2018-08-23
Added · Updated
This circular replaces Circular CSSF 12/546 to specify the conditions for obtaining and maintaining authorization for investment fund managers (IFMs), including management companies, SIAGs, and FIAAGs. It establishes requirements for shareholding structures, minimum own funds, administrative bodies, senior management, and internal governance arrangements. The document also sets out rules for the permanent risk management, compliance, and internal audit functions, as well as specific provisions on the fight against money laundering and terrorist financing. Circulars CSSF 04/155 and IML 98/143 are no longer applicable to IFMs.
CSSF published 3 documents in the last 30 days — get each new one by email the day it lands.
In case of discrepancies between the French and the English text, the French text shall prevail. Luxembourg, 23 August 2018 To all investment fund managers and entities carrying out the activity of registrar agent CIRCULAR CSSF 18/698 Re: Authorisation and organisation of investment fund managers incorporated under Luxembourg law Specific provisions on the fight against money laundering and terrorist financing applicable to investment fund managers and entities carrying out the activity of registrar agent Ladies and Gentlemen, This circular applies to investment fund managers incorporated under Luxembourg law (hereinafter “IFMs”). IFMs comprise the following:
Circular CSSF 18/698 Page 2/96
This circular does not apply to IFMs referred to in Chapter 18 of the 2010 Law. The entities referred to in Article 3 of the 2013 Law and which are not included in the above definition of IFMs are also excluded from the scope of application of this circular. Circular CSSF 12/546, as amended, was applicable to management companies incorporated under Luxembourg law and subject to Chapter 15 of the 2010 Law as well as to SIAGs. The purpose of this circular is to replace Circular CSSF 12/546, as amended, in order to take into account the legislative developments regarding alternative investment funds and to specify in a single circular the conditions for obtaining and maintaining the authorisation for all IFMs as defined above. It also applies to branches and representative offices which an IFM has established in Luxembourg and/or abroad. As regards the activity of registrar agent, credit institutions, investment firms, professionals of the financial sector and IFMs incorporated under Luxembourg law as well as Luxembourg branches of foreign institutions must refer to Sub-chapter 5.4. Organisation of the fight against money laundering and terrorist financing, and in particular point 304. The purpose of the circular is to provide additional clarifications on certain conditions for authorisation, more particularly the shareholding structure, the minimum own funds requirements, the administrative bodies, the arrangements concerning the central administration and governance and the rules governing the delegation framework. Furthermore, the circular includes rules, with reference to CSSF Regulation N° 10-04 and Delegated Regulation (EU) 231/2013, regulating the compliance and internal audit functions as specified in Circulars CSSF 04/155 and IML 98/143. Consequently, Circulars CSSF 04/155 and IML 98/143 are no longer applicable to IFMs. Yours faithfully, COMMISSION de SURVEILLANCE du SECTEUR FINANCIER Jean-Pierre FABER Simone DELCOURT Claude MARX Director General
Circular CSSF 18/698 Page 3/96
TABLE OF CONTENTS
Part I. Definitions and abbreviations.............................................................................................. 8
Part II. Conditions for obtaining and maintaining the authorisation of an authorised
investment fund manager (IFM) who engages solely in the activity of management of UCIs as
laid down in Article 101(2) of the 2010 Law and Article 5(2) of the 2013 Law......................... 11
Chapter 1. Basic principles ............................................................................................................ 11
Chapter 2. Shareholding ............................................................................................................... 11
Sub-chapter 2.1. Initial authorisation....................................................................................... 11
Sub-chapter 2.2. Changes in the shareholding......................................................................... 13
Chapter 3. Own funds..................................................................................................................... 13
Sub-chapter 3.1. Required own funds....................................................................................... 13
Sub-chapter 3.2. Eligible capital................................................................................................ 15
Sub-chapter 3.3. Use of own funds............................................................................................ 15
Chapter 4. The bodies of the IFM ................................................................................................. 17
Sub-chapter 4.1. The members of the governing body or management body....................... 17
Section 4.1.1. Required number........................................................................................................17
Section 4.1.2. Requirements regarding the skills, experience and good repute and the composition of
the management body/governing body.............................................................................................17
Section 4.1.3. Conditions for performing multiple mandates...........................................................18
Section 4.1.4. Obligations regarding meetings and deliberations.....................................................19
Sub-chapter 4.2. Senior management ....................................................................................... 19
Section 4.2.1. Required number, presence in Luxembourg and contractual relationship with the IFM
..........................................................................................................................................................19
Section 4.2.2. Requirements regarding the skills, experience and the good repute of the senior
management ......................................................................................................................................20
Section 4.2.3. Organisation of the senior management.....................................................................20
Section 4.2.4. Obligations regarding meetings and deliberations.....................................................22
Sub-chapter 4.3. Procedure for the approval of the members of the management
body/governing body and the conducting officers................................................................... 22
Sub-chapter 4.4. Independence of the IFM’s bodies from the depositary............................. 23
Chapter 5. Arrangements regarding the central administration and internal governance..... 24
Sub-chapter 5.1. Arrangements regarding the central administration of the IFM.............. 24
Section 5.1.1. Clarifications on human resources.............................................................................24
Section 5.1.2. Clarifications on technical infrastructure, IT and business continuity.......................26
Section 5.1.3. Clarifications on the accounting function ..................................................................27
Section 5.1.4. Clarifications on the premises in Luxembourg ..........................................................27
Sub-chapter 5.2. General internal governance arrangements............................................... 27
Circular CSSF 18/698 Page 4/96
Sub-chapter 5.3. Internal control functions ............................................................................. 28
Section 5.3.1. Permanent risk management function........................................................................31
Sub-section 5.3.1.1. Obligations of IFMs regarding risk management.........................................31
Sub-section 5.3.1.2. Permanent risk management function..........................................................31
Sub-section 5.3.1.3. Person responsible for the permanent risk management function................32
Sub-section 5.3.1.4. Risk management policy ..............................................................................33
Sub-section 5.3.1.5. Risk management procedure (RMP) to be communicated to the CSSF ......34
Sub-section 5.3.1.6. Use of third-party experts.............................................................................35
Section 5.3.2. Permanent compliance function.................................................................................36
Sub-section 5.3.2.1. General principles ........................................................................................36
Sub-section 5.3.2.2. Operational arrangements and compliance charter ......................................36
Sub-section 5.3.2.3. Specific responsibilities and scope of the compliance function...................36
Sub-section 5.3.2.4. Person responsible for the permanent compliance function.........................38
Sub-section 5.3.2.5. Use of third-party experts or technical means..............................................39
Sub-section 5.3.2.6. Obligations regarding the drawing-up of reports.........................................40
Section 5.3.3. Permanent internal audit function ..............................................................................41
Sub-section 5.3.3.1. General principles ........................................................................................41
Sub-section 5.3.3.2. Operational arrangements and internal audit charter ...................................41
Sub-section 5.3.3.3. Specific responsibilities and scope of the internal audit function ................42
Sub-section 5.3.3.4. Person responsible for the permanent internal audit function......................43
Sub-section 5.3.3.5. Use of third-party experts or technical means..............................................43
Sub-section 5.3.3.6. Performance of the internal audit function according to an internal audit plan
......................................................................................................................................................44
Sub-section 5.3.3.7. Obligations regarding the drawing-up of reports.........................................45
Sub-chapter 5.4. Organisation of the fight against money laundering and terrorist financing 46
Section 5.4.1. Obligations applicable to every IFM referred to in this sub-chapter .........................46
Sub-section 5.4.1.1. General principles ........................................................................................46
Sub-section 5.4.1.2. Obligation to designate an AML/CFT Compliance Officer at senior
management level and drawing-up of a summary report on AML/CFT.......................................47
Sub-section 5.4.1.3. Internal audit control....................................................................................49
Section 5.4.2. Obligations applicable to the IFM according to the manner in which the relationship
with marketing intermediaries and the function of registrar agent is organised ...............................49
Sub-chapter 5.5. Requirements with respect to organisation and procedures ..................... 52
Section 5.5.1. Management Information and internal reporting system...........................................52
Section 5.5.2. Business continuity ....................................................................................................53
Section 5.5.3. Approval of new business relationships and new products........................................54
Circular CSSF 18/698 Page 5/96
Section 5.5.4. Manual of procedures.................................................................................................54
Section 5.5.5. Claim and complaint handling ...................................................................................54
Section 5.5.6. Personal transactions..................................................................................................55
Section 5.5.7. Management of conflicts of interest...........................................................................55
Sub-section 5.5.7.1.: Conflicts of interest policy..........................................................................56
Sub-section 5.5.7.2.: Keeping a record of conflicts of interest.....................................................56
Sub-section 5.5.7.3.: Obligation to inform investors....................................................................57
Section 5.5.8. Rules of conduct.........................................................................................................57
Section 5.5.9. Remuneration policy..................................................................................................57
Section 5.5.10. Exercise of voting rights..........................................................................................58
Section 5.5.11. Obligations of the IFM to monitor compliance with the obligations under EMIR..58
Section 5.5.12. Obligations of the IFM to monitor compliance with the obligations under the MMFR
..........................................................................................................................................................59
Chapter 6. Specific organisational arrangements........................................................................ 60
Sub-chapter 6.1. Limits to the scope of delegation .................................................................. 60
Sub-chapter 6.2. Delegation framework................................................................................... 61
Section 6.2.1. Obligation to notify the CSSF....................................................................................62
Section 6.2.2. Obligation to draw up a contract................................................................................63
Section 6.2.3. Initial due diligence and ongoing monitoring of delegates........................................63
Sub-section 6.2.3.1. General principles ........................................................................................63
Sub-section 6.2.3.2. Establishment of a delegation framework procedure ...................................63
Sub-section 6.2.3.3. Details on the initial due diligence...............................................................64
Sub-section 6.2.3.4. Details on the ongoing monitoring...............................................................66
Sub-chapter 6.3. Organisation of the portfolio management function .................................. 67
Section 6.3.1. Specificities related to the internal performance of the portfolio management function
..........................................................................................................................................................67
Sub-section 6.3.1.1. Implementation of a portfolio management procedure ................................67
Sub-section 6.3.1.2. Details on the staff and IT systems ..............................................................68
Sub-section 6.3.1.3. Functioning of the portfolio management committee ..................................68
Sub-section 6.3.1.4. Use of investment advisers...........................................................................68
Section 6.3.2. Specificities related to the delegation of the portfolio management..........................69
Sub-section 6.3.2.1. Specific conditions.......................................................................................69
Sub-section 6.3.2.2. Due diligence and ongoing monitoring........................................................70
Sub-chapter 6.4. Organisation of the function of UCI administration .................................. 71
Section 6.4.1. General obligations....................................................................................................71
Section 6.4.2. Specificities related to the wholly or partially internal UCI administration function71
Section 6.4.3. Specificities related to the delegation of the UCI administration ..............................72
Circular CSSF 18/698 Page 6/96
Sub-section 6.4.3.1. Specific conditions.......................................................................................72
Sub-section 6.4.3.2. Due diligence and ongoing monitoring........................................................73
Sub-chapter 6.5. Organisation of the marketing function ...................................................... 73
Sub-chapter 6.6. Organisation of the valuation function (specific provisions applicable to
IFMs authorised as AIFM) ........................................................................................................ 74
Section 6.6.1. General obligations....................................................................................................74
Section 6.6.2. Specificities related to the internal performance of the valuation function ...............75
Section 6.6.3. Specificities related to the delegation of the valuation function ................................76
Chapter 7. External audit............................................................................................................... 76
Chapter 8. Information exchange between the IFM and the depositary................................... 76
Chapter 9. Programme of activity................................................................................................. 77
Part III. Conditions for obtaining and maintaining the authorisation of IFMs which exercise
activities of UCI management and management of portfolios of investments on a client-by-client
basis as referred to in Article 101(3) of the 2010 Law and Article 5(4) of the 2013 Law ......... 79
Part IV. The IFM and the principle of freedom of establishment and freedom to provide
services............................................................................................................................................. 80
Chapter 1. Freedom to establish a branch.................................................................................... 80
Sub-chapter 1.1. Obligation of notification .............................................................................. 80
Sub-chapter 1.2. Operating conditions..................................................................................... 81
Chapter 2. Freedom to provide services....................................................................................... 82
Chapter 3. General provisions regarding the freedom of establishment and the freedom to
provide services............................................................................................................................... 82
Part V. Principle of proportionality .............................................................................................. 83
Part VI. IFMs governed by Article 125-1 of Chapter 16 and IFMs governed by Chapter 17 of
the 2010 Law.................................................................................................................................... 83
Chapter 1. IFMs governed by Article 125-1 of Chapter 16 of the 2010 Law ............................ 83
Chapter 2. IFMs governed by Chapter 17 of the 2010 Law........................................................ 84
Part VII. The SIAG and the FIAAG............................................................................................. 84
Chapter 1. Conditions for obtaining and maintaining authorisation ........................................ 84
Chapter 2. Prudential supervision of SIAGs and FIAAGs......................................................... 86
Part VIII. Communication with the CSSF ................................................................................... 86
Part IX. Entry into force and various provisions......................................................................... 86
ANNEXES ....................................................................................................................................... 87
ANNEX 1: The risk management procedure of AIFs to be communicated to the CSSF......... 87
Circular CSSF 18/698 Page 7/96
ANNEX 2: Summary table of the arrangements for the communication to the CSSF according
to the nature of the change (non-exhaustive list) ......................................................................... 91
Circular CSSF 18/698 Page 8/96
Part I. Definitions and abbreviations
Circular CSSF 18/698 Page 9/96
18) “senior management” means the persons who effectively conduct the business of an IFM
within the meaning of Article 102(1)(c) of the 2010 Law and Article 7(1)(c) of the 2013 Law;
19) “Law of 27 October 2010” means the Law of 27 October 2010 enhancing the anti-money
laundering and counter terrorist financing legal framework; organising the controls of physical transport of cash entering, transiting through or leaving the Grand Duchy of Luxembourg; implementing United Nations Security Council resolutions as well as acts adopted by the European Union concerning prohibitions and restrictive measures in financial matters in respect of certain persons, entities and groups in the context of the combat against terrorist financing;
20) “AML/CFT Law” means the Law of 12 November 2004 on the fight against money laundering
and terrorist financing, as amended;
21) “2010 Law” means the Law of 17 December 2010 relating to undertakings for collective
investment, as amended;
22) “2013 Law” means the Law of 12 July 2013 on alternative investment fund managers, as
amended;
23) “AML/CFT” means Anti-Money Laundering and Counter-Terrorist Financing;
24) “LFS” means the Law of 5 April 1993 on the financial sector, as amended;
25) “UCIs” include undertakings for collective investment in transferable securities (UCITS),
regulated and non-regulated alternative investment funds (AIFs), investment companies in risk capital (SICARs) which do not qualify as AIF and specialised investment funds (SIFs) which do not qualify as AIF;
26) “UCITS” means undertaking for collective investment in transferable securities subject to the
UCITS Directive;
27) “management body” means management body as defined in Article 1(26a) of the 2010 Law,
namely: a) as regards sociétés anonymes (public limited companies), the board of directors or the management board, as the case may be; b) as regards other types of companies, the body that represents the management company or the UCITS pursuant to the law and the instruments of incorporation;
28) “governing body” means the governing body as defined in Article 1 of Delegated Regulation
(EU) 231/2013, namely the body with ultimate decision-making authority in an AIFM, comprising the supervisory and the managerial functions, or only the managerial function if the two functions are separated;
29) “Joint Guidelines” means joint guidelines of ESMA, the EBA and EIOPA on the prudential
assessment of acquisitions and increases of qualifying holdings in the financial sector;
30) “Joint Guidelines (EBA/ESMA/EIOPA) on ML/TF risk factors” means joint guidelines issued
by the three European Supervisory Authorities (EBA/ESMA/EIOPA) on money laundering and terrorist financing risk factors;
31) “qualifying holding” means a direct or indirect holding in an undertaking which represents
10% or more of the capital or of the voting rights or which makes it possible to exercise a significant influence over the management of that undertaking;
32) “RMP” means risk management procedure;
33) “PRIIPs-KID” means key information documents for packaged retail and insurance-based
investment products, required under Regulation (EU) No 1286/2014 of the European Parliament and of the Council of 26 November 2014;
34) “Delegated Regulation (EU) 2016/438” means Commission Delegated Regulation (EU)
2016/438 of 17 December 2015 supplementing Directive 2009/65/EC of the European Parliament and of the Council with regard to obligations of depositaries;
35) “Delegated Regulation (EU) 231/2013” means Commission Delegated Regulation (EU) No
231/2013 of 19 December 2012 supplementing Directive 2011/61/EU of the European Parliament and of the Council with regard to exemptions, general operating conditions, depositaries, leverage, transparency and supervision;
36) “Delegated Regulation (EU) 241/2014” means Commission Delegated Regulation (EU) No
241/2014 of 7 January 2014 supplementing Regulation (EU) No 575/2013 of the European
Circular CSSF 18/698 Page 10/96
Parliament and of the Council with regard to regulatory technical standards for Own Funds requirements for institutions, as amended;
37) “EMIR” means Regulation (EU) No 648/2012 of the European Parliament and of the Council
of 4 July 2012 on OTC derivatives, central counterparties and trade repositories as well as the related delegated and implementing acts;
38) “MiFID II Regulation” means
Circular CSSF 18/698 Page 11/96
Part II. Conditions for obtaining and maintaining the authorisation of an
authorised investment fund manager (IFM) who engages solely in the activity of management of UCIs as laid down in Article 101(2) of the 2010 Law and Article 5(2) of the 2013 Law
Chapter 1. Basic principles
2. Access to the business of an IFM is subject to prior authorisation by the CSSF (in accordance with
Articles 101 and 125-2 of the 2010 Law and/or Article 6 of the 2013 Law, respectively).
3. The same applies when a Luxembourg IFM opens agencies in Luxembourg, representative offices
and branches in Luxembourg and/or abroad.
4. For an AIFM, the scope of responsibility of the AIFM vis-à-vis each managed AIF must be assessed
taking into account the compulsory or ancillary nature of the functions laid down in point (1) or (2) of Annex I of the 2013 Law and performed by the AIFM. However, this principle does not exempt the AIFM from complying with the provisions referred to in Sub-chapter 5.4. Organisation of the fight against money laundering and terrorist financing, and in point 516 of Sub-chapter 6.4. Organisation of the function of UCI administration
Chapter 2. Shareholding
Sub-chapter 2.1. Initial authorisation
5. The CSSF only grants authorisation to an IFM if it has been informed of the identities of the direct
and indirect1 shareholders or members, whether natural or legal persons, that have qualifying holdings, and of the amounts of those holdings. The CSSF must be satisfied that a holder of a qualifying holding is of good repute and suitable to exercise its powers so that the sound and prudent management of the IFM is ensured (Articles 103(1) of the 2010 Law and 7(1)(d) of the 2013 Law).
6. Moreover, the direct and indirect shareholding structure, including the persons with whom the IFM
has close links, must be clearly determined and organised so that the CSSF is not prevented from exercising supervision (Articles 102(2) of the 2010 Law and 7(3) of the 2013 Law).
7. Sound and prudent management is assessed in the light of the assessment criteria laid down in
Chapter 3 of the Joint Guidelines2
. The five criteria are:
1 “Indirect shareholders” means the ultimate shareholders and beneficial owners of the IFM’s shareholding structure. 2 JC/GL/2016/01 of 20 December 2016:
https://esas-joint-committee.europa.eu/Publications/Guidelines/JC_QH_GLs_EN.pdf 3 For the IFM which adopted the form of a société en commandite (limited partnership), the concept of acquirer includes both, the general partner and the limited partner.
Circular CSSF 18/698 Page 12/96
8. Provision applicable to ManCos: As regards the IFM governed by Chapter 15 of the 2010 Law, the
concept of sound and prudent management is assessed specifically in the light of the assessment criteria laid down in Article 108 of the 2010 Law which refers to Article 18 of the LFS.
9. The application file submitted for authorisation as provided for in point 2 of this circular must include
at least the information listed in Annex I of the Joint Guidelines.
10. The authorisation request must comprise a detailed organisation chart of the group to which the IFM
belongs. This chart must identify the direct shareholders and every indirect shareholder having a qualifying holding in the IFM. In any case, the final beneficial owner of the IFM must be identified. The organisation chart must highlight the possible holdings/subsidiaries and branches of the IFM and, in principle, all the entities which are part of the group.
11. Furthermore, the authorisation request must comprise, for each shareholder intending to have a
qualifying holding, the following information to be provided in one of the languages approved by the CSSF in accordance with Part VIII of this circular:
Circular CSSF 18/698 Page 13/96
Circular CSSF 18/698 Page 14/96
27. The CSSF does not, in principle, accept contributions in kind, such as receivables, either at the time
of the incorporation of the IFM, or in the case of capital increase during its lifetime.
28. Every IFM whose authorisation exclusively covers UCI management within the meaning of Article
101(2) of the 2010 Law and/or Article 5(2) of the 2013 Law must at any time be able to prove an amount of own funds which is at least equal to the greater of the two following amounts:
Circular CSSF 18/698 Page 15/96
36. The CSSF publishes on its website4 details on the methods for calculating the required own funds of
IFMs.
Specific provisions applicable to AIFMs:
37. To cover potential professional liability risks resulting from the activities the AIFM may carry out
pursuant to the 2013 Law, the AIFM and the FIAAG must either:
4 Point 17 of https://www.cssf.lu/en/document/faq-alternative-investment-fund-managers/
Circular CSSF 18/698 Page 16/96
46. It is permissible for the required own funds to be invested in liquid assets or assets easily convertible
into liquid short-term assets and not containing any speculative positions.
47. In this context, the IFM must implement a treasury management policy. The surplus own funds
required under the legal and regulatory requirements may be invested in non-liquid assets, provided that these assets do not pose a substantial risk for the required own funds of the IFM and do not jeopardise the sound and prudent management of the IFM. The acquisition of units/shares of UCIs by the IFM, for example during the launch of UCIs or of classes of units/shares in managed UCIs (seeding), must be financed by the IFM’s surplus own funds in relation to the required own funds.
48. The own funds of the IFM required under the legal and regulatory requirements can neither be used
for investment in the shareholder of the IFM nor be used for granting a loan to this shareholder. Arrangements with respect to holdings and creation of subsidiaries
49. Any holding of an IFM in another company, as well as any creation or acquisition of a subsidiary
within the meaning of Article 1(18) of the 2010 Law or Article 1(44) of the 2013 Law must be notified beforehand to the CSSF in writing.
50. The IFM must be able to demonstrate that the holding or subsidiary activity remains in line with the
activities which may be carried out by an IFM.
51. The file must include at least:
Circular CSSF 18/698 Page 17/96 material. This document must be sent to the CSSF via email at opc@cssf.lu within two months following the end of the calendar half year.
57. The compliance and internal audit functions must also cover the activity of the subsidiaries owned
by an IFM, where appropriate.
Chapter 4. The bodies of the IFM
Sub-chapter 4.1. The members of the governing body or management body
58. This sub-chapter applies to the members of the governing body or management body. Where a legal
person is appointed as member of the governing body or management body, this sub-chapter applies to the permanent representative of the legal person. The supervisory board must also comply with the provisions referred to in this sub-chapter.
Section 4.1.1. Required number
59. There must be at least three members of the management body/governing body. However, in case of
a two-tier system in which the supervisory and management functions are separated, the supervisory board must be composed of three members at least and the management board must be composed of two members at least.
Section 4.1.2. Requirements regarding the skills, experience and good repute and the
composition of the management body/governing body
60. The members of the management body/governing body must possess sufficient skills and
professional experience having regard to the type(s) of UCI(s) concerned and to the investment strategies of the managed UCIs, particularly the strategies referred to in Annex IV of Delegated Regulation (EU) 231/2013 for which the AIFM is authorised, where appropriate.
61. With regard to sufficient experience, the members of the management body/governing body must
have adequate professional experience gained, for example, through having already carried out similar activities at a high level of responsibility and autonomy.
62. Every member of the management body/governing body must prove to be of good professional
repute.
63. The composition of the members of the management body/governing body as a whole must be
appropriate so that the management body/governing body can fully meet its responsibilities. The appropriateness refers in particular to professional skills (knowledge, understanding and experience), as well as personal qualities of the members of the management body/governing body. Thus, the management body/governing body, as collective body, must have a complete understanding of all the activities, risks incurred by the IFM and managed UCIs, as well as of the economic and regulatory environment in which the IFM operates. Every single member of the management body/governing body must have a complete understanding of the internal governance arrangements and his/her responsibilities within the IFM.
64. The members of the management body/governing body must ensure that their personal qualities
enable them to properly perform their mandate as member of the management body/governing body, with the required commitment, availability, objectivity, critical thinking and independence. In this respect, the management body/governing body cannot have a majority of persons among its members who take on an executive role within the IFM (conducting officers or other employees of the IFM, with the exception of staff representatives) unless adequately justified.
65. Moreover, with respect to the management of UCIs which adopted the form of a company, it is
recommended that the management body/governing body of the IFM and of the UCI concerned do not mainly consist of the same persons.
Circular CSSF 18/698 Page 18/96
66. In case a member of the management body/governing body is part of the IFM’s senior management,
s/he may, in addition to his/her mandate as member of the management body/governing body, assume the position of the Compliance Officer, the AML/CFT Compliance Officer or the person responsible for risk management. In case a member of the management body/governing body is part of the IFM’s senior management, s/he may, in addition to his/her mandate as member of the management body/governing body, assume the position of the person responsible for internal audit in accordance with the provision under point 97 below.
Section 4.1.3. Conditions for performing multiple mandates
67. The members of the management body/governing body must ensure that their mandate is and remains
compatible with their other professional occupations. They must inform the management body/governing body of the mandates they have outside the IFM. The IFM must then identify the conflicts of interest which could result from this organisation and strive to avoid them in accordance with the procedures provided for in the conflict of interest policy of the IFM.
68. Furthermore, every member of the management body/governing body of the IFM must dedicate the
required time and attention to his/her duties. Consequently, each one of them must ensure that s/he limits the number of other professional engagements to the extent necessary in order to perform his/her tasks correctly. “Mandate” means any position as member of a management body/governing body or of a supervisory function or of the senior management within regulated or non-regulated entities. The mandates for which an approval request which was submitted to a supervisory authority is being analysed must also be included.
69. As a result, every candidate for the position of member of the IFM’s management body/governing
body must ensure compliance with the following requirements:
a) the number of hours spent fulfilling professional engagements cannot exceed 1920 hours per year; and b) the number of mandates in regulated entities and in operating companies cannot exceed 20 mandates.
70. For the purposes of determining the number of performed mandates referred to in point 69(b) above,
the CSSF may consider the mandates within the entities that are part of the structure of some managed UCIs (such as, for example, the UCI’s mandates performed in special purpose vehicles or in the UCI itself) or the mandates of UCIs with the same initiator or the mandates in entities belonging to the same group and subject to supervision by an authority (such as, for example, the IFMs belonging to the same group) as one single mandate in order to assess the total number of mandates performed pursuant to the provisions of point 69(b) above. In that case, the candidate must justify such combination by demonstrating the synergies resulting from the performance of these combined mandates.
71. Where one of the thresholds referred to in point 69 above is exceeded, taking into account the
application of point 70, the candidate must enclose with his/her authorisation request a description of the measures implemented to ensure his/her additional mandate receives the required time and attention. This description must include, in particular, justifications on how the candidate intends to organise himself/herself to fulfil his/her responsibilities by taking into account the existing and future workload. The number of managed UCIs/compartments, the size, the volume, the nature, the scale and complexity of the managed UCIs/compartments and operating entities, where appropriate, must also be taken into account. The file must detail, in particular, the technical and administrative support the candidate requires or will require.
72. The thresholds referred to in point 69 must be revised downwards when the nature, scope or
complexity of the activities of the above-mentioned entities so justify or when the candidates’ work time is reduced.
73. Every member of the management body/governing body of the IFM is responsible for continuously
ensuring compliance with the principles laid down in this section.
Circular CSSF 18/698 Page 19/96
Section 4.1.4. Obligations regarding meetings and deliberations
74. The management body/governing body must meet regularly, and at least once every quarter, in order
to efficiently perform its duties. The frequency of the meetings must be proportionate to the nature, scale and complexity of the IFM’s activities. Video conferencing or any other means of remote telecommunication allowing the identification of the participants and ensuring the effective participation in the meeting of the management body/governing body is also accepted.
75. The work of the management body/governing body must be documented in writing. This
documentation must include the agenda of the meeting, the minutes of the meeting recording the decisions and measures taken by the management body/governing body. These minutes must be available or accessible in the premises of the IFM in Luxembourg. Sub-chapter 4.2. Senior management
Section 4.2.1. Required number, presence in Luxembourg and contractual relationship with
the IFM
76. “Senior management” means the persons who effectively conduct the business of the IFM within the
meaning of Article 102(1)(c) of the 2010 Law and Article 7(1)(c) of the 2013 Law (hereinafter the “conducting officers”) irrespective of the form or legal structure of the IFM. In case of a two-tier system, if one or more members of the management board are also members of the senior management, then these members must comply with the provisions of this sub-chapter.
77. Points 78 to 80 as well as points 84 and 85 set out the general principles regarding the required
number, the presence in Luxembourg and the contractual relationship with the IFM. Points 81 to 83 concern the specific requirements in the application of these principles according to the value of the portfolios managed by the IFM.
78. The number of conducting officers must be at least two.
79. For the accomplishment of their tasks, the conducting officers must, in principle, be permanently
located in Luxembourg. This does not however prevent the conducting officers from having their domicile in a place allowing them, in principle, to come to Luxembourg every day.
80. The IFM must employ at least two conducting officers in Luxembourg (i.e. bound to the IFM by an
employment contract and employees of the IFM) who spend an FTE on the duties in the IFM. The CSSF may accept that one or more conducting officers (including the legally required conducting officers) are made available or seconded, provided that there is an agreement precisely defining their rights and obligations and, where appropriate, the reporting lines, in accordance with the specific requirements referred to in points 81 and 82 below.
81. Where the value of the portfolios managed by the IFM as defined in Articles 102(1)(a) of the 2010
Law, 8(7) of the 2013 Law and the second subparagraph of Article 14(2) of Delegated Regulation (EU) 231/2013 is less than one billion five hundred million euros (EUR 1,500,000,000), the following conditions must apply:
a) the conducting officers cannot perform more than two mandates as conducting officer in IFMs; b) the CSSF may authorise, based on a prior and duly supported request for derogation, that only one of the legally required conducting officers is permanently located in Luxembourg, provided that the IFM employs sufficient and competent staff in Luxembourg in order to support the conducting officer who is not permanently located in Luxembourg in his/her duties and that this conducting officer can regularly come to Luxembourg to demonstrate that the provisions of Section 4.2.3. (Organisation of the senior management) and of point 118 are complied with; c) if the IFM has more than two conducting officers, the provisions of point 81 must also apply to these additional conducting officers.
Circular CSSF 18/698 Page 20/96
82. Where the value of the portfolios managed by the IFM as defined in Articles 102(1)(a) of the 2010
Law, 8(7) of the 2013 Law and the second subparagraph of Article 14(2) of Delegated Regulation (EU) 231/2013 exceeds one billion five hundred million euros (EUR 1,500,000,000), the following conditions must apply:
a) the two legally required conducting officers cannot perform other mandates as conducting officers of IFMs; b) if the IFM has only two conducting officers, then these two conducting officers must be permanently located in Luxembourg in accordance with point 79; c) if the IFM has more than two conducting officers, then the CSSF may authorise, based on a prior duly supported request for derogation, that one or more of these additional conducting officers are not permanently located in Luxembourg and/or spend less than an FTE on their duties, provided that the IFM employs sufficient and competent staff in Luxembourg in order to support these conducting officers in their duties and that they can regularly come to Luxembourg to demonstrate that the provisions of Section 4.2.3. (Organisation of the senior management) and of point 118 are complied with.
83. In accordance with the provisions referred to in points 81 and 82(c) above, a person performing more
than one mandate as conducting officer must be able to satisfactorily demonstrate to the CSSF that a second mandate as conducting officer does not and is not likely to prevent him/her from discharging soundly, honestly and professionally any of his/her functions with the necessary time and due attention. Moreover, the IFM must identify the conflicts of interest which could result from this organisation and strive to avoid them in accordance with the procedures provided for in the conflict of interest policy of the IFM.
84. The CSSF must be able to contact each conducting officer directly. These persons must be able to
provide all information that the CSSF deems essential for its supervision.
85. Furthermore, the conducting officers must benefit from appropriate support in their daily work
provided by qualified staff that are sufficient in number and working in Luxembourg (Section 5.1.1. Clarifications on human resources). The staff employed in one or more branches of the IFM may be taken into account. In any case, every IFM must employ at least three people full-time at the head office in Luxembourg (i.e.: senior management and/or staff) who perform key functions in accordance with point 123.
Section 4.2.2. Requirements regarding the skills, experience and the good repute of the senior
management
86. The conducting officers of the IFM must possess sufficient skills and professional experience having
regard to the type(s) of UCI(s) concerned and to the investment strategies of the managed UCIs, particularly the strategies referred to in Annex IV of Delegated Regulation (EU) 231/2013 for which the AIFM is authorised, where appropriate.
87. With regard to required experience, the conducting officers must have adequate professional
experience gained, for example, through having already carried out similar activities at a high level of responsibility and autonomy.
88. Each conducting officer must demonstrate his/her good repute.
89. The conducting officers, both individually and collectively, must have the necessary professional
skills (expertise, understanding and experience), good repute and personal qualities to fulfil their duties so as to ensure a sound and prudent management of the IFM.
Section 4.2.3. Organisation of the senior management
90. The conducting officers of every IFM must be members of the executive committee. The members
of this committee work together in close partnership to take all actions falling within the scope of their responsibilities.
Circular CSSF 18/698 Page 21/96
91. The executive committee, under the ultimate responsibility of the management body/governing body,
must, among other things:
Circular CSSF 18/698 Page 22/96
Circular CSSF 18/698 Page 23/96
105. This notification must be accompanied by the following pieces of information and any other
document which the CSSF may request subsequently:
Circular CSSF 18/698 Page 24/96
Chapter 5. Arrangements regarding the central administration and
internal governance
Sub-chapter 5.1. Arrangements regarding the central administration of the IFM
115. Every IFM must have a central administration in Luxembourg, consisting of a "decision-making
centre" and an "administrative centre". This requirement implies that the IFM cannot only have a corporate or registered office in Luxembourg.
116. The central administration of the IFM, referred to in Article 102(1)(e) of the 2010 Law and 7(1)(e)
of the 2013 Law should not be confused with the “administration” function referred to in Annex II of the 2010 Law or Annex I of the 2013 Law, respectively.
117. The central administration of the IFM, which comprises in a broad sense the functions of direction
and management, of execution and of control, must permit the IFM to have control of all its activities.
118. The concept of “decision-making centre” does not only include the activity of the senior management
pursuant to Article 102(1)(c) of the 2010 Law and Article 7(1)(c) of the 2013 Law but also the activities of the persons responsible for the different key functions or of any other business unit within the IFM.
119. The administrative centre comprises in particular a sound administrative and accounting organisation
which ensures, among others, the adequate execution of transactions, the correct and complete recording of transactions, the production of sound and readily available management information, the monitoring of delegated activities, the management of conflicts of interest and the compliance with applicable rules of conduct and other operating conditions. To that effect, the IFM must have in Luxembourg the human and technical resources necessary and sufficient to exercise the activities it intends to exercise and in order to monitor the delegated functions. This implies that it has the following elements (non-exhaustive list) in place in Luxembourg:
Circular CSSF 18/698 Page 25/96
123. Every IFM must employ at least three full-time people (FTE) at the head office in Luxembourg who
perform key functions. Depending on the nature and complexity of its activity, the IFM must adapt the size of the teams performing key functions and employ more people with the necessary skills, knowledge and expertise in order to perform key functions.
124. Long-term absences or departures of staff members (for example, resignations or dismissals) cannot
impair the proper functioning of the IFM in the long run.
125. In the absence of a staff member in charge of key functions, it is necessary to arrange that a staff
member with appropriate experience and necessary independence replaces him/her if need be.
126. The staff are, in principle, employed by the IFM with which it is bound by an employment contract.
127. The CSSF may grant derogation from the requirements referred to in point 126 and authorise part of
the staff to be seconded or made available by an entity belonging to the same group or by a thirdparty company. In this case, the contract governing this secondment or this availability must be submitted to the CSSF for prior approval. Furthermore, the contract must contain rules for managing conflicts of interest between the relevant staff and the entity to which the staff also provide services. This contract must also specify the tasks of the relevant staff, the reporting line with the conducting officers of the IFM for the functions performed in the entity pursuant to Articles 5(1)(a) of CSSF Regulation 10-4 and 57(1)(a) of Delegated Regulation (EU) 231/2013 as well as actual time spent within the IFM. The staff thus made available to the IFM or seconded must be permanently located in Luxembourg and must be reachable at any time in Luxembourg during normal business hours. This does not however prevent the staff members from having their domicile in a place allowing them, in principle, to come to Luxembourg every day.
128. Where, due to the small size of the IFM, several duties and responsibilities have to be assigned to the
same person, this grouping must be organised so that it does not prejudice the objective pursued by the segregation of duties.
129. Specific provision applicable to ManCos: The performance of multiple functions by the same person
should not prevent or be likely to prevent this same person from discharging any particular function soundly, honestly and professionally in accordance with Article 6(3) of CSSF Regulation 10-4.
130. Specific recommendation to AIFMs: It is recommended that the AIFM also complies with the
provision referred to in point 129 above.
131. The organisation chart of the IFM must detail the various (operational and control) functions of the
structure and the reporting and functional links between these functions and between the senior management and management body/governing body of the IFM.
132. The organisation chart and description of the duties must be established based on the principle of
segregation of duties. Pursuant to this principle, the duties and responsibilities must be assigned so as to avoid that they are incompatible for the same person. The objective pursued is to avoid conflicts of interest and to prevent, through a peer review environment, a person from making mistakes and irregularities.
133. Upon the CSSF’s request, the IFM must provide an updated organisation chart. To this end, the
organisation chart must, in particular, include:
Circular CSSF 18/698 Page 26/96
Section 5.1.2. Clarifications on technical infrastructure, IT and business continuity
134. Every IFM must have in its premises a suitable technical and IT infrastructure for the activity it
intends to exercise.
135. According to Article 5(2) of CSSF Regulation 10-4 and Article 57(2) of Delegated Regulation (EU)
231/2013, every IFM must establish, implement and maintain systems and procedures that are adequate to safeguard the security, integrity and confidentiality of information, taking into account the nature of the information in question.
136. The requirements in the above paragraph are best met when the IFM has its own IT infrastructure
which is supported by its own IT department organised and surrounded by an internal control system determined by the senior management. As a general rule, the IFM must have its own computers and appropriate and duly documented computer programmes in its premises in Luxembourg.
137. Thus, the IFM must implement procedures and a system for the identification and management of IT
risks, particularly in the following areas:
Circular CSSF 18/698 Page 27/96
IFM must designate a person among its employees, the cloud officer, responsible for using cloud computing services and guarantor of the skills of the staff managing cloud computing resources. This function may be performed directly by the conducting officer in charge of the IT function.
144. The CSSF would like to remind all IFMs that they must comply with the provisions of Circular CSSF
11/504 on frauds and incidents due to external computer attacks.
Section 5.1.3. Clarifications on the accounting function
145. According to Article 5(4) of CSSF Regulation 10-4 and Article 57(4) of Delegated Regulation (EU)
231/2013, every IFM must establish, implement and maintain accounting policies and procedures as well as valuation rules providing financial information which reflects a true and fair view of the IFM’s financial situation.
146. Consequently, every IFM must communicate to the CSSF the name of the person in charge within
the IFM who can provide information on the accounting situation of the IFM.
147. The identity of the person responsible for the accounting function as well as of every person
succeeding him/her in office must be communicated forthwith to the CSSF.
148. Regarding the organisation of the accounting function, the IFM can either put in place its own
accounting function, or use, under its responsibility, the accounting expertise of a third party. Any use of a third party must be notified beforehand to the CSSF and formalised by a service contract. In addition, the third party must be subject to initial due diligence and ongoing monitoring pursuant to the provisions under Sub-chapter 6.2. (Delegation framework) of this circular.
149. Regardless of the organisation of the accounting function, particularly the use of a third party, the
accounting documents relating to the activity of the IFM must always be available and/or accessible electronically at the head office of the IFM in Luxembourg to enable the IFM to draw up a balance sheet and a profit and loss account in an independent way.
150. The accounting function must operate based on written procedures that provide for:
Circular CSSF 18/698 Page 28/96
154. Internal governance must ensure in particular sound and prudent business management, including
the risks inherent therein. In order to achieve this objective, the IFMs must establish internal governance arrangements which are consistent with the three-lines-of-defence model.
155. The first line of defence consists of the business units that take or acquire risks under a predefined
policy and limits and carry out controls.
156. The second line consists of the permanent risk management (Section 5.3.1.) and compliance (Section
5.3.2.) functions which contribute to the independent risk control, as well as of the support functions, including the IT function (Section 5.1.2.) and accounting function (Section 5.1.3.).
157. The third line consists of the internal audit function (Section 5.3.3.) which provides an independent,
objective and critical review of the first two lines of defence.
158. The three lines of defence are complementary, each line of defence assuming its control
responsibilities regardless of the other lines.
159. These internal governance arrangements must be structured around the following areas, which have
essentially been elaborated in CSSF Regulation 10-4 and Delegated Regulation (EU) 231/2013:
Circular CSSF 18/698 Page 29/96
163. The policies implemented with respect to risk management, compliance and audit must provide for
three distinct internal control functions: on the one hand, the risk control function and compliance function which are part of the second line of defence and on the other hand, the internal audit function which is part of the third line of defence. These policies which describe the fields of intervention directly related to each internal control function must clearly define the responsibilities for the common fields of intervention and the objectives as well as the independence, objectivity and permanence of the internal control functions.
164. Each internal control function must be under the responsibility of a separate function manager who
is appointed and revoked in accordance with an internal written procedure. The appointments and revocations of the persons responsible for the internal control functions must be approved by the management body/governing body and communicated to the CSSF in writing, in accordance with the provisions laid down in Sub-section 5.3.1.3. for the risk management function, Sub-section
5.3.2.4. for the compliance function and Sub-section 5.3.3.4. for the internal audit function.
165. The persons responsible for the three internal control functions are accountable to the senior
management and ultimately to the management body/governing body for the performance of their mandate. In this respect, these persons must be able to contact and inform, directly and on their own initiative, the management body/governing body or, where appropriate, the members of the audit committee as well as the CSSF.
166. The main purpose of the internal control functions is to verify compliance with all the internal
policies and procedures which fall under their competence, to regularly assess their suitability as regards the IFM’s organisational and operational structure, strategies, activities and risks and as regards the applicable legal and regulatory requirements and to report it directly to the senior management and to the management body/governing body. They must provide the senior management and the management body/governing body with the opinions and advice they deem necessary in order to improve the arrangements regarding the central administration and the internal governance of the IFM.
167. The persons responsible for the internal control functions must respond as soon as possible to the
requests for opinions and advice from the senior management and the management body/governing body of the IFM or, where appropriate, the IFM’s specialised committees. If they consider that effective, sound or prudent business management is compromised, the persons responsible for the internal control functions must promptly inform, on their own initiative, the senior management and the management body/governing body in accordance with the applicable internal procedures.
168. The internal control functions must also cover the activity of branches, representative offices,
agencies and subsidiaries owned by an IFM.
169. It should be noted that the compliance and the internal audit functions cannot be performed by the
same natural person. Similarly, where the performance of the permanent compliance or internal audit function is delegated in compliance with the conditions referred to in the respective sections below (5.3.2. and 5.3.3.), the monitoring of these functions cannot be entrusted to the same natural person.
170. Moreover, the persons responsible for the internal control function must submit annual reports to the
CSSF in accordance with point 212 (for the risk management function), Sub-section 5.3.2.6. (for the compliance function) and Sub-section 5.3.3.7. (for the internal audit function) below. Characteristics of the internal control functions
171. The internal control functions must be permanent and independent functions each with sufficient
authority. The persons responsible for these functions must have the right to directly contact the IFM’s management body/governing body and réviseur d'entreprises agréé (approved statutory auditor) as well as the CSSF.
172. The independence of the internal control functions is incompatible with the situation in which:
Circular CSSF 18/698 Page 30/96
Circular CSSF 18/698 Page 31/96
184. In case of serious problems, shortcomings and irregularities, the persons responsible for the internal
control functions must inform forthwith the senior management and the management body/governing body thereof.
185. The persons responsible for the internal control functions must verify the effective follow-up of the
recommendations relating to the identified problems, shortcomings and irregularities. They must report regularly on this subject to the senior management and management body/governing body of the IFM.
Section 5.3.1. Permanent risk management function
Sub-section 5.3.1.1. Obligations of IFMs regarding risk management
186. Articles 42(1) of the 2010 Law and 14 of the 2013 Law introduce, in particular, the obligation for an
IFM to use a method and systems for risk management allowing it to identify, measure and control the risks of UCI positions.
187. The permanent risk management function and the risk management policy are central elements
thereof.
Sub-section 5.3.1.2. Permanent risk management function
188. In accordance with Articles 13 of CSSF Regulation 10-4 and 39 of Delegated Regulation (EU)
231/2013, an IFM must, among others, establish and maintain a permanent risk management function.
189. The permanent risk management function must be hierarchically and functionally independent from
the business units in accordance with Article 13(2) of CSSF Regulation 10-4 and Article 14(1) of the 2013 Law as specified in point 533 of this circular.
190. The functional and hierarchical separation of the functions of risk management is reviewed by the
CSSF in accordance with the principle of proportionality, on the understanding that the IFM must, in any event, be able to demonstrate that specific safeguards against conflicts of interest allow for the independent exercise of risk management activities and that the risk management process satisfies the requirements of Articles 42 of the 2010 Law and 14 of the 2013 Law and is consistently effective.
191. The risk management function must:
Circular CSSF 18/698 Page 32/96 management of the IFM. These written reports must include analyses which allow the addressees to verify the consistency between:
Circular CSSF 18/698 Page 33/96
202. The tasks of the person responsible for the permanent risk management function cannot be exercised
directly by a member of the management body/governing body, unless s/he is part of the IFM’s senior management. Sub-section 5.3.1.4. Risk management policy
203. In accordance with Articles 43 of CSSF Regulation 10-4 and 40 of Delegated Regulation (EU)
231/2013, an IFM must establish, implement and maintain an appropriate and documented risk management policy which identifies the risks which the UCIs it manages are or might be exposed to. This policy must be implemented by the permanent risk management function.
204. The risk management policy must include all the necessary procedures to allow the IFM to assess for
each UCI it manages the exposure of the UCI to market, credit, liquidity and counterparty risks, as well as exposure of the UCI to any other risks, including operational risk, likely to be material for the UCI.
205. The risk management policy must cover at least the elements referred to in Articles 43 of CSSF
Regulation 10-4 and 40 of Delegated Regulation (EU) 231/2013. In particular, the description of the techniques, tools and arrangements allowing the IFM to measure and manage the risks as well as the allocation of responsibilities within the IFM must be detailed and complete. Moreover, Articles 45 of CSSF Regulation 10-4 and 44 and 45 of Delegated Regulation (EU) 231/2013 detail the requirements regarding the risk measurement and management and regarding the risk limits. In this context, the IFM is reminded that it must in particular:
Circular CSSF 18/698 Page 34/96
211. More generally, the person responsible for the permanent risk management function must report on
the adequacy and effectiveness of the risk management process to the management body/governing body and, where it exists, to the supervisory function of the IFM in accordance with Articles 13(3)(d) of CSSF Regulation 10-4 and 39(1)(d) of Delegated Regulation (EU) 231/2013. This report must indicate, in particular, the status of possible remedial measures.
212. The written report assessing the adequacy and effectiveness of the risk management to be drawn up,
in accordance with Articles 10(4) of CSSF Regulation 10-4 and 60(4) of Delegated Regulation (EU) 231/2013, by the risk management function, must be submitted to the CSSF once a year and at the latest five months following the end of the financial year of the IFM. This report may be a consolidated report covering all the UCIs managed by the IFM. Sub-section 5.3.1.5. Risk management procedure (RMP) to be communicated to the CSSF
213. Pursuant to Articles 42(1) of the 2010 Law and 22(2)(c) of the 2013 Law, the IFM must communicate
to the CSSF some information on the risk management policy aimed at identifying, measuring, managing, monitoring and reporting the risks likely to be material for the UCIs it manages. This communication must be made via an RMP as described herein.
214. As regards ManCos, for the UCITS they manage, Circular CSSF 11/512 presenting, among others,
the main regulatory changes in risk management and providing further clarifications on risk management rules, specifies in Chapter V the requirements of the CSSF regarding the communication in this context. In particular, the Annex to this circular presents a framework to be complied with for this RMP.
215. As regards AIFMs, the format of the RMP in Annex 1 of this circular must be complied with for the
managed AIFs. The general section concerns the main organisation of AIFMs. Specific complementary sections must be drawn up according to the strategies of the managed AIFs: at least one specific complementary section will be created for each type of investment strategy of the AIFs, as defined in Annex IV of Delegated Regulation (EU) 231/2013 (“Hedge Fund Strategy”, “Private Equity Strategy”, “Real Estate Strategy”, “Fund of Fund Strategy” and “Other Strategy”). If necessary, specific sections must be drawn up at a higher degree of granularity (e.g. creation of a specific complementary section for the strategy “Other Strategies/Commodity fund” and creation of a specific complementary section for the strategy “Other Strategies/Infrastructure fund). The assessment of the relevance of these specific sections is carried out by the AIFMs. However, the CSSF reserves the right to require one or more specific complementary section(s) if it deems it necessary.
216. The RMP must also comply with the following rules:
Circular CSSF 18/698 Page 35/96 authorisation to a new type of AIF investment strategy, as defined in Annex IV of Delegated Regulation (EU) 231/2013, an RMP adapted to this new type of strategy must be submitted to the CSSF.
218. Before launching a new UCI (including a compartment) and, where appropriate, when submitting
the authorisation file to the CSSF, the IFM must particularly ensure that the risk management policy and, thus, the RMP is adequate. If this is the case, the IFM must confirm it in writing to the CSSF at the time of the launch and, where appropriate, at the time of the submission of the file concerning this new UCI by indicating the reference of the latest submitted version of the RMP. If this is not the case (e.g. the UCI’s strategy is not covered by the risk management policy), the IFM must adapt its risk management policy, make changes in the RMP accordingly and send this document to the CSSF together with other elements of the file relating to the new UCI.
219. It should be noted that the procedure must cover at all times all the managed UCIs (including the
compartments) and that in case of significant changes in the risk management policy (e.g. change in the risk management procedures or methods), the IFM must update the RMP and inform the CSSF by readily submitting an updated version of this procedure.
220. The CSSF would like to point out that this RMP to be submitted to the CSSF is actually a distinct
part of the risk management policy described in Sub-section 5.3.1.4. Indeed, whereas the risk
management procedure described here is a synthetic communication tool vis-à-vis the CSSF allowing it, in particular, to carry out its prudential supervision with respect to risk management, the risk management policy is a documentation which is more free in form but more detailed in content and which includes, among others, processes, techniques, tools and allocations of responsibilities for the performance of risk management.
221. The CSSF also points out that pursuant to Article 50 of CSSF Regulation 10-4, a ManCo must
provide the CSSF at least once a year with a report containing information giving a true picture of the types of financial instruments used for each managed UCITS, the underlying risks, the quantitative limits and the methods chosen for assessing the risks associated with transactions in derivative instruments. This report must be submitted within five months following the end of the financial year of the IFM. Sub-section 5.3.1.6. Use of third-party experts
222. In accordance with Articles 110(1) of the 2010 Law and 26(4) of CSSF Regulation 10-4 or Articles
18 of the 2013 Law and 75 to 82 of Delegated Regulation (EU) 231/2013 respectively, the performance of some risk management tasks may be delegated to a third-party expert, provided there is a contract and the CSSF is notified beforehand.
223. Where an IFM delegates some risk management activities, the provisions of Articles 110(1) of the
2010 Law, 26(4) of CSSF Regulation 10-4, 18 of the 2013 Law and 75 to 82 of Delegated Regulation (EU) 231/2013 must apply. The IFM must also comply with the provisions referred to in Sub-chapter
6.2. Delegation framework of this circular.
224. The contract and the name of the mandated third party(ies) together with a description of the expertise
and internal organisation of this(these) third party(ies) must be communicated to the CSSF. The fact that the IFM has delegated part of the risk management to a specialised third party does not affect the IFM's responsibility for the adequacy and effectiveness of the risk management policy and its responsibility to ensure adequate monitoring of the risks of the UCI.
225. The ongoing monitoring of the specialised third parties in charge of risk management must cover in
particular the exposure of the UCI to market, liquidity, counterparty and concentration risks as well as to all other risks, including operational risk, which may be significant for the UCI.
Circular CSSF 18/698 Page 36/96
Section 5.3.2. Permanent compliance function
Sub-section 5.3.2.1. General principles
226. An IFM must have its own compliance function in Luxembourg which is organised in accordance
with the provisions referred to in Articles 11 of CSSF Regulation 10-4 and 61 of Delegated Regulation (EU) 231/2013 as well as with the provisions of this sub-chapter.
227. The aim of the compliance function is to anticipate, identify and assess the compliance risks of an
IFM as well as to assist the senior management in controlling these risks. These risks may include a variety of risks such as reputational risk, legal risk, litigation risk, risk of sanctions, as well as some operational risk aspects, in connection with all activities of the IFM, including the activities and services referred to in Article 101(3) of the 2010 Law and/or Article 5(4) of the 2013 Law. This task must be carried out on an ongoing basis and without delay.
228. The compliance function must be able to operate independently and must comply with the principle
of segregation of duties in order to identify any risk of non-compliance of the IFM with the requirements imposed by the 2010 Law, 2013 Law, CSSF Regulation 10-4, Delegated Regulation (EU) 231/2013 and all other regulations applicable to the IFM. Sub-section 5.3.2.2. Operational arrangements and compliance charter
229. The operational arrangements of the compliance function in terms of objectives, responsibilities and
powers must be laid down in a compliance charter drawn up by the compliance function and approved by the senior management and ultimately by the management body/governing body.
230. The compliance charter must at least:
Circular CSSF 18/698 Page 37/96
Circular CSSF 18/698 Page 38/96
236. The compliance function must centralise all information on the compliance problems (inter alia,
infringements of standards, non-compliance with procedures or conflicts of interest) identified in the IFM.
237. As long as the compliance function has not obtained this information on its own involvement, it must
examine relevant documents, whether internal (e.g. internal control reports and internal audit reports, reports or statements of the senior management or, where appropriate, of the management body/governing body) or external (e.g. reports of the external auditor, correspondence from the supervisory authority).
238. The Compliance Officer must assist and advise the senior management on issues of compliance and
standards, notably by drawing its attention to changes in standards which may subsequently have an impact on the compliance area.
239. The compliance function must raise awareness of the staff about the significance of compliance and
related aspects and assist them in the daily activities relating to compliance. To this end, it must also develop an ongoing training programme and ensure its implementation. Sub-section 5.3.2.4. Person responsible for the permanent compliance function
240. Every IFM must, pursuant to Article 11(3)(b) of CSSF Regulation 10-4 or Article 61(3)(b) of
Delegated Regulation (EU) 231/2013, appoint a person responsible for compliance, the Compliance Officer, who has the necessary skills, knowledge and expertise in the area. The IFM must communicate beforehand to the CSSF the name of its Compliance Officer supplemented by the following pieces of information and any other document which might be subsequently indicated by the CSSF:
Circular CSSF 18/698 Page 39/96
Sub-section 5.3.2.5. Use of third-party experts or technical means
248. An IFM whose authorisation is limited to the management of UCIs may invoke, via a specific prior
derogation request based on an adequate justification, the possibility of delegating the performance of the compliance function to a third party in accordance with Article 10(2)(c) of CSSF Regulation 10-4 and Article 6(2)(d) of Delegated Regulation (EU) 231/2013.
249. However, an IFM providing, in addition to management of UCIs, one or more of the services referred
to in Article 101(3) of the 2010 Law or Article 5(4) of the 2013 Law is not in principle authorised to delegate the performance of the compliance function.
250. In general, the IFM which has one or more branches is not allowed to delegate the performance of
the compliance function. However, the CSSF may derogate based on an adequate justification from this above-mentioned general principle provided that the importance of the activity and the size of the branch(es) so justify.
251. Pursuant to the principle of proportionality, the IFM may thus, upon duly justified derogation,
delegate the performance of the compliance function either by using third-party experts or technical means (external expert) or by establishing, where appropriate, a functional link with the group’s compliance function for the performance of compliance tasks.
252. The senior management must select these third parties on the basis of an analysis of suitability
between the IFM's needs and the specific services and competences offered by these third parties. The choice of the external expert carrying out the compliance work must be approved by the management body/governing body. The use of an external expert must be based on a written mandate. The expert must carry out the work in compliance with the applicable regulatory and internal provisions (notably the compliance charter). The external expert must carry out its work in accordance with the provisions of this sub-chapter. In this respect, it must take over all duties and responsibilities incumbent upon the compliance under this circular.
253. The IFM which decides to delegate the performance of the compliance function must submit
beforehand a written request to the CSSF. This request must include the information necessary for the assessment, including in particular:
Circular CSSF 18/698 Page 40/96
255. In the event of a change of the Compliance Officer referred to in point 254, the IFM must
communicate beforehand to the CSSF the name of the person succeeding him/her in office supplemented by the documents referred to in point 254. Sub-section 5.3.2.6. Obligations regarding the drawing-up of reports
256. The Compliance Officer must report in writing on a regular basis, and, where necessary, on an ad
hoc basis, to the senior management and, where appropriate, to the specialised committees and management body/governing body of the IFM. These reports concern the follow-up of the recommendations, problems, shortcomings and irregularities identified in the past as well as the new problems, shortcomings and irregularities identified. Each report must specify the risks related thereto as well as their seriousness (measuring the impact) and must propose corrective measures, as well as, in general, the position of the persons concerned.
257. The Compliance Officer must prepare, at least once a year, a summary report on his/her activities
and his/her operation. As far as the operation of the compliance function is concerned, the report must mention in particular the nature and level of reliance on external experts pursuant to Sub-section
5.3.2.5. as well as any problems which may have occurred in this context. This report must be
submitted for approval to the management body/governing body and, where appropriate, the specialised committees and for information purposes to the senior management.
258. The summary report of the compliance function must be provided to the CSSF annually. The CSSF
must receive this document within five months following the end of the financial year of the IFM.
259. It is recommended that the summary report of an IFM’s compliance function covers at least the
following information:
Circular CSSF 18/698 Page 41/96
Circular CSSF 18/698 Page 42/96
Circular CSSF 18/698 Page 43/96
Circular CSSF 18/698 Page 44/96 accordance with the provisions of this sub-chapter. In this respect, it must take over all duties and responsibilities incumbent upon the internal audit under this circular.
282. The IFM which decides to delegate the performance of the internal audit function must submit
beforehand a written request to the CSSF. This request must include the information necessary for the assessment, including in particular:
Circular CSSF 18/698 Page 45/96
288. The plan must be discussed with the senior management and submitted to the latter for approval,
confirmed, where appropriate, by the audit committee and ultimately approved by the management body/governing body. It should be reviewed on an annual basis and adapted, where appropriate, to developments and emergencies. Any adaptation is to be formally approved by the senior management and, where appropriate, the audit committee. The approval implies that the senior management provides the person responsible for the internal audit function with the means necessary to implement the internal audit plan.
289. In the summary report to the management body/governing body pursuant to point 298 below, the
person responsible for the internal audit function must indicate and explain the main changes made to the audit plan as initially approved by the management body/governing body.
290. The plan, which is adequately documented, must set out the objectives of each mission and the scope
of the tasks to be executed, give an estimate of the necessary time and human and material resources and assign an audit frequency to each activity and risk.
291. The internal audit plan must also provide for the adequate and sufficiently frequent coverage, within
a planning period of several years, of important or complex activities which represent a significant potential risk, including a reputational risk. It must focus on the risk of execution errors and the risk of fraud.
292. The person responsible for the internal audit function must regularly inform the senior management
of the implementation of the internal audit plan.
293. Each internal audit engagement must be planned, executed and documented pursuant to the
professional standards adopted by the internal audit function in its internal audit charter.
294. Where the internal audit department of the parent company of the Luxembourg IFM regularly carries
out on-site inspections of its subsidiary, it is recommended, for reasons of effectiveness, that the Luxembourg IFM coordinate, as far as possible, its internal audit plan with that of its parent company.
295. In case of use of an external expert, this expert must carry out his/her work under the internal audit
plan of the IFM by following a work programme, by producing detailed documentation on his/her work and by drafting the reports for each engagement. These reports are to be drafted in French, German or English and to be given to the person responsible for the internal audit, the senior management, where appropriate, the audit committee and the management body/governing body. Sub-section 5.3.3.7. Obligations regarding the drawing-up of reports
296. The person responsible for the internal audit function must report in writing on a regular basis, and,
where necessary, on an ad hoc basis, to the senior management and, where appropriate, to the specialised committees and management body/governing body of the IFM. These reports concern the follow-up of the recommendations, problems, shortcomings and irregularities identified in the past as well as the new problems, shortcomings and irregularities identified. Each report must specify the risks related thereto as well as their seriousness (measuring the impact) and must propose corrective measures, as well as in general the position of the persons concerned.
297. Every engagement must be subject to a written report of the internal auditor, generally for the audited
persons, the senior management and, possibly as a summary, for the management body/governing body in accordance with point 298 below. The reports must also be made available to the réviseur d'entreprises agréé (approved statutory auditor) and the CSSF. These reports must be drafted in French, German or English.
298. The person responsible for the internal audit function must prepare, at least once a year, a summary
report on his/her activities and his/her operation. As far as the operation of the internal audit function is concerned, the report must mention in particular the nature and level of reliance on external experts pursuant to Sub-section 5.3.3.5. as well as any problems which may have occurred in this context. As regards the activities, every summary report must include a statement to the senior management of the main recommendations on significant problems (existing or emerging), shortcomings and
Circular CSSF 18/698 Page 46/96 irregularities identified since the last report, the measures taken in this respect as well as the statement on the significant problems, shortcomings and irregularities identified in the last report but which have not yet been subject to appropriate corrective measures. This report must be submitted for approval to the management body/governing body and for information purposes to the senior management.
299. It is recommended that the summary report of an IFM’s internal audit function also cover, over a
period of several years (generally three years), at least the following information:
Circular CSSF 18/698 Page 47/96 in respect of certain persons, entities and groups in the context of the combat against terrorist financing, as well as to Articles 33(1) and 39(1) of CSSF Regulation 12-02 on the obligation of ongoing due diligence in this context. In this respect, EU regulations directly applicable in national law or via the adoption of ministerial regulations also apply to every IFM. The IFM must be organised so as to take into account and apply the new laws and regulations on this subject as soon as they become applicable. The IFM is also urged to follow the publications of the Financial Action Task Force (FATF) on this subject, including those related to financial sanctions relating to terrorist financing and those relating to the prevention, suppression and disruption of proliferation of weapons of mass destruction and its financing. Similarly, the IFM must follow Guidances for the Securities Sector issued by the FATF.
306. When carrying out UCI management and, where appropriate, the discretionary management and noncore services referred to in Article 101(3)(a) of the 2010 Law and Article 5(4) of the 2013 Law, every
IFM must take appropriate measures to identify and assess money laundering and terrorist financing (ML/TF) risks to which it is exposed by taking into account the risk factors, including those linked to customers, countries or geographical areas, products, services and transactions or delivery channels. The IFM must take effective measures to mitigate these risks.
307. The professional obligations laid down in the AML/CFT Law and the Law of 27 October 2010 must
be implemented effectively by every IFM. Compliance with these obligations must be subject to regular monitoring and verifications at a frequency determined according to the risks to the which the IFM is exposed and at least every time the relevant obligations change.
308. Every IFM must implement due diligence measures, in particular, on clients, initiators of UCIs,
portfolio managers to whom it delegates the management and on investment advisers. The IFM must implement due diligence measures which are adapted to ML/TF risks which may arise from the UCIs it manages.
309. Pursuant to Articles 3(7) and 4(1) of the AML/CFT Law, the IFM must also apply due diligence
measures on the assets of the UCIs it manages.
310. It should be borne in mind that, in accordance with Article 3 of CSSF Regulation 12-02, the UCI, its
IFM or, where appropriate, the respective proxies of these professionals, must put in place enhanced due diligence measures on intermediaries subscribing units on behalf of clients.
311. The IFM must also comply with Circular CSSF 17/661 adopting the joint guidelines issued by the
three European Supervisory Authorities (EBA/ESMA/EIOPA) on money laundering and terrorist financing risk factors, particularly with Chapter 9 of Title III of these guidelines, as well as any circular supplementing or repealing it.
312. Where the exercise of some AML/CFT tasks is delegated to a third party, notably the transfer agent,
the IFM is not exempt from its AML/CFT responsibility.
Sub-section 5.4.1.2. Obligation to designate an AML/CFT compliance officer at senior management level and drawing-up of a summary report on AML/CFT
313. In accordance with Article 4 of the AML/CFT Law, every IFM must designate an AML/CFT
Compliance Officer at senior management level (AML/CFT compliance officer at the management level) as well as an AML/CFT Compliance Officer. As regards the designation of an AML/CFT Compliance Officer referred to in Article 4(1)(a) of the AML/CFT Law, the IFM must take into account the size and nature of its activities.
314. The persons referred to in point 313 above must have sufficient experience and knowledge of the
Luxembourg and EU legal and regulatory framework on AML/CFT. Moreover, they must allocate sufficient time for their function, be permanently located in Luxembourg and be employed by the IFM pursuant to Article 41 of CSSF Regulation 12-02. This does not however prevent these people from having their domicile in a place allowing them, in principle, to come to Luxembourg every day.
Circular CSSF 18/698 Page 48/96
315. The IFM must communicate beforehand to the CSSF the name of the persons referred to in point 313
above supplemented by the following pieces of information and any other document which might be subsequently indicated by the CSSF:
Circular CSSF 18/698 Page 49/96 from the work of the AML/CFT Compliance Officer, the internal audit, the external réviseur (auditor) or of the CSSF’s inspections.
319. The report must be accompanied by documentation on the identification, assessment and mitigation
of ML/TF risks referred to in point 306.
Sub-section 5.4.1.3. Internal audit control
320. It should be borne in mind that the internal audit function must assess independently the policies,
monitoring and procedures, including the procedure relating to the functioning of the IFM’s approval committee referred to in point 355 below, as well as the ML/TF risk management models of the IFM and report to the senior management and to the management body/governing body of the IFM by submitting them at least once a year a summary report on the compliance with the AML/CFT obligations. The internal audit must show diligence by ensuring that its recommendations or corrective measures are effectively carried out.
Section 5.4.2. Obligations applicable to the IFM according to the manner in which the
relationship with marketing intermediaries and the function of registrar agent is organised
321. The following cases may occur, on the understanding that several identified cases may apply to one
and the same IFM, depending on the nature of the relations.
Case (a): the IFM is in a direct relationship i) with the intermediaries which ensure the marketing and act on behalf of clients and/or ii) with the direct investors and ensures itself the function of registrar agent. Case (b): the IFM is in a direct relationship i) with the intermediaries which ensure the marketing and act on behalf of clients and/or ii) with the direct investors and the registrar agent function has been delegated to one or more6 registrar agents. Case (c): the IFM is in no direct relationship i) with the intermediaries which ensure the marketing and act on behalf of clients and/or ii) with the direct investors and the registrar agent function has been delegated to one or more7 registrar agents. Case (d): the AIFM performs neither the additional marketing function of the UCIs it manages nor the registrar agent function.
322. Depending on the case which applies to the IFM, the latter is subject to the following provisions:
Provisions applicable to IFMs in case (a):
323. The IFM must implement its own due diligence measures on the intermediaries who ensure the
marketing and/or on the direct investors in accordance with the legal and regulatory provisions in force.
324. The relationships with the intermediaries which market UCIs managed by the IFM must be
formalised in a written contract in order to establish the respective responsibilities with regard to compliance with AML/CFT obligations of the intermediary and of the IFM.
6 Case of an IFM managing several UCIs, all compartments combined.
7 Case of an IFM managing several UCIs, all compartments combined.
Circular CSSF 18/698 Page 50/96
325. The IFM must submit annually a list of all the marketing intermediaries with whom it is in a direct
relationship to the CSSF. This list must be provided within five months following the end of the financial year of the IFM.
326. Moreover, the IFM must put in place the measures necessary to ensure that the intermediaries comply
with the provisions of this section as well. The due diligence measures must be adapted to the ML/TF risks which may arise from these intermediaries.
327. The IFM must also comply with the provisions referred to in Section 6.2.3. (Initial due diligence and
ongoing monitoring of the delegates) with respect to the marketing intermediaries, insofar as some issues are not covered in point 328 below.
328. Furthermore, pursuant to Article 4 of the AML/CFT Law, the IFM must establish internal policies,
controls and procedures which include, among others, arrangements for due diligence on intermediaries who ensure the marketing as laid down in Article 3 of the AML/CFT Law. These arrangements must take the form, among others, of initial and ongoing due diligence covering at least the points referred to in Article 3(2) of the AML/CFT Law and the following aspects (non-exhaustive list):
a) the types of intermediaries chosen by the IFM and the collection of information on the country of establishment of the intermediary and the applicable AML/CFT legal and regulatory framework, the supervisory authority and regime applicable to it, the ownership and control structure of the intermediary; b) the collection of sufficient information to understand fully the nature of the intermediary and to determine from publicly available information the reputation of the intermediary and the quality of supervision; c) the collection of documents required pursuant to the IFM’s AML/CFT obligations when entering into a business relationship with an intermediary (Know Your Intermediary); d) the distribution channels, the risks of which must be assessed in accordance with the factors referred to particularly in points 215 and 216 of the Joint Guidelines (EBA/ESMA/EIOPA) on ML/TF risk factors adopted by way of Circular CSSF 17/661; thus, for example, the use of unclear or complex distribution channels and the fact that the intermediary is located in a jurisdiction associated with higher ML/TF risks are high risk factors requiring the implementation of an enhanced monitoring of these intermediaries; e) the country risk to be assessed in accordance with the factors referred to particularly in point 217 of the Joint Guidelines (EBA/ESMA/EIOPA) on ML/TF risk factors adopted by way of Circular CSSF 17/661.
329. The IFM using intermediaries which ensure the marketing and act on behalf of clients as provided
for in Article 3 of CSSF Regulation 12-02 must, according to the terms of Article 28 of CSSF Regulation 12-02 to which Article 3 of the same regulation refers, carry out among others:
a) a periodic review according to the risk and, where applicable, an update of the information on which the decision to enter into a relationship was based; b) a re-examination of this relationship, where information is obtained which is likely to weaken the trust in the AML/CFT mechanism of the intermediary's country of establishment or in the effectiveness of the AML/CFT controls set by the latter; c) verifications and periodic assessments according to the risk so that the intermediary ensures at all times the compliance with the subscribed commitments, notably with respect to the communication, without delay and upon request, of relevant identification data of clients.
330. The ongoing monitoring operations of intermediaries which market and act on behalf of clients must
for example concern (non-exhaustive list):
Circular CSSF 18/698 Page 51/96 a) the monitoring of the marketing policy with the implementation of a procedure enabling the IFM to be involved in decision-making concerning new countries of registration; b) the monitoring of the existence of contracts or any other document up to date which establish the responsibilities of the intermediary and of the IFM, respectively; c) the regular screening of the lists of financial sanctions relating to terrorist financing as well as a screening of the persons, entities or groups mentioned in the United Nations Security Council resolutions and acts adopted by the European Union as referred to in point 305; d) the monitoring of the compliance of the intermediaries with their AML/CFT obligations.
331. As regards direct investors, the IFM must at least ensure the following aspects (non-exhaustive list):
a) the collection of documents required pursuant to the IFM’s AML/CFT obligations when entering into a business relationship (Know Your Customer); b) the country risk to be assessed in accordance with the factors referred to particularly in point 217 of the Joint Guidelines (EBA/ESMA/EIOPA) on ML/TF risk factors adopted by way of Circular CSSF 17/661; c) the regular screening of the lists of financial sanctions relating to terrorist financing as well as a screening of the persons, entities or groups mentioned in the United Nations Security Council resolutions and acts adopted by the European Union as referred to in point 305.
332. As regards the AML/CFT obligations of the IFM which also performs the registrar agent function,
these obligations are the same as those laid down in points 323 to 331 above, except for points 324, 325, 330(a) and (b). Provisions applicable to IFMs in case (b):
333. The IFM referred to in this case must comply with the provisions referred to in points 323 to 331
with respect to direct relationship i) with the intermediaries which ensure the marketing and act on behalf of clients and/or ii) with the direct investors.
334. In connection with the delegation of the registrar agent function, the IFM must, given its obligations
as specified in Section 5.4.1., comply with the provisions of Chapter 6 (Specific organisational provisions) among which in particular Section 6.2.2. (Obligation to conclude a contract), Section
6.2.3. (Initial due diligence and ongoing monitoring of delegates) and the relevant provisions referred
to in Sub-section 6.4.3.2. (Due diligence and ongoing monitoring). In particular, the contract between the IFM and the registrar agent provides for the latter’s obligation to make available to the IFM any information necessary for the performance by the IFM of its initial due diligence and ongoing monitoring of this registrar agent.
335. This contract between the two parties also provides for the obligation to make any information
available to each other so that each of the two parties can comply with its AML/CFT obligations. Finally, the contract must allow the IFM and registrar agent to determine their respective responsibilities with regard to AML/CFT obligations, including the provisions referred to in points 323 to 331 of this circular. Provisions applicable to IFMs in case (c):
336. In connection with the delegation of the registrar agent function, the IFM must comply with the
provisions of Chapter 6 (Specific organisational provisions) among which in particular Section 6.2.2. (Obligation to conclude a contract), Section 6.2.3. (Initial due diligence and ongoing monitoring of delegates) and the relevant provisions referred to in Sub-section 6.4.3.2. (Due diligence and ongoing monitoring), in view of its obligations as specified in Section 5.4.1. In particular, the contract between the IFM and the registrar agent provides for the latter’s obligation to make available to the IFM any information necessary for the performance by the IFM of its initial due diligence and ongoing monitoring of this registrar agent.
Circular CSSF 18/698 Page 52/96
337. This contract between the two parties also provides for the registrar agent to make available any
necessary information to the IFM so that the latter can comply with its AML/CFT obligations. Finally, the contract must allow the IFM and registrar agent to determine their respective responsibilities with regard to AML/CFT obligations, including the provisions referred to in points 323 to 331 of this circular, except for points 324, 325, 330(a) and (b). Provisions applicable to AIFMs in case (d):
338. Given its obligations as specified in Section 5.4.1. above, the AIFM which performs neither the
additional marketing function of the UCIs it manages nor the registrar agent function must implement procedures and arrangements allowing it to meet its responsibility in the context of AML/CFT.
339. In particular, the AIFM must be able to ensure that the provisions of points 323 to 331 are complied
with. To this end, the members of the board of directors or the members of any other managing body, respectively, which represent the UCI pursuant to the instruments of incorporation must make available any necessary information to the AIFM so that the latter can comply with its AML/CFT obligations. In particular, a document signed by the AIFM and the UCI must include this availability obligation. Sub-chapter 5.5. Requirements with respect to organisation and procedures
Section 5.5.1. Management Information and internal reporting system
340. According to Article 5(1)(e) of CSSF Regulation 10-4 and Article 57(1)(e) of Delegated Regulation
(EU) 231/2013, every IFM must maintain adequate and orderly records of its business and internal organisation.
341. To this end, every IFM must draw up Management Information enabling the monitoring of its
activities and that of its delegates. It is important that this Management Information includes, among others, the monitoring of the activities of the IFM and its UCIs, the result of the relevant controls and analyses and the monitoring of incidents.
342. In this context, the Management Information must cover, at least:
Circular CSSF 18/698 Page 53/96
Circular CSSF 18/698 Page 54/96
Section 5.5.3. Approval of new business relationships and new products
353. This section applies to any changes in the activity of the IFM (in terms of coverage of markets and
clients, products and services).
354. Thus, every IFM must implement arrangements enabling it to identify and assess risks, including
ML/TF risks as referred to in Sub-chapter 5.4. (Organisation of the fight against money laundering and terrorist financing), in particular regulatory and operational risks related to the launch of a UCI, a compartment or a new type of assets, the creation of new business relationships (including, in particular, with a new UCI initiator or a delegate or any business relationship during the exercise of discretionary management and non-core services, where appropriate), in the event of the IFM’s intervention on new markets or in new geographical areas. To this end, the IFM must refer to Chapter 9 of Title III of the Joint Guidelines (EBA/ESMA/EIOPA) on ML/TF risk factors adopted by Circular CSSF 17/661, in particular, points 210 to 217.
355. These arrangements must be based on the implementation of adequate procedures and the use of an
approval committee within the IFM. The procedures must provide for the consultation with the risk management and compliance functions as well as escalation measures, particularly in case of disagreement between the stakeholders.
356. Where appropriate, the IFM must cooperate with the intermediary ensuring the marketing during the
implementation of the product approval process which includes the definition of the target market of end clients, the assessment of all relevant risks to such identified target market and the verification of the adequacy of the distribution strategy with the identified target market in accordance with point (1) of Article 98 of the Law of 30 May 2018 on markets in financial instruments and transposing Directive 2014/65/EU of the European Parliament and of the Council of 15 May 2014 on markets in financial instruments and amending Directive 2002/92/EC and Directive 2011/61/EU.
Section 5.5.4. Manual of procedures
357. Every IFM must, in accordance with Article 5(1)(a), (b) and (d) of CSSF Regulation 10-4 and Article
57(1)(a), (b) and (d) of Delegated Regulation (EU) 231/2013, have a precise and clear manual of procedures which describes, in particular, its internal functioning, the allocation of tasks among its staff as well as the reporting lines. The manual of procedures may include the compliance policy referred to in point 233. Where appropriate, the procedures for exchanging information with delegates and the controls carried out on them in accordance with the provisions of Chapter 6 (Specific organisational provisions) must be detailed in the manual of procedures.
358. This manual of procedures must be available at the head office of the IFM, accessible to its staff and
kept up-to-date taking into account the evolution of the IFM’s business.
359. Every new request for authorisation of an IFM must include a confirmation relating to the
establishment of such a manual.
Section 5.5.5. Claim and complaint handling
360. Every IFM must have a complaint management policy in accordance with Article 15 of CSSF
Regulation 16-07. This policy must be defined, endorsed and implemented by the senior management of the IFM. The complaint management policy must be set out in a written document and must be formalised in an internal complaint resolution procedure made available to all relevant staff. This procedure must be effective and transparent in order to handle the complaint reasonably and promptly in full compliance with the provisions of above-mentioned regulation. It must reflect the concern for objectivity and for ascertaining the truth. It must also enable the identification and mitigation of any possible conflicts of interest.
361. The name of the conducting officer responsible for the handling, centralisation and monitoring of
complaints must be communicated to the CSSF. Subject to prior notification to the CSSF and in accordance with Article 15(3) of CSSF Regulation 16-07, the person responsible at senior management level may delegate internally the complaint management.
Circular CSSF 18/698 Page 55/96
362. In accordance with Article 16(3) of CSSF Regulation 16-07 and as detailed in Section 3 of Circular
CSSF 17/671, the conducting officer responsible for complaint handling must communicate to the CSSF, on an annual basis, a table including the number of complaints registered by the professional, classified by type of complaints, as well as a summary report of the complaints and of the measures taken to handle them. In addition, the reasons for the complaints as well as the progress made in their handling must be stated. This summary report may be included in the report of the compliance function referred to in point 257.
363. Every IFM must submit this table and summary report to the CSSF within five months following the
end of the financial year of the IFM.
364. Moreover, the initial authorisation request of an IFM must comprise a description of the procedures
for handling claims and complaints implemented by the IFM.
365. A specific mandate for the handling of complaints may be given to a specialised third party
established in Luxembourg or abroad. For example, the mandate may be given to an entity of the group to which the IFM belongs.
366. The IFM must communicate a list of third parties authorised to handle complaints to the CSSF
annually. The CSSF must receive this document within five months following the end of the financial year of the IFM.
367. Specific provision applicable to ManCos: The ManCo must also comply with Article 7 of CSSF
Regulation 10-4. In particular, the information concerning this procedure for handling complaints must be made available to investors free of charge.
368. Specific recommendation to AIFMs: It is recommended that the AIFM also comply with the principle
referred to in point 367.
Section 5.5.6. Personal transactions
369. Pursuant to Articles 14 of CSSF Regulation 10-4 and 63 of Delegated Regulation (EU) 231/2013,
the IFM must have written procedures regarding personal transactions. A list of all personal transactions notified to or identified by the IFM must be available at its head office in Luxembourg.
370. In accordance with Article 14(2) of CSSF Regulation 10-4 and Article 63(2) of Delegated Regulation
(EU) 231/2013, in case of delegation of some activities of the IFM to third parties, the above procedures must allow the IFM to ensure that the entity carrying out the activity maintains a record of personal transactions entered into by any relevant person and provides that information to the IFM promptly on request.
371. At the moment of its authorisation, the IFM must confirm that a written procedure regarding personal
transactions has been put in place. This procedure may be based on the one established in this respect at the level of the group to which the IFM belongs. It must be updated regularly. The CSSF reserves the right to request a copy of this procedure at any time.
Section 5.5.7. Management of conflicts of interest
Specific provisions applicable to ManCos:
372. In accordance with Article 109(1)(b) of the 2010 Law, the ManCo must be structured and organised
in such a way as to minimise the risk that conflicts of interest between the company and its clients, between two of its clients, between one of its clients and a UCITS or between two UCITS prejudice the interests of UCITS or clients.
373. The ManCo must try to avoid conflicts of interest and when they cannot be avoided, ensure that the
UCITS it manages are fairly treated in accordance with Article 111(d) of the 2010 Law.
Circular CSSF 18/698 Page 56/96
Specific provisions applicable to AIFMs:
374. In accordance with Article 13 of the 2013 Law, the AIFM must take all reasonable steps to identify
conflicts of interest that arise in the course of managing AIFs between:
a) the AIFM, including its managers, employees or any person directly or indirectly linked to the AIFM by control and the AIF managed by the AIFM or the investors in that AIF; b) the AIF or the investors in this AIF and another AIF or the investors in that other AIF; c) the AIF or the investors in this AIF and another client of the AIFM; d) the AIF or the investors in this AIF and a UCITS managed by the AIFM or the investors in that UCITS; or e) two clients of the AIFM.
375. In accordance with Article 11(1)(d) of the 2013 Law, the AIFM must take all reasonable steps to
avoid conflicts of interest and, when they cannot be avoided, to identify, manage and monitor and, where appropriate, disclose, these conflicts of interest in order to prevent them from adversely affecting the interests of the AIFs and their investors and to ensure that the AIFs they manage are treated fairly.
376. Provision applicable to IFMs: The IFM must try to avoid conflicts of interest and, when they cannot
be avoided, ensure that the UCIs it manages are treated fairly.
Sub-section 5.5.7.1.: Conflicts of interest policy
377. In accordance with Article 20 of CSSF Regulation 10-4 and Article 31 of Delegated Regulation (EU)
231/2013, an IFM must establish, implement and maintain an effective conflicts of interest policy. This policy must be set out in writing and must be appropriate to the size and organisation of the IFM and the nature, scale and complexity of its business. This policy must include the following:
Circular CSSF 18/698 Page 57/96
Circular CSSF 18/698 Page 58/96
389. The IFM subject to Chapter 15 of the 2010 Law must also comply with the guidelines of the European
Securities and Markets Authority ESMA/2016/5758 .
390. The AIFM must comply with the guidelines of the European Securities and Markets Authority
ESMA/2016/5799
.
391. The IFM which intends to take a proportionate approach to compliance with a remuneration principle
must inform the CSSF thereof and explain the reasons for it. However, this principle does not exempt an IFM from implementing a remuneration policy.
Section 5.5.10. Exercise of voting rights
392. Pursuant to Article 23 of CSSF Regulation 10-4 and Article 37 of Delegated Regulation (EU)
231/2013, the IFM must, among others, develop an adequate and effective strategy for determining when and how voting rights attached to instruments held in the managed portfolios are to be exercised, to the exclusive benefit of the UCI concerned and its investors.
393. Any UCI that has not specifically mandated the IFM to exercise the voting rights attached to the
instruments held in its portfolio, must develop its own strategy for the exercise of voting rights.
394. It is also acceptable for an IFM to refer either to the strategies developed in this regard by the group
to which it belongs or to the recognised international standards when developing its own strategy for exercising voting rights. The use of a delegate’s strategy, where appropriate, is allowed provided that the IFM ensures during its initial due diligence and ongoing monitoring as referred to in Section
6.2.3. (Initial due diligence and ongoing monitoring of delegates) that the delegate’s strategy
complies with the provisions of point 392 above.
395. A brief description of this strategy must be made available to investors free of charge, in particular
by way of a website.
396. At the moment of its authorisation, the IFM must confirm that an adequate and effective strategy has
been put in place permitting the exercise of voting rights attached to the instruments held in the portfolios in the exclusive interest of the UCIs concerned. This procedure must be regularly updated. The CSSF reserves the right to request a copy of this procedure at any time.
Section 5.5.11. Obligations of the IFM to monitor compliance with the obligations under EMIR
397. EMIR imposes obligations on any UCI qualifying as financial or non-financial counterparty
according to Article 2(8) or Article 2(9), respectively, of EMIR which takes positions in derivative contracts, particularly:
8 https://www.esma.europa.eu/sites/default/files/library/2016-575_ucits_remuneration_guidelines.pdf 9 https://www.esma.europa.eu/sites/default/files/library/2016-579_aifmd_remuneration_guidelines_0.pdf
Circular CSSF 18/698 Page 59/96
399. Moreover, since the obligations introduced by EMIR aim to limit the counterparty risk and
operational risk when the UCIs take positions in OTC derivative contracts, the risk management policy referred to in Sub-section 5.3.1.4. as well as the risk management procedure referred to in Sub-section 5.3.1.5. established by the permanent risk management function must include the procedures and arrangements necessary to comply with the obligations under EMIR.
400. The IFM must in particular have procedures and arrangements to:
Circular CSSF 18/698 Page 60/96
404. The IFM must in particular have procedures and arrangements to:
Circular CSSF 18/698 Page 61/96
Circular CSSF 18/698 Page 62/96
421. The provisions of this sub-chapter must also be applied when the IFM delegates one or more
functions included in the activity of collective portfolio management as defined in Annex II of the 2010 Law or the functions included in Annex I of the 2013 Law respectively, including the delegation on a cross-border basis and in case of management of a non-regulated UCI.
422. The requirements which apply when delegating the performance of functions on behalf of the IFM
must apply mutatis mutandis in case the delegate sub-delegates the functions which were delegated to it and in case of any subsequent level of sub-delegation. The conditions associated with the subdelegation are subject to the same requirements as those referred to in this sub-chapter. In practice, this means that the IFM must ensure that its delegate also complies with the provisions laid down in this sub-chapter. In addition, the IFM must inform the CSSF beforehand if the delegate carries out a partial or full sub-delegation of its activity.
423. Specific provision applicable to AIFMs: The AIFM must notably comply with the conditions
applicable to sub-delegation as defined in Article 18(4), (5) and (6) of the 2013 Law and Article 81 of Delegated Regulation (EU) 231/2013. In particular, the AIFM must give its consent prior to the sub-delegation.
Section 6.2.1. Obligation to notify the CSSF
424. In accordance with Article 110(1)(a) of the 2010 Law and Article 18(1) of the 2013 Law, the CSSF
must be notified beforehand when the IFM intends to delegate one or more of the following functions:
portfolio management, risk management, UCI administration and valuation.
425. To this end, the IFM must submit to the CSSF beforehand an update of the programme of activity
referred to in Chapter 9 of this circular, detailing the functions it intends to delegate, the identity of the entities to which the functions will be delegated and their country of establishment as well as, where appropriate, the name of the supervisory authority of these entities. The IFM must submit to the CSSF on a yearly basis a list of all its delegates of the functions referred to in point 407 and, where appropriate, the valuation function. This list must be provided within five months following the end of the financial year of the IFM.
426. The notification file must also include the IFM’s procedures for monitoring the activities of the
undertakings to which functions have been delegated. This description must contain the necessary information allowing the CSSF to verify whether the preconditions have been effectively met.
427. The CSSF reserves the right to request at any time the documentation regarding the due diligence
carried out at the time the delegate has been chosen.
428. In case of change of the delegate or when the IFM wants to perform itself one or more functions or
activities which had been previously delegated without prejudice to compliance with Articles 110(1)(f) of the 2010 Law and Article 18(f) of the 2010 Law, the IFM must seek the CSSF’s approval beforehand and submit its updated programme of activity. Specific provisions applicable to AIFMs:
429. For each EU AIF it manages and for each AIF it markets in the EU, the IFM must, among others,
make available to investors of the AIF, before it invests in this AIF in accordance with the management regulations or instruments of incorporation of the AIF, a description of all management functions referred to in Annex I of the 2013 Law delegated by the IFM and all safe-keeping functions delegated by the depositary, the identity of the delegate and any conflict of interest which might arise from these delegations.
430. In accordance with the provisions referred to in Article 76 of Delegated Regulation (EU) 231/2013,
the AIFM must communicate the objective reasons for delegation, including when the delegate belongs to the same group as the AIFM. Specific provisions applicable to ManCos:
431. The prospectuses of the UCITS list the functions which the IFM has been authorised to delegate.
Circular CSSF 18/698 Page 63/96
432. It is recommended that the ManCo include the information referred to in point 430 in the notification
to the CSSF.
Section 6.2.2. Obligation to draw up a contract
433. A written contract must be concluded between the IFM and the delegate.
434. In accordance with Article 110(1)(f) of the 2010 Law and Article 18(f) of the 2013 Law, the mandate
must not prevent the persons who conduct the business of the IFM from giving further instructions at all times to the undertaking to which functions have been delegated or from withdrawing the mandate with immediate effect when this is in the interest of investors. The drafting of the contracts must take these requirements into account and specify the terms thereof.
435. The contract must clearly set out the rights and obligations of each party.
436. The contract between the IFM and the delegate must provide a right of access for the IFM to the
documents relating to transactions carried out by the delegate as well as data on UCIs upon simple request even in electronic form. The delegate may deny the request if this request would lead the delegate to act in breach of the applicable legislation in its country of establishment.
437. Moreover, the contract must provide the right for the IFM to carry out an on-site visit at a frequency
and under the terms to be laid down in the contract, for the purposes of exercising its due diligence and ongoing monitoring activities in accordance with Section 6.2.3., particularly the AML/CFT monitoring of the registrar agent. The delegate may deny the request if this request would lead the delegate to act in breach of the applicable legislation in its country of establishment.
438. The mandate must not prevent the effectiveness of supervision of the IFM; in particular, it must not
prevent the IFM from acting, or the UCI from being managed, in the best interests of its investors.
439. To this end, the delegation must be structured so that compliance with the rules of conduct laid down
in Articles 111 of the 2010 Law and the other operating conditions referred to in Article 11 of the 2013 Law, as specified in Section 5.5.8. (Rules of conduct) above, are ensured and may be monitored at any time.
440. The IFM and the delegate must establish, implement and maintain a business continuity plan for the
recovery of the business after a disaster or any other exceptional event which provides for a regular testing of the backup facilities, whenever this appears necessary in view of the nature of the delegated task or function.
Section 6.2.3. Initial due diligence and ongoing monitoring of delegates
Sub-section 6.2.3.1. General principles
441. Any use of a delegate within the meaning of point 1(9) of this circular must be subject to a prior
written initial due diligence carried out on the third party by the IFM.
442. In accordance with Article 110(1)(f), (g) and (h) of the 2010 Law and Article 18(1)(f) of the 2013
Law, the IFM must be able to effectively monitor and control at any time the delegated task. After having received the mandate, the delegate must be subject to proper ongoing monitoring by the IFM. Sub-section 6.2.3.2. Establishment of a delegation framework procedure
443. All IFMs must define and implement a procedure which covers all aspects of delegation.
444. In particular, the procedure must describe the process of selection and change of a delegate.
445. All IFMs must implement procedures and arrangements allowing them to ensure that the delegated
activity(ies) is(are) carried out in compliance with the legal and regulatory provisions in force.
446. The procedure must include the implementing rules for initial and periodic due diligence carried out
by the IFM on all its delegates and the requirements applicable in case of sub-delegation, as described in points 422 and 423.
Circular CSSF 18/698 Page 64/96
447. The procedure must describe the measures taken which allow the persons who conduct the business
of the IFM and its operating staff to effectively monitor the business of the undertaking to which the mandate has been given on an ongoing basis, in order to ensure that the exercise and quality of the activities are monitored as if they were carried out internally. The procedure must set out reporting requirements to which the delegates are subject. The drawing-up of the contract referred to in Section
6.2.2. above must take these obligations into account.
448. In particular, the procedure must determine the nature, scope and frequency of the periodic due
diligence to be carried out on delegates taking into account a risk-based approach. When carrying out its risk assessment, the IFM must take into account not only the risks incurred by every delegate but also the number of delegates it uses.
449. The IFM must implement a multi-year plan (generally three years) for conducting periodic due
diligence on delegates. This plan must be updated taking into account the risk-based approach determined by the IFM and provided that the principle of proportionality which the IFM may rely on to increase or reduce this update frequency is applied.
450. Moreover, the procedure must describe the escalation measures and decision-making procedures
regarding delegation.
451. Under no circumstances can the monitoring of the activities delegated to a third party be delegated.
Thus, the IFM must have staff in Luxembourg which are sufficient in number and qualified to carry out a proper monitoring of the delegated activities taking into account the risks arising from the delegation(s) identified by the IFM and the number of delegates. The procedure must identify which departments or staff members of the IFM are in charge of the ongoing monitoring of delegates.
452. The IFM may take into account transversal or specific skills existing within the group to which it
belongs when implementing its control arrangements. In that case, the IFM must participate in the process of selection of delegates and of maintaining the delegation relationship. In particular, the IFM must ensure to have access to documents received during the initial due diligence and ongoing monitoring operations.
453. The procedure must describe the measures allowing the IFM to ensure the continuity of operations
in case of withdrawal of the mandate.
454. Moreover, the IFM must ensure that the data protection is guaranteed at all times.
Sub-section 6.2.3.3. Details on the initial due diligence
455. When carrying out the initial due diligence, the IFM must, among others, identify and assess all risks
arising from the delegation, in particular, the operational, financial, legal and reputational risks in order to manage them appropriately in accordance with the IFM’s risk management policy.
456. The initial due diligence must allow the IFM to ensure that the undertaking to which functions will
be delegated is qualified and capable of performing these functions, depending on the nature of the delegated functions, in compliance with the legal, regulatory and contractual obligations.
457. Moreover, the initial due diligence must allow the IFM to ensure the delegate’s ability to provide the
information necessary to fulfil its ongoing monitoring obligations. During the initial due diligence, the IFM must assess its ability to ensure the appropriate ongoing monitoring of the delegate given the identified risks and the specificities of the delegate. Thus, for example, the geographical location of the delegate cannot, in principle, impede regular on-site visits.
458. The IFM must, among others, analyse the organisational structure of the delegate. It must verify that
the delegate has taken appropriate measures to comply in particular with the requirements regarding the organisation, conflicts of interest and rules of conduct laid down in CSSF Regulation 10-4 as well as the other operating conditions referred to in Delegated Regulation (EU) 231/2013. The abovementioned requirement also applies to partial delegation of one or more functions. The IFM must also effectively monitor the compliance with these requirements by the third party.
Circular CSSF 18/698 Page 65/96
459. Besides the authorisations which may be required by applicable regulations, the entities to which
functions are delegated must prove that they have adequate human and technical resources in view of the delegated functions.
460. In their assessment of risks arising from delegation, as referred to in point 448 above, and in order to
assess the quality of the contemplated delegate, the IFM must take into account all relevant criteria including in particular the following listed information (non-exhaustive list):
Circular CSSF 18/698 Page 66/96
Circular CSSF 18/698 Page 67/96
Ongoing monitoring
471. The ongoing monitoring obliges the IFM to implement control arrangements which allow the
monitoring of the business of the delegates within the meaning of point 1(9) of this circular.
472. Moreover, this requirement obliges the IFM to implement control arrangements which allow the
senior management and its staff to access the data documenting the activities exercised by the delegate(s) for and on behalf of the IFM and the UCIs under its management.
473. The Management Information referred to in Section 5.5.1. must also allow the monitoring of the
delegates’ activity.
474. Thus, the conducting officers must regularly receive detailed reports on the results of the control
arrangements, including in particular key performance indicators, for all the UCIs managed by the IFM. The frequency of submission and the detail of such reports will be determined by the profile of the managed UCIs and their inherent risks. The IFM must determine and implement its own key performance indicators when the key performance indicators provided by the delegate are not sufficient to ensure an appropriate ongoing monitoring.
475. Moreover, the IFM must define and implement a methodology to analyse the results of the control
arrangements and set up its own warning systems in order to monitor its delegates according to a risk-based approach. The analysis of this information must be documented in writing and made available to the CSSF upon request.
476. In the case where the delegate uses a standard for the internal control such as for example the ISAE
3402, the IFM may take this information into account for the organisation of its monitoring of the delegate. Sub-chapter 6.3. Organisation of the portfolio management function
Section 6.3.1. Specificities related to the internal performance of the portfolio management
function
Sub-section 6.3.1.1. Implementation of a portfolio management procedure
477. In accordance with Article 26 of CSSF Regulation 10-4 and Article 18 of Delegated Regulation (EU)
231/2013, every IFM must apply a high standard of diligence in the selection and ongoing monitoring of investments of the managed UCIs. The IFM must establish, implement and apply written policies and procedures on due diligence and implement effective arrangements for ensuring that investment decisions are carried out in compliance with the objectives, the investment strategy and, where appropriate, the risk limits of the managed UCIs. In this context, every IFM must determine and implement a portfolio management procedure. This procedure must cover at least the following information:
Circular CSSF 18/698 Page 68/96
478. Specific provision applicable to AIFMs: The AIFM must, in addition, comply with Articles 18 and
19 of Delegated Regulation (EU) 231/2013. In accordance with Article 19 of Delegated Regulation (EU) 231/2013 concerning investments in assets of limited liquidity which are preceded by a negotiation phase, the portfolio management procedure must describe in particular:
Circular CSSF 18/698 Page 69/96 instruments in which the UCI may invest (“white list”), this list must be subject to prior analysis and validation by the IFM;
Circular CSSF 18/698 Page 70/96 instructions which may be given from time to time by the management body/governing body of the IFM, by the management body/governing body of the UCI which adopted the form of a company or by the persons who conduct the business of the IFM. In the event of a change of one of these elements, the contract will be amended in good time.
493. In view of the due diligence obligation provided for in Article 26 of CSSF Regulation 10-4 and
Article 18 of Delegated Regulation (EU) 231/2013, the IFM must ensure that the investment
decisions taken are based on qualitative, quantitative, reliable and up-to-date research. Furthermore, it must ensure that these investment decisions are carried out in compliance with the objectives, the investment strategy and the risk limits of the managed UCIs.
494. Where an IFM has delegated the portfolio management, it must, from the moment it enters into the
relationship, monitor on an ongoing basis that each delegate has suitable IT systems in order to meet the requirements of Articles 8, 9, 15 and 16 of CSSF Regulation 10-4 and Articles 58, 59, 64 and 65 of Delegated Regulation (EU) 231/2013. Sub-section 6.3.2.2. Due diligence and ongoing monitoring
495. In addition to the elements referred to in Sub-section 6.2.3.3. Details on the initial due diligence, the
IFM delegating the portfolio management function should, for example, include the following elements (non-exhaustive list) to its due diligence assessment:
Circular CSSF 18/698 Page 71/96
Sub-chapter 6.4. Organisation of the function of UCI administration
Section 6.4.1. General obligations
497. In view of the provisions of CSSF Regulation 10-4 and Delegated Regulation (EU) 231/2013, every
IFM must have established (with reference to Article 9 of CSSF Regulation 10-4) or must establish (with reference to Article 59 of Delegated Regulation (EU) 231/2013), implement and maintain accounting policies and procedures which comply with the accounting rules of the UCI’s home Member State and which ensure that the net asset value of each UCI is accurately calculated on the basis of its accounts and that subscription and redemption orders are properly executed at that net asset value.
498. The accounting records shall be kept in such a way that all assets and liabilities of a UCI can be
directly identified at all times. If the UCI in question has different compartments, separate accounts must be maintained for those compartments.
499. The IFM must ensure that, for UCIs with multiple compartments, separate information on each
compartment must be provided in their annual financial reports in order to allow the investor to have clear and accurate information on the compartment in which s/he invests.
500. An IFM must establish appropriate procedures to ensure the proper and accurate valuation of the
assets and liabilities of the UCIs or, where appropriate, of their compartments. In the case of delegation, these procedures include, in particular, the implementation by the IFM of its own control and monitoring system referred to in point 518 below.
501. The principles laid down above must apply to all types of UCIs managed by the IFM, including nonregulated UCIs managed, where appropriate, by the IFM.
502. The IFM must designate a person among its staff who is responsible for the accounting administration
of UCIs. This function may be combined with other functions. The name of this person and of every person succeeding him/her in office must be communicated forthwith to the CSSF.
Section 6.4.2. Specificities related to the wholly or partially internal UCI administration
function
503. Every IFM which intends to exercise one or more activities falling under the administration function
within the meaning of Annex II of the 2010 Law or Annex I of the 2013 Law must inform the CSSF beforehand in order to get a specific approval to act as UCI administration in addition to its authorisation as IFM. To this end, the IFM must duly fill in and submit the questionnaire Application for approval as administration of a UCI available on the CSSF’s website.
504. Every IFM which intends to delegate one or more tasks falling under the UCI administration function
must inform the CSSF beforehand in order to get a specific approval to act as UCI administration and delegate some tasks relating to the UCI administration function in addition to its authorisation as IFM. To this end, the IFM must duly fill in and submit the questionnaire Application in case of outsourcing of administration tasks for UCI available on the CSSF website.
505. Every IFM must implement procedures and arrangements allowing it to ensure that the delegates
comply with the legal and regulatory provisions in force.
506. An IFM which is directly in charge of the UCI administration, including the maintenance of the
register of the unit-holders must make the appropriate arrangements for suitable IT systems so as to permit the timely and proper recording of each subscription or redemption order in accordance with Articles 8 and 16 of CSSF Regulation 10-4 as well as Articles 58 and 65 of Delegated Regulation (EU) 231/2013.
507. The IFM must have an IT environment permitting to comply with the accounting principles referred
to in Section 6.4.1. above.
Circular CSSF 18/698 Page 72/96
Section 6.4.3. Specificities related to the delegation of the UCI administration
Sub-section 6.4.3.1. Specific conditions
508. In addition to the general provisions on the delegation framework as laid down in Sub-chapter 6.2.
(Delegation framework) above, the following specific conditions are applicable.
509. An IFM established in Luxembourg may be authorised to delegate the administration of a UCI that
it manages to a third party which has all the necessary authorisations and a suitable organisation in order to perform this function.
510. However, different rules of delegation in the area of UCI administration are applicable depending on
the home Member State of the UCI.
511. In the case where a Luxembourg IFM manages a regulated Luxembourg UCI, it is authorised to
delegate the administration of this UCI to a delegate established in the territory of Luxembourg (i.e. bank, professional of the financial sector, IFM) which has all the necessary authorisations and a suitable organisation to perform this function.
512. Where a Luxembourg IFM intends to manage UCIs established in a country other than Luxembourg
and to use an administrative agent established outside Luxembourg, the IFM must also inform the CSSF in accordance with the provisions referred to in Section 6.2.1. (Obligation to notify the CSSF) and must apply the provisions of Section 6.2.3. (Initial due diligence and ongoing monitoring of delegates). As part of its due diligence process, it must verify in particular that the delegate has an organisation permitting to ensure the administration of the UCI(s) concerned. In any case, the third party must have all the necessary authorisations, if applicable in the country in question, and be qualified and capable of undertaking the function in question. In the notification to the CSSF, it must demonstrate that such a delegation complies with the legal and regulatory provisions in force in the country of establishment of the UCI and that the delegation is permitted by the supervisory authority of the UCI.
513. It should be borne in mind that, in all the above-mentioned cases, the IFM must ensure that the third
party in charge of the administration employs accounting procedures and policies (i.e. application of the accounting rules of the home country of the UCI, separate accounting for UCIs with multiple compartments, means permitting the identification and measurement of assets and liabilities of the UCI) when applying due diligence measures, such as referred to in Article 9 of CSSF Regulation 10- 4 and Article 59 of Delegated Regulation (EU) 231/2013.
514. Every IFM must implement procedures and arrangements allowing it to ensure that the delegates
comply with the legal and regulatory provisions in force.
515. Where an IFM has delegated the UCI administration, including the maintenance of the register of
unit-holders, to one or more third parties, it must, from the moment it enters into the relationship, monitor on an ongoing basis that each delegate has suitable IT systems in order to meet the requirements of Articles 8, 9, 15 and 16 of CSSF Regulation 10-4 and Articles 58, 59, 64 and 65 of Delegated Regulation (EU) 231/2013.
516. Specific provision applicable to AIFMs: In view of the obligations of the AIFM under Article 17 of
the 2013 Law and given the responsibility of the AIFM regarding the calculation and publication of the AIF’s net asset value referred to in paragraph 10 of the above-mentioned article, the AIFM must implement measures to fulfil this responsibility. With this in mind, in the event of a delegation of the administration function by the AIF which adopted the form of a company, the AIFM must either be
part of a delegation contract or ensure that bilateral contracts allow the AIFM to fulfil its
responsibilities in accordance with Article 17(10) of the 2013 Law.
Circular CSSF 18/698 Page 73/96
Sub-section 6.4.3.2. Due diligence and ongoing monitoring
517. In addition to the elements referred to in Sub-section 6.2.3.3. Details on the initial due diligence, the
IFM delegating the UCI administration function, including the function of registrar agent, should include the following elements (non-exhaustive list) to its due diligence assessment:
Circular CSSF 18/698 Page 74/96
522. In addition to the elements referred to in Sub-section 6.2.3.4. (Details on the ongoing monitoring),
the IFM must carry out an ongoing monitoring of the marketing intermediaries in compliance with
Section 5.4.2. (Obligations applicable to the IFM according to the manner in which the relationship
with marketing intermediaries and the function of registrar agent is organised) of this circular and include the following elements (non-exhaustive list):
Circular CSSF 18/698 Page 75/96 the arrangements for the use of valuation models and include at least details on the following elements:
Circular CSSF 18/698 Page 76/96
Circular CSSF 18/698 Page 77/96 which it has been designated as depositary, so that the depositary may comply with its obligations in accordance with the applicable legal and regulatory provisions.
546. Consequently, the IFM must also ensure that its delegates as well as, where appropriate, the external
persons who are not designated directly by the IFM (such as, for example, the administration of the AIF or the collateral manager, where appropriate) make available to the depositary all the relevant information it needs to carry out its duties in accordance with point 545 above.
547. Specific provision applicable to ManCos: The ManCo must, in particular, ensure that the written
procedures laid down in point 33 of Circular CSSF 16/644 describe the information that must be provided in this context to the depositary of the managed UCITS. Specific provisions applicable to AIFMs:
548. The AIFM must ensure that the written procedures laid down in point 65 of Circular CSSF 18/697
describe the information that must be provided in this context to the depositary of the managed AIFs.
549. Where the prime broker must hold custody of the assets owned by the AIF, the prime broker must
then be considered as acting as delegate of the depositary of this AIF. The AIFM must ensure that the depositary has a right of refusal regarding the choice and appointment of a prime broker by the AIF or its IFM where the prime broker will, in the discharge of its duties, hold custody of the assets owned by the AIF. The IFM must transmit to the depositary in good time all the relevant information on the prime broker so that the depositary is able to perform its duties.
550. Provisions applicable to IFMs: The procedures referred to in points 547 and 548 above must
determine the nature of the information for which the IFM should play a centralising role in order to facilitate the flow of information.
Chapter 9. Programme of activity
551. The application for authorisation of an IFM includes a programme of activity as referred to in Article
102(1)(d) of the 2010 Law and Article 6(2)(c) of the 2013 Law. This document provides a description of the envisaged activities as well as of the development projects of the IFM.
552. Note should be made that the programme of activity referred to in this chapter is different from the
document referred to in Article 114(2)(b) of the 2010 Law and Article 32(2)(b) of the 2013 Law in the context of the freedom to provide services and freedom of establishment.
553. The programme of activity includes, at least, information on:
Circular CSSF 18/698 Page 78/96 indicate if the IFM intends to manage UCIs qualifying as money market funds under the MMFR;
Circular CSSF 18/698 Page 79/96
Part III. Conditions for obtaining and maintaining the authorisation of
IFMs which exercise activities of UCI management and management of portfolios of investments on a client-by-client basis as referred to in Article 101(3) of the 2010 Law and Article 5(4) of the 2013 Law
558. All the conditions set forth under Part II above remain applicable. Additional requirements apply that
are specific to the activity of the management of portfolios of investments on a client-by-client basis. It should be borne in mind that, in accordance with point 305 of this circular, the IFM referred to in this part is also subject to the AML/CFT laws and regulations in force, among which the AML/CFT Law, the Law of 27 October 2010, CSSF Regulation 12-02, CSSF circulars on AML/CFT and the United Nations Security Council resolutions as well as acts adopted by the European Union.
559. The programme of activity as described in Chapter 9 of Part II includes also information on the scope
of the proposed services for the next three financial years regarding at least:
Circular CSSF 18/698 Page 80/96 basis, must also comply, besides with the provisions of Part II, Chapter 3 Own funds of this circular, with Luxembourg laws and regulations transposing Directive 2013/36/EU of 26 June 2013 on capital adequacy.
566. To this end, the IFM referred to in this part must submit its calculation of the capital ratio in
accordance with Circular CSSF 07/290 on a quarterly basis, i.e. by the 20th of the month following the end of the calendar quarter at the latest.
567. Finally, every IFM whose authorisation covers the services set out in Article 101(3) of the 2010 Law
or Article 5(4) of the 2013 Law and thus ensuring discretionary management, must participate for these services in an investor compensation system set up in Luxembourg and recognised by the CSSF. Consequently, the IFMs must be members of the Système d’Indemnisation des Investisseurs Luxembourg.
Part IV. The IFM and the principle of freedom of establishment and
freedom to provide services
Chapter 1. Freedom to establish a branch
Sub-chapter 1.1. Obligation of notification
Specific provisions applicable to ManCos:
568. Every IFM subject to Chapter 15 of the 2010 Law and wishing to exercise activities or to provide
services within the territory of another Member State, by way of a branch under the UCITS Directive, must submit a notification which includes the information referred to in Article 114 of the 2010 Law to the CSSF. Thus, the notification must be accompanied by the following pieces of information:
a) the Member State within the territory of which the ManCo plans to establish a branch; b) a programme of operations setting out the activities and services according to Article 101(2) and (3) envisaged and the organisational structure of the branch, which must include a description of the risk management process put in place by the ManCo. It must also include a description of the procedures and arrangements taken to handle complaints and to make information available at the request of the public or the competent authorities of the UCITS home Member State; c) the address in the ManCo's host Member State from which documents may be obtained; and d) the name of the conducting officer(s) responsible for the management of the branch.
569. The description of the risk management process must be appropriate and proportionate to the activity
and/or services actually provided at the level of the branch in the host country. It covers, where appropriate, the services provided for in Article 101(3) of the 2010 Law, i.e. the management of mandates on a client-by-client basis.
570. Specific provision applicable to AIFMs: Every IFM authorised as AIFM and wishing to exercise
activities or to provide services within the territory of another Member State, by way of a branch under the AIFMD, must submit a notification which includes the information referred to in Article 32 of the 2013 Law to the CSSF. Thus, the notification must be accompanied by the following pieces of information:
a) the Member State within the territory of which the AIFM plans to establish a branch, and/or to provide the services referred to in Article 5(4) of the 2013 Law; b) a programme of operations stating in particular the services which the AIFM intends to provide and/or identifying the AIFs it intends to manage; c) the organisational structure of the branch; d) the address in the home Member State of the AIF from which documents may be obtained;
Circular CSSF 18/698 Page 81/96 e) the names and contact details of the persons responsible for the management of the branch.
571. The notification file must be established in a language mutually accepted by the CSSF and the
competent authority of the host Member State.
572. The branch of the IFM must have at least one branch manager
(“dirigeant”/”Zweigniederlassungsleiter”) located in the host country.
573. As regards the branch manager(s), every IFM must include the following pieces of information and
any other document which might be subsequently indicated by the CSSF in the notification:
Circular CSSF 18/698 Page 82/96
581. It should be borne in mind that, in accordance with Circular CSSF 10/467, the IFM which have one
or more branches must communicate not only the accounting version “L” of the periodic tables (figures of the sole head office in Luxembourg) but also the version “N” (overall figures of the head office and of all the branches) and the version “S” (figures of each branch separately).
582. The réviseur d’entreprises agréé (approved statutory auditor) includes the branches when auditing
the annual accounts of the IFM.
Chapter 2. Freedom to provide services
Specific provisions applicable to ManCos:
583. Every ManCo wishing to exercise activities or provide services within the territory of another
Member State under the freedom to provide services pursuant to the UCITS Directive must submit to the CSSF a notification containing the information referred to in Article 115 of the 2010 Law. Thus, the notification must be accompanied by the following pieces of information:
a) the Member State within the territory of which the ManCo intends to operate; b) a programme of operations stating the activities and services referred to in Article 101(2) and (3) of the 2010 Law envisaged which must include a description of the risk management process put in place by the ManCo. It must also include a description of the procedures and arrangements taken in accordance with Article 112 of the 2010 Law.
584. The description of the risk management process must be appropriate and proportionate to the activity
and/or services actually provided at the level of the branch in the host country. It covers, where appropriate, the services provided for in Article 101(3) of the 2010 Law, i.e. the management of mandates on a client-by-client basis.
585. It should be noted that under Article 113 of the 2010 Law, a ManCo which proposes, without
establishing a branch, only to market the units of the UCITS it manages in a Member State other than the UCITS home Member State, is not subject to the provisions regarding the freedom to provide services.
586. Specific provision applicable to AIFMs: Every AIFM wishing to exercise activities or provide
services within the territory of another Member State under the freedom to provide services pursuant to the AIFMD must submit to the CSSF a notification containing the information referred to in Article 32 of the 2013 Law. Thus, the notification file must include:
a) the Member State within the territory of which the AIFM intends to manage AIFs directly and/or to provide the services referred to in Article 5(4) of the 2013 Law; b) a programme of operations stating in particular the services which the AIFM intends to provide and/or identifying the AIFs it intends to manage;
587. The notification file must be established in a language mutually accepted by the CSSF and the
competent authority of the host Member State.
588. The IFM must also provide a description of the main marketing techniques which it intends to use
(regular trips to the host Member State, distance sales, etc.) if marketing is one of its key functions.
Chapter 3. General provisions regarding the freedom of establishment and the
freedom to provide services
589. The IFM which established a branch or which acts under the freedom to provide services in another
Member State, must notify in writing any changes in the information referred to in point 568(b), (c) and (d), or in point 583(b) for ManCos, or in point 570 or point 586 for AIFMs, to the competent authority of its host country as well as to the CSSF within one month before the entry into force of the change at the latest (Articles 114(7) or 115(4) of the 2010 Law for the ManCo and Article 32(5) of the 2013 Law for the AIFM).
Circular CSSF 18/698 Page 83/96
590. Specific provision applicable to ManCos: Where a ManCo wishes to manage a UCITS of a Member
State on a cross-border basis via the creation of a branch or via the freedom to provide services, it must provide the competent authorities of the UCITS home Member State with the written agreement concluded with the depositary and with information relating to the delegation arrangements made by the ManCo in relation to the functions referred to in Annex II of the 2010 Law on administration and investment management.
Part V. Principle of proportionality
591. The principle of proportionality may be invoked by an IFM in the application of certain requirements
set out in CSSF Regulation 10-4 and Delegated Regulation (EU) 231/2013 while taking into account the nature, scale and complexity of its activities and the range of services provided.
592. Thus, an IFM may be authorised to apply the principle of proportionality when organising its
permanent risk management (Section 5.3.1.), compliance (Section 5.3.2.), internal audit (Section 5.3.3.) functions, subject to prior duly reasoned request. The principle of proportionality cannot be invoked in order to put in place the above-mentioned functions.
593. Moreover, every IFM may take this principle into account in the organisation of its human resources,
in the management of conflicts of interest, in the implementation of the remuneration policy, in compliance with the conditions referred to above in Sections 5.1.1., 5.5.7. and 5.5.9. of this circular.
594. When applying the provisions regarding the organisational requirements referred to in Article 5 of
CSSF Regulation 10-4 and Article 57 of Delegated Regulation (EU) 231/2013, the IFM must take into account the nature, the size and the complexity of its activity as well as the nature and range of the provided services and performed tasks.
595. However, the application of the principle of proportionality cannot be invoked with respect to the
obligation to employ at least three FTE people at the Luxembourg head office who spend their work time performing key functions as referred to in point 123.
596. In order to assess the principle of proportionality, the following elements are taken into account: the
number of UCIs/compartments managed by the IFM, whether or not they are regulated, including the UCIs managed on a cross-border basis, the total assets under management, the risk level of the types of assets or strategies managed, the closed-end or open-end nature of the UCIs, the number of transactions at the level of UCIs, the possibility for the IFM to benefit from a specific intra-group expertise.
Part VI. IFMs governed by Article 125-1 of Chapter 16 and IFMs governed
by Chapter 17 of the 2010 Law
Chapter 1. IFMs governed by Article 125-1 of Chapter 16 of the 2010 Law
597. Access to the activity of an IFM governed by Article 125-1 of Chapter 16 of the 2010 Law is subject
to prior authorisation by the CSSF (Article 125-1 of the 2010 Law).
598. The conditions for obtaining and maintaining this authorisation are specified in this chapter. To this
end, the following requirements with which the IFM subject to Article 125-1 of Chapter 16 of the 2010 Law must comply are particularly noteworthy:
Circular CSSF 18/698 Page 84/96 provisions referred to in Sub-chapter 3.3. of Part II (Use of own funds), including with respect to the arrangements regarding the acquisition of holding and the creation of a subsidiary, except for point 57 of this circular, where appropriate;
Circular CSSF 18/698 Page 85/96
Circular CSSF 18/698 Page 86/96 authorities of the home Member State of the UCITS pursuant to Article 27(2) of the 2010 Law with reference to Article 112 of the 2010 Law.
610. Based on a duly reasoned request, a SIAG or a FIAAG may invoke the principle of proportionality
pursuant to Part V, provided that the provisions concerned apply to it.
611. Finally, it should be noted that the provisions of Part IV regarding the freedom to provide services
or the freedom of establishment of a branch, respectively, do not apply to a SIAG or a FIAAG.
Chapter 2. Prudential supervision of SIAGs and FIAAGs
Specific provisions applicable to SIAGs:
612. Articles 27 and 39 of the 2010 Law require a SIAG to comply with the applicable provisions
regarding prudential supervision. Every SIAG is asked to submit specific financial information to the CSSF which must be drawn up on a quarterly basis. This financial information will be used by the CSSF for the purpose of the prudential supervision of a SIAG.
613. The financial information schedules which must be submitted periodically to the CSSF are set out in
Annex 3. This information concerns the “Financial situation” (Table SIAG 1A), the “Profit and loss
account” (Table SIAG 1B) and the “Number of employees” (Table Employees).
614. The tables must be drawn up on a quarterly basis. The dates of the report are the last day of each
calendar-quarter, i.e. 31 March, 30 June, 30 September and 31 December. The CSSF must receive these tables by the 20th day of the month following the reference date.
615. The final tables must be communicated to the CSSF one month after the ordinary general meeting
that approved the annual accounts.
616. Specific provision applicable to FIAAGs: The CSSF expects that the FIAAG submits its specific
financial information under the conditions referred to in points 612 to 615 above.
Part VIII. Communication with the CSSF
617. When communicating in writing with the CSSF, the IFM must use a language accepted by the CSSF.
The use of Luxembourgish, French, German or English is accepted in any case.
Part IX. Entry into force and various provisions
618. This circular repeals Circular CSSF 12/546.
619. Point (e) of Title V.I. Content and format of the risk management process of Circular CSSF 11/512
is amended in that the implementation of the risk management procedure must be communicated no later than five months following the end of the financial year of the IFM.
620. The last sub-paragraph of Title 3. Communication of information to the CSSF of Circular CSSF
17/671 is amended in that the table and summary report regarding the handling of complaints must be communicated to the CSSF within five months following the end of the financial year of the IFM.
621. This circular enters into force with immediate effect.
Circular CSSF 18/698 Page 87/96
ANNEXES
ANNEX 1: The risk management procedure of AIFs to be communicated to
the CSSF
Circular CSSF 18/698 Page 88/96
1.3. Pursuant to Articles 14 of the 2013 Law and 42 and 43 of Delegated Regulation (EU)
231/2013, demonstrate the independence of the permanent risk management function. Demonstrate (where appropriate) that appropriate safeguards have been implemented against conflicts of interest in order to allow the independent exercise of risk management activities.
1.4. Risk management policy
1.4.1. Describe the risk management policy by specifying the risks covered. As a reminder,
Article 40 of Delegated Regulation (EU) 231/2013 refers to market, liquidity and
counterparty risks as well as to any other risk, including the operational likely to be significant for AIFs (including the risks likely to be significant for AIFs which are not specifically covered in the following sections of this annex).
1.4.2. Demonstrate the compliance of the risk management policy with all the provisions
laid down in Article 40 of Delegated Regulation (EU) 231/2013.
1.4.3. List the main procedures included in the risk management procedure (cf. Article 40
of Delegated Regulation (EU) 231/2013).
1.5. Permanent risk management function
1.5.1. Describe the role of the permanent risk management function and describe
consecutively the manner in which it fulfils every requirement referred to in Article 39 of Delegated Regulation (EU) 231/2013.
1.5.2. Describe the process for the establishment of the risk profiles of every AIF.
1.6. Describe the valuation, monitoring and periodic review process of the risk management
system. Specify the reporting process in this respect to the senior management, management body/governing body and supervisory function, if any.
1.7. Describe the regular reports on risk management using the table below by describing the
information reports on the management of these risks for the risks covered by the risk management policy (cf. under 1.4) and at least for the risks listed in the table. Risks covered Report title Issuing entity Addressees* Frequency Market Liquidity Counterparty Operational Credit Compliance …
Circular CSSF 18/698 Page 89/96
Risks covered IT system Person responsible for configuration* Person responsible for the monitoring of risks Market Liquidity Counterparty Operational Credit Compliance …
Circular CSSF 18/698 Page 90/96
2. Specific complementary section: risk management policy in respect of strategies
2.1. Provide the name of the strategy subject to this specific complementary section.
2.2. Briefly describe the strategy and instruments used to implement it.
2.3. Briefly describe the investment process, including the process for the selection, due
diligence, decision, monitoring and disinvestment of assets. Name the players involved in the process.
2.4. Where appropriate, describe possible organisational elements regarding the risk management
which would differ from the presentation in the general section.
2.5. Describe the market risk management policy.
2.6. Describe the liquidity risk management policy, demonstrate that the liquidity profile of the
AIFs’ investments is appropriate to the AIFs’ obligations and explain the role played by the stress testing in this assessment.
2.7. Describe the counterparty risk management policy.
2.8. Describe the credit risk management policy.
2.9. Describe the operational risk management policy, detail the significant operational risks
(including the legal risk) to which the AIFs are subject and explain the manner in which they are assessed and managed.
2.10. Describe the valuation policy of assets.
2.11. Describe the policy on the use of leverage.
2.12. Provide the list of AIFs covered by this specific complementary section.
3. Specific complementary section: exercise of discretionary management
Briefly describe the manner in which the IFM providing services of management of portfolios of investments on a discretionary and individual basis in the framework of a mandate given by the investors pursuant to Article 5(4) of the 2013 Law complies with the risk management requirements under MiFID II Regulation.
Circular CSSF 18/698 Page 91/96
ANNEX 2: Summary table of the arrangements for the communication to
the CSSF according to the nature of the change (non-exhaustive list)
Circular CSSF 18/698 Page 92/96
2. Changes subject to notification to the CSSF (non-exhaustive list):
Circular CSSF 18/698 Page 93/96
3. List of closing documents to be provided yearly, within five months following the end of the
financial year of the IFM at the latest, except for the elements referred to in points 1 and 2 which must be submitted within one month after the ordinary general meeting that approved the annual accounts of the IFM and seven months following the closing date of the financial year of the IFM at the latest:
Circular CSSF 18/698 Page 94/96
ANNEX 3: Specific information applicable to SIAGs and FIAAGs
FINANCIAL SITUATION AS AT …
(Expressed in the currency of the capital)
Company:
Status: ☐ SICAV ☐ Other
Person in charge:
Frequency: quarterly
ASSETS AMOUNT
Circular CSSF 18/698 Page 95/96
PROFIT AND LOSS ACCOUNT AS AT …
(Expressed in the currency of the capital)
Company:
Status: ☐ SICAV ☐ Other
Person in charge:
Frequency: quarterly
AMOUNT
Total income
Circular CSSF 18/698 Page 96/96
TABLE EMPLOYEES
NUMBER OF EMPLOYEES AS AT 00/01/00
Company: 0
Person in charge: 0
Male Female Total
Luxembourgish Foreign Luxembourgish Foreign Luxembourgish Foreign Conducting officers* 0 0 Employees 0 0 Workers 0 0 Total 0
Part-time staff 0 0
TOTAL
Total number of employees in the self-managed investment company 0 Including the number of people on secondment or made available by a company having its registered office in Luxembourg
Read the rest free
Amended 2 times · last 2023-07-26
Source: Commission de Surveillance du Secteur Financier — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from CSSF
CSSF published 3 documents in the last 30 days. We email you each new one the day it's published.