Anti-Money Laundering (AML) Compliance Lawyer | Understanding Your Obligations and Regulatory Exposure
Summary
Korea regulates money laundering and terrorist financing risk primarily through the Act on Reporting and Using Specified Financial Transaction Information (특정 금융거래정보의 보고 및 이용 등에 관한 법률) and the Act on Regulation and Punishment of Concealment of Criminal Proceeds (범죄수익은닉의 규제 및 처벌 등에 관한 법률). Reporting entities — banks, securities firms, insurers, and since 2021 virtual asset service providers — must run customer due diligence, monitor transactions, and file suspicious transaction reports with the Korea Financial Intelligence Unit (KoFIU). Failure to maintain adequate internal controls can trigger FSS sanctions, business suspension, or referral for criminal prosecution of individuals involved, even where no underlying predicate crime is proven against the company itself.
Administrative · Financial RegulationGoverning law: Act on Reporting and Using Specified Financial Transaction InformationGoverning law: Act on Regulation and Punishment of Concealment of Criminal Proceeds
Anti-Money Laundering (AML) Compliance | Who is a reporting entity and what must they do
Not every business is directly regulated, but the scope of covered entities is broader than most assume, and obligations attach the moment an entity qualifies.
Who counts as a reporting entity
Reporting entities include banks, mutual savings banks, securities and futures firms, insurers, credit-specialized finance companies, and virtual asset service providers (특정 금융거래정보의 보고 및 이용 등에 관한 법률 제2조). Once an entity falls within this list, it must appoint a reporting officer and build internal AML systems regardless of its actual transaction volume.
Customer due diligence duties
Reporting entities must verify customer identity and, where risk indicators exist, the identity of the beneficial owner before or at the time of establishing a transaction relationship (특정 금융거래정보의 보고 및 이용 등에 관한 법률 제5조의2). The depth of verification should scale with the customer's risk profile — a point regulators frequently flag in on-site inspections.
Enhanced due diligence for high-risk customers
Politically exposed persons, customers from high-risk jurisdictions, and unusually large or complex transactions call for enhanced due diligence, including source-of-funds inquiries. Institutions that apply a uniform, low-intensity check across all customers are the ones most often cited in FSS examinations.
The reporting duty is the operational core of Korea's AML system, and it is also where good-faith mistakes most often turn into regulatory findings.
Suspicious Transaction Reports (STR)
Where there is reasonable ground to suspect that assets received in a transaction are criminal proceeds, or that a customer is engaged in money laundering, the entity must report this to KoFIU (특정 금융거래정보의 보고 및 이용 등에 관한 법률 제4조). The threshold is 'reasonable suspicion,' not certainty, so under-reporting out of caution is itself a compliance risk.
Currency Transaction Reports (CTR)
Cash transactions above a set threshold amount must be reported automatically, regardless of suspicion, under the same Act (특정 금융거래정보의 보고 및 이용 등에 관한 법률 제4조의2). CTR is a mechanical trigger, which makes it easier to audit for compliance but also easier to inadvertently miss through system errors.
Tipping-off is prohibited
Disclosing the fact that an STR has been or will be filed to the customer or any third party is itself prohibited (특정 금융거래정보의 보고 및 이용 등에 관한 법률 제4조 제6항). This provision often surprises frontline staff who feel obligated to explain an account freeze to an anxious customer.
Anti-Money Laundering (AML) Compliance | Building and defending an internal AML system
When regulators find a gap, the first question is not just whether a single report was missed, but whether the institution's internal control system was adequate in design and operation.
Required internal control elements
Reporting entities must establish internal control standards covering customer risk assessment, employee training, independent audit of the AML program, and a designated reporting officer with sufficient authority (특정 금융거래정보의 보고 및 이용 등에 관한 법률 제5조). A written policy that is never actually followed in practice offers little protection during an inspection.
FSS on-site and off-site examinations
The Financial Supervisory Service conducts periodic and targeted examinations of AML systems, and can request transaction logs, training records, and STR decision memos going back several years. Preparing a defensible file — showing not just outcomes but the reasoning behind each due diligence decision — is usually more valuable than reacting after a deficiency notice arrives.
Sanctions for institutional failures
Findings of inadequate internal controls or repeated reporting failures can lead to corrective orders, fines, or restrictions on business operations, and in serious cases referral of individual officers for potential criminal liability. Because sanctions can attach to the institution and to specific compliance officers separately, the two exposures need to be assessed and defended distinctly.
Anti-Money Laundering (AML) Compliance | AML obligations for virtual asset service providers
Since the 2021 amendment brought virtual asset service providers into the reporting entity framework, exchanges and related businesses face AML obligations layered on top of separate registration requirements.
Registration as a prerequisite
Virtual asset service providers must first register with KoFIU, which requires (among other things) an information security management certification and, for entities handling KRW transactions, a real-name verification arrangement with a bank (특정 금융거래정보의 보고 및 이용 등에 관한 법률 제7조). Operating without registration is itself a separate offense, independent of any AML failure.
Travel rule and wallet screening
Virtual asset transfers above a certain threshold require the originating and beneficiary VASPs to exchange identifying information about the parties, mirroring the international 'travel rule.' Screening counterparties and wallet addresses against sanctions and risk lists has become a distinct compliance workstream for exchanges.
Anti-Money Laundering (AML) Compliance | From initial diagnosis to ongoing compliance support
1
Initial consultation and risk scoping We review your business model, customer base, and transaction types to identify whether — and to what extent — AML obligations apply, and flag any immediate red flags such as pending reports or upcoming examinations.
2
Gap analysis of existing controls We compare your current customer due diligence procedures, reporting officer structure, and internal audit practices against statutory requirements and recent FSS examination trends.
3
Policy and procedure drafting We help draft or revise internal control standards, STR/CTR decision trees, and training materials so that day-to-day staff decisions are documented and defensible.
4
Regulatory response support Where an FSS examination, KoFIU inquiry, or criminal referral is already underway, we assist with document production, examiner interviews, and drafting responses to deficiency findings.
5
Ongoing advisory retainer For institutions that need continuing support, we provide periodic policy updates and on-call advice for edge-case transactions that staff are unsure how to classify.
Anti-Money Laundering (AML) Compliance | How advisory fees are calculated
Initial consultation fee A flat fee for the initial review of your business structure and a preliminary assessment of applicable obligations, scoped by the complexity of the business and number of jurisdictions or products involved.
Gap analysis and documentation fee Calculated based on the volume of policies and procedures to be reviewed or drafted, and whether on-site interviews with compliance staff are required.
Regulatory response fee For active FSS examinations or KoFIU inquiries, fees are typically set based on the expected scope of document review and the number of examiner or investigator interactions anticipated.
Retainer arrangement Ongoing advisory relationships are usually structured as a monthly or quarterly retainer covering a set number of advisory hours, with additional work billed separately.
Disbursements Separate from professional fees, costs such as translation of foreign-language documents or expert review may be billed at actual cost.
※ Costs vary depending on case complexity and specific circumstances; exact fees will be provided during consultation. No specific outcome is guaranteed.
Does your business fall within one of the statutory categories of financial companies or VASPs under Article 2?
Have you registered with KoFIU if you handle virtual assets?
Have you appointed a designated reporting officer with real authority?
Do you have written internal control standards, or only informal practices?
2️⃣ Customer Due Diligence Health Check
Do you verify beneficial ownership for corporate customers, not just the account holder?
Does your due diligence intensity actually change for high-risk customers, or is it a flat checklist for everyone?
Are politically exposed persons flagged and reviewed separately?
Is source-of-funds documentation retained and retrievable years later?
3️⃣ Reporting Discipline
Do frontline staff know the difference between an STR and a CTR trigger?
Is there a documented decision memo for every case where an STR was considered but not filed?
Have staff been trained on the tipping-off prohibition?
Is there a process for escalating ambiguous cases to the reporting officer promptly?
4️⃣ Preparing for an FSS Examination
Can you produce training records and audit logs for the past several years on short notice?
Have you conducted an internal mock examination or audit recently?
Do you know which prior deficiency findings, if any, remain unresolved?
Is there a clear internal chain of responsibility if an examiner identifies a gap?
Frequently Asked Questions
Q. Does AML law apply to my business if I'm not a bank?
A. AML reporting duties apply specifically to entities listed as 'reporting entities' under Article 2 of the Act on Reporting and Using Specified Financial Transaction Information (특정 금융거래정보의 보고 및 이용 등에 관한 법률 제2조), which includes banks, securities firms, insurers, and virtual asset service providers. If your business is outside that list, you may still face exposure indirectly, for example if you receive funds later found to be criminal proceeds, under separate concealment-of-proceeds rules.
Q. What triggers a suspicious transaction report?
A. An STR is required whenever there is reasonable ground to suspect that assets involved in a transaction are related to criminal proceeds or money laundering (특정 금융거래정보의 보고 및 이용 등에 관한 법률 제4조). This is a lower threshold than proof, so institutions are generally advised to document their reasoning even when they decide not to file.
Q. Can I tell a customer that we filed an STR about their account?
A. No. Disclosing the existence or contents of an STR to the customer or a third party is itself prohibited under the tipping-off provision (특정 금융거래정보의 보고 및 이용 등에 관한 법률 제4조 제6항). Staff should be trained to handle customer inquiries about frozen or delayed transactions without confirming or denying an STR filing.
Q. What happens during an FSS AML examination?
A. The Financial Supervisory Service typically requests transaction records, internal policy documents, training logs, and STR/CTR decision memos, and may interview compliance staff. Findings can range from informal guidance to corrective orders, fines, or referral of specific individuals for criminal investigation, depending on severity.
Q. Do virtual asset exchanges have the same AML duties as banks?
A. Since the 2021 amendment, virtual asset service providers are included as reporting entities and carry similar customer due diligence and reporting duties, but they also face additional requirements such as KoFIU registration and real-name account arrangements (특정 금융거래정보의 보고 및 이용 등에 관한 법률 제7조). Travel rule compliance for virtual asset transfers adds a further layer specific to this sector.
Q. Is my company liable if an employee fails to file a required report?
A. Both the institution and the individual employee can face separate consequences — the institution may face corrective orders or fines for inadequate internal controls, while an employee who deliberately concealed a required report could face individual liability. Whether liability attaches often depends on whether the institution's internal control system gave the employee clear guidance in the first place.
Q. What is the difference between an STR and a CTR?
A. A CTR is filed automatically whenever a cash transaction exceeds the statutory threshold amount, regardless of suspicion (특정 금융거래정보의 보고 및 이용 등에 관한 법률 제4조의2). An STR, by contrast, depends on a judgment call — reasonable suspicion that the funds are connected to a crime — and has no fixed monetary threshold.
Q. Can a small business unintentionally violate AML rules just by accepting large cash payments?
A. If the business is not a statutory reporting entity, it is not directly subject to STR/CTR filing duties, but it can still face criminal exposure separately if it knowingly receives or helps conceal criminal proceeds, under the Act on Regulation and Punishment of Concealment of Criminal Proceeds. Businesses that regularly handle large cash volumes should still consider basic due diligence practices even without a formal AML obligation.
Q. How far back can regulators look when reviewing our AML compliance?
A. Examinations commonly request several years of records, and the exact retrospective scope depends on the examiner's mandate and any specific red flags identified. Institutions with weak document retention practices are often at a disadvantage simply because they cannot reconstruct the reasoning behind past decisions.
Q. We received a KoFIU inquiry letter — what should we do first?
A. Before responding, it is worth reviewing exactly what records and explanations are being requested and cross-checking them against your internal files to identify any gaps before regulators do. Early engagement with counsel at this stage, rather than after a formal deficiency finding, generally gives more options for shaping the institution's response.
법무법인 프런티어(이하 “사무소”)는 개인정보보호법에 따라 정보주체의 개인정보 및 권익을 보호하고 개인정보와 관련된 정보주체의 고충을 신속하고 원활하게 처리하기 위하여 본 개인정보 처리방침을 수립·공개합니다.
제 1 조 수집하는 개인정보의 항목, 목적, 방법
제 2 조 개인정보의 처리 및 보유기간
제 3 조 개인정보의 제3자 제공
제 4 조 개인정보 처리업무의 위탁
제 5 조 정보주체의 권리·의무 및 그 행사방법
제 6 조 개인정보의 파기
제 7 조 의견수렴 및 불만처리
제 8 조 개인정보 처리방침의 변경
제 9 조 개인정보의 안전성 확보 조치
제 1 조 (수집하는 개인정보의 항목, 목적, 방법)
① 게시판 글 작성 시 필수 항목에 대한 수집목적은 ‘별도의 구체적 상담을 위하여’이며 수집항목은 ‘이름, 이메일, 연락처’입니다.
② 전항 외에 고객의 서비스 이용 과정이나 요청 사항 처리 과정에서 ‘IP주소, 접속로그, 단말기 및 환경정보, 서비스 이용기록, 쿠키’와 같은 정보들이 자동으로 수집 및 저장될 수 있으며, 이 때의 수집목적은 ‘사용자 홈페이지 이용, 사이트 이용에 대한 문의 민원 등 고객 고충 처리’입니다.
③ 사무소는 ‘홈페이지 고객 문의/고충 처리 시 전화 또는 인터넷을 통한 상담’과 같은 방법으로 개인정보를 수집합니다
제 2 조 (개인정보의 처리 및 보유기간)
관계법령의 규정에 따라 개인정보를 보존하여야 하는 의무가 있는 경우가 아닌 한, 정보주체의 개인정보는 원칙적으로 해당 개인정보의 처리목적이 달성될 때까지 보유 및 이용되며, 그 목적이 달성되면 지체 없이 파기됩니다.
제 3 조 (개인정보의 제3자 제공)
사무소는 정보주체의 개인정보를 본 처리방침에서 명시한 목적에 한해서만 처리하며 정보주체의 사전동의가 있는 경우 또는 개인정보보호법 등 관계법령의 규정에 의거한 경우에만 개인정보를 제3자에게 제공합니다. 사무소는 현재 개인정보를 제3자에게 제공하지 않고 있습니다.
제 4 조 (개인정보 처리업무의 위탁)
사무소는 현재 귀하의 개인정보 보호를 위해 귀하의 개인정보를 직접 취급 관리하고 있습니다. 단, 향후 보다 전문적인 서비스를 제공하기 위하여 제3의 전문기관에 귀하의 정보를 위탁할 필요가 있다고 판단되는 경우, 귀하의 사전 동의 하에 개인정보에 대한 취급을 위탁할 수 있습니다.
제 5 조 (정보주체의 권리·의무 및 그 행사방법)
① 정보주체는 개인정보보호법 등 관계법령이 정하는 바에 따라 사무소에 대해 개인정보의 열람, 정정 및 삭제, 처리정지 요구 등 개인정보 보호 관련 권리를 행사할 수 있습니다.
② 제1항에 따른 권리행사는 정보주체의 법정대리인이나 위임을 받은 사람을 통해서도 할 수 있습니다. 다만, 이 경우에는 개인정보보호법 시행규칙에 따른 위임장을 사무소에 제출하여야 합니다.
③ 사무소는 정보주체의 권리행사에 대하여 개인정보보호법 등 관계법령이 정하는 바에 따라 지체 없이 조치하겠습니다.
제 6 조 (개인정보의 파기)
① 사무소는 원칙적으로 개인정보의 처리목적이 달성된 경우 등 그 개인정보가 불필요하게 되었을 때에는 지체 없이 해당 개인정보를 파기합니다.
② 사무소가 관계법령의 규정에 따라 개인정보를 파기하지 아니하고 보존하여야 하는 경우에는 해당 개인정보 또는 개인정보파일을 다른 개인정보와 분리해서 저장·관리 합니다.
③ 사무소는 파기사유가 발생한 개인정보를 선정하여 개인정보 보호책임자의 승인을 받아 해당 개인정보를 파기합니다.
④ 사무소는 파기하여야 할 개인정보가 전자적 파일 형태인 경우 복원이 불가능한 방법으로 영구 삭제하며, 이외의 기록물, 인쇄물, 서면, 그 밖의 기록매체인 경우 파쇄 또는 소각합니다.
제 7 조 (의견수렴 및 불만처리)
정보주체는 개인정보 보호 관련 문의, 불만처리, 피해구제 등에 관한 사항을 아래 개인정보 보호책임자 또는 담당부서에 문의하실 수 있습니다. 사무소는 정보주체의 문의에 대하여 신속하고 충분한 답변을 드릴 것입니다.
개인정보 보호 책임자 : 변호사
연락처 : 02.
제 8 조 (개인정보 처리방침의 변경)
사무소의 개인정보 처리방침은 관련 법령, 지침 및 사무소 내부규정에 따라 변경될 수 있으며, 개인정보 처리방침이 변경되는 경우 관련 법령이 정하는 방법에 따라 공개합니다.
제 9 조 (개인정보의 안전성 확보 조치)
사무소는 개인정보의 안전성 확보를 위해 다음과 같은 조치를 취하고 있습니다.
관리적 조치 : 내부관리계획의 수립 및 시행, 구성원에 대한 정기적인 개인정보 보호교육 등
기술적 조치 : 개인정보처리시스템 등의 접근권한 관리, 접근통제시스템 설치, 고유식별정보 등의 암호화, 보안프로그램의 설치 등
물리적 조치 : 전산실, 자료보관실 등 개인정보 보관장소에 대한 접근통제