Japan's FSA Pulls Forward IC-Chip KYC for Bitcoin (BTC) Exchanges Before April 2027
Japan's FSA urged banks and crypto exchanges on October 9 to shift from photo uploads to IC chip identity checks before the April 2027 abolition.
AI SummaryAI
- Japan's FSA on October 9 urged financial institutions to adopt IC chip identity checks early
- The amended enforcement rules abolish photo-upload checks from April 1, 2027
- Park24 disclosed on September 29 that about 1.6 million identity document images leaked at Times Car
- An April 3, 2026 FSA policy requires crypto exchanges to run cybersecurity self-assessments
FSA Notice Pushes Chip Reading Early
Japan's Financial Services Agency issued a notice on Friday, October 9, telling banks, securities firms and other regulated entities to stop relying on uploaded identity document photos for remote verification and move to IC chip reading without waiting for the legal deadline of April 1, 2027. The notice, published on the agency's site, covers every non-face-to-face check, account opening included, and singles out the practice it wants retired: a customer photographing a driver's license or residence certificate and sending the image to the provider. Under the amended enforcement rules of the Act on Prevention of Transfer of Criminal Proceeds, that method is set for abolition on April 1, 2027, after which IC chip reading becomes the default. The notice leaves the statutory date unchanged and leaves the timing of each switch to the operator, but the agency called chip reading extremely effective against forgery and asked firms to act as quickly as circumstances allow. Bitcoin (BTC) price action showed no notable response to the release, which rewrites compliance procedure rather than trading rules. The trigger is a run of intrusions in which customer files, identity images among them, leaked to attackers. The notice names no case, but the pattern is documented: Park24, parent of the car-sharing service Times Car, disclosed on September 29 that roughly 1.6 million identity document images had leaked, including driver's licenses, address proof documents, student IDs from its student plan and family documents under household plans. Nippon Rent-A-Car disclosed a member data breach in the same period. Until operators complete the switch, the agency requires a renewed check of submitted document images and customer face photos for anomalies, on the ground that impersonation techniques keep getting more sophisticated. The notice also carries two cybersecurity demands: firms must review defenses, including third-party risk management and incident response arrangements, in light of the alert the Cabinet's national cyber office issued the same day, close any gaps according to risk, fold in attack methods that become public as investigations proceed, and keep applying the financial-sector cybersecurity guidelines together with the short-term measures already ordered against fast-moving AI-enabled threats.
Crypto Exchanges Inside the Scope
Exchanges sit squarely inside the scope. The agency's October 2024 cybersecurity guidelines list crypto-asset exchange operators alongside banks and securities firms as covered institutions, and exchanges are simultaneously specified business operators under the anti-transfer act, which obliges them to verify each customer's identity at account opening, the step the industry calls KYC. The instruction to move early applies to them without modification, because the agency framed it as a request addressed to all financial institutions. The route most Japanese platforms use today, known as the ho method, has the user photograph their face and an identity document on a smartphone and send both images. The documents collected this way are the same file type that leaked in the recent incidents. The 2027 amendment abolishes that route: non-face-to-face checks move in principle to reading the IC chip of a My Number Card or an equivalent document, or to the public personal authentication service known as JPKI, a certificate built into the same card. Every platform still onboarding customers through document photos will need a rebuilt flow before the deadline. The legal date stays fixed, so each operator controls its own switching schedule, but waiting is now an explicit choice a regulator has discouraged in writing. The work lands on top of an existing program. On April 3, 2026, the agency published a policy dedicated to cybersecurity across the crypto-asset exchange business, requiring every operator to complete a cybersecurity self-assessment from the 2026 business year and raising the security baseline set out in its office guidelines. The frame around the sector is shifting too: in July 2026 the amended Financial Instruments and Exchange Act passed, bringing crypto assets under securities-style rules with insider trading prohibitions and disclosure duties, and on August 7, 2026, the agency reorganized to create a dedicated Crypto-Asset and Stablecoin Division.
A Compressed Compliance Calendar
For Japanese platforms the practical effect is a compressed compliance calendar. The notice is technically non-binding, since the April 1, 2027 date stands and switching remains each operator's call, but a regulator that puts this language in writing rarely stays passive if firms wait. Onboarding flows built around document photos have been the fastest remote method available, and operators that rely on that speed for customer conversion will feel the rebuild cost first. Exchanges that move early also cut their fraud exposure, because chip reading is hard to defeat with a stolen photograph, which is the exact failure mode the recent breaches enabled. Set against the securities-law reclassification and the new division, the sector now has several overlapping workstreams converging on the same window, and the notice effectively tells exchanges to sequence the identity-check rebuild ahead of everything else.
Primary sources
- published a policy · fsa.go.jp
AI-generated, AI-reviewed, under COINOTAG editorial oversight.

