Why EMI onboarding for Turkey-based VASPs is harder than it looks
EMI onboarding for VASPs in Turkey sits at the collision point of two moving regulatory systems: Turkey's own crypto law (the regime enacted under the Capital Markets Law, supervised by the Capital Markets Board of Turkey – the CMB) and the onboarding policies of electronic money institutions (EMIs, payment-account providers authorised under the Banking Regulation and Supervision Agency's payment-services framework). A VASP that has completed CMB registration cannot automatically open fiat rails. That is the core commercial problem. The analysis below maps the regulated basis, the practical onboarding process, the cross-border interaction with tax and banking, and the decision points that determine whether a Turkish-nexus structure can actually move money.
As VASP supervision in Turkey tightens and CMB registration requirements become more prescriptive, EMIs are simultaneously raising their own compliance thresholds. The gap between obtaining regulatory standing and securing functional banking is widening. Operating without a resolved fiat-rail strategy exposes the business to enforcement, frozen accounts and – at worst – forced wind-down of client balances.
What is the regulatory basis for VASPs in Turkey?
The Turkish VASP regime is grounded in the Capital Markets Law as amended to bring crypto-asset service providers within the CMB's supervisory perimeter. Providers that offer crypto-asset trading, custody, transfer or related services to Turkish users must register with – and increasingly seek authorisation from – the CMB. The regime is not a voluntary label. Operating a crypto platform serving Turkish residents without CMB standing is an unlicensed activity with criminal and administrative consequences. The CMB is the primary regulator for crypto-asset service providers in Turkey; the Banking Regulation and Supervision Agency (BRSA) governs the payment and EMI layer separately.
The two regulatory pillars do not automatically align. A CMB-registered VASP is not thereby authorised to issue e-money, hold client funds in payment accounts or operate a payment system. Each function sits under its own licence. For most VASPs the practical consequence is that fiat custody – holding Turkish lira or hard-currency balances on behalf of clients – must be structured through a separately authorised bank or EMI. That structural dependency is where the onboarding friction originates.
Turkey's AML/CFT framework applies the Travel Rule (the obligation to pass originator and beneficiary data alongside a transfer) in line with the FATF Recommendations, including Recommendation 15 on virtual assets. EMIs conducting correspondent relationships with VASPs are therefore subject to enhanced due-diligence obligations. A VASP that cannot demonstrate its own AML programme, beneficial ownership records and transaction-monitoring architecture will not pass an EMI's counterparty assessment.
For an inbound business – a VASP incorporated outside Turkey but serving Turkish users or holding a Turkish entity – the sequence matters: CMB registration precedes the EMI conversation. Attempting to open business accounts before regulatory standing is established typically results in immediate rejection and a flagged application record that complicates the second attempt.
To map the correct entry path for your structure, contact OBOLUS at info@oboluslaw.com. The entity, the user base and the intended fiat-flow architecture all affect the analysis before the first EMI conversation begins.
How does the EMI onboarding process actually work for a VASP?
EMI onboarding for a VASP is a structured due-diligence process, not a standard account-opening form. Turkish-licensed EMIs and the Turkish subsidiaries or branches of European EMIs each conduct their own counterparty assessment, but the substantive content they require is broadly consistent. The process runs in three phases.
Phase one is document assembly. The EMI will require the VASP's corporate structure chart (to ultimate beneficial owner level), CMB registration certificate, AML/KYC policy documentation, board-level compliance sign-off, evidence of transaction-monitoring controls and – for any VASP holding customer crypto assets – a description of the custody architecture. Where the VASP is part of a multi-entity group (a common structure for tax and licensing reasons), the EMI will want to understand the group flow of funds and the role of each entity.
Phase two is counterparty risk scoring. The EMI applies its own risk model to the VASP's client profile, product set and geographic exposure. A VASP serving retail users in multiple jurisdictions, offering leveraged products or operating in markets flagged by FATF as high-risk will score differently from a B2B settlement platform with a narrow, verified institutional client base. The scoring outcome determines whether onboarding proceeds, whether conditions attach, or whether the application is declined at the pre-contractual stage.
Phase three is contractual and operational setup: master services agreement, sub-account structure, transaction limit parameters and ongoing reporting obligations. For VASPs that will pass client funds through the EMI – rather than using it purely for treasury – the client-money safeguarding model must be agreed before the account goes live.
Timeline is variable. In our cross-border practice, we have seen straightforward onboardings complete in a matter of weeks where the documentation package was complete on day one. Applications that enter the process with gaps in AML policy, unclear beneficial ownership or unresolved regulatory status routinely extend to several months – if they complete at all.
Why do EMIs de-risk VASPs, and how does a VASP respond?
De-risking – the practice by which payment institutions exit relationships with whole categories of client rather than managing risk at the individual-client level – is the dominant structural obstacle facing VASPs seeking EMI onboarding in Turkey and across most major jurisdictions. The phenomenon is well-documented by the FATF and has been the subject of repeated guidance from financial-sector supervisors, but it persists because the compliance cost of maintaining a VASP relationship is, from the EMI's perspective, disproportionate to the revenue it generates.
The VASP's strategic response is to de-commoditize itself: to present not as a generic crypto platform but as a specific, well-governed counterparty with a verifiable regulatory footprint and a documented risk profile. This requires investment in AML infrastructure before the onboarding process begins. An EMI cannot pass its own supervisory inspection if its VASP counterparties do not meet the same substantive standard.
In practice, operators we advise regularly encounter three scenarios. First, a VASP with strong AML documentation but incomplete CMB standing is declined because the EMI cannot satisfy itself that the counterparty is regulated. Second, a VASP with CMB registration but a generic AML policy passes phase one and fails phase two on risk scoring. Third, a VASP that has previously been de-risked by another institution – and carries that history in public registry data – faces a materially harder conversation the second time.
The cross-border dimension compounds all three scenarios. A Turkish entity that also holds users in EU member states must demonstrate compliance not only with Turkish CMB and BRSA requirements, but also with the expectations that MiCA and ESMA have placed on the EU-facing activity. An EMI with EU passporting will apply MiCA-aligned standards to its entire VASP book, regardless of where the individual VASP is regulated.
What does a VASP de-risking defence look like in practice?
In a recent matter, a digital-asset exchange with Turkish CMB registration and an EU-facing product line was notified by its sole payment partner that the relationship would be terminated within thirty days. The notification cited generic concerns about the VASP's client jurisdiction profile. We conducted a rapid structural review: the exchange's AML policy predated its current product scope, its beneficial-ownership records were incomplete at a subsidiary level, and its Travel Rule compliance documentation had not been updated to reflect the EU user base. We assembled a remediation package – revised AML policy, updated UBO records and a Travel Rule implementation brief – and re-presented the VASP to two alternative EMIs simultaneously. The relationship with one was established before the termination date took effect, preventing a gap in fiat-rail access. The outcome was continuity of service; it was not guaranteed at the outset.
How do banking and tax interact for Turkey-structured VASPs?
For a VASP structured through a Turkish entity, the fiat-rail and tax questions are inseparable. Where the Turkish entity is the group's trading entity – booking revenue in Turkey, holding Turkish-lira and hard-currency balances, paying Turkish corporate tax – the EMI relationship directly affects the tax position. Revenue that cannot be received because fiat rails are unavailable is not a tax problem; it is an operational failure that prevents the business from existing.
The more common structuring question involves a multi-entity group: a Turkish operating entity (for CMB registration and local market access) alongside an offshore entity (for international liquidity, custody or treasury functions). In that model, the EMI onboarding question arises for each entity independently. The offshore entity may need EU or UK EMI access for its European user base; the Turkish entity needs Turkish or Turkish-compatible payment infrastructure for its domestic book.
Transfer-pricing consequences follow the fiat flows. If the Turkish entity receives all client-facing revenue and then remits a licence fee or service fee to an offshore holding vehicle, both the Turkish tax authority and the receiving jurisdiction's authority will scrutinize the arm's-length basis of that arrangement. We have seen Turkish-structured VASPs receive transfer-pricing enquiries within their first full operating year. The EMI account structure – specifically, which entity holds which pool of funds – is not a banking-operations question. It is a tax architecture question and must be designed as one.
Turkish VAT treatment of crypto-asset transactions is a separate analysis and has been the subject of evolving guidance from the Turkish Revenue Administration. VASPs should obtain current local tax counsel before finalising the revenue booking model. OBOLUS works with allied counsel in Turkey for the domestic tax and regulatory components.
How should a VASP decide whether a Turkish entity is the right structure?
The structural decision turns on three axes: the user base, the product set and the available fiat-rail architecture. A VASP whose primary market is Turkey, whose product is spot trading and whose clients are Turkish retail and institutional users has a strong reason to hold CMB registration through a Turkish entity. The regulatory standing is required, the tax residence is aligned to the revenue base, and the EMI onboarding challenge, while real, is a solvable operational problem.
A VASP whose primary market is elsewhere – EU, Gulf, Southeast Asia – but that has incidentally acquired Turkish users faces a harder calculation. CMB registration may be required regardless of where the entity is incorporated if the service is being actively marketed to Turkish residents. In that scenario, the VASP must decide whether to register a Turkish entity, to geo-block Turkish users (with the legal and commercial consequences that entails), or to engage directly with the CMB about the scope of the regime's extraterritorial reach.
In our practice, we have seen operators commit to Turkish structures on the basis of market-size projections and then discover that the EMI onboarding timeline exceeded their cash-runway planning. The sequencing matters: regulatory standing, then documentation package, then EMI approach, then banking go-live. Each step has a realistic timeframe that must be built into the business plan.
A common assumption in the market is that a single offshore licence – typically a BVI VASP registration or a Cayman fund structure – provides sufficient regulatory cover to serve clients globally, including in Turkey. That assumption is incorrect. Turkish CMB supervision is user-location-based, not entity-location-based. The CMB's reach extends to services marketed or provided to Turkish residents regardless of where the service provider is domiciled. An entity that relies on its BVI registration to serve Turkish users without CMB engagement does so at significant legal risk.
If your EMI onboarding process has stalled or a prior application was declined, a second read of your documentation package and regulatory posture can identify the structural reason and the route forward. Write to info@oboluslaw.com.
Self-assessment: Is your VASP ready for EMI onboarding in Turkey?
The following questions reflect the minimum threshold an EMI counterparty review will reach. A VASP that cannot answer all of them affirmatively before opening the conversation should resolve the gaps first.
- Is CMB registration confirmed and current, or is the application in process with a defined timeline?
- Does the VASP's AML/KYC policy reflect its current product set, user geography and transaction-monitoring architecture?
- Are beneficial ownership records complete to the ultimate natural-person level, including any offshore holding vehicles?
- Has the VASP documented its Travel Rule implementation – specifically how it passes originator and beneficiary data on transfers above the applicable threshold?
- Does the VASP's group structure map clearly show which entity holds client assets, which entity books revenue and which entity contracts with the EMI?
- Has the VASP considered the transfer-pricing basis of any intra-group fee arrangements?
- Is there a documented response procedure for an EMI's ongoing monitoring queries?
Regulators in the leading hubs increasingly expect VASPs to treat EMI onboarding readiness as a continuous compliance function, not a one-time project. The documentation that passes an initial counterparty assessment today may not satisfy the same EMI's enhanced-due-diligence cycle twelve months later.
Related at OBOLUS
- Banking, Payments and EMI Onboarding for Digital-Asset Businesses – the full practice-area guide to fiat-rail strategy across licensing jurisdictions.
- De-risking and Account Closure Defence for Institutional Clients – how we respond when a payment partner exits a VASP relationship.
- Smart Contract Dispute Resolution in UAE – VARA Dubai – jurisdiction-specific disputes analysis for Gulf-structured digital-asset businesses.
FAQ
Why do banks close crypto company accounts?
Banks and EMIs close crypto company accounts primarily because the compliance cost of maintaining those relationships – enhanced due diligence, ongoing transaction monitoring, regulatory reporting – is assessed as disproportionate to the revenue generated. This is de-risking: a category-level exit rather than an individual risk assessment. A VASP can reduce its de-risking exposure by presenting complete AML documentation, verified beneficial ownership records and a clear regulatory standing before the relationship begins.
How can a VASP onboard with an EMI?
A VASP seeking EMI onboarding should prepare a three-layer package: regulatory standing (the relevant licence or registration certificate), compliance infrastructure documentation (AML policy, Travel Rule implementation, transaction-monitoring evidence) and a group structure map showing beneficial ownership and fund flows. The process runs through counterparty risk scoring before any contractual terms are reached. Timeline varies by the completeness of the package and the EMI's own onboarding queue; a well-prepared application typically completes faster than one that enters the process with gaps.
What does client-money safeguarding require?
Client-money safeguarding requires that client funds held by an EMI or payment institution are segregated from the institution's own funds, held in a designated account and protected in the event of the institution's insolvency. For VASPs that route client fiat through an EMI, the safeguarding model – pooled omnibus account versus individual client sub-accounts – must be agreed contractually before the account goes live. The applicable safeguarding standard is set by the BRSA framework for Turkish-licensed EMIs; EU passported EMIs apply the payment-services safeguarding rules of their home member state.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. We map the licence stack across operating, custody and payment layers before you commit – so the fiat-rail architecture is designed in, not retrofitted. Digital assets are the whole of our practice. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory and Compliance Analyst – specialising in VASP regulatory onboarding, EMI counterparty compliance and the cross-border interaction between crypto licensing regimes and payment-institution frameworks.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.