on the fight against money laundering and terrorist financing
All Firms
amending Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
All Firms
amending Regulation (EU) No 833/2014 concerning restrictive measures in view of Russia’s actions destabilising the situation in Ukraine
All Firms
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
All Firms
amending Regulation (EC) No 765/2006 concerning restrictive measures in view of the situation in Belarus and the involvement of Belarus in the Russian aggression against Ukraine
All Firms
implementing Article 8a(1) of Regulation (EC) No 765/2006 concerning restrictive measures in view of the situation in Belarus and the involvement of Belarus in the Russian aggression against Ukraine
All Firms
No description available.
All Firms
Administrative sanction imposed on the members of the board of directors of an electronic money institution
The CSSF has publicly announced that an **administrative sanction** was imposed on the **members of the board of directors of a Luxembourg electronic money institution** by decision dated 23 March 2026. Although the notice does not detail the breaches, the timing and targeted individuals strongly indicate failures in board-level governance and oversight under the new CSSF governance framework for payment and e‑money institutions (Circular 26/906), making this an important precedent for senior managers and directors in the payments and e‑money sector.
What Changed
- - The CSSF demonstrates that it is prepared to impose administrative sanctions directly on members of the board of directors of electronic money institutions, not just on the institution as a legal...
- Board members of Luxembourg‑authorised electronic money institutions are now clearly exposed to personal regulatory liability for governance, risk management and safeguarding failures under the CSSF...
- This enforcement confirms that CSSF Circular 26/906 on central administration, internal governance and risk management for payment institutions and electronic money institutions is not only a formal...
- The sanction underscores CSSF expectations that the supervisory body (board of directors) must ensure sound and prudent management, continuity of the institution and protection of its reputation, and...
- The case signals a stricter enforcement posture by the CSSF towards the payments and e‑money sector, aligning its expectations and enforcement intensity more closely with bank‑equivalent governance...
Suggested Considerations
- Review and map the institution’s current governance framework, board charter and committee mandates against the detailed requirements of CSSF Circular 26/906, including central administration, board composition, responsibilities and functioning.
- Ensure that the board of directors collectively has the required expertise, independence, diversity and time commitment, and that this is documented and periodically reassessed in line with CSSF expectations.
- Update board policies to explicitly assign responsibility for strategy, risk appetite, safeguarding of client funds, information security, outsourcing, conflicts of interest and AML/CFT, and ensure these responsibilities are effectively discharged and evidenced.
- Confirm that the institution’s central administration, decision‑making centre and administrative centre are physically located in Luxembourg and that members of the management body are sufficiently present on site, as required under the governance framework.
- Establish or reinforce the “three lines of defence” model by clearly separating business units, control functions (compliance and risk) and internal audit, and ensure reporting lines to the board are independent and robust.
Key Dates
– CSSF Circular 26/906 on central administration, internal governance and risk management for payment institutions, electronic money institutions and account information service providers is published
– Decision date of the administrative sanction imposed on members of the board of directors of an electronic money institution
– Application date of CSSF Circular 26/906, from which its governance and risk‑management requirements formally apply to payment institutions and electronic money institutions
– CSSF publicly releases the notice “Administrative sanction of 23 March 2026 – Administrative sanction imposed on the members of the board of directors of an electronic money institution.”
Compliance Impact
Non‑compliance with CSSF governance, safeguarding and AML/CFT expectations can lead to administrative sanctions directly against board members, reputational damage, potential licence constraints and increased supervisory scrutiny. For EMIs and PIs, this raises the risk profile of board roles and makes demonstrable, documented governance and oversight a critical compliance priority.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Payment ProviderFintechBank
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
All Firms
No description available.
BankPayment Provider
amending Regulation (EU) No 833/2014 concerning restrictive measures in view of Russia’s actions destabilising the situation in Ukraine
All Firms
implementing Regulation (EU) 2024/2642 concerning restrictive measures in view of Russia’s destabilising activities
All Firms
implementing Regulation (EU) 2024/1485 concerning restrictive measures in view of the situation in Russia
All Firms
No description available.
FintechAll Firms
Administrative sanction imposed on PingPong Europe S.A.
The CSSF has imposed an administrative fine of EUR 12,000 on PingPong Europe S.A., a Luxembourg-authorised **electronic money institution**, by decision dated 2 March 2026 and published on 8 July 2026. The case signals the CSSF’s increasing enforcement focus on payment and e‑money institutions, and should be read together with CSSF Circular 26/906 as a practical warning that weaknesses in governance, safeguarding and reporting will attract public sanctions.
What Changed
- (From the enforcement notice itself, there are no new rules; the impact is interpretative and enforcement‑related.)
- CSSF confirms that authorised electronic money institutions are subject to active supervisory and enforcement scrutiny, including public administrative sanctions for regulatory breaches.
- The sanction demonstrates that failures which may appear operational or procedural can nonetheless result in monetary fines and public naming, reinforcing the need for robust compliance frameworks in...
- The case is likely to be assessed by CSSF in light of the new governance, risk management and safeguarding expectations introduced under CSSF Circular 26/906 for payment and e‑money institutions,...
- The public nature of the sanction underscores CSSF’s use of transparency as a deterrent tool, increasing reputational risk for firms that do not comply with licensing, governance, reporting or...
Suggested Considerations
- Review the CSSF sanction against PingPong Europe S.A. and identify which categories of requirements (e.g. governance, safeguarding of client funds, reporting, outsourcing, internal controls) were implicated, then map these to your own control framework.
- Conduct a gap analysis against CSSF Circular 26/906, focusing on central administration, internal governance, risk management, and safeguarding of client funds for payment and e‑money institutions.
- Update policies, procedures and internal control documentation governing payment services, e‑money issuance, safeguarding (segregation, reconciliations), outsourcing and IT connectivity to ensure alignment with CSSF Circular 26/906.
- Ensure that a clearly designated member of the management body holds documented responsibility for oversight of safeguarding arrangements and compliance with CSSF requirements for payment and e‑money institutions.
- Implement or enhance daily reconciliations and robust segregation of client funds accounts, supported by periodic internal reviews and testing of safeguarding controls.
Key Dates
– CSSF publishes Circular 26/906 on central administration, internal governance and risk management for payment and e‑money institutions, raising supervisory expectations for the sector
– CSSF issues the administrative sanction decision imposing an administrative fine of EUR 12,000 on PingPong Europe S.A. as an electronic money institution
– Effective date of CSSF Circular 26/906, from which strengthened governance, risk management and safeguarding requirements apply to payment and e‑money institutions
– CSSF publicly publishes the administrative sanction of 2 March 2026, formally informing the market and stakeholders
Compliance Impact
The compliance impact is high for Luxembourg‑authorised payment and electronic money institutions, given the combination of a formal monetary sanction and public disclosure, which increases both regulatory and reputational risk. Continued or serious non‑compliance with governance, safeguarding or reporting obligations could lead to larger fines, restrictions on business, or, in extreme cases, licence withdrawal.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Payment ProviderFintech
No description available.
All Firms
No description available.
Crypto ExchangeFintechPayment Provider
No description available.
Crypto ExchangeFintech
No description available.
FATF has launched a public consultation, flagged by the CSSF, on new **guidance for implementing the revised FATF Recommendation 16 (“travel rule”)**, with the objective of significantly increasing payment transparency by 2030. This consultation will shape how jurisdictions and supervisors (including Luxembourg/CSSF) expect payment and virtual asset flows to carry and use originator/beneficiary data, so compliance teams should treat this as an early signal of future mandatory AML/CTF requirements for both fiat and virtual asset transfers.
What Changed
- *(Based on the CSSF notice plus the 2025 FATF revisions to Recommendation 16 and existing travel‑rule standards; details may be further refined by the new guidance now under consultation.)*
- FATF is issuing implementation guidance for the updated Recommendation 16, which already increased obligations regarding payment transparency, including more granular beneficiary data and expanded...
- Cross‑border payments and value transfers above 1,000 USD/EUR are expected to include additional mandatory beneficiary information, such as beneficiary name, account or unique reference, and at least...
- Beneficiary institutions are given enhanced responsibilities to use travel‑rule information (not just receive it) for transaction monitoring, including detecting misdirected payments and indicators...
- The revised travel rule continues to apply to both traditional wire transfers and value transfers involving virtual assets, reinforcing that Virtual Asset Service Providers (VASPs) must collect,...
Suggested Considerations
- Map and document all existing and planned cross‑border payment and value‑transfer flows (including virtual asset transfers) to identify where FATF Recommendation 16 and travel‑rule obligations currently apply or will apply by 2030.
- Review the June 2025 FATF modifications to Recommendation 16 and the current consultation materials, and perform a gap analysis against your existing AML/CTF, KYC and payments data standards, including thresholds, data fields, and monitoring use‑cases.
- Establish an internal project for travel‑rule implementation and enhancement that spans AML, operations, technology, legal and data‑protection teams, with explicit ownership and governance.
- Strengthen beneficiary‑side transaction‑monitoring rules to use incoming travel‑rule data for sanctions, fraud and AML detection, including controls to identify misdirected or unusual payments based on name, location, and other attributes.
- Review and, where necessary, update customer due diligence and KYC procedures to ensure the availability and verification of data fields that will be required to travel with transactions (for example, address, town and country, identification numbers, date of birth).
Key Dates
- FATF adopts modifications to Recommendation 16 to enhance payment transparency, including strengthened travel‑rule standards
- FATF launches public consultation on guidance for the implementation of the updated Recommendation 16
- FATF public consultation period closes; this is the deadline for private‑sector contributions highlighted by the CSSF
- FATF’s revised Recommendation 16 framework is expected to be fully effective, with jurisdictions having implemented the standard into national law or regulation by this date
Compliance Impact
Non‑compliance with the revised travel‑rule expectations will materially increase the risk of supervisory criticism, enforcement action, and restrictions on cross‑border business, especially in higher‑risk client segments and payment corridors. Failure to implement adequate data‑collection and monitoring capabilities may also compromise sanctions and AML controls, leading to heightened legal, financial and reputational exposure.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankPayment ProviderCrypto Exchange Identification of obliged entities eligible for direct supervision by AMLA
Circular CSSF 26/914 identifies which Luxembourg obliged entities fall within the perimeter for **potential direct supervision by the future EU Anti-Money Laundering Authority (AMLA)**, as part of the new EU-level AML/CFT supervisory architecture. This matters for compliance teams because in‑scope entities will face an additional EU supervisory layer, more intrusive AML/CFT oversight, and will need to prepare for alignment with AMLA’s methodologies, data requirements, and enforcement practices.
What Changed
- - The CSSF formally identifies Luxembourg “obliged entities” under AML/CFT law that are potentially eligible for direct AMLA supervision, clarifying which categories of firms fall into the EU‑level...
- The circular operationalises, at CSSF level, the EU allocation mechanism for direct supervision, building on Regulation (EU) 2024/… establishing AMLA and the forthcoming directly applicable AML...
- The CSSF establishes a process for providing information to AMLA on Luxembourg obliged entities (e.g. size, cross‑border activities, risk profile) to support AMLA’s periodic selection and review of...
- The circular clarifies that CSSF‑supervised entities identified as “eligible” remain under CSSF supervision unless and until AMLA formally designates them for direct supervision, at which point AMLA...
- The circular anticipates enhanced data and reporting requirements for entities assessed as eligible for AMLA direct supervision, including more granular information on cross‑border business,...
Suggested Considerations
- Determine whether your firm is likely to fall within the “eligible for AMLA direct supervision” perimeter by assessing your cross‑border footprint, ML/TF risk profile, group structure, and relative size against AMLA’s high‑risk and cross‑border criteria.
- Review and update the firm‑wide AML/CFT risk assessment to ensure it is robust, data‑driven, and aligned with an EU‑level supervisory perspective, including explicit consideration of cross‑border risks, complex group structures, and high‑risk products.
- Strengthen AML/CFT governance and oversight, including Board and senior management reporting, to demonstrate clear ownership of ML/TF risk, documented risk appetite, and effective challenge consistent with what AMLA expects from directly supervised entities.
- Review and, where necessary, enhance customer due diligence, transaction monitoring, screening and suspicious activity reporting frameworks to withstand more intrusive and harmonised EU‑level scrutiny.
- Map and document cross‑border business lines and passporting activities (branches, agents, tied intermediaries, distributors) to ensure you can provide complete and up‑to‑date information to the CSSF and AMLA on request.
Key Dates
- AMLA formally designates its first batch of directly supervised obliged entities at EU level, potentially including entities identified under this circular
- CSSF publishes Circular 26/914 identifying obliged entities eligible for direct supervision by AMLA and setting the framework for Luxembourg’s contribution to AMLA’s selection and supervisory process
- Periodic reviews by AMLA and the CSSF of eligible entities’ status and updates to the list of entities subject to, or proposed for, direct AMLA supervision
Compliance Impact
The compliance impact is high for any entity that is, or may become, eligible for AMLA direct supervision, given the likely increase in supervisory intensity, data expectations, and EU‑level enforcement risk. Non‑compliance could result in sanctions from both AMLA and national authorities, including significant administrative fines, business restrictions, remediation mandates, and reputational damage across the EU.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankPayment ProviderCrypto Exchange No description available.
Crypto ExchangeFintechPayment Provider
1) high-risk jurisdictions on which enhanced due diligence and, where appropriate, counter-measures are imposed2) jurisdictions under increased monitoring of the FATFVersion of 19 June 2026
CSSF published a new **Annex to Circular CSSF 22/822** on **22 June 2026**, updating the Luxembourg regulator’s reference list of FATF **high-risk jurisdictions** and **jurisdictions under increased monitoring**. For compliance teams, this matters because AML/CFT country-risk scoring, enhanced due diligence triggers, and sanctions-style controls must be aligned to the current FATF position reflected by CSSF.
What Changed
- - CSSF republished the annex to Circular CSSF 22/822 in a Version of 19 June 2026, meaning firms should treat this as the current Luxembourg reference point for FATF jurisdiction screening and...
- The annex distinguishes between high-risk jurisdictions subject to enhanced due diligence and, where appropriate, counter-measures, and jurisdictions under increased monitoring that require...
- The publication incorporates the FATF’s current statements on jurisdictions with strategic AML/CFT/CPF deficiencies, which is the basis for operational country-risk controls used by...
- The related Circular CSSF 22/822 remains the framework document that instructs professionals to use FATF statements when assessing jurisdictional ML/TF/PF risk.
Suggested Considerations
- Review your AML/CFT country-risk methodology and update it to reflect the 19 June 2026 FATF/CSSF jurisdiction list.
- Re-screen customers, beneficial owners, counterparties, and transactions against the updated high-risk and monitored jurisdiction lists.
- Apply enhanced due diligence for relationships and transactions involving high-risk jurisdictions, and escalate where counter-measures may be required.
- Reassess risk ratings for customers linked to jurisdictions under increased monitoring and document the rationale for any continued onboarding, retention, or exit decisions.
- Update automated screening rules, transaction-monitoring scenarios, and onboarding checklists so they use the current CSSF annex version.
Key Dates
- Circular CSSF 22/822 was issued, establishing the framework for using FATF statements on high-risk jurisdictions and jurisdictions under increased monitoring
- The annex was updated to this version date, reflecting the current FATF jurisdiction lists and associated risk posture
- CSSF published the annex on its website, making the updated reference document operationally relevant for supervised firms
Compliance Impact
Non-compliance can lead to supervisory findings, remediation orders, and possible enforcement action where firms fail to apply risk-sensitive AML controls consistent with CSSF/FATF expectations. The practical impact is highest for onboarding, correspondent-like relationships, cross-border payments, and any business line exposed to higher-risk jurisdictions.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
All Firms
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
All Firms
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
All Firms
implementing Regulation (EU) 2024/2642 concerning restrictive measures in view of Russia’s destabilising activities
All Firms
amending Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
All Firms
No description available.
BankPayment Provider
No description available.
All Firms
Further details concerning the AMLA webinar of 10 June 2026 from 10 am to 12 pm CEST
All Firms
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
All Firms
No description available.
Broker DealerAll Firms
Preparation of the new data collection exercice for the purpose of the direct supervision by AMLA – AMLA webinar of 10 June 2026 from 10 am – 12 pm CEST
All Firms
No description available.
The CSSF publication highlights AMLA's public consultation on draft Regulatory Technical Standards (RTS) under Articles 16(4) and 17(3) of Regulation (EU) 2024/1624, specifying minimum group-wide AML/CFT requirements and additional measures for subsidiaries and branches in third countries. This matters because it aims to harmonize cross-border AML frameworks, ensuring groups maintain consolidated ML/TF risk views and robust controls, particularly in high-risk third-country operations, impacting EU financial groups' compliance structures. Private sector input is encouraged to align standards with practical operations.[https://www.cssf.lu/en/Document/public-consultation-by-amla-on-the-draft-rts-on-group-wide-minimum-requirements-and-additional-measures-for-subsidiaries-and-branches-in-third-countries/][https://www.amla.europa.eu/amla-consults-group-wide-requirements-and-business-wide-risk-assessment_en]
What Changed
- - Group-wide AML/CFT frameworks: Establishes minimum standards for design and implementation across groups, including cross-border structures and third-country operations, to enable consolidated...
- Third-country subsidiaries and branches: Introduces additional measures for entities in non-EU countries, extending requirements beyond traditional groups to other...
- Information sharing and parent identification: Defines provisions for intra-group data sharing and criteria to identify the EU parent undertaking when multiple entities report to a third-country head...
- Interlinked mandates: Cross-references obligations between Articles 16(4) and 17(3) for complementary requirements on organizational...
Suggested Considerations
- Register for 20 May 2026 public hearing to engage directly on practical application across group structures.[https://www.amla.europa.eu/events/public-hearing-draft-rts-group-wide-minimum-requirements-and-additional-measures-subsidiaries-and-2026-05-20_en]
- Assess current group-wide AML/CFT frameworks against proposed minimums, identifying gaps in third-country controls, risk consolidation, and data sharing protocols.
Compliance Impact
Urgency: High – Firms with third-country exposure must act now on consultation (closes 15 July 2026) to influence final RTS, as these will mandate binding minimums for group-wide AML/CFT, potentially requiring significant framework overhauls for risk consolidation and controls. Non-engagement risks misaligned systems post-adoption, increasing supervisory scrutiny under harmonized EU standards; early assessment prevents rushed...
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankAsset ManagerPayment Provider
No description available.
AMLA has launched a public consultation on draft Guidelines for business-wide risk assessments (BWRA) under the new Anti-Money Laundering Regulation (EU 2024/1624), with submissions open until 15 July 2026. These guidelines establish minimum requirements for all obliged entities across financial and non-financial sectors to systematically identify and manage money laundering and terrorist financing risks inherent to their operations.
What Changed
- The draft Guidelines introduce four minimum requirements for conducting adequate business-wide risk assessments applicable to all obliged entities. The framework mandates that entities:
- Identify risk exposure across their business model, customers, products, services, transactions, delivery channels, and geographical exposure
- Maintain consolidated risk views across group structures, eliminating silos between branches and subsidiaries
- Utilize internal and external data sources to build comprehensive risk landscapes, including monitoring customer behavior changes and tracking international typologies
- Apply proportionality based on entity size, business model, and risk profile, while ensuring consistent application of policies across the organization
The guidelines specifically address evaluation...
Suggested Considerations
- *Immediate (by 15 July 2026):
- Review draft Guidelines and assess alignment with current BWRA practices
- Identify gaps between existing risk assessment frameworks and proposed minimum requirements
- Prepare formal consultation responses, particularly if your organization operates in non-financial sectors
- Register for relevant public hearings (28 May for BWRA Guidelines; 20 May for group-wide RTS) to engage directly with AMLA
Key Dates
- Final adoption of guidelines and technical standards
- Consultation launched
- Public hearing on draft RTS on group-wide requirements
- Public hearing on draft Guidelines on business-wide risk assessment
- Consultation deadline for submissions
Compliance Impact
Urgency: HIGH
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
All Firms
No description available.
Crypto ExchangeFintechPayment Provider
Application of the Guidelines of the European Securities and Markets Authority for the criteria on the assessment of knowledge and competence under the Markets in Crypto Assets Regulation (MiCA) (ESMA35-24871704-2922)
Circular CSSF 26/909 specifies how the CSSF applies ESMA's Guidelines (ESMA35-24871704-2922) for assessing **knowledge and competence** criteria under MiCA, targeting staff involved in crypto-asset services. It matters because it enforces MiCA's staff certification requirements, ensuring Luxembourg CASPs meet EU-wide standards for consumer protection and operational integrity amid the full MiCA rollout on 30 December 2024.
What Changed
- - Adoption of ESMA Guidelines: CSSF mandates application of ESMA's criteria for evaluating staff knowledge and competence in crypto-asset services, including roles in custody, trading, portfolio...
- Assessment Framework: Firms must implement standardized tests and processes to verify staff qualifications, aligning with MiCA Article 62 on CASP authorization, focusing on technical crypto...
- No New Standalone Rules: This circular builds on prior CSSF MiCA circulars (e.g., 25/890 on crypto-asset classification), integrating competence checks into licensing dossiers and ongoing supervision.
Suggested Considerations
- Assess Staff Competence: Implement ESMA-guided evaluations (e.g., exams, certifications) for all relevant personnel handling crypto services; document results in governance frameworks.
- Update Policies and Training: Integrate competence criteria into HR, onboarding, and annual reviews; roll out MiCA-specific training on reporting, breaches, and governance.
- Licensing Dossier Enhancement: Include competence attestations in CSSF applications; appoint dedicated compliance/risk officers with verified qualifications.
- Ongoing Monitoring: Conduct regular audits, penetration tests, and incident planning; confirm compliance annually via management body statements.
- Early CSSF Engagement: Schedule dialogues and info sessions; create MiCA readiness scorecards for board and regulator discussions.
Key Dates
Circular CSSF 26/909 published; immediate application of ESMA competence guidelines.; [User-provided content]
Compliance Impact
Urgency: High – With publication today (1 April 2026) and MiCA's CASP regime live since 30 December 2024, firms face immediate supervisory scrutiny during licensing and VASP transitions ending 1 July 2026. Non-compliance risks authorization denial, enforcement, or operational halts, especially as CSSF audits dossiers for competence gaps amid Luxembourg's role as MiCA hub.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Crypto ExchangeBankFintech No description available.
Payment Provider
No description available.
FintechPayment Provider
1) high-risk jurisdictions on which enhanced due diligence and, where appropriate, counter-measures are imposed2) jurisdictions under increased monitoring of the FATFVersion of 17 February 2026
The Annex of Circular CSSF 22/822 (Version of 17 February 2026) is Luxembourg's Commission de Surveillance du Secteur Financier's implementation guidance on FATF (Financial Action Task Force) designations of high-risk jurisdictions requiring enhanced due diligence and counter-measures, as well as jurisdictions under increased monitoring. This document is critical for Luxembourg-regulated financial institutions because it operationalizes international AML/CFT standards into binding compliance obligations, directly impacting customer acceptance, transaction monitoring, and correspondent banking relationships.
What Changed
The current version (17 February 2026) represents the most recent update to the CSSF's FATF-aligned jurisdiction risk framework. Based on the available search results, the document establishes two primary regulatory categories:
High-Risk Jurisdictions (Category 1): Jurisdictions designated by FATF as having strategic deficiencies in their AML/CFT regimes, requiring enhanced due diligence and, where appropriate, counter-measures.
Suggested Considerations
- *For High-Risk Jurisdictions:
- Apply enhanced due diligence and monitoring measures to business relationships and transactions with designated jurisdictions
- Increase the frequency and timing of transaction controls
- Select transaction patterns requiring further examination and obtain detailed information on transaction purposes
- Maintain enhanced mechanisms for reporting suspicious activity to the FIU
Key Dates
- Original Circular CSSF 22/822 issued
- Previous version superseded
- Current version effective (Annex of Circular CSSF 22/822)
- CSSF annual AML/CFT questionnaire launch (related compliance reporting deadline)
Compliance Impact
Urgency: CRITICAL
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankAsset ManagerPayment Provider No description available.
BankPayment Provider
AML/CFT standardised data collection taking place in 2026
The CSSF Circular Letter 2026-02-12 announces a standardized data collection exercise on AML/CFT for supervised entities, scheduled for 2026, aimed at enhancing regulatory oversight of money laundering and terrorist financing risks. This matters because it signals intensified CSSF scrutiny on AML/CFT compliance, requiring firms to prepare structured data submissions that could inform future supervisory actions, risk assessments, and enforcement. As part of broader CSSF AML/CFT initiatives, non-compliance risks fines or heightened inspections.
What Changed
- - Introduction of standardized AML/CFT data collection: CSSF mandates uniform reporting formats for collecting data on AML/CFT risks, controls, and practices across supervised sectors, building on...
- Alignment with ongoing AML/CFT enhancements: Complements recent governance-focused circulars (e.g., Circular 26/906 on central administration and risk management for payment/e-money institutions) by...
- No explicit new obligations beyond preparation for data submission, but implies deeper integration of tax-related AML indicators and sub-sector risk updates, as seen in related CSSF activities.
Suggested Considerations
- Assess and document AML/CFT data readiness: Inventory current risk assessments, transaction monitoring logs, KYC processes, SAR filings, and third-party oversight records in standardized formats; map to proportionality factors (e.g., transaction volumes, outsourcing).
- Update governance and controls: Ensure compliance functions have independence, direct board reporting, and audit coverage of AML/CFT; test ICT resilience for monitoring continuity.
- Conduct internal reviews: Perform gap analyses against Circular 26/906 (e.g., fund safeguarding, escalation protocols) and recent conference topics (e.g., terrorist financing, tax indicators); remediate deficiencies with board-approved plans.
- Prepare for submission: Designate resources for data compilation; cooperate fully with CSSF/FIU requests, including transfer-of-funds information under EU 2015/847.
- Engage auditors: Leverage approved auditors for validation of AML/CFT effectiveness ahead of collection.
Key Dates
AML/CFT standardised data collection exercise; Firms must submit required data during this period; preparation recommended immediately given today's date (12 February 2026)
Issuance of related Circular 26/906; Establishes governance baselines (e.g., compliance independence, risk proportionality) informing data collection expectations
CSSF AML/CFT Conference for Specialised PFS; Provided updates on sub-sector risks, terrorist financing reviews, and FIU insights relevant to data preparation
Conference materials published; Available for download to guide compliance alignment
Compliance Impact
Urgency: High – With data collection in 2026 underway today (12 February 2026), firms face immediate preparation needs amid recent enforcement (e.g., EUR 102,000 fine on depositary for AML-related gaps) and conferences signaling sub-sector focus. This elevates AML/CFT as a supervisory priority, potentially triggering on-site inspections, fines, or remediation orders for inadequate data/risks; proactive alignment prevents escalation in a risk-based regime.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankPayment ProviderAll Firms
Guidance allowing financial entities to identify the National Competent Authority to which their register of information has to be submitted.
This CSSF guidance document, published on 11 February 2026, provides detailed explanations and resolution steps for error messages encountered during the submission of the DORA Register of Information (RoI) via the eDesk portal, specifically for the 2026 submission cycle. It matters because it enables Luxembourg financial entities to ensure compliant submissions amid enhanced validation checks on more data fields, avoiding re-submission delays and supporting timely transmission to the ESAs by CSSF deadlines. Non-compliance risks supervisory scrutiny under DORA's ICT risk management framework.
What Changed
- - Enhanced validation checks for the 2026 RoI submission: Applies ESA-defined checks (last updated April 2025) to more data fields to improve data quality, compared to prior cycles.
- Specific error resolutions detailed, including requirements for LEI code communication to CSSF beforehand, correct reference date ('2025-12-31') in file naming, plain-CSV files in predefined .zip...
- Mandatory inclusion of all tables (even empty) in FilingIndicators.csv set to 'true', with matching identification codes across parent-child records.
- Builds on prior CSSF guides, emphasizing eDesk role "DORA Reporting" assignment and ESAs' technical standards.
No new regulatory requirements under DORA itself; this refines technical submission...
Suggested Considerations
- Assign "DORA Reporting" role in eDesk to dedicated employee(s) per user guide.
- Communicate LEI code to CSSF line supervisor prior to first submission to enable upload.
- Prepare RoI in plain-CSV files within .zip following ESAs' folder structure/file naming (reference date '2025-12-31'); include all tables in FilingIndicators.csv (even empty, set to 'true').
- Test submissions against listed error codes (e.g., ICTO007 for LEI, identification mismatches); resolve per guidance sections (e.g., Sections 3.2.2, 5.1.2, 6).
- Consult ESAs' EBA resources (data point model, validation rules, FAQs) and CSSF guides (e.g., submission guide, guidance tables).
Key Dates
- CSSF re-submission deadline post-validation for 2025; analogous for 2026 if errors detected
- ESAs' second-round validation for 2025; expect similar for 2026 with potential re-submissions
- Initial 2025 submission window via eDesk (for context; 2026 window likely similar, pending confirmation)
- Reference date for 2026 RoI submission (all contractual arrangements up to this date)
- Publication date of this error guidance (last updated 10/02/2026)
Compliance Impact
Urgency: High - Published today (11 February 2026), this equips firms for imminent 2026 RoI submissions (reference date 31 December 2025), with stricter validations on expanded fields risking rejections/re-submissions. Matters for operational resilience compliance under DORA Article 28, as accurate RoI supports supervisory oversight of ICT third-party risks; delays could trigger CSSF/ESA follow-up or fines. Firms with prior 2025 issues (e.g., portal extensions to May 2025) must prioritize to avoid recurrence.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankFintechPayment Provider
No description available.
Payment Provider
The CSSF informs the market regarding the outcomes of the SFTR Data Quality indicators review performed in 2025
BankBroker DealerPayment Provider
No description available.
BankWealth ManagerPayment Provider
No description available.
CSSF Circular 26/906, published on 20 January 2026, establishes detailed requirements for central administration, internal governance, and risk management for payment institutions (PIs) and electronic money institutions (EMIs) in Luxembourg, repealing prior circulars IML 95/120, IML 96/126, IML 98/143, and CSSF 04/155. It clarifies application of the amended Law of 10 November 2009 on payment services, emphasizing robust governance amid sector growth to ensure safety, efficiency, and trust. This matters for compliance as it mandates comprehensive reviews and updates to governance frameworks by mid-2026, addressing rising transaction volumes.
What Changed
- The circular consolidates and updates governance rules, focusing on:
- Management bodies: Responsibilities, composition, qualifications, organization, and functioning, including CSSF authorization of members based on professional experience, standing (e.g., police...
- Internal control functions: Responsibilities, characteristics, organization, and execution of work for compliance officers and internal auditors, with notifications to CSSF including detailed...
- Conflicts of interest: Key requirements for a management policy applicable to all staff and management body members.
- New product approval: Defined key steps in the process.
Suggested Considerations
- Gap analysis: Assess current frameworks against circular requirements on management bodies, internal controls, conflicts of interest, product approval, and fund safeguarding.
- Updates and notifications: Review/revise governance arrangements (e.g., policies, structures); notify CSSF of management body members, compliance officers, and internal auditors with required documentation (professional experience, police records, etc.).
- Implementation: Establish robust risk identification/management/monitoring/reporting processes, internal controls, and proportional arrangements (e.g., IT, outsourcing).
- Documentation: Develop conflicts policy, new product approval procedures, and safeguarding rules; ensure management body authorization.
- Ongoing: Maintain sound/prudent management amid growth; integrate with Law of 10 November 2009 requirements.
Key Dates
- Publication date of Circular CSSF 26/906
- Compliance deadline: Institutions must assess/review central administration, internal governance, and risk management frameworks to ensure full compliance
Compliance Impact
Urgency: High - With ~5 months from publication (20 Jan 2026) to compliance (30 Jun 2026), firms face tight timelines for assessments, policy overhauls, and CSSF notifications, especially given repealed circulars and sector growth pressures. Non-compliance risks supervisory actions, as this fosters "sound and prudent management" in a high-volume industry; proactive reviews are essential to avoid disruptions.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Payment ProviderFintech
Central administration, internal governance and risk management
Circular CSSF 26/906, published on 20 January 2026, consolidates and clarifies Luxembourg's rules on central administration, internal governance, and risk management specifically for payment institutions, electronic money institutions, and account information service providers. It repeals prior circulars (IML 95/120, IML 96/126, IML 98/143, and CSSF 04/155) to address growth in transaction volumes by mandating robust governance, control functions, and risk processes, enhancing safety, efficiency, and trust in these services. This matters for compliance professionals as it strengthens defenses against financial crime, operational risks, and supervisory scrutiny in a high-growth sector.
What Changed
- - Consolidation and repeal: Replaces outdated circulars with unified requirements under the amended Law of 10 November 2009 on payment services, covering central administration (decision-making must...
- Governance enhancements: Board approves strategy, risk appetite, AML/CFT policies, outsourcing, and information security; management implements via procedures; proportionality based on business...
- Operational controls: Strict access to systems (need-to-know, least-privilege, 4-eyes validation); counterparty due diligence for custodians/insurers; full responsibility for agents, distributors,...
- AML/CFT focus: Elevates compliance function independence, direct board reporting, risk-based resourcing, and oversight of third parties/opaque structures to close gaps exploited by criminals.
Suggested Considerations
- Assess and update governance frameworks: Review central administration location, board/management responsibilities, risk strategy, AML/CFT policies, compliance charter, and funds safeguarding principles to align with the circular.
- Confirm control functions: Ensure compliance function (CCO) has independence, resources, direct board access, and authority for investigations; justify/secure CSSF approval for part-time/dual roles.
- Implement operational safeguards: Establish daily reconciliations (or justified weekly), segregation/insurance for client funds, system access controls (4-eyes, board validation for significant movements), and third-party due diligence/monitoring.
- Document proportionality: Tailor governance to business risks (staff, volumes, products, outsourcing); update new product approval, conflicts policies, and business continuity/incident reporting.
- Retain records and report: Board-approve all key policies; prepare for CSSF inspections on outsourcing (per Circular CSSF 22/806) and ICT risks.
Key Dates
Publication date of Circular CSSF 26/906
Compliance deadline; Institutions must assess, review, and ensure their central administration, internal governance, and risk management frameworks fully comply with the circular
Compliance Impact
Urgency: High – With a 30 June 2026 deadline (five months from publication), firms face immediate pressure to review and remediate governance gaps amid sector growth and heightened AML/CFT scrutiny; non-compliance risks supervisory actions, fines, or license issues, especially as it closes criminal exploitation vectors like weak controls and third-party risks.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Payment Provider
No description available.
This CSSF publication, dated January 12, 2026, identifies the specific population (likely a firm or individual) subject to an enforcement action, such as an administrative sanction, as part of the CSSF's transparency in supervisory measures. It matters because it signals CSSF's active enforcement priorities, potentially in areas like AML or reporting failures, enabling firms to assess similar risks in their operations and strengthen compliance to avoid parallel actions. Published amid rising focus on financial crime typologies like sexual extortion, it underscores the regulator's commitment to public accountability.
What Changed
No new regulatory changes or requirements are introduced in this publication, as it is an enforcement notice rather than a circular or guideline. It serves as a disclosure of an ongoing or concluded enforcement case, aligning with CSSF's practice of publishing sanction details to deter non-compliance and inform the market, without altering existing rules.
Suggested Considerations
- For the named population: Comply with any sanction terms (e.g., pay fines, implement remediation plans, or cease certain activities), and report to CSSF as required; appeal if applicable under Luxembourg administrative law.
- Update internal policies, train staff on enforcement precedents, and ensure robust reporting under Circular CSSF 19/726 or Transparency Law obligations.
Compliance Impact
Urgency: High – Immediate relevance for the named party facing direct consequences; medium-to-high for peers due to CSSF's pattern of public enforcements signaling heightened scrutiny on financial crime, especially amid rising OCSE/FSEC cases noted in recent CSSF guidance. It matters as it could preview broader supervisory sweeps, impacting reputation, operations, and costs if similar vulnerabilities exist.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankPayment ProviderAll Firms
Survey on the amount of covered deposits held on 31 December 2025
Circular CSSF-CPDI 25/49 is a **mandatory quarterly reporting requirement** for Luxembourg credit institutions and postal financial service providers to submit data on covered deposits as of December 31, 2025. This survey directly feeds into the Single Resolution Fund's annual target level calculation and the Luxembourg deposit guarantee scheme's contribution assessments, making it essential for regulatory compliance and fund management.
What Changed
The circular explicitly states that no substantive changes have been made to the survey process compared to previous quarters. The only modifications are administrative: the reference date (December 31, 2025) and the submission deadline (January 30, 2026). The specifications for data collection, definitions of covered and eligible deposits, and reporting methodologies remain unchanged from prior circulars, particularly Circular CSSF-CPDI 16/02 as amended by Circular CSSF-CPDI 23/35.
Suggested Considerations
- *Calculate covered deposits as defined in Article 163 of the 2015 law, including balance and accrued interest (even if not yet due)
- *Report eligible deposits after applying exclusions under Article 172 of the 2015 law, including exclusions for financial institutions and life insurance products
- *Distinguish deposit types by reporting:
- Total eligible deposits (field 201)
- Eligible deposits in omnibus accounts, fiduciary accounts, trusts, sub-accounts, and segregated accounts (field 0226)
Key Dates
- Circular publication date
- Reference date for the survey
- Deadline for transmitting average covered deposits data to the Single Resolution Board
Compliance Impact
Urgency: HIGH
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankPayment Provider
Adoption of the EBA Guidelines on internal policies, procedures and controls to ensure the implementation of Union and national restrictive measures (sanctions)
Circular CSSF 25/896 adopts the EBA Guidelines EBA/GL/2024/14 and EBA/GL/2024/15, mandating Luxembourg financial institutions to establish robust internal policies, procedures, and controls for complying with EU and national restrictive measures (sanctions). This matters because it sets binding EU-wide standards to prevent sanctions violations and circumvention, with absolute obligations for immediate asset freezing and reporting, amid escalating geopolitical tensions.
What Changed
- - Institutions must develop, implement, and maintain up-to-date policies, procedures, and controls for identifying, investigating, and applying restrictive measures without delay, including risk...
- Management body responsibilities expanded: approve sanctions compliance strategy, oversee implementation, conduct at least annual assessments of exposure and controls, ensure remedial actions, and...
- Screening and monitoring requirements: Maintain updated sanctions lists with immediate integration of changes; screen customer base, transactions, and datasets accurately; enable immediate...
- Training and testing: Deliver regular, documented role-specific training; perform ongoing system testing for screening calibration, list accuracy, transaction monitoring effectiveness, and reporting.
- Proportionality applies based on institution's size, activities, and exposure; PSPs and CASPs explicitly addressed with tailored controls.
Suggested Considerations
- Conduct annual exposure assessments to sanctions risks and circumvention; update policies accordingly.
- Appoint senior management/board-level responsibility for approving and overseeing sanctions strategy, including annual reviews and deficiency reporting.
- Implement reliable screening systems for customers, transactions, and lists; define screenable datasets; test systems regularly for effectiveness (e.g., immediate freezing, accurate hits).
- Provide documented training to relevant staff on sanctions, institutional exposure, and internal processes.
- Establish processes for immediate action on matches: suspend transfers, freeze assets, report to Ministry of Finance/CSSF/FIU without delay; maintain whitelists only under strict conditions.
Compliance Impact
Urgency: High – With less than 12 months until the 30 December 2025 deadline (as of January 2026), firms face binding requirements for absolute compliance, including personal accountability for management bodies; non-compliance risks enforcement by CSSF, reputational damage, and fines amid frequent EU sanctions updates (e.g., Regulations 2025/1469, 2025/1476). This elevates sanctions from operational task to strategic board priority.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankPayment ProviderCrypto Exchange