EST · MMXXVI
Home/Jurisdictions/Turkey/AML/cft policy drafting in Turkey: Legal Requirements for Businesses
Compliance, AML & Travel Rule

AML/cft policy drafting in Turkey: Legal Requirements for Businesses

Aml/cft policy drafting in Turkey. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

A digital-asset business operating in Turkey – or routing transactions through Turkish counterparties – faces a specific and increasingly enforced AML/CFT compliance obligation. Turkey maintains a dedicated MASAK (Financial Crimes Investigation Board) regime that applies to crypto asset service providers (CASPs), an obligation set that sits alongside the global FATF framework and that regulators have been actively tightening since Turkey's 2021 CASP registration rules took effect. Getting the policy wrong does not merely produce a technical deficiency: it risks enforcement action, correspondent-bank derisking and, in severe cases, closure of the business. This page maps the legal basis, the drafting requirements and the cross-border considerations that any business serving Turkish users or structured through a Turkish entity must address.

Turkey's AML/CFT Regime for Crypto Asset Businesses

Turkey's primary AML/CFT obligations for digital-asset businesses flow from two converging sources: the MASAK framework (the national Financial Crimes Investigation Board, operating under the Ministry of Treasury and Finance) and Turkey's formal compliance with FATF Recommendation 15, which extends the standard AML/CFT rulebook to virtual asset service providers. The country was added to the FATF grey list in 2021 and subsequently undertook a structured package of legislative reforms as a condition of exit – reforms that directly elevated the compliance bar for CASPs. Turkey was removed from the grey list in June 2024, but the upgraded legislative infrastructure remains fully in force.

Under the applicable regime, CASPs must register with the Capital Markets Board of Turkey (SPK), which became the designated supervisory authority for crypto asset platforms following the 2024 amendments to the Capital Markets Law. MASAK retains jurisdiction over AML/CFT supervision. In practice, a CASP operating in Turkey is therefore subject to a dual supervisory structure: SPK for market conduct and registration, MASAK for financial-crime compliance. A policy document that satisfies one without the other is incomplete.

The applicable FATF Travel Rule – the obligation to pass originator and beneficiary data with a virtual asset transfer – applies to Turkish CASPs on the same conceptual basis as it does in FATF member states globally. The specific de-minimis threshold and data-field requirements are set in MASAK secondary legislation and should be confirmed against the current version before any policy is finalized.

Operating without a compliant AML/CFT program exposes the business to administrative penalties under MASAK, potential suspension of the SPK registration, and – critically – the loss of banking relationships. Turkish and correspondent banks are themselves under strong MASAK scrutiny and will exit CASP relationships that lack demonstrably robust AML documentation.

For a scoped assessment of your Turkey compliance position, contact OBOLUS at info@oboluslaw.com. The process above describes the standard structure. Your entity form, user base and banking arrangements change the analysis materially.

What Must an AML/CFT Policy for a Turkish CASP Contain?

A compliant AML/CFT policy for a CASP under the Turkish regime is not a generic compliance template – it must reflect the specific risk profile of the business, the product set and the jurisdictions served. MASAK guidance and the applicable FATF methodology share a common architecture, and a Turkish CASP policy must address each of the following layers.

Risk Assessment

The policy must begin with a documented business-wide risk assessment. This covers customer risk (retail versus institutional, geographic origin, politically exposed persons), product risk (spot trading, staking, custody, OTC desks) and channel risk (self-hosted wallets, third-party exchanges, payment rails). Assessments are expected to be living documents, updated when the product set or customer base changes materially.

Customer Due Diligence and Enhanced Due Diligence

A KYC framework (know-your-customer program) must specify the onboarding process, the identity verification method, and the conditions triggering enhanced due diligence. Under the Turkish regime, enhanced due diligence is mandatory for high-risk customers, for transactions above defined thresholds, and for any customer connected to a higher-risk jurisdiction as designated by MASAK or by Turkey's own country-risk lists. Beneficial ownership verification for corporate customers is a specific MASAK requirement.

Transaction Monitoring

Transaction monitoring must be addressed at the procedural level in the policy: the rules and scenarios used to detect suspicious activity, the escalation path from an automated alert to a human review, and the timeline for filing a suspicious transaction report (STR) with MASAK. The policy must also describe the systems or tools used, without requiring them to be named at the policy level – the key is demonstrating that the monitoring is calibrated to the risk profile of the business.

Travel Rule Compliance

The policy must explain how the business collects, transmits and receives originator and beneficiary data for transfers meeting the applicable threshold. Where the counterparty VASP is unregistered or in a jurisdiction with no Travel Rule framework, the policy must specify what enhanced scrutiny applies. In our cross-border practice, we regularly advise that the Travel Rule section is the element MASAK examiners focus on most closely in audits of crypto businesses – it is the area where the gap between policy documentation and operational reality is most often exposed.

MLRO Appointment and Governance

A Money Laundering Reporting Officer (MLRO) must be designated with documented authority to file STRs with MASAK, to escalate to senior management, and to oversee the compliance program. The policy must specify the MLRO's reporting line, their independence from commercial functions, and the escalation protocol if the MLRO is unavailable.

Record-Keeping and Staff Training

Records of customer identification, transaction data and STRs must be retained for the period required under MASAK rules. The policy must describe the training program for staff who interact with customers or handle compliance alerts, including induction training and periodic refreshers.

How Does the AML/CFT Policy Drafting and Registration Process Work in Turkey?

The drafting process for a Turkish CASP has a defined sequence, and the sequencing matters because MASAK will not treat a policy as compliant if it pre-dates the risk assessment that is supposed to underpin it.

The practical steps run as follows. First, the business completes a formal risk assessment covering the dimensions described above. Second, counsel drafts the core policy document, mapping each MASAK obligation to a specific internal control. Third, the ancillary documents – KYC procedures, STR escalation protocol, Travel Rule data-sharing protocol, training records – are built to fit the policy framework. Fourth, the MLRO is formally appointed and the appointment is documented in internal governance records. Fifth, the full package is submitted as part of, or alongside, the SPK registration application.

The SPK registration process itself involves an application to the Capital Markets Board, submission of the compliance documentation, and a review period whose length varies depending on application volume and the completeness of the submission. Incomplete applications – and a common deficiency is an AML policy that lacks a supporting risk assessment – extend the process materially. We advise clients to treat the policy package as a standalone deliverable, not an afterthought to the registration form.

A micro-matter illustrates the practical stakes. In a recent licensing matter, a payments-oriented CASP had built its AML policy around a template designed for an EU jurisdiction. The document referenced frameworks that do not apply in Turkey and omitted the MASAK-specific STR-filing mechanics entirely. We identified the gap during a pre-submission review, rebuilt the risk assessment from the Turkish VASP-category risk criteria, and rewrote the Travel Rule section to reflect the MASAK data-field requirements. The submission proceeded without the delay the original document would have caused.

If a prior application stalled or an account was closed, contact OBOLUS at info@oboluslaw.com. A second read of the compliance documentation often surfaces the structural reason and the route back. Map your options.

How Does Turkish AML/CFT Compliance Interact with Cross-Border Operations?

For most digital-asset businesses, Turkey is not an isolated jurisdiction – it sits within a cross-border structure that may involve EU entities, offshore holding companies or banking relationships in multiple countries. Each layer creates a compliance interaction point that the Turkish policy must address.

Where a Turkish CASP is part of a group structure with an EU entity operating under MiCA (the Markets in Crypto-Assets Regulation supervised by ESMA and national competent authorities), the group-level AML policy and the Turkish local policy must be reconciled. The Travel Rule data-field requirements under MiCA and under MASAK are similar in principle but may differ in their de-minimis thresholds and in their treatment of unhosted wallets. A group policy that does not acknowledge the Turkish addendum will fail a MASAK examination.

Banking is the most acute cross-border pressure point. Turkish correspondent banks and international banks with Turkish CASP relationships apply their own AML standards, which are typically at least as demanding as MASAK's. A CASP that holds a technically compliant MASAK policy but cannot demonstrate it in English to a compliance officer in Frankfurt or Singapore will still lose the account. In our practice, we routinely prepare a dual-language summary of the AML/CFT framework – a document that is not a regulatory requirement but is operationally essential for maintaining banking rails.

The Travel Rule creates a specific interaction challenge for businesses that also operate in jurisdictions where Travel Rule infrastructure is immature. If a Turkish CASP sends a transfer to a VASP in a jurisdiction without a compliant Travel Rule framework, the policy must specify the enhanced scrutiny that applies – MASAK expects this to be explicit, not implicit. Operators we advise routinely underestimate the due-diligence burden on the receiving side of a Travel Rule interaction; the policy must address both directions.

Tax and banking are structurally linked to the compliance posture. A CASP that has implemented a strong KYC framework in Turkey will find that its customer identification data supports the reporting obligations under Turkey's CRS (Common Reporting Standard) implementation. Conversely, a business that attempts to minimize its KYC burden for commercial reasons will create a CRS reporting gap that generates separate regulatory exposure. Regulators in the leading hubs increasingly expect AML and tax-transparency obligations to be addressed in a unified compliance architecture, not in separate silos.

A Common Assumption That Gets CASPs Into Trouble

A common assumption among businesses expanding into Turkey is that an existing offshore VASP registration – in the BVI, Cayman Islands or a similar jurisdiction – satisfies the Turkish compliance obligation for customers served from or through Turkey. It does not. Turkey's CASP registration and MASAK AML/CFT requirements apply on a functional basis: if the business is operating in Turkey, serving Turkish users or using Turkish banking rails, the Turkish regime applies regardless of where the entity is formally registered.

The BVI FSC regime and the Cayman CIMA VASP framework each produce a valid registration in their own jurisdiction. They do not produce a Turkish compliance certificate, and MASAK does not treat them as equivalent. An operator relying on a single offshore registration to cover a Turkish user base is exposed to enforcement action from SPK, deregistration risk and – because Turkish banks conduct their own regulatory checks – the loss of banking access.

A related misconception is that a GDPR-compliant EU privacy policy substitutes for a MASAK-specific data-handling clause. It does not. The data retention and sharing rules under the Turkish Personal Data Protection Law (KVKK) operate separately from GDPR. A CASP policy that addresses only GDPR will have a gap in its Turkish compliance documentation.

Regulators in this space are increasingly sophisticated about spotting regulatory arbitrage – the practice of using a friendly offshore registration to avoid a more demanding onshore regime. The correct approach is to map the actual jurisdictions in which the business operates – by entity, by user base, by banking – and to build a compliance layer for each.

Self-Assessment: Is Your Turkish AML/CFT Policy Fit for Purpose?

The following questions allow a CASP or its in-house counsel to conduct a preliminary assessment of whether the existing policy will withstand MASAK scrutiny.

  • Does the policy begin with a documented risk assessment that reflects the actual Turkish product set and customer profile – not a generic template?
  • Does the KYC section specify the identity verification method, the beneficial-ownership verification process and the conditions triggering enhanced due diligence under MASAK's own risk criteria?
  • Does the transaction-monitoring section describe the escalation path to an STR filing with MASAK, including the responsible officer and the timeline?
  • Does the Travel Rule section address both the data-transmission obligation (outgoing transfers) and the enhanced-scrutiny obligation for transfers received from non-compliant jurisdictions?
  • Has an MLRO been formally appointed with documented authority and a clear reporting line?
  • Does the record-keeping section specify the retention period in terms that match the MASAK-prescribed minimum?
  • Is there a training log that documents induction training and periodic refreshers for all relevant staff?
  • For group structures: has the Turkish policy been reconciled with the group AML policy, with discrepancies documented and explained?

A "no" answer to any of the above items identifies a gap that a MASAK examiner is likely to identify. In our practice, the most common deficiencies are in the Travel Rule section and in the risk-assessment foundation – the two areas where generic templates most frequently fall short.

Which Compliance Architecture Fits Your Business Profile?

The correct AML/CFT program structure depends on the business model, the user base and the group structure. Three common profiles illustrate the decision points.

Profile A – Turkish-licensed CASP, domestic focus. The business is registered with SPK, serves Turkish retail and institutional users, and banks in Turkey. The AML/CFT policy is a standalone Turkish document. The primary obligation is MASAK compliance, with Travel Rule obligations calibrated to the Turkish de-minimis threshold. The MLRO is a Turkey-resident individual. Timeline for a new policy from scratch – assuming the risk assessment is commissioned simultaneously – is typically a matter of weeks, not months, provided the business provides accurate input data.

Profile B – EU-licensed CASP (MiCA CASP authorisation) serving Turkish users as part of a broader EU/non-EU user base. The business holds a MiCA authorisation from a national competent authority and passports across the EU. It also serves Turkish users from the same platform. It needs both the EU-compliant AML policy and a Turkish law addendum. The addendum must address the MASAK STR-filing obligation, the Turkish Travel Rule specifics and the KVKK data-handling requirements. The MLRO for the EU entity may or may not satisfy the Turkish requirement – this turns on whether the business has a Turkish establishment, which requires separate legal analysis.

Profile C – Offshore-holding-company structure (BVI or Cayman) with a Turkish operational presence. This is the highest-risk profile from a compliance-architecture standpoint. The offshore entity holds the assets; the Turkish entity provides operational services. MASAK will look through the structure and apply its obligations to the Turkish operational entity. The AML/CFT policy must document the relationship between the entities, clarify which entity files STRs, and ensure the KYC data is accessible to the Turkish-side MLRO. Allied counsel in the relevant jurisdiction can address the offshore entity's own compliance obligations in parallel.

FAQ

What does the Travel Rule require from a VASP?

The Travel Rule requires a VASP to collect, verify and transmit originator and beneficiary data alongside a virtual asset transfer above the applicable threshold. This means the sending VASP must pass the originator's name, account identifier and – depending on the jurisdiction – additional identification data to the receiving VASP before or simultaneously with the transfer. The receiving VASP must verify and retain the data. Under MASAK, Turkish CASPs must comply with this obligation on both sides of a transfer, and the policy must address what happens when the counterparty VASP is not compliant.

Who must act as MLRO for a crypto firm?

A Money Laundering Reporting Officer (MLRO) is the individual formally designated to receive internal suspicious-activity reports, to decide whether to file with MASAK, and to oversee the AML/CFT program. Under the Turkish regime, the MLRO must be a sufficiently senior individual with documented independence from the commercial side of the business. For Turkish-licensed CASPs, the role is typically filled by a compliance officer who is resident and accessible to MASAK. The appointment must be documented in governance records and notified to the relevant authority as required by the applicable provisions.

How do regulators audit crypto AML programs?

MASAK and the SPK conduct audits of CASP AML programs through a combination of document reviews, on-site inspections and transaction-level sampling. Examiners will typically request the risk assessment, the policy document, a sample of KYC files, a log of STR filings, and evidence of Travel Rule data transmission. A policy that exists as a document but cannot be evidenced in the transaction records or KYC files will fail. Regulators in the leading hubs increasingly focus on the gap between written policy and operational practice – the test is not what the document says but what the business actually does.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when enforcement becomes necessary. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in AML/CFT program design and VASP regulatory compliance across FATF-aligned jurisdictions, with a focus on inbound-operator structures in the MENA and European markets.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours