Establishment and Operating Principles of Crypto Asset Service Providers
- Vardar Şanlı

- Mar 13, 2025
- 5 min read
The Communiqué on the Establishment and Operating Principles of Crypto Asset Service Providers (the “Communiqué”) published in the Official Gazette dated March 13, 2025 and numbered 32840, regulates the principles and rules regarding the establishment of crypto asset service providers (the “CASPs”), as well as their founders, executives, shareholders, and personnel, operations, organization, and obligations.
You will find below a summary outlining the key rules that CASPs must comply with under the Communiqué. A. Conditions for Establishment and Operating License Under the Communiqué, significant and detailed regulations have been introduced regarding the establishment and operating licenses of CASPs, in alignment with the principle decisions published by the Capital Markets Board (the “Board”) and the amendments made to the Capital Markets Law No. 6362 through Law No. 7518. These regulations cover not only the requirements related to the founders of CASPs but also the conditions necessary to obtain an operating license, ranging from the selection of a trade name to capital requirements. To obtain an operating license, CASPs must design their organizational structure to include (i) adequate personnel employment, (ii) internal audit, internal control, and risk management systems, and (iii) generally sound management structure. After obtaining an establishment license from the Board, CASPs are required to apply for an operating license within six months at the latest. Failure to submit an application within this period will result in the loss of the right to obtain an operating license. The Communiqué differentiates between entities on the “List of Operating Platforms” and those applying after its publication. Entities on this list must comply with the new obligations by June 30, 2025. Additionally, entities with an operating license must obtain an “Authorization Certificate” to commence operations in line with similar requirements for intermediary institutions. B. Conditions for Personnel The Communiqué imposes strict requirements on CASPs personnel and executives, stating that they must meet the same conditions as founders and shareholders, except for the financial sufficiency requirement. It mandates that the majority of board members and all personnel must either hold a bachelor's degree from a four-year higher education institution. The Communiqué provides detailed guidelines for CEOs and deputy CEOs, requiring Board approval for their appointments. Additionally, the CEO must be a fulltime resident in Türkiye, aligning the regulatory structure with that of banks. Under the Communiqué, CASPs are obligated to employ specialized personnel in internal audit, internal control, risk management, operations, information security, and IT. The Communiqué also emphasizes that personnel must demonstrate professional competence, diligence, integrity, and confidentiality in their duties.
C. Conditions for Operations and Principles
CASPs are required to comply with the principles set by the Board, maintain membership in the Capital Markets Association, and ensure the continuity of critical operations in accordance with relevant regulations. As part of their customer risk disclosure obligations, CASPs must clearly disclose information regarding general risks associated with crypto assets, transaction fees, market makers, asset custody conditions, and counterparty details. Before engaging in transactions, platforms must sign a framework agreement with customers in written or electronic form, and any modifications require the customer’s prior consent. During the customer identification process, identity verification must comply with applicable regulations, and for joint accounts, all rightful owners must undergo separate identity verification. Additionally, platforms must maintain updated information on their websites, including authorized services, risk disclosures, custody policies, and measures for extraordinary situations. Furthermore, key platform information must be published on the Public Disclosure Platform (the “PDP”), and any updates must be made within two business days of a change.
D. Conditions Related to Obligations
CASPs must obtain Board approval for significant changes in their shareholding structure, while smaller share transfers must be reported within ten business days. Unauthorized share transfers will be deemed invalid. Additionally, trade registry records, trademark registrations, and operating licenses must be publicly announced on the PDP and company websites. In cases of temporary suspension or license revocation, such announcements are also required. While CASPs can freely invest in certain financial institutions, their participation in other companies is limited to 25% of their equity capital. Furthermore, advertisements and announcements must not include misleading statements, guaranteed profit promises, or exploit sensitive topics. High-value material rewards in promotional campaigns are also prohibited.
E. Conditions for Document and Record Keeping System
CASPs may receive customer orders through their own websites or digital platforms. During this process, critical order details such as order type, validity period, price, and quantity must be recorded. A transaction form must be sent to the customer’s registered email address no later than the end of the same business day. Additionally, all records generated by CASPs must be securely stored, ensuring accessibility, traceability, and confidentiality. To maintain compliance, CASPs are required to establish internal control, internal audit, and risk management units.
F. Conditions for Outsourcing Services
The Communiqué extensively regulates outsourcing services for CASPs. Certain critical functions that must be exclusively performed by the board of directors cannot be outsourced. These include activities requiring the Board approval, provision and marketing of regulated services, accounting of CASP transactions, preparation of financial reports, and internal audit, internal control, and risk management functions. However, outsourcing is permitted for non-core services such as consulting and security, provided they are not directly related to CASP operations. A written contract is mandatory between the CASP and the service provider. Additionally, the CASPs must develop an emergency plan addressing risks associated with outsourced services. A detailed report on outsourcing decisions, including scope, cost, and implementation details, must be prepared by senior management and submitted to the board of directors. The Board holds the authority to audit external service providers and review all related documents and information. These regulations aim to ensure effective management of outsourcing processes and minimize risks associated with external service procurement.
G. Conditions for Information Systems Audit
Under the provisions of Communiqué No. III-62.2, CASPs must enter into an agreement with an independent auditor listed on the Board’s website for information systems audits. In this context, CASPs are required to conduct an independent audit of their information systems at least once a year.
H. Conditions for Business Restrictions
CASPs are prohibited from engaging in industrial, agricultural, or other commercial activities outside the Board-approved operations. They cannot issue financial commitment documents or engage in commercial real estate trading, except where explicitly permitted by regulations. Additionally, they cannot accept deposits or participation funds or engage in any transactions leading to such an outcome. CASPs are also strictly forbidden from: unauthorized disposal of customer assets, providing preferential transactions to employees or customers, opening fictitious accounts or conducting off-the-record transactions.
Furthermore, they may not operate under general Powers of Attorney, induce unnecessary or excessive trading, cover customer losses, or execute transactions without customer instructions. Additional restrictions include to donations exceeding 0.05% of their annual equity capital, engaging in foreign exchange trading or transfers abroad, and using any terms or symbols that imply foreign exchange trading activities.
I. Conditions for Compliance Deadlines
CASPs listed in the List of Operating Entities must apply for an operating license by June 30, 2025. Companies that fail to apply but are included listed in the List of Operating Entities will be subject to liquidation. For operating license applications, CASPs must submit two separate reserve proof reports from the last twomonth period and an independent information systems audit report by September 30, 2025. The final deadline to obtain an Authorization Certificate is June 30, 2026 for the operating entities. Regarding custody obligations, platforms must sign a contract with at least one custody provider by December 31, 2025. Liquidated entities must cease operations within 15 days, stop accepting new customers, and ensure that customers’ crypto assets are converted into cash. Additionally, existing framework agreements must be renewed by December 31, 2025. Custody providers must also apply for an operating license by June 30, 2025, while the first independent audits will be conducted for the 2026 fiscal year.


