Hello, this is Ryuta Hamamoto from TIMEWELL.
Whenever export control comes up, someone eventually asks the practical question: where do people actually get caught?
It is a fair question. Reading the statutes tells you what is prohibited, not where your own company is likely to trip. And there is an answer in public: Japan's Ministry of Economy, Trade and Industry publishes an annual analysis of the violations it has ruled on.
One year at a time, in separate PDFs. The index page lists only the three most recent. Nobody has stitched them together, so the trend is invisible.
So I pulled all of them and counted. The result was some distance from what I expected.
How I counted
Let me show my hand first, because a piece whose numbers have no traceable origin is worth nothing.
The source is METI's "Analysis of Violations of the Foreign Exchange and Foreign Trade Act (security export control)", annual editions1. The index page listed three years, but the PDF filenames were sequential, so I walked the numbers and recovered six editions.
| Fiscal year | Pages | Text extraction |
|---|---|---|
| FY2019 | 13 | succeeded |
| FY2020 | 11 | failed (image PDF) |
| FY2021 | 11 | succeeded |
| FY2022 | 11 | succeeded |
| FY2023 | 15 | succeeded |
| FY2024 | 15 | succeeded |
Number 7 and beyond do not exist. So: six editions retrieved, five usable. The FY2020 edition is a scan with no extractable text and is excluded. Treating it as zero would distort the trend, so I am recording the gap as a gap.
Each edition covers cases where a disposition was decided during that fiscal year. Some editions omit absolute case counts, so all comparisons here are in percentages. Extraction was scripted, and the headline figures were cross-checked by eye against each document's own summary lines.
If you want to place your own company first, our three-minute export compliance check makes the rest of this more concrete.
Customs is finding them, not you
The biggest finding first.
Violations are increasingly surfacing through customs post-clearance audits — and sharply so, within three years.

FY2021 was 20%. FY2022 rose to 36%, FY2023 to 43%, and FY2024 reached 59%. Roughly triple in three years.
In-house discovery, meaning the company found it through internal audit and self-reported, ran 38% in FY2021, 42% in FY2022, 27% in FY2023 and 30% in FY2024. Flat to slightly down.
Lay the numbers side by side and the shift is structural. FY2021 was a year when companies found more than the authorities did: self-reporting 66%, official findings 34%, about two to one. By FY2024 customs alone accounted for 59% and self-reporting had fallen to 37%. The party doing the finding moved from the company to the border.
To be careful: this does not directly mean violations increased. These are shares, and the underlying case counts are not consistently published. What can be read is the change in composition.
Even so I take this seriously, for a simple reason. Being found by customs means nobody inside the company had noticed up to that point. The export already happened. The finding comes retrospectively. In-house discovery means you found a hole in your own system; customs discovery does not.
Replace siloed classification work with AI.
METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.
The cause was not "got the classification wrong"
Next, why violations happen. This is where I was most wrong.

The FY2024 edition summarises classification-related violations at 52% and management-system-related violations at 36%. The single largest cause was "no classification performed, assumed not controlled" at 32%.
Read that carefully. It does not say the classification was wrong. It says the classification never happened. Someone assumed the item was not controlled and the goods never entered the classification process at all. Misclassification, including relying uncritically on someone else's determination, accounts for only 5%.
So the most common failure in export control is not getting a difficult judgement wrong. It is that the judgement step does not exist. I sat with that for a while, because I had assumed this was a problem of technical difficulty. In practice, a third of cases never reach the starting line.
The management-system side breaks down similarly: no rules or structure 19%, lack of awareness of the Act 9%, weak or hollowed-out control system 8%. Thirty-six percent in total, and all of it is "didn't know" or "hadn't built it" rather than a question of operational skill.
We build TRAFEED, an export control agent that supports classification against METI criteria and counterparty screening. Having seen these numbers, though, I will say plainly that whether a classification step exists matters more than how accurate the tool is. If there is no step, no amount of accuracy gets invoked. Final classification always rests with your own export control officer; before that, check whether anything routes items into classification at all.
Having a programme flips how you find out
There is one more cut that puts everything above in context: splitting by whether the company had filed an internal compliance programme.

Among companies with a filed programme, 61% of violations were found in-house and 21% by customs. Among those without, the picture inverts completely: in-house discovery falls to 17% and customs accounts for 74%.
METI's own text notes that companies with a programme reach 60% in-house discovery, "demonstrating the importance of the audit function." The ratio of self-detection differs by roughly 3.6 times.
Looking at those two charts side by side is what finally made the value of a compliance programme land for me. It is not that having a programme stops violations. Both groups violate. What differs is whether you can find it yourself.
That difference is operationally large. Self-discovery puts you on the path of voluntary reporting, root cause analysis and a commitment to prevent recurrence — the "written report" disposition that dominates the statistics. Discovery by customs means the export is complete and something you did not know is being presented to you from outside. Same violation, entirely different position.
For completeness: by destination, FY2024 was 65% Asia, 19% Europe and 14% the Americas. Not exotic transactions in distant markets, but the regions where everyday counterparties are.
The penalties are light, which is not reassuring
The disposition mix is milder than people expect.
| Fiscal year | Sanction | Warning | Report + written reprimand | Report + verbal caution | Written report |
|---|---|---|---|---|---|
| FY2019 | 0% | 0% | 1% | 22% | 63% |
| FY2021 | 5% | 5% | 11% | 9% | 73% |
| FY2022 | 0% | 0% | 2% | 14% | 84% |
| FY2023 | 0% | 3% | 3% | 15% | 79% |
| FY2024 | 0% | 0% | 5% | 26% | 69% |
Administrative sanctions such as an export ban appear in only one of the five years I could aggregate: 5% in FY2021. Most years are zero. The dominant outcome is the written report, where root cause analysis and a prevention commitment suffice, at 69–84%.
Note that FY2019 does not sum to 100%. That edition formats its table differently and I may have missed a row, so I am not drawing conclusions from it.
You might read this table as "not a big deal". I read it the other way. The penalties are light because most cases are not deliberate. Nobody set out to divert controlled goods; they simply never classified, or had no system. Hence no heavy sanction.
Which means most companies currently receiving dispositions were not trying to do anything wrong — and that is exactly why the same thing can happen to yours.
The size data supports this. In FY2024, 71% had not filed a compliance programme, 61% had capital of ¥300 million or less, and 64% had 300 or fewer employees. Firms without the headroom for a dedicated export control function make up the majority.
What to do with these numbers
Three things I think follow. This part is interpretation, so read it as such.
Check whether a classification step exists before arguing about accuracy. When the leading cause is "never classified", the first question is which transactions route into classification, not how precise the classification is. If someone internally decides an item is out of scope and skips it, that path is your biggest hole.
Keep records on the assumption of a post-clearance audit. With around 60% of discoveries coming that way, you should expect to be asked to explain retrospectively. Who decided, when, and on what basis, that this item was not controlled. Without that record, you cannot answer.
Being small is not an exemption. Over 60% of firms receiving dispositions have capital of ¥300 million or less. "We're too small to be in scope" does not survive contact with this data.
One last observation from doing the work: the fact that METI publishes this every year is itself a message. It does not name violators. It publishes causes and proportions. It is built to stop the same mistakes repeating. Which makes not reading it the expensive choice.
In summary
- The index page lists three editions, but sequential filenames yield six. The FY2020 edition is an image PDF, so five were usable
- Customs post-clearance audits accounted for 59% of discoveries in FY2024, up from 20% in FY2021 — roughly triple in three years
- In-house discovery is flat at 27–42%. The finder shifted from companies to the border
- The leading cause is "no classification performed, assumed not controlled" at 32%. Not a wrong judgement, an absent one
- Classification-related causes 52%, management-system causes 36%
- With a compliance programme: 61% in-house, 21% customs. Without: 17% in-house, 74% customs
- Destinations: Asia 65%, Europe 19%, Americas 14%
- Administrative sanctions in one of five years only. Written reports dominate at 69–84%
- FY2024 violators: 71% without a filed programme, 61% capital ≤¥300m, 64% ≤300 employees
What stayed with me is that single line: classification not performed, most common. I had assumed the difficulty of export control lived in the technical judgement. Where people actually fall is earlier. Not unable to solve the hard problem — unaware there is a problem.
If that is right, the first move is not training and not tooling. It is counting what share of your shipments passes through classification at all.
If you want to review your classification process or work out where to start building a programme, talk to us directly.
Footnotes
-
METI, "Post-shipment review of security trade control (violations of the Foreign Exchange and Foreign Trade Act)" https://www.meti.go.jp/policy/anpo/violation00.html and the annual PDFs (
gaitameho_document/ihanjireigaitamehou*.pdf). This article covers the six editions retrievable as of 27 August 2026 and aggregates the five whose text could be extracted. ↩



![[FY2024 Data] 52% of Foreign Exchange Act Violations Trace Back to Classification Errors - METI Statistics on the 5 Most Common Export Compliance Failures](/images/columns/gaitameho-violation-analysis-2024-meti-data/cover.png)
![Japan's Certificate of Non-Applicability Explained — What Foreign Suppliers Must Provide Japanese Buyers [Feb 14, 2026 Update]](/images/columns/non-applicable-certificate-guide/cover.png)

