From the 20th, screening for digital asset business reporting will be expanded to cover major shareholders, financial condition, organisation and staffing, and IT facilities. If major shareholders or compliance systems change, businesses must file in advance 30 days before the change, instead of filing afterward.
The Financial Intelligence Unit (FIU) and the Financial Supervisory Service said on the 13th they held a briefing in Seoul's Dreamplus Gangnam for digital asset businesses and prospective operators on the revised reporting manual.
The briefing was held to fully revise the reporting manual and provide detailed working-level standards, in line with the Act on Reporting and Using Specified Financial Transaction Information taking effect from the 20th after passing the National Assembly in January.
The revised law expands the scope of criminal history screening at the reporting stage from representatives and executives to major shareholders. It also adds economic crime-related laws, including the Fair Trade Act, to the laws covered by the screening.
The scope of major shareholders will also be widened. It will include not only the largest shareholder and key shareholders holding 10 percent or more of voting shares, but also shareholders who appoint a majority of the chief executive or directors or exercise dominant influence over key decision-making.
Shareholders who are related parties of the largest shareholder will also be subject to screening. If the largest shareholder is a company, the largest shareholder of that company and its representative, among others, will also be included in the reporting 대상. If a major shareholder is overseas or the ownership structure is formed through multiple companies, related materials must be secured in advance.
A business operator's financial condition and social creditworthiness will become screening items. When calculating the debt ratio, user deposits will be excluded from total liabilities. The authorities will check, for each operator and each major shareholder and executive or representative, defaults, whether they fall under troubled financial institutions, histories of bankruptcy or rehabilitation procedures, and histories of business suspension.
Criteria for reviewing organisation and staffing have also been specified. Anti-money laundering staffing will be checked against a benchmark of at least 4 people, and authorities will examine whether the compliance officer has completed professional training, relevant work experience and certifications. It added that dual roles may be allowed in consideration of the business type and organisational scale.
Requirements for IT facilities have also been revised. IT facilities that process unique identification information or personal credit information must be located in South Korea, but if cloud services are used, they will be recognised as domestic facilities if the server region is in South Korea.
Previously, compliance systems such as organisation and staffing, IT facilities and internal control systems were verified mainly based on submitted documents. Going forward, they will be reviewed for actual operation as they are included among reasons for non-acceptance of reporting. On-site inspections are also planned if needed.
The method for reporting changes will also change. Until now, matters related to major shareholders and compliance systems could be reported within 14 days after a change, but going forward they must be filed in advance 30 days before the change.
If items subject to advance reporting are implemented before the FIU's acceptance notice, it may be a violation of the law and could lead to criminal punishment or administrative sanctions. The starting point for change reporting will be based on the actual date of change.
Reporting deadlines are calculated based on the date of change on the corporate registry for the company name and business address, the actual activation or use date for contact information, the date the ISMS certificate is received for Information Security Management System certification, and the contract start date for real-name verified deposit and withdrawal accounts.
Criteria have also been newly 마련 to determine whether non-custodial wallets are subject to reporting. A personal non-custodial wallet in which the operator does not exclusively manage the user's private key may be excluded from reporting.
Authorities said they will determine whether reporting is required by comprehensively assessing whether an operator can transfer digital assets unilaterally, whether it can arbitrarily generate, recognise or decrypt private keys, whether individual private keys and wallet addresses are created for each user, and whether the user is the actual signing party.
Ha Joo-sik (하주식), director for system operation planning at the FIU, said, "The digital asset market has recently grown into a market that broadly affects the national economy and people's economic life and financial markets, so the situation is different from when the reporting system was first introduced in 2021." He added, "To maintain market trust, it is necessary to thoroughly check and screen the soundness of operators and major shareholders from the entry stage."
The FIU and the Financial Supervisory Service plan to finalise and implement the revised reporting manual from the 20th and operate a system for responding to working-level inquiries through associations and other channels.