2024-08-29
Added · Updated
Circular CSSF 24/860 updates Circular CSSF 12/552 by clarifying the definition of significant institutions in Part I and introducing a definition for transactions with related parties. The scope is clarified for mixed financial holding companies acting as intermediaries in the holding chain to promote proportionality. Adjustments align the requirement to establish an audit committee with the Law of 23 July 2016 concerning the audit profession and adapt provisions regarding the veto right of the head of the risk management function to comply with EBA Guidelines on internal governance. The term "risk control function" is replaced by "risk management function," and direct links are established with Circulars CSSF 22/824 and CSSF 17/675 regarding credit risk requirements.
CSSF published 3 documents in the last 30 days — get each new one by email the day it lands.
Circular CSSF 24/860
Update of Circular CSSF 12/552, as amended by Circulars CSSF 13/563, 14/597, 16/642, 16/647, 17/655, 20/750, 20/759, 21/785 and 22/807, relating to central administration, internal governance and risk management
In case of discrepancies between the French and the English texts, the French text shall prevail. CIRCULAR CSSF 24/860 2/3 Circular CSSF 24/860 Update of Circular CSSF 12/552, as amended by Circulars CSSF 13/563, 14/597, 16/642, 16/647, 17/655, 20/750, 20/759, 21/785 and 22/807, relating to central administration, internal governance and risk management To all credit institutions and professionals performing lending operations Luxembourg, 29 August 2024 Ladies and Gentlemen, The purpose of this circular is to clarify certain provisions of Circular CSSF 12/552 (“the Circular”). It notably specifies the definition of significant institutions in Part I of the Circular and introduces the definition of “transactions with related parties”. The scope of application of the Circular has also been clarified for (mixed) financial holding companies when they are intermediaries in the holding chain in order to promote proportionality. Certain elements of the Circular have been adjusted for consistency with the applicable regulations. o The requirement to establish an audit committee in Part II has been aligned with the Law of 23 July 2016 concerning the audit profession. o The provisions concerning the veto right of the head of the risk management function and their ability to challenge management decisions have been adapted to fully comply with the European Banking Authority (“EBA”) Guidelines on internal governance (EBA/GL/2021/05). Some adjustments have also been made to align with Circular CSSF 22/806 on outsourcing arrangements. o In Part III, Chapter 3 on credit risk, the Circular now establishes direct links with Circular CSSF 22/824 adopting the EBA Guidelines on loan origination and monitoring (EBA/GL/2020/06) and Circular CSSF 17/675 adopting the EBA Guidelines on credit institutions’ credit risk management practices and accounting for expected credit losses (EBA/GL/2017/06) and develops the content of the requirements applicable for exposures to individuals secured by mortgages on residential property and for exposures to real estate developments. o Finally, in accordance with Directive 2013/36/EU, the term “risk control function” has been replaced by “risk management function” throughout the Circular, and the legal references have been updated. A version of the Circular showing the changes made is attached to this document. In the near future, the CSSF plans to publish a consolidated and amended version of all applicable Questions/Answers (“FAQs”) relating to the Circular. This Circular is applicable from 30 September 2024.
CIRCULAR CSSF 24/860 3/3
Claude WAMPACH
Director
Marco ZWICK
Director
Jean-Pierre FABER
Director
Françoise KAUTHEN
Director
Claude MARX
Director General
Annex Circular CSSF 12/552 as amended by Circulars CSSF 13/563, 14/597, 16/642,
16/647, 17/655, 20/750, 20/759, 21/785, 22/807 and 24/860
In case of discrepancies between the French and the English texts, the French text shall prevail. Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 1/85 Circular CSSF 12/552 as amended by Circulars CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785 and, CSSF 22/807 and 24/860 Central administration, internal governance and risk management
In case of discrepancies between the French and the English texts, the French text shall prevail. Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 2/85 Circular CSSF 12/552 as amended by Circulars CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785 and, CSSF 22/807 and 24/860 Re: Central administration, internal governance and risk management1 Ladies and Gentlemen, Articles 5(1a), and 38-1 of the Law of 5 April 1993 on the financial sector (“LFS”) , supplemented by Regulation CSSF No 15-02 relating to the supervisory review and evaluation (“RCSSF 15-02”) require credit institutions to have robust internal governance arrangements, which shall include a clear organisational structure with well-defined, transparent and consistent lines of responsibility, effective processes to identify, manage, monitor and report the risks to which they are or might be exposed, adequate internal control mechanisms, including sound administrative and accounting procedures and remuneration policies and practices allowing and promoting sound and effective risk management, as well as control and security mechanisms for their IT systems. This Circular specifies the measures credit institutions must take pursuant to the provisions of the LFS and RCSSF 15-02 as regards central administration, internal governance and risk management and Regulation CSSF No 15-02 relating to the supervisory review and evaluation process that applies to CRR institutions (“RCSSF 15-02”). It reflects the European and international principles, guidelines and recommendations which apply in this respect, translating them, in a proportionate way, in the context of the Luxembourg banking sector. Where, due to the size, the nature and the complexity of the activities and the organisation, the application of the principle of proportionality requires enhanced central administration, internal governance or risk management, the credit institutions shall refer to the principles set out in
Chapter 2 of Part I and to the guidelines and recommendations listed in Part IV
of this Circular for guidance on this implementation. This concerns especially the European Banking Authority (“EBA”) Guidelines on internal governance, as updated on 2 July 2021 (Guidelines on internal governance, EBA/GL/2021/05), and the joint EBA and European Securities and Markets Authority (“ESMA”) Guidelines on the assessment of the suitability of members of the management body and key function holders, as updated on 2 July 2021 (EBA/GL/2021/06). 1 To professionals performing lending operations as defined in Article 28-4 of the Law of 5 April 1993 on the financial sector, Chapter 3 of Part III, with the exception of Sub-chapter 3.4 “Exposures associated with particularly high risk” shall apply. Chapter 2(12) of Part III shall also apply. Luxembourg, 11 December 2012 To all credit institutions and professionals performing lending operations1
In case of discrepancies between the French and the English texts, the French text shall prevail. Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 3/85 The principles and good practices arising from other sources already included in the previous versions of the Circular have been maintained in so far as they have not become obsolete.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 1/85 As regards the appointments of members of the management body and key function holders, this Circular should be read in conjunction with the Prudential Procedure in this respect published on the CSSF website. The Circular is divided into four parts: the first part establishes the scope, the second part is dedicated to central administration and internal governance requirements, the third part covers specific risk management requirements and the fourth part provides for the entry into force and the history of the updates, allowing the reader to retrace the amendments entailed by the successive updates.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 2/85
TABLE OF CONTENTS
Part I - Definitions and Scope 5
Chapter 1. Definitions and abbreviations 5
Chapter 2. Scope and proportionality 7
Part II. Central administration and internal
governance arrangements 10
Chapter 1. Central administration 10
Chapter 2. Internal governance arrangements 10
Chapter 3. General characteristics of “robust”
central administration and internal governance arrangements 12
Chapter 4. Supervisory body and authorised
management 13
Sub-chapter 4.1. Supervisory body 13
Section 4.1.1. Responsibilities of the supervisory body 13
Section 4.1.2. Composition and qualification of the
supervisory body 18
Section 4.1.3. Organisation and functioning of the
supervisory body 19
Section 4.1.4. Specialised committees 20
Sub-section 4.1.4.1. Audit committee 22
Sub-section 4.1.4.2. Risk committee 23
Sub-chapter 4.2. Authorised management 25
Section 4.2.1. Responsibilities of the authorised
management 25
Section 4.2.2. Qualification of the authorised management
29
Chapter 5. Administrative, accounting and IT
organisation 29
Sub-chapter 5.1. Organisation chart and human resources29 Sub-chapter 5.2. Procedures and internal documentation30 Sub-chapter 5.3. Administrative and technical infrastructure 31
Section 5.3.1. Administrative infrastructure of the business
functions 31
Section 5.3.2. Financial and accounting function 32
Section 5.3.3. IT function 34
Section 5.3.4. Communication and internal and external
alert arrangements 34
Section 5.3.5. Crisis management arrangements 35
Chapter 6. Internal control 35
Sub-chapter 6.1. Operational controls 36
Section 6.1.1. Day-to-day controls carried out by the
operating staff 37
Section 6.1.2. Ongoing critical controls 37
Section 6.1.3. Controls carried out by the members of the
authorised management on the activities or functions which fall under their direct responsibility 37
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 3/85 Sub-chapter 6.2. Internal control functions 38
Section 6.2.1. General responsibilities of the internal
control functions 39
Section 6.2.2. Characteristics of the internal control
functions 39
Section 6.2.3. Execution of the internal control functions'
work 41
Section 6.2.4. Organisation of the internal control functions
42
Section 6.2.5. Risk management function 45
Sub-section 6.2.5.1. Scope and specific responsibilities of the risk management function 45 Sub-section 6.2.5.2. Organisation of the risk management function 47
Section 6.2.6. Compliance function 48
Sub-section 6.2.6.1. Compliance charter 48 Sub-section 6.2.6.2. Scope and specific responsibilities of the compliance function 49 Sub-section 6.2.6.3. Organisation of the compliance function 52
Section 6.2.7. The internal audit function 52
Sub-section 6.2.7.1. Internal audit charter 52 Sub-section 6.2.7.2. Specific responsibilities and scope of the internal audit function 54 Sub-section 6.2.7.3. Execution of the internal audit work 55 Sub-section 6.2.7.4. Organisation of the internal audit function 56
Chapter 7. Specific requirements 56
Sub-chapter 7.1. Organisational structure and legal entities (Know-yourstructure) 56
Section 7.1.1. Complex structures and non-standard or
potentially non-transparent activities 57
Sub-chapter 7.2. Management of conflicts of interest 58
Section 7.2.1. Specific requirements relating to conflicts of
interest involving related parties 59
Section 7.2.2. Documentation of loans granted to
members of the management body and to their related parties 61 Sub-chapter 7.3. New Product Approval Process 62 Sub-chapter 7.4. Outsourcing 62
Chapter 8. Legal reporting 63
Part III. Risk management 63
Chapter 1. General principles as regards risk
measurement and risk management 63
Sub-chapter 1.1. Institution-wide risk management framework 63
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 4/85
Section 1.1.1. General information 63
Section 1.1.2. Specific (risk, capital and liquidity) policies
64
Section 1.1.3. Risk identification, management,
measurement and reporting 65
Chapter 2. Concentration risk 66
Chapter 3. Credit risk 67
Sub-chapter 3.1. General principles 67
Sub-chapter 3.2. Exposures to individuals secured by mortgages on residential property 68 Sub-chapter 3.3. Exposures to the real estate developments 68 Sub-chapter 3.4. Exposures associated with particularly high risk 69 Sub-chapter 3.5. Non-performing and forborne exposures 70
Chapter 4. Risk transfer pricing 71
Chapter 5. Private wealth management (“private
banking”) 71
Chapter 6. Exposures to shadow banking entities 72
Sub-chapter 6.1. Implementation of sound internal control principles 72 Sub-chapter 6.2. Application of quantitative limits 73
Chapter 7. Asset encumbrance 74
Chapter 8. Interest rate risk 75
Sub-chapter 8.1 Interest rate risk arising from non-trading book activities 75 Sub-chapter 8.2. Corrections to modified duration for debt instruments 75
Chapter 9. Risks associated with the custody of
financial assets by third parties 75
Part IV. Timeline 76
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 5/85
Part I - Definitions and Scope
Chapter 1. Definitions and abbreviations
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 6/85
4. “significant institution” shall mean systemically important credit institutions
in accordance with Article 59-3 of the LFS. and, if applicableWhere appropriate, the competent authority may determine whether other credit institutions should be considered as significant institutions for the purposes of this Circular determined as such by the competent authority based on the assessment of the institutions’ size and internal organisation as well as the nature, the scale and the complexity of their activities;
5. “management body” shall mean the management body in its supervisory
function and in its management function in accordance with the EBA Guidelines on internal governance (EBA/GL/2021/05). It shall refer to the Board of Directors and the authorised management of an institution with a one-tier structure or the Supervisory Board and the Executive Board of an institution with a two-tier structure;
6. “supervisory body” shall correspond to the management body in its
supervisory function in accordance with the EBA Guidelines on internal governance (EBA/GL/2021/05). According to the financial sector regulation, boards of directors and supervisory boards of credit institutions are assigned responsibilities as regards the supervision and control, as well as the determination and approval of strategic orientations and guiding principles;
7. “related parties” shall mean
a. the legal entities (structures) which are part of the group to which the institution belongs; b. the shareholders;
c. the members of the management body of the institution or entities
mentioned in point (a), their spouses or partners registered in accordance with the applicable national law and their children and parents; d. the commercial entities, in which a member of the management body or his or her close family member as referred to in point (c) has a qualifying holding of 10 % or more of capital or of voting rights in that entity, in which those persons can exercise significant influence, or in which those persons hold senior management positions or are members of the management body;
8. “Prudential Procedure” shall mean the prudential procedure for the
appointment of members of the management body and key function holders in credit institutions;
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 7/85
9. “key function holders” shall mean the heads of functions whose
performance allows a significant influence over the conduct or monitoring of the activities of the institutions. They include, at least, the heads of the three internal control functions in all institutions, i.e. the Chief Risk Officer (“CRO”) for the risk control management function, the Chief Compliance Officer (“CCO”) for the compliance function and the Chief Internal Auditor (“CIA”) for the internal audit function, as well as the head of the financial function (Chief Financial Officer, “CFO”) in significant institutions. The institutions may identify other key function holders according to a riskbased approach;
9.10. “transactions with related parties” include all types of transactions.
This includes both on-balance sheet and off-balance sheet credit exposures and claims, but also dealings such as service contracts, asset purchases and sales, construction contracts, lease agreements, derivative transactions, borrowings, and write-offs. It encompasses transactions with parties that would become related parties as a result of the transaction, or where it is determined at the time of the transaction, that the contracting party will become a related party;
10.11. “ESG” shall mean Environmental, Social and Governance (risks);
11.12. “CEBS” shall mean the Committee of European Banking
Supervisors;
12.13. “CRD” shall mean Directive 2013/36/EU of 26 June 2013 on access
to the activity of credit institutions and the prudential supervision of credit institutions and investment firms, as amended;
13.14. “CRR” shall mean Regulation (EU) No 575/2013 of 26 June 2013 on
prudential requirements for credit institutions and investment firms, as amended;
14.15. “EEA” shall mean the European Economic Area;
15.16. “ICAAP” shall mean the Internal Capital Adequacy Assessment
Process;
16.17. “ILAAP” shall mean the Internal Liquidity Adequacy Assessment
Process;
17.18. “LFS” shall mean the Law of 5 April 1993 on the financial sector, as
amended;
18.19. “MiFID” shall mean the Markets in Financial Instruments Directive.
Chapter 2. Scope and proportionality
a. This Circular shall apply to institutions incorporated under Luxembourg law, including their branches, as well as their Luxembourg branches of thirdcountry institutions.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 8/85 In respect of the areas for which the CSSF retains an oversight responsibility as host authority and as authority in charge of an area outside the banking prudential supervision, respectively - i.e. anti-money laundering and counter terrorist financing measures, rules applicable to the provision of investment services and requirements applicable to UCI depositaries – Luxembourg branches of credit institutions authorised in another Member State, in coordination with this institution, shall establish central administration, internal governance and risk management arrangements which are comparable to those provided for in this Circular. b. This Circular shall apply to institutions, on a stand-alone, sub-consolidated and consolidated basis., In addition, this Circular shall apply to financial holding companies or mixed financial holding companies referred to in Article 21a(1) of the CRD and to credit institutions referred to in Article 21a(4)(c) of the CRD. However, for this type of companies, when they are intermediaries in the holding chain and have no material impact on the conduct and compliance of both their consolidating parent institution and their subsidiaries, a proportionate approach shall be applied. The extent of this approach shall be determined by mutual agreement with the competent authority. If the institution is a parent undertaking (group head), the Circular shall then apply to “the group” as a whole: to the parent undertaking and the various legal entities that are part of this group - whether or not they are included in the scope of prudential consolidation according to the CRR - including the branches, in compliance with the national laws and regulatory provisions which apply to the entities in question. Thus, whatever Regardless of the organisational and operational structure in which of the institution or a groupis integrated, the implementation of this Circular shall enable the institution to have maintain complete control over its activities and the risks to which it is or may be exposed, including the intragroup activities and risks and regardless of the location of the risks. The same shall apply to financial holding companies or mixed financial holding companies referred to in Article 21a(1) of the CRD. Proportionality shall apply to the implementing measures, which the institutions take pursuant to this Circular, having regard to the nature, scale and complexity of their activities, including the risks. In practice, the application of the principle of proportionality implies that the institutions which are more significant, complex or riskier have in place enhanced central administration, internal governance and risk management arrangements. These enhanced arrangements shall include, for example, the establishment of specialised committees,
the appointment of independent members additional to the supervisory body or additional authorised managers to facilitate the day-to-day management.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 9/85 Conversely, for institutions which are smaller in size and internal organisation, whose activities are minor in terms of nature, scale and complexity, the principle of proportionality could be applied downward. Thus, an institution with limited activities of low complexity may operate properly within the meaning of this Circular by designating heads of compliance and risk management control functions on a part-time basis (without questioning the principle of permanence of the function) or by fully or partially outsourcing the performance of the operational tasks of the internal audit. The downward application of the principle of proportionality is limited, in particular, by the principle of segregation of duties under which the duties and responsibilities must be assigned so as to avoid conflicts of interest involving the same person. The criteria of size or systemic importance alone are however not sufficient to reflect the degree to which an institution is exposed to certain risks. While the allocation of tasks within the authorised management is done in compliance with the principle of segregation of duties, joint responsibility shall be maintained. The implementation of the principle of proportionality shall take account of the following:
a. the legal form and the ownership and funding structure of the institution; b. the business model and risk strategy;
c. the size of the institution and its subsidiaries as well as the nature and
complexity of the activities (including the type of customers and the complexity of the products and contracts); d. the nature and complexity of the organisational and operational structure, including the geographic footprint, the distribution channels and the outsourced activities; e. the nature and state of the IT systems and continuity systems; f. the fact that the institution is a “small and non-complex institution” or a “large institution”, as defined in points 145 and 146 of Article 4(1) of the CRR and provided for in Annex II to this Circular. Regardless of the adopted organisation, the arrangements in this respect shall enable the institution to operate in full compliance with the provisions of Part II of this Circular. The institutions shall document their proportionality analysis in writing and have their conclusions approved by the supervisory body.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 10/85
Part II. Central administration and internal
governance arrangements
Chapter 1. Central administration
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 11/85
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 12/85 This strong and ubiquitous overall risk and compliance culture must also be reflected in the strategies, policies and procedures of the institution, the training offered and the messages brought to staff members as regards the risk-taking and the risk management within the institution. Such culture shall be characterised by the example the management body sets (“tone from the top”) and requires all staff members to be accountable for their acts and behaviour, an open and critical dialogue and the absence of an incentive for inappropriate risk-taking.
Chapter 3. General characteristics of “robust” central
administration and internal governance arrangements
8. Central administration and internal governance arrangements shall be
developed and implemented so that they:
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 13/85
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 14/85
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 15/85
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 16/85 The latter may influence the prudential risks, such as credit risk (for example owing to the risk factors linked to the transition towards a sustainable economy or climate-related events6 affecting the debtors, the market or liquidity), operational risk and reputational risk (for example in case of outsourcing). There may be legal risks linked to contract or labour law, risks linked to potential breaches of human rights and other ESG risk factors that may affect the country in which a service provider is established, as well as the latter’s capacity to provide the agreed levels of service.
14. The supervisory body shall critically assess, adapt, where necessary, and reapprove, on a regular basis and at least once a year, the internal governance
arrangements, including the key strategies and guiding principles and their implementation within the institution, the internal control mechanisms and the framework for risk-taking and risk management. These assessments and reapprovals aim to ensure that the internal governance arrangements continue to comply with the requirements of this Circular and the objectives of effective, sound and prudent business management. The assessment and re-approval by the supervisory body shall relate, in particular, to the following:
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 17/85
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 18/85
Section 4.1.2. Composition and qualification of the supervisory
body
18. The members of the supervisory body must be in sufficient number and, as a
whole, must be composed adequately so that the supervisory body can fully meet its responsibilities. The adequacy of the composition of the supervisory body refers, in particular, to professional qualifications (adequate knowledge, skills and experience), as well as to the personal qualities of the members of the supervisory body. Moreover, each member must demonstrate his/her professional repute. The guiding principles governing the appointment and succession of the members of the supervisory body explain and provide for the abilities deemed necessary to ensure an appropriate composition and qualification of the supervisory body.
19. The supervisory body must collectively have appropriate knowledge, skills and
experience with regard to the nature, scale and complexity of the activities and the organisation of the institution. Collectively, the supervisory body must fully know and understand all the activities (and inherent risks) as well as the economic and regulatory environment in which the institution operates. Each member of the supervisory body shall have a full understanding of the internal governance arrangements and of his/her responsibilities within the institution. The members shall control the activities which fall within their areas of expertise and shall have a good understanding of the other significant activities of the institution.
20. The members of the supervisory body shall ensure that their personal qualities
enable them to perform their mandate effectively, with the required commitment, availability, objectivity, critical thinking and independence of mind. In this respect, the supervisory body cannot have among its members a majority of persons who take on an executive role within the institution (authorised managers or other staff members of the institution, with the exception of staff representatives elected in accordance with the applicable regulations). The supervisory body’s decision-making shall not be dominated by any one individual member or small group of members. The members of the supervisory body shall ensure that their mandate is and remains compatible with any other positions, mandates and interests they may have, in particular in terms of conflicts of interest and availability. They shall inform the supervisory body of the mandates they have outside the institution.
21. The terms of reference of the mandates must be laid down so that the
supervisory body may fulfil its responsibilities effectively and on an ongoing basis. The renewal of the existing members' mandates must, in particular, be based on their past performance. Continuity in the functioning of the supervisory body must be ensured.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 19/85
22. The guiding principles governing the appointment and succession of the
members of the supervisory body provide for the measures required in order for these members to be and remain qualified throughout their mandate. These measures include a specific initiation to understand the structure, the business model, the risk profile and the governance arrangements, and then vocational training programmes which enable members of the supervisory body, on the one hand, to understand the operations of the institution, their role and, on the other hand, to update and develop their skills.
23. Each institution should appoint at least one member to its supervisory body
who may be considered as “independent member”.
An independent member of the supervisory body shall not have any conflict of interest which might impair his/her judgement because s/he is or has been, in the recent past, bound by any professional, family or other relationship with the institution, its controlling shareholder or the management of either. As to the assessment of “being independent”, the institutions shall apply the criteria of Section 9.3 of EBA/GL/2021/06 as provided for in Annex I. The significant institutions or the institutions whose shares are admitted to trading on a regulated market shall ensure that their supervisory body has a sufficient number of independent members, considering their organisation and the nature, the scale and the complexity of their activities.
Section 4.1.3. Organisation and functioning of the supervisory
body
24. The supervisory body shall regularly meet in order to effectively fulfil its
responsibilities. To this end, a majority of the meetings of the supervisory body should be held at the registered office of the Luxembourg institution in the presence (on site) of a majority of its members. The organisation and functioning of the supervisory body shall be documented in writing. The objectives and responsibilities of its members shall also be documented by way of written mandates.
25. The work of the supervisory body must be documented in writing. This
documentation shall include the agenda and minutes of the meetings as well as the decisions and measures taken by the supervisory body. The minutes are an important tool which must, on the one hand, help the supervisory body and its members monitor the decisions and, on the other hand, enable the body and its members to be accountable to the shareholders and the competent authorities. Thus, the routine items may be included succinctly in the minutes of a meeting, in the form of a simple decision, while important items on the agenda involving risks for the institution or jointly discussed must be reported in more detail, allowing readers to follow the discussions and to identify the positions taken.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 20/85
26. The supervisory body shall assess the procedures governing its operating
mode and its work in order to regularly improve them to ensure their effectiveness and to verify whether the applicable procedures are complied with in practice. It shall ensure that all its members have a clear picture of their obligations, responsibilities and allocation of tasks within the supervisory body and specialised committees that depend on it.
27. The chairperson of the supervisory body shall ensure a balanced composition
thereof, in particular in terms of diversity, to ensure its proper functioning, to promote a culture of informed discussion in which all parties are heard within the supervisory body and to propose the appointment of independent members. The chairperson of the supervisory body shall not exercise executive functions within the institution, save in exceptional situations to be authorised by the competent authority.
Section 4.1.4. Specialised committees
28. The supervisory body may be assisted by specialised committees, in particular,
in the fields of audit, risks, compliance, remuneration and appointments, internal governance and professional ethics, or anti-money laundering and counter-terrorist financing, according to its needs and considering the organisation, nature, scale and complexity of the institution’s activities. Their missions shall be to provide the supervisory body with critical assessments in respect of the organisation and functioning of the institution in their specific areas of competence.
29. The significant institutions as defined in point 1 of paragraph 4 of Part I of this
Circular must put in place an audit committee, a risk committee, a nomination committee, and a remuneration committee. Furthermore, institutions subject to Article 52 of the Law of 23 July 2016 concerning the audit profession, as amended (“Audit Law”), and that do not benefit from the exemption provided for in paragraph 5 of the aforementioned Article, must establish an audit committee.
30. In accordance with the principle of proportionality, the institutions that are not
significant may put in place dedicated committees combining different areas of responsibility, for example, an audit and risk committee, an audit and compliance committee or a risk and remuneration committee. The members of such committees must possess the necessary knowledge, skills and expertise to perform their functions, both individually and collectively.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 21/85
31. Without prejudice to the specific legal and regulatory requirements in this
respect, the permanent members of the specialised committees shall be, as the case may be, members of the supervisory body who do not perform any executive function within the institution or independent members. Each committee shall be composed of at least three members whose knowledge, skills and expertise are in line with the missions of the committee. Where there are several specialised committees within an institution and in so far as the number of non-executive and independent members of the supervisory body allows it, the institution should ensure that the members of the respective committees are different. Moreover, the institution should try to ensure an occasional rotation of the chairpersons and members of the committees, considering the specific experience, knowledge and skills required on an individual and collective basis.
32. The specialised committees shall be chaired by one of their members. These
committee chairpersons shall have in-depth knowledge in the area of activities of the committee they chair and shall ensure a critical and constructive debate within the committee.
33. The CSSF recommends that the significant institutions’ risk committee have a
majority of independent members, including its chairperson.
34. The specialised committees shall meet on a regular basis in order to discharge
their tasks and work assigned to them or to prepare the meetings of the supervisory body. According to their needs, they may be assisted by external experts independent of the institution, and may involve, in their work, the réviseur d’entreprises agréé, the authorised managers, the other specialised committees, the heads of the internal control functions and the other persons working for the institution, provided that these persons are not members and do not take part in the recommendations of the committee.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 22/85
35. The supervisory body shall lay down, in writing, the missions, composition and
working procedures of the specialised committees. Under these procedures, the specialised committees shall receive regular reports from the internal control functions on the development in the institution’s risk profile, the breaches of the regulatory framework, the internal governance and the risk management as well as the concerns raised through the internal alert arrangements and the remedial actions. The specialised committees shall regularly revise the relevance of the information that must be communicated to them. They must be able to request any document and information they deem necessary to fulfil their mission, including information on compliance with the rules governing the fight against money laundering and terrorist financing, on suspicious transaction reports and on ML/TF risk factors. The committees shall document the agendas of their meetings as well as the findings and recommendations according to the same principles as in point 25. Furthermore, the procedures shall provide for the conditions under which the external experts provide their assistance and the terms under which other persons are involved in the work of the specialised committees.
36. The supervisory body shall ensure that the different committees interact
effectively, communicate with each other, with the internal control functions and the réviseur d'entreprises agréé, and report to the supervisory body on a regular basis.
37. The supervisory body cannot delegate its powers and responsibilities pursuant
to this Circular to the specialised committees. Where it is not assisted by specialised committees, the tasks referred to in Sub-sections 4.1.4.1 and
4.1.4.2 shall be directly incumbent upon it.
Sub-section 4.1.4.1. Audit committee
38. The purpose of the audit committee shall be to assist the supervisory body in
the areas of financial information, internal control, including internal audit as well as the audit by the réviseur d'entreprises agréé.
39. Without prejudice to the other provisions set out inof point 29 of this Part,
Section 4.1.4, the institutions must establish an audit committee when
imposed by Article 52 of the Law of 23 July 2016 concerning the audit profession, as amended (“Audit Law”).
40. The audit committee shall be in charge of the process of appointment,
reappointment, revocation and remuneration of the réviseur d’entreprises agréé.
41. The audit committee shall confirm the internal audit charter as well as the
multi-annual audit plan and its reviews. It shall assess whether the human and material resources used for the internal audit are sufficient and shall make sure that the internal auditors have the required skills and independence.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 23/85
42. The audit committee shall regularly and critically deliberate on the following7:
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 24/85
46. The risk committee shall confirm the specific policies of the authorised
management in accordance with Section 1.1.2 of Part III. It shall assist the supervisory body in its supervisory mission, i.e. implementing the risk strategy, the overall risk-taking and risk management framework and the adequacy of all the incurred risks relating to the strategy, the risk appetite and the risk mitigation measures of the institution.
47. The risk committee shall assess whether the human and material resources,
as well as the organisation of the risk management control function are sufficient and shall ensure that the members of the risk management control function have the required skills.
48. The risk committee shall advise and assist the supervisory body in the
recruitment of external experts that the supervisory body would hire to provide advice or support.
49. The risk committee shall regularly and critically deliberate on the following:
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 25/85 Sub-chapter 4.2. Authorised management
Section 4.2.1. Responsibilities of the authorised management
51. The authorised management shall be in charge of the effective, sound and
prudent day-to-day management of the activities (and inherent risks). This management shall be exercised in compliance with the strategies and guiding principles approved by the supervisory body and the applicable regulations, by considering and safeguarding the institution’s long-term financial interests, solvency and liquidity situation. The authorised management shall constructively and critically assess all the proposals, explanations and information submitted to it for decision. The authorised management shall document its decisions by way of minutes of meetings, which must, on the one hand, help it monitor the decisions and, on the other hand, enable it to account for its management to the supervisory body and the competent authorities. Thus, the routine items may be included succinctly in the minutes of a meeting, in the form of a simple decision, while important items on the agenda involving risks for the institution or jointly discussed must be reported in more detail, allowing readers to follow the discussions and to identify the positions taken.
52. Pursuant to Article 7(2) of the LFS, the members of the authorised
management must be authorised to determine the business direction effectively. Consequently, where management decisions are taken by larger management committees rather than solely by the authorised management, at least one member of the authorised management must be part of it and have a veto right.
53. The authorised management shall perform its duties as a permanent function
within the institution; it must be on site.
54. The authorised management shall implement, through written internal policies
and procedures, all the strategies and guiding principles laid down by the supervisory body in relation to central administration and internal governance, in compliance with the legal and regulatory provisions and after having heard the internal control functions. The policies shall include detailed measures to be implemented; the procedures shall be the work instructions which govern this implementation. The term “procedures” is to be taken in the broad sense, including all the measures, instructions and rules governing the organisation and internal functioning. The authorised management shall ensure that the institution has the necessary internal control mechanisms, technical infrastructures and human resources to ensure a sound and prudent management of the activities (and inherent risks) within the context of robust internal governance arrangements pursuant to this Circular.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 26/85
55. Under the guiding principles of professional conduct, corporate values and
management of conflicts of interest laid down by the supervisory body, the authorised management shall define an internal code of conduct applicable to all the persons working in the institution. It shall ensure its proper application on the basis of regular controls carried out by the compliance and internal audit functions. The purpose of this code of conduct must be the prevention of operational and reputational risks which the institution may incur as a result of administrative or criminal sanctions, restrictive measures imposed on it or legal disputes, the damage to its corporate image or the loss of the trust of its customers and the consumers. The code of conduct must remind the staff and the members of the management body of the compliance with the applicable regulations, the internal rules and limitations, the principles that underlie honesty and integrity in their behaviour, by providing examples of acceptable and unacceptable or prohibited professional behaviour and practices, including in the field of antimoney laundering and combating the financing of terrorism, as well as the sanction that would arise from non-compliance.
56. Under the ninth indent of point 11 of Part II, the authorised management shall
ensure that the institution’s policies are neutral from a gender point of view and guarantee equal treatment and equal opportunity for every staff member, including in the context of their career prospects. The policies concerned should facilitate the reintegration of staff members after a maternity, paternity or parental leave.
57. The authorised management must have a full understanding of the
organisational and operational structure of the institution, in particular, of the underlying legal entities (structures), of their raison d'être, the intra-group links and interactions as well as the related risks. It shall ensure that the required management information is available, in due time, at all decisionmaking and control levels of the institution and legal structures which are part of it.
58. In its day-to-day management, the authorised management shall consider the
advice and opinions provided by the internal control functions. Where the decisions taken by the authorised management have or could have a significant impact on the risk profile of the institution, the authorised management shall first obtain the opinion of the risk management control function and of the compliance function.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 27/85 The authorised management shall promptly and effectively implement the corrective measures to address the weaknesses (problems, shortcomings, irregularities or concerns) identified by the internal control functions, the réviseur d’entreprises agréé or through the internal alert arrangements, by considering the recommendations issued in this respect. This approach shall be laid down in a written procedure which the supervisory body shall approve upon proposal of the internal control functions. According to this procedure, the internal control functions shall prioritise the various weaknesses they identified and set, upon approval of the authorised management, the (short) deadlines by which these weaknesses shall be remedied. The authorised management shall designate the business units or persons in charge of the implementation of the corrective measures by allocating the resources (budget, human resources and technical infrastructure) required for that purpose. The internal control functions shall be in charge of following up on the implementation of the corrective measures. Any significant delay in the implementation of the corrective measures shall be notified by the authorised management to the supervisory body which must authorise time extensions for the implementation of these measures. The institution shall establish a similar procedure, approved by the supervisory body, which shall apply where the competent authority requests the institution to take (corrective) measures. In this case, any significant delay in the implementation of these measures is to be notified by the authorised management to the supervisory body and the competent authority.
59. The authorised management shall verify the implementation of and compliance
with internal policies and procedures. Any breach of internal policies and procedures shall result in prompt and adapted corrective measures.
60. The authorised management shall verify the soundness of the central
administration and internal governance arrangements on a regular basis. It shall adapt the internal policies and procedures in light of the internal and external, current and anticipated changes and the lessons learnt from the past.
61. The authorised management shall inform the internal control functions of any
major change in the activities or organisation in order to enable them to identify and assess the risks which may arise therefrom.
62. The authorised management shall regularly or at least annually inform the
supervisory body, in a comprehensive manner and in writing, of the implementation, adequacy, effectiveness of and compliance with the internal governance arrangements, comprising the state of compliance (including the concerns raised through the internal alert arrangements) and of internal control as well as the ICAAP/ILAAP reports on the situation and the management of risks, internal and regulatory capital and liquidity reserves.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 28/85
63. Once a year, the authorised management shall confirm compliance with this
Circular to the competent authority by way of a single written sentence followed by the signatures of all the members of the authorised management. Where, due to non-compliance, the authorised management is not able to confirm full compliance with the Circular, the aforementioned statement takes the form of a reservation which outlines the non-compliant items by providing explanations on their raison d'être. The information to be provided pursuant to the first paragraph must be submitted together with the annual accounts to be published to the competent authority.
64. Where the authorised management becomes aware that the central
administration and internal governance arrangements no longer enable a sound and prudent management of the activities or that the incurred risks are or will no longer be properly borne by the institution’s ability to manage these risks, by the internal and regulatory capital and liquidity reserves, it shall inform the supervisory body and the competent authority by providing them, without delay, with any necessary information to assess the situation.
65. Notwithstanding the joint responsibility of the members of the authorised
management, it shall designate at least one of its members who shall be in charge of the administrative, accounting and IT organisation and who shall assume responsibility for implementing the policy and rules that it has established in this context. This member shall be in charge, in particular, of drawing up the organisation chart and the task description which s/he submits, prior to their implementation, to the authorised management for approval. S/he then shall ensure their proper implementation. The member in question shall also be in charge of the production and publication of accounting information intended for third parties and the transmission of periodic information to the competent authority. Thus, s/he shall ensure that the form and content of this information comply with the legal rules and instructions of the competent authority in this field. The authorised management shall also designate, among its members, the person(s) in charge of the internal control functions and, in accordance with Regulation CSSF 12-02, the person responsible for the professional obligations as regards the fight against money laundering and terrorist financing.
66. The institutions shall inform the competent authority of the appointments and
removals of the members of the authorised management, in accordance with the provisions of this Circular and the Prudential Procedure, stating moreover the reasons for the removal.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 29/85
Section 4.2.2. Qualification of the authorised management
67. The members of the authorised management shall, both individually and
collectively, have the necessary professional qualifications (knowledge, skills and experience), the good repute and personal qualities to manage the institution and determine the business direction effectively. The personal qualities shall be those which enable them to effectively perform their authorised manager’s mandate with the required commitment, availability, objectivity, critical thinking and independence of mind.
Chapter 5. Administrative, accounting and IT organisation
Sub-chapter 5.1. Organisation chart and human resources
68. The institution shall have a sufficient number of human resources on-site with
appropriate individual and collective professional skills in order to take decisions under the policies laid down by the authorised management and based on delegated powers, and in order to implement the decisions taken in compliance with the existing procedures and regulations. The organisation chart and the task description shall be laid down in writing and made available to all relevant staff in an easily accessible manner.
69. The structure of the different functions (business, support and control) and of
the different business units must be presented in the organisation chart, along with the reporting and functional lines with each other and with the authorised management and the supervisory body.
70. The task description to be filled in by the operating staff shall explain the
function, powers and responsibility of each officer.
71. The organisation chart and the task description shall be established based on
the principle of segregation of duties. Pursuant to this principle, the duties and responsibilities shall be assigned so as to avoid making them incompatible for the same person. The goal pursued shall be to avoid conflicts of interest and to prevent through reciprocal controls environment a person from making mistakes and committing irregularities which would not be identified.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 30/85
72. Pursuant to Article 7(2) of the LFS, the authorised management shall be jointly
liable for the management of the institution. The principle of segregation of duties shall not derogate from this joint liability. It shall remain compatible with the practice whereby the members of the authorised management share the day-to-day tasks relating to the close monitoring of the various activities. The institution must organise this allocation so as to avoid conflicts of interest. Thus, the same member of the authorised management cannot be in charge of or be responsible for functions relating to both the risk-taking and the independent control of these risks. Moreover, if in an institution limited in size and activity, and composed of only two authorised managers, there are conflicts of interest between these two managers following the assignment of the risk-taking function and the risk control function and if these conflicts of interest cannot be mitigated effectively, a third authorised manager shall be appointed.
73. The institution shall have a continuing vocational training programme which
shall ensure that the staff members as well as the management body remain qualified and understand the internal governance arrangements as well as their own roles and responsibilities in this regard.
74. Each staff member must take at least two consecutive calendar weeks of
personal leave annually. It must be assured that each staff member is actually absent during that leave and that his/her substitute actually takes charge of the work of the absent person. Sub-chapter 5.2. Procedures and internal documentation
75. The institutions shall document all central administration and internal
governance arrangements in writing.
This documentation shall relate to the strategies, guiding principles, policies and procedures relating to central administration and internal governance. It shall include a clear, comprehensive, detailed and accessible manual of procedures, whose procedures shall be known by the entire staff concerned and which is updated on an ongoing basis.
76. The description of the procedures to ensure the proper execution of activities
shall concern the following points:
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 31/85
77. The institutions shall document, in writing, all their transactions, i.e. any
process which includes a commitment on the part of the institution as well as the decisions relating thereto. The documentation shall be updated and kept by the institution in accordance with the law. It should be organised in such a way that it can be easily accessed by any authorised third party. By way of illustration as regards credit transactions, full documentation of the decisions to grant, change or terminate credits shall be included in the institution’s files in Luxembourg, as well as the agreements and any documents relating to the follow-up of the debt service and evolution of the debtor’s financial situation.
78. The files, working papers and control reports of the internal control functions,
experts and service providers referred to in Sub-chapter 6.2 as well as the long form reports drawn up by the réviseur d'entreprises agréé shall be kept in the Luxembourg institution during at least five years, without prejudice to other applicable laws, in order to enable the institution to retrace the controls carried out, the identified problems, shortcomings or irregularities as well as the recommendations and conclusions. The competent authority as well as the réviseur d’entreprises agréé must always be able to access these documents.
79. All transaction orders initiated by the institution and all correspondence with
the customers or their proxies shall be issued by the institution; all correspondence shall be addressed thereto. In the case where the institution has a branch abroad, the latter is the contact point for its own customers. Sub-chapter 5.3. Administrative and technical infrastructure
80. The institution shall have the necessary and sufficient support functions,
material and technical resources to execute its activities.
Section 5.3.1. Administrative infrastructure of the business
functions
81. Each business function must be based on an administrative infrastructure
which guarantees the implementation of the business decisions taken and their proper execution, as well as compliance with the powers and procedures for the area in question.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 32/85
Section 5.3.2. Financial and accounting function
82. The institution shall have a financial and accounting department whose mission
is to assume the accounting and financial management of the institution. Some parts of the financial and accounting function within the institution may be decentralised, provided however that the central financial and accounting department centralises and controls all the entries made by the various departments and prepares the global accounts. The financial and accounting department must ensure that other departments intervene in full compliance with the chart of accounts and the instructions relating thereto. The central department shall remain responsible for the preparation of the annual accounts and the preparation of the information to be provided to the competent authority. In the significant institutions, the CFO shall be selected, appointed and removed from office according to a written internal procedure and with the prior approval of the supervisory body.
83. The financial and accounting function shall operate based on written
procedures which shall provide for:
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 33/85
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 34/85 While defining and implementing these procedures, the institutions shall ensure compliance with the principle of integrity in order to avoid, in particular, that the accounting system is used for fraudulent purposes.
Section 5.3.3. IT function
90. The institutions shall organise their IT function so as to have control over it
and to ensure robustness, effectiveness, consistency and integrity pursuant to
Chapter 3 of this part. For those purposes, they shall comply with the
requirements of Circular CSSF 20/750 on requirements regarding information and communication technology (ICT) and security risk management.
91. Institutions which rely on service providers as regards the IT function shall
comply, in particular, with the conditions laid down in Circular CSSF 22/806 on outsourcing arrangements.
Section 5.3.4. Communication and internal and external alert
arrangements
92. The internal communication arrangements shall ensure that the strategies,
policies and procedures of the institution as well as the decisions and measures taken by the management body, directly or by way of delegation, are communicated in a clear and comprehensive manner to all staff members of the institution, considering their information needs and their responsibilities within the institution. The internal communication arrangements shall enable staff to have easy and constant access to this information.
93. The management information system shall ensure that all management
information is, in normal circumstances and in times of stress, transmitted, in a clear and comprehensive manner, and without delay, to all members of the management body and staff of the institution, considering their information needs, their responsibilities within the institution and the objective to ensure a sound and prudent business management.
94. The institutions shall maintain internal alert arrangements (whistleblowing)
which shall enable the entire staff of the institution to draw attention to legitimate concerns about internal governance, internal requirements or the national and Union regulatory frameworks. These arrangements shall keep confidential the identity of the persons who raise such concerns as well as of the persons that are presumed to be responsible for breaches. These arrangements shall provide for the possibility to raise these concerns outside the established reporting lines as well as with the supervisory body. They shall guarantee appropriate follow-up and safekeeping of the files. The alerts issued in good faith shall not result in any liability or adverse impact of any sort for the persons who issued them.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 35/85
95. The CSSF has also made a tool and a procedure to report incidents directly to
it available on its website.
(https://whistleblowing.apps.cssf.lu/index.html?language=en).
Section 5.3.5. Crisis management arrangements
96. The crisis management arrangements shall be based on resources (human
resources, administrative and technical infrastructure and documentation) which shall be easily accessible and available in emergencies.
97. The crisis management arrangements shall ensure that, in times of stress, the
credit institutions provide the public with the information referred to in the CEBS guidelines published on 26 April 2010 (“Principles for disclosures in times of stress (Lessons learnt from the financial crisis)”).
98. The crisis management arrangements shall include a recovery plan which shall
comply with the requirements of Chapter 2 of Part IV of the LFS.
99. The crisis management arrangements shall be tested and updated, on a
regular basis, in order to ensure and maintain its effectiveness.
Chapter 6. Internal control
100.The internal control shall be a control system composed of rules and procedures which aim to ensure that the objectives set by the institution are reached, the resources are effectively used, the risks are controlled and the assets and liabilities are protected, the financial and management information is accurate, comprehensive, relevant, understandable and available without delay, the laws and regulations as well as the internal policies and procedures are complied with and that the requests and requirements of the competent authority are met8. 8 The internal control mechanisms also provide for mechanisms aimed to prevent execution errors and frauds and to enable their early detection. Pursuant to the principle of proportionality, institutions whose asset management activity and service activities related in particular to the administration of UCIs are significant, define adequate internal control mechanisms for these activities, in particular in the field of discretionary management, processing of held mails, safekeeping of securities of third parties (depositary bank), bookkeeping and net asset value calculation of investment funds.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 36/85 The internal control arrangements must include effective processes and procedures preventing fraud and ensuring compliance with the obligations regarding the fight against money laundering and terrorist financing. The institutions should assess their exposure to the risk of being misused for money laundering or terrorist financing purposes, adapt their control arrangements to the level of identified risk (risk-based approach) and take efficient mitigating measures to reduce this risk, as well as the associated operational and reputational risks. These arrangements guarantee adequate information and training of staff in relation to these risks. 101.The internal control arrangements of an institution must be adapted to its organisation and to the nature, scale and complexity of its activities and relating risks and comply with the principles of the “three lines of defence” model. The first line of defence consists of the business units which take or are exposed to risks, which are responsible for their management and which monitor compliance with the policies, procedures and limits imposed on them, on a permanent basis. The second line consists of support functions, such as the financial and accounting function, and especially the compliance and the risk management control functions which control risks on an independent basis and support the business units in complying with the applicable policies and procedures. The third line consists of the internal audit function which makes an independent, objective and critical assessment of the first two lines of defence and of the internal governance arrangements as a whole. The three lines of defence are complementary, each line of defence assuming its control responsibilities regardless of the other lines. The implementation of sound internal control arrangements shall go hand in hand with a relevant segregation of functions, duties and responsibilities, the implementation of a management of information access and the physical separation of certain functions and departments in order to secure data and transactions. Sub-chapter 6.1. Operational controls A sound internal control environment shall include the following types of controls:
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 37/85
Section 6.1.1. Day-to-day controls carried out by the operating
staff
102.The internal control procedures shall provide that the operating staff control, on a day-to-day basis, the transactions they carry out in order to identify as soon as possible the errors and omissions that occurred during the processing of the current transactions. Examples of these controls are: the verification of the cash account balance, the verification of his/her positions by the trader, the follow-up of outstanding issues by each staff member.
Section 6.1.2. Ongoing critical controls
103.This category of controls shall include inter alia:
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 38/85
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 39/85
Section 6.2.1. General responsibilities of the internal control
functions
106.The main purpose of the internal control functions shall be to verify compliance with all the internal policies and procedures which fall within the area for which they are responsible, to regularly assess their adequacy with respect to the organisational and operational structure, the strategies, the activities and the risks of the institution as well as with respect to the applicable legal and regulatory requirements, and to report directly to the authorised management as well as to the supervisory body and, where appropriate, to the specialised committees. They shall provide the authorised management and the supervisory body, and, where appropriate, the specialised committees with the opinions and advice they deem useful or which are requested by these bodies or committees. Notwithstanding the relevant specific responsibilities assigned to the Compliance function, all the internal control functions shall contribute to the efficient fight against money laundering and terrorist financing. 107.Where they consider that the effective, sound or prudent business management is compromised, the heads of the internal control functions shall promptly inform, on their own initiative, the authorised management and the supervisory body or, where appropriate, the specialised committees. 108.Where the institution is the group head, its internal control functions shall supervise and control the internal control functions of the different entities of the group. The internal control functions of the institution shall ensure that the problems, shortcomings, irregularities and risks identified throughout the whole group are reported to the local management and supervisory bodies as well as to the authorised management and to the supervisory body of the group head.
Section 6.2.2. Characteristics of the internal control functions
109.The internal control functions shall be permanent and independent functions each with sufficient authority. The heads of these functions shall have direct access right to the supervisory body or its chairperson or, where appropriate, to the specialised committees which are part of it, to the réviseur d’entreprises agréé of the institution as well as to the competent authority. The independence of the internal control functions is incompatible where:
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 40/85
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 41/85
Section 6.2.3. Execution of the internal control functions' work
116.The internal control functions shall document the work carried out in accordance with the assigned responsibilities, in particular in order to allow retracing the interventions as well as the conclusions reached. 117.The internal control functions shall report, in writing, on a regular basis and, if necessary, on an ad hoc basis, to the authorised management and the supervisory body or, where appropriate, to the specialised committees. These reports shall concern the follow-up to the recommendations, problems, shortcomings and irregularities found in the past as well as the new identified problems, shortcomings and irregularities. Each report shall specify the risks related thereto as well as their severity (measuring the impact) and shall propose corrective measures, as well as in general the position of the persons concerned. Each internal control function shall prepare, at least once a year, a summary report on its activities and its operation covering all the activities assigned to it. As regards the activities, each summary report shall include a statement of the function’s activities carried out since the last report, the main recommendations to the authorised management, the (existing or emerging) problems, the major shortcomings and irregularities found since the last report and the measures taken in this respect as well as the statement of the problems, shortcomings and irregularities identified in the last report but which have not yet been subject to appropriate corrective measures. Finally, the report shall indicate the state of their control area as a whole. As far as operation is concerned, the report shall, in particular, comment on the adequacy of the internal human and technical resources, and the nature and level of reliance on external human and technical resources as well as on any problems which may have occurred in this context. This report shall be submitted for approval to the supervisory body or the competent specialised committees to ensure its follow-up and that the supervisory body is informed; it shall be submitted for information to the authorised management. In case of serious problems, shortcomings and irregularities, the heads of the internal control functions shall immediately inform the authorised management, the chairperson of the supervisory body and, where appropriate, the chairpersons of the specialised committees. In such cases, the heads of the internal control functions may request to be heard by the specialised committees in a private meeting. The internal control functions shall verify the effective follow-up of the recommendations relating to the problems, shortcomings and irregularities identified in accordance with the procedure laid down in the third paragraph of point 57. They shall report on this subject to the authorised management on a regular basis.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 42/85
Section 6.2.4. Organisation of the internal control functions
118.Each internal control function shall be under the responsibility of a separate head of the function who shall be selected, appointed and dismissed in accordance with a written internal procedure. The appointments and removals of the heads of the internal control functions shall be approved beforehand by the supervisory body and reported in writing to the competent authority in accordance with the Prudential Procedure as published by the CSSF on its website. 119.The heads of the three internal control functions shall be responsible vis-à-vis the authorised management and, ultimately, vis-à-vis the supervisory body for the performance of their mandate. In this respect, these heads must be able to contact, directly and on their own initiative, the chairperson of the supervisory body or, where appropriate, the competent specialised committee. The heads of the three internal control functions shall be referred to as Chief Risk Officer for the risk management control function, Chief Compliance Officer for the compliance function and as Chief Internal Auditor for the internal audit function. 120.Outsourcing of the compliance function and risk management control function is not authorised. The full range of operational tasksactivities of the internal audit function may be outsourced by small institutions with a low and non-complex risk profile. Such outsourcing is not, in principle, acceptable for institutions with agencies, branches or subsidiaries. The supervisory body of the institution shall remain ultimately responsible for outsourcing the outsourced internal audit tasksactivities. ServiceExternal providers entrusted with the outsourced internal audit tasksactivities shall depend on and report directly to the member of the authorised management in charge of internal audit. They shall have direct access to the supervisory body or, where appropriate, the chairperson of the audit committee. 121.The provisions of the preceding point shall not exclude the possibility for the internal control functions to use, on an ad hoc basis, external expertise and human or technical means or to outsource certain tasks to a provider (belonging or not to the same group as the institution). 122.This ad-hoc use of external resources shall be governed by an internal procedure which must allow, in particular, the authorised management and the supervisory body to assess the dependencies and risks which a significant use of these external resources might pose for the institution.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 43/85 The authorised management shall select these external resources based on an analysis of correlation between the institution’s needs and services, the level of objectivity and independence, and the specific skills offered by these experts which must be independent from the institution’s réviseur d'entreprises (statutory auditor) and cabinet de révision agréé (approved audit firm) and from the group to which these parties belong. The supervisory body shall approve the external resources selected by the authorised management. Any ad-hoc use of external resources must be based on a written mandate. These experts shall carry out their work in accordance with the regulatory and internal provisions applicable to the internal control function and the area of control in question. They must be placed under the authority of the head of the internal control function covering the controlled area. This head shall supervise the work of these third parties. 123.Any outsourcing of activities or tasks shall follow the provisions of Circular CSSF 22/806 on outsourcing arrangements. 124.Where the institution can demonstrate, in accordance with the principle of proportionality, that there is no justification for setting up a distinct risk management control function and a compliance function or for appointing two heads of these functions full time, the institution may set up a combined function or a position with combined responsibility, subject to prior approval of the competent authority. However, the application of the principle of proportionality may not result in the accumulation of other responsibilities for a person already combining the responsibility for the risk management control function and the compliance function. The institution wishing to create a combined risk management control and compliance function, allocate the responsibilities for these two functions to one single person or combine one of these responsibilities with other tasks must submit a request to the competent authority which shall include:
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 44/85 125.The institution wishing, in accordance with the principle of proportionality, to outsource the full range of operational tasks of the internal audit function must submit a prior request to the competent authority by using the CSSF notification template for outsourcing a critical or important business process (Business Process Outsourcing/BPO)9. which shall include:
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 45/85 Pursuant to the principle of proportionality, the institution which created three permanent and independent internal control functions may decide not to set up individual internal control functions in the legal entities or branches of the group which are limited in size and activities. In this case, the institution shall ensure that its internal control functions carry out regular and frequent controls, including annual on-site inspections of these entities. Where the institution is not a parent undertaking, it shall seek to obtain a summary of the reports of the internal control functions of the legal entities in question and have them analysed by its own internal control functions. They shall report the major recommendations, main problems, shortcomings and irregularities identified, agreed corrective measures and the effective follow-up of these measures in accordance with point 116. 128.The principles of this Circular shall not exclude that, for Luxembourg institutions, whether or not they are branches or subsidiaries of Luxembourg financial professionals having internal control functions at the level of these professionals, the internal control functions are functionally linked to those of the professional in question.
Section 6.2.5. Risk management control function
Sub-section 6.2.5.1. Scope and specific responsibilities of the risk management control function 129.The risk management control function shall ensure that all business units anticipate, identify, assess, measure, monitor, manage and duly report all the risks to which the institution is or may be exposed. It shall carry out its tasks continuously and without delay. It shall be a central element of the internal governance and organisation of the institution dedicated to limiting risks. It shall inform and advise the supervisory body and assist the authorised management, propose improvements in the risk management framework and actively participate in the decision-making processes, ensuring that appropriate attention is given to risk considerations. The ultimate responsibility for the decisions regarding risks shall remain, however, with the business units which take the risks and, finally, with the authorised management and supervisory body. Thus, the term “risk management control function” shall not reduce this function to a simple ex-post “control” of the limits. 130.The scope of intervention of the risk management control function shall cover the whole institution, including the risks associated with the complexity of the institution’s legal structure and the relationships and operations of the institution with related parties.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 46/85 131.The risk management control function shall ensure that the internal risk objectives and limits are robust and compatible with the regulatory framework, the internal strategies and policies, the activities, and the organisational and operational structure of the institution. It shall monitor compliance with these objectives and limits, propose appropriate remedial measures in case of breach, ensure compliance with the escalation procedure in case of significant breach and ensure that the breaches are remedied as soon as possible. 132.The head of the risk management control function shall ensure that the authorised management and the supervisory body receive an independent, comprehensive, objective and relevant overview of the risks to which the institution is or may be exposed10. This overview shall include, in particular, an assessment of the correlation between these risks and the own funds and liquidity reserves and the institution's ability to manage these risks in normal times and in times of stress. This assessment shall be based, in particular, on the stress test programme in accordance with Circular CSSF 11/506. It shall also include an assessment of the correlation between the risks incurred and the strategy and the risk appetite defined by the supervisory body. The frequency of this communication shall be adapted to the institution’s characteristics and needs, in view of its business model, the risks incurred and its organisation. The summary annual report of the risk management control function, a copy of which shall be provided to the competent authority, possibly duplicates elements of the ICAAP and ILAAP report. The risk management control function may therefore refer to the ICAAP and ILAAP report in its summary report, provided that it agrees with the descriptions and analyses of risks contained therein. In case of disagreement, the risk management control function shall provide its own assessments and conclusions in its summary report. 133.The risk management control function shall ensure that the terminology, methodology and technical resources used for the risk anticipation, identification, measurement, reporting, management and control are consistent and effective. 134.The risk management control function shall ensure that the risk assessment is based on conservative assumptions and on a range of relevant scenarios, in particular regarding dependencies between risks. Quantitative assessments shall be validated by qualitative assessment methods and expert judgements based on structured and documented analyses. 10 In line with “Principles for effective risk data aggregation and risk reporting” (BCBS 239) of January 2013.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 47/85 The risk management control function shall inform the authorised management and supervisory body of the assumptions, limits and possible deficiencies of the applied analyses and models and must regularly compare its ex-ante assessments of the possible risks measured with ex-post materialised risks to improve the accuracy of its assessment methods (backtesting). 135.The risk management control function shall strive to anticipate and recognise the risks arising in a changing environment. In this respect, it shall also accompany the implementation of the changes in the activities (“New Product Approval Process”) in order to guarantee that the associated risks remain under control. Sub-section 6.2.5.2. Organisation of the risk management control function 136.The institutions shall create a permanent and independent risk management control function, considering the principle of proportionality and the criteria governing its application as well as the considerations regarding the organisation of the internal control functions laid down in Section 6.2.4. Where the organisation of an institution, the scale and complexity of its activities or even the incurred risks justify setting up satellite risk management control or compliance functions within the business units, the institution must nevertheless set up a central risk management control function to which the different satellite functions shall report. This central function shall manage the consolidated overview of risks and ensure compliance with the defined risk strategies and appetite. 137.Within the significant institutions, the head of the risk management control function shall be a member of the authorised management who is independent and individually responsible for the risk management control function. Where the principle of proportionality does not require such an appointment, another member of the senior management of the institution may assume that function, provided there is no conflict of interest.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 48/85 138.The head of the risk management control function must be is should be able to challenge decisions taken by the institution’s management and its management body, and the grounds for objections should be formally documented., when deemed necessary, to raise awareness and confront, including in writing, both senior management and/or the management body on any decision or potential decision affecting an institution’s exposure to risk to challenge the decisions of the authorised management. These challenges and the reasons cited must be documented by the institution. Where the institution wishes to grant the Chief Risk Officer the right to veto decisions made at levels below the management body, it should specify the scope of such veto right, the escalation or appeal procedures, and how to interact with the management body will be involved.gives a veto right over the decisions of the authorised management to the Chief Risk Officer, the scope of this right must be decided clearly and in writing, including the escalation process of the supervisory body. The decisions which were given a reasoned negative opinion by the Chief Risk Officer should be subject to an enhanced decision-making process.
Section 6.2.6. Compliance function
This Circular comprises the “general guidelines” contained in the ESMA Guidelines on certain aspects of the MiFID II compliance function requirements (ESMA35-36-1952) and applies them to all the activities of the institution, including the provision of investment services. Where the institutions implement these requirements in relation to investment services within the meaning of the LFS, they shall take into account the “supporting guidelines” set out in ESMA35-36-1952. Sub-section 6.2.6.1. Compliance charter 139.The operational arrangements of the compliance function in terms of objectives, responsibilities and powers shall be laid down in a compliance charter drawn up by the compliance function and approved by the authorised management and ultimately by the supervisory body. 140.The compliance charter must at least:
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 49/85
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 50/85
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 51/85 The summary report of the compliance function, a copy of which shall be submitted to the competent authority and shall cover the field of antimoney laundering and counter terrorist financing in a dedicated chapter laying down in a concise yet comprehensive manner the activities and events relating to this area, i.e. the main recommendations issued, major (existing or emerging) deficiencies, irregularities and problems identified, the corrective and preventive measures implemented, as well as a list of deficiencies, irregularities and problems which have not yet been subject to appropriate corrective measures. The report shall describe the progress of the AML/CFT compliance monitoring plan and explain the elements of the plan that could not be achieved within the time limits set out. The report must allow assessing the seriousness of the events covered and the adequacy of the compliance monitoring plan, in order to allow an overall assessment of the adequacy and efficient functioning of the AML/CFT preventive framework set up by the institution;
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 52/85 146.The compliance function shall assist and advise the authorised management on issues of compliance and applicable laws, regulations and standards, notably by drawing its attention to changes in standards which may subsequently have an impact on the compliance area. 147.The compliance function shall raise awareness of the staff about the significance of compliance and related aspects and assist them in their day-today operations related to compliance. To this end, it shall also develop an ongoing training programme and ensure its implementation. 148.The Chief Compliance Officer shall be the key contact person of the competent authorities in relation to the fight against money laundering and terrorist financing for any question in this respect as well as in relation to market abuse. It shall also be in charge of the transmission of any information or report to these authorities. Sub-section 6.2.6.3. Organisation of the compliance function The institutions shall create a permanent and independent compliance function, considering the principle of proportionality and the criteria governing its application as well as general considerations regarding the organisation of the internal control functions laid down in Section 6.2.4.
Section 6.2.7. The internal audit function
Sub-section 6.2.7.1. Internal audit charter 149.The operational arrangements of the internal audit function in terms of objectives, responsibilities and powers must be laid down in an internal audit charter drawn up by the internal audit function and ultimately approved by the supervisory body. The internal audit charter must at least:
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 53/85
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 54/85 Sub-section 6.2.7.2. Specific responsibilities and scope of the internal audit function 151.The internal audit function shall examine and assess, among others (nonexhaustive list12), the following in accordance with the organisation and the nature, scale and complexity of the activities:
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 55/85 Sub-section 6.2.7.3. Execution of the internal audit work 154.All internal audit missions shall be planned and executed in accordance with an internal audit plan. The plan shall be established by the head of the internal audit function for a period of several years (in general three years). Its purpose shall be to cover all activities and functions, considering both the risks posed by an activity or function and the effectiveness of the organisation and internal control in place for this activity or function (risk-based approach). The plan shall consider the opinions issued by the supervisory body or, where appropriate, the audit committee as well as the authorised management. The plan shall cover all matters of prudential interest (including the competent authority’s observations and requests) and shall also reflect the developments and innovations provided for as well as the risks which may arise therefrom. 155.The plan shall be discussed with the authorised management and, where appropriate, with the audit committee and ultimately approved by the supervisory body. It shall be reviewed, on an annual basis, and adapted to developments and emergencies. The plan shall be reviewed by the authorised management and, where appropriate, by the audit committee before being approved by the supervisory body. The approval implies that the authorised management provides the internal audit department with the means necessary to implement the internal audit plan. In its summary report to the supervisory body, the internal audit shall indicate and state the reasons for the main changes brought to the audit plan as initially approved by the supervisory body: cancelled missions, delayed missions as well as the missions whose scope has significantly changed. 156.The plan shall set out the objectives of each mission and the scope of the tasks to be executed, give an estimate of the necessary time and human and material resources and assign an audit frequency to each activity and risk. The internal audit plan shall also provide for the adequate and sufficiently frequent coverage, within a multi-year planning period, of important or complex activities with a potential significant risk, including a reputational risk. It shall focus on the risk of execution errors and the risk of fraud. The internal audit plan shall provide for adequate coverage of areas with a risk of money laundering or terrorist financing, so that the internal audit may give an account of the compliance with the policy regarding the fight against money laundering and terrorist financing in its summary report on an annual basis. 157.Where the internal audit department of the parent undertaking of the Luxembourg institution carries out on-site inspections of its subsidiary on a regular basis, it is recommended for reasons
of effectiveness that, in so far as possible, the Luxembourg institution coordinates its internal audit plan with that of the parent undertaking.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 56/85 158.The internal audit department shall regularly inform the authorised management and, where appropriate, the audit committee on the implementation of the internal audit plan. 159.Each internal audit mission shall be planned, executed and documented in compliance with the professional standards adopted by the internal audit function in its internal audit charter. 160.Each mission shall be the subject of a written report of the internal audit department, in general, intended for the audited persons, the authorised management as well as - possibly in summarised form - for the supervisory body (and, where appropriate, the audit committee). The reports shall also be made available to the réviseur d'entreprises agréé and the competent authority. These reports shall be drafted in French, German or English. The internal audit department shall prepare a table of the internal audit missions and the written reports related thereto. It shall draft, at least once a year, a summary report. Sub-section 6.2.7.4. Organisation of the internal audit function 161.The institutions shall create a permanent and independent internal audit function, considering the principle of proportionality and the criteria governing its application as well as the considerations regarding the organisation of the internal control functions laid down in Section 6.2.4.
162. (Removed as part of the update of the 29 August 2024)
162.In case the operational tasks of the internal audit are outsourced, the external providers shall carry out their work under the internal audit plan of the institution by following a work programme, by producing detailed documentation on their work and by drafting reports for each mission. These reports shall be drafted in French, German or English and submitted to the designated head of the function, the authorised management, where appropriate, the audit committee and the supervisory body.
Chapter 7. Specific requirements
Sub-chapter 7.1. Organisational structure and legal entities (Knowyour-structure) 163.The organisational structure shall, in terms of legal entities (structures), be appropriate and justified as regards the strategies and guiding principles. It shall be clear and transparent for all the stakeholders.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 57/85 The legal, organisational and operational structure must enable and promote effective, sound and prudent business management. It must not impede the sound governance of the institution, in particular the ability of the management body, to effectively manage and oversee the activities (and the risks) of the institution and the different legal entities which are part of it. The group head institution shall clearly define and delineate the powers which it agrees to delegate to the managers of the legal entities which are part of the group in order to make sure that the parent undertaking can monitor their activity, on an ongoing basis, and that it is involved in any transaction of a certain importance. 164.The guiding principles that the supervisory body lays down as regards the organisational structure (in terms of legal entities) shall provide notably that:
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 58/85
c. the extent to which the jurisdiction in which a given structure will
be or is established complies with the international and EU standards on tax transparency and anti-money laundering and combating the financing of terrorism; d. the extent to which the structure serves a clear and legal economic purpose; e. the extent to which the structure could be used to hide the identity of the ultimate beneficial owner; f. the extent to which the customer’s request to create such a structure gives rise to doubts; g. the fact that the structure might impede appropriate supervision by the management body or the capacity of the institution to manage the related risk; and h. the fact that the structure includes elements that are an obstacle to efficient supervision by the competent authorities. When exercising complex or non-transparent activities for its customers, such as creating complex structures or instruments, financing of transactions or providing fiduciary services, which create, in particular, significant operational and reputational risks, the institution shall apply the same risk control measures than for its own activities. The institution shall notably analyse the reason why a customer wishes to set up a particular structure. Sub-chapter 7.2. Management of conflicts of interest 167.The policy on the management of conflicts of interest shall cover all conflicts of interest, for economic, personal, professional or political purposes, whether they are persistent or linked to a single event. Particular attention must be given to the conflicts of interest between the institution and its related parties and service providers. This policy shall be applicable to all staff as well as to the authorised management and members of the supervisory body. 168.The policy on the management of conflicts of interest shall provide that all current and possible conflicts of interest must be identified, assessed, managed and mitigated or avoided. Where conflicts of interest remain, the policy in this respect shall lay down the procedures to be followed in order to report, document and manage them so as to avoid that the institution, its counterparties and the customers suffer unjustified consequences thereof. The policy and procedures in question shall also include the procedure to be followed in case of non-compliance with this policy.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 59/85 169.The policy on the management of conflicts of interest shall provide for the identification of the main sources of conflicts of interest - potentially affected relationships and activities as well as all internal and external parties involved
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 60/85 174.Any material change in significant transactions carried out with related parties must be brought immediately to the attention of the supervisory body, which must take a new decision. 175.Transactions with related parties must be carried out objectively and in the interest of the institution. The institution’s interest is not met where transactions with related parties:
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 61/85
Section 7.2.2. Documentation of loans granted to members of
the management body and to their related parties 179.The institution shall document the key data relating to loans granted to members of the management body and to their related parties. For the purpose of this point, related parties shall mean a spouse, registered partner in accordance with the applicable national law, child or parent, commercial entity, in which a member of the management body or his or related party has a qualifying holding of 10 % or more of capital or of voting rights in that entity, or in which those persons can exercise significant influence, or in which those persons hold authorised management positions or are members of the management body. The information that must be documented includes:
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 62/85 Sub-chapter 7.3. New Product Approval Process 180.The new product approval process shall cover the development of new activities in terms of products, services, markets, systems and processes or customers as well as their material changes and exceptional transactions. It shall guarantee that any new product remains consistent with the guiding principles established by the supervisory body, the risk strategy, the risk appetite of the institution and the relevant limits. 181.The new product approval process shall define, in particular, the changes in the activities subject to the approval process, the considerations to be taken into account, the main issues to be addressed as well as the implementation of the approval process, including the responsibilities of all the parties concerned. The main issues to be addressed shall include regulatory compliance, accounting, pricing models, the impact on risk profile, capital adequacy and profitability, the availability of adequate front, back and middle office resources and the availability of adequate internal tools and expertise to understand and monitor the associated risks. 182.Consequently, the institutions shall carefully analyse any proposed change in the activities and ensure that they have the ability to bear the risks related thereto, the technical infrastructure and sufficient and competent human resources to control these activities and the associated risks. The business unit requesting the change in its activities shall be in charge of issuing an analysis of the risks in this regard. Similarly, the risk management control function shall carry out a prior, objective and comprehensive analysis of the risks associated with any proposed change in the activities. The risk analysis shall take into account the various scenarios and shall indicate, in particular, the ability of the institution to bear, manage and control the risks inherent in the planned activities. The money-laundering and terrorist-financing risk and the general compliance risk associated with new products shall also be subject to prior analysis by the compliance function. 183.No new activity must be undertaken unless the authorised management approved it, all relevant parties have been heard, and the means mentioned in the preceding point are available. 184.The internal control functions may require that a change in activities shall be deemed to be material and thus be subject to the approval process. Sub-chapter 7.4. Outsourcing 185.Outsourcing shall not lead to a situation in which the spirit or the letter of this Circular on central administration, internal governance and risk management are no longer complied with.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 63/85 For a definition of outsourcing and general requirements and information relating to outsourcing of activities (in addition to those applicable to the internal control functions in accordance with Chapter 6.2 of this part), reference is made to Circular CSSF 22/806 on outsourcing. As regards outsourcing of activities relating to the fight against money laundering and terrorist financing, reference is also made to CSSF Regulation 12-02 on the fight against money laundering and terrorist financing.
Chapter 8. Legal reporting
186.The credit institutions shall provide the competent authority with the ICAAP/ILAAP reports and the annual certificate of compliance with the requirements of this Circular as well as the summary reports of the internal control functions in accordance with the requirements of Circular CSSF 195/731602. The relevant information shall be drafted in French, German or English.
Part III. Risk management
Chapter 1. General principles as regards risk measurement and
risk management
Sub-chapter 1.1. Institution-wide risk management framework
Section 1.1.1. General information
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 64/85
Section 1.1.2. Specific (risk, capital and liquidity) policies
3. The risk policy which implements the risk strategy defined by the supervisory
body shall include:
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 65/85
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 66/85 Consequently, the institutions must avoid any excess of confidence in any specific methodology or model. The risk measurement techniques used must always be the subject of an internal, independent, objective and critical validation and the risk measurements which arise from these techniques are to be critically assessed, and wisely and carefully used by all staff, the authorised management and the supervisory body of the institution. The quantitative risk assessments shall be supplemented by qualitative approaches, including (independent) expert judgements, based on structured and documented analyses.
Chapter 2. Concentration risk
11. Concentration risk results, in particular, from large concentrated exposures to
customers, counterparties or service providers, respectively, groups of customers, counterparties or related service providers, including related parties, to countries or sectors (industries) as well as to specific products or markets (intra-risk concentration). These exposures are not necessarily limited to balance sheet items or off-balance sheet items. Moreover, concentration risk may be the result of various risks (credit risk, market risk, liquidity risk, operational risk - in particular those related to outsourcing - or systemic risk) which combine (inter-risk concentration). Intra-risk or inter-risk concentrations may result in economic and financial losses as well as in a significant and negative impact on the risk profile of the institution. Concentration risk must be subject to particular vigilance and identification effort as it may jeopardise the financial stability of the institution.
12. For institutions operating on the domestic market, there is generally a
concentrated exposure to the Luxembourg real estate market. A significant market downturn would undermine the financial stability of these institutions and have an adverse impact on the image of the Luxembourg financial centre as a whole. Consequently, the institutions shall implement prudent policies as regards the granting of real estate mortgage credits pursuant to Sub-chapters
3.2 and 3.3.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 67/85
Chapter 3. Credit risk
Sub-chapter 3.1. General principles14
13. Risk-taking within the meaning of this sub-chapter shall mean not only the
decisions on new credits to be granted, but also the decisions made in the context of the restructuring or renegotiation of exiting credits, particularly following a significant deterioration of the debtor’s creditworthiness. The restructuring and renegotiations (forbearance) shall comprise, in particular, granting extensions, deferrals, renewals or amendments of the credit terms, including the repayment plan and any forbearance measures within the meaning of Article 47b of the CRR and non-performing loans within the meaning of Article 47a(3) of the CRR.
14. Each credit risk-taking must be subject to a written analysis which shall cover
at least the debtor’s creditworthiness, the repayment plan and the borrower’s repayment ability over the period of the borrowing. In particular, the credit decision cannot be based on an exclusive analysis of collateral or other credit risk mitigation techniques15. The institutions shall take into account the overall debt level of the debtor or the group of associated debtors, respectively. Regular repayments cannot exceed an amount which would not allow Repayment plans shall be designed in such a way as to leave the borrower withto have an adequate disposable income. There must be a reasonable security margin in order to cover an increase in interest rates and, where applicable, changes in foreign exchange rates.
15. Each credit risk-taking must be subject to a predetermined decision-making
process which shall also involve a body separate from the business function. For low credit risk-taking in terms of risk exposure, the institutions may put in place a grant-making process which enables them to monitor this risk-taking, as a whole, without necessarily going through the decision-making processes and individual analyses as referred here. 14 Supplementing the provisions of Article 53-15 of the LFS and the relevant Article of RCSSF 15-02 regarding credit and counterparty risk. In implementing these rules, institutions shall comply with the applicable EBA guidelines as adopted by the CSSF. See in particular Circular CSSF 22/824 adopting Guidelines EBA/GL/2020/06, and the related FAQ, as well as Circular CSSF 17/675 adopting Guidelines EBA/GL/2017/06. 15 Without prejudice to point 33 and the FAQ relating to the provisions of Circular CSSF 22/824 on the application of the Guidelines of the European Banking Authority on loan origination and monitoring (EBA/GL/2020/06).
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 68/85 The institutions shall be in charge of internally defining the concept of “low” credit risk for the purposes of the preceding paragraph. This definition shall focus at least on the institution’s ability to manage, bear and control these risks, on the one hand, and on the exposure amount and credit quality of the debtor and transaction, on the other hand. Sub-chapter 3.2. Exposures to individuals secured by mortgages on Rresidential real estate mortgage credit to individuals property
16. The institutions shall apply a prudent credit granting policy which aims to
safeguard their financial stability regardless of the observed or expected developments in the residential real estate market. This policy shall focus on healthy values of debt ratios and ratios between debt burden and income for the whole credit duration, as well as between the amount of the credit granted and the value of the mortgaged residential propertythe obtained guarantees (loan-to-value), including the underlying mortgage on the property, based on prudent assessment methods. When defining their policy, institutions take due account of the requirements of the CSSF Regulation No 20-08 (which sets limits on lending criteria with a view to maintaining financial stability) and the provisions of the Law of 23 December 2016 transposing Directive 2014/17/EU on residential mortgage loans. Sub-chapter 3.3. Exposures to the real estate developmentsCredits to real estate developers
17. Credit risk-taking in property development should not be based solely on the
reputation of the developer.
Each real estate development project financing must provide for a start date of the principal repayment when the credit is granted. This date cannot exceed a reasonable time limit as regards the beginning of the project financing. When this time limit is exceeded, the file shall be automatically classified under the list of credits “in default” within the meaning of Article 178 of the CRR, Article 14 of CSSF Regulation 18-03 and EBA/GL/2016/07 and the full provisioning of unpaid interest. The institution shall monitor the progress of the project to ensure that the deadline is met. The institution shall reassess the property developer's situation and, if necessary, adjust the repayment schedule for each extension of the original deadline and each subsequent extension. Moreover, the financing must be covered at all times, in addition to the mortgage on the financed object, by a personal guarantee of the developer, and, if necessary, by the economic beneficiaries of the development, unless other guarantees or securities significantly cover the total cost of the financed object.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 69/85 When assessing debtors or The real estate development projects, at the time of the granting, for commercial or residential purposes, the institution shallfinancing must not only be based on the developer's reputation. In particular, it must take into consideration all the other factors which that enable the assessment of the developer’s strength, the legal structuring and the financial strength and the profitability of the projects, the environment in which the projects are carried out, their development implementation phases in the life cycle of the projects and all the related guarantees and insurance. Any change in the creditworthiness of the project or adjustment to the developer’s repayment schedule requires an assessment of the deterioration in credit quality and the triggers for ‘default’ as defined in Article 178 of the CRR and entails the establishment of the necessary provisions. Moreover, the financing must be covered, in addition to the mortgage on the financed object, by a personal guarantee of the developer unless other guarantees or securities significantly cover the total cost of the financed object. The institutions shall set an internal limit for aggregate exposure they incur on the real estate development sector. Without prejudice to the rules applicable regarding large exposures (Part Four of the CRR), the completion bank guarantees may be excluded from this aggregate limit as far as the completion costs are adequately covered by pre-sale or pre-lease rates. This limit must be in healthy proportion to their regulatory capital. It should be borne in mind that speculative immovable property financing as defined in Article 4(1)(79) of the CRR are deemed exposures associated with particularly high risk. In this respect, they shall be assigned a risk weight of 150%, as defined in Article 128(2)(d) of the CRR, under the standardised approach for credit risk. Sub-chapter 3.4. Exposures associated with particularly high risk
18. The institutions applying a standardised approach for credit risk shall put in
place a process to identify exposures associated with particularly high risk. This process shall cover at least the exposures within the meaning of Article 128(2) and (3) of the CRR.
19. The institutions shall apply Guidelines EBA/GL/2019/01 which specify the
terms “investment in venture capital firms” and “investment in private equity” as defined in Article 128(2)(a) and (c) of the CRR. These Guidelines also specify which types of exposures, other than those mentioned in Article 128(2) of the CRR, must be associated with particularly high risk and under which circumstances.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 70/85 The types of exposures identified by the institutions as carrying a particularly high risk of loss, without however meeting the specific characteristics described in EBA/GL/2019/01, must be notified to the competent authority by using the corresponding form available on the CSSF website. Sub-chapter 3.5. Non-performing and forborne exposures
20. The institutions shall have sound arrangements for the identification and
management of commitments whose contractual maturity dates set for the payment of principal and/or interests have expired. To this end, the institutions shall have policies in place which define the measures to be taken where a debtor does not comply with or indicates to the bank that s/he is no longer able to comply with the contractual provisions of his/her commitment, in particular the various payment deadlines. In addition, the institutions shall have sound arrangements for the identification, management and provisioning of commitments “in default” within the meaning of Article 178 of the CRR, Article 14 of CSSF Regulation No 18-03 and EBA/GL/2016/07.
21. The institutions must maintain a list of commitments on a debtor or group of
related debtors, whether they are forborne within the meaning of Article 47b of the CRR, non-performing within the meaning of Article 47a(3) of the CRR or “in default”. These commitments shall be subject to periodic and objective review which must enable the institution to acknowledge and carry out the impairment and provisions of assets as required.
22. The institutions must have appropriate practices regarding governance and
risk management of their non-performing exposures16, their forborne exposures17 and foreclosed assets in order to efficiently and sustainably reduce non-performing exposures in their balance sheets in accordance with the requirements of Circular CSSF 20/751. 16 Exposures classified as non-performing in accordance with Annex V of Commission Implementing Regulation (EU) No 680/2014. 17 Exposures for which forbearance measures were applied in accordance with Annex V of Commission Implementing Regulation (EU) No 680/2014.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 71/85
Chapter 4. Risk transfer pricing
23. The institutions shall implement a pricing mechanism for all risks incurred. This
mechanism, which is part of the internal governance arrangements, serves as an incentive to effectively allocate the financial resources in accordance with the risk appetite and the principle of sound and prudent business management.
24. The pricing mechanism shall be approved by the authorised management and
monitored by the risk management control function. The transfer prices must be transparent and communicated to the relevant staff members. The comparability and consistency of the internal transfer pricing systems used within the group must be ensured.
25. The institution shall establish a complete and effective internal transfer pricing
system for liquidity. This system shall include all liquidity costs, benefits and risks.
Chapter 5. Private wealth management (“private banking”)
26. Private banking activity is especially exposed to money laundering and
terrorist financing risks. Consequently, the institutions shall pay particular attention to comply with the anti-money laundering and counter terrorist financing obligations, whether they are regulatory, deriving from internal policies and procedures or falling within the good practices and organisation recommendations recognised as authority in this field.
27. The institutions shall have sound processes to ensure that the business
relationships with their customers comply with the agreements concluded with these customers. This objective may be best achieved when the discretionary management, advice management and simple execution of activities are separated from an organisational point of view.
28. The institutions shall have sound arrangements to ensure compliance with the
customers' risk profiles, for the purposes, in particular, of fulfilling the requirements arising from the MiFID regulations.
29. The institutions shall have sound arrangements in place to ensure the
communication of accurate information to the customers on the state of their assets. The issue and distribution of account statements and any other information on the state of assets must be separated from the business function.
30. The physical inflows and outflows of cash, securities or other valuables must
be carried out or overseen by a function separated from the business function.
31. Any entry and amendment of customers' identification data must be carried
out or overseen by a function that is independent from the business function.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 72/85
32. If a customer purchases a derivative traded on an organised market, the
institution shall forthwith pass on (at least) the margin calls to be provided by the institution to the customer.
33. The institutions must have sound arrangements in respect of credit control and
bank overdraft within the context of the private banking activities. The financial guarantees covering these credits must be sufficiently diversified and liquid. For the purposes of having an adequate security margin, prudent discounts must be applied according to the nature of the financial guarantees. The institutions must have an early warning system independent from the business function which organises the monitoring of the financial guarantees’ value and triggers the liquidation process of the financial guarantees. It must ensure that the liquidation process is triggered in good time, and in any case before the value of the guarantees becomes lower than the credit. Contracts with customers must clearly describe the procedure triggered in the event of inadequacy of the guarantees.
Chapter 6. Exposures to shadow banking entities
Sub-chapter 6.1. Implementation of sound internal control principles
34. The institutions shall put in place an internal framework for the identification,
management, monitoring and mitigation of the risks arising from the exposures to shadow banking entities18 in accordance with EBA/GL/2015/20.
35. The institutions shall apply a materiality threshold to identify the exposures to
shadow banking entities. In accordance with EBA/GL/2015/20, any individual exposure to a shadow banking entity that is equal to or in excess of 0.25%19 of the institution’s eligible capital20, after taking into account the effect of the credit risk mitigation and exemptions21, must be taken into consideration and cannot be deemed as low exposure. 18 Shadow banking entities are defined in paragraph 11 “Definitions” of EBA/GL/2015/20. These entities are undertakings that carry out one or more credit intermediation activities and that are not excluded undertakings within the meaning of said paragraph. “Credit intermediation activities” shall mean “bank-like activities involving maturity transformation, liquidity transformation, leverage, credit risk transfer or similar activities”. 19 According to the definition “Exposures to shadow banking entities” of paragraph 11 of EBA/GL/2015/20. 20 Within the meaning of point (71) of Article 4(1) of the CRR. 21 i) Credit risk mitigating effects in accordance with Articles 399 and 403 of the CRR; ii) Exemptions provided for in Articles 400 and 493(3) of the CRR.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 73/85
36. The institutions shall ensure that any possible risks for the institution as a
result of their various exposures to shadow banking entities are adequately taken into account within the institution’s Internal Capital Adequacy Assessment (ICAAP) and capital planning. Sub-chapter 6.2. Application of quantitative limits
37. The institutions shall limit their exposures to shadow banking entities in
accordance with one of the two approaches (principal approach or fallback approach) as defined in EBA/GL/2015/20.
38. In accordance with the principal approach, the institutions must set an
aggregate limit to their exposures to shadow banking entities relative to their eligible capital.
39. When setting an aggregate limit to exposures to shadow banking entities, each
institution must take into account:
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 74/85
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 75/85
46. The institutions shall include, in their business continuity plan, actions to
address the contingent encumbrance resulting from relevant stress events, which means plausible albeit unlikely shocks, including downgrades in the credit institution’s credit rating, devaluation of pledged assets and increases in margin requirements.
Chapter 8. Interest rate risk
Sub-chapter 8.1 Interest rate risk arising from non-trading book activities
47. When implementing Article 53-20 (Interest rate risk arising from non-trading
book activities) of the LFS and the relevant Article of RCSSF 15-02, the institutions shall comply with EBA/GL/2018/022022/14. Sub-chapter 8.2. Corrections to modified duration for debt instruments
48. The institutions applying the standardised approach for the calculation of their
capital requirements associated with the general interest rate risk in accordance with Article 92(3)(b)(i) of the CRR are required to apply modifications to the calculation of the duration to reflect prepayment risk for debt instruments. The institutions shall apply one of the two methods for the correction to modified duration provided for in EBA/GL/2016/09.
Chapter 9. Risks associated with the custody of financial assets
by third parties
49. The institutions shall have a policy for the selection of sub-custodians which
hold their customers’ financial assets. This policy shall establish minimum quality criteria which a sub-custodian must meet.
50. The institutions shall carry out due diligence controls before concluding an
agreement with a sub-custodian and they shall exercise an ongoing supervision of the sub-custodian for the whole duration of the relationship in order to ensure that these quality criteria are met.
51. The institutions shall perform regular reconciliations between the assets
recorded in their accounts as belonging to the customers and those confirmed by their sub-custodians.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 76/85
Part IV. Timeline
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 77/85
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 78/85
Annex I - Extracts from Section 9.3 of EBA/GL/2021/06, independent members
of an institution’s management body in its supervisory function
89. Without prejudice to paragraph 91, in the following situations it is
presumed that a member of a relevant institution’s management body in its supervisory function is regarded as not ‘being independent’:
a. the member has or has had a mandate as a member of the management body in its management function within an institution within the scope of prudential consolidation, unless he or she has not occupied such a position for the previous five years; b. the member is a controlling shareholder of the relevant institution, being determined by reference to the cases mentioned in Article 22(1) of Directive 2013/34/EU, or represents the interest of a shareholder controlling the institution, including where the owner is a Member State or other public body;
c. the member has a material financial or business relationship with
the relevant institution; d. the member is an employee of, or is otherwise associated with a controlling shareholder of the relevant institution; e. the member is employed by any entity within the scope of consolidation, except when both of the following conditions are met:
i. the member does not belong to the institution’s highest
hierarchical level, which is directly accountable to the management body;
ii. the member has been elected to the supervisory function in
the context of a system of employees’ representation and national law provides for adequate protection against abusive dismissal and other forms of unfair treatment; f. the member has previously been employed in a position at the highest hierarchical level in the relevant institution or another entity within its scope of prudential consolidation, being directly accountable only to the management body, and there has not been a period of at least three years, between ceasing such employment and serving on the management body; g. the member has been, within a period of three years, a principal of a material professional adviser, an external auditor or a material consultant to the relevant institution or another entity within the scope of prudential consolidation, or otherwise an employee materially associated with the service provided;
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 79/85 h. the member is or has been, within the last year, a material supplier or material customer of the relevant institution or another entity within the scope of prudential consolidation or had another material business relationship, or is a senior officer of or is otherwise associated directly or indirectly with a material supplier, customer or commercial entity that has a material business relationship;
i. the member receives in addition to remuneration for his or her
function and remuneration for employment in line with point (c) significant fees or other benefits from the relevant institution or another entity within its scope of prudential consolidation; j. the member served as member of the management body within the entity for 12 consecutive years or longer; k. the member is a close family member of a member of the management body in the management function of the relevant institution or another entity in the scope of prudential consolidation or a person in a situation referred to under points (a) to (h).
90. The mere fact of meeting one or more situations under paragraph 89 is
not automatically qualifying a member as not being independent. Where a member falls under one or more of the situations set out in paragraph 89, the relevant institution may demonstrate to the competent authority that the member should nevertheless be considered as ‘being independent’. To this end, the relevant institutions should be able to justify to the competent authority the reasoning why the members’ ability to exercise objective and balanced judgement and to take decisions independently are not affected by the situation.
91. For the purposes of paragraph 90, the relevant institutions should
consider that being a shareholder of a relevant institution, having private accounts or loans or using other services, other than in the cases explicitly listed within this section, should not lead to a situation where the member is considered to be non-independent if they stay within an appropriate de minimis threshold. Such relationships should be taken into account within the management of conflicts of interest in accordance with the relevant EBA Guidelines on Internal Governance.
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 80/85
Annex II - “Small and non-complex institutions” and “Large institutions”
according to points 145 and 146 of Article 4(1) of Regulation (EU) No 575/2013:
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 81/85
Circular CSSF 12/552 AS AMENDED BY CIRCULARS CSSF 13/563, CSSF 14/597, CSSF 16/642, CSSF 16/647, CSSF 17/655, CSSF 20/750, CSSF 20/759, CSSF 21/785, AND CSSF 22/807 AND 24/860 82/85 Commission de Surveillance du Secteur Financier 283, route d’Arlon L-2991 Luxembourg (+352) 26 25 1-1 direction@cssf.lu www.cssf.lu
Read the rest free
This document amends: Circular CSSF 20/750 on ICT and Security Risk Management Requirements
This document supersedes: Circular CSSF 22/807 Update of Circular CSSF 12/552 on Central Administration, Internal Governance and Risk Management
Source: Commission de Surveillance du Secteur Financier — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from CSSF
CSSF published 3 documents in the last 30 days. We email you each new one the day it's published.