Trackers
Trackers

AML & KYC in Japan: 2026 Update

AML & KYC in Japan is governed by a layered framework of domestic legislation and international standards, making compliance a serious operational priority for any business active in the Japanese financial system. Japan has strengthened its anti-money laundering regime considerably following scrutiny from the Financial Action Task Force (FATF), and regulated entities now face more demanding customer due diligence, transaction monitoring, and reporting obligations than at any previous point. This guide covers the legal foundations, key obligations, recent reforms, enforcement trends, and practical steps that foreign and domestic businesses need to understand to operate compliantly in Japan.

Legal foundations of AML & KYC in Japan

Japan';s core AML statute is the Act on Prevention of Transfer of Criminal Proceeds, commonly referred to as the Criminal Proceeds Transfer Prevention Act (CPTPA). This law establishes the customer identification and verification obligations that apply to a broad range of designated business operators, including banks, securities firms, insurance companies, money service businesses, real estate agents, and certain professional service providers. The CPTPA is supplemented by the Foreign Exchange and Foreign Trade Act (FEFTA), which governs cross-border transactions and imposes additional screening requirements on international fund flows.

The Financial Services Agency (FSA) is the primary supervisory authority for financial institutions. It issues guidelines, conducts on-site inspections, and has the power to impose administrative sanctions on non-compliant entities. The National Police Agency (NPA) and the Japan Financial Intelligence Unit (JAFIC), which operates under the NPA, receive suspicious transaction reports (STRs) and analyse financial intelligence. JAFIC publishes annual typology reports that regulated entities are expected to consult when calibrating their risk assessments.

A non-obvious requirement for many foreign businesses is that the CPTPA applies not only to traditional financial institutions but also to a wide category of "specified business operators." This includes dealers in high-value goods, postal transfer operators, and certain legal professionals. Foreign companies establishing a branch or subsidiary in Japan that falls within any of these categories must implement a compliant AML programme from the date operations commence, not from the date of any regulatory inspection.

Customer due diligence and KYC requirements

Customer due diligence (CDD) under Japanese law requires regulated entities to verify the identity of customers at the point of account opening or transaction initiation. For individual customers, acceptable identification documents include a My Number Card, a driver';s licence, a passport, or a residence card for foreign nationals. For corporate customers, entities must verify the corporate registration certificate, confirm the identity of the representative, and identify the beneficial owner - defined as any natural person holding more than 25% of voting rights or otherwise exercising effective control.

Enhanced due diligence (EDD) is mandatory for higher-risk relationships. The FSA';s supervisory guidelines specify that EDD applies to politically exposed persons (PEPs), customers from jurisdictions identified as high-risk by FATF, and relationships involving complex ownership structures or unusual transaction patterns. In practice, EDD requires obtaining additional documentation, conducting senior management approval, and applying more frequent periodic reviews.

Simplified due diligence is permitted in limited circumstances for lower-risk customers, such as listed companies on recognised exchanges or certain government entities. However, regulated entities must document the rationale for applying simplified measures and remain alert to changes in the customer';s risk profile.

A common mistake made by foreign-owned entities entering Japan is treating KYC as a one-time onboarding exercise. Japanese law and FSA guidance require ongoing monitoring of customer relationships. Periodic re-verification is expected, particularly when a customer';s circumstances change, when a transaction falls outside the established pattern, or when the entity';s own risk assessment is updated. Failure to maintain current customer records is one of the most frequently cited deficiencies in FSA inspection reports.

Suspicious transaction reporting and record-keeping

Regulated entities in Japan are required to file a suspicious transaction report (STR) with JAFIC whenever a transaction is suspected to involve criminal proceeds or to be connected to terrorist financing. The obligation to report arises from reasonable suspicion, not from certainty. The threshold is intentionally low to encourage proactive reporting, and entities that fail to file when suspicion exists face administrative and potentially criminal liability.

STRs must be submitted electronically through the JAFIC online system. The report must include details of the transaction, the customer, the basis for suspicion, and any supporting documentation. Tipping off - informing the customer that a report has been or may be filed - is prohibited under the CPTPA and can itself constitute a criminal offence.

Record-keeping obligations require regulated entities to retain customer identification records for seven years from the date the business relationship ends. Transaction records must also be kept for seven years from the date of the transaction. These timelines are strictly enforced, and entities that cannot produce records during an FSA inspection face significant regulatory risk.

In practice, many smaller regulated entities - particularly non-bank financial intermediaries and real estate agents - underestimate the administrative burden of maintaining compliant records. Digital record-keeping systems that integrate with transaction monitoring tools are increasingly expected by the FSA as a baseline standard, not a best practice.

If your business is establishing operations in Japan and needs to design an STR workflow or record-keeping architecture that meets current FSA expectations, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.

Recent reforms and the FATF mutual evaluation

Japan underwent a FATF mutual evaluation, the results of which identified significant gaps in the country';s AML framework, particularly in the areas of beneficial ownership transparency, supervision of designated non-financial businesses and professions (DNFBPs), and the effectiveness of STR analysis. In response, the Japanese government and FSA launched a series of legislative and supervisory reforms that have progressively tightened requirements across all regulated sectors.

Among the most significant recent changes is the strengthening of beneficial ownership registration requirements. Amendments to the Commercial Registration Act now require companies to register beneficial ownership information with the Legal Affairs Bureau, making this data accessible to competent authorities. This reform directly addresses the FATF finding that Japan';s corporate transparency mechanisms were insufficient to prevent the misuse of legal entities for money laundering.

The FSA has also revised its supervisory approach, moving from a compliance-focused inspection model to a risk-based effectiveness model. Under the current approach, inspectors assess not only whether policies and procedures exist on paper but whether they are genuinely effective in detecting and preventing financial crime. This shift has significant practical implications: entities with technically compliant documentation but weak implementation are now more likely to receive adverse findings.

Real estate agents and dealers in precious metals and stones - both classified as DNFBPs - have faced increased supervisory attention. These sectors were identified in the FATF evaluation as presenting elevated money laundering risk due to the high value of transactions and historically limited oversight. Entities in these sectors should treat AML compliance as a core operational function, not an administrative formality.

Risk-based approach and internal programme requirements

Japan';s AML framework requires regulated entities to adopt a risk-based approach (RBA) to compliance. This means that the intensity of due diligence, monitoring, and controls must be proportionate to the assessed level of money laundering and terrorist financing risk posed by customers, products, services, delivery channels, and geographic exposures.

A compliant internal AML programme in Japan must include the following elements:

  • A written AML/CFT policy approved by senior management.
  • A designated compliance officer with clear responsibility for AML matters.
  • A documented risk assessment covering the entity';s specific business activities.
  • Training for all relevant staff, conducted at regular intervals.
  • An independent audit or review function to test programme effectiveness.

The FSA expects the risk assessment to be a living document, updated when the business model changes, when new products or services are introduced, or when the regulatory environment shifts. A static risk assessment that has not been reviewed for several years is a red flag during inspections.

Foreign businesses operating in Japan through a subsidiary or branch face an additional layer of complexity: group-level AML policies designed for another jurisdiction may not satisfy Japanese requirements. The FSA expects entities to have Japan-specific documentation and controls, even where a parent company maintains a global compliance programme. Many underestimate the degree of localisation required and discover this only when an inspection is underway.

Scenario one: a European fintech company establishes a payment services subsidiary in Japan. It implements its EU-compliant AML programme and assumes this satisfies Japanese requirements. In practice, the FSA expects Japanese-language policies, Japan-specific risk assessments, and STR procedures calibrated to JAFIC';s reporting system. The entity must localise its programme before commencing regulated activities.

Scenario two: a real estate agency in Tokyo begins working with foreign investors purchasing high-value residential property. Under the CPTPA, the agency is a specified business operator and must conduct CDD on all customers, including beneficial ownership verification for corporate purchasers. Failure to do so exposes the agency to administrative sanctions and reputational risk.

Penalties, enforcement, and practical compliance steps

The consequences of non-compliance with Japan';s AML and KYC requirements range from administrative orders and fines to suspension of business operations and, in serious cases, criminal prosecution. The FSA has demonstrated increasing willingness to use its enforcement powers, and the trend in recent years has been toward more frequent and more severe sanctions for systemic compliance failures.

Administrative measures available to the FSA include business improvement orders, business suspension orders, and licence revocations. These measures are public, meaning that an enforcement action against a financial institution or regulated entity will typically become known to counterparties, correspondent banks, and customers. The reputational consequences of a public enforcement action often exceed the direct financial penalty.

Criminal liability under the CPTPA can attach to individuals, not only to corporate entities. Officers and employees who knowingly facilitate the transfer of criminal proceeds or who wilfully fail to file STRs face personal criminal exposure. This personal liability dimension is often underappreciated by foreign executives managing Japanese operations from overseas.

Practical steps for regulated entities to strengthen their AML & KYC posture in Japan include:

  • Conducting a gap analysis against current FSA supervisory guidelines.
  • Reviewing and updating the entity';s risk assessment to reflect recent regulatory changes.
  • Ensuring beneficial ownership records are complete and current for all corporate customers.
  • Testing the STR filing process to confirm it functions correctly and within expected timeframes.
  • Delivering refresher training to staff on current typologies identified by JAFIC.

To discuss your entity';s current compliance posture or to prepare for an FSA inspection, contact info@vlolawfirm.com. We can assist with documents and filings.

Frequently asked questions

Which businesses in Japan are required to comply with AML and KYC rules?

The CPTPA applies to a broad range of "specified business operators," which includes banks, securities companies, insurance firms, money service businesses, credit card companies, real estate agents, dealers in precious metals and stones, and certain legal and accounting professionals. The scope is wider than many foreign businesses expect. Any entity that falls within a designated category must implement a compliant AML programme from the date it begins regulated activities in Japan, regardless of whether it has received a formal inspection or regulatory communication. Businesses that are unsure whether their activities trigger CPTPA obligations should seek legal advice before commencing operations.

How long does it take to build a compliant AML programme, and what does it cost?

The timeline depends heavily on the complexity of the business and the starting point. A small entity with a straightforward business model and an experienced compliance consultant can typically develop and implement a basic compliant programme within two to three months. Larger or more complex entities - particularly those with multiple product lines, international customer bases, or group-level integration requirements - should allow six months or more. Costs vary significantly: professional fees for programme design and documentation typically start from the low thousands of EUR equivalent, while technology solutions for transaction monitoring and customer screening add further expense. Ongoing costs include staff training, periodic audits, and system maintenance.

What is the difference between a business improvement order and a business suspension order in Japan?

A business improvement order requires the regulated entity to identify the root causes of compliance deficiencies and submit a remediation plan to the FSA within a specified timeframe. It is the more common of the two measures and is typically used for systemic but remediable failures. A business suspension order is a more severe measure that prohibits the entity from conducting some or all of its regulated activities for a defined period. Suspension orders are reserved for serious or repeated violations and carry significant reputational and operational consequences. Both types of order are published by the FSA, making them visible to counterparties and the public. Entities that receive a business improvement order should treat it as a serious warning and engage experienced legal counsel immediately.

Conclusion

Japan';s AML and KYC framework is now among the more demanding in the Asia-Pacific region, driven by FATF recommendations and a more assertive FSA supervisory posture. Regulated entities - whether domestic or foreign-owned - must maintain current, effective, and Japan-specific compliance programmes. The cost of non-compliance, measured in enforcement actions, reputational damage, and personal liability, substantially exceeds the investment required to build a robust programme.

VLO Law Firms advises international clients on AML & KYC matters in Japan. We can assist with compliance programme design, gap analysis, beneficial ownership documentation, STR workflow implementation, and FSA inspection preparation. To request a consultation, contact: info@vlolawfirm.com