The 'risk-based approach' required by the FSA's AML/CFT Guidelines, framed for crypto exchanges and electronic payment instrument handlers.
Last updated: July 2026
The FSA's 'Guidelines for Anti-Money Laundering and Combating the Financing of Terrorism' supplement specific statutes such as the APTCP and set out, as 'required' and 'expected' actions, the framework financial institutions must build. Crypto exchanges and electronic payment instrument handlers are in scope, and following FATF's 4th mutual evaluation of Japan the effectiveness of the risk-based approach (RBA) is continuously scrutinised. This page explains the three stages of the RBA at the core of the guideline, plus transaction monitoring / filtering, ongoing customer due diligence, and governance (the three lines of defence) from a crypto operator's implementation viewpoint.
The guideline requires firms to understand the risks they face and apply proportionate mitigation. The core is a three-stage cycle: identify, assess, mitigate.
The guideline requires both suspicious-activity detection (transaction monitoring) and pre-emptive blocking of transactions with sanctioned parties (transaction filtering). For crypto firms, extending coverage beyond off-chain customer data to on-chain fund flows is key to effectiveness.
The guideline requires firms to update customer risk assessment continuously using information gained through transactions, not just at onboarding — applying enhanced due diligence (EDD) to high-risk customers and efficient handling to low-risk ones. ChainAnalyzer supports this through continuous monitoring (Watchlist) of on-chain addresses a customer is involved with, with alerts on risk change.
The guideline requires the 'three lines of defence' to function under active senior-management involvement. Tooling supports the effectiveness of the first and second lines; it does not replace the governance itself.
ChainAnalyzer provides the on-chain transaction monitoring, filtering, continuous monitoring, and record-keeping portions of the mitigation the guideline requires — in native Japanese and hosted in-country.
Strictly, the FSA's 'Guidelines for AML/CFT' is a supervisory guideline common to all financial institutions, and crypto exchanges / electronic payment instrument handlers are in scope. The APTCP, Payment Services Act, and JVCEA self-regulatory rules layer on top to form the industry-specific practice.
Identify your inherent risks, assess and document them as a risk assessment, assign mitigation proportionate to risk (CDD, transaction monitoring, filtering, etc.), and review the cycle periodically. ChainAnalyzer covers the on-chain portion of the mitigation.
Monitoring detects abnormal transactions on an ongoing / after-the-fact basis to feed the suspicious-transaction-report decision; filtering matches against sanctions lists pre-transaction to block dealings with sanctioned parties. The guideline requires both.
No. Policy, procedure, and the three lines of defence remain the operator's responsibility. ChainAnalyzer is a mitigation tool supporting the first and second lines; it does not replace the AML officer's judgement or the reporting obligation.
Try ChainAnalyzer's on-chain transaction monitoring and sanctions screening, starting on the free plan.
Start freeThis page is educational general information, not legal advice. Interpretation and application of the guideline vary by fact pattern and can be revised. For actual framework build-out, confirm the FSA's primary sources and consult qualified counsel.
© 2026 ChainAnalyzer. All rights reserved.