İstanbul, Türkiye | Publication | September 2026

New CBRT Rules on Remote Identity Verification

Authors: Dr. Ceylan Necipoğlu, LL.M. , CIPP/E, Zeynep Uçar

The Central Bank of the Republic of Türkiye (“CBRT”) introduced amendments concerning remote identity verification to the Regulation on Payment Services and Electronic Money Issuance and Payment Service Providers (“Regulation”) and the Communiqué on Information Systems of Payment and Electronic Money Institutions and Data Sharing Services of Payment Service Providers in the Area of Payment Services (“Communiqué”), published in the Official Gazette dated 4 September 2026 and numbered 33360.

The amendments were published following the Capital Markets Board’s (“CMB”) amendments on remote identity verification dated 3 September 2026. You may access our Client Alert dated 09.09.2026 on the CMB amendments [here].

Biometric Methods and Identity Documents with Electronic Authentication Capabilities

The amendment to the Regulation provides that biometric methods or identity documents with electronic authentication capabilities may be used to verify a customer’s identity through remote communication means.

The Communiqué was also amended to incorporate the biometric data of the person whose identity is being verified into the remote identity verification process.

Requirements for Verifying Identity Documents

For remote identity verification, the required information and identity document must be obtained from the person whose identity is being verified, and the authenticity of the identity document and the data and information contained therein must primarily be verified using near-field communication (NFC).

Where Verification via NFC Is Not Possible

Where verification via NFC cannot be performed for any reason, the identity document and the data and information contained therein must be verified using at least one of the following methods: optical character recognition (OCR), a card reader, or other methods determined by the CBRT upon obtaining the opinion of the Financial Crimes Investigation Board (MASAK).

In such cases, the security features that are visually distinguishable under white light, in the types and numbers prescribed under the Financial Crimes Investigation Board General Communiqué (Serial No. 19), must also be checked. The identity document and the data and information contained therein must be tested for authenticity, integrity, wear and tampering, and the front and back of the identity document must be visually inspected. The entire verification process must be recorded without interruption.

Remote Identity Verification Requirements Will Not Be Mandatory for Certain Transactions

Under the amendment to the Communiqué, the remote identity verification procedures described above will not be mandatory where remote communication means are used in connection with the processes relating to information, agreements, receipts and similar documents required for:

  • anonymous prepaid instruments;
  • one-off payment transactions that do not require identity verification under Law No. 5549 on Prevention of Laundering Proceeds of Crime and the relevant legislation and that do not constitute an ongoing business relationship; and
  • electronic money issuance and payment transactions specified in the first paragraph of Article 2.2.11 of the Financial Crimes Investigation Board General Communiqué (Serial No. 5).

Remote Identity Verification of Non-Turkish Nationals

Under the new provision added to the Communiqué, the identity of non-Turkish nationals may be verified remotely, in accordance with the principles set out in Article 4/C of the Financial Crimes Investigation Board General Communiqué (Serial No. 19), using an NFC-enabled passport that complies with International Civil Aviation Organization Standard No. 9303.

Effective Date

The amendments to the Regulation and the Communiqué entered into force on 4 September 2026.