Platform
Solutions
Resources
Company
Resources

Remote Identification Rules Updated for Payment Institutions

TCMB has prioritized the use of NFC in the remote identification processes of payment and electronic money institutions. While biometric data verification has become mandatory, the rules for remote customer onboarding with passports for foreign nationals have been clarified.

Summary

The Central Bank of the Republic of Turkey (TCMB) has updated its remote identification rules. The Communiqu dated September 4, 2026, directly binds payment and electronic money institutions. The new rules place Near Field Communication (NFC) technology at the center of customer onboarding. Biometric data verification is now becoming a mandatory part of the process. For the remote onboarding of foreign national customers, the use of chipped passports is being standardized. The regulation requires collaboration between compliance and information technology teams. Institutions are expected to redesign their current customer onboarding flows in accordance with these new technical requirements. These steps, aimed at reducing fraud risk, make KYC processes more secure.

What changed

The Communiqu establishes a strict framework for the definition of identity documents. Now, only the identity card defined in the Identity Card Regulation of the Republic of Turkey is accepted. Documents such as old-style national ID cards or driver's licenses are completely excluded from this definition. This change aims to prevent fraud attempts made with non-standard documents.

Biometric data verification is becoming mandatory in remote identification. Institutions must verify the customer's biometric data. This step proves that the person presenting the identity document is the same person who owns the document. Liveness detection tests and face recognition algorithms play a critical role at this stage.

The use of NFC is designated as the primary method in the identity verification process. The accuracy of the data on the identity document is primarily checked using this method. The authenticity and integrity of the document are verified directly via the NFC chip. Whether the data inside the chip has been altered is cryptographically confirmed. This minimizes the risk of physical tampering.

Alternatives are provided for cases where verification cannot be performed via NFC. Optical Character Recognition (OCR) or card readers can be used. Other methods determined by TCMB, in consultation with MASAK, are also valid. However, these alternatives can only be deployed in exceptional cases where NFC does not work. Starting the process directly with OCR is now considered non-compliant with the regulations.

A new standard is introduced for the remote identification of foreign nationals. Passports complying with the International Civil Aviation Organization (ICAO) 9303 standard can be used. These passports must have NFC capabilities. This introduces a chip-reading requirement for foreign customers as well, aiming to prevent the use of fraudulent cross-border documents.

The rule requiring all these verification steps to be recorded is reinforced. The inspection of visual elements and security tests are recorded continuously. Security features that can be visually distinguished under white light are examined. Elements such as photos and signatures are tested for wear or tampering. These records prove that the process was operated in compliance with the regulations during a potential audit.

Certain transactions are exempted from the remote identification requirement. Anonymous prepaid instruments fall under this scope. One-off payment transactions that do not establish a continuous business relationship are also within the exemption area. This rule is also relaxed for certain electronic money issuance transactions under MASAK General Communiqu No. 5. These exceptions aim to accelerate the customer experience for low-risk products, preventing unnecessary compliance costs.

Who is affected

The Communiqu directly affects payment institutions and electronic money institutions. Product teams designing the customer onboarding processes of these institutions are covered. Information technology units providing the remote identification infrastructure are affected by the regulation. Compliance managers running KYC processes are obliged to implement the new rules. Technology providers offering identification solutions through outsourcing must also update their systems. Internal control and audit teams are held responsible for testing the new process.

Obligations and dates

The Communiqu entered into force on September 4, 2026, the day of its publication. There is no transition period between the publication and effective dates.

Obliged EntityObligationDate
Payment and electronic money institutionsTo check identity data primarily via NFC in remote identification.September 4, 2026
Payment and electronic money institutionsTo verify the customer's biometric data during the identification process.September 4, 2026
Payment and electronic money institutionsTo use OCR, card readers, or other approved methods when NFC does not work.September 4, 2026
Payment and electronic money institutionsTo use NFC-enabled passports complying with ICAO 9303 standards for foreign nationals.September 4, 2026
Payment and electronic money institutionsTo record the verification and visual inspection process continuously.September 4, 2026

Steps for compliance

Review your current remote identification flow from end to end. Set your application's NFC reading capability as the default verification step. Remove legacy flows that direct the customer straight to the OCR step from the system.

Design a fallback flow for scenarios where NFC reading fails. In this flow, deploy alternative methods such as OCR or card readers. Clearly state the reason for switching to the alternative method in the system logs. These logs will prove during audits that you complied with the NFC priority rule.

Integrate biometric data verification steps into the customer onboarding process. Regularly test the accuracy of your liveness detection and face recognition algorithms. Monitor the match rates of biometric data with the photo on the ID. Recalibrate your threshold values according to your risk appetite.

Update your passport reading infrastructure for foreign national customers. Ensure that the system supports the ICAO 9303 standard and the NFC chip in the passport. Perform passport reading tests with documents from different countries. Add user guidance to minimize chip-reading errors.

List your exempted products. Remove unnecessary identification steps from the process for anonymous prepaid instruments. Adopt a risk-based approach for one-off transactions. Clarify in your internal policies which transactions establish a continuous business relationship.

Verify that all verification and testing processes are recorded continuously. Periodically check whether your logging infrastructure is audit-ready. Review the integrity and storage conditions of video recordings. Comply with retention periods without compromising on data security standards.

Renew your Service Level Agreements (SLAs) with your vendors. Confirm that the new communiqu requirements are fully met by the technology provider. Request in writing when your vendor will complete the system updates.

Establish a task force consisting of compliance, product, and information technology teams. Measure the impact of the new rules on customer conversion rates weekly. Make improvements to the user interface to reduce error rates.

Truvali note

Truvali is a compliance software that consolidates AML, KYC, and transaction monitoring into a single platform. In Turkey, teams that currently source these three areas from three different vendors navigate between separate applications to evaluate a single customer. Truvali unifies this flow in one place; risk scoring and case management are also part of the same platform.

References

https://www.resmigazete.gov.tr/eskiler/2026/09/20260904-2.htm

Related