Operating a crypto exchange or digital-asset service in Japan without a registered VASP (virtual asset service provider) licence under the FSA (Financial Services Agency) regime exposes the business to enforcement action, compulsory suspension and the near-certain loss of banking relationships. Japan was the first major economy to create a statutory VASP registration framework, and its regulator treats unlicensed operation with singular seriousness. This page sets out the legal basis, the application process for an inbound business, and the cross-border realities that shape how the Japanese regime interacts with a multi-jurisdictional operating structure.
What activities require a VASP registration in Japan?
Any business that exchanges, transfers or manages crypto-assets (the statutory term under the applicable Payment Services Act provisions) on behalf of customers, or that operates a platform enabling such activity, must register as a Crypto-Asset Exchange Service Provider (CAESP) with the FSA. The obligation turns on the nature of the activity, not the corporate domicile of the operator. A foreign entity serving Japanese residents through a Japanese-language platform, accepting Japanese payment rails or actively marketing to users in Japan will generally fall inside the perimeter regardless of where it is incorporated.
The FSA applies a substance-over-structure analysis when assessing whether a foreign operator is effectively carrying on a regulated activity in Japan. In our practice, we see businesses assume that an offshore entity with no Japanese office sits outside the perimeter. That assumption has been wrong often enough to treat it as a default risk. The regulator's guidance on cross-border applicability has tightened progressively, and enforcement against unlicensed foreign operators has followed.
Brokerage, spot exchange, custody and transfer services all fall within the regulated category. Derivative products linked to crypto-assets attract an additional layer of oversight under the applicable financial instruments provisions, and the distinction between spot and derivative activity is a structural decision point for any inbound operator. The JVCEA (Japan Virtual and Crypto assets Exchange Association) functions as a self-regulatory organization; FSA-registered operators are expected to join and comply with its rules.
To discuss how the perimeter applies to your specific activity mix, contact OBOLUS at info@oboluslaw.com. The process above describes the standard analytical path. Your entity structure, the products you offer, and the channels you use to reach Japanese users each change the analysis materially.
How does the FSA/JVCEA dual-layer regime work?
Japan's VASP regime operates on two tracks: statutory registration with the FSA and self-regulatory membership with the JVCEA. The FSA issues the registration and retains supervisory authority. The JVCEA sets operational standards for its members – covering listing processes, custody arrangements, marketing rules and system security – that sit above the statutory minimum. In practice, JVCEA membership is not formally optional for licensed operators; the FSA expects registered firms to belong, and the JVCEA's rules are treated as a practical extension of the regulatory floor.
The structure matters for an inbound business for two reasons. First, the JVCEA listing review is one of the more operationally intensive parts of the process. Each crypto-asset the operator intends to list must clear a JVCEA review that examines the project's technical design, the token economics and the associated legal risks. New listings require advance JVCEA clearance, and the review timeline varies by asset. Businesses that intend to list a broad range of assets need to factor that queue into their commercial planning. Second, JVCEA membership fees and governance obligations are ongoing; they are not a one-time registration cost.
The FSA's supervisory approach is explicitly risk-proportionate. Operators handling large volumes, operating custody functions or offering leverage are subject to more intensive examination. The regulator conducts on-site inspections and off-site returns; it has issued improvement orders to registered firms and has revoked registrations where systemic failures were identified. Japan's enforcement record is substantive, not decorative.
What is the VASP registration process for an inbound business?
Registering with the FSA requires a Japanese legal presence: a domestic branch or a wholly owned subsidiary incorporated under Japanese law. The corporate establishment step must be completed before the registration application is lodged. For most inbound groups, the preferred vehicle is a kabushiki kaisha (joint-stock company), though a godo kaisha is also used for certain structures. Either way, the local entity must be adequately capitalized and staffed before the FSA will accept the application as complete.
The application itself addresses several substantive requirements. The operator must demonstrate: a governance structure with clear accountability; a compliance framework covering AML/CFT obligations under the applicable anti-money laundering provisions; segregated custody of client assets from proprietary assets; an IT security management framework that meets FSA expectations; a business continuity plan; and an internal audit function. The FSA expects the compliance and IT security functions to be staffed in Japan, not managed remotely from a foreign parent.
Timeline is a frequent source of surprise. The FSA does not operate to a fixed statutory clock in the same way as some European regulators. In our experience advising inbound operators, the period from submission of a complete application to registration decision is typically measured in several months to over a year, depending on the complexity of the business model, the quality of the initial submission and the volume of FSA requests for additional information. Businesses that submit underprepared applications encounter iterative information requests that extend the timeline significantly.
A structured pre-application engagement – reviewing the draft application with the FSA before formal submission – is standard practice and materially reduces rework. We advise clients to treat the pre-application stage as the substantive review. Entering it without prepared documentation and a coherent compliance narrative is the most common avoidable mistake.
Minimum net assets requirements apply by licence category, and capital adequacy is assessed on an ongoing basis. The specific thresholds vary by activity and are confirmed by the FSA at the point of application; they should not be assumed from publicly available historical figures without verification against current FSA guidance.
What are the AML and Travel Rule obligations for registered operators?
Japan implemented the Travel Rule (the obligation to transmit originator and beneficiary identification data with crypto-asset transfers) ahead of many peer jurisdictions. Registered crypto-asset exchange service providers must comply with the applicable Travel Rule provisions under the regime governing funds transfer reporting, which align with the FATF Recommendation 15 standard on virtual assets. The threshold above which the Travel Rule applies is set by the relevant provisions; operators should confirm the current threshold with counsel rather than relying on thresholds applicable in other jurisdictions.
AML/CFT obligations for registered operators include customer due diligence, enhanced due diligence for higher-risk relationships, transaction monitoring, suspicious transaction reporting and record-keeping requirements. The FSA reviews AML programmes as part of both the registration process and ongoing supervision. Operators that demonstrate robust AML infrastructure at application stage create a materially better supervisory relationship than those who treat AML as a post-registration project.
For businesses operating across Japan and one or more other jurisdictions, the interaction between Japan's Travel Rule implementation and those of peer jurisdictions – particularly Singapore's MAS framework, the EU's MiCA-adjacent provisions and the UK FCA's regime – requires careful mapping. Different thresholds, different counterparty verification requirements and different data-handling rules mean that a single technical Travel Rule solution rarely satisfies all regimes simultaneously without customization. We map those interactions as part of every multi-jurisdiction compliance engagement.
How does Japanese VASP registration interact with a cross-border group structure?
For a group that operates or intends to operate across Japan and other major hubs, the Japanese registration is one node in a larger licence and compliance stack. The structural questions that arise most often in our practice are: which entity within the group holds the Japanese registration; how client assets are segregated from group assets in a way that satisfies both the FSA and foreign depositaries; how the Japanese entity transacts with affiliated entities in other jurisdictions; and how the tax treatment of intra-group flows is aligned with the operational reality of the business.
On tax, Japan applies withholding tax to certain payments made to foreign related parties, and transfer pricing rules apply to intra-group service arrangements between the Japanese entity and offshore affiliates. The Japanese entity's taxable income is affected by the arm's-length characterization of management fees, IP licensing fees and technology services provided by the group. These are not exotic structures: they are the standard arrangements of any multi-jurisdictional platform. But they require deliberate design before the Japanese entity is established, not retrospective rationalization after the FSA application is filed.
Banking is a distinct operational constraint. Japanese financial institutions have historically applied conservative due diligence to crypto-asset businesses. A registered operator with strong compliance documentation and a clear client asset segregation model is materially better placed to maintain stable banking relationships than an unregistered or thinly documented entity. The FSA registration itself is a necessary but not sufficient condition for banking access; the bank's own risk appetite and the operator's compliance narrative both matter.
For groups with a European presence, the MiCA CASP (Crypto-Asset Service Provider) authorisation regime and Japan's CAESP registration address overlapping but distinct perimeters. An operator cannot substitute one for the other. For groups with a Singapore presence, the MAS Payment Services Act licensing framework similarly runs in parallel. Allied counsel in the relevant jurisdiction can provide local law advice where the OBOLUS engagement spans multiple seats.
A recent cross-border registration engagement
In a recent licensing matter, a payments technology business headquartered outside Japan sought to offer crypto-asset transfer services to Japanese corporate clients. The operator had an existing MAS-licensed entity in Singapore and assumed the Singapore licence provided a foundation for the Japanese registration. We reviewed the regulatory perimeter under both regimes and identified that the Japanese activity – involving the transmission of crypto-assets on behalf of Japanese counterparties – required independent FSA registration, with no passporting or mutual recognition available from the Singapore licence. We structured the Japanese subsidiary, mapped the intra-group service arrangements for transfer pricing purposes, and prepared the FSA application with particular attention to the AML/CFT framework and IT security documentation. The application advanced to registration without a request for material supplementary information – an outcome that reflects the value of preparation at the pre-application stage rather than discovery of gaps during FSA review.
Which operator profiles should pursue Japanese VASP registration?
Japanese VASP registration makes strategic sense for a defined set of operator profiles. It does not make sense for every business that has a tangential connection to Japan.
The first profile is an operator whose primary market includes Japan: a platform that expects a material share of its revenue from Japanese users, that intends to integrate with Japanese payment rails, or that holds or transacts yen-denominated assets on behalf of clients. For this profile, the compliance and operational cost of registration is the cost of market access, and the alternative – operating without registration – is not viable.
The second profile is a group building a regulated multi-jurisdiction presence and for whom Japan is one of the top-tier licence targets alongside the EU CASP authorisation, a Singapore MAS licence and one of the Gulf hubs (VARA in Dubai or FSRA in Abu Dhabi). For this profile, Japan adds depth to a global compliance narrative and access to a market with significant institutional and retail depth. The timeline and cost need to be sequenced against the other applications in the programme.
The third profile is a custody or infrastructure provider that has Japanese institutional clients or counterparties. Where the relationship involves holding or transferring crypto-assets on behalf of a Japanese institution, the FSA perimeter analysis will likely apply, and registration may be required before the commercial relationship can be formalized.
A business that serves no Japanese users, holds no Japanese accounts and has no Japanese contractual counterparties does not, as a general matter, need to engage with the Japanese regime. The perimeter is activity-based. The question is not where the operator is incorporated but what it does and for whom.
What are the most common mistakes in the Japanese crypto licensing process?
The first and most consequential mistake is underestimating the documentation standard. The FSA's application review is genuinely substantive. Applicants that submit incomplete or high-level documentation – compliance frameworks described in outline, IT security policies that reference foreign group standards without Japan-specific implementation detail, governance charts without clear accountability lines – receive iterative information requests that extend the timeline by months. We have seen well-resourced operators add the better part of a year to their registration timeline because the initial submission was drafted to a European standard rather than to FSA expectations.
The second mistake is treating the JVCEA asset listing review as secondary to the FSA application. For operators whose commercial model depends on listing a specific set of assets from day one of operation, the JVCEA review timeline for each of those assets needs to be built into the project plan. An operator that is FSA-registered but cannot list its intended assets because the JVCEA review is incomplete is not commercially operational.
The third mistake is a common assumption in the broader crypto industry: that a single offshore licence – whether in BVI, Cayman, or any other offshore centre – is sufficient to serve Japanese clients without Japanese registration. It is not. The FSA applies its perimeter analysis based on the activity, and enforcement against unlicensed foreign operators has been documented. Operators that have historically relied on a geographic distance argument or a lack of active marketing argument should have those assumptions tested against current FSA guidance, not against the position as it stood several years ago.
To pressure-test your structure before you commit, message us via t.me/oboluslaw. If a prior application stalled or the FSA has raised substantive concerns, a second read of the application and the supporting documentation can identify the structural reason and the route back.
Related at OBOLUS
- Licensing & Registration for Digital-Asset Businesses – how we map the full licence stack across operating, custody and payment layers
- Switzerland vs. United Kingdom: Where to License a Crypto Business – a comparative analysis for operators choosing between two major non-EU hubs
- Reverse Solicitation: A Narrowing Defence for Offshore Operators – why the passive-marketing argument is becoming harder to sustain across major regimes
FAQ
How long does a crypto licence take to obtain?
In Japan, the FSA does not operate to a fixed statutory clock. From submission of a complete, well-prepared application, the period to registration is typically several months to over a year, depending on the complexity of the business model and the quality of the submission. Underprepared applications attract iterative information requests that extend timelines significantly. In other jurisdictions, timelines vary materially by regime and application category; they are best confirmed with counsel against current regulatory guidance.
Which jurisdiction is best for licensing my crypto business?
There is no universal answer. The right jurisdiction depends on the operator's target market, the activity mix, the group structure, the banking environment and the tax position. Japan is appropriate for operators serving Japanese users or building a top-tier global licence stack. For operators serving the EU, a MiCA CASP authorisation in a member state with passporting rights is the relevant instrument. For operators focused on the Gulf, VARA in Dubai or the FSRA in Abu Dhabi each present distinct profiles. We map these decision axes before any application is committed.
Do I need a separate custody licence?
In Japan, the custody of crypto-assets on behalf of customers falls within the regulated activity perimeter. An operator providing both exchange and custody services under the same entity must ensure that both activity sets are covered by the registration and that the FSA's asset segregation and safeguarding requirements are met. In other jurisdictions – including Singapore under the Payment Services Act and the EU under MiCA – custody is a separately defined regulated activity with its own authorisation requirements. Whether a separate vehicle is needed depends on the structure and the jurisdiction.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance frameworks that sit around them. Digital assets are the whole of our practice. We map the licence, banking and compliance stack across operating, custody and payment layers before you commit – and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when things go wrong. To discuss your situation, contact info@oboluslaw.com.
By Aisha Tan, Licensing & Jurisdictions Analyst – specialising in inbound VASP registration strategy across Asia-Pacific and the Gulf, including FSA/JVCEA applications and cross-border licence stack design.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.