2021-04-09
Added · Updated
Supervised entities must maintain a robust central administration in Luxembourg, ensuring at least one authorized manager and key functions remain on-site to guarantee decision-making and critical activity continuity. Entities are required to implement a telework policy approved by the Board of Directors that defines limits on staff numbers, working hours, and on-site presence, while conducting regular risk analyses and maintaining evidence of compliance for regulatory monitoring. ICT security measures include encrypting device storage, restricting private device use for critical activities, and recertifying access rights annually for non-privileged users and biannually for privileged users.
More like this from CSSF
We email you every new CSSF publication the day it's published.