EST · MMXXVI
Home/Jurisdictions/Turkey/Payment institution licensing in Turkey: Legal Requirements for Businesses
Banking, Payments & EMI Onboarding

Payment institution licensing in Turkey: Legal Requirements for Businesses

Payment institution licensing in Turkey. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Operating a digital-asset or payments business across borders without the correct Turkish authorisation is not a minor compliance gap. Payment institution licensing in Turkey is mandatory for any entity that processes payments, holds client funds or provides fiat rails to Turkish users – and the regulator, BDDK (the Banking Regulation and Supervision Agency), has consistently enforced that perimeter. The regime sits alongside Turkey's distinct crypto-asset legislative track, creating a layered licensing environment that inbound operators often underestimate. This page sets out the regulated perimeter, the application pathway, the cross-border interaction with banking and tax, and the practical decision point for businesses weighing a Turkish presence.

What does the Turkish payment institution licensing regime actually cover?

The Turkish payment services regime, administered by BDDK, applies to any business providing payment services to Turkish-resident clients or processing transactions denominated in Turkish lira – regardless of where the entity is incorporated. The regime distinguishes between payment institutions and electronic money institutions (EMIs, entities authorised to issue electronic money). Both categories require a Turkish legal entity and a formal licence from BDDK before any regulated activity begins. A foreign entity routing transactions through a Turkish bank account, or offering wallet infrastructure to Turkish users without local authorisation, sits inside the regulated perimeter.

The crypto-asset layer adds a second regulatory track. Turkey's Crypto Asset Service Provider (CASP) regime – introduced under legislation that amended the Capital Markets Law – is supervised by the CMB (Capital Markets Board, known locally as SPK). A business operating a crypto exchange, providing custody or offering portfolio management over crypto assets therefore faces two distinct regulators: BDDK for the fiat payment rails and CMB for the crypto-asset activities. In our practice, operators consistently underestimate this dual-track structure and attempt to address one layer while leaving the other exposed.

The practical boundary is defined by the nature of the activity, not the label the business applies to itself. Accepting fiat deposits from Turkish users, converting between fiat and crypto, or providing a custodial wallet where client funds are aggregated – each of these triggers one or both regimes. A business that processes only crypto-to-crypto and never touches lira-denominated rails may remain outside BDDK's perimeter, but that is a fact-specific analysis that must be done before the product goes live.

What is the BDDK application pathway for an inbound operator?

BDDK requires a Turkish joint-stock company (anonim şirket) as the licence-holding entity; a branch of a foreign company is not an eligible applicant for a payment institution licence. The application process involves submission of a detailed business plan, corporate governance documentation, an AML/CFT programme, IT security assessments and evidence of minimum capital – which varies by activity category and is set in the applicable BDDK regulations. Timeline varies but applications for straightforward payment institution licences are generally processed over several months; complex applications or those requiring supplemental information take longer. The process is sequential: BDDK reviews the file, may issue requests for information, and a licence decision follows.

Key documents in a BDDK application include: articles of association of the Turkish entity; shareholder and ultimate beneficial owner declarations; a detailed IT architecture and security review; the internal control and risk management framework; and a three-year business plan with revenue and capital adequacy projections. Shareholders holding above a defined threshold are subject to fitness-and-propriety review, which extends to the cross-border group structure. If a foreign parent is licensed in another jurisdiction – for example, holding a VARA licence in Dubai or a MiCA CASP authorisation in the EU – BDDK will still conduct its own independent assessment; there is no mutual recognition.

Electronic money institution applicants face a substantially similar process but with additional requirements around safeguarding the float of e-money issued. The two licence types are not interchangeable: a payment institution licence authorises transaction processing but not the issuance of e-money; an EMI licence covers both, subject to the ring-fencing requirements BDDK imposes on client funds.

To map the licence stack your Turkish structure requires before you commit capital to incorporation, contact OBOLUS at info@oboluslaw.com. The process above describes the standard path. Your facts – the entity structure, the user base, the banking relationships, the crypto-asset product mix – change the analysis materially.

How does the CMB crypto-asset regime interact with the BDDK payment layer?

Turkey's CASP regime, supervised by the CMB, created a licensing obligation for crypto-asset service providers that is distinct from and parallel to BDDK's payment institution framework. A Turkish CASP licence authorises a business to operate a crypto-asset trading platform, provide custody services, or offer other defined crypto-asset activities to Turkish clients. The CMB administers its own application procedure, capital requirements and ongoing compliance obligations under the relevant implementing legislation. Critically, a BDDK payment institution licence does not authorise crypto-asset service provision, and a CMB CASP licence does not authorise the provision of fiat payment services. Businesses offering both functions need both authorisations.

In our cross-border practice, operators targeting Turkey from established positions in Singapore (under the MAS Payment Services Act), the EU (under MiCA) or the UK (under FCA registration) frequently assume their home-country authorisation gives them a compliance runway in Turkey. It does not. Turkey operates a closed perimeter: regulated services to Turkish-resident clients require a Turkish entity and Turkish authorisations from the competent authority for each activity. The CMB and BDDK do not accept foreign passports or equivalence declarations.

The Travel Rule obligation – the requirement under the FATF Recommendation 15 framework to pass originator and beneficiary data with virtual-asset transfers – applies to Turkish CASPs on an equivalent basis to other FATF-member jurisdictions. The threshold at which the Travel Rule is triggered and the specific technical standard applied are set in CMB and BDDK implementing rules; operators should verify the current position against the applicable Turkish regulations before go-live, as the details are amended periodically.

What are the cross-border banking and tax realities for a licensed Turkish operator?

Obtaining a licence from BDDK or CMB does not automatically resolve the banking challenge. Turkish commercial banks apply enhanced due diligence to digital-asset businesses regardless of licensing status, and in our experience Turkish banks are notably cautious about onboarding CASP or payment institution clients that have significant cross-border flows. A licensed entity must still demonstrate the source of funds, the user onboarding process, the AML controls and the nature of the cross-border counterparty relationships before a correspondent account is opened.

Banking for the Turkish entity typically involves maintaining accounts with at least one Turkish bank for lira operations and, where the product requires it, a separate relationship for foreign-currency flows. The lira accounts are subject to BDDK's client-money safeguarding requirements: funds belonging to clients must be segregated from the institution's own capital. For EMIs, the safeguarding model specifies how the float must be held and reported. Non-compliance with safeguarding obligations is an enforcement trigger independent of the licence itself.

On the tax side, a Turkish anonim şirket is subject to Turkish corporate income tax on its worldwide income at the applicable rate. VAT treatment of payment services and crypto-asset transactions is an area where Turkish law has evolved, and the characterisation of specific revenue streams – transaction fees, spread income, custody fees – determines the VAT and withholding tax position. Transfer pricing applies where the Turkish entity transacts with group entities in other jurisdictions. Operators structuring a Turkish operation alongside an EU CASP entity or a Dubai VARA licensee need to model the inter-company arrangements, the controlled-foreign-company rules that may apply in the parent's jurisdiction, and the treaty position between Turkey and the parent jurisdiction.

Turkey's currency controls add a further dimension. Restrictions on lira transfer and on holding foreign-denominated assets apply to Turkish residents and Turkish entities. A payment institution or CASP must build the currency control requirements into its product design – not as a post-licensing consideration, but before the product architecture is finalised.

What are the most common mistakes operators make when entering the Turkish market?

The first and most costly mistake is delaying the licence application until after the product has launched to Turkish users. BDDK and the CMB both have the power to order a business to cease regulated activities, to freeze accounts and to impose administrative penalties. Operating without authorisation – even briefly, on a "we'll apply shortly" basis – creates enforcement exposure that the eventual licence does not retroactively cure.

The second common error is treating the BDDK and CMB as a single regulatory contact. They are separate agencies with separate application portals, separate documentation requirements and separate ongoing supervisory relationships. A business that files with CMB and considers the Turkish compliance question answered will find that BDDK pursues the fiat rail separately. We regularly advise businesses that have correctly completed one application and overlooked the other entirely.

The third error involves corporate structure. Incorporating a Turkish entity after a foreign parent has already been publicly associated with the Turkish product – through social media, marketing, or app store listings accessible to Turkish residents – creates a timeline problem. BDDK and CMB treat the commencement of regulated activity as the date on which Turkish users could first access the service, not the date of the licence application. Pre-launch legal review is the correct sequence.

A fourth area of failure is the AML/CFT programme. Turkish AML requirements for payment institutions and CASPs are detailed and require a locally adapted programme, not a translation of the group AML policy. The Money Laundering Investigation Board (MASAK) oversees AML compliance separately from BDDK and CMB, and MASAK audits examine the adequacy of the Turkish entity's specific controls, staff training and suspicious transaction reporting – not the group framework document.

An illustrative cross-border matter

In a recent engagement, a payments operator headquartered in an EU member state sought to extend its product to Turkish users while relying on its existing MiCA CASP authorisation. The business had established fiat rails through a European EMI and assumed the Turkish user base could be served from the EU entity without a Turkish presence. Our review identified that the volume and frequency of transactions with Turkish-resident clients, combined with the Turkish-lira-denominated settlement flows, placed the business squarely within BDDK's licensing perimeter. We mapped the dual BDDK/CMB authorisation requirement, advised on the Turkish corporate structure and the inter-company payment flows between the EU parent and the proposed Turkish entity, and prepared the pre-application engagement strategy with BDDK. The client restructured the product before launch, avoiding the enforcement exposure that would have arisen from continuing operations under the mistaken equivalence assumption.

Which operator profile needs which Turkish authorisation?

Operators approaching Turkey from different business profiles reach different authorisation conclusions. A business providing only fiat payment processing – no crypto-asset services – requires a BDDK payment institution or EMI licence and sits entirely outside CMB's scope. The timeline to authorisation is typically measured in months rather than quarters for a well-prepared application, though complex group structures extend this materially.

A crypto-native exchange offering lira on-ramps and off-ramps to Turkish users requires both a CMB CASP licence for the crypto activities and a BDDK authorisation for the fiat payment services. These applications can proceed in parallel, but the sequencing and the interaction between the two applications require coordination. A CMB CASP applicant that has not addressed the BDDK position will face a gap in its operational authorisation even after CMB approval.

A business offering only crypto-to-crypto services with no lira-denominated rails – for example, a pure-play crypto custody provider – requires a CMB CASP licence but may be able to avoid a BDDK authorisation, subject to a careful analysis of the specific payment flows. That analysis turns on whether client onboarding and client withdrawal involve any fiat interface at the Turkish level.

A foreign operator with no Turkish entity that markets to Turkish residents via geo-targeted advertising or Turkish-language interfaces is not protected by its offshore incorporation. BDDK and CMB both apply a services-to-Turkish-residents test. The entity's legal domicile is relevant to jurisdiction, but it does not exempt the business from Turkish licensing requirements where Turkish users are being actively solicited.

If a prior Turkish application stalled, a banking relationship was refused, or a compliance gap has been identified post-launch, OBOLUS can provide a second read of the structure and the pathway forward. Write to us at info@oboluslaw.com or message t.me/oboluslaw.

A common assumption that carries real risk

A common assumption among operators entering Turkey is that a single offshore licence – a BVI FSC registration, a Cayman CIMA authorisation, or a well-recognised EU CASP under MiCA – is sufficient to serve Turkish clients on a cross-border basis. That assumption is incorrect and in some cases dangerous. Turkey does not apply a third-country equivalence or passporting regime to digital-asset or payment services. The licensing obligation arises from the nature of the service provided to Turkish residents, not from the operator's home-country regulatory status. Operators who have launched on this assumption and subsequently received a BDDK or CMB inquiry have faced the compounded difficulty of seeking authorisation while a compliance concern is already on record. The correct sequence is always: legal analysis, entity formation, licence application, then product launch.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily because of perceived AML/CFT risk, the volume and cross-border complexity of transaction flows, and internal risk-appetite policies that treat digital-asset businesses as a high-risk category. In Turkey, this challenge is compounded by the dual BDDK/CMB regulatory structure: a bank's compliance team may be uncertain whether the business holds the correct authorisation for all its activities, making de-risking the simpler outcome. A well-documented licensing position, a clear AML programme and a structured pre-onboarding submission materially improve the outcome.

How can a VASP onboard with an EMI?

A VASP (virtual asset service provider) seeking to onboard with an EMI must demonstrate that it holds the applicable licence for its activities, operates a documented AML/CFT programme compliant with FATF standards including the Travel Rule, and can evidence the source of client funds. EMIs apply enhanced due diligence to VASP clients. The application typically requires a detailed business description, AML policy documentation, licensing certificates and ownership structure charts. In our practice, preparation of a structured EMI onboarding pack significantly reduces the timeline and the number of follow-up information requests.

What does client-money safeguarding require?

Client-money safeguarding requires a licensed payment institution or EMI to hold funds belonging to clients in a segregated account, separate from the institution's own capital, at a credit institution or in qualifying liquid assets. The purpose is to protect client funds in the event of the institution's insolvency. In Turkey, BDDK sets the specific safeguarding method and the reporting obligations for licensed entities. Non-compliance is an independent enforcement ground: a licensed business that commingles client and own funds is in breach regardless of its compliance with other licence conditions.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance obligations that surround them. Digital assets are the entirety of our practice, and we act only for businesses – not retail clients. We map the licence stack across operating, custody and payment layers before you commit, and we work with allied counsel in relevant jurisdictions where local-counsel presence is required. To discuss your Turkish authorisation or cross-border payments structure, contact info@oboluslaw.com.

By Victor Olsen, Regulatory and Compliance Analyst – specialising in VASP licensing, payment institution authorisation and cross-border regulatory compliance for digital-asset businesses.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours