EST · MMXXVI
Home/Jurisdictions/Turkey/PSP and acquiring agreement in Turkey: Legal Requirements for Businesses
Banking, Payments & EMI Onboarding

PSP and acquiring agreement in Turkey: Legal Requirements for Businesses

Psp and acquiring agreement in Turkey. Cross-border digital-asset legal counsel for business – licensing, disputes and structuring. Talk to OBOLUS.

Securing payment service provider (PSP) and acquiring agreements in Turkey is a prerequisite for any digital-asset or fintech business that needs to move fiat money through Turkish rails – yet the regime governing those agreements has tightened considerably in recent years. Turkey's payments sector is regulated by the Bankacılık Düzenleme ve Denetleme Kurumu (BDDK, the Banking Regulation and Supervision Agency) and the Ödeme ve Menkul Kıymet Mutabakat Sistemleri, Ödeme Hizmetleri ve Elektronik Para Kuruluşları Hakkında Kanun – referred to here as the Payment Services Law – which governs licensed payment institutions and electronic money institutions operating in Turkey. For a crypto exchange, token issuer or cross-border payments platform, the path to Turkish fiat rails runs through that law and through the separate but overlapping framework that the Central Bank of the Republic of Turkey (CBRT) administers for payment systems oversight. Getting either relationship wrong – the PSP onboarding or the acquiring contract – exposes the business to enforcement, frozen settlement accounts and severed access to Turkish lira liquidity.

What is the regulatory basis for PSP and acquiring agreements in Turkey?

Turkey's payment services regime requires every entity providing payment initiation, account information, card acquiring or fund transfer services domestically to hold a licence issued under the Payment Services Law, supervised by the BDDK and, for systemic payment systems, the CBRT. A foreign business cannot simply contract with a Turkish bank or licensed acquirer without that institution satisfying itself that the counterparty's activity is either covered by the Turkish licence or lawfully exempted. In practice, that means a crypto company presenting itself as a PSP customer must demonstrate the legal basis for its own operations – both in Turkey and in its home jurisdiction – before the acquiring relationship can be established.

The CBRT separately oversees a prohibition on using crypto assets as a means of payment for goods and services within Turkey, introduced in 2021. That prohibition does not ban holding or trading digital assets; it bars crypto from functioning as a payment instrument for Turkish-resident counterparties. Any acquiring agreement touching Turkish merchants must therefore be structured to route only fiat consideration – not token value – through the acquirer's settlement infrastructure.

For an inbound digital-asset business, the first structural question is whether it is presenting as a VASP (virtual asset service provider) providing exchange or custody services, or as a licensed payment institution seeking to clear fiat on behalf of its users. Turkey maintains a separate VASP registration regime administered by the Capital Markets Board of Turkey (CMB, or SPK in Turkish). Since mid-2023 the SPK has required VASPs operating in or toward Turkish residents to register and comply with AML/CFT obligations aligned to FATF Recommendation 15 on virtual assets. An entity that conflates its VASP status with its PSP contracting can find itself ineligible for the acquiring relationship it needs.

The process above describes the standard path. Your facts – the entity, the user base, the banking structure – change the analysis substantially. For a scoped assessment of your entry approach, contact OBOLUS at info@oboluslaw.com.

Which businesses need a PSP or acquiring agreement in Turkey?

Any business collecting Turkish lira from Turkish-resident customers – through card payments, bank transfers or e-wallet credits – requires either its own Turkish payment institution licence or a contractual relationship with a licensed Turkish acquirer or payment institution that processes on its behalf. For digital-asset businesses the categories that most commonly trigger this need include: crypto exchanges that offer TRY trading pairs or TRY deposit and withdrawal; fiat-to-crypto on-ramp providers; stablecoin issuers settling in TRY; and cross-border remittance platforms routing through Turkey.

A business operating entirely offshore, with no Turkish-resident user base and no TRY settlement obligation, may be outside the immediate scope of the Turkish payment services regime. In our cross-border practice, however, we regularly advise clients who have grown a Turkish user base organically and only then discovered that their acquiring relationship was conditional on a Turkish regulatory status they had not obtained. The cost of that discovery – in compliance remediation, back-dated onboarding documentation and potential CMB engagement – consistently exceeds the cost of a pre-entry legal review.

The acquiring bank or licensed PSP will conduct its own due diligence on the counterparty's regulatory standing. Turkish payment institutions are subject to BDDK supervisory expectations that include knowing the regulatory status of their business customers. A crypto company that cannot present a coherent licence stack – showing its own VASP registration, its AML programme and its corporate structure – is routinely declined at the onboarding stage, regardless of the commercial relationship the business believed it had built.

How does the PSP onboarding and acquiring application process work?

The onboarding process for a digital-asset business seeking a Turkish acquiring relationship proceeds in three broad stages: pre-engagement legal preparation, the PSP due-diligence submission, and the ongoing contractual and compliance relationship. Each stage carries its own documentation burden, and the timeline for each depends heavily on how well-prepared the applicant is at the outset.

In the first stage, the business assembles its corporate and regulatory documentation. For a foreign-incorporated entity, this means certified constitutional documents, a group structure chart, audited financials, the AML/CFT programme, and evidence of the home-jurisdiction licence or registration. Where the business holds a CASP authorisation under MiCA (Markets in Crypto-Assets Regulation) from an EU member state, that authorisation carries significant weight in Turkish PSP due diligence – not as a direct passport, because Turkey is not part of the EU regulatory perimeter, but as evidence of a credible, externally supervised compliance framework. Similarly, a Singapore MAS licence under the Payment Services Act, or an FCA registration under the UK Money Laundering Regulations, provides a comparable comfort signal.

In the second stage, the PSP or acquiring bank runs its own KYB (know-your-business) process. This typically involves review of the business model, transaction flow analysis, anticipated volume, the jurisdictions of the underlying users, and the source of the funds being processed. For crypto businesses, acquirers will specifically examine whether TRY flows can be ring-fenced from flows denominated in or linked to crypto assets, so as to satisfy the CBRT prohibition on crypto-as-payment.

In the third stage, once the acquiring agreement is executed, the business enters an ongoing monitoring relationship. Turkish acquirers are subject to BDDK transaction-monitoring obligations; they expect their business customers to maintain equivalent standards. AML transaction reports, periodic compliance certifications and prompt notification of any material change to the business model are standard contractual expectations. Failure to maintain these obligations is the most common reason for mid-term account termination in our experience.

Timeline from first engagement to a live acquiring relationship is typically measured in weeks rather than months when the documentation pack is complete at the start. When the pack is incomplete – or when the business's regulatory status is unclear – the process can extend significantly, and some acquirers will decline to re-engage after a failed first submission.

How does the Turkish PSP requirement interact with cross-border licence and banking structures?

For most digital-asset businesses serving Turkey, the Turkish acquiring relationship is one node in a wider international payments architecture. The business may hold a MiCA CASP licence through a Malta or Lithuanian entity, process EUR settlements through a European EMI, and seek TRY acquiring through a separate Turkish arrangement. Each layer of that stack carries its own regulatory logic, and the layers must be legally consistent with one another.

A common structural tension arises from the CBRT's crypto-payment prohibition. A business that uses its EU-licensed entity to issue a stablecoin or tokenized e-money product, and then routes TRY acquiring through a Turkish PSP, must ensure that no element of the acquiring flow involves the crypto asset as consideration. The acquiring agreement should expressly address this – specifying that the Turkish PSP processes fiat currency only, with any crypto-leg of the transaction handled outside the Turkish acquiring infrastructure.

Tax interaction is a related consideration. Turkey taxes gains on crypto asset disposals, and Turkish-resident users of a foreign exchange may have reporting obligations that the exchange is expected to facilitate. A PSP contracting with a Turkish acquirer on behalf of a foreign exchange may find the acquirer asking questions about the exchange's own Turkish tax compliance posture. In our practice, we see this most acutely where the business has a Turkish subsidiary or a local representative – facts that can create Turkish permanent establishment exposure even if the licence sits offshore.

Banking for the Turkish entity itself, as distinct from the acquiring relationship, follows a separate path. Turkish banks apply heightened due diligence to crypto-related corporate customers. A business that has secured a VASP registration with the CMB and can demonstrate a clean AML programme stands materially better positioned in bank account opening than one that presents only an offshore licence. We regularly advise on structuring the banking approach in parallel with the PSP onboarding, because the two processes often involve the same decision-makers at the institution.

If a prior application stalled or an account was closed, a second review can surface the structural reason and the route back. To map the licence, banking and PSP stack for your Turkey entry, write to OBOLUS at info@oboluslaw.com.

What AML and VASP obligations apply to businesses using Turkish PSPs?

Turkey's AML/CFT framework for virtual asset service providers requires SPK-registered VASPs to implement customer due diligence, transaction monitoring, suspicious activity reporting and record-keeping obligations consistent with FATF standards. The Travel Rule – the obligation under FATF Recommendation 16 to pass originator and beneficiary identification data alongside a virtual asset transfer – applies to Turkish-registered VASPs above the applicable threshold, which varies and should be confirmed against current SPK guidance at the time of onboarding.

For a foreign VASP contracting with a Turkish PSP, the AML obligations cut both ways. The Turkish PSP must satisfy itself that the VASP customer's AML programme is adequate; the VASP must in turn ensure that its own Travel Rule compliance does not create a data-sharing conflict with the Turkish PSP's data-protection obligations under Turkish personal data law (KVKK). In practice, this means the acquiring agreement should contain explicit provisions on how customer data is handled when the PSP's settlement reporting intersects with the VASP's Travel Rule transmission records.

We have seen acquiring relationships declined – at an advanced stage – because the VASP's Travel Rule implementation used a counterparty identification method that the Turkish PSP's legal team considered non-compliant with KVKK. Addressing this mismatch in the agreement negotiation phase, rather than post-execution, saves both parties significant remediation effort.

A matter from our practice

In a recent engagement, an EU-licensed payments platform with a growing Turkish user base approached us after its Turkish acquiring relationship was terminated mid-contract. The acquirer cited changes to the platform's product set – specifically, the addition of a crypto-to-fiat conversion feature – without prior notification under the agreement's material-change clause. We reviewed the original agreement, identified that the change-notification obligation had not been clearly defined to cover product-layer changes (as distinct from corporate or regulatory changes), and drafted a remediation package including a revised product scope description and a compliance attestation addressed to the acquirer's BDDK compliance function. The acquiring relationship was reinstated within weeks of submission. The platform subsequently engaged us to draft a template material-change protocol for its PSP agreements across three European jurisdictions.

A common assumption: one offshore licence covers all markets

A common assumption among digital-asset businesses is that a single well-regarded offshore licence – a BVI FSC registration, a Cayman CIMA filing, or even an EU MiCA CASP – is sufficient regulatory infrastructure for global operations, including Turkey. That assumption is not correct in the Turkish context. Turkish PSPs and acquirers operate under BDDK supervision that requires them to assess the regulatory standing of their customers under Turkish law, not just under the law of the customer's home jurisdiction. An EU MiCA CASP authorisation is valuable evidence of regulatory credibility, but it does not substitute for Turkish CMB registration where that registration is required for the VASP's Turkish-resident activities.

The practical consequence is that a business relying solely on an offshore licence will typically find that Turkish PSPs request additional Turkish-specific documentation – CMB registration evidence, a Turkish AML policy addressing KVKK compliance, and in some cases a local legal opinion – before they will execute an acquiring agreement. Building those elements into the entry plan from the outset is materially cheaper than retrofitting them after a failed onboarding attempt.

Which structure fits your business profile?

Profile A – the established EU-licensed exchange seeking Turkish TRY acquiring: the optimal path typically involves a MiCA CASP authorisation in a passporting member state, a parallel CMB VASP registration for Turkish-resident users, and a bespoke acquiring agreement with a BDDK-licensed Turkish payment institution. The fiat and crypto legs of each transaction are contractually separated. Timeline to a live acquiring relationship, assuming complete documentation, is typically a matter of weeks. Key risk: the CBRT prohibition on crypto-as-payment must be explicitly addressed in the agreement.

Profile B – the early-stage token issuer or on-ramp provider without an EU licence: the path is longer. The business should first establish its home-jurisdiction regulatory status (whether a full CASP authorisation, an FCA MLR registration, a MAS DPT licence or a comparable regime). That licence then serves as the foundational document for Turkish PSP due diligence. Operating in the Turkish market without this foundation creates enforcement exposure both from the CMB and from the BDDK via the acquirer's supervisory obligations. Key risk: timeline is measured in months, not weeks, because the home-jurisdiction licensing must precede the Turkish onboarding.

Profile C – the business already banking in Turkey through a corporate account, seeking to upgrade to a formal acquiring relationship: this is the most common scenario in our practice. The business often has an informal TRY collection arrangement through a corporate account that the bank is now reconsidering. The upgrade path requires the CMB registration, a formal acquiring agreement with clear product scope, and a revised AML programme that addresses the bank's BDDK obligations. The informal arrangement should not be continued while the formal process is underway.

Related at OBOLUS

FAQ

Why do banks close crypto company accounts?

Banks close crypto company accounts primarily because the account holder's business model, transaction patterns or regulatory status do not align with the bank's own AML and supervisory obligations. In Turkey, BDDK-supervised banks must assess and continuously monitor the compliance posture of their business customers. A crypto company that cannot demonstrate a current CMB VASP registration, a documented AML programme and a clear separation of fiat and crypto transaction flows is treated as elevated risk. Material changes to the product set without notification are a frequent proximate cause of termination.

How can a VASP onboard with an EMI?

A VASP (virtual asset service provider) seeking to onboard with an EMI (electronic money institution) must present the EMI with evidence of its own regulatory status – typically a home-jurisdiction VASP licence or registration, an AML policy that meets the EMI's standards, and a clear business model description showing that fiat flows are separable from crypto activity. In Turkey specifically, the CMB VASP registration is expected by Turkish-licensed EMIs reviewing cross-border counterparties. Onboarding timelines depend on the completeness of the documentation and the EMI's own queue.

What does client-money safeguarding require?

Client-money safeguarding requires a licensed payment institution or EMI to hold funds received from customers in a manner that keeps those funds protected from the institution's own insolvency. In most leading jurisdictions – including under MiCA and the UK EMI regime – this means segregating client funds in a dedicated account at an authorised credit institution, or covering them with an equivalent insurance or guarantee arrangement. The specific safeguarding mechanics vary by jurisdiction and by licence category; Turkish payment institutions are subject to BDDK safeguarding requirements that should be reviewed against current regulatory guidance.

OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – so that your PSP and banking relationships are built on a foundation that holds under regulatory scrutiny. To discuss your Turkey entry or PSP onboarding, contact info@oboluslaw.com.

By Victor Olsen, Regulatory & Compliance Analyst – specialising in payment services licensing and VASP regulatory frameworks across cross-border digital-asset business structures.

This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.

Tell us the task — we'll map your options in 30 minutes.

Fixed-fee packages with defined scope and SLAs. The first call is free and under NDA. Business clients only.

Map your optionsinfo@oboluslaw.com · t.me/oboluslaw · reply < 2 hours