1. Home
  2. Resources
  3. MASAK compliance for intermediaries
Explainer · Türkiye

MASAK compliance for intermediary institutions and leveraged FX/CFD

What Law 5549 and the MASAK regulations require of an SPK-licensed aracı kurum, with the points that matter most for a firm offering leveraged trading (kaldıraçlı işlemler): customer identification, the risk-based approach, the compliance programme, monitoring, reporting and the red flags that recur in leveraged accounts. Each obligation links to the text it comes from.

Reviewed · Educational material, not legal advice.

Two authorities, one set of AML rules

The SPK licenses intermediary institutions and supervises their compliance with capital-markets legislation (SPK: duties, powers and responsibilities). Anti-money-laundering obligations come from a separate line: Law No. 5549 and the regulations and communiqués issued under it, with MASAK as the authority. The Tedbirler Yönetmeliği lists capital-markets intermediaries among the obliged parties in article 4.

The two meet at inspection. Law 5549 counts SPK experts among the inspectors (denetim elemanları) in article 2(ç), and under article 11 compliance with the Law is inspected by those inspectors, including at MASAK's request, who report breaches to MASAK. An SPK expert can therefore review a firm's AML controls against MASAK's rules.

SPK rules on leveraged trading itself, such as client categories, leverage limits and margin, are outside this guide. Where they touch AML, for example on who may fund an account, check the current SPK text.

Know your customer

Article 3 of Law 5549: identify the customer, and anyone on whose behalf the customer acts, before the transaction. The Regulation sets the detail: identification before a business relationship is established or a transaction is carried out (article 5); the data to collect for natural persons, such as name, date of birth, nationality and the type and number of the identity document (article 6); identification without face-to-face contact for firms whose business is conducted remotely (article 6/A); and identification of the beneficial owner (article 17/A).

Anyone acting for another person must disclose on whose behalf they act. Failing to do so is a crime under article 15 of the Law: six months to one year's imprisonment or a judicial fine of up to 5,000 days. For a broker, this is where account sharing stops being only a terms-of-business question.

MASAK's guide on customer identification and enhanced measures explains how these articles apply, including the additional measures for remote identification.

Risk-based approach

Article 5 of the Law empowers the Ministry to require training, internal audit, control and risk management systems built on a risk-based approach. The risk management articles of the Compliance Programme Regulation (articles 11 and 12) ask the firm to identify, rate, monitor, assess and reduce its risks, including a risk classification of customers and periodic review of the methods used.

The guide for intermediaries prepared with MASAK (TSPAKB) works with three risk types: customer risk, service risk (for example non-face-to-face and electronic transactions) and country risk.

Where risk is higher, the firm applies enhanced measures (sıkılaştırılmış tedbirler, Regulation article 26/A). MASAK's guide lists them:

The compliance programme

The Compliance Programme Regulation (Uyum Programına İlişkin Yönetmelik, Official Gazette 16 September 2008, No. 26999) applies to the obliged parties listed in its article 4, and capital-markets intermediaries are on that list. It was last amended in August 2025 (Official Gazette No. 32994); read the consolidated text before relying on article numbers.

The programme has these parts (article 5, as set out in the intermediaries' guide):

The uyum görevlisi reports to the board or to the board members it designates (article 16) and must meet the conditions in article 17. Since the 2025 amendment, a person cannot be appointed at a firm they inspected in the previous two years, and the removal of an uyum görevlisi is notified to MASAK within ten days with the reasons.

Monitoring and control

Article 15(3) of the Compliance Programme Regulation lists what monitoring and control must cover. In summary:

The Regulation also requires special attention to complex and unusually large transactions and to those with no apparent lawful or economic purpose (Tedbirler Yönetmeliği, article 18, as described in MASAK's enhanced measures guide).

For a leveraged-trading book, payments and trading have to be read together. A pass-through account looks ordinary on the payments side until you see that it barely traded.

Training and internal audit

Training is delivered within a set training programme (Compliance Programme Regulation, articles 22 to 24). Each year, by the end of March, the firm reports its training figures to MASAK: dates, locations, methods, hours, number of participants and content.

Internal audit reviews the compliance programme every year on a risk-based approach and reports the results to the board. The audit figures, such as the volume of transactions reviewed, the number of staff and branches audited and the audit periods, go to MASAK by the end of March (articles 26 to 28).

Reporting and records

Suspicious transactions are reported to MASAK within ten business days of the suspicion being formed, and immediately where delay would be harmful. The steps, the form and the disclosure ban are in the MASAK ŞİB filing guide.

Article 6 of Law 5549 allows the Ministry to require obliged parties to report transactions above amounts it sets (continuous reporting, devamlı bilgi verme), with the transaction types, procedures and exemptions set in secondary rules. Check the current MASAK guidance for whether any continuous reporting applies to your firm's transactions. A transaction reported this way still needs an ŞİB if it is suspicious (Regulation, article 27).

The firm gives MASAK and the inspectors any information and documents they ask for, completely and accurately (Law 5549, article 7), and keeps records for eight years (article 8). A breach of either is a crime under article 14. Breaches of the customer identification, reporting and compliance programme duties are sanctioned with administrative fines under article 13; the amounts have been amended several times, so check the current consolidated text.

Red flags in leveraged trading

MASAK's guide treats transactions that let payments reach third parties other than the real beneficiary, such as payment orders and standing instructions, as higher risk. The intermediaries' guide points to unreasonable orders that mostly end in losses, and to continuous transfers to accounts of apparently unrelated persons at other intermediaries. In a leveraged FX/CFD book these patterns usually look like this:

PatternWhat it looks likeWhat to check
Third-party fundingDeposits from a card or bank account in another person's name; several clients funded from one source.Payer name against the account holder; the relationship between them; whether the payer also trades.
Pass-throughMoney in and out with little or no trading, often to a different destination.Traded volume against funds moved; where the withdrawal goes.
StructuringDeposits or withdrawals split to stay under internal limits or reporting thresholds.Linked transactions over several days, across accounts and payment methods.
Account sharingOne device, IP address or login pattern across accounts in different names.Who actually trades; whether someone is acting for another person (Law 5549, article 15).
Wash trades and loss transferOpposite positions in the same instrument at the same time in related accounts; one side's loss is the other side's profit.Matched tickets and times; what links the accounts; the net profit and loss moved.

A red flag is a reason to look, not a finding. The full list, with the market-abuse patterns, is in the AML red flags checklist for FX/CFD brokers.

Where Marqib fits

Marqib covers the monitoring and case work in this programme for leveraged-trading firms. Deterministic rules run on trading-platform and payment data for patterns in the table above, among them wash trading between linked accounts, third-party funding, pass-through and structuring. Each alert becomes a case with the evidence rows, a draft explanation that cites them, the MASAK clock from the date suspicion was formed and a draft in the MASAK ŞİB structure. The uyum görevlisi decides and files. The policy, training and internal audit remain the firm's own.

Sources

Questions

Are aracı kurumlar obliged parties under MASAK rules?

Yes. The Tedbirler Yönetmeliği lists capital-markets intermediaries and portfolio management companies among the obliged parties in article 4, so they identify customers, report suspicious transactions and keep records under Law 5549.

Must an intermediary have a compliance programme and an uyum görevlisi?

Yes. Capital-markets intermediaries are within the scope of the Compliance Programme Regulation (article 4), which requires policies and procedures, risk management, monitoring and control, training, internal audit and an uyum görevlisi.

Does the SPK or MASAK supervise AML at a broker?

MASAK sets the AML rules and receives reports. Compliance with Law 5549 is inspected by the inspectors the Law lists, which include SPK experts, and breaches are reported to MASAK (articles 2 and 11).

Is funding from a third party's card a reason to file?

Not on its own. It is a reason to check who paid and why. If the explanation does not hold, or the pattern repeats across accounts, it can form a suspicion, and the ten-business-day clock runs from that date.

When are training and internal audit results reported?

Each year by the end of March, under the Compliance Programme Regulation (articles 24 and 28).

Test the rules on your own data

The sandbox runs on synthetic MT5 and payments data, or on your own CSV files tokenised in the browser before upload.