Japan KYC, KYB & AML compliance checklist
A practical, source-linked checklist for implementing KYC, KYB and AML requirements in Japan.
- Last reviewed
- Last reviewed:
- Version
- Version 1.0

Portable implementation guide
Get the PDF checklist
11 control areas · 33 implementation checks
Last reviewed: 25 September 2026 · Version 1.0
Download the checklistDirect answer
What does the Japan compliance checklist cover?
The Japan checklist translates primary KYC, KYB and AML rules into 11 control areas and 33 implementation checks. It identifies the relevant authorities, customer and beneficial-owner controls, reporting duties, recordkeeping expectations and evidence teams should retain.
Key regulatory facts
- FIU
- Japan Financial Intelligence Center (JAFIC), National Police Agency
- Primary AML rule
- Act on Prevention of Transfer of Criminal Proceeds and its current Order and Ordinance
- STR timing and route
- Promptly to the competent administrative authority through its prescribed route; JAFIC centralizes and analyzes notified information
- Threshold reporting
- No universal cash-threshold report; CDD thresholds and transaction-record exclusions are sector- and transaction-specific
- High-risk source check
- For a high-risk transaction transferring more than JPY 2 million, verify assets and income to the extent required by the APTCP framework
- AML records
- Generally 7 years, with the start event depending on verification or transaction record type
- Privacy authority
- Personal Information Protection Commission (PPC) under the APPI
- FATF public lists
- Not listed at 19 June 2026
Implementation detail
Japan compliance requirements and actions
Open each control area to review the requirement, recommended implementation action, evidence to retain and the primary-source citation used by the research team.
01Scope, authorities, and licensingJapan applies the APTCP by specified business, specified activity and specified transaction, with supervision remaining sector-specific.3 items+
Map each Japanese activity to the specified-business and specified-transaction perimeter.
- Implementation action
- Classify the legal entity, service, customer, transaction and exemptions under APTCP Article 2, the Enforcement Order and Enforcement Ordinance before onboarding or product launch; do not assume every business or every transaction is covered identically.
- Evidence to retain
- Perimeter memo, service and funds-flow map, statutory mapping, exemptions and Japanese counsel sign-off.
- Primary citation
- APTCP Articles 2 and 4; Enforcement Order Articles 6 and 7; JAFIC APTCP Overview dated 7 August 2026
Identify the competent administrative authority and filing channel for each regulated activity.
- Implementation action
- Record the sector supervisor, registration or licence, APTCP reporting destination and current e-Gov or authority procedure; distinguish the reporting destination from JAFIC's FIU analysis role.
- Evidence to retain
- Authority matrix, licence or registration, filing credentials, test submission and escalation contacts.
- Primary citation
- APTCP Articles 8 and 13; JAFIC suspicious-transaction reporting destination table
Obtain the required financial-services registration or authorization before operating.
- Implementation action
- Map banking, funds-transfer, electronic-payment-instrument, crypto-asset, prepaid-payment, financial-instruments and intermediary activities to the current business law and FSA perimeter; obtain approval or registration and observe scope and conditions.
- Evidence to retain
- Regulatory-perimeter analysis, application, FSA or Local Finance Bureau decision, conditions and renewal or change log.
- Primary citation
- Payment Services Act; Banking Act; Financial Instruments and Exchange Act; FSA FinTech Support Desk guidance
02Governance and risk assessmentControls must reflect Japan's national risk assessment, the operator's own risks and sector-supervisory expectations.3 items+
Maintain an enterprise-wide ML/TF/PF risk assessment.
- Implementation action
- Assess customers, beneficial owners, products, services, countries, delivery channels, transactions, technologies, agents and outsourced providers; incorporate the current National Risk Assessment and refresh for material change.
- Evidence to retain
- Methodology, current assessment, data sources, inherent and residual risk, approval and remediation plan.
- Primary citation
- APTCP Article 11; Enforcement Ordinance Article 32; 2025 National Risk Assessment; FSA AML/CFT Guidelines revised 31 March 2026
Maintain risk-based policies, governance and an accountable control function.
- Implementation action
- Document customer verification, ongoing review, monitoring, STR, transfer information, sanctions, records, training, audit and outsourcing controls; designate an overall manager and give management usable risk reporting.
- Evidence to retain
- Approved framework, roles, committee minutes, management information, training, control testing and issue closure.
- Primary citation
- APTCP Article 11; Enforcement Ordinance Article 32; FSA AML/CFT Guidelines revised 31 March 2026
Test whether the framework operates effectively.
- Implementation action
- Use independent and risk-based validation to test data, scenarios, customer-risk models, screening, reporting, record retrieval and remediation rather than relying only on policy existence.
- Evidence to retain
- Testing plan, samples, model and data validation, findings, owners, deadlines and verified closure.
- Primary citation
- FSA AML/CFT Guidelines revised 31 March 2026; FSA dialogue paper on validation of effectiveness
03Natural-person identificationTransaction verification applies at the legally defined trigger and must establish the customer and any person acting for the customer.3 items+
Complete transaction verification at each applicable trigger.
- Implementation action
- Before or when conducting a specified transaction, verify identification particulars, transaction purpose and occupation using a method permitted for the channel; aggregate an apparently split transaction when the Order requires it.
- Evidence to retain
- Trigger analysis, identity data, verification source and method, purpose, occupation, timestamp and exception rationale.
- Primary citation
- APTCP Article 4; Enforcement Order Article 7; Enforcement Ordinance Articles 4 to 10; JAFIC APTCP Overview
Verify the representative and their authority.
- Implementation action
- Where an individual acts for another customer, verify that individual's identification particulars and establish a valid basis for authority; do not treat an employee card or non-representative officer registration alone as sufficient authority.
- Evidence to retain
- Representative KYC, mandate or authority evidence, customer confirmation, scope and transaction log.
- Primary citation
- APTCP Article 4(4); Enforcement Ordinance Article 12; JAFIC APTCP Overview, representative verification
Use remote verification methods only when every prescribed condition is met.
- Implementation action
- Select a current Enforcement Ordinance method for non-face-to-face onboarding, test document authenticity and impersonation controls, preserve the required evidence and stop or escalate when verification cannot be completed reliably.
- Evidence to retain
- Method legal mapping, images or electronic evidence, liveness and fraud tests, device signals, result and exception review.
- Primary citation
- APTCP Article 4; Enforcement Ordinance Article 6 as amended; JAFIC materials on transaction-verification methods
04KYB, registries, and beneficial ownershipCommercial-registry evidence supports KYB, but beneficial ownership requires a separate natural-person control analysis.3 items+
Verify a legal person's identity, existence, business and representative.
- Implementation action
- Obtain current commercial or corporation registration, constitutional information, head office, corporate number, officers and business purpose from reliable sources and resolve discrepancies.
- Evidence to retain
- Legal Affairs Bureau certificate or registry data, corporate-number check, constitutional documents, officer list and discrepancy log.
- Primary citation
- APTCP Article 4; Enforcement Ordinance Articles 6 and 7; Commercial Registration Act; Ministry of Justice commercial-registration guidance
Identify the natural persons who ultimately own or control the legal person.
- Implementation action
- For a capital-majority corporation, identify natural persons with more than 25% direct or indirect voting rights unless a person with more than 50% displaces that tier, then assess control by other means and apply the prescribed senior-manager fallback when no other natural person is identified; use the applicable test for other legal-person types.
- Evidence to retain
- Layered ownership chart, voting-right calculations, control evidence, verified identities and fallback rationale.
- Primary citation
- APTCP Article 4(1)(iv); Enforcement Ordinance Article 11; JAFIC APTCP Overview, beneficial-owner method
Treat the Beneficial Ownership of Legal Persons List as corroboration, not conclusive proof or a universal public register.
- Implementation action
- Where a stock company supplies a registrar-certified copy, verify its date, attachments and scope, then corroborate ownership and control. Record that the system is request-based, is limited to eligible stock companies and does not prove the submitted description is true.
- Evidence to retain
- Certified list copy, attachment inventory, independent corroboration, current ownership check and limitations note.
- Primary citation
- Ministry of Justice Beneficial Ownership of Legal Persons List System; Enforcement Ordinance Article 11(2)
05PEPs, enhanced due diligence, and remote riskThe APTCP defines foreign PEP transactions as high risk; financial-sector expectations require broader risk-sensitive management where relevant.3 items+
Identify foreign PEPs, specified family members and legal persons they beneficially own.
- Implementation action
- Screen customers and beneficial owners at onboarding and periodically for the foreign-PEP categories in the Enforcement Ordinance, including former office holders and covered family relationships.
- Evidence to retain
- Screening source and date, role and relationship analysis, ownership evidence, false-positive disposition and refresh history.
- Primary citation
- Enforcement Order Article 12; Enforcement Ordinance Article 15; JAFIC APTCP Overview, high-risk transactions
Apply the prescribed enhanced verification to high-risk transactions.
- Implementation action
- Use the stricter identity and beneficial-owner verification method for impersonation or false-information risk, customers in designated high-risk jurisdictions and foreign PEP transactions. For a high-risk transfer above JPY 2 million, verify assets and income to the extent needed for the STR decision.
- Evidence to retain
- Trigger, enhanced sources, dual verification, assets-and-income evidence where scoped, approval and monitoring plan.
- Primary citation
- APTCP Article 4(2); Enforcement Order Articles 12 and 13; JAFIC APTCP Overview, high-risk verification and JPY 2 million scope
Do not treat domestic PEP screening as an express APTCP foreign-PEP rule.
- Implementation action
- Where sector guidance or the risk assessment supports screening Japanese public functions, document it as a risk-based control and define approval, source-of-funds, source-of-wealth and monitoring measures without mislabeling it as the statutory foreign-PEP category.
- Evidence to retain
- Policy basis, risk assessment, screening result, approval, corroboration and review history.
- Primary citation
- FSA AML/CFT Guidelines revised 31 March 2026; APTCP foreign-PEP provisions
06Ongoing monitoring and suspicious transaction reportingSuspicion is risk-based, covers attempted or refused activity in relevant cases and must be reported promptly without tipping off.3 items+
Keep verified information current and monitor activity against purpose and risk.
- Implementation action
- Refresh customer, representative and beneficial-owner information; compare activity with expected purpose, occupation or business, known history and the National Risk Assessment; investigate unusual or inconsistent activity.
- Evidence to retain
- Refresh schedule, monitoring scenarios, alert chronology, investigation, decision and quality review.
- Primary citation
- APTCP Articles 8 and 11; Enforcement Ordinance Articles 26 and 32; FSA AML/CFT Guidelines revised 31 March 2026
Report qualifying suspicion promptly to the competent administrative authority.
- Implementation action
- When property received in specified business is suspected criminal proceeds or the customer is suspected of concealment or receipt conduct, record when suspicion arose and submit promptly through the current sector route. Include attempted or refused activity when the statutory test is met; do not wait for proof.
- Evidence to retain
- Suspicion chronology, legal test, decision-maker, report, submission receipt and authority correspondence.
- Primary citation
- APTCP Article 8; Enforcement Ordinance Articles 25 and 26; JAFIC APTCP Overview and reporting guidance
Apply the professional-sector exceptions and protect report confidentiality.
- Implementation action
- Confirm whether the operator is excluded or whether professional secrecy limits a report. For a reportable case, prevent disclosure to the customer or related person and restrict report data to authorized personnel.
- Evidence to retain
- Sector and privilege analysis, access log, disclosure controls, training and incident record.
- Primary citation
- APTCP Articles 8 and 12; JAFIC APTCP Overview dated 7 August 2026
07Payments, transfers, thresholds, and virtual assetsAmounts in Japan serve different purposes; no single figure is a universal CDD or cash-reporting threshold.3 items+
Apply each sector-specific CDD threshold and anti-structuring rule only to its legal context.
- Implementation action
- Map account opening, large cash transactions, remittances, payment instruments, crypto-assets, professional services and other specified transactions to the current Order. Aggregate an apparently divided transaction where required and apply special-attention CDD even below a normal threshold.
- Evidence to retain
- Threshold matrix, transaction aggregation logic, scenario tests, exceptions and legal citations.
- Primary citation
- APTCP Article 4; Enforcement Order Article 7; Enforcement Ordinance Articles 4 and 5; JAFIC APTCP Overview
Transmit required originator and beneficiary information for covered transfers.
- Implementation action
- For foreign-exchange transfers, electronic payment instruments and crypto-assets, populate the prescribed sender and recipient fields, validate completeness, retain the information and apply repair or restriction procedures for missing data.
- Evidence to retain
- Field matrix, payment or transfer messages, validation rules, exception queue, disposition and retention evidence.
- Primary citation
- APTCP Articles 10, 10-3 and 10-5; 2024 fully effective amendments; FSA travel-rule notice effective 3 August 2026
Use the correct Payment Services Act category and registration.
- Implementation action
- Classify funds-transfer services as Type I, II or III and respect the category conditions; register covered crypto-asset exchange and electronic-payment-instrument services before operation and verify counterparties against current FSA information.
- Evidence to retain
- Product and value-flow analysis, category and limit tests, authorization or registration, counterparty checks and change monitoring.
- Primary citation
- Payment Services Act; FSA FinTech Support Desk; FSA registered crypto-asset exchange provider list
08Targeted financial sanctionsJapan's sanctions framework uses transaction restrictions, permission requirements and domestic asset-freezing measures; the applicable list and legal mechanism must be identified.3 items+
Screen against current Japanese designations and restrictions.
- Implementation action
- Screen customers, beneficial owners, controllers, representatives, counterparties and transactions against the Ministry of Finance and Ministry of Foreign Affairs lists at onboarding, before execution and when lists change; assess ownership and control beyond exact-name matching.
- Evidence to retain
- List versions, update logs, configuration tests, match analysis and disposition.
- Primary citation
- Foreign Exchange and Foreign Trade Act; Ministry of Finance economic-sanctions measures and target lists
Prevent a prohibited or unlicensed payment, capital transaction or asset dealing.
- Implementation action
- Place an immediate operational hold on a potential match, identify whether FEFTA, the International Terrorist, etc. Asset-Freezing Act or another measure applies, obtain any required permission before activity and follow the competent authority's reporting or consultation route.
- Evidence to retain
- Match and ownership-control analysis, hold timestamp, legal-mechanism memo, authority contact, permission and release decision.
- Primary citation
- FEFTA; International Terrorist, etc. Asset-Freezing Act; Ministry of Finance AML/CFT/CPF regime overview
Keep AML suspicion and sanctions decisions linked but legally distinct.
- Implementation action
- Assess whether the same facts require an STR, sanctions action, both or neither; do not delay sanctions control while investigating suspicion and do not assume a sanctions false positive resolves AML risk.
- Evidence to retain
- Parallel decision log, STR assessment, sanctions disposition, approvals and case closure.
- Primary citation
- APTCP Article 8; FEFTA; International Terrorist, etc. Asset-Freezing Act
09Records and regulator accessSeven years is the central APTCP period, but the record category determines when the clock starts.3 items+
Retain verification records for seven years from the applicable end event.
- Implementation action
- Create the record immediately after verification and retain it for seven years from termination or completion of the contract or transaction specified by the APTCP framework; preserve the method, documents and verified matters.
- Evidence to retain
- Verification record, retention classification, start event, deletion hold and retrieval test.
- Primary citation
- APTCP Article 6; Enforcement Ordinance Articles 19 and 20; JAFIC APTCP Overview
Retain covered transaction records for seven years from the transaction date.
- Implementation action
- Record the customer or lookup key, date, type, value and transfer origin or destination for covered activity and retain for seven years, subject to the scoped small-transaction exclusions.
- Evidence to retain
- Transaction record, source and destination fields, exclusion rationale, retention proof and retrieval test.
- Primary citation
- APTCP Article 7; Enforcement Ordinance Articles 23 and 24; JAFIC APTCP Overview
Provide accurate and retrievable records to the competent authority.
- Implementation action
- Maintain Japanese-readable records and controlled export procedures so reports, inspections and correction orders can be answered completely without altering source data or exposing STR information improperly.
- Evidence to retain
- Request log, data lineage, production package, approval, delivery receipt and remediation tracking.
- Primary citation
- APTCP Articles 15 to 18; applicable sector supervisory law
10Privacy, biometrics, breaches, and transfersKYC necessity does not remove the separate APPI duties for purpose, notice, security, third parties, overseas transfers and incidents.3 items+
Specify lawful use purposes and minimize KYC personal information.
- Implementation action
- Identify and communicate the use purpose as specifically as possible, collect only data needed for AML, fraud, sanctions and service purposes, control incompatible use and honor applicable access, correction and cessation rights.
- Evidence to retain
- Data inventory, purpose register, notices, necessity assessment, rights workflow and deletion schedule.
- Primary citation
- APPI Articles 17 to 21 and 32 to 39; PPC APPI legal materials
Protect identity and biometric data with risk-appropriate safeguards.
- Implementation action
- Classify face images, facial templates and other identity data under the APPI based on their actual form and use; document necessity, accuracy and retention, restrict access, test vendors and avoid treating every biometric as automatically special care-required personal information.
- Evidence to retain
- Data classification, privacy assessment, security controls, accuracy and bias tests, vendor review and deletion evidence.
- Primary citation
- APPI Articles 2 and 23; PPC Guidelines; PPC facial-recognition principles
Control reportable breaches and foreign third-party transfers.
- Implementation action
- Escalate a qualifying leakage or other incident to the PPC and affected individuals under the Act and Rules, preserving the preliminary and final reporting clocks that apply to the incident. Before providing personal data to a third party abroad, use consent or a valid statutory route, provide required country and safeguard information and maintain continuing-information duties where applicable.
- Evidence to retain
- Incident assessment, PPC reports and notices, transfer map, recipient-country information, consent or exception, contract and monitoring.
- Primary citation
- APPI Articles 26 and 28; Enforcement Rules; PPC General and Foreign Transfer Guidelines
11Practical evidence packsEvidence should reconstruct the Japan-specific legal basis and every material decision from onboarding through reporting and exit.3 items+
Maintain a reconstructable customer and KYB pack.
- Implementation action
- Bundle trigger analysis, identity, representative authority, registry evidence, beneficial ownership, purpose, occupation or business, risk, PEP and sanctions results, privacy records and exceptions under stable identifiers.
- Evidence to retain
- Complete sampled onboarding pack, source provenance, approvals and retrieval result.
- Primary citation
- Operational control supporting APTCP Articles 4 and 6 and APPI security duties
Maintain a reconstructable monitoring, STR and sanctions pack.
- Implementation action
- Link activity, alerts, information reviewed, suspicion time, promptness decision, submission, confidentiality, sanctions hold, authority contacts and release or exit decision.
- Evidence to retain
- Complete sampled case pack, timeline, receipts and controlled-access record.
- Primary citation
- Operational control supporting APTCP Article 8 and Japanese sanctions laws
Maintain a launch and change-control pack.
- Implementation action
- Record the service perimeter, licence, competent authority, customer-verification method, transaction thresholds, transfer information, reporting route, sanctions, APPI controls, outsourcing and validation before launch and material change.
- Evidence to retain
- Signed launch pack, source register, legal-change log, tests, uncertainty register and approvals.
- Primary citation
- Official sources listed below
Primary-source register
22 sources used for this checklist
Use these links to verify the underlying legislation, regulator guidance, reporting procedures and international status statements.
- Act on Prevention of Transfer of Criminal Proceeds - current Japanese texte-Gov Laws and Regulations · Primary legislation
- Order for Enforcement of the Act on Prevention of Transfer of Criminal Proceedse-Gov Laws and Regulations · Primary delegated legislation
- Ordinance for Enforcement of the Act on Prevention of Transfer of Criminal Proceedse-Gov Laws and Regulations · Primary delegated legislation
- APTCP overview current at 7 August 2026Japan Financial Intelligence Center, National Police Agency · Official current legal guidance
- JAFIC Annual Report 2025Japan Financial Intelligence Center, National Police Agency · Official implementation report
- National Risk Assessment 2025National Police Agency · Official risk assessment
- Suspicious transaction reporting and competent authoritiesJapan Financial Intelligence Center, National Police Agency · Official reporting guidance
- AML/CFT Guidelines revised 31 March 2026Financial Services Agency · Official supervisory guidance
- Reference cases on suspicious transactionsFinancial Services Agency · Official reporting guidance
- Commercial and corporation registrationMinistry of Justice · Official registry guidance
- Beneficial Ownership of Legal Persons List SystemMinistry of Justice · Official beneficial-ownership guidance
- FinTech Support Desk regulatory perimeter guidanceFinancial Services Agency · Official licensing guidance
- Finalized 2026 travel-rule jurisdiction amendmentFinancial Services Agency · Official transfer-rule notice
- Registered crypto-asset exchange service providers - 1 April 2026Financial Services Agency · Official register
- Japan AML/CFT/CPF legislative regimeMinistry of Finance · Official regime overview
- Current economic sanctions measures and target listsMinistry of Finance · Authoritative sanctions lists
- APPI laws and policiesPersonal Information Protection Commission · Primary law and official guidance
- Guidelines for provision to a third party in a foreign countryPersonal Information Protection Commission · Official privacy guidance
- Japan country profile and 2024 follow-up reportFinancial Action Task Force · Authoritative current assessment
- FATF jurisdictions under increased monitoring - 19 June 2026Financial Action Task Force · Authoritative current status
- FATF high-risk jurisdictions subject to a call for action - 19 June 2026Financial Action Task Force · Authoritative current status
- Act on National Flag and Antheme-Gov Laws and Regulations · Primary national-symbol legislation
Direct answers
Japan KYC, KYB and AML questions
Who receives suspicious transaction reports?+
The competent administrative authority for the specified business receives the report through its prescribed route. The National Public Safety Commission and National Police Agency, through JAFIC, centralize, analyze and disseminate the information.
When must a suspicious transaction be reported?+
Promptly after the statutory suspicion test is met. The APTCP does not set one universal hours-or-days clock, so the operator should record when suspicion arose and why the submission was prompt.
Does Japan require a universal cash-threshold report?+
No. Japan uses sector- and transaction-specific CDD and record rules rather than one universal cash-threshold report. A large-cash CDD trigger must not be described as an automatic threshold report.
What does the JPY 2 million high-risk figure mean?+
It applies to verification of assets and income when a high-risk transaction involves a transfer of property exceeding JPY 2 million. It is not a universal transaction-monitoring or reporting threshold.
How is beneficial ownership determined?+
For a capital-majority corporation, the analysis begins with natural persons holding more than 25% of voting rights, subject to the more-than-50% displacement rule, then control by other means and the prescribed fallback. Other legal-person types use their applicable test.
Is Japan's beneficial-owner list a universal public register?+
No. It is a request-based system for eligible stock companies. A registrar confirms consistency with submitted attachments, but the certified copy does not prove that the company's description is true.
How long are APTCP records retained?+
Generally seven years. Verification records run from the applicable termination or completion event, while covered transaction records run from the transaction date; the precise category and exclusions must be documented.
Must crypto-asset businesses register?+
Covered crypto-asset exchange services require registration under the Payment Services Act. Operators must also apply APTCP controls and the scoped travel rule, including the current designated-jurisdiction framework for transfers to foreign VASPs.
What should happen on a Japanese sanctions match?+
Hold the activity operationally, identify the controlling FEFTA, asset-freezing or other measure, consult or report through the competent route and obtain any required permission before proceeding. Do not describe every Japanese measure as an identical automatic account freeze.
Is Japan on a FATF public list?+
No. Japan was absent from both FATF public lists dated 19 June 2026. FATF's October 2024 follow-up recorded 4 compliant and 35 largely compliant Recommendations, with no partially compliant ratings.
Research and review method
VOVE ID Compliance Research maps the regulatory perimeter, translates obligations into operational controls, links each material claim to a source and records the date and version of every review.
General regulatory information, not legal advice or a licence determination. Reviewed as applicable on 25 September 2026. The legally effective texts are Japanese. Confirm the current specified-business and specified-transaction perimeter, sector rules, filing route, sanctions designation, privacy basis, outsourcing structure and licensing position with the competent authority and qualified Japanese counsel before launch.