A trading company operating between Tokyo and a third market discovers, mid-shipment, that a freight intermediary it has used for eighteen months appears on a foreign screening list. The goods have cleared Japanese customs. The payment is already in the banking chain. What does the business do next – and how does it investigate what went wrong?
An internal sanctions investigation under the Japan regime is the process by which a business identifies, scopes, and documents a potential breach of Japan's foreign exchange and foreign trade rules, assesses its exposure under those rules and any parallel regimes that apply extraterritorially, and decides whether voluntary disclosure is appropriate. Japan's primary instrument is the Foreign Exchange and Foreign Trade Act ("FEFTA"), administered by the Ministry of Economy, Trade and Industry ("METI") and, for financial transactions, the Ministry of Finance ("MOF"). No single published playbook governs an internal investigation, but the steps that produce a defensible result are well-established in cross-border practice.
This guide walks through the procedure stage by stage, maps the points where investigations under the Japan regime diverge from OFAC and OFSI practice, and identifies the pitfalls that cause matters to escalate unnecessarily.
What governs internal investigations under Japan's sanctions regime?
FEFTA is the foundational instrument: it controls capital transactions, trade, and the provision of services involving designated persons or prohibited destinations, and it gives METI and MOF the authority to investigate, impose administrative penalties, and refer serious matters to prosecutors. Japan implements United Nations Security Council measures directly through Cabinet Orders, and METI maintains its own list of entities subject to catch-all controls and end-user screening obligations. The interplay between UN-derived designations and METI's autonomous export controls means that an apparent breach may engage both the financial-transaction prohibitions administered by MOF and the export-licensing rules administered by METI – two separate authorities, two separate reporting lines.
For a business conducting an internal investigation, that duality is the first structural fact to grasp. A shipment of dual-use items to a counterparty that later appears on the UN Consolidated List may trigger METI's export-control reporting mechanism at the same time as MOF's financial-sanctions reporting mechanism. In our experience, businesses that treat these as a single channel rather than two parallel tracks create avoidable procedural errors early in the investigation. The governing instruments and the authorities differ; the internal workbook must reflect both.
Japan's regime also sits alongside – and is increasingly tested by – the extraterritorial reach of other regimes. A Japanese subsidiary of a US group will face OFAC's rules in addition to FEFTA. A Japanese bank clearing transactions in US dollars through a New York correspondent is within OFAC's jurisdiction regardless of where the underlying trade originates. An EU-headquartered company with a Japan procurement office operates under the relevant EU Council regulations in parallel. The internal investigation must identify which regimes are actually in play before it can scope the problem correctly.
Step 1 – Preserve and scope: the first forty-eight hours
The first priority in any internal investigation is to stop the clock on additional exposure and preserve the evidence base. In cross-border practice, the first forty-eight hours of a Japan-regime investigation typically involve three simultaneous actions: an evidence hold, a preliminary scope assessment, and a decision on who runs the investigation.
Evidence preservation under a Japan investigation follows the same logic as elsewhere: a litigation hold directed to the relevant custodians, covering email, payment records, shipping documentation, screening logs, and any internal approvals for the transaction in question. Japanese labour and data-privacy rules affect how employee communications can be collected, and where data sits in cloud systems outside Japan additional transfer considerations arise. These are operational constraints, not reasons to delay the hold.
The preliminary scope assessment answers four questions. First, what is the product, the transaction, and the counterparty? Second, which regime or regimes are potentially engaged – FEFTA, a Cabinet Order implementing a UN measure, METI's export-control rules, and/or a parallel foreign regime? Third, what is the chronological footprint of the apparent breach – a single transaction or a course of dealing? Fourth, who within the business had knowledge or approval authority?
The decision on who runs the investigation matters for privilege and for credibility. Japanese law does not provide attorney-client privilege in the same form as common-law systems. Documents prepared by in-house counsel in Japan do not automatically attract the protection that a US or UK internal review might assume. Where the investigation has a cross-border dimension – a US parent, an EU controller, a UK-regulated bank in the payment chain – the privilege architecture should be designed around the jurisdiction that offers the strongest protection and is most likely to be the forum for any eventual enforcement action. This decision cannot be deferred.
Step 2 – Map the counterparty and the ownership chain
A Japanese-regime investigation requires a thorough map of the counterparty, its ownership chain, and any intermediate parties – freight forwarders, financial intermediaries, and agents – that touched the transaction. Japan does not publish a single consolidated ownership-threshold rule equivalent to OFAC's 50 percent rule (OFAC's rule treating entities owned 50 percent or more by blocked persons as themselves blocked), but METI's end-user screening guidance and the UN-derived Cabinet Orders require businesses to look through corporate structures to identify whether a designated person or prohibited end-user is the ultimate beneficiary of the goods or the funds.
In practice, that look-through obligation operates similarly to the EU and UK ownership and control test (the UK and EU test for whether a non-listed entity is caught through a listed person). The analytical steps are: identify the direct counterparty; obtain its ownership structure to the ultimate beneficial owner; screen each layer against the UN Consolidated List, METI's lists, and any other applicable lists for the parallel regimes in play; and document the result. Where documents are in Japanese, Korean, or another Asian language and the investigation team lacks internal capability, translation and local verification add time – plan for it.
The cross-regime comparison is instructive here. Under OFAC, the 50 percent aggregation rule is the mechanical trigger: two listed persons each holding a minority stake can together push an entity over the line. OFSI in the UK applies an ownership and control standard that is broader and more judgement-dependent. Japan's approach under FEFTA and the Cabinet Orders does not reduce to a single published threshold in the same way. The obligation is to exercise due care to avoid transacting with a designated person or a prohibited end-user. That standard is principles-based, which means the investigation must document not just what the structure is, but what the business did to find out. Did you ask? Did you verify? Did you record the answer?
Step 3 – Reconstruct the transaction and the control failure
Once the ownership map is complete, the investigation turns to the transaction itself. The goal at this stage is a factual chronology that a regulator could read: what was ordered, when, by whom, at what price, through which intermediaries, and what screening was applied at each decision point. Every gap in that chronology is a gap in the defence.
Common weaknesses at this stage include incomplete screening logs – records that show a search was run but not the version of the list used or the result returned – and approval records that are oral or exist only as informal email exchanges rather than in a compliance workflow system. In our cross-border practice, we have seen businesses where the screening was run correctly but the log was not retained, leaving the firm unable to demonstrate that the check occurred. That is a record-keeping failure, not a screening failure, but the regulatory consequence can be the same.
For export-control matters under METI, the investigation should reconstruct whether the goods were properly classified, whether the relevant export licence was in place, and whether the stated end-use matched the actual end-use. METI's end-use verification obligations mean that a business may have acquired a representation from the buyer about the ultimate destination and use of the goods. If that representation was false, the business's culpability turns in part on how it obtained and verified the representation. Document the verification steps, not just the representation itself.
The transaction reconstruction also serves the parallel-regime analysis. If a US-dollar payment flowed through a US correspondent bank, the OFAC analysis runs on the same transaction record. If an EU-incorporated entity was the exporter of record, the EU dual-use regulation may also be engaged. The factual record compiled for the Japan-regime investigation is the starting point for all of them.
What are the disclosure obligations, and how do they compare?
Japan does not operate a formal voluntary self-disclosure scheme equivalent to OFAC's VSD (voluntary self-disclosure to a regulator) programme, under which a business can approach the regulator proactively and receive defined mitigation credit. METI and MOF have administrative mechanisms that allow a business to report a potential breach, and Japanese practice does treat proactive co-operation as a mitigating factor. But the process is less structured than OFAC's, and the degree of mitigation is less predictable.
That difference has direct implications for the investigation. Under OFAC, the decision to file a VSD is a discrete, consequential choice with a clear procedural track, a defined timeline, and a published mitigation matrix. Under METI and MOF, the decision to approach the authority is more context-dependent: the severity of the apparent breach, the nature of the goods, the counterparty involved, and the political sensitivity of the programme all bear on whether voluntary approach is strategically optimal. There is no equivalent of the OFAC prior disclosure programme's published penalty-reduction framework to anchor the decision.
Under OFSI in the UK, a business that holds funds or resources belonging to a designated person is required to report that fact within a defined statutory window. OFAC's general framework similarly requires reporting of blocked property. Japan's reporting obligations under FEFTA and the Cabinet Orders are transaction-category specific and require careful reading of the applicable instrument. An investigation that reaches a preliminary conclusion of breach should identify the applicable reporting obligation and its timeline before any external contact is made – because in some categories the obligation to report arises automatically and independently of any disclosure decision.
The position above covers the standard case. Your facts – the goods, the counterparty, the regime in play, and the corporate structure of the entities involved – change the analysis. For a confidential assessment of your disclosure obligations and exposure, contact Calder & Vance at info@caldervance.com.
Step 4 – Assess the cross-border exposure and parallel regimes
No investigation into a Japan-regime issue is complete without a parallel assessment of the other regimes that may apply. This is not a formality. It is the step most commonly deferred or omitted by businesses that treat the matter as a domestic Japanese compliance question – and it is the step that most frequently produces surprises.
The extraterritorial reach of the US regime is the most significant risk factor for most international businesses. OFAC's jurisdiction extends to US persons, to transactions processed in US dollars, and to US-origin goods and technology wherever they are in the supply chain. A Japanese subsidiary of a US-incorporated group is a US person for OFAC purposes. A shipment of goods with US-origin content above a defined threshold is subject to the EAR regardless of where the shipper is domiciled. In our experience, the most common cross-border escalation in Japan-initiated investigations is the discovery that a transaction that appeared to be a purely Japanese matter also involved US-dollar clearing or US-origin components, bringing it within OFAC's and BIS's reach.
For EU-headquartered groups with a Japan presence, the relevant Council regulations and the EU dual-use rules apply to EU-incorporated entities and, in some cases, to activities conducted from the EU regardless of where the transaction closes. A procurement decision made by an EU parent company and executed by a Japan subsidiary may sit within the EU regulatory perimeter as well as FEFTA's. The investigation should map not just where the transaction occurred, but where each decision-making step in the transaction chain took place, and which legal entity in the group was the principal.
The UK regime adds a further dimension where a UK-regulated financial institution is in the payment chain, or where the trading entity has UK nexus. OFSI's enforcement posture has sharpened considerably in recent years, and a matter that begins as a Japan-FEFTA question can acquire a UK dimension quickly once the payment routing is traced.
If a transaction has already been flagged, or a filing has been refused, an early review can preserve options that narrow with time. Contact us at info@caldervance.com.
Risk flags and common pitfalls
Several patterns recur in Japan-regime investigations that cause matters to escalate from manageable compliance questions to serious enforcement exposures. Identifying them early is the most effective form of risk management.
The first is the assumption of domestic containment. A business that runs an investigation on the premise that the matter is purely a FEFTA question, without checking the parallel regimes, may inadvertently waive privilege, make disclosures in Japan that bind the position in the US or EU, or take remediation steps domestically that foreclose options under OFAC or ECJU. The investigation architecture should be set before any external communication, including with Japanese counsel.
The second pitfall is late evidence preservation. Japanese employees are not always aware of litigation-hold obligations in the way that counterparts in US or UK businesses may be. The investigation team should issue the hold notice quickly, before the scope is fully defined, and confirm compliance explicitly. Evidence that is overwritten or deleted after a hold notice is a separate and serious problem.
The third risk is underestimating METI's end-user focus. METI has the authority to conduct on-site inspections and to require production of export-related records. A business that is conducting an internal investigation simultaneously faces the possibility of a regulatory inquiry from METI. The internal investigation should proceed on the assumption that its findings may ultimately be shared with – or independently reached by – the regulator.
A fourth risk, specific to the cross-border dimension, is the BIS Entity List. The Entity List maintained by the US Bureau of Industry and Security identifies parties subject to specific export-licence requirements. An entity that is not on the UN Consolidated List or METI's lists may nonetheless appear on the BIS Entity List. A Japan-regime investigation that screens only against Japanese and UN lists may miss this. The investigation's scope should cover the lists relevant to each regime in play.
Finally, the privilege question bears repeating. Work product generated during the investigation – interviews, chronologies, preliminary legal assessments – may or may not be protected depending on who authors it and under which jurisdiction's rules it is assessed. In a matter with US, UK, EU, and Japan dimensions, the privilege architecture must be established deliberately. Do not assume that documents labelled "legal privilege" are protected in every relevant forum.
When to involve external counsel, and what to ask for
External sanctions counsel should be involved from the moment the apparent breach is identified, not after the preliminary investigation has already produced a written record. The most common timing error is for a business to run an internal review, reach a preliminary conclusion, and then bring in counsel to manage the disclosure – at which point the internal documents already exist and their privilege status is uncertain.
Counsel should be instructed to: scope the applicable regimes; design the privilege architecture; advise on evidence-preservation obligations across jurisdictions; direct the factual investigation; advise on whether any mandatory reporting obligation has been triggered and its timeline; assess the voluntary disclosure question under each regime in play; and, if disclosure is appropriate, manage the regulator's queries. This is not a sequential list. Several of these tasks run in parallel from day one.
In a recent matter, an Asia-Pacific trading business identified a potential FEFTA issue involving an intermediary. We assessed the parallel OFAC and BIS exposure, structured the privilege architecture across the US and Japanese entities, and advised on the voluntary disclosure question under both OFAC's framework and the Japanese administrative mechanism. The matter resolved without referral to prosecutors, and the business implemented a revised end-user screening programme. The outcome cannot be promised – but early, structured engagement consistently produces better results than reactive management of an already-documented problem.
A myth worth correcting: many businesses believe that a matter involving only Japanese-incorporated entities and goods originating in Japan is insulated from US enforcement. It is not. US-dollar clearing, US-origin technology above the applicable content threshold, and US-person involvement in the transaction chain can all engage OFAC's and BIS's jurisdiction, regardless of where the counterparties are incorporated. The test is not the nationality of the parties; it is the nature of the US nexus in the transaction.
Related practices
- Apparent Violation Assessment – EU – scoping and advising on apparent violations under EU sanctions, including voluntary disclosure and enforcement defence.
- Internal Sanctions Investigations under OFAC – Guide – step-by-step procedure for OFAC-facing internal reviews, VSD, and penalty mitigation.
- Internal Sanctions Investigations under OFSI – Guide – UK-regime investigation procedure, statutory reporting obligations, and enforcement defence.