İstanbul, Türkiye | Publication | July 2026

Remote KYC Regulation for Non-Resident Foreign Nationals

Authors: Dr. Ceylan Necipoğlu, LL.M. , CIPP/E, Selin Yılmaz

The Financial Crimes Investigation Board (“MASAK“), operating under the Ministry of Treasury and Finance, has published the Communiqué (Serial No: 32) Amending the MASAK General Communiqué (Serial No: 19), introducing a comprehensive framework for the remote identification of non-Turkish individuals residing abroad. Under the new rules, Crypto Asset Service Providers (“CASPs“) have also been expressly included among the obliged entities permitted to conduct remote identity verification.

The new framework enables the remote onboarding of foreign customers while simultaneously imposing significant compliance and operational obligations on CASPs and other obliged financial institutions.

  1. Key Requirements Introduced by the Regulation
  1. Passport Requirements and Technological Infrastructure

Remote identity verification may only be carried out using NFC-enabled passports that comply with ICAO Doc 9303 standards. Institutions must ensure that their systems are capable of reading and verifying the data stored on the passport chip. If the chip data cannot be successfully verified, the customer relationship cannot be established through remote identification.

  1. Video Identification Process

Identity verification must be conducted through a live video interview by personnel specifically trained for passport-based remote identification. The use of artificial intelligence-based solutions for liveness detection and facial comparison is permitted, provided that the applicable regulatory requirements are satisfied.

  1. Address Verification

The customer’s declared address must be verified within three months on a risk-based approach by using official residence documents, recent utility bills, public authority records or publicly available databases of the relevant jurisdiction. Until the address verification is completed, the customer may not perform fund transfers or cash withdrawals.

  1. Risk Management and Technical Controls

Technical information collected during the onboarding process, including IP address, device identification, geolocation, browser information and similar data, must be assessed together with the passport information as part of a risk-based review. Where any suspicious circumstance is identified, the remote identity verification process must be immediately terminated.

  • High-Risk Customer Classification

Customers onboarded through this method must automatically be classified as high-risk customers and be subject to enhanced monitoring and control measures throughout the business relationship.

  • Initial Funding and Transfer Restrictions

The initial funding must originate from a bank account or bank/credit card registered in the customer’s own name and consistent with the verified identity information. Furthermore, incoming transfers may only be made from the customer’s own foreign bank accounts, while outgoing transfers may only be sent to bank accounts held in the customer’s own name.

  • High-Risk Jurisdictions

Obliged entities are prohibited from onboarding, through this remote identification method, individuals who are nationals of countries designated as high-risk under their internal risk assessment framework.

  • Notification and Reporting Obligations

Within one month following the commencement of customer onboarding under this framework, obliged entities must notify MASAK of the security measures, internal procedures and implementation guidelines adopted for the process.

In addition, statistical information regarding customers onboarded through this method must be submitted to MASAK on a quarterly basis.

  1. Compliance Considerations

The new regulation requires obliged entities to comprehensively review and update their existing remote customer onboarding processes. In particular, institutions should:

  • Update their internal policies and procedures;
  • Establish operational processes specific to passport-based remote identity verification;
  • Prepare dedicated implementation guidelines for this onboarding method;
  • Ensure that their technological infrastructure supports NFC-enabled passport verification; and
  • Enhance their risk management, monitoring and control mechanisms in line with the new regulatory requirements.

Accordingly, CASPs intending to onboard foreign customers remotely should promptly review their operational processes and internal compliance documentation to ensure full alignment with the new regulatory framework