AML Officer FAQ

Common questions AML officers at crypto and stablecoin businesses run into, answered as general principles under Japan's APTCP and FSA AML guidelines.

Last updated: July 2026

About this page

This FAQ answers concrete day-to-day questions from AML officers at crypto exchanges and electronic payment instrument handlers, based on general principles from the APTCP and the FSA's AML guidelines. Individual determinations vary by business model and customer profile, so ultimately follow your own policies and the advice of qualified counsel.

Practical Q&A

When receiving a transfer from an overseas company, must that company's representative director also be AML-checked (verified and screened)?

Generally, transaction-time verification for a corporate customer requires both the natural person actually conducting the transaction (the representative/agent) and the beneficial owner to be verified. For an overseas company you first identify a natural person holding more than 25% of the voting rights as the beneficial owner; if none exists, the natural person who effectively controls the business; and if that too cannot be identified, the representative (e.g. representative director) is treated as the beneficial owner. So the representative director can indeed fall within scope for verification and sanctions screening — as the transaction agent and/or the beneficial-owner fallback. In addition, the entity and its beneficial owners should be screened against sanctions lists such as OFAC SDN, and the receiving/originating on-chain address risk-assessed.

How far up the ownership chain must beneficial-owner verification reach?

Under the APTCP you identify natural persons holding more than 25% of the voting rights. Where a shareholder is itself a legal entity, you trace through it to the natural person who ultimately controls, as a rule. For higher-risk cases (high-risk jurisdictions, complex ownership), apply enhanced due diligence — additional documentation and ongoing monitoring. Consult counsel for difficult structures.

How can I tell whether a receiving address belongs to an exchange, a mixer, or a scam cluster?

Through on-chain address attribution and registry matching. ChainAnalyzer matches receiving / sending addresses against the known-entities registry, ScamDB, and OFAC SDN, and evaluates Neo4j graph proximity (how many hops to a mixer, bridge, or scam cluster) to surface attribution and risk.

Can the AML officer decide a suspicious transaction report (STR) alone?

The AML officer performs detection and first-line judgement, but whether to file is normally an organisational decision under internal policy, with records kept. ChainAnalyzer surfaces the detection signals and evidence (evidence transactions, score rationale) to organise the decision, but the final filing determination and submission to authorities remain the operator's responsibility.

A customer disperses small amounts to many addresses in a short window — how should monitoring treat this?

Small-amount dispersal (structuring / smurfing) is a classic suspicious pattern aimed at evading thresholds. Rather than the size of a single transfer, evaluate the aggregated / dispersed graph structure over a period. ChainAnalyzer's fund-flow graph expansion (Follow Mode) surfaces the dispersal destinations to support pattern detection.

Which sanctions lists should I screen against, and how often?

Generally screen against OFAC SDN, UN, EU, and relevant domestic lists, and re-screen whenever a list updates. ChainAnalyzer provides this sanctions / risk-list matching as transaction filtering, and automates re-screening of existing customers via continuous monitoring (Watchlist).

How long must verification and transaction records be retained?

Under the APTCP, verification and transaction records must be retained for seven years from the end of the transaction. ChainAnalyzer's Case Management, PDF reports, and audit logs (Activity Log) preserve detection evidence in a tamper-resistant form, supporting record retention and audit readiness.

A customer sends stablecoins to an individual's self-hosted wallet. Is extra verification needed?

For transfers to self-hosted (unhosted) wallets there is no receiving VASP, so depending on risk you record originator / beneficiary information or perform additional verification. First determine, via attribution, whether the destination is a self-hosted wallet or another VASP, then decide based on that address's risk assessment.

Can I halt a transaction (or file an STR) on the ML risk score alone?

The score is only decision input; using it alone to automatically halt a transaction or justify an STR is not recommended. ChainAnalyzer presents the score's rationale (the detection rules that fired, evidence transactions) so the AML officer can review it in an explainable way and decide under internal policy.

We are a small operator — is deploying a tool enough for guideline compliance?

No. A tool supports mitigation (transaction monitoring, filtering, etc.), but producing the risk assessment, building policies and procedures, and standing up the three lines of defence (business, compliance, internal audit) are the operator's responsibility. ChainAnalyzer streamlines the on-chain portion of mitigation and complements — not replaces — the framework.

Streamline your AML work

Recipient screening, transaction monitoring, sanctions matching, and evidence retention — native Japanese, hosted in-country. Try it on the free plan.

Start free

Related pages

Disclaimer

This FAQ is educational general information, not individual legal advice. Interpretation of the APTCP and guidelines varies by fact pattern and can be revised. For actual compliance, confirm the FSA / JVCEA primary sources and consult qualified counsel.

© 2026 ChainAnalyzer. All rights reserved.