Crypto AML/CFT Guideline explainer (Japan)

The 'risk-based approach' required by the FSA's AML/CFT Guidelines, framed for crypto exchanges and electronic payment instrument handlers.

Last updated: July 2026

The guideline at a glance

The FSA's 'Guidelines for Anti-Money Laundering and Combating the Financing of Terrorism' supplement specific statutes such as the APTCP and set out, as 'required' and 'expected' actions, the framework financial institutions must build. Crypto exchanges and electronic payment instrument handlers are in scope, and following FATF's 4th mutual evaluation of Japan the effectiveness of the risk-based approach (RBA) is continuously scrutinised. This page explains the three stages of the RBA at the core of the guideline, plus transaction monitoring / filtering, ongoing customer due diligence, and governance (the three lines of defence) from a crypto operator's implementation viewpoint.

1. The three stages of the risk-based approach (RBA)

The guideline requires firms to understand the risks they face and apply proportionate mitigation. The core is a three-stage cycle: identify, assess, mitigate.

  • Identify: enumerate inherent risk across products / services (listed assets, transfers, custody), transaction types, countries / regions, and customer attributes
  • Assess: evaluate identified risk comprehensively and document it as a risk assessment; review periodically and on material change
  • Mitigate: assign mitigation measures — customer due diligence (CDD/EDD), transaction monitoring, transaction filtering, record keeping — proportionate to the assessment

2. Transaction monitoring and transaction filtering

The guideline requires both suspicious-activity detection (transaction monitoring) and pre-emptive blocking of transactions with sanctioned parties (transaction filtering). For crypto firms, extending coverage beyond off-chain customer data to on-chain fund flows is key to effectiveness.

  • Transaction monitoring: detect abnormal patterns, threshold breaches, rapid dispersal transfers, feeding the suspicious-transaction-report (STR) decision
  • Transaction filtering: match sending / receiving addresses against OFAC SDN, UN, EU, and domestic lists, and block or hold on a hit
  • Detection quality: suppress false positives and periodically validate detection scenarios
  • On-chain extension: assess proximity of counterparty addresses to mixers, bridges, and scam clusters via graph analysis

3. Ongoing customer due diligence

The guideline requires firms to update customer risk assessment continuously using information gained through transactions, not just at onboarding — applying enhanced due diligence (EDD) to high-risk customers and efficient handling to low-risk ones. ChainAnalyzer supports this through continuous monitoring (Watchlist) of on-chain addresses a customer is involved with, with alerts on risk change.

4. Governance — the three lines of defence

The guideline requires the 'three lines of defence' to function under active senior-management involvement. Tooling supports the effectiveness of the first and second lines; it does not replace the governance itself.

  • First line (business units): front-line management of risk in customer handling and transaction execution
  • Second line (compliance): design and oversight of risk policy and monitoring scenarios (the AML officer sits here)
  • Third line (internal audit): independent validation of the first and second lines

5. Mitigation measures ChainAnalyzer covers

ChainAnalyzer provides the on-chain transaction monitoring, filtering, continuous monitoring, and record-keeping portions of the mitigation the guideline requires — in native Japanese and hosted in-country.

  • On-chain transaction monitoring via 76+ detection rules plus an ML ensemble (0-100 risk score)
  • Transaction filtering via OFAC SDN / UN / EU / JFSA sanctions matching
  • Continuous address monitoring via Watchlist with email / webhook alerts
  • Record keeping of detection evidence via Case Management + PDF reports (audit ready)
  • Audit logs (Activity Log) referenceable in risk assessments and internal audit

6. FAQ

Is there a standalone 'crypto AML/CFT guideline' statute?

Strictly, the FSA's 'Guidelines for AML/CFT' is a supervisory guideline common to all financial institutions, and crypto exchanges / electronic payment instrument handlers are in scope. The APTCP, Payment Services Act, and JVCEA self-regulatory rules layer on top to form the industry-specific practice.

What does the risk-based approach concretely require?

Identify your inherent risks, assess and document them as a risk assessment, assign mitigation proportionate to risk (CDD, transaction monitoring, filtering, etc.), and review the cycle periodically. ChainAnalyzer covers the on-chain portion of the mitigation.

What is the difference between transaction monitoring and filtering?

Monitoring detects abnormal transactions on an ongoing / after-the-fact basis to feed the suspicious-transaction-report decision; filtering matches against sanctions lists pre-transaction to block dealings with sanctioned parties. The guideline requires both.

Does ChainAnalyzer replace the compliance framework itself?

No. Policy, procedure, and the three lines of defence remain the operator's responsibility. ChainAnalyzer is a mitigation tool supporting the first and second lines; it does not replace the AML officer's judgement or the reporting obligation.

Try transaction monitoring

Try ChainAnalyzer's on-chain transaction monitoring and sanctions screening, starting on the free plan.

Start free

Related pages

Disclaimer

This page is educational general information, not legal advice. Interpretation and application of the guideline vary by fact pattern and can be revised. For actual framework build-out, confirm the FSA's primary sources and consult qualified counsel.

© 2026 ChainAnalyzer. All rights reserved.