CSSF Table B 4.6 Reporting: The 22 Named Functions Due by 20 January
Every credit institution in the Luxembourg market files CSSF table B 4.6 at least annually: the table covers 22 specified functions and activities, the annual submission reflects the 31 December position and is due at the CSSF by 20 January of the following year, and changes to persons reported on B 4.6 during the year must be reported immediately through an additional submission. The CSSF instructions for the table, last updated on 11 December 2025, fix the content, and since 2 January 2024 the return has travelled through the eDesk “National Banking Reporting” procedure or as a JSON file over the CSSF’s S3 interface.
The eDesk data include the name, function, starting date and, where applicable, ending date for each position, and the 22 function lines carry legal or regulatory references. Several of those citations have moved since the form was last revised in January 2021: Circular CSSF 12/552 has been amended three more times, and Circular CSSF 25/881 took DORA entities out of the scope of Circular CSSF 20/750, which two ICT lines still cite. The eDesk questionnaire also has a roll-forward function that pre-fills last year’s answers, which saves typing and carries forward any mapping that has gone stale.
Related reading: CSSF B 2.5 B and B 2.5 E Reporting: Luxembourg Staff Costs and Taxes
The fixed B 4.6 calendar, from the CSSF instructions, the CSSF reporting handbook and the CSSF FAQ on national reporting B4.5 and B4.6:
- Reference date: 31 December of each year.
- Remittance deadline: 20 January of the following year.
- Years without any change: the annual submission is still mandatory.
- Changes during the year: reported immediately, as an additional submission.
- Channel: eDesk webform or JSON over S3 since 2 January 2024, with the SOFiE/E-file and MFT routes closed.
Legal Basis for CSSF Table B 4.6: Circular 14/593 and the Source Texts
B 4.6 is a national CSSF table that sits outside the common European reporting framework. Circular CSSF 14/593 on supervisory reporting requirements applicable to credit institutions, as amended most recently by Circular CSSF 22/823, keeps the CSSF’s own tables in force alongside the EBA templates. Its point 6 lists “Persons responsible for certain functions and activities: Table B 4.6” in the same group as table B 2.4 on participating interests and subordinated loans, covered in our CSSF table B 2.4 reporting guide, and the B 2.5 B and B 2.5 E tables. The CSSF issues the table, its instructions and the eDesk procedure.
The circular trail is untidy. Circular CSSF 13/576 of 3 December 2013 gave the table its current title and scope: the names of persons responsible for a function or activity within the authorised management, the names of the heads of the internal control functions, and the authorised manager responsible for the Single Customer View system used for deposit guarantee. Circular CSSF 14/593 refers instead to the table “as updated by Circular CSSF 18/695”, a circular of 20 July 2018.
The CSSF marks both 13/576 and 18/695 as outdated, and its page for 18/695 shows the circular archived on 20 May 2026. Version 8.3 of the CSSF handbook “Reporting requirements for credit institutions” still labels its B4.6 row “CSSF Circular 13/576”, and the CSSF FAQ lists 13/576 as the update of table B 4.6. The operative texts read as point 6 of Circular CSSF 14/593 for the obligation and the CSSF instructions for table B 4.6, in their December 2025 version, for the content.
The instructions state the purpose in one sentence: the table reports the names of the persons a credit institution has designated as in charge of a function or activity at the level of the authorised management, together with the names of the heads of the internal control functions, under the CSSF circulars and any other laws or regulations in force. The December 2025 instructions still list Circulars IML 93/101, IML 96/125, CSSF 01/29, CSSF 07/301, CSSF 07/307, CSSF 12/552, CSSF 13/555, CSSF 17/665 and CSSF 17/671, the Grand-ducal Regulation of 30 May 2018 and CSSF Regulation No 12-02. That list is not a current-law inventory: Circular IML 96/125 was repealed by Circular CSSF 22/821 with effect from 31 December 2022, and several other listed circulars have later amendments that the instructions do not reproduce. The printed references are legacy references that must be checked against the current governing texts before being relied on as substantive legal bases; the corresponding lines remain part of the current B 4.6 return.
The December 2025 instructions still use the term “authorised management” and cite Article 7(2) of the Law of 5 April 1993 for Luxembourg-law credit institutions and Article 32 for third-country branches. Following the Law of 5 May 2026, however, the CSSF has stated that references to “authorised management” in Circular CSSF 12/552 and other CSSF regulatory publications applicable to CRR institutions must now be read as referring to all members of the Management Body in its Management Function (MBMF). Current Article 7(2) continues to require at least two persons to be responsible for the management of a Luxembourg credit institution, while Article 32 subjects third-country branches to the applicable authorisation framework and extends the professional-standing and experience requirement to the persons responsible for managing the branch. The Law of 5 May 2026 also inserts a new Part I, Chapter 3, Sub-chapter 2, Section 3 (Articles 32-2 to 32-19) dedicated to third-country credit institution branches, including a two-person effective-management requirement at Article 32-10; a transitional Article 73 lets the CSSF keep existing branch authorisations granted under the current Article 32 valid provided the branch meets the new section’s requirements, with the new section’s other provisions (Articles 32-14 and 32-15 excepted, already in force since 11 January 2026) applying from 11 January 2027, so this citation needs rechecking once that section takes effect. B 4.6 creates no function of its own, so each line must be read together with its current underlying legal or regulatory basis.
Who Must Report B 4.6: Every Luxembourg Bank and Both Kinds of Branch
The instructions put the scope in one line: B 4.6 is drawn up only in accounting version “L”, meaning information on the entity established in Luxembourg, by all credit institutions of the Luxembourg market. The CSSF handbook repeats the B4.6 row in each of its four individual-basis tables: Luxembourg-law credit institutions with foreign branches, Luxembourg-law credit institutions without branches, Luxembourg branches of credit institutions whose head office is outside the EU, and Luxembourg branches of credit institutions whose head office is in the EU. The table has no consolidated version, and neither the instructions nor the handbook set a size or activity threshold for filing it.
Branch status changes which names can go on which line:
- For Luxembourg-law CRR institutions, any B 4.6 line that requires a member of the “authorised management” must now be read as requiring the relevant designated member of the Management Body in its Management Function (MBMF), following the CSSF’s May 2026 communique; Article 7(2) separately requires at least two persons to be responsible for the management of the institution.
- Branches of non-EU credit institutions name their authorised managers under Article 32 of the same law.
- Branches of EU credit institutions must pick each authorised-management name from the persons already notified to the CSSF as managers in the branch notification procedure. The form’s first footnote adds that EU branches need not have local heads of the internal control functions, so the Chief Compliance Officer, Chief Internal Auditor and Chief Risk Officer roles may be performed by the head-office function. The second footnote makes one line mandatory for every filer, EU branches included: the person in charge of controlling compliance with AML/CFT professional obligations.
Three lines carry their own size conditions. The Chief Financial Officer line applies only at institutions of significant importance, a term the B 4.6 instructions use without defining it. For the heads of the ICT function and of ICT and security risk control, the instructions accept a staff member or, at small institutions, a member of the authorised management.
Merging B 4.6 with the shareholding table in one eDesk procedure produced the one visible scope difference between the two. According to the CSSF FAQ, the B4.5 shareholding part does not apply to Luxembourg branches of EU credit institutions and is greyed out in their questionnaire, while the B4.6 part stays open to them.
What the Report Contains: 22 Function Lines, Each Tied to a Source Text
The form in use carries the version stamp January 2021; the CSSF document page records original publication on 24 July 2018 and an update on 28 January 2021. It opens with two header fields, the bank and the date, followed by 22 function lines, each printed with its legal reference. The CSSF FAQ reproduces the same 22 lines in English in its annex. Grouped by subject, they are:
Authorised-management business roles (lines 1 to 6)
- Market activity (Circular IML 93/101, point II, paragraph 5).
- Handling of customer complaints (Circular CSSF 17/671, page 3, point 2).
- Correct application of the policy defined by the consolidating undertaking (Circular IML 96/125, point III.1.6, third indent).
- Coordination of information flows with subsidiaries (Circular IML 96/125, point III.1.6, sixth indent).
- Domiciliation (Circular CSSF 01/29, page 2, point II).
- Conduct of business rules for the financial sector (Circular CSSF 07/307, point 15).
Organisation and internal control (lines 7 to 14)
- The authorised manager or managers in charge of the administrative, accounting and IT organisation.
- The authorised managers in charge of the internal audit, compliance and risk control functions, one line each.
- The heads of those three functions: Chief Internal Auditor, Chief Compliance Officer and Chief Risk Officer.
- The external expert, where the operational tasks of internal audit are outsourced.
ICT (lines 15 and 16)
- The head of the ICT function (“IT Officer”) and the ICT and security risk control function or functions, both referenced to points 2 and 11 of Circular CSSF 20/750, which the FAQ annex ties to paragraphs 3.2.1 and 3.3.1 of Guidelines EBA/GL/2019/04.
Deposit guarantee and client assets (lines 17 and 18)
- The authorised manager in charge of the Single Customer View mechanism for the deposit guarantee scheme (Circular CSSF 13/555, point 13).
- The person responsible for protecting client assets under Article 6 of the Grand-ducal Regulation of 30 May 2018, the role the instructions call the single officer (“agent unique”).
Knowledge and competence, AML/CFT and finance (lines 19 to 22)
- The authorised manager monitoring the ESMA guidelines on the assessment of knowledge and competence and Circular CSSF 17/665, who the instructions say must be a member of the authorised management under point 3.a), fifth paragraph, of that circular.
- The member of the authorised management or of the board responsible for compliance with AML/CFT professional obligations.
- The person in charge of controlling compliance with those obligations, both AML/CFT lines citing Article 40(1) of CSSF Regulation No 12-02.
- The Chief Financial Officer of significant institutions.
In the eDesk questionnaire each line takes a name, a function, a starting date and an ending date. The CSSF FAQ sets the date logic: the starting date is the start of the person’s mandate, and the ending date stays empty while the mandate runs. The external-expert line needs three items under the instructions: the identity of the audit firm, the name of the natural person who represents it, and the name of the authorised manager who follows up the expert’s work. B 4.6 contains person, function and mandate-date information rather than monetary reporting fields. No name-order or character-limit rule was identified in the publicly accessible B 4.6 form, instructions or FAQ; procedure-specific field constraints should be checked in the dedicated eDesk user guide.
The legal references printed beside each line hide a trap. The 2021 form and the FAQ annex cite different point numbers of Circular CSSF 12/552 for the same functions. The authorised managers for audit, compliance and risk control sit under point 64 on the form and point 65 in the FAQ; the three internal-control heads under point 118 on the form and points 118 and 119 in the FAQ; the external expert under points 119 to 121 on the form and 120 to 122 in the FAQ; the CFO under point 81 on the form and point 82 in the FAQ. The instructions cite points 100, 103 and 117 for the internal control functions and their heads, and points 119 to 121 for the external expert. Their amendment list for Circular 12/552 stops at Circular CSSF 20/759, while the CSSF page for the circular also lists Circulars CSSF 21/785, 22/807 and 24/860.
The risk control line shows the same drift. The form cites Circular CSSF 20/753 (annex 2, point 7) next to Circular 12/552, while the FAQ annex cites point 137 of Circular 12/552 and Circular CSSF 07/301, the two ICAAP and ILAAP circulars covered in our CSSF ICAAP and ILAAP filing guide. The function description on each line is the stable element, and the printed point numbers are the part most likely to be out of date.
Reference Date, Deadline and In-Year Changes for B 4.6
The annual rule has no variants. The table is drawn up on the situation at 31 December of each year and must reach the CSSF by 20 January of the following year, and the handbook expresses the same deadline as the 20th calendar day after the reporting reference date. In eDesk the reference period of an annual submission is predefined as the year before the deadline, so the filing due on 20 January of year N shows the position on 31 December of year N-1. The year now closing is always the one reported the following January.
The handbook attaches a note on non-December accounting year-ends to the B 2.5 B and B 2.5 E rows. B 4.6 carries no such note, and the instructions fix the reference date at 31 December each year.
The other trigger for a filing is a change of holder during the year. The instructions require any change affecting a person named on B 4.6 to be reported to the CSSF immediately. The FAQ turns that into an additional submission whose reference period is the date from which the change applies, meaning the date on which the new person holds the position. Neither document puts a number of days on “immediately”.
For the eDesk procedure itself, the FAQ says the first submission had to reflect the 31 December 2023 position and asked filers to enter starting dates for every person already in post. The documents do not record the table’s original first reference date, which predates the eDesk era.
Submission of B 4.6 Through the eDesk Portal or the S3 API
Since 2 January 2024 the CSSF has required credit institutions to transmit B4.5 and B4.6 by one of two methods: a dedicated eDesk procedure reached through the eDesk Portal, or an API solution that submits a structured exchange file in JSON format over the S3 (“simple storage service”) protocol. The two historical reports now form a single eDesk procedure, “National Banking Reporting”. The handbook’s transmission table lists B4.6 as “Webform/JSON” through “eDesk/API”, available from 2 January 2024, which is the earliest eDesk/API date in that table. The public Reporting Handbook classifies B 4.6 as Webform/JSON rather than XBRL and points users to the dedicated eDesk user guide for the procedure-specific technical details.
The old routes are closed. Asked whether the reports can still go in OTHREP format through SOFiE/E-file or MFT, the FAQ answers no, citing a CSSF communication of 21 December 2023, and tells entities without an eDesk user account to create one. Table B 2.4 followed onto eDesk/API from 1 February 2026, so the national tables are converging on the same channel.
Access is the practical prerequisite. The CSSF’s eDesk authentication rules, as summarised in its user guide for bank prudential XBRL reports, require each user to hold a LuxTrust certificate and to link the account to the entity through a request approved by the entity’s advanced user, a role the CSSF validates on application.
The FAQ states that B4.6 may be submitted as a structured JSON exchange file via S3 and that the dedicated user guide is available in eDesk. The public Reporting Handbook classifies B4.6 as Webform/JSON and refers its file-naming convention to the dedicated eDesk user guide; it also points users to the CSSF’s general API technical guide. The B4.6-specific JSON and file-naming requirements should therefore be taken from the dedicated eDesk user guide.
Three mechanics from the FAQ matter at filing time:
- The roll-forward function pre-fills the questionnaire with the previous submission’s answers, and the user must check and correct them before submitting.
- A new draft cannot be created outside the annual reporting window. A change during the year is filed by reopening the last submitted report, setting the reason of submission to “additional submission (change during the year)”, adding an ending date to the outgoing holder’s line and a new line for the incoming holder, then submitting the questionnaire.
- Errors found in the year-end filing are corrected through the same reopen-and-resubmit steps, without changing the reason of submission.
Validation and Rejection: What the CSSF Publishes for B 4.6
No numbered B 4.6 validation-rule set was identified in the publicly accessible CSSF sources reviewed; the dedicated eDesk user guide contains completion, validation and submission guidance but is login-gated. The EBA validation rules, CSSF plausibility checks and ECB data quality checks described on the CSSF’s prudential reporting page are framed around the EBA reporting modules, and B 4.6 is a questionnaire. The one integrated validation rule the FAQ describes belongs to the B4.5 part, where the direct shareholdings must sum to 100%.
The requirements the documents do make explicit give a working list of the ways a B 4.6 submission can be wrong:
- No filing in a year without changes, although the FAQ makes the annual submission mandatory regardless.
- Blank lines for functions with no holder. The FAQ convention for a function that is not occupied, or that has no dedicated person, is “01/01/1800” as the starting date and “N/A” for the name and the function.
- A departed holder left open. A mandate ends with an ending date on the existing line, and the successor goes on a new line.
- An authorised-management line filled with someone outside the authorised management or, at an EU branch, outside the persons notified to the CSSF as managers.
No list of rejection causes for the questionnaire appears in the public CSSF documents, and the user guide that describes the eDesk validation steps sits behind the eDesk login. One cross-check needs no published rule: the key function holders on B 4.6 should be the same people the CSSF has processed under its prudential procedure for the appointment of management body members and key function holders, because the instructions route every such change through that procedure.
Caveats and Interactions: DORA, AML/CFT Notifications and the Approval Procedure
The ICT lines after Circular CSSF 25/881
Circular CSSF 25/881 removed DORA financial entities from the scope of Circular CSSF 20/750, and the framework changed again on 27 August 2026 through Circular CSSF 26/915. The CSSF then removed third-country branches falling within the DORA scope described by the CSSF from Circular 20/750 and brought them within the relevant DORA-related CSSF circulars. The December 2025 B 4.6 instructions nevertheless still cite points 2 and 11 of Circular 20/750 for the two ICT lines, and the January 2021 form and April 2025 FAQ annex retain the same legacy reference.
No revised B 4.6 instruction or FAQ replacing those two line references was identified. The two reporting lines therefore remain part of B 4.6, but their underlying ICT reference must be read against the regime currently applicable to the institution, including Circular CSSF 26/915 for affected third-country branches. The DORA reporting side is covered in our DORA register of information guide.
AML/CFT roles: communicated to the CSSF in advance, recorded on B 4.6
Article 40(2) of CSSF Regulation No 12-02 requires the names of the person responsible for AML/CFT compliance and of the compliance officer, and information prior to any change to those functions, to be communicated to the CSSF. B 4.6 lines 20 and 21 record the same two roles, so a change to either one touches two obligations: the prior communication under the regulation and the B 4.6 update. The December 2025 B 4.6 instructions still refer to point 146 of Circular CSSF 12/552 for the relationship between the compliance function and AML/CFT, but that reference is stale.
Article 40(1) of CSSF Regulation No 12-02 distinguishes two roles: the person responsible for compliance with AML/CFT professional obligations at the level of the authorised management or Board of Directors, and the compliance officer in charge of controlling compliance with those obligations. Current Circular CSSF 12/552 states that the Chief Compliance Officer is responsible for the control of compliance with AML/CFT professional obligations, whereas current point 146 concerns the compliance function’s assistance and advice to authorised management. A Chief Compliance Officer may therefore appear on the AML/CFT control-role line where that person has been appointed to the Article 40(1) compliance-officer role; the sources do not support treating the CCO automatically as the separate AML/CFT responsible person. Suspicious transaction reporting sits in a separate regime, set out in our AML reporting in Luxembourg guide.
B 4.6 sits downstream of the approval procedure
The instructions keep the approval question apart from the reporting one. Key function holders, as defined in point 1.9 of Circular 12/552, include in particular the heads of the three internal control functions and the CFO where the CFO line applies. The December 2025 B 4.6 instructions cite points 65 and 117 of Circular CSSF 12/552 for these notifications, but those cross-references no longer match the current consolidated circular. Current point 66 requires institutions to inform the competent authority of appointments and removals of members of the authorised management in accordance with the Prudential Procedure, while current point 118 requires appointments and removals of the heads of the internal control functions to be reported in writing in accordance with that procedure.
Other key function holders remain subject to the CSSF’s published fit-and-proper procedure where applicable. Following the May 2026 amendments to the Law of 5 April 1993, “authorised management” must be read as the MBMF for CRR institutions; Article 7(2bis) of the same law further requires a credit institution to submit a suitability application for a prospective management-body member as soon as there is a clear intention to appoint that person and, in any event, at the latest 30 working days before the person is scheduled to take up the position. Updating B 4.6 remains a separate reporting step.
Proportionality and branches
Proportionality in B 4.6 works only through the individual lines described under scope above: the head-office option for EU branches, the ICT option for small institutions and the CFO line for institutions of significant importance. The CSSF documents provide no reduced version of the table, no waiver, no national discretion and no transitional provision.
Changes to B 4.6 From 2013 to the December 2025 Instructions
- 3 December 2013: Circular CSSF 13/576 renames the table “Persons responsible for certain functions and activities”, aligns it with Circular CSSF 12/552 as amended by Circular CSSF 13/563, and adds the Single Customer View authorised manager.
- 20 July 2018: Circular CSSF 18/695 updates the table again. The CSSF now lists the circular as outdated.
- 28 January 2021: the CSSF updates the form to the January 2021 version that remains published.
- 1 March 2022: the version log of the instructions records a change of submission method for B 4.6 without describing it. The B 4.5 instructions log a submission-method change on the same date.
- 2 January 2024: eDesk webform or JSON over S3 becomes the required channel, B4.5 and B4.6 merge into the National Banking Reporting procedure, and the historical channels close following the CSSF communication of 21 December 2023.
- 12 January 2024 to 23 April 2025: the FAQ’s internal version history dates the initial version 12 January 2024, while the CSSF document page records publication on 15 January 2024; the FAQ was subsequently updated on 30 December 2024 and 23 April 2025. For B 4.6 the relevant updates of 30 December 2024 cover the reference period and the handling of changes during the year.
- 11 December 2025: new instructions, described in their version log as a change relating to the single officer function.
The track-changes version of the December 2025 instructions shows exactly what moved. One sentence was deleted: the statement that the single officer function could not be performed by a member of the credit institution’s authorised management. The sentence that survives lets each credit institution decide whether the appointed officer works exclusively on that mission or can discharge those responsibilities effectively while taking on others. From that version on, the instructions place no bar on naming an authorised manager on the single-officer line.
The CSSF documents announce no further change to the table or its instructions. The FAQ says it will be updated when required, and Circular CSSF 14/593 says the handbook will be updated on a regular basis. No later public version of the B 4.6 instructions was identified; later legislation, circular amendments and CSSF communiques can nevertheless change how a printed legacy reference must be read before the instructions themselves are revised.
Frequently Asked Questions
One person holds several of the 22 functions. Does the name go on each line?
Each line asks for the holder of that specific function, so the same name appears wherever that person holds the role. B 4.6 sets no rule against combining roles; the limits come from the underlying texts, such as the requirement that the knowledge-and-competence monitor under Circular CSSF 17/665 be a member of the authorised management.
A new Chief Risk Officer is chosen in March, but the CSSF approval is still pending. When does B 4.6 change?
The FAQ keys the additional submission to the date from which the new person holds the position. Under the Prudential Procedure applicable since 30 June 2022, the appointment of a key function holder who is not a member of the authorised management does not require formal authorisation under Luxembourg law, although the heads of the internal control functions and the CFO of certain significant CRD institutions are subject to prior competent-authority assessment. The CSSF has said it will adapt that procedure to the Law of 5 May 2026, which tightened the fit-and-proper criteria and inserted Article 38-2ter of the Law of 5 April 1993 on the suitability assessment of key function holders, once the EBA has published its revised guidelines. A key function holder who is also a management-body member follows the applicable management-body suitability process. The B 4.6 update therefore follows the date the person actually takes up the role; whether prior assessment or authorisation is required depends on the applicable fit-and-proper route.
Should a Luxembourg bank with foreign branches list the function holders at those branches?
The instructions ask for accounting version “L” only, defined as information on the entity established in Luxembourg, and they say nothing specific about people who work at foreign branches. The reading that fits version L is the Luxembourg entity’s own designations; a bank with a different case should put it to the CSSF.
What happens when 20 January falls on a weekend or public holiday?
The instructions, the handbook and the FAQ are silent on moving the date. A filer who treats 20 January as fixed meets the deadline under any reading.
Our ICT function is run by a group entity. Whose name goes on the IT Officer line?
The instructions describe the ICT heads as a staff member or, at small institutions, a member of the authorised management. Unlike internal audit, where a separate line exists for an external expert and the person representing it, the ICT lines have no slot for an outside provider. On the instructions’ wording, the name expected is an individual inside the institution who holds the role.
A change during the year affects only one B 4.6 line. Do we have to touch the B4.5 part?
No. The FAQ procedure reopens the last submitted questionnaire and then asks the user to edit whichever part, B4.5 or B4.6, requires the update before resubmitting. The shareholding part can stay as it was.
Can a board member appear on the table?
The AML/CFT responsible-person line expressly allows a member of the authorised management or of the Board of Directors under Article 40(1) of CSSF Regulation No 12-02. Separately, for CRR institutions, the CSSF’s May 2026 communique requires every B 4.6 reference to “authorised management” to be read as referring to all members of the Management Body in its Management Function (MBMF). Whether a board member can therefore populate another line depends on whether that person is a member of the MBMF and satisfies the underlying requirement for that function.
Related Articles
- CSSF Table B 2.4 Reporting: Participations and Subordinated Loans: the national table on participating interests and subordinated loans, which moved to eDesk/API in 2026.
- CSSF B 2.5 B and B 2.5 E Reporting: Luxembourg Staff Costs and Taxes: the other annual national tables kept alive by Circular CSSF 14/593.
- CSSF ICAAP and ILAAP: Filing Under Circulars 07/301 and 20/753: the circulars behind the risk control line on B 4.6.
- COFREP Validation Rules: The CSSF List Banks Must Recheck: how validation works for the XBRL modules that B 4.6 sits beside.
- DORA Register of Information: A Practical Guide for Financial Entities: the DORA reporting that now frames the ICT roles.
Key Takeaways
- Give one person ownership of the National Banking Reporting procedure, with eDesk access, for both the January filing and every reopening during the year.
- Map the 22 lines by their function descriptions, and check any Circular 12/552 point number against the current consolidated text before quoting it.
- Keep the two ICT lines in B 4.6, but do not infer a one-to-one replacement from the legacy Circular CSSF 20/750 citations. For a DORA entity, document how the institution maps its current ICT and ICT-risk-control responsibilities to the two functions requested by B 4.6 and obtain CSSF clarification where that mapping is not clear.
- A bank with a non-December financial year still reports the 31 December position on B 4.6.
- Treat a change to either AML/CFT role as two separate obligations: the prior communication to the CSSF required by Article 40(2) of CSSF Regulation No 12-02 and the B 4.6 in-year update.
- Revisit the single-officer designation: the December 2025 instructions removed the previous sentence barring a member of the authorised management from that role and now state that the single officer may combine the mission with other responsibilities if the responsibilities can still be discharged effectively.
- Build any B 4.6 JSON/S3 integration from the dedicated eDesk user guide together with the CSSF’s public API/S3 guidance. The public handbook points B 4.6 file naming to the dedicated eDesk guide, while the guide itself is available through eDesk.
Sources and References
- CSSF, Instructions relating to table B 4.6 “Persons responsible for certain functions and activities” (French, version December 2025, clean): https://www.cssf.lu/wp-content/uploads/Tableau-4.6-Instructions_Clean.pdf
- CSSF, Instructions relating to table B 4.6 (French, track changes, December 2025): https://www.cssf.lu/wp-content/uploads/Tableau-4.6-Instructions_TC.pdf
- CSSF, document page for the table B 4.6 instructions (updated 11 December 2025): https://www.cssf.lu/en/Document/instructions-relating-to-table-b-4-6/
- CSSF, Table B 4.6 form (French, version January 2021): https://www.cssf.lu/wp-content/uploads/Tableau-4.6_Clean_280121.pdf
- CSSF, FAQ National reporting B4.5 and B4.6 (23 April 2025): https://www.cssf.lu/wp-content/uploads/FAQ-national-reporting-B4.5-and-B4.6.pdf
- CSSF, Reporting requirements for credit institutions, final version 8.3 (17 November 2025), version-update log confirming the B2.4 eDesk/API transmission channel from 1 February 2026: https://www.cssf.lu/wp-content/uploads/Reporting_requirements_final.pdf
- CSSF, Circular CSSF 14/593 on supervisory reporting requirements applicable to credit institutions, as amended: https://www.cssf.lu/wp-content/uploads/cssf14_593eng.pdf
- CSSF, Circular CSSF 13/576 (3 December 2013), update of table B 4.6: https://www.cssf.lu/wp-content/uploads/cssf13_576eng.pdf
- CSSF, Circular CSSF 18/695 (20 July 2018), document page: https://www.cssf.lu/en/Document/circular-cssf-18-695/
- CSSF, Circular CSSF 12/552 on central administration, internal governance and risk management, as amended, document page: https://www.cssf.lu/en/Document/circular-cssf-12-552/
- CSSF, Circular CSSF 22/821 (as amended by Circulars CSSF 23/845, 24/865 and 25/897), on the revised Long Form Report for credit institutions, repealing Circular IML 96/125 from 31 December 2022, document page: https://www.cssf.lu/en/Document/circular-cssf-22-821/
- CSSF, Circular CSSF 25/881 amending Circular CSSF 20/750 on ICT and security risk management (9 April 2025, as amended by Circular CSSF 26/915): https://www.cssf.lu/wp-content/uploads/cssf25_881eng.pdf
- CSSF, Circular CSSF 26/915 amending Circulars CSSF 20/750, 22/806, 25/881, 25/882, 25/883, 25/892 and 25/893 on the applicability of DORA to third-country branches in Luxembourg (27 August 2026): https://www.cssf.lu/wp-content/uploads/cssf26_915eng.pdf
- CSSF Regulation No 12-02 of 14 December 2012 on the fight against money laundering and terrorist financing, consolidated: https://www.cssf.lu/wp-content/uploads/RCSSF_No12-02eng.pdf
- CSSF, Law of 5 April 1993 on the financial sector, document page (consolidated text, as amended, including Article 7): https://www.cssf.lu/en/Document/law-of-5-april-1993/
- Legilux, Journal Officiel du Grand-Duche de Luxembourg, Memorial A No. 227 of 6 May 2026 (Law of 5 May 2026 transposing Directive (EU) 2024/1619 (CRD VI) and amending the Law of 5 April 1993), inserting Article 7, paragraph 2bis (suitability-application deadline of 30 working days before taking up the position) and, for third-country credit institution branches, a new Part I, Chapter 3, Sub-chapter 2, Section 3 (Articles 32-2 to 32-19) with the transitional Article 73: https://data.legilux.public.lu/filestore/eli/etat/leg/loi/2026/05/05/a227/jo/fr/pdfa/eli-etat-leg-loi-2026-05-05-a227-jo-fr-pdfa.pdf
- CSSF, Publication of the Law of 5 May 2026 transposing Directive (EU) 2024/1619 (CRD VI) and Directive (EU) 2024/2994: https://www.cssf.lu/en/2026/05/publication-of-the-law-of-5-may-2026-transposing-directive-eu-2024-1619-crd-vi-and-directive-eu-2024-2994/
- CSSF, Prudential reporting for credit institutions: https://www.cssf.lu/en/prudential-reporting-credit-institutions/
- CSSF, User Guide for XBRL reports: Bank prudential reporting, version 1.3: https://www.cssf.lu/wp-content/uploads/Bank_prudential_reporting.pdf
- CSSF, Methods of transmitting reports via API: https://www.cssf.lu/en/methods-of-transmitting-reports-via-api/
- CSSF, Prudential procedure for the appointment of members of the management body and key function holders in credit institutions (applicable as from 30.06.2022): https://www.cssf.lu/wp-content/uploads/Prudential_procedure_CI_eng.pdf
Preparing the Next 20 January B 4.6 Filing
Each filing shows the 31 December position just passed and reaches the CSSF by the following 20 January. The file to have ready before that date is a line-by-line map of the 22 functions to named holders and mandate start dates, with every vacancy and every change since the last submission marked, so the eDesk questionnaire can be checked against it before it goes in.
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.
