What FSA Examination Teams Typically Request
Governance Documentation
- Board meeting minutes for the examination period — typically the most recent 12 to 24 months — demonstrating that AML/CTF risk appeared as a substantive agenda item. Examiners specifically look for evidence of board engagement: questions asked, challenges raised, decisions made. Minutes that record ‘compliance report noted’ without further detail do not satisfy this requirement.
- Management information reports presented to the board — the actual reports provided, including the content, frequency, and the specific metrics and analysis presented. Examiners assess whether the information was sufficient to support meaningful governance.
- Internal audit reports on AML/CTF compliance, with findings classified by severity, management responses, and remediation status.
- The enterprise-wide ML/TF risk assessment with documented evidence of board approval and the date of the most recent review and update.
CDD Programme Records
- Sampling of customer CDD records across risk tiers. Examiners select records at their discretion — typically a mix of standard-risk and high-risk customers, including PEP customers if any are held. They assess completeness of identity verification, consistency of beneficial ownership documentation, appropriateness of the CDD tier assigned, and evidence of periodic review.
- EDD records for PEP customers and high-risk customers: senior management approval documentation, source of wealth and source of funds investigation records, and evidence of enhanced monitoring calibration.
- PEP screening records and the database and coverage used. Examiners specifically test whether domestic Japanese PEP screening was conducted, and may present examiner-selected domestic PEP names to verify they appear in the platform’s results.
- Beneficial ownership verification records for corporate customers, with documentation of how the UBO determination was reached for customers with complex ownership structures.
Transaction Monitoring Performance
- Alert volume statistics for the examination period by alert category and month, showing trends over time — not just current state.
- False positive rates with evidence of how these are measured, what action is taken when false positive rates are high, and the trend over the examination period.
- Alert resolution times: the average and distribution of time from alert generation to disposition decision, with trend analysis.
- STR filing rates as a proportion of alerts reviewed, by month, with analysis of how this rate relates to the institution’s assessed risk profile.
- Monitoring parameter documentation: the specific rules and thresholds applied, version history, the date of each review, and the documented rationale connecting each parameter to the risk assessment.
STR Process Records
- Sample STR case records selected by examiners — the complete record from initial alert through investigation steps to JAFIC submission, with system timestamps at every stage.
- Not-filed disposition records for alerts that were reviewed and closed without STR filing. The documented rationale for each such decision — not a blank field, and not a generic statement.
- JAFIC submission confirmation records with the submission timestamp and reference number.
The Most Common Evidence Gaps at Mid-Market Institutions
Based on FSA examination findings, the following gaps appear with the greatest frequency at mid-market institutions:
- Incomplete alert disposition records: the most frequent gap. Alerts closed without documented rationale — often because the compliance analyst closed the alert in the system without completing the disposition note. A case management system that requires a documented rationale before an alert can be closed eliminates this gap automatically.
- Inconsistent CDD record formats and completeness: manually compiled CDD records vary in format and completeness across the customer book — some records have all required fields, others have gaps. A platform that enforces required field completion produces consistent records regardless of which team member completed the onboarding.
- Absence of domestic PEP screening evidence: no documentation that domestic Japanese PEP screening was conducted, because the institution’s screening platform does not include domestic Japanese PEP data. This gap is both a compliance gap (Article 4 APTCP requirement not met) and an evidence gap.
- Monitoring calibration without documented rationale: monitoring rules exist in the system but there is no documented record of why those specific parameters were selected, when they were last reviewed, or how they connect to the risk assessment. The calibration rationale documentation must exist in the system — not in the CCO’s head.
- Governance records without substance: board meeting minutes that record a compliance officer presentation but do not reflect questions, challenges, or decisions by board members. The content of minutes — not just their existence — is what the FSA assesses.
How Compliance Infrastructure Drives Evidence Quality
Each of the common evidence gaps above is directly and systematically addressed by properly configured compliance infrastructure:
- Alert disposition records: a case management system that requires a documented disposition rationale — with a minimum content standard — before an alert can be closed generates complete records for every alert, automatically. No compliance team member can close an alert without completing the record.
- CDD record consistency: a platform that enforces required data fields at CDD completion produces consistent records across all customers, regardless of which compliance team member conducted the onboarding. Field-level validation eliminates missing fields.
- Domestic PEP screening evidence: a platform with comprehensive Japanese domestic PEP database coverage provides a screen-by-screen evidence record for every customer screened. The evidence is generated automatically at each screening event.
- Monitoring calibration documentation: a platform that stores monitoring rule parameters with version history, review dates, and associated calibration rationale notes provides FSA-ready evidence on demand. This documentation does not need to be compiled before an examination — it exists in the system.
- Management reporting quality: a platform with built-in reporting dashboards produces consistent, scheduled management information that can be presented to the board as a standard governance process. The reports are system-generated and consistent in format and content.
The practical conclusion for CCOs at mid-market institutions preparing for the 2028 examination cycle: the investment in compliance infrastructure is a direct investment in examination readiness. The two cannot be separated, and the preparation window is now.
Frequently Asked Questions
FSA Examination Evidence Pack Japan: What to Document | Nexiant
What Japan’s FSA examination teams request at mid-market institution AML/CTF examinations — governance records, CDD sampling, monitoring performance, STR trails — and how compliance technology drives evidence quality.
Speak to our teamThis article was accurate at the time of publication in June 2026 and is intended for general informational purposes only. It does not constitute legal, regulatory or compliance advice. Organisations should seek qualified professional guidance in relation to their specific obligations.




