EST · MMXXVI
Home/Jurisdictions/Japan/VASP licence application in Japan (FSA/JVCEA)
Licensing & Registration

VASP licence application in Japan (FSA/JVCEA)

Vasp licence application in Japan (FSA/JVCEA). Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Japan is one of the most demanding — and most commercially credible — crypto licensing regimes in the world. The Financial Services Agency (FSA) and its self-regulatory counterpart, the Japan Virtual Currency Exchange Association (JVCEA), together run a dual-layer oversight system that has, since the industry's earliest exchange collapses, set the global standard for consumer protection in digital-asset markets. For an inbound operator, that credibility comes at a price: a preparation-intensive application, a multi-month review cycle, and an ongoing compliance architecture that rivals a bank's. Operating without registration — or misjudging which activities trigger the obligation — exposes the business to enforcement action, frozen correspondent-banking rails and reputational damage in one of the world's deepest crypto markets.

Japan's VASP licence is formally a Crypto Asset Exchange Service Provider (CAESP) registration under the Payment Services Act, supervised by the FSA with JVCEA serving as a designated self-regulatory organisation. Every business soliciting Japanese users for exchange, transfer, custody or brokerage of crypto assets must hold — or operate under — that registration before it touches a yen of revenue. The analysis below walks through the regulatory basis, the inbound application process, the cross-border structuring questions, the common failure points, and the decision factors that determine whether Japan should anchor your licence stack or complement it.

The Regulatory Basis: FSA, JVCEA and the Payment Services Act

Japan's crypto licensing obligation flows from the Payment Services Act, which defines crypto asset exchange services broadly enough to capture spot exchange, custody, transfer and the management of users' crypto assets on their behalf. The FSA administers registrations and sets the prudential standards; the JVCEA operates as the industry's self-regulatory body, setting detailed rules on security standards, listing procedures and operational protocols that registered members must observe. Membership in the JVCEA is, in practice, a prerequisite: the FSA refers applicants to JVCEA membership assessment as part of its own review, and approval from neither body is possible in isolation.

The Payment Services Act draws a clear perimeter. Soliciting Japanese residents — even from an entity incorporated abroad — triggers the registration obligation. Jurisdiction is determined by user location, not by where the operator sits. An exchange incorporated in Singapore or Malta that markets to Japanese retail clients is operating an unlicensed crypto asset exchange service under Japanese law. The FSA has acted against offshore operators on precisely this basis, and Japanese banks will not maintain correspondent relationships with entities they believe serve Japanese users without FSA registration.

Two additional layers sit above the exchange regime. Where a crypto asset has characteristics of a security — economic participation rights, profit-sharing features — the Financial Instruments and Exchange Act engages, requiring a separate registration as a financial instruments business operator. The line between a utility token and a security token in Japan is drawn by the FSA on a substance-over-label basis, consistent with the principle applied across most major regimes. In our practice, the most common early structuring error is assuming that a token labelled "utility" avoids financial-instruments analysis. It does not.

Who Must Register: The Regulated Perimeter in Practice

Any person or entity conducting crypto asset exchange services on a commercial basis for Japanese users must register with the FSA as a Crypto Asset Exchange Service Provider. The obligation covers four core activities: exchanging crypto assets for fiat or other crypto assets, acting as intermediary for such exchanges, managing or transferring crypto assets on behalf of users, and issuing instruments whose value is denominated in crypto assets.

The registration obligation attaches regardless of business model. Centralised exchange operators, custodians offering segregated wallets, OTC desks, and transfer service providers that move crypto assets on user instruction all fall within the perimeter. The JVCEA's member rules additionally govern token listing decisions, requiring exchanges to conduct a structured listing review before admitting a new asset to trading — a process that can itself add months to a product-launch timeline if not planned in parallel with the licensing application.

Decentralised-protocol operators occupy a grayer zone. Where the protocol involves smart-contract-mediated exchanges with no intermediary holding user funds, the FSA's position has been cautious but not absolute: it has signalled that genuine non-custodial, fully decentralised operations may fall outside the perimeter, but it examines the operational reality rather than the technical description. In our cross-border practice, operators of DeFi-adjacent products regularly underestimate this scrutiny. If the protocol involves any admin-key control over funds, any fee-collection mechanism pointing to a legal entity, or any marketing directed at identifiable Japanese users, the registration question is live.

How Does the Inbound Application Process Work?

The FSA registration process for an inbound operator — one without an existing Japanese legal presence — begins with incorporation of a Japanese entity, typically a kabushiki kaisha (joint-stock company) or godo kaisha (limited liability company), because the FSA does not register foreign entities directly. This is a non-negotiable structural threshold, and it is where many operators first miscalculate their timeline. Japanese company formation, bank account opening for the operating entity, and the engagement of a local compliance officer and representative director all run in parallel with documentation preparation — and bank account opening for a crypto company in Japan can, on its own, take several months.

The registration dossier is extensive. It encompasses corporate constitutional documents, a detailed business plan, an internal-control description, AML/CFT policies aligned with the JVCEA's standards, a cybersecurity framework (the FSA publishes specific security guidance for crypto exchanges), a system-audit report from an approved auditor, and descriptions of how the entity will segregate customer assets from its own. The FSA's review is thorough; it typically involves multiple rounds of supplementary questions before a registration is granted. The JVCEA membership assessment runs on a parallel track and its questionnaire is independently detailed.

From initial submission to registration, the process generally takes many months — an exact timeline depends on the complexity of the business model, the responsiveness of the applicant to supplementary queries and the current queue at the FSA. In our experience, operators who approach the FSA without a complete and internally consistent dossier extend their review cycle significantly. First-time applicants who have not previously interfaced with the JVCEA's security audit expectations often require a full revision of their cybersecurity documentation before the application can progress.

CTA #1: The process above describes the standard registration path. Your specific facts — the entity structure, the token offering, the user base's geography and the banking arrangements — change the analysis materially. For a scoped assessment of your Japan licensing position, contact OBOLUS at info@oboluslaw.com or map your options here.

AML, the Travel Rule and JVCEA Compliance Obligations

Japan adopted the Travel Rule — the obligation, drawn from FATF Recommendation 15, to pass originator and beneficiary information alongside a crypto asset transfer — and the JVCEA has implemented specific technical standards for how member exchanges must exchange that data. Compliance requires integration with a Travel Rule protocol capable of communicating with counterparty exchanges both domestically and cross-border. This is a live operational requirement, not a documentation exercise: exchanges that cannot demonstrate working Travel Rule infrastructure at the time of application will not receive registration.

The AML/CFT framework in Japan requires registered entities to maintain risk-based customer due diligence, enhanced due diligence for high-risk relationships, transaction monitoring calibrated to the FSA's supervisory expectations, and a reporting structure for suspicious transactions to the Japan Financial Intelligence Center (JAFIC). The JVCEA's member rules go further, setting standards on wallet screening, on-chain monitoring and the handling of privacy coins. The FSA has shown a consistent willingness to issue administrative orders and business improvement orders — formal corrective-action instruments — to registered exchanges that fall short on AML controls; several high-profile orders have followed exchange security incidents and AML deficiencies over the past several years.

Cross-border operators face a specific challenge here. An entity that processes transfers from international exchanges must ensure that its Travel Rule system can receive data from, and send data to, counterparts operating under different Travel Rule protocols — including those in the EU under MiCA, in Singapore under the Payment Services Act regime, and in the UAE under VARA's AML rulebooks. The interoperability question is legal as much as technical: the JVCEA's standards set the floor, but the data must be lawfully transmissible under the data-protection regimes of the sending and receiving jurisdictions.

Cross-Border Interaction: Tax, Banking and Structural Reality

For a business that operates in Japan as one node of a global crypto-asset enterprise, the structural relationship between the Japanese entity and the wider group raises several interconnected issues. Japan taxes corporate income at rates that, combined with local levies, produce an effective rate that is material for a trading-intensive business. Transfer-pricing rules apply to intra-group arrangements — including arrangements for technology licensing, liquidity provision and back-office services between the Japanese subsidiary and an offshore parent — and the FSA scrutinises related-party arrangements for regulatory-arbitrage risk.

Banking remains the most acute operational constraint for inbound operators. Japanese banks are conservative when onboarding crypto entities; they will typically require evidence of FSA registration (or at minimum a credible advanced application), a Japanese-resident director of substance, and a business plan that demonstrates the entity is genuinely operating in Japan rather than using a local shell to hold a licence for offshore operations. In our cross-border practice, we have seen groups attempt to open banking before the FSA application is filed — that sequencing rarely succeeds. The reverse — filing the application, demonstrating seriousness to the bank, and then progressing both tracks together — has a materially higher success rate.

The interaction between the Japanese licence and other jurisdictions also matters commercially. A Japan-licensed exchange that wants to serve EU residents will need to consider whether its activities in EU member states trigger a CASP authorisation requirement under MiCA. Serving Singapore residents adds MAS's Digital Payment Token service licensing to the stack. The JVCEA licence does not passport. Each jurisdiction is a separate analysis, and the group structure — which entity holds which licence, how risk and capital are allocated across entities, and how user data flows across borders — must be planned before incorporation, not after.

A practical cross-border note: custody of crypto assets in Japan by a registered exchange is regulated; the FSA requires asset segregation and prohibits the commingling of customer and firm assets. If the group runs custody as a separate business line — managing assets for institutional clients, family offices or funds — a separate registration analysis applies, and the business model must be mapped to the correct CAESP activity category before the application is filed.

What Are the Most Common Failure Points in Japan Licence Applications?

The most frequent reason an FSA application stalls is an incomplete or inconsistent security framework. Japan's exchange-security expectations are among the most detailed of any major regime — the FSA and JVCEA publish guidance on cold-wallet ratios, multi-signature key management, penetration-testing cadence and incident-response protocols. An applicant that presents a generic cybersecurity policy adapted from another jurisdiction's submission will typically receive a comprehensive list of supplementary questions that effectively restarts the review. The cybersecurity documentation must be Japan-specific, technically detailed and demonstrably implemented, not aspirational.

The second common failure is the wrong corporate structure. The FSA requires that the registered entity be managed by individuals of demonstrable competence and good standing; the representative director and compliance officer must typically be Japan-resident and must satisfy the FSA's fit-and-proper assessment. Groups that appoint a nominee director without substance — or whose compliance officer is dual-hatted across multiple group entities with insufficient time to devote to the Japanese operation — routinely draw FSA scrutiny. The FSA has refused registrations on governance grounds, and it has revoked registrations from exchanges that allowed their management substance to deteriorate post-registration.

Third: token listing. Applicants that propose to list a wide universe of tokens from day one face a longer and more complicated review. The JVCEA's listing assessment process is separate from the registration and can add materially to the timeline. Starting with a curated, defensible token list — ideally tokens already listed on other JVCEA member exchanges — is a pragmatic approach that we regularly recommend to operators focused on getting to market.

The fourth failure point is AML documentation that does not reflect the actual operational workflow. The JVCEA's AML questionnaire is granular; it maps to specific transaction flows, counterparty types and risk scenarios. A policy that describes the ideal state without evidence of tested implementation will not satisfy the review. The FSA has the authority to conduct on-site inspections before and after registration, and it uses that authority.

A Pattern from Practice

In a recent licensing matter, a digital-asset exchange that had operated successfully under an EU CASP authorisation sought to enter the Japanese market by establishing a local subsidiary. The group's initial assumption was that its European compliance infrastructure — AML policies, Travel Rule integration, cybersecurity framework — could be adapted with minimal modification. After an initial FSA pre-consultation, it became clear that the security framework did not meet the JVCEA's cold-storage ratio expectations and that the Travel Rule implementation used a protocol not then interoperable with the major Japanese exchange counterparts. We restructured the project timeline, coordinated the cybersecurity audit with a Japan-approved auditor, and rebuilt the Travel Rule interoperability layer before refiling. The application progressed without material supplementary queries in the second round. The lesson — that a well-developed compliance architecture in one jurisdiction is a foundation, not a substitute, for Japan-specific work — is one we articulate to every group at the outset of a Japan engagement.

Which Operator Profile Should Prioritise the Japan Registration?

Not every operator with Japan ambitions should lead with a full FSA registration. The decision depends on commercial scale, timeline tolerance and structural readiness.

An operator whose primary market is Japan — whose revenue model depends on serving Japanese retail or institutional clients directly — has no credible alternative: registration is required, and the question is only how to structure and sequence the application most effectively. For this profile, the pre-application period should be used to establish the Japanese entity, engage a Japan-resident director and compliance officer, open banking (in parallel), and develop the security and AML framework to JVCEA standards before the formal submission.

An operator that sees Japan as a secondary or future market — one that currently serves other Asian markets and intends to expand — should plan the Japanese corporate and compliance architecture in parallel with its current licensing work, so that the Japan application is ready to file when the commercial commitment is made. Late-stage Japan applications filed under commercial pressure, without adequate preparation, are the ones that stall most severely.

A third profile — the operator whose token-issuance or DeFi activity has incidental Japanese user exposure — should conduct a perimeter analysis before concluding that registration is not required. The FSA's approach to offshore operators with Japanese users is not passive. Geo-blocking that is demonstrably implemented and enforced, combined with terms of service that exclude Japanese users, can be a defensible position; geo-blocking that exists on paper but is not operationally enforced is not. We map this distinction carefully with every client that raises the question.

CTA #2: If a prior application stalled, or if your Japan analysis is at an impasse on banking, governance or security documentation, a second read can identify the structural issue and the route forward. Write to OBOLUS at info@oboluslaw.com or map your options here.

A Common Assumption: One Offshore Licence Is Enough

A persistent assumption among operators planning a multi-market rollout is that a single well-respected offshore registration — in the BVI, Cayman Islands, or a mid-tier EU jurisdiction — provides a sufficient basis to serve clients globally, including in Japan. It does not. Japan's regime is explicit: the payment Services Act reaches any entity providing crypto asset exchange services to Japanese residents, regardless of where the entity is incorporated or where its servers sit. The FSA does not recognise equivalence with foreign regimes. An entity operating in Japan on the basis of an offshore licence is, under Japanese law, operating without registration.

The broader point is structural. The jurisdictions that matter most commercially — Japan, Singapore, Hong Kong, the EU under MiCA — each run independent licensing regimes with no mutual-recognition arrangement for crypto asset service providers. A serious cross-border operation requires a licence stack: the right entities, in the right jurisdictions, with the right activities registered, banked and capitalised in each. OBOLUS maps that stack as a first step before any application is filed.

Related at OBOLUS

FAQ

How long does a crypto licence take to obtain?

In Japan, the FSA registration process is among the more time-intensive of the major licensing regimes. From initial corporate establishment through to registration, the process generally takes many months — the exact duration depends on the completeness of the application dossier, the complexity of the business model, and the pace of supplementary-question cycles with the FSA and JVCEA. Operators that submit a fully prepared application, with security, AML and governance documentation built to Japanese standards before filing, consistently achieve shorter review periods than those who file speculatively and revise under query.

Which jurisdiction is best for licensing my crypto business?

There is no universal answer. The right jurisdiction depends on your target user base, your business model, your capital position, your banking relationships and your timeline. Japan suits operators whose commercial focus is the Japanese market; it offers high credibility but requires a fully localised structure. Singapore, Hong Kong, the EU under MiCA and the UAE under VARA each serve different operator profiles. A cross-border business typically needs a stack of licences across multiple regimes, not a single answer. OBOLUS maps the stack before advising on which jurisdiction to lead with.

Do I need a separate custody licence?

In Japan, custody of crypto assets for users is a regulated activity under the Payment Services Act and falls within the Crypto Asset Exchange Service Provider registration. If your business model separates custody from exchange — for example, providing institutional custody as a standalone service — the registration analysis must reflect that activity specifically. In other major regimes, custody may require a separate authorisation, particularly where the regulatory regime treats custody as a distinct regulated activity with its own capital and safeguarding requirements. The answer is jurisdiction-specific and model-specific; we assess both dimensions as part of any licence-stack engagement.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across more than seventy jurisdictions, on disputes and on-chain asset recovery across more than twenty-five forums, and on the tax, banking and compliance structures that sit around them. Digital assets are the whole of our practice. We map the licence, banking and compliance stack across operating, custody and payment layers before you commit — and we have done so for crypto exchanges, custodians, token issuers and funds operating in some of the world's most demanding regulatory environments. To discuss your Japan licensing situation or your broader structure, contact info@oboluslaw.com or message us at t.me/oboluslaw.

By Aisha Tan, Licensing & Jurisdictions Analyst — specialising in inbound VASP registration and licence-stack structuring across Asia-Pacific and the major international hubs.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours