Cesa Yazılım
TR EN DE

AMP • EN

How to Set Up an Electronic Money Institution (EMI) in Turkey

Step-by-step guide to establishing an EMI in Turkey: licensing, capital, KYC/AML, PCI-DSS/3DS, architecture, and application checklist.

How to Set Up an Electronic Money Institution (EMI) in Turkey

This guide covers BDDK requirements for EMI licensing: capital, compliance (KYC/AML), PCI-DSS/3DS, secure architecture, and the application dossier. It’s structured as a hub with spoke links to long-tail topics (capital, PCI-DSS, DR/BCP, KYC/AML).

Last updated

1) Legal and corporate framework

2) Capital and financials

3) Architecture and security

4) Compliance and operations

5) Application dossier (core)

6) Indicative timeline

  1. Preparation (policies, architecture, docs): 6–10 weeks
  2. Filing + pre-reads: 2–4 weeks
  3. BDDK review & clarifications: 8–16 weeks
  4. License + go-live: 4–8 months total (readiness-dependent)

7) Checklist

8) Hub-spoke and links

FAQ

What is the minimum capital for an EMI?

BDDK sets a higher threshold than payment institutions; check latest BDDK releases for exact numbers.

Which technical documents are required?

Network/system architecture, access matrix, HA/DR design, security controls (WAF/DDoS/IPS), PCI-DSS/3DS design, logging/audit policies.

What KYC/AML controls are expected?

e-ID/face match, watchlist screening, STR scenarios, retention per KVKK.

How long does licensing take?

Typically 4–8 months depending on dossier completeness and technical readiness.

Is PCI-DSS mandatory?

If you process/handle card data, yes; even with tokenization, segmentation and controls are reviewed.

Why is DR/BCP critical?

Regulatory expectations and uptime targets require proven RPO/RTO, redundancy, and tested drills.

Conclusion

EMI licensing demands strong compliance, secure architecture, resilient ops, and robust financial planning. Hub-spoke content plus a complete technical dossier accelerates approvals.

Need expert help?

Sıkça Sorulan Sorular

What is the minimum capital for an EMI? BDDK sets a higher threshold than payment institutions; check latest BDDK releases for exact numbers.

Which technical documents are required? Network/system architecture, access matrix, HA/DR design, security controls (WAF/DDoS/IPS), PCI-DSS/3DS design, logging/audit policies.

What KYC/AML controls are expected? e-ID/face match, watchlist screening, STR scenarios, retention per KVKK.

How long does licensing take? Typically 4–8 months depending on dossier completeness and technical readiness.

Is PCI-DSS mandatory? If you process/handle card data, yes; even with tokenization, segmentation and controls are reviewed.

Why is DR/BCP critical? Regulatory expectations and uptime targets require proven RPO/RTO, redundancy, and tested drills. Conclusion EMI licensing demands strong compliance, secure architecture, resilient ops, and robust financial planning. Hub-spoke content plus a complete technical dossier accelerates approvals. Need expert help? 📧 iletisim@cesayazilim.com 📞 +90 850 225 53 34 💬 WhatsApp: EMI License Desk