Buying a transaction monitoring system for Japan means satisfying two different demands at once. The Financial Services Agency judges whether you can evidence that your scenarios and thresholds work, while Japanese name and address data forces matching problems that Latin-script products handle poorly. Vendor selection has to answer both.
Key takeaways
- The FSA requires scenarios and thresholds set from the institution's own risk assessment, then improved using analysis of transactions already reported as suspicious.
- JAFIC received 849,861 suspicious transaction reports in 2024, up from 707,929 in 2023, so alert volume and case throughput are capacity questions before they are technology questions.
- Japanese names cross writing systems rather than spellings, and the katakana readings introduced into the family register on 26 May 2025 changed what reference data is available.
- The FSA fined nobody in the AEON Bank case, but its January 2025 order recorded 14,639 detected transactions left without a suspicion judgement and a 152-day average filing delay in February 2024.
- Effectiveness validation, not documentation, is the current supervisory theme, and the FSA expects quantitative indicators to support it.
What does the FSA expect a monitoring system to demonstrate?
Four things, and only one of them is detection. The Guidelines for Anti-Money Laundering and Combating the Financing of Terrorism, revised on 31 March 2026, require an institution to set scenarios and thresholds that reflect the result of its own risk assessment, rather than adopting a vendor's defaults unchanged.
The second requirement is a feedback loop. The institution must analyse the characteristics of transactions for which it has filed suspicious transaction reports, including line of business and geography, judge the effectiveness of current scenarios and thresholds against that, and enhance the monitoring method accordingly.
Third, filtering for sanctions is treated as a separate framework from monitoring, with its own requirement that lists stay current and detection criteria be reviewed at a frequency set by risk. Fourth, the response has to be proportionate to the level of suspicion, which means an alert model that only ever produces one outcome will not satisfy the text.
Which selection criteria matter most in the Japanese market?
Score vendors against the obligation, not the feature list. Every row below maps a requirement in the FSA Guidelines to the evidence a buyer should demand during evaluation rather than after go-live.
| Criterion | What the FSA text requires | Evidence to demand before purchase |
|---|---|---|
| Scenario design | Scenarios and thresholds reflecting your own risk assessment | Ability to author and version scenarios in-house, not vendor-only change control |
| Feedback loop | Analysis of filed STR characteristics feeding scenario change | Reporting that joins alert outcomes to filed reports by typology and geography |
| Japanese name matching | Detection of high-risk customers using reliable databases and systems | Blind test on your own kanji, katakana and romanised name data |
| Sanctions filtering | Up-to-date lists, criteria reviewed at a risk-based frequency | List update latency, and evidence of screening on designation day |
| Explainability | Risk mitigation proportionate to level of suspicion | Per-alert reason codes an analyst and an examiner can both read |
| Data governance | Periodic validation of the integrity and accuracy of system data | Data quality reporting and reconciliation against source systems |
| Auditability | Effectiveness evaluated through independent assurance | Exportable audit trail covering tuning changes and who approved them |
| Outsourcing | Own analysis where a process is outsourced or shared | Right to inspect, and model documentation you may show a supervisor |
Why do kanji, kana and romaji break standard name matching?
Because the problem is transliteration, not spelling. A Japanese personal name is normally written in kanji, and most kanji carry several possible readings, so the written form does not determine the pronunciation and the pronunciation does not determine the written form. Fuzzy string matching assumes the opposite.
The writing systems then multiply. The same name may reach your screening engine as kanji, as hiragana, as katakana in full-width or half-width encoding, or as a Latin transcription, and Japanese core banking systems have historically stored the katakana reading rather than the kanji. Sanctions and PEP lists are published mainly in Latin script.
Romanisation adds a third layer of variation. Long vowels can be written with a macron, doubled, marked with an h, or dropped entirely, and given name and surname order flips between Japanese and Western convention. A matching engine that treats these as typographical noise will either miss the match or drown the analyst.
What changed in Japanese name data in 2025 and 2026?
The reference data improved. The revised Family Register Act took effect on 26 May 2025, adding katakana readings to the family register for the first time, and the Ministry of Justice records that the notification window closed on 25 May 2026, after which municipalities recorded readings automatically.
That matters for screening because it makes an authoritative reading available for a population where the reading was previously a matter of convention. It also means customer records captured before 2025 may carry a reading that differs from the one now on the register.
The practical consequence is a data question to put to a vendor. Ask how the system stores kanji and reading as separate attributes, whether it can match across them, and what happens when a customer's registered reading is updated. A product that normalises everything into one romanised string discards the very field that the reform created.
How do you tune false positives without weakening detection?
Tune against outcomes, and record the reasoning. The Guidelines require thresholds to be tightened for high-risk customers and permit them to be raised for customers assessed as low risk under simplified due diligence, so tuning is expected to be risk-differentiated rather than uniform.
The FSA's March 2025 paper on validation of effectiveness sets the standard a tuning exercise is now judged against. It asks institutions to verify both the design and the implementation of mitigation measures, qualitatively and quantitatively using indicators, and it opens by warning readers not to use the document as a checklist.
Volume gives the exercise its urgency. Against the 849,861 reports filed nationally in 2024 recorded by JAFIC, of which banks and comparable depository institutions filed 580,382, an alert population that grows faster than analyst capacity produces the failure mode Japanese supervisors have already penalised, which is unreviewed alerts rather than undetected ones. Our guide to reducing false positives covers the mechanics in more detail.
What does Japanese enforcement show about weak monitoring?
It shows that the gap regulators punish sits after detection. On 29 January 2025 the FSA issued a business improvement order to AEON Bank under Article 26(1) of the Banking Act, citing at least 14,639 transactions detected by the bank's transaction monitoring system that were left without any judgement on whether they were suspicious.
Timeliness featured alongside volume. The order records that the average number of days before filing peaked at 152 in February 2024, and that the bank had not completed the control environment the FSA had required by the end of March 2024. An improvement plan was due by 31 January 2025, with quarterly progress reports from 28 February 2025.
The governance finding is the one worth quoting internally. The FSA concluded that the board and management had failed to take the initiative in ascertaining the reality of the position or giving instructions. Detection technology was not the deficiency; the operating model around it was.
What evidence will an inspection actually ask for?
Data, and the trail behind decisions. The Guidelines require an institution to ensure the accuracy of customer identification and transaction records, to periodically validate the integrity and accuracy of the data its systems consume, and to organise that data so it can be analysed and submitted to the authorities.
They also name specific holdings. An institution is expected to be able to produce the number of suspicious transaction reports filed, broken down by country or geographic area and customer attribute, together with internal audit and training records and the reports made to the board on the risk control framework.
Independent assurance closes the loop. System effectiveness must be evaluated through an independent assurance process such as internal or external audit, and where any process is outsourced or a shared system is used, the institution must still analyse its own business and decide whether additional measures are needed. Buy accordingly, because a system that cannot export its own tuning history cannot support any of this.
Should you buy cloud, on-premises or a shared system?
The Guidelines take no position, which is itself the answer. What they require is that the institution verify that system design and operation respond to trends in money laundering and terrorist financing risk and remain consistent with its own risk control framework, and that it regularly review and enhance the system.
Shared and outsourced arrangements are common among Japan's regional banks, shinkin banks and credit cooperatives, and the Guidelines address them directly by requiring the user institution to analyse its own business characteristics and accompanying risks and determine whether additional measures are necessary. Responsibility does not transfer with the hosting.
Ask two commercial questions early. Whether you can change a scenario without a vendor release, and whether you can extract your own alert, disposition and tuning history if you leave. Platforms that combine monitoring with sanctions and PEP screening, as MemberCheck does, reduce reconciliation work between the two, but the export question still applies.
Which questions belong on the vendor shortlist?
The evidential ones come first. Ask whether your own team can author and version a scenario without waiting for a vendor release, whether the vendor can show alert-to-report conversion broken down by scenario, and what the list update latency is for a designation published on a Friday evening in Tokyo.
The Japanese specifics come next, and a demonstration beats a datasheet. Insist on a blind match test against your own file of kanji, katakana and romanised names, ask how the product stores written form and reading as separate attributes, and establish what happens to existing matches when a customer's registered reading is updated.
The supervisory questions close the evaluation, because they decide what you can show an examiner. Print a single alert's reason code and read it as an outsider would, confirm what tuning history you can export without vendor assistance, and settle who signs the model documentation the FSA may ask to see. For the wider obligations see our guides to AML compliance in Japan, the 2026 FSA Guidelines changes, our transaction monitoring solution, and the Japan country coverage page.



