On 9 October 2026 Japan's FSA asked firms to stop image-based ID checks before the April 2027 deadline and move to IC chip verification. What changes for KYC.
Table of contents
On 9 October 2026 Japan's Financial Services Agency asked the firms it supervises to move to IC chip verification without waiting for 1 April 2027, the date Japan's AML rules abolish identity checks based on photographed documents. The request follows a run of breaches that leaked driver's licence images. It is a supervisory request, not a new legal deadline.
- The FSA issued a cybersecurity alert on 9 October 2026 citing repeated unauthorised access that leaked customer data, including images of driver's licences and other identity documents.
- It asks firms to review cybersecurity, including third-party risk management and incident response, and to re-check document and face images in remote onboarding for anything unnatural.
- An ordinance promulgated on 24 June 2025 removes the image-upload methods from 1 April 2027. The FSA asks firms to act on IC chip verification as quickly as possible, without waiting for that date.
- The same day, the National Cybersecurity Office asked businesses holding large volumes of personal data to delete information they no longer need.
- Image-based checks remain lawful until 31 March 2027, but a firm that keeps them now does so against an explicit supervisory request.
What did the FSA ask for on 9 October 2026?
The FSA asked financial institutions and other supervised firms to do three things: review their cybersecurity, including third-party risk management and incident response; scrutinise document and face images in remote onboarding more closely; and bring forward the move from document images to IC chip verification ahead of the legal deadline of 1 April 2027.
The FSA alert opens with the reason. Internet-facing customer services and business systems have suffered repeated unauthorised access, and customer data has leaked, including images of identity documents such as driver's licences. The FSA names no company. Park24 first disclosed the Times Car data breach on 25 September and on 29 September put the accounts with leaked identity document images at about 1.6 million.
The alert grounds its requests in the FSA's Cybersecurity Guidelines for the Financial Sector of 4 October 2024 and in its earlier request on short-term responses to threats from frontier AI, and asks firms to respond under the leadership of senior management. It recalls that remote checks already require reviewing document thickness and the customer's photo, but notes that this is happening "なりすましの手口が巧妙化している中" (as impersonation techniques grow more sophisticated, our translation).
The third request carries the news. Japan's amended AML rules will abolish the method of receiving document images and unify, in principle, on reading the IC chip. The FSA describes chip reading as "不正対策として極めて効果が高い" (extremely effective as a fraud countermeasure, our translation). It asks firms to act "施行日を待たず、可及的速やかな対応を図ること" (without waiting for the effective date, as quickly as possible, our translation).
| Item | Detail |
|---|---|
| Issuer | Financial Services Agency of Japan |
| Date | 9 October 2026 |
| Form | Alert to financial institutions and others (supervisory request) |
| Request 1 | Review cybersecurity, third-party risk and incident response |
| Request 2 | Re-check document and face images in remote verification |
| Request 3 | Move to IC chip reads before 1 April 2027 |
| Linked alert | National Cybersecurity Office, same day |
The alert also points firms to the National Cybersecurity Office notice of the same date and to later public information on the causes and methods of the attacks. Where a review finds gaps, firms should take the necessary measures promptly, in proportion to the risk.
What does the 2027 rule change, and what is its legal status?
The 2027 rule is an amendment to the Enforcement Regulations of the Act on Prevention of Transfer of Criminal Proceeds, Japan's main AML statute. It was promulgated on 24 June 2025 and applies from 1 April 2027. It is adopted and published but not yet applicable, so image-based remote checks stay lawful until 31 March 2027.
The amending ordinance deletes the method known as the ho method: a selfie plus a software-captured image of a photo ID showing the name, address, date of birth, photo and the document's thickness. The label refers to item ho of Regulation Article 6(1)(i) as it stands today; after the amendment, the letter ho designates a chip-read method. It also removes the image option from two other remote methods, leaving them to rely on data read from the document's chip or, for the postal route, an original document, and deletes the method based on posted copies. Its supplementary provision fixes the start date at 1 April 2027 (e-Gov record).
The National Police Agency's Q&A on the amendment explains the aim: removing methods with a high risk of impersonation through forged or altered documents. It adds three practical points. Accounts opened under the old methods do not need re-verification. A copy posted before the change but received after it must be verified again by another method. And IC chip verification must check the expiry date on the chip and confirm the chip data is genuine, for example by decrypting signed data with the public key.
| Remote method for individuals | Until 31 March 2027 | From 1 April 2027 |
|---|---|---|
| Selfie plus photographed photo ID (current item ho) | Permitted | Abolished |
| Selfie plus data read from a photo ID's IC chip | Permitted | Retained |
| Photographed ID plus non-forwardable post | Permitted | Only chip data or a posted original qualify |
| Copies of documents by post | Permitted | Abolished |
| Original of certain anti-forgery documents by post | Permitted | Retained |
| My Number card public key authentication | Permitted | Retained |
The FSA alert does not change any of these dates. It changes the supervisory expectation about when a firm should stop using the methods that are going away.
What does this mean for your KYC obligations?
For firms covered by the AML Act, the alert touches five duties: how customer identity is verified, how long verification records are kept, when suspicious transactions are reported, how internal controls are maintained, and how third-party verification vendors are overseen. Each now carries a sharper supervisory expectation, even though the binding text only changes in April 2027.
Identity verification under Article 4 and Regulation Article 6. The covered businesses listed in Article 2(2) of the Act include banks and crypto-asset exchange service providers. Until 31 March 2027 the ho method remains a lawful way to verify a natural person remotely. After the alert, a firm that keeps it as its main route should be ready to explain why. The practical target is IC chip verification with a selfie, or My Number card authentication, with expiry and authenticity checked on the chip data as the NPA Q&A requires. The Enforcement Regulations set out the full list of methods.
Enhanced scrutiny of images during the transition. The FSA asks firms to check document images and face images for anything unnatural. Leaked licence images are now in circulation, so a firm still accepting photographs should treat a clean image as weak evidence. Liveness detection and checks for reused images become the main defence until the switch.
Record-keeping under Article 6. Verification records must be kept for seven years from the end of the relationship. Switching to chip reads stops new document images accumulating; it does not shorten the retention of images already collected. Those archives remain a target for the full period.
Suspicious transaction reporting under Article 8. Firms must report promptly when they suspect property is criminal proceeds. An application that reuses a leaked licence image is an impersonation signal to weigh in that decision, alongside the synthetic fraud patterns that follow large identity leaks.
Internal controls under Article 11. The Act requires covered businesses to keep verification information up to date and to work towards training, internal rules and an officer in charge of these measures. A remote onboarding flow the regulator now treats as high risk is a natural subject for that review now, not in 2027.
Third-party risk management. The alert names third-party risk management explicitly, and the NCO notice spells out what that means for contractors. The National Cybersecurity Office notice asks businesses to keep data given to contractors to the minimum, to make sure contractors delete it when the work ends, and to delete information whose purpose has ended. For eKYC vendors that hold document images on a firm's behalf, those are direct questions for the next vendor review.
What is still uncertain, and what are the risks?
Four points remain open: how hard the FSA will push before April 2027, how customers without chip documents or NFC phones will be served, whether vendors can migrate in time, and whether chip reads alone shrink the data that attackers target. The alert answers none of them directly.
The first is enforceability. The alert is a request. It does not amend the ordinance, and it sets no interim deadline. A firm cannot breach the 2027 rule before it applies, but the FSA can assess its controls now against the existing cybersecurity guidelines and the internal-control duty in Article 11 of the AML Act. In our view, the gap is more likely to be closed through supervisory dialogue than penalties.
The second is coverage. Not every customer has a chip document or an NFC-capable phone. The NPA Q&A points to the retained route of posting originals of certain anti-forgery documents, but that route is slower and costs conversion.
The third is capacity. Many firms rely on eKYC vendors, and every regulated firm in Japan now faces the same request at once. A firm that moves late may find integration queues, while a firm that rushes may skip the expiry and authenticity checks the NPA Q&A requires.
The fourth is the data itself. IC chip verification makes forged images useless for onboarding, but a firm that stores the chip data and selfie in one central database still holds a valuable archive. The NCO notice speaks to that risk: hold less, delete what has served its purpose, and encrypt what remains. Combining chip reads with data minimisation addresses both the fraud and the breach problem.
How does Japan compare with other regulators?
Japan is moving from guidance to a hard technical cut-off. Hong Kong and the EU are tightening remote onboarding as well, but through principles and default routes rather than a named method ban. Japan's approach is the most prescriptive of the three, and the FSA alert makes it the most urgent.
| Regulator | Instrument and date | Legal status | Effect on remote ID checks |
|---|---|---|---|
| Japan FSA | Alert, 9 October 2026 | Supervisory request | Move to chip reads before April 2027 |
| Cabinet Office and seven ministries | Joint amending ordinance, 24 June 2025 | Adopted, applies 1 April 2027 | Image-upload methods abolished |
| HKMA | Circular, 3 September 2026 | Supervisory guidance | Full review of remote onboarding, deepfakes named |
| AMLA | Final draft CDD RTS, 1 October 2026 | Draft sent to the Commission | ID document or eID default, other tools a justified fallback |
The HKMA remote onboarding circular sets no deadline and drops the technology examples of its 2019 predecessor. The AMLA CDD RTS keep identity documents and eIDAS electronic identification as defaults and make other remote tools a fallback the firm must justify. Japan names the method to retire and the date.
How should compliance teams respond?
Teams with Japanese customers should treat April 2027 as already here. Inventory every remote flow that still accepts photographed documents, including vendor-run flows, and set a switch date for IC chip verification well before the deadline. Confirm the vendor checks chip expiry and signature authenticity. Until the switch, add liveness checks, flag document images already seen on another application or account, and step up checks when a licence image arrives without a chip read.
IC chip verification fixes onboarding, not storage, so review the archive next. List where document images sit, who holds them and for how long, and delete what is past its retention period. Ask vendors the NCO's questions: what data they hold for you, how access is logged, and how deletion is confirmed when a contract ends. Teams outside Japan should read the alert as a preview of where remote onboarding rules are heading.
For customers who verify with a passport, Zyphe reads the NFC chip to ICAO 9303 standards, runs two-step liveness and needs no image upload. Documents and biometrics are encrypted into the user's own vault, split across nodes and unlockable only with a key the user or customer holds, so your business receives verification results, not a central store of customer PII. See how Zyphe KYC software works, or book a demo.
The bottom line
Japan has decided that a photograph of an identity document is no longer good enough evidence of identity, and its regulator now wants firms to act on that before the law forces them to. The lesson travels: read the chip, check its signature, and hold as little of what you collect as the law allows.
Cited sources
- FSA alert on strengthening cybersecurity and responses to transaction applications, 9 October 2026 (Japanese)
- FSA Cybersecurity Guidelines for the Financial Sector, 4 October 2024 (Japanese)
- National Cybersecurity Office alert on responses to leaks caused by unauthorised access, 9 October 2026 (Japanese)
- Ordinance amending the Enforcement Regulations of the Act on Prevention of Transfer of Criminal Proceeds, 24 June 2025 (Japanese)
- e-Gov public comment record for the 2025 amending ordinance, with promulgation date (Japanese)
- National Police Agency Q&A on the amendment to the Enforcement Regulations (Japanese)
- Act on Prevention of Transfer of Criminal Proceeds, Articles 2, 4, 6, 8 and 11, on e-Gov (Japanese)
- Enforcement Regulations of the Act on Prevention of Transfer of Criminal Proceeds, Article 6, on e-Gov (Japanese)
Michelangelo Frigo (Co-Founder at Zyphe) Michelangelo Frigo is a privacy and identity infrastructure expert and co-founder of Zyphe.