AML and KYC in Turkey are governed by a comprehensive legal framework that has undergone significant reform in recent years, driven by FATF recommendations and Turkey';s own legislative agenda. Businesses operating in Turkey - whether banks, payment institutions, crypto asset service providers or designated non-financial businesses - face binding obligations to identify customers, monitor transactions and report suspicious activity. Non-compliance carries serious administrative and criminal consequences. This guide covers the legal foundations, current obligations, recent regulatory changes, sector-specific requirements, enforcement trends and practical steps for foreign-owned businesses operating in Turkey.
The primary statute governing anti-money laundering in Turkey is Law No. 5549 on the Prevention of Laundering Proceeds of Crime, which entered into force in the mid-2000s and has been amended several times since. This law establishes the core obligations: customer due diligence, record-keeping, suspicious transaction reporting and internal compliance programmes. It applies to a broad range of obliged entities, including banks, insurance companies, capital markets intermediaries, money transfer operators, real estate agents, lawyers, accountants and notaries.
The implementing regulation is the Regulation on Measures Regarding the Prevention of Laundering Proceeds of Crime and the Financing of Terrorism, issued by the Council of Ministers and updated periodically. This regulation specifies the detailed procedures for customer identification, enhanced due diligence, politically exposed persons screening and the risk-based approach that obliged entities must adopt.
The competent authority is the Financial Crimes Investigation Board, known by its Turkish acronym MASAK, which operates under the Ministry of Treasury and Finance. MASAK issues binding communiqués, conducts on-site inspections, receives suspicious transaction reports and coordinates with international counterparts. Sector-specific supervisors - the Banking Regulation and Supervision Agency (BDDK), the Capital Markets Board (SPK) and the Insurance and Private Pension Regulation and Supervision Agency (SEDDK) - also carry out AML compliance inspections within their respective sectors.
KYC in Turkey requires obliged entities to verify the identity of every customer before establishing a business relationship or executing a transaction above applicable thresholds. For natural persons, this means collecting and verifying full name, date of birth, nationality and identity document details. For legal entities, obliged entities must identify the company itself and determine the ultimate beneficial owner - defined as any natural person who directly or indirectly owns or controls more than twenty-five percent of the shares or voting rights, or who otherwise exercises effective control.
The beneficial ownership requirement is one of the most demanding aspects of KYC in Turkey. Foreign companies establishing subsidiaries or branches must provide a chain of ownership documentation that traces back to the natural person at the apex of the structure. A common mistake made by foreign founders is submitting corporate ownership charts without accompanying certified translations and apostilles, which causes delays in account opening and licensing processes.
Enhanced due diligence applies in several circumstances:
Simplified due diligence is permitted in limited circumstances, such as for certain low-risk financial products or publicly listed companies subject to disclosure requirements, but obliged entities must document their risk assessment before applying it.
Record-keeping obligations require all customer identification data and transaction records to be retained for at least eight years from the date the business relationship ends or the transaction is completed. Many businesses underestimate the practical burden of this requirement, particularly when dealing with large volumes of occasional transactions.
Turkey';s AML framework has evolved substantially in recent periods, largely in response to FATF';s monitoring process. After being placed on the FATF grey list, Turkey undertook a series of legislative and institutional reforms to address identified deficiencies. The country was subsequently removed from the grey list, reflecting progress in areas including beneficial ownership transparency, supervision of designated non-financial businesses and the effectiveness of suspicious transaction reporting.
Among the most significant recent changes is the extension of AML obligations to crypto asset service providers. MASAK issued a communiqué bringing virtual asset service providers - exchanges, wallet providers and similar platforms - within the scope of Law No. 5549. These providers must now register with MASAK, implement full KYC procedures, monitor transactions and file suspicious transaction reports. The Capital Markets Law was also amended to bring crypto asset trading platforms under SPK supervision, adding a second layer of regulatory oversight.
Real estate agents and construction companies have faced tightened obligations. MASAK communiqués now require real estate professionals to conduct customer due diligence before any transaction, not merely at the point of contract signing. This change addresses a historically weak point in Turkey';s AML architecture, where property transactions were a recognised vulnerability.
The legal profession and accounting sector have also seen increased scrutiny. Lawyers and independent accountants acting in certain capacities - such as forming companies, managing client funds or advising on real estate transactions - are classified as obliged entities and must comply with KYC and reporting requirements, subject to professional privilege limitations defined by their respective bar and chamber rules.
If you are assessing your firm';s compliance posture under the current framework, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.
Suspicious transaction reporting is a cornerstone of Turkey';s AML regime. Obliged entities must file a suspicious transaction report with MASAK whenever they have knowledge, suspicion or reasonable grounds to suspect that a transaction or attempted transaction involves proceeds of crime or is connected to terrorist financing. There is no minimum threshold for reporting - even small transactions must be reported if suspicion arises.
Reports must be filed electronically through MASAK';s dedicated reporting system. The obligation to report arises regardless of whether the transaction is ultimately completed. Tipping off the customer that a report has been filed is prohibited and constitutes a criminal offence. In practice, many compliance officers in Turkey struggle with the tipping-off prohibition when a customer asks why a transaction has been delayed or refused.
Internal compliance programmes are mandatory for obliged entities above certain size thresholds. These programmes must include:
Smaller obliged entities - such as individual accountants or small real estate agencies - are not required to maintain a full compliance programme but must still fulfil all customer identification, record-keeping and reporting obligations. A non-obvious requirement for foreign-owned businesses is that the compliance officer must be resident in Turkey and accessible to MASAK for inspections and inquiries.
Foreign businesses entering Turkey encounter AML and KYC requirements at multiple points in the establishment and operational lifecycle. When opening a corporate bank account, Turkish banks apply their own internal KYC procedures on top of the statutory minimum, often requesting additional documentation such as source-of-funds declarations, group structure charts and reference letters from correspondent banks. Account opening timelines can range from a few weeks to several months depending on the bank';s risk appetite and the complexity of the ownership structure.
Payment institutions and electronic money institutions licensed by the BDDK face particularly detailed AML obligations. They must implement real-time transaction monitoring systems, maintain sanctions screening against Turkish and international lists, and report to both MASAK and the BDDK. The BDDK has issued specific guidance on the minimum technical standards for transaction monitoring, and inspectors assess whether the system generates meaningful alerts rather than simply producing large volumes of unreviewed notifications.
In the capital markets sector, the SPK requires licensed intermediaries to conduct KYC on all clients before executing trades, with enhanced procedures for clients trading in complex or illiquid instruments. Portfolio management companies and investment advisors must also assess the suitability of products for clients, which intersects with KYC data collection in practice.
For businesses in the real estate sector - whether developers, agents or legal advisors facilitating transactions - the current framework requires due diligence on both buyer and seller, identification of the source of funds and filing of suspicious transaction reports where warranted. Foreign buyers of Turkish real estate are a particular focus area, given the volume of cross-border transactions in this market.
Two practical scenarios illustrate the compliance challenges. First, a European fintech company establishing a Turkish subsidiary to offer payment services must obtain a BDDK licence, appoint a resident compliance officer, build a transaction monitoring system meeting BDDK technical standards and register with MASAK - all before processing a single transaction. Second, a foreign private equity fund acquiring a Turkish company through a local holding structure must ensure that the acquiring entity';s beneficial ownership is fully documented and disclosed to the target company';s bank, which will re-run its KYC process on the new ownership structure after closing.
MASAK and sector supervisors have increased enforcement activity in recent periods. Administrative fines for AML violations are calculated as a percentage of the obliged entity';s annual turnover or as fixed amounts, depending on the nature of the breach. Serious or repeated violations can result in licence suspension or revocation. Criminal liability under Law No. 5549 extends to natural persons - including compliance officers and senior managers - who knowingly facilitate money laundering or fail to fulfil reporting obligations.
The most commonly cited enforcement findings in MASAK inspection reports include inadequate beneficial ownership identification, failure to apply enhanced due diligence to high-risk customers, poor-quality suspicious transaction reports that lack sufficient detail, and gaps in employee training records. Foreign-owned businesses are not exempt from these findings; in fact, they are sometimes at greater risk because their compliance teams may be unfamiliar with Turkish-specific requirements.
Practical risk management for obliged entities operating in Turkey should include a periodic gap analysis against current MASAK communiqués, which are updated more frequently than the primary legislation. Communiqués address specific sectors and risk categories and carry the same binding force as the underlying regulation. Many businesses discover during MASAK inspections that they have been complying with an outdated version of a communiqué without realising it had been amended.
A common mistake among foreign-owned entities is delegating AML compliance entirely to a local service provider without maintaining adequate oversight from the group compliance function. Turkish law places responsibility on the obliged entity itself, not on any outsourced provider. Outsourcing certain functions - such as customer identification technology or training delivery - is permissible, but the obliged entity remains fully liable for the quality of the output.
What are the main KYC thresholds that trigger customer identification in Turkey?
Turkish law requires obliged entities to identify customers before establishing any business relationship, regardless of transaction size. For occasional transactions without an ongoing relationship, identification is required when the transaction amount reaches or exceeds a threshold set by MASAK communiqué for the relevant sector. In practice, most obliged entities apply KYC to all customers from the outset rather than relying on thresholds, because the risk of misclassifying a relationship as "occasional" is significant. Enhanced due diligence applies whenever a transaction is unusually large or complex, even if the customer has already been identified. The safest approach is to treat every new customer as requiring full identification until a risk assessment confirms otherwise.
How long does it typically take to complete AML compliance setup for a new business in Turkey?
The timeline depends heavily on the sector and the complexity of the ownership structure. A straightforward trading company with a simple ownership chain can complete basic KYC registration and internal policy documentation within four to eight weeks. A regulated entity - such as a payment institution or crypto asset service provider - faces a longer process because MASAK registration and sector supervisor licensing must be completed before operations begin, which can take several months in total. Building a compliant transaction monitoring system and training staff adds further time. Foreign-owned businesses should budget for additional weeks to gather and certify the ownership documentation that Turkish banks and regulators require.
Does Turkey';s AML framework apply to foreign companies with no physical presence in Turkey?
The primary obligations under Law No. 5549 apply to entities that are either incorporated in Turkey or carry out regulated activities in Turkey. A foreign company with no Turkish entity and no Turkish-licensed activity is generally not directly subject to MASAK oversight. However, any Turkish bank, payment institution or other obliged entity that provides services to a foreign company will apply KYC to that foreign company as its customer. Foreign companies that acquire Turkish assets, open Turkish bank accounts or engage Turkish intermediaries will therefore encounter KYC requirements indirectly. If a foreign company establishes a branch or subsidiary in Turkey, that entity becomes an obliged entity in its own right and must comply fully with Turkish AML law.
AML and KYC compliance in Turkey is a substantive and evolving obligation that affects a wide range of businesses, from banks and fintechs to real estate professionals and legal advisors. The framework is grounded in Law No. 5549 and implemented through MASAK communiqués that are updated regularly. Recent reforms have extended obligations to crypto asset providers and tightened requirements for real estate and professional services sectors. Foreign-owned businesses face particular challenges around beneficial ownership documentation and the appointment of resident compliance officers. Staying current with MASAK guidance and conducting periodic internal reviews are essential to managing enforcement risk.
VLO Law Firms advises international clients on AML and KYC matters in Turkey. We can assist with compliance programme design, MASAK registration, beneficial ownership documentation, suspicious transaction reporting procedures and regulatory gap analyses. To request a consultation, contact: info@vlolawfirm.com