Consumer Protection / Conduct regulatory updates from Luxembourg.
We track 92 Consumer Protection / Conduct updates from Luxembourg regulators, published by CSSF. The archive covers 61 warnings, 22 news items and 5 guidance notes. Most recent update: September 2026. Coverage runs from 2025 to 2026.
This is a formal CSSF communication announcing the entry into force of transposed EU legislation (ECGT Directive) with a specific compliance date. The directive introduces new mandatory requirements for sustainability-related claims in consumer-facing communications across financial services.
This is a regulatory warning issued by CSSF concerning identity theft and fraudulent misuse of Permira Management S.à r.l.'s name. Unknown persons are impersonating the legitimate, authorized alternative investment fund manager through fake contact channels (email, phone numbers) and fraudulent platforms (PHLmax,...
The CSSF warning concerns identity theft and fraudulent misuse of Quintet Private Bank's name through fake websites and email addresses. While the content is relevant to AML/Financial Crime and Consumer Protection, it is administrative in nature—a standard regulatory alert to warn the public and legitimate customers...
The CSSF warning concerns identity theft and fraudulent misuse of the names of two legitimate Luxembourg-regulated firms (ADEPA ASSET MANAGEMENT S.A. and ADEPA ASSET SERVICING Luxembourg S.A.).
The CSSF has issued a warning about unknown persons fraudulently impersonating DAC Investments S.à r.l. using a fake website and email addresses. The warning clarifies that the legitimate company is not responsible for these activities.
This is a CSSF warning against unknown persons fraudulently misusing the name and identity of TEIKO ASSET MANAGEMENT S.À R.L., an unauthorized alternative investment fund manager.
This is a standard regulatory warning against an unlicensed entity (MelzaPay S.A.) claiming to offer financial services from Luxembourg without CSSF authorisation. The warning targets a specific fraudulent operator rather than establishing new obligations or precedent.
The CSSF warning concerns a fraudulent website impersonating BVF CAPITAL S.à r.l., involving identity theft and illicit activities. While the warning addresses financial crime and consumer protection concerns, it is a standard administrative alert about a specific fraudulent operation rather than a binding obligation...
The CSSF has issued a warning about unknown persons fraudulently impersonating ICI Invest S.A. using a fake website, email addresses, and phone numbers. The warning clarifies that the legitimate company is not responsible for these activities.
CSSF warning about identity theft and fraudulent impersonation of a legitimate Luxembourg alternative investment fund manager. High urgency due to active fraud scheme using fake contact details and website to deceive consumers and investors.
CSSF warning of identity theft and fraudulent impersonation of Luxembourg-registered company Molentis S.A. Fraudsters using fake website, email, and claiming false registered office. High urgency due to active fraud scheme targeting financial sector participants and potential customers.
CSSF warning of identity theft and fraudulent impersonation of a legitimate tied agent. High urgency due to active fraud scheme using fake website and email addresses targeting clients of Gablau Invest Sàrl, requiring immediate awareness among market participants and consumers.
CSSF warning against unauthorized entity claiming to provide investment services from Luxembourg. Critical for investor protection as 3cGroup operates without proper authorization and supervision. High urgency due to active illicit operations and potential fraud risk to consumers.
CSSF warning about identity theft and fraudulent impersonation of legitimate investment firm. Fraudsters using fake website, emails, and phone number to deceive customers. High urgency due to active fraud scheme targeting financial services sector, requiring immediate awareness among regulated entities and consumers.
CSSF warning about identity theft and fraudulent impersonation of Gekko Fund SICAV. Unknown persons misusing the fund's name through fake website, email addresses, and phone number to conduct illicit activities.
CSSF warning of identity theft and fraudulent impersonation of legitimate investment firm. Fraudsters using fake websites to misrepresent Winvest International S.C.S., FIAR. High urgency due to active fraud scheme targeting consumers and potential reputational harm to legitimate entity.
This is an informational press release from CSSF announcing the judicial dissolution and liquidation of DIVERSIFIED ASSET MANAGEMENT S.A., an investment firm. The document details the court order, appointment of liquidator and official receiver, and procedures for eligible clients to claim compensation through the...
CSSF warning about fraudulent impersonation of Luxempart S.A., a securities issuer. Unknown persons misusing the company name for identity theft and illicit activities. High urgency due to active fraud scheme targeting investors and stakeholders, requiring immediate awareness across financial institutions.
ESMA has withdrawn its MiFID II/MiFIR market data Guidelines because their subject matter has been transposed into Commission Delegated Regulation (EU) 2025/1156 on the obligation to make market data available on a reasonable commercial basis. As a result, CSSF Circular 21/783, which implemented those ESMA Guidelines in Luxembourg supervisory practice, will become formally outdated from 23 August 2026, requiring MiFID firms and trading venues to ensure their policies and commercial terms now fully align with the directly applicable RTS in the Delegated Regulation.
Key dates
12 June 2025
- Commission Delegated Regulation (EU) 2025/1156 is adopted, supplementing MiFIR with RTS on the obligation to make market data available to the public on a reasonable commercial basis
23 August 2026
- ESMA Guidelines on MiFID II/MiFIR market data obligations are withdrawn; CSSF Circular 21/783, which incorporated these Guidelines into CSSF administrative practice, becomes outdated from this date
Suggested considerations
Identify and catalogue all internal policies, procedures, contractual templates, and pricing frameworks that reference CSSF Circular 21/783 or ESMA’s MiFID II/MiFIR market data Guidelines.
Review Commission Delegated Regulation (EU) 2025/1156 in detail and map its RTS requirements (e.g. cost-based pricing, non-discriminatory access, data unbundling, publication formats) against current market data practices.
Update market data pricing policies to ensure that fees are demonstrably based on reasonable commercial basis criteria defined in Delegated Regulation (EU) 2025/1156, including documentation of cost allocation and margin methodology.
Revise market data access policies and client terms to ensure non‑discriminatory conditions and appropriate unbundling of pre‑trade and post‑trade data, in line with the RTS.
Amend compliance manuals, MiFID/MiFIR control frameworks, and training materials to remove references to CSSF Circular 21/783 and ESMA Guidelines, replacing them with references to Delegated Regulation (EU) 2025/1156.
What changed
- CSSF Circular 21/783, which applied ESMA’s Guidelines on MiFID II/MiFIR obligations on market data in Luxembourg, will cease to be applicable as of 23 August 2026 and is formally classified as...
The supervisory reference framework for market data obligations in Luxembourg shifts from ESMA soft-law Guidelines to binding regulatory technical standards contained in Commission Delegated...
Requirements on making market data available to the public on a “reasonable commercial basis” are now set out in directly applicable EU law, including detailed RTS criteria on cost-based pricing,...
ESMA’s interpretative role via Guidelines is replaced by binding RTS, which reduces reliance on national circulars and increases harmonisation of market data rules across EU trading venues and data...
Luxembourg firms can no longer rely on Circular 21/783 as the primary interpretative document for market data obligations; instead, their compliance frameworks must directly reference Delegated...
Compliance impact
Non-compliance will now be assessed directly against binding RTS under Delegated Regulation (EU) 2025/1156, increasing enforcement risk if market data is priced or provided on terms that are not objectively “reasonable” or non‑discriminatory. Firms that fail to adapt their frameworks by 23 August 2026 risk supervisory findings, potential sanctions, and challenges to their market data commercial models.
CSSF warning of identity theft and fraudulent impersonation of authorized Luxembourg asset manager. Multiple fraudulent contact channels (websites, emails, phone numbers) used to deceive consumers. High urgency due to active fraud scheme targeting investors, though informational in nature as a regulatory alert.
CSSF warning of fraudulent website impersonating legitimate financial services company. Involves identity theft, illicit activities, and unauthorized financial services provision. Critical urgency due to active fraud threat to consumers and need for immediate awareness across financial sector.
CSSF warning about fraudulent impersonation of Clearstream Banking S.A. using fake contact details. This is a financial crime alert requiring immediate awareness among market participants to prevent fraud victimization.
ESMA supervisory briefing on triangular passporting under MiFID II, establishing common supervisory expectations for investment firms using branches/tied agents across multiple EU member states. Informational guidance on regulatory framework, firm responsibilities, and client protections.
The CSSF has republished its MiFID II/MiFIR FAQ (Q&A) in a version dated 13 July 2026, consolidating guidance on investor protection, conduct of business, and reporting obligations applicable to Luxembourg MiFID firms. While the publication page itself is largely technical (cookies, website functioning), firms should treat the 13 July 2026 FAQ version as the current CSSF interpretative benchmark for MiFID II/MiFIR compliance, aligned with ESMA Q&As and recent EU‑level MiFID II/MiFIR review developments.
Key dates
02 March 2026
- Most revised MiFIR transparency requirements under the MiFID II/MiFIR review (amending Delegated Regulation) apply at EU level, influencing the content and focus of national FAQs and supervisory guidance, including CSSF’s
13 July 2026 Deadline
- CSSF publishes/updates the MiFID II/MiFIR FAQ version dated 13 July 2026, which becomes the current reference point for CSSF supervisory expectations on MiFID II/MiFIR compliance
Suggested considerations
Review the latest CSSF MiFID II/MiFIR FAQ (13 July 2026 version) in full, comparing it against existing internal MiFID II/MiFIR policies, procedures, and controls to identify gaps or misalignments.
Confirm and, where necessary, update client‑facing disclosures to clearly state whether investment services (especially advice and portfolio management) are provided on an independent or non‑independent basis, and ensure that inducement arrangements are consistent with this classification.
Reassess inducement frameworks (commissions, fees, non‑monetary benefits) for investment advice and portfolio management to ensure that no prohibited inducements are received or retained where services are independent or involve portfolio management.
Review and update product governance frameworks, including target market definition processes and product approval procedures, to ensure that each instrument’s intended target market is properly documented and consistently used by distributors.
Examine best execution policies to confirm they are clear, detailed, and understandable to clients, and implement or enhance ongoing monitoring mechanisms (e.g. execution quality reports, periodic reviews) to evidence compliance with best execution obligations.
What changed
Because the visible page content provided is limited to technical and cookie‑related information, the key points below focus on the regulatory substance of the CSSF MiFID II/MiFIR FAQ (Q&A) as the...
The CSSF confirms the application of MiFID II investor protection rules to Luxembourg investment service providers, including obligations on inducements, suitability, product governance, and best...
The FAQ reiterates that investment services providers must inform clients clearly whether their investment advice or services are provided on an independent or non‑independent basis, and explains the...
The FAQ clarifies that inducements are expressly prohibited when investment advice is provided on an independent basis and for portfolio management services, requiring firms to structure their...
The CSSF guidance reflects product governance obligations: manufacturers must define a target market for each financial instrument based on clients’ knowledge and experience, financial situation,...
Compliance impact
Non‑compliance with CSSF’s MiFID II/MiFIR expectations can lead to supervisory findings, remediation orders, administrative sanctions, and potential reputational damage, particularly where investor protection (suitability, inducements, best execution) is compromised. Given the 2026 EU‑level MiFID II/MiFIR review changes and the updated FAQ, firms that fail to update frameworks risk being assessed against a higher and more current supervisory benchmark.
CSSF warning of identity theft and impersonation of regulated investment firm European Broker S.A. Luxembourg. Fraudsters using spoofed email address to conduct illicit activities. High urgency due to active fraud threat affecting multiple stakeholders and need for immediate awareness among market participants.
CSSF warning against unauthorized entity Nexura VG operating without proper authorization to provide investment/financial services. High urgency due to active illicit operations and consumer protection risk, though not critical as it is a warning rather than emergency alert.
CSSF warning against unauthorized entity SB Systems sp. Zo.o conducting fraudulent investment services from Luxembourg without authorization. Critical urgency due to active fraud alert requiring immediate awareness among regulated entities and consumers.
CSSF warning about fraudulent impersonation of regulated investment firm 2 PM EUROPE S.A. through fake website, email, and phone contact details. Identity theft and illicit activities pose direct risks to consumers and market integrity.
Informational update from CSSF regarding the end of MiCA transition period for virtual asset service providers on 1 July 2026. Focuses on regulatory compliance requirements, consumer guidance on checking provider authorizations, and wind-down procedures for non-compliant providers.
CSSF warning of fraudulent website impersonating legitimate Luxembourg financial services firm. Identity theft and illicit activities pose immediate risk to consumers and regulated entities. Critical urgency due to active fraud scheme requiring immediate awareness and protective action.
CSSF warning of fraudulent website impersonating legitimate Luxembourg-based investment firms (Indylux Capital and Kherty Finance). Alert involves identity theft, illicit activities, and unauthorized use of company names across multiple jurisdictions.
ESMA directive regarding wind-down of unauthorised crypto-asset service providers as MiCA transitional period concludes. High urgency due to regulatory deadline and mandatory compliance requirement for unauthorised providers, with emphasis on client asset safeguarding during transition.
CSSF warning about identity theft and fraud targeting Luxembourg investment fund managers with German branches. Involves forged websites and financial guarantees.
ESMA statement on Common Supervisory Action results regarding MiFID II sustainability integration in suitability assessments and product governance. Informational regulatory guidance with proportionate supervisory approach during sustainable finance framework transition. No immediate enforcement action indicated.
CSSF warning of identity theft and fraudulent impersonation of authorized investment fund manager Nordea Investment Funds S.A. High urgency due to active fraud scheme using spoofed email addresses and phone numbers targeting potential investors/clients. Requires immediate awareness among market participants.
CSSF warning against unauthorized crypto exchange operating without Luxembourg authorization. High urgency due to active illicit operations and consumer protection risk, though not critical as it is a warning rather than emergency alert.
CSSF warning of fraudulent website impersonating regulated fund manager RBC Funds (Lux). Involves identity theft, illicit activities, and unauthorized use of legitimate company credentials. Critical urgency due to active fraud targeting investors and potential harm to regulated entity's reputation and customer trust.
CSSF clarification on ML/FT risk management expectations, addressing de-risking practices and financial inclusion balance. Informational guidance to supervised entities on proper risk management frameworks rather than risk avoidance, with emphasis on proportionate customer assessment and cooperation requirements.
CSSF warning about fraudulent website impersonating legitimate investment undertaking (Robus Umbrella). Involves identity theft and illicit activities targeting collective investment scheme. High urgency due to active fraud threat to consumers and potential reputational harm to regulated entity.
CSSF warning of identity theft and fraudulent impersonation of authorized alternative investment fund manager. Unknown persons misusing legitimate firm's name and contact details to conduct illicit activities.
Administrative sanction imposed on Stonehage Fleming Luxembourg S.A.
AI Analysis
The CSSF has announced that an **administrative sanction was imposed on Stonehage Fleming Luxembourg S.A. on 5 March 2026**, but it has not yet published the underlying decision or grounds. For compliance teams, this signals that the CSSF continues to actively use sanctions against Luxembourg wealth/asset management entities and that a detailed decision is likely forthcoming, which may contain important precedents on governance, AML/CFT or conduct requirements.
Key dates
05 March 2026
- CSSF imposes the administrative sanction on Stonehage Fleming Luxembourg S.A. (date of decision)
09 June 2026
- CSSF publicly announces the administrative sanction and the existence of a PDF decision (date of publication on CSSF website)
Suggested considerations
Monitor the CSSF website for publication of the detailed PDF decision relating to the administrative sanction of 5 March 2026 against Stonehage Fleming Luxembourg S.A.
Once available, review the full decision to identify the specific legal bases (e.g. LFS, Law of 2010, Law of 2013, AML/CFT Law) and control failures cited by the CSSF.
Map the identified weaknesses from the decision against your firm’s governance, internal control, delegate oversight and AML/CFT frameworks to identify any similar risk areas.
Update internal compliance risk assessments to reflect the enforcement themes highlighted in this and recent CSSF sanctions, including the weighting of enforcement risk for organisational and AML/CFT deficiencies.
Review and, where necessary, strengthen board and senior management oversight arrangements, including the documentation of decisions, challenge and escalation processes, in anticipation of CSSF expectations evidenced in the forthcoming decision.
What changed
At this stage, based on the CSSF notice alone, no new legal or regulatory requirements are introduced; the publication is a transparency notice that a sanction decision exists.
the Law of 5 April 1993 on the financial sector (LFS), the Law of 17 December 2010 on undertakings for collective investment, the Law of 12 July 2013 on AIFMs, and the Law of 12 November 2004 on the...
the CSSF’s established practice of publishing individual sanction decisions, which typically detail shortcomings in organisational requirements, internal controls, oversight of delegates, conduct of...
the legal provisions breached (for example, Articles 109–111 and 148 of the Law of 2010 or Articles 2-2, 3 and 8-4 of the AML/CFT Law, by analogy with other CSSF sanctions),
the factual deficiencies identified (e.g., weaknesses in governance, delegate oversight, AML risk assessment, customer due diligence), and
Compliance impact
The specific financial and qualitative impact of this particular sanction is not yet public, but recent CSSF cases show that deficiencies in governance, delegate oversight and AML/CFT controls can lead to significant fines, public censure and supervisory follow-up. Non-compliance increases the likelihood of intrusive inspections, remediation programmes under CSSF scrutiny, and reputational risk with clients and counterparties.
CSSF warning against unauthorized entity claiming to offer investment services without Luxembourg authorization. High urgency due to active illicit operations and consumer protection risk, though not critical as it is a warning notice rather than emergency alert.
CSSF warning of fraudulent website impersonating legitimate wealth manager. Identity theft and illicit activities pose immediate risk to consumers and the legitimate firm's reputation. High urgency due to active fraud scheme targeting financial services clients.
The CSSF has published a Feedback Report following a thematic review of the **valuation framework for less liquid and illiquid assets**, focused primarily on Luxembourg AIFMs managing AIFs in asset classes such as private equity, real estate, infrastructure, private debt and fund of funds, and on UCITS “trash ratio” positions under Article 41(2) of the UCI Law. All Luxembourg IFMs are explicitly expected to benchmark their existing valuation frameworks against the CSSF’s observations and recommendations and to implement corrective measures, with valuation risk confirmed as a key supervisory priority for 2026.
Key dates
End 2023
– CSSF thematic review launched by dedicated questionnaire to IFMs, with work conducted through 2024 and 2025 (contextual start of the current thematic exercise)
Throughout 2024 and 2025
– CSSF conducts off‑site and on‑site work as part of the dedicated thematic review on valuation frameworks for less liquid and illiquid assets
2026 Deadline
– Valuation risk for less liquid and illiquid assets is confirmed as a key supervisory priority, implying heightened supervisory focus and potential follow‑up actions during the year; no hard implementation deadline is set but prompt action is implicitly expected
04 June 2026
– CSSF publishes the Communication and Feedback Report on the thematic review and formally expects IFMs to perform a benchmarking exercise and implement corrective measures as needed
Suggested considerations
Perform a structured benchmarking of existing valuation policies, procedures, methodologies and controls against the detailed observations and recommendations in the CSSF Feedback Report on valuation frameworks for less liquid and illiquid assets.
Document, at IFM and fund level, all identified gaps or weaknesses in the current valuation framework, including for AIFs in illiquid strategies and UCITS Article 41(2) trash ratio positions.
Develop and approve a remediation plan with clear owners, milestones and target dates to address identified shortcomings in valuation governance, methodologies, model validation, data sources and control processes.
Review and, where necessary, update valuation policies and procedures to ensure they explicitly cover less liquid and illiquid assets, stressed market conditions, use of external valuers, and documentation standards across the investment lifecycle.
Enhance valuation governance by clearly defining roles and responsibilities (including segregation from portfolio management where applicable), escalation procedures, and oversight by the board/senior management.
What changed
- The CSSF publishes a dedicated Feedback Report on the thematic review of valuation frameworks for less liquid and illiquid assets and formally expects IFMs to use it as guidance for implementing...
All Luxembourg IFMs are required to conduct a benchmarking exercise of their valuation frameworks against the CSSF’s observations and recommendations set out in the new Feedback Report.
Where gaps or weaknesses are identified through this benchmarking, IFMs are expected to implement corrective measures to strengthen their valuation policies, procedures and lifecycle controls for...
The thematic review scope formally covers AIFMs of AIFs investing in less liquid and illiquid assets (including private equity, real estate, infrastructure, private debt and fund of funds), and, on...
The CSSF explicitly links this thematic work to previous supervisory exercises (ESMA CSA on valuation, CSSF self‑assessment questionnaires, and on‑site inspection feedback) and consolidates...
Compliance impact
Failure to benchmark and remediate valuation frameworks for less liquid and illiquid assets exposes IFMs to material supervisory risk, including targeted reviews, formal remedial orders or sanctions, particularly given the CSSF’s designation of valuation risk as a key supervisory priority in 2026. Deficient valuation practices also heighten the risk of NAV errors, investor detriment and potential civil liability or reputational damage.
CSSF warning against unauthorized entity claiming to provide investment services without Luxembourg authorization. High urgency due to active illicit operations and consumer protection risk. Entity operating across multiple financial service categories without proper licensing.
amending the regulatory technical standards laid down in Delegated Regulation (EU) 2019/979 as regards updating the list of data necessary for the classification of prospectuses and the list of information that can be incorporated by reference into prospectuses
AI Analysis
Commission Delegated Regulation (EU) 2026/395 of 23 February 2026 amends the Prospectus Regulation RTS in Delegated Regulation (EU) 2019/979 to update: (i) the **data set used for ESMA classification and filing of prospectuses** and (ii) the **categories of information that may be incorporated by reference** into a prospectus.
For compliance teams in Luxembourg and across the EU, this means prospectus production, filing templates, and reference documentation frameworks must be revised so that all new prospectuses and supplements meet the updated RTS data and incorporation-by-reference standards under Regulation (EU) 2017/1129.
Key dates
14 March 2019
- Original Delegated Regulation (EU) 2019/979 is adopted, setting the RTS on key financial information, publication and classification of prospectuses, advertisements, supplements and incorporation by reference
23 February 2026
- Commission Delegated Regulation (EU) 2026/395 is adopted, amending Delegated Regulation (EU) 2019/979 on the list of data necessary for prospectus classification and the list of information allowed to be incorporated by reference
2 June 2026
- CSSF publishes notice of Delegated Regulation (EU) 2026/395, signalling its relevance for Luxembourg‑supervised entities and prospectus approval processes
TBD (upon OJ publication)
- The Delegated Regulation will enter into force on the date specified in the Official Journal; in line with standard EU practice, firms should expect application from a specified date shortly after OJ publication and plan prospectus updates accordingly
Suggested considerations
Map all existing prospectus templates, checklists and workflows against the revised Delegated Regulation (EU) 2019/979 data fields and immediately identify gaps in prospectus classification data and reference documentation.
Update internal prospectus data dictionaries and metadata schemas so that all new and updated prospectuses capture the full revised list of ESMA classification data required by the amended RTS.
Review and revise the firm’s incorporation‑by‑reference policy, including standard clauses and cross‑reference tables, to ensure only information categories permitted under the updated RTS are incorporated by reference.
Reconfigure electronic filing tools and interfaces used for submissions to the CSSF (and other NCAs) so that they generate and transmit the updated RTS data set required for classification and ESMA register purposes.
Train legal, capital markets, and product teams involved in prospectus drafting on the new RTS requirements, including examples of acceptable and non‑acceptable incorporation‑by‑reference documents.
What changed
- The amending Delegated Regulation updates the list of data fields required for the classification of prospectuses under Delegated Regulation (EU) 2019/979, impacting how issuers and their advisors...
The RTS amendment revises the list of information that can be incorporated by reference into a prospectus, narrowing or clarifying which external documents (e.g.
Prospectus classification data fields are expected to better align with current ESMA Prospectus Register needs (for example finer product type, offer type, and home/host state metadata), requiring...
The updated incorporation-by-reference list seeks to ensure that only readily accessible and reliable information may be referenced, which will affect how issuers structure cross‑references to annual...
National competent authorities, including the CSSF, will apply the revised RTS when reviewing and approving prospectuses and supplements, meaning filings that use outdated data sets or ineligible...
Compliance impact
Non‑compliance can lead to prospectus approval delays, rejection of filings, or required resubmissions, which may disrupt issuance timetables and investor communications. Persistent or material breaches may expose firms and issuers to supervisory measures, sanctions, and reputational risk for failing to meet Prospectus Regulation standards.
CSSF warning of fraudulent website impersonating authorized alternative investment fund manager. Identity theft and illicit activities pose direct risk to consumers and market integrity. High urgency due to active fraud scheme targeting legitimate firm's reputation and potential investor harm.
This warning from the CSSF relates to potential illicit activities by an unauthorized entity operating a website called 'werdy.net', which is offering investment services or other financial services without authorization in Luxembourg.
This regulatory warning concerns fraudulent activities misusing the name of a licensed crypto-asset service provider and electronic money institution, Coinbase Luxembourg S.A.
This warning concerns an unauthorized entity named Afitaustin that is allegedly providing investment services or other financial services without authorization in Luxembourg. This poses risks to consumers and could involve illicit activities, requiring a high level of urgency.
This is a warning from the CSSF about a potentially fraudulent website called Nuveramix, which is not authorized to provide investment or financial services in Luxembourg. This is a high urgency issue as it involves potential financial fraud targeting consumers.
on key information documents for packaged retail and insurance-based investment products
Why this matters
This regulatory update relates to the Law of 17 April 2018 on key information documents for packaged retail and insurance-based investment products, which impacts firms in the banking, investment management, and insurance sectors.
This regulatory update provides a list of members of the CPDI, which is relevant for firms in the banking, investment management, and wealth management sectors. The topics covered include AML/financial crime, consumer protection, and authorization/licensing, which are important for these types of firms.
Application of the Guidelines of the European Securities and Markets Authority for the criteria on the assessment of knowledge and competence under the Markets in Crypto Assets Regulation (MiCA) (ESMA35-24871704-2922)
AI Analysis
Circular CSSF 26/909 specifies how the CSSF applies ESMA's Guidelines (ESMA35-24871704-2922) for assessing **knowledge and competence** criteria under MiCA, targeting staff involved in crypto-asset services. It matters because it enforces MiCA's staff certification requirements, ensuring Luxembourg CASPs meet EU-wide standards for consumer protection and operational integrity amid the full MiCA rollout on 30 December 2024.
Assess Staff Competence: Implement ESMA-guided evaluations (e.g., exams, certifications) for all relevant personnel handling crypto services; document results in governance frameworks.
Update Policies and Training: Integrate competence criteria into HR, onboarding, and annual reviews; roll out MiCA-specific training on reporting, breaches, and governance.
Licensing Dossier Enhancement: Include competence attestations in CSSF applications; appoint dedicated compliance/risk officers with verified qualifications.
Ongoing Monitoring: Conduct regular audits, penetration tests, and incident planning; confirm compliance annually via management body statements.
Early CSSF Engagement: Schedule dialogues and info sessions; create MiCA readiness scorecards for board and regulator discussions.
What changed
- Adoption of ESMA Guidelines: CSSF mandates application of ESMA's criteria for evaluating staff knowledge and competence in crypto-asset services, including roles in custody, trading, portfolio...
Assessment Framework: Firms must implement standardized tests and processes to verify staff qualifications, aligning with MiCA Article 62 on CASP authorization, focusing on technical crypto...
No New Standalone Rules: This circular builds on prior CSSF MiCA circulars (e.g., 25/890 on crypto-asset classification), integrating competence checks into licensing dossiers and ongoing supervision.
Compliance impact
Urgency: High – With publication today (1 April 2026) and MiCA's CASP regime live since 30 December 2024, firms face immediate supervisory scrutiny during licensing and VASP transitions ending 1 July 2026. Non-compliance risks authorization denial, enforcement, or operational halts, especially as CSSF audits dossiers for competence gaps amid Luxembourg's role as MiCA hub.
This regulatory update from the CSSF focuses on improving financial education and empowerment, particularly for women, through a walking challenge program. It covers consumer protection, sustainability, and technology aspects relevant to banks, wealth managers, and fintechs.
The CSSF Technical FAQ on Regulation No 20-08 provides implementation guidance on **loan-to-value (LTV) limits for residential real estate credit in Luxembourg**, establishing borrower-based macroprudential measures designed to limit leverage in the mortgage market. This guidance is critical for lenders operating in Luxembourg as it clarifies how to calculate own funds, determine LTV compliance, and apply temporary portfolio exemptions that have been extended through June 30, 2025.
Key dates
December 3, 2020
- CSSF Regulation No 20-08 originally published
January 1, 2021
- Regulation and LTV limits became effective for residential real estate credit on Luxembourg territory
May 21, 2024
- CSSF Regulation No 24-04 introduced temporary adjustments to LTV limits
December 30, 2024
- CSSF Regulation No 24-10 extended temporary adjustments
January 7, 2025
- Most recent Technical FAQ version published (prior to March 9, 2026 update)
Suggested considerations
*For all lenders:
*Verify LTV compliance calculations for all new residential mortgage originations using the framework specified in the FAQ, ensuring own funds are calculated as actual equity contributions from borrowers
*Implement dual LTV tracking for borrowers financing new property through sale of existing property, ensuring compliance with both interim and final LTV ratios
*Document own funds sources carefully, particularly when cash collateral or sale proceeds are used, as these are only permitted for loans with initial LTV below 100%
*Prepare for June 30, 2025 transition by:
What changed
The most recent update (March 9, 2026) to the Technical FAQ reflects the regulatory framework established by CSSF Regulation No 20-08 (as modified by Regulation No 24-10).
First-time buyers: LTV limit of up to 100%
Other buyers: LTV limit of 90%, implemented via portfolio allowance
Buy-to-Let Residential Loans:
Standard LTV limit of 80%
Temporary exemption (until June 30, 2025): Lenders may apply LTV ratios up to 95% for up to 10% of annual production
Other Residential Real Estate Loans:
This is a warning from the CSSF about fraudsters misusing the name of the CSSF Board Chair to contact supervised entities. It is relevant for banks, wealth managers, and all financial firms that may be targeted by such fraud attempts. The warning covers consumer protection, AML, and operational resilience topics.
This regulatory update from the CSSF covers consumer protection and financial crime issues, which are relevant for banking, wealth management, and fintech firms. The medium urgency reflects the ongoing nature of these compliance requirements.
This is a warning from the CSSF about fraudulent activities misusing the name of JPMorgan Asset Management (Europe) S.à r.l., an investment management firm. It involves identity theft, illicit activities, and impersonation, which pose risks to consumers and the financial sector.
in relation to additional liquidity management requirements for Luxembourg-domiciled UCITS, or where applicable their management company, and Luxembourg-authorised AIFMs that manage open-ended AIFs, introduced by the Law of 3 March 2026, transposing Directive (EU) 2024/927 of the European Parliament and of the Council…
Why this matters
This regulatory update introduces new liquidity management requirements for UCITS and open-ended AIFs in Luxembourg, which is relevant for investment managers and banks operating in the investment fund industry.
This is a warning from the CSSF regarding a fraudulent website impersonating a Luxembourg-based bank, Sumitomo Mitsui Trust Bank (Luxembourg) S.A. This poses risks of identity theft and illicit activities, which is of high importance for banks and wealth managers to be aware of.
This is a warning from the CSSF regarding a fraudulent website impersonating a legitimate electronic money institution, VIVID MONEY S.A. The warning covers identity theft and illicit activities, which are relevant to AML/financial crime and consumer protection.
This regulatory update provides a breakdown of UCIs (Undertakings for Collective Investment) registered in Luxembourg by reference currency. It is informational in nature, covering statistics and data related to the investment management industry, banking, and wealth management firms operating in Luxembourg.
This is a warning from the CSSF regarding fraudulent websites impersonating a regulated investment firm, which poses risks of identity theft and illicit activities. It is a high-urgency issue for banks, wealth managers, and fintechs that may be targeted or impersonated by such scams.
This warning concerns a fraudulent website impersonating a legitimate investment firm, which poses risks of identity theft and illicit activities. It is relevant to banking, investment management, and wealth management firms, as well as fintechs, and requires prompt attention due to the potential for consumer harm.
Administrative sanction imposed on an investment firm
AI Analysis
The CSSF imposed an administrative sanction on 8 October 2025 against an unnamed investment firm, as detailed in a publication released on 4 March 2026. This enforcement action underscores CSSF's rigorous oversight of investment firms, particularly in areas like AML/CFT compliance, conduct rules, and organizational requirements, serving as a warning for similar entities to strengthen cooperation and internal controls. It matters because it highlights escalating fines for repeated or material breaches, potentially influencing supervisory expectations across Luxembourg's financial sector.
Key dates
10 January 2025
- Date of prior depositary oversight fine
4 April 2025 Deadline
- Deadline for submitting CSSF AML/CFT Questionnaire (breach example from similar case)
16 July 2025
- Date of fine imposition for UCITS investment policy breaches
11 September 2025
- Date of fine imposition in comparable AIFM non-cooperation case
8 October 2025
- Date of the sanction in question
Suggested considerations
Enhance cooperation protocols: Implement automated tracking for CSSF requests (e.g., questionnaires) with escalations for reminders; document all responses.
Review investment compliance: Audit broker exposures, valuation processes, and subscription/redemption controls against UCI Law Articles 41-43, 109; suspend dealings if uncertainties arise.
Strengthen governance: Conduct gap analyses on internal controls, risk assessments, and reporting for depositary/oversight functions per AIFM Law Article 19(9) and CDR 231/2013.
Training and monitoring: Roll out firm-wide training on AML/CFT obligations (Article 5(1)) and perform reconciliations of assets/records; prepare for on-site/off-site CSSF inspections.
Self-reporting: Proactively disclose prior breaches to mitigate fine severity.
What changed
No new regulatory changes or requirements are introduced; this is an enforcement action applying existing rules.
Failure to cooperate with CSSF requests, e.g., not submitting required AML/CFT questionnaires by deadlines, violating Article 5(1) of the amended Law of 12 November 2004 on AML/CFT.
Non-compliance with investment policies, organizational requirements, or conduct rules under the UCI Law (e.g., Articles 41, 43, 109), including improper broker exposures or valuation failures.
These reflect ongoing enforcement of established frameworks like the AIFM Law, UCI Law, and AML/CFT Law, with fines calibrated by factors like breach duration, firm size, cooperation level, and prior...
Compliance impact
Urgency: High - This matters due to CSSF's pattern of publicizing nominative sanctions (e.g., Max Gain Capital, Zeus Asset Management), signaling increased scrutiny on investment firms amid AML/CFT and conduct risks. Fines (EUR 10,000–127,500) represent material hits (up to 10% of turnover), with factors like poor cooperation amplifying penalties; firms with similar exposures face elevated inspection risk, especially post-2025 enforcement wave.
This directive establishes a public register of the audit profession in the EU, which is relevant for banking, investment management, and wealth management firms that are subject to audit requirements. The topics covered include AML/financial crime, consumer protection, and reporting/disclosure obligations.
This is a warning from the CSSF about fraudulent activities carried out by an unauthorized entity called Aisbierg Ennerstetzung Bank, which is posing as a financial services provider.
This is a warning from the CSSF about fraudulent activities by persons misusing the name of MERITUM CAPITAL, a Luxembourg-based investment management firm. The warning covers identity theft, illicit activities, and the use of unauthorized websites and email addresses.
This warning concerns a fraudulent website impersonating a legitimate investment firm, which poses risks of identity theft and illicit activities. It is a high-priority issue for banks, wealth managers, and fintechs that may be targeted or impacted by this scam.
This warning concerns a fraudulent website impersonating a legitimate investment management firm, which poses risks of identity theft and illicit activities. It is a high-urgency issue for firms in the banking, investment management, and wealth management sectors that need to be aware of this scam and take appropriate...
This warning from the CSSF relates to potential illicit activities associated with the website www.qatari.xyz, which is not authorized to provide investment or financial services in Luxembourg. This is a high-urgency issue for banks, wealth managers, and fintechs that may be impacted by this unauthorized entity.
This warning concerns fraudulent activities by an unauthorized entity, Minea Global Finance SA, which is not supervised by the CSSF and has not been granted any authorization to provide investment or financial services in Luxembourg. This poses a high risk to consumers and the financial system.
This regulatory update from the CSSF provides monthly statistics on the net assets of Undertakings for Collective Investment (UCIs), which are investment funds. This information is relevant for investment management firms, banks, and wealth managers that operate or invest in these types of funds.
This regulatory update provides a breakdown of UCIs (Undertakings for Collective Investment) registered in Luxembourg by reference currency. It is an informational update for investment management firms, banks, and wealth managers that operate in the Luxembourg market.
This regulatory update provides a list of investment funds (UCIs and SIFs) that have a sharia-compliant policy, which is relevant for investment management and wealth management firms.
This warning concerns a fraudulent website impersonating a legitimate financial services firm, which poses risks of identity theft and illicit activities. It is relevant for banks, wealth managers, and fintechs that may be targeted or impersonated in such scams.
This regulatory update warns about online financial frauds and scams in an artificial intelligence world, which is highly relevant for banking, investment management, and wealth management firms, as well as fintechs and crypto exchanges that operate in the digital finance space.
This regulatory update from the CSSF warns about crypto frauds and scams, which is relevant for crypto exchanges and all firms dealing with crypto assets. It covers consumer protection and AML/financial crime topics.
This is a warning from the CSSF regarding an unauthorized entity, Castleforbes Wealth Limited, that is allegedly providing investment services without proper authorization in Luxembourg.
This regulatory update provides information on a registration form for meetings with UCI Departments of the CSSF, which is relevant for financial firms in the banking, investment management, and wealth management sectors.
This is a warning about fraudulent activities misusing the name of a specific investment fund, which is relevant for investment managers and wealth managers who need to be aware of such scams to protect their clients.
This regulatory update from the CSSF relates to a product intervention measure taken by the German regulator BaFin regarding turbo certificates. It impacts the marketing, distribution and sale of these products to retail clients in Germany, which is relevant for banking, investment management and capital markets firms...
This regulatory update relates to the registration of EU/EEA mortgage credit intermediaries operating in Luxembourg under the freedom to provide services, which is relevant for banking, credit, and mortgage lending firms.
This regulatory update from the CSSF provides guidance for 'finfluencers' on responsible promotion, which is relevant for investment management firms, wealth managers, banks, and fintechs that engage in digital marketing and social media activities.
Rules applicable to undertakings for collective investment when they employ certain techniques and instruments relating to transferable securities and money market instruments
AI Analysis
Circular CSSF 08/356, as amended by Circular CSSF 25/901, establishes detailed rules for Luxembourg undertakings for collective investment (UCIs), including UCITS and alternative investment funds (AIFs), on the use of techniques and instruments relating to transferable securities and money market instruments, such as securities lending, repo transactions, and over-the-counter (OTC) derivatives. It matters because it ensures investor protection, risk management, and market stability by imposing strict eligibility, collateral, and operational requirements, aligning Luxembourg funds with EU standards under UCITS and AIFMD directives. Compliance is critical for Luxembourg-domiciled funds engaging in these activities to avoid regulatory sanctions and operational disruptions.
Key dates
23 December 2008
- Original Circular CSSF 08/356 effective date for UCITS III implementation
21 July 2011
- Partial updates for UCITS IV alignment
22 July 2013
- Extension to AIFs under AIFMD transposition
15 October 2025
- Issuance of amending Circular CSSF 25/901
01 January 2026
- Effective date for amendments (e.g., new collateral rules, reporting formats)
Suggested considerations
*Policy Review & Update: Revise fund prospectuses, KIIDs, and risk management policies to reflect amended limits (e.g., counterparty caps, ESG collateral) within 3 months of 01 January 2026.
*Risk Management Systems: Implement or upgrade systems for daily collateral valuation, stress testing, and exposure monitoring; conduct gap analysis against Section 4 requirements.
*Counterparty Due Diligence: Reassess OTC counterparties for eligibility (e.g., EMIR clearing thresholds); negotiate ISDA/CSA agreements with updated haircuts.
*Operational Setup: Appoint triparty agents where required; ensure collateral segregation complies with Section 5.
*Reporting & Disclosure: Prepare for new quarterly CSSF filings (template in Annex 1); disclose revenues/reinvestments from techniques in annual reports (Article 14 UCITS Law).
What changed
The original Circular CSSF 08/356 (2008) transposed UCITS III requirements on eligible techniques like securities lending and repos.
Expanded collateral rules: Collateral must now include sustainable assets meeting SFDR criteria, with daily marking-to-market and haircuts adjusted for liquidity and credit risk (Section 3).
Counterparty exposure limits: Net exposure to a single OTC counterparty capped at 10% of net asset value (NAV), down from previous thresholds in some cases, with mandatory collateralization (Section...
Operational safeguards: Mandatory use of triparty agents for repos, enhanced segregation of collateral, and annual stress testing disclosures (Section 5, as amended).
Reporting enhancements: Quarterly reports to CSSF on transaction volumes, risks, and revenues from these activities (Annex 1, updated).
These align with ESMA guidelines (e.g., ESMA/2012/832 on OTC...
Compliance impact
Urgency: High - Immediate relevance for funds actively using these techniques (common in fixed-income and equity strategies for yield enhancement). Non-compliance risks CSSF fines (up to 5% of NAV), temporary prohibitions on techniques, or fund suspension. With the 01 January 2026 effective date recently passed (as of current context), firms face heightened scrutiny in 2026 reporting cycles; proactive remediation avoids enforcement actions amid CSSF's focus on operational resilience.
This regulatory update discusses a supply-chain attack targeting NPM packages, which could impact firms across the financial services sector. It is relevant for banks, fintechs, and all firms that rely on third-party software and services.
This regulatory update warns about loan scams on social media, which is relevant for banking, consumer credit, and mortgage lending firms. It covers consumer protection and anti-money laundering topics, and is applicable to banks, fintechs, and all firms that engage in lending activities.
This regulatory update relates to the takeover of Iris Financial S.A. by Younited Financial S.A., which are firms operating in the banking, investment management, and wealth management sectors. The key topics covered include authorization and licensing, prudential/capital requirements, and consumer protection.