Payments & E-Money regulatory updates from Luxembourg.
We track 65 Payments & E-Money updates from Luxembourg regulators, published by CSSF. The archive covers 31 news items, 16 guidance notes and 10 warnings. Most recent update: September 2026. Coverage runs from 2025 to 2026.
This is a policy statement from CSSF announcing a modernized prudential reporting framework with binding obligations for payment institutions, electronic money institutions, and crypto-asset service providers.
on the applicability of the Digital Operational Resililience Act (DORA) to third-country branches in Luxembourg
AI Analysis
CSSF Circular 26/915, published on 27 August 2026 and effective immediately, confirms that DORA applies to Luxembourg branches of third-country undertakings where the head-office undertaking would qualify as a DORA entity under Article 2(1)(a) to (t) in its home country. The circular reallocates these branches from the legacy ICT-risk and ICT-outsourcing frameworks into the DORA-related regimes, while retaining CSSF Circular 22/806 Part I for non-ICT outsourcing; this reverses the pre-update market treatment identified in earlier consultancy commentary, which had generally classified Luxembourg third-country branches as outside DORA.
Key dates
2025-01-17
DORA became applicable to financial entities within the CSSF supervisory perimeter.
2025-12-17
The European Commission confirmed through DORA Q&A DORA102-3097 that DORA applies to qualifying third-country branches in an EU country.
2026-08-27
Circular CSSF 26/915 was published and its amendments took effect immediately.
2027-02-27 Deadline
The six-month transition period for PSPs not otherwise subject to DORA under Circular CSSF 25/893 is expected to end; the DORA incident-reporting framework then applies to those PSPs and Circular CSSF 21/787 is repealed for them.
2027-03-31 Deadline
Latest date in the annual CSSF register-of-information submission window for arrangements contracted during 2026, subject to the applicable CSSF collection process.
Suggested considerations
Firms should map each Luxembourg third-country branch against the DORA Article 2(1)(a) to (t) categories as the undertaking would be classified in the third country, documenting the legal-entity and regulatory-status analysis.
Compliance teams may wish to update the branch's regulatory inventory, DORA applicability assessment, governance documentation and responsibility matrices to reflect immediate inclusion where the qualifying test is met.
Affected branches should review ICT third-party-service contracts, the register of information and planned arrangements supporting critical or important functions, including whether CSSF notification was made at least three months before implementation or one month where the specified Luxembourg support-PFS exception applies.
Firms should distinguish ICT outsourcing from other outsourcing: ICT outsourcing should be managed under the DORA framework and Circular CSSF 25/882, while non-ICT outsourcing remains subject to Circular CSSF 22/806 Part I.
Incident-response teams should test the CSSF eDesk Portal and S3 API reporting channels and maintain a contingency process for notifying ictrisksupervision@cssf.lu by the applicable deadline if technical failure prevents use of the primary channel.
Firms should confirm that major ICT incidents are reported individually and that outsourced reporting arrangements preserve the firm's responsibility for timing, completeness and notification content.
Affected branches should assess whether they are microenterprises under DORA Article 3(60), since Circular CSSF 25/892 excludes microenterprises from its aggregated-cost estimation framework, except for trading venues, central counterparties, trade repositories and central securities depositories.
Where the branch is an EU branch rather than a third-country branch, firms should verify the home-Member-State allocation rules because the CSSF circulars generally exclude EU branches from the relevant Luxembourg reporting chapters.
What changed
The circular implements the European Commission's 17 December 2025 DORA Q&A position and includes qualifying third-country branches in the scope of Circulars CSSF 25/882 on ICT third-party services, 25/892 on aggregated annual costs and losses from major ICT incidents, and 25/893 on major ICT-related incident and significant cyber-threat reporting.
Compliance impact
The impact is high for affected third-country branches because the clarification brings them into DORA governance, ICT third-party-service, register-of-information, incident-reporting and loss-estimation regimes immediately, while removing reliance on Circulars 20/750 and 22/806 Part II for ICT matters. The CSSF states that missed notification deadlines or non-compliant arrangements may be treated as not notified and may lead to supervisory or administrative measures; outsourcing reporting does not transfer responsibility away from the branch.
CSSF Circular 26/915, published on 27 August 2026, confirms with immediate effect that qualifying Luxembourg branches of third-country financial institutions fall within DORA where their non-EU head office would qualify as an entity listed in Article 2(1)(a) to (t) of Regulation (EU) 2022/2554. The update reallocates these branches from legacy Luxembourg ICT and outsourcing frameworks into DORA-specific requirements, while adding an email fallback for major ICT-incident and significant cyber-threat reporting when the CSSF’s primary channels are technically unavailable.
Key dates
2025-01-17
DORA began applying to in-scope financial entities supervised by the CSSF.
2025-12-17
The European Commission confirmed through DORA Q&A 102 that DORA applies to qualifying third-country branches in an EU Member State.
2026-06-30 Deadline
CSSF’s extended best-efforts deadline for the first register-of-information submission by third-country branches of credit institutions headquartered in a third country.
2026-08-27
Circular CSSF 26/915 was published and took effect immediately; the listed CSSF circulars were amended to include or remove qualifying third-country branches as applicable.
2027-03-31 Deadline
Target date identified by CSSF for the required-quality register-of-information submission by third-country branches of credit institutions headquartered in a third country.
2027-01-11
Relevant CRD VI third-country-branch provisions are scheduled to take effect, subject to national transposition and applicable transitional rules.
Suggested considerations
Firms should map each Luxembourg third-country branch against the counterfactual test in Circular 26/915: whether the head-office undertaking would qualify under Article 2(1)(a) to (t) of DORA if established in the relevant third country.
Affected branches should update their regulatory-perimeter inventories, governance documents, ICT-risk policies, outsourcing inventories, incident-classification procedures and DORA control testing to reflect immediate inclusion in the DORA-specific CSSF circulars.
Compliance teams may wish to separate non-ICT outsourcing, which remains subject to Part I of Circular CSSF 22/806, from ICT outsourcing, which is governed by DORA and Circular CSSF 25/882 rather than the legacy Part II framework.
Affected entities should validate their register-of-information process under DORA and Circular CSSF 25/882, including branch-level data, ICT third-party contracts, intra-group arrangements and submission ownership. The 30 June 2026 best-efforts deadline for third-country branches of credit institutions has passed, and firms should prepare for the 31 March 2027 collection and any CSSF remediation requests.
Incident-response teams should test access to the CSSF eDesk procedure and S3 API and document an escalation process for emailing ictrisksupervision@cssf.lu when technical impossibility prevents electronic submission.
Firms should assess whether they qualify for the microenterprise exclusion in Circular CSSF 25/892; the exclusion applies to entities employing fewer than 10 persons with annual turnover and/or annual balance-sheet total not exceeding EUR 2 million, subject to the DORA definition and exclusions for specified market infrastructures.
Third-country banking groups should coordinate DORA implementation with the CRD VI third-country-branch analysis, including the 11 January 2027 effective date for relevant CRD VI provisions, rather than assuming that the two regimes have identical scope or timing.
What changed
Qualifying third-country branches are added to the scope of Circulars CSSF 25/882, 25/892 and 25/893, covering DORA ICT third-party-service information and reporting, estimation of aggregated annual costs and losses from major ICT-related incidents under Article 11(11) of DORA and the Joint ESA Guidelines JC/GL/2024/34, and reporting of major ICT-related incidents and significant cyber threats.
Compliance impact
The impact is high for affected Luxembourg third-country branches because Circular 26/915 makes DORA-specific ICT third-party, incident-reporting and operational-resilience obligations immediately applicable and removes reliance on legacy ICT frameworks. Non-compliance may create supervisory findings, missed DORA reporting deadlines and deficiencies in ICT third-party oversight or incident governance; the CSSF does not describe a new penalty schedule in this publication.
amending Circular CSSF 20/750 on requirements regarding information and communication technology (ICT) and security risk management
AI Analysis
Circular CSSF 25/881, published on 2025-04-09, realigned Circular CSSF 20/750 with DORA by removing DORA financial entities from its scope and retaining the framework for entities outside DORA. Circular CSSF 26/915, published on 2026-08-27, further removes qualifying Luxembourg third-country branches from Circular 20/750 and confirms that DORA applies to them where their non-EU head office would fall within DORA Article 2(1)(a) to (t).
Key dates
2025-01-17
DORA became applicable to financial entities within its scope, subject to the specific DORA provisions and technical standards applicable to each entity.
2025-04-09
Circular CSSF 25/881 was published and took effect, removing DORA financial entities from Circular 20/750 and retaining 20/750 for entities outside DORA; PSP-specific provisions were reorganised under Circular 25/880.
2026-06-30 Deadline
CSSF extended the first Register of Information submission for Luxembourg branches of third-country credit institutions to this date on a best-efforts basis; the CSSF indicated that the required level of quality should be achieved for the 2027 submission.
2026-08-27
Circular CSSF 26/915 was published, confirming the DORA treatment of qualifying third-country branches and removing them from the full scope of Circular 20/750 and related overlapping circular provisions.
2027-03-31 Deadline
Target date identified by the CSSF for the required-quality Register of Information submission by Luxembourg branches of third-country credit institutions.
Suggested considerations
Firms should classify each Luxembourg entity and branch against DORA Article 2 and the amended scope of Circular 20/750, including an assessment of whether a third-country head office would qualify under DORA Article 2(1)(a) to (t).
Compliance teams may wish to determine whether the entity should operate under DORA rather than 20/750, and document the rationale, legal-entity perimeter and treatment of any Luxembourg branch.
Firms remaining within Circular 20/750 should consider reviewing their ICT and security-risk-management framework, governance approvals, risk assessments, incident processes, business-continuity arrangements and control testing against the continuing requirements.
Payment service providers should consider replacing references to the PSP provisions formerly contained in Circular 20/750 with the applicable requirements in Circular CSSF 25/880 and EBA/GL/2025/02.
Third-country branches treated as DORA entities should consider validating their DORA governance, ICT-risk framework, incident-reporting arrangements, ICT contractual inventory and Register of Information processes, taking account of CSSF reporting communications.
Firms should update policies, regulatory inventories, outsourcing and ICT-third-party registers, training materials and regulatory mapping to distinguish DORA obligations from the residual Circular 20/750 obligations.
Compliance teams may wish to retain evidence of the scope assessment and implementation date, because the 2025 amendment was effective immediately and the 2026 amendment changes the treatment of a previously identified 20/750 population.
What changed
Circular 25/881 provides that DORA financial entities supervised by the CSSF no longer fall within Circular 20/750; for entities covered by 20/750 but outside DORA, the circular continues to apply in full. Payment-service-provider-specific ICT and security-risk provisions were removed from 20/750 and regrouped in Circular CSSF 25/880, reflecting the revised EBA Guidelines on ICT and security risk management for payment service providers, including EBA/GL/2025/02.
Compliance impact
The principal impact is perimeter and framework migration rather than a wholly new ICT-control standard: entities in DORA must avoid relying on residual 20/750 requirements where DORA governs, while non-DORA entities retain substantive 20/750 obligations. The CSSF and market commentary indicate that misclassification may create gaps in DORA governance, ICT-third-party documentation, incident reporting and Register of Information submissions, with potential supervisory findings and related remediation or enforcement consequences.
amending Circular CSSF 22/806 on outsourcing arrangements
AI Analysis
Circular CSSF 25/883, effective 9 April 2025 and updated by Circular CSSF 26/915 on 27 August 2026, realigns Circular CSSF 22/806 with DORA and extends the DORA perimeter to qualifying Luxembourg branches of third-country financial entities. For DORA entities, ICT outsourcing is principally governed by Regulation (EU) 2022/2554 and related CSSF requirements, while Circular 22/806 remains relevant for business-process outsourcing and entities outside the DORA scope.
Key dates
2025-01-17
DORA began applying to financial entities within its scope, subject to the relevant provisions and transitional arrangements.
2025-04-09
Circular CSSF 25/883 was published and applied with immediate effect, amending Circular CSSF 22/806 and introducing the DORA-based division between ICT and business-process outsourcing.
2025-12-17
The European Commission confirmed through a DORA Q&A that DORA applies to qualifying third-country branches in an EU Member State.
2026-06-30 Deadline
CSSF-extended submission date for the 2026 DORA register of information for third-country branches of credit institutions headquartered in a third country; entities were invited to submit on a best-efforts basis.
2026-08-27
Circular CSSF 26/915 was published and applied with immediate effect, confirming the DORA treatment of qualifying Luxembourg third-country branches and updating Circular CSSF 22/806 accordingly.
2027-03-31 Deadline
Target CSSF submission deadline for the DORA register of information for affected third-country branches following the initial 2026 collection.
Suggested considerations
Firms should classify each outsourcing arrangement as ICT or non-ICT and determine whether the entity and arrangement fall within DORA, Circular 22/806, or both regimes in their respective areas of application.
DORA entities should consider moving ICT arrangements from their Circular 22/806 outsourcing inventory and controls into the DORA ICT third-party register, while retaining Circular 22/806 controls for business-process outsourcing.
Non-DORA entities should consider continuing to apply the full Circular 22/806 framework to ICT and business-process outsourcing, including due diligence, governance, critical-or-important assessments, monitoring, sub-outsourcing and exit planning.
Third-country branches should assess whether their head office would qualify under Article 2(1)(a) to (t) of DORA and, if so, align ICT governance, contractual arrangements, registers and reporting with DORA rather than relying solely on Circular 22/806.
Compliance teams may wish to review cloud contracts and avoid carrying forward legacy EEA governing-law or hosting clauses where DORA now provides the applicable framework, while preserving enforceable audit, access, cooperation, security, business-continuity and exit rights.
Firms should use the revised CSSF notification form for new critical or important ICT outsourcing arrangements and preserve evidence supporting the three-month notification period, or the one-month period for arrangements involving a support PSF.
Firms should consider validating that existing ICT outsourcing notifications remain complete under the applicable DORA register-of-information requirements, even though Circular 25/883 does not require their re-submission.
Affected third-country branches should consider submitting and maintaining the DORA register of information through the CSSF process, with the 2027 collection requiring data quality suitable for the 31 March 2027 submission deadline.
What changed
From 9 April 2025, DORA entities generally no longer apply the ICT-outsourcing provisions of Circular CSSF 22/806 to ICT arrangements; those arrangements are governed by DORA, including its ICT third-party risk-management, contractual, register-of-information and oversight requirements, together with Circular CSSF 25/882. Circular 22/806 continues to apply to business-process outsourcing by DORA entities, and continues to apply in full to non-DORA entities, including their ICT outsourcing. Chapter 16 management companies remain subject to Circular 22/806 for ICT outsourcing.
Compliance impact
The impact is material for outsourcing inventories, contractual templates, ICT governance, regulatory registers and third-country branch assessments, although Circular 25/883 does not require previously notified ICT outsourcing arrangements to be re-notified. Misclassification may result in applying the wrong control framework, incomplete DORA registers or failures to meet CSSF notification and oversight expectations; the CSSF and market commentary indicate that DORA entities should treat Circular 22/806 primarily as the business-process outsourcing framework, while non-DORA entities retain...
Application of the Joint ESA Guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents under Regulation (EU) 2022/2554 (JC 2024 34)
AI Analysis
CSSF Circular 25/892 applies the ESAs’ Joint Guidelines JC/GL/2024/34 for estimating aggregated annual costs and losses from major ICT-related incidents under Article 11(10) and (11) of DORA. Circular 26/915, issued on 2026-08-27, immediately extends that framework to qualifying Luxembourg branches of third-country undertakings, while leaving the underlying methodology unchanged.
Key dates
2025-05-19
The Joint ESA Guidelines JC/GL/2024/34 apply at ESA level.
2025-05-31
Circular CSSF 25/892 applies to its original in-scope Luxembourg entities, excluding DORA microenterprises.
2026-08-27
Circular CSSF 26/915 is issued and applies with immediate effect, bringing qualifying Luxembourg third-country branches into the scope of Circular CSSF 25/892.
Suggested considerations
Compliance teams may wish to determine whether each Luxembourg entity or third-country branch falls within the amended scope, including whether a third-country head-office undertaking would qualify under DORA Article 2(1)(a) to (t).
Firms should consider documenting their microenterprise analysis against DORA Article 3(60), including the fewer-than-10-employees and EUR 2 million annual turnover and/or balance-sheet-total thresholds, while noting that the DORA definition excludes trading venues, central counterparties, trade repositories and central securities depositories from the microenterprise exemption.
Firms should consider maintaining an incident-level ledger linking major ICT-related incidents, DORA final-report reference codes, gross costs, losses, provisions, recoveries and subsequent adjustments.
Finance, operational-risk and ICT-incident teams may wish to agree whether the firm will use a completed calendar year or completed accounting year as its reference basis and establish controls to apply that basis consistently.
Firms should consider reconciling estimates to financial-statement or supervisory-reporting data where available, while retaining documented estimation methodology and assumptions where accurate data is unavailable.
Firms should consider tracking quantifiable financial impacts from prior-year major incidents because those impacts may need to be included in a later reference year without reopening the original final incident report.
Third-country branches may wish to confirm reporting ownership and data availability with their head office, because the amended CSSF scope is at branch level but the required cost and loss information may arise across the undertaking.
Compliance teams may wish to monitor CSSF communications for a specific request, reporting channel and submission deadline; the circular itself establishes an upon-request obligation rather than a fixed automatic annual filing deadline.
What changed
From 2025-05-31, in-scope Luxembourg financial entities other than DORA microenterprises must be able, upon CSSF request, to provide an entity-level estimate of aggregated annual costs and losses arising from major ICT-related incidents. The estimate must use the ESA common template and identify each relevant incident by the same reference code used in its DORA final incident report.
Compliance impact
The requirement is operationally significant because firms must preserve incident-level financial-impact data, distinguish gross costs from recoveries and retain historical linkage to DORA final incident reports, even though submission occurs only upon competent-authority request. The ESAs’ approach does not impose a minimum cost threshold: every incident classified as major must be covered, irrespective of the classification trigger, increasing the importance of coordination between ICT, operational risk, finance and regulatory reporting teams.
on reporting of major ICT-related incidents and significant cyber threats under the Digital Operational Resilience Act (DORA)
AI Analysis
CSSF Circular 25/893 establishes the Luxembourg reporting process for major ICT-related incidents and significant cyber threats under Regulation (EU) 2022/2554 (DORA), replacing the former CSSF 24/847 framework for DORA entities and extending the same framework to payment service providers outside DORA. The 27 August 2026 update, issued through Circular CSSF 26/915 (although the page title refers to 25/915), expressly brings qualifying Luxembourg branches of third-country financial entities within the DORA-related scope, increasing the population required to maintain rapid, event-specific reporting capability.
Key dates
2025-01-17
DORA provisions became applicable to financial entities in scope and supervised by the CSSF.
2025-05-28
Circular CSSF 25/893 was published and established the Luxembourg DORA incident and significant cyber-threat reporting modalities.
2025-11-28 Deadline
End of the six-month transition period granted to payment service providers outside DORA for implementation of the Circular 25/893 framework.
2026-08-27
Circular CSSF 26/915 was published and the 25/893 page was updated to clarify DORA applicability to qualifying third-country branches in Luxembourg; the amendment applies immediately.
Suggested considerations
Compliance teams may wish to confirm the entity-by-entity scope analysis against DORA Article 2, including whether a Luxembourg third-country branch is covered following the 27 August 2026 clarification.
Firms should consider documenting incident-classification criteria and decision records against Commission Delegated Regulation (EU) 2024/1772, including the quantitative thresholds for clients, transactions, duration, geographical spread, data loss, economic impact and reputational impact.
Firms should consider testing an escalation timetable that supports classification, initial notification within four hours and no later than 24 hours after awareness, the 72-hour intermediate report and the one-month final report.
PSPs outside DORA may wish to update policies so that all ICT-related incidents, rather than only payment-service incidents, are assessed under the DORA framework and to verify that the six-month transition requirements were completed by 28 November 2025.
Firms should consider ensuring that eDesk access, authorised users, templates, internal approvals and S3 API connectivity are operational before an incident occurs.
Incident-response procedures may wish to prohibit aggregation of separate major incidents where the CSSF reporting process requires event-specific submissions and should assign ownership even where reporting support is outsourced.
Third-country branches may wish to align their Luxembourg reporting playbooks, head-office escalation arrangements and local CSSF contacts with the immediate-effect scope clarification.
Firms should consider retaining evidence of classification, notification times, report versions, management approvals and communications with ICT third parties to demonstrate timely compliance.
What changed
DORA financial entities supervised by the CSSF must classify ICT-related incidents using the criteria and thresholds in Commission Delegated Regulation (EU) 2024/1772 and report each major ICT-related incident using the DORA reporting templates and procedures. Reporting is phased: an initial notification is generally due within four hours after classification as major and in any event no later than 24 hours after the entity becomes aware of the incident; an intermediate report is generally due within 72 hours after the initial notification; and a final report is generally due within one month...
Compliance impact
The framework creates time-critical supervisory reporting obligations with potentially material consequences for firms unable to classify or notify major incidents accurately and promptly; the regulated entity remains accountable even when submission is delegated. The 2026 clarification is particularly significant for third-country branches because it removes scope uncertainty and requires immediate integration of local branch incident reporting into DORA governance and response arrangements.
CSSF Circular 22/806 has been updated to reflect Circular 25/883 and the 27 August 2026 Circular 26/915. The framework now distinguishes between ICT outsourcing governed primarily by DORA and business-process outsourcing governed by Circular 22/806, while confirming that DORA applies to qualifying Luxembourg branches of third-country financial entities; this materially affects outsourcing inventories, contractual controls, registers of information and supervisory reporting.
Key dates
2022-04-22
Circular CSSF 22/806 was published and replaced or amended specified earlier CSSF and IML outsourcing, governance and control circulars.
2022-06-30
Circular CSSF 22/806 became applicable according to the CSSF implementation framework.
2025-01-17
DORA Regulation (EU) 2022/2554 became applicable to in-scope financial entities, creating the primary EU framework for ICT third-party risk management.
2025-04-09
Circular CSSF 25/883 was published; the amended Circular 22/806 applies to outsourcing arrangements entered into, reviewed or amended on or after this date.
2025-12-17
The European Commission confirmed that DORA also applies to qualifying third-country branches in an EU Member State where the third-country head-office entity would fall within DORA Article 2(1)(a) to (t).
2026-08-27
Circular CSSF 26/915 was published and the CSSF webpage consolidated the amended version of Circular 22/806, confirming the DORA treatment of qualifying Luxembourg third-country branches.
Suggested considerations
Firms should map each outsourcing and third-party technology arrangement against the applicable regime: DORA, Circular 22/806 business-process outsourcing requirements, or the full Circular 22/806 framework for non-DORA entities.
Compliance teams may wish to review whether Luxembourg third-country branches have a head-office activity that corresponds to a DORA Article 2(1)(a) to (t) financial entity and document the resulting DORA scope assessment.
Firms should update outsourcing policies, risk assessments, governance approvals, materiality or criticality assessments, due-diligence files, monitoring controls and exit strategies to reflect the split between DORA ICT third-party risk management and Circular 22/806 business-process outsourcing.
Firms should maintain or update the DORA register of information for ICT third-party arrangements where DORA applies, and reconcile it with the outsourcing inventory and CSSF notification processes.
Firms should review legacy cloud contracts and remove reliance on the repealed Circular 22/806 EEA-law and EEA-resilience clauses where DORA is the applicable ICT third-party regime, while retaining contract terms needed to satisfy DORA and any applicable national requirements.
Non-DORA entities should consider whether their existing contracts still address Circular 22/806 requirements for access and audit rights, sub-outsourcing, confidentiality, data location, business continuity, termination and exit.
Management companies authorised solely under Article 125-1 should consider retaining the full Circular 22/806 control framework for ICT outsourcing rather than assuming that DORA displaces it.
Firms should assess whether outsourcing arrangements entered into, reviewed or amended from 9 April 2025 require remediation or re-papering under the amended framework.
What changed
Circular 25/883 amended Circular 22/806 following DORA Regulation (EU) 2022/2554 becoming applicable on 17 January 2025. For entities subject to DORA, the ICT-outsourcing provisions of Circular 22/806 were largely repealed or displaced by DORA's ICT third-party risk-management requirements, while Circular 22/806 remains applicable to business-process outsourcing.
Compliance impact
The impact is high for firms with complex ICT and outsourcing models because misclassification can lead to the wrong contractual, governance, register and notification framework, and because DORA brings direct requirements for ICT third-party risk management and supervisory oversight. Independent market commentary from EY, Deloitte, Baker McKenzie and Luxembourg industry bodies reads the amendments as a practical division between DORA-regulated ICT services and Circular 22/806 business-process outsourcing, with particular remediation needs for investment managers, non-DORA entities and...
Requirements regarding information and communication technology (ICT) and security risk management
AI Analysis
CSSF Circular 26/915, published on 2026-08-27, updates Circular 20/750 to reflect the European Commission’s position that certain Luxembourg branches of third-country firms fall within DORA where their non-EU head office would qualify as a DORA-covered entity. Those branches are removed from Circular 20/750 and instead fall within the DORA-related CSSF framework, while the circular remains the principal ICT and security risk-management framework for specified non-DORA entities.
Key dates
2020-08-25
Circular CSSF 20/750 was originally published, establishing CSSF expectations for ICT and security risk management.
2025-01-17
Regulation (EU) 2022/2554 on digital operational resilience for the financial sector became applicable to DORA-defined financial entities supervised by the CSSF.
2025-04-09
Circular CSSF 25/881 amended Circular 20/750, narrowing it primarily to non-DORA entities and moving PSP-specific requirements to Circular CSSF 25/880.
2026-08-27
Circular CSSF 26/915 was published and applies with immediate effect; DORA-equivalent third-country branches are removed from Circular 20/750 and addressed through the DORA-related CSSF framework.
Suggested considerations
Firms with Luxembourg third-country branches should document an entity-by-entity DORA scoping analysis, including the classification of the non-EU head-office undertaking under Article 2(1)(a) to (t) of Regulation (EU) 2022/2554 and the relevance of Article 2(2).
Affected branches should consider retiring Circular 20/750 as their primary ICT framework and mapping controls instead to DORA and the applicable CSSF circulars, including Circular CSSF 25/882 on ICT third-party services and Circular CSSF 25/893 on major ICT-related incidents and significant cyber threats.
Firms should review ICT third-party inventories, contracts, due diligence files, exit strategies and, where relevant, the DORA Register of Information so that all ICT services are captured regardless of whether the arrangement is formally classified as outsourcing.
Entities remaining within Circular 20/750 should consider confirming that the management body has approved the ICT and security risk-management framework and that it is reviewed at least annually.
Remaining in-scope entities should consider refreshing their annual ICT and security risk assessment, critical-function and information-asset mapping, threat and vulnerability monitoring, access controls, patching, backup, recovery, incident-response and business-continuity documentation.
Compliance teams may wish to verify that critical ICT systems undergo security testing at least annually, non-critical systems are tested regularly and at least every three years, and critical business continuity arrangements are tested at least annually.
Branches and PSP-related entities should consider validating incident-reporting channels and escalation procedures, including the CSSF alternative email channel for exceptional technical failures where the prescribed DORA reporting channel cannot be used.
Firms should consider preserving evidence of proportionality assessments, control testing, audit findings, remediation, management-body reporting and staff security training for CSSF supervisory review.
What changed
Circular 26/915 applies with immediate effect and removes DORA-equivalent third-country branches from the scope of Circular 20/750. A third-country branch is treated as DORA-relevant where, in the jurisdiction of its head office, the undertaking would qualify as an entity listed in Article 2(1)(a) to (t) of Regulation (EU) 2022/2554, subject to the applicable exclusions and Article 2(2) conditions.
Compliance impact
The immediate-effect scope change is operationally significant for third-country branches because applying the wrong framework could result in duplicated controls, incomplete DORA reporting, or failure to maintain DORA third-party and incident-reporting records. For entities remaining under Circular 20/750, the CSSF continues to expect a documented, independently controlled and annually reviewed ICT risk framework, with deficiencies capable of generating supervisory remediation and broader CSSF enforcement consequences.
This is a standard regulatory warning against an unlicensed entity (MelzaPay S.A.) claiming to offer financial services from Luxembourg without CSSF authorisation. The warning targets a specific fraudulent operator rather than establishing new obligations or precedent.
The update announces a survey by AMLA targeting EMIs and PSPs regarding Central Contact Points under AML frameworks. The survey is voluntary and informational in nature, with a September deadline.
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
Why this matters
This is an EU implementing regulation on restrictive measures (sanctions) related to Ukraine, published as informational content by CSSF. It affects financial institutions' compliance with sanctions screening and AML obligations. Classified as news/informational rather than urgent regulatory change, hence null urgency.
CSSF warning of identity theft and fraudulent impersonation of Luxembourg-registered company Molentis S.A. Fraudsters using fake website, email, and claiming false registered office. High urgency due to active fraud scheme targeting financial sector participants and potential customers.
on the fight against money laundering and terrorist financing
Why this matters
Consolidated legislative update on anti-money laundering and terrorist financing requirements applicable across financial services. Published as informational regulatory reference material by CSSF (Luxembourg regulator). Affects all regulated financial institutions.
amending Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
Why this matters
EU sanctions regulation amending restrictive measures against Russia regarding Ukraine. This is informational regulatory update affecting financial institutions' compliance obligations for sanctions screening, reporting, and AML procedures.
amending Regulation (EU) No 833/2014 concerning restrictive measures in view of Russia’s actions destabilising the situation in Ukraine
Why this matters
This is an EU sanctions regulation amendment concerning Russia, published as regulatory news by CSSF. It affects financial institutions' compliance obligations regarding restrictive measures and sanctions screening.
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
Why this matters
This is an EU implementing regulation on restrictive measures (sanctions) regarding Ukraine, published by CSSF as informational content. It affects financial institutions' compliance obligations for sanctions screening, reporting, and AML/CFT procedures.
amending Regulation (EC) No 765/2006 concerning restrictive measures in view of the situation in Belarus and the involvement of Belarus in the Russian aggression against Ukraine
Why this matters
This is an EU Council Regulation amending restrictive measures against Belarus and related to Russian aggression. It constitutes sanctions/restrictive measures that impact financial institutions' AML/sanctions compliance obligations.
implementing Article 8a(1) of Regulation (EC) No 765/2006 concerning restrictive measures in view of the situation in Belarus and the involvement of Belarus in the Russian aggression against Ukraine
Why this matters
This is an EU implementing regulation concerning restrictive measures (sanctions) against Belarus and related entities. It impacts financial institutions' AML/sanctions compliance obligations across banking and payment sectors.
CSSF warning of fraudulent website impersonating legitimate financial services company. Involves identity theft, illicit activities, and unauthorized financial services provision. Critical urgency due to active fraud threat to consumers and need for immediate awareness across financial sector.
Administrative sanction imposed on the members of the board of directors of an electronic money institution
AI Analysis
The CSSF has publicly announced that an **administrative sanction** was imposed on the **members of the board of directors of a Luxembourg electronic money institution** by decision dated 23 March 2026. Although the notice does not detail the breaches, the timing and targeted individuals strongly indicate failures in board-level governance and oversight under the new CSSF governance framework for payment and e‑money institutions (Circular 26/906), making this an important precedent for senior managers and directors in the payments and e‑money sector.
Key dates
20 January 2026
– CSSF Circular 26/906 on central administration, internal governance and risk management for payment institutions, electronic money institutions and account information service providers is published
23 March 2026
– Decision date of the administrative sanction imposed on members of the board of directors of an electronic money institution
30 June 2026
– Application date of CSSF Circular 26/906, from which its governance and risk‑management requirements formally apply to payment institutions and electronic money institutions
21 July 2026
– CSSF publicly releases the notice “Administrative sanction of 23 March 2026 – Administrative sanction imposed on the members of the board of directors of an electronic money institution.”
Suggested considerations
Review and map the institution’s current governance framework, board charter and committee mandates against the detailed requirements of CSSF Circular 26/906, including central administration, board composition, responsibilities and functioning.
Ensure that the board of directors collectively has the required expertise, independence, diversity and time commitment, and that this is documented and periodically reassessed in line with CSSF expectations.
Update board policies to explicitly assign responsibility for strategy, risk appetite, safeguarding of client funds, information security, outsourcing, conflicts of interest and AML/CFT, and ensure these responsibilities are effectively discharged and evidenced.
Confirm that the institution’s central administration, decision‑making centre and administrative centre are physically located in Luxembourg and that members of the management body are sufficiently present on site, as required under the governance framework.
Establish or reinforce the “three lines of defence” model by clearly separating business units, control functions (compliance and risk) and internal audit, and ensure reporting lines to the board are independent and robust.
What changed
- The CSSF demonstrates that it is prepared to impose administrative sanctions directly on members of the board of directors of electronic money institutions, not just on the institution as a legal...
Board members of Luxembourg‑authorised electronic money institutions are now clearly exposed to personal regulatory liability for governance, risk management and safeguarding failures under the CSSF...
This enforcement confirms that CSSF Circular 26/906 on central administration, internal governance and risk management for payment institutions and electronic money institutions is not only a formal...
The sanction underscores CSSF expectations that the supervisory body (board of directors) must ensure sound and prudent management, continuity of the institution and protection of its reputation, and...
The case signals a stricter enforcement posture by the CSSF towards the payments and e‑money sector, aligning its expectations and enforcement intensity more closely with bank‑equivalent governance...
Compliance impact
Non‑compliance with CSSF governance, safeguarding and AML/CFT expectations can lead to administrative sanctions directly against board members, reputational damage, potential licence constraints and increased supervisory scrutiny. For EMIs and PIs, this raises the risk profile of board roles and makes demonstrable, documented governance and oversight a critical compliance priority.
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
Why this matters
This is an EU implementing regulation on restrictive measures (sanctions) regarding Ukraine, published as informational content by CSSF. It affects financial institutions' compliance obligations for sanctions screening, reporting, and AML/CFT procedures.
CSSF warning about fraudulent impersonation of Clearstream Banking S.A. using fake contact details. This is a financial crime alert requiring immediate awareness among market participants to prevent fraud victimization.
amending Regulation (EU) No 833/2014 concerning restrictive measures in view of Russia’s actions destabilising the situation in Ukraine
Why this matters
This is an EU Council Regulation amending sanctions measures against Russia related to Ukraine. It affects financial institutions' compliance obligations regarding restrictive measures, sanctions screening, and reporting requirements. Published as regulatory news update by CSSF (Luxembourg financial regulator).
implementing Regulation (EU) 2024/2642 concerning restrictive measures in view of Russia’s destabilising activities
Why this matters
This is an implementing regulation for EU restrictive measures against Russia. It affects financial institutions' compliance obligations regarding sanctions screening, reporting, and asset freeze procedures.
implementing Regulation (EU) 2024/1485 concerning restrictive measures in view of the situation in Russia
Why this matters
This is an implementing regulation for EU restrictive measures related to Russia, published by CSSF as informational content. It affects financial institutions' compliance obligations regarding sanctions and restrictive measures. Classified as news/informational with null urgency.
CSSF warning against unauthorized entity SB Systems sp. Zo.o conducting fraudulent investment services from Luxembourg without authorization. Critical urgency due to active fraud alert requiring immediate awareness among regulated entities and consumers.
Administrative sanction imposed on PingPong Europe S.A.
AI Analysis
The CSSF has imposed an administrative fine of EUR 12,000 on PingPong Europe S.A., a Luxembourg-authorised **electronic money institution**, by decision dated 2 March 2026 and published on 8 July 2026. The case signals the CSSF’s increasing enforcement focus on payment and e‑money institutions, and should be read together with CSSF Circular 26/906 as a practical warning that weaknesses in governance, safeguarding and reporting will attract public sanctions.
Key dates
20 January 2026
– CSSF publishes Circular 26/906 on central administration, internal governance and risk management for payment and e‑money institutions, raising supervisory expectations for the sector
2 March 2026
– CSSF issues the administrative sanction decision imposing an administrative fine of EUR 12,000 on PingPong Europe S.A. as an electronic money institution
30 June 2026
– Effective date of CSSF Circular 26/906, from which strengthened governance, risk management and safeguarding requirements apply to payment and e‑money institutions
8 July 2026
– CSSF publicly publishes the administrative sanction of 2 March 2026, formally informing the market and stakeholders
Suggested considerations
Review the CSSF sanction against PingPong Europe S.A. and identify which categories of requirements (e.g. governance, safeguarding of client funds, reporting, outsourcing, internal controls) were implicated, then map these to your own control framework.
Conduct a gap analysis against CSSF Circular 26/906, focusing on central administration, internal governance, risk management, and safeguarding of client funds for payment and e‑money institutions.
Update policies, procedures and internal control documentation governing payment services, e‑money issuance, safeguarding (segregation, reconciliations), outsourcing and IT connectivity to ensure alignment with CSSF Circular 26/906.
Ensure that a clearly designated member of the management body holds documented responsibility for oversight of safeguarding arrangements and compliance with CSSF requirements for payment and e‑money institutions.
Implement or enhance daily reconciliations and robust segregation of client funds accounts, supported by periodic internal reviews and testing of safeguarding controls.
What changed
(From the enforcement notice itself, there are no new rules; the impact is interpretative and enforcement‑related.)
CSSF confirms that authorised electronic money institutions are subject to active supervisory and enforcement scrutiny, including public administrative sanctions for regulatory breaches.
The sanction demonstrates that failures which may appear operational or procedural can nonetheless result in monetary fines and public naming, reinforcing the need for robust compliance frameworks in...
The case is likely to be assessed by CSSF in light of the new governance, risk management and safeguarding expectations introduced under CSSF Circular 26/906 for payment and e‑money institutions,...
The public nature of the sanction underscores CSSF’s use of transparency as a deterrent tool, increasing reputational risk for firms that do not comply with licensing, governance, reporting or...
Compliance impact
The compliance impact is high for Luxembourg‑authorised payment and electronic money institutions, given the combination of a formal monetary sanction and public disclosure, which increases both regulatory and reputational risk. Continued or serious non‑compliance with governance, safeguarding or reporting obligations could lead to larger fines, restrictions on business, or, in extreme cases, licence withdrawal.
CSSF communiqué providing guidance on AI-related cybersecurity risks and mitigation strategies for supervised financial institutions. Addresses frontier AI models' potential to accelerate cyberattacks and recommends governance structures, patch management prioritization, and defense measures aligned with DORA...
Informational update from CSSF regarding the end of MiCA transition period for virtual asset service providers on 1 July 2026. Focuses on regulatory compliance requirements, consumer guidance on checking provider authorizations, and wind-down procedures for non-compliant providers.
CSSF warning against unauthorized entity UrbanMint Digital Assets S.A. operating www.urbanmint.io without proper authorization or supervision. Warning highlights illicit activities and lack of regulatory approval to provide investment/financial services in Luxembourg.
FATF has launched a public consultation, flagged by the CSSF, on new **guidance for implementing the revised FATF Recommendation 16 (“travel rule”)**, with the objective of significantly increasing payment transparency by 2030. This consultation will shape how jurisdictions and supervisors (including Luxembourg/CSSF) expect payment and virtual asset flows to carry and use originator/beneficiary data, so compliance teams should treat this as an early signal of future mandatory AML/CTF requirements for both fiat and virtual asset transfers.
Key dates
18 June 2025
- FATF adopts modifications to Recommendation 16 to enhance payment transparency, including strengthened travel‑rule standards
24 June 2026
- FATF launches public consultation on guidance for the implementation of the updated Recommendation 16
21 August 2026 Deadline
- FATF public consultation period closes; this is the deadline for private‑sector contributions highlighted by the CSSF
End 2030
- FATF’s revised Recommendation 16 framework is expected to be fully effective, with jurisdictions having implemented the standard into national law or regulation by this date
Suggested considerations
Map and document all existing and planned cross‑border payment and value‑transfer flows (including virtual asset transfers) to identify where FATF Recommendation 16 and travel‑rule obligations currently apply or will apply by 2030.
Review the June 2025 FATF modifications to Recommendation 16 and the current consultation materials, and perform a gap analysis against your existing AML/CTF, KYC and payments data standards, including thresholds, data fields, and monitoring use‑cases.
Establish an internal project for travel‑rule implementation and enhancement that spans AML, operations, technology, legal and data‑protection teams, with explicit ownership and governance.
Strengthen beneficiary‑side transaction‑monitoring rules to use incoming travel‑rule data for sanctions, fraud and AML detection, including controls to identify misdirected or unusual payments based on name, location, and other attributes.
Review and, where necessary, update customer due diligence and KYC procedures to ensure the availability and verification of data fields that will be required to travel with transactions (for example, address, town and country, identification numbers, date of birth).
What changed
*(Based on the CSSF notice plus the 2025 FATF revisions to Recommendation 16 and existing travel‑rule standards; details may be further refined by the new guidance now under consultation.)*
FATF is issuing implementation guidance for the updated Recommendation 16, which already increased obligations regarding payment transparency, including more granular beneficiary data and expanded...
Cross‑border payments and value transfers above 1,000 USD/EUR are expected to include additional mandatory beneficiary information, such as beneficiary name, account or unique reference, and at least...
Beneficiary institutions are given enhanced responsibilities to use travel‑rule information (not just receive it) for transaction monitoring, including detecting misdirected payments and indicators...
The revised travel rule continues to apply to both traditional wire transfers and value transfers involving virtual assets, reinforcing that Virtual Asset Service Providers (VASPs) must collect,...
Compliance impact
Non‑compliance with the revised travel‑rule expectations will materially increase the risk of supervisory criticism, enforcement action, and restrictions on cross‑border business, especially in higher‑risk client segments and payment corridors. Failure to implement adequate data‑collection and monitoring capabilities may also compromise sanctions and AML controls, leading to heightened legal, financial and reputational exposure.
Identification of obliged entities eligible for direct supervision by AMLA
AI Analysis
Circular CSSF 26/914 identifies which Luxembourg obliged entities fall within the perimeter for **potential direct supervision by the future EU Anti-Money Laundering Authority (AMLA)**, as part of the new EU-level AML/CFT supervisory architecture. This matters for compliance teams because in‑scope entities will face an additional EU supervisory layer, more intrusive AML/CFT oversight, and will need to prepare for alignment with AMLA’s methodologies, data requirements, and enforcement practices.
Key dates
TBD (from AMLA operational go‑live date in 2025–2026)
- AMLA formally designates its first batch of directly supervised obliged entities at EU level, potentially including entities identified under this circular
25 June 2026
- CSSF publishes Circular 26/914 identifying obliged entities eligible for direct supervision by AMLA and setting the framework for Luxembourg’s contribution to AMLA’s selection and supervisory process
TBD (periodic, post‑AMLA go‑live)
- Periodic reviews by AMLA and the CSSF of eligible entities’ status and updates to the list of entities subject to, or proposed for, direct AMLA supervision
Suggested considerations
Determine whether your firm is likely to fall within the “eligible for AMLA direct supervision” perimeter by assessing your cross‑border footprint, ML/TF risk profile, group structure, and relative size against AMLA’s high‑risk and cross‑border criteria.
Review and update the firm‑wide AML/CFT risk assessment to ensure it is robust, data‑driven, and aligned with an EU‑level supervisory perspective, including explicit consideration of cross‑border risks, complex group structures, and high‑risk products.
Strengthen AML/CFT governance and oversight, including Board and senior management reporting, to demonstrate clear ownership of ML/TF risk, documented risk appetite, and effective challenge consistent with what AMLA expects from directly supervised entities.
Review and, where necessary, enhance customer due diligence, transaction monitoring, screening and suspicious activity reporting frameworks to withstand more intrusive and harmonised EU‑level scrutiny.
Map and document cross‑border business lines and passporting activities (branches, agents, tied intermediaries, distributors) to ensure you can provide complete and up‑to‑date information to the CSSF and AMLA on request.
What changed
- The CSSF formally identifies Luxembourg “obliged entities” under AML/CFT law that are potentially eligible for direct AMLA supervision, clarifying which categories of firms fall into the EU‑level...
The circular operationalises, at CSSF level, the EU allocation mechanism for direct supervision, building on Regulation (EU) 2024/… establishing AMLA and the forthcoming directly applicable AML...
The CSSF establishes a process for providing information to AMLA on Luxembourg obliged entities (e.g. size, cross‑border activities, risk profile) to support AMLA’s periodic selection and review of...
The circular clarifies that CSSF‑supervised entities identified as “eligible” remain under CSSF supervision unless and until AMLA formally designates them for direct supervision, at which point AMLA...
The circular anticipates enhanced data and reporting requirements for entities assessed as eligible for AMLA direct supervision, including more granular information on cross‑border business,...
Compliance impact
The compliance impact is high for any entity that is, or may become, eligible for AMLA direct supervision, given the likely increase in supervisory intensity, data expectations, and EU‑level enforcement risk. Non‑compliance could result in sanctions from both AMLA and national authorities, including significant administrative fines, business restrictions, remediation mandates, and reputational damage across the EU.
ESMA directive regarding wind-down of unauthorised crypto-asset service providers as MiCA transitional period concludes. High urgency due to regulatory deadline and mandatory compliance requirement for unauthorised providers, with emphasis on client asset safeguarding during transition.
1) high-risk jurisdictions on which enhanced due diligence and, where appropriate, counter-measures are imposed2) jurisdictions under increased monitoring of the FATFVersion of 19 June 2026
AI Analysis
CSSF published a new **Annex to Circular CSSF 22/822** on **22 June 2026**, updating the Luxembourg regulator’s reference list of FATF **high-risk jurisdictions** and **jurisdictions under increased monitoring**. For compliance teams, this matters because AML/CFT country-risk scoring, enhanced due diligence triggers, and sanctions-style controls must be aligned to the current FATF position reflected by CSSF.
Key dates
27 October 2022
- Circular CSSF 22/822 was issued, establishing the framework for using FATF statements on high-risk jurisdictions and jurisdictions under increased monitoring
19 June 2026
- The annex was updated to this version date, reflecting the current FATF jurisdiction lists and associated risk posture
22 June 2026
- CSSF published the annex on its website, making the updated reference document operationally relevant for supervised firms
Suggested considerations
Review your AML/CFT country-risk methodology and update it to reflect the 19 June 2026 FATF/CSSF jurisdiction list.
Re-screen customers, beneficial owners, counterparties, and transactions against the updated high-risk and monitored jurisdiction lists.
Apply enhanced due diligence for relationships and transactions involving high-risk jurisdictions, and escalate where counter-measures may be required.
Reassess risk ratings for customers linked to jurisdictions under increased monitoring and document the rationale for any continued onboarding, retention, or exit decisions.
Update automated screening rules, transaction-monitoring scenarios, and onboarding checklists so they use the current CSSF annex version.
What changed
- CSSF republished the annex to Circular CSSF 22/822 in a Version of 19 June 2026, meaning firms should treat this as the current Luxembourg reference point for FATF jurisdiction screening and...
The annex distinguishes between high-risk jurisdictions subject to enhanced due diligence and, where appropriate, counter-measures, and jurisdictions under increased monitoring that require...
The publication incorporates the FATF’s current statements on jurisdictions with strategic AML/CFT/CPF deficiencies, which is the basis for operational country-risk controls used by...
The related Circular CSSF 22/822 remains the framework document that instructs professionals to use FATF statements when assessing jurisdictional ML/TF/PF risk.
Compliance impact
Non-compliance can lead to supervisory findings, remediation orders, and possible enforcement action where firms fail to apply risk-sensitive AML controls consistent with CSSF/FATF expectations. The practical impact is highest for onboarding, correspondent-like relationships, cross-border payments, and any business line exposed to higher-risk jurisdictions.
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
Why this matters
Corrigendum to EU sanctions regulation concerning Ukraine. Affects financial institutions subject to restrictive measures compliance and reporting obligations. Published as regulatory update/news rather than urgent enforcement action.
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
Why this matters
This is a corrigendum to EU sanctions regulation concerning Ukraine. It affects financial institutions' compliance with restrictive measures and sanctions screening requirements. Published as informational update by CSSF (Luxembourg regulator). Applies broadly to all financial firms subject to EU sanctions regulations.
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
Why this matters
This is an EU implementing regulation on restrictive measures (sanctions) related to Ukraine. It affects financial institutions' compliance obligations regarding sanctions screening and AML/CFT procedures. Published as informational regulatory update by CSSF (Luxembourg financial regulator), hence null urgency.
implementing Regulation (EU) 2024/2642 concerning restrictive measures in view of Russia’s destabilising activities
Why this matters
This is an implementing regulation for EU restrictive measures against Russia. It affects financial institutions' compliance obligations regarding sanctions screening, reporting, and asset freezing. Classified as informational news publication rather than new substantive requirement, hence null urgency.
amending Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
Why this matters
This is a Council Regulation amending EU restrictive measures regarding Ukraine. It impacts financial institutions through sanctions compliance, AML/CFT obligations, and reporting requirements. Published as informational content by CSSF (Luxembourg financial regulator), so urgency is null.
CSSF clarification on ML/FT risk management expectations, addressing de-risking practices and financial inclusion balance. Informational guidance to supervised entities on proper risk management frameworks rather than risk avoidance, with emphasis on proportionate customer assessment and cooperation requirements.
MiCAR STORs (Suspicious Transaction and Order Reports) under the Markets in Crypto-Assets Regulation is a regulatory framework requirement for reporting suspicious activities. This is informational content from CSSF (Luxembourg financial regulator) about a public register related to audit profession oversight.
Further details concerning the AMLA webinar of 10 June 2026 from 10 am to 12 pm CEST
Why this matters
This is an informational update from CSSF announcing a webinar by AMLA regarding identification of obliged entities eligible for direct supervision. It covers AML/CFT regulatory requirements applicable to multiple financial sectors and firm types.
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
Why this matters
This is a corrigendum to EU sanctions regulation concerning Ukraine. It affects financial institutions' compliance with restrictive measures and sanctions screening requirements. Classified as informational/news content rather than new substantive regulatory requirement, hence null urgency.
CSSF warning against unauthorized entity claiming to provide investment services without Luxembourg authorization. High urgency due to active illicit operations and consumer protection risk. Entity operating across multiple financial service categories without proper licensing.
Preparation of the new data collection exercice for the purpose of the direct supervision by AMLA – AMLA webinar of 10 June 2026 from 10 am – 12 pm CEST
Why this matters
AMLA webinar announcement regarding identification of obliged entities eligible for direct supervision. Covers AML/CFT regulatory framework, data collection exercise, and reporting requirements. Applies broadly to all obliged entities under AMLA jurisdiction.
The CSSF publication highlights AMLA's public consultation on draft Regulatory Technical Standards (RTS) under Articles 16(4) and 17(3) of Regulation (EU) 2024/1624, specifying minimum group-wide AML/CFT requirements and additional measures for subsidiaries and branches in third countries. This matters because it aims to harmonize cross-border AML frameworks, ensuring groups maintain consolidated ML/TF risk views and robust controls, particularly in high-risk third-country operations, impacting EU financial groups' compliance structures. Private sector input is encouraged to align standards with practical operations.[https://www.cssf.lu/en/Document/public-consultation-by-amla-on-the-draft-rts-on-group-wide-minimum-requirements-and-additional-measures-for-subsidiaries-and-branches-in-third-countries/][https://www.amla.europa.eu/amla-consults-group-wide-requirements-and-business-wide-risk-assessment_en]
Suggested considerations
Register for 20 May 2026 public hearing to engage directly on practical application across group structures.[https://www.amla.europa.eu/events/public-hearing-draft-rts-group-wide-minimum-requirements-and-additional-measures-subsidiaries-and-2026-05-20_en]
Assess current group-wide AML/CFT frameworks against proposed minimums, identifying gaps in third-country controls, risk consolidation, and data sharing protocols.
What changed
- Group-wide AML/CFT frameworks: Establishes minimum standards for design and implementation across groups, including cross-border structures and third-country operations, to enable consolidated...
Third-country subsidiaries and branches: Introduces additional measures for entities in non-EU countries, extending requirements beyond traditional groups to other...
Information sharing and parent identification: Defines provisions for intra-group data sharing and criteria to identify the EU parent undertaking when multiple entities report to a third-country head...
Interlinked mandates: Cross-references obligations between Articles 16(4) and 17(3) for complementary requirements on organizational...
Compliance impact
Urgency: High – Firms with third-country exposure must act now on consultation (closes 15 July 2026) to influence final RTS, as these will mandate binding minimums for group-wide AML/CFT, potentially requiring significant framework overhauls for risk consolidation and controls. Non-engagement risks misaligned systems post-adoption, increasing supervisory scrutiny under harmonized EU standards; early assessment prevents rushed...
AMLA has launched a public consultation on draft Guidelines for business-wide risk assessments (BWRA) under the new Anti-Money Laundering Regulation (EU 2024/1624), with submissions open until 15 July 2026. These guidelines establish minimum requirements for all obliged entities across financial and non-financial sectors to systematically identify and manage money laundering and terrorist financing risks inherent to their operations.
Key dates
Later in 2026
- Final adoption of guidelines and technical standards
16 April 2026
- Consultation launched
20 May 2026, 10:00–12:00 CET
- Public hearing on draft RTS on group-wide requirements
28 May 2026, 10:00–12:00 CET
- Public hearing on draft Guidelines on business-wide risk assessment
15 July 2026 Deadline
- Consultation deadline for submissions
Suggested considerations
*Immediate (by 15 July 2026):
Review draft Guidelines and assess alignment with current BWRA practices
Identify gaps between existing risk assessment frameworks and proposed minimum requirements
Prepare formal consultation responses, particularly if your organization operates in non-financial sectors
Register for relevant public hearings (28 May for BWRA Guidelines; 20 May for group-wide RTS) to engage directly with AMLA
What changed
The draft Guidelines introduce four minimum requirements for conducting adequate business-wide risk assessments applicable to all obliged entities. The framework mandates that entities:
Identify risk exposure across their business model, customers, products, services, transactions, delivery channels, and geographical exposure
Maintain consolidated risk views across group structures, eliminating silos between branches and subsidiaries
Utilize internal and external data sources to build comprehensive risk landscapes, including monitoring customer behavior changes and tracking international typologies
Apply proportionality based on entity size, business model, and risk profile, while ensuring consistent application of policies across the organization
The guidelines specifically address evaluation...
This regulatory warning concerns fraudulent activities misusing the name of a licensed crypto-asset service provider and electronic money institution, Coinbase Luxembourg S.A.
Application of the Guidelines of the European Securities and Markets Authority for the criteria on the assessment of knowledge and competence under the Markets in Crypto Assets Regulation (MiCA) (ESMA35-24871704-2922)
AI Analysis
Circular CSSF 26/909 specifies how the CSSF applies ESMA's Guidelines (ESMA35-24871704-2922) for assessing **knowledge and competence** criteria under MiCA, targeting staff involved in crypto-asset services. It matters because it enforces MiCA's staff certification requirements, ensuring Luxembourg CASPs meet EU-wide standards for consumer protection and operational integrity amid the full MiCA rollout on 30 December 2024.
Assess Staff Competence: Implement ESMA-guided evaluations (e.g., exams, certifications) for all relevant personnel handling crypto services; document results in governance frameworks.
Update Policies and Training: Integrate competence criteria into HR, onboarding, and annual reviews; roll out MiCA-specific training on reporting, breaches, and governance.
Licensing Dossier Enhancement: Include competence attestations in CSSF applications; appoint dedicated compliance/risk officers with verified qualifications.
Ongoing Monitoring: Conduct regular audits, penetration tests, and incident planning; confirm compliance annually via management body statements.
Early CSSF Engagement: Schedule dialogues and info sessions; create MiCA readiness scorecards for board and regulator discussions.
What changed
- Adoption of ESMA Guidelines: CSSF mandates application of ESMA's criteria for evaluating staff knowledge and competence in crypto-asset services, including roles in custody, trading, portfolio...
Assessment Framework: Firms must implement standardized tests and processes to verify staff qualifications, aligning with MiCA Article 62 on CASP authorization, focusing on technical crypto...
No New Standalone Rules: This circular builds on prior CSSF MiCA circulars (e.g., 25/890 on crypto-asset classification), integrating competence checks into licensing dossiers and ongoing supervision.
Compliance impact
Urgency: High – With publication today (1 April 2026) and MiCA's CASP regime live since 30 December 2024, firms face immediate supervisory scrutiny during licensing and VASP transitions ending 1 July 2026. Non-compliance risks authorization denial, enforcement, or operational halts, especially as CSSF audits dossiers for competence gaps amid Luxembourg's role as MiCA hub.
This regulatory update from the CSSF provides information on a notification form for updating payment institutions and electronic money institutions' information, which is relevant for payment providers.
This is a warning from the CSSF regarding a fraudulent website impersonating a legitimate electronic money institution, VIVID MONEY S.A. The warning covers identity theft and illicit activities, which are relevant to AML/financial crime and consumer protection.
1) high-risk jurisdictions on which enhanced due diligence and, where appropriate, counter-measures are imposed2) jurisdictions under increased monitoring of the FATFVersion of 17 February 2026
AI Analysis
The Annex of Circular CSSF 22/822 (Version of 17 February 2026) is Luxembourg's Commission de Surveillance du Secteur Financier's implementation guidance on FATF (Financial Action Task Force) designations of high-risk jurisdictions requiring enhanced due diligence and counter-measures, as well as jurisdictions under increased monitoring. This document is critical for Luxembourg-regulated financial institutions because it operationalizes international AML/CFT standards into binding compliance obligations, directly impacting customer acceptance, transaction monitoring, and correspondent banking relationships.
Key dates
27 October 2022
- Original Circular CSSF 22/822 issued
27 October 2025
- Previous version superseded
17 February 2026
- Current version effective (Annex of Circular CSSF 22/822)
Apply enhanced due diligence and monitoring measures to business relationships and transactions with designated jurisdictions
Increase the frequency and timing of transaction controls
Select transaction patterns requiring further examination and obtain detailed information on transaction purposes
Maintain enhanced mechanisms for reporting suspicious activity to the FIU
What changed
The current version (17 February 2026) represents the most recent update to the CSSF's FATF-aligned jurisdiction risk framework. Based on the available search results, the document establishes two primary regulatory categories:
High-Risk Jurisdictions (Category 1): Jurisdictions designated by FATF as having strategic deficiencies in their AML/CFT regimes, requiring enhanced due diligence and, where appropriate, counter-measures.
This regulatory update is relevant for third-country branches of credit institutions, as it sets a new submission timeframe for a register of information required under DORA. This impacts banking and payments firms operating in the EU.
AML/CFT standardised data collection taking place in 2026
AI Analysis
The CSSF Circular Letter 2026-02-12 announces a standardized data collection exercise on AML/CFT for supervised entities, scheduled for 2026, aimed at enhancing regulatory oversight of money laundering and terrorist financing risks. This matters because it signals intensified CSSF scrutiny on AML/CFT compliance, requiring firms to prepare structured data submissions that could inform future supervisory actions, risk assessments, and enforcement. As part of broader CSSF AML/CFT initiatives, non-compliance risks fines or heightened inspections.
Key dates
2026 (exact date TBD) Deadline
AML/CFT standardised data collection exercise; Firms must submit required data during this period; preparation recommended immediately given today's date (12 February 2026)
20 January 2026 Deadline
Issuance of related Circular 26/906; Establishes governance baselines (e.g., compliance independence, risk proportionality) informing data collection expectations
26 January 2026
CSSF AML/CFT Conference for Specialised PFS; Provided updates on sub-sector risks, terrorist financing reviews, and FIU insights relevant to data preparation
28 January 2026 Deadline
Conference materials published; Available for download to guide compliance alignment
Suggested considerations
Assess and document AML/CFT data readiness: Inventory current risk assessments, transaction monitoring logs, KYC processes, SAR filings, and third-party oversight records in standardized formats; map to proportionality factors (e.g., transaction volumes, outsourcing).
Update governance and controls: Ensure compliance functions have independence, direct board reporting, and audit coverage of AML/CFT; test ICT resilience for monitoring continuity.
Conduct internal reviews: Perform gap analyses against Circular 26/906 (e.g., fund safeguarding, escalation protocols) and recent conference topics (e.g., terrorist financing, tax indicators); remediate deficiencies with board-approved plans.
Prepare for submission: Designate resources for data compilation; cooperate fully with CSSF/FIU requests, including transfer-of-funds information under EU 2015/847.
Engage auditors: Leverage approved auditors for validation of AML/CFT effectiveness ahead of collection.
What changed
- Introduction of standardized AML/CFT data collection: CSSF mandates uniform reporting formats for collecting data on AML/CFT risks, controls, and practices across supervised sectors, building on...
Alignment with ongoing AML/CFT enhancements: Complements recent governance-focused circulars (e.g., Circular 26/906 on central administration and risk management for payment/e-money institutions) by...
No explicit new obligations beyond preparation for data submission, but implies deeper integration of tax-related AML indicators and sub-sector risk updates, as seen in related CSSF activities.
Compliance impact
Urgency: High – With data collection in 2026 underway today (12 February 2026), firms face immediate preparation needs amid recent enforcement (e.g., EUR 102,000 fine on depositary for AML-related gaps) and conferences signaling sub-sector focus. This elevates AML/CFT as a supervisory priority, potentially triggering on-site inspections, fines, or remediation orders for inadequate data/risks; proactive alignment prevents escalation in a risk-based regime.
Guidance allowing financial entities to identify the National Competent Authority to which their register of information has to be submitted.
AI Analysis
This CSSF guidance document, published on 11 February 2026, provides detailed explanations and resolution steps for error messages encountered during the submission of the DORA Register of Information (RoI) via the eDesk portal, specifically for the 2026 submission cycle. It matters because it enables Luxembourg financial entities to ensure compliant submissions amid enhanced validation checks on more data fields, avoiding re-submission delays and supporting timely transmission to the ESAs by CSSF deadlines. Non-compliance risks supervisory scrutiny under DORA's ICT risk management framework.
Key dates
30 April 2025 Deadline
- CSSF re-submission deadline post-validation for 2025; analogous for 2026 if errors detected
May 2025
- ESAs' second-round validation for 2025; expect similar for 2026 with potential re-submissions
- Reference date for 2026 RoI submission (all contractual arrangements up to this date)
11 February 2026
- Publication date of this error guidance (last updated 10/02/2026)
Suggested considerations
Assign "DORA Reporting" role in eDesk to dedicated employee(s) per user guide.
Communicate LEI code to CSSF line supervisor prior to first submission to enable upload.
Prepare RoI in plain-CSV files within .zip following ESAs' folder structure/file naming (reference date '2025-12-31'); include all tables in FilingIndicators.csv (even empty, set to 'true').
Test submissions against listed error codes (e.g., ICTO007 for LEI, identification mismatches); resolve per guidance sections (e.g., Sections 3.2.2, 5.1.2, 6).
Consult ESAs' EBA resources (data point model, validation rules, FAQs) and CSSF guides (e.g., submission guide, guidance tables).
What changed
- Enhanced validation checks for the 2026 RoI submission: Applies ESA-defined checks (last updated April 2025) to more data fields to improve data quality, compared to prior cycles.
Specific error resolutions detailed, including requirements for LEI code communication to CSSF beforehand, correct reference date ('2025-12-31') in file naming, plain-CSV files in predefined .zip...
Mandatory inclusion of all tables (even empty) in FilingIndicators.csv set to 'true', with matching identification codes across parent-child records.
Builds on prior CSSF guides, emphasizing eDesk role "DORA Reporting" assignment and ESAs' technical standards.
No new regulatory requirements under DORA itself; this refines technical submission...
Compliance impact
Urgency: High - Published today (11 February 2026), this equips firms for imminent 2026 RoI submissions (reference date 31 December 2025), with stricter validations on expanded fields risking rejections/re-submissions. Matters for operational resilience compliance under DORA Article 28, as accurate RoI supports supervisory oversight of ICT third-party risks; delays could trigger CSSF/ESA follow-up or fines. Firms with prior 2025 issues (e.g., portal extensions to May 2025) must prioritize to avoid recurrence.
This regulatory update is related to the annual PSD2 ICT assessment reporting requirement for payment service providers (PSPs) in Luxembourg. It provides details on the submission process and timeline, which is of medium importance for the affected firms.
The CSSF informs the market regarding the outcomes of the SFTR Data Quality indicators review performed in 2025
Why this matters
This regulatory update from the CSSF focuses on the outcomes of the 2025 SFTR data quality review, which is relevant for banking, capital markets, and payments firms that are subject to SFTR reporting requirements.
This regulatory update is focused on the money laundering and terrorist financing risks associated with trust and company service provider (TCSP) activities within the financial sector in Luxembourg. It requires firms providing these services to integrate the findings and recommendations into their AML/CFT frameworks.
CSSF Circular 26/906, published on 20 January 2026, establishes detailed requirements for central administration, internal governance, and risk management for payment institutions (PIs) and electronic money institutions (EMIs) in Luxembourg, repealing prior circulars IML 95/120, IML 96/126, IML 98/143, and CSSF 04/155. It clarifies application of the amended Law of 10 November 2009 on payment services, emphasizing robust governance amid sector growth to ensure safety, efficiency, and trust. This matters for compliance as it mandates comprehensive reviews and updates to governance frameworks by mid-2026, addressing rising transaction volumes.
Key dates
20 January 2026
- Publication date of Circular CSSF 26/906
30 June 2026 Deadline
- Compliance deadline: Institutions must assess/review central administration, internal governance, and risk management frameworks to ensure full compliance
Suggested considerations
Gap analysis: Assess current frameworks against circular requirements on management bodies, internal controls, conflicts of interest, product approval, and fund safeguarding.
Updates and notifications: Review/revise governance arrangements (e.g., policies, structures); notify CSSF of management body members, compliance officers, and internal auditors with required documentation (professional experience, police records, etc.).
Documentation: Develop conflicts policy, new product approval procedures, and safeguarding rules; ensure management body authorization.
Ongoing: Maintain sound/prudent management amid growth; integrate with Law of 10 November 2009 requirements.
What changed
The circular consolidates and updates governance rules, focusing on:
Management bodies: Responsibilities, composition, qualifications, organization, and functioning, including CSSF authorization of members based on professional experience, standing (e.g., police...
Internal control functions: Responsibilities, characteristics, organization, and execution of work for compliance officers and internal auditors, with notifications to CSSF including detailed...
Conflicts of interest: Key requirements for a management policy applicable to all staff and management body members.
New product approval: Defined key steps in the process.
Compliance impact
Urgency: High - With ~5 months from publication (20 Jan 2026) to compliance (30 Jun 2026), firms face tight timelines for assessments, policy overhauls, and CSSF notifications, especially given repealed circulars and sector growth pressures. Non-compliance risks supervisory actions, as this fosters "sound and prudent management" in a high-volume industry; proactive reviews are essential to avoid disruptions.
Central administration, internal governance and risk management
AI Analysis
Circular CSSF 26/906, published on 20 January 2026, consolidates and clarifies Luxembourg's rules on central administration, internal governance, and risk management specifically for payment institutions, electronic money institutions, and account information service providers. It repeals prior circulars (IML 95/120, IML 96/126, IML 98/143, and CSSF 04/155) to address growth in transaction volumes by mandating robust governance, control functions, and risk processes, enhancing safety, efficiency, and trust in these services. This matters for compliance professionals as it strengthens defenses against financial crime, operational risks, and supervisory scrutiny in a high-growth sector.
Key dates
20 January 2026
Publication date of Circular CSSF 26/906
30 June 2026 Deadline
Compliance deadline; Institutions must assess, review, and ensure their central administration, internal governance, and risk management frameworks fully comply with the circular
Suggested considerations
Assess and update governance frameworks: Review central administration location, board/management responsibilities, risk strategy, AML/CFT policies, compliance charter, and funds safeguarding principles to align with the circular.
Confirm control functions: Ensure compliance function (CCO) has independence, resources, direct board access, and authority for investigations; justify/secure CSSF approval for part-time/dual roles.
Implement operational safeguards: Establish daily reconciliations (or justified weekly), segregation/insurance for client funds, system access controls (4-eyes, board validation for significant movements), and third-party due diligence/monitoring.
Document proportionality: Tailor governance to business risks (staff, volumes, products, outsourcing); update new product approval, conflicts policies, and business continuity/incident reporting.
Retain records and report: Board-approve all key policies; prepare for CSSF inspections on outsourcing (per Circular CSSF 22/806) and ICT risks.
What changed
- Consolidation and repeal: Replaces outdated circulars with unified requirements under the amended Law of 10 November 2009 on payment services, covering central administration (decision-making must...
Governance enhancements: Board approves strategy, risk appetite, AML/CFT policies, outsourcing, and information security; management implements via procedures; proportionality based on business...
Operational controls: Strict access to systems (need-to-know, least-privilege, 4-eyes validation); counterparty due diligence for custodians/insurers; full responsibility for agents, distributors,...
AML/CFT focus: Elevates compliance function independence, direct board reporting, risk-based resourcing, and oversight of third parties/opaque structures to close gaps exploited by criminals.
Compliance impact
Urgency: High – With a 30 June 2026 deadline (five months from publication), firms face immediate pressure to review and remediate governance gaps amid sector growth and heightened AML/CFT scrutiny; non-compliance risks supervisory actions, fines, or license issues, especially as it closes criminal exploitation vectors like weak controls and third-party risks.
This CSSF publication, dated January 12, 2026, identifies the specific population (likely a firm or individual) subject to an enforcement action, such as an administrative sanction, as part of the CSSF's transparency in supervisory measures. It matters because it signals CSSF's active enforcement priorities, potentially in areas like AML or reporting failures, enabling firms to assess similar risks in their operations and strengthen compliance to avoid parallel actions. Published amid rising focus on financial crime typologies like sexual extortion, it underscores the regulator's commitment to public accountability.
Suggested considerations
For the named population: Comply with any sanction terms (e.g., pay fines, implement remediation plans, or cease certain activities), and report to CSSF as required; appeal if applicable under Luxembourg administrative law.
Update internal policies, train staff on enforcement precedents, and ensure robust reporting under Circular CSSF 19/726 or Transparency Law obligations.
What changed
No new regulatory changes or requirements are introduced in this publication, as it is an enforcement notice rather than a circular or guideline. It serves as a disclosure of an ongoing or concluded enforcement case, aligning with CSSF's practice of publishing sanction details to deter non-compliance and inform the market, without altering existing rules.
Compliance impact
Urgency: High – Immediate relevance for the named party facing direct consequences; medium-to-high for peers due to CSSF's pattern of public enforcements signaling heightened scrutiny on financial crime, especially amid rising OCSE/FSEC cases noted in recent CSSF guidance. It matters as it could preview broader supervisory sweeps, impacting reputation, operations, and costs if similar vulnerabilities exist.
Survey on the amount of covered deposits held on 31 December 2025
AI Analysis
Circular CSSF-CPDI 25/49 is a **mandatory quarterly reporting requirement** for Luxembourg credit institutions and postal financial service providers to submit data on covered deposits as of December 31, 2025. This survey directly feeds into the Single Resolution Fund's annual target level calculation and the Luxembourg deposit guarantee scheme's contribution assessments, making it essential for regulatory compliance and fund management.
Key dates
December 24, 2025
- Circular publication date
December 31, 2025
- Reference date for the survey
January 30, 2026 Deadline
- Deadline for transmitting average covered deposits data to the Single Resolution Board
Suggested considerations
*Calculate covered deposits as defined in Article 163 of the 2015 law, including balance and accrued interest (even if not yet due)
*Report eligible deposits after applying exclusions under Article 172 of the 2015 law, including exclusions for financial institutions and life insurance products
*Distinguish deposit types by reporting:
Total eligible deposits (field 201)
Eligible deposits in omnibus accounts, fiduciary accounts, trusts, sub-accounts, and segregated accounts (field 0226)
What changed
The circular explicitly states that no substantive changes have been made to the survey process compared to previous quarters. The only modifications are administrative: the reference date (December 31, 2025) and the submission deadline (January 30, 2026). The specifications for data collection, definitions of covered and eligible deposits, and reporting methodologies remain unchanged from prior circulars, particularly Circular CSSF-CPDI 16/02 as amended by Circular CSSF-CPDI 23/35.
Adoption of the EBA Guidelines on internal policies, procedures and controls to ensure the implementation of Union and national restrictive measures (sanctions)
AI Analysis
Circular CSSF 25/896 adopts the EBA Guidelines EBA/GL/2024/14 and EBA/GL/2024/15, mandating Luxembourg financial institutions to establish robust internal policies, procedures, and controls for complying with EU and national restrictive measures (sanctions). This matters because it sets binding EU-wide standards to prevent sanctions violations and circumvention, with absolute obligations for immediate asset freezing and reporting, amid escalating geopolitical tensions.
Suggested considerations
Conduct annual exposure assessments to sanctions risks and circumvention; update policies accordingly.
Appoint senior management/board-level responsibility for approving and overseeing sanctions strategy, including annual reviews and deficiency reporting.
Implement reliable screening systems for customers, transactions, and lists; define screenable datasets; test systems regularly for effectiveness (e.g., immediate freezing, accurate hits).
Provide documented training to relevant staff on sanctions, institutional exposure, and internal processes.
Establish processes for immediate action on matches: suspend transfers, freeze assets, report to Ministry of Finance/CSSF/FIU without delay; maintain whitelists only under strict conditions.
What changed
- Institutions must develop, implement, and maintain up-to-date policies, procedures, and controls for identifying, investigating, and applying restrictive measures without delay, including risk...
Management body responsibilities expanded: approve sanctions compliance strategy, oversee implementation, conduct at least annual assessments of exposure and controls, ensure remedial actions, and...
Screening and monitoring requirements: Maintain updated sanctions lists with immediate integration of changes; screen customer base, transactions, and datasets accurately; enable immediate...
Training and testing: Deliver regular, documented role-specific training; perform ongoing system testing for screening calibration, list accuracy, transaction monitoring effectiveness, and reporting.
Proportionality applies based on institution's size, activities, and exposure; PSPs and CASPs explicitly addressed with tailored controls.
Compliance impact
Urgency: High – With less than 12 months until the 30 December 2025 deadline (as of January 2026), firms face binding requirements for absolute compliance, including personal accountability for management bodies; non-compliance risks enforcement by CSSF, reputational damage, and fines amid frequent EU sanctions updates (e.g., Regulations 2025/1469, 2025/1476). This elevates sanctions from operational task to strategic board priority.