top of page

Enhanced Measures Guideline under the Know Your Customer Principle Updated

  • Writer: Vardar Şanlı
    Vardar Şanlı
  • Sep 30, 2025
  • 2 min read

The Guideline on Enhanced Measures (“Guideline”), published by the Financial Crimes Investigation Board (FCIB), has been reviewed in line with technological developments, changes in the structure of financial markets, and the requirements of compliance with international standards, and was updated on September 30, 2025. While the previous version primarily set out obligations for traditional financial institutions as well as certain businesses and professions, the updated version has expanded the scope to explicitly include the introduction of additional obligations for crypto asset service providers (“CASPs”) payment and electronic money institutions and terminal services, and the implementation of stricter measures regarding remote identification


Changes Introduced with the Updated Guideline


While the previous version of the Guideline on Enhanced Measures primarily set out obligations for banks, financial institutions, and certain designated non-financial businesses and professions, the updated version has expanded its scope to include CASPs, payment and electronic money institutions, as well as payment terminal services.


In the previous version, references to crypto assets were limited to the context of “technological risks, ” whereas the current version introduces detailed provisions on crypto assets in line with FCIB General Communiqué No. 29. In this regard, it has been made mandatory to include minimum information on the sender and the recipient in crypto transfer messages, and transaction amount limits applicable to stable crypto asset transfers have been incorporated into the Guideline. In addition, restrictions concerning the source of funds, the purpose of transactions, transaction monitoring, as well as the number and amounts of transactions in customer relations with CASPs have been made compulsory.


Whereas the previous version regulated remote identification only as “additional measures, ” the updated version explicitly prohibits CASPs providing intermediary services for privacy based crypto assets from carrying out remote identification. Furthermore, it is now mandatory that the first financial movement in crypto transactions be executed through a bank account or a card account that is verifiably linked to the customer’s identity.


While the previous version contained no provisions regarding payment and electronic money institutions, the updated version introduces enhanced measures governing their relationships with merchants and payment terminals. In particular, it is stipulated that the first transaction should be executed through a financial institution, and that payment terminals must not be used by third parties; otherwise, the business relationship should be terminated.

bottom of page