2022-04-22

Added · Updated

Circular CSSF 22/806 on outsourcing arrangements as amended by Circular CSSF 25/883

This circular establishes supervisory requirements for outsourcing arrangements, extending the scope of application beyond credit institutions, investment firms, and payment institutions to include specialised and support professionals of the financial sector, POST Luxembourg, and management companies authorised under Article 125-1 of the UCITS Law. It mandates that In-Scope Entities adopt robust internal governance arrangements, including clear organisational structures, adequate internal control mechanisms, and sound risk management practices when resorting to outsourcing. The document specifies detailed obligations regarding the assessment, governance framework, contractual phase, oversight, and exit plans for outsourcing processes, with specific additional requirements for ICT outsourcing, including cloud computing infrastructure. As of 17 January 2025, the circular has been amended to align with the Digital Operational Resilience Act (DORA) to avoid duplication of requirements.

Commission de Surveillance du Secteur Financier logo

Luxembourg

Commission de Surveillance du Secteur Financier

Scan of the document's first page
Share

CSSF published 3 documents in the last 30 days — get each new one by email the day it lands.

Read the rest free

Lineage: Amended

amendssupersedesissued underrefers toproposed or not in RegAlertarrows run from the older text to the one that changes it

Source: Commission de Surveillance du Secteur Financier — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works

More like this from CSSF

CSSF published 3 documents in the last 30 days. We email you each new one the day it's published.