When assessing AML and KYC requirements in Türkiye, first determine the organisation's activity and the regulations it is subject to. MASAK obligations and sector-specific rules must be considered together.
Start with the institution type
Do not automatically apply the same process template to a bank, a payment or e-money institution and a crypto-asset service provider. Identify the relevant regulatory sources and the scope of activity.
Separate the controls
Identity verification, name screening, customer risk assessment and record-keeping serve different purposes. Define clearly which data supports which decision.
MASAK and the record-keeping approach
The retention provision under Law No. 5549 includes an eight-year period; data type and the triggering event matter. Assess the retention period in a software plan separately from the legal obligation. Refer to the current official texts and to a process review specific to your institution.
Sources
Sources were checked as part of the review dated 9 September 2026. Refer to the official text for current provisions.
This content is general information. Determine the requirements that apply to your institution from current official sources and your own assessment process.
See the related product scope → Compliance approach
Legichain — technology for identity verification, AML and blockchain screening. Contact: [email protected]