EST · MMXXVI
Home/Jurisdictions/Japan/Crypto exchange setup in Japan (FSA/JVCEA)
Licensing & Registration

Crypto exchange setup in Japan (FSA/JVCEA)

Crypto exchange setup in Japan (FSA/JVCEA). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Any business planning a crypto exchange setup in Japan faces one of the world's most demanding licensing regimes. Japan's Financial Services Agency (FSA) operates a mandatory registration system for crypto asset exchange service providers (CAESPs) – the domestic term for virtual asset service providers – and the JVCEA (Japan Virtual and Crypto assets Exchange Association) acts as the FSA-designated self-regulatory body whose membership and rulebook compliance are effectively prerequisites for market access. Operating without registration exposes the business to criminal liability, immediate injunctions and forced exit from the Japanese market. This page sets out the regulated basis, the inbound application path, the self-regulatory layer, the cross-border considerations and the decision framework an inbound operator needs before committing capital.

Who needs FSA registration to run a crypto exchange in Japan?

Any entity that solicits Japanese users to buy, sell or exchange crypto assets as a business must register with the FSA as a CAESP under the applicable provisions of the Payment Services Act. The obligation follows the user, not the incorporator. A Cayman-incorporated exchange with a Japanese-language website, a yen payment rail and Japanese residents on the user base is within scope. The FSA's enforcement posture toward offshore operators marketing into Japan without registration is well-documented and has resulted in published warnings and, in the most serious cases, formal cease-and-desist proceedings. There is no de-minimis user-count carve-out. The registration requirement is binary.

Two subsidiary questions arise quickly. First, whether the platform also handles security tokens – tokens that constitute securities under the Financial Instruments and Exchange Act (FIEA) – in which case an additional Type I or Type II Financial Instruments Business registration is required alongside the CAESP registration. Second, whether the platform offers margin or derivatives trading in crypto assets, which triggers a separate FIEA authorisation. In our practice, inbound operators frequently underestimate the FIEA exposure when structuring their product set for Japan. The FSA applies the substance-over-label principle: the name the operator gives its product is immaterial; what counts is the right it confers on the holder.

The FSA's registration requirement under the Payment Services Act applies to any entity soliciting Japanese users, regardless of the entity's country of incorporation. The JVCEA self-regulatory layer sits above the statutory floor and adds conduct, listing and margin-trading standards with which registered exchanges must comply.

To discuss whether your product triggers FSA registration, contact OBOLUS at info@oboluslaw.com. The analysis turns on your product structure, your user-acquisition channels and your settlement rails – not just your corporate domicile. Map your options

What does the FSA registration process actually involve?

FSA registration for a CAESP is a multi-stage process with a material documentation burden and no fast-track for well-capitalised foreign applicants. The process below reflects the standard inbound path; your facts will affect sequencing and timeline at several points.

The first stage is entity establishment. The FSA requires the applicant to be a Japanese incorporated entity – either a kabushiki kaisha (joint-stock company) or a godo kaisha (limited liability company). A branch of a foreign entity is not sufficient for CAESP registration. Foreign operators must incorporate in Japan, which typically requires a resident director or representative director with a registered address in Japan. This alone can add several weeks to the pre-application runway.

The second stage is the pre-consultation (jizen soudan) with the FSA or the relevant Local Finance Bureau. In practice, the FSA expects applicants to engage informally before submitting the formal application. The pre-consultation surfaces documentation gaps and structural concerns before the clock formally starts on the application review. Skipping this stage is the single most common mistake inbound operators make – the FSA uses it to assess the operator's seriousness and operational readiness, and a poorly prepared pre-consultation can prejudice the formal application that follows.

The third stage is the formal application filing. The application package is extensive. Core elements include: a business plan with detailed operational descriptions; a system security audit report prepared by an FSA-recognised third-party auditor; an AML/CFT manual and customer due-diligence procedures aligned to the FATF Recommendations and the applicable Japanese AML regime; cold-wallet custody management documentation (the FSA requires that a significant proportion of customer crypto assets be held in cold wallets); internal governance and compliance frameworks; key-person background documentation for directors and major shareholders; and financial projections and capital adequacy evidence. The FSA's review focuses heavily on system security, cold-wallet management and AML/CFT controls – these are the areas that most frequently generate supplemental questions and delays.

The fourth stage is FSA review and supplemental questioning. The FSA review period is not fixed by statute; from formal filing to registration, the process generally extends across several months and can run considerably longer for complex business models or where the applicant's responses to supplemental questions are slow or incomplete. Operators who have gone through this process in other demanding regimes – MAS in Singapore, the SFC in Hong Kong – consistently report that the FSA process is more document-intensive, not less.

What is the JVCEA and why does it matter for market access?

The JVCEA is the FSA-designated self-regulatory organisation for the crypto exchange industry in Japan, and JVCEA membership is effectively a condition of operating a registered exchange. It is not optional. The JVCEA issues and enforces detailed rules on token listing standards, margin-trading limits, AML procedures, system security requirements, handling of customer assets and advertising standards. A registered CAESP that is not in good standing with the JVCEA is exposed to regulatory sanction.

The JVCEA's listing standards matter in a practical sense for any operator planning to support a broad token set. The JVCEA maintains a whitelist of tokens approved for trading on registered exchanges. A token not on the whitelist requires the exchange to go through a separate JVCEA review process before it can be listed. For an operator building a product set around mid- or long-tail tokens, the listing review timeline adds a material lead time that must be built into the product roadmap. We regularly advise clients at the product-design stage to map their intended listing set against the JVCEA whitelist before committing to a Japan launch – the gap between the intended and the approvable set is often larger than founders expect.

JVCEA membership dues and compliance costs are a real operational overhead. The JVCEA conducts periodic on-site inspections of member exchanges. A registered exchange that repeatedly fails JVCEA inspection standards risks referral to the FSA, which can suspend or revoke the CAESP registration. The JVCEA rulebook is the operational compliance standard for any registered Japanese crypto exchange, and it is updated regularly in response to FSA guidance and market incidents.

What are the AML and Travel Rule requirements for Japanese exchanges?

Japan was an early adopter of the Travel Rule – the obligation under FATF Recommendation 15 to pass originator and beneficiary identifying information alongside virtual asset transfers. Japanese registered exchanges are required to comply with the Travel Rule as implemented under Japanese law, including for transfers to and from other VASPs. The JVCEA has published technical standards for Travel Rule implementation that registered exchanges must meet. In our cross-border practice, the Travel Rule is a persistent operational challenge for operators whose counterparty exchanges are in jurisdictions with different or delayed implementation standards – the practical result is that transfers between a Japanese-registered exchange and an exchange in a non-Travel-Rule-compliant jurisdiction can be operationally constrained or declined.

The broader AML/CFT framework for registered CAESPs requires robust customer due diligence, enhanced due diligence for higher-risk customers, ongoing transaction monitoring and suspicious transaction reporting obligations to the Japanese financial intelligence unit. The FSA conducts supervisory inspections focused on AML/CFT compliance, and enforcement actions against registered exchanges for AML failures have resulted in business improvement orders, partial suspensions and, in the most serious cases, registration revocations. The FSA's published inspection criteria are detailed; preparing for and passing an FSA inspection is a material compliance project for any new registrant.

How do cross-border tax and banking interact with a Japanese exchange licence?

A Japanese incorporated exchange is subject to Japanese corporate tax on its worldwide income. Japan's tax treatment of crypto assets held as business inventory, as proprietary trading positions and as custodied client assets involves detailed rules that can produce material tax costs if the structure is not designed correctly from the outset. We have seen operators establish a Japanese entity for the licence, run trading operations through it, and then discover that their consolidated group structure creates unexpected Japanese tax exposure for income earned outside Japan. Getting the cross-border tax structure right before incorporation – not after – is the correct sequence.

Banking access for a Japanese-registered crypto exchange is a real operational constraint. Japanese banks are not uniformly willing to provide operating accounts to crypto exchanges, even registered ones. A small number of banks with established crypto-sector banking relationships are the primary counterparties, and competition for those relationships is material. Operators who approach Japanese banking without a prepared compliance presentation, a credible AML framework and a clear description of their customer base and transaction flows face extended delays or outright rejection. In our practice, banking preparation begins in parallel with the FSA pre-consultation, not after registration is obtained.

There is also a cross-border user-base question. A Japanese-registered CAESP may serve Japanese users. If it also proposes to serve users in the EU, it may trigger MiCA CASP authorisation requirements. If it serves Singapore users, MAS Payment Services Act licensing applies. If it serves UK users, FCA cryptoasset registration and financial promotion rules engage. The Japanese licence does not passport to any other jurisdiction. Operators building a multi-market strategy from a Japanese base need a licence-stack map that addresses each user-base jurisdiction independently.

If your structure sits between Japan and one or more other markets, the licensing and tax questions interact in ways that a single-jurisdiction analysis will miss. Write to info@oboluslaw.com to map the full stack before you commit. Map your options

A recent matter: inbound operator with a mixed token set

In a recent matter, a digital-asset trading platform incorporated in a leading offshore jurisdiction sought to register in Japan and extend its token set to include several assets that were not on the JVCEA whitelist. We advised on the Japan entity structure, the FSA pre-consultation strategy and the sequencing of the JVCEA listing applications alongside the registration process. The engagement surfaced a FIEA exposure for two of the operator's proposed products that had not been identified in an earlier self-assessment. The product set was restructured before the formal FSA application was filed, removing the delay and cost of a mid-review product redesign. The matter closed in the second half of the most recent calendar year.

Which operator profile should pursue a Japanese licence?

Not every exchange operator should build toward a Japanese registration. The process is demanding and the ongoing compliance cost is material. The decision turns on the operator's market thesis, its capitalisation, its product set and its timeline.

Profile A – Established exchange, Japanese market as a priority. An operator with an existing registered customer base, a credible compliance team and a product set alignable to the JVCEA whitelist should pursue FSA registration directly. The regulatory burden is high but the market access is real and the FSA registration is a meaningful competitive signal. The timeline from a well-prepared start to registration is typically measured in months, not weeks. Allied counsel in Japan is essential at the pre-consultation stage.

Profile B – Early-stage platform, Japan as a long-term target. An operator in the build phase with an uncertain product set, limited compliance infrastructure and no Japanese market revenue should not commence the FSA process until the product is stable. The pre-consultation is not a discovery exercise for an unprepared applicant; it will produce a list of deficiencies that sets the timeline back. A better sequence is to establish the product, build the compliance infrastructure and engage allied counsel in Japan to conduct a pre-application readiness assessment before approaching the FSA.

Profile C – Multi-market operator using Japan as part of a regional licence stack. Some operators license in Singapore under MAS and in Hong Kong under the SFC for the broader Asia-Pacific market and treat Japan as a subsequent phase. This is a rational sequencing for operators whose primary user base is outside Japan. The MAS and SFC processes, while demanding, are better documented for inbound foreign applicants and the JVCEA-equivalent self-regulatory burden is lower. Building toward Japan from an established Asia-Pacific licence is a credible path; attempting Japan first without a regional compliance team in place is the harder route.

What mistakes do inbound operators most often make when seeking a Japanese crypto licence?

The most common mistake is treating the JVCEA as an administrative step rather than a substantive compliance obligation. Operators who obtain FSA registration and then discover that their token set, their margin-trading product or their AML procedures do not meet JVCEA standards face a material remediation exercise under regulatory scrutiny. The JVCEA engagement should run in parallel with the FSA process, not after it.

The second most common mistake is the branch-of-a-foreign-entity error. Operators accustomed to the ADGM or Cayman structures, where a branch of a foreign entity can in some cases hold a licence, do not always read the Japanese requirement for a locally incorporated entity. Discovering this after a corporate structure has been established and banking arranged elsewhere adds cost and delay.

A common assumption in this space is that a single offshore licence – BVI, Cayman, or a Seychelles registration – is sufficient to operate globally, including in Japan. It is not. The FSA's position is clear: entities serving Japanese users require Japanese registration. There is no offshore-licence passporting arrangement that covers Japan. Operators relying on an offshore entity to cover their Japanese user base are exposed to enforcement at the moment the FSA identifies the Japanese user activity, which it does through monitoring of Japanese-language marketing, app-store listings and payment flows.

The third mistake is inadequate system security documentation. The FSA requires a security audit from a recognised third-party auditor, and the scope of that audit is broader than operators used to ISO 27001 certification typically expect. Cold-wallet management documentation, key-management procedures and incident-response plans all form part of the FSA's security review. Engaging the security auditor late in the process is a consistent source of delay.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

In Japan, the FSA registration timeline depends heavily on the completeness of the application and the complexity of the business model. From the first pre-consultation to registration, operators should plan for a process measured in several months at minimum; complex models or incomplete initial submissions extend that materially. The JVCEA membership process runs in parallel. Timelines in other major jurisdictions – MAS in Singapore, the SFC in Hong Kong, ESMA-aligned CASP authorisation under MiCA – vary by regime, application quality and the regulator's current processing load. Qualitative planning ranges are available in a scoped assessment.

Which jurisdiction is best for licensing my crypto business?

There is no universally best jurisdiction. The right licence, or licence stack, depends on where your users are, what products you offer, what your banking requirements are and what your capital and compliance capacity allows. Japan offers credible market access to one of the world's largest retail crypto markets but carries a high compliance burden. Singapore and Hong Kong are often better entry points for operators building a regional Asia-Pacific presence. EU operators licensing under MiCA gain passporting across member states. Mapping the user-base, product and capital variables against the available regimes is the starting point for any licensing decision.

Do I need a separate custody licence?

In Japan, the custody of customer crypto assets is regulated as part of the CAESP registration; there is no separate custody-only track. However, if the custodied assets include security tokens under the FIEA, a separate financial instruments business registration applies. In other jurisdictions – ADGM, VARA, MAS, MiCA – custody is treated as a separate regulated activity with its own authorisation requirements, capital thresholds and safeguarding rules. Operators who custody for third parties across multiple jurisdictions typically need to map custody authorisation requirements jurisdiction by jurisdiction as a distinct exercise from the exchange licence analysis.

About OBOLUS

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than seventy jurisdictions, on disputes and on-chain asset recovery across more than twenty-five forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence, custody and payment-service stack across operating layers before our clients commit capital – so structural problems surface before an application is filed, not after. To discuss your Japan licence strategy or your cross-border structure, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in inbound market-access strategy for digital-asset exchanges and custodians across the Asia-Pacific and Gulf licensing regimes.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours