2025-10-31
Added · Updated
Circular CSSF 25/897 amends Circular CSSF 22/821 by adding UCI administration and European Market Infrastructure Regulation (EMIR) modules to the self-assessment questionnaire (SAQ) for Luxembourg credit institutions and Luxembourg branches of non-EU credit institutions. The circular removes the Credit risk – IFRS 9 and DORA preparedness modules from the SAQ, with the latter integrated into the IT risk module. Existing modules are updated to align with supervisory objectives or request information more proportionately, and the detailed list of modules is removed from the circular text to be published on the CSSF website.
Circular CSSF 25/897 Update of Circular CSSF 22/821 on the Long Form Report (as amended by Circulars CSSF 23/845 and CSSF 24/865)
CIRCULAR CSSF 25/897 2/2 Circular CSSF 25/897 Update of Circular CSSF 22/821 on the Long Form Report (as amended by Circulars CSSF 23/845 and CSSF 24/865) To all Luxembourg credit institutions and Luxembourg branches of non-EU credit institutions Luxembourg, 31 October 2025 Ladies and Gentlemen, The purpose of this circular is to amend Circular CSSF 22/821 on the long form report (LFR) with the aim to further align the content of the self-assessment questionnaire with supervisory points of focus. As a result, the following modules have been included in the revised SAQ: a. UCI administration b. European Market Infrastructure Regulation (EMIR) In addition, the “Credit risk – IFRS 9” and “DORA preparedness” modules have been removed from the SAQ. The latter has been integrated as part of the “IT risk” modules. Some existing modules have been updated either to better align with supervisory objectives or to request information in a more proportionate manner, according to the nature of banks’ activities. The list of modules in the self-assessment questionnaire and their descriptions have been removed from the circular and are now available on the CSSF website (www.cssf.lu/en/prudential-reportingcredit-institutions). Please refer to Annex I for the details of the amendments to Circular CSSF 22/821 (as amended by Circular CSSF 23/285, 24/865 and 25/897). Yours faithfully, Claude WAMPACH Director Marco ZWICK Director Jean-Pierre FABER Director Françoise KAUTHEN Director Claude MARX Director General Annex: Circular CSSF 22/821, as amended by Circulars CSSF 24/865, CSSF 23/845 and 25/897
Annex - Circular CSSF 22/821 as amended by Circulars CSSF 23/845, 24/865 and 25/897 Long Form Report Practical rules concerning the self-assessment questionnaire to be submitted by institutions. Mission and related reports of the approved statutory auditors (réviseurs d’entreprises agréés). To all Luxembourg credit institutions and Luxembourg branches of non-EU credit institutions Luxembourg, 25 October 2022 Ladies and Gentlemen, Circular 22/821 published on 25 October 2022 introduced a revised version of the long form report following on from the regulatory developments and the evolving supervisory practices since 2001. The revision of the long form report as contemplated under Circular CSSF 01/27 was the result of a thorough reconsideration of its objective, scope and content in order to realign it with supervisory and prudential points of focus as well as to suppress redundancies between existing reporting requirements. The circular introduced a self-assessment questionnaire to be filled in on an annual basis by the institutions. It also introduced Agreed Upon Procedure report(s) and an annual separate report on the protection of financial instruments and funds belonging to clients as required under Article 7 of the Grand-ducal Regulation of 30 May 2018 to be established by the réviseurs d’entreprises agréés (REA) of the institutions. The self-assessment questionnaire and the Agreed Upon Procedure report(s) did not include matters relating to anti-money laundering and countering the financing of terrorism (AML/CFT) that have to be covered by the REA in its annual, separate report further to CSSF Regulation No 12-02. Following the revision of Circular 22/821 as amended by Circular CSSF 23/845, no more Agreed Upon Procedure reports are foreseen. As a result, the REA would only have to provide the annual separate report on the protection of financial instruments and funds belonging to clients as required under Article 7 of the Grand-ducal Regulation of 30 May 2018 as well as the annual separate AML/CFT report further to CSSF Regulation No 12-02.
CIRCULAR CSSF 22/821 (AS AMENDED BY CIRCULARS CSSF 23/845, CSSF 24/865 AND CSSF 25/897) 2/12 TABLE OF CONTENTS
CIRCULAR CSSF 22/821 (AS AMENDED BY CIRCULARS CSSF 23/845, CSSF 24/865 AND CSSF 25/897) 3/12
CIRCULAR CSSF 22/821 (AS AMENDED BY CIRCULARS CSSF 23/845, CSSF 24/865 AND CSSF 25/897) 4/12 protection of financial instruments and funds belonging to clients and AML/CFT are under the exclusive competence of the CSSF. All parts of the framework have been designed in a proportionate way and target in-scope institutions with a view to allowing the competent authorities to gather sufficient information to implement their risk-based approaches to supervision and to obtain information and assurances as regards in-scope institutions’ compliance with key regulatory provisions the control of which falls within the competent authorities’ legal mandate. 1.2. The self-assessment questionnaire The self-assessment questionnaire to be completed by institutions consists of the following sections: Section Description Level of application Exemptions Internal governance Overview of the operational and decision-making structure of the institutions, including the composition of its committees and internal control functions. Institutions, on an individual basis, excluding their branches, if any. / IT risk Overview of IT systems and processes, including an assessment of the level of risks and the controls in place. Institutions, on an individual basis, including their branches, if any. / Credit risk – IFRS 9 Overview of the methodologies applied for calculating impairment losses under IFRS 9 as well as a description of how the concept of “forborne” is implemented at the level of the institutions. This section shall also provide an overview of scenarios and forecasts used by the institution to account for its exposure to credit risk. Institutions, on an individual basis, including their branches, if any. Institutions for which the annual accounts are prepared in accordance with IFRS 9 accounting standard. Credit and counterparty risk Overview of the organisation, internal governance, methodology, reporting and monitoring of the credit and counterparty risk. Institutions, on an individual basis, including their branches, if any. / Interest rate risk in the banking book (IRRBB) and credit spread Overview of the IRRBB/CSRBB risk controls in place. Institutions, on an individual basis, including their branches, if any. /
CIRCULAR CSSF 22/821 (AS AMENDED BY CIRCULARS CSSF 23/845, CSSF 24/865 AND CSSF 25/897) 5/12 Section Description Level of application Exemptions risk arising from nontrading book activities (CSRBB) Liquidity risk Overview of liquidity risk documentation, liquid assets, intraday liquidity risk and parent company funding. Institutions, on an individual basis, including their branches, if any. / Large exposures Qualitative information on large exposures reported by the institutions. Institutions, on an individual basis, including their branches, if any. / Related parties Overview of intragroup exposures, including a description of the purpose of these exposures. In addition, this section shall also provide an overview of services provided to / received from related parties. Institutions, on an individual basis, including their branches, if any. / Foreign branches Overview of the foreign branches, including a description of how corporate, commercial and risk group policies are applied in the foreign branches, as well as an overview of the controls in place. Foreign branches located in another Member State or in a third country. Institutions that did not have any foreign branches located in another Member State or in a third country at the closure of the financial year. MiFID Overview of organisational and operational setup with regard to MiFID, as well as a description of investment services and financial instruments offered by the institutions to their clients. This section shall include information on distribution and communication means and on the client database. Institutions, on an individual basis, excluding their branches, if any. Institutions that did not provide any investment services or sell or advise in relation to structured deposits during the financial year. PSD 2 – payment services provided Overview of payment services and a description of the interface through which those payment services are offered to clients. Institutions, on an individual basis, including Institutions that did not provide any payment services
CIRCULAR CSSF 22/821 (AS AMENDED BY CIRCULARS CSSF 23/845, CSSF 24/865 AND CSSF 25/897) 6/12 Section Description Level of application Exemptions their branches, if any. during the financial year. PSD 2 – RTS on strong customer authentication and secure communication (SCA & CSC) Overview of applicability and compliance with the provisions of Commission Delegated Regulation (EU) 2018/389 (RTS on SCA & CSC). Institutions, on an individual basis, including their branches, if any. Institutions that did not provide any payment services during the financial year. Depositary bank Quantitative and qualitative overview of the UCI depositary function and the related services. In addition, this section contains a self-assessment against the main legal requirements. Institutions, on an individual basis, excluding their branches, if any. Institutions that do not provide depositary and related services. Climaterelated and environmental risks Information relating to materiality assessment and relevance of climate-related and environmental risks, action plan and alignment with supervisory expectations. Institutions, on an individual basis, excluding their branches, if any. / Consolidation aspects Information relating to the oversight of the subsidiaries (organisation, control function, IT systems) and quantitative information on each subsidiary. Covering all subsidiaries included in the scope of prudential consolidation according to the provisions of Chapter 2 of Title II of Part One of Regulation (EU) No 575/2013. Institutions that did not consolidate other entities from a prudential perspective at the closure of the relevant financial year. DORA preparedness Self-assessment of the level of readiness of the institution with regard to the different chapters of DORA Institutions, on an individual basis, including their branches, if any. Branches of non-EU credit institutions LCRDA Article 23(2) Declaration according to article 23(2) LCRDA Less Significant Institutions, on an individual basis, including their branches, if any. Branches of non-EU credit institutions
CIRCULAR CSSF 22/821 (AS AMENDED BY CIRCULARS CSSF 23/845, CSSF 24/865 AND CSSF 25/897) 7/12 The self-assessment questionnaire covers domains in scope of the prudential supervision for which the CSSF or the European Central Bank are competent. Please note however that the modulessections of the self-assessment questionnaire covering matters relating to the Market in Financial Instruments Directive (MiFID), the Payment Services Directive (PSD 2) and undertaking for collective investments (UCI) depositaries and, the European Market Infrastructure Regulation (EMIR) as well as the separate reports to be prepared by the REA covering protection of financial instruments and funds belonging to clients and AML/CFT are under the exclusive competence of the CSSF. All parts of the frameworkself-assessment questionnaire have been designed in a proportionate way and target in-scope institutions with a view to allowing the CSSF to gather sufficient information to implement their risk-based approaches to supervision and to obtain information and assurances as regards in-scope institutions’ compliance with key regulatory provisions the control of which falls within the competent authorities’ legal mandate. The information communicated as part of the self-assessment questionnaire shall be accurate and as concise as possible, while providing a true and fair view, and be based on the prudential reporting figures (FINREP/COREP/LAREX) under IFRS as at the closure of the financial year.4 The self-assessment questionnaire is available in digital form as described in section 4.1. Its content is will be adapted for subsequent financial yearson a yearly basis as required, including in response to developments of the legal and regulatory framework. The individual modules of the self-assessment questionnaire and their level of application as well as the applicable exemptions are directly recorded in the CSSF’s digital solution and are also reflected on the CSSF website (www.cssf.lu/en/prudential-reporting-credit-institutions). 2.3. The mission of the REA 2.1.3.1.The report on the protection of financial instruments and funds belonging to clients If applicable, institutions are required to mandate their REA to prepare, on an annual basis, a separate report on the protection of financial instruments and funds belonging to clients. This report shall cover the adequacy of the arrangements under Article 37-1(7) and (8) of the Law of 5 April 1993 on the financial sector, as amended, Article 13(4) of the Law of 5 August 2005 on financial collateral arrangements, as amended, and Section 2 of the Grand-ducal Regulation of 30 May 2018. The authorised management of the institution is responsible for providing the REA with the required information for the drafting of the descriptive parts of the report. The REA may include in its report descriptive elements directly provided by the institution’s authorised management, but s/he shall verify and ensure that these elements are correct and adequate. If needed, s/he may have to perform some amendments. The purpose of this separate report, which must be uploaded through a CSSF digital solution, is notably to ensure the reliability of the answers provided by an institution in the self-assessment 4 For institutions for which the date of the closure of the financial year is not aligned with the remittance date of the prudential reporting, the questionnaire should be based on the last prudential reporting submitted before the closure of the financial year.
CIRCULAR CSSF 22/821 (AS AMENDED BY CIRCULARS CSSF 23/845, CSSF 24/865 AND CSSF 25/897) 8/12 questionnaire in relation to the protection of financial instruments and funds belonging to clients. However, this does not preclude the REA to perform further assessments beyond those set forth in the self-assessment questionnaire. 2.2.3.2.The AML/CFT report Institutions are also required to mandate their REA to prepare, on an annual basis, a separate report covering AML/CFT further to RCSSF 12-02. The AML/CFT report describes the procedures set up by the institution concerning the prevention of money laundering and terrorist financing as required for compliance with or as defined in:
CIRCULAR CSSF 22/821 (AS AMENDED BY CIRCULARS CSSF 23/845, CSSF 24/865 AND CSSF 25/897) 9/12 • the control of the application of the provisions of Regulation (EU) 2015/847, as amended by the institution, in its respective role, and the percentage of transfers of funds for which data on the payer or payee were missing or incomplete and the measures taken in this context by the institution. The AML/CFT report shall also provide: • a description of roles and responsibilities with regard to AML/CFT within the institution, including the roles and responsibilities of and the interactions between the management and the different departments and services, indicating the corresponding number of staff involved on AML/CFT matters. The AML/CFT report shall also include a description of the committees and the corresponding hierarchical and functional structures by indicating the general and particular delegations of power with respect to AML/CFT. It shall also provide a description by the institution and an assessment by the REA of the three-lines-ofdefence model, as defined in Article 39(7) of the RCSSF 12-02; • the list of persons involved in AML/CFT matters, as referred to in the RCSSF 12-02 and Circular CSSF 12/552, as amended (compliance officer, person responsible for compliance, Chief Compliance Officer, etc.). It shall also state all the changes with regard to these persons which occurred during the financial year. Since these persons may delegate to members of staff certain operational tasks in relation to these functions, the AML/CFT report shall provide, where appropriate, a description of the delegation mechanism; • a description of the network of national agencies, national and foreign subsidiaries, the branches abroad, the foreign representative offices and the tied agents, as well as the main related ML/FT risks. The AML/CFT report shall also indicate if the institution uses the services of external managers as regards the clients' assets and shall, where appropriate, provide a description of the manner in which the relationships with external managers are managed and documented from an AML/CFT perspective; • a description of the institution’s commercial policy as well as the strategy regarding the management of the related ML/FT risks. It shall also include a description of how the institution monitors and ensures compliance with its internal objectives with regard to ML/FT risks management. The REA shall assess if the institution has sufficient financial resources and the appropriate infrastructure to control ML/FT risks to which it is exposed. The REA shall state how the sample of reviewed files was selected. When determining the sample, the CSSF expects the REA to apply a risk-based approach, taking into account the different business activities performed. The REA shall state the reference date of the sample data and provide relevant information on the methodology adopted for determining the sample (for example, the number of files reviewed compared to the total number of clients or the volume of deposits reviewed compared to the total volume of deposits). Where the REA identifies cases of non-compliance with the legal or regulatory provisions or deficiencies, the REA shall give detailed indications enabling the CSSF to assess the situation (number of pending incomplete files as a percentage of the total number of reviewed files, details of the deficiencies identified, etc.). Where applicable, the AML/CFT report must encompass the institution's branches, majority-owned subsidiaries abroad and the tied agents. It must cover, in particular, the branches', majority-owned subsidiaries' and the tied agents’ compliance with the applicable provisions as regards the prevention of money laundering and terrorist financing and it must include, in that respect: • an analysis of money laundering and terrorist financing risks incurred by the branches, majority-owned subsidiaries and the tied agents;
CIRCULAR CSSF 22/821 (AS AMENDED BY CIRCULARS CSSF 23/845, CSSF 24/865 AND CSSF 25/897) 10/12 • a description and assessment of the money laundering and terrorist financing risk management in the branches, majority-owned subsidiaries and the tied agents; • the verification of the implementation of and compliance with the institution's AML/CFT policy in the branches, majority-owned subsidiaries and the tied agents. The AML/CFT report must be sufficiently exhaustive and transparent, providing detailed descriptions and assessments, in order to allow a precise and informed judgement on the risks incurred by the institution with respect to money laundering and terrorist financing. With regard to the language used for the assessments, the AML/CFT report shall not include imprecise negative formulations (e.g. “We did not encounter serious weaknesses”) or global and approximative assessments (e.g. “We noted that most of the points comply with the laws and regulations”). The AML/CFT report shall rather provide a positive assessment for each area and subject by providing an overview of the methodology adopted (e.g. use of the sample technique, method for selecting the sample, etc.) and, where applicable, provide a description of the identified findings in order to allow the CSSF to better understand and judge the extent of the noticed irregularities and weaknesses. The REA shall also perform the follow-up of findings observed during the previous audits and described in detail in the previous AML/CFT report. The REA shall provide a description of any potential issues in relation to AML/CFT the institution may have with foreign competent authorities. The authorised management of the institution is responsible for providing the REA with the required information for the drafting of the descriptive parts of the AML/CFT report. The REA may include in its report descriptive elements directly provided by the institution’s authorised management, but s/he shall verify and ensure that these elements are correct and adequate. If needed, s/he may have to perform some amendments. In addition to the descriptive parts, the REA shall perform independently a detailed assessment of the ML/FT risks to which the institution is exposed as well as organisational aspects. This assessment shall be duly documented. It should be noted that the REA shall also inform the CSSF of all the suspicious transactions reported pursuant to Article 5 of the Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended, and which concern the institutions. Similarly, the REA must inform the CSSF in case they deem that the institution should have reported a suspicious transaction but has not, explaining their reasoning and having regard to the institution’s rationale. When discussing the cases with the institution, the REA need to be mindful of applicable professional obligations. 3.4. Submission procedures 3.1.4.1.Self-assessment questionnaire The self-assessment questionnaire will be accessible through a CSSF digital solution for each institution within three months before the closure of the institution’s financial year. The self-assessment questionnaire must be reviewed and electronically signed by the authorised management before submitting it to the CSSF.
CIRCULAR CSSF 22/821 (AS AMENDED BY CIRCULARS CSSF 23/845, CSSF 24/865 AND CSSF 25/897) 11/12 The self-assessment questionnaire must be transmitted on an annual basis to the CSSF in an electronic form via a CSSF digital solution within three months after the closure of the financial year, in accordance with the procedure described in section 4.3. 3.2.4.2.Reports prepared by the REA The separate report on the protection of financial instruments and funds belonging to clients and the AML/CFT report shall include the digital signature of the partner in charge of the mandate with the audit firm s/he represents. The REA submits the reports to the institution, which submits them subsequently to the CSSF. The reports prepared by the REA must be transmitted by the institution to the CSSF in electronic form via a CSSF digital solution within five months after the closure of the financial year, in accordance with the procedure described in section 4.3. 3.3.4.3.Practical rules Procedures and explanations on the practical modalities regarding the preparation and transmission of the self-assessment questionnaire, the separate report on the protection of financial instruments and funds belonging to clients and the AML/CFT report are made available to institutions and their REA, on the website of the CSSF under the following link: https://edesk.apps.cssf.lu/edeskdashboard/api/v1/documentation/LFRB_GU/en. A user guide “Authentication and user account management” is available to institutions via the eDesk portal of the CSSF.
CIRCULAR CSSF 22/821 (AS AMENDED BY CIRCULARS CSSF 23/845, CSSF 24/865 AND CSSF 25/897) 12/12 4.5. Final provisions Circular CSSF 22/821, as published on 25 October 2022, repealed Circular CSSF 01/27, as amended by Circulars CSSF 08/340, CSSF 10/484, CSSF 11/521 and CSSF 21/765, as well as Circular IML 96/125. It applied from 31 December 2022. The current revised version shall apply as from 31 December 2025.3. Claude WAMPACH Director Marco ZWICK Director Jean-Pierre FABER Director Françoise KAUTHEN Director Claude MARX Director General
More like this from CSSF
We email you every new CSSF publication the day it's published.