Join our Newsletter — 33% off our NHI Course
Home Glossary Governance, Ownership & Risk Anti-Boryokudan Act
Governance, Ownership & Risk

Anti-Boryokudan Act

← Back to Glossary
By NHI Mgmt Group Updated August 27, 2026 Domain: Governance, Ownership & Risk

A Japanese law that allows prefectural public safety commissions to formally designate organised crime groups and restrict coercive demands on businesses. It supports exclusion and enforcement measures, but it does not eliminate the need for broader risk-based screening because anti-social forces exposure can exist outside formal designation.

Expanded Definition

The Anti-Boryokudan Act is a Japanese legal framework used to identify organised crime groups and restrict coercive conduct toward businesses and individuals. In security and governance discussions, it matters because formal designation is only one part of risk treatment; exposure to anti-social forces can still exist through intermediaries, informal influence, or overlapping commercial relationships.

Definitions vary by jurisdictional context, but the practical lesson is consistent: designation creates an enforcement basis, not a complete risk boundary. For NHI security and third-party governance, that means screening rules, escalation paths, and supplier due diligence should not rely solely on a named-list approach. A useful comparison point is NIST SP 800-53 Rev 5 Security and Privacy Controls, which emphasises control-based risk management rather than single-factor reliance.

The most common misapplication is treating formal designation as sufficient clearance, which occurs when organisations assume that non-listed counterparties are automatically free of coercive or criminal influence.

Examples and Use Cases

Implementing anti-social-force screening rigorously often introduces a commercial friction tradeoff, requiring organisations to weigh faster onboarding against deeper diligence and ongoing monitoring.

  • A bank screens corporate customers against designated organised crime groups, then adds manual review for beneficial owners, agents, and shell entities that may not appear on a formal list.
  • A procurement team rejects a high-risk subcontractor relationship after discovering indirect ties to a designated group, even though the direct vendor itself is not formally listed.
  • An enterprise adds contractual representations and exit clauses for distributors operating in regions where anti-social-force exposure is difficult to observe through standard sanctions-style checks.
  • A risk team uses policy-based screening aligned to NIST SP 800-53 Rev 5 Security and Privacy Controls while also consulting Ultimate Guide to NHIs to understand how hidden privilege and weak lifecycle control amplify third-party exposure.
  • A security operations team escalates suspicious payment, access, or account-creation requests that mirror coercive demand patterns, even when the requester is not formally designated.

Why It Matters in NHI Security

For NHI security, the Anti-Boryokudan Act is relevant because coercive external relationships can drive account abuse, contract pressure, and improper access requests that bypass ordinary identity controls. This becomes especially important where service accounts, API keys, or delegated automation are provisioned for partners that have not been fully vetted for indirect influence. The control lesson is similar to the one highlighted in the Ultimate Guide to NHIs: weak visibility and overly broad privileges create conditions where risk persists even after a surface-level review. NHI Mgmt Group notes that 97% of NHIs carry excessive privileges, which makes any external pressure on account holders or vendors materially more dangerous.

That is why governance teams should pair legal designation checks with identity lifecycle controls, segmentation, and exception handling. Formal lists help with exclusion, but they do not substitute for continuous monitoring of access paths, delegated authority, and third-party behaviour. Organisations typically encounter the operational impact only after a suspicious vendor request, access incident, or fraud investigation, at which point the Anti-Boryokudan Act context becomes unavoidable to address.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV.SC-1Supply-chain risk treatment includes external party screening and oversight.
OWASP Non-Human Identity Top 10NHI-01Overprivileged non-human access magnifies external coercion and abuse risk.
NIST Zero Trust (SP 800-207)SC.AAZero trust requires continuous verification of identity, context, and access intent.
NIST SP 800-63IAL2Identity proofing strength informs how much confidence to place in external parties.

Screen counterparties continuously and escalate indirect influence risks before granting access.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org