주메뉴바로가기본문바로가기
비즈한국 비즈한국

Toss Bank receives "Institutional Caution" and fines over 200 million won in first regular FSS inspection

[비즈한국] Toss Bank has been issued an "Institutional Caution" and fined over 200 million won following its first regular inspection by the Financial Supervisory Service (FSS). The disciplinary action was taken due to violations including failure to report electronic financial accidents, mismanagement of financial transaction information, and insufficient control during IT operations. Additionally, the bank was hit with 57 counts of "management cautions" and "requests for improvement." As Toss Bank’s internal control system—which was also under scrutiny following a large-scale embezzlement case last year—comes back into the spotlight, critics argue that internet-only banks that have grown rapidly must strengthen accident prevention and risk management.

According to the results of its first regular inspection released by financial authorities, Toss Bank has been issued an Institutional Caution and fines. Photo = Reporter Park Jung-hoon

The FSS recently disclosed the results of its first regular inspection of Toss Bank. According to the disclosure document regarding sanctions, more than eight violations were discovered at Toss Bank during the inspection period from October 2021 to the end of 2024. The FSS imposed an institutional caution, fines totaling 245.2 million won, and disciplinary actions such as cautions and salary reductions on 11 employees involved in the violations.

The regulations violated by Toss Bank include the Act on Real Name Financial Transactions and Confidentiality (Real Name Financial Act), the Special Act on the Prevention of Loss Caused by Telecommunications-based Financial Fraud (Telecommunications Financial Fraud Refund Act), the Banking Act, the Electronic Financial Transactions Act, and the Credit Information Use and Protection Act.

Specifically, there were cases where the bank violated the Electronic Financial Transactions Act by failing to notify authorities and customers of financial accidents, such as interest rate calculation errors and account balance display errors that occurred during the development and application of lending and deposit interest rate programs. Between October 2021 and December 2024, eight electronic financial accidents occurred; Toss Bank failed to notify customers of the cause and processing results for seven of those cases, and reported one case with a delay.

There was also an incident where an transfer error occurred because a staff member violated supervision regulations during work related to the information processing system. On May 27, 2024, while expanding storage devices for its core banking system (the system that processes financial transactions), Toss Bank outsourced the work; however, the bank's supervisor failed to verify the work contents, leading to a transfer accident. As a result, 8,857 transfers (totaling approximately 2.4 billion won) were not processed between 11:12 PM on May 27 and 12:21 AM on May 28, 2024.

Banks are required to post changes to electronic financial transaction terms and conditions one day before they take effect and notify customers, but Toss Bank failed to comply. Between April 2022 and October 2023, Toss Bank changed its terms related to electronic financial transactions but failed to notify customers four times, and in one instance, posted the changes to its website with a delay.

There were also violations regarding the notification of information provision. Under the Real Name Financial Act, when a bank provides customer financial transaction information to entities like courts or the National Tax Service, it must notify the account holder in writing of the details, purpose of use, the recipient, and the date of provision. However, Toss Bank delayed such notifications for 1,289 cases until the end of September 2024. Furthermore, while transaction information must be recorded and managed in a standard format, it was found that for more than 50,000 cases up until February 2023, the records were either missing from the management ledger or were incorrectly entered.

It appears there are more violations beyond those explicitly listed in this sanction. The FSS noted in the document that "some matters currently undergoing separate processing will be disclosed at a later date." An FSS official stated, "We informed the bank of the matters that could be processed first, and there are still a few matters that require more time."

A significant number of issues were also pointed out under "Management Cautions and Improvements," which are non-disciplinary measures. These are administrative guidance measures that are issued not because of legal violations, but to advise the institution to exercise caution or voluntarily improve areas where management vulnerabilities exist. In this regular inspection, the FSS notified Toss Bank of 22 management cautions and 35 improvement requests. Even considering that this period included the bank's early settlement phase, there were nearly 60 items requiring improvement.

Kakao Bank, an internet-only bank, is awaiting the results of its second regular inspection conducted in 2025. Photo = Reporter Park Jung-hoon

Regarding the results of its first regular inspection, Toss Bank stated that it has already addressed most of the issues. Toss Bank stated, "We respect and humbly accept the resolution of the Financial Services Commission," adding, "Most of the pointed-out issues were procedural or IT-related matters from the early stages of our launch, and a significant portion were already corrected during the inspection process. We will continue to strengthen our internal control and consumer protection systems."

Meanwhile, with the institutional caution and numerous management cautions and improvement requests issued to Toss Bank, critics point out that even internet-only banks, which were once considered relatively safe, need to strengthen internal controls. In particular, Toss Bank has a history of a large-scale embezzlement incident in May 2025, a first for the industry. In that case, a team leader from the finance department diverted approximately 2.786 billion won from the bank's corporate account to a personal account. Although no general customers were harmed, it raised questions about the system, as a single individual was able to transfer such a substantial amount of company money.

The inspection results of other internet-only banks are also drawing attention. Kakao Bank was the first among internet-only banks to undergo a regular inspection by financial authorities in 2021, and it was issued an institutional caution and fined for violating the ban on credit offerings to major shareholders, such as lending hundreds of millions of won to an affiliate's employees. Kakao Bank's second regular inspection took place last year, but the results have not yet been released. It is known that the FSS focused on the improvement of violations found in previous inspections, internal control systems, and IT risks. K-Bank was included in this year's financial sector regular inspections, but the inspection is currently being delayed due to an increase in unscheduled inspections regarding urgent pending issues for the authorities.

In April, the FSS held a meeting with the Chief Information Officers (CIOs) of the three internet-only banks, Kakao Pay, and Toss Securities, emphasizing IT-related internal controls and consumer protection measures. Lee Jong-oh, Assistant Governor of the FSS's Digital and IT sector, emphasized, "You must build IT stability and accident prevention systems at a level commensurate with your growth scale," adding, "Computer accidents are occurring due to a lack of basic controls, so please strive to prevent similar accidents through autonomous control activities such as IT sector audits."

This article was automatically translated by AI. There may be errors compared to the original Korean article.
심지영 기자

금융·가상자산·핀테크·투자 업계 중심으로 취재하고 있습니다. 언제든 제보주세요.

jyshim@bizhankook.com
저작권자 ⓒ 비즈한국 무단전재 및 재배포 금지