Three Turkish Regulators Now Put the NFC Chip at the Centre of Remote Onboarding
Between June and September 2026, Türkiye's financial intelligence unit (MASAK), its Capital Markets Board (CMB) and its central bank (CBRT) each amended their rules so that remote customer identification rests on reading the chip inside an identity document, and so that non-Turkish nationals can be onboarded remotely with an NFC-enabled passport that meets ICAO standard 9303.
Each change took effect on its publication date. Together they give payment, e-money, investment and crypto firms a common technical baseline, and open remote onboarding to foreign residents, visitors and investors.
Key takeaways
- MASAK set the passport route for non-Turkish natural persons on 27 June 2026 (Official Gazette No. 33293), with a video call, NFC chip matching and a three-month deadline for address verification.
- The CMB extended the route to intermediary institutions, portfolio management companies and crypto asset service providers on 3 September 2026 (No. 33359), with transfers only via SWIFT between accounts in the customer's own name.
- The CBRT amended its payment services regulation on 4 September 2026 (No. 33360) to require biometric methods or identity documents with electronic authentication capability, with NFC as the primary method.
What each regulator changed
MASAK acted first. Its Communiqué Serial No. 32, amending General Communiqué Serial No. 19, sets the principles for remotely identifying non-Turkish natural persons, and foreign representatives of legal entities registered with the trade registry, using passports. The sector regulators then aligned their own rulebooks.
The CMB published amendment III-42.1.b to its Communiqué III-42.1 on remote identification by investment and crypto firms. A day later, the CBRT amended the Regulation on Payment Services and Electronic Money Issuance and Payment Service Providers and its communiqué on the information systems of payment and e-money institutions.
| Regulator | Who it covers | Official Gazette | Key requirement |
|---|---|---|---|
| MASAK (Financial Crimes Investigation Board) | Obliged parties using remote identification for non-Turkish natural persons | 27 June 2026, No. 33293 | Video call by trained staff; passport chip data matched to the document by NFC |
| CMB (Capital Markets Board) | Intermediary institutions, portfolio management companies, crypto asset service providers | 3 September 2026, No. 33359 | Passport route for foreign nationals; SWIFT-only transfers between own-name accounts |
| CBRT (Central Bank of the Republic of Türkiye) | Payment service providers and electronic money institutions | 4 September 2026, No. 33360 | Biometric methods or electronically authenticable ID documents; NFC first, approved fallbacks |
The requirements in detail
The table paraphrases the published provisions as reported by Turkish law firms and professional publications.
| Requirement | What the rules say | Source |
|---|---|---|
| Document standard | Passport must comply with ICAO 9303 and support near-field communication (NFC) | MASAK, CMB, CBRT |
| Chip check | Identity data in the passport chip must be matched with the data printed on the passport, using NFC | MASAK, CMB |
| Live interaction | Identification by video call with specially trained personnel; artificial intelligence tools may be used for liveness testing or photo comparison | MASAK |
| Technical signals | IP and port data, device identity, geolocation and browser data assessed on a risk-based approach | MASAK |
| Address | Checked within three months; no money transfers or cash withdrawals until then | MASAK, CMB |
| Excluded customers | No onboarding of nationals of countries the obliged party itself assesses as high risk | MASAK |
| Funding | Incoming funds only from a bank account abroad in the customer's own name; outgoing only to the customer's own accounts | MASAK, CMB |
| SWIFT matching | Transfers only via SWIFT; identifying data in the SWIFT message matched to remote identification data before any other transaction | CMB |
| Reporting | Quarterly statistics to MASAK in the last month of each quarter, including portfolio sizes and investment amounts for CMB firms | MASAK, CMB |
| Legal entities | Representation authority checked against MERSİS and/or the Trade Registry Gazette; beneficial owners identified | CMB |
| Fallback | If NFC is unavailable: OCR, a card reader or other CBRT-approved methods, with security features checked under white light, front and back examined, and the whole process recorded without interruption | CBRT |
| Biometrics | Explicit consent for biometric data, real-time liveness and a comparison between the applicant and the document photo; device-level phone biometrics are not sufficient | CBRT |
The CBRT also lists situations where remote identification is not mandatory, including anonymous prepaid instruments, one-off payment transactions outside an ongoing relationship, and certain e-money transactions under MASAK General Communiqué Serial No. 5.
Why the chip matters
Chip-first onboarding changes where authenticity comes from. A camera image of a passport can be edited, replayed or generated. The data on an ICAO 9303 chip is digitally signed by a document signer acting for the issuing state, and that signature chains up to the country's signing certificate authority. Checking that signature, a step known as passive authentication under ICAO Doc 9303, shows whether the data was written by the issuer and has not been altered since.
Verifiable credentials use the same pattern: a trusted issuer signs a claim, the holder presents it, and the relying party checks the signature rather than a picture. Türkiye has made that pattern the default for regulated remote identification, as document images and faces get easier to fake, a risk we examined in our analysis of the HKMA's remote on-boarding circular.
The chip shows the document is genuine, not that the person holding the phone is its owner. That is why the rules pair NFC with a live video call or biometric comparison, and why the CBRT does not accept a phone's built-in face or fingerprint login as a substitute.
Foreign customers become reachable, on tight terms
The passport route gives regulated firms a lawful way to reach expatriates, long-stay visitors and foreign investors without a branch visit.
The funding controls keep that channel narrow. Money can only come from, and go back to, bank accounts abroad in the customer's own name. For investment and crypto firms, the SWIFT requirement adds a second match: the sender data in the payment message must agree with what the customer presented at onboarding before any other transaction proceeds. In effect, a foreign customer's identity is checked twice, once by chip and once through the banking system that funds the account.
A welcome step, and one that will keep moving
We welcome the direction. One technical baseline across three regulators reduces ambiguity for firms holding more than one licence, and state-signed chip data raises the cost of document fraud. These controls will still need to be reviewed and recalibrated continually as technology and fraud methods evolve, particularly the fallback routes (OCR and visual inspection) used when a chip cannot be read.
Where verifiable credentials fit
Regulated remote identification stays exactly where the rules put it: with the licensed firm, using NFC, video or biometrics, and funding checks. A credential layer does not replace any of that, and it does not make any requirement unnecessary. What it can add is reuse of an outcome, with consent, in places the regulated check does not reach.
| Requirement | What stays with existing controls | What a credential layer can add |
|---|---|---|
| NFC chip matching | The regulated firm reads and checks the chip during onboarding | After onboarding, the firm can issue a signed credential stating the check was passed, without sharing chip data |
| Video call and liveness | Trained staff and liveness tools at the regulated firm | Nothing at onboarding; later, a unique-person credential can reduce repeat checks at non-regulated partners |
| Address verification | Documents or databases within three months | A residency credential another business can check as a yes or no |
| Own-name funding and SWIFT matching | Banks and the regulated firm | No change; payment controls remain with regulated institutions |
| High-risk country exclusion | The firm's own risk assessment | No change; each verifier applies its own policy |
| Reporting to MASAK | The obliged party | No change |
AIR Identity, built by Moca Network, works from both sides. Trusted issuers, such as banks, fintechs and licensed KYC partners, issue reusable, user-held credentials from checks they already ran, for example "passed KYC in Türkiye" or residency. Businesses that need to know one of those facts request a proof of just that fact and receive a yes or no answer, with the user's consent and minimal data custody. Each verifier remains responsible for deciding whether a credential satisfies its own regulatory requirements.
In practice, a customer onboarded through a chip-based regulated check could later prove a single fact to a ticketing platform, a gaming marketplace or a loyalty programme, instead of uploading a passport again. Moca Network, the identity network of Animoca Brands, has partnerships in Türkiye across that range: with Inveo Kripto and Ichain Investment Holding to explore verifiable identity for financial applications, with ticketing platform Biletinial, and with gaming marketplace Oyunfor.
What firms should do now
- Map which rulebook applies to each licensed product line.
- Measure NFC read failures on real devices, because that is when the fallback path applies.
- Run SWIFT and own-name funding checks before the first transaction, not in a later review.
- Document the high-risk country assessment, which MASAK leaves to the obliged party.
- Decide which onboarding outcomes customers could reuse elsewhere, with consent.
Our read
Türkiye's regulators agreed on a common baseline and anchored it in cryptographic proof from the document issuer, a step we welcome. Foreign customers become reachable remotely through tightly controlled funding routes. The chip-first check is the regulated foundation; credentials can sit on top, carrying single facts to partners that do not need the underlying documents.
Frequently asked questions
What are the new remote identification rules in Türkiye in 2026?
MASAK (27 June), the CMB (3 September) and the CBRT (4 September 2026) amended their rules so remote identification relies on NFC chip reading plus video or biometric checks, and non-Turkish nationals can be onboarded with NFC-enabled ICAO 9303 passports.
Can foreigners open accounts remotely in Türkiye with a passport?
Yes, where the firm offers it. Funds must come from, and return to, bank accounts in the customer's own name, and address checks must be completed within three months under the MASAK and CMB rules.
Which firms do the CMB's III-42.1.b rules cover?
Intermediary institutions, portfolio management companies and crypto asset service providers. For passport-onboarded customers, transfers run only via SWIFT between own-name accounts, with SWIFT data matched to onboarding data first.
What happens if an NFC chip cannot be read under the CBRT rules?
Institutions may use OCR, a card reader or another CBRT-approved method, checking security features under white light and recording the whole process without interruption.
Can verifiable credentials replace remote identification in Türkiye?
No. Regulated remote identification stays with the licensed firm. A credential issued after that check can let other businesses confirm a single fact, such as residency, with consent, as an additional layer.
Want to reach customers who already hold the credentials you need? See how AIR Identity works, or partner with us to grow your business.
Sources
- LBF Partners: MASAK principles for remote identity verification of non-Turkish natural persons using passports
- Pekin & Pekin: New CMB rules on remote identification
- Alo Maliye: CMB Communiqué III-42.1.b (Official Gazette 3 September 2026, No. 33359)
- ProCompliance: CMB rules on passport-based remote onboarding of foreign investors
- Pekin & Pekin: New CBRT rules on remote identity verification
- Alo Maliye: Amendment to the Payment Services and Electronic Money Regulation (Official Gazette 4 September 2026, No. 33360)
- Müşavirler Kulübü: Payment services regulation amendment and biometric methods
- ICAO Doc 9303, Machine Readable Travel Documents, Part 11 and Part 12
Partner with AIR
AIR is one integration suite for identity, money and loyalty. AIR Identity lets trusted issuers issue verifiable credentials and businesses verify them, so acquisition starts with users who already qualify, with minimal data custody. AIR Money embeds compliant global financial infrastructure, opening new markets without building new rails. AIR Loyalty gives brands a programmable, stable-value points engine that keeps users coming back.
Partner with us to grow your business.
AIR is built by Moca Network, the identity network of Animoca Brands.

.png)