News

Three Turkish Regulators Now Put the NFC Chip at the Centre of Remote Onboarding

Moca Network
September 18, 2026

Between June and September 2026, Türkiye's financial intelligence unit (MASAK), its Capital Markets Board (CMB) and its central bank (CBRT) each amended their rules so that remote customer identification rests on reading the chip inside an identity document, and so that non-Turkish nationals can be onboarded remotely with an NFC-enabled passport that meets ICAO standard 9303.

Each change took effect on its publication date. Together they give payment, e-money, investment and crypto firms a common technical baseline, and open remote onboarding to foreign residents, visitors and investors.

Key takeaways

  • MASAK set the passport route for non-Turkish natural persons on 27 June 2026 (Official Gazette No. 33293), with a video call, NFC chip matching and a three-month deadline for address verification.
  • The CMB extended the route to intermediary institutions, portfolio management companies and crypto asset service providers on 3 September 2026 (No. 33359), with transfers only via SWIFT between accounts in the customer's own name.
  • The CBRT amended its payment services regulation on 4 September 2026 (No. 33360) to require biometric methods or identity documents with electronic authentication capability, with NFC as the primary method.

What each regulator changed

MASAK acted first. Its Communiqué Serial No. 32, amending General Communiqué Serial No. 19, sets the principles for remotely identifying non-Turkish natural persons, and foreign representatives of legal entities registered with the trade registry, using passports. The sector regulators then aligned their own rulebooks.

The CMB published amendment III-42.1.b to its Communiqué III-42.1 on remote identification by investment and crypto firms. A day later, the CBRT amended the Regulation on Payment Services and Electronic Money Issuance and Payment Service Providers and its communiqué on the information systems of payment and e-money institutions.

RegulatorWho it coversOfficial GazetteKey requirement
MASAK (Financial Crimes Investigation Board)Obliged parties using remote identification for non-Turkish natural persons27 June 2026, No. 33293Video call by trained staff; passport chip data matched to the document by NFC
CMB (Capital Markets Board)Intermediary institutions, portfolio management companies, crypto asset service providers3 September 2026, No. 33359Passport route for foreign nationals; SWIFT-only transfers between own-name accounts
CBRT (Central Bank of the Republic of Türkiye)Payment service providers and electronic money institutions4 September 2026, No. 33360Biometric methods or electronically authenticable ID documents; NFC first, approved fallbacks

The requirements in detail

The table paraphrases the published provisions as reported by Turkish law firms and professional publications.

RequirementWhat the rules saySource
Document standardPassport must comply with ICAO 9303 and support near-field communication (NFC)MASAK, CMB, CBRT
Chip checkIdentity data in the passport chip must be matched with the data printed on the passport, using NFCMASAK, CMB
Live interactionIdentification by video call with specially trained personnel; artificial intelligence tools may be used for liveness testing or photo comparisonMASAK
Technical signalsIP and port data, device identity, geolocation and browser data assessed on a risk-based approachMASAK
AddressChecked within three months; no money transfers or cash withdrawals until thenMASAK, CMB
Excluded customersNo onboarding of nationals of countries the obliged party itself assesses as high riskMASAK
FundingIncoming funds only from a bank account abroad in the customer's own name; outgoing only to the customer's own accountsMASAK, CMB
SWIFT matchingTransfers only via SWIFT; identifying data in the SWIFT message matched to remote identification data before any other transactionCMB
ReportingQuarterly statistics to MASAK in the last month of each quarter, including portfolio sizes and investment amounts for CMB firmsMASAK, CMB
Legal entitiesRepresentation authority checked against MERSİS and/or the Trade Registry Gazette; beneficial owners identifiedCMB
FallbackIf NFC is unavailable: OCR, a card reader or other CBRT-approved methods, with security features checked under white light, front and back examined, and the whole process recorded without interruptionCBRT
BiometricsExplicit consent for biometric data, real-time liveness and a comparison between the applicant and the document photo; device-level phone biometrics are not sufficientCBRT

The CBRT also lists situations where remote identification is not mandatory, including anonymous prepaid instruments, one-off payment transactions outside an ongoing relationship, and certain e-money transactions under MASAK General Communiqué Serial No. 5.

Why the chip matters

Chip-first onboarding changes where authenticity comes from. A camera image of a passport can be edited, replayed or generated. The data on an ICAO 9303 chip is digitally signed by a document signer acting for the issuing state, and that signature chains up to the country's signing certificate authority. Checking that signature, a step known as passive authentication under ICAO Doc 9303, shows whether the data was written by the issuer and has not been altered since.

Verifiable credentials use the same pattern: a trusted issuer signs a claim, the holder presents it, and the relying party checks the signature rather than a picture. Türkiye has made that pattern the default for regulated remote identification, as document images and faces get easier to fake, a risk we examined in our analysis of the HKMA's remote on-boarding circular.

The chip shows the document is genuine, not that the person holding the phone is its owner. That is why the rules pair NFC with a live video call or biometric comparison, and why the CBRT does not accept a phone's built-in face or fingerprint login as a substitute.

Foreign customers become reachable, on tight terms

The passport route gives regulated firms a lawful way to reach expatriates, long-stay visitors and foreign investors without a branch visit.

The funding controls keep that channel narrow. Money can only come from, and go back to, bank accounts abroad in the customer's own name. For investment and crypto firms, the SWIFT requirement adds a second match: the sender data in the payment message must agree with what the customer presented at onboarding before any other transaction proceeds. In effect, a foreign customer's identity is checked twice, once by chip and once through the banking system that funds the account.

A welcome step, and one that will keep moving

We welcome the direction. One technical baseline across three regulators reduces ambiguity for firms holding more than one licence, and state-signed chip data raises the cost of document fraud. These controls will still need to be reviewed and recalibrated continually as technology and fraud methods evolve, particularly the fallback routes (OCR and visual inspection) used when a chip cannot be read.

Where verifiable credentials fit

Regulated remote identification stays exactly where the rules put it: with the licensed firm, using NFC, video or biometrics, and funding checks. A credential layer does not replace any of that, and it does not make any requirement unnecessary. What it can add is reuse of an outcome, with consent, in places the regulated check does not reach.

RequirementWhat stays with existing controlsWhat a credential layer can add
NFC chip matchingThe regulated firm reads and checks the chip during onboardingAfter onboarding, the firm can issue a signed credential stating the check was passed, without sharing chip data
Video call and livenessTrained staff and liveness tools at the regulated firmNothing at onboarding; later, a unique-person credential can reduce repeat checks at non-regulated partners
Address verificationDocuments or databases within three monthsA residency credential another business can check as a yes or no
Own-name funding and SWIFT matchingBanks and the regulated firmNo change; payment controls remain with regulated institutions
High-risk country exclusionThe firm's own risk assessmentNo change; each verifier applies its own policy
Reporting to MASAKThe obliged partyNo change

AIR Identity, built by Moca Network, works from both sides. Trusted issuers, such as banks, fintechs and licensed KYC partners, issue reusable, user-held credentials from checks they already ran, for example "passed KYC in Türkiye" or residency. Businesses that need to know one of those facts request a proof of just that fact and receive a yes or no answer, with the user's consent and minimal data custody. Each verifier remains responsible for deciding whether a credential satisfies its own regulatory requirements.

In practice, a customer onboarded through a chip-based regulated check could later prove a single fact to a ticketing platform, a gaming marketplace or a loyalty programme, instead of uploading a passport again. Moca Network, the identity network of Animoca Brands, has partnerships in Türkiye across that range: with Inveo Kripto and Ichain Investment Holding to explore verifiable identity for financial applications, with ticketing platform Biletinial, and with gaming marketplace Oyunfor.

What firms should do now

  1. Map which rulebook applies to each licensed product line.
  2. Measure NFC read failures on real devices, because that is when the fallback path applies.
  3. Run SWIFT and own-name funding checks before the first transaction, not in a later review.
  4. Document the high-risk country assessment, which MASAK leaves to the obliged party.
  5. Decide which onboarding outcomes customers could reuse elsewhere, with consent.

Our read

Türkiye's regulators agreed on a common baseline and anchored it in cryptographic proof from the document issuer, a step we welcome. Foreign customers become reachable remotely through tightly controlled funding routes. The chip-first check is the regulated foundation; credentials can sit on top, carrying single facts to partners that do not need the underlying documents.

Frequently asked questions

What are the new remote identification rules in Türkiye in 2026?

MASAK (27 June), the CMB (3 September) and the CBRT (4 September 2026) amended their rules so remote identification relies on NFC chip reading plus video or biometric checks, and non-Turkish nationals can be onboarded with NFC-enabled ICAO 9303 passports.

Can foreigners open accounts remotely in Türkiye with a passport?

Yes, where the firm offers it. Funds must come from, and return to, bank accounts in the customer's own name, and address checks must be completed within three months under the MASAK and CMB rules.

Which firms do the CMB's III-42.1.b rules cover?

Intermediary institutions, portfolio management companies and crypto asset service providers. For passport-onboarded customers, transfers run only via SWIFT between own-name accounts, with SWIFT data matched to onboarding data first.

What happens if an NFC chip cannot be read under the CBRT rules?

Institutions may use OCR, a card reader or another CBRT-approved method, checking security features under white light and recording the whole process without interruption.

Can verifiable credentials replace remote identification in Türkiye?

No. Regulated remote identification stays with the licensed firm. A credential issued after that check can let other businesses confirm a single fact, such as residency, with consent, as an additional layer.

Want to reach customers who already hold the credentials you need? See how AIR Identity works, or partner with us to grow your business.

Sources

Partner with AIR

AIR is one integration suite for identity, money and loyalty. AIR Identity lets trusted issuers issue verifiable credentials and businesses verify them, so acquisition starts with users who already qualify, with minimal data custody. AIR Money embeds compliant global financial infrastructure, opening new markets without building new rails. AIR Loyalty gives brands a programmable, stable-value points engine that keeps users coming back.

Partner with us to grow your business.

AIR is built by Moca Network, the identity network of Animoca Brands.

Stay updated on AIR launches
Product updates, partner launches, and research across digital identity, fintech, and loyalty. Unsubscribe anytime.
By subscribing, you agree to our Privacy Policy and consent to receive updates.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
In this article
Blog

Read more articles

Lorem ipsum dolor sit amet, consectetur adipiscing elit.
View all
News
US Regulators Confirm Banks Can Accept Mobile Driver's Licences When Opening Accounts
FinCEN and four US banking agencies say a government-issued mobile driver's licence can serve as documentary ID under the CIP Rule. What the 2026 FAQs require.
News
The EU KIDS Act Proposes 15 as the Minimum Age for Independent Social Media Accounts
The EU KIDS Act proposal sets 15 as the minimum age for independent social media accounts, adds supervised accounts from 13 and requires certified age checks.
News
South Korea's Amended Privacy Law Lets the Regulator Fine Serious Breaches up to 10% of Total Revenue
South Korea's amended privacy law took effect on 11 September 2026: fines up to 10% of total revenue, CEO accountability and 72-hour notice of possible leaks.