The financial authorities will expand the scope of review for virtual asset service provider filings to include controlling shareholders and will examine financial condition, social credit, and anti-money-laundering organizations and staffing. When a controlling shareholder or the compliance system changes, the current post-change filing system will switch to a pre-change filing system 30 days in advance.
The Financial Intelligence Unit (FIU) and the Financial Supervisory Service said on the 13th they held an on-site briefing on the revised filing manual for virtual asset service providers for virtual asset service providers and prospective operators. The briefing was arranged to coincide with the enforcement on the 20th of the revised Act on Reporting and Using Specified Financial Transaction Information, which passed the National Assembly in Jan. The financial authorities revamped the virtual asset service provider filing manual to reflect the revised law and subordinate regulations, including the enforcement decree and supervisory regulations, and explained it to the industry.
Under the revised filing manual, the scope for checking histories of legal violations and requirements for financial condition and social credit will be expanded from existing operators, representatives, and executives to controlling shareholders. Under the revised law, controlling shareholders include not only the largest shareholders and major shareholders but also shareholders who are special related parties of the largest shareholder. The filing must include all controlling shareholders subject to filing and specify the controlling shareholders' real names, nationalities, and their holdings of shares and equity. Supporting documents such as shareholder registers of the operator and of the corporation that is the largest shareholder must be submitted as evidence.
The financial authorities also specified the verification criteria and methods for each newly introduced review requirement in the filing manual. First, when reviewing a sound financial condition, the calculation of the debt ratio must deduct user deposits and similar items from total liabilities. The filing must also separately state the "adjusted total liabilities," which deducts user deposits and similar items.
For social credit, the items to be checked are distinguished by review subject, including operators, controlling shareholders, executives, and representatives. The review will check any history of default, whether the entity is a failed financial institution, whether bank transactions are suspended due to dishonor, any bankruptcy or rehabilitation procedures, and the period elapsed since any business suspension measures.
For organizational and staffing requirements, it will be verified whether four or more personnel are engaged in anti-money-laundering work. The professionalism of the compliance officer will also be reviewed. This includes checking completion of professional training courses, experience in anti-money-laundering work, and possession of relevant certifications. However, concurrent positions may be permitted in consideration of the business form, organizational size, and staffing conditions.
Requirements for IT systems were also specified. While checking security and backup systems, only IT systems that process unique identification information or personal credit information must be located in Korea. When using cloud services, if the server is in a domestic region, the IT system is deemed to be located domestically. The original draft required IT systems to be located in Korea regardless of the type of information processed, but the regulation was eased during the public comment process.
The review method itself will also be strengthened. Previously, the "compliance system" filing items—such as organization and staffing, IT systems, and internal controls—were verified only through submitted documents. However, after the revised law takes effect, since the compliance system is also grounds for rejecting a filing, the financial authorities will substantively review the adequacy of the system and whether it actually operates. If necessary, they plan to conduct on-site inspections to check actual operating conditions.
The change-filing system will also change significantly. Changes related to "controlling shareholders" and the "compliance system" will shift from the current "post-change filing within 14 days" to a "pre-change filing 30 days in advance." Accordingly, operators must file relevant changes in advance with sufficient lead time.
The reference point for calculating deadlines for change filings, which had caused some practical confusion, was also clarified. In principle, the "actual change date" serves as the reference point, but specific criteria were presented for each change-filing item so operators can determine on their own whether they meet the filing deadline. Specifically, for trade names and business locations, the change date on the corporate registry applies; for contact information, the date of actual activation or use applies. For Information Security Management System (ISMS) certification, the certificate receipt date applies, and for real-name deposit and withdrawal accounts, the contract start date is deemed the change date.
As wallet services have diversified recently, the criteria for determining whether non-custodial wallets are subject to virtual asset service provider filing were newly refined. As a rule, businesses that engage in the custody and management of virtual assets as a business must file as virtual asset service providers. However, personal non-custodial wallets and similar cases where the operator does not have exclusive control over private keys can be excluded from the filing requirement.