No description available.
All Firms
No description available.
The CSSF is formally drawing attention to the CNC Q&A 26/038, which provides detailed interpretative guidance on the **new accounting regime introduced by the Law of 7 August 2023** for large not‑for‑profit associations, public‑utility associations and foundations. This matters for compliance teams because these entities are now aligned with the accounting regime for “medium‑sized undertakings” under Luxembourg company law, with specific obligations on annual accounts formats, filing, and chart‑of‑accounts choices that require governance, process and system changes.
What Changed
- - Large associations, associations recognised as being of public utility and foundations are now subject to the accounting regime applicable to “medium‑sized undertakings” under the amended...
- Annual accounts for affected entities must include a non‑abridged balance sheet, a profit and loss account (at least in abridged format), and notes to the accounts containing disclosures required by...
- Affected entities must use statutory LRCS layouts for the balance sheet and profit and loss account and file their annual accounts in classic format with the Luxembourg Trade and Companies Register...
- Large associations, public‑utility associations and foundations remain exempt from the mandatory use of the Standard Chart of Accounts (Plan Comptable Normalisé – PCN) and from eCDF standard data...
- Affected entities may voluntarily adopt the PCN; if they do not adopt PCN, they must maintain an internal chart of accounts and ensure robust, documented mapping between internal accounts and...
Suggested Considerations
- Identify all Luxembourg associations, public‑utility associations and foundations within or related to the group that are impacted by the Law of 7 August 2023 and confirm their size classification (small, medium‑sized, large) and whether they fall under the “medium‑sized undertakings” regime.
- Review existing accounting policies, charts of accounts and annual accounts formats for affected entities to ensure alignment with LRCS statutory layouts, including non‑abridged balance sheet, appropriate profit and loss format, and required notes disclosures.
- Decide at governing‑body level whether each affected entity will voluntarily adopt the PCN or maintain an internal chart of accounts, documenting the rationale, governance approvals and compliance impacts of the chosen option.
- Where PCN is not adopted, design, implement and document a robust mapping from the internal chart of accounts to the statutory LRCS balance sheet and profit and loss layouts, ensuring audit‑ready documentation and traceability.
- Update accounting systems and reporting tools for affected entities to support LRCS statutory layouts, consistent layout adaptations, and classic‑format filing with the RCS, including necessary changes to interfaces and data capture.
Key Dates
- Law of 7 August 2023 introducing the new accounting regime for associations and foundations enters into force and defines classification as “small associations”, “medium‑sized associations” and “large associations” with corresponding accounting obligations
- CNC plans to publish an accounting guide dedicated to the new accounting regime for ASBLs classified as small, medium‑sized and large associations, and associations recognised as being of public utility
- CSSF press release is published, formally drawing supervisory attention to CNC Q&A 26/038 and the related upcoming CNC accounting guide
Compliance Impact
Non‑compliance may result in defective or non‑compliant annual accounts filings, potential rejection or queries from the RCS, and heightened supervisory scrutiny by the CSSF where the entities are linked to regulated groups, with knock‑on effects on group reporting and reputational risk. For larger public‑interest or group‑related entities, persistent non‑compliance could trigger audit qualifications and regulatory concerns about governance and internal control over financial reporting.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankInsuranceAsset Manager No description available.
The CSSF is formally drawing attention to CNC Q&A 26/038, which provides detailed interpretative guidance on the **new accounting regime introduced by the Law of 7 August 2023** for large not‑for‑profit associations, public‑utility associations and foundations. This matters for compliance teams because these entities are now subject to annual accounts obligations aligned with the regime for “medium‑sized undertakings” under the Luxembourg commercial companies law, with specific rules on formats, exemptions from PCN/eCDF, and forthcoming detailed guidance for all association size categories.
What Changed
- - Large not‑for‑profit associations, associations recognised as being of public utility and foundations are required to prepare annual accounting documents consisting at a minimum of annual accounts...
- These entities fall within the regime applicable to “medium‑sized undertakings”, which drives the required content and level of detail of their annual accounts (balance sheet, profit and loss account...
- The law and the CNC Q&A confirm that large associations, public‑utility associations and foundations are not legally required to use the Standard chart of accounts (Plan comptable normalisé, PCN) or...
- Although exempt from mandatory PCN use and eCDF standard data collection, these entities must still file their annual accounts with the Luxembourg Trade and Companies Register (RCS) using statutory...
- Large associations, public‑utility associations and foundations are exempt from the obligation to file the PCN trial balance (balance générale) via the eCDF platform, even though they may still...
Suggested Considerations
- Identify whether the organisation qualifies as a large association, an association recognised as being of public utility or a foundation under the Law of 7 August 2023, and document the classification decision with reference to Articles 18, 36 and 52 of that law.
- Update internal accounting policies to require annual accounts to be prepared in accordance with the regime for undertakings referred to in Article 47 LRCS, including minimum content (balance sheet, profit and loss account and notes) and disclosure requirements.
- Decide formally whether to adopt the PCN on a voluntary basis or to maintain an internal chart of accounts, and record this decision in accounting governance documents approved by the board or governing body.
- Where PCN is not adopted, design and implement a detailed and documented mapping from internal general ledger accounts to LRCS statutory balance sheet and profit and loss layouts to ensure accurate preparation and filing of annual accounts.
- Review and, where necessary, redesign annual accounts templates to comply with LRCS layouts while making only permitted adaptations (for example, titles and subtotals) that maintain clarity, comparability and consistency over time.
Key Dates
- Earliest financial year start date from which adjusted size criteria under Articles 35 and 47 LRCS may be applied to undertakings and groups, which indirectly affects categorisation and accounting obligations of entities subject to commercial‑law size criteria
- Law of 7 August 2023 introducing the new accounting regime for associations and foundations is adopted, setting the legal basis for reclassification and annual accounts obligations
- Default application date of the adjusted LRCS size criteria for undertakings and groups where early application from 01 January 2023 is not chosen
- New LRCS size thresholds start to determine the categorisation of pre‑existing Luxembourg undertakings and, by analogy, influence assessments of “medium‑sized” status relevant to associations
- CNC plans to publish an accounting guide dedicated to the new accounting regime for not‑for‑profit associations (ASBLs) classified as small, medium‑sized and large, as well as public‑utility associations and foundations
Compliance Impact
Non‑compliance primarily exposes large associations, public‑utility associations and foundations to deficiencies in statutory annual accounts and registry filings, which can lead to legal and governance risks, increased audit findings and potential supervisory concerns where the CSSF has a stake. For CSSF‑regulated firms, reliance on non‑compliant counterparties may undermine financial reporting integrity and due‑diligence standards, with knock‑on effects in broader regulatory reviews.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankAsset ManagerAll Firms
No description available.
Bank
Version 3.3
Asset ManagerBank
on the fight against money laundering and terrorist financing
All Firms
No description available.
All Firms
amending Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
All Firms
amending Regulation (EU) No 833/2014 concerning restrictive measures in view of Russia’s actions destabilising the situation in Ukraine
All Firms
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
All Firms
amending Regulation (EC) No 765/2006 concerning restrictive measures in view of the situation in Belarus and the involvement of Belarus in the Russian aggression against Ukraine
All Firms
implementing Article 8a(1) of Regulation (EC) No 765/2006 concerning restrictive measures in view of the situation in Belarus and the involvement of Belarus in the Russian aggression against Ukraine
All Firms
No description available.
All Firms
No description available.
ESMA has withdrawn its MiFID II/MiFIR market data Guidelines because their subject matter has been transposed into Commission Delegated Regulation (EU) 2025/1156 on the obligation to make market data available on a reasonable commercial basis. As a result, CSSF Circular 21/783, which implemented those ESMA Guidelines in Luxembourg supervisory practice, will become formally outdated from 23 August 2026, requiring MiFID firms and trading venues to ensure their policies and commercial terms now fully align with the directly applicable RTS in the Delegated Regulation.
What Changed
- - CSSF Circular 21/783, which applied ESMA’s Guidelines on MiFID II/MiFIR obligations on market data in Luxembourg, will cease to be applicable as of 23 August 2026 and is formally classified as...
- The supervisory reference framework for market data obligations in Luxembourg shifts from ESMA soft-law Guidelines to binding regulatory technical standards contained in Commission Delegated...
- Requirements on making market data available to the public on a “reasonable commercial basis” are now set out in directly applicable EU law, including detailed RTS criteria on cost-based pricing,...
- ESMA’s interpretative role via Guidelines is replaced by binding RTS, which reduces reliance on national circulars and increases harmonisation of market data rules across EU trading venues and data...
- Luxembourg firms can no longer rely on Circular 21/783 as the primary interpretative document for market data obligations; instead, their compliance frameworks must directly reference Delegated...
Suggested Considerations
- Identify and catalogue all internal policies, procedures, contractual templates, and pricing frameworks that reference CSSF Circular 21/783 or ESMA’s MiFID II/MiFIR market data Guidelines.
- Review Commission Delegated Regulation (EU) 2025/1156 in detail and map its RTS requirements (e.g. cost-based pricing, non-discriminatory access, data unbundling, publication formats) against current market data practices.
- Update market data pricing policies to ensure that fees are demonstrably based on reasonable commercial basis criteria defined in Delegated Regulation (EU) 2025/1156, including documentation of cost allocation and margin methodology.
- Revise market data access policies and client terms to ensure non‑discriminatory conditions and appropriate unbundling of pre‑trade and post‑trade data, in line with the RTS.
- Amend compliance manuals, MiFID/MiFIR control frameworks, and training materials to remove references to CSSF Circular 21/783 and ESMA Guidelines, replacing them with references to Delegated Regulation (EU) 2025/1156.
Key Dates
- Commission Delegated Regulation (EU) 2025/1156 is adopted, supplementing MiFIR with RTS on the obligation to make market data available to the public on a reasonable commercial basis
- ESMA Guidelines on MiFID II/MiFIR market data obligations are withdrawn; CSSF Circular 21/783, which incorporated these Guidelines into CSSF administrative practice, becomes outdated from this date
Compliance Impact
Non-compliance will now be assessed directly against binding RTS under Delegated Regulation (EU) 2025/1156, increasing enforcement risk if market data is priced or provided on terms that are not objectively “reasonable” or non‑discriminatory. Firms that fail to adapt their frameworks by 23 August 2026 risk supervisory findings, potential sanctions, and challenges to their market data commercial models.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Broker DealerBankAsset Manager
No description available.
All Firms
Clarifications regarding certain aspects of Regulation (EU) 2019/2088 on sustainability-related disclosures in the financial sector (SFDR)Version 5
The CSSF’s FAQ clarifies several SFDR disclosure points for Luxembourg fund managers and related entities, especially around Article 8/9 investment strategies, sustainable-investment methodology, and periodic reporting. It also signals supervisory expectations that disclosure changes can be “material” under CSSF circular rules and therefore may trigger formal review and authorisation requirements.
What Changed
- - Article 8 funds must describe how the investment strategy actually enables the fund to meet the environmental and/or social characteristics disclosed to investors.
- If an Article 8 fund relies mainly on an exclusion strategy, the CSSF expects the exclusion policy to be detailed enough for investors to understand how the stated characteristics are being met.
- Article 9 funds cannot rely only on an exclusion strategy; they must invest in sustainable investments and use a positive selection process that demonstrates alignment with Article 2(17) SFDR.
- For Article 9 funds, the CSSF expects sustainable-investment status to be maintained at all times, including on an ongoing basis during the life cycle of the fund.
- Financial market participants should make available the methodology used to determine whether an investment is a sustainable investment, including any thresholds used for a pass-fail approach.
Suggested Considerations
- Review all Article 8 pre-contractual disclosures to confirm that the stated investment strategy clearly explains how the fund’s environmental or social characteristics are achieved.
- Strengthen any Article 8 exclusion-based strategy disclosures so they provide sufficient detail for investors to understand the connection between exclusions and the claimed sustainability characteristics.
- Reassess all Article 9 product classifications to confirm that the portfolio is built around qualifying sustainable investments, not only exclusions.
- Implement controls to verify that Article 9 holdings remain aligned with Article 2(17) SFDR on an ongoing basis throughout the fund lifecycle.
- Document and retain the internal methodology used to assess sustainable-investment status, including any thresholds, and ensure it can be provided to investors or supervisors upon request.
Key Dates
- CSSF published the SFDR FAQ clarifying supervisory expectations for Article 8 and Article 9 disclosures
- UCITS and AIFs disclosing under Article 8 or Article 9 must use the SFDR RTS periodic reporting templates in annual reports issued after this date
Compliance Impact
Non-compliance can lead to supervisory scrutiny, requests for remediation, and potential reclassification risk if a product cannot substantiate its Article 8 or Article 9 claims. The practical consequence is heightened greenwashing exposure and the possibility that disclosure changes may need formal review or authorisation before implementation.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerBankAll Firms
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
All Firms
No description available.
BankPayment Provider
amending Regulation (EU) No 833/2014 concerning restrictive measures in view of Russia’s actions destabilising the situation in Ukraine
All Firms
No description available.
Asset ManagerBank
No description available.
All Firms
No description available.
All Firms
implementing Regulation (EU) 2024/2642 concerning restrictive measures in view of Russia’s destabilising activities
All Firms
implementing Regulation (EU) 2024/1485 concerning restrictive measures in view of the situation in Russia
All Firms
No description available.
All Firms
Situation as at 31 December 2024
All Firms
No description available.
All Firms
No description available.
All Firms
No description available.
ESMA has launched a public consultation (via CSSF notification) on its technical advice to the European Commission for simplifying the EU Taxonomy disclosure framework, focusing on selected KPIs under the Taxonomy Disclosures Delegated Act and reducing reporting burdens. This matters for compliance teams because it is the first formal step in the review of Article 8 Taxonomy disclosure KPIs that will likely change how financial and non‑financial undertakings calculate and disclose Taxonomy‑related indicators from around Q3 2027.
What Changed
- - ESMA is consulting on technical advice to the European Commission specifically targeting selected KPIs under the Taxonomy Disclosures Delegated Act (Article 8 of the Taxonomy Regulation), including...
- The stated policy objective is simplification of the EU Taxonomy disclosure framework while preserving decision‑useful information for investors and supervisors.
- ESMA aims to reduce reporting burdens for market participants, notably corporates and financial institutions subject to Taxonomy Article 8 disclosures.
- The consultation covers selected KPIs under the Taxonomy Disclosures Delegated Act, with the European Commission having requested focused advice on: OpEx KPI of non‑financial firms; Commissions and...
- ESMA is proposing more pragmatic approaches to group‑level reporting for mixed groups, including reporting at parent‑undertaking level to reduce complexity for conglomerates.
Suggested Considerations
- Conduct an internal impact assessment of current Taxonomy Article 8 KPI calculation and reporting processes, focusing on OpEx, Commissions and Fees, Trading Book, and Underwriting KPIs, to identify pain points and simplification priorities.
- Prepare and submit a response to ESMA’s consultation by 12 August 2026, either directly or via industry associations, articulating specific operational, data, and system challenges and concrete proposals for simplification.
- Register for and attend ESMA’s public hearing on 22 July 2026 to understand the detailed proposals, ask clarifying questions, and align internal positions ahead of submission.
- Coordinate with regulatory affairs, sustainability, risk, and finance functions to develop a unified institutional position on the desired design of revised KPIs and group‑level reporting under the Taxonomy Disclosures Delegated Act.
- Map dependencies between Taxonomy Article 8 data and other ESG reporting (including SFDR product disclosures and CSRD/ESRS reporting) to anticipate how changes to KPIs may affect cross‑framework consistency and data architecture.
Key Dates
- ESMA launches its public consultation on simplifying the EU Taxonomy disclosure framework and technical advice on selected KPIs under the Taxonomy Disclosures Delegated Act
- ESMA holds a public hearing to present its proposals and engage with stakeholders on the consultation
- Deadline for stakeholders to submit responses to ESMA’s consultation on Taxonomy disclosure simplification
- ESMA (and other ESAs) are expected to deliver final technical advice on the Taxonomy Disclosures Delegated Act KPIs to the European Commission
- Target date for the European Commission to complete its review of the Taxonomy Disclosures Delegated Act based on ESAs’ advice
Compliance Impact
In the short term, non‑participation in the consultation does not create direct non‑compliance risk but may leave firms exposed to a revised framework that does not reflect their operational realities. In the medium term (Q3 2027 onward), failure to implement the revised Taxonomy KPIs and disclosure rules will create material regulatory, supervisory, and reputational risk, given the central role of Taxonomy data in EU sustainable finance and investor disclosures.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerBankInsurance No description available.
All Firms
No description available.
All Firms
No description available.
All Firms
Survey on the amount of covered deposits held on 30 June 2026
CSSF-CPDI 26/51 announces the **regular CPDI/Fonds de garantie des dépôts Luxembourg (FGDL) survey of covered deposits as at 30 June 2026**, to be completed by Luxembourg FGDL member institutions. This quarterly data collection feeds directly into the risk-based, ex‑ante contribution methodology under the deposit guarantee framework and is operationally important for prudential planning, reporting controls, and funding of the FGDL.
What Changed
- - CSSF launches a new covered deposits data survey with reference date 30 June 2026, continuing the established quarterly reporting cycle used for FGDL funding and risk-based contribution...
- Credit institutions incorporated under Luxembourg law, POST Luxembourg (for postal financial services), and Luxembourg branches of credit institutions from third countries must report the stock of...
- The survey must be submitted via the CSSF reporting channels (CSSF eDesk platform or other specified electronic means), using the data templates and technical specifications communicated by the CPDI,...
- Institutions that are members of the FGDL must ensure alignment between the survey data and the definition of “covered deposits” under the Law of 18 December 2015 on the failure of credit...
- The circular reaffirms that data reported for the survey feed into the risk‑based ex‑ante contribution mechanism set out in CPDI circulars on FGDL contributions (e.g.
Suggested Considerations
- Apply the EUR 100,000 coverage cap per depositor for the survey and ensure that non‑eligible deposits (such as certain financial sector deposits or specific categories excluded under the 2015 Law) are correctly filtered out of the covered deposits figures.
- Reconcile the 30 June 2026 covered deposits data with internal finance, risk, and regulatory reporting systems to ensure consistency with other prudential data and FGDL contribution calculations.
- Arrange for the survey report to be reviewed and formally approved by the institution’s governing body or the designated senior manager responsible for deposit guarantee scheme reporting, documenting the approval and any key assumptions or methodological choices.
- Submit the completed 30 June 2026 covered deposits survey through the CSSF eDesk platform or other specified reporting channel within the deadline set by CSSF-CPDI 26/51 and any accompanying CPDI instructions.
- Retain detailed working papers, data extracts, and methodology documentation supporting the 30 June 2026 survey in order to evidence compliance to CSSF, facilitate internal audit review, and support future FGDL ex‑ante contribution calculations.
Key Dates
– Reference date for the covered deposits snapshot; all figures in the survey must reflect the amount of covered deposits outstanding at close of business on this date
– Expected opening of the reporting window for uploading the 30 June 2026 covered deposits survey via CSSF eDesk or other specified channels, in line with the timetable used in prior CPDI surveys
– Likely cut-off date for submission of the 30 June 2026 survey, consistent with prior CPDI quarterly survey practices that require prompt post‑quarter reporting for FGDL purposes
Compliance Impact
Non-compliance with the 30 June 2026 covered deposits survey (late, incomplete, or inaccurate reporting) can trigger supervisory follow-up by the CSSF, impact the calculation of FGDL ex-ante contributions, and expose institutions to enforcement measures or reputational risk for weaknesses in deposit guarantee scheme reporting. Because covered deposits data underpin the adequacy of the deposit guarantee fund, supervisory scrutiny of data quality and governance over this survey is likely to be high.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Bank
Situation as at 31 May 2026
All Firms
No description available.
All Firms
on the setting of the countercyclical buffer rate for the third quarter of 2026
Bank
No description available.
All Firms
No description available.
What Changed
- - CSSF has published its 2025 supervisory disclosure covering supervisory measures and administrative penalties taken during the year.
- The publication serves as a public register-style disclosure of enforcement outcomes, increasing transparency around CSSF supervision and sanctioning activity.
- A related 2025 CSSF administrative sanction shows that AML/CFT non-compliance can result in a reprimand under the amended Luxembourg AML/CFT Law.
- The 28 July 2025 sanction confirms that CSSF can act where firms fail to maintain adequate professional AML/CFT obligations and related internal controls.
Suggested Considerations
- Review the firm’s AML/CFT control framework against the Luxembourg AML/CFT Law provisions that can trigger CSSF reprimands or sanctions, including governance, monitoring, and escalation controls.
- Verify that suspicious activity detection, investigation, and escalation procedures are documented, implemented, and tested for effectiveness.
- Reassess whether internal controls are sufficient to demonstrate timely compliance with professional AML/CFT obligations under CSSF supervision.
- Update remediation tracking to ensure supervisory findings are closed out promptly and supported by evidence of corrective action.
- Brief senior management on the reputational impact of public supervisory disclosures and ensure that recurring weaknesses are escalated to the board.
Key Dates
- CSSF’s supervisory disclosure covers **measures and administrative penalties for the year 2025**
- CSSF published the prior year’s supervisory disclosure page referencing the **2024** measures and penalties, showing the annual disclosure cycle
- CSSF issued an **administrative sanction** in an AML/CFT case, imposing a reprimand for non-compliance with the AML/CFT Law
Compliance Impact
The compliance impact is material because CSSF enforcement disclosures can expose weaknesses to the market, counterparties, auditors, and other regulators, creating reputational and supervisory pressure. Non-compliance with AML/CFT obligations can lead to public reprimands and potentially more severe measures if deficiencies persist or are systemic.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankAsset ManagerBroker Dealer No description available.
All Firms
No description available.
All Firms
No description available.
All Firms
No description available.
BankAsset ManagerBroker Dealer
No description available.
All Firms
No description available.
All Firms
No description available.
All Firms
No description available.
All Firms
No description available.
All Firms
No description available.
FATF has launched a public consultation, flagged by the CSSF, on new **guidance for implementing the revised FATF Recommendation 16 (“travel rule”)**, with the objective of significantly increasing payment transparency by 2030. This consultation will shape how jurisdictions and supervisors (including Luxembourg/CSSF) expect payment and virtual asset flows to carry and use originator/beneficiary data, so compliance teams should treat this as an early signal of future mandatory AML/CTF requirements for both fiat and virtual asset transfers.
What Changed
- *(Based on the CSSF notice plus the 2025 FATF revisions to Recommendation 16 and existing travel‑rule standards; details may be further refined by the new guidance now under consultation.)*
- FATF is issuing implementation guidance for the updated Recommendation 16, which already increased obligations regarding payment transparency, including more granular beneficiary data and expanded...
- Cross‑border payments and value transfers above 1,000 USD/EUR are expected to include additional mandatory beneficiary information, such as beneficiary name, account or unique reference, and at least...
- Beneficiary institutions are given enhanced responsibilities to use travel‑rule information (not just receive it) for transaction monitoring, including detecting misdirected payments and indicators...
- The revised travel rule continues to apply to both traditional wire transfers and value transfers involving virtual assets, reinforcing that Virtual Asset Service Providers (VASPs) must collect,...
Suggested Considerations
- Map and document all existing and planned cross‑border payment and value‑transfer flows (including virtual asset transfers) to identify where FATF Recommendation 16 and travel‑rule obligations currently apply or will apply by 2030.
- Review the June 2025 FATF modifications to Recommendation 16 and the current consultation materials, and perform a gap analysis against your existing AML/CTF, KYC and payments data standards, including thresholds, data fields, and monitoring use‑cases.
- Establish an internal project for travel‑rule implementation and enhancement that spans AML, operations, technology, legal and data‑protection teams, with explicit ownership and governance.
- Strengthen beneficiary‑side transaction‑monitoring rules to use incoming travel‑rule data for sanctions, fraud and AML detection, including controls to identify misdirected or unusual payments based on name, location, and other attributes.
- Review and, where necessary, update customer due diligence and KYC procedures to ensure the availability and verification of data fields that will be required to travel with transactions (for example, address, town and country, identification numbers, date of birth).
Key Dates
- FATF adopts modifications to Recommendation 16 to enhance payment transparency, including strengthened travel‑rule standards
- FATF launches public consultation on guidance for the implementation of the updated Recommendation 16
- FATF public consultation period closes; this is the deadline for private‑sector contributions highlighted by the CSSF
- FATF’s revised Recommendation 16 framework is expected to be fully effective, with jurisdictions having implemented the standard into national law or regulation by this date
Compliance Impact
Non‑compliance with the revised travel‑rule expectations will materially increase the risk of supervisory criticism, enforcement action, and restrictions on cross‑border business, especially in higher‑risk client segments and payment corridors. Failure to implement adequate data‑collection and monitoring capabilities may also compromise sanctions and AML controls, leading to heightened legal, financial and reputational exposure.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankPayment ProviderCrypto Exchange Identification of obliged entities eligible for direct supervision by AMLA
Circular CSSF 26/914 identifies which Luxembourg obliged entities fall within the perimeter for **potential direct supervision by the future EU Anti-Money Laundering Authority (AMLA)**, as part of the new EU-level AML/CFT supervisory architecture. This matters for compliance teams because in‑scope entities will face an additional EU supervisory layer, more intrusive AML/CFT oversight, and will need to prepare for alignment with AMLA’s methodologies, data requirements, and enforcement practices.
What Changed
- - The CSSF formally identifies Luxembourg “obliged entities” under AML/CFT law that are potentially eligible for direct AMLA supervision, clarifying which categories of firms fall into the EU‑level...
- The circular operationalises, at CSSF level, the EU allocation mechanism for direct supervision, building on Regulation (EU) 2024/… establishing AMLA and the forthcoming directly applicable AML...
- The CSSF establishes a process for providing information to AMLA on Luxembourg obliged entities (e.g. size, cross‑border activities, risk profile) to support AMLA’s periodic selection and review of...
- The circular clarifies that CSSF‑supervised entities identified as “eligible” remain under CSSF supervision unless and until AMLA formally designates them for direct supervision, at which point AMLA...
- The circular anticipates enhanced data and reporting requirements for entities assessed as eligible for AMLA direct supervision, including more granular information on cross‑border business,...
Suggested Considerations
- Determine whether your firm is likely to fall within the “eligible for AMLA direct supervision” perimeter by assessing your cross‑border footprint, ML/TF risk profile, group structure, and relative size against AMLA’s high‑risk and cross‑border criteria.
- Review and update the firm‑wide AML/CFT risk assessment to ensure it is robust, data‑driven, and aligned with an EU‑level supervisory perspective, including explicit consideration of cross‑border risks, complex group structures, and high‑risk products.
- Strengthen AML/CFT governance and oversight, including Board and senior management reporting, to demonstrate clear ownership of ML/TF risk, documented risk appetite, and effective challenge consistent with what AMLA expects from directly supervised entities.
- Review and, where necessary, enhance customer due diligence, transaction monitoring, screening and suspicious activity reporting frameworks to withstand more intrusive and harmonised EU‑level scrutiny.
- Map and document cross‑border business lines and passporting activities (branches, agents, tied intermediaries, distributors) to ensure you can provide complete and up‑to‑date information to the CSSF and AMLA on request.
Key Dates
- AMLA formally designates its first batch of directly supervised obliged entities at EU level, potentially including entities identified under this circular
- CSSF publishes Circular 26/914 identifying obliged entities eligible for direct supervision by AMLA and setting the framework for Luxembourg’s contribution to AMLA’s selection and supervisory process
- Periodic reviews by AMLA and the CSSF of eligible entities’ status and updates to the list of entities subject to, or proposed for, direct AMLA supervision
Compliance Impact
The compliance impact is high for any entity that is, or may become, eligible for AMLA direct supervision, given the likely increase in supervisory intensity, data expectations, and EU‑level enforcement risk. Non‑compliance could result in sanctions from both AMLA and national authorities, including significant administrative fines, business restrictions, remediation mandates, and reputational damage across the EU.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankPayment ProviderCrypto Exchange 1) high-risk jurisdictions on which enhanced due diligence and, where appropriate, counter-measures are imposed2) jurisdictions under increased monitoring of the FATFVersion of 19 June 2026
CSSF published a new **Annex to Circular CSSF 22/822** on **22 June 2026**, updating the Luxembourg regulator’s reference list of FATF **high-risk jurisdictions** and **jurisdictions under increased monitoring**. For compliance teams, this matters because AML/CFT country-risk scoring, enhanced due diligence triggers, and sanctions-style controls must be aligned to the current FATF position reflected by CSSF.
What Changed
- - CSSF republished the annex to Circular CSSF 22/822 in a Version of 19 June 2026, meaning firms should treat this as the current Luxembourg reference point for FATF jurisdiction screening and...
- The annex distinguishes between high-risk jurisdictions subject to enhanced due diligence and, where appropriate, counter-measures, and jurisdictions under increased monitoring that require...
- The publication incorporates the FATF’s current statements on jurisdictions with strategic AML/CFT/CPF deficiencies, which is the basis for operational country-risk controls used by...
- The related Circular CSSF 22/822 remains the framework document that instructs professionals to use FATF statements when assessing jurisdictional ML/TF/PF risk.
Suggested Considerations
- Review your AML/CFT country-risk methodology and update it to reflect the 19 June 2026 FATF/CSSF jurisdiction list.
- Re-screen customers, beneficial owners, counterparties, and transactions against the updated high-risk and monitored jurisdiction lists.
- Apply enhanced due diligence for relationships and transactions involving high-risk jurisdictions, and escalate where counter-measures may be required.
- Reassess risk ratings for customers linked to jurisdictions under increased monitoring and document the rationale for any continued onboarding, retention, or exit decisions.
- Update automated screening rules, transaction-monitoring scenarios, and onboarding checklists so they use the current CSSF annex version.
Key Dates
- Circular CSSF 22/822 was issued, establishing the framework for using FATF statements on high-risk jurisdictions and jurisdictions under increased monitoring
- The annex was updated to this version date, reflecting the current FATF jurisdiction lists and associated risk posture
- CSSF published the annex on its website, making the updated reference document operationally relevant for supervised firms
Compliance Impact
Non-compliance can lead to supervisory findings, remediation orders, and possible enforcement action where firms fail to apply risk-sensitive AML controls consistent with CSSF/FATF expectations. The practical impact is highest for onboarding, correspondent-like relationships, cross-border payments, and any business line exposed to higher-risk jurisdictions.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Application of the Guidelines of the European Banking Authority on ancillary services undertakings specifying the criteria for the identification of activities referred to in Article 4(1)(18) of Regulation (EU) No 575/2013 (EBA/GL/2026/01)
What Changed
- - The CSSF has formally applied the EBA Guidelines on ancillary services undertakings specified in EBA/GL/2026/01 for identifying activities under Article 4(1)(18) of Regulation (EU) No 575/2013.
- Firms must assess whether a non-bank activity or group entity qualifies as an ancillary services undertaking under the EBA criteria, rather than relying on internal labels or informal business...
- The regulatory perimeter analysis now needs to consider whether relevant activities are performed within a banking group in a way that affects prudential consolidation and supervisory treatment.
- Institutions should expect the CSSF to use the EBA framework as the benchmark for determining whether an activity is sufficiently connected to banking support functions to fall within the ancillary...
- Compliance evidence will need to show a documented, reproducible assessment of each potentially relevant activity against the EBA identification criteria.
Suggested Considerations
- Review all group entities and business lines to identify activities that may fall within the definition of an ancillary services undertaking under Article 4(1)(18) CRR.
- Document a formal assessment methodology for classifying activities against the EBA/GL/2026/01 criteria.
- Reconfirm the prudential consolidation perimeter and ensure all ancillary service entities are correctly included or excluded, with the reasoning retained for supervisory review.
- Update legal entity inventories, regulatory mapping, and governance documents so they align with the CSSF’s adopted EBA framework.
- Test whether existing internal reporting, risk management, and control frameworks capture any newly identified ancillary services undertakings.
Key Dates
- Circular CSSF 26/913 is published and the CSSF confirms application of EBA/GL/2026/01
- Firms should apply the CSSF’s expectations from the date the circular becomes applicable, if that date is specified in the full circular text or accompanying CSSF notice
- Affected firms should complete internal perimeter reviews and any resulting governance or reporting updates by the first supervisory reporting cycle after application
Compliance Impact
The compliance impact is moderate to high because the main risk is misclassification of entities or activities within the prudential perimeter, which can lead to supervisory findings, reporting errors, or consolidation issues. Non-compliance may result in CSSF remediation expectations, delayed approvals, or corrective supervisory action if a firm’s entity mapping is inconsistent with the EBA criteria.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankAll Firms
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
All Firms
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
All Firms
No description available.
Bank
No description available.
Asset ManagerBroker DealerBank
No description available.
Asset ManagerAll Firms
Press release 26/12
Bank
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
All Firms
implementing Regulation (EU) 2024/2642 concerning restrictive measures in view of Russia’s destabilising activities
All Firms
amending Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
All Firms
No description available.
BankPayment Provider
Situation as at 30 April 2026
All Firms
Situation as at 31 March 2026
All Firms
Situation as at 30 April 2026
Bank
Situation as at 31 March 2026
All Firms
No description available.
The CSSF is flagging to the market a new **CNC Q&A 26/037** that clarifies the distinction between **statutory (legal) annual accounts** and **annual accounts prepared for contractual or voluntary purposes**, and an interview indicating an upcoming **overhaul of Luxembourg accounting legislation**. This matters for compliance and finance teams because mislabeling or misusing “statutory” accounts, or applying CNC doctrine inconsistently, can create legal, regulatory, lending, and investor‑information risks, and the announced legislative reform implies future adjustments to accounting policies, reporting processes, and governance.
What Changed
- - The CSSF formally draws regulated entities’ attention to CNC Q&A 26/037, elevating it as a key interpretative reference on the concepts of annual accounts prepared for legal/statutory purposes...
- The CNC Q&A 26/037 provides clarified definitions of “comptes annuels établis à fins légales” (statutory annual accounts) and “comptes annuels établis à des fins contractuelles ou sur base...
- The Q&A gives practical answers to frequently asked questions from preparers about when accounts qualify as statutory versus merely contractual or voluntary, and how this affects applicable...
- The Q&A addresses related issues, such as the extent to which CNC doctrine and Luxembourg GAAP must be followed for contractual or voluntary accounts, and the risks of presenting non‑statutory...
- The CSSF also highlights an interview with the CNC chairman announcing that Luxembourg accounting legislation will undergo a refonte (major overhaul), signaling that current CNC doctrine, including...
Suggested Considerations
- Obtain and review the full CNC Q&A 26/037 and the CNC chairman’s interview (French‑language originals), ensuring that finance, accounting, and compliance teams understand the clarified distinctions between statutory and contractual/voluntary annual accounts.
- Map all sets of financial statements prepared by each Luxembourg entity (statutory accounts, covenant‑based or lender‑specific accounts, group reporting packages, management accounts, etc.) and classify each set as statutory or contractual/voluntary in line with CNC Q&A 26/037 definitions.
- Update internal accounting policies and manuals to explicitly define statutory versus contractual/voluntary annual accounts, specify the applicable accounting principles and disclosures for each, and describe any differences in measurement, presentation, or scope.
- Assess current practices for communicating financial information to lenders, investors, regulators, and other stakeholders to confirm that non‑statutory accounts are not labeled or presented in a way that could be misinterpreted as statutory accounts approved under Luxembourg company law.
- Implement clear labeling and disclosure conventions on the face of financial statements and in accompanying notes (e.g., in engagement reports, board minutes, and management communications) to distinguish statutory annual accounts from any contractual or voluntary accounts.
Key Dates
– Publication of the interview with the CNC chairman in Paperjam announcing that Luxembourg accounting legislation will be overhauled
– CSSF press release published, drawing attention to CNC Q&A 26/037 and the CNC chairman’s interview and signaling supervisory expectations that entities consider this doctrine when preparing annual accounts
Compliance Impact
Failure to correctly distinguish and label statutory versus contractual/voluntary annual accounts can lead to breaches of Luxembourg company law, mis‑disclosure to investors, lenders, and regulators, and increased enforcement risk from the CSSF and other authorities. Misalignment between CNC doctrine and practice may also complicate audits and regulatory reviews, leading to qualified opinions, remediation requirements, or sanctions in severe cases.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankAsset ManagerInsurance Q&A CNC 26/037 titled “A reminder of the differences between annual accounts prepared for statutory purposes and annual accounts prepared for contractual purposes or on a voluntary basis” and interview with the chairman of the CNC (Mr. Yvan Thommes)
The CSSF is formally directing market participants’ attention to new guidance from the Luxembourg Commission des normes comptables (CNC) clarifying the distinction between **statutory annual accounts** and **contractual/voluntary annual accounts**, and to an interview announcing a forthcoming overhaul of Luxembourg accounting law. This matters for compliance and finance functions because it affects how firms label, prepare, approve, file and use financial statements in regulatory, contractual and investor contexts, and foreshadows medium‑term changes to the Luxembourg accounting framework.
What Changed
- - The CSSF endorses and promotes CNC Q&A 26/037 as the reference clarification on the concept of “comptes annuels établis à fins légales” (statutory annual accounts) versus annual accounts prepared...
- The Q&A provides clear criteria to distinguish statutory accounts from non‑statutory accounts, including their legal basis, approval process, filing and publication obligations, and permissible use...
- The CNC guidance clarifies that statutory annual accounts must fully comply with Luxembourg accounting law (including mandatory layouts, valuation rules and disclosures), whereas...
- The CNC addresses frequent practical questions from preparers, including whether financial statements prepared for banks, covenants, shareholders’ agreements, management incentive plans or...
- The CSSF communicates that misunderstandings between statutory and contractual accounts remain common, implicitly warning against the risk of using non‑statutory statements in contexts where...
Suggested Considerations
- Identify all sets of financial statements prepared by the firm or its Luxembourg entities (statutory, covenant/banking, shareholder/management, group‑reporting, voluntary) and map which are statutory annual accounts under Luxembourg law and which are contractual or voluntary.
- Review the CNC Q&A 26/037 in detail and update internal accounting manuals and group reporting policies to embed the CNC’s definitions, terminology and criteria for statutory versus non‑statutory annual accounts.
- Implement a clear labelling and disclosure convention so that all non‑statutory financial statements explicitly state their nature (contractual or voluntary) and are not presented or communicated as statutory annual accounts.
- Update templates for board and shareholder approvals, minutes and resolutions to ensure that the correct set of statutory annual accounts is approved for legal purposes such as profit appropriation, dividend distribution, capital reduction and regulatory filings.
- Review all contractual arrangements (loan agreements, bond indentures, shareholder agreements, management incentive plans and service contracts) to determine whether they require statutory annual accounts or allow contractual/adjusted accounts, and align documentation and practice accordingly.
Key Dates
– Publication of the interview with the CNC chairman in Paperjam announcing that Luxembourg accounting legislation will be subject to a comprehensive overhaul
– CSSF communiqué published, formally drawing attention to CNC Q&A 26/037 and the CNC chairman’s interview, and thereby activating supervisory expectations that firms take these clarifications into account
– Effective dates for the planned overhaul of Luxembourg accounting legislation remain to be defined; firms should anticipate consultation and transition periods once draft law is published
Compliance Impact
Misclassification or misuse of contractual/voluntary accounts where statutory annual accounts are legally required can lead to breaches of Luxembourg company law, invalid shareholder resolutions, misstatements in regulatory or investor reporting, and potential CSSF supervisory findings. Consistent application of the CNC guidance will be expected in future inspections and could influence audit opinions and governance assessments.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankAsset ManagerBroker Dealer No description available.
Asset Manager
No description available.
All Firms
No description available.
All Firms
No description available.
All Firms
Further details concerning the AMLA webinar of 10 June 2026 from 10 am to 12 pm CEST
All Firms
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
All Firms
Version 1.5
All Firms
No description available.
CSSF is pressing Luxembourg market participants to complete T+1 readiness surveys by **9 June 2026** and to engage with ESMA’s broader T+1 consultation work, because the EU settlement cycle moves to **T+1 on 11 October 2027** under CSDR. The publication matters because it signals that supervisors are already assessing industry preparedness and that firms must accelerate post-trade process changes, especially around allocations, confirmations, and electronic messaging.
What Changed
- - CSSF is requiring market participants to complete the national competent authorities’ T+1 readiness survey by 9 June 2026, with responses visible only to CSSF and ESMA.
- CSSF is strongly encouraging participation in the EU T+1 Industry Committee second readiness survey to support a Union-wide assessment of market preparedness.
- CSSF is flagging that the transition to T+1 settlement on 11 October 2027 under CSDR will require coordinated changes across the trading and post-trading chain.
- CSSF is warning that forthcoming amendments to the RTS on Settlement Discipline are expected to be endorsed by the European Commission and will further define operational requirements for the T+1...
- ESMA’s revised guidelines on standardised procedures and messaging protocols are intended to make post-trade communication faster, clearer, and more consistent across the EU.
Suggested Considerations
- Complete the CSSF T+1 readiness survey before 9 June 2026 and ensure the submission accurately reflects the firm’s current operational readiness.
- Participate in the EU T+1 Industry Committee second readiness survey to demonstrate engagement with the EU-wide readiness process.
- Review the firm’s allocation and confirmation workflows to ensure they can operate within T+1 timeframes.
- Replace any reliance on oral, manual, or non-machine-readable communications with electronic, standardised messaging channels unless a temporary technical disruption justifies an exception.
- Align internal messaging standards with international messaging protocols used for post-trade communication.
Key Dates
- CSSF publishes the reminder on T+1 readiness, survey participation, and ESMA’s consultation work
- Deadline to complete the CSSF national competent authorities’ T+1 readiness survey
- Expected application date of the revised ESMA guidelines on standardised procedures and messaging protocols
- T+1 settlement cycle becomes effective under CSDR
Compliance Impact
Non-participation in the surveys will not itself appear to be the substantive T+1 breach, but it will materially weaken supervisory visibility and may invite follow-up scrutiny from CSSF and ESMA. Firms that fail to adapt allocations, confirmations, and messaging processes risk being unprepared for the 7 December 2026 guidance phase-in and the 11 October 2027 settlement-cycle change, which could create settlement fails, operational disruption, and conduct/governance issues.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
All FirmsAsset ManagerBank No description available.
CSSF reminds Luxembourg market participants that the EU move to a **T+1 settlement cycle under CSDR on 11 October 2027** is now in execution phase and links this directly to concrete supervisory tools: mandatory-like readiness surveys, RTS on Settlement Discipline amendments, and new ESMA post‑trade communication guidelines. For compliance teams, this is a front‑to‑back operating model change: firms must demonstrate T+1 readiness to CSSF/ESMA, transition to fully electronic, standardised post‑trade communication, and align allocations/confirmations processes to tighter regulatory timelines.
What Changed
- - The EU settlement cycle for in‑scope financial instruments under CSDR will shorten from T+2 to T+1 with effect from 11 October 2027, materially reducing the time to complete front‑to‑back trade,...
- CSSF has launched a national competent authorities’ T+1 readiness survey and sets a firm completion deadline of 9 June 2026 for Luxembourg market participants, treating it as a critical supervisory...
- In parallel, CSSF strongly encourages Luxembourg firms to complete the EU T+1 Industry Committee (EUIC) second readiness survey to support an EU‑wide view of T+1 readiness and potential systemic...
- ESMA’s final draft amendments to the CSDR RTS on Settlement Discipline will introduce additional operational requirements specifically designed to support T+1 (e.g.
- ESMA has launched a consultation on updated guidelines on standardised procedures and messaging protocols for allocations, confirmations and affirmations, explicitly aimed at facilitating the T+1...
Suggested Considerations
- Identify all group entities and business lines in Luxembourg that are in scope of CSDR T+1 (trading, clearing, settlement, custody, collateral, fund dealing) and formally designate a T+1 programme owner at senior management level.
- Complete the CSSF T+1 national competent authorities’ survey in full and by 9 June 2026, ensuring that responses accurately reflect current readiness, key risks, dependencies on third parties, and planned remediation milestones.
- Arrange for appropriate internal review and sign‑off (e.g. by Compliance and relevant senior management) of the responses to both the CSSF survey and the EUIC second readiness survey before submission.
- Participate in the EU T+1 Industry Committee second readiness survey and ensure the firm’s answers are consistent with the information provided to CSSF and with internal T+1 project documentation.
- Perform a comprehensive T+1 impact assessment of front‑to‑back trade flows, covering trade execution, allocation, confirmation, affirmation, clearing, settlement, collateral movements, cash and liquidity management, and corporate actions.
Key Dates
- Deadline for Luxembourg market participants to complete the CSSF national competent authorities’ T+1 readiness survey
- Expected application date of revised ESMA guidelines on standardised procedures and messaging protocols and the aligned new RTS on Settlement Discipline requirements on allocations and confirmations
- Effective date for the transition to a T+1 settlement cycle in the EU under CSDR
Compliance Impact
Non‑compliance is high‑impact: failure to prepare for T+1, to respond adequately to supervisory surveys, or to align processes with RTS on Settlement Discipline and ESMA guidelines can lead to increased settlement fails, penalties, supervisory scrutiny, and potential enforcement action. The T+1 change also amplifies operational, liquidity, and conduct risks if firms cannot meet accelerated timelines, making early execution of remediation plans a prudential and conduct priority.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankBroker DealerAsset Manager Preparation of the new data collection exercice for the purpose of the direct supervision by AMLA – AMLA webinar of 10 June 2026 from 10 am – 12 pm CEST
All Firms
No description available.
All Firms
No description available.
All Firms
No description available.
All Firms
No description available.
All Firms
amending Regulation (EU) 2023/1529 concerning restrictive measures in view of Iran’s military support to Russia’s war of aggression against Ukraine and to armed groups and entities in the Middle East and the Red Sea region as well as Iran’s actions undermining freedom of navigation in the Middle East
All Firms
No description available.
All Firms
1° amending:(a) the Law of 5 April 1993 on the financial sector, as amended;(b) the Law of 17 December 2010 relating to undertakings for collective investment, as amended;(c) the Law of 18 December 2015 on the failure of credit institutions and certain investment firms, as amended;(d) the Law of 15 March 2016 on OTC derivatives, central counterparties and trade repositories and amending different laws relating to financial services, as amended;2° transposing:(a) Directive (EU) 2024/1619 of th...
Bank
No description available.
The CSSF publication highlights AMLA's public consultation on draft Regulatory Technical Standards (RTS) under Articles 16(4) and 17(3) of Regulation (EU) 2024/1624, specifying minimum group-wide AML/CFT requirements and additional measures for subsidiaries and branches in third countries. This matters because it aims to harmonize cross-border AML frameworks, ensuring groups maintain consolidated ML/TF risk views and robust controls, particularly in high-risk third-country operations, impacting EU financial groups' compliance structures. Private sector input is encouraged to align standards with practical operations.[https://www.cssf.lu/en/Document/public-consultation-by-amla-on-the-draft-rts-on-group-wide-minimum-requirements-and-additional-measures-for-subsidiaries-and-branches-in-third-countries/][https://www.amla.europa.eu/amla-consults-group-wide-requirements-and-business-wide-risk-assessment_en]
What Changed
- - Group-wide AML/CFT frameworks: Establishes minimum standards for design and implementation across groups, including cross-border structures and third-country operations, to enable consolidated...
- Third-country subsidiaries and branches: Introduces additional measures for entities in non-EU countries, extending requirements beyond traditional groups to other...
- Information sharing and parent identification: Defines provisions for intra-group data sharing and criteria to identify the EU parent undertaking when multiple entities report to a third-country head...
- Interlinked mandates: Cross-references obligations between Articles 16(4) and 17(3) for complementary requirements on organizational...
Suggested Considerations
- Register for 20 May 2026 public hearing to engage directly on practical application across group structures.[https://www.amla.europa.eu/events/public-hearing-draft-rts-group-wide-minimum-requirements-and-additional-measures-subsidiaries-and-2026-05-20_en]
- Assess current group-wide AML/CFT frameworks against proposed minimums, identifying gaps in third-country controls, risk consolidation, and data sharing protocols.
Compliance Impact
Urgency: High – Firms with third-country exposure must act now on consultation (closes 15 July 2026) to influence final RTS, as these will mandate binding minimums for group-wide AML/CFT, potentially requiring significant framework overhauls for risk consolidation and controls. Non-engagement risks misaligned systems post-adoption, increasing supervisory scrutiny under harmonized EU standards; early assessment prevents rushed...
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankAsset ManagerPayment Provider
No description available.
AMLA has launched a public consultation on draft Guidelines for business-wide risk assessments (BWRA) under the new Anti-Money Laundering Regulation (EU 2024/1624), with submissions open until 15 July 2026. These guidelines establish minimum requirements for all obliged entities across financial and non-financial sectors to systematically identify and manage money laundering and terrorist financing risks inherent to their operations.
What Changed
- The draft Guidelines introduce four minimum requirements for conducting adequate business-wide risk assessments applicable to all obliged entities. The framework mandates that entities:
- Identify risk exposure across their business model, customers, products, services, transactions, delivery channels, and geographical exposure
- Maintain consolidated risk views across group structures, eliminating silos between branches and subsidiaries
- Utilize internal and external data sources to build comprehensive risk landscapes, including monitoring customer behavior changes and tracking international typologies
- Apply proportionality based on entity size, business model, and risk profile, while ensuring consistent application of policies across the organization
The guidelines specifically address evaluation...
Suggested Considerations
- *Immediate (by 15 July 2026):
- Review draft Guidelines and assess alignment with current BWRA practices
- Identify gaps between existing risk assessment frameworks and proposed minimum requirements
- Prepare formal consultation responses, particularly if your organization operates in non-financial sectors
- Register for relevant public hearings (28 May for BWRA Guidelines; 20 May for group-wide RTS) to engage directly with AMLA
Key Dates
- Final adoption of guidelines and technical standards
- Consultation launched
- Public hearing on draft RTS on group-wide requirements
- Public hearing on draft Guidelines on business-wide risk assessment
- Consultation deadline for submissions
Compliance Impact
Urgency: HIGH
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
All Firms
No description available.
BankAsset ManagerWealth Manager
No description available.
BankWealth ManagerFintech
No description available.
BankWealth ManagerAll Firms
No description available.
BankAsset ManagerWealth Manager
No description available.
BankWealth ManagerFintech
regarding the “LMT activation” module in relation to additional liquidity management requirements for Luxembourg-domiciled UCITS, or where applicable their management company, and Luxembourg-authorised AIFMs that manage open-ended AIFs, introduced by the Law of 3 March 2026, transposing Directive (EU) 2024/927 of the European Parliament and of the Council of 13 March 2024
Asset ManagerBank
Situation as at 31 March 2026
BankAsset ManagerBroker Dealer
Situation as at 28 February 2026
BankAsset ManagerWealth Manager
Situation from March 2025 to March 2026
BankAsset ManagerBroker Dealer
Situation from March 2025 to March 2026
BankAsset ManagerBroker Dealer
Situation from March 2025 to March 2026
Asset ManagerBankBroker Dealer
No description available.
No description available.
BankWealth ManagerFintech
relating to the issue of covered bonds
BankWealth ManagerAll Firms
on the operationalisation of European regulations in the area of financial services
BankAsset ManagerWealth Manager
on markets in financial instruments
BankAsset ManagerBroker Dealer
on key information documents for packaged retail and insurance-based investment products
Asset ManagerBankInsurance
on market abuse
BankBroker DealerAsset Manager concerning the audit profession
BankWealth ManagerAsset Manager
on the failure of credit institutions and certain investment firms
BankWealth ManagerAsset Manager
transposing Directive 2004/25/EC of the European Parliament and of the Council of 21 April 2004 on takeover bids
BankBroker DealerAsset Manager
on institutions for occupational retirement provision in the form of SEPCAVs and ASSEPs
Asset ManagerBankInsurance
on the financial sector
BankWealth ManagerAsset Manager
No description available.
BankWealth ManagerAsset Manager
No description available.
BankWealth ManagerAsset Manager
No description available.
Asset ManagerBankWealth Manager
on the setting of the countercyclical buffer rate for the second quarter of 2026
Bank
Situation as at 28 February 2026
BankAsset ManagerWealth Manager
Survey on the amount of covered deposits held on 31 March 2026
Circular CSSF-CPDI 26/50 mandates a recurring annual survey on the amount of **covered deposits** held as of **31 March 2026** by specified Luxembourg credit institutions, to support the Fonds de garantie des dépôts Luxembourg (FGDL) in meeting Deposit Guarantee Scheme (DGS) requirements under the 2015 Law and DGSD. This matters for compliance as it ensures institutions contribute accurately to the FGDL's buffer (targeting 2% of covered deposits by 2026), with data also feeding into Single Resolution Board (SRB) calculations for resolution funding.
What Changed
This circular introduces no substantive changes to survey content, methodology, or reporting specifications compared to prior issuances (e.g., CSSF-CPDI 25/49 for 31 December 2025). Updates are limited to the reference date (31 March 2026) and associated deadlines, maintaining the risk-based ex-ante contribution method from Circular CSSF-CPDI 20/21 and quarterly reporting under CSSF-CPDI 17/07.
Suggested Considerations
- Compile data on covered deposits (eligible deposits up to €100,000 per depositor, per Article 163 of 2015 Law), excluding items per Article 172 (e.g., financial institutions, life insurance).
- Report detailed breakdowns: total eligible/covered deposits, omnibus/fiduciary accounts (with beneficiary counts), natural vs. legal persons, branch-level data.
- Submit via specified format (per attached specs, unchanged from priors) to CPDI by deadline; quarterly data ongoing per CSSF-CPDI 17/07.
- Ensure alignment with FGDL contributions under CSSF-CPDI 25/48.
Key Dates
- Reference date for snapshot of covered deposits
(inferred from pattern in prior circulars like 25/49) - Likely submission deadline for survey data to CPDI (exact date in full PDF; aligns with one-month post-reference in predecessors)
Compliance Impact
Urgency: High – Immediate action required today (publication date) to prepare for 31 March 2026 snapshot (just 5 days away), with submission likely due early May 2026. Non-compliance risks FGDL penalties, inaccurate contributions (impacting 0.8% extra buffer to 2% DGSD minimum), and SRB reporting failures under Regulation (EU) 2015/63; recurring nature demands robust quarterly data processes.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Bank
No description available.
BankWealth ManagerFintech
Amendment of Circular CSSF 18/703 on the introduction of a semi-annual reporting of borrower related residential real estate indicators
Circular CSSF 26/908 amends Circular CSSF 18/703 to update semi-annual reporting requirements for borrower-related residential real estate indicators, enhancing supervisory oversight of credit risk in Luxembourg's financial sector. Published today (25 March 2026), it matters for credit institutions as it refines data collection to better monitor real estate lending exposures amid potential market vulnerabilities.
What Changed
The circular introduces amendments to the original Circular CSSF 18/703 (itself amended by Circulars CSSF 20/737 and 21/772), focusing on semi-annual reporting of indicators tied to borrowers in residential real estate. Specific changes are not detailed in the provided summary or full content excerpt, but they likely involve refinements to reporting templates, data granularity, or submission processes to align with evolving EU prudential standards on real estate risk monitoring. The updated consolidated version of Circular CSSF 18/703 is now available as a 258.91Kb PDF.
Suggested Considerations
- Download and review the full Circular CSSF 26/908 (291.96Kb PDF) and the updated consolidated Circular CSSF 18/703 (258.91Kb PDF) from the CSSF website: https://www.cssf.lu/en/Document/circular-cssf-26-908/.
- Conduct a gap analysis of current reporting processes against the amended requirements for borrower-related residential real estate indicators.
- Update internal systems, data collection templates, and reporting workflows to ensure accurate semi-annual submissions to the CSSF.
- Train relevant compliance, risk, and finance teams on changes; document compliance confirmations for audit trails.
Key Dates
- Original issuance of Circular CSSF 18/703 introducing semi-annual reporting
- Publication date of Circular CSSF 26/908 (today)
Compliance Impact
Urgency: Medium - This is a targeted amendment to existing reporting obligations rather than a new regime, reducing immediate disruption, but non-compliance risks supervisory scrutiny, fines, or enhanced monitoring given CSSF's focus on real estate risk. It matters for maintaining accurate credit risk data, especially in a potentially volatile residential property market, supporting broader prudential stability.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Bank
Version of 9 March 2026
The CSSF Technical FAQ on Regulation No 20-08 provides implementation guidance on **loan-to-value (LTV) limits for residential real estate credit in Luxembourg**, establishing borrower-based macroprudential measures designed to limit leverage in the mortgage market. This guidance is critical for lenders operating in Luxembourg as it clarifies how to calculate own funds, determine LTV compliance, and apply temporary portfolio exemptions that have been extended through June 30, 2025.
What Changed
- The most recent update (March 9, 2026) to the Technical FAQ reflects the regulatory framework established by CSSF Regulation No 20-08 (as modified by Regulation No 24-10).
- First-time buyers: LTV limit of up to 100%
- Other buyers: LTV limit of 90%, implemented via portfolio allowance
Buy-to-Let Residential Loans:
- Standard LTV limit of 80%
- Temporary exemption (until June 30, 2025): Lenders may apply LTV ratios up to 95% for up to 10% of annual production
Other Residential Real Estate Loans:
Suggested Considerations
- *For all lenders:
- *Verify LTV compliance calculations for all new residential mortgage originations using the framework specified in the FAQ, ensuring own funds are calculated as actual equity contributions from borrowers
- *Implement dual LTV tracking for borrowers financing new property through sale of existing property, ensuring compliance with both interim and final LTV ratios
- *Document own funds sources carefully, particularly when cash collateral or sale proceeds are used, as these are only permitted for loans with initial LTV below 100%
- *Prepare for June 30, 2025 transition by:
Key Dates
- CSSF Regulation No 20-08 originally published
- Regulation and LTV limits became effective for residential real estate credit on Luxembourg territory
- CSSF Regulation No 24-04 introduced temporary adjustments to LTV limits
- CSSF Regulation No 24-10 extended temporary adjustments
- Most recent Technical FAQ version published (prior to March 9, 2026 update)
Compliance Impact
Urgency: HIGH
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankFintech
on the introduction of a semi-annual reporting of borrower-related residential real estate indicators
Circular CSSF 18/703 introduces semi-annual reporting requirements for Luxembourg-based lenders on borrower-related residential real estate (RRE) indicators to monitor macroprudential risks in the RRE lending market, in line with ESRB Recommendation 2016/14 (as amended). It matters for compliance because it mandates data collection via a dedicated CSSF template, with exclusions only for banks below EUR 10 million in outstanding RRE exposures, ensuring supervisory oversight of lending standards. The circular has been iteratively amended (CSSF 20/737, 21/772, 26/908), with the latest update on 25 March 2026 refining reporting processes.
What Changed
- - Original Scope (CSSF 18/703, 17 Dec 2018): Requires semi-annual reporting of RRE indicators for loans secured by Luxembourg residential real estate (existing dwellings, under construction,...
- Amendment CSSF 20/737 (19 Feb 2020): Clarified reporting thresholds and processes; banks with total outstanding RRE exposure ≤ EUR 10 million are exempt from reporting (no zero report needed if no...
- FAQ (19 Feb 2020): Specifies reporting for new exposures (Jan-Jun or Jul-Dec) and outstanding exposures as of 30 June/31 Dec; exemption applies only if exposure < EUR 10 million.
- Amendment CSSF 21/772 (10 May 2021): Further refinements to data template and indicators.
- Amendment CSSF 26/908 (25 Mar 2026): Latest update to reporting template and processes, effective immediately given publication date.
Data is collected via a CSSF template on the website, focusing on...
Suggested Considerations
- Download and use the dedicated RRE data template from the CSSF website (https://www.cssf.lu/en/Document/circular-cssf-18-703/).
- Assess total outstanding RRE exposure; if > EUR 10 million, collect data on new/outstanding exposures per reference dates (30 Jun/31 Dec).
- Ensure IT systems store/process RRE indicators (e.g., borrower debt metrics, collateral details) for semi-annual extraction.
- Submit reports to CSSF in April/October; review amendments (20/737, 21/772, 26/908) and FAQ for updates.
- For exempt banks: Confirm eligibility annually; no zero report required.
Key Dates
Original Circular CSSF 18/703 published; reporting obligation introduced
Circular CSSF 20/737 and FAQ published; clarified exemptions and scope
Circular CSSF 21/772 amendment published
Circular CSSF 26/908 amendment published (today's date); immediate implementation expected for upcoming cycles
annual); Reports due in April (ref. 31 Dec) and October (ref. 30 Jun) each year
Compliance Impact
Urgency: High – Ongoing semi-annual obligation with latest amendment today (25 Mar 2026, CSSF 26/908) likely affects the next October 2026 cycle (ref. 30 Jun 2026); non-compliance risks supervisory sanctions, as it supports macroprudential monitoring under ESRB framework. Firms must validate systems/data immediately post-amendment to avoid gaps in reporting population.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Bank
No description available.
BankAsset ManagerWealth Manager
Press release 26/07
Bank
Situation as at 31 December 2025
BankWealth ManagerAll Firms
(first publication: 30 October 2024)
BankWealth ManagerAll Firms
Situation as at 31 December 2025
BankAsset ManagerWealth Manager
Situation as at 31 December 2025
BankAsset ManagerWealth Manager
Out-of-court consumer complaint resolution
BankWealth ManagerFintech
No description available.
Asset ManagerBankWealth Manager
in relation to additional liquidity management requirements for Luxembourg-domiciled UCITS, or where applicable their management company, and Luxembourg-authorised AIFMs that manage open-ended AIFs, introduced by the Law of 3 March 2026, transposing Directive (EU) 2024/927 of the European Parliament and of the Council of 13 March 2024
Asset ManagerBank
Latest update on the AML/CFT standardised data collection
This CSSF circular letter addresses the 2026 AML/CFT standardised data collection exercise, aligning with AMLA's EU-wide initiatives by adopting AMLA-developed templates for most supervised entities while requiring specialised professionals to use CSSF-specific forms. It matters for Luxembourg financial firms as it mandates reporting on ML/TF risks and mitigation measures to support consistent EU supervision, with recent delays emphasizing preparation needs amid evolving templates.
What Changed
- - CSSF adopts AMLA-developed data collection templates for credit institutions, investment firms, and investment fund managers (excluding specialised professionals), replacing its prior questionnaire...
- Entities selected for AMLA's mandatory calibration exercise (notified directly by CSSF) must report quantitative and qualitative ML/TF risk data; non-selected entities still report via AMLA templates...
- Launch delayed from 2 March 2026 due to AMLA's consultation feedback on templates and guidance; new timelines and final questionnaire to be announced, but AMLA maintains 15 April 2026 submission for...
- Specialised professionals of the financial sector complete a separate CSSF questionnaire, launching earlier on 23 February 2026 (subject to delay).
Suggested Considerations
- Monitor CSSF communications for final questionnaire, launch dates, and eDesk access; prepare data on 2025 ML/TF risks and mitigation using current AMLA draft (not for submission).
- Selected AMLA calibration participants: Compile and submit quantitative/qualitative data via eDesk by 15 April 2026; attend 13 March webinar.
- Non-selected credit/financial institutions: Complete AMLA templates on ML/TF risks/mitigation for 2025 via eDesk upon launch.
- Specialised professionals: Prepare CSSF-specific questionnaire ahead of (delayed) 23 February launch.
- All: Ensure resources for timely reporting; review internal AML/CFT risk assessments for consistency with EU standards.
Key Dates
- Planned launch for specialised professionals' CSSF questionnaire (delayed per 11 March update)
- Original launch date for AMLA questionnaire and calibration exercise via eDesk platform (delayed)
- AMLA webinar (10:00-12:00) on reporting framework and clarifications (connection details in CSSF annex)
- Submission deadline for AMLA calibration exercise participants (maintained despite delays; changes to be communicated)
11 March 2026); - New launch and submission deadlines for all data collections, pending final AMLA questionnaire
Compliance Impact
Urgency: High - Mandatory reporting supports CSSF's supervisory strategy and EU AMLA calibration, with non-compliance risking enforcement; delays provide preparation time but require immediate data readiness as final deadlines approach shortly (e.g., potential April submissions). This directly feeds into entity-level ML/TF risk assessments, influencing ongoing supervision and resource allocation.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankAsset ManagerAll Firms
No description available.
BankWealth ManagerAll Firms
No description available.
BankWealth Manager
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
BankWealth ManagerAsset Manager
Situation as at 31 January 2026
BankAsset ManagerWealth Manager
Situation as at 31 January 2026
BankAsset ManagerWealth Manager
No description available.
BankWealth ManagerFintech
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
BankWealth ManagerAsset Manager
No description available.
BankWealth ManagerAsset Manager
Delay in the 2026 AML/CFT standardised data collection
BankAsset ManagerWealth Manager
Delay in the 2026 AML/CFT standardised data collection
BankAsset ManagerWealth Manager
Press release 26/06
BankAsset ManagerWealth Manager
No description available.
BankWealth ManagerAll Firms
Delay in the 2026 AML/CFT standardised data collection
The CSSF circular letter dated 11 March 2026 announces a delay in its planned AML/CFT standardised data collection exercise originally scheduled for 2026, primarily due to overlap with a concurrent broad-scope data collection by the European Anti-Money Laundering Authority (AMLA). This matters for compliance professionals as it reduces immediate reporting burdens on supervised entities, promotes regulatory simplification, and aligns Luxembourg practices with emerging EU AML/CFT methodologies, allowing firms to redirect resources to the mandatory AMLA exercise.
What Changed
- - Postponement of CSSF-specific questionnaire: The CSSF has decided not to proceed with its own AML/CFT standardised data collection for most supervised entities (credit institutions, investment...
- Exception for specialised professionals: Specialised professionals of the financial sector (e.g., certain non-credit institutions) remain subject to a CSSF-specific questionnaire, though timelines...
- Rationale tied to AMLA calibration exercise: Entities selected for AMLA's 2026 calibration exercise (notified directly by CSSF) must complete it regardless; non-selected entities were to use AMLA...
- Potential for ad-hoc requests: CSSF reserves the right to issue targeted questionnaires later in 2026 for essential data points not covered by AMLA.
These changes supersede the 12 February 2026...
Suggested Considerations
- Monitor CSSF updates: Await forthcoming communications on revised modalities, new timelines, and any ad-hoc requests via eDesk platform.
- Prioritize AMLA obligations: Selected entities must prepare quantitative/qualitative ML/TF risk data per draft RTS on risk assessments (Article 40(2) of Directive (EU) 2024/1640); non-selected entities focus on AMLA templates for 2025 risks/mitigation.
- Specialised professionals: Continue preparations for CSSF-specific questionnaire, confirming any shifts post-delay.
- Internal review: Assess ML/TF risk profiles, mitigation measures, and reporting readiness in light of EU alignment; update compliance calendars to reflect simplification.
- No immediate submissions: Stand down from original 2 March/15 April deadlines unless individually notified otherwise.
Key Dates
Potential ad-hoc CSSF questionnaires for essential data points
Original launch for specialised professionals' CSSF questionnaire
Original launch date for AMLA calibration exercise data collection via eDesk (now potentially adjusted or paused per delay circular)
Publication of delay circular, superseding prior timelines; further modalities to be communicated
Original reporting deadline to CSSF for AMLA calibration exercise data
Compliance Impact
Urgency: Medium. The delay alleviates short-term pressure by postponing submissions and reducing dual reporting, enabling resource reallocation to higher-priority AMLA efforts amid EU harmonization. It matters for maintaining a risk-based approach (RBA) under FATF standards, avoiding overburden from overlapping exercises, and preparing for the new EU AML/CFT methodology—non-compliance risks supervisory scrutiny, but the simplification lowers immediate enforcement exposure.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankAsset ManagerAll Firms
Situation as at 28 February 2026
BankAsset ManagerBroker Dealer
Situation as at 31 January 2026
Asset ManagerBankWealth Manager
Situation as at 31 January 2026
BankAsset ManagerWealth Manager
Situation as at 31 January 2026
Asset ManagerBankWealth Manager
No description available.
BankWealth ManagerFintech
No description available.
BankWealth ManagerFintech
No description available.
BankWealth ManagerAll Firms
implementing Regulation (EU) No 208/2014 concerning restrictive measures directed against certain persons, entities and bodies in view of the situation in Ukraine
BankWealth ManagerAsset Manager
implementing Article 8a of Regulation (EC) No 765/2006 concerning restrictive measures in view of the situation in Belarus and the involvement of Belarus in the Russian aggression against Ukraine
BankWealth ManagerAsset Manager
Situation from February 2025 to February 2026
BankAsset ManagerBroker Dealer
Situation from February 2025 to February 2026
BankAsset ManagerBroker Dealer
Situation from February 2025 to February 2026
Asset ManagerBankBroker Dealer
No description available.
BankAsset ManagerWealth Manager
Situation as of 31 December 2025
Asset ManagerBank
Update March 2026
Asset ManagerBankWealth Manager
No description available.
BankWealth ManagerAsset Manager
amending Directives 2006/43/EC, 2013/34/EU, (EU) 2022/2464 and (EU) 2024/1760 as regards certain corporate sustainability reporting requirements and certain corporate sustainability due diligence requirements
Asset ManagerBankWealth Manager
No description available.
BankWealth Manager
No description available.
BankWealth ManagerAll Firms
No description available.
BankWealth ManagerFintech
No description available.
Asset ManagerBank
No description available.
Asset ManagerWealth ManagerBank
implementing Regulation (EU) 2024/1485 concerning restrictive measures in view of the situation in Russia
BankWealth ManagerAsset Manager
Conditions relating to the organisation of the credit institution issuing covered bonds
Bank
Conditions specific to each covered bond issue programme
Bank
No description available.
BankWealth Manager
Exigences applicables au réviseur d’entreprises agréé spécial auprès des établissements de crédit émetteurs de lettres de gage
Circular CSSF 26/907, published on February 18, 2026, establishes requirements for **approved special statutory auditors (réviseurs d'entreprises agréés spéciaux) serving credit institutions that issue mortgage bonds (lettres de gage)**. This circular formalizes the governance and audit standards applicable to a specialized auditor role within Luxembourg's credit institution framework, ensuring enhanced oversight of entities engaged in mortgage bond issuance.
What Changed
- The search results provided do not contain the full text of Circular CSSF 26/907, as it is available only in French and the PDF content was not included in the available materials.
- Statutory auditor qualifications and requirements for the specialized role of approving auditors (réviseurs agréés spéciaux) overseeing credit institutions that issue mortgage bonds
- Governance standards for auditors in this specialized capacity
- Audit and oversight responsibilities specific to mortgage bond issuance activities
The circular aligns with broader Luxembourg regulatory modernization efforts evident in concurrent CSSF guidance,...
Suggested Considerations
- *Obtain and review the full French text of Circular CSSF 26/907 from the CSSF website
- *Assess current auditor qualifications against the new requirements for approved special statutory auditors
- *Update audit engagement letters and terms to reflect any new standards or responsibilities
- *Document compliance with the circular's requirements in governance and audit files
- *Communicate with appointed auditors to ensure alignment with the new framework
Key Dates
- Circular CSSF 26/907 published
in available search results; firms should consult the full French text for any transition periods or effective dates
Compliance Impact
Urgency: HIGH
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Bank
No description available.
BankWealth ManagerFintech
No description available.
BankAsset ManagerWealth Manager
No description available.
BankAsset ManagerWealth Manager
1) high-risk jurisdictions on which enhanced due diligence and, where appropriate, counter-measures are imposed2) jurisdictions under increased monitoring of the FATFVersion of 17 February 2026
The Annex of Circular CSSF 22/822 (Version of 17 February 2026) is Luxembourg's Commission de Surveillance du Secteur Financier's implementation guidance on FATF (Financial Action Task Force) designations of high-risk jurisdictions requiring enhanced due diligence and counter-measures, as well as jurisdictions under increased monitoring. This document is critical for Luxembourg-regulated financial institutions because it operationalizes international AML/CFT standards into binding compliance obligations, directly impacting customer acceptance, transaction monitoring, and correspondent banking relationships.
What Changed
The current version (17 February 2026) represents the most recent update to the CSSF's FATF-aligned jurisdiction risk framework. Based on the available search results, the document establishes two primary regulatory categories:
High-Risk Jurisdictions (Category 1): Jurisdictions designated by FATF as having strategic deficiencies in their AML/CFT regimes, requiring enhanced due diligence and, where appropriate, counter-measures.
Suggested Considerations
- *For High-Risk Jurisdictions:
- Apply enhanced due diligence and monitoring measures to business relationships and transactions with designated jurisdictions
- Increase the frequency and timing of transaction controls
- Select transaction patterns requiring further examination and obtain detailed information on transaction purposes
- Maintain enhanced mechanisms for reporting suspicious activity to the FIU
Key Dates
- Original Circular CSSF 22/822 issued
- Previous version superseded
- Current version effective (Annex of Circular CSSF 22/822)
- CSSF annual AML/CFT questionnaire launch (related compliance reporting deadline)
Compliance Impact
Urgency: CRITICAL
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankAsset ManagerPayment Provider No description available.
BankPayment Provider
For which the CSSF is the relevant competent authority under Regulation (EU) No 236/2012 of the European Parliament and of the Council of 14 March 2012 on short selling and certain aspects of credit default swaps
BankBroker DealerAsset Manager
Version 1
Asset ManagerBank
Version 1
Asset ManagerBank
Version 3.1
Asset ManagerBank
No description available.
BankWealth ManagerFintech
Situation as at 31 December 2025
Asset ManagerBankWealth Manager
Situation as at 31 December 2025
Asset ManagerBankWealth Manager
Situation as at 31 December 2025
BankAsset ManagerWealth Manager
No description available.
BankFintechCrypto Exchange
AML/CFT standardised data collection taking place in 2026
The CSSF Circular Letter 2026-02-12 announces a standardized data collection exercise on AML/CFT for supervised entities, scheduled for 2026, aimed at enhancing regulatory oversight of money laundering and terrorist financing risks. This matters because it signals intensified CSSF scrutiny on AML/CFT compliance, requiring firms to prepare structured data submissions that could inform future supervisory actions, risk assessments, and enforcement. As part of broader CSSF AML/CFT initiatives, non-compliance risks fines or heightened inspections.
What Changed
- - Introduction of standardized AML/CFT data collection: CSSF mandates uniform reporting formats for collecting data on AML/CFT risks, controls, and practices across supervised sectors, building on...
- Alignment with ongoing AML/CFT enhancements: Complements recent governance-focused circulars (e.g., Circular 26/906 on central administration and risk management for payment/e-money institutions) by...
- No explicit new obligations beyond preparation for data submission, but implies deeper integration of tax-related AML indicators and sub-sector risk updates, as seen in related CSSF activities.
Suggested Considerations
- Assess and document AML/CFT data readiness: Inventory current risk assessments, transaction monitoring logs, KYC processes, SAR filings, and third-party oversight records in standardized formats; map to proportionality factors (e.g., transaction volumes, outsourcing).
- Update governance and controls: Ensure compliance functions have independence, direct board reporting, and audit coverage of AML/CFT; test ICT resilience for monitoring continuity.
- Conduct internal reviews: Perform gap analyses against Circular 26/906 (e.g., fund safeguarding, escalation protocols) and recent conference topics (e.g., terrorist financing, tax indicators); remediate deficiencies with board-approved plans.
- Prepare for submission: Designate resources for data compilation; cooperate fully with CSSF/FIU requests, including transfer-of-funds information under EU 2015/847.
- Engage auditors: Leverage approved auditors for validation of AML/CFT effectiveness ahead of collection.
Key Dates
AML/CFT standardised data collection exercise; Firms must submit required data during this period; preparation recommended immediately given today's date (12 February 2026)
Issuance of related Circular 26/906; Establishes governance baselines (e.g., compliance independence, risk proportionality) informing data collection expectations
CSSF AML/CFT Conference for Specialised PFS; Provided updates on sub-sector risks, terrorist financing reviews, and FIU insights relevant to data preparation
Conference materials published; Available for download to guide compliance alignment
Compliance Impact
Urgency: High – With data collection in 2026 underway today (12 February 2026), firms face immediate preparation needs amid recent enforcement (e.g., EUR 102,000 fine on depositary for AML-related gaps) and conferences signaling sub-sector focus. This elevates AML/CFT as a supervisory priority, potentially triggering on-site inspections, fines, or remediation orders for inadequate data/risks; proactive alignment prevents escalation in a risk-based regime.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankPayment ProviderAll Firms
Submission of the register of information at individual or consolidated level to the CSSF (excluding entities under the direct supervision of the ECB)
BankAsset ManagerWealth Manager
Guidance allowing financial entities to identify the National Competent Authority to which their register of information has to be submitted.
This CSSF guidance document, published on 11 February 2026, provides detailed explanations and resolution steps for error messages encountered during the submission of the DORA Register of Information (RoI) via the eDesk portal, specifically for the 2026 submission cycle. It matters because it enables Luxembourg financial entities to ensure compliant submissions amid enhanced validation checks on more data fields, avoiding re-submission delays and supporting timely transmission to the ESAs by CSSF deadlines. Non-compliance risks supervisory scrutiny under DORA's ICT risk management framework.
What Changed
- - Enhanced validation checks for the 2026 RoI submission: Applies ESA-defined checks (last updated April 2025) to more data fields to improve data quality, compared to prior cycles.
- Specific error resolutions detailed, including requirements for LEI code communication to CSSF beforehand, correct reference date ('2025-12-31') in file naming, plain-CSV files in predefined .zip...
- Mandatory inclusion of all tables (even empty) in FilingIndicators.csv set to 'true', with matching identification codes across parent-child records.
- Builds on prior CSSF guides, emphasizing eDesk role "DORA Reporting" assignment and ESAs' technical standards.
No new regulatory requirements under DORA itself; this refines technical submission...
Suggested Considerations
- Assign "DORA Reporting" role in eDesk to dedicated employee(s) per user guide.
- Communicate LEI code to CSSF line supervisor prior to first submission to enable upload.
- Prepare RoI in plain-CSV files within .zip following ESAs' folder structure/file naming (reference date '2025-12-31'); include all tables in FilingIndicators.csv (even empty, set to 'true').
- Test submissions against listed error codes (e.g., ICTO007 for LEI, identification mismatches); resolve per guidance sections (e.g., Sections 3.2.2, 5.1.2, 6).
- Consult ESAs' EBA resources (data point model, validation rules, FAQs) and CSSF guides (e.g., submission guide, guidance tables).
Key Dates
- CSSF re-submission deadline post-validation for 2025; analogous for 2026 if errors detected
- ESAs' second-round validation for 2025; expect similar for 2026 with potential re-submissions
- Initial 2025 submission window via eDesk (for context; 2026 window likely similar, pending confirmation)
- Reference date for 2026 RoI submission (all contractual arrangements up to this date)
- Publication date of this error guidance (last updated 10/02/2026)
Compliance Impact
Urgency: High - Published today (11 February 2026), this equips firms for imminent 2026 RoI submissions (reference date 31 December 2025), with stricter validations on expanded fields risking rejections/re-submissions. Matters for operational resilience compliance under DORA Article 28, as accurate RoI supports supervisory oversight of ICT third-party risks; delays could trigger CSSF/ESA follow-up or fines. Firms with prior 2025 issues (e.g., portal extensions to May 2025) must prioritize to avoid recurrence.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankFintechPayment Provider
Situation as at 31 January 2026
BankAsset ManagerBroker Dealer
Situation from January 2025 to January 2026
BankAsset ManagerBroker Dealer
Situation from January 2025 to January 2026
BankAsset ManagerBroker Dealer
Situation from January 2025 to January 2026
Asset ManagerBankBroker Dealer
CVE-2026-1281 & CVE-2026-1340
BankWealth ManagerFintech
Situation as at 31 December 2025
BankAsset ManagerWealth Manager
Situation as at 31 December 2025
BankWealth ManagerAsset Manager
Situation as at 31 December 2025
BankAsset ManagerWealth Manager
Situation as at 31 December 2025
BankAsset ManagerWealth Manager
Situation as at 31 December 2025
BankAsset ManagerWealth Manager
No description available.
BankWealth ManagerFintech
Press release 26/03
BankWealth Manager
No description available.
BankWealth ManagerFintech No description available.
BankWealth ManagerAsset Manager
implementing Regulation (EU) 2024/2642 concerning restrictive measures in view of Russia’s destabilising activities
BankAsset ManagerWealth Manager
The CSSF informs the market regarding the outcomes of the SFTR Data Quality indicators review performed in 2025
BankBroker DealerPayment Provider
implementing Regulation (EU) 2024/2642 concerning restrictive measures in view of Russia’s destabilising activities
BankWealth ManagerAsset Manager
No description available.
BankWealth ManagerAsset Manager
No description available.
BankWealth ManagerAsset Manager
No description available.
BankAsset ManagerWealth Manager
No description available.
BankWealth ManagerAsset Manager
No description available.
BankBroker Dealer
No description available.
BankWealth ManagerAsset Manager
No description available.
BankWealth ManagerAsset Manager
No description available.
BankWealth ManagerAsset Manager
Press release 26/02
BankBroker Dealer
No description available.
BankAsset ManagerWealth Manager
No description available.
BankWealth ManagerPayment Provider
No description available.
BankAsset ManagerWealth Manager
No description available.
BankBroker DealerAsset Manager
Application of the Guidelines of the European Banking Authority on the management of environmental, social and governance (ESG) risks (EBA/GL/2025/01)
Circular CSSF 26/905 mandates the application of EBA Guidelines (EBA/GL/2025/01) on managing **ESG risks** for Luxembourg-supervised institutions, requiring integration of environmental, social, and governance risk identification, measurement, management, and monitoring into internal processes. This aligns with CRD amendments (Articles 74, 76, 87a) and emphasizes proportionality to institutions' business models, with plans including timelines, targets, and milestones toward EU climate goals like net-zero by 2050. It matters for compliance as it embeds ESG into prudential supervision, potentially impacting capital, risk frameworks, and supervisory reviews.
What Changed
- - Institutions must establish proportionate strategies, policies, processes, and systems for ESG risk management, covering short-, medium-, and long-term horizons, including transition and physical...
- Develop plans per Article 76(2) CRD with specific timelines, intermediate quantifiable targets, and milestones to address ESG financial risks, consistent with EU objectives (e.g., 55% GHG reduction...
- Incorporate ESG into internal governance, risk appetite, and supervisory review processes (SREP), with scenario analysis requirements (to be detailed in future EBA guidelines).
- Applies minimum standards and methodologies for ESG risk identification, measurement, monitoring, and impact assessment on institutions' exposures.
- No requirement for full alignment with specific sustainability trajectories, but plans must consider transition risks and institutions' ESG product offerings, loan policies, and targets.
Suggested Considerations
- Map and integrate ESG risks into governance, risk management frameworks, and business strategies, proportionate to scale/risk exposure.
- Develop and document ESG risk management plans with quantifiable targets, milestones, timelines, and scenario analyses (broad requirements now; detailed later).
- Conduct assessments of ESG risks in portfolios, including sustainability products, transition finance, and loan origination policies, for SREP submission.
- Embed in internal processes per Articles 74, 76, 87a CRD: identify/measure ESG risks (minimum standards), monitor over time horizons, and report to CSSF.
- Review and update existing policies/systems for compliance by applicable dates; prepare for CSSF supervisory evaluation of plan robustness.
Key Dates
- Circular published by CSSF
- Application date for Less Significant Institutions (other than SNCIs)
- Application date for SNCIs (dependent on CRD transposition)
Compliance Impact
Urgency: High - With application starting 1 April 2026 (just over 2 months from publication), firms face immediate pressure to gap-analyze current ESG frameworks against EBA standards, especially for SREP integration and long-term risk planning. Non-compliance risks supervisory scrutiny, capital add-ons, or enforcement, as ESG is now a core prudential pillar amid EU sustainability push; smaller institutions get a head-start but must act swiftly given proportionality demands.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankAll Firms
2026 update
BankWealth ManagerFamily Office
No description available.
BankAsset ManagerWealth Manager
No description available.
BankAsset ManagerWealth Manager
Communiqué
The CSSF's January 2026 enforcement report documents the results of its 2025 examination campaign on 2024 financial and non-financial disclosures by issuers under Luxembourg's Transparency Law. This publication is critical for compliance professionals because it reveals systematic compliance gaps across financial reporting (IFRS), sustainability reporting (ESRS), and Alternative Performance Measures (APMs), with 27% of enforcement decisions resulting in injunctions for non-compliance.
What Changed
- The regulatory landscape has evolved significantly with the introduction of new sustainability reporting requirements:
- ESRS Implementation (First Year): 2024 marked the first full reporting year under the European Sustainability Reporting Standards (ESRS), with the CSSF conducting a fact-finding exercise to assess...
- Taxonomy Disclosures Amendment: On 4 July 2025, the European Commission adopted a Delegated Act amending the Taxonomy Disclosures as part of the Omnibus package, affecting Article 8 of the Taxonomy...
- Double Materiality Assessment (DMA) Focus: The CSSF emphasized the importance of issuers not only disclosing the results of their DMA but also explaining the process itself, including granular...
Suggested Considerations
- *Financial Information (IFRS):
- *Enhanced Note Disclosures: Provide sufficient disaggregation and additional information in financial statement notes for material amounts and variances, particularly where information is not presented on the face of primary statements. The CSSF emphasizes compliance with paragraph 112(c) of IAS 1.
- *Cash Flow Statement Presentation: Ensure cash flows are presented on a gross basis (not net), exclude non-cash transactions, and disclose restricted cash balances with accompanying management commentary as required by paragraph 48 of IAS 7.
- *Segment Reporting Completeness: Clearly disclose all income and expense items in segment reporting, even when not separately provided to or reviewed by the Chief Operating Decision Maker (CODM), if they are included in reported segment results.
- *Going Concern Assessment: Maintain high transparency regarding accounting policies and judgments applied when classifying going concern assumptions.
Key Dates
- CSSF published enforcement priorities press release for FY2024 reporting
- European Commission adopted Delegated Act amending Taxonomy Disclosures (Omnibus package)
- CSSF published full results of fact-finding exercise on ESRS reporting
- CSSF published enforcement results report (current publication)
Compliance Impact
Urgency: HIGH
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
All Firms
relating to the fees to be levied by the Commission de Surveillance du Secteur Financier
BankAsset ManagerWealth Manager
amending Council Regulation (EU) No 833/2014 concerning restrictive measures in view of Russia’s actions destabilising the situation in Ukraine
BankWealth ManagerAsset Manager
No description available.
BankWealth ManagerAsset Manager
No description available.
Bank
No description available.
This CSSF publication, dated January 12, 2026, identifies the specific population (likely a firm or individual) subject to an enforcement action, such as an administrative sanction, as part of the CSSF's transparency in supervisory measures. It matters because it signals CSSF's active enforcement priorities, potentially in areas like AML or reporting failures, enabling firms to assess similar risks in their operations and strengthen compliance to avoid parallel actions. Published amid rising focus on financial crime typologies like sexual extortion, it underscores the regulator's commitment to public accountability.
What Changed
No new regulatory changes or requirements are introduced in this publication, as it is an enforcement notice rather than a circular or guideline. It serves as a disclosure of an ongoing or concluded enforcement case, aligning with CSSF's practice of publishing sanction details to deter non-compliance and inform the market, without altering existing rules.
Suggested Considerations
- For the named population: Comply with any sanction terms (e.g., pay fines, implement remediation plans, or cease certain activities), and report to CSSF as required; appeal if applicable under Luxembourg administrative law.
- Update internal policies, train staff on enforcement precedents, and ensure robust reporting under Circular CSSF 19/726 or Transparency Law obligations.
Compliance Impact
Urgency: High – Immediate relevance for the named party facing direct consequences; medium-to-high for peers due to CSSF's pattern of public enforcements signaling heightened scrutiny on financial crime, especially amid rising OCSE/FSEC cases noted in recent CSSF guidance. It matters as it could preview broader supervisory sweeps, impacting reputation, operations, and costs if similar vulnerabilities exist.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankPayment ProviderAll Firms
amending Delegated Regulation (EU) 2016/1675 to add Russia to the list of high-risk third countries with strategic deficiencies
BankAsset ManagerWealth Manager
No description available.
Asset ManagerWealth ManagerBank Extract from the CSSF Newsletter No 300 – January 2026
BankAsset ManagerWealth Manager
Survey on the amount of covered deposits held on 31 December 2025
Circular CSSF-CPDI 25/49 is a **mandatory quarterly reporting requirement** for Luxembourg credit institutions and postal financial service providers to submit data on covered deposits as of December 31, 2025. This survey directly feeds into the Single Resolution Fund's annual target level calculation and the Luxembourg deposit guarantee scheme's contribution assessments, making it essential for regulatory compliance and fund management.
What Changed
The circular explicitly states that no substantive changes have been made to the survey process compared to previous quarters. The only modifications are administrative: the reference date (December 31, 2025) and the submission deadline (January 30, 2026). The specifications for data collection, definitions of covered and eligible deposits, and reporting methodologies remain unchanged from prior circulars, particularly Circular CSSF-CPDI 16/02 as amended by Circular CSSF-CPDI 23/35.
Suggested Considerations
- *Calculate covered deposits as defined in Article 163 of the 2015 law, including balance and accrued interest (even if not yet due)
- *Report eligible deposits after applying exclusions under Article 172 of the 2015 law, including exclusions for financial institutions and life insurance products
- *Distinguish deposit types by reporting:
- Total eligible deposits (field 201)
- Eligible deposits in omnibus accounts, fiduciary accounts, trusts, sub-accounts, and segregated accounts (field 0226)
Key Dates
- Circular publication date
- Reference date for the survey
- Deadline for transmitting average covered deposits data to the Single Resolution Board
Compliance Impact
Urgency: HIGH
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankPayment Provider
Update of Circular CSSF 24/850 on the practical rules concerning the descriptive report and the self-assessment questionnaire to be submitted on an annual basis by support PFS, as well as the engagement of the réviseurs d’entreprises agréés (approved statutory auditors) of support PFS and practical rules concerning the management letter and the separate report to be drawn up on an annual basis.
Circular CSSF 25/903 updates Circular CSSF 24/850, refining practical rules for support Professional of the Financial Sector (support PFS) in Luxembourg regarding their annual descriptive report, self-assessment questionnaire, and the roles of approved statutory auditors (réviseurs d’entreprises agréés). It specifies requirements for auditors' engagement, management letters, and separate annual reports. This matters for support PFS as it enhances supervisory oversight, ensures consistent reporting quality, and strengthens internal controls, directly impacting compliance and audit processes amid CSSF's focus on robust PFS supervision.
What Changed
- - Updates to Descriptive Report and Self-Assessment Questionnaire: Refines content, format, and submission requirements for support PFS's annual submissions, emphasizing more detailed disclosures on...
- Auditor Engagement Rules: Introduces specific practical guidelines for approved statutory auditors, including mandatory scope of work, independence confirmations, and standardized procedures for...
- Management Letter and Separate Report: Establishes detailed rules for auditors to issue an annual management letter (addressing findings, recommendations, and remediation) and a separate report for...
- Enhanced Documentation and Evidence: Requires support PFS and auditors to provide verifiable evidence (e.g., checklists, testing samples) supporting self-assessments, with stricter CSSF validation...
Suggested Considerations
- *Review and Update Processes: Support PFS must map current reporting against new templates in CSSF 25/903 and revise internal procedures for descriptive reports and self-assessments.
- *Engage/Confirm Auditors: Select or confirm approved statutory auditors compliant with new engagement rules; execute updated engagement letters incorporating circular requirements by Q4 2025.
- *Implement Templates and Testing: Adopt CSSF-provided templates for reports, management letters, and separate reports; conduct sample-based testing of controls as specified.
- *Training and Governance: Train compliance/audit teams on changes; ensure board approval of self-assessments and auditor findings.
- *Submit on Time: Prepare and file all documents by 30 April deadlines, retaining evidence for CSSF inspections.
Key Dates
Submission Deadline; Support PFS must submit descriptive report, self-assessment questionnaire, management letter, and separate auditor report to CSSF by 30 April following the financial year-end (first applicable: 30 April 2026 for FY 2025)
Preparation Milestone; Auditors must be engaged and initial scoping completed by year-end 2025 for FY 2025 compliance
Effective Date; Applies to annual reporting cycles starting for financial year 2025 onwards
Compliance Impact
Urgency: High. This is high urgency for support PFS due to the impending 30 April 2026 deadline for FY 2025 submissions, with non-compliance risking supervisory fines, license reviews, or reputational damage under CSSF's PFS enforcement regime. It matters as it tightens audit accountability, potentially increasing costs (e.g., auditor fees) while reducing reporting errors—critical for smaller support entities with limited resources.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
All FirmsFintechPayment Provider
Repeal of Circular CSSF 19/731 regarding the documents to be submitted on an annual basis by credit institutions.
Circular CSSF 25/902 repeals Circular CSSF 19/731 (as amended by Circular CSSF 19/710), which previously detailed annual document submission requirements for credit institutions, shifting to a dynamic list published on the CSSF website. This matters because it streamlines compliance by centralizing and updating requirements online, reducing reliance on static circulars while maintaining submission obligations. Credit institutions must transition to the new process to avoid disruptions in prudential reporting.
What Changed
- - Repeal of prior circulars: Circular CSSF 19/731 and its amendment via Circular CSSF 19/710 are fully repealed, eliminating the fixed list of annual submission documents.
- Shift to website-based guidance: The updated list of required documents, affected entity categories, electronic submission channels, and deadlines is now published on the CSSF’s Prudential reporting...
- Ongoing obligations: The requirement to submit documents annually remains unchanged; only the reference source and potential content updates via the website are modified.
Suggested Considerations
- Review the CSSF Prudential reporting webpage (https://www.cssf.lu/en/prudential-reporting-credit-institutions/) and summary table (https://www.cssf.lu/en/Document/summary-of-documents-to-be-submitted-on-an-annual-basis/) to identify current document lists, categories, channels, and deadlines.
- Update internal reporting processes, templates, and workflows to reference the website instead of the repealed circular.
- Confirm ongoing annual submissions via specified electronic channels; test interactive table for applicability to the institution's profile.
- Archive references to Circular CSSF 19/731 in policies and train staff on the change.
Key Dates
- Original issuance of repealed Circular CSSF 19/731 (archived on 23 December 2025)
- Publication and effective date of Circular CSSF 25/902, repealing Circular CSSF 19/731; transition to website-based list begins
Compliance Impact
Urgency: Medium – The repeal does not alter core submission obligations but requires procedural updates to avoid non-compliance with potentially evolving lists under CRR3 alignments. It matters for operational efficiency, as failure to adapt could lead to missed deadlines or incorrect submissions, especially with website updates tied to EU regulations like Regulation (EU) 2024/1623 (CRR3, applicable from 1 January 2025). Institutions should prioritize review before the next annual cycle to ensure seamless reporting.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Bank
Practical rules concerning the descriptive report and the self-assessment questionnaire to be submitted on an annual basis by support PFS.Engagement of the réviseurs d’entreprises agréés (approved statutory auditors) of support PFS and practical rules concerning the management letter and the separate report to be drawn up on an annual basis.
Circular CSSF 24/850, as amended by Circular CSSF 25/903, establishes practical rules for support Professional of the Financial Sector (support PFS) in Luxembourg to submit annual descriptive reports and self-assessment questionnaires, while also defining the roles of approved statutory auditors (réviseurs d’entreprises agréés) in issuing management letters and separate reports. This guidance standardizes supervisory reporting and audit processes to enhance oversight of support PFS, which provide essential back-office services to authorized PFS. It matters because non-compliance risks supervisory sanctions, reputational damage, and operational disruptions for entities reliant on support PFS structures.
What Changed
- - Standardized Reporting Templates: Introduces detailed formats and content requirements for the annual descriptive report and self-assessment questionnaire, covering governance, risk management,...
- Auditor Engagement Rules: Mandates approved statutory auditors to perform specific procedures, issue a management letter highlighting control weaknesses, and prepare a separate report confirming...
- Amendments via CSSF 25/903: Updates clarify submission procedures, expand self-assessment criteria (e.g., adding cybersecurity and outsourcing risk questions), and refine auditor independence...
- Frequency and Scope: Annual submissions required without exceptions; scope limited to support PFS (not primary PFS), emphasizing substance over form in service descriptions.
Suggested Considerations
- Annual Reporting Cycle:
1. By year-end, conduct internal self-assessment using the prescribed questionnaire template (available via CSSF portal).
- February to review submissions, test controls, and issue management letter (flagging deficiencies) plus separate compliance report.
- Governance Updates: Review and update internal policies on risk assessment, auditor selection, and remediation of management letter findings; ensure board oversight of submissions.
- Auditor Coordination: Verify auditor qualifications per CSSF register; implement any remediation plans from prior-year management letters before next cycle.
- Record-Keeping: Maintain 5-year audit trail of all supporting documentation for CSSF inspections.
Key Dates
- Effective date of original Circular CSSF 24/850
- Effective date of amendments in Circular CSSF 25/903, applicable to 2025 reporting cycle onwards
- Deadline for submission of descriptive report, self-assessment questionnaire, management letter, and separate auditor report to CSSF (first applicable for FY 2024 reporting due 31 March 2025)
- Support PFS must engage auditors and provide necessary data to enable timely report preparation
Compliance Impact
Urgency: High – This is a recurring annual obligation with a firm 31 March deadline, where delays trigger automatic CSSF notifications and potential fines (up to €250,000 per Law 1993). It matters for support PFS as it intensifies scrutiny on operational resilience in a post-SFI (2021) landscape, where CSSF prioritizes substance in delegated functions; failure risks de-authorization or client outflows. Early implementation of templates and auditor pipelines is essential to avoid first-year pitfalls.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankWealth ManagerAll Firms
Press release 25/20
Bank
Application of the Guidelines of the European Banking Authority on Acquisition, Development, and Construction (ADC) exposures to residential property under Article 126a of Regulation (EU) 575/2013 (EBA/GL/2025/03)
Circular CSSF 25/899 mandates the application of EBA Guidelines (EBA/GL/2025/03) on Acquisition, Development, and Construction (ADC) exposures to residential property under Article 126a of Regulation (EU) 575/2013 (CRR), specifying conditions for reducing the risk weight from 150% to 100% on qualifying exposures. This matters for Luxembourg credit institutions as it directly impacts capital requirements for real estate lending, promoting safer lending practices while aligning with Basel III standards via CRR3 implementation.
What Changed
- - Introduces precise definitions for CRR Article 126a(2) terms, enabling 100% risk weight (instead of 150%) for ADC exposures to residential property if conditions are met: at least 50% of total...
- Mandates "sound standards for lending and credit monitoring" alongside these criteria.
- Accounts for social housing/public not-for-profit lending specificities, with tailored rules for regulated entities serving long-term tenant housing.
- Replaces prior "particularly high-risk exposure" class with dedicated ADC class under CRR3.
Suggested Considerations
- Review and classify ADC exposures against EBA-defined criteria (e.g., contract thresholds, equity levels, monitoring standards) to determine eligibility for 100% risk weight.
- Update internal policies, risk assessment models, and credit approval processes to incorporate "sound lending standards" and EBA specifications, including social housing carve-outs.
- Recalculate capital requirements under standardized credit risk approach; report changes via CRR disclosures.
- Maintain documentation proving compliance (e.g., deposit proofs, equity valuations) for supervisory audits by CSSF.
- Institutions must "make every effort to comply" per EBA Regulation Article 16(3).
Key Dates
- EBA Guidelines (EBA/GL/2025/03) apply across EU (two months post-publication on 27 June 2025 in all official languages)
- CSSF Circular 25/899 published, requiring immediate compliance preparation for Luxembourg firms
Compliance Impact
Urgency: High – Firms with significant ADC portfolios face immediate capital relief opportunities (50bp risk weight reduction) but risk non-compliance penalties if processes aren't updated by early 2026, especially post-CRR3 rollout; misclassification could inflate capital needs amid ongoing Basel implementation.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Bank
Press release 25/18
BankFintechAll Firms
Fonds de garantie des dépôts Luxembourg (FGDL) – Method for calculating the ex-ante contributions pursuant to Article 182 of the Law of 18 December 2015 on the failure of credit institutions and of certain investment firms
Circular CSSF-CPDI 25/48, published on 13 November 2025, updates the methodology for calculating ex-ante contributions to the Fonds de garantie des dépôts Luxembourg (FGDL), Luxembourg's deposit guarantee scheme, by aligning risk adjustments with EBA Guidelines and introducing a zero floor for certain calculation components. This matters for Luxembourg credit institutions as it refines risk-sensitive contributions to meet DGSD target levels for two compartments (0.8% and an additional 0.8% of covered deposits), ensuring financial stability while promoting supervisory convergence across the EU.
What Changed
- - Risk Adjustment Updates (Annex 2): Increases weight of 'Return on assets' (ROA) risk indicator from 7.5% to 10%; decreases 'Deposit-size Risk' from 15% to 12.5%; adjusts sliding scale bounds for...
- Formula Component Floor (Annex 1): Introduces a zero floor for Component 1 (max(0, A_{j,k})), preventing negative values from offsetting Component 2; retains both components but ensures no...
- Contribution Calculation Refinements: Annual contributions per compartment use updated formulas (e.g., formula (1) with max operator); contribution rates are uniform per compartment but...
- Repeals Prior Circulars: Repeals CSSF-CPDI 23/34 (4 June 2020) and CSSF-CPDI 20/21 (as amended), replacing the 2020-reviewed method.
Suggested Considerations
- Review and update internal systems/models for contribution calculations to incorporate new risk weights, bounds (Table 2), zero floor for Component 1, and revised formulas in Annexes 1-2.
- Validate data reporting for risk indicators (e.g., ROA, LCR, NSFR, NPL) against adjusted sliding scales; ensure alignment with EBA Guidelines for simplicity and resource efficiency.
- Prepare for FGDL invoices reflecting compartment-specific rates; monitor covered deposits for surveys (e.g., per Circular 25/49).
- Conduct gap analysis against repealed circulars (20/21, 23/34); update policies for mergers, deposit changes, and gap fillings (Γ_λ).
Compliance Impact
Urgency: High – Institutions must promptly recalibrate risk models ahead of 2026 contributions to avoid miscalculations, penalties, or underfunding risks, as this directly impacts prudential contributions amid ongoing DGSD buildup to 2026; non-alignment with EBA could trigger CSSF scrutiny. Failure to adapt may increase costs for riskier profiles, emphasizing the shift to greater risk sensitivity.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Bank
Fonds de garantie des dépôts Luxembourg (FGDL) – Method for calculating the ex-ante contributions pursuant to Article 182 of the Law of 18 December 2015 on the failure of credit institutions and of certain investment firms
Circular CSSF-CPDI 25/48 updates the methodology for calculating ex-ante annual contributions to the Fonds de garantie des dépôts Luxembourg (FGDL), Luxembourg's deposit guarantee scheme, specifically for the target levels in Articles 179 and 180 of the Law of 18 December 2015 on the failure of credit institutions and certain investment firms. This matters because it introduces a risk-adjusted contribution model aligned with EBA Guidelines, shifting from purely deposit-based calculations to ones incorporating institution-specific risk factors, potentially increasing contributions for higher-risk banks while promoting stability in the scheme's funding.
What Changed
- - Modified Contribution Formula: Replaces prior methods (e.g., from Circulars CSSF-CPDI 16/01, 17/06, 20/21) with a new structure: Component 1 proportional to covered deposits growth (Γ_{j,k}) at...
- Risk Adjustment Introduction: ARW is calculated using a weighted score (minimum 75% on EBA core categories, plus 12.5% deposit-size risk and 10% others) from indicators like leverage ratio (bounds...
- Merger/Transfer Handling: For failed/merged institutions, contributions are redistributed proportionally to receiving institutions' deposit increases, capped by their own required amounts; no...
- Floor and Alignment: Introduces max(0, A_{j,k}) floor to avoid negative components; ensures EBA compliance, simplicity, and risk sensitivity.
Suggested Considerations
- Data Reporting: Submit accurate covered deposits data (e.g., as of 31 Dec 2025 per Circular 25/49) and risk indicator metrics (leverage, LCR, NSFR, NPL, etc.) to FGDL/CSSF for ARW calculation; prepare for annual surveys like CPDI 25/45 (31 Mar 2025 snapshot).
- Internal Calculations: Model contributions using new formula C_{j,k} = ARW_{j,k} * max(0, max(A_{j,k}) + T_j D_{j-2,k}) * μ; forecast based on historical deposits (D_{j-2,k}) and growth.
- Risk Monitoring: Track and improve key metrics (e.g., reduce NPLs below 3%, maintain LCR/NSFR >100%) to minimize ARW >1; review merger impacts.
- Payment: Pay FGDL invoices reflecting uniform rates per compartment, risk-adjusted amounts.
- Systems Update: Adapt finance/compliance systems for new inputs; align with EBA risk guidelines (https://www.eba.europa.eu/regulation-and-policy/single-rulebook/interactive-single-rulebook/1085).
Key Dates
- Circular publication date by CSSF
- Reference date for covered deposits survey (per related Circular CSSF-CPDI 25/49)
- First application year for new methodology (contributions for year j=2026 based on j-1=2025 data; invoices issued by FGDL)
Compliance Impact
Urgency: High - Affects 2026 contributions directly, requiring immediate data readiness and modeling by Q1 2026; non-compliance risks penalties, inaccurate payments, or higher costs from poor risk scores. Matters for capital planning as riskier profiles face uplifts, emphasizing proactive risk management amid EU harmonization.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Bank
Update of Circular CSSF 22/821 on the Long Form Report, as amended by Circulars CSSF 23/845 and CSSF 24/865
Circular CSSF 25/897 updates Circular CSSF 22/821 on the Long Form Report (LFR) for credit institutions, further aligning the self-assessment questionnaire (SAQ) with current supervisory priorities such as ML/FT risks and organizational aspects. This matters because it refines reporting to reduce redundancies, enhance transparency in REA assessments, and reflect evolving prudential focuses since prior amendments via Circulars CSSF 23/845 and 24/865, ensuring institutions' reports better support CSSF oversight.
What Changed
- - Introduces new modules in the revised SAQ to align with supervisory points of focus, building on prior expansions (e.g., credit/counterparty risk, liquidity risk, climate-related risks from CSSF...
- Emphasizes REA's independent assessment in the AML/CFT report, requiring exhaustive, transparent evaluations of ML/FT risks across institutions, branches, majority-owned subsidiaries abroad, and tied...
- REA must verify and amend descriptive elements provided by management for the Financial Instruments and Funds Report and AML/CFT report, including quantitative metrics like pending file ratios.
- Confirms the three-part LFR framework: institution-completed SAQ, REA's client assets protection report (per Article 7 of Grand-ducal Regulation of 30 May 2018), and REA's AML/CFT report; no Agreed...
- Enhances REA responsibilities for collateral arrangements and client fund protections under relevant laws.
Suggested Considerations
- Complete and submit revised SAQ annually, incorporating new modules on supervisory focuses like ML/FT risks and providing detailed data to REA.
- Authorized management: Supply accurate descriptive information to REA for reports, covering client protections, collateral, and AML/CFT procedures across group entities.
- REA: Independently assess and report on ML/FT risks and client assets with transparency, quantitative details, and verified management inputs; avoid imprecise language.
- Ensure AML/CFT report details methodologies (e.g., sampling techniques) and covers branches/subsidiaries/tied agents.
- Review prior LFR submissions against this update to align with suppressed redundancies and new emphases.
Key Dates
- Issuance date of Circular CSSF 25/897
end; - Annual submission deadline for SAQ to CSSF (unchanged from prior circulars)
end; - Submission deadline for REA Reports (Financial Instruments and Funds Report; AML/CFT Report)
end; - Aligned submission for REA management letter (per amendments in CSSF 23/845 to Circular 22/826)
Compliance Impact
Urgency: High - Institutions face immediate refinement needs for 2025 year-end reporting (e.g., SAQ due ~Q1 2026), with stricter REA scrutiny on AML/CFT transparency risking supervisory findings or enforcement if vague assessments persist; aligns with ongoing CSSF push for risk-focused oversight amid regulatory evolution.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Bank
Long Form ReportPractical rules concerning the self-assessment questionnaire to be submitted by institutionsMission and related reports of the statutory auditors (réviseurs d’entreprises agréés)
**Circular CSSF 22/821** (as amended) fundamentally restructures how Luxembourg credit institutions report to the Commission de Surveillance du Secteur Financier (CSSF) by replacing the traditional Long Form Report with a digital **self-assessment questionnaire (SAQ)**, complemented by auditor-prepared reports. This shift represents a significant operational change that requires institutions to directly participate in prudential self-assessment while maintaining robust external audit oversight, making it essential for compliance and operational teams to understand new submission requirements and digital workflows.
What Changed
- The circular introduces a three-component reporting framework that fundamentally alters the compliance landscape:
- Self-Assessment Questionnaire (SAQ): A digital, annually-completed questionnaire that institutions must prepare directly, covering domains within CSSF and ECB prudential supervision competence
- Agreed Upon Procedures (AUP) Reports: Reports prepared by approved statutory auditors (réviseurs d'entreprises agréés) on specific compliance areas
- Separate REA Report on Financial Instruments Protection: A dedicated auditor assessment on safeguarding of client financial instruments
Scope of SAQ Coverage: The questionnaire addresses prudential...
Suggested Considerations
- *For Credit Institutions:
- *Establish SAQ Governance: Designate authorized management responsible for reviewing and electronically signing the SAQ before submission; ensure accuracy and true-and-fair representation of information
- *Data Preparation: Align SAQ responses with prudential reporting figures (FINREP/COREP/LAREX) under IFRS as of financial year closure
- *Digital System Access: Obtain access credentials to the CSSF digital solution and familiarize compliance teams with the platform interface and submission workflow
- *Module Completion: Complete all applicable SAQ modules as configured in the CSSF digital solution; note that module applicability and exemptions are institution-specific and recorded directly in the system
Key Dates
- Circular CSSF 22/821 issued
- Initial publication date (updated 15 November 2023)
- Circular enters into application
- SAQ becomes accessible through CSSF digital solution
- Deadline for SAQ submission to CSSF
Compliance Impact
Urgency: HIGH
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Bank
Provisions relating to credit institutions and investment firms of EU origin established in Luxembourg by way of branches or exercising activities in Luxembourg by way of free provision of services
Circular CSSF 07/325, as amended by Circulars CSSF 21/765, CSSF 22/827, and most recently CSSF 25/898, establishes supervisory requirements for EU credit institutions and investment firms operating in Luxembourg via branches or free provision of services (FOPS). It matters for compliance professionals as it defines CSSF's host authority role, notification obligations, reporting, and enforcement powers, ensuring alignment with CRD and MiFID II while adapting to evolving EU rules.
What Changed
- - CSSF 21/765: Updated provisions following amendments to CSSF Regulation No 12-02, refining notification and operational requirements for branches and FOPS.
- CSSF 22/827: Further amendments to align with CRD and MiFID II changes, including enhanced notifications for programme alterations (e.g., one-month prior written notice for changes in operations,...
- CSSF 25/898: Latest update (noted in CSSF Newsletter No 298, November 2025), incorporating recent legal/regulatory developments, such as refined reporting via eDesk portal, AML/CFT compliance...
Suggested Considerations
- Notifications: Submit initial branch/FOPS notification to home authority (including operational programme); notify changes (e.g., services, locations) at least one month in advance to both home authority and CSSF.
- Reporting: Complete and sign SAQ (accurate, concise, true/fair view) via eDesk within six months post-year-end; provide REA-appraised AML/CFT and conduct reports, detailing branch procedures/controls.
- Supervision cooperation: Facilitate home/CSSF on-site inspections (with professional secrecy guarantees); ensure branch compliance with Luxembourg laws (e.g., LFS Article 46(2)).
- Ongoing: Maintain branch infrastructure, update for legal changes, and align with CSSF user guides for eDesk authentication.
Key Dates
- Notify CSSF and home authority in writing of programme changes (e.g., operations, services, additional places of business) per CRD Article 36(3) and MiFID II Article 35(10)
- Home state authority communicates notification file to CSSF for branch/FOPS establishment
end; - Submit electronically signed SAQ (via eDesk), annual AML/CFT and conduct of business report (per Circular CSSF 19/731, to be repealed by CSSF 25/902), reviewed by REA
Compliance Impact
Urgency: Medium - Matters due to recurring annual reporting (e.g., SAQ, AML/CFT within six months post-year-end) and prior notifications for changes, with CSSF enforcement powers (e.g., measures under LFS Article 46(2)) for non-compliance. Recent CSSF 25/898 update (Nov 2025) requires immediate review of processes for digital submissions, but no retroactive changes or hard deadlines post-2025; grandfathering for pre-existing setups reduces immediate pressure.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankBroker Dealer
Update of Circular CSSF 07/325 on Provisions relating to credit institutions and investment firms of EU origin established in Luxembourg by way of branches or exercising activities in Luxembourg by way of free provision of services, as amended by Circulars CSSF 21/765 and CSSF 22/827
Circular CSSF 25/898 updates Luxembourg's supervisory framework for EU-origin credit institutions and investment firms operating in Luxembourg through branches or free provision of services. This amendment enhances the self-assessment questionnaire (SAQ) used by the CSSF to align supervisory oversight with current regulatory priorities, particularly adding UCI administration as a new thematic module. The update reflects the CSSF's evolving supervisory focus and requires affected institutions to demonstrate compliance with expanded assessment criteria.
What Changed
- The circular introduces the following material modifications to Circular CSSF 07/325:
New Supervisory Module
- UCI administration has been added as a thematic module to the self-assessment questionnaire, reflecting increased regulatory attention to fund administration practices.
Enhanced Self-Assessment...
- Existing modules have been updated to better align with supervisory objectives and current regulatory priorities.
- The revised SAQ now captures a broader range of supervisory points of focus relevant to branch operations and cross-border service provision.
Scope Clarification
- The circular applies to credit institutions whose head office is in another EU Member State and to investment firms of EU origin established in Luxembourg by way of branches or exercising activities...
Suggested Considerations
- *Update Self-Assessment Processes
- Revise internal SAQ completion procedures to address the new UCI administration module
- Ensure all thematic modules reflect current supervisory expectations
- *Assess UCI Administration Compliance
- If the institution provides or is involved in UCI administration services, conduct a detailed assessment of compliance with CSSF expectations
Key Dates
- Circular CSSF 25/898 published by the CSSF
- Related modernization framework (Circular CSSF 25/901) entered into force for Part II UCIs, SIFs, and SICARs
- Institutions should align their SAQ responses and compliance documentation with the updated framework immediately upon publication
Compliance Impact
Urgency: HIGH
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankBroker DealerAsset Manager
Survey on the amount of covered deposits held on 30 September 2025
Circular CSSF-CPDI 25/47 mandates a regular survey by Luxembourg credit institutions on the amount of covered deposits as of **30 September 2025**, focusing on eligible and covered deposits under the Law of 18 December 2015 on deposit guarantee schemes. It matters because it ensures accurate reporting to the Conseil de protection des déposants et des investisseurs (CPDI) for FGDL (Fonds de garantie des dépôts Luxembourg) compliance, with detailed field-by-field instructions for complex accounts like omnibus and trusts.
What Changed
This circular updates prior guidance (notably CSSF-CPDI 16/02 as amended by CSSF-CPDI 23/35) by specifying the survey reference date of 30 September 2025 and providing granular reporting fields for eligible deposits (e.g., exclusions for financial institution-like structures and life insurance products), covered deposits capped at €100,000 per person, and breakdowns by natural/legal persons, including shares in omnibus accounts, fiduciaries, trusts, sub-accounts, and segregated accounts.
Suggested Considerations
- Collect data on total deposits (field 0100), apply exclusions per Article 172 (field 0201), calculate covered deposits up to €100,000 limit (field 0300), and break down by natural/legal persons, balance thresholds, and special accounts (fields 0210-0330).
- For omnibus/trust accounts, obtain and report shares of identifiable entitled persons, apportion by legal status of holder, and ensure fields like 0226 and 0255 reconcile.
- Designated management reviews/approves data; transmit accurately to CSSF/CPDI, respecting prior circulars (e.g., 16/02, 23/35).
- Exclude non-creditor accounts or those assimilated to financial institutions/life insurance.
Key Dates
- Reference date for snapshot of deposits, eligible deposits, and covered deposits
- Publication date of the circular by CSSF
Compliance Impact
Urgency: Medium – Past reference date (30 September 2025) as of January 2026 means non-reporting firms risk immediate FGDL non-compliance, fines, or supervisory action from CSSF, but this is a routine quarterly survey (see related Circular CSSF-CPDI 25/49 for December 2025). Matters for prudential reporting accuracy, especially amid EU deposit guarantee harmonization.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Bank
Press release 25/15
Bank
Single Resolution Fund – Information request by the Single Resolution Board for the calculation of the 2026 contribution according to Articles 4 and 14 of Commission Delegated Regulation (EU) 2015/63
Circular CSSF-CODERES 25/21, issued by the CSSF on 29 September 2025, mandates Luxembourg credit institutions to submit specific data via XBRL-formatted Data Reporting Forms (DRFs) to enable the Single Resolution Board (SRB) to calculate 2026 ex-ante contributions to the Single Resolution Fund (SRF) under Articles 4 and 14 of Commission Delegated Regulation (EU) 2015/63. This matters because non-compliance risks SRB using estimates, applying the highest risk multiplier, or penalties, ensuring the financial sector funds resolution costs without taxpayer burden.
What Changed
- - Introduces data collection for 2026 SRF contributions, conditional on SRB verifying SRF funds fall below 1% of covered deposits in the Banking Union by early 2026.
- Mandates XBRL submission of DRFs (except restatements up to 2022 in Excel); provides templates in Annexes 3a, 4, 5 (User Guide), and 7a/7b for additional assurances.
- Additional assurance requirements (e.g., auditor reports or Agreed-Upon Procedures - AUP) apply conditionally to ECB-supervised institutions unless under lump-sum payment; restatements require AUP by...
- References SRB's 2026 kick-off letter (Annex 1) and ECB-supervised list (Annex 6 as of 24 September 2025).
Suggested Considerations
- Download and complete DRF using Annexes (e.g., Annex 3a PDF, Annex 5 User Guide v1.4); submit in XBRL format by deadline.
- For ECB-supervised institutions: Provide additional assurances per Annex 7a/7b if SRB proceeds with collections; prepare restatement AUPs with auditor exceptions where applicable.
- Align internal systems with CSSF templates early; validate data to avoid SRB assumptions under Article 17(1) DR.
- Review Annex 1 (SRB kick-off letter), Annex 4 (2026 Guidance), and Annex 6 (ECB list).
Key Dates
- SRB decision deadline on whether to calculate/collect 2026 SRF contributions based on DRFs (triggers full additional assurance application)
- ECB-supervised institutions submit AUP or auditor reports on restatements to CSSF resolution department
- All institutions submit completed DRF in XBRL to CSSF; late/incomplete submissions lead to SRB estimates or highest risk multiplier
Compliance Impact
Urgency: High - The 16 January 2026 deadline is imminent (today is 25 January 2026), risking immediate SRB penalties like estimates or maximum risk multipliers if submissions are missed/inaccurate; affects capital planning as contributions directly impact prudential positions.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Bank
Adoption of the EBA Guidelines on internal policies, procedures and controls to ensure the implementation of Union and national restrictive measures (sanctions)
Circular CSSF 25/896 adopts the EBA Guidelines EBA/GL/2024/14 and EBA/GL/2024/15, mandating Luxembourg financial institutions to establish robust internal policies, procedures, and controls for complying with EU and national restrictive measures (sanctions). This matters because it sets binding EU-wide standards to prevent sanctions violations and circumvention, with absolute obligations for immediate asset freezing and reporting, amid escalating geopolitical tensions.
What Changed
- - Institutions must develop, implement, and maintain up-to-date policies, procedures, and controls for identifying, investigating, and applying restrictive measures without delay, including risk...
- Management body responsibilities expanded: approve sanctions compliance strategy, oversee implementation, conduct at least annual assessments of exposure and controls, ensure remedial actions, and...
- Screening and monitoring requirements: Maintain updated sanctions lists with immediate integration of changes; screen customer base, transactions, and datasets accurately; enable immediate...
- Training and testing: Deliver regular, documented role-specific training; perform ongoing system testing for screening calibration, list accuracy, transaction monitoring effectiveness, and reporting.
- Proportionality applies based on institution's size, activities, and exposure; PSPs and CASPs explicitly addressed with tailored controls.
Suggested Considerations
- Conduct annual exposure assessments to sanctions risks and circumvention; update policies accordingly.
- Appoint senior management/board-level responsibility for approving and overseeing sanctions strategy, including annual reviews and deficiency reporting.
- Implement reliable screening systems for customers, transactions, and lists; define screenable datasets; test systems regularly for effectiveness (e.g., immediate freezing, accurate hits).
- Provide documented training to relevant staff on sanctions, institutional exposure, and internal processes.
- Establish processes for immediate action on matches: suspend transfers, freeze assets, report to Ministry of Finance/CSSF/FIU without delay; maintain whitelists only under strict conditions.
Compliance Impact
Urgency: High – With less than 12 months until the 30 December 2025 deadline (as of January 2026), firms face binding requirements for absolute compliance, including personal accountability for management bodies; non-compliance risks enforcement by CSSF, reputational damage, and fines amid frequent EU sanctions updates (e.g., Regulations 2025/1469, 2025/1476). This elevates sanctions from operational task to strategic board priority.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankPayment ProviderCrypto Exchange
Press release 25/13
Bank
Press release 25/10
Bank
Press release 25/08
BankAsset ManagerWealth Manager No description available.
BankAsset ManagerWealth Manager
Press release 25/05
BankAsset ManagerWealth Manager
Press release 25/04
BankFintechAll Firms
Press release 25/03
BankWealth Manager
No description available.
BankWealth Manager
No description available.
BankWealth ManagerAsset Manager
No description available.
All Firms