ブログ
【Financial Instruments Business Regulation Blog】Key Areas of Focus in the SESC’s Securities Monitoring for Program Year 2026: An Overview of the SESC’s Basic Policy (Part 2)
2026.09.09
Key Areas of Focus by Size and Business Type
This blog provides an overview of the key areas of focus in the authorities’ securities monitoring for PY2026, covered in two parts (Part 1 and Part 2). Part 1 discussed the “cross-industry areas of focus” (see Part 1 here). Part 2 focuses on the “key areas of focus by size and business type.”
The PY2026 Policy sets out a wide range of focus areas based on the size and business type of financial instruments business operators and other regulated entities. This blog highlights the key points. For further details, please refer to the sources cited below.
>Source: SESC https://www.fsa.go.jp/sesc/news/c_2026/2026/20260731-2/02.pdf)
(1)Major Securities Company Groups
The PY2026 Policy identifies the “management of corporate-related information” and “internal control frameworks for underwriting reviews, among others” as areas of focus that were not specifically addressed in the PY2025 Policy. With respect to underwriting reviews, particular attention should be paid to the Japan Securities Dealers Association (JSDA)’s Guidelines on Underwriting Reviews. ¹
¹ JSDA, Guidelines on Underwriting Reviews in Light of Accounting Fraud Cases at the Time of Initial Public Offerings (March 18, 2026)
The Guidelines were developed in response to cases of accounting fraud by issuers coming to light in connection with initial public offerings. They set out matters that lead managing member firms should pay particular attention to when conducting underwriting reviews to ensure that their underwriting review functions operate appropriately.
Specifically, lead managing member firms are expected to pay particular attention to the matters listed under the following areas: (i) inquiries and other procedures tailored to the risk of fraud; (ii) confirmation of the appropriate establishment and operation of internal whistleblowing systems and responses to information concerning fraud and other misconduct; and (iii) inquiries directed to representative directors and other senior management, audit & supervisory board members and other audit personnel, and independent officers.
(2)Online Securities Companies
The PY2026 Policy states that the authorities will conduct a cross-industry review of, among other matters, cybersecurity measures in light of increasingly sophisticated and complex methods of unauthorized access and fraudulent transactions in online trading, as well as the status of internal control frameworks relating to required confirmation at the time of transactions of customer identification and other measures, and trading surveillance systems.
The PY2025 Policy stated that the authorities would review the management of system risks, including cybersecurity measures, in light of the increasing number of cases involving unauthorized access and fraudulent transactions in online trading. The PY2026 Policy therefore reflects a slight change in how cybersecurity measures are addressed.
In addition, the PY2026 Policy newly identifies internal control frameworks relating to customer identification and other transaction-related measures, as well as the status of trading surveillance systems, as areas of focus. These matters were not specifically addressed in the PY2025 Policy.
(3)Mid-Sized and Regional Securities Companies (Including Securities Companies Affiliated with Regional Banks)
The PY2026 Policy newly identifies the following areas of focus:
|
With respect to item 1, a relevant case is a regulatory action taken in June 2026 against a securities company that provided online trading services to retail investors. The authorities found multiple issues, including inappropriate business practices relating to the registration of NISA-eligible products in the company’s systems, and issued a recommendation and administrative sanction. ²
² This case is described on page 6 of the “PY2025 Securities Monitoring Overview and Case Studies”.
The company in question was originally a securities company based in the Kansai region whose business was primarily conducted through face-to-face transactions. Following its acquisition by a foreign company that operated securities trading services overseas, the company began offering online trading services to retail investors and financial products through NISA.
While the company expanded its business by introducing new products and services, it failed to conduct sufficient checks when introducing them, including whether they could be supported by its systems and whether they complied with applicable laws, regulations and other rules. The company was also found not to have established an adequate system risk management framework commensurate with the scale and nature of its business. As a result, the authorities determined that the company’s internal control and management frameworks were inadequate.
Item 1 can therefore be viewed as a response to this type of case. In recent years, some companies seeking to enter the Type I Financial Instruments Business have done so by acquiring small or mid-sized securities companies rather than obtaining a new registration, and then significantly changing the combined companies’ business and expanding services. Where a financial instruments business operator changes the nature or scope of its business, including through such an acquisition, particular attention should be paid to whether it has established an effective internal control framework appropriate to its changed business.
With respect to item 2, a relevant case is a regulatory action taken in June 2026 concerning inappropriate business practices in connection with the sale of Turkish lira-denominated foreign bonds. ³
³ This case is described on page 10 of the “PY2025 Securities Monitoring Overview and Case Studies”.
One of the issues identified in that case was the company’s failure to conduct a sufficient assessment of whether the product had a reasonable basis for sale to investors.
The “reasonable-basis suitability” requirement is intended to operationalize the suitability principle and other relevant requirements by requiring firms to assess in advance whether a product is appropriate for sale to investors. The requirement is set out in Article 3, paragraph 3 of the JSDA Rules Concerning Investment Solicitation, Customer Management, etc., and the JSDA has also established guidelines on reasonable-basis suitability.
In the case above, the company introduced a new type of Turkish lira-denominated bond: a zero-coupon bond subject to an issuer call option (a “Callable Bond”). When deciding whether to introduce the product, the company’s New Product Committee, which was responsible for the preliminary review of new products, and the subsequent company management meeting did not conduct a specific analysis or assessment of the product’s characteristics, risks, intended customer base or reasonableness as an investment product. Nevertheless, the company proceeded with the sale of the bonds and continued to sell them thereafter. The authorities therefore found that the company had failed to conduct a sufficient assessment of reasonable-basis suitability.
Item 2 above can likewise be viewed as a response to this type of case. Securities companies should pay particular attention to whether an appropriate framework for assessing reasonable-basis suitability has been established in accordance with the JSDA rules and guidelines.
(4)Investment Management Companies
As in the PY2025 Policy, the PY2026 Policy identifies the following areas of focus:
|
With respect to item 3, the PY2026 Policy provides more detail than the PY2025 Policy on matters to be reviewed. Specifically, it refers to whether there have been any breaches of the duty of loyalty, such as transactions in which the interests of a parent company or other related party are prioritized over those of investors, and whether a framework is in place to enable the appropriateness of transactions with a parent company or other related party to be reviewed retrospectively. In this regard, a relevant case is a regulatory action taken in December 2025 against a REIT asset management company after the authorities found that the company had failed to conduct its investment management business loyally for the benefit of the investment corporation. ⁴
⁴ This case is described on page 15 of the PY2025 Securities Monitoring Overview and Case Studies.
In that case, when acquiring a property from its parent company, the company sought a real estate appraiser that was expected to provide an appraisal value meeting the price proposed by the parent company and such an appraiser was selected. The company also prepared drawings showing a use of the property different from its current use, based on an assumed use after the existing lease agreement expired, provided the drawings to the appraiser, and encouraged the appraiser to assume use of the property in accordance with those drawings.
The authorities found that, in the process of selecting a real estate appraiser, where eliminating arbitrariness was particularly important because the transaction involved the acquisition of a property from an interested party, the compliance department had failed to exercise sufficient oversight. The authorities also found that the company’s directors had intervened beyond what was reasonably necessary, against a background in which the company’s directors were composed of secondees from the parent company. The authorities therefore determined that the company’s conflict-of-interest management framework was significantly inadequate and that the company had violated the duty of loyalty under Article 42, paragraph 1 of the Financial Instruments and Exchange Act.
The above areas of focus concerning conflict-of-interest management can be viewed as a response to this type of case. Investment management companies should continue to pay particular attention to the rules governing transactions with parent companies and other related parties, the appropriateness of investment management operations, and the framework for retrospectively reviewing the appropriateness of such transactions.
Conclusion
This concludes our overview of the key areas of focus in the authorities’ securities monitoring for PY2026, based on the PY2026 Policy. While these are not the only matters that may be examined as part of the authorities’ securities monitoring, we hope that this overview will serve as a useful reference for financial instruments business operators and other regulated entities in identifying matters that warrant particular attention and proactive action during the current fiscal year.
TMI Associates will continue to publish articles on this blog covering interpretations and key issues relating to business regulations applicable to financial instruments business operators and other regulated entities, including regulations under the Financial Instruments and Exchange Act and self-regulatory rules established by self-regulatory organizations, as well as articles on inspections (audits) and supervision by the Financial Services Agency, the Securities and Exchange Surveillance Commission, and self-regulatory organizations.
Member
PROFILE
