EuReCA Reporting: CSSF Names AMLA in Joint Controllership Update
On 11 September 2026, the Commission de Surveillance du Secteur Financier (CSSF) reissued its statement on the EuReCA joint controllership arrangement, and the edit is narrow on the page but material underneath it: every reference to the European Banking Authority (EBA) is now a reference to the Authority for Anti-Money Laundering and Countering the Financing of Terrorism (AMLA). EuReCA, the EU central database that records serious AML/CFT weaknesses found in individual financial institutions, has moved from the EBA to AMLA.
For firms supervised in Luxembourg, EuReCA reporting stays a supervisor-side exercise, and the practical point of the update is a data-protection one. The authority that jointly controls their AML/CFT weakness data alongside the CSSF is now AMLA, so AMLA is now the EU-level controller; during the Article 106 transition, however, the EBA may continue to access and act on EuReCA on behalf of AMLA. The CSSF’s underlying duty to report the material weaknesses it detects is unchanged. What the 11 September update settles is who the CSSF stands beside as a joint controller when personal data passes into and out of the database.
The legal hook is Article 106 of Regulation (EU) 2024/1620, the AMLA Regulation. Under that provision, AMLA and the EBA entered into a bilateral agreement on access to the AML/CFT central database established under Article 9a of Regulation (EU) No 1093/2010, together with its financing and joint management. The CSSF then re-papered its 2024 statement to match. This is a governance and privacy change riding on top of a stable reporting pipe, and reading it that way keeps compliance teams from chasing a filing that does not exist.
Related reading: our guide to what the AML Regulation changes in Luxembourg.
The EuReCA transfer: dates Luxembourg teams should log
EuReCA has a longer paper trail than the September statement suggests, and the operative dates run from the database’s launch through to AMLA’s direct-supervision start. Keeping the sequence straight matters when a policy or a record of processing needs a citation that still resolves.
- 20 December 2021: the EBA published the draft regulatory technical standards for the central database.
- 31 January 2022: the EBA launched EuReCA, the European reporting system for material AML/CFT weaknesses.
- 9 November 2023: the Commission adopted the RTS as Commission Delegated Regulation (EU) 2024/595.
- 26 June 2024: AMLA was legally established when Regulation (EU) 2024/1620 entered into force.
- 30 August 2024: the CSSF published its original statement on the CSSF and EBA joint controllership arrangement.
- 1 July 2025: AMLA took up its work, based in Frankfurt am Main.
- 1 January 2026: the EBA completed the handover of its AML/CFT mandates to AMLA, EuReCA included.
- 11 September 2026: the CSSF updated its statement so that references to the EBA read as references to AMLA.
- 2028: AMLA is due to begin direct supervision of a first group of selected obliged entities (six months after the list of selected entities is published per Article 13(4) of Regulation (EU) 2024/1620).
None of these dates is a reporting deadline for a supervised firm. They are the audit trail behind a change of controller, and the two that a Luxembourg compliance function will cite most often are 1 January 2026, when EuReCA passed to AMLA, and 11 September 2026, when the CSSF confirmed the counterparty on its own statement.
What changed on 11 September, and what did not
The mechanics of the update are deliberately light. The CSSF substituted the responsible authority, leaving the substance of the arrangement otherwise unchanged. As the statement puts it, references to the EBA in the 30 August 2024 text should be read as references to AMLA, on the understanding that the EBA may still access and act on EuReCA on behalf of AMLA. That last clause matters for continuity: Under Article 106, the EBA may continue to access and act on EuReCA on behalf of AMLA during the agreed transition period.
Two things did not change. First, the reporting obligation. The CSSF, as a reporting authority, still records material weaknesses it identifies and the measures it imposes, and it still submits reasoned requests to draw information back out. Second, the purpose of the arrangement. The joint controllership arrangement was, and remains, a data-protection instrument that allocates responsibilities between two public authorities under the applicable data-protection rules. Swapping the EBA for AMLA changes the name on one side of that allocation without altering what the arrangement is for.
The common misread here is to treat the update as a supervisory-reporting change and to go looking for a new template, a new portal, or a new remittance date. There is none. This EuReCA joint-controllership update changes the database’s governance; it does not itself create a firm-level EuReCA return or deadline. Other AMLA-related data collections must be assessed separately.
Who feeds EuReCA: the supervisor-to-database pipeline
EuReCA is a supervisor-to-database system. It originated under Article 9a(1) and (3) of Regulation (EU) No 1093/2010; Article 9a has since been deleted following AMLA’s establishment, and Article 11 of Regulation (EU) 2024/1620 now governs the central database, while Article 106 of Regulation (EU) 2024/1620 covers the transitional arrangements. It is populated by reporting authorities, meaning EU financial-sector supervisors such as the CSSF and the other authorities defined in Commission Delegated Regulation (EU) 2024/595. Those authorities report the material weaknesses they detect during supervision and the remedial measures they impose. Obliged entities are not EuReCA reporting authorities and do not submit material-weakness records to the database directly.
This is the distinction that most often gets blurred in internal briefings. A Luxembourg credit institution or payment institution does not report to EuReCA the way it reports suspicious transactions to the Cellule de Renseignement Financier. Those are separate regimes with separate legal bases: firm-level financial-intelligence reporting runs through the FIU, while EuReCA captures a supervisor’s assessment of a firm’s control failures. A team that files diligently through the goAML workflow to the CRF has still done nothing that appears in EuReCA, because the two systems answer different questions.
The RTS frames what a supervisor must pass along. Reporting authorities provide information on material weaknesses without undue delay, and they do so whether or not a measure has yet been taken in response. The weaknesses in scope run across a firm’s processes and procedures, its governance arrangements, the fitness and propriety of the people who run it, acquisitions of qualifying holdings, and its business model and activities. In other words, the record is the supervisor’s, built from supervision, and the firm is assessed while it files nothing.
The joint controllership arrangement covers personal data, and only that
The arrangement exists because EuReCA processes personal data. GDPR Article 26 governs joint controllership for the CSSF, while AMLA, as a Union authority, is subject to Article 28 of Regulation (EU) 2018/1725; both provisions require joint controllers to determine their respective data-protection responsibilities. The CSSF and AMLA have formalised those responsibilities in the joint controllership arrangement, and the CSSF publishes the essence of it as required by data-protection law. Its reach is confined to the personal data that the parties transfer to or from EuReCA. It does not govern the supervisory content of a weakness record, the CSSF’s decision to impose a measure, or any other AML/CFT process.
That boundary is easy to lose. A weakness record can name individuals, for example a member of a management body who was informed of a control failure and chose not to remediate it, which is precisely the kind of finding the EBA cited when it launched the database. The arrangement governs how the personal data of such individuals is handled between the CSSF and AMLA. The arrangement allocates data-protection responsibilities and does not determine the merits of the underlying supervisory finding. Reading the arrangement as anything wider than a data-protection allocation invites the wrong internal owner to pick it up.
The essence the CSSF publishes rests on three commitments: mutual assistance between the CSSF and AMLA in meeting their data-protection obligations, a defined route for handling data-subject requests, and cooperation on any personal-data breach connected to the database. Each binds the authorities to one another and to data subjects; none of it hands a task to supervised firms.
EuReCA reporting: what lands in the database about a Luxembourg firm
A material weakness, in EuReCA terms, is a serious deficiency in AML/CFT compliance that exposes a financial-sector operator to money-laundering or terrorist-financing risk; EuReCA also records related measures where a reporting authority has taken them. The EBA’s own examples when it launched the system included the absence of transaction monitoring at group level and the absence of policies and procedures for high-risk customers, the kind of structural gap that a supervisor treats as material instead of a one-off lapse.
According to the EBA’s EuReCA database update of 16 December 2024, reporting authorities logged 787 material weaknesses concerning 267 entities during 2024, and applied 377 corrective measures ranging from compliance orders and pecuniary fines through to authorisation withdrawals. The EBA reported that most weaknesses related to deficiencies in customer due diligence, and in particular the effectiveness of ongoing transaction monitoring, and that the improper use of technology was a factor in more than half of all cases. Credit institutions remained the most frequently reported category, with a rise in submissions concerning payment institutions and electronic money institutions.
For a Luxembourg firm, the read-across is concrete. On the EBA’s figures, the failings recorded most often are the effectiveness of transaction monitoring and customer due diligence. A weakness recorded here is available to supervisors across the Union through reasoned requests, so the quality of a firm’s monitoring and CDD evidence carries weight beyond a single inspection. EuReCA makes a supervisor’s assessment portable across borders without publishing firm names to the market.
Data-subject rights and breaches now route through AMLA
The operational consequence of the update sits in the request and breach flows, and this is where the change of controller becomes a workflow item rather than a footnote. Where the CSSF receives a data-subject request touching personal data processed through EuReCA, it forwards that request, or the relevant part of it, promptly to AMLA. Where AMLA receives the request, it processes it with the help of the reporting authority that supplied the personal data and informs the other parties of its decision, and the authority that received the request replies on the basis of what AMLA communicates.
Breach handling follows the same logic. The CSSF and AMLA cooperate on any personal-data breach connected to EuReCA, and the CSSF notifies AMLA and, where required, the relevant data-protection authorities and data subjects of a breach it becomes aware of. For a supervised firm, the point to internalise is where the request lands: an individual who wants to exercise data-protection rights over EuReCA-held data now deals with AMLA and the CSSF, and the CSSF directs such questions to its data protection officer at dpo@cssf.lu or to AMLA’s own data protection notice. Any internal privacy notice or record of processing that still names the EBA as the joint controller for EuReCA is now out of date.
Where EuReCA sits in the wider AMLA handover
The EuReCA update is one visible piece of a larger migration. The EBA completed the handover of its AML/CFT mandates to AMLA on 1 January 2026, transferring the database along with supervisory insight and risk assessments, and existing EBA guidelines stayed in force until AMLA replaces them. AMLA itself began operating on 1 July 2025 from Frankfurt am Main, and its direct supervision of a first selection of high-risk obliged entities is due to start in 2028, after the first selection process (which must commence by 1 July 2027 per Article 13(4) of Regulation (EU) 2024/1620 and concludes within six months) and publication of the list of selected entities.
The database therefore now feeds an authority that will, in time, supervise some entities directly and coordinate the supervision of the rest. That gives EuReCA a sharper role than it had as an EBA tool: the same authority that identifies AML/CFT risk trends from the data will increasingly act on them. Luxembourg firms tracking the broader package can follow it through AMLA’s emerging standards, including AMLA’s home-host supervisory cooperation work and the single AML rulebook that arrives with the AML Regulation. None of that alters the September statement’s message, which is that the controller has changed and the filing has not.
Frequently Asked Questions
Does a Luxembourg firm have to report anything into EuReCA after this update?
No. EuReCA is populated by supervisors and by the other reporting authorities defined in Commission Delegated Regulation (EU) 2024/595; obliged entities are not among them. The update changes the joint controller from the EBA to AMLA; it does not create a firm-level return. A firm’s own AML/CFT obligations, including suspicious transaction reporting to the CRF, are separate and unchanged.
Can a supervised firm see what the CSSF has recorded about it in EuReCA?
Access to EuReCA content is for authorities, exercised by AMLA and reporting authorities through reasoned requests; supervised firms have no such access. An individual whose personal data appears in a record can exercise data-protection rights over that data, but that is a data-subject route handled by AMLA and the CSSF, not a firm-level right to read its own weakness file.
A senior manager was named in a material weakness record. How does that person exercise data-protection rights now?
A data subject may exercise rights through the relevant joint controllers, including the CSSF or AMLA. During the Article 106 transition, the EBA may continue acting on AMLA’s behalf in operating EuReCA. The CSSF points such requests to its data protection officer at dpo@cssf.lu and to AMLA’s data protection notice.
Does EuReCA replace suspicious transaction reporting to the CRF via goAML?
No. Those are different systems with different legal bases. goAML carries a firm’s suspicious transaction reports to the Luxembourg financial intelligence unit. EuReCA carries a supervisor’s assessment of a firm’s AML/CFT control weaknesses. Filing one has no bearing on the other.
Is EuReCA the same as the CSSF’s annual AML/CFT data collection?
No. The CSSF’s annual AML/CFT survey is firm-level information that supervised entities submit to the CSSF. EuReCA holds supervisor-detected material weaknesses and the measures imposed. A firm completing the annual collection is not populating EuReCA.
What happens to weakness records the EBA held before 1 January 2026?
They moved to AMLA with the rest of the database on completion of the handover. Under the Article 106 bilateral agreement, the EBA may still access and act on EuReCA on behalf of AMLA, which supports continuity while control sits with AMLA.
Does the EBA still have any role in EuReCA?
Yes, but an operational one on AMLA’s behalf. The AMLA Regulation lets the EBA continue to access and act on the database under the bilateral agreement covering access, financing and joint management. AMLA is a controller for EuReCA personal-data processing and has joint-controllership arrangements with national competent authorities; the EBA may continue acting on AMLA’s behalf during the Article 106 transition.
Related Articles
- AMLR: What the Single AML Rulebook Changes in Luxembourg: how the AML Regulation reshapes obligations for Luxembourg-supervised firms.
- AMLA Home-Host Supervisory Cooperation: what AMLA’s cross-border cooperation standards mean for AML teams.
- CSSF AML/CFT Data Collection 2026: the annual firm-level survey Luxembourg entities file to the CSSF.
- goAML and the Luxembourg CRF Reporting Workflow: how suspicious transaction reporting reaches the financial intelligence unit.
- AMLA Central Contact Point Survey for PSPs and EMIs: an early AMLA data exercise aimed at payment and e-money firms.
Key Takeaways
- The CSSF’s 11 September 2026 update replaces the EBA with AMLA as the EuReCA joint controller; it creates no new firm-level filing.
- EuReCA moved to AMLA under Article 106 of Regulation (EU) 2024/1620, and the EBA may still access and act on the database on AMLA’s behalf during the agreed transition period.
- Supervisors and other reporting authorities feed EuReCA; obliged entities are not reporting authorities and do not submit material-weakness records directly.
- The joint controllership arrangement governs only personal-data processing; the CSSF is subject to GDPR Article 26 and AMLA to Article 28 of Regulation (EU) 2018/1725. Route EuReCA data-subject requests to AMLA or the CSSF DPO at dpo@cssf.lu.
- Update any record of processing or privacy notice that still names the EBA as the EuReCA joint controller so that it names AMLA.
- In 2024, authorities logged 787 material weaknesses on 267 entities and applied 377 corrective measures, with customer due diligence and transaction monitoring the most common failings.
- AMLA has controlled EuReCA since the 1 January 2026 handover and begins direct supervision of selected entities in 2028.
Sources and References
- CSSF, Update of the statement of 30 August 2024 on the joint controllership arrangement between the CSSF and the EBA regarding the EuReCA central database (updated 11 September 2026): cssf.lu.
- Regulation (EU) 2024/1620 establishing AMLA (Article 11 on the AML/CFT central database; Article 106 on transitional arrangements): EUR-Lex.
- Regulation (EU) No 1093/2010 establishing the EBA (former Article 9a, the historical EuReCA legal basis; Article 9a was deleted following AMLA’s establishment): EUR-Lex.
- Commission Delegated Regulation (EU) 2024/595 of 9 November 2023 (RTS on the AML/CFT central database): EUR-Lex.
- Regulation (EU) 2016/679 (GDPR), Article 26 on joint controllers: EUR-Lex.
- Regulation (EU) 2018/1725 of the European Parliament and of the Council (applicable to AMLA’s personal-data processing, including Article 28 on joint controllership for Union institutions): EUR-Lex.
- EBA, EBA launches EuReCA, the EU central database for AML/CFT (31 January 2022): eba.europa.eu.
- EBA, EuReCA database update (16 December 2024): ec.europa.eu.
- EBA and AMLA, EBA and AMLA complete handover of AML/CFT mandates (published 19 January 2026; handover effective 1 January 2026): eba.europa.eu.
- Regulation (EU) 2024/1624 (Anti-Money Laundering Regulation, the single AML rulebook): EUR-Lex.
- AMLA, Authority for Anti-Money Laundering and Countering the Financing of Terrorism: amla.europa.eu.
Updating your records for the AMLA-era EuReCA
The task the September statement generates for a Luxembourg compliance function is administrative, and it is small. Where an internal record of processing, a privacy notice, or a data-protection procedure refers to the EBA as the EuReCA joint controller, that reference now points to AMLA, with the CSSF DPO at dpo@cssf.lu as the local contact and AMLA’s data protection notice as the wider one. Nothing new goes onto the reporting calendar, and the CSSF’s duty to record material weaknesses continues as before. The date to watch now is a supervisory one: AMLA begins direct supervision of selected obliged entities in 2028, and that will decide how actively the authority now controlling EuReCA uses what the database holds. This EuReCA joint-controllership update changes the database’s governance; it does not itself create a firm-level EuReCA return or deadline. Other AMLA-related data collections must be assessed separately.
Disclaimer: The information on RegReportingDesk.com is for educational and informational purposes only. It does not constitute legal, regulatory, tax, or compliance advice. Always consult your compliance officer, legal counsel, or the relevant supervisory authority for guidance specific to your institution.
