Published
Key points
- The FISC Security Guidelines on Computer Systems for Financial Institutions are published by the Center for Financial Industry Information Systems (FISC), a public interest incorporated foundation. They are not law, and FISC states that it does not judge whether any company’s systems or operations conform to them.
- The current edition is the 14th, issued in March 2026. The Japanese PDF costs 3,000 yen including tax and is free for FISC members; the latest English translation is of the 13th edition (November 2025, 2,400 yen).
- FISC lists four revision areas in the 14th edition: AI safety measures, cybersecurity, post-quantum cryptography (PQC), and system failure cases with other guidelines. The PQC changes reflect the points to note and the timeline in the FSA’s November 2024 study group report.
- The 13th edition (March 2025) already absorbed the FSA’s Guidelines on Cybersecurity for the Financial Sector of 4 October 2024, turning its fundamental response measures and recommended measures into new or revised sub-items. The FSA guideline asks for a risk-based approach, not a uniform response.
- The FSA study group report says high-priority systems should be able to use PQC algorithms by around the mid-2030s, and that institutions should start early on a cryptographic inventory of where cryptography is used.
What the FISC Security Guidelines are
The FISC Security Guidelines, known in Japanese as the Anzen Taisaku Kijun (security measures standards), are published by the Center for Financial Industry Information Systems (FISC) under the official English title “FISC Security Guidelines on Computer Systems for Financial Institutions”. They set out the security measures that financial institutions in Japan need when they develop, introduce and operate financial information systems, and explain each item with concrete examples.
FISC was established in November 1984 as an incorporated foundation with the approval of the then Minister of Finance, and became a public interest incorporated foundation in April 2011. It had 679 member institutions as of 31 March 2026. The first edition of the guidelines appeared in December 1985 and has been revised many times since. The current text is deliberated by FISC committee members drawn from academia, financial institutions, computer manufacturers, cloud service providers and FinTech companies.
Legal status and the FSA
The guidelines are not law. FISC says it established them in collaboration with its member institutions, the Financial Services Agency (FSA) and the Bank of Japan, and that they have been voluntarily observed by most financial institutions in Japan.
The FSA has also relied on them. In its paper on dialogue about IT governance (2nd edition, June 2023), the FSA explains that its former inspection manual told inspectors to verify system risk management against the FISC guidelines when examining a business in depth, so the guidelines were used in inspections. After the manual was abolished, the FSA expects institutions to keep using generally available guidelines, and names as examples the FISC Security Guidelines, the FISC System Audit Guidelines, COBIT from ISACA, and the system management and system audit standards of the Ministry of Economy, Trade and Industry (METI).
FISC states that it does not judge whether the systems or operations of any company, organisation or institution conform to its guidelines, and that it takes no responsibility for conformity judgements made by third parties. A “FISC compliant” label on a vendor document is therefore an assessment by the vendor or a third party, not a certification by FISC.
Who uses them: financial institutions, outsourcees, cloud and SaaS providers
The guidelines are written for financial institutions, including banks, securities firms and insurers. In practice, the companies that build and run systems for those institutions, and the cloud and SaaS providers that serve them, also work to the guidelines, because their clients ask them to explain their controls item by item.
The FSA’s Guidelines on Cybersecurity for the Financial Sector say that third parties providing services to financial institutions should offer the support those institutions need to manage cybersecurity risk, including making sure they can access relevant information about the cybersecurity risks of the third party itself. The FSA adds that, under the applicable laws, it has the authority to issue reporting orders to outsourced entities and to inspect them on site when it deems this necessary.
- Financial institutions use the guidelines as the basis for their system risk management rules and security standards, and check their own controls against the items.
- Outsourcees and system vendors are asked to show that their development, operations, access management and incident communication follow the standards their client applies.
- Cloud and SaaS providers are asked, during a client’s onboarding review, to explain how they meet each relevant item. Cloud-specific considerations were folded into the standard items in the 11th edition (May 2023).
How the guidelines are structured
The body of the guidelines is divided into four sets of standards: control standards (tosei kijun), practice standards (jitsumu kijun), facility standards (setsubi kijun) and audit standards (kansa kijun). For each item they describe what to implement and how, with concrete examples. FISC describes the book as a guide to the security measures an institution should take according to the nature and importance of its business.
FISC’s pages for earlier editions (the 9th edition of December 2021, the 10th, and the English 13th) publish the following table of contents (our translation). The page for the 14th edition does not show one, so check the details in the purchased copy.
- I. Overview
- II. Framework
- III. Using this book
- IV. List of the security standards
- V. Control standards
- VI. Practice standards
- VII. Facility standards
- VIII. Audit standards
The 9th edition (March 2018) reorganised and expanded the standards for controlling outsourcees and introduced a risk-based approach grounded in IT governance. Instead of meeting every item uniformly, an institution sets the level of each control according to the importance and risk of the system or business concerned. The 10th edition extended the risk-based wording to the facility standards.
The text of the guidelines is a paid publication. This article summarises only what FISC and the FSA publish openly; check the wording and numbering of individual items in the purchased edition.
The four changes in the 14th edition (March 2026)
The 14th edition, issued by FISC in March 2026, is the current edition. FISC lists four revision areas: AI safety measures, cybersecurity, post-quantum cryptography (PQC), and system failure cases together with other guidelines.
| Area | FISC’s description |
|---|---|
| AI safety measures | Collected and analysed guidelines and reports on AI and generative AI from government agencies, industry associations and other bodies, and reflected them in the standards |
| Cybersecurity | Collected and analysed cybersecurity guidelines and reports from government agencies, industry associations and other bodies, and reflected them in the standards |
| Post-quantum cryptography (PQC) | Reflected the points to note on PQC migration and the response timeline in the FSA’s November 2024 report of the study group on PQC for deposit-taking financial institutions |
| System failure cases and other guidelines | Analysed documents on system failure cases and various guidelines, and reflected them in the standard items and their commentary |
The PQC report is the only source document FISC names. For AI and cybersecurity it refers only to guidelines and reports published by government agencies, associations and other bodies, and its public pages do not say which items were added or changed. To see the item-level differences from the 13th edition, you need to compare the purchased editions.
Also in March 2026, FISC published two companion PDFs: the third edition of its guide to developing security policies for financial institutions, and a commentary on system risk management for financial institutions, each priced at 3,000 yen.
Revision history since the 9th edition
Since the fundamental overhaul of the 9th edition in March 2018, FISC has revised the guidelines frequently. From 2024 a new edition has appeared every March: the 12th in March 2024, the 13th in March 2025 and the 14th in March 2026.
| Edition | Issued | Main changes |
|---|---|---|
| 9th | March 2018 | Fundamental revision: reorganised and expanded controls over outsourcees; introduced a risk-based approach grounded in IT governance |
| 9th, December 2021 version | December 2021 | Wider use of teleworking, and fraudulent withdrawals made through direct-debit account transfers |
| 10th | July 2022 | Full revision of the facility standards with more on the risk-based approach; system failure cases and business continuity lessons from the pandemic |
| 10th, December 2022 revision | December 2022 | Cybersecurity, including measures that assume intrusion; the 2020 and 2021 amendments to the Act on the Protection of Personal Information; analysis of a series of system failures at a city bank in early 2021 |
| 11th | May 2023 | Folded the trial guide on cloud adoption and operation into the standard items; clearer wording |
| 12th | March 2024 | More diverse ATM locations, volcanic ash risk, system failure cases and cybersecurity |
| 13th | March 2025 | Economic Security Promotion Act, operational resilience, the FSA cybersecurity guideline, AI safety measures, system failure cases |
| 14th | March 2026 | AI safety measures, cybersecurity, post-quantum cryptography, system failure cases and other guidelines |
AI and generative AI controls
AI safety measures entered the guidelines in the 13th edition (March 2025) and were revised again in the 14th. In the 13th edition, responding to the rapid spread of AI and generative AI, FISC added commentary to the framework part of the book and created new sub-items that set out security measures.
The groundwork was a FISC study published in September 2024, “Considerations from the Perspective of Safety Measures for Utilization of AI by FIs in Their Business” (the FSA’s English rendering of the title). The FSA’s AI Discussion Paper (version 1.1, March 2026) says FISC added standard items covering AI on the basis of that study, and notes that a FISC document of September 2024 identified three information security issues: information leakage, specifications and settings, and monitoring.
The 14th edition then reflected FISC’s analysis of AI and generative AI guidelines and reports from government agencies, associations and other bodies. According to the same discussion paper, many financial institutions said they drew on the AI Guidelines for Business issued by METI and the Ministry of Internal Affairs and Communications when writing internal rules, and they also widely referred to private-sector guidelines, FISC publications and AI laws abroad, such as those of the EU.
Checks that follow the three issues FISC identified
- Information leakage: decide, in both policy and configuration, which classes of information may be entered, whether data may be sent to external services, and how prompts and outputs are logged.
- Specifications and settings: bring models, services, permissions, connections and update procedures under configuration management, and record every change.
- Monitoring: check outputs and usage continuously for errors and misuse. The FSA discussion paper also says the outputs of generative AI need monitoring for hallucinations and copyright infringement.
- Outsourcing: include external AI services, and SaaS products with AI built in, in outsourcing and third-party risk management.
Post-quantum cryptography: the mid-2030s benchmark
The 14th edition reflects the points to note and the timeline in the report of the FSA’s study group on post-quantum cryptography for deposit-taking financial institutions, published on 26 November 2024. The report says that high-priority systems in each organisation should be able to use PQC algorithms by around the mid-2030s, while watching technical progress and regulation abroad.
The concern is that a cryptographically relevant quantum computer (CRQC) could break today’s widely used public-key cryptography in a realistic time. The report notes that estimates of when a CRQC will appear range from about 2030 to 2050, and that some say one will never be built, but because replacing cryptography takes a long time, it recommends starting work promptly. It also points out that the US government is driving migration with 2035 as a target, so migration requirements could find their way into laws and foreign regulations that apply to deposit-taking institutions.
Because of harvest-now-decrypt-later (HNDL) attacks, in which encrypted data is collected now and decrypted once quantum computers mature, the report says some uses that need long-term protection may call for early action, citing code signing for firmware and key exchange in TLS as examples.
Basic migration steps in the report
- Prioritise migration targets according to the risk that a quantum computer able to break cryptography would compromise existing cryptography.
- Build a cryptographic inventory, a register of where cryptography is used and with which algorithms, to understand the targets in detail.
- Consider an architecture that can respond safely and quickly as cryptography becomes compromised.
- Set migration deadlines, starting with the highest priorities, and plan risk-reduction measures in case a deadline is missed.
The report also asks senior management to lead and decide the migration policy; to raise crypto-agility, the ability to switch algorithms flexibly, because PQC algorithms may themselves turn out to have weaknesses; and to work with vendors, financial infrastructure providers and FinTech companies.
The report is addressed to deposit-taking institutions. The FISC Security Guidelines, however, are written for financial institutions in general, so securities firms, insurers and others working towards the 14th edition also need to check how it treats PQC.
How the FSA cybersecurity guideline of October 2024 fits in
The FSA’s Guidelines on Cybersecurity for the Financial Sector, published on 4 October 2024, were folded into the 13th edition of the FISC guidelines (March 2025). FISC says it organised the guideline’s fundamental response measures and recommended measures and turned them into new or revised sub-items.
The FSA developed the guideline as a more detailed document, separate from its comprehensive supervisory guidelines, drawing on the results of its inspections and monitoring. It has three sections: fundamental principles, the cybersecurity management framework, and stronger collaboration between the FSA and related organisations. Section 2 sets out points of focus on governance, identification, protection, detection, response, recovery and third-party risk management.
| Tier | Definition in the guideline (summarised) |
|---|---|
| Fundamental response measures | Foundational actions that financial institutions generally need to implement, often called cyber hygiene: embedding basic practices such as proper IT asset management and security patching across the organisation |
| Recommended measures | Practices desirable for institutions whose incidents could significantly affect local communities and economies, and best practices identified through dialogue with foreign authorities and institutions, which major financial institutions and major financial market infrastructures should consider |
Neither tier demands a uniform response. Institutions are expected to identify and assess their cybersecurity risks in light of their business environment, strategy and risk tolerance, and to take proportionate mitigation measures: a risk-based approach. The FSA says its monitoring will bear in mind that institutions should prioritise by importance and urgency and work within their resource constraints.
The guideline applies to a wide range of firms whose supervisory guidelines contain cybersecurity provisions, from major banks, regional financial institutions and insurers to financial instruments business operators, funds transfer and crypto-asset exchange service providers, clearing institutions and exchanges. It also lists the FISC Security Guidelines among its reference materials, together with the NIST Cybersecurity Framework and The Profile from the Cyber Risk Institute.
Using the two together
The FSA guideline sets out in detail what the FSA looks at in inspections and monitoring. The FISC guidelines absorbed it in the 13th edition and also cover areas beyond cybersecurity, with implementation methods. The two do not compete, so it is efficient to manage the guideline measures and the FISC items in one mapping table.
Running a gap assessment against the 14th edition
Working through five stages, from scope to evidence, makes it easier to avoid gaps when moving to the 14th edition.
- Set the scope: obtain the 14th edition and list the systems, business processes, outsourcees and cloud services in scope. Following the risk-based approach, assess the most important systems first.
- Build a mapping table: for each item, record the internal policy or procedure, the owning department and the evidence. Put the measures of the FSA cybersecurity guideline in the same table to avoid keeping two sets of records.
- Assess the gaps: start with the four revised areas (AI, cybersecurity, PQC and system failure cases) and rate each item as met, partly met, not met, or not applicable with a recorded reason.
- Plan the response: give each gap an action, an owner, a deadline and a budget, and report to senior management. Put multi-year work such as PQC migration on a roadmap aligned with system renewal plans.
- Keep evidence and ledgers: retain policy revision histories, risk assessment results, IT asset and cryptographic inventories, and outsourcee assessments, ready to show in inspections, internal audits and client enquiries.
Common pitfalls
- Relying on a vendor’s “FISC compliant” claim: FISC does not judge conformity, so assess the service against your own use of it.
- Keeping an old mapping table: a new edition has appeared every March since 2024, so build an annual review into the plan.
- Leaving generative AI and SaaS out of the ledgers: services contracted by individual departments easily fall outside outsourcing management.
- Not knowing where cryptography is used: without a cryptographic inventory you cannot prioritise PQC migration.
How findn can help
findn Co., Ltd. provides IT consulting grounded in IT governance frameworks such as the FISC Security Guidelines and COBIT, covering IT risk and compliance, information security and data governance, cloud adoption and AI tool adoption. findn is ISO/IEC 27001:2022 certified, and its CEO, Saravana Prathap, is a CISA with more than 25 years in IT who moved to Japan in 2005 and has since worked with major securities firms in Japan and abroad. shachi, findn’s IT governance platform for Japanese financial institutions, holds a risk ledger with KRIs, policies and regulatory reports, an inspection binder, an audit trail, an IT asset ledger and SBOM/AIBOM records, and can keep the mapping tables, ledgers and evidence described in this article.
Questions and answers
- Are the FISC Security Guidelines legally binding?
- No. They are a voluntary standard set by the Center for Financial Industry Information Systems (FISC), not a law or regulation. FISC says most Japanese financial institutions observe them voluntarily, and the FSA used them in inspections under its former inspection manual and still names them among the general guidelines it expects institutions to use. FISC does not judge whether any company’s systems conform to them.
- Where can I get the 14th edition?
- Buy the PDF from the publications section of the FISC website. The general price is 3,000 yen including tax; FISC members receive it free, and educational institutions are charged a separate rate. After purchase you download it with an ID and password. As of 1 October 2026 it is available in Japanese only.
- Do cloud and SaaS providers have to comply with the FISC Security Guidelines?
- The guidelines place no legal obligation on providers. But financial institutions must manage risk across their outsourcees, and the FSA cybersecurity guideline says third parties serving financial institutions should support them, for example by making relevant information available. A provider selling to Japanese financial institutions should be ready to explain its controls item by item.
- What changed from the 13th edition?
- FISC lists four revision areas: AI safety measures, cybersecurity, post-quantum cryptography, and system failure cases with other guidelines. PQC does not appear in the revision notes for earlier editions and reflects the FSA’s November 2024 study group report; AI and cybersecurity were also revised in the 13th edition. FISC does not publish item-level differences, so compare the purchased editions.
- Is there an English version of the FISC Security Guidelines?
- Yes. FISC sells English translations under the title FISC Security Guidelines on Computer Systems for Financial Institutions, as PDFs that can be supplied outside Japan using an overseas order form sent by email or fax. As of 1 October 2026 the latest English translation is of the 13th edition, published in November 2025 at 2,400 yen; no English translation of the 14th edition is listed yet.
Sources
- FISC Security Guidelines on Computer Systems for Financial Institutions, 14th edition (PDF): publication page (Japanese) Opens an external site (The Center for Financial Industry Information Systems (FISC))
- FISC Security Guidelines on Computer Systems for Financial Institutions, 13th edition (PDF): publication page (Japanese) Opens an external site (The Center for Financial Industry Information Systems (FISC))
- Publications catalogue (Japanese) Opens an external site (The Center for Financial Industry Information Systems (FISC))
- FISC Introduction Opens an external site (The Center for Financial Industry Information Systems (FISC))
- Points and Practices for Dialogue on IT Governance of Financial Institutions, 2nd edition (Japanese) Opens an external site (Financial Services Agency (FSA), Japan)
- Guidelines on Cybersecurity for the Financial Sector (provisional translation, 4 October 2024) Opens an external site (Financial Services Agency (FSA), Japan)
- Report of the Study Group on Post-Quantum Cryptography for Deposit-Taking Financial Institutions (Japanese, 26 November 2024) Opens an external site (Financial Services Agency (FSA), Japan)
- AI Discussion Paper, Version 1.1 (Japanese) Opens an external site (Financial Services Agency (FSA), Japan)
