Japan FSA's Revised AML/CFT Guidelines (March 2026): The Risk-Based Era
Japan's FSA AML/CFT guideline revisions took effect 31 March 2026: risk-based approach, STR analytics, board accountability — and what compliance teams must do.

Japan's Financial Services Agency (FSA) has raised its anti-money-laundering expectations. Revised AML/CFT guidelines took effect on 31 March 2026, sharpening the risk-based approach Japanese financial institutions must operate under — with sharper expectations around outsourcing, technology, transaction monitoring, suspicious-transaction analytics, and direct senior-management accountability. The guidelines also land alongside a separate reform: a revision of the Act on Prevention of Transfer of Criminal Proceeds that will make IC-chip-based identity verification mandatory for remote account openings from April 2027. Here's what changed, who is affected, and what to do about it.
The short version
- The FSA's revised AML/CFT guidelines took effect 31 March 2026, sharpening the risk-based approach: institutions must run self-directed risk assessments and design their own mitigation, not just follow templates.
- New obligations cover outsourcing, technology adoption and transaction monitoring, and suspicious-transaction-report data must be broken down by country and by customer attribute.
- Regulators get access to board-level AML/CFT reports, and senior management is directly accountable — AML is no longer delegable to the compliance back office.
- The revisions align Japan with FATF standards after effectiveness gaps were flagged in FATF's 2021 mutual evaluation.
- On the horizon: from April 2027, IC-chip-based identity verification becomes mandatory for non-face-to-face account openings, and submitting photos or photocopies of ID documents will be outlawed.
A note on sources. This article is current as of July 2026 and draws on publications from Japan's FSA, JAFIC and the Digital Agency, together with reporting from The Japan Times and Biometric Update. Regulations evolve — if you spot something that has changed, let us know at didit.me/contact.
Why the FSA moved: the FATF 2021 backdrop
The trigger for this revision cycle is not mysterious. FATF's 2021 mutual evaluation of Japan flagged effectiveness gaps — the framework existed on paper, but the watchdog wanted evidence that institutions actually understood their own risks and acted on them. The March 2026 guideline revisions are Japan's structural answer: they close the distance between Japanese supervisory practice and FATF standards by demanding demonstrable effectiveness, not documented procedure.
The statutory baseline hasn't changed. Financial institutions must still verify customer identity, retain records for seven years, and file suspicious transaction reports (STRs) with JAFIC, Japan's financial intelligence unit. What has changed is everything wrapped around that baseline: how risk is assessed, who is answerable, and how much analytical depth the regulator expects.
What changed on 31 March 2026
A sharpened risk-based approach
The centerpiece is a genuinely self-directed risk-based approach. Institutions are expected to run their own risk assessments — mapping their specific products, customer base, geographies and delivery channels — and then design mitigation proportionate to what they found. A generic risk matrix copied from an industry template is exactly the pattern this revision is built to end: if your assessment could describe any bank in Japan, it doesn't describe yours.
New obligations: outsourcing, technology and transaction monitoring
Three operational areas get explicit treatment, and each carries a concrete implication for how compliance teams work day to day:
- Outsourcing. Many institutions rely on third parties for screening, verification or monitoring — and the revised guidelines set explicit supervisory expectations for how those arrangements are governed. The practical move: inventory every outsourced AML/CFT function you have, and make sure you can evidence how you oversee each vendor, because "our provider handles that" is not a defensible answer.
- Technology adoption. The guidelines speak directly to how institutions adopt technology in their AML programs. The practical move: reassess whether your current tooling — manual review queues, batch overnight screening, image-based document checks — still matches the risk profile your own assessment describes, and document the reasoning behind each technology choice so it stands up to scrutiny.
- Transaction monitoring. Monitoring is now framed as an obligation to get right, not a box to tick. The practical move: recalibrate scenarios and thresholds against your institution's own risk assessment rather than vendor defaults, since the risk-based approach makes institution-specific tuning the standard.
For the precise wording of each obligation, go straight to the FSA's published guideline text — this article summarizes direction, not statutory language.
STR analytics by country and customer attribute
Suspicious-transaction-report data must now be broken down by country and by customer attribute. That turns STR filing from a throughput exercise into an analytical one: institutions need reporting pipelines that can slice suspicious activity by origin geography and customer segment, and they should expect that data to be read as a measure of how well they understand their own exposure.
Boards on the hook
Two governance changes travel together. Regulators gain access to board-level AML/CFT reports, and senior management is made directly accountable for the program. In combination, they mean AML has to be a standing board-visible topic with real management information behind it — risk-assessment results, monitoring performance, STR analytics — rather than an annual compliance summary. If the board pack can't show what the institution's money-laundering risk looks like this quarter, that is now a governance finding, not a paperwork gap.
The compliance timeline: 2025 → 2027
The guideline revision is the middle act of a three-year sequence reshaping Japanese AML compliance:
| When | What happens | Who is affected |
|---|---|---|
| August 2025 | Electronic Payment Instrument Service Providers (EPISPs) brought fully into AML scope, including Travel Rule obligations | Stablecoin and electronic-payment-instrument businesses |
| Mid-January 2026 | Verification becomes available via JPKI using the My Number card, and by matching an ID's IC-chip digital data with the holder's facial image | Institutions onboarding customers remotely |
| 31 March 2026 | Revised FSA AML/CFT guidelines take effect | Banks and financial institutions under FSA supervision |
| April 2027 | IC-chip-based identity verification becomes mandatory for non-face-to-face account openings; submitting photos or photocopies of ID documents is outlawed | All banks and financial institutions opening accounts remotely |
Crypto and stablecoins: EPISPs and the Travel Rule
The August 2025 entry deserves its own note. By bringing EPISPs fully into scope — Travel Rule included — Japan pulled stablecoin and electronic-payment businesses into its AML/CFT regime. Crypto-adjacent firms serving Japan should read the March 2026 guidelines as their supervisory weather forecast too, not just the banks'.
April 2027: the end of photo-based remote onboarding
The most visible change for customers arrives last. Under the revised Act on Prevention of Transfer of Criminal Proceeds, from April 2027 remote applicants must have the embedded IC chip of their My Number card or driver's licence read — because forged and counterfeit IDs are too hard to detect from images alone.
| Remote verification method | Today | From April 2027 |
|---|---|---|
| Uploading a photo of an ID document | Accepted | Outlawed |
| Submitting a photocopy of an ID document | Accepted | Outlawed |
| Reading the ID's embedded IC chip (My Number card or driver's licence) | Available — JPKI and chip-plus-face-match rails live since mid-January 2026 | Mandatory |
The market is already moving: one major Japanese provider reported IC-chip-based checks growing 1.8x to 14 million, within a total of more than 60 million verifications. Institutions that wait until early 2027 to rebuild onboarding will be migrating under deadline pressure while their competitors are already running chip-first flows.
Where Didit helps: Japan's shift from photo-based checks to chip-based verification maps directly onto capabilities Didit already runs globally. NFC chip reading — a pricing line item under User Verification at $0.15 — reads the embedded chip of chip-equipped identity documents, and the core KYC bundle ($0.33 per successful check: ID Verification, Passive Liveness, Face Match 1:1, IP Analysis, with 500 free core-KYC checks per month) covers the biometric face-match layer the new Japanese rules emphasize. For the FSA's risk-based expectations, AML Screening ($0.20 per check across 1,300+ lists, with ongoing monitoring at $0.07 per user per year) and Transaction Monitoring support the screening and monitoring side of the program. Coverage spans 220+ countries and 14,000+ document types with sub-2s inference. See how this fits Japan's criminal-proceeds-act framework on Didit's Japan solutions page.
What compliance teams should do now
A practical sequence between now and April 2027:
- Rerun your risk assessment as if the FSA will read it — because it can. Make it institution-specific: your products, your corridors, your customer segments.
- Map your outsourcing. List every third party performing an AML/CFT function and attach oversight evidence to each.
- Recalibrate transaction monitoring against that risk assessment, and document why each scenario and threshold exists.
- Build STR analytics by country and customer attribute into your reporting pipeline now, so the breakdowns exist before anyone asks for them.
- Put AML on the board agenda with real management information — governance access and senior-management accountability are now part of the supervisory toolkit.
- Plan the IC-chip migration early. Photo and photocopy verification for remote account opening dies in April 2027; the JPKI and chip-reading rails have been live since mid-January 2026, so there is no reason to be redesigning onboarding in the final quarter.
- If you touch stablecoins or electronic payment instruments, confirm your Travel Rule posture — EPISPs have been fully in scope since August 2025.
For authoritative detail, the FSA, JAFIC and the Digital Agency publish the primary texts — including the Digital Agency's My Number FAQ for the identity-verification side.
Ready for Japan's risk-based era?
The March 2026 guidelines reward institutions that can prove they understand their own risk — and the April 2027 chip mandate rewards those that modernize verification before they're forced to. Didit brings identity verification, biometric face matching, NFC chip reading, AML screening and transaction monitoring together in one platform with usage-based pricing, so compliance teams can build the stack Japan's new era expects. Get started with Didit.
This article is general information, not legal advice. For decisions about your institution's obligations under Japanese law, consult qualified counsel and the primary FSA, JAFIC and Digital Agency texts.
Related articles
- Japan Crypto & EPISP Compliance: Travel Rule, KYC and the 2025–2027 Timeline
- NFC Chip Reading vs Photo Uploads: Why Identity Verification Is Going Chip-First
- JPKI and the My Number Card: How Japan's Public-Key Identity Verification Works
- Japan's April 2027 IC-Chip Verification Mandate: What Changes for Remote Onboarding
- Japan's eKYC Overhaul (2026–2027): JPKI, IC-Chip Mandates and the End of Photo-Based Account Opening
- NFC Passport Verification Reliability