours, subject to the limited statutory exceptions, and provide follow-up details as they are confirmed. Report to PIPC or KISA within 72 hours only when the current decree criteria apply, including a breach involving at least 1,000 data subjects, sensitive or unique-identification information, or unlawful external access, subject to the decree's limited exception. Also notify affected persons within 72 hours when either possible-breach scenario in Enforcement Decree Article 39-2 is identified, and follow up if an actual breach is confirmed or ruled out.
- Preuves à conserver
- Incident chronology, affected-person analysis, Article 39-2 possible-breach assessment, notification copies and timestamps, Article 40 regulator-reporting analysis, PIPC/KISA receipt where required, exception rationale and follow-up notices.
- Source primaire
- PIPA Article 34; PIPA Enforcement Decree Articles 39, 39-2, 39-3 and 40, as in force 11 September 2026
Scope privacy impact assessment correctly.
- Action d’implémentation
- For public institutions establishing or changing a covered personal-information file, complete the statutory impact assessment before operation; for private high-risk biometric KYC, use an impact assessment as a documented risk control without mislabeling it universally mandatory.
- Preuves à conserver
- Applicability decision, assessment, mitigations, approval and residual-risk register.
- Source primaire
- PIPA Article 33; operational control for non-statutory cases
11Practical evidence packsAssemble evidence that reconstructs legal scope, customer decisions, reporting and privacy compliance.3 éléments+
Maintain a complete onboarding and beneficial-ownership pack.
- Action d’implémentation
- Link identity and legal-existence evidence, authority, ownership chain, 25% and control analysis, risk rating, PEP and sanctions results and approval.
- Preuves à conserver
- One sampled file showing source provenance, timestamps, reviewer and unresolved issues.
- Source primaire
- Operational control supporting FTRA Article 5-2 and Enforcement Decree Articles 10-4 and 10-5
Maintain a reconstructable reporting and sanctions pack.
- Action d’implémentation
- Link monitoring alert, suspicion or designation analysis, decision time, CTR or STR or authority report, submission receipt, confidentiality and blocked-property actions.
- Preuves à conserver
- One sampled case with full chronology, filings, access record and management review.
- Source primaire
- Operational control supporting FTRA Articles 4 and 4-2 and PFOPIA Articles 4 and 5
Maintain a current regulatory-change pack.
- Action d’implémentation
- Track the Korean controlling text, English translation lag, KoFIU notices, VASP deferred effective dates, FATF statements and PIPA amendments; assign owners and test changes before effective dates.
- Preuves à conserver
- Source register, legal update log, impact assessment, approved implementation plan and post-change test.
- Source primaire
- Operational control supporting the FTRA, PFOPIA and PIPA frameworks
Registre des sources primaires
26 sources utilisées pour cette checklist
Utilisez ces liens pour vérifier la législation, les lignes directrices, les procédures de déclaration et les statuts internationaux.
- Financial Transaction Reports Act - current Korean textKorea Ministry of Government Legislation · Primary legislation
- FTRA - English statutory translationKorea Legislation Research Institute · Authoritative legal translation
- FTRA Enforcement Decree - current Korean textKorea Ministry of Government Legislation · Primary subordinate legislation
- KoFIU AML/CFT statutes and regulationsKorea Financial Intelligence Unit · Official legal index
- KoFIU AML/CFT regime and CDD guidanceKorea Financial Intelligence Unit · Official FIU guidance
- KoFIU customer due diligence guidanceKorea Financial Intelligence Unit · Official FIU guidance
- KoFIU suspicious transaction reporting guidanceKorea Financial Intelligence Unit · Official FIU guidance
- KoFIU currency transaction reporting guidanceKorea Financial Intelligence Unit · Official FIU guidance
- Approved 2026 VASP registration and AML rule changesFinancial Services Commission · Official regulatory release
- PFOPIA - English statutory textKorea Legislation Research Institute · Authoritative legal translation
- KoFIU counter-terrorist and proliferation-financing regimeKorea Financial Intelligence Unit · Official sanctions guidance
- KoFIU designated-person reporting guidanceKorea Financial Intelligence Unit · Official sanctions guidance
- KoFIU current notices and subordinate rulesKorea Financial Intelligence Unit · Official notice register
- Electronic Financial Transactions ActKorea Legislation Research Institute · Authoritative legal translation
- Commercial Act - registration and shareholder recordsKorea Legislation Research Institute · Authoritative legal translation
- Supreme Court registration servicesSupreme Court of Korea · Official registry guidance
- Personal Information Protection Act - current text and versionsKorea Legislation Research Institute · Authoritative legal translation
- PIPC laws and regulationsPersonal Information Protection Commission · Official privacy law index
- PIPC biometric information protection guidelinePersonal Information Protection Commission · Official privacy guidance
- PIPC personal-information breach reportingPersonal Information Protection Commission · Official incident guidance
- PIPA governance and breach amendments effective 11 September 2026Personal Information Protection Commission · Official amendment guidance
- FATF Korea follow-up report 2024FATF · Authoritative current assessment
- FATF Korea mutual evaluation 2020FATF · Authoritative mutual evaluation
- FATF jurisdictions under increased monitoring - 19 June 2026FATF · Authoritative current public list
- FATF high-risk jurisdictions subject to a call for action - 19 June 2026FATF · Authoritative current public list
- Official Taegeukgi design and constructionMinistry of the Interior and Safety · Official national-symbol guidance
Réponses directes
Questions KYC, KYB et AML pour Corée du Sud
Who receives suspicious transaction reports?+
KoFIU, the Korea Financial Intelligence Unit, using the current prescribed reporting form and channel.
When must an STR be filed?+
Without delay after the reporting entity has reasonable grounds to suspect that received assets are illegal or that the counterparty is engaged in money laundering or terrorist financing. There is no minimum STR amount.
What cash activity is threshold-reportable?+
KRW 10 million or more paid or received in cash, with payments and receipts aggregated separately over one trading day under the same real name at the same financial institution, subject to statutory exclusions, is reportable within 30 days.
Is there one universal occasional-transaction CDD threshold?+
No. Current thresholds differ: KRW 3 million for casino transactions, KRW 1 million equivalent for virtual-asset transactions and wire transfers, USD 10,000 equivalent for foreign-currency transactions, and KRW 10 million for other occasional financial transactions.
How is an AML beneficial owner identified?+
Start with a natural person holding at least 25% of issued voting shares or investment. If none is identified, apply the largest-holder and other-control tests; if those fail, identify the representative. Trace corporate ownership through to natural persons.
How long are AML records kept?+
Five years from the statutory termination of the relevant financial-transaction relationship. The termination event depends on the transaction type; for a VASP relationship, it is when all claims and obligations from virtual-asset transactions are settled.
Must a VASP register?+
A covered VASP must register with KoFIU and satisfy the current acceptance and renewal conditions. Registration and travel-rule transition details changed in 2026, so operators must verify the current Korean text and KoFIU notices before launch.
What happens on a Korean restricted-person match?+
Do not execute a covered financial transaction or dispose of relevant property without prior FSC approval. Escalate and block the activity, and make the without-delay investigative-authority and KoFIU reports when the statutory knowledge tests are met.
What are PIPA's 72-hour breach duties?+
Known actual breaches generally require notice to affected persons within 72 hours, subject to limited exceptions. PIPC or KISA reporting within 72 hours applies only when the current decree criteria are met, including at least 1,000 affected data subjects, sensitive or unique-identification information, or unlawful external access. Separate notice applies to the specified possible-breach scenarios introduced in 2026.
Is South Korea on a FATF public list?+
No. The Republic of Korea was absent from both FATF public lists dated 19 June 2026. It remains subject to FATF mutual-evaluation follow-up, and absence from a list is not a low-risk finding.
Méthode de recherche et de revue
VOVE ID Compliance Research cartographie le périmètre réglementaire, traduit les obligations en contrôles opérationnels, relie les affirmations importantes aux sources et date chaque revue.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 25 September 2026. Confirm the entity-specific FTRA perimeter, current KoFIU regulations and forms, sector licence, VASP transition dates, sanctions notices, privacy basis and any Korean-language source text with the competent authority and qualified Korean counsel before launch.