single blog

Fintech regulation Turkey is not one licence or one regulator. The correct framework depends on what the product actually does: payments and electronic money are centred on the Central Bank of the Republic of Türkiye (TCMB); banks and digital banks are regulated by BDDK; capital-markets and crowdfunding activities fall under SPK; crypto-asset service providers are now within SPK’s capital-markets framework; AML/CFT obligations are administered by MASAK for businesses that fall within the obliged-party rules; and personal-data processing is also subject to KVKK and sector-specific information-systems rules.

The safest 2026 sequence is: define the money/data flow → classify the regulated activity → identify the competent regulator → test whether an operating licence/authorisation is required → design the company/capital/governance/technology around that licence → build AML, consumer, security and data compliance → launch only within the authorised scope.

Table of Contents

Quick Answer: Which Regulator Applies to Your Fintech Model?

Business model Primary regulatory owner First question
Payment service / payment institution TCMB Does the model provide one or more payment services defined in Law No. 6493?
Electronic money / wallet TCMB Is the business issuing electronic money and/or providing authorised payment services?
Payment initiation / account information / open-banking service TCMB Does the model fall within the payment-service/data-sharing services regulated under Law No. 6493 and secondary rules?
Bank / digital bank / Banking-as-a-Service bank BDDK Does the model perform banking activity requiring a banking licence or operate under the Digital Banks/BaaS Regulation?
Crowdfunding platform SPK Does the platform conduct equity- or debt-based crowdfunding within the SPK framework?
Crypto-asset platform / custody SPK Is the business a crypto-asset service provider subject to the 2024 law change and 2025 secondary communiqués?
Investment / brokerage / portfolio activity SPK Does the product amount to a regulated capital-markets service rather than software only?
Pure B2B fintech software vendor Depends on function Does the company merely supply technology, or does it itself hold funds, execute payments, intermediate investments or provide another regulated service?

Do not start with the word “fintech.” Start with the regulated function. Two apps that look similar to a user can have very different legal status depending on who holds funds, who contracts with the customer, who executes the transaction and who carries regulatory responsibility.

1. Payments and Electronic Money: TCMB Is the Regulator

Turkey’s payments framework is based on Law No. 6493 and its secondary legislation. Since 1 January 2020, TCMB has been responsible for the regulation and supervision of payment services, payment service providers and electronic-money issuance.

TCMB publishes separate live lists showing:

  • authorised payment institutions and the exact Article 12 payment services each may provide;
  • authorised electronic-money institutions and their payment-service scopes;
  • institutions whose licences have been suspended or revoked.

This scope-by-scope model is important: a company does not receive a generic “fintech licence” authorising every payment product.

Official starting point: TCMB Payment Services.

2. Payment Institution vs Electronic-Money Institution

Payment services and electronic-money issuance should not be treated as interchangeable.

Question Why it changes the route
Will the company only provide specified payment services? A payment-institution authorisation may be the relevant route, with scope tied to the approved services.
Will the company issue electronically stored monetary value against funds received? Electronic-money issuance brings the electronic-money-institution framework into the analysis.
Will the company hold customer funds? Safeguarding, accounting, operational and regulatory design becomes central.
Will the company provide acquiring, money transfer, payment initiation or account information? Each service must be mapped to the legal service definitions and the requested licence scope.

Capital, shareholding, governance, technical infrastructure and application requirements should be taken from the current licence route for the exact service. Do not reuse old internet tables with generic “TRY 1m / 2m / 5m fintech capital” figures.

Once the proposed service has been classified within the payment or electronic-money framework, continue with the Payment & E-Money Licence in Turkey guide for the applicant’s corporate, financial, technical and compliance file. For a business choosing a provider to accept card payments for its own sales, use the separate Virtual POS merchant-application guide.

3. Supervision Is Active, Not Just a Registration Formality

TCMB’s January 2026 supervision release shows why an operating licence should not be viewed as a one-time setup document. Based on its 2025 supervision work, TCMB reported that 7 institutions’ operating licences were revoked and 14 were temporarily suspended, alongside other supervisory measures and administrative penalties.

This is a dated enforcement indicator, not a prediction about any individual applicant. The practical lesson is that regulated fintechs need ongoing:

  • licence-scope control;
  • governance and internal controls;
  • financial/safeguarding compliance;
  • information-systems and security controls;
  • regulatory reporting;
  • AML/CFT compliance;
  • consumer and complaints processes.

Current TCMB authorisation status should be checked on the regulator’s live institution lists rather than through an old fintech directory.

4. Open Banking Is Part of the Regulated Payments Framework

Turkey’s open-banking/data-sharing framework includes regulated payment initiation and account information services and TCMB’s payment-services data-sharing infrastructure/guidance.

A founder planning account aggregation or payment initiation should map:

  • which party is the account servicing payment service provider;
  • which party provides the regulated initiation/information service;
  • customer authentication/consent mechanics;
  • API/data-sharing standards;
  • security and incident controls;
  • data minimisation and retention;
  • whether the company itself needs authorisation or acts only as a technology supplier to an authorised institution.

Do not treat “customer consent” alone as permission to access banking data outside the regulated technical and legal framework.

5. Digital Banks and Banking-as-a-Service: BDDK, Not TCMB Payment Licensing

A digital bank is still a bank. BDDK maintains the Regulation on the Operating Principles of Digital Banks and Banking as a Service Model within the Banking Law framework.

This is a different regulatory path from establishing a payment or electronic-money institution. If the business model involves accepting deposits/participation funds, lending as a bank, or operating as a licensed digital bank, do not attempt to fit it into a Law No. 6493 payment-institution application.

Official regulation list: BDDK Banking Regulations.

6. Crowdfunding and Investment Platforms: SPK Boundary

Equity- and debt-based crowdfunding sit within Turkey’s capital-markets regime. SPK’s current legislation includes the Crowdfunding Communiqué (III-35/A.2).

A platform should not describe itself merely as a “marketplace connecting founders and investors” if its actual activity falls within regulated crowdfunding or another investment-service category. Before launch, identify:

  • who offers the investment instrument;
  • who solicits/invites investors;
  • who operates the platform;
  • how investor funds are handled;
  • what disclosures and limits apply;
  • whether SPK listing/authorisation requirements are triggered.

Official SPK legislation portal: SPK Legislation System.

7. Crypto-Asset Services: SPK Rules and the 2026 Transition Matter

Law No. 7518, published in July 2024, brought crypto-asset service providers within SPK’s regulatory and supervisory framework. In 2025, SPK published two major secondary communiqués:

  • III-35/B.1 — establishment, commencement of operations, shareholders/transfers, management/personnel, internal systems, information systems, records and audit;
  • III-35/B.2 — permitted services/activities, trading environments, custody/transfers, listing and capital adequacy.

For 2026 due diligence, there is an additional transition point: SPK’s public “Faaliyette Bulunanlar Listesi” is a provisional list and expressly does not mean that every listed business has been authorised under the new framework. A founder, investor or counterparty should distinguish provisional-list status from establishment approval, operating permission and any final authorisation document required under the applicable rules.

SPK also announced on 26 March 2026 that certain transition periods for platforms’ custody agreements and for businesses on the provisional operating list to obtain authorisation documents would be set after SPK-authorised custody institutions begin providing custody services broadly. This makes current SPK status checks more important than relying on a 2025 article or an old provider list.

Therefore, a crypto exchange or custody project should not be presented as an ordinary software company with only AML/KVKK obligations, and a company’s appearance on a provisional SPK list should not be marketed as a completed operating authorisation.

Official sources: SPK Crypto-Asset Service Provider Communiqués and current SPK crypto-asset service-provider status list.

8. AML/KYC: First Ask Whether You Are a MASAK “Obliged Party”

AML/KYC is not one identical checklist for every company using financial technology. Under Law No. 5549 and secondary rules, specific financial institutions and other businesses are obliged parties with customer-identification, suspicious-transaction reporting, record/information and—in specified cases—compliance-program obligations.

MASAK’s current compliance materials expressly include payment and electronic-money institutions within key obliged-party obligations. The 2025 updated enhanced-measures guidance also addresses technology risks, risky countries, crypto relationships, payment/e-money institutions and terminal services.

A regulated fintech should design a risk-based AML programme around:

  • customer/beneficial-owner identification;
  • risk classification;
  • ongoing transaction monitoring;
  • sanctions/high-risk jurisdiction controls where applicable;
  • suspicious transaction escalation/reporting;
  • prohibition on tipping-off;
  • training, internal control, risk management and compliance officer/program where the applicable rules require them;
  • record retention and regulatory access.

Official source: MASAK Obligations.

9. KYC Is Not “Collect Passport + Selfie for Everyone”

The correct identity-verification method depends on the regulated entity, customer type, transaction, remote-onboarding rules and sector-specific regulation.

Before choosing an onboarding vendor, map:

  • natural person vs legal entity;
  • domestic vs foreign customer;
  • beneficial ownership;
  • face-to-face vs remote identity verification;
  • document/chip/video/liveness or other approved method where applicable;
  • PEP/high-risk controls;
  • ongoing monitoring and refresh;
  • data retention and evidence requirements.

A vendor’s technical ability to scan an ID does not prove regulatory acceptance for the specific institution.

10. KVKK: Do Not Use a Blanket “All Financial Data Must Stay in Turkey” Rule

Fintech companies process personal and often sensitive financial/behavioural data, so the Personal Data Protection Law (KVKK) is central. But a generic statement that all financial data must always be stored only on servers physically located in Turkey is too broad.

Separate:

  • KVKK legal basis, transparency, security and data-subject rights;
  • cross-border personal-data transfer rules under the amended Article 9 framework;
  • sector-specific information-system, outsourcing, primary/secondary system or data-location rules that can apply to a regulated bank/payment/e-money/capital-markets institution.

KVKK Article 9 was materially amended in 2024 and now provides adequacy and appropriate-safeguard mechanisms for cross-border transfers, plus limited exceptional routes under the legal conditions.

Official source: Personal Data Protection Law.

11. Information Systems and Cybersecurity Are Licence Architecture

For regulated fintechs, cybersecurity is not a generic ISO checklist added after product launch. TCMB’s payment-services framework includes a dedicated communique on information systems of payment/e-money institutions and payment-service data-sharing services. Banks and capital-markets/crypto institutions have their own sector rules.

During architecture design, identify:

  • critical systems and service continuity;
  • authentication and transaction security;
  • privileged access;
  • encryption/key management;
  • logging and traceability;
  • penetration/vulnerability controls;
  • outsourcing/cloud/vendor requirements;
  • incident response and regulator notification;
  • business continuity/disaster recovery;
  • independent audit requirements where applicable.

Do this before committing to a cloud/vendor stack that may conflict with the chosen licence.

12. Consumer Protection and Safeguarding Depend on the Product

Payment/e-money, banking, investment and crypto products have different customer-asset and disclosure mechanics. A regulated company should map:

  • whether it holds customer money/assets;
  • how funds/assets are safeguarded or custodied;
  • fees and pre-contract information;
  • complaints and dispute handling;
  • unauthorised/fraudulent transaction rules;
  • refund/cancellation mechanics;
  • customer communications and advertising claims;
  • service interruption/business continuity.

Do not use “our funds are insured” or “customer money is guaranteed” unless the exact statutory protection mechanism truly applies.

13. Foreign Investors: Equal Treatment Does Not Waive Financial-Regulatory Approval

Turkey’s general FDI framework is based on equal treatment, but regulated financial businesses are still subject to sector-specific rules on founders/shareholders, qualified holdings, management, capital, corporate form and regulatory approval.

Therefore, do not publish either of these blanket claims:

  • “Foreign investors cannot own a Turkish fintech.”
  • “Foreign investors can always own 100% of every Turkish regulated financial institution without additional approval.”

Test the selected licence and shareholder structure under the current sector rules before incorporation or acquisition.

14. Company Formation Must Follow Regulatory Classification

An ordinary software startup can often be incorporated with a broad technology activity. A regulated payment, e-money, bank, crowdfunding or crypto business may require a specific legal form, minimum capital, shareholder suitability, governance, purpose clause and pre-licence structure.

Before MERSIS filing:

  1. draw the customer/fund/data flow;
  2. classify the regulated service;
  3. confirm the regulator and licence type;
  4. confirm corporate form and capital;
  5. screen shareholders/managers;
  6. design governance/internal functions;
  7. validate technology/security architecture;
  8. then draft the company purpose and formation file.

For the general corporate layer, see Company Formation in Turkey: 2026 Guide.

15. Licence vs Technology Vendor: A Critical Boundary

A SaaS vendor can sell fraud detection, onboarding, ledger, payment orchestration or banking middleware without necessarily becoming the regulated financial institution. The boundary can change if the vendor itself:

  • contracts with end customers for the regulated service;
  • holds or controls customer funds/assets;
  • executes or initiates regulated transactions in its own regulatory capacity;
  • provides regulated investment/financial intermediation;
  • assumes responsibilities reserved for a licensed institution.

Contract wording alone cannot change the substance of the activity. Map the real operational role.

16. Regulatory Map Before Launch

Question If yes, investigate
Do we move money for customers? TCMB / Law No. 6493 payment-service classification.
Do we issue stored monetary value? TCMB electronic-money framework.
Do we accept deposits or operate as a bank? BDDK Banking Law / digital-bank rules.
Do we intermediate investment/crowdfunding? SPK capital-markets rules.
Do we operate crypto trading/custody? SPK crypto-asset service-provider rules.
Are we a MASAK obliged party? AML/KYC, STR, compliance programme and sector guidance.
Do we process/share personal data? KVKK plus sector-specific IT/data rules.
Do we outsource critical systems? Regulator-specific outsourcing/cloud/information-system rules.

17. What Workon Can Coordinate

Workon can coordinate Turkish company-formation readiness, foreign shareholder documents, registered-address/workspace, bank-account application support and the operational handoff to appropriately qualified fintech regulatory, legal, AML, cybersecurity and tax professionals. The competent regulators and appropriately licensed or qualified professionals retain responsibility for financial-services authorisations, regulated services, MASAK compliance functions and professional opinions.

Last reviewed: 17 September 2026.

Workon fintech company registration and regulatory readiness coordination Turkey

For a regulated fintech, classify the licence before finalising the Turkish company structure and technical stack.

Key Takeaways

  • There is no universal fintech licence or single fintech regulator in Turkey.
  • TCMB regulates payment services, payment institutions and electronic-money institutions under Law No. 6493.
  • BDDK owns banking and digital-bank/BaaS regulation.
  • SPK owns capital-markets/crowdfunding and now regulates crypto-asset service providers under the updated capital-markets framework.
  • AML/KYC obligations depend on whether the business is an obliged party and on its regulated model; use MASAK’s risk-based rules.
  • KVKK does not by itself create a blanket rule that every piece of financial data must stay on Turkish servers; sector-specific IT rules must be checked separately.
  • Foreign-investor equal treatment does not remove financial-sector shareholder, capital, governance or approval requirements.
  • Classify the service before incorporating or choosing the technology stack.

Frequently Asked Questions

No. The regulator depends on the actual function: TCMB for payment and e-money services, BDDK for banking and digital banking, SPK for capital-markets, crowdfunding and crypto-asset service providers, MASAK for AML\/CFT obligations where the business is an obliged party, plus KVKK and sector-specific information-systems rules for data and technology.

Map the real customer, money and data flows first, then classify the regulated activity, identify the competent regulator and test whether operating authorisation is required. The company form, capital, governance and technology should be designed around that classification rather than around a generic fintech label.

No. A pure B2B technology vendor may remain outside the licensed-provider role, while a company that itself holds or controls customer funds, executes regulated payments, issues electronic money, intermediates investments or provides another regulated service can enter a licensing perimeter. Contract labels do not override the real function.

Foreign investment is generally permitted, but equal treatment does not remove sector-specific shareholder suitability, qualified-holding, capital, governance or regulatory approval requirements. The exact ownership route must be checked under the selected licence regime.

No blanket rule should be stated that broadly. KVKK cross-border transfer rules and the amended Article 9 framework must be analysed separately from sector-specific information-system, outsourcing or data-location requirements that may apply to regulated banks, payment institutions or capital-markets firms.

Not necessarily. The article notes that SPK's public provisional operating list is not itself proof that every listed business has completed all authorisation steps under the updated framework. Current SPK status and the exact approval stage should be verified before relying on a provider.

Important: This guide provides general information on fintech regulation in Türkiye and is not legal, financial-regulatory, investment, AML, cybersecurity or data-protection advice. Licence scope, capital, ownership, governance, information-system, AML and data requirements depend on the exact business model and current TCMB, BDDK, SPK, MASAK and KVKK rules. Confirm the proposed model with the competent regulator and appropriately licensed/qualified professionals before incorporating, raising capital, building regulated infrastructure or serving customers. Workon coordinates business setup and operational readiness but does not issue financial-services licences or provide regulated financial services.

Contact Us

If you have any questions, you can contact us.

or

Let's Connect

Fill out the form below to get information about the services we offer and we will call you back.