The Challenge
On February 19, 2027, South Korean virtual asset providers face a strict compliance deadline. They must refuse any incoming transfer lacking complete originator and beneficiary information. The responsibility lies with the receiving institution in Seoul, but the impact is felt by the sending firm, regardless of its location or Korean presence.
The issue isn't the deadline itself; Presidential Decree No. 36592 sets that clearly. The challenge is the absence of defined compliance criteria. Article 10-20 delegates seven operative standards to notices from the Korea Financial Intelligence Unit, which haven't been published yet. These include how a provider proves control over an address and what evidence satisfies the requirement. Korean firms are preparing for a fixed date without a clear standard.
This situation isn't unique to Korea. Many jurisdictions handle technical rulemaking this way. However, it's a useful test case because the deadline is firm, the gaps are visible, and it's happening before the European Commission's report on self-hosted wallet transfers under Regulation (EU) 2023/1113.
The Environment and Constraints
The decree amended Korea's Act on Reporting and Using Specified Financial Transaction Information, taking effect in two stages. Most provisions began on August 20, 2026, tightening provider registration with financial-soundness tests and shareholder screening. The transfer rules were delayed until February 19, 2027.
Article 10-10 governs the information that must accompany a transfer and removes the old value threshold below which no information was required. Article 10-20 outlines the measures providers must take, including for transfers involving foreign providers and self-hosted wallets.
English-language coverage has misreported key details. Some summaries incorrectly claim Korea already restricts withdrawals to self-custody wallets; this takes effect in February. Others cite a requirement that transfers to personal wallets are only allowed when sender and recipient are the same person, which isn't in Article 10-10 or Article 10-20. This language comes from Financial Services Commission press material, which has been revised.
Compliance professionals know a regulator's press release isn't the law, but it's easy to forget under deadline pressure. Press material describes intent and is meant to be quoted. The decree is meant to be applied.
The Approach Compliance Teams Are Taking
You can't wait for the FIU notices to start building. The data-capture layer is already specified; Article 10-10 lists the required information categories. Design counterparty attestation workflows for transfers to Korean providers now. An exception-handling path for refused transfers is mandatory, as refusal is required under Article 10-20, item 6, when information isn't provided on request.
Two elements must wait for unpublished notices: the evidentiary standard for showing control of a receiving address and any risk tiering of foreign counterparties.
Here's the practical sequence:
Identify every counterparty under the February rules, including indirect exposure through intermediaries. If you route through a correspondent serving Korean providers, you're in scope.
Build to what the decree specifies, information fields and a request-then-refuse sequence, and document which controls are waiting on delegated criteria. Mark them as provisional and note the dependency.
Treat refusal as an expected outcome, not an incident. Decide now who gets notified, what the customer is told, and how the transfer is unwound. If you wait until a transfer is refused to figure out the operational response, you've already failed the control.
Read the instrument itself. If an English summary is your only source, mark the control as provisional until someone checks the original text. The gap between English reports and the decree is a reminder that secondary sources compress detail.
Watch for the delegated notices. In Korea, that means the FIU. In your jurisdiction, it's whichever body is responsible for the criteria your regulator has deferred.
Results and What's at Stake
The decree's effectiveness won't be measurable until after February 19, 2027. What happens in Seoul in early 2027, refused transfers, failed attestations, criteria published late or revised, will provide evidence for European and US compliance teams before their regulators address the same issue.
Under Regulation (EU) 2023/1113, the European Commission must report by June 30, 2027, on whether to limit, control, or prohibit transfers involving self-hosted addresses. Korea's rules take effect four months before this deadline. If Korean providers struggle with undefined criteria or if the FIU publishes unworkable standards, that outcome will inform the EU's decision.
Takeaways for Your Team
The Korean case demonstrates a compliance pattern you'll see again: fixed deadlines paired with undefined criteria. The jurisdiction changes, but the structure repeats.
Distinguish what's specified from what's delegated. Build the controls you can now and document the dependencies for what you can't. This documentation becomes your defense if criteria arrive late or change.
Refusal workflows matter more than you think. Most teams design for remediation, hold the transaction, request information, release when satisfied. Korea requires refusal when information isn't provided. This operational model requires different customer communications, exception handling, and internal escalation paths.
Don't rely on English summaries when the original instrument is available. The gap between press material and the decree itself is a reminder that summaries compress detail and sometimes introduce requirements not in the text.
Watch jurisdictions that move first. Korea's February deadline gives you four months of operational evidence before the EU decides whether to adopt similar restrictions. Use it.





