Turkey (TR)
Lead Signal
The defining feature of Türkiye's payments operating environment is the degree to which the Central Bank of the Republic of Türkiye (CBRT) concentrates regulatory and infrastructural control. The CBRT is the sole competent licensing and supervisory authority for payment institutions and electronic money institutions under Law No. 6493 (2013) and its supporting secondary regulation, with non-bank market access available only through the PI and EMI licence categories. That authority was consolidated at the central bank when regulatory and supervisory power over payment and e-money institutions moved from BRSA/BDDK to the CBRT effective 1 January 2020 under Law No. 7192, with operational licensing under the new CBRT regulation commencing from 18 January 2021. The same institution develops and owns the FAST instant-payment system and acquired a controlling interest in the Interbank Card Center (BKM) in 2020, which operates the domestic card switch, local 3DS infrastructure, the BKM Express wallet and the Troy domestic scheme. This combination — single licensing gatekeeper, owner of the national instant rail, and controller of domestic card switching — gives the central bank unusually direct leverage over both non-bank market access and domestic scheme and rail infrastructure.
Against this centralised backdrop, the dominant near-term risk vector is enforcement rather than rulemaking. During 2025 a surge of money-laundering raids targeted payment companies and fintechs in the run-up to a FATF on-site inspection; dozens of payment companies had licences suspended, executives were detained, and several holdings were transferred to the state TMSF, with investigations focused on shareholder and ownership due-diligence failures during licensing. This wave materially raises operational and ownership-due-diligence risk for non-bank PSPs operating in Türkiye and sits directly atop the country's AML/CFT posture. Türkiye exited the FATF grey list on 28 June 2024 after completing its action plan, with one Recommendation (R.15) assessed partially compliant, but a late-2025 FATF on-site inspection reflects residual payments-sector supervision and enforcement gaps. The illicit-finance substance of these developments is carried for original analysis by the FIM monitor; the World Payments view registers only the regulatory and commercial consequences for market participants.
Outlook
The near-term horizon is dominated by deadlines and verification. ÖHVPS 2.0 open-banking certification and production go-live, alongside digital-wallet provider CBRT licensing, carried a 31 December 2025 compliance deadline, bringing TPPs and wallet providers fully into the CBRT perimeter. The late-2025 FATF on-site inspection may drive further payments-sector enforcement, and the annual CBRT minimum-capital and security-deposit re-determination — set in January and entering force mid-year — is trending materially higher. Residual correspondent-banking de-risking is expected to persist despite the June 2024 delisting, sustaining elevated documentary friction for Turkish counterparties.
Other Developments
The non-bank prudential perimeter is tightening on the capital side. Historical minimum security deposits of TRY 2m for bill-payment-intermediation PIs, TRY 3m for other PIs and TRY 5m for EMIs are determined annually by the CBRT, and significantly higher figures — including a TRY 15m floor for bill-payment-only activity — entered force on 30 June 2025. Türkiye's e-money safeguarding regime relies on bank-held blocked segregation: e-money issuers must transfer funds received for issuance into a separate account at Law No. 5411 banks, which block those amounts during the term of use. Both mechanisms shape EMI cost and liquidity profiles and raise the capital cost of operating as a Turkish licensee.
On digital money, crypto-as-payment is structurally blocked while crypto-asset trading is regulated. The CBRT Regulation on the Disuse of Crypto Assets in Payments, published 16 April 2021 and in force 30 April 2021, prohibits direct or indirect use of crypto assets in payments and bars PIs and EMIs from intermediating crypto trading platforms. Law No. 7518, published in the Official Gazette on 2 July 2024, established Türkiye's first crypto-asset legal framework, authorising the CMB/SPK to license CASPs. There is no dedicated stablecoin category equivalent to MiCA EMTs; stablecoins currently fall under CML/CMB crypto-asset rules. The Digital Turkish Lira CBDC pilot completed phase one in February 2024, confirming a two-tier programmable model with bank-supplied wallets.
The resilience regime is among the strictest globally: universal two-factor authentication is mandated and SMS-OTP is banned for mobile banking under the BDDK 2020 banking IT regulation, with real-time incident reporting, data localisation and an annual IS risk assessment reported to the CBRT by end-January. Oversight is coordinated across BDDK, CBRT and a Cybersecurity Directorate whose powers were significantly expanded under Law No. 7545 in March 2025. In domestic schemes, Troy reached approximately 67 million cards as of August 2025, capturing roughly a 20% share of card transactions.
Commercial momentum remains strong despite the enforcement climate. iyzico, wholly owned by Prosus, completed its $87M acquisition of Paynet in February 2025; investment platform Midas raised an $80M round led by QED Investors in Q3 2025; and ColendiBank, an AI-based fully-digital deposit bank, began operating in March 2025.
Cross-Monitor Connections
The W11 AML/CFT surface is sourced from the Sentinel.gi feed, and the original illicit-finance analysis of MASAK's FIU status, the FATF grey-list exit and the 2025 payments-sector money-laundering crackdown is routed to the FIM monitor. The World Payments view carries provenance and the consequences for licensing, enforcement and correspondent-banking access only. The same FATF dynamic links the enforcement crackdown in W7, the supervisory state in W11 and the residual de-risking pressure in W12.
Domains
14 regulatory modules · click to expand the full sub-briefLicensing, Authorisation & Market Access
ConfirmedThe Central Bank of the Republic of Türkiye (CBRT/TCMB) is the sole competent licensing and supervisory authority for payment institutions and electronic money institutions under Law No.
Stablecoins & Digital Money
HighTürkiye has no dedicated stablecoin category equivalent to MiCA EMTs; stablecoins currently fall under CML/CMB crypto-asset rules established by Law No. 7518.
Legal & Litigation
AssessedThe dominant legal and enforcement theme is the 2025 AML crackdown on payment companies.
Commercial Intelligence (M&A, Investment & Product)
HighThis module carries discrete commercial events.
AML/CFT & Financial Crime (Sentinel.gi-fed)
ConfirmedThis module is sourced from the Sentinel.gi feed; the World Payments Monitor attributes the intelligence to Sentinel and does not re-analyse illicit finance.
Conduct, Safeguarding & Promotions
ConfirmedTürkiye's safeguarding regime for non-bank EMIs rests on bank-held blocked segregation. E-money issuers must transfer funds received for e-money issuance into a separate bank account at Law No.
Full per-domain detail — all 14 modules
W1aConfirmedLicensing, Authorisation & Market Access
see this theme across all jurisdictions →5 claimsNon-bank market access via PI and EMI licences under Law No. 6493 (2013); CBRT competent authority since 1 Jan 2020 (operational licensing from 18 Jan 2021); ~86 licensed PI/EMIs in 2024.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Licensing, Authorisation & Market Access
The Central Bank of the Republic of Türkiye (CBRT/TCMB) is the sole competent licensing and supervisory authority for payment institutions and electronic money institutions under Law No. 6493 (2013) and supporting secondary regulation, with non-bank market access available only through the PI and EMI licence categories. Any PSP or EMI seeking entry must obtain a CBRT licence as a Turkish-incorporated joint-stock company, meaning these two routes define the only legal pathways for non-bank participation in the Turkish payments market.
This architecture is the product of a deliberate consolidation. Regulatory and supervisory authority over payment and e-money institutions moved from BRSA/BDDK to the CBRT effective 1 January 2020 under Law No. 7192, enacted in November 2019, with operational licensing under the new CBRT regulation commencing from 18 January 2021. The supervisory-transfer date and the operational-licensing date are distinct, and the bank-PSP versus non-bank-PI/EMI distinction is central: where banks carry their own credit-institution authorisation, non-bank players sit entirely within the CBRT's PI/EMI perimeter. The transfer reshaped the supervisory interface for all Turkish PIs and EMIs by concentrating oversight at the central bank.
Outlook
The licensing module is established and confirmed. Forward attention is on the annual prudential re-determination addressed under W1b and on the licensing-integrity questions surfaced by the 2025 enforcement wave under W7, where investigations centred on shareholder and ownership due-diligence failures during licensing.
Non-bank market access via PI and EMI licences under Law No. 6493 (2013); CBRT competent authority since 1 Jan 2020 (operational licensing from 18 Jan 2021); ~86 licensed PI/EMIs in 2024.
Evidence — 5 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Crypto-as-payment banned since Apr 2021; CASPs regulated under Law No. 7518 (Jul 2024); no MiCA-equivalent stablecoin category; Digital TL CBDC pilot phase one complete.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Stablecoins & Digital Money
Türkiye has no dedicated stablecoin category equivalent to MiCA EMTs; stablecoins currently fall under CML/CMB crypto-asset rules established by Law No. 7518. Industry commentary anticipates that stablecoin payment-rail issuance may migrate to CBRT payment-services law in future, but no official roadmap is published, and that forward-migration assertion rests on single-source commentary rather than confirmed policy.
Law No. 7518, published in the Official Gazette No. 32590 on 2 July 2024, established Türkiye's first crypto-asset legal framework, authorising the CMB/SPK to license and supervise CASPs, with TÜBİTAK supplying technical standards and MASAK enforcing AML. Crypto-asset trading is therefore regulated, but crypto-as-payment is separately and structurally blocked: the CBRT Regulation on the Disuse of Crypto Assets in Payments, published 16 April 2021 and in force 30 April 2021, prohibits direct or indirect use of crypto assets in payments and bars PIs and EMIs from intermediating crypto trading platforms. This prevents non-bank PIs and EMIs from building crypto-settled payment products domestically, sharply constraining any prospective TRY-denominated stablecoin payment rail.
On the public-money side, the bank-led CBDC programme is advancing. The CBRT completed phase one of the Digital Turkish Lira pilot in February 2024, confirming a two-tier programmable payment model with bank-supplied wallets, testing offline resilience and cross-border interoperability and aligning R&D with BIS standards.
Outlook
The stablecoin and digital-money module is established. The key uncertainty is whether stablecoin payment-rail issuance migrates into CBRT payment-services law; absent an official roadmap, the regulatory trajectory for TRY stablecoin payment instruments remains unconfirmed.
Crypto-as-payment banned since Apr 2021; CASPs regulated under Law No. 7518 (Jul 2024); no MiCA-equivalent stablecoin category; Digital TL CBDC pilot phase one complete.
Evidence — 5 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
2025 AML/financial-crime crackdown on payment companies ahead of FATF on-site; Law No. 6493 Arts 27-40 enforcement framework; Competition Board PF/bank acquiring disputes.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Legal & Litigation
The dominant legal and enforcement theme is the 2025 AML crackdown on payment companies. A surge of money-laundering raids targeted payment companies and fintechs, linked to an upcoming FATF on-site inspection; dozens of payment companies had licences suspended, executives were detained, and several holdings were transferred to the state TMSF, with investigations focused on shareholder and ownership due-diligence failures during licensing. This is the dominant near-term risk vector for non-bank PSPs operating in Türkiye, materially raising operational and ownership-due-diligence risk. The trajectory of this module is escalating.
The enforcement wave correlates directly with the W11 supervision-gap finding fed from Sentinel; the underlying illicit-finance analysis is routed to the FIM monitor, and the World Payments view carries the regulatory and licensing consequences only.
Outlook
Litigation and enforcement remain escalating. The late-2025 FATF on-site inspection may drive further payments-sector enforcement, and licensing-integrity scrutiny over shareholder and ownership due diligence is likely to persist as a structural risk for non-bank licensees.
2025 AML/financial-crime crackdown on payment companies ahead of FATF on-site; Law No. 6493 Arts 27-40 enforcement framework; Competition Board PF/bank acquiring disputes.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
W13HighCommercial Intelligence (M&A, Investment & Product)
see this theme across all jurisdictions →5 claimsTrailing-12-month commercial activity led by iyzico/Paynet $87M close, Midas $80M Series B (QED), ColendiBank launch and record ~$219.7M 2025 fintech funding.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Commercial Intelligence (M&A, Investment & Product)
This module carries discrete commercial events. iyzico, wholly owned by Prosus, completed its $87M acquisition of Paynet in February 2025 — a completed M&A deal approved by the Turkish Competition Authority and the CBRT — expanding its B2B/B2B2C offering and targeting TRY 350bn transaction volume; deal value disclosed. Investment platform Midas raised an $80M early-stage round led by QED Investors in Q3 2025, a key highlight of Turkish startup investment activity; amount disclosed. ColendiBank, an AI-based fully-digital deposit bank, received its BDDK operating licence in 2024 and began operating in March 2025, offering accounts, payments, lending, deposits and BNPL via mobile-first infrastructure; the value of this product/market launch is not publicly disclosed.
Taken together, these events indicate continued investment appetite even amid intensified enforcement, with consolidation strengthening incumbents such as iyzico and new entrants expanding neobank competition in the retail layer.
Outlook
The commercial-intelligence module is escalating. The pace of M&A consolidation and the durability of international VC appetite for Turkish fintech are the key trackers, particularly against the backdrop of the 2025 enforcement wave.
Trailing-12-month commercial activity led by iyzico/Paynet $87M close, Midas $80M Series B (QED), ColendiBank launch and record ~$219.7M 2025 fintech funding.
Evidence — 5 structured claims
Key facts
- Content Tier
- D
- Sentinel Feed
- False
Event Findings
W11ConfirmedAML/CFT & Financial Crime (Sentinel.gi-fed)
Sentinelsee this theme across all jurisdictions →9 claimsMASAK FIU; FATF grey-list exit 28 Jun 2024 (R.15 partially compliant); crypto Travel Rule fully in force; late-2025 on-site inspection over residual payments-sector gaps. Sentinel-fed.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
AML/CFT & Financial Crime (Sentinel.gi-fed)
This module is sourced from the Sentinel.gi feed; the World Payments Monitor attributes the intelligence to Sentinel and does not re-analyse illicit finance. Per the Sentinel feed, Türkiye's FIU is MASAK; the country was grey-listed in October 2021 and removed on 28 June 2024 after completing its action plan, with one Recommendation (R.15) assessed partially compliant. CASPs are designated obliged parties, and a crypto Travel Rule (Official Gazette 25 December 2024) applies with a 15,000 TRY threshold. A late-2025 FATF on-site inspection reflects residual payments-sector supervision and enforcement gaps.
The original illicit-finance analysis of these surfaces is routed to the FIM monitor via cross-monitor flags. Within the World Payments view, the FATF status and the on-site inspection are noted only as direct drivers of the payments-sector enforcement crackdown and of residual correspondent-banking de-risking pressure.
Outlook
The Sentinel-fed AML/CFT surface is stable but consequential. The outcome of the late-2025 FATF on-site inspection is the key forward signal, with potential to drive further payments-sector enforcement; refer to the FIM monitor for the underlying financial-crime analysis.
MASAK FIU; FATF grey-list exit 28 Jun 2024 (R.15 partially compliant); crypto Travel Rule fully in force; late-2025 on-site inspection over residual payments-sector gaps. Sentinel-fed.
Evidence — 9 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- True
Event Findings
Safeguarding under Law No. 6493 requires e-money issuers to convert received funds into e-money without delay and to hold customer funds in segregated, blocked bank accounts at Law No. 5411 banks during the term of use, separate from the institution's own assets. PIs/EMIs must additionally deposit minimum security amounts with the CBRT (tiered by activity). Institutions are activity-restricted to permitted payment/e-money services. Conduct is governed by framework agreements with users, KVKK data-protection obligations, mandatory data localisation within Türkiye, and MASAK AML reporting. The CBRT supervises, audits, and can suspend or revoke licences.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Conduct, Safeguarding & Promotions
Türkiye's safeguarding regime for non-bank EMIs rests on bank-held blocked segregation. E-money issuers must transfer funds received for e-money issuance into a separate bank account at Law No. 5411 banks, with the holding bank blocking those amounts during the term of use, thereby segregating customer funds from institution assets. This is a segregation mechanism rather than an insurance or trust structure, and it shapes EMI cost and liquidity profiles accordingly.
Layered on top is a security-deposit buffer. Historically, bill-payment-intermediation PIs faced a TRY 2m minimum, other PIs TRY 3m and EMIs TRY 5m deposited with the CBRT, but these figures are now historical: the CBRT determines amounts annually and significantly higher figures — including a TRY 15m floor for bill-payment-only activity — entered force on 30 June 2025. The exact current schedule following the January 2025 determinations is not precisely captured and requires T1/T2 confirmation; the figures carried here are assessed with the caveat that current amounts are materially higher than the legacy thresholds. The distinction matters most for non-bank PIs and EMIs, for whom rising annual minimum-security thresholds raise the capital cost of operating and may pressure smaller licensees.
Outlook
The annual CBRT minimum-capital and security-deposit re-determination is expected around Q1 2026, set in January and entering force mid-year, and is trending materially higher. Precise capture of the post-30 June 2025 schedule remains an open intelligence gap requiring confirmation from primary or specialist sources.
Safeguarding under Law No. 6493 requires e-money issuers to convert received funds into e-money without delay and to hold customer funds in segregated, blocked bank accounts at Law No. 5411 banks during the term of use, separate from the institution's own assets. PIs/EMIs must additionally deposit minimum security amounts with the CBRT (tiered by activity). Institutions are activity-restricted to permitted payment/e-money services. Conduct is governed by framework agreements with users, KVKK data-protection obligations, mandatory data localisation within Türkiye, and MASAK AML reporting. The CBRT supervises, audits, and can suspend or revoke licences.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Operational resilience for Turkish payments draws on the CBRT's information-systems communiqué for PIs/EMIs and the BDDK's 2020 banking IT regulation (Regulation on Banks' Information Systems and Electronic Banking Services). Institutions must run annual information-systems risk assessments, submit reports to the CBRT by end-January, notify the KVKK board and customers of cyber incidents, and use independent auditors for IT systems. Türkiye mandates strict authentication (universal 2FA, an SMS-OTP ban for mobile banking), data localisation, and real-time incident reporting; cybersecurity oversight is shared among BDDK, CBRT and a Cybersecurity Authority empowered under Law No. 7545 (2025). Core RTGS/instant-payment infrastructure is CBRT-developed and self-assessed against BIS-IOSCO PFMI.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Operational Resilience & Critical Infrastructure
Türkiye operates among the strictest authentication regimes globally. Universal two-factor authentication is mandated and SMS-OTP is banned for mobile banking under the BDDK 2020 Regulation on Banks' Information Systems and Electronic Banking Services, with real-time incident reporting, data localisation, ISO 27001 and PCI DSS compliance required, and an annual IS risk assessment reported to the CBRT by end-January. The SMS-OTP ban forces PSPs — banks and non-banks alike — to adopt phishing-resistant authentication, raising onboarding and infrastructure costs.
Cyber oversight is coordinated across BDDK for banking, the CBRT for payment systems, and a Cybersecurity Directorate whose powers were significantly expanded under Law No. 7545 enacted in March 2025. This third agency adds regulatory complexity for payment operators navigating overlapping BDDK, CBRT and Directorate mandates. The Law No. 7545 development is single-source and carried as assessed.
Outlook
The resilience module is established with high confidence on the authentication regime. The practical effect of the expanded Cybersecurity Directorate mandate on payment operators warrants monitoring as implementation detail emerges.
Operational resilience for Turkish payments draws on the CBRT's information-systems communiqué for PIs/EMIs and the BDDK's 2020 banking IT regulation (Regulation on Banks' Information Systems and Electronic Banking Services). Institutions must run annual information-systems risk assessments, submit reports to the CBRT by end-January, notify the KVKK board and customers of cyber incidents, and use independent auditors for IT systems. Türkiye mandates strict authentication (universal 2FA, an SMS-OTP ban for mobile banking), data localisation, and real-time incident reporting; cybersecurity oversight is shared among BDDK, CBRT and a Cybersecurity Authority empowered under Law No. 7545 (2025). Core RTGS/instant-payment infrastructure is CBRT-developed and self-assessed against BIS-IOSCO PFMI.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Card-scheme infrastructure runs through the Interbank Card Center (BKM), a non-profit jointly owned by the CBRT (controlling stake since April 2020) and banks, which operates the domestic card authorisation/clearing switch, the local 3DS ACS, the BKM Express wallet and the domestic Troy card scheme. Visa and Mastercard dominate alongside Troy (~25M cards in 2026, with Discover/Diners reciprocal acceptance abroad). PCI DSS and 3D Secure 2.2 are enforced; the TR QR Code (TR Karekod) is the national QR standard. Card clearing settles on a deferred net basis (e.g. T+2 via Gosas for member banks). PSPs must share payment infrastructure with other PSPs on request under Article 8 of the Payment Services Regulation.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Scheme & Network Compliance
The Interbank Card Center (BKM) operates the domestic card authorisation and clearing switch, the local 3DS ACS, the BKM Express wallet and the Troy domestic scheme, with the CBRT having acquired a controlling interest in BKM in 2020; Gosas clears card transactions on deferred net settlement at T+2. The exact 30 April 2020 date for the controlling-stake acquisition is not corroborated by primary sources, so year-only framing is adopted. CBRT control of BKM gives the central bank direct leverage over domestic card switching, the Troy scheme and 3DS infrastructure.
Troy itself has scaled materially: it reached approximately 67 million cards as of August 2025, capturing a roughly 20% share of card transactions, and offers credit, debit and prepaid issuing, with acceptance on the US Discover network since 2017. This represents meaningful domestic-scheme displacement of Visa/Mastercard volume; a research-stated figure of around 25 million cards in 2026 is materially understated and stale, and the corrected figure is carried pending higher-tier confirmation.
The access regime is mandatory. Article 8 of the CBRT Payment Services Regulation obliges all PSPs — banks, PIs and EMIs — to make their payment account services and payment infrastructure available to other PSPs on request, with a decision required within one month. This lowers entry barriers for non-bank PSPs but creates margin-squeeze friction with bank POS owners.
Outlook
The scheme module is established. Troy's continued card-base growth and transaction-share trajectory remain the key tracker, alongside the competitive dynamics created by mandatory Article 8 infrastructure access.
Card-scheme infrastructure runs through the Interbank Card Center (BKM), a non-profit jointly owned by the CBRT (controlling stake since April 2020) and banks, which operates the domestic card authorisation/clearing switch, the local 3DS ACS, the BKM Express wallet and the domestic Troy card scheme. Visa and Mastercard dominate alongside Troy (~25M cards in 2026, with Discover/Diners reciprocal acceptance abroad). PCI DSS and 3D Secure 2.2 are enforced; the TR QR Code (TR Karekod) is the national QR standard. Card clearing settles on a deferred net basis (e.g. T+2 via Gosas for member banks). PSPs must share payment infrastructure with other PSPs on request under Article 8 of the Payment Services Regulation.
Evidence — 5 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Domestic rails centre on the CBRT-owned FAST instant-payment system (launched January 2021, 24/7, sub-second settlement in central-bank money) with BKM-run overlay services (KOLAS easy-addressing, TR QR Code), plus the EFT (BPS/RPS) and ESTS RTGS systems. Cross-border settlement flows through correspondent banking and Visa/Mastercard rails; FAST currently operates within national boundaries with cross-border interoperability under exploration. Türkiye is a large remittance and e-export corridor; PayU/iyzico explicitly position Türkiye as a bridge between CEE and Africa for local-currency cross-border trade. International digital wallets (PayPal, Apple Pay, Google Pay) are not permitted to operate domestically.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Payment Corridor Dynamics
The central plank of the corridor view is FAST, the CBRT-developed and owned instant-payment system, which launched a pilot on 18 December 2020 and opened to all customers on 8 January 2021. FAST executes 24/7 sub-second payments in central-bank money, with overlay services — KOLAS easy-addressing and the TR QR Code — commissioned to BKM, and direct participation open to banks and non-bank PSPs with no joining or annual fee. Fee-free non-bank participation in a 24/7 central-bank instant rail is a strong driver of account-to-account payment growth and a competitive threat to card volumes.
On the cross-border dimension, FAST cross-border interoperability is described only as under exploration, with no concrete timeline or specific corridor go-live commitments evidenced.
Outlook
The domestic instant rail is confirmed and established. Cross-border interoperability is the open question; the absence of concrete corridor timelines is a flagged intelligence gap pending further evidence.
Domestic rails centre on the CBRT-owned FAST instant-payment system (launched January 2021, 24/7, sub-second settlement in central-bank money) with BKM-run overlay services (KOLAS easy-addressing, TR QR Code), plus the EFT (BPS/RPS) and ESTS RTGS systems. Cross-border settlement flows through correspondent banking and Visa/Mastercard rails; FAST currently operates within national boundaries with cross-border interoperability under exploration. Türkiye is a large remittance and e-export corridor; PayU/iyzico explicitly position Türkiye as a bridge between CEE and Africa for local-currency cross-border trade. International digital wallets (PayPal, Apple Pay, Google Pay) are not permitted to operate domestically.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Türkiye's payments market is large and fast-growing — 110M+ active cards and ~86 licensed payment/e-money institutions in 2024, with combined PI/EMI transaction volume around TRY 5 trillion (vs ~TRY 120 trillion for banks). The structure blends bank-owned utilities (BKM, Troy) with a deep fintech layer: major acquirers/PSPs include PayTR, iyzico (Prosus/PayU-owned), Param, Stripe Turkey, and marketplace wallets (Trendyol Cüzdan, HepsiPay). Neobank/embedded-finance players Papara (a unicorn) and ColendiBank (BDDK-licensed 2024) are scaling. Fintech led Turkish startup investment in 2025 with a record ~$219.7M raised, and Sipay (valuation ~$875M) bills itself as Türkiye's largest fintech.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Industry Structure & Commercial
Türkiye's payments market combines a large bank layer with a deep and fast-growing fintech layer. As of 2024 there were approximately 86 licensed PI/EMIs plus 6 digital banks, with combined PI/EMI volume of around TRY 5tn against banks' approximately TRY 120tn, and more than 110 million active cards. Key acquirers and PSPs include PayTR, iyzico (Prosus/PayU), Param and Stripe Türkiye; marketplace wallets include Trendyol Cüzdan and HepsiPay; and the neobank layer features Papara, a unicorn, and ColendiBank. This is a structural, market-landscape view distinct from the discrete commercial events tracked under W13.
The shape of the market signals an attractive but increasingly consolidating competitive landscape, with the non-bank layer still small in value terms relative to banks but growing rapidly and producing its first unicorns.
Outlook
The industry-structure module is established with high confidence. Consolidation pressure and the relative scale of the non-bank layer versus banks remain the key structural trends to watch, with discrete deals captured separately under W13.
Türkiye's payments market is large and fast-growing — 110M+ active cards and ~86 licensed payment/e-money institutions in 2024, with combined PI/EMI transaction volume around TRY 5 trillion (vs ~TRY 120 trillion for banks). The structure blends bank-owned utilities (BKM, Troy) with a deep fintech layer: major acquirers/PSPs include PayTR, iyzico (Prosus/PayU-owned), Param, Stripe Turkey, and marketplace wallets (Trendyol Cüzdan, HepsiPay). Neobank/embedded-finance players Papara (a unicorn) and ColendiBank (BDDK-licensed 2024) are scaling. Fintech led Turkish startup investment in 2025 with a record ~$219.7M raised, and Sipay (valuation ~$875M) bills itself as Türkiye's largest fintech.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Merchant acquiring is conducted by banks and CBRT-licensed payment facilitators/PIs; the Turkish Competition Board treats PFs and banks as competitors in this market while PFs depend on banks' POS access. Dispute/chargeback handling is centralised through BKM, which operates a standardised central chargeback system, and consumer-favourable rules (aligned with EU standards) place the burden of proving transaction authenticity on merchants. 3D Secure 2.2 and a deep installment (taksit) culture shape acquiring economics. iyzico (Prosus/PayU), PayTR, Param and Stripe Turkey are leading acquirers; iyzico cites buyer-protection services securing over 4 million consumer transactions.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Merchant Acquiring & Risk
The acquiring module turns on an unresolved competition tension. The Turkish Competition Board treats payment facilitators and banks as competitors in the merchant-acquiring market while their POS-access relationship is also vertical, raising unresolved margin-squeeze concerns where no bank holds a dominant position. This horizontal-and-vertical relationship between payment facilitators and banks creates structural margin-squeeze risk shaping acquirer economics. Dispute and chargeback handling is centralised through BKM, with the merchant authenticity burden placed on the acquiring side.
Merchant-acquiring operational economics — chargeback ratios, high-risk MCC handling and acquirer stress — are thinly evidenced beyond the competition-law framing and are an under-indexed area relative to the regulatory and structural findings.
Outlook
The acquiring module is established but assessed. The unresolved margin-squeeze question and the under-indexed operational economics are the priority areas for deeper evidencing in future cycles.
Merchant acquiring is conducted by banks and CBRT-licensed payment facilitators/PIs; the Turkish Competition Board treats PFs and banks as competitors in this market while PFs depend on banks' POS access. Dispute/chargeback handling is centralised through BKM, which operates a standardised central chargeback system, and consumer-favourable rules (aligned with EU standards) place the burden of proving transaction authenticity on merchants. 3D Secure 2.2 and a deep installment (taksit) culture shape acquiring economics. iyzico (Prosus/PayU), PayTR, Param and Stripe Turkey are leading acquirers; iyzico cites buyer-protection services securing over 4 million consumer transactions.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Open banking is being built out through BKM's GATE infrastructure under CBRT authority, with Payment Initiation and Account Information Services (the ÖHVPS/DSSP framework) defined under Article 12 of Law No. 6493; certification (HHS/YÖS) deadlines were rescaled to a December 2025 ÖHVPS 2.0 transition, and the March 2025 amendment narrowed the connection obligation. Digital wallets were brought into the licensing perimeter (compliance deadline extended to 31 December 2025), with interoperable card-on-file treated as wallet/open-banking services. The CBRT runs the Digital Turkish Lira CBDC pilot, and instant-rail/QR products (FAST, TR Karekod, KOLAS) plus BNPL (Colendi, Garanti Pay) are expanding.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Product Innovation & Market Development
Open banking is built through BKM's GATE infrastructure under CBRT authority, with payment initiation services and account information services defined under Article 12 of Law No. 6493. Institutions with a transition obligation must complete ÖHVPS 2.0 certification and go into production by 31 December 2025, while a March 2025 amendment narrowed the connection obligation. The digital-wallet compliance deadline was likewise extended to 31 December 2025. Together these deadlines bring TPPs and wallet providers fully into the CBRT perimeter, reshaping product-access economics for both banks and non-banks.
This thematic product-access regulatory view sits alongside the Digital Turkish Lira CBDC pilot, whose phase-one completion is detailed under W2, as a forward driver of programmable-payment innovation.
Outlook
The product-innovation module is established and confirmed. The principal near-term event is the 31 December 2025 ÖHVPS 2.0 production go-live and digital-wallet licensing deadline, after which full participant onboarding into the CBRT open-banking perimeter can be assessed.
Open banking is being built out through BKM's GATE infrastructure under CBRT authority, with Payment Initiation and Account Information Services (the ÖHVPS/DSSP framework) defined under Article 12 of Law No. 6493; certification (HHS/YÖS) deadlines were rescaled to a December 2025 ÖHVPS 2.0 transition, and the March 2025 amendment narrowed the connection obligation. Digital wallets were brought into the licensing perimeter (compliance deadline extended to 31 December 2025), with interoperable card-on-file treated as wallet/open-banking services. The CBRT runs the Digital Turkish Lira CBDC pilot, and instant-rail/QR products (FAST, TR Karekod, KOLAS) plus BNPL (Colendi, Garanti Pay) are expanding.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Consumer protection rests on Türkiye's Consumer Protection Law (consumer-favourable, broadly EU-aligned) plus the CBRT payment-services conduct rules and KVKK data protection. Card-dispute/chargeback handling is centralised through BKM, with merchants bearing the authenticity burden. Türkiye has no dedicated UK-style mandatory APP-fraud reimbursement scheme; instead fraud control operates at system level — the CBRT mandates fraud controls through FAST instructions and the Security Overlay Service (SIPER) for risk-data sharing, plus a centralised Merchant Registration System and transaction monitoring. Universal 2FA and the SMS-OTP ban harden consumer authentication.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Consumer Protection & APP Fraud
Türkiye has no dedicated UK-style mandatory APP-fraud reimbursement scheme. Fraud control instead operates at system level, via CBRT FAST instructions, the Security Overlay Service (SIPER) for risk-data sharing, a centralised Merchant Registration System and transaction monitoring, with BKM operating centralised chargebacks under a merchant authenticity burden, and universal 2FA and the SMS-OTP ban hardening authentication. The reliance on system-level controls rather than a reimbursement mandate shifts liability allocation away from a UK-style PSP reimbursement model.
Outlook
The consumer-protection module is established but assessed. Any move toward a mandatory reimbursement regime would materially change liability allocation; absent that, the system-level control architecture is the operative model and warrants monitoring for incremental change.
Consumer protection rests on Türkiye's Consumer Protection Law (consumer-favourable, broadly EU-aligned) plus the CBRT payment-services conduct rules and KVKK data protection. Card-dispute/chargeback handling is centralised through BKM, with merchants bearing the authenticity burden. Türkiye has no dedicated UK-style mandatory APP-fraud reimbursement scheme; instead fraud control operates at system level — the CBRT mandates fraud controls through FAST instructions and the Security Overlay Service (SIPER) for risk-data sharing, plus a centralised Merchant Registration System and transaction monitoring. Universal 2FA and the SMS-OTP ban harden consumer authentication.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False
Event Findings
Wholesale and correspondent-related settlement runs through the CBRT's EFT systems — interbank payments and banks' international correspondent transactions settle in the Turkish Lira Interbank Payments System (BPS), customer payments in the Customer Payments System (RPS) — with ESTS for securities, all open to banks operating in Türkiye and benchmarked against BIS-IOSCO PFMI. Cross-border card flows clear via BKM or correspondent banking. Although Türkiye was removed from the FATF grey list in June 2024, international banks that imposed enhanced due diligence during the 2021-2024 listing continue to apply elevated scrutiny, so Turkish counterparties face higher documentary requirements and residual de-risking pressure in cross-border transactions.
No periodic updates yet · baseline brief is current.
Read the full sub-brief
Correspondent Banking, Settlement & Access
The analytical spine of this structural module is the bank versus non-bank access asymmetry in cross-border settlement. Interbank and banks' international correspondent transactions settle in the CBRT Turkish Lira Interbank Payments System (BPS), customer payments in the Customer Payments System (RPS), and securities in ESTS, all open to banks operating in Türkiye and benchmarked against BIS-IOSCO PFMI. These settlement systems are a bank-PSP domain; non-bank PIs and EMIs do not enjoy the same correspondent access.
Despite the June 2024 FATF delisting, international and correspondent banks continue to apply elevated enhanced due diligence, leaving Turkish counterparties with higher documentary requirements and residual de-risking pressure. This sustains cross-border friction for Turkish counterparties even as the formal FATF status has improved.
Outlook
The correspondent-banking module is stable with high confidence. Residual de-risking is expected to persist despite the delisting; whether elevated EDD eases as FATF on-site verification concludes is the key forward variable.
Wholesale and correspondent-related settlement runs through the CBRT's EFT systems — interbank payments and banks' international correspondent transactions settle in the Turkish Lira Interbank Payments System (BPS), customer payments in the Customer Payments System (RPS) — with ESTS for securities, all open to banks operating in Türkiye and benchmarked against BIS-IOSCO PFMI. Cross-border card flows clear via BKM or correspondent banking. Although Türkiye was removed from the FATF grey list in June 2024, international banks that imposed enhanced due diligence during the 2021-2024 listing continue to apply elevated scrutiny, so Turkish counterparties face higher documentary requirements and residual de-risking pressure in cross-border transactions.
Evidence — 4 structured claims
Key facts
- Content Tier
- SB
- Sentinel Feed
- False