Identification of Legal Entities Regulated in the MASAK Communiqué
Identification of Legal Entities Regulated in the MASAK Communiqué
During the adjustment period regarding remote identification, remote identification became initially available for real persons through Article 6/A added to the Regulation on Measures to Prevent Laundering Proceeds of Crime and Financing of Terrorism with the amendment published in the Official Gazette on 24.02.2021.
As explained in our previous article, banks have recently paved the way for remote identification of legal entities registered in the trade registry. With the latest amendment subject to this article, amendments have also been made to ensure that the necessary security measures can be taken before the Financial Crimes Investigation Board ["MASAK"] in the process of remote identification of legal entities. Accordingly, with the MASAK Communiqué No. 24 Amending the MASAK General Communiqué No. 19 published in the Official Gazette on 11.08.2023 ["Communiqué"] (available only in Turkish):
- Legal entities registered in the trade registry were added to the scope of "customers".
- General principles regarding remote identification of real persons and legal entities registered in the trade registry were determined.
- The remote identification process needs to be annotated from start to finish, and the methods and additional security measures to be used in this process have been identified.
- Remote identification process shall be completed before the establishment of a permanent business relationship.
- The information required to be obtained within the scope of the first paragraph of Article 6 of the Communiqué regarding the identification of real persons and legal entities registered with the trade registry can also be sent through forms filled in electronically through mediums such as websites, internet branches or mobile applications.
- In the event that the remote identification process is carried out through service procurement, the service provider must have TS EN ISO/IEC 27001 Information Security Management System certification.
TSE STANDARD TO ARTIFICIAL INTELLIGENCE
As explained in our previous article, artificial intelligence may also be used in the services related to remote identification. According to the Communiqué, when artificial intelligence applications are used, the artificial intelligence will check whether the person undergoing remote identification is a real person and will verify that the applicant is the owner of the submitted identity card by comparing the photograph and images on the identity card.
In order for artificial intelligence algorithms to be used, it is mandatory to obtain a Turkish Standards Institute report showing that the false confirmation rate is below one in ten million while comparing the photo on the contactless chip or, if this is not possible, the photo on the identity document with the face image of the applicant who is present live or while performing a viability test. However, such a report will not be required if the artificial intelligence algorithm is provided by a foreign organization and the organization in question has an internationally recognized certificate abroad.