Turkey's crypto sector reached a regulatory inflection point when the country's crypto-asset service provider rules took effect, placing AML (anti-money laundering) obligations – including a version of the Travel Rule (the obligation to pass originator and beneficiary data with a value transfer) – squarely on every firm handling digital assets from Turkish soil or serving Turkish customers. A business that reads the obligation too narrowly, or that relies on an offshore licence as a substitute for local compliance architecture, faces enforcement by the Capital Markets Board (SPK, the Sermaye Piyasası Kurulu), MASAK (Turkey's financial intelligence unit) and the banking counterparties that are themselves under supervision. The cost of that miscalculation is measured in frozen payment rails, lost correspondent-bank relationships and, in serious cases, criminal AML exposure for responsible officers. This page sets out what a sound Travel Rule compliance program looks like under Turkish crypto-asset law, how it interacts with cross-border AML obligations, and where foreign operators most commonly misread the requirement.
What is the legal basis for Travel Rule obligations in Turkey?
Turkey's Travel Rule obligation flows from the country's crypto-asset service provider (CASP) licensing regime introduced under legislation amending the Capital Markets Law, administered by the SPK (Capital Markets Board of Turkey), and from Turkey's AML/CFT framework supervised by MASAK (Mali Suçları Araştırma Kurulu). The FATF Recommendation 15 standard – which requires VASPs to collect, verify and transmit originator and beneficiary information alongside virtual-asset transfers – was adopted into Turkish domestic rules as part of Turkey's FATF compliance program. Turkey was placed on the FATF grey list in 2021 and subsequently undertook a legislative and supervisory reform program; the crypto-asset licensing law was a central element of that response. Turkey was removed from the grey list in June 2024 – a milestone that reflects the depth of the regulatory changes made, including VASP registration requirements and the AML obligations that sit around them.
Under the applicable CASP provisions, a firm that operates a virtual-asset exchange, provides custody, or executes transfers involving digital assets on behalf of customers is a regulated entity. That entity must implement a Travel Rule compliance program – a documented set of procedures that captures the required data at transaction initiation, screens it against sanctions lists, verifies counterparty VASP status, and transmits the data to the receiving institution in a form that satisfies both Turkish and receiving-jurisdiction requirements. The threshold below which the obligation may be reduced is set by MASAK guidance; until a specific threshold is formally confirmed in updated guidance, operators should treat every outgoing transfer as subject to full Travel Rule procedures.
The SPK and MASAK collectively form the supervisory axis for crypto AML in Turkey. The SPK holds licensing authority over CASPs; MASAK holds AML/CFT examination authority and can impose administrative penalties and refer criminal matters. A compliance program that satisfies one authority but not the other is structurally incomplete.
OBOLUS advises businesses that are building or auditing a Travel Rule program for the Turkish market. The process above describes the standard regulatory path. Your entity structure, the jurisdictions your counterparty VASPs operate in, and your banking architecture each affect the analysis significantly.
Map your options – contact OBOLUS at info@oboluslaw.com for a scoped compliance assessment.
What does a compliant Travel Rule program look like in practice?
A compliant Travel Rule program in Turkey is built on four operational pillars: data collection, counterparty VASP verification, transmission, and records retention. Each pillar must be documented in a written AML policy that is reviewed and approved by the firm's MLRO (Money Laundering Reporting Officer) and presented to MASAK on examination. The following describes what each pillar requires in a Turkish context.
Data collection. For each outgoing transfer, the originating CASP must collect the full legal name, account identifier or wallet address, and – for transfers above the applicable threshold – additional identifying information such as date of birth or registered address for natural persons, or legal entity identifiers for corporate customers. This information must be captured in the firm's transaction management system at the point of instruction, not retrospectively. The data must be accurate: collection processes that rely on customer self-declaration without verification controls are routinely flagged on examination.
Counterparty VASP verification. Before transmitting Travel Rule data to a receiving institution, the originating CASP must verify that the recipient is itself a regulated entity – either under a domestic regime (such as the SPK/MASAK framework) or a recognized foreign VASP regime. Where the receiving entity cannot be verified as regulated, the Turkish CASP must apply enhanced due diligence or decline the transfer. In our practice, the counterparty verification step is the most common gap in programs built by operators that migrated from the pre-regulation era: they have collection workflows but no systematic counterparty onboarding process.
Transmission. The Travel Rule data must travel with the transaction. Turkish CASPs may use a compliant messaging protocol – several interoperability solutions operate in the market, including TRISA and VerifyVASP-compatible frameworks – but the choice of protocol must be documented and must meet the data-format requirements set out in MASAK guidance. Encryption, data integrity and access controls are minimum requirements. A transmission approach that relies on email or unstructured messages does not satisfy the obligation.
Records retention. Transaction records, Travel Rule data packets, counterparty verification files and MLRO decision logs must be retained for the period set by MASAK rules. Examination requests for historical records are common; the inability to produce a complete audit trail is treated as a standalone compliance failure, regardless of whether the underlying transfers were legitimate.
Who carries governance responsibility for AML compliance?
Every CASP licensed under the Turkish regime must designate a natural person as MLRO – a senior individual with day-to-day responsibility for the AML/CFT program and with direct reporting authority to the board or equivalent governing body. The MLRO is personally accountable for the adequacy of the compliance program and for the submission of suspicious transaction reports (STRs) to MASAK.
The MLRO must be based in Turkey or have operational availability that satisfies MASAK's oversight expectations. A compliance function run remotely from a group's offshore headquarters, without a named and identifiable Turkish-responsible officer, does not meet the governance standard. This point trips up a significant proportion of foreign-headquartered operators who assume that a group-level Chief Compliance Officer designation travels across borders automatically.
The MLRO must also be supported by written procedures, a risk-based customer due diligence (CDD) framework, a transaction monitoring system calibrated to the firm's specific product and customer risk profile, and a training program covering all relevant staff. MASAK expects evidence of all of these on examination – not a statement of intent but operational documentation of a functioning program.
The board or senior management of the CASP carries a residual governance duty. Where MASAK finds that the AML program was inadequate, enforcement action can reach beyond the MLRO to the individuals who approved the program, or who failed to allocate adequate resources to it.
How does a KYC framework integrate with Travel Rule data flows?
The KYC framework (know-your-customer identity verification and risk-scoring) is the foundation on which Travel Rule data quality depends. A CASP cannot produce accurate originator data for outgoing transfers if its onboarding process has not verified the customer's legal name, jurisdiction of residence and account ownership. The two programs must be designed together, not bolted onto each other after implementation.
Under the Turkish AML regime, customer due diligence at onboarding must include identity verification through document review and, for higher-risk customers, enhanced due diligence measures. For corporate customers, beneficial ownership verification is required: the CASP must identify and verify the ultimate beneficial owner (UBO) to the standard required by MASAK guidance. This aligns with FATF Recommendation 10 but the specific documentary requirements and the UBO threshold applicable in Turkey should be confirmed against current MASAK guidance, as they are subject to periodic update.
Transaction monitoring must be risk-based. The monitoring system must generate alerts for structuring behavior, unusual transaction velocity, transfers to or from high-risk jurisdictions and wallet addresses associated with sanctions targets or known illicit activity. Alert thresholds must be calibrated, documented and reviewed regularly. A monitoring system running on default settings without jurisdiction-specific calibration is consistently flagged on examination as a control weakness.
The integration point between KYC and Travel Rule data creates an important operational dependency: if a customer's identity data is updated (a change of legal name, correction of a date of birth error), the Travel Rule transmission records must also be correctable. Systems that hold KYC data and Travel Rule data in separate silos without a reconciliation process create a data-integrity gap that is difficult to resolve under time pressure.
How does a Turkish Travel Rule program interact with cross-border obligations?
A Turkish CASP that transacts with counterparty VASPs in EU member states, the United Kingdom, Singapore or the United States faces a bilateral Travel Rule obligation: its own Turkish-law requirements must align with the receiving jurisdiction's requirements, and vice versa for inbound transfers. Where those requirements diverge – on data fields, thresholds or transmission timing – the CASP must apply the stricter of the two or implement a dual-track process.
Under MiCA (the EU's Markets in Crypto-Assets Regulation, administered by ESMA and national competent authorities), EU-based CASPs transacting with Turkish counterparties will apply the EU Travel Rule rules on their side of the transfer. The Turkish CASP must be able to receive and process that data in a compatible format and must be able to transmit data in a format the EU CASP can ingest. Protocol interoperability is therefore not merely a technical preference – it is a cross-border legal requirement.
The FATF Travel Rule remains the baseline. Turkey's alignment with Recommendation 15, as part of its exit from the grey list, means that Turkish CASP data standards are substantively closer to those of major international counterparties than they were before the 2021-2024 reform period. In practice, however, Turkish CASPs still encounter friction when transacting with EU or UK counterparties that apply enhanced due diligence to jurisdictions without full FATF membership or that apply their own risk-based adjustments. Operators should expect that some receiving institutions will request additional documentation or apply an initial quarantine period to transfers from newly registered Turkish CASPs.
Banking interaction adds another dimension. A Turkish CASP's fiat settlement rails depend on correspondent banking relationships that are themselves subject to AML oversight. Correspondent banks review their CASP clients' Travel Rule programs as part of periodic due diligence. A program that is technically compliant with MASAK requirements but that lacks documentation meeting correspondent-bank expectations – typically a more demanding standard than the regulatory minimum – risks the loss of fiat settlement capacity. In our cross-border practice, we have seen operators lose banking relationships not because their program was deficient under Turkish law, but because the documentation was not packaged in the format the bank's compliance team expected.
For a scoped review of your cross-border Travel Rule architecture, including an assessment of EU and UK counterparty obligations, contact OBOLUS at info@oboluslaw.com or message us via t.me/oboluslaw.
A recent engagement: bringing a Travel Rule program into examination readiness
In a recent engagement, a digital-asset exchange registered under the Turkish CASP regime approached us in advance of a scheduled MASAK compliance examination. The firm had implemented a basic KYC workflow at launch but had not built a structured Travel Rule data-capture and transmission process. Its MLRO designation existed on paper but the individual had received no formal program documentation and had no documented escalation procedure for suspicious transaction reports. We conducted a gap analysis against the applicable MASAK requirements and FATF Recommendation 15, produced a written AML policy and Travel Rule procedures manual, restructured the transaction monitoring calibration, and prepared the MLRO for the examination interview. The examination concluded without a remediation notice. The firm subsequently used the same documentation package in its correspondent-bank due-diligence response, which had been pending for several months.
Where do Turkish CASP Travel Rule programs most often fail?
Examination findings and enforcement notices from MASAK and comparable FATF-member regulators consistently identify four failure patterns in CASP Travel Rule programs. Operators building or auditing a Turkish compliance program should stress-test against each of them.
Incomplete counterparty VASP onboarding. Operators assume that a licensed counterparty will have a compliant Travel Rule program and transmit data in an acceptable format. In practice, counterparty programs vary widely. A CASP that has not conducted its own assessment of counterparty Travel Rule capability, and documented that assessment, cannot demonstrate that its transmission obligations were met.
Threshold misapplication is a second common failure. The applicable data-collection threshold may differ between domestic transfers and cross-border transfers, and the applicable rules are subject to revision. Operators that hard-code a threshold figure without a process for monitoring regulatory updates risk applying an outdated figure at exactly the wrong moment.
Governance documentation gaps are the third failure pattern. A well-functioning compliance team whose procedures are not written, version-controlled and board-approved cannot demonstrate to an examiner that the program existed in the form described. MASAK examiners expect a document trail, not a verbal account of what the compliance function does.
Finally, a persistent myth in the market is that an offshore licence – a Cayman Islands, BVI or even an EU passported CASP authorisation – removes the Turkish Travel Rule obligation for a firm that is actually operating in Turkey or serving Turkish customers. It does not. The Turkish AML obligations attach to the activity, not to the incorporation address. A firm that holds a foreign licence but processes transactions for Turkish-resident customers, or that uses Turkish banking infrastructure, is within scope of the MASAK regime regardless of where the holding company is incorporated.
Which compliance program structure fits which operator profile?
The appropriate program architecture depends on the firm's licence category, transaction volume, counterparty mix and banking structure. The following decision branches describe the most common profiles we encounter.
Profile A – Newly licensed Turkish CASP, domestic focus. A firm with a fresh SPK licence, serving predominantly Turkish-resident retail customers and transacting primarily with domestic counterparties, should prioritize: a complete KYC onboarding workflow with MASAK-compliant identity verification; a transaction monitoring system calibrated to domestic risk indicators; a Travel Rule data-capture process for all outgoing transfers; and a written MLRO governance package. Cross-border transmission volume will be lower, but the counterparty VASP verification process must still be in place for any international transfers. Timeline for building a compliant program from a standing start is typically measured in weeks – longer if the transaction monitoring system requires custom integration with the core platform.
Profile B – Foreign-headquartered operator with Turkish user base. A firm incorporated offshore that serves Turkish customers, or that holds fiat settlement accounts in Turkey, must treat itself as within the MASAK perimeter for AML purposes regardless of its CASP licence jurisdiction. The program must include a Turkish-facing MLRO or compliance officer with genuine operational authority, a Travel Rule workflow that can interact with Turkish banking counterparties' documentation expectations, and a cross-border data-transmission capability for transfers between the Turkish customer base and foreign exchange accounts. The risk of enforcement in this profile is elevated: MASAK and the SPK have shown increasing willingness to examine firms that operate in the Turkish market through a foreign licensing structure without local AML compliance infrastructure.
Profile C – Established CASP expanding cross-border transfer volume. A CASP already holding a Turkish licence and operating a functioning domestic program, now scaling its cross-border transfer business, needs to layer on counterparty VASP onboarding procedures, dual-track Travel Rule transmission protocols (Turkish law plus receiving-jurisdiction requirements), and enhanced due diligence procedures for high-risk corridors. Correspondent-bank documentation must be updated to reflect the expanded scope. The incremental compliance build for this profile is less disruptive than a ground-up program but the counterparty onboarding workstream is typically underestimated.
Related at OBOLUS
- AML and Travel Rule compliance for digital-asset businesses – cross-border AML program design, MLRO support and Travel Rule architecture across major VASP regimes
- Transaction monitoring setup in Lithuania – MiCA-aligned monitoring program design for EU-licensed CASPs seeking passporting capacity
- Staking and rewards taxation for established operators – tax treatment of staking income for crypto businesses across multiple jurisdictions
FAQ
What does the Travel Rule require from a VASP?
The Travel Rule requires a VASP (virtual asset service provider) to collect, verify and transmit originator and beneficiary information – including legal names, account identifiers and, above applicable thresholds, additional identifying data – alongside each virtual-asset transfer. The receiving VASP must be able to receive and process that data. The obligation applies to both outgoing and incoming transfers and is grounded in FATF Recommendation 15, which Turkey has adopted into its domestic AML/CFT framework under MASAK supervision. The specific data fields and thresholds are set by national guidance and are subject to update.
Who must act as MLRO for a crypto firm?
Under the Turkish AML regime, every CASP must designate a named, senior individual as its MLRO (Money Laundering Reporting Officer). That person bears day-to-day responsibility for the AML program, signs off on suspicious transaction reports submitted to MASAK, and is the primary point of contact in a regulatory examination. The MLRO must have genuine authority within the firm – a nominal designation of a junior employee or a group-level officer with no Turkish operational role does not satisfy the governance standard. MASAK expects the MLRO to be identifiable, available and documentably responsible.
How do regulators audit crypto AML programs?
MASAK and comparable FATF-member regulators audit CASP AML programs through a combination of off-site document reviews and on-site examinations. Examiners typically request the written AML policy, the risk assessment, transaction monitoring calibration documentation, a sample of customer due-diligence files, Travel Rule transmission logs for a defined period, and MLRO decision records. They assess whether documented procedures match operational reality. Gaps between the written program and actual practice are treated as control failures. Correspondent banks conduct similar reviews and apply their own risk-appetite overlays, which are frequently more demanding than the regulatory floor.
OBOLUS is an independent digital-asset law boutique acting only for businesses. We advise exchanges, custodians, token issuers and funds on licensing across 70+ jurisdictions, on disputes and on-chain asset recovery across 25+ forums, and on the tax, banking and compliance that sit around them. Digital assets are the whole of our practice. We map the licence stack across operating, custody and payment layers before you commit – and we structure licensing, banking and tax as one mandate rather than three disconnected workstreams. To discuss your situation, contact info@oboluslaw.com.
By Victor Olsen, Regulatory & Compliance Analyst – specialist in VASP regulatory program design, AML/CFT compliance architecture and cross-border supervisory requirements for digital-asset businesses.
This publication is general information about the law and does not constitute legal advice. It is not a substitute for advice tailored to your circumstances. OBOLUS accepts no liability for action taken or not taken on the basis of this material. For advice on your situation, contact info@oboluslaw.com.