Investment Management regulatory updates from Luxembourg.
We track 373 Investment Management updates from Luxembourg regulators, published by CSSF. The archive covers 233 news items, 56 warnings and 43 guidance notes. Most recent update: September 2026. Coverage runs from 2020 to 2026.
This is a formal CSSF communication announcing the entry into force of transposed EU legislation (ECGT Directive) with a specific compliance date. The directive introduces new mandatory requirements for sustainability-related claims in consumer-facing communications across financial services.
This is a standard quarterly statistics release from CSSF (Commission de Surveillance du Secteur Financier) presenting data on authorised and other investment fund managers as of 30 June 2026.
for Luxembourg-domiciled funds subject to the 2010 Law relating to UCIs, specialised investment funds governed by the Law of 13 February 2007, and investment companies in risk capital governed by the Law of 15 June 2004.
Why this matters
This is a CSSF communiqué establishing mandatory notification procedures through the eDesk 'LMT activation' module for suspension of redemptions under national law. The update implements transposition of EU Directive 2024/927 and applies to UCIs, specialised investment funds, and risk capital investment companies.
The CSSF warning concerns identity theft and fraudulent misuse of CYCLOPE INVESTISSEMENTS' name via a spoofed website, email, and phone numbers. The legitimate firm is a specialised investment fund under Luxembourg law.
This is a regulatory warning issued by CSSF concerning identity theft and fraudulent misuse of Permira Management S.à r.l.'s name. Unknown persons are impersonating the legitimate, authorized alternative investment fund manager through fake contact channels (email, phone numbers) and fraudulent platforms (PHLmax,...
This is a consumer protection alert issued by CSSF (Commission de Surveillance du Secteur Financier) warning of identity theft and fraudulent activities conducted under the name of Axxion S.A., a legitimate alternative investment fund manager.
The CSSF warning concerns identity theft and fraudulent misuse of the names of two legitimate Luxembourg-regulated firms (ADEPA ASSET MANAGEMENT S.A. and ADEPA ASSET SERVICING Luxembourg S.A.).
The CSSF has issued a warning about unknown persons fraudulently impersonating DAC Investments S.à r.l. using a fake website and email addresses. The warning clarifies that the legitimate company is not responsible for these activities.
This is a CSSF warning against unknown persons fraudulently misusing the name and identity of TEIKO ASSET MANAGEMENT S.À R.L., an unauthorized alternative investment fund manager.
Overview of the CSSF’s activities and initiatives in 2025
Why this matters
This is an annual report from the Commission de Surveillance du Secteur Financier (Luxembourg's financial regulator) summarizing 2025 activities, initiatives, and references to EBA/ESMA guidelines. The content is primarily informational and administrative in nature.
This is a news announcement of an educational webinar by CSSF and ALFI to present findings from a June 2026 thematic review on valuation of less liquid and illiquid assets. The webinar is invitation-only for professionals at Luxembourg investment fund managers and administrators.
This is a standard monthly press release from CSSF providing aggregate data on undertakings for collective investment (UCIs), including net asset figures, market performance by category, and administrative changes (registrations/deregistrations).
Launch of the public API for the consultation of fund identification data
Why this matters
This is an informational announcement about a new CSSF service (eRegister by eDesk) providing API access to fund identification data. It describes a voluntary, opt-in tool requiring prior agreement rather than imposing binding obligations.
This is a standard monthly statistical report on Undertakings for Collective Investment (UCIs) published by the CSSF (Luxembourg financial regulator). The content consists of basic statistical data in spreadsheet format with no regulatory announcements, guidance, or binding requirements.
The document is primarily a data publication (net assets of Undertakings for Collective Investment as at 31 July 2026) from CSSF with references to EBA/ESMA guidelines and a public register. The bulk of the visible content is boilerplate cookie and website usage policy.
This is a standard monthly statistics release from CSSF (Commission de Surveillance du Secteur Financier) presenting breakdowns of Undertakings for Collective Investment (UCIs) registered in Luxembourg by reference currency.
This is a monthly statistical report published by the CSSF (Commission de Surveillance du Secteur Financier) showing the geographic origin of Undertakings for Collective Investment (UCI) initiators in Luxembourg as of 31 July 2026. The content consists of a data download and reference to a statistics page.
The document is primarily a snapshot of UCI statistics published by CSSF (Luxembourg's financial regulator) as of 31 July 2026. The content references EBA and ESMA guidelines and includes standard website cookie/privacy notices.
This is a monthly statistics release from CSSF (Commission de Surveillance du Secteur Financier) presenting aggregated data on Undertakings for Collective Investment (UCIs) broken down by investment policy as of 31 July 2026.
on requirements on the use of ICT third-party services for Financial Entities subject to the Digital Operational Resilience Act (DORA)
AI Analysis
Circular CSSF 25/882 establishes Luxembourg-specific requirements for DORA financial entities using ICT third-party services, including professional-secrecy safeguards, prior notification, annual registers of information and cloud-governance responsibilities. Circular CSSF 26/915, effective 27 August 2026, expands the circular to qualifying third-country branches in Luxembourg, with immediate effect and no separate transition period.
Key dates
2025-01-17
DORA became applicable to in-scope financial entities, according to the CSSF implementation communication referenced by Circular CSSF 25/882.
2025-04-09
Circular CSSF 25/882 was published and applied with immediate effect.
2025-04-01 Deadline
The first exceptional CSSF register submission window opened for arrangements contracted up to 31 March 2025.
2025-04-15 Deadline
The first exceptional CSSF register submission window closed.
2026-08-27
Circular CSSF 26/915 was published and immediately amended Circular CSSF 25/882 to include qualifying third-country branches in Luxembourg.
2027-03-31 Deadline
Latest date for submission of the register covering arrangements contracted through the end of 2026, under the recurring annual window running from 28 February to 31 March of the following year.
Suggested considerations
Firms should assess whether Luxembourg third-country branches now fall within the amended scope by comparing the branch’s undertaking and head-office activities with the DORA categories in Article 2(1)(a) to (t) and documenting the conclusion.
Compliance teams may wish to inventory all ICT third-party arrangements, including digital, data, cloud, infrastructure and operational services that may not qualify as outsourcing under prior CSSF terminology.
Firms should consider updating ICT third-party approval workflows so arrangements supporting critical or important functions are notified through the CSSF-prescribed form at least three months before commencement, or one month before commencement where the provider is an eligible Luxembourg support PFS.
Firms should maintain an accurate register of information at individual, sub-consolidated and consolidated levels, with controls for prompt correction when requested by the CSSF and the ability to provide the register outside the annual submission window.
Compliance and outsourcing teams may wish to reassess contractual access to professional-secrecy data against Article 41(2a) LFS or Article 30(2a) LPS and verify that Luxembourg ICT management or operations providers hold the required Article 29-3 LFS authorisation or qualify for an applicable exception.
Firms using cloud services should confirm that the resource operator has designated a suitably qualified cloud officer and that internal cloud, information-security and third-party oversight responsibilities are clearly allocated.
Third-country branches should consider implementing the requirements immediately because Circular CSSF 26/915 provides no transition period, while preserving evidence of governance, notification and register controls for supervisory review.
What changed
Circular CSSF 26/915 includes in Circular CSSF 25/882’s scope all Luxembourg third-country branches of undertakings covered by the specified DORA financial-entity categories where the head office would qualify as a DORA entity under Article 2(1)(a) to (t) in the relevant third country. The requirements apply to ICT services broadly, not only arrangements that meet a traditional outsourcing definition.
Compliance impact
The amendment materially increases the population subject to Luxembourg’s ICT third-party controls because qualifying third-country branches must comply immediately, without a transition period. Non-compliance may leave arrangements formally untreated as notified and expose firms to supervisory measures, binding measures and administrative sanctions, while firms remain fully responsible for compliance and for the resilience and governance of their ICT third-party providers.
Application of the Joint ESA Guidelines on the estimation of aggregated annual costs and losses caused by major ICT-related incidents under Regulation (EU) 2022/2554 (JC 2024 34)
AI Analysis
CSSF Circular 25/892 applies the ESAs’ Joint Guidelines JC/GL/2024/34 for estimating aggregated annual costs and losses from major ICT-related incidents under Article 11(10) and (11) of DORA. Circular 26/915, issued on 2026-08-27, immediately extends that framework to qualifying Luxembourg branches of third-country undertakings, while leaving the underlying methodology unchanged.
Key dates
2025-05-19
The Joint ESA Guidelines JC/GL/2024/34 apply at ESA level.
2025-05-31
Circular CSSF 25/892 applies to its original in-scope Luxembourg entities, excluding DORA microenterprises.
2026-08-27
Circular CSSF 26/915 is issued and applies with immediate effect, bringing qualifying Luxembourg third-country branches into the scope of Circular CSSF 25/892.
Suggested considerations
Compliance teams may wish to determine whether each Luxembourg entity or third-country branch falls within the amended scope, including whether a third-country head-office undertaking would qualify under DORA Article 2(1)(a) to (t).
Firms should consider documenting their microenterprise analysis against DORA Article 3(60), including the fewer-than-10-employees and EUR 2 million annual turnover and/or balance-sheet-total thresholds, while noting that the DORA definition excludes trading venues, central counterparties, trade repositories and central securities depositories from the microenterprise exemption.
Firms should consider maintaining an incident-level ledger linking major ICT-related incidents, DORA final-report reference codes, gross costs, losses, provisions, recoveries and subsequent adjustments.
Finance, operational-risk and ICT-incident teams may wish to agree whether the firm will use a completed calendar year or completed accounting year as its reference basis and establish controls to apply that basis consistently.
Firms should consider reconciling estimates to financial-statement or supervisory-reporting data where available, while retaining documented estimation methodology and assumptions where accurate data is unavailable.
Firms should consider tracking quantifiable financial impacts from prior-year major incidents because those impacts may need to be included in a later reference year without reopening the original final incident report.
Third-country branches may wish to confirm reporting ownership and data availability with their head office, because the amended CSSF scope is at branch level but the required cost and loss information may arise across the undertaking.
Compliance teams may wish to monitor CSSF communications for a specific request, reporting channel and submission deadline; the circular itself establishes an upon-request obligation rather than a fixed automatic annual filing deadline.
What changed
From 2025-05-31, in-scope Luxembourg financial entities other than DORA microenterprises must be able, upon CSSF request, to provide an entity-level estimate of aggregated annual costs and losses arising from major ICT-related incidents. The estimate must use the ESA common template and identify each relevant incident by the same reference code used in its DORA final incident report.
Compliance impact
The requirement is operationally significant because firms must preserve incident-level financial-impact data, distinguish gross costs from recoveries and retain historical linkage to DORA final incident reports, even though submission occurs only upon competent-authority request. The ESAs’ approach does not impose a minimum cost threshold: every incident classified as major must be covered, irrespective of the classification trigger, increasing the importance of coordination between ICT, operational risk, finance and regulatory reporting teams.
on reporting of major ICT-related incidents and significant cyber threats under the Digital Operational Resilience Act (DORA)
AI Analysis
CSSF Circular 25/893 establishes the Luxembourg reporting process for major ICT-related incidents and significant cyber threats under Regulation (EU) 2022/2554 (DORA), replacing the former CSSF 24/847 framework for DORA entities and extending the same framework to payment service providers outside DORA. The 27 August 2026 update, issued through Circular CSSF 26/915 (although the page title refers to 25/915), expressly brings qualifying Luxembourg branches of third-country financial entities within the DORA-related scope, increasing the population required to maintain rapid, event-specific reporting capability.
Key dates
2025-01-17
DORA provisions became applicable to financial entities in scope and supervised by the CSSF.
2025-05-28
Circular CSSF 25/893 was published and established the Luxembourg DORA incident and significant cyber-threat reporting modalities.
2025-11-28 Deadline
End of the six-month transition period granted to payment service providers outside DORA for implementation of the Circular 25/893 framework.
2026-08-27
Circular CSSF 26/915 was published and the 25/893 page was updated to clarify DORA applicability to qualifying third-country branches in Luxembourg; the amendment applies immediately.
Suggested considerations
Compliance teams may wish to confirm the entity-by-entity scope analysis against DORA Article 2, including whether a Luxembourg third-country branch is covered following the 27 August 2026 clarification.
Firms should consider documenting incident-classification criteria and decision records against Commission Delegated Regulation (EU) 2024/1772, including the quantitative thresholds for clients, transactions, duration, geographical spread, data loss, economic impact and reputational impact.
Firms should consider testing an escalation timetable that supports classification, initial notification within four hours and no later than 24 hours after awareness, the 72-hour intermediate report and the one-month final report.
PSPs outside DORA may wish to update policies so that all ICT-related incidents, rather than only payment-service incidents, are assessed under the DORA framework and to verify that the six-month transition requirements were completed by 28 November 2025.
Firms should consider ensuring that eDesk access, authorised users, templates, internal approvals and S3 API connectivity are operational before an incident occurs.
Incident-response procedures may wish to prohibit aggregation of separate major incidents where the CSSF reporting process requires event-specific submissions and should assign ownership even where reporting support is outsourced.
Third-country branches may wish to align their Luxembourg reporting playbooks, head-office escalation arrangements and local CSSF contacts with the immediate-effect scope clarification.
Firms should consider retaining evidence of classification, notification times, report versions, management approvals and communications with ICT third parties to demonstrate timely compliance.
What changed
DORA financial entities supervised by the CSSF must classify ICT-related incidents using the criteria and thresholds in Commission Delegated Regulation (EU) 2024/1772 and report each major ICT-related incident using the DORA reporting templates and procedures. Reporting is phased: an initial notification is generally due within four hours after classification as major and in any event no later than 24 hours after the entity becomes aware of the incident; an intermediate report is generally due within 72 hours after the initial notification; and a final report is generally due within one month...
Compliance impact
The framework creates time-critical supervisory reporting obligations with potentially material consequences for firms unable to classify or notify major incidents accurately and promptly; the regulated entity remains accountable even when submission is delegated. The 2026 clarification is particularly significant for third-country branches because it removes scope uncertainty and requires immediate integration of local branch incident reporting into DORA governance and response arrangements.
CSSF Circular 22/806 has been updated to reflect Circular 25/883 and the 27 August 2026 Circular 26/915. The framework now distinguishes between ICT outsourcing governed primarily by DORA and business-process outsourcing governed by Circular 22/806, while confirming that DORA applies to qualifying Luxembourg branches of third-country financial entities; this materially affects outsourcing inventories, contractual controls, registers of information and supervisory reporting.
Key dates
2022-04-22
Circular CSSF 22/806 was published and replaced or amended specified earlier CSSF and IML outsourcing, governance and control circulars.
2022-06-30
Circular CSSF 22/806 became applicable according to the CSSF implementation framework.
2025-01-17
DORA Regulation (EU) 2022/2554 became applicable to in-scope financial entities, creating the primary EU framework for ICT third-party risk management.
2025-04-09
Circular CSSF 25/883 was published; the amended Circular 22/806 applies to outsourcing arrangements entered into, reviewed or amended on or after this date.
2025-12-17
The European Commission confirmed that DORA also applies to qualifying third-country branches in an EU Member State where the third-country head-office entity would fall within DORA Article 2(1)(a) to (t).
2026-08-27
Circular CSSF 26/915 was published and the CSSF webpage consolidated the amended version of Circular 22/806, confirming the DORA treatment of qualifying Luxembourg third-country branches.
Suggested considerations
Firms should map each outsourcing and third-party technology arrangement against the applicable regime: DORA, Circular 22/806 business-process outsourcing requirements, or the full Circular 22/806 framework for non-DORA entities.
Compliance teams may wish to review whether Luxembourg third-country branches have a head-office activity that corresponds to a DORA Article 2(1)(a) to (t) financial entity and document the resulting DORA scope assessment.
Firms should update outsourcing policies, risk assessments, governance approvals, materiality or criticality assessments, due-diligence files, monitoring controls and exit strategies to reflect the split between DORA ICT third-party risk management and Circular 22/806 business-process outsourcing.
Firms should maintain or update the DORA register of information for ICT third-party arrangements where DORA applies, and reconcile it with the outsourcing inventory and CSSF notification processes.
Firms should review legacy cloud contracts and remove reliance on the repealed Circular 22/806 EEA-law and EEA-resilience clauses where DORA is the applicable ICT third-party regime, while retaining contract terms needed to satisfy DORA and any applicable national requirements.
Non-DORA entities should consider whether their existing contracts still address Circular 22/806 requirements for access and audit rights, sub-outsourcing, confidentiality, data location, business continuity, termination and exit.
Management companies authorised solely under Article 125-1 should consider retaining the full Circular 22/806 control framework for ICT outsourcing rather than assuming that DORA displaces it.
Firms should assess whether outsourcing arrangements entered into, reviewed or amended from 9 April 2025 require remediation or re-papering under the amended framework.
What changed
Circular 25/883 amended Circular 22/806 following DORA Regulation (EU) 2022/2554 becoming applicable on 17 January 2025. For entities subject to DORA, the ICT-outsourcing provisions of Circular 22/806 were largely repealed or displaced by DORA's ICT third-party risk-management requirements, while Circular 22/806 remains applicable to business-process outsourcing.
Compliance impact
The impact is high for firms with complex ICT and outsourcing models because misclassification can lead to the wrong contractual, governance, register and notification framework, and because DORA brings direct requirements for ICT third-party risk management and supervisory oversight. Independent market commentary from EY, Deloitte, Baker McKenzie and Luxembourg industry bodies reads the amendments as a practical division between DORA-regulated ICT services and Circular 22/806 business-process outsourcing, with particular remediation needs for investment managers, non-DORA entities and...
This is a CSSF warning against unknown persons misusing the name of INTERNATIONAL FUND SERVICES & ASSET MANAGEMENT S.A., an investment firm. The warning identifies fraudulent contact details (email: [email protected]) and clarifies that the legitimate company is not responsible for these activities.
This is a standard regulatory warning against an unlicensed entity (MelzaPay S.A.) claiming to offer financial services from Luxembourg without CSSF authorisation. The warning targets a specific fraudulent operator rather than establishing new obligations or precedent.
The CSSF warning concerns a fraudulent website impersonating BVF CAPITAL S.à r.l., involving identity theft and illicit activities. While the warning addresses financial crime and consumer protection concerns, it is a standard administrative alert about a specific fraudulent operation rather than a binding obligation...
This is a CSSF warning against unknown persons fraudulently misusing the name of NEVENTA MANAGEMENT, a registered alternative investment fund manager. The warning provides fraudulent contact details (website, email) to help the public identify and avoid the scam.
Information to be provided by a ManCo15 managing a European UCITS (UCITS without compartments)
Why this matters
This is a form update published by the CSSF (Luxembourg financial regulator) for ManCos managing European UCITS without compartments. The content is purely procedural—providing an updated template for information submission. No new rules, enforcement actions, or substantive policy guidance are present.
Information to be provided by a Luxembourg AIFM which manages an AIF non-authorised by the CSSF (AIF without compartments)
Why this matters
This is a form update published by the CSSF for Luxembourg AIFMs managing non-authorised AIFs. The content is procedural—providing a template for initial/update submissions—with a related circular (CSSF 25/894) that establishes the underlying reporting requirement.
Information to be provided by a Luxembourg AIFM which manages an AIF non-authorised by the CSSF (AIF with multiple compartments)
Why this matters
This is a form update published by the CSSF (Luxembourg regulator) for AIFMs managing non-authorised AIFs with multiple compartments. The content is purely procedural—providing an updated template for information submission.
The CSSF has issued a warning about unknown persons fraudulently impersonating ICI Invest S.A. using a fake website, email addresses, and phone numbers. The warning clarifies that the legitimate company is not responsible for these activities.
CSSF warning about identity theft and fraudulent impersonation of a legitimate Luxembourg alternative investment fund manager. High urgency due to active fraud scheme using fake contact details and website to deceive consumers and investors.
CSSF warning of identity theft and fraudulent impersonation of a legitimate tied agent. High urgency due to active fraud scheme using fake website and email addresses targeting clients of Gablau Invest Sàrl, requiring immediate awareness among market participants and consumers.
CSSF warning against unauthorized entity claiming to provide investment services from Luxembourg. Critical for investor protection as 3cGroup operates without proper authorization and supervision. High urgency due to active illicit operations and potential fraud risk to consumers.
This is a regulatory statistical report from CSSF on collective investment undertakings (UCIs) in Luxembourg as of June 2026. It provides market data, net asset information, and lists of newly registered and deregistered funds.
CSSF warning about identity theft and fraudulent impersonation of legitimate investment firm. Fraudsters using fake website, emails, and phone number to deceive customers. High urgency due to active fraud scheme targeting financial services sector, requiring immediate awareness among regulated entities and consumers.
The CSSF is formally drawing attention to the CNC Q&A 26/038, which provides detailed interpretative guidance on the **new accounting regime introduced by the Law of 7 August 2023** for large not‑for‑profit associations, public‑utility associations and foundations. This matters for compliance teams because these entities are now aligned with the accounting regime for “medium‑sized undertakings” under Luxembourg company law, with specific obligations on annual accounts formats, filing, and chart‑of‑accounts choices that require governance, process and system changes.
Key dates
07 August 2023
- Law of 7 August 2023 introducing the new accounting regime for associations and foundations enters into force and defines classification as “small associations”, “medium‑sized associations” and “large associations” with corresponding accounting obligations
Autumn 2026
- CNC plans to publish an accounting guide dedicated to the new accounting regime for ASBLs classified as small, medium‑sized and large associations, and associations recognised as being of public utility
04 August 2026
- CSSF press release is published, formally drawing supervisory attention to CNC Q&A 26/038 and the related upcoming CNC accounting guide
Suggested considerations
Identify all Luxembourg associations, public‑utility associations and foundations within or related to the group that are impacted by the Law of 7 August 2023 and confirm their size classification (small, medium‑sized, large) and whether they fall under the “medium‑sized undertakings” regime.
Review existing accounting policies, charts of accounts and annual accounts formats for affected entities to ensure alignment with LRCS statutory layouts, including non‑abridged balance sheet, appropriate profit and loss format, and required notes disclosures.
Decide at governing‑body level whether each affected entity will voluntarily adopt the PCN or maintain an internal chart of accounts, documenting the rationale, governance approvals and compliance impacts of the chosen option.
Where PCN is not adopted, design, implement and document a robust mapping from the internal chart of accounts to the statutory LRCS balance sheet and profit and loss layouts, ensuring audit‑ready documentation and traceability.
Update accounting systems and reporting tools for affected entities to support LRCS statutory layouts, consistent layout adaptations, and classic‑format filing with the RCS, including necessary changes to interfaces and data capture.
What changed
- Large associations, associations recognised as being of public utility and foundations are now subject to the accounting regime applicable to “medium‑sized undertakings” under the amended...
Annual accounts for affected entities must include a non‑abridged balance sheet, a profit and loss account (at least in abridged format), and notes to the accounts containing disclosures required by...
Affected entities must use statutory LRCS layouts for the balance sheet and profit and loss account and file their annual accounts in classic format with the Luxembourg Trade and Companies Register...
Large associations, public‑utility associations and foundations remain exempt from the mandatory use of the Standard Chart of Accounts (Plan Comptable Normalisé – PCN) and from eCDF standard data...
Affected entities may voluntarily adopt the PCN; if they do not adopt PCN, they must maintain an internal chart of accounts and ensure robust, documented mapping between internal accounts and...
Compliance impact
Non‑compliance may result in defective or non‑compliant annual accounts filings, potential rejection or queries from the RCS, and heightened supervisory scrutiny by the CSSF where the entities are linked to regulated groups, with knock‑on effects on group reporting and reputational risk. For larger public‑interest or group‑related entities, persistent non‑compliance could trigger audit qualifications and regulatory concerns about governance and internal control over financial reporting.
The CSSF is formally drawing attention to CNC Q&A 26/038, which provides detailed interpretative guidance on the **new accounting regime introduced by the Law of 7 August 2023** for large not‑for‑profit associations, public‑utility associations and foundations. This matters for compliance teams because these entities are now subject to annual accounts obligations aligned with the regime for “medium‑sized undertakings” under the Luxembourg commercial companies law, with specific rules on formats, exemptions from PCN/eCDF, and forthcoming detailed guidance for all association size categories.
Key dates
01 January 2023
- Earliest financial year start date from which adjusted size criteria under Articles 35 and 47 LRCS may be applied to undertakings and groups, which indirectly affects categorisation and accounting obligations of entities subject to commercial‑law size criteria
07 August 2023
- Law of 7 August 2023 introducing the new accounting regime for associations and foundations is adopted, setting the legal basis for reclassification and annual accounts obligations
01 January 2024
- Default application date of the adjusted LRCS size criteria for undertakings and groups where early application from 01 January 2023 is not chosen
Financial year 2025
- New LRCS size thresholds start to determine the categorisation of pre‑existing Luxembourg undertakings and, by analogy, influence assessments of “medium‑sized” status relevant to associations
Autumn 2026
- CNC plans to publish an accounting guide dedicated to the new accounting regime for not‑for‑profit associations (ASBLs) classified as small, medium‑sized and large, as well as public‑utility associations and foundations
Suggested considerations
Identify whether the organisation qualifies as a large association, an association recognised as being of public utility or a foundation under the Law of 7 August 2023, and document the classification decision with reference to Articles 18, 36 and 52 of that law.
Update internal accounting policies to require annual accounts to be prepared in accordance with the regime for undertakings referred to in Article 47 LRCS, including minimum content (balance sheet, profit and loss account and notes) and disclosure requirements.
Decide formally whether to adopt the PCN on a voluntary basis or to maintain an internal chart of accounts, and record this decision in accounting governance documents approved by the board or governing body.
Where PCN is not adopted, design and implement a detailed and documented mapping from internal general ledger accounts to LRCS statutory balance sheet and profit and loss layouts to ensure accurate preparation and filing of annual accounts.
Review and, where necessary, redesign annual accounts templates to comply with LRCS layouts while making only permitted adaptations (for example, titles and subtotals) that maintain clarity, comparability and consistency over time.
What changed
- Large not‑for‑profit associations, associations recognised as being of public utility and foundations are required to prepare annual accounting documents consisting at a minimum of annual accounts...
These entities fall within the regime applicable to “medium‑sized undertakings”, which drives the required content and level of detail of their annual accounts (balance sheet, profit and loss account...
The law and the CNC Q&A confirm that large associations, public‑utility associations and foundations are not legally required to use the Standard chart of accounts (Plan comptable normalisé, PCN) or...
Although exempt from mandatory PCN use and eCDF standard data collection, these entities must still file their annual accounts with the Luxembourg Trade and Companies Register (RCS) using statutory...
Large associations, public‑utility associations and foundations are exempt from the obligation to file the PCN trial balance (balance générale) via the eCDF platform, even though they may still...
Compliance impact
Non‑compliance primarily exposes large associations, public‑utility associations and foundations to deficiencies in statutory annual accounts and registry filings, which can lead to legal and governance risks, increased audit findings and potential supervisory concerns where the CSSF has a stake. For CSSF‑regulated firms, reliance on non‑compliant counterparties may undermine financial reporting integrity and due‑diligence standards, with knock‑on effects in broader regulatory reviews.
CSSF warning about identity theft and fraudulent impersonation of Gekko Fund SICAV. Unknown persons misusing the fund's name through fake website, email addresses, and phone number to conduct illicit activities.
CSSF publication providing statistical analysis and best practices guidance on processing times for initial authorizations of regulated investment vehicles (UCITS, SIFs, PII L10). Informational content sharing regulatory expectations and procedural guidance for fund authorization applicants.
CSSF communication regarding implementation of AIFMD II directive changes for Luxembourg-domiciled investment fund managers. Provides updated notification templates and procedural guidance for cross-border management activities within the EEA. Informational in nature with implementation deadline of 31 July 2026.
CSSF warning of identity theft and fraudulent impersonation of legitimate investment firm. Fraudsters using fake websites to misrepresent Winvest International S.C.S., FIAR. High urgency due to active fraud scheme targeting consumers and potential reputational harm to legitimate entity.
This is an informational notification letter from CSSF regarding AIFM procedures for managing AIFs across Member States or establishing branches under AIFMD Article 33.
This is an informational notification letter from CSSF regarding the UCITS Directive framework for management companies seeking to pursue authorized activities in other EU Member States. It provides a template form for cross-border notification under Articles 17(2) and 18(1) of Directive 2009/65/EC.
This is a monthly statistical publication by CSSF on Undertakings for Collective Investment (UCIs), providing basic statistical data for June 2026. It is informational/reporting content with no regulatory action or deadline, hence urgency is null.
Quarterly statistical publication by CSSF (Luxembourg financial regulator) reporting on UCI (Undertakings for Collective Investment) net assets, fund counts, and unit volumes. This is informational regulatory reporting data relevant to asset managers and investment funds.
This is an administrative form update from CSSF for UCI depositary authorization applications. It is informational/procedural content regarding licensing requirements for entities acting as depositaries for Undertakings for Collective Investment.
ESMA Common Supervisory Action targeting UCITS Management Companies and Alternative Investment Fund Managers on risk management function effectiveness. Focuses on governance, risk identification/measurement/monitoring, and reporting requirements.
CSSF newsletter is a periodic informational publication covering latest regulatory publications and financial sector statistics. No specific regulatory action, deadline, or urgent requirement indicated. Content is general across multiple sectors and firm types, warranting 'All Firms' classification.
This is an informational press release from CSSF announcing the judicial dissolution and liquidation of DIVERSIFIED ASSET MANAGEMENT S.A., an investment firm. The document details the court order, appointment of liquidator and official receiver, and procedures for eligible clients to claim compensation through the...
CSSF warning about fraudulent impersonation of Luxempart S.A., a securities issuer. Unknown persons misusing the company name for identity theft and illicit activities. High urgency due to active fraud scheme targeting investors and stakeholders, requiring immediate awareness across financial institutions.
CSSF warning of identity theft and fraudulent impersonation of authorized Luxembourg asset manager. Multiple fraudulent contact channels (websites, emails, phone numbers) used to deceive consumers. High urgency due to active fraud scheme targeting investors, though informational in nature as a regulatory alert.
Administrative sanction imposed on Transnet Soc Ltd
AI Analysis
The CSSF has published an administrative sanction dated 21 July 2026 in respect of Transnet Soc Ltd, a South African issuer with Luxembourg as home Member State under the Transparency regime. Although the notice itself is very brief, it clearly continues a pattern of enforcement against Transnet for breaches of the Luxembourg Law of 11 January 2008 on transparency requirements for issuers (Transparency Law), including a prior EUR 15,000 fine for late publication of its annual financial report. For compliance teams, this underscores the CSSF’s willingness to publicly sanction and name issuers that fail to meet periodic disclosure obligations, even for relatively modest monetary amounts.
Key dates
31 March 2021 Deadline
– End of the financial year referenced in the prior CSSF sanction against Transnet Soc Ltd for failure to publish its annual financial report within the required time limit
15 November 2021
– CSSF imposed an administrative fine of EUR 15,000 on Transnet Soc Ltd under Article 25(2) of the Transparency Law for late publication of the annual financial report as of 31 March 2021
21 July 2026
– CSSF publishes the administrative sanction “Administrative sanction imposed on Transnet Soc Ltd”; this enforcement notice is made public in line with the Transparency Law’s publication requirements
TBD (within 3 months of CSSF decision)
– Statutory window during which Transnet Soc Ltd (or any sanctioned issuer) may lodge a court action against the CSSF decision with the Luxembourg Administrative Court under Article 27 of the Transparency Law
Suggested considerations
Map all Transparency Law obligations applicable to your entity, including periodic (annual and half‑yearly) reporting and ongoing disclosure of regulated information, and document them in a compliance obligations register.
Review and, where necessary, strengthen internal processes to ensure annual and half‑yearly financial reports are prepared, approved, and published within statutory deadlines for issuers with Luxembourg as home Member State.
Implement a formal disclosure governance framework assigning clear responsibilities to senior management and the board for oversight of regulated information, including escalation procedures where delays or issues arise.
Establish a calendar of regulatory reporting and publication deadlines, including internal cut‑off dates and contingency plans, and ensure it is monitored by compliance and finance functions.
Conduct a gap analysis of prior disclosures (financial reports, major holdings notifications, inside information) to confirm that all items required under the Transparency Law have been published correctly and on time; remediate any deficiencies promptly.
What changed
As the 21 July 2026 CSSF notice is an enforcement publication (not a new rule), it does not introduce new regulatory requirements; it applies existing Transparency Law obligations.
Issuers with Luxembourg as home Member State under the Transparency Law must publish annual financial reports within the statutory deadline, typically within four months of financial year-end, and...
Failure to publish periodic financial information within the required time limits can result in administrative fines imposed by the CSSF under Article 25(2) of the Transparency Law.
The CSSF will publicly disclose administrative fines imposed on issuers, including naming the issuer and the amount, in line with Article 26b of the Transparency Law.
Issuers retain the right to challenge CSSF decisions before the Luxembourg Administrative Court within the period set by Article 27 of the Transparency Law (three months from notification), but...
Compliance impact
CSSF administrative fines under the Transparency Law may be modest in absolute value but carry material reputational and supervisory impact because the sanctions, the issuer’s name, and the failures are publicly disclosed. Persistent or repeated non‑compliance with transparency and disclosure obligations can trigger higher fines, closer supervisory scrutiny, and increased legal risk, including potential court actions and investor claims.
Clarifications regarding certain aspects of Regulation (EU) 2019/2088 on sustainability-related disclosures in the financial sector (SFDR)Version 5
AI Analysis
The CSSF’s FAQ clarifies several SFDR disclosure points for Luxembourg fund managers and related entities, especially around Article 8/9 investment strategies, sustainable-investment methodology, and periodic reporting. It also signals supervisory expectations that disclosure changes can be “material” under CSSF circular rules and therefore may trigger formal review and authorisation requirements.
Key dates
02 December 2022
- CSSF published the SFDR FAQ clarifying supervisory expectations for Article 8 and Article 9 disclosures
01 January 2023 Deadline
- UCITS and AIFs disclosing under Article 8 or Article 9 must use the SFDR RTS periodic reporting templates in annual reports issued after this date
Suggested considerations
Review all Article 8 pre-contractual disclosures to confirm that the stated investment strategy clearly explains how the fund’s environmental or social characteristics are achieved.
Strengthen any Article 8 exclusion-based strategy disclosures so they provide sufficient detail for investors to understand the connection between exclusions and the claimed sustainability characteristics.
Reassess all Article 9 product classifications to confirm that the portfolio is built around qualifying sustainable investments, not only exclusions.
Implement controls to verify that Article 9 holdings remain aligned with Article 2(17) SFDR on an ongoing basis throughout the fund lifecycle.
Document and retain the internal methodology used to assess sustainable-investment status, including any thresholds, and ensure it can be provided to investors or supervisors upon request.
What changed
- Article 8 funds must describe how the investment strategy actually enables the fund to meet the environmental and/or social characteristics disclosed to investors.
If an Article 8 fund relies mainly on an exclusion strategy, the CSSF expects the exclusion policy to be detailed enough for investors to understand how the stated characteristics are being met.
Article 9 funds cannot rely only on an exclusion strategy; they must invest in sustainable investments and use a positive selection process that demonstrates alignment with Article 2(17) SFDR.
For Article 9 funds, the CSSF expects sustainable-investment status to be maintained at all times, including on an ongoing basis during the life cycle of the fund.
Financial market participants should make available the methodology used to determine whether an investment is a sustainable investment, including any thresholds used for a pass-fail approach.
Compliance impact
Non-compliance can lead to supervisory scrutiny, requests for remediation, and potential reclassification risk if a product cannot substantiate its Article 8 or Article 9 claims. The practical consequence is heightened greenwashing exposure and the possibility that disclosure changes may need formal review or authorisation before implementation.
ESMA supervisory briefing on triangular passporting under MiFID II, establishing common supervisory expectations for investment firms using branches/tied agents across multiple EU member states. Informational guidance on regulatory framework, firm responsibilities, and client protections.
AIFM (Alternative Investment Fund Manager) reporting dashboard is a periodic statistical publication by CSSF. This is informational content providing regulatory reporting data and metrics for alternative investment fund managers.
CSSF announcement regarding authorized investment funds and Islamic finance with reference to audit profession public register. Primarily informational content about regulatory framework and compliance infrastructure rather than substantive policy change. No time-sensitive compliance deadline indicated.
The CSSF has republished its MiFID II/MiFIR FAQ (Q&A) in a version dated 13 July 2026, consolidating guidance on investor protection, conduct of business, and reporting obligations applicable to Luxembourg MiFID firms. While the publication page itself is largely technical (cookies, website functioning), firms should treat the 13 July 2026 FAQ version as the current CSSF interpretative benchmark for MiFID II/MiFIR compliance, aligned with ESMA Q&As and recent EU‑level MiFID II/MiFIR review developments.
Key dates
02 March 2026
- Most revised MiFIR transparency requirements under the MiFID II/MiFIR review (amending Delegated Regulation) apply at EU level, influencing the content and focus of national FAQs and supervisory guidance, including CSSF’s
13 July 2026 Deadline
- CSSF publishes/updates the MiFID II/MiFIR FAQ version dated 13 July 2026, which becomes the current reference point for CSSF supervisory expectations on MiFID II/MiFIR compliance
Suggested considerations
Review the latest CSSF MiFID II/MiFIR FAQ (13 July 2026 version) in full, comparing it against existing internal MiFID II/MiFIR policies, procedures, and controls to identify gaps or misalignments.
Confirm and, where necessary, update client‑facing disclosures to clearly state whether investment services (especially advice and portfolio management) are provided on an independent or non‑independent basis, and ensure that inducement arrangements are consistent with this classification.
Reassess inducement frameworks (commissions, fees, non‑monetary benefits) for investment advice and portfolio management to ensure that no prohibited inducements are received or retained where services are independent or involve portfolio management.
Review and update product governance frameworks, including target market definition processes and product approval procedures, to ensure that each instrument’s intended target market is properly documented and consistently used by distributors.
Examine best execution policies to confirm they are clear, detailed, and understandable to clients, and implement or enhance ongoing monitoring mechanisms (e.g. execution quality reports, periodic reviews) to evidence compliance with best execution obligations.
What changed
Because the visible page content provided is limited to technical and cookie‑related information, the key points below focus on the regulatory substance of the CSSF MiFID II/MiFIR FAQ (Q&A) as the...
The CSSF confirms the application of MiFID II investor protection rules to Luxembourg investment service providers, including obligations on inducements, suitability, product governance, and best...
The FAQ reiterates that investment services providers must inform clients clearly whether their investment advice or services are provided on an independent or non‑independent basis, and explains the...
The FAQ clarifies that inducements are expressly prohibited when investment advice is provided on an independent basis and for portfolio management services, requiring firms to structure their...
The CSSF guidance reflects product governance obligations: manufacturers must define a target market for each financial instrument based on clients’ knowledge and experience, financial situation,...
Compliance impact
Non‑compliance with CSSF’s MiFID II/MiFIR expectations can lead to supervisory findings, remediation orders, administrative sanctions, and potential reputational damage, particularly where investor protection (suitability, inducements, best execution) is compromised. Given the 2026 EU‑level MiFID II/MiFIR review changes and the updated FAQ, firms that fail to update frameworks risk being assessed against a higher and more current supervisory benchmark.
CSSF warning of identity theft and impersonation of regulated investment firm European Broker S.A. Luxembourg. Fraudsters using spoofed email address to conduct illicit activities. High urgency due to active fraud threat affecting multiple stakeholders and need for immediate awareness among market participants.
CSSF warning against unauthorized entity Nexura VG operating without proper authorization to provide investment/financial services. High urgency due to active illicit operations and consumer protection risk, though not critical as it is a warning rather than emergency alert.
CSSF warning against unauthorized entity SB Systems sp. Zo.o conducting fraudulent investment services from Luxembourg without authorization. Critical urgency due to active fraud alert requiring immediate awareness among regulated entities and consumers.
CSSF warning about fraudulent impersonation of regulated investment firm 2 PM EUROPE S.A. through fake website, email, and phone contact details. Identity theft and illicit activities pose direct risks to consumers and market integrity.
CSSF annual statistics publication on specialized PFS balance sheet totals and net results for 2024. This is informational regulatory reporting data showing financial metrics trends from 2010-2024. No compliance action or urgent requirement indicated.
CSSF alert regarding identity theft and fraud prevention targeting financial sector entities. Informational content warning about impersonation of regulatory authority. Applies broadly to all regulated firms under CSSF supervision. No time-sensitive compliance deadline indicated.
ESMA has launched a public consultation (via CSSF notification) on its technical advice to the European Commission for simplifying the EU Taxonomy disclosure framework, focusing on selected KPIs under the Taxonomy Disclosures Delegated Act and reducing reporting burdens. This matters for compliance teams because it is the first formal step in the review of Article 8 Taxonomy disclosure KPIs that will likely change how financial and non‑financial undertakings calculate and disclose Taxonomy‑related indicators from around Q3 2027.
Key dates
01 July 2026
- ESMA launches its public consultation on simplifying the EU Taxonomy disclosure framework and technical advice on selected KPIs under the Taxonomy Disclosures Delegated Act
22 July 2026
- ESMA holds a public hearing to present its proposals and engage with stakeholders on the consultation
12 August 2026 Deadline
- Deadline for stakeholders to submit responses to ESMA’s consultation on Taxonomy disclosure simplification
By October 2026
- ESMA (and other ESAs) are expected to deliver final technical advice on the Taxonomy Disclosures Delegated Act KPIs to the European Commission
Q1 2027
- Target date for the European Commission to complete its review of the Taxonomy Disclosures Delegated Act based on ESAs’ advice
Suggested considerations
Conduct an internal impact assessment of current Taxonomy Article 8 KPI calculation and reporting processes, focusing on OpEx, Commissions and Fees, Trading Book, and Underwriting KPIs, to identify pain points and simplification priorities.
Prepare and submit a response to ESMA’s consultation by 12 August 2026, either directly or via industry associations, articulating specific operational, data, and system challenges and concrete proposals for simplification.
Register for and attend ESMA’s public hearing on 22 July 2026 to understand the detailed proposals, ask clarifying questions, and align internal positions ahead of submission.
Coordinate with regulatory affairs, sustainability, risk, and finance functions to develop a unified institutional position on the desired design of revised KPIs and group‑level reporting under the Taxonomy Disclosures Delegated Act.
Map dependencies between Taxonomy Article 8 data and other ESG reporting (including SFDR product disclosures and CSRD/ESRS reporting) to anticipate how changes to KPIs may affect cross‑framework consistency and data architecture.
What changed
- ESMA is consulting on technical advice to the European Commission specifically targeting selected KPIs under the Taxonomy Disclosures Delegated Act (Article 8 of the Taxonomy Regulation), including...
The stated policy objective is simplification of the EU Taxonomy disclosure framework while preserving decision‑useful information for investors and supervisors.
ESMA aims to reduce reporting burdens for market participants, notably corporates and financial institutions subject to Taxonomy Article 8 disclosures.
The consultation covers selected KPIs under the Taxonomy Disclosures Delegated Act, with the European Commission having requested focused advice on: OpEx KPI of non‑financial firms; Commissions and...
ESMA is proposing more pragmatic approaches to group‑level reporting for mixed groups, including reporting at parent‑undertaking level to reduce complexity for conglomerates.
Compliance impact
In the short term, non‑participation in the consultation does not create direct non‑compliance risk but may leave firms exposed to a revised framework that does not reflect their operational realities. In the medium term (Q3 2027 onward), failure to implement the revised Taxonomy KPIs and disclosure rules will create material regulatory, supervisory, and reputational risk, given the central role of Taxonomy data in EU sustainable finance and investor disclosures.
CSSF newsletter is a periodic informational publication covering latest regulatory publications and financial sector statistics. No specific regulatory action, deadline, or urgent requirement indicated. Content is general across multiple sectors and firm types, warranting 'All Firms' classification.
This is a regulatory statistical report from CSSF on collective investment undertakings (UCIs) in Luxembourg as of May 2026. It provides monthly performance data, net asset tracking, and registration/deregistration updates.
This is an informational update about the CSSF's public register of the audit profession. It primarily concerns regulatory registration and disclosure requirements applicable to audit firms operating in Luxembourg's financial sector.
CSSF communication announcing the application of EU ESG Ratings Regulation (2024/3005) effective 2 July 2026. Requires financial market participants and advisers to disclose ESG ratings in marketing communications with specific website disclosures per Annex III.
This is a monthly statistical publication by CSSF (Luxembourg financial regulator) providing basic data on UCIs (Undertakings for Collective Investment). It is informational/disclosure content with no regulatory action required, hence null urgency. Relevant to asset managers and investment management sector.
This is an informational update from CSSF regarding net assets statistics of Undertakings for Collective Investment (UCIs), published as of 31 May 2026. It appears to be a routine statistical disclosure/reporting publication rather than a regulatory requirement or enforcement action.
This is a monthly statistical publication from CSSF (Luxembourg financial regulator) providing breakdown of Undertakings for Collective Investment (UCIs) by currency. It is informational/disclosure content with no regulatory action or deadline, hence null urgency.
This is a statistical publication from CSSF (Luxembourg financial regulator) providing monthly data on the origin of UCI (Undertakings for Collective Investment) initiators. It is informational/reporting content with no regulatory action or deadline, hence null urgency.
This is a monthly statistical publication from CSSF (Luxembourg financial regulator) providing breakdown of net assets of UCIs (Undertakings for Collective Investment) by investment policy. It is informational/reporting content with no regulatory action or deadline, hence null urgency.
CSSF warning of fraudulent website impersonating legitimate Luxembourg financial services firm. Identity theft and illicit activities pose immediate risk to consumers and regulated entities. Critical urgency due to active fraud scheme requiring immediate awareness and protective action.
CSSF announcement regarding public register of audit profession exemptions for 2025. This is informational content about regulatory registry data rather than a substantive regulatory requirement.
- CSSF’s supervisory disclosure covers **measures and administrative penalties for the year 2025**
23 July 2025
- CSSF published the prior year’s supervisory disclosure page referencing the **2024** measures and penalties, showing the annual disclosure cycle
28 July 2025 Deadline
- CSSF issued an **administrative sanction** in an AML/CFT case, imposing a reprimand for non-compliance with the AML/CFT Law
Suggested considerations
Review the firm’s AML/CFT control framework against the Luxembourg AML/CFT Law provisions that can trigger CSSF reprimands or sanctions, including governance, monitoring, and escalation controls.
Verify that suspicious activity detection, investigation, and escalation procedures are documented, implemented, and tested for effectiveness.
Reassess whether internal controls are sufficient to demonstrate timely compliance with professional AML/CFT obligations under CSSF supervision.
Update remediation tracking to ensure supervisory findings are closed out promptly and supported by evidence of corrective action.
Brief senior management on the reputational impact of public supervisory disclosures and ensure that recurring weaknesses are escalated to the board.
What changed
- CSSF has published its 2025 supervisory disclosure covering supervisory measures and administrative penalties taken during the year.
The publication serves as a public register-style disclosure of enforcement outcomes, increasing transparency around CSSF supervision and sanctioning activity.
A related 2025 CSSF administrative sanction shows that AML/CFT non-compliance can result in a reprimand under the amended Luxembourg AML/CFT Law.
The 28 July 2025 sanction confirms that CSSF can act where firms fail to maintain adequate professional AML/CFT obligations and related internal controls.
Compliance impact
The compliance impact is material because CSSF enforcement disclosures can expose weaknesses to the market, counterparties, auditors, and other regulators, creating reputational and supervisory pressure. Non-compliance with AML/CFT obligations can lead to public reprimands and potentially more severe measures if deficiencies persist or are systemic.
SREP is the ECB/CSSF supervisory review and evaluation process applicable to all regulated financial institutions in Luxembourg. This appears to be an informational update about the public register of the audit profession related to supervisory oversight.
CSSF supervisory disclosure on variable remuneration elements under EU 2019/2034 Directive Article 32. Informational guidance document for financial institutions on compensation structure requirements. Published as reference material for compliance purposes.
Supervisory disclosure document from CSSF reporting statistics on investment firms utilizing transitional provisions under IFD/IFR. This is informational/statistical reporting on regulatory compliance metrics rather than a new requirement or urgent directive.
CSSF supervisory disclosure document outlining regulatory options and discretions under EU investment firm directives (2019/2034 and 2019/2033). This is informational guidance for compliance with capital requirements and reporting frameworks applicable across financial services sectors.
This is an informational announcement about the public register of the audit profession maintained by CSSF (Luxembourg financial regulator). It relates to regulatory reporting requirements and professional licensing/authorization.
CSSF supervisory disclosure document outlining specific disclosure requirements for investment firms in 2025. This is informational guidance material published by the Luxembourg financial regulator, not a regulatory change requiring immediate action.
CSSF warning of fraudulent website impersonating legitimate Luxembourg-based investment firms (Indylux Capital and Kherty Finance). Alert involves identity theft, illicit activities, and unauthorized use of company names across multiple jurisdictions.
CSSF warning against unauthorized entity operating illegally in Luxembourg jurisdiction. Entity claims investment services capability without authorization. High urgency due to active illicit operations and consumer protection risk.
CSSF published a periodic UCITS risk reporting dashboard for December 2025. This is informational statistical content tracking risk metrics across UCITS funds. It relates to investment management sector reporting requirements and prudential oversight, with primary relevance to asset managers managing UCITS funds.
This MMF Reporting Dashboard encompasses a set of indicators based on the data reported under Article 37 of the MMF Regulation, with data as from Q1/2020 onwards.
Why this matters
This is an informational publication of the MMF Reporting Dashboard by CSSF, containing regulatory statistics and indicators based on Article 37 of the MMF Regulation. It is periodic reporting data for money market fund managers, relevant to asset managers engaged in MMF operations.
1) high-risk jurisdictions on which enhanced due diligence and, where appropriate, counter-measures are imposed2) jurisdictions under increased monitoring of the FATFVersion of 19 June 2026
AI Analysis
CSSF published a new **Annex to Circular CSSF 22/822** on **22 June 2026**, updating the Luxembourg regulator’s reference list of FATF **high-risk jurisdictions** and **jurisdictions under increased monitoring**. For compliance teams, this matters because AML/CFT country-risk scoring, enhanced due diligence triggers, and sanctions-style controls must be aligned to the current FATF position reflected by CSSF.
Key dates
27 October 2022
- Circular CSSF 22/822 was issued, establishing the framework for using FATF statements on high-risk jurisdictions and jurisdictions under increased monitoring
19 June 2026
- The annex was updated to this version date, reflecting the current FATF jurisdiction lists and associated risk posture
22 June 2026
- CSSF published the annex on its website, making the updated reference document operationally relevant for supervised firms
Suggested considerations
Review your AML/CFT country-risk methodology and update it to reflect the 19 June 2026 FATF/CSSF jurisdiction list.
Re-screen customers, beneficial owners, counterparties, and transactions against the updated high-risk and monitored jurisdiction lists.
Apply enhanced due diligence for relationships and transactions involving high-risk jurisdictions, and escalate where counter-measures may be required.
Reassess risk ratings for customers linked to jurisdictions under increased monitoring and document the rationale for any continued onboarding, retention, or exit decisions.
Update automated screening rules, transaction-monitoring scenarios, and onboarding checklists so they use the current CSSF annex version.
What changed
- CSSF republished the annex to Circular CSSF 22/822 in a Version of 19 June 2026, meaning firms should treat this as the current Luxembourg reference point for FATF jurisdiction screening and...
The annex distinguishes between high-risk jurisdictions subject to enhanced due diligence and, where appropriate, counter-measures, and jurisdictions under increased monitoring that require...
The publication incorporates the FATF’s current statements on jurisdictions with strategic AML/CFT/CPF deficiencies, which is the basis for operational country-risk controls used by...
The related Circular CSSF 22/822 remains the framework document that instructs professionals to use FATF statements when assessing jurisdictional ML/TF/PF risk.
Compliance impact
Non-compliance can lead to supervisory findings, remediation orders, and possible enforcement action where firms fail to apply risk-sensitive AML controls consistent with CSSF/FATF expectations. The practical impact is highest for onboarding, correspondent-like relationships, cross-border payments, and any business line exposed to higher-risk jurisdictions.
This is a notification form from CSSF regarding a Luxembourg-based Investment Fund Manager (IFM) seeking to provide ancillary services to third parties. It is informational content announcing regulatory filing procedures under Luxembourg financial laws (Law of 2013 and Law of 2010), with no indication of urgent...
under Article 5(4)(b)(iv) of the Law of 2013 and/or Article 101(3)(b), fourth indent of the Law of 2010 as introduced by the Law of 3 March 2026, transposing Directive (EU) 2024/927 of the European Parliament and of the Council of 13 March 2024
Why this matters
CSSF communication announcing new notification procedures for Luxembourg-based investment fund managers seeking to provide ancillary services to third parties under transposed EU Directive 2024/927. Informational guidance on regulatory requirements and form submission process.
The CSSF has introduced two **mandatory standardised application forms** for authorisation of UCITS **domestic mergers** under the Luxembourg Law of 17 December 2010 and **outbound cross‑border mergers** where the receiving UCITS is located in another EU Member State under Directive 2009/65/EC. From 19 June 2026, any new UCITS merger authorisation request of these types must use the new forms and be filed by email with the full supporting documentation required by the applicable UCITS merger provisions.
Key dates
19 June 2026
- CSSF communiqué published announcing the two new merger authorisation forms for UCITS domestic mergers and UCITS outbound cross‑border mergers
19 June 2026 Deadline
- **Start of mandatory use of the new forms** for all **new merger authorisation applications** filed with the CSSF; applications submitted from this date must use the new templates and be sent to [email protected]
Suggested considerations
Identify all current and planned UCITS domestic and outbound cross‑border merger projects and determine which will have CSSF authorisation requests submitted on or after 19 June 2026 so that the new forms are used.
Download and review in detail the “Application form for authorisation of a UCITS domestic merger” and “Application form for authorisation of a UCITS outbound cross‑border merger” and map each field of the forms to existing internal data sources and documents.
Update internal UCITS merger procedures and checklists to replace any existing CSSF filing templates with the new standardised forms and to include the requirement that all merger authorisation applications are submitted to [email protected].
Train legal, product, operations and compliance staff involved in UCITS mergers on how to complete the new forms accurately, including coordination of information across the prospectus, KIIDs/KIDs, common draft merger terms, depositary statements and shareholder communications.
Review and, where necessary, update board and governance templates (board minutes, resolutions approving merger terms) to ensure they produce all information that the new forms require to be confirmed or attached.
What changed
- The CSSF has created a standardised “Application form for authorisation of a UCITS domestic merger” specifically for merger authorisation requests where both merging and receiving UCITS are...
The CSSF has created a standardised “Application form for authorisation of a UCITS outbound cross‑border merger” for mergers where the merging UCITS is Luxembourg‑authorised and the receiving UCITS...
Use of the two new forms is mandatory for all new merger authorisation applications submitted to the CSSF from 19 June 2026 onwards; legacy formats (ad‑hoc letters or bespoke templates) may no longer...
Each application form must be “duly completed” and accompanied by all documents required under the applicable UCITS merger regulations, including the common draft terms of merger, updated prospectus...
The CSSF has specified a centralised submission channel for these applications: completed forms and supporting documentation must be sent to [email protected], aligning merger filings with the...
Compliance impact
Non‑compliance (e.g. using outdated templates or submitting incomplete forms) is likely to result in the CSSF treating the file as inadmissible or incomplete, delaying merger authorisation and potentially requiring postponement of planned merger effective dates. Repeated deficiencies or failure to comply with the standardised process may also raise supervisory concerns about the firm’s governance and regulatory controls around UCITS product actions.
This is an informational regulatory document from CSSF regarding application procedures for UCITS outbound cross-border mergers. It pertains to investment management authorization processes and is primarily procedural/administrative in nature rather than substantive regulatory change, warranting null urgency...
Document concerns UCITS domestic merger authorization procedures from Luxembourg financial regulator CSSF. This is procedural/informational content regarding investment fund licensing requirements, not time-sensitive regulatory change.
CSSF warning about identity theft and fraud targeting Luxembourg investment fund managers with German branches. Involves forged websites and financial guarantees.
ESMA statement on Common Supervisory Action results regarding MiFID II sustainability integration in suitability assessments and product governance. Informational regulatory guidance with proportionate supervisory approach during sustainable finance framework transition. No immediate enforcement action indicated.
CSSF warning of identity theft and fraudulent impersonation of authorized investment fund manager Nordea Investment Funds S.A. High urgency due to active fraud scheme using spoofed email addresses and phone numbers targeting potential investors/clients. Requires immediate awareness among market participants.
CSSF warning of fraudulent website impersonating regulated fund manager RBC Funds (Lux). Involves identity theft, illicit activities, and unauthorized use of legitimate company credentials. Critical urgency due to active fraud targeting investors and potential harm to regulated entity's reputation and customer trust.
Quarterly employment statistics publication by CSSF for specialised PFS (Professional Financial Sector). This is informational/statistical content tracking employment trends across the financial sector, not a regulatory requirement or enforcement action.
Quarterly statistical publication by CSSF reporting on UCI (Undertakings for Collective Investment) net assets, fund counts, and unit volumes as of March 2026. This is informational regulatory reporting data relevant to asset managers and investment funds, with no time-sensitive compliance requirements.
Quarterly employment statistics published by CSSF for support PFS (Professional Financial Sector) personnel. This is informational statistical reporting showing employment trends across the financial sector with minimal quarter-to-quarter variation.
amending Delegated Regulation (EU) 2019/980 as regards the reduced content and the standardised format and sequence of the EU Follow-on prospectus and the EU Growth issuance prospectus
Why this matters
This is an EU delegated regulation amending prospectus requirements for follow-on offerings and growth issuances. It affects capital markets participants and issuers regarding standardized prospectus format and content. Classified as informational regulatory update rather than urgent compliance requirement.
CSSF warning about fraudulent website impersonating legitimate investment undertaking (Robus Umbrella). Involves identity theft and illicit activities targeting collective investment scheme. High urgency due to active fraud threat to consumers and potential reputational harm to regulated entity.
The CSSF is flagging to the market a new **CNC Q&A 26/037** that clarifies the distinction between **statutory (legal) annual accounts** and **annual accounts prepared for contractual or voluntary purposes**, and an interview indicating an upcoming **overhaul of Luxembourg accounting legislation**. This matters for compliance and finance teams because mislabeling or misusing “statutory” accounts, or applying CNC doctrine inconsistently, can create legal, regulatory, lending, and investor‑information risks, and the announced legislative reform implies future adjustments to accounting policies, reporting processes, and governance.
Key dates
08 June 2026
– Publication of the interview with the CNC chairman in Paperjam announcing that Luxembourg accounting legislation will be overhauled
15 June 2026
– CSSF press release published, drawing attention to CNC Q&A 26/037 and the CNC chairman’s interview and signaling supervisory expectations that entities consider this doctrine when preparing annual accounts
Suggested considerations
Obtain and review the full CNC Q&A 26/037 and the CNC chairman’s interview (French‑language originals), ensuring that finance, accounting, and compliance teams understand the clarified distinctions between statutory and contractual/voluntary annual accounts.
Map all sets of financial statements prepared by each Luxembourg entity (statutory accounts, covenant‑based or lender‑specific accounts, group reporting packages, management accounts, etc.) and classify each set as statutory or contractual/voluntary in line with CNC Q&A 26/037 definitions.
Update internal accounting policies and manuals to explicitly define statutory versus contractual/voluntary annual accounts, specify the applicable accounting principles and disclosures for each, and describe any differences in measurement, presentation, or scope.
Assess current practices for communicating financial information to lenders, investors, regulators, and other stakeholders to confirm that non‑statutory accounts are not labeled or presented in a way that could be misinterpreted as statutory accounts approved under Luxembourg company law.
Implement clear labeling and disclosure conventions on the face of financial statements and in accompanying notes (e.g., in engagement reports, board minutes, and management communications) to distinguish statutory annual accounts from any contractual or voluntary accounts.
What changed
- The CSSF formally draws regulated entities’ attention to CNC Q&A 26/037, elevating it as a key interpretative reference on the concepts of annual accounts prepared for legal/statutory purposes...
The CNC Q&A 26/037 provides clarified definitions of “comptes annuels établis à fins légales” (statutory annual accounts) and “comptes annuels établis à des fins contractuelles ou sur base...
The Q&A gives practical answers to frequently asked questions from preparers about when accounts qualify as statutory versus merely contractual or voluntary, and how this affects applicable...
The Q&A addresses related issues, such as the extent to which CNC doctrine and Luxembourg GAAP must be followed for contractual or voluntary accounts, and the risks of presenting non‑statutory...
The CSSF also highlights an interview with the CNC chairman announcing that Luxembourg accounting legislation will undergo a refonte (major overhaul), signaling that current CNC doctrine, including...
Compliance impact
Failure to correctly distinguish and label statutory versus contractual/voluntary annual accounts can lead to breaches of Luxembourg company law, mis‑disclosure to investors, lenders, and regulators, and increased enforcement risk from the CSSF and other authorities. Misalignment between CNC doctrine and practice may also complicate audits and regulatory reviews, leading to qualified opinions, remediation requirements, or sanctions in severe cases.
Q&A CNC 26/037 titled “A reminder of the differences between annual accounts prepared for statutory purposes and annual accounts prepared for contractual purposes or on a voluntary basis” and interview with the chairman of the CNC (Mr. Yvan Thommes)
AI Analysis
The CSSF is formally directing market participants’ attention to new guidance from the Luxembourg Commission des normes comptables (CNC) clarifying the distinction between **statutory annual accounts** and **contractual/voluntary annual accounts**, and to an interview announcing a forthcoming overhaul of Luxembourg accounting law. This matters for compliance and finance functions because it affects how firms label, prepare, approve, file and use financial statements in regulatory, contractual and investor contexts, and foreshadows medium‑term changes to the Luxembourg accounting framework.
Key dates
08 June 2026
– Publication of the interview with the CNC chairman in Paperjam announcing that Luxembourg accounting legislation will be subject to a comprehensive overhaul
15 June 2026
– CSSF communiqué published, formally drawing attention to CNC Q&A 26/037 and the CNC chairman’s interview, and thereby activating supervisory expectations that firms take these clarifications into account
TBD (post‑2026)
– Effective dates for the planned overhaul of Luxembourg accounting legislation remain to be defined; firms should anticipate consultation and transition periods once draft law is published
Suggested considerations
Identify all sets of financial statements prepared by the firm or its Luxembourg entities (statutory, covenant/banking, shareholder/management, group‑reporting, voluntary) and map which are statutory annual accounts under Luxembourg law and which are contractual or voluntary.
Review the CNC Q&A 26/037 in detail and update internal accounting manuals and group reporting policies to embed the CNC’s definitions, terminology and criteria for statutory versus non‑statutory annual accounts.
Implement a clear labelling and disclosure convention so that all non‑statutory financial statements explicitly state their nature (contractual or voluntary) and are not presented or communicated as statutory annual accounts.
Update templates for board and shareholder approvals, minutes and resolutions to ensure that the correct set of statutory annual accounts is approved for legal purposes such as profit appropriation, dividend distribution, capital reduction and regulatory filings.
Review all contractual arrangements (loan agreements, bond indentures, shareholder agreements, management incentive plans and service contracts) to determine whether they require statutory annual accounts or allow contractual/adjusted accounts, and align documentation and practice accordingly.
What changed
- The CSSF endorses and promotes CNC Q&A 26/037 as the reference clarification on the concept of “comptes annuels établis à fins légales” (statutory annual accounts) versus annual accounts prepared...
The Q&A provides clear criteria to distinguish statutory accounts from non‑statutory accounts, including their legal basis, approval process, filing and publication obligations, and permissible use...
The CNC guidance clarifies that statutory annual accounts must fully comply with Luxembourg accounting law (including mandatory layouts, valuation rules and disclosures), whereas...
The CNC addresses frequent practical questions from preparers, including whether financial statements prepared for banks, covenants, shareholders’ agreements, management incentive plans or...
The CSSF communicates that misunderstandings between statutory and contractual accounts remain common, implicitly warning against the risk of using non‑statutory statements in contexts where...
Compliance impact
Misclassification or misuse of contractual/voluntary accounts where statutory annual accounts are legally required can lead to breaches of Luxembourg company law, invalid shareholder resolutions, misstatements in regulatory or investor reporting, and potential CSSF supervisory findings. Consistent application of the CNC guidance will be expected in future inspections and could influence audit opinions and governance assessments.
CSSF warning of identity theft and fraudulent impersonation of authorized alternative investment fund manager. Unknown persons misusing legitimate firm's name and contact details to conduct illicit activities.
This is an SSM (Single Supervisory Mechanism) calendar publication from CSSF (Luxembourg financial regulator) listing scheduled supervisory activities and events. It is informational/administrative in nature, providing transparency on regulatory calendar items rather than announcing new rules or requirements.
CSSF guidance document providing an overview of Luxembourg investment vehicles and their Investment Fund Managers (IFM) framework. This is informational/educational content updated for regulatory clarity on vehicle structures and IFM requirements.
This is an updated notification letter template from CSSF regarding marketing notifications for EU AIFs and ELTIFs under AIFMD and ELTIF regulations. It is informational/procedural guidance for asset managers seeking to market alternative investment funds and long-term investment funds across EU member states.
CSSF warning against unauthorized entity operating investment services without proper licensing. Tag Markets and related entities are conducting illicit financial activities from Mauritius while targeting Luxembourg market. High urgency due to active fraud risk to investors and need for market awareness.
Administrative sanction imposed on Stonehage Fleming Luxembourg S.A.
AI Analysis
The CSSF has announced that an **administrative sanction was imposed on Stonehage Fleming Luxembourg S.A. on 5 March 2026**, but it has not yet published the underlying decision or grounds. For compliance teams, this signals that the CSSF continues to actively use sanctions against Luxembourg wealth/asset management entities and that a detailed decision is likely forthcoming, which may contain important precedents on governance, AML/CFT or conduct requirements.
Key dates
05 March 2026
- CSSF imposes the administrative sanction on Stonehage Fleming Luxembourg S.A. (date of decision)
09 June 2026
- CSSF publicly announces the administrative sanction and the existence of a PDF decision (date of publication on CSSF website)
Suggested considerations
Monitor the CSSF website for publication of the detailed PDF decision relating to the administrative sanction of 5 March 2026 against Stonehage Fleming Luxembourg S.A.
Once available, review the full decision to identify the specific legal bases (e.g. LFS, Law of 2010, Law of 2013, AML/CFT Law) and control failures cited by the CSSF.
Map the identified weaknesses from the decision against your firm’s governance, internal control, delegate oversight and AML/CFT frameworks to identify any similar risk areas.
Update internal compliance risk assessments to reflect the enforcement themes highlighted in this and recent CSSF sanctions, including the weighting of enforcement risk for organisational and AML/CFT deficiencies.
Review and, where necessary, strengthen board and senior management oversight arrangements, including the documentation of decisions, challenge and escalation processes, in anticipation of CSSF expectations evidenced in the forthcoming decision.
What changed
At this stage, based on the CSSF notice alone, no new legal or regulatory requirements are introduced; the publication is a transparency notice that a sanction decision exists.
the Law of 5 April 1993 on the financial sector (LFS), the Law of 17 December 2010 on undertakings for collective investment, the Law of 12 July 2013 on AIFMs, and the Law of 12 November 2004 on the...
the CSSF’s established practice of publishing individual sanction decisions, which typically detail shortcomings in organisational requirements, internal controls, oversight of delegates, conduct of...
the legal provisions breached (for example, Articles 109–111 and 148 of the Law of 2010 or Articles 2-2, 3 and 8-4 of the AML/CFT Law, by analogy with other CSSF sanctions),
the factual deficiencies identified (e.g., weaknesses in governance, delegate oversight, AML risk assessment, customer due diligence), and
Compliance impact
The specific financial and qualitative impact of this particular sanction is not yet public, but recent CSSF cases show that deficiencies in governance, delegate oversight and AML/CFT controls can lead to significant fines, public censure and supervisory follow-up. Non-compliance increases the likelihood of intrusive inspections, remediation programmes under CSSF scrutiny, and reputational risk with clients and counterparties.
This is an updated regulatory guidance document from CSSF regarding marketing of non-EU Alternative Investment Funds (AIFs) by EU-based AIFMs to professional investors in Luxembourg.
This is an updated regulatory form and guidance from CSSF regarding marketing of AIFs by non-EU AIFMs to professional investors in Luxembourg under Article 45 of the AIFM Law. It is informational content providing procedural requirements for asset managers seeking to market alternative investment funds.
The CSSF has launched a consultation on national **Guidance on Money Market Fund Weekly Liquid Asset (WLA) Levels**, aligned with the European Commission’s 2026 MMF report, which defines “market resilience” WLA benchmarks above the MMFR regulatory minimums. This signals a move toward **enhanced liquidity risk management and intensified supervisory scrutiny** for Luxembourg‑authorised MMFs whose WLA levels fall below these resilience benchmarks, even if they remain above the legal minimum.
Key dates
11 May 2026
– European Commission publishes its report on the adequacy of the MMFR and FAQs, identifying market resilience WLA levels for VNAV and CNAV/LVNAV MMFs
15 May 2026
– CSSF informs the market of the Commission’s MMF report and FAQs and flags the identified WLA “market resilience” benchmarks
8 June 2026
– CSSF publishes the communiqué launching the consultation on “Guidance on Money Market Fund Weekly Liquid Asset Levels.”
3 August 2026 Deadline
– Deadline for stakeholders to submit electronic responses on the consultation to the CSSF at [email protected]
Suggested considerations
Review the CSSF consultation paper “Guidance on Money Market Fund Weekly Liquid Asset Levels” in detail and map the proposed WLA resilience benchmarks against existing MMF liquidity policies, procedures and internal limits.
Perform a quantitative impact analysis comparing each MMF’s historical and current WLA levels against both MMFR minimum requirements and the Commission’s market resilience benchmarks (20% for VNAV; 40% for LVNAV and CNAV) to identify potential shortfalls or pressure points.
Assess and, where necessary, update MMF liquidity risk management frameworks to incorporate explicit internal WLA targets, triggers and escalation procedures linked to the new resilience benchmarks, including governance oversight and board reporting.
Integrate the proposed WLA resilience levels into stress testing programmes under Article 28 MMFR, ensuring scenarios reflect the ability of funds to maintain or restore WLA around the benchmark levels under severe but plausible market stress.
Revisit know‑your‑investor / liability profile analysis under Article 27 MMFR to ensure that internal WLA targets adequately reflect investor concentration, redemption behaviour, dealing frequency and distribution channels.
What changed
- The CSSF, in coordination with the European Commission, AMF (France) and Central Bank of Ireland, is consulting on national guidance that operationalises the Commission’s “market resilience” levels...
The guidance will introduce non-binding but supervisory‑relevant WLA benchmarks designed to indicate when an MMF’s liquidity profile may warrant closer scrutiny and additional supervisory engagement.
The consultation builds on the European Commission’s 11 May 2026 report, which identifies WLA benchmarks of 20% for VNAV MMFs and 40% for LVNAV and CNAV MMFs, compared with the MMFR regulatory minima...
The guidance is intended to support more consistent and well‑calibrated supervision of MMFs across the EU, specifically on liquidity resilience under stress.
MMFs that fall below the identified “market resilience” WLA levels, even while remaining compliant with the MMFR minimum percentages, can expect increased supervisory scrutiny, closer monitoring and...
Compliance impact
The immediate legal impact is limited because the text is a consultation on guidance, not a binding rule change, but the direction of travel is towards higher de‑facto liquidity expectations and more intrusive supervision where WLA levels fall below resilience benchmarks. Non‑alignment with the eventual guidance is likely to result in increased supervisory challenge, potential remediation demands and heightened risk that liquidity weaknesses are escalated within the CSSF’s prudential risk framework.
The CSSF has launched a consultation on new **Guidance on Money Market Fund (MMF) Weekly Liquid Asset Levels**, signalling its intention to clarify supervisory expectations on the calibration and use of weekly liquid asset (WLA) buffers under the EU Money Market Funds Regulation (MMFR). This matters for compliance teams because it will likely drive changes to MMF liquidity risk frameworks, escalation triggers, governance around liquidity thresholds, and potentially the design of internal stress tests and contingency plans.
---
Key dates
TBD (final guidance – est. late 2026)
– Expected date for CSSF to publish final guidance on MMF weekly liquid asset levels, following review of consultation feedback
08 June 2026
– CSSF publishes consultation communiqué “Guidance on Money Market Fund Weekly Liquid Asset Levels” and opens consultation on its proposed guidance
– Expected closing date for industry comments on the consultation (to be confirmed once the full consultation paper and response deadline are made available by CSSF)
Suggested considerations
Review the CSSF consultation paper in full as soon as it is available and identify all proposed expectations relating to weekly liquid asset levels, monitoring, and escalation.
Map the proposed CSSF guidance against current MMF liquidity policies, prospectus disclosures, and internal procedures to identify gaps and potential areas needing enhancement.
Assess whether existing MMF weekly liquidity monitoring tools, dashboards, and reporting are sufficient to meet anticipated CSSF expectations on frequency, granularity, and early warning indicators.
Evaluate the current escalation framework for declining WLA levels, including board and senior management involvement, and update governance documentation to align with the likely CSSF approach to thresholds and decision‑making.
Review MMF stress‑testing methodologies to ensure that scenarios adequately capture severe but plausible redemption and market stress in relation to WLA levels and that results are integrated into risk appetite and contingency planning.
What changed
Given the consultation nature and the absence of a published consultation text in the extract, the following points reflect what compliance teams should reasonably anticipate and prepare for, based...
The CSSF is consulting on formal guidance that will specify how MMFs domiciled in Luxembourg should determine, monitor, and maintain weekly liquid asset levels under the EU Money Market Funds...
The guidance is expected to operationalise the MMFR WLA requirements (for example, minimum weekly liquidity levels and interaction with redemption activity) by setting out supervisory expectations on...
The consultation will likely address the interaction between WLA levels and the use of liquidity management tools (such as gates, fees, or suspensions), including expectations on when and how...
The CSSF is expected to clarify how MMFs should incorporate WLA targets and thresholds into their internal risk management policies, including stress-testing assumptions, early warning indicators,...
Compliance impact
Non‑compliance with the forthcoming CSSF guidance, once finalised, could result in supervisory findings, remediation programmes, and potential restrictions on MMF activities, particularly in stressed markets where liquidity management failures are highly scrutinised. Given MMFs’ systemic importance, firms should treat this as a high‑impact development for liquidity risk management, board oversight, and investor protection.
Administrative sanction imposed on a registered alternative investment fund manager
AI Analysis
The CSSF has published an administrative sanction dated 17 April 2026 imposed on a **registered alternative investment fund manager (registered AIFM)**, but the public notice contains no detail on the nature of the breach, legal basis, or penalty level, which are presumably only available in the linked PDFs. For compliance teams, this is another data point that the CSSF is actively enforcing the AIFMD and related Luxembourg implementing laws against even registered (sub‑threshold) AIFMs, not only fully authorised managers.
Because the body text and PDFs are not accessible from the prompt, the analysis below focuses on the **regulatory framework and typical CSSF enforcement themes** that are most likely relevant, and how compliance teams at AIFMs should respond.
---
Key dates
17 April 2026
- CSSF adopts an administrative sanction decision against a registered alternative investment fund manager
05 June 2026
- CSSF publishes the administrative sanction notice on its website, including links to the detailed sanction decision in PDF form
Suggested considerations
Obtain and review the full CSSF sanction decision PDFs published with the 17 April 2026 administrative sanction to identify the specific legal provisions, facts and control failures cited.
Map the identified breaches (e.g. governance, risk management, reporting, valuation, delegation, marketing, or conduct of business) against your firm’s current policies and procedures under the Law of 12 July 2013 on AIFMs and the AIFMD framework.
Perform a targeted gap analysis for registered AIFMs, focusing on whether “light” registration has led to under‑resourced compliance, risk, valuation, or reporting functions that could attract similar enforcement.
Review and, where necessary, update internal governance arrangements, including board oversight, documented decision‑making, and escalation processes for regulatory issues, to align with CSSF expectations evidenced in recent sanctions against AIFMs and management companies.
Test the effectiveness of regulatory reporting and disclosure processes (including Annex IV reporting, investor disclosures, periodic reporting, and prospectus/issuing document accuracy) to ensure they are complete, timely and consistent with CSSF rules.
What changed
There are no formal rule changes announced in the short notice itself; however, the enforcement action reinforces several practical expectations that compliance teams should treat as de‑facto...
CSSF confirms that registered alternative investment fund managers are fully subject to Luxembourg’s AIFM framework, including the Law of 12 July 2013 on alternative investment fund managers and the...
CSSF reiterates, through enforcement practice, that registration status (sub‑threshold AIFM) does not shield managers from administrative sanctions where organisational, conduct, reporting, or...
CSSF continues its policy of public naming and shaming through publication of administrative sanctions, signalling that reputational impact is a key component of its deterrence strategy.
The sanction underscores the CSSF’s readiness to use its full sanctioning toolkit under the AIFM Law, which can include monetary fines, public statements, and prohibitions or restrictions on...
Compliance impact
The compliance impact is medium to high: while the publication does not create new rules, it underscores that the CSSF will actively sanction even registered AIFMs and publicly disclose those sanctions, increasing both regulatory and reputational risk for weakly controlled managers. Firms that treat registration as a “lighter” supervisory regime without proportionate controls are particularly exposed to similar action.
CSSF warning against unauthorized entity claiming to offer investment services without Luxembourg authorization. High urgency due to active illicit operations and consumer protection risk, though not critical as it is a warning notice rather than emergency alert.
CSSF warning of fraudulent website impersonating legitimate wealth manager. Identity theft and illicit activities pose immediate risk to consumers and the legitimate firm's reputation. High urgency due to active fraud scheme targeting financial services clients.
Quarterly statistical report from CSSF on investment fund managers in Luxembourg as of 31 March 2026. Provides data on authorized and other IFMs, assets under management, employment figures, and cross-border activities. Informational content for regulatory monitoring and compliance purposes.
This is a regulatory statistical report from CSSF on collective investment undertakings (UCIs) in Luxembourg as of April 2026. It provides market data, net asset developments, and registration/deregistration information.
The CSSF has published a Feedback Report following a thematic review of the **valuation framework for less liquid and illiquid assets**, focused primarily on Luxembourg AIFMs managing AIFs in asset classes such as private equity, real estate, infrastructure, private debt and fund of funds, and on UCITS “trash ratio” positions under Article 41(2) of the UCI Law. All Luxembourg IFMs are explicitly expected to benchmark their existing valuation frameworks against the CSSF’s observations and recommendations and to implement corrective measures, with valuation risk confirmed as a key supervisory priority for 2026.
Key dates
End 2023
– CSSF thematic review launched by dedicated questionnaire to IFMs, with work conducted through 2024 and 2025 (contextual start of the current thematic exercise)
Throughout 2024 and 2025
– CSSF conducts off‑site and on‑site work as part of the dedicated thematic review on valuation frameworks for less liquid and illiquid assets
2026 Deadline
– Valuation risk for less liquid and illiquid assets is confirmed as a key supervisory priority, implying heightened supervisory focus and potential follow‑up actions during the year; no hard implementation deadline is set but prompt action is implicitly expected
04 June 2026
– CSSF publishes the Communication and Feedback Report on the thematic review and formally expects IFMs to perform a benchmarking exercise and implement corrective measures as needed
Suggested considerations
Perform a structured benchmarking of existing valuation policies, procedures, methodologies and controls against the detailed observations and recommendations in the CSSF Feedback Report on valuation frameworks for less liquid and illiquid assets.
Document, at IFM and fund level, all identified gaps or weaknesses in the current valuation framework, including for AIFs in illiquid strategies and UCITS Article 41(2) trash ratio positions.
Develop and approve a remediation plan with clear owners, milestones and target dates to address identified shortcomings in valuation governance, methodologies, model validation, data sources and control processes.
Review and, where necessary, update valuation policies and procedures to ensure they explicitly cover less liquid and illiquid assets, stressed market conditions, use of external valuers, and documentation standards across the investment lifecycle.
Enhance valuation governance by clearly defining roles and responsibilities (including segregation from portfolio management where applicable), escalation procedures, and oversight by the board/senior management.
What changed
- The CSSF publishes a dedicated Feedback Report on the thematic review of valuation frameworks for less liquid and illiquid assets and formally expects IFMs to use it as guidance for implementing...
All Luxembourg IFMs are required to conduct a benchmarking exercise of their valuation frameworks against the CSSF’s observations and recommendations set out in the new Feedback Report.
Where gaps or weaknesses are identified through this benchmarking, IFMs are expected to implement corrective measures to strengthen their valuation policies, procedures and lifecycle controls for...
The thematic review scope formally covers AIFMs of AIFs investing in less liquid and illiquid assets (including private equity, real estate, infrastructure, private debt and fund of funds), and, on...
The CSSF explicitly links this thematic work to previous supervisory exercises (ESMA CSA on valuation, CSSF self‑assessment questionnaires, and on‑site inspection feedback) and consolidates...
Compliance impact
Failure to benchmark and remediate valuation frameworks for less liquid and illiquid assets exposes IFMs to material supervisory risk, including targeted reviews, formal remedial orders or sanctions, particularly given the CSSF’s designation of valuation risk as a key supervisory priority in 2026. Deficient valuation practices also heighten the risk of NAV errors, investor detriment and potential civil liability or reputational damage.
CSSF warning against unauthorized entity claiming to provide investment services without Luxembourg authorization. High urgency due to active illicit operations and consumer protection risk. Entity operating across multiple financial service categories without proper licensing.
The CSSF has issued a feedback report on a thematic review of the **valuation framework for less liquid and illiquid assets**, signalling intensified supervisory focus on how Luxembourg investment fund managers value complex, hard‑to‑price positions. This matters because it will drive stricter expectations around valuation governance, model oversight, data validation, and the interaction between valuation, liquidity management, and investor protection for funds holding such assets.
Although the specific 2026 feedback report text is not yet available, it clearly follows and deepens the CSSF’s 2023 Feedback Report on ESMA’s CSA on Valuation and its 2026 supervisory priorities on valuation, with a narrower focus on less liquid and illiquid assets.
Key dates
18 July 2023
– CSSF publishes its Feedback Report on the ESMA Common Supervisory Action (CSA) on Valuation, setting out broad expectations for valuation frameworks, including for less liquid assets
31 December 2023 Deadline
– Deadline by which all IFMs managing UCITS and/or AIFs were required to complete a comprehensive assessment of their valuation frameworks and implement necessary corrective measures in line with the 2023 CSSF Feedback Report on valuation
Early 2026
– CSSF identifies valuation as an ongoing key supervisory priority for the investment fund sector in its 2026 priorities, with specific focus on IFM valuation organisation and processes
04 June 2026
– CSSF publishes the new Feedback Report on the thematic review of valuation frameworks for less liquid and illiquid assets, signalling renewed and more granular supervisory scrutiny of this area
TBD (2026–2027)
– CSSF is expected to conduct follow‑up supervisory work (off‑site reviews and on‑site inspections) to test implementation of its expectations on valuation of less liquid and illiquid assets; firms should plan remediation programmes within months rather than years
Suggested considerations
Conduct a comprehensive gap analysis of existing valuation policies and procedures against the CSSF’s feedback on valuation, with specific attention to less liquid and illiquid assets, and document all identified weaknesses and remediation actions.
Update and formally approve valuation policies and procedures to clearly define methodologies, model hierarchies, and data source selection for less liquid and illiquid assets, including explicit provisions for stressed market conditions.
Implement or enhance a formal valuation model governance framework for illiquid asset models, including independent model validation, periodic back‑testing, documentation of assumptions, and at least annual model reviews.
Review and, where necessary, redesign organisational arrangements to ensure the operational and hierarchical independence of the valuation function from portfolio management, and adjust remuneration policies to avoid performance‑linked incentives for valuation staff.
Strengthen controls over external pricing providers and external valuers by documenting selection criteria, performing initial and ongoing due diligence, challenging methodologies, and periodically back‑testing third‑party valuations of illiquid assets.
What changed
Based on the prior CSSF feedback on valuation and the indicated thematic focus, compliance teams should expect the following concrete expectations to apply specifically to less liquid and illiquid...
Investment fund managers must maintain concise, centralised, and comprehensive valuation policies and procedures that explicitly cover all asset types, including less liquid and illiquid instruments,...
Valuation policies must define and justify the valuation methodologies and models used for less liquid and illiquid assets, including the hierarchy of methods, model selection criteria, and...
Firms must perform robust model governance for valuation models used on less liquid and illiquid assets, including independent model review (by staff not involved in model development), back‑testing,...
Valuation frameworks must explicitly address stressed market conditions for illiquid and thinly traded assets, including triggers for stress conditions, alternative valuation methodologies under...
Compliance impact
Non‑compliance exposes firms to heightened risk of CSSF supervisory measures, including remediation orders, restrictions on activities, and possible enforcement actions, especially where valuation weaknesses have led or could lead to investor detriment. Given the CSSF’s explicit supervisory priority on valuation, firms with significant illiquid exposures should treat this as a high‑impact issue requiring proactive remediation and robust documentation.
amending the regulatory technical standards laid down in Delegated Regulation (EU) 2019/979 as regards updating the list of data necessary for the classification of prospectuses and the list of information that can be incorporated by reference into prospectuses
AI Analysis
Commission Delegated Regulation (EU) 2026/395 of 23 February 2026 amends the Prospectus Regulation RTS in Delegated Regulation (EU) 2019/979 to update: (i) the **data set used for ESMA classification and filing of prospectuses** and (ii) the **categories of information that may be incorporated by reference** into a prospectus.
For compliance teams in Luxembourg and across the EU, this means prospectus production, filing templates, and reference documentation frameworks must be revised so that all new prospectuses and supplements meet the updated RTS data and incorporation-by-reference standards under Regulation (EU) 2017/1129.
Key dates
14 March 2019
- Original Delegated Regulation (EU) 2019/979 is adopted, setting the RTS on key financial information, publication and classification of prospectuses, advertisements, supplements and incorporation by reference
23 February 2026
- Commission Delegated Regulation (EU) 2026/395 is adopted, amending Delegated Regulation (EU) 2019/979 on the list of data necessary for prospectus classification and the list of information allowed to be incorporated by reference
2 June 2026
- CSSF publishes notice of Delegated Regulation (EU) 2026/395, signalling its relevance for Luxembourg‑supervised entities and prospectus approval processes
TBD (upon OJ publication)
- The Delegated Regulation will enter into force on the date specified in the Official Journal; in line with standard EU practice, firms should expect application from a specified date shortly after OJ publication and plan prospectus updates accordingly
Suggested considerations
Map all existing prospectus templates, checklists and workflows against the revised Delegated Regulation (EU) 2019/979 data fields and immediately identify gaps in prospectus classification data and reference documentation.
Update internal prospectus data dictionaries and metadata schemas so that all new and updated prospectuses capture the full revised list of ESMA classification data required by the amended RTS.
Review and revise the firm’s incorporation‑by‑reference policy, including standard clauses and cross‑reference tables, to ensure only information categories permitted under the updated RTS are incorporated by reference.
Reconfigure electronic filing tools and interfaces used for submissions to the CSSF (and other NCAs) so that they generate and transmit the updated RTS data set required for classification and ESMA register purposes.
Train legal, capital markets, and product teams involved in prospectus drafting on the new RTS requirements, including examples of acceptable and non‑acceptable incorporation‑by‑reference documents.
What changed
- The amending Delegated Regulation updates the list of data fields required for the classification of prospectuses under Delegated Regulation (EU) 2019/979, impacting how issuers and their advisors...
The RTS amendment revises the list of information that can be incorporated by reference into a prospectus, narrowing or clarifying which external documents (e.g.
Prospectus classification data fields are expected to better align with current ESMA Prospectus Register needs (for example finer product type, offer type, and home/host state metadata), requiring...
The updated incorporation-by-reference list seeks to ensure that only readily accessible and reliable information may be referenced, which will affect how issuers structure cross‑references to annual...
National competent authorities, including the CSSF, will apply the revised RTS when reviewing and approving prospectuses and supplements, meaning filings that use outdated data sets or ineligible...
Compliance impact
Non‑compliance can lead to prospectus approval delays, rejection of filings, or required resubmissions, which may disrupt issuance timetables and investor communications. Persistent or material breaches may expose firms and issuers to supervisory measures, sanctions, and reputational risk for failing to meet Prospectus Regulation standards.
This is a user guide update for remuneration reporting from CSSF (Luxembourg financial regulator). It relates to disclosure and reporting requirements for audit profession entities. The content is informational/guidance in nature rather than announcing new regulatory requirements, hence null urgency.
IOSCO's final report on CIS valuation practices is an informational update consolidating valuation principles for collective investment schemes and hedge funds. It addresses disclosure and valuation standards across fund types, particularly relevant for asset managers and hedge funds managing less liquid and private...
CSSF is pressing Luxembourg market participants to complete T+1 readiness surveys by **9 June 2026** and to engage with ESMA’s broader T+1 consultation work, because the EU settlement cycle moves to **T+1 on 11 October 2027** under CSDR. The publication matters because it signals that supervisors are already assessing industry preparedness and that firms must accelerate post-trade process changes, especially around allocations, confirmations, and electronic messaging.
Key dates
02 June 2026
- CSSF publishes the reminder on T+1 readiness, survey participation, and ESMA’s consultation work
09 June 2026 Deadline
- Deadline to complete the CSSF national competent authorities’ T+1 readiness survey
07 December 2026
- Expected application date of the revised ESMA guidelines on standardised procedures and messaging protocols
11 October 2027
- T+1 settlement cycle becomes effective under CSDR
Suggested considerations
Complete the CSSF T+1 readiness survey before 9 June 2026 and ensure the submission accurately reflects the firm’s current operational readiness.
Participate in the EU T+1 Industry Committee second readiness survey to demonstrate engagement with the EU-wide readiness process.
Review the firm’s allocation and confirmation workflows to ensure they can operate within T+1 timeframes.
Replace any reliance on oral, manual, or non-machine-readable communications with electronic, standardised messaging channels unless a temporary technical disruption justifies an exception.
Align internal messaging standards with international messaging protocols used for post-trade communication.
What changed
- CSSF is requiring market participants to complete the national competent authorities’ T+1 readiness survey by 9 June 2026, with responses visible only to CSSF and ESMA.
CSSF is strongly encouraging participation in the EU T+1 Industry Committee second readiness survey to support a Union-wide assessment of market preparedness.
CSSF is flagging that the transition to T+1 settlement on 11 October 2027 under CSDR will require coordinated changes across the trading and post-trading chain.
CSSF is warning that forthcoming amendments to the RTS on Settlement Discipline are expected to be endorsed by the European Commission and will further define operational requirements for the T+1...
ESMA’s revised guidelines on standardised procedures and messaging protocols are intended to make post-trade communication faster, clearer, and more consistent across the EU.
Compliance impact
Non-participation in the surveys will not itself appear to be the substantive T+1 breach, but it will materially weaken supervisory visibility and may invite follow-up scrutiny from CSSF and ESMA. Firms that fail to adapt allocations, confirmations, and messaging processes risk being unprepared for the 7 December 2026 guidance phase-in and the 11 October 2027 settlement-cycle change, which could create settlement fails, operational disruption, and conduct/governance issues.
CSSF reminds Luxembourg market participants that the EU move to a **T+1 settlement cycle under CSDR on 11 October 2027** is now in execution phase and links this directly to concrete supervisory tools: mandatory-like readiness surveys, RTS on Settlement Discipline amendments, and new ESMA post‑trade communication guidelines. For compliance teams, this is a front‑to‑back operating model change: firms must demonstrate T+1 readiness to CSSF/ESMA, transition to fully electronic, standardised post‑trade communication, and align allocations/confirmations processes to tighter regulatory timelines.
Key dates
09 June 2026 Deadline
- Deadline for Luxembourg market participants to complete the CSSF national competent authorities’ T+1 readiness survey
07 December 2026
- Expected application date of revised ESMA guidelines on standardised procedures and messaging protocols and the aligned new RTS on Settlement Discipline requirements on allocations and confirmations
11 October 2027
- Effective date for the transition to a T+1 settlement cycle in the EU under CSDR
Suggested considerations
Identify all group entities and business lines in Luxembourg that are in scope of CSDR T+1 (trading, clearing, settlement, custody, collateral, fund dealing) and formally designate a T+1 programme owner at senior management level.
Complete the CSSF T+1 national competent authorities’ survey in full and by 9 June 2026, ensuring that responses accurately reflect current readiness, key risks, dependencies on third parties, and planned remediation milestones.
Arrange for appropriate internal review and sign‑off (e.g. by Compliance and relevant senior management) of the responses to both the CSSF survey and the EUIC second readiness survey before submission.
Participate in the EU T+1 Industry Committee second readiness survey and ensure the firm’s answers are consistent with the information provided to CSSF and with internal T+1 project documentation.
Perform a comprehensive T+1 impact assessment of front‑to‑back trade flows, covering trade execution, allocation, confirmation, affirmation, clearing, settlement, collateral movements, cash and liquidity management, and corporate actions.
What changed
- The EU settlement cycle for in‑scope financial instruments under CSDR will shorten from T+2 to T+1 with effect from 11 October 2027, materially reducing the time to complete front‑to‑back trade,...
CSSF has launched a national competent authorities’ T+1 readiness survey and sets a firm completion deadline of 9 June 2026 for Luxembourg market participants, treating it as a critical supervisory...
In parallel, CSSF strongly encourages Luxembourg firms to complete the EU T+1 Industry Committee (EUIC) second readiness survey to support an EU‑wide view of T+1 readiness and potential systemic...
ESMA’s final draft amendments to the CSDR RTS on Settlement Discipline will introduce additional operational requirements specifically designed to support T+1 (e.g.
ESMA has launched a consultation on updated guidelines on standardised procedures and messaging protocols for allocations, confirmations and affirmations, explicitly aimed at facilitating the T+1...
Compliance impact
Non‑compliance is high‑impact: failure to prepare for T+1, to respond adequately to supervisory surveys, or to align processes with RTS on Settlement Discipline and ESMA guidelines can lead to increased settlement fails, penalties, supervisory scrutiny, and potential enforcement action. The T+1 change also amplifies operational, liquidity, and conduct risks if firms cannot meet accelerated timelines, making early execution of remediation plans a prudential and conduct priority.
The CSSF has updated its FAQ on the Money Market Funds Regulation (MMFR), making the current guidance version available as **Version 5**. This matters because CSSF FAQs are used to clarify supervisory expectations for MMFs, and firms operating or managing MMFs in Luxembourg should treat the update as a prompt to confirm that prospectus disclosures, weekly transparency information, and reporting arrangements remain aligned with current CSSF practice.
Key dates
21 July 2018
- Article 36(2) transparency requirements apply to MMFs authorised under MMFR as of this date, excluding MMFs benefiting from the transitional provision in article 44(1)
28 August 2018
- CSSF first published the MMFR FAQ, establishing the supervisory clarification framework for MMF questions
18 March 2024
- The CSSF MMF page shows Version 4 of the FAQ and references updated related MMF materials, including ESMA stress test scenario guidance
05 June 2025
- The CSSF webpage shows Version 4 as updated on this date, before the current Version 5 publication
Version 5 / current publication date not stated in the provided extract
- The updated FAQ is now the current CSSF guidance version on the public webpage
Suggested considerations
Review the MMF prospectus and website disclosure architecture to ensure that maturity breakdown and credit profile information are presented in a manner consistent with the CSSF’s current FAQ interpretation.
Confirm that weekly article 36(2) disclosures are scheduled on a controlled and documented day of the week, with escalation procedures for missed or late publication.
Verify that internal credit quality assessment methodology, evidence, and sign-off are documented and available for disclosure or supervisory review.
Reassess whether each MMF in scope is subject to article 36(2) based on its authorisation status and whether any transitional article 44(1) treatment applies.
Align reporting and disclosure controls with the broader CSSF MMF framework, including recurring financial reporting expectations for CSSF-supervised MMF managers.
What changed
- The CSSF has published an updated MMFR FAQ and the current public version is Version 5, indicating that supervisory clarifications have been refreshed since the prior Version 4 publication.
The FAQ continues to address key MMFR transparency topics, including maturity breakdown, credit profile disclosure, and the ability to provide some information via a website link in the prospectus.
The guidance confirms that the manager may choose the day of the week for the weekly disclosure required under article 36(2), which is operationally important for recurring disclosure controls.
The FAQ states that information on internal credit quality assessment must be provided, reinforcing the expectation that the assessment is documented and made available as required.
The FAQ clarifies that article 36(2) applies only to MMFs authorised in accordance with MMFR as at 21 July 2018, and not to MMFs benefiting from the transitional provision in article 44(1).
Compliance impact
The compliance impact is moderate to high because MMFR breaches can create direct transparency, reporting, and governance deficiencies in a regulated fund product. Non-compliance may lead to CSSF supervisory challenge, remediation requests, or enforcement consequences if disclosures or reporting are inconsistent with the regulator’s expectations.
CSSF warning of fraudulent website impersonating authorized alternative investment fund manager. Identity theft and illicit activities pose direct risk to consumers and market integrity. High urgency due to active fraud scheme targeting legitimate firm's reputation and potential investor harm.
CSSF publishes mandatory list of independent approved statutory auditors and audit firms meeting EU Regulation 537/2014 Article 16 criteria (receiving <15% audit fees from PIEs).
This is a monthly statistical publication by CSSF (Luxembourg financial regulator) providing basic data on UCIs (Undertakings for Collective Investment). It is informational/reporting content with no regulatory action or deadline, hence urgency is null.
This is an informational update from CSSF regarding net assets statistics of Undertakings for Collective Investment (UCIs), published as of 30 April 2026. It appears to be a routine statistical disclosure/reporting publication rather than a regulatory requirement or enforcement action.
This is a monthly statistical publication from CSSF providing breakdown of Undertakings for Collective Investment (UCIs) registered in Luxembourg by currency. It is informational/disclosure content with no regulatory action or deadline, hence urgency is null. Relevant to asset managers and investment management sector.
This is a statistical publication from CSSF (Luxembourg financial regulator) providing monthly data on the origin of UCI (Undertakings for Collective Investment) initiators. It is informational/reporting content with no regulatory action or deadline, hence null urgency.
CSSF statistical update on UCI (Undertakings for Collective Investment) numbers as of April 2026. Informational content providing regulatory data and references to EBA/ESMA guidelines. No urgent action required; primarily serves as reference material for regulated entities and industry participants.
CSSF monthly statistical release on UCI (Undertakings for Collective Investment) net asset breakdown by investment policy as of April 2026. This is informational/statistical content providing regulatory reporting data, not a policy change or enforcement action.
The CSSF has formally repealed Circular IML 91/75 with immediate effect through the publication of Circular CSSF 26/912 on 22 May 2026. Compliance teams for Luxembourg UCIs and related structures must now ensure that no policies, procedures or prospectus provisions continue to rely on or reference IML 91/75, and instead rely on the current UCI, SIF, SICAR and EU fund law framework and subsequent CSSF circulars and administrative practice.
Key dates
21 January 1991
- Original Circular IML 91/75 entered into force, setting rules for undertakings governed by the Law of 30 March 1988 on undertakings for collective investment
22 May 2026
- Circular CSSF 26/912 is published and takes effect, repealing Circular IML 91/75 (as amended) with immediate effect and archiving it from the same date
Suggested considerations
Identify and inventory all internal and external documents (including policies, procedures, compliance manuals, prospectuses, offering documents, service agreements and SLAs) that reference Circular IML 91/75 or its amending Circulars CSSF 05/177, 18/697, 21/790, 22/811 and 25/901.
Remove or replace all references to Circular IML 91/75 and its amending circulars in compliance frameworks, manuals, registers of applicable rules and control libraries, ensuring they are mapped instead to the current applicable UCI, SIF, SICAR, AIFM and relevant CSSF circulars.
Perform a gap analysis to confirm that all substantive topics previously governed by IML 91/75 in your framework are now fully covered by current Luxembourg laws, EU fund regulations and up‑to‑date CSSF circulars and FAQs.
Update training materials and onboarding content for compliance, portfolio management, risk and operations staff to reflect that IML 91/75 has been repealed and to direct staff to the current legal and regulatory sources governing UCIs and alternative funds.
Adjust internal audit and compliance monitoring programs so that any test steps or key controls referencing IML 91/75 are updated to reference the applicable current provisions and CSSF administrative practice.
What changed
- Circular IML 91/75, which set out rules for Luxembourg undertakings governed by the Law of 30 March 1988 on undertakings for collective investment, is repealed in full with effect from 22 May 2026...
All amendments to Circular IML 91/75 introduced by Circulars CSSF 05/177, 18/697, 21/790, 22/811 and 25/901 are implicitly repealed as part of the repeal of IML 91/75 itself.
The regulatory expectations previously contained in IML 91/75 are now either superseded by later Luxembourg fund laws (including post‑1988 UCI legislation and regimes for SICARs and SIFs), later CSSF...
The historical link to the Law of 30 March 1988 on undertakings for collective investment is effectively severed at circular level, confirming that the operative framework is now the modern suite of...
IML 91/75 is flagged as archived by the CSSF as of 22 May 2026, clarifying that it has no continuing normative or interpretative value as a live supervisory instrument.
Compliance impact
The immediate compliance risk is moderate: there are no new obligations, but relying on a repealed circular can create legal uncertainty, documentation inconsistencies and supervisory challenges during CSSF inspections. Failure to update frameworks may weaken control design, lead to outdated disclosures and reduce credibility with the CSSF in the event of reviews or thematic inspections.
Repeal of Circular IML 91/75 related to the revision and remodelling of the rules to which Luxembourg undertakings governed by the Law of 30 March 1988 on undertakings for collective investment (“UCI”) are subject
AI Analysis
The CSSF has issued Circular CSSF 26/912, formally repealing Circular IML 91/75 (and its amendments) governing Luxembourg UCIs under the (now repealed) Law of 30 March 1988 on undertakings for collective investment. This is a technical clean‑up measure that removes an obsolete circular from the rulebook and confirms that the 1991 governance, organisational and investment rules under IML 91/75 no longer apply.
Key dates
21 January 1991
- Original Circular IML 91/75 on revision and remodelling of rules applicable to UCIs under the Law of 30 March 1988 is issued (subsequently amended by later circulars)
22 May 2026
- Circular CSSF 26/912 is published and Circular IML 91/75 (as amended by Circulars CSSF 05/177, 18/697, 21/790, 22/811 and 25/901) is repealed and archived
Suggested considerations
Update your regulatory inventory and obligation registers to reflect that Circular IML 91/75 and its amending circulars (CSSF 05/177, 18/697, 21/790, 22/811 and 25/901) have been repealed by Circular CSSF 26/912 as of 22 May 2026.
Verify that your compliance monitoring programmes and internal audit test plans do not rely on requirements sourced from Circular IML 91/75, and re-align any such tests to the currently applicable legal and regulatory standards.
Communicate the repeal of Circular IML 91/75 internally to legal, compliance, risk, product, and fund administration teams to prevent continued reliance on obsolete rules in ongoing or future projects.
For any ongoing remediation, authorisation or approval processes that previously cited IML 91/75 as justification for a control design, reassess and document those controls against the current CSSF requirements that have effectively replaced or superseded the 1991 framework.
Maintain an audit trail evidencing the update of documentation and registers in response to Circular CSSF 26/912, including board or senior management notification where your governance framework requires it for changes in regulatory obligations.
What changed
- Circular IML 91/75, including its amendments by Circulars CSSF 05/177, 18/697, 21/790, 22/811 and 25/901, is formally repealed by Circular CSSF 26/912.
The rules on “revision and remodelling of the rules to which Luxembourg undertakings governed by the Law of 30 March 1988 on undertakings for collective investment are subject” no longer form part of...
Supervisory expectations for Luxembourg UCIs are now to be derived exclusively from the current UCI regime (notably the Law of 17 December 2010 relating to undertakings for collective investment and...
Any internal compliance mappings, policy references, or control frameworks that still cite Circular IML 91/75 or its amending circulars must be treated as referencing repealed guidance and should be...
Compliance impact
The immediate compliance risk is low, as the circular repeals an already outdated framework; however, continuing to reference or rely on Circular IML 91/75 could create documentation inconsistencies, misalignment with current CSSF expectations and weaknesses in regulatory audits or inspections.
Document is a questionnaire template for sub-fund approval from Luxembourg's financial regulator (CSSF). This is procedural/informational content related to investment fund authorization requirements, not a substantive regulatory change. Urgency is null as this is administrative guidance.
CSSF newsletter is a periodic informational publication covering latest regulatory publications and financial sector statistics. No specific regulatory action, deadline, or urgent requirement indicated. Content is general across multiple sectors and firm types, warranting 'All Firms' classification.
ESMA Guidelines on stress test scenarios under Article 28 of the Money Market Fund Regulation – Update 2025 (ESMA50-481369926-30585)
AI Analysis
Circular CSSF 26/911 informs Luxembourg money market fund (MMF) managers that the CSSF is integrating ESMA’s 2025 update of the stress test scenarios under Article 28 of the Money Market Fund Regulation (MMFR), and that these new ESMA Guidelines now form part of the Luxembourg supervisory expectations. The circular repeals and replaces Circular CSSF 25/877 as of 26 May 2026 and requires MMFs and their managers to apply the 2025 stress test parameters for MMF reporting from the reporting date 30 June 2026 onwards, driving immediate model, data, and reporting changes.
Key dates
26 March 2026
- ESMA publishes the English, French, and German translations of the 2025 Guidelines on stress test scenarios under Article 28 MMFR on its website, starting the two‑month period to application
26 May 2026
- Circular CSSF 26/911 enters into force and Circular CSSF 25/877 is repealed and replaced, making the 2025 ESMA Guidelines the applicable stress testing framework in Luxembourg
30 June 2026 Deadline
- MMFs and MMF managers must apply the 2025 ESMA Guidelines for the preparation of the required MMF reporting as from the reporting date 30 June 2026 onwards, meaning that stress test calculations underlying this and subsequent reports must be based on the 2025 parameters
Suggested considerations
Identify all MMFs and MMF mandates in scope of Regulation (EU) 2017/1131 for which the CSSF is the competent authority and confirm that they are currently using the 2024 ESMA stress test framework under Circular CSSF 25/877.
Obtain and review in detail the ESMA 2025 Guidelines on stress test scenarios (ESMA50-481369926-30585) and the annexed parameters as integrated by Circular CSSF 26/911, comparing them line‑by‑line to the 2024 version to map all methodological and parameter changes.
Update the MMF stress testing policy and procedures to reference Circular CSSF 26/911 and the 2025 ESMA Guidelines, including explicit descriptions of the scenarios, calibration choices, modelling techniques, and governance for scenario approval.
Recalibrate stress testing models and tools used for MMFs to reflect the 2025 common reference parameters, ensuring that interest rate shocks, credit spread moves, liquidity shocks, redemption scenarios, and concentration risks are aligned with the new ESMA specifications.
Perform impact analyses on representative MMFs using both 2024 and 2025 parameters to quantify changes in stress outcomes, and prepare internal briefing materials for senior management and boards explaining the impacts on liquidity and risk profiles.
What changed
- Circular CSSF 26/911 replaces Circular CSSF 25/877 and integrates ESMA’s 2025 Guidelines on stress test scenarios under Article 28 of Regulation (EU) 2017/1131 (MMFR), making the updated scenarios...
The 2025 ESMA Guidelines (Ref. ESMA50-481369926-30585) update the common reference stress test parameters for MMFs, reflecting more recent market conditions and liquidity risk drivers than the 2024...
The circular clarifies that MMFs and MMF managers must use the updated 2025 ESMA stress test scenarios when preparing the MMF reporting required under the MMFR and the related Commission Implementing...
Circular CSSF 26/911 confirms that the 2025 Guidelines and their translations, published by ESMA on 26 March 2026, are now integrated into CSSF supervisory practice, following the ESMA process...
The circular reiterates that MMFs and their managers must tailor the ESMA reference scenarios to the specificities of each MMF, adding additional risk factors or requirements where needed to ensure...
Compliance impact
Non‑compliance with Circular CSSF 26/911 and the integrated 2025 ESMA stress test Guidelines can lead to MMF reporting deficiencies, supervisory findings, and potential risk‑management remediation measures imposed by the CSSF, including expectations to strengthen liquidity and governance. Persistent or material breaches could contribute to more intrusive supervisory engagement, restrictions on MMF activities, or sanctions under the MMFR and Luxembourg supervisory framework.
1° amending:(a) the Law of 5 April 1993 on the financial sector, as amended;(b) the Law of 17 December 2010 relating to undertakings for collective investment, as amended;(c) the Law of 18 December 2015 on the failure of credit institutions and certain investment firms, as amended;(d) the Law of 15 March 2016 on OTC…
The CSSF publication highlights AMLA's public consultation on draft Regulatory Technical Standards (RTS) under Articles 16(4) and 17(3) of Regulation (EU) 2024/1624, specifying minimum group-wide AML/CFT requirements and additional measures for subsidiaries and branches in third countries. This matters because it aims to harmonize cross-border AML frameworks, ensuring groups maintain consolidated ML/TF risk views and robust controls, particularly in high-risk third-country operations, impacting EU financial groups' compliance structures. Private sector input is encouraged to align standards with practical operations.[https://www.cssf.lu/en/Document/public-consultation-by-amla-on-the-draft-rts-on-group-wide-minimum-requirements-and-additional-measures-for-subsidiaries-and-branches-in-third-countries/][https://www.amla.europa.eu/amla-consults-group-wide-requirements-and-business-wide-risk-assessment_en]
Suggested considerations
Register for 20 May 2026 public hearing to engage directly on practical application across group structures.[https://www.amla.europa.eu/events/public-hearing-draft-rts-group-wide-minimum-requirements-and-additional-measures-subsidiaries-and-2026-05-20_en]
Assess current group-wide AML/CFT frameworks against proposed minimums, identifying gaps in third-country controls, risk consolidation, and data sharing protocols.
What changed
- Group-wide AML/CFT frameworks: Establishes minimum standards for design and implementation across groups, including cross-border structures and third-country operations, to enable consolidated...
Third-country subsidiaries and branches: Introduces additional measures for entities in non-EU countries, extending requirements beyond traditional groups to other...
Information sharing and parent identification: Defines provisions for intra-group data sharing and criteria to identify the EU parent undertaking when multiple entities report to a third-country head...
Interlinked mandates: Cross-references obligations between Articles 16(4) and 17(3) for complementary requirements on organizational...
Compliance impact
Urgency: High – Firms with third-country exposure must act now on consultation (closes 15 July 2026) to influence final RTS, as these will mandate binding minimums for group-wide AML/CFT, potentially requiring significant framework overhauls for risk consolidation and controls. Non-engagement risks misaligned systems post-adoption, increasing supervisory scrutiny under harmonized EU standards; early assessment prevents rushed...
AMLA has launched a public consultation on draft Guidelines for business-wide risk assessments (BWRA) under the new Anti-Money Laundering Regulation (EU 2024/1624), with submissions open until 15 July 2026. These guidelines establish minimum requirements for all obliged entities across financial and non-financial sectors to systematically identify and manage money laundering and terrorist financing risks inherent to their operations.
Key dates
Later in 2026
- Final adoption of guidelines and technical standards
16 April 2026
- Consultation launched
20 May 2026, 10:00–12:00 CET
- Public hearing on draft RTS on group-wide requirements
28 May 2026, 10:00–12:00 CET
- Public hearing on draft Guidelines on business-wide risk assessment
15 July 2026 Deadline
- Consultation deadline for submissions
Suggested considerations
*Immediate (by 15 July 2026):
Review draft Guidelines and assess alignment with current BWRA practices
Identify gaps between existing risk assessment frameworks and proposed minimum requirements
Prepare formal consultation responses, particularly if your organization operates in non-financial sectors
Register for relevant public hearings (28 May for BWRA Guidelines; 20 May for group-wide RTS) to engage directly with AMLA
What changed
The draft Guidelines introduce four minimum requirements for conducting adequate business-wide risk assessments applicable to all obliged entities. The framework mandates that entities:
Identify risk exposure across their business model, customers, products, services, transactions, delivery channels, and geographical exposure
Maintain consolidated risk views across group structures, eliminating silos between branches and subsidiaries
Utilize internal and external data sources to build comprehensive risk landscapes, including monitoring customer behavior changes and tracking international typologies
Apply proportionality based on entity size, business model, and risk profile, while ensuring consistent application of policies across the organization
The guidelines specifically address evaluation...
This newsletter from the CSSF (Luxembourg financial regulator) covers a range of topics relevant to banking, investment management, and wealth management firms operating in Luxembourg. The low urgency reflects that this is an informational publication rather than a time-sensitive regulatory update.
This warning from the CSSF relates to potential illicit activities by an unauthorized entity operating a website called 'werdy.net', which is offering investment services or other financial services without authorization in Luxembourg.
This regulatory update is related to the progress of a liquidation, which is likely to impact banking, investment management, and wealth management firms. The topics covered include prudential requirements, reporting, and authorization, which are relevant for these sectors.
This regulatory update provides guidance on the additional information required for AIFMs to market AIFs, which is relevant for investment management and wealth management firms that manage and market alternative investment funds.
This regulatory update from the CSSF covers the EBA Guidelines and Recommendations, which are relevant for banking, investment management, and wealth management firms. The topics include prudential requirements, reporting, and authorization, indicating medium urgency for these regulated entities.
ESMA Guidelines on Liquidity Management Tools (LMTs) of UCITS and open-ended AIFs (ESMA34-671404336-1364)
AI Analysis
Circular CSSF 26/910 announces the CSSF's application of ESMA Guidelines on Liquidity Management Tools (LMTs) for UCITS and open-ended AIFs, establishing standards for selecting, calibrating, and using LMTs to manage liquidity risks and mitigate financial stability threats. This matters for Luxembourg investment fund managers (IFMs) as it enforces uniform EU-wide supervisory practices under UCITS Directive Article 18a(2) and AIFMD Articles 16(2b)/(2c), holding IFMs primarily accountable for liquidity risk oversight.
Key dates
15 April 2026
Publication and CSSF application date of ESMA Guidelines via Circular CSSF 26/910
Suggested considerations
Review and Update Policies: IFMs must select, calibrate, activate/deactivate LMTs per ESMA guidelines, documenting fair/reasonable ADT calibration (e.g., transaction costs, market impact analysis).
Demonstrate Compliance: Be prepared to show regulators liquidity risk management, including at least one quantitative LMT, one ADT, and condition-specific tools; integrate with UCITS/AIFMD requirements.
Risk Management Integration: Ensure primary responsibility for LMTs, with consistent supervisory application; open-ended SIFs to cross-reference with (EU) 2026/465.
Supervisory Preparedness: Maintain records of previous transactions for market impact estimation and overall LMT rationale.
What changed
- Adoption of ESMA Guidelines: CSSF formally applies ESMA's guidelines (ESMA34-671404336-1364), focusing on LMT selection (e.g., redemption gates, suspension of redemptions/dealings, side pockets),...
Calibration Requirements: IFMs must demonstrate fair and reasonable ADT calibration for normal and stressed conditions, including explicit transaction costs and, where appropriate, estimated implicit...
LMT Recommendations: IFMs should select at least one quantitative-based LMT, one ADT, one for normal conditions, and one for stressed conditions; consider additional measures.
Scope Expansion Recommendation: Open-ended SIFs (not under Part II of the 2010 Law) should consider the circular alongside Commission Delegated Regulation (EU) 2026/465.
Compliance impact
Urgency: High – Published today (15 April 2026), this imposes immediate supervisory expectations on liquidity risk management for Luxembourg's dominant fund sector, where non-compliance risks enforcement under UCITS/AIFMD. IFMs must promptly review LMT frameworks to avoid supervisory scrutiny, especially amid potential market stress.
This warning concerns an unauthorized entity named Afitaustin that is allegedly providing investment services or other financial services without authorization in Luxembourg. This poses risks to consumers and could involve illicit activities, requiring a high level of urgency.
regarding the “LMT activation” module in relation to additional liquidity management requirements for Luxembourg-domiciled UCITS, or where applicable their management company, and Luxembourg-authorised AIFMs that manage open-ended AIFs, introduced by the Law of 3 March 2026, transposing Directive (EU) 2024/927 of the…
Why this matters
This regulatory update from the CSSF introduces new liquidity management requirements for investment funds in Luxembourg, including notification requirements for activating or deactivating certain liquidity management tools. This impacts investment managers and banks operating in the Luxembourg fund industry.
This regulatory update from the CSSF in Luxembourg provides monthly statistics on issuers of securities whose home Member State is Luxembourg. It covers topics related to reporting, authorization, and prudential requirements for banks, asset managers, and broker-dealers operating in the Luxembourg market.
This regulatory update from the CSSF provides monthly statistics on the balance sheet total and provisional net results of support PFS (Professionals of the Financial Sector) firms.
This regulatory update from the CSSF provides monthly statistics on notifications sent to other EEA competent authorities, covering topics such as prospectuses and base prospectuses. This is informational in nature and does not appear to require immediate action, hence the low urgency classification.
This regulatory update from the CSSF provides monthly statistics on notifications received from other EEA competent authorities, primarily related to prospectuses and base prospectuses.
This regulatory update from the CSSF provides monthly statistics on the number of prospectuses approved, which is relevant for investment management firms, banks, and broker-dealers operating in Luxembourg.
This is a critical supply chain attack targeting the widely used Axios HTTP client library, which is central to many architectures. The compromise of the build pipeline can result in remote code execution, credential theft, and lateral movement within the information system.
This is a warning from the CSSF about a potentially fraudulent website called Nuveramix, which is not authorized to provide investment or financial services in Luxembourg. This is a high urgency issue as it involves potential financial fraud targeting consumers.
on the operationalisation of European regulations in the area of financial services
Why this matters
This consolidated law on the operationalisation of European regulations in financial services is likely to impact banks, asset managers, and wealth managers across areas such as AML, prudential requirements, and licensing. The update indicates ongoing regulatory changes, warranting a medium level of urgency.
This regulatory update relates to the Law of 30 May 2018 on markets in financial instruments, which impacts banking, investment management, and capital markets firms. It covers prudential requirements, reporting and disclosure obligations, as well as authorization and licensing.
on key information documents for packaged retail and insurance-based investment products
Why this matters
This regulatory update relates to the Law of 17 April 2018 on key information documents for packaged retail and insurance-based investment products, which impacts firms in the banking, investment management, and insurance sectors.
This regulatory update relates to the law on market abuse, which is relevant for banking, investment management, and capital markets firms. It covers topics such as market abuse surveillance, reporting and disclosure requirements, and authorization and licensing.
This regulatory update relates to the audit profession in Luxembourg, which is relevant for banking, investment management, and wealth management firms operating in the country. It covers prudential requirements, authorization and licensing, as well as governance standards for statutory auditors.
on the failure of credit institutions and certain investment firms
Why this matters
This regulatory update relates to the law on the failure of credit institutions and certain investment firms, which is being updated. It covers prudential and operational requirements, as well as authorization and licensing for banks, wealth managers, and asset managers.
relating to undertakings for collective investment
Why this matters
This regulatory update relates to the Luxembourg Law of 17 December 2010 on undertakings for collective investment, which is relevant for investment management firms, wealth managers, and banks operating in Luxembourg.
transposing Directive 2004/25/EC of the European Parliament and of the Council of 21 April 2004 on takeover bids
Why this matters
This regulatory update relates to the transposition of the EU Takeover Directive, which impacts banking, investment management, and capital markets firms. It covers authorization, prudential, and market abuse topics.
on institutions for occupational retirement provision in the form of SEPCAVs and ASSEPs
Why this matters
This regulatory update relates to the law on institutions for occupational retirement provision in Luxembourg, which impacts banking, investment management, and insurance firms involved in pension products. It covers prudential requirements, authorization, and reporting obligations for these firms.
This regulatory update consolidates and amends the Law of 5 April 1993 on the financial sector, which is relevant for banks, wealth managers, and asset managers. The update covers prudential requirements, reporting obligations, and licensing/authorization, indicating medium urgency for affected firms.
This regulatory update provides information on the members of the Resolution Board, which is relevant for banks, wealth managers, and asset managers subject to prudential requirements, reporting obligations, and authorization procedures.
This regulatory update provides a list of members of the CPDI, which is relevant for firms in the banking, investment management, and wealth management sectors. The topics covered include AML/financial crime, consumer protection, and authorization/licensing, which are important for these types of firms.
This regulatory update from the CSSF covers a pre-inception readiness review for managed file transfer (MFT) services, which is relevant for investment management firms, wealth managers, and banks.
This regulatory update provides information on the global situation of undertakings for collective investment in Luxembourg, covering topics such as net asset values, fund flows, and market developments. It is informational in nature and does not appear to require immediate action, hence the 'null' urgency level.
This is a monthly statistical update on UCIs (Undertakings for Collective Investment) published by the CSSF, the financial regulator in Luxembourg. It is informational in nature and does not appear to require any immediate action, hence the low urgency level.
on the setting of the countercyclical buffer rate for the second quarter of 2026
Why this matters
This regulation from the CSSF (Luxembourg financial regulator) sets the countercyclical buffer rate for banks in Luxembourg for Q2 2026, which is a prudential measure related to capital requirements.
This regulatory update from the CSSF provides statistics on the net assets of Undertakings for Collective Investment (UCIs) in Luxembourg. It is an informational update related to reporting and disclosure requirements, as well as prudential and capital requirements, for investment management and wealth management...
This regulatory update provides a breakdown of UCIs (Undertakings for Collective Investment) registered in Luxembourg by reference currency. This information is relevant for investment management firms, wealth managers, and banks operating in the Luxembourg investment funds market.
This regulatory update from the CSSF in Luxembourg provides statistics on the origin of UCI (Undertakings for Collective Investment) initiators in the country. This information is relevant for investment management and wealth management firms operating in Luxembourg.
This regulatory update from the CSSF provides information on the number of UCIs (Undertakings for Collective Investment) in Luxembourg, which is relevant for banking, investment management, and wealth management firms operating in the country.
This regulatory update from the CSSF provides a breakdown of the investment policies and net assets of Undertakings for Collective Investment (UCIs) in Luxembourg. It is informational in nature and relevant for asset managers and wealth managers who operate UCIs.
This regulatory update from the CSSF outlines key supervisory priorities for the investment fund sector in 2026, covering areas such as governance/operational risks, ICT/cyber risks, liquidity and credit risks, contagion risks, asset valuation, sustainable finance, and costs/fees.
This newsletter from the CSSF (Luxembourg financial regulator) covers a range of topics relevant to banking, investment management, and wealth management firms operating in Luxembourg. The low urgency reflects the informational nature of the content.
This regulatory update provides annual statistics on the development of the Luxembourg banking sector over the past decades, including key metrics such as number of banks, balance sheet totals, and net results. The information is relevant for banks, wealth managers, and the broader financial industry in Luxembourg.
This is a warning from the CSSF about fraudsters misusing the name of the CSSF Board Chair to contact supervised entities. It is relevant for banks, wealth managers, and all financial firms that may be targeted by such fraud attempts. The warning covers consumer protection, AML, and operational resilience topics.
This regulatory update provides quarterly statistics on the development of banks' balance sheet totals, which is relevant for prudential requirements, reporting, and operational resilience. It covers a range of banking and investment management firms.
This regulatory update provides quarterly statistics on employment in the banking sector, which is relevant for banks, asset managers, and wealth managers from a prudential, reporting, and operational resilience perspective.
This regulatory update provides information on the members of the Investment Fund Managers Committee, which is relevant for investment management and wealth management firms. It also touches on topics related to authorization, prudential requirements, and governance, which are important for these types of firms.
This regulatory update from the CSSF in Luxembourg is relevant for investment management firms domiciled in Luxembourg. It provides information on the procedures for management notifications and de-notifications when using the European passport, which is an important authorization and licensing requirement for these...
This regulatory update from the CSSF covers consumer protection and financial crime issues, which are relevant for banking, wealth management, and fintech firms. The medium urgency reflects the ongoing nature of these compliance requirements.
This is a warning from the CSSF about fraudulent activities misusing the name of JPMorgan Asset Management (Europe) S.à r.l., an investment management firm. It involves identity theft, illicit activities, and impersonation, which pose risks to consumers and the financial sector.
in relation to additional liquidity management requirements for Luxembourg-domiciled UCITS, or where applicable their management company, and Luxembourg-authorised AIFMs that manage open-ended AIFs, introduced by the Law of 3 March 2026, transposing Directive (EU) 2024/927 of the European Parliament and of the Council…
Why this matters
This regulatory update introduces new liquidity management requirements for UCITS and open-ended AIFs in Luxembourg, which is relevant for investment managers and banks operating in the investment fund industry.
Latest update on the AML/CFT standardised data collection
AI Analysis
This CSSF circular letter addresses the 2026 AML/CFT standardised data collection exercise, aligning with AMLA's EU-wide initiatives by adopting AMLA-developed templates for most supervised entities while requiring specialised professionals to use CSSF-specific forms. It matters for Luxembourg financial firms as it mandates reporting on ML/TF risks and mitigation measures to support consistent EU supervision, with recent delays emphasizing preparation needs amid evolving templates.
Key dates
23 February 2026
- Planned launch for specialised professionals' CSSF questionnaire (delayed per 11 March update)
2 March 2026
- Original launch date for AMLA questionnaire and calibration exercise via eDesk platform (delayed)
13 March 2026
- AMLA webinar (10:00-12:00) on reporting framework and clarifications (connection details in CSSF annex)
15 April 2026 Deadline
- Submission deadline for AMLA calibration exercise participants (maintained despite delays; changes to be communicated)
TBD (post Deadline
11 March 2026); - New launch and submission deadlines for all data collections, pending final AMLA questionnaire
Suggested considerations
Monitor CSSF communications for final questionnaire, launch dates, and eDesk access; prepare data on 2025 ML/TF risks and mitigation using current AMLA draft (not for submission).
Selected AMLA calibration participants: Compile and submit quantitative/qualitative data via eDesk by 15 April 2026; attend 13 March webinar.
Non-selected credit/financial institutions: Complete AMLA templates on ML/TF risks/mitigation for 2025 via eDesk upon launch.
Specialised professionals: Prepare CSSF-specific questionnaire ahead of (delayed) 23 February launch.
All: Ensure resources for timely reporting; review internal AML/CFT risk assessments for consistency with EU standards.
What changed
- CSSF adopts AMLA-developed data collection templates for credit institutions, investment firms, and investment fund managers (excluding specialised professionals), replacing its prior questionnaire...
Entities selected for AMLA's mandatory calibration exercise (notified directly by CSSF) must report quantitative and qualitative ML/TF risk data; non-selected entities still report via AMLA templates...
Launch delayed from 2 March 2026 due to AMLA's consultation feedback on templates and guidance; new timelines and final questionnaire to be announced, but AMLA maintains 15 April 2026 submission for...
Specialised professionals of the financial sector complete a separate CSSF questionnaire, launching earlier on 23 February 2026 (subject to delay).
Compliance impact
Urgency: High - Mandatory reporting supports CSSF's supervisory strategy and EU AMLA calibration, with non-compliance risking enforcement; delays provide preparation time but require immediate data readiness as final deadlines approach shortly (e.g., potential April submissions). This directly feeds into entity-level ML/TF risk assessments, influencing ongoing supervision and resource allocation.
This regulatory update from the CSSF in Luxembourg relates to the public register of the audit profession, which is relevant for banking, investment management, and wealth management firms operating in Luxembourg. The key topics covered are reporting, authorization, and governance requirements.
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
Why this matters
This regulation implements restrictive measures against actions undermining Ukraine's territorial integrity, which is highly relevant for financial firms operating in the region or with Ukrainian counterparties. It covers areas such as AML, prudential requirements, and reporting, making it critical for compliance.
This regulatory update from the CSSF provides monthly statistics on the balance sheet total and provisional net results of specialised PFS (Professional of the Financial Sector) firms in Luxembourg.
This regulatory update from the CSSF provides monthly statistics on the balance sheet total and provisional net results of support PFS (Professionals of the Financial Sector) in Luxembourg.
This regulatory update from the CSSF relates to disruptions on the eDesk platform, which is likely a critical operational system for financial firms. The impact could be widespread across banking, investment management, and wealth management firms, as well as fintechs that rely on the eDesk platform.
implementing Regulation (EU) No 269/2014 concerning restrictive measures in respect of actions undermining or threatening the territorial integrity, sovereignty and independence of Ukraine
Why this matters
This Council Implementing Regulation imposes restrictive measures on actions undermining Ukraine's territorial integrity, sovereignty and independence. It is relevant for banks, wealth managers, and asset managers operating in the EU and dealing with entities/individuals subject to the sanctions.
This appears to be a calendar of SSM (Single Supervisory Mechanism) events related to Claude Wampach, which would be of interest to regulated financial firms in the banking, investment management, and wealth management sectors.
This regulatory update from the CSSF relates to a new reporting template for GBP LDI funds, which is relevant for investment managers and wealth managers that operate such funds. The update involves new disclosure and prudential requirements, hence the classification.
Delay in the 2026 AML/CFT standardised data collection
Why this matters
This interpretative note from the CSSF relates to a delay in the 2026 AML/CFT standardised data collection, which is relevant for banking, investment management and wealth management firms. It involves AML/financial crime compliance and reporting requirements, so the urgency is medium.
Delay in the 2026 AML/CFT standardised data collection
Why this matters
This regulatory update from the CSSF relates to a delay in the 2026 AML/CFT standardised data collection, which is relevant for banking, investment management, and wealth management firms. The update includes a reporting template, indicating new regulatory reporting requirements in the AML/financial crime domain.
This regulatory update provides information on the profit and loss account of credit institutions in Luxembourg as of 31 December 2025. It covers key financial metrics such as net interest margin, net commission income, and general expenses.
This regulatory update from the CSSF announces public hearings by the AMLA on draft regulatory technical standards related to AML/CFT requirements, including criteria for identifying business relationships, transactions, and customer due diligence.
Table listing the professional activities and the mandates performed
AI Analysis
This CSSF publication is an updated table (in XLSX format) listing standardized professional activities and mandates for members of the management body/governing body and conducting officers, as required under points 105 and 107 of Circular CSSF 18/698. It matters because it ensures consistent, transparent reporting of senior personnel roles in Luxembourg investment fund managers (IFMs), supporting governance, conflict-of-interest management, and CSSF supervisory oversight. Compliance professionals must use this list to standardize disclosures in authorization files and ongoing reporting.
Key dates
23 August 2018
- Publication of underlying Circular CSSF 18/698, setting baseline requirements
14 January 2019
- Original publication of the list
12 March 2026
- Latest update to the list, requiring immediate review and integration into reporting processes[Source URL]
End of May (post Deadline
financial year); - Compliance deadline for Circular 18/698 obligations, including governance reporting (e.g., 5 months after year-end)
Suggested considerations
Download and use the XLSX table: Incorporate the exact list of activities/mandates into internal templates for reporting management body and conducting officer roles[Source URL].
Update authorization and notification files: Include detailed CVs, criminal record extracts, wealth declarations, and organization charts for relevant personnel/shareholders; notify CSSF of changes (e.g., qualifying holdings, guarantees).
Conduct fit-and-proper assessments: Ensure declarations cover all listed mandates, demonstrating no conflicts and adequate resources; perform initial/ongoing due diligence on delegates.
Annual compliance review: Document roles in compliance monitoring plans, training, and reporting to senior management/CSSF; align with delegate oversight (e.g., risk-based monitoring of compliance, audit functions).
Policy updates: Revise governance policies to reflect the updated list, including AML/CFT officer designations and own funds proofs.
What changed
The document was originally published on 14 January 2019 and updated on 12 March 2026, reflecting revisions to the predefined list of professional activities and mandates[Source URL].
Alignment with Circular CSSF 18/698 requirements for IFMs (management companies for UCIs and AIFs), specifying reportable roles like those in collective portfolio management, risk management,...
Emphasis on detailed documentation of mandates to demonstrate fitness, properness, and avoidance of conflicts, including for shareholders with qualifying holdings.
No entirely new requirements introduced, but the update likely incorporates evolving governance expectations, such as enhanced delegate oversight and AML/CFT compliance officer designations.
Compliance impact
Urgency: High – The March 12, 2026 update coincides with today's date, demanding immediate review to avoid supervisory findings during CSSF inspections or authorization processes. Non-compliance risks authorization delays, fines, or reputational damage, as Circular 18/698 emphasizes robust governance in a heightened scrutiny environment for IFMs (e.g., delegate oversight, AML).
This regulatory update provides information on the global situation of undertakings for collective investment in Luxembourg at the end of January 2026. It covers topics related to investment management, reporting, and licensing, which are relevant for asset managers and wealth managers.
Delay in the 2026 AML/CFT standardised data collection
AI Analysis
The CSSF circular letter dated 11 March 2026 announces a delay in its planned AML/CFT standardised data collection exercise originally scheduled for 2026, primarily due to overlap with a concurrent broad-scope data collection by the European Anti-Money Laundering Authority (AMLA). This matters for compliance professionals as it reduces immediate reporting burdens on supervised entities, promotes regulatory simplification, and aligns Luxembourg practices with emerging EU AML/CFT methodologies, allowing firms to redirect resources to the mandatory AMLA exercise.
Key dates
TBD 2026
Potential ad-hoc CSSF questionnaires for essential data points
23 February 2026
Original launch for specialised professionals' CSSF questionnaire
2 March 2026
Original launch date for AMLA calibration exercise data collection via eDesk (now potentially adjusted or paused per delay circular)
11 March 2026
Publication of delay circular, superseding prior timelines; further modalities to be communicated
15 April 2026 Deadline
Original reporting deadline to CSSF for AMLA calibration exercise data
Suggested considerations
Monitor CSSF updates: Await forthcoming communications on revised modalities, new timelines, and any ad-hoc requests via eDesk platform.
Prioritize AMLA obligations: Selected entities must prepare quantitative/qualitative ML/TF risk data per draft RTS on risk assessments (Article 40(2) of Directive (EU) 2024/1640); non-selected entities focus on AMLA templates for 2025 risks/mitigation.
Specialised professionals: Continue preparations for CSSF-specific questionnaire, confirming any shifts post-delay.
Internal review: Assess ML/TF risk profiles, mitigation measures, and reporting readiness in light of EU alignment; update compliance calendars to reflect simplification.
No immediate submissions: Stand down from original 2 March/15 April deadlines unless individually notified otherwise.
What changed
- Postponement of CSSF-specific questionnaire: The CSSF has decided not to proceed with its own AML/CFT standardised data collection for most supervised entities (credit institutions, investment...
Exception for specialised professionals: Specialised professionals of the financial sector (e.g., certain non-credit institutions) remain subject to a CSSF-specific questionnaire, though timelines...
Rationale tied to AMLA calibration exercise: Entities selected for AMLA's 2026 calibration exercise (notified directly by CSSF) must complete it regardless; non-selected entities were to use AMLA...
Potential for ad-hoc requests: CSSF reserves the right to issue targeted questionnaires later in 2026 for essential data points not covered by AMLA.
These changes supersede the 12 February 2026...
Compliance impact
Urgency: Medium. The delay alleviates short-term pressure by postponing submissions and reducing dual reporting, enabling resource reallocation to higher-priority AMLA efforts amid EU harmonization. It matters for maintaining a risk-based approach (RBA) under FATF standards, avoiding overburden from overlapping exercises, and preparing for the new EU AML/CFT methodology—non-compliance risks supervisory scrutiny, but the simplification lowers immediate enforcement exposure.
This is a monthly statistical update on UCIs (Undertakings for Collective Investment) published by the CSSF, the financial regulator in Luxembourg. It is informational in nature and does not appear to require any immediate action, hence the low urgency level.
This regulatory update from the CSSF provides statistics on the net assets of UCIs (Undertakings for Collective Investment) as of January 2026. This information is relevant for investment management and wealth management firms that operate or invest in UCIs.
This regulatory update from the CSSF in Luxembourg provides monthly statistics on issuers of securities whose home Member State is Luxembourg. It is informational in nature and covers topics related to reporting, licensing, and prudential requirements for banks, asset managers, and broker-dealers operating in...
This regulatory update provides a breakdown of UCIs (Undertakings for Collective Investment) registered in Luxembourg by reference currency. It is informational in nature, covering statistics and data related to the investment management industry, banking, and wealth management firms operating in Luxembourg.
This regulatory update from the CSSF provides statistics on the origin of UCI (Undertakings for Collective Investment) initiators in Luxembourg. This is relevant for investment management and wealth management firms operating in Luxembourg, as it provides insights into the market composition.
This regulatory update from the CSSF provides information on the number of UCIs (Undertakings for Collective Investment) in Luxembourg, which is relevant for banking, investment management, and wealth management firms operating in the country.
This regulatory update from the CSSF provides information on the investment policy breakdown of Undertakings for Collective Investment (UCIs) in Luxembourg. It is relevant for investment management firms, banks, and wealth managers that operate or invest in Luxembourg-domiciled funds.
Administrative sanction imposed on a réviseur d’entreprises agréé
AI Analysis
The CSSF imposed an administrative sanction on 2 December 2025 against an approved statutory auditor (*réviseur d’entreprises agréé*) for breaches of professional obligations, likely related to continuing education requirements under Luxembourg's Audit Law, mirroring patterns in recent similar cases. This enforcement action underscores the CSSF's rigorous oversight of audit professionals, emphasizing compliance with ongoing training mandates to maintain audit quality and market integrity. Compliance professionals should note it as evidence of heightened scrutiny on non-delegable professional duties.
Key dates
31 December 2024 Deadline
- Likely reference period end for continuing education non-compliance (inferred from identical prior case)
2 December 2025
- Date of administrative sanction imposition by CSSF
6 March 2026
- Publication date of the sanction notice (today's date, aligning with CSSF practice for transparency under Article 48(2) of the Audit Law)
Suggested considerations
Immediate self-audit: Statutory auditors must verify personal compliance with continuing education hours under CSSF Regulation N°16-10, documenting hours against Article 3(1) requirements and submitting evidence if requested.
Remediation plan: If shortfalls identified, complete deficit training promptly and notify CSSF of corrective measures, as seen in related governance cases where entities implemented remediation.
Internal training programs: Audit firms should enhance monitoring of auditor CPE (continuing professional education) logs, integrating CSSF controls akin to Article 10 of the Audit Law.
Fit-and-proper reviews: Boards and compliance officers assess auditor qualifications, escalating any gaps to CSSF per professional obligations.
Record retention: Maintain verifiable CPE records for at least the reference period plus CSSF inspection windows (typically 3-5 years).
What changed
This is not a regulatory change or new requirement but an enforcement action applying existing rules under point f) of Article 43(1) read with point a) of Article 43(2) and Article 44 of the Law of 23 July 2016 on the audit profession (Audit Law), alongside CSSF Regulation N°16-10 on continuing education.
Compliance impact
Urgency: Medium. This matters as a signal of CSSF's proactive controls on auditor CPE, with fines starting at EUR 1,500 for initial breaches but scaling with severity/duration; repeated actions (e.g., multiple 2025 sanctions) indicate rising enforcement tempo, risking broader audit ecosystem scrutiny. Affected parties face direct fines and reputational harm, while others must prioritize CPE to avoid chain-reaction liabilities in financial reporting.
Administrative sanction imposed on a réviseur d’entreprises agréé
AI Analysis
The CSSF imposed an administrative sanction on 2 December 2025 against an approved statutory auditor (*réviseur d’entreprises agréé*) for breaches of professional obligations, likely related to continuing education requirements under Luxembourg's Audit Law, mirroring patterns in recent similar cases. This enforcement action underscores the CSSF's rigorous oversight of audit professionals, emphasizing compliance with ongoing training mandates to maintain audit quality and market integrity. Compliance professionals should note it as evidence of heightened scrutiny on non-compliance with minimum continuing education hours.
Key dates
31 December 2024 Deadline
- Reference period end for continuing education compliance (inferred from similar case)
2 December 2025
- Date of administrative sanction imposition by CSSF
6 March 2026
- Publication date of the sanction notice
Suggested considerations
Statutory auditors must immediately verify compliance with Article 3(1) of CSSF Regulation N°16-10, ensuring minimum continuing education hours are met for relevant periods.
Audit firms should conduct internal audits of training logs and implement remediation plans, including supplementary training if deficits exist.
All affected parties must report any identified breaches to CSSF proactively and retain evidence of corrective actions, as CSSF controls under Article 10 of the Audit Law can trigger fines.
What changed
No new regulatory changes are introduced; this is an enforcement action applying existing rules under point f) of Article 43(1) read with point a) of Article 43(2) and Article 44 of the Law of 23 July 2016 concerning the audit profession (Audit Law), alongside CSSF Regulation N°16-10 on continuing education for statutory auditors. Breaches typically involve failing to meet the minimum total hours of continuing education by the reference period end (e.g., December 31, 2024, as in a comparable August 2025 case).
Compliance impact
Urgency: Medium. This matters due to the pattern of CSSF enforcement on audit continuing education (e.g., EUR 1,500 fine in August 2025 case for similar breaches), signaling ongoing supervisory controls that could expand to on-site inspections. Non-compliance risks fines, public naming (or anonymous publication per Article 48(2) Audit Law), and reputational damage, but lacks immediate firm-wide deadlines, reducing to medium urgency for proactive reviews.
This is a warning from the CSSF regarding fraudulent websites impersonating a regulated investment firm, which poses risks of identity theft and illicit activities. It is a high-urgency issue for banks, wealth managers, and fintechs that may be targeted or impersonated by such scams.
This warning concerns a fraudulent website impersonating a legitimate investment firm, which poses risks of identity theft and illicit activities. It is relevant to banking, investment management, and wealth management firms, as well as fintechs, and requires prompt attention due to the potential for consumer harm.
This regulatory update announces the results of the 2025 professional competence examination for statutory auditors ('réviseurs d'entreprises') in Luxembourg. It is an informational update relevant for banks, wealth managers, and all firms subject to statutory audits in Luxembourg.
Administrative sanction imposed on an investment firm
AI Analysis
The CSSF imposed an administrative sanction on 8 October 2025 against an unnamed investment firm, as detailed in a publication released on 4 March 2026. This enforcement action underscores CSSF's rigorous oversight of investment firms, particularly in areas like AML/CFT compliance, conduct rules, and organizational requirements, serving as a warning for similar entities to strengthen cooperation and internal controls. It matters because it highlights escalating fines for repeated or material breaches, potentially influencing supervisory expectations across Luxembourg's financial sector.
Key dates
10 January 2025
- Date of prior depositary oversight fine
4 April 2025 Deadline
- Deadline for submitting CSSF AML/CFT Questionnaire (breach example from similar case)
16 July 2025
- Date of fine imposition for UCITS investment policy breaches
11 September 2025
- Date of fine imposition in comparable AIFM non-cooperation case
8 October 2025
- Date of the sanction in question
Suggested considerations
Enhance cooperation protocols: Implement automated tracking for CSSF requests (e.g., questionnaires) with escalations for reminders; document all responses.
Review investment compliance: Audit broker exposures, valuation processes, and subscription/redemption controls against UCI Law Articles 41-43, 109; suspend dealings if uncertainties arise.
Strengthen governance: Conduct gap analyses on internal controls, risk assessments, and reporting for depositary/oversight functions per AIFM Law Article 19(9) and CDR 231/2013.
Training and monitoring: Roll out firm-wide training on AML/CFT obligations (Article 5(1)) and perform reconciliations of assets/records; prepare for on-site/off-site CSSF inspections.
Self-reporting: Proactively disclose prior breaches to mitigate fine severity.
What changed
No new regulatory changes or requirements are introduced; this is an enforcement action applying existing rules.
Failure to cooperate with CSSF requests, e.g., not submitting required AML/CFT questionnaires by deadlines, violating Article 5(1) of the amended Law of 12 November 2004 on AML/CFT.
Non-compliance with investment policies, organizational requirements, or conduct rules under the UCI Law (e.g., Articles 41, 43, 109), including improper broker exposures or valuation failures.
These reflect ongoing enforcement of established frameworks like the AIFM Law, UCI Law, and AML/CFT Law, with fines calibrated by factors like breach duration, firm size, cooperation level, and prior...
Compliance impact
Urgency: High - This matters due to CSSF's pattern of publicizing nominative sanctions (e.g., Max Gain Capital, Zeus Asset Management), signaling increased scrutiny on investment firms amid AML/CFT and conduct risks. Fines (EUR 10,000–127,500) represent material hits (up to 10% of turnover), with factors like poor cooperation amplifying penalties; firms with similar exposures face elevated inspection risk, especially post-2025 enforcement wave.
implementing Regulation (EU) No 208/2014 concerning restrictive measures directed against certain persons, entities and bodies in view of the situation in Ukraine
Why this matters
This regulation implements restrictive measures against certain persons, entities and bodies in view of the situation in Ukraine. It is relevant for banking, investment management and wealth management firms that may be impacted by sanctions or need to comply with reporting requirements.
implementing Article 8a of Regulation (EC) No 765/2006 concerning restrictive measures in view of the situation in Belarus and the involvement of Belarus in the Russian aggression against Ukraine
Why this matters
This regulation implements restrictive measures against Belarus in view of its involvement in the Russian aggression against Ukraine. It is likely to have a high impact on banks, wealth managers, and asset managers that have exposure to Belarus or are required to comply with the sanctions.
This regulatory update from the CSSF provides monthly statistics on notifications sent to other EEA competent authorities, primarily related to prospectuses and base prospectuses. This is informational in nature and does not appear to require immediate action, hence the low urgency classification.
This regulatory update from the CSSF provides monthly statistics on notifications received from other EEA competent authorities, primarily related to prospectuses and base prospectuses. This information is relevant for banking, investment management, and capital markets firms operating in Luxembourg and the EEA.
This regulatory update from the CSSF provides monthly statistics on the number of prospectuses approved, which is relevant for investment management firms, banks, and broker-dealers operating in Luxembourg.
This regulatory update identifies reporting requirements and completeness checks, which is relevant for banks, asset managers, and wealth managers from a prudential, operational resilience, and disclosure perspective.
The CSSF published guidance on 2 March 2026 specifying minimum documents and information required for assessing shareholding structures of authorised Investment Fund Managers (IFMs) during initial authorisation and subsequent modifications, covering both qualified and non-qualified shareholders. This matters because incomplete submissions will not be processed, potentially delaying authorisations or amendments amid ongoing CSSF scrutiny of governance and ownership in Luxembourg's fund sector.
Key dates
2 March 2026
Publication and effective date; Guidance applies immediately; incomplete applications received on/after this date will not start processing until complete
Suggested considerations
Review Guidance: Download and study the XLSX document (Version 1.0) detailing per-shareholder/per-change requirements.
Prepare Complete Packages: For initial authorisation or amendments, compile minimum docs (e.g., IDs for beneficial owners/PEPs, group charts, financing details, MEF, fees); use *MEF templates where noted.
Submit Fully: Ensure all minimums included in future filings to avoid delays; anticipate CSSF requests for extras.
Internal Processes: Update compliance checklists, train teams on shareholder due diligence, and integrate into authorisation workflows.
What changed
- Minimum Document Requirements: Establishes a mandatory list of documents for each new shareholder candidate, differentiated by type (e.g., natural person, legal person, beneficial owner,...
Additional Mandatory Submissions: For changes involving qualified holdings (entry, increase/decrease, removal), requires updated group structure charts, MEF (in some cases), financing information,...
Enforcement Mechanism: From 2 March 2026, applications lacking these minimums are deemed incomplete, halting analysis until fully submitted.
No prior formalised list existed in this detail for IFMs, shifting from case-by-case to standardised requirements.
Compliance impact
Urgency: High – Effective immediately on publication (2 March 2026), with strict non-processing of incomplete files risking significant delays in time-sensitive authorisations/amendments. Matters for maintaining operational timelines in competitive fund markets, where CSSF oversight of IFM ownership ties to broader governance expectations (e.g., board composition, qualifications).
This CSSF guidance (Version 1.0, published 2 March 2026) specifies the minimum documents and information required for assessing shareholding structures of authorised Investment Fund Managers (IFMs) during initial authorisation or modifications involving qualified and non-qualified shareholders. It standardises submissions to ensure completeness, with incomplete applications rejected until fully provided, enhancing regulatory efficiency and scrutiny of ownership changes. Compliance professionals must prioritise this to avoid delays in authorisation processes for Luxembourg-domiciled IFMs.
Key dates
2 March 2026
Publication and immediate applicability; New guidance effective; incomplete applications received on/after this date not processed until complete
Suggested considerations
Prepare Complete Packages: For each new shareholder candidate, compile type-specific docs (e.g., ID/CV/DH/CR for direct unqualified shareholders; financing proof if indirect qualified lacks resources).
Submit Core Items: Always include updated group structure chart, MEF (template available), acquisition financing details, fee form; classify request type (e.g., prior authorisation for qualified changes).
Initial/Modification Filings: Use XLSX guidance as checklist; ensure beneficial owner verification per Circular CSSF 19/732.
Ongoing: Notify CSSF of changes; anticipate ad-hoc requests for extras like PEP declarations.
What changed
- Minimum Document Lists: Introduces detailed checklists in an XLSX format covering candidate shareholder documents (e.g., ID, CV, declarations of honour (DH), criminal records (CR) for natural...
Differentiation by Shareholder Type: Requirements vary by natural/legal person, beneficial owner, direct/indirect qualified/unqualified shareholders, and involvement in financing (e.g., "Yes, if PEP...
Other Mandatory Submissions: For qualified holding changes (entry, increase/decrease, removal), requires updated group structure charts, Market Entry Forms (MEF), financing details, and fee forms;...
Enforcement Mechanism: From 2 March 2026, incomplete submissions halt analysis until remedied; CSSF may request additional info.
Compliance impact
Urgency: High – Immediate effect from 2 March 2026 means any ongoing or planned IFM authorisation/modification applications risk delays or rejection if non-compliant, potentially disrupting fund launches or ownership restructurings in Luxembourg's key investment management hub. Matters due to standardised scrutiny on fit-and-proper ownership, aligning with AIFMD governance and reducing administrative back-and-forth.
This regulatory update from the CSSF provides quarterly statistics and analysis on investment fund managers in Luxembourg, including authorised and other investment fund managers, their assets under management, investment strategies, and cross-border activities.
This regulatory update from the CSSF focuses on its supervisory priorities in the area of sustainable finance, covering transparency and disclosures, risk management and governance, and MiFID rules related to sustainability for credit institutions and investment firms, as well as priorities for the asset management...
This directive establishes a public register of the audit profession in the EU, which is relevant for banking, investment management, and wealth management firms that are subject to audit requirements. The topics covered include AML/financial crime, consumer protection, and reporting/disclosure obligations.
amending Directives 2006/43/EC, 2013/34/EU, (EU) 2022/2464 and (EU) 2024/1760 as regards certain corporate sustainability reporting requirements and certain corporate sustainability due diligence requirements
Why this matters
This directive amends several existing EU directives related to corporate sustainability reporting and due diligence requirements. It will have a significant impact on financial firms in the banking, investment management, and wealth management sectors, requiring changes to their reporting and compliance processes.
This is a warning from the CSSF about fraudulent activities carried out by an unauthorized entity called Aisbierg Ennerstetzung Bank, which is posing as a financial services provider.
This is a warning from the CSSF about fraudulent activities by persons misusing the name of MERITUM CAPITAL, a Luxembourg-based investment management firm. The warning covers identity theft, illicit activities, and the use of unauthorized websites and email addresses.
This warning concerns a fraudulent website impersonating a legitimate investment firm, which poses risks of identity theft and illicit activities. It is a high-priority issue for banks, wealth managers, and fintechs that may be targeted or impacted by this scam.
This regulatory update from the CSSF provides standardized model articles of incorporation for UCITS funds, which is relevant for investment management firms and banks that operate UCITS funds.
This warning concerns a fraudulent website impersonating a legitimate investment management firm, which poses risks of identity theft and illicit activities. It is a high-urgency issue for firms in the banking, investment management, and wealth management sectors that need to be aware of this scam and take appropriate...
implementing Regulation (EU) 2024/1485 concerning restrictive measures in view of the situation in Russia
Why this matters
This regulation implements further restrictive measures against Russia, which will impact financial firms across banking, investment management, and wealth management sectors. The topics covered include AML/financial crime, prudential requirements, and reporting obligations, which are critical for firms to comply with.
This regulatory update from the CSSF in Luxembourg is relevant for banks and wealth managers that are involved in the issuance of covered bonds ('lettres de gage').
This regulatory update provides an overview of the global situation of undertakings for collective investment in Luxembourg at the end of December 2025. It covers topics related to investment management, wealth management, prudential requirements, and reporting, which are relevant for asset managers, banks, and wealth...
This warning from the CSSF relates to potential illicit activities associated with the website www.qatari.xyz, which is not authorized to provide investment or financial services in Luxembourg. This is a high-urgency issue for banks, wealth managers, and fintechs that may be impacted by this unauthorized entity.
This newsletter from the CSSF (Luxembourg financial regulator) covers a range of topics relevant to banking, investment management, and wealth management firms operating in Luxembourg. The low urgency reflects that this is an informational update rather than a critical regulatory change.
This regulatory update appears to be a calendar of events related to the Single Supervisory Mechanism (SSM) and Claude Wampach. It covers a range of topics relevant to banking, investment management, and wealth management firms, including prudential requirements, reporting, and governance.
1) high-risk jurisdictions on which enhanced due diligence and, where appropriate, counter-measures are imposed2) jurisdictions under increased monitoring of the FATFVersion of 17 February 2026
AI Analysis
The Annex of Circular CSSF 22/822 (Version of 17 February 2026) is Luxembourg's Commission de Surveillance du Secteur Financier's implementation guidance on FATF (Financial Action Task Force) designations of high-risk jurisdictions requiring enhanced due diligence and counter-measures, as well as jurisdictions under increased monitoring. This document is critical for Luxembourg-regulated financial institutions because it operationalizes international AML/CFT standards into binding compliance obligations, directly impacting customer acceptance, transaction monitoring, and correspondent banking relationships.
Key dates
27 October 2022
- Original Circular CSSF 22/822 issued
27 October 2025
- Previous version superseded
17 February 2026
- Current version effective (Annex of Circular CSSF 22/822)
Apply enhanced due diligence and monitoring measures to business relationships and transactions with designated jurisdictions
Increase the frequency and timing of transaction controls
Select transaction patterns requiring further examination and obtain detailed information on transaction purposes
Maintain enhanced mechanisms for reporting suspicious activity to the FIU
What changed
The current version (17 February 2026) represents the most recent update to the CSSF's FATF-aligned jurisdiction risk framework. Based on the available search results, the document establishes two primary regulatory categories:
High-Risk Jurisdictions (Category 1): Jurisdictions designated by FATF as having strategic deficiencies in their AML/CFT regimes, requiring enhanced due diligence and, where appropriate, counter-measures.
The CSSF has updated its FAQ on portfolio transparency requirements for UCITS ETFs, relaxing disclosure frequency from monthly to quarterly publication of detailed holdings while maintaining daily information sharing with market makers and authorized participants. This change aligns Luxembourg's regulatory framework more closely with Ireland's semi-transparent ETF approach and is designed to attract active asset managers to the Luxembourg domicile by reducing proprietary information exposure.
- Firms should implement changes promptly to ensure compliance with the new quarterly disclosure requirement
Suggested considerations
*For IFMs Managing UCITS ETFs:
*Update disclosure procedures to transition from monthly to quarterly publication schedules for detailed portfolio holdings
*Maintain daily information sharing with APs and market makers to support arbitrage mechanisms—this requirement remains unchanged
*Revise prospectuses to reflect the new quarterly disclosure frequency and confirm compliance with the 30 business-day publication window
*Document procedures for calculating the 30 business-day deadline from quarter-end
What changed
The update modifies two critical FAQ sections:
Portfolio Transparency Requirements (Question 12.1)
The CSSF has expanded and clarified its guidance to apply to all UCITS ETFs, not just actively...
Daily disclosure to market participants: Market makers and authorized participants (APs) continue to receive detailed portfolio information on a daily basis to maintain efficient arbitrage mechanisms...
Quarterly public disclosure: Investment Fund Managers (IFMs) must now publish detailed portfolio holdings to all investors at least quarterly with a maximum time lag of 30 business days (previously...
This CSSF FAQ (Version 23, updated 17 February 2026) provides interpretive guidance on the Luxembourg Law of 17 December 2010 relating to undertakings for collective investment (UCIs), covering UCITS, Part II UCIs, SIFs, and SICARs. It matters for compliance professionals as it clarifies authorisation processes, investment rules, and supervisory expectations, ensuring alignment with evolving EU frameworks like AIFMD and MiCAR. The update, effective today, addresses recent regulatory shifts including crypto-asset integration.
Key dates
20 May 2025
Related AIFM FAQ Version 24; Introduces changes relevant to UCI managers acting as AIFMs
16 January 2026
UCI Authorisation page update; Reflects ongoing CSSF expectations for approvals
04 February 2026
Crypto FAQ Version 7 update effective; MiCAR-aligned changes on crypto exposure, authorisation extensions, and depositary notifications
17 February 2026 Deadline
FAQ Version 23 update effective; Applies immediately to UCI operations, authorisations, and compliance.[User-provided content]
Suggested considerations
Review and Update Documents: Align UCI constitutive documents, investment policies, and sales documents with clarified rules on strategies, LMTs, conflicts, and risk-spreading; apply look-through for intermediaries.
Crypto-Specific: For >10% NAV exposure, apply for "Other-Other Fund-Crypto-assets" extension (custody, valuation, AML/CFT plans, expertise); notify CSSF for depositary crypto custody; implement heightened AML/CFT due diligence per FATF/Luxembourg assessments.
Authorisation/Amendments: Submit for CSSF approval on new setups, manager changes, or sub-funds (esp. SICAV multi-sub-funds with EU cross-border services).
Governance and Reporting: Ensure RC/RR demonstrate crypto risk understanding; update disclosures for investors on risks, LMTs, and fair treatment.
Ongoing Compliance: Use FAQ/Compilation for RAIFs/SIFs/SICARs/Part II UCIs; auditors/managers confirm tax-exempt status for SICARs.
What changed
- Authorisation Requirements: UCIs require CSSF approval of constitutive documents (articles, management regulations), depositary selection, and management company/AIFM applications for contractual...
Crypto-Asset Updates (aligned with separate but related FAQ Version 7): Replaces "virtual assets" with "crypto-assets" per MiCAR (EU 2023/1114); UCITS and retail AIFs (non-well-informed investors)...
Investment Policies and Liquidity Management: Funds must detail objectives, strategies, asset classes, restrictions, borrowing, and conflicts; look-through for intermediary vehicles per ESMA/AIFMD...
Risk Spreading Exemptions: Limits do not apply to OECD/EU-guaranteed securities or UCIs with comparable risk-spreading.
Depositary Role in Crypto: Luxembourg depositaries can custody crypto-assets with safeguards and CSSF notification; responsibility varies by model (depositary or MiCAR provider).
Compliance impact
Urgency: High – The update coincides with MiCAR implementation and today's release, requiring immediate review for crypto-exposed funds to avoid unauthorised strategies or AML gaps; non-compliance risks supervisory actions, authorisation delays, or investor disputes in Luxembourg's key fund domicile.
For which the CSSF is the relevant competent authority under Regulation (EU) No 236/2012 of the European Parliament and of the Council of 14 March 2012 on short selling and certain aspects of credit default swaps
Why this matters
This regulatory update from the CSSF provides a list of issuers of shares and sovereign debt for which the CSSF is the competent authority under the EU short selling regulation. This is informational content relevant for banks, broker-dealers, and asset managers operating in capital markets and investment management.
This regulatory update from the CSSF relates to the termination of the operation of a branch under the AIFMD directive, which is relevant for investment management firms and banks operating in Luxembourg.
This regulatory update from the CSSF relates to the termination of the operation of a branch under the UCITS Directive, which is relevant for investment management firms and banks operating in Luxembourg. It covers authorization and licensing requirements as well as prudential considerations.
This regulatory update from the CSSF relates to the notification requirements under the UCITS Directive, which is relevant for investment management firms and banks that offer UCITS funds.
This regulatory update from the CSSF relates to the notification requirements under Article 33 of the AIFMD, which is relevant for investment managers and wealth managers. It covers AML/financial crime compliance as well as authorization and licensing, which are critical topics for these firms.
This warning concerns fraudulent activities by an unauthorized entity, Minea Global Finance SA, which is not supervised by the CSSF and has not been granted any authorization to provide investment or financial services in Luxembourg. This poses a high risk to consumers and the financial system.
This is a monthly statistical update on UCIs (Undertakings for Collective Investment) published by the CSSF, the financial regulator in Luxembourg. It is informational in nature and covers reporting and disclosure requirements as well as prudential/capital aspects relevant for investment managers and wealth managers.
This regulatory update from the CSSF provides monthly statistics on the net assets of Undertakings for Collective Investment (UCIs), which are investment funds. This information is relevant for investment management firms, banks, and wealth managers that operate or invest in these types of funds.
This regulatory update provides a breakdown of UCIs (Undertakings for Collective Investment) registered in Luxembourg by reference currency. It is an informational update for investment management firms, banks, and wealth managers that operate in the Luxembourg market.
This regulatory update from the CSSF provides statistics on the origin of UCI (Undertakings for Collective Investment) initiators in Luxembourg. This is relevant for investment management and wealth management firms operating in Luxembourg, as it provides insights into the market composition.
This regulatory update from the CSSF provides annual statistics on the development of net assets and number of UCIs (Undertakings for Collective Investment) in Luxembourg. It is an informational update relevant for investment management and wealth management firms operating in Luxembourg.
This regulatory update from the CSSF provides information on the number of UCIs (Undertakings for Collective Investment) as of 31 December 2025. It is an informational update related to the banking and investment management sectors, covering topics such as prudential requirements, reporting, and licensing.
This regulatory update provides a breakdown of the investment policies and net assets of Undertakings for Collective Investment (UCIs) as of 31 December 2025. It is informational in nature and relevant for asset managers and wealth managers who invest in or advise on UCIs.
This regulatory update provides a list of investment funds (UCIs and SIFs) that have a sharia-compliant policy, which is relevant for investment management and wealth management firms.
This regulatory update relates to net assets of Undertakings for Collective Investment (UCIs) according to the Sustainable Finance Disclosure Regulation (SFDR). It is informational in nature and relevant for investment management and wealth management firms that are subject to SFDR reporting requirements.
AML/CFT standardised data collection taking place in 2026
AI Analysis
The CSSF Circular Letter 2026-02-12 announces a standardized data collection exercise on AML/CFT for supervised entities, scheduled for 2026, aimed at enhancing regulatory oversight of money laundering and terrorist financing risks. This matters because it signals intensified CSSF scrutiny on AML/CFT compliance, requiring firms to prepare structured data submissions that could inform future supervisory actions, risk assessments, and enforcement. As part of broader CSSF AML/CFT initiatives, non-compliance risks fines or heightened inspections.
Key dates
2026 (exact date TBD) Deadline
AML/CFT standardised data collection exercise; Firms must submit required data during this period; preparation recommended immediately given today's date (12 February 2026)
20 January 2026 Deadline
Issuance of related Circular 26/906; Establishes governance baselines (e.g., compliance independence, risk proportionality) informing data collection expectations
26 January 2026
CSSF AML/CFT Conference for Specialised PFS; Provided updates on sub-sector risks, terrorist financing reviews, and FIU insights relevant to data preparation
28 January 2026 Deadline
Conference materials published; Available for download to guide compliance alignment
Suggested considerations
Assess and document AML/CFT data readiness: Inventory current risk assessments, transaction monitoring logs, KYC processes, SAR filings, and third-party oversight records in standardized formats; map to proportionality factors (e.g., transaction volumes, outsourcing).
Update governance and controls: Ensure compliance functions have independence, direct board reporting, and audit coverage of AML/CFT; test ICT resilience for monitoring continuity.
Conduct internal reviews: Perform gap analyses against Circular 26/906 (e.g., fund safeguarding, escalation protocols) and recent conference topics (e.g., terrorist financing, tax indicators); remediate deficiencies with board-approved plans.
Prepare for submission: Designate resources for data compilation; cooperate fully with CSSF/FIU requests, including transfer-of-funds information under EU 2015/847.
Engage auditors: Leverage approved auditors for validation of AML/CFT effectiveness ahead of collection.
What changed
- Introduction of standardized AML/CFT data collection: CSSF mandates uniform reporting formats for collecting data on AML/CFT risks, controls, and practices across supervised sectors, building on...
Alignment with ongoing AML/CFT enhancements: Complements recent governance-focused circulars (e.g., Circular 26/906 on central administration and risk management for payment/e-money institutions) by...
No explicit new obligations beyond preparation for data submission, but implies deeper integration of tax-related AML indicators and sub-sector risk updates, as seen in related CSSF activities.
Compliance impact
Urgency: High – With data collection in 2026 underway today (12 February 2026), firms face immediate preparation needs amid recent enforcement (e.g., EUR 102,000 fine on depositary for AML-related gaps) and conferences signaling sub-sector focus. This elevates AML/CFT as a supervisory priority, potentially triggering on-site inspections, fines, or remediation orders for inadequate data/risks; proactive alignment prevents escalation in a risk-based regime.
This CSSF FAQ (Version 2, July 2013, with updates through 24 June 2013 and 11 July 2013) provides guidance on master-feeder structures for UCITS funds under the Luxembourg Law of 12 July 2010 (the "2010 Law"), addressing financial reporting, performance disclosure, and operational requirements. It matters for Luxembourg-domiciled UCITS managers and depositaries as it clarifies compliance with UCITS Directive rules on aggregation of charges, audit irregularities, and past performance in cross-border master-feeder setups, reducing ambiguity in documentation and investor communications.
Suggested considerations
Review and amend master-feeder agreements (per Art 79(1) 2010 Law) to require masters provide charge/fee data to feeders.
Ensure financial statements/annual reports disclose irregularities in specified sections and aggregate charges with audit report caveats if periods misalign.
Update KIIDs and marketing materials for past performance compliance, disclosing conversions/material changes per Regulation 583/2010 Articles 17, 19, 35.
Implement processes for ad hoc financial statements when accounting years differ, allocating audit/preparation fees appropriately.
Monitor CSSF website regularly for FAQ updates.
What changed
- Financial reporting for aggregate charges (Art 82(2) 2010 Law): When master and feeder UCITS have different year-ends, feeder must present master charges for the same period if possible; otherwise,...
Disclosure of irregularities (CSSF Regulation 10-05 Art 27(e)): Present in notes to financial statements or "other information" section of annual report.
Past performance rules (Art 159(3)c) 2010 Law and Commission Regulation (EU) 583/2010): Feeders converting to new masters cannot refer to pre-conversion past performance; masters converting from...
Document is periodically updated; CSSF reserves right to alter positions—firms must monitor website.
Compliance impact
Urgency: low—This 2013 guidance (Version 2) is outdated relative to 2026, with no new enforcement actions noted, but remains relevant for legacy UCITS master-feeder structures under the 2010 Law. It matters for audit/financial close processes and investor disclosures to avoid CSSF scrutiny, particularly in cross-border setups where ESMA UCITS rules apply; non-compliance risks reporting errors or investor complaints.
This publication is a CSSF FAQ in relation to the use by Luxembourg-domiciled UCITS of the following Securities Financing Transactions: securities lending transactions, reverse repurchase agreement transactions and repurchase agreement transactions. The objective of the FAQ is to bring further clarity concerning the…
AI Analysis
This CSSF FAQ (Version 2) provides guidance on the use of securities financing transactions (SFTs)—specifically securities lending, reverse repurchase agreements, and repurchase agreements—by Luxembourg-domiciled UCITS, clarifying regulatory requirements based on the applicable framework and CSSF's supervisory experience. It matters because it updates prior guidance to reflect evolved practices, helping UCITS managers ensure compliant SFT usage amid heightened scrutiny on liquidity, risk management, and investor protection in Luxembourg's fund sector.
Key dates
18 December 2020
Original publication date of Version 1
12 February 2026
Update date for Version 2; (effective immediately as non-binding guidance)
Suggested considerations
Review and update policies: UCITS managers must assess current SFT programs against the FAQ's clarifications, ensuring alignment with regulatory framework (e.g., UCITS Directive) and CSSF supervisory expectations on risk, collateral, and transparency.
Enhance disclosures: Update fund prospectuses, KIIDs, and annual reports to reflect SFT usage, risks, and revenues, per CSSF emphasis on investor clarity.
Conduct gap analysis: Audit SFT counterparties, collateral management, and liquidity tools for compliance; remediate any deviations based on gained supervisory experience.
Train staff and delegates: Implement training on updated FAQ to cover securities lending, repos, and reverse repos specifics.
Monitor ongoing use: Maintain records of SFT volumes, counterparties, and performance for CSSF inspections; integrate with broader UCI regulatory updates like risk-spreading.
What changed
The document is an updated FAQ (Version 2), originally published on 18 December 2020 and revised on 12 February 2026, but the provided content does not detail specific changes from Version 1 beyond incorporating recent supervisory experience and regulatory framework updates. It emphasizes clarity on SFT eligibility, operational controls, and risk mitigation for UCITS, without introducing new prohibitions or mandates visible in the summary; full details require accessing the PDF (201.4Kb).
Compliance impact
Urgency: High – The 12 February 2026 update coincides with today's date, signaling immediate relevance for Luxembourg UCITS engaging in SFTs, which are common for yield enhancement but carry liquidity and counterparty risks. Non-compliance risks supervisory actions, given CSSF's focus on practical experience; firms should prioritize review to avoid findings in upcoming audits or inspections, especially amid parallel 2026 updates on UCI investments.
Submission of the register of information at individual or consolidated level to the CSSF (excluding entities under the direct supervision of the ECB)
Why this matters
This regulatory update from the CSSF provides details on the submission timeframe and process for the DORA register of information, which is relevant for banking, investment management, and wealth management firms. It covers operational resilience, reporting, and technology/cyber topics.
Guidance allowing financial entities to identify the National Competent Authority to which their register of information has to be submitted.
AI Analysis
This CSSF guidance document, published on 11 February 2026, provides detailed explanations and resolution steps for error messages encountered during the submission of the DORA Register of Information (RoI) via the eDesk portal, specifically for the 2026 submission cycle. It matters because it enables Luxembourg financial entities to ensure compliant submissions amid enhanced validation checks on more data fields, avoiding re-submission delays and supporting timely transmission to the ESAs by CSSF deadlines. Non-compliance risks supervisory scrutiny under DORA's ICT risk management framework.
Key dates
30 April 2025 Deadline
- CSSF re-submission deadline post-validation for 2025; analogous for 2026 if errors detected
May 2025
- ESAs' second-round validation for 2025; expect similar for 2026 with potential re-submissions
- Reference date for 2026 RoI submission (all contractual arrangements up to this date)
11 February 2026
- Publication date of this error guidance (last updated 10/02/2026)
Suggested considerations
Assign "DORA Reporting" role in eDesk to dedicated employee(s) per user guide.
Communicate LEI code to CSSF line supervisor prior to first submission to enable upload.
Prepare RoI in plain-CSV files within .zip following ESAs' folder structure/file naming (reference date '2025-12-31'); include all tables in FilingIndicators.csv (even empty, set to 'true').
Test submissions against listed error codes (e.g., ICTO007 for LEI, identification mismatches); resolve per guidance sections (e.g., Sections 3.2.2, 5.1.2, 6).
Consult ESAs' EBA resources (data point model, validation rules, FAQs) and CSSF guides (e.g., submission guide, guidance tables).
What changed
- Enhanced validation checks for the 2026 RoI submission: Applies ESA-defined checks (last updated April 2025) to more data fields to improve data quality, compared to prior cycles.
Specific error resolutions detailed, including requirements for LEI code communication to CSSF beforehand, correct reference date ('2025-12-31') in file naming, plain-CSV files in predefined .zip...
Mandatory inclusion of all tables (even empty) in FilingIndicators.csv set to 'true', with matching identification codes across parent-child records.
Builds on prior CSSF guides, emphasizing eDesk role "DORA Reporting" assignment and ESAs' technical standards.
No new regulatory requirements under DORA itself; this refines technical submission...
Compliance impact
Urgency: High - Published today (11 February 2026), this equips firms for imminent 2026 RoI submissions (reference date 31 December 2025), with stricter validations on expanded fields risking rejections/re-submissions. Matters for operational resilience compliance under DORA Article 28, as accurate RoI supports supervisory oversight of ICT third-party risks; delays could trigger CSSF/ESA follow-up or fines. Firms with prior 2025 issues (e.g., portal extensions to May 2025) must prioritize to avoid recurrence.
This regulatory update from the CSSF provides monthly statistics on issuers of securities whose home Member State is Luxembourg. It is informational in nature and covers topics related to reporting, licensing, and prudential requirements for banks, asset managers, and broker-dealers operating in Luxembourg.
This regulatory update from the CSSF provides monthly statistics on notifications sent to other EEA competent authorities, primarily related to prospectuses and base prospectuses. This is informational in nature and does not appear to require immediate action, hence the low urgency classification.
This regulatory update from the CSSF provides monthly statistics on notifications received from other EEA competent authorities, primarily related to prospectuses and base prospectuses. This is informational in nature and does not appear to require immediate action, hence the low urgency classification.
This regulatory update from the CSSF provides monthly statistics on the number of prospectuses approved, which is relevant for investment management firms, banks, and broker-dealers operating in Luxembourg.
This CSSF communiqué announces the availability of updated UCI Reports (SAQ, SR, and ML) under Circular CSSF 21/790 on the eDesk platform's CISERO module for specific 2026 year-ends, with key enhancements focused on valuation, NAV determination, and risk-based streamlining. It matters for Luxembourg UCIs as it reflects evolving supervisory priorities, aligns with EU directives like Directive (EU) 2024/927, and imposes refined self-assessment obligations to bolster resilience in stressed conditions and liquidity management.
Key dates
9 February 2026
Reports (SAQ, SR, ML) made available on eDesk CISERO for year-ends 31 January, 28 February, 31 March, 30 April 2026
16 April 2026
Entry into application of AIFM/UCITS Review Directive LMT requirements
Financial year Deadline
end +5 months (UCITS/Part II UCIs); SAQ/SR submission deadline
Financial year Deadline
end +6 months (SIFs/SICARs); SAQ/SR submission deadline
Three months before year
end (post-30 April 2026); Future Reports availability
Suggested considerations
Access updated Reports on eDesk CISERO module immediately and review changes vs. 31 December 2025 versions.
Update valuation policies/procedures to explicitly cover stressed conditions, new sub-funds/strategies, model validations, and backtesting; document compliance.
Revise NAV processes for LMT alignment with Directive (EU) 2024/927 Annexes and ESMA performance fee guidelines; confirm for open-ended UCIs.
Dirigeants/management: Complete/validate SAQ addressing new/clarified questions; prepare for REA SR/ML review.
REAs: Perform streamlined SR procedures; issue ML on prior weaknesses with remediation timelines.
What changed
- SAQ Updates (Valuation Section): New questions on valuation policies for stressed market conditions/exceptional circumstances; coverage for new sub-funds/strategies; independent validation of...
SAQ Simplifications and Clarifications: Removed questions on sub-funds with significant non-standard OTC derivatives, unquoted assets, or external valuer OTC FDIs (including NAV proportions); refined...
SAQ NAV Determination: Updated Liquidity Management Tools (LMTs) sub-section to align with Annexes of AIFM/UCITS Review Directive (Directive (EU) 2024/927); added question on compliance with ESMA...
SR Streamlining: Removed procedures in investment compliance (e.g., eligibility assessments for closed-ended funds, structured instruments, non-plain vanilla OTC derivatives; credit quality for money...
Reports for year-ends after 30 April 2026 available three months prior.
Compliance impact
Urgency: High – Immediate access required for imminent submissions (e.g., 31 January 2026 year-end due ~June 2026); new valuation questions demand policy reviews to avoid supervisory findings, especially amid stressed markets; SR simplifications reduce burden but shift focus to SAQ self-assessment, heightening dirigeants' accountability. Non-compliance risks CSSF follow-up on modified audits or weaknesses, per Circular 21/790.
The regulatory update describes active exploitation of vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), a mobile endpoint management solution. This poses a severe risk to managed devices and sensitive data, especially for financial firms that use EPMM.
This regulatory update from the CSSF provides monthly statistics on the balance sheet total and provisional net results of specialised PFS (Professionals of the Financial Sector) in Luxembourg.
This regulatory update provides quarterly employment statistics for specialized professional financial services (PFS) firms in Luxembourg. It covers employment trends across different sectors and is likely of interest to firms operating in the banking, investment management, and wealth management industries.
This regulatory update from the CSSF provides monthly statistics on the balance sheet total and provisional net results of support PFS (Professionals of the Financial Sector) in Luxembourg.
This regulatory update provides quarterly employment statistics for support PFS firms, which is informational in nature and does not indicate any urgent regulatory changes or actions.
This regulatory update provides annual statistics on the balance sheet total and net result of support PFS firms in Luxembourg. It is informational in nature and does not appear to require immediate action, hence the low urgency level.
This warning concerns a fraudulent website impersonating a legitimate financial services firm, which poses risks of identity theft and illicit activities. It is relevant for banks, wealth managers, and fintechs that may be targeted or impersonated in such scams.
Administrative sanction imposed on Corestate Capital Holding S.A.
AI Analysis
The CSSF published an administrative sanction on 6 February 2026 against Corestate Capital Holding S.A., likely for breaches in regulatory compliance such as depositary duties, oversight, or governance under Luxembourg financial laws, marking a repeat enforcement action following a prior sanction in June 2025. This matters for compliance professionals as it underscores CSSF's aggressive enforcement on alternative investment fund managers (AIFMs) and depositaries, signaling heightened scrutiny on safekeeping, oversight, and internal controls to prevent systemic risks in Luxembourg's fund sector. It highlights the regulator's willingness to impose public nominative sanctions, amplifying reputational damage alongside fines.
Key dates
20 June 2025 Deadline
- Prior administrative sanction imposed on Corestate Capital Holding S.A., indicating ongoing non-compliance issues
6 February 2026
- Publication date of the current administrative sanction on Corestate Capital Holding S.A., effective immediately as a public enforcement notice
Suggested considerations
Conduct immediate gap analysis: Review safekeeping processes for ownership verification (Article 19(8)(b) AIFM Law), ensuring transaction documentation, segregated account proofs, and full holding chain records are available at transaction points.
Enhance oversight duties: Implement risk assessments per Article 92(1) CDR 231/2013, valuation compliance checks (Article 94), and cash remittance monitoring (Article 96); appoint delegates with due diligence.
Strengthen governance: Update internal controls, procedures, and conflict-of-interest policies (e.g., director overlaps); ensure key documentation availability and evidence of controls.
Firm-wide audit: For repeat offenders like Corestate, perform root-cause analysis on prior sanctions and submit remediation plans to CSSF if inspected.
Training and reporting: Train staff on CSSF expectations; improve cooperation mechanisms to avoid AML/CFT fines for non-submission of requests.
What changed
No new regulatory changes or requirements are introduced; this is an enforcement action enforcing existing obligations under laws like the AIFM Law of 12 July 2013 (e.g., Articles 19(8), 19(9), 19(11) on safekeeping and oversight duties), the Law of 5 April 1993 on the financial sector, and Commission Delegated Regulation (EU) No 231/2013 (CDR 231/2013, e.g., Articles 92, 94, 96 on risk assessment, valuation verification, and cash flow monitoring).
Compliance impact
Urgency: High – This represents CSSF's pattern of public nominative fines (e.g., EUR 102,000 on JTC for depositary breaches, EUR 10,000 on Capitalis for AML non-cooperation), with escalation risks for repeat violations like Corestate's back-to-back sanctions. It matters due to Luxembourg's dominance in European fund assets (over EUR 5 trillion), where governance lapses can trigger outflows, license revocation, or cross-border ESMA scrutiny; firms must act preemptively to mitigate fines (typically EUR 10,000–102,000) and reputational harm from nominative publication.
Administrative sanction imposed on Corestate Capital Holding S.A.
AI Analysis
The CSSF published an administrative sanction on 6 February 2026 against Corestate Capital Holding S.A., likely imposing a fine for regulatory breaches, marking a repeat enforcement action following a prior sanction on the same entity dated 20 June 2025. This matters as it underscores CSSF's intensified supervisory scrutiny on Luxembourg-based investment managers, particularly regarding governance, asset safekeeping, and oversight duties under AIFM Law, signaling heightened enforcement risks for similar firms. Compliance teams should review it for patterns in depositary and transparency violations evident in recent CSSF cases.
Key dates
20 June 2025
- Prior administrative sanction imposed on Corestate Capital Holding S.A
6 February 2026
- Publication date of the current administrative sanction on Corestate Capital Holding S.A
Suggested considerations
Conduct immediate gap analysis on depositary functions: Verify ownership chains, transaction documentation, segregated account reconciliations, and custodian delegations per AIFM Law Articles 19(8) and 19(11).
Enhance oversight processes: Implement risk assessments for AIF strategies, valuation policy checks, and cashflow monitoring per CDR 231/2013 Articles 92, 94, and 96.
Strengthen governance: Review internal controls, procedures, and conflicts (e.g., director overlaps with affiliates); ensure availability of control evidence.
For issuers like Corestate: Confirm compliance with half-yearly financial reporting and dissemination under Transparency Law Article 4.
Firm-wide: Perform mock CSSF on-site inspections focusing on 2022-2025 periods, given inspection timelines in recent cases.
What changed
No new regulatory changes or requirements are introduced; this is an enforcement action highlighting non-compliance with existing obligations under Luxembourg's AIFM Law (notably Articles 19(8), 19(9), 19(11), and 51) and related delegated regulations like CDR 231/2013. Key breaches from analogous recent CSSF sanctions include inadequate safekeeping of assets (e.g., missing ownership verification and records), failure to oversee AIFM valuation policies and cash remittance timelines, improper delegation to custodians without due diligence, and weak internal governance such as conflicts of...
Compliance impact
Urgency: High – This represents repeat enforcement on Corestate (second sanction in under a year), aligning with CSSF's pattern of nominative publications for severe, ongoing breaches in depositary and governance areas, as seen in JTC (EUR 102,000 fine for similar safekeeping/oversight failures) and BigRep SE (EUR 10,000 for reporting lapses). It elevates risks of fines, reputational damage, and market jeopardy assessments under AIFM Law Article 51, urging preemptive remediation amid CSSF's active 2023-2026 inspection cycle.
This regulatory update is related to the list of fund units subject to the European Social Entrepreneurship Funds (EuSEF) regulation, which is relevant for investment management and wealth management firms that offer or invest in such funds.
This regulatory update lists fund units subject to the EuVECA regulation, which is relevant for investment management firms and capital markets participants. The update covers authorization and licensing requirements as well as reporting obligations for these funds.
This regulatory update provides a list of fund units subject to the European Long-Term Investment Funds (ELTIFs) regulation, which is relevant for investment management and wealth management firms that offer or manage such funds.
This is an update to a regulatory form related to the notification and change of particulars for tied agents, which is relevant for investment management and wealth management firms.
This regulatory update announces the reappointment of the Director General of the CSSF, the financial regulator in Luxembourg. It is relevant for banks and wealth managers operating in Luxembourg as it signals continuity in the leadership and oversight of the regulator.
This regulatory update warns about online financial frauds and scams in an artificial intelligence world, which is highly relevant for banking, investment management, and wealth management firms, as well as fintechs and crypto exchanges that operate in the digital finance space.
The Commission de Surveillance du Secteur Financier (CSSF) has updated its FAQ on crypto-asset investments by undertakings for collective investment, effective February 4, 2026, to align with the EU's Markets in Crypto-Assets Regulation (MiCAR). This update establishes clear investment limits and licensing requirements for UCITS and AIFs investing in crypto-assets, fundamentally reshaping how Luxembourg-regulated funds can structure crypto exposure.
Key dates
4 February 2026 Deadline
- FAQ Version 7 effective date; MiCAR compliance requirements become operative
1 July 2026 Deadline
- Deadline for Virtual Asset Service Providers (VASPs) to transition from registration to authorization under MiCAR or cease operations
Suggested considerations
*For UCITS Managers:
by-case assessment of crypto-asset investment impact on fund risk profiles
specific risks (volatility, liquidity, technological risk)
asset investments
*For AIFMs Managing AIFs with Crypto Exposure:
What changed
The regulatory framework introduces several material modifications:
Investment Exposure Limits
UCITS may invest indirectly in crypto-assets for a maximum of 10% of their net asset value (NAV). These indirect investments are restricted to transferable securities that do not embed derivatives. AIFs open to retail investors other than well-informed investors face the same 10% NAV ceiling.
MiCAR Alignment
The FAQ modifications directly reflect the entry into force of Regulation (EU) 2023/1114 on markets in crypto-assets.
This is a warning from the CSSF regarding an unauthorized entity, Castleforbes Wealth Limited, that is allegedly providing investment services without proper authorization in Luxembourg.
Administrative sanction imposed on Genève Invest (Europe) S.A.
AI Analysis
The CSSF imposed an administrative sanction on 23 July 2025 against Genève Invest (Europe) S.A., a Luxembourg-regulated entity, for breaches of professional obligations, as detailed in a publication released on 4 February 2026. This enforcement action underscores the CSSF's focus on robust internal controls and compliance with investment rules, serving as a warning to investment firms on the consequences of organizational and conduct failures. Compliance professionals should note it as evidence of heightened CSSF scrutiny on fund managers handling client assets and counterparties.
Key dates
23 July 2025
- Date of administrative sanction imposition on Genève Invest (Europe) S.A
4 February 2026
- Publication date of the sanction document by CSSF
Suggested considerations
Immediate review of counterparty due diligence: Verify licenses and financial stability of brokers/prime brokers; cease deposits with unauthorized or suspended entities per UCI Law Article 41.
Enhance valuation and accounting controls: Ensure assets (e.g., cash deposits) are valued at probable realization value per Article 28(4) UCI Law and prospectus terms; implement automated monitoring for ongoing compliance.
Conduct internal audits: Assess organizational requirements, investment policies, and conduct rules (CSSF Regulation 10-04); remediate gaps proactively, as seen in mitigated sanctions for cooperative firms.
Update governance and reporting: Document risk assessments and report prior breaches to CSSF to demonstrate cooperation, potentially reducing fine severity.
What changed
This is not a regulatory change or new requirement but an enforcement action highlighting existing obligations under Luxembourg law. Key breaches likely mirror patterns in recent CSSF sanctions, such as non-compliance with UCI Law provisions on investment policies (e.g., Articles 41, 43), sound accounting procedures (Article 109), and rules of conduct (Articles 111, CSSF Regulation 10-04), including improper cash deposits with unauthorized brokers and inaccurate asset valuation.
Compliance impact
Urgency: High – This sanction, published today (4 February 2026), signals ongoing CSSF off-site and on-site probes into fund operations, similar to fines imposed in July 2025 on Zeus Asset Management (€18,136 for UCI breaches) and a bank (reprimand for AML gaps). It matters due to escalating enforcement—fines calibrated to turnover (e.g., 10% in Zeus case)—and risks of reputational damage, especially for wealth managers with broker exposures. Non-compliance could trigger investigations, as CSSF considers infringement duration, cooperation, and history.
This regulatory update provides information on a registration form for meetings with UCI Departments of the CSSF, which is relevant for financial firms in the banking, investment management, and wealth management sectors.
The CSSF has released Version 7 of its FAQ on Crypto-Assets for Undertakings for Collective Investment, updated on February 4, 2026, to reflect the entry into force of the Markets in Crypto-Assets Regulation (MiCAR). This guidance establishes binding investment limits, authorization requirements, and risk management standards for UCITS and AIFs investing in crypto-assets, fundamentally reshaping how Luxembourg-regulated collective investment schemes can engage with digital assets.
Key dates
February 4, 2026
- FAQ Version 7 effective date (entry into force of MiCAR alignment)
July 1, 2026 Deadline
- Deadline for Virtual Asset Service Providers (VASPs) to transition to CASP authorization or cease operations
No specific implementation grace period
- The FAQ does not specify a transition period for existing funds exceeding the 10% limit; firms should clarify this with the CSSF immediately
Suggested considerations
*Immediate Compliance Steps:
*Portfolio Audit: Conduct a comprehensive review of all UCITS and AIF holdings to identify current and potential crypto-asset exposures, both direct and indirect (including derivatives with crypto underlyings).
*Investment Policy Updates: Revise fund documentation, prospectuses, and investment policies to reflect the 10% NAV limits and MiCAR compliance requirements.
*Risk Management Assessment: Update risk management policies to address crypto-asset volatility, liquidity, and technological risks, with case-by-case impact assessments on fund risk profiles.
*Investor Notification: Ensure transparent and timely communication with investors regarding any crypto-asset investments or policy changes.
What changed
The most significant regulatory modifications in Version 7 include:
Investment Limits for UCITS
UCITS may invest indirectly in crypto-assets for a maximum of 10% of their net asset value (NAV). These indirect investments are limited to transferable securities that do not embed derivatives in accordance with Article 10 of the Grand-ducal Regulation of 8.
Investment Limits for AIFs
AIFs open to retail investors other than well-informed investors may invest in crypto-assets for a maximum of 10% of their NAV.
This regulatory update relates to the Luxembourg Law on alternative investment fund managers, which is relevant for investment management and wealth management firms operating in Luxembourg.
implementing Regulation (EU) 2024/2642 concerning restrictive measures in view of Russia’s destabilising activities
Why this matters
This regulation implements sanctions against Russia, which will impact banking, investment management, and wealth management firms that have exposure to Russia. Firms will need to comply with the new sanctions requirements, including reporting and disclosure obligations.
This regulatory update from the CSSF provides information on the processing times for initial authorisations of regulated investment vehicles, including UCITS funds, SIFs, and PIILs. This is relevant for asset managers and wealth managers seeking to obtain authorisation for new investment funds.
implementing Regulation (EU) 2024/2642 concerning restrictive measures in view of Russia’s destabilising activities
Why this matters
This regulation implements further restrictive measures against Russia, which will impact financial institutions across banking, investment management, and wealth management sectors.
Administrative sanction imposed on a registered alternative investment fund manager (“AIFM”)
AI Analysis
The CSSF imposed an administrative fine of EUR 10,000 on registered alternative investment fund manager (AIFM) C5 S.à r.l. on 11 September 2025 for failing to submit its annual financial crime questionnaire by the 4 April 2025 deadline, despite reminders, breaching the cooperation obligation under Article 5(1) of Luxembourg's AML/CFT Law of 12 November 2004. This enforcement action underscores the CSSF's strict enforcement of AML reporting duties and serves as a warning to supervised entities on the consequences of non-compliance with supervisory requests. It matters because it demonstrates the CSSF's willingness to publish names and impose fines for procedural lapses, potentially signaling increased scrutiny on AIFMs' AML/CFT obligations amid broader regulatory focus on financial crime risks.
Key dates
4 April 2025 Deadline
- Deadline for submission of the annual financial crime questionnaire covering the year ending 31 December 2024
11 September 2025
- Date CSSF imposed the EUR 10,000 administrative fine on the AIFM for non-submission
9 January 2026
- Publication date of the sanction decision
30 January 2026
- Publication of the queried sanction notice (noting minor title discrepancy possibly referencing a separate but analogous case).[user provided]
Suggested considerations
Immediate verification: Confirm timely submission of 2025 financial crime questionnaire (likely due April 2026 for 2025 data); review internal processes for CSSF reminders and automate alerts.
Procedural enhancements: Implement robust tracking systems for supervisory questionnaires, designate a responsible senior manager for AML cooperation, and document all responses or justifications for delays.
Training and testing: Conduct firm-wide training on AML/CFT Law Article 5(1) obligations; perform mock audits of reporting workflows, especially for registered AIFMs managing non-CSSF authorized funds.
Engagement protocol: Respond promptly to CSSF reminders; request in-person meetings if needed before fines escalate; review cooperation history to mitigate fine severity.
Policy updates: Align with CSSF Circular 25/894 for expanded AIFM reporting on unauthorized funds (notification within 10 working days for registered AIFMs).
What changed
This is not a regulatory change or new requirement but an enforcement precedent highlighting existing obligations under the AML/CFT Law:
Mandatory annual submission of the CSSF financial crime questionnaire by supervised entities, including registered AIFMs, as part of the cooperation duty in Article 5(1).
Fines determined per Article 8-4(1), (2)(f), and (3)(a), considering circumstances under Article 8-5(1), with publication assessed for proportionality under Article 8-6(1).
No new rules introduced;...
Compliance impact
Urgency: High – This sanction, though modest at EUR 10,000, exemplifies CSSF's proactive use of fines and public naming for AML reporting failures, with potential for higher penalties up to EUR 500,000 or 0.5% of turnover. It heightens risks for registered AIFMs amid CSSF's 2025-2026 priorities on financial crime, sanctions, and expanded reporting (e.g., Circular 25/894), where procedural lapses can trigger investigations, reputational damage, and barriers to remediation. Firms must prioritize to avoid escalation, especially post-publication on 30 January 2026.
This regulatory update from the CSSF introduces a new dedicated data entry form for investment firms to update their information, including changes to entity details, services, management, shareholders, and other key functions.
This is a warning about fraudulent activities misusing the name of a specific investment fund, which is relevant for investment managers and wealth managers who need to be aware of such scams to protect their clients.
This is an informational update on the members of the Consultative Committee for Prudential Regulation, which is relevant for banks, asset managers, and wealth managers from a prudential, operational resilience, and authorization perspective.
This regulatory update announces the updated list of members of the Consultative Committee for the Audit Profession, which is relevant for banking, investment management, and wealth management firms that are subject to audit requirements.
This regulatory update provides information on the list of members of the Board, which is relevant for banking, investment management, and wealth management firms that are subject to oversight by the CSSF.
This regulatory update provides information on the updated list of members of the Executive Board, which is relevant for banking, investment management, and wealth management firms that operate in Luxembourg and are subject to CSSF oversight.
This regulatory update from the CSSF (Luxembourg financial regulator) provides information about the public register of the audit profession, which is relevant for banking, investment management, and wealth management firms operating in Luxembourg.
This newsletter from the CSSF (Luxembourg financial regulator) covers a range of topics relevant to banking, investment management, and wealth management firms operating in Luxembourg. The low urgency reflects that this is an informational publication rather than a time-sensitive regulatory update.
This regulatory update relates to resolution reporting requirements, which is relevant for banking, investment management, and wealth management firms. The topics covered include reporting and disclosure, prudential/capital requirements, and operational resilience.
This regulatory update from the CSSF relates to a product intervention measure taken by the German regulator BaFin regarding turbo certificates. It impacts the marketing, distribution and sale of these products to retail clients in Germany, which is relevant for banking, investment management and capital markets firms...
This regulatory update on resolution reporting requirements is relevant for banking, investment management, and wealth management firms. It covers prudential and capital requirements, reporting and disclosure obligations, as well as operational resilience considerations.
This regulatory update from the CSSF deactivates certain validation rules and EBA small validation packages for COFREP reporting, which is relevant for banks, asset managers, and wealth managers in the banking and investment management sectors. The update is informational in nature, so the urgency is low.
The CSSF's January 2026 enforcement report documents the results of its 2025 examination campaign on 2024 financial and non-financial disclosures by issuers under Luxembourg's Transparency Law. This publication is critical for compliance professionals because it reveals systematic compliance gaps across financial reporting (IFRS), sustainability reporting (ESRS), and Alternative Performance Measures (APMs), with 27% of enforcement decisions resulting in injunctions for non-compliance.
Key dates
5 December 2024
- CSSF published enforcement priorities press release for FY2024 reporting
- CSSF published full results of fact-finding exercise on ESRS reporting
January 2026
- CSSF published enforcement results report (current publication)
Suggested considerations
*Financial Information (IFRS):
*Enhanced Note Disclosures: Provide sufficient disaggregation and additional information in financial statement notes for material amounts and variances, particularly where information is not presented on the face of primary statements. The CSSF emphasizes compliance with paragraph 112(c) of IAS 1.
*Cash Flow Statement Presentation: Ensure cash flows are presented on a gross basis (not net), exclude non-cash transactions, and disclose restricted cash balances with accompanying management commentary as required by paragraph 48 of IAS 7.
*Segment Reporting Completeness: Clearly disclose all income and expense items in segment reporting, even when not separately provided to or reviewed by the Chief Operating Decision Maker (CODM), if they are included in reported segment results.
*Going Concern Assessment: Maintain high transparency regarding accounting policies and judgments applied when classifying going concern assumptions.
What changed
The regulatory landscape has evolved significantly with the introduction of new sustainability reporting requirements:
ESRS Implementation (First Year): 2024 marked the first full reporting year under the European Sustainability Reporting Standards (ESRS), with the CSSF conducting a fact-finding exercise to assess...
Taxonomy Disclosures Amendment: On 4 July 2025, the European Commission adopted a Delegated Act amending the Taxonomy Disclosures as part of the Omnibus package, affecting Article 8 of the Taxonomy...
Double Materiality Assessment (DMA) Focus: The CSSF emphasized the importance of issuers not only disclosing the results of their DMA but also explaining the process itself, including granular...
relating to the fees to be levied by the Commission de Surveillance du Secteur Financier
Why this matters
This regulatory update relates to the fees levied by the Luxembourg financial regulator CSSF, which is relevant for banks, asset managers, and wealth managers operating in the Luxembourg financial sector.
amending Council Regulation (EU) No 833/2014 concerning restrictive measures in view of Russia’s actions destabilising the situation in Ukraine
Why this matters
This regulation amends existing sanctions against Russia related to the Ukraine conflict, which will impact financial firms across banking, investment management, and wealth management sectors. The changes require firms to update their compliance programs, reporting, and capital requirements.
This appears to be an informational update from the CSSF regarding the SSM Calendar Claude Wampach, which is likely relevant for banks, wealth managers, and asset managers operating in the banking and investment management sectors.
Circular CSSF 19/708 mandates the electronic transmission of specified documents to the CSSF via secure platforms like e-file or SOFiE, effective from February 1, 2019, replacing prior paper or other methods. This updated annex (as amended by Circular CSSF 21/790 and further revisions up to April 1, 2025) standardizes submissions for investment funds and related entities, reducing administrative burdens while ensuring document integrity and CSSF accessibility. Compliance professionals must monitor the dynamic annex list on the CSSF website to avoid nullified submissions.
Key dates
28 January 2019
Publication date; of original Circular CSSF 19/708
1 February 2019
Entry into force; Mandatory electronic transmission for listed documents; non-electronic submissions null and void
22 December 2021
Amendment; by Circular CSSF 21/790
1 April 2025
Latest annex update; noted
Ongoing Deadline
Regular checks required; Entities must monitor CSSF website for annex updates
Suggested considerations
Register/access e-file or SOFiE platforms if not already (test/production environments available since February 2019).
Consult and adhere to the latest Annex I for document list, nomenclatures, and formats (PDF with full functionality).
Ensure submissions are final/official versions matching hard copies; use specified identifiers for UCIs/SIFs/SICARs.
Implement processes for automatic/manual transmission (e.g., via updated sending services v4.9.0 or transmission module 6.6.0).
Train staff on responsibilities and integrate into reporting workflows; reference CSSF FAQs for closing documents.
What changed
- Mandatory Electronic-Only Submission: Documents listed in Annex I must be transmitted exclusively via e-file (http://www.e-file.lu) or SOFiE...
Dynamic Annex Updates: The annex, published on the CSSF website, is regularly updated (e.g., latest noted April 1, 2025) and includes prospectuses, management regulations, annual reports, risk...
Scope Expansion: Extends beyond UCIs to securitisation undertakings (2004 Law), pension funds (2005 Law), SICARs, and Luxembourg IFMs; repeals prior Circulars CSSF 09/423 and 08/371.
Filer Responsibilities: Entities ensure documents match official final hard copies, handle content/format accuracy, and check annex updates regularly.
Compliance impact
Urgency: Low (for new implementations post-2019; medium for ongoing monitoring). This matters for operational efficiency and CSSF relations, as non-compliance risks rejected filings, delays (e.g., approvals under SFDR processes), or supervisory scrutiny, but long-standing rule (since 2019) with established platforms reduces immediate pressure. Firms must prioritize annex vigilance to avoid disruptions in routine reporting like annual reports or prospectuses.
amending Delegated Regulation (EU) 2016/1675 to add Russia to the list of high-risk third countries with strategic deficiencies
Why this matters
This regulation amends the list of high-risk third countries, which has implications for AML/CFT compliance, prudential requirements, and authorization/licensing for firms operating in the banking, investment management, and wealth management sectors.
Administrative sanction imposed on the alternative investment fund manager Premium Capital Management (“AIFM”)
AI Analysis
The CSSF imposed a €10,000 administrative fine on 11 September 2025 against alternative investment fund manager (AIFM) Premium Capital Management for failing to submit its annual financial crime questionnaire by the 4 April 2025 deadline, breaching the cooperation obligation under Article 5(1) of Luxembourg's AML/CFT Law of 12 November 2004. This enforcement action underscores the CSSF's strict enforcement of AML reporting duties, signaling heightened scrutiny on timely supervisory cooperation amid ongoing AML risks in Luxembourg. Compliance teams should view this as a reminder of the low tolerance for even administrative lapses, with potential for escalated fines in repeat cases.
Key dates
31 December 2024
- Reference year-end for the financial crime Questionnaire
4 April 2025 Deadline
- Statutory deadline for Questionnaire submission to CSSF
11 September 2025
- Date CSSF imposed the €10,000 administrative fine after non-submission despite reminders
9 January 2026
- Publication date of the sanction decision
Suggested considerations
Immediately review internal processes for annual Questionnaire submission, ensuring calendar invites and automated reminders for the 4 April deadline (covering prior year-end data).
Conduct a gap analysis on AML/CFT cooperation obligations under Article 5(1), including response protocols to CSSF reminders or queries.
Update compliance calendars and train staff on escalation procedures; document all submissions with proof (e.g., timestamps, acknowledgments).
For AIFMs: Verify CSSF registration status under Article 3(2) of the 12 July 2013 AIFM Law and align with broader AML duties.
If late, proactively submit overdue items and request meetings if needed, as non-response forfeits mitigation opportunities.
What changed
This is not a regulatory change but an enforcement precedent under existing rules: non-compliance with Article 5(1) of the AML/CFT Law, which mandates annual submission of a financial crime questionnaire ("Questionnaire") to the CSSF. The fine was calculated per Articles 8-4(1), 8-4(2)(f), and 8-4(3)(a), considering circumstances under Article 8-5(1). Publication followed Article 8-6(1) after a proportionality assessment, confirming no market stability risks.
Compliance impact
Urgency: Medium – This €10,000 fine for a straightforward reporting failure demonstrates CSSF's willingness to penalize non-cooperation swiftly, even without aggravating factors, but the amount is modest and targeted at administrative breaches. It matters as a warning shot in Luxembourg's AML landscape, where repeated failures could trigger higher fines (up to proportionality limits under Article 8-5), reputational damage via public naming, or supervisory escalations; firms should audit 2025/2026 reporting now to preempt similar actions, especially post-NRA updates.
Administrative sanction imposed on the alternative investment fund manager Sunbricks GP S.à r.l. (“AIFM”)
AI Analysis
The CSSF imposed a **€10,000 administrative fine on Sunbricks GP S.à r.l.**, an alternative investment fund manager, for failing to submit a mandatory annual financial crime questionnaire by the April 4, 2025 deadline, despite two formal reminders. This enforcement action demonstrates the CSSF's strict approach to cooperation obligations under Luxembourg's anti-money laundering and counter-terrorist financing (AML/CFT) framework and signals that non-submission of required compliance documentation—even without evidence of underlying financial crime—triggers regulatory penalties.
Key dates
April 4, 2025 Deadline
– Annual financial crime questionnaire submission deadline (for year ending December 31, 2024)
Before September 11, 2025
– Two reminder notices issued by CSSF to Sunbricks GP
September 11, 2025
– Administrative fine decision date; questionnaire still not submitted
January 9, 2026
– Publication date of enforcement decision
Suggested considerations
regulated entities must:
*Establish Calendar Controls: Implement internal compliance calendars flagging the April 4 annual questionnaire submission deadline with sufficient lead time (minimum 4-6 weeks before deadline)
*Designate Responsible Parties: Assign clear ownership for questionnaire completion and submission, with backup contacts
*Prepare Documentation: Maintain contemporaneous records of financial crime controls, suspicious activity reporting, and compliance activities throughout the year to support accurate questionnaire responses
*Monitor Communications: Ensure all CSSF correspondence is tracked and escalated immediately; do not ignore reminder notices
What changed
This is not a regulatory change but rather an enforcement action clarifying existing obligations:
Mandatory Annual Questionnaire Requirement: All professionals supervised, authorized, or registered by the CSSF must submit an annual questionnaire on financial crime by April 4 each year, covering...
Cooperation Obligation: Article 5(1) of the amended Law of 12 November 2004 on AML/CFT establishes a non-negotiable duty to cooperate with the CSSF, which includes timely submission of requested...
Administrative Fine Framework: The CSSF applies Article 8-4 of the AML/CFT Law to impose fines for non-compliance, with amounts determined under Article 8-5 based on all relevant circumstances.
Administrative sanction imposed on the alternative investment fund manager Capitalis Premiere Group (“AIFM”)
AI Analysis
The CSSF imposed a €10,000 administrative fine on alternative investment fund manager (AIFM) Capitalis Premiere Group on 11 September 2025 for failing to submit its annual financial crime questionnaire by the 4 April 2025 deadline, despite two reminders, breaching the cooperation obligation under Article 5(1) of Luxembourg's AML/CFT Law of 12 November 2004. This enforcement action underscores the CSSF's strict enforcement of AML reporting duties, signaling heightened scrutiny on timely supervisory cooperation for Luxembourg-regulated entities. Compliance teams should note this as a low-value but public reminder of potential fines for administrative lapses in AML processes.
Key dates
4 April 2025 Deadline
- Deadline for submitting the annual financial crime questionnaire covering the year ending 31 December 2024
11 September 2025
- Date CSSF imposed the €10,000 administrative fine on Capitalis Premiere Group for non-submission
9 January 2026
- Date of CSSF publication of the sanction decision
Suggested considerations
Ensure timely submission of annual financial crime questionnaires by 4 April each year (for prior calendar year data); implement calendar reminders and escalation processes for CSSF requests.
Respond promptly to CSSF reminders or queries on AML/CFT compliance to avoid escalation to fines; document any delays with justification evidence.
Review internal AML cooperation protocols, including governance for questionnaire completion, and train staff on Article 5(1) obligations; consider requesting in-person meetings if disputing CSSF demands.
No retroactive actions needed for this case, but conduct gap analysis on reporting workflows to prevent similar breaches.
What changed
This is not a regulatory change or new requirement but an enforcement precedent under existing rules: non-compliance with the annual financial crime questionnaire submission, mandated by Article 5(1) of the AML/CFT Law, triggers fines per Articles 8-4(1), 8-4(2)(f), and 8-4(3)(a). The CSSF considered all relevant circumstances under Article 8-5(1) to set the €10,000 fine amount and published the sanction nominatively after proportionality assessment per Article 8-6(1), confirming no market stability risks.
Compliance impact
Urgency: Medium - This €10,000 fine is modest but publicly names the firm, amplifying reputational risk in Luxembourg's competitive fund domicile; it matters as a clear CSSF signal of zero tolerance for basic cooperation failures in AML, potentially foreshadowing stricter enforcement amid EU AML harmonization pressures. AIFMs face ongoing annual risk, with non-response despite reminders treated as willful breach; firms with weak reporting controls should prioritize fixes to avoid cumulative fines or escalations.
Administrative sanction imposed on the alternative investment fund manager Lion Management (“AIFM”)
AI Analysis
The CSSF imposed a €10,000 administrative fine on Lion Management, an alternative investment fund manager, on 11 September 2025 for failing to submit a mandatory annual financial crime questionnaire by the 4 April 2025 deadline. This enforcement action demonstrates the CSSF's commitment to enforcing cooperation obligations under Luxembourg's anti-money laundering and terrorist financing framework, with direct implications for all AIFMs regarding timely compliance with supervisory reporting requirements.
Key dates
4 April 2025 Deadline
- Deadline for submission of annual financial crime questionnaire for year ending 31 December 2024
11 September 2025
- Date CSSF imposed administrative fine after two reminders went unheeded
9 January 2026
- Publication date of the administrative sanction decision
Suggested considerations
*Establish Calendar Controls: Implement firm-wide systems to track the annual financial crime questionnaire deadline (typically 4 April for the prior calendar year)
*Designate Responsible Parties: Assign clear ownership for questionnaire completion and submission to the CSSF, with escalation procedures
*Monitor CSSF Communications: Establish protocols to immediately flag and respond to any CSSF correspondence, including reminders or requests for information
*Document Submission: Maintain evidence of timely submission (timestamps, confirmation receipts) to demonstrate compliance
*Escalate Non-Compliance Immediately: If submission cannot be met by deadline, proactively contact the CSSF to explain delays and request extensions rather than ignoring reminders
What changed
This is not a regulatory change but rather an enforcement action clarifying existing obligations. However, it reinforces critical compliance requirements:
Mandatory Annual Questionnaire Submission: All CSSF-supervised professionals, including AIFMs, must submit an annual questionnaire on financial crime by the specified deadline (in this case, 4 April...
Cooperation Obligation: Article 5(1) of the amended Law of 12 November 2004 on the fight against money laundering and terrorist financing establishes a non-negotiable obligation to cooperate with the...
Enforcement Escalation: The CSSF will issue reminders before imposing sanctions, but failure to respond to reminders results in administrative fines determined under Article 8-4 of the AML/CFT Law.
Administrative sanction imposed on the alternative investment fund manager Max Gain Capital S.à r.l. (“AIFM”)
AI Analysis
The CSSF imposed a €10,000 administrative fine on Max Gain Capital S.à r.l., an alternative investment fund manager, on 11 September 2025 for failing to submit a mandatory annual financial crime questionnaire by the April 2025 deadline. This enforcement action demonstrates the CSSF's active monitoring of AML/CFT compliance obligations and its willingness to sanction non-cooperation, even for procedural failures unrelated to substantive money laundering violations.
Key dates
4 April 2025 Deadline
- Deadline for submission of financial crime questionnaire for the year ending 31 December 2024
Before 11 September 2025 Deadline
- CSSF issued two reminders to Max Gain Capital after the missed deadline
11 September 2025
- CSSF imposed the €10,000 administrative fine
9 January 2026
- CSSF published the administrative sanction decision
Suggested considerations
regulated entities must:
*Identify Reporting Obligations: Confirm whether your firm is subject to the annual financial crime questionnaire requirement under Article 5(1) of the AML/CFT Law
*Calendar Management: Establish internal processes to ensure questionnaires are submitted by 4 April each year for the preceding calendar year
*Documentation: Maintain records demonstrating timely submission and preserve evidence of compliance
*Escalation Protocol: If unable to meet deadlines, proactively contact the CSSF to request extensions or clarification rather than ignoring reminders
What changed
This is not a regulatory change but rather an enforcement action clarifying existing obligations:
Mandatory Annual Questionnaire Requirement: All CSSF-supervised professionals must submit an annual questionnaire on financial crime covering the preceding calendar year.
Cooperation Obligation: Article 5(1) of the amended Law of 12 November 2004 on AML/CFT imposes a non-negotiable duty to cooperate with CSSF supervisory requests.
Enforcement Escalation: The CSSF will issue reminders before imposing sanctions, but continued non-compliance triggers administrative fines under Article 8-4 of the AML/CFT Law.
Administrative sanction imposed on the alternative investment fund manager Agriland Management S.A. (“AIFM”)
AI Analysis
The Commission de Surveillance du Secteur Financier (CSSF), Luxembourg's financial regulator, imposed a **EUR 10,000 administrative fine on Agriland Management S.A.**, an alternative investment fund manager, on 11 September 2025 for failing to submit a mandatory annual financial crime questionnaire by the April 2025 deadline. This enforcement action demonstrates the CSSF's commitment to enforcing cooperation obligations under Luxembourg's anti-money laundering and terrorist financing (AML/CFT) framework and signals heightened scrutiny of compliance with supervisory reporting requirements.
Key dates
4 April 2025 Deadline
– Deadline for submission of financial crime questionnaire for year ending 31 December 2024
Before 11 September 2025
– Two reminder notices issued by CSSF to Agriland Management S.A
11 September 2025
– Administrative fine imposed
9 January 2026
– Sanction published by CSSF
Suggested considerations
*Establish Reporting Calendars: Implement systems to track the 4 April annual deadline for financial crime questionnaire submissions
*Designate Responsible Personnel: Assign clear accountability for completing and submitting the questionnaire to the CSSF
*Respond to Regulatory Requests: Do not ignore CSSF reminders; engage proactively, including requesting in-person meetings if clarification is needed
*Document Justifications: If unable to meet deadlines, provide written evidence explaining the delay and proposed remediation timeline
*Monitor Supervisory Communications: Establish procedures to ensure regulatory correspondence is tracked and escalated appropriately
What changed
This is not a regulatory change but rather an enforcement action that clarifies existing obligations:
Mandatory Annual Reporting: All CSSF-supervised professionals must submit an annual questionnaire on financial crime by 4 April each year, covering the preceding calendar year.
Cooperation Obligation: Article 5(1) of the amended Law of 12 November 2004 on AML/CFT establishes a non-negotiable duty to cooperate with the CSSF, including timely submission of requested...
Enforcement Escalation: The CSSF will issue reminders for non-compliance, but continued failure to respond triggers administrative sanctions without requiring evidence of intentional misconduct.
Administrative sanction imposed on the alternative investment fund manager Bedrock I GP S.à r.l. (“AIFM”)
AI Analysis
The CSSF imposed a €10,000 administrative fine on alternative investment fund manager (AIFM) Bedrock I GP S.à r.l. on 11 September 2025 for failing to submit its annual financial crime questionnaire by the 4 April 2025 deadline, despite two reminders, breaching the cooperation obligation under Article 5(1) of Luxembourg's AML/CFT Law of 12 November 2004. This enforcement action underscores CSSF's strict enforcement of AML reporting duties and serves as a public warning to supervised entities on timely supervisory compliance. It matters because it demonstrates that even modest fines are pursued for basic reporting lapses, potentially signaling heightened scrutiny on AIFMs' AML processes amid ongoing regulatory focus on financial crime risks.
Key dates
31 December 2024 Deadline
- Reference period end for the Questionnaire covering financial crime compliance
4 April 2025 Deadline
- Statutory deadline for Questionnaire submission to CSSF
11 September 2025
- Date of administrative fine imposition (€10,000) after non-submission despite reminders
9 January 2026
- Publication date of the sanction decision by CSSF
Suggested considerations
Immediately verify submission status of the 2024 Questionnaire (or any outstanding); if overdue, submit promptly with justification to mitigate further escalation.
Implement automated calendar alerts and internal workflows for all CSSF reporting deadlines, including annual AML/CFT Questionnaire.
Conduct a compliance gap analysis on cooperation obligations under Article 5(1) AML/CFT Law, documenting reminder responses and evidence retention.
Train senior managers and compliance teams on supervisory interactions, including rights to request in-person meetings before fines.
Review governance for timely escalation of CSSF reminders to decision-makers.
What changed
This is not a regulatory change or new requirement but an enforcement of existing obligations under the amended Law of 12 November 2004 on the fight against money laundering and terrorist financing (AML/CFT Law). Specifically, it reaffirms the mandatory annual submission of the CSSF's financial crime questionnaire ("Questionnaire") by supervised professionals, including AIFMs under Article 3(2) of the Law of 12 July 2013 on AIFMs, as part of the cooperation duty in Article 5(1).
Compliance impact
Urgency: Medium - This is a post-facto enforcement on a past breach (2024 reporting cycle), with the €10,000 fine relatively low, indicating proportionality for a first-time or isolated lapse. It matters as a leading indicator of CSSF's 2025-2026 focus on AML cooperation, with multiple similar AIFM sanctions published simultaneously, risking escalated fines or reputational harm for repeat offenders; firms should prioritize reporting hygiene to avoid public naming, which CSSF deems non-disruptive to markets here.
Administrative sanction imposed on the alternative investment fund manager C5 Haven Cyber GP S.à r.l. (“AIFM”)
AI Analysis
The CSSF imposed a €10,000 administrative fine on alternative investment fund manager (AIFM) C5 Haven Cyber GP S.à r.l. on 11 September 2025 for failing to submit its annual financial crime questionnaire by the 4 April 2025 deadline, despite two reminders, breaching the cooperation obligation under Article 5(1) of Luxembourg's AML/CFT Law of 12 November 2004. This enforcement action underscores CSSF's strict enforcement of AML reporting duties and serves as a public warning to supervised entities on the consequences of non-cooperation. It matters because it demonstrates that even modest fines will be levied for procedural lapses, potentially signaling increased scrutiny on timely AML compliance submissions amid broader regulatory focus on financial crime risks.
Key dates
31 December 2024
- Reference year-end for the financial crime Questionnaire
4 April 2025 Deadline
- Statutory deadline for submitting the Questionnaire for the year ending 31 December 2024
11 September 2025
- Date CSSF imposed the €10,000 administrative fine after noting non-submission despite reminders
9 January 2026
- Date of CSSF publication of the sanction decision
Suggested considerations
Immediate Review: AIFMs and similar entities must verify their internal processes for annual Questionnaire submission, ensuring calendar reminders and automated tracking for 4 April deadlines.
Remediation if Late: Submit overdue Questionnaires promptly with explanations; request in-person meetings if needed, as the sanctioned AIFM failed to do so.
Process Enhancements: Implement escalation protocols for CSSF reminders, designate a senior compliance officer for oversight, and document all submissions/acknowledgments to demonstrate cooperation under Article 5(1).
Training: Conduct firm-wide training on AML/CFT cooperation duties, emphasizing that non-response leads to fines without need for justification.
What changed
This is not a regulatory change or new requirement but an enforcement of existing obligations under the amended AML/CFT Law:
Annual Questionnaire Submission: Supervised professionals, including AIFMs under Article 3(2) of the Law of 12 July 2013 on AIFMs, must submit an annual financial crime questionnaire...
Fine Provisions: Fines are imposed per Articles 8-4(1), 8-4(2)(f), and 8-4(3)(a), with amounts determined by relevant circumstances under Article 8-5(1); publication follows Article 8-6(1) after...
Compliance impact
Urgency: Medium - This is a low-value fine (€10,000) for a procedural breach, not involving substantive AML failures like suspicious transactions or sanctions screening delays seen in higher fines (e.g., €185,000 on Rakuten Bank). It matters as a precedent for CSSF's willingness to publicly name-and-shame for basic non-cooperation, potentially escalating to higher penalties for repeats; with publication on 9 January 2026, firms should prioritize 2025/2026 reporting to avoid similar exposure amid CSSF's active enforcement (3192+ sanctions published).
Administrative sanction imposed on the alternative investment fund manager C5 S.à r.l. (“AIFM”)
AI Analysis
The CSSF imposed a €10,000 administrative fine on alternative investment fund manager C5 Haven Cyber GP S.à r.l. on 11 September 2025 for failing to submit its annual financial crime questionnaire by the 4 April 2025 deadline, despite reminders, breaching the cooperation obligation under Article 5(1) of Luxembourg's AML/CFT Law of 12 November 2004. This enforcement action underscores CSSF's strict enforcement of reporting duties in AML/CFT compliance, serving as a warning to supervised entities on the consequences of administrative delays. It matters because it highlights low-tolerance for even minor procedural lapses, potentially signaling increased scrutiny on annual reporting amid broader AML/CFT priorities.
Key dates
4 April 2025 Deadline
- Deadline for submission of financial crime Questionnaire covering year ending 31 December 2024
11 September 2025
- Date CSSF imposed €10,000 administrative fine on C5 Haven Cyber GP S.à r.l. for non-submission despite reminders
9 January 2026
- Date of CSSF publication announcing the sanction
Suggested considerations
Review and confirm timely submission of all pending or future CSSF financial crime questionnaires; establish automated calendar reminders for annual deadlines (e.g., 4 April for prior year-end data).
Implement escalation protocols for CSSF reminders, ensuring immediate response and submission within days, not weeks.
Conduct internal audit of AML/CFT cooperation obligations, documenting justifications for any delays and preparing evidence for potential CSSF hearings or meetings.
Update compliance policies to prioritize Article 5(1) duties, including training for responsible persons on fine risks under Article 8-4.
For AIFMs: Verify alignment with Article 3(2) of AIFM Law and integrate questionnaire processes into governance frameworks.
What changed
This is not a regulatory change or new requirement but an enforcement of existing obligations under the amended AML/CFT Law:
Article 5(1) mandates supervised professionals, including AIFMs under Article 3(2) of the Law of 12 July 2013 on AIFMs, to cooperate fully with CSSF, including submitting the annual financial crime...
Breach occurred due to non-submission of the 2024 year-end Questionnaire, with fine determined per Articles 8-4(1), 8-4(2)(f), 8-4(3)(a), and 8-5(1).
Publication of the sanction follows Article 8-6(1), after proportionality assessment to avoid market stability risks.
No new rules introduced; reinforces ongoing duty to meet CSSF reporting timelines...
Compliance impact
Urgency: Medium - Matters due to CSSF's demonstrated willingness to impose and publicize fines for straightforward reporting failures, even at €10,000, which could escalate for repeat or severe cases; acts as a precedent amid rising AML/CFT enforcement (e.g., larger fines like €214,000 in similar contexts). Firms delaying submissions risk reputational damage from nominative publications under Article 8-6(1), market confidence erosion, and cumulative penalties; proactive remediation now prevents higher scrutiny in upcoming inspections.
Administrative sanction imposed on JTC (Luxembourg) S.A.
AI Analysis
The CSSF imposed a €102,000 administrative fine on JTC (Luxembourg) S.A. on 23 July 2025 for breaches in its professional obligations as a depositary of non-financial assets under the AIFM Law, identified during an on-site inspection from February 2023 to January 2024 covering activities up to December 2022. This enforcement action highlights CSSF's scrutiny of depositary functions, particularly risk assessment and oversight controls, serving as a warning for similar entities to strengthen compliance amid rising supervisory focus on AIFM depositaries.
Key dates
February 2023
January 2024; Period of CSSF on-site inspection on depositary obligations, covering activities up to December 2022
23 July 2025
Date CSSF imposed the €102,000 administrative fine on JTC (Luxembourg) S.A
9 January 2026
Date of official CSSF publication announcing the sanction
Suggested considerations
related entities) must:
Conduct immediate gap analyses on risk assessment processes for AIF strategies and AIFM organization per Article 92(1) CDR 231/2013.
Implement robust verification processes for AIFM compliance with asset delegation rules.
Ensure availability of key documentation and evidence of controls for the depositary function, addressing pre-2022 gaps if applicable.
Develop and test oversight processes, leveraging self-identified improvements and action plans as mitigating factors, as JTC did prior to inspection.
What changed
This is an enforcement action, not a regulatory change; it enforces existing requirements under Article 51(1) (1st and 7th indents) and Article 51(2) (1st sub-paragraph, 3rd indent) of the amended Law of 12 July 2013 on AIFMs (AIFM Law), and related provisions like Article 92(1) of Commission Delegated Regulation (EU) No 231/2013 (CDR 231/2013).
Compliance impact
Urgency: High – This matters due to the fine's size (€102,000), reflecting breach accumulation, severity, and duration, despite JTC's partial remediation; it signals intensified CSSF on-site scrutiny of depositary functions post-2023 inspections, with potential for higher penalties absent proactive controls. Depositaries face elevated enforcement risk, especially with unavailability of evidence pre-2022, urging swift remediation to avoid similar outcomes under Article 51 AIFM Law.
This regulatory update from the CSSF provides guidance for 'finfluencers' on responsible promotion, which is relevant for investment management firms, wealth managers, banks, and fintechs that engage in digital marketing and social media activities.
Update of Circular CSSF 24/853 on the Long Form Report (as amended by Circular CSSF 25/870) – Practical rules concerning the self-assessment questionnaire to be submitted by investment firms Mission and related reports of the réviseurs d’entreprises agréés (approved statutory auditors)
AI Analysis
Circular CSSF 26/904 updates Circular CSSF 24/853 (as amended by Circular CSSF 25/870) by introducing a revised Long Form Report (LFR) for investment firms, featuring a digital self-assessment questionnaire (SAQ) and enhanced auditor reports focused on AML/CFT and risk management. This matters because it aligns reporting with CSSF's risk-based supervision under CSSF 4.0, reduces redundancies, applies proportionality based on business models, and mandates digital submission to improve efficiency and data analysis.
Key dates
Financial year ending 31 December 2024
- Applicability of revised LFR to all investment firms; submissions begin for this period onward on a yearly basis
No specific submission deadline stated Deadline
- Yearly production required via CSSF portal; firms should align with existing annual reporting cycles for auditors (typically post-year-end)
Suggested considerations
Investment Firms: Complete and submit the digital SAQ yearly via CSSF portal, providing descriptions of business model, ML/FT risks, commercial policy, monitoring, AML/CFT roles, and entity-level compliance; ensure data on fund transfers (e.g., missing payer/payee info) is included.
REAs/Auditors: Verify SAQ adequacy, assess descriptions, perform corroborative controls, supplement with findings (e.g., AML/CFT audit declarations), independently assess ML/FT risks/organization, and integrate into single LFR document.
General: Review existing processes for proportionality (focus on incremental info); update AML/CFT policies/documentation for branches/subsidiaries/tied agents; prepare for digital submission; document risk assessments thoroughly.
Ongoing: Monitor compliance with related regs like Regulation (EU) 2023/1113 (effective 30 December 2024, per draft bill 8387).
What changed
- Revised LFR Structure: Comprises four parts in a single digital document: (1) yearly SAQ completed by investment firms; (2) descriptive elements verified by approved statutory auditors (REAs); (3)...
Digital Format: Completion and submission via CSSF's online portal, supporting CSSF 4.0 digital strategy for efficient processing.
Proportionality and Scope: Applies individually to investment firms (no consolidated LFR if under CSSF consolidated supervision); focuses on incremental, relevant information tied to business models,...
Enhanced AML/CFT Focus: Requires descriptions of commercial policy, ML/FT risk management, roles/responsibilities, branch/subsidiary/tied agent compliance; REA must assess adequacy of...
REA Responsibilities: Verify/ensure adequacy of SAQ elements, assess descriptions, perform control procedures, and provide assessments on AML/CFT policy implementation across entities.
Compliance impact
Urgency: High - Applies immediately to FY ending 31 December 2024 reports, requiring swift updates to reporting processes, digital tools, and AML/CFT documentation amid CSSF's risk-based shift; non-compliance risks supervisory actions, as LFR directly informs CSSF oversight on key prudential/AML areas with no transition period specified.
This press release provides an update on the global situation of undertakings for collective investment at the end of November 2025, which is relevant for investment management and wealth management firms.
Extract from the CSSF Newsletter No 300 – January 2026
Why this matters
This regulatory update from the CSSF provides monthly statistics and main figures regarding the Luxembourg financial centre, which is relevant for banking, investment management, and wealth management firms operating in the jurisdiction.
Update of Circular CSSF 24/850 on the practical rules concerning the descriptive report and the self-assessment questionnaire to be submitted on an annual basis by support PFS, as well as the engagement of the réviseurs d’entreprises agréés (approved statutory auditors) of support PFS and practical rules concerning…
AI Analysis
Circular CSSF 25/903 updates Circular CSSF 24/850, refining practical rules for support Professional of the Financial Sector (support PFS) in Luxembourg regarding their annual descriptive report, self-assessment questionnaire, and the roles of approved statutory auditors (réviseurs d’entreprises agréés). It specifies requirements for auditors' engagement, management letters, and separate annual reports. This matters for support PFS as it enhances supervisory oversight, ensures consistent reporting quality, and strengthens internal controls, directly impacting compliance and audit processes amid CSSF's focus on robust PFS supervision.
Key dates
30 April (annually) Deadline
Submission Deadline; Support PFS must submit descriptive report, self-assessment questionnaire, management letter, and separate auditor report to CSSF by 30 April following the financial year-end (first applicable: 30 April 2026 for FY 2025)
31 December 2025 Deadline
Preparation Milestone; Auditors must be engaged and initial scoping completed by year-end 2025 for FY 2025 compliance
1 January 2026
Effective Date; Applies to annual reporting cycles starting for financial year 2025 onwards
Suggested considerations
*Review and Update Processes: Support PFS must map current reporting against new templates in CSSF 25/903 and revise internal procedures for descriptive reports and self-assessments.
*Engage/Confirm Auditors: Select or confirm approved statutory auditors compliant with new engagement rules; execute updated engagement letters incorporating circular requirements by Q4 2025.
*Implement Templates and Testing: Adopt CSSF-provided templates for reports, management letters, and separate reports; conduct sample-based testing of controls as specified.
*Training and Governance: Train compliance/audit teams on changes; ensure board approval of self-assessments and auditor findings.
*Submit on Time: Prepare and file all documents by 30 April deadlines, retaining evidence for CSSF inspections.
What changed
- Updates to Descriptive Report and Self-Assessment Questionnaire: Refines content, format, and submission requirements for support PFS's annual submissions, emphasizing more detailed disclosures on...
Auditor Engagement Rules: Introduces specific practical guidelines for approved statutory auditors, including mandatory scope of work, independence confirmations, and standardized procedures for...
Management Letter and Separate Report: Establishes detailed rules for auditors to issue an annual management letter (addressing findings, recommendations, and remediation) and a separate report for...
Enhanced Documentation and Evidence: Requires support PFS and auditors to provide verifiable evidence (e.g., checklists, testing samples) supporting self-assessments, with stricter CSSF validation...
Compliance impact
Urgency: High. This is high urgency for support PFS due to the impending 30 April 2026 deadline for FY 2025 submissions, with non-compliance risking supervisory fines, license reviews, or reputational damage under CSSF's PFS enforcement regime. It matters as it tightens audit accountability, potentially increasing costs (e.g., auditor fees) while reducing reporting errors—critical for smaller support entities with limited resources.
Practical rules concerning the descriptive report and the self-assessment questionnaire to be submitted on an annual basis by support PFS.Engagement of the réviseurs d’entreprises agréés (approved statutory auditors) of support PFS and practical rules concerning the management letter and the separate report to be…
AI Analysis
Circular CSSF 24/850, as amended by Circular CSSF 25/903, establishes practical rules for support Professional of the Financial Sector (support PFS) in Luxembourg to submit annual descriptive reports and self-assessment questionnaires, while also defining the roles of approved statutory auditors (réviseurs d’entreprises agréés) in issuing management letters and separate reports. This guidance standardizes supervisory reporting and audit processes to enhance oversight of support PFS, which provide essential back-office services to authorized PFS. It matters because non-compliance risks supervisory sanctions, reputational damage, and operational disruptions for entities reliant on support PFS structures.
Key dates
1 January 2025
- Effective date of original Circular CSSF 24/850
15 December 2025
- Effective date of amendments in Circular CSSF 25/903, applicable to 2025 reporting cycle onwards
31 March annually Deadline
- Deadline for submission of descriptive report, self-assessment questionnaire, management letter, and separate auditor report to CSSF (first applicable for FY 2024 reporting due 31 March 2025)
End of February annually Deadline
- Support PFS must engage auditors and provide necessary data to enable timely report preparation
Suggested considerations
Annual Reporting Cycle:
1. By year-end, conduct internal self-assessment using the prescribed questionnaire template (available via CSSF portal).
February to review submissions, test controls, and issue management letter (flagging deficiencies) plus separate compliance report.
Governance Updates: Review and update internal policies on risk assessment, auditor selection, and remediation of management letter findings; ensure board oversight of submissions.
Auditor Coordination: Verify auditor qualifications per CSSF register; implement any remediation plans from prior-year management letters before next cycle.
Record-Keeping: Maintain 5-year audit trail of all supporting documentation for CSSF inspections.
What changed
- Standardized Reporting Templates: Introduces detailed formats and content requirements for the annual descriptive report and self-assessment questionnaire, covering governance, risk management,...
Auditor Engagement Rules: Mandates approved statutory auditors to perform specific procedures, issue a management letter highlighting control weaknesses, and prepare a separate report confirming...
Amendments via CSSF 25/903: Updates clarify submission procedures, expand self-assessment criteria (e.g., adding cybersecurity and outsourcing risk questions), and refine auditor independence...
Frequency and Scope: Annual submissions required without exceptions; scope limited to support PFS (not primary PFS), emphasizing substance over form in service descriptions.
Compliance impact
Urgency: High – This is a recurring annual obligation with a firm 31 March deadline, where delays trigger automatic CSSF notifications and potential fines (up to €250,000 per Law 1993). It matters for support PFS as it intensifies scrutiny on operational resilience in a post-SFI (2021) landscape, where CSSF prioritizes substance in delegated functions; failure risks de-authorization or client outflows. Early implementation of templates and auditor pipelines is essential to avoid first-year pitfalls.
Press release 25/21(published on 22 December 2025, updated on 31 December 2025)
Why this matters
This regulatory update is about the dissolution and judicial liquidation of ALFA ASSET MANAGEMENT (EUROPE) S.A., an investment management and wealth management firm. It involves topics related to authorization and licensing as well as prudential and capital requirements.
This regulatory update relates to the profit and loss account of credit institutions, which is relevant for banking and investment management firms. The topics of prudential/capital requirements and reporting/disclosure are also applicable. The update is informational in nature, so the urgency is low.
relating to specialised investment funds, investment companies in risk capital and undertakings for collective investment subject to Part II of the Law of 17 December 2010
AI Analysis
Circular CSSF 25/901 consolidates and modernizes the supervisory framework for Luxembourg specialised investment funds (SIFs), investment companies in risk capital (SICARs), and undertakings for collective investment subject to Part II of the Law of 17 December 2010 (Part II UCIs), including their sub-funds. It streamlines investment rules, diversification limits, borrowing, disclosures, and risk management while enhancing flexibility for sophisticated investors and formalizing prior informal guidance, reducing regulatory complexity without compromising investor protection.
Suggested considerations
Review and update fund documents (e.g., sales documents, instruments of incorporation) to include mandated disclosures on investment strategy/limits, risks, UCIs/vehicles, borrowing, liquidity tools, and retail-specific warnings.
Assess and document compliance with new/relaxed diversification, borrowing, and SICAR investment rules; apply for CSSF derogations where justified.
Ensure risk-spreading in derivatives/collateral and deployment of SICAR cash into eligible assets; confirm look-through for intermediaries.
For retail-marketed funds: Limit investments/UCIs to 25%, cap borrowing at 70%, add prominent risk warnings for illiquids/long-duration.
Maintain robust governance/documentation to leverage flexibility; reference CSSF's Compilation for concepts.
What changed
- Diversification and investment limits: Introduces tailored percentage-based thresholds; for funds marketed to unsophisticated retail investors, limits remain at 25% per issuer/UCI/asset, raised to...
SICAR-specific rules: Confirms risk capital investments (e.g., equity, mezzanine) must align with development objectives, exceed mere market risk, and deploy incoming cash into eligible assets;...
Borrowing: For retail-exposed SIFs/Part II UCIs, investment borrowing capped at 70% of assets/commitments; no hard cap for sophisticated investor funds if disclosed, with SICARs limited to risk...
Derivatives and techniques: Permits use if economically appropriate (e.g., risk/cost reduction), with risk-spreading via diversified underlyings/collateral; counterparty risk limited if...
Urgency: High – Formalizes prior informal guidance into binding rules with enhanced flexibility but stricter retail protections and disclosure mandates, requiring immediate document reviews/updates for non-compliant SIFs/SICARs/Part II UCIs to avoid supervisory scrutiny or authorization issues; critical for funds targeting private markets or retail.
Revision and remodelling of the rules to which Luxembourg undertakings governed by the Law of 30 March 1988 on undertakings for collective investment (“UCI”) are subject
AI Analysis
Circular IML 91/75, as amended up to CSSF Circular 25/901, consolidates and modernizes the supervisory framework for Luxembourg Part II UCIs, SIFs, and SICARs, refining rules on diversification, borrowing, risk-spreading, and disclosures while tailoring requirements to investor profiles. It matters because it streamlines fragmented regulations, enhances fund competitiveness, and formalizes CSSF expectations without mandating immediate changes for pre-existing funds, reducing compliance burdens while promoting transparency and flexibility. This update aligns administrative practices with market realities, repealing outdated circulars to eliminate ambiguity.
Suggested considerations
Review and update offering documents/prospectuses for enhanced transparency on risks, limits, borrowing, liquidity tools (e.g., gates, notice periods), redemption processes, and investor-specific warnings.
Align fund documentation/terminology with CSSF Compilation of key concepts for consistency in filings and communications.
Disclose ramp-up/wind-down periods, potential derogations, and life extensions clearly; seek CSSF approval for exemptions where justified.
For SICARs: Ensure risk capital investments meet modernized criteria; apply look-through for limits.
Assess portfolio compliance for new funds/compartments; leverage flexibility for sophisticated investors but maintain robust governance.
What changed
- Consolidation and Repeals: Repeals CSSF Circulars 02/80, 07/309, 06/241, and Chapters G and I of IML 91/75; renders CSSF 08/356 and Chapter H of IML 91/75 inapplicable to Part II UCIs.
Flexible Diversification Rules: Introduces investor-category-based thresholds (e.g., stricter for retail, looser for sophisticated investors); allows CSSF derogations for SIFs/Part II UCIs with...
Borrowing Limits: New limits for SIFs/Part II UCIs (e.g., 70% of net assets, excluding temporary borrowings tied to commitments); tailored by investor type.
Enhanced Disclosures: Offering documents must detail investment policies, risks (especially private equity for retail), subscription/redemption processes, liquidity tools, gates, and amendment...
SICAR Risk Capital: Modernizes definition to include equity, loans, bonds, mezzanine; clarifies direct/indirect investments with three cumulative elements (risk of total loss, no redemption rights,...
Compliance impact
Urgency: Medium – Not critical as existing funds are grandfathered with no retroactive changes required, but high relevance for new launches or material updates post-19 Dec 2025. It matters for operational efficiency (streamlined rules reduce fragmentation) and investor protection (tailored risks/disclosures), potentially lowering long-term costs while mitigating supervisory scrutiny; failure to update docs could delay approvals or trigger CSSF queries.
Rules applicable to undertakings for collective investment when they employ certain techniques and instruments relating to transferable securities and money market instruments
AI Analysis
Circular CSSF 08/356, as amended by Circular CSSF 25/901, establishes detailed rules for Luxembourg undertakings for collective investment (UCIs), including UCITS and alternative investment funds (AIFs), on the use of techniques and instruments relating to transferable securities and money market instruments, such as securities lending, repo transactions, and over-the-counter (OTC) derivatives. It matters because it ensures investor protection, risk management, and market stability by imposing strict eligibility, collateral, and operational requirements, aligning Luxembourg funds with EU standards under UCITS and AIFMD directives. Compliance is critical for Luxembourg-domiciled funds engaging in these activities to avoid regulatory sanctions and operational disruptions.
Key dates
23 December 2008
- Original Circular CSSF 08/356 effective date for UCITS III implementation
21 July 2011
- Partial updates for UCITS IV alignment
22 July 2013
- Extension to AIFs under AIFMD transposition
15 October 2025
- Issuance of amending Circular CSSF 25/901
01 January 2026
- Effective date for amendments (e.g., new collateral rules, reporting formats)
Suggested considerations
*Policy Review & Update: Revise fund prospectuses, KIIDs, and risk management policies to reflect amended limits (e.g., counterparty caps, ESG collateral) within 3 months of 01 January 2026.
*Risk Management Systems: Implement or upgrade systems for daily collateral valuation, stress testing, and exposure monitoring; conduct gap analysis against Section 4 requirements.
*Counterparty Due Diligence: Reassess OTC counterparties for eligibility (e.g., EMIR clearing thresholds); negotiate ISDA/CSA agreements with updated haircuts.
*Operational Setup: Appoint triparty agents where required; ensure collateral segregation complies with Section 5.
*Reporting & Disclosure: Prepare for new quarterly CSSF filings (template in Annex 1); disclose revenues/reinvestments from techniques in annual reports (Article 14 UCITS Law).
What changed
The original Circular CSSF 08/356 (2008) transposed UCITS III requirements on eligible techniques like securities lending and repos.
Expanded collateral rules: Collateral must now include sustainable assets meeting SFDR criteria, with daily marking-to-market and haircuts adjusted for liquidity and credit risk (Section 3).
Counterparty exposure limits: Net exposure to a single OTC counterparty capped at 10% of net asset value (NAV), down from previous thresholds in some cases, with mandatory collateralization (Section...
Operational safeguards: Mandatory use of triparty agents for repos, enhanced segregation of collateral, and annual stress testing disclosures (Section 5, as amended).
Reporting enhancements: Quarterly reports to CSSF on transaction volumes, risks, and revenues from these activities (Annex 1, updated).
These align with ESMA guidelines (e.g., ESMA/2012/832 on OTC...
Compliance impact
Urgency: High - Immediate relevance for funds actively using these techniques (common in fixed-income and equity strategies for yield enhancement). Non-compliance risks CSSF fines (up to 5% of NAV), temporary prohibitions on techniques, or fund suspension. With the 01 January 2026 effective date recently passed (as of current context), firms face heightened scrutiny in 2026 reporting cycles; proactive remediation avoids enforcement actions amid CSSF's focus on operational resilience.
amending Circular CSSF 22/811.Authorisation and organisation of entities acting as UCI administrators.
AI Analysis
Circular CSSF 25/900, issued on 16 December 2025, amends Circular CSSF 22/811 to clarify governance principles, authorisation requirements, and operational standards for UCI (Undertakings for Collective Investment) administrators in Luxembourg, while reforming annual reporting obligations. It matters because it strengthens supervisory oversight, aligns with DORA for ICT outsourcing, and simplifies reporting to enhance efficiency and compliance in the fund administration sector.
Key dates
January 2025
- DORA entry into force, applying to ICT outsourcing for in-scope UCIAs
16 December 2025
- Issuance date; repeal of Annex B of Circular CSSF 22/811 effective immediately
31 December 2025
- New reporting framework (SAQ and updated modalities) applies to all financial years ending on or after this date
Suggested considerations
Assess eligibility and obtain prior CSSF authorisation via Annex A application (or notify substantial changes); ensure ongoing validity by monitoring operational model and delegations.
Adapt internal processes for revised annual UCIA reporting (SAQ-focused, integrated where applicable); submit using CSSF website instructions starting for FY ending 31 Dec 2025.
Review/update contracts with UCIs/IFMs to define roles, responsibilities, and oversight; implement delegation monitoring, remediation plans, and ICT compliance (DORA/Circular 25/882 or 20/750).
For DORA-scope entities, align outsourcing arrangements with Circular CSSF 25/882.
What changed
- Repeals Annex B of Circular CSSF 22/811 with immediate effect, replacing it with streamlined annual reporting via a core compliance-focused Self-Assessment Questionnaire (SAQ) that assesses...
Introduces prior CSSF authorisation requirements for entities acting as UCI administrators, including a defined administrative procedure with application details in Annex A; authorisation remains...
Clarifies scope for eligible entities (e.g., UCIs, IFMs, management companies under Luxembourg law) performing one or more of three UCI administration functions (defined in point 10); mandates...
Aligns ICT outsourcing with DORA (effective January 2025) for in-scope UCIAs (credit institutions, investment fund managers, investment firms, certain support professionals), referencing Circular...
Strengthens delegation rules (section 3.5): prior CSSF notification for critical/important tasks, ongoing monitoring by UCI/IFM, and remediation plans for shortcomings.
Compliance impact
Urgency: High - Immediate repeal of prior reporting Annex requires prompt process updates; new framework applies to FY 2025 year-ends (just past as of Jan 2026), risking supervisory scrutiny or penalties for non-compliance; DORA alignment adds operational resilience pressure amid ongoing CSSF focus on fund admin governance.
Authorisation and organisation of entities acting as UCI administrators
AI Analysis
Circular CSSF 22/811, as amended by Circular CSSF 25/900, establishes CSSF requirements for the authorisation, governance, internal organisation, and oversight of entities acting as UCI (Undertakings for Collective Investment) administrators in Luxembourg. It matters because it standardises practices amid regulatory, technological, and market evolutions, ensuring robust controls, risk management, and supervision for fund administration activities critical to Luxembourg's fund industry.
Suggested considerations
Submit authorisation application to CSSF with Annex A information before commencing UCI administration; notify substantial changes and keep file updated.
Establish/implement governance, controls, escalation processes, resource adequacy, ICT/business continuity per circular; ensure single provider per function.
For delegations: Conduct due diligence, execute written contracts detailing roles/obligations, notify CSSF in advance, retain oversight without delegating monitoring.
Conclude written contracts with UCI/IFM; submit annual UCIA activity reports.
UCIs/IFMs: Supervise coordinators, ensure information exchange/cooperation with administrators.
What changed
- Authorisation Requirements: Prior CSSF authorisation is mandatory for appointment as UCI administrator, via full application under sectoral laws or a simplified administrative procedure;...
Scope of UCI Administration: Defines three core functions—registrar, NAV calculation/accounting, and client communication—requiring only one designated service provider per function per UCI (or...
Governance and Controls: Mandates sound governance principles, control frameworks, escalation processes for errors/incidents, adequate resources (human, ICT), business continuity, and compliance with...
Delegation Rules: Delegation of tasks allowed but not of monitoring/oversight; requires written contracts, due diligence, and prior CSSF notification (3 months generally, 1 month for certain agents);...
Contracts and Reporting: Written contracts between UCI administrator and UCI/IFM; annual activity reporting due 5 months after financial year-end, starting from financial years ending post-30 June...
Compliance impact
Urgency: High – Non-compliance risks CSSF sanctions, as authorisation is prior and ongoing; critical for Luxembourg fund ecosystem given evolutions in tech/markets/DORA. Firms must act promptly if unauthorised or misaligned, especially with annual reporting since 2023 and DORA integration; impacts operational models, delegations, and reporting immediately for active administrators.
This regulatory update from the CSSF provides information on the global situation of undertakings for collective investment at the end of October 2025, which is relevant for investment management and wealth management firms.
This regulatory update discusses a supply-chain attack targeting NPM packages, which could impact firms across the financial services sector. It is relevant for banks, fintechs, and all firms that rely on third-party software and services.
Long Form ReportPractical rules concerning the self-assessment questionnaire to be submitted by institutionsMission and related reports of the statutory auditors (réviseurs d’entreprises agréés)
AI Analysis
**Circular CSSF 22/821** (as amended) fundamentally restructures how Luxembourg credit institutions report to the Commission de Surveillance du Secteur Financier (CSSF) by replacing the traditional Long Form Report with a digital **self-assessment questionnaire (SAQ)**, complemented by auditor-prepared reports. This shift represents a significant operational change that requires institutions to directly participate in prudential self-assessment while maintaining robust external audit oversight, making it essential for compliance and operational teams to understand new submission requirements and digital workflows.
Key dates
25 October 2022
- Circular CSSF 22/821 issued
23 December 2022
- Initial publication date (updated 15 November 2023)
31 December 2022
- Circular enters into application
Three months before financial year closure
- SAQ becomes accessible through CSSF digital solution
Three months after financial year closure Deadline
- Deadline for SAQ submission to CSSF
Suggested considerations
*For Credit Institutions:
*Establish SAQ Governance: Designate authorized management responsible for reviewing and electronically signing the SAQ before submission; ensure accuracy and true-and-fair representation of information
*Data Preparation: Align SAQ responses with prudential reporting figures (FINREP/COREP/LAREX) under IFRS as of financial year closure
*Digital System Access: Obtain access credentials to the CSSF digital solution and familiarize compliance teams with the platform interface and submission workflow
*Module Completion: Complete all applicable SAQ modules as configured in the CSSF digital solution; note that module applicability and exemptions are institution-specific and recorded directly in the system
What changed
The circular introduces a three-component reporting framework that fundamentally alters the compliance landscape:
Self-Assessment Questionnaire (SAQ): A digital, annually-completed questionnaire that institutions must prepare directly, covering domains within CSSF and ECB prudential supervision competence
Agreed Upon Procedures (AUP) Reports: Reports prepared by approved statutory auditors (réviseurs d'entreprises agréés) on specific compliance areas
Separate REA Report on Financial Instruments Protection: A dedicated auditor assessment on safeguarding of client financial instruments
Scope of SAQ Coverage: The questionnaire addresses prudential...
Update of Circular CSSF 07/325 on Provisions relating to credit institutions and investment firms of EU origin established in Luxembourg by way of branches or exercising activities in Luxembourg by way of free provision of services, as amended by Circulars CSSF 21/765 and CSSF 22/827
AI Analysis
Circular CSSF 25/898 updates Luxembourg's supervisory framework for EU-origin credit institutions and investment firms operating in Luxembourg through branches or free provision of services. This amendment enhances the self-assessment questionnaire (SAQ) used by the CSSF to align supervisory oversight with current regulatory priorities, particularly adding UCI administration as a new thematic module. The update reflects the CSSF's evolving supervisory focus and requires affected institutions to demonstrate compliance with expanded assessment criteria.
Key dates
31 October 2025
- Circular CSSF 25/898 published by the CSSF
19 December 2025
- Related modernization framework (Circular CSSF 25/901) entered into force for Part II UCIs, SIFs, and SICARs
No specific implementation deadline stated Deadline
- Institutions should align their SAQ responses and compliance documentation with the updated framework immediately upon publication
Suggested considerations
*Update Self-Assessment Processes
Revise internal SAQ completion procedures to address the new UCI administration module
Ensure all thematic modules reflect current supervisory expectations
*Assess UCI Administration Compliance
If the institution provides or is involved in UCI administration services, conduct a detailed assessment of compliance with CSSF expectations
What changed
The circular introduces the following material modifications to Circular CSSF 07/325:
New Supervisory Module
UCI administration has been added as a thematic module to the self-assessment questionnaire, reflecting increased regulatory attention to fund administration practices.
Enhanced Self-Assessment...
Existing modules have been updated to better align with supervisory objectives and current regulatory priorities.
The revised SAQ now captures a broader range of supervisory points of focus relevant to branch operations and cross-border service provision.
Scope Clarification
The circular applies to credit institutions whose head office is in another EU Member State and to investment firms of EU origin established in Luxembourg by way of branches or exercising activities...
This press release provides an update on the global situation of undertakings for collective investment at the end of September 2025, which is relevant for investment management and wealth management firms.
This press release from the CSSF provides an update on the global situation of undertakings for collective investment at the end of August 2025, which is relevant for investment management and wealth management firms.
This regulatory update relates to the profit and loss account of credit institutions, which is relevant for banking and investment management firms. The topics of prudential/capital requirements and reporting/disclosure are also applicable. The update is informational in nature, so the urgency is low.
This press release from the CSSF provides an update on the global situation of undertakings for collective investment at the end of July 2025, which is relevant for investment management and wealth management firms.
This press release from the CSSF appears to be related to regulatory oversight and authorization for BGL BNP Paribas, a bank operating in the banking, investment management, and wealth management sectors.
This regulatory update from the CSSF provides information on the global situation of undertakings for collective investment at the end of June 2025, which is relevant for investment management and wealth management firms.
This press release from the CSSF provides an update on the global situation of undertakings for collective investment at the end of May 2025, which is relevant for investment management and wealth management firms.
This regulatory update relates to the profit and loss account of credit institutions, which is relevant for banking and investment management firms. The topics of prudential/capital requirements and reporting/disclosure are also applicable. The update is informational in nature, so the urgency is low.
This press release from the CSSF provides an update on the global situation of undertakings for collective investment at the end of April 2025, which is relevant for investment management and wealth management firms.
This regulatory update from the CSSF in Luxembourg focuses on the use of artificial intelligence in the financial sector, which impacts banking, investment management, and wealth management firms.
This regulatory update provides information on the global situation of undertakings for collective investment at the end of March 2025, which is relevant for investment management and wealth management firms.
This regulatory update relates to the mandate and audit charter for the Internal Auditors Committee of the Eurosystem/ESCB and the Single Supervisory Mechanism. It is relevant for banks, asset managers, and wealth managers as it covers prudential requirements, operational resilience, and reporting obligations.
This press release from the CSSF provides an update on the global situation of undertakings for collective investment at the end of February 2025, which is relevant for investment management and wealth management firms.
This regulatory update relates to the profit and loss account of credit institutions, which is relevant for banking, investment management, and wealth management firms. The topics covered include prudential requirements, reporting, and licensing, which are important for these sectors.
This regulatory update relates to the takeover of Iris Financial S.A. by Younited Financial S.A., which are firms operating in the banking, investment management, and wealth management sectors. The key topics covered include authorization and licensing, prudential/capital requirements, and consumer protection.
This regulatory update relates to the application form for third country auditors and audit entities, which is relevant for banking, investment management, and wealth management firms that may need to engage such auditors.
This appears to be a general news update from the CSSF regulator, likely containing information relevant to multiple financial sectors and firm types. The lack of detailed content description suggests this is a low urgency, informational update.
This is an informational announcement about a public register of the audit profession maintained by CSSF (Luxembourg financial regulator). The content primarily concerns regulatory registration and licensing matters for audit firms.