Skip to content
Anlık Bakiyem
Back to blog

August 12, 2026

What Is Open Banking? How It Works in Turkey and What It Offers Companies

Open banking is a banking model that allows a customer's account information and payment services to be shared with authorized third parties through secure APIs (application programming interfaces), based on the customer's explicit consent. In other words, your company can view balances and transactions across different banks through a single application it has authorized itself, without logging into each online banking portal separately. In Turkey, this model comes to life both through the BDDK's electronic banking regulations and through the web services banks offer their corporate customers. In this article we answer the question of what open banking is, and walk step by step through the legal framework in Turkey, how bank API integration works in practice, the concrete benefits for companies, and how security is maintained.

What Is Open Banking and Where Did It Come From?

In its simplest definition, open banking means banks opening up the customer data they hold and certain banking functions to external applications through standardized interfaces, provided the customer has given consent. The model is built on two core services: account information services (reading balances and account transactions) and payment initiation services (issuing a payment order on the customer's behalf).

Globally, the concept took off with the European Union's PSD2 (the second Payment Services Directive), which came into force in 2018 and obliged banks to open account access to third-party providers holding the customer's consent. Similar approaches followed with the Open Banking standard in the United Kingdom and with local regulations in many other countries. Turkey is among the countries that adapted this wave into its own legislation.

How Does Open Banking Work in Turkey?

The legal foundation of open banking in Turkey rests on two main pillars. The first is the 2019 amendment to Law No. 6493, which defined "payment initiation" and "account information" as regulated payment services and placed the field under the oversight of the Central Bank of the Republic of Türkiye (TCMB). The second is the Regulation on Banks' Information Systems and Electronic Banking Services published in 2020 by the BDDK (Turkey's Banking Regulation and Supervision Agency), which defines "open banking services" as an electronic banking channel.

Within this framework, the central bank set the technical API standards for account information and payment initiation services; the standardized infrastructure runs through GEÇİT, operated by the Interbank Card Center (BKM).

Alongside this, there is a route Turkish corporates have long relied on: web services that banks open to corporate customers under contract. The company signs a service definition form with its bank, and the bank grants company-specific access to operations such as transaction history and balance inquiries. Major banks such as Ziraat, İşbank, Garanti BBVA and Akbank, as well as participation banks, offer this kind of service. In practice, bank API integration usually means using these two channels — regulated open banking APIs and bank-specific web services — together.

What Does Open Banking Offer Companies?

For companies, the most tangible payoff of open banking is time and visibility. A finance team working with multiple banks can monitor every account on a single screen, live, instead of logging into each online banking portal every morning to check balances. In multi-company, multi-currency structures, that means a consolidated cash position that is always current.

The second major benefit is reconciliation. When account transactions flow in automatically, comparing bank records with accounting records no longer depends on a manual cycle of downloading and uploading statements; team members can attach notes to transactions and run the reconciliation together.

The third is accounting and ERP integration. Because bank data arrives via API, transferring it to ERP systems such as Odoo or comparing it with accounting software records becomes automatic. Cash flow reporting rests on current data from the bank, not on manual data entry.

How Is Security Ensured in Open Banking?

In open banking, security sits at the center of the design and is built in layers. The first principle is read-only access: an account information service only reads balances and transactions; it carries no authority to move money. In most open banking scenarios for companies, this read permission is all that is needed, which narrows the risk surface from the start.

The second layer is IP authorization: banks allow access to their web services only from the static IP addresses the company has registered; requests coming from anywhere else are rejected on the bank's side.

The third layer is protecting credentials. Service usernames and passwords must be stored encrypted and never kept anywhere in plain text. On top of this comes the corporate layer: role-based access control (RBAC) so each employee sees only the accounts they are authorized for, two-factor authentication (2FA), and audit logging of every operation. In Turkish open banking practice, BDDK and central bank regulations also set minimum standards for authentication and data security.

Open banking moves a company's access to bank data from individual effort to corporate infrastructure. AnlıkBakiyem delivers that infrastructure as ready-made connections to 30 banks in Turkey: it shows the live balance of all your accounts on one screen, keeps up to 365 days of encrypted transaction history, and lightens your finance team's routine with an annotated reconciliation mode and Odoo transfer — all with read-only access, IP authorization, and encrypted credential storage. Visit anlikbakiyem.com to see what open banking can do for your company and start connecting your accounts today.

Calculate pricing