FATF Türkiye Mutual Evaluation 2026: Refreshing the Respondent File

On 23 September 2026 the Financial Action Task Force published its mutual evaluation report on Türkiye, based on an on-site visit in November 2025. The FATF Türkiye mutual evaluation rates Recommendation 13, the correspondent banking standard, compliant, and puts 38 of the 40 Recommendations in the compliant or largely compliant bands. It also finds only a moderate level of effectiveness on eight of the eleven immediate outcomes, including the outcomes the FATF groups as supervision and preventive measures, and it places Türkiye in enhanced follow-up.

For a bank providing correspondent services to Turkish respondents, that report is relevant to jurisdictional and respondent-level factors tested by the EU, UK and US regimes. The EU and UK correspondent provisions require an assessment of the respondent’s AML/CFT controls and a determination, from public information, of its reputation and the quality of supervision; the US rule separately requires a risk assessment that includes the AML and supervisory regime of the relevant jurisdiction. Country-risk memos and respondent reviews written before 23 September cite an older picture. The findings that change the file sit in the effectiveness chapters, on politically exposed persons, suspicious transaction reporting, beneficial ownership verification and targeted financial sanctions. The compliant rating on Recommendation 13 answers a narrower question.

Enhanced follow-up is also easy to misfile. It is a follow-up category inside the FATF’s evaluation process, and Türkiye’s place on the public list of jurisdictions under increased monitoring ended on 28 June 2024.

Related reading: MONEYVAL Bulgaria AML Follow-Up: The Correspondent Banking Read

The Türkiye file in dates

Five dates frame any respondent review that touches a Turkish bank this year:

  • 21 October 2021: the FATF adds Türkiye to its list of jurisdictions under increased monitoring (FinCEN release of 26 October 2021).
  • 28 June 2024: the FATF removes Türkiye from that list, together with Jamaica (FinCEN release of 3 July 2024).
  • November 2025: the assessment team’s on-site visit. The report assesses Türkiye’s measures as they stood at that point.
  • 23 September 2026: the mutual evaluation report is published. Türkiye receives a roadmap of Key Recommended Actions to complete within three years and is placed in enhanced follow-up.
  • 10 July 2027: Regulation (EU) 2024/1624 (AMLR) applies, and its Article 36 sets the EU’s enhanced due diligence measures for cross-border correspondent relationships directly.

The November 2025 date deserves a line of its own in the file. The report describes a snapshot, and some findings were already moving when it was taken. The FATF says a solid regulatory framework for virtual asset service providers “was still being implemented at the time of the onsite visit”. A correspondent citing the report for a respondent with crypto-related business should record that vintage next to the citation, because the position ten months later may differ and the report cannot tell you by how much.

Reading the ratings table beyond the headline count

The FATF publishes two sets of ratings. Technical compliance ratings reflect, in the FATF’s words, the extent to which a country has implemented the technical requirements of the Recommendations. Effectiveness ratings reflect the extent to which a country’s measures are effective, assessed across eleven immediate outcomes.

On technical compliance, Türkiye’s table reads 15 compliant, 23 largely compliant, two partially compliant and none non-compliant. The two partially compliant ratings are Recommendation 7 (targeted financial sanctions related to proliferation) and Recommendation 8 (non-profit organisations). Recommendation 10 on customer due diligence is largely compliant; Recommendations 12 (politically exposed persons), 13 (correspondent banking), 14 (money or value transfer services), 17 (reliance on third parties) and 20 (suspicious transaction reporting) are compliant.

The effectiveness table is less flattering. Three outcomes reached a substantial level: risk understanding and co-ordination (IO.1), international co-operation (IO.2) and financial intelligence (IO.6), where the FATF describes Türkiye’s FIU, MASAK, as playing a central and effective role. The other eight are moderate. That group includes IO.3 and IO.4, which the FATF presents together as supervision and preventive measures, IO.5 on transparency and beneficial ownership, and the terrorist and proliferation financing outcomes, IO.9 to IO.11.

Set those two tables side by side and the correspondent’s problem becomes concrete. Recommendation 12 on PEPs is rated compliant, while the IO.4 finding says PEP identification and monitoring by financial institutions is only partially effective. Recommendation 20 on suspicious transaction reporting is compliant, while the same finding says shortcomings continue to be identified in suspicious transaction reporting. The law on paper meets the standard; the practice inside reporting entities, as the assessors saw it, does not yet match it. A respondent file that quotes the “38 of 40” count and stops there has recorded the rulebook and skipped the result.

Enhanced follow-up and the lists a screening engine reads

The report’s stated consequence is short: based on the effectiveness and technical compliance ratings, Türkiye is placed in enhanced follow-up and will report back to the FATF on its progress. The published summary does not give the reporting cadence, so the file should not invent one.

Enhanced follow-up is a different mechanism from the FATF’s public lists. Türkiye sat on the increased monitoring list, often called the grey list, from 21 October 2021 until 28 June 2024. The 2026 report’s own summary does not refer to increased monitoring at all.

The distinction matters because the regimes use different country-designation and correspondent-risk mechanisms, and nothing in the provisions cited here attaches a prescribed correspondent measure solely to FATF enhanced-follow-up status:

  • EU: the high-risk third countries identified under Article 9 of Directive (EU) 2015/849 are listed in the Annex to Commission Delegated Regulation (EU) 2016/1675. Türkiye does not appear in the current consolidated Annex of 29 January 2026.
  • UK: the current Money Laundering Regulations 2017 use the term “FATF call for action country”, defined as a country named on the FATF’s list of High-Risk Jurisdictions subject to a Call for Action as that list has effect from time to time. The earlier 2024 formulation that also captured jurisdictions under increased monitoring has been superseded.
  • US: 31 CFR 1010.610(c) reserves its enhanced due diligence procedures for foreign banks operating under an offshore banking licence, a licence from a jurisdiction designated as non-cooperative with international AML principles, or a licence from a jurisdiction the Treasury has designated as warranting special measures. A follow-up category fits none of the three.

That leaves the report in the file as risk evidence under the general correspondent provisions. FinCEN made the point when Türkiye was delisted: for jurisdictions removed from the FATF listing process, US financial institutions should take the FATF’s decisions and the reasons behind the delisting into consideration when assessing risk, consistent with 31 CFR 1010.610(a) and 1010.210. I read the new report the same way. It adds detail to a risk assessment the correspondent already has to perform, and it does not switch on a prescribed measure.

What a compliant rating on Recommendation 13 covers

Recommendation 13 is the FATF standard on correspondent banking, and a technical compliance rating measures whether Türkiye’s legal and regulatory requirements implement it. My reading is that the compliant rating tells a foreign correspondent something specific: Turkish law imposes correspondent banking controls on Turkish institutions when they act as correspondents themselves.

The Recommendation 13 rating is relevant to nested exposure, but it is a country-level technical-compliance conclusion, not a finding about a particular respondent or downstream relationship. IO.4 is likewise a country-level effectiveness outcome for preventive measures; its overall rating should not be treated as a respondent-specific or correspondent-banking-specific control rating.

Two neighbouring ratings belong in the same paragraph of a respondent memo. Recommendation 16 on wire transfers is largely compliant, and Recommendation 19 on higher-risk countries is largely compliant. The published summary does not say which Recommendation 16 criteria fell short. The full report is the place to check before any conclusion about payment message data from Turkish respondents goes into a file.

Recommendation 16 is itself moving. The FATF’s own timetable calls for the Recommendation 16 changes to be fully implemented by the end of 2030, with guidance to help industry prepare expected by the end of 2026. Our note on the FATF travel rule consultation and Recommendation 16 covers what that means for EU payment firms. The 2026 Recommendation 16 rating should not be described as an assessment against the June 2025 revised Recommendation 16 unless the MER expressly confirms that version was assessed. Under the FATF’s Procedures governing this fifth round of mutual evaluations, countries are evaluated on the basis of the FATF Standards and Methodology as they exist on the date the country’s technical-compliance submission is due, and assessors conducting the technical-compliance review take into account only laws, regulations or other measures that are in force and effect at the time of that review, or will be in force and effect by the end of the on-site visit.

Five findings from the FATF Türkiye mutual evaluation to test at the respondent

The EU and UK correspondent provisions expressly require an assessment of the respondent’s AML/CFT controls. The US general rule in 31 CFR 1010.610(a) instead requires a risk assessment using specified relationship, jurisdictional and AML-record factors. Information about a foreign bank’s AML programme forms part of the enhanced scrutiny in paragraph (b) for the foreign banks described in paragraph (c). The Türkiye report can inform all three regimes, but the legal tests are not identical.

PEP identification and monitoring

The FATF finds that financial institutions and VASPs have a thorough knowledge of their obligations but that important deficiencies remain in effective implementation, and it singles out PEP identification and monitoring as only partially effective. For a respondent review, the natural follow-up is how the respondent identifies PEPs and their close associates at onboarding and during the relationship, and what evidence it can show that the monitoring runs. A questionnaire answer that simply confirms a PEP policy exists addresses the Recommendation 12 question, which Türkiye already passes.

Suspicious transaction reporting, and terrorist financing in particular

The report says shortcomings continue to be identified in suspicious transaction reporting, and that low levels of TF-related STRs across several higher-risk sectors suggest constraints in detecting and reporting TF activity relative to risk exposure. Read the scope carefully. The FATF finds that financial institutions and VASPs generally understand their ML risks well, while understanding of TF risks is more limited across sectors outside banking. For a bank respondent, the TF understanding point is framed mainly as a non-bank weakness. For a respondent that is a payment institution, money transfer operator or VASP, it weighs more heavily.

Beneficial ownership accuracy

Under IO.5 the FATF says major improvements are needed to ensure basic and beneficial ownership information is consistently accurate and up to date, particularly through more systematic and risk-based verification, and it notes a concentrated reliance by competent authorities on core registries. On my reading, two consequences follow for a correspondent. When the correspondent verifies the respondent’s own ownership, a Turkish registry extract is only as reliable as the verification the FATF says needs to become more systematic. And when the respondent’s CDD on its corporate customers leans on the same registries, its answer to “how do you verify beneficial owners” deserves a closer look than the Recommendation 24 rating of largely compliant suggests.

Targeted financial sanctions

Türkiye implements terrorism-related targeted financial sanctions without delay “to some extent yet not systematically”, according to the report, and financial institutions and VASPs are complying with those obligations to a certain extent. On proliferation financing, the FATF finds a good overall understanding of risk but a weaker understanding of sanctions evasion through the misuse of legal persons, including foreign ones. Recommendation 7 is one of the two partially compliant ratings. The respondent questions here concern screening latency after a UN designation and how the respondent looks through corporate customers, including foreign-incorporated ones, when screening for proliferation-related designations.

Cross-border and trade-related risk

Under IO.1 the FATF says Türkiye needs to deepen its understanding of cross-border ML and TF risks, including those involving trade and smuggling. The Key Recommended Actions include prioritising money laundering investigations and prosecutions for drug trafficking, smuggling and illegal betting. For a correspondent clearing trade-related payments through a Turkish respondent, these findings point at the monitoring scenarios applied to that flow rather than at the respondent’s onboarding file.

The Financial Stability Board’s page on the FATF’s October 2016 guidance on correspondent banking services states that the FATF Recommendations do not require correspondent institutions to conduct customer due diligence on each individual customer of their respondents’ customers. The five test points are questions about the respondent’s systems and outcomes, which is what the “assess the respondent’s AML/CFT controls” limb already covers. If your file runs on the Wolfsberg Group’s Correspondent Banking Due Diligence Questionnaire (version 1.4, 2023), the practical step is to re-read the respondent’s existing answers on these five topics against the report, and to request evidence where an answer is a bare yes.

Where the EU text puts the Türkiye report

Until 10 July 2027, EU correspondents apply national law transposing Article 19 of Directive (EU) 2015/849. For cross-border correspondent relationships involving the execution of payments with a third-country respondent, it requires, in addition to standard CDD: gathering sufficient information to understand the respondent’s business and to determine from publicly available information its reputation and the quality of supervision; assessing the respondent’s AML/CFT controls; senior management approval before a new relationship; documenting each institution’s responsibilities; and, for payable-through accounts, being satisfied about the respondent’s CDD on customers with direct access. Article 24 prohibits correspondent relationships with shell banks.

Once the AMLR applies, its Article 36 carries the same five elements directly, with the scope stated to include relationships established for securities transactions or fund transfers, and it adds that a decision to terminate a cross-border correspondent relationship for reasons relating to AML/CFT policy must be documented. Our guide to the EU AML package and the 10 July 2027 switch sets out how the Regulation and national law will sit side by side.

The phrase “quality of supervision” from “publicly available information” is where a mutual evaluation enters the file. The Directive’s Annexes II and III already name mutual evaluations as a source for geographical risk, and the AMLR annexes repeat the pair. AMLR Annex III lists as a geographical higher-risk factor third countries identified by credible sources, such as mutual evaluations, detailed assessment reports or published follow-up reports, as not having effective AML/CFT systems. Annex II lists as a lower-risk factor third countries that, on the basis of the same kind of sources, have requirements consistent with the FATF Recommendations and effectively implement them.

The Türkiye report fits neither description cleanly. Its requirements are largely in line with the Recommendations; its effectiveness ratings are mostly moderate. That is my interpretation of how the annexes read against these ratings, and it is the reason I would not use the report to support a lower-risk country score for Türkiye. The Directive already warns against the opposite shortcut: recital 29 says countries not included in the high-risk list should not be automatically considered to have effective AML/CFT systems, and that natural persons or legal entities established in such countries should be assessed on a risk-sensitive basis. The AMLR’s recital 80 adds that the intensity of enhanced due diligence for correspondent relationships should be set by applying the risk-based approach.

Article 38 of the AMLR works at the level of a named institution. AMLA issues a recommendation on a specific third-country respondent institution where a financial supervisor considers that the institution is in serious, repeated or systematic breach of AML/CFT requirements, or has controls likely to lead to such breaches or not commensurate with its risks, in a way that may affect the risk exposure of the correspondent relationship, and Union financial supervisors agree. Only then do the Article 38(6) measures apply: abstaining from new relationships and, for existing ones, reviewing the respondent information and terminating the relationship, in each case unless the institution concludes that the mitigating measures can adequately mitigate the ML/TF risks, and informing the respondent of the conclusions. The trigger is supervisory information about the named institution.

One more EU input is due by the same date. Article 32 of the AMLR requires AMLA to issue, by 10 July 2027, guidelines defining ML/TF risks, trends and methods involving geographical areas outside the Union, taking into account evaluations by international standard setters. Once issued, those guidelines become one of the higher-risk inputs Article 34(3) requires obliged entities to take into account.

UK and US files: same evidence, different wording

Regulation 34(1) of the UK Money Laundering Regulations 2017 follows the same pattern for correspondent relationships with respondents from third countries: understand the respondent’s business, assess its controls, obtain senior management approval, document responsibilities, and deal with customers who have direct access to accounts. Regulation 34(2) prohibits correspondent relationships with shell banks. The UK wording has one addition worth using: the reputation and quality-of-supervision determination is made from publicly-available information “from credible sources”. A FATF mutual evaluation is the obvious credible source for supervision quality, and citing it by name and date answers that wording directly.

The US regulation is more granular about jurisdictions. Under 31 CFR 1010.610(a)(2), the risk assessment of a foreign correspondent account considers, among other factors, the AML and supervisory regime of the jurisdiction that issued the foreign institution’s charter or licence and, to the extent information on it is reasonably available, of the jurisdiction in which any company that owns the foreign institution is incorporated or chartered. That owner limb is easy to miss. The Türkiye report feeds it when the respondent is licensed elsewhere but owned by a Turkish company, as well as when the respondent is a Turkish-licensed bank.

Prudential supervision is a separate evidence stream. The Banking Regulation and Supervision Agency (BRSA) is Türkiye’s banking regulator, and RCAP assessments such as the Basel Committee’s April 2025 review of Türkiye’s large exposures rules are scoped to rule consistency, not supervisory effectiveness. So a Basel consistency assessment cannot stand in for the FATF report on the quality of AML/CFT supervision. For Canadian correspondents, our FINTRAC correspondent banking guide sets out that regime’s own requirements.

Recording the outcome: refresh, restrict or exit

The report changes the evidence a decision rests on; the decision itself stays with the correspondent’s own methodology. A workable sequence for an existing Turkish respondent looks like this:

  1. Update the country-risk memo for Türkiye: cite the report by title and publication date, the on-site date, the technical compliance distribution, the effectiveness ratings and the enhanced follow-up status.
  2. Map the five test points above against the respondent’s latest questionnaire answers and supporting evidence, and record which answers the report now calls into question.
  3. Decide whether the country score or the respondent’s rating moves, under your own methodology, and record the reasoning in terms of the report’s findings.
  4. Where the outcome is an exit for AML/CFT reasons, document it. Under the AMLR that documentation becomes an explicit Article 36 requirement for cross-border correspondent relationships.
  5. Set a watch on new FATF publications on Türkiye. Under enhanced follow-up, Türkiye reports back on its progress, and those reports are the next public evidence on the same points.

Exit decisions attract scrutiny of their own. The CSSF’s position, covered in our note on the CSSF de-risking communiqué, is one published example of a supervisor distinguishing effective ML/TF risk management from unwarranted de-risking and from commercial exit decisions. For a Türkiye file, the useful discipline is to tie any restriction to a named finding in the report, such as TF-related reporting in non-bank sectors or sanctions screening latency, and to the respondent’s own answers on that point.

Frequently Asked Questions

A Turkish banking group has an EU-authorised subsidiary. Does Article 19 of the Directive, or Article 36 of the AMLR, apply to our relationship with that subsidiary?

Both provisions are framed around a third-country respondent institution. An institution authorised and established in the Union falls outside that wording, which takes the relationship out of the specific cross-border correspondent measures by their terms. That is a reading of the scope wording; group ownership and flows routed from the Turkish parent remain risk factors in the ordinary CDD and risk assessment.

We are the respondent: we hold a nostro account with a Turkish bank. Does the report change our obligations?

The cited EU and UK correspondent measures bind correspondents that fall within those regimes; they do not impose duties on a Turkish bank merely because it provides the correspondent service. In that set-up the Turkish bank is the correspondent and you are the respondent, but this article does not establish the Turkish bank’s obligations under Turkish law. The report may still be relevant to your own risk assessment where Turkish exposure is material, including customer flows routed through that account.

Can we cite the report as our only evidence on the quality of supervision?

It is a detailed public source on AML/CFT supervision in Türkiye, but the EU and UK texts also require a view on the respondent’s own reputation, which a country report does not address. The report is also dated to its November 2025 on-site visit, so later developments need their own sources.

We are a crypto-asset service provider with a counterparty exchange in Türkiye. Which provision applies?

For an EU crypto-asset service provider, Article 19b of Directive (EU) 2015/849, inserted by Regulation (EU) 2023/1113 and applicable through national law from 30 December 2024, applies by way of derogation from Article 19; it first requires the correspondent to determine whether the respondent entity is licensed or registered. From 10 July 2027 Article 37 of the AMLR carries those measures directly. In the UK, SI 2026/621 inserts a separate regulation 34A for specified third-country crypto correspondent relationships, but that provision does not come into force until 1 February 2027. The applicable provision therefore depends on the correspondent’s jurisdiction and date.

Does the proliferation financing finding belong in the AML file or the sanctions file?

Both, in practice. The finding concerns sanctions evasion through the misuse of legal persons, including foreign ones, which is a sanctions screening and ownership question. It also sits in the FATF’s effectiveness findings, the same source the AML/CFT country memo relies on. Recording it once, with a cross-reference, avoids two teams scoring the same finding differently.

What happens to the file if Türkiye’s ratings change during follow-up?

The FATF has published follow-up reports on Türkiye before, in November 2021, May 2022 and July 2023. Under enhanced follow-up Türkiye will report back again, and a later FATF publication can change the evidence the file relies on. The country memo should name the report it relies on so that a later publication triggers a visible update.

Key Takeaways

  • Replace pre-September 2026 FATF citations in the Türkiye country memo before the next periodic review of any Turkish respondent.
  • Keep technical compliance and effectiveness as separate inputs in the country model, so a strong Recommendation count cannot offset moderate outcomes.
  • Apply the TF-understanding finding first to Turkish payment institutions, money transfer operators and VASPs, where the FATF locates it.
  • Where a respondent’s PEP or STR answers carry no supporting evidence, request it; the report marks both as implementation gaps.
  • For respondents licensed outside Türkiye, 31 CFR 1010.610(a)(2)(iv) makes the AML and supervisory regime of an owner company’s jurisdiction relevant to the extent information on that jurisdiction is reasonably available; the Türkiye report is relevant under that factor where an owner company is incorporated or chartered in Türkiye.
  • RCAP assessments such as the Basel Committee’s review of Türkiye’s large exposures rules are scoped to rule consistency, not supervisory effectiveness, and cannot support a quality-of-supervision conclusion.
  • Re-check the EU Annex and the FATF lists whenever either is updated; enhanced follow-up on its own changes neither.

Sources and References

The next entry in a Turkish respondent file

The artifact to produce now is a dated Türkiye country-risk update built on the new report, with its November 2025 assessment date recorded and the five effectiveness findings mapped against each Turkish respondent’s latest answers. The next fixed EU date is 10 July 2027, when Article 36 of the AMLR and its documentation duty apply directly; the next FATF input is Türkiye’s own progress report under enhanced follow-up, and the file should reopen when it is published.

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts

  • Regulation 2026/1779: Screening the New EU Sanctions Listings

    On 17 July 2026 the Council of the European Union adopted Council Implementing Regulation (EU) 2026/1779, which amends Annex I to Regulation (EU) No 269/2014 and adds six new designations to the EU list of persons and entities subject to an asset freeze over the situation in Ukraine. The measure entered into force on the…

  • UK Payments Initiative: What the New Open Banking Scheme Means for UK PSPs

    Updated July 2026In this guideWhat the UK Payments Initiative actually isThe legal basis, and the Brexit trap that catches EU-trained teamsCommercial variable recurring payments: what cVRP changesThe pricing model and the position the regulators have parkedWho has to do whatThe Future Entity: the governance handover most teams have not noticedTimeline and what to prepare nowCommon…

  • The FCA’s June 2026 Financial Crime Speech: What It Means for AML Reporting in UK-Regulated Firms

    Updated July 2026In this guideWhat the FCA actually said, and why a reporting team should careThe legal spine: where the FCA’s financial crime mandate comes fromThe reporting layer the speech sits on: REP-CRIM and SUP 16.23Suspicious activity reports: the obligation that does not run to the FCAThe Money Laundering Regulations 2017 and the risk-based approachThe…

  • AML Reporting in Luxembourg: STRs, GoAML, and Your Obligations

    Updated July 2026In this guideIntroductionThe Legal Basis for AML Reporting in LuxembourgWho Must Report? Obliged Entities and ScopeSuspicious Transaction Reports: What Triggers Reporting?Filing Suspicious Transaction Reports: The ProcessOther AML Reporting Obligations Beyond STRsThe CRF: Luxembourg’s Financial Intelligence UnitHow AML Reporting Works in PracticeCommon AML Reporting MistakesRecent Developments: AMLA, the AMLR, and the Single RulebookComing Soon:…

  • ECB Legal Framework Volume III: The SSM Internal Rulebook, Mapped

    In August 2026 the European Central Bank issued a new edition of Volume III of its Legal Framework for Banking Supervision, the digital compilation that gathers the internal-organisation rules of the Single Supervisory Mechanism. Volume III is the part supervised banks meet when they interact with the ECB itself: it holds the rules of procedure…

  • CRD6 Third-Country Branch Authorisation: The 11 January 2027 Deadline

    Updated September 2026In this guideThe dates that drive the branch-authorisation projectWhat the CRD6 third-country branch regime actually changesWhat the EBA Guidelines put in the third-country branch authorisation fileClass 1 or class 2: the classification that sets your obligationsCapital endowment and liquidity: the numbers to evidenceBooking arrangements and the registry bookTerritorial scope, reverse solicitation, and the…