Luxembourg AML Law: CRF Fraud Alerts for Banks and CASPs

On 4 August 2026, Luxembourg published the Law of 22 July 2026 in Mémorial A No 412. It is a short instrument, two substantive articles, and it adds a power the Luxembourg AML law had not carried before: it lets the Cellule de renseignement financier (CRF), the country’s financial intelligence unit, push fraud-risk account numbers and fraud typologies out to a defined set of obliged entities. The reporting relationship most compliance teams know runs the other way, from the professional to the CRF through the suspicious transaction report. This law adds the return leg.

The mechanism is voluntary and defined by statutory cross-reference. It is available to the professionals in Article 2(1), point 1: credit institutions, professionals of the financial sector, payment institutions, electronic-money institutions and the specified tied and payment agents, and to crypto-asset service providers within point 20 as defined by the 2004 law. To receive reports, an in-scope professional must submit a request. Reports may be used only for combating money laundering, associated predicate offences and terrorist financing, may not be disclosed to the customer concerned or third parties, and the CRF-supplied account-number information must be deleted within six months of receipt. The law reaches those results by inserting a new Article 74-4bis into the Law of 7 March 1980 on judicial organisation, which houses the CRF, and a matching new Article 5-1 into the Law of 12 November 2004 on the fight against money laundering and terrorist financing, which houses the professional obligations.

For a bank or a CASP the decision is real and near-term: subscribe to the CRF feed or not, and if yes, build the intake and controls the two new articles require.

Related reading: our guide to AML reporting in Luxembourg.

Key dates and reference points

  • 14 July 2026: the Chamber of Deputies adopted the bill (parliamentary dossier Doc. parl. 8722, legislature 2023-2028).
  • 17 July 2026: the Council of State dispensed with a second constitutional vote.
  • 22 July 2026: the date of the law, signed by the Grand Duke and the Minister of Justice.
  • 4 August 2026: publication in Mémorial A No 412. Because the law sets no different commencement date, it becomes binding on 8 August 2026, the fourth day following publication, under Article 4 of the legislation governing the Journal officiel.
  • Six months: the deletion window for any account numbers a subscribing professional receives, counted from the date of receipt (new Article 5-1).
  • At least every six months: the frequency of the feedback meetings the CRF must hold with subscribing professionals (new Article 74-4bis, paragraph 6).

Two articles, one shared channel

The Law of 22 July 2026 builds one channel out of two legal anchors, and the split matters because it tells you which authority does what.

Article 1 inserts Article 74-4bis into the Law of 7 March 1980 on judicial organisation. That is the statute containing the CRF’s legal basis and powers. Since 1 November 2018, the CRF has been instituted under the administrative supervision of the State Prosecutor General and is operationally independent and autonomous. The new Article 74-4bis says the CRF may report (“peut signaler”) typologies and information that present a significant fraud risk to professionals covered by Article 2, paragraph 1, points 1 and 20, of the 2004 AML law, where that information is relevant to strengthening those professionals’ prevention of money laundering, associated predicate offences and terrorist financing.

Article 2 inserts Article 5-1 into the 2004 AML law, immediately after the Article 5 cooperation-with-the-CRF provisions. Article 5-1 is the professional’s side of the same channel: the covered professionals may solicit receipt of the Article 74-4bis reports by sending the CRF a request through its secure IT system, and it sets the conditions of use that come with the data.

Read together, the two articles describe a subscription. The CRF holds a discretionary power to share; the professional holds a right to request; and once the request is made it covers all of the CRF’s reports until the professional explicitly withdraws it. Nothing in the law obliges the CRF to send anything, and nothing obliges a professional to subscribe. The change is the existence of a lawful gateway, not a new filing duty.

Who can receive the feed, and who cannot

The scope is defined by cross-reference to Article 2(1), points 1 and 20 of the 2004 law. Point 1 covers credit institutions, professionals of the financial sector, payment institutions, electronic-money institutions and the specified tied and payment agents. Point 20 covers crypto-asset service providers within Article 1(32)’s definition, which excludes a provider whose only crypto-asset service is advice. Article 2 also extends the title to Luxembourg branches of foreign professionals and to foreign-law professionals supplying services in Luxembourg without a branch.

Professionals falling only under other Article 2 points do not qualify for the channel on that basis. A management company, domiciliation provider or family office must therefore determine whether it also qualifies independently under point 1 or point 20; those labels alone do not determine access.

Point 20 places qualifying crypto-asset service providers within the statutory recipient scope. The explanatory memorandum states that the measure is also intended to prevent fraudsters from using Luxembourg CASPs to launder illicit proceeds through accounts reported by the CRF. CASPs weighing whether to subscribe should read it alongside their wider reporting obligations for crypto-asset service providers under MiCAR, because the intake and deletion controls this law demands represent new compliance build.

It is an opt-in, and opting in creates no new report

The verbs in the statute are permissive on both sides. The CRF “may” report; the professional “may solicit”. A professional that does not request the reports will not receive them and does not breach Article 5-1 merely by declining to request them. That is worth stating plainly, because the instinct on reading any new AML law is to ask which return has changed. Here, none has. The suspicious transaction reporting duty under Article 5 of the 2004 law is untouched: professionals must still inform the CRF, on their own initiative, whenever they know, suspect or have reasonable grounds to suspect money laundering, an associated predicate offence or terrorist financing, for every suspicious transaction including attempts, regardless of amount.

What subscribing does is give the analyst a new input, not a new output. If the CRF flags an account number that matches a counterparty in your book, that flag feeds your transaction monitoring and your customer due diligence. Filing an Article 5 suspicious transaction report follows only from the same judgement applied to any internal alert. The voluntary subscription and the mandatory STR duty are separate mechanisms that both involve the CRF.

The law specifies the channel and continuing effect of the request, but does not prescribe its form or implementation steps. One request, sent through the CRF’s secure IT system, stands for the whole stream of the CRF’s reports unless the professional explicitly withdraws it. A firm that later wants out has to say so; silence keeps the subscription live.

What the CRF shares, and the fraud it has in mind

The statute identifies the information shared under Article 74-4bis(4) as account numbers known to the CRF under its legal powers that present a significant fraud risk; the reports also state the fraud typologies in which those accounts were used. It does not prescribe a one-account-per-record structure, a typology-label schema or any other technical data model. The explanatory memorandum adds that the CRF intended reports to include context on typologies, risk indicators and trends.

The fraud the law targets is defined by reference to the Penal Code. Article 74-4bis, paragraph 2, covers fraud and attempted fraud within Book II, Title IX, Chapter II of the Penal Code, together with laundering of the proceeds of those offences, where the conduct is carried out on a large scale against undetermined victims or uses social-engineering techniques targeting specific victims. The explanatory memorandum gives phishing by email, SMS or other messaging as an example of large-scale fraud and describes targeted social-engineering fraud against enterprises, associations, independent professionals and public bodies. The CRF’s contribution is to name the accounts it already sees as part of that activity so the receiving institution can act sooner.

Paragraph 6 closes the loop and keeps the feed honest. The CRF must convene the subscribing professionals at least every six months to discuss whether the reports are landing usefully, and it must adapt future reports in light of what it hears. The data flow is meant to be curated against feedback, which is a familiar feature of the public-private information-sharing arrangements documented in FATF’s work on public-private partnerships for illicit finance.

One purpose, no disclosure, sole responsibility

Article 5-1 attaches three use conditions to the data, and each one is a control a compliance function has to be able to evidence. The professional may use the reports exclusively for the fight against money laundering, associated predicate offences and terrorist financing. The professional acts under its sole responsibility in using them. And the professional may not reveal the reports to the client concerned or to third parties.

The purpose limitation covers the fight against money laundering, associated predicate offences and terrorist financing. Because Article 74-4bis concerns fraud and attempted fraud, use in a fraud-prevention or investigation workflow may fall within the permitted predicate-offence purpose; the law does not require organisational confinement to an AML team. Unrelated commercial use remains outside the stated purpose. Firms should document the permitted purpose, restrict access accordingly and apply the six-month deletion rule to every copy of the CRF-supplied account-number information.

The non-disclosure condition rhymes with the tipping-off prohibition compliance teams already operate. Article 5, paragraph 5 of the 2004 law bars a professional from telling a client or a third party that information has been, will be or is being passed to the authorities. Article 5-1 extends the same reflex to data coming the other way: the fact that the CRF has flagged an account is not something to raise with the account holder. Article 5-1 states that professionals use the reports under their sole responsibility. It does not itself define the consequences of deciding not to act on a report.

The secure channel and the six-month deletion clock

Two operational requirements turn this from a policy into a build. First, exclusivity of channel: Article 74-4bis, paragraph 5, requires that the transmission of reports and all exchanges between the professional and the CRF pass solely through a secure IT channel. The explanatory memorandum identifies GoAML as the CRF’s secure channel. The statute does not prescribe the recipient’s internal intake architecture, system integration or access-control design. Those implementation choices must be determined by the subscribing professional in light of the statutory purpose, non-disclosure and deletion requirements.

Second, the deletion clock. Article 5-1 requires the professional to delete all information received under Article 74-4bis, paragraph 4, first subparagraph, that is, the account numbers, within six months of receiving them. This is a data-minimisation rule written into the AML law, and it needs a real process behind it: a receipt timestamp on every inbound list, a scheduled purge at six months, and an audit trail proving the purge ran.

Article 5-1 requires deletion, within six months of receipt, of all information received in CRF reports under Article 74-4bis(4), first subparagraph, namely the reported account numbers. Neither Article 5-1 nor the explanatory memorandum expressly resolves how that rule applies to replicated data, derived analysis, investigation files, STR records or records subject to separate retention duties. Firms should map those uses and obtain a documented legal position on deletion, redaction and retention before implementation.

How the new Luxembourg AML law fits the STR regime

Structurally, the new channel completes a shape the 2004 law already had on one side. Article 5 gives the CRF a fast, confidential intake from the private sector and a power to instruct a professional to hold a transaction. What it lacked was a statutory basis for the CRF to seed the private sector with its own fraud intelligence. Article 74-4bis supplies that basis, and Article 5-1 sets the terms on which a bank or CASP can take the seed.

The direction is consistent with where the standard-setters have been pointing. Feedback from financial intelligence units to obliged entities, and structured public-private information sharing, run through the reformed European framework and through the FATF agenda, including FATF’s 2026-28 fraud-focused roadmap. Luxembourg firms also mapping the EU single rulebook should hold this national channel alongside the EU AML Regulation and what it changes for Luxembourg. FATF’s 2026-2028 programme includes fraud and public-private information sharing, but that policy context does not alter the legal effect of the Luxembourg statute. Regulation (EU) 2024/1624 is in force but generally applies from 10 July 2027; the Luxembourg channel becomes binding on 8 August 2026.

None of that turns the Law of 22 July 2026 into more than it is. It is a targeted, permissive, tightly conditioned sharing power for the professionals falling within Article 2(1), points 1 and 20 of the 2004 law. Its weight comes from the controls it demands of anyone who chooses to use it.

Frequently Asked Questions

If we subscribe to the CRF feed, does that create a new reporting obligation?

No. The law creates a right to request the CRF’s fraud reports and conditions of use for them; it does not add a new return or filing. The suspicious transaction reporting duty under Article 5 of the 2004 law is unchanged, and a CRF flag feeds your existing monitoring, while any report still turns on your own judgement.

We received a CRF flag on an existing customer. Must we file a suspicious transaction report?

Not automatically. The flag is an input to your analysis. If it, alone or with other indicators, takes you to knowledge, suspicion or reasonable grounds to suspect money laundering, an associated predicate offence or terrorist financing, the Article 5 duty to inform the CRF applies as it always would. The judgement is yours; the flag does not make it for you.

Can we share the CRF-supplied data across our group or with a correspondent?

The law does not provide for onward sharing. Article 5-1 restricts use to the fight against money laundering and related offences, bars disclosure to the client or third parties, and places the data under the professional’s sole responsibility. Any intra-group handling would need to be assessed against those limits and the group information-sharing rules in the 2004 law, and treated conservatively.

Does the six-month deletion rule conflict with our AML record-keeping duties?

Article 5-1 requires the reported account-number information to be deleted within six months of receipt. The statute does not expressly resolve its interaction with replicated data, derived records or separate AML record-retention duties, so firms should obtain a documented legal interpretation before designing deletion and retention controls.

Are CASPs without a Luxembourg establishment in scope?

Potentially. Article 2 extends the AML title to Luxembourg branches of foreign professionals and to foreign-law professionals supplying services in Luxembourg without a branch. A cross-border CASP can request the feed only if it falls within point 20 and that territorial extension; absence of a Luxembourg establishment does not by itself exclude it.

Can we start receiving reports and later stop?

Yes. A request applies to all CRF reports unless it is explicitly withdrawn. The statute does not prescribe the form, timing or operational process for withdrawal, so a subscribing professional should confirm and document that process with the CRF.

Why did the change touch the 1980 judicial-organisation law as well as the AML law?

Because the CRF lives in the judicial organisation. The power for the unit to share, Article 74-4bis, has to be granted in the Law of 7 March 1980, while the professional’s right to request and the use conditions, Article 5-1, belong in the 2004 AML law. The single mechanism needs both anchors.

Key Takeaways

  • The Law of 22 July 2026 (Mémorial A No 412, published 4 August 2026, binding 8 August 2026) creates an opt-in channel for the CRF to share fraud-risk account numbers and fraud typologies with obliged entities.
  • The feed is available to the professionals in Article 2(1), point 1: credit institutions, professionals of the financial sector, payment institutions, electronic-money institutions and the specified tied and payment agents, and to point 20 crypto-asset service providers within the statutory definition, subject to Article 2’s territorial scope.
  • Subscribing is a request through the CRF’s secure IT system; it covers all CRF reports until explicitly withdrawn, and it creates no new filing obligation.
  • The suspicious transaction reporting duty under Article 5 of the 2004 law is unchanged; a CRF flag informs your analysis, and any report still turns on the Article 5 test.
  • Received reports may be used only for AML/CFT purposes, must not be disclosed to the client or third parties, and are used under the professional’s sole responsibility.
  • Article 5-1 requires the reported account-number information to be deleted within six months of receipt; the statute does not expressly resolve how that duty applies to replicated data, derived records or records subject to separate retention requirements.
  • The CRF must hold feedback meetings with subscribing professionals at least every six months and adapt future reports accordingly.
  • Decision now: whether to subscribe, and if so, build the secure intake, the AML/CFT-only use control, the non-disclosure discipline and the six-month purge.

Sources and References

  • Law of 22 July 2026 amending the Law of 7 March 1980 on judicial organisation and the Law of 12 November 2004 on the fight against money laundering and terrorist financing, Mémorial A No 412 of 4 August 2026 (Legilux): data.legilux.public.lu.
  • Parliamentary dossier 8722 (Bill of 20 March 2026, Expose des motifs, Commentaire des articles), Chambre des Deputes du Grand-Duche de Luxembourg: wdocs-pub.chd.lu.
  • Law of 23 December 2016 on the Journal officiel of the Grand Duchy of Luxembourg (Article 4, entry-into-force rule), Legilux: data.legilux.public.lu.
  • Consolidated Law of 12 November 2004 on the fight against money laundering and terrorist financing, as amended (CSSF information version, French): cssf.lu.
  • Consolidated Law of 12 November 2004 on AML/CFT, as amended (CSSF English translation): cssf.lu.
  • CSSF, Anti-money laundering and countering the financing of terrorism (overview and supervisory materials): cssf.lu.
  • CRF, Cellule de renseignement financier (institutional overview): crf.public.lu.

The decision on your desk

The Law of 22 July 2026 creates an opt-in channel for professionals within Article 2(1), points 1 and 20, subject to the statutory definitions and territorial scope. From 8 August 2026, an in-scope professional may request the reports through the CRF’s secure IT system. If the CRF exercises its discretion to send reports, the recipient must apply the permitted-purpose, non-disclosure, secure-channel and six-month deletion requirements.

Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.

Similar Posts

  • Council Regulation (EU) 2026/1164: Iran Sanctions Update

    Updated July 2026In this guideWhat Council Regulation (EU) 2026/1164 changesThe obligations that bite: freeze, no funds, reportWhere the travel ban stops and your obligations beginHow this reaches Luxembourg entitiesWhat teams commonly get wrongFrequently Asked QuestionsRelated ArticlesKey TakeawaysSources and ReferencesReading the next designation before it landsA sanctions amendment is not a memo you read next quarter….

  • FINTRAC Correspondent Banking Requirements: A Canadian Compliance Guide

    Canada’s anti-money laundering regime draws one line for correspondent banking that leaves no room for a risk-based judgment call. Under subsection 9.4(2) of the Proceeds of Crime (Money Laundering) and Terrorist Financing Act, no person or entity may have a correspondent banking relationship with a shell bank. FINTRAC’s correspondent banking guidance explains the pre-entry, record-keeping…

  • CSSF UCITS Merger Application Forms: A Filing Guide for Luxembourg Fund Teams

    Updated July 2026In this guideWhat the CSSF UCITS merger forms actually coverThe procedure the form sits insideInformation to unit-holders and the redemption windowWhere filing teams lose daysFrequently Asked QuestionsRelated ArticlesKey TakeawaysSources and ReferencesFiling the merger, not just the formA UCITS merger submitted to the CSSF without the required Article 67 information is not a complete…

  • EMIR Reporting Requirements – What You File, When, and How to Get It Right

    Updated July 2026In this guideEMIR Transaction Reporting: Who Reports, Which Trades, and What You FileEMIR Reporting to Trade Repositories: Submission, Reconciliation, and Error HandlingEMIR Regulatory and Supervisory Reporting: How NCAs and ESMA Use the DataFrequently Asked QuestionsRelated ArticlesKey TakeawaysSources and ReferencesGetting EMIR Reporting Right Across All Three DisciplinesA single lapsed LEI can cascade into hundreds…

  • CSSF de-risking communique: managing ML/FT risk instead of avoiding it, what Luxembourg-regulated firms must address in their AML/CFT frameworks

    Updated July 2026In this guideWhat the CSSF de-risking communique actually saysThe Luxembourg legal basis the communique sits onWhy blanket exits weaken your own frameworkWhat the EBA guidance expects insteadHow simplified and enhanced due diligence fit the pictureWhat AMLR and AMLA change from July 2027The FATF backdrop and why “proportionate” is now the testBuilding a de-risking…

  • CSSF Material Operations Notification: Approval Triggers Under CRD VI

    On 3 August 2026 the CSSF published a dedicated material-operations webpage explaining the prior-notification and assessment framework for Luxembourg credit institutions and in-scope financial holding companies and mixed financial holding companies. The page follows the Law of 5 May 2026, which amended the Law of 5 April 1993 on the financial sector to transpose CRD…