
If a no-fault compensation system for voice phishing is introduced, financial institutions such as banks and mutual credit unions are estimated to bear an annual burden of up to 280 billion won. However, analyses suggest that even if the system is implemented, its effect on preventing fraud will be limited. In the UK, which financial authorities used as a benchmark case, while the refund rate itself increased after the system was introduced, its effectiveness in reducing the scale of financial fraud was limited. Consequently, experts agree that regulations mandating compensation liability cannot be a fundamental solution to financial fraud.
According to reports from the financial sector and the National Assembly on the 15th, the amount domestic financial institutions would need to compensate under a no-fault compensation system for voice phishing is projected to reach up to 281.1 billion won annually.
Currently pending in the National Assembly are two amendment bills on the Communication Fraud Victim Refund Act containing provisions for a no-fault compensation system for voice phishing, proposed by Kang Jun-hyun and Cho In-cheol of the Democratic Party of Korea. The Kang Jun-hyeon (Rep.) bill sets the compensation cap at 0.5 billion won or less, while the Jo In-cheol (Rep.) bill sets it at 0.1 billion won or more. The Financial Services Commission (FSC) plans to compromise between the two bills by establishing specific statutory compensation standards within a range of 0.1 billion won to 0.5 billion won.
According to data submitted by the FSC to the National Assembly, if the cap is set at 0.5 billion won, financial institutions such as banks and mutual credit unions are estimated to bear compensation costs totaling 281.1 billion won. This estimate reflects the assumption that victims with damages exceeding 0.5 billion won (2,160 people based on 2024 voice phishing statistics) would receive 0.5 billion won each, while victims with damages of 0.5 billion won or less would receive full compensation. If the cap is set at 0.1 billion won, compensation payments would amount to 109.8 billion won.
While the introduction of a compensation liability system could impose financial burdens on financial institutions ranging from 109.8 billion to 281.1 billion won, the effect on preventing financial fraud in the UK, which proactively introduced the system, was minimal. The UK introduced the so-called "APP Fraud Compensation Scheme" in 2024, mandating that financial institutions must compensate victims for losses resulting from payment authorization push (APP) fraud. It is known that the FSC benchmarked the UK when designing this system. Previously, Financial Commission Chairman Lee Eung-won mentioned at a press conference last year, "We plan to revise the Communication Fraud Victim Refund Act," and added, "The no-fault compensation liability for voice phishing is also being adopted in cases like the UK."
In the UK, financial institutions must compensate victims by sharing the loss between the sending and receiving banks within a limit of 85,000 pounds (approximately 160 million won) if they determine that the victim was not grossly negligent. Financial institutions can only avoid compensation liability in extremely exceptional cases, such as when the victim participated in the fraud or intentionally ignored repeated warnings from the bank. In cases leading to consumer disputes, the compensation cap can rise to a maximum of 430,000 pounds (approximately 780 million won).
With compensation made mandatory, the refund rate relative to financial fraud losses naturally improved. According to a research report by the UK's Payment Systems Regulator (PSR), the regulatory body, the rate rose from 54% (April 2023 to September 2024) before the system was introduced to 65% (January to September 2025) after, an increase of 11 percentage points (P).
However, the scale of financial fraud losses actually increased. According to the annual report published by UK Finance, a local private financial industry association, the amount of APP financial fraud losses in 2025 reached 576.4 million pounds, a 19% increase year-on-year. In terms of number of cases, it also rose by 7% to 248,070 cases. APP fraud losses through FPS (Faster Payments Service) and CHAPS (Clearing House Automated Payment System), which are mandatory compensation targets, increased by 20% and 11%, respectively.
While the effectiveness remains uncertain, the costs financial institutions will incur may exceed expectations. UK financial institutions are estimated to face annual administrative costs of approximately 44 million to 576.4 million pounds (80 billion to 100 billion won) for fraud prevention, complaint and dispute management, reporting, and regulatory compliance.
Expert analyses also reaffirm that a no-fault compensation liability system cannot be a fundamental solution. The UK Finance report noted that while the increase in refund rates had an effect on victim relief, it did not prevent fraud from occurring.
Kim Na-yul, a research fellow at the Financial Research Institute, pointed out in a December report last year that "after introducing the mandatory compensation system, criminal methods have become more organized and large-scale." He added, "While strict compensation liability regulations targeting payment service providers such as banks may yield some effects based on the UK case," he also stated, "This confirms the importance of preventive systems that block fraudsters' access routes through digital platforms and communication networks, while acknowledging that it cannot be a fundamental solution."

Instead of imposing no-fault compensation liability on financial institutions for voice phishing losses, an alternative approach is emerging to establish a joint fund similar to the "New Leap Fund" to relieve victims. This structure involves not only financial institutions but also other entities playing roles in voice phishing prevention and investigation, such as telecommunications companies and the government, jointly contributing resources, with the fund providing priority compensation to victims. It is expected that victim relief will be swift and responsibility will not be concentrated on a specific industry.
According to reports from the financial sector on the 15th, establishing a new "Voice Phishing Victim Compensation Fund" with contributions from the financial, telecommunications, and public sectors is gaining attention as an alternative to the no-fault compensation liability system. Specifically, a structure that establishes a separate legal entity to bear resources, similar to the New Leap Fund launched last year, is gaining momentum.
The core of the joint fund lies in contributions from financial institutions, telecommunications companies, and the government, which are directly or indirectly involved in voice phishing incidents, according to their respective roles. For financial institutions and telecom companies, contribution ratios will be determined by analyzing how much fault existed in past voice phishing accidents. In particular, as seen in the case of the New Leap Fund, which contributed 400 billion won, government funds can also be injected to ensure initial fund stability.
In the future, contribution ratios will reflect heavily on industries where negligence or lapses in internal controls are confirmed in incidents after the fund begins operations. The less an industry fulfills its role in preventing accidents, the greater its burden on the fund becomes. This approach offers a way to avoid concerns about telecommunications companies "free-riding," which is cited as the biggest drawback of the no-fault compensation liability system.
Regarding government funding, plans are being discussed to prioritize the use of recovered criminal proceeds and related penalties for the fund. Creating a structure where recovered funds are reinvested into the fund would enable continuous victim relief. It also addresses equity concerns by reducing the possibility that costs are passed on to citizens who have not suffered voice phishing losses.
To operate the fund, it appears necessary to establish a separate legal entity, similar to the New Leap Fund case. The New Leap Fund is managed independently by Korea Asset Management Corporation, supervised by the Financial Services Commission (FSC), which established a "New Leap Fund" corporation to handle fund management and long-term delinquent debt acquisition.
In particular, if a separate legal entity is established, it becomes possible to compensate victims first and then pursue recovery of the funds. By setting up a dedicated organization for recovery, compensation can be followed by efforts to recover losses from not only criminals but also financial institutions, telecommunications companies, and account holders who bear responsibility for negligence or management lapses in the incident. In contrast, under the no-fault compensation liability system, while financial institutions gain claims against voice phishing organizations, they lack means to recover payments, leading some within the financial sector to raise concerns about "breach of trust."
There are also clear advantages for victims. First, the time required until compensation is received is expected to decrease. Under the no-fault liability system, each financial institution must go through different internal opinion procedures, but if a fund corporation is established, compensation can be made according to unified procedures. Additionally, equity issues arising from receiving different compensations for similar losses due to varying compensation standards across financial institutions could be reduced.
A financial sector official stated, "If a fund corporation is established, recovery methods will diversify, including active lawsuits against overseas criminal organizations," and added, "Taking into account contribution ratios by institutional investors, stakeholders should participate to share responsibilities, ensuring that not only victim compensation but also post-incident measures are not neglected."