# AML and KYC in Türkiye: from institution scope to control flow

> When assessing AML and KYC requirements in Türkiye, first determine the organisation's activity and the regulations it is subject to.

Canonical: https://legichain.com/en/resources/aml-and-kyc-in-turkiye

When assessing AML and KYC requirements in Türkiye, first determine the organisation's activity and the regulations it is subject to. MASAK obligations and sector-specific rules must be considered together.

## Start with the institution type

Do not automatically apply the same process template to a bank, a payment or e-money institution and a crypto-asset service provider. Identify the relevant regulatory sources and the scope of activity.

## Separate the controls

Identity verification, name screening, customer risk assessment and record-keeping serve different purposes. Define clearly which data supports which decision.

## MASAK and the record-keeping approach

The retention provision under Law No. 5549 includes an eight-year period; data type and the triggering event matter. Assess the retention period in a software plan separately from the legal obligation. Refer to the current official texts and to a process review specific to your institution.

## Sources

- [Law No. 5549 on Prevention of Laundering Proceeds of Crime (Turkish)](https://masak.hmb.gov.tr/5549-sayili-suc-gelirlerinin-aklanmasinin-onlenmesi-hakkinda-kanun-2)

_Sources were checked as part of the review dated 9 September 2026. Refer to the official text for current provisions._

> This content is general information. Determine the requirements that apply to your institution from current official sources and your own assessment process.

**See the related product scope** → [Compliance approach](https://legichain.com/en/compliance)

---
Legichain — technology for identity verification, AML and blockchain screening. Contact: contact@legichain.com

