Remote Identity Verification for Foreign Nationals: An Assessment of Recent Amendments to the MASAK General Communiqué
Introduction
The General Communiqué of the Financial Crimes Investigation Board (No. 19)[1] (“Communiqué”) has served, since its entry into force in 2021, as the foundational framework governing the procedures and principles applicable to remote identity verification methods used for the purposes of preventing the laundering of proceeds of crime and the financing of terrorism. While this framework was expanded in 2023 through the introduction of specific provisions addressing natural persons and legal entities registered with the trade registry, a regulation that would permit remote identity verification for foreign nationals had until recently been absent from the legislation.
The Communiqué Amending the General Communiqué of the Financial Crimes Investigation Board (No. 19) (No. 32)[2] (“Amending Communiqué”), published in the Official Gazette dated June 27, 2026, and numbered 33293, addresses this gap and simultaneously introduces a series of updates to various provisions of the existing framework. This article examines the principal changes brought about by the Amending Communiqué.
Remote Identity Verification Opportunity Introduced for Foreign Nationals
The most significant innovation introduced by the Amending Communiqué is the newly added Article 4/C. This provision makes it possible for the identity of individuals who are not Turkish nationals to be verified through remote methods, provided that certain technical and procedural conditions are satisfied. To benefit from this option, the individual concerned must hold a passport that complies with Standard 9303 of the International Civil Aviation Organization (ICAO) and is equipped with near field communication capability.
The regulation is designed not only to facilitate access by foreign nationals to the financial system in Türkiye but also to establish an effective control mechanism against money laundering and terrorist financing. Reflecting this dual purpose, Article 4/C sets out strict technical requirements for identity verification and places customers acquired through this method in a high-risk category from the outset.
Technical Requirements for Passport-Based Remote Identity Verification
Several core requirements stand out in the remote identity verification of foreign nationals via passport. The most critical of these is the mandatory near field communication verification. The identity information stored on the chip of the passport must be verified against the information appearing on the face of the document through near field communication. Where this verification cannot be completed, a business relationship may under no circumstances be established through remote identity verification. Passports without NFC functionality therefore fall outside the scope of the regulation, and this requirement functions as a decisive threshold in practice.
Identity verification must be conducted by personnel who have received specific training in passport-based remote verification through a video call. This requirement does not, however, prevent the use of artificial intelligence applications that satisfy the conditions set out in the Communiqué for purposes such as liveness detection or facial comparison. The capture of images showing both the individual and the information appearing on the passport during the video call is also mandatory.
Technical data derived from the electronic environment used during the identity verification process constitutes a separate layer of assessment. Elements such as IP and port information, device identifiers, geographic location, and browser data are evaluated together with the information on the passport within a risk-based framework, and where any circumstance giving rise to suspicion is identified, the process is immediately terminated. This approach moves identity verification beyond a purely technical confirmation exercise and transforms it into an ongoing risk analysis activity.
Address Verification and Transaction Restrictions
The rules on address verification represent one of the most notable features of the Amending Communiqué. The address information obtained during remote identity verification must be confirmed, within a period not exceeding three months, either through specific documentation or through publicly available databases of the relevant country and within a risk-based framework. This confirmation may be carried out using a certificate of residence, a utility bill for services requiring address-based subscription such as electricity, water, or natural gas issued in the name of the individual concerned and dated no more than three months prior to the transaction date, a document issued by any public authority, or publicly accessible databases of the foreign country in question.
The practical weight of address verification derives from the consequences attached to it. The Amending Communiqué explicitly provides that no funds transfer or cash withdrawal may be carried out until address verification has been completed. This transforms address confirmation from an abstract procedural obligation into a functional prerequisite that directly determines the scope of services that may be provided to the customer.
High-Risk Classification and Enhanced Measures
Customers acquired through passport-based remote identity verification are classified as high-risk from the very beginning and subjected to monitoring and control measures appropriate to that classification. This overarching principle gives rise to several concrete and interrelated obligations in practice.
Regarding funds transfers, a specific transfer requirement is imposed before any transaction may be carried out on the customer's account for the purpose of verifying identity. Accordingly, a funds transfer must be made from a domestic or foreign bank account or a bank or credit card consistent with the customer's identity information. Verifying that the distinguishing information in the transfer messages corresponds to the information obtained from the customer during the remote identity verification process is an inseparable part of this obligation. Where this process is not completed within the reasonable period to be determined by the obliged party in its procedures and guidelines, action must be taken in accordance with Article 22 of the Regulation on Measures against the Laundering of Proceeds of Crime and the Financing of Terrorism[3] (“Regulation”).
A restricted structure has also been adopted with respect to incoming and outgoing transfers on the account. Funds may be transferred into the account opened through this method only from bank accounts held by the individual in their own name abroad. Equally, outgoing transfers from the account to destinations outside of Türkiye may only be made to bank accounts held in that individual's name. These restrictions may be lifted only where identity verification is carried out face to face within the scope of Article 6(2) of the Communiqué. With respect to cash deposits and withdrawals, the provisions of Article 18 of the Regulation are to be observed. Obliged parties are also required to take necessary measures where transactions inconsistent with the customer's profile or the purpose of the business relationship are identified.
Foreign National Representatives of Legal Entities Registered with the Trade Registry
The scope of Article 4/C is not limited to individual customers. In the context of the remote identity verification of legal entities registered with the trade registry, the identity of a foreign national authorized to represent the legal entity may also be verified in accordance with the principles set out in this provision. In that case, obtaining the information required for authorized representatives under Article 7(1) of the Regulation is a prerequisite. This arrangement offers a practical solution to the difficulties that have arisen to date in the context of customer relationships with legal entities.
Administrative Obligations Imposed on Obliged Parties
The Amending Communiqué also places substantial administrative obligations on obliged parties that intend to accept customers through passport-based remote identity verification. These parties are required to take the necessary measures for identifying, grading, monitoring, and mitigating the relevant risks. In addition, the preparation of an implementation guide covering customer due diligence, risk management, and monitoring and control activities is mandatory. Obliged parties required to establish a compliance program must incorporate these measures into their institutional policies and procedures.
A significant restriction is imposed with respect to nationals of high-risk countries. Obliged parties may not accept nationals of countries they have designated as high-risk through this method.
Two distinct notifications and reporting obligations merit particular attention. The first is the requirement to notify the Presidency of MASAK within one month of commencing customer acceptance, covering the measures taken and the procedures and guidelines established. The second is the obligation to submit statistical information regarding customers accepted within this scope to the Presidency on a quarterly basis in the last month of each three-month period based on the calendar year. Together, these obligations create a continuous supervisory mechanism that allows the regulatory authority to closely monitor the implementation of the framework.
Changes Concerning Crypto Asset Service Providers
The Amending Communiqué also takes a notable step with respect to crypto asset service providers. By replacing the phrase "and Portfolio Management Companies" in Article 5/A(1) of the Communiqué with "Portfolio Management Companies and Crypto Asset Service Providers," crypto asset service providers are explicitly brought within the scope of this provision. As a result of this change, such providers will be able to conduct remote identity verification for the establishment of ongoing business relationships with their customers within the same framework as brokerage firms and portfolio management companies.
It is nonetheless important to emphasize that the regulatory framework applicable to crypto asset service providers does not present an entirely permissive picture. The fifth paragraph of Article 6, added to the Communiqué by an amendment made in late 2024, explicitly provides that crypto asset service providers that intermediate in the buying and selling or custody of privacy-based crypto assets may not conduct remote identity verification. This prohibition remains unchanged under the Amending Communiqué and continues to reinforce the regulatory distinction within the crypto asset ecosystem. The requirement that deposits and withdrawals be made through a bank or credit card account consistent with the customer's identity information also remains in force.
Other Amendments
In addition to the principal changes addressed above, the Amending Communiqué introduces several technical textual updates. The definition of "financial institution" is revised to refer directly to the entities listed in Article 3(1)(f) of the Regulation in place of the previous reference. The phrase "fourth paragraph of Article 4" in Article 5(2) of the Communiqué is amended to read "first paragraph of Article 4/A," aligning the provision governing YUVAM accounts with the current article structure. The replacement of the phrase "financial institutions and specified non-financial businesses and professions" in Article 6(3) with the term "obliged parties" extends the scope of application of the enhanced measures to a broader category of entities.
Conclusion
The Amending Communiqué fills a significant gap in the remote identity verification framework and makes it possible, under defined conditions, for foreign nationals to access the financial system in Türkiye through remote means. At the same time, this opportunity has been embedded within a layered supervisory framework that is consistent with the principles of combating money laundering and terrorist financing. When the NFC-enabled passport requirement, the trained personnel condition, the linkage of transaction capability to address verification, the high-risk classification, the restrictions on account movements, and the comprehensive notification obligations are considered together, it becomes clear that the regulation envisions a cautious rather than a permissive opening.
Obliged parties that plan to accept customers through this method would be well advised to conduct a thorough review of their technical infrastructure, internal policies and procedures, high-risk country lists, customer acceptance processes, and monitoring mechanisms in light of the requirements set out in the Communiqué. For crypto asset service providers, the broader trend suggests that the sector's position within the regulatory framework is becoming increasingly defined and that a layered compliance structure is taking hold.
- General Communiqué of the Financial Crimes Investigation Board (No. 19), Official Gazette dated 30.04.2021, No. 31470.
- Communiqué Amending the General Communiqué of the Financial Crimes Investigation Board (No. 19) (No. 32), Official Gazette dated 27.06.2026, No. 33293
- Regulation on Measures against the Laundering of Proceeds of Crime and the Financing of Terrorism, Official Gazette dated 09.01.2008, No. 26751.
All rights of this article are reserved. This article may not be used, reproduced, copied, published, distributed, or otherwise disseminated without quotation or Erdem & Erdem Law Firm's written consent. Any content created without citing the resource or Erdem & Erdem Law Firm’s written consent is regularly tracked, and legal action will be taken in case of violation.