Domestic VASP security / audit / ISMS certification landscape
ConfidenceLikelyUpdated2026-05-19Review by2026-09-21Sources2Machine-translatedOriginal (JA)
On this page
Overview
Domestic VASPs bear security + audit obligations across three layers: FSA supervisory guidelines + JVCEA self-regulatory rules + industry self-standards. In addition to statutory requirements, obtaining third-party certifications such as ISMS (ISO/IEC 27001) and SOC2 Type II reports has effectively become standard, serving as a prerequisite for institutional-investor onboarding + overseas collaboration + B2B custody engagements. Following the Coincheck NEM theft (2018) + the DMM Bitcoin Lazarus theft (2024), obtaining certification has reached a state of “voluntary but you cannot stay in the industry without it.”
Statutory obligations (amended Payment Services Act + supervisory guidelines)
- System-risk management framework: management involvement + risk assessment + internal audit (annual)
- Segregated management of customer assets: trust custody + internal audit + external audit by an audit firm
- Cold storage 95% / hot 5%: JVCEA rules · operational-audit obligation
- AML/CFT internal controls: compliance with the Act on Prevention of Transfer of Criminal Proceeds + JAFIC reporting framework
- Personal information protection: Act on the Protection of Personal Information (APPI) + extraterritorial application of GDPR (where overseas customers exist)
Third-party certifications (voluntary but effectively mandatory)
- ISMS (ISO/IEC 27001): obtained by all major firms including bitFlyer / Coincheck / GMO Coin / SBI VC Trade / bitbank
- SOC2 Type II: centered on institutional OTC / custody (Crypto Garage / Custodiem / Komainu Japan, etc.)
- PCI DSS: related to fiat-currency card payments (some)
- Certified Internal Auditor (CIA) / Certified Information Systems Auditor (CISA): mandatorily placed in internal-audit departments
VASPs by audit firm
- EY ShinNihon: bitFlyer / Coincheck
- PwC Aarata: SBI VC Trade
- Deloitte Touche: GMO Coin
- KPMG AZSA: Custodiem / Mercury group
- The global 4 majors hold a 100% oligopoly — small and mid-sized audit firms find it difficult to enter VASP auditing (specialized talent + cost + risk tolerance)
International comparison
- U.S.: SOC2 + per-state MTL individual audits + NYDFS Part 500 (BitLicense)
- EU: MiCA + DORA strengthen ICT third-party auditing (2025-)
- South Korea: ISMS-P (integrated personal-information + information-protection) mandatory
- Japan: ISMS + internal audit + FSA monitoring three layers — a unique structure in which self-regulation (JVCEA) effectively mandates obtaining certification
Related
#exchanges#vasp#security#audit#isms#iso27001
Discovery
Keep reading
Read next
- Domestic Web3 / Crypto-Asset Public Policy Body Layer (METI Web3 Policy Office / LDP web3 PT / Cabinet Secretariat)Japanese Web3 and crypto-asset policy involves the FSA's financial regulation, METI's industrial policy, cross-government work by the Cabinet Secretariat and Digital Agency, and policy propo...
- JVCEA: Overview of the Self-Regulatory Framework1. Membership screening: Reviews the structure and compliance of VASPs applying for membership, both before and after FSA registration 2. Token review (White List): Prior-review framework fo...
- JVCEA Domestic Spot Trading Volume Statistical Analysis (2017-2026)JVCEA publishes consolidated monthly statistics for its members (Type 1 crypto asset exchange operators), continuously reporting key metrics including spot / leverage / spot holdings / custo...
Links here
- Crypto-asset custody provider landscape matrix — Japan + Global institutional custody 10 社 technology / regulation / customer comparisonThe institutional crypto-asset custody market is differentiated along three axes: (1) technology model (cold storage / MPC / hybrid) × (2) license tier (Trust Charter / VASP / vendor only) ×...
- Global crypto-asset forensics-vendor layer — Chainalysis / Elliptic / TRM / Crystal comparisonCEXs + banks + law-enforcement agencies depend on specialized forensics vendors for AML/CFT monitoring, sanctions screening, and illicit-fund tracing of crypto-asset transactions. Chainalysi...
- Japan crypto audit-firm landscape — Big4 + Grant Thornton Taiyo + BDO Sanyu crypto-practice comparisonFSA-registered VASPs are, under the Payment Services Act + Cabinet Office Ordinance, obligated to receive each fiscal year a financial-statement audit and a segregated-management audit(assur...
- Etherscan verified-source poisoning — why \"verified\" is not \"the bytecode\"Verification recompiles submitted source under declared compiler settings and compares the output to the deployed bytecode. The strength of that assertion varies by tool and match type:
- A Five-Layer Audit Framework for Fork-and-Rebrand ProjectsThe core idea of the Fork-and-Rebrand audit is "what matters is not the code that did not change, but what was changed, what was inherited, and what was hidden."