2025-12-16
Added · Updated
Circular CSSF 25/900 amends Circular CSSF 22/811 by repealing Annex B with immediate effect, which previously contained modalities for annual reporting by UCI administrators. The specific reporting instructions are now defined on the CSSF website rather than within the circular. The amendments apply to all entities carrying out the activity of UCI administration or part thereof, as defined in Circular CSSF 22/811.
CSSF published 3 documents in the last 30 days — get each new one by email the day it lands.
Circular CSSF 25/900
Amending Circular CSSF 22/811
Authorisation and organisation of entities acting as UCI administrators
CIRCULAR CSSF 25/900
Amending Circular CSSF 22/811 2/2
Circular CSSF 25/900
Amending Circular CSSF 22/811
Authorisation and organisation of entities acting as UCI administrators To all entities, as defined in Circular CSSF 22/811, carrying out the activity of UCI administration, or part thereof. Luxembourg, 16 December 2025 Ladies and Gentlemen, This circular amends Circular CSSF 22/811 on the authorisation and organisation of entities acting as UCI administrators. Annex B of Circular CSSF 22/811 is repealed with immediate effect. The modalities and instructions in relation to the annual reporting to be provided by UCI administrators are further defined on the CSSF website. The amendments to Circular CSSF 22/811 are shown in “track changes” hereinafter. Claude WAMPACH Director Marco ZWICK Director Jean-Pierre FABER Director Françoise KAUTHEN Director Claude MARX Director General
Annex Circular CSSF 22/811 as amended by Circular CSSF 25/900
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 1/42 Circular CSSF 22/811 (as amended by Circular CSSF 25/900) Authorisation and organisation of entities acting as UCI administrators
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 2/42 Circular CSSF 22/811 (as amended by Circular 25/900) Re: Authorisation and organisation of entities acting as UCI administrators
TABLE OF CONTENTS
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 3/42 Circular CSSF 22/811 (as amended by Circular CSSF 25/900) Re: Authorisation and organisation of entities acting as UCI administrators Ladies and Gentlemen,
Chapter D of Circular IML 91/75 specifies the rules concerning the central
administration of Luxembourg UCIs. This circular replaces Chapter D of Circular IML 91/75 taking into account the legislative developments, changes in technology and market evolution with respect to the activity of UCI administration. This new circular clarifies the activity of UCI administrators by specifying the principles of sound governance and the CSSF requirements on internal organisation and good practice applicable to them. To that effect, the circular will apply to the entities acting as UCI administrator for regulated and non-regulated UCIs established, or not, in Luxembourg. It is reminded that all entities carrying out the activity of UCI administration are subject to the laws and regulations in force, notably due to their status, authorisation or activities, including, but not limited to, legislation in the area of the fight against money laundering and terrorist financing and on delegation. UCIs must refer to applicable laws and regulations to determine the eligibility of UCI administrators. Luxembourg, 16 May 2022 To all entities, as defined hereafter, carrying out the activity of UCI administration or part thereof T o a l l e n t i t i e s , a s d e f i n e d h e r e a f t e r , c a r r y i
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 4/42
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 5/42 Circular CSSF 20/750: shall mean Circular CSSF 20/750, as amended by Circulars CSSF 22/828 and 25/881, on the requirements regarding information and communication technology (ICT) and security risk management, as amended or replaced, where applicable. Circular CSSF 22/806: shall mean Circular CSSF 22/806, as amended by Circular CSSF 25/883, on outsourcing arrangements, as amended or replaced, where applicable. Circular CSSF 24/856: shall mean Circular CSSF 24/856 on the protection of investors in case of an NAV calculation error, an instance of non-compliance with the investment rules and other errors at UCI level, as amended or replaced, where applicable. Circular CSSF 25/882: shall mean Circular CSSF 25/882 on requirements on the use of ICT third-party services for Financial Entities subject to the Digital Operational Resilience Act (DORA), as amended or replaced, where applicable. Delegate: shall mean any third party carrying out on behalf of a UCI administrator one or more functions or tasks. Delegation: shall mean the appointment by an entity of a third party or of third parties to carry out functions or tasks, fully or partially, on its behalf. For the purpose of this circular, the terms “externalisation” or “outsourcing” should be understood as “delegation”. DORA Regulation: shall mean Regulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sector and amending Regulations (EC) No 1060/2009, (EU) No 648/2012, (EU) No 600/2014, (EU) No 909/2014 and (EU) 2016/1011, and all its underlying regulatory technical standards and implementing technical standards. DRP: shall mean disaster recovery plan. External valuer: shall mean a natural or legal person that is independent from the AIF, the IFM and any other person having close links to the AIF or the IFM, and appointed by the IFM to perform the valuation function, in accordance with Article 17 of the 2013 Law. A third party that carries out the calculation of the net asset value for an AIF should not be considered as an external valuer as long as it does not provide valuations for individual assets, including those requiring a subjective judgement, but incorporates into the calculation process values which are obtained from the IFM, pricing sources or an external valuer. Foreign UCIs: shall mean undertakings for collective investment and collective investment undertakings, respectively, not established in Luxembourg. FTE: shall mean full-time equivalent. ICT: shall mean information and communication technology.
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 6/42 IFM: shall mean an investment fund manager. For the purpose of this circular, IFM shall mean the designated external IFM or, where applicable, the internally managed UCI. Investments: shall mean the assets in portfolio, along with the derivatives (including those used for efficient portfolio management and hedging techniques) in which a UCI is invested at a given time and/or owned by a UCI at a given time. KPI: shall mean key performance indicators. KRI: shall mean key risk indicators. Management Body: shall mean a) as regards sociétés anonymes (public limited companies), the board of directors (conseil d’administration) or the management board (directoire) of the UCI administrator, as the case may be; b) as regards other types of companies, the body that represents the UCI administrator by virtue of the law and the instruments of incorporation. NAV: shall mean net asset value. Non-regulated UCIs established in Luxembourg: shall mean undertakings for collective investment and collective investment undertakings, respectively, established in Luxembourg that do not qualify as regulated UCIs established in Luxembourg as defined by this circular. Proper instruction: shall mean any signed, dated and written instruction delivered by the UCI or a person duly authorized to give an instruction on behalf of the UCI upon a decision of the UCI or the IFM. Regulated UCIs established in Luxembourg: shall mean the following entities:
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 7/42 UCIs: shall mean regulated UCIs established in Luxembourg, non-regulated UCIs established in Luxembourg and foreign UCIs. UCITS: shall mean an undertaking for collective investment in transferable securities falling under the scope of Directive 2009/65/EC of the European Parliament and of the Council of 13 July 2009 on the coordination of laws, regulations and administrative provisions relating to undertakings for collective investment in transferable securities.
2. Scope
2.1 Eligible entities
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 8/42 As the case may be, a UCI or its IFM may also delegate the UCI administration activity, or part thereof, to an external IFM in Luxembourg, which is not the designated IFM of a given UCI. The UCI administration activity may further also be performed by the following external service providers established under the 1993 Law:
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 9/42
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 10/42
8. The UCI administrator must, in addition, comply with applicable sectorial
legislation.
9. It is to be noted that all requirements of this circular apply at the level of the
UCI administrator (irrespective of whether the function is performed by the UCI, the IFM and/or by an external provider). Section 3.5. of this circular covering delegation requirements must be complied with by the entity(ies) acting as UCI administrator.
2.2.2 UCI administration activity
10. The UCI administration activity may be split into three main functions: the
registrar function, the NAV calculation and accounting function, and the client communication function.
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 11/42 o In cooperation with the UCI or its IFM, when applicable, drawingup of prospectuses, financial reports and other documents intended for the UCI’s investors and their dispatching, filing and publication when required; o Cooperation and participation in the preparation of general meetings of the UCI’s unit-/shareholders, notices of meetings and related publications, filing and dispatching as well as all the preparation and dispatching of all other documents intended for investors; o Regulatory reporting (in particular, to the CSSF, to the BCL, or to the UCI national competent authority where applicable); and o Maintenance of the core documentation relating to the UCI and its operations (including but not limited to, contracts and agreements, minutes of the Management Body’s meetings, minutes of the liquidator’s resolutions, correspondence with the statutory auditors and the CSSF or any other national competent authority of the UCI, UCI’s books and financial reporting, prospectuses, financial reports and other documents intended for investors).
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 12/42
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 13/42 UCI or its IFM, when applicable, without delay, of any instances of noncompliance with the investment policy and restrictions.
15. The UCI administrator must establish, implement and maintain procedures to
detect, assess and, when applicable, notify the UCI or its IFM, when applicable, without delay, of material or non-material NAV errors, breaches or operational incidents (with a financial impact or “near-by” incident). Such material or nonmaterial NAV errors, breaches or operational incidents must be logged by the UCI administrator and in case of relevant or significant shortcomings, the UCI administrator, in cooperation with the other parties, should design a remediation plan to be approved by the UCI or its IFM, when applicable and implement the related corrective measures as well as ensure that a proper follow-up is being done.
16. In accordance with the aforementioned requirements, the UCI administrator
must establish, implement and maintain an escalation process detailing for each type of error/breach/incident, the type of information to be exchanged, the parties to be involved (internally and externally) and the steps to be taken (log, corrective actions, etc.). In particular, the UCI administrator must, when applicable, ensure that an adequate notification is sent to the CSSF or any other national competent authority of the UCI either by the UCI itself, the IFM, when applicable, or by the UCI administrator itself (as required or agreed upon contractually). The processes and procedures under points 14 and 15 of this circular must also document in sufficient detail the appropriate steps in terms of communication towards investors and the national competent authority of the UCI and/or the IFM, in particular in case of NAV errors and breaches.
17. For regulated UCIs established in Luxembourg, such procedures and processes
must comply with Circular CSSF 02/7724/856, when applicable.
18. For regulated UCIs established in Luxembourg, the UCI administrator must
inform the CSSF without undue delay in case the UCI administrator becomes aware that the UCI or its IFM, when applicable, does not properly fulfil its legal, regulatory or contractual obligations and/or does not notify the CSSF as required by applicable laws and regulations of material or non-material NAV errors/breaches/incidents.
2.2.3 Registrar function
19. The entity in charge of the registrar function must ensure the maintenance of
the UCI’s unit-/shareholder register. The register must be available at all times to the UCI administrator which performs the registrations, alterations or
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 14/42 deletions necessary to ensure its regular update and maintenance. The maintenance of the UCI’s unit-/shareholder register must be performed in accordance with the applicable laws and regulations, along with the UCI rules as set out in the offering documents.
20. For each UCI, the registrar function must at least cover the following
operations:
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 15/42 the IFM when applicable, or the UCI administrator when placing their subscription and redemption orders. It is therefore necessary for UCIs to explicitly and prominently mention this possibility in their offering documents.
23. The dispatching of confidential documents sent to investors must remain
under the supervision of the UCI administrator. When the UCI administrator does not perform this task itself (in the event of delegation of this task), the UCI administrator must implement adequate procedures to control the dispatching, in particular the safeguard of data confidentiality relating to investors. The measures of protection should ensure that non-authorised third parties may not access confidential data relating to investors for whom the dispatches are intended. These measures are equally applicable to the dispatching of other, non-confidential documents to investors or potential investors by the UCI administrator.
24. When applicable, the UCI administrator must implement and apply adequate
procedures and processes to ensure compliance of the UCI with the wellinformed and professional investor statuses.
25. When acting as registrar for regulated UCIs established in Luxembourg, the
UCI administrator must, beside others, comply with Circular CSSF 04/146.
2.2.4 NAV calculation and accounting function
26. The entity in charge of the NAV calculation and accounting function (the “fund
accounting function”) must ensure that the UCI’s NAV is accurate. It must ensure the correct and complete recording of transactions to adequately keep the UCI’s books and records in compliance with applicable legal, regulatory and contractual requirements as well as the applicable accounting principles. The UCI’s books must be available at all times to the UCI administrator. The calculation and production of the NAV of UCIs must be performed in accordance with the applicable laws and regulations, along with the UCI rules as set out in the offering documents.
27. To calculate the UCI’s NAV and, when applicable, the NAV of its units/shares
at compartment and/or class level, the NAV calculation and fund accounting function must at least cover the following operations:
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 16/42
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 17/42 at least, the following controls in addition to the operations detailed in point 27 of this circular:
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 18/42 delivered to the CSSF in a timely manner. To that effect, the UCI administrator must establish, implement and maintain appropriate procedures to ensure the proper and accurate valuation of the assets and liabilities of the UCI. In case of delegation, the UCI administrator is always in charge of the final step of the NAV production and must perform a final validation.
2.2.5 Client communication function
33. The client communication function is comprised of the handling of confidential
communication and correspondence of confidential documents intended for investors. The aforementioned communication and correspondence must be performed in accordance with the applicable laws and regulations, along with the UCI rules as set out in the offering documents.
34. The UCI administrator executing the client communication function may cover
the following operations:
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 19/42
36. The dispatching of confidential documents sent to investors must remain
under the supervision of the UCI administrator. When the UCI administrator does not perform this task itself (i.e. having delegated this task), the UCI administrator must implement adequate procedures and processes to control the correct dispatching, in particular the safeguard of the data confidentiality relating to investors. The UCI administrator must have specific ex-post controls in place to ensure that documents are duly transmitted to the final investors. The measures of protection should ensure that non-authorised third parties may not access confidential data relating to investors for whom the dispatches are intended.
3. Organisational arrangements
3.1 General provisions
37. The UCI administrator must have an adequate internal organisation (including
an adequate and appropriate environment of control) and sufficient resources (e.g. human resources, technical infrastructure and IT means). In particular, it must comply with the provisions set out in this chapter. Those provisions apply in the context of its activity as UCI administrator.
38. A written contract must be concluded between the UCI administrator and the
UCI and/or the IFM1
, when applicable. The contract must clearly set out the roles, the responsibilities, the rights and the obligations of each party. It must, at least, include the following elements:
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 20/42
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 21/42
40. The UCI administrator must grant a right of access for the UCI and when
applicable, the IFM, the statutory auditor of the UCI, the liquidator, the CSSF or any other national competent authority of a UCI, where applicable, to the documents and data relating to its administration upon simple request. Moreover, the UCI administrator must allow the UCI or its IFM, when applicable, to carry out on-site visits at a frequency and under the terms to be laid down in the contract, for the purposes of exercising its due diligence and ongoing monitoring activities. The UCI administrator must communicate proactively the information, documents and data necessary to perform its duties to the UCI or its IFM, when applicable. Furthermore, the UCI administrator must answer requests from the statutory auditor of the UCI, the CSSF or any other national competent authority of the UCI, where applicable, in a diligent and professional manner.
41. Since the UCI administrator is a main actor of a UCI, its name shall be
disclosed in the offering documents of any UCI for which the UCI administrator acts in this capacity. When several entities cover different functions, all entities shall be listed and their functions indicated.
42. The UCI administrator must act honestly, fairly, professionally, independently
and in the best interest of the UCI and its investors. To that effect, the UCI administrator must act independently and be functionally and hierarchically separated from the depositary as specified in point 60 of this circular.
43. The UCI administrator’s premises must be of sufficient size, adequate and
secure. Access must be restricted to its staff and approved persons such as clients or visitors. To that effect physical documents and records must be kept secure to warrant data confidentiality and protection. It is the responsibility of the UCI administrator to keep and safeguard physical records for the UCIs it services.
3.2 Internal organisation
3.2.1 General principles
44. The UCI administrator must have in place an adequate internal organisation ,
including an adequate and appropriate control framework.
45. The internal control functions must adequately cover the UCI administration
activity.
46. The UCI administrator must establish, implement and maintain written
procedures and processes covering and describing in an accurate manner all the related administration functions of UCIs. The procedures and processes
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 22/42 must be kept up-to-date taking into account the evolution of the business (e.g. activities, clients, etc.) and the regulatory updates.
47. The UCI administrator should maintain a manual of procedures and processes
easily accessible to the UCI administrator staff. The manual should cover the overall activity by documenting the overall framework and also include the necessary details to cover each UCI’s type and profile. Those procedures and processes should at least cover:
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 23/42
51. The UCI administrator must keep an up-to-date organisational chart, including
the hierarchical and functional lines and, where appropriate, the reliance on other entities. The person designated as responsible for the UCI administration activity must be clearly identified in the organisational chart. The chart must also draw a distinction between the different functions and disclose the allocation by number of staff.
52. The UCI administrator must establish, implement and maintain protective
measures against fraud.
53. The UCI administrator must have in place KPIs/KRIs that cover the UCI
administration activity. Those indicators must take into account the services rendered, the number of UCIs, the compartments and unit/share classes administered, along with the volume and complexity of the UCIs.
3.2.2 Approval of new business relationships and new services
54. When approving new business relationships or services, the UCI administrator
must:
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 24/42
57. The procedures relating to the conflicts of interest policy must be regularly
updated so as to adapt them to the evolution of the UCI administrator’s business.
58. The UCI administrator must keep and regularly update a record of the types
of activities and clients in which a conflict of interest entailing a material risk of damage to the interests of one or more UCIs or its investors has arisen or, in the case of an ongoing activity, may arise. This record must be specific to the organisation and activities of the UCI administrator. It is recommended that the record covers at least the following items:
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 25/42 On the same basis, the depositary must, on an ongoing basis, make available to the UCI administrator all the relevant information it needs to carry out its duties. For this purpose, the UCI administrator and the depositary must agree upon adequate information flows (means, type of information, format, frequency, etc.) in line with the UCIs profile and complexity. The means and procedures by which the UCI administrator, or the depositary, transmits all relevant information should be documented and formalised in an agreed-upon operating memorandum, or an internal operating memorandum when the same entity performs both functions.
63. Whereas the depositary is in charge of the safekeeping of all of the UCI assets,
the UCI administrator must beside others reconcile the investments and cash accounts of the UCI by using independent and reliable sources. In particular, the UCI administrator should use different sources that are considered valid to confirm the existence of each kind of reconciled assets. It is reminded that for regulated UCIs established in Luxembourg, point 36 of Circular CSSF 16/644 and point 75 of Circular CSSF 18/697 acknowledge that the depositary uses the records and accounts opened in the accounting books of the UCI with the UCI administrator and accounts statements issued by third parties to perform its own record-keeping of the other assets.
3.2.5 Access and retention of the core UCI documentation,
including in case of change of UCI administrator
64. The data necessary to keep adequate records of the UCI’s activity and
encompassing the core UCI documentation, shall be retained on a medium that allows for the storage of information in a way for it to be accessible for future reference by the UCI, the IFM when applicable, the statutory auditor of the UCI and the CSSF or any other national competent authority of the UCI, where applicable, and in such a form and manner that the following conditions are met:
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 26/42 be ensured for a period of time as further defined by the laws applicable to the UCI for which UCI administration activities are performed.
66. In case of liquidation of regulated UCIs established in Luxembourg, the UCI
administrator must ensure that the essential documents necessary for the NAV calculation, as mentioned above, are (i) stored for a period of 10 years after the end of the relevant accounting period, and (ii) made available upon request to the statutory auditor of the UCI and the CSSF. The UCI’s books and essential documents at the liquidation date must hence be kept in Luxembourg. In case of a non-judicial liquidation of a UCI, the UCI’s books and documents must be kept for at least 5 years in Luxembourg after the closure of the liquidation in the Luxembourg Business Registers. In case of liquidation of non-regulated UCIs established in Luxembourg and foreign UCIs, the UCI administrator must ensure that the UCIs’ books and essential documents are kept and made available in accordance with the relevant laws and regulations.
67. In case of change of the UCI administrator (e.g. migration), the current UCI
administrator, the future UCI administrator and the UCI or its IFM, when applicable, must agree upon a transfer process (proportionate to the size and complexity of the migration and including elements such as, for instance, a parallel run requirement, etc.) which should be adequately documented. The document describing the transfer process (the “process document”) must cover, at least, the following:
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 27/42
3.3 Human resources
68. The UCI administrator must at all times have sufficient substance and
resources (including but not limited to human resources, operational processes and procedures, and ICT resources) to perform its activity in accordance with this circular. The staff must be sufficient in number and skills, taking into account the volume of UCIs serviced and their complexity.
69. Staff at the UCI administrator must:
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 28/42
73. The person in charge of and responsible for the UCI administration, whose
name shall be provided to the CSSF forthwith, must:
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 29/42 To that effect, the CSSF considers that a UCI administrator must use a dedicated professional software to calculate NAVs and maintain the UCIs’ unit- /shareholder registers, suitable to the complexity and nature of the UCIs it administers and allowing for the timely and proper recording of accounting movements, in line with legal and regulatory requirements. End-user computing systems (e.g. MS Excel with macro features, MS Access) shall be avoided, except when the UCI administrator can justify that the volume and complexity of the UCI administered do not require the use of such a professional software. When end-user computing systems are used, the UCI administrator must implement specific controls to reduce and mitigate the risks associated with such systems.
78. A UCI administrator must establish, implement and maintain systems and
procedures that are adequate to safeguard the security (confidentiality, integrity and availability) of information, taking into account the nature of the information in question. The need-to-know/need-to-have principles must be ensured when granting access rights which must be regularly reviewed. In addition, the UCI administrator must ensure that the systems used are suitable for their chosen function and allow for, at least, the appropriate audit trail for accounting and registrar transactions and positions and privileged IT management activities.
79. Every UCI administrator must establish, implement and maintain an adequate
business and service continuity policy ensuring the recovery of its activities and services after a disaster (i.e. BCP and DRP) within an adequate timeframe with regard to the NAV calculation frequency and providing for regular testing of those plans. In this context, the UCI administrator shall define and implement data and system backup and restoration procedures to ensure that they can be recovered as required.
80. When using a system that is located outside of Luxembourg, the UCI
administrator shall have a secure backup of all accounting and registrar positions in a readable format at the end of each NAV calculation day. This backup shall be stored in the European Economic Area, either in the UCI administrator’s premises, or by a service provider different from the one to whom the system is outsourced, or by a group entity. In case of liquidation, the UCI administrator must take into account the requirements set out in point 66 of this circular. UCI administrators in the scope of the DORA Regulation that make use of services provided by ICT third-party service providers must follow the applicable requirements of the DORA Regulation and Circular CSSF 25/882. UCI administrators outside the scope of the DORA Regulation, having
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 30/42 implemented or planning to implement ICT outsourcing arrangements, must follow the requirements of Circular CSSF 22/806, as amended.
81. Since the ICT requirements may evolve or be clarified through the adoption of
new regulations, notably at European level, in particular through the upcoming European Regulation of the European Parliament and of the Council on digital operational resilience (DORA) or through the publication of guidelines, recommendations, or questions and answers of the European Securities and Markets Authority (ESMA), the organisational arrangements set out in this
chapter may be supplemented or amended and, where relevant, should be
read together with such regulations, guidelines, recommendations and questions and answers.
3.5 Delegation models1
82. In accordance with applicable sectorial legislation, the UCI administrator may
delegate to third parties (i.e. delegates) the performance of one or more of its UCI administration tasks, for the purpose of a more efficient conduct of its business. This section sets out the delegation requirements that apply to the entities acting as UCI administrator which are delegating one or more of their UCI administration tasks. In that case, the principles set forth in this chapter must be complied with at all times during the delegation by all its delegates. However, under no circumstances may the monitoring of the delegated tasks or the due diligence/oversight on the delegates be delegated.
83. The delegation of tasks must be clearly detailed in a dedicated written contract
following the requirements listed under point 38 and, when applicable, 88 of this circular. In any case, the division of tasks related to the duties of UCI administration must not result in a fragmentation which renders the exercise of the coordination and general supervisory function difficult, if not impossible, or which unnecessarily increases costs by unjustified duplication or complexity of the operating model.
84. The delegation model must not be detrimental to the UCI administration
services provided to the UCIs (notably in terms of quality and/or cost). It also must not generate additional or increased risks for the UCIs, in particular legal or operational risks. 1 ICT delegations are excluded from the scope of this section and subject to the applicable sectorial legislation.
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 31/42
85. The delegation of tasks does not relieve the UCI administrator of its
responsibilities. It must be able to provide at any time to the CSSF the list of all delegation arrangements (critical/important or not) in place, including the description of the delegated tasks performed and information on its delegates.
86. With respect to the delegation in the area of the NAV calculation and
accounting function, any final NAV, respectively its publication, must be controlled and validated by the UCI administrator. The final controls/checks and the validation must therefore be performed and duly documented by the UCI administrator in accordance with point 29 of this circular.
87. Adequate initial and ongoing due diligence must be performed by the UCI
administrator on its delegates. The UCI administrator must in this context:
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 32/42
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 33/42 To that effect, the UCI administrator must be provided with an immediate and unlimited editor access to the delegate’s related system(s) allowing it to directly intervene in the processing of information. Such access must also allow for the instantaneous and full production of any data necessary for normal operations of the UCI administrator. If this is not possible, the UCI administrator must be provided with a non-restrictive and immediate reader access to such system allowing it to adequately retrieve the data necessary to perform its duties and maintain suitable systems to upload and use such data. In addition, the UCI administrator must ensure that the delegation model complies with point 80 of this circular.
91. The essential documentation of the UCIs must be available at all times at the
UCI administrator. Therefore, the delegate must forward all necessary documents to the UCI administrator (electronically or physically if such documents are irreplaceable).
92. The UCI administrator shall assess, in view of possible legal risks and
obligations, whether or not the third parties concerned by the delegation, and in particular investors, should be informed or their consent be obtained. In this respect, the UCI administrator shall also comply with the regulations in force relating to, beside others, general data protection.
93. In case the delegation implies a transfer of relevant information to a third
party, the UCI administrator must ensure that the UCI or its IFM, when applicable, has accepted the delegation of the relevant delegated services, the type of information transmitted in the context of the delegation and the country of establishment of the entities that provide the delegated services. Any transfer of information related to investors should be disclosed prior to the transfer, by the UCI or its IFM, when applicable, to investors through appropriate means, namely the offering documents and the subscription form combined, if appropriate, with a reference to a website. Existing investors should be informed by the UCI or its IFM, when applicable, prior to the transfer of their information, about any update of the offering documents aiming at the aforesaid disclosure by means of a letter, email or any other means of communication provided for by the offering documents.
94. The UCI administrator’s BCP as mentioned in point 79 of this circular must
take into account any delegation model. Special attention should be paid to the continuity aspects and the revocable nature of delegation. The UCI administrator shall in this context take the necessary measures to be in a position to adequately transfer the delegated activities to a different service provider or back to itself, whenever the continuity or quality of the services provisions are likely to be affected negatively.
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 34/42
95. The results of the due diligences and the ongoing oversight must be formalised
in writing.
96. The CSSF considers that, if the UCI administrator operates its UCI
administration activities based on a delegation model, it must always be able to take over or transfer to alternative service providers the delegated UCI administration tasks when required (in the event of any issues that would negatively impact the services provided). Any delegation model, which is of such a scale that the UCI administrator can no longer be considered as a UCI administrator in substance and that it would become a letter-box entity, must be considered as contravening the conditions which the UCI administrator is required to meet in order to obtain and maintain its authorisation.
97. The concept of letter-box entity is particularly assessed in the light of the size
of the staff performing the UCI administration, which must be appropriate, given for example the complexity and number of NAVs administered by the UCI administrator. The size of the staff must also be proportionate to the size of the team providing support at the delegate.
98. When the UCI administrator relies on companies of the group to which it
belongs for due diligence assessment and/or oversight monitoring, it must perform an independent review of its group’s assessment and monitoring. Consequently, it must be in a position to challenge the group’s decision. As a general principle, the overall delegation model should remain at all times under the control of the UCI administrator.
99. The requirements, which apply when delegating, must apply mutatis mutandis
where the delegate sub-delegates UCI administration tasks (excluding ICT delegation), and in case of any subsequent level of sub-delegation (i.e. a chain of delegation). The conditions applicable to any sub-delegation are those referred to in this chapter on delegation. In this context, the CSSF considers that the risks associated with sub-delegation of UCI administration tasks outside the group to which the UCI administrator belongs, to an entity not supervised by the CSSF, do not allow the UCI administrator to comply with the requirements of this circular and such sub-delegations are therefore prohibited.
100. A UCI administrator that intends to delegate a critical or important
operational task shall notify in advance its plans to the CSSF using the instructions and, where available, the forms on the CSSF website. Such a notification is to be submitted at least three months before the planned delegation comes into effect. When resorting to a client communication agent or an administrative agent authorised under Part I, Chapter 2 of the 1993 Law, this notice period is reduced to one month. Any planned delegation
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 35/42 arrangement which has not been notified within the above notification period and/or without using the instructions and, where applicable, the forms available on the CSSF website will be considered as not notified.
101. The notification is without prejudice to the supervisory measures or the
application of binding measures and/or administrative sanctions which the CSSF might take as part of its ongoing supervision, where it appears that these delegation projects do not comply with the applicable legal and regulatory framework. In any event, the UCI administrator remains fully responsible to comply with all the relevant laws and regulations as regards the planned delegation projects.
102. The UCI administrator must assess the criticality or importance of tasks
considering, in particular, where a defect or failure in its performance would materially impair any of the following:
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 36/42
104. This circular enters into force with immediate effect.
The requirement of authorisation set in section 2.2.1 of this circular does not apply to entities already acting as UCI administrator at the date of entry in force of this circular. A grandfathering period, in order to comply with the remaining provisions of the present circular, is granted to such entities already acting as UCI administrator at the date of entry in force of this circular until 30/06/2023. In relation to the annual reporting required by point 7 of this circular and detailed in annex B of this circular, the UCI administrator must file at the latest five months after its financial year-end, starting from 30/06/2023. Claude WAMPACH Director Marco ZWICK Director Jean-Pierre FABER Director Françoise KAUTHEN Director Claude MARX Director General Annexes A - List of information to be provided to the CSSF to apply for authorisation to act as UCI administrator B - List of information on UCI administration functions to be provided to the CSSF on an annual basis
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 37/42 ANNEXES A - List of information to be provided to the CSSF to apply for authorisation to act as UCI administrator The application file must be submitted ex-ante in electronic format to the CSSF. To this end, the prospective UCI administrator must duly fill in and submit the corresponding form(s) available on the CSSF website. The prospective UCI administrator must provide at least the following information:
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 38/42 B - List of information on UCI administration functions to be provided to the CSSF on an annual basis1 Pursuant to the point 7 of this circular, the UCI administrator must communicate to the CSSF information regarding its business activities and resources. The information must be provided by function as defined in point 10 of this circular. To this end, the UCI administrator must keep up-to-date the information listed hereafter and provide it to the CSSF on an annual basis, by duly filling in and submitting the corresponding form(s) available on the CSSF website:
BUSINESS OF UCI ADMINISTRATION & SIGNIFICANT INFORMATION ON THE ACTIVITY Number of regulated UCIs established in Luxembourg administered Volume in terms of net assets (millions EUR) Number of compartments of regulated UCIs established in Luxembourg administered Number of non-regulated UCIs established in Luxembourg administered Number of compartments of non-regulated UCIs established in Luxembourg administered Number of foreign UCIs administered Number of compartments of foreign UCIs administered Number of daily NAVs administered 1 The information is to be provided at the latest five months after the the financial year-end of the UCI administrator.
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 39/42 Number of weekly NAVs administered Number of monthly NAVs administered Number of quarterly NAVs administered Number of yearly NAVs administered Number of investors’ complaints received Number of UCIs’ and IFMs’ complaints received Number of NAV errors Number of NAV errors for which the UCI administrator is contractually responsible For regulated UCIs established in Luxembourg, number of material1 NAV errors For regulated UCIs established in Luxembourg, number of material2 NAV errors for which the UCI administrator is contractually responsible Number of corrected NAV 1 As defined by Circular CSSF 02/77 2 As defined by Circular CSSF 02/77
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 40/42 Number of corrected NAV for which the UCI administrator is contractually responsible When applicable1 , number of active investment breaches Date of the last review/update of the procedures (dd/mm/yyyy) List of procedures with an indication of the thematic covered Delegated task(s), when applicable Delegates HUMAN RESOURCES Name of the person responsible for the UCI administration (including nomination date) Contact information (email/telephone(s)) Number of staff in the UCI administration Number of staff expressed in FTEs in the UCI administration Any change (Yes/No) If any change, current organisational chart 1 Applicable to UCI administrators which are in charge of compliance monitoring of the investment policy and restrictions as detailed in point 13 of this circular.
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 41/42 TECHNICAL RESOURCES Hardware and software used Any change (Yes/No) Number and description of ICT related issues (system break downs leading to major delays in NAV calculation, major bugs detected, problems with new patches/system implementations, interface issues, or other major incidents including cyber incidents), including system outage duration, root cause and mitigating or corrective measures.
CIRCULAR CSSF 22/811 (AS AMENDED BY CIRCULAR CSSF 25/900) 42/42 Commission de Surveillance du Secteur Financier 283, route d’Arlon L-2991 Luxembourg (+352) 26 25 1-1 direction@cssf.lu www.cssf.lu
Read the rest free
This document amends: Authorisation and organisation of entities acting as UCI administrators
Source: Commission de Surveillance du Secteur Financier — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from CSSF
CSSF published 3 documents in the last 30 days. We email you each new one the day it's published.