By NHI Mgmt Group Editorial TeamBased on SumSub: “Compliance Digest—June 2026” (July 1, 2026)

TL;DR: Turkey’s updated MASAK communiqué allows remote identity verification for foreign nationals using NFC-enabled passports, video checks, address verification and enhanced monitoring, while also bringing crypto-asset service providers into scope for certain remote onboarding provisions, according to SumSub’s June compliance digest. The change widens digital onboarding access, but it also hardens the identity assurance burden on institutions that must govern high-risk remote relationships.


At a glance

What this is: Turkey has expanded remote customer identification for foreign nationals, allowing NFC passport-based verification with video checks, address verification, technical risk controls and enhanced monitoring.

Why it matters: IAM and compliance teams need to treat remote onboarding as a governed identity workflow, because digital convenience now comes with higher assurance, monitoring and lifecycle obligations.


Context

Remote identity verification is the process of establishing who a person is without requiring physical presence, usually by combining document validation, live checks and risk controls. In this case, Turkey’s updated MASAK framework extends that model to foreign nationals while tightening the controls around it.

For IAM, IGA and compliance teams, the important change is not remote onboarding itself but the governance load that follows it. When the onboarding path is high risk by default, identity assurance, evidence quality and ongoing monitoring become part of the access model, not just the compliance wrapper.

The article also broadens the operational picture by bringing crypto-asset service providers into scope for certain remote identification provisions. That makes the change relevant beyond traditional banking and into digital asset onboarding flows where remote identity assurance already tends to be fragile.


Key questions

Q: What should teams do first when remote identity verification for foreign nationals is allowed?

A: Start by mapping the onboarding path to explicit proofing gates. Require NFC passport validation, trained video review, address confirmation and technical risk checks before the relationship is activated, then document who approves exceptions. The first control is evidence quality, because downstream monitoring cannot rescue weak initial identity assurance.

Q: Why do remote onboarding journeys create more compliance risk than in-person checks?

A: Remote onboarding reduces the opportunity to observe the applicant directly, so teams must rely more heavily on documents, device signals, and procedural controls. That increases the risk of weak identity proofing, incomplete due diligence, and inconsistent decisions if the workflow is not tightly governed. The practical challenge is proving who was verified and why the decision was reasonable.

Q: What breaks when remote identity proofing is treated as a one-time check?

A: The identity lifecycle breaks. A remote customer can pass initial verification yet still require ongoing monitoring, periodic review and escalation based on later signals. If the programme stops at onboarding, the institution creates a gap between acceptance and oversight, which is where misuse and weak identity records become hardest to detect.

Q: How should organisations govern remote onboarding when regulators allow digital identity verification?

A: Organisations should treat remote onboarding as an evidence and lifecycle control, not just a front-end convenience. That means using documented proofing steps, preserving audit artefacts, assigning clear ownership, and linking the onboarding risk rating to ongoing monitoring. Without that chain, the institution cannot show how trust was established or maintained.


Technical breakdown

NFC passport verification as an identity proofing control

NFC-enabled passports allow systems to read the chip data embedded in an ICAO 9303-compliant document and compare it with the visible document and the live presenter. That reduces some document spoofing risk, but it does not by itself establish that the person controlling the session is the legitimate holder. The control only works when it is tied to trained review, reliable device capture and exception handling for document anomalies. In identity terms, this is proofing, not authentication, and the distinction matters because onboarding confidence still has to be carried forward into downstream access decisions.

Practical implication: Treat NFC passport checks as one evidence source in a broader identity proofing workflow, not as a complete trust decision.

Why video verification and technical telemetry belong in the same onboarding chain

Video verification checks liveness and consistency between the person, document and stated identity, while technical telemetry such as device and IP data adds contextual risk signals. Neither is enough alone. Together they create a richer signal set for remote onboarding, especially when the regulation automatically treats the resulting relationship as high risk. That combination is useful because remote identity failures often hide in context, not just in documents. A valid passport does not remove the need to understand whether the session origin, device posture or behavioural pattern looks inconsistent with the claimed customer.

Practical implication: Correlate video evidence with device and network signals so onboarding risk is evaluated as a single decision, not separate checks.

High-risk classification changes the lifecycle burden after onboarding

Once a remote onboarding route automatically places the customer into a high-risk category, the programme has to assume ongoing scrutiny from day one. That means customer due diligence, review cycles and monitoring thresholds must be configured for escalation rather than normalisation. The governance issue is that remote identity verification is not a one-time event. It creates a relationship that needs sustained review because the initial identity evidence, while acceptable under the rule, is still weaker than in-person assurance. For institutions, the real challenge is aligning identity proofing, AML policy and operational review cadence into one governed lifecycle.

Practical implication: Build the high-risk classification into customer review and monitoring logic at onboarding time, not after the account is live.


Threat narrative

Attacker objective: The attacker or fraudulent applicant seeks to obtain a remotely opened, apparently legitimate financial or crypto relationship under an identity that is difficult to challenge later.

  1. Entry occurs through remote onboarding channels where a foreign national presents an NFC-enabled passport and completes video-based verification.
  2. Credential or identity evidence is then validated through document chip data, address checks and technical telemetry, but weak presentation or synthetic identity cues can still pass if review quality is poor.
  3. Escalation follows when a low-assurance remote identity is accepted into a high-risk relationship without enough ongoing monitoring to detect misuse.
  4. Impact is the creation of regulated customer accounts or business relationships that are harder to unwind, investigate or defend if the original identity evidence was weak.

Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

Remote onboarding now turns identity assurance into a lifecycle problem, not a front-door check. Once a foreign national can be admitted remotely, the security question shifts from whether the document looked valid to whether the institution can sustain confidence after the account is opened. That is a governance change for IAM, IGA and AML teams alike. Practitioners should treat the onboarding decision as the start of a monitored identity relationship.

High-risk-by-default onboarding changes the economics of assurance. When the regulation classifies the relationship as high risk, the cost of weak evidence moves downstream into alerts, reviews and remediation. That means institutions need stronger evidence capture, tighter exception handling and clearer review ownership. The practical conclusion is that remote onboarding design now belongs in identity governance, not only in compliance operations.

Identity proofing and transaction monitoring can no longer be managed as separate controls. A remote customer accepted on the basis of a passport, video and device telemetry still needs monitoring that understands why that identity was accepted in the first place. This is where a named concept matters: remote identity assurance debt accumulates when onboarding confidence is not carried forward into later review logic. Practitioners should align proofing evidence with downstream risk scoring.

Crypto onboarding broadens the governance surface without changing the core identity problem. Bringing crypto-asset service providers into scope does not create a new verification model, but it does extend the same remote identity challenge into a sector that often moves faster than its governance. The implication is straightforward: firms should not treat digital asset onboarding as an exception to identity governance discipline.

MASAK’s framework validates remote access to regulated relationships, but it also codifies the need for stronger internal controls. That reinforces a broader market direction in which digital onboarding is acceptable only when evidence, review cadence and ownership are explicit. The practitioner takeaway is that remote identity workflows now need the same lifecycle discipline as privileged access.

What this signals

Remote identity assurance debt: When institutions accept a remote customer on the basis of documents and live checks, they are borrowing trust from the onboarding moment. If that trust is not carried into later review and escalation logic, the programme accumulates risk that surfaces only after the relationship is already live.

A controlled remote onboarding model should be judged by whether the evidence captured at entry is still usable months later in a dispute, review or investigation. That is the practical test for whether identity governance is integrated or merely procedural.


For practitioners

  • Update remote onboarding decision trees Map foreign-national onboarding to explicit approval paths that require NFC passport validation, trained human video review, address verification and technical risk checks before account activation.
  • Classify remote foreign-national relationships as high risk by default Ensure the customer risk model marks this onboarding route as high risk at acceptance so enhanced monitoring, escalation thresholds and review frequency are configured from the outset.
  • Align identity proofing evidence with AML review logic Store the passport, video, address and device evidence in a way that downstream analysts can see why the customer was accepted and which signals triggered the decision.
  • Review crypto onboarding against the new MASAK scope Check whether crypto-asset service provider onboarding follows the same remote identity controls and whether internal procedures, notifications and risk controls were updated within the required timetable.

Key takeaways

  • Turkey’s updated framework makes remote foreign-national onboarding possible, but only inside a heavier identity assurance model.
  • The control burden shifts from a single verification event to ongoing evidence, risk scoring and review.
  • Institutions should align onboarding proofing, monitoring and AML governance before adopting the remote path at scale.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 and NIST CSF 2.0 set the technical controls, and GDPR defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04 — Insecure AuthenticationRemote onboarding depends on stronger identity proofing than document presence alone.
NHI-05 — Overprivileged NHIHigh-risk customers can receive access or service scope that exceeds what the evidence supports.
Recommendation — Strengthen remote proofing so NFC passport checks and video review are required before activation. Limit initial entitlements until remote identity evidence is validated and reviewed.
NIST SP 800-53 Rev 5IA-8 — Identification and Authentication (Non-Organizational Users)Remote foreign nationals are external users whose identity assurance must be controlled.
Recommendation — Apply IA-8 to validate external-user identity before granting account access.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsRemote onboarding decisions affect what access is authorized after proofing completes.
Recommendation — Align authorizations with the assurance level established during remote onboarding.
GDPRArt.32 — Security of ProcessingRemote identity verification processes still require appropriate security safeguards for personal data.
Recommendation — Protect onboarding evidence with security controls proportionate to the sensitivity of identity data.

Key terms

  • Remote Identity Proofing: Remote identity proofing is the process of verifying that a person is who they claim to be without meeting in person. It combines document checks, biometric comparison, device and signal analysis, and fraud screening to establish confidence in identity remotely. It is used before account creation, recovery, or high-risk access.
  • High-Risk Customer: A high-risk customer is a person or entity that presents a greater chance of involvement in money laundering, fraud, sanctions exposure, or other illicit activity. Risk can arise from geography, industry, ownership structure, political exposure, transaction behaviour, licensing gaps, or adverse regulatory history.
  • Identity Assurance: The confidence an organisation has that a person or system is truly who it claims to be before access or action is granted. In modern IAM, assurance depends on evidence quality, channel trust, and the strength of verification around high-risk decisions.
  • Continuous Monitoring: Continuous Monitoring is the ongoing evaluation of access, activity, and control state rather than a periodic snapshot. In practice, it helps teams spot privilege drift, conflicting transactions, and configuration changes before they become audit findings or operational losses.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 1, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org