No description available.
The CSSF is formally drawing attention to the CNC Q&A 26/038, which provides detailed interpretative guidance on the **new accounting regime introduced by the Law of 7 August 2023** for large not‑for‑profit associations, public‑utility associations and foundations. This matters for compliance teams because these entities are now aligned with the accounting regime for “medium‑sized undertakings” under Luxembourg company law, with specific obligations on annual accounts formats, filing, and chart‑of‑accounts choices that require governance, process and system changes.
What Changed
- - Large associations, associations recognised as being of public utility and foundations are now subject to the accounting regime applicable to “medium‑sized undertakings” under the amended...
- Annual accounts for affected entities must include a non‑abridged balance sheet, a profit and loss account (at least in abridged format), and notes to the accounts containing disclosures required by...
- Affected entities must use statutory LRCS layouts for the balance sheet and profit and loss account and file their annual accounts in classic format with the Luxembourg Trade and Companies Register...
- Large associations, public‑utility associations and foundations remain exempt from the mandatory use of the Standard Chart of Accounts (Plan Comptable Normalisé – PCN) and from eCDF standard data...
- Affected entities may voluntarily adopt the PCN; if they do not adopt PCN, they must maintain an internal chart of accounts and ensure robust, documented mapping between internal accounts and...
Suggested Considerations
- Identify all Luxembourg associations, public‑utility associations and foundations within or related to the group that are impacted by the Law of 7 August 2023 and confirm their size classification (small, medium‑sized, large) and whether they fall under the “medium‑sized undertakings” regime.
- Review existing accounting policies, charts of accounts and annual accounts formats for affected entities to ensure alignment with LRCS statutory layouts, including non‑abridged balance sheet, appropriate profit and loss format, and required notes disclosures.
- Decide at governing‑body level whether each affected entity will voluntarily adopt the PCN or maintain an internal chart of accounts, documenting the rationale, governance approvals and compliance impacts of the chosen option.
- Where PCN is not adopted, design, implement and document a robust mapping from the internal chart of accounts to the statutory LRCS balance sheet and profit and loss layouts, ensuring audit‑ready documentation and traceability.
- Update accounting systems and reporting tools for affected entities to support LRCS statutory layouts, consistent layout adaptations, and classic‑format filing with the RCS, including necessary changes to interfaces and data capture.
Key Dates
- Law of 7 August 2023 introducing the new accounting regime for associations and foundations enters into force and defines classification as “small associations”, “medium‑sized associations” and “large associations” with corresponding accounting obligations
- CNC plans to publish an accounting guide dedicated to the new accounting regime for ASBLs classified as small, medium‑sized and large associations, and associations recognised as being of public utility
- CSSF press release is published, formally drawing supervisory attention to CNC Q&A 26/038 and the related upcoming CNC accounting guide
Compliance Impact
Non‑compliance may result in defective or non‑compliant annual accounts filings, potential rejection or queries from the RCS, and heightened supervisory scrutiny by the CSSF where the entities are linked to regulated groups, with knock‑on effects on group reporting and reputational risk. For larger public‑interest or group‑related entities, persistent non‑compliance could trigger audit qualifications and regulatory concerns about governance and internal control over financial reporting.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankInsuranceAsset Manager No description available.
The CSSF is formally drawing attention to CNC Q&A 26/038, which provides detailed interpretative guidance on the **new accounting regime introduced by the Law of 7 August 2023** for large not‑for‑profit associations, public‑utility associations and foundations. This matters for compliance teams because these entities are now subject to annual accounts obligations aligned with the regime for “medium‑sized undertakings” under the Luxembourg commercial companies law, with specific rules on formats, exemptions from PCN/eCDF, and forthcoming detailed guidance for all association size categories.
What Changed
- - Large not‑for‑profit associations, associations recognised as being of public utility and foundations are required to prepare annual accounting documents consisting at a minimum of annual accounts...
- These entities fall within the regime applicable to “medium‑sized undertakings”, which drives the required content and level of detail of their annual accounts (balance sheet, profit and loss account...
- The law and the CNC Q&A confirm that large associations, public‑utility associations and foundations are not legally required to use the Standard chart of accounts (Plan comptable normalisé, PCN) or...
- Although exempt from mandatory PCN use and eCDF standard data collection, these entities must still file their annual accounts with the Luxembourg Trade and Companies Register (RCS) using statutory...
- Large associations, public‑utility associations and foundations are exempt from the obligation to file the PCN trial balance (balance générale) via the eCDF platform, even though they may still...
Suggested Considerations
- Identify whether the organisation qualifies as a large association, an association recognised as being of public utility or a foundation under the Law of 7 August 2023, and document the classification decision with reference to Articles 18, 36 and 52 of that law.
- Update internal accounting policies to require annual accounts to be prepared in accordance with the regime for undertakings referred to in Article 47 LRCS, including minimum content (balance sheet, profit and loss account and notes) and disclosure requirements.
- Decide formally whether to adopt the PCN on a voluntary basis or to maintain an internal chart of accounts, and record this decision in accounting governance documents approved by the board or governing body.
- Where PCN is not adopted, design and implement a detailed and documented mapping from internal general ledger accounts to LRCS statutory balance sheet and profit and loss layouts to ensure accurate preparation and filing of annual accounts.
- Review and, where necessary, redesign annual accounts templates to comply with LRCS layouts while making only permitted adaptations (for example, titles and subtotals) that maintain clarity, comparability and consistency over time.
Key Dates
- Earliest financial year start date from which adjusted size criteria under Articles 35 and 47 LRCS may be applied to undertakings and groups, which indirectly affects categorisation and accounting obligations of entities subject to commercial‑law size criteria
- Law of 7 August 2023 introducing the new accounting regime for associations and foundations is adopted, setting the legal basis for reclassification and annual accounts obligations
- Default application date of the adjusted LRCS size criteria for undertakings and groups where early application from 01 January 2023 is not chosen
- New LRCS size thresholds start to determine the categorisation of pre‑existing Luxembourg undertakings and, by analogy, influence assessments of “medium‑sized” status relevant to associations
- CNC plans to publish an accounting guide dedicated to the new accounting regime for not‑for‑profit associations (ASBLs) classified as small, medium‑sized and large, as well as public‑utility associations and foundations
Compliance Impact
Non‑compliance primarily exposes large associations, public‑utility associations and foundations to deficiencies in statutory annual accounts and registry filings, which can lead to legal and governance risks, increased audit findings and potential supervisory concerns where the CSSF has a stake. For CSSF‑regulated firms, reliance on non‑compliant counterparties may undermine financial reporting integrity and due‑diligence standards, with knock‑on effects in broader regulatory reviews.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankAsset ManagerAll Firms
No description available.
Asset ManagerHedge Fund
Administrative sanction imposed on Transnet Soc Ltd
The CSSF has published an administrative sanction dated 21 July 2026 in respect of Transnet Soc Ltd, a South African issuer with Luxembourg as home Member State under the Transparency regime. Although the notice itself is very brief, it clearly continues a pattern of enforcement against Transnet for breaches of the Luxembourg Law of 11 January 2008 on transparency requirements for issuers (Transparency Law), including a prior EUR 15,000 fine for late publication of its annual financial report. For compliance teams, this underscores the CSSF’s willingness to publicly sanction and name issuers that fail to meet periodic disclosure obligations, even for relatively modest monetary amounts.
What Changed
- As the 21 July 2026 CSSF notice is an enforcement publication (not a new rule), it does not introduce new regulatory requirements; it applies existing Transparency Law obligations.
- Issuers with Luxembourg as home Member State under the Transparency Law must publish annual financial reports within the statutory deadline, typically within four months of financial year-end, and...
- Failure to publish periodic financial information within the required time limits can result in administrative fines imposed by the CSSF under Article 25(2) of the Transparency Law.
- The CSSF will publicly disclose administrative fines imposed on issuers, including naming the issuer and the amount, in line with Article 26b of the Transparency Law.
- Issuers retain the right to challenge CSSF decisions before the Luxembourg Administrative Court within the period set by Article 27 of the Transparency Law (three months from notification), but...
Suggested Considerations
- Map all Transparency Law obligations applicable to your entity, including periodic (annual and half‑yearly) reporting and ongoing disclosure of regulated information, and document them in a compliance obligations register.
- Review and, where necessary, strengthen internal processes to ensure annual and half‑yearly financial reports are prepared, approved, and published within statutory deadlines for issuers with Luxembourg as home Member State.
- Implement a formal disclosure governance framework assigning clear responsibilities to senior management and the board for oversight of regulated information, including escalation procedures where delays or issues arise.
- Establish a calendar of regulatory reporting and publication deadlines, including internal cut‑off dates and contingency plans, and ensure it is monitored by compliance and finance functions.
- Conduct a gap analysis of prior disclosures (financial reports, major holdings notifications, inside information) to confirm that all items required under the Transparency Law have been published correctly and on time; remediate any deficiencies promptly.
Key Dates
– End of the financial year referenced in the prior CSSF sanction against Transnet Soc Ltd for failure to publish its annual financial report within the required time limit
– CSSF imposed an administrative fine of EUR 15,000 on Transnet Soc Ltd under Article 25(2) of the Transparency Law for late publication of the annual financial report as of 31 March 2021
– CSSF publishes the administrative sanction “Administrative sanction imposed on Transnet Soc Ltd”; this enforcement notice is made public in line with the Transparency Law’s publication requirements
– Statutory window during which Transnet Soc Ltd (or any sanctioned issuer) may lodge a court action against the CSSF decision with the Luxembourg Administrative Court under Article 27 of the Transparency Law
Compliance Impact
CSSF administrative fines under the Transparency Law may be modest in absolute value but carry material reputational and supervisory impact because the sanctions, the issuer’s name, and the failures are publicly disclosed. Persistent or repeated non‑compliance with transparency and disclosure obligations can trigger higher fines, closer supervisory scrutiny, and increased legal risk, including potential court actions and investor claims.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerBroker DealerBank Administrative sanction imposed on the members of the board of directors of an electronic money institution
The CSSF has publicly announced that an **administrative sanction** was imposed on the **members of the board of directors of a Luxembourg electronic money institution** by decision dated 23 March 2026. Although the notice does not detail the breaches, the timing and targeted individuals strongly indicate failures in board-level governance and oversight under the new CSSF governance framework for payment and e‑money institutions (Circular 26/906), making this an important precedent for senior managers and directors in the payments and e‑money sector.
What Changed
- - The CSSF demonstrates that it is prepared to impose administrative sanctions directly on members of the board of directors of electronic money institutions, not just on the institution as a legal...
- Board members of Luxembourg‑authorised electronic money institutions are now clearly exposed to personal regulatory liability for governance, risk management and safeguarding failures under the CSSF...
- This enforcement confirms that CSSF Circular 26/906 on central administration, internal governance and risk management for payment institutions and electronic money institutions is not only a formal...
- The sanction underscores CSSF expectations that the supervisory body (board of directors) must ensure sound and prudent management, continuity of the institution and protection of its reputation, and...
- The case signals a stricter enforcement posture by the CSSF towards the payments and e‑money sector, aligning its expectations and enforcement intensity more closely with bank‑equivalent governance...
Suggested Considerations
- Review and map the institution’s current governance framework, board charter and committee mandates against the detailed requirements of CSSF Circular 26/906, including central administration, board composition, responsibilities and functioning.
- Ensure that the board of directors collectively has the required expertise, independence, diversity and time commitment, and that this is documented and periodically reassessed in line with CSSF expectations.
- Update board policies to explicitly assign responsibility for strategy, risk appetite, safeguarding of client funds, information security, outsourcing, conflicts of interest and AML/CFT, and ensure these responsibilities are effectively discharged and evidenced.
- Confirm that the institution’s central administration, decision‑making centre and administrative centre are physically located in Luxembourg and that members of the management body are sufficiently present on site, as required under the governance framework.
- Establish or reinforce the “three lines of defence” model by clearly separating business units, control functions (compliance and risk) and internal audit, and ensure reporting lines to the board are independent and robust.
Key Dates
– CSSF Circular 26/906 on central administration, internal governance and risk management for payment institutions, electronic money institutions and account information service providers is published
– Decision date of the administrative sanction imposed on members of the board of directors of an electronic money institution
– Application date of CSSF Circular 26/906, from which its governance and risk‑management requirements formally apply to payment institutions and electronic money institutions
– CSSF publicly releases the notice “Administrative sanction of 23 March 2026 – Administrative sanction imposed on the members of the board of directors of an electronic money institution.”
Compliance Impact
Non‑compliance with CSSF governance, safeguarding and AML/CFT expectations can lead to administrative sanctions directly against board members, reputational damage, potential licence constraints and increased supervisory scrutiny. For EMIs and PIs, this raises the risk profile of board roles and makes demonstrable, documented governance and oversight a critical compliance priority.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Payment ProviderFintechBank
Clarifications regarding certain aspects of Regulation (EU) 2019/2088 on sustainability-related disclosures in the financial sector (SFDR)Version 5
The CSSF’s FAQ clarifies several SFDR disclosure points for Luxembourg fund managers and related entities, especially around Article 8/9 investment strategies, sustainable-investment methodology, and periodic reporting. It also signals supervisory expectations that disclosure changes can be “material” under CSSF circular rules and therefore may trigger formal review and authorisation requirements.
What Changed
- - Article 8 funds must describe how the investment strategy actually enables the fund to meet the environmental and/or social characteristics disclosed to investors.
- If an Article 8 fund relies mainly on an exclusion strategy, the CSSF expects the exclusion policy to be detailed enough for investors to understand how the stated characteristics are being met.
- Article 9 funds cannot rely only on an exclusion strategy; they must invest in sustainable investments and use a positive selection process that demonstrates alignment with Article 2(17) SFDR.
- For Article 9 funds, the CSSF expects sustainable-investment status to be maintained at all times, including on an ongoing basis during the life cycle of the fund.
- Financial market participants should make available the methodology used to determine whether an investment is a sustainable investment, including any thresholds used for a pass-fail approach.
Suggested Considerations
- Review all Article 8 pre-contractual disclosures to confirm that the stated investment strategy clearly explains how the fund’s environmental or social characteristics are achieved.
- Strengthen any Article 8 exclusion-based strategy disclosures so they provide sufficient detail for investors to understand the connection between exclusions and the claimed sustainability characteristics.
- Reassess all Article 9 product classifications to confirm that the portfolio is built around qualifying sustainable investments, not only exclusions.
- Implement controls to verify that Article 9 holdings remain aligned with Article 2(17) SFDR on an ongoing basis throughout the fund lifecycle.
- Document and retain the internal methodology used to assess sustainable-investment status, including any thresholds, and ensure it can be provided to investors or supervisors upon request.
Key Dates
- CSSF published the SFDR FAQ clarifying supervisory expectations for Article 8 and Article 9 disclosures
- UCITS and AIFs disclosing under Article 8 or Article 9 must use the SFDR RTS periodic reporting templates in annual reports issued after this date
Compliance Impact
Non-compliance can lead to supervisory scrutiny, requests for remediation, and potential reclassification risk if a product cannot substantiate its Article 8 or Article 9 claims. The practical consequence is heightened greenwashing exposure and the possibility that disclosure changes may need formal review or authorisation before implementation.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerBankAll Firms
Version of 13 July 2026
The CSSF has republished its MiFID II/MiFIR FAQ (Q&A) in a version dated 13 July 2026, consolidating guidance on investor protection, conduct of business, and reporting obligations applicable to Luxembourg MiFID firms. While the publication page itself is largely technical (cookies, website functioning), firms should treat the 13 July 2026 FAQ version as the current CSSF interpretative benchmark for MiFID II/MiFIR compliance, aligned with ESMA Q&As and recent EU‑level MiFID II/MiFIR review developments.
What Changed
- Because the visible page content provided is limited to technical and cookie‑related information, the key points below focus on the regulatory substance of the CSSF MiFID II/MiFIR FAQ (Q&A) as the...
- The CSSF confirms the application of MiFID II investor protection rules to Luxembourg investment service providers, including obligations on inducements, suitability, product governance, and best...
- The FAQ reiterates that investment services providers must inform clients clearly whether their investment advice or services are provided on an independent or non‑independent basis, and explains the...
- The FAQ clarifies that inducements are expressly prohibited when investment advice is provided on an independent basis and for portfolio management services, requiring firms to structure their...
- The CSSF guidance reflects product governance obligations: manufacturers must define a target market for each financial instrument based on clients’ knowledge and experience, financial situation,...
Suggested Considerations
- Review the latest CSSF MiFID II/MiFIR FAQ (13 July 2026 version) in full, comparing it against existing internal MiFID II/MiFIR policies, procedures, and controls to identify gaps or misalignments.
- Confirm and, where necessary, update client‑facing disclosures to clearly state whether investment services (especially advice and portfolio management) are provided on an independent or non‑independent basis, and ensure that inducement arrangements are consistent with this classification.
- Reassess inducement frameworks (commissions, fees, non‑monetary benefits) for investment advice and portfolio management to ensure that no prohibited inducements are received or retained where services are independent or involve portfolio management.
- Review and update product governance frameworks, including target market definition processes and product approval procedures, to ensure that each instrument’s intended target market is properly documented and consistently used by distributors.
- Examine best execution policies to confirm they are clear, detailed, and understandable to clients, and implement or enhance ongoing monitoring mechanisms (e.g. execution quality reports, periodic reviews) to evidence compliance with best execution obligations.
Key Dates
- Most revised MiFIR transparency requirements under the MiFID II/MiFIR review (amending Delegated Regulation) apply at EU level, influencing the content and focus of national FAQs and supervisory guidance, including CSSF’s
- CSSF publishes/updates the MiFID II/MiFIR FAQ version dated 13 July 2026, which becomes the current reference point for CSSF supervisory expectations on MiFID II/MiFIR compliance
Compliance Impact
Non‑compliance with CSSF’s MiFID II/MiFIR expectations can lead to supervisory findings, remediation orders, administrative sanctions, and potential reputational damage, particularly where investor protection (suitability, inducements, best execution) is compromised. Given the 2026 EU‑level MiFID II/MiFIR review changes and the updated FAQ, firms that fail to update frameworks risk being assessed against a higher and more current supervisory benchmark.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerBroker DealerBank Administrative sanction imposed on PingPong Europe S.A.
The CSSF has imposed an administrative fine of EUR 12,000 on PingPong Europe S.A., a Luxembourg-authorised **electronic money institution**, by decision dated 2 March 2026 and published on 8 July 2026. The case signals the CSSF’s increasing enforcement focus on payment and e‑money institutions, and should be read together with CSSF Circular 26/906 as a practical warning that weaknesses in governance, safeguarding and reporting will attract public sanctions.
What Changed
- (From the enforcement notice itself, there are no new rules; the impact is interpretative and enforcement‑related.)
- CSSF confirms that authorised electronic money institutions are subject to active supervisory and enforcement scrutiny, including public administrative sanctions for regulatory breaches.
- The sanction demonstrates that failures which may appear operational or procedural can nonetheless result in monetary fines and public naming, reinforcing the need for robust compliance frameworks in...
- The case is likely to be assessed by CSSF in light of the new governance, risk management and safeguarding expectations introduced under CSSF Circular 26/906 for payment and e‑money institutions,...
- The public nature of the sanction underscores CSSF’s use of transparency as a deterrent tool, increasing reputational risk for firms that do not comply with licensing, governance, reporting or...
Suggested Considerations
- Review the CSSF sanction against PingPong Europe S.A. and identify which categories of requirements (e.g. governance, safeguarding of client funds, reporting, outsourcing, internal controls) were implicated, then map these to your own control framework.
- Conduct a gap analysis against CSSF Circular 26/906, focusing on central administration, internal governance, risk management, and safeguarding of client funds for payment and e‑money institutions.
- Update policies, procedures and internal control documentation governing payment services, e‑money issuance, safeguarding (segregation, reconciliations), outsourcing and IT connectivity to ensure alignment with CSSF Circular 26/906.
- Ensure that a clearly designated member of the management body holds documented responsibility for oversight of safeguarding arrangements and compliance with CSSF requirements for payment and e‑money institutions.
- Implement or enhance daily reconciliations and robust segregation of client funds accounts, supported by periodic internal reviews and testing of safeguarding controls.
Key Dates
– CSSF publishes Circular 26/906 on central administration, internal governance and risk management for payment and e‑money institutions, raising supervisory expectations for the sector
– CSSF issues the administrative sanction decision imposing an administrative fine of EUR 12,000 on PingPong Europe S.A. as an electronic money institution
– Effective date of CSSF Circular 26/906, from which strengthened governance, risk management and safeguarding requirements apply to payment and e‑money institutions
– CSSF publicly publishes the administrative sanction of 2 March 2026, formally informing the market and stakeholders
Compliance Impact
The compliance impact is high for Luxembourg‑authorised payment and electronic money institutions, given the combination of a formal monetary sanction and public disclosure, which increases both regulatory and reputational risk. Continued or serious non‑compliance with governance, safeguarding or reporting obligations could lead to larger fines, restrictions on business, or, in extreme cases, licence withdrawal.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Payment ProviderFintech
No description available.
What Changed
- - CSSF has published its 2025 supervisory disclosure covering supervisory measures and administrative penalties taken during the year.
- The publication serves as a public register-style disclosure of enforcement outcomes, increasing transparency around CSSF supervision and sanctioning activity.
- A related 2025 CSSF administrative sanction shows that AML/CFT non-compliance can result in a reprimand under the amended Luxembourg AML/CFT Law.
- The 28 July 2025 sanction confirms that CSSF can act where firms fail to maintain adequate professional AML/CFT obligations and related internal controls.
Suggested Considerations
- Review the firm’s AML/CFT control framework against the Luxembourg AML/CFT Law provisions that can trigger CSSF reprimands or sanctions, including governance, monitoring, and escalation controls.
- Verify that suspicious activity detection, investigation, and escalation procedures are documented, implemented, and tested for effectiveness.
- Reassess whether internal controls are sufficient to demonstrate timely compliance with professional AML/CFT obligations under CSSF supervision.
- Update remediation tracking to ensure supervisory findings are closed out promptly and supported by evidence of corrective action.
- Brief senior management on the reputational impact of public supervisory disclosures and ensure that recurring weaknesses are escalated to the board.
Key Dates
- CSSF’s supervisory disclosure covers **measures and administrative penalties for the year 2025**
- CSSF published the prior year’s supervisory disclosure page referencing the **2024** measures and penalties, showing the annual disclosure cycle
- CSSF issued an **administrative sanction** in an AML/CFT case, imposing a reprimand for non-compliance with the AML/CFT Law
Compliance Impact
The compliance impact is material because CSSF enforcement disclosures can expose weaknesses to the market, counterparties, auditors, and other regulators, creating reputational and supervisory pressure. Non-compliance with AML/CFT obligations can lead to public reprimands and potentially more severe measures if deficiencies persist or are systemic.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankAsset ManagerBroker Dealer No description available.
All Firms
No description available.
BankAsset ManagerBroker Dealer
Identification of obliged entities eligible for direct supervision by AMLA
Circular CSSF 26/914 identifies which Luxembourg obliged entities fall within the perimeter for **potential direct supervision by the future EU Anti-Money Laundering Authority (AMLA)**, as part of the new EU-level AML/CFT supervisory architecture. This matters for compliance teams because in‑scope entities will face an additional EU supervisory layer, more intrusive AML/CFT oversight, and will need to prepare for alignment with AMLA’s methodologies, data requirements, and enforcement practices.
What Changed
- - The CSSF formally identifies Luxembourg “obliged entities” under AML/CFT law that are potentially eligible for direct AMLA supervision, clarifying which categories of firms fall into the EU‑level...
- The circular operationalises, at CSSF level, the EU allocation mechanism for direct supervision, building on Regulation (EU) 2024/… establishing AMLA and the forthcoming directly applicable AML...
- The CSSF establishes a process for providing information to AMLA on Luxembourg obliged entities (e.g. size, cross‑border activities, risk profile) to support AMLA’s periodic selection and review of...
- The circular clarifies that CSSF‑supervised entities identified as “eligible” remain under CSSF supervision unless and until AMLA formally designates them for direct supervision, at which point AMLA...
- The circular anticipates enhanced data and reporting requirements for entities assessed as eligible for AMLA direct supervision, including more granular information on cross‑border business,...
Suggested Considerations
- Determine whether your firm is likely to fall within the “eligible for AMLA direct supervision” perimeter by assessing your cross‑border footprint, ML/TF risk profile, group structure, and relative size against AMLA’s high‑risk and cross‑border criteria.
- Review and update the firm‑wide AML/CFT risk assessment to ensure it is robust, data‑driven, and aligned with an EU‑level supervisory perspective, including explicit consideration of cross‑border risks, complex group structures, and high‑risk products.
- Strengthen AML/CFT governance and oversight, including Board and senior management reporting, to demonstrate clear ownership of ML/TF risk, documented risk appetite, and effective challenge consistent with what AMLA expects from directly supervised entities.
- Review and, where necessary, enhance customer due diligence, transaction monitoring, screening and suspicious activity reporting frameworks to withstand more intrusive and harmonised EU‑level scrutiny.
- Map and document cross‑border business lines and passporting activities (branches, agents, tied intermediaries, distributors) to ensure you can provide complete and up‑to‑date information to the CSSF and AMLA on request.
Key Dates
- AMLA formally designates its first batch of directly supervised obliged entities at EU level, potentially including entities identified under this circular
- CSSF publishes Circular 26/914 identifying obliged entities eligible for direct supervision by AMLA and setting the framework for Luxembourg’s contribution to AMLA’s selection and supervisory process
- Periodic reviews by AMLA and the CSSF of eligible entities’ status and updates to the list of entities subject to, or proposed for, direct AMLA supervision
Compliance Impact
The compliance impact is high for any entity that is, or may become, eligible for AMLA direct supervision, given the likely increase in supervisory intensity, data expectations, and EU‑level enforcement risk. Non‑compliance could result in sanctions from both AMLA and national authorities, including significant administrative fines, business restrictions, remediation mandates, and reputational damage across the EU.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankPayment ProviderCrypto Exchange Application of the Guidelines of the European Banking Authority on ancillary services undertakings specifying the criteria for the identification of activities referred to in Article 4(1)(18) of Regulation (EU) No 575/2013 (EBA/GL/2026/01)
What Changed
- - The CSSF has formally applied the EBA Guidelines on ancillary services undertakings specified in EBA/GL/2026/01 for identifying activities under Article 4(1)(18) of Regulation (EU) No 575/2013.
- Firms must assess whether a non-bank activity or group entity qualifies as an ancillary services undertaking under the EBA criteria, rather than relying on internal labels or informal business...
- The regulatory perimeter analysis now needs to consider whether relevant activities are performed within a banking group in a way that affects prudential consolidation and supervisory treatment.
- Institutions should expect the CSSF to use the EBA framework as the benchmark for determining whether an activity is sufficiently connected to banking support functions to fall within the ancillary...
- Compliance evidence will need to show a documented, reproducible assessment of each potentially relevant activity against the EBA identification criteria.
Suggested Considerations
- Review all group entities and business lines to identify activities that may fall within the definition of an ancillary services undertaking under Article 4(1)(18) CRR.
- Document a formal assessment methodology for classifying activities against the EBA/GL/2026/01 criteria.
- Reconfirm the prudential consolidation perimeter and ensure all ancillary service entities are correctly included or excluded, with the reasoning retained for supervisory review.
- Update legal entity inventories, regulatory mapping, and governance documents so they align with the CSSF’s adopted EBA framework.
- Test whether existing internal reporting, risk management, and control frameworks capture any newly identified ancillary services undertakings.
Key Dates
- Circular CSSF 26/913 is published and the CSSF confirms application of EBA/GL/2026/01
- Firms should apply the CSSF’s expectations from the date the circular becomes applicable, if that date is specified in the full circular text or accompanying CSSF notice
- Affected firms should complete internal perimeter reviews and any resulting governance or reporting updates by the first supervisory reporting cycle after application
Compliance Impact
The compliance impact is moderate to high because the main risk is misclassification of entities or activities within the prudential perimeter, which can lead to supervisory findings, reporting errors, or consolidation issues. Non-compliance may result in CSSF remediation expectations, delayed approvals, or corrective supervisory action if a firm’s entity mapping is inconsistent with the EBA criteria.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankAll Firms
No description available.
The CSSF is flagging to the market a new **CNC Q&A 26/037** that clarifies the distinction between **statutory (legal) annual accounts** and **annual accounts prepared for contractual or voluntary purposes**, and an interview indicating an upcoming **overhaul of Luxembourg accounting legislation**. This matters for compliance and finance teams because mislabeling or misusing “statutory” accounts, or applying CNC doctrine inconsistently, can create legal, regulatory, lending, and investor‑information risks, and the announced legislative reform implies future adjustments to accounting policies, reporting processes, and governance.
What Changed
- - The CSSF formally draws regulated entities’ attention to CNC Q&A 26/037, elevating it as a key interpretative reference on the concepts of annual accounts prepared for legal/statutory purposes...
- The CNC Q&A 26/037 provides clarified definitions of “comptes annuels établis à fins légales” (statutory annual accounts) and “comptes annuels établis à des fins contractuelles ou sur base...
- The Q&A gives practical answers to frequently asked questions from preparers about when accounts qualify as statutory versus merely contractual or voluntary, and how this affects applicable...
- The Q&A addresses related issues, such as the extent to which CNC doctrine and Luxembourg GAAP must be followed for contractual or voluntary accounts, and the risks of presenting non‑statutory...
- The CSSF also highlights an interview with the CNC chairman announcing that Luxembourg accounting legislation will undergo a refonte (major overhaul), signaling that current CNC doctrine, including...
Suggested Considerations
- Obtain and review the full CNC Q&A 26/037 and the CNC chairman’s interview (French‑language originals), ensuring that finance, accounting, and compliance teams understand the clarified distinctions between statutory and contractual/voluntary annual accounts.
- Map all sets of financial statements prepared by each Luxembourg entity (statutory accounts, covenant‑based or lender‑specific accounts, group reporting packages, management accounts, etc.) and classify each set as statutory or contractual/voluntary in line with CNC Q&A 26/037 definitions.
- Update internal accounting policies and manuals to explicitly define statutory versus contractual/voluntary annual accounts, specify the applicable accounting principles and disclosures for each, and describe any differences in measurement, presentation, or scope.
- Assess current practices for communicating financial information to lenders, investors, regulators, and other stakeholders to confirm that non‑statutory accounts are not labeled or presented in a way that could be misinterpreted as statutory accounts approved under Luxembourg company law.
- Implement clear labeling and disclosure conventions on the face of financial statements and in accompanying notes (e.g., in engagement reports, board minutes, and management communications) to distinguish statutory annual accounts from any contractual or voluntary accounts.
Key Dates
– Publication of the interview with the CNC chairman in Paperjam announcing that Luxembourg accounting legislation will be overhauled
– CSSF press release published, drawing attention to CNC Q&A 26/037 and the CNC chairman’s interview and signaling supervisory expectations that entities consider this doctrine when preparing annual accounts
Compliance Impact
Failure to correctly distinguish and label statutory versus contractual/voluntary annual accounts can lead to breaches of Luxembourg company law, mis‑disclosure to investors, lenders, and regulators, and increased enforcement risk from the CSSF and other authorities. Misalignment between CNC doctrine and practice may also complicate audits and regulatory reviews, leading to qualified opinions, remediation requirements, or sanctions in severe cases.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankAsset ManagerInsurance Q&A CNC 26/037 titled “A reminder of the differences between annual accounts prepared for statutory purposes and annual accounts prepared for contractual purposes or on a voluntary basis” and interview with the chairman of the CNC (Mr. Yvan Thommes)
The CSSF is formally directing market participants’ attention to new guidance from the Luxembourg Commission des normes comptables (CNC) clarifying the distinction between **statutory annual accounts** and **contractual/voluntary annual accounts**, and to an interview announcing a forthcoming overhaul of Luxembourg accounting law. This matters for compliance and finance functions because it affects how firms label, prepare, approve, file and use financial statements in regulatory, contractual and investor contexts, and foreshadows medium‑term changes to the Luxembourg accounting framework.
What Changed
- - The CSSF endorses and promotes CNC Q&A 26/037 as the reference clarification on the concept of “comptes annuels établis à fins légales” (statutory annual accounts) versus annual accounts prepared...
- The Q&A provides clear criteria to distinguish statutory accounts from non‑statutory accounts, including their legal basis, approval process, filing and publication obligations, and permissible use...
- The CNC guidance clarifies that statutory annual accounts must fully comply with Luxembourg accounting law (including mandatory layouts, valuation rules and disclosures), whereas...
- The CNC addresses frequent practical questions from preparers, including whether financial statements prepared for banks, covenants, shareholders’ agreements, management incentive plans or...
- The CSSF communicates that misunderstandings between statutory and contractual accounts remain common, implicitly warning against the risk of using non‑statutory statements in contexts where...
Suggested Considerations
- Identify all sets of financial statements prepared by the firm or its Luxembourg entities (statutory, covenant/banking, shareholder/management, group‑reporting, voluntary) and map which are statutory annual accounts under Luxembourg law and which are contractual or voluntary.
- Review the CNC Q&A 26/037 in detail and update internal accounting manuals and group reporting policies to embed the CNC’s definitions, terminology and criteria for statutory versus non‑statutory annual accounts.
- Implement a clear labelling and disclosure convention so that all non‑statutory financial statements explicitly state their nature (contractual or voluntary) and are not presented or communicated as statutory annual accounts.
- Update templates for board and shareholder approvals, minutes and resolutions to ensure that the correct set of statutory annual accounts is approved for legal purposes such as profit appropriation, dividend distribution, capital reduction and regulatory filings.
- Review all contractual arrangements (loan agreements, bond indentures, shareholder agreements, management incentive plans and service contracts) to determine whether they require statutory annual accounts or allow contractual/adjusted accounts, and align documentation and practice accordingly.
Key Dates
– Publication of the interview with the CNC chairman in Paperjam announcing that Luxembourg accounting legislation will be subject to a comprehensive overhaul
– CSSF communiqué published, formally drawing attention to CNC Q&A 26/037 and the CNC chairman’s interview, and thereby activating supervisory expectations that firms take these clarifications into account
– Effective dates for the planned overhaul of Luxembourg accounting legislation remain to be defined; firms should anticipate consultation and transition periods once draft law is published
Compliance Impact
Misclassification or misuse of contractual/voluntary accounts where statutory annual accounts are legally required can lead to breaches of Luxembourg company law, invalid shareholder resolutions, misstatements in regulatory or investor reporting, and potential CSSF supervisory findings. Consistent application of the CNC guidance will be expected in future inspections and could influence audit opinions and governance assessments.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankAsset ManagerBroker Dealer Administrative sanction imposed on Stonehage Fleming Luxembourg S.A.
The CSSF has announced that an **administrative sanction was imposed on Stonehage Fleming Luxembourg S.A. on 5 March 2026**, but it has not yet published the underlying decision or grounds. For compliance teams, this signals that the CSSF continues to actively use sanctions against Luxembourg wealth/asset management entities and that a detailed decision is likely forthcoming, which may contain important precedents on governance, AML/CFT or conduct requirements.
What Changed
- At this stage, based on the CSSF notice alone, no new legal or regulatory requirements are introduced; the publication is a transparency notice that a sanction decision exists.
- the Law of 5 April 1993 on the financial sector (LFS), the Law of 17 December 2010 on undertakings for collective investment, the Law of 12 July 2013 on AIFMs, and the Law of 12 November 2004 on the...
- the CSSF’s established practice of publishing individual sanction decisions, which typically detail shortcomings in organisational requirements, internal controls, oversight of delegates, conduct of...
- the legal provisions breached (for example, Articles 109–111 and 148 of the Law of 2010 or Articles 2-2, 3 and 8-4 of the AML/CFT Law, by analogy with other CSSF sanctions),
- the factual deficiencies identified (e.g., weaknesses in governance, delegate oversight, AML risk assessment, customer due diligence), and
Suggested Considerations
- Monitor the CSSF website for publication of the detailed PDF decision relating to the administrative sanction of 5 March 2026 against Stonehage Fleming Luxembourg S.A.
- Once available, review the full decision to identify the specific legal bases (e.g. LFS, Law of 2010, Law of 2013, AML/CFT Law) and control failures cited by the CSSF.
- Map the identified weaknesses from the decision against your firm’s governance, internal control, delegate oversight and AML/CFT frameworks to identify any similar risk areas.
- Update internal compliance risk assessments to reflect the enforcement themes highlighted in this and recent CSSF sanctions, including the weighting of enforcement risk for organisational and AML/CFT deficiencies.
- Review and, where necessary, strengthen board and senior management oversight arrangements, including the documentation of decisions, challenge and escalation processes, in anticipation of CSSF expectations evidenced in the forthcoming decision.
Key Dates
- CSSF imposes the administrative sanction on Stonehage Fleming Luxembourg S.A. (date of decision)
- CSSF publicly announces the administrative sanction and the existence of a PDF decision (date of publication on CSSF website)
Compliance Impact
The specific financial and qualitative impact of this particular sanction is not yet public, but recent CSSF cases show that deficiencies in governance, delegate oversight and AML/CFT controls can lead to significant fines, public censure and supervisory follow-up. Non-compliance increases the likelihood of intrusive inspections, remediation programmes under CSSF scrutiny, and reputational risk with clients and counterparties.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Wealth ManagerAsset ManagerFamily Office
Consultation Paper
The CSSF has launched a consultation on new **Guidance on Money Market Fund (MMF) Weekly Liquid Asset Levels**, signalling its intention to clarify supervisory expectations on the calibration and use of weekly liquid asset (WLA) buffers under the EU Money Market Funds Regulation (MMFR). This matters for compliance teams because it will likely drive changes to MMF liquidity risk frameworks, escalation triggers, governance around liquidity thresholds, and potentially the design of internal stress tests and contingency plans.
---
What Changed
- Given the consultation nature and the absence of a published consultation text in the extract, the following points reflect what compliance teams should reasonably anticipate and prepare for, based...
- The CSSF is consulting on formal guidance that will specify how MMFs domiciled in Luxembourg should determine, monitor, and maintain weekly liquid asset levels under the EU Money Market Funds...
- The guidance is expected to operationalise the MMFR WLA requirements (for example, minimum weekly liquidity levels and interaction with redemption activity) by setting out supervisory expectations on...
- The consultation will likely address the interaction between WLA levels and the use of liquidity management tools (such as gates, fees, or suspensions), including expectations on when and how...
- The CSSF is expected to clarify how MMFs should incorporate WLA targets and thresholds into their internal risk management policies, including stress-testing assumptions, early warning indicators,...
Suggested Considerations
- Review the CSSF consultation paper in full as soon as it is available and identify all proposed expectations relating to weekly liquid asset levels, monitoring, and escalation.
- Map the proposed CSSF guidance against current MMF liquidity policies, prospectus disclosures, and internal procedures to identify gaps and potential areas needing enhancement.
- Assess whether existing MMF weekly liquidity monitoring tools, dashboards, and reporting are sufficient to meet anticipated CSSF expectations on frequency, granularity, and early warning indicators.
- Evaluate the current escalation framework for declining WLA levels, including board and senior management involvement, and update governance documentation to align with the likely CSSF approach to thresholds and decision‑making.
- Review MMF stress‑testing methodologies to ensure that scenarios adequately capture severe but plausible redemption and market stress in relation to WLA levels and that results are integrated into risk appetite and contingency planning.
Key Dates
– Expected date for CSSF to publish final guidance on MMF weekly liquid asset levels, following review of consultation feedback
– CSSF publishes consultation communiqué “Guidance on Money Market Fund Weekly Liquid Asset Levels” and opens consultation on its proposed guidance
– Expected closing date for industry comments on the consultation (to be confirmed once the full consultation paper and response deadline are made available by CSSF)
Compliance Impact
Non‑compliance with the forthcoming CSSF guidance, once finalised, could result in supervisory findings, remediation programmes, and potential restrictions on MMF activities, particularly in stressed markets where liquidity management failures are highly scrutinised. Given MMFs’ systemic importance, firms should treat this as a high‑impact development for liquidity risk management, board oversight, and investor protection.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerHedge FundBank
Administrative sanction imposed on a registered alternative investment fund manager
The CSSF has published an administrative sanction dated 17 April 2026 imposed on a **registered alternative investment fund manager (registered AIFM)**, but the public notice contains no detail on the nature of the breach, legal basis, or penalty level, which are presumably only available in the linked PDFs. For compliance teams, this is another data point that the CSSF is actively enforcing the AIFMD and related Luxembourg implementing laws against even registered (sub‑threshold) AIFMs, not only fully authorised managers.
Because the body text and PDFs are not accessible from the prompt, the analysis below focuses on the **regulatory framework and typical CSSF enforcement themes** that are most likely relevant, and how compliance teams at AIFMs should respond.
---
What Changed
- There are no formal rule changes announced in the short notice itself; however, the enforcement action reinforces several practical expectations that compliance teams should treat as de‑facto...
- CSSF confirms that registered alternative investment fund managers are fully subject to Luxembourg’s AIFM framework, including the Law of 12 July 2013 on alternative investment fund managers and the...
- CSSF reiterates, through enforcement practice, that registration status (sub‑threshold AIFM) does not shield managers from administrative sanctions where organisational, conduct, reporting, or...
- CSSF continues its policy of public naming and shaming through publication of administrative sanctions, signalling that reputational impact is a key component of its deterrence strategy.
- The sanction underscores the CSSF’s readiness to use its full sanctioning toolkit under the AIFM Law, which can include monetary fines, public statements, and prohibitions or restrictions on...
Suggested Considerations
- Obtain and review the full CSSF sanction decision PDFs published with the 17 April 2026 administrative sanction to identify the specific legal provisions, facts and control failures cited.
- Map the identified breaches (e.g. governance, risk management, reporting, valuation, delegation, marketing, or conduct of business) against your firm’s current policies and procedures under the Law of 12 July 2013 on AIFMs and the AIFMD framework.
- Perform a targeted gap analysis for registered AIFMs, focusing on whether “light” registration has led to under‑resourced compliance, risk, valuation, or reporting functions that could attract similar enforcement.
- Review and, where necessary, update internal governance arrangements, including board oversight, documented decision‑making, and escalation processes for regulatory issues, to align with CSSF expectations evidenced in recent sanctions against AIFMs and management companies.
- Test the effectiveness of regulatory reporting and disclosure processes (including Annex IV reporting, investor disclosures, periodic reporting, and prospectus/issuing document accuracy) to ensure they are complete, timely and consistent with CSSF rules.
Key Dates
- CSSF adopts an administrative sanction decision against a registered alternative investment fund manager
- CSSF publishes the administrative sanction notice on its website, including links to the detailed sanction decision in PDF form
Compliance Impact
The compliance impact is medium to high: while the publication does not create new rules, it underscores that the CSSF will actively sanction even registered AIFMs and publicly disclose those sanctions, increasing both regulatory and reputational risk for weakly controlled managers. Firms that treat registration as a “lighter” supervisory regime without proportionate controls are particularly exposed to similar action.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerHedge FundWealth Manager
No description available.
The CSSF has published a Feedback Report following a thematic review of the **valuation framework for less liquid and illiquid assets**, focused primarily on Luxembourg AIFMs managing AIFs in asset classes such as private equity, real estate, infrastructure, private debt and fund of funds, and on UCITS “trash ratio” positions under Article 41(2) of the UCI Law. All Luxembourg IFMs are explicitly expected to benchmark their existing valuation frameworks against the CSSF’s observations and recommendations and to implement corrective measures, with valuation risk confirmed as a key supervisory priority for 2026.
What Changed
- - The CSSF publishes a dedicated Feedback Report on the thematic review of valuation frameworks for less liquid and illiquid assets and formally expects IFMs to use it as guidance for implementing...
- All Luxembourg IFMs are required to conduct a benchmarking exercise of their valuation frameworks against the CSSF’s observations and recommendations set out in the new Feedback Report.
- Where gaps or weaknesses are identified through this benchmarking, IFMs are expected to implement corrective measures to strengthen their valuation policies, procedures and lifecycle controls for...
- The thematic review scope formally covers AIFMs of AIFs investing in less liquid and illiquid assets (including private equity, real estate, infrastructure, private debt and fund of funds), and, on...
- The CSSF explicitly links this thematic work to previous supervisory exercises (ESMA CSA on valuation, CSSF self‑assessment questionnaires, and on‑site inspection feedback) and consolidates...
Suggested Considerations
- Perform a structured benchmarking of existing valuation policies, procedures, methodologies and controls against the detailed observations and recommendations in the CSSF Feedback Report on valuation frameworks for less liquid and illiquid assets.
- Document, at IFM and fund level, all identified gaps or weaknesses in the current valuation framework, including for AIFs in illiquid strategies and UCITS Article 41(2) trash ratio positions.
- Develop and approve a remediation plan with clear owners, milestones and target dates to address identified shortcomings in valuation governance, methodologies, model validation, data sources and control processes.
- Review and, where necessary, update valuation policies and procedures to ensure they explicitly cover less liquid and illiquid assets, stressed market conditions, use of external valuers, and documentation standards across the investment lifecycle.
- Enhance valuation governance by clearly defining roles and responsibilities (including segregation from portfolio management where applicable), escalation procedures, and oversight by the board/senior management.
Key Dates
– CSSF thematic review launched by dedicated questionnaire to IFMs, with work conducted through 2024 and 2025 (contextual start of the current thematic exercise)
– CSSF conducts off‑site and on‑site work as part of the dedicated thematic review on valuation frameworks for less liquid and illiquid assets
– Valuation risk for less liquid and illiquid assets is confirmed as a key supervisory priority, implying heightened supervisory focus and potential follow‑up actions during the year; no hard implementation deadline is set but prompt action is implicitly expected
– CSSF publishes the Communication and Feedback Report on the thematic review and formally expects IFMs to perform a benchmarking exercise and implement corrective measures as needed
Compliance Impact
Failure to benchmark and remediate valuation frameworks for less liquid and illiquid assets exposes IFMs to material supervisory risk, including targeted reviews, formal remedial orders or sanctions, particularly given the CSSF’s designation of valuation risk as a key supervisory priority in 2026. Deficient valuation practices also heighten the risk of NAV errors, investor detriment and potential civil liability or reputational damage.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerHedge FundWealth Manager No description available.
The CSSF has issued a feedback report on a thematic review of the **valuation framework for less liquid and illiquid assets**, signalling intensified supervisory focus on how Luxembourg investment fund managers value complex, hard‑to‑price positions. This matters because it will drive stricter expectations around valuation governance, model oversight, data validation, and the interaction between valuation, liquidity management, and investor protection for funds holding such assets.
Although the specific 2026 feedback report text is not yet available, it clearly follows and deepens the CSSF’s 2023 Feedback Report on ESMA’s CSA on Valuation and its 2026 supervisory priorities on valuation, with a narrower focus on less liquid and illiquid assets.
What Changed
- Based on the prior CSSF feedback on valuation and the indicated thematic focus, compliance teams should expect the following concrete expectations to apply specifically to less liquid and illiquid...
- Investment fund managers must maintain concise, centralised, and comprehensive valuation policies and procedures that explicitly cover all asset types, including less liquid and illiquid instruments,...
- Valuation policies must define and justify the valuation methodologies and models used for less liquid and illiquid assets, including the hierarchy of methods, model selection criteria, and...
- Firms must perform robust model governance for valuation models used on less liquid and illiquid assets, including independent model review (by staff not involved in model development), back‑testing,...
- Valuation frameworks must explicitly address stressed market conditions for illiquid and thinly traded assets, including triggers for stress conditions, alternative valuation methodologies under...
Suggested Considerations
- Conduct a comprehensive gap analysis of existing valuation policies and procedures against the CSSF’s feedback on valuation, with specific attention to less liquid and illiquid assets, and document all identified weaknesses and remediation actions.
- Update and formally approve valuation policies and procedures to clearly define methodologies, model hierarchies, and data source selection for less liquid and illiquid assets, including explicit provisions for stressed market conditions.
- Implement or enhance a formal valuation model governance framework for illiquid asset models, including independent model validation, periodic back‑testing, documentation of assumptions, and at least annual model reviews.
- Review and, where necessary, redesign organisational arrangements to ensure the operational and hierarchical independence of the valuation function from portfolio management, and adjust remuneration policies to avoid performance‑linked incentives for valuation staff.
- Strengthen controls over external pricing providers and external valuers by documenting selection criteria, performing initial and ongoing due diligence, challenging methodologies, and periodically back‑testing third‑party valuations of illiquid assets.
Key Dates
– CSSF publishes its Feedback Report on the ESMA Common Supervisory Action (CSA) on Valuation, setting out broad expectations for valuation frameworks, including for less liquid assets
– Deadline by which all IFMs managing UCITS and/or AIFs were required to complete a comprehensive assessment of their valuation frameworks and implement necessary corrective measures in line with the 2023 CSSF Feedback Report on valuation
– CSSF identifies valuation as an ongoing key supervisory priority for the investment fund sector in its 2026 priorities, with specific focus on IFM valuation organisation and processes
– CSSF publishes the new Feedback Report on the thematic review of valuation frameworks for less liquid and illiquid assets, signalling renewed and more granular supervisory scrutiny of this area
– CSSF is expected to conduct follow‑up supervisory work (off‑site reviews and on‑site inspections) to test implementation of its expectations on valuation of less liquid and illiquid assets; firms should plan remediation programmes within months rather than years
Compliance Impact
Non‑compliance exposes firms to heightened risk of CSSF supervisory measures, including remediation orders, restrictions on activities, and possible enforcement actions, especially where valuation weaknesses have led or could lead to investor detriment. Given the CSSF’s explicit supervisory priority on valuation, firms with significant illiquid exposures should treat this as a high‑impact issue requiring proactive remediation and robust documentation.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerHedge FundBank No description available.
CSSF is pressing Luxembourg market participants to complete T+1 readiness surveys by **9 June 2026** and to engage with ESMA’s broader T+1 consultation work, because the EU settlement cycle moves to **T+1 on 11 October 2027** under CSDR. The publication matters because it signals that supervisors are already assessing industry preparedness and that firms must accelerate post-trade process changes, especially around allocations, confirmations, and electronic messaging.
What Changed
- - CSSF is requiring market participants to complete the national competent authorities’ T+1 readiness survey by 9 June 2026, with responses visible only to CSSF and ESMA.
- CSSF is strongly encouraging participation in the EU T+1 Industry Committee second readiness survey to support a Union-wide assessment of market preparedness.
- CSSF is flagging that the transition to T+1 settlement on 11 October 2027 under CSDR will require coordinated changes across the trading and post-trading chain.
- CSSF is warning that forthcoming amendments to the RTS on Settlement Discipline are expected to be endorsed by the European Commission and will further define operational requirements for the T+1...
- ESMA’s revised guidelines on standardised procedures and messaging protocols are intended to make post-trade communication faster, clearer, and more consistent across the EU.
Suggested Considerations
- Complete the CSSF T+1 readiness survey before 9 June 2026 and ensure the submission accurately reflects the firm’s current operational readiness.
- Participate in the EU T+1 Industry Committee second readiness survey to demonstrate engagement with the EU-wide readiness process.
- Review the firm’s allocation and confirmation workflows to ensure they can operate within T+1 timeframes.
- Replace any reliance on oral, manual, or non-machine-readable communications with electronic, standardised messaging channels unless a temporary technical disruption justifies an exception.
- Align internal messaging standards with international messaging protocols used for post-trade communication.
Key Dates
- CSSF publishes the reminder on T+1 readiness, survey participation, and ESMA’s consultation work
- Deadline to complete the CSSF national competent authorities’ T+1 readiness survey
- Expected application date of the revised ESMA guidelines on standardised procedures and messaging protocols
- T+1 settlement cycle becomes effective under CSDR
Compliance Impact
Non-participation in the surveys will not itself appear to be the substantive T+1 breach, but it will materially weaken supervisory visibility and may invite follow-up scrutiny from CSSF and ESMA. Firms that fail to adapt allocations, confirmations, and messaging processes risk being unprepared for the 7 December 2026 guidance phase-in and the 11 October 2027 settlement-cycle change, which could create settlement fails, operational disruption, and conduct/governance issues.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
All FirmsAsset ManagerBank No description available.
CSSF reminds Luxembourg market participants that the EU move to a **T+1 settlement cycle under CSDR on 11 October 2027** is now in execution phase and links this directly to concrete supervisory tools: mandatory-like readiness surveys, RTS on Settlement Discipline amendments, and new ESMA post‑trade communication guidelines. For compliance teams, this is a front‑to‑back operating model change: firms must demonstrate T+1 readiness to CSSF/ESMA, transition to fully electronic, standardised post‑trade communication, and align allocations/confirmations processes to tighter regulatory timelines.
What Changed
- - The EU settlement cycle for in‑scope financial instruments under CSDR will shorten from T+2 to T+1 with effect from 11 October 2027, materially reducing the time to complete front‑to‑back trade,...
- CSSF has launched a national competent authorities’ T+1 readiness survey and sets a firm completion deadline of 9 June 2026 for Luxembourg market participants, treating it as a critical supervisory...
- In parallel, CSSF strongly encourages Luxembourg firms to complete the EU T+1 Industry Committee (EUIC) second readiness survey to support an EU‑wide view of T+1 readiness and potential systemic...
- ESMA’s final draft amendments to the CSDR RTS on Settlement Discipline will introduce additional operational requirements specifically designed to support T+1 (e.g.
- ESMA has launched a consultation on updated guidelines on standardised procedures and messaging protocols for allocations, confirmations and affirmations, explicitly aimed at facilitating the T+1...
Suggested Considerations
- Identify all group entities and business lines in Luxembourg that are in scope of CSDR T+1 (trading, clearing, settlement, custody, collateral, fund dealing) and formally designate a T+1 programme owner at senior management level.
- Complete the CSSF T+1 national competent authorities’ survey in full and by 9 June 2026, ensuring that responses accurately reflect current readiness, key risks, dependencies on third parties, and planned remediation milestones.
- Arrange for appropriate internal review and sign‑off (e.g. by Compliance and relevant senior management) of the responses to both the CSSF survey and the EUIC second readiness survey before submission.
- Participate in the EU T+1 Industry Committee second readiness survey and ensure the firm’s answers are consistent with the information provided to CSSF and with internal T+1 project documentation.
- Perform a comprehensive T+1 impact assessment of front‑to‑back trade flows, covering trade execution, allocation, confirmation, affirmation, clearing, settlement, collateral movements, cash and liquidity management, and corporate actions.
Key Dates
- Deadline for Luxembourg market participants to complete the CSSF national competent authorities’ T+1 readiness survey
- Expected application date of revised ESMA guidelines on standardised procedures and messaging protocols and the aligned new RTS on Settlement Discipline requirements on allocations and confirmations
- Effective date for the transition to a T+1 settlement cycle in the EU under CSDR
Compliance Impact
Non‑compliance is high‑impact: failure to prepare for T+1, to respond adequately to supervisory surveys, or to align processes with RTS on Settlement Discipline and ESMA guidelines can lead to increased settlement fails, penalties, supervisory scrutiny, and potential enforcement action. The T+1 change also amplifies operational, liquidity, and conduct risks if firms cannot meet accelerated timelines, making early execution of remediation plans a prudential and conduct priority.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankBroker DealerAsset Manager Version 5
The CSSF has updated its FAQ on the Money Market Funds Regulation (MMFR), making the current guidance version available as **Version 5**. This matters because CSSF FAQs are used to clarify supervisory expectations for MMFs, and firms operating or managing MMFs in Luxembourg should treat the update as a prompt to confirm that prospectus disclosures, weekly transparency information, and reporting arrangements remain aligned with current CSSF practice.
What Changed
- - The CSSF has published an updated MMFR FAQ and the current public version is Version 5, indicating that supervisory clarifications have been refreshed since the prior Version 4 publication.
- The FAQ continues to address key MMFR transparency topics, including maturity breakdown, credit profile disclosure, and the ability to provide some information via a website link in the prospectus.
- The guidance confirms that the manager may choose the day of the week for the weekly disclosure required under article 36(2), which is operationally important for recurring disclosure controls.
- The FAQ states that information on internal credit quality assessment must be provided, reinforcing the expectation that the assessment is documented and made available as required.
- The FAQ clarifies that article 36(2) applies only to MMFs authorised in accordance with MMFR as at 21 July 2018, and not to MMFs benefiting from the transitional provision in article 44(1).
Suggested Considerations
- Review the MMF prospectus and website disclosure architecture to ensure that maturity breakdown and credit profile information are presented in a manner consistent with the CSSF’s current FAQ interpretation.
- Confirm that weekly article 36(2) disclosures are scheduled on a controlled and documented day of the week, with escalation procedures for missed or late publication.
- Verify that internal credit quality assessment methodology, evidence, and sign-off are documented and available for disclosure or supervisory review.
- Reassess whether each MMF in scope is subject to article 36(2) based on its authorisation status and whether any transitional article 44(1) treatment applies.
- Align reporting and disclosure controls with the broader CSSF MMF framework, including recurring financial reporting expectations for CSSF-supervised MMF managers.
Key Dates
- Article 36(2) transparency requirements apply to MMFs authorised under MMFR as of this date, excluding MMFs benefiting from the transitional provision in article 44(1)
- CSSF first published the MMFR FAQ, establishing the supervisory clarification framework for MMF questions
- The CSSF MMF page shows Version 4 of the FAQ and references updated related MMF materials, including ESMA stress test scenario guidance
- The CSSF webpage shows Version 4 as updated on this date, before the current Version 5 publication
- The updated FAQ is now the current CSSF guidance version on the public webpage
Compliance Impact
The compliance impact is moderate to high because MMFR breaches can create direct transparency, reporting, and governance deficiencies in a regulated fund product. Non-compliance may lead to CSSF supervisory challenge, remediation requests, or enforcement consequences if disclosures or reporting are inconsistent with the regulator’s expectations.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerHedge FundAll Firms
Repeal of Circular IML 91/75 related to the revision and remodelling of the rules to which Luxembourg undertakings governed by the Law of 30 March 1988 on undertakings for collective investment (“UCI”) are subject
The CSSF has issued Circular CSSF 26/912, formally repealing Circular IML 91/75 (and its amendments) governing Luxembourg UCIs under the (now repealed) Law of 30 March 1988 on undertakings for collective investment. This is a technical clean‑up measure that removes an obsolete circular from the rulebook and confirms that the 1991 governance, organisational and investment rules under IML 91/75 no longer apply.
What Changed
- - Circular IML 91/75, including its amendments by Circulars CSSF 05/177, 18/697, 21/790, 22/811 and 25/901, is formally repealed by Circular CSSF 26/912.
- The rules on “revision and remodelling of the rules to which Luxembourg undertakings governed by the Law of 30 March 1988 on undertakings for collective investment are subject” no longer form part of...
- Supervisory expectations for Luxembourg UCIs are now to be derived exclusively from the current UCI regime (notably the Law of 17 December 2010 relating to undertakings for collective investment and...
- Any internal compliance mappings, policy references, or control frameworks that still cite Circular IML 91/75 or its amending circulars must be treated as referencing repealed guidance and should be...
Suggested Considerations
- Update your regulatory inventory and obligation registers to reflect that Circular IML 91/75 and its amending circulars (CSSF 05/177, 18/697, 21/790, 22/811 and 25/901) have been repealed by Circular CSSF 26/912 as of 22 May 2026.
- Verify that your compliance monitoring programmes and internal audit test plans do not rely on requirements sourced from Circular IML 91/75, and re-align any such tests to the currently applicable legal and regulatory standards.
- Communicate the repeal of Circular IML 91/75 internally to legal, compliance, risk, product, and fund administration teams to prevent continued reliance on obsolete rules in ongoing or future projects.
- For any ongoing remediation, authorisation or approval processes that previously cited IML 91/75 as justification for a control design, reassess and document those controls against the current CSSF requirements that have effectively replaced or superseded the 1991 framework.
- Maintain an audit trail evidencing the update of documentation and registers in response to Circular CSSF 26/912, including board or senior management notification where your governance framework requires it for changes in regulatory obligations.
Key Dates
- Original Circular IML 91/75 on revision and remodelling of rules applicable to UCIs under the Law of 30 March 1988 is issued (subsequently amended by later circulars)
- Circular CSSF 26/912 is published and Circular IML 91/75 (as amended by Circulars CSSF 05/177, 18/697, 21/790, 22/811 and 25/901) is repealed and archived
Compliance Impact
The immediate compliance risk is low, as the circular repeals an already outdated framework; however, continuing to reference or rely on Circular IML 91/75 could create documentation inconsistencies, misalignment with current CSSF expectations and weaknesses in regulatory audits or inspections.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerHedge FundBank
1° amending:(a) the Law of 5 April 1993 on the financial sector, as amended;(b) the Law of 17 December 2010 relating to undertakings for collective investment, as amended;(c) the Law of 18 December 2015 on the failure of credit institutions and certain investment firms, as amended;(d) the Law of 15 March 2016 on OTC derivatives, central counterparties and trade repositories and amending different laws relating to financial services, as amended;2° transposing:(a) Directive (EU) 2024/1619 of th...
Bank
No description available.
The CSSF publication highlights AMLA's public consultation on draft Regulatory Technical Standards (RTS) under Articles 16(4) and 17(3) of Regulation (EU) 2024/1624, specifying minimum group-wide AML/CFT requirements and additional measures for subsidiaries and branches in third countries. This matters because it aims to harmonize cross-border AML frameworks, ensuring groups maintain consolidated ML/TF risk views and robust controls, particularly in high-risk third-country operations, impacting EU financial groups' compliance structures. Private sector input is encouraged to align standards with practical operations.[https://www.cssf.lu/en/Document/public-consultation-by-amla-on-the-draft-rts-on-group-wide-minimum-requirements-and-additional-measures-for-subsidiaries-and-branches-in-third-countries/][https://www.amla.europa.eu/amla-consults-group-wide-requirements-and-business-wide-risk-assessment_en]
What Changed
- - Group-wide AML/CFT frameworks: Establishes minimum standards for design and implementation across groups, including cross-border structures and third-country operations, to enable consolidated...
- Third-country subsidiaries and branches: Introduces additional measures for entities in non-EU countries, extending requirements beyond traditional groups to other...
- Information sharing and parent identification: Defines provisions for intra-group data sharing and criteria to identify the EU parent undertaking when multiple entities report to a third-country head...
- Interlinked mandates: Cross-references obligations between Articles 16(4) and 17(3) for complementary requirements on organizational...
Suggested Considerations
- Register for 20 May 2026 public hearing to engage directly on practical application across group structures.[https://www.amla.europa.eu/events/public-hearing-draft-rts-group-wide-minimum-requirements-and-additional-measures-subsidiaries-and-2026-05-20_en]
- Assess current group-wide AML/CFT frameworks against proposed minimums, identifying gaps in third-country controls, risk consolidation, and data sharing protocols.
Compliance Impact
Urgency: High – Firms with third-country exposure must act now on consultation (closes 15 July 2026) to influence final RTS, as these will mandate binding minimums for group-wide AML/CFT, potentially requiring significant framework overhauls for risk consolidation and controls. Non-engagement risks misaligned systems post-adoption, increasing supervisory scrutiny under harmonized EU standards; early assessment prevents rushed...
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankAsset ManagerPayment Provider
No description available.
AMLA has launched a public consultation on draft Guidelines for business-wide risk assessments (BWRA) under the new Anti-Money Laundering Regulation (EU 2024/1624), with submissions open until 15 July 2026. These guidelines establish minimum requirements for all obliged entities across financial and non-financial sectors to systematically identify and manage money laundering and terrorist financing risks inherent to their operations.
What Changed
- The draft Guidelines introduce four minimum requirements for conducting adequate business-wide risk assessments applicable to all obliged entities. The framework mandates that entities:
- Identify risk exposure across their business model, customers, products, services, transactions, delivery channels, and geographical exposure
- Maintain consolidated risk views across group structures, eliminating silos between branches and subsidiaries
- Utilize internal and external data sources to build comprehensive risk landscapes, including monitoring customer behavior changes and tracking international typologies
- Apply proportionality based on entity size, business model, and risk profile, while ensuring consistent application of policies across the organization
The guidelines specifically address evaluation...
Suggested Considerations
- *Immediate (by 15 July 2026):
- Review draft Guidelines and assess alignment with current BWRA practices
- Identify gaps between existing risk assessment frameworks and proposed minimum requirements
- Prepare formal consultation responses, particularly if your organization operates in non-financial sectors
- Register for relevant public hearings (28 May for BWRA Guidelines; 20 May for group-wide RTS) to engage directly with AMLA
Key Dates
- Final adoption of guidelines and technical standards
- Consultation launched
- Public hearing on draft RTS on group-wide requirements
- Public hearing on draft Guidelines on business-wide risk assessment
- Consultation deadline for submissions
Compliance Impact
Urgency: HIGH
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
All Firms
concerning the audit profession
BankWealth ManagerAsset Manager
Application of the Guidelines of the European Securities and Markets Authority for the criteria on the assessment of knowledge and competence under the Markets in Crypto Assets Regulation (MiCA) (ESMA35-24871704-2922)
Circular CSSF 26/909 specifies how the CSSF applies ESMA's Guidelines (ESMA35-24871704-2922) for assessing **knowledge and competence** criteria under MiCA, targeting staff involved in crypto-asset services. It matters because it enforces MiCA's staff certification requirements, ensuring Luxembourg CASPs meet EU-wide standards for consumer protection and operational integrity amid the full MiCA rollout on 30 December 2024.
What Changed
- - Adoption of ESMA Guidelines: CSSF mandates application of ESMA's criteria for evaluating staff knowledge and competence in crypto-asset services, including roles in custody, trading, portfolio...
- Assessment Framework: Firms must implement standardized tests and processes to verify staff qualifications, aligning with MiCA Article 62 on CASP authorization, focusing on technical crypto...
- No New Standalone Rules: This circular builds on prior CSSF MiCA circulars (e.g., 25/890 on crypto-asset classification), integrating competence checks into licensing dossiers and ongoing supervision.
Suggested Considerations
- Assess Staff Competence: Implement ESMA-guided evaluations (e.g., exams, certifications) for all relevant personnel handling crypto services; document results in governance frameworks.
- Update Policies and Training: Integrate competence criteria into HR, onboarding, and annual reviews; roll out MiCA-specific training on reporting, breaches, and governance.
- Licensing Dossier Enhancement: Include competence attestations in CSSF applications; appoint dedicated compliance/risk officers with verified qualifications.
- Ongoing Monitoring: Conduct regular audits, penetration tests, and incident planning; confirm compliance annually via management body statements.
- Early CSSF Engagement: Schedule dialogues and info sessions; create MiCA readiness scorecards for board and regulator discussions.
Key Dates
Circular CSSF 26/909 published; immediate application of ESMA competence guidelines.; [User-provided content]
Compliance Impact
Urgency: High – With publication today (1 April 2026) and MiCA's CASP regime live since 30 December 2024, firms face immediate supervisory scrutiny during licensing and VASP transitions ending 1 July 2026. Non-compliance risks authorization denial, enforcement, or operational halts, especially as CSSF audits dossiers for competence gaps amid Luxembourg's role as MiCA hub.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Crypto ExchangeBankFintech Press release 26/07
Bank
No description available.
Asset ManagerWealth ManagerBank
No description available.
BankWealth ManagerAll Firms
No description available.
BankWealth ManagerAsset Manager
Table listing the professional activities and the mandates performed
This CSSF publication is an updated table (in XLSX format) listing standardized professional activities and mandates for members of the management body/governing body and conducting officers, as required under points 105 and 107 of Circular CSSF 18/698. It matters because it ensures consistent, transparent reporting of senior personnel roles in Luxembourg investment fund managers (IFMs), supporting governance, conflict-of-interest management, and CSSF supervisory oversight. Compliance professionals must use this list to standardize disclosures in authorization files and ongoing reporting.
What Changed
- The document was originally published on 14 January 2019 and updated on 12 March 2026, reflecting revisions to the predefined list of professional activities and mandates[Source URL].
- Alignment with Circular CSSF 18/698 requirements for IFMs (management companies for UCIs and AIFs), specifying reportable roles like those in collective portfolio management, risk management,...
- Emphasis on detailed documentation of mandates to demonstrate fitness, properness, and avoidance of conflicts, including for shareholders with qualifying holdings.
- No entirely new requirements introduced, but the update likely incorporates evolving governance expectations, such as enhanced delegate oversight and AML/CFT compliance officer designations.
Suggested Considerations
- Download and use the XLSX table: Incorporate the exact list of activities/mandates into internal templates for reporting management body and conducting officer roles[Source URL].
- Update authorization and notification files: Include detailed CVs, criminal record extracts, wealth declarations, and organization charts for relevant personnel/shareholders; notify CSSF of changes (e.g., qualifying holdings, guarantees).
- Conduct fit-and-proper assessments: Ensure declarations cover all listed mandates, demonstrating no conflicts and adequate resources; perform initial/ongoing due diligence on delegates.
- Annual compliance review: Document roles in compliance monitoring plans, training, and reporting to senior management/CSSF; align with delegate oversight (e.g., risk-based monitoring of compliance, audit functions).
- Policy updates: Revise governance policies to reflect the updated list, including AML/CFT officer designations and own funds proofs.
Key Dates
- Publication of underlying Circular CSSF 18/698, setting baseline requirements
- Original publication of the list
- Latest update to the list, requiring immediate review and integration into reporting processes[Source URL]
financial year); - Compliance deadline for Circular 18/698 obligations, including governance reporting (e.g., 5 months after year-end)
Compliance Impact
Urgency: High – The March 12, 2026 update coincides with today's date, demanding immediate review to avoid supervisory findings during CSSF inspections or authorization processes. Non-compliance risks authorization delays, fines, or reputational damage, as Circular 18/698 emphasizes robust governance in a heightened scrutiny environment for IFMs (e.g., delegate oversight, AML).
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerBankAll Firms
Administrative sanction imposed on a réviseur d’entreprises agréé
The CSSF imposed an administrative sanction on 2 December 2025 against an approved statutory auditor (*réviseur d’entreprises agréé*) for breaches of professional obligations, likely related to continuing education requirements under Luxembourg's Audit Law, mirroring patterns in recent similar cases. This enforcement action underscores the CSSF's rigorous oversight of audit professionals, emphasizing compliance with ongoing training mandates to maintain audit quality and market integrity. Compliance professionals should note it as evidence of heightened scrutiny on non-delegable professional duties.
What Changed
This is not a regulatory change or new requirement but an enforcement action applying existing rules under point f) of Article 43(1) read with point a) of Article 43(2) and Article 44 of the Law of 23 July 2016 on the audit profession (Audit Law), alongside CSSF Regulation N°16-10 on continuing education.
Suggested Considerations
- Immediate self-audit: Statutory auditors must verify personal compliance with continuing education hours under CSSF Regulation N°16-10, documenting hours against Article 3(1) requirements and submitting evidence if requested.
- Remediation plan: If shortfalls identified, complete deficit training promptly and notify CSSF of corrective measures, as seen in related governance cases where entities implemented remediation.
- Internal training programs: Audit firms should enhance monitoring of auditor CPE (continuing professional education) logs, integrating CSSF controls akin to Article 10 of the Audit Law.
- Fit-and-proper reviews: Boards and compliance officers assess auditor qualifications, escalating any gaps to CSSF per professional obligations.
- Record retention: Maintain verifiable CPE records for at least the reference period plus CSSF inspection windows (typically 3-5 years).
Key Dates
- Likely reference period end for continuing education non-compliance (inferred from identical prior case)
- Date of administrative sanction imposition by CSSF
- Publication date of the sanction notice (today's date, aligning with CSSF practice for transparency under Article 48(2) of the Audit Law)
Compliance Impact
Urgency: Medium. This matters as a signal of CSSF's proactive controls on auditor CPE, with fines starting at EUR 1,500 for initial breaches but scaling with severity/duration; repeated actions (e.g., multiple 2025 sanctions) indicate rising enforcement tempo, risking broader audit ecosystem scrutiny. Affected parties face direct fines and reputational harm, while others must prioritize CPE to avoid chain-reaction liabilities in financial reporting.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
All Firms
Administrative sanction imposed on a réviseur d’entreprises agréé
The CSSF imposed an administrative sanction on 2 December 2025 against an approved statutory auditor (*réviseur d’entreprises agréé*) for breaches of professional obligations, likely related to continuing education requirements under Luxembourg's Audit Law, mirroring patterns in recent similar cases. This enforcement action underscores the CSSF's rigorous oversight of audit professionals, emphasizing compliance with ongoing training mandates to maintain audit quality and market integrity. Compliance professionals should note it as evidence of heightened scrutiny on non-compliance with minimum continuing education hours.
What Changed
No new regulatory changes are introduced; this is an enforcement action applying existing rules under point f) of Article 43(1) read with point a) of Article 43(2) and Article 44 of the Law of 23 July 2016 concerning the audit profession (Audit Law), alongside CSSF Regulation N°16-10 on continuing education for statutory auditors. Breaches typically involve failing to meet the minimum total hours of continuing education by the reference period end (e.g., December 31, 2024, as in a comparable August 2025 case).
Suggested Considerations
- Statutory auditors must immediately verify compliance with Article 3(1) of CSSF Regulation N°16-10, ensuring minimum continuing education hours are met for relevant periods.
- Audit firms should conduct internal audits of training logs and implement remediation plans, including supplementary training if deficits exist.
- All affected parties must report any identified breaches to CSSF proactively and retain evidence of corrective actions, as CSSF controls under Article 10 of the Audit Law can trigger fines.
Key Dates
- Reference period end for continuing education compliance (inferred from similar case)
- Date of administrative sanction imposition by CSSF
- Publication date of the sanction notice
Compliance Impact
Urgency: Medium. This matters due to the pattern of CSSF enforcement on audit continuing education (e.g., EUR 1,500 fine in August 2025 case for similar breaches), signaling ongoing supervisory controls that could expand to on-site inspections. Non-compliance risks fines, public naming (or anonymous publication per Article 48(2) Audit Law), and reputational damage, but lacks immediate firm-wide deadlines, reducing to medium urgency for proactive reviews.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
All Firms
No description available.
BankWealth ManagerAll Firms
Administrative sanction imposed on an investment firm
The CSSF imposed an administrative sanction on 8 October 2025 against an unnamed investment firm, as detailed in a publication released on 4 March 2026. This enforcement action underscores CSSF's rigorous oversight of investment firms, particularly in areas like AML/CFT compliance, conduct rules, and organizational requirements, serving as a warning for similar entities to strengthen cooperation and internal controls. It matters because it highlights escalating fines for repeated or material breaches, potentially influencing supervisory expectations across Luxembourg's financial sector.
What Changed
- No new regulatory changes or requirements are introduced; this is an enforcement action applying existing rules.
- Failure to cooperate with CSSF requests, e.g., not submitting required AML/CFT questionnaires by deadlines, violating Article 5(1) of the amended Law of 12 November 2004 on AML/CFT.
- Non-compliance with investment policies, organizational requirements, or conduct rules under the UCI Law (e.g., Articles 41, 43, 109), including improper broker exposures or valuation failures.
- These reflect ongoing enforcement of established frameworks like the AIFM Law, UCI Law, and AML/CFT Law, with fines calibrated by factors like breach duration, firm size, cooperation level, and prior...
Suggested Considerations
- Enhance cooperation protocols: Implement automated tracking for CSSF requests (e.g., questionnaires) with escalations for reminders; document all responses.
- Review investment compliance: Audit broker exposures, valuation processes, and subscription/redemption controls against UCI Law Articles 41-43, 109; suspend dealings if uncertainties arise.
- Strengthen governance: Conduct gap analyses on internal controls, risk assessments, and reporting for depositary/oversight functions per AIFM Law Article 19(9) and CDR 231/2013.
- Training and monitoring: Roll out firm-wide training on AML/CFT obligations (Article 5(1)) and perform reconciliations of assets/records; prepare for on-site/off-site CSSF inspections.
- Self-reporting: Proactively disclose prior breaches to mitigate fine severity.
Key Dates
- Date of prior depositary oversight fine
- Deadline for submitting CSSF AML/CFT Questionnaire (breach example from similar case)
- Date of fine imposition for UCITS investment policy breaches
- Date of fine imposition in comparable AIFM non-cooperation case
- Date of the sanction in question
Compliance Impact
Urgency: High - This matters due to CSSF's pattern of publicizing nominative sanctions (e.g., Max Gain Capital, Zeus Asset Management), signaling increased scrutiny on investment firms amid AML/CFT and conduct risks. Fines (EUR 10,000–127,500) represent material hits (up to 10% of turnover), with factors like poor cooperation amplifying penalties; firms with similar exposures face elevated inspection risk, especially post-2025 enforcement wave.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerBroker DealerWealth Manager
No description available.
The CSSF published guidance on 2 March 2026 specifying minimum documents and information required for assessing shareholding structures of authorised Investment Fund Managers (IFMs) during initial authorisation and subsequent modifications, covering both qualified and non-qualified shareholders. This matters because incomplete submissions will not be processed, potentially delaying authorisations or amendments amid ongoing CSSF scrutiny of governance and ownership in Luxembourg's fund sector.
What Changed
- - Minimum Document Requirements: Establishes a mandatory list of documents for each new shareholder candidate, differentiated by type (e.g., natural person, legal person, beneficial owner,...
- Additional Mandatory Submissions: For changes involving qualified holdings (entry, increase/decrease, removal), requires updated group structure charts, MEF (in some cases), financing information,...
- Enforcement Mechanism: From 2 March 2026, applications lacking these minimums are deemed incomplete, halting analysis until fully submitted.
- No prior formalised list existed in this detail for IFMs, shifting from case-by-case to standardised requirements.
Suggested Considerations
- Review Guidance: Download and study the XLSX document (Version 1.0) detailing per-shareholder/per-change requirements.
- Prepare Complete Packages: For initial authorisation or amendments, compile minimum docs (e.g., IDs for beneficial owners/PEPs, group charts, financing details, MEF, fees); use *MEF templates where noted.
- Submit Fully: Ensure all minimums included in future filings to avoid delays; anticipate CSSF requests for extras.
- Internal Processes: Update compliance checklists, train teams on shareholder due diligence, and integrate into authorisation workflows.
Key Dates
Publication and effective date; Guidance applies immediately; incomplete applications received on/after this date will not start processing until complete
Compliance Impact
Urgency: High – Effective immediately on publication (2 March 2026), with strict non-processing of incomplete files risking significant delays in time-sensitive authorisations/amendments. Matters for maintaining operational timelines in competitive fund markets, where CSSF oversight of IFM ownership ties to broader governance expectations (e.g., board composition, qualifications).
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset Manager
Version 1.0
This CSSF guidance (Version 1.0, published 2 March 2026) specifies the minimum documents and information required for assessing shareholding structures of authorised Investment Fund Managers (IFMs) during initial authorisation or modifications involving qualified and non-qualified shareholders. It standardises submissions to ensure completeness, with incomplete applications rejected until fully provided, enhancing regulatory efficiency and scrutiny of ownership changes. Compliance professionals must prioritise this to avoid delays in authorisation processes for Luxembourg-domiciled IFMs.
What Changed
- - Minimum Document Lists: Introduces detailed checklists in an XLSX format covering candidate shareholder documents (e.g., ID, CV, declarations of honour (DH), criminal records (CR) for natural...
- Differentiation by Shareholder Type: Requirements vary by natural/legal person, beneficial owner, direct/indirect qualified/unqualified shareholders, and involvement in financing (e.g., "Yes, if PEP...
- Other Mandatory Submissions: For qualified holding changes (entry, increase/decrease, removal), requires updated group structure charts, Market Entry Forms (MEF), financing details, and fee forms;...
- Enforcement Mechanism: From 2 March 2026, incomplete submissions halt analysis until remedied; CSSF may request additional info.
Suggested Considerations
- Prepare Complete Packages: For each new shareholder candidate, compile type-specific docs (e.g., ID/CV/DH/CR for direct unqualified shareholders; financing proof if indirect qualified lacks resources).
- Submit Core Items: Always include updated group structure chart, MEF (template available), acquisition financing details, fee form; classify request type (e.g., prior authorisation for qualified changes).
- Initial/Modification Filings: Use XLSX guidance as checklist; ensure beneficial owner verification per Circular CSSF 19/732.
- Ongoing: Notify CSSF of changes; anticipate ad-hoc requests for extras like PEP declarations.
Key Dates
Publication and immediate applicability; New guidance effective; incomplete applications received on/after this date not processed until complete
Compliance Impact
Urgency: High – Immediate effect from 2 March 2026 means any ongoing or planned IFM authorisation/modification applications risk delays or rejection if non-compliant, potentially disrupting fund launches or ownership restructurings in Luxembourg's key investment management hub. Matters due to standardised scrutiny on fit-and-proper ownership, aligning with AIFMD governance and reducing administrative back-and-forth.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset Manager
Exigences applicables au réviseur d’entreprises agréé spécial auprès des établissements de crédit émetteurs de lettres de gage
Circular CSSF 26/907, published on February 18, 2026, establishes requirements for **approved special statutory auditors (réviseurs d'entreprises agréés spéciaux) serving credit institutions that issue mortgage bonds (lettres de gage)**. This circular formalizes the governance and audit standards applicable to a specialized auditor role within Luxembourg's credit institution framework, ensuring enhanced oversight of entities engaged in mortgage bond issuance.
What Changed
- The search results provided do not contain the full text of Circular CSSF 26/907, as it is available only in French and the PDF content was not included in the available materials.
- Statutory auditor qualifications and requirements for the specialized role of approving auditors (réviseurs agréés spéciaux) overseeing credit institutions that issue mortgage bonds
- Governance standards for auditors in this specialized capacity
- Audit and oversight responsibilities specific to mortgage bond issuance activities
The circular aligns with broader Luxembourg regulatory modernization efforts evident in concurrent CSSF guidance,...
Suggested Considerations
- *Obtain and review the full French text of Circular CSSF 26/907 from the CSSF website
- *Assess current auditor qualifications against the new requirements for approved special statutory auditors
- *Update audit engagement letters and terms to reflect any new standards or responsibilities
- *Document compliance with the circular's requirements in governance and audit files
- *Communicate with appointed auditors to ensure alignment with the new framework
Key Dates
- Circular CSSF 26/907 published
in available search results; firms should consult the full French text for any transition periods or effective dates
Compliance Impact
Urgency: HIGH
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Bank
No description available.
BankAsset ManagerWealth Manager
AML/CFT standardised data collection taking place in 2026
The CSSF Circular Letter 2026-02-12 announces a standardized data collection exercise on AML/CFT for supervised entities, scheduled for 2026, aimed at enhancing regulatory oversight of money laundering and terrorist financing risks. This matters because it signals intensified CSSF scrutiny on AML/CFT compliance, requiring firms to prepare structured data submissions that could inform future supervisory actions, risk assessments, and enforcement. As part of broader CSSF AML/CFT initiatives, non-compliance risks fines or heightened inspections.
What Changed
- - Introduction of standardized AML/CFT data collection: CSSF mandates uniform reporting formats for collecting data on AML/CFT risks, controls, and practices across supervised sectors, building on...
- Alignment with ongoing AML/CFT enhancements: Complements recent governance-focused circulars (e.g., Circular 26/906 on central administration and risk management for payment/e-money institutions) by...
- No explicit new obligations beyond preparation for data submission, but implies deeper integration of tax-related AML indicators and sub-sector risk updates, as seen in related CSSF activities.
Suggested Considerations
- Assess and document AML/CFT data readiness: Inventory current risk assessments, transaction monitoring logs, KYC processes, SAR filings, and third-party oversight records in standardized formats; map to proportionality factors (e.g., transaction volumes, outsourcing).
- Update governance and controls: Ensure compliance functions have independence, direct board reporting, and audit coverage of AML/CFT; test ICT resilience for monitoring continuity.
- Conduct internal reviews: Perform gap analyses against Circular 26/906 (e.g., fund safeguarding, escalation protocols) and recent conference topics (e.g., terrorist financing, tax indicators); remediate deficiencies with board-approved plans.
- Prepare for submission: Designate resources for data compilation; cooperate fully with CSSF/FIU requests, including transfer-of-funds information under EU 2015/847.
- Engage auditors: Leverage approved auditors for validation of AML/CFT effectiveness ahead of collection.
Key Dates
AML/CFT standardised data collection exercise; Firms must submit required data during this period; preparation recommended immediately given today's date (12 February 2026)
Issuance of related Circular 26/906; Establishes governance baselines (e.g., compliance independence, risk proportionality) informing data collection expectations
CSSF AML/CFT Conference for Specialised PFS; Provided updates on sub-sector risks, terrorist financing reviews, and FIU insights relevant to data preparation
Conference materials published; Available for download to guide compliance alignment
Compliance Impact
Urgency: High – With data collection in 2026 underway today (12 February 2026), firms face immediate preparation needs amid recent enforcement (e.g., EUR 102,000 fine on depositary for AML-related gaps) and conferences signaling sub-sector focus. This elevates AML/CFT as a supervisory priority, potentially triggering on-site inspections, fines, or remediation orders for inadequate data/risks; proactive alignment prevents escalation in a risk-based regime.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankPayment ProviderAll Firms
No description available.
This CSSF communiqué announces the availability of updated UCI Reports (SAQ, SR, and ML) under Circular CSSF 21/790 on the eDesk platform's CISERO module for specific 2026 year-ends, with key enhancements focused on valuation, NAV determination, and risk-based streamlining. It matters for Luxembourg UCIs as it reflects evolving supervisory priorities, aligns with EU directives like Directive (EU) 2024/927, and imposes refined self-assessment obligations to bolster resilience in stressed conditions and liquidity management.
What Changed
- - SAQ Updates (Valuation Section): New questions on valuation policies for stressed market conditions/exceptional circumstances; coverage for new sub-funds/strategies; independent validation of...
- SAQ Simplifications and Clarifications: Removed questions on sub-funds with significant non-standard OTC derivatives, unquoted assets, or external valuer OTC FDIs (including NAV proportions); refined...
- SAQ NAV Determination: Updated Liquidity Management Tools (LMTs) sub-section to align with Annexes of AIFM/UCITS Review Directive (Directive (EU) 2024/927); added question on compliance with ESMA...
- SR Streamlining: Removed procedures in investment compliance (e.g., eligibility assessments for closed-ended funds, structured instruments, non-plain vanilla OTC derivatives; credit quality for money...
- Reports for year-ends after 30 April 2026 available three months prior.
Suggested Considerations
- Access updated Reports on eDesk CISERO module immediately and review changes vs. 31 December 2025 versions.
- Update valuation policies/procedures to explicitly cover stressed conditions, new sub-funds/strategies, model validations, and backtesting; document compliance.
- Revise NAV processes for LMT alignment with Directive (EU) 2024/927 Annexes and ESMA performance fee guidelines; confirm for open-ended UCIs.
- Dirigeants/management: Complete/validate SAQ addressing new/clarified questions; prepare for REA SR/ML review.
- REAs: Perform streamlined SR procedures; issue ML on prior weaknesses with remediation timelines.
Key Dates
Reports (SAQ, SR, ML) made available on eDesk CISERO for year-ends 31 January, 28 February, 31 March, 30 April 2026
Entry into application of AIFM/UCITS Review Directive LMT requirements
end +5 months (UCITS/Part II UCIs); SAQ/SR submission deadline
end +6 months (SIFs/SICARs); SAQ/SR submission deadline
end (post-30 April 2026); Future Reports availability
Compliance Impact
Urgency: High – Immediate access required for imminent submissions (e.g., 31 January 2026 year-end due ~June 2026); new valuation questions demand policy reviews to avoid supervisory findings, especially amid stressed markets; SR simplifications reduce burden but shift focus to SAQ self-assessment, heightening dirigeants' accountability. Non-compliance risks CSSF follow-up on modified audits or weaknesses, per Circular 21/790.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset Manager
Administrative sanction imposed on Corestate Capital Holding S.A.
The CSSF published an administrative sanction on 6 February 2026 against Corestate Capital Holding S.A., likely for breaches in regulatory compliance such as depositary duties, oversight, or governance under Luxembourg financial laws, marking a repeat enforcement action following a prior sanction in June 2025. This matters for compliance professionals as it underscores CSSF's aggressive enforcement on alternative investment fund managers (AIFMs) and depositaries, signaling heightened scrutiny on safekeeping, oversight, and internal controls to prevent systemic risks in Luxembourg's fund sector. It highlights the regulator's willingness to impose public nominative sanctions, amplifying reputational damage alongside fines.
What Changed
No new regulatory changes or requirements are introduced; this is an enforcement action enforcing existing obligations under laws like the AIFM Law of 12 July 2013 (e.g., Articles 19(8), 19(9), 19(11) on safekeeping and oversight duties), the Law of 5 April 1993 on the financial sector, and Commission Delegated Regulation (EU) No 231/2013 (CDR 231/2013, e.g., Articles 92, 94, 96 on risk assessment, valuation verification, and cash flow monitoring).
Suggested Considerations
- Conduct immediate gap analysis: Review safekeeping processes for ownership verification (Article 19(8)(b) AIFM Law), ensuring transaction documentation, segregated account proofs, and full holding chain records are available at transaction points.
- Enhance oversight duties: Implement risk assessments per Article 92(1) CDR 231/2013, valuation compliance checks (Article 94), and cash remittance monitoring (Article 96); appoint delegates with due diligence.
- Strengthen governance: Update internal controls, procedures, and conflict-of-interest policies (e.g., director overlaps); ensure key documentation availability and evidence of controls.
- Firm-wide audit: For repeat offenders like Corestate, perform root-cause analysis on prior sanctions and submit remediation plans to CSSF if inspected.
- Training and reporting: Train staff on CSSF expectations; improve cooperation mechanisms to avoid AML/CFT fines for non-submission of requests.
Key Dates
- Prior administrative sanction imposed on Corestate Capital Holding S.A., indicating ongoing non-compliance issues
- Publication date of the current administrative sanction on Corestate Capital Holding S.A., effective immediately as a public enforcement notice
Compliance Impact
Urgency: High – This represents CSSF's pattern of public nominative fines (e.g., EUR 102,000 on JTC for depositary breaches, EUR 10,000 on Capitalis for AML non-cooperation), with escalation risks for repeat violations like Corestate's back-to-back sanctions. It matters due to Luxembourg's dominance in European fund assets (over EUR 5 trillion), where governance lapses can trigger outflows, license revocation, or cross-border ESMA scrutiny; firms must act preemptively to mitigate fines (typically EUR 10,000–102,000) and reputational harm from nominative publication.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerAll Firms
Administrative sanction imposed on Corestate Capital Holding S.A.
The CSSF published an administrative sanction on 6 February 2026 against Corestate Capital Holding S.A., likely imposing a fine for regulatory breaches, marking a repeat enforcement action following a prior sanction on the same entity dated 20 June 2025. This matters as it underscores CSSF's intensified supervisory scrutiny on Luxembourg-based investment managers, particularly regarding governance, asset safekeeping, and oversight duties under AIFM Law, signaling heightened enforcement risks for similar firms. Compliance teams should review it for patterns in depositary and transparency violations evident in recent CSSF cases.
What Changed
No new regulatory changes or requirements are introduced; this is an enforcement action highlighting non-compliance with existing obligations under Luxembourg's AIFM Law (notably Articles 19(8), 19(9), 19(11), and 51) and related delegated regulations like CDR 231/2013. Key breaches from analogous recent CSSF sanctions include inadequate safekeeping of assets (e.g., missing ownership verification and records), failure to oversee AIFM valuation policies and cash remittance timelines, improper delegation to custodians without due diligence, and weak internal governance such as conflicts of...
Suggested Considerations
- Conduct immediate gap analysis on depositary functions: Verify ownership chains, transaction documentation, segregated account reconciliations, and custodian delegations per AIFM Law Articles 19(8) and 19(11).
- Enhance oversight processes: Implement risk assessments for AIF strategies, valuation policy checks, and cashflow monitoring per CDR 231/2013 Articles 92, 94, and 96.
- Strengthen governance: Review internal controls, procedures, and conflicts (e.g., director overlaps with affiliates); ensure availability of control evidence.
- For issuers like Corestate: Confirm compliance with half-yearly financial reporting and dissemination under Transparency Law Article 4.
- Firm-wide: Perform mock CSSF on-site inspections focusing on 2022-2025 periods, given inspection timelines in recent cases.
Key Dates
- Prior administrative sanction imposed on Corestate Capital Holding S.A
- Publication date of the current administrative sanction on Corestate Capital Holding S.A
Compliance Impact
Urgency: High – This represents repeat enforcement on Corestate (second sanction in under a year), aligning with CSSF's pattern of nominative publications for severe, ongoing breaches in depositary and governance areas, as seen in JTC (EUR 102,000 fine for similar safekeeping/oversight failures) and BigRep SE (EUR 10,000 for reporting lapses). It elevates risks of fines, reputational damage, and market jeopardy assessments under AIFM Law Article 51, urging preemptive remediation amid CSSF's active 2023-2026 inspection cycle.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerAll Firms
Press release 26/03
BankWealth Manager
Administrative sanction imposed on Genève Invest (Europe) S.A.
The CSSF imposed an administrative sanction on 23 July 2025 against Genève Invest (Europe) S.A., a Luxembourg-regulated entity, for breaches of professional obligations, as detailed in a publication released on 4 February 2026. This enforcement action underscores the CSSF's focus on robust internal controls and compliance with investment rules, serving as a warning to investment firms on the consequences of organizational and conduct failures. Compliance professionals should note it as evidence of heightened CSSF scrutiny on fund managers handling client assets and counterparties.
What Changed
This is not a regulatory change or new requirement but an enforcement action highlighting existing obligations under Luxembourg law. Key breaches likely mirror patterns in recent CSSF sanctions, such as non-compliance with UCI Law provisions on investment policies (e.g., Articles 41, 43), sound accounting procedures (Article 109), and rules of conduct (Articles 111, CSSF Regulation 10-04), including improper cash deposits with unauthorized brokers and inaccurate asset valuation.
Suggested Considerations
- Immediate review of counterparty due diligence: Verify licenses and financial stability of brokers/prime brokers; cease deposits with unauthorized or suspended entities per UCI Law Article 41.
- Enhance valuation and accounting controls: Ensure assets (e.g., cash deposits) are valued at probable realization value per Article 28(4) UCI Law and prospectus terms; implement automated monitoring for ongoing compliance.
- Conduct internal audits: Assess organizational requirements, investment policies, and conduct rules (CSSF Regulation 10-04); remediate gaps proactively, as seen in mitigated sanctions for cooperative firms.
- Update governance and reporting: Document risk assessments and report prior breaches to CSSF to demonstrate cooperation, potentially reducing fine severity.
Key Dates
- Date of administrative sanction imposition on Genève Invest (Europe) S.A
- Publication date of the sanction document by CSSF
Compliance Impact
Urgency: High – This sanction, published today (4 February 2026), signals ongoing CSSF off-site and on-site probes into fund operations, similar to fines imposed in July 2025 on Zeus Asset Management (€18,136 for UCI breaches) and a bank (reprimand for AML gaps). It matters due to escalating enforcement—fines calibrated to turnover (e.g., 10% in Zeus case)—and risks of reputational damage, especially for wealth managers with broker exposures. Non-compliance could trigger investigations, as CSSF considers infringement duration, cooperation, and history.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerWealth ManagerAll Firms
No description available.
BankWealth ManagerAsset Manager
No description available.
CSSF Circular 26/906, published on 20 January 2026, establishes detailed requirements for central administration, internal governance, and risk management for payment institutions (PIs) and electronic money institutions (EMIs) in Luxembourg, repealing prior circulars IML 95/120, IML 96/126, IML 98/143, and CSSF 04/155. It clarifies application of the amended Law of 10 November 2009 on payment services, emphasizing robust governance amid sector growth to ensure safety, efficiency, and trust. This matters for compliance as it mandates comprehensive reviews and updates to governance frameworks by mid-2026, addressing rising transaction volumes.
What Changed
- The circular consolidates and updates governance rules, focusing on:
- Management bodies: Responsibilities, composition, qualifications, organization, and functioning, including CSSF authorization of members based on professional experience, standing (e.g., police...
- Internal control functions: Responsibilities, characteristics, organization, and execution of work for compliance officers and internal auditors, with notifications to CSSF including detailed...
- Conflicts of interest: Key requirements for a management policy applicable to all staff and management body members.
- New product approval: Defined key steps in the process.
Suggested Considerations
- Gap analysis: Assess current frameworks against circular requirements on management bodies, internal controls, conflicts of interest, product approval, and fund safeguarding.
- Updates and notifications: Review/revise governance arrangements (e.g., policies, structures); notify CSSF of management body members, compliance officers, and internal auditors with required documentation (professional experience, police records, etc.).
- Implementation: Establish robust risk identification/management/monitoring/reporting processes, internal controls, and proportional arrangements (e.g., IT, outsourcing).
- Documentation: Develop conflicts policy, new product approval procedures, and safeguarding rules; ensure management body authorization.
- Ongoing: Maintain sound/prudent management amid growth; integrate with Law of 10 November 2009 requirements.
Key Dates
- Publication date of Circular CSSF 26/906
- Compliance deadline: Institutions must assess/review central administration, internal governance, and risk management frameworks to ensure full compliance
Compliance Impact
Urgency: High - With ~5 months from publication (20 Jan 2026) to compliance (30 Jun 2026), firms face tight timelines for assessments, policy overhauls, and CSSF notifications, especially given repealed circulars and sector growth pressures. Non-compliance risks supervisory actions, as this fosters "sound and prudent management" in a high-volume industry; proactive reviews are essential to avoid disruptions.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Payment ProviderFintech
Central administration, internal governance and risk management
Circular CSSF 26/906, published on 20 January 2026, consolidates and clarifies Luxembourg's rules on central administration, internal governance, and risk management specifically for payment institutions, electronic money institutions, and account information service providers. It repeals prior circulars (IML 95/120, IML 96/126, IML 98/143, and CSSF 04/155) to address growth in transaction volumes by mandating robust governance, control functions, and risk processes, enhancing safety, efficiency, and trust in these services. This matters for compliance professionals as it strengthens defenses against financial crime, operational risks, and supervisory scrutiny in a high-growth sector.
What Changed
- - Consolidation and repeal: Replaces outdated circulars with unified requirements under the amended Law of 10 November 2009 on payment services, covering central administration (decision-making must...
- Governance enhancements: Board approves strategy, risk appetite, AML/CFT policies, outsourcing, and information security; management implements via procedures; proportionality based on business...
- Operational controls: Strict access to systems (need-to-know, least-privilege, 4-eyes validation); counterparty due diligence for custodians/insurers; full responsibility for agents, distributors,...
- AML/CFT focus: Elevates compliance function independence, direct board reporting, risk-based resourcing, and oversight of third parties/opaque structures to close gaps exploited by criminals.
Suggested Considerations
- Assess and update governance frameworks: Review central administration location, board/management responsibilities, risk strategy, AML/CFT policies, compliance charter, and funds safeguarding principles to align with the circular.
- Confirm control functions: Ensure compliance function (CCO) has independence, resources, direct board access, and authority for investigations; justify/secure CSSF approval for part-time/dual roles.
- Implement operational safeguards: Establish daily reconciliations (or justified weekly), segregation/insurance for client funds, system access controls (4-eyes, board validation for significant movements), and third-party due diligence/monitoring.
- Document proportionality: Tailor governance to business risks (staff, volumes, products, outsourcing); update new product approval, conflicts policies, and business continuity/incident reporting.
- Retain records and report: Board-approve all key policies; prepare for CSSF inspections on outsourcing (per Circular CSSF 22/806) and ICT risks.
Key Dates
Publication date of Circular CSSF 26/906
Compliance deadline; Institutions must assess, review, and ensure their central administration, internal governance, and risk management frameworks fully comply with the circular
Compliance Impact
Urgency: High – With a 30 June 2026 deadline (five months from publication), firms face immediate pressure to review and remediate governance gaps amid sector growth and heightened AML/CFT scrutiny; non-compliance risks supervisory actions, fines, or license issues, especially as it closes criminal exploitation vectors like weak controls and third-party risks.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Payment Provider
Application of the Guidelines of the European Banking Authority on the management of environmental, social and governance (ESG) risks (EBA/GL/2025/01)
Circular CSSF 26/905 mandates the application of EBA Guidelines (EBA/GL/2025/01) on managing **ESG risks** for Luxembourg-supervised institutions, requiring integration of environmental, social, and governance risk identification, measurement, management, and monitoring into internal processes. This aligns with CRD amendments (Articles 74, 76, 87a) and emphasizes proportionality to institutions' business models, with plans including timelines, targets, and milestones toward EU climate goals like net-zero by 2050. It matters for compliance as it embeds ESG into prudential supervision, potentially impacting capital, risk frameworks, and supervisory reviews.
What Changed
- - Institutions must establish proportionate strategies, policies, processes, and systems for ESG risk management, covering short-, medium-, and long-term horizons, including transition and physical...
- Develop plans per Article 76(2) CRD with specific timelines, intermediate quantifiable targets, and milestones to address ESG financial risks, consistent with EU objectives (e.g., 55% GHG reduction...
- Incorporate ESG into internal governance, risk appetite, and supervisory review processes (SREP), with scenario analysis requirements (to be detailed in future EBA guidelines).
- Applies minimum standards and methodologies for ESG risk identification, measurement, monitoring, and impact assessment on institutions' exposures.
- No requirement for full alignment with specific sustainability trajectories, but plans must consider transition risks and institutions' ESG product offerings, loan policies, and targets.
Suggested Considerations
- Map and integrate ESG risks into governance, risk management frameworks, and business strategies, proportionate to scale/risk exposure.
- Develop and document ESG risk management plans with quantifiable targets, milestones, timelines, and scenario analyses (broad requirements now; detailed later).
- Conduct assessments of ESG risks in portfolios, including sustainability products, transition finance, and loan origination policies, for SREP submission.
- Embed in internal processes per Articles 74, 76, 87a CRD: identify/measure ESG risks (minimum standards), monitor over time horizons, and report to CSSF.
- Review and update existing policies/systems for compliance by applicable dates; prepare for CSSF supervisory evaluation of plan robustness.
Key Dates
- Circular published by CSSF
- Application date for Less Significant Institutions (other than SNCIs)
- Application date for SNCIs (dependent on CRD transposition)
Compliance Impact
Urgency: High - With application starting 1 April 2026 (just over 2 months from publication), firms face immediate pressure to gap-analyze current ESG frameworks against EBA standards, especially for SREP integration and long-term risk planning. Non-compliance risks supervisory scrutiny, capital add-ons, or enforcement, as ESG is now a core prudential pillar amid EU sustainability push; smaller institutions get a head-start but must act swiftly given proportionality demands.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankAll Firms
2026 update
BankWealth ManagerFamily Office
Administrative sanction imposed on the alternative investment fund manager Max Gain Capital S.à r.l. (“AIFM”)
The CSSF imposed a €10,000 administrative fine on Max Gain Capital S.à r.l., an alternative investment fund manager, on 11 September 2025 for failing to submit a mandatory annual financial crime questionnaire by the April 2025 deadline. This enforcement action demonstrates the CSSF's active monitoring of AML/CFT compliance obligations and its willingness to sanction non-cooperation, even for procedural failures unrelated to substantive money laundering violations.
What Changed
- This is not a regulatory change but rather an enforcement action clarifying existing obligations:
- Mandatory Annual Questionnaire Requirement: All CSSF-supervised professionals must submit an annual questionnaire on financial crime covering the preceding calendar year.
- Cooperation Obligation: Article 5(1) of the amended Law of 12 November 2004 on AML/CFT imposes a non-negotiable duty to cooperate with CSSF supervisory requests.
- Enforcement Escalation: The CSSF will issue reminders before imposing sanctions, but continued non-compliance triggers administrative fines under Article 8-4 of the AML/CFT Law.
Suggested Considerations
- regulated entities must:
- *Identify Reporting Obligations: Confirm whether your firm is subject to the annual financial crime questionnaire requirement under Article 5(1) of the AML/CFT Law
- *Calendar Management: Establish internal processes to ensure questionnaires are submitted by 4 April each year for the preceding calendar year
- *Documentation: Maintain records demonstrating timely submission and preserve evidence of compliance
- *Escalation Protocol: If unable to meet deadlines, proactively contact the CSSF to request extensions or clarification rather than ignoring reminders
Key Dates
- Deadline for submission of financial crime questionnaire for the year ending 31 December 2024
- CSSF issued two reminders to Max Gain Capital after the missed deadline
- CSSF imposed the €10,000 administrative fine
- CSSF published the administrative sanction decision
Compliance Impact
Urgency: HIGH
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerAll Firms
Administrative sanction imposed on JTC (Luxembourg) S.A.
The CSSF imposed a €102,000 administrative fine on JTC (Luxembourg) S.A. on 23 July 2025 for breaches in its professional obligations as a depositary of non-financial assets under the AIFM Law, identified during an on-site inspection from February 2023 to January 2024 covering activities up to December 2022. This enforcement action highlights CSSF's scrutiny of depositary functions, particularly risk assessment and oversight controls, serving as a warning for similar entities to strengthen compliance amid rising supervisory focus on AIFM depositaries.
What Changed
This is an enforcement action, not a regulatory change; it enforces existing requirements under Article 51(1) (1st and 7th indents) and Article 51(2) (1st sub-paragraph, 3rd indent) of the amended Law of 12 July 2013 on AIFMs (AIFM Law), and related provisions like Article 92(1) of Commission Delegated Regulation (EU) No 231/2013 (CDR 231/2013).
Suggested Considerations
- related entities) must:
- Conduct immediate gap analyses on risk assessment processes for AIF strategies and AIFM organization per Article 92(1) CDR 231/2013.
- Implement robust verification processes for AIFM compliance with asset delegation rules.
- Ensure availability of key documentation and evidence of controls for the depositary function, addressing pre-2022 gaps if applicable.
- Develop and test oversight processes, leveraging self-identified improvements and action plans as mitigating factors, as JTC did prior to inspection.
Key Dates
January 2024; Period of CSSF on-site inspection on depositary obligations, covering activities up to December 2022
Date CSSF imposed the €102,000 administrative fine on JTC (Luxembourg) S.A
Date of official CSSF publication announcing the sanction
Compliance Impact
Urgency: High – This matters due to the fine's size (€102,000), reflecting breach accumulation, severity, and duration, despite JTC's partial remediation; it signals intensified CSSF on-site scrutiny of depositary functions post-2023 inspections, with potential for higher penalties absent proactive controls. Depositaries face elevated enforcement risk, especially with unavailability of evidence pre-2022, urging swift remediation to avoid similar outcomes under Article 51 AIFM Law.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset Manager
Long Form Report – Practical rules concerning the self-assessment questionnaire to be submitted by investment firms – Mission and related reports of the réviseurs d’entreprises agréés (approved statutory auditors)
Broker DealerAll Firms
Update of Circular CSSF 24/853 on the Long Form Report (as amended by Circular CSSF 25/870) – Practical rules concerning the self-assessment questionnaire to be submitted by investment firms Mission and related reports of the réviseurs d’entreprises agréés (approved statutory auditors)
Circular CSSF 26/904 updates Circular CSSF 24/853 (as amended by Circular CSSF 25/870) by introducing a revised Long Form Report (LFR) for investment firms, featuring a digital self-assessment questionnaire (SAQ) and enhanced auditor reports focused on AML/CFT and risk management. This matters because it aligns reporting with CSSF's risk-based supervision under CSSF 4.0, reduces redundancies, applies proportionality based on business models, and mandates digital submission to improve efficiency and data analysis.
What Changed
- - Revised LFR Structure: Comprises four parts in a single digital document: (1) yearly SAQ completed by investment firms; (2) descriptive elements verified by approved statutory auditors (REAs); (3)...
- Digital Format: Completion and submission via CSSF's online portal, supporting CSSF 4.0 digital strategy for efficient processing.
- Proportionality and Scope: Applies individually to investment firms (no consolidated LFR if under CSSF consolidated supervision); focuses on incremental, relevant information tied to business models,...
- Enhanced AML/CFT Focus: Requires descriptions of commercial policy, ML/FT risk management, roles/responsibilities, branch/subsidiary/tied agent compliance; REA must assess adequacy of...
- REA Responsibilities: Verify/ensure adequacy of SAQ elements, assess descriptions, perform control procedures, and provide assessments on AML/CFT policy implementation across entities.
Suggested Considerations
- Investment Firms: Complete and submit the digital SAQ yearly via CSSF portal, providing descriptions of business model, ML/FT risks, commercial policy, monitoring, AML/CFT roles, and entity-level compliance; ensure data on fund transfers (e.g., missing payer/payee info) is included.
- REAs/Auditors: Verify SAQ adequacy, assess descriptions, perform corroborative controls, supplement with findings (e.g., AML/CFT audit declarations), independently assess ML/FT risks/organization, and integrate into single LFR document.
- General: Review existing processes for proportionality (focus on incremental info); update AML/CFT policies/documentation for branches/subsidiaries/tied agents; prepare for digital submission; document risk assessments thoroughly.
- Ongoing: Monitor compliance with related regs like Regulation (EU) 2023/1113 (effective 30 December 2024, per draft bill 8387).
Key Dates
- Applicability of revised LFR to all investment firms; submissions begin for this period onward on a yearly basis
- Yearly production required via CSSF portal; firms should align with existing annual reporting cycles for auditors (typically post-year-end)
Compliance Impact
Urgency: High - Applies immediately to FY ending 31 December 2024 reports, requiring swift updates to reporting processes, digital tools, and AML/CFT documentation amid CSSF's risk-based shift; non-compliance risks supervisory actions, as LFR directly informs CSSF oversight on key prudential/AML areas with no transition period specified.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerBroker DealerAll Firms
Update of Circular CSSF 24/850 on the practical rules concerning the descriptive report and the self-assessment questionnaire to be submitted on an annual basis by support PFS, as well as the engagement of the réviseurs d’entreprises agréés (approved statutory auditors) of support PFS and practical rules concerning the management letter and the separate report to be drawn up on an annual basis.
Circular CSSF 25/903 updates Circular CSSF 24/850, refining practical rules for support Professional of the Financial Sector (support PFS) in Luxembourg regarding their annual descriptive report, self-assessment questionnaire, and the roles of approved statutory auditors (réviseurs d’entreprises agréés). It specifies requirements for auditors' engagement, management letters, and separate annual reports. This matters for support PFS as it enhances supervisory oversight, ensures consistent reporting quality, and strengthens internal controls, directly impacting compliance and audit processes amid CSSF's focus on robust PFS supervision.
What Changed
- - Updates to Descriptive Report and Self-Assessment Questionnaire: Refines content, format, and submission requirements for support PFS's annual submissions, emphasizing more detailed disclosures on...
- Auditor Engagement Rules: Introduces specific practical guidelines for approved statutory auditors, including mandatory scope of work, independence confirmations, and standardized procedures for...
- Management Letter and Separate Report: Establishes detailed rules for auditors to issue an annual management letter (addressing findings, recommendations, and remediation) and a separate report for...
- Enhanced Documentation and Evidence: Requires support PFS and auditors to provide verifiable evidence (e.g., checklists, testing samples) supporting self-assessments, with stricter CSSF validation...
Suggested Considerations
- *Review and Update Processes: Support PFS must map current reporting against new templates in CSSF 25/903 and revise internal procedures for descriptive reports and self-assessments.
- *Engage/Confirm Auditors: Select or confirm approved statutory auditors compliant with new engagement rules; execute updated engagement letters incorporating circular requirements by Q4 2025.
- *Implement Templates and Testing: Adopt CSSF-provided templates for reports, management letters, and separate reports; conduct sample-based testing of controls as specified.
- *Training and Governance: Train compliance/audit teams on changes; ensure board approval of self-assessments and auditor findings.
- *Submit on Time: Prepare and file all documents by 30 April deadlines, retaining evidence for CSSF inspections.
Key Dates
Submission Deadline; Support PFS must submit descriptive report, self-assessment questionnaire, management letter, and separate auditor report to CSSF by 30 April following the financial year-end (first applicable: 30 April 2026 for FY 2025)
Preparation Milestone; Auditors must be engaged and initial scoping completed by year-end 2025 for FY 2025 compliance
Effective Date; Applies to annual reporting cycles starting for financial year 2025 onwards
Compliance Impact
Urgency: High. This is high urgency for support PFS due to the impending 30 April 2026 deadline for FY 2025 submissions, with non-compliance risking supervisory fines, license reviews, or reputational damage under CSSF's PFS enforcement regime. It matters as it tightens audit accountability, potentially increasing costs (e.g., auditor fees) while reducing reporting errors—critical for smaller support entities with limited resources.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
All FirmsFintechPayment Provider
Practical rules concerning the descriptive report and the self-assessment questionnaire to be submitted on an annual basis by support PFS.Engagement of the réviseurs d’entreprises agréés (approved statutory auditors) of support PFS and practical rules concerning the management letter and the separate report to be drawn up on an annual basis.
Circular CSSF 24/850, as amended by Circular CSSF 25/903, establishes practical rules for support Professional of the Financial Sector (support PFS) in Luxembourg to submit annual descriptive reports and self-assessment questionnaires, while also defining the roles of approved statutory auditors (réviseurs d’entreprises agréés) in issuing management letters and separate reports. This guidance standardizes supervisory reporting and audit processes to enhance oversight of support PFS, which provide essential back-office services to authorized PFS. It matters because non-compliance risks supervisory sanctions, reputational damage, and operational disruptions for entities reliant on support PFS structures.
What Changed
- - Standardized Reporting Templates: Introduces detailed formats and content requirements for the annual descriptive report and self-assessment questionnaire, covering governance, risk management,...
- Auditor Engagement Rules: Mandates approved statutory auditors to perform specific procedures, issue a management letter highlighting control weaknesses, and prepare a separate report confirming...
- Amendments via CSSF 25/903: Updates clarify submission procedures, expand self-assessment criteria (e.g., adding cybersecurity and outsourcing risk questions), and refine auditor independence...
- Frequency and Scope: Annual submissions required without exceptions; scope limited to support PFS (not primary PFS), emphasizing substance over form in service descriptions.
Suggested Considerations
- Annual Reporting Cycle:
1. By year-end, conduct internal self-assessment using the prescribed questionnaire template (available via CSSF portal).
- February to review submissions, test controls, and issue management letter (flagging deficiencies) plus separate compliance report.
- Governance Updates: Review and update internal policies on risk assessment, auditor selection, and remediation of management letter findings; ensure board oversight of submissions.
- Auditor Coordination: Verify auditor qualifications per CSSF register; implement any remediation plans from prior-year management letters before next cycle.
- Record-Keeping: Maintain 5-year audit trail of all supporting documentation for CSSF inspections.
Key Dates
- Effective date of original Circular CSSF 24/850
- Effective date of amendments in Circular CSSF 25/903, applicable to 2025 reporting cycle onwards
- Deadline for submission of descriptive report, self-assessment questionnaire, management letter, and separate auditor report to CSSF (first applicable for FY 2024 reporting due 31 March 2025)
- Support PFS must engage auditors and provide necessary data to enable timely report preparation
Compliance Impact
Urgency: High – This is a recurring annual obligation with a firm 31 March deadline, where delays trigger automatic CSSF notifications and potential fines (up to €250,000 per Law 1993). It matters for support PFS as it intensifies scrutiny on operational resilience in a post-SFI (2021) landscape, where CSSF prioritizes substance in delegated functions; failure risks de-authorization or client outflows. Early implementation of templates and auditor pipelines is essential to avoid first-year pitfalls.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankWealth ManagerAll Firms
Authorisation and organisation of entities acting as UCI administrators
Circular CSSF 22/811, as amended by Circular CSSF 25/900, establishes CSSF requirements for the authorisation, governance, internal organisation, and oversight of entities acting as UCI (Undertakings for Collective Investment) administrators in Luxembourg. It matters because it standardises practices amid regulatory, technological, and market evolutions, ensuring robust controls, risk management, and supervision for fund administration activities critical to Luxembourg's fund industry.
What Changed
- - Authorisation Requirements: Prior CSSF authorisation is mandatory for appointment as UCI administrator, via full application under sectoral laws or a simplified administrative procedure;...
- Scope of UCI Administration: Defines three core functions—registrar, NAV calculation/accounting, and client communication—requiring only one designated service provider per function per UCI (or...
- Governance and Controls: Mandates sound governance principles, control frameworks, escalation processes for errors/incidents, adequate resources (human, ICT), business continuity, and compliance with...
- Delegation Rules: Delegation of tasks allowed but not of monitoring/oversight; requires written contracts, due diligence, and prior CSSF notification (3 months generally, 1 month for certain agents);...
- Contracts and Reporting: Written contracts between UCI administrator and UCI/IFM; annual activity reporting due 5 months after financial year-end, starting from financial years ending post-30 June...
Suggested Considerations
- Submit authorisation application to CSSF with Annex A information before commencing UCI administration; notify substantial changes and keep file updated.
- Establish/implement governance, controls, escalation processes, resource adequacy, ICT/business continuity per circular; ensure single provider per function.
- For delegations: Conduct due diligence, execute written contracts detailing roles/obligations, notify CSSF in advance, retain oversight without delegating monitoring.
- Conclude written contracts with UCI/IFM; submit annual UCIA activity reports.
- UCIs/IFMs: Supervise coordinators, ensure information exchange/cooperation with administrators.
Compliance Impact
Urgency: High – Non-compliance risks CSSF sanctions, as authorisation is prior and ongoing; critical for Luxembourg fund ecosystem given evolutions in tech/markets/DORA. Firms must act promptly if unauthorised or misaligned, especially with annual reporting since 2023 and DORA integration; impacts operational models, delegations, and reporting immediately for active administrators.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
Asset ManagerBankAll Firms
Provisions relating to credit institutions and investment firms of EU origin established in Luxembourg by way of branches or exercising activities in Luxembourg by way of free provision of services
Circular CSSF 07/325, as amended by Circulars CSSF 21/765, CSSF 22/827, and most recently CSSF 25/898, establishes supervisory requirements for EU credit institutions and investment firms operating in Luxembourg via branches or free provision of services (FOPS). It matters for compliance professionals as it defines CSSF's host authority role, notification obligations, reporting, and enforcement powers, ensuring alignment with CRD and MiFID II while adapting to evolving EU rules.
What Changed
- - CSSF 21/765: Updated provisions following amendments to CSSF Regulation No 12-02, refining notification and operational requirements for branches and FOPS.
- CSSF 22/827: Further amendments to align with CRD and MiFID II changes, including enhanced notifications for programme alterations (e.g., one-month prior written notice for changes in operations,...
- CSSF 25/898: Latest update (noted in CSSF Newsletter No 298, November 2025), incorporating recent legal/regulatory developments, such as refined reporting via eDesk portal, AML/CFT compliance...
Suggested Considerations
- Notifications: Submit initial branch/FOPS notification to home authority (including operational programme); notify changes (e.g., services, locations) at least one month in advance to both home authority and CSSF.
- Reporting: Complete and sign SAQ (accurate, concise, true/fair view) via eDesk within six months post-year-end; provide REA-appraised AML/CFT and conduct reports, detailing branch procedures/controls.
- Supervision cooperation: Facilitate home/CSSF on-site inspections (with professional secrecy guarantees); ensure branch compliance with Luxembourg laws (e.g., LFS Article 46(2)).
- Ongoing: Maintain branch infrastructure, update for legal changes, and align with CSSF user guides for eDesk authentication.
Key Dates
- Notify CSSF and home authority in writing of programme changes (e.g., operations, services, additional places of business) per CRD Article 36(3) and MiFID II Article 35(10)
- Home state authority communicates notification file to CSSF for branch/FOPS establishment
end; - Submit electronically signed SAQ (via eDesk), annual AML/CFT and conduct of business report (per Circular CSSF 19/731, to be repealed by CSSF 25/902), reviewed by REA
Compliance Impact
Urgency: Medium - Matters due to recurring annual reporting (e.g., SAQ, AML/CFT within six months post-year-end) and prior notifications for changes, with CSSF enforcement powers (e.g., measures under LFS Article 46(2)) for non-compliance. Recent CSSF 25/898 update (Nov 2025) requires immediate review of processes for digital submissions, but no retroactive changes or hard deadlines post-2025; grandfathering for pre-existing setups reduces immediate pressure.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankBroker Dealer
Adoption of the EBA Guidelines on internal policies, procedures and controls to ensure the implementation of Union and national restrictive measures (sanctions)
Circular CSSF 25/896 adopts the EBA Guidelines EBA/GL/2024/14 and EBA/GL/2024/15, mandating Luxembourg financial institutions to establish robust internal policies, procedures, and controls for complying with EU and national restrictive measures (sanctions). This matters because it sets binding EU-wide standards to prevent sanctions violations and circumvention, with absolute obligations for immediate asset freezing and reporting, amid escalating geopolitical tensions.
What Changed
- - Institutions must develop, implement, and maintain up-to-date policies, procedures, and controls for identifying, investigating, and applying restrictive measures without delay, including risk...
- Management body responsibilities expanded: approve sanctions compliance strategy, oversee implementation, conduct at least annual assessments of exposure and controls, ensure remedial actions, and...
- Screening and monitoring requirements: Maintain updated sanctions lists with immediate integration of changes; screen customer base, transactions, and datasets accurately; enable immediate...
- Training and testing: Deliver regular, documented role-specific training; perform ongoing system testing for screening calibration, list accuracy, transaction monitoring effectiveness, and reporting.
- Proportionality applies based on institution's size, activities, and exposure; PSPs and CASPs explicitly addressed with tailored controls.
Suggested Considerations
- Conduct annual exposure assessments to sanctions risks and circumvention; update policies accordingly.
- Appoint senior management/board-level responsibility for approving and overseeing sanctions strategy, including annual reviews and deficiency reporting.
- Implement reliable screening systems for customers, transactions, and lists; define screenable datasets; test systems regularly for effectiveness (e.g., immediate freezing, accurate hits).
- Provide documented training to relevant staff on sanctions, institutional exposure, and internal processes.
- Establish processes for immediate action on matches: suspend transfers, freeze assets, report to Ministry of Finance/CSSF/FIU without delay; maintain whitelists only under strict conditions.
Compliance Impact
Urgency: High – With less than 12 months until the 30 December 2025 deadline (as of January 2026), firms face binding requirements for absolute compliance, including personal accountability for management bodies; non-compliance risks enforcement by CSSF, reputational damage, and fines amid frequent EU sanctions updates (e.g., Regulations 2025/1469, 2025/1476). This elevates sanctions from operational task to strategic board priority.
AI-generated analysis. May contain errors or omissions — verify with the
original CSSF source
before acting. Full disclaimer.
BankPayment ProviderCrypto Exchange