South Korea's Presidential Decree No. 36592 takes effect on February 19, 2027. Virtual asset providers must refuse any incoming transfer lacking required originator and beneficiary information. This obligation applies whether or not you operate a Korean entity, and the deadline is fixed even as key implementation criteria remain unpublished.
This isn't just a Korean compliance issue. It's a preview of self-hosted wallet restrictions the EU must decide on by June 30, 2027, under Regulation (EU) 2023/1113. What happens in Seoul during Q1 2027 will influence European and US regulators considering similar controls.
Prerequisites
Before starting this checklist, confirm:
- You've identified all counterparties subject to the February rules, including indirect exposure through correspondent relationships.
- Someone on your team has read the decree itself (Articles 10-10 and 10-20 of the enforcement decree to the Act on Reporting and Using Specified Financial Transaction Information), not just English-language summaries.
- You've documented which controls depend on Korea Financial Intelligence Unit notices that haven't been published yet.
- You've established who owns this work: compliance, operations, or a joint team with clear decision rights.
Readiness Checklist
Data Layer
1. Capture originator information for all outbound transfers
Build fields for the data categories Article 10-10 specifies. You don't need to wait for FIU guidance to structure your data model.
Good looks like: Every outbound transfer record includes originator name, account identifier, address, and national identifier or registration number in structured fields your system can validate before transmission.
2. Capture beneficiary information for all inbound transfers
Mirror the originator structure for incoming flows. The decree eliminated the old value threshold, so every transfer needs full information regardless of amount.
Good looks like: Inbound transfer processing stops at validation, not reconciliation. Missing beneficiary data triggers refusal before the transfer posts.
3. Tag transfers by counterparty jurisdiction and entity type
Article 10-20 delegates risk classification of foreign providers to unpublished FIU criteria, but you can build the tagging infrastructure now.
Good looks like: Every counterparty record includes jurisdiction, registration status, and entity classification. When FIU publishes risk tiers, you update logic, not schema.
Workflow Layer
4. Implement request-then-refuse sequence for incomplete transfers
Article 10-20, item 6 requires refusal when information isn't provided on request. Build the request step now; you'll need it whether or not the sender responds.
Good looks like: System generates a structured information request within four hours of receiving an incomplete transfer. If the sender doesn't respond within your defined window (recommend 24 hours), the transfer moves automatically to refusal processing.
5. Build counterparty attestation workflow for Korean recipients
When you're the sending firm and your customer wants to transfer to a Korean provider, you need a way to collect and transmit the required information.
Good looks like: Customer-facing form collects beneficiary details before transfer initiation. System validates completeness against Article 10-10 requirements and blocks submission until all fields are populated with properly formatted data.
6. Create exception path for refused transfers
Refusal is an expected outcome under these rules, not an incident. Decide now how funds are returned, who gets notified, and what the customer is told.
Good looks like: Refused transfers trigger a return workflow that notifies the customer, logs the refusal reason, and processes the reversal within your standard timeframe. Customer communication explains what information was missing and how to resubmit correctly.
Control Documentation
7. Document controls that depend on unpublished criteria
Two things can't be finalized until FIU publishes delegated notices: the evidentiary standard for proving control of a receiving address and the risk classification of foreign counterparties.
Good looks like: Your control matrix identifies these as "pending regulatory guidance" with a specific reference to the FIU notice you're waiting for. You've assigned someone to monitor for publication and update the control when criteria are released.
8. Map self-hosted wallet handling to current capabilities
Article 10-20 covers transfers to addresses the provider doesn't exclusively control. What's your current process for verifying wallet ownership?
Good looks like: You've documented your existing wallet verification method and identified the gap between what you do today and what the unpublished FIU criteria might require. You know which vendor solutions or internal builds could close that gap.
Common Mistakes
Treating press releases as regulation. The Financial Services Commission issued explanatory material alongside the decree that has already been revised once. The widely reported restriction limiting personal wallet transfers to same-person sender-recipient pairs doesn't appear in Articles 10-10 or 10-20. Build to the decree, not the press release.
Waiting for complete guidance before starting. The information fields are specified. The refusal sequence is specified. You can build the data capture and workflow layers now and leave placeholders for the criteria FIU will publish later.
Assuming this only matters if you have a Korean entity. The obligation sits with the receiving institution in Seoul, but the consequences land on whoever controls outbound flows at the sending firm, regardless of where that firm is based.
Building for a single jurisdiction. Korea's rules take effect four months before the European Commission must report on self-hosted wallet restrictions. Whatever implementation problems surface in Seoul become case studies for EU and US compliance teams facing similar requirements.
Next Steps
Set a monthly review cadence starting now through February 2027. Each review should check:
- Has FIU published any of the seven delegated notices referenced in Articles 10-10 and 10-20?
- Have you tested the request-then-refuse workflow with at least one counterparty?
- Can your system generate the compliance report you'll need when your auditor asks how you're meeting the February deadline?
If you're waiting to see what other firms do, you're already behind. The firms that will adapt fastest to similar rules in other jurisdictions are the ones building reusable components now, while the Korean deadline is still visible but not urgent.





