Japan AML Laws and Regulations: A Practical Guide for Financial Institutions

Table of Contents

Japan AML laws and regulations framework showing APTCP, FSA, JAFIC, KYC, CDD and financial crime compliance

Japan’s anti-money laundering and counter-terrorist financing (AML/CFT) framework is among the most developed in Asia, but it is also one of the fastest-evolving. For compliance teams navigating Japan AML laws and regulations, staying current is essential.

This guide explains the key AML/CFT laws, regulatory authorities, compliance requirements and 2026 developments that financial institutions and other regulated businesses need to understand when operating in or with Japan.

1. Quick Overview: Japan's AML/CFT Regime in 2024–2026

Japan’s AML CFT and counter-proliferation financing framework is broadly mature and aligned with Financial Action Task Force standards. However, since the 2021 Fourth Round Mutual Evaluation exposed both technical and effectiveness gaps, the government has accelerated legislative reform, supervisory tightening, and institutional coordination. Regulatory supervision in Japan involves multiple authorities, including the Financial Services Agency and the National Police Agency. The Financial Services Agency oversees AML compliance in Japan, while JAFIC, the Japan Financial Intelligence Centre, serves as the country’s financial intelligence unit, receiving and analysing suspicious transaction reports.

The core statutes underpinning the legislative regime are:

  • Act on Prevention of Transfer of Criminal Proceeds (APTCP, in force since 2007, amended in 2016 and later)

  • Act on Punishment of Organised Crimes and Control of Proceeds of Crime (APOC)

  • Foreign Exchange and Foreign Trade Act (FEFTA)

  • Terrorist Asset-Freezing Act (TAFA) and related terrorism-financing laws

The 2024 FATF Follow-Up Report re-rated Japan on several recommendations to be “largely compliant,” but effectiveness-real world effectiveness in prosecutions, asset recovery, and supervisory enforcement remains a focal area. On 31 March 2026, the FSA published a heavily revised set of AML/CFT Guidelines that raise expectations on operational effectiveness and enterprise-wide governance. The FSA issues guidance and conducts inspections for AML compliance across all regulated sectors.

For institutions seeking scalable technology to meet these evolving expectations, ZIGRAM provides RegTech solutions purpose-built for AML compliance, transaction monitoring, and customer due diligence CDD automation across multiple jurisdictions, including Japan.

2. Key AML and CFT Laws in Japan

Japan’s AML regulations are based on the Act on Prevention of Transfer of Criminal Proceeds, but the full ecosystem involves several interlocking statutes. Understanding how they fit together is essential for effective implementation.

Act on Prevention of Transfer of Criminal Proceeds (APTCP)

The APTCP is the core preventive AML law. It designates specified business operators like banks, securities firms, insurers, money services businesses, crypto-asset exchange service providers, and designated non-financial businesses and professions as obliged entities. Concrete requirements include customer due diligence at onboarding and for specified transactions, record keeping for at least seven years, suspicious transaction reporting to JAFIC, and internal controls, including staff training. The APTCP was enacted in 2007 and revised in 2016 to expand CDD measures. Recent amendments further cover virtual currency and digital assets, adding crypto-asset transfer notification obligations enforced from June 2023.

Act on Punishment of Organised Crimes and Control of Proceeds of Crime (APOC)

APOC defines money laundering offences, extends predicate offences beyond drug crimes to organised crimes and other serious criminal offences, and provides the machinery for seizure, confiscation, and forfeiture of criminal proceeds. Where the Act on prevention of transfer of criminal proceeds sets preventive obligations for business operators, the Act on punishment of organised crimes delivers criminal sanctions. Recent amendments expanded property subject to confiscation, including electronic property rights.

Foreign Exchange and Foreign Trade Act (FEFTA)

The Foreign Exchange and Foreign Trade Act regulates cross-border transactions and economic sanctions. It underpins asset freezing for proliferation financing and terrorism-related parties and mandates CDD for overseas remittances. The Foreign Exchange Act requires CDD for remittances over 100,000 yen. FEFTA also implements financial sanctions by authorising or prohibiting external payments involving specific countries or parties, reinforcing Japan’s international cooperation commitments. Customs declarations are required for means of payment exceeding ¥1,000,000 when entering or exiting Japan.

Terrorist and Sanctions-Related Laws (including TAFA)

Japan’s Terrorist Asset Freezing Act regulates transactions by terrorists, operationalising asset freezing and targeted financial sanctions based on United Nations Security Council resolutions. The Act on Punishment of Financing of Offences of Public Intimidation punishes terrorist funding, criminalising the provision of terrorist funds. These measures link directly to anti money laundering controls that institutions must integrate sanctions screening and transaction blocking into their AML workflows. Japan’s Financial Services Agency oversees compliance with terrorism financing laws alongside its broader supervisory mandate.

The Anti-Drug Special Provisions Law

This statute targets drug crime proceeds specifically, criminalising laundering of proceeds from activities involving controlled substances and psychotropics under the Psychotropics Control Act. It forms key predicate offences under APOC and reinforces international cooperation on narcotics cases, connecting to broader counter-terrorism financing and anti-drug special provisions across borders.

3. National AML/CFT Policy and Institutional Architecture

Japan established a coordinated national policy structure following the 2021 FATF evaluation. The Inter-Ministerial Council for AML/CFT/CPF Policy coordinates Japan’s AML strategy at the director-general level, co-chaired by the National Police Agency and the Ministry of Finance.

Inter-Ministerial Council and Action Plan

The Inter-Ministerial Council was established in August 2021. Japan’s AML/CFT Action Plan was established in August 2021 and has been updated through successive fiscal years. The National AML/CFT/CPF action plan for FY2024–2026 focuses on legislative refinement, strengthening supervision of financial institutions and DNFBPs, improving beneficial ownership transparency, and enhancing information sharing with the private sector. Institutions are expected to align their internal AML frameworks with risk themes flagged in the Plan, including digital assets, cross-border transactions, and NPOs.

JAFIC

Japan’s Financial Intelligence Unit is named Japan Financial Intelligence Center (JAFIC). Operating under the National Public Safety Commission, JAFIC receives and analyses STRs, disseminates intelligence to law enforcement agencies, and cooperates with over 100 foreign FIUs. Its periodic National Risk Assessment follow-up reports on ML/TF risk inform both supervisory priorities and institutional risk assessments.

Other Key Agencies

Agency

Primary AML Role

FSA

Supervision, inspections, guidelines for financial institutions

NPA

Criminal investigation and enforcement under APOC

MOF

Policy leadership, FEFTA, sanctions, foreign governments coordination

Ministry of Justice

Legal framework, criminal definitions, registries

Customs

Cross-border means-of-payment declarations

4. Core Preventive Obligations under the APTCP

The Act on Prevention of Transfer of Criminal Proceeds governs AML obligations for all specified business operators. Japan’s APTCP mandates customer due diligence for specified operators across a range of trigger events.

Customer Due Diligence and KYC

CDD is required at onboarding, for specified transactions over certain thresholds, for cross-border payments, and whenever ML/TF suspicion arises. Financial institutions must verify customer identity using government-issued ID, residence card details (nationality, residence status, and expiration), and, for legal persons, identify beneficial owners holding more than 25% of voting rights. CDD measures were strengthened in Japan’s APTCP revision in 2016. Japan requires enhanced due diligence for high-risk customers, including non-residents, complex structures, politically exposed persons, and digital asset activity. For lower-risk scenarios, simplified due diligence is permitted under the risk-based approach.

Ongoing Monitoring

Japan’s AML regulations require continuous transaction monitoring for compliance. SBOs must periodically refresh KYC data, respond to triggers from transaction anomalies, and check for changes in address, occupation, or ownership. FSA Guidelines require risk-based frequency of reviews linked to the institution’s enterprise-wide risk assessment.

Record-Keeping

The Act on Prevention of Transfer of Criminal Proceeds mandates transaction record-keeping. Specified business operators must keep transaction records for seven years after the end of the business relationship or completion of a specific transaction. Records include identification data, transaction details, CDD rationale, and internal escalation notes.

Suspicious Transaction Reporting

Financial institutions must report suspicious transactions to JAFIC. Suspicious Transaction Reports must be filed by institutions when suspicious activity is detected. The obligation covers all specified business operators-including crypto-asset providers and, under recent amendments, legal professionals for certain transactions. Timeliness, confidentiality (no tipping off), and documented internal escalation procedures are essential. Japan’s regulatory regime includes penalties for failing to report suspicious activities.

AML/CFT Internal Controls

SBOs must maintain written AML policies, designate a responsible AML officer, deliver role-based staff training, and conduct independent audit or testing. Direct accountability for AML outcomes lies with senior management and boards of financial institutions. The FSA expects documented procedures for handling higher-risk economic activities, cross-border business, and digital assets.

5. Supervisory Guidance: FSA AML/CFT Guidelines and FATF Standards

Relevant laws set the “what.” FSA Guidelines and FATF guidance define the “how”-especially for building and operating an AML compliance programme that satisfies inspectors.

The FSA’s AML/CFT Guidelines-first published in 2018 and most recently revised on 31 March 2026-are the primary supervisory document specifying risk-based AML expectations for financial institutions. Key themes include enterprise-wide risk assessment, governance with board-level oversight, group-wide controls, and third-party risk management. FSA AML/CFT guidelines emphasize actual operational effectiveness over mere compliance. Financial institutions face penalties for weak AML controls per the FSA guidelines, and recent amendments to Japan’s AML laws increased scrutiny and penalties for non-compliance.

Institutions must categorise risks by customer type, products/services, geography, delivery channels, and digital assets. Japan’s AML framework aligns with FATF standards for effectiveness, and examiners look for evidence that controls are tailored and updated-not merely checklist-based. Japan’s AML regulations require an enterprise-wide risk-based approach to compliance.

Japan’s 4th Round FATF Mutual Evaluation (2021) and subsequent follow-up reports through 2024 have driven stricter FSA inspections and more focus on “effective outcomes.” Regulatory compliance expectations in Japan have shifted towards demonstrable operational effectiveness-institutions must prove their frameworks work, not just exist.

FSA FAQs encourage use of advanced RegTech and SupTech solutions for name screening, transaction monitoring, and adverse media checks, provided governance and model-risk management are robust.

6. Scope of Application: Who Must Comply (FIs and DNFBPs)

Japan’s AML regulations apply to various financial entities, including crypto providers, as well as designated non-financial sectors.

Financial Institutions

Banks, credit unions, securities firms, insurance companies, money lenders, credit card companies, payment service providers, electronic money issuers, and crypto-asset exchange service providers must implement full AML/CFT frameworks. This includes CDD, transaction monitoring, STR reporting, and asset freezing processes aligned with FEFTA and TAFA. The APTCP requires banks and other financial institutions to verify customer identities during transactions.

Designated Non-Financial Businesses and Professions (DNFBPs)

Real estate agents, dealers in precious metals and stones, lawyers, judicial scriveners, certified public accountants, notaries, and trust/company service providers are treated as specified business operators under the APTCP. CDD and STR duties are tailored to certain transaction types-large cash deals, company formation, property purchases. Casino business operators are also in scope under expanded obligations.

Non-Profit Organisations

Some NPOs are in scope mainly for CFT risk, with guidance focusing on governance and transparency, particularly for cross-border funding. Japan’s National Risk Assessment flags NPOs in relation to potential misuse for financing of terrorism and terrorist activities.

Digital Asset and Fintech Businesses

Crypto-asset service providers must register with the FSA. Crypto providers must comply with customer identification and transaction monitoring. Japan’s Financial Services Agency oversees AML compliance for crypto services. These entities must maintain AML/CFT programmes specifically designed for pseudonymous, high-velocity transactions and comply with Travel Rule-style information-sharing requirements where applicable.

Foreign Institutions with Japan Exposure

Foreign banks, securities houses, and fintechs operating branches or providing cross-border services into Japan must understand Japanese AML obligations and integrate them into group-wide policies. FEFTA and APTCP apply regardless of the institution’s home jurisdiction, and foreign governments are expected to cooperate on enforcement matters.

7. Operational AML Components: From CDD to Asset Freezing

CDD and Beneficial Ownership

Detailed CDD flows for individuals and corporates require collection of beneficial owner data for legal persons-threshold of more than 25% voting rights under APTCP practice. Beneficial ownership identification is crucial to prevent money laundering using shell companies. Japan’s emerging beneficial ownership registries help institutions verify corporate ownership, with expectations to detect opaque or high-risk structures.

Transaction Monitoring

Transaction monitoring systems minimize false positives in suspicious activity alerts while preserving sensitivity to new typologies flagged by JAFIC and FATF. In 2024, 139 cleared APOC money laundering cases involved foreign visitors, which is 11% of all APOC cases charged with fraud, theft, and computer fraud as the leading predicate offences.

Sanctions, Screening, and Asset Freezing

Institutions must screen customers and suspicious transactions against domestic and international sanctions lists, United Nations Security Council lists, international organizations lists, and terrorism lists, including international terrorists designated under TAFA. Operational asset freezing steps include immediate blocking, internal escalation, regulatory notification, and monitoring for attempted circumvention. The Foreign Exchange and Foreign Trade Act requires asset freezing for terrorism-related parties and those linked to weapons of mass destruction proliferation.

STR and Internal Escalation

Alerts move from frontline detection to specialist review, decisioning, and STR filing with JAFIC. Documentation quality, confidentiality, and periodic feedback from law enforcement agencies refine scenarios. Such information must be handled with strict confidentiality to prevent tipping off.

Governance, Training, and Culture

Senior management and boards bear direct accountability. AML risk must be formally integrated into enterprise risk management. Regular training is tailored to role-front office, operations, and management-and periodic independent testing of AML systems is required. The sound development of an AML culture is a consistent FSA expectation.

8. Emerging Areas: Digital Assets, Cross-Border Risks, and Technology

Japan’s innovation agenda creates new AML/CFT risks that demand equally sophisticated responses.

Digital Assets and Crypto-Asset Service Providers

Japan requires registration and licensing of crypto-asset exchanges and certain wallet providers, subjecting them to full AML obligations under APTCP. Specific risks include anonymity, mixer services, and DeFi protocols. Expectations cover robust customer due diligence CDD, Travel Rule compliance, and blockchain analytics. The effective implementation of these controls is under increasing supervisory scrutiny.

Cross-Border Transactions and Trade

FEFTA-based controls on foreign exchange transactions require CDD for overseas remittances above thresholds and enhanced scrutiny of high-risk jurisdictions. Institutions must integrate country risk lists, FATF grey/black lists, and National Police Agency guidance into their risk scoring and monitoring.

Use of Advanced RegTech

AI-powered Complete AML Systems or Complete FRAML System for name screening, adverse media monitoring, and entity risk assessment tools, such as ZIGRAM’s PreScreening.io, Fraud Fighter, Entity Hero, and Transact Comply, support FSA expectations for real-world effectiveness. Explainability, audit trails, model validation, and alignment with FSA technology guidance are non-negotiable for any AML software deployed in Japan.

Data Quality and Integration

Breaking down silos between onboarding, transaction data, sanctions lists, and external intelligence is essential to produce a single customer view. Fragmented legacy systems lead to missed risks, inconsistent risk ratings, and elevated false positives-all red flags during FSA inspections.

9. Practical Roadmap for AML Compliance in Japan (2024–2026)

Step 1 – Map Legal and Regulatory Requirements

Compile an inventory of applicable laws (APTCP, APOC, FEFTA, TAFA, etc.), FSA Guidelines, NRA follow-up findings, and FATF evaluation comments relevant to your business model and reporting obligations.

Step 2 – Conduct or Refresh Enterprise-Wide Risk Assessment

Assess inherent risk by customer, product, geography, channels, and digital assets. Map controls, identify gaps, and review at least annually or upon significant changes for new products, markets, or regulatory updates. Japan’s AML laws include the Act on Prevention of Transfer of Criminal Proceeds as the baseline for this assessment.

Step 3 – Strengthen Governance and Documentation

Formalise board-approved AML policies, clearly define roles and responsibilities, and ensure board-level reporting with metrics on STRs, high-risk exposures, and system performance. International standards require that governance be demonstrable, not aspirational.

Step 4 – Upgrade CDD, Screening, and Monitoring

Adopt integrated platforms for KYC, sanctions/PEP screening, transaction monitoring, and adverse media checks. ZIGRAM’s suite is designed to meet multi-jurisdictional AML obligations, including Japan’s requirements for customer identification and ongoing monitoring.

Step 5 – Test, Audit, and Engage Regulators

Conduct regular independent testing of AML controls. Remediate findings and proactively engage with FSA/JAFIC FATF guidance and industry typology reports. By 2026, regulators will expect demonstrable, data-backed evidence that AML/CFT frameworks are preventing misuse for criminal proceeds and terrorist financing-not just satisfying formal checklists.

The window to prepare is closing. With the 2026 FSA Guidelines revisions already in force and the 5th FATF Mutual Evaluation on the horizon for 2027, institutions operating in or with Japan should review their AML frameworks now.

Book a demo or schedule a discovery call with ZIGRAM to explore how AI-driven AML solutions can help operationalise Japanese regulatory requirements efficiently and at scale.

Enhance Your AML Compliance Efforts

Empower your organization with ZIGRAM's integrated RegTech solutions

Financial Crime Prevention Image

Articles

Explore insightful articles on cutting-edge topics like regulations, technological advancements, and critical insights into AML and financial crime risks
https://d2g4ubq4o0ypu0.cloudfront.net/wp-content/uploads/2026/09/Japan-AML-Laws-scaled.webp

Japan AML Laws and Regulations: A Practical...

11 Min
https://d2g4ubq4o0ypu0.cloudfront.net/wp-content/uploads/2026/09/Article-Banner-47-scaled.png

AMLC Registration in the Philippines: Essential Requirements,...

9 Min
https://d2g4ubq4o0ypu0.cloudfront.net/wp-content/uploads/2026/09/Australia-AML-Laws-scaled.webp

Australia AML Laws: A Practical Guide to...

8 Min
https://d2g4ubq4o0ypu0.cloudfront.net/wp-content/uploads/2026/09/AML-Regulations-Canada-scaled.webp

AML Regulations Canada: 2026 Guide for Financial...

16 Min
https://d2g4ubq4o0ypu0.cloudfront.net/wp-content/uploads/2026/09/Article-Banner-46-scaled.png

The Rise of Digital Hawala: How Financial...

9 Min
https://d2g4ubq4o0ypu0.cloudfront.net/wp-content/uploads/2026/09/UK-AML-Strategy-2026-2029-scaled.webp

UK AML Strategy 2026–2029: Key Changes in...

12 Min