Blog

Jurisdictions & Regulation

FSA AML/CFT Guidelines: What the March 2026 Revision Changed

The FSA revised its AML/CFT guidelines on 31 March 2026, deleting the expected-actions tier and adding required actions on outsourcing, monitoring and new technologies.

Japan's Financial Services Agency revised its AML/CFT guidelines on 31 March 2026, effective the same day with no transition period. The revision deleted the entire expected-actions tier and the advanced-practice examples, added a required action on outsourcing, and promoted the new technologies item from expected to required.

Key takeaways

  • The revised guidelines and FAQ took effect on 31 March 2026, the day of publication, and have applied for the whole period since.
  • The deleted expected actions were not made mandatory. The FSA moved them into the FAQ as examples, and said firms should continue with those they judge necessary for their own risks.
  • One expected action was promoted to required: examining the benefits and effectiveness of new technologies.
  • A wholly new section requires firms outsourcing ML/FT risk management work to verify the outsourcing contractor's control framework.
  • The FSA set an end of March 2024 deadline for basic framework completion and reported a 99% completion rate, which is the stated reason the guidelines moved on.

What changed in the FSA guidelines on 31 March 2026?

Structurally, the guidelines lost a layer. The pre-2026 text carried three tiers: required actions, expected actions, and advanced practice examples drawn from monitoring of Japanese and foreign institutions. The revised text contains only required actions, twenty blocks of them.

Against that subtraction sit four additions. A new subsection III-3(4) covers the management of outsourcing of ML/FT risk management. A new item (c) under transaction monitoring requires risk mitigation measures proportionate to the level of suspicion detected. The trade finance requirement was widened to cover mitigation, and the new technologies item moved up a tier.

The FAQ was revised on the same day and grew considerably, to 160 pages in the English provisional translation. That is where most of the deleted material now lives.

The precise wording changes are set out clause by clause in the FSA's own old-and-new comparison table. The table below summarises the substantive shifts.

AreaBefore 31 March 2026From 31 March 2026
Document tiersRequired actions, expected actions, advanced practice examplesRequired actions only
New technologies (II-2(5))Expected action; section headed "Use of FinTech etc."Required action; section headed "New technologies"
Outsourcing of risk managementNot addressedNew III-3(4) with a required action to verify the contractor's framework
Transaction monitoring (II-2(3)(iii))Two required items: set scenarios and thresholds; analyse and improve themThird item added: apply mitigation proportionate to the level of suspicion
Trade-based finance (II-2(4)(ii))Identify and assess the riskIdentify, assess and mitigate the risk
Deleted expected actions and examplesIn the guidelinesRelocated into the FAQ as examples

Why did the FSA delete the expected-actions tier?

The FSA gave its reasoning in the consultation announcement of 19 January 2026 and repeated it in the published response to comments. Basic risk management frameworks at financial institutions are, in its assessment, largely complete, so the guidelines no longer need to carry an aspirational tier alongside the mandatory one.

That assessment rests on a measurable milestone. The FSA required firms to complete framework building against the required actions by the end of March 2024 and to report results by the end of April. Its June 2025 review put the completion rate at 99% as at 31 March 2024, with targeted inspections following up on the remainder.

Two forward-looking drivers were also named. The first is strengthening measures against fraudulent use of deposit accounts, which is the same policy concern behind the June 2026 amendments to the Act on Prevention of Transfer of Criminal Proceeds. The second is the methodology for the FATF fifth round mutual evaluation.

Consultation ran from 19 January to 19 February 2026 and drew 52 comments from 18 individuals and organisations, a large share of them asking exactly what the deletions meant.

Where did the deleted expected actions go?

Into the FAQ, not into the bin. This is the point most secondary commentary gets wrong, and the FSA answered it directly in its response to consultation comments.

The FSA's position is that expected actions and advanced practice examples were always addressed at particular situations, or at institutions of a certain size or business profile, from the standpoint of building a more robust framework. Rather than delete them outright, it relocated them into the FAQ entries attached to the existing required actions, as examples of initiatives.

The consequence for firms is a change of status, not of substance. A firm whose own risk assessment made a former expected action necessary should still be doing it; what has gone is the implication that every institution should be working towards all of them.

Reading the guidelines without the FAQ is therefore now a mistake it was previously possible to get away with. The material deleted from one document is the material added to the other.

Which new required actions apply now?

Three additions bind every FSA-regulated institution from 31 March 2026. The first is outsourcing, dealt with in its own section below. The second sits inside transaction monitoring: alongside setting scenarios and thresholds that reflect the firm's risk assessment, and analysing filed report characteristics to improve them, firms must now implement risk mitigation measures according to the level of suspicion of detected transactions and trends in ML/FT risk.

That third item closes a gap between detection and response. A monitoring system that generates alerts and files reports, but applies the same treatment to a weak alert and a strong one, no longer satisfies the required actions. It is the reason transaction monitoring tuning and alert triage now attract inspection attention together rather than separately.

The trade finance change is smaller but reads the same way. The requirement previously covered identification and assessment of risk in financing and extending credit involving trade-based finance; it now covers mitigation as well.

Several detailed expected actions on trade finance were deleted at the same time, including price benchmarking against market rates and re-screening against sanctions lists at document receipt, amendment and execution. Those moved to the FAQ.

What does the new outsourcing requirement mean in practice?

Section III-3(4) is new text rather than reworded text. It acknowledges that firms may outsource ML/FT risk management work depending on the characteristics of their business, and then sets the test: the control framework of the outsourcing contractor must be verified from the standpoint of achieving the same level of effectiveness required by the required actions.

The standard is effect-equivalence, not contract-equivalence. Confirming that a vendor holds a certification, or that a service agreement contains AML clauses, does not on its own answer the question the guidelines ask. What has to be verified is whether the outsourced work delivers what the firm would have had to deliver itself.

The section sits under the three lines of defence heading, which places responsibility with the second line and the board rather than with procurement. It also has to be read with the FSA's encouragement elsewhere in the guidelines of joint operation by outsourcing in areas such as customer due diligence, risk assessment and monitoring.

Firms buying screening or monitoring services should expect to evidence how they tested the provider, not only that they selected one. Our enhanced due diligence and identity verification pages set out the control points that verification usually covers.

Why was the FinTech section renamed?

The section heading changed from "Use of FinTech etc." to "New technologies", and the substance changed with it. Under the old text, examining the benefits of new technology was an expected action, phrased as something institutions were encouraged to consider actively. It is now a required action.

The wording of the requirement is deliberately open. A firm must examine the benefits and effectiveness of new technologies as necessary, and explore the possibility of using them based on its own size, characteristics and business content, taking account of what other institutions do and the issues around introduction. The guidelines name artificial intelligence, blockchain and robotic process automation as examples.

Nothing in the text mandates adopting any specific technology. What it mandates is a documented examination, proportionate to the firm's profile, of whether available technology would make its controls more effective or more efficient.

The practical reading is that a firm running manual controls at scale now needs a reasoned answer to why, rather than silence. That answer belongs in the same record as the risk assessment it follows from.

Is there a transition period, and what happens next?

There is no transition period. The FSA's notice states that the revised guidelines and the revised FAQ apply as of the date of publication, 31 March 2026. Firms have been inspected against the revised text since then, and the change is not forthcoming in any sense.

Supervision has already moved beyond framework building. The FSA's July 2026 report on AML and financial crime initiatives records that since the 2025 programme year it has been confirming, through inspections and other supervisory activity, whether each institution is verifying the effectiveness of what it built.

Further change is signalled rather than scheduled. The same report describes continued agile updates to the guidelines and FAQ, so the March 2026 text should not be treated as a settled position for the next several years the way the 2021 version was.

The FATF fifth round mutual evaluation of Japan is the backdrop. The FSA has published no assessment date for Japan, and firms should treat any specific date they see as unsourced; what it has published is the instruction to analyse the results of the first five countries assessed under the new methodology, being Malaysia, Belgium, Italy, Austria and Singapore.

What should a firm do differently now?

Start with the FAQ, because that is where the guidance moved. A gap analysis run against the guidelines alone will now show fewer expectations than a year ago, which is the opposite of what the revision intended.

Next, evidence the two genuinely new obligations. For outsourcing, that means a documented verification of each provider's control framework against the effect the required actions target, refreshed rather than done once at selection. For monitoring, it means showing that alert handling differentiates by level of suspicion and by current risk trends, not only that alerts are worked and closed.

Third, write down the technology examination. The requirement is satisfied by a reasoned, proportionate assessment on file, and failed by having nothing on file at all.

None of this replaces the statutory duties. Verification, record retention and reporting continue to come from the Act on Prevention of Transfer of Criminal Proceeds, which our APTCP compliance guide covers article by article, while the regime overview and the Japan country coverage page set out how the layers interact for financial institutions.

FAQ

Common questions.

When did the revised FSA AML/CFT guidelines take effect?
31 March 2026, the day they were published. The FSA's notice of the public comment results states that the revised guidelines and the revised FAQ apply as of that date, and no transition period was set. Firms have been supervised against the revised text since then.
Did the FSA make best practices mandatory in 2026?
No. The FSA deleted the expected-actions tier and the advanced-practice examples from the guidelines, but moved that material into the FAQ as examples of initiatives. In its published response to consultation comments the FSA said firms that judge those measures necessary for their own risks should continue with them. Only one expected action was promoted to a required action.
Which new required actions did the March 2026 revision add?
Three. A new requirement to verify the control framework of any third party to which ML/FT risk management work is outsourced, a new transaction monitoring item requiring risk mitigation measures proportionate to the level of suspicion detected, and the promotion of the new technologies item from expected to required. The trade finance requirement was also extended from identification and assessment to include mitigation.
Why did the FSA revise the guidelines in 2026?
The FSA said basic AML risk management frameworks at financial institutions were largely complete, having set an end of March 2024 deadline with a 99% reported completion rate. The revision responds to strengthening measures against fraudulent use of deposit accounts and to the FATF fifth round mutual evaluation methodology.
Do the FSA AML/CFT guidelines have the force of law?
They are supervisory guidelines rather than statute. The statutory duties sit in the Act on Prevention of Transfer of Criminal Proceeds and the Foreign Exchange and Foreign Trade Act. The FSA inspects against the guidelines and can escalate to supervisory action, so in practice they set the standard for FSA-regulated financial institutions.

See MemberCheck against your own risk data.

Book a walkthrough with our compliance team and screen a real case in the first session.