CryptaCount
EN
EnglishENDeutschDEEspañolESFrançaisFRItalianoIT日本語JA한국어KONederlandsNLPolskiPLPortuguêsPT
Log in Start Free

Japan FSA Requests Crypto Exchange Withdrawal Safeguards: What Accounting Firms and CFOs Must Assess Now

CryptaCount Editorial · · 9 min read
AML / KYC / LICENSING Japan FSA Requests Crypto Exchange WithdrawalSafeguards: What Accounting Firms and CFOs MustAssess Now

Japan's Financial Services Agency (FSA) and the National Police Agency (NPA) have jointly asked the country's crypto exchanges to introduce withdrawal delays, pre-registered address requirements, and stronger authentication controls. The request, directed at the Japan Virtual and Crypto Assets Exchange Association (JVCEA), is not yet binding regulation, but it carries regulatory weight that compliance teams and their advisers cannot ignore. For accounting firms, auditors, and CFOs with exposure to Japanese crypto markets, the practical implications land now, well before any formal rule is gazetted.

Japan FSA Requests Crypto Exchange Withdrawal Safeguards: What Accounting Firms and CFOs Must Assess Now

What the FSA and NPA Actually Requested

The joint request covers several distinct controls. Understanding each one matters because they affect different layers of an exchange's operational and financial infrastructure.

Withdrawal Delays After Fiat Deposits or Asset Purchases

Exchanges are asked to restrict crypto withdrawals for a defined period after a customer deposits fiat currency or completes a digital asset purchase. The rationale is straightforward: a significant proportion of fraud-related losses arise when victim funds move from a bank account directly into an exchange and are then quickly swept to an external wallet before the fraud is detected. A mandatory cooling-off window gives financial institutions and exchanges time to intercept suspicious flows.

From a bookkeeping standpoint, this introduces a category of funds that are received but not yet freely transferable. Any crypto accounting software used to track exchange-held positions needs to distinguish between settled balances and balances subject to a withdrawal hold, both for accurate reporting and for any real-time treasury dashboards a CFO relies on.

Pre-Registration and Waiting Periods for Withdrawal Addresses

Exchanges are also asked to require users to pre-register the external crypto addresses they intend to withdraw to, and to impose a waiting period before newly added addresses become active. This mirrors the payee confirmation model used in traditional banking in a number of jurisdictions and is intended to disrupt scam networks that rapidly cycle funds through freshly created wallets.

For compliance teams, address pre-registration creates a natural checkpoint for sanctions screening. Every whitelisted address can be run against relevant sanctions lists at the point of registration rather than only at the point of withdrawal. That is a material improvement over a reactive screening model, and it aligns with guidance the Financial Action Task Force (FATF) has issued on the travel rule and virtual asset monitoring.

Customer-Specific Withdrawal Limits and Monitoring

The request calls for individual withdrawal limits calibrated to each customer's profile. This is a risk-based approach: a retail customer with a modest transaction history would face lower limits than a verified institutional participant. Exchanges are also asked to strengthen monitoring of transaction patterns and access environments, meaning the devices and network locations from which account activity originates.

Behavioural monitoring of this kind generates data. Accounting firms advising exchanges should be aware that the records produced by enhanced monitoring may become relevant in any subsequent regulatory review or audit, and that record-retention obligations under Japan's Act on Prevention of Transfer of Criminal Proceeds will apply.

Phishing-Resistant Multifactor Authentication

Standard SMS-based one-time passwords are explicitly insufficient under the spirit of this request. The FSA is asking for phishing-resistant multifactor authentication (MFA), a term that in practice points toward hardware security keys or passkey-based systems that cannot be intercepted through a fake login page. This has operational cost implications for exchanges and their technology providers, and indirectly affects the timeline and budget assumptions in any ongoing systems audit.

Bank Remitter Name Matching

A further control asks exchanges to verify that the name on an incoming bank transfer matches the name of the registered crypto account holder. This targets a common fraud pattern where a victim is manipulated into sending funds from their own bank account into a fraudster's exchange account. Name-matching at the deposit stage is a simple but effective break in that chain.

Why This Matters Beyond Japan's Borders

Japan has consistently been a regulatory pace-setter in the virtual asset space. The JVCEA self-regulatory framework, the Payment Services Act registration regime, and the FSA's track record of converting guidance into enforceable rules all mean that today's non-binding request frequently becomes tomorrow's mandatory standard. Firms operating across Asia-Pacific should treat this as an early signal of the direction regional regulators are moving.

The FATF Connection

Several of the controls in the FSA/NPA request align closely with FATF Recommendation 16 (the travel rule) and the broader FATF guidance on virtual assets. Address pre-registration strengthens originator and beneficiary data collection. Enhanced access-environment monitoring supports suspicious transaction reporting obligations. Firms that have already built compliance frameworks around FATF standards will find that the Japanese request fits within existing architecture, though the specific operational timelines and technical thresholds will need to be defined by each exchange.

For a broader picture of how AML risks and licensing obligations are evolving across the region, see our analysis of APAC crypto AML risks and licensing realities.

Accounting and Audit Implications

The operational changes the FSA is requesting have direct consequences for how exchange financials are recorded, audited, and reported.

Balance Sheet Classification of Held Funds

Withdrawal delays create a population of customer assets that are received but subject to a temporary transfer restriction. Under both IFRS and Japanese GAAP, the classification of these funds on the exchange's own balance sheet warrants careful consideration. Whether they sit as a current liability, a restricted liability, or require separate disclosure depends on the duration and conditionality of the hold. Auditors reviewing exchange financial statements should include this question in their planning ahead of any formal rule adoption.

Operational Cost Recognition

Implementing phishing-resistant MFA, rebuilding address management systems, and deploying enhanced behavioural monitoring all carry costs. For exchanges preparing financial statements, these are likely capital or revenue expenditures depending on whether they extend the useful life of existing systems or represent new infrastructure. The distinction matters for tax purposes under Japan's Corporation Tax Act and for any IFRS 16 or IAS 38 treatment where software development costs are involved.

Internal Controls Documentation

Exchanges that are subject to external audit, or that are part of a group with a listed parent, will need to document the new controls as part of their internal control framework. Auditors should request a written mapping of each FSA-requested measure to the exchange's existing control environment, noting gaps and remediation timelines. This documentation also provides the evidential base if the FSA later conducts an on-site inspection.

AML Record Retention

The address pre-registration logs, name-matching records, and withdrawal delay audit trails that these controls generate are AML records. Japan's Act on Prevention of Transfer of Criminal Proceeds requires specified business operators to retain transaction records. Compliance teams should confirm that the new data categories are captured within existing retention schedules and that crypto accounting software or bookkeeping systems used alongside exchange platforms can ingest and preserve this metadata.

What the JVCEA Process Means for Timing

The FSA directed its request to the JVCEA, Japan's industry self-regulatory organisation. The JVCEA has a track record of translating FSA guidance into enforceable member rules, typically through a consultation and rule amendment process. Exchanges that are JVCEA members, which covers the overwhelming majority of FSA-registered platforms, should expect formal JVCEA rule proposals to follow. The FSA's explicit statement that exchanges should determine implementation based on their own operations, services, and risk exposure signals a risk-based rather than prescriptive approach, at least initially.

For accounting firms advising exchange clients, the practical recommendation is to initiate a gap analysis now rather than waiting for JVCEA rule text. The five control areas are clearly articulated, and a gap analysis structured around them can be completed without waiting for binding thresholds to be set. This is also an opportunity to review whether current crypto accounting software and bookkeeping systems produce the audit trails these controls require. For context on how the FSA has been escalating its fraud prevention posture, see our earlier coverage of the FSA Japan escalates crypto fraud prevention initiative.

Practical Steps for Firms and CFOs

The following steps reflect the five control areas in the FSA/NPA request and the accounting implications discussed above.

Immediate Actions

First, map the five requested controls against the exchange client's current technical and operational setup. Identify which controls are partially in place, which require new system builds, and which require third-party vendor involvement. Second, assess whether withdrawal delay logic, if implemented, requires any change to how customer liabilities are classified in the financial statements. Third, confirm that address pre-registration records will be retained in a format that satisfies AML record-keeping obligations and can be accessed by auditors.

Medium-Term Actions

Monitor JVCEA communications for a formal consultation on rule amendments. When the draft rules are published, compare the specific thresholds and timelines against the gap analysis already completed. Engage the exchange's IT and compliance teams early on the MFA upgrade, as hardware-based authentication rollouts typically involve user communication periods that affect customer experience metrics and need to be reflected in operational forecasting.

For firms managing multi-jurisdictional crypto portfolios, this development sits alongside a wider pattern of regulatory tightening. Our pillar resource on crypto compliance reporting provides the broader framework for tracking these changes across jurisdictions.

Japan FSA Requests Crypto Exchange Withdrawal Safeguards: What Accounting Firms and CFOs Must Assess Now

Frequently Asked Questions

Are the FSA safeguards legally binding on Japanese crypto exchanges today?

No. The FSA and NPA issued a request, not a formal regulatory directive. However, the request was directed to the JVCEA, which has the authority to convert FSA guidance into binding member rules. Exchanges should treat the request as a strong indicator of near-term regulatory direction and begin gap analysis immediately.

Which exchanges are in scope?

The request targets exchanges operating under Japan's Payment Services Act registration regime and those registered with the JVCEA. Foreign exchanges without a Japanese registration are not directly in scope, but firms operating internationally should note that Japan's approach often informs regional regulatory thinking.

How should withdrawal delays affect balance sheet reporting?

Funds received but subject to a withdrawal hold represent customer liabilities with a temporary transfer restriction. The appropriate classification under IFRS or Japanese GAAP will depend on the specific duration and conditions of the hold. Auditors and CFOs should assess this as part of financial statement preparation once the exchange's implementation parameters are defined.

What does address pre-registration mean for sanctions screening workflows?

Pre-registration creates a defined point at which external wallet addresses can be screened against sanctions lists before they are activated. This is generally an improvement over screening only at the moment of withdrawal. Compliance teams should update their AML procedures to confirm that screening occurs at registration and is repeated periodically or on trigger events such as a sanctions list update.

How does this interact with FATF travel rule obligations?

Address pre-registration and name-matching at deposit both support the originator and beneficiary data requirements under FATF Recommendation 16. Exchanges that have already implemented travel rule solutions should review whether the new controls are additive or whether existing systems can be extended to cover them without duplicating infrastructure.

Source: Cointelegraph

JPGeneralProposedAML/KYC & Licensing

Related articles

AML/KYC & Licensing
Bitget Exits Japan: What Accounting Firms and CFOs Must Address Now
AML/KYC & Licensing
FSA Japan Escalates Crypto Fraud Prevention: What Accounting Firms and CFOs Must Assess Now
AML/KYC & Licensing
FSA Japan Strengthens Crypto Fraud Prevention: What Accounting Firms and CFOs Must Assess Now
AML/KYC & Licensing
FATF DeFi Report: Regulatory Gaps and the Compliance Priorities for Accounting Firms and CFOs