Custodial wallet / SaaS in Japan
Hosted wallet provider that holds keys on behalf of end users, often white-labeled to businesses (custody as a service).
Custodial SaaS is conditionally permitted in Japan with a local entity, subject to AML obligations and high licensing burden.
Verdict Details
- Permitted
- conditional
- Local entity required
- Yes
- Licensing burden
- High
- Last updated
- 2026-07-13
AML Obligations
- VASPs (including custodial wallet providers) must register as a Crypto-Asset Exchange Service Provider (CAESP) with the FSA under the Payment Services Act
- Comprehensive KYC procedures required for all customers (aligned with FATF recommendations)
- Transaction monitoring and suspicious activity reporting (SAR) obligations to the FSA
- Travel Rule compliance expected (FATF-aligned rules apply)
- Ongoing AML/CFT compliance programs required with internal controls and audits
Key Restrictions
- Must register as a CAESP (Crypto-Asset Exchange Service Provider) with the FSA — the custodial wallet SaaS model falls under 'management of crypto-assets for others'
- Minimum capital of JPY 10M (~$70K USD) required
- Must maintain positive net assets at all times
- Mandatory segregation of customer assets (trust account or equivalent required)
- 100% cold storage recommended for customer assets
- JVCEA membership is mandatory (self-regulatory organization)
- Multi-signature wallets, penetration testing, and internal audits required by regulation
- Token listings must be pre-screened by JVCEA
- Application timeline of 6-18 months for CAESP registration
Key Risks
- FSA has enforcement power to issue administrative orders, impose penalties, and revoke licenses — high regulatory scrutiny
- The boundary between the custodial SaaS provider's AML obligations and the white-label client's obligations is not explicitly delineated in the regulatory framework — both likely need separate CAESP registrations
- Stablecoin Law (June 2023) creates separate requirements for stablecoin custody — issuance/mediation may require additional fund transfer service provider registration
- 6-18 month licensing timeline creates operational delay risk for market entry
- Tax treatment uncertainty — National Tax Agency (NTA) has its own enforcement priorities for crypto
Evidence
This verdict synthesizes the following facts. Each fact links to its primary source(s).
FSA/JFSA — CAESP registration, exchange oversight, stablecoin regulation, policy development
JVCEA — Mandatory self-regulatory organization — token listing standards (green/white list), operational rules, member monitoring
Payment Services Act (amended 2017, 2020) (2017) — CAESP registration, crypto-asset definition, customer asset segregation
VASP: CAESP registration with FSA. JPY 10M (~$70K USD) minimum capital. Must maintain positive net assets. 100% cold storage recommended for customer assets. JVCEA membership mandatory. 6-18 month application timeline. Token listings pre-screened by JVCEA.
CUSTODY: Included under CAESP registration. Mandatory segregation of customer assets (trust account or equivalent). Multi-signature wallets, penetration testing, internal audits required.
Licensing Requirement: Mandates that all entities operating "Crypto-Asset Exchange Services" (which include buying/selling, exchanging, intermediating, managing, or transferring crypto-assets for others) must register with and obtain a license from the FSA.
Segregation of Customer Assets: VCEPs must segregate customer crypto-assets from their own assets. Cold wallets are preferred for a significant portion of customer holdings.
Robust Security Measures: Strict requirements for cybersecurity, including multi-signature wallets, penetration testing, and internal audits.
Anti-Money Laundering (AML) & Counter-Terrorist Financing (CFT): Comprehensive Know Your Customer (KYC) procedures, transaction monitoring, and suspicious activity reporting (SAR) obligations. These align with FATF recommendations.
Core Requirements for Licensed Exchanges (VCEPs):
Regulator: Financial Services Agency (FSA).
Regulator: National Tax Agency (NTA).
Verdict Attribution
- Source:
- AI-Generated · Unreviewed
- AI synthesized:
- 2026-07-13 (deepseek-chat)
- Last updated:
- 2026-07-13
- Confidence:
- high
This verdict was produced by an AI model from the underlying facts. Confirm with counsel before relying on it for material decisions.
Conditional — Custodial wallet / SaaS providers are permitted in Japan but must register as a Crypto-Asset Exchange Service Provider (CAESP) with the FSA, join JVCEA, meet mandatory asset segregation and security requirements, and comply with comprehensive AML/CFT obligations; the 6-18 month licensing timeline and high regulatory burden apply.
Questions this verdict aims to answer
- What custody license / qualified-custodian status applies?
- What segregation, insurance, and proof-of-reserves rules apply?
- What AML obligations attach to the SaaS vs the white-label client?