The FSA issued a caution notice dated 9 Oct to “financial institutions, etc.”, according to the notice on its website. It is a warning, not a new rule. The rule change it refers to was already set. Quotes below are our translations from the Japanese.
1. Drop image-based ID checks before 1 April 2027
Under an amendment to the enforcement regulations of the law on preventing the transfer of criminal proceeds, firms will from 1 April 2027 no longer be allowed to receive images of ID documents as a way to verify identity. The method will be consolidated, in principle, into reading the data on the card’s IC chip. The FSA asked firms not to wait for that date and to act “as promptly as possible”.
Why it matters: the legal switch is about six months away, and the regulator is asking firms to move now.
2. Re-check document and face images in the meantime
For non-face-to-face identity checks, the notice asks firms to re-confirm that neither the ID document image nor the applicant’s face image shows anything unnatural. It says impersonation methods are becoming more sophisticated.
3. Review cybersecurity and third-party risk
Firms are asked to review their defences, including third-party risk management and incident response, using the notice issued the same day by the Cabinet Secretariat’s National Cybersecurity Office, and to act quickly on any gaps. The FSA says unauthorised access to customer-facing services has led to leaks of customer data, including images of driving licences. ITmedia, a Japanese technology outlet, names two cases: about 1.6 million identity-document records leaked from the car-sharing service Times Car, and possible exposure of members’ licence numbers at Nippon Rent-A-Car.
Why it matters: images of identity documents held by one firm have become a target for impersonation elsewhere.
Where crypto comes in
The notice does not mention crypto. NADA NEWS, a Japanese crypto outlet, reports that the FSA’s cybersecurity guidelines count crypto-asset exchange operators among “financial institutions, etc.”, so account opening at exchanges is covered. We have not checked the guideline text. NADA adds that the FSA and the National Police Agency asked all registered exchange operators on 6 Aug, through the industry body JVCEA, to strengthen document-authenticity checks and limits on outbound withdrawals; we have not seen that request.
Caveat: the notice sets no deadline earlier than 1 April 2027 and names no exchange. How individual exchanges respond has not been reported.
Related reading from the region: Korea’s cross-border crypto transfer reporting decree and Singapore’s MAS on stablecoins and agent safeguards.
This article is for information only and is not investment advice.
