D1 Sanctions
Sanctions is not yet covered for this jurisdiction in this report.
Japan runs an integrated AML/CFT/CPF framework under the APTCP, PSA and FIEA, supervised by the FSA/JVCEA with JAFIC (under the National Police Agency) as FIU.
Sanctions is not yet covered for this jurisdiction in this report.
Beneficial Ownership is not yet covered for this jurisdiction in this report.
Enabler Jurisdictions is not yet covered for this jurisdiction in this report.
Conflict Finance is not yet covered for this jurisdiction in this report.
Crypto / Digital Assets / Financial Innovation is not yet covered for this jurisdiction in this report.
Compliance Technology & Active Defence is not yet covered for this jurisdiction in this report.
The stock-company-only beneficial-ownership registry and its reported financial-institution-only accessibility narrow the reliability of registry-based verification for non-stock-company Japan counterparties. The Boryokudan finding indicates that low prosecution volume relative to predicate-crime proceeds is a structural, not incident-level, condition. The DMM Bitcoin theft, assessed as funding DPRK weapons of mass destruction and ballistic missile programmes, together with the lapsed UN Panel of Experts mandate, reduces the independent verification layer available for DPRK-typology reporting.
Japan remains absent from FATF and EU high-risk-jurisdiction lists, and its October 2024 re-rating on five Recommendations is well evidenced, though the underlying aggregate zero-partially-compliant claim carries an unresolved evidentiary caveat. The beneficial-ownership registry access-limitation caveat and the pending bank crypto-custody and JPYC stablecoin developments together define the areas where Japan policy framework is either incomplete or still in motion.
The absence of secondary-sanctions authority in Japan domestic Foreign Exchange and Foreign Trade Act framework limits reach over third-country intermediaries implicated in transhipment of Japan-origin dual-use goods toward Russia. The lapsed UN Panel of Experts mandate further narrows the independent evidentiary base available for DPRK sanctions-evasion enforcement and litigation contexts.
The October 2024 re-rating and continued absence from grey and high-risk lists indicate a positive strategic-level regulatory trajectory for Japan. Against that trajectory, the approximately 305 million dollar DMM Bitcoin theft and the resulting wind-down and customer migration represent the clearest institutional-scale financial-crime loss event in this baseline, and are assessed as connected to DPRK weapons proliferation financing rather than a standalone cybersecurity incident.
The JFSA cybersecurity supervisory policy, including sector information-sharing through a Japan Crypto ISAC and threat-led penetration testing, is a direct technical-architecture response to prior exchange-hacking losses. JPYC embedded AML and CFT screening from launch illustrates a build-in-from-inception pattern for new regulated digital-asset products. The pending review of bank crypto-custody and exchange licensing, if it proceeds, would extend crypto-asset technical and surveillance requirements into banking-group infrastructure not currently built for it.
Each of these findings independently narrows the visibility available to risk functions: transhipment exploits Japan limited independent end-use verification once goods leave direct control, Boryokudan laundering exploits the beneficial-ownership registry scope gap, and the lapsed UN Panel narrows multilateral DPRK-typology reporting. The JFSA cybersecurity supervisory policy is the one countervailing signal, representing a concrete narrowing of the crypto-exchange attack surface specifically.
The DMM Bitcoin wind-down represents a completed operational migration of customer accounts and assets rather than an open remediation. The JPYC stablecoin launch, with Elliptic-powered screening embedded in its compliance framework, illustrates an operational template for AML and CFT control build in a new regulated Japan digital-asset product, though the precise approval and launch date sequencing carries an unresolved caveat.
The claim that Japan carries zero partially-compliant FATF Recommendations is not explicitly confirmed in the underlying follow-up report and is held below High confidence pending verification. Separately, this cycle run recorded publication-gate quality-floor failures inconsistent with the profile-level source-quality block reporting the floor as met, an internal control-testing discrepancy flagged for evidence-base integrity rather than resolved in this cycle.
Japan first baseline surfaces three reportable-risk anchors: a beneficial-ownership registry limited to stock companies, persistently low Boryokudan money-laundering prosecution volume, and a DPRK-linked crypto-exchange theft assessed as proliferation financing.
Japan aggregate FATF compliance posture continues to improve on paper, while a stock-company-only beneficial-ownership registry and an uncertain-direction bank crypto-custody review both remain open.
Japan lacks an OFAC-style secondary-sanctions authority, a structural divergence that intersects with unresolved third-country transhipment exposure and a degraded multilateral DPRK-verification mechanism.
Japan improving FATF trajectory sits alongside a material financial-crime loss event, the DMM Bitcoin theft, and its wind-down into a domestic acquirer.
A newly finalised mandatory cybersecurity supervisory policy for Japan crypto exchanges follows the DMM Bitcoin theft, while JPYC launched with embedded blockchain-analytics screening and a bank crypto-custody review remains open.
Third-country transhipment of Japan-origin dual-use goods, Boryokudan front-company laundering and the lapsed DPRK verification mechanism together describe a widening evidentiary and typology gap.
DMM Bitcoin customer migration to SBI VC Trade completed by March 2025, and JPYC launched with embedded travel-rule-relevant screening infrastructure.
An unresolved evidentiary caveat on Japan aggregate FATF compliance count coincides with an internal publication-gate discrepancy in this baseline cycle.
Illustrative orientation only: as the AMLA Regulation (Reg (EU) 2024/1620) moves the EU from purely national AML supervision toward a hybrid regime of AMLA direct and indirect supervision of high-risk cross-border obliged entities, alongside the directly applicable AMLR (Reg (EU) 2024/1624) and per-state 6AMLD transposition, evasion-oriented actors could plausibly test the seams between national and AMLA-level supervisory reach during the transition period, for example by structuring cross-border obliged-entity relationships to sit just below the direct-supervision threshold while still spanning multiple national supervisory regimes. This is architecture-over-incident illustration of a possible structural mechanism during a supervisory transition, not a description of an observed evasion scheme.
Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.
Illustrative orientation only: a state-linked actor could hypothetically compromise a licensed exchange, rapidly move stolen assets through cross-chain bridges and mixing services, and route resulting value through intermediary over-the-counter counterparties toward procurement or program-financing use, all while the primary independent multilateral mechanism for verifying such typologies is degraded. This sketch illustrates a possible structural pathway connecting exchange-security failure to proliferation-adjacent financing under conditions of reduced multilateral verification capacity; it does not assert that any specific transaction chain described here has occurred.
Illustrative scenario for analytical orientation only. Not compliance advice, not a prediction, and not a statement of observed fact.
| Tracker | Status | Note |
|---|---|---|
| T1 · Russian Sanctions-Evasion Architecture | material_change | Japan's MOF/MOFA asset-freeze list update (2026-03-25) adds a 50%-shareholding designation-extension rule and maintains a crypto-payment prohibition for sanctioned entities. |
| T2 · EU AML Package / AMLA | no_change | Not applicable in JP's regime — JP is a non-EU jurisdiction and the AMLR/6AMLD/AMLA instruments do not apply domestically; no spillover into JP-facing supervisory perimeters identified this cycle. |
| T3 · FATF Grey List | watch | Japan is not grey-listed; fifth-round on-site review scheduled June 2028, adoption expected February 2029. Cambodia faces renewed grey-list re-listing risk amid a scam-centre/illegal-casino crackdown. |
| T4 · Beneficial-Ownership Register Status | material_change | Japan lacks a central public UBO register; media reports indicate movement toward mandatory BO reporting; a related shareholding-disclosure reform took effect 2026-05-01, and real-estate ownership-transparency reforms advance in parallel through 2026. |
| T5 · Crypto & Digital-Asset Integrity | material_change | Japan's Diet passed FIEA reclassification of crypto assets on 2026-07-15 (targeted FY2027 effect); FSA ordinance recognising foreign trust-type stablecoins took effect 2026-06-01, requiring supervisory-equivalence with the foreign issuer's home regulator. |
| T6 · Sanctions Regime Divergence | watch | Japan's Russia sanctions remain broadly G7-aligned (price cap, export controls) but retain idiosyncratic features — the 50%-shareholding extension rule and explicit crypto-payment prohibition — not uniformly mirrored in OFAC/EU/UK autonomous lists. |