South Korea’s Travel Rule: What VASPs Need to Know
From February 2027, South Korea will remove its KRW 1 million Travel Rule threshold, meaning Travel Rule requirements will apply to virtual asset transfers regardless of value.
However, there are other changes Korean virtual asset business operators (VASPs) need to prepare for. The framework also reinforces requirements around self-hosted wallets and cross-border transfers, with a more risk-based approach to transactions involving foreign VASPs and individual wallets (self-hosted wallets).
TL;DR
- South Korea's Travel Rule has been in force since 25 March 2022.
- The current KRW 1 million threshold is being removed, with a zero-threshold requirement expected to take effect in February 2027.
- VASPs must collect and transmit required originator and beneficiary information alongside virtual asset transfers.
- Beneficiary VASPs must obtain and secure the required information and may refuse transactions where information is missing.
- Transfers involving overseas VASPs and self-hosted wallets are subject to additional risk-based requirements.
- Transfers involving high-risk counterparties are prohibited.
- Transactions of KRW 10 million or more involving overseas VASPs or self-hosted wallets trigger internal suspicious transaction monitoring obligations.
Understanding the Regulatory Obligations for Virtual Asset Service Providers
Scope of the Travel Rule in South Korea
South Korea's Travel Rule applies to transfers of virtual assets between registered virtual asset business operators, as well as certain transfers involving self-hosted wallets where at least one regulated entity is involved in the transaction.
Under the Act on the Protection of Virtual Asset Users, etc., relevant virtual asset business activities include:
- the sale or purchase of virtual assets;
- the exchange of virtual assets for other virtual assets;
- the transfer of virtual assets prescribed by Presidential Decree;
- the storage or management of virtual assets; and
- the mediation, arrangement, or acting on behalf of the activities described above.
VASPs must therefore maintain appropriate compliance controls around customer identification, AML/CFT procedures, transaction monitoring, and the exchange of Travel Rule information.
Compliance Obligations for VASPs
South Korean VASPs must implement appropriate processes to collect, transmit, obtain, and secure required Travel Rule information for domestic transfers, while applying risk-based controls to transfers involving foreign VASPs and self-hosted wallets.
Originator VASPs are responsible for collecting and transmitting the required information to the beneficiary VASP alongside the virtual asset transfer. Where the beneficiary VASP or the Director of the Financial Intelligence Unit (FIU) requests additional identifying information, the originator VASP must provide it within three business days.
Beneficiary VASPs are responsible for obtaining and securing the required Travel Rule information. Where information is missing, the beneficiary VASP may request it from the counterparty and, where necessary, refuse to process the transaction. The counterparty has three business days to provide the missing information. If it is not provided within this period, the transaction must be refused.
When conducting transfers with foreign VASPs, domestic VASPs must assess the risks associated with the counterparty. This includes considering the foreign VASP's measures for preventing money laundering and terrorist financing, as well as whether the proposed transfer complies with standards prescribed by the Director of the FIU.
Where the relevant requirements are satisfied, the approved framework provides that:
- transfers to low-risk overseas exchanges are permitted;
- transfers to other overseas exchanges and self-hosted wallets are permitted where the sender and recipient are the same person;
- transfers involving high-risk counterparties are prohibited; and
- for transactions of KRW 10 million or more, or where otherwise instructed by the Director of the FIU, VASPs must establish and operate an internal suspicious transaction monitoring system.
VASPs should therefore have systems and procedures in place to identify incomplete Travel Rule messages, request missing information, assess counterparty risk, and determine whether transactions should be processed or refused.
NB: These requirements have been discussed and approved by the regulators but have not yet been enforced. VASPs should therefore monitor further regulatory guidance and developments as implementation progresses.
Required Travel Rule Data
Before a qualifying transfer, the originator VASP must collect and transmit information identifying both the originator and beneficiary.
The required information includes:
- originator's full name;
- originator's wallet address;
- beneficiary's full name; and
- beneficiary's wallet address.
For a corporation or organisation, the name of the corporation or organisation and the name of its representative must also be provided.
Upon request from the Director of the FIU or the beneficiary VASP, additional information must be provided within three business days. This may include:
- the originator's official identification number or corporate registration number, where the originator is a corporation; or
- the originator's passport number or foreigner registration number, where applicable.
Self-hosted Wallets (Individual Wallets)
South Korea's regulatory framework also addresses self-hosted wallets.
Transfers involving self-hosted wallets are subject to differentiated treatment based on the risks presented and will generally follow the same rules applied to cross-border transactions.
Where a VASP conducts a virtual asset transfer with a counterparty using a virtual asset address over which the counterparty does not have exclusive management rights, the VASP must conduct the transaction in accordance with standards determined and notified by the Director of the FIU. These standards take into account factors such as customer characteristics and transaction patterns.
NB: These requirements have been discussed and approved by the regulators but have not yet been enforced. VASPs should therefore monitor further regulatory guidance and developments as implementation progresses.
In Conclusion
South Korea's Travel Rule framework is entering a significant new phase.
While Travel Rule requirements have applied since 2022, the removal of the KRW 1 million threshold will extend Travel Rule obligations to qualifying transfers regardless of value from February 2027. At the same time, transfers involving overseas VASPs and self-hosted wallets are subject to additional risk-based controls under the evolving regulatory framework.
Firms should ensure that their systems can support high-volume, automated information exchange while maintaining effective controls for counterparty due diligence, incomplete information, suspicious activity, and higher-risk transfers.
21 Travel Rule and South Korea’s Travel Rule
21 Travel Rule helps South Korean VASPs simplify Travel Rule compliance through secure, automated information exchange, counterparty identification, risk-based controls, and transaction monitoring.
Through connectivity to TRUST, which includes many of the world's largest exchanges, and the open protocols like TRP, 21 Analytics enables secure communication with counterparties across different Travel Rule ecosystems, helping VASPs meet South Korea's requirements for exchanging originator and beneficiary information.
Automated counterparty discovery and due diligence tools allow VASPs to verify whether counterparties are appropriately regulated before executing transfers, while risk-based controls help identify high-risk counterparties and prevent non-compliant transactions.
With secure, on-premises data handling, 21 Travel Rule keeps sensitive customer information under the VASP's control while supporting compliance with South Korea's Travel Rule and broader AML/CFT requirements.
Downloadable audit logs also enable compliance teams to quickly produce Travel Rule records when required by regulators or auditors, providing a clear and efficient way to demonstrate compliance.
Become Travel Rule Compliant with 21 Analytics
Further Reading
Disclaimer
This material is provided for educational and informational purposes only and is not intended to be a substitute for professional advice or detailed research.

