AML for VASPs — an adoption & operations guide

A practical guide for VASPs (crypto exchanges and e-payment instrument handlers) to select, adopt and operationalise AML tooling. The regulatory explainers live on related pages; this page focuses on how you deploy it and how you run it.

Last updated: July 2026

VASP AML operations (what this page is)

A VASP's AML operation is the ongoing work of assessing risk on customer deposits, withdrawals and transfers, and detecting, recording and reporting suspicious transactions. In Japan the PFMSA and APTCP require crypto exchanges and e-payment instrument handlers to perform identity verification, transaction monitoring, and suspicious-transaction reporting. This page is not an explainer of those requirements — it focuses on adopting and operating an AML tool that meets them. See the related pages at the end for the regulatory detail.

1. Requirements to evaluate at adoption

The minimum functional requirements a VASP should confirm when selecting an AML tool.

  • Address screening: can it match deposit/withdrawal counterparties against OFAC SDN, scam clusters, mixers and no-KYC exchanges?
  • Transaction monitoring: can it continuously apply threshold and behaviour-based rules and catch risk change?
  • Multi-chain coverage: does it cover the chains of your handled assets (how many chains, and which are live)?
  • Case management & reporting: can it consolidate investigation records and output evidence for audit and reporting?
  • Record retention: can it preserve detection results and screening evidence in a tamper-evident form (APTCP record-keeping)?
  • Operating cost & Japanese support: is the price, language and hosting practical for a domestic team to run?

2. The operating workflow (daily operations)

After adoption, an AML tool only works once embedded into daily operations. A standard VASP workflow looks like this.

  • Pre-transfer screening: match withdrawal / deposit addresses before execution; hold CRITICAL / HIGH for review
  • Continuous monitoring: periodically rescan existing customer wallets and hot wallets to catch later risk change
  • Alert triage: sort detection alerts by severity, filter false positives, and identify cases needing investigation
  • Investigate & record: consolidate related addresses into a case and record the basis and evidence for the decision
  • Report & retain: route suspicious transactions to the reporting flow and preserve evidence as audit logs

3. Decision factors for adoption

Whether to adopt an AML tool is decided by operational sustainability, not features alone. Key axes a VASP should weigh in practice.

  • False-positive suppression: does it avoid wrongly flagging legitimate issuer operations or high-throughput infrastructure (over-flagging inflates triage load)?
  • Explainability: can it show why something was flagged — and why zero results — with a basis (essential for audit and supervisor dialogue)?
  • Integration into existing flows: can it embed into your existing deposit/withdrawal review via REST API, webhook and batch?
  • Fit for domestic operation: Japanese-native UI and reports, and domestic hosting for explainable data residency

4. ChainAnalyzer deployment options

ChainAnalyzer offers multiple deployment options that embed into a VASP's deposit/withdrawal review. It covers 9 live chains (including Kaia); BNB Smart Chain ships on Enterprise rollout.

  • Web UI: on-demand per-address scans and case management (analyst manual operation)
  • REST API: embedding into a withdrawal-review pipeline (programmatic screening)
  • Batch scan: bulk matching of large address sets (periodic stock-take of existing customer wallets)
  • Webhook: instant notification of three events — risk change, watchlist update, report ready — to your existing systems
  • Evidence & reports: automatic generation and retention of audit-ready compliance evidence, Japanese-native

5. FAQ

Is this page an explainer of VASP regulation?

No. This page focuses on adopting and operating an AML tool. For the regulatory detail (PFMSA, APTCP, Travel Rule, etc.), see the related pages at the end — the Japan AML Regulatory Guide, Travel Rule & APTCP, and AML Officer FAQ.

Can it embed into our existing deposit/withdrawal review flow?

Yes. Via REST API and webhook you can embed it into your withdrawal-review pipeline, automating pre-transfer address screening and instant notification on risk change. Large address sets can be matched in bulk via batch scan.

Does it file suspicious-transaction reports on our behalf?

No. Reporting is work the VASP itself performs via its prescribed flow. ChainAnalyzer supports the upstream detection, investigation and evidence retention, providing the on-chain analysis and audit logs that underpin the reporting decision.

Too many false positives make operations unmanageable — how is that handled?

It is tuned to avoid false-flagging legitimate issuer operational wallets and high-throughput infrastructure, and each detection carries a basis (why flagged / why zero results). This keeps alert-triage effort down.

Try AML operations

Start with address screening on the free ScamDB API. Transaction monitoring, case management and webhooks are available on higher plans.

Start free

Related pages (regulatory explainers)

Disclaimer

This page is educational general information, not legal advice. The regulatory requirements and operational standards imposed on VASPs can be revised. For actual compliance, confirm the primary sources from the FSA / JVCEA and consult qualified counsel.

© 2026 ChainAnalyzer. All rights reserved.