· Gokcen OZKAN
Remote Identity Verification in Türkiye: Regulatory Timeline, AI and CASP Obligations
Knowing your customer is the oldest problem in financial regulation. We have moved from photocopying an ID at a bank counter to reading a chip-enabled ID with a phone and opening an account in thirty seconds. That transition did not happen on its own — every step of it was opened by a piece of legislation.
Below is that timeline with its dates. Then we look at two things in particular: how AI-based verification entered Turkish regulation, and why crypto asset service providers are today the sector under the heaviest compliance pressure.
Timeline
11 October 2006 — The foundation: Law No. 5549
The Law on Prevention of Laundering Proceeds of Crime was adopted and published in Official Gazette No. 26323 of 18 October 2006. It defines the categories of obliged parties and the duty to identify customers; every piece of secondary legislation on remote identification in force today derives its authority from it.
The Law does not say how identification is to be performed, only that it must be. Leaving the method to secondary legislation was the structural choice that opened the door to digitalisation fifteen years later.
Full text of Law No. 5549 — Turkish Legislation Information System
1 April 2021 — The BRSA Regulation
The Regulation on Remote Identification Methods to be Used by Banks and the Establishment of Contractual Relationships in Electronic Environment was published in Official Gazette No. 31441 and entered into force on 1 May 2021. The draft had been opened to public consultation on 21 September 2020.
This is the first text to systematically regulate remote identification and the electronic conclusion of contracts in Türkiye. Concepts such as identification by video call, chip verification of the identity document and liveness detection entered Turkish regulation through it.
BRSA — Regulation announcement and full text
30 April 2021 — MASAK General Communiqué No. 19
MASAK, the Financial Crimes Investigation Board, set out the procedures and principles of remote identification in General Communiqué No. 19. While the BRSA regulation is specific to banks, the MASAK communiqué widens the group of obliged parties.
It carried an important limit, however: the communiqué confined remote identification to Turkish national natural persons and sole traders. Companies were outside its scope.
MASAK Communiqué No. 19 (consolidated text as amended by Communiqué No. 24)
1 May 2021 — The same day: crypto asset service providers become obliged parties
On the day the BRSA Regulation entered into force, Presidential Decision No. 3941, published in Official Gazette No. 31471, added crypto asset service providers (CASPs) to Article 4 of the Measures Regulation, making them obliged parties under Law No. 5549.
The coincidence of dates is not accidental: as the legal infrastructure for remote identification was being built, the sector that would need it most was brought into scope at the same moment. A field previously outside regulation became subject overnight to the same know-your-customer duties as banks.
31 August 2022 — BRSA revision
The BRSA revised technical requirements in the regulation following feedback from implementation.
5 April 2023 — Legal entities come through the door
An amendment to the Regulation on Measures Regarding Prevention of Laundering Proceeds of Crime and Financing of Terrorism opened remote identification to legal entities registered in the trade registry when establishing a continuous business relationship.
This is the largest break in the timeline. Until then remote customer acquisition was a retail banking matter; with this change it moved to the corporate side.11 August 2023 — MASAK Communiqué No. 24 and artificial intelligence
Communiqué No. 24, amending Communiqué No. 19, was published in Official Gazette No. 32276 and entered into force on the date of publication. It did two things: it added legal entities registered in the trade registry to the definition of customer — joint stock, limited, collective and commandite companies and cooperatives can now be onboarded remotely by video call — and it permitted the use of artificial-intelligence-based methods in remote identification.
The second point is usually passed over in a single sentence. Its sectoral effect is in fact larger than the first.
MASAK — Amendments to remote identification
2 July 2024 — Law No. 7518: crypto enters CMB supervision
The Law Amending the Capital Markets Law (No. 7518) was published in Official Gazette No. 32590. Crypto asset service providers were brought under the regulatory and supervisory authority of the Capital Markets Board (CMB) and their activities made subject to licensing.
A CASP now answers to two separate authorities: MASAK for anti-money-laundering and the CMB for market regulation.
2025 — CMB secondary legislation and remote identification
The CMB issued communiqués on the establishment, activities and operating principles of CASPs. Under Communiqué III-42.1, crypto asset service providers may onboard customers through remote identification. CASPs were also required to complete identification — face-to-face or remote — for their existing customers.
CMB — Announcement on CASP communiqués
MASAK — CASP Compliance Guide (PDF, Turkish)
Since then — foreign nationals and passport-based identification
The framework was extended to cover passport-based remote identification for non-Turkish natural persons. This step matters for companies employing foreign staff and working with international customers.
AI-based verification: the door the regulation actually opened
The artificial intelligence provision in Communiqué No. 24 solved the scale problem in remote identification. To see why it matters, recall the previous state of affairs.
The old model depended on a human operator. For every customer an agent joined a video call, had the ID held up to the camera and confirmed liveness with their own eyes. That model works at a hundred customers a day; it does not work at five thousand. Adding operators grows cost linearly — and the human eye is weaker than a machine at detecting forged documents.
Document verification. Security features of the ID or passport — hologram, microprint, typeface consistency, agreement between chip data and printed data — are checked by machine. An ID produced in Photoshop can look convincing on an operator's screen; it does not survive pixel-level analysis.
Liveness and deepfake detection. The system distinguishes a real person in real time from a photograph held to the screen, a mask, or synthetically generated video. With the spread of generative AI this stopped being a theoretical risk and became an operational threat — and it is not a problem a human operator can handle alone.
Automated risk scoring. Each application receives a score; those below the threshold are approved automatically, those above go to human review. Manual load falls to a small percentage of total volume.
This is precisely what the regulation permits: the requirement that all verification be performed by human hand has been relaxed. But one thing must not be forgotten — compliance responsibility remains with the obliged party. Buying technology does not transfer that responsibility; the decisions the system produces must be auditable, logged and justifiable.
Crypto asset service providers: the sector under most pressure
CASPs are today the sector in Türkiye with the sharpest need for remote identification, for three reasons that stack on top of each other:
Dual supervision. Obliged party under MASAK since 2021, subject to CMB licensing since 2024. Each authority has its own compliance expectations, and the licensing process examines whether compliance infrastructure exists.
Volume and speed expectations. A crypto customer expects an account within minutes. Inviting them to a branch is not an option, and queueing them for a video call with a human operator loses competitive ground. Scale makes automation mandatory.
High fraud risk. Account opening with forged identity, use of stolen identity and synthetic identity creation are more concentrated in this sector than in banking. Account-opening attempts using deepfakes are no longer exceptional cases.
Put together: for a CASP, AI-supported identity verification is not a preference but a condition of licensing and operation.
What Maresign does
As an authorised ArkSigner sales representative we meet remote identification needs with three products:
LiveAuth AI4KYC — AI-supported verification. Forged document, mask and deepfake detection; automated risk scoring. The primary solution for our customers doing high-volume onboarding, particularly on the CASP and fintech side.
LiveAuth KYC — NFC chip ID reading, liveness detection and document validation. The standard remote onboarding flow.
LiveAuth Communicator — Identity verification by video call and remote contract signing. Used in legal-entity onboarding and in flows where the regulation requires a video call.
But first we do this: we map your existing customer acquisition flow. Which category of obliged party you fall into, at which step identification is required, which documents still wait for a wet signature, what compliance evidence the CMB licensing process asks for. Product mapping comes after that.
The needs analysis is free. Request a quote or write directly: digital@maresign.com
This article is for information only and does not constitute legal advice. Consult your own legal counsel regarding your compliance obligations.
Maresign Dijital Güven Teknolojileri · Metropol İstanbul, B Blok No: 22, Ataşehir / İstanbul · +90 850 305 40 15 · digital@maresign.com · Last updated: 20 August 2026
