Skip to content
Free guide: How to use AI in compliance
Editorial illustration for the article "Japan's FSA wants IC chip verification now, not in April 2027".

On 9 October 2026 Japan's FSA asked firms to stop image-based ID checks before the April 2027 deadline and move to IC chip verification. What changes for KYC.

Table of contents

On 9 October 2026 Japan's Financial Services Agency asked the firms it supervises to move to IC chip verification without waiting for 1 April 2027, the date Japan's AML rules abolish identity checks based on photographed documents. The request follows a run of breaches that leaked driver's licence images. It is a supervisory request, not a new legal deadline.

  • The FSA issued a cybersecurity alert on 9 October 2026 citing repeated unauthorised access that leaked customer data, including images of driver's licences and other identity documents.
  • It asks firms to review cybersecurity, including third-party risk management and incident response, and to re-check document and face images in remote onboarding for anything unnatural.
  • An ordinance promulgated on 24 June 2025 removes the image-upload methods from 1 April 2027. The FSA asks firms to act on IC chip verification as quickly as possible, without waiting for that date.
  • The same day, the National Cybersecurity Office asked businesses holding large volumes of personal data to delete information they no longer need.
  • Image-based checks remain lawful until 31 March 2027, but a firm that keeps them now does so against an explicit supervisory request.

What did the FSA ask for on 9 October 2026?

The FSA asked financial institutions and other supervised firms to do three things: review their cybersecurity, including third-party risk management and incident response; scrutinise document and face images in remote onboarding more closely; and bring forward the move from document images to IC chip verification ahead of the legal deadline of 1 April 2027.

The FSA alert opens with the reason. Internet-facing customer services and business systems have suffered repeated unauthorised access, and customer data has leaked, including images of identity documents such as driver's licences. The FSA names no company. Park24 first disclosed the Times Car data breach on 25 September and on 29 September put the accounts with leaked identity document images at about 1.6 million.

The alert grounds its requests in the FSA's Cybersecurity Guidelines for the Financial Sector of 4 October 2024 and in its earlier request on short-term responses to threats from frontier AI, and asks firms to respond under the leadership of senior management. It recalls that remote checks already require reviewing document thickness and the customer's photo, but notes that this is happening "なりすましの手口が巧妙化している中" (as impersonation techniques grow more sophisticated, our translation).

The third request carries the news. Japan's amended AML rules will abolish the method of receiving document images and unify, in principle, on reading the IC chip. The FSA describes chip reading as "不正対策として極めて効果が高い" (extremely effective as a fraud countermeasure, our translation). It asks firms to act "施行日を待たず、可及的速やかな対応を図ること" (without waiting for the effective date, as quickly as possible, our translation).

ItemDetail
IssuerFinancial Services Agency of Japan
Date9 October 2026
FormAlert to financial institutions and others (supervisory request)
Request 1Review cybersecurity, third-party risk and incident response
Request 2Re-check document and face images in remote verification
Request 3Move to IC chip reads before 1 April 2027
Linked alertNational Cybersecurity Office, same day

The alert also points firms to the National Cybersecurity Office notice of the same date and to later public information on the causes and methods of the attacks. Where a review finds gaps, firms should take the necessary measures promptly, in proportion to the risk.

The 2027 rule is an amendment to the Enforcement Regulations of the Act on Prevention of Transfer of Criminal Proceeds, Japan's main AML statute. It was promulgated on 24 June 2025 and applies from 1 April 2027. It is adopted and published but not yet applicable, so image-based remote checks stay lawful until 31 March 2027.

The amending ordinance deletes the method known as the ho method: a selfie plus a software-captured image of a photo ID showing the name, address, date of birth, photo and the document's thickness. The label refers to item ho of Regulation Article 6(1)(i) as it stands today; after the amendment, the letter ho designates a chip-read method. It also removes the image option from two other remote methods, leaving them to rely on data read from the document's chip or, for the postal route, an original document, and deletes the method based on posted copies. Its supplementary provision fixes the start date at 1 April 2027 (e-Gov record).

The National Police Agency's Q&A on the amendment explains the aim: removing methods with a high risk of impersonation through forged or altered documents. It adds three practical points. Accounts opened under the old methods do not need re-verification. A copy posted before the change but received after it must be verified again by another method. And IC chip verification must check the expiry date on the chip and confirm the chip data is genuine, for example by decrypting signed data with the public key.

Remote method for individualsUntil 31 March 2027From 1 April 2027
Selfie plus photographed photo ID (current item ho)PermittedAbolished
Selfie plus data read from a photo ID's IC chipPermittedRetained
Photographed ID plus non-forwardable postPermittedOnly chip data or a posted original qualify
Copies of documents by postPermittedAbolished
Original of certain anti-forgery documents by postPermittedRetained
My Number card public key authenticationPermittedRetained

The FSA alert does not change any of these dates. It changes the supervisory expectation about when a firm should stop using the methods that are going away.

What does this mean for your KYC obligations?

For firms covered by the AML Act, the alert touches five duties: how customer identity is verified, how long verification records are kept, when suspicious transactions are reported, how internal controls are maintained, and how third-party verification vendors are overseen. Each now carries a sharper supervisory expectation, even though the binding text only changes in April 2027.

Identity verification under Article 4 and Regulation Article 6. The covered businesses listed in Article 2(2) of the Act include banks and crypto-asset exchange service providers. Until 31 March 2027 the ho method remains a lawful way to verify a natural person remotely. After the alert, a firm that keeps it as its main route should be ready to explain why. The practical target is IC chip verification with a selfie, or My Number card authentication, with expiry and authenticity checked on the chip data as the NPA Q&A requires. The Enforcement Regulations set out the full list of methods.

Enhanced scrutiny of images during the transition. The FSA asks firms to check document images and face images for anything unnatural. Leaked licence images are now in circulation, so a firm still accepting photographs should treat a clean image as weak evidence. Liveness detection and checks for reused images become the main defence until the switch.

Record-keeping under Article 6. Verification records must be kept for seven years from the end of the relationship. Switching to chip reads stops new document images accumulating; it does not shorten the retention of images already collected. Those archives remain a target for the full period.

Suspicious transaction reporting under Article 8. Firms must report promptly when they suspect property is criminal proceeds. An application that reuses a leaked licence image is an impersonation signal to weigh in that decision, alongside the synthetic fraud patterns that follow large identity leaks.

Internal controls under Article 11. The Act requires covered businesses to keep verification information up to date and to work towards training, internal rules and an officer in charge of these measures. A remote onboarding flow the regulator now treats as high risk is a natural subject for that review now, not in 2027.

Third-party risk management. The alert names third-party risk management explicitly, and the NCO notice spells out what that means for contractors. The National Cybersecurity Office notice asks businesses to keep data given to contractors to the minimum, to make sure contractors delete it when the work ends, and to delete information whose purpose has ended. For eKYC vendors that hold document images on a firm's behalf, those are direct questions for the next vendor review.

What is still uncertain, and what are the risks?

Four points remain open: how hard the FSA will push before April 2027, how customers without chip documents or NFC phones will be served, whether vendors can migrate in time, and whether chip reads alone shrink the data that attackers target. The alert answers none of them directly.

The first is enforceability. The alert is a request. It does not amend the ordinance, and it sets no interim deadline. A firm cannot breach the 2027 rule before it applies, but the FSA can assess its controls now against the existing cybersecurity guidelines and the internal-control duty in Article 11 of the AML Act. In our view, the gap is more likely to be closed through supervisory dialogue than penalties.

The second is coverage. Not every customer has a chip document or an NFC-capable phone. The NPA Q&A points to the retained route of posting originals of certain anti-forgery documents, but that route is slower and costs conversion.

The third is capacity. Many firms rely on eKYC vendors, and every regulated firm in Japan now faces the same request at once. A firm that moves late may find integration queues, while a firm that rushes may skip the expiry and authenticity checks the NPA Q&A requires.

The fourth is the data itself. IC chip verification makes forged images useless for onboarding, but a firm that stores the chip data and selfie in one central database still holds a valuable archive. The NCO notice speaks to that risk: hold less, delete what has served its purpose, and encrypt what remains. Combining chip reads with data minimisation addresses both the fraud and the breach problem.

How does Japan compare with other regulators?

Japan is moving from guidance to a hard technical cut-off. Hong Kong and the EU are tightening remote onboarding as well, but through principles and default routes rather than a named method ban. Japan's approach is the most prescriptive of the three, and the FSA alert makes it the most urgent.

RegulatorInstrument and dateLegal statusEffect on remote ID checks
Japan FSAAlert, 9 October 2026Supervisory requestMove to chip reads before April 2027
Cabinet Office and seven ministriesJoint amending ordinance, 24 June 2025Adopted, applies 1 April 2027Image-upload methods abolished
HKMACircular, 3 September 2026Supervisory guidanceFull review of remote onboarding, deepfakes named
AMLAFinal draft CDD RTS, 1 October 2026Draft sent to the CommissionID document or eID default, other tools a justified fallback

The HKMA remote onboarding circular sets no deadline and drops the technology examples of its 2019 predecessor. The AMLA CDD RTS keep identity documents and eIDAS electronic identification as defaults and make other remote tools a fallback the firm must justify. Japan names the method to retire and the date.

How should compliance teams respond?

Teams with Japanese customers should treat April 2027 as already here. Inventory every remote flow that still accepts photographed documents, including vendor-run flows, and set a switch date for IC chip verification well before the deadline. Confirm the vendor checks chip expiry and signature authenticity. Until the switch, add liveness checks, flag document images already seen on another application or account, and step up checks when a licence image arrives without a chip read.

IC chip verification fixes onboarding, not storage, so review the archive next. List where document images sit, who holds them and for how long, and delete what is past its retention period. Ask vendors the NCO's questions: what data they hold for you, how access is logged, and how deletion is confirmed when a contract ends. Teams outside Japan should read the alert as a preview of where remote onboarding rules are heading.

For customers who verify with a passport, Zyphe reads the NFC chip to ICAO 9303 standards, runs two-step liveness and needs no image upload. Documents and biometrics are encrypted into the user's own vault, split across nodes and unlockable only with a key the user or customer holds, so your business receives verification results, not a central store of customer PII. See how Zyphe KYC software works, or book a demo.

The bottom line

Japan has decided that a photograph of an identity document is no longer good enough evidence of identity, and its regulator now wants firms to act on that before the law forces them to. The lesson travels: read the chip, check its signature, and hold as little of what you collect as the law allows.

Cited sources

Michelangelo Frigo Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.

Frequently Asked Questions

The FSA issued an alert asking financial institutions to review cybersecurity, including third-party risk and incident response, to re-check document and face images in remote onboarding, and to move to IC chip verification without waiting for 1 April 2027, the date Japan's AML rules abolish image-based identity checks.

No. The amending ordinance applies from 1 April 2027, so the method based on a selfie and a photographed ID document remains lawful until 31 March 2027. The FSA alert is a supervisory request to stop earlier, not a change to the legal deadline.

IC chip verification means the customer uses the firm's software to read the name, address, date of birth and photo stored on the chip of a photo ID, usually with a selfie. The National Police Agency's Q&A says firms must also check the expiry date and confirm the chip data is genuine.

No. The National Police Agency's Q&A says accounts opened under the old methods before 1 April 2027 do not need re-verification, although their verification records must still be kept for seven years after the relationship ends.

The alert is addressed to financial institutions and other firms the FSA supervises. Crypto-asset exchange service providers are covered businesses under Article 2(2) of the Act on Prevention of Transfer of Criminal Proceeds, so the 2027 rule applies to them, and the FSA's request is relevant to their onboarding flows.

See privacy-first KYC in action

Verify identity without a central store of documents. Reusable credentials, an exportable audit trail, and a 15-minute integration.

Book a demo