EST · MMXXVI
Home/Jurisdictions/Turkey/De-risking and account closure defence in Turkey
Banking, Payments & EMI Onboarding

De-risking and account closure defence in Turkey

De-risking and account closure defence in Turkey. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Turkish banks and global EMIs (electronic money institutions) are terminating digital-asset business accounts at an accelerating rate. A payment licence granted in one jurisdiction carries no automatic weight with a Turkish correspondent bank, and a VASP operating across the EU-Turkey corridor routinely discovers that its fiat rails disappear without warning. The legal question is not whether de-risking is lawful – it generally is – but whether the closure was procedurally proper, whether a defence or alternative structure exists, and whether the business can onboard sustainable banking before operations halt. This page maps the regulated basis for account defence, the practical onboarding path for crypto businesses in Turkey, and the cross-border structuring moves that reduce exposure.

What is de-risking and why does it hit crypto businesses in Turkey first?

De-risking is the practice by which a bank or EMI exits a client relationship to reduce its own compliance exposure, rather than managing that exposure through enhanced due diligence. For a digital-asset business operating in Turkey, the risk profile is compounded: Turkey appears on the FATF grey list (the list of jurisdictions under increased monitoring), meaning every correspondent bank that processes Turkish-origin flows applies a higher scrutiny threshold. A VASP licensed elsewhere – under the VARA regime in Dubai, under MiCA in the EU, or under the Payment Services Act in Singapore – still finds that Turkish-origin transaction flows attract additional compliance review. That review, in a risk-appetite environment shaped by global AML pressure, frequently ends in a termination notice.

The practical consequence is severe. Payroll cannot be met. Client settlements stall. Regulatory reporting obligations tied to fiat flow become impossible to fulfil. In our cross-border practice, we see businesses lose their primary banking relationship with fewer than thirty days' notice – sometimes fewer than seven, where a bank invokes its standard contractual right to close on short notice without cause.

Turkey's own crypto regulatory environment adds a second layer. Turkey's Capital Markets Board (Sermaye Piyasası Kurulu, or SPK) administers the crypto-asset service provider licensing regime introduced under legislation that took effect in 2024. Until a business holds the relevant SPK licence, it cannot lawfully offer crypto-asset services to clients in Turkey, which means that an unlicensed platform simultaneously faces banking closure risk and enforcement exposure from the SPK itself.

How does the SPK licensing regime affect banking access?

The SPK licensing regime is the gateway to legitimate banking in Turkey for any VASP, and a business that has cleared SPK authorisation is materially better placed with Turkish correspondent banks than one relying solely on an offshore licence. The SPK regime requires applicants to demonstrate technical infrastructure, AML/CFT systems, capital adequacy at levels set by the SPK, and – critically – a physical presence and governance structure in Turkey. The capital requirement varies by the scope of licensed activities and is set by secondary SPK regulation; the current thresholds are [VERIFY] and must be confirmed against current SPK bulletins before any application planning.

The cross-border tension here is real. Many operators approaching the Turkish market arrive with a MiCA CASP authorisation from an EU national competent authority, or a VARA licence from Dubai. Neither of those licences substitutes for SPK authorisation in Turkey. A MiCA CASP passport is valid across the EU and EEA; it does not extend to Turkey, which is not an EU member state and has not adopted MiCA-equivalent mutual recognition arrangements. An operator serving Turkish users from an EU-licensed entity is, under current Turkish law, operating without the required local licence. Banks and EMIs are aware of this gap and treat it as a red flag rather than a comfort.

CTA: The process above describes the standard path. Your facts – the entity structure, the Turkish user base, and the banking counterparties – change the analysis materially. Map your options with OBOLUS.

What grounds exist to challenge an account closure in Turkey?

A bank's right to close an account is broad, but it is not unlimited. Turkish banking law requires banks to act within the terms of the account agreement and, in certain circumstances, to give notice periods consistent with commercial custom. Where a closure is immediate and unexplained, a business has at least three potential grounds for challenge or remedy.

First, if the closure was triggered by an incorrect AML flag – for instance, a transaction mistakenly identified as sanctions-related – a formal rectification request supported by documentation can reopen the relationship. We have seen this work where the bank's automated screening system generated a false positive on a counterparty name, and where the client was able to produce a clean sanctions search within forty-eight hours.

Second, where a closure is discriminatory in the sense of targeting a lawfully licensed business without a documented AML rationale, a regulatory complaint to the Banking Regulation and Supervision Agency (BDDK) may be appropriate. BDDK has jurisdiction over Turkish deposit banks and participation banks. A complaint forces the bank to produce its documented basis for the decision.

Third, and most practically, the business should be simultaneously engaging alternative banking – whether a domestic Turkish bank with a documented VASP policy, a European EMI with Turkish correspondent access, or a payment institution licensed in a third jurisdiction that can intermediate flows. Defence of the existing account and procurement of a replacement run in parallel; waiting for the defence to conclude before beginning onboarding is the most common mistake we see.

How can a digital-asset business onboard with an EMI for Turkish operations?

EMI onboarding for a crypto business with Turkish exposure follows a structured due-diligence process, and businesses that approach it without preparation typically face a second rejection that is harder to reverse. The EMI's core concern is whether the applicant's regulatory status, transaction volumes and AML framework are coherent and documented.

The onboarding package should address, at minimum: the entity's licence or registration (SPK, MiCA CASP, VARA, or equivalent); the AML/CFT policy including the Travel Rule (the obligation under FATF Recommendation 15 to pass originator and beneficiary data with virtual-asset transfers) compliance approach; a description of the business model and expected transaction flows; source-of-funds and source-of-wealth documentation for the beneficial owners; and – for Turkish-origin flows specifically – an explanation of how the business manages FATF grey-list exposure in its own risk framework.

EMIs that are willing to bank digital-asset businesses with Turkish flows typically require enhanced ongoing monitoring, periodic AML reporting, and contractual rights to request transaction-level information on short notice. These are not unusual terms in this environment; accepting them is preferable to losing all fiat access. Businesses should negotiate the notice period for account closure – many standard EMI agreements allow closure on notice periods that are commercially inadequate – and should secure a written AML policy acknowledgment from the EMI that creates a clear evidentiary record if a later dispute arises.

The timeline for EMI onboarding varies materially by institution and jurisdiction. A well-prepared application with a licensed entity and clean UBO chain can move through KYC in a matter of weeks at a responsive EMI. An application with unresolved UBO questions or a novel business model can take considerably longer, and some EMIs will decline entirely. Planning for parallel applications to multiple institutions is standard practice.

What does client-money safeguarding require for a Turkey-facing business?

Client-money safeguarding – the regulatory obligation to hold client funds separately from the business's own funds – applies wherever the business holds fiat on behalf of clients, and the applicable standard depends on which regulatory regime governs the entity receiving and holding those funds. Under MiCA, a CASP that holds client funds must maintain segregated accounts and comply with the safeguarding requirements of the relevant national competent authority. Under the VARA regime, the rules on client asset segregation are set in the VARA rulebooks for the relevant activity licence. Under the SPK regime in Turkey, a licensed crypto-asset service provider is subject to SPK rules on client asset protection, which include segregation obligations.

The cross-border complication is that a business serving Turkish clients through an EU-licensed entity is subject to the EU safeguarding regime for the funds it holds, but its Turkish-bank correspondent may not recognise the EU account structure as satisfying Turkish client-protection expectations. The result is a gap that must be addressed structurally – either by licensing the entity that holds Turkish-client funds under the SPK regime, or by ensuring that the EU-licensed entity's safeguarding structure is documented in a way that Turkish regulators and correspondent banks can verify.

In our practice, we regularly advise on how to align the safeguarding structure across the licensing, banking and custody layers before a business launches in a new market. The cost of retrofitting safeguarding compliance after banking relationships are established is substantially higher than building it correctly at the outset.

How does the Turkey-EU or Turkey-Dubai corridor affect the optimal entity structure?

For a business operating at the intersection of Turkey and either the EU or the UAE, the entity structure question is not merely a tax-optimisation exercise – it determines which regulator has primary authority over the business, which banking options are realistically available, and what the enforcement exposure looks like if a regulator acts. Operating a digital-asset business serving Turkish users from a single offshore entity, without a local Turkish presence or SPK licence, is the structural profile that most consistently triggers both banking closure and regulatory attention.

A dual-entity structure – an SPK-licensed Turkish entity for Turkish clients, combined with an EU CASP or VARA-licensed entity for cross-border flows – is a more defensible arrangement. The Turkish entity holds the SPK licence and operates the local fiat rails. The offshore entity handles cross-border treasury, custody, and institutional flows. The two entities operate under a documented intragroup service agreement that is transparent to both the SPK and the offshore regulator. This structure is more expensive to maintain but is significantly more durable in a de-risking environment.

The tax interaction matters. Turkey taxes corporate income, and an entity with a Turkish permanent establishment is subject to Turkish corporate tax on the income attributed to that establishment. Transfer pricing rules apply to intragroup flows. A poorly documented intragroup agreement can create both a tax dispute and a regulatory one – the SPK may question whether the Turkish entity is genuinely the entity serving Turkish clients, or whether it is a shell for a substance-free offshore structure. We map the licence, banking and tax stack together, because optimising one layer at the expense of another is the most common structural error in this market.

CTA: If a prior banking application stalled or an account was closed without a clear explanation, a second read of the structure can surface the reason and identify the route forward. Write to OBOLUS at info@oboluslaw.com.

A recent account closure matter

In a recent banking matter, a payments company operating under a European electronic money licence found that its Turkish correspondent bank had terminated all settlement accounts following a transaction monitoring alert on a batch of crypto-to-fiat settlements. The bank provided no substantive explanation and gave notice of fewer than ten business days. We reviewed the transaction records and identified that the alert had been generated by an automated screening match on a common surname in the originator data – not a sanctions hit. We prepared a formal rectification submission to the bank's compliance function, supported by a clean TRM analysis of the flagged transactions and a legal opinion on the entity's regulated status. The bank restored the accounts within three weeks. In parallel, we initiated an onboarding process with two alternative EMIs, so that operations would not have been interrupted had the bank declined to reverse. The business now operates with a primary and a backup banking relationship across two institutions and two jurisdictions.

Which structure fits which operator profile?

A business with a small Turkish client base served from an EU-licensed entity, with no intention of establishing a Turkish presence, faces primarily a banking-access problem, not a licensing one. The practical solution is a well-documented AML framework, a Travel Rule-compliant transfer protocol, and an EMI relationship with explicit FATF grey-list policy coverage for Turkish flows. SPK licensing is not yet required for this profile, provided the EU entity is not actively soliciting Turkish clients in a way that triggers local licensing obligations.

A business that is actively marketing to Turkish retail or institutional clients, processing Turkish-source fiat in material volumes, or holding Turkish-client assets, is in a materially different position. That business needs SPK authorisation, a Turkish corporate entity, and a domestic banking relationship. The offshore licence is an additional comfort, not a substitute. The timeline for SPK authorisation is subject to SPK processing capacity and varies; planning for a process measured in months, not weeks, is prudent.

A business that is already de-risked – account closed, operations interrupted – has a compressed decision window. The immediate priorities are: document the closure basis, identify whether a rectification claim has merit, and secure interim banking through an alternative institution that has clear VASP and Turkey-risk policy. Legal counsel engaged on the first day after a closure notice produces materially better outcomes than counsel engaged after the notice period expires.

What is the most common structural mistake that leads to de-risking?

A common assumption is that a single offshore licence – whether a MiCA CASP, a VARA licence, or a Cayman VASP registration – is sufficient to serve clients globally, including in Turkey, without additional local regulatory engagement. That assumption is incorrect, and it is the structural premise that most consistently produces banking closure. An offshore licence demonstrates that the business is regulated somewhere; it does not demonstrate that the business is regulated appropriately for the specific market it is serving. Turkish banks, EMI compliance teams, and the SPK itself are each capable of identifying the gap between a business's claimed regulatory status and its actual regulated footprint in Turkey.

The second common mistake is treating banking as a procurement problem rather than a regulatory one. A business that approaches ten EMIs with an undocumented AML framework and an unlicensed Turkish operation will receive ten declines. The EMI's decision is a compliance judgment, and it responds to compliance evidence. Preparing the onboarding package – policy documentation, licence certificates, UBO chain, Travel Rule compliance confirmation, FATF risk-country policy – before approaching any institution reduces the rejection rate substantially.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily to manage their own AML and sanctions compliance exposure, rather than because the client has committed any breach. A digital-asset business generates transaction patterns – high volume, cross-border, pseudonymous counterparties – that automated monitoring systems flag as elevated risk. When a bank's compliance function determines that enhanced due diligence costs outweigh the commercial relationship, it exits the account. For businesses with Turkish-origin flows, the FATF grey-list status of Turkey raises the bank's risk score for those flows, accelerating that calculation. The defence is a documented compliance programme that makes the cost-benefit calculation work in the client's favour.

How can a VASP onboard with an EMI?

A VASP seeking EMI onboarding should present a complete due-diligence package: the entity's licence or registration, a documented AML/CFT policy with Travel Rule compliance confirmation, beneficial ownership transparency, projected transaction volumes, and – for Turkey-facing flows – an explicit explanation of how the business manages FATF grey-list exposure. EMIs with clear VASP-acceptance policies exist across the EU and EEA. Preparation quality is the primary differentiator between businesses that onboard in weeks and those that face repeated rejection. Working with counsel familiar with EMI compliance expectations reduces the cycle time and improves the outcome.

What does client-money safeguarding require?

Client-money safeguarding requires that funds held on behalf of clients are kept separate from the business's own operational funds, held in accounts clearly designated as client accounts, and subject to reconciliation and audit processes that allow clients' positions to be identified at any time. The precise requirements depend on the governing regulatory regime: MiCA sets standards for EU CASPs, VARA sets them for Dubai-licensed entities, and the SPK sets them for Turkish-licensed crypto-asset service providers. A business operating across multiple regimes must ensure that its safeguarding architecture satisfies each applicable standard, not merely the most permissive one.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the entirety of our practice, and we act only for businesses. We map the licence stack across operating, custody and payment layers before you commit – because operating without the right structure risks enforcement, frozen rails and lost banking. To discuss your situation, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in cross-border VASP licensing and banking-access strategy for digital-asset businesses in emerging and established regulatory markets.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours