Live Updates

Circular CSSF 26/914

AI Analysis

Executive Summary

Circular CSSF 26/914 identifies which Luxembourg obliged entities fall within the perimeter for **potential direct supervision by the future EU Anti-Money Laundering Authority (AMLA)**, as part of the new EU-level AML/CFT supervisory architecture. This matters for compliance teams because in‑scope entities will face an additional EU supervisory layer, more intrusive AML/CFT oversight, and will need to prepare for alignment with AMLA’s methodologies, data requirements, and enforcement practices.

What Changed

  • - The CSSF formally identifies Luxembourg “obliged entities” under AML/CFT law that are potentially eligible for direct AMLA supervision, clarifying which categories of firms fall into the EU‑level “high‑risk and cross‑border” perimeter defined under
  • The circular operationalises, at CSSF level, the EU allocation mechanism for direct supervision, building on Regulation (EU) 2024/… establishing AMLA and the forthcoming directly applicable AML Regulation and revised AMLD, by mapping AMLA’s selection
  • The CSSF establishes a process for providing information to AMLA on Luxembourg obliged entities (e.g. size, cross‑border activities, risk profile) to support AMLA’s periodic selection and review of entities for direct supervision.
  • The circular clarifies that CSSF‑supervised entities identified as “eligible” remain under CSSF supervision unless and until AMLA formally designates them for direct supervision, at which point AMLA becomes the lead AML/CFT supervisor and the CSSF as
  • The circular anticipates enhanced data and reporting requirements for entities assessed as eligible for AMLA direct supervision, including more granular information on cross‑border business, high‑risk customers, products, distribution channels, and g
  • The CSSF aligns its supervisory framework with AMLA’s risk‑based methodology, signposting that entities in scope may be subject to more intensive on‑site inspections, thematic reviews, and requests for information, coordinated at EU level.

Suggested Considerations

  • Determine whether your firm is likely to fall within the “eligible for AMLA direct supervision” perimeter by assessing your cross‑border footprint, ML/TF risk profile, group structure, and relative size against AMLA’s high‑risk and cross‑border criteria.
  • Review and update the firm‑wide AML/CFT risk assessment to ensure it is robust, data‑driven, and aligned with an EU‑level supervisory perspective, including explicit consideration of cross‑border risks, complex group structures, and high‑risk products.
  • Strengthen AML/CFT governance and oversight, including Board and senior management reporting, to demonstrate clear ownership of ML/TF risk, documented risk appetite, and effective challenge consistent with what AMLA expects from directly supervised entities.
  • Review and, where necessary, enhance customer due diligence, transaction monitoring, screening and suspicious activity reporting frameworks to withstand more intrusive and harmonised EU‑level scrutiny.
  • Map and document cross‑border business lines and passporting activities (branches, agents, tied intermediaries, distributors) to ensure you can provide complete and up‑to‑date information to the CSSF and AMLA on request.
  • Review group‑wide AML/CFT policies, intra‑group data‑sharing arrangements and centralised functions to ensure they are consistent with AMLA’s future role as potential group‑level supervisor and that any legal or data‑protection constraints are identified and mitigated.

Key Dates

TBD (from AMLA operational go‑live date in 2025–2026)
- AMLA formally designates its first batch of directly supervised obliged entities at EU level, potentially including entities identified under this circular
25 June 2026
- CSSF publishes Circular 26/914 identifying obliged entities eligible for direct supervision by AMLA and setting the framework for Luxembourg’s contribution to AMLA’s selection and supervisory process
TBD (periodic, post‑AMLA go‑live)
- Periodic reviews by AMLA and the CSSF of eligible entities’ status and updates to the list of entities subject to, or proposed for, direct AMLA supervision

Compliance Impact

The compliance impact is high for any entity that is, or may become, eligible for AMLA direct supervision, given the likely increase in supervisory intensity, data expectations, and EU‑level enforcement risk. Non‑compliance could result in sanctions from both AMLA and national authorities, including significant administrative fines, business restrictions, remediation mandates, and reputational dam

Who is Affected

Luxembourg credit institutions (banks) with significant cross‑border activities or high‑risk business modelsLuxembourg‑authorised payment institutions and electronic money institutions with material cross‑border payment flowsInvestment firms and other MiFID‑licensed entities supervised by the CSSFCrypto‑asset service providers and virtual asset service providers supervised by the CSSF as obliged entitiesFinancial groups headquartered or significantly present in LuxembourgCSSF‑supervised non‑bank financial institutions that qualify as obliged entities under Luxembourg AML/CFT law

AI-generated analysis. May contain errors or omissions — verify with the original CSSF source before acting. Full disclaimer.

Summary

Identification of obliged entities eligible for direct supervision by AMLA

Relevant Firm Types

BankPayment ProviderCrypto ExchangeAll Firms
View Original on CSSF Back to Feed

Share this update