Skip to main content
Didit Raises $7.5M to Build the Infrastructure for Identity and Fraud
Didit
Back to blog
Blog · July 23, 2026

Japan Crypto & EPISP Compliance: Travel Rule, KYC and the 2025–2027 Timeline

Japan's crypto AML timeline: EPISP Travel Rule scope (Aug 2025), FSA's revised guidelines (Mar 2026) and the April 2027 IC-chip mandate for onboarding.

By DiditUpdated
japan-crypto-episp-compliance-timeline-2025-2027.png

Japan is upgrading its anti-money-laundering framework in three clearly dated steps. Stablecoin intermediaries — Electronic Payment Instrument Service Providers (EPISPs) — were brought fully into AML scope, including Travel Rule obligations, in August 2025. The Financial Services Agency's (FSA) revised AML/CFT guidelines took effect on 31 March 2026. And from April 2027, a revision to the Act on Prevention of Transfer of Criminal Proceeds makes IC-chip-based identity verification mandatory for non-face-to-face account openings at banks and financial institutions. If you run an exchange, a web3 platform or an EPISP touching the Japanese market, each of these dates carries work. This guide consolidates them into a single timeline.

The short version

- August 2025: EPISPs — stablecoin intermediaries — were brought fully into Japan's AML regime, including Travel Rule obligations.

- 31 March 2026: the FSA's revised AML/CFT guidelines took effect: a sharpened risk-based approach, new obligations around outsourcing, technology adoption and transaction monitoring, and direct senior-management accountability.

- April 2027: IC-chip-based identity verification becomes mandatory for non-face-to-face account openings at banks and financial institutions; photos and photocopies of ID documents will be outlawed for those openings. Crypto firms should confirm with the FSA/JAFIC how the mandate applies to their licence category.

- Baseline duties remain throughout: verify customer identity, retain records for 7 years, file suspicious transaction reports with JAFIC.

A note on sources. This article is current as of July 2026 and draws on publications from Japan's FSA, JAFIC and Digital Agency, plus reporting from The Japan Times and Biometric Update. Rules evolve and details matter — consult the regulators directly for authoritative guidance. Spot an error? Tell us at https://didit.me/contact.

Three dated changes, one direction

Each of the three milestones tackles a different layer of the AML stack: the August 2025 change extends who is regulated, the March 2026 guidelines reshape how firms manage risk, and the April 2027 mandate hardens how identity is proven at remote account opening. The common thread is a move away from trust in static documents and box-ticking, toward cryptographic verification and demonstrable, board-owned risk management — the direction FATF pushed Japan after its 2021 mutual evaluation flagged effectiveness gaps.

August 2025: EPISPs enter full AML scope, Travel Rule included

Effective August 2025, Electronic Payment Instrument Service Providers — Japan's stablecoin intermediaries — were brought fully into scope of the AML framework, including Travel Rule obligations. For the precise boundaries of the EPISP category and which activities it captures, the FSA is the authority to consult.

The Travel Rule itself is a FATF standard: in general terms, it requires that identifying information about the parties to a transfer accompany the transfer, so that funds cannot move through regulated intermediaries anonymously. Firms newly subject to it typically need data pipelines that can attach and receive that information, procedures for performing due diligence on counterparty institutions, and documented handling for transfers where a counterparty cannot receive the data. How each of those elements is operationalized under Japanese rules is exactly the kind of detail to confirm with the FSA and JAFIC rather than assume from FATF's general framework.

If you intermediate stablecoins in or into Japan and treated AML as someone else's problem before August 2025, that assumption is now stale.

31 March 2026: the FSA's revised AML/CFT guidelines

The FSA's revised guidelines, in effect since 31 March 2026, align Japan's supervisory expectations with FATF standards. The headline items:

  • A sharpened risk-based approach. Firms must run self-directed risk assessments and design their own mitigation — not wait for a regulator-issued checklist.
  • New obligations around outsourcing. If you delegate onboarding, screening or monitoring to a vendor, responsibility for the outcome stays with you.
  • Technology adoption and transaction monitoring. The guidelines set expectations around adopting technology and monitoring transactions on an ongoing basis.
  • Richer suspicious-transaction-report data, broken down by country and customer attribute.
  • Regulator access to board-level AML/CFT reports and direct senior-management accountability. AML is now explicitly a boardroom topic, not a back-office one.

For crypto and EPISP compliance teams, the practical translation: a written, current risk assessment; monitoring that actually runs and generates reviewable alerts; vendor oversight you can evidence; and reporting that reaches — and is owned by — senior management.

April 2027: the IC-chip mandate for remote account openings

The revision to the Act on Prevention of Transfer of Criminal Proceeds (犯罪収益移転防止法) sets the hardest deadline. From April 2027, IC-chip-based identity verification becomes mandatory for non-face-to-face account openings at banks and financial institutions, and submitting photos or photocopies of ID documents will be outlawed for those openings. The rationale, as reported by The Japan Times in June 2025: forged and counterfeit IDs are too hard to detect from images. Remote applicants will instead need the embedded IC chip of their My Number card or driver's licence read.

The compliant routes already exist. Since mid-January 2026, verification is available via JPKI (Japanese Public Key Infrastructure) using the My Number card, and by matching the IC-chip digital data of an ID document against the holder's facial image.

Remote verification method (non-face-to-face account openings at banks and financial institutions)TodayFrom April 2027
Photo or photocopy of an ID documentAcceptedOutlawed
IC-chip read of a My Number card or driver's licenceAvailableMandatory
JPKI via My Number cardAvailable since mid-January 2026Compliant route
IC-chip data matched against the holder's facial imageAvailable since mid-January 2026Compliant route

Note the stated scope: the mandate is written for account openings at banks and financial institutions. Whether and how it reaches crypto-asset exchanges and EPISPs depends on your licence category — confirm directly with the FSA and JAFIC rather than assuming either way. Even where the mandate doesn't bite directly, the direction is unambiguous: image-based checks are losing regulatory trust, and the market is moving early. Biometric Update reports one major Japanese provider saw chip-based checks grow 1.8x to 14 million, within a total of more than 60 million verifications.

Where Didit helps: Japan's shift toward chip-based verification maps to NFC chip reading — a capability Didit performs on chip-equipped identity documents, priced at $0.15 per check under User Verification. Around it sits the full KYC bundle at $0.33 per successful check (ID Verification, Passive Liveness, Face Match 1:1, IP Analysis — with 500 free core-KYC checks per month), plus AML Screening at $0.20 per check against 1,300+ lists ($0.07/user/year ongoing) and Transaction Monitoring for the FSA's risk-based expectations. Coverage spans 220+ countries and 14,000+ document types with sub-2s inference. See how it fits Japan's criminal-proceeds-act requirements at didit.me/solutions/countries/japan.

The consolidated compliance timeline

WhenWhat takes effectStated scope
August 2025EPISPs brought fully into AML scope, including Travel Rule obligationsStablecoin intermediaries (EPISPs)
Mid-January 2026JPKI verification via My Number card available; IC-chip data + facial-image matching availableOptional verification routes, ahead of the mandate
31 March 2026Revised FSA AML/CFT guidelines: risk-based approach, outsourcing, technology, transaction monitoring, STR data by country/customer attribute, board-level accountabilityFSA-supervised financial institutions
April 2027IC-chip verification mandatory; photo/photocopy ID outlawed for non-face-to-face account openingsBanks and financial institutions — crypto firms and EPISPs should confirm applicability for their licence category with the FSA/JAFIC
OngoingIdentity verification, 7-year record retention, suspicious transaction reports to JAFICAll obliged entities

What crypto and EPISP teams should do now

1. Pin down your licence category. Everything downstream — Travel Rule mechanics, guideline expectations, whether the 2027 chip mandate reaches your onboarding — turns on how your activity is classified. Get that answer from the FSA or JAFIC in writing, not from a blog (including this one).

2. Audit Travel Rule readiness. Can your systems attach and receive the transfer information FATF's standard contemplates? Do you have documented counterparty due-diligence procedures and a defined policy for transfers where required data can't be exchanged?

3. Rebuild the risk assessment. The March 2026 guidelines expect a self-directed assessment with mitigation you designed, monitoring output your team reviews, and reporting your board sees. If your last risk assessment predates the guidelines, it's due for a rewrite.

4. Plan for chip-capable onboarding. If the 2027 mandate applies to you, photo-upload flows have a hard end date. If it doesn't, the verification surge — 1.8x growth in chip-based checks at a single provider — suggests users and counterparties will increasingly expect chip-grade assurance anyway.

5. Check the plumbing. Seven-year record retention, suspicious transaction reports filed with JAFIC, and STR data granular enough to break down by country and customer attribute.

Japan has published the schedule; the firms that treat 2025–2027 as one program rather than three surprises will spend less and scramble less. If you're building or upgrading verification for the Japanese market, you can talk to Didit's team here.

This article is general information, not legal advice. For obligations specific to your licence and business, consult the FSA, JAFIC and qualified Japanese counsel.

Infrastructure for identity and fraud.

One API for KYC, KYB, Transaction Monitoring, and Wallet Screening. Integrate in 5 minutes.

Ask an AI to summarise this page
Japan Crypto & EPISP Compliance: Travel Rule to 2027 IC-Chip