Regulation

AML and KYC in Türkiye: from institution scope to control flow

When assessing AML and KYC requirements in Türkiye, first determine the organisation's activity and the regulations it is subject to.

When assessing AML and KYC requirements in Türkiye, first determine the organisation's activity and the regulations it is subject to. MASAK obligations and sector-specific rules must be considered together.

Start with the institution type

Do not automatically apply the same process template to a bank, a payment or e-money institution and a crypto-asset service provider. Identify the relevant regulatory sources and the scope of activity.

Separate the controls

Identity verification, name screening, customer risk assessment and record-keeping serve different purposes. Define clearly which data supports which decision.

MASAK and the record-keeping approach

The retention provision under Law No. 5549 includes an eight-year period; data type and the triggering event matter. Assess the retention period in a software plan separately from the legal obligation. Refer to the current official texts and to a process review specific to your institution.

Sources

Sources were checked as part of the review dated 9 September 2026. Refer to the official text for current provisions.

This content is general information. Determine the requirements that apply to your institution from current official sources and your own assessment process.

See the related product scopeCompliance approach


Legichain — technology for identity verification, AML and blockchain screening. Contact: [email protected]