Regal PartnersRegal Partners

Comprehensive Assessment of the Legislative Amendments on Remote Identification Dated 3–4 September 2026

|Legislation|Av. Nur Şentürk

I. Introduction

With the legislative packages published in the Official Gazettes dated 3 September 2026 and numbered 33359 and dated 4 September 2026 and numbered 33360, respectively, two sets of regulations concerning different segments of the financial sector, yet directly interconnected in terms of their subject matter and regulatory approach, entered into force.

Both sets of regulations expand the scope of the remote identification regime while introducing additional requirements aimed at enhancing the security of identity verification and strengthening risk management mechanisms. This information note aims to provide a comprehensive assessment of these two sets of regulations.

II. Procedures and Principles Regarding the Acceptance of Foreign Natural and Legal Persons as Customers Through Remote Identification Pursuant to the Capital Markets Board's Amendment Dated 3 September 2026

Through the Communiqué Amending the Communiqué on Remote Identification Methods to be Used by Intermediary Institutions, Portfolio Management Companies and Crypto-Asset Service Providers and the Establishment of Contractual Relationships in Electronic Environment (III-42.1) (III-42.1.b) (the "Amendment Communiqué"), published in the Official Gazette dated 3 September 2026 and numbered 33359, the Capital Markets Board of Türkiye ("CMB") introduced significant amendments concerning remote customer onboarding.

The Amendment Communiqué sets forth the procedures and principles governing the acceptance, through remote identification, of non-Turkish natural persons, legal persons satisfying certain conditions, and representatives of such eligible legal persons as customers of intermediary institutions, portfolio management companies and crypto-asset service providers ("CASPs").

Pursuant to the Amendment Communiqué, the identification of non-Turkish natural persons may be carried out using passports that comply with International Civil Aviation Organization ("ICAO") Standard 9303 and have near-field communication ("NFC") capability. In this context, the identity information contained in the electronic chip embedded in the passport must be verified against the information printed on the passport through NFC technology.

The identification interview must be conducted by personnel who have received specific training on identification procedures involving passports. The use of artificial intelligence-supported applications satisfying the requirements prescribed under the Communiqué for liveness detection or photographic comparison purposes does not eliminate the obligation to employ appropriately trained personnel.

Where the required matching cannot be successfully completed for any reason, an ongoing business relationship may not be established through remote identification. Accordingly, the ability to electronically read and verify the information stored on the passport chip has become one of the mandatory conditions for establishing an ongoing business relationship with foreign customers.

Following the assessment conducted by trained personnel, passport information must be evaluated on a risk-based basis, and foreign nationals onboarded through this method must be monitored within the high-risk customer category. If any suspicious or inconsistent matter is identified during the relevant checks, the remote identification process must be terminated.

The address information of foreign customers whose identities have been verified remotely must be verified within three months at the latest. Address verification may be carried out through a certificate of residence, an electricity, water or natural gas bill issued in the customer's name within the preceding three months, documents issued by public authorities, or publicly accessible databases maintained by the authorities of the relevant country.

Until the address verification process has been completed, no transfer of funds or crypto-assets may be made to or from the customer's account, nor may any transfer of capital market instruments be carried out. Accordingly, a foreign customer may not conduct transactions until the address verification process has been completed.

With respect to foreign customers classified as high-risk, additional measures must be implemented where transactions inconsistent with the customer's profile, the purpose of the business relationship or the expected transaction volume are identified. Accordingly, while foreign customers are granted remote access, enhanced compliance requirements apply in relation to customer acceptance, transaction monitoring and suspicious transaction controls.

Funds transferred to the accounts of foreign customers identified remotely by means of their passports may only originate from bank accounts opened in the relevant customer's own name outside Türkiye. Transfers originating from non-bank financial institutions will not be accepted. Similarly, outgoing transfers from the customer's account may only be made to a bank account registered in the customer's own name.

These requirements are intended to prevent accounts from being funded by third parties and transfers from being made to third parties. Such fund transfers must be carried out exclusively through the SWIFT system.

Where the foreign customer is a legal person, the identity of the person authorised to represent the legal entity must be verified in accordance with the provisions of the Communiqué, while the representative's authority must be verified against up-to-date information obtained through the Central Registry System ("MERSIS") and/or the Turkish Trade Registry Gazette.

In respect of persons considered to present a higher risk, or where suspicious circumstances exist, a copy of the representative's signature circular may be requested, signature specimens may be compared, and the authenticity of the relevant document may additionally be verified through notarisation.

Information concerning the legal person must be matched against up-to-date information obtained from MERSIS, the Turkish Trade Registry Gazette and the databases of the Revenue Administration. In addition, the necessary measures must be taken to identify the beneficial owner of the legal person.

For the purposes of identifying the beneficial owner, the shareholding thresholds prescribed for beneficial owners of legal persons under Article 17/A of the Regulation on Measures Regarding Prevention of Laundering Proceeds of Crime and Financing of Terrorism, numbered 2007/13012, including shareholders holding more than 25% of the shares, must be taken into consideration.

Where the beneficial owner cannot be identified, inconsistencies exist between the information provided, or suspicious circumstances arise, the remote identification process must be terminated.

Information concerning persons accepted as customers through remote identification, together with their portfolio sizes and investment amounts, must be reported to the Financial Crimes Investigation Board ("MASAK") in the final month of each calendar quarter.

Accordingly, CASPs intending to onboard foreign customers will be required to align their remote identification procedures, fund transfer restrictions, customer risk classifications, technical control systems and MASAK reporting processes with the Amendment Communiqué.

III. Introduction of Biometric Methods and NFC-Enabled Identity Documents for Remote Identification by Payment and Electronic Money Institutions Pursuant to the Regulations Dated 4 September 2026

The Regulation on Payment Services and Electronic Money Issuance and Payment Service Providers (the "Regulation"), published in the Official Gazette dated 1 December 2021 and numbered 31676, and the Communiqué on the Information Systems of Payment and Electronic Money Institutions and the Data Sharing Services of Payment Service Providers in the Field of Payment Services (the "Communiqué"), published in the same Official Gazette, set forth the technical principles governing customer onboarding and identification processes conducted through remote communication channels by payment institutions and electronic money institutions.

Two separate regulatory instruments published in the Official Gazette dated 4 September 2026 and numbered 33360, which entered into force on the date of publication, amended the provisions of the Regulation and the Communiqué concerning remote identification.

The common feature of these amendments is that remote identification processes are no longer limited solely to video-based interviews and may also be conducted through biometric methods and identity documents equipped with NFC functionality.

Under the new framework, identity verification in customer onboarding processes conducted through remote communication channels may be performed using both biometric methods and identity documents with electronic identity verification capabilities.

The expression "biometric data" has been added to the first paragraph of Article 22 of the Communiqué, thereby requiring internet-based methods used for remote identification to enable verification of the individual's biometric data.

Under the new framework, the necessary information and identity document must first be obtained from the natural person whose identity is to be verified. The authenticity of the identity document must then, as a general rule, be verified through NFC technology. In this context, the relevant data and information, particularly security features, photographs and signatures, must be tested in terms of authenticity, integrity and possible tampering, and the entire process must be recorded without interruption.

Where NFC cannot be used, an alternative verification process subject to the same recording requirements may be conducted using optical character recognition, a card reader, or another method to be determined by the Central Bank of the Republic of Türkiye (the "Bank"), upon obtaining the opinion of MASAK.

The requirement to apply the remote identification procedure set out under the relevant provision has been removed for processes conducted through remote communication channels in relation to single payment transactions for which identification is not mandatory and which do not constitute an ongoing business relationship in connection with anonymous prepaid instruments, as well as electronic money issuance and payment transactions specified under Article 2.2.11 of MASAK General Communiqué (Serial No. 5).

The identification of non-Turkish natural persons may also be carried out remotely, in accordance with the principles set forth under Article 4/C of MASAK General Communiqué (Serial No. 19), by using passports compliant with ICAO Standard 9303 and equipped with NFC functionality.

IV. Assessment and Conclusion

Although the CMB and Central Bank regulations published in the Official Gazettes dated 3 September 2026 and 4 September 2026 were issued by different regulatory authorities and apply to different categories of obliged entities, they constitute complementary components of a broader regulatory framework sharing two principal objectives: strengthening the security and verification standards applicable to remote identification processes and enabling non-Turkish natural persons to undergo remote identification using ICAO 9303-compliant, NFC-enabled passports.

While the CMB framework primarily regulates the acceptance of foreign natural and legal persons as customers, their risk classification and the restrictions applicable to fund transfers, the Central Bank regulations establish the technical and procedural framework governing the use of biometric verification methods and NFC-enabled identity documents by payment and electronic money institutions.

Accordingly, all relevant obliged entities should carefully identify the regulatory framework applicable to their respective activities and align their remote identification procedures, risk management processes and MASAK reporting obligations with the applicable legislation.

Establish a Legal Solution Partnership With Us

Contact Us