Customer Identification Obligation in Payment Institutions
In Turkey, payment institutions play a crucial role in the system for preventing money laundering and terrorist financing, as they carry out money transfers, payment acceptance, and other payment services on behalf of or at the instruction of customers. Therefore, it is not sufficient for payment institutions to simply record the customer's name and contact information. The institution be able to identify the customer, the purpose of the transaction, whether another person is acting on behalf of the customer, and, if necessary, the true beneficiary of the transaction .
The fundamental legal framework for the customer identification obligation in payment institutions by Law No. 5549 on the Prevention of Money Laundering, the Regulation on Measures Regarding the Prevention of Money Laundering and Terrorist Financing, and secondary regulations published by MASAK (Financial Crimes Investigation Board). MASAK regulates customer identification as one of the essential measures that ensure obligated institutions have sufficient information about their customers and their activities.
For payment institutions, the customer identification process is not merely a procedure to be established at the time of company formation. It is a continuous compliance obligation that must be integrated into all of the organization's operations, from customer acquisition and transaction tracking to legitimate beneficiary verification and suspicious transaction assessment.
Are Payment Institutions Obligated Under MASAK (Financial Crimes Investigation Board)?
Yes. Payment institutions are among the entities obligated under legislation related to preventing money laundering and terrorist financing. Therefore, payment institutions have obligations regarding customer identification, identity verification, reporting of suspicious transactions, providing, preserving and presenting information and documents, and compliance programs according to their scope of activity.
However, the customer identification obligation should not be understood simply as taking a photocopy of a person's identity card.
The payment institution needs to know the customer;
- identifying the customer's identity,
- verifying the customer's identity,
- understanding the purpose of the employment relationship,
- Identifying the individuals acting on behalf of the client,
- Identifying the actual beneficiary,
- creating a risk profile for the customer,
- keeping customer information up-to-date and
- monitoring the alignment of transactions with the customer profile
It may be required.
Therefore, the KYC – Know Your Customer system used in practice can be considered the technological and operational equivalent of MASAK's customer identification obligation.
Are Customer Identification and Customer Verification the Same Thing?
No.
Identity verificationis the process of determining and verifying the customer's identity based on the information and documents specified in the legislation.
Customer identification is more comprehensive than mere identity verification.
A payment institution must assess not only the identity of the customer but also, as far as possible, the customer's activities, the purpose of their transactions, the level of risk, and their transaction behavior. MASAK's regulations regarding customer identification include measures such as identifying the actual beneficiary, obtaining information about the purpose of the business relationship, and monitoring the customer's status and transactions, in addition to identity verification.
For example, even if the user has successfully completed the authentication process;
If a customer receives payments from hundreds of different people, the money is transferred to different individuals as soon as it arrives, and these transactions cannot be explained by the user's known financial profile, then the customer identification process cannot be considered complete with identity verification alone.
In this case, the organization may need to further assess its customers and transactions on a risk-based approach.
When is identity verification carried out at payment processing facilities?
MASAK regulations specify different situations that require identity verification.
especially a continuous business relationship has been established . Additionally, identification becomes relevant when transactions exceed the amount specified in the legislation, or when the total of multiple interconnected transactions exceeds the relevant limit. Furthermore, identification is required regardless of the transaction amount when a situation warrants reporting a suspicious transaction.
Therefore, a payment institution;
"The customer's transaction amount is low, so we don't need to verify their identity."
It is not correct to formulate a general policy in this way.
Whether a long-term business relationship has been established with the customer and whether there is any suspicion surrounding the transaction should also be evaluated.
What is a Continuous Employment Relationship?
From the perspective of payment institutions, one of the most important concepts in practice is the ongoing business relationship.
A customer creating an account with a payment institution, using a digital wallet or similar continuously available service, or entering into a contractual relationship with the institution can constitute a continuous business relationship, depending on the characteristics of the business model.
In ongoing business relationships, identity verification is not only required when a certain transaction amount is exceeded. Customer identification and necessary checks must be carried out during the establishment phase of the relationship. The Measures Regulation also specifically addresses identity verification and customer identification measures in establishing ongoing business relationships.
Therefore, the practice of allowing customers to make hundreds of transactions in mobile payment applications before subjecting them to the KYC process for the first time when they reach a certain monetary threshold should be further evaluated from a regulatory perspective, particularly for models with ongoing business relationships.
What information is collected from individual customers?
For individual customers, identification must be obtained using the identification information stipulated by law and verified through appropriate sources.
For Turkish citizens, identity information may be verified through identity documents and appropriate verification systems; for foreign customers, depending on the person's status and the method used, the evaluation of passports or other accepted identity documents may be considered. The documents and methods by which identity verification will be carried out are regulated in detail in the Measures Regulation.
According to the customer's own statement on the payment institution's application screen;
"My name is Ahmet, my surname is Yılmaz."
Entering information in this way alone does not constitute identity verification.
Identity information must be verified using methods prescribed by law.
Is it possible to remotely verify the identities of foreign customers?
Remote customer acquisition is becoming increasingly important, especially for payment institutions.
According to MASAK General Circular No. 19, payment and electronic money institutions can carry out remote identity verification while establishing continuous business relationships with their customers within the framework of the methods and measures determined in the Central Bank of the Republic of Turkey's regulations regarding the information systems of payment and electronic money institutions.
Furthermore, it was announced that MASAK on January 19, 2026, allowing for remote identity verification of non-Turkish citizens using passports. Therefore, current MASAK and Central Bank of Turkey regulations should be considered together in processes related to acquiring foreign clients through digital channels.
This development is particularly significant for fintech companies in Türkiye that offer international money transfers or payment services to foreign customers.
However, the fact that remote identity verification is possible does not mean that simply uploading an image of the passport to the system is sufficient.
How is remote identity verification performed at payment institutions?
Remote identity verification is a process designed to facilitate in-person customer acquisition in a mobile or digital environment.
The payment institution must comply with both the MASAK's customer identification regulations and the Central Bank of the Republic of Turkey's (TCMB) technical requirements regarding information systems and remote customer acquisition during this process. MASAK General Circular No. 19 refers to the methods and measures specified in the TCMB Circular for remote identity verification of payment and electronic money institutions.
Therefore, in terms of technology infrastructure;
- identity document verification,
- determining that the person is real and alive
- establishing the connection between identity and person,
- process security,
- Preventing attempts to create fake identities,
- proper recording of transactions
Factors such as these need to be considered together.
The fact that a payment institution purchases services from a third-party KYC software company does not mean that the institution is relieved of its own MASAK (Financial Crimes Investigation Board) obligations.
How to Identify Corporate Customers?
The payment institution's customers are not limited to individuals only.
For e-commerce companies, platforms, stores, businesses, and other commercial customers, the corporate customer identification process may be more comprehensive.
The organization only;
"The company's name is ABC Ltd."
It is not enough for him to simply receive the information.
The company's legal entity, officers, representatives, ownership structure, and, where applicable, its beneficial owners should be examined.
The identity of the person acting on behalf of the customer must also be determined, and their authorization to represent the customer must be verified. MASAK regulations stipulate that if another person acts on behalf of the customer, the identity of that person must also be determined.
This is especially important in virtual POS and business acquisition processes.
Who is the real beneficiary?
Identifying the true beneficiary is one of the most important stages of a customer identification system.
When a payment institution's customer is a company, simply recognizing the company as listed in the commercial register may not always be sufficient.
The payment institution must take the necessary measures, within the scope of legislation regarding the identification of the beneficial owner, to identify the natural person who has ultimate control over the company or in whose account the transaction was actually carried out. The Measures Regulation contains provisions for the identification of the beneficial owner within the scope of customer identification.
For example, the client company;
Company A → Holding B → foreign company → individual partner
If a company has such a chain of partnerships, identifying only the manager of company A in Türkiye may not be sufficient.
It may be necessary to understand the company's actual control structure.
What happens if the actual beneficiary cannot be identified?
This is one of the key consequences of the know-your-customer obligation.
According to MASAK regulations, obligated parties should not establish a business relationship or perform a requested transaction if they cannot perform the necessary identity verification or obtain sufficient information about the purpose of the business relationship . In existing customer relationships, termination of the relationship may also be considered if the obligations of identity verification and customer identification are not fulfilled.
Therefore, due to the payment institution's commercial objectives;
"Let's bring the client into the system first, we'll examine the partnership structure later."
Acting in this manner could create a serious risk of non-compliance.
What happens if someone else is making transactions on behalf of the customer?
In payment processing facilities, the use of an account or payment instrument by individuals other than the actual customer is a significant area of risk.
MASAK regulations may require the identification of the person acting on behalf of the customer.
For example, when opening a merchant account at a payment institution on behalf of a company, if the transactions are carried out by a company employee;
- company identity,
- representatives
- Identity of the person performing the transaction,
- the basis of the power of representation
They should be evaluated together.
Similarly, the practice of allowing others to use personal payment accounts, or "account rental," is also of particular importance in terms of customer identification and suspicious transaction monitoring systems.
Should the purpose of the customer's business relationship be learned?
Yes.
Since the obligation to know a customer goes beyond simply identifying the customer, especially in ongoing business relationships, the organization needs to be aware of the purpose and nature of the relationship.
For example, a commercial customer;
- which sector it operates in,
- for what purpose it will use the payment service
- expected trading volume,
- Countries where transactions will be conducted,
- Estimated customer profile
This can be important from a risk assessment perspective.
According to the Measures Regulation, the obligated party may face an obligation not to establish an employment relationship if they cannot obtain sufficient information about the purpose of the employment relationship.
Therefore, the questions asked during customer acquisition should not be seen as mere formality.
Can Payment Institutions Classify Their Customers into Risk Groups?
One of the fundamental approaches of the MASAK system a risk-based customer identification system.
It is not correct to assume that every customer has the same risk level.
For example;
- the sector in which the customer operates,
- the country where it is located,
- the nature of the processes
- trading volume,
- product used,
- customer acquisition method,
- direction of money transfers,
- the true beneficiary structure of the customer
Factors such as these can be considered in risk assessment.
In high-risk situations, stricter measures beyond standard customer identification procedures may be considered. MASAK (Financial Crimes Investigation Board) published an updated Guide to Stricter Measures on this matter on September 30, 2025.
What are the tightened measures?
Customers or transactions identified as high-risk may require a more thorough review.
The Compliance Program Regulation includes measures such as obtaining additional information about the customer, updating the identity information of the customer and the actual beneficiary more frequently, and monitoring transactions more closely, as part of the tightened measures.
Depending on the specifics of the case, the payment institution;
- may request additional information about the customer
- one can investigate the economic purpose of the transaction,
- They may request information about the source of the funds
- We can update customer information more frequently
- can intensify transaction monitoring,
- It can use a senior management approval mechanism.
The aim here is not to automatically reject all high-risk customers, but to manage the risk with appropriate measures.
Do politically influential individuals require special oversight?
In customer risk assessment, individuals with political influence and certain individuals connected to them may also be among the customer groups that need to be considered.
For such clients, the nature of the relationship, the source of funds, and the transaction profile can be examined in more detail; stricter measures can be applied depending on the risk level.
MASAK's customer identification and risk-based compliance system allows for the implementation of measures beyond standard controls in high-risk customer groups.
Therefore, a payment institution's use of software that only checks the sanctions list does not mean it has fulfilled its entire customer identification obligation.
Is it sufficient to collect customer information once?
No.
Customer recognition is an ongoing process.
The client's identity, activities, or actual beneficiary structure may change over time.
For example, for a corporate client;
- Partners may change,
- company control may pass to another person,
- The scope of activity may change
- Trading volume could increase significantly.
Similarly, an individual customer's transaction behavior can differ significantly from the profile established during initial customer acquisition.
Therefore, customer information needs to be updated at intervals appropriate to the risk level, and the consistency of transactions with the current customer profile needs to be monitored. For high-risk customers, more frequent updates of information are explicitly foreseen as one of the tightened measures.
Is Transaction Tracking part of the Customer Identification Obligation?
Yes.
A true customer recognition system doesn't just work during the onboarding phase, which is the customer acquisition stage.
The payment institution also needs to monitor the customer's transaction behavior after they log into the system.
For example, if a user states that they will make transactions of 20,000 TL per month, but then millions of TL are transferred from their account in a short period of time, this could be an indicator of inconsistency with their customer profile.
Similarly;
- receiving money from numerous different people,
- money transferred to other accounts within seconds or minutes,
- Accessing multiple different customer accounts from the same device,
- continuous money movements that have no economic explanation
This can create situations that require customer identification and suspicious transaction assessment systems to be considered together.
MASAK (Financial Crimes Investigation Board) has published a sectoral Suspicious Transaction Reporting Guide for payment and electronic money institutions, including risk and suspicion indicators according to the characteristics of the sector.
Is a transaction that doesn't match the customer profile automatically considered a crime?
No.
The fact that a transaction differs from a customer's usual transaction behavior does not, in itself, prove that the transaction stemmed from a crime.
However, it could raise an alarm .
Compliance or the relevant control unit;
The customer profile, the parties to the transaction, the transaction amount, the transaction frequency, and its economic explanation should be evaluated together.
The Financial Crimes Investigation Board (MASAK) Suspicious Transaction Reporting system also states that more detailed investigations can be conducted on the customer and transaction when necessary; however, during this investigation, behaviors that might lead the customer to suspect that a report will be filed about them should be avoided.
Can the transaction be completed if identity verification is not possible?
As a rule, no.
In transactions where identity verification is mandatory, if the payment institution cannot adequately verify the customer's identity, the transaction should not be processed.
According to the Measures Regulation, those obligated to do so shall not establish an employment relationship or perform the requested transaction if they are unable to verify the identity of the individual or obtain sufficient information about the purpose of the employment relationship.
This provision is one of the most important consequences of the customer identification obligation.
Therefore, it is not possible to prioritize sales targets over KYC requirements.
Is identity verification different for prepaid cards?
There are specific regulations regarding the application of simplified measures under certain conditions for prepaid vehicles.
MASAK General Circular No. 5 contains specific provisions regarding the obligation to verify identity for prepaid cards or similar devices subject to certain limits and terms of use.
However, the existence of these exceptions;
"Prepaid cards never require identity verification."
That doesn't mean anything.
Whether the product is reloadable, loading and usage limits, cash withdrawal options, and other conditions must be evaluated together. Furthermore, the obligation to identify customers cannot be avoided by relying on simplified measures in cases of suspicious transactions. MASAK (Financial Crimes Investigation Board) also states that simplified measures will be applied within the general principles and limitations of the customer identification system.
What is the relationship between Customer Identification and Suspicious Transaction Reporting?
These two obligations are separate but directly related.
If a payment processing company doesn't know its customer well enough, it becomes difficult to determine which transactions are normal and which are suspicious.
For example, the customer's;
- profession,
- commercial activity,
- expected trading volume,
- Purpose of using the service
If this information is unknown, it will be more difficult to assess whether a transfer of 500,000 TL is consistent with the customer's normal activity.
Therefore, one of the prerequisites for an effective Suspicious Transaction Reporting system is an effective customer identification system. The purpose of the sectoral guidelines prepared by MASAK for payment and electronic money institutions is to enable these institutions to identify suspicious transactions accurately and effectively.
Can a Payment Institution Delegate its KYC Service to Another Company?
Payment institutions may obtain authentication technologies, video conferencing infrastructure, or technical support from various external service providers.
However, outsourcing services should not be interpreted as eliminating the payment institution's ultimate responsibility under MASAK regulations.
Therefore, when obtaining KYC services from an external source;
- compliance of the system used with the legislation,
- method of verifying identity information,
- error rates,
- fake identity checks,
- access security,
- record keeping,
- protection of personal data
Factors such as these should be considered together.
In addition to MASAK regulations, the Central Bank of Turkey's (TCMB) information systems regulations should also be considered regarding payment institutions. The MASAK regulation on remote identity verification directly refers to the TCMB's technical requirements in this area.
Does the Personal Data Protection Law (KVKK) also apply to the Customer Identification Process?
Yes.
Due to the processing of identity, address, contact, transaction, and in some cases biometric data during the customer identification process, obligations under the Turkish Personal Data Protection Law (KVKK) may also arise.
However, processing data that is legally mandated by MASAK regulations and processing data for on-demand marketing purposes are not based on the same legal grounds.
Therefore, all data collected on the payment institution's KYC screen;
"The customer gave explicit consent"
It may not be accurate to explain it with a single legal justification like that.
Mandatory data processing obligations arising from MASAK (Financial Crimes Investigation Board) and other financial regulations, as well as disclosure and data security obligations under the Personal Data Protection Law (KVKK), should be considered together.
Are Payment Institutions Required to Retain Customer Identification Records?
Yes.
Under Law No. 5549, those liable for certain obligations have the responsibility to retain documents, ledgers, and records related to their responsibilities for the period stipulated in the legislation and to present them to the competent authorities upon request. The law prescribes an eight-year period for retention and presentation .
Therefore, the customer needs to close their account;
This does not mean that all KYC records relating to a customer must be irreversibly deleted on the same day.
Retention obligations arising from MASAK (Financial Crimes Investigation Board), KVKK (Personal Data Protection Law), tax regulations, and other financial legislation should be considered together.
What happens if the Customer Identification Obligation is violated?
Violation of customer identification obligations can result in significant administrative penalties for payment institutions.
Law No. 5549 stipulates administrative fines for violations of identity verification and other customer identification obligations. The amounts of fines to be applied between 2022 and 2026, as well as the principles regarding violations of these obligations, are also published separately on MASAK's (Financial Crimes Investigation Board) current sanctions page.
Moreover, the breach of the customer identification obligation should not be considered merely a one-off procedural deficiency.
The fact that numerous customer accounts were opened in violation of regulations may indicate serious structural deficiencies in the payment institution's overall MASAK (Financial Crimes Investigation Board) compliance system.
Since payment institutions are also subject to the supervision and control of the Central Bank of Turkey (TCMB), serious AML/KYC deficiencies may have consequences for the institution's overall regulatory compliance and risk management assessments.
How should an effective KYC system be established in payment institutions?
Payment institutions need to design customer identification systems that are both legally and technologically sound.
In a healthy system, generally speaking;
- Customer types are identified.
- The KYC processes for individuals and legal entities are separated.
- Authentication methods are established.
- Individuals acting on behalf of the client are checked.
- A system for identifying the actual beneficiaries will be established.
- The purpose of the business relationship and the expected transaction profile are defined.
- Customers are divided into risk categories.
- Stricter measures are put in place for high-risk customers.
- Customer information is updated periodically.
- The transaction monitoring system is integrated with the customer risk profile.
- Suspicious transactions are referred to the compliance unit.
- KYC records are maintained in accordance with regulations.
This structure should not only be included in policy and procedure documents, but should also be actually implemented in the payment institution's software and operational systems.
The Most Common Mistakes in Customer Identification at Payment Institutions
One of the most common mistakes made by payment processing companies is the belief that their customer identification obligation is limited solely to obtaining identification documents.
In practice, especially;
- Failure to verify the customer's identity,
- Delaying identity verification in ongoing employment relationships,
- Failure to investigate the actual beneficiary of the legal entity,
- Failure to verify the authority of the person acting on behalf of the customer,
- all customers are assessed at the same risk level,
- customer information not being updated for years,
- Not applying stricter measures to high-risk customers,
- customer profile not being linked to the transaction tracking system,
- Failure to check the regulatory compliance of remote authentication software,
- Continuing to process transactions for commercial reasons even though the customer cannot be identified
This could create significant MASAK compliance risks.
Frequently Asked Questions
Is the payment institution required to verify the customer's identity?
Yes. According to MASAK (Financial Crimes Investigation Board) regulations, payment institutions are required to identify customers and implement necessary measures for customer recognition in certain situations. Identity verification is important in establishing a continuous business relationship, regardless of the transaction amount.
Can payment services be provided if the customer refuses identification?
If identity verification is required but cannot be performed, the payment institution should not establish a business relationship or process the requested transaction.
Is identity verification only carried out for high-value transactions?
No. Identity verification obligations may arise regardless of the transaction amount in situations such as establishing a long-term business relationship or in cases of suspicious transactions.
Can payment institutions identify their customers remotely?
Yes. Remote identity verification in establishing ongoing business relationships between payment and electronic money institutions and their customers can be carried out in accordance with the methods and measures determined by MASAK (Financial Crimes Investigation Board) and the Central Bank of Turkey (TCMB).
Is it possible to open accounts remotely for foreign customers?
With the amendment made in 2026, a regulation was published allowing for remote identity verification of non-Turkish citizens using passports. The concrete customer acquisition process must be established in accordance with the current technical requirements of MASAK and TCMB.
When dealing with company clients, is it sufficient to only obtain the company representative's ID?
Not in every case. It is necessary to identify the legal entity itself, as well as the individuals acting on behalf of the client and, where necessary, the actual beneficiary.
Should customer information be updated later?
Yes. Customer identification is an ongoing process. Especially for high-risk customers, more frequent updating of identity and actual beneficiary information is among the tightened measures.
Conclusion: Customer Identification at Payment Institutions is Not a One-Time Identity Verification
In payment processing facilities, the obligation to identify customers is not limited to simply uploading the user's ID card to the system.
An effective customer recognition system;
Verifying the customer's identity, understanding the purpose of the business relationship, identifying individuals acting on behalf of the customer and the true beneficiary, determining the customer's risk level, keeping information up-to-date, and continuously monitoring customer transactions
It requires the combined application of these elements. MASAK's current regulations stipulate that customer identification is one of the fundamental elements of the system for combating money laundering and terrorist financing by payment institutions.
Especially in payment institutions operating in the digital environment, it is impossible to track hundreds of thousands of users manually. Therefore, designing KYC (Know Your Customer) systems, including customer risk scoring, legitimate beneficiary verification, transaction monitoring, and suspicious transaction alarm systems, along with their software infrastructure is crucial.
Therefore, payment institutions should consider MASAK customer identification processes not as a compliance file to be prepared after operations begin, but a fundamental part of customer acquisition and payment infrastructure ; they should take into account Law No. 5549, MASAK regulations, and the Central Bank of Turkey's technical regulations regarding payment institutions together.