Platform
Solutions
Resources
Company
Resources

Remote Identification Rules for Foreign and Legal Entities Have Changed

SPK has updated remote identification rules for brokerage firms, portfolio management companies, and crypto asset service providers. New controls have been introduced for verifying foreign nationals via passport and legal entities via MERSİS.

Summary

Sermaye Piyasası Kurulu (SPK) has made significant changes to remote identification processes. The new communiqué regulates the remote onboarding of foreign real persons. It also establishes the rules for the remote identification of legal entities registered in the trade registry. For foreign nationals, the use of passports with Near Field Communication (NFC) capabilities is becoming standard. The communiqué mandates MERSİS (Central Registry System) checks for legal entities. It also makes ultimate beneficial owner (UBO) identification an integral part of the legal entity onboarding process. These changes create new risk scenarios in KYC processes. Furthermore, they introduce new periodic reporting obligations for compliance teams. Transactions of remotely onboarded customers must now pass through a stricter transaction monitoring filter.

What has changed

The communiqué expands the scope of individuals and institutions for whom remote identification can be performed. Non-Turkish real persons can now become customers through remote identification. For this process, individuals use passports complying with the International Civil Aviation Organization (ICAO) Document 9303 standard. The communiqué requires the use of the passport's Near Field Communication (NFC) feature. Institutions verify that the information on the passport chip matches the information on the passport itself using NFC. If institutions cannot perform this verification, they cannot establish a business relationship through remote identification.

Institutions automatically classify customers whose remote identification is performed via passport into the high-risk group. The communiqué imposes very strict restrictions on money transfers to and from these accounts. Customers can only make incoming transfers from their own bank accounts abroad. Similarly, institutions can only send outgoing transfers to the bank account belonging to the individual in question. The communiqué mandates that these transfers be carried out exclusively through the SWIFT system. Institutions verify that the information in the SWIFT messages matches the information obtained from the customer. Institutions complete this check before any other transaction is performed on the customer's account.

The communiqué regulates the verification of representation authority in the remote identification of legal entities. Institutions confirm the representative's authority through MERSİS or the Ticaret Sicili Gazetesi. The communiqué makes it mandatory to identify the ultimate beneficial owner (UBO) of the legal entity. If institutions cannot identify the UBO, they must terminate the process immediately. Institutions also terminate the process if they find discrepancies among the submitted information. If institutions detect a suspicious situation, they cancel the remote identification process.

If the representative already has an account with the institution, the process becomes easier. This person can create a request through the online banking branch for the legal entity they represent. A request to establish a continuous business relationship can also be made via the mobile application. In this case, institutions continue the identification process of the legal entity seamlessly.

Liveness detection and photo comparison steps are of great importance in the remote identification process. The communiqué allows the use of artificial intelligence-based applications in this process. However, this does not eliminate the requirement for a video call conducted by specially trained personnel. During the video call, the personnel captures clear images showing the individual and the information on the passport. Institutions also record technical data obtained from the electronic environment where the customer performs the transaction. Systems collect data such as IP address, port information, device ID, and geographic location. Institutions also evaluate browser information within this scope. Institutions analyze all this technical data and the passport information using a risk-based approach.

While performing the identification of the legal entity representative, institutions strictly verify that the individual is authorized to represent the entity. There may be multiple individuals jointly authorized to represent the legal entity. In this case, institutions can perform the identification of all authorized representatives in the same session. Alternatively, institutions can complete the process by organizing separate sessions at different times. When needed, institutions can request a copy of the signature circular from the representative. Personnel takes photos or screenshots showing the information on the signature circular. Personnel compares the signature specimen on the signature circular with the signature on the identification document. Personnel also includes the signature specimen available on MERSİS in this comparison. Personnel checks whether the signature circular is notarized. Personnel verifies the authenticity of the document using the date and journal number on it. Personnel also queries the Gelir İdaresi Başkanlığı database to match the up-to-date information.

Who is affected

These changes directly bind three main types of institutions operating in the capital market:

Obligations and dates

The communiqué was published on September 3, 2026, and entered into force on the same day. The actions to be taken by institutions and their deadlines are listed as follows:

Obligated PartyObligationDeadline
Brokerage firms, portfolio management companies, kripto varlık hizmet sağlayıcılarTo report information of customers acquired through remote identification to MASAK.The last month of each quarterly period based on the calendar year
Brokerage firms, portfolio management companies, kripto varlık hizmet sağlayıcılarTo obtain and verify the address information of the individual identified via passport.Within three months at the latest from the transaction date
Brokerage firms, portfolio management companies, kripto varlık hizmet sağlayıcılarNot to allow money and crypto asset transfers before address verification is completed.During and after the establishment of a continuous business relationship
Brokerage firms, portfolio management companies, kripto varlık hizmet sağlayıcılarTo identify the ultimate beneficial owner (UBO) during the identification process of the legal entity representative.During the establishment of a continuous business relationship

Steps for compliance

The concrete steps a compliance officer should take to comply with this communiqué are as follows:

  1. Update your remote customer onboarding workflows. Set up the NFC-enabled passport reading infrastructure for foreign nationals.
  2. Revise your risk assessment model. Define a rule that assigns customers whose remote identification is performed via passport to the high-risk group.
  3. Tighten money transfer controls. Create a control mechanism to verify that incoming transfers to these high-risk accounts are made exclusively via SWIFT.
  4. Integrate the address verification process into the system. Implement system-level restrictions that prevent foreign customers from transacting before their address verification is completed.
  5. Plan MASAK reporting processes. Prepare data extraction queries to report the information of customers acquired through remote identification every three months.
  6. Structure the legal entity onboarding process. Ensure integrations with MERSİS and the Ticaret Sicili Gazetesi.
  7. Update ultimate beneficial owner (UBO) identification scenarios. Write business rules that automatically halt the process when the UBO cannot be identified.
  8. Train on video call scenarios. Provide specialized training to customer representatives on remote identification via passport.
  9. Update customer representative screens. Design interfaces where personnel can upload signature circulars to the system and compare them with MERSİS data.
  10. Revise your internal audit plan. Test whether restrictions introduced by the new communiqué, such as address verification and SWIFT controls, are functioning correctly in the system.
  11. Improve customer communication processes. Establish a workflow that sends automated reminder messages to foreign customers with missing address verification.

Truvali note

Truvali is a compliance software that consolidates anti-money laundering (AML), KYC, and transaction monitoring into a single platform. Today in Turkey, teams procuring these three services from three different vendors navigate between separate applications to evaluate a single customer. Truvali unifies this workflow in one place; risk scoring and case management are also part of the same platform.

Sources

Disclaimer

This article is for informational purposes only and does not constitute legal advice. The scope of your obligations varies depending on your institution's operating license and business model; for a binding assessment, please refer to the current text of the legislation and consult your legal advisor.

Related