2021-04-09

Added · Updated

Governance and security requirements for supervised entities to perform tasks or activities through telework

Supervised entities must maintain a robust central administration in Luxembourg, ensuring at least one authorized manager and key functions remain on-site to guarantee decision-making and critical activity continuity. Entities are required to implement a telework policy approved by the Board of Directors that defines limits on staff numbers, working hours, and on-site presence, while conducting regular risk analyses and maintaining evidence of compliance for regulatory monitoring. ICT security measures include encrypting device storage, restricting private device use for critical activities, and recertifying access rights annually for non-privileged users and biannually for privileged users.

Commission de Surveillance du Secteur Financier logo

Luxembourg

Commission de Surveillance du Secteur Financier

Click to view full text

More like this from CSSF

We email you every new CSSF publication the day it's published.

Share