← Luxembourg

The CSSF’s supervisory priorities in the area of sustainable finance

Published on 2 March 2026 Email this Share this on LinkedIn Share this on Facebook Communiqué The CSSF’s supervisory priorities in the area of sustainable finance Update March 2026 The objective of th

Article 2

, point 16 of Regulation (EU) No 468/2014 of the European Central Bank (ECB) of 16 April 2014 (SSM Framework Regulation) shall refer to the relevant ECB rules. 2 The definitions of physical and transition risks are framed exclusively in terms of financial impact that Institutions may face. The financial impact is assessed as the most relevant for Luxembourg Institutions. Institutions that in addition face operational impacts shall duly take these into account. CSSF CIRCULAR 21/773 3/9

  1. Climate-related and environmental risks are drivers of existing risks, in particular credit risk, operational risk, market risk and liquidity risk. Climaterelated and environmental risk factors also impact reputational risk.
  2. Identification of risk exposure
  3. The CSSF expects Institutions to regularly assess the materiality and relevance of climate-related and environmental risks for the Institution in the short, medium and long term, covering more than five years. The assessment of materiality is an institution-specific assessment, taking into account the specificities of the business model, the operating environment and the risk profile.
  4. Institutions shall identify their exposure to climate-related and environmental risks drivers, considering risk concentration by sector, geographies, products and services, as relevant, and using a forward-looking perspective taking into account their business model.
  5. Business strategy and risk appetite
  6. The business strategy is an Institution’s principal tool for positioning itself within its business environment in order to generate acceptable and sustainable returns in line with its risk appetite. When determining their business strategy, Institutions are expected to integrate climate-related and environmental risks that materially impact their business environment in the short, medium or long term. When implementing their strategy, Institutions should factor such risks also into their internal communication.
  7. Institutions shall include as part of their risk appetite framework, climaterelated and environmental risk indicators and limits for the risks that they are willing to bear.
  8. Institutions are encouraged to monitor the fulfilment of their strategy, by setting key performance indicators (KPIs) and key risk indicators (KRIs), that are cascaded down to individual business lines and portfolios, where relevant. Such indicators should be approved by the management body and linked to the risk appetite.
  9. Given the limitations of actual data and quantitative methodologies, Institutions may resort to qualitative measures to monitor strategic objectives. Institutions are expected to progressively develop and keep up-to-date sound and robust monitoring tools tailored to their specific risk appetite/profile. CSSF CIRCULAR 21/773 4/9
  10. Risk management framework
  11. When climate-related and environmental risks are assessed as material, they shall be fully integrated into the risk management framework of an Institution.
  12. Institutions are expected to incorporate climate-related and environmental risks as drivers of existing risk categories into their risk management framework, with a view to managing and monitoring these over a sufficiently long-term horizon, and to review their management and monitoring arrangements on a regular basis.
  13. Institutions are expected to identify and quantify these risks within their overall process of ensuring capital and liquidity adequacy. The risk identification shall be documented in writing by the Institutions. A high-level summary of this risk identification shall be provided in the ICAAP and ILAAP reports issued each year.
  14. Institutions are expected to understand the ways in which material climaterelated and environmental risks affect the different regulatory risk categories, including credit, operational, market and liquidity risks. The table below provides an example of how physical and transition factors may lead to increased risks. Risks affected Physical Climate-related Environmental Transition Climate-related Environmental • Extreme weather • Water stress • Policy and • Policy and events • Resource scarcity regulation regulation • Chronic weather • Biodiversity loss • Technology • Technology patterns • Pollution • Market sentiment • Market sentiment • Other Credit The probabilities of default (PD) and loss given Energy default (LGD) of exposures within sectors or substantial adaptation costs and lower corporate efficiency standards may trigger geographies vulnerable to physical risk may be profitability, which may lead to a higher PD as impacted, for example, through lower collateral well as lower collateral values. valuations in real estate portfolios as a result of increased flood risk. Market Operational Severe physical events may lead to shifts in Transition risk drivers may generate an abrupt market expectations and could result in sudden repricing repricing, higher volatility and losses in asset example for products associated with industries values on some markets. affected by asset stranding. The bank’s operations may be disrupted due to Changing consumer sentiment regarding climate physical damage to its property, branches and issues can lead to reputation and liability risks data centres as a result of extreme weather for the bank as a result of scandals caused by events. the financing of environmentally controversial of securities and derivatives, activities. CSSF CIRCULAR 21/773 5/9 for Other risk types Liquidity risk may be affected in the event of Transition risk drivers may affect the viability of (liquidity, clients withdrawing money from their accounts some business lines and lead to strategic risk for business model) in order to finance damage repairs. specific business models if the necessary adaptation or diversification is not implemented. An abrupt repricing of securities may reduce the value of banks’ high-quality liquid assets, thereby affecting liquidity buffers. Source: ECB, Guide on climate-related and environmental risks
  15. In their credit risk management, Institutions are expected to consider climaterelated and environmental risks at all stages of the credit-granting process and to monitor the related risks in their portfolios.
  16. In their operational risk management, Institutions are expected to consider how climate-related events could have an adverse impact on business continuity and the extent to which the nature of Institutions’ activities could increase reputational and/or liability risks.
  17. In their market risk management, Institutions are encouraged to monitor on an ongoing basis the effect of climate-related and environmental factors on their current market risk positions and to evaluate potential investments in respect of these risks.
  18. Institutions with material climate-related and environmental risks are expected to assess whether those risks could cause net cash outflows or depletion of liquidity buffers and, if so, incorporate these factors into their liquidity risk management.
  19. Institutions with material climate-related and environmental risks are expected to evaluate the appropriateness of their stress testing framework, with a view to incorporating such risks into their baseline and adverse scenarios. Institutions should progressively enhance their stress testing capacities to strengthen their understanding on how adverse events or scenarios driven by physical and transition risks affect their financial and operational position. CSSF CIRCULAR 21/773 6/9
  20. Internal governance
  21. The assessment of the negative consequences that climate change might have on an Institution’s strategic positioning and its financial risks shall be critically assessed, and its outcome explicitly endorsed, by the management body. The management body shall ensure that climate change and environmental risks are factored into business strategy, risk appetite and risk management frameworks as described in this Circular.
  22. Institutions shall clearly define and assign responsibility for the management of climate-related and environmental risks within the organizational structure in accordance with the three lines of defence model. Roles and responsibilities for all business areas shall be documented and communicated.
  23. Business line staff, acting as first line of defence, shall perform its duties in accordance with any climate-related and environmental policy, procedure or limit. More specifically, the first line of defence is expected to identify, assess and monitor any climate-related and environmental risks relevant for the creditworthiness and the scoring/rating of a client or counterparty, as well as to conduct proper due diligence on climate-related and environmental risks that the Institution is or will become exposed to.
  24. The risk control function is key in the operational implementation of climaterelated and environmental risk mitigation within the risk management framework as detailed in section
  25. The compliance function shall ensure that Institutions take into account the legal and reputational risks and monitor the alignment of the Institutions’ activities with all applicable legal and regulatory requirements on climate and environmental aspects as well as Institutions’ own internal policies.
  26. Once the climate-related and environmental risks have been incorporated into Institutions’ governance and organisational arrangements, the internal audit function shall include those features in their audit plans and capture them under the existing processes.
  27. The CSSF expects that adequate training on climate-related and environmental risks is given to all relevant staff in order to ensure the necessary skills and avoid knowledge gaps.
  28. Institutions shall develop regular and transparent reporting to the management body in order to enable it to exercise effective oversight in line with the overall business strategy and the risk management framework. The management body in its supervisory function is expected to monitor and follow-up on targets and developments in KPIs and KRIs. CSSF CIRCULAR 21/773 7/9
  29. To encourage behaviour consistent with their climate-related and environmental (risk) approach, Institutions that have set climate-related and environmental objectives should consider implementing a variable remuneration component linked to the successful achievement of those objectives.
  30. Date of application
  31. This Circular is applicable as of its date of publication. CSSF expects Institutions to start reviewing their current business models and operational frameworks by mid-year 2021 with a view to progressively implement operational arrangements that incorporate climate-related and environmental risk factors. Claude WAMPACH Director Marco ZWICK Director Françoise KAUTHEN Claude MARX Director Director General Jean-Pierre FABER Director CSSF CIRCULAR 21/773 8/9 Commission de Surveillance du Secteur Financier 283, route d’Arlon L-2991 Luxembourg (+352) 26 25 1-1 direction@cssf.lu www.cssf.lu CSSF CIRCULAR 21/773 9/9 Circulaire CSSF 22/821 telle que modifiée par les circulaires CSSF 23/845, 24/865 et 25/897 Compte rendu analytique Règles pratiques concernant le questionnaire d’autoévaluation à soumettre par les établissements Mission et rapports y relatifs des réviseurs d’entreprises agréés En cas de divergences entre les textes français et anglais, le texte anglais prévaut. Circulaire CSSF 22/821 telle que modifiée par les circulaires CSSF 23/845, 24/865 et 25/897 Compte rendu analytique Règles pratiques concernant le questionnaire d’auto-évaluation à soumettre par les établissements Mission et rapports y relatifs des réviseurs d’entreprises agréés À tous les établissements de crédit de droit luxembourgeois et aux succursales luxembourgeoises d’établissements de crédit d’origine hors UE Luxembourg, le 25 octobre 2022 Mesdames, Messieurs, La circulaire CSSF 22/821 publiée le 25 octobre 2022 a introduit une version révisée du compte rendu analytique à la suite de développements réglementaires et de l’évolution des pratiques de surveillance depuis
  32. La révision du compte rendu analytique tel que prévu dans la circulaire CSSF 01/27 résultait d’un réexamen approfondi de son objectif, champ d’application et contenu afin de l’aligner sur les priorités prudentielles et de surveillance ainsi que de supprimer les redondances entre les exigences de reporting existantes. La circulaire a introduit un questionnaire d’auto-évaluation à remplir annuellement par les établissements. Elle a également introduit le(s) rapport(s) de procédures convenues (Agreed Upon Procedures) ainsi qu’un rapport annuel séparé concernant la protection des instruments financiers et des fonds des clients, tel que requis en vertu de l’article 7 du règlement grand-ducal du 30 mai 2018, à établir par les réviseurs d’entreprises agréés (« REA ») des établissements. Le questionnaire d’auto-évaluation et le(s) rapport(s) de procédures convenues ne couvraient pas le domaine de la lutte contre le blanchiment et le financement du terrorisme (« LBC/FT ») qui doit être couvert par le REA dans son rapport annuel séparé en application du règlement CSSF N°
  33. Suite à la révision de la circulaire CSSF 22/821 telle que modifiée par la circulaire CSSF 23/845, plus aucun rapport de procédures convenues n’est exigé. Ainsi, le REA n’aura à fournir que le rapport annuel séparé concernant la protection des instruments financiers et des fonds des clients, conformément à l’article 7 du règlement grand-ducal du 30 mai 2018, ainsi que le rapport annuel LBC/FT séparé en application du règlement CSSF N° 12-
  34. CIRCULAIRE CSSF 22/821 telle que modifiée par les circulaires CSSF 23/845, 24/865 et 25/897 2/10 TABLE DES MATIÈRES
  35. Champ d’application et base légale ............................................................................... 4
  36. Le questionnaire d’auto-évaluation ............................................................................... 5
  37. La mission du REA ...................................................................................................... 5 3.
  38. Le rapport concernant la protection des instruments financiers et des fonds des clients .... 5 3.
  39. Le rapport LBC/FT .................................................................................................... 6
  40. Procédure de soumission ............................................................................................. 9 4.
  41. Le questionnaire d’auto-évaluation ............................................................................. 9 4.
  42. Rapports établis par le REA ....................................................................................... 9 4.
  43. Règles pratiques ...................................................................................................... 9
  44. Dispositions finales ..................................................................................................... 9 CIRCULAIRE CSSF 22/821 telle que modifiée par les circulaires CSSF 23/845, 24/865 et 25/897 3/10
  45. Champ d’application et base légale Les dispositions de la présente circulaire s’appliquent aux établissements de crédit 1 de droit luxembourgeois, y compris leurs succursales, ainsi qu’aux succursales luxembourgeoises d’établissements de crédit de pays tiers (« établissement »). La présente circulaire ne s’applique pas aux succursales luxembourgeoises d’établissements de crédit de l’UE. Le compte rendu analytique révisé se compose de trois parties : - un questionnaire d’auto-évaluation à compléter par les établissements ; - un rapport séparé à établir par le REA concernant la protection des instruments financiers et des fonds des clients ; - un rapport séparé à établir par le REA concernant les procédures mises en place par les établissements relatives à la prévention du blanchiment et du financement du terrorisme (« rapport LBC/FT »). Le questionnaire d’auto-évaluation introduit par la présente circulaire repose sur les pouvoirs de la CSSF, énumérés ci-dessous, d’obtenir des informations de la part des établissements dans le cadre de son mandat légal de surveillance : - l’article 53, paragraphe 1, points

(2)et
(8), de la loi modifiée du 5 avril 1993 relative au secteur financier ; - l’article 45, paragraphe 2, de la loi modifiée du 30 mai 2018 relative aux marchés d’instruments financiers ; - l’article 58-5 de la loi modifiée du 10 novembre 2009 relative aux services de paiement, à l’activité d’établissement de monnaie électronique et au caractère définitif du règlement dans les systèmes de paiement et les systèmes de règlement des opérations sur titres ; - l’article 147, paragraphe 2, de la loi modifiée du 17 décembre 2010 concernant les organismes de placement collectif et l’article 50, paragraphe 2, de la loi modifiée du 12 juillet 2013 relative aux gestionnaires de fonds d’investissement alternatifs ; - l’article 62, paragraphe 1, de la loi modifiée du 13 juillet 2005 relative aux institutions de retraite professionnelle sous forme de société d’épargne-pension à capital variable (sepcav) et d’association d’épargne-pension (assep). Le rapport séparé établi par le REA concernant la protection des instruments financiers et des fonds des clients est requis en vertu de l’article 7 du règlement grand-ducal du 30 mai 2018. 2 Le rapport séparé établi par le REA en matière de LBC/FT repose sur l’application de l’article 49, paragraphes 2 et 3, du règlement CSSF N° 12-02 du 14 décembre 2012 (« RCSSF 12-02 »). 3 1 La présente circulaire s’applique à la fois aux entités importantes soumises à la surveillance prudentielle et aux entités moins importantes soumises à la surveillance prudentielle, telles que définies à l’article 2, points
(16)et
(7)du règlement (UE) modifié n° 468/2014 de la Banque centrale européenne (« BCE ») du 16 avril 2014 (le « Règlement-cadre MSU »). 2 Règlement grand-ducal modifié du 30 mai 2018 relatif à la protection des instruments financiers et des fonds des clients, aux obligations applicables en matière de gouvernance des produits et aux règles régissant l'octroi ou la perception de droits, de commissions ou de tout autre avantage monétaire ou non monétaire. 3 Règlement CSSF modifié N° 12-02 du 14 décembre 2012 relatif à la lutte contre le blanchiment et contre le financement du terrorisme. CIRCULAIRE CSSF 22/821 telle que modifiée par les circulaires CSSF 23/845, 24/865 et 25/897 4/10
  1. Le questionnaire d’auto-évaluation Le questionnaire d’auto-évaluation couvre les domaines du champ d’application de la surveillance prudentielle pour lesquels la CSSF ou la Banque centrale européenne est compétente. Veuillez noter, cependant, que les modules du questionnaire d’auto-évaluation couvrant les sujets en relation avec la directive concernant les marchés d’instruments financiers (« directive MiFID »), la directive révisée sur les services de paiement (« directive PSD 2 »), les dépositaires d’organismes de placement collectif (« OPC ») et le règlement sur les infrastructures de marché européennes (« EMIR ») relèvent exclusivement de la compétence de la CSSF. Toutes les parties du questionnaire d’auto-évaluation ont été élaborées de manière proportionnée et visent tous les établissements concernés, afin de permettre à la CSSF de collecter les informations nécessaires pour mettre en œuvre une approche fondée sur les risques pour la surveillance et d’obtenir les informations et assurances concernant le respect par les établissements concernés des principales dispositions réglementaires dont le contrôle relève du mandat légal des autorités compétentes. Les informations communiquées dans le cadre du questionnaire d’auto-évaluation doivent être exactes et aussi concises que possible, tout en donnant une image fidèle et honnête, et se baser sur les chiffres du reporting prudentiel (FINREP/COREP/LAREX) en IFRS à la clôture de l’exercice financier. 4 Le questionnaire d’auto-évaluation est disponible en format numérique tel que décrit à la section 4.
  2. Son contenu est adapté de manière annuelle, s’il y a lieu, notamment en réponse aux évolutions du cadre légal et réglementaire. Les différents modules et leur niveau d’application ainsi que les exemptions applicables sont directement disponibles dans la solution numérique de la CSSF et consultables sur le site de la CSSF (www.cssf.lu/fr/reporting-prudentiel-etablissements-de-credit)
  3. La mission du REA 3.
  4. Le rapport concernant la protection des instruments financiers et des fonds des clients Le cas échéant, les établissements sont tenus de mandater leur REA pour établir, sur une base annuelle, un rapport séparé concernant la protection des instruments financiers et des fonds des clients. Ce rapport doit couvrir l’adéquation des dispositions visées à l’article 37-1, paragraphes 7 et 8, de la loi modifiée du 5 avril 1993 relative au secteur financier, à l’article 13, paragraphe 4, de la loi modifiée du 5 août 2005 sur les contrats de garantie financière et à la section 2 du règlement grand-ducal du 30 mai
  5. La direction autorisée de l’établissement est chargée de fournir au REA les informations nécessaires pour la rédaction des parties descriptives du rapport. Le REA peut inclure dans son rapport des 4 Pour les établissements dont la date de clôture de l’exercice financier n’est pas alignée sur la date de remise du reporting prudentiel, le questionnaire devrait se baser sur le dernier reporting prudentiel soumis avant la clôture de l’exercice financier. CIRCULAIRE CSSF 22/821 telle que modifiée par les circulaires CSSF 23/845, 24/865 et 25/897 5/10 éléments descriptifs fournis directement par la direction autorisée de l’établissement, mais il doit vérifier et s’assurer que ces éléments sont corrects et adéquats. Il peut, si nécessaire, avoir à procéder à des modifications. L’objet de ce rapport séparé, qui doit être téléchargé via une solution numérique de la CSSF, est notamment de veiller à la fiabilité des réponses données par un établissement dans le questionnaire d’auto-évaluation concernant la protection des instruments financiers et des fonds des clients. Cependant, cela n’empêche pas le REA d’effectuer des évaluations supplémentaires, au-delà de celles énoncées dans le questionnaire d’auto-évaluation. 3.
  6. Le rapport LBC/FT Les établissements sont également tenus de mandater leur REA pour établir, sur une base annuelle, un rapport séparé qui couvre le domaine LBC/FT en application du RCSSF 12-
  7. Le rapport LBC/FT décrit les procédures mises en place par l’établissement relatives à la prévention du blanchiment et du financement du terrorisme, telles que requises en vue de se conformer à ou telle que définies par : - la partie II, chapitre 5, de la loi modifiée du 5 avril 1993 relative au secteur financier ; - la loi modifiée du 12 novembre 2004 relative à la lutte contre le blanchiment et contre le financement du terrorisme ; - le règlement grand-ducal modifié du 1er février 2010 portant précision de certaines dispositions de la loi modifiée du 12 novembre 2004 relative à la lutte contre le blanchiment et contre le financement du terrorisme ; - le règlement (UE) modifié 2015/847 du Parlement européen et du Conseil du 20 mai 2015 sur les informations accompagnant les transferts de fonds ; - les actes internationaux en matière de lutte contre le financement du terrorisme portés à la connaissance des établissements par voie de circulaires CSSF ; - les règlements CSSF en matière de lutte contre le blanchiment et le financement du terrorisme ; - les circulaires CSSF relatives à la LBC/FT. Le rapport LBC/FT doit fournir en particulier les éléments suivants : • la description de la politique LBC/FT mise en place par l’établissement en vue de la prévention du blanchiment et du financement du terrorisme, la vérification de sa conformité avec les dispositions de la partie II, chapitre 5, de la loi modifiée 5 avril 1993 relative au secteur financier, de la loi modifiée du 12 novembre 2004 relative à la lutte contre le blanchiment et contre le financement du terrorisme, du règlement grand-ducal modifié du 1er février 2010, du règlement (UE) modifié 2015/847, des règlements CSSF et des circulaires CSSF en matière de LBC/FT, et le contrôle de leur bonne application ; • l’appréciation de l’analyse faite par l’établissement des risques de blanchiment et de financement du terrorisme auxquels il est exposé. Le REA doit vérifier si les procédures, infrastructures et contrôles mis en place, ainsi que l’étendue des mesures prises en matière de LBC/FT, sont appropriés face aux risques de BC/FT auxquels l’établissement est exposé, notamment par ses activités, la nature de sa clientèle et les produits et services proposés ; CIRCULAIRE CSSF 22/821 telle que modifiée par les circulaires CSSF 23/845, 24/865 et 25/897 6/10 • une déclaration indiquant si un audit du respect de la politique LBC/FT de l’établissement a été effectué par la fonction d’audit interne et le responsable du contrôle du respect des obligations professionnelles 5 ; • une brève description des mesures de formation et de sensibilisation des employés en matière de blanchiment et de financement du terrorisme, et en particulier en ce qui concerne la détection des opérations de blanchiment et de financement du terrorisme ; • les statistiques des transactions suspectes détectées, renseignant sur le nombre de déclarations de transactions suspectes faites par l’établissement à la CRF ainsi que le montant total des fonds impliqués au cours de l’exercice financier ; • le contrôle de l’application par l’établissement, dans son rôle respectif, des dispositions du règlement (UE) modifié 2015/847 et le pourcentage des transferts de fonds pour lesquels les données sur le donneur d’ordre ou le bénéficiaire ont été manquantes ou incomplètes et des mesures prises par l’établissement dans ce contexte. Le rapport LBC/FT doit également fournir les éléments suivants : • une description des rôles et responsabilités en matière de LBC/FT au sein de l’établissement, y compris les rôles et responsabilités de et les interactions entre la direction et les différents départements et services, renseignant l’effectif correspondant impliqué dans les questions de LBC/FT. Le rapport LBC/FT doit également inclure une description des comités et des structures hiérarchiques et fonctionnelles correspondantes, en renseignant les délégations générales et particulières des pouvoirs en matière de LBC/FT. Il doit également fournir une description par l’établissement et l’évaluation par le REA du modèle des trois lignes de défense, tel que défini à l’article 39, paragraphe 7, du RCSSF 12-02 ; • la liste des personnes impliquées dans les questions de LBC/FT, telles que visées dans le RCSSF 12-02 et la circulaire CSSF 12/552, telle que modifiée, (le responsable de contrôle, le responsable du respect, le « Chief Compliance Officer », etc.). Il doit indiquer en outre tous les changements intervenus au cours de l’exercice financier concernant ces personnes. Étant donné que ces personnes peuvent déléguer certaines tâches opérationnelles en rapport avec ces fonctions à des membres du personnel, le rapport LBC/FT doit fournir, le cas échéant, une description du mécanisme de délégation ; • une description du réseau d’agences national, les filiales nationales et étrangères, les succursales à l’étranger, les bureaux de représentation à l’étranger et les agents liés, ainsi que les principaux risques BC/FT y associés. Le rapport LBC/FT doit également renseigner si l’établissement a recours aux services de gestionnaires externes concernant les actifs des clients et doit, le cas échéant, fournir une description de la façon dont les relations avec les gestionnaires externes sont gérées et documentées d’un point de vue LBC/FT ; • une description de la politique commerciale de l’établissement ainsi que la stratégie relative à la gestion des risques BC/FT y associés. Il doit inclure en outre une description de la façon dont l’établissement effectue le suivi et s’assure du respect de ses objectifs internes en matière de gestion des risques BC/FT. Le REA doit évaluer si l’établissement dispose de ressources financières suffisantes et de l’infrastructure appropriée pour le contrôle des risques BC/FT auxquels il est exposé. Le REA doit renseigner la façon dont l’échantillon des dossiers contrôlés a été sélectionné. Lors de la sélection de l’échantillon, la CSSF s’attend à ce que le REA applique une approche fondée sur les 5 Tel que défini à l’article 1, paragraphe 1, du RCSSF 12-
  8. CIRCULAIRE CSSF 22/821 telle que modifiée par les circulaires CSSF 23/845, 24/865 et 25/897 7/10 risques, en prenant en considération les différentes activités commerciales exercées. Le REA doit renseigner la date de référence des données de l’échantillon et fournir les informations pertinentes relatives à la méthodologie adoptée pour la sélection de l’échantillon (par exemple, le nombre de dossiers examinés par rapport au nombre total de clients ou le volume des dépôts contrôlés par rapport au volume total des dépôts). Lorsque le REA constate des cas de non-respect des dispositions légales ou réglementaires ou de lacunes, le REA doit donner des indications précises permettant à la CSSF d’évaluer la situation (nombre de dossiers non complets en suspens qui est à rapporter également au nombre total de dossiers contrôlés, détail des lacunes constatées, etc.). Le cas échéant, le rapport LBC/FT doit englober les succursales, les filiales majoritaires étrangères et les agents liés. Il doit couvrir, notamment, le respect par les succursales, filiales majoritaires et agents liés des dispositions applicables en matière de prévention du blanchiment et du financement du terrorisme et doit comporter, à cet égard : • une analyse des risques encourus par les succursales, filiales majoritaires et agents liés en matière de blanchiment et de financement du terrorisme ; • une description et une évaluation de la gestion du risque de blanchiment et de financement du terrorisme dans les succursales, filiales majoritaires et agents liés ; • la vérification de la mise en œuvre et du respect de la politique LBC/FT de l’établissement dans les succursales, filiales majoritaires et agents liés. Le rapport LBC/FT doit être suffisamment exhaustif et transparent, inclure des descriptions et évaluations détaillées afin de permettre un jugement précis et fondé sur les risques de blanchiment et de financement du terrorisme encourus par l’établissement. En ce qui concerne le langage utilisé dans les évaluations, le rapport LBC/FT ne doit pas contenir des formulations imprécises du type négatif (p.ex. « Nous n’avons pas trouvé de faiblesses graves ») ou encore des évaluations globales et approximatives (p.ex. « Nous avons constaté que la plupart des points sont conformes à la réglementation »). Le rapport LBC/FT doit plutôt donner, pour chaque domaine et chaque sujet, une évaluation positive en fournissant un aperçu de la méthodologie adoptée (p.ex. recours à la technique d’échantillonnage, méthode de sélection de l’échantillon, etc.) et, le cas échéant, inclure une description des observations, ceci afin de permettre à la CSSF de mieux comprendre et juger la portée des irrégularités et des faiblesses notées. Le REA doit également effectuer le suivi des constatations observées durant les audits précédents et détaillées dans le rapport LBC/FT précédent. Le REA doit fournir une description des problèmes potentiels en matière de LBC/FT que l’établissement peut rencontrer avec les autorités compétentes étrangères. La direction autorisée de l’établissement est chargée de fournir au REA les informations nécessaires pour la rédaction des parties descriptives du rapport LBC/FT. Le REA peut inclure dans son rapport des éléments descriptifs fournis directement par la direction autorisée de l’établissement, mais il doit vérifier et s’assurer que ces éléments sont corrects et adéquats. Il peut, si nécessaire, avoir à procéder à des modifications. Outre les parties descriptives, le REA doit effectuer de manière indépendante une évaluation détaillée des risques BC/FT auxquels l’établissement est exposé ainsi que des aspects organisationnels. Cette évaluation doit être dûment documentée. Il est souligné que le REA doit également avertir la CSSF de tous les cas de transactions suspectes déclarées conformément à l’article 5 de la loi modifiée du 12 novembre 2004 relative à la lutte contre le blanchiment et contre le financement du terrorisme et qui concernent les établissements. De même, le REA doit informer la CSSF s’il estime que l’établissement aurait dû déclarer une transaction CIRCULAIRE CSSF 22/821 telle que modifiée par les circulaires CSSF 23/845, 24/865 et 25/897 8/10 suspecte mais ne l’a pas fait, en expliquant son raisonnement et en prenant en considération la justification de l’établissement. Lors des discussions avec l’établissement concernant ces cas, le REA doit tenir compte des obligations professionnelles applicables.
  9. Procédure de soumission 4.
  10. Le questionnaire d’auto-évaluation Le questionnaire d’auto-évaluation sera accessible à chaque établissement via une solution numérique de la CSSF endéans trois mois avant la clôture de l’exercice financier de l’établissement. Le questionnaire d’auto-évaluation doit être revu et signé électroniquement par la direction autorisée avant d’être soumis à la CSSF. Le questionnaire d’auto-évaluation doit être transmis annuellement à la CSSF sous forme électronique via une solution numérique de la CSSF, endéans trois mois suivant la clôture de l’exercice financier, conformément à la procédure décrite à la section 4.
  11. 4.
  12. Rapports établis par le REA Le rapport séparé concernant la protection des instruments financiers et des fonds des clients et le rapport LBC/FT doivent comporter la signature numérique de l’associé chargé du mandat auprès du cabinet d’audit. Le REA soumet les rapports à l’établissement qui les soumet ensuite à la CSSF. Les rapports établis par le REA doivent être transmis par l’établissement à la CSSF sous forme électronique via une solution numérique de la CSSF, endéans cinq mois suivant la clôture de l’exercice financier, conformément à la procédure décrite à la section 4.
  13. 4.
  14. Règles pratiques Les procédures et les explications concernant les modalités pratiques pour la préparation et la transmission du questionnaire d’auto-évaluation, du rapport séparé concernant la protection des instruments financiers et des fonds des clients et du rapport LBC/FT sont mises à la disposition des établissements et de leur REA sur le site Internet de la CSSF à l’adresse https://edesk.apps.cssf.lu/edesk-dashboard/api/v1/documentation/LFRB_GU/en. Un guide utilisateur Authentication and user account management est disponible pour les établissements sur le portail eDesk de la CSSF.
  15. Dispositions finales La circulaire CSSF 22/821, telle que publiée le 25 octobre 2022, a abrogé la circulaire CSSF 01/27, telle que modifiée par les circulaires CSSF 08/340, CSSF 10/484, CSSF 11/521 et CSSF 21/765, ainsi que la circulaire IML 96/
  16. Elle était d’application à partir du 31 décembre
  17. La version révisée actuelle s’applique à compter du 31 décembre
  18. CIRCULAIRE CSSF 22/821 telle que modifiée par les circulaires CSSF 23/845, 24/865 et 25/897 9/10 Claude WAMPACH Directeur Françoise KAUTHEN Directeur Marco ZWICK Directeur Jean-Pierre FABER Directeur Claude MARX Directeur général CIRCULAIRE CSSF 22/821 telle que modifiée par les circulaires CSSF 23/845, 24/865 et 25/897 10/10 Circular CSSF 22/821 as amended by Circulars CSSF 23/845, 24/865 and 25/897 Long Form Report Practical rules concerning the self-assessment questionnaire to be submitted by institutions. Mission and related reports of the approved statutory auditors (réviseurs d’entreprises agréés). Circular CSSF 22/821 as amended by Circulars CSSF 23/845, 24/865 and 25/897 Long Form Report Practical rules concerning the self-assessment questionnaire to be submitted by institutions. Mission and related reports of the approved statutory auditors (réviseurs d’entreprises agréés). To all Luxembourg credit institutions and Luxembourg branches of non-EU credit institutions Luxembourg, 25 October 2022 Ladies and Gentlemen, Circular 22/821 published on 25 October 2022 introduced a revised version of the long form report following on from the regulatory developments and the evolving supervisory practices since
  19. The revision of the long form report as contemplated under Circular CSSF 01/27 was the result of a thorough reconsideration of its objective, scope and content in order to realign it with supervisory and prudential points of focus as well as to suppress redundancies between existing reporting requirements. The circular introduced a self-assessment questionnaire to be filled in on an annual basis by the institutions. It also introduced Agreed Upon Procedure report(s) and an annual separate report on the protection of financial instruments and funds belonging to clients as required under Article 7 of the Grand-ducal Regulation of 30 May 2018 to be established by the réviseurs d’entreprises agréés (REA) of the institutions. The self-assessment questionnaire and the Agreed Upon Procedure report(s) did not include matters relating to anti-money laundering and countering the financing of terrorism (AML/CFT) that have to be covered by the REA in its annual, separate report further to CSSF Regulation No 12-
  20. Following the revision of Circular 22/821 as amended by Circular CSSF 23/845, no more Agreed Upon Procedure reports are foreseen. As a result, the REA would only have to provide the annual separate report on the protection of financial instruments and funds belonging to clients as required under Article 7 of the Grand-ducal Regulation of 30 May 2018 as well as the annual separate AML/CFT report further to CSSF Regulation No 12-
  21. CIRCULAR CSSF 22/821 as amended by Circulars CSSF 23/845, 24/865 and 25/897 2/9 TABLE OF CONTENTS
  22. Scope of application and legal basis ................................................................................. 4
  23. The self-assessment questionnaire .................................................................................. 4
  24. The mission of the REA .................................................................................................. 5 3.
  25. The report on the protection of financial instruments and funds belonging to clients ......... 5 3.
  26. The AML/CFT report ................................................................................................. 6
  27. Submission procedures .................................................................................................. 8 4.
  28. Self-assessment questionnaire .................................................................................. 8 4.
  29. Reports prepared by the REA..................................................................................... 8 4.
  30. Practical rules .......................................................................................................... 9
  31. Final provisions ............................................................................................................. 9 CIRCULAR CSSF 22/821 as amended by Circulars CSSF 23/845, 24/865 and 25/897 3/9
  32. Scope of application and legal basis The provisions of this circular are applicable to credit institutions 1 incorporated under Luxembourg law, including their branches, as well as Luxembourg branches of third-country credit institutions (institution). This circular does not apply to Luxembourg branches of EU credit institutions. The framework for the revised long form report consists of three parts: - a self-assessment questionnaire to be completed by institutions; - a separate report to be prepared by the REA on the protection of financial instruments and funds belonging to clients; - a separate report to be prepared by the REA on the procedures set up by institutions concerning the prevention of money laundering and terrorist financing (AML/CFT report). The self-assessment questionnaire introduced by this circular is based on the following powers of the CSSF to obtain information from institutions in the context of its legal supervisory mandate: - Article 53
(1), points
(2)and
(8), of the Law of 5 April 1993 on the financial sector, as amended; - Article 45
(2)of the Law of 30 May 2018 on markets in financial instruments, as amended; - Article 58-5 of the Law of 10 November 2009 on payment services, on the activity of electronic money institution and settlement finality in payment and securities settlement systems, as amended; - Article 147
(2)of the Law of 17 December 2010 relating to undertakings for collective investment, as amended and Article 50
(2)of the Law of 12 July 2013 on alternative investment fund managers, as amended; - Article 62
(1)of the Law of 13 July 2005 on institutions for occupational retirement provision in the form of pension savings companies with variable capital (SEPCAVs) and pension savings associations (ASSEPs), as amended. The separate report prepared by the REA on the protection of financial instruments and funds belonging to clients is required under Article 7 of the Grand-ducal Regulation of 30 May 2018. 2 The separate report prepared by the REA on AML/CFT is based on the application of Articles 49
(2)and
(3)of CSSF Regulation No 12-02 of 14 December 2012 (RCSSF 12-02). 3 2. The self-assessment questionnaire The self-assessment questionnaire covers domains in scope of the prudential supervision for which the CSSF or the European Central Bank are competent. Please note however that the modules of the self-assessment questionnaire covering matters relating to the Market in Financial Instruments 1 This circular applies to both significant supervised entities and less significant supervised entities

Article 2, points

(16)and
(7)of Regulation (EU) No 468/2014 of the European Central Bank (ECB) of 16 April 2014, as amended (the SSM Framework Regulation) respectively. 2 Grand-ducal Regulation of 30 May 2018 on the protection of financial instruments and funds belonging to clients, product governance obligations and the rules applicable to the provision or reception of fees, commissions or any monetary or non-monetary benefits, as amended. 3 CSSF Regulation No 12-02 of 14 December 2012 on the fight against money laundering and terrorist financing, as amended. CIRCULAR CSSF 22/821 as amended by Circulars CSSF 23/845, 24/865 and 25/897 4/9 Directive (MiFID), the Payment Services Directive (PSD 2) and undertaking for collective investments (UCI) depositaries and the European Market Infrastructure Regulation (EMIR) are under the exclusive competence of the CSSF. All parts of the self-assessment questionnaire have been designed in a proportionate way and target in-scope institutions with a view to allowing the CSSF to gather sufficient information to implement risk-based approaches to supervision and to obtain information and assurances as regards in-scope institutions’ compliance with key regulatory provisions the control of which falls within the competent authorities’ legal mandate. The information communicated as part of the self-assessment questionnaire shall be accurate and as concise as possible, while providing a true and fair view, and be based on the prudential reporting figures (FINREP/COREP/LAREX) under IFRS as at the closure of the financial year. 4 The self-assessment questionnaire is available in digital form as described in section 4.1. Its content is adapted on a yearly basis as required, including in response to developments of the legal and regulatory framework. The individual modules of the self-assessment questionnaire and their level of application as well as the applicable exemptions are directly recorded in the CSSF’s digital solution and are also reflected on the CSSF website (www.cssf.lu/en/prudential-reporting-credit-institutions). 3. The mission of the REA 3.1. The report on the protection of financial instruments and funds belonging to clients If applicable, institutions are required to mandate their REA to prepare, on an annual basis, a separate report on the protection of financial instruments and funds belonging to clients. This report shall cover the adequacy of the arrangements under Article 37-1
(7)and
(8)of the Law of 5 April 1993 on the financial sector, as amended, Article 13
(4)of the Law of 5 August 2005 on financial collateral arrangements, as amended, and Section 2 of the Grand-ducal Regulation of 30 May
  1. The authorised management of the institution is responsible for providing the REA with the required information for the drafting of the descriptive parts of the report. The REA may include in its report descriptive elements directly provided by the institution’s authorised management, but s/he shall verify and ensure that these elements are correct and adequate. If needed, s/he may have to perform some amendments. The purpose of this separate report, which must be uploaded through a CSSF digital solution, is notably to ensure the reliability of the answers provided by an institution in the self-assessment questionnaire in relation to the protection of financial instruments and funds belonging to clients. However, this does not preclude the REA to perform further assessments beyond those set forth in the self-assessment questionnaire. 4 For institutions for which the date of the closure of the financial year is not aligned with the remittance date of the prudential reporting, the questionnaire should be based on the last prudential reporting submitted before the closure of the financial year. CIRCULAR CSSF 22/821 as amended by Circulars CSSF 23/845, 24/865 and 25/897 5/9 3.
  2. The AML/CFT report Institutions are also required to mandate their REA to prepare, on an annual basis, a separate report covering AML/CFT further to RCSSF 12-
  3. The AML/CFT report describes the procedures set up by the institution concerning the prevention of money laundering and terrorist financing as required for compliance with or

: - Chapter 5 of Part II of the Law of 5 April 1993 on the financial sector, as amended; - the Law of 12 November 2004 on the fight against money laundering and terrorist - the Grand-ducal Regulation of 1 February 2010 providing details on certain provisions of financing, as amended; the amended Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended; - Regulation (EU) 2015/847 of the European Parliament and of the Council of 20 May 2015 on information accompanying transfers of funds, as amended; - international acts on the fight against terrorist financing brought to the attention of the institutions through CSSF circulars; - CSSF regulations on the fight against money laundering and terrorist financing; - CSSF circulars with regard to AML/CFT. The AML/CFT report shall provide, in particular: • the description of the AML/CFT policy set up by the institution in order to prevent money laundering and terrorist financing, the verification of its compliance with the provisions of Part II, Chapter 5 of the Law of 5 April 1993 on the financial sector, as amended, the Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended, the Grand-ducal Regulation of 1 February 2010, as amended, Regulation (EU) 2015/847, as amended, CSSF regulations and CSSF circulars relating to AML/CFT and the control of their sound application; • the assessment of the institution's analysis of money laundering and terrorist financing risks to which it is exposed. The REA must verify if the implemented procedures, infrastructures and controls, as well as the scope of the AML/CFT measures are appropriate considering the ML/FT risks to which the institution is exposed, particularly through its activities, the nature of its customers and the provided products and services; • a declaration on whether an audit of compliance with the institution's AML/CFT policy has been performed by the internal audit function and the compliance officer in charge of the control of compliance with the professional obligations 5; • a short description of the training and awareness-raising measures for employees as regards money laundering and terrorist financing, and, in particular, with respect to the identification of money laundering and terrorist financing transactions; • statistics concerning the detected suspicious transactions which indicate the number of suspicious transaction cases reported to the FIU by the institution, as well as the total amount of funds involved during the financial year; • the control of the application of the provisions of Regulation (EU) 2015/847, as amended by the institution, in its respective role, and the percentage of transfers of funds for which data on the payer or payee were missing or incomplete and the measures taken in this context by the institution. The AML/CFT report shall also provide: 5

Article 1(1) of RCSSF 12-02.

CIRCULAR CSSF 22/821 as amended by Circulars CSSF 23/845, 24/865 and 25/897 6/9 • a description of roles and responsibilities with regard to AML/CFT within the institution, including the roles and responsibilities of and the interactions between the management and the different departments and services, indicating the corresponding number of staff involved on AML/CFT matters. The AML/CFT report shall also include a description of the committees and the corresponding hierarchical and functional structures by indicating the general and particular delegations of power with respect to AML/CFT. It shall also provide a description by the institution and an assessment by the REA of the three-lines-ofdefence model,

Article 39

(7)of the RCSSF 12-02; • the list of persons involved in AML/CFT matters, as referred to in the RCSSF 12-02 and Circular CSSF 12/552, as amended (compliance officer, person responsible for compliance, Chief Compliance Officer, etc.). It shall also state all the changes with regard to these persons which occurred during the financial year. Since these persons may delegate to members of staff certain operational tasks in relation to these functions, the AML/CFT report shall provide, where appropriate, a description of the delegation mechanism; • a description of the network of national agencies, national and foreign subsidiaries, the branches abroad, the foreign representative offices and the tied agents, as well as the main related ML/FT risks. The AML/CFT report shall also indicate if the institution uses the services of external managers as regards the clients' assets and shall, where appropriate, provide a description of the manner in which the relationships with external managers are managed and documented from an AML/CFT perspective; • a description of the institution’s commercial policy as well as the strategy regarding the management of the related ML/FT risks. It shall also include a description of how the institution monitors and ensures compliance with its internal objectives with regard to ML/FT risks management. The REA shall assess if the institution has sufficient financial resources and the appropriate infrastructure to control ML/FT risks to which it is exposed. The REA shall state how the sample of reviewed files was selected. When determining the sample, the CSSF expects the REA to apply a risk-based approach, taking into account the different business activities performed. The REA shall state the reference date of the sample data and provide relevant information on the methodology adopted for determining the sample (for example, the number of files reviewed compared to the total number of clients or the volume of deposits reviewed compared to the total volume of deposits). Where the REA identifies cases of non-compliance with the legal or regulatory provisions or deficiencies, the REA shall give detailed indications enabling the CSSF to assess the situation (number of pending incomplete files as a percentage of the total number of reviewed files, details of the deficiencies identified, etc.). Where applicable, the AML/CFT report must encompass the institution's branches, majority-owned subsidiaries abroad and the tied agents. It must cover, in particular, the branches', majority-owned subsidiaries' and the tied agents’ compliance with the applicable provisions as regards the prevention of money laundering and terrorist financing and it must include, in that respect: • an analysis of money laundering and terrorist financing risks incurred by the branches, majority-owned subsidiaries and the tied agents; • a description and assessment of the money laundering and terrorist financing risk management in the branches, majority-owned subsidiaries and the tied agents; • the verification of the implementation of and compliance with the institution's AML/CFT policy in the branches, majority-owned subsidiaries and the tied agents. The AML/CFT report must be sufficiently exhaustive and transparent, providing detailed descriptions and assessments, in order to allow a precise and informed judgement on the risks incurred by the CIRCULAR CSSF 22/821 as amended by Circulars CSSF 23/845, 24/865 and 25/897 7/9 institution with respect to money laundering and terrorist financing. With regard to the language used for the assessments, the AML/CFT report shall not include imprecise negative formulations (e.g. “We did not encounter serious weaknesses”) or global and approximative assessments (e.g. “We noted that most of the points comply with the laws and regulations”). The AML/CFT report shall rather provide a positive assessment for each area and subject by providing an overview of the methodology adopted (e.g. use of the sample technique, method for selecting the sample, etc.) and, where applicable, provide a description of the identified findings in order to allow the CSSF to better understand and judge the extent of the noticed irregularities and weaknesses. The REA shall also perform the follow-up of findings observed during the previous audits and described in detail in the previous AML/CFT report. The REA shall provide a description of any potential issues in relation to AML/CFT the institution may have with foreign competent authorities. The authorised management of the institution is responsible for providing the REA with the required information for the drafting of the descriptive parts of the AML/CFT report. The REA may include in its report descriptive elements directly provided by the institution’s authorised management, but s/he shall verify and ensure that these elements are correct and adequate. If needed, s/he may have to perform some amendments. In addition to the descriptive parts, the REA shall perform independently a detailed assessment of the ML/FT risks to which the institution is exposed as well as organisational aspects. This assessment shall be duly documented. It should be noted that the REA shall also inform the CSSF of all the suspicious transactions reported pursuant to Article 5 of the Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended, and which concern the institutions. Similarly, the REA must inform the CSSF in case they deem that the institution should have reported a suspicious transaction but has not, explaining their reasoning and having regard to the institution’s rationale. When discussing the cases with the institution, the REA need to be mindful of applicable professional obligations.
  1. Submission procedures 4.
  2. Self-assessment questionnaire The self-assessment questionnaire will be accessible through a CSSF digital solution for each institution within three months before the closure of the institution’s financial year. The self-assessment questionnaire must be reviewed and electronically signed by the authorised management before submitting it to the CSSF. The self-assessment questionnaire must be transmitted on an annual basis to the CSSF in an electronic form via a CSSF digital solution within three months after the closure of the financial year, in accordance with the procedure described in section 4.
  3. 4.
  4. Reports prepared by the REA The separate report on the protection of financial instruments and funds belonging to clients and the AML/CFT report shall include the digital signature of the partner in charge of the mandate with the CIRCULAR CSSF 22/821 as amended by Circulars CSSF 23/845, 24/865 and 25/897 8/9 audit firm s/he represents. The REA submits the reports to the institution, which submits them subsequently to the CSSF. The reports prepared by the REA must be transmitted by the institution to the CSSF in electronic form via a CSSF digital solution within five months after the closure of the financial year, in accordance with the procedure described in section 4.
  5. 4.
  6. Practical rules Procedures and explanations on the practical modalities regarding the preparation and transmission of the self-assessment questionnaire, the separate report on the protection of financial instruments and funds belonging to clients and the AML/CFT report are made available to institutions and their REA, on the website of the CSSF under the following link: https://edesk.apps.cssf.lu/edeskdashboard/api/v1/documentation/LFRB_GU/en. A user guide “Authentication and user account management” is available to institutions via the eDesk portal of the CSSF.
  7. Final provisions Circular CSSF 22/821, as published on 25 October 2022, repealed Circular CSSF 01/27, as amended by Circulars CSSF 08/340, CSSF 10/484, CSSF 11/521 and CSSF 21/765, as well as Circular IML 96/
  8. It applied from 31 December
  9. The current revised version shall apply as from 31 December
  10. Claude WAMPACH Director Marco ZWICK Director Françoise KAUTHEN Director CIRCULAR CSSF 22/821 as amended by Circulars CSSF 23/845, 24/865 and 25/897 Jean-Pierre FABER Director Claude MARX Director General 9/9 Circular CSSF 24/853 as amended by Circulars CSSF 25/870 and 26/904 LONG FORM REPORT – Practical rules concerning the self-assessment questionnaire to be submitted by investment firms Mission and related reports of the réviseurs d’entreprises agréés (approved statutory auditors) CIRCULAR CSSF 24/853 as amended by Circulars CSSF 25/870 and 26/904 1/13 Circular CSSF 24/853 as amended by Circulars CSSF 25/870 and 26/904 LONG FORM REPORT – Practical rules concerning the selfassessment questionnaire to be submitted by investment firms Mission and related reports of the réviseurs d’entreprises agréés (approved statutory auditors) To investment firms and Luxembourg branches of non-EU investment firms Luxembourg, 30 January 2024 Ladies and Gentlemen, The purpose of this circular is to introduce the key aspects of the revised long form report (the revised LFR) that applies to all investment firms as from the financial year ending on 31 December
  11. The revision of the long form report is the result of a thorough reconsideration of its objective, scope and content in order to realign it with the supervisory and prudential points of focus of the CSSF. Accordingly, the revised LFR has been designed with a view to allowing the CSSF to obtain relevant information as regards investment firms’ compliance with key regulatory provisions. In this view, the revised LFR allows the CSSF to gather sufficient information all the while further facilitating the implementation of a risk-based approach to supervision. In the review process, due consideration has been given to the principle of proportionality, as investment firms will only be required to provide information that is both relevant against the background of their business model and incremental compared to information already provided by them to the CSSF via other reporting obligations and channels, thus reducing redundancies between existing reports. With respect to its form and in line with the CSSF’s digital strategy (CSSF 4.0), the revised LFR turns digital to allow a more efficient reporting processing and ease data analysis. Its completion and submission will be required through the dedicated channel via the online portal of the CSSF. CIRCULAR CSSF 24/853 as amended by Circulars CSSF 25/870 and 26/904 2/13 Table of Contents
  12. Scope of application .................................................................................................... 4
  13. Overview of the revised LFR ......................................................................................... 4
  14. The self-assessment questionnaire (SAQ) ...................................................................... 5
  15. The mission of the REA ................................................................................................ 6 4.
  16. The AUP report(s) .................................................................................................... 6 4.
  17. The MiFID report...................................................................................................... 7 4.
  18. The AML/CFT report ................................................................................................. 7
  19. Submission procedures.............................................................................................. 11 5.
  20. SAQ ..................................................................................................................... 11 5.
  21. Reports prepared by the REA................................................................................... 11 5.
  22. Practical rules ........................................................................................................ 11
  23. Final provisions ........................................................................................................ 12 CIRCULAR CSSF 24/853 as amended by Circulars CSSF 25/870 and 26/904 3/13
  24. Scope of application
  25. This Circular applies in full to all non-SNI IFR investment firms 1 incorporated under Luxembourg law, including their branches (the In-Scope Class 2 IF) 2 and certain 3 SNI IFR investment firms 4 incorporated under Luxembourg law, including their branches (the InScope Class 3 IF), hereafter collectively the Full-Scope IF.
  26. It also applies to Class 3 IF that by reference to their risk attributes represent a comparably lesser risk. These Class 3 IF are not subject to all the requirements of this Circular and are therefore designated as Partial Scope IF. In accordance with the principle of proportionality, the CSSF may adapt the requirements with respect to a specific Partial Scope IF on a case-by-case basis if the CSSF concludes that the IF’s risk profile 5 has changed.
  27. Overview of the revised LFR
  28. The revised LFR comprises four parts that shall be produced on a yearly basis in principle: 1) a Self-Assessment Questionnaire (the SAQ) to be filled in on a yearly basis by the investment firms. The requirement to complete an SAQ is based on the powers of the CSSF to obtain information from investment firms in the context of its legal supervisory mandate and in particular Article 53
(1), second subparagraph, points
(1)and
(2)of the Law of 5 April 1993 on the financial sector, as amended (the LFS) and Article 45
(2), points
(1)and
(2)of the Law of 30 May 2018 on markets in financial instruments, as amended (the MiFID Law); 2) an Agreed-Upon Procedures report to be prepared by the réviseurs d’entreprises agréés (approved statutory auditors, the REA) of the investment firms in accordance with the International Standard on Related Services (ISRS) 4400 (Revised), in application of the legal provisions which authorise the CSSF to request an REA to carry out an audit in relation to one or more specific aspects of the activities and operations of institutions (Article 54
(2)of the LFS and Article 45
(2), point
(9)of the MiFID Law) (the AUP report 6). Each year, the annual AUP report shall cover a sub-set of relevant MiFID aspects, whereas the AUP three-year-cycle will ensure the coverage of all relevant MiFID areas over a period of three
(3)years;

point (9a-2) of Article 1 of the Law of 5 April 1993 on the financial sector, as amended (the LFS). As of the date of issuance of this circular, there is no CRR investment firm

point

(9a)of Article 1 of the LFS being incorporated in Luxembourg nor are there Luxembourg branches of third-country investment firms. 3 The In-Scope Class 3 IF concerned have been selected by the CSSF using a risk-based approach, considering certain representative risk attributes (e.g. business model, size). They were informed bilaterally that they were required to submit the revised LFR for the financial year ending 31 December 2023. 4 Small and non-interconnected investment firms as set out in Article 12
(1)of Regulation (EU) 2019/2033. 5 For this reassessment the CSSF considers all information available and assesses in particular whether the nature, size and complexity including the risks of the entity as a whole or of a specific risk attribute have changed. 6 This report must also cover the branches that the investment firm incorporated under Luxembourg law has abroad. 1 2 CIRCULAR CSSF 24/853 as amended by Circulars CSSF 25/870 and 26/904 4/13 3) a separate report on the protection of financial instruments and funds belonging to clients as required by Article 7 of the Grand-ducal Regulation of 30 May 2018 7 (the MiFID GDR) to be prepared on a yearly basis by the REA (the MiFID report 8); and 4) a separate report on the procedures set up by the investment firm concerning antimoney laundering and countering the financing of terrorism based on Articles 49
(2)and 49
(3)of CSSF Regulation No 12-02 of 14 December 2012 (the RCSSF 12-02) 9 to be prepared on a yearly basis by the REA (the AML/CFT report). Partial Scope IF subject to the revised LFR for the first time for the financial year ending 31 December 2024 are exempted from the submission of the AUP report for the AUP threeyear-cycle starting at the financial year ending 31 December
  1. Please refer to Annex I.
  2. The revised LFR shall apply to investment firms on an individual basis only
  3. No consolidated revised LFR is required where an investment firm is subject to supervision on a consolidated basis by the CSSF.
  4. The four parts of the revised LFR form a single document. The SAQ to be completed by the investment firms represents a key element for defining the contents of the mission of the REA. The REA’s mission is not to validate the SAQ. However, considering the interlinkages between the SAQ and the AUP and MIFID reports of the REA, the REA shall take contact with the CSSF 11 should material errors having an impact on the extent of their work required under section 4 of this Circular be identified in the SAQ.
  5. The self-assessment questionnaire (SAQ)
  6. The aim of the SAQ is to receive relevant and precise information in digital form with respect to governance and MiFID topics.
  7. The SAQ is composed of a “General information” section and several thematic sections. The individual modules of the SAQ and their level of application as well as the applicable exemptions are directly recorded in the CSSF’s digital solution and are also described on the CSSF website.
  8. To give due consideration to the varying business models of investment firms, the purpose of the “General information” section is to activate, based on the answers provided by the investment firm, only those thematic sections that are actually relevant against the background of an investment firm’s given business model.
  9. The information communicated by the investment firm via the SAQ shall be accurate and as concise as possible and be in line with the prudential reporting figures as at the end of the financial year, where applicable. 7 Grand-ducal Regulation of 30 May 2018 on the protection of financial instruments and funds belonging to clients, product governance obligations and the rules applicable to the provision or reception of fees, commissions or any monetary or non-monetary benefits, as amended. 8 This report must also cover the branches that the investment firm incorporated under Luxembourg law has abroad. 9 CSSF Regulation No 12-02 of 14 December 2012 on the fight against money laundering and terrorist financing, as amended. 10 Except for Section 6 of the SAQ “Recommendations or observations raised”. 11 In accordance with Article 54
(3)point 2.a of the LFS. CIRCULAR CSSF 24/853 as amended by Circulars CSSF 25/870 and 26/904 5/13 5. The investment firm is required to upload specific supporting documents as attached documents in the SAQ (e.g. organisation chart, IT flowchart, outsourcing register, summary report of the internal audit function). 4. The mission of the REA 1. Investment firms shall mandate in writing their REA to prepare, on annual basis, the reports listed below. The REA shall be the REA appointed by the investment firm for the statutory audit of its annual accounts. 4.1. 2. The AUP report(
  1. s)The agreed-upon procedures (the AUP) shall be performed in accordance with ISRS 4400 (Revised) applicable to “Agreed-Upon Procedures Engagements”. 3. The REA’s findings shall be clearly documented in the AUP report(
  2. s)to be filled in using a CSSF digital solution. 4. The AUP report is composed of individual thematic sections. Depending on the individual business model of an investment firm, certain thematic sections or procedures of the AUP may not be (fully) applicable. In this case, the REA shall explicitly mention it. 5. The REA shall perform the AUP by using predefined sample sizes, as further specified in the relevant AUP thematic sections. 6. As regards the sample selections (e.g., clients, orders) by the AUP thematic section, the following guiding principles shall apply: a. the Full-Scope IF shall provide the REA with all relevant and complete information pertaining notably to its client database (e.g., client name, client reference, country of residence, date of account opening, MiFID categorisation, client risk profile), its transaction database (e.g., client reference, order reference, ISIN code of the financial instruments, type of financial instruments, nature of the order) and the nature of services effectively provided (discretionary asset management, advisory, execution only) to allow the REA to select a representative sample; b. the REA shall determine samples that are sufficiently diversified and representative in order to accurately reflect the composition of the Full-Scope IF’s client structure and the nature of the transactions performed. In this context, the REA shall notably provide an indication of the relative importance of the sample (for example, the number of the reviewed client files compared to the total number of client files of a specific nature) compared to the total population; c. the REA shall describe, if applicable, additional key elements taken into consideration for the composition of the sample. 7. The REA shall provide a detailed and meaningful description of the findings, if any, by type of clients, transactions and/or financial instruments. CIRCULAR CSSF 24/853 as amended by Circulars CSSF 25/870 and 26/904 6/13 4.2. 8. The MiFID report The MiFID report shall cover the adequacy of the arrangements under Article 37-1
(7)and
(8)of the LFS, Article 13
(4)of the Law of 5 August 2005 on financial collateral arrangements, as amended, and Section 2 of Chapter 1 of the MiFID GDR.
  1. The purpose of the MiFID report is to assess the reliability of the answers provided by an investment firm in the SAQ in relation to the protection of financial instruments and funds belonging to clients.
  2. The authorised management of the investment firm is responsible for providing the REA with the required information in the SAQ for the drafting of the descriptive parts of the MiFID report.
  3. The structure of the MiFID report shall follow the structure of the relevant section of the SAQ on the protection of financial instruments and funds belonging to clients.
  4. The REA shall include in the MiFID report the descriptive elements provided by the investment firm’s authorised management in the SAQ.
  5. In this context, the REA shall (including on the reconciliation process of financial instruments and funds belonging to clients): a. verify and ensure that these elements are correct and adequate; b. assess the appropriateness of the description provided by the investment firm; and c. perform appropriate control procedures to corroborate assertions set forth by the investment firm in the SAQ. Where applicable, the REA shall supplement the descriptive elements by items s/he deems appropriate. Where a specific item does not apply to the investment firm, the REA shall explicitly state it under the item concerned.
  6. The REA shall describe the work performed and the findings, if any, and, where applicable, provide additional information on the aspects of the SAQ.
  7. The MiFID report must be uploaded through a CSSF digital solution. 4.
  8. The AML/CFT report
  9. The AML/CFT report shall describe the procedures set up by the investment firm concerning the prevention of money laundering and terrorist financing as required for compliance with or

: - Chapter 5 of Part II of the LFS; - the Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended (the AML/CFT Law); - the Grand-ducal Regulation of 1 February 2010 providing details on certain provisions of the amended Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended (the Grand-ducal Regulation 2010); - Regulation (EU) 2023/1113 of the European Parliament and of the Council of 31 May 2023 on information accompanying transfers of funds and certain crypto-assets and amending Directive (EU) 2015/849 (Regulation (EU) 2023/1113) CIRCULAR CSSF 24/853 as amended by Circulars CSSF 25/870 and 26/904 7/13 - international acts on the fight against terrorist financing brought to the attention of the investment firms through CSSF circulars; - CSSF regulations on the fight against money laundering and terrorist financing; - CSSF circulars relating to AML/CFT. 17. The AML/CFT report shall provide, in particular: - the description of the AML/CFT policy set up by the investment firm in order to prevent money laundering and terrorist financing, the verification of its compliance with the provisions of Part II, Chapter 5 of the LFS, the AML/CFT Law, the Grand-ducal Regulation 2010, the Regulation (EU) 2023/1113, the CSSF regulations and the CSSF circulars relating to AML/CFT and the control of their sound application; - the assessment of the investment firm’s analysis of money laundering and terrorist financing risks to which it is exposed. The REA must verify if the implemented procedures, infrastructures and controls, as well as the scope of the AML/CFT measures are appropriate considering the money laundering or terrorist financing (ML/TF) risks to which the investment firm is exposed, particularly through its activities, the nature of its customers and the provided products and services; - a declaration on whether an audit of compliance with the investment firm's AML/CFT policy has been performed by the internal audit function and the compliance officer in charge of the control of compliance with the professional obligations 12; - a short description of the training and awareness-raising measures for employees as regards money laundering and terrorist financing, and, in particular, with respect to the identification of money laundering and terrorist financing transactions; - statistics concerning the detected suspicious transactions which indicate the number of suspicious transaction cases reported to the FIU by the investment firm, as well as the total amount of funds involved during the financial year; - the control of the application of the provisions of Regulation (EU) 2023/1113 by the investment firm, in its respective role, and the percentage of the transfers of funds for which data on the payer or payee were missing or incomplete and the measures taken in this context by the investment firm. The AML/CFT report shall also provide: - a description of roles and responsibilities with regard to AML/CFT within the investment firm, including the roles and responsibilities of and the interactions between the management and the different departments and services, indicating the corresponding number of staff involved on AML/CFT matters. The AML/CFT report shall also include a description of the committees and the corresponding hierarchical and functional structures by indicating the general and particular delegations of power with respect to AML/CFT. It shall also provide a description by the investment firm and an assessment by the REA of the three-lines-of-defence model,

Article 39

(7)of RCSSF 1202; - the list of persons involved in AML/CFT matters, as referred to in RCSSF 12-02 and Circular CSSF 20/758 on central administration, internal governance and risk management, as amended (compliance officer, person responsible for compliance, Chief 12

Article 1(1) of RCSSF 12-02.

CIRCULAR CSSF 24/853 as amended by Circulars CSSF 25/870 and 26/904 8/13 Compliance Officer, etc.). It shall also state all the changes with regard to these persons which occurred during the financial year. Since these persons may delegate to members of staff certain operational tasks in relation to these functions, the AML/CFT report shall provide, where appropriate, a description of the delegation mechanism; a description of the network of national agencies, national and foreign subsidiaries, the - branches abroad, the foreign representative offices and the tied agents, as well as the main related ML/FT risks. The AML/CFT report shall also indicate if the investment firm uses the services of external managers as regards the clients' assets and shall, where appropriate, provide a description of the manner in which the relationships with external managers are managed and documented from an AML/CFT perspective; a description of the investment firm’s commercial policy as well as the strategy regarding - the management of the related ML/FT risks. It shall also include a description of how the investment firm monitors and ensures compliance with its internal objectives with regard to ML/FT risk management. The REA shall assess if the investment firm has sufficient financial resources and the appropriate infrastructure to control ML/FT risks to which it is exposed.

  1. When determining the sample, the CSSF expects the REA to apply a risk-based approach, taking into account the different business activities performed. The REA shall state the reference date of the sample data and provide relevant information on the methodology adopted for determining the sample (for example, the number of files reviewed compared to the total number of clients). Where the REA identifies cases of non-compliance with the legal or regulatory provisions or deficiencies, the REA shall give detailed indications enabling the CSSF to assess the situation (number of pending incomplete files as a percentage of the total number of reviewed files, details of the deficiencies identified, etc.).
  2. Where applicable, the AML/CFT report must encompass the investment firm's branches, majority-owned subsidiaries abroad and tied agents. It must cover, in particular, the branches', majority-owned subsidiaries' and tied agents’ compliance with the applicable provisions as regards the prevention of money laundering and terrorist financing and it must include, in that respect: • an analysis of money laundering and terrorist financing risks incurred by the branches, majority-owned subsidiaries and tied agents; • a description and assessment of the money laundering and terrorist financing risk management in the branches, majority-owned subsidiaries and tied agents; • the verification of the implementation of, and compliance with, the investment firm's AML/CFT policy in the branches, majority-owned subsidiaries and tied agents. CIRCULAR CSSF 24/853 as amended by Circulars CSSF 25/870 and 26/904 9/13
  3. The AML/CFT report must be sufficiently exhaustive and transparent, providing detailed descriptions and assessments, in order to allow a precise and informed judgement on the risks incurred by the investment firm with respect to money laundering and terrorist financing. With regard to the language used for the assessments, the AML/CFT report shall not include imprecise negative formulations (e.g. “We did not encounter serious weaknesses”) or global and approximative assessments (e.g. “We noted that most of the points comply with the laws and regulations”). The AML/CFT report shall rather provide a positive assessment for each area and subject by providing an overview of the adopted methodology (e.g. use of the sample technique, method for selecting the sample, etc.) and, where applicable, provide a description of the identified findings in order to allow the CSSF to better understand and judge the extent of the noticed irregularities and weaknesses.
  4. The REA shall also perform the follow-up to the findings observed during the previous audits and described in detail in the previous AML/CFT report.
  5. The REA shall provide a description of any potential issues in relation to AML/CFT the investment firm may have with foreign competent authorities.
  6. The authorised management of the investment firm is responsible for providing the REA with the required information for the drafting of the descriptive parts of the AML/CFT report. The REA may include in its report descriptive elements directly provided by the investment firm’s authorised management, but s/he shall verify and ensure that these elements are correct and adequate. If needed, s/he may have to perform some amendments.
  7. In addition to the descriptive parts, the REA shall perform independently a detailed assessment of the ML/FT risks to which the investment firm is exposed as well as of the organisational aspects. This assessment shall be duly documented.
  8. It should be noted that the REA must also inform the CSSF of all the suspicious transactions reported pursuant to Article 5 of the AML/CFT Law, and which concern the investment firm. Similarly, the REA must inform the CSSF in case they deem that the investment firm should have reported a suspicious transaction but has not, explaining their reasoning and having regard to the investment firm’s rationale. When discussing the cases with the investment firm, the REA needs to be mindful of applicable professional obligations.
  9. The AML/CFT report must be uploaded through a CSSF digital solution. CIRCULAR CSSF 24/853 as amended by Circulars CSSF 25/870 and 26/904 10/13
  10. Submission procedures 5.
  11. SAQ The SAQ must be approved and electronically signed by the authorised management before submitting it to the CSSF
  12. The SAQ must be transmitted on an annual basis 14 to the CSSF in an electronic form via a CSSF digital solution within three months after the end of the financial year, in accordance with the procedure described in Section 5.
  13. 5.
  14. Reports prepared by the REA The AUP report(s), the MiFID report and the AML/CFT report must include the digital signature of the partner in charge of the mandate with the audit firm s/he represents.
  15. The REA submits the AUP report(s) to the investment firm, which can provide comments on the findings identified by the REA. These comments do not form part of the AUP report(s). The AUP report(s) must be submitted subsequently by the investment firm to the CSSF.
  16. The REA submits the MiFID report and the AML/CFT report to the investment firm, which submits them subsequently to the CSSF.
  17. These three reports must be transmitted by the investment firm to the CSSF in electronic form via a CSSF digital solution within seven months after the end of the financial year, in accordance with the procedure described in Section 5.
  18. 5.
  19. Practical rules Procedures and explanations on the practical modalities regarding the preparation and transmission of (i) the SAQ, (ii) the AUP report(s), (iii) the MiFID report and (iv) the AML/CFT report will be available to investment firms and their REA, on the website of the CSSF.
  20. A user guide “Authentication and user account management” is available to investment firms via the eDesk portal of the CSSF. 13 The CSSF will only have access to the answers of the investment firm once the SAQ is approved and uploaded (i.e. the CSSF has no access to preliminary answers provided in the draft SAQ by the investment firm). 14 It has to be noted that the CSSF digital solution includes a roll-forward functionality that will allow investment firm to update the SAQ of year N+1 based on the answers provided in the SAQ of year N. CIRCULAR CSSF 24/853 as amended by Circulars CSSF 25/870 and 26/904 11/13
  21. Final provisions
  22. This circular shall apply with immediate effect. Claude WAMPACH Director Marco ZWICK Director Françoise KAUTHEN Director Annex I Jean-Pierre FABER Director Claude MARX Director General Overview of the scope of application of Circular CSSF 24/853 as amended by Circulars CSSF 25/870 and 26/904 CIRCULAR CSSF 24/853 as amended by Circulars CSSF 25/870 and 26/904 12/13 Annex I: Overview of the scope of application of Circular CSSF 24/853 as amended by Circulars CSSF 25/870 and 26/904 Questionnaire / Report Full Scope IF Partial Scope IF SAQ Required Required AUP report Required Exempted MiFID report Required Required AML/CFT report Required Required required CIRCULAR CSSF 24/853 as amended by Circulars CSSF 25/870 and 26/904 13/13 Circulaire CSSF 26/905 Application des Orientations de l’Autorité bancaire européenne (EBA) en matière de gestion des risques environnementaux, sociaux et de gouvernance (ESG) (EBA/GL/2025/01) En cas de divergences entre les textes français et anglais, le texte anglais prévaut. Circulaire CSSF 26/905 Application des Orientations de l’Autorité bancaire européenne (EBA) en matière de gestion des risques environnementaux, sociaux et de gouvernance (ESG) (EBA/GL/2025/01) À tous les établissements de crédit désignés comme établissements moins importants (« LSI ») 1 conformément au Mécanisme de surveillance unique. Luxembourg, le 20 janvier 2026 Mesdames, Messieurs, L’objet de la présente circulaire est de porter à votre attention l’application, p

🔗 Vers la source officielle

AI explanation based on the official legal text. Indicative, not a substitute for legal advice.