What correspondent banking means for crypto businesses in Turkey
Correspondent banking access – the arrangement by which a domestic or foreign bank extends account services, payment-processing capacity and fiat-rail connectivity to a business operating in digital assets – is one of the hardest operational problems a crypto firm entering Turkey will face. The Turkish banking sector is supervised by the Banking Regulation and Supervision Agency (BDDK), and the country's crypto law (the amendments to the Capital Markets Law, administered by the Capital Markets Board, CMB/SPK) imposes a licensing and compliance layer that directly affects whether a Turkish bank will accept a digital-asset counterparty at all. Turkey's Financial Crimes Investigation Board (MASAK) runs the AML/CFT regime, and its posture on virtual-asset service providers shapes every banking conversation in the market.
For an inbound operator, the answer is blunt: without a demonstrable regulatory basis in Turkey – or a compliant cross-border structure that satisfies a Turkish bank's risk team – correspondent banking access will be refused, delayed or withdrawn. This page sets out the legal requirements, the inbound process, the cross-border interaction with tax and the decision points that determine which structure survives due diligence.
The regulatory foundation: CMB, BDDK and MASAK
Three regulators define the operating environment for any business seeking fiat-rail access in Turkey. The CMB (Capital Markets Board / SPK) is the primary licensing authority for crypto-asset service providers under the Turkish crypto regime, which brought VASP-type activities under a formal authorisation requirement. The BDDK supervises banks and sets the know-your-customer and risk-appetite expectations that banks apply to their prospective clients. MASAK transposes FATF Recommendation 15 into Turkish domestic AML/CFT obligations, including Travel Rule equivalents (the obligation to pass originator and beneficiary data with a transfer) for covered transactions.
A business that cannot demonstrate CMB authorisation – or a credible path toward it – will typically fail at the first stage of a Turkish bank's onboarding review. Banks have experienced regulatory pressure over correspondent relationships with unregistered crypto counterparties, which has made their compliance teams acutely sensitive to documentation gaps. The MASAK-driven AML framework requires that the bank itself satisfy its own obligations when onboarding a virtual-asset service provider, so the crypto firm's regulatory standing becomes a direct input into the bank's own compliance calculus.
In our cross-border practice, we regularly advise operators who assume that a European CASP authorisation (under MiCA, the EU Markets in Crypto-Assets Regulation) or a Payment Services Act licence from Singapore's MAS will open Turkish banking automatically. It does not. Turkish banks conduct an independent assessment of local-law compliance and local AML posture, separate from whatever foreign licence is presented.
For a scoped review of your regulatory standing and its banking implications in Turkey, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the transaction profile – change the analysis materially.
Who needs correspondent banking access in Turkey?
Any business that collects or pays fiat currency in connection with a digital-asset activity touching Turkish residents or the Turkish market requires a fiat-rail relationship with a Turkish or Turkey-facing financial institution. That category is broader than it appears.
It covers exchanges that allow Turkish lira deposits or withdrawals, custodians holding assets for Turkish institutional clients, over-the-counter desks settling in lira, and payment processors routing stablecoin-to-fiat conversions for Turkish merchants. It also captures foreign businesses that operate cross-border: a Maltese VASP (virtual asset service provider) whose primary user base is Turkish nationals cannot treat Turkey as a purely offshore market if its transaction flows route through Turkish bank accounts or if it solicits Turkish residents directly.
The Turkish regime – unlike some lighter-touch regimes – ties licensing obligations to the nexus between the activity and Turkish users or Turkish market access, not only to where the entity is incorporated. This means that the threshold question is not "are we a Turkish company" but "are we providing services to the Turkish market." Banks apply the same logic when assessing counterparty risk.
What does the inbound business process look like?
The path to a functioning correspondent banking relationship in Turkey runs through four sequential stages, each of which generates documentation that the bank will scrutinize.
Stage one: regulatory classification. The first step is determining whether the activity requires CMB authorisation in Turkey or whether a cross-border licensing structure – a foreign-licensed entity with a defined set of Turkish-facing activities – satisfies the applicable provisions. Classification determines whether the entity is a direct applicant to the CMB or whether it can operate via a correspondent or agent arrangement.
Stage two: AML/KYC infrastructure build. MASAK's requirements for virtual-asset service providers include customer due diligence, transaction monitoring, and Travel Rule compliance for qualifying transfers. Before a Turkish bank will open accounts, it will require evidence that this infrastructure is in place and tested – not planned. A compliance manual is not sufficient; the bank wants to see policies, procedures, system architecture and, where the business is of any scale, an independent AML audit or review.
Stage three: bank selection and pre-application outreach. Not all Turkish banks accept crypto business. The BDDK-supervised sector has seen exits and tightened risk appetite. Identifying which institutions are currently open to digital-asset counterparties, and at what tier of activity, requires current market intelligence. We have seen firms waste months pursuing institutions that had quietly closed their crypto onboarding queues, while ignoring smaller licensed institutions that remained open.
Stage four: formal onboarding and correspondent documentation. The bank's compliance team will typically request the CMB licence or registration document, MASAK registration evidence, the AML/KYC policy suite, the business plan with projected transaction volumes and currencies, ultimate beneficial ownership documentation, and – for foreign-incorporated entities – evidence of the foreign licence and a legal opinion on cross-border compliance. Timelines from formal submission to account opening vary considerably; straightforward structures with complete documentation move faster than complex cross-border arrangements.
How does a foreign licence interact with Turkish banking requirements?
A foreign licence is a supporting document, not a substitute for Turkish regulatory engagement. Banks in Turkey will accept evidence of a MiCA CASP authorisation, an FCA (UK Financial Conduct Authority) registration or a VARA (Virtual Assets Regulatory Authority, Dubai) licence as evidence of institutional credibility – but only in the context of a complete Turkish compliance build. The bank still needs to satisfy itself that the counterparty complies with Turkish AML law and that the CMB position is clear.
The practical consequence is that a dual-layer structure is almost always necessary for a business with material Turkey exposure. The foreign-licensed entity provides the credibility signal; a Turkish entity or a Turkish compliance overlay provides the local regulatory hook. The two layers must be documented consistently – inconsistencies between the foreign corporate structure and the Turkish-facing regulatory disclosures are a common reason applications stall.
Under MiCA's passporting mechanism, a CASP authorized in an EU member state may passport across the EU/EEA. Turkey is not an EU member state, so MiCA passporting provides no direct benefit for Turkish market access. Operators building an EU-plus-Turkey strategy must treat the two legs as separate regulatory projects with separate banking arrangements.
In a recent matter, a payments business incorporated in an EU jurisdiction had operated a Turkish-facing service for over a year under its EU authorisation alone. When its primary Turkish banking relationship was terminated following a MASAK audit of the bank's crypto counterparties, it had no fallback. We worked with allied counsel in Turkey to structure a compliant local entity, prepared the CMB classification filing, and rebuilt the AML documentation to MASAK standards. The business resumed fiat-rail operations within a matter of months, though the period of enforced closure had cost it materially in client attrition.
What EMI and payment licence options complement Turkish banking access?
An EMI (electronic money institution) licence or a payment institution licence – held in a jurisdiction with a strong correspondent-banking ecosystem – can supplement rather than replace Turkish banking access for operators with cross-border fiat flows. The logic is structural: if the Turkish lira leg of a transaction is handled through a CMB-compliant Turkish entity, the euro or dollar leg can route through an EMI licensed in the EU (under MiCA's broader payment-services environment) or through a Singapore MAS-licensed payment institution.
This split-rail approach is increasingly common among operators who serve both Turkish and international users. The Turkish entity holds the CMB authorisation and the MASAK registration; the foreign entity holds the EMI or payment licence and manages cross-currency settlement. The two entities transact at arm's length, with intercompany agreements that satisfy both Turkish foreign-exchange rules and the foreign regulator's outsourcing or intragroup-transaction requirements.
The critical point is that the EMI or payment licence does not resolve the Turkish banking problem on its own. Banks in Turkey assess the Turkish entity's compliance position directly; they will not treat a foreign EMI as a proxy for Turkish regulatory standing. The rails must be built at both ends.
If your payment structure spans Turkey and one or more foreign jurisdictions, OBOLUS can map the full rail and identify the compliance gaps. Write to info@oboluslaw.com or message us at t.me/oboluslaw. If a prior application stalled or an account was closed, a second read can surface the structural reason and the route back.
Tax and transfer-pricing considerations for the Turkey–foreign-entity structure
A dual-entity structure – a Turkish operating company alongside a foreign licensed entity – creates transfer-pricing obligations that directly affect the banking relationship. Turkish tax law requires that intercompany transactions between the Turkish entity and related foreign parties are conducted at arm's length, and the Turkish Revenue Administration has increased its focus on digital businesses with cross-border intragroup flows.
The tax treatment of crypto-asset activities in Turkey is evolving. The tax characterization of token receipts, exchange margins and custodial fees for Turkish entities is treated qualitatively here, as it varies by activity type and any specific rate or threshold requires verification against current Turkish tax legislation. What is clear is that a Turkish entity generating revenue from digital-asset activities will have a Turkish corporate-tax exposure, and the intercompany pricing between the Turkish entity and any foreign payment or custody entity must be documented at the time the structure is established – not retrospectively.
Operators we advise routinely underestimate the interaction between the banking structure and the tax structure. A bank's compliance team reviewing an application will examine the intercompany flows as part of its anti-money-laundering review. Undocumented or inconsistently priced intercompany transactions are a red flag in that review, regardless of whether they reflect a deliberate evasion or merely an administrative gap.
The Georgian tax environment – a common complement to a Turkey-facing structure for operators in the region – is addressed separately in our analysis of token taxation in that jurisdiction.
A self-assessment checklist before approaching a Turkish bank
Operators approaching Turkish banks for the first time can use the following checklist to assess whether their structure is likely to pass initial review. Each item represents a question that the bank's compliance team will ask; a negative answer on any item is likely to trigger a delay or refusal.
- Is the Turkish-facing entity registered with or authorized by the CMB under the applicable provisions of Turkish crypto law?
- Is the entity registered with MASAK as a virtual-asset service provider for AML/CFT purposes?
- Is there a documented AML/KYC policy that reflects MASAK's current requirements, including Travel Rule compliance for qualifying transfers?
- Are ultimate beneficial owners identified and documented, with source-of-funds explanations for any significant capital contributions?
- Is the intercompany structure – if a foreign entity is involved – documented with an arm's-length pricing analysis?
- Has the business identified and approached banks that are currently open to crypto counterparties, rather than assuming general market availability?
- Has a Turkish-law legal opinion been obtained confirming the regulatory classification of the proposed activities?
A complete positive answer to each item does not guarantee account opening – bank risk appetite is a commercial decision – but it substantially increases the probability and the speed of the review.
Common mistakes and the objection they reflect
A common assumption among operators entering Turkey is that a single offshore licence – a BVI FSC registration, a Cayman VASP registration or even an FCA MLR registration in the UK – is sufficient to support a Turkish banking relationship without any Turkish-law engagement. This is incorrect.
Turkish banks are required under BDDK guidance to perform their own due diligence on the counterparty's regulatory standing in relation to Turkish law. A foreign registration shows that the operator has taken a licensing step; it does not show that the operator is compliant with Turkish AML law or that its Turkish-facing activities are within the CMB's permitted scope. Banks that have been penalized for inadequate crypto-counterparty due diligence have become significantly less willing to accept the argument that a foreign licence is a proxy for local compliance.
The second common mistake is timing: approaching the bank before the regulatory infrastructure is in place, with the intention of building the compliance documentation while the account is open. Banks are not prepared to open an account on the basis of a compliance plan. The documentation must exist at the time of the application.
Regulators in the leading hubs increasingly expect digital-asset businesses to demonstrate compliance readiness before licensing, before banking, and before first transaction – not as a sequential process, but as a simultaneous one. Turkey is no exception.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital Asset Businesses – legal counsel for fiat-rail access, EMI selection and payment-licence structuring across jurisdictions
- EMI Onboarding for VASPs – specialist counsel on electronic-money institution onboarding for virtual-asset service providers
- Tax Treatment of Tokens in Georgia – analysis of the Georgian tax environment for digital-asset businesses in the region
FAQ
Why do banks close crypto company accounts?
Banks close crypto accounts primarily because of unresolved AML/KYC concerns – either the operator's documentation does not satisfy the bank's own compliance obligations, or a regulatory review identifies gaps in the counterparty's licensing posture. In Turkey, MASAK audits of bank portfolios have directly triggered account terminations for VASPs that lacked CMB registration or adequate AML infrastructure. A change in the bank's internal risk appetite, or a broader regulatory communication from the BDDK, can also lead to exits that are not the operator's individual fault but that have the same operational consequence.
How can a VASP onboard with an EMI?
A VASP (virtual asset service provider) can onboard with an EMI by demonstrating that it meets the EMI's enhanced due diligence requirements for high-risk categories. EMIs typically require a current regulatory licence or registration, a documented AML/KYC policy aligned with FATF Recommendation 15, Travel Rule compliance evidence, source-of-funds documentation for the principal beneficial owners, and a clear description of the business model and transaction flow. The process is materially smoother when the VASP has an existing authorisation from a recognized regulator – MiCA, MAS, FCA or an equivalent – rather than a lighter registration in a less-scrutinized jurisdiction.
What does client-money safeguarding require?
Client-money safeguarding requires that funds held on behalf of clients are kept separate from the firm's own funds, held in a designated account at a regulated institution, and protected in the event of insolvency. Under most regulated regimes – including the payment-services frameworks that govern EMIs – safeguarding obligations specify permissible asset classes and require regular reconciliation. For digital-asset businesses, the safeguarding question extends to on-chain custody: segregated wallet architecture, sub-custodian arrangements and proof-of-reserve practices are now baseline expectations in the leading licensed regimes. The specific technical and legal requirements vary by jurisdiction and licence category.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and our disputes team coordinates freezing relief and on-chain tracing across leading common-law forums when things go wrong. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specializing in VASP licensing, AML regulatory compliance and cross-border banking access for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.