EST · MMXXVI
Home/Jurisdictions/Turkey/Client funds safeguarding in Turkey: Legal Requirements for Businesses
Banking, Payments & EMI Onboarding

Client funds safeguarding in Turkey: Legal Requirements for Businesses

Client funds safeguarding in Turkey. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Operating a digital-asset or payments business in Turkey without correctly structured client-money arrangements exposes the enterprise to enforcement action, frozen correspondent rails and the loss of banking relationships that are already difficult to secure. Turkey's regulatory environment for payment services, electronic money and crypto-asset custody has tightened materially, and the Bankacılık Düzenleme ve Denetleme Kurumu (BDDK, the Banking Regulation and Supervision Agency) and the Sermaye Piyasası Kurulu (SPK, Capital Markets Board of Turkey) now each assert jurisdiction over distinct parts of a digital-asset business's client-fund obligations. Getting the structure right before you onboard clients – not after the first regulatory inquiry – is the defining operational question for any inbound operator.

This page maps the legal basis for client-funds safeguarding in Turkey, the licence categories that trigger the obligation, the cross-border interaction with EMI onboarding (the process of accessing electronic money institution rails) and fiat rails (the bank and payment network channels that connect a crypto business to the conventional financial system), and the decision points that a foreign business must resolve before committing capital to the Turkish market.

What is the regulated perimeter for client funds in Turkey?

Client-funds safeguarding in Turkey turns on two parallel regimes: the payment and electronic money framework administered by the BDDK, and the crypto-asset custody and trading rules administered by the SPK under Turkey's dedicated crypto-asset legislation. A business touching client money on either side of the fiat-crypto interface will typically engage both regulators. The BDDK governs the receipt, holding and transmission of fiat funds by payment service providers and electronic money institutions. The SPK governs the custody of crypto assets and the operational requirements that crypto-asset service providers (CASPs) must meet when holding client positions. Neither licence substitutes for the other. An operator that receives Turkish lira from clients and simultaneously holds crypto on their behalf sits squarely within both regimes.

The critical structural point is that safeguarding under the BDDK regime requires segregation: client funds must be held in designated accounts, separated from the institution's own operational funds, and the BDDK prescribes the eligible institutions and instruments into which safeguarded funds may be placed. Under the SPK's crypto-asset framework, CASPs face analogous requirements for the custody layer – client crypto-asset holdings must be identifiable, segregated and recoverable on an individual basis. These are not optional compliance best practices. They are licence conditions, and breach of either triggers supervisory action.

The BDDK and the SPK each publish rulebooks that an authorised firm must embed into its operational and contractual architecture from day one.

For a scoped assessment of your entity's obligations under both regimes, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity type, the user base, whether you hold fiat and crypto simultaneously – change the analysis materially. Map your options

Who needs a Turkish payment or crypto-asset licence to hold client funds?

Any business that receives, holds or transmits fiat funds from Turkish resident clients in the course of providing payment services requires a BDDK authorisation or must operate under a passporting arrangement where one is legally recognised – and Turkey does not operate an EU-style MiCA passporting model. The obligation is triggered by the activity, not the entity's country of incorporation. A foreign payment institution serving Turkish clients through a website without a local presence or authorisation is operating in breach of Turkish payment services law. The BDDK has demonstrated a willingness to take enforcement action against unlicensed operators, including referrals to prosecutors.

On the crypto side, the SPK's framework requires any entity that provides crypto-asset custody, trading platform, transfer or portfolio management services in Turkey – or to Turkish residents – to hold the relevant CASP authorisation. The SPK has published a list of activities that constitute regulated crypto-asset services, and the language tracks the activity-based approach used in VARA's Dubai rulebooks and in MiCA's CASP categories, even though Turkey operates its own standalone regime rather than adopting either of those frameworks directly.

There is a specific pinch point for businesses structured offshore. A common assumption among inbound operators is that a single offshore licence – a BVI FSC registration, a Cayman VASP Act filing or an EU MiCA CASP passport – is sufficient to serve Turkish clients. It is not. Turkey does not recognise those licences as a substitute for domestic authorisation. The practical consequence is that an offshore-licensed CASP that onboards Turkish-resident clients without a local Turkish authorisation, or without a compliant partnership with a locally authorised institution, is exposed to SPK enforcement and to the loss of any Turkish banking relationships it has established.

How does the licence application process work in Turkey?

The BDDK and SPK each run their own authorisation processes, and an operator that needs both must manage them in parallel rather than sequentially. The BDDK's payment institution or electronic money institution authorisation requires a locally incorporated entity (a Turkish joint-stock company, anonim şirket), a fit-and-proper assessment of shareholders and management, a detailed business plan, an IT systems assessment and evidence of the required minimum capital. Timelines vary by application quality and completeness; in our practice we consistently advise clients to treat the process as one measured in months rather than weeks, and to engage with pre-application meetings with BDDK staff before formal filing.

The SPK's CASP authorisation process follows a similar architecture. The SPK evaluates the applicant's governance, its custody infrastructure, its AML/CFT programme and its capital position. A key differentiator in the SPK process is the technical assessment of the custody solution: the SPK requires evidence that client crypto-asset holdings are held in a manner that ensures recoverability in the event of the firm's insolvency. Cold-storage arrangements, key management protocols and the use of qualified custodians are all scrutinised. Applicants that have not designed their custody architecture before filing face significant rework.

For businesses that hold both fiat and crypto, the sequencing question matters. In our cross-border practice, we advise starting with the BDDK process if fiat receipts are operationally critical – because access to Turkish banking typically requires BDDK authorisation, and banking access is the rate-limiting factor for the whole stack. The SPK process can run concurrently once the BDDK application is filed and the corporate vehicle is in place.

What do Turkey's AML and Travel Rule obligations add to safeguarding requirements?

Turkey's AML/CFT framework – built around the Financial Crimes Investigation Board (MASAK) – applies to both payment institutions and CASPs. MASAK supervision adds a second compliance layer on top of the BDDK and SPK licence conditions. Customer due diligence, beneficial ownership verification, transaction monitoring, suspicious activity reporting and record-keeping obligations all apply from the moment a client account is opened. These obligations are not merely administrative; they are the mechanism by which Turkish supervisors assess whether a firm's client-fund architecture is operationally sound, because a deficient CDD programme typically signals deficient fund-flow controls.

Turkey has implemented the Travel Rule (the obligation to pass originator and beneficiary data with a crypto-asset transfer) under MASAK's supervision, aligning with the FATF Recommendation 15 standard for virtual asset service providers. For an operator running a cross-border CASP, this means that transfers to and from Turkish-domiciled counterparty VASPs must carry the required data fields. In practice, the Travel Rule creates a pre-onboarding due-diligence obligation: before a Turkish CASP connects to a foreign VASP for settlement purposes, it must assess that counterparty's compliance posture. Regulators in the leading hubs increasingly expect CASPs to document those assessments as part of their own AML programme.

MASAK maintains an active enforcement posture, and the penalties for AML deficiencies at a licenced CASP are material – running parallel to the SPK's own supervisory sanctions.

How does cross-border EMI onboarding and fiat rails access work for Turkey-based operators?

For a digital-asset business licensed in Turkey, the fiat rail question is operationally critical. Turkish licensed payment institutions and CASPs must maintain Turkish lira settlement accounts at Turkish deposit banks. The correspondent banking environment for crypto-related businesses in Turkey is selective: several of the larger state-linked banks have taken a cautious stance toward crypto-adjacent clients, while some mid-tier private banks have developed more structured onboarding frameworks for BDDK-licensed payment institutions that have clean AML records.

The cross-border dimension is equally important. Many Turkey-based operators need to settle in USD or EUR as well as TRY. That typically requires a relationship with a European or offshore EMI that can hold multi-currency accounts and connect to SEPA or SWIFT. EMI onboarding for a Turkish CASP or payment institution requires the EMI to conduct its own enhanced due diligence: the Turkish entity's licence status, its AML programme and its beneficial ownership structure will all be reviewed. In our practice, operators that present a complete compliance pack – licence certificate, AML policy, audited financials and a clean MASAK record – onboard materially faster than those that treat the EMI process as a secondary task.

A business sitting between the Turkish market and a European EMI must also manage the foreign-exchange dimension. Turkey maintains capital controls and FX regulations administered by the Central Bank of the Republic of Turkey (TCMB). Cross-border fund movements are subject to TCMB reporting requirements, and certain restrictions on the holding of foreign currencies by Turkish residents affect the product design of any crypto offering that involves USD or EUR-denominated stable-value instruments. These are product-level decisions that must be made before client onboarding begins, not resolved retroactively.

To map the licence, banking and compliance stack for your Turkey build, write to OBOLUS at info@oboluslaw.com. If a prior application stalled or a banking relationship was closed, a second read can surface the structural reason and the route back. Map your options

A cross-border safeguarding matter: what the failure point looked like

In a recent engagement, a payments company licensed in an EU member state sought to extend its services to Turkish-resident clients through a Turkish subsidiary. The subsidiary had been incorporated and had opened a local bank account, but the BDDK authorisation process had not been initiated – the operator assumed that its EU MiCA-era CASP authorisation would provide a transitional basis for Turkish operations. It did not. When the Turkish bank identified that the subsidiary was receiving client funds without a BDDK payment institution licence, it froze the account pending clarification and filed a MASAK report. We were engaged to assess the structural deficiency, prepare the remediation response to the BDDK and design the dual-authorisation pathway that the operator should have built before entering the market. The account freeze was resolved, the authorisation process was restarted on a corrected basis and the operator's EU compliance infrastructure was adapted to meet MASAK's parallel requirements. The cost of the remediation – in time, management distraction and legal fees – substantially exceeded what a pre-entry scoping exercise would have required.

How do tax and banking interact with client-funds safeguarding in Turkey?

Tax treatment of crypto assets in Turkey sits under the SPK framework and the Turkish Revenue Administration (GİB). The GİB has issued guidance treating gains from crypto-asset transactions as taxable income for Turkish resident individuals and entities, though the precise characterisation – capital gain, commercial income or other – continues to evolve as the regulatory regime matures. For an operator, this creates a client disclosure and withholding analysis that must be embedded in the product terms before launch. A CASP that holds client assets and facilitates disposals without addressing the tax reporting dimension faces both a supervisory risk (the SPK expects client-facing disclosures to be accurate) and a client-relationship risk.

Banking interaction with the tax layer is direct. Turkish banks are required to report certain cross-border transfers to the GİB and to MASAK, and the TCMB's FX reporting obligations create a parallel data trail. A well-structured safeguarding model – segregated client accounts, transaction-by-transaction records, clean AML tagging – also produces the data that tax reporting requires. Operators that treat compliance as a modular exercise, building the AML programme separately from the account structure and the tax reporting model, consistently find that the three layers are misaligned when examined in detail.

Which operator profile should choose which licence route in Turkey?

The right entry path depends on the business model, the client base and the asset types involved. For a payments-focused business that handles fiat but does not custody crypto, the BDDK payment institution or EMI authorisation is the primary licence, and the banking relationship is the rate-limiting factor. The timeline for authorisation varies by application quality; operators with a complete compliance architecture and an experienced local management team proceed faster than those building the infrastructure after filing. The key risk for this profile is underestimating the capital requirement and the IT systems assessment burden.

For a CASP that holds crypto, executes trades or manages portfolios for Turkish clients, the SPK authorisation is the primary licence. The BDDK layer becomes necessary if the CASP also receives fiat. The key risk for this profile is the custody architecture: the SPK's technical review of key management and cold-storage procedures is more detailed than many operators have encountered in other jurisdictions, and the documentation burden is substantial. Businesses that have previously operated under FINMA guidance or MAS Payment Services Act rules are generally better prepared than those coming from lighter-touch regimes.

For a foreign operator seeking market access without a full local licence, a partnership with a locally authorised Turkish CASP or payment institution is the alternative route. This model reduces the capital and operational commitment but shifts compliance risk onto the partner and requires a carefully structured outsourcing agreement that satisfies both the BDDK and the SPK on the delegation of safeguarding obligations. In our cross-border practice, we have seen partnership structures fail at the banking level when the Turkish partner's own banking relationships deteriorate – which means the foreign operator inherits the banking problem without having the licence-holder's tools to address it.

A common assumption: why one offshore licence is not enough

A common assumption among digital-asset operators planning Turkish market entry is that a well-regarded offshore licence – a BVI VASP registration, a Cayman CIMA filing, or an EU MiCA CASP authorisation – creates a legally defensible basis for serving Turkish clients without further local authorisation. This assumption is incorrect, and the consequences of acting on it are material. Turkey's SPK and BDDK each assert extraterritorial reach over services provided to Turkish-resident clients, regardless of where the provider is incorporated or licensed. The analysis turns on the location of the client, not the location of the server or the licence. Operators we advise who have entered the Turkish market on this basis consistently face the same sequence: an initial period of operation, followed by a MASAK query, followed by account closure by the Turkish banking partner, followed by an SPK inquiry. The remediation path is longer and more expensive than the preventive path. Building the right structure before market entry is not optional – it is the business case for the engagement.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily because of unresolved AML/CFT risk concerns, unclear beneficial ownership, the absence of a local operating licence or a mismatch between the declared business activity and the observed transaction patterns. In Turkey, MASAK's reporting obligations create a direct link between account behaviour and supervisory attention. A crypto business that cannot demonstrate a clean compliance programme, segregated client funds and a clear regulatory status will find its banking relationships unstable regardless of the jurisdiction where it is incorporated. The solution is structural: the licence, the AML programme and the account architecture must be aligned before account opening, not patched after closure.

How can a VASP onboard with an EMI?

A VASP (virtual asset service provider) seeking to onboard with an EMI must present its regulatory status, AML/CFT programme, beneficial ownership disclosure and audited financials at a standard that satisfies the EMI's enhanced due diligence requirements for high-risk financial services clients. European EMIs operating under MiCA-adjacent frameworks assess Turkish VASPs as third-country entities and apply their own risk-based due diligence. VASPs that have a BDDK or SPK authorisation, a clean MASAK record and a documented Travel Rule compliance programme onboard materially faster. An EMI relationship is not a substitute for the local Turkish licence – it is the fiat rail that the licensed entity uses to serve clients.

What does client-money safeguarding require?

Client-money safeguarding requires that funds received from clients are held separately from the firm's own capital, in eligible institutions and instruments specified by the relevant regulator. In Turkey, the BDDK sets these requirements for payment institutions and EMIs; the SPK sets parallel requirements for crypto-asset custody. Safeguarding means the funds are identifiable, recoverable and insulated from the firm's insolvency. It is a licence condition, not a voluntary practice. A safeguarding failure – commingling of client and operational funds, holding client money in ineligible accounts or failing to maintain individual client balances – constitutes a material regulatory breach under both the BDDK and SPK regimes.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses – not individuals. Operators we advise routinely face multi-layered licence stacks across operating, custody and payment layers; we map that full stack before commitment. To discuss your Turkey entry or an existing compliance problem, contact info@oboluslaw.com or reach us at t.me/oboluslaw.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in VASP authorisation frameworks, cross-border payment licence strategy and the intersection of AML supervision with client-funds architecture across emerging and developed digital-asset markets.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours